百度空间 | 百度首页 
 
查看文章
 
[原创]下载者qrypz.exe浅析
2007-05-25 14:34

样本来自:http://bbs.kafan.cn/viewthread.php?tid=89016&extra=page%3D1

.rdata:121520DC s_Urldownloadto db 'URLDownloadToFileA',0 ; DATA XREF: .text:12151488 o

.rdata:12152118 s_ProgramFilesI db 'program files\Internet Explorer\IEXPLORE.EXE',0

.rdata:12152284 s_File1_5D15_zi db 'file/1.5/d15.zip',0 ; DATA XREF: start+153 o
.rdata:12152295                      align 4
.rdata:12152298 s_Docprop1_dll       db '\DocProp1.dll',0         ; DATA XREF: start+123 o
.rdata:121522A6                      align 4
.rdata:121522A8 ; char s_File1_5M15_zi[]
.rdata:121522A8 s_File1_5M15_zi db 'file/1.5/m15.zip',0 ; DATA XREF: start+103 o
.rdata:121522B9                      align 4
.rdata:121522BC ; char s_Http3w_39100_[]
.rdata:121522BC s_Http3w_39100_ db 'http://3w.39100.net/',0 ; DATA XREF: start+F1 o

//调用URLDownloadToFileA函数开启IE后台进行小马下大马,两个木马的连接为(以证实):

http://3w.39100.net/file/1.5/d15.zip

http://3w.39100.net/file/1.5/m15.zip

.rdata:12152210 s_SoftwareMic_0 db 'Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msv1_1\',0

.rdata:121521E8 s_Dllname            db 'DllName',0               ; DATA XREF: start+3C0 o
.rdata:121521F0 s_Msv1_1_dll_0       db 'msv1_1.dll',0            ; DATA XREF: start+395 o

//写注册表挂接winlogon.exe进程

d15.zip浅析:

被下载的木马实则为PE文件,应该是该病毒的空间无法上传PE文件导致病毒幕后使用者更改扩展名,如图:

待d15.zip'下载完成运行后,同上:
.rdata:35155114 s_ProgramFilesI db 'program files\Internet Explorer\IEXPLORE.EXE',0
.rdata:35155114                                             ; DATA XREF: sub_35151DA5+62 o
.rdata:35155114                                             ; sub_35152D5C+83 o
.rdata:35155141                     align 4
.rdata:35155144 ; char s_Urldownloadto[]
.rdata:35155144 s_Urldownloadto db 'URLDownloadToFileA',0 ; DATA XREF: sub_35151E2F+32 o
.rdata:351552D0 s_Login_asp?cpu db 'login.asp?cpuid=',0 ; DATA XREF: sub_35152F0C+10E o
.rdata:351552E1                     align 4
.rdata:351552E4 ; char s_Http3w_39100_[]
.rdata:351552E4 s_Http3w_39100_ db 'http://3w.39100.net/',0 ; DATA XREF: sub_35152F0C+FD o
//尝试连接http://3w.39100.net/login.asp?
.rdata:351553E8 s_File1_5D15_zi db 'file/1.5/d15.zip',0 ; DATA XREF: DllEntryPoint+139 o
.rdata:351553F9                     align 4
.rdata:351553FC ; char s_Docprop1_dll[]
.rdata:351553FC s_Docprop1_dll      db '\DocProp1.dll',0        ; DATA XREF: DllEntryPoint+115 o
.rdata:3515540A                     align 4
.rdata:3515540C ; char s_File1_5Fb15_z[]
.rdata:3515540C s_File1_5Fb15_z db 'file/1.5/fb15.zip',0 ; DATA XREF: DllEntryPoint+F7 o
.rdata:3515541E                     align 10h
.rdata:35155420 ; char s_File1_5Server[]
.rdata:35155420 s_File1_5Server db 'file/1.5/serverhelp.zip',0
.rdata:35155420                                             ; DATA XREF: DllEntryPoint+9E o
.rdata:35155420                                             ; DllEntryPoint+A9 o
//继续进行下载,下载文件如下(已证实):
http://3w.39100.net/file/1.5/serverhelp.zip
http://3w.39100.net/file/1.5/fb15.zip

