English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24050
À§Çèµµ 40
Æ÷Æ® 10085,10086
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Syphillis ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Syphillis´Â 1999³â 11¿ù¿¡ µ¨ÆÄÀÌ 4(Delphi 4)·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ Syphillis.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ shell32.exe·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ±âº»ÀûÀ¸·Î º¯°æ ºÒ°¡´ÉÇÑ 10085
¶Ç´Â 10086 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϱâ À§Çؼ­´Â packet32.dll ÆÄÀÏÀÌ ÇÊ¿äÇÏ´Ù. Syphillis ¹éµµ¾î´Â ICQ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥À¸·Î µ¿ÀÛÇÏ°í ¶ÇÇÑ, ÆÐŶ ½º´ÏÇÎ, UDP ¸Þ½ÃÁö Àü¼Û°ú °°Àº »õ·Î¿î ±â´ÉµéÀ» °¡Áö°í ÀÖ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ÀÌ ¹éµµ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ Shell32.exe °ªÀ» °¡Áø "Win32 Shell" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Syphillis ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ÆÄÀÏ °ü¸®
- ½Ã½ºÅÛ Á¤º¸ ȹµæ(CPU, ³×Æ®¿öÅ©, ¿î¿µÃ¼Á¦, ¸Þ¸ð¸®, ....)
- ½Ã½ºÅÛ ·Î±× ¿ÀÇÁ/Á¾·á
- ¼­¹ö ¼³Á¤/Á¾·á
- ij½¬µÈ(cached) ÆÐ½º¿öµå ȹµæ
- ÀÎÅÍ³Ý ½ÃÀÛ ÆäÀÌÁö ¼³Á¤
- Ű ·Î°Å(key logger)
- ÆÐŶ ½º´ÏÆÛ(packet sniffer)
- ·¹Áö½ºÆ®¸® ÆíÁý(registry editor)
- ÅÚ³Ý(Telnet) Ŭ¶óÀ̾ðÆ®
- UDP ¸Þ½ÃÁö Àü¼Û/¼ö½Å
- Á¢¼Ó/internet history/ÇÁ·Î¼¼½º/½ÇÇà ÇÁ·Î±×·¥/°øÀ¯ º¸±â
- µ¥½ºÅ©Å¾ ¾ÆÀÌÄÜ/½ÃÀÛ ¹öư/ÀÛ¾÷ Ç¥½ÃÁÙ °¨Ãã/º¸ÀÓ
- FTP ¶Ç´Â HTTP ÆÄÀÏ ´Ù¿î·Îµå
- ÆÄÀÏ ½ÇÇà
- ICQ Á¤º¸ ȹµæ
- ICQ »óÅ º¯°æ
- ´ëÈ­»ó´ë Ãß°¡(Add contact)

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4814.php
http://www.dark-e.com/archive/trojans/syphillis/118/index.shtml
http://www.glocksoft.com/trojan_list/Syphillis.htm
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'Win32 shell' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Shell32.exe ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Shell32.exe¸¦ Á¦°ÅÇÑ´Ù. ½Ã½ºÅÛ µð·ºÅ丮 ³»¿¡ Shell32.log ÆÄÀÏÀº ¿ÜºÎ È£½ºÆ®·ÎºÎÅÍ ·Î±×¿ÂµÈ ½Ã°£°ú »ç¿ëÀÚ¿¡ ´ëÇÑ ·Î±× Á¤º¸¸¦ ´ã°í ÀÖ´Ù. .

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)