高雄市觀光協會網站被植入惡意連結

2007 年 12 月 12 日 – 17:33:00

高雄市觀光協會網站被植入惡意連結,此惡意程式為 PWS:Win32/Gamania.gen!B,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒。

惡意連結/程式碼是放置在首頁和 index-down.asp (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:

[DLL injection]
C:\WINDOWS\Help\9712499B91DB.DLL

[Added file]
C:\autorun.inf
C:\Documents and Settings\Administrator\Desktop\2.bat
C:\Documents and Settings\Administrator\Local Settings\Temp\~s.bat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\m[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\gmsex[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\h[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\stat[1].htm
C:\shell.exe
C:\WINDOWS\Help\9712499B91DB.DLL
C:\WINDOWS\Help\9712499B91DB.EXE
C:\WINDOWS\Help\autorun.inf

[ Added COM/BHO ]
{6B12A5F5-CABF-41EE-B8B3-EC5D2AAFF132}-C:\WINDOWS\HELP\9712499B91DB.DLL

到目前為止 (2007/12/12 @ 16:04),下面的防毒軟體可以偵測到這些惡意檔案 (僅提供參考):

9712499B91DB.DLL:
[ Trend ], "Possible_Infostl"
9712499B91DB.EXE:
[ IntelliTrap ], "PAK_Generic.001″
[ Alpha_Gen ], "Possible_Mlwr-13″
[ Microsoft ], "PWS:Win32/Gamania.gen!B"
[ Kaspersky ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"
[ Sophos ], "[FILE:0000]:Mal/LineDLL-B, [FILE:0001]:Mal/LineDLL-B, Mal/EncPk-AP"
[ Nod32 ], "probably a variant of Win32/Genetik trojan"
[ HBEDV ], "DR/Delphi.Gen"
[ Norman ], "[Heuristic Sandbox detection]:Virus W32/Malware"
[ eAladdin ], "Suspicious File [100]"
[ vba32 ], "MalwareScope.Trojan-PSW.Game.14″
[ Sunbelt ], "VIPRE.Suspicious"
[ WebWasher ], "Trojan.Dropper.Delphi.Gen"
autorun.inf:
[ Beta_Gen ], "Possible_Otorun1″
[ Ikarus ], "Trojan-PWS.OnlineGames.NIT"
[ bitdefender ], "Trojan.PWS.OnLineGames.NIT"
gmsex[1].exe:
[ IntelliTrap ], "PAK_Generic.001″
[ Alpha_Gen ], "Possible_Mlwr-13″
[ Microsoft ], "PWS:Win32/Gamania.gen!B"
[ Kaspersky ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"
[ Sophos ], "[FILE:0000]:Mal/LineDLL-B, [FILE:0001]:Mal/LineDLL-B, Mal/EncPk-AP"
[ Nod32 ], "probably a variant of Win32/Genetik trojan"
[ HBEDV ], "DR/Delphi.Gen"
[ Norman ], "[Heuristic Sandbox detection]:Virus W32/Malware"
[ eAladdin ], "Suspicious File [100]"
[ vba32 ], "MalwareScope.Trojan-PSW.Game.14″
[ Sunbelt ], "VIPRE.Suspicious"
[ WebWasher ], "Trojan.Dropper.Delphi.Gen"
h[1].htm:
[ Alpha_Gen ], "Heur_Infrm-1″
[ Sophos ], "Mal/Iframe-A"
[ HBEDV ], "HEUR/Exploit.HTML"
[ Norman ], "Trojan HTML/Exploit!IFrame.G"
m[1].htm:
[ McAfee ], "Exploit-ObscuredHtml"
[ McAfee_Beta ], "Exploit-ObscuredHtml"
[ HBEDV ], "HTML/ADODB.Exploit.Gen"
[ Grisoft ], "Virus found JS/Downloader.Agent"
[ WebWasher ], "Script.ADODB.Exploit.Gen"
shell.exe:
[ IntelliTrap ], "PAK_Generic.001″
[ Alpha_Gen ], "Possible_Mlwr-13″
[ Microsoft ], "PWS:Win32/Gamania.gen!B"
[ Kaspersky ], "PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE"
[ Sophos ], "[FILE:0000]:Mal/LineDLL-B, [FILE:0001]:Mal/LineDLL-B, Mal/EncPk-AP"
[ Nod32 ], "probably a variant of Win32/Genetik trojan"
[ HBEDV ], "DR/Delphi.Gen"
[ Norman ], "[Heuristic Sandbox detection]:Virus W32/Malware"
[ eAladdin ], "Suspicious File [100]"
[ vba32 ], "MalwareScope.Trojan-PSW.Game.14″
[ Sunbelt ], "VIPRE.Suspicious"
[ WebWasher ], "Trojan.Dropper.Delphi.Gen"

  1. “高雄市觀光協會網站被植入惡意連結” 目前有 2 迴響

  2. 今天已經12/23了
    還是有……….
    而且那個.co.kr的木馬網頁還有在12/16更新..

    By Anonymous on 2007 年 12 月 23 日 - 17:15:00

  3. 謝謝站主貼了這麼多糟惡意植入連結的網站,但除了警告之外,有沒有一些防護措施或辦法分享給大家?發現問題是一回事,解決問題又是另外一件事。相信更深入的探討與思考解決方案是更可以幫助進步的。

    By Pointer on 2007 年 12 月 25 日 - 15:55:00

請在此留下您的意見