안녕하십니까? 잉카인터넷 nProtect 입니다.


2017년 03월 21일자 두번째 업데이트 안내문입니다.


금일 정기 업데이트에서는 총 2개 악성코드에 대한 진단/치료가 안티 바이러스에 업데이트 되었습니다.



1. 안티 바이러스 업데이트 안내


1-1. 안티 바이러스 업데이트 버전 : 2017-03-21.02


1-2. 다음 2개 악성코드에 대한 진단/치료가 자사 엔진에 업데이트 되었습니다.


Banker/W32.Agent.333824
Trojan-Dropper/W32.Agent.335304


--------------------------------------------------------------------------------------

       Copyright ⓒ, (주) 잉카인터넷, 2000-2017, All rights reserved.

--------------------------------------------------------------------------------------

저작자 표시 비영리 변경 금지
신고
크리에이티브 커먼즈 라이선스
Creative Commons License
Posted by Erteam

안녕하십니까? 잉카인터넷 nProtect 입니다.


2017년 03월 21일자 첫번째 업데이트 안내문입니다.


금일 정기 업데이트에서는 총 1022개 악성코드에 대한 진단/치료가 안티 바이러스에 업데이트 되었습니다.



1. 안티 바이러스 업데이트 안내


1-1. 안티 바이러스 업데이트 버전 : 2017-03-21.01


1-2. 다음 1022개 악성코드에 대한 진단/치료가 자사 엔진에 업데이트 되었습니다.


