À©µµ¿ìÁî ·çƮŶ Á¶»ç»ç·Ê
1. °³¿ä ÃÖ±Ù À©µµ¿ìÁî ÇØÅ·µ¿ÇâÀº °ø°Ý¿¡ ¼º°øÇÑ ÈÄ ½Ã½ºÅÛ¿¡ ´Ù¿î·Îµå µÈ ¾Ç¼ºÇÁ·Î±×·¥ (Bot, ¹éµµ¾î µî) ÆÄÀÏ ¹× ½ÇÇàµÈ ¾Ç¼º ³×Æ®¿öÅ©/ÇÁ·Î¼¼½º Á¤º¸¸¦ ¼û±â±â À§ÇØ ·çƮŶ ÀÌ ¿¬µ¿µÇ°í ÀÖ´Ù. Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(ÀÌÇÏ ¡°KISA¡±)Àº ±¹³» º¿C&C¼¹ö È°µ¿À» ŽÁöÇÏ´ø Áß µ¿ÀÏÇÑ ÆÐÅÏÀ» ³ªÅ¸³»´Â ½Ã½ºÅÛÀ» ¿©·µ °¨ÁöÇÏ¿´´Ù. ¼¹öµéÀ» ºÐ¼®ÇÑ °á°ú µ¿ÀÏÇÑ Áõ»óÀ» º¸¿´°í 1.exe(À©µµ¿ì 2000)¶ó´Â ÇÁ·Î±×·¥À» ÅëÇØ µ¥ÀÌÅÍ ´Ù¿î·Î´õ, Ä¿³Î ·çƮŶ, ¼ºñ½º µî·Ï °ü·Ã ÇÁ·Î±×·¥ÀÌ ½ÇÇàµÇ´Â °ÍÀ¸·Î È®ÀÎÀÌ µÇ¾ú´Ù. º»°í¿¡¼´Â À̹ø¿¡ ¹ß°ßÇÑ 1.exe ·çƮŶ ÇÁ·Î±×·¥ÀÇ Æ¯Â¡°ú Á¶»ç ³»¿ëÀ» Á¤¸®ÇÏ¿´´Ù.
2. ·çƮŶ Á¶»ç
1) Àüü °³¿ä
1.exe ½ÇÇà ¼ø¼¸¦ Á¾ÇÕ ±¸¼ºÇØ º¸¸é ¾Æ·¡¿Í °°´Ù.
(±×¸² 1) Àüü °³¿äµµ
2) 1.exe Á¶»ç
ù ¹ø°·Î Á¶»çÇÑ 1.exeÀÇ Æ¯Â¡Àº ´ÙÀ½°ú °°´Ù. - ¾ÐÃà : "instyler ex-it! Self-Extractor" - ±â´É : RECYCLER µð·ºÅ͸®¿¡ °ü·ÃÆÄÀÏµé ¾ÐÃàÇØÁ¦ config.exe¸¦ ½ÇÇàÇÏ¿© ¾Ç¼º ÇÁ·Î±×·¥ ¼¼Æà ¹× ½ÇÇà - °ü·Ã ÆÄÀÏ : ±×¸² 2 1.exeÀÇ ¾ÐÃàÇØÁ¦ ÂüÁ¶
1.exe ¹ÙÀ̳ʸ®´Â ¸ðµç ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¾ÐÃàµÈ ÇüÅ·ΠÁö´Ï°í ÀÖ°í ¾ÐÃà ÇØÁ¦ ÈÄ config.exe¸¦ ÅëÇÏ¿© ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ½Ã½ºÅÛ¿¡ µî·Ï/½ÇÇà ÇÏ°Ô µÈ´Ù. C:\RECYCLER ´Â °ü¸®°¡ ¼ÒȦÇÏ°í µð·ºÅ͸® ¼Ó¼ºÀÌ µðÆúÆ®·Î ¿î¿µÃ¼Á¦ ÆÄÀÏ·ÎÁöÁ¤ µÇ¾î ÀÖ¾î °ü¸®ÀÚÀÇ ´«À» ÇÇÇÒ ¼ö ÀÖ´Ù. ¾Æ·¡ ±×¸²°ú °°ÀÌ C:\RECYCLER¿¡ °ü·Ã ÆÄÀϵéÀ» ¾ÐÃàÇØÁ¦ ÇÑ´Ù.
