<![CDATA[smallmo.bokee.com]]> zh_cn Tue,15 Mar 2005 19:05:22 CST Fri,11 Jul 2008 14:02:40 CST http://www.bokee.com http://reg.bokee.com/account/web/img/logo.gif 博客网 http://www.bokee.com 您好,欢迎访问yunle110.bokee.com <![CDATA[7.7上海外籍女模特被杀案告破]]> .html 来自上海市公安局网站的消息:

 

“7.7”昭化路凶案告破  ——犯罪嫌疑人陈军安徽郎溪落网       

    经过上海警方连续四天四夜的缜密侦查,“7.7”昭化路凶案顺利告破。7月11日早晨,在安徽省宣城市公安局大力协助下,犯罪嫌疑人陈军在宣城市郎溪县落网。
    7日凌晨5时30分许,市公安局110指挥中心接报警称:昭化路一居民楼里内有一女子被害。警方迅速前往处置。经调查,被害人戴安娜23岁,持加拿大护照,今年6月24日入境,暂住昭化路。
    案件引起市公安局领导高度重视,要求从速破案。上海警方立即抽调精兵强将,成立了由市公安局刑侦总队和长宁公安分局等单位组成的专案组,全力展开侦破工作。
    经现场勘查,专案组初步锁定:作案者为一名青年男性,中等身材,曾骑一辆自行车到现场附近。侦查工作随即有针对性地展开。
    7月10日,一叫陈军的男子进入警方视线。据查,陈军,1990年2月出生,案发后逃至浙江湖州,后又在安徽宣城地区出现。在掌握陈军的作案轨迹后,专案组即组织精干力量赶赴安徽宣城实施抓捕。
    7月11日 8时 15分许,在宣城警方大力协助下,犯罪嫌疑人陈军在宣城郎溪县束手就擒。随后,警方追缴了“7.7”案中被劫的便携式电脑等物品。
    经审讯,犯罪嫌疑人陈军交代了7月6日晚在昭化路尾随被害人入室后实施盗窃,遭被害人反抗后将其杀害并抢劫钱财的犯罪经过。

 

原文地址:http://gaj.sh.gov.cn/shga/gweb/xxnr_view.jsp?pa=58e282badd297ff32c39d6aa91d115dd002b8ca9817ab551b3e4c275140f52b48756d7d06f8129ba

]]>
Fri,11 Jul 2008 14:02:40 CST 0
<![CDATA[[转]汶川大地震遇难同胞网络公祭]]> .html 今天一早就在新华网等网站上看到这则消息,下午2点半的时候想去祭拜一下的,可一直无法登陆网站,也许是由于太多网友访问的缘故。刚又去看了一下,可以访问了。

 

网络公祭地址:http://512.china5000.org.cn

鲜花地址:http://www.china5000.org.cn/flower/default.aspx

 

]]>
Sun,18 May 2008 15:42:40 CST 0
<![CDATA[24日起证券(股票)交易印花税税率调回1‰]]> .html     呵呵,一个小时前刚看到的消息。

    新华网中央政府网站都已经发布消息了。

]]>
Wed,23 Apr 2008 19:48:31 CST 0
<![CDATA[代号“红心闪闪”]]> .html     继续关注一下中国黑客 vs CNN的事件。

    一个代号为红心闪闪的行动昨天在国内互联网上被广泛宣传,在Google百度上搜了一下相关的内容,那是相当的多。从Arbor Networks的报道来看,攻击确实出现了,不过没有贴出相关的数据,只有简短的几句话:

 

UPDATE 8PM US Eastern: More attacks to report, with greater intensity. It look s like some people still giving this a go. I cannot, with the data I have, attribute this to any of the Chinese attacker groups that are supposedly behind the rally call, so this could be other parties entirely.

 

在Neeao的日志里看到了相关被黑的页面,不过我去看的时候,CNN似乎已经恢复了。

]]>
Sun,20 Apr 2008 16:36:54 CST 0
<![CDATA[4.19,DDoS,示威游行]]> .html     今天在安全新闻中看到了国外媒体关于中国黑客将在今天(4.19)对CNN网站发动DDoS攻击的报道

    在该篇报道中,提到了一个名为The Dark Visitor的网站,似乎是一个跟踪中国黑客活动的网站,我这里登不上,因此关于这个网站的具体内容也一无所知。不过从Arbornet works的监测情况来看,似乎大规模的攻击还未开始。

 

Destinations
www.cnn.com (one of the IPs for this DNS name)

Attacks in past 24 hours
36 attacks measured

Attacks by type
36 TCP SYN floods

Average and max attack duration
330 seconds average (5.5 minutes), 337 second maximum (slightly longer)

 

    除此之外,好像今天华人也准备举行游行示威。祝示威活动能达到预期的效果!

]]>
Sat,19 Apr 2008 14:41:15 CST 0
<![CDATA[莫名其妙的汇款]]> .html 刚去开邮箱,收到一封莫名其妙的汇款邮件。我想这样的邮件很难让人受骗的吧?

 

主 题: 汇款银行帐户
发件人:
cfgh@qq.com.cn

您好!

麻烦(这2天)把款存入以下银行帐户:

中国平安银行--深圳分行

卡号:6222   9800  0012   6369

户名:岑燕萍

请尽快办理--多谢合作!

 

Google和Baidu了一下,似乎也有些朋友收到了这样的邮件。

]]>
Tue,05 Feb 2008 13:04:41 CST 0
<![CDATA[AV-TEST Q1/2008 测评结果]]> .html 测评结果地址:http://blogs.pcmag.com/securitywatch/Results-2008q1.htm

 

瑞星还需努力啊!!!

]]>
Sat,26 Jan 2008 12:33:42 CST 0
<![CDATA[腊八节]]> .html 刚看新闻,才意识到今天是腊八节。祝各位腊八节快乐!

