Home | Data Center | Contact US | Login

Á¦¸ñ À©µµ¿ìÁî ·çƮŶ Á¶»ç»ç·Ê
÷ºÎÆÄÀÏ IN2007001.pdf ÀÛ¼ºÀÏ 2007-04-27 09:53:00

À©µµ¿ìÁî ·çƮŶ Á¶»ç»ç·Ê

1. °³¿ä
ÃÖ±Ù À©µµ¿ìÁî ÇØÅ·µ¿ÇâÀº °ø°Ý¿¡ ¼º°øÇÑ ÈÄ ½Ã½ºÅÛ¿¡ ´Ù¿î·Îµå µÈ ¾Ç¼ºÇÁ·Î±×·¥ (Bot, ¹éµµ¾î µî) ÆÄÀÏ ¹× ½ÇÇàµÈ ¾Ç¼º ³×Æ®¿öÅ©/ÇÁ·Î¼¼½º Á¤º¸¸¦ ¼û±â±â À§ÇØ ·çƮŶ ÀÌ ¿¬µ¿µÇ°í ÀÖ´Ù.
Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(ÀÌÇÏ ¡°KISA¡±)Àº ±¹³» º¿C&C¼­¹ö È°µ¿À» ŽÁöÇÏ´ø Áß µ¿ÀÏÇÑ ÆÐÅÏÀ» ³ªÅ¸³»´Â ½Ã½ºÅÛÀ» ¿©·µ °¨ÁöÇÏ¿´´Ù. ¼­¹öµéÀ» ºÐ¼®ÇÑ °á°ú µ¿ÀÏÇÑ Áõ»óÀ» º¸¿´°í 1.exe(À©µµ¿ì 2000)¶ó´Â ÇÁ·Î±×·¥À» ÅëÇØ µ¥ÀÌÅÍ ´Ù¿î·Î´õ, Ä¿³Î ·çƮŶ, ¼­ºñ½º µî·Ï °ü·Ã ÇÁ·Î±×·¥ÀÌ ½ÇÇàµÇ´Â °ÍÀ¸·Î È®ÀÎÀÌ µÇ¾ú´Ù.
º»°í¿¡¼­´Â À̹ø¿¡ ¹ß°ßÇÑ 1.exe ·çƮŶ ÇÁ·Î±×·¥ÀÇ Æ¯Â¡°ú Á¶»ç ³»¿ëÀ» Á¤¸®ÇÏ¿´´Ù.

2. ·çƮŶ Á¶»ç

1) Àüü °³¿ä

1.exe ½ÇÇà ¼ø¼­¸¦ Á¾ÇÕ ±¸¼ºÇØ º¸¸é ¾Æ·¡¿Í °°´Ù.

(±×¸² 1) Àüü °³¿äµµ

2) 1.exe Á¶»ç

ù ¹ø°·Î Á¶»çÇÑ 1.exeÀÇ Æ¯Â¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : "instyler ex-it! Self-Extractor"
- ±â´É :
RECYCLER µð·ºÅ͸®¿¡ °ü·ÃÆÄÀÏµé ¾ÐÃàÇØÁ¦
config.exe¸¦ ½ÇÇàÇÏ¿© ¾Ç¼º ÇÁ·Î±×·¥ ¼¼Æà ¹× ½ÇÇà
- °ü·Ã ÆÄÀÏ :
±×¸² 2 1.exeÀÇ ¾ÐÃàÇØÁ¦ ÂüÁ¶

1.exe ¹ÙÀ̳ʸ®´Â ¸ðµç ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¾ÐÃàµÈ ÇüÅ·ΠÁö´Ï°í ÀÖ°í ¾ÐÃà ÇØÁ¦ ÈÄ config.exe¸¦ ÅëÇÏ¿© ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ½Ã½ºÅÛ¿¡ µî·Ï/½ÇÇà ÇÏ°Ô µÈ´Ù.
C:\RECYCLER ´Â °ü¸®°¡ ¼ÒȦÇÏ°í µð·ºÅ͸® ¼Ó¼ºÀÌ µðÆúÆ®·Î ¿î¿µÃ¼Á¦ ÆÄÀÏ·ÎÁöÁ¤ µÇ¾î ÀÖ¾î °ü¸®ÀÚÀÇ ´«À» ÇÇÇÒ ¼ö ÀÖ´Ù. ¾Æ·¡ ±×¸²°ú °°ÀÌ C:\RECYCLER¿¡ °ü·Ã
ÆÄÀϵéÀ» ¾ÐÃàÇØÁ¦ ÇÑ´Ù.


