|
W32.Wapomi.B 是一種蠕蟲,此病毒會利用Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (BID 31874)漏洞複製本身至網路共用以及可移動裝置,並且會在遭受破壞的電腦上感染其執行檔。
此蠕蟲可能會藏匿於影音撥放程式,如:QVOD
當此蠕蟲執行時,會監視下列服務狀態:
AppMgmt (appmgmts.dll)
BITS (qmgr.dll)
Browser (browser.dll)
CryptSvc (cryptsvc.dll)
EventSystem (es.dll)
FastUserSwitchingCompatibility (shsvcs.dll)
helpsvc (pchsvc.dll)
Netman (netman.dll)
Nla (mswsock.dll)
Ntmssvc (ntmssvc.dll)
RemoteRegistry (regsvc.dll)
Schedule (schedsvc.dll)
SSDPSRV (ssdpsrv.dll)
Tapisrv (tapisrv.dll)
upnphost (upnphost.dll)
WmdmPmSN (mspmsnsv.dll)
xmlprov (xmlprov.dll)
這些服務是由svchost載入的:
%SystemDrive%\System32\svchost.exe -k netsvcs
當蠕蟲發現到服務停止時,會複製自身到相應的DLL檔案,並啟動被替換的服務。
這些修改過的DLL檔會被檢測為W32.Wapomi.B病毒,可能是以下檔案:
%SystemDrive%\system32\appmgmts.dll
%SystemDrive%\system32\qmgr.dll
%SystemDrive%\system32\shsvcs.dll
%SystemDrive%\system32\mspmsnsv.dll
%SystemDrive%\system32\xmlprov.dll
%SystemDrive%\system32\es.dll
%SystemDrive%\system32\ntmssvc.dll
%SystemDrive%\system32\upnphost.dll
%SystemDrive%\system32\ssdpsrv.dll
%SystemDrive%\system32\netman.dll
%SystemDrive%\system32\mswsock.dll
%SystemDrive%\system32\tapisrv.dll
%SystemDrive%\system32\browser.dll
%SystemDrive%\system32\cryptsvc.dll
%SystemDrive%\system32\pchsvc.dll
%SystemDrive%\system32\regsvc.dll
%SystemDrive%\system32\schedsvc.dll
然後該蠕蟲會建立以下檔案:
%System%\drivers\[RANDOM CHARACTERS].sys (Hacktool.Rootkit)
下一步,該蠕蟲會為上述檔案建立一個機瑪去設定服務:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[RANDOM CHARACTERS]
再來會建立以下機碼:
請參考原廠文件
下一步,該蠕蟲會覆寫%SystemDrive%\system32\drivers\etc\hosts檔案
下一步,該蠕蟲會感染所有.exe執行檔,包括在.rar裡面的執行檔以及網路分享目錄的執行檔,但是不會感染以下資料夾:
Common Files
ComPlus Applications
Documents and Settings
InstallShield Installation Information
Internet Explorer
Messenger
Microsoft Frontpage
Movie Maker
MSN Gaming Zone
NetMeeting
Outlook Express
RECYCLER
System Volume Information
Thunder
Thunder Network
WINDOWS
Windows Media Player
Windows NT
WindowsUpdate
WinNT
WinRAR
感染的執行檔會被檢測為W32.Wapomi.B!inf
然後蠕蟲會嘗試從遠端裝置下載加密資料和惡意軟體。在下載之前,蠕蟲會檢查網域內IP位址,如果屬於下列位置,則不會下載檔案:
http://192.168.*.*
http://169.254.*.*
http://172.16.*.*
http://10.*.*.*
http://127.*.*.*
蠕蟲會嘗試從下列路徑下載msdownload/update/v5/redir/wuredirt.rar檔案:
http://[RANDOM NUMBER BETWEEN 1 AND 500].ns768.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].WAP517.NET
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631261.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631262.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631262.INFO
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631262.NET
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631262.ORG
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631263.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631263.INFO
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631263.NET
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS1631263.ORG
http://[RANDOM NUMBER BETWEEN 1 AND 500].ns792.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].ns529.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsvjn987.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsvhn987.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].ns2275ab.com
然後會試圖從以下位址下載cl/51.exe檔案:
http://[RANDOM NUMBER BETWEEN 1 AND 500].WAP517.MOBI
http://[RANDOM NUMBER BETWEEN 1 AND 500].WAP517.ORG
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS2000WIP.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS3000WIP.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS4000WIP.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NS5000WIP.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsv33987.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsvbg987.com
然後蠕蟲會傳送被感染電腦之MAC Address至下列遠端裝置之一:
http://[RANDOM NUMBER BETWEEN 1 AND 500].WAP517.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].WAP517.INFO
http://[RANDOM NUMBER BETWEEN 1 AND 500].NSDOWNUSA.COM
http://[RANDOM NUMBER BETWEEN 1 AND 500].NSDOWNUSA.INFO
http://[RANDOM NUMBER BETWEEN 1 AND 500].NSDOWNUSA.NET
http://[RANDOM NUMBER BETWEEN 1 AND 500].NSDOWNUSA.ORG
http://[RANDOM NUMBER BETWEEN 1 AND 500].NSDOWNUSA.US
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsvw3987.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsopk876.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsyh6778.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsd907.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nshh987.com
http://[RANDOM NUMBER BETWEEN 1 AND 500].nssv987.com
下一步,蠕蟲會開啟IE瀏覽以下網址,該網址可能包含廣告軟體:
http://[RANDOM NUMBER BETWEEN 1 AND 500].nsb927.com:8080/mac.htm?51
http://[RANDOM NUMBER BETWEEN 1 AND 500].nse917.com:8080/mac.htm?51
蠕蟲還會使用下列帳號密碼的組合去嘗試連接預設網路分享:
請參考原廠文件
蠕蟲會複製自身到以下共用位置:
[NETWORK SHARE FOLDER]\[RANDOM CHARACTERS].exe
蠕蟲會從下網址之一下載惡意軟體:
請參考原廠文件
下載惡意軟體儲存到以下位置:
C:\boottemp.exe
蠕蟲複製自身至可移動式儲存裝置:
%DriveLetter%\recycle.{645FF040-5081-101B-9F08-00AA002F954E}\Install.exe
還會建立下列檔案使蠕蟲在另一台電腦自動執行:
%DriveLetter%\recycle.{645FF040-5081-101B-9F08-00AA002F954E}\autorun.inf
|