위협 데이터베이스 트로이 목마 트로이목마.MSIL.크립트.MDCF

트로이목마.MSIL.크립트.MDCF

Trojan.MSIL.Krypt.MDCF 는 트로이목마 범주에 속하는 악성 프로그램을 식별하는 데 사용되는 탐지 이름입니다. 이름의 "MSIL" 부분은 해당 악성 프로그램이 Microsoft의 .NET 프레임워크를 사용하여 작성되었고 Microsoft 중간 언어(MSIL)로 컴파일되었음을 나타내며, "Krypt"는 파일이 암호화, 압축 또는 기타 난독화 처리를 거쳐 보안 소프트웨어와 연구원으로부터 실제 목적을 숨기려는 시도를 나타냅니다. 일반적인 이름이나 휴리스틱 방식의 이름을 사용하는 대부분의 위협과 마찬가지로 개별 샘플의 정확한 기능은 다를 수 있지만, 일반적으로 이 탐지 이름은 백그라운드에서 조용히 악성 행위를 수행하도록 설계된 트로이목마의 전형적인 동작과 관련이 있습니다.

이 위협의 기능은 무엇인가요?

이 계열의 트로이 목마는 일반적으로 사용자를 속여 실행시키기 위해 합법적이거나 무해한 파일로 위장합니다. Trojan.MSIL.Krypt.MDCF와 같은 위협은 일단 활성화되면 추가 악성 구성 요소를 다운로드하거나, 시스템 설정을 변경하거나, 감염된 장치에서 정보를 수집하거나, 원격 공격자에게 감염된 시스템에 대한 제어 권한을 제공할 수 있습니다. 이 파일은 난독화되거나 암호화되어 있기 때문에 가능한 한 오랫동안 안티바이러스 엔진의 탐지를 피하도록 특별히 제작되는 경우가 많으며, 이를 통해 의도된 작업을 방해받지 않고 수행할 수 있습니다.

바이러스가 컴퓨터에 침투하는 일반적인 경로

이러한 유형의 트로이목마는 취약점을 직접 악용하는 방식보다는 기만적인 수단을 통해 유포되는 경우가 많습니다. 일반적인 감염 경로는 악성 이메일 첨부 파일, 비공식 또는 불법 복제 소프트웨어 출처에서 제공되는 번들 다운로드, 가짜 소프트웨어 업데이트, 감염된 이동식 드라이브, 스팸 메시지에 포함된 링크 및 해킹된 웹사이트 등이 있습니다. 사용자는 첨부 파일을 열거나, 크랙된 프로그램을 실행하거나, 문서, 이미지 또는 정식 애플리케이션 설치 프로그램처럼 보이는 파일을 다운로드하는 과정에서 자신도 모르게 트로이목마를 설치할 수 있습니다.

사용자에게 미치는 위험

이러한 트로이목마를 시스템에서 계속 활성화 상태로 두면 사용자는 심각한 위험에 노출될 수 있습니다. 특정 페이로드에 따라 개인 정보나 금융 정보 유출, 기기에 대한 무단 원격 접근, 추가 악성코드 설치, 시스템 성능 저하 또는 정상적인 컴퓨터 작동 중단으로 이어질 수 있습니다. 이 파일은 은밀하게 작동하도록 설계되었기 때문에 피해자는 즉시 이상 징후를 알아차리지 못할 수 있으며, 이로 인해 시간이 지남에 따라 피해가 누적될 수 있습니다.

감염 징후

트로이 목마는 탐지를 피하도록 설계되었지만, 특정 경고 신호를 통해 감염 여부를 알 수 있습니다. 이러한 경고 신호에는 다음과 같은 것들이 있습니다.

  • 컴퓨터가 이유 없이 느려지거나 멈추는 현상
  • 백그라운드에서 실행 중이거나 작업 관리자에 표시되는 익숙하지 않은 프로세스
  • 예기치 않은 네트워크 활동 또는 데이터 사용량 증가
  • 보안 소프트웨어가 비활성화되었거나 업데이트할 수 없음
  • 사용자 조작 없이 새롭거나 알 수 없는 파일, 바로가기 또는 프로그램이 나타남

자신을 보호하는 방법

Trojan.MSIL.Krypt.MDCF와 같은 위협으로부터 감염 위험을 줄이려면 사용자는 비공식적이거나 신뢰할 수 없는 출처에서 소프트웨어를 다운로드하지 말고, 알 수 없는 발신자가 보낸 이메일 첨부 파일과 링크에 주의하며, 운영 체제와 설치된 애플리케이션을 최신 상태로 유지해야 합니다. 평판이 좋고 최신 버전의 보안 소프트웨어를 실행하고 정기적으로 시스템 검사를 수행하면 피해를 입히기 전에 이러한 위협을 탐지하고 제거할 수 있습니다. 중요한 파일을 정기적으로 백업하는 것도 좋은 방법이며, 악성코드 감염이 발생하더라도 그 영향을 최소화할 수 있습니다.

분석 보고서

일반 정보

성씨: Trojan.MSIL.Krypt.MDCF
서명 상태: No Signature

알려진 샘플

MD5: 0c9df79ec52597b08d12c716e1e5a742
샤1: 27c801f42a2360c1a24d668e86617b50aeabafa8
샤256: AA060D25B06EDB7C3EEC0DDBADC5BD9C8E03E03099584512D587A42320D94BC0
파일 크기: 492.03 KB,492032 바이트

Windows 휴대용 실행 파일 속성

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
더 보기
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

파일 아이콘

Windows PE 버전 정보

이름 값
Assembly Version 1.0.8605.38175
Comments WindowexeRemappingKey
Company Name windowexe.com
File Description WindowexeRemappingKey
File Version 1.0.8605.38175
Internal Name WindowexeRemappingKey.exe
Legal Copyright Copyright (c) windowexe.com
Original Filename WindowexeRemappingKey.exe
Product Name WindowexeRemappingKey
Product Version 1.0.8605.38175

파일 특성

  • .NET
  • HighEntropy
  • NewLateBinding
  • x86

블록 정보

총 블록 수: 287
잠재적으로 악의적인 차단: 76
허용된 블록: 211
알 수 없는 블록: 0

시각적 지도

x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 x x 0 0 0 0
0 - 안전 블록 가능성 높음
? - 알 수 없는 블록
x - 잠재적으로 악의적인 차단

Windows API 사용법

범주 API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
더 보기
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent