lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.BSO.4.58.0312251611190.20271@mail.klake.org>
From: jt at klake.org (Jarkko Turkulainen)
Subject: Sears Scam Trojan Code

> being a programmer, I was simply wondering what the content of page.hta
> actually does.  I've attached the file as page.txt for anyone who wishes
> to find out; perhaps the results will be interesting.  Page.hta can be
> found at  http://radnorthgm.com/special/.

The HTA file contains a binary program that seems to be a some sort loader
program. As a first impression, it tries to download something from
cjdra.com via HTTP and run it.


Regards,

--
Jarkko Turkulainen <jt@...ke.org>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