-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gabriele said:
Hi all,
I received one of these infamous "you received a greeting card" mails,
and this time, the body is empty.
Below the HTML sectino (y<es, *below*) is a snippet of Java code, which
is probably designed to exploit the Java loopholes which have already
been mentioned here.
What I'd like to know, is how to deciver the gibberish - it is
deliberately encrypted, to hide what it is about to do. Is there any
tool or site, that will decrypt and display the content? The URL where
the malign code is to be downloaded from, must be hidden in the
encrypted text...
I don't suppose it pretended to come from (e-mail address removed)? If so I've had
one recently. I opened it in Outlook Express set up in "Internet Zone",
rather than the default "Restricted Zone" using Virtual PC. Don't do this
on your computer, whoever may read this
It downloaded a rootkit keylogger which NOD32 detected and chewed up. (Once
NOD32 was turned off) It did a rather crap job of rootkitting though
because "type" worked on one of the files, and the filing-system stealthing
hid so many files from view it was obvious something was amiss, before
running RootkitRevealer. As usual it hooked into winlogon and set itself to
run in safe mode.
Virus Total
_______________________________________________
Scan results
File: file.exe
Date: 02/10/2006 11:14:19 (CET)
- ----
AntiVir 6.33.0.81/20060210 found nothing
Avast 4.6.695.0/20060209 found nothing
AVG 718/20060210 found nothing
Avira 6.33.0.81/20060210 found nothing
BitDefender 7.2/20060210 found [BehavesLike:Trojan.WinlogonHook]
CAT-QuickHeal 8.00/20060210 found [(Suspicious) - DNAScan]
ClamAV devel-20060126/20060209 found nothing
DrWeb 4.33/20060210 found nothing
eTrust-InoculateIT 23.71.72/20060209 found [Win32/Haxdoor.Variant!Trojan]
eTrust-Vet 12.4.2074/20060210 found [Win32/Haxdoor!generic]
Ewido 3.5/20060210 found [Backdoor.Haxdoor.gh]
Fortinet 2.54.0.0/20060210 found [suspicious]
F-Prot 3.16c/20060209 found nothing
Ikarus 0.2.59.0/20060209 found [Backdoor.Win32.Haxdoor.GH]
Kaspersky 4.0.2.24/20060210 found [Backdoor.Win32.Haxdoor.gh]
McAfee 4693/20060209 found nothing
NOD32v2 1.1402/20060209 found [a variant of Win32/Haxdoor]
Norman 5.70.10/20060209 found [W32/Haxdoor.SA]
Panda 9.0.0.4/20060209 found nothing
Sophos 4.02.0/20060210 found [Troj/Haxdor-Gen]
Symantec 8.0/20060210 found nothing
TheHacker 5.9.4.094/20060210 found nothing
UNA 1.83/20060209 found [Backdoor.Haxdoor]
VBA32 3.10.5/20060209 found [suspected of Trojan-Downloader.Agent.84]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (MingW32)
iD8DBQFD7Ld37uRVdtPsXDkRAitwAJ4wuHPqoPtpd/Oa6g7Si8j6eP8YXgCeIyNw
yWlhiORSxr4acRQpH3cyD4Q=
=pYWu
-----END PGP SIGNATURE-----