½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ Ä¿ÇǴнº Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
 FAQFAQ   °Ë»ö°Ë»ö   ¸â¹ö¸®½ºÆ®¸â¹ö¸®½ºÆ®   »ç¿ëÀÚ ±×·ì»ç¿ëÀÚ ±×·ì   »ç¿ëÀÚ µî·ÏÇϱâ»ç¿ëÀÚ µî·ÏÇϱâ 
 °³ÀÎ Á¤º¸°³ÀÎ Á¤º¸   ºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀ   ·Î±×Àηα×ÀΠ

°¡ÀÔ¾øÀÌ ´©±¸³ª ±ÛÀ» ¾µ ¼ö ÀÖ½À´Ï´Ù. °øÁö»çÇ׿¡ ´ëÇÑ ´ñ±Û±îÁöµµ..




BBS >> ¼³Ä¡, ¿î¿µ Q&A | ³×Æ®¿÷, º¸¾È Q&A | ÀÏ¹Ý Q&A || Á¤º¸¸¶´ç | AWS || ÀÚÀ¯°Ô½ÃÆÇ | ±¸Àα¸Á÷ || °øÁö»çÇ× | ÀǰßÁ¦½Ã
¸ÞÀϰú ³×Æ®¿÷°øÀ¯·Î ÀüÆÄµÇ´Â WORM_NETSKY.B ¿ú

 
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â  
±Û¾´ÀÌ ¸Þ½ÃÁö
truefeel
Ä«Æä °ü¸®ÀÚ


°¡ÀÔ: 2003³â 7¿ù 24ÀÏ
¿Ã¸° ±Û: 1277
À§Ä¡: ´ëÇѹα¹

¿Ã¸®±â¿Ã·ÁÁü: 2004.2.19 ¸ñ, 10:28 pm    ÁÖÁ¦: ¸ÞÀϰú ³×Æ®¿÷°øÀ¯·Î ÀüÆÄµÇ´Â WORM_NETSKY.B ¿ú Àοë°ú ÇÔ²² ´äº¯

Ȥ NETSKY.B ¿úÀ» ¿©·¯ ¹ø ¹Þ´Â´Ù¸é Àú¿¡°Ô Æ÷¿öµùÇØÁÖ¼¼¿ä. ^^ procmailÀ» ÅëÇÑ ÇÊÅ͸µ ¼³Á¤À» À§Çؼ­ÀÔ´Ï´Ù.
¹¹~ Á¦¸ñÀ¸·Î ÇÊÅ͸µÇÏ¸é °£´ÜÈ÷ µÇ±â´Â ÇϰÚÁö¸¸, º¸´Ù Á¤È®ÇÑ ¹æ¹ýÀ¸·Î ¹üÀ§¸¦ Á¼È÷·Á°í Çϰŵç¿ä.

--------------------------------------------------------------------------------------------------
Ãâó : secinfo ¸ÞÀϸµ¸®½ºÆ®

Àοë:

From cert_at_certcc.or.kr Thu Feb 19 09:54:02 2004
Date: Thu, 19 Feb 2004 09:41:16 +0900
Subject: WORM_NETSKY.B


¾È³çÇϽʴϱî?
Çѱ¹Á¤º¸º¸È£ÁøÈï¿øÀÇ CERTCC-KR ÀÔ´Ï´Ù.

ÇöÀçµî±ÞÀ¸·Î ¹ß·ÉµÇ¾úÀ½À» ¾Ë·Áµå¸³´Ï´Ù.

==============================================================
VN2004048: WORM_NETSKY.B
---------------------------------------------------------------

¡Ù °³¿ä

WORM__NETSKY.B ´Â ¸ÞÀϰú ³×Æ®À§Å© °øÀ¯ Æú´õ¸¦ ÅëÇØ ÀüÆÄµÈ´Ù. 2¿ù18ÀÏ ±¹¿Ü¿¡¼­ óÀ½ ¹ß°ßµÇ¾úÀ¸¸ç ÇöÀç, ±¹³»¿¡¼­µµ ¿©·¯°ÇÀÇ °¨¿° º¸°í°¡ ÀÖ´Ù. À«¿¡ °¨¿°µÇ¸é À©µµ¿ì Æú´õ¿¡ SERVICE.EXE ÆÄÀÏÀÌ ¸¸µé¾îÁø´Ù. ƯÈ÷ ÀüÆÄ¸¦ À§ÇØ ´ë·®ÀÇ ¸ÞÀÏÀ» ¹ß¼ÛÇϹǷΠÁÖÀǰ¡ ¿ä±¸µÈ´Ù.