Backdoor/W32.Agent.106496.FF
Backdoor/W32.Agent.10708961
Backdoor/W32.Agent.1098099
Backdoor/W32.Agent.1098245
Backdoor/W32.Agent.1142784.K
Backdoor/W32.Agent.1171976
Backdoor/W32.Agent.1207808.G
Backdoor/W32.Agent.1266107
Backdoor/W32.Agent.126976.EG
Backdoor/W32.Agent.1284982
Backdoor/W32.Agent.1290660
Backdoor/W32.Agent.13059042
Backdoor/W32.Agent.131072.FS
Backdoor/W32.Agent.134144.X
Backdoor/W32.Agent.139746
Backdoor/W32.Agent.143875
Backdoor/W32.Agent.146651
Backdoor/W32.Agent.151040.AD
Backdoor/W32.Agent.158208.AH
Backdoor/W32.Agent.161285
Backdoor/W32.Agent.164193
Backdoor/W32.Agent.1704448
Backdoor/W32.Agent.1713152.B
Backdoor/W32.Agent.178688.N
Backdoor/W32.Agent.20663
Backdoor/W32.Agent.2151904
Backdoor/W32.Agent.230308
Backdoor/W32.Agent.247203
Backdoor/W32.Agent.255470
Backdoor/W32.Agent.291760
Backdoor/W32.Agent.332152
Backdoor/W32.Agent.345445
Backdoor/W32.Agent.377246
Backdoor/W32.Agent.382464.P
Backdoor/W32.Agent.410040
Backdoor/W32.Agent.447326
Backdoor/W32.Agent.468874
Backdoor/W32.Agent.545142
Backdoor/W32.Agent.633908
Backdoor/W32.Agent.66560.CX
Backdoor/W32.Agent.6806986
Backdoor/W32.Agent.722834
Backdoor/W32.Agent.90624.AY
Backdoor/W32.Agent.917504.AE
Backdoor/W32.Agent.974805
Backdoor/W32.Agent.98304.JQ
Backdoor/W32.Androm.110592.AG
Backdoor/W32.Androm.131072.AQ
Backdoor/W32.Androm.13705216
Backdoor/W32.Androm.151552.AJ
Backdoor/W32.Androm.184832.C
Backdoor/W32.Androm.212992.G
Backdoor/W32.Androm.528384.E
Backdoor/W32.Androm.86016.N
Backdoor/W32.Bedep.311296
Backdoor/W32.DarkKomet.1036288.E
Backdoor/W32.Farfli.77939
Backdoor/W32.Gulpix.32768.D
Backdoor/W32.Gulpix.32768.E
Backdoor/W32.Hlux.1097132
Backdoor/W32.Hlux.1097329
Backdoor/W32.Hlux.1097604
Backdoor/W32.Hlux.1097968
Backdoor/W32.Hupigon.283877
Backdoor/W32.IRCNite.2396921
Backdoor/W32.NanoBot.528384.B
Backdoor/W32.Prorat.1473202
Backdoor/W32.Prorat.2890777
Backdoor/W32.RemoteManipulator.5304320
Banker/W32.Agent.237807
Banker/W32.Agent.4415216
Banker/W32.Agent.4415216.B
Banker/W32.Agent.519680
Banker/W32.Agent.746496
Banker/W32.BestaFera.3872256
Banker/W32.BestaFera.392192.C
Banker/W32.BestaFera.756736
Banker/W32.Tinba.126976
Banker/W32.Tinba.69632
Banker/W32.Tinba.69632.B
Downloader/W32.Agent.66644
Downloader/W32.Agent.68149
Ransom/W32.Agent.255178.C
Ransom/W32.Agent.255190.B
Ransom/W32.Agent.289872
Ransom/W32.Agent.406697
Ransom/W32.Agent.504234
Ransom/W32.Cerber.196864
Ransom/W32.Cerber.261321
Ransom/W32.Cerber.261322
Ransom/W32.Cerber.261334
Ransom/W32.Cerber.261834
Ransom/W32.Cerber.261834.B
Ransom/W32.Cerber.261834.C
Ransom/W32.Cerber.261845
Ransom/W32.Cerber.261845.B
Ransom/W32.Cerber.261846
Ransom/W32.Cerber.261846.B
Ransom/W32.Cerber.262857
Ransom/W32.Cerber.262858
Ransom/W32.Cerber.262858.B
Ransom/W32.Cerber.262858.C
Ransom/W32.Cerber.262869
Ransom/W32.Cerber.305833
Ransom/W32.Cerber.476329
Ransom/W32.Crusis.468992
Ransom/W32.CryptXXX.14279091
Ransom/W32.Foreign.208968
Ransom/W32.Foreign.242176
Ransom/W32.Foreign.277504
Ransom/W32.Foreign.417856.B
Ransom/W32.Foreign.429056
Ransom/W32.Foreign.574976
Ransom/W32.Locky.340992
Ransom/W32.SageCrypt.324352
Ransom/W32.SageCrypt.328192
Ransom/W32.SageCrypt.374784
Ransom/W32.SageCrypt.398592
Ransom/W32.SageCrypt.423168
Ransom/W32.SageCrypt.544512
Ransom/W32.Spora.70144
Ransom/W32.Spora.70144.B
Ransom/W32.Spora.70144.C
Ransom/W32.Spora.70144.D
Trojan-Downloader/W32.AdLoad.30414
Trojan-Downloader/W32.AdLoad.501994
Trojan-Downloader/W32.Agent.2074545
Trojan-Downloader/W32.Agent.403500
Trojan-Downloader/W32.Agent.90048
Trojan-Downloader/W32.Banload.1285120.B
Trojan-Downloader/W32.Dofoil.173056.C
Trojan-Downloader/W32.Refroso.557056
Trojan-Downloader/W32.Snoload.627712
Trojan-Downloader/W32.Upatre.112916
Trojan-Downloader/W32.Upatre.112948
Trojan-Downloader/W32.Upatre.123384
Trojan-Downloader/W32.Upatre.123448
Trojan-Downloader/W32.Upatre.123584
Trojan-Downloader/W32.Upatre.123650
Trojan-Downloader/W32.Upatre.123720
Trojan-Downloader/W32.Upatre.123786
Trojan-Downloader/W32.Upatre.123856
Trojan-Downloader/W32.Upatre.125002
Trojan-Downloader/W32.Upatre.125216
Trojan-Downloader/W32.Upatre.125505
Trojan-Downloader/W32.Upatre.246160
Trojan-Downloader/W32.Upatre.246459
Trojan-Downloader/W32.Upatre.246504
Trojan-Downloader/W32.Upatre.247168
Trojan-Downloader/W32.Upatre.248480
Trojan-Downloader/W32.Upatre.249832
Trojan-Downloader/W32.Upatre.254907
Trojan-Downloader/W32.Upatre.255043
Trojan-Downloader/W32.Upatre.255344
Trojan-Downloader/W32.Upatre.257920
Trojan-Downloader/W32.Upatre.26726
Trojan-Downloader/W32.Upatre.26790.B
Trojan-Downloader/W32.Upatre.26926
Trojan-Downloader/W32.Upatre.27062
Trojan-Downloader/W32.Upatre.362996
Trojan-Downloader/W32.Upatre.363116
Trojan-Downloader/W32.Upatre.363476
Trojan-Downloader/W32.Upatre.364608
Trojan-Downloader/W32.Upatre.364670
Trojan-Downloader/W32.Upatre.369204
Trojan-Downloader/W32.Upatre.369236
