|
|
|
Wandering Through Trojan.NtRootKit.47 Driver |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : Wandering Through Trojan.NtRootKit.47 Driver Author Davide ocean Quarta Introduction I didn t have the dropper at the moment of writing this, only the driver. Without the dropper we can only get a generic idea of what the driver is used for. The driver has been reverse engineered by deadlist, a really irritating thing to do actually, but it can be useful to see the generic structure of a typical driver. It s a driver with dll functionality. Erssd shows us that the driver is produced by ErrorSafe, a fake-av scareware company. Seems like there are no rootkit functionality in this driver, while only a few zw functions are exposed to the dropper, through the use of IOCTLS, though we can t know how this is used without access to the dropper. Driver entry point driver entry point graph Simple start structure, a Device is created with name erssdd and linked with a Dosdevice with the same name, next every PDRIVER_DISPATCH MajorFunction IRP_MJ_MAXIMUM_FUNCTION 1 will be written to point to a general IRP_dispatch procedure. Also a driver unload routine is set. .text 000113EA push 1Ch IRP_MJ_MAXIMUM_FUNCTION 1 .text 000113EC lea edi, ebx 38h .text 000113EF pop ecx .text 000113F0 mov eax, offset irp_dispatch .text 000113F5 rep stosd .text 000113F7 mov dword ptr ebx 34h , offset unload unload procedure is pretty simple too .text 0001133A unload .text 0001133A cmp Handle, 0 .text 00011341 jz short loc_1134A .text 00011343 push 0 .text 00011345 call close_handle .text 0001134A .text 0001134A loc_1134A .text 0001134A push offset DestinationString .text 0001134F call ds IoDeleteSymbolicLink .text 00011355 push DeviceObject .text 0001135B call ds IoDeleteDevice .text 00011361 retn 4 it will just check if there s and object handle open and close it inside function close_handle there s a call to ZwClose . now the irp dispatcher procedure read more
Les derniers articles du site "Offensive Computing Community Malicious code research and analysis" :
- Spam and Abuse - Trouble Unpacking - One Million Samples - Siberia Exploit Pack. Another package of explois In-the-Wild - Rule2Alert - Ether Mailing List - Buster Sandbox Analyzer 1.0 release version - Wandering Through Trojan.NtRootKit.47 Driver - Huytebesy4ko Hijacker analysis - T-IFRAMER. Kit for the injection of malware In-the-Wild
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, microsoft, réseau, attaque, vulnérabilité, outil, système, audit, virus, internet, données, présentation, linux, metasploit, protocol, bluetooth, vista, shell, scanner, réseaux, rootkit, paquet, trames, source, conférence, téléphone, wishmaster, noyau, engineering, mobile, sysun, https, téléphones, mémoire, patch, intel, botnet, libre, rapport, scapy, reverse, contourner, securitech |
| Mini-Tagwall de l'annuaire video : | | | | vmware, security, virus, biometric, windows, lockpicking, password, metasploit, botnet, tutorial, crypt, attack, linux, network, iphone, server, exploit, wimax, conficker, virtu, virtual, engineering, cisco, reverse, ettercap, wireshark, hacker, firewall, knoppix, arduino, internet, rootkit, wireless, source, brucon, backtrack, openbsd, systm, overflow, openssh, conference, buffer, access, remote, defcon |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|