Home | Data Center | Contact US | Login

Á¦¸ñ ½ºÆÔ¸ÞÀÏÀ» ÅëÇÏ¿© ÀüÆĵǴ ¾Ç¼ºÄÚµå ºÐ¼®
÷ºÎÆÄÀÏ 08_spam.pdf ÀÛ¼ºÀÏ 2008-02-18 13:07:32
½ºÆÔ¸ÞÀÏÀ» ÅëÇÏ¿© ÀüÆĵǴ ¾Ç¼ºÄÚµå ºÐ¼®

1. °³ ¿ä

ÃÖ±Ù ±¹³» ¿Ü¿¡¼­ E-card ¹ß¼ÛÀ» °¡ÀåÇÑ ½ºÆÔ¸ÞÀÏ·Î ÀÎÇÏ¿© ¾Ç¼ºÄڵ忡 °¨¿°µÇ´Â ÇÇÇØ°¡ ´Ù¼ö º¸°í µÇ¾ú´Ù. ¾Ç¼ºÄÚµå´Â ¸ÞÀϺ»¹®¿¡ ¾ÇÀÇÀûÀÎ URLÀ» »ðÀÔ ¹× Ŭ¸¯À» À¯µµÇÏ´Â ¹æ½ÄÀ¸·Î ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÑ´Ù. »ç¿ëÀÚ°¡ ½ºÆÔ¸ÞÀÏ¿¡ Æ÷ÇԵǾî ÀÖ´Â ¾Ç¼ºURLÀ» Ŭ¸¯ÇÒ °æ¿ì °¨¿°µÉ ¼ö ÀÖÀ¸¸ç, °¨¿° ÈÄ¿¡´Â ¾Ç¼ºÄڵ尡 °¨¿°PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ¸ÞÀÏÁÖ¼ÒµéÀ» ÃßÃâÇÏ¿© ÇØ´çÁÖ¼Ò·Î µ¿ÀÏÀ¯ÇüÀÇ ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÏ°Ô µÈ´Ù. ¶ÇÇÑ, P2P¸¦ ÅëÇÑ ¸í·ÉÀü´Þ ¹× Ãß°¡ ¾Ç¼ºÄÚµå ´Ù¿î·Îµå µîÀÇ ¾Ç¼ºÇàÀ§°¡ ¿¹»óµÇ¹Ç·Î »ç¿ëÀÚ´Â URLÀÌ Æ÷ÇԵǾî ÀÖ´Â ½ºÆÔ ¼º ¸ÞÀÏ ¼ö½Å ½Ã Ŭ¸¯ÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇÑ´Ù. Äü ŸÀÓ, Winzip »ç¿ëÀÚÀÇ °æ¿ì, ÇØ´ç Á¦Ç°À» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ®Çϵµ·Ï Çϸç, OS ¹× ¼³Ä¡µÇ¾î ÀÖ´Â ¹é½ÅÀ» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ¿© °¨¿°À» ¿¹¹æÇϵµ·Ï ÇÑ´Ù.


2. ½ºÆÔ¸ÞÀÏÀ» ÀÌ¿ëÇÑ ÀüÆÄ ±â¹ý

o ÀüÆıâ¹ý ºÐ¼®
¸ÞÀÏÀ» ÅëÇÏ¿© ¾Ç¼º¸µÅ© Ŭ¸¯À» À¯µµ ¹× Ãë¾àÁ¡À» ¾Ç¿ëÇÏ¿© »ç¿ëÀÚ PC¸¦ °¨¿°½ÃŲ´Ù.
- ½ºÆÔ¸ÞÀÏ ¹ß¼ÛÀ» ÅëÇÑ ¾Ç¼º À¥»çÀÌÆ® Á¢¼ÓÀ¯µµ
- À¥ ºê¶ó¿ìÁ® ¹× Third-Party ¾îÇø®ÄÉÀÌ¼Ç Ãë¾àÁ¡ ¾Ç¿ë
¢Ñ ½ºÆÔ¸ÞÀÏ À¯Çü ºÐ¼®
½ºÆÔ ¸ÞÀÏÀº ¿µ¹®À̸ç, ¾Æ·¡¿Í °°ÀÌ ecard ¹ß¼ÛÀ» °¡ÀåÇÏ¿©, ¾Ç¼º URL¿¡ Á¢¼ÓÇϵµ·Ï À¯µµÇÑ´Ù.
- ¸ÞÀÏÁ¦¸ñ ¹× ³»¿ë À¯Çü
¡Ø Âü°í: ¸ÞÀÏÁ¦¸ñ ¹× ³»¿ëÀº ´Ù¸¥ À¯ÇüÀ¸·Î °è¼ÓÀûÀ¸·Î ¾÷µ¥ÀÌÆ® µÇ´Â °ÍÀ¸·Î È®ÀεÊ
* ¸ÞÀÏÁ¦¸ñ ¿¹
- Thank you ecard,
- Animated card,
- Greeting ecard,
- Musical e-card
- Movie-quality e-card,
- Thank you postcard,
- Funny postcard ,
- Birthday postcard
- Á¦¸ñ¾øÀ½ µî

