English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24051
À§Çèµµ 40
Æ÷Æ® 17499,17490
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ CrazzyNet ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
CrazzyNetÀº 2000³â 7¿ù¿¡ ¸¸µé¾îÁø ¸¹Àº ±â´ÉµéÀ» Á¦°øÇÏ´Â Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü 3.7, 3.7.1, 3.7.5, 3.7.8, 5.0, 5.2, 5.2.1 °¡ ¹èÆ÷µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ Client.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ Server.exe·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ±âº»ÀûÀ¸·Î ¹öÀü¿¡ µû¶ó º¯°æÀÌ ºÒ°¡´ÉÇÑ 17499 ¶Ç´Â 17490 TCP Æ÷Æ®¸¦ »ç¿ëÇϸç 17500 TCP Æ÷Æ®¸¦ µ¿½Ã¿¡ »ç¿ëÇÑ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ÀÌ ¹éµµ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é
'HKEY_CURRNET_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ Registry32.exe °ªÀ» °¡Áø "Reg32" ۰¡ ¹ß°ßµÈ´Ù. ¶ÇÇÑ, ÀÏ´Ü ¹éµµ¾î°¡ µ¿ÀÛÇϸé win.ini, system.ini ÆÄÀÏÀ» º¯°æ½ÃŲ´Ù. ³×Æ®¿öÅ© »ó¿¡¼­ ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ È£½ºÆ®µéÀ» °Ë»öÇÒ ¼ö ÀÖ´Â NetScanner ±â´ÉÀ» Á¦°øÇÑ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ CrazzyNet ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ij½¬µÈ(cashed) ÆÐ½º¿öµå ȹµæ
- ICQ UIN/»ç¿ëÀÚ È¹µæ
- ½Ã½ºÅÛ »ö»ó ȹµæ
- ¾îÇø®ÄÉÀ̼ǰú ±× °æ·Î ȹµæ
- ½Ã½ºÅÛ Á¤º¸(ÄÄÇ»ÅÍ À̸§, »ç¿ëÀÚ À̸§, ¿î¿µÃ¼Á¦, ÇØ»óµµ, ... )ȹµæ ¹× ¼³Á¤
- È­¸é ĸÃç
- ¸Þ½ÃÁö Àü´Þ
- CrazzyNet Scanner (¹éµµ¾î¿¡ °¨¿°µÈ È£½ºÆ® °Ë»ö)
- ½Ã½ºÅÛ ·Î±× ¿ÀÇÁ/Á¾·á/ÀçºÎÆÃ
- ¸ðµç Űº¸µå ÀÔ·Â ·Î±×ÀÛ¼º (log all keystrokes)
- ÆÄÀÏ °ü¸®(ÆÄÀÏ ¾÷·Îµå/´Ù¿î·Îµå/½ÇÇà)
- À©µµ¿ìÁî ¼¼¼Ç °ü¸®
- ¼­¹ö ÆíÁý

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/5541.php
http://www.tlsecurity.net/backdoor/crazynet.html
http://www.glocksoft.com/trojan_list/CrazzyNet.htm
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'Reg32' ۸¦ Á¦°ÅÇÑ´Ù.
2. system.ini (ÀϹÝÀûÀ¸·Î c:\windows\system.ini) ÆÄÀÏ¿¡¼­ shell=Explorer.exe Registry32.exe ۸¦ shell=Explorer.exe ·Î º¯°æÇÑ´Ù.
3. win.ini(ÀϹÝÀûÀ¸·Î c:\windows\win.ini) ÆÄÀÏ¿¡¼­ [Windows]ÀÇ run=Registry32.exe ¸¦ »èÁ¦ÇÑ´Ù.
4. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Registry32.exe ¸¦ Á¾·áÇÑ´Ù.
5. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Registry32.exe ¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)