28/01/2014 MCAFEE SECURE 認證的網站

https://www.mcafeesecure.com/RatingVerify?ref=www.HongKongCupid.com

2014年7月7日 星期一

**USA/UK/TW/PT(FDZ)/Koren/FR/....International lauguage**--*^Anonymous, the essence of management, too many technical articles ===> MobileAPP behind the secret: _ Spy parade, updated June 18 -'' I've only seen photos of my mouth Dengmu stay, tongue-tie, man ..... can Millia random .. People only know oh stolen bank account / accounts hacker intrusion into other forms of trading ...., .... ~''! - **佚名,管理(admin)*的精髓,太多的技术文章===> MobileAPP背后的秘密:_间谍APP大閱兵,,更新的6月18日 - ''我只看到我的嘴張瞪目呆,,男人。...可以收放自如随机.., 人们只知道被盗的银行账户/账户的黑客侵入其他形式的交易....,....〜''! - * Anônimo, a essência da gestão, muitos artigos técnicos ===> Aplicativos Móveis por trás do segredo: _ desfile Spy, atualizado 18 de junho -'' Eu só vi fotos de minha boca Dengmu ficar, língua presa, o homem .. ... pode Millia aleatória .. As pessoas só sabem conta bancária oh roubado / accounts invasão de hackers em outras formas de negociação ...., .... ~!'' - * 익명, 관리의 본질, 비밀 뒤에 너무 많은 기술 문서 ===> MobileAPP : _ 스파이 퍼레이드, 업데이트 6월 18일 - 나는 단지 내 입의 사진 Dengmu 유지를 보았다 ', 혀 넥타이, 남자 .. 랜덤 Millia 수 있습니다 .. 사람은 오 도난 은행 계좌 / 거래의 다른 형태로 해커의 침입을 차지 알고 ..., .... ~! '' - * Anonymous, l'essence de la gestion, de trop nombreux articles techniques ===> MobileApp derrière le secret: _ Spy défilé, Updated 18 juin -'' Je n'ai vu que des photos de ma bouche Dengmu séjour, frein de la langue, l'homme .. ... peut Millia aléatoire .. Les gens ne savent compte bancaire oh volé / comptes intrusions de pirates dans d'autres formes de commerce ...., .... ~''! - * Anonymous, la esenco de mastrumado, tro multaj teknikaj artikoloj ===> MobileAPP malantaŭ la sekreton: _ Spiono parado, ĝisdatigita Junio ​​18 -'' Mi nur vidis la fotojn de mia buŝo Dengmu resti, lingvo-egaleco, viro .. ... povas Millia hazarda .. Homoj nur scias ho ŝtelita bankokonto / kontoj hacker entrudiĝo en aliajn formojn de komerco ...., .... ~''! -

**USA/UK/TW/PT(FDZ)/Koren/FR/....International lauguage**----** Anonymous, the essence of management, too many technical articles ===> MobileAPP behind the secret: _ Spy parade, updated June 18 -'' I've only seen photos of my mouth Dengmu stay, tongue-tie, man ..... can Millia random ..
People only know oh stolen bank account / accounts hacker intrusion into other forms of trading ...., .... ~''! -
**佚名,管理(admin)*的精髓,太多的技术文章===> MobileAPP背后的秘密:_间谍APP大閱兵,,更新的6月18日 - ''我只看到我的嘴張瞪目呆,,男人。...可以收放自如随机..,
人们只知道被盗的银行账户/账户的黑客侵入其他形式的交易....,....〜''! -
 * Anônimo, a essência da gestão, muitos artigos técnicos ===> Aplicativos Móveis por trás do segredo: _ desfile Spy, atualizado 18 de junho -'' Eu só vi fotos de minha boca Dengmu ficar, língua presa, o homem .. ... pode Millia aleatória ..
As pessoas só sabem conta bancária oh roubado / accounts invasão de hackers em outras formas de negociação ...., .... ~!'' -
* 익명, 관리의 본질, 비밀 뒤에 너무 많은 기술 문서 ===> MobileAPP : _ 스파이 퍼레이드, 업데이트 6월 18일 - 나는 단지 내 입의 사진 Dengmu 유지를 보았다 ', 혀 넥타이, 남자 .. 랜덤 Millia 수 있습니다 ..
사람은 오 도난 은행 계좌 / 거래의 다른 형태로 해커의 침입을 차지 알고 ..., .... ~! '' -

* Anonymous, l'essence de la gestion, de trop nombreux articles techniques ===> MobileApp derrière le secret: _ Spy défilé, Updated 18 juin -'' Je n'ai vu que des photos de ma bouche Dengmu séjour, frein de la langue, l'homme .. ... peut Millia aléatoire ..
Les gens ne savent compte bancaire oh volé / comptes intrusions de pirates dans d'autres formes de commerce ...., .... ~''! -
* Anonymous, la esenco de mastrumado, tro multaj teknikaj artikoloj ===> MobileAPP malantaŭ la sekreton: _ Spiono parado, ĝisdatigita Junio ​​18 -'' Mi nur vidis la fotojn de mia buŝo Dengmu resti, lingvo-egaleco, viro .. ... povas Millia hazarda ..
Homoj nur scias ho ŝtelita bankokonto / kontoj hacker entrudiĝo en aliajn formojn de komerco ...., .... ~''! - 


*

**--Please use Google with a large family of God translator to translate your country / language city Oh ^ ^
--請各位用家善用谷歌大神的翻譯器,來翻譯你們的國家/城市的語言喔^^
--Por favor, use o Google com uma grande familia de Deus tradutor para traduzir sua cidade pais / idioma Oh ^ ^
--** - 국가 / 언어 번역하는 하나님 번역기 가족과 함께 구글을 사용하십시오 ^ ^
--S'il vous plait utilisez Google avec une grande famille de Dieu traducteur pour traduire votre ville de pays / langue Oh ^ ^
--Bitte verwenden Sie Google mit einer grosen Familie Gottes Ubersetzer zu Ihrem Land / Sprache ubersetzen Stadt Oh ^ ^
--*** - あなたの国/言語の街を翻訳する神トランスレータの大きなファミリーでGoogleを使用してくださいああ^ ^
** - Sila gunakan Google dengan keluarga besar penterjemah Tuhan untuk menterjemahkan bandar negara / bahasa anda Oh ^ ^
--** - Utilice Google con una gran familia de Dios traductor para traducir tu ciudad país / idioma Oh ^ ^
** - Si prega di utilizzare Google con una grande famiglia di Dio traduttore per tradurre la tua città paese / lingua Oh ^ ^
--Sila gunakan Google dengan keluarga besar penterjemah Tuhan untuk menterjemahkan bandar negara / bahasa anda Oh ^ ^
--Bonvole uzu Google kun granda familio de Dio tradukisto traduki via lando / lingvo urbon Ho ^ ^
 

 http://www.ourlove520.com/Article/others/jiami/201406/275709.html

Secrets Behind Mobile APP: APP spy Parade


Article Writer: Anonymous Editor: admin Updated: 2014-6-18

 With the rapid development of mobile Internet technology matures mobile intelligent system, equipped with a smart phone system, flat in large numbers, 
so intelligent system an important part of the application App fire.  
Whether you are using a mobile phone or tablet PC , or other device, the face of such massive App, installation and use of these kinds of App is thought such a thing,   
some of the App behind secretly steal sensitive to the privacy of your personal !
Here we take a look at what they are doing behind the hidden secret.

A steal, everywhere

1.1 steal financial account information

2013 is the beginning of the outbreak of the financial year of the Internet for a piece of "fat" naturally eager malicious applications.
When you click the login screen Merchants Bank, it will jump to SocketDemo this activity.

Application into SocketDemo this activity, the user enters the account, phone number and password and click send button will send the above information to "1891128940" number, to steal user account and password.

Also found disguised as Alipay, ICBC, China Construction Bank, Bank of Communications and other login screen, almost real, but in reality the background to get account passwords and other sensitive information and send it via SMS.

Alipay to obtain a password, for example, were to get Alipay account, password and payment password and connect to the # after base64 encryption and then send a text message.
Not just domestic, foreign banks are very serious ones.

Santander is a name which the Bank of Spain, Clave de firma is Spanish, translated back to: signature key. The main behavior of this sample is:
Disguised as online banking password generator to trick the user to enter their bank passwords within the control Clave de firma under false randomly generated password (mToken) displayed to the user. Then the user's bank passwords via SMS and web form was leaked, and after with the sample, the interception to the bank sent to the user's mobile phone verification code, an attacker can steal the user's bank wealth in the user completely unaware of the situation.

