Ò»¡¢¸ÅÊö£º
²¡¶¾Ãû³Æ£ºEmail-Worm.Win32.VB.ac
Îļþ´óС£º13.279k
±àдÓïÑÔ£ºMicrosoft Visual Basic
¿ÇÀàÐÍ£ºUPX-Scrambler RC1.x -> ©OnT®oL
½üÁ½ÈÕ£¬ÖÚ¶àQQÓû§¾³£½Óµ½±ðÈË·¢À´µÄQQÓʼþ£¬ÇëСÐIJ»Òª´ò¿ª²é¿´£¬ÒÔÃâÖÐľÂí¡£
¸ÃÈä³æÊ¹ÓÃÎı¾Í¼±êºÍ.txt.exeÀ©Õ¹Ãûαװ×ÔÉí£¬ÓÕµ¼Óû§Ö´ÐÐÈ䳿Ìå¡£
¶þ¡¢·ÖÎö£º£¨vvvÊDZ»ÆÁ±ÎµôµÄÁ¬½Ó£©
1¡¢ È䳿ÔËÐк󣬻ᵯ³öÒ»¸öÎļþ¸ñʽÎÞЧµÄ¶Ô»°¿ò£¬ÃÔ»óÓû§£¬²¢½«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼%system%Ϊ£º
C:\WINDOWS\system32\Inetdbs.exe ÎļþÊôÐÔΪ£ºRHS
ͬʱ½«×ÔÉí¼ÓÈ뵽ϵͳע²á±íÆô¶¯ÏîÄ¿£º
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¼üÃû£ºInet DataBase ¼üÖµ£º"C:\WINDOWS\System32\Inetdbs.exe"
2¡¢È»ºóÈ䳿»áµ½£ºÃÜÂë½â°Ô¡£
3¡¢½«ÏÂÔØµÄnew.jpg¸ÄÃûΪ~DF41F8.EXE²¢Ö´ÐС£Ö´ÐкóÊͷŽ«×ÔÉí¿½±´µ½ÏµÍ³Ä¿Â¼£º
¿½±´ÎļþΪ£º
C:\WINDOWS\system32\mstext32.dll 7KB
C:\WINDOWS\system32\ÿwowexec.exe 140KB
ÆäÖÐmstext32.dllÊÇRiskWare.PSWTool.Finder.a£¬Ò»¸öÓÃÀ´½øÐÐhook ²éÕÒÃÜÂëµÄdll¿â¡£
²¢Ôö¼Ó×¢²á±íÆô¶¯Ï
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¼üÃû£ºMSIEXEC ¼üÖµ£º"ÿwowexec.exe"
¸ÃľÂí»¹»áÔÚ×¢²á±íÖÐÔö¼ÓÈçϼüÖµ£¬ÓÃÀ´´æ´¢×ÔÉíÉèÖãº
HKEY_CLASSES_ROOT\ZPwd_box
HKEY_CLASSES_ROOT\ZPwd_box tmUpgrade_p dword:41bfabb0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box tmUpgrade_p dword:41bfabb0
4¡¢wowexec.exe »á·ÃÎʱàºÅΪ£º163com[20030606]¡¢IP£º202.108.44.153µÄ163ÐÅÏ䣬»ñÈ¡Éý¼¶ÐÅÏ¢¡£
¶Ë¿Ú:110
Óû§:pwdboxup
ÃÜÂë:shengjile
ÃÜÂë½â°ÔÊÇΣº¦±È½Ï´óµÄľÂí£¬¿ÉÒÔ»ñÈ¡¸÷ÖÖ¼°Ê±Í¨Ñ¶Èí¼þ¡¢EMAIL¡¢ÍøÂçÓÎÏ·¡¢ÍøÂçÒøÐС¢IEÖÐÊäÈëµÄ¸÷ÖÖÃÜÂëµÈ¡£
