1、文件运行后会释放以下文件
%Windir%\yataghan.exe
2、病毒运行后用Load资源加密信息,包括病毒要衍生病毒名称、上线IP地址、端口、服务名等信息
CCCQFOGTCKCYAYAIECBZBFEJHADBEGEQANGNCWJFCGCJEFGUAGAJDXEOFGFCBAEUEYACHNHIGRDTFKISBJBUEMFEFRELIBEBBHA
HHAGHBBDMESHLDOFQFGEGFLDOFBATCPGPCTBEAEBEAMGGJSDIFUHQDJFZDICHBQBIGMEXHKHPFZFYBBAYFOEEJKIRFPATDTICGN
BYGIHAIFCOAOEMBFAZIYGJGOBRBUHHDPHDEJFKJFJABGJTBTEZJCEIBBANGWGEBPAJEZIVESEUJSBZCDHECNAFEOHHDYBAAKEWH
KJGEDEWGLAGAODQIODBHMFGAHDDCKDAHQADDLEYFCBT
解密后:
10.0.23.**:7187、yataghan.exe、yataghanfuckurmother、60000、iexplore.exe、 yataghanfuckyoumother09
3、开启一个IEXPLORE.EXE进程并将病毒代码注入到该进程中连接网络进行通信,还有一种方法是注入到userinit.exe、svchost.exe进程中
4、创建病毒服务
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yataghanfuckurmother\Description
值: 字符串: "FinalFantasy服务端程序"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yataghanfuckurmother\DisplayName
值: 字符串: "yataghanfuckurmother"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yataghanfuckurmother\Description
值: 字符串: "FinalFantasy服务端程序"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yataghanfuckurmother\ImagePath
值: 字符串: "C:\WINDOWS\yataghan.exe."
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yataghanfuckurmother\Start
值: DWORD: 2 (0x2)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yataghanfuckurmother\Type
值: DWORD: 272 (0x110)
描述:添加注册表服务 |