97, 2/4 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lycan
   ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Translate&no=78 [º¹»ç]


Áö±Ý±îÁö ÇÑ °Í ¿Ã¸³´Ï´Ù.
============================================

We are briefly sowing what is called Michael Jackson Trojan(Á¤ºÎ¿¡¼­ °¢º°È÷ ÁÖÀÇÇ϶ó´Â).
¿ì¸®´Â ¿©±â¿¡ Michael Jackson Trojan(ÀÌÇÏ MJT)(Á¤ºÎ¿¡¼­)¿¡ ´ëÇؼ­ °£´ÜÈ÷ ¼Ò°³ÇÏ°íÀÚ ÇÕ´Ï´Ù.
and i got a lot of emails.
Àú´Â ¸¹Àº ÀÌ ¸ÞÀÏÀ» ¹Þ¾Ò¾î¿ä.
and i did some research.
¿¬±¸¸¦ Á» ÇßÁÒ.
I did not. The way it works.
The website exploits some Internet explorers.
MJT´Â ¸î °¡ÁöÀÇ ÀÎÅÍ³Ý ºê¶ó¿ìÁ®¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
I did dead o clock explain.

I did not think it was not zero day.
Àú´Â ±×°ÍÀÌ Á¦·Îµ¥ÀÌ´Â ¾Æ´Ï¶ó°í »ý°¢Çß½À´Ï´Ù.
It downloads into few stages.
MJT´Â ½ºÅ×ÀÌÁö·Î ³ª´µ¾îÁ® ´Ù¿îÀÌ ¹Þ¾ÆÁý´Ï´Ù.
The ultimate piece it ends up downloading is SCPR32V.EXE.
ÃÖÁ¾ÀûÀ¸·Î´Â SCPR32V.EXE¶ó´Â ÆÄÀÏ·Î ´Ù¿îÀÌ ´Ù ¹Þ¾ÆÁý´Ï´Ù.
If you are looking at NMN{} executable, you can load it up online pro relatively safely.
¸¸¾à ´ç½ÅÀÌ NMN executableÀ» °¡Áö°í °è½Ã´Ù¸é, ´ç½ÅÀº ¿Â¶óÀο¡ ÀÌ°ÍÀ» »ó´çÈ÷ ¾ÈÀüÇÏ°Ô ¿Ã¸®½Ç ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
There happens to be a couple of exploitable problems tonight pro in the past, that I believe, in today's current version as far as concerned is safe.
°ú°Å¿¡´Â tonight pro¸¦ »ç¿ëÇÒ ¶§ ¾Ç¿ëµÉ ¼ö ÀÖ´Â À§ÇèÀÌ ÀÖ¾úÁö¸¸ ÃֽŹöÁ¯ÀÇ pro´Â ±×·± ¿ì·Á´Â °ÅÀÇ ¾ø½À´Ï´Ù.
However, I am going to have that taking a glance at everything in Notepad.
±×·¯³ª, Àú´Â MJTÀÇ ¸ðµç °ÍÀ» Notepad¿¡¼­ °üÂû ÇØ º¼ °ÍÀÔ´Ï´Ù.
If you get used to looking executable treenotes in certain structures,
¸¸¾à ´ç½ÅÀÌ executable treenotes¸¦ ƯÁ¤ÇÑ ÇüÅ·Πº¸´Âµ¥ Àͼ÷ÇÏ´Ù¸é,
this one immediately screens out UPS caps to me.
´ç½ÅÀº Notepad¿¡ ÀÖ´Â Á¤º¸°¡ ³ª¿¡°Ô UPS capsµéÀ» ½Å¼ÓÇÏ°í ¾Ë¾Æº¸±â ½±°Ô º¸¿©Áشٴ °ÍÀ» ¾Ë °ÍÀÔ´Ï´Ù.
( If you remember what UPS package treatable)
(¸¸¾à ´ç½ÅÀÌ UPS package treatable¸¦ ±â¾ïÇÏ°í ÀÖ´Ù¸é)
Some of the key signs are I got nothing recognizable in the strings of things.
ÀÌ (notepad¿¡ ÀÖ´Â)ÇÁ·Î±×·¥¾îÀÇ ³ª¿­¿¡¼­ ¿³º¼ ¼ö ÀÖ´Â °ÍÀº ±×·¸°Ô Ưº°ÇÑ °ÍÀº ¾øÀ¸³ª
I don¡¯t see a Niclues of imported functions.
Niclues of imported functions¸¦ ã¾Æ º¼ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.
Okay, so there is something funny going on there.
ÁÁ½À´Ï´Ù, ±×·¡¼­ °Å±â¿¡´Â ¹º°¡ Àç¹Õ´Â°ÍÀÌ ÀÖ½À´Ï´Ù.
I am going to go ahead run this utility called PDID (Packer Unifier) on it.
ÀÚ ´ÙÀ½À¸·Î PDID (packer unifier)¶ó´Â À¯Æ¿¸®Æ¼¸¦ ½ÇÇà½Ãų °ÍÀÔ´Ï´Ù.
And point it at that file.
±×¸®°í ÁöÁ¤µÈ ÆÄÀÏÀ» Ŭ¸¯ÇÕ´Ï´Ù.
This modified version of (1:30~1:50).
(1:30 ~ 1:50 ±îÁö µé¸®Áö ¾Ê¾Æ¼­ ¸øÇß¾î¿ä ¤Ì¤Ì)
At this point you can load it up on online pro.
ÀÌ ½ÃÁ¡¿¡¼­ ´ç½ÅÀº ÀÌ°ÍÀ» ¿Â¶óÀο¡ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù.
And at first I need to tell you.
¿ì¼± ¸»Çϰǵ¥
A lot of it are something.
´ëºÎºÐÀÇ °ÍµéÀÌ °ÅÀÇ´Ù ¶È°°½À´Ï´Ù.
Something funny is going on here, asking whether to upload it up.
¾Æ ½Å±âÇÑ ÀÏÀÌ ÀϾ³×¿ä, PDID°¡ ¿Ã¸± °ÇÁö ¸» °ÇÁö ¹°¾îº¾´Ï´Ù.
And sure.
Yes¸¦ Ŭ¸¯ÇØÁÖ¼¼¿ä.
You can tell quickly that this is not normal programming, bubble code is jumping around all like this.
ÀÚ º¸½Ã´Ù½ÃÇÇ MJT´Â ´Ù¸¥ ÇÁ·Î±×·¥°ú ¸¹ÀÌ ´Ù¸¨´Ï´Ù. Bubble code°¡ ³­ÀâÇÏ°Ô ¹è¿­ÇØ ÀÖ½À´Ï´Ù.
Have things like ¡°no call¡¯ one instruction ahead.
±×¸®°í ÇÁ·Î±×·¡¸Ó°¡ Áö½Ãµµ ³»¸®±â ÀüÀε¥(ÇϳªÂ÷ÀÌ) ¡°no call¡±°°Àº ¸í·ÉÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù (or °°Àº °ÍµéÀÌ Á¸ÀçÇÕ´Ï´Ù.)
So what we normally do in this case is call Nico.
ÀÌ·± »óȲ¿¡ ÀÖÀ» ¶§ (unpacking ÇÒ¶§) ¿ì¸®´Â Nico (°ËÀº»ö ¸Ó¸® »ç¶÷) ¸¦ ºÎ¸¨´Ï´Ù.

