|
ASPLux.A is a virus without a destructive payload. Its main objective
is to spread by inserting its code in ASPX files, used on many web
pages. In order to infect, it searches for ASPX files hosting the
web page created by the user and adds its own code. Because of this,
some ASPX files become unusable. Infected files are marked "<!--
LUX -->" in order to prevent them from being reinfected. Dengis.A also has no destructive payload. It infects source files
in the 'Matlab' numerical computation program. To do this, it creates
a COM object using the 'actxserver' function. This object allows code
not present in the virus to be executed. Dengis.A has pseudo-polymorphic
encryption, which uses an XOR operation and a key that varies with
each infection. This Trojan obtains information entered by users in forms (through
Firefox), such as passwords for the ICQ instant messaging program,
the FTP server and IMAP and POP3 mail clients. This data is then sent
to the creator of the code. It connects to: http://81.9<blocked>6.133/sutra/in.cgi4_,
to check if it has already been downloaded.
|