My website database was hacked via sql injection (yes I know).
Injected js code pointing at: <link removed. See attachment>
The sample file is one of the subsequent downloaded files from this page.
This a class of attack that virus scanners seem unable to detect because of the obsfucation of the com clsid's. This code can probably be randomised/obsfucated in thousands of different ways making it hard to use signature based detection.
Perhaps the av scanners should incorporate a runtime scanner, which can interpret js and vbscript code, this would stop any virus/dropper/downloaders which use this technique, which is so simple its not funny.
I've attached the ****** files which were undetected, but definitely are malicious. Password is infected.
Thanks
/applications/core/interface/file/attachment.php?id=1993" data-fileid="1993" rel="">killwow.zip
/applications/core/interface/file/attachment.php?id=1995" data-fileid="1995" rel="">js_link.txt