國際電子戰協會中華民國總會網站被植入惡意連結
2007 年 05 月 25 日 – 10:26:00國際電子戰協會中華民國總會網站被植入惡意連結,此惡意程式結合間諜軟體和 Agent 的變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號、密碼和監控系統)。另外,不曉得台灣的軍事單位有沒有常常瀏覽此網站,如果有的話,那可要小心了。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。
惡意連結是放置在首頁 (可能要仔細檢查一下囉) 中的:
執行之後,有下面的行為:
[DLL injection]
C:\Documents and Settings\Administrator\Desktop\mlang.dll
C:\WINDOWS\system32\rsvp32_2.dll
[Added service]
NAME: SysmonLogTapiSrv
DISPLAY: Performance Logs and Alerts SysmonLogTapiSrv
FILE: C:\WINDOWS\system32\6to4svcr.exe srv
NAME: WS2IFSL (這是正常的服務)
DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment
FILE: \SystemRoot\System32\drivers\ws2ifsl.sys
[Added file]
C:\Documents and Settings\Administrator\Desktop\mlang.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\1.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\5.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\6.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\xaC896.tmp
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\Dropper[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\45555_sn[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zzz[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\inexed[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\zupastik[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\file[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\svchost[1].exe
C:\WINDOWS\system32\6to4svcr.exe
C:\WINDOWS\system32\77089387.dat
C:\WINDOWS\system32\ipv6monl.dll
C:\WINDOWS\system32\msvcrl.dll
C:\WINDOWS\system32\rsvp32_2.dll
C:\WINDOWS\system32\sporder.dll
[Added LSP]
ID: 1012
NAME: MzName (連結至 C:\WINDOWS\system32\rsvp32_2.dll)
ID: 1013
NAME: LAYERED MSAFD Tcpip [TCP/IP]
ID: 1014
NAME: LAYERED MSAFD Tcpip [UDP/IP]
ID: 1015
NAME: LAYERED MSAFD Tcpip [RAW/IP]
ID: 1016
NAME: LAYERED RSVP UDP Service Provider
ID: 1017
NAME: LAYERED RSVP TCP Service Provider
ID: 1018
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{5D08099D-7943-4EA6-A096-1B462434FA54}] SEQPACKET 0
ID: 1019
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{5D08099D-7943-4EA6-A096-1B462434FA54}] DATAGRAM 0
ID: 1020
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{52F2F2DC-BD23-4F3F-B226-3D35AF867824}] SEQPACKET 1
ID: 1021
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{52F2F2DC-BD23-4F3F-B226-3D35AF867824}] DATAGRAM 1
ID: 1022
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B4131A8-C8E1-4CFF-996B-D8AFB89B3607}] SEQPACKET 2
ID: 1023
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B4131A8-C8E1-4CFF-996B-D8AFB89B3607}] DATAGRAM 2
ID: 1024
NAME: LAYERED MzName
到目前為止 (2007/5/24 @ 09:09),下面的防毒軟體可以偵測到這些惡意檔案:
msvcrl.dll:
[ Trend ], "TROJ_Generic"
svchost[1].exe:
[ Trend ], "TSPY_CEDA.AB"
zupastik[1].exe:
[ Trend ], "TSPY_BZUB.A"
zzz[1].exe:
[ Trend ], "TSPY_BZUB.A"
5.tmp:
[ Trend ], "TSPY_BZUB.A"
6.tmp:
[ Trend ], "TSPY_BZUB.A"
ipv6monl.dll:
[ Trend ], "TSPY_BZUB.A"
rsvp32_2.dll:
[ Symantec ], "Trojan.Mespam"
[ Microsoft ], "[->(Aspack v2.12)]:Trojan:Win32/Mespam.B"
[ Kaspersky ], "PAK:ASPack, Trojan-Proxy.Win32.Jaber.a"
[ McAfee ], "Spam-Mespam"
[ Sophos ], "Troj/SpamToo-AM"
[ Panda ], "Trj/Spammer.AAZ"
[ Nod32 ], "a variant of Win32/TrojanProxy.Jaber trojan"
[ Fortinet ], "W32/SpamToo.A!tr"
[ HBEDV ], "TR/Faktura.A"
[ Ewido ], "Proxy.Jaber.a"
4.tmp:
[ Kaspersky ], "PAK:PE_Patch, PAK:UPack, Trojan-Spy.Win32.Webmoner.cg"
[ McAfee ], "New Malware.aj !!"
[ Sophos ], "Mal/Packer"
[ Fortinet ], "suspicious"
[ HBEDV ], "HEUR/Crypted"
[ Norman ], "Security Risk W32/Suspicious_U.gen"
45555_sn[1].exe:
[ Symantec ], "Trojan.Goldun"
[ Kaspersky ], "PAK:UPX, Trojan-Spy.Win32.Goldun.ms"
[ McAfee ], "Generic PWS"
[ Panda ], "Trj/Goldun.OZ"
[ Nod32 ], "Win32/Spy.Goldun.NBC trojan"
[ Fortinet ], "Spy/Goldun"
[ HBEDV ], "TR/Crypt.FKM.Gen"
[ Norman ], "Trojan W32/Goldun.ARK"
[ Ewido ], "Logger.Goldun.ms"
Dropper[1].exe:
[ Kaspersky ], "PAK:PE_Patch, PAK:UPack, Trojan-Spy.Win32.Webmoner.cg"
[ McAfee ], "New Malware.aj !!"
[ Sophos ], "Mal/Packer"
[ Fortinet ], "suspicious"
[ HBEDV ], "HEUR/Crypted"
[ Norman ], "Security Risk W32/Suspicious_U.gen"
file[1].exe:
[ Kaspersky ], "Trojan-Downloader.Win32.Agent.bkm"
[ McAfee ], "Downloader-BBS"
[ Sophos ], "Mal/Clagger-D"
[ HBEDV ], "TR/Dldr.Agent.bkm.5″
[ Norman ], "Trojan W32/Agent.BPCB"
[ Ewido ], "Downloader.Agent.bkm"
mlang.dll:
[ Fortinet ], "suspicious"
/> [ HBEDV ], "HEUR/Crypted"
[ Ewido ], "Logger.Webmoner.cc"


“國際電子戰協會中華民國總會網站被植入惡意連結” 目前有 1 迴響
昨天就有看到了
http://x-solve.com/blog/wp-content/uploads/2007/05/1.thumbnail.PNG
http://x-solve.com/blog/?p=166
By Anonymous on 2007 年 05 月 25 日 - 12:50:00