 

好友狮子昨天发了一篇文章:解答:《实战揭露瑞星主动防御本质》,引起了安全爱好者的关注,评论数量很多(比我这里多多了^_^)。今天花了些时间,把所有的评论看了一下,总体感觉:很有趣。我又重温了一次一人舌战众人的感觉,哈哈,当然想要狮子说服所有的人,那是不可能的事,因为有些人生来就是喜欢与人争辩的,哪怕自己没有一点道理。评论中,有些网友的意见很诚恳,希望瑞星可以吸纳,因为想用户所想才是你们应该做的。

 

最后对狮子说:如果以后还有有关产品的文章,尽量别放在个人博客上;如果非要放在个人博客上,那记得关闭评论功能,这样就不会被一些“无赖”盯上。

]]>
Tue,15 Jan 2008 19:31:51 CST 0
<![CDATA[雷军卸任]]> .html 刚看到有关雷军卸任职务的消息。

这的确是个蛮吃惊的消息,网易等网站都已对雷军离职事件作出了专题报道:http://tech.163.com/special/00092GJD/ljlz.html

]]>
Fri,21 Dec 2007 18:54:42 CST 0
<![CDATA[今年MSN蠕虫特别多]]> .html 07年似乎是MSN蠕虫的大年,截止目前为止已经出现了将近几十个变种。相信通过蠕虫的传播,已经在全球建立起庞大的僵尸网络(Botnet)。

CISRT刚刚针对今年的MSN蠕虫发布了相关的总结报告,希望对MSN用户有帮助。

 

广大网友可以访问:http://www.cisrt.org/blog/read.php?383

 

 

]]>
Fri,21 Sep 2007 21:39:10 CST 0
<![CDATA[误杀门,趋势也来凑热闹]]> .html 今年两起令人关注的误杀门事件,大家都该了解了吧。今天,在51CTO上看到这么篇文章,标题为“趋势掌门叶伟伦曝内幕 杀毒厂商在故意误杀”。

 

叶伟伦的部分话语:

记者:据说为了让病毒列表显得很长,以显示公司的技术实力,有的厂商故意误杀?

叶伟伦:的确有厂商利用误杀来制造卖点,因为用户通常以为杀出来的病毒越多,杀毒软件就越有效,这里面当然有误解,可是厂商们会利用这一点,比如把一些似是而非的程序也放进“黑名单”。

记者:据您了解,在中国有多少厂商在这样做?

叶伟伦:前段时间的流氓软件大战是典型的例子,其实那些被称作“流氓”的程序该不该放进“黑名单”是值得商榷的,但仍然有厂商在这样做。不过,趋势科技在这个问题上会坚持原则,哪怕客户向我们抱怨列出来的病毒不够多。

这是说谁呢?不用我说,大家都该明白。仁者见仁,智者见智吧。

 

原文地址:http://netsecurity.51cto.com/art/200707/51097.htm

]]>
Thu,12 Jul 2007 23:21:39 CST 0
<![CDATA[卡巴 VS 瑞星]]> .html 7.2,卡巴斯基(中国)发布了一则声明:卡巴斯基已以瑞星不正当竞争为由向天津市一中院提起诉讼,开庭日期7.23。

 

于是去一中院的网站查了一下,结果傻眼。

 

是我搞错了?还是案子的资料还没输入系统?

]]>
Sat,07 Jul 2007 23:36:59 CST 0
<![CDATA[[新闻]“熊猫烧香”作者被擒]]> .html 刚上来,就看到海色在CISRT上贴了一则新闻,标题为: [新闻]“熊猫烧香”作者被擒

看来咱们政府这次终于发彪了,同志们还是不要做病毒啦,更不要传播病毒……

]]>
Mon,12 Feb 2007 21:57:03 CST 0
<![CDATA[每天down一次]]> .html 破服务器每天要down一次。诶~~

不知道今天啥时候可以恢复,来这里发发牢骚

海色说,这样天天down,我们可以每天晚上回家看看电视,10点准时睡觉……

]]>
Mon,22 Jan 2007 18:28:07 CST 0
<![CDATA[21个小时后]]> .html 一个小时前,也就是北京时间16:30左右,我们的服务器又down了,目前还不知道是啥原因。如果又是被攻击,那我真的是无言了。不知道这次需要几天才能恢复……

海色说,这个周末我们可以彻底休息一下了,估计是恢复不了的

]]>
Fri,19 Jan 2007 17:45:06 CST 0
<![CDATA[服务器终于恢复了]]> .html 就在今晚8时45左右,接到海色的消息,我们的服务器终于在今晚19时左右恢复了。在经过二又三分之一天后,终于能登陆我们的小站了,激动啊

同志们,不容易啊……但愿别再被攻击了。

要知道作个站容易吗?黑客同学们也要为我们想想啊

我们开始准备建立daily backup制度,同时再找个空间作我们的副站点,以备不时之需。

]]>
Thu,18 Jan 2007 22:18:58 CST 0
<![CDATA[服务器遭攻击]]> .html 从今天上午11:20左右,我们CISRT的服务器开始遭受攻击,截止目前为止仍未修复。只能期待尽快恢复。

准备启用CISRT在BAIDU的临时空间,凑活凑活用用

]]>
Tue,16 Jan 2007 16:34:33 CST 0
<![CDATA[趋势科技成立中国地区病毒中心(China Lab),China Pattern迅猛出击]]> .html 前些阵子,在《波氏堂》里听到趋势科技中国区总裁叶伟伦说,07年1月会在中国区建立反病毒实验室。今天在趋势科技中国的网站上看到了这条新闻,China Lab设在上海。在上海的哪里呢?有机会一定要去看看……

 

趋势科技成立中国地区病毒中心(China Lab),China Pattern迅猛出击

网络安全软件及服务领域的全球领导者——趋势科技(纳斯达克代码:TMIC,东京证券交易所代码:4704)今日宣布,趋势科技中国区病毒中心(China Lab)近日在上海成立,同时宣布推出针对中国地区的病毒代码库(China pattern)在2007年伊始即展开全面的“扫毒行动”。趋势科技通过“主动”收集中国地区大量病毒样本,快速分析病毒样本,发布针对中国地区的特殊解决方案,该解决方案在包括全球病毒码的基础上,增加中国地区的本土病毒码,结合趋势科技的“清毒”技术DCE 5.0,以提高趋势科技防病毒产品针对中国地区用户的病毒查杀率。

全文:趋势科技成立中国地区病毒中心(China Lab),China Pattern迅猛出击]]>
Tue,09 Jan 2007 18:23:34 CST 0
<![CDATA[听了Elva新专辑]]> .html 今天萧亚轩的新专辑《1087》和挂历一起送来了,就算送给自己的圣诞礼物吧,而且挂历不错的说。在写这篇blog的时候,正在听第三遍。两遍听下来,我个人比较喜欢的有《Honey Honey Honey》、《不远》、《代言人》、《我要的世界》。

正版专辑中还有一首隐藏的歌曲叫《恋爱疯》,是紧接在《我要的世界》后的,大概在5'15''左右的样子,轩迷们可别忽略咯^_^

]]>
Sun,24 Dec 2006 22:52:11 CST 0
<![CDATA[Backdooring Images]]> .html 刚刚看到一篇不错的文章,我转载一下。可千万别用来干坏事哦

Backdooring Images:http://www.gnucitizen.org/blog/backdooring-images

]]>
Fri,15 Dec 2006 18:35:51 CST 0
<![CDATA[Elva新专辑《1087》]]> .html Elva最新专辑《1087》将于本月22日全球同步发行。Too great!