1.2 steal chat application message logging

"Those who hear the wind," the reality of the listener, the application running interface and website features description, this software also has a back-log in to view the chat history

Functional foreign spy application is greater.
Which left for the program to run after the interface, the application right is some social or chat messages back to view.

Such as access to whatsapp message record

Enhance safety awareness, increased safety precautions, do not let the invisible "Ting Feng who" make you become the protagonist of a certain door, oh.

1.3 steal more privacy

Get SMS records, such as sensitive Paypal or bank related information


Get call recording, SMS information, location information, environmental recordings

Get phone call records

Get SD card file list.

Get contact information

No surprise, only do that once caught, there is no privacy anymore. Know thyself, then we summarize the behavior under common processes and functions of these spyware, do not let yourself become a "chicken."

Second, the control mode

2.1 SMS command control

Family: MguSpy.a
Description: The program runs after listening SMS, receive remote SMS commands to control.

2.2 Network command control

Family: Lien.d
Description: The connection malicious remote server, receives the server command control

2.3 google cloud push

Family: Tramp.a
Description: In fact, the control also belongs to the network one, only not directly controlled by a malicious remote server, but by the google cloud servers perform commands sent, with some covert.
Radio listeners registered google GCM


According to the instruction execution-related operations .

Third, privacy mode returns

3.1 SMS Returns

Family: Lurker.a
Description: SMS return operation is simple, practical (as long as there are calls to mobile phones). General personal development program used in this way, of course, there are procedures to send a receipt via SMS, such as the success of the command CMB.
SMS record

Send a call log

3.2 Network mode returns

Family: Vla DOS py.a
Description: General through the network returned spyware, has a powerful back-end management systems , unified view or manage. General features of such spyware powerful, mostly to be charged.
Get Device Information

SMS record

3.3 mailbox way return

Family: Dd1d.e
Description: Installation status via e-mail to send the user information or procedures.
Send by 163 mailboxes

Sent Items

Fourth, the common features

Typical features: SMS records, call logs, contacts, etc.

4.1 Get SMS record

Access SMS common agreement

4.2 obtain phone records

Common uri: CallLog.Calls.CONTENT_URI;

4.3 for contact information

Get Contact uri: android.provider.ContactsContract.CommonDataKinds.Phone.CONTENT_URI, android.provider.Contacts.People.CONTENT_URI

4.4 Call Recording

Common are recording the call or the environment

4.5 photos

Photographs

Fifth, lend me a pair of eye - identify spyware applications

5.1 No icons or hide icons

No activity, no icon is installed, only radio and services.

First install an icon, but the icon next run will be hidden.
General hide icons by setComponentEnabledSetting API.

Activation Device Manager 5.2

AM Registration laser device manager, but no icons or hidden icons.

5.3 SMS monitoring

Listens SMS, intercept behavior, but will judge the content of the message, such as *, # the beginning, and so different from the general user texting habits.

5.4 large number of suspicious permissions

SMS, contacts, positioning a large number of suspicious authority, while the package name and relatively suspicious.
Generally also has three or more privileges suspicious.


5.5 send mail

There are messages sent code while a large number of suspicious permissions and services.

5.6 package name camouflage system services

Package name and program name camouflage system services or applications.


5.7 Comparison of a large number of strings

String comparison is generally used for matching instruction.
Such as: startsWith

Such as: equals

5.8 String Table Keyword

Direct search string table, see a lot of sensitive keywords.
Chinese: command, open the recording, calls, uploading

English: uploadgps, uploadrecord

In fact, obvious command prompt.

5.9 monitor calls

Listen and call number for judgments, dialed numbers generally contain *, #, etc., are not regular users dial the number.

Excessive 5.10 service, activity is less.


5.11 View package structure

Spyware generally head to strong organizational structure is more clear, if the package name contains: call, contact, gps, record, server, task and other more questionable.

VI Summary

Class powerful spy program, once caught, the individual will no privacy at all, great harm. It also has a hidden strong (no icon is installed, start the service only), easy to remove (activate the device manager, anti unloading) and so on. For such spyware applications, An Tianan full expert advice, to develop safety awareness, from the well-known site to download the application, the user can not run this software directly cleared.
Meanwhile you can download AVL mobile security teams AVL Pro killing malicious applications.




 http://www.ourlove520.com/Article/others/jiami/201406/275709.html
移动APP背后的秘密:间谍APP大阅兵


文章录入:佚名 责任编辑:admin 更新时间: 2014-6-18


随着移动互联网技术的飞速发展,移动智能系统的逐步成熟,搭载着智能系统的手机、平板大量涌现,于是智能系统的重要组成部分App应用火了。无论您使用的是手机还是平板电脑,或者其他设备,面对如此海量的App,在安装和使用这些形形色色的App时是否想到过这样的事情, 一些App背后偷偷地在窃取着您的个人敏感隐私!
下面我们就来看看它们背后都做了哪些不可告人的秘密。

一、窃取,无处不在

1.1 盗取金融账号信息

2013是互联网金融开始爆发的一年,针对这块”肥肉”恶意应用自然不甘寂寞。
当点击招商银行登陆界面时,会跳转到SocketDemo这个activity。

应用进入到SocketDemo这个activity,用户输入账户、手机号和密码,点击send按钮,便会向”1891128940″号码发送以上信息,从而盗取用户账号及密码。

同时也发现有伪装成支付宝,工商银行,建设银行,交通银行等登录界面,几乎可以假乱真,实则后台获取账号密码等敏感信息并通过短信发送。

以获取支付宝密码为例,分别获取支付宝账号,密码及支付密码并以#号连接,之后base64加密再短信形式发送。
不仅仅是国内,国外的银行盗号也很严重。

其中 Santander是一个西班牙银行的名称,Clave de firma是西班牙语,翻译后为:签名密钥。这个样本的主要行为就是:
伪装成银行的在线口令生成器,诱骗用户在Clave de firma下的控件内输入自己的银行密码,并随机生成虚假的口令(mToken)显示给用户。这时用户的银行密码通过短信和网络的形式被泄露,并且在之后配合样本,截取到银行发送给用户的手机验证码,攻击者可以在用户完全不知情的情况下窃取用户的银行财富。

1.2 盗取聊天应用消息记录

“听风者”现实中的监听,该应用运行界面及网站功能说明,此软件还有一个登录后台可查看聊天记录

国外间谍应用的功能更是有过之而无不及。
其中左图为该程序运行后的界面,右图为后台查看的一些社交或聊天应用的消息。

如获取whatsapp消息记录

加强安全意识,增加安全防范,不要让无形的”听风者”让你成为某某门的主角哦。

1.3 盗取更多隐私

获取短信记录,如敏感的支付宝或银行相关信息

‍ ‍ ‍‍ ‍
获取通话录音、SMS信息、定位信息、环境录音

获取手机通话记录

获取SD卡文件列表。

获取联系人信息

没有想不到,只有做不到,一旦中招,就没有隐私可言了。知己知彼,接下来我们总结下这些间谍件的常用行为流程及功能,不要让自己成为”肉鸡”。

二、控制方式

2.1 短信指令控制

家族:MguSpy.a
说明:该程序运行后进行短信监听,接收远程短信指令控制。

2.2 网络指令控制

家族:Lien.d
说明:连接恶意远程服务器,接收服务器指令控制

2.3 google云推送

家族:Tramp.a
说明:其实该控制方式也属于网络的一种,只有不是直接由恶意远程服务器控制,而由google云服务器进行指令发送,具有一定隐蔽性。
注册google GCM监听广播


根据指令执行相关操作

三、隐私回传方式

3.1 短信方式回传

家族:Lurker.a
说明:短信回传操作简单,实用(只要手机还有话费即可)。一般个人开发的程序采用此种方式,当然也有程序通过短信发送回执信息,如指令招行成功与否。
发送短信记录

发送通话记录

3.2 网络方式回传

家族:Vladospy.a
说明:一般通过网络回传的间谍件,都有一个功能强大的后台管理系统,进行统一查看或管理。该类间谍件一般功能强大,大都是要收费的。
获取设备信息

短信记录

3.3 邮箱方式回传

家族:Dd1d.e
说明:通过邮箱发送用户相关信息或程序安装状态等。
通过163邮箱进行发送

已发送邮件

四、常见功能

典型功能:短信记录,通话记录,联系人等。

4.1 获取短信记录

访问短信常见协议

4.2 获取通话记录

常用uri: CallLog.Calls.CONTENT_URI;

4.3 获取联系人信息

获取联系人uri: android.provider.ContactsContract.CommonDataKinds.Phone.CONTENT_URI, android.provider.Contacts.People.CONTENT_URI

4.4 通话录音

常见的有通话或环境录音

4.5 拍照

拍摄照片

五、借我一双慧眼–识别间谍应用

5.1 无图标或隐藏图标

无activity,安装无图标,仅有广播和服务。

首次安装有图标,但下次运行会隐藏图标的。
一般通过setComponentEnabledSetting API进行隐藏图标。

5.2 激活设备管理器

AM注册有激设备管理器,而又无图标或隐藏图标的。

5.3 短信监听

会监听短信,有拦截行为,同时会对短信内容进行判断的,如*,#开头的,等不同于一般用户发短信习惯的。

5.4 大量可疑权限

短信,联系人,定位等大量可疑权限,同时包名又比较可疑的。
一般来说同时拥有以下三种或以上权限很可疑。


5.5 邮件发送

有邮件发送代码同时有大量可疑权限及服务。

5.6 包名伪装系统服务

包名和程序名伪装系统服务或应用。


5.7 大量字串比较

字串比较一般用于指令的匹配。
如:startsWith

如:equals

5.8 字串表关键字

直接搜索字串表,看到很多敏感关键字的。
中文:指令,开启录音,通话,上传

英文:uploadgps,uploadrecord

其实明显指令提示信息。

5.9 通话监听

监听拨打电话并对号码进行判断的,所拨打号码一般包含*,#等,不是用户常规拨打号码。

5.10 服务过多,activity较少。


5.11 查看包结构

间谍件一般目地性较强,组织结构较清晰,若包名中包含:call,contact,gps,record,server,task等较为可疑。

六、小结

间谍类程序功能强大,一旦中招,个人将再无隐私可言,危害极大。 
同时还具有隐蔽性强(安装无图标,仅启动服务),  
不易清除(激活设备管理器,防卸载)等特点。   
针对此类间谍应用,安天安全专家建议,养成安全意识,   
从知名站点下载应用,未运行此软件用户可直接清除。
同时可以下载AVL移动安全团队AVL Pro对恶意应用进行查杀。




 =============================================================
 http://www.ourlove520.com/Article/others/jiami/201406/275709.html

Secrets de mobile APP: APP espion Parade


Article Writer: Anonymous Éditeur: admin Mise à jour: 18/06/2014

 Avec le développement rapide de la technologie de l'Internet mobile mûrit système intelligent mobile, équipé d'un système intelligent de téléphone, plat en grand nombre, si intelligent système une partie importante de l'application App feu. Que vous utilisiez un téléphone portable ou une tablette PC ou un autre périphérique, le visage de cette énorme App, l'installation et l'utilisation de ces types de App est pensé une telle chose, une partie de l'App derrière voler secrètement sensible à l'intimité de votre personnel !
Ici, nous prenons un coup d'oeil à ce qu'ils font derrière le secret caché.

Une voler partout

1.1 voler des informations de compte financier

2013 est le début de l'épidémie de l'année financière de l'Internet pour une pièce d'applications "gras" naturellement désireux malveillants.
Lorsque vous cliquez sur l'écran de connexion Merchants Bank, il va sauter à SocketDemo cette activité.

Application dans SocketDemo cette activité, l'utilisateur entre dans le compte, numéro de téléphone et mot de passe et cliquez sur le bouton envoyer enverra les informations ci-dessus pour nombre "1891128940", de voler compte d'utilisateur et mot de passe.

On trouve également déguisé en Alipay, ICBC, China Construction Bank, Bank of Communications et autre écran de connexion, presque réel, mais en réalité le fond pour obtenir les mots de passe et autres informations sensibles et l'envoyer via SMS.

Alipay pour obtenir un mot de passe, par exemple, étaient pour obtenir le compte Alipay, mot de passe et de paiement et se connecter à la # après cryptage base64, puis envoyer un message texte.
Pas seulement nationale, les banques étrangères sont très graves.

Santander est un nom qui la Banque d'Espagne, Clave de ferme est l'espagnol, traduit vers: signature clé. Le comportement principal de cet échantillon est:
Déguisé en générateur de mot de passe de services bancaires en ligne pour tromper l'utilisateur à entrer son mot de passe bancaires sous le contrôle Clave de ferme sous un faux mot de passe généré aléatoirement (mToken) affiché à l'utilisateur. Ensuite, les mots de passe bancaires de l'utilisateur par SMS et web forme a été divulgué, et après avec l'échantillon, l'interception de la banque envoyés vers les mobiles le code de vérification de téléphone de l'utilisateur, un attaquant peut voler la richesse de la banque de l'utilisateur dans le mode complètement inconscients de la situation.

1,2 voler la journalisation des messages d'application de chat

"Ceux qui entendent le vent», la réalité de l'auditeur, l'interface d'application en cours d'exécution et le site dispose description, ce logiciel dispose également d'un back-vous pour voir l'histoire de chat

Application espion étranger fonctionnelle est plus grande.
Qui a laissé pour le programme à exécuter après l'interface, l'application est juste quelques messages sociaux ou de tchatter avec vous pour voir.

Comme l'accès à l'enregistrement des messages WhatsApp

Accroître la sensibilisation à la sécurité, l'augmentation sécurité précautions, ne laissez pas l'invisible "Feng Ting qui" vous faire devenir le protagoniste d'une certaine porte, oh.

1,3 voler plus d'intimité

Obtenir des enregistrements de SMS, comme Paypal ou des informations sensibles de banque liées


Faites-vous appeler les informations de SMS, des informations de localisation, des enregistrements environnementaux enregistrement,

Obtenir des enregistrements d'appels téléphoniques

Obtenez la liste de fichiers de la carte SD.

Obtenir des informations de contact

Pas de surprise, que faire une fois pris, il n'y a aucune intimité plus. Connais-toi toi, nous résumons le comportement sous processus et les fonctions de ces logiciels espions ordinaires, ne vous laissez pas devenir un "poulet".

En second lieu, le mode de commande

2.1 SMS de contrôle-commande

Famille: MguSpy.a
Description: Le programme s'exécute après avoir écouté SMS, recevoir des SMS à distance des commandes à contrôler.

2.2 Réseau de contrôle-commande

Famille: Lien.d
Description: La connexion malveillant serveur distant, reçoit le serveur de contrôle de commande

2.3 google nuage poussoir

Famille: Tramp.a
Description: En fait, le contrôle appartient aussi à réseau un, ne pas directement contrôlé par un serveur distant malveillant, mais par le nuage google serveurs exécuter des commandes envoyées, avec un peu secrète.
Les auditeurs inscrits google GCM


Selon les instructions liés à l'exécution des opérations .

Troisièmement, les déclarations de mode de la vie privée

3.1 SMS retours

Famille: Lurker.a
Description: retour de SMS fonctionnement est simple, pratique (aussi longtemps que il ya des appels vers les mobiles). Programme général de développement personnel utilisé de cette façon, bien sûr, il existe des procédures pour envoyer un accusé de réception par SMS, comme le succès de la commande CMB.
dossier de SMS

Envoyer un journal d'appels

3.2 Réseau des rendements de mode

Famille: Vla DOS py.a
Description: général par l'intermédiaire du réseau retourné les logiciels espions, a un puissant gestion back-end des systèmes , vue unifiée ou gérer. Caractéristiques générales de ces logiciels espions puissants, la plupart du temps à charger.
Obtenir des informations de périphérique

dossier de SMS

Retour 3.3 manière de boîte aux lettres

Famille: Dd1d.e
Description: état de l'installation par e-mail à envoyer des informations ou des procédures utilisateur.
Envoyer par 163 boîtes aux lettres

Éléments envoyés

Quatrièmement, les caractéristiques communes

Les caractéristiques typiques: les dossiers de SMS, journaux d'appels, contacts, etc

4.1 Obtenez dossier SMS

Accès SMS commun accord

4.2 obtenir des enregistrements téléphoniques

Uri commun: CallLog.Calls.CONTENT_URI;

4.3 pour les informations de contact

Obtenez contact uri: android.provider.ContactsContract.CommonDataKinds.Phone.CONTENT_URI, android.provider.Contacts.People.CONTENT_URI

Enregistrement 4.4 d'appel

Commune enregistrez l'appel ou l'environnement

4.5 les photos

Photographies

Cinquièmement, prêtez-moi une paire de yeux - identifier les logiciels espions

5.1 Aucun des icônes ou des icônes de masquer

Aucune activité, aucune icône n'est installé, seule la radio et services.

Installez d'abord une icône, mais l'icône prochaine course sera caché.
Cacher les icônes générales par setComponentEnabledSetting API.

Activation Device Manager 5.2

AM gestionnaire de périphériques laser d'enregistrement, mais aucune icône ou les icônes cachées.

5.3 suivi de SMS

Écoute SMS, le comportement d'interception, mais juger le contenu du message, tels que *, # le début, et si différent des habitudes générales de textos utilisateur.

