97, 2/4 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lycan
   ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Translate&no=78 [º¹»ç]


Áö±Ý±îÁö ÇÑ °Í ¿Ã¸³´Ï´Ù.
============================================

We are briefly sowing what is called Michael Jackson Trojan(Á¤ºÎ¿¡¼­ °¢º°È÷ ÁÖÀÇÇ϶ó´Â).
¿ì¸®´Â ¿©±â¿¡ Michael Jackson Trojan(ÀÌÇÏ MJT)(Á¤ºÎ¿¡¼­)¿¡ ´ëÇؼ­ °£´ÜÈ÷ ¼Ò°³ÇÏ°íÀÚ ÇÕ´Ï´Ù.
and i got a lot of emails.
Àú´Â ¸¹Àº ÀÌ ¸ÞÀÏÀ» ¹Þ¾Ò¾î¿ä.
and i did some research.
¿¬±¸¸¦ Á» ÇßÁÒ.
I did not. The way it works.
The website exploits some Internet explorers.
MJT´Â ¸î °¡ÁöÀÇ ÀÎÅÍ³Ý ºê¶ó¿ìÁ®¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
I did dead o clock explain.

I did not think it was not zero day.
Àú´Â ±×°ÍÀÌ Á¦·Îµ¥ÀÌ´Â ¾Æ´Ï¶ó°í »ý°¢Çß½À´Ï´Ù.
It downloads into few stages.
MJT´Â ½ºÅ×ÀÌÁö·Î ³ª´µ¾îÁ® ´Ù¿îÀÌ ¹Þ¾ÆÁý´Ï´Ù.
The ultimate piece it ends up downloading is SCPR32V.EXE.
ÃÖÁ¾ÀûÀ¸·Î´Â SCPR32V.EXE¶ó´Â ÆÄÀÏ·Î ´Ù¿îÀÌ ´Ù ¹Þ¾ÆÁý´Ï´Ù.
If you are looking at NMN{} executable, you can load it up online pro relatively safely.
¸¸¾à ´ç½ÅÀÌ NMN executableÀ» °¡Áö°í °è½Ã´Ù¸é, ´ç½ÅÀº ¿Â¶óÀο¡ ÀÌ°ÍÀ» »ó´çÈ÷ ¾ÈÀüÇÏ°Ô ¿Ã¸®½Ç ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
There happens to be a couple of exploitable problems tonight pro in the past, that I believe, in today's current version as far as concerned is safe.
°ú°Å¿¡´Â tonight pro¸¦ »ç¿ëÇÒ ¶§ ¾Ç¿ëµÉ ¼ö ÀÖ´Â À§ÇèÀÌ ÀÖ¾úÁö¸¸ ÃֽŹöÁ¯ÀÇ pro´Â ±×·± ¿ì·Á´Â °ÅÀÇ ¾ø½À´Ï´Ù.
However, I am going to have that taking a glance at everything in Notepad.
±×·¯³ª, Àú´Â MJTÀÇ ¸ðµç °ÍÀ» Notepad¿¡¼­ °üÂû ÇØ º¼ °ÍÀÔ´Ï´Ù.
If you get used to looking executable treenotes in certain structures,
¸¸¾à ´ç½ÅÀÌ executable treenotes¸¦ ƯÁ¤ÇÑ ÇüÅ·Πº¸´Âµ¥ Àͼ÷ÇÏ´Ù¸é,
this one immediately screens out UPS caps to me.
´ç½ÅÀº Notepad¿¡ ÀÖ´Â Á¤º¸°¡ ³ª¿¡°Ô UPS capsµéÀ» ½Å¼ÓÇÏ°í ¾Ë¾Æº¸±â ½±°Ô º¸¿©Áشٴ °ÍÀ» ¾Ë °ÍÀÔ´Ï´Ù.
( If you remember what UPS package treatable)
(¸¸¾à ´ç½ÅÀÌ UPS package treatable¸¦ ±â¾ïÇÏ°í ÀÖ´Ù¸é)
Some of the key signs are I got nothing recognizable in the strings of things.
ÀÌ (notepad¿¡ ÀÖ´Â)ÇÁ·Î±×·¥¾îÀÇ ³ª¿­¿¡¼­ ¿³º¼ ¼ö ÀÖ´Â °ÍÀº ±×·¸°Ô Ưº°ÇÑ °ÍÀº ¾øÀ¸³ª
I don¡¯t see a Niclues of imported functions.
Niclues of imported functions¸¦ ã¾Æ º¼ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.
Okay, so there is something funny going on there.
ÁÁ½À´Ï´Ù, ±×·¡¼­ °Å±â¿¡´Â ¹º°¡ Àç¹Õ´Â°ÍÀÌ ÀÖ½À´Ï´Ù.
I am going to go ahead run this utility called PDID (Packer Unifier) on it.
ÀÚ ´ÙÀ½À¸·Î PDID (packer unifier)¶ó´Â À¯Æ¿¸®Æ¼¸¦ ½ÇÇà½Ãų °ÍÀÔ´Ï´Ù.
And point it at that file.
±×¸®°í ÁöÁ¤µÈ ÆÄÀÏÀ» Ŭ¸¯ÇÕ´Ï´Ù.
This modified version of (1:30~1:50).
(1:30 ~ 1:50 ±îÁö µé¸®Áö ¾Ê¾Æ¼­ ¸øÇß¾î¿ä ¤Ì¤Ì)
At this point you can load it up on online pro.
ÀÌ ½ÃÁ¡¿¡¼­ ´ç½ÅÀº ÀÌ°ÍÀ» ¿Â¶óÀο¡ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù.
And at first I need to tell you.
¿ì¼± ¸»Çϰǵ¥
A lot of it are something.
´ëºÎºÐÀÇ °ÍµéÀÌ °ÅÀÇ´Ù ¶È°°½À´Ï´Ù.
Something funny is going on here, asking whether to upload it up.
¾Æ ½Å±âÇÑ ÀÏÀÌ ÀϾ³×¿ä, PDID°¡ ¿Ã¸± °ÇÁö ¸» °ÇÁö ¹°¾îº¾´Ï´Ù.
And sure.
Yes¸¦ Ŭ¸¯ÇØÁÖ¼¼¿ä.
You can tell quickly that this is not normal programming, bubble code is jumping around all like this.
ÀÚ º¸½Ã´Ù½ÃÇÇ MJT´Â ´Ù¸¥ ÇÁ·Î±×·¥°ú ¸¹ÀÌ ´Ù¸¨´Ï´Ù. Bubble code°¡ ³­ÀâÇÏ°Ô ¹è¿­ÇØ ÀÖ½À´Ï´Ù.
Have things like ¡°no call¡¯ one instruction ahead.
±×¸®°í ÇÁ·Î±×·¡¸Ó°¡ Áö½Ãµµ ³»¸®±â ÀüÀε¥(ÇϳªÂ÷ÀÌ) ¡°no call¡±°°Àº ¸í·ÉÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù (or °°Àº °ÍµéÀÌ Á¸ÀçÇÕ´Ï´Ù.)
So what we normally do in this case is call Nico.
ÀÌ·± »óȲ¿¡ ÀÖÀ» ¶§ (unpacking ÇÒ¶§) ¿ì¸®´Â Nico (°ËÀº»ö ¸Ó¸® »ç¶÷) ¸¦ ºÎ¸¨´Ï´Ù.

