Talk About Network

Google


Register and Login
Nick
Password
Register create new account Sign up is FREE and you can post replies, new topics, bookmark posts and more!
Recover lost password


Businesses > Domain Name - Disputes > Re: President B...
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 1 of 1 Topic 134 of 223
Post > Topic >>

Re: President Bush Assasinated: backdoor trojan, W32/Backdoor.LU.

by Spamless <Spamless@[EMAIL PROTECTED] > Jan 7, 2005 at 02:44 AM

On 2005-01-06, andrewsmith@[EMAIL PROTECTED]
 <andrewsmith@[EMAIL PROTECTED]
> wrote:
> Assasination of President Bush
>
> Today two CNN re****ters ...

TROJAN LOADER in http://mendel.
                        home.
                        comcast .net
              (HTML help exploit)

TROJAN in http://mitchell.
                 home.
                 comcast .net
       (backdoor trojan, W32/Backdoor.LU)

=============================

Well, remember paddy.home.comcast.net and the spam for:
"Santa Claus as you have never seen him!"

This is precisely the same (except for the obfuscation
of the location of the trojan which is actually installed).

What we have here is:

  15 lines of nothing much.
 213 blank lines
 an HTML help exploit.

(short version)
---------------
This exploit uses hhctrl.ocx to write out a file
"MicrosoftOffice.hta" to your startup group.

That runs when next you reboot the computer and
contains VBScript to get the file
 http://mitchell.home.comcast.net/xp.exe
and save as "OfficeOSA.exe" in your startup group.
(18976 bytes in size)

On the next boot this runs.

F-prot flags it as the backdoor trojan W32/Backdoor.LU.

So if you have an 18976 byte file named OfficeOSA.exe
in your startup group, do NOT reboot until you move
it elsewhere so you can check it - or delete it.
The same goes for a file named MicrosoftOffice.hta
in your startup group.

(long version)
-------------
Posted to nanas (news.admin.net-abuse.sightings)
6 January 2005
Subject: [usenet] TROJAN (W32/Backdoor.LU): President Bush Assasinated
>From: spamless@[EMAIL PROTECTED]

 




 1 Posts in Topic:
Re: President Bush Assasinated: backdoor trojan, W32/Backdoor.LU
Spamless <Spamless@[EM  2005-01-07 02:44:47 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
tan12V112 Sat Oct 11 16:56:47 CDT 2008.