5.4 grand nombre d'autorisations suspectes

SMS, contacts, le positionnement d'un grand nombre de l'autorité suspecte, tandis que le nom du paquet et relativement suspect.
Généralement dispose également de trois ou plus de privilèges suspectes.


5.5 envoyer un mail

Il ya des messages envoyés Code tandis qu'un grand nombre d'autorisations et de services suspectes.

5.6 nom du paquet camouflage système services

Nom du package et le nom du programme camouflage système des services ou des applications.


5.7 Comparaison d'un grand nombre de cordes

La comparaison de chaînes est généralement utilisé pour l'enseignement correspondant.
Tels que: startsWith

Tels que: égaux

5.8 Chaîne tableau de mots-clés

Direct table de chaînes de recherche, voir un grand nombre de mots-clés sensibles.
Chinois: commande, ouvrez l'enregistrement, les appels, ajout de

Anglais: uploadgps, uploadrecord

En fait, l'invite de commande évident.

5.9 surveille les appels

Écoutez et le numéro d'appel pour les jugements, les numéros composés contiennent généralement *, #, etc, ne sont pas des utilisateurs réguliers composer le numéro.

5.10 Service excessive, l'activité est moins.


5.11 Voir structure de paquet

Spyware tête généralement à forte structure organisationnelle est plus clair, si le nom du paquet contient: appel, contact, gps, record, serveur, tâche et d'autres plus discutables.

VI Résumé

programme espion de classe puissante, une fois pris, la volonté individuelle aucune intimité, beaucoup de mal. Il a également une forte caché (pas d'icône est installé, démarrez le service seulement), facile à enlever (activer le gestionnaire de périphériques, anti déchargement) et ainsi de suite. Pour de telles applications de spyware, un avis d'expert complet Tianan, de développer la sécurité conscience, sur le site bien connu pour télécharger l'application, l'utilisateur ne peut pas exécuter ce logiciel directement dégagé.
En attendant, vous pouvez télécharger mobiles AVL sécurité des équipes AVL applications malveillantes tuant Pro.

 Article Writer: Anonymous Éditeur: admin   ^^
 ==================================================================




"And the process is complicated, if not selfless sharing "Anonymous"
You do not know how it was stolen!
Not every hacker has chivalrous spirit of
He is just one of thousands of papers tips here
His skill Millia
Is not representative lofty honor "^ ^ ~

http://melodytoyssexy.blogspot.com/2014/07/usauktwptfdzkorenfrinternational.html
================================


"當中的過程複雜,如沒有佚名的無私分享
你也不知如何被盗了吧!
俠義精神不是每個黑客都有的
這裡只是他千百篇技巧文章之一
他的技巧收放自如
還不是尊榮崇高的代表者"^^~

http://melodytoyssexy.blogspot.com/2014/07/usauktwptfdzkorenfrinternational.html
================================

"E o processo é complicado, se não partilha desinteressada "Anonymous"
Você não sabe como ele foi roubado!
Nem todo hacker tem espírito cavalheiresco de
Ele é apenas um dos milhares de papéis dicas aqui
Sua habilidade Millia
Não é honra sublime representante" ^ ^ ~

http://melodytoyssexy.blogspot.com/2014/07/usauktwptfdzkorenfrinternational.html
================================

"그리고 그 과정은 사심 공유 "익명"복잡하지 않을 경우
당신은 도난 된 방법을 모르겠어요!
아니 모든 해커의 의협심이
그는 여기에 단 하나의 논문 팁 수천입니다
그의 기술 Millia
대표 고원 영광 ^ ^ ~ 아니다"

http://melodytoyssexy.blogspot.com/2014/07/usauktwptfdzkorenfrinternational.html
================================

"Et le processus est compliqué, si le partage pas désintéressé" Anonymous "
Vous ne savez pas comment il a été volé!
Non chaque pirate a de l'esprit chevaleresque de
Il est juste un des milliers de documents de conseils ici
Son habileté Millia
N'est pas représentatif honneur noble "^ ^ ~

http://melodytoyssexy.blogspot.com/2014/07/usauktwptfdzkorenfrinternational.html
================================

"Kaj la procezo estas komplika, se ĝi ne neprofitema sharing" Anonima "
Vi ne scias kiel gxi estis ŝtelita!
Ne ĉiu hacker havas kavalireca spirito de
Li estas nur unu el la miloj da paperoj tips here
Lia lerteco Millia
Ne estas reprezenta altega honoro "^ ^ ~

http://melodytoyssexy.blogspot.com/2014/07/usauktwptfdzkorenfrinternational.html

================================
===MelodyRO===THE   END===>/


**USA/UK/TW/PT(Macau)FDZ/Koren/SP/IT/JP/UKN.....International lauguage**-- ---**By Lan Lan @ July .7 * Whitecaps information dissemination Facebook released --- ** ---> Bitcoin <------- Mining Trojan ** -? Bitcoin in our tribe is a vicious virtual currency, which means you have to ...... "-! Maintain a certain distance ....- --**由兰兰@七月.7*白帽信息传播的Facebook发布---**---> Bitcoin<-------采矿木马** - ?Bitcoin在我们的部落是一个恶性的虛擬貨幣,这意味着你要......“ - !保持一定的距离..... - --**Por Lan Lan @ July 0,7 * Informações Whitecaps disseminação Facebook lançou --- ** ---> Bitcoin <------- Mineração Trojan ** - Bitcoin em nossa tribo é uma moeda virtual vicioso , o que significa que você tem que ...... "- Manter uma certa distância ....- --- ** 란 란 7 월에 0.7 @ 페이스 북이 발표 * 화이트 캡스 정보 보급 --- ** ---> 비트 코인은 <------- 광업 트로이 ** -? 우리의 부족에있는 비트 코인은 악순환의 가상입니다 ! 일정한 거리를 유지 - 당신이 ...... "하는 것을 의미 통화, ....- --- ** Par Lan Lan @ Juillet 0,7 * Whitecaps diffusion de l'information Facebook a publié --- ** ---> Bitcoin <------- Trojan minières ** - Bitcoin dans notre tribu est un virtuel vicieux monnaie, ce qui signifie que vous avez à ...... "- Maintenir une certaine distance ....- --- ** Con Lan Lan @ LUGLIO 0,7 * Le informazioni Whitecaps diffusione Facebook ha rilasciato --- ** ---> Bitcoin <------- estrazione mineraria di Troia ** -? Bitcoin nella nostra tribù è un virtuale vizioso valuta, il che significa che si deve ...... "- Mantenere una certa distanza .....- ----?---**ランラン7月0.7@ *ホワイトキャップス情報発信Facebookは---**---> Bitcoin<-------鉱業トロイの木馬**発売さ - 私たちの部族にBitcoinを悪質仮想です!一定の距離を維持する - あなたは...... "しなければならないことを意味通貨、 .....- --- ** За Лан Лан @ липня 0,7 * Вайткепс поширення інформації Facebook випустила --- ** ---> Bitcoin <------- Видобуток Trojan ** -? Bitcoin в нашому племені порочне віртуальний валюта, яка означає, що ви повинні ......! "- підтримання певної відстані .....- --- ** Per Lan Lan @ Julio .7 * Whitecaps disvastigo de informo al Facebook liberigis --- ** ---> Bitcoin <--- Ministo Trojan ** -? Bitcoin en nia tribo estas malvirta virtuala monero, kiu signifas ke vi devas ..."-! subteni certa distanco....-

FreeBuf hackers and geeks**USA/UK/TW/PT(Macau)FDZ/Koren/SP/IT/JP/UKN.....International lauguage**--
---**By Lan Lan @ July .7 * Whitecaps information dissemination Facebook released --- ** ---> Bitcoin <-------


