English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24056
À§Çèµµ 40
Æ÷Æ® 15382
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ SubZero ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.

SubZero´Â 2000³â 12¿ù¿¡ µ¨ÆÄÀÌ(Delphi)·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎSubZero.exe, ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ server.exe ·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ±âº»ÀûÀ¸·Î 15382 TCP Æ÷Æ®¸¦ »ç¿ëÇÏÁö¸¸ Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÇ ¼­¹ö ¼¼ÆÃ ¸Þ´º¸¦ ÅëÇØ¼­ ÀÓÀÇ·Î º¯°æÀÌ °¡´ÉÇÏ´Ù. ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϱâ À§Çؼ­´Â ICQMAPI.dll ÆÄÀÏÀÌ ÇÊ¿äÇÏ´Ù. ÇöÀç ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº °³¹ßÀÌ ÁߴܵǾúÀ¸¸ç ¼Ò½ºÄڵ嵵 °ø°³µÇ¾î ÀÖÁö ¾Ê´Ù. ¹éµµ¾î°¡ µ¿ÀÛÇÏ°Ô µÇ¸é ¹éµµ¾î ÇÁ·Î±×·¥Àº À©µµ¿ìÁî µð·ºÅ丮¿¡ ÀÚ½ÅÀ» º¹»çÇØ ³Ö±â´Â ÇÏÁö¸¸ ·¹Áö½ºÆ®¸® µî·ÏÀº ÇÏÁö ¾Ê´Â´Ù. ¸¸¾à, µî·ÏÀÌ µÈ´Ù¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ C\WINDOWS\SYSTEM\taskmann.dll.exe °ªÀ» °¡Áø "taskmann.dll" ·¹Áö½ºÆ®¸® ۸¦ ¹ß°ßÇÒ ¼ö ÀÖ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ SubZero ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- Ű ·Î°Å(key logger)
- ICQ/AIM/IE/MSN/YAHOO °¨½Ã(spy)
- ¼­¹ö¿Í äÆÃ
- ÇØ»óµµ, º¼·ý(volume), ½ÃÀÛ ¹öư, À©µµ¿ìÁî »ö»ó º¯°æ
- Ŭ·°(clock), ½ÃÀÛ¹öư, ½Ã½ºÅÛ Æ®·¹ÀÌ(systray), ÀÛ¾÷ Ç¥½ÃÁÙ º¸ÀÓ/°¨Ãã/±ÝÁö/Á¦°Å
- ÆÄÀÏ °ü¸®( ÆÄÀÏ °Ë»ö/´Ù¿î·Îµå/½ÇÇà, FTP, ...)
- AIM(AOL ÀνºÅÏÆ® ¸Þ½ÅÀú), RAS(Remote Access Server), ij½¬µÈ(cached) ÆÐ½º¿öµå ȹµæ
- Æ÷Æ® ¸®´ÙÀÌ·ºÆ®(Redirect)
- ¸Þ½ÃÁö Àü´Þ
- URL Àü´Þ
- ÇÁ·Î¼¼½º º¸±â/Á¾·á
- À©µµ¿ìÁî Á¾·á/ÀçºÎÆÃ/·Î±× ¿ÀÇÁ/ÆÄ¿ö ¿ÀÇÁ..
- ½Ã½ºÅÛ Á¤º¸(»ç¿ëÀÚ, ¿î¿µÃ¼Á¦, µå¶óÀ̺ê, µð·ºÅ丮 Á¤º¸) ȹµæ

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.dark-e.com/archive/trojans/subzero/alpha/index.shtml
http://www.megasecurity.org/trojans/s/subzero/Subzero_alpha.html
http://www.glocksoft.com/trojan_list/SubZero.htm
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "taskmann.dll" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª taskmann.dll.exe ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ taskmann.dll.exe ¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)