English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24057
À§Çèµµ 40
Æ÷Æ® 11223
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Progenic ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.

ProgenicÀº 1999³â 4¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷ 6(Visual Basic 6)·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü ¥â1.0, ¥â2.0, ¥â3.0, 1.0, 1.1 ÀÌ ¹èÆ÷µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ Å¬¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥ÀÎ ProgenicT.exe, ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ AntiNuke.exe ·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ±âº»ÀûÀ¸·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 11223 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÀÌ ¹éµµ¾îÀÇ ¼­¹ö ÇÁ·Î±×·¥ÀÌ Ã³À½ ½ÇÇàµÉ ¶§, "Runtime error 403 wrong statement" ¿Í °°Àº ¸Þ½ÃÁö°¡ Ãâ·ÂµÈ´Ù. ±×·¡¼­ »ç¿ëÀÚ´Â ÀÌ ÇÁ·Î±×·¥¿¡ ¿¡·¯°¡ Á¸ÀçÇÏ¸ç ¿Ã¹Ù¸£°Ô ½ÇÇàµÇÁö ¾Ê¾Ò´Ù°í »ý°¢ÇÏÁö¸¸ ½ÇÁ¦·Î ³»ºÎÀûÀ¸·Î ÇÁ·Î±×·¥Àº µ¿À۵ȴÙ. ¹éµµ¾î°¡ µ¿ÀÛÇÏ°Ô µÇ¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ C\windows\scandiskc.exe(¶Ç´Â C:\Windows\Scandiskwr.exe) °ªÀ» °¡Áø "Kernel32(¶Ç´Â Scandisk)" ·¹Áö½ºÆ®¸® ۸¦ ¹ß°ßÇÒ ¼ö ÀÖÀ¸¸ç ¶ÇÇÑ, "win.ini" ÆÄÀϵµ º¯°æµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Progenic ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ij½¬µÈ(cached), E-mail ÆÐ½º¿öµå ȹµæ
- ½Ã½ºÅÛ Á¤º¸(ÇØ»óµµ, »ç¿ëÀÚ¸í, ÄÄÇ»Å͸í, µå¶óÀ̺ê, À©µµ¿ìÁî ¹öÀü, ....) ȹµæ
- ISP ¸í ¹× »ç¿ëÀÚ¸í ȹµæ
- ¸¶Áö¸· ¹æ¹® À¥ ÆäÀÌÁö ¹× ½ÃÀÛ ÆäÀÌÁö Á¤º¸ ȹµæ
- ICQ °æ·Î ¹× UIN ȹµæ
- ÆÄÀÏ °ü¸®
- ICQ Á¾·á
- ½Ã½ºÅÛ ÀçºÎÆÃ ¹× Á¾·á
- ¸¶¿ì½º ¹öư »ç¿ë/±ÝÁö/º¯°æ
- Ű ·Î°Å(key logger : ¸ðµç Űº¸µå ÀÔ·Â Á¤º¸ ȹµæ)
- URL Àü´Þ
- ¼­¹ö ÇÁ·Î±×·¥ Á¾·á ¹× Á¦°Å

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/3119.php
http://www.dark-e.com/archive/trojans/progenic/index.html
http://www.megasecurity.org/trojans/p/progenictrojan/Progenictrojan_all.html
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "Kernel32(¶Ç´Â Scandisk)" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÆíÁý ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© win.ini(º¸Åë C:\windows\win.ini) ÆÄÀÏ¿¡¼­ [Windows] ¾ÈÀÇ "run=c:\windows\scandiskc.exe" ۸¦ Á¦°ÅÇÑ´Ù.
3. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª tscandiskc.exe(¶Ç´Â Scandiskwr.exe) ¸¦ Á¾·áÇÑ´Ù.
4. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ scandiskc.exe(¶Ç´Â Scandiskwr.exe) ¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)