CPS currently run Spearhead and COD 4 public Servers
Cornish Public Server - IP: 78.110.160.79:12203
[CPS] CoD4 Server - IP: 78.110.160.79:28960
-=BK=- Main Server - IP: 78.110.160.103:12204
Disconnected Server - IP: 78.110.160.79:12212
VENTRILLO IP 78.110.160.79 Port: 3784 
Select your theme
Go Back   CPS Forums > General Discussion > News

Collapse the side panel
» Online Users: 3
0 members and 3 guests
Members: No Members online
Online: Most users ever online was 169, 4 Weeks Ago at 04:04.
» Stats
Members: 210
Threads: 4,240
Posts: 21,884
Top Poster: Top Poster: Dai_Nasty (3,736)
Newest Member: Welcome to our newest member, Pointblank
» Today's Birthdays
None
 
 
LinkBack Article Tools Display Modes
Prev Previous Post   Next Post Next
Storm Worm readys for another attack
Published by Dai_Nasty
10-05-2008
Storm Worm readys for another attack

sudosecure.net Blog Archive Storm Worm Morphs to only serve exploits

Alrighty then let me get to some of the juicy stuff about this new campaign. We now have three active Storm Fast Flux domain names serving up obfusticated JavaScript via a PHP file titled "ind.php". The thing that completely threw me off yesterday was they are filtering the exploit with a User Agent check. If you try to grab the "ind.php" with a non exploitable browser or command you will receive a blank page. Here is a PDF of the current "ind.php" file and it's deobfusticated code: ind.php analysis. As you can see in the PDF you will be hit with multiple exploits and if any of them are successful you will be receiving the Storm Worm binary downloader from another PHP file titled: "load.php". Detection is very limited for this new variant downloader: VirusTotal Results for load.php. This downloader will then grab the file "load.exe" which is the actual Storm Worm binary and detection for this is low as well: VirusTotal Results for load.exe.
Article Tools

Featured Articles
 

Bookmarks

Tags
attack, readys, storm, worm


Currently Active Users Viewing This Article: 1 (0 members and 1 guests)
 
Article Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Article Article Starter Category Comments Last Post
Storm Data Private Parts General Chat 0 08-01-2008 20:40
Storm The Castle LAWMAN*GER*[CPS] General Chat 1 18-09-2007 18:50
Storm Worm of a thousand faces gothic News 0 22-08-2007 05:39
DoS Attack Feared As Storm Worm Siege Escalates gothic News 0 03-08-2007 05:47
Storm Worm Erupts Into Worst Virus Attack In 2 Years gothic News 0 25-07-2007 05:06


All times are GMT +1. The time now is 05:12.
© 2002 - 2009 Fairfield Designs
Article powered by GARS 2.1.9 ©2005-2006

Home | Forums | Archive | Contact Us | Top