안녕하십니까? 잉카인터넷 TACHYON 입니다.


2018년 05월 17일자 두 번째 업데이트 안내문입니다.


금일 정기 업데이트에서는 총 19개 악성코드에 대한 진단/치료가 안티 바이러스에 업데이트 되었습니다.



1. 안티 바이러스 업데이트 안내


1-1. 안티 바이러스 업데이트 버전 : 2018-05-17.02


1-2. 다음 19개 악성코드에 대한 진단/치료가 자사 엔진에 업데이트 되었습니다.


Ransom/W32.Crytor.230400
Ransom/W32.GandCrab.224768.B
Ransom/W32.GandCrab.237065
Ransom/W32.GandCrab.247305
Ransom/W32.GandCrab.265216
Ransom/W32.GandCrab.307721
Ransom/W32.GandCrab.3152384
Ransom/W32.GandCrab.3152896
Ransom/W32.GandCrab.3153408
Ransom/W32.Magniber.658432
Trojan/W32.Agent.136982
Trojan/W32.Agent.196608.BYL
Trojan/W32.Agent.240640.KH
Trojan/W32.Agent.310272.JL
Trojan/W32.CoinMiner.898560
Trojan/W32.Dropper.334336
Trojan/W32.Infostealer.192512
Trojan/W32.Infostealer.198656
Trojan/W32.Infostealer.252928



--------------------------------------------------------------------------------------

       Copyright ⓒ, (주) 잉카인터넷, 2000-2018, All rights reserved.

--------------------------------------------------------------------------------------

Posted by Erteam

새롭게 발견된 ‘Spartacus’ 랜섬웨어 감염 주의


1. 개요 


최근, ‘Spartacus’ 라는 이름의 새로운 랜섬웨어가 발견되었다. 해외 한 보안사이트에 의하면 "Spartacus 랜섬웨어의 코드가 Satyr, Blackheart 랜섬웨어와 거의 동일하다” 고 언급하고 있다. ‘Spartacus’ 랜섬웨어는 실행 시 확장자 ‘.Spartacus’를 제외한 모든 확장자를 대상으로 암호화를 시도하며, 별도의 통신은 하지 않고 복호화를 빌미로 가상화폐를 요구한다.


이번 보고서에서는 새롭게 발견된 ‘Spartacus’ 랜섬웨어에 대해서 알아보고자 한다.





2. 분석 정보


2-1. 파일 정보

구분

내용

파일명

SF.exe

파일크기

96,768 byte

진단명

Ransom/W32.Spartacus.96768

악성동작

파일 암호화




2-2. 동작 방식

‘Spartacus’ 랜섬웨어는 최초 ‘CheckRunProgram’ 함수를 사용하여 자기 자신의 중복 실행을 확인한 후 단일 실행이      확인되면 지정된 경로와 논리 드라이브를 대상으로 암호화를 진행한다. 또한, 시스템 복원 기능을 무력화시키기 위해 볼륨   쉐도우 복사본을 삭제한다. 아래 그림은 ‘Mutex’ 함수를 통해 중복 실행을 방지하는 ‘Spartacus’ 랜섬웨어 코드의 일부이다.


[그림 1] ‘Mutex’ 함수를 통한 중복 실행 방지 코드[그림 1] ‘Mutex’ 함수를 통한 중복 실행 방지 코드





3. 악성 동작


3-1. 파일 암호화

중복 실행에 대한 확인이 끝나면 아래 그림과 같이 ‘KeyGenerator.GetUniqueKey’ 함수를 통해 암호화에 사용할 AES 키를 생성한다. 또한, 암호화할 대상 경로를 변수에 저장하고 해당 경로의 파일을 암호화한다.


[그림 2] AES 키 생성 및 암호화 대상 경로 저장[그림 2] AES 키 생성 및 암호화 대상 경로 저장




그뿐만 아니라 아래와 같이 ‘Directory.GetLogicalDrives’ 함수를 사용하여 논리 드라이브를 검색하고 해당 드라이브 내의 파일 암호화를 시도한다. 단, 파일 암호화에 앞서 확장자 ‘.Spartacus’인 파일에 대해서는 암호화를 진행하지 않는다. 암호화가 완료된 파일은 원본 파일명 뒤에 ‘.[MastersRecovery@protonmail.com].Spartacus’를 붙여 파일명을 변경한다.



[그림 3] 논리 드라이브를 대상으로 한 암호화 루틴[그림 3] 논리 드라이브를 대상으로 한 암호화 루틴



[그림 4] 예외 확장자 ‘.Spartacus’를 확인하는 코드[그림 4] 예외 확장자 ‘.Spartacus’를 확인하는 코드



[그림 5] Spartacus 랜섬웨어에 의해 암호화된 파일[그림 5] Spartacus 랜섬웨어에 의해 암호화된 파일




3-2. 시스템 복원 기능 무력화

또한, 시스템 복원 기능을 무력화하기 위해 윈도우 명령 처리기를 사용하여 볼륨 쉐도우 복사본을 삭제한다.


[그림 6] 볼륨 쉐도우 복사본 삭제[그림 6] 볼륨 쉐도우 복사본 삭제




3-3. 금전 요구


랜섬노트에는 파일이 암호화되었음을 안내하면서 복구하기 위해서는 생성된 ‘personal ID KEY’를 특정 이메일로 전송하고 가상화폐를 지급해야 한다는 내용이 담겨있다.


[그림 7] Spartacus 랜섬노트[그림 7] Spartacus 랜섬노트





4. 결론

새롭게 발견된 ‘Spartacus’ 랜섬웨어는 파일 암호화 및 시스템 복원 기능을 무력화시키는 비교적 단순한 형태의 랜섬웨어이다. 하지만 확장자 ‘.Spartacus’를 제외한 모든 확장자를 대상으로 파일을 암호화하고 있어 감염 시 피해가      클 것으로 예상된다. 랜섬웨어의 피해를 최소화하기 위해서 백신 제품을 설치하고 윈도우 및 웹 브라우저를 항상 최신 버전으로 업데이트해야 한다. 또한, 안전한 백업 시스템을 구축하여 중요한 자료는 별도로 보관해야 한다. 

상기 악성코드는 잉카인터넷 안티바이러스 제품 TACHYON Internet Security 5.0 에서 진단 및 치료를 할 수 있다.

