English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24058
À§Çèµµ 40
Æ÷Æ® 1001,9580,6711
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Theef ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Theef´Â 2001³â 5¿ù¿¡ µ¨ÆÄÀÌ 3.0(Delphi 3.0)·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÇöÀç ¹öÀü 1.1, 1.2, 1.21, 1.22, 1.23, 1.30, 1.31, 1.33, 1.34, 1.35, 1.37, Lite 1.0, Lite 1.11ÀÌ ¹èÆ÷µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î´Â ¹öÀü¿¡ µû¶ó »ç¿ëÇÏ´Â Æ÷Æ®, ÀÚµ¿ ½ÇÇà ¹æ¹ý, ÆÄÀÏ À̸§, ±â´É µî ¸¹Àº Â÷À̰¡ ÀÖ´Ù.

* ·¹Áö½ºÆ®¸® À§Ä¡:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run (V1.1, 1.2, 1.22, 1.23, 1.37, Lite 1.0, 1.11)
- HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices (V1.22, 1.23)
- HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce (V1.22, 1.23)

* ·¹Áö½ºÆ®¸® °ª:
- ocxreg(V1.1, 1.2, 1.22, 1.23), Queue(V1.37), AutoUpdate(Lite 1.0), UpdateComponent(Lite 1.11)

* °ª µ¥ÀÌÅÍ:
- C:\WINDOWS\SYSTEM\ocxreg.exe(V1.1, 1.2, 1.22, 1.23)
- c:\windows\Queue.exe(V1.37)
- C:\WINDOWS\wincheck.exe(Lite 1.0)
- C:\WINDOWS\Lib32.exe(Lite 1.11)

* µðÆúÆ® »ç¿ë Æ÷Æ®:
- 1001(V1.1) 1001, 1005, 1000 (V1.2)
- 1001, 3000, 1005 (V1.22, 1.23)
- 6711 (V1.37)
- 9580 (Lite 1.0, 1.11)

* ±¸¼º ÆÄÀÏ:
- client.exe, server.exe (V1.1, 1.2)
- theef.exe, server.exe, editserver.exe (V1.22, 1.23)
- client137.exe, server137.exe, editserver137.exe (V1.37)
- Client.exe, theefliteserver.exe (Lite 1.0)
- Client_1.11.exe, theefliteserver.exe (Lite 1.11)

¿ø°ÝÁö °ø°ÝÀÚµéÀº À̸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù:
- ½Ã½ºÅÛ Á¤º¸ ȹµæ
- ÇÁ·Î¼¼½º º¸±â/Á¾·á/°¨Ãã
- Ű ·Î°Å(key logger)
- ij½¬µÈ, ³Ü½ºÅÍ, À©Áý ÆÐ½º¿öµå ȹµæ
- ½Ã½ºÅÛ Á¾·á/ÀçºÎÆÃ/Log Off/°­Á¦ Á¾·á
- µå¶óÀÌºê Æ÷¸Ë
- ¹æÈ­º®, ¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥, ¹éµµ¾î Á¦°Å ÇÁ·Î±×·¥ Á¾·á
- ¸Þ½ÃÁö ¹Ú½º, ºí·ç ½ºÅ©¸°(½Ã½ºÅÛ Àå¾ÖÈ­¸é) ¶ç¿ì±â
- CMOS ¼³Á¤ Áö¿ì±â
- Áñ°Üã±â ȹµæ
- ÆÄÀÏ °ü¸®(´Ù¿î·Îµå, ¾÷·Îµå, ½ÇÇà, Àб⠵î)
- ÇöÀç ¿¬°áµÈ ¼­¹ö ÇÁ·Î±×·¥ÀÇ ¼³Á¤(ÆÐ½º¿öµå, Æ÷Æ®, ¼­¹ö¸í µî) ÆíÁý
- ¼­¹ö ÇÁ·Î±×·¥ Á¦°Å/Á¾·á/Àç½ÃÀÛ

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.megasecurity.org/trojans/t/theef/Theef_all.html
http://www.tlsecurity.net/backdoor/theef.backdoor.html
http://theef.4-all.org/
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

* ¹öÀü 1.1, 1.2ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "ocxreg" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª ocxreg.exe ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ ocxreg.exe ¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü 1.22, 1.23ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices,
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "ocxreg" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª ocxreg.exe ¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ ocxreg.exe ¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü 1.37ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "Queue" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Queue.exe¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Queue.exe¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü Lite 1.0ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "AutoUpdate" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª wincheck.exe¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ wincheck.exe¸¦ Á¦°ÅÇÑ´Ù.

* ¹öÀü Lite 1.11ÀÇ °æ¿ì,
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ "UpdateComponent" ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Lib32.exe¸¦ Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Lib32.exe¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)