查看: 4186|回复: 14
收起左侧

[病毒样本] 网络蠕虫变种

[复制链接]
Symantec.
头像被屏蔽
发表于 2014-12-27 23:18:33 | 显示全部楼层 |阅读模式

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
欧阳宣
头像被屏蔽
发表于 2014-12-27 23:21:28 | 显示全部楼层
to mcafee
诸葛亮
发表于 2014-12-27 23:29:41 | 显示全部楼层
红伞miss
lovelive10010
发表于 2014-12-27 23:37:38 | 显示全部楼层
to 360
XywCloud
发表于 2014-12-27 23:43:38 | 显示全部楼层
样本重复且文件安全。
Symantec.
头像被屏蔽
 楼主| 发表于 2014-12-27 23:45:35 | 显示全部楼层
XywCloud 发表于 2014-12-27 23:43
样本重复且文件安全。

      安全?你确定?
lovelive10010
发表于 2014-12-27 23:57:12 | 显示全部楼层

行为描述:        写权限映射文件
详情信息:       
\WINDOWS\system32\zh-cn\ieframe.dll.mui
Local\UrlZonesSM_Administrator
Local\!PrivacIE!SharedMem!Counter
AtlDebugAllocator_FileMappingNameStatic3_12c
CiceroSharedMemDefaultS-1-5-21-1482476501-1645522239-1417001333-500
\WINDOWS\system32\zh-cn\mshtml.dll.mui
行为描述:        设置特殊文件夹属性
详情信息:       
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述:        修改文件内容
详情信息:       
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\dnserrordiagoff_webOC[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\ErrorPageTemplate[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\errorPageStrings[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\info_48[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\down[1]---> Offset = 0
网络行为
行为描述:        连接指定站点
详情信息:       
InternetConnectA: ServerName = user.ttliuliang.com, PORT = 80
InternetConnectA: ServerName = user5.ttliuliang.com, PORT = 80
InternetConnectA: ServerName = user3.ttliuliang.com, PORT = 80
InternetConnectA: ServerName = user1.ttliuliang.com, PORT = 80
InternetConnectA: ServerName = int.dpool.sina.com.cn, PORT = 80
InternetConnectA: ServerName = tbcart.ttliuliang.com, PORT = 80
InternetConnectA: ServerName = uzhan.ttliuliang.com, PORT = 80
行为描述:        建立到一个指定的套接字连接
详情信息:       
127.0.0.1:1040
行为描述:        下载文件
详情信息:       
URLDownloadToFileW: http://update.ttliuliang.com/upd ... .txt?rnd=1419695183 ---> c:\monitor\update.txt
C:\monitor\update.txt
行为描述:        读取网络文件
详情信息:       
hFile = 0x00000360, BytesToRead =4096, BytesRead = 4096.
hFile = 0x000004b0, BytesToRead =4096, BytesRead = 4096.
hFile = 0x000004ac, BytesToRead =4096, BytesRead = 4096.
行为描述:        打开HTTP请求
详情信息:       
HttpOpenRequestA: user.ttliuliang.com:80/clnt/tips_flownews.htm, hConnect = 0x00000530
HttpOpenRequestA: user5.ttliuliang.com:80/?act=getmemberuid&hostid=9d271956f01ee021a61f470e680b5960&ver=166&isclnt=1&r=1419695185070&mode=2, hConnect = 0x0000035c
HttpOpenRequestA: user3.ttliuliang.com:80/?act=getmemberpoints&hostid=9d271956f01ee021a61f470e680b5960&ver=166&isclnt=1&r=1419695185148&mode=2, hConnect = 0x0000035c
HttpOpenRequestA: user1.ttliuliang.com:80/?act=getconstinfo&hostid=9d271956f01ee021a61f470e680b5960&ver=166&isclnt=1&r=1419695185242&mode=2, hConnect = 0x0000035c
HttpOpenRequestA: int.dpool.sina.com.cn:80/iplookup/iplookup.php?format=js, hConnect = 0x000004ac
HttpOpenRequestA: tbcart.ttliuliang.com:80/?act=gettask&hostid=9d271956f01ee021a61f470e680b5960&ver=166&isclnt=1&r=1419695187195&mode=2, hConnect = 0x000004ac