* ¸ÞÀϳ»¿ë ¿¹
Hi. Colleague has sent you a greeting ecard.
See your card as often as you wish during the next 15 days.
SEEING YOUR CARD
If your email software creates links to Web pages, click on your
card's direct www address below while you are connected to the Internet:
http://88.8[»ý·«]9.10/?55844a4912b62c4232c3a9ebeed43 (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù)
Or copy and paste it into your browser's "Location" box (where Internet
addresses go).
We hope you enjoy your awesome card.
Wishing you the best,
Webmaster,
BlueMountain.Com

Family member(jbilones@qu[»ý·«]utual.com) has created Animated e-card for
you
at americ[»ý·«]eetings.com.
To see your custom Animated e-card, simply click on the following
Internet address (if your mail program doesn't support this feature
you will need to COPY and PASTE the address into your browser's address
box):
http://68.4[»ý·«]165/?9dc7f80c760e2baa0067 (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù)
Send a FREE greeting card from americ[»ý·«]etings.com whenever you want
by visiting us at:
http://america[»ý·«]eetings.com/
This service is provided and hosted by ameri[»ý·«]eetings.com.

Good day.
Your School friend has sent you Thank you card from netfu[»ý·«]ds.com.
Click on your card's direct www address below:
http://68.5[»ý·«]80.218/ (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù)
Copyright (c) 1997-2007 netfuncards.com All Rights Reserved

Oh baby, I love what you sent me. Here is some pics to say thanks.
http://75.3[»ý·«]44.127/ (URLÁÖ¼Ò´Â °¡º¯ÀûÀÌ´Ù)

¢Ñ ¾Ç¿ë Ãë¾àÁ¡ ºÐ¼®
»ç¿ëÀÚ°¡ ¾Ç¼º URL¿¡ Á¢¼ÓÇÒ °æ¿ì, ¾Æ·¡¿Í °°Àº È­¸éÀÌ Ãâ·ÂµÇ´Âµ¥, È­¸é ³»¿¡´Â ÀÚ¹Ù½ºÅ©¸³Æ® Äڵ尡 »ðÀԵǾî ÀÖ´Ù.

ÇØ´ç ÀÚ¹Ù½ºÅ©¸³Æ® ³»¿¡´Â Ãë¾àÁ¡ °ø°ÝÀ» À§ÇÑ ÇÙ½ÉÄÚµåµéÀÌ Å½Áö¸¦ ¾î·Æ°Ô Çϱâ À§ÇÏ ¿© ¾Ïȣȭ ÇüÅ·Π»ðÀԵǾî ÀÖ´Ù.

<ÀÎ ÄÚµùµÈ °ø°ÝÄÚµå ¿¹>

¾Ïȣȭ µÈ °ø°ÝÄÚµåµéÀº ¾Æ·¡ÀÇ ·çƾ¿¡ ÀÇÇÏ¿© º¹È£È­ µÈ´Ù.

