ÇØÄ¿Áî´º½º / ÇØÄ¿´ëÇÐ

Donation bitcoin(±âºÎ¿ë ºñÆ®ÄÚÀÎ ÁÖ¼Ò)

¡¡
1Pq3K39XM5xx4CifGKgppXeavtWNNHH7K4
¡¡
±âºÎÇϽŠºñÆ®ÄÚÀÎÀº "º¸¾È Ãë¾à °èÃþ"À» À§ÇØ »ç¿ëµÇ°í ÀÖ½À´Ï´Ù.
¡¡
¡¡

Donation bitcoin(±âºÎ¿ë ºñÆ®ÄÚÀÎ ÁÖ¼Ò)

¡¡
1Pq3K39XM5xx4CifGKgppXeavtWNNHH7K4
¡¡
±âºÎÇϽŠºñÆ®ÄÚÀÎÀº "º¸¾È Ãë¾à °èÃþ"À» À§ÇØ »ç¿ëµÇ°í ÀÖ½À´Ï´Ù.
¡¡

°øÁö

¡¡

1. MS ¿§Áö ºê¶ó¿ìÀú¿¡¼­ÀÇ °æ°íâÀº 'À©µµ¿ì µðÆæ´õ'¸¦ ²ô½Ã¸é µË´Ï´Ù.

             'À©µµ¿ì µðÆæ´õ ²ô±â'

2. Å©·Ò ºê¶ó¿ìÀú·Î Á¢¼Ó½Ã ³ª¿À´Â ¾Ç¼ºÄÚµå °æ°íâÀº ±¸±Û Å©·ÒÀÇ ¿¡·¯, Áï ¿ÀŽ(ŽÁö ¿À·ù)À̹ǷΠ¹«½ÃÇÏ½Ã¸é µË´Ï´Ù.

3. ÀÌ »çÀÌÆ®´Â ¾ÈÀüÇÏ¸ç ±ú²ýÇÏ´Ù´Â °ÍÀ» ¾Ë·Á µå¸³´Ï´Ù.

4. ¹«°íÇÑ »çÀÌÆ®µé¿¡ ´ëÇÑ °ø·æ ±â¾÷ ºê¶ó¿ìÀúµéÀÇ ¹«Â÷º°ÀûÀÎ 'ŽÁö ¿À·ù ȾÆ÷'°¡ »ç¿ëÀÚµéÀÇ Á¤º¸ °øÀ¯ÀÇ ÀÚÀ¯¸¦ ħÇØÇÏ°í ÀÖ½À´Ï´Ù. ÀÌ¿¡ ´ëÀÀÇÏ¿© ÀÌ ±â¾÷µéÀ» »ó´ë·Î ¼Ò¼ÛÀ» ÁغñÇÏ°í ÀÖ½À´Ï´Ù.

¡¡



ÇØÄ¿Áî´º½º Á¦°ø ¹ÙÀÌ·¯½º °æº¸
2004/6/17(¸ñ)
Paps.A ´ë·® ¸ÞÀϸµ ¿ú  
¹ÙÀÌ·¯½º/¿ú ¸íĪ : Paps.A ´ë·® ¸ÞÀϸµ ¿ú
¹ß·ÉÀϽà : 6¿ù17ÀÏ
¹ÙÀÌ·¯½º À¯Çü : ¸ÞÀϸµ ¿ú
À§Çèµµ : »ó
ÇØ´ç½Ã½ºÅÛ : À©µµ
W32.Paps.A@mm is a mass-mailing worm that sends itself as an attachment to the email addresses that it finds on your computer. The email will have a variable subject and file attachment. The attachment will have a .exe file extension.

This threat is written in the Delphi language and is packed by UPX.

Type:  Worm
Infection Length:  approx. 255KB
 
 
 
Systems Affected:  Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected:  DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX, Windows 3.x

=====

When W32.Paps.A@mm executes, it performs the following actions:


Creates the following files:
%Windir%\Win32config.exe
%Windir%\Win32apps3.txt
%Windir%\Kernel32.dll
%Windir%\Ntbtlog.txt
iphist.dat. This file is created in the same folder as the original worm file.


--------------------------------------------------------------------------------
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
--------------------------------------------------------------------------------


Adds the value:

"Win32Config" = "%Windir%\win32config.exe"

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm is executed every time Windows starts.


Scans the following file types on all the local drives for email addresses:

.doc
.txt
.wab
.rtf
.htm
.html
.dbx
.xml
.msg
.php
.cgi
.pst
.nk2


The worm sends itself to the addresses that it found as an email attachment. The contents of the email message varies depending on the top-level domain of the target email address.

The worm does not send email to the addresses containing the following strings:

VIRUS
PESTPATROL
KASPERSKY
SOPHOS
SYMANTEC
NORTON
AVP
ANTIVIR
FREEAV
EWIDO
F-SECURE
MCAFEE
NAI.COM
BUSE@
MICROSOFT


If the To address contains the top-level domains of .de, .at, or .ch, the email will be:

Subject: The subject will be one of following:

RE: RE: FWD:
Re: Message Error
Re: Ihre Informationen
Re: Bad Request
Anzeige wegen illegalem Mp3-Tausch
du hast einen Trojaner auf deinem PC
Du Idiot!!!
ups, Ich habe Ihre Mail bekommen
Ich hasse dich!!
Achtung: Neuer Virus!!!
MailerDaemon: Mail Delivery Failure

Message: The message body will be one of the following:

Hi du! Hab mal schnell ein paar Fotos mit Meikes Webcam geschossen. Sind echt lustig geworden :)
Hab dir die Fotos angehngt! Wir sehen uns...