Nico: ¡°UnpackingÀ̶õ ÀÛ¾÷Àº reverse engineer¿¡°Ô »ó´çÈ÷ Æí¸®ÇÑ ±â´ÉÀÔ´Ï´Ù. ÇöÀçÀÇ °ÅÀÇ ¸ðµç ÆÄÀϵéÀÌ packedµÇ ÀÖ¾î¿ä. ƯÈ÷ malwareµéÀÌ¿ä.
Sometimes worms and malwares affect with Houston packers, tools like PID, Walt, multisizing packer=strategy to find out which packer was used and is in effect is to look at the last section of and the characters of the sections.
ÀÌ ¼¼°è¿¡´Â ¾ÆÁÖ ¸¹Àº ¼öÀÇ PE packers°¡ ÀÖ°í PE protector °¡ ÀÖ½À´Ï´Ù. °¡²û°¡´Ù worms³ª malwares°¡ Houston packers¿Í ÇÔ²² °ø°ÝÇÕ´Ï´Ù.  À̹ۿ¡µµ PID, Walt, multisizing packer°°Àº µµ±¸¸¦ ÀÌ¿ëÇÕ´Ï´Ù. ¾î¶² Çü½ÄÀÇ packer°¡ »ç¿ëµÇ°í ¾î¶² toolÀÌ ÀÌ¿ëµÇ°í ÀÖ´ÂÁö ¾Ë¾Æ º¼ ¼ö ÀÖ´Â ÇÑ Àü·«Àº ??? ÀÇ ¸¶Áö¸· ¼½¼Ç°ú ±× ¼½¼ÇÀÇ Æ¯¼ºµéÀ» ÆľÇÇÏ´Â °ÍÀÔ´Ï´Ù.
If the last sections are executable it can fight back virus.
¸¸¾à ¸¶Áö¸· ¼½¼ÇÀÌ executable ÇÏ´Ù¸é ¹ÙÀÌ·¯½º¿¡ ´ëÇ× ÇÒ ¼ö ÀÖ½À´Ï´Ù.

