½ºÆÔ¸ÞÀÏÀ» ÅëÇÏ¿© ÀüÆĵǴ ¾Ç¼ºÄÚµå ºÐ¼®
1. °³ ¿ä
ÃÖ±Ù ±¹³» ¿Ü¿¡¼ E-card ¹ß¼ÛÀ» °¡ÀåÇÑ ½ºÆÔ¸ÞÀÏ·Î ÀÎÇÏ¿© ¾Ç¼ºÄڵ忡 °¨¿°µÇ´Â ÇÇÇØ°¡ ´Ù¼ö º¸°í µÇ¾ú´Ù. ¾Ç¼ºÄÚµå´Â ¸ÞÀϺ»¹®¿¡ ¾ÇÀÇÀûÀÎ URLÀ» »ðÀÔ ¹× Ŭ¸¯À» À¯µµÇÏ´Â ¹æ½ÄÀ¸·Î ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÑ´Ù. »ç¿ëÀÚ°¡ ½ºÆÔ¸ÞÀÏ¿¡ Æ÷ÇԵǾî ÀÖ´Â ¾Ç¼ºURLÀ» Ŭ¸¯ÇÒ °æ¿ì °¨¿°µÉ ¼ö ÀÖÀ¸¸ç, °¨¿° ÈÄ¿¡´Â ¾Ç¼ºÄڵ尡 °¨¿°PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ¸ÞÀÏÁÖ¼ÒµéÀ» ÃßÃâÇÏ¿© ÇØ´çÁÖ¼Ò·Î µ¿ÀÏÀ¯ÇüÀÇ ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÏ°Ô µÈ´Ù. ¶ÇÇÑ, P2P¸¦ ÅëÇÑ ¸í·ÉÀü´Þ ¹× Ãß°¡ ¾Ç¼ºÄÚµå ´Ù¿î·Îµå µîÀÇ ¾Ç¼ºÇàÀ§°¡ ¿¹»óµÇ¹Ç·Î »ç¿ëÀÚ´Â URLÀÌ Æ÷ÇԵǾî ÀÖ´Â ½ºÆÔ ¼º ¸ÞÀÏ ¼ö½Å ½Ã Ŭ¸¯ÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇÑ´Ù. Äü ŸÀÓ, Winzip »ç¿ëÀÚÀÇ °æ¿ì, ÇØ´ç Á¦Ç°À» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ®Çϵµ·Ï Çϸç, OS ¹× ¼³Ä¡µÇ¾î ÀÖ´Â ¹é½ÅÀ» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ¿© °¨¿°À» ¿¹¹æÇϵµ·Ï ÇÑ´Ù.
2. ½ºÆÔ¸ÞÀÏÀ» ÀÌ¿ëÇÑ ÀüÆÄ ±â¹ý
o ÀüÆıâ¹ý ºÐ¼® ¸ÞÀÏÀ» ÅëÇÏ¿© ¾Ç¼º¸µÅ© Ŭ¸¯À» À¯µµ ¹× Ãë¾àÁ¡À» ¾Ç¿ëÇÏ¿© »ç¿ëÀÚ PC¸¦ °¨¿°½ÃŲ´Ù. - ½ºÆÔ¸ÞÀÏ ¹ß¼ÛÀ» ÅëÇÑ ¾Ç¼º À¥»çÀÌÆ® Á¢¼ÓÀ¯µµ - À¥ ºê¶ó¿ìÁ® ¹× Third-Party ¾îÇø®ÄÉÀÌ¼Ç Ãë¾àÁ¡ ¾Ç¿ë ¢Ñ ½ºÆÔ¸ÞÀÏ À¯Çü ºÐ¼® ½ºÆÔ ¸ÞÀÏÀº ¿µ¹®À̸ç, ¾Æ·¡¿Í °°ÀÌ ecard ¹ß¼ÛÀ» °¡ÀåÇÏ¿©, ¾Ç¼º URL¿¡ Á¢¼ÓÇϵµ·Ï À¯µµÇÑ´Ù. - ¸ÞÀÏÁ¦¸ñ ¹× ³»¿ë À¯Çü ¡Ø Âü°í: ¸ÞÀÏÁ¦¸ñ ¹× ³»¿ëÀº ´Ù¸¥ À¯ÇüÀ¸·Î °è¼ÓÀûÀ¸·Î ¾÷µ¥ÀÌÆ® µÇ´Â °ÍÀ¸·Î È®ÀÎµÊ * ¸ÞÀÏÁ¦¸ñ ¿¹ - Thank you ecard, - Animated card, - Greeting ecard, - Musical e-card - Movie-quality e-card, - Thank you postcard, - Funny postcard , - Birthday postcard - Á¦¸ñ¾øÀ½ µî
* ¸ÞÀϳ»¿ë ¿¹