<º¹È£È­ ·çƾ>

o °ø°Ý¿¡ ¾Ç¿ëµÇ´Â Ãë¾àÁ¡
- MS06-014: MS µ¥ÀÌÅÍ Á¢±Ù ÄÄÆ÷³ÍÆ® Ãë¾àÁ¡
- MS06-057: MS À©µµ¿ì Ž»ö±â ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡
- ¾ÖÇûç ÄüŸÀÓ 7.1.3ÀÌÇÏÀÇ ¹öÀü¿¡¼­
RTSP(Real Time Stream Protocol) URLó¸® Ãë¾àÁ¡
- WinZip(¾ÐÃàÀ¯Æ¿¸®Æ¼) 10.0 ÀÌÇÏÀÇ ¹öÀü¿¡¼­ ÀÓÀǸí·É ½ÇÇàÃë¾àÁ¡

o °¨¿° ÀýÂ÷ ¹× Áõ»ó
¸ÞÀÏ ³»ÀÇ ¾Ç¼º URL ¸µÅ©¸¦ Ŭ¸¯ÇÒ °æ¿ì, ÇØ´ç »çÀÌÆ®·ÎºÎÅÍ ´Ù¼öÀÇ °ø°ÝÄڵ尡 ´Ù¿î·Îµå µÇ¸ç, ¾Ç¼ºÄڵ忡 °¨¿°µÇ°Ô µÈ´Ù.
°¨¿° ½Ã, °¨¿° PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ¸ÞÀÏÁÖ¼ÒµéÀ» ´ë»óÀ¸·Î ¾Ç¼º ½ºÆÔ¸ÞÀÏÀÌ ¹ß¼ÛµÈ´Ù.

¨ç »ç¿ëÀÚ°¡ ¼ö½ÅµÈ ¸ÞÀÏ ³»ÀÇ ¾Ç¼º¸µÅ©·Î Á¢¼Ó½Ãµµ
¨è °ø°ÝÄÚµå ¹× ¾Ç¼ºÆÄÀÏÀÌ ´Ù¿î·Îµå
¨é »ç¿ëÀÚPC °¨¿° ¹ß»ý
¨ê ¿úÀº PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ¸ÞÀÏÁÖ¼ÒµéÀ» °Ë»öÇÏ¿©
¾Ç¼º½ºÆÔ ¸ÞÀÏ ¹ß¼Û
¨ë P2P Åë½Å

¢Ñ ÀýÂ÷º° »ó¼¼
¾Ç¼º»çÀÌÆ®¿¡ Á¢¼ÓÇϸé, ¾Ç¼ºÆÄÀÏÀÌ ¼³Ä¡µÈ´Ù. ÃÖÃÊ·Î sys[·£´ý].exe ÆÄÀÏÀÌ »ý¼ºµÇ´Âµ¥, ÀÌ ÆÄÀÏÀº 2Â÷ ¾Ç¼ºÆÄÀÏÀÎ ecard.exe ¸¦ Ãß°¡ ¼³Ä¡ÇÑ´Ù.
ecard.exe´Â ÀÚ½ÅÀÇ º¹Á¦ÆÄÀÏÀ» spooldr.exe ÆÄÀϸíÀ¸·Î À©µµ¿ì Æú´õ¿¡ »ý¼ºÇϸç, ¾Ç¼º ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÏ°í, Ÿ ½Ã½ºÅÛ°ú P2P Åë½ÅÀ» ½ÃµµÇÑ´Ù.


i) ½ºÆÔ¸ÞÀÏ¿¡ Æ÷ÇÔµÈ ¾Ç¼º¸µÅ©·Î Á¢¼Ó½Ãµµ ÇÒ °æ¿ì, ¾Ç¼ºÆÄÀÏÀÌ ´Ù¿î·Îµå µÇ¾î sys
[·£´ý].exe ÇüÅ·ΠÀúÀå ¹× ½ÇÇàµÊ
. http://[¾Ç¼º»çÀÌÆ® ÁÖ¼Ò]\file.php ·ÎºÎÅÍ ÆÄÀÏÀ» ´Ù¿î·Îµå ¹Þ¾Æ sys[·£´ý4¹®ÀÚ].exe ÆÄÀϸíÀ¸·Î "c:\"Æú´õ¿¡ ÀúÀå ÇÑÈÄ ½ÇÇà

<¾Ç¼ºÆÄÀÏÀ» ´Ù¿î·Îµå ¹× ÀúÀå, ½ÇÇàÇϱâ À§ÇÑ ÀÚ¹Ù ½ºÅ©¸³Æ® °ø°ÝÄÚµå>

<ÆÄÀÏ ¼³Ä¡ ¿¹>




ii) sys[·£´ý].exe ÆÄÀÏÀº fncarp.com »çÀÌÆ®·ÎºÎÅÍ ecard.exe ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ¿© ¹ÙÅÁÈ­¸é¿¡ ÀúÀå ¹× ½ÇÇà.
. ´Ù¿î·Îµå °æ·Î: "fncarp.com/ecard.exe"



