97, 3/4 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lycan
   ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Translate&no=78 [º¹»ç]


Áö±Ý±îÁö ÇÑ °Í ¿Ã¸³´Ï´Ù.
============================================

We are briefly sowing what is called Michael Jackson Trojan(Á¤ºÎ¿¡¼­ °¢º°È÷ ÁÖÀÇÇ϶ó´Â).
¿ì¸®´Â ¿©±â¿¡ Michael Jackson Trojan(ÀÌÇÏ MJT)(Á¤ºÎ¿¡¼­)¿¡ ´ëÇؼ­ °£´ÜÈ÷ ¼Ò°³ÇÏ°íÀÚ ÇÕ´Ï´Ù.
and i got a lot of emails.
Àú´Â ¸¹Àº ÀÌ ¸ÞÀÏÀ» ¹Þ¾Ò¾î¿ä.
and i did some research.
¿¬±¸¸¦ Á» ÇßÁÒ.
I did not. The way it works.
The website exploits some Internet explorers.
MJT´Â ¸î °¡ÁöÀÇ ÀÎÅÍ³Ý ºê¶ó¿ìÁ®¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
I did dead o clock explain.

I did not think it was not zero day.
Àú´Â ±×°ÍÀÌ Á¦·Îµ¥ÀÌ´Â ¾Æ´Ï¶ó°í »ý°¢Çß½À´Ï´Ù.
It downloads into few stages.
MJT´Â ½ºÅ×ÀÌÁö·Î ³ª´µ¾îÁ® ´Ù¿îÀÌ ¹Þ¾ÆÁý´Ï´Ù.
The ultimate piece it ends up downloading is SCPR32V.EXE.
ÃÖÁ¾ÀûÀ¸·Î´Â SCPR32V.EXE¶ó´Â ÆÄÀÏ·Î ´Ù¿îÀÌ ´Ù ¹Þ¾ÆÁý´Ï´Ù.
If you are looking at NMN{} executable, you can load it up online pro relatively safely.
¸¸¾à ´ç½ÅÀÌ NMN executableÀ» °¡Áö°í °è½Ã´Ù¸é, ´ç½ÅÀº ¿Â¶óÀο¡ ÀÌ°ÍÀ» »ó´çÈ÷ ¾ÈÀüÇÏ°Ô ¿Ã¸®½Ç ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
There happens to be a couple of exploitable problems tonight pro in the past, that I believe, in today's current version as far as concerned is safe.
°ú°Å¿¡´Â tonight pro¸¦ »ç¿ëÇÒ ¶§ ¾Ç¿ëµÉ ¼ö ÀÖ´Â À§ÇèÀÌ ÀÖ¾úÁö¸¸ ÃֽŹöÁ¯ÀÇ pro´Â ±×·± ¿ì·Á´Â °ÅÀÇ ¾ø½À´Ï´Ù.
However, I am going to have that taking a glance at everything in Notepad.
±×·¯³ª, Àú´Â MJTÀÇ ¸ðµç °ÍÀ» Notepad¿¡¼­ °üÂû ÇØ º¼ °ÍÀÔ´Ï´Ù.
If you get used to looking executable treenotes in certain structures,
¸¸¾à ´ç½ÅÀÌ executable treenotes¸¦ ƯÁ¤ÇÑ ÇüÅ·Πº¸´Âµ¥ Àͼ÷ÇÏ´Ù¸é,
this one immediately screens out UPS caps to me.
´ç½ÅÀº Notepad¿¡ ÀÖ´Â Á¤º¸°¡ ³ª¿¡°Ô UPS capsµéÀ» ½Å¼ÓÇÏ°í ¾Ë¾Æº¸±â ½±°Ô º¸¿©Áشٴ °ÍÀ» ¾Ë °ÍÀÔ´Ï´Ù.
( If you remember what UPS package treatable)
(¸¸¾à ´ç½ÅÀÌ UPS package treatable¸¦ ±â¾ïÇÏ°í ÀÖ´Ù¸é)
Some of the key signs are I got nothing recognizable in the strings of things.
ÀÌ (notepad¿¡ ÀÖ´Â)ÇÁ·Î±×·¥¾îÀÇ ³ª¿­¿¡¼­ ¿³º¼ ¼ö ÀÖ´Â °ÍÀº ±×·¸°Ô Ưº°ÇÑ °ÍÀº ¾øÀ¸³ª
I don¡¯t see a Niclues of imported functions.
Niclues of imported functions¸¦ ã¾Æ º¼ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.
Okay, so there is something funny going on there.
ÁÁ½À´Ï´Ù, ±×·¡¼­ °Å±â¿¡´Â ¹º°¡ Àç¹Õ´Â°ÍÀÌ ÀÖ½À´Ï´Ù.
I am going to go ahead run this utility called PDID (Packer Unifier) on it.
ÀÚ ´ÙÀ½À¸·Î PDID (packer unifier)¶ó´Â À¯Æ¿¸®Æ¼¸¦ ½ÇÇà½Ãų °ÍÀÔ´Ï´Ù.
And point it at that file.
±×¸®°í ÁöÁ¤µÈ ÆÄÀÏÀ» Ŭ¸¯ÇÕ´Ï´Ù.
This modified version of (1:30~1:50).
(1:30 ~ 1:50 ±îÁö µé¸®Áö ¾Ê¾Æ¼­ ¸øÇß¾î¿ä ¤Ì¤Ì)
At this point you can load it up on online pro.
ÀÌ ½ÃÁ¡¿¡¼­ ´ç½ÅÀº ÀÌ°ÍÀ» ¿Â¶óÀο¡ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù.
And at first I need to tell you.
¿ì¼± ¸»Çϰǵ¥
A lot of it are something.
´ëºÎºÐÀÇ °ÍµéÀÌ °ÅÀÇ´Ù ¶È°°½À´Ï´Ù.
Something funny is going on here, asking whether to upload it up.
¾Æ ½Å±âÇÑ ÀÏÀÌ ÀϾ³×¿ä, PDID°¡ ¿Ã¸± °ÇÁö ¸» °ÇÁö ¹°¾îº¾´Ï´Ù.
And sure.
Yes¸¦ Ŭ¸¯ÇØÁÖ¼¼¿ä.
You can tell quickly that this is not normal programming, bubble code is jumping around all like this.
ÀÚ º¸½Ã´Ù½ÃÇÇ MJT´Â ´Ù¸¥ ÇÁ·Î±×·¥°ú ¸¹ÀÌ ´Ù¸¨´Ï´Ù. Bubble code°¡ ³­ÀâÇÏ°Ô ¹è¿­ÇØ ÀÖ½À´Ï´Ù.
Have things like ¡°no call¡¯ one instruction ahead.
±×¸®°í ÇÁ·Î±×·¡¸Ó°¡ Áö½Ãµµ ³»¸®±â ÀüÀε¥(ÇϳªÂ÷ÀÌ) ¡°no call¡±°°Àº ¸í·ÉÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù (or °°Àº °ÍµéÀÌ Á¸ÀçÇÕ´Ï´Ù.)
So what we normally do in this case is call Nico.
ÀÌ·± »óȲ¿¡ ÀÖÀ» ¶§ (unpacking ÇÒ¶§) ¿ì¸®´Â Nico (°ËÀº»ö ¸Ó¸® »ç¶÷) ¸¦ ºÎ¸¨´Ï´Ù.