(±×¸² 2) 1.exeÀÇ ¾ÐÃàÇØÁ¦

°ü·Ã ÆÄÀÏµé ¾ÐÃàÇØÁ¦°¡ ³¡³ª¸é ShellExecute ÇÔ¼ö¸¦ ÅëÇØ ¾Æ·¡ ±×¸²°ú °°ÀÌ config.exe¸¦ ½ÇÇàÇÏ°Ô µÈ´Ù.


(±×¸² 3) config.exe ½ÇÇà

3) config.exe Á¶»ç

config.exe Ư¡Àº ´ÙÀ½°ú °°´Ù.

- ¾ÐÃà : ¾øÀ½
- ±â´É : ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ½ÇÇàÇÏ´Â ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÏ°í ½ÇÇà
- °ü·ÃÆÄÀÏ : c:\Documents~1\kisa\Locals~1\Temp\bt0312.bat

config.exe ¹ÙÀ̳ʸ®¸¦ µð¹ö°Å¸¦ ÅëÇÏ¿© È®ÀÎÇÑ °á°ú
c:\Documents~1\kisa\Locals~1\Temp\bt0312.bat ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ¶ÇÇÑ ¾Æ·¡ ±×¸²°ú °°ÀÌ CreateProcessÇÔ¼ö·Î cmd ¸í·É¾î¸¦ ÀÌ¿ë bt0312.bat ÆÄÀÏÀ» ½ÇÇàÇÑ´Ù.


(±×¸² 4) bt0312.bat ½ÇÇà

bt0312.bat ÆÄÀÏÀÇ ½ºÅ©¸³Æ®´Â ´ÙÀ½°ú °°Àº ¼ø¼­·Î ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¼øÂ÷ÀûÀ¸·Î ½Ã½ºÅÛ¿¡ µî·Ï ¹× ½ÇÇàÇÏ°Ô µÈ´Ù.

¨ç mkdir "C:\Recycler\S-1-5-21-3127...\_restore.."
¡°C:\Recycler¡°´Â º¸È£µÇ´Â ¿î¿µÃ¼Á¦ µð·ºÅ͸®·Î Ž»ö±âÀÇ µµ±¸-¿É¼Ç¿¡¼­ °ü·ÃºÎºÐÀ» üũÇؼ­ È®ÀÎÇÏÁö ¾Ê´Â ÀÌ»ó »ý¼ºµÇ´Â ·çƮŶ Ȩ µð·ºÅ͸®¸¦ ã±â°¡ ½±Áö ¾Ê´Ù.

»ý¼ºµÇ´Â µð·ºÅ͸® ¸í :
"C:\Recycler\S-1-5-21-3127994617-2291869382-1739915505-1006\_restore{DIWJDS7S-C329-32
42-91EC-D2SD72C70D82}\¡°

¨è move C:\recycler\msprexe.exe "C:\Recycler\S-1-5-21-3127...\_restore.." ¸ðµç ÇÁ·Î±×·¥ ¹× ÆÄÀϵéÀ» ¾Õ¼­ »ý¼ºÇÑ ·çƮŶ Ȩ µð·ºÅ͸®·Î À̵¿½ÃŲ´Ù.

¨é C:\recycler\dtreg.exe -AddKey "\HKLM\SOFTWARE\Sublime Solutions\TaskDaemon" ·¹Áö½ºÆ®¸®¸¦ µî·ÏÇÏ´Â dtreg.exe ÇÁ·Î±×·¥À» ÀÌ¿ëÇؼ­ taskdaemon ÇÁ·Î±×·¥À» ·¹Áö½ºÆ®¸®¿¡ µî·Ï ½ÃŲ´Ù.

