Scripts in ASF files
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 




Scripts in ASF filesExpand / Collapse
Author
Message
Posted 4/30/2008 7:27 AM


Forum Moderator

Forum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum Moderator

Group: Moderators
Last Login: 8/8/2008 6:28 AM
Posts: 2,777, Visits: 7,025
Recently one of our readers, Doug, sent us an ASF file that does something interesting: when you open it in Windows Media Player, it will immediately launch Internet Explorer which will then prompt you to download an executable file.

As I don't see this every day, I went to investigate this a bit further. According to Microsoft, the ASF file format (and possibly other formats) allows creation of a script stream. The script stream can use certain, simple, script commands in Windows Media Player. This information is available at http://msdn2.microsoft.com/en-us/library/aa390699(VS.85).aspx

Now, the malicious ASF file we received opened Internet Explorer with the URL pointing to hxxp://www. fastmp3player.com/affiliates/772465/1/?embedded=false. This web site had a further 302 redirect to hxxp://www. fastmp3player.com/affiliates/772465/1/PLAY_MP3.exe (both links are still working), which is some adware and is reasonably detected by 20 out of 32 AV programs on VirusTotal...

isc.sans.org


__________________________________________

"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"





Microsoft MVP - Windows Security
Post #238731
« Prev Topic | Next Topic »


Reading This TopicExpand / Collapse

All times are GMT -6:00, Time now is 8:13pm

Powered By InstantForum.NET v4.1.4 © 2008
Execution: 0.047. 10 queries. Compression Enabled.