Hi. Colleague has sent you a greeting ecard. See your card as often as you wish during the next 15 days. SEEING YOUR CARD If your email software creates links to Web pages, click on your card's direct www address below while you are connected to the Internet: http://88.8[»ý·«]9.10/?55844a4912b62c4232c3a9ebeed43 (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù) Or copy and paste it into your browser's "Location" box (where Internet addresses go). We hope you enjoy your awesome card. Wishing you the best, Webmaster, BlueMountain.Com |
Family member(jbilones@qu[»ý·«]utual.com) has created Animated e-card for you at americ[»ý·«]eetings.com. To see your custom Animated e-card, simply click on the following Internet address (if your mail program doesn't support this feature you will need to COPY and PASTE the address into your browser's address box): http://68.4[»ý·«]165/?9dc7f80c760e2baa0067 (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù) Send a FREE greeting card from americ[»ý·«]etings.com whenever you want by visiting us at: http://america[»ý·«]eetings.com/ This service is provided and hosted by ameri[»ý·«]eetings.com. |
Good day. Your School friend has sent you Thank you card from netfu[»ý·«]ds.com. Click on your card's direct www address below: http://68.5[»ý·«]80.218/ (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù) Copyright (c) 1997-2007 netfuncards.com All Rights Reserved |
Oh baby, I love what you sent me. Here is some pics to say thanks. http://75.3[»ý·«]44.127/ (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù) | ¢Ñ ¾Ç¿ë Ãë¾àÁ¡ ºÐ¼® »ç¿ëÀÚ°¡ ¾Ç¼º URL¿¡ Á¢¼ÓÇÒ °æ¿ì, ¾Æ·¡¿Í °°Àº ȸéÀÌ Ãâ·ÂµÇ´Âµ¥, È¸é ³»¿¡´Â ÀÚ¹Ù½ºÅ©¸³Æ® Äڵ尡 »ðÀԵǾî ÀÖ´Ù.
ÇØ´ç ÀÚ¹Ù½ºÅ©¸³Æ® ³»¿¡´Â Ãë¾àÁ¡ °ø°ÝÀ» À§ÇÑ ÇÙ½ÉÄÚµåµéÀÌ Å½Áö¸¦ ¾î·Æ°Ô Çϱâ À§ÇÏ ¿© ¾ÏÈ£È ÇüÅ·Π»ðÀԵǾî ÀÖ´Ù.
<ÀÎ ÄÚµùµÈ °ø°ÝÄÚµå ¿¹>
¾ÏÈ£È µÈ °ø°ÝÄÚµåµéÀº ¾Æ·¡ÀÇ ·çƾ¿¡ ÀÇÇÏ¿© º¹È£È µÈ´Ù.
