home *** CD-ROM | disk | FTP | other *** search
/ AmigActive 19 / AACD19.BIN / AACD / System / Safe14.9 / Analyze / Expl0de.analyze
Text File  |  2001-02-03  |  4KB  |  104 lines

  1.  
  2. Entry...............: Expl0de Virus
  3. Alias(es)...........: VaginitisClone
  4. Virus Strain........: none
  5. Virus detected when.: 1.2001
  6.               where.: New Zealand
  7. Classification......: System/Linkvirus, memory-resident, not reset-resident
  8. Length of Virus.....: 1. Length on storage medium:      ca 730 Bytes
  9.                       2. Length in RAM:                   2048 Bytes
  10.  
  11. --------------------- Preconditions ------------------------------------
  12.  
  13. Operating System(s).: AMIGA-DOS Version/Release..: 2.04 and above (V37+)
  14. Computer model(s)...: all models/processors (MC68000-MC68060)
  15.  
  16. --------------------- Attributes ---------------------------------------
  17.  
  18. Easy Identification.: none
  19.  
  20. Type of infection...: Self-identification method in files:
  21.  
  22.                       - none (the virus infects only C:mount)
  23.  
  24.                       Self-identification method in memory:
  25.  
  26.                       - checks for $60ea at LoadSeg patch offset -2
  27.  
  28.                       System infection:
  29.                       -  infects the following function:
  30.                          Dos LoadSeg()
  31.  
  32.  
  33.                       Infection preconditions:
  34.  
  35.                       - Hunk Code is found
  36.                       - File is not infected already (double
  37.                         infections are impossible)
  38.                       - device is validated
  39.                       - device contains free blocks
  40.  
  41.  
  42. Infection Trigger...: Direct accessing C:mount
  43.  
  44. Storage media affected:
  45.                       C:
  46.  
  47. Interrupts hooked...: None
  48.  
  49. Damage..............: Permanent damage:
  50.                       - none
  51.                       Transient damage:
  52.                       - none
  53. Damage Trigger......: Permanent damage:
  54.                       - none
  55.                       Transient damage:
  56.                       - none
  57.  
  58. Particularities.....: (Installer is currently unknown.)
  59.                       Installer infects only one file - C:mount,
  60.                       the code of Vaginitis/Fungus virus is used
  61.                       here only to implement TCP: new shell
  62.                       opener to system.
  63.                       The virus performs:
  64.                       run >nil: newshell TCP:9876
  65.                       
  66. Similarities........: Link-method is first hunk increasing.
  67.                       Last RTS will be rewritten with nop.
  68.                       Whole code is 95% equal to Fungus/Vaginitis
  69.                       viruses.
  70.  
  71. Stealth.............: Only one file is infected.
  72.                       One of the additional files is file called
  73.                       c:f which is small lame coded patcher for
  74.                       dos/Write prepared to prevent writing files that
  75.                       contain string '.987'. This is to hide
  76.                       existence of the secret shell in TCP:,
  77.                       also may damage some files with this string.
  78.  
  79. Armouring...........: very simply eor crypter with static key $1337
  80.  
  81.  
  82. Comments............: The virus contains string 'expl0de!'.
  83.                       The virus probably appeared with some other support
  84.                       stuff that will be analyzed if we get it.
  85.                       Author of this virus in love with
  86.                       the longword $DEADF00D.
  87.  
  88. --------------------- Agents -------------------------------------------
  89.  
  90. Countermeasures.....: -
  91. above Standard means......: -
  92.  
  93. --------------------- Acknowledgement ----------------------------------
  94.  
  95. Location............: Pawlowice, Poland  25.1.2001
  96. Classification by...: Zbigniew Trzcionkowski
  97. Documentation by....: Zbigniew Trzcionkowski
  98. Date................: 25.1.2001
  99. Information Source..: Virus disassembly
  100. Copyright...........: This documentation is public domain
  101.  
  102. ===================== End of Expl0de virus =============================
  103.  
  104.