五月, 2007

南港軟體工業園區網站被植入惡意連結

2007 年 05 月 31 日 – 08:47:00

南港軟體工業園區網站被植入惡意連結,最近有瀏覽這個網站的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息。另外,此惡意程式是利用微軟所公佈ANI 的安全漏洞 (Vulnerability in Windows Animated Cursor Handling)對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(感謝網友通知)

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

當執行此惡意程式時,會產生應用程式錯誤的訊息:

執行之後,有下面的行為:

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\ie.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\ie.vbs
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\qq614[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\miantwo[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\stat[1].htm

到目前為止 (2007/5/30 @ 12:25),下面的防毒軟體可以偵測到這些惡意檔案:

qq614[1].htm:
[ Microsoft ], “[->(SCRIPT0000)]:TrojanDownloader:JS/Agent.DA”
[ McAfee ], “VBS/Psyme”
[ Sophos ], “Mal/Psyme-A”
[ HBEDV ], “HEUR/Exploit.HTML”
[ Rising ], “Trojan.DL.JS.Agent.ldf”
[ Ewido ], “Downloader.Agent.gr”

徵才訊息:誠徵研發人員

2007 年 05 月 30 日 – 10:29:00

哪個學校畢業並不重要,只要您對自己有信心、對資訊安全有熱誠、對新的領域有學習心,那您就是我們想要找的人才。

徵才公司:Malware-Test Lab (梅爾斯特系統有限公司)
職務性質:全職或工讀皆可
需求人數:
2~3 人
休假制度:週休二日 (正常上下班)

Web Programmer:
1. 資訊相關科系畢業
2. Database, Programming (must: HTML, PHP, .NET nice to have’s: Python, Perl), XML, etc.

Developer:
1. 資訊相關科系畢業
2. C/C++ programming experiences
3. Software design experiences
4. Network programming experiences

我們公司提供兩種報酬方式:

  1. 成為創業夥伴:你只會拿到可能成為壁紙(不過機率極低)的技術入股股份,正如預售屋,兩年內,你就可以獲得比你現在工作高出N倍的報酬。
  2. 成為員工:你會得到與市場水準差不多的報酬與福利。

如果您對這工作有高度的興趣,請將您的履歷表及選擇哪種報酬方式,寄到下面的電子郵件信箱,並留下您的聯絡方式,我會儘快與您聯絡。

階梯數位學院網站被植入惡意連結

2007 年 05 月 30 日 – 09:26:00

階梯數位學院網站被植入惡意連結,此惡意程式為 Lineage 和 Agent 變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: Jimau)

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:

[DLL injection]
C:\WINDOWS\Help\B7C8A6484EE3.dll

[Added file]
C:\autorun.inf
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\desktop.ini
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\h[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\gmsex[1].exe
C:\Shell.exe
C:\WINDOWS\Help\autorun.inf
C:\WINDOWS\Help\B7C8A6484EE3.dll
C:\WINDOWS\Help\B7C8A6484EE3.exe

[ Added COM/BHO ]
{6FC2B704-28A3-464F-AEA2-034E1107B0C4}-C:\WINDOWS\Help\B7C8A6484EE3.dll

到目前為止 (2007/5/30 @ 09:29),下面的防毒軟體可以偵測到這些惡意檔案:

B7C8A6484EE3.exe:
[ Trend ], “TROJ_AGENT.IM”
gmsex[1].exe:
[ Trend ], “TROJ_AGENT.IM”
h[1].htm:
[ Trend ], “VBS_PSYME.ALS”
Shell.exe:
[ Trend ], “TROJ_AGENT.IM”
B7C8A6484EE3.dll:
[ Microsoft ], “PWS:Win32/Gamania.gen!B”
[ Kaspersky ], “PAK:PE_Patch.PECompact, PAK:PecBundle, PAK:PECompact, PAK:PE_Patch.MaskPE”
[ Panda ], “Suspicious file”
[ Nod32 ], “a variant of Win32/PSW.Lineage.DN trojan”
[ HBEDV ], “HEUR/Malware”
autorun.inf:
[ McAfee ], “W32/USBAgent!inf”

國立聯合大學教務處網站被植入惡意連結

2007 年 05 月 30 日 – 08:59:00

國立聯合大學教務處網站被植入惡意連結,此惡意程式為 Lineage 變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: ~ ~)

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:

[Added process]
C:\WINDOWS\avp.exe

[Added service]
NAME: VGADown
DISPLAY: Audio Adapter
FILE: C:\WINDOWS\avp.exe

NAME: WS2IFSL (這是正常的服務)
DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment
FILE: \SystemRoot\System32\drivers\ws2ifsl.sys

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\update[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\mystat[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\test[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\update[1].htm
C:\WINDOWS\avp.exe
C:\WINDOWS\system32\od2media.dll

[Added LSP]
ID: 1012
NAME: MSAFD Tcpip [RAW/IP] (連結至 C:\WINDOWS\system32\od2media.dll)

ID: 1013
NAME: MSAFD Tcpip [TCP/IP] (連結至 C:\WINDOWS\system32\od2media.dll)