¡Ø»ç¿ëÀÚ°¡ Á÷Á¢ ¡°click" ¸µÅ©¸¦ Ŭ¸¯ÇÏ´Â °æ¿ì´Â ¾Ç¼ºÆÄÀÏÀÎ msdataaccess.exe °¡ ´Ù¿î·Îµå µÊ. ÇØ´ç ÆÄÀÏÀº ecard.exe¿Í µ¿Àϱâ´ÉÀ» ¼öÇàÇÔ

iii) ecard.exe´Â ÀÚ½ÅÀÇ º¹Á¦º»À» À©µµ¿ìÆú´õ¿¡ spooldr.exe ÆÄÀϸíÀ¸·Î »ý¼º. ¶ÇÇÑ ½Ã½ºÅÛ Æú´õ¿¡ spooldr.sys ÆÄÀÏÀ» »ý¼ºÇÏ°í ¹ÙÅÁÈ­¸é¿¡ spooldr.ini ÆÄÀÏÀ» »ý¼ºÇÏ¸ç µå¶óÀ̹ö Æú´õÀÇ tcpip.sys ÆÄÀÏÀ» º¯Á¶ÇÑ´Ù.









o °¨¿° ÈÄ Áõ»ó
- °¨¿°PC¿¡ ÀúÀåµÈ ÆÄÀϷκÎÅÍ ¸ÞÀÏÁÖ¼Ò¸¦ ÃßÃâÇÏ¿© ´ë»óÁÖ¼Ò·Î ½ºÆÔ¸ÞÀÏÀ» ¹ß¼ÛÇÑ´Ù.
¡Ø°¨¿°PC³»¿¡ ÀúÀåµÇ¾î ÀÖ´Â ÆÄÀÏ Áß ¸ÞÀÏÁÖ¼Ò ÃßÃâÀ» À§ÇÏ¿© ¾Æ·¡ÀÇ È®Àå¸í ÆÄÀÏÀ» °Ë»öÇÑ´Ù.
lst, dat, jsp, dhtm, mht, cgi, uni, oft, xls, sht, tbb, adb,
wsh, pl, php, asp, cfg, ods, mmf, nch, eml, mdx, mbx,
dbx, xml, stm, shtm, htm, msg, txt, wab



¡Ø¾Æ·¡ÀÇ ¹®ÀÚ¿­ÀÌ Æ÷ÇԵǾî ÀÖ´Â Áּҷδ ¸ÞÀÏÀ» ¹ß¼ÛÇÏÁö ¾Ê´Â´Ù.
postmaster@, root@, local, noreply, @avp, pgp, spam, cafee, panda,
abuse, samples, winrar, google, winzip, @messagelab, free-av, @iana,
@foo, sopho, certific, istserv, linux, bsd, unix, ntivi, support, icrosoft,
admin, kasp, noone@m nobody@, info, help@, gold-certs@, feste,
contract@, bugs@ anyone@, update, news, f-secur, rating@, @microsoft



- ½ÇÇà ¿¡·¯Ã¢ Ãâ·Â
»ç¿ëÀÚ PC°¡ °¨¿°µÇ¸é ¾Æ·¡¿Í °°Àº ½ÇÇà ¿¡·¯Ã¢ÀÌ Ãâ·ÂµÈ´Ù.


- ¹æÈ­º® ¿ìȸ
¾Æ·¡ ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ¿© ¾Ç¼ºÄڵ尡 ¹æÈ­º®À» ¿ìȸÇÒ ¼ö ÀÖµµ·Ï µî·ÏÇÑ´Ù
¡°netsh firewall set allowedprogram c:\\WINDOWS\spooldr.exe enable¡±


- º¸¾ÈÇÁ·Î±×·¥ µî ½ÇÇà ¹æÇØ
¾Æ·¡¿Í °°Àº ÇÁ·Î±×·¥ÀÇ ±â´É ¼öÇàÀ» ¹æÇØÇÑ´Ù.