Mining Trojan ** -? Bitcoin in our tribe is a vicious virtual currency, which means you have to ...... "-! Maintain a certain distance ....-
--**由兰兰@七月.7*白帽信息传播的Facebook发布---**---> Bitcoin<-------采矿木马** - ?Bitcoin在我们的部落是一个恶性的虛擬貨幣,这意味着你要......“ - !保持一定的距离..... -
--**Por Lan Lan @ July 0,7 * Informações Whitecaps disseminação Facebook lançou --- ** ---> Bitcoin <-------
Mineração Trojan ** - Bitcoin em nossa tribo é uma moeda virtual vicioso , o que significa que você tem que ...... "- Manter uma certa distância ....-
--- ** 란 란 7 월에 0.7 @ 페이스 북이 발표 * 화이트 캡스 정보 보급 --- ** ---> 비트 코인은 <------- 광업 트로이 ** -? 우리의 부족에있는 비트 코인은 악순환의 가상입니다 ! 일정한 거리를 유지 - 당신이 ...... "하는 것을 의미 통화, ....-
--- ** Par Lan Lan @ Juillet 0,7 * Whitecaps diffusion de l'information Facebook a publié --- ** ---> Bitcoin <------- Trojan minières ** - Bitcoin dans notre tribu est un virtuel vicieux monnaie, ce qui signifie que vous avez à ...... "- Maintenir une certaine distance ....-
--- ** Con Lan Lan @ LUGLIO 0,7 * Le informazioni Whitecaps diffusione Facebook ha rilasciato --- ** ---> Bitcoin <------- estrazione mineraria di Troia ** -? Bitcoin nella nostra tribù è un virtuale vizioso valuta, il che significa che si deve ...... "- Mantenere una certa distanza .....-
----?---**ランラン7月0.7@ *ホワイトキャップス情報発信Facebookは---**---> Bitcoin<-------鉱業トロイの木馬**発売さ - 私たちの部族にBitcoinを悪質仮想です!一定の距離を維持する - あなたは...... "しなければならないことを意味通貨、 .....-
--- ** За Лан Лан @ липня 0,7 * Вайткепс поширення інформації Facebook випустила --- ** ---> Bitcoin <------- Видобуток Trojan ** -? Bitcoin в нашому племені порочне віртуальний валюта, яка означає, що ви повинні ......! "- підтримання певної відстані .....-
--- ** Per Lan Lan @ Julio .7 * Whitecaps disvastigo de informo al Facebook liberigis --- ** ---> Bitcoin <--- Ministo Trojan ** -? Bitcoin en nia tribo estas malvirta virtuala monero, kiu signifas ke vi devas ..."-! subteni certa distanco....- 


*

**--Please use Google with a large family of God translator to translate your country / language city Oh ^ ^

--請各位用家善用谷歌大神的翻譯器,來翻譯你們的國家/城市的語言喔^^
--Por favor, use o Google com uma grande familia de Deus tradutor para traduzir sua cidade pais / idioma Oh ^ ^
--** - 국가 / 언어 번역하는 하나님 번역기 가족과 함께 구글을 사용하십시오 ^ ^
--S'il vous plait utilisez Google avec une grande famille de Dieu traducteur pour traduire votre ville de pays / langue Oh ^ ^
--Bitte verwenden Sie Google mit einer grosen Familie Gottes Ubersetzer zu Ihrem Land / Sprache ubersetzen Stadt Oh ^ ^
--*** - あなたの国/言語の街を翻訳する神トランスレータの大きなファミリーでGoogleを使用してくださいああ^ ^
** - Sila gunakan Google dengan keluarga besar penterjemah Tuhan untuk menterjemahkan bandar negara / bahasa anda Oh ^ ^
--** - Utilice Google con una gran familia de Dios traductor para traducir tu ciudad país / idioma Oh ^ ^
** - Si prega di utilizzare Google con una grande famiglia di Dio traduttore per tradurre la tua città paese / lingua Oh ^ ^
--Sila gunakan Google dengan keluarga besar penterjemah Tuhan untuk menterjemahkan bandar negara / bahasa anda Oh ^ ^
--Bonvole uzu Google kun granda familio de Dio tradukisto traduki via lando / lingvo urbon Ho ^ ^
 


 FreeBuf hackers and geeks
 http://www.freebuf.com/news/37673.html

Spread through facebook bitcoin mining Trojans

Lanlan @ Information
 EDITORIAL:
In fact, the use and dissemination of this Trojan is still very old-fashioned, in addition to selling author payload inside a sprouting outside.
Text:
Facebook users in many countries, Portugal, Belgium, India, Rome, Spain, etc., are being a new Trojan attacks, the victims of this Trojan will control the host bitcoin mining.
Bitdefender's security experts say, there are already a large number of Facebook users   
are infected by this Trojan. Alexandra Gheorghe in his blog which wrote:    
This Trojan via facebook in a private letter to spread, private letter contains a 1IMAG00953.zip, including malicious file disguised as jpg files.     

This document will be pre-set by Dropbox account to download DLL files,   
which will link to C & C server and returns a shellcode.     
In this shellcode inside the payload section of such information.
  "Hello people .. :) <-! Designed by the SkyNet Team -> 
but am not the f ***** g zeus bot / skynet bot or whatever piece of s ** t .. 
no fraud here .. only a bit of mining. Stop breaking my b *** z .. 
Probably meant to say, I was digging mining, no other malicious functions, mercy and   
the like. shellcode will lead to a second DLL download, and began mining processes.
But Bitdefender's security experts discovered the malicious Trojan many other functions,    
but only a small part of the mining among these features,    
this Trojan will transform every few hours shellcode content, do anything on the victim host.
Facebook users, the best private letter carefully strange contents, even if he is one of your friends send to you.
lanlan
(6) Alibaba Safety Engineer

 ===============================================================

 FreeBuf黑客与极客
 http://www.freebuf.com/news/37673.html
 

通过facebook传播的比特币挖矿木马

@ 资讯 2014-07-07
写在前面:
    其实这种木马的利用和传播方式还是很老套的,除了作者在payload里面卖了个萌之外。
正文:
    葡萄牙,比利时,印度,罗马,西班牙等众多国家的facebook用户,正遭到一种新型木马的攻击,这种木马会控制受害者的主机挖掘比特币。
    Bitdefender 公司的安全专家声称,已经有大量的Facebook用户被这种木马所感染。Alexandra Gheorghe在他的blog里 面写道:这种木马通过facebook中的私信来进行传播,
私信中包含一个1IMAG00953.zip,其中有伪装成jpg文件的恶意文件。
这个文件会 通过预先设置好的Dropbox账号下载DLL文件,这些文件会链接C&C服务器,
并返回一个shellcode。在这个shellcode的 payload里面有一段这样的信息。
“Hello people.. :) <!– Designed by the SkyNet Team –> but am not  
the f*****g zeus bot/skynet bot or whatever piece of s**t.. no fraud here..  
only a bit of mining. Stop breaking my b***z..
    大概意思就是说,我就是挖挖矿,没有别的恶意功能,手下留情之类的。
shellcode会引发第二个DLL的下载,同时开始挖矿流程。
    但是Bitdefender 的安全专家发现了这个木马很多其他的恶意功能,
而挖矿只是这些功能之中的一小部分,这个木马每过几个小时就会变换shellcode的内容,
在受害主机上执行任何内容。
    Facebook的用户,最好还是小心奇怪的私信内容,即便他是你的某个好友发送给你的。
lanlan
(6级) 阿里巴巴安全工程师
 ================================================================

 Hackers e geeks FreeBuf
 http://www.freebuf.com/news/37673.html

Espalhe através do facebook bitcoin Trojans de mineração

Lanlan @ Informações 2014/07/07
 EDITORIAL:
Na verdade, o uso ea disseminação deste Trojan é ainda muito à moda antiga, além de vender autor carga útil dentro de um surgimento de fora.
Texto:
Os usuários do Facebook em muitos países, Portugal, Bélgica, Índia, Roma, Espanha, etc, estão sendo um novo ataque de Tróia, as vítimas deste Trojan irá controlar o anfitrião bitcoin mineração.
Os especialistas em segurança Bitdefender dizer, já há um grande número de usuários do Facebook estão infectados por este Trojan. Alexandra Gheorghe no seu blogue , que escreveu: Este Trojan via facebook em uma carta privada a se espalhar, carta particular contém uma 1IMAG00953.zip, incluindo arquivo malicioso disfarçado como jpg. Este documento será pré-definido pela conta Dropbox baixar os arquivos DLL, que apontam para C & C servidor e retorna um shellcode. Neste shellcode dentro da secção de carga de tais informações.
  "Olá pessoas .. :) <- projetado pela equipe SkyNet -> 
mas não sou o f ***** g zeus bot / skynet bot ou o que quer pedaço de s ** t .. 
nenhuma fraude aqui .. só um Pare pouco de mineração. quebrando meu b *** z .. 
Provavelmente queria dizer, eu estava cavando mineração, há outras funções maliciosas, misericórdia e afins. shellcode levará a um segundo de download DLL, e começou a processos de mineração.
Mas especialistas em segurança Bitdefender ® descobriu os maliciosos Tróia muitas outras funções, mas apenas uma pequena parte da mineração entre estas características, este Trojan vai transformar a cada poucas horas de conteúdo shellcode, fazer qualquer coisa no host vítima.
Os usuários do Facebook, a melhor carta particular conteúdo cuidadosamente estranhos, mesmo que ele é um dos seus amigos enviar para você.

