Author Topic: Malware I Got In An EMail Attachment  (Read 1071 times)

0 Members and 2 Guests are viewing this topic.

Offline ThePH30N1X

  • Peasant
  • *
  • Posts: 50
  • Cookies: 18
  • Java Programmer
    • View Profile
Malware I Got In An EMail Attachment
« on: June 16, 2014, 11:47:27 pm »
I got some malware in an attachment with some fake email from amazon. Thought you guys might want to mess around with it for fun or whatever. Be careful with this shit, I'm not responsible if you get fucked. Also, Yahoo's shitty Norton attachment scan reported it as a "Trojan.Smoaler". I found this document with some information about it: http://www.symantec.com/security_response/writeup.jsp?docid=2011-100515-1838-99

EDIT: Also attached the message lol.
« Last Edit: June 16, 2014, 11:51:33 pm by ThePH30N1X »

Offline Nero

  • /dev/null
  • *
  • Posts: 11
  • Cookies: -39
    • View Profile
Re: Malware I Got In An EMail Attachment
« Reply #1 on: June 17, 2014, 02:43:10 am »
I find this handy for script kiddies. I have no use for it however.
This is a Signature! Woot!

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: Malware I Got In An EMail Attachment
« Reply #2 on: June 17, 2014, 04:50:05 am »
It's a dropper with probably netcat or a metasploit backdoor
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline ThePH30N1X

  • Peasant
  • *
  • Posts: 50
  • Cookies: 18
  • Java Programmer
    • View Profile
Re: Malware I Got In An EMail Attachment
« Reply #3 on: June 17, 2014, 02:35:30 pm »
It's a dropper with probably netcat or a metasploit backdoor
That's what I found. Probably going to try to do some static analysis when I have time.

Offline InfosecFurry

  • /dev/null
  • *
  • Posts: 8
  • Cookies: 0
  • fuzzer.c
    • View Profile
Re: Malware I Got In An EMail Attachment
« Reply #4 on: June 17, 2014, 08:57:08 pm »
IIRC metasploit shells all have the same assembly signature (unless you write your own). So, it should be easy to determine. Will examine later tonight.
There are no pentesters in fox-holes

$trik3r

  • Guest
Re: Malware I Got In An EMail Attachment
« Reply #5 on: June 17, 2014, 09:06:52 pm »
have to be some script kiddies work ... lol!!! luckily we hacker's know how to deal with these types of threat 

Offline AnarchyAngel

  • Peasant
  • *
  • Posts: 50
  • Cookies: 1
  • mmmm beer
    • View Profile
Re: Malware I Got In An EMail Attachment
« Reply #6 on: June 18, 2014, 02:06:23 am »
what was in the headers? i have found fun info in them from time to time with emails like this.
https://dc414.org - MKE area DEFCON group