ESMTP [Secure Mail System #334]: Secure message is attached.
++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.com

Guten Tag! Die angeforderten Informationen befinden sich im Anhang. MfG
++++ Attachment: No Virus found +++ Kaspersky AntiVirus - www.kaspersky.com

Bad Gateway: The message has been attached.
++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.com

Sie tauschen illegal mp3-files aus! Ein Gerichtsverfahren gegen Sie wurde eingeleitet.
Nhere Informationen entnehmen Sie bitte dem Anhang.

Hallo, ich bin aus sterreich. Ich hab gerade mal kurz deinen Computer gescannt und festgestellt, das du einen Trojaner drauf hast. Ich konnte mir deine komplette Festplatte angucken.
Ich hab dir mal nen Removal tool an die Mail angehngt. :)

Warum machen sie das? Sie Idiot! Sie haben mein Geld gestolen!!!
ICH WERDE SIE BEI DER POLIZEI ANZEIGEN!!!! Schauen Sie sich den Anhang an!

Das muss wohl ein Fehllufer sein. Irgendjemand hat eine Mail, die fr Sie bestimmt war an meine Mail Adresse geschickt. Ich leite die Mail einfach mal weiter. Der Anhang ist sehr interessant :)

Ich hab dir gesagt, das ich dich liebe...und du?? Du....du hast garnichts gesagt!!!
Verschwinde...du Schuft ... Ich hasse dich!! Du kannst deine Dateien zurck haben!!! Ich hab sie angehngt...

Achtung: An alle Online-Spieler!! Ein neuer Wurm verbreitet sich ber Online-Spiele!!!
Installiert euch den Patch im Anhang so schnell wie mglich damit ihr das nicht auch kriegt!!

Mail transaction failed. Partial message is available
++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.com


If the To address does not contain the top-level domains of .de, .at, or .ch, the email properties will be:

Subject: The subject will be one of following:

RE: RE: FWD:
Re: Message Error
Re: Mail Authentification
Re: Bad Request
illegal file sharing
a trojan horse is on your PC
you are an idiot
ups, i've got your mail
I hate you
hi, its me
MailerDaemon: Mail Delivery Failure

Message: The message body will be one of the following:

Here, the DigiCam photos. A few are overexposed...

ESMTP [Secure Mail System #334]: Secure message is attached.
++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.com

Please read the attachment to get the message.
++++ Attachment: No Virus found +++ Kaspersky AntiVirus - www.kaspersky.com

Bad Gateway: The message has been attached.
++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.com

You are sharing illegal mp3-files. A legal investigation has been startet. For details read the attachment.

hi, I am from austria and you`ll don`t believe me, but a trojan horse in on your PC.
I've scanned your Computer and discovered that the trojan horse subseven is running on Port 1234. I have
attached a removal tool for you to this mail :)

why did you do that? idiot! You stole my money!!! I`LL REPORT YOU TO THE POLICE!!!! See the attachment!

i`m very very sorry, but anybody have sent your mail to my address. The attachment is very surprising :)

I said, I love you...and you said NOTHING And now... Go Away From Me ... I hate you!!
You can have your documents back!! I`ve attached them...

Caution: To all gamers A new worm spread via online gaming! Install the attached patch as soon as possible!!

Mail transaction failed. Partial message is available
++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.com


In all the cases, the file name of the attachment will be one of the following:

Pics.JPG.exe
MailMessage.Msg.exe
Filesharing_details.DOC.exe
Trojan_removal_tool.exe
Report.DOC.exe
Documents.DOC.exe
Removal_tool.exe


Attempts to access the following Web sites:

http: //www.google.de
http: //www.hausaufgaben.de
http: //www.referate.de
http: //www.eselfilme.com


Attempts to access http: //www.whatismyip.com to get the IP address of the local system.


                    ´äº¯/°ü·Ã ¾²±â Æû¸ÞÀÏ ¹ß¼Û
NoI¢ÆN¢ÆD¢ÆE¢ÆXDate
216   Anisc ¹ÙÀÌ·¯½º °æº¸ 2004/06/21
215   Korgo.L º¯Á¾ ¿ú 2004/06/19
214   Paps.A ´ë·® ¸ÞÀϸµ ¿ú 2004/06/17
213   Sober.H º¯Á¾ Æ®·ÎÀÌ 2004/06/15
212   Ascetic.A Æ®·ÎÀÌ °æº¸ 2004/06/13
211   Sasser.G º¯Á¾ ¿ú 2004/06/11
210   Dingsta.A Æ®·ÎÀÌ 2004/06/09
209   Startpage.E Æ®·ÎÀÌ 2004/06/07

 
óÀ½ ÀÌÀü ´ÙÀ½       ¸ñ·Ï