에브리존소개 | 제품소개 | 고객센터 | 사이트맵 | Home
개인고객 여성고객 e보안마켓 이벤트
개인고객기업고객
보안접속 ID저장
AD 무료로 책받아가세요!


 목록 |  윗글 |  아랫글  
W32/Netsky.18432@mm
 바이러스 종류
Worm
 실행환경
Windows
 발견일
2004년04월04일
 제작지
불분명
 위험등급
 확산방법
 바이러스 크기
18,432 byte
 첨부파일
sample8.pif 외 다수
 메일제목
  Sample 외 다수
 증상요약
  
 치료방법

터보백신Ai, 터보백신 Online, 터보백신 2001 제품군으로 치료가능.

*터보백신 Ai를 사용하시고 아웃룩을 사용하신 다면 반드시 이메일 감시기를 실행하시기 바랍니다.


  
 
상세설명
이 웜은 이메일을 통하여 4월 4일 부터 전파되었으며 국내에는 4월 6일 부터 전파되기 시작한 것으로 추정된다.
첨부파일의 아이콘 모양은 도스용 프로그램 아이콘으로 되어 있다.


웜을 포함한 이메일은 아래와 같은 내용을 가지고 있다.

[메일 제목]

Approved
Hello
Hello!
Important
My details
Re: Approved
Re: Hello
Re: Hi
Re: Important
Re: My details
Re: Request
Re: Thanks you!
Re: Your details
Re: Your document
Re: Your information
Request
Sample
Thank you!
Your details
Your document
Your information

[메일 내용]

현재 까지 알려진 것중 다음에서 선택 된어 지며 크게 네부분으로 구성되어 있다.

* 본문의 첫부분
Hello!
Hi!

* 본문의 두번째 부분
Approved, here is the document.
For more details see the attached document.
For more information see the attached document.
Here is the <랜덤한 문자열>.
Here is the document.
I have found the <랜덤한 문자열>.
I have sent the <랜덤한 문자열>.
I have spent much time for the <랜덤한 문자열>.
I have spent much time for your document.
It can also include the following:
My <랜덤한 문자열> is attached.
My <랜덤한 문자열>.
Note that I have attached your document.
Please have a look at the <랜덤한 문자열>.
Please have a look at the attached document.
Please notice the attached <랜덤한 문자열>.
Please notice the attached document.
Please read quickly.
Please read the <랜덤한 문자열>.
Please read the attached document.
Please see the <랜덤한 문자열>.
Please, <랜덤한 문자열>.
See the document for details.
The <랜덤한 문자열> is attached.
The <랜덤한 문자열>.
The requested <랜덤한 문자열> is attached!
Your <랜덤한 문자열> is attached.
Your <랜덤한 문자열>.
Your file is attached to this mail.

* 본문의 세번째 부분

Thank you
Thanks
Yours sincerely

* 본문의 네번째 부분

+++ X-Attachment-Type: document
+++ X-Attachment-Status: no virus found
+++ Powered by the new Panda OnlineAntiVirus Visit us:
+++ Website: www.pandasoftware.com

+++ X-Attachment-Type: document
+++ X-Attachment-Status: no virus found
+++ Powered by the new MCAfee OnlineAntiVirus Visit us:
+++ Homepage: www.mcafee.com

+++ X-Attachment-Type: document
+++ X-Attachment-Status: no virus found
+++ Powered by the new F-Secure OnlineAntiVirus Visit us:
+++ Visit us: www.f-secure.com

+++ X-Attachment-Type: document
+++ X-Attachment-Status: no virus found
+++ Powered by the new Norton OnlineAntiVirus Visit us:
+++ Free trial: www.norton.com




[첨부파일]

<랜덤 문자열><랜덤한 숫자>.PIF

(예)
Sample8.pif (29KB)

랜덤한 문자열은 다음에서 선택되어 진다.

abuse list
account
answer
approved document
approved file
archive
concept
contact list
corrected document
description
detailed document
details
developement
diggest
document
e-mail
excel document
final version
homepage
icq number
important document
improved document
improved file
information
instructions
letter
message
movie document
new document
notice
number list
old document
order
personal message
phone number
photo document
picture document
postcard
powerpoint document
presentation document
release
report
requested document
sample
secound document
story
summary
textfile
user list
word document

(웜이 발송한 메일의 예)

메일 제목 Sample

본문 내용

Hi!
Please read the sample.
Thank you

+++ X-Attachment-Type: document
+++ X-Attachment-Status: no virus found
+++ Powered by the new F-Secure OnlineAntiVirus Visit us:
+++ www.f-secure.com

첨부파일 이름 : sample8.pif

[특징]

첨부파일은 특정 문자열과 숫자로 구성되어 있으며 pif확장자를 가진 파일로 전파된다.

처음 실행시에 다음과 같이 윈도우 폴더 (win 2000, NT : c:\Wint, win XP : c:\windows)에 EasyAv.exe, UINMZERTINMDS.OPM 파일이 생성된다.

또한, 다음처럼 레지스트를 수정하여 다음 부팅시 실행되도록 조작한다. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run 항목에
(win2000, NT의 경우)
EasyAV = c:\winnt\EasyAV.EXE

(WinXP의 경우)
EasyAV = c:\windows\EasyAV.EXE

다음으로 .HTM, .HTML,, .TXT, .WAB, .PHP, .MDX, ,MBX, .MSG 확장자를 지닌 파일에서 메일 주소를 수집하여 웜이 첨부된 메일을 발송한다

단 다음과 같은 메일주소로는 감염된 파일을 보내지 않는다.
@antivi
@bitdefender
@f-pro
@f-secur
@freeav
@kaspersky
@mcafee
@messagel
@microsof
@norman
@norton
@pandasof
@skynet
@sophos
@spam
@symantec
@viruslis
abuse@
noreply@
ntivir
reports@
spam@

또한 레지스트리에 Mydoom, Mimail, Bagle, 등이 생성한 값과 몇가지 레지스트리 값이 삭제 된다.

마지막으로 TCP 6789 포트를 열어 두어 개인정보 유출의 위험을 가지고 있다.
 
예방 및 수동조치방법
무단전재ㆍ배포금지
에브리존에서 제공하는 모든 컨텐츠 정보에 대한 저작권은 에브리존의 소유이며 관련법의 보호를 받습니다.
에브리존의 사전 허가 없이 에브리존 컨텐츠를 무단으로 전재, 배포를 금지되어 있습니다.
이를 위반하는 경우 손해배상의 대상 또는 민.형사상의 법적 소송 대상이 될 수 있습니다.
                                                                 * 에브리존 정보 이용 문의 : greenking@everyzone.com
 목록