¨ê taskdaemon.exe -i DirIndex.xml
taskdaemon.exe -i ProfileMgr.xml ¼­ºñ½º µî·Ï ÇÁ·Î±×·¥ÀÎ taskdaemonÀ» ÀÌ¿ë logongui.exe¸¦ DirIndex ¼­ºñ½º¸íÀ¸·Î µî·ÏÇÏ°í msprexe.exe¸¦ ProfileMgr ¼­ºñ½º¸íÀ¸·Î µî·Ï ÇÑ´Ù.

¨ë C:\recycler\control.exe
control.exe ½ÇÇà

4] control.exe Á¶»ç

Ư¡Àº ´ÙÀ½°ú °°´Ù.
- ¾ÐÃà : PECompact 2.x
- ±â´É : ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ½ÇÇàÇÏ´Â ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÏ°í ½ÇÇà
- °ü·ÃÆÄÀÏ : C:\Documents~1\kisa\Locals~1\Temp\bt4607.bat control.exe ¹ÙÀ̳ʸ®¸¦ µð¹ö°Å¸¦ ÅëÇÏ¿© È®ÀÎÇÑ °á°ú

c:\Documents~1\kisa\Locals~1\Temp\bt4607.bat ¹èÄ¡ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ¶ÇÇÑ ¾Æ·¡ ±×¸²°°ÀÌ CreateProcessÇÔ¼ö·Î cmd ¸í·É¾î¸¦ ÀÌ¿ë bt4607.bat ÆÄÀÏÀ» ½ÇÇàÇÑ´Ù.
 
(±×¸² 5) bt4607.bat ½ÇÇà

bt4607.bat ÆÄÀÏÀÇ ½ºÅ©¸³Æ®´Â ´ÙÀ½°ú °°Àº ¼ø¼­·Î ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¼øÂ÷ÀûÀ¸·Î ½Ã½ºÅÛ¿¡ µî·Ï ¹× ½ÇÇàÇÏ°Ô µÈ´Ù.

¨ç move C:\recycler\config.exe "C:\Recycler\S-1-5-21-3127...\_restore.." move C:\recycler\control.exe "C:\Recycler\S-1-5-21-3127...\_restore.."
·çƮŶ ÇÁ·Î±×·¥µéÀ» ¼¼ÆÃÇÏ°í ½ÇÇàÇß´ø config¿Í control ÆÄÀÏÀ» ·çƮŶ Ȩµð·ºÅ͸®·Î À̵¿ ½ÃŲ´Ù.

¨è rename control.exe system.ocx
rename config.exe settings.ocx
2°³ÀÇ ·çƮŶ Á¦¾î ÇÁ·Î±×·¥ ÆÄÀϸíÀ» º¯°æÇØ ³õ´Â´Ù.

¨é attrib +s +h C:\Recycler\* /S /D
°ü¸®ÀÚ ´«¿¡ ½±°Ô ¶çÁö ¾Êµµ·Ï µð·ºÅ͸®¿Í ÆÄÀÏµé ¼Ó¼ºÀ» ¼û±è(Hidden)/½Ã½ºÅÛ(System)À¸·Î º¯°æÇÑ´Ù.

¨ê NetSec.exe
Ä¿³Î ·çƮŶ ¸ðµâÀ» ·ÎµùÇÏ°í Á¦¾îÇÏ´Â ÇÁ·Î±×·¥ ½ÇÇà (ÀÚ¼¼ÇÑ ³»¿ëÀº NetSec.exe¿¡¼­ ¼³¸í)

¨ë net start ProfileMgr
net start DirIndex
logongui.exe, msprexe.exe¸¦ ½ÇÇàÇÏ´Â ¼­ºñ½º¸¦ ½ÃÀÛÇÑ´Ù.

¨ì fclear.exe all
ÇöÀç±îÁö ¹ß»ýÇß´ø À̺¥Æ® ·Î±×¸¦ ¸ðµÎ »èÁ¦ ÇÑ´Ù.

5) NetSec.exe Á¶»ç

Ư¡Àº ´ÙÀ½°ú °°´Ù.

