Post by
Wildbob on Mar 05, 2018 11:19pm
Malware
Tks side show
no what you sent wasn’t what I got it was just a bitcoin bulletin board not all those numbers etc
will have the I Pad scanned anwway
appreciate your help
bob
Comment by
Sidesh0w on Mar 06, 2018 12:28am
If anyone opened the CYX.hta file that was in the post, I found an article that confirms that it did a reverse-http to 31.41.220.9. To reveal the code in the hta file (that I posted) you need to open it in notepad, and do a base64 decode of the encoded text. It is black hat code, and well-written.