º¸¾ÈIT´º½º º¸¾È±Ç°í¹® º¸¾ÈTip º¸¾Èó¹æ º¸¾ÈÅë½Å º¸¾È¿ë¾î º¸¾È¹é½Å¸ÞÀÏ º¸¾ÈĶ¸°´õ
º¸¾ÈÀ§ÇùDB ã±â
º¸¾ÈÄ®·³
¿¡ºê¸®Á¸ Zip¿¡ºê¸®Á¸ See¿¡ºê¸®Á¸ FTP

  º¸¾ÈIT´º½º
  º¸¾È±Ç°í¹®
  º¸¾ÈTip
  º¸¾Èó¹æ
  º¸¾ÈÅë½Å
  º¸¾È¿ë¾î
  º¸¾È¹é½Å¸ÞÀÏ
  º¸¾ÈĶ¸°´õ
  º¸¾ÈÀ§ÇùDBã±â
  º¸¾ÈÄ®·³

   º¸¾ÈÀ§ÇùDBã±â
   
  
 ¸ñ·Ï |  À­±Û |  ¾Æ·§±Û  
Backdoor-W32/IRCBot.18944.C
 ¹ÙÀÌ·¯½º Á¾·ù
Backdoor
 ½ÇÇàȯ°æ
Windows
 ¹ß°ßÀÏ
2007³â03¿ù26ÀÏ
 Á¦ÀÛÁö
ºÒºÐ¸í
 À§Çèµî±Þ
À§Çè
 È®»ê¹æ¹ý
¸Þ½ÅÀú
 ¹ÙÀÌ·¯½º Å©±â
18,944 Byte
 Ã·ºÎÆÄÀÏ
photo album.zip
 ¸ÞÀÏÁ¦¸ñ
  
 Áõ»ó¿ä¾à
  MSN ¸Þ½ÅÀú¸¦ ÅëÇؼ­ ÀüÆÄµÇ¸ç °¨¿°µÈ ½Ã½ºÅÛÀº À©µµ¿ì Æú´õ¿Í À©µµ¿ì ½Ã½ºÅÛ Æú´õ¿¡ ¾Ç¼ºÄڵ带 »ý¼ºÇÑ´Ù.
 Ä¡·á¹æ¹ý

Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.



  
 
»ó¼¼¼³¸í

*°¨¿° °æ·Î


MSN
¸Þ½ÅÀú¸¦ ÅëÇØ ÀüÆĵȴÙ.



*Áõ»ó

 

 photo album.zip À̶ó´Â ÆÄÀϸíÀ¸·Î msn¸Þ½ÅÀú¸¦ ÅëÇØ È®»êµÇ¸ç photo album.zip ÆÄÀϼӿ¡´Â photo album.pif ÆÄÀÏÀÌ ¾ÐÃàµÇ¾î ÀÖ´Ù.

 

 ÀÌ ÆÄÀÏÀ» ½ÇÇàÇϸé À©µµ¿ì Æú´õ¿Í ½Ã½ºÅÛ Æú´õ¿¡ photo album.zip, rdshost.dll ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.

¶ÇÇÑ msnÀ¸·Î ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö¸¦ º¸³½´Ù.

 

      -      lol my sister wants me to send you this photo album 

-         HEY lol i''''''''''''''''ve done a new photo album !:) Second ill find file and send you it.  

-          - Hey wanna see my new photo album?  

-         OMG just accept please its only my photo album!!

-         Hey accept my photo album, Nice new pics of me and my friends and stuff and when i was young lol... 

- Hey just finished new photo album! :) might be a few nudes ;) lol...     

- hey you got a photo album? anyways heres my new photo album :) accept k?     

- hey man accept my new photo album.. :( made it for yah, been doing picture story of my life lol..

 

 

-ÆÄÀÏ »ý¼º

 

Backdoor °¡ ½ÇÇà µÇ¸é, ÀϹÝÀûÀ¸·Î À©µµ¿ì Æú´õ¿¡ photo album.zipÆÄÀÏÀÌ ¼³Ä¡ µÈ´Ù
-
photo album.pif(Backdoor-W32/IRCBot.18944.C) ÆÄÀÏÀÌ ¾ÐÃàµÇ¾î ÀÖÀ½

 

-À©µµ¿ì Æú´õ¶õ?

-          À©µµ¿ì 95/98/ME/XP  - C:\Windows\

-          À©µµ¿ì NT/2000       -C:\WinNT\

 

Backdoor °¡ ½ÇÇà µÇ¸é, ÀϹÝÀûÀ¸·Î À©µµ¿ì ½Ã½ºÅÛ Æú´õ¿¡ rdshost.dll(Backdoor-W32/IRCBot.14848.B) ÆÄÀÏÀÌ ¼³Ä¡ µÈ´Ù


-
À©µµ¿ì ½Ã½ºÅÛ Æú´õ¶õ?

-          À©µµ¿ì 95/98/ME     - C:\Windows\System,

-          À©µµ¿ì NT/2000      -C:\WinNT\System32

-          À©µµ¿ì XP           - C:\Windows\System32

 

 

-·¹Áö½ºÆ®¸® µî·Ï.


°¨¿°µÈ ½Ã½ºÅÛÀº ÀÚ½ÅÀ» ´ÙÀ½°ú °°ÀÌ ·¹Áö½ºÆ®¸®¿¡ µî·ÏÇØ ´ÙÀ½ ºÎÆýà ½ÇÇàµÇµµ·Ï Á¶ÀÛ ÇÑ´Ù.


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad
rdshost = {829053f7 6ED6 4557 95D4- 628CF4C5946D}

HKEY_CLASSES_ROOT\CLSID\{829053f7 – 6ED6 – 4557 – 95D4- 628CF4C5946D}\InProcServer32
(±âº»°ª) = rdshost.dll


°¨¿°µÈ
½Ã½ºÅÛÀº TCP 8080 Æ÷Æ®¸¦ LISTENING »óÅ·Π¿­¾îµÐ´Ù. (»ó´ë·ÎºÎÅÍ Á¢¼ÓÀ» ±â´Ù¸®´Â »óÅÂ)

±× ÈÄ »ç¿ëÀÚ ¸ô·¡ Á¢¼Ó ÇØ ½ºÆÔ ¸ÞÀÏ ¹ß¼Û, ¾Öµå¿þ¾î ¼³Ä¡, µ¥ÀÌÅÍ »èÁ¦, ±×¸®°í °³ÀÎÀÇ ÄÄÇ»ÅÍ »ç¿ë ³»¿ªÀ» ÈÉÃĺ¸°Å³ª °¢Á¾ ÆÄÀÏ(°³ÀÎ ¹®¼­, ±â¹Ð ¹®¼­ µî)À» ¿ÜºÎ·Î »©°¡´Â º¸¾È»ó ¹®Á¦µµ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. 


¹éµµ¾î·Î¼­ µ¿ÀÛ ÇϰԵǸé, ´ÙÀ½°ú °°Àº ½Ã½ºÅÛ ¿Àµ¿ÀÛÀÌ ÀϾ ¼ö ÀÖ´Ù.

1.
ÆÄÀÏ ½ÇÇà¹× »èÁ¦
2.
Æ÷Æ®°¨½Ã
3.
Å°º¸µå ŸÀÌÇÎ ³»¿ë ÀúÀå
4.
ÆÄÀÏ ´Ù¿î·Îµå
5. ftp
¹× IRC ¼­¹ö·Î µ¿ÀÛ°¡´É
6.
½Ã½ºÅÛ Çϵå¿þ¾î Á¤º¸ ¼öÁý

 
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇعè»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
 ¸ñ·Ï