Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: New auto download / install / exploit URL? |
|---|---|
| Date: | Wed, 27 Apr 2005 21:35:57 +0200 |
joke0 wrote:
In-Reply-To: <BE8F2DE1.1B07C%gandalf@digital.net> Hi, Gandalf The White:Someone want to take the time to decode?Not so easy, but done. The decrypted result of this hta leads to an intermediate javascript code (not provided here). Once this one is decrypted too, we get the HTA, pasted below. Explanations on what the code does are welcome ;-)
Hi, it installs a browser helper object that loads this psde.exe file from the russian server, right? Unfortunately, the file isn´t available yet (because the domain isn´t connected), has anyone this file? Is it a known trojan horse? Hermann
hermi.vcf
Description: Vcard
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [VulnWatch] High risk flaw in HP OpenView Radia Management Agent, NGSSoftware Insight Security Research |
|---|---|
| Next by Date: | Security contact at sourceforge?, Joxean Koret |
| Previous by Thread: | Re: New auto download / install / exploit URL?, joke0 |
| Next by Thread: | Re: New auto download / install / exploit URL?, Nicob |
| Indexes: | [Date] [Thread] [Top] [All Lists] |