๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๐Ÿšจ ์ •๋ณด ๋ณด์•ˆ9

Naver ํ”ผ์‹ฑ ํŽ˜์ด์ง€ URL์„ ํฌํ•จํ•œ ์ŠคํŒธ๋ฉ”์ผ ์œ ํฌ Naver ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€๋ฅผ ์‚ฌ์นญํ•œ ํ”ผ์‹ฑ ํŽ˜์ด์ง€๋ฅผ ํ™•์ธ ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ŠคํŒธ๋ฉ”์ผ์— URL ์„ ์ ‘์†ํ•˜๋„๋ก ํฌํ•จํ•˜์—ฌ ๋ฐœ์†ก ํ•˜์˜€๊ณ  ๋ฐœ์‹ ์ž ์ฃผ์†Œ๋Š” NAVER๋กœ ๋ณ€์กฐํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ์ฃผ์†Œ๋ฅผ ์ฃผ์˜ ๊นŠ๊ฒŒ ๋ณธ๋‹ค๋ฉด ํ”ผ์‹ฑ์ธ๊ฑธ ์•Œ ์ˆ˜ ์žˆ์„ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. IOC ์นจํ•ด์ง€ํ‘œ URL : naver-corpid432bajsd.weihnachts-backstube[.]de IP : 81.169.145.66 "๋„ค์ด๋ฒ„ ์•„์ด๋”” ๋ณดํ˜ธ์กฐ์น˜ ํ•ด์ œ"๋กœ ์œ„์žฅํ•œ ํ”ผ์‹ฑ๋ฉ”์ผ ์œ ํฌ ์ฃผ์˜! ์•ˆ๋…•ํ•˜์„ธ์š”? ์ด์ŠคํŠธ์‹œํ๋ฆฌํ‹ฐ ์‹œํ๋ฆฌํ‹ฐ๋Œ€์‘์„ผํ„ฐ(์ดํ•˜ ESRC)์ž…๋‹ˆ๋‹ค. ๊ตญ๋‚ด ํฌํ„ธ์‚ฌ์ดํŠธ ๋„ค์ด๋ฒ„์˜ ์•„์ด๋”” ๋ณดํ˜ธ์กฐ์น˜๊ฐ€ ์‹ค์‹œ๋˜์—ˆ๋‹ค๋Š” ๋‚ด์šฉ์˜ ํ”ผ์‹ฑ ๊ณต๊ฒฉ์ด ๋‹ค์ˆ˜ ๋ฐœ๊ฒฌ๋˜์–ด ์‚ฌ์šฉ์ž๋“ค์˜ ์ฃผ์˜๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค blog.alyac.co.kr 2022. 10. 29.
[News] "๋‚ด PC ๋Œ๋ณด๋ฏธ"๋กœ ์œ„์žฅํ•œ ์•…์„ฑ์ฝ”๋“œ ์นด์นด์˜ค ์„œ๋น„์Šค ์žฅ์•  ์‚ฌ๊ฑด ์ดํ›„ ์ŠคํŒธ๋ฉ”์ผ์œผ๋กœ "๋‚ด PC ๋Œ๋ณด๋ฏธ" ๋กœ ์œ„์žฅํ•œ ์•…์„ฑํŒŒ์ผ์„ ์ฒจ๋ถ€ํ•˜์—ฌ ์œ ํฌํ•˜๊ณ  ์žˆ๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. IOC URL : kisa-down[.]com/mypc_care.zip ๅŒ— ํ•ด์ปค, ์นด์นด์˜ค ์‚ฌํƒœ ์•…์šฉโ€ฆ'๋‚ดPC ๋Œ๋ณด๋ฏธ' ์œ„์žฅ [๋ฐ์ดํ„ฐ๋ง] ์ตœ๊ทผ '์นด์นด์˜ค ๋จนํ†ต ์‚ฌํƒœ'๋ฅผ ์•…์šฉํ•œ ํ”ผ์‹ฑ ๋ฉ”์ผ์ด ์œ ํฌ๋˜๊ณ  ์žˆ๋Š” ๊ฐ€์šด๋ฐ ์นด์นด์˜คํ†ก ์„ค์น˜ํŒŒ์ผ์— ์ด์–ด ๋ณด์•ˆ ์ ๊ฒ€ ์„œ๋น„์Šค๋กœ ์œ„์žฅํ•œ ์•…์„ฑ์ฝ”๋“œ๊ฐ€ ๋ฐœ๊ฒฌ๋ผ ์ฃผ์˜๊ฐ€ ์š”๊ตฌ๋œ๋‹ค. 21์ผ ๋ณด์•ˆ์—…๊ณ„์— ๋”ฐ๋ฅด๋ฉด ์ง€๋‚œ 2 n.news.naver.com 2022. 10. 23.