到目前為止 (2007/5/30 @ 09:29),下面的防毒軟體可以偵測到這些惡意檔案:

avp.exe:
[ Trend ], “TSPY_ONLINEG.ASH”
od2media.dll:
[ Trend ], “TSPY_ONLINEG.BHX”
update[1].exe:
[ Trend ], “TROJ_NSANTI.CE”
update[1].htm:
[ Trend ], “HTML_AGENT.AACU”

得利影視娛樂網又被值入惡意連結

2007 年 05 月 28 日 – 07:22:00

得利影視娛樂網又被值入惡意連結,此惡意程式為 DELF 和 DOWNLOADER 變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為 (會重新開機):

[Added file]
C:\1.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\g0ld.com
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\System32[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\d[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\qsvj[1].htm
C:\pass.dic
C:\Program Files\Common Files\System\commond.pif
C:\WINDOWS\system32\Shell.exe
C:\WINDOWS\system32\Shell.pci

到目前為止 (2007/5/27 @ 23:44),下面的防毒軟體可以偵測到這些惡意檔案:

qsvj[1].htm:
[ McAfee ], “ObfuscatedHtml”
[ Norman ], “Trojan AsciiExploit.gen”
Shell.exe:
[ Kaspersky ], “PAK:PE_Patch.UPX, PAK:UPX”
[ McAfee ], “[GenUnp]:New Malware.b !!”
[ Sophos ], “Mal/Basine-A”
[ Nod32 ], “a variant of Win32/Delf.BO worm”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Delphi.Downloader.Gen”
[ Norman ], “[Heuristic Sandbox detection]:Virus W32/Malware”
System32[1].exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Beta_Gen ], “Possible_MLWR-5″
[ Symantec ], “Bloodhound.Packed.29″
[ McAfee ], “New Malware.bx !!”
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Virus W32/Viking.gen5″
commond.pif:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Beta_Gen ], “Possible_MLWR-5″
[ Symantec ], “Bloodhound.Packed.29″
[ McAfee ], “New Malware.bl !!”
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Virus W32/Viking.gen5″
d[1].exe:
[ Kaspersky ], “PAK:PE_Patch.UPX, PAK:UPX”
[ McAfee ], “[GenUnp]:New Malware.b !!”
[ Sophos ], “Mal/Basine-A”
[ Nod32 ], “a variant of Win32/Delf.BO worm”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Delphi.Downloader.Gen”
[ Norman ], “[Heuristic Sandbox detection]:Virus W32/Malware”
g0ld.com:
[ Kaspersky ], “PAK:PE_Patch.UPX, PAK:UPX”
[ McAfee ], “[GenUnp]:New Malware.b !!”
[ Sophos ], “Mal/Basine-A”
[ Nod32 ], “a variant of Win32/Delf.BO worm”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Delphi.Downloader.Gen”
[ Norman ], “[Heuristic Sandbox detection]:Virus W32/Malware”
pass.dic:
[ Microsoft ], “Worm:Win32/Datheens!pwd”
[ McAfee ], “W32/Emerleox.worm”
[ Nod32 ], “Win32/Hensis.A worm”

國際電子戰協會中華民國總會網站被植入惡意連結

2007 年 05 月 25 日 – 10:26:00

國際電子戰協會中華民國總會網站被植入惡意連結,此惡意程式結合間諜軟體和 Agent 的變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號、密碼和監控系統)。另外,不曉得台灣的軍事單位有沒有常常瀏覽此網站,如果有的話,那可要小心了對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝

惡意連結是放置在首頁 (可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:

[DLL injection]
C:\Documents and Settings\Administrator\Desktop\mlang.dll
C:\WINDOWS\system32\rsvp32_2.dll

[Added service]
NAME: SysmonLogTapiSrv
DISPLAY: Performance Logs and Alerts SysmonLogTapiSrv
FILE: C:\WINDOWS\system32\6to4svcr.exe srv

NAME: WS2IFSL (這是正常的服務)
DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment
FILE: \SystemRoot\System32\drivers\ws2ifsl.sys

[Added file]
C:\Documents and Settings\Administrator\Desktop\mlang.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\1.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\5.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\6.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\xaC896.tmp
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\Dropper[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\45555_sn[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\zzz[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\inexed[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\zupastik[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\file[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\svchost[1].exe
C:\WINDOWS\system32\6to4svcr.exe
C:\WINDOWS\system32\77089387.dat
C:\WINDOWS\system32\ipv6monl.dll
C:\WINDOWS\system32\msvcrl.dll
C:\WINDOWS\system32\rsvp32_2.dll
C:\WINDOWS\system32\sporder.dll

[Added LSP]
ID: 1012
NAME: MzName (連結至 C:\WINDOWS\system32\rsvp32_2.dll)

ID: 1013
NAME: LAYERED MSAFD Tcpip [TCP/IP]

ID: 1014
NAME: LAYERED MSAFD Tcpip [UDP/IP]

ID: 1015
NAME: LAYERED MSAFD Tcpip [RAW/IP]

ID: 1016
NAME: LAYERED RSVP UDP Service Provider

ID: 1017
NAME: LAYERED RSVP TCP Service Provider

ID: 1018
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{5D08099D-7943-4EA6-A096-1B462434FA54}] SEQPACKET 0

ID: 1019
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{5D08099D-7943-4EA6-A096-1B462434FA54}] DATAGRAM 0