.rdata:35155244 ; char s_ShellAutoComm[]
.rdata:35155244 s_ShellAutoComm db 'shell\Auto\command',0 ; DATA XREF: sub_351529E9+1CB o
.rdata:35155257                     align 4
.rdata:35155258 ; char s_Shellexecute[]
.rdata:35155258 s_Shellexecute      db 'shellexecute',0         ; DATA XREF: sub_351529E9+1B5 o
.rdata:35155265                     align 4
.rdata:35155268 ; char s_Autorun[]
.rdata:35155268 s_Autorun           db 'AutoRun',0              ; DATA XREF: sub_351529E9+19F o
.rdata:35155270 ; char s_Open[]
.rdata:35155270 s_Open              db 'OPEN',0                 ; DATA XREF: sub_351529E9+19A o
.rdata:35155275                     align 4
.rdata:35155278 ; char String[]
.rdata:35155278 String              db '1.5',0                  ; DATA XREF: sub_351529E9+147 o
.rdata:35155278                                             ; sub_351529E9+1DA o
.rdata:35155278                                             ; sub_35152F0C+5A o
.rdata:35155278                                             ; sub_351535CB+49 o
.rdata:35155278                                             ; sub_35153A30+4A o
.rdata:3515527C ; char s_Ver[]
.rdata:3515527C s_Ver               db 'ver',0                  ; DATA XREF: sub_351529E9+12F o
.rdata:3515527C                                             ; sub_351529E9+1DF o
.rdata:3515527C                                             ; sub_351535CB+4E o
.rdata:3515527C                                             ; sub_35153A30+39 o
.rdata:35155280 ; char s_Autorun_inf[]
.rdata:35155280 s_Autorun_inf       db 'autorun.inf',0          ; DATA XREF: sub_351529E9+100 o
.rdata:35155280                                             ; sub_35152C2D+B0 o
.rdata:3515528C ; char s_Recycler_0[]
.rdata:3515528C s_Recycler_0        db 'RECYCLER\',0            ; DATA XREF: sub_351529E9+BC o
.rdata:3515528C                                             ; sub_35152C2D+6C o
.rdata:35155296                     align 4
.rdata:35155298 ; char s_Recycler[]
.rdata:35155298 s_Recycler          db 'RECYCLER',0             ; DATA XREF: sub_351529E9+33 o
.rdata:351552A1                     align 4

//该病毒为autorun病毒,将自身写入回收站目录中
serverhelp.zip浅析
serverhelp.zip是一个VC++写得dll程序,伪装为zip文件,里面只获得如下脚本:
.rdata:09167538                    unicode 0, <my applet>,0
.rdata:0916754C s_Afterbegin:                              ; DATA XREF: sub_9153920+CF o
.rdata:0916754C                    unicode 0, <afterBegin>,0
.rdata:09167562                    align 8
.rdata:09167568 ; char s_<divIdTmpdiv>[]
.rdata:09167568 s_<divIdTmpdiv> db '<div id=tmpdiv></div>&nbsp;<script        language=javascript      src=%s      defer></script>',0
.rdata:09167568                                            ; DATA XREF: sub_9153AE0+158 o
对脚本不是很了解,只能够到此

类别:病毒岁月 | 浏览() | 评论 (3)
 
网友评论:
1
2007-05-26 09:26 | 回复
.rdata:35155144 s_Urldownloadto db 'URLDownloadToFileA',0 ; DATA XREF: sub_35151E2F+32 o .rdata:351552D0 s_Login_asp?cpu db 'login.asp?cpuid=',0 ; DATA XREF: sub_35152F0C+10E o 这个里面的那个'login.asp?cpuid=‘是要登录什么?还是有什么作用?
 
2
2007-05-26 23:49 | 回复
winlogon.exe\msv1_1.dll Trojan program Trojan-Downloader.Win32.Tiny.gn File: C:\WINDOWS\system32\DocProp1.dll deleted: Trojan program Trojan-Downloader.Win32.Tiny.gn File: C:\windows\system32\__delete_on_reboot__d_o_c_p_r_o_p_1_._d_l_l_ 这么几个东东,一直杀不掉,开机会产生一个recyler文件夹和dielc.exe 文件,还有一个autorun的inf文件,分区目录下会产生右键auto菜单,疑是U盘传染的,不知怎么杀掉,盼指点,谢谢
 
3
2007-05-27 00:14 | 回复
re:2 使用冰刃禁止线程创建后打开winlogon.exe进程,将'msv1_1.dll'模块强制删除打开注册表找到: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\,把msv1_1项删除,至于其他的几个dll,用同样方法删除,可能有的只是插入了explorer.exe进程中,可能有的插入了所有,用上述方法举一反三即可,至于autorun.inf可以在cmd里面用命令: del -sh autorun.inf /q del RECYCLER /s /q /f taskkill /f /im explorer.exe start explorer 来解决
 
发表评论:
姓 名:
网址或邮箱: (选填)
内 容:
验证码: 请点击后输入四位验证码,字母不区分大小写
      

     

©2009 Baidu