060.jpgÌäÂê

³µÍ×

RO Skin Station SideÆâ ¥¹¥­¥óÀìÍÑ¥¢¥×¥í¥À¤ËŽ¤é¤ì¤¿¡¢³ÈÄ¥»Ò¤ò .jpg¤Èµ¶Áõ¤·¤¿¥¦¥£¥ë¥¹html¤Ë¤Ä¤¤¤Æ¤ÎÁǿͤˤè¤ë¥á¥â¡£

¥¢¥«¥¦¥ó¥È¥Ï¥Ã¥¯Áí¹ç¥¹¥ì 5
http://gemma.mmobbs.com/test/read.cgi/ragnarok/1170419695/l50

¤ËÅê¹Æ¤·¤¿Ê¸¾Ï¤ò¸µ¤ËºÆ¹½À®¡£
¤³¤Î·ï¤Ë¤Ä¤¤¤Æ¤ÎÌ䤤¹ç¤ï¤»¤Ï¾åµ­¥¹¥ì¤Ë¤ÆÂбþ¡£

¾ÜºÙ

´¶À÷¥×¥í¥»¥¹

060.jpg¤Ï Jpeg²èÁü¤È»×¤ï¤»¤ë³ÈÄ¥»Ò¤ò»ý¤Ã¤Æ¤¤¤ë¤¬¡¢Ãæ¿È¤Ï JavaScript, VBScript¤ò´Þ¤à html¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë¡£
mime¤ä³ÈÄ¥»Ò¤Ë½¾¤¦¤Þ¤È¤â¤Êhtml¥Ö¥é¥¦¥¶¤Ê¤é¤Ð¡¢²õ¤ì¤¿jpeg²èÁü¥Õ¥¡¥¤¥ë¤Ë¤·¤«¸«¤¨¤Ê¤¤¤¬¡¢Internet Explorer (¡Ö³ÈÄ¥»Ò¤Ç¤Ï¤Ê¤¯¡¢ÆâÍƤˤè¤Ã¤Æ¥Õ¥¡¥¤¥ë¤ò³«¤¯¡×¤¬¡ÖÍ­¸ú¡×¤Ë¤Ê¤Ã¤Æ¤¤¤ë IE7¤ò´Þ¤à)¤Ç¤Ï¡¢¾¡¼ê¤ËÄ̾ï¤Îhtml¤È²ò¼á¤·¡¢JavaScript¤ä¡¢VBScript¤¬(µö²Ä¤µ¤ì¤Æ¤¤¤ì¤Ð)¼Â¹Ô¤µ¤ì¤ë¡£

¤³¤Î¥Õ¥¡¥¤¥ë(060.jpg)¤Ë´Þ¤Þ¤ì¤ëVBScript¤ÎÆ°ºî

¥Õ¥¡¥¤¥ë¤ÎºîÀ®
Windows¤ÎSystem¥Ç¥£¥ì¥¯¥È¥ê (¼Â¸³´Ä¶­¤Ç¤Ï C:\WINNT\system32 °Ê²¼ System¥Ç¥£¥ì¥¯¥È¥ê¤Èɽµ­) ¤Ë
  • TSP32E.DLL - ¥Æ¥­¥¹¥È¥Õ¥¡¥¤¥ë¡£Ãæ¿È¤Ï¿ô»ú¤ÎÍåÎó (Kernel.exe¤ò¥¨¥ó¥³¡¼¥É¤·¤¿¤â¤Î)
  • TSP32V.DLL - ¥Æ¥­¥¹¥È¥Õ¥¡¥¤¥ë¡£Ãæ¿È¤Ï¿ô»ú¤ÎÍåÎó (Kernel.vbs¤ò¥¨¥ó¥³¡¼¥É¤·¤¿¤â¤Î)
    ¤È
  • Kernel.exe - Win32¼Â¹Ô¥Õ¥¡¥¤¥ë
  • Kernel.vbs - VBScript¥Õ¥¡¥¤¥ë
    ¤òºîÀ®¤¹¤ë¡£
    Kernel.*¥Õ¥¡¥¤¥ë¤Ï¡¢¤½¤ì¤¾¤ì Systeme.dll, Systemv.dll¥Õ¥¡¥¤¥ë¤ÎÃæ¿È¤¬ "on" ¤Ç¤Ê¤¤¤È¤­ºîÀ®¤µ¤ì¤ë(¸å½Ò)
¥×¥í¥°¥é¥à¡¢¥¹¥¯¥ê¥×¥È¤Îµ¯Æ°
  • Systeme.dll¤òÆɤßÃæ¿È¤¬ "on"¤Ç¤Ê¤±¤ì¤Ð¡¢Kernel.exe¤ò¼Â¹Ô¤¹¤ë¡£
  • Systemv.dll¤òÆɤßÃæ¿È¤¬ "on"¤Ç¤Ê¤±¤ì¤Ð¡¢Kernel.vbs¤ò¼Â¹Ô¤¹¤ë¡£