ID: 1020
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{52F2F2DC-BD23-4F3F-B226-3D35AF867824}] SEQPACKET 1

ID: 1021
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{52F2F2DC-BD23-4F3F-B226-3D35AF867824}] DATAGRAM 1

ID: 1022
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B4131A8-C8E1-4CFF-996B-D8AFB89B3607}] SEQPACKET 2

ID: 1023
NAME: LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B4131A8-C8E1-4CFF-996B-D8AFB89B3607}] DATAGRAM 2

ID: 1024
NAME: LAYERED MzName

到目前為止 (2007/5/24 @ 09:09),下面的防毒軟體可以偵測到這些惡意檔案:

msvcrl.dll:
[ Trend ], “TROJ_Generic”
svchost[1].exe:
[ Trend ], “TSPY_CEDA.AB”
zupastik[1].exe:
[ Trend ], “TSPY_BZUB.A”
zzz[1].exe:
[ Trend ], “TSPY_BZUB.A”
5.tmp:
[ Trend ], “TSPY_BZUB.A”
6.tmp:
[ Trend ], “TSPY_BZUB.A”
ipv6monl.dll:
[ Trend ], “TSPY_BZUB.A”
rsvp32_2.dll:
[ Symantec ], “Trojan.Mespam”
[ Microsoft ], “[->(Aspack v2.12)]:Trojan:Win32/Mespam.B”
[ Kaspersky ], “PAK:ASPack, Trojan-Proxy.Win32.Jaber.a”
[ McAfee ], “Spam-Mespam”
[ Sophos ], “Troj/SpamToo-AM”
[ Panda ], “Trj/Spammer.AAZ”
[ Nod32 ], “a variant of Win32/TrojanProxy.Jaber trojan”
[ Fortinet ], “W32/SpamToo.A!tr”
[ HBEDV ], “TR/Faktura.A”
[ Ewido ], “Proxy.Jaber.a”
4.tmp:
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack, Trojan-Spy.Win32.Webmoner.cg”
[ McAfee ], “New Malware.aj !!”
[ Sophos ], “Mal/Packer”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Crypted”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
45555_sn[1].exe:
[ Symantec ], “Trojan.Goldun”
[ Kaspersky ], “PAK:UPX, Trojan-Spy.Win32.Goldun.ms”
[ McAfee ], “Generic PWS”
[ Panda ], “Trj/Goldun.OZ”
[ Nod32 ], “Win32/Spy.Goldun.NBC trojan”
[ Fortinet ], “Spy/Goldun”
[ HBEDV ], “TR/Crypt.FKM.Gen”
[ Norman ], “Trojan W32/Goldun.ARK”
[ Ewido ], “Logger.Goldun.ms”
Dropper[1].exe:
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack, Trojan-Spy.Win32.Webmoner.cg”
[ McAfee ], “New Malware.aj !!”
[ Sophos ], “Mal/Packer”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Crypted”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
file[1].exe:
[ Kaspersky ], “Trojan-Downloader.Win32.Agent.bkm”
[ McAfee ], “Downloader-BBS”
[ Sophos ], “Mal/Clagger-D”
[ HBEDV ], “TR/Dldr.Agent.bkm.5″
[ Norman ], “Trojan W32/Agent.BPCB”
[ Ewido ], “Downloader.Agent.bkm”
mlang.dll:
[ Fortinet ], “suspicious”
/> [ HBEDV ], “HEUR/Crypted”
[ Ewido ], “Logger.Webmoner.cc”

台灣電子地圖服務網網站又被植入惡意連結

2007 年 05 月 24 日 – 09:09:00

**高度危險網站:常常被植入惡意連結,列入網站黑名單,不建議瀏覽此網站**
台灣電子地圖服務網網站又被植入惡意連結,大部分的防毒軟體認不出此惡意程式,最近有瀏覽這個網頁的網友 (請各位使用其他的電子地圖,如果各位還是使用此電子地圖,那就是自尋死路),應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝

惡意連結是放置在 index.asp (可能要仔細檢查一下囉) 中的 (惡意連結被編碼過):

執行之後,有下面的行為:

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\play[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\play-a[1].png
C:\WINDOWS\Help\019JDNCT.dll
C:\WINDOWS\Help\019JDNCT.exe

[Added COM/BHO]
{79921D3F-7537-463E-9E38-CD503A8FA485}-C:\WINDOWS\help\019JDNCT.dll

到目前為止 (2007/5/24 @ 09:08),下面的防毒軟體可以偵測到這些惡意檔案:

019JDNCT.dll:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “PWS:Win32/Frethog.C”
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
019JDNCT.exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “PWS:Win32/Frethog.C”
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
play-a[1].png:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “PWS:Win32/Frethog.C”
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”

OKWAP 英華達網站又被植入惡意連結

2007 年 05 月 21 日 – 15:21:00

OKWAP 英華達網站又被植入惡意連結,此惡意程式為 ADWARE_RUGO 和 QQPass 變種,稍後會更新資訊,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個 網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝

惡意連結是放置在 event_hot.asp (可能要仔細檢查一下或重新安裝) 中的:

執行之後,有下面的行為 (值入很多東西,情況滿慘的):

