Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <!doctype html>
- <!--
- Material Design Lite
- Copyright 2015 Google Inc. All rights reserved.
- Licensed under the Apache License, Version 2.0 (the "License");
- you may not use this file except in compliance with the License.
- You may obtain a copy of the License at
- https://www.apache.org/licenses/LICENSE-2.0
- Unless required by applicable law or agreed to in writing, software
- distributed under the License is distributed on an "AS IS" BASIS,
- WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- See the License for the specific language governing permissions and
- limitations under the License
- -->
- <html lang="en">
- <head>
- <meta charset="utf-8">
- <meta http-equiv="X-UA-Compatible" content="IE=edge">
- <meta name="description" content="A front-end template that helps you build fast, modern mobile web apps.">
- <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0">
- <title>B.A.S.H</title>
- <!-- Add to homescreen for Chrome on Android -->
- <meta name="mobile-web-app-capable" content="yes">
- <link rel="icon" sizes="192x192" href="images/android-desktop.png">
- <!-- Add to homescreen for Safari on iOS -->
- <meta name="apple-mobile-web-app-capable" content="yes">
- <meta name="apple-mobile-web-app-status-bar-style" content="black">
- <meta name="apple-mobile-web-app-title" content="Material Design Lite">
- <link rel="apple-touch-icon-precomposed" href="images/ios-desktop.png">
- <!-- Tile icon for Win8 (144x144 + tile color) -->
- <meta name="msapplication-TileImage" content="images/touch/ms-touch-icon-144x144-precomposed.png">
- <meta name="msapplication-TileColor" content="#3372DF">
- <link rel="shortcut icon" href="images/favicon.png">
- <!-- SEO: If your mobile URL is different from the desktop URL, add a canonical link to the desktop page https://developers.google.com/webmasters/smartphone-sites/feature-phones -->
- <!--
- <link rel="canonical" href="http://www.example.com/">
- -->
- <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:regular,bold,italic,thin,light,bolditalic,black,medium&lang=en">
- <link rel="stylesheet" href="https://fonts.googleapis.com/icon?family=Material+Icons">
- <link rel="stylesheet" href="https://code.getmdl.io/1.3.0/material.light_blue-amber.min.css" />
- <link rel="stylesheet" href="styles.css">
- <style>
- #view-source {
- position: fixed;
- display: block;
- right: 0;
- bottom: 0;
- margin-right: 40px;
- margin-bottom: 40px;
- z-index: 900;
- }
- .fit-img {
- max-width: 100%;
- max-height: 100%;
- }
- .pointer {
- cursor: pointer;
- }
- .ta-left td,
- .ta-left th {
- text-align: left;
- }
- .table-container {
- width: 100%;
- }
- #tracelog-tb {
- margin: 0 auto;
- }
- .dll {
- cursor: pointer;
- color: #03A9F4;
- }
- .header-title{
- color:#F5F5F5;
- }
- .section-header-info{
- font-size: 28px;
- }
- .hide{
- display: none;
- }
- </style>
- </head>
- <body class="mdl-demo mdl-color--grey-100 mdl-color-text--grey-700 mdl-base">
- <div class="mdl-layout mdl-js-layout mdl-layout--fixed-header">
- <header class="mdl-layout__header mdl-layout__header--scroll mdl-color--black">
- <div class="mdl-layout--large-screen-only mdl-layout__header-row">
- </div>
- <div class="mdl-layout--large-screen-only mdl-layout__header-row">
- <h3 class="header-title">$B.A.S.H - Become A Smarter Hacker</h3>
- </div>
- <div class="mdl-layout--large-screen-only mdl-layout__header-row">
- </div>
- <div class="mdl-layout__tab-bar mdl-js-ripple-effect mdl-color--primary-dark">
- <a href="#overview" class="mdl-layout__tab is-active">Overview</a>
- <a href="#features" class="mdl-layout__tab">Features</a>
- <a href="#features" class="mdl-layout__tab">Details</a>
