apuromafo
December 10th, 2008, 23:22
unpacked ep
004109CC >/$ 55 PUSH EBP
004109CD |. 8BEC MOV EBP,ESP
004109CF |. 6A FF PUSH -1
004109D1 |. 68 D0854100 PUSH malware_.004185D0
004109D6 |. 68 18514100 PUSH malware_.00415118 ; SE handler installation
004109DB |. 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
004109E1 |. 50 PUSH EAX
* The following Registry Keys were created:
o HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
o HKEY_CURRENT_USER\Software\Microsoft\OLE
* The newly created Registry Values are:
o [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
+ Microsoft Svchost local services = "Winsec32.exe"
so that Winsec32.exe runs every time Windows starts
o [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
+ Microsoft Svchost local services = "Winsec32.exe"
so that Winsec32.exe runs every time Windows starts
o [HKEY_CURRENT_USER\Software\Microsoft\OLE]
+ Microsoft Svchost local services = "Winsec32.exe"
HKLM\Software\Microsoft\Tracing\RASAPI32 0 Attributes Change,Value Change,Security Descriptor Change 2
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5 0 Key Change 1
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 0 Key Change 1
HKLM\system\CurrentControlSet\control\NetworkProvider\HwOrder 0 Value Change 1
and
C:\WINDOWS\Winsec32.exe
ejecutes an bat
* To mark the presence in the system, the following Mutex object was created:
o 1
* The following Host Name was requested from a host database:
o testirc1.sh1xy2bg.NET
NICK USA[XP]5187016
USER oktnjqw 0 0 :USA[XP]5187016
USERHOST USA[XP]5187016
MODE USA[XP]5187016 +i-x+s
JOIN #chalenge happy12
NOTICE USA[XP]5187016 :.VERSION http://www.W32-gen.us (-National Virus Site-).
NOTICE #chalenge :USA[XP]5187016 has just versioned me.
PRIVMSG #chalenge :RealmBoT (irc.p.l.g) .... Status: Ready. Bot Uptime: 0d 0h 0m.
PRIVMSG #chalenge :RealmBoT (irc.p.l.g) .... Bot ID: 1.
PRIVMSG #chalenge :RealmBoT (portscan.p.l.g) .... Exploit Statistics: VNC: 0, Total: 0 in 0d 0h 0m.
PRIVMSG #chalenge :RealmBoT (irc.p.l.g) .... Uptime: 0d 0h 4m.
PRIVMSG #chalenge :[REALMBOT] : Failed to start scan, port is invalid.
NICK USA[XP]0315871
USER ywwzkfkx 0 0 :USA[XP]0315871
USERHOST USA[XP]0315871
MODE USA[XP]0315871 +i-x+s
NICK USA[XP]2962195
USER ywwzkfkx 0 0 :USA[XP]2962195
USERHOST USA[XP]2962195
MODE USA[XP]2962195 +i-x+s
NICK USA[XP]3943036
USER rcfovkzy 0 0 :USA[XP]3943036
USERHOST USA[XP]3943036
MODE USA[XP]3943036 +i-x+s
well the other is similar to others comments in the solutions..
nice tutorials