[Added process]
C:\WINDOWS\IMEINPUTS.EXE
C:\WINDOWS\system32\SVCH0ST.EXE
C:\WINDOWS\system32\f91b.exe

[DLL injection]
C:\Documents and Settings\Administrator\Local Settings\Temp\SVCH0ST.exe
C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys
C:\WINDOWS\preupd.dll
C:\WINDOWS\system32\5E9F0D5.DLL
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\nwizAsktao.dll
C:\WINDOWS\system32\nwizqjsj.dll
C:\WINDOWS\system32\SVCH0ST.EXE
C:\WINDOWS\system32\upxdnd.dll

[Added service]
NAME: 2FED61CD
DISPLAY: 2FED61CD
FILE: C:\WINDOWS\system32\AE9C6AE4.EXE -d

NAME: fast
DISPLAY: Fast Client
FILE: C:\WINDOWS\system32\f91b.exe

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\009.mdb
C:\Documents and Settings\Administrator\Local Settings\Temp\bofang.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\GTIAPI.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\hbcmd.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\IECONFIG.EXE
C:\Documents and Settings\Administrator\Local Settings\Temp\lfrmewrk.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\mhso.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\mhso0.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\RGInstall.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\SPy.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\SVCH0ST.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\zhu3.com
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\ldasd[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\pop[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\SC0NFIG1[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\SPy[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\007[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\658359[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\bind_50423[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\IECOFIG[1].EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\s[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\wanmeishijie[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\yun[1].js
:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\596139[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\boolan64[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\IECONFIG[1].EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\SPSJ[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\SVCH0ST[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\cj[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\IEXPL0R[1].EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\MCONFIG[1].EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\TIMPLATF0RM[1].exe
C:\Program Files\Internet Explorer\Connection Wizard\isignup.dll
C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys
C:\WINDOWS\0e460.dat
C:\WINDOWS\4603f.avi
C:\WINDOWS\603fa.jpg
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\e4603.cfg
C:\WINDOWS\IMEINPUTS.EXE
C:\WINDOWS\mppds.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\preupd.dll
C:\WINDOWS\system32\1-716696
C:\WINDOWS\system32\5E9F0D5.DLL
C:\WINDOWS\system32\7df9.dll
C:\WINDOWS\system32\91b6.dll
C:\WINDOWS\system32\AE9C6AE4.EXE
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\ctfnom.exe
C:\WINDOWS\system32\df91.dll
C:\WINDOWS\system32\drivers\usbinte.sys
C:\WINDOWS\system32\f91b.exe
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\nwizAsktao.dll
C:\WINDOWS\system32\nwizAsktao.exe
C:\WINDOWS\system32\nwizqjsj.dll
C:\WINDOWS\system32\nwizqjsj.exe
C:\WINDOWS\system32\nwizwmsjs.dll
C:\WINDOWS\system32\nwizwmsjs.exe
C:\WINDOWS\system32\SVCH0ST.EXE
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\upxdnd.exe

到目前為止 (2007/5/21 @ 14:25),下面的防毒軟體可以偵測到這些惡意檔案 (除了 ANI 的檔案外):