  Hit : 1598     Date : 2011/08/02 12:14



    
72   6¹ø ÆÄÆ® ¾Èµé¸®´Â °Íµé ¸¹ÀÌ ¸øÇ߳׿䠠   ahotsuna
08/02 1779
71   ÆÄÆ® 2¹ø ºÐ·®ÀÔ´Ï´Ù. (90% Á¤µµµÆ°í ¾ÆÁ÷ 10% - ¾à 30~40Ãʺз®- ¹Ì¿ÏÀÔ´Ï´Ù.))     CodeAche
08/02 1662
70   Á¦ 2ȸ ¹ø¿ª ÁøÇà»óȲ ´ñ±Û ¹Ù¶ø´Ï´Ù.[9]     ¸Û¸Û
08/02 1732
69   ÆÄÆ®1 ºÐ·®ÀÔ´Ï´Ù.     ¸Û¸Û
08/02 1889
  ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.     lycan
08/02 1597
67   ¾ÆÁ÷¸¹ÀÌÇÏÁö¸øÇ߳׿䠠   d4rkang3l
08/01 1515
66   13¹ø ÆÄÆ® ¹ø¿ªÀÔ´Ï´Ù.     20500
08/01 1584
65   4¹ø ÆÄÆ® ¹ø¿ª ¿Ã¸³´Ï´Ù.     babyalpha
08/01 1653
64   ´Ù¸¥ ºÐµéÀº ¾ó¸¶³ª Çϼ̳ª¿ä?[3]     ahotsuna
07/31 1676
63   ±âÇÑÀÌ...[3]     20500
07/31 1495
62   [Á¦ 2ȸ] ¹ø¿ª ÆÄÆ®°¡ Á¤ÇØÁ³½À´Ï´Ù[12]     ¸Û¸Û
07/18 1886
61   [Á¦ 2ȸ] µ¿¿µ»ó ÆÄÀÏ[1]     lycan
07/16 2685
60   [Á¦ 2ȸ] À¯Åõºê ¸µÅ©[1]     lycan
07/16 1758
59   [Á¦ 2ȸ] Á¦ 2ȸ ¸®½º´×&¹ø¿ª ÀÛ¾÷À» ½ÃÀÛÇÕ´Ï´Ù.[20]     ¸Û¸Û
07/14 2063
58   [1ȸ] recon - auditing source code ºÐÇÒ ÆÄÀÏÀÔ´Ï´Ù (ÃÑ 9°³)[8]     ¸Û¸Û
05/04 1874
57   [°øÁö] Á¦ 1ȸ ¹ø¿ª ½ºÄÉÁìÀÔ´Ï´Ù. (ÁøÇà»óȲÀ» °¢ÀÚ ´ñ±Û·Î update)[10]     ¸Û¸Û
05/03 1770
56   ÀÚ¸· - ÃÖÁ¾ ¼öÁ¤º»ÀÔ´Ï´Ù~     ¸Û¸Û
06/30 1597
55   ÀÚ¸· - darkangel´Ô °Í°ú lycan´Ô °Í ÅëÇÕ     ¸Û¸Û
06/22 1817
54   ÀÚ¸·[1]     d4rkang3l
06/21 1462
53   µÎ ¹ø° ¹ø¿ª ´ë»ó °ü·Ã..[5]     ¸Û¸Û
06/16 1879
52   ÀÚ¸·(¿µ¾î,Çѱ۸¸ ¿Ï¼º ½ÌÅ© ¿¡·¯)[1]     d4rkang3l
06/16 1715
51   ÀÚ¸· ¿Ã¸³´Ï´Ù~[4]     lycan
06/13 1591
50     [re] °³Çà ¹× ÀϺΠ¼öÁ¤ÇÑ ÀÚ¸· ¿Ã¸³´Ï´Ù.[1]     lycan
06/15 1593
49   ÀúÀÚ¸·ÀÌ¿ä(¹Ì¿Ï¼º)[1]     d4rkang3l
06/09 1497
48   Á¦ 1ȸ ¹ø¿ª ÀÚ¸· °ü·ÃÀÔ´Ï´Ù.     ¸Û¸Û
06/02 1668
[1] 2 [3][4]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org