Trojan-Downloader/W32.Upatre.369340
Trojan-Downloader/W32.Upatre.370068
Trojan-Downloader/W32.Upatre.370100
Trojan-Downloader/W32.Upatre.370260
Trojan-Downloader/W32.Upatre.371036
Trojan-Downloader/W32.Upatre.371172
Trojan-Downloader/W32.Upatre.372500
Trojan-Downloader/W32.Upatre.372588
Trojan-Downloader/W32.Upatre.372596
Trojan-Downloader/W32.Upatre.372892
Trojan-Downloader/W32.Upatre.373180
Trojan-Downloader/W32.Upatre.373876
Trojan-Downloader/W32.Upatre.374012
Trojan-Downloader/W32.Upatre.374388
Trojan-Downloader/W32.Upatre.374868
Trojan-Downloader/W32.Upatre.374940
Trojan-Downloader/W32.Upatre.375156
Trojan-Downloader/W32.Upatre.375228
Trojan-Downloader/W32.Upatre.375732
Trojan-Downloader/W32.Upatre.38016.J
Trojan-Downloader/W32.Upatre.38048.F
Trojan-Downloader/W32.Upatre.38130.E
Trojan-Downloader/W32.Upatre.38418.B
Trojan-Downloader/W32.Upatre.38514
Trojan-Downloader/W32.Upatre.38554.B
Trojan-Downloader/W32.Upatre.38688.B
Trojan-Downloader/W32.Upatre.39392.C
Trojan-Downloader/W32.Upatre.39528.E
Trojan-Downloader/W32.Upatre.39646
Trojan-Downloader/W32.Upatre.39782
Trojan-Downloader/W32.Upatre.40032.D
Trojan-Downloader/W32.Upatre.40174
Trojan-Downloader/W32.Upatre.40382.B
Trojan-Downloader/W32.Upatre.40510
Trojan-Downloader/W32.Upatre.40654
Trojan-Downloader/W32.Upatre.40670
Trojan-Downloader/W32.Upatre.41024.D
Trojan-Downloader/W32.Upatre.41156.B
Trojan-Downloader/W32.Upatre.41204.C
Trojan-Downloader/W32.Upatre.41292.B
Trojan-Downloader/W32.Upatre.41320.D
Trojan-Downloader/W32.Upatre.41340.B
Trojan-Downloader/W32.Upatre.41372.B
Trojan-Downloader/W32.Upatre.41428.B
Trojan-Downloader/W32.Upatre.41476
Trojan-Downloader/W32.Upatre.41492.B
Trojan-Downloader/W32.Upatre.41500.B
Trojan-Downloader/W32.Upatre.41564
Trojan-Downloader/W32.Upatre.41628
Trojan-Downloader/W32.Upatre.41636
Trojan-Downloader/W32.Upatre.41720.B
Trojan-Downloader/W32.Upatre.42208.B
Trojan-Downloader/W32.Upatre.425560
Trojan-Downloader/W32.Upatre.42688.B
Trojan-Downloader/W32.Upatre.43096
Trojan-Downloader/W32.Upatre.43610.B
Trojan-Downloader/W32.Upatre.43610.C
Trojan-Downloader/W32.Upatre.44226
Trojan-Downloader/W32.Upatre.44330
Trojan-Downloader/W32.Upatre.44458
Trojan-Downloader/W32.Upatre.47136.C
Trojan-Downloader/W32.Upatre.47136.D
Trojan-Downloader/W32.Upatre.47200
Trojan-Downloader/W32.Upatre.47272.B
Trojan-Downloader/W32.Upatre.47288.B
Trojan-Downloader/W32.Upatre.47288.C
Trojan-Downloader/W32.Upatre.47288.D
Trojan-Downloader/W32.Upatre.47288.E
Trojan-Downloader/W32.Upatre.47424.B
Trojan-Downloader/W32.Upatre.47424.C
Trojan-Downloader/W32.Upatre.47560.B
Trojan-Downloader/W32.Upatre.47696
Trojan-Downloader/W32.Upatre.47712
Trojan-Downloader/W32.Upatre.47832
Trojan-Downloader/W32.Upatre.48724
Trojan-Downloader/W32.Upatre.68164
Trojan-Downloader/W32.Upatre.68164.B
Trojan-Downloader/W32.Upatre.68164.C
Trojan-Downloader/W32.Upatre.68164.D
Trojan-Downloader/W32.Upatre.68164.E
Trojan-Downloader/W32.Upatre.68164.F
Trojan-Downloader/W32.Upatre.68164.G
Trojan-Downloader/W32.Upatre.68164.H
Trojan-Downloader/W32.Upatre.68164.I
Trojan-Downloader/W32.Upatre.68164.J
Trojan-Downloader/W32.Upatre.68164.K
Trojan-Downloader/W32.Upatre.68164.L
Trojan-Downloader/W32.Upatre.68164.M
Trojan-Downloader/W32.Upatre.68164.N
Trojan-Downloader/W32.Upatre.68164.O
Trojan-Downloader/W32.Upatre.68164.P
Trojan-Downloader/W32.Upatre.68300
Trojan-Downloader/W32.Upatre.68300.B
Trojan-Downloader/W32.Upatre.68300.C
Trojan-Downloader/W32.Upatre.68300.D
Trojan-Downloader/W32.Upatre.68300.E
Trojan-Downloader/W32.Upatre.68300.F
Trojan-Downloader/W32.Upatre.68300.G
Trojan-Downloader/W32.Upatre.68436
Trojan-Downloader/W32.Upatre.68684
Trojan-Downloader/W32.Upatre.68820
Trojan-Downloader/W32.Upatre.72036.B
Trojan-Downloader/W32.Upatre.72708
Trojan-Downloader/W32.Upatre.72740
Trojan-Downloader/W32.Upatre.76978
Trojan-Dropper/W32.Agent.120659
Trojan-Dropper/W32.Agent.235859
Trojan-Dropper/W32.Agent.327680.CJ
Trojan-Dropper/W32.Agent.360448.BH
Trojan-Dropper/W32.Agent.4889348
Trojan-Dropper/W32.Agent.6110244
Trojan-Dropper/W32.Agent.7121408
Trojan-Dropper/W32.Agent.7334356
Trojan-Dropper/W32.Agent.8283860
Trojan-Dropper/W32.Dapato.3806720
Trojan-Dropper/W32.Dapato.6054400
Trojan-Dropper/W32.Dapato.8584704
Trojan-Dropper/W32.Daws.1650688.C
Trojan-Dropper/W32.Daws.1920946
Trojan-Dropper/W32.Dorgam.106496
Trojan-Dropper/W32.Dycler.4409159
Trojan-Dropper/W32.FrauDrop.15360.FL
Trojan-Dropper/W32.Inject.285088
Trojan-Dropper/W32.Inject.3851283
Trojan-Dropper/W32.Inject.5823008
Trojan-Dropper/W32.Keylogger.163840.C
Trojan-Dropper/W32.Keylogger.568289
Trojan-Dropper/W32.Microjoin.130840
Trojan-Dropper/W32.Pincher.53530
Trojan-Dropper/W32.Pincher.53531
Trojan-PWS/W32.Fareit.116871
Trojan-PWS/W32.Fareit.139264.N
Trojan-PWS/W32.Fareit.147456.R
Trojan-PWS/W32.Fareit.151552.P
Trojan-PWS/W32.Fareit.159744.I
Trojan-PWS/W32.Fareit.188416.Q
Trojan-PWS/W32.Fareit.222088
