ad: CQMM-1

Morse code used in phishing attack

Discussion in 'Amateur Radio News' started by N2RJ, Feb 9, 2021.

ad: L-HROutlet
ad: l-rl
ad: Radclub22-2
ad: L-MFJ
ad: abrind-2
ad: Left-3
ad: Left-2
  1. N0TZU

    N0TZU Platinum Subscriber Platinum Subscriber QRZ Page

  2. K0OKS

    K0OKS Ham Member QRZ Page

    It’s simple code obfuscation. Nothing really new other than that they happen use a Morse code encoder / decoder rather than as more complex code obfuscator.

    The goal is to hide malicious looking bits of JavaScript code from the anti virus software that is scanning it by changing the JavaScript code into something the anti virus cannot directly decipher.

    This has been done for decades with various forms of obfuscation.
     
    KI4POT likes this.
  3. AJ6KZ

    AJ6KZ Ham Member QRZ Page

    But mostly it's just cats.
     
    KA5RIO, N6SPP, KD7CFM and 1 other person like this.
  4. W3KCK

    W3KCK Ham Member QRZ Page

    It looks like the code is off by 1 character.
     
  5. SV1RUX

    SV1RUX XML Subscriber QRZ Page

    Beam me up, Scotty! This planet sucks . . . . .
     
    K2NED likes this.
  6. KI7Z

    KI7Z Ham Member QRZ Page

    I completely understand how this could happen. I am setting up a filter to look for CW in web/email pages. That should make this benign.
     
  7. KC8UD

    KC8UD Ham Member QRZ Page

    This should be easy enough for most virus scanning applications to incorporate into their defense routines. But in reality this type of code camouflage cold be accomplished with any string of characters and symbols that the malicious code author decides to put together. It wouldn't need to be Morse.
     
  8. K0NH

    K0NH Ham Member QRZ Page

    Better turn on your vpn!
     
  9. KE0PUQ

    KE0PUQ Ham Member QRZ Page

    I do not think a ham did it.
     
    AJ6KZ likes this.
  10. AG6QR

    AG6QR Premium Subscriber QRZ Page

    I finally looked at the code. They info they include in Morse is just hexadecimal strings. Meaning they only use the letters A through F and digits 0 through 9.

    They could have shortened their decoder routine by eliminating the codes for Morse letters G through Z, since they never use those letters.
     
    K6LPM and N0TZU like this.
  11. N3PZZ

    N3PZZ Ham Member QRZ Page

    D'oh!!!!!
     
  12. W1YW

    W1YW Ham Member QRZ Page

    [​IMG]
     
  13. N0TZU

    N0TZU Platinum Subscriber Platinum Subscriber QRZ Page

    They probably just cut and pasted it in toto from somewhere LOL.
     
    K0OKS and AG6QR like this.
  14. K0OKS

    K0OKS Ham Member QRZ Page

    I am pretty sure it was a script kiddie who just copied the code because they didn't know how to write a better obfuscator.
     
    WA7AXT and AG6QR like this.
  15. KI5AAI

    KI5AAI Ham Member QRZ Page

    Most people are script kitties these days.
     

Share This Page

ad: Halibut-1