SC0NFIG1[1].exe:
[ Trend ], “TSPY_ONLINEG.BYF”
wanmeishijie[1].exe:
[ Trend ], “TROJ_INFOSTEA.BI”
0e460.dat:
[ Trend ], “ADW_RUGO.A”
7df9.dll:
[ Trend ], “ADW_RUGO.A”
bofang.dll:
[ Trend ], “ADW_RUGO.A”
boolan64[1].exe:
[ Trend ], “TROJ_AGENT.AAEO”
df91.dll:
[ Trend ], “ADW_RUGO.A”
e4603.cfg:
[ Trend ], “ADW_RUGO.A”
f91b.exe:
[ Trend ], “ADW_RUGO.A”
hbcmd.dll:
[ Trend ], “ADW_RUGO.
A”
IECOFIG[1].EXE:
[ Trend ], “TROJ_INFOSTEA.BE”
lfrmewrk.exe:
[ Trend ], “ADW_RUGO.A”
msccrt.exe:
[ Trend ], “TSPY_ONLINEG.BYF”
nwizAsktao.exe:
[ Trend ], “TROJ_INFOSTEA.BE”
nwizqjsj.exe:
[ Trend ], “TROJ_INFOSTEA.BI”
RGInstall.dll:
[ Trend ], “ADW_RUGO.A”
SPSJ[1].exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ Sophos ], “Mal/Behav-027″
[ Panda ], “Suspicious file”
[ Nod32 ], “a variant of Win32/PSW.Agent.NEW trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Ewido ], “Trojan.WOW.qp”
SPy.exe:
[ Microsoft ], “[->(UPX)]:TrojanDropper:Win32/Dowque.A”
[ Kaspersky ], “PAK:UPX”
[ Sophos ], “[FILE:0000]:Mal/QQPass-B”
[ Nod32 ], “probably a variant of Win32/PSW.QQShou trojan”
[ Fortinet ], “W32/QQShou.5D42!tr.pws”
[ HBEDV ], “DR/Delphi.Gen”
[ Norman ], “Trojan W32/Malware.TQE”
SVCH0ST.exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Virus W32/Viking.gen5″
TIMPLATF0RM[1].exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ Sophos ], “Mal/Behav:06″
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.SunOnline.n”
upxdnd.dll:
[ Symantec ], “Infostealer.Gampass”
[ Microsoft ], “PWS:Win32/Frethog.A!dll”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ McAfee ], “PWS-LegMir.dll”
[ Sophos ], “Troj/PSW-Gen”
[ Nod32 ], “probably a variant of Win32/Genetik trojan”
[ HBEDV ], “HEUR/Malware”
upxdnd.exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ Sophos ], “Mal/Behav:06″
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.SunOnline.n”
usbinte.sys:
[ HBEDV ], “TR/Rootkit.Gen”
5E9F0D5.dll:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ Nod32 ], “probably a variant of Win32/Agent.NEO trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Norman ], “Trojan Hupigon.gen66″
007[1].exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Virus W32/Viking.gen5″
009.mdb:
[ Microsoft ], “Worm:Win32/Oanum!ini”
91b6.dll:
[ McAfee ], “Adware-BDSearch”
[ Panda ], “Adware/Sohu”
[ Rising ], “Trojan.Mnless.ksj”
[ Ewido ], “Adware.WSearch”
AE9C6AE4.exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ McAfee ], “New Malware.dm !!”
[ Panda ], “Suspicious file”
[ Nod32 ], “a variant of Win32/Agent.NEO trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Crypted”
[ Norman ], “Trojan Hupigon.gen66″
bind_50423[1].exe:
[ Kaspersky ], “PAK:PE_Patch”
cj[1].exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ McAfee ], “New Malware.dm !!”
[ Panda ], “Suspicious file”
[ Nod32 ], “a variant of Win32/Agent.NEO trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Crypted”
[ Norman ], “Trojan Hupigon.gen66″
cmdbcs.dll:
[ Symantec ], “Infostealer.Gampass”
[ Microsoft ], “PWS:Win32/Lmir.gen!B”
[ McAfee ], “PWS-LegMir.dll”
[ Sophos ], “Troj/PSW-Gen”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.OnlineGames.bog”
cmdbcs.exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ McAfee ], “PWS-LegMir.gen.b”
[ Sophos ], “Mal/Behav:06″
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.SunOnline.n”
ctfnom.exe:
[ Kaspersky ], “PAK:NSPack, Trojan-Downloader.Win32.Small.czl”
[ McAfee ], “New Malware.aq !!”
[ Sophos ], “Mal/Packer”
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.FKM.Gen”
GTIAPI.dll:
[ McAfee ], “Adware-BDSearch”
[ Panda ], “Adware/Sohu”
[ Rising ], “Trojan.Mnless.ksj”
[ Ewido ], “Adware.WSearch”
IECONFIG.EXE:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:UPX”
[ Sophos ], “Mal/Behav-044″
[ Panda ], “Suspicious file”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Dldr.Agent.20827″
IECONFIG[1].EXE:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:UPX”
[ Sophos ], “Mal/Behav-044″
[ Panda ], “Suspicious file”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Dldr.Agent.20827″
IEXPL0R[1].EXE:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ McAfee ], “PWS-LegMir.gen.b”
[ Sophos ], “Mal/Behav:06″
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.SunOnline.n”
IMEINPUTS.EXE:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:UPX”
[ Sophos ], “Mal/Behav-044″
[ Panda ], “Suspicious file”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Dldr.Agent.20827″
isignup.dll:
[ Microsoft ], “[->(UPX)]:TrojanDropper:Win32/Dowque.A”
[ Kaspersky ], “PAK:UPX”
[ Sophos ], “[FILE:0000]:Mal/QQPass-B”
[ Nod32 ], “probably a variant of Win32/PSW.QQShou trojan”
[ Fortinet ], “W32/QQShou.5D42!tr.pws”
[ HBEDV ], “DR/Delphi.Gen”
[ Norman ], “Trojan W32/Malware.TQE”
isignup.sys:
[ Sophos ], “Mal/QQPass
-B”
[ Nod32 ], “probably a variant of Win32/PSW.QQShou trojan”
[ Fortinet ], “W32/QQShou.5D42!tr.pws”
[ HBEDV ], “HEUR/Malware”
ldasd[1].exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ Sophos ], “Mal/Behav:06″
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.SunOnline.n”
MCONFIG[1].EXE:
[ Kaspersky ], “PAK:NSPack, Trojan-Downloader.Win32.Small.czl”
[ McAfee ], “New Malware.aq !!”
[ Sophos ], “Mal/Packer”
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.FKM.Gen”
mhso0.dll:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Virus W32/Viking.gen5″
mhso.exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Virus W32/Viking.gen5″
mppds.dll:
[ Symantec ], “Infostealer.Gampass”
[ Microsoft ], “PWS:Win32/Lmir.gen!B”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ McAfee ], “PWS-LegMir.dll”
[ Sophos ], “Troj/PSW-Gen”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.WoWar.ahi”
mppds.exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.tl”
[ Sophos ], “Mal/Behav:06″
[ Nod32 ], “probably unknown NewHeur_PE virus [7]“
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.SunOnline.n”
msccrt.dll:
[ Symantec ], “Infostealer.Gampass”
[ Microsoft ], “PWS:Win32/Lmir.gen!B”
[ McAfee ], “PWS-LegMir.dll”
[ Sophos ], “Troj/PSW-Gen”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.CabalOnline.aia”
nwizAsktao.dll:
[ Kaspersky ], “Trojan-PSW.Win32.WOW.qp”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.Asktao.e”
nwizqjsj.dll:
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.rc”
[ Panda ], “Suspicious file”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.OnlineGames.boj”
[ Ewido ], “Trojan.Nilage.bjp”
nwizwmsjs.dll:
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.sw”
[ Panda ], “Suspicious file”
[ Nod32 ], “Win32/PSW.Agent.NFD trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Rising ], “Trojan.PSW.WorldOnline.gi”
[ Ewido ], “Trojan.OnLineGames.sw”
nwizwmsjs.exe:
[ Symantec ], “Infostealer.Gampass”
[ Kaspersky ], “PAK:PE_Patch, PAK:UPack”
[ Sophos ], “Mal/Behav-027″
[ Panda ], “Suspicious file”
[ Nod32 ], “a variant of Win32/PSW.Agent.NEW trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “HEUR/Malware”
[ Norman ], “Security Risk W32/Suspicious_U.gen”
[ Ewido ], “Trojan.WOW.qp”
preupd.dll:
[ Symantec ], “Downloader”
[ Kaspersky ], “Trojan-PSW.Win32.OnLineGames.qw”
[ Panda ], “Trj/INService.BL”
[ Fortinet ], “W32/OnLineGames.QW!tr.pws”
[ HBEDV ], “TR/Dldr.Agent.20827″
[ Rising ], “Trojan.PSW.ROCOnline.fp”
[ Ewido ], “Trojan.OnLineGames.qw”

