A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20050  by rkhunter
 Thu Jul 11, 2013 6:54 pm
has been patched in latest patch tuesday and IE 8-9-10 marked as vulnerable https://technet.microsoft.com/ru-ru/sec ... n/ms13-055

now observed itw
http://blogs.technet.com/b/srd/archive/ ... -long.aspx
Attachments
pass:infected
(5.89 KiB) Downloaded 70 times
pass:infected
(12.26 KiB) Downloaded 73 times
 #20056  by sierra
 Thu Jul 11, 2013 11:18 pm
Hi, thanks for your sharing.
e2fe34c58765b4f6e41e4b096203d04a turns to be the clean one, without packed by doswf.
Does anyone have the html loader, 2nd stage html?