在列表里加入了首播主打歌《表白》,再来张照片

]]>
Thu,07 Dec 2006 14:39:24 CST 0
<![CDATA[金山毒霸系统清理专家]]> .html 继昨天瑞星发布卡卡3.0后,今天金山公司也发布了旗下的一款对抗流氓软件的工具——金山毒霸系统清理专家(KSC)。看来国内的反病毒公司已经彻底向流氓软件、恶意软件宣战。从最先的江民KV2007中加入反流氓软件功能,到现在的卡卡3.0、金山毒霸系统清理专家(KSC),流氓软件的地位在我们国内已经不亚于病毒、蠕虫、木马。

流氓软件是就此被终结,还是道高一尺、魔高一丈,让我们拭目以待,广大受流氓软件困扰的朋友们到是可以选择适合自己的一款工具来保护自己的电脑。

相关链接:

1. 金山毒霸系统清理专家(KSC)下载

2. 金山毒霸系统清理专家(KSC)专题首页

]]>
Wed,15 Nov 2006 12:36:20 CST 0
<![CDATA[瑞星卡卡3.0雷霆出击]]> .html 今天一早,瑞星主页就改头换面了。瑞星推出了他们的新工具“瑞星卡卡3.0”,重点针对今年在国内一撅突起的流氓软件。不知道为什么,我对这些东西是提不起一点兴趣,无论是360safe还是瑞星卡卡3.0有需要的朋友们可以去下载使用!

相关新闻:

1. 瑞星卡卡3.0雷霆出击 用反病毒技术铲除流氓软件

2. [技术详解]瑞星“碎甲(Anti-Rootkits)”技术说明

3. 瑞星卡卡上网安全助手3.0(下载)

]]>
Tue,14 Nov 2006 13:33:41 CST 0
<![CDATA[大富翁是病毒]]> .html 今天江民发布了一则新闻“ “大富翁”是病毒 专家建议禁用微软自动播放 ”。这玩意据海色说在20号左右就发现样本了,当时没怎么主意它,后来跟着Kaspersky和毒霸都报了,所以我们CISRT也做了报道。

详情可以访问这里:自动播放是做什么的?是用来“播放”病毒的

解决方案:【CISRT2006053】木马 大富翁.exe 趣味游戏.exe bug.exe 解决方案

]]>
Fri,27 Oct 2006 21:31:31 CST 0
<![CDATA[歌词:Elva is back]]> .html elva is back
☆萧亚轩☆
☆词:萧亚轩 陈宏宇 alex
曲:alex☆
☆music☆
rap: turn the music up
because i been waiting so
long for a chance to dance
to a elva song
she's back
bikky bu bu back
she's back
bikky bikky bu bu back
turn the music up
because i been waiting so
long for a chance to dance
to a elva song
she's back
bikky bu bu back
she's back
bikky bikky bu bu back
有没有听过节奏让人着火
有没有玩过声音让汗水失控
有没有尝过一种金色泡沫
停不住我的诱惑
下一步来吧跟着我
太呛的动作擦出了火
等待的眼睛都张开
发电体热起来
身体正好看的厉害
抢谁的地盘
来来来一起来
拍拍拍一起拍
你会感觉到
来享受自己的舞台
汗水都high起来
身体正发烫的厉害
来我的地盘
我们都不贪爱
只是有点贪玩
现在你听到
☆歌词提供:再兴
有没有停住
rap: turn the music up
because i been waiting solong
for a chance to dance
to a elva song
she's back
bikky bu bu back
she's back
bikky bikky bu bu back
turn the music up
because i been waiting solong
for a chance to dance
to a elva song
she's back
bikky bu bu back
she's back
bikky bikky bu bu back
下一步来吧跟着我
太呛的动作擦出了火
等待的眼睛都张开
发电体热起来
身体正好看的厉害
抢谁的地盘
来来来一起来
拍拍拍一起拍
你会感觉到
来享受自己的舞台
汗水都high起来
身体正发烫的厉害
来我的地盘
我们都不贪爱
只是有点贪玩
现在你听到
bridge:
有没有停住
bridge:ewe-ewe-ewe-
elva's back
biwi back-b-back-back-back
b-biwi-back-biwi
back-b-back-back-back
b-biwi-biwi-biwi
el-e-el-ewe-el-e-elva-ewe
el-e-el-ewe-ow-ow-ow-ow-ow
back-b-back-back-back-
bbiwi-back-biwi
back-b-back-back-back
b-biwi-biwi-biwi
el-e-el-ewe-el-e-elva-ewe
el-e-el-ewe-ow-ow-ow-ow
让身体自己擦出火
发烫的节奏有没有听到

]]>
Thu,26 Oct 2006 21:46:38 CST 0
<![CDATA[SpamThru——好玩的木马]]> .html 今天在cnBeta上看到一则新闻,标题为“奇闻:木马安装自带病毒扫描软件 专杀竞争对手”。文章里提到的是国外的分析员发现的一个木马,该木马自带反病毒扫描技术,这个木马设计的精密度和复杂令人瞠目结舌.撇开这款木马的破坏性不谈,它传染到一台系统后首先要做的事情竟然是将"竞争对手"扫地出门。

 

我找了一下关于这个东西的资料,来自SecureWorks的Joe Stewart做了一份详尽的分析报告:SpamThru Trojan Analysis

]]>
Mon,23 Oct 2006 19:16:29 CST 0
<![CDATA[新一轮Warezov蠕虫攻击]]> .html 从昨天开始,新一轮的Warezov蠕虫开始在互联网上快速传播了,我已经收到了不少的报告及病毒邮件。

CISRT也已经发布了相关的新闻:

http://www.cisrt.org/blog/read.php?137

http://www.cisrt.org/blog/read.php?138

查看了Kaspersky的库记录,从昨天开始,Kaspersky收到了数个变种,分别为:

