Portable ExecutablePE˥ե륤ե륹뤳Ȥɤ뤳ȤRAWե륷ƥͳե륤եΥǤϡMaster Boot RecordMBR˥ե륷ƥ।եפϡ⤦
ˤϡPEե𤵤ʤƤ궯Ǥǡȯ䥳ȥ뤬ưפȤͳ⤢롣оŪMBRեϤʣǡ627C00Hˤ˸ꤵƤ롣ޤ顼;Ϥ⾯ʤʤMBRե륷ƥ।եǤξʥߥХϡƥưǽˤΤ
äơĤ̵ե붦ͭͥåȥˤäۤƤ餷Trojan:W32/Smitnyl.A (98b349c7880eda46c63ae1061d2475181b2c9d7b)פΤ褦MBRե륷ƥ।եϡĤPortable ExecutableƥեɸŪˤƤǤäƤ⡢Ƥδ̤Υ륹ե륤եӤñǤäƤ⡢®ʬϤ뤳ȤϲͤȻפ롣
Smitnyl.AפϺǽˡRAWǥ𤷤MBR롣ˤե륤ե롼ޤభդMBR֤ʥ32¸ˡ
12ꥸʥMBRѡ1ʾˤȥѡ2ʲ


ʤMBRե륷ƥ।եʤΤ餯ϡ줬Windows File ProtectionWFPˤХѥ뤳ȤǤ뤫WFPϥץƥȥ⡼ɤưƤΤǡ⤷֤С٤ƤWFPݸե¨¤˥ꥹȥ롣
եڥɤA00Hǥ39鳫ϤǡꥸʥMBRϥ5¸롣ΥڥɤϡWindowsΥƥ륷ƥեuserinit.exeפ˾롣
3416ˡˤ봶MBRʺˤȥꥸʥMBRʲ


516ˡˤMBRե륷ƥ।ե롼

616ˡˤUserinitեڥ

ʤUserinitפʤΤ餯ϡƥबȤȼưŪ˥ץΰĤǤꡢƥॹȻ˥ޥ륦ưŪ˼¹Բǽˤʤ뤿
Smitnylפϥ֡ȥκǽΥơ顢Userinit롣MBR0x7C00˥ɤݡѡƥơ֥롢ˤϥ֡ȥstarting offset饢ƥ֥ѡƥ¬ꤹ롣
˥ޥΥե륷ƥॿפå롧
7֡ȥפ¬

NTFSե륷ƥबĤСޥեơ֥MFTˤϤMFTϤȲꤷơ˥ǥΡUserinitפǡꤹ뤿ᡢ$ROOT (.)ե쥳ɤ°ɤ$INDEX_ALLOCATION°õSmitnylפϡuserinit.exe֤Ƥ롢$ROOTSystem32ǥ쥯ȥޤWindowsΥѥå롣
89Userinit.exeΰ֤ꤹ롣ѡ1


Υޥ륦ϡuserinit.exeեĤΤˡget_userinit_data_content_addrץ롼ѤExtended Write FunctionʥեʥС ah = 43HˤѤơ39ǥեڥɤࡣuserinit.exe롼δ֡Ʊޥ륦offset 0x28Ǵޡ¸ߤʸ夫ܤ˥å롣
1011Userinit.exeΰ֤ꤹ롣ѡ2


ޥMBRȤȤˡޤ֡Ȥȡuserinit.exeϴ졢ưŪ˥Ϥuserinit.exeǧĤˡϡեץѥƥΥå
1213userinit.exeץѥƥꥸʥȴ

ʤȤˡ㤤Ϥʤ
16ɽǡեƤߤ褦
14Userinit

ե롼˴ޡ0x55AAåȻŦȤפФǤϤ줬¹Ԥݡ褦ȤΤפʥڥɤϥ45ˤ롢ɤ줿¹ԥե뤳Ȥ
1545Υɤ줿¹ԥե

ϥǥɤϤǽڥɤˡĤνԤ
• 360safe륹¸ߤå롣⤷ĤС360safe IE֥饦ץƥ̵ˤ롣
16360safe IEץƥ쥸ȥꥭå

• ե˵explorer.exe롣ϡǥɤ줿¹ԥե
17ǥɤ줿¹ԥեˤ뵶Explorer

18ǥɤ줿¹ԥեˤ뵶Explorer

• ǥǥ塢ShellExecuteѤơ%temp%\explorer.exeפ롣ϴǥȤѤ롣ƱˡWinexecפѤʪΡexplorer.exeפ¹Ԥ롣
Ρexplorer.exeפ¹ԤꥸʥΡexplorer.exeפ

