La mia libreria
La mia libreria

Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Libreria dei virus

L’analisi delle tecnologie utilizzate dai malfattori ci permette di trarre conclusioni su possibili vettori dello sviluppo del settore dei virus affinché possiamo affrontare le minacce future in modo ancora più efficace. Scoprite anche voi come funzionano in sistemi infetti determinati programmi malevoli e come affrontarli.

Linux.Sshdkit nella libreria di virus:

A malicious dynamic library for 32-bit and 64-bit Linux distributions. On different infected servers, the following file names were detected:

  • libkeyutils.so.1.9,
  • libkeyutils.so.1.3.0,
  • libkeyutils.so.1.3.2,
  • libkeyutils-1.2.so.2.

Depending on the platform, the files resided in /lib or /lib64.</p. <<

The Trojan's main purpose is to steal SSHD passwords by intercepting the following functions:

  • pam_authenticate,
  • crypt.

Using the XOR algorithm and a 4-byte key stored in the Trojan's body, the malicious program encrypts data and forwards it via the UDP protocol to port 53 of the remote server. The data is included into a standard DNS request for dereferencing of a domain name.

At first, the IP address 78.47.***.110 is used as a remote server. After that, a new IP address is determined every two days. For this purpose, a domain generation algorithm consisting of the following steps is used:

  1. Depending on the infection date, two numbers are selected every two days.
  2. Every number is modified into a string sequence with one of the following suffixes: “.biz”, “.info”, “.net”.
  3. Both strings should resolve to the same IP address.
  4. The IP address determined at the third step is modified into the final IP address, which will be used for data transfer.

It should be noted that the counter of infection days resets every 10, 20, 30 and till 1,024 days from the moment of infection. Thus, a possible number of domain pairs equals 1,024.

The malware also performs other malicious activities. For example, it can set a default password to access the infected server. Moreover, the Trojan can execute the following commands:

  • Xver—print to the console the Trojan's version.
  • Xcat—print to the console the gathered data.
  • Xbnd—establish a connection using the connect() function.

Linux.Sshdkit nella libreria di virus:

Vulnerabilità per Android

Secondo le statistiche ogni quinto programma per SO Android contiene una vulnerabilità (ovvero un "buco"), il che permette ai malfattori di introdurre con successo trojan mobili sui dispositivi e di eseguire le azioni richieste.

Auditor di sicurezza in Dr.Web per Android farà la diagnostica e l’analisi della sicurezza del dispositivo mobile, proporrà soluzioni per risolvere i problemi e le vulnerabilità rilevate.