SEe Wh0 viewed Y0ur Pr0f!le — a deconstruction

May 4, 2011

It asks us to run


in the location bar.  This should ring alarm bells at once: the only reason to ask this is that the browser would block such functionality in clicking a link, and a browser would probably have good reason to block such things.

Anyway, it asks the browser to download and execute (by adding a script element to the page) the file  More alarm bells: the url points to an anonymous (numbered) web location (reverse DNS gives it as, pointing a browser there redirects to a page at  Anything proper would not be doing this.

So, we download the file (using CURL, not a browser) and take a look in a text editor.

Amongst the comments (which are nicely left in) we see

// Post Link to friends walls
// Hide chat boxes
// Get online friends and send chat message to them

which gives a good hint as to what it does, and then it modifies the HTML on screen and then sends the browser to a new page:

There is much code commented out, which indicates that most likely someone downloaded this from one scam and modified it for use in this one–probably some bored 16 year old with no life wondering what mischief he can get up to with his computer.  Have pity on the poor sod.