Email-Worm.Win32.Warezov.dc Email-Worm.Win32.Warezov.dd Email-Worm.Win32.Warezov.de Email-Worm.Win32.Warezov.df Email-Worm.Win32.Warezov.dg Email-Worm.Win32.Warezov.dh Email-Worm.Win32.Warezov.di Email-Worm.Win32.Warezov.dj Email-Worm.Win32.Warezov.dk Email-Worm.Win32.Warezov.dl Email-Worm.Win32.Warezov.dm Email-Worm.Win32.Warezov.dn Email-Worm.Win32.Warezov.do Email-Worm.Win32.Warezov.dp Email-Worm.Win32.Warezov.dq

]]>
Fri,20 Oct 2006 22:11:54 CST 0
<![CDATA[Elva is back]]> .html 明天Elva的新歌"Elva is back"就要在全球发布了,前两天关于新歌的介绍片已经在elva的blog上发布了。听了一下,动感很强啊,不错!

 

期待elva年末的新专辑

]]>
Wed,18 Oct 2006 23:09:28 CST 0
<![CDATA[CISRT网站今天中午遭到入侵]]> .html 我们CISRT的网站今天中午的时候被黑客入侵,有两个地方被人植入了恶意网址,我们担心的事情终于发生了。海色已经及时将这些恶意网址清除了,我只能向这个时段访问我们网站的朋友说声抱歉了。

 

由于我电脑上没装杀毒软件、没打补丁,一系列的木马都到我电脑上了。我看了一下,真是有不少木马。有盗qq的,有盗传奇的等等。希望这位黑客朋友不要再这样做了,这样来炫耀自己的技术没任何意思。

 

我记录了一些木马的下载地址:

http://kkpic.net/ggg/adc/123.txt
http://222.220.16.185/data6/jwm.exe
http://222.220.16.185/data6/zt2.exe
http://222.220.16.185/data6/wol.exe
http://222.220.16.185/data6/mir.exe
http://222.220.16.185/data6/qqq.exe
http://222.220.16.185/data6/mhh.exe

 

还有一些特征:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<DLMon><C:\WINNT\system32\DLMain.dll> []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><KB351677M.LOG>

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<9><C:\WINNT\system32\Ravdm.exe>  [Microsoft Corporation]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<rx><C:\WINNT\system32\explore.exe> []

]]>
Thu,28 Sep 2006 20:17:10 CST 0
<![CDATA[KV07]]> .html 今天晚上uninstall了KV06,install了KV07。初步看了一下,07版的功能比之06版又复杂了许多,象我这种菜鸟已经越来越不适合装这么多功能的杀毒软件了。但是其中的一些功能还是可以帮助我们对付一些流行病毒,希望KV的同志们或者一些aver们可以配合以后出来的新病毒,发布一些KV新功能的使用教程,别让新功能荒废咯……

 

最近在忙着一些私人的事情,所以上网时间比较少,一个星期后,我就可以抽更多的时间来更新博客。希望那时的KV07会更完善!!

]]>
Sat,09 Sep 2006 23:21:46 CST 0
<![CDATA[毒霸07公测]]> .html 前两天还在说公测的事情,呵呵,这不毒霸的07版公测也跟上脚步了。

这下可好,三家一起公测,这情况还是比较少见的,准备一起上市瓜分市场?

 

喜欢测试的同学可以都装一下:

 

1.毒霸07版公测:http://www.duba.net/zt/2007gc/index.shtml

2.瑞星07版公测:http://www.ikaka.com/2007/index.htm

3.江民07版公测:http://forum.jiangmin.com/kv2007/kv2007.htm

]]>
Sat,02 Sep 2006 13:16:24 CST 0
<![CDATA[金色九月]]> .html 今天是KV2007公测的日子,截止目前为止,江民和瑞星都已经推出了自己新一年的产品进行公测,相信不久以后就会正式上市了。

 

想想也该差不多是时候推出自己的新品了,否则今年两家的员工没奖金发了(纯属玩笑)。两家的新产品我都还没装,所以不能给予评价。但感觉自己现在已经失去对新软件的测试兴趣了,还是等正式版出来后,装正式版吧……

 

再问一句,装杀毒软件有用吗?不装杀毒软件一定会中毒吗?

]]>
Fri,01 Sep 2006 18:51:40 CST 0
<![CDATA[更新新版bokee]]> .html 新版Blog已经运营蛮长时间了。我也于今天完成了升级,将原来的旧博客移到新系统上来了。呵呵,在这里要对博客网的技术人员表示感谢!!

 

总体感觉,新版Blog有向个人门户发展的趋势,吸取了各家Blog的风格,比先前老版本的花样更多了,噱头更足了,应该会吸收一些新的用户。

 

不管怎么说,我也搬到新系统上来了,呵呵,也算乔迁了一把,希望能够尽快适应新系统。

我也决定改变Blog原来的名称,从新开始Blog生活

]]>
Thu,31 Aug 2006 23:55:25 CST 0
<![CDATA[QQDragon有蠕虫行为?]]> .html 最近这几天,QQDragon系列的变种在国内开始慢慢传播,有不少朋友都中了。在我记忆里,QQDragon是QQ尾巴的典型代表,可最近发现的新变种却加入了自我复制的功能,开始有蠕虫的行为特征了,会向各个文件夹下复制。难道Trojan.QQDragon要变成Worm.QQDragon了?

有关这个东西的介绍可以看这:services.exe is virus?

]]>
Thu,10 Aug 2006 13:17:16 CST 0
<![CDATA[八月第一篇]]> .html 已经n久没更新自己的blog了,似乎已经忘记有这个blog了

原因有二:(1)因为和几个朋友一起搞了个CISRTBlog,主要时间都在那边了 (2)因为要准备一场对本人来说非常重要的考试

基于以上两个原因,所以以后这里的反病毒资讯都会移往CISRT那边,而这边将会是记载一些我个人的东西。

另外还看到瑞星的一篇文章:众多新病毒向杀毒软件开战 抢夺网络游戏、QQ密码,瑞星的危险级别也提升为“危险  ”,大家小心!