HitoCard 喜多喜卡網又被植入惡意連結

2007 年 05 月 21 日 – 15:14:00

**高度危險網站:常常被植入惡意連結,列入網站黑名單,不建議瀏覽此網站**
HitoCard 喜多喜卡網又被植入惡意連結,此惡意程式為 Lineage 變種,最近有瀏覽這個網站的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。另外,此惡意程式是利用微軟所公佈ANI 的安全漏洞 (Vulnerability in Windows Animated Cursor Handling)對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:

[DLL injection]
C:\WINDOWS\Web\printers\images\59594F8550.dll

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\ie.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\ie.vbs
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\cao714[1].gif
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\swallow[2].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\help2[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\m[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\index6142[1].htm
C:\WINDOWS\Web\printers\images\59594F8550.dll
C:\WINDOWS\Web\printers\images\59594F8550.exe

[ Added COM/BHO ]
{11374E20-CFCA-473D-A81E-233D28856E23}-C:\WINDOWS\Web\printers\images\59594F8550.dll

到目前為止 (2007/5/21 @ 14:46),下面的防毒軟體可以偵測到這些惡意檔案 (除了 ANI 的檔案外):

59594F8550.exe:
[ Trend ], “TSPY_LINEAGE.FJM”
ie.exe:
[ Trend ], “TSPY_LINEAGE.FJM”
index6142[1].htm:
[ Trend ], “VBS_PSYME.ACO”
m[1].exe:
[ Trend ], “TSPY_LINEAGE.FJM”
59594F8550.dll:
[ Trend ], “Possible_Infostl”
help2[1].htm:
[ Fortinet ], “VBS/Psyme.DN!tr.dldr”
swallow[2].htm:
[ McAfee ], “ObfuscatedHtml”

Audi Taiwan 網站被植入惡意連結

2007 年 05 月 21 日 – 13:21:00

Audi Taiwan 網站被植入惡意連結,此惡意程式為 TROJ_NSPM,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息。另外,此惡意程式是利用微軟所公佈ANI 的安全漏洞 (Vulnerability in Windows Animated Cursor Handling)對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: Sung)

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

執行之後,有下面的行為:

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\mystat[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\vip[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\css[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\vip[1].js
C:\WINDOWS\Debug\UserMode\3083516.dll
C:\WINDOWS\Debug\UserMode\3083516.exe
C:\WINDOWS\rising659.exe

[ Added COM/BHO ]
{A4A0D94D-2566-4876-9FC4-C26C6E107C66}-C:\WINDOWS\debug\userMode\3083516.dll

到目前為止 (2007/5/21 @ 09:18),下面的防毒軟體可以偵測到這些惡意檔案 (除了 ANI 的檔案外):

3083516.exe:
[ Trend ], “TROJ_NSPM.FN”
css[1].exe:
[ Trend ], “TROJ_NSPM.FN”
rising659.exe:
[ Trend ], “TROJ_NSPM.FN”
3083516.dll:
[ Trend ], “Possible_Infostl”
vip[1].htm:
[ Kaspersky ], “Trojan-Downloader.JS.Agent.gj”
[ Ewido ], “Downloader.Agent.fm”

國立政治大學心理學系暨心理學研究所網站被植入惡意連結

2007 年 05 月 20 日 – 11:28:00

國立政治大學心理學系暨心理學研究所網站被植入惡意連結,此惡意程式為 GrayBird 和 Lineage 的變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: wfx)

惡意連結是放置英文首頁 (可能要仔細檢查一下囉) 中的:

惡意程式碼的一部份為:

