Jump to content
[[Template core/front/custom/_customHeader is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]

just a heads up on...


Robash
 Share

Recommended Posts

not that any of you are dumb enough to actually click the link... :wacko:

 

http://groups.google.com/group/alt.comp.vi...14dc75b942e64bc

 

 

alt.comp.virus

 

"Gabriele Neukam" wrote:

> Don't follow anything that leads to

> hxxp://algalibon.net/new/blocks/Barack-Obama-Incident.html

 

 

Well, naturally I did. It redirects to ibn3.com/daleel/img/index.php

which then redirects to the actual content page at the same host. It

appears to be a blog type thingy provided by searchwarp.com.

 

 

> It can't be anything else but a page with trojan waiting to jumpon

> your machine.

 

 

Absolutely. The page contains an invisible iframe (possibly not put

there by the author) to trustsellers.co.cr/stat-xr.php. It redirects

to sutgon.info/in.cgi?4 which then redirects back to

trustsellers.co.cr/stat/index.php.

 

That contains a heap of obfuscated Javascript and shellcode to exploit

vulnerabilities in ActiveX components and Acrobat reader.

 

 

WebViewFolderIcon

createControlRange

SetFormatLikeSample

DirectAnimation.PathControl

PrintSnapshot

XML

PDF

 

 

If one of those works it will download and install a BHO with class ID

{00009E9F-DDD7-AA59-AA7D-AA4B7D6BE000} named mscorews.dll. Except it

doesn't. The installer is broken and, while it sets the appropriate

registry entries, fails to create the dll in [win]\system32.

 

 

A few AV products detect it as a bank password stealer.

Link to comment
Share on other sites

OK I havn't been a proponent of this being a paid members forum but I am now. Just so you know'd it, I didn't shooted the Sheriff.

 

....but, did you shooted the deputy ?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information