Belonard, Counter-Strike 1.6 |
11 2019
Counter-Strike Valve 2000 . , CS 1.6 20 000 , Steam 5000. , . , 200 , -.
, : , . , . , , . , Belonard : .
. , , . Remote Code Execution (RCE): .
, Trojan.Belonard , - . , - , . , Trojan.Belonard.
, CS 1.6. , 5000 , Steam, 1951 Belonard. 39% . , .
rojan.Belonard 11 . , RCE-, , . . , .
. Steam . RCE-, , client.dll (Trojan.Belonard.1) Mssv24.asi (Trojan.Belonard.5).
, Trojan.Belonard.1 .dat , . fuztxhus.valve-ms[.]ru:28445 Mp3enc.asi (Trojan.Belonard.2). .
, :
Counter-Strike. .asi .
, , Trojan.Belonard.10 ( Mssv36.asi), , . , Trojan.Belonard.10 . , Trojan.Belonard.5 ( Mssv24.asi). , Trojan.Belonard.10 , , . , , .
Trojan.Belonard.10 . , , , .
Trojan.Belonard.5 DllMain . rundll32.exe, . Trojan.Belonard.5 [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] '< >', RUNASADMIN . Mssv24.asi, Mssv24.asi, , Trojan.Belonard.3 ( Mssv16.asi). , .
Trojan.Belonard.2. DllMain , client.dll (Trojan.Belonard.1). rundll32.exe, [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] '< >' RUNASADMIN. , DialogGamePage.res. .
:
Mssv16.asi (Trojan.Belonard.3). DialogGamePage.res, Trojan.Belonard.5 .
Trojan.Belonard.3. , Trojan.Belonard.5 , . rundll32.exe, %WINDIR%\System32\ : Trojan.Belonard.7 ( WinDHCP.dll) Trojan.Belonard.6 (davapi.dll). , Trojan.Belonard.5, . 0xFFFC ( ). .
, Trojan.Belonard.3 WinDHCP WinDHCP.dll (Trojan.Belonard.7) svchost.exe. , .
WinDHCP:
Trojan.Belonard.3 , WinDHCP. , .
Trojan.Belonard.7 WinDHCP.dll ServiceMain . , HKLM\SYSTEM\CurrentControlSet\Services\WinDHCP Tag. 0, Trojan.Belonard.7 davapi.dll (Trojan.Belonard.6) , SERVICE_STATUS, WinDHCP. 1 Tag. 0, Trojan.Belonard.7 spwinres.dll (Trojan.Belonard.4), Trojan.Belonard.6. , SERVICE_STATUS, WinDHCP.
.
WinDHCP, :
Trojan.Belonard.6 WinDHCP Tag Data. Data , AES . , openssl 32 , . Info Scheme WinDHCP. Scheme 4 AES- . Info SHA256 .
, Trojan.Belonard.6 oihcyenw.valve-ms[.]ru . , DGA .ru. , - , .
, %WINDIR%\System32\. wmcodecs.dll (Trojan.Belonard.8) ssdp32.dll (Trojan.Belonard.9).
Trojan.Belonard.6 :
.
Belonard , . Trojan.Belonard.8 Trojan.Belonard.6.
Trojan.Belonard.8 Counter-Strike 1.6 SHA256-. Trojan.Belonard.6 . , SHA256- , Trojan.Belonard.8. , Trojan.Belonard.8 , hl.exe . , Could not load game. Please try again at a later time. , . , hl.exe , .
:
.
Trojan.Belonard.10, . , , , CS 1.6 11 500 .
. .
Trojan.Belonard.9 - Steam API. game_srv_low_port, . fakesrvbatch, . Goldsource - A2S_INFO, A2S_PLAYER, A2A_PING, challenge steam/non-steam , Counter-Strike connect. connect .
- svc_director DRC_CMD_STUFFTEXT, Counter-Strike. Valve 2014 . , - . Trojan.Belonard.
, Trojan.Belonard.9 , -. , - : Game Counter-Strike n, n 1 3.
Belonard . , . . .
Trojan.Belonard.2:
def decrypt(d):
s = ''
c = ord(d[0])
for i in range(len(d)-1):
c = (ord(d[i+1]) + 0xe2*c - 0x2f*ord(d[i]) - 0x58) & 0xff
s += chr(c)
return s
:
def decrypt(data):
s = 'f'
for i in range(0,len(data)-1):
s += chr((ord(s[i]) + ord(data[i]))&0xff)
print s
Belonard . , . RSA . , RSA 342 . , 342 , RSA, AES. AES- , RSA-. AES-, .
, . , AES-.
