97, 1/4 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lycan
   ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Translate&no=78 [º¹»ç]


Áö±Ý±îÁö ÇÑ °Í ¿Ã¸³´Ï´Ù.
============================================

We are briefly sowing what is called Michael Jackson Trojan(Á¤ºÎ¿¡¼­ °¢º°È÷ ÁÖÀÇÇ϶ó´Â).
¿ì¸®´Â ¿©±â¿¡ Michael Jackson Trojan(ÀÌÇÏ MJT)(Á¤ºÎ¿¡¼­)¿¡ ´ëÇؼ­ °£´ÜÈ÷ ¼Ò°³ÇÏ°íÀÚ ÇÕ´Ï´Ù.
and i got a lot of emails.
Àú´Â ¸¹Àº ÀÌ ¸ÞÀÏÀ» ¹Þ¾Ò¾î¿ä.
and i did some research.
¿¬±¸¸¦ Á» ÇßÁÒ.
I did not. The way it works.
The website exploits some Internet explorers.
MJT´Â ¸î °¡ÁöÀÇ ÀÎÅÍ³Ý ºê¶ó¿ìÁ®¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
I did dead o clock explain.

I did not think it was not zero day.
Àú´Â ±×°ÍÀÌ Á¦·Îµ¥ÀÌ´Â ¾Æ´Ï¶ó°í »ý°¢Çß½À´Ï´Ù.
It downloads into few stages.
MJT´Â ½ºÅ×ÀÌÁö·Î ³ª´µ¾îÁ® ´Ù¿îÀÌ ¹Þ¾ÆÁý´Ï´Ù.
The ultimate piece it ends up downloading is SCPR32V.EXE.
ÃÖÁ¾ÀûÀ¸·Î´Â SCPR32V.EXE¶ó´Â ÆÄÀÏ·Î ´Ù¿îÀÌ ´Ù ¹Þ¾ÆÁý´Ï´Ù.
If you are looking at NMN{} executable, you can load it up online pro relatively safely.
¸¸¾à ´ç½ÅÀÌ NMN executableÀ» °¡Áö°í °è½Ã´Ù¸é, ´ç½ÅÀº ¿Â¶óÀο¡ ÀÌ°ÍÀ» »ó´çÈ÷ ¾ÈÀüÇÏ°Ô ¿Ã¸®½Ç ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
There happens to be a couple of exploitable problems tonight pro in the past, that I believe, in today's current version as far as concerned is safe.
°ú°Å¿¡´Â tonight pro¸¦ »ç¿ëÇÒ ¶§ ¾Ç¿ëµÉ ¼ö ÀÖ´Â À§ÇèÀÌ ÀÖ¾úÁö¸¸ ÃֽŹöÁ¯ÀÇ pro´Â ±×·± ¿ì·Á´Â °ÅÀÇ ¾ø½À´Ï´Ù.
However, I am going to have that taking a glance at everything in Notepad.
±×·¯³ª, Àú´Â MJTÀÇ ¸ðµç °ÍÀ» Notepad¿¡¼­ °üÂû ÇØ º¼ °ÍÀÔ´Ï´Ù.
If you get used to looking executable treenotes in certain structures,
¸¸¾à ´ç½ÅÀÌ executable treenotes¸¦ ƯÁ¤ÇÑ ÇüÅ·Πº¸´Âµ¥ Àͼ÷ÇÏ´Ù¸é,
this one immediately screens out UPS caps to me.
´ç½ÅÀº Notepad¿¡ ÀÖ´Â Á¤º¸°¡ ³ª¿¡°Ô UPS capsµéÀ» ½Å¼ÓÇÏ°í ¾Ë¾Æº¸±â ½±°Ô º¸¿©Áشٴ °ÍÀ» ¾Ë °ÍÀÔ´Ï´Ù.
( If you remember what UPS package treatable)
(¸¸¾à ´ç½ÅÀÌ UPS package treatable¸¦ ±â¾ïÇÏ°í ÀÖ´Ù¸é)
Some of the key signs are I got nothing recognizable in the strings of things.
ÀÌ (notepad¿¡ ÀÖ´Â)ÇÁ·Î±×·¥¾îÀÇ ³ª¿­¿¡¼­ ¿³º¼ ¼ö ÀÖ´Â °ÍÀº ±×·¸°Ô Ưº°ÇÑ °ÍÀº ¾øÀ¸³ª
I don¡¯t see a Niclues of imported functions.
Niclues of imported functions¸¦ ã¾Æ º¼ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.
Okay, so there is something funny going on there.
ÁÁ½À´Ï´Ù, ±×·¡¼­ °Å±â¿¡´Â ¹º°¡ Àç¹Õ´Â°ÍÀÌ ÀÖ½À´Ï´Ù.
I am going to go ahead run this utility called PDID (Packer Unifier) on it.
ÀÚ ´ÙÀ½À¸·Î PDID (packer unifier)¶ó´Â À¯Æ¿¸®Æ¼¸¦ ½ÇÇà½Ãų °ÍÀÔ´Ï´Ù.
And point it at that file.
±×¸®°í ÁöÁ¤µÈ ÆÄÀÏÀ» Ŭ¸¯ÇÕ´Ï´Ù.
This modified version of (1:30~1:50).
(1:30 ~ 1:50 ±îÁö µé¸®Áö ¾Ê¾Æ¼­ ¸øÇß¾î¿ä ¤Ì¤Ì)
At this point you can load it up on online pro.
ÀÌ ½ÃÁ¡¿¡¼­ ´ç½ÅÀº ÀÌ°ÍÀ» ¿Â¶óÀο¡ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù.
And at first I need to tell you.
¿ì¼± ¸»Çϰǵ¥
A lot of it are something.
´ëºÎºÐÀÇ °ÍµéÀÌ °ÅÀÇ´Ù ¶È°°½À´Ï´Ù.
Something funny is going on here, asking whether to upload it up.
¾Æ ½Å±âÇÑ ÀÏÀÌ ÀϾ³×¿ä, PDID°¡ ¿Ã¸± °ÇÁö ¸» °ÇÁö ¹°¾îº¾´Ï´Ù.
And sure.
Yes¸¦ Ŭ¸¯ÇØÁÖ¼¼¿ä.
You can tell quickly that this is not normal programming, bubble code is jumping around all like this.
ÀÚ º¸½Ã´Ù½ÃÇÇ MJT´Â ´Ù¸¥ ÇÁ·Î±×·¥°ú ¸¹ÀÌ ´Ù¸¨´Ï´Ù. Bubble code°¡ ³­ÀâÇÏ°Ô ¹è¿­ÇØ ÀÖ½À´Ï´Ù.
Have things like ¡°no call¡¯ one instruction ahead.
±×¸®°í ÇÁ·Î±×·¡¸Ó°¡ Áö½Ãµµ ³»¸®±â ÀüÀε¥(ÇϳªÂ÷ÀÌ) ¡°no call¡±°°Àº ¸í·ÉÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù (or °°Àº °ÍµéÀÌ Á¸ÀçÇÕ´Ï´Ù.)
So what we normally do in this case is call Nico.
ÀÌ·± »óȲ¿¡ ÀÖÀ» ¶§ (unpacking ÇÒ¶§) ¿ì¸®´Â Nico (°ËÀº»ö ¸Ó¸® »ç¶÷) ¸¦ ºÎ¸¨´Ï´Ù.

