1、文件运行后会释放以下文件
%System32%\breemat.dll
2、创建注册表病毒服务项
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abcd\Description
值: 字符串: "breeR"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abcd\DisplayName
值: 字符串: "bree"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abcd\Parameters\ServiceDll
值: 字符串: "C:\WINDOWS\system32\breemat.dll."
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abcd\Start
值: DWORD: 2 (0x2)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abcd\Type
值: DWORD: 272 (0x110)
3、解密病毒资源信息包括(病毒的连网上线地址、端口、服务名):
加密前
"-gEAA5YB8QIClgHxAgLRlpYB8QIC+v7zvQP7+5YDAvuWlvfz8++pvLzv77S0rq+9sLCxsb388QSpsbCzsp8="
解密后
"abcd bree breeR breemat.dll del http://pp7710.3***.org:2345"
解密代码:
00401F02 |> /8B5424 04 /MOV EDX,DWORD PTR SS:[ESP+4]
00401F06 |. |8A1C11 |MOV BL,BYTE PTR DS:[ECX+EDX]
00401F09 |. |80C3 7A |ADD BL,7A
00401F0C |. |881C11 |MOV BYTE PTR DS:[ECX+EDX],BL
00401F0F |. |8B5424 04 |MOV EDX,DWORD PTR SS:[ESP+4]
00401F13 |. |8A1C11 |MOV BL,BYTE PTR DS:[ECX+EDX]
00401F16 |. |80F3 19 |XOR BL,19
00401F19 |. |881C11 |MOV BYTE PTR DS:[ECX+EDX],BL
00401F1C |. |41 |INC ECX
00401F1D |. |3BC8 |CMP ECX,EAX
00401F1F |.^\7C E1 \JL SHORT 6.00401F02
使用RUN32DLL.EXE启动病毒DLL文件"rundll32.exe C:\WINDOWS\system32\breemat.dll setup" |