, :
#pragma pack(push,1)
struct st_payload
{
_BYTE hash1[32];
_DWORD totalsize;
_BYTE hash2[32];
_DWORD dword44;
_DWORD dword48;
_DWORD dword4c;
_WORD word50;
char payload_name[];
_BYTE payload_sha256[32];
_DWORD payload_size;
_BYTE payload_data[payload_size];
}
#pragma pack(pop)
AES CFB 128 , . 36 , DWORD . AES- DWORD SHA256. 32 . .
. REG.ru . - , CS 1.6 Belonard. .
, Dr.Web , , DGA. - 127 . , Dr.Web Belonard 1004 .
, Counter-Strike .
8bbc0ebc85648bafdba19369dff39dfbd88bc297 - Backdoored Counter-Strike 1.6 client
200f80df85b7c9b47809b83a4a2f2459cae0dd01 - Backdoored Counter-Strike 1.6 client
8579e4efe29cb999aaedad9122e2c10a50154afb - Backdoored Counter-Strike 1.6 client
ce9f0450dafda6c48580970b7f4e8aea23a7512a - client.dll - Trojan.Belonard.1
75ec1a47404193c1a6a0b1fb61a414b7a2269d08 - Mp3enc.asi - Trojan.Belonard.2
4bdb31d4d410fbbc56bd8dd3308e20a05a5fce45 - Mp3enc.asi - Trojan.Belonard.2
a0ea9b06f4cb548b7b2ea88713bd4316c5e89f32 - Mssv36.asi - Trojan.Belonard.10
e6f2f408c8d90cd9ed9446b65f4b74f945ead41b - FileSystem.asi - Trojan.Belonard.11
15879cfa3e5e4463ef15df477ba1717015652497 - Mssv24.asi - Trojan.Belonard.5
4b4da2c0a992d5f7884df6ea9cc0094976c1b4b3 - Mssv24.asi - Trojan.Belonard.5
6813cca586ea1c26cd7e7310985b4b570b920803 - Mssv24.asi - Trojan.Belonard.5
6b03e0dd379965ba76b1c3d2c0a97465329364f2 - Mssv16.asi - Trojan.Belonard.3
2bf76c89467cb7c1b8c0a655609c038ae99368e9 - Mssv16.asi - Trojan.Belonard.3
d37b21fe222237e57bc589542de420fbdaa45804 - Mssv16.asi - Trojan.Belonard.3
72a311bcca1611cf8f5d4d9b4650bc8fead263f1 - Mssv16.asi - Trojan.Belonard.3
73ba54f9272468fbec8b1d0920b3284a197b3915 - davapi.dll - Trojan.Belonard.6
d6f2a7f09d406b4f239efb2d9334551f16b4de16 - davapi.dll - Trojan.Belonard.6
a77d43993ba690fda5c35ebe4ea2770e749de373 - spwinres.dll - Trojan.Belonard.4
8165872f1dbbb04a2eedf7818e16d8e40c17ce5e - WinDHCP.dll - Trojan.Belonard.7
027340983694446b0312abcac72585470bf362da - WinDHCP.dll - Trojan.Belonard.7
93fe587a5a60a380d9a2d5f335d3e17a86c2c0d8 - wmcodecs.dll - Trojan.Belonard.8
89dfc713cdfd4a8cd958f5f744ca7c6af219e4a4 - wmcodecs.dll - Trojan.Belonard.8
2420d5ad17b21bedd55309b6d7ff9e30be1a2de1 - ssdp32.dll - Trojan.Belonard.9
client.dll - Trojan.Belonard.1
Mp3enc.asi - Trojan.Belonard.2
Mssv16.asi - Trojan.Belonard.3
spwinres.dll - Trojan.Belonard.4
Mssv24.asi - Trojan.Belonard.5
davapi.dll - Trojan.Belonard.6
WinDHCP.dll - Trojan.Belonard.7
wmcodecs.dll - Trojan.Belonard.8
ssdp32.dll - Trojan.Belonard.9
Mssv36.asi - Trojan.Belonard.10
FileSystem.asi - Trojan.Belonard.11
csgoogle.ru
etmpyuuo.csgoogle.ru
jgutdnqn.csgoogle.ru
hl.csgoogle.ru
half-life.su
play.half-life.su
valve-ms.ru
bmeadaut.valve-ms.ru
fuztxhus.valve-ms.ru
ixtzhunk.valve-ms.ru
oihcyenw.valve-ms.ru
suysfvtm.valve-ms.ru
wcnclfbi.valve-ms.ru
reborn.valve-ms.ru
IP-
37.143.12.3
46.254.17.165
http://feedproxy.google.com/~r/drweb/viruses/~3/NeK10p1f1qE/