*감염
경로
MSN
메신저를
통해
전파된다.
*증상
photo
album.zip 이라는 파일명으로
msn메신저를 통해 확산되며 photo
album.zip 파일속에는 photo
album.pif 파일이 압축되어 있다.
이 파일을 실행하면 윈도우 폴더와 시스템 폴더에 photo
album.zip, rdshost.dll 파일을 생성한다.
또한 msn으로 다음과 같은 메시지를 보낸다.
-
lol my sister wants me to send you this photo album
-
HEY lol i''''''''ve done a new photo album !:)
Second ill find file and send you it.
-
- Hey wanna see my new photo
album?
-
OMG just accept please its only my photo
album!!
-
Hey accept my photo album, Nice new pics
of me and my friends and stuff and when i was young lol...
- Hey just
finished new photo album! :) might be a few nudes ;) lol...
- hey you got a
photo album? anyways heres my new photo album :) accept k?
- hey man accept
my new photo album.. :( made it for yah, been doing picture story of my life
lol..
-파일 생성
Backdoor
가
실행
되면,
일반적으로
윈도우
폴더에
photo album.zip파일이
설치
된다 - photo album.pif(Backdoor-W32/IRCBot.18944.C)
파일이
압축되어 있음
-윈도우
폴더란?
-
윈도우
95/98/ME/XP -
C:\Windows\
-
윈도우
NT/2000
-C:\WinNT\
Backdoor
가
실행
되면,
일반적으로
윈도우
시스템
폴더에
rdshost.dll(Backdoor-W32/IRCBot.14848.B)
파일이
설치
된다
-윈도우
시스템
폴더란?
-
윈도우
95/98/ME -
C:\Windows\System,
-
윈도우
NT/2000
-C:\WinNT\System32
-
윈도우
XP
- C:\Windows\System32
-레지스트리
등록.
감염된
시스템은
자신을
다음과
같이
레지스트리에
등록해
다음
부팅시
실행되도록
조작
한다.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad rdshost
= {829053f7 – 6ED6 – 4557 – 95D4- 628CF4C5946D}
HKEY_CLASSES_ROOT\CLSID\{829053f7 – 6ED6 – 4557 – 95D4-
628CF4C5946D}\InProcServer32 (기본값) = rdshost.dll
감염된
시스템은
TCP 8080 포트를
LISTENING 상태로
열어둔다.
(상대로부터
접속을
기다리는
상태)
그
후
사용자
몰래
접속
해
스팸
메일
발송,
애드웨어
설치,
데이터
삭제,
그리고
개인의
컴퓨터
사용
내역을
훔쳐보거나
각종
파일(개인
문서,
기밀
문서
등)을
외부로
빼가는
보안상
문제도
발생할
수
있다. 백도어로서
동작
하게되면,
다음과
같은
시스템
오동작이
일어날
수
있다.
1. 파일
실행및
삭제
2. 포트감시
3. 키보드
타이핑
내용
저장
4. 파일
다운로드
5. ftp및
IRC 서버로
동작가능
6. 시스템
하드웨어
정보
수집
|