๋žœ์„ฌ์›จ์–ด, ์•…์„ฑ์ฝ”๋“œ ๊ฒ€์‚ฌ ์‚ฌ์ดํŠธ - ๋ฐ”์ด๋Ÿฌ์Šค ํ† ํƒˆ(VirusTotal)
๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
์•Œ์“ธ์‹ ์žก

๋žœ์„ฌ์›จ์–ด, ์•…์„ฑ์ฝ”๋“œ ๊ฒ€์‚ฌ ์‚ฌ์ดํŠธ - ๋ฐ”์ด๋Ÿฌ์Šค ํ† ํƒˆ(VirusTotal)

by ์ผ์ƒ์„ ๊ณต์œ ํ•จ๋‹ˆ๋‹ค 2022. 11. 17.

Virus Total - ์˜์‹ฌ์Šค๋Ÿฌ์šด ํŒŒ์ผ, ๋„๋ฉ”์ธ, IP ๋ฐ URL์„ ๋ถ„์„ํ•˜์—ฌ ๋งฌ์›จ์–ด ๋ฐ ๊ธฐํƒ€ ์นจํ•ด๋ฅผ ํƒ์ง€ํ•˜๊ณ  ๋ณด์•ˆ ์ปค๋ฎค๋‹ˆํ‹ฐ์™€ ์ž๋™์œผ๋กœ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค.

์ธํ„ฐ๋„ท์ด๋‚˜ ์ด๋ฉ”์ผ, ๋ฉ”์‹ ์ € ๋“ฑ์œผ๋กœ ํŒŒ์ผ์„ ๋ฐ›์•˜์„ ๋•Œ 
์ด ํŒŒ์ผ์„ ํ†ตํ•ด์„œ ๋žœ์„ฌ์›จ์–ด์— ๊ฐ์—ผ๋˜๋Š” ๊ฑด ์•„๋‹๊นŒ? ์•…์„ฑ์ฝ”๋“œ๊ฐ€ ์‹ฌ์–ด์ ธ ์žˆ๋Š” ๊ฑด ์•„๋‹๊นŒ?

๊ณ ๋ฏผ์„ ํ•˜๊ฒŒ๋ ๋•Œ ๋‚ด PC์— ๋ถ€๋‹ด ์—†์ด ๊ฒ€์‚ฌํ•ด์ฃผ๋Š” ์‚ฌ์ดํŠธ๊ฐ€ ์žˆ๋‹ค๋ฉด ์–ผ๋งˆ๋‚˜ ์ข‹์„๊นŒ??
์žˆ์–ด์„œ ์ฐธ ์ข‹๋‹ค.

์šฐ๋ฆฌ์—๊ฒŒ ์žˆ์–ด ๋ฐฉ์‹์€ ์ฐธ ๊ฐ„๋‹จํ•˜๋‹ค.
ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜๊ฑฐ๋‚˜ URL ์„ ์ž…๋ ฅํ•ด์„œ ๊ฒ€์‚ฌํ•˜๊ธฐ๋ฅผ ์›ํ•˜๋Š” ํŒŒ์ผ์„ ์›น๋ธŒ๋ผ์šฐ์ €๋ฅผ ํ†ตํ•ด ์ „๋‹ฌ๋งŒ ํ•˜๋ฉด ์•„๋ž˜์ฒ˜๋Ÿผ ๋ฐ”๋กœ ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์˜จ๋‹ค.

์›น์—์„œ ๋ฐ›์€ ํŒŒ์ผ ํ•˜๋‚˜๋ฅผ ์˜ฌ๋ ค๋ณด๋‹ˆ 67๊ฐœ ๋ฐฑ์‹ ํ”„๋กœ๊ทธ๋žจ ์ค‘์—์„œ 8๊ฐœ์˜ ํ”„๋กœ๊ทธ๋žจ์—์„œ ๋ฐ”์ด๋Ÿฌ์Šค๋กœ ์˜์‹ฌ๋œ๋‹ค๋Š” ๊ฒฐ๊ณผ๊ฐ€ ๋ณด์ธ๋‹ค.

