BleepingComputer.com: Likely malicious html file - can someone take a look?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Likely malicious html file - can someone take a look?

#1 User is offline   Charlie Tounah 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 5
  • Joined: 21-October 10

Posted 04 June 2011 - 09:24 AM

Hi,

I'm a consultant, with a client that received an email with a suspicious link. I was able to download the html file from the redirected site without running it, and took a look at it in a text editor. It's obviously specially crafted, but it's beyond my ability to decipher. Could anyone interpret the file to figure out what the payload is supposed to be?

It's a 191K file, and I'm not sure how best to attach it. If someone could let me know, I'd appreciate it.

Thanks in advance,

Charlie T.

#2 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,425
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 04 June 2011 - 12:09 PM

You can upload it here. Please put it in a .zip archive first.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#3 User is offline   Charlie Tounah 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 5
  • Joined: 21-October 10

Posted 04 June 2011 - 03:37 PM

Hi, I just uploaded the file as requested.

Thanks,
Charlie T.

#4 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,425
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 04 June 2011 - 04:32 PM

It's a packed and obfuscated, and very common, fake malware scanner page. It emulates the appearance of Windows Explorer in Windows XP and claims to be scanning your computer while finding numerous infections (almost identical in every respect to this image.) It then prompts you to download and install and they purchase a rogue Antimalware tool.

If the page is on a server you control, then you need to immediately take action to remove these rogue pages and close whatever security hole may have allowed them in. If the page lives on an otherwise innocuous website then you should consider contacting the owner of the site and informing them that their site is hosting scam/malware pages.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#5 User is offline   Charlie Tounah 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 5
  • Joined: 21-October 10

Posted 04 June 2011 - 05:29 PM

Thanks for your help.

The curious thing is that this lady got this email with the malicious link, along with only a handful of other people she knows in the CC: list, and is pretty sure she knows who sent it. Could you tell if there is anything more specifically targeted than the rogue antivirus program? She is concerned about trojans, keyloggers, etc. I scanned her system with Combofix, MBAM, AVG's Virut remover, GMER and catchme, and everything's clean as far as I can tell.

Thanks again,
Charlie T.

#6 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,425
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 04 June 2011 - 05:58 PM

Nothing obvious.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users