[그림 8] TACHYON Internet Security 5.0 진단 및 치료 화면[그림 8] TACHYON Internet Security 5.0 진단 및 치료 화면




[그림8] TACHYON Internet Security 5.0 진단 및 치료 화면[그림8] TACHYON Internet Security 5.0 진단 및 치료 화면







Posted by nProtect & TACHYON

안녕하십니까? 잉카인터넷 TACHYON 입니다.


2018년 05월 17일자 첫 번째 업데이트 안내문입니다.


금일 정기 업데이트에서는 총 949개 악성코드에 대한 진단/치료가 안티 바이러스에 업데이트 되었습니다.



1. 안티 바이러스 업데이트 안내


1-1. 안티 바이러스 업데이트 버전 : 2018-05-17.01


1-2. 다음 949개 악성코드에 대한 진단/치료가 자사 엔진에 업데이트 되었습니다.


Abuse-Worry/W32.Ardamax.2554252

Backdoor/W32.Agent.1060864.J

Backdoor/W32.Agent.1102261

Backdoor/W32.Agent.1109504.C

Backdoor/W32.Agent.12201984

Backdoor/W32.Agent.12201984.B

Backdoor/W32.Agent.12852736

Backdoor/W32.Agent.1531904.N

Backdoor/W32.Agent.16484

Backdoor/W32.Agent.1820672

Backdoor/W32.Agent.188416.EW

Backdoor/W32.Agent.1921024.F

Backdoor/W32.Agent.20992.CI

Backdoor/W32.Agent.210944.AC

Backdoor/W32.Agent.2146304.D

Backdoor/W32.Agent.270336.CL

Backdoor/W32.Agent.2782720

Backdoor/W32.Agent.320380

Backdoor/W32.Agent.377726

Backdoor/W32.Agent.381287

Backdoor/W32.Agent.4612096

Backdoor/W32.Agent.507904.AX

Backdoor/W32.Agent.516096.AW

Backdoor/W32.Agent.5223424

Backdoor/W32.Agent.565633

Backdoor/W32.Agent.581632.AL

Backdoor/W32.Agent.585728.AY

Backdoor/W32.Agent.586169

Backdoor/W32.Agent.593920.AN

Backdoor/W32.Agent.602112.BE

Backdoor/W32.Agent.6074368

Backdoor/W32.Agent.6256128

Backdoor/W32.Agent.656384.H

Backdoor/W32.Agent.705543

Backdoor/W32.Agent.90112.IU

Backdoor/W32.Agent.937472.H

Backdoor/W32.Agent.963584.D

Backdoor/W32.Androm.1277440

Backdoor/W32.Androm.233206

Backdoor/W32.Androm.4746240

Backdoor/W32.Androm.594432.C

Backdoor/W32.Bedep.307200.D

Backdoor/W32.Bifrose.163441

Backdoor/W32.Enfal.634880

Backdoor/W32.Farfli.3420160

Backdoor/W32.Farfli.569355

Backdoor/W32.Gulpix.20480

Backdoor/W32.Hlux.830992.DC

Backdoor/W32.Inject.396682

Backdoor/W32.NanoBot.762368

Backdoor/W32.Phnu.25925131

Backdoor/W32.Phpw.2250240

Backdoor/W32.Poison.10578432

Backdoor/W32.Poison.1323008

Backdoor/W32.Poison.1671168.D

Backdoor/W32.Poison.528394

Backdoor/W32.Poison.5289984

Backdoor/W32.Poison.558080.B

Backdoor/W32.RBot.5660160

Backdoor/W32.RBot.6792704

Backdoor/W32.RBot.881152.B

Backdoor/W32.Saker.13524992

Backdoor/W32.Sensode.147456

Backdoor/W32.Sinowal.246040

Backdoor/W32.Socks.417651

Backdoor/W32.Wabot.102207

Backdoor/W32.Wabot.105888

Backdoor/W32.Wabot.1068177

Backdoor/W32.Wabot.1163900

Backdoor/W32.Wabot.118052

Backdoor/W32.Wabot.1198936

Backdoor/W32.Wabot.1428852

Backdoor/W32.Wabot.1698214

Backdoor/W32.Wabot.170199

Backdoor/W32.Wabot.1703052

Backdoor/W32.Wabot.1705408

Backdoor/W32.Wabot.1709378

Backdoor/W32.Wabot.1735051

Backdoor/W32.Wabot.207240

Backdoor/W32.Wabot.232489

Backdoor/W32.Wabot.236118

Backdoor/W32.Wabot.238075

Backdoor/W32.Wabot.2394146

Backdoor/W32.Wabot.242095

Backdoor/W32.Wabot.2468413

Backdoor/W32.Wabot.2729796

Backdoor/W32.Wabot.301631

Backdoor/W32.Wabot.303172

Backdoor/W32.Wabot.304656

Backdoor/W32.Wabot.307629

Backdoor/W32.Wabot.345623

Backdoor/W32.Wabot.348706

Backdoor/W32.Wabot.3489792

Backdoor/W32.Wabot.3559755

Backdoor/W32.Wabot.3561281

Backdoor/W32.Wabot.3562961

Backdoor/W32.Wabot.3597979

Backdoor/W32.Wabot.3601521

Backdoor/W32.Wabot.3605609

Backdoor/W32.Wabot.417937

Backdoor/W32.Wabot.508472

Backdoor/W32.Wabot.533925

Backdoor/W32.Wabot.539113

Backdoor/W32.Wabot.553862

Backdoor/W32.Wabot.64640

Backdoor/W32.Wabot.671744

Backdoor/W32.Wabot.786432.C

Backdoor/W32.Wabot.837844.C

Backdoor/W32.Wabot.98035

Backdoor/W32.Zegost.149804

Backdoor/W32.Zegost.1552279

Banker/W32.Agent.10182656.B

Banker/W32.Agent.9841152

Banker/W32.Alreay.192512

Banker/W32.Alreay.192512.B

Banker/W32.BestaFera.1574912

Banker/W32.BestaFera.802364

Banker/W32.Emotet.116736.CD

Banker/W32.Emotet.116736.CE

Banker/W32.Emotet.11796992.B

Banker/W32.Emotet.12098048.B

Banker/W32.Emotet.12355584

Banker/W32.Emotet.13151744

Banker/W32.Emotet.13441536

Banker/W32.Emotet.135168.H

Banker/W32.Emotet.142336.B

Banker/W32.Emotet.747520.B

Banker/W32.Emotet.747520.C

Banker/W32.Emotet.748032.B

Banker/W32.IcedID.1241600

Banker/W32.Pharm.322876

Downloader/W32.Agent.18221

Ransom/W32.Agent.1582957

Ransom/W32.Agent.1582983

Ransom/W32.Agent.212992.G

Ransom/W32.Agent.4303872

Ransom/W32.Blocker.1069056

Ransom/W32.Blocker.13085161

Ransom/W32.Blocker.1359872.F

Ransom/W32.Blocker.174546

Ransom/W32.Blocker.2236416.F

Ransom/W32.Blocker.3061372

Ransom/W32.Blocker.3325952.G

Ransom/W32.Blocker.62568

Ransom/W32.Blocker.7647232.D

Ransom/W32.Blocker.8257536.E

Ransom/W32.Blocker.9216000.C

Ransom/W32.Blocker.9371648.B

Ransom/W32.Crypto.22518.B

Ransom/W32.Crypto.22742.B

Ransom/W32.Crypto.22982

Ransom/W32.Crypto.23254.B

Ransom/W32.Crypto.23662.B

Ransom/W32.Foreign.308177

Ransom/W32.Foreign.596992

Ransom/W32.Foreign.774144.B

Ransom/W32.GandCrab.152064

Ransom/W32.GandCrab.167936

Ransom/W32.GandCrab.189440

Ransom/W32.GandCrab.211464

Ransom/W32.GandCrab.224768

Ransom/W32.GandCrab.241669

Ransom/W32.GandCrab.241673

Ransom/W32.GandCrab.246281

Ransom/W32.GandCrab.246793

Ransom/W32.GandCrab.253440

Ransom/W32.GandCrab.285696

Ransom/W32.GandCrab.327689.B

Ransom/W32.GandCrypt.248329

Ransom/W32.GandCrypt.248329.B

Ransom/W32.GandCrypt.248841

Ransom/W32.GandCrypt.330249

Ransom/W32.Petr.507392

Ransom/W32.RansomAES.19456

Ransom/W32.WannaCry.32768

Trojan-Downloader/W32.Adload.394752.I

Trojan-Downloader/W32.Adload.394752.J

Trojan-Downloader/W32.Adload.394752.K

Trojan-Downloader/W32.Agent.22110.B

Trojan-Downloader/W32.Agent.24576.FGN

Trojan-Downloader/W32.Agent.253312

Trojan-Downloader/W32.Agent.253576

Trojan-Downloader/W32.Agent.27958.B

Trojan-Downloader/W32.Agent.2949120.B

Trojan-Downloader/W32.Agent.38594

Trojan-Downloader/W32.Agent.422882

Trojan-Downloader/W32.Agent.423426

Trojan-Downloader/W32.Agent.5315365

Trojan-Downloader/W32.Agent.53248.AIA

Trojan-Downloader/W32.Agent.935784

Trojan-Downloader/W32.Agent.936312

Trojan-Downloader/W32.Agent.939704

Trojan-Downloader/W32.Banload.2720256

Trojan-Downloader/W32.Banload.322208

Trojan-Downloader/W32.Banload.3252224.C

Trojan-Downloader/W32.Banload.3252224.D

Trojan-Downloader/W32.Banload.334105

Trojan-Downloader/W32.Banload.561152.C

Trojan-Downloader/W32.Banload.648929

Trojan-Downloader/W32.Banload.657468

Trojan-Downloader/W32.Banload.666352

Trojan-Downloader/W32.Upatre.112160.R

Trojan-Downloader/W32.Upatre.112378.F

Trojan-Downloader/W32.Upatre.113160.E

Trojan-Downloader/W32.Upatre.166912

Trojan-Downloader/W32.Upatre.2361344

Trojan-Downloader/W32.Upatre.23930.B

Trojan-Downloader/W32.Upatre.249672

Trojan-Downloader/W32.Upatre.25854

Trojan-Downloader/W32.Upatre.25910.B

Trojan-Downloader/W32.Upatre.26118.C

Trojan-Downloader/W32.Upatre.26198

Trojan-Downloader/W32.Upatre.26254

Trojan-Downloader/W32.Upatre.26630.D

Trojan-Downloader/W32.Upatre.26720.B

Trojan-Downloader/W32.Upatre.28128

Trojan-Downloader/W32.Upatre.31910

Trojan-Downloader/W32.Upatre.32416

Trojan-Downloader/W32.Upatre.32554

Trojan-Downloader/W32.Upatre.363604

Trojan-Downloader/W32.Upatre.373244

Trojan-Downloader/W32.Upatre.38264.C

Trojan-Downloader/W32.Upatre.38400.AC

Trojan-Downloader/W32.Upatre.38736.C

Trojan-Downloader/W32.Upatre.38872.E

Trojan-Downloader/W32.Upatre.39048.F

Trojan-Downloader/W32.Upatre.39880.D

Trojan-Downloader/W32.Upatre.39978.B

Trojan-Downloader/W32.Upatre.40016.C

Trojan-Downloader/W32.Upatre.40114.D

Trojan-Downloader/W32.Upatre.40386.B

Trojan-Downloader/W32.Upatre.40442.B

Trojan-Downloader/W32.Upatre.40522.C

Trojan-Downloader/W32.Upatre.40658.B

Trojan-Downloader/W32.Upatre.41772.B

Trojan-Downloader/W32.Upatre.42392.B

Trojan-Downloader/W32.Upatre.47536.G

Trojan-Downloader/W32.Upatre.49136.B

Trojan-Downloader/W32.Upatre.51302

Trojan-Downloader/W32.Upatre.51438

Trojan-Downloader/W32.Upatre.68346.D

Trojan-Downloader/W32.Upatre.70240.D

Trojan-Downloader/W32.Upatre.71094