(±×¸² 2) 1.exeÀÇ ¾ÐÃàÇØÁ¦
°ü·Ã ÆÄÀÏµé ¾ÐÃàÇØÁ¦°¡ ³¡³ª¸é ShellExecute ÇÔ¼ö¸¦ ÅëÇØ ¾Æ·¡ ±×¸²°ú °°ÀÌ config.exe¸¦ ½ÇÇàÇÏ°Ô µÈ´Ù.
(±×¸² 3) config.exe ½ÇÇà
3) config.exe Á¶»ç
config.exe Ư¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : ¾øÀ½ - ±â´É : ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ½ÇÇàÇÏ´Â ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÏ°í ½ÇÇà - °ü·ÃÆÄÀÏ : c:\Documents~1\kisa\Locals~1\Temp\bt0312.bat
config.exe ¹ÙÀ̳ʸ®¸¦ µð¹ö°Å¸¦ ÅëÇÏ¿© È®ÀÎÇÑ °á°ú c:\Documents~1\kisa\Locals~1\Temp\bt0312.bat ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ¶ÇÇÑ ¾Æ·¡ ±×¸²°ú °°ÀÌ CreateProcessÇÔ¼ö·Î cmd ¸í·É¾î¸¦ ÀÌ¿ë bt0312.bat ÆÄÀÏÀ» ½ÇÇàÇÑ´Ù.
(±×¸² 4) bt0312.bat ½ÇÇà
bt0312.bat ÆÄÀÏÀÇ ½ºÅ©¸³Æ®´Â ´ÙÀ½°ú °°Àº ¼ø¼·Î ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¼øÂ÷ÀûÀ¸·Î ½Ã½ºÅÛ¿¡ µî·Ï ¹× ½ÇÇàÇÏ°Ô µÈ´Ù.
¨ç mkdir "C:\Recycler\S-1-5-21-3127...\_restore.." ¡°C:\Recycler¡°´Â º¸È£µÇ´Â ¿î¿µÃ¼Á¦ µð·ºÅ͸®·Î Ž»ö±âÀÇ µµ±¸-¿É¼Ç¿¡¼ °ü·ÃºÎºÐÀ» üũÇؼ È®ÀÎÇÏÁö ¾Ê´Â ÀÌ»ó »ý¼ºµÇ´Â ·çƮŶ Ȩ µð·ºÅ͸®¸¦ ã±â°¡ ½±Áö ¾Ê´Ù.
»ý¼ºµÇ´Â µð·ºÅ͸® ¸í : "C:\Recycler\S-1-5-21-3127994617-2291869382-1739915505-1006\_restore{DIWJDS7S-C329-32 42-91EC-D2SD72C70D82}\¡°
¨è move C:\recycler\msprexe.exe "C:\Recycler\S-1-5-21-3127...\_restore.." ¸ðµç ÇÁ·Î±×·¥ ¹× ÆÄÀϵéÀ» ¾Õ¼ »ý¼ºÇÑ ·çƮŶ Ȩ µð·ºÅ͸®·Î À̵¿½ÃŲ´Ù.
¨é C:\recycler\dtreg.exe -AddKey "\HKLM\SOFTWARE\Sublime Solutions\TaskDaemon" ·¹Áö½ºÆ®¸®¸¦ µî·ÏÇÏ´Â dtreg.exe ÇÁ·Î±×·¥À» ÀÌ¿ëÇؼ taskdaemon ÇÁ·Î±×·¥À» ·¹Áö½ºÆ®¸®¿¡ µî·Ï ½ÃŲ´Ù.