]]>
Sat,05 Aug 2006 12:58:07 CST 0
<![CDATA[俊曦被抓了?]]> .html 从瑞星那里看到的新闻,“敲诈者”的作者——欧阳俊曦,已被警方刑事拘留。

吼吼,各位同学可千万别学他哦

原文地址:全国首例计算机病毒敲诈案告破 疑犯已被刑事拘留

]]>
Tue,25 Jul 2006 11:22:39 CST 0
<![CDATA[“互联星空 山东 星空教育”被放木马]]> .html 记录一下,"互联星空 山东 星空教育"被放木马

被放木马的网址是http://www.vnetedu.com/down/count.js

]]>
Sun,23 Jul 2006 18:59:28 CST 0
<![CDATA[Microsoft PowerPoint 0-day Vulnerability FAQ]]> .html 转载一篇来自Securiteam的关于MS Powerpoint 0-day漏洞的FAQ:

This is Frequently Asked Questions document about new zero-day vulnerability in Microsoft PowerPoint. The document describes related malwares and e-mail attacks as well.


- Several updates done on 15th Jul and 17th Jul, 2006.

NOTE: Several Riler category Trojan descriptions included

Q: What is Microsoft PowerPoint 0-day vulnerability?
A: This previously unknown vulnerability is caused by an unknown error when processing malformed PowerPoint documents. The detailed characteristics is not publicly known, but the component being exploited is mso.dll (a shared Office library). Vulnerability was disclosed via malware descriptions informing new Trojan exploiting undocumented vulnerability in PowerPoint. This flaw has been used in several e-mail attacks against unknown organizations. Microsoft has confirmed these “very targeted” attacks.

Q: How does the vulnerability work?
A: The vulnerability is code execution type vulnerability. Attacker successfully exploiting this vulnerability can run code of his or hers choice in the affected machine. Executing arbitrary code is done with the recent privileges of logged user. It is known that keylogger and backdoor features are included to malwares exploiting this vulnerability. Additionally, vulnerability is caused due to memory corruption triggered by a specially drafted string in PowerPoint file.

Q: When this vulnerability was found?
A: The first malware description was published on Wednesday 12th July. Microsoft confirmed the existence of vulnerability on 13th July and officially in MSRC Blog on 14th July. There is information about samples received by one AV vendor on 11th July already.

Q: Is this one of the critical vulnerabilities reported on 11th July with MS July Security Bulletins?
A: No. This is new, unpatched vulnerability. Vulnerabilities fixed in MS06-038 etc. are different issues.

Q: Which Windows versions are affected?
A: Microsoft PowerPoint installations used in Windows 95, Windows 98, Windows Me, Windows NT, Windows 2000, Windows XP and Windows 2003 Server systems are reportedly affected.

Q: What PowerPoint versions are affected?
A: According to Microsoft Security Advisory #922970 PowerPoint versions 2003, 2002 and 2000 are affected. Several vendors list Office 2000, Office XP (2002) and Office 2003 as affected too.
Three PoCs posted to public mailing list have been tested against PowerPoint version 2003.

Q: Is PowerPoint Viewer utility affected too?
A: UPDATE: No. Microsoft lists PowerPoint Viewer 2003 as immune on its Security Advisory #922970

Q: Is Microsoft Works Suite affected too?
A: At time of writing there is no official information about this yet.

Q: Is Microsoft PowerPoint for Mac affected in this vulnerability?
A: There is no official information about this. US-CERT lists Mac versions affected too.

Q: I am using non-English version of PowerPoint 2003. Am I affected?
A: As of 17th July it is impossible to say. Exact information about affected language versions is not available yet.

Q: Where are the official Microsoft documents related to this case located?
A: Documents published by Microsoft are located at Microsoft Security Response Center (MSRC) Blog site. The address of this site is blogs.technet.com/msrc/default.aspx. UPDATE: Security advisory was published at Microsoft Security Advisories section of Microsoft TechNet Security site, www.microsoft.com/technet/security/advisory/default.mspx.

Q: How can I protect from this vulnerability?
A: The best advice is to use anti-virus software protecting from this specific malware and check that virus signature files are up-to-date.

Q: Is the exploit code of this vulnerability publicly released?
A: UPDATE: Yes. Three separate Proof-of-Concept has been posted to public, non-moderated and moderated security mailing lists on 15th July. These PoCs has been tested against PowerPoint version 2003. However, it is reported that these PoCs demonstrate new, different vulnerabilities.

Q: Does this mean that there are several, unpatched vulnerabilities in PowerPoint?
A: According to the newest information answer is yes.
PoCs introduce the following three vulnerabilities:
#1 memory corruption - CVE-2006-3656
#2 mso.dll - CVE-2006-3655
#3 powerpnt.exe CVE-2006-3660

PoC exploits mentioned reportedly affect a Denial of Service state or enable code execution, but code execution is not confirmed yet. It is worth of mentioning that exploitation in CVE-2006-3656 triggers when a PowerPoint document is closed.
UPDATE: Separate CVE names assigned to these vulnerabilities are the following:
CVE-2006-3656
CVE-2006-3655
CVE-2006-3660

Q: Is these separate malwares related to these three new disclosures yet?
A: No. This is the situation on 18th July, 2006.

Q: Is there PoC-type sample file of this vulnerability publicly available?
A: No.

Q: Is it safe to open any .PPT files any more?
A: It is very important not to open PowerPoint files from unknown sources. However, files from familiar sources can cause an infection too if a spoofed e-mail is being used.

Q: Are there any visual effects informing about the infection?
A: Yes. The title page (dia) shows Chinese characters when a malicious PowerPoint document is opened. Screenshot of the first page is included to Sophos document related to this vulnerability (see related item later). The background colour in PowerPoint presentation used is black and the text colour is white, in turn.

Q: Are there any changes to file system made by related Trojan malware?
A: Yes. Files rtfmsv.exe and regvrt.exe are being copied to the Windows System folder when the malicious .PPT attachment is opened.

Q: What are the Registry keys used?
A: Modifications are done under HKCU\Software\SKavx\ and HKEY_LOCAL_MACHINE\Software\SKavx.

Q: Are there any special features included to the way how this new Trojan works?
A: Yes. It can inject itself to Explorer process.

Q: What are the names of malwares exploiting this vulnerability?
A: Reportedly there is one Trojan and one dropper component for this malware. The following names are used:

Backdoor.Bifrose.F [Trojan]
Trojan.PPDropper.B [dropper]

BKDR_BIFROSE.DS [Trojan]
TROJ_MDROPPER.AS [dropper]

BackDoor-CEP [Trojan]
Exploit-PPT.b [exploit]

Troj/Edepol-C [Trojan]

Bifrose.UZ [Trojan]

Backdoor.Win32.Bifrose.uz [Trojan]

Backdoor:Win32/Bifrose!E029 [Trojan]

W32/Bifrose.UZ [Trojan]

The list is very coverage. There are some W32/Bifrose based names in use too.