當執行此惡意程式時,會產生應用程式錯誤的訊息:

執行之後,有下面的行為:

[Added process]
C:\WINDOWS\avp.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\winlogin.exe

[DLL injection]
C:\Documents and Settings\Administrator\Local Settings\Temp\winlogin.exe
C:\WINDOWS\system32\tf2sound.dll

[Added service]
NAME: GrayPigeon
DISPLAY: GrayPigeon
FILE: C:\WINDOWS\winlogone.exe

NAME: VGADown
DISPLAY: Audio Adapter
FILE: C:\WINDOWS\avp.exe

NAME: WS2IFSL (這是正常的服務)
DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment
FILE: \SystemRoot\System32\drivers\ws2ifsl.sys

[Added file]
C:\Deleteme.bat
:\Documents and Settings\Administrator\Local Settings\Temp\winlogin.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\server1[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\2[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\12[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\hker[3].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\hker[4].htm
C:\Program Files\Common Files\System\commond.pif
C:\update~1.exe
C:\update~2.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\system32\delplme.bat
C:\WINDOWS\system32\tf2sound.dll
C:\WINDOWS\winlogone.exe

[Added LSP]
ID: 1012
NAME: MSAFD Tcpip [RAW/IP] (C:\WINDOWS\system32\tf2sound.dll)

ID: 1013
NAME: MSAFD Tcpip [TCP/IP] (C:\WINDOWS\system32\tf2sound.dll)

到目前為止 (2007/5/19 @ 15:30),下面的防毒軟體可以偵測到這些惡意檔案:

12[1].exe:
[ Trend ], “TROJ_MARAN.IY”
avp.exe:
[ Trend ], “TSPY_MARAN.HC”
hker[3].htm:
[ Trend ], “VBS_SMALL.GJD”
server1[1].exe:
[ Trend ], “TSPY_LINEAGE.GEN”
tf2sound.dll:
[ Trend ], “TSPY_MARAN.LE”
winlogin.exe:
[ Trend ], “TSPY_LINEAGE.GEN”
2[1].exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ Kaspersky ], “Trojan-PSW.Win32.Maran.dz”
[ Nod32 ], “a variant of Win32/PSW.Maran trojan”
[ Fortinet ], “W32/Maran.DZ!tr.pws”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Trojan Hupigon.gen66″
[ Rising ], “Trojan.IMMSG.TBMSG.eu”
[ Ewido ], “Trojan.Maran.dz”
commond.pif:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “TrojanDropper:Win32/Hupigon.gen!A”
[ Kaspersky ], “Backdoor.Win32.Hupigon.bdl”
[ McAfee ], “BackDoor-AWQ”
[ Sophos ], “Mal/GrayBird”
[ Alwil ], “Win32:Hupigon-AK [Trj]“
[ Nod32 ], “a variant of Win32/Hupigon trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “BDS/Hupigon.bhi”
[ Norman ], “Trojan W32/Hupigon.AROI”
[ Rising ], “Trojan.IMMSG.TBMSG.eu”
[ Ewido ], “Backdoor.Hupigon.awp”
update~1.exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ Nod32 ], “a variant of Win32/Hupigon trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Trojan Hupigon.gen66″
[ Rising ], “Trojan.IMMSG.TBMSG.eu”
[ Ewido ], “Trojan.OnLineGames.es”
update~2.exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ Kaspersky ], “Trojan-PSW.Win32.Maran.dz”
[ Nod32 ], “a variant of Win32/PSW.Maran trojan”
[ Fortinet ], “W32/Maran.DZ!tr.pws”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Trojan Hupigon.gen66″
[ Rising ], “Trojan.IMMSG.TBMSG.eu”
[ Ewido ], “Trojan.Maran.dz”
1[1].exe:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “VirTool:Win32/Obfuscator.A”
[ Nod32 ], “a variant of Win32/Hupigon trojan”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”
[ Norman ], “Trojan Hupigon.gen66″
[ Rising ], “Trojan.IMMSG.TBMSG.eu”
[ Ewido ], “Trojan.OnLineGames.es”

社團法人中華民國管理科學學會網站被植入惡意連結

2007 年 05 月 19 日 – 10:52:00

社團法人中華民國管理科學學會網站被植入惡意連結,防毒軟體無法偵測此惡意程式,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息。另外,此惡意程式是利用微軟所公佈ANI 的安全漏洞 (Vulnerability in Windows Animated Cursor Handling) (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: ychsiao)

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

惡意程式碼的一部份為:

當執行此惡意程式後,會產生應用程式錯誤的訊息:

執行之後,有下面的行為:

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\vip[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\vip[1].js
C:\WINDOWS\rising413.exe
C:\WINDOWS\rising613.exe

到目前為止 (2007/5/18 @ 23:13),下面的防毒軟體可以偵測到這些惡意檔案 (除了 ANI 的檔案外):

vip[1].htm:
[ Ewido ], “Downloader.Agent.fm”

公告:台灣地區惡意程式與駭客攻擊行為誘捕系統免費架設計畫

2007 年 05 月 18 日 – 15:56:00

計畫主旨:
台灣地區惡意程式所佔的比率節節高升,尤其是以校園為大宗。在普遍缺乏惡意程式基本知識的校園內,希望透過架設惡意程式誘捕系統來誘捕惡意程式與駭客攻擊行為,讓參與單位清楚掌握校園內惡意程式與駭客攻擊的來源,然後,對症下藥,以收成效。

