• Åͺ¸¹é½Å
¿£Áø¾÷µ¥ÀÌÆ®
º¸¾È±Ç°í¹®
½ÅÁ¾ ¹ÙÀÌ·¯½º
½ÅÁ¾¾Ç¼ºÄÚµå
¹®ÀÇÇϱâ
¿À´ÃÀÇ º¸¾È°æº¸
Level3 : ÁÖÀÇ
Ãֽо÷µ¥ÀÌÆ® ÇöȲ   document.write("2018.07.06.0");
¹ÙÀÌ·¯½º ½Å°íÇϱâ
½ÅÁ¾¹ÙÀÌ·¯½º
   
¸ñ·Ï¤Ó ÀÎ¼â  
VBS/Baracuda
¹ÙÀÌ·¯½º Á¾·ù Script Virus ½ÇÇàȯ°æ windows
¹ß°ßÀÏ - Á¦ÀÛÁö
À§Çèµî±Þ È®»ê¹æ¹ý
¹ÙÀÌ·¯½º Å©±â ÷ºÎÆÄÀÏ Energy.vbs
¸ÞÀÏÁ¦¸ñ
Áõ»ó¿ä¾à
Ä¡·á¹æ¹ý Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Ä¡·á °¡´É
Åͺ¸¹é½Å IS üÇè°ü  Åͺ¸¹é½Å IS ±¸¸Å
»ó¼¼¼³¸í
ÀÌ ¹ÙÀÌ·¯½º¸¦ ½ÇÇàÇϸé À©µµ¿ì Æú´õ¿¡ MSNetLog ¿Í
À©µµ¿ì Command Æú´õ
¿¡ Energy.vbs¸¦ »ý¼ºÇÑ´Ù.
·¹Áö½ºÆ®¸®¿¡ ¾Æ·¡¿Í °°Àº ³»¿ëÀ» Ãß°¡ÇÑ´Ù.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\Searc
hMSN
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\MSNet
Log


½ÃÀÛ È¨ÆäÀÌÁö¸¦ "http://vx.dirtyhosting.com"·Î ¹Ù
²Û´Ù.
mirc °¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸é script.ini ¸¦ ¾Æ·¡¿Í °°ÀÌ
¹Ù²Û´Ù.

[script]
;MIRC Script By Ahamad Boby
n0=on 1:JOIN:#:{
n1= /if ( $nick == $me ) { halt }
n2= /.dcc send $nick "&windir&"\Command\Energy.vbs
n3=}

¾Æ¿ô·èÀÇ ÁÖ¼Ò·Ï¿¡ µî·ÏµÇ¾î ÀÖ´Â »ç¿ëÀڵ鿡°Ô ¾Æ·¡
ÀÇ ³»¿ëÁßÀÇ Çϳª¿Í ÇÔ
²² Energy.vbs ¸¦ ÷ºÎÇÏ¿© º¸³½´Ù

Á¦¸ñ : Surprise
º»¹® : A nice surprise for you, check it out...

Á¦¸ñ : Great...
º»¹® : Great app, check it out..

Á¦¸ñ : Important, Please Read
º»¹® : A paper I downloaded from Symantec about
new virus, you should
read it

Á¦¸ñ : Happy Birthday
º»¹® : A happy birthday surprise

Á¦¸ñ : Take a look...
º»¹® : Take a look and the app that chenge to a
pic

Á¦¸ñ : Great Joke.. Read it
º»¹® : Read this joke, it is so great... ha ha


·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏÁö ¸øÇϵµ·Ï regedit.exe ÆÄÀÏÀ»
Áö¿î´Ù.
2 ÀÏ 10 ÀÏ 20 ÀÏ 28 ÀÏ¿¡ notepad.exe ¸¦ °è¼Ó ½ÇÇà
½ÃŲ´Ù.

½Ã½ºÅÛ Æú´õ¿¡¼­ È®ÀåÀÚ°¡ sys, dll, ocx ÀÎ ÆÄÀÏÀ»
ã¾Æ ¼Õ»ó½ÃŲ´Ù.

¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¸ñ·Ïº¸±â
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
- ¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
- ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
- À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com