Trojan-PWS/W32.Fareit.278528.E
Trojan-PWS/W32.Fareit.290816.N
Trojan-PWS/W32.Fareit.296448.B
Trojan-PWS/W32.Fareit.356352.G
Trojan-PWS/W32.Fareit.364544.D
Trojan-PWS/W32.Fareit.528384.E
Trojan-PWS/W32.Fareit.699392
Trojan-PWS/W32.QQPass.2439688
Trojan-PWS/W32.QQPass.605038
Trojan-PWS/W32.Tepfer.159744.AT
Trojan-PWS/W32.Tepfer.212992.N
Trojan-PWS/W32.Tepfer.217088.AA
Trojan-PWS/W32.Tepfer.90112.BZ
Trojan-Spy/W32.Agent.151552.AN
Trojan-Spy/W32.Agent.1611264.B
Trojan-Spy/W32.Agent.280064.H
Trojan-Spy/W32.Agent.46592.O
Trojan-Spy/W32.Recam.877056
Trojan-Spy/W32.ZBot.135720
Trojan-Spy/W32.ZBot.135858
Trojan-Spy/W32.ZBot.161792.EC
Trojan-Spy/W32.ZBot.20628.E
Trojan-Spy/W32.ZBot.20886.C
Trojan-Spy/W32.ZBot.21024.C
Trojan-Spy/W32.ZBot.30174.B
Trojan-Spy/W32.ZBot.310784.XP
Trojan-Spy/W32.ZBot.324096.BA
Trojan-Spy/W32.ZBot.35586
Trojan-Spy/W32.ZBot.356864.BE
Trojan-Spy/W32.ZBot.35698
Trojan-Spy/W32.ZBot.35722
Trojan-Spy/W32.ZBot.357376.AR
Trojan-Spy/W32.ZBot.35858
Trojan-Spy/W32.ZBot.36162
Trojan-Spy/W32.ZBot.36370
Trojan-Spy/W32.ZBot.528384.AG
Trojan-Spy/W32.ZBot.62846
Trojan-Spy/W32.ZBot.62984
Trojan-Spy/W32.ZBot.850718
Trojan-Spy/W32.ZBot.87080
Trojan-Spy/W32.ZBot.87752
Trojan-Spy/W32.ZBot.87888
Trojan-Spy/W32.ZBot.88024
Trojan/W32.AddUser.41802
Trojan/W32.Agent.1015808.FZ
Trojan/W32.Agent.10240.ZA
Trojan/W32.Agent.102400.ESA
Trojan/W32.Agent.1044624
Trojan/W32.Agent.1048576.KP
Trojan/W32.Agent.1048576.KQ
Trojan/W32.Agent.105472.UZ
Trojan/W32.Agent.10866487
Trojan/W32.Agent.1092608.Z
Trojan/W32.Agent.12308480.B
Trojan/W32.Agent.1237975
Trojan/W32.Agent.126976.CTE
Trojan/W32.Agent.126976.CTF
Trojan/W32.Agent.1289175
Trojan/W32.Agent.13090816
Trojan/W32.Agent.1328128.Y
Trojan/W32.Agent.1329664.T
Trojan/W32.Agent.139264.CJI
Trojan/W32.Agent.14336.VC
Trojan/W32.Agent.159232.PV
Trojan/W32.Agent.159744.BWQ
Trojan/W32.Agent.160256.QP
Trojan/W32.Agent.160768.SC
Trojan/W32.Agent.161280.TE
Trojan/W32.Agent.161792.VG
Trojan/W32.Agent.162304.TE
Trojan/W32.Agent.162816.TL
Trojan/W32.Agent.163328.PR
Trojan/W32.Agent.1636350
Trojan/W32.Agent.163840.CPS
Trojan/W32.Agent.164352.QE
Trojan/W32.Agent.164864.PO
Trojan/W32.Agent.165376.RE
Trojan/W32.Agent.165888.SH
Trojan/W32.Agent.166400.TD
Trojan/W32.Agent.166912.SH
Trojan/W32.Agent.167424.RH
Trojan/W32.Agent.167936.BNA
Trojan/W32.Agent.1782272.F
Trojan/W32.Agent.1810432.BR
Trojan/W32.Agent.194048.NO
Trojan/W32.Agent.202079
Trojan/W32.Agent.205699.B
Trojan/W32.Agent.208896.AVZ
Trojan/W32.Agent.212992.BTO
Trojan/W32.Agent.21504.ACU
Trojan/W32.Agent.21504.ACV
Trojan/W32.Agent.21504.ACW
Trojan/W32.Agent.21504.ACX
Trojan/W32.Agent.21504.ACY
Trojan/W32.Agent.21504.ACZ
Trojan/W32.Agent.21504.ADA
Trojan/W32.Agent.22016.YX
Trojan/W32.Agent.22016.YY
Trojan/W32.Agent.221817.B
Trojan/W32.Agent.2224128.AH
Trojan/W32.Agent.225861.C
Trojan/W32.Agent.228550.B
Trojan/W32.Agent.229569.D
Trojan/W32.Agent.24064.ABV
Trojan/W32.Agent.241152.IJ
Trojan/W32.Agent.2645343
Trojan/W32.Agent.266622
Trojan/W32.Agent.266752.KG
Trojan/W32.Agent.268034.B
Trojan/W32.Agent.280645.B
Trojan/W32.Agent.280649
Trojan/W32.Agent.286728.J
Trojan/W32.Agent.287802.C
Trojan/W32.Agent.29384.D
Trojan/W32.Agent.29416.C
Trojan/W32.Agent.29756.C
Trojan/W32.Agent.30874.B
Trojan/W32.Agent.31216.D
Trojan/W32.Agent.32768.ECJ
Trojan/W32.Agent.338237
Trojan/W32.Agent.34846.D
Trojan/W32.Agent.3496897
Trojan/W32.Agent.35526
Trojan/W32.Agent.358096
Trojan/W32.Agent.35840.VS
Trojan/W32.Agent.35944.D
Trojan/W32.Agent.36466.D
Trojan/W32.Agent.368121
Trojan/W32.Agent.36832
Trojan/W32.Agent.369152.HA
Trojan/W32.Agent.37278.C
Trojan/W32.Agent.373248.HU
Trojan/W32.Agent.376361
Trojan/W32.Agent.377344.GF
Trojan/W32.Agent.384000.FR
Trojan/W32.Agent.386120
Trojan/W32.Agent.396831.C
Trojan/W32.Agent.396890.C
Trojan/W32.Agent.407040.IE
Trojan/W32.Agent.415921
Trojan/W32.Agent.415925
Trojan/W32.Agent.425954
Trojan/W32.Agent.427520.FU
Trojan/W32.Agent.44895.B
Trojan/W32.Agent.491520.SD
Trojan/W32.Agent.49174.C
Trojan/W32.Agent.498903
Trojan/W32.Agent.500660
Trojan/W32.Agent.501248.CU
Trojan/W32.Agent.516096.OY
Trojan/W32.Agent.518144.DI
Trojan/W32.Agent.524358.B
Trojan/W32.Agent.524360.E
Trojan/W32.Agent.526743
Trojan/W32.Agent.53410.D
Trojan/W32.Agent.534966
Trojan/W32.Agent.54822.F
Trojan/W32.Agent.548248.B
Trojan/W32.Agent.600396
Trojan/W32.Agent.60470.F
Trojan/W32.Agent.631566
Trojan/W32.Agent.639068
Trojan/W32.Agent.64706.D
Trojan/W32.Agent.67584.AQL
Trojan/W32.Agent.679938.B
Trojan/W32.Agent.69120.AEV
Trojan/W32.Agent.700416.NN
Trojan/W32.Agent.70354.G
Trojan/W32.Agent.708055
Trojan/W32.Agent.711877
Trojan/W32.Agent.7168.YY
Trojan/W32.Agent.735848
Trojan/W32.Agent.753664.MO
Trojan/W32.Agent.753664.MP
Trojan/W32.Agent.7680.XH
Trojan/W32.Agent.7680.XI
Trojan/W32.Agent.7680.XJ
Trojan/W32.Agent.811008.KG
Trojan/W32.Agent.82634.F
Trojan/W32.Agent.835584.JN
Trojan/W32.Agent.844569
Trojan/W32.Agent.851968.MZ
Trojan/W32.Agent.86016.EBM
Trojan/W32.Agent.862720.B
Trojan/W32.Agent.862720.C
Trojan/W32.Agent.868352.IQ
Trojan/W32.Agent.8704.AHM
Trojan/W32.Agent.889344.BF
Trojan/W32.Agent.930816
Trojan/W32.Agent.94208.EDN
Trojan/W32.Agent.96342
Trojan/W32.Agent.968704
Trojan/W32.Agent.97785.C
Trojan/W32.AntiAV.1665024
Trojan/W32.Bcex.1044480
Trojan/W32.Bcex.1100288
Trojan/W32.Biodata.761344
Trojan/W32.Bublik.22460
Trojan/W32.Bublik.22596
Trojan/W32.Bublik.22732.B
Trojan/W32.Bublik.27500
Trojan/W32.Bublik.27602
Trojan/W32.Bublik.27740
Trojan/W32.Bublik.27874
Trojan/W32.Bublik.27884
Trojan/W32.Bublik.28012
Trojan/W32.Bublik.28022
Trojan/W32.Bublik.28150
Trojan/W32.Bublik.28288
Trojan/W32.Bublik.573504
Trojan/W32.Bublik.647200
Trojan/W32.Bublik.89316
Trojan/W32.Bublik.901152
Trojan/W32.Crypt.1254336
Trojan/W32.Crypt.1266688
Trojan/W32.Crypt.1266712
Trojan/W32.Crypt.1266712.AA
Trojan/W32.Crypt.1266712.AB
Trojan/W32.Crypt.1266712.AC
Trojan/W32.Crypt.1266712.AD
Trojan/W32.Crypt.1266712.AE
Trojan/W32.Crypt.1266712.AF
Trojan/W32.Crypt.1266712.AG
Trojan/W32.Crypt.1266712.AH
Trojan/W32.Crypt.1266712.AI
Trojan/W32.Crypt.1266712.AJ
Trojan/W32.Crypt.1266712.AK
Trojan/W32.Crypt.1266712.AL
Trojan/W32.Crypt.1266712.AM
Trojan/W32.Crypt.1266712.AN
Trojan/W32.Crypt.1266712.AO
Trojan/W32.Crypt.1266712.AP
Trojan/W32.Crypt.1266712.AQ
Trojan/W32.Crypt.1266712.AR
Trojan/W32.Crypt.1266712.AS
Trojan/W32.Crypt.1266712.AT
Trojan/W32.Crypt.1266712.AU
Trojan/W32.Crypt.1266712.AV
Trojan/W32.Crypt.1266712.AW
Trojan/W32.Crypt.1266712.AX
Trojan/W32.Crypt.1266712.AY
Trojan/W32.Crypt.1266712.AZ
Trojan/W32.Crypt.1266712.B
Trojan/W32.Crypt.1266712.C
Trojan/W32.Crypt.1266712.D
Trojan/W32.Crypt.1266712.E
Trojan/W32.Crypt.1266712.F
Trojan/W32.Crypt.1266712.G
Trojan/W32.Crypt.1266712.H
Trojan/W32.Crypt.1266712.I
Trojan/W32.Crypt.1266712.J
Trojan/W32.Crypt.1266712.K
Trojan/W32.Crypt.1266712.L
Trojan/W32.Crypt.1266712.M
Trojan/W32.Crypt.1266712.N
Trojan/W32.Crypt.1266712.O
Trojan/W32.Crypt.1266712.P
Trojan/W32.Crypt.1266712.Q
Trojan/W32.Crypt.1266712.R
Trojan/W32.Crypt.1266712.S
Trojan/W32.Crypt.1266712.T
Trojan/W32.Crypt.1266712.U
Trojan/W32.Crypt.1266712.V
Trojan/W32.Crypt.1266712.W
Trojan/W32.Crypt.1266712.X
Trojan/W32.Crypt.1266712.Y
Trojan/W32.Crypt.1266712.Z
Trojan/W32.Crypt.15194112
Trojan/W32.Csfrsys.176847
Trojan/W32.DNSChanger.72723.C
Trojan/W32.DNSChanger.73763.F
Trojan/W32.DNSChanger.73785.C
Trojan/W32.DNSChanger.73822.C
Trojan/W32.Fsysna.1424602
Trojan/W32.Fsysna.2883072
Trojan/W32.Gofot.4350848
Trojan/W32.Gotango.1549312
Trojan/W32.Inject.10503231
Trojan/W32.Inject.109793
Trojan/W32.Inject.1173585
Trojan/W32.Inject.127125
Trojan/W32.Inject.131458.B
Trojan/W32.Inject.148811
Trojan/W32.Inject.152241
Trojan/W32.Inject.194048.C
Trojan/W32.Inject.259025
Trojan/W32.Inject.262144.W
Trojan/W32.Inject.3123036
Trojan/W32.Inject.40960.CE
Trojan/W32.Inject.419328.C
Trojan/W32.Inject.419328.D
Trojan/W32.Inject.419840.G
Trojan/W32.Inject.421888.O
Trojan/W32.Inject.66560.KTV
Trojan/W32.Inject.66560.KTW
Trojan/W32.Inject.66560.KTX
Trojan/W32.Inject.66560.KTY
Trojan/W32.Inject.66560.KTZ
Trojan/W32.Inject.66560.KUA
Trojan/W32.Inject.66560.KUB
Trojan/W32.Inject.66560.KUC
Trojan/W32.Inject.66560.KUD
Trojan/W32.Inject.66560.KUE
Trojan/W32.Inject.66560.KUF
Trojan/W32.Inject.66560.KUG
Trojan/W32.Inject.66560.KUH
Trojan/W32.Inject.66560.KUI
Trojan/W32.Inject.66560.KUJ
Trojan/W32.Inject.66560.KUK
Trojan/W32.Inject.66560.KUL
Trojan/W32.Inject.66560.KUM
Trojan/W32.Inject.66560.KUN
Trojan/W32.Inject.66560.KUO
Trojan/W32.Inject.66560.KUP
Trojan/W32.Inject.66560.KUQ
Trojan/W32.Inject.66560.KUR
Trojan/W32.Inject.66560.KUS
Trojan/W32.Inject.66560.KUT
Trojan/W32.Inject.66560.KUU
Trojan/W32.Inject.66560.KUV
Trojan/W32.Inject.66560.KUW
Trojan/W32.Inject.66560.KUX
Trojan/W32.Inject.66560.KUY
Trojan/W32.Inject.66560.KUZ
Trojan/W32.Inject.66560.KVA
Trojan/W32.Inject.66560.KVB
Trojan/W32.Inject.66560.KVC
Trojan/W32.Inject.66560.KVD
Trojan/W32.Inject.66560.KVE
Trojan/W32.Inject.66560.KVF
Trojan/W32.Inject.66560.KVG
Trojan/W32.Inject.66560.KVH
Trojan/W32.Inject.66560.KVI
Trojan/W32.Inject.66560.KVJ
Trojan/W32.Inject.66560.KVK
Trojan/W32.Inject.66560.KVL
Trojan/W32.Inject.66560.KVM
Trojan/W32.Inject.66560.KVN
Trojan/W32.Inject.66560.KVO
Trojan/W32.Inject.66560.KVP
Trojan/W32.Inject.66560.KVQ
Trojan/W32.Inject.66560.KVR
Trojan/W32.Inject.66560.KVS
Trojan/W32.Inject.66560.KVT
Trojan/W32.Inject.66560.KVU
Trojan/W32.Inject.66560.KVV
Trojan/W32.Inject.66560.KVW
Trojan/W32.Inject.66560.KVX
Trojan/W32.Inject.66560.KVY
Trojan/W32.Inject.66560.KVZ
Trojan/W32.Inject.66560.KWA
Trojan/W32.Inject.66560.KWB
Trojan/W32.Inject.66560.KWC
Trojan/W32.Inject.66560.KWD
Trojan/W32.Inject.66560.KWE
Trojan/W32.Inject.66560.KWF
Trojan/W32.Inject.66560.KWG
Trojan/W32.Inject.66560.KWH
Trojan/W32.Inject.66560.KWI
Trojan/W32.Inject.66560.KWJ
Trojan/W32.Inject.66560.KWK
