°Ô½ÃÆÇȨ / À©µµ¿ì / msgfix ¿¡ ´ëÇÑ Ä¡·á¹ý.»õ±Û¾²±â ´ä±Û¾²±â

ÀúÀÚ msgfix ¿¡ ´ëÇÑ Ä¡·á¹ý.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-03-12 12:16||
¾È³çÇϼ¼¿ä.

Àú´Â win 2000 server¸¦ °³Àοë PC·Î »ç¿ëÇÏ°í ÀÖ´Â »ç¶÷ÀÔ´Ï´Ù.

ÀÌ·¸°Ô »ç¿ëÇÏ°í ÀÖ´Â ÀÌÀ¯´Â asp¸¦ ±â¹ÝÀ¸·Î ÇÏ¿© À¥¸¶½ºÅ͸¦ °øºÎÇÏ°í ÀÖ³¢ ¶§¹®ÀÔ´Ï´Ù.

ÀÌ·¸°Ô Áú¹®À» ¿Ã¸®´Â ÀÌÀ¯´Â ´Ù¸§ÀÌ ¾Æ´Ï¶ó ¾ó¸¶ÀüºÎÅÍ ÄÄÇ»ÅÍ°¡ ´À·ÁÁö±â ½ÃÀÛÇؼ­ ºÎ·ªºÎ·ª È®ÀÎÀ» Çغôõ´Ï

C:\winnt\system32\¿¡ msgfix.exe, payload.dat µîµîÀÇ ÆÄÀϵéÀÌ µ¹¾Æ´Ù´Ï±â ½ÃÀÚÇß½À´Ï´Ù.

¹ÙÀÌ·¯½º °æ°í°¡ ¶ß´Â´ë·Î Ä¡·á´Â ÇÏ°í ÀÖ½À´Ï´Ù¸¸, ±Ùº»ÀûÀÎ ¿øÀÎÀ» ÇØ°áÇÏÁö ¸øÇÏ´Â °Í °°½À´Ï´Ù.

Á¦°¡ ¾Æ´Â°Ô ¾ø¾î Á¤È®ÇÑ ¼³¸íÀ» µå¸®Áö ¸øÇÔÀ» ¿ë¼­ÇØ ÁÖ½Ã°í ºÎµð ÇØ°á¹æ¾ÈÀ» ¾Ë·ÁÁÖ½Ã¸é °¨»çµå¸®°Ú½À´Ï´Ù.

1. O/S : Win 2000 Server (SP4)

2. »ç¿ëÁßÀÎ ¹é½Å ÇÁ·Î±×·¥ : Virobot Expert 4.0 (Á¤Ç°ÀÔ´Ï´Ù. Á¦°¡ °®°í ÀÖ´Â°Ô ÀÌ°Å ¹Û¿¡ ¾ø¾î¼­ ´Ù¸¥ ½¦¾î¹öÀüÀÇ ¹é½ÅÀº »ç¿ëÇϱⰡ Á» ±×·¸´õ¶ó±¸¿ä)

3. Áõ»óµé


(1) Root µð·ºÅ丮³ª System32¿¡ ¾Æ·¡¿Í °°Àº ÆÄÀϵéÀÌ »ý¼ºµË´Ï´Ù.

skssve.exe, msgfix.exe, payload.dat µîµî

(2) ·¹Áö½ºÆ®¸®¿¡ Run, RunOnce µî¿¡ À§ÀÇ ÆÄÀϵéÀ» ½ÇÇàÇϵµ·Ï ³ª¿É´Ï´Ù.

-------------------------
ÀÌ°ÍÀÌ ¸¸¾à ¹éµµ¾î¶ó¸é ¾î¶»°Ô ¸·À»¼ö ÀÖ³ª¿ä? ¾î¶»°Ô Ä¡·áÇÒ ¼ö ÀÖ´Â °ÍÀϱî¿ä?

