English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24054
À§Çèµµ 40
Æ÷Æ® 5880,5802,5838
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Y3K RAT ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Y3K RATÀº 2000³â 5¿ù¿¡ µ¨ÆÄÀÌ(Delphi)·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü 1.0, 1.1, 1.2, 1.3, 1.4, 1.4b, 1.5, 1.6, 1.6 MegaSecurity, Pro 0.1ÀÌ ¹èÆ÷µÇ¾î ÀÖ´Ù.
ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ client.exe, ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ server.exe ¿Í ¼­¹ö ÆíÁýÀÌ °¡´ÉÇÑ server editor.exe (¶Ç´Â server builder.exe)·Î ±¸¼ºµÇ¾î ÀÖ´Ù.
±âº»ÀûÀ¸·Î »ç¿ëÇÏ´Â Æ÷Æ®´Â 5880, 5802(v1.6), 5838(pro0.1) TCP Æ÷Æ®ÀÌ¸ç µ¿½Ã¿¡ 5882, 5890, 5803, 5839 TCP, 5888, 5889 TCP/UDP Æ÷Æ®µîµµ »ç¿ëµÈ´Ù.
Y3K RATÀº ¹öÀü¸¶´Ù »ç¿ëÇÏ´Â Æ÷Æ® ¹× ÀÚµ¿½ÇÇà Á¤º¸°¡ ÀúÀåµÇ´Â ·¹Áö½ºÆ®¸® Ű¿¡ ¸¹Àº Â÷À̰¡ ÀÖÀ¸¸ç 1.3 ÀÌÈÄ ¹öÀüºÎÅÍ´Â Æ÷Æ®º¯°æµµ °¡´ÉÇÏ´Ù.
Y3K RAT ¹éµµ¾î´Â ICQ IP ½º´ÏÆÛ ±â´É°ú °ø°ÝÀÚÀÇ ICQ UINÀ¸·Î °¨¿°µÈ IPÀÇ »óŸ¦ ¾Ë·ÁÁÖ´Â notification(¾Ë¸² ¸Þ½ÃÁö)¸¦ º¸³» ÁÖ´Â ±â´ÉÀÌ ÀÖÀ¸¸ç 40 °¡ÁöÀÇ ±â´ÉÀ» Á¶ÇÕÇÏ¿© ¼­¹ö¸¦ ÆíÁýÇÒ ¼öµµ ÀÖ´Ù.
·ÎÄà ȣ½ºÆ®¿¡¼­ÀÇ Á¢¼ÓÀ» Çã¿ëÇÏÁö ¾Ê±â ¶§¹®¿¡ ¼­¹ö¿Í Ŭ¶óÀÌ¾ðÆ®¸¦ ÇÑ È£½ºÆ®¿¡¼­ µ¿½Ã¿¡ »ç¿ëÇÒ ¼ö ¾ø´Ù.
ÀÌ ¹éµµ¾î´Â ´Ù¾çÇÑ ·¹Áö½ºÆ®¸® µî·ÏÀÌ °¡´ÉÇϱ⠶§¹®¿¡ »ç¿ëÀÚ¿¡ ÀÇÇØ ¼öµ¿ÀûÀ¸·Î Á÷Á¢ Á¦°ÅÇÏ´Â ¹æ¹ýÀ¸·Î´Â ¹éµµ¾î°¡ ¿ÏÀüÈ÷ Á¦°ÅµÇÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù.
¸¸¾à, ½Ã½ºÅÛ¿¡ ¹éµµ¾î°¡ µ¿ÀÛÇÏ°Ô µÇ¸é ¹öÀü¿¡ µû¶ó ´ÙÀ½°ú °°Àº ·¹Áö½ºÆ®¸® ۵éÀ» ¹ß°ßÇÒ ¼ö ÀÖ´Ù.

* ·¹Áö½ºÆ®¸® À§Ä¡:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' (All Versions)
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices' (V1.4, 1.4b, 1.5)
'HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' (V1.4, 1.4b, 1.5)

* ·¹Áö½ºÆ®¸® °ª:
Explorer32 (V1.0, 1.1, 1.2)
Nvarch16 (V1.3)
Msscmc32 (V1.4, 1.4b)
Dcomcnofg (V1.5)
MSCONFIG (V1.6)

* °ª µ¥ÀÌŸ:
C\WINDOWS\Rundll.exe (V1.0, 1.1, 1.2)
C\WINDOWS\Nvarch16.exe (V1.3)
C\WINDOWS\Advapi32.exe (V1.4, 1.4b)
C\WINDOWS\SYSTEM\Dcomcnofg.exe (V1.5)
C\WINDOWS\SYSTEM\MSCONFIG.exe (V1.6)

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4496.php
http://www.symantec.com/avcenter/venc/data/backdoor.y3krat.12.html
http://www.tlsecurity.net/backdoor/y3k.html
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

* ¹öÀü 1.0, 1.1, 1.2 ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ '"Explorer32" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Rundll.exe¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Rundll.exe¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü 1.3 ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ '"Nvarch16" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Nvarch16.exe¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Nvarch16.exe¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü 1.4, 1.4b ¶Ç´Â 1.5 ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "Msscmc32(or Dcomcnofg)" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Nvarch16.exe (or Dcomcnofg.exe) ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Nvarch16.exe (or Dcomcnofg.exe)¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü 1.6 ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ '"MSCONFIG" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª MSCONFIG.exe¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ MSCONFIG.exe¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)