¨ê taskdaemon.exe -i DirIndex.xml taskdaemon.exe -i ProfileMgr.xml ¼ºñ½º µî·Ï ÇÁ·Î±×·¥ÀÎ taskdaemonÀ» ÀÌ¿ë logongui.exe¸¦ DirIndex ¼ºñ½º¸íÀ¸·Î µî·ÏÇÏ°í msprexe.exe¸¦ ProfileMgr ¼ºñ½º¸íÀ¸·Î µî·Ï ÇÑ´Ù.
¨ë C:\recycler\control.exe control.exe ½ÇÇà
4] control.exe Á¶»ç
Ư¡Àº ´ÙÀ½°ú °°´Ù. - ¾ÐÃà : PECompact 2.x - ±â´É : ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ½ÇÇàÇÏ´Â ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÏ°í ½ÇÇà - °ü·ÃÆÄÀÏ : C:\Documents~1\kisa\Locals~1\Temp\bt4607.bat control.exe ¹ÙÀ̳ʸ®¸¦ µð¹ö°Å¸¦ ÅëÇÏ¿© È®ÀÎÇÑ °á°ú
c:\Documents~1\kisa\Locals~1\Temp\bt4607.bat ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ¶ÇÇÑ ¾Æ·¡ ±×¸²°°ÀÌ CreateProcessÇÔ¼ö·Î cmd ¸í·É¾î¸¦ ÀÌ¿ë bt4607.bat ÆÄÀÏÀ» ½ÇÇàÇÑ´Ù. (±×¸² 5) bt4607.bat ½ÇÇà
bt4607.bat ÆÄÀÏÀÇ ½ºÅ©¸³Æ®´Â ´ÙÀ½°ú °°Àº ¼ø¼·Î ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¼øÂ÷ÀûÀ¸·Î ½Ã½ºÅÛ¿¡ µî·Ï ¹× ½ÇÇàÇÏ°Ô µÈ´Ù.
¨ç move C:\recycler\config.exe "C:\Recycler\S-1-5-21-3127...\_restore.." move C:\recycler\control.exe "C:\Recycler\S-1-5-21-3127...\_restore.." ·çƮŶ ÇÁ·Î±×·¥µéÀ» ¼¼ÆÃÇÏ°í ½ÇÇàÇß´ø config¿Í control ÆÄÀÏÀ» ·çƮŶ Ȩµð·ºÅ͸®·Î À̵¿ ½ÃŲ´Ù.
¨è rename control.exe system.ocx rename config.exe settings.ocx 2°³ÀÇ ·çƮŶ Á¦¾î ÇÁ·Î±×·¥ ÆÄÀϸíÀ» º¯°æÇØ ³õ´Â´Ù.
¨é attrib +s +h C:\Recycler\* /S /D °ü¸®ÀÚ ´«¿¡ ½±°Ô ¶çÁö ¾Êµµ·Ï µð·ºÅ͸®¿Í ÆÄÀÏµé ¼Ó¼ºÀ» ¼û±è(Hidden)/½Ã½ºÅÛ(System)À¸·Î º¯°æÇÑ´Ù.
¨ê NetSec.exe Ä¿³Î ·çƮŶ ¸ðµâÀ» ·ÎµùÇÏ°í Á¦¾îÇÏ´Â ÇÁ·Î±×·¥ ½ÇÇà (ÀÚ¼¼ÇÑ ³»¿ëÀº NetSec.exe¿¡¼ ¼³¸í)
¨ë net start ProfileMgr net start DirIndex logongui.exe, msprexe.exe¸¦ ½ÇÇàÇÏ´Â ¼ºñ½º¸¦ ½ÃÀÛÇÑ´Ù.
¨ì fclear.exe all ÇöÀç±îÁö ¹ß»ýÇß´ø À̺¥Æ® ·Î±×¸¦ ¸ðµÎ »èÁ¦ ÇÑ´Ù.