watchdog.sys, zclient.sys, bcfilter.sys, bcftdi.sys, bc_hassh_f.sys
bc_ip_f.sys, bc_ngn.sys, bc_pat_f.sys, bc_prt_f.sys, bc_tdi_f.sys
filtnt.sys, sandbox.sys, mpfirewall.sys, msssrv.exe, mcsheld.exe
fsbl.exe, avz.exe, avp.exe, avpm.exe, kav.exe, kavss.exe
kavsvc.exe, klswd.exe, ccapp.exe, ccevtmgr.exe, ccpxysvc.exe
iao.exe, issvc.exe, rtvscan.exe, savscan.exe, bdss.exe, bdmcon.exe
livesrv.exe, cclaw.exe, fsav32.exe, fsm32.exe, gcasserv.exe
icmon.exe, inetupd.exe, nod32krn.exe, nod32ra.exe, pavfnsvr.exe

- Ÿ °¨¿° PC¿ÍÀÇ P2P Åë½Å
°¨¿° PC´Â ·£´ýÇÑ Æ÷Æ®¸¦ OpenÇÏ¿©, P2PÇÁ·ÎÅäÄÝÀ» ÅëÇÏ¿© ´Ù¸¥ °¨¿° PCµé°ú Åë½ÅÇÑ´Ù. °ø°ÝÀÚ°¡ P2P¸¦ ÅëÇÏ¿© ¸í·ÉÀ» Àü´ÞÇÏ¿© ¿úÀ» ¾÷µ¥ÀÌÆ®Çϰųª ´Ù¸¥ ¾Ç¼ºÄÚ
µå¸¦ Ãß°¡·Î ¼³Ä¡ÇÏ´Â ¾Ç¼ºÇàÀ§°¡ ¿¹»óµÈ´Ù.

<P2P Åë½Å ¿¹>




¡Ø peer Á¤º¸´Â ¹ÙÅÁÈ­¸é¿¡ spooldr.ini ÆÄÀÏ ³»¿¡ ÀúÀåµÊ.
<spooldr.ini ÆÄÀÏ ³»ÀÇ ÀúÀåµ¥ÀÌÅÍ ¿¹>


- ±â Ÿ
ÀÚ±â ÀºÆó±â´ÉÀÌ ÀÖÀ¸¸ç, ´Ù¼öÀÇ º¯Á¾ Á¸Àç.

3. ¿¹¹æ ¹æ¹ý

o ÀÎÅͳÝÄ«µå°¡ ¼ö½ÅµÇ¾ú´Ù¸ç È®ÀÎÀ» À§ÇÏ¿© ƯÁ¤»çÀÌÆ®¿¡ Á¢¼ÓÀÌ ÇÊ¿äÇÏ´Ù´Â À¯ÇüÀÇ Àǽɽº·¯¿î ½ºÆÔ ¼º ¸ÞÀÏÀ» ¼ö½ÅÇÒ °æ¿ì, °ü·Ã ¸µÅ©¸¦ Ŭ¸¯ÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇÑ´Ù.
o À©µµ¿ìOS¿¡ ´ëÇÑ ÃֽŠº¸¾È¾÷µ¥ÀÌÆ®¸¦ ½Ç½ÃÇϸç, Winzip ¹× Quicktime ¾îÇø®ÄÉÀÌ¼Ç »ç¿ëÀÚÀÇ °æ¿ì ÇØ´ç Á¦Ç°¿¡ ´ëÇؼ­µµ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ ½Ç½ÃÇÑ´Ù.
o ¹é½ÅÀ» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ® ¹× ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ­ ÇÑ´Ù.
o DNS °ü¸®ÀÚ´Â fncarp.com »çÀÌÆ®¿¡ ´ëÇÏ¿© lookback ¼³Á¤À» ÇϹǷνá, DNS »ç¿ëÀÚµéÀÌ Ãß°¡ÀûÀ¸·Î °¨¿°µÇÁö ¾Êµµ·Ï ¿¹¹æÇÑ´Ù.


[ÀÚ·á: Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA)]
  Virut ¾Ç¼ºÄڵ带 ÀÌ¿ëÇÑ DDoS °ø°Ý±â¹ý ºÐ¼®
  ½Ã½ºÅÛ ÀÌ»ó½Ã ±âº»ÀûÀÎ Á¡°Ë »çÇ× ¹× ¸í·É¾î





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