파밍 악성코드(jpg 출력형)

 

 

 

 

  

■  바이러스 토탈 정보

https://www.virustotal.com/ko/file/6f812b67ae1b4b442d334cbcb35aff3aba2c58f019a83b105f4a17b743af6df5/analysis/

 

 

■ 생성파일

     C:\Program Files\c\1.exe

     C:\Program Files\c\2.jpg

     C:\koreaautoup.bmp

     C:\Program Files\Common Files\1.exe

 

 

 

 

 

                                                                ▶ 2.jpg

  

 

■  실행압축 MEW

 

 

 

 

 

■  레지스트리 변경

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\autoup: "1.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\koreaautoup: "C:\Program Files\Common Files\1.exe"

 

 

 

■  접속 사이트

http://pv.sohu.com/cityjson?ie=gb2312

 

 

 

 ■  hosts 변조 - 피싱 사이트

115.177.179.151 www.naver.com
115.177.179.151 www.daum.net
115.177.179.151 daum.net
115.177.179.151 naver.com
115.177.179.151 kIsA.kBstor.coM
115.177.179.151 kIsA.Nenghuyp.coM
115.177.179.151 kIsA.shiNhoN.coM
115.177.179.151 kIsA.wooribenk.coM
115.177.179.151 kIsA.hoNabenk.coM
115.177.179.151 kIsA.epostbenk.go.kR
115.177.179.151 kIsA.idk.co.kR
115.177.179.151 kIsA.kcB.co.kR
115.177.179.151 kIsA.kfoc.co.kR

 

127.0.0.1 www.kbstar.com
127.0.0.1 kbstar.com
127.0.0.1 www.nonghyup.com
127.0.0.1 nonghyup.com
127.0.0.1 www.kfcc.co.kr
127.0.0.1 kfcc.co.kr
127.0.0.1 www.wooribank.com
127.0.0.1 wooribank.com
127.0.0.1 ibk.co.kr
127.0.0.1 www.shinhan.com
127.0.0.1 shinahan.com
127.0.0.1 www.hanabank.com
127.0.0.1 hanbank.com

 

Posted by Noise0
,