5) NetSec.exe Á¶»ç
Ư¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : PECompact 2.x - ±â´É : Ä¿³Î ·çƮŶ ¸ðµâ ·Îµù ¹× Á¦¾î, ¼ºñ½º µî·Ï, ·¹Áö½ºÆ®¸® µî·Ï - °ü·ÃÆÄÀÏ : netsec.sys
NetSec ÇÁ·Î±×·¥Àº º¿ C&C ¼¹ö°¡ »ç¿ëÇÏ´Â Æ÷Æ®¸¦ Ŭ¶óÀ̾ðÆ®µéÀÌ Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï ¾Æ·¡¿Í °°Àº netsh firewall ¸í·É¾î¸¦ ÅëÇØ ¹æȺ®À» ¿ÀÇÂÇÑ´Ù. "%cmd%?/c netsh firewall add portopening protocol = TCP port = 27397 name = "Automatic Updates" mode = ENABLE scope = ALL profile = ALL" ÀÌ ÈÄ NetSecManager¶ó´Â ¼ºñ½º µî·ÏÀ» À§ÇØ °ü·ÃµÈ ·¹Áö½ºÆ®¸® µî·ÏÀ» ÇÏ°í ¾Æ·¡ ±×¸²Ã³·³ CreateService ÇÔ¼ö¸¦ ÅëÇØ NetSec.exe¸¦ ½ÇÇàÇÏ´Â NetSecManager ¼ºñ½º¸¦ µî·ÏÇÑ´Ù.
(±×¸² 6) NetSecManager ¼ºñ½º µî·Ï
¼ºñ½º µî·Ï ÈÄ °ð ¹Ù·Î StartService ÇÔ¼ö¸¦ ÅëÇØ NetSecManager ¼ºñ½º¸¦ ½ÇÇàÇØ NetSec.exe¸¦ ´Ù½Ã ½ÇÇàÇÏ°Ô µÈ´Ù. NetSec.sys ¸ðµâÀ» »ý¼ºÇØ Ä¿³Î¿¡ ·ÎµùÇÏ°í ¾Æ·¡¿Í °°Àº ·¹Áö½ºÆ®¸®¿¡ sys ÆÄÀÏÀ» µî·ÏÇÑ´Ù.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetSecDriver
Ä¿³Î ·çƮŶÀº API ÇÔ¼öµéÀ» ÈÄÅ·ÇÏ¿© ¿øÇÏ´Â ÆÄÀÏ/ÇÁ·Î¼¼½º/³×Æ®¿öÅ© Á¤º¸µéÀ» °¨Ãß°Ô µÇ´Âµ¥ µð¹ö±ëÀ» ÅëÇØ ´ÙÀ½°ú °°Àº ¹®ÀÚ¿À» Á¤º¸µéÀ» È®ÀÎÇÒ ¼ö ÀÖ¾ú´Ù. ÇÏÁö¸¸ ÀÎÄÚµùµÇ¾î ÀúÀåµÇ¾î ÀÖ´Â ¹®ÀÚ¿ Á¤º¸µéÀÌ ÀÖ¾î ¼û°ÜÁø ¹®ÀÚ¿µéÀº ´õ ¸¹À» °ÍÀ¸·Î ¿¹»óÇÒ ¼ö ÀÖ´Ù.
6) taskdaemon.exe Á¶»ç
Ư¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : PECompact 2.x - ±â´É : xmlÀ» ÀÌ¿ëÇÑ ¼ºñ½º µî·Ï ÇÁ·Î±×·¥ - °ü·ÃÆÄÀÏ : taskdaemonrt.dll libxml2.dll taskdaemon.dtd DirIndex.xml ProfileMgr.xml
taskdaemonÀº xmlÀ» ÀÌ¿ëÇØ ¼ºñ½º¸¦ µî·ÏÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. bt0312.bat ¹èÄ¡ ½ºÅ©¸³Æ®¿¡¼ ¼öÇàÇÏ´Â ¸í·É¾î¸¦ È®ÀÎÇغ¸¸é
taskdaemon.exe -i DirIndex.xml
¸í·É¾î·Î -i ÀνºÅç ¿É¼ÇÀ» ÅëÇؼ ¾Æ·¡ DirIndex.xml, ProfileMgr.xml¿¡ Á¤ÀǵǾî ÀÖ´Â logongui.exe, msprexe.exe ÇÁ·Î±×·¥À» ½ÇÇàÇÏ´Â ¼ºñ½º¸¦ µî·Ï ½ÃŲ´Ù. ½ÇÇà¸ðµå¸¦ ¡°Automatic"À¸·Î ¼³Á¤ÇØ ½Ã½ºÅÛÀÌ ÀçºÎÆà µÇ´õ¶óµµ Àç½ÃÀÛ µÇµµ·Ï ¼³Á¤ÇÑ´Ù.