Nico: ¡°UnpackingÀ̶õ ÀÛ¾÷Àº reverse engineer¿¡°Ô »ó´çÈ÷ Æí¸®ÇÑ ±â´ÉÀÔ´Ï´Ù. ÇöÀçÀÇ °ÅÀÇ ¸ðµç ÆÄÀϵéÀÌ packedµÇ ÀÖ¾î¿ä. ƯÈ÷ malwareµéÀÌ¿ä.
Sometimes worms and malwares affect with Houston packers, tools like PID, Walt, multisizing packer=strategy to find out which packer was used and is in effect is to look at the last section of and the characters of the sections.
ÀÌ ¼¼°è¿¡´Â ¾ÆÁÖ ¸¹Àº ¼öÀÇ PE packers°¡ ÀÖ°í PE protector °¡ ÀÖ½À´Ï´Ù. °¡²û°¡´Ù worms³ª malwares°¡ Houston packers¿Í ÇÔ²² °ø°ÝÇÕ´Ï´Ù.  À̹ۿ¡µµ PID, Walt, multisizing packer°°Àº µµ±¸¸¦ ÀÌ¿ëÇÕ´Ï´Ù. ¾î¶² Çü½ÄÀÇ packer°¡ »ç¿ëµÇ°í ¾î¶² toolÀÌ ÀÌ¿ëµÇ°í ÀÖ´ÂÁö ¾Ë¾Æ º¼ ¼ö ÀÖ´Â ÇÑ Àü·«Àº ??? ÀÇ ¸¶Áö¸· ¼½¼Ç°ú ±× ¼½¼ÇÀÇ Æ¯¼ºµéÀ» ÆľÇÇÏ´Â °ÍÀÔ´Ï´Ù.
If the last sections are executable it can fight back virus.
¸¸¾à ¸¶Áö¸· ¼½¼ÇÀÌ executable ÇÏ´Ù¸é ¹ÙÀÌ·¯½º¿¡ ´ëÇ× ÇÒ ¼ö ÀÖ½À´Ï´Ù.

