|
|
|

 |
|
 |
¹ÙÀÌ·¯½º¸í
|
Trojan.PWS.Snap |
ÇüÅ |
Æ®·ÎÀÌ ¸ñ¸¶ |
ÀüÆÄ¹æ¹ý |
¾Ç¼º¾Öµå¿þ¾î ȤÀº ¾×Ƽºê¾×½º ÄÁÆ®·Ñ¿¡ ÀÇÇØ ´Ù¿î·Îµå µÇ¾îÁö´Â°ÍÀ¸·Î º¸ÀδÙ. |
¿î¿µÃ¼Á¦ |
Windows Ç÷§Æû |
Á¤º¸ÀÛ¼ºÀÏ |
2006-08-29 |
ÆÐÅÏ
¾÷µ¥ÀÌÆ®ÀÏ |
2006-07-27 |
º°Äª |
Trojan-PSW.Win32.Sinowal, Trojan.Anserin |
°£·«È÷ |
¤· °¨¿°½Ã½ºÅÛÀÇ ½Ã½ºÅÛ Á¤º¸ ¹× »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ ÀÎÅÍ³Ý ¹ðÅ· »çÀÌÆ®ÀÇ Á¢¼ÓID ¹× ÆÐ½º¿öµå µîÀÇ Á¤º¸¸¦ ¿ÜºÎ·Î À¯Ãâ½ÃŲ´Ù.
¤· °¨¿°½Ã½ºÅÛ¿¡¼ ½ÇÇàÁßÀÎ ¸ðµç ÇÁ·Î¼¼½º¿¡ ÀÎÁ§Æ® µÇ¾î µ¿ÀÛÇÑ´Ù.
¤· °¨¿°½Ã½ºÅÛ¿¡ Á¸ÀçÇÏ´Â ¸ÞÀÏ Å¬¶óÀÌ¾ðÆ® ¹× FTP Ŭ¶óÀÌ¾ðÆ®¸¦ ÅëÇØ ¿ÜºÎ·Î Á¤º¸¸¦ À¯Ãâ½ÃŲ´Ù.
¤· ƯÁ¤ Æ÷Æ®¸¦ ¿°í Àΰ¡µÇÁö ¾ÊÀº ¿ÜºÎÀÇ Á¢±Ù¿¡ ´ë±âÇÑ´Ù. (TCP 8886, TCP 8906) |
Á¶Ä¡¹æ¹ý |
[»çÀü¿¹¹æ]
- ¹ÙÀÌ·¯½º üÀ̼ ½Ç½Ã°£ °¨½Ã±â¸¦ Ȱ¼ºÈ ½ÃŲ´Ù.
[¼öµ¿Ä¡·á]
A. ´ÙÀ½°ú °°Àº ·¹Áö½ºÆ®¸® °ªÀ» ¼öÁ¤ÇÏ¿© Trojan.PWS.SnapÀÌ ÀÚµ¿À¸·Î ½ÇÇàµÇÁö ¸øÇϵµ·Ï ÇÑ´Ù.
[HKLM\SYSTEM32\CurrentControlSet\Winlogon]
"shell" = "Explorer.exe, <°ø¹é»ý·«> "%ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe""¸¦
"shell" = "Explorer.exe"·Î ¼öÁ¤
[HKLM\SOFTWARE\Microsoft\Windows\CurruntVersion\Run]
"shell"= "%ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe" °ª »ý·«
B. ÄÄÇ»ÅÍ Àç½ÃÀÛ
C. Trojan.PWS.SnapÀÇ ±¸¼ºÆÄÀÏ »èÁ¦
´ÙÀ½ÀÇ À§Ä¡¿¡ Á¸ÀçÇÏ´Â Trojan.PWS.SnapÀÇ ±¸¼ºÆÄÀϵéÀ» »èÁ¦ÇÑ´Ù.
