Xploit + Trojan?

RoboMan

Level 38
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
High Reputation
Forum Veteran
Jun 24, 2016
2,608
24,580
3,600
Hidden Village of Hispanic America
Got some nice e-mail today.

From: Dropbox. <mark.opdyke@pepsico.com>
Date: Wednesday, July 19, 2017
Subject: Pdf_file333 _invoice(2) Received
To: xxxx <xxxx>



Hi

You have Receieved An invoice uploaded via dropbox

Due to large size. Access Your Invoice Here

Thanks,

Dropbox!

Definitely scam. On an isolated browser i clicked the link, which drove me here:

Code:
hxxps://topdunet.fr/XTDDROPSERES/documentsharepdfEN/documentsharepdffile/index.html
u6lgI2y.jpg


Definitely scam. Looks like xploit method to get your credentials. I used fake ID and password and of course, it redirected me to the "download" as if my login authentication succeeded. The following download link was created.

Code:
hxxps://topdunet.fr/XTDDROPSERES/documentsharepdfEN/documentsharepdffile/google/phonever.html

Anybody has an active isolated enviroment as to test what kind of malware this is? I'm setting my VM soon when i have a decent internet connection u.u
 
Last edited:
Got some nice e-mail today.



Definitely scam. On an isolated browser i clicked the link, which drove me here:

Code:
hxxps://topdunet.fr/XTDDROPSERES/documentsharepdfEN/documentsharepdffile/index.html
u6lgI2y.jpg


Definitely scam. Looks like xploit method to get your credentials. I used fake ID and password and of course, it redirected me to the "download" as if my login authentication succeeded. The following download link was created.

Code:
hxxps://topdunet.fr/XTDDROPSERES/documentsharepdfEN/documentsharepdffile/google/phonever.html

Anybody has an active isolated enviroment as to test what kind of malware this is? I'm setting my VM soon when i have a decent internet connection u.u

Web content virus scan
Address: hxxp://topdunet.fr/XTDDROPSERES/documentsharepdfEN/documentsharepdffile/google/phonever.html
Virus: Script.Packed.Agent.F@susp (Engine B)
Status: Access denied.
Engines: Engine A: AVA 25.13458, Engine B: GD 25.10036
 
Web content virus scan
Address: hxxp://topdunet.fr/XTDDROPSERES/documentsharepdfEN/documentsharepdffile/google/phonever.html
Virus: Script.Packed.Agent.F@susp (Engine B)
Status: Access denied.
Engines: Engine A: AVA 25.13458, Engine B: GD 25.10036

Seems like ransomware to me
 
  • Like
Reactions: SHvFl
Blacklisting a webpage (URL) is not the same as scanning and blacklisting the webpage content.
Yeah true that. I used VT in order to see if the antivirus scanners detected the download link as a malicious link. Not the actual payload.
 
  • Like
Reactions: SHvFl
Seems like ransomware to me

Probably not. Just suspicious webpage script.

Look here at signatures assigned to support webpage hjacks or "ransom" pages:

  • Exploit.SWF_c.CAL
  • SWF/Trojan.YWCL-5
  • Exploit:SWF/Netis
  • JS.Redirector.F
  • Trojan.HTML.k
  • Script.Packed.Agent.F@susp
  • Ransom:JS/FakeBsod.A
  • Uds.Dangerousobject.Multi!c
ransom does not mean ransomeware.
 
  • Like
Reactions: SHvFl and RoboMan
Probably not. Just suspicious webpage script.

Look here at signatures assigned to support webpage hjacks or "ransom" pages:

  • Exploit.SWF_c.CAL
  • SWF/Trojan.YWCL-5
  • Exploit:SWF/Netis
  • JS.Redirector.F
  • Trojan.HTML.k
  • Script.Packed.Agent.F@susp
  • Ransom:JS/FakeBsod.A
  • Uds.Dangerousobject.Multi!c
ransom does not mean ransomeware.
Thanks for the share. I wish i had my VM set up...
 
Last edited by a moderator:
  • Like
Reactions: SHvFl
Yeah true that. I used VT in order to see if the antivirus scanners detected the download link as a malicious link. Not the actual payload.

Not the payload, the actual webpage content loaded into the browser. I guess you can call that a payload of a sort. Using the terminology payload is not always the technically most accurate. Lots of people have different definition of what constitutes a payload.
 
  • Like
Reactions: SHvFl
I have so many of these in my spam folder. If i was actually getting so many amazon, fedex and google messages i would be both rich and popular.
 
  • Like
Reactions: RoboMan and frogboy

You may also like...