|
|
|
|
¹ÙÀÌ·¯½º
À̸§ |
Trojan-W32/LineageHack.33381 |
¹ÙÀÌ·¯½º
Á¾·ù |
Trojan |
½ÇÇà
ȯ°æ |
windows |
Á¦ÀÛÁö |
Áß±¹À¸·Î ÃßÁ¤ |
¹ß°ßÀÏ |
20051207 |
¹ÙÀÌ·¯½ºÅ©±â |
33,381 Byte |
¸ÞÀÏ
Á¦¸ñ |
|
÷ºÎÆÄÀÏ |
|
¹ÙÀÌ·¯½º Áõ»ó |
ÀÌ Æ®·ÎÀ̾áÀº µ¨ÆÄÀÌ·Î Á¦À۵Ǿî À©µµ¿ì º¸¾ÈÇêÁ¡°ú ³×Æ®¿÷ °øÀ¯ Æú´õ, À¥¼ÇÎÀ»
ÅëÇÏ¿© ÀüÆĵǸç, ´Ù¸¥ ¹éµµ¾î¿¡ ÀÇÇؼ ¼³Ä¡ ÆÄÀÏÀ» ƯÁ¤ ¼¹ö·ÎºÎÅÍ ¹ÞÀ»¼ö ÀÖ´Ù.
[Ư¡]
½º½º·Î ÀüÆĵǴ ´É·ÂÀº ¾øÀ¸³ª Browser Helper Object ¿Í À©µµ¿ì Ãë¾àÁ¡À» ÀÌ¿ë ÇÏ¿©
ÀͽºÇ÷η¯¿¡ Æ÷ÇԵǰųª, À¥ÆäÀÌÁöÀÇ ½ºÅ©¸³Æ®(iframe ű×ÀÌ¿ë)¿¡ Æ÷ÇԵǴ µîÀÇ
¿©·¯°¡Áö ÀüÆĹæ¹ýÀ» »ç¿ëÇÑ´Ù.
ƯÁ¤ ¿Â¶óÀÎ °ÔÀÓÀÇ ¾ÆÀ̵ð¿Í ºñ¹Ð¹øÈ£ ÀԷ½à Űº¸µå°ªÀ» °¡·Îä¾î
c:\log.dat, c:\game.txt ÅؽºÆ® ÆÄÀÏ¿¡ ±â·Ï, ƯÁ¤ ¸ÞÀÏÁÖ¼Ò·Î Àü¼ÛÇØ
ÀϺΠ°³ÀÎÁ¤º¸ À¯Ãâ À§ÇèÀ» ³»Æ÷ÇÏ°í ÀÖ´Ù.
¶ÇÇÑ c:\program files\common files\microsoft shared\inetdll.dll(33,381 Byte)
¿Í c:\internet.exe(33,381 byte)ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
explorer.exe ¶Ç´Â lineage.exe, lin.bin, bin.bin¿¡ Æ÷ÇÔµÇ¾î ½ÇÇàµÇ¾î
Å°º¸µå ÀԷ°ªÀ» °¡·ÎÄ¡±â ¶§¹®¿¡ Åͺ¸¹é½ÅÀ¸·Î Ä¡·á½Ã ÇØ´ç ÇÁ·Î±×·¥ÀÇ Á¾·áÈÄ Ä¡·á°¡ ÇÊ¿äÇÏ´Ù.
±×¸®°í ½ÇÇàÁßÀÎ À©µµ¿ì À̸§ÀÌ Lineage Windows Client Àΰæ¿ìµµ Å°º¸µå ÈÄÅ·ÀÌ ½ÃÀ۵ȴÙ.
´ÙÀ½ÀÇ ¸µÅ©¿¡¼ º¸¾ÈÆÐÄ¡¸¦ ¹Þ¾Æ À©µµ¿ì¿î¿µÃ¼Á¦ÀÇ ¾÷µ¥ÀÌÆ®¸¦ ½ÇÇàÇØ¾ß ÇÑ´Ù.
[MS04-013 Ãë¾àÁ¡]
http://www.microsoft.com/korea/technet/security/bulletin/MS04-013.asp
[MS05-001 Ãë¾àÁ¡]
http://www.microsoft.com/korea/technet/security/bulletin/MS05-001.mspx
|
Ä¡·á ¹æ¹ý |
Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.
|
Á÷Á¢Ä¡·á¹æ¹ý |
|
|
|
|
|