HttpOpenRequestA: uzhan.ttliuliang.com:80/?act=gettask&hostid=9d271956f01ee021a61f470e680b5960&ver=166&isclnt=1&r=1419695217289&mode=2, hConnect = 0x000003a0
注册表行为
行为描述:        修改注册表
详情信息:       
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
\REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG\Trace Level
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Local AppWizard-Generated Applications\挂机版\Settings\c_bClearCookie
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Local AppWizard-Generated Applications\挂机版\Settings\c_bClearCache
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Local AppWizard-Generated Applications\挂机版\Settings\c_bNotActiveX
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Local AppWizard-Generated Applications\挂机版\Settings\c_bFlowCheckCookie
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Local AppWizard-Generated Applications\挂机版\Settings\c_bExitIfRefNavFail
行为描述:        删除注册表键值
详情信息:       
\REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\sample\DEBUG\Trace Level
行为描述:        删除注册表键值_IE连接设置
详情信息:       
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
其他行为
行为描述:        创建互斥体
详情信息:       
Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
RasPbFile
Local\!PrivacIE!SharedMemory!Mutex
CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1645522239-1417001333-500MUTEX.DefaultS-1-5-21-1482476501-1645522239-1417001333-500
行为描述:        查找指定窗口
详情信息:       
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
行为描述:        隐藏指定窗口
详情信息:       
[Window,Class] = [,ComboLBox]
[Window,Class] = [,tooltips_class32]
[Window,Class] = [Progress1,msctls_progress32]
[Window,Class] = [STWorker,Afx:400000:8:10011:0:3001c5]
[Window,Class] = [0,Edit]
行为描述:        窗口信息
详情信息:       
Pid = 300, Hwnd=0xc01d6, Text = 什么是天天挂机版?, ClassName = Button.
Pid = 300, Hwnd=0xd01c8, Text = 系统设置, ClassName = Button.
Pid = 300, Hwnd=0xc01c2, Text = 关于, ClassName = Button.
Pid = 300, Hwnd=0xb0184, Text = 会员账号或挂机编号(UID):, ClassName = Static.
Pid = 300, Hwnd=0xa01aa, Text = 0, ClassName = Edit.
Pid = 300, Hwnd=0xb01b0, Text = 注册账号, ClassName = Button.
Pid = 300, Hwnd=0xa018c, Text = 查询编号, ClassName = Button.
Pid = 300, Hwnd=0xe016e, Text = 停止挂机, ClassName = Button.
Pid = 300, Hwnd=0xa0198, Text = 一键隐藏, ClassName = Button.
Pid = 300, Hwnd=0xd01a4, Text = 挂机速度:, ClassName = Static.
Pid = 300, Hwnd=0xc01e8, Text = 智能模式, ClassName = ComboBox.
Pid = 300, Hwnd=0xb01be, Text = 可用天币:, ClassName = Static.
Pid = 300, Hwnd=0xb0170, Text = 0 正在挂机中, ClassName = msctls_progress32.
Pid = 300, Hwnd=0xb01ce, Text = 0, ClassName = Static.
Pid = 300, Hwnd=0xd01ac, Text = 升级, ClassName = Button.
抱歉其实我也看不懂,
lll714775117
发表于 2014-12-28 00:17:41 | 显示全部楼层
本帖最后由 lll714775117 于 2014-12-28 00:35 编辑

文件安全,或者需要特定环境才能触发,B超没跑出来,我这里本地也没跑出来,哈勃跑出来的无可疑行为
XywCloud
发表于 2014-12-28 06:52:33 来自手机 | 显示全部楼层
Symantec. 发表于 2014-12-27 23:45
安全?你确定?

我确定。
这个是一个刷流量的软件。
狐狸糊涂
发表于 2014-12-28 08:26:41 | 显示全部楼层
BD没报
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-9-17 17:08 , Processed in 0.124995 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表