<º¹È£È ·çƾ>
o °ø°Ý¿¡ ¾Ç¿ëµÇ´Â Ãë¾àÁ¡
- MS06-014: MS µ¥ÀÌÅÍ Á¢±Ù ÄÄÆ÷³ÍÆ® Ãë¾àÁ¡ - MS06-057: MS À©µµ¿ì Ž»ö±â ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡ - ¾ÖÇûç ÄüŸÀÓ 7.1.3ÀÌÇÏÀÇ ¹öÀü¿¡¼ RTSP(Real Time Stream Protocol) URLó¸® Ãë¾àÁ¡ - WinZip(¾ÐÃàÀ¯Æ¿¸®Æ¼) 10.0 ÀÌÇÏÀÇ ¹öÀü¿¡¼ ÀÓÀǸí·É ½ÇÇàÃë¾àÁ¡ | o °¨¿° ÀýÂ÷ ¹× Áõ»ó ¸ÞÀÏ ³»ÀÇ ¾Ç¼º URL ¸µÅ©¸¦ Ŭ¸¯ÇÒ °æ¿ì, ÇØ´ç »çÀÌÆ®·ÎºÎÅÍ ´Ù¼öÀÇ °ø°ÝÄڵ尡 ´Ù¿î·Îµå µÇ¸ç, ¾Ç¼ºÄڵ忡 °¨¿°µÇ°Ô µÈ´Ù. °¨¿° ½Ã, °¨¿° PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ¸ÞÀÏÁÖ¼ÒµéÀ» ´ë»óÀ¸·Î ¾Ç¼º ½ºÆÔ¸ÞÀÏÀÌ ¹ß¼ÛµÈ´Ù.
¨ç »ç¿ëÀÚ°¡ ¼ö½ÅµÈ ¸ÞÀÏ ³»ÀÇ ¾Ç¼º¸µÅ©·Î Á¢¼Ó½Ãµµ ¨è °ø°ÝÄÚµå ¹× ¾Ç¼ºÆÄÀÏÀÌ ´Ù¿î·Îµå ¨é »ç¿ëÀÚPC °¨¿° ¹ß»ý ¨ê ¿úÀº PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ¸ÞÀÏÁÖ¼ÒµéÀ» °Ë»öÇÏ¿© ¾Ç¼º½ºÆÔ ¸ÞÀÏ ¹ß¼Û ¨ë P2P Åë½Å
¢Ñ ÀýÂ÷º° »ó¼¼ ¾Ç¼º»çÀÌÆ®¿¡ Á¢¼ÓÇϸé, ¾Ç¼ºÆÄÀÏÀÌ ¼³Ä¡µÈ´Ù. ÃÖÃÊ·Î sys[·£´ý].exe ÆÄÀÏÀÌ »ý¼ºµÇ´Âµ¥, ÀÌ ÆÄÀÏÀº 2Â÷ ¾Ç¼ºÆÄÀÏÀÎ ecard.exe ¸¦ Ãß°¡ ¼³Ä¡ÇÑ´Ù. ecard.exe´Â ÀÚ½ÅÀÇ º¹Á¦ÆÄÀÏÀ» spooldr.exe ÆÄÀϸíÀ¸·Î À©µµ¿ì Æú´õ¿¡ »ý¼ºÇϸç, ¾Ç¼º ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÏ°í, Ÿ ½Ã½ºÅÛ°ú P2P Åë½ÅÀ» ½ÃµµÇÑ´Ù.