Trojan/W32.Inject.66560.KWL
Trojan/W32.Inject.66560.KWM
Trojan/W32.Inject.66560.KWN
Trojan/W32.Inject.66560.KWO
Trojan/W32.Inject.66560.KWP
Trojan/W32.Inject.66560.KWQ
Trojan/W32.Inject.66560.KWR
Trojan/W32.Inject.66560.KWS
Trojan/W32.Inject.66560.KWT
Trojan/W32.Inject.66560.KWU
Trojan/W32.Inject.66560.KWV
Trojan/W32.Inject.66560.KWW
Trojan/W32.Inject.66560.KWX
Trojan/W32.Inject.66560.KWY
Trojan/W32.Inject.66560.KWZ
Trojan/W32.Inject.66560.KXA
Trojan/W32.Inject.66560.KXB
Trojan/W32.Inject.66560.KXC
Trojan/W32.Inject.66560.KXD
Trojan/W32.Inject.66560.KXE
Trojan/W32.Inject.66560.KXF
Trojan/W32.Inject.66560.KXG
Trojan/W32.Inject.66560.KXH
Trojan/W32.Inject.66560.KXI
Trojan/W32.Inject.66560.KXJ
Trojan/W32.Inject.66560.KXK
Trojan/W32.Inject.66560.KXL
Trojan/W32.Inject.66560.KXM
Trojan/W32.Inject.66560.KXN
Trojan/W32.Inject.66560.KXO
Trojan/W32.Inject.66560.KXP
Trojan/W32.Inject.66560.KXQ
Trojan/W32.Inject.66560.KXR
Trojan/W32.Inject.66560.KXS
Trojan/W32.Inject.66560.KXT
Trojan/W32.Inject.66560.KXU
Trojan/W32.Inject.66560.KXV
Trojan/W32.Inject.66560.KXW
Trojan/W32.Inject.66560.KXX
Trojan/W32.Inject.66560.KXY
Trojan/W32.Inject.66560.KXZ
Trojan/W32.Inject.66560.KYA
Trojan/W32.Inject.66560.KYB
Trojan/W32.Inject.66560.KYC
Trojan/W32.Inject.66560.KYD
Trojan/W32.Inject.66560.KYE
Trojan/W32.Inject.66560.KYF
Trojan/W32.Inject.66560.KYG
Trojan/W32.Inject.66560.KYH
Trojan/W32.Inject.66560.KYI
Trojan/W32.Inject.66560.KYJ
Trojan/W32.Inject.66560.KYK
Trojan/W32.Inject.66560.KYL
Trojan/W32.Inject.66560.KYM
Trojan/W32.Inject.66560.KYN
Trojan/W32.Inject.66560.KYO
Trojan/W32.Inject.66560.KYP
Trojan/W32.Inject.66560.KYQ
Trojan/W32.Inject.66560.KYR
Trojan/W32.Inject.66560.KYS
Trojan/W32.Inject.66560.KYT
Trojan/W32.Inject.66560.KYU
Trojan/W32.Inject.66560.KYV
Trojan/W32.Inject.66560.KYW
Trojan/W32.Inject.66560.KYX
Trojan/W32.Inject.66560.KYY
Trojan/W32.Inject.66560.KYZ
Trojan/W32.Inject.66560.KZA
Trojan/W32.Inject.66560.KZB
Trojan/W32.Inject.66560.KZC
Trojan/W32.Inject.66560.KZD
Trojan/W32.Inject.66560.KZE
Trojan/W32.Inject.66560.KZF
Trojan/W32.Inject.66560.KZG
Trojan/W32.Inject.66560.KZH
Trojan/W32.Inject.66560.KZI
Trojan/W32.Inject.66560.KZJ
Trojan/W32.Inject.66560.KZK
Trojan/W32.Inject.66560.KZL
Trojan/W32.Inject.66560.KZM
Trojan/W32.Inject.66560.KZN
Trojan/W32.Inject.66560.KZO
Trojan/W32.Inject.66560.KZP
Trojan/W32.Inject.66560.KZQ
Trojan/W32.Inject.66560.KZR
Trojan/W32.Inject.66560.KZS
Trojan/W32.Inject.66560.KZT
Trojan/W32.Inject.66560.KZU
Trojan/W32.Inject.66560.KZV
Trojan/W32.Inject.66560.KZW
Trojan/W32.Inject.66560.KZX
Trojan/W32.Inject.66560.KZY
Trojan/W32.Inject.66560.KZZ
Trojan/W32.Inject.66560.LAA
Trojan/W32.Inject.66560.LAB
Trojan/W32.Inject.66560.LAC
Trojan/W32.Inject.66560.LAD
Trojan/W32.Inject.66560.LAE
Trojan/W32.Inject.66560.LAF
Trojan/W32.Inject.66560.LAG
Trojan/W32.Inject.66560.LAH
Trojan/W32.Inject.66560.LAI
Trojan/W32.Inject.66560.LAJ
Trojan/W32.Inject.66560.LAK
Trojan/W32.Inject.66560.LAL
Trojan/W32.Inject.66560.LAM
Trojan/W32.Inject.66560.LAN
Trojan/W32.Inject.66560.LAO
Trojan/W32.Inject.66560.LAP
Trojan/W32.Inject.66560.LAQ
Trojan/W32.Inject.66560.LAR
Trojan/W32.Inject.66560.LAS
Trojan/W32.Inject.66560.LAT
Trojan/W32.Inject.66560.LAU
Trojan/W32.Inject.66560.LAV
Trojan/W32.Inject.66560.LAW
Trojan/W32.Inject.66560.LAX
Trojan/W32.Inject.66560.LAY
Trojan/W32.Inject.66560.LAZ
Trojan/W32.Inject.66560.LBA
Trojan/W32.Inject.66560.LBB
Trojan/W32.Inject.66560.LBC
Trojan/W32.Inject.66560.LBD
Trojan/W32.Inject.66560.LBE
Trojan/W32.Inject.66560.LBF
Trojan/W32.Inject.66560.LBG
Trojan/W32.Inject.66560.LBH
Trojan/W32.Inject.66560.LBI
Trojan/W32.Inject.66560.LBJ
Trojan/W32.Inject.66560.LBK
Trojan/W32.Inject.66560.LBL
Trojan/W32.Inject.66560.LBM
Trojan/W32.Inject.66560.LBN
Trojan/W32.Inject.66560.LBO
Trojan/W32.Inject.66560.LBP
Trojan/W32.Inject.66560.LBQ
Trojan/W32.Inject.66560.LBR
Trojan/W32.Inject.66560.LBS
Trojan/W32.Inject.66560.LBT
Trojan/W32.Inject.66560.LBU
Trojan/W32.Inject.66560.LBV
Trojan/W32.Inject.66560.LBW
Trojan/W32.Inject.66560.LBX
Trojan/W32.Inject.66560.LBY
Trojan/W32.Inject.66560.LBZ
Trojan/W32.Inject.66560.LCA
Trojan/W32.Inject.66560.LCB
Trojan/W32.Inject.66560.LCC
Trojan/W32.Inject.66560.LCD
Trojan/W32.Inject.66560.LCE
Trojan/W32.Inject.66560.LCF
Trojan/W32.Inject.66560.LCG
Trojan/W32.Inject.66560.LCH
Trojan/W32.Inject.66560.LCI
Trojan/W32.Inject.66560.LCJ
Trojan/W32.Inject.66560.LCK
Trojan/W32.Inject.66560.LCL
Trojan/W32.Inject.66560.LCM
Trojan/W32.Inject.66560.LCN
Trojan/W32.Inject.66560.LCO
Trojan/W32.Inject.66560.LCP
Trojan/W32.Inject.66560.LCQ
Trojan/W32.Inject.66560.LCR
Trojan/W32.Inject.66560.LCS
Trojan/W32.Inject.66560.LCT
Trojan/W32.Inject.66560.LCU
Trojan/W32.Inject.66560.LCV
Trojan/W32.Inject.66560.LCW
Trojan/W32.Inject.66560.LCX
Trojan/W32.Inject.66560.LCY
Trojan/W32.Inject.66560.LCZ
Trojan/W32.Inject.66560.LDA
Trojan/W32.Inject.66560.LDB
Trojan/W32.Inject.66560.LDC