 

๋ฐ˜์‘ํ˜•

 

์‚ฌ์šฉ๋ฐฉ๋ฒ•

https://www.virustotal.com/

1. ํŒŒ์ผ์„ ์„ ํƒํ•œ๋‹ค.

  • ๋‚ด PC์˜ ํŒŒ์ผ ์—…๋กœ๋“œ
  • ์›น์— ์žˆ๋Š” ํŒŒ์ผ ์ฃผ์†Œ

2. ๊ฒ€์‚ฌ๋ฅผ ์‹œ์ž‘ํ•œ๋‹ค.

3. ๊ฒ€์‚ฌ ๊ฒฐ๊ณผ๋ฅผ ํ™•์ธํ•œ๋‹ค.

  • ๋ฐ”์ด๋Ÿฌ์Šค ๊ฒ€์ถœ๋  ๊ฒฝ์šฐ ํ•ด๋‹น ๋ฐฑ์‹ ์—์„œ ๊ฒ€์ถœํ•œ ๋‚ด์šฉ์„ ๋นจ๊ฐ„์ƒ‰์œผ๋กœ ํ‘œ์‹œํ•ด์ค€๋‹ค.
     - ESET-NOD32 : A Variant Of Win32/Kryptik.HRJU
     - Google : Detected
     - Gridinsoft (no cloud) : Trojan.Heur!.02012821
     - Ikarus : Trojan.Win32.Crypt
     - Rising : Malware.SwollenFile!1.DDB4 (CLASSIC)
     - SecureAge : Malicious
     - SentinelOne (Static ML) : Static AI - Suspicious PE
     - Trapmine : Malicious.moderate.ml.score
  • ๋ฐ”์ด๋Ÿฌ์Šค๊ฐ€ ๊ฒ€์ถœ๋˜์ง€ ์•Š๋Š”๋‹ค๋ฉด Undetected or Clean ์œผ๋กœ ํ‘œ์‹œ๋œ๋‹ค.
     - Undetected

     - Clean
  • ๋ฐฑ์‹  ํ”„๋กœ๊ทธ๋žจ์ด ์ง€์›ํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ Unable to process file type or Unrated ๋กœ ํ‘œ์‹œ๋œ๋‹ค.
     - Unrated

     - Unable to process file type

 

์œ ์˜์‚ฌํ•ญ

ํŒŒ์ผ ํ™•์žฅ์ž์— ๋”ฐ๋ผ ๊ฒ€์‚ฌ๋ฅผ ์ง€์›ํ•˜๋Š” ๋ฐฑ์‹ ํ”„๋กœ๊ทธ๋žจ์ด ๋‹ค๋ฅด๋‹ค.

์œ„ 3๊ฐœ ๊ฒ€์‚ฌ ๊ฒฐ๊ณผ๋Š” ๋ชจ๋‘ ๋™์ผํ•œ ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ๋‹ค์šด๋กœ๋“œ URI์™€ ์••์ถ•ํŒŒ์ผ, ์‹คํ–‰ํŒŒ์ผ 3๊ฐ€์ง€ ํ˜•ํƒœ๋กœ ๊ฒ€์‚ฌ๋ฅผ ์ง„ํ–‰ํ•˜์˜€๋‹ค. ํ•˜์ง€๋งŒ, ๊ฒฐ๊ณผ๋Š” 3๊ฐœ ๋ชจ๋‘ ๋‹ค๋ฅด๊ฒŒ ๋‚˜์™”๋‹ค.

๊ฐ€๋Šฅํ•˜๋‹ค๋ฉด ์‚ฌ์šฉ์ž๊ฐ€ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์ข… ํ˜•ํƒœ์˜ ํŒŒ์ผ๋กœ ๊ฒ€์‚ฌ๋ฅผ ํ•˜๋Š” ๊ฒƒ์ด ๊ฐ€์žฅ ์•ˆ์ •์ ์ด๋ผ ์ƒ๊ฐ๋œ๋‹ค.

