Author | Post | |||
unknown user |
There are a lot of peculiar things in this email message, that urged me to look into it a little bit more. The attached .scr does not appear to be a screen saver. the width of the lines from the base64 encoded file.scr seem strange. The atual body of the email doesn't contain characters < ascii 0x20 except for the newline character 0xa. The from address was special. [edit] removed the email message. [/edit] googling for substrings like lhUC‰zûÎâÖ¥¦ shows that there were other similar messages earlier. dating back two years. So i thought I'd ask you dear community to shed some light on what this was supposed to do. I'll probably do some further analysis myself too, though |
|||
13.10.2007 21:17:35 |
|
|||
moose |
is this still actuall? if not, please close this topic. if its actual, why did you remove the message? how should we know what it should exploit when we don't see the message? (to be honest, I'm sure I wouldn't know even if I saw the message) |
|||
13.10.2007 21:31:45 |
|
|||
unknown user |
you can google the string, i removed it due to the possible data leakage |
|||
13.10.2007 21:45:26 |
|