Portable ExecutablePE˥ե륤ե륹򸫤뤳Ȥɤ뤳ȤRAWե륷ƥͳե륤եΥǤϡMaster Boot RecordMBR˥ե륷ƥ।եפϡ⤦

 ˤϡPEե𤵤ʤƤ궯Ǥǡȯ䥳ȥ뤬ưפȤͳ⤢롣оŪMBRեϤʣǡ627C00Hˤ˸ꤵƤ롣ޤ顼;Ϥ⾯ʤʤMBRե륷ƥ।եǤξʥߥХϡƥưǽˤΤ

 äơĤ̵ե붦ͭͥåȥˤäۤƤ餷Trojan:W32/Smitnyl.A (98b349c7880eda46c63ae1061d2475181b2c9d7b)פΤ褦MBRե륷ƥ।եϡĤPortable ExecutableƥեɸŪˤƤǤäƤ⡢Ƥδ̤Υ륹ե륤եӤñǤäƤ⡢®ʬϤ뤳ȤϲͤȻפ롣

 Smitnyl.AפϺǽˡRAWǥ𤷤MBR롣ˤ򡢥ե륤ե롼ޤభդMBR֤ʥ32¸ˡ

12ꥸʥMBR񤭡ѡ1ʾˤȥѡ2ʲ
1: Overwriting original MBR

2: Overwriting original MBR

 ʤMBRե륷ƥ।եʤΤ餯ϡ줬Windows File ProtectionWFPˤХѥ뤳ȤǤ뤫WFPϥץƥȥ⡼ɤưƤΤǡ⤷֤С٤ƤWFPݸե¨¤˥ꥹȥ롣

 եڥɤA00Hǥ39鳫ϤǡꥸʥMBRϥ5¸롣ΥڥɤϡWindowsΥƥ륷ƥեuserinit.exeפ˾񤭤롣

3416ˡˤ봶MBRʺˤȥꥸʥMBRʲ
3: Hex view of infected MBR

4: Hex view of original MBR

516ˡˤMBRե륷ƥ।ե롼
5: Hex View MBR File System Infector Routine

616ˡˤUserinitեڥ
6: Hex View Userinit Infector Payload

 ʤUserinitפʤΤ餯ϡƥबȤȼưŪ˥ץΰĤǤꡢƥॹȻ˥ޥ륦ưŪ˼¹Բǽˤʤ뤿

 Smitnylפϥ֡ȥ󥹤κǽΥơ顢Userinit롣MBR0x7C00˥ɤݡѡƥơ֥롢ˤϥ֡ȥstarting offset饢ƥ֥ѡƥ¬ꤹ롣

 ˥ޥΥե륷ƥॿפå롧

7֡ȥפ¬
7: Determine Boot Sector Type

 NTFSե륷ƥबĤСޥեơ֥MFTˤϤMFTϤȲꤷơ˥ǥΡUserinitפǡꤹ뤿ᡢ$ROOT (.)ե쥳ɤ°ɤ$INDEX_ALLOCATION°õSmitnylפϡuserinit.exe֤Ƥ롢$ROOTSystem32ǥ쥯ȥޤWindowsΥѥå롣

89Userinit.exeΰ֤ꤹ롣ѡ1
8: Locate Userinit.exe, Part 1

9: Locate Userinit.exe, Part 1

 Υޥ륦ϡuserinit.exeե򸫤ĤΤˡget_userinit_data_content_addrץ롼ѤExtended Write Functionʥե󥯥ʥС ah = 43HˤѤơ39ǥեڥɤ񤭹ࡣuserinit.exe롼δ֡Ʊޥ륦offset 0x28Ǵޡ¸ߤʸ夫ܤ˥å롣

1011Userinit.exeΰ֤ꤹ롣ѡ2
10: Locate Userinit.exe, Part 2

11: Locate Userinit.exe, Part 2

 ޥ󤬴MBRȤȤˡޤ֡Ȥȡuserinit.exeϴ졢ưŪ˥Ϥuserinit.exeǧĤˡϡեץѥƥΥå

1213userinit.exeץѥƥꥸʥȴ
userinit.exe Properties, original userinit.exe Properties, infected

 ʤȤˡ㤤Ϥʤ

 16ɽǡե򸫤Ƥߤ褦

14Userinit
14: Infected Userinit

 ե롼󤬡˴ޡ0x55AAåȻŦȤפФǤϤ줬¹Ԥݡ򤷤褦ȤΤפʥڥɤϥ45ˤ롢󥳡ɤ줿¹ԥե뤳Ȥ

1545Υ󥳡ɤ줿¹ԥե
15: Encoded Executable File at Sector 45

 ϥǥɤ򳫻ϤǽڥɤˡĤνԤ

  •  360safe륹¸ߤå롣⤷ĤС360safe IE֥饦ץƥ̵ˤ롣

16360safe IEץƥ󡦥쥸ȥꥭå
16: 360safe IE Protection Registry Key Checking

  •  ե˵explorer.exe롣ϡǥɤ줿¹ԥե

17ǥɤ줿¹ԥեˤ뵶Explorer
17: Fake Explorer with Decoded Executable

18ǥɤ줿¹ԥեˤ뵶Explorer
18: Fake Explorer with Decoded Executable

  •  ǥǥ󥰸塢ShellExecuteѤơ%temp%\explorer.exeפ롣ϴ򱣤ǥȤѤ롣ƱˡWinexecפѤʪΡexplorer.exeפ¹Ԥ롣

Ρexplorer.exeפ¹ԤꥸʥΡexplorer.exeפ
19: Execute fake explorer.exe and launch original explorer.exe

 λȡڥɤ롣

20ǽڥ
20: Final Downloader Payload

 ˤ⡢κǽڥɤˤϲ̤ʤȤ̵ñʤuserinit.exeפϡ360safeIE֥饦ݸ̵ˤˤ⡼ȥСhttp://[...]פեФȤǽˤʤ롣

ƤLow Chin Yickˤ롣