Spearhead Server:
[CPS]Cornish Public Server
IP: 78.110.160.79 : 12203
Players: 0 / 12
Map: Stalingrad
CoD4 Server:
[CPS]Cornish MixMode HC
IP: 78.110.160.79 : 28960
Players: 0 / 12
Map: Bloc
 
Portal Register Arcade Page Members Search

CPS currently run Spearhead and COD 4 public Servers
Cornish Public Server - IP: 78.110.160.79:12203
[CPS] CoD4 Server - IP: 78.110.160.79:28960
-=BK=- Main Server - IP: 78.110.160.79:12211
[CPS] CoD4 FFA - IP: 78.110.160.79:28961
Go Back   CPS Forums > General Discussion > News

Menu

Onlineuser
View Who's Online Users: 2
Guests: 7
Total: 9
Team: 0
Users:  Private Parts, Spiritwalker

Portalsearch

Advanced Search

Statistic
Topics: 3919
Posts: 20630
Users: 309
Active Members: 30
We welcome our newest user: wraggy101
Most users ever online was 719, 3 Days Ago at 07:36.
New users:
22-10-2008
- wraggy101
15-09-2008
- oXyz
05-09-2008
- big dragon
24-08-2008
- gallagher
07-08-2008
- welly

Forum overview

 
 
LinkBack Article Tools Display Modes
Prev Previous Post   Next Post Next
Storm Worm readys for another attack
Published by Dai_Nasty
10-05-2008
Storm Worm readys for another attack

sudosecure.net Blog Archive Storm Worm Morphs to only serve exploits

Alrighty then let me get to some of the juicy stuff about this new campaign. We now have three active Storm Fast Flux domain names serving up obfusticated JavaScript via a PHP file titled "ind.php". The thing that completely threw me off yesterday was they are filtering the exploit with a User Agent check. If you try to grab the "ind.php" with a non exploitable browser or command you will receive a blank page. Here is a PDF of the current "ind.php" file and it's deobfusticated code: ind.php analysis. As you can see in the PDF you will be hit with multiple exploits and if any of them are successful you will be receiving the Storm Worm binary downloader from another PHP file titled: "load.php". Detection is very limited for this new variant downloader: VirusTotal Results for load.php. This downloader will then grab the file "load.exe" which is the actual Storm Worm binary and detection for this is low as well: VirusTotal Results for load.exe.
Article Tools

 

Bookmarks

Tags
attack, readys, storm, worm


Currently Active Users Viewing This Article: 1 (0 members and 1 guests)
 
Article Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Article Article Starter Category Comments Last Post
Storm Data Private Parts General Chat 0 08-01-2008 21:40
Storm The Castle LAWMAN*GER*[CPS] General Chat 1 18-09-2007 18:50
Storm Worm of a thousand faces gothic News 0 22-08-2007 05:39
DoS Attack Feared As Storm Worm Siege Escalates gothic News 0 03-08-2007 05:47
Storm Worm Erupts Into Worst Virus Attack In 2 Years gothic News 0 25-07-2007 05:06



All times are GMT +1. The time now is 23:02.
© 2002 - 2008 LC-Systems
Article powered by GARS 2.1.9 ©2005-2006