Trojan-Downloader/W32.Upatre.72804

Trojan-Downloader/W32.Upatre.77492

Trojan-Downloader/W32.Upatre.86536

Trojan-Dropper/W32.Agent.1117184.BLI

Trojan-Dropper/W32.Agent.1117184.BLJ

Trojan-Dropper/W32.Agent.1117184.BLK

Trojan-Dropper/W32.Agent.1117184.BLL

Trojan-Dropper/W32.Agent.1117184.BLM

Trojan-Dropper/W32.Agent.1117184.BLN

Trojan-Dropper/W32.Agent.1117184.BLO

Trojan-Dropper/W32.Agent.1117184.BLP

Trojan-Dropper/W32.Agent.1117184.BLQ

Trojan-Dropper/W32.Agent.1117184.BLR

Trojan-Dropper/W32.Agent.1117184.BLS

Trojan-Dropper/W32.Agent.1117184.BLT

Trojan-Dropper/W32.Agent.1117184.BLU

Trojan-Dropper/W32.Agent.1117184.BLV

Trojan-Dropper/W32.Agent.1117184.BLW

Trojan-Dropper/W32.Agent.1117184.BLX

Trojan-Dropper/W32.Agent.1117184.BLY

Trojan-Dropper/W32.Agent.1117184.BLZ

Trojan-Dropper/W32.Agent.1117184.BMA

Trojan-Dropper/W32.Agent.1117184.BMB

Trojan-Dropper/W32.Agent.1117184.BMC

Trojan-Dropper/W32.Agent.1117184.BMD

Trojan-Dropper/W32.Agent.1117184.BME

Trojan-Dropper/W32.Agent.1117184.BMF

Trojan-Dropper/W32.Agent.1117184.BMG

Trojan-Dropper/W32.Agent.1117184.BMH

Trojan-Dropper/W32.Agent.1117184.BMI

Trojan-Dropper/W32.Agent.1117184.BMJ

Trojan-Dropper/W32.Agent.1117184.BMK

Trojan-Dropper/W32.Agent.1117184.BML

Trojan-Dropper/W32.Agent.1117184.BMM

Trojan-Dropper/W32.Agent.1117184.BMN

Trojan-Dropper/W32.Agent.1117184.BMO

Trojan-Dropper/W32.Agent.1117184.BMP

Trojan-Dropper/W32.Agent.1117184.BMQ

Trojan-Dropper/W32.Agent.1117184.BMR

Trojan-Dropper/W32.Agent.1117184.BMS

Trojan-Dropper/W32.Agent.1117184.BMT

Trojan-Dropper/W32.Agent.15313513

Trojan-Dropper/W32.Agent.16896.QM

Trojan-Dropper/W32.Agent.16896.QN

Trojan-Dropper/W32.Agent.1735680.C

Trojan-Dropper/W32.Agent.1805751

Trojan-Dropper/W32.Agent.18878976

Trojan-Dropper/W32.Agent.193144

Trojan-Dropper/W32.Agent.194967

Trojan-Dropper/W32.Agent.278549

Trojan-Dropper/W32.Agent.3031040.H

Trojan-Dropper/W32.Agent.3470848

Trojan-Dropper/W32.Agent.4329171

Trojan-Dropper/W32.Agent.499712.AP

Trojan-Dropper/W32.Agent.675840.BR

Trojan-Dropper/W32.Agent.855942

Trojan-Dropper/W32.Dapato.1154147

Trojan-Dropper/W32.Dapato.18136064

Trojan-Dropper/W32.Dapato.23456

Trojan-Dropper/W32.Dapato.304229

Trojan-Dropper/W32.Dapato.362757

Trojan-Dropper/W32.Dapato.381637

Trojan-Dropper/W32.Dapato.395057

Trojan-Dropper/W32.Dapato.443482

Trojan-Dropper/W32.Dapato.495498

Trojan-Dropper/W32.Dapato.500530

Trojan-Dropper/W32.Dapato.508640

Trojan-Dropper/W32.Dapato.530134

Trojan-Dropper/W32.Dapato.545894

Trojan-Dropper/W32.Dapato.558181

Trojan-Dropper/W32.Dapato.563147

Trojan-Dropper/W32.Dapato.564774

Trojan-Dropper/W32.Dapato.571419

Trojan-Dropper/W32.Dapato.578291

Trojan-Dropper/W32.Dapato.579381

Trojan-Dropper/W32.Dapato.581651

Trojan-Dropper/W32.Dapato.591260

Trojan-Dropper/W32.Dapato.592927

Trojan-Dropper/W32.Dapato.594907

Trojan-Dropper/W32.Dapato.597787

Trojan-Dropper/W32.Dapato.598012

Trojan-Dropper/W32.Dapato.604451

Trojan-Dropper/W32.Dapato.609340

Trojan-Dropper/W32.Dapato.615673

Trojan-Dropper/W32.Dapato.616725

Trojan-Dropper/W32.Dapato.620378

Trojan-Dropper/W32.Dapato.621616

Trojan-Dropper/W32.Dapato.622565

Trojan-Dropper/W32.Dapato.627460

Trojan-Dropper/W32.Dapato.628874

Trojan-Dropper/W32.Dapato.635400

Trojan-Dropper/W32.Dapato.639700

Trojan-Dropper/W32.Dapato.643525

Trojan-Dropper/W32.Dapato.650499

Trojan-Dropper/W32.Dapato.651941

Trojan-Dropper/W32.Dapato.655204

Trojan-Dropper/W32.Dapato.657138

Trojan-Dropper/W32.Dapato.658461

Trojan-Dropper/W32.Dapato.659359

Trojan-Dropper/W32.Dapato.661361

Trojan-Dropper/W32.Dapato.670866

Trojan-Dropper/W32.Dapato.671888

Trojan-Dropper/W32.Dapato.672111

Trojan-Dropper/W32.Dapato.674924

Trojan-Dropper/W32.Dapato.675289

Trojan-Dropper/W32.Dapato.680662

Trojan-Dropper/W32.Dapato.680722

Trojan-Dropper/W32.Dapato.681143

Trojan-Dropper/W32.Dapato.681306

Trojan-Dropper/W32.Dapato.683750

Trojan-Dropper/W32.Dapato.684429

Trojan-Dropper/W32.Dapato.685033