Nico: ¡°UnpackingÀ̶õ ÀÛ¾÷Àº reverse engineer¿¡°Ô »ó´çÈ÷ Æí¸®ÇÑ ±â´ÉÀÔ´Ï´Ù. ÇöÀçÀÇ °ÅÀÇ ¸ðµç ÆÄÀϵéÀÌ packedµÇ ÀÖ¾î¿ä. ƯÈ÷ malwareµéÀÌ¿ä.
Sometimes worms and malwares affect with Houston packers, tools like PID, Walt, multisizing packer=strategy to find out which packer was used and is in effect is to look at the last section of and the characters of the sections.
ÀÌ ¼¼°è¿¡´Â ¾ÆÁÖ ¸¹Àº ¼öÀÇ PE packers°¡ ÀÖ°í PE protector °¡ ÀÖ½À´Ï´Ù. °¡²û°¡´Ù worms³ª malwares°¡ Houston packers¿Í ÇÔ²² °ø°ÝÇÕ´Ï´Ù.  À̹ۿ¡µµ PID, Walt, multisizing packer°°Àº µµ±¸¸¦ ÀÌ¿ëÇÕ´Ï´Ù. ¾î¶² Çü½ÄÀÇ packer°¡ »ç¿ëµÇ°í ¾î¶² toolÀÌ ÀÌ¿ëµÇ°í ÀÖ´ÂÁö ¾Ë¾Æ º¼ ¼ö ÀÖ´Â ÇÑ Àü·«Àº ??? ÀÇ ¸¶Áö¸· ¼½¼Ç°ú ±× ¼½¼ÇÀÇ Æ¯¼ºµéÀ» ÆľÇÇÏ´Â °ÍÀÔ´Ï´Ù.
If the last sections are executable it can fight back virus.
¸¸¾à ¸¶Áö¸· ¼½¼ÇÀÌ executable ÇÏ´Ù¸é ¹ÙÀÌ·¯½º¿¡ ´ëÇ× ÇÒ ¼ö ÀÖ½À´Ï´Ù.

