«   2025/05   »
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Tags
more
Archives
Today
Total
관리 메뉴

www.ManiaLab.com

[Analysis] some suspicious files 본문

1.Sec_Vulnerability

[Analysis] some suspicious files

HaiDong 2010. 9. 17. 11:05

# Analysis Encoded Script, HaiDong, 100917

// script.js

Suspicious URL is encoded by URL Encoding method, The result of decode is like below..


// www.openovation.co.kr/images/xxx.jpg

This use ms10-018
So, decode the payload > you will see hxxp://www.ticket365.co.kr/filedata/xxx/xxx.exe


k.exe is Win-Trojan/Agent in V3


thanks

Comments