Kernel.vbs¤ÎÆ°ºî

  • 'Navid new virus 2006(1375.1) ¤È¤¤¤¦¥³¥á¥ó¥È¤ò»ý¤Ä
¥ì¥¸¥¹¥È¥ê¥­¡¼¤ÎºîÀ®
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
    ¤Ë¡¢
    C:\WINNT\system32\Kernel.vbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
    ¤Ë¡¢C:\WINNT\system32\Kernel.exe
    ¤òºîÀ®¤¹¤ë¡£
    ¤³¤ì¤é¤ÏPCµ¯Æ°»þ¡¢¤ª¤è¤Ó¥í¥°¥¤¥ó»þ¤Ë¼«¤é¤¬ºîÀ®¤·¤¿ Kernel.vbs¡¢Kernel.exe¤ò¼Â¹Ô¤µ¤»¤ë¤â¤Î¤Ç¤¢¤ë¡£
¥Õ¥é¥°¤ÎÀßÄê
system¥Ç¥£¥ì¥¯¥È¥ê¤Ë Systemv.dll¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¡¢"on"¤È¤¤¤¦Ê¸»úÎó¤òÀßÄꤹ¤ë¡£(¿½Åµ¯Æ°¤òËɤ°¤¿¤á¤ÎÆ°ºî¾õ¶·¥Õ¥é¥°¤È»×¤ï¤ì¤ë)
html¥Õ¥¡¥¤¥ë¤Î²þÊÑ
¥í¡¼¥«¥ë¥Ç¥£¥¹¥¯, ¥Í¥Ã¥È¥ï¡¼¥¯¶¦Í­¥É¥é¥¤¥ÖÆâ¤Ë¤¢¤ëÁ´¤Æ¤Î¥Ç¥£¥ì¥¯¥È¥ê¤ò½ä²ó¤·
htm, html, htt ¤Î³ÈÄ¥»Ò¤ò»ý¤Ä¥Õ¥¡¥¤¥ë¤Ë 060.jpg¤Ë´Þ¤Þ¤ì¤Æ¤¤¤¿¤â¤ÎÁêÅö¤Î VBScript¤òÄɲ乤롣
Yahoo!ID¤Î°ìÍ÷¤òºîÀ®
  • Yahoo!Messenger (¿ʬÆüËܤΥ桼¥¶¡¼¤Ï´Ø·¸¤Ê¤¤¤¬Ì¤³Îǧ)¤ÎProfile¥Ç¥£¥ì¥¯¥È¥ê¤ò¸«¤Ä¤±¤¿¤é¤½¤³¤Ëµ­Ï¿¤µ¤ì¤Æ¤¤¤ë¥Õ¥¡¥¤¥ë̾¤òYahooID¤È¸«¤Ê¤·¤Æ mail.log¤Ë¥¢¥É¥ì¥¹°ìÍ÷¤òºîÀ®¤¹¤ë¡£
  • send.log¤Ë"HKEY_CURRENT_USER\Software\yahoo\pager\Yahoo! User ID"¥­¡¼¤ÎÃÍ + @yahoo.com ¤È¤¤¤¦Ê¸»úÎó¤òºîÀ®¤¹¤ë¡£
¥á¡¼¥ë¤ÎÁ÷¿®
mail.log¤ËºîÀ®¤·¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹°ìÍ÷¤¢¤Æ¤Ë¤È¤¢¤ëURL (¸½ºß404)¤ÎÀëÅÁ¥á¡¼¥ë¤òÁ÷¤ê¤Ä¤±¤ë¡£¤½¤Î¤È¤­¤Î From¤Ë¤Ï send.log¤òÀßÄꤹ¤ë¡£
¥Õ¥é¥°¤ÎÀßÄê
system¥Ç¥£¥ì¥¯¥È¥ê¤Ë Systemv.dll¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤Ë¡¢"off"¤È¤¤¤¦Ê¸»úÎó¤òÀßÄꤹ¤ë¡£