ÀÌ·±°É ¿¹¹æÇϱâ À§Çؼ­´Â ¾î¶»°Ô ÇÏ´Â °ÍÀÌ °¡Àå ÁÁÀ»±î¿ä?
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-03-12 13:19||
ÀÏ´Ü Áú¹®Çϱâ Àü¿¡ Áú¹®½Ã À¯ÀÇ »çÇ×À» Àаí Áú¹®ÇϽñ⠹ٶø´Ï´Ù. ¾Æ¿ï·¯ °Ô½ÃÆÇÀ» °Ë»öÇغ¸¸é ¾Ë ¼ö ÀÖÁö¸¸ ´Ô°ú ºñ½ÁÇÑ Áú¹®À» ¿Ã¸®´Â »ç¶÷µéÀÌ ²Ï µË´Ï´Ù. ¾Æ¿ï·¯ ±×·± °Ô½Ã¹° ¸¶³ª HijackLog¸¦ ¿äûÇÏ´Â ±Ûµµ ÇÔ²² º¼ ¼ö ÀÖÀ» °Ì´Ï´Ù.

´Ôó·³ ¹éµµ¾î³ª ¾Ç¼º ½ºÅ©¸³Æ®°¡ ¼³Ä¡µÈ °æ¿ì ¹Ýµå½Ã ÇÊ¿äÇÑ ÃÖ¼Ò Á¤º¸°¡ HiJack LogÀÔ´Ï´Ù. Hijack Log¸¦ ÀÛ¼ºÇÒ ÁÙ ¸ð¸£´Ù´Â ±Ûµµ ¿Ã¶ó¿Í ÀÛ¼ºÇÏ´Â ¹æ¹ý±îÁö ÀÌ¹Ì ÆÁÀ¸·Î ¿Ã·ÁµÐ »óÅÂÀÔ´Ï´Ù.

µû¶ó¼­ Áú¹®Çϱâ Àü¿¡ ¸ÕÀú °Ë»öÀ» Çغ¸½Ã°í, ÇÊ¿äÇÑ Á¤º¸¸¦ Á¦°øÇØ¾ß ´äº¯ÀÌ °¡´ÉÇÕ´Ï´Ù.

ÀÏ´Ü ´ÔÀÇ HijackLog°¡ ¾ø±â¶§¹®¿¡ ¸ðµç ½ÇÇàÅ°¸¦ ¹é¾÷ÇÏ°í, »èÁ¦ÇÏ´Â °ÍÀ¸·Î ÁøÇàÇÏ°Ú½À´Ï´Ù. ÀÌ ¹æ¹ýÀ¸·Î Á¤»óÀûÀ¸·Î »èÁ¦µÈ´Ù¸é ½ÇÇà Å°¸¦ º¹±¸ÇÏ°í, msgfix.exe¿¡ °ü·ÃµÈ ½ÇÇàÅ°(Configuration Loader)¸¸ »èÁ¦ÇϸéµË´Ï´Ù.

1. ½Ã½ºÅÛÀ» Á¾·áÇÏ°í F8¸¦ ´­·¯ OS ¸Þ´º È£Ãâ
2. ¾ÈÀü ¸ðµå(¸í·É ÇÁ·ÒÇÁÆ® »ç¿ë)·Î ·Î±×ÀÎ
3. ¸í·ÉÇà¿¡¼­ ´ÙÀ½ ¸í·É ½ÇÇà
dir /s C:\msgfix.exe
4. ¹ß°ßµÈ ¸ðµç msgfix.exe »èÁ¦
5. ¸í·ÉÇà¿¡¼­ ´ÙÀ½ ¸í·É ½ÇÇà
dir /s C:\skssve.exe
6. ¹ß°ßµÈ ¸ðµç skssve.exe »èÁ¦
7. ±×¿Ü dir ¸í·ÉÀ¸·Î msgfix.exe °ü·Ã ÆÄÀÏÀ» ã¾Æ¼­ »èÁ¦
8. ¸í·ÉÇà¿¡¼­ ´ÙÀ½ ¸í·É ½ÇÇà

reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run LRun.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce LRunOnce.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx LRunOnceEx.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices LRunServices.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce LRunServicesOnce.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\Run CRun.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce CRunOnce.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx CRunOnceEx.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices CRunServices.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce CRunServicesOnce.hiv

reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

°ªÀ» »èÁ¦ÇÏÁö ¾Ê°í Å°¸¦ »èÁ¦ÇÑ ÀÌÀ¯´Â ´ÔÀÇ Hijack Log°¡ ¾ø±â¶§¹®ÀÔ´Ï´Ù.