[์„œ๋น„์Šค ์†Œ๊ฐœ] OSINT Open Source + Intelligence ๋ž€? OSINT(Open Source Intelligence)๋Š” ๊ณต๊ฐœ๋œ ์ถœ์ฒ˜๋ผ๋Š” ์˜๋ฏธ๋กœ Open Source์™€ ๊ตฐ(Military)์—์„œ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•˜๋Š” ์ฒฉ๋ณดํ™œ๋™์—์„œ ์œ ๋ž˜๋œ Intelligence๊ฐ€ ํ•ฉ์ณ์ ธ ํƒ„์ƒํ•œ ์šฉ์–ด ์ถœ์ฒ˜ : https://www.kisec.com/rsrh_rpt_det.do?id=163 ๊ฐ„๋‹จํ•˜๊ฒŒ๋Š” ์˜จ๋ผ์ธ ์ƒ์— ๋„๋ฆฌ ํผ์ ธ ์žˆ๋Š” ๊ฐ์ข… ์ •๋ณด๋“ค์„ ํ•œ ๊ณณ์— ๋ชจ์•„์„œ ๋ณผ ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ์—ญํ• ์„ ํ•˜๋Š” ๊ฒƒ ๊ฐ™๋‹ค 1. Shodan Shodan Search engine of Internet-connected devices. Create a free account to get started. www.shodan.io 2. Criminal IP Cybersecu.. 2022. 9. 3.
[News] '๋ ˆ๋นŒ' ์‹ฌ์ƒ์น˜ ์•Š๋‹ค…๋‹คํฌ์›น์„œ ้Ÿ“ ๊ธฐ์—…๋ฐ์ดํ„ฐ ํƒˆ์ทจ '์ฃผ์žฅ' '๋ ˆ๋นŒ' ์‹ฌ์ƒ์น˜ ์•Š๋‹คโ€ฆ๋‹คํฌ์›น์„œ ้Ÿ“ ๊ธฐ์—…๋ฐ์ดํ„ฐ ํƒˆ์ทจ '์ฃผ์žฅ' [๋ฐ์ดํ„ฐ๋ง] ์ง€๋‚œํ•ด 7์›” ์นด์„ธ์•ผ(Kaseya) ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ์œผ๋กœ ์ „ ์„ธ๊ณ„๋ฅผ ๊ณตํฌ์— ๋ชฐ์•„๋„ฃ์—ˆ๋˜ '๋ ˆ๋นŒ(REvil)'์€ ๋ฏธ๊ตญ ์ •๋ถ€์˜ ์••๋ ฅ๊ณผ ๊ตญ์ œ ๊ณต์กฐ ์ˆ˜์‚ฌ๋กœ ์‚ฌ์‹ค์ƒ ํ•ด์ฒด๋œ ๊ฒƒ์œผ๋กœ ์•Œ๋ ค์กŒ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์˜ฌํ•ด 5์›” ๋ ˆ๋นŒ์˜ ๋‹คํฌ์›น ์‚ฌ n.news.naver.com 2022. 8. 13.
[๊ทธ๊ฒƒ์ด ์•Œ๊ณ  ์‹ถ๋‹ค] ๋ถํ•œ ํ•ด์ปค ํŽธ ๅŒ—ํ•ด์ปค, SNSยท๋น„ํŠธ์ฝ”์ธ์œผ๋กœ ์žฅ๊ต ๋งค์ˆ˜โ€ฆ'์ „์žฅ๋ง' ํ†ต์งธ๋กœ ๋šซ๋ฆด๋ป”(์ข…ํ•ฉ) | ์—ฐํ•ฉ๋‰ด์Šค (์„œ์šธ=์—ฐํ•ฉ๋‰ด์Šค) ์ด์ •ํ˜„ ์ •๋น›๋‚˜ ๊ธฐ์ž = ๋ถํ•œ ํ•ด์ปค(๊ณต์ž‘์›)๊ฐ€ ๊ฐ€์ƒํ™”ํ๋ฅผ ๋Œ€๊ฐ€๋กœ ํ˜„์—ญ ์žฅ๊ต๋ฅผ ํฌ์„ญํ•ด ๊ตฐ์‚ฌ๊ธฐ๋ฐ€์„ ๋นผ๋‚ด๊ณ  ์ „์žฅ๋ง ํ•ดํ‚น๊นŒ์ง€ ์‹œ๋„ํ•œ ์‚ฌ... www.yna.co.kr ์ด๋ฒˆ์— ์ด์Šˆ๊ฐ€ ๋˜์—ˆ๋˜ ๋‚ด์šฉ์ด๋‹ค. ๊ฐ€์ƒํ™”ํ๋ฅผ ๋Œ€๊ฐ€๋กœ ํ˜„์—ญ ์žฅ๊ต๋ฅผ ํฌ์„ญํ•ด ๊ตฐ์‚ฌ ๊ธฐ๋ฐ€์„ ํƒˆ์ทจ ํ•˜๊ณ ์ž ํ–ˆ์—ˆ๊ณ  ๊ทธ ๋ฐฐํ›„์—๋Š” ๋ถํ•œ ํ•ด์ปค๊ฐ€ ์žˆ๋‹ค๋Š” ๋‚ด์šฉ์ด๋‹ค. ์ธํ„ฐ๋„ท ๋ณด๊ธ‰์œจ์ด ๋†’์•„์ง€๋Š” ๋งŒํผ ๋” ๋งŽ์€ ์œ„ํ˜‘์— ๋…ธ์ถœ๋˜๊ณ  ์žˆ๋Š” ๊ฒƒ ๊ฐ™๋‹ค.. 2022. 7. 10.
