Ahh, as I begun to dive through the Researched prompted by a mysterious Download I was requested to complete, I believe I have found useful information to aid in my investigation. Here's what I have encountered at this current point in time. (I do apologize in advance if I sound as if I am speaking nonsense, mind you, I'm quite the Computer-Nerd. ^^U) :
-In the starting steps of uncovering the identity of the Anonymous File, it was quite apparent from Bing Suggestions that it was quite popular, and searched quite frequently. I reacted in positive and negative ways over this- I now was aware of that fact it was popular, hence, simple to discover the mysteries behind. Of course, this may have too meant that the File packed a powerful punch, with awful Malicious Codes such as Trojans, Malware- And for all I knew, CryptoLocker could have been hiding inside. O:
-The Search Results behind my questions did not aid me in the slightest as I attempted to relieve the increasing worries I had directed towards this oddity. Oh, you're curious as of why? Ahh. Not only did the majority of Links dropped on the Webpage appear rather shady, though many of them had Descriptions including the query of the File, alongside the word, "JavaScript." What is that, you ask? JavaScript is a Programming Language used on multiple Webpages for multiple functions. I believe this sounds logical for the File, considering that it's name ends with ".Js".
-With this, I travelled to wonderful world of Wikipedia to continue with my research. Though I found it impossible to find knowledge on the File Name itself, I did find that the beginning extension, "DPX" is an abbreviation for "Digital Picture Exchange", a Filing Format commonly used for the matters of Pictures. Ahh, a Picture-JavaScript?
-Since I had uncovered a portion of the first query, I figured that it was logical to find the second: "I.Simpli.Fi." What is it? For such pondering questions, I took my journey back through the realms of Bing, and with patience, found evidence that "I.Simpli.Fi" could possibly categorize as a Domain Service. This statement I am not positive of, though there were multiple hints hidden through the Webpage allowing me to fall to such a conclusion.
-Now, what do I have? An unknown Picture File, which appears to be coded with JavaScript. I'm not exactly sure of what harm may be caused with the mysterious Picture itself, though I am aware of the fact that the attached JavaScript is rather suspicious- Script is often used in the process of Malicious Coding, which of course leads to awful threats such as Trojans and Backdoors. A strange Picture File with suspicious JavaScript which may in fact have malice in it's Coding, offered to me by an odd Website with intentions I am unaware of. Okay, time to take my investigation to Sophos.
-As I arrived at my destination of the home of the brilliant Antivirus Software, Sophos, I figured it logical to search the query of this shady Website. "I.Simpli.Fi"- Oh. Oh! Would you look at that?
Sophos, you say you've found a match? A Trojan? Here, we must take a deeper look!
That I did, and as I looked throughout the Download Requests, I found a Link which I am certain that I- And You!- Have all viewed previously to this.:
![]() |
| Huh? Look at the surrounding Links! I thought Zone Alarm was an Antivirus? O: |
This was a victorious and frightening moment for me. I scrolled down even further to capture a glimpse of more information.:
I'm shaking. Should I be crying tears filled with fear as of now, or tears filled with joy? :O
Concluding my mission, it appears that this mysterious behavior was in fact malicious, as Sophos entitles it: "Troj/BHO-TN", which is a Trojan that was first seen on May 4, 2012. I was correct. My suspicions were at last deemed true. The journey is complete.
Or so we thought.
Hah, I'm joking, it's over. Thank you all for reading, I understand that it was quite long, though I must say, I found it rather important. I feel as if I accomplish my goal- Whatever that was. XD
-Jersey. ;)



No comments:
Post a Comment