- DirIndex.xml ¼ºñ½º¸í : DirIndex ½ÇÇàÇÁ·Î±×·¥ : logongui.exe ½ÇÇà¸ðµå : "Automatic"
- ProfileMgr.xml ³»¿ë ¼ºñ½º¸í : ProfileMgr ½ÇÇàÇÁ·Î±×·¥ : msprexe.exe ½ÇÇà¸ðµå : "Automatic"
8) logingui.exe Á¶»ç
Ư¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : ¾øÀ½ - ±â´É : ServU FTP ¼¹ö ÇÁ·Î±×·¥, 43958 Æ÷Æ®¸¦ ÅëÇØ ¼ºñ½º - °ü·ÃÆÄÀÏ :
libeay32.dll ssleay32.dll wbemup32.dll wmspdscore.dll winservices.dll (¼³Á¤ÆÄÀÏ) WindowsStartFnc.dll (·Î±×ÆÄÀÏ)
logongui.exe ÇÁ·Î±×·¥Àº Æ÷Æ® 43958¹øÀ» ÀÌ¿ëÇÑ ServU FTP ¼¹ö ÇÁ·Î±×·¥ÀÌ´Ù. À§ÀÇ °ü·ÃÆÄÀÏ¿¡¼ libeay32.dll, ssleay32.dllÀ» Á¦¿ÜÇÑ ³ª¸ÓÁö DLLÆÄÀϵéÀº ½ÇÁ¦ ¶óÀ̺귯¸® ÆÄÀÏÀÌ ¾Æ´Ï°í ÀÏ¹Ý ÅؽºÆ® ÆÄÀÏÀ» È®ÀåÀÚ¸¸ dll·Î »ý¼º½ÃÄÑ ³õÀº °Íµé ÀÌ´Ù. winservices.dll ÆÄÀÏÀº ftp ȯ°æ¼³Á¤ ÆÄÀÏÀÌ°í WindowsStartFnc.dllÀº ·Î±× ÆÄÀÏÀÌ´Ù. ³ª¸ÓÁö 2°³ ÆÄÀÏÀº ¾ÏÈ£È Å° µî·Ï ÆÄÀϵéÀÌ´Ù.
- winservices.dll
- WindowsStartFnc.dll
9) msprexe.exe Á¶»ç
Ư¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : UPX 0.89.6 - 1.02 - ±â´É : iroffer ÇÁ·Î±×·¥ , IRC »ç¿ëÀڵ鿡°Ô ÆÄÀÏ Á¦°ø ¹× µ¥ÀÌÅÍ Àü¼Û - °ü·ÃÆÄÀÏ : cygcrypt-0.dll cygwin1.dll MSVCP60.dll dhtml.c.dll (»óÅÂ·Î±× ÆÄÀÏ) winhlp.dll (ȯ°æ¼³Á¤ ÆÄÀÏ)
msprexe.exe´Â iroffer ÇÁ·Î±×·¥¸íÀ» º¯°æÇÑ ¹ÙÀ̳ʸ®·Î TCP/UDP Æ÷Æ®¸¦ ÀÌ¿ëÇؼ IRC Ŭ¶óÀ̾ðÆ®µé¿¡°Ô µ¥ÀÌÅ͸¦ Á¦°øÇØÁØ´Ù. msprexe.exe ÇÁ·Î±×·¥À» ½ÇÇàÇϸé winhlp.dll ÆÄÀÏÀÌ »ý¼ºµÇ°í ÀÌ ÆÄÀÏÀº DLL°ú »ó°ü¾ø´Â iroffer ·Î±× ÆÄÀÏÀÌ´Ù. ½ÇÇà µÈ ÈÄ dhtml.c.dll ȯ°æ ¼³Á¤ÆÄÀÏÀ» ÅëÇØ IRC ¼¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÏ°í Á¢¼ÓÀÌ µÇ¸é °ü·ÃµÈ ¼¼Æà °ªÀ¸·Î ä³Î¿¡ µî·ÏÇÑ´Ù.
