English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24052
À§Çèµµ 40
Æ÷Æ® 2589,1386
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Dagger ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
DaggerÀº 2000³â¿¡ ºñÁê¾ó C++(Visual C++)·Î ¸¸µé¾îÁø Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü 31.3.1(b), 1.4.0ÀÌ ¹èÆ÷µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ Client.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ Server.exe·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ±âº»ÀûÀ¸·Î »ç¿ëÇÏ´Â Æ÷Æ®´Â º¯°æÀÌ ºÒ°¡´ÉÇÑ 1386(1.3.1b)¶Ç´Â 2589(1.4.0)¸¦ »ç¿ëÇÏ¸ç ¹öÀü¿¡ µû¶ó Â÷À̰¡ ÀÖ´Ù. Dagger 1.4.0 ¹öÀüÀº ÀÌÀü ¹öÀü°ú »ç¿ëÇÏ´Â Æ÷Æ® ¹× ÀÚµ¿½ÇÇà Á¤º¸°¡ ÀúÀåµÇ´Â ·¹Áö½ºÆ®¸® Ű¿¡ Â÷À̰¡ ÀÖ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ¹öÀü 1.4.0ÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run', HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices' À§Ä¡¿¡¼­ C\WINDOWS\System\Manager.exe °ªÀ» °¡Áø "SysManager" ۰¡ ¹ß°ßµÇ°í ±× ÀÌÀü ¹öÀü(1.3.1b)ÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °æ¿ì´Â 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ C\WINDOWS\System\VScan.exe °ªÀ» °¡Áø "WinVirusScan" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Dagger ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ¼­¹ö¿ÍÀÇ Ã¤ÆÃ
- µ¥½ºÅ©Å¾(desktop) Çã¿ë/±ÝÁö
- ÆÄÀÏ °ü¸®( ÆÄÀÏ ´Ù¿î·Îµå, »èÁ¦, ½ÇÇà, ...)
- ½Ã½ºÅÛ Á¤º¸(»ç¿ëÀÚ¸í, À©µµ¿ìÁî Á¦Ç° ¶óÀ̼¾½º Ű(product key), ÇÁ·Î¼¼¼­, ÇØ»óµµ, ... ) ȹµæ
- ÀÛ¾÷ Ç¥½ÃÁÙ ¼û±è/º¸ÀÓ
- ¸Þ½ÃÁö Àü¼Û
- ½Ã½ºÅÛ Á¾·á/ÀçºÎÆÃ
- ¾îÇø®ÄÉÀ̼Ç(Application) º¸±â/Á¾·á
- ¼­¹ö ÇÁ·Î±×·¥ Á¾·á/Á¦°Å

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/6238.php
http://www.megasecurity.org/trojans/d/dagger/Dagger_all.html
http://www.tlsecurity.net/backdoor/Dagger.1.4.html
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

* ¹öÀü 1.3bÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'WinVirusScan' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª VScan.exe ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ VScan.exe ¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü 1.4ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'SysManager' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Manager.exe ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Manager.exe¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)