——-
NOTE: The following names assigned on 17th July or later:

Trojan.Riler.F [Trojan]
Trojan.PPDropper.C. [dropper]

TROJ_RILER.B [Trojan]
TROJ_MDROPPER.AK [dropper]

Win32.Fantador.E [Trojan]

Win32/Fantador.E!Backdoor [Trojan]

This new category uses different techniques, e.g. Layered Service Provider (LSP), see
en.wikipedia.org/wiki/Layered_Service_Provider
and
www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_RILER.B

Q: My AV vendor doesn’t list these names at their Web pages. How do I know my AV software protects me?
A: It’s possible that anti-virus software has protection to this threat, but malware database at their Web page doesn’t include specific write-up yet because of beginning weekend, holiday season etc. The best way is to check the situation from your AV vendor.

Q: Is there Internet Storm Center documents available about the issue?
A: Yes. Internet Storm Center (ISC) has been released the following Diary entry: isc.sans.org/diary.php?storyid=1484

Q: Is there CME name to this related malware available?
A: No. The Common Malware Enumeration (CME) project has not assigned an identifier to this malware.

Q: Does Windows Live Safety Center detect this malware?
A: UPDATE: Yes. According to new MSRC Blog posting there is detection added to Windows Live Safety Center (in Beta phase) now.

Q: What is the file attachment name used in attacks mentioned?
A: Name including Chinese characters was used. The attackers can use other names in the future too, because the information about the format of the name used is publicly known.

Q: Is there information about file size used?
A: UPDATE: Yes. The size of the PowerPoint file is 220,160 bytes. Additionally, the .PPT file includes 18 slides.

Q: What is the sender address in use?
A: Reportedly gmail.com addresses has been used.

Q: Are the names of the recipients shown in message including malicious PowerPoint attachment?
A: No. Only name ‘Undisclosed-Recipient:;’ used widely in phishing e-mails etc. was used.

Q: What is the Subject line of e-mails sent in attacks mentioned?
A: Chinese characters has been used.

Q: What is the contents of the PowerPoint presentation?
A: Sophos has a short translation of two first pages located at
www.sophos.com/pressoffice/news/articles/2006/07/chinesewords.html

Q: Is any user interaction needed when opening malicious PowerPoint file?
A: No. Opening a malformed PowerPoint file triggers a vulnerability.

Q: Is it safe to open PowerPoint presentations coming from trusted, known sender during next days?
A: The answer is yes and no. If your anti-virus software is updated it will protect you. If you want protection of one hundred percent you can save presentations first and scan them with your AV software.
These days you can’t trust that the sender information included to message PowerPoint file attached is truthful. If You are not sure, You can always call to the sender if e-mail including .PPT attachments arrives unexpectedly.
Additionally, it is possible to include malicious Microsoft Power Point files as embedded files to Microsoft Word files, or Microsoft Excel files.

Q: Is it possible that malicious PowerPoint files (.PPT file extension etc.) are located at Web pages too?
A: Yes. It is possible that attacker can locate malformed PowerPoint files to Web pages too.

Q: Does the filtering PowerPoint documents at network perimeter protect me?
A: No. Normally Windows will open files with file header information, i.e. filtering by extension is not the way you can trust.

Q: When the fix to this vulnerability is expected?
A: It is impossible to say. Normally Microsoft security advisory includes information about the fixing timeline of unpatched vulnerabilities. The next monthly security updates are scheduled to 8th August, 2006.

Q: Is there CVE name available to this vulnerability?
A: Yes, CVE name CVE-2006-3590 was assigned on 14th July. Link to the CVE document is cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3590.

Q: Is there rootkit techniques included to malwares exploiting this vulnerability?
A: At time of writing there is no information about rootkit functionality included.

Q: Is there other payload than backdoor and keylogging functionality included to Trojan malware?
A: Yes. Reportedly this Trojan horse may attempt to disable AV (anti-virus) software. Additionally, it sends system information to the remote Web site. This can help attacker in future attacks.

Q: Is there information about the origin of related malware authors?
A: No. It is known that some of the target Web sites used in attacks mentioned are located in China, in Hong Kong and Jiangsu area. Additionally, some target sites are located in the USA.

Q: What is the TCP/IP port used in related attacks?
A: There are several, random TCP/IP ports in use.

(c) Juha-Matti Laurio, Finland (UTC +3hrs)


-UPDATE-
: MSRC Blog posting states Microsoft has activated their security response process and they have added detection to the Windows Live Safety Center.

Revision History:
1.0 14-07-2006 Initial release
1.1 14-07-2006 Added information about Registry keys used
1.2 14-07-2006 Added Trojan descriptions and information about translation of PPT file contents
1.3 14-07-2006 Added CVE name. Some minor updates.
1.4 15-07-2006 Added information about Windows Live Safety Center protection and PoCs posted to public mailing list
1.5 15-07-2006 Several updates and fixes, added new items
1.6 16-07-2006 Added new item to clarify the existence of multiple vulnerabilities, minor updates
1.7 17-07-2006 Added information about TCP/IP ports used in attacks and more technical information about Trojan. Added CVE names of three separate issues reported by ‘naveed’. Added new item about affected language versions, minor updates and fixes
1.8 18-07-2006 Added information from published Microsoft Security Advisory, added new type of Trojans and droppers. Added new item related to malwares exploiting three separate 0-day vulnerabilties, so-called ‘naveed issues’.
1.9 20-07-2006 Added new Riler category Trojan description, added more Fantador based Trojan names

]]>
Fri,21 Jul 2006 11:05:25 CST 0
<![CDATA[假冒七夕电子玫瑰的QQ尾巴]]> .html 转载CISRT的一篇报道:假冒七夕电子玫瑰的QQ尾巴

呵呵,又到了“七夕”,而且今年有两个“七夕”,利用第一个“七夕”的木马已经出现了,看看到第二个“七夕”会有什么新的变化。

木马的样子

]]>
Sun,16 Jul 2006 12:33:41 CST 0
<![CDATA[木马利用俄罗斯总统普京死讯传播]]> .html Sophos今天报道了一个利用俄罗斯总统普京死讯进行传播的木马Troj/Dloadr-ZP