5¡¢ÔÚÖØÆô¶¯ºóInetdbs.exe»á±»ÔËÐУ¬ÔËÐкó»áÏÂÔØhttp://www.vvv.com/b.wavÎļþ£¬¸ÃÎļþΪһzip°ü¹ü£¬ÎªÈ䳿Ìå×ÔÉí¡£ÔÚ%temp%Ŀ¼ÏÂÖØÃûΪ~DF0032.ZIP,ÓÃÀ´×÷Ϊ·¢ËÍÓʼþµÄ±¸Óø½¼þ¡£
»¹»áµ½http://freehost23.vvv.com/wpzkq/MSWINSCK.OCX¿Ø¼þ±£´æµ½%system%Ŀ¼Ï£¬È·±£ÔÚijЩϵͳÉÏÄܹ»ÕýÈ··¢ËÍEMAIL£¬¸Ã¿Ø¼þΪVB ÍøÂçÖ§³Ö¿â¡£
ͬʱ»á½«¸Ã¿Ø¼þÔÚ×¢²á±íµÄMSWinsock.WinsockºÍClassid½øÐÐ×¢²á¡£
6¡¢Inetdbs.exe »áÄ£·ÂFOXMAIL 5.0 ½øÐз¢ËÍÀ¬»øÓʼþ£º
Óʼþ±êÌâΪÏÂÃæÆäÖÐÒ»ÖÖ£º
ÎÒ°®Äã,ÎÒÏëÄã,Äãϲ»¶ÎÒÂð,ÖØÒª,¾øÃÜ,ÎҵļòÀú,ÇóÖ°Êé,ÇóÖ°ÐÅ,ÎÒѧ¼ÆËã»ú,ÓÐûÓпյÄÖ°Îñ,ÉúÈÕ¿ìÀÖ,ÄãºÃ¿É°®,×Ô¼öÊé,ÉêÇëÊé,Çë¼í,¾®¸ÔɽÈýÈÕÓÎ,Ì칤ÂÃÓι«Ë¾,ϵͳ²¹¶¡,ÍÆ¹ã׬Ǯ¼¼Êõ,¼¤ÇéÍòÖÖ,ÑûÇë,Ãâ·Ñ»áÔ±,Äã°®ÎÒÂð,ÄãÏëÎÒÂð,¶Ô²»Æð£¬±ðÉúÆø,µÀǸ
ÄÚÈÝΪÏÂÃæÒ»ÖÖ£º
ÏêÇé²é¿´¸½¼þ,ÖØÒªÎļþ,¾ÍÒª¸½¼þÖÐ,×¢Òâ²éÊÕ,Á¢¼´²é¿´,×÷Æ·,Îļþ,Îĵµ,ÏêÇé,¸½¼þÖÐ,ѹËõ°üÄÚ,ѹËõ°ü,½âѹ¼´¿É,´ò¿ªÑ¹Ëõ°ü,¿´ÁËûÓÐ
7¡¢·¢ËÍÀ¬»øÓʼþ¹ý³Ì£º
220 qs20.qq.com ESMTP QQ Mail Server
HELO XPPROSP1
250 qs20.qq.com
mail from: ockt@uixj.com
250 Ok
rcpt to: 97986@qq.com
250 Ok
DATA
354 End data with .
From: ockt@uixj.com
Date: Wed, 15 Dec 2004 13:59:55 +0800
X-Mailer: Foxmail 5.0 [cn]
To: 97986@qq.com
Subject: ÓÎÏ·±Ò·ÀµÁר¼Ò
Mime-Version: 1.0
Content-Type: multipart/mixed;
boundary="=====line_63193098====="
This is a multi-part message in MIME format.
--=====line_63193098=====
Content-Type: text/plain;
charset="GB2312"
Content-Transfer-Encoding: 7bit
¸½¼þÖÐ
--=====line_63193098=====
Content-Type: application/octet-stream;
name="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="ÓÎÏ·±Ò·ÀµÁר¼Ò.zip"
...
Èý¡¢½â¾ö°ì·¨£º
¸ù¾Ý·ÖÎöɾ³ý¶ÔÓ¦Îļþ£¬»Ö¸´×¢²á±í¼üÖµ¡£