|
|
|
Security Essentials Rogue AV Anti-Debugging |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Security Essentials Rogue AV Anti-Debugging Par DeobfuscatedLe [2010-10-20] à 16:21:55
Présentation : While Microsoft Security Essentials is a legitimate AV software, there's also a rogue AV going by the same name. Usual story, fake alerts constantly popping up, enticing the user to buy a licence... With no surprise, the sample I was looking at calls home in Latvia. whois 85.234.191.185 pourcents This is the RIPE Database query service. pourcents The objects are in RPSL format. pourcents pourcents The RIPE Database is subject to Terms and Conditions. pourcents See http www.ripe.net db support db-terms-conditions.pdf pourcents Note This output has been filtered. pourcents To receive output for a database update, use the -B flag. pourcents Information related to '85.234.190.0 - 85.234.191.255' inetnum 85.234.190.0 - 85.234.191.255 netname ATECH-SAGADE descr Sagade Ltd. descr Latvia, Rezekne, Darzu 21 descr 371 20034981 remarks abuse-mailbox piotrek89 gmail.com country LV admin-c TMCD111-RIPE tech-c TMCD111-RIPE status ASSIGNED PA mnt-by AS6851-MNT source RIPE Filtered role TMCD Admin Contacts address Ieriku 67a, Riga, LV-1084 org ORG-TMDA1-RIPE e-mail bkc bkc.lv admin-c AS1606-RIPE admin-c TP422-RIPE tech-c RF2443-RIPE tech-c IR106-RIPE nic-hdl TMCD111-RIPE source RIPE Filtered pourcents Information related to '85.234.160.0 19AS6851' route 85.234.160.0 19 descr BKCNET Autonomous System descr IZZI SIA descr Ieriku 67a, Riga, LATVIA origin AS6851 mnt-by AS6851-MNT source RIPE Filtered Enough with the boring stuff... The funny part starts right at the entry point. A quick look at the disassembly reveals that this piece of crap overwrites its own code with the opcode 0x43 INC EBX via REP STOSB. The puzzling detail is that the REP STOSB instruction will be overwritten as well. And, indeed, if we step trough this code, we end up with that Indeed, when single stepping, the debugger executes only one instruction i.e one iteration of REP and ends up executing the overwritten bytes. When the JNZ is reached, ECX equals 1. This is because REP STOSB has been overwritten before the last iteration of STOSB That's why only half of REP STOSB has been replaced by 0x43 . The jump is taken and the sample quits after showing a dialog box reading BitDefender . Might be complete crap or a way for the bad guys to underline that BitDefender's emulator cannot handle properly this code. However, I won't bother checking this... If, instead of single stepping, you set a breakpoint on the JNZ and run the debuggee, the behaviour is different. REP STOSB is executed normally atomic execution and ECX equals 0 when the conditional jump is reached. And malware happily keeps running... Not very stealth but a nice little anti-debugging and maybe anti-emulation trick.
Les mots clés de la revue de presse pour cet article : security Les videos sur SecuObs pour les mots clés : security Les mots clés pour les articles publiés sur SecuObs : security Les éléments de la revue Twitter pour les mots clé : security
Les derniers articles du site "Deobfuscated" :
- Coloring junk code in IDA Pro - Security Essentials Rogue AV Anti-Debugging - More on moron packers and anti-debugging - Big brother with big vulnerabilities... - R.I.P milw0rm - l0phtcrack 6 and Nmap 5 are out - Null pointer dereference vulnerability in the Linux kernel - Hey There's a worm in that apple - Die Delphi, die - And here comes another secure by design OS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|