 ================================================================
 FreeBuf 해커와 괴짜
 http://www.freebuf.com/news/37673.html

광산 트로이 목마 비트 코인 페이스 북을 통해 확산

Lanlan @ 정보 4천5백22명의 2014년 7월 7일

 사설 :
사실,이 트로이 목마의 사용과 배포는 외부 돋 안에 저자의 페이로드를 판매뿐만 아니라, 여전히 구식이다.
텍스트 :
많은 국가 등 포르투갈, 벨기에, 인도, 로마, 스페인, 새로운 트로이 목마 공격이 트로이 목마의 피해자되고있다 페이스 북 사용자는 광산 비트 코인 호스트를 제어 할 수 있습니다.
디펜더의 보안 전문가들은이 트로이 목마에 감염된 페이스 북 많은 수의 사용자가 이미있다,라고. 알렉산드라 게 오르게는 자신의 블로그에 쓴 :이 트로이 목마를 페이스 북을 통해 확산하는 개인 편지에서, 개인 편지는 JPG 파일로 위장한 악성 파일을 포함 1IMAG00953.zip가 포함되어 있습니다. 이 문서는 C & C 서버에 연결됩니다 DLL 파일을 다운로드 할 수 드롭 박스 계정이 미리 설정하고 쉘 코드를 반환 할 것입니다. 이러한 정보의 페이로드 부분 안쪽이 쉘 코드.
  "안녕하세요 사람들은 .. :) <- 스카이 넷 팀에 의해 디자인 ->하지만 F ***** g 
제우스 봇 / 스카이 넷 로봇이든의 조각 ** t .. 여기없는 사기 .. 
단지입니다 광산의 비트. 내 B *** Z를 깨고 중지 .. 
아마 말을 의미, 나는 광업, 다른 악성 기능, 자비 등을 발굴했다.     
쉘 코드는 두 번째 DLL 다운로드로 이어질 및 마이닝 프로세스를 시작합니다.
그러나 명 Bitdefender의 보안 전문가들은 악성 트로이 목마 많은 다른 기능을 발견하지만,    
이러한 기능 중 광산의 작은 부분이 트로이 목마는 감염된 호스트의 작업을 수행,    
몇 시간마다 쉘 코드의 내용을 변형시킬 것이다.
페이스 북 사용자, 최고의 개인 편지 신중 이상한 내용, 그 친구 중 하나입니다 경우에도 당신에게 보냅니다.

 =================================================================

 FreeBuf 해커와 괴짜
  http://www.freebuf.com/news/37673.html

Corre a través de facebook bitcoin troyanos mineras

Lanlan @ Información 07/07/2014
 EDITORIAL:
De hecho, el uso y la difusión de este troyano es todavía muy pasado de moda, además de la exitosa autora de carga útil dentro de un brote fuera.
Texto:
Los usuarios de Facebook en muchos países, Portugal, Bélgica, India, Roma, España, etc, están siendo un nuevo ataque de Troya, las víctimas de este troyano controlarán el anfitrión bitcoin minero.
Expertos de seguridad de Bitdefender dicen, ya hay un gran número de usuarios de Facebook están infectados por este troyano. Alexandra Gheorghe en su blog de ​​la que escribió: Este troyano a través de Facebook en una carta privada a extenderse, carta privada contiene una 1IMAG00953.zip, incluyendo archivo malicioso disfrazado como archivos jpg. Este documento será previamente establecido por cuenta de Dropbox para descargar archivos DLL, que unirán al servidor C & C y devuelve un código shell. En este código shell dentro de la sección de carga útil de dicha información.
  "Hola gente .. :) <- diseñado por el equipo SkyNet -> pero no soy el f ***** g 
zeus bot / skynet bot o cualquier pedazo de s ** t .. hay fraude aquí .. 
sólo un poco de la minería. dejar de romper mi b *** z .. 
Probablemente quería decir, me estaba cavando la minería, no hay otras funciones maliciosas, misericordia y similares. shellcode llevará a una segunda descarga DLL, y comenzó los procesos mineros.
Pero los expertos de seguridad de Bitdefender ® descubrieron los maliciosos troyanos muchas otras funciones, pero sólo una pequeña parte de la minería entre estas características, este troyano se transformarán cada pocas horas de contenido shellcode, hacer nada en el host víctima.
Los usuarios de Facebook, la mejor carta privada contenidos cuidadosamente extraños, incluso si es uno de sus amigos le envían.

 ==============================================================

 FreeBuf 해커와 괴짜
  http://www.freebuf.com/news/37673.html

Diffondere attraverso facebook bitcoin Trojan minerari

Lanlan @ Informazioni 2014/07/07

 EDITORIALE:
In effetti, l'uso e la diffusione di questo Trojan è ancora molto vecchio stile, oltre a vendere autore payload all'interno di una germinazione esterno.
Testo:
Gli utenti di Facebook in molti paesi, Portogallo, Belgio, India, Roma, Spagna, ecc, sono in corso di un nuovo attacco di Troia, le vittime di questo Trojan controlleranno l'host bitcoin mining.
Gli esperti di sicurezza Bitdefender dicono, ci sono già un gran numero di utenti di Facebook sono infettati da questo Trojan. Alexandra Gheorghe nel suo blog , che ha scritto: Questo Trojan via facebook in una lettera privata a diffondersi, lettera privata contiene un 1IMAG00953.zip, compresi file dannoso mascherato da file jpg. Questo documento sarà pre-impostato account Dropbox per scaricare file DLL, che collegheranno al server C & C e restituisce un shellcode. In questo shellcode all'interno della sezione payload di tali informazioni.
  "Ciao gente .. :) <- Creato dal Team SkyNet -> ma non sono il f ***** g 
Zeus bot / SkyNet bot o qualsiasi pezzo di s ** t .. nessuna frode qui .. 
solo un po 'di estrazione mineraria. Smettere di rompere il mio b *** z .. 
Probabilmente voleva dire, stavo scavando miniere, altre funzioni maligni,    
la misericordia e simili. shellcode porterà ad una seconda DLL di download,    
e cominciò processi di estrazione.
Ma gli esperti Bitdefender ® di sicurezza scoperti i malware Trojan molte altre funzioni,    
ma solo una piccola parte della miniera tra queste caratteristiche,     
questo Trojan si trasformeranno ogni poche ore di contenuti shellcode,     
fare qualsiasi cosa sulla macchina vittima.
Gli utenti di Facebook, il meglio per lettera privata contenuto con precauzione strane, anche se è uno dei tuoi amici inviare a voi.

 ===============================================================
 FreeBufハッカーやギーク
 http://www.freebuf.com/news/37673.html

鉱業トロイの木馬bitcoinのFacebookを介して広がる

LANLAN @ 情報 5000人の2014年7月7日
 社説:
実際には、このトロイの木馬の使用と普及が発芽内外著者ペイロードを販売することに加えて、まだ非常に古風です。
テキスト:
多くの国でのFacebookユーザーなど、ポルトガル、ベルギー、インド、ローマ、スペインは、新たなトロイの木馬攻撃されて、このトロイの木馬の犠牲者は鉱山bitcoinホストを制御している。
BitDefenderののセキュリティ専門家は、このトロイの木馬に感染しているFacebookユーザーが多数に既に存在する、と言う。   
アレクサンドラゲオルゲは自分でブログを書いた:このトロイの木馬をFacebook経由広めるために、民間の手紙の中で、民間の手紙は、JPGファイルを装った悪質なファイルを含め1IMAG00953.zipが含まれています。 このドキュメントでは、C&Cサーバーにリンクします、DLLのファイルを、ダウンロードするためのDropboxアカウントによって事前に設定され、シェルコードが返されます。 そのような情報のペイロード部内でこのシェルコード中。
  「こんにちは、人々は.. :) <! - スカイネットチームによって設計された - >ではなく
、F ***** Gゼウスボット/スカイネットボットまたは何秒の作品**トン..
ここには詐欺いただける午前鉱業のビット。私のB *** Zを、こわしつづけるのはもうやめ.. 
おそらく言うことを意味、私は鉱業、他の悪意のある機能、慈悲などを掘りました。 シェルコードは、第2のDLLのダウンロードにつながり、鉱業プロセスを開始したします。
しかし、ビットディフェンダーのセキュリティ専門家は、悪質なトロイの木馬の多くの他の機能を発見したが、これらの機能の中で、鉱業のほんの一部に、このトロイの木馬は、被害者のホスト上で何でも、数時間ごとにシェルコードの内容を変えていく。
Facebookユーザー、最高のプライベートの手紙を慎重に奇妙な内容、彼はあなたの友人の一人であっても、あなたに送ります。


 =================================================================
 FreeBuf хакерів і вундеркіндів
 http://www.freebuf.com/news/37673.html

