                                                                                      Wellcome to BadBlood
                                                                                               by Marklord

Disclaimer
Just a simple reminder.If you screw up something using BadBlood and you get in
trouble, don't blame me.I take no responsability for whatever BadBlood causes.
So be warned!!!(Mobman words,from SubSeven ver 1.*)

1.What is BadBlood?

BadBlood is a tool that help you to infect people(victims) with trojans more easy by email.This  is made from the latest xploit descover by me,Marklord,xploit that allow runing attached files,without a user knowing about it,using the regobj script.This does not affect only the Outlook Express users,affect all users that have IE5.0 with Outlook Express installed,using Windows'95 or Windows'98.Even if thay use mail client like Netscape Messager,etc,they will be affected if they open a  .eml that contain this xploit.You can infect even the Hotmail user,or other html-mail,but only if you they open a .eml

//To findout more about the xploit read the xploit.txt
//Wen you work with this xploit be sure to have Scripting disable(this option is on Internet Explorer,Option,Security Tab,press Custom Level,and go to the butom of the window and disable ALL Scripting)

2.What does contain and how work BadBlood?

BadBlood contain:
A)Recipient(recip.eml) - this is the recipient of exploit that allow to add your own executables(trojans,viruses,etc)
How it work:
-this recipient contain the regobj script,and after you attach your executable and send to someone the script executes and move(rename) your executable to c:\windows\startm~1\programs\startup\file.exe so it can be run next time windows start.

B)Next recipents contain the server of SubSeven trojan,server of The Thing backdoor,and a recipient that format drivers

badblood.eml
-this is the recipient that format drives
How it work:
-this recipient contain the regobj script that wen it executes will freeze the system and overwrite the autoexec.bat.So if the victim press Reset next time autoexec.bat run it will format  F: E: D: C: drives.
If you dont know how to work with this dont try it,and remeber the disclaimer.Becose Y2K is coming and if you want to infect somebody,a friend(hehe) just send them this mail.

subseven.eml
-this is recipient of trojan SubSeven version 2.1a
How it work:
-this recipient contain the server of trojan SubSeven.When the script executes it move the subseven server to  c:\windows\startm~1\programs\startup\file.exe so it can be run next time windows start.
Subseven Server:-the server run on deault port:27374
                               -it notified on Irc:irc.subgenius.net:6667 channel #badblood

tthing.eml
-this is recipient of backdoor The Thing 1.6
How it work:
-this recipient contain the server if backdoor The Thing.When the script executes it move the backdoor server to  c:\windows\startm~1\programs\startup\file.exe so it can be run next time windows start.
The Thing Sever:-the server run on port 6006
                               -the server password is:badblood
                               -it ICQ to a nonexisting ICQ number

Atention wen you type the message.Type it before the > sign,and not after.You can delete the > sign,but do not delete after the > sign becose you will delete the script.

3.How to infect Netscape Messager and html based mail users?

This is a little bit complicated,but also simple.You will have to make a .eml,that contain the exploit with your executable,but not a recipient,and a real .eml.How to do that?Just send your self to your email using your acount,a email that contain the exploit with your executable.In OE open your self sended mail,and save it as msg.eml.And then you attach the msg.eml and send it to someone.You got as example tthing.eml recipient that has attach a message.eml that contain the exploit with The Thing 1.6 server.

4.How sure I am the xploit work?
I can asure you 51% of it.And why is that?Becose how creator of God Message sed:"There has been a patch released for the script lib... but, because Microsoft does not advertise these things and people do not update their systems ('what the hell is script lib?', 'do I have to boot, no way!', they say)... you will find a very large number of systems "at risk"."
So you need to spread all this,I mean Subseven server,and other before appearing other versions of IE and Outlook Express.OK

If there is a problem,a bug,or something remind me at: 1928@dnt.ro .Also all thanks goes there.

See you
Marklord