- ¾ÐÃà : PECompact 2.x
- ±â´É : Ä¿³Î ·çƮŶ ¸ðµâ ·Îµù ¹× Á¦¾î, ¼­ºñ½º µî·Ï, ·¹Áö½ºÆ®¸® µî·Ï
- °ü·ÃÆÄÀÏ : netsec.sys

NetSec ÇÁ·Î±×·¥Àº º¿ C&C ¼­¹ö°¡ »ç¿ëÇÏ´Â Æ÷Æ®¸¦ Ŭ¶óÀ̾ðÆ®µéÀÌ Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï ¾Æ·¡¿Í °°Àº netsh firewall ¸í·É¾î¸¦ ÅëÇØ ¹æÈ­º®À» ¿ÀÇÂÇÑ´Ù.
"%cmd%?/c netsh firewall add portopening protocol = TCP port = 27397 name =
"Automatic Updates" mode = ENABLE scope = ALL profile = ALL"
ÀÌ ÈÄ NetSecManager¶ó´Â ¼­ºñ½º µî·ÏÀ» À§ÇØ °ü·ÃµÈ ·¹Áö½ºÆ®¸® µî·ÏÀ» ÇÏ°í ¾Æ·¡ ±×¸²Ã³·³ CreateService ÇÔ¼ö¸¦ ÅëÇØ NetSec.exe¸¦ ½ÇÇàÇÏ´Â NetSecManager ¼­ºñ½º¸¦ µî·ÏÇÑ´Ù.


(±×¸² 6) NetSecManager ¼­ºñ½º µî·Ï

¼­ºñ½º µî·Ï ÈÄ °ð ¹Ù·Î StartService ÇÔ¼ö¸¦ ÅëÇØ NetSecManager ¼­ºñ½º¸¦ ½ÇÇàÇØ NetSec.exe¸¦ ´Ù½Ã ½ÇÇàÇÏ°Ô µÈ´Ù. NetSec.sys ¸ðµâÀ» »ý¼ºÇØ Ä¿³Î¿¡ ·ÎµùÇÏ°í ¾Æ·¡¿Í °°Àº ·¹Áö½ºÆ®¸®¿¡ sys ÆÄÀÏÀ» µî·ÏÇÑ´Ù.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetSecDriver

Ä¿³Î ·çƮŶÀº API ÇÔ¼öµéÀ» ÈÄÅ·ÇÏ¿© ¿øÇÏ´Â ÆÄÀÏ/ÇÁ·Î¼¼½º/³×Æ®¿öÅ© Á¤º¸µéÀ» °¨Ãß°Ô µÇ´Âµ¥ µð¹ö±ëÀ» ÅëÇØ ´ÙÀ½°ú °°Àº ¹®ÀÚ¿­À» Á¤º¸µéÀ» È®ÀÎÇÒ ¼ö ÀÖ¾ú´Ù. ÇÏÁö¸¸ ÀÎÄÚµùµÇ¾î ÀúÀåµÇ¾î ÀÖ´Â ¹®ÀÚ¿­ Á¤º¸µéÀÌ ÀÖ¾î ¼û°ÜÁø ¹®ÀÚ¿­µéÀº ´õ ¸¹À» °ÍÀ¸·Î ¿¹»óÇÒ ¼ö ÀÖ´Ù.


6) taskdaemon.exe Á¶»ç

Ư¡Àº ´ÙÀ½°ú °°´Ù.

- ¾ÐÃà : PECompact 2.x
- ±â´É : xmlÀ» ÀÌ¿ëÇÑ ¼­ºñ½º µî·Ï ÇÁ·Î±×·¥
- °ü·ÃÆÄÀÏ :
taskdaemonrt.dll
libxml2.dll
taskdaemon.dtd
DirIndex.xml
ProfileMgr.xml

taskdaemonÀº xmlÀ» ÀÌ¿ëÇØ ¼­ºñ½º¸¦ µî·ÏÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. bt0312.bat ¹èÄ¡ ½ºÅ©¸³Æ®¿¡¼­ ¼öÇàÇÏ´Â ¸í·É¾î¸¦ È®ÀÎÇغ¸¸é

taskdaemon.exe -i DirIndex.xml

¸í·É¾î·Î -i ÀνºÅç ¿É¼ÇÀ» ÅëÇؼ­ ¾Æ·¡ DirIndex.xml, ProfileMgr.xml¿¡ Á¤ÀǵǾî ÀÖ´Â logongui.exe, msprexe.exe ÇÁ·Î±×·¥À» ½ÇÇàÇÏ´Â ¼­ºñ½º¸¦ µî·Ï ½ÃŲ´Ù. ½ÇÇà¸ðµå¸¦ ¡°Automatic"À¸·Î ¼³Á¤ÇØ ½Ã½ºÅÛÀÌ ÀçºÎÆà µÇ´õ¶óµµ Àç½ÃÀÛ µÇµµ·Ï ¼³Á¤ÇÑ´Ù.

