Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: new WIN virus?

Re: new WIN virus?

From: <markus-1977_at_gmx.net>
Date: Thu, 29 Jan 2004 23:00:20 +0100 (MET)

Hi,
Seems that the webpage uses several known (unfixed) exploits in IE, i.e. it
spoofes the URL in the adress-bar and overwrites Mediaplayer with an
executable (updatte.exe). I took a quick look at the executable. It seems to be some
sort of 900#-dialer. I couldn't find out a lot since all my disassembly tools
don't like the stuff that my unpacker produced (the executable uses an
exe-packer called FSG), but from the API that's imported (some RAS stuff) my best
guess right now is that it is yet-another-dialer. Strings in the unpacked
executable seem to be encrypted for the most part. If this spam was meant to be
for the German "market", the spamers forgot to register their dialer with the
RegTP/government, so no lead there...

Markus

-- 
The early bird gets the worm. If you want
something else for breakfast, get up later.
+++ GMX - die erste Adresse für Mail, Message, More +++
Bis 31.1.: TopMail + Digicam für nur 29 EUR http://www.gmx.net/topmail
Received on Feb 03 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos