该木马是使用VC编写的盗号木马程序,由微点主动防御软件自动捕获,采用Unpack方式加壳,长度为120,320字节,图标为 ,病毒扩展名为exe。病毒主要下载其它木马。
病毒分析
病毒主程序exe:
打开注册表项:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
创建以下子项达到映像文件劫持目的,以上文件不能再启动
| Quote: |
avp.com avp.exe runiep.exe PFW.exe FYFireWall.exe rfwmain.exe rfwsrv.exe KAVPF.exe KPFW32.exe nod32kui.exe nod32.exe Navapsvc.exe Navapw32.exe avconsol.exe webscanx.exe NPFMntor.exe vsstat.exe KPfwSvc.exe Ras.exe RavMonD.exe mmsk.exe WoptiClean.exe QQKav.exe QQDoctor.exe EGHOST.exe 360Safe.exe iparmo.exe adam.exe IceSword.exe 360rpt.exe 360tray.exe AgentSvr.exe AppSvc32.exe autoruns.exe avgrssvc.exe AvMonitor.exe CCenter.exe ccSvcHst.exe FileDsty.exe FTCleanerShell.exe HijackThis.exe Iparmor.exe isPwdSvc.exe kabaload.exe KaScrScn.SCR KASMain.exe KASTask.exe KAVDX.exe KAVPFW.exe KAVSetup.exe KAVStart.exe KISLnchr.exe KMailMon.exe KMFilter.exe KPFW32.exe KPFW32X.exe KPFWSvc.exe KRegEx.exe KRepair.com KsLoader.exe KVCenter.kxp KvDetect.exe KvfwMcl.exe KVMonXP.kxp KVMonXP_1.kxp kvol.exe kvolself.exe KvReport.kxp KVScan.kxp KVSrvXP.exe KVStub.kxp kvupload.exe kvwsc.exe KvXP.kxp KvXP_1.kxp KWatch.exe KWatch9x.exe KWatchX.exe MagicSet.exe mcconsol.exe mmqczj.exe KAV32.exe nod32krn.exe PFWLiveUpdate.exe QHSET.exe RavMonD.exe RavStub.exe RegClean.exe rfwcfg.exe RfwMain.exe rfwsrv.exe RsAgent.exe Rsaupd.exe safelive.exe scan32.exe shcfg32.exe SmartUp.exe SREng.EXE symlcsvc.exe SysSafe.exe TrojanDetector.exe Trojanwall.exe TrojDie.kxp UIHost.exe UmxAgent.exe UmxAttachment.exe UmxCfg.exe UmxFwHlp.exe UmxPol.exe UpLive.exe procexp.exe OllyDBG.EXE OllyICE.EXE rfwstub.exe RegTool.exe rfwProxy.exe RawCopy.exe CCenter.exe |
|
指向的值:0
创建文件:%SystemRoot%\system32\ jffday(六个随机英文字母)(驱动文件)
创建服务:
子键:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ jffday
键值:DisplayName
指向数据:jffday(六个随机英文字母)
键值:ImagePath
指向数据:\??\C:\windows\system32\ jffday(六个随机英文字母)
键值:Start
指向数据:3
创建文件:%SystemRoot%\system32\jdjfla.dll(六个随机英文字母)(DLL文件)
驱动文件sys:
病毒主体exe与%SystemRoot%\System32\jffday(驱动文件)通过以下控制码进行通信,使用不同方法来结束以下进程
控制代码0x228004:把CrackMe.sys文件的0x3074偏移位置填充零
控制代码0x228008:提取CrackMe.sys文件的0x1810这个位置的代码,作为函数运行
控制代码0x228010:得到进程ID,使用ZwTerminateProcess关闭进程
控制代码0x22E14B:恢复SSDT表,使某些安全软件失效
控制代码0x228014:向目标线程插入内核态APC,调用ZwTerminateProcess结束进程;
控制代码0x22800C:用函数NtOpenProcess打开进程,得到函数句柄,用函数ZwTerminateProcess结束进程
| Quote: |
avp.com avp.exe runiep.exe PFW.exe FYFireWall.exe rfwmain.exe rfwsrv.exe KAVPF.exe KPFW32.exe nod32kui.exe nod32.exe Navapsvc.exe Navapw32.exe avconsol.exe webscanx.exe NPFMntor.exe vsstat.exe KPfwSvc.exe Ras.exe RavMonD.exe mmsk.exe WoptiClean.exe QQKav.exe QQDoctor.exe EGHOST.exe 360Safe.exe iparmo.exe adam.exe IceSword.exe 360rpt.exe 360tray.exe AgentSvr.exe AppSvc32.exe autoruns.exe avgrssvc.exe AvMonitor.exe CCenter.exe ccSvcHst.exe FileDsty.exe FTCleanerShell.exe HijackThis.exe Iparmor.exe isPwdSvc.exe kabaload.exe KaScrScn.SCR KASMain.exe KASTask.exe KAVDX.exe KAVPFW.exe KAVSetup.exe KAVStart.exe KISLnchr.exe KMailMon.exe KMFilter.exe KPFW32.exe KPFW32X.exe KPFWSvc.exe KRegEx.exe KRepair.com KsLoader.exe KVCenter.kxp KvDetect.exe KvfwMcl.exe KVMonXP.kxp KVMonXP_1.kxp kvol.exe kvolself.exe KvReport.kxp KVScan.kxp KVSrvXP.exe KVStub.kxp kvupload.exe kvwsc.exe KvXP.kxp KvXP_1.kxp KWatch.exe KWatch9x.exe KWatchX.exe MagicSet.exe mcconsol.exe mmqczj.exe KAV32.exe nod32krn.exe PFWLiveUpdate.exe QHSET.exe RavMonD.exe RavStub.exe RegClean.exe rfwcfg.exe RfwMain.exe rfwsrv.exe RsAgent.exe Rsaupd.exe safelive.exe scan32.exe shcfg32.exe SmartUp.exe SREng.EXE symlcsvc.exe SysSafe.exe TrojanDetector.exe Trojanwall.exe TrojDie.kxp UIHost.exe UmxAgent.exe UmxAttachment.exe UmxCfg.exe UmxFwHlp.exe UmxPol.exe UpLive.exe procexp.exe OllyDBG.EXE OllyICE.EXE rfwstub.exe RegTool.exe rfwProxy.exe RawCopy.exe CCenter.exe |
|
DLL文件:
使用SetWindowsHookEx这个函数实现系统全局映象动态库,实现进程代码注入
如果自己注入到iexplorer.exe,执行以下破坏
在API函数CreateFileA上挂钩,过滤掉文件名包含” Root#RCVYL”文件
在API函数URLDownloadToFileA上挂钩,当下载到本地文件的目录是 %temp%,不执行URLDownloadToFileA函数
下载列表http://ccc.*****ame.cn/txt.txt到本地%SystemRoot%\system32\bzzpm.log
从此列表下载文件:
Tags:木马下载器
Trojan-Downloader.Win32.Agent.qgg
来源:微点