View Single Post
Old 11 December 2011, 11:37 PM   #14
dsio
"TRF" Member
 
dsio's Avatar
 
Join Date: Jun 2010
Real Name: Ashley
Location: Brisbane
Watch: Rolex Sub 1680 '79
Posts: 2,301
Quote:
Originally Posted by 2careless View Post
Ashley, did firefox execute the payload?
Mine did download it but the payload didn't run.
Yea, it actually did, then crashed firefox (if you check the screenshot you can see firefox no longer responding). I didn't have FF installed so I just pulled it down, current version, no settings changed, ignored the warning, and it ran first go. IE7/8 in WinXP / Vista VMs did the same, didn't try anything else. It didn't get as far as connecting out or doing anything on OSX, just ran then crashed firefox, but the Windows VMs it had no problem, and you could see it establishing external connections. Most likely it only ran on a mac at all by virtue of it happening to be a .jar and being able to create a JVM process but you would imagine it was intended for windows.
__________________
-- Omega Seamaster Grand-Lux Stepped Pie-Pan 14K Gold OJ2627 '53 --
-- Omega Cal 320 Chronograph 18K Gold OT2872 '58 --
-- Omega Cal 321 Speedmaster Pro 145.012 '67 --
-- Rolex Submariner 1680 "Ghost" '79 --
-- Rolex SS Daytona 116520 '04 --
dsio is offline   Reply With Quote