|
이 웜은 W32/Netsky.18432의 변종으로 이메일을 통하여 4월 6일 부터 전파되기 시작 했다.
첨부파일의 아이콘 모양은 도스용 프로그램 아이콘으로 되어 있다.
웜을 포함한 이메일은 아래와 같은 내용을 가지고 있다.
[메일 제목]
Approved
Hello
Hello!
Important
My details
Re: Approved
Re: Hello
Re: Hi
Re: Important
Re: My details
Re: Request
Re: Thanks you!
Re: Your details
Re: Your document
Re: Your information
Request
Sample
Thank you!
Your details
Your document
Your information
[메일 내용]
현재 까지 알려진 것중 다음에서 선택 된어 지며 크게 세부분으로 구성되어 있다.
* 본문의 첫부분
Hello!
Hi!
* 본문의 두번째 부분
Approved, here is the document.
For more details see the attached document.
For more information see the attached document.
Here is the <랜덤한 문자열>.
Here is the document.
I have found the <랜덤한 문자열>.
I have sent the <랜덤한 문자열>.
I have spent much time for the <랜덤한 문자열>.
I have spent much time for your document.
It can also include the following:
My <랜덤한 문자열> is attached.
My <랜덤한 문자열>.
Note that I have attached your document.
Please have a look at the <랜덤한 문자열>.
Please have a look at the attached document.
Please notice the attached <랜덤한 문자열>.
Please notice the attached document.
Please read quickly.
Please read the <랜덤한 문자열>.
Please read the attached document.
Please see the <랜덤한 문자열>.
Please, <랜덤한 문자열>.
See the document for details.
The <랜덤한 문자열> is attached.
The <랜덤한 문자열>.
The requested <랜덤한 문자열> is attached!
Your <랜덤한 문자열> is attached.
Your <랜덤한 문자열>.
Your file is attached to this mail.
* 본문의 세번째 부분
Thank you
Thanks
Yours sincerely
[첨부파일]
<랜덤 문자열><랜덤한 숫자>.PIF
(예)
Sample8.pif (18.5K)
랜덤한 문자열은 다음에서 선택되어 진다.
abuse list
account
answer
approved document
approved file
archive
concept
contact list
corrected document
description
detailed document
details
developement
diggest
document
e-mail
excel document
final version
homepage
icq number
important document
improved document
improved file
information
instructions
letter
message
movie document
new document
notice
number list
old document
order
personal message
phone number
photo document
picture document
postcard
powerpoint document
presentation document
release
report
requested document
sample
secound document
story
summary
textfile
user list
word document
(웜이 발송한 메일의 예)
1. 메일 제목: Request
본문 내용
Hi!
Please, excel document.
첨부파일 이름: excel_document8.pif
2. 메일 제목: Your information
본문 내용
Hello!
Please read quickly.
첨부파일 이름: description4.pif
3. 메일 제목: Re: Postcard
본문 내용
Hello!
Please have a look at the postcard.
Thank you
첨부파일 이름: postcard5.pif
[특징]
첨부파일은 특정 문자열과 숫자로 구성되어 있으며 pif확장자를 가진 파일로 전파된다.
처음 실행시에 다음과 같이 윈도우 폴더 (win 2000, NT : c:\Wint, win XP : c:\windows)에 EasyAv.exe, UINMZERTINMDS.OPM 파일이 생성된다.
또한, 다음처럼 레지스트를 수정하여 다음 부팅시 실행되도록 조작한다.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run 항목에
(win2000, NT의 경우)
EasyAV = c:\winnt\EasyAV.EXE
(WinXP의 경우)
EasyAV = c:\windows\EasyAV.EXE
다음으로 .HTM, .HTML,, .TXT, .WAB, .PHP, .MDX, ,MBX, .MSG 확장자를 지닌 파일에서 메일 주소를 수집하여 웜이 첨부된 메일을 발송한다
그리고 2004년 4월 14일 부터 23일 사이에 다음 싸이트에 DoS 공격을 할 수 있게 코딩되 있다.
www.cracks.am
www.emule.de
www.freemule.net
www.kazaa.com
www.keygen.us
또한 레지스트리에 Mydoom, Mimail, Bagle, 등이 생성한 값과 몇가지 레지스트리 값이 삭제 된다.
마지막으로 TCP 6789 포트를 열어 두어 개인정보 유출의 위험을 가지고 있다.
|
|
|