국내 상륙한 한글판 랜섬웨어(Cryt0L0cker)
- 재앙은 시작되었다 -
클리앙 유포지 :
http://row.bottomwebsites.xyz/[J5yEDRtHtVz5MW2NpX-IAK3avXWbbMvmXS6C76FmQBfJePZ5]
(뒷쪽 주소는 세션기반 랜덤 문자열 주소)
▶ C&C 서버 : lepodick.ru

클리앙 - 2015. 4. 21

시코(www.seeko.co.kr) - 2015. 4. 22


응모 이벤트 관련 사이트 감염 추정 - 2015. 4. 28
▶ C&C 서버 : qwokeris.ru
▶ 파일명 : exeterac.exe
▶ 레지스트리 : Run "epusysgg"=""C:\WINDOWS\exeterac.exe""
유포지
http://row.bottomwebsites.xyz/...
http://res.startnetingswapp.xyz/...
랜섬웨어 감염 분석
[파일생성]
[공통]
C:\WINDOWS\(랜덤8자리).exe
[Win XP]
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\00000000
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\01000000
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\02000000
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\03000000
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\04000000
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\05000000
C:\Documents and Settings\All Users\Application Data\yfysozezamyhirug\06000000
[Win 7]
C:\ProgramData\yfysozezamyhirug\00000000
C:\ProgramData\yfysozezamyhirug\01000000
C:\ProgramData\yfysozezamyhirug\02000000
C:\ProgramData\yfysozezamyhirug\03000000
C:\ProgramData\yfysozezamyhirug\04000000
C:\ProgramData\yfysozezamyhirug\05000000
C:\ProgramData\yfysozezamyhirug\06000000
파일명.encrypted
DECRYPT_INSTRUCTIONS.html
DECRYPT_INSTRUCTIONS.txt
[레지스트리]
[공통]
키: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
이름: (랜덤8자리)
값: "C:\WINDOWS\(랜덤8자리).exe"
[특징]
explorer.exe Injection