Showing posts with label javascript. Show all posts
Showing posts with label javascript. Show all posts

Sunday, May 15, 2016

***SPAM*** Invoice #34069680 [Malware]

Iam always more interested in SPAM emails rather than my Inbox. Today, I stumbled upon an email in my Spam box with subject Invoice #34069680. It had a spam-my named attachment along with it saying they have sent some of my shipment lol! and this is the invoice to the same.

I then de-activated my Anti-Virus software, downloaded the zip archive, extracted & it had a lonely file in it named invoice_copy_Bqa6Ci.js. It was in fact, no invoice document but a JavaScript file with following contents.

It seemed like it was obfuscated, so I went in to dig the thing deeper and de-obsfuscate it line-to-line by hand. The result I got is as below:

This clearly shows what it does. It downloads a file from either http://wherareyoufromff.com/25.exe or http://arendroukysdqq.com/25.exe (most probably the second URL is there as a fallback in case the first one fails), and saves it as 4194304.exe in your %TEMP% folder, and finally executes it upon successful download. Thenafter, you cannot tell how much the unknown executable saved in your %TEMP% folder will be able to exploit your system.

So beware! If you receive any email similar or exactly as this one, make sure don't download anything there in it.

Sunday, November 1, 2015

eToolkit - Open-source Client-side Password Generation, Hash & More

eToolkit is an online toolkit to perform common confidential tasks I use to do on a regular basis including Generating Random Passwords, Base64 decoding & encoding, Text Hashing using MD5/SHA-1/SHA-224/SHA-256/SHA-512 algorithms, Character Counting and things.
I admit there are various tools available online for the purpose and undoubtedly I have been using them. Even more, major functions of eToolkit are inspired if not powered by them. But I did not like the idea of submitting confidential content to a website or application which is not open for review.
For most random websites those they appear in google search, following concerns arise in my mind whenever I am using their services:
  • The password I am generating might be stored on their server
  • The text I am hashing might be saved in rainbow tables for reverse-lookups
  • I do not want to reload a page just to Base64 encode or decode a word. That feels creepy
For addressing all those concerns and try to solve the most, I made this tiny-little angular powered web-app that does all of those in your browser (doesn't send a thing to server) and open-sourced it here on Github because this how things I wanted these tools to be. Open!
To become useful, eToolkit is grateful to below open-source projects which power it: