Win-Trojan/Hotra.49152ÀÇ Áõ»ó°ú º¹±¸
- Áõ»ó
ƯÁ¤ ÇÁ·Î±×·¥ÀÌ ½ÇÇàÀÌ ¾ÈµÇ°Å³ª µô·¹ÀÌÇö»óÀ» º¸ÀδÙ.
- ÀüÆÄ¹æ¹ý
ÇöÀç Win-Trojan/Hotra.49152ÀÇ ÀüÆÄ °æ·Î´Â Á¤È®È÷ ÆÄ¾ÇµÇÁö ¾Ê¾Ò°í ÇöÀç ÆÄ¾Ç ÁßÀÌ´Ù.
- ½ÇÇàÈÄ Áõ»ó
ÆÄÀÏÀÌ ½ÇÇàµÇ¸é ½ÇÇàµÈ Æú´õÀÇ ÆÄÀÏÀ» ´ÙÀ½ ·¹Áö½ºÆ®¸®¿¡ Ãß°¡ÇØ À©µµ¿ì ½ÃÀ۽à ÀÚµ¿½ÇÇàµÇ°Ô ÇÑ´Ù. º¸Åë À©µµ¿ì ½Ã½ºÅÛ Æú´õ(ÀϹÝÀûÀ¸·Î C:WindowsSystem, C:WindowsSystem32, C:WinNTSystem32)¿¡ ¼³Ä¡µÈ´Ù.
HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
Run
¿¡ hotdog.exe µî·Ï
´ÙÀ½ ÆÄÀϵµ Á¸ÀçÇÒ ¼ö ÀÖÀ¸¸ç ÀÌµé ÆÄÀÏÀº µ¥ÀÌÅÍ ÆÄÀÏÀ̹ǷΠV3 Á¦Ç°±º¿¡¼ Áø´Ü/Ä¡·á(»èÁ¦)¾Ê´Â´Ù.
»èÁ¦¸¦ ¿øÇÏ¸é »ç¿ëÀÚ°¡ Á÷Á¢ ÆÄÀÏÀ» ã¾Æ »èÁ¦ÇØÁà¾ßÇÑ´Ù.
- hotdogid.ini
- config_url.txt
- notify_url.txt
- result.txt
ÇöÀç Ä¡·á¹æ¹ý ÀÔ´Ï´Ù.
1. hotdog.exe ÇÁ·Î¼¼¼¸¦ ÁßÁöÇÑ´Ù.
(Ctrl+Alt+Del·Î Windows ÀÛ¾÷ °ü¸®ÀÚ ½ÇÇà ÈÄ hotdog.exe Á¾·á)
2. ÇØ´ç ÆÄÀÏÀ» »èÁ¦ÇÑ´Ù.
À©µµ¿ì ½Ã½ºÅÛ Æú´õ¿¡¼ hotdog.exe³ª extra.exe Á¾·á
WIN98 ¿¹ : C:WindowsSYSTEMHOTDOG.EXE
3. ·¹Áö½ºÆ®¸® ÆíÁý±â ½ÇÇà ÈÄ(regedit.exe) ÇØ´ç ·¹Áö½ºÆ®¸® °ªÀ» »èÁ¦ÇÑ´Ù.
HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
RunÀÇ hotdog.exe
4. ¾Æ·¡ÀÇ ÆÄÀÏÀ» ã¾Æ¼ »èÁ¦ ÇÑ´Ù.
- hotdogid.ini
- config_url.txt
- notify_url.txt
- result.txt
À©µµ¿ì 2000°ú XP »ç¿ëÀÚ
½ÃÀÛ->½ÇÇà->regsvr32 /u c:winntsystem32sav12.dllÀ» ½ÇÇàÇÑ´Ù
À©µµ¿ì 98 »ç¿ëÀÚ
½ÃÀÛ->½ÇÇà->regsvr32 /u c:windowssystemsav12.dllÀ» ½ÇÇàÇÑ´Ù
À©µµ¿ì °øÅë»çÇ×
½ÃÀÛ->½ÇÇà->regedit ½ÇÇàÈÄ ·¹Áö½ºÆ®¸® â¿¡¼
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionexplorerBrowser Helper Objects
ÇÏÀ§ µð·ºÅ丮¿¡ {F6D050E2-42CE-4B27-9588-13FC979FB53D}ÀÌ·±½ÄÀ¸·Î µÈ Æú´õ¸¸ »èÁ¦ÇÏ½Ã¸é º¹¿øÀÌ µÉ°ÍÀÔ´Ï´Ù. º¸Åë ³»¹®¼³ª ³»ÄÄÇ»Å͵îµîÀÇ ÀÀ¿ëÇÁ·Î±×·¥À̳ª ÀϺÎÇÁ·Î±×·¥ÀÌ µ¿ÀÛÀ» ¾ÈÇϰųª µô·¹À̰¡ ½ÉÇÑÁõ»óÀ» ³ªÅ¸³À´Ï´Ù.
¹ÙÀÌ·¯½º ¾ø´Â ¼¼»óÀÇ À§ÇÏ¿©
Ãâó:¾Èö¼ö·¦,ÇϿ츮,WINBBSÀÔ´Ï´Ù.