- <a href="#features" class="mdl-layout__tab">Technology</a>
- <a href="#features" class="mdl-layout__tab">FAQ</a>
- <button class="mdl-button mdl-js-button mdl-button--fab mdl-js-ripple-effect mdl-button--colored mdl-shadow--4dp mdl-color--accent"
- id="add">
- <i class="material-icons" role="presentation">add</i>
- <span class="visuallyhidden">Add</span>
- </button>
- </div>
- </header>
- <main class="mdl-layout__content">
- <div class="mdl-layout__tab-panel is-active" id="overview">
- <!-- malware summary section -->
- <section class="section--center mdl-grid mdl-grid--no-spacing mdl-shadow--2dp">
- <header class="section-header-info section__play-btn mdl-cell mdl-cell--3-col-desktop mdl-cell--2-col-tablet mdl-cell--4-col-phone mdl-color--lime-500 mdl-color-text--white">
- WORM
- </header>
- <div class="mdl-card mdl-cell mdl-cell--9-col-desktop mdl-cell--6-col-tablet mdl-cell--4-col-phone">
- <div class="mdl-card__supporting-text">
- <h4>Allaple</h4>
- <div class="mal_summary">
- Worm:Win32/Allaple.A is a multi-threaded, polymorphic network wormcapable ofspreadingto other computers connected to a local
- area network (LAN)and performingdenial-of-service (DoS) attacks against targeted remote Web sites.
- </div>
- </div>
- <!-- <div class="mdl-card__actions">
- <a href="#" class="mdl-button">Read our features</a>
- </div> -->
- </div>
- <button class="mdl-button mdl-js-button mdl-js-ripple-effect mdl-button--icon" id="btn1">
- <i class="material-icons">more_vert</i>
- </button>
- <ul class="mdl-menu mdl-js-menu mdl-menu--bottom-right" for="btn1">
- <li class="mdl-menu__item"> All</li>
- <li class="mdl-menu__item">Microsft</li>
- <li class="mdl-menu__item">F-secure</li>
- </ul>
- </section>
- <!-- malware info section -->
- <section class="info-section section--center mdl-grid mdl-grid--no-spacing mdl-shadow--2dp">
- <div class="mdl-card mdl-cell mdl-cell--12-col">
- <div class="mdl-card__supporting-text mdl-grid mdl-grid--no-spacing">
- <h4 class="mdl-cell mdl-cell--12-col">Information</h4>
- <div class="mal_behaviors section__circle-container mdl-cell mdl-cell--2-col mdl-cell--1-col-phone">
- <div class="section__circle-container__circle mdl-color--accent"></div>
- </div>
- <div class="mal_behaviors section__text mdl-cell mdl-cell--10-col-desktop mdl-cell--6-col-tablet mdl-cell--3-col-phone">
- <h5>Behaviors</h5>
- <div class="mal_behaviors_content">
- The malware scans for vulnerable computers (on TCP ports 139 and 445) and sends exploits there in order to infect them. Scans
- for .HTM and .HTML files on all local hard disks and infects them by prepending a reference to worm’s CLSID
- there. It also performs a DoS attack on three websites located in Estonia
- </div>
- </div>
- <div class="mal_tech_description section__circle-container mdl-cell mdl-cell--2-col mdl-cell--1-col-phone">
- <div class="section__circle-container__circle mdl-color--primary"></div>
- </div>
- <div class="mal_tech_description section__text mdl-cell mdl-cell--10-col-desktop mdl-cell--6-col-tablet mdl-cell--3-col-phone">
- <h5>Technical description</h5>
- <div class="mal_tech_description_content">
- The worm's file is polymorphically encrypted, which means every copy of the worm is different.The worm creates a different
- CLSID for every copy of itself that it creates on the hard drive. After getting control, the worm creates
- a few threads.
- <ul>
- 1. One thread scans for vulnerable computers (on TCP ports 139 and 445) and sends exploits there in order to infect them.
- <br> (1)Microsoft Security Bulletin MS06-040,利用Server 服務中的弱點可能會允許遠端執行程式碼
- <br> (2)字典破解弱密碼
- </ul>
- <ul>
- 2. The other thread scans for .HTM and .HTML files on all local hard disks and infects them by prepending a reference to
- worm's CLSID there.
