-

   rss_drweb_viruses

 - e-mail

 

 -

 LiveInternet.ru:
: 30.09.2009
: 711
: 1
: 1

:


Belonard, Counter-Strike 1.6

, 07 2019 . 19:58 +

11 2019

Counter-Strike Valve 2000 . , CS 1.6 20 000 , Steam 5000. , . , 200 , -.

, : , . , . , , . , Belonard : .

#drweb

. , , . Remote Code Execution (RCE): .

, Trojan.Belonard , - . , - , . , Trojan.Belonard.

, CS 1.6. , 5000 , Steam, 1951 Belonard. 39% . , .

CS 1.6, . , . Valve. , , , .

rojan.Belonard 11 . , RCE-, , . . , .

#drweb

. Steam . RCE-, , client.dll (Trojan.Belonard.1) Mssv24.asi (Trojan.Belonard.5).

, Trojan.Belonard.1 .dat , . fuztxhus.valve-ms[.]ru:28445 Mp3enc.asi (Trojan.Belonard.2). .

, :

#drweb

Counter-Strike. .asi .

, , Trojan.Belonard.10 ( Mssv36.asi), , . , Trojan.Belonard.10 . , Trojan.Belonard.5 ( Mssv24.asi). , Trojan.Belonard.10 , , . , , .

Trojan.Belonard.10 . , , , .

Trojan.Belonard.5 DllMain . rundll32.exe, . Trojan.Belonard.5 [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] '< >', RUNASADMIN . Mssv24.asi, Mssv24.asi, , Trojan.Belonard.3 ( Mssv16.asi). , .

Trojan.Belonard.2. DllMain , client.dll (Trojan.Belonard.1). rundll32.exe, [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] '< >' RUNASADMIN. , DialogGamePage.res. .

:

#drweb

Mssv16.asi (Trojan.Belonard.3). DialogGamePage.res, Trojan.Belonard.5 .

Trojan.Belonard.3. , Trojan.Belonard.5 , . rundll32.exe, %WINDIR%\System32\ : Trojan.Belonard.7 ( WinDHCP.dll) Trojan.Belonard.6 (davapi.dll). , Trojan.Belonard.5, . 0xFFFC ( ). .

, Trojan.Belonard.3 WinDHCP WinDHCP.dll (Trojan.Belonard.7) svchost.exe. , .

WinDHCP:

  • : Windows DHCP Service Windows DHCP;
  • : Windows Dynamic Host Configuration Protocol Service Windows;
  • ImagePath : %SystemRoot%\System32\svchost.exe -k netsvcs, ServiceDll .

Trojan.Belonard.3 , WinDHCP. , .

Trojan.Belonard.7 WinDHCP.dll ServiceMain . , HKLM\SYSTEM\CurrentControlSet\Services\WinDHCP Tag. 0, Trojan.Belonard.7 davapi.dll (Trojan.Belonard.6) , SERVICE_STATUS, WinDHCP. 1 Tag. 0, Trojan.Belonard.7 spwinres.dll (Trojan.Belonard.4), Trojan.Belonard.6. , SERVICE_STATUS, WinDHCP.

.

WinDHCP, :
















Trojan.Belonard.6 WinDHCP Tag Data. Data , AES . , openssl 32 , . Info Scheme WinDHCP. Scheme 4 AES- . Info SHA256 .

, Trojan.Belonard.6 oihcyenw.valve-ms[.]ru . , DGA .ru. , - , .

, %WINDIR%\System32\. wmcodecs.dll (Trojan.Belonard.8) ssdp32.dll (Trojan.Belonard.9).

Trojan.Belonard.6 :

  • Counter-Strike 1.6;
  • Trojan.Belonard.9;
  • .

.

Belonard , . Trojan.Belonard.8 Trojan.Belonard.6.

Trojan.Belonard.8 Counter-Strike 1.6 SHA256-. Trojan.Belonard.6 . , SHA256- , Trojan.Belonard.8. , Trojan.Belonard.8 , hl.exe . , Could not load game. Please try again at a later time. , . , hl.exe , .

:

\\valve\\dlls\\*
\\cstrike\\dlls\\*
\\valve\\cl_dlls\\*
\\cstrike\\cl_dlls\\*
\\cstrike\\resource\\*.res
\\valve\\resource\\*.res
\\valve\\motd.txt
\\cstrike\\resource\\gameui_english.txt
\\cstrike\\resource\\icon_steam.tga
\\valve\\resource\\icon_steam.tga
\\cstrike\\resource\\icon_steam_disabled.tga
\\valve\\resource\\icon_steam_disabled.tga
\\cstrike\\sound\\weapons\\fiveseven_reload_clipin_sliderelease.dll
\\cstrike_russian\\sound\\weapons\\fiveseven_reload_clipin_sliderelease.dll
\\cstrike_romanian\\sound\\weapons\\fiveseven_reload_clipin_sliderelease.dll

.

Trojan.Belonard.10, . , , , CS 1.6 11 500 .

. .

#drweb

Trojan.Belonard.9 - Steam API. game_srv_low_port, . fakesrvbatch, . Goldsource - A2S_INFO, A2S_PLAYER, A2A_PING, challenge steam/non-steam , Counter-Strike connect. connect .

- svc_director DRC_CMD_STUFFTEXT, Counter-Strike. Valve 2014 . , - . Trojan.Belonard.

, Trojan.Belonard.9 , -. , - : Game Counter-Strike n, n 1 3.