Nico: ¡°UnpackingÀ̶õ ÀÛ¾÷Àº reverse engineer¿¡°Ô »ó´çÈ÷ Æí¸®ÇÑ ±â´ÉÀÔ´Ï´Ù. ÇöÀçÀÇ °ÅÀÇ ¸ðµç ÆÄÀϵéÀÌ packedµÇ ÀÖ¾î¿ä. ƯÈ÷ malwareµéÀÌ¿ä.
Sometimes worms and malwares affect with Houston packers, tools like PID, Walt, multisizing packer=strategy to find out which packer was used and is in effect is to look at the last section of and the characters of the sections.
ÀÌ ¼¼°è¿¡´Â ¾ÆÁÖ ¸¹Àº ¼öÀÇ PE packers°¡ ÀÖ°í PE protector °¡ ÀÖ½À´Ï´Ù. °¡²û°¡´Ù worms³ª malwares°¡ Houston packers¿Í ÇÔ²² °ø°ÝÇÕ´Ï´Ù.  À̹ۿ¡µµ PID, Walt, multisizing packer°°Àº µµ±¸¸¦ ÀÌ¿ëÇÕ´Ï´Ù. ¾î¶² Çü½ÄÀÇ packer°¡ »ç¿ëµÇ°í ¾î¶² toolÀÌ ÀÌ¿ëµÇ°í ÀÖ´ÂÁö ¾Ë¾Æ º¼ ¼ö ÀÖ´Â ÇÑ Àü·«Àº ??? ÀÇ ¸¶Áö¸· ¼½¼Ç°ú ±× ¼½¼ÇÀÇ Æ¯¼ºµéÀ» ÆľÇÇÏ´Â °ÍÀÔ´Ï´Ù.
If the last sections are executable it can fight back virus.
¸¸¾à ¸¶Áö¸· ¼½¼ÇÀÌ executable ÇÏ´Ù¸é ¹ÙÀÌ·¯½º¿¡ ´ëÇ× ÇÒ ¼ö ÀÖ½À´Ï´Ù.