- winhlp.dll
¶Ç ÇϳªÀÇ DLL ÆÄÀÏÀÌ Á¸ÀçÇϴµ¥ dhtml.c.dllÀº ȯ°æ¼³Á¤ ÆÄÀÏ·Î ¼¼Æÿ¡ ÇÊ¿äÇÑ Á¤º¸µéÀÌ Á¸ÀçÇÑ´Ù.
- dhtml.c.dll
9) fclear.exe, dtreg.exe Á¶»ç
flcear.exe - ¾ÐÃà : UPX 0.89.6 - 1.02 / 1.05 - 1.24 - ±â´É : À̺¥Æ® ·Î±× »èÁ¦ ÇÁ·Î±×·¥
fclear.exe´Â ClearEventLog ÇÁ·Î±×·¥ ¸íÀ» º¯°æÇÑ ¹ÙÀ̳ʸ®·Î À̺¥Æ® ·Î±×¸¦ »èÁ¦Çϴµ¥ »ç¿ëµÈ´Ù. all ¿É¼ÇÀ» ÅëÇØ ¸ðµç ·Î±×¸¦ Á¦°ÅÇϸç fclear¸¦ ¿É¼Ç ¾øÀÌ ½ÇÇàÇÑ È¸éÀº ¾Æ·¡¿Í °°´Ù.
(±×¸² 7) fclar.exe ½ÇÇàȸé
?dtreg.exe
- ¾ÐÃà : PECompact 2.x - ±â´É : ·¹Áö½ºÆ®¸® µî·Ï ÇÁ·Î±×·¥
TaskDaemon ÇÁ·Î±×·¥À» ·¹Áö½ºÆ®¸®¿¡ µî·ÏÇϴµ¥ »ç¿ëµÇ¸ç ÀÌ ÈÄ ¹Ù·Î »èÁ¦µÈ´Ù.
3. °á·Ð ¹× ´ëÃ¥
Á¶»ç°á°ú 1.exe´Â ÇÇÇؽýºÅÛ¿¡ ¼³Ä¡ÇÒ ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¼û±â±â À§ÇØ ½Ã½ºÅÛ Æú ´õÀÎ C:\RECYLER Æú´õ ÇÏÀ§¿¡ ½ÇÁ¦ À̸§°ú À¯»çÇÑ ½Ã½ºÅÛ Æú´õ¸¦ »ý¼º ÇÏ¿´°í ÀÌ ÈÄ °ü·Ã ¾Ç¼ºÇÁ·Î±×·¥µéÀ» ±× Æú´õ·Î ¾ÐÃàÇØÁ¦ ½ÃŲ ÈÄ Çϳª¾¿ ¾Ç¼ºÇÁ·Î±×·¥µéÀ» ½ÇÇàÇÏ¿´´Ù. ½ÇÇàµÈ ¾Ç¼º ÇÁ·Î±×·¥µéÀº ÀڽŵéÀÇ È¨ µð·ºÅ͸® ¹× Æ÷Æ®, º¿ C&C ÇÁ·Î±×·¥, IRC Ŭ¶óÀ̾ðÆ® ÇÁ·Î±×·¥ µîÀÇ Á¤º¸¸¦ ¼û°Ü °ü¸®ÀÚ°¡ ½±°Ô ¹ß°ßÇÏÁö ¸øÇϵµ·Ï ÇÏ¿´´Ù. 1.exe ·çƮŶ ÇÁ·Î±×·¥À» ŽÁö¸¦ ¸øÇÏ´Â ¹é½Å