Anyone got his computer screwed already ???


An HTA executes without the constraints of the internet browser security model; in fact, it executes as a "fully trusted" application.

An HTA is treated like any executable file with extension .exe. When executed via mshta.exe (or the file icon is double-clicked), it runs immediately. When executed via the browser, the user is asked once, before the HTA is downloaded, whether or not to save or run the application; if saved, it can simply be run on demand after that.

>implying anyone is stupid enough to download shit and run it as html applications

You greatly overestimate internet users

>people on fucking /sci/, of all goddamn places, getting raped by this sort of bullshit

Where the fuck did you people leave your fucking logic.
Don't run shit you see on 4chan, you fucking cunts.
You goddamn deserve this shit.

Pic somewhat related

1. Go on 4chan
2. Someone tells you to do something with your computer that you do not even slightly understand (AND uses the words "Shit bricks")
3. Sounds legit, do it.

Anyone who follows that pattern deserves to get their PCs CRUSHED, not used as a botnet.

"It's copying old posts and the pictures in them, adding the code to the pic and then reposts the result in random threads."


>Anyone who follows that pattern deserves to get their skulls CRUSHED.

>Developed by Microsoft
fucking microsoft

Everybody is retarded.

Are we getting haxed?

A matter of minutes until this post is copied and guarantees some funnies

>implying it is not a troll on the pic

can your shit copy goddamn trips, nigger?

That is, unless it just ignores the trip.

What the fuck? That vulnerability... it just sounds so fucking easy to "hack" into anyone's computer.

You can't fucking be serious...

The possibilities are endless with that shit. I am so abusing it from now on to fuck around with friends.

I modified the script.

Basically it causes the script to post something that will get the user who used the script banned.

Here's the pastebin:


Do what you want with it.

Fuck you, I hate you.

>mfw you don't even remotely know how it works

That's more social engineering than hacking. It's not an exploit or bug, it's getting the user to do something stupid.

Check out this shit bros.

Pic related: Check it out.

Somebody explain how this virus works/what it does, my curiosity has been piqued.

And by how it works, I mean how it attacks your system. I obviously know how it gets on to the computer thanks to OPs post

If you fell for this then you deserve it. Fucking retard.

anyone else notice that nearly all these idiots that executed the file are foreign (not english/murican)?

>> No.1447737


hta files run with full access to your system, so they can do whatever the fuck they want.

This downloads a random image from 4chan, downloads an image converter, uses the converter to add the instruction tag to the top left of the image, inserts itself into the image so it can be run again, then it the steals a random file from your documents folder and embeds it in the image before re-uploading it to a random board on 4chan.

All I can say after seeing the kinds of documents this worm carries along, is that most of the people that get infected are subhuman trash.

Also, it takes random documents?

Does that mean that one of them COULD contain shit like passwords and shit?

youre an idiot for falling for it

- It chooses a random board
- It chooses a random thread from that board
- It chooses a random post+image from that thread
- It downloads the text and image of that post
- It downloads a graphic editing program to your PC
- It uses the program to add the HTA text to the downloaded image
- It adds the 'virus' code to the image's code
- It randomly switches a few letters in the text to make it 'unique'.
- It posts the image+text on the same board it was taken from, in a random thread. This is why the image and text often seem relevant to the board it's posted on.
It's actually pretty clever.

ahahaha that's golden.

shit son. when i was a kid i'd get like 2 games and some socks max for xmas. back when it was £40 for a snes game.

It could be anything from the documents folder.
I've found way too many fanfics. Way too many oh god.

God dammit /sci/, you are the most infected board I bother to visit.

You're incredibly wrong.
I frequent about 4 boards and /sci/ is no worse, it's just slower, making the infected threads stay nearer the front page for longer.

I bet it can copy trips.

Nah, it's dump as fuck
For example, the image being uploaded contains both the original image (part4 in the source) and the modified ("Save as...") image (part2 in the source).

Padding is added to make things unique, but the padding is all in one bit and is way too large - There's no point in adding several kilobytes of random alphanumericals (it is limited to those), for detection purposes that just makes it easier.

Also, even though the unmodified image is still included in the upload, if an infected image is chosen the entire infected image is re-infected. This recursive process makes the image grow in size in a linear fashion.

Combined with the multi-kilobyte padding, the images quickly reach the 3072KB size limit, causing the upload to fail.

As the thing cannot detect if the downloaded carrier image is already infected (even though this would be trivial to do), it will not only hit the size limit but in time the flood of infected images will mean that few new images are infected. The result is that the vast majority of images on the board are multi-infected images close to the size limit.
This means that the ratio of infectable images gets lower and lower, until it reaches approximately zero.

tl;dr: The "worm" actually dies out / kills itself due to incompetence on part of the author.