- %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe
- %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.dll
- %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00002.dll
- %systemroot%\kl1.exe
- %systemroot%\temp\$_2341233.TMP |
ÀÌÀü±Û |
¾øÀ½ |
´ÙÀ½±Û |
¾øÀ½ |
|
ÀÚ¼¼È÷ |
Trojan.PWS.SnapÀº ¸î°¡Áö Á¾·ùÀÇ º¯Á¾ÀÌ Á¸ÀçÇϸç ÇöÀç ÀÛ¼ºµÇ´Â Á¤º¸´Â 2006³â 7¿ù 27ÀÏ ¹ß°ßµÈ »ùÇÃÀ» ±âÁØÀ¸·Î ÀÛ¼ºµÇ¾ú´Ù.
<¼³Ä¡/Ư¡>
¤· Trojan.PWS.SnapÀÌ ½ÇÇàµÇ¸é ´ÙÀ½°ú °°Àº ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
°æ·Î : %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\
- ibm00001.exe : Trojan.PWS.SnapÀ¸·Î Áø´Ü
- ibm00001.dll : ŰÀÔ·Â À¯Ãâ - Trojan.PWS.SnapÀ¸·Î Áø´Ü
- ibm00002.dll : ¹éµµ¾î ±â´É - Trojan.PWS.SnapÀ¸·Î Áø´Ü
* ±âº»ÀûÀÎ ÇÁ·Î±×·¥ ¼³Ä¡Æú´õ(%ProgramFiles%)
-Windows 9X/ME/NT/2000/XP: C:\Program Files
¤· °¨¿°½Ã½ºÅÛ°ú °ü·ÃµÈ Á¤º¸¸¦ ¼öÁýÇÏ¿© ´ÙÀ½°ú °°Àº ÆÄÀÏ¿¡ ±â·ÏÇÑ´Ù.
- %systemroot%\temp\$_2341233.TMP
* ±âº»ÀûÀÎ À©µµ¿ì Æú´õ(%systemroot%)
-Windows 9X/ME: C:\Windows
-Windows NT/2000: C:\Winnt
-Windows XP: C:\Windows
¤· $_2341233.TMP¿¡´Â ´ÙÀ½°ú °°Àº Á¤º¸°¡ ÀúÀåµÈ´Ù.
- °¨¿°½Ã½ºÅÛÀÇ IP
- °¨¿°½Ã½ºÅÛ¿¡ ÀúÀåµÇ¾îÀÖ´Â Áñ°Üã±â ÁÖ¼Ò
<ÇÁ·Î¼¼½º ÀÎÁ§Æ®>
¤· Trojan.PWS.SnapÀº ½ÇÇàÁßÀÎ ¸ðµç ÇÁ·Î¼¼½º¿¡ ´ÙÀ½°ú °°Àº ÆÄÀÏÀ» ÀÎÁ§Æ® ½ÃŲ´Ù.
- ibm00002.dll
: °¨¿°½Ã½ºÅÛÀÇ Å°º¸µå ÀԷ°ªÀ» °¨½ÃÇÏ¿© ƯÁ¤ »çÀÌÆ®¿¡¼ »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ °ªÀ» ¿ÜºÎ·Î À¯Ãâ½ÃŲ´Ù.
¤· °¨¿°½Ã½ºÅÛÀÇ explorer.exe¿¡ ´ÙÀ½ÀÇ ÆÄÀÏÀ» ÀÎÁ§Æ® ½ÃŲ´Ù.
- ibm00001.dll
: explorer°¡ ƯÁ¤ Æ÷Æ®¸¦ ¿¾î ¿ÜºÎÀÇ Àΰ¡µÇÁö ¾ÊÀº »ç¿ëÀÚ°¡ Á¢±ÙÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.
¤· ibm00001.dll¿¡ ÀÇÇÏ¿© explorer.exe°¡ ¿ÀÇÂÇÏ´Â Æ÷Æ®¹øÈ£´Â ´ÙÀ½°ú °°´Ù.
- TCP 8886
- TCP 8906
<Á¤º¸ À¯Ãâ>
¤· Trojan.PWS.SnapÀÌ ½ÇÇàµÇ¸é ´ÙÀ½°ú °°Àº »çÀÌÆ®·Î Á¢¼ÓÀ» ½ÃµµÇÑ´Ù.