  Hit : 1599     Date : 2011/08/02 12:14



    
97   ÇïÇÁ¿ä~![1]     sdjgfhhfg12
12/13 1299
96   °¡ÀÔÇß½À´Ï´Ù.     nectars
03/03 1426
95   Èå¾Æ Á˼ÛÇØ¿ä ¤Ð¤Ð¤Ð 11¹ø µ¿¿µ»ó ¹ø¿ª~     dex023
04/14 2735
94 ºñ¹Ð±ÛÀÔ´Ï´Ù  VPN ¸Þ´º¾ó ¹ø¿ªÁ¡..[1]     wkdrns9711
03/07 0
93   Áß±¹¾î ¹ø¿ªÀº ÇÊ¿ä ¾ø³ª¿ä?     ºÒ²É¿¬ÁÖ°¡
01/02 2351
92   ³²Àº 10¹ø, 11¹ø ÆÄÆ® ¸®½º´×&¹ø¿ª ÇØÁÖ½Ç ºÐ ã½À´Ï´Ù.[5]     ¸Û¸Û
11/17 2499
91   9¹øÆÄÆ® dictationÀÔ´Ï´Ù[13]     neb91
08/26 2306
90   hackerwannabe´Ô, neb91´Ô, eplesky´Ô ÁøÇà»óȲ ¸»¾¸ÇØ Áֽñ⠹ٶø´Ï´Ù.[2]     ¸Û¸Û
08/23 2348
89   µ¿¿µ»ó 7¹ø ÆÄÆ®ÀÔ´Ï´Ù.[1]     babyalpha
08/22 2476
88   ¹ø¿ª part 7 status     babyalpha
08/21 1995
87   7¹ø, 9¹ø, 10¹ø, 11¹ø ÆÄÆ® ¸Ã¾ÆÁÖ½Ç ºÐ ¸ð½Ê´Ï´Ù~[9]     ¸Û¸Û
08/09 2399
86   ÆÄÆ® 3 ºÐ·® ÀÔ´Ï´Ù[1]     L0phrack
08/09 2225
85   l0phrack, heeya90, goodfacesong´ÔµéÀº ÁøÇà»óȲÀ» Àû¾îÁÖ¼¼¿ä[2]     ¸Û¸Û
08/08 2258
84   Àú Æ÷±â..Çؾ߰ڳ׿©     d4rkang3l
08/07 2654
83   ¹ø¿ª ÁøÇàÀÌ Á» ´õµð³×¿ä.[2]     babyalpha
08/06 2180
82   ÁøÇà»óȲ Á¤¸® (¸Þ¸ð¿ë)     ¸Û¸Û
08/05 2223
81   12¹ø ÆÄÆ® (ºóÄ­ÀÌ ¸¹¾Æ¿ä)     Prox
08/03 2011
80   6¹ø ÆÄÆ® ¾Èµé¸®´Â °Íµé ¸¹ÀÌ ¸øÇ߳׿䠠   ahotsuna
08/02 1780
79   ÆÄÆ® 2¹ø ºÐ·®ÀÔ´Ï´Ù. (90% Á¤µµµÆ°í ¾ÆÁ÷ 10% - ¾à 30~40Ãʺз®- ¹Ì¿ÏÀÔ´Ï´Ù.))     CodeAche
08/02 1664
78   Á¦ 2ȸ ¹ø¿ª ÁøÇà»óȲ ´ñ±Û ¹Ù¶ø´Ï´Ù.[9]     ¸Û¸Û
08/02 1735
77   ÆÄÆ®1 ºÐ·®ÀÔ´Ï´Ù.     ¸Û¸Û
08/02 1891
  ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.     lycan
08/02 1598
75   ¾ÆÁ÷¸¹ÀÌÇÏÁö¸øÇ߳׿䠠   d4rkang3l
08/01 1517
74   13¹ø ÆÄÆ® ¹ø¿ªÀÔ´Ï´Ù.     20500
08/01 1586
73   4¹ø ÆÄÆ® ¹ø¿ª ¿Ã¸³´Ï´Ù.     babyalpha
08/01 1655
1 [2][3][4]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org