Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Yet another trojan?

 
Thread Tools Search this Thread
Old 10-03-2004, 05:48 PM   #1
Default Yet another trojan?


I've seen a number of messages looking like this, they just get
deleted, but what exactly are they ? Is this another attempt
to execute code on MS Outluck?

--------------------

- Home directory: The location of the home directory varies by
platform.
Windows 98 (single-user): C:\Windows
Windows 98 (multi-user): C:\Windows\Profiles
Windows 2000/XP: C:\Documents and Settings




-----BEGIN BLOCK-----
F%D5%CDU%C2%058%E5%9A%D5%7D%85
JJ%E3%DF%D7o%C1%1F%60%EA%F0%B2

etc ...
--
Jim Watt
http://www.gibnet.com


Jim Watt
  Reply With Quote
Old 10-03-2004, 11:57 PM   #2
Ant
 
Posts: n/a
Default Re: Yet another trojan?
"Jim Watt" wrote...
> I've seen a number of messages looking like this,


So have I - since about the end of August.

> they just get deleted, but what exactly are they ?


Just spammer nonsense, I think.

> Is this another attempt to execute code on MS Outluck?


The block displays as plain text. I can't make sense of it as
executable code after escaping.

I've seen examples of spam containing these blocks, which also contain
an encoded javascript. This is the real exploit. It contains an iframe
with a URL to a site hosting a trojan. The idea is that this gets
silently downloaded and installed if you're unlucky enough to preview
or open it with OE.

Easy enough to avoid with the proper security settings. OE should be
in the restricted zone, which should of course have scripting disabled.

> - Home directory: The location of the home directory varies by
> platform.
> Windows 98 (single-user): C:\Windows
> Windows 98 (multi-user): C:\Windows\Profiles
> Windows 2000/XP: C:\Documents and Settings
>
> -----BEGIN BLOCK-----
> F%D5%CDU%C2%058%E5%9A%D5%7D%85
> JJ%E3%DF%D7o%C1%1F%60%EA%F0%B2
>
> etc ...





Ant
  Reply With Quote
Old 10-04-2004, 12:14 AM   #3
Mark3324
 
Posts: n/a
Default Re: Yet another trojan?
Googling the first line or first two lines gets quite a few hits. For
example: http://www.dslreports.com/forum/rema...t=-1~mode=flat


On Sun, 3 Oct 2004 12:48:48 -0400, Jim Watt wrote
(in article <>):

> I've seen a number of messages looking like this, they just get
> deleted, but what exactly are they ? Is this another attempt
> to execute code on MS Outluck?
>[snipped]




Mark3324
  Reply With Quote
Old 10-04-2004, 02:34 AM   #4
Ant
 
Posts: n/a
Default Re: Yet another trojan?
"Mark3324" wrote...
> Googling the first line or first two lines gets quite a few hits. For
> example: http://www.dslreports.com/forum/rema...t=-1~mode=flat


There's an example on that page of the "JScript.Encode" obfuscated
scripting I mentioned.




Ant
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan zlob? Please help! whackamole General Help Related Topics 4 10-16-2008 09:23 PM
eBay Users Targeted By Advanced Trojan ufo DVD Video 2 03-07-2007 04:13 AM
Removing Trojan Richard A+ Certification 1 01-04-2006 04:01 PM
Help with Trojan Breedo A+ Certification 1 03-25-2005 05:05 AM
Re: Monitor problem after infection of a Trojan Horse! Tom MacIntyre A+ Certification 0 07-19-2003 02:40 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46