Поширення через Facebook Bitcoin гірничодобувних троянів

Lanlan @ Інформація 2014-07-07
 РЕДАКЦІЯ:
Насправді, використання та поширення даного троянця раніше дуже старомодний,    
на додаток до продажу автор корисного навантаження всередині проростання зовні.
Текст:
Користувачі Facebook в багатьох країнах, Португалії, Бельгії, Індії, Римі, Іспанії і т.д.,    
в даний час новий троянських атак, жертвами даного троянця контролюватиме господаря Bitcoin видобутку.
Експерти з безпеки BitDefender кажуть, вже є велика кількість користувачів Facebook заражені цим трояном. Олександра Георге у своєму блозі , який писав:    
Цей троян через Facebook у приватному листі поширення, приватний лист містить 1IMAG00953.zip, в тому числі шкідливого файлу, замаскований під JPG-файлів.  
Цей документ буде попередньо встановити на аккаунт Dropbox для завантаження DLL файли, які будуть посилатися на C & C сервера і повертає шеллкод.      
У цьому шеллкоде усередині секції корисного навантаження такої інформації.
  "Привіт люди .. :) <! - Розроблений SkyNet Team ->, 
але я не е ***** г Зевс пляшок / 
SkyNet бот або будь-який шматок г ** .. 
ніякого шахрайства тут .. 
тільки трохи видобутку. Стоп розбиває моє B *** г .. 
Напевно хотів сказати, я копав видобутку, ніякі інші шкідливі функції, милосердя і т.п.. Шеллкод призведе до друга DLL скачування, і почав гірничих процесів.
Але експерти з безпеки BitDefender виявила шкідливі троянські багато інших функцій, але лише невелика частина видобутку серед цих особливостей, цей троян перетворить кожні кілька годин вміст шелл-код, нічого робити на комп'ютері жертви.
Користувачі Facebook, кращий приватний лист ретельно дивні зміст, навіть якщо він один з ваших друзів послати до вас.


===============================================================
 FreeBuf hackere og nerder
 http://www.freebuf.com/news/37673.html

Spre gjennom facebook Bitcoin gruvedrift trojanere

Lanlan @ Information 2014-07-07

 LEDER:
Faktisk er bruk og spredning av denne trojaneren fortsatt veldig gammeldags, i tillegg til å selge forfatteren nyttelast inne i en spirende utenfor.
Tekst:
Facebook-brukere i mange land, Portugal, Belgia, India, Roma, Spania, etc.,  
blir en ny trojanske angrep, ofrene for denne trojaneren vil kontrollere vert Bitcoin mining.
BitDefenders sikkerhetseksperter sier, det er allerede et stort antall Facebook-brukere   
er infisert av denne trojaneren. Alexandra Gheorghe i sin blogg , som skrev:     
Denne trojaneren via facebook i et privat brev til spredt, privat brev inneholder en 1IMAG00953.zip, inkludert skadelig fil forkledd som jpg-filer.      
Dette dokumentet vil bli pre-set av Dropbox-konto for å laste ned DLL-filer,     
noe som vil lenker til C & C-server, og returnerer en shellcode.  
I denne shellcode inne i nyttelast delen av slik informasjon.
  "Hei folk .. :) <- Designet av SkyNet Team -> men er ikke den f ***** g 
zeus bot / Skynet bot eller hva stykke s ** t .. ingen svindel her .. 
bare en bit av gruvedrift. Stopp bryte min b *** z .. 
Sannsynligvis mente å si, var jeg grave gruvedrift, ingen andre skadelige funksjoner, barmhjertighet og lignende. shellcode vil føre til en andre DLL nedlasting, og begynte gruvedrift prosesser.
Men BitDefenders sikkerhetseksperter oppdaget de ondsinnede trojanske mange andre funksjoner, men bare en liten del av gruve blant disse funksjonene, vil denne trojaneren forvandle hver noen timer shellcode innhold, gjøre noe på offeret vert.
Facebook-brukere, de beste private brev nøye merkelige innholdet, selv om han er en av dine venner sender til deg.


=================================================================
*"This is the purpose of our blog
Virtual impossible to be true
Some people just self-hypnosis
It does not matter if the entire labor
Non-productive, sit and wait for money to fall from the sky?
Then life will be wasted.

Therefore, we do not agree with Bitcoin'' '
Back in March, the first two to share Taiwan's Ministry of Education
Moonlight tribe, information sharing Nick already mentioned

Our objective becomes more book reviews
Network can not be deceived not for the money shared
We can not conceal cases of patience to endure if deception
And changes Evil
As long as we can see their
Hear, see and hear analysis
Share with others, do not return, discrimination does not exist,
Will do the right thing, even though we are far apart, and place your
Under the same sky, we are one family.
For injustice, but also to extend the appeal of the channels found
Political power is not afraid of a closed element,
Fair, open and free and independent people were drawn bright history channel
Enlightened country's swastika moral argumentation is to defend the people and the country's first social elite national / local leaders.
It is in 2014 the world.
             Sincerely, ~ small ignorance MelodyRO

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

=================================================

"這是我們部落格的宗旨
虛擬不可當成真
只是某些人在自我催眠

人們若全都不事勞動
不事生產,坐着等着金錢從天上掉下來?
那麼一生便浪費掉了.

故我們並不同意''比特幣'
早在兩至三月前在台灣分享部的
月光部落,Nick的分享資訊中已提及過

而讀後感更加成了我們的宗旨
不能作網絡欺騙,不可為金錢而分享
不能對受欺騙的個案作出隱瞞.
正與邪因人而異
我們只要把自已看到的
聽到的,分析過的所見所聞
分享給別人,不需回報,不存歧視,
對的事便要做,縱使你和我們相隔很遠的地方
在同一天空下,我們都是一體的人"
對於不公義的事,也要找尋渠道伸訴
不懼怕強權封閉的政治要素,
公平公正公開和自由自主是人們被歷史引領出的光明之道
卍德行義理者的開明國家是保衞人們及社會國家的賢能國首/地方首長.
這是現今2014的世界了."
           渺小愚昧的 MelodyRO敬上~

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

===============================================


"Este é o objetivo do nosso blog
Virtual impossível para ser verdade
Algumas pessoas simplesmente auto-hipnose
Não importa se todo o trabalho
Não produtivos, sentar-se e esperar o dinheiro cair do céu?
Então a vida será desperdiçado.

Portanto, não estamos de acordo com a Bitcoin'' '
Em março, os dois primeiros a compartilhar Ministério da Educação de Taiwan
Tribo do luar, o compartilhamento de informações Nick já mencionado

Nosso objetivo se torna mais resenhas de livros
Rede não pode ser enganado não pelo dinheiro compartilhado
Não podemos ocultar casos de paciência para suportar se engano
E mudanças Mal
Contanto que nós podemos ver o seu
Ouvir, ver e ouvir análise
Partilhe com os outros, não retornam, a discriminação não existe,
Será que fazer a coisa certa, apesar de estarmos distantes, e colocar o seu
Sob o mesmo céu, somos uma família.
Para a injustiça, mas também para ampliar o apelo dos canais encontrados
O poder político não tem medo de um elemento fechado,
Pessoas justas, abertas e livres e independentes foram atraídos brilhante canal de história
Argumentação moral suástica do país Enlightened é defender as pessoas e os primeiros líderes nacionais / locais de elite sociais do país.
É em 2014 o mundo.
              Atenciosamente, ~ pequena ignorância MelodyRO

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

=================================================


"이 블로그의 목적이다
사실 불가능 가상
어떤 사람들은 자기 최면
그것은 문제가되지 않는 경우 전체 노동
비 생산, 앉아서 돈이 하늘에서 떨어질 때까지 기다립니다?
그런 생활은 낭비됩니다.

따라서, 우리는 '비트 코인'에 동의하지 않는다
지난 3 월, 제 두 교육 대만의 사역을 공유하는
닉을 공유 달빛 부족, 정보가 이미 언급

우리의 목표는 더 많은 서평됩니다
네트워크 공유 돈을하지기만 할 수 없습니다
우리는 견딜 인내의 사례를 은폐 할 수없는 경우 속임수
악 및 변경
로 우리가 볼 수있는 자신의
듣고,보고, 분석을 듣고
다른 사람과 공유, 차별이 존재하지 않는, 반환하지 않습니다
우리가 멀리 떨어져에도 불구하고, 옳은 일을하고, 배치 할 것이다
같은 하늘 아래, 우리는 한 가족입니다.
부정을 위해, 또한 발견 채널의 매력을 확장 할
정치 권력은 폐쇄 요소 두려워하지 않는
공정하고 개방적이고 자유롭고 독립적 인 사람은 밝은 역사 채널 그려진
계몽 된 국가의 만자 도덕적 논증은 사람과 나라 최초의 사회 엘리트 국가 / 지역의 지도자를 방어하는 것입니다.
그것은 2014 년 세계입니다.
              감사합니다 ~ 작은 무지 MelodyRO

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

=================================================


"Este es el propósito de nuestro blog
Virtual imposible para ser verdad
Algunas personas simplemente la auto-hipnosis
No importa si toda la mano de obra
Improductivo, sentarse y esperar a que el dinero caiga del cielo?
Entonces la vida será en vano.

