2009년 2월 21일 토요일

2009.02.21.01

http://ixmi.reOOOradio.com http://qxbsj.OOOOpoem.com 등의 도메인을 통해 좀비PC를 이용하여 웹상에서 이메일카드로 꾸며 실행하게끔 유도.

run.exe, kit.exe, lovekit.exe 등의 이름으로 유포되고 있고있음.



안티바이러스 엔진 버전 정의 날짜 검사 결과
a-squared 4.0.0.93 2009.02.21 -
AhnLab-V3 2009.2.21.0 2009.02.20 -
AntiVir 7.9.0.85 2009.02.20 -
Authentium 5.1.0.4 2009.02.20 -
Avast 4.8.1335.0 2009.02.20 -
AVG 8.0.0.237 2009.02.20 -
BitDefender 7.2 2009.02.21 -
CAT-QuickHeal 10.00 2009.02.20 (Suspicious) - DNAScan
ClamAV 0.94.1 2009.02.20 -
Comodo 983 2009.02.20 -
DrWeb 4.44.0.09170 2009.02.21 -
eSafe 7.0.17.0 2009.02.19 -
eTrust-Vet 31.6.6368 2009.02.20 -
F-Prot 4.4.4.56 2009.02.20 -
F-Secure 8.0.14470.0 2009.02.20 -
Fortinet 3.117.0.0 2009.02.20 W32/PackWaledac.A
GData 19 2009.02.21 -
Ikarus T3.1.1.45.0 2009.02.21 -
K7AntiVirus 7.10.638 2009.02.20 -
Kaspersky 7.0.0.125 2009.02.21 -
McAfee 5531 2009.02.21 -
McAfee+Artemis 5531 2009.02.21 -
Microsoft 1.4306 2009.02.21 Trojan:Win32/Waledac.A
NOD32 3875 2009.02.21 a variant of Win32/Waledac.GF
Norman 6.00.06 2009.02.20 -
nProtect 2009.1.8.0 2009.02.20 -
Panda 10.0.0.10 2009.02.20 Suspicious file
PCTools 4.4.2.0 2009.02.20 -
Prevx1 V2 2009.02.21 -
Rising 21.17.42.00 2009.02.20 -
SecureWeb-Gateway 6.7.6 2009.02.20 Trojan.LooksLike.Backdoor.Hupigon
Sophos 4.39.0 2009.02.21 Mal/WaledPak-B
Sunbelt 3.2.1855.2 2009.02.17 -
Symantec 10 2009.02.21 -
TheHacker 6.3.2.3.261 2009.02.20 -
TrendMicro 8.700.0.1004 2009.02.20 -
VBA32 3.12.10.0 2009.02.20 -
ViRobot 2009.2.20.1617 2009.02.20 -
VirusBuster 4.5.11.0 2009.02.20 -
추가 정보
File size: 440321 bytes
MD5...: 12644c0c7dcfc6d2c3a7be352c3d63a3
SHA1..: 1bacec104ff0fdc9c656617a55f27df6b8dc7fc8
SHA256: 053031ed4834b2c684c4674ee052ce017592f4420d7df8401ff4f3bba2949527
SHA512: 8b7d62ea1e7f89e802948d26dd92bd95ddb1942abaaf545b5e061fc4db224fa8
304bcb280a89b4f97cfd9488940ec352449cc0ecf6e4481393e4afff9a22cd34
ssdeep: 12288:AW7KT+TN6v/jHmjx6AvjVXQCyGpmERM4M/KxU:AU6njHmjxHvjlQCyymER
VM/Kx
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x401888
timedatestamp.....: 0x45adca6e (Wed Jan 17 07:04:14 2007)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x493e2 0x48c00 8.00 ed030bb73738ad7865f322e6039d93df
.ervc 0x4b000 0x133c6 0xe800 7.98 3d8dc44721ca37bfa6dd354409b2e293
.dbze 0x5f000 0x104046 0x13c00 7.99 80bb4118b9c37f808c9f9ebb3857a1fd
.reloc 0x164000 0x43f 0x400 2.11 9002999194f3dfb530492458417ef346

( 4 imports )
> GDI32.DLL: GetMetaRgn, GetViewportOrgEx, RemoveFontResourceA, CreateDIBSection, GetTextMetricsA, GetClipRgn, GetMiterLimit, GetTextCharsetInfo, GetObjectA, GetTextCharset, SetBkMode, SetMetaFileBitsEx, CreateDCW, GetCurrentObject, GetBitmapBits, GetObjectW, SetICMProfileA, GetObjectType, GetGraphicsMode, SetWindowOrgEx, SetPolyFillMode, GetViewportExtEx, GetTextMetricsW, ExtSelectClipRgn
> OLE32.DLL: WdtpInterfacePointer_UserFree, OleGetIconOfClass, GetHGlobalFromStream, CoBuildVersion, OleCreateLinkFromDataEx, HGLOBAL_UserSize, WdtpInterfacePointer_UserUnmarshal, HPALETTE_UserMarshal, UtGetDvtd32Info, StgSetTimes
> KERNEL32.DLL: FindFirstChangeNotificationA, GetSystemTime, GetEnvironmentVariableW, FlushConsoleInputBuffer, EnumResourceLanguagesW, lstrcmpiW, GetBinaryTypeA, GetModuleHandleA, GetProfileIntW, SuspendThread, Sleep, SetFileTime, lstrcmpA, InterlockedDecrement, GetConsoleTitleW, GetConsoleOutputCP, EraseTape, HeapLock, lstrlenW, _lopen, GetCurrentDirectoryW, GetStartupInfoW, ExitProcess, CreateEventW, GetModuleHandleW, VirtualUnlock, Toolhelp32ReadProcessMemory, VirtualFree, GetLocalTime, SetCommBreak, FillConsoleOutputAttribute, BeginUpdateResourceA, lstrcatA, EnumTimeFormatsA, lstrcmpW, GetPrivateProfileStringA, lstrcmpiA, VirtualAlloc, lstrcpyA, lstrlenA
> msvcrt.dll: _pipe, strcat, _adj_fprem, tmpnam, _setsystime, _commit, _wrmdir, __threadid, tan, getenv, iswgraph, _strnset, _wrename, _CItan, __dllonexit, gets, _mbsrchr, isleadbyte, _fputwchar, _winver, _getmbcp, _ismbstrail

( 0 exports )

댓글 없음:

댓글 쓰기