  Hit : 1601     Date : 2011/08/02 12:14



    
47   À̹ø ÀÛ¾÷(nish_bhalla_auditing_source_code) ¿øº» ÆÄÀÏÀÌ¿ä.     W.H.
05/03 1725
46   ÀÚ¸·(¿µ¾î,Çѱ۸¸ ¿Ï¼º ½ÌÅ© ¿¡·¯)[1]     d4rkang3l
06/16 1718
45   ÆÄÆ® 2¿¡ ´ëÇÑ Çùµ¿ ¸®½º´×&¹ø¿ªÀ» ÁøÇàÇÕ´Ï´Ù.     ¸Û¸Û
05/16 1716
44   ÆÄÆ®2 ¾î¶»°Ô µÈ°ÅÁÒ..[2]     ahotsuna
05/16 1705
43   WIKI ¶Ç ´Ù¿îµÅ¼­ ÆÄÆ® 7 ¿©±â¿¡ ¿Ã¸³´Ï´Ù     ¸Û¸Û
06/02 1697
42   ¹ø¿ª ½ºÄÉÁì ¼öÁ¤ÇÏ¿´½À´Ï´Ù.     ¸Û¸Û
05/13 1686
41   ´Ù¸¥ ºÐµéÀº ¾ó¸¶³ª Çϼ̳ª¿ä?[3]     ahotsuna
07/31 1684
40   Á¦ 1ȸ ¹ø¿ª ÀÚ¸· °ü·ÃÀÔ´Ï´Ù.     ¸Û¸Û
06/02 1671
39   2¹ø ÆÄÆ® ¸®½º´×&¹ø¿ªÀÔ´Ï´Ù.[2]     stardung86
05/09 1668
38   Àú±â Á˼ÛÇѵ¥,,[1]     bluemario
05/12 1668
37   ÆÄÆ® 2¹ø ºÐ·®ÀÔ´Ï´Ù. (90% Á¤µµµÆ°í ¾ÆÁ÷ 10% - ¾à 30~40Ãʺз®- ¹Ì¿ÏÀÔ´Ï´Ù.))     CodeAche
08/02 1668
36   ¸®½º´× & ¹ø¿ª ½ÃÀÇ ±ÔÄ¢ÀÌ ¾÷µ¥ÀÌÆ® µÇ¾ú½À´Ï´Ù.     ¸Û¸Û
05/21 1665
35   4¹ø ÆÄÆ® ¹ø¿ª ¿Ã¸³´Ï´Ù.     babyalpha
08/01 1658
34   5¹ø ÆÄÀÏ[1]     ¼­°æÀç
05/10 1643
33   8¹ø ÆÄÆ®ÀÔ´Ï´Ù[1]     Prox
05/11 1643
32   Á¦ 1ȸ ¹ø¿ª ÁøÇà »óȲÀÔ´Ï´Ù.[1]     ¸Û¸Û
05/11 1632
31   ¿À´Ã ÀÛ¾÷ ÇÒ ÆÄÆ® 4~6 ¸µÅ©ÀÔ´Ï´Ù.[4]     ¸Û¸Û
05/17 1625
30   7¹ø ÆÄÆ® ÂÉ°³ÁÖ½Ç ºÐ ã½À´Ï´Ù.[2]     ¸Û¸Û
05/11 1621
29   ÀÚ¸· - ÃÖÁ¾ ¼öÁ¤º»ÀÔ´Ï´Ù~     ¸Û¸Û
06/30 1602
28   ¹ø¿ªÆÀ ºÐµé ÀüÈ­¹øÈ£Á» ÂÊÁö·Î º¸³»ÁÖ¼¼¿ä~     ¸Û¸Û
05/17 1600
  ÆÄÆ®8 ºÐ·®ÀÔ´Ï´Ù.     lycan
08/02 1600
26   ÆÄÆ® 7, 8¸¸ Á¶±Ý ´õ º¸°­ÇÏ°í ¹ø¿ª Á¾·áÇÏ°Ú½À´Ï´Ù~!     ¸Û¸Û
05/25 1599
25   5¿ù 20ÀÏ Á¤Æà ³»¿ë ¿ä¾àÀÔ´Ï´Ù.[4]     ¸Û¸Û
05/21 1597
24   ÀÚ¸· ¿Ã¸³´Ï´Ù~[4]     lycan
06/13 1596
23     [re] °³Çà ¹× ÀϺΠ¼öÁ¤ÇÑ ÀÚ¸· ¿Ã¸³´Ï´Ù.[1]     lycan
06/15 1596
[1][2] 3 [4]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org