The worm chooses the board to post on completely at random. Slow boards look like they're hit hardest because there are fewer real posts per worm post.


It's entirely possible to capture your trip from your cookies, but this worm is really dumb and doesn't do anything like that.

man its actually kind of tempting

why is this

Also, further analysis suggests that an (not yet identified) bug results in most infected images not having the sidechannel data (the file being smuggled out).

A quick survey gives an approximate 70% failure rate where (for whatever reason) no sidechannel data was attached.

Non-complete analysis of the sidechannel data included on /sci/ gives a predictable result: Most of the sidechannel files that make it out are useless.

So far, the following files have been recovered from /sci/ as side channel data (paths have been pruned):

Carol Edwards Head of Consumer Education.jpg

Except for "jonslight.txt", none of these files hold any value (linkandtriforce.doc" is triforce ASCII art).

"jonslight.txt" holds several flight plans from 2009, but offers no personal or otherwise sensitive information, not even a name.

tl;dr: zZzZ

>Carol Edwards

Hahaha oh wow:


How do you know all that`?

>> No.1448206


There's a couple more files I managed to find as well. One was some shitty essay, english lit or something. Another was some English for foreign people document.

I get the feeling that the aim of the virus is to far personal info, if it's pulling out random documents. Perhaps the author is hoping to get lucky and pull out something with some sensitive info in it.

Interesting stuff.

It's nice to see /sci/ has an intelligent thread about the spam.

>> No.1448326


Most people don't really use their "my documents" folder and the worm will drop out of the document loop without selecting anything if the RNG comes up with a zero, so the high failure rate isn't surprising. Thanks to the algorithm used, that'll happen 100% of the time for 0 or 1 document, or %50 of the time for two documents.

>> No.1448335

There's also a chance the worm will select a directory because it doesn't check if the list entry is a file, and this will cause the insertion operation to fail.

>> No.1448336


If it was smart, it would pull documents out of the most recently opened documents list. Those are the most likely to contain sensitive data.

>> No.1448359


I'm a bad person. I hope the author sees this thread and fixes his bad virus.


When I open that shit in notepad, I find stuff like:
WaitForSingleObject GetProcAddress ñLoadLibraryA LFreeLibrary ” CreateProcessA — CreateProcessW ¤HeapReAlloc  HeapDestroy ŸHeapCreate WVirtualFree ¡HeapFree HeapAlloc TVirtualAlloc ©HeapValidate žHeapCompact ªHeapWalk ¦HeapSize ZVirtualProtect

And some random characters. Why is this?

Means it grabbed an executable.
Search the file for "c:\" and probably find the path/filename/size.

>> No.1448530

>An HTA executes without the constraints of the internet browser security model; in fact, it executes as a "fully trusted" application.

But GNU/Linux does not ever assume that files have execution permission. Lol windows.

Oh yeah, it found the more readable path. It adds some javascript shit to the registry, so when you startup IE it runs:
copyname = shell.regRead("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Startup") + "\\4chan.js";
And this was the path C:\Users\TiMpF\Documents\=).txt
Bytes: 150

Lol, and lots of other interesting stuff
// List of boards
var dir = "a b c d e g h hr k m o p r s t u v w wg i ic cm y r9k 3 adv an cgl ck co fa fit int jp lit mu n new po sci sp tg toy trv tv vp x".split(" ");
var mfs = [3,2,3,3,3,3,3, 8,3,3,3,5,8,3,3,3,3,4, 4,3, 3, 3,3, 2,3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3,3, 3, 8, 3, 3, 3, 3, 8, 3, 3,3];

I want to know how this works, this is funny. There are some comments above the scripts roughly telling what it does, probably for the author to make it easier to find. Just, awesome.

There may also be more than one file embedded in the image. The worm is really stupid and will re-infect already infected files.

Wait, so /sci/ actually uses Windows?

>> No.1448648


This isn't /g/. People use whatever works for them.
I use Linux myself but you'd never know it if I hadn't told you.

Windows home laptop, Linux uni laptop


Yes I see, there are two scripts inside, both called "thisscript". That's why the bunny with the pancake file is so big. Both parts of the script use imagemagick, and download it. Will these two scripts not interfere with eachother?

// Download ImageMagick
var imc;
try {
imc = download("https://develop.participatoryculture.org/trac/democracy/browser/trunk/dtv-binary-kit/

And it grabs documents, but what exactly happens to these? I can read some basic script stuff, but not when they get long :P The documents are divided into 5 parts, and then what? Are they sent somewhere? Or added in the picture?

It grabs a random document and adds it to the picture.

No I use Linux Mint, so I didn't fear to open that script lol And I know there's gEdit on it, but I just prefer Wine-> notepad haha

It'll just run the script twice, downloading/altering/attaching file/reuploading two images. Because of this careless behaviour though it's liable to make files too large to upload eventually.