¡Ù ÀüÆÄ¹æ¹ý

o ¸ÞÀÏÀ» ÀÌ¿ëÇÑ ÀüÆÄ, ³×Æ®¿öÅ© °øÀ¯ Æú´õ¸¦ ÅëÇØ ÀüÆÄµÈ´Ù.
º¸ ³½ ÀÌ : <°¨¿°µÈ ½Ã½ºÅÛ¿¡¼­ ãÀº ¸ÞÀÏ ÁÖ¼Ò¿¡¼­ ÀÓÀÇ·Î ÃßÃâ>
- .msg
- .oft
- .sht
- .dbx
-. tbb
- .adb
- .doc
- .wab
- .asp
- .uin
- .rtf
- .vbs
- .html
- .htm
- .pl
- .php
- .txt
- .eml

Á¦ ¸ñ : <¾Æ·¡ Á¦¸ñ Áß¿¡¼­ ¼±ÅÃ>
- hi
- hello
- read it immediately
- something for you
- warning
- information
- stolen
- fake
- unknown

º» ¹® : <¾Æ·¡ÀÇ º»¹® Áß¿¡¼­ ¼±Åõǰųª, ÀÓÀÇ·Î º¯°æµÉ ¼ö ÀÖ´Ù.>
- anything ok?
- what does it mean?
- ok
- i am waiting
- read the details.
- here is the document.
- read it immediately!
-my hero
- here
- is that true?
- is that your name?
- is that your account?
- i wait for a reply!
- is that from you?
- you are a bad writer
- I have your password!
- something about you!
- kill the writer of this document!
- i hope it is not true!
- your name is wrong
- i found this document about you
- yes really?
- that is bad
- here it is
- see you
- greetings
- stuff about you?
- something is going wrong!
- information about you
- about me
- from the chatter
- here, the serials
- here, the introduction
- here, the cheats
- thats funny
- do you?
- reply
- take it easy
- why?
- thats wrong
- misc
- you earn money
- you feel the same
- you try to steal
- you are bad
- something is going wrong
- something is fool

÷ºÎÆÄÀϸí : ¾Æ·¡ÀÇ ÆÄÀÏ¸í¿¡¼­ ¼±ÅõȴÙ.
- party
- disco
- part2
- mail2
- object
- ranking
- dinner
- release
- final
- location
- jokes
- friend
- website
- mails
- story
- found
- nomoney
- aboutyou
- shower
- topseller
- product
- swimmingpool
- concert
- textfile
- posting
- stuff
- attachment
- details
- creditcard
- message
- document

È®Àå¸í : È®Àå¸í1, È®Àå¸í2 ÀÇ ÇüÅ·Π±¸¼ºµÇ¸ç, È®Àå¸í 1, 2 ´Â ´ÙÀ½°ú °°´Ù.
È®Àå¸í 1.
- .doc
- .htm
- .rtf
- .text

È®Àå¸í 2.
- .exe
- .scr
- .com
- .pif
ex) message.txt.exe, document.htm.scr
³×Æ®À§Å©·Î °øÀ¯µÈ Æú´õ¿¡ ¿ú ÆÄÀÏÀ» º¹»çÇØ ÀüÆÄ µÇ¸ç, ´Ù¸¥ »ç¿ëÀÚ°¡ ÆÄÀÏ À̸§¿¡ ÇöȤµÇ¾î ¿ú ÆÄÀÏÀ» ½ÇÇàÇÏ¸é °¨¿°µÈ´Ù.