- <div>
- <img class="fit-img" src="https://i.imgur.com/VUCwgxA.png" />
- </div>
- </ul>
- <ul>
- 3. One of the remaining threads performs a DoS attack on three websites located in Estonia.
- </ul>
- </div>
- </div>
- <div class="mal_symptons section__circle-container mdl-cell mdl-cell--2-col mdl-cell--1-col-phone">
- <div class="section__circle-container__circle mdl-color--red"></div>
- </div>
- <div class="mal_symptons section__text mdl-cell mdl-cell--10-col-desktop mdl-cell--6-col-tablet mdl-cell--3-col-phone">
- <h5>Symptons</h5>
- <div class="mal_symptons_content">
- The following symptoms may be indicative of a Worm:Win32/Allaple.A infection:
- <ul>
- 1. Unexpected presence of arandomly named .EXE file in folders containing files with .HTML and .HTM file extensions
- </ul>
- <ul>
- 2. Presence of the following registry modification: ImagePath =
- <system folder>\
- <filename> /service Insubkey:
- <code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows</code>
- </ul>
- <ul>
- 3. The only constant aspect of the worm’s code is the size of its executable file - 57856 bytes.Large copies of 57856 bytes
- files in disk.
- </ul>
- </div>
- </div>
- </div>
- <div class="mdl-card__actions">
- <span class="mdl-chip mdl-chip--contact pointer ms-tab">
- <span class="mdl-chip__contact mdl-color--blue mdl-color-text--white">M</span>
- <span class="mdl-chip__text">Microsoft</span>
- </span>
- <span class="mdl-chip mdl-chip--contact pointer">
- <span class="mdl-chip__contact mdl-color--teal mdl-color-text--white">F</span>
- <span class="mdl-chip__text">F-secure</span>
- </span>
- </div>
- </div>
- <button class="mdl-button mdl-js-button mdl-js-ripple-effect mdl-button--icon" id="btn2">
- <i class="material-icons">more_vert</i>
- </button>
- <ul class="mdl-menu mdl-js-menu mdl-menu--bottom-right" for="btn2">
- <li class="mdl-menu__item"> All</li>
- <li class="mdl-menu__item">Microsft</li>
- <li class="mdl-menu__item">F-secure</li>
- </ul>
- </section>
- <section class="section--center mdl-grid mdl-grid--no-spacing mdl-shadow--2dp">
- <div class="mdl-card mdl-cell mdl-cell--12-col">
- <div class="mdl-card__supporting-text">
- <h4>More Information</h4>
- </div>
- <div class="mdl-card__actions">
- <a href="#" class="mdl-button">Read our features</a>
- </div>
- </div>
- <button class="mdl-button mdl-js-button mdl-js-ripple-effect mdl-button--icon" id="btn3">
- <i class="material-icons">more_vert</i>
- </button>
- <ul class="mdl-menu mdl-js-menu mdl-menu--bottom-right" for="btn3">
- <li class="mdl-menu__item">Lorem</li>
- <li class="mdl-menu__item" disabled>Ipsum</li>
- <li class="mdl-menu__item">Dolor</li>
- </ul>
- </section>
- <section class="section--footer mdl-color--white mdl-grid">
- <div class="section__circle-container mdl-cell mdl-cell--2-col mdl-cell--1-col-phone">
- <div class="section__circle-container__circle mdl-color--accent section__circle--big"></div>
- </div>
- <div class="section__text mdl-cell mdl-cell--4-col-desktop mdl-cell--6-col-tablet mdl-cell--3-col-phone">
- <h5>Tracelog Analysis</h5>
- Tracelog Analysis description text here
- </div>
- <div class="table-container">
- <table id="tracelog-tb" class="mdl-data-table mdl-js-data-table mdl-shadow--2dp ta-left">
- <thead>
- <tr>
- <th>Timestamp</th>
- <th>Stage</th>
- <th>Technical Description</th>
- <th>Observerd Behavior</th>
- <th>Tracelog</th>
- </tr>
- </thead>
- <tbody>
- </tbody>
- </table>
- </div>
- </section>
- </div>
- <div class="mdl-layout__tab-panel" id="features">
- <section class="section--center mdl-grid mdl-grid--no-spacing">
- <div class="mdl-cell mdl-cell--12-col">
- <h4>Features</h4>
- Minim duis incididunt est cillum est ex occaecat consectetur. Qui sint ut et qui nisi cupidatat. Reprehenderit nostrud proident
- officia exercitation anim et pariatur ex.
