http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Translate&no=78 [º¹»ç]
Áö±Ý±îÁö ÇÑ °Í ¿Ã¸³´Ï´Ù.
============================================
We are briefly sowing what is called Michael Jackson Trojan(Á¤ºÎ¿¡¼ °¢º°È÷ ÁÖÀÇÇ϶ó´Â).
¿ì¸®´Â ¿©±â¿¡ Michael Jackson Trojan(ÀÌÇÏ MJT)(Á¤ºÎ¿¡¼)¿¡ ´ëÇؼ °£´ÜÈ÷ ¼Ò°³ÇÏ°íÀÚ ÇÕ´Ï´Ù.
and i got a lot of emails.
Àú´Â ¸¹Àº ÀÌ ¸ÞÀÏÀ» ¹Þ¾Ò¾î¿ä.
and i did some research.
¿¬±¸¸¦ Á» ÇßÁÒ.
I did not. The way it works.
The website exploits some Internet explorers.
MJT´Â ¸î °¡ÁöÀÇ ÀÎÅÍ³Ý ºê¶ó¿ìÁ®¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
I did dead o clock explain.
I did not think it was not zero day.
Àú´Â ±×°ÍÀÌ Á¦·Îµ¥ÀÌ´Â ¾Æ´Ï¶ó°í »ý°¢Çß½À´Ï´Ù.
It downloads into few stages.
MJT´Â ½ºÅ×ÀÌÁö·Î ³ª´µ¾îÁ® ´Ù¿îÀÌ ¹Þ¾ÆÁý´Ï´Ù.
The ultimate piece it ends up downloading is SCPR32V.EXE.
ÃÖÁ¾ÀûÀ¸·Î´Â SCPR32V.EXE¶ó´Â ÆÄÀÏ·Î ´Ù¿îÀÌ ´Ù ¹Þ¾ÆÁý´Ï´Ù.
If you are looking at NMN{} executable, you can load it up online pro relatively safely.
¸¸¾à ´ç½ÅÀÌ NMN executableÀ» °¡Áö°í °è½Ã´Ù¸é, ´ç½ÅÀº ¿Â¶óÀο¡ ÀÌ°ÍÀ» »ó´çÈ÷ ¾ÈÀüÇÏ°Ô ¿Ã¸®½Ç ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
There happens to be a couple of exploitable problems tonight pro in the past, that I believe, in today's current version as far as concerned is safe.
°ú°Å¿¡´Â tonight pro¸¦ »ç¿ëÇÒ ¶§ ¾Ç¿ëµÉ ¼ö ÀÖ´Â À§ÇèÀÌ ÀÖ¾úÁö¸¸ ÃֽŹöÁ¯ÀÇ pro´Â ±×·± ¿ì·Á´Â °ÅÀÇ ¾ø½À´Ï´Ù.
However, I am going to have that taking a glance at everything in Notepad.
±×·¯³ª, Àú´Â MJTÀÇ ¸ðµç °ÍÀ» Notepad¿¡¼ °üÂû ÇØ º¼ °ÍÀÔ´Ï´Ù.
If you get used to looking executable treenotes in certain structures,
¸¸¾à ´ç½ÅÀÌ executable treenotes¸¦ ƯÁ¤ÇÑ ÇüÅ·Πº¸´Âµ¥ Àͼ÷ÇÏ´Ù¸é,
this one immediately screens out UPS caps to me.
´ç½ÅÀº Notepad¿¡ ÀÖ´Â Á¤º¸°¡ ³ª¿¡°Ô UPS capsµéÀ» ½Å¼ÓÇÏ°í ¾Ë¾Æº¸±â ½±°Ô º¸¿©Áشٴ °ÍÀ» ¾Ë °ÍÀÔ´Ï´Ù.
( If you remember what UPS package treatable)
(¸¸¾à ´ç½ÅÀÌ UPS package treatable¸¦ ±â¾ïÇÏ°í ÀÖ´Ù¸é)
Some of the key signs are I got nothing recognizable in the strings of things.
ÀÌ (notepad¿¡ ÀÖ´Â)ÇÁ·Î±×·¥¾îÀÇ ³ª¿¿¡¼ ¿³º¼ ¼ö ÀÖ´Â °ÍÀº ±×·¸°Ô Ưº°ÇÑ °ÍÀº ¾øÀ¸³ª
I don¡¯t see a Niclues of imported functions.
Niclues of imported functions¸¦ ã¾Æ º¼ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.
Okay, so there is something funny going on there.
ÁÁ½À´Ï´Ù, ±×·¡¼ °Å±â¿¡´Â ¹º°¡ Àç¹Õ´Â°ÍÀÌ ÀÖ½À´Ï´Ù.
I am going to go ahead run this utility called PDID (Packer Unifier) on it.