  Hit : 1612     Date : 2011/08/02 12:14



    
72   [Á¦ 2ȸ] µ¿¿µ»ó ÆÄÀÏ[1]     lycan
07/16 2697
  ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.     lycan
08/02 1611
70   9¹øÆÄÆ® dictationÀÔ´Ï´Ù[13]     neb91
08/26 2321
69   °¡ÀÔÇß½À´Ï´Ù.     nectars
03/03 1443
68   8¹ø ÆÄÆ®ÀÔ´Ï´Ù[1]     Prox
05/11 1657
     Á¦°¡ »ç¿ëÇÏ´Â ¸®½º´× ¹æ¹ý ÆÁ.. [4] Prox 05/21 3260
66   12¹ø ÆÄÆ® (ºóÄ­ÀÌ ¸¹¾Æ¿ä)     Prox
08/03 2026
65   ÇïÇÁ¿ä~![1]     sdjgfhhfg12
12/13 1316
64   2¹ø ÆÄÆ® ¸®½º´×&¹ø¿ªÀÔ´Ï´Ù.[2]     stardung86
05/09 1685
63   À§¿¡ ¸Û¸Û´ÔÀÌ ¿Ã¸®½Å µ¿¿µ»óÀ¸·Î ÀÛ¾÷ÇØÁÖ¼¼¿ä~ (ÀÌ °Ô½Ã¹°X)[21]     W.H.
05/03 1760
62   À̹ø ÀÛ¾÷(nish_bhalla_auditing_source_code) ¿øº» ÆÄÀÏÀÌ¿ä.     W.H.
05/03 1743
61   1¹ø ÆÄÆ® ÀÏ´Ü Áö±Ý±îÁö ÇÑ°Å ¿Ã¸³´Ï´Ù.[2]     W.H.
05/10 1761
60   À§Å° ÆäÀÌÁö º¯°æ ¹× ¸ðµÎ ¸¸µé¾î ³õ°Ú½À´Ï´Ù. + ¸Û¸Û´Ô Çѹø ºÁÁÖ¼¼¿ä[1]     W.H.
05/13 1805
59   µ¿¿µ»ó ÆÄÀÏÀÔ´Ï´Ù. <- ÀÌ µ¿¿µ»óÀº Á¤ÇØÁø µ¿¿µ»óÀÌ ¾Æ´Ï¿¡¿ä~~[8]     W.H.
05/27 1798
58 ºñ¹Ð±ÛÀÔ´Ï´Ù  VPN ¸Þ´º¾ó ¹ø¿ªÁ¡..[1]     wkdrns9711
03/07 0
     [°øÁö] ¹ø¿ªÆÀ ¸â¹ö ¸ñ·ÏÀÔ´Ï´Ù. [33] ¸Û¸Û 05/03 3216
     [°øÁö] RECON 2005 ¹ßÇ¥ÀÚ·á ¸ñ·ÏÀÔ´Ï´Ù ¸Û¸Û 05/03 3015
55   [1ȸ] µ¿¿µ»ó ºÐÇÒÇØÁÖ½Ç ºÐ![2]     ¸Û¸Û
05/03 2149
54   [1ȸ] ¿ªÇÒ ºÐ´ãÇÕ´Ï´Ù.[1]     ¸Û¸Û
05/03 1760
53   [°øÁö] Á¦ 1ȸ ¹ø¿ª ½ºÄÉÁìÀÔ´Ï´Ù. (ÁøÇà»óȲÀ» °¢ÀÚ ´ñ±Û·Î update)[10]     ¸Û¸Û
05/03 1783
52   ¸â¹öºÐµé ³×ÀÌÆ®¿Â or Ä«Åå or Æ®À§ÅÍ ±³È¯ÇØ¿ä[4]     ¸Û¸Û
05/03 2066
51   [1ȸ] recon - auditing source code ºÐÇÒ ÆÄÀÏÀÔ´Ï´Ù (ÃÑ 9°³)[8]     ¸Û¸Û
05/04 1887
50   ¾ÆÂü ¹ø¿ª¹®Àº Á¸´ñ¸»·Î Àû¾îÁÖ¼¼¿ä~ (³Ã¹«)     ¸Û¸Û
05/04 1383
49   ÀÛ¾÷ÇÏ´Ù ¸·È÷½Å ºÐ, ±×¸®°í ÀÛ¾÷ ÇÒ´ç ¸ø¹ÞÀ¸½Å ºÐ ºÁÁÖ¼¼¿ä     ¸Û¸Û
05/06 1766
48   4¹ø ÆÄÆ® ¸®½º´×&¹ø¿ª ³»¿ëÀÔ´Ï´Ù.[1]     ¸Û¸Û
05/09 1779
[1] 2 [3][4]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org