Á¦Ç°µéÀÌ ÀÖ¾î ¼¹ö°ü¸®ÀÚµéÀÌ ¾Ç¼ºÇÁ·Î±×·¥µéÀÇ ¼³Ä¡ ¿©ºÎ¸¦ È®ÀÎÇÏÁö ¸øÇÏ°í ÀÖ¾ú´Ù. ÀÌ ÈÄ À©µµ¿ì XP ½Ã½ºÅÛ¿¡¼µµ 1.exe º¯Á¾ÀÎ esyp4.exe¸¦ ¹ß°ßÇßÁö¸¸ À̸§¸¸ º¯°æµÇ¾úÀ» »Ó ¶È °°Àº ±â´ÉÀ» ÇÏ ¿´´Ù. Ä¿³Î ·çƮŶ ½ÇÇàÀ¸·Î °ü·Ã ·çƮŶ ÇÁ·Î±×·¥ Á¤º¸µéÀ» ã¾Æ³»±â°¡ ½±Áö°¡ ¾Ê±â ¶§¹®¿¡ °ø°³¿ë Ä¿³Î ·çƮŶ ŽÁö ÇÁ·Î±×·¥ÀÎ IceSword µµ±¸¸¦ ÀÌ¿ëÇØ °ü·Ã ÇÁ·Î±×·¥µéÀÇ È¨ µð·ºÅ͸®, ÇÁ·Î¼¼½º, Æ÷Æ®Á¤º¸, ¼ºñ½º, ·¹Áö½ºÆ®¸®¸¦ ã¾Æ³»¼ ¸ðµÎ Á¦°ÅÇØ ÁÖ¾î¾ß ÇÑ´Ù. ¾Æ·¡ ±×¸²Àº Ä¿³Î ·çƮŶ ½ÇÇà ¼ºñ½ºÀÎ NetSecManger¸¦ ãÀº ÈÄ ¼ºñ½º ÁßÁö ¹× Á¦°ÅÇØ Áִ ȸéÀÌ´Ù.
(±×¸² 8) Ä¿³Î ·çƮŶ Á¦°Å
·çƮŶ 1.exe°¡ ¼³Ä¡µÈ º¿C&C¼¹ö ÇÇÇؽýºÅÛµéÀº °ü¸®ÀÚµéÀÌ ¼ÒȦÇϱ⠽¬¿î °³¹ß¿ë ¼¹ö³ª ÀÚÁÖ ÀÌ¿ëÇÏÁö ¾Ê´Â ½Ã½ºÅÛÀ¸·Î º¸¾ÈÆÐÄ¡ÀÇ ¹ÌÀû¿ë, ¼¹ö ¾È¼³Á¤ ¹Ì½Ç½Ã µîÀ¸·Î ÀÎÇØ ÇÇÇظ¦ ÀÔ¾ú´Ù. ¶ÇÇÑ, ÀÚÁÖ »ç¿ëÇÏÁö ¾Ê´Ù º¸´Ï ½Ã½ºÅÛÀÌ ¾Ç¿ëÀÌ µÇ°í ÀÖ´Â »óÅ¿¡¼µµ À̸¦ ½±°Ô ¹ß°ßÇÏÁö ¸øÇÏ¿´´Ù. ½Ã½ºÅÛ ´ã´çÀÚµéÀº º» »ç°í»ç·Ê¿Í °°Àº ÇÇÇظ¦ ÁÙÀ̱â À§ÇØ À©µµ¿ì ÀÚµ¿¾÷µ¥ÀÌÆ® ±â´ÉÀ» ¹Ýµå½Ã »ç¿ëÇÒ °ÍÀ» ±ÇÀåÇϸç, ƯÈ÷ °ü¸®ÀÇ ¼ÕÀÌ ¹ÌÄ¡Áö ¾ÊÀº¹æÄ¡µÈ ½Ã½ºÅÛÀÌ ¾ø´Â Áö È®ÀÎÇÒ ÇÊ¿ä°¡ ÀÖ´Ù.
[ÀÚ·á: Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA)]
|
|