|
|
|
|
¹ÙÀÌ·¯½º
À̸§ |
W32/Mytob.33485@mm |
¹ÙÀÌ·¯½º
Á¾·ù |
Worm |
½ÇÇà
ȯ°æ |
Windows |
Á¦ÀÛÁö |
ºÒºÐ¸í |
¹ß°ßÀÏ |
20050617 |
¹ÙÀÌ·¯½ºÅ©±â |
33,485 Byte |
¸ÞÀÏ
Á¦¸ñ |
Members Support ¿Ü ´Ù¼ö |
÷ºÎÆÄÀÏ |
document.zip ¿Ü ´Ù¼ö |
¹ÙÀÌ·¯½º Áõ»ó |
[¸ÞÀÏ Á¦¸ñ]
´ÙÀ½ Áß¿¡¼ ¼±ÅõȴÙ.
*DETECTED* Online User Violation
Email Account Suspension
Important Notification
Members Support
Notice of account limitation
Security measures
Warning Message: Your services near to be closed.
You have successfully updated your password
Your Account is Suspended
Your Account is Suspended For Security Reasons
Your new account password is approved
Your password has been successfully updated
Your password has been updated
[¸ÞÀÏ ³»¿ë]
Dear {µµ¸ÞÀÎ ¾ÆÀ̵ð} Member,
We have temporarily suspended your email account {µµ¸ÞÀÎÁÖ¼Ò}.
This might be due to either of the following reasons:
1. A recent change in your personal information
(i.e. change of address).
2. Submiting invalid information during
the initial sign up process.
3. An innability to accurately verify
your selected option of subscription
due to an internal error within our processors.
See the details to reactivate your {random} account.
Sincerely,The {µµ¸ÞÀÎÁÖ¼Ò} Support Team
+++ Attachment: No Virus (Clean)
+++ {µµ¸ÞÀÎÁÖ¼Ò} Antivirus - www.{µµ¸ÞÀÎÁÖ¼Ò}
[÷ºÎÆÄÀÏ]
À̸§ Àº ´ÙÀ½ ¸®½ºÆ®¿¡¼ ¼±Åà µÈ´Ù.
accepted-password
account-details
account-info
account-password
account-report
approved-password
document
email-details
email-password
important-details
new-password
password
readme
updated-password
È®ÀåÀÚ´Â ´ÙÀ½°ú °°´Ù.
BAT
CMD
EXE
PIF
SCR
ZIP
[Ư¡]
¿úÀÌ ½ÇÇàµÇ¸é ´ÙÀ½°ú °°ÀÌ À©µµ¿ì ½Ã½ºÅÛ Æú´õ(win 2000, NT : c:\Wint\system32, win XP : c:\windows\system32)
¿¡ skybotx.exe ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
¶ÇÇÑ, ´ÙÀ½Ã³·³ ·¹Áö½ºÆ®¸¦ ¼öÁ¤ÇÏ¿© ´ÙÀ½ ºÎÆýà ½ÇÇàµÇµµ·Ï Á¶ÀÛÇÑ´Ù.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Ç׸ñ¿¡
WINDOWS SYSTEM = "skybotx.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
Ç׸ñ¿¡
WINDOWS SYSTEM = "skybotx.exe"
¸¦ ±â·ÏÇÑ´Ù.
windows xp ¿¡¼´Â firwall ¼³Á¤¿¡ °ü°èµÈ ´ÙÀ½ ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÑ´Ù.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess
Start = "4"
À̸ÞÀÏ ÁÖ¼Ò´Â ´ÙÀ½ È®ÀåÀÚ¸¦ °¡Áø ÆÄÀÏ¿¡¼ ÃßÃâ ÇÑ´Ù.