÷ºÎÆÄÀϸí : ¾Æ·¡ÀÇ ÆÄÀÏ¸í¿¡¼­ ¼±ÅõȴÙ.
- doom2.doc.pif
- sex sex sex sex.doc.exe
- rfc compilation.doc.exe
- dictionary.doc.exe
- win longhorn.doc.exe
- e.book.doc.exe
- programming basics.doc.exe
- how to hack.doc.exe
- max payne 2.crack.exe
- e-book.archive.doc.exe
- virii.scr
- nero.7.exe
- eminem - lick my pussy.mp3.pif
- cool screensaver.scr
- serial.txt.exe
- office_crack.exe
- hardcore porn.jpg.exe
- angels.pif
- porno.scr
- matrix.scr
- photoshop 9 crack.exe
- strippoker.exe
- dolly_buster.jpg.pif
- winxp_crack.exe


¡Ù ÇÇÇØÁõ»ó

o ¿úÀÌ ½ÇÇàµÇ¸é À©µµ¿ìÁî Æú´õ¿¡ services.exe ·Î ÀÚ½ÅÀ» º¹»çÇÑ´Ù.
¡Ø À©µµ¿ìÁî Æú´õ
¡¤ Windows 2000/NT : C:WINNT
¡¤ Windows XP/95/98/ME : C:Windows

¡Ø À©µµ¿ìÁî ½Ã½ºÅÛ Æú´õ¿¡ ÀÖ´Â service.exe ´Â Á¤»óÆÄÀÏÀ̹ǷΠȥµ¿Çؼ­´Â ¾ÊµÈ´Ù.
¡¤ Windows 2000/NT : C:WINNTSystem32
¡¤ Windows XP : C:WindowsSystem32
¡¤ Windows 95/98/ME : C:WindowsSystem


o ÀçºÎÆÃ ½Ã¿¡µµ ¿úÀÌ µ¿ÀÛÇϱâ À§ÇØ ´ÙÀ½ÀÇ ³»¿ëÀÌ ·¹Áö½ºÆ®¸®¿¡ Ãß°¡µÈ´Ù.
- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRun service = C:WINNTservices.exe -serv

o °¨¿°½Ã ´ÙÀ½¿¡ ³»¿ëÀÌ ·¹Áö½ºÆ®¸®¿¡¼­ »èÁ¦µÈ´Ù.

- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRun Taskmon

- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRun Explorer

- HKEY_CURRENT_USERSOFTWAREMicrosoftWindows
CurrentVersionRun Taskmon

- HKEY_CURRENT_USERSOFTWAREMicrosoftWindows
CurrentVersionRun Explorer

- HKEY_CLASSES_ROOTCLSID{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
InProcServer32


¡Ù °¨¿°½Ã Ä¡·á¹æ¹ý

o ¼öµ¿Ä¡·á¹æ¹ý
- ¾Æ·¡ÀÇ ·¹Áö½ºÆ®¸® Ű °ªÀ» »èÁ¦ÇÑ´Ù.

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
service = %Windir%services.exe -serv

o ¹é½ÅÇÁ·Î±×·¥À» ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÑ ´ÙÀ½ °Ë»çÇÏ¿© Ä¡·áÇÑ´Ù.


¡Ù ¿¹¹æ¹ý

Ãâó°¡ ºÒºÐ¸íÇÑ ¸ÞÀÏÀÏ °æ¿ì ÀÐÁö ¸»°í »èÁ¦ÇÏ¿©¾ß ¿ú °¨¿°À» ¸·À» ¼ö ÀÖ´Ù.


¡Ù ÂüÁ¶»çÀÌÆ®

ÇϿ츮: http://hauri.co.kr/virus/virusinfo/virusinfo_read.html?code=IWW3000476
¾Èö¼ö¿¬±¸¼Ò: http://info.ahnlab.com/smart2u/virus_detail_1319.html
½Ã¸¸ÅØ: http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.b@mm.html
¸Æ¾ÆÇÇ: http://vil.nai.com/vil/content/v_101034.htm
Æ®·£µå¸¶ÀÌÅ©·Î: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.B

À§·Î
»ç¿ëÀÚ Á¤º¸ º¸±â ºñ¹Ð ¸Þ½ÃÁö º¸³»±â ±Û ¿Ã¸°ÀÌÀÇ À¥»çÀÌÆ® ¹æ¹®
ÀÌÀü ±Û Ç¥½Ã:   
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸ ½Ã°£´ë: GMT + 9 ½Ã°£(Çѱ¹)
ÆäÀÌÁö 1 Áß 1

 
°Ç³Ê¶Ù±â:  
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù
¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù
ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù


Powered by phpBB © 2001, 2005 phpBB Group