計畫內容:
一、主辦單位:Malware-Test Lab
二、執行單位:Malware-Test Lab
三、協辦單位:參予此項計畫之大專院校
四、贊助單位:尚無 (如要贊助此項計畫,請用 E-mail 聯繫我)
六、執行時間:暫定96年6月1日至96年6月30日
七、預定參與學校:接洽中

預期效益與影響:
執行單位將會定期提供相關數據與報告給參與單位,參與單位可以利用這些資訊,清楚掌控校園內惡意行為之來源,亦可利用這些資訊做相關研究或做日後購買相關安全軟體之參考,以減少校園內惡意程式氾濫之問題。

參與單位 (初期以學校為主):
完全免費 (原則上,一個單位或學校,架設一個誘捕系統)。參與單位需提供一個真實 IP 與一個或多個虛擬 IP,可以對外連線至管理系統。

Q&A:

Q:此系統會參與單位會有何影響呢?
A:此系統並不會主動發送任何封包,對參與單位之網路無任何影響。

Q:此系統使用哪種作業系統呢?
A:可能是 Debian Linux 或是 Red Hat Linux。

最後,想要參加此計畫之單位 (名額有限),可以用 E-mail 聯繫我。另外,請各位幫忙將此訊息傳送給大專院校網路管理人員,謝謝

年代售票網站又被值入惡意連結

2007 年 05 月 17 日 – 10:12:00

**高度危險網站:常常被植入惡意連結,列入網站黑名單,不建議瀏覽此網站**
年代售票網站又被值入惡意連結,此惡意程式 FRETHOG 的變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息。對於一個這樣的網站,竟然這麼容易被入侵,會員的資料也許早已經被竊取了,難道他們不需要檢討嗎?也許刑事局或調查局應該要調查是否有消費者資料被竊取的情形。 對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: Jimau)

惡意連結是放置在首頁 (可能要仔細檢查一下囉) 中的:

惡意程式碼的一部份為:

執行之後,有下面的行為:

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\play[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\top[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\play-a[1].png
C:\WINDOWS\Help\90GTUABC.dll
C:\WINDOWS\Help\90GTUABC.exe

[ Added COM/BHO ]
{79921D3F-7537-463E-9E38-CD503A8FA485}-C:\WINDOWS\help\90GTUABC.dll

到目前為止 (2007/5/17 @ 08:53),下面的防毒軟體可以偵測到這些惡意檔案:

play-a[1].png:
[ Trend ], “TSPY_FRETHOG.GI”
90GTUABC.exe:
[ Trend ], “TSPY_FRETHOG.GI”
90GTUABC.dll:
[ Alpha_Gen ], “Possible_MLWR-5″
[ Microsoft ], “PWS:Win32/Frethog.C”
[ Sophos ], “Mal/EncPk-F”
[ Fortinet ], “suspicious”
[ HBEDV ], “TR/Crypt.NSPM.Gen”

休閒農業宜蘭旅遊網網站被植入惡意連結

2007 年 05 月 16 日 – 08:22:00

休閒農業宜蘭旅遊網網站被植入惡意連結,此惡意程式為 MARAN 的變種,最近有瀏覽這個網頁的網友,應該要盡速檢查自己的電腦,請各位暫時不要瀏覽這個網站,以免中毒,等確認他們已經修復後,會在此更新訊息 (此惡意程式應該會偷帳號與密碼)。對此有興趣的網友,可以在 VMWare 上測試一下,然後,回報修復的情形,而且,幫忙通知他們,謝謝。(Credit: Jimau)

惡意連結是放置在首頁 (其他頁面可能要仔細檢查一下囉) 中的:

惡意程式碼的一部份為:

執行之後,有下面的行為 (會造成網站中斷):

[Added process]
C:\WINDOWS\avp.exe

[DLL injection]
C:\WINDOWS\system32\od7media.dll

[Added service]
NAME: VGADown
DISPLAY: Audio Adapter
FILE: C:\WINDOWS\avp.exe

NAME: WS2IFSL (正常的服務)
DISPLAY: Windows Socket 2.0 Non-IFS Service Provider Support Environment
FILE: \SystemRoot\System32\drivers\ws2ifsl.sys

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\520[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\3[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\html[1].htm
C:\WINDOWS\avp.exe
C:\WINDOWS\system32\od7media.dll

[Added LSP]
ID: 1012
NAME: MSAFD Tcpip [RAW/IP] (連結至 C:\WINDOWS\system32\od7media.dll)

ID: 1013
NAME: MSAFD Tcpip [TCP/IP] (連結至 C:\WINDOWS\system32\od7media.dll)

到目前為止 (2007/5/15 @ 16:50),下面的防毒軟體可以偵測到這些惡意檔案:

520[1].exe:
[ Trend ], “TSPY_MARAN.LG”
avp.exe:
[ Trend ], “TSPY_MARAN.LG”
od7media.dll:
[ Trend ], “TSPY_MARAN.LG”
3[1].htm:
[ Trend ], “JS_PSYME.ALQ”