DragonFly BSD
DragonFly kernel List (threaded) for 2004-08
[Date Prev][Date Next]  [Thread Prev][Thread Next]  [Date Index][Thread Index]

Re: b0x.com link


From: Wouter Clarie <rimshot@xxxxxxxxxx>
Date: Tue, 10 Aug 2004 23:13:49 +0200 (CEST)

On Tue, 10 Aug 2004, cmulcahy@xxxxxxxxx wrote:

> prompts the execution of a script, wgotten and renamed b0x.js (attached)
> which performs browser detection, and in the case of Netscape 5+ prompts
> for the download and install of sbc_netscape.xpi (also attached ;; DO
> NOT EXECUTE) which if interrogated with zip or jar is revealed to be an
> install script and a windows executable ( which is so resistant to
> 'strings' as to appear intentionally encrypted or obfuscated ).

McAfee detects the executable as 'Keylog-Briss'.

Wouter



[Date Prev][Date Next]  [Thread Prev][Thread Next]  [Date Index][Thread Index]