- DirIndex.xml
  ¼­ºñ½º¸í : DirIndex
  ½ÇÇàÇÁ·Î±×·¥ : logongui.exe
  ½ÇÇà¸ðµå : "Automatic"


- ProfileMgr.xml ³»¿ë
  ¼­ºñ½º¸í : ProfileMgr
  ½ÇÇàÇÁ·Î±×·¥ : msprexe.exe
  ½ÇÇà¸ðµå : "Automatic"


8) logingui.exe Á¶»ç

Ư¡Àº ´ÙÀ½°ú °°´Ù.

- ¾ÐÃà : ¾øÀ½
- ±â´É : ServU FTP ¼­¹ö ÇÁ·Î±×·¥, 43958 Æ÷Æ®¸¦ ÅëÇØ ¼­ºñ½º
- °ü·ÃÆÄÀÏ :

libeay32.dll
ssleay32.dll
wbemup32.dll
wmspdscore.dll
winservices.dll (¼³Á¤ÆÄÀÏ)
WindowsStartFnc.dll (·Î±×ÆÄÀÏ)

logongui.exe ÇÁ·Î±×·¥Àº Æ÷Æ® 43958¹øÀ» ÀÌ¿ëÇÑ ServU FTP ¼­¹ö ÇÁ·Î±×·¥ÀÌ´Ù.
À§ÀÇ °ü·ÃÆÄÀÏ¿¡¼­ libeay32.dll, ssleay32.dllÀ» Á¦¿ÜÇÑ ³ª¸ÓÁö DLLÆÄÀϵéÀº ½ÇÁ¦ ¶óÀ̺귯¸® ÆÄÀÏÀÌ ¾Æ´Ï°í ÀÏ¹Ý ÅؽºÆ® ÆÄÀÏÀ» È®ÀåÀÚ¸¸ dll·Î »ý¼º½ÃÄÑ ³õÀº °Íµé ÀÌ´Ù. winservices.dll ÆÄÀÏÀº ftp ȯ°æ¼³Á¤ ÆÄÀÏÀÌ°í WindowsStartFnc.dllÀº ·Î±× ÆÄÀÏÀÌ´Ù. ³ª¸ÓÁö 2°³ ÆÄÀÏÀº ¾Ïȣȭ Å° µî·Ï ÆÄÀϵéÀÌ´Ù.

- winservices.dll

- WindowsStartFnc.dll


9) msprexe.exe Á¶»ç

Ư¡Àº ´ÙÀ½°ú °°´Ù.

- ¾ÐÃà : UPX 0.89.6 - 1.02
- ±â´É : iroffer ÇÁ·Î±×·¥ , IRC »ç¿ëÀڵ鿡°Ô ÆÄÀÏ Á¦°ø ¹× µ¥ÀÌÅÍ Àü¼Û
- °ü·ÃÆÄÀÏ :
  cygcrypt-0.dll
  cygwin1.dll
  MSVCP60.dll
  dhtml.c.dll (»óÅÂ·Î±× ÆÄÀÏ)
  winhlp.dll (ȯ°æ¼³Á¤ ÆÄÀÏ)

msprexe.exe´Â iroffer ÇÁ·Î±×·¥¸íÀ» º¯°æÇÑ ¹ÙÀ̳ʸ®·Î TCP/UDP Æ÷Æ®¸¦ ÀÌ¿ëÇؼ­ IRC Ŭ¶óÀ̾ðÆ®µé¿¡°Ô µ¥ÀÌÅ͸¦ Á¦°øÇØÁØ´Ù. msprexe.exe ÇÁ·Î±×·¥À» ½ÇÇàÇϸé winhlp.dll ÆÄÀÏÀÌ »ý¼ºµÇ°í ÀÌ ÆÄÀÏÀº DLL°ú »ó°ü¾ø´Â iroffer ·Î±× ÆÄÀÏÀÌ´Ù. ½ÇÇà µÈ ÈÄ dhtml.c.dll ȯ°æ ¼³Á¤ÆÄÀÏÀ» ÅëÇØ IRC ¼­¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÏ°í Á¢¼ÓÀÌ µÇ¸é °ü·ÃµÈ ¼¼Æà °ªÀ¸·Î ä³Î¿¡ µî·ÏÇÑ´Ù.