Por lo tanto, no estamos de acuerdo con Bitcoin'' '
Ya en marzo, los dos primeros para compartir Ministerio de Educación de Taiwán
Tribu Moonlight, compartiendo Nick información ya mencionada

Nuestro objetivo se vuelve más reseñas de libros
La red no puede ser engañado, no por el dinero compartido
No podemos ocultar los casos de paciencia para soportar si el engaño
Y los cambios Evil
Mientras que podemos ver a su
Oye, ver y oír el análisis
Comparte con los demás, no regrese, la discriminación no existe,
Hará lo correcto, a pesar de que estamos separados, y coloque su
Bajo el mismo cielo, somos una sola familia.
Por la injusticia, sino también para ampliar el atractivo de los canales encontrados
El poder político no tiene miedo de un elemento cerrado,
Personas justas, abiertas y libres e independientes se elaboraron canal historia brillante
Esvástica argumentación moral del país Enlightened es la defensa de las personas y los primeros líderes nacionales / locales de la élite social del país.
Es en el año 2014 el mundo.
              Atentamente, ~ pequeña ignorancia MelodyRO



=================================================

"Questo è lo scopo del nostro blog
Virtuale impossibile per essere vero
Alcune persone semplicemente auto-ipnosi
Non importa se l'intero lavoro
Non produttivi, sedersi e aspettare che i soldi a cadere dal cielo?
Poi sarà sprecato vita.

Pertanto, non siamo d'accordo con Bitcoin'' '
Già nel mese di marzo, i primi due a condividere Taiwan Ministero della Pubblica Istruzione
Tribù Moonlight, la condivisione di Nick informazioni già citato

Il nostro obiettivo diventa più recensioni di libri
Rete non può essere ingannato, non per i soldi in comune
Non possiamo nascondere casi di pazienza per sopportare se l'inganno
E cambiamenti Male
Fintanto che siamo in grado di vedere la loro
Ascoltare, vedere e sentire analisi
Condividi con gli altri, non ritorno, la discriminazione non esiste,
Farà la cosa giusta, anche se siamo lontani, e posizionare il
Sotto lo stesso cielo, siamo un'unica famiglia.
Per l'ingiustizia, ma anche di estendere l'appello dei canali trovati
Il potere politico non ha paura di un elemento chiuso,
Fiera, aperti e liberi e indipendenti persone sono state tratte canale storia brillante
Svastica argomentazione morale del paese illuminato è quello di difendere il popolo e primi leader nazionali / locali d'elite sociali del Paese.
È nel 2014 il mondo.
              Cordiali saluti, ~ piccola ignoranza MelodyRO

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

=================================================

"これは私たちのブログの目的である
本当であることは不可能仮想
一部の人だけ自己催眠
それは問題ではない場合は、全労働
非生産的、座ってお金が空から落下するのを待つ?
その後の人生は無駄になります。

したがって、我々は「Bitcoin''に同意しない
戻る3月、最初の2は教育の台湾省を共有する
ニックを共有して月明かりの部族、情報は既に述べた

我々の目的は、より多くの書評になる
ネットワーク共有のお金のためではないだまさすることはできません
我々は我慢する忍耐の例を隠すことができない場合は詐欺
悪と変化
限り、我々が見ることができるように彼らの
聞く、参照と分析を聞く
他のユーザーと共有、差別が存在していない、返さない
私たちは遠く離れていても、正しいことを行うと、配置されます、あなたの
同じ空の下、私たちは一つの家族です。
不正義のためだけでなく、見つかったチャンネルの魅力を拡張する
政治権力は、閉じられた要素を恐れていないです
公正、オープンで自由で独立した人々は明るい歴史チャネルを描いた
悟りを開いた国の卍道徳的な議論は、人と同国初の社会的エリートのローカル/国家指導者を守るためです。
これは、2014年の世界である。
             敬具〜小さな無知MelodyRO

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

================================================

"Це і є мета нашого блогу
Віртуальний неможливо, щоб бути правдою
Деякі люди просто самонавіювання
Це не має значення, якщо весь труд
Невиробнича, сидіти і чекати грошей, щоб падати з неба?
Тоді життя буде витрачено даремно.

Таким чином, ми не згодні з Bitcoin'' '
Ще в березні, перші два поділитися Тайваню Міністерство освіти
Місячне світло плем'я, обміну Нік інформація вже згадувалося

Наша мета стає більше рецензії на книги
Мережа не може бути обдурять не за гроші загальної
Ми не можемо приховати випадки терпіння, щоб витримати, якщо обман
І зміни Злі
До тих пір, як ми можемо бачити їх
Слухай, бачити і чути аналіз
Поділіться з іншими, не повертаються, дискримінація не існує,
Буде робити правильні речі, навіть якщо ми далеко один від одного, і Наведіть
Під одним небом, ми одна сім'я.
Для несправедливості, але й розширити привабливість знайдених каналів
Політична влада не боїться замкнутого елемента,
Справедливих, відкритих і вільних і незалежних людей були залучені яскравий історичний канал
Свастика моральна аргументація Просвітленого країни є захист людей і перші соціальні елітних національних / місцевих лідерів країни.
Саме в 2014 році світовий.
              З повагою, ~ маленький невігластво MelodyRO

http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

=================================================

"Ĉi tio estas la celo de nia blogo
Virtuala neeble esti vera
Iuj homoj simple autohipnosis
Ne gravas, se la tuta laboro
Ne-produktiva, sidi kaj atendi monon fali de la ĉielo?
Tiam vivo estos ekstermotaj.

Sekve, ni ne konsentas kun Bitcoin'' '
Reen en marto, la unua du kunhavigi tajvana Ministerio de Edukado
Lunlumo tribo, informoj dividante Nick jam menciita

Nia celo iĝas pli libron recenzoj
Reto ne povas esti trompitaj ne por la mono dividis
Ni ne povas kaŝi kazojn de pacienco elteni se trompado
Kaj ŝanĝoj Evil
Tiel longe kiel ni povas vidi ilian
Auxskultu, vidi kaj aŭdi analitiko
Kunhavigi kun aliaj, ne revenas, la diskriminacio ne ekzistas,
Ĉu venos la ĝusta, kvankam ni estas malproksime aparte, kaj metu vian
Sub la sama ĉielo, ni estas unu familio.
Por maljusteco, sed ankaŭ por etendi la apelacio de la kanaloj trovita
Politika povo ne timas fermita elemento,
Foiro, malferma kaj libera kaj sendependa homoj estis desegnita brilan historion kanalo
Prilumitaj landan swastika morala argumentado estas protekti la popolon kaj la landa unua socia elito nacia / loka gvidantoj.
Ĝi estas en 2014 la mondo.
              Sincere, ~ malgranda nescio MelodyRO


http://melodytoyssexy.blogspot.com/2014/07/usaukptmacaufdzkorenspitjpukninternatio.html

===============================================

**USA/UK/TW/PT(Macau)FDZ/Koren/SP/IT/JP/UKN.....International lauguage**--
---**By Lan Lan @ July .7 * Whitecaps information dissemination Facebook released --- ** ---> Bitcoin <------- Mining Trojan ** -? Bitcoin in our tribe is a vicious virtual currency, which means you have to ...... "-! Maintain a certain distance ....-
--**由兰兰@七月.7*白帽信息传播的Facebook发布---**---> Bitcoin<-------采矿木马** - ?Bitcoin在我们的部落是一个恶性的虛擬貨幣,这意味着你要......“ - !保持一定的距离..... -
--**Por Lan Lan @ July 0,7 * Informações Whitecaps disseminação Facebook lançou --- ** ---> Bitcoin <------- Mineração Trojan ** - Bitcoin em nossa tribo é uma moeda virtual vicioso , o que significa que você tem que ...... "- Manter uma certa distância ....-
--- ** 란 란 7 월에 0.7 @ 페이스 북이 발표 * 화이트 캡스 정보 보급 --- ** ---> 비트 코인은 <------- 광업 트로이 ** -? 우리의 부족에있는 비트 코인은 악순환의 가상입니다 ! 일정한 거리를 유지 - 당신이 ...... "하는 것을 의미 통화, ....-


===MelodyRO===THE   END===>/