|
이 웜은 4월 28일 부터 전파되기 시작 하였으며 TCP 25 번 포트의 이상 트레픽을 일으킨다.
웜을 포함한 이메일은 아래와 같은 내용을 가지고 있다.
[메일 제목]
Correction
Criminal
Found
Funny
Hurts
Letter
Money
More samples
Numbers
Only love?
Password
Picture
Pictures
Privacy
Question
Stolen
Text
Wow
Illegal
[메일 내용]
현재 까지 알려진 것중 다음에서 선택 된어 진다.
Are your numbers correct?
Do you have more photos about you?
Do you have more samples?
Do you have no money?
Do you have written the letter?
Does it hurt you?
Hey, are you criminal?
How can I help you?
I''''ve found your creditcard. Check the data!
I''''ve your password. Take it easy!
Please do not sent me your illegal stuff again!!!
Please use the font arial!
Still?
The text you sent to me is not so good!
True love letter?
Why do you show your body?
Wow! Why are you so shy?
Your pictures are good!
[첨부파일]
다음에서 선택되어 진다.
abuses.pif
all_pictures.pif
corrected_doc.pif
document1.pif
hurts.pif
image034.pif
loveletter.pif
my_stolen_document.pif
myabuselist.pif
pin_tel.pif
visa_data.pif
your_bill.pif
your_letter.pif
your_picture.pif
your_text.pif
(웜이 발송한 메일의 예)
1. 메일 제목: Stolen
본문 내용: Do you have asked me?
첨부파일 이름: my_stolen_document.pif.
2. 메일 제목: Criminal
본문 내용: Hey, are you criminal?
첨부파일 이름: myabuselist.pif.
[특징]
웜이 실행 되면 다음과 같이 윈도우 폴더 (win 2000, NT : c:\Wint, win XP : c:\windows)에
CSRSS.exe 파일이 생성된다.
이 파일과 동일한 이름을 가진 정상 파일은 윈도우 시스템 폴더에 있다.
또한, 다음처럼 레지스트를 수정하여 다음 부팅시 실행되도록 조작한다.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run 항목에
(win2000, NT의 경우)
BagleAV = c:\winnt\CSRSS.EXE
(WinXP의 경우)
BagleAV = c:\windows\CSRSS.EXE
다음으로 .HTM, .HTML,, .TXT, .WAB, .PHP, .MDX, ,MBX, .MSG 확장자를 지닌 파일에서 메일 주소를 수집하여 웜이 첨부된 메일을 발송한다.
|
|
|