Server:
[CPS]Cornish Public Server
IP: 78.110.160.79 : 12203
Players: 0 / 10
Map: Stalingrad
Server:
[CPS]Cornish MixMode HC
IP: 78.110.160.79 : 28960
Players: 0 / 12
Map: Crossfire
 
Portal Register Arcade Page Members Members List Search PC Help

CPS currently run Spearhead and COD 4 public Servers
Cornish Public Server - IP: 78.110.160.79:12203
[CPS] CoD4 Server - IP: 78.110.160.79:28960
-=BK=- Main Server - IP: 78.110.160.79:12211
[CPS] CoD4 FFA - IP: 78.110.160.79:28961
Go Back   CPS Forums > General Discussion > News

» Online: 7
1 members and 6 guests
View Who's Online Users: 1
Guests: 6
Total: 7
Members:  Angelheart
» Donations
We are in need of your help. If you like this site, and enjoy playing on our Game-Servers we really could do with some help to cover the ongoing cost. We are currently expanding the website, introducing exciting new features, but these are not free. Your support is always appreciated.

£

Select your donation amount
and press the "Donate Button".

» PC Help Latest Posts
Latest Active Threads
» Stats
Threads: 3816
Posts: 20949
Members: 302
Active Members: 86
Our Newest Member:JTankers
Users Most users ever online was 60, 10-06-2008 at 10:48.
 
 
LinkBack Article Tools Display Modes
Prev Previous Post   Next Post Next
Storm Worm readys for another attack
Storm Worm readys for another attack
Published by Dai_Nasty
10-05-2008
Storm Worm readys for another attack

sudosecure.net Blog Archive Storm Worm Morphs to only serve exploits

Alrighty then let me get to some of the juicy stuff about this new campaign. We now have three active Storm Fast Flux domain names serving up obfusticated JavaScript via a PHP file titled "ind.php". The thing that completely threw me off yesterday was they are filtering the exploit with a User Agent check. If you try to grab the "ind.php" with a non exploitable browser or command you will receive a blank page. Here is a PDF of the current "ind.php" file and it's deobfusticated code: ind.php analysis. As you can see in the PDF you will be hit with multiple exploits and if any of them are successful you will be receiving the Storm Worm binary downloader from another PHP file titled: "load.php". Detection is very limited for this new variant downloader: VirusTotal Results for load.php. This downloader will then grab the file "load.exe" which is the actual Storm Worm binary and detection for this is low as well: VirusTotal Results for load.exe.
Article Tools

Featured Articles
 

Bookmarks


Currently Active Users Viewing This Article: 1 (0 members and 1 guests)
 
Article Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Article Article Starter Category Comments Last Post
Storm Data Private Parts General Chat 0 08-01-2008 20:40
Storm The Castle LAWMAN*GER*[CPS] General Chat 1 18-09-2007 18:50
Storm Worm of a thousand faces gothic News 0 22-08-2007 05:39
DoS Attack Feared As Storm Worm Siege Escalates gothic News 0 03-08-2007 05:47
Storm Worm Erupts Into Worst Virus Attack In 2 Years gothic News 0 25-07-2007 05:06


All times are GMT +1. The time now is 10:11.
© 2002 - 2008 LC-Systems
Article powered by GARS 2.1.8m ©2005-2006