English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24047
À§Çèµµ 40
Æ÷Æ® 13473
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Chupacabra1.0 ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Chupacabra1.0Àº 1999³â 10¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷ 5(Visual Basic 5)·Î Á¦ÀÛµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ Chupacabra.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ server.exe·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ±âº»ÀûÀ¸·Î´Â º¯°æÀÌ ºÒ°¡´ÉÇÑ 13473 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϱâ À§Çؼ­´Â MSwinsck.ocx ¿Í VB5 ·±Å¸ÀÓ ÆÄÀϵéÀÌ ÇÊ¿äÇÏ´Ù. Chupacabra´Â ¼­¹ö ½Ã½ºÅÛÀ» Æ÷¸ËÇÏ´Â ±â´ÉÀ» °¡Áö°í ÀÖ¾î ÆÄ±«ÀûÀÎ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌÁö¸¸ ´Ù¼Ò ¿À·¡µÇ°í ¸¹Àº ±â´ÉµéÀ» °¡Áö°í ÀÖÁö ¾Ê¾Æ¼­ ³Î¸® »ç¿ëµÇÁø ¾Ê´Â´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ÀÌ ¹éµµ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run', 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices',
'HKEY_CURRNET_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. À§Ä¡¿¡¼­ winprot.exe °ªÀ» °¡Áø "System Protect" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Chupacabra1.0 ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ½Ã½ºÅÛ Á¾·á/·Î±×¿ÀÇÁ/ÀçºÎÆÃ
- ÆÄÀÏ »èÁ¦
- CTRL+ALT+DEL Çã¿ë/±ÝÁö
- ½Ã½ºÅÛ Æ÷¸Ë
- ICQ »ç¿ëÀÚ È¹µæ
- ½Ã°£ ȹµæ
- ÀÛ¾÷ Ç¥½ÃÁÙ °¨Ãã/º¸ÀÓ
- ¸Þ½ÃÁö Àü´Þ
- È­¸é º¸È£±â ½ÇÇà

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/5304.php
http://www.dark-e.com/archive/trojans/chupacabra/10/index.shtml
http://www.tlsecurity.net/backdoor/Chupacabra.htm
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run,
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices,
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'System Protect' ۸¦ Á¦°ÅÇÑ´Ù.
2. win.ini ÆÄÀÏ(´ë°³, c:\windows\win.ini¿¡ À§Ä¡) ¿¡¼­ [Windows] ¿£Æ®¸® ¹Ø¿¡ load=winprot.exe¿Í run=winprot.exe ¸¦ Á¦°ÅÇÑ´Ù.
3. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª winprot.exe¸¦ Á¾·áÇÑ´Ù.
4. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ winprot.exe¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)