P.S. 1. ÆÁÀ» ÁøÇàÇϱâÀü¿¡ HiJack Log¸¦ ¸ÕÀú ÀÛ¼ºÇÑ ÈÄ HiJack ·Î±×¸¦ Á¦ ¸ÞÀÏ·Î º¸³»Áֱ⠹ٶø´Ï´Ù.
P.S. 2. msgfix.exe¿Í skssve.exe°¡ ¹ß°ßµÈ Æú´õ¸¦ ¾Ë·ÁÁֱ⠹ٶø´Ï´Ù.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-03-15 11:08||
payload.dat ´Â agobotÀ̳ª sdbot °ú °°Àº bot·ùÀÇ backdoor¿¡ °¨¿°µÇ¾úÀ»¶§ »ý¼ºµÇ´Â trojanÀÇ »çº»ÀÔ´Ï´Ù.

¹éµµ¾î°¡ ÀÌ¹Ì µé¾î¿Í¼­ µ¹¾Æ´Ù´Ï±â ½ÃÀÛÇß´Ù¸é ±¸¼®¿¡ ¼û¾îÀÖ´Â °ÍµéÀÌ ¸»¾¸ ÇϽŰŠ¿Ü¿¡µµ ´õ ÀÖÀ» È®·üÀÌ ³ô½À´Ï´Ù.

Á¦ÀÏ ¸ÕÀú
1. º¸¾È ÆÐÄ¡°¡ Àß µÇ¾ú´ÂÁö È®ÀÎÇϽðí
2. °ü¸®ÀÚ °èÁ¤¿¡ º»ÀÎÀÌ ±â¾ï ÇÒ ¼ö ÀÖ´Â ¾î·Á¿î ¾ÏÈ£¸¦ °É¾îÁÝ´Ï´Ù.
3. ÀÎÅÍ³Ý ÀÓ½ÃÆÄÀÏ, %TEMP%Æú´õ µî¿¡ ³²¾ÆÀÖ´Â ºÒÇÊ¿äÇÑ ÆÄÀϵéÀ» ¸ðµÎ Á¦°ÅÇÏ°í
4. ¹é½ÅÀ» ÀÌ¿ëÇÏ¿© Çϵåµð½ºÅ© Àüü ÆÄÀÏÀ» °Ë»çÇϼ¼¿ä.

Âü°í·Î bot·ù¿¡ ´ëÇÑ Áø´ÜÀ²Àº ¿Ü»ê¹é½ÅÀÌ ³ôÀº Æí ÀÔ´Ï´Ù.
¹ÙÀ̷κ¿µµ À̹ø´ÞºÎÅÍ ºñÆ®µðÆæ´õ ¿£ÁøÀ» Àû¿ëÇؼ­ »ó´çÇÑ ¼º´É Çâ»óÀÌ ÀÖ´Ù°í Çϳ׿ä. ÃֽŠ¹öÁ¯À¸·Î ¾÷µ¥ÀÌÆ® Çؼ­ »ç¿ëÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.
´ÙÀ½±Û: Çϵåµð½ºÅ© »óÅ°¡ ¸Å¿ì ÁÁÁö ¾Ê½À´Ï´Ù. (1)4208numberup2005-09-09
ÀÌÀü±Û: ÄÚµ¦ Áú¹® (0)4263dyoverdx2005-01-05

»õ±Û¾²±â ´ä±Û¾²±â
À̵¿:

¼¼»ó»ç´Â À̾߱â



RSS ±¸µ¶ (À͸í | ȸ¿ø | °­Á | Æ÷·³)
(C) 1996 ~ 2017 QAOS.com All rights reserved.