Trojan/W32.Inject.66560.LDD
Trojan/W32.Inject.66560.LDE
Trojan/W32.Inject.66560.LDF
Trojan/W32.Inject.66560.LDG
Trojan/W32.Inject.66560.LDH
Trojan/W32.Inject.66560.LDI
Trojan/W32.Inject.66560.LDJ
Trojan/W32.Inject.66560.LDK
Trojan/W32.Inject.66560.LDL
Trojan/W32.Inject.66560.LDM
Trojan/W32.Inject.66560.LDN
Trojan/W32.Inject.66560.LDO
Trojan/W32.Inject.66560.LDP
Trojan/W32.Inject.66560.LDQ
Trojan/W32.Inject.66560.LDR
Trojan/W32.Inject.66560.LDS
Trojan/W32.Inject.66560.LDT
Trojan/W32.Inject.66560.LDU
Trojan/W32.Inject.66560.LDV
Trojan/W32.Inject.66560.LDW
Trojan/W32.Inject.66560.LDX
Trojan/W32.Inject.66560.LDY
Trojan/W32.Inject.66560.LDZ
Trojan/W32.Inject.66560.LEA
Trojan/W32.Inject.66560.LEB
Trojan/W32.Inject.66560.LEC
Trojan/W32.Inject.66560.LED
Trojan/W32.Inject.66560.LEE
Trojan/W32.Inject.66560.LEF
Trojan/W32.Inject.66560.LEG
Trojan/W32.Inject.66560.LEH
Trojan/W32.Inject.66560.LEI
Trojan/W32.Inject.66560.LEJ
Trojan/W32.Inject.66560.LEK
Trojan/W32.Inject.66560.LEL
Trojan/W32.Inject.66560.LEM
Trojan/W32.Inject.66560.LEN
Trojan/W32.Inject.66560.LEO
Trojan/W32.Inject.66560.LEP
Trojan/W32.Inject.66560.LEQ
Trojan/W32.Inject.66560.LER
Trojan/W32.Inject.66560.LES
Trojan/W32.Inject.66560.LET
Trojan/W32.Inject.66560.LEU
Trojan/W32.Inject.66560.LEV
Trojan/W32.Inject.66560.LEW
Trojan/W32.Inject.66560.LEX
Trojan/W32.Inject.66560.LEY
Trojan/W32.Inject.66560.LEZ
Trojan/W32.Inject.66560.LFA
Trojan/W32.Inject.66560.LFB
Trojan/W32.Inject.66560.LFC
Trojan/W32.Inject.66560.LFD
Trojan/W32.Inject.66560.LFE
Trojan/W32.Inject.66560.LFF
Trojan/W32.Inject.66560.LFG
Trojan/W32.Inject.66560.LFH
Trojan/W32.Inject.739328.B
Trojan/W32.Inject.745472.G
Trojan/W32.Inject.83968.AP
Trojan/W32.Inject.97774
Trojan/W32.Kolovorot.1288752
Trojan/W32.Kolovorot.1309064
Trojan/W32.Kolovorot.876544
Trojan/W32.Kovter.386877
Trojan/W32.Lebag.131072.I
Trojan/W32.Mepaow.2326528
Trojan/W32.MicroFake.23977
Trojan/W32.MicroFake.30781
Trojan/W32.Miner.475682
Trojan/W32.Miner.58532
Trojan/W32.Nymaim.639488
Trojan/W32.Nymaim.770048
Trojan/W32.Plugax.2560
Trojan/W32.Poweliks.191659
Trojan/W32.Poweliks.386946
Trojan/W32.Poweliks.386991
Trojan/W32.Poweliks.391372
Trojan/W32.Poweliks.391457
Trojan/W32.Poweliks.391501
Trojan/W32.Poweliks.391579
Trojan/W32.Poweliks.391600
Trojan/W32.Reconyc.1155072
Trojan/W32.Reconyc.126976.G
Trojan/W32.Reconyc.1269760
Trojan/W32.Reconyc.1370488
Trojan/W32.Reconyc.3247168
Trojan/W32.Reconyc.391168.C
Trojan/W32.Reconyc.540848
Trojan/W32.Reconyc.753725
Trojan/W32.Reconyc.755455
Trojan/W32.Reconyc.756130
Trojan/W32.Scarsi.313856
Trojan/W32.Scarsi.317440
Trojan/W32.Scarsi.317952
Trojan/W32.Scarsi.731648.B
Trojan/W32.Scarsi.733696.C
Trojan/W32.Scarsi.734208
Trojan/W32.Scarsi.735232
Trojan/W32.Scarsi.735744
Trojan/W32.Scarsi.735744.B
Trojan/W32.Scarsi.735744.C
Trojan/W32.Scarsi.736256.B
Trojan/W32.Scarsi.736256.C
Trojan/W32.Scarsi.736256.D
Trojan/W32.Scarsi.736768.B
Trojan/W32.Scarsi.737280
Trojan/W32.Scarsi.737280.B
Trojan/W32.Scarsi.738304.B
Trojan/W32.Scarsi.738304.C
Trojan/W32.Scarsi.738816.B
Trojan/W32.SchoolBoy.95086
Trojan/W32.SchoolGirl.1365399
Trojan/W32.SchoolGirl.1366299
Trojan/W32.Sennoma.199680
Trojan/W32.Shelma.1396224
Trojan/W32.ShipUp.284856
Trojan/W32.ShipUp.284864.B
Trojan/W32.Snojan.131072
Trojan/W32.Snojan.2419200
Trojan/W32.Snojan.3966976
Trojan/W32.Snojan.4496525
Trojan/W32.Snojan.4767487
Trojan/W32.Stava.7609856
Trojan/W32.Swisyn.7390208
Trojan/W32.TrickBot.412160
Trojan/W32.VBKryjetor.102400.D
Trojan/W32.VBKryjetor.1036288.D
Trojan/W32.VBKryjetor.249856.E
Trojan/W32.VBKryjetor.282624
Trojan/W32.VBKryjetor.282624.B
Trojan/W32.VBKryjetor.729088
Trojan/W32.VBKrypt.196608.BU
Trojan/W32.VBKrypt.425984.AN
Trojan/W32.Vilsel.491520.D
Trojan/W32.Waldek.5819520
Trojan/W32.Waldek.6779328
Trojan/W32.Waldek.8428896.B
Trojan/W64.Agent.1618609
Trojan/W64.Dridex.529920
Trojan/W64.Shelma.21504.C
Trojan/W64.Shelma.7168.DZ
Trojan/W64.Wdfload.3272192
Worm/W32.Agent.159764
Worm/W32.AutoRun.45028
Worm/W32.AutoRun.47104.G
Worm/W32.AutoRun.524681
Worm/W32.AutoRun.524693
Worm/W32.AutoRun.524740
Worm/W32.AutoRun.524742
Worm/W32.AutoRun.524867
Worm/W32.AutoRun.524881
Worm/W32.AutoRun.524985
Worm/W32.AutoRun.525026
Worm/W32.AutoRun.525040
Worm/W32.AutoRun.525056
Worm/W32.AutoRun.525069
Worm/W32.AutoRun.525070
Worm/W32.AutoRun.525071
Worm/W32.AutoRun.525085
Worm/W32.AutoRun.525188
Worm/W32.AutoRun.525213
Worm/W32.AutoRun.525454
Worm/W32.AutoRun.525515
Worm/W32.AutoRun.525530
Worm/W32.AutoRun.525589
Worm/W32.AutoRun.525599
Worm/W32.AutoRun.526755
Worm/W32.AutoRun.526770
Worm/W32.AutoRun.526853
Worm/W32.AutoRun.526952
Worm/W32.AutoRun.527032
Worm/W32.Bobic.40767
Worm/W32.Bobic.41681.B
Worm/W32.Kido.153584
Worm/W32.Kido.64240
Worm/W32.Mytob.117760
Worm/W32.Mytob.122880.F
Worm/W32.Mytob.123904
Worm/W32.Mytob.63488
Worm/W32.Socks.3478661
Worm/W32.VBNA.12104407
Worm/W32.VBNA.214766
Worm/W32.WBNA.57344.AC