๋˜ํ•œ ๊ฒ€์‚ฌ ๊ฒฐ๊ณผ์— ๋ณด๋ฉด ์‚ฌ์šฉ์ž๋“ค์—๊ฒŒ ์นœ์ˆ™ํ•œ AhnLab, ALYac, AVG, Avast, ViRobot, Symantec, McAfee ๋ฐฑ์‹ ํ”„๋กœ๊ทธ๋žจ์€ ๋ฐ”์ด๋Ÿฌ์Šค๋กœ ๊ฒ€์ถœํ•ด๋‚ด์ง€ ๋ชปํ–ˆ๋‹ค. 

๋ฌด์—‡์ด ์„ฑ๋Šฅ์ด ์ข‹๋‹ค๋ผ๊ณ  ๋งํ•  ์ˆ˜ ์—†์ง€๋งŒ ์ตœ์‹  ๋ฐ”์ด๋Ÿฌ์Šค์˜ ์—…๋ฐ์ดํŠธ ์†๋„์ธ์ง€ ์˜คํƒ์ธ์ง€๋Š” ์‚ฌ์šฉ์ž์˜ ํŒ๋‹จ์— ๋งก๊ธธ ์ˆ˜ ๋ฐ–์— ์—†๋‹ค๊ณ  ์ƒ๊ฐํ•œ๋‹ค.

๊ฒ€์‚ฌ ๊ฒฐ๊ณผ ์ƒ์„ธ๋Š” ์•„๋ž˜ ๋‚ด์šฉ์ฒ˜๋Ÿผ ๋‚˜์˜จ๋‹ค.
 
Basic Properties

MD5  60dd925cf0a1ab2b398cefc9ee2213b1
SHA-1  a71f1c0987cb5392d0142ec3ca4d548a6333550b
SHA-256  65938ff340f8d274cb93f4b18320cf52097c2779aa9302303b990c5ac861958d
Vhash  038086655d15551555751az153z1hz1fz
Authentihash  4e57223f161de6e40b2eaed0830f708bba98646c0b2b8992b66b60b9f94d0354
Imphash  24504b64b274a3328adc46b4630241bb
Rich PE  header hash cf30076b572dcb317e63dfa2b9b9bc90
SSDEEP 98304: TiLyCB10MxcdtHrlei7HsNaEBOBqj90+J1sWkkjaHjTo82Pb0:TimE0Nrlx7HsgEB4qH8Wfs
TLSH  T104E8D108C63B9915EC4C893D22C542DD1AAC4FC88F63CE64EA597075F9788E83D799BC
File type  Win32 EXE
Magic  PE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrID
 - Win32 Dynamic Link Library (generic) (29.6%)
 - Win16 NE executable (generic) (22.7%)
 - Win32 Executable (generic) (20.3%)
 - OS/2 Executable (generic) (9.1%)
 - Generic Win/DOS Executable (9%)
DetectItEasy  PE32 Linker: Microsoft Linker (14.0, Visual Studio 2015 14.0*) [GUI32]
File size  304.04 MB (318805504 bytes)

History Creation
Time 2022-11-15 14:08:10 UTC
First Submission 2022-11-15 18:38:19 UTC
Last Submission 2022-11-16 14:27:58 UTC
Last Analysis 2022-11-15 18:38:19 UTC

Names
Setup.exe

Portable Executable Info
Compiler Products
- id: 203, version: 65501 count=4
- id: 257, version: 29304 count=2
- [---] Unmarked objects count=25
- id: 93, version: 4035 count=3
- id: 265, version: 24210 count=2
- id: 258, version: 24210 count=1

Header
- Target Machine Intel 386 or later processors and compatible processors
- Compilation Timestamp 2022-11-15 14:08:10 UTC
- Entry Point 4631
- Contained Sections 8

Sections
Imports
 - ntdll.dll
 - KERNEL32.dll
 - USER32.dll

Contained Resources By Typ
- RT_MANIFEST1
- RT_GROUP_ICON1
- RT_ICON1

Contained Resources By Language
- ENGLISH US 3

Contained Resources

๋Œ“๊ธ€