- winhlp.dll


¶Ç ÇϳªÀÇ DLL ÆÄÀÏÀÌ Á¸ÀçÇϴµ¥ dhtml.c.dllÀº ȯ°æ¼³Á¤ ÆÄÀÏ·Î ¼¼Æÿ¡ ÇÊ¿äÇÑ
Á¤º¸µéÀÌ Á¸ÀçÇÑ´Ù.

- dhtml.c.dll



9) fclear.exe, dtreg.exe Á¶»ç

 flcear.exe
- ¾ÐÃà : UPX 0.89.6 - 1.02 / 1.05 - 1.24
- ±â´É : À̺¥Æ® ·Î±× »èÁ¦ ÇÁ·Î±×·¥

fclear.exe´Â ClearEventLog ÇÁ·Î±×·¥ ¸íÀ» º¯°æÇÑ ¹ÙÀ̳ʸ®·Î À̺¥Æ® ·Î±×¸¦ »èÁ¦Çϴµ¥ »ç¿ëµÈ´Ù. all ¿É¼ÇÀ» ÅëÇØ ¸ðµç ·Î±×¸¦ Á¦°ÅÇϸç fclear¸¦ ¿É¼Ç ¾øÀÌ ½ÇÇàÇÑ È­¸éÀº ¾Æ·¡¿Í °°´Ù.



(±×¸² 7) fclar.exe ½ÇÇàÈ­¸é

?dtreg.exe

- ¾ÐÃà : PECompact 2.x
- ±â´É : ·¹Áö½ºÆ®¸® µî·Ï ÇÁ·Î±×·¥

TaskDaemon ÇÁ·Î±×·¥À» ·¹Áö½ºÆ®¸®¿¡ µî·ÏÇϴµ¥ »ç¿ëµÇ¸ç ÀÌ ÈÄ ¹Ù·Î »èÁ¦µÈ´Ù.

3. °á·Ð ¹× ´ëÃ¥

Á¶»ç°á°ú 1.exe´Â ÇÇÇؽýºÅÛ¿¡ ¼³Ä¡ÇÒ ¾Ç¼º ÇÁ·Î±×·¥µéÀ» ¼û±â±â À§ÇØ ½Ã½ºÅÛ Æú ´õÀÎ C:\RECYLER Æú´õ ÇÏÀ§¿¡ ½ÇÁ¦ À̸§°ú À¯»çÇÑ ½Ã½ºÅÛ Æú´õ¸¦ »ý¼º ÇÏ¿´°í ÀÌ ÈÄ °ü·Ã ¾Ç¼ºÇÁ·Î±×·¥µéÀ» ±× Æú´õ·Î ¾ÐÃàÇØÁ¦ ½ÃŲ ÈÄ Çϳª¾¿ ¾Ç¼ºÇÁ·Î±×·¥µéÀ» ½ÇÇàÇÏ¿´´Ù. ½ÇÇàµÈ ¾Ç¼º ÇÁ·Î±×·¥µéÀº ÀڽŵéÀÇ È¨ µð·ºÅ͸® ¹× Æ÷Æ®, º¿ C&C ÇÁ·Î±×·¥, IRC Ŭ¶óÀ̾ðÆ® ÇÁ·Î±×·¥ µîÀÇ Á¤º¸¸¦ ¼û°Ü °ü¸®ÀÚ°¡ ½±°Ô ¹ß°ßÇÏÁö ¸øÇϵµ·Ï ÇÏ¿´´Ù. 1.exe ·çƮŶ ÇÁ·Î±×·¥À» ŽÁö¸¦ ¸øÇÏ´Â ¹é½Å Á¦Ç°µéÀÌ ÀÖ¾î ¼­¹ö°ü¸®ÀÚµéÀÌ ¾Ç¼ºÇÁ·Î±×·¥µéÀÇ ¼³Ä¡ ¿©ºÎ¸¦ È®ÀÎÇÏÁö ¸øÇÏ°í ÀÖ¾ú´Ù. ÀÌ ÈÄ À©µµ¿ì XP ½Ã½ºÅÛ¿¡¼­µµ 1.exe º¯Á¾ÀÎ esyp4.exe¸¦ ¹ß°ßÇßÁö¸¸ À̸§¸¸ º¯°æµÇ¾úÀ» »Ó ¶È °°Àº ±â´ÉÀ» ÇÏ ¿´´Ù.
Ä¿³Î ·çƮŶ ½ÇÇàÀ¸·Î °ü·Ã ·çƮŶ ÇÁ·Î±×·¥ Á¤º¸µéÀ» ã¾Æ³»±â°¡ ½±Áö°¡ ¾Ê±â ¶§¹®¿¡ °ø°³¿ë Ä¿³Î ·çƮŶ ŽÁö ÇÁ·Î±×·¥ÀÎ IceSword µµ±¸¸¦ ÀÌ¿ëÇØ °ü·Ã ÇÁ·Î±×·¥µéÀÇ È¨ µð·ºÅ͸®, ÇÁ·Î¼¼½º, Æ÷Æ®Á¤º¸, ¼­ºñ½º, ·¹Áö½ºÆ®¸®¸¦ ã¾Æ³»¼­ ¸ðµÎ Á¦°ÅÇØ ÁÖ¾î¾ß ÇÑ´Ù. ¾Æ·¡ ±×¸²Àº Ä¿³Î ·çƮŶ ½ÇÇà ¼­ºñ½ºÀÎ NetSecManger¸¦ ãÀº ÈÄ ¼­ºñ½º ÁßÁö ¹× Á¦°ÅÇØ ÁÖ´Â È­¸éÀÌ´Ù.


