lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
From: maxime at (Maxime Ducharme)
Subject: Malicious Javascript from "Hack Peoples Passwords" spam

Hi all,
    I received a spam pinting on a link which contains suspicious

The code seems protected with some kind of "script encoder",
I'd like to know which tool it is or any other similar.

I started decoding the script and I put the fils here :

The spam source is in "Hack Peoples Passwords ..." txt file.

The first loaded file is

which I saved under "index_1.dat"in my site.
index_2.dat have a part of script decoded.
index_3.dat is a little further.

index_3_unsp.dat contains what is outputted by the first script.

I found that this script loads via an hidden frame this other URL :

which contains similar script, but pops up this other URL instead :

I'm now at this step (did had time to got further yet), but there are
some parts of the scripts which I could not decode. These parts
do not seem to be used like (in index_3.dat) :
      var vm66=6743;

these lines seems to be added only to make the script bigger
and harder to read, but I'm not sure.

Someone with more experience may find something else ?

Thanks for replies

  Maxime Ducharme
  Administrateur reseau, Programmeur

Powered by blists - more mailing lists