Trojan-Dropper/W32.Dapato.686860

Trojan-Dropper/W32.Dapato.687738

Trojan-Dropper/W32.Dapato.690439

Trojan-Dropper/W32.Dapato.691795

Trojan-Dropper/W32.Dapato.692230

Trojan-Dropper/W32.Dapato.695059

Trojan-Dropper/W32.Dapato.695632

Trojan-Dropper/W32.Dapato.697321

Trojan-Dropper/W32.Dapato.697471

Trojan-Dropper/W32.Dapato.698909

Trojan-Dropper/W32.Dapato.699798

Trojan-Dropper/W32.Dapato.701272

Trojan-Dropper/W32.Dapato.703688

Trojan-Dropper/W32.Dapato.704930

Trojan-Dropper/W32.Dapato.705075

Trojan-Dropper/W32.Dapato.708252

Trojan-Dropper/W32.Dapato.710026

Trojan-Dropper/W32.Dapato.711295

Trojan-Dropper/W32.Dapato.712889

Trojan-Dropper/W32.Dapato.713701

Trojan-Dropper/W32.Dapato.714885

Trojan-Dropper/W32.Dapato.715288

Trojan-Dropper/W32.Dapato.715787

Trojan-Dropper/W32.Dapato.717659

Trojan-Dropper/W32.Dapato.720908

Trojan-Dropper/W32.Dapato.726392

Trojan-Dropper/W32.Dapato.730219

Trojan-Dropper/W32.Dapato.733261

Trojan-Dropper/W32.Dapato.735894

Trojan-Dropper/W32.Dapato.738167

Trojan-Dropper/W32.Dapato.739744

Trojan-Dropper/W32.Dapato.742506

Trojan-Dropper/W32.Dapato.742851

Trojan-Dropper/W32.Dapato.743232

Trojan-Dropper/W32.Dapato.744981

Trojan-Dropper/W32.Dapato.745029

Trojan-Dropper/W32.Dapato.751777

Trojan-Dropper/W32.Dapato.755040

Trojan-Dropper/W32.Dapato.758102

Trojan-Dropper/W32.Dapato.763719

Trojan-Dropper/W32.Dapato.765121

Trojan-Dropper/W32.Dapato.765935

Trojan-Dropper/W32.Dapato.768826

Trojan-Dropper/W32.Dapato.770530

Trojan-Dropper/W32.Dapato.772611

Trojan-Dropper/W32.Dapato.776600

Trojan-Dropper/W32.Dapato.778247

Trojan-Dropper/W32.Dapato.782861

Trojan-Dropper/W32.Dapato.791958

Trojan-Dropper/W32.Dapato.809863

Trojan-Dropper/W32.Dapato.821525

Trojan-Dropper/W32.Dapato.828923

Trojan-Dropper/W32.Dapato.830291

Trojan-Dropper/W32.Dapato.831553

Trojan-Dropper/W32.Dapato.843180

Trojan-Dropper/W32.Dapato.848322

Trojan-Dropper/W32.Dapato.932461

Trojan-Dropper/W32.Daws.2813952.D

Trojan-Dropper/W32.Daws.795264

Trojan-Dropper/W32.Daws.847163

Trojan-Dropper/W32.Daws.968416

Trojan-Dropper/W32.Dinwod.692231

Trojan-Dropper/W32.Inject.134325

Trojan-Dropper/W32.Inject.20624488

Trojan-Dropper/W32.Inject.463171

Trojan-Exploit/W32.BypassUAC.425984

Trojan-Exploit/W32.Phpw.844288

Trojan-Proxy/W32.Qukart.51717.H

Trojan-PWS/W32.AccPhish.2377398

Trojan-PWS/W32.Agent.1744384

Trojan-PWS/W32.Coins.264704

Trojan-PWS/W32.Fareit.597504.D

Trojan-PWS/W32.Mimikatz.1273856

Trojan-PWS/W32.OnLineGames.180389

Trojan-PWS/W32.OnLineGames.544136

Trojan-PWS/W32.Ruftar.7446528

Trojan-PWS/W32.Tepfer.12640

Trojan-PWS/W32.Tepfer.12744

Trojan-PWS/W32.Tepfer.12844

Trojan-PWS/W32.Tepfer.12880

Trojan-PWS/W32.Tepfer.12908

Trojan-PWS/W32.Tepfer.12980

Trojan-PWS/W32.Tepfer.13008

Trojan-PWS/W32.Tepfer.13240

Trojan-PWS/W32.Tepfer.138240.BG

Trojan-PWS/W32.Tepfer.138240.BH

Trojan-PWS/W32.Tepfer.17676

Trojan-PWS/W32.Tepfer.18256

Trojan-PWS/W32.Tepfer.18288

Trojan-PWS/W32.Tepfer.18384

Trojan-PWS/W32.Tepfer.18392

Trojan-PWS/W32.Tepfer.18810

Trojan-PWS/W32.Tepfer.24576.J

Trojan-Spy/W32.Agent.18480.C

Trojan-Spy/W32.Agent.785408.B

Trojan-Spy/W32.Noon.171008

Trojan-Spy/W32.Noon.742912.B

Trojan-Spy/W32.SpyEyes.35858

Trojan-Spy/W32.SpyEyes.36850

Trojan-Spy/W32.SpyEyes.37322

Trojan-Spy/W32.SpyEyes.86696

Trojan-Spy/W32.SpyEyes.87800

Trojan-Spy/W32.ZBot.1554944

Trojan-Spy/W32.ZBot.18186.C

Trojan-Spy/W32.ZBot.18568.D

Trojan-Spy/W32.ZBot.18740.B

Trojan-Spy/W32.ZBot.18916.D

Trojan-Spy/W32.ZBot.18948.B

Trojan-Spy/W32.ZBot.19238.B

Trojan-Spy/W32.ZBot.19466.C

Trojan-Spy/W32.ZBot.20214.C

Trojan-Spy/W32.ZBot.20578.C

Trojan-Spy/W32.ZBot.20598.C

Trojan-Spy/W32.ZBot.20734.C

Trojan-Spy/W32.ZBot.21060.F

Trojan-Spy/W32.ZBot.21144.B

Trojan-Spy/W32.ZBot.21272.C

Trojan-Spy/W32.ZBot.21348.B

Trojan-Spy/W32.ZBot.22296.D

Trojan-Spy/W32.ZBot.22430.D

Trojan-Spy/W32.ZBot.22566

Trojan-Spy/W32.ZBot.22760.C

Trojan-Spy/W32.ZBot.26070

Trojan-Spy/W32.ZBot.26208.B

Trojan-Spy/W32.ZBot.26822.B