i) ½ºÆÔ¸ÞÀÏ¿¡ Æ÷ÇÔµÈ ¾Ç¼º¸µÅ©·Î Á¢¼Ó½Ãµµ ÇÒ °æ¿ì, ¾Ç¼ºÆÄÀÏÀÌ ´Ù¿î·Îµå µÇ¾î sys [·£´ý].exe ÇüÅ·ΠÀúÀå ¹× ½ÇÇàµÊ . http://[¾Ç¼º»çÀÌÆ® ÁÖ¼Ò]\file.php ·ÎºÎÅÍ ÆÄÀÏÀ» ´Ù¿î·Îµå ¹Þ¾Æ sys[·£´ý4¹®ÀÚ].exe ÆÄÀϸíÀ¸·Î "c:\"Æú´õ¿¡ ÀúÀå ÇÑÈÄ ½ÇÇà
<¾Ç¼ºÆÄÀÏÀ» ´Ù¿î·Îµå ¹× ÀúÀå, ½ÇÇàÇϱâ À§ÇÑ ÀÚ¹Ù ½ºÅ©¸³Æ® °ø°ÝÄÚµå>
<ÆÄÀÏ ¼³Ä¡ ¿¹>
ii) sys[·£´ý].exe ÆÄÀÏÀº fncarp.com »çÀÌÆ®·ÎºÎÅÍ ecard.exe ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ¿© ¹ÙÅÁȸ鿡 ÀúÀå ¹× ½ÇÇà. . ´Ù¿î·Îµå °æ·Î: "fncarp.com/ecard.exe"
¡Ø»ç¿ëÀÚ°¡ Á÷Á¢ ¡°click" ¸µÅ©¸¦ Ŭ¸¯ÇÏ´Â °æ¿ì´Â ¾Ç¼ºÆÄÀÏÀÎ msdataaccess.exe °¡ ´Ù¿î·Îµå µÊ. ÇØ´ç ÆÄÀÏÀº ecard.exe¿Í µ¿Àϱâ´ÉÀ» ¼öÇàÇÔ
iii) ecard.exe´Â ÀÚ½ÅÀÇ º¹Á¦º»À» À©µµ¿ìÆú´õ¿¡ spooldr.exe ÆÄÀϸíÀ¸·Î »ý¼º. ¶ÇÇÑ ½Ã½ºÅÛ Æú´õ¿¡ spooldr.sys ÆÄÀÏÀ» »ý¼ºÇÏ°í ¹ÙÅÁȸ鿡 spooldr.ini ÆÄÀÏÀ» »ý¼ºÇÏ¸ç µå¶óÀ̹ö Æú´õÀÇ tcpip.sys ÆÄÀÏÀ» º¯Á¶ÇÑ´Ù.
o °¨¿° ÈÄ Áõ»ó - °¨¿°PC¿¡ ÀúÀåµÈ ÆÄÀϷκÎÅÍ ¸ÞÀÏÁÖ¼Ò¸¦ ÃßÃâÇÏ¿© ´ë»óÁÖ¼Ò·Î ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÑ´Ù. ¡Ø°¨¿°PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ÆÄÀÏ Áß ¸ÞÀÏÁÖ¼Ò ÃßÃâÀ» À§ÇÏ¿© ¾Æ·¡ÀÇ È®Àå¸í ÆÄÀÏÀ» °Ë»öÇÑ´Ù.
lst, dat, jsp, dhtm, mht, cgi, uni, oft, xls, sht, tbb, adb, wsh, pl, php, asp, cfg, ods, mmf, nch, eml, mdx, mbx, dbx, xml, stm, shtm, htm, msg, txt, wab |
¡Ø¾Æ·¡ÀÇ ¹®ÀÚ¿ÀÌ Æ÷ÇԵǾî ÀÖ´Â Áּҷδ ¸ÞÀÏÀ» ¹ß¼ÛÇÏÁö ¾Ê´Â´Ù.
postmaster@, root@, local, noreply, @avp, pgp, spam, cafee, panda, abuse, samples, winrar, google, winzip, @messagelab, free-av, @iana, @foo, sopho, certific, istserv, linux, bsd, unix, ntivi, support, icrosoft, admin, kasp, noone@m nobody@, info, help@, gold-certs@, feste, contract@, bugs@ anyone@, update, news, f-secur, rating@, @microsoft |
- ½ÇÇà ¿¡·¯Ã¢ Ãâ·Â »ç¿ëÀÚ PC°¡ °¨¿°µÇ¸é ¾Æ·¡¿Í °°Àº ½ÇÇà ¿¡·¯Ã¢ÀÌ Ãâ·ÂµÈ´Ù.
