ÇØÅ·¡¤Á¤º¸ À¯Ãâ·Î ¾Ç¿ë¿ì·Á...ÃÖ±Ù 5°³¿ù°£ W32.Shadesrat°¨¿° Áõ°¡
[º¸¾È´º½º ±è°æ¾Ö] ¹Ì±¹, ¿µ±¹, Àεµ µî Àü ¼¼°èÀûÀ¸·Î ¿ø°Ý¿¡¼ ½Ã½ºÅÛÀ» Á¶ÀÛÇÒ ¼ö ÀÖ´Â ¿ø°Ý°ü¸® Åø°ú °ü·Ã ¾Ç¼ºÄڵ尡 ¹ß°ßµÇ¸é¼ °ü½ÉÀÌ ÁýÁߵǰí ÀÖ´Ù.
ÃÖ±Ù ½Ã¸¸ÅØ º¸¾È¿¬±¸¼Ò´Â °¨¿°µÈ ½Ã½ºÅÛ¿¡ ¹éµµ¾î¸¦ »ðÀÔÇÏ´Â Blackshades ¿ø°Ý °ü¸® Åø(RAT) ¾Ç¼ºÄÚµåÀÇ ÀÏÁ¾ÀÎ W32.Shadesrat°¡ ¹ß°ßµÆ´Ù°í ¹àÇû´Ù.
Blackshades RAT(Remote Administration Tool)´Â ¿ø°Ý¿¡¼ ½Ã½ºÅÛÀ» Á¶ÀÛÇÒ ¼ö ÀÖ´Â ¿ø°Ý°ü¸® Åø(RAT)ÀÇ ÇÑ Á¾·ù·Î ºÒ¹ýÀûÀ¸·Î °Å·¡µÇ¾î ÇØÅ·À̳ª Á¤º¸À¯ÃâÀÇ ¸ñÀûÀ¸·Î ¾Ç¿ëµÉ ¼ö ÀÖ´Ù.
ÃÖ±Ù 5°³¿ù µ¿¾È W32.ShadesratÀÇ °¨¿°ÀÌ Áõ°¡ÇßÀ¸¸ç, ¼ö¹é °³ÀÇ C&C ¼¹ö°¡ ¹ß°ßµÇ¾ú´Ù. ¶ÇÇÑ, W32.Shadesrat´Â °¨¿°µÈ ½Ã½ºÅÛÀ¸·ÎºÎÅÍ ¾ÏÈ£ ¹× Áõ¸í¼¿Í °°Àº ¹Î°¨ÇÑ Á¤º¸µéÀ» ¼öÁýÇØ C&C ¼¹ö·Î Àü¼ÛÇÑ °ÍÀ¸·Î µå·¯³µ´Ù.
°ø°ÝÀÚ´Â ¿ø°Ý°ü¸® Åø(RAT)À» ÅëÇØ °¨¿°µÈ ½Ã½ºÅÛ¿¡ ´Ù¼öÀÇ ÆäÀ̷εå¿Í Ãß°¡ÀûÀÎ ¾Ç¼ºÄڵ带 ´Ù¿î·ÎµåÇØ ¼³Ä¡ÇÒ ¼ö ÀÖÀ¸¸ç, C&C ¼¹ö´Â Ransomlock, Adware, Tidserv µî°ú °°ÀÌ ´Ù¸¥ ¾Ç¼ºÄÚµåµéÀ» Æ۶߸°´Ù.
¹Ì±¹, ¿µ±¹, Àεµ°¡ W32.Shadesrat·Î ÀÎÇÑ °¨¿°ÀÌ °¡Àå ¸¹À¸¸ç, ¸®Åõ¾Æ´Ï¾Æ¿Í ¹Ì±¹Àº ´Ù¼öÀÇ C&C ¼¹ö¸¦ Áö´Ï°í ÀÖ´Â °ÍÀ¸·Î ¹àÇôÁ³´Ù.
½Ã¸¸ÅØ º¸¾È¿¬±¸¼Ò¿¡ µû¸£¸é Àü ¼¼°èÀûÀ¸·Î ÁÖ¿ä C&C¼¹öÀÇ À§Ä¡¿Í W32.Shadesrat¿¡ °¨¿°µÈ Áö¿ªÀº ´ÙÀ½°ú °°´Ù. ¼¼ºÎ³»¿ëÀº KISA ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ¿¡¼ Á¦½ÃÇÑ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¸é µÈ´Ù.
1. http://www.symantec.com/connect/blogs/blackshades-rat-usage-rise-despite-author-s-alleged-arrest (2013/11/25)
2. http://removeyourmalware.wordpress.com/2013/11/27/blackshades-malware-still-on-sale/ (2013/11/27)
3. https://www.securityweek.com/blackshades-rat-attack-activity-increasing (2013/11/26)
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>