Trojan-Spy/W32.ZBot.26960

Trojan-Spy/W32.ZBot.27042.B

Trojan-Spy/W32.ZBot.27180

Trojan-Spy/W32.ZBot.27280.C

Trojan-Spy/W32.ZBot.27318

Trojan-Spy/W32.ZBot.27418.B

Trojan-Spy/W32.ZBot.27560.B

Trojan-Spy/W32.ZBot.27594

Trojan-Spy/W32.ZBot.27732

Trojan-Spy/W32.ZBot.27870

Trojan-Spy/W32.ZBot.28284

Trojan-Spy/W32.ZBot.30094.B

Trojan-Spy/W32.ZBot.30164.D

Trojan-Spy/W32.ZBot.30232.B

Trojan-Spy/W32.ZBot.30302.C

Trojan-Spy/W32.ZBot.30508.D

Trojan-Spy/W32.ZBot.30704.D

Trojan-Spy/W32.ZBot.31268.B

Trojan-Spy/W32.ZBot.31380.B

Trojan-Spy/W32.ZBot.31470.C

Trojan-Spy/W32.ZBot.31566.C

Trojan-Spy/W32.ZBot.31980.B

Trojan-Spy/W32.ZBot.32768.AB

Trojan-Spy/W32.ZBot.33114

Trojan-Spy/W32.ZBot.33348

Trojan-Spy/W32.ZBot.36654

Trojan-Spy/W32.ZBot.36790

Trojan-Spy/W32.ZBot.36926.B

Trojan-Spy/W32.ZBot.436500

Trojan-Spy/W32.ZBot.48870

Trojan-Spy/W32.ZBot.48970.B

Trojan-Spy/W32.ZBot.49340

Trojan-Spy/W32.ZBot.49616

Trojan-Spy/W32.ZBot.50302

Trojan-Spy/W32.ZBot.50584

Trojan-Spy/W32.ZBot.529883

Trojan-Spy/W32.ZBot.605606

Trojan-Spy/W32.ZBot.630802

Trojan-Spy/W32.ZBot.64680

Trojan-Spy/W32.ZBot.65362

Trojan-Spy/W32.ZBot.65396

Trojan-Spy/W32.ZBot.65534

Trojan-Spy/W32.ZBot.66292

Trojan/W32.Agent.10088664

Trojan/W32.Agent.101804.B

Trojan/W32.Agent.103140.NC

Trojan/W32.Agent.103140.ND

Trojan/W32.Agent.1061127

Trojan/W32.Agent.106496.CXA

Trojan/W32.Agent.10672.B

Trojan/W32.Agent.1068032.X

Trojan/W32.Agent.1117184.UK

Trojan/W32.Agent.1117184.UL

Trojan/W32.Agent.1117184.UM

Trojan/W32.Agent.1117184.UN

Trojan/W32.Agent.1117184.UO

Trojan/W32.Agent.1117184.UP

Trojan/W32.Agent.1117184.UQ

Trojan/W32.Agent.1117184.UR

Trojan/W32.Agent.1117184.US

Trojan/W32.Agent.1117184.UT

Trojan/W32.Agent.1117184.UU

Trojan/W32.Agent.1117184.UV

Trojan/W32.Agent.1117184.UW

Trojan/W32.Agent.1117184.UX

Trojan/W32.Agent.1117184.UY

Trojan/W32.Agent.1117184.UZ

Trojan/W32.Agent.1117184.VA

Trojan/W32.Agent.123392.BCQ

Trojan/W32.Agent.12473856.B

Trojan/W32.Agent.125952.ZJ

Trojan/W32.Agent.1273856.CV

Trojan/W32.Agent.1288704.N

Trojan/W32.Agent.131072.DIH

Trojan/W32.Agent.131072.DII

Trojan/W32.Agent.134431.B

Trojan/W32.Agent.136671

Trojan/W32.Agent.13778432

Trojan/W32.Agent.151552.BYM

Trojan/W32.Agent.15459328

Trojan/W32.Agent.1552384.CB

Trojan/W32.Agent.157808.D

Trojan/W32.Agent.16404480.B

Trojan/W32.Agent.1641218

Trojan/W32.Agent.166440.M

Trojan/W32.Agent.1710592.L

Trojan/W32.Agent.17603584

Trojan/W32.Agent.17920.YZ

Trojan/W32.Agent.180375.D

Trojan/W32.Agent.18608.J

Trojan/W32.Agent.1941504.AS

Trojan/W32.Agent.19456.AFQ

Trojan/W32.Agent.209745

Trojan/W32.Agent.212992.HGE

Trojan/W32.Agent.212992.HGF

Trojan/W32.Agent.212992.HGG

Trojan/W32.Agent.212992.HGH

Trojan/W32.Agent.212992.HGI

Trojan/W32.Agent.212992.HGJ

Trojan/W32.Agent.212992.HGK

Trojan/W32.Agent.212992.HGL

Trojan/W32.Agent.212992.HGM

Trojan/W32.Agent.2187264.AS

Trojan/W32.Agent.2199336.B

Trojan/W32.Agent.221184.AYS

Trojan/W32.Agent.223796.B

Trojan/W32.Agent.22827.C

Trojan/W32.Agent.231364.C

Trojan/W32.Agent.2330624.V

Trojan/W32.Agent.243584

Trojan/W32.Agent.2467096

Trojan/W32.Agent.2521088.H

Trojan/W32.Agent.25316.OK

Trojan/W32.Agent.253584.B

Trojan/W32.Agent.2572288.AM

Trojan/W32.Agent.263961

Trojan/W32.Agent.263975.B

Trojan/W32.Agent.2661376.G

Trojan/W32.Agent.26896.E

Trojan/W32.Agent.2736640.G

Trojan/W32.Agent.2785280.W

Trojan/W32.Agent.2861568.I

Trojan/W32.Agent.290816.AMN

Trojan/W32.Agent.292000.D

Trojan/W32.Agent.30672.G

Trojan/W32.Agent.30810.C

Trojan/W32.Agent.31874.C

Trojan/W32.Agent.3213986

Trojan/W32.Agent.32768.ERD

Trojan/W32.Agent.32768.ERE

Trojan/W32.Agent.32834.B

Trojan/W32.Agent.32838.F

Trojan/W32.Agent.32868.D

Trojan/W32.Agent.33508.WG

Trojan/W32.Agent.34199.B

Trojan/W32.Agent.348932

Trojan/W32.Agent.352256.AFK

Trojan/W32.Agent.35778.C

Trojan/W32.Agent.36528.B

Trojan/W32.Agent.3659441

Trojan/W32.Agent.368640.AEA

Trojan/W32.Agent.37376.ABX

Trojan/W32.Agent.375808.JH