这支木马通过俄罗斯总统普京已死消息的垃圾邮件进行传播,邮件为html形式,夹杂了ADODB.Stream漏洞, 当用户浏览此邮件时,就会自动下载这个木马下载器。同时邮件里的链接地址也假冒BBC的链接地址,其实是指向一个俄罗斯的网站。

引用一下Sophos关于这封垃圾邮件的图片:

]]>
Thu,13 Jul 2006 21:57:10 CST 0
<![CDATA[利用PPT漏洞的木马Trojan.PPDropper]]> .html Symantec报道了一支叫Trojan.PPDropper.B的木马,这是一支利用Microsoft Powerpoint远程代码可执行漏洞进行传播的木马,疑似国人编写。

木马通过邮件进行传播,以扩展名为.ppt的附件到达用户邮箱。当用户打开这支含有漏洞的ppt文档后,会释放%System%\regvrt.exe,这是Backdoor.Bifrose.E变种。然后注入EXPLORER.EXE进程,释放一个没有漏洞的ppt文档来覆盖有漏洞的文档。

同时会显示一段话:“什么叫浪漫?明知那个女孩儿不爱他,还送给她999朵玫瑰;什么叫浪费?明知那个女孩儿爱他,还送给她999朵玫瑰”,如图:(图片来自Symantec)

]]>
Thu,13 Jul 2006 13:08:44 CST 0
<![CDATA[微软7月安全公告]]> .html 微软发布7月安全公告,包含5个严重等级,2个重要等级,请广大网友尽快下载补丁安装。

这次发布的补丁包括:

MS06-033ASP.NET 中的漏洞可能允许信息泄露 (917283)

MS06-034使用 Active Server Pages 的 Microsoft Internet 信息服务中的漏洞可能允许远程执行代码 (917537)

MS06-035Server 服务中的漏洞可能允许远程执行代码 (917159)

MS06-036DHCP Client 服务中的漏洞可能允许远程执行代码 (914388)

MS06-037Microsoft Excel 中的漏洞可能允许远程执行代码 (917285)

MS06-038Microsoft Office 中的漏洞可能允许远程执行代码 (915384)

MS06-039Microsoft Office 中的漏洞可能允许远程执行代码 (915384) 

]]>
Wed,12 Jul 2006 11:41:06 CST 0
<![CDATA[Sohu上之网页含有盗号木马]]> .html 刚接到网友的反映,国内门户网站搜狐(Sohu.com)上的网页链接含有木马。小陌对该网页进行了分析,的确含有木马,其中有一个木马还比较新,Kaspersky、瑞星等反病毒软件还无法检测,广大网友小心!

被放木马的网页是一个叫“雪花啤酒一号通缉令”的网页,如图:

在打开图中红框所指的网页后,会打开另外个恶意网址,如下图:

这个恶意网址会打开一个脚本h**p://bcwr1.3322.org/css/1/sp2.asp

该脚本会下载h**p://bcwr1.3322.org/css/1/wsxedc.jpg,这个文件其实是一个exe的文件,大小66,381 字节,NSPack加壳,AVP检测为Trojan-PSW.Win32.QQPass.fq,Trojan.PSW.Liumazi.fd(瑞星)。

同时下载h**p://bcwr1.3322.org/css/1/edcx.gif,是个脚本文件,大小2,588 字节,是用来运行wsxedc.jpg的。

还会打开h**p://bcwr1.3322.org/css/1/index.htm,下载:h**p://bcwr1.3322.org/css/1/upx.gif,这是个chm文档,大小39,280 字节,释放schove.exe,UPX加壳,大小31,232 字节,是个盗游戏帐号的木马,目前Kaspersky、瑞星等都不能查杀。

2006.7.11 11:55更新:

AVP最新的库已经可以查杀,命名为Trojan-Spy.Win32.Agent.nf

瑞星18.35.10版本可以查杀Trojan.PSW.Agent.adw

CISRT监测,雪花啤酒的网站和多家大型网站均有合作,新浪的主页上也存在该网站的链接,详情可访问CISRT论坛:搜狐上之网页含有盗号木马,浏览时务必小心

]]>
Mon,10 Jul 2006 23:35:53 CST 0
<![CDATA[Jalabed.B蠕虫假借世界杯球票]]> .html 一支名叫W32.Jalabed.B@mm的蠕虫被Symantec截获,这支蠕虫通过邮件、P2P、IRC多种方式传播,并且假冒2006德国世界杯球票,广大网友须小心!

Jalabed.B,大小77312字节,病毒邮件形式如下:

主题:
Im the winner of 2 FIFA tickets

正文:
You wont believe it but im the winner of 2 tickets for FIFA 2006 in Germany,if you want a ticket read attackment ;)

附件:
FIFA 2006 Ticket.doc.exe

当用户运行病毒后,会生成

%Windows%\kh4l3d.txt
%Windows%\arabic.exe
%Windows%\usefull.txt.exe
%Windows%\FIFA 2006 Ticket.doc.exe
%Windows%\mail.vbs

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\Run
"4r4bic h4x0r" = "%Windir%\arabic.exe"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
"4r4bic h4x0r" = "%Windir%\arabic.exe"

蠕虫还能通过IRC传播,向IRC频道里的用户发送名为usefull.txt.exe;同时还会通过Kazaa进行传播

]]>
Sun,09 Jul 2006 18:18:49 CST 0
<![CDATA[概念型病毒Gattman指向反汇编软件IDA]]> .html 一个通过IDA反汇编软件传播的概念型病毒Gattman-A被反病毒厂商截获。

Datarescue IDA PRO是全球广大反病毒工程师在分析病毒时所用到的一款常用工具,这次出现的Gattman-A病毒将目标指向了IDA,似乎是想通过反病毒工程师来进行传播。

Gattman-A感染.IDC脚本文件,而.IDC脚本文件可以被IDA打开。

以下是反病毒公司的一些报道:

1. Sophos: W32/Gattman-A

2. Trend Micro: PE_GATTMAN.A-O

]]>
Sat,08 Jul 2006 18:36:34 CST 0
<![CDATA[“淘宝百万格子”网站被放木马]]> .html 刚才在分析一个被放木马的网址时,偶然看到了“淘宝百万格子”网站(taobaobox.com),顺便对网站进行了一次检查,结果发现网站被人放了木马,而且此木马比较新,Kaspersky等反病毒软件目前还无法查杀,因此提醒广大网友,特别是淘宝的个人用户们小心!

