| Ãë¾àÁ¡ID |
24054 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
5880,5802,5838 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡¼ Y3K RAT ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù. Y3K RATÀº 2000³â 5¿ù¿¡ µ¨ÆÄÀÌ(Delphi)·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü 1.0, 1.1, 1.2, 1.3, 1.4, 1.4b, 1.5, 1.6, 1.6 MegaSecurity, Pro 0.1ÀÌ ¹èÆ÷µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ client.exe, ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼¹öÇÁ·Î±×·¥ÀÎ server.exe ¿Í ¼¹ö ÆíÁýÀÌ °¡´ÉÇÑ server editor.exe (¶Ç´Â server builder.exe)·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ±âº»ÀûÀ¸·Î »ç¿ëÇÏ´Â Æ÷Æ®´Â 5880, 5802(v1.6), 5838(pro0.1) TCP Æ÷Æ®ÀÌ¸ç µ¿½Ã¿¡ 5882, 5890, 5803, 5839 TCP, 5888, 5889 TCP/UDP Æ÷Æ®µîµµ »ç¿ëµÈ´Ù. Y3K RATÀº ¹öÀü¸¶´Ù »ç¿ëÇÏ´Â Æ÷Æ® ¹× ÀÚµ¿½ÇÇà Á¤º¸°¡ ÀúÀåµÇ´Â ·¹Áö½ºÆ®¸® Ű¿¡ ¸¹Àº Â÷À̰¡ ÀÖÀ¸¸ç 1.3 ÀÌÈÄ ¹öÀüºÎÅÍ´Â Æ÷Æ®º¯°æµµ °¡´ÉÇÏ´Ù. Y3K RAT ¹éµµ¾î´Â ICQ IP ½º´ÏÆÛ ±â´É°ú °ø°ÝÀÚÀÇ ICQ UINÀ¸·Î °¨¿°µÈ IPÀÇ »óŸ¦ ¾Ë·ÁÁÖ´Â notification(¾Ë¸² ¸Þ½ÃÁö)¸¦ º¸³» ÁÖ´Â ±â´ÉÀÌ ÀÖÀ¸¸ç 40 °¡ÁöÀÇ ±â´ÉÀ» Á¶ÇÕÇÏ¿© ¼¹ö¸¦ ÆíÁýÇÒ ¼öµµ ÀÖ´Ù. ·ÎÄà ȣ½ºÆ®¿¡¼ÀÇ Á¢¼ÓÀ» Çã¿ëÇÏÁö ¾Ê±â ¶§¹®¿¡ ¼¹ö¿Í Ŭ¶óÀÌ¾ðÆ®¸¦ ÇÑ È£½ºÆ®¿¡¼ µ¿½Ã¿¡ »ç¿ëÇÒ ¼ö ¾ø´Ù. ÀÌ ¹éµµ¾î´Â ´Ù¾çÇÑ ·¹Áö½ºÆ®¸® µî·ÏÀÌ °¡´ÉÇϱ⠶§¹®¿¡ »ç¿ëÀÚ¿¡ ÀÇÇØ ¼öµ¿ÀûÀ¸·Î Á÷Á¢ Á¦°ÅÇÏ´Â ¹æ¹ýÀ¸·Î´Â ¹éµµ¾î°¡ ¿ÏÀüÈ÷ Á¦°ÅµÇÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ¹éµµ¾î°¡ µ¿ÀÛÇÏ°Ô µÇ¸é ¹öÀü¿¡ µû¶ó ´ÙÀ½°ú °°Àº ·¹Áö½ºÆ®¸® ۵éÀ» ¹ß°ßÇÒ ¼ö ÀÖ´Ù.
* ·¹Áö½ºÆ®¸® À§Ä¡: 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' (All Versions) 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices' (V1.4, 1.4b, 1.5) 'HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' (V1.4, 1.4b, 1.5)
* ·¹Áö½ºÆ®¸® °ª: Explorer32 (V1.0, 1.1, 1.2) Nvarch16 (V1.3) Msscmc32 (V1.4, 1.4b) Dcomcnofg (V1.5) MSCONFIG (V1.6)
* °ª µ¥ÀÌŸ: C\WINDOWS\Rundll.exe (V1.0, 1.1, 1.2) C\WINDOWS\Nvarch16.exe (V1.3) C\WINDOWS\Advapi32.exe (V1.4, 1.4b) C\WINDOWS\SYSTEM\Dcomcnofg.exe (V1.5) C\WINDOWS\SYSTEM\MSCONFIG.exe (V1.6)
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû : Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4496.php http://www.symantec.com/avcenter/venc/data/backdoor.y3krat.12.html http://www.tlsecurity.net/backdoor/y3k.html |
| ÇØ°áÃ¥ |
½Ã½ºÅÛ¿¡¼ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.
* ¹öÀü 1.0, 1.1, 1.2 ÀÇ °æ¿ì, 1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ '"Explorer32" ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Rundll.exe¸¦ Á¾·áÇÑ´Ù. 3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Rundll.exe¸¦ Á¦°ÅÇÑ´Ù.
* ¹öÀü 1.3 ÀÇ °æ¿ì, 1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ '"Nvarch16" ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Nvarch16.exe¸¦ Á¾·áÇÑ´Ù. 3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Nvarch16.exe¸¦ Á¦°ÅÇÑ´Ù.
* ¹öÀü 1.4, 1.4b ¶Ç´Â 1.5 ÀÇ °æ¿ì, 1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ "Msscmc32(or Dcomcnofg)" ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Nvarch16.exe (or Dcomcnofg.exe) ¸¦ Á¾·áÇÑ´Ù. 3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Nvarch16.exe (or Dcomcnofg.exe)¸¦ Á¦°ÅÇÑ´Ù.
* ¹öÀü 1.6 ÀÇ °æ¿ì, 1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ '"MSCONFIG" ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª MSCONFIG.exe¸¦ Á¾·áÇÑ´Ù. 3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ MSCONFIG.exe¸¦ Á¦°ÅÇÑ´Ù.
-- ¶Ç´Â --
¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|