Kernel.exe¤ÎÆ°ºî

  • ¾ÜºÙÉÔÌÀ
  • Kernel.vbsÁêÅö¤ÎÆ°ºî¤ò»ý¤Ä¤ÈͽÁÛ¤µ¤ì¤ë¡£
  • ¤½¤ì°Ê¾å¤Îµ¡Ç½¤ò»ý¤Ã¤Æ¤¤¤ë¤«¤â¤·¤ì¤Ê¤¤¡£

´¶À÷¤·¤Æ¤·¤Þ¤Ã¤¿¤é

  • Ç°¤Î¤¿¤á¥»¡¼¥Õ¥â¡¼¥É¤Çµ¯Æ°¤¹¤ë
    (µ¯Æ°»þ¤Ë Kernel.exe, Kernel.vbs¤ò¼Â¹Ô¤µ¤»¤Ê¤¤¤¿¤á)
  • system¥Ç¥£¥ì¥¯¥È¥êÆâ¤Î
    • TSP32E.DLL
    • TSP32V.DLL
    • Kernel.exe
    • Kernel.vbs
      ¥Õ¥¡¥¤¥ë¤òºï½ü¤¹¤ë¡£
  • ¥ì¥¸¥¹¥È¥ê¥­¡¼
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows
      ¤òºï½ü¤¹¤ë¡£
  • ¥í¡¼¥«¥ë¥Ç¥£¥¹¥¯¡¢¶¦Í­¥É¥é¥¤¥Ö¤Ê¤¤¤Î *.htm, *.html, *.htt¥Õ¥¡¥¤¥ë¤ò¸¡º÷¤·ºï½ü¤¹¤ë (¤«¡¢Äɲ䵤줿VBScriptÉôʬ¤òÀÚ½ü¤¹¤ë)
  • ºÆµ¯Æ°¸å WindowsUpdate¤¹¤ë

Ãí°Õ

¸½»þÅÀ(2007/02/26)¤Ë¤ª¤¤¤Æ¡¢Symantec AntiVirus¤ÏKernel.vbs, Kernel.exe¼«ÂΤò¶¼°Ò¤È¸«¤Ê¤µ¤Ê¤¤¤Î¤Ç¤¢¤Æ¤Ë¤·¤Ê¤¤¤³¤È¡£
¥«¥¹¥Ú¥ë¥¹¥­¡¼¤Ï¶¼°Ò¤È·Ù¹ð¤·¤¿¡£

Kernel.vbsʬ¤Î¶î½ü¤Ï°Ê¾å¤Î¤È¤ª¤ê¤À¤¬¡¢Kernel.exe¤Îµ¡Ç½¤Ë¤Ä¤¤¤Æ¤ÏÇÄ°®¤·¤Æ¤¤¤Ê¤¤¡£
¤½¤â¤½¤â´¶À÷¤·¤Æ¤·¤Þ¤Ã¤¿¤³¤È¼«ÂΤ¬ÌäÂê¤Ç¤¢¤ë¤Î¤Ç¡¢¤½¤ÎÂнè¤ò´Þ¤áÁá´ü¤ËºÆ¥¤¥ó¥¹¥È¡¼¥ë¤«¤é¤Î´Ä¶­¤ÎºÆ¹½ÃÛ¤ò¤¹¤ë¤Ù¤­¤ÈȽÃǤ¹¤ë¡£

ÍúÎò

  • 2007/02/26 - ½éÈÇ

¥È¥Ã¥×   º¹Ê¬ ¥Ð¥Ã¥¯¥¢¥Ã¥× ¥ê¥í¡¼¥É   °ìÍ÷ ñ¸ì¸¡º÷ ºÇ½ª¹¹¿·   ¥Ø¥ë¥×   ºÇ½ª¹¹¿·¤ÎRSS
Last-modified: 2007-02-26 (·î) 14:49:38 (6490d)