#drweb

Belonard . , . . .

Trojan.Belonard.2:

def decrypt(d):
s = ''
c = ord(d[0])
for i in range(len(d)-1):
c = (ord(d[i+1]) + 0xe2*c - 0x2f*ord(d[i]) - 0x58) & 0xff
s += chr(c)
return s

:

def decrypt(data):
s = 'f'
for i in range(0,len(data)-1):
s += chr((ord(s[i]) + ord(data[i]))&0xff)
print s

Belonard . , . RSA . , RSA 342 . , 342 , RSA, AES. AES- , RSA-. AES-, .

, . , AES-.

, :

#pragma pack(push,1)
struct st_payload
{
_BYTE hash1[32];
_DWORD totalsize;
_BYTE hash2[32];
_DWORD dword44;
_DWORD dword48;
_DWORD dword4c;
_WORD word50;
char payload_name[];
_BYTE payload_sha256[32];
_DWORD payload_size;
_BYTE payload_data[payload_size];
}
#pragma pack(pop)

AES CFB 128 , . 36 , DWORD . AES- DWORD SHA256. 32 . .

. REG.ru . - , CS 1.6 Belonard. .

, Dr.Web , , DGA. - 127 . , Dr.Web Belonard 1004 .

, Counter-Strike .

8bbc0ebc85648bafdba19369dff39dfbd88bc297 - Backdoored Counter-Strike 1.6 client
200f80df85b7c9b47809b83a4a2f2459cae0dd01 - Backdoored Counter-Strike 1.6 client
8579e4efe29cb999aaedad9122e2c10a50154afb - Backdoored Counter-Strike 1.6 client
ce9f0450dafda6c48580970b7f4e8aea23a7512a - client.dll - Trojan.Belonard.1
75ec1a47404193c1a6a0b1fb61a414b7a2269d08 - Mp3enc.asi - Trojan.Belonard.2
4bdb31d4d410fbbc56bd8dd3308e20a05a5fce45 - Mp3enc.asi - Trojan.Belonard.2
a0ea9b06f4cb548b7b2ea88713bd4316c5e89f32 - Mssv36.asi - Trojan.Belonard.10
e6f2f408c8d90cd9ed9446b65f4b74f945ead41b - FileSystem.asi - Trojan.Belonard.11
15879cfa3e5e4463ef15df477ba1717015652497 - Mssv24.asi - Trojan.Belonard.5
4b4da2c0a992d5f7884df6ea9cc0094976c1b4b3 - Mssv24.asi - Trojan.Belonard.5
6813cca586ea1c26cd7e7310985b4b570b920803 - Mssv24.asi - Trojan.Belonard.5
6b03e0dd379965ba76b1c3d2c0a97465329364f2 - Mssv16.asi - Trojan.Belonard.3
2bf76c89467cb7c1b8c0a655609c038ae99368e9 - Mssv16.asi - Trojan.Belonard.3
d37b21fe222237e57bc589542de420fbdaa45804 - Mssv16.asi - Trojan.Belonard.3
72a311bcca1611cf8f5d4d9b4650bc8fead263f1 - Mssv16.asi - Trojan.Belonard.3
73ba54f9272468fbec8b1d0920b3284a197b3915 - davapi.dll - Trojan.Belonard.6
d6f2a7f09d406b4f239efb2d9334551f16b4de16 - davapi.dll - Trojan.Belonard.6
a77d43993ba690fda5c35ebe4ea2770e749de373 - spwinres.dll - Trojan.Belonard.4
8165872f1dbbb04a2eedf7818e16d8e40c17ce5e - WinDHCP.dll - Trojan.Belonard.7
027340983694446b0312abcac72585470bf362da - WinDHCP.dll - Trojan.Belonard.7
93fe587a5a60a380d9a2d5f335d3e17a86c2c0d8 - wmcodecs.dll - Trojan.Belonard.8
89dfc713cdfd4a8cd958f5f744ca7c6af219e4a4 - wmcodecs.dll - Trojan.Belonard.8
2420d5ad17b21bedd55309b6d7ff9e30be1a2de1 - ssdp32.dll - Trojan.Belonard.9

client.dll - Trojan.Belonard.1
Mp3enc.asi - Trojan.Belonard.2
Mssv16.asi - Trojan.Belonard.3
spwinres.dll - Trojan.Belonard.4
Mssv24.asi - Trojan.Belonard.5
davapi.dll - Trojan.Belonard.6
WinDHCP.dll - Trojan.Belonard.7
wmcodecs.dll - Trojan.Belonard.8
ssdp32.dll - Trojan.Belonard.9
Mssv36.asi - Trojan.Belonard.10
FileSystem.asi - Trojan.Belonard.11

csgoogle.ru
etmpyuuo.csgoogle.ru
jgutdnqn.csgoogle.ru
hl.csgoogle.ru
half-life.su
play.half-life.su
valve-ms.ru
bmeadaut.valve-ms.ru
fuztxhus.valve-ms.ru
ixtzhunk.valve-ms.ru
oihcyenw.valve-ms.ru
suysfvtm.valve-ms.ru
wcnclfbi.valve-ms.ru
reborn.valve-ms.ru

IP-

37.143.12.3
46.254.17.165

http://feedproxy.google.com/~r/drweb/viruses/~3/NeK10p1f1qE/


: [1] []
 

:
: 

: ( )

:

  URL