| Ãë¾àÁ¡ID |
24046 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
60411 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡¼ Connection ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù. ConnectionÀº 2000³â 5¿ù¿¡ ºê¶óÁú¿¡¼ ¸¸µé¾îÁø Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥À¸·Î ¸Å¿ì ´Ü¼øÇÏÁö¸¸ Ä¡¸íÀûÀÎ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü 1.0, 1.1, 1.2, 1.3ÀÌ ¹èÆ÷µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ Connection.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â Normal, Virus µÎ °¡Áö ¹öÀüÀÇ ¼¹öÇÁ·Î±×·¥ÀÎ winoldap.exe·Î ±¸¼ºµÇ¾î ÀÖ´Ù. Virus ¼¹ö´Â ´Ù¸¥ (.exe) ½ÇÇà ÆÄÀÏ¿¡ ÀÚ½ÅÀ» ºÎÂø½ÃŰ´Â ¹ÙÀÌ·¯½º¿Í °°ÀÌ µ¿ÀÛÇÑ´Ù. ±âº»ÀûÀ¸·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 60411 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ¹öÀü 1.2¿Í 1.3 Àº ¹éµµ¾î ÇÁ·Î±×·¥À» µ¿ÀÛ½Ã۱â À§ÇØ mSwinsck.ocx ¿Í msvbvm50.dll ÆÄÀϵéÀ» ÇÊ¿ä·Î ÇÑ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ÀÌ ¹éµµ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é 'HKEY_CURRNET_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼ C:\win\system\winrun.exe °ªÀ» °¡Áø "Winrun" ۰¡ ¹ß°ßµÈ´Ù.
¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Connection ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
- ÆÄÀÏ ½Ã½ºÅÛ ³»¿ë º¸±â - ij½¬µÈ(cashed) ÆÐ½º¿öµå ȹµæ
* Ãë¾àÇÑ Ç÷§Æû : Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4848.php http://www.tlsecurity.net/backdoor/connection.htm http://www.megasecurity.org/trojans/connection/ |
| ÇØ°áÃ¥ |
½Ã½ºÅÛ¿¡¼ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ 'Winrun' ۸¦ Á¦°ÅÇÑ´Ù. 2. C:\win\system\winrun.exe ÆÄÀÏÀÌ Á¸ÀçÇÏ¸é »èÁ¦ÇÑ´Ù. 3. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇÑ´Ù.
-- ¶Ç´Â --
¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|