ÀÚ ´ÙÀ½À¸·Î PDID (packer unifier)¶ó´Â À¯Æ¿¸®Æ¼¸¦ ½ÇÇà½Ãų °ÍÀÔ´Ï´Ù.
And point it at that file.
±×¸®°í ÁöÁ¤µÈ ÆÄÀÏÀ» Ŭ¸¯ÇÕ´Ï´Ù.
This modified version of (1:30~1:50).
(1:30 ~ 1:50 ±îÁö µé¸®Áö ¾Ê¾Æ¼ ¸øÇß¾î¿ä ¤Ì¤Ì)
At this point you can load it up on online pro.
ÀÌ ½ÃÁ¡¿¡¼ ´ç½ÅÀº ÀÌ°ÍÀ» ¿Â¶óÀο¡ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù.
And at first I need to tell you.
¿ì¼± ¸»Çϰǵ¥
A lot of it are something.
´ëºÎºÐÀÇ °ÍµéÀÌ °ÅÀÇ´Ù ¶È°°½À´Ï´Ù.
Something funny is going on here, asking whether to upload it up.
¾Æ ½Å±âÇÑ ÀÏÀÌ ÀϾ³×¿ä, PDID°¡ ¿Ã¸± °ÇÁö ¸» °ÇÁö ¹°¾îº¾´Ï´Ù.
And sure.
Yes¸¦ Ŭ¸¯ÇØÁÖ¼¼¿ä.
You can tell quickly that this is not normal programming, bubble code is jumping around all like this.
ÀÚ º¸½Ã´Ù½ÃÇÇ MJT´Â ´Ù¸¥ ÇÁ·Î±×·¥°ú ¸¹ÀÌ ´Ù¸¨´Ï´Ù. Bubble code°¡ ³ÀâÇÏ°Ô ¹è¿ÇØ ÀÖ½À´Ï´Ù.
Have things like ¡°no call¡¯ one instruction ahead.
±×¸®°í ÇÁ·Î±×·¡¸Ó°¡ Áö½Ãµµ ³»¸®±â ÀüÀε¥(ÇϳªÂ÷ÀÌ) ¡°no call¡±°°Àº ¸í·ÉÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù (or °°Àº °ÍµéÀÌ Á¸ÀçÇÕ´Ï´Ù.)
So what we normally do in this case is call Nico.
ÀÌ·± »óȲ¿¡ ÀÖÀ» ¶§ (unpacking ÇÒ¶§) ¿ì¸®´Â Nico (°ËÀº»ö ¸Ó¸® »ç¶÷) ¸¦ ºÎ¸¨´Ï´Ù.
Nico: ¡°UnpackingÀ̶õ ÀÛ¾÷Àº reverse engineer¿¡°Ô »ó´çÈ÷ Æí¸®ÇÑ ±â´ÉÀÔ´Ï´Ù. ÇöÀçÀÇ °ÅÀÇ ¸ðµç ÆÄÀϵéÀÌ packedµÇ ÀÖ¾î¿ä. ƯÈ÷ malwareµéÀÌ¿ä.
Sometimes worms and malwares affect with Houston packers, tools like PID, Walt, multisizing packer=strategy to find out which packer was used and is in effect is to look at the last section of and the characters of the sections.
ÀÌ ¼¼°è¿¡´Â ¾ÆÁÖ ¸¹Àº ¼öÀÇ PE packers°¡ ÀÖ°í PE protector °¡ ÀÖ½À´Ï´Ù. °¡²û°¡´Ù worms³ª malwares°¡ Houston packers¿Í ÇÔ²² °ø°ÝÇÕ´Ï´Ù. À̹ۿ¡µµ PID, Walt, multisizing packer°°Àº µµ±¸¸¦ ÀÌ¿ëÇÕ´Ï´Ù. ¾î¶² Çü½ÄÀÇ packer°¡ »ç¿ëµÇ°í ¾î¶² toolÀÌ ÀÌ¿ëµÇ°í ÀÖ´ÂÁö ¾Ë¾Æ º¼ ¼ö ÀÖ´Â ÇÑ Àü·«Àº ??? ÀÇ ¸¶Áö¸· ¼½¼Ç°ú ±× ¼½¼ÇÀÇ Æ¯¼ºµéÀ» ÆľÇÇÏ´Â °ÍÀÔ´Ï´Ù.
If the last sections are executable it can fight back virus.
¸¸¾à ¸¶Áö¸· ¼½¼ÇÀÌ executable ÇÏ´Ù¸é ¹ÙÀÌ·¯½º¿¡ ´ëÇ× ÇÒ ¼ö ÀÖ½À´Ï´Ù.
|
Hit : 1598 Date : 2011/08/02 12:14
|