(±×¸² 8) Ä¿³Î ·çƮŶ Á¦°Å

·çƮŶ 1.exe°¡ ¼³Ä¡µÈ º¿C&C¼­¹ö ÇÇÇؽýºÅÛµéÀº °ü¸®ÀÚµéÀÌ ¼ÒȦÇϱ⠽¬¿î °³¹ß¿ë ¼­¹ö³ª ÀÚÁÖ ÀÌ¿ëÇÏÁö ¾Ê´Â ½Ã½ºÅÛÀ¸·Î º¸¾ÈÆÐÄ¡ÀÇ ¹ÌÀû¿ë, ¼­¹ö ¾È¼³Á¤ ¹Ì½Ç½Ã µîÀ¸·Î ÀÎÇØ ÇÇÇظ¦ ÀÔ¾ú´Ù. ¶ÇÇÑ, ÀÚÁÖ »ç¿ëÇÏÁö ¾Ê´Ù º¸´Ï ½Ã½ºÅÛÀÌ ¾Ç¿ëÀÌ µÇ°í ÀÖ´Â »óÅ¿¡¼­µµ À̸¦ ½±°Ô ¹ß°ßÇÏÁö ¸øÇÏ¿´´Ù.
½Ã½ºÅÛ ´ã´çÀÚµéÀº º» »ç°í»ç·Ê¿Í °°Àº ÇÇÇظ¦ ÁÙÀ̱â À§ÇØ À©µµ¿ì ÀÚµ¿¾÷µ¥ÀÌÆ® ±â´ÉÀ» ¹Ýµå½Ã »ç¿ëÇÒ °ÍÀ» ±ÇÀåÇϸç, ƯÈ÷ °ü¸®ÀÇ ¼ÕÀÌ ¹ÌÄ¡Áö ¾ÊÀº¹æÄ¡µÈ ½Ã½ºÅÛÀÌ ¾ø´Â Áö È®ÀÎÇÒ ÇÊ¿ä°¡ ÀÖ´Ù.
 
[ÀÚ·á: Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA)]
  ARP Spoofing ±â¹ýÀ» ÀÌ¿ëÇÑ À¥ ÆäÀÌÁö ¾Ç¼ºÄÚµå »ðÀÔ »ç·Ê
  µð·ºÅ丮¸®½ºÆà Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ÔÀÓDB¼­¹ö ÇØÅ·»ç°í





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