--------------------------------------------------------------------------------------

       Copyright ⓒ, (주) 잉카인터넷, 2000-2017, All rights reserved.

--------------------------------------------------------------------------------------



저작자 표시 비영리 변경 금지
신고
크리에이티브 커먼즈 라이선스
Creative Commons License
Posted by Erteam

Neutrino bot 분석 




1. 개요 


봇넷(Botnet)은 네트워크에 연결되어 있으면서 제 3자에게 제어 권한을 빼앗긴 컴퓨터들의 집합을 말한다. 이러한 봇넷을 구성하는 봇(Bot)들은 공격자의 목적을 달성하기 위해 다양한 기능을 가지고 있으며, 주로 확장을 위한 추가 악성코드 다운로드와 DDoS(Distributed Denial of Service) 공격을 이루기 위한 flooding 공격 등 다양한 기능을 갖춘다. 해당 악성코드에서 다루게 될 Neutrino bot은 앞서 설명한 봇의 일종이며, 같은 이름을 가진 익스플로잇 킷(Exploit-kit) Neutrino EK를 활용하여 유포된다. 





2. 분석 정보


2-1. 파일 정보

구분

내용

파일명

neutrino.exe

파일크기

274,432 byte

진단명

Trojan/W32.Agent.274432.AIO

악성동작

C&C

네트워크

82.211.30.40:80

 



2-2. 유포 경로

해당 악성코드는 뉴트리노 익스플로잇 킷을 활용 한 인터넷 익스플로러(Internet Explorer)및 플래시 플레이어(Flash Player) 취약점을 통하여 유포된 것으로 알려진다.




2-3. 실행 과정

최초 감염시 아래 그림과 같이 C&C 서버에 아래와 같이 Base64로 인코딩 된 문자열 “enter”와 “success”를 HTTP 프로토콜로 주고받는다.


[그림 1] 감염 시 패킷[그림 1] 감염 시 패킷




그 후 곧바로 감염 PC의 정보를 보내고 screenshot 명령을 받아 감염된 시스템의 스크린샷을 전송한다.


[그림 2] screenshot 명령[그림 2] screenshot 명령


[그림 3] 스크린샷 전송[그림 3] 스크린샷 전송






3. 악성 동작

아래와 같이 C&C 서버에서 받은 내용을 cmd.exe를 통해 수행하는 명령 쉘(Command Shell)을 포함하고있다. 


[그림 4] 명령 쉘[그림 4] 명령 쉘




이 외 다른 봇넷을 제거하기 위한 용도로 보이는 기능과 추가 악성코드 설치와 사용자의 파일을 전송하는 등 다양한 기능을 포함한다.


[그림 5] 기타 기능[그림 5] 기타 기능





4. 결론

이러한 유형의 악성코드는 공격자의 목적을 이루기 위해 감염된 시스템의 자원을 공격자 마음대로 사용할 수 있기 때문에 사용자가 의도치 않게 네트워크 및 시스템의 부하를 일으킬 수 있다. 그러므로 수시로 OS와 응용 프로그램들을 최신 버전으로 업데이트하고 출처가 불분명한 파일을 받지 않는 등 미리 감염을 예방할 필요가 있다.


상기 악성코드는 잉카인터넷 안티바이러스 제품 nProtect Anti-Virus Spyware V3.0과 nProtect Anti-Virus/Spyware V4.0에서 진단 및 치료가 가능하다.


[그림 6] nProtect Anti-Virus/Spyware V4.0 진단 및 치료 화면[그림 6] nProtect Anti-Virus/Spyware V4.0 진단 및 치료 화면



[그림 7] nProtect Anti-Virus/Spyware V3.0 진단 및 치료 화면[그림 7] nProtect Anti-Virus/Spyware V3.0 진단 및 치료 화면





저작자 표시 비영리 변경 금지
신고
크리에이티브 커먼즈 라이선스
Creative Commons License
Posted by nProtect