- Á¢¼ÓÁÖ¼Ò1 : kurva<»ý·«>.com
- Á¢¼ÓÁÖ¼Ò2 : hansy<»ý·«>.com
- Á¢¼ÓÆ÷Æ® : 80
¤· Á¢¼ÓÀÌ ¼º°øÇÑ »çÀÌÆ®·Î ´ÙÀ½ÀÇ Á¤º¸µéÀ» Get ¹æ½ÄÀ¸·Î Àü¼ÛÇÑ´Ù.
- ¹ÙÀÌ·¯½º ¹öÀüÁ¤º¸
- °¨¿°½Ã½ºÅÛÀÇ IP
- explorer.exe°¡ ¿ÀÇÂÁßÀÎ Æ÷Æ®¹øÈ£µé
- °¨¿°½Ã½ºÅÛÀÌ À§Ä¡ÇÑ ±¹°¡
¤· ´ÙÀ½°ú °°Àº ÆÄÀÏÀ» ´Ù¿î·Îµå ¹Þ´Â´Ù.
- %systemroot%\kl1.exe : Trojan.PWS.SnapÀ¸·Î Áø´Ü
: kl1.exe´Â ÀÎÅÍ³Ý ¹ðÅ· »çÀÌÆ®ÀÇ ÁÖ¼Ò °ª µîÀÌ ÀúÀåµÇ¾î ÀÖ´Ù.
¤· ibm00002.dllÀº °¨¿°½Ã½ºÅÛ¿¡¼ kl1.exe¿¡ Æ÷ÇÔµÈ ÀÎÅÍ³Ý ¹ðÅ· »çÀÌÆ®¿¡ »ç¿ëÀÚ°¡ Á¢¼ÓÇÏ´ÂÁö °¨½ÃÇϸç, ÇØ´ç »çÀÌÆ®¿¡¼ »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ Å°º¸µå °ªÀ» ´ÙÀ½ÀÇ ÆÄÀÏ¿¡ Ãß°¡ÇÑ´Ù.
- $_2341233.TMP
¤· °¨¿°½Ã½ºÅÛ¿¡ ´ÙÀ½°ú °°Àº ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ¾îÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
- À̸ÞÀÏ Å¬¶óÀ̾ðÆ®
: Outlook Express
: Eudora
: Thunder Bird
: AK-Mail
: TheBat
- FTP Ŭ¶óÀ̾ðÆ®
: Flash FXP
: Total Command
¤· °¨¿°½Ã½ºÅÛ¿¡¼ ÀÌ·¯ÇÑ ÇÁ·Î±×·¥ÀÌ ¹ß°ßµÇ¸é ÇØ´ç ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© ¼öÁýµÈ Á¤º¸¸¦ ¿ÜºÎ·Î À¯Ãâ½ÃŲ´Ù.
¤· ¼öÁýµÈ Á¤º¸´Â $_2341233.TMP ÆÄÀÏ¿¡ ÀúÀåÀÌ µÇ¸ç, À̸¦ ¿ÜºÎ·Î À¯Ãâ½Ãų¶§¿¡´Â ´ÙÀ½°ú °°Àº ÆÄÀϸíÀ¸·Î º¯°æ½ÃŲ ÈÄ Àü¼ÛÇÑ´Ù.
- data.str
<ÀÚµ¿ Àç½ÃÀÛ>
¤· Trojan.PWS.SnapÀº À©µµ¿ì ½ÃÀ۽à ÀÚµ¿À¸·Î ½ÃÀ۵DZâ À§ÇÏ¿© ´ÙÀ½°ú °°ÀÌ ·¹Áö½ºÆ®¸® °ªÀ» ¼öÁ¤ÇÑ´Ù.
[HKLM\SYSTEM32\CurrentControlSet\Winlogon]
"shell" = "Explorer.exe, <°ø¹é»ý·«> "%ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe""
[HKLM\SOFTWARE\Microsoft\Windows\CurruntVersion\Run]
"shell"= "%ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe"
Write-Up by j.y.Han |
ÀÌÀü±Û |
¾øÀ½ |
´ÙÀ½±Û |
¾øÀ½ |
|
|
|
|
|