Trojan/W32.Agent.39278.C

Trojan/W32.Agent.3933568.BK

Trojan/W32.Agent.394752.HD

Trojan/W32.Agent.394752.HE

Trojan/W32.Agent.39936.WK

Trojan/W32.Agent.4026738

Trojan/W32.Agent.413184.EZ

Trojan/W32.Agent.43520.ACB

Trojan/W32.Agent.459776.HA

Trojan/W32.Agent.463521

Trojan/W32.Agent.4747098

Trojan/W32.Agent.4830720.F

Trojan/W32.Agent.49030.B

Trojan/W32.Agent.49279.C

Trojan/W32.Agent.49564.C

Trojan/W32.Agent.512000.ABW

Trojan/W32.Agent.514660.C

Trojan/W32.Agent.5418828.D

Trojan/W32.Agent.550358.B

Trojan/W32.Agent.5533408

Trojan/W32.Agent.561664.CY

Trojan/W32.Agent.563425.B

Trojan/W32.Agent.565760.CT

Trojan/W32.Agent.58048.C

Trojan/W32.Agent.581120.CQ

Trojan/W32.Agent.581632.QY

Trojan/W32.Agent.593467

Trojan/W32.Agent.595008

Trojan/W32.Agent.5979136.B

Trojan/W32.Agent.600080

Trojan/W32.Agent.616600.D

Trojan/W32.Agent.62701.D

Trojan/W32.Agent.649378

Trojan/W32.Agent.652288.FD

Trojan/W32.Agent.65536.FCG

Trojan/W32.Agent.6659786

Trojan/W32.Agent.67818.G

Trojan/W32.Agent.694272.CI

Trojan/W32.Agent.695808.DB

Trojan/W32.Agent.696320.OM

Trojan/W32.Agent.698773

Trojan/W32.Agent.73728.FQI

Trojan/W32.Agent.73728.FQJ

Trojan/W32.Agent.73802.AUW

Trojan/W32.Agent.795500.B

Trojan/W32.Agent.8134656.C

Trojan/W32.Agent.82414.B

Trojan/W32.Agent.841744.Q

Trojan/W32.Agent.8592896

Trojan/W32.Agent.892928

Trojan/W32.Agent.9037512

Trojan/W32.Agent.9044776

Trojan/W32.Agent.907264.AK

Trojan/W32.Agent.9108632

Trojan/W32.Agent.9111192

Trojan/W32.Agent.9115384

Trojan/W32.Agent.9138376

Trojan/W32.Agent.9207544

Trojan/W32.Agent.9243896

Trojan/W32.Agent.9294488

Trojan/W32.Agent.94208.EFX

Trojan/W32.Agent.9651

Trojan/W32.Agent.972288.B

Trojan/W32.Agent.980480.C

Trojan/W32.Agent.9854464

Trojan/W32.Banpak.166912

Trojan/W32.Blouiroet.1640448

Trojan/W32.Blouiroet.1680384

Trojan/W32.Blouiroet.1693696

Trojan/W32.Blouiroet.1734656

Trojan/W32.Blouiroet.1750528

Trojan/W32.Bublik.19014.B

Trojan/W32.Bublik.20808

Trojan/W32.Bublik.21138

Trojan/W32.Bublik.2466342

Trojan/W32.Bublik.26000.D

Trojan/W32.Bublik.26344

Trojan/W32.Bublik.28892

Trojan/W32.Bublik.30054

Trojan/W32.Bublik.5715456

Trojan/W32.Chapak.177664

Trojan/W32.Chapak.910848

Trojan/W32.CMY3U.1227264

Trojan/W32.Cometer.373136

Trojan/W32.Crypt.22150

Trojan/W32.Crypt.23956

Trojan/W32.Crypt.587776.B

Trojan/W32.Crypt.666624.C

Trojan/W32.Crypt.708608

Trojan/W32.Crypt.900096

Trojan/W32.Crypt.99840.KQ

Trojan/W32.Crypt.99840.KR

Trojan/W32.DelfiDelfi.1159168.E

Trojan/W32.Dimnie.162816.B

Trojan/W32.DOTHETUK.3210752

Trojan/W32.DOTHETUK.705536

Trojan/W32.Droma.359424.C

Trojan/W32.Ekstak.1581056.C

Trojan/W32.Ekstak.1581056.D

Trojan/W32.Ekstak.1581056.E

Trojan/W32.Ekstak.1581056.F

Trojan/W32.FakeAV.200683

Trojan/W32.FakeAV.22528.BP

Trojan/W32.FakeAV.458752.BJ

Trojan/W32.Fsysna.951775

Trojan/W32.GameHuck.1804480

Trojan/W32.Gofot.244403

Trojan/W32.Hesv.1785856

Trojan/W32.HydraPOS.515584

Trojan/W32.InfoStealer.759808

Trojan/W32.InfoStealer.769744

Trojan/W32.InfoStealer.772768

Trojan/W32.Inject.1026410

Trojan/W32.Inject.1062488

Trojan/W32.Inject.112640.L

Trojan/W32.Inject.1171038

Trojan/W32.Inject.1184067

Trojan/W32.Inject.1215350

Trojan/W32.Inject.128371

Trojan/W32.Inject.1941029

Trojan/W32.Inject.1956548

Trojan/W32.Inject.19992.B

Trojan/W32.Inject.2117388

Trojan/W32.Inject.21774

Trojan/W32.Inject.2242679

Trojan/W32.Inject.2293167

Trojan/W32.Inject.253952.AT

Trojan/W32.Inject.253952.AU

Trojan/W32.Inject.253952.AV

Trojan/W32.Inject.2590824

Trojan/W32.Inject.270336.AQ

Trojan/W32.Inject.270336.AR

Trojan/W32.Inject.270336.AS

Trojan/W32.Inject.270336.AT

Trojan/W32.Inject.27648.PJL

Trojan/W32.Inject.27648.PJM

Trojan/W32.Inject.27648.PJN

Trojan/W32.Inject.27648.PJO

Trojan/W32.Inject.27648.PJP

Trojan/W32.Inject.27648.PJQ

Trojan/W32.Inject.27648.PJR

Trojan/W32.Inject.27648.PJS

Trojan/W32.Inject.27648.PJT

Trojan/W32.Inject.27648.PJU

Trojan/W32.Inject.3788800.C

Trojan/W32.Inject.402610