- ¹æȺ® ¿ìȸ ¾Æ·¡ ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ¿© ¾Ç¼ºÄڵ尡 ¹æȺ®À» ¿ìȸÇÒ ¼ö ÀÖµµ·Ï µî·ÏÇÑ´Ù ¡°netsh firewall set allowedprogram c:\\WINDOWS\spooldr.exe enable¡±
- º¸¾ÈÇÁ·Î±×·¥ µî ½ÇÇà ¹æÇØ ¾Æ·¡¿Í °°Àº ÇÁ·Î±×·¥ÀÇ ±â´É ¼öÇàÀ» ¹æÇØÇÑ´Ù.
watchdog.sys, zclient.sys, bcfilter.sys, bcftdi.sys, bc_hassh_f.sys bc_ip_f.sys, bc_ngn.sys, bc_pat_f.sys, bc_prt_f.sys, bc_tdi_f.sys filtnt.sys, sandbox.sys, mpfirewall.sys, msssrv.exe, mcsheld.exe fsbl.exe, avz.exe, avp.exe, avpm.exe, kav.exe, kavss.exe kavsvc.exe, klswd.exe, ccapp.exe, ccevtmgr.exe, ccpxysvc.exe iao.exe, issvc.exe, rtvscan.exe, savscan.exe, bdss.exe, bdmcon.exe livesrv.exe, cclaw.exe, fsav32.exe, fsm32.exe, gcasserv.exe icmon.exe, inetupd.exe, nod32krn.exe, nod32ra.exe, pavfnsvr.exe | - Ÿ °¨¿° PC¿ÍÀÇ P2P Åë½Å °¨¿° PC´Â ·£´ýÇÑ Æ÷Æ®¸¦ OpenÇÏ¿©, P2PÇÁ·ÎÅäÄÝÀ» ÅëÇÏ¿© ´Ù¸¥ °¨¿° PCµé°ú Åë½ÅÇÑ´Ù. °ø°ÝÀÚ°¡ P2P¸¦ ÅëÇÏ¿© ¸í·ÉÀ» Àü´ÞÇÏ¿© ¿úÀ» ¾÷µ¥ÀÌÆ®Çϰųª ´Ù¸¥ ¾Ç¼ºÄÚ µå¸¦ Ãß°¡·Î ¼³Ä¡ÇÏ´Â ¾Ç¼ºÇàÀ§°¡ ¿¹»óµÈ´Ù.
<P2P Åë½Å ¿¹>
¡Ø peer Á¤º¸´Â ¹ÙÅÁȸ鿡 spooldr.ini ÆÄÀÏ ³»¿¡ ÀúÀåµÊ. <spooldr.ini ÆÄÀÏ ³»ÀÇ ÀúÀåµ¥ÀÌÅÍ ¿¹>
- ±â Ÿ ÀÚ±â ÀºÆó±â´ÉÀÌ ÀÖÀ¸¸ç, ´Ù¼öÀÇ º¯Á¾ Á¸Àç.
3. ¿¹¹æ ¹æ¹ý
o ÀÎÅͳÝÄ«µå°¡ ¼ö½ÅµÇ¾ú´Ù¸ç È®ÀÎÀ» À§ÇÏ¿© ƯÁ¤»çÀÌÆ®¿¡ Á¢¼ÓÀÌ ÇÊ¿äÇÏ´Ù´Â À¯ÇüÀÇ Àǽɽº·¯¿î ½ºÆÔ ¼º ¸ÞÀÏÀ» ¼ö½ÅÇÒ °æ¿ì, °ü·Ã ¸µÅ©¸¦ Ŭ¸¯ÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇÑ´Ù. o À©µµ¿ìOS¿¡ ´ëÇÑ ÃֽŠº¸¾È¾÷µ¥ÀÌÆ®¸¦ ½Ç½ÃÇϸç, Winzip ¹× Quicktime ¾îÇø®ÄÉÀÌ¼Ç »ç¿ëÀÚÀÇ °æ¿ì ÇØ´ç Á¦Ç°¿¡ ´ëÇؼµµ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ ½Ç½ÃÇÑ´Ù. o ¹é½ÅÀ» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ® ¹× ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ ÇÑ´Ù. o DNS °ü¸®ÀÚ´Â fncarp.com »çÀÌÆ®¿¡ ´ëÇÏ¿© lookback ¼³Á¤À» ÇϹǷνá, DNS »ç¿ëÀÚµéÀÌ Ãß°¡ÀûÀ¸·Î °¨¿°µÇÁö ¾Êµµ·Ï ¿¹¹æÇÑ´Ù.
[ÀÚ·á: Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA)]
|
|