- <ul class="toc">
- <h4>Contents</h4>
- <a href="#lorem1">Lorem ipsum</a>
- <a href="#lorem2">Lorem ipsum</a>
- <a href="#lorem3">Lorem ipsum</a>
- <a href="#lorem4">Lorem ipsum</a>
- <a href="#lorem5">Lorem ipsum</a>
- </ul>
- <h5 id="lorem1">Lorem ipsum dolor sit amet</h5>
- Excepteur et pariatur officia veniam anim culpa cupidatat consequat ad velit culpa est non.
- <ul>
- <li>Nisi qui nisi duis commodo duis reprehenderit consequat velit aliquip.</li>
- <li>Dolor consectetur incididunt in ipsum laborum non et irure pariatur excepteur anim occaecat officia sint.</li>
- <li>Lorem labore proident officia excepteur do.</li>
- </ul>
- </div>
- </section>
- </div>
- <footer class="mdl-mega-footer">
- <div class="mdl-mega-footer--middle-section">
- <div class="mdl-mega-footer--drop-down-section">
- <input class="mdl-mega-footer--heading-checkbox" type="checkbox" checked>
- <h1 class="mdl-mega-footer--heading">Features</h1>
- <ul class="mdl-mega-footer--link-list">
- <li>
- <a href="#">About</a>
- </li>
- <li>
- <a href="#">Terms</a>
- </li>
- <li>
- <a href="#">Partners</a>
- </li>
- <li>
- <a href="#">Updates</a>
- </li>
- </ul>
- </div>
- <div class="mdl-mega-footer--drop-down-section">
- <input class="mdl-mega-footer--heading-checkbox" type="checkbox" checked>
- <h1 class="mdl-mega-footer--heading">Details</h1>
- <ul class="mdl-mega-footer--link-list">
- <li>
- <a href="#">Spec</a>
- </li>
- <li>
- <a href="#">Tools</a>
- </li>
- <li>
- <a href="#">Resources</a>
- </li>
- </ul>
- </div>
- <div class="mdl-mega-footer--drop-down-section">
- <input class="mdl-mega-footer--heading-checkbox" type="checkbox" checked>
- <h1 class="mdl-mega-footer--heading">Technology</h1>
- <ul class="mdl-mega-footer--link-list">
- <li>
- <a href="#">How it works</a>
- </li>
- <li>
- <a href="#">Patterns</a>
- </li>
- <li>
- <a href="#">Usage</a>
- </li>
- <li>
- <a href="#">Products</a>
- </li>
- <li>
- <a href="#">Contracts</a>
- </li>
- </ul>
- </div>
- <div class="mdl-mega-footer--drop-down-section">
- <input class="mdl-mega-footer--heading-checkbox" type="checkbox" checked>
- <h1 class="mdl-mega-footer--heading">FAQ</h1>
- <ul class="mdl-mega-footer--link-list">
- <li>
- <a href="#">Questions</a>
- </li>
- <li>
- <a href="#">Answers</a>
- </li>
- <li>
- <a href="#">Contact us</a>
- </li>
- </ul>
- </div>
- </div>
- <div class="mdl-mega-footer--bottom-section">
- <div class="mdl-logo">
- More Information
- </div>
- <ul class="mdl-mega-footer--link-list">
- <li>
- <a href="https://developers.google.com/web/starter-kit/">Web Starter Kit</a>
- </li>
- <li>
- <a href="#">Help</a>
- </li>
- <li>
- <a href="#">Privacy and Terms</a>
- </li>
- </ul>
- </div>
- </footer>
- <dialog class="mdl-dialog dll-dialog">
- <h4 class="mdl-dialog__title">DLL</h4>
- <div class="mdl-dialog__content">
- <p>
- DLL stuff
- </p>
- </div>
- <div class="mdl-dialog__actions">
- <!-- <button type="button" class="mdl-button close">Agree</button> -->
- <button type="button" class="mdl-button close">Close</button>