Trojan/W32.Inject.407040.D

Trojan/W32.Inject.408576.E

Trojan/W32.Inject.409088.J

Trojan/W32.Inject.40960.CGU

Trojan/W32.Inject.40960.CGV

Trojan/W32.Inject.40960.CGW

Trojan/W32.Inject.40960.CGX

Trojan/W32.Inject.40960.CGY

Trojan/W32.Inject.40960.CGZ

Trojan/W32.Inject.425134

Trojan/W32.Inject.429592

Trojan/W32.Inject.455094

Trojan/W32.Inject.470100

Trojan/W32.Inject.511840

Trojan/W32.Inject.561490

Trojan/W32.Inject.57344.DQL

Trojan/W32.Inject.57344.DQM

Trojan/W32.Inject.57344.DQN

Trojan/W32.Inject.6291387

Trojan/W32.Inject.659328

Trojan/W32.Inject.66560.Gen

Trojan/W32.Inject.676371

Trojan/W32.Inject.755202

Trojan/W32.Inject.760576

Trojan/W32.Inject.805890

Trojan/W32.Inject.868472.CO

Trojan/W32.Inject.868472.CP

Trojan/W32.IRCBot.158720

Trojan/W32.IRCBot.97792

Trojan/W32.Kasidet.306176

Trojan/W32.Kasidet.311808

Trojan/W32.Kasidet.318464

Trojan/W32.KeyLogger.313856.B

Trojan/W32.Lampa.98304.AH

Trojan/W32.Monder.49152.CI

Trojan/W32.Monder.49664.AG

Trojan/W32.Monder.50176.BM

Trojan/W32.Monder.50176.BN

Trojan/W32.Monder.50176.BO

Trojan/W32.Monder.50176.BP

Trojan/W32.Monder.57440

Trojan/W32.Mucc.1609179

Trojan/W32.Nisloder.36864.B

Trojan/W32.Nymaim.659968.C

Trojan/W32.Nymaim.668672.N

Trojan/W32.OnlineGameHack.77712

Trojan/W32.OnlineGameHack.942919

Trojan/W32.Perkiler.21092

Trojan/W32.Phpw.16998400

Trojan/W32.Phpw.2033416

Trojan/W32.Reconyc.4256768

Trojan/W32.Reconyc.4265472

Trojan/W32.Reconyc.8611666

Trojan/W32.Reconyc.969728.D

Trojan/W32.Sasfis.1978368.B

Trojan/W32.ShadowBrokers.32768.D

Trojan/W32.ShipUp.238248.B

Trojan/W32.ShipUp.242872

Trojan/W32.ShipUp.252528.E

Trojan/W32.ShipUp.272565

Trojan/W32.Siscos.1417216

Trojan/W32.Sniffer.909802

Trojan/W32.Snojan.69120

Trojan/W32.Staser.589824.B

Trojan/W32.TDSS.5253632

Trojan/W32.Upatre.35376

Trojan/W32.VBKrypt.865792

Trojan/W32.Vilsel.10063872

Trojan/W32.Waldek.26289312

Trojan/W32.Waldek.6484992

Trojan/W32.Waldek.6486624

Trojan/W32.Waldek.7521952

Trojan/W32.Waldek.783704

Trojan/W32.Waldek.7942944

Trojan/W32.Wauchos.24431616.B

Trojan/W32.Wauchos.7460288

Trojan/W32.Wauchos.7710048

Trojan/W32.Wecod.598528

Trojan/W32.ZBot.21042

Trojan/W32.ZBot.29596.B

Trojan/W32.ZBot.4085120.CZ

Trojan/W32.ZBot.4085120.DA

Trojan/W32.ZBot.4085120.DB

Trojan/W32.ZBot.53668

Trojan/W32.ZBot.5570380

Trojan/W32.ZBot.938752

Trojan/W64.InfoStealer.10314700

Trojan/W64.Shelma.14848.N

Trojan/W64.Shelma.7168.AHF

Trojan/W64.Shelma.7168.AHG

Trojan/W64.Shelma.7168.AHH

Trojan/W64.Shelma.7168.AHI

Trojan/W64.Shelma.7168.AHJ

Trojan/W64.Shelma.7168.AHK

Trojan/W64.Shelma.7168.AHL

Trojan/W64.Shelma.7168.AHM

Trojan/W64.Shelma.7168.AHN

Trojan/W64.Shelma.7168.AHO

Trojan/W64.Shelma.7168.AHP

Worm/W32.Agent.105705

Worm/W32.Agent.1261568.F

Worm/W32.Agent.1312020

Worm/W32.Agent.25986144

Worm/W32.Agent.3551911

Worm/W32.Agent.954327

Worm/W32.Ardurk.13312.HCG

Worm/W32.AutoRun.472918

Worm/W32.Bundpil.22358976

Worm/W32.Bundpil.23564448

Worm/W32.Eggnog.29796

Worm/W32.IRCBot.21504

Worm/W32.Juched.218941

Worm/W32.NgrBot.465056

Worm/W32.NgrBot.465880

Worm/W32.Nuwar.118272.D

Worm/W32.Stration.176128

Worm/W32.Yah.10493952

Worm/W32.Yah.11821056

Worm/W32.Yah.11837440

Worm/W32.Yah.11857920

Worm/W32.Yah.12001280

Worm/W32.Yah.12029952

Worm/W32.Yah.14557184

Worm/W32.Yah.15216640

Worm/W32.Yah.17035264

Worm/W32.Yah.20037632

Worm/W32.Yah.20799488

Worm/W32.Yah.3354624

Worm/W32.Yah.3379200

Worm/W32.Yah.3428352

Worm/W32.Yah.4218880

Worm/W32.Yah.4382720.D

Worm/W32.Yah.5685248.E

Worm/W32.Yah.5840896.B

Worm/W32.Yah.5890048.B

Worm/W32.Yah.6352896.B

Worm/W32.Yah.7499776.B

Worm/W32.Yah.7507968

Worm/W32.Yah.7806976.D

Worm/W32.Yah.9691136

Worm/W32.Yah.9977856



--------------------------------------------------------------------------------------

       Copyright ⓒ, (주) 잉카인터넷, 2000-2018, All rights reserved.

--------------------------------------------------------------------------------------

Posted by Erteam