https://faxue.inmoke.com

but since I work in the AV industry as well and had contact

but since I work in the AV industry as well and had contact with Doug before, Batman! Someone actually trojanized WinDirStat and it looks like EPO just from a brief look. Again。

19h.text:004471BBincecx.text:004471BCretf 0BECAh.text:004471BC _wWinMain@16 endp ; sp-analysis failed Holy moly,。

so you should never rely on it alone anyway. It is possible to forge binaries that match the MD5 hash of another binary as recent government-sanctioned malware has shown. [ ] Usually you wont get a file that is deemed malicious from any anti-malware company, Well, so never ever rely on MD5 alone. // Oliver Recap: the clean files are: MD5: 3abf1c149873e25d4e266225fbf37cbf *windirstat1_1_2_setup.exe 3f3dd4476249ae664e3365e5bb651601 *release/windirstat.exe 24cd9a82fcfc658dd3ae7ba25c958ffb *urelease/windirstat.exe SHA1: 6fa92dd2ca691c11dfbfc0a239e34369897a7fab *windirstat1_1_2_setup.exe 752e1687d58de3bef927d9ad24c0ed3da3754e17 *release/windirstat.exe 26e14a532e1e050eb20755a0b7a5fea99dd80588 *urelease/windirstat.exe that false positive has been fixed meanwhile. [ ] keep in mind that MD5 has been broken, but in actuality this is a trojanized version of the genuine file. Now I dont have the time to investigate into what exactly this thing is doing。

ebp.text:004471B9 loc_4471B9:.text:004471B9oral, just some things like the sections and a whole lot of code or data had been changed in the middle of the file. So I loaded the genuine file into IDA Pro and the entry point looked like this: .text:004471B4 _wWinMain@16 proc near.text:004471B4.text:004471B4 hInstance= dword ptr 4.text:004471B4 hPrevInstance = dword ptr 8.text:004471B4 lpCmdLine= dword ptr 0Ch.text:004471B4 nShowCmd= dword ptr 10h.text:004471B4.text:004471B4jmp_wWinMain@16_0.text:004471B4 _wWinMain@16 endp and when I did the same on the trojanized file it looked like this: .text:004471B4 _wWinMain@16 proc far.text:004471B4enter 0FFFFA5D1h, the report I got from a WinDirStat user from Sweden (thanks again!) was that MalwareBytes had detected WDS once again. I assumed false positive and it turned out that it was at least for the particular file that the Swedish user had (SHA1: 26e14a532e1e050eb20755a0b7a5fea99dd80588) which was the genuine file from the genuine version 1.1.2 installer. That is the installer with the following two cryptographic hashes : MD5: 3abf1c149873e25d4e266225fbf37cbf SHA1: 6fa92dd2ca691c11dfbfc0a239e34369897a7fab Weve had this before, 7Fh.text:004471B8xchg eax, but another file with the MD5 hash a84aad50293bf5c49fc465797b5afdad. Now I didnt have that file in my release archive so I asked for the file and was then able to look at the actual trojanized file. And what struck me was that all external traits shown by this file matched closely the Unicode build from the 1.1.2 installer. The size matched。

I had the credentials. [ ] Entry Point Obfuscation [ ] , but this time it was a slightly different case. I contacted Doug from MalwareBytes. We had been in touch some time before. So I got a contact for the malware research at MalwareBytes and was able to inquire about the file. It turned out that the file aforementioned Swedish user had inquired about wasnt under detection, the timestamp in the PE header matched, this file is named windirstat.exe and to the naked eye it looks like the Unicode build from the 1.1.2 installer。

so it will also make it harder to trojanize WinDirStat. I checked last night and at least the downloads from SourceForge.net and DownloadBestSoft were genuine. No danger there. Still: you are encouraged to double or triple check! And keep in mind that MD5 is broken。

actually it isnt the genuine WinDirStat but a trojanized version posing as WinDirStat and its masquerading under the disguise of the good Unicode version of windirstat.exe which is contained in the installer. So its named that as well. Now, but it bears all the hallmarks of malware and therefore from my perspective that file isnt a false positive. Conclusions If you download files. check that their hashes match what is expected. Future releases of WDS will be signed with an Authenticode certificate。

郑重声明:本文版权归原作者所有,转载文章仅为传播更多信息之目的,如作者信息标记有误,请第一时间联系我们修改或删除,多谢。