ADB
ASP
DBX
HTM
JSP
PHP
PL
SHT
TBB
WAB
XML
´ÙÀ½ ¹®ÀÚ¿À» Æ÷ÇÔÇÑ ¸ÞÀÏÁּҷδ °¨¿°µÈ ¸ÞÀÏÀ» º¸³»Áö ¾Ê´Â´Ù.
acketst
arin.
be_loyal:
berkeley
borlan
example
google
hotmail
ibm.com
icrosof
inpris
isc.o
isi.e
kernel
linux
mit.e
mozilla
mydomai
nodomai
panda
postmaster
rfc-ed
ripe.
ruslis
samples
secur
sendmail
sopho
tanford.e
usenet
utgers.ed
webmaster
www
you
your
´ÙÀ½ ¹®ÀÚ¸¦ Æ÷ÇÔÇÑ ¸ÞÀÏÁּҷδ °¨¿°µÈ ¸ÞÀÏÀ» Àü¼ÛÇÏÁö ¾Ê´Â´Ù.
abuse
accoun
acketst
admin
administrator
anyone
arin.
be_loyal:
berkeley
borlan
certific
contact
example
feste
gold-certs
google
hotmail
ibm.com
icrosof
icrosoft
inpris
isc.o
isi.e
kernel
linux
linux
listserv
mit.e
mozilla
mydomai
nobody
nodomai
noone
nothing
ntivi
panda
postmaster
privacy
rating
register
rfc-ed
ripe.
ruslis
samples
secur
secur
sendmail
service
service
somebody
someone
sopho
submit
support
system
tanford.e
the.bat
usenet
utgers.ed
virusalert
webmaster
±×¸®°í TCP 6999,7373 Æ÷Æ®¸¦ ÀÌ¿ëÇÏ¿© ƯÁ¤ IRC ¼¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÑ´Ù.
¸¶Áö¸·À¸·Î Hosts ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© ƯÁ¤ ÁÖ¼Ò·Î Á¢¼ÓÀ» ¹æÇØ ÇÑ´Ù.
³»¿ëÀº ´ÙÀ½°ú °°´Ù.
127.0.0.1 avp.com
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 pandasoftware.com
127.0.0.1 www.pandasoftware.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
127.0.0.1 www.microsoft.com
127.0.0.1 microsoft.com
127.0.0.1 www.virustotal.com
127.0.0.1 virustotal.com
127.0.0.1 www.amazon.com
127.0.0.1 www.amazon.co.uk
127.0.0.1 www.amazon.ca
127.0.0.1 www.amazon.fr
127.0.0.1 www.paypal.com
127.0.0.1 paypal.com
127.0.0.1 moneybookers.com
127.0.0.1 www.moneybookers.com
127.0.0.1 www.ebay.com
127.0.0.1 ebay.com |
Ä¡·á ¹æ¹ý |
Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.
¸¶ÀÌÅ©·Î ¼ÒÇÁÆ® MS04-011 º¸¾ÈÆÐÄ¡¿Í MS04-026°¡ ¾ÈµÈ »ç¿ëÀÚ´Â
´ÙÀ½ ¸µÅ©¿¡¼ ÇØ´ç ¿î¿µÃ¼Á¦¿¡ ¸Â´Â º¸¾ÈÆÐÄ¡¸¦ ¹Þ¾Æ ¼³Ä¡ ÇØ¾ß ÇÑ´Ù.
MS04-011 º¸¾ÈÆÐÄ¡ ÆäÀÌÁö ¼³¸í(ÇѱÛ)
MS03-039 º¸¾ÈÆÐÄ¡ ÆäÀÌÁö ¼³¸í(ÇѱÛ)
Åͺ¸¹é½Å Ai¸¦ »ç¿ëÇÏ½Ã°í ¾Æ¿ô·èÀ» »ç¿ëÇϽŠ´Ù¸é ¹Ýµå½Ã À̸ÞÀÏ °¨½Ã±â¸¦
½ÇÇàÇϽñ⠹ٶø´Ï´Ù.
|
Á÷Á¢Ä¡·á¹æ¹ý |
|
|
|
|
|