[Community-sigs] Win.Downloader
Xabier Ugarte-Pedrero
xpedrero at sourcefire.com
Mon Jul 4 16:30:51 EDT 2016
Hello Arnaud,
Unfortunately the signature has not passed the FP test. It seems it is
matching the NSIS inetc plugin, which comes as a resource in files
generated by the NSIS (Nullsoft Scriptable Install System -
http://nsis.sourceforge.net/Main_Page), used by several legitimate
software.
Nevertheless, the binary seems to contain some characteristic VBScript code:
var fso = new ActiveXObject("Scripting.FileSystemObject");
var s3 = fso.GetSpecialFolder(2).Path; // s3 @02=> "C:\\WINDOWS\\TEMP"
var f2 = fso.OpenTextFile(s3+"\\add_js.js",1);
var source2 = f2.ReadAll();
f2.Close();
source2 = str_replace("\\", "\\\\", source2)
eval(source2);
var f = fso.OpenTextFile(file_path,1);
var source = f.ReadAll();
f.Close();
var already_boomarked = false;
var my_obj = JSON.parse(source, function (k, v) {
if (typeof v === "string" && k == "name" && v == name) {
already_boomarked = true;
return v;
if (add_dell == '1') {
if (!already_boomarked) {
var obj = {
date_added:time (),
id:"",
name:name,
type:"url",
url:url
my_obj.roots.bookmark_bar.children.push(obj);
var json_encoded = JSON.stringify(my_obj, function (key, value) {
return typeof value === "string" && key == "name" ?
string_encode(value) : value;
});
json_encoded = str_replace("\\\\u", "\\u", json_encoded);
var f = fso.OpenTextFile(file_path,2);
f.Write(json_encoded);
f.Close();
A google search of some those strings seems to point just to malware
reports (and not to any legitimate software). We have created a
signature that you can test over your dataset to check if it matches
your binaries:
Win.Downloader
In the mean time, we will enqueue the signature for FP test in our end.
Regards,
-- Xabier
On Mon, Jul 4, 2016 at 6:58 AM, Arnaud Jacques / SecuriteInfo.com
<webmaster at securiteinfo.com> wrote:
> Hello,
>
>> Thank you. This has been submitted for FP testing.
>
> Did it pass FP tests ?
>
> --
> Best regards,
>
> Arnaud Jacques
> SecuriteInfo.com
>
> Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
> Twitter : @SecuriteInfoCom
> _______________________________________________
> Community-sigs mailing list
> Community-sigs at lists.clamav.net
> http://lists.clamav.net/cgi-bin/mailman/listinfo/community-sigs
>
> http://www.clamav.net/contact.html#ml
More information about the Community-sigs
mailing list