λȡڥɤ롣
20ǽڥ

ˤ⡢κǽڥɤˤϲ̤ʤȤ̵ñʤuserinit.exeפϡ360safeIE֥饦ݸ̵ˤˤ⡼ȥСhttp://[...]פեФȤǽˤʤ롣
ƤLow Chin Yickˤ롣
ˤϡPEե𤵤ʤƤ궯Ǥǡȯ䥳ȥ뤬ưפȤͳ⤢롣оŪMBRեϤʣǡ627C00Hˤ˸ꤵƤ롣ޤ顼;Ϥ⾯ʤʤMBRե륷ƥ।եǤξʥߥХϡƥưǽˤΤ
äơĤ̵ե붦ͭͥåȥˤäۤƤ餷Trojan:W32/Smitnyl.A (98b349c7880eda46c63ae1061d2475181b2c9d7b)פΤ褦MBRե륷ƥ।եϡĤPortable ExecutableƥեɸŪˤƤǤäƤ⡢Ƥδ̤Υ륹ե륤եӤñǤäƤ⡢®ʬϤ뤳ȤϲͤȻפ롣
Smitnyl.AפϺǽˡRAWǥ𤷤MBR롣ˤե륤ե롼ޤభդMBR֤ʥ32¸ˡ
12ꥸʥMBRѡ1ʾˤȥѡ2ʲ


ʤMBRե륷ƥ।եʤΤ餯ϡ줬Windows File ProtectionWFPˤХѥ뤳ȤǤ뤫WFPϥץƥȥ⡼ɤưƤΤǡ⤷֤С٤ƤWFPݸե¨¤˥ꥹȥ롣
եڥɤA00Hǥ39鳫ϤǡꥸʥMBRϥ5¸롣ΥڥɤϡWindowsΥƥ륷ƥեuserinit.exeפ˾롣
3416ˡˤ봶MBRʺˤȥꥸʥMBRʲ


516ˡˤMBRե륷ƥ।ե롼

616ˡˤUserinitեڥ

ʤUserinitפʤΤ餯ϡƥबȤȼưŪ˥ץΰĤǤꡢƥॹȻ˥ޥ륦ưŪ˼¹Բǽˤʤ뤿
Smitnylפϥ֡ȥκǽΥơ顢Userinit롣MBR0x7C00˥ɤݡѡƥơ֥롢ˤϥ֡ȥstarting offset饢ƥ֥ѡƥ¬ꤹ롣
˥ޥΥե륷ƥॿפå롧
7֡ȥפ¬

NTFSե륷ƥबĤСޥեơ֥MFTˤϤMFTϤȲꤷơ˥ǥΡUserinitפǡꤹ뤿ᡢ$ROOT (.)ե쥳ɤ°ɤ$INDEX_ALLOCATION°õSmitnylפϡuserinit.exe֤Ƥ롢$ROOTSystem32ǥ쥯ȥޤWindowsΥѥå롣
89Userinit.exeΰ֤ꤹ롣ѡ1


Υޥ륦ϡuserinit.exeեĤΤˡget_userinit_data_content_addrץ롼ѤExtended Write FunctionʥեʥС ah = 43HˤѤơ39ǥեڥɤࡣuserinit.exe롼δ֡Ʊޥ륦offset 0x28Ǵޡ¸ߤʸ夫ܤ˥å롣
1011Userinit.exeΰ֤ꤹ롣ѡ2


ޥMBRȤȤˡޤ֡Ȥȡuserinit.exeϴ졢ưŪ˥Ϥuserinit.exeǧĤˡϡեץѥƥΥå
1213userinit.exeץѥƥꥸʥȴ


ʤȤˡ㤤Ϥʤ
16ɽǡեƤߤ褦
14Userinit

ե롼˴ޡ0x55AAåȻŦȤפФǤϤ줬¹Ԥݡ褦ȤΤפʥڥɤϥ45ˤ롢ɤ줿¹ԥե뤳Ȥ
1545Υɤ줿¹ԥե

ϥǥɤϤǽڥɤˡĤνԤ
• 360safe륹¸ߤå롣⤷ĤС360safe IE֥饦ץƥ̵ˤ롣
16360safe IEץƥ쥸ȥꥭå

• ե˵explorer.exe롣ϡǥɤ줿¹ԥե
17ǥɤ줿¹ԥեˤ뵶Explorer

18ǥɤ줿¹ԥեˤ뵶Explorer

• ǥǥ塢ShellExecuteѤơ%temp%\explorer.exeפ롣ϴǥȤѤ롣ƱˡWinexecפѤʪΡexplorer.exeפ¹Ԥ롣
Ρexplorer.exeפ¹ԤꥸʥΡexplorer.exeפ

λȡڥɤ롣
20ǽڥ

ˤ⡢κǽڥɤˤϲ̤ʤȤ̵ñʤuserinit.exeפϡ360safeIE֥饦ݸ̵ˤˤ⡼ȥСhttp://[...]פեФȤǽˤʤ롣
ƤLow Chin Yickˤ롣