- </div>
- </dialog>
- </main>
- </div>
- <a href="https://github.com/google/material-design-lite/blob/mdl-1.x/templates/text-only/" target="_blank" id="view-source"
- class="mdl-button mdl-js-button mdl-button--raised mdl-js-ripple-effect mdl-color--accent mdl-color-text--accent-contrast">View Source</a>
- <script src="https://code.getmdl.io/1.3.0/material.min.js"></script>
- <script src="https://code.jquery.com/jquery-3.2.1.min.js"></script>
- </body>
- <script>
- function dialog_registry(dll_data) {
- var dll_dialog = document.querySelector('.mdl-dialog.dll-dialog');
- dll_dialog.querySelector('.close').addEventListener('click', function () {
- dll_dialog.close();
- });
- $('.dll').click(function () {
- var dll = $(this).text().toLowerCase();
- if (dll_data[dll]) {
- // console.log(dll, dll_data[dll]);
- dll_dialog.querySelector('.mdl-dialog__title').innerHTML = dll;
- dll_dialog.querySelector('p').innerHTML = dll_data[dll];
- dll_dialog.showModal();
- }
- });
- }
- $(window).ready(function () {
- $.ajax({
- url: "data.json",
- dataType: 'json',
- async: false,
- success: function (data) {
- console.log(data.length);
- var $tbody = $('#tracelog-tb tbody');
- for (var i = 0; i < data.length; ++i) {
- var tb_row = "";
- // index
- tb_row += '<td>' + (i+1).toString() + '</td>';
- // stage
- var stage;
- if (i <= 23)
- stage = '1';
- else if (i <= 91)
- stage = '2';
- else if (i <= 96)
- stage = '3';
- else
- stage = '4';
- tb_row += '<td>' + stage + '</td>';
- // technical description
- tb_row += '<td>' + 'TD' + '</td>';
- // observed behavior
- tb_row += '<td>' + 'OB' + '</td>';
- var tracelog = "";
- tracelog += '<strong>' + data[i]['action_name'] + '</strong> <br>';
- if (data[i]['actions'].length > 0) {
- for (var j = 0; j < data[i]['actions'].length; ++j) {
- tracelog += data[i]['actions'][j][0] + ": ";
- if (data[i]['actions'][j][1].toLowerCase().includes("dll")) {
- tracelog += '<span class="dll">' + data[i]['actions'][j][1] + '</span><br>';
- }
- else{
- tracelog += data[i]['actions'][j][1] + '<br>';
- }
- }
- }
- tracelog += "Return:" + data[i]['return'];
- tb_row += '<td >' + tracelog + '</td>';
- var tr = "<tr>" + tb_row + '</tr>';
- $tbody.append(tr);
- }
- }
- });
- var dll_data;
- $.ajax({
- url: "dll.json",
- dataType: 'json',
- async: false,
- success: function (data) {
- dll_data = data;
- }
- });
- var malware_data;
- $.ajax({
- url: "malware_info.json",
- dataType: 'json',
- async: false,
- success: function (data) {
- malware_data = data;
- // malware_data = malware_data['allaple'];
- malware_data = malware_data[0]['content'][0];
- console.log(malware_data);
- }
- });
- $('.ms-tab').click(function name(params) {
- $('.info-section .mal_tech_description_content').html(malware_data['tech']);
- $('.info-section .mal_symptons_content').html(malware_data['symptoms']);
- console.log($(this));
- });
- dialog_registry(dll_data);
- });
- </script>
- </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement