Backdoor.Win32.IRCBot.st 蠕虫公告

创建时间:2006-08-13 更新时间:2006-08-13
文章属性:原创
文章提交:killer (killer_at_xfocus.org)
Author: killer (killer<2>xfocus.org)
Date:2006-8-13

一、病毒描述:

近日,一种新的BOT蠕虫现身网络,该蠕虫利用最新的MS06040漏洞传播,目前已经有多个变种。从分析上看,基本目的为发动拒绝服务攻击,蠕虫主要内置了syn/udp/scan等命令。

二、病毒基本情况:

[File Info]
File: C:\WIN2K\system32\wgareg.exe
Size|Attrib: 0×2589 (9609), (disk) 0×2589 (9609) | (attrib) archive
Packer:MEW

三、病毒行为:

1、病毒体执行后,将自身拷贝到系统目录:

%System%\wgareg.exe

创建文件:%windir%\Debug\dcpromo.log

2、添加系统服务确保自身在系统重启动后被加载:

服务名:wgareg
显示名称:Windows Genuine Advantage Registration Service
服务描述:Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability.
对应文件:%System%\wgareg.exe

3、连接IRC地址,接受远程命令控制:

域名:ypgw.wallloan.com
bniu.househot.com

IRC IP:58.81.137.157 端口:18067
IRC IP:61.163.231.115 端口:18067
IRC IP:202.121.199.200 端口:18067
IRC IP:61.189.243.240 端口:18067

4、修改多处注册表键,用以关闭杀毒软件、防火墙降低系统安全性。

5、该蠕虫和还会下载其它木马,目前截获下载的木马为:Trojan-Proxy.Win32.Ranky.fv

四、临时解决方案:

1、防火墙处阻止TCP端口: 139、445
2、启用TCP/IP筛选功能进行过滤。
3、使用IPSec来阻止受影响的端口访问。

五、补丁下载:

中文Windows 2000 Service Pack 4:

http://download.microsoft.com/download/f/2/%%f/f2f6f032-b0db-459d-9e89-fc0218973e73/Windows2000-KB921883-x86-CHS.EXE

中文Windows XP Service Pack 1 & Service Pack 2:

http://download.microsoft.com/download/3/1/b/31be1ef4-18e0-44a1-bc80-1753b8b43528/WindowsXP-KB921883-x86-CHS.exe

中文Windows Server 2003 & Service Pack 1:http://download.microsoft.com/download/3/1/e/31e1b295-80cf-47fb-be65-c542a55bc1cd/WindowsServer2003-KB921883-x86-CHS.exe

Windows XP Professional x64 Edition:

http://download.microsoft.com/download/0/f/9/0f9eb45e-cb70-40dd-8506-8cdf226731f7/WindowsServer2003.WindowsXP-KB921883-x64-ENU.exe

随机日志

发表评论

0 评论.

Leave a Reply



[ Ctrl + Enter ]

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

CNXCT小组的博客 is Stephen Fry proof thanks to caching by WP Super Cache