⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 108.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid:108--Summary:QAZ is a Trojan Horse.--Impact:Possible theft of data and control of the targeted machine leading to a compromise of all resources the machine is connected to.--Detailed Information:This Trojan affects the following operating systems:	Windows 95	Windows 98	Windows ME	Windows NT	Windows 2000	Windows XPNo other systems are affected. This is a windows executable that makes changes to the system registry.The Trojan changes system startup files and registry settings to add theQAZ sever to programs normally started on boot.	SID	Message	---	-------	108	QAZ Worm Client Login access	731	Virus - Possible QAZ Worm (Indicates worm activity)	775	Virus - Possible QAZ Worm Infection (Indicates worm activity)	733	Virus - Possible QAZ Worm Calling Home (Indicates the worm is trying to send mail)--Attack Scenarios:This Trojan may be delivered to the target in a number of ways. This event is indicative of an existing infection being activated. Initial compromise can be in the form of a Win32 installation program that may use the extension ".jpg" or ".bmp" when delivered via e-mail for example.--Ease of Attack:This is Trojan activity, the target machine may already be compromised. Updated virus definition files are essential in detecting this Trojan.--False Positives:None Known--False Negatives:None Known--Corrective Action:This is a particularly difficult Trojan to remove and should only be attempted by an experienced Windows Administrator.Edit the system registry to remove the extra keys or restore a previously known good copy of the registry.Affected registry keys are:	HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version\RunRegistry keys added are:	StartIE=C:\WINDOWS\notepad.exe qazwsx.hsqThis will start the Trojan each time notepad is executed.Look for the existence of the file note.com. The file notepad.exe may have been replaced with a Trojaned version that is approximately 120 kb in size (the original is 52 kb).A machine reboot is required to clear the existing process from running in memory.--Contributors:Original Rule Writer Max Vision <vision@whitehats.com>Sourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References:Whitehats arachNIDShttp://www.whitehats.com/info/IDS501http://www.whitehats.com/info/IDS498http://www.whitehats.com/info/IDS499McAfeehttp://vil.nai.com/vil/content/v_98775.htmSymantec Security Responsehttp://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.qaz.a.htmlDiamond Computer Systems Security Advisoryhttp://www.diamondcs.com.au/web/alerts/qaz.htm--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -