5 ms·
Source code of the worm: https://hastebin.com/gubegaqusi.xml https://hastebin.com/gubegaqusi.xml Pretty much what you'd expect. Edit: This isn't the full sour
by sudom82 9y ago
Source code of the worm: https://hastebin.com/gubegaqusi.xml https://hastebin.com/gubegaqusi.xml
Pretty much what you'd expect.
Edit: This isn't the full source code. There was another PHP file visible on their website that unfortunately isn't visible anymore.
- mintplant 9y agoHeh, they're using Google Analytics to track its spread. That's a nice touch.
- taf2 9y agoIt's possible to send any data we want to their Analytics tracker... perhaps we send them some spam?
- soared 9y agoWhere is ilovevitaly when you need him?!
- smacktoward 9y ago"No fair! You got your privacy invasion in my privacy invasion!"
- emersonrsantos 9y agoThat made my day.
- ben174 9y agoSending everything to this mailinator address which oddly seems to be empty: https://www.mailinator.com/inbox2.jsp?public_to=hhhhhhhhhhhh.. https://www.mailinator.com/inbox2.jsp?public_to=hhhhhhhhhhhh.... Maybe Mailinator has purged the box and is rejecting mail from it. Good on them.
- sudom82 9y agoMailinator purged it early on yeah.
- eli 9y agoMan, I wonder how wider this would have spread if they spent a teensy bit more time to make e.g. the To address less suspicious.
- andrewflnr 9y agoOn a brief skim, it doesn't seem to do much besides spread itself. Am I missing something, or was it just for lulz? Or maybe a grey hat trying to prove a point?
- smudgymcscmudge 9y agoThat's all this code does, but The author then has a backdoor to all the victim's email through the oauth app.
- kardos 9y agoExcept that Google can kill those auths.
- evan_ 9y agoIt's really a question of how malicious the author was- if they set it up to download everything attached to the account as soon as it connected, it could still cause a lot of damage.
- shmed 9y agoEven worst: The hacker could have taken a list of lets say the top 1000 banking (or any type of online service) websites accross the globe. The moment the hacker get access to your gmail account, he initiatite a password recovery request on each of those 1000 websites, get the password reset link from the email, reset the password, delete the email. he could now have access to any other online account you have that had its recovery email set to your gmail account.
- nol13 9y agoSafe to assume that google could track such activity for affected accounts and notify if that was widespread? (or is that somehow against the 'only our anonymized ad display program can scan your email' privacy policy?)
- BadassFractal 9y agoWhat context was that code expected to be executed in?