[์„œ๋น„์Šค ์†Œ๊ฐœ] IP ์™ธ๋ถ€ ํ‰ํŒ ์กฐํšŒ - IBM X-Force Exchange ์˜ค๋Š˜ ํฌ์ŠคํŒ…ํ•˜๋Š” ์‚ฌ์ดํŠธ๋Š” IP ํ‰ํŒ ์กฐํšŒ๋ฅผ ํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์ดํŠธ์ž…๋‹ˆ๋‹ค. IP ์™ธ์—๋„ ๋‹ค๋ฅธ IOC ์ •๋ณด๋“ค์ด ๋งŽ์ด ๋“ฑ๋ก๋˜์–ด ์žˆ๊ณ  ์‚ฌ์šฉ ๋ฐฉ๋ฒ•์€ ์•„๋ž˜ ํŽ˜์ด์ง€ ์ ‘์† ํ›„ ๊ฒ€์ƒ‰์ฐฝ์— ๋„๋ฉ”์ธ, IP ์ •๋ณด๋ฅผ ์ ๊ณ  ๊ฒ€์ƒ‰ํ•˜๋ฉด ๊ทธ์— ๋Œ€ํ•œ ํ‰ํŒ ์ •๋ณด๋ฅผ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 1. IBM ํ™ˆํŽ˜์ด์ง€ https://exchange.xforce.ibmcloud.com/ IBM X-Force Exchange IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers exchange.xforce.ibmcloud.com.. 2022. 6. 17.
์ŠคํŒŒ์ด๋”๋งจ-๋…ธ์›จ์ดํ™ˆ ๋‹ค์šด๋กœ๋“œ๋ฅผ ์‚ฌ์นญํ•œ ์•…์„ฑ ํŒŒ์ผ ์•ˆ๋…•ํ•˜์„ธ์š”! ์ €๋ฒˆ์ฃผ ์ŠคํŒŒ์ด๋”๋งจ - ๋…ธ์›จ์ด ํ™ˆ์ด ๊ฐœ๋ด‰ ํ–ˆ๋Š”๋ฐ์š”, ๋‹ค๋“ค ๋ณด์…จ๋‚˜์š”?? ์ธ๊ธฐ๊ฐ€ ์ƒ๋‹นํ•œ ๋งŒํผ ์ด๋ฅผ ์ด์šฉํ•ด์„œ ๋‹ค์šด๋กœ๋“œ(torrent) ํŒŒ์ผ์„ ์ด์šฉํ•ด ์•…์„ฑ ์„ ์ „ํŒŒ์‹œํ‚ค๊ณ  ์žˆ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ์›๋ณธ ํŒŒ์ผ๋ช…(๋Ÿฌ์‹œ์•„์–ด) : spiderman_net_putidomoi.torrent.exe Torrent์— ํ‘œ์‹œ๋˜๋Š” ํŒŒ์ผ๋ช… : spiderman_no_wayhome.torrent.exe ์•…์„ฑ์ฝ”๋“œ ๋ช… : Cryptominer -> ํ”ผํ•ด์ž ๊ธฐ๊ธฐ์˜ ์ฒ˜๋ฆฌ ๋Šฅ๋ ฅ์„ ๊ฐ€๋กœ์ฑ„ ์ด๋ฅผ ์ด์šฉํ•ด ๊ฐ€์ƒํ™”ํ๋ฅผ ์ฑ„๊ตดํ•˜๋„๋ก ์„ค๊ณ„๋œ ์•…์„ฑ ํŒŒ์ผ ๋ฐฑ๊ทธ๋ผ์šด๋“œ์—์„œ ์‹คํ–‰๋˜๋ฉฐ ์‚ฌ์šฉ์ž ๋ชจ๋ฅด๊ฒŒ ๊ณ„์† PC์˜ ์ž์›์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. https://threatpost.com/spider-man-no-way-home-download-installs-cryptominer/1.. 2021. 12. 29.