Rootkit takes advantage of MS08-078 vulnerability
Common Information
Type Value
UUID 9b3b2deb-5721-4ba2-ba8b-004af482243f
Fingerprint 9e44297aa122bee5
Analysis status DONE
Considered CTI value 0
Text language
Published Dec. 18, 2008, 2:12 p.m.
Added to db June 1, 2023, 11:07 a.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Cisco Talos Intelligence Blog
Title Rootkit takes advantage of MS08-078 vulnerability
Detected Hints/Tags/Attributes 37/1/51
Attributes
Details Type #Events CTI Value
Details CVE 5
cve-2008-4844
Details Domain 1
wieyou.com
Details Domain 1
count.realuu.com
Details Domain 1
www-17173.com
Details Domain 1
u3.www-pconline.com
Details Domain 1
loader.51edm.net
Details Domain 1
login.webbrowser.51edm.net
Details Domain 1
www.126.com
Details File 48
mshtml.dll
Details File 15
explore.exe
Details File 3
appmgmts.dll
Details File 16
wmplayer.exe
Details File 35
windbg.exe
Details File 1122
svchost.exe
Details File 16
360safe.exe
Details File 5
zonealarm.exe
Details File 79
regedit.exe
Details File 1
norton.exe
Details File 1
kav32.exe
Details File 2
kavstart.exe
Details File 3
f-prot95.exe
Details File 6
f-prot.exe
Details File 1
antivir.exe
Details File 7
blackice.exe
Details File 4
mcafee.exe
Details File 1
appwinproc.dll
Details File 46
system.exe
Details File 1
c:\\documents and settings\\all users\\application data\\microsoft\\office\\userdata\\webbrowser_2234.dll
Details File 1
webbrowser_2234.dll
Details File 1
c:\\program files\\foobar2000\\components\\foo_ui_yqllyrics.dll
Details IPv4 1441
127.0.0.1
Details Url 1
http://wieyou.com
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Apcdli
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBKernel32
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NPF
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NsDlRK250
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NsPsDk00
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NsPsDk01
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NsPsDk02
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NsPsDk03
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NsPsDk04
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\b1a18a3e
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\b71fe93
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\f28907d
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wmpobj
Details Windows Registry Key 49
HKLM\Software\Microsoft\Windows
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CurrentVersion\Run\HBService32\\System.exe
Details Windows Registry Key 3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
Details Windows Registry Key 7
HKLM\SOFTWARE\Classes\CLSID
Details Windows Registry Key 22
HKCU\Software\Microsoft\Internet
Details Windows Registry Key 1
HKLM\SOFTWARE\Yiqilai\Lyrics