在“淘宝百万格子”网站的尾部被人植入了一个恶意网址,如图:

同时在其主页代码里也发现了大量的色情词语。sms.htm会同时打开
h**p://www.ads173.com/shipin/index.htm
h**p://www.ads173.com/shipin/count.asp

index.htm网页会根据系统的版本分别打开
h**p://www.ads173.com/shipin/w98.htm
h**p://www.ads173.com/shipin/winnt.htm
这两个网址分别会下载h**p://www.ads173.com/shipin/haha.ico和h**p://www.ads173.com/shipin/logo.gif。haha.ico,大小30,839 字节,FSG2.0加壳,是个比较新的盗号木马。

count.asp会下载h**p://www.ads173.com/shipin/ray.exe,30,839 字节,FSG2.0加壳,同haha.ico,同时修改注册表
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools","REG_DWORD" = "0"
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1200","REG_DWORD" = "0"
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1004","REG_DWORD" = "0"

2006.7.7 21:40更新:

AVP最新的库可以查了Trojan-PSW.Win32.QQPass.io

]]>
Fri,07 Jul 2006 19:18:12 CST 0
<![CDATA[“悲情告别论坛”被放木马]]> .html 有网友反映,“悲情告别论坛”(sorrowbyes.com)被放木马,小陌检查了一下,的确被人放了木马,提醒大家小心!

被放木马的网址,如图:

ad.htm会打开以下三个网页:

h**p://mm.47555.com/count.html
h**p://mm.47555.com/winnt.htm
h**p://mm.47555.com/w98.htm

count.html是个chm文档,大小19,062 字节,释放QQ.EXE。QQ.EXE,大小11,208 字节,NSPack加壳,MD5值为f04973fb8267827f347594b373732290,AVP报为Trojan-Downloader.Win32.Agent.ue

winnt.htm会下载并运行
h**p://mm.47555.com/logo.gif
h**p://mm.47555.com/logo.ico(同QQ.EXE)

w98.htm打开h**p://mm.47555.com/count.html

“比特论坛”被放木马上的木马

]]>
Thu,06 Jul 2006 19:06:19 CST 0
<![CDATA[IRCBot.st假冒微软反盗版程序WGA]]> .html 2006.6.30左右,一个名叫Backdoor.Win32.IRCBot.st(AVP)的蠕虫被各大反病毒厂商截获。由于这支蠕虫假冒微软反盗版程序WGA,所以引起了不少安全信息厂商的关注。

根据目前小陌收集到的信息来看,由于其是通过AOL即时聊天软件进行传播,因此主要的感染对象还是国外用户,已经收到一些国外用户感染这支蠕虫的报告,相信对国内用户的影响还是比较小的。下面简单介绍一下关于这支蠕虫的信息:

Backdoor.Win32.IRCBot.st,大小在7K左右,通过AOL向列表中的好友发送名为“wgavn.exe”的文件,当用户打开这个文件后,会在系统中生成

\%system32%\wgavn.exe
\%Windows%\Debug\dcpromo.log

在服务中添加

服务名称: wgavn
显示名称: Windows Genuine Advantage Validation Notification
可执行文件的路径: \%system32%\wgavn.exe
启动类型: 自动

添加、修改注册表:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wgavn
DisplayName = "Windows Genuine Advantage Validation Notification

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
UpdatesDisableNotify = "dword:00000001"
AntiVirusDisableNotify = "dword:00000001"
FirewallDisableNotify = "dword:00000001"
AntiVirusOverride = "dword:00000001"
FirewallOverride = "dword:00000001"

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall = "dword:00000000"

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall = "dword:00000000"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
AutoShareWks = "dword:00000000"
AutoShareServer = "dword:00000000"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole
EnableDCOM = "N"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous = "dword:00000001"

反病毒厂商的命名:

1. Trend Micro: BKDR_IRCBOT.DB

2. Sophos: W32/Cuebot-K

3. Nod32: Win32/IRCBot.OO

4. Symantec: W32.Esbot.E

]]>
Tue,04 Jul 2006 12:42:43 CST 0
<![CDATA[和世界杯有关的IRC蠕虫]]> .html 刚刚分析了一个和世界杯有关的IRC蠕虫,估计是个国内葡萄牙球迷写的。

文件名为Portugal.vbs,大小1,937字节,是个脚本,AVP命名为IRC-Worm.VBS.Generic,瑞星命名为VBS.I-Worm.Lee-Based

具有以下行为特征:

1. 通过MAPI自动发送邮件,邮件形式:

主题: "葡萄牙赢啦!!"
正文: "葡萄牙赢啦!!葡萄牙赢啦!!"
附件:Portugal.vbs

2. 添加注册表:
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page,"h**p://www.mumayi.net"
HKCU\Software\Microsoft\Internet Explorer\Main\Window Title, ""
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Portugal,"C:\WINDOWS\Portugal.vbs"
HKCU\software\Worm\Mirqued", "1"

还会通过mirc,发送Portugal.vbs

AVP和瑞星都是广谱的命名,呵呵,我个人也做了个命名,就叫IRC-Worm.VBS.Mirqued.a吧

]]>
Mon,03 Jul 2006 13:29:28 CST 0
<![CDATA[“浙江影视娱乐频道”网站被放木马]]> .html 浙江影视娱乐频道”网站(ztv-5.com)被放木马,小陌提醒广大网友小心!

该网站上被人植入了一个恶意网址,如图:

sina.htm会根据系统版本来打开不同网页

98版本的会打开h**p://sina109.3322.org/sina/w98.htm,该网页上含有两个文件

h**p://sina109.3322.org/sina/young.css
h**p://sina109.3322.org/sina/young.gif

young.css其实是个exe文件,大小512 字节,PE_Patch加壳,是个木马下载器,AVP报为Trojan-Downloader.Win32.Tiny.cj,会从远程下载灰鸽子:h**p://sina109.3322.org/sina/sina.exe,大小303,104字节,AVP命名为Backdoor.Win32.GrayBird.jj,瑞星命名为Backdoor.Gpigeon.xiy

nt版本的会打开h**p://sina109.3322.org/sina/winnt.htm,该网页上含有两个文件

h**p://sina109.3322.org/sina/young.css
h**p://sina109.3322.org/sina/young.gif(同上)

]]>
Fri,30 Jun 2006 22:49:24 CST 0