위협 데이터베이스 트로이 목마 트로이목마.크립틱.Gen.GCC

트로이목마.크립틱.Gen.GCC

Trojan.Kryptik.Gen.GCC 는 "Kryptik" 계열 트로이목마에 속하는 악성 프로그램을 식별하는 데 사용되는 탐지 이름입니다. "Kryptik"이라는 명칭은 일반적으로 보안 스캐너로부터 실제 코드와 목적을 숨기기 위해 난독화 또는 패킹 기법을 사용하는 위협에 적용됩니다. 이 특정 탐지에 대한 자세한 기술적 정보는 제공되지 않으므로, 아래 정보는 이 위협이 공유할 가능성이 높은 해당 범주의 트로이목마의 일반적인 동작을 설명합니다.

이 위협의 기능은 무엇인가요?

대부분의 트로이목마처럼 Trojan.Kryptik.Gen.GCC는 악성 프로그램으로 위장하여 백그라운드에서 악의적인 행위를 수행하도록 설계되었습니다. 일반적으로 Kryptik 계열 트로이목마는 추가 악성코드를 배포하거나, 민감한 정보를 탈취하거나, 공격자가 감염된 시스템에 원격으로 접근하거나, 사용자의 동의 없이 시스템 설정을 변경하는 데 사용될 수 있습니다. "Kryptik"이라는 명명 규칙은 흔히 일반적이고, 심하게 난독화되었거나, 압축된 악성코드를 지칭하기 때문에 정확한 페이로드는 감염 사례마다 다를 수 있으며, 운영자가 악성코드를 업데이트함에 따라 시간이 지남에 따라 변경될 수도 있습니다.

일반적으로 이 범주의 트로이 목마는 탐지를 피하고 백그라운드에서 조용히 실행되며, 컴퓨터를 재시작한 후에도 계속 실행되도록 지속성을 유지하려고 시도할 수 있습니다. 일부 변종은 제거를 피하기 위해 보안 소프트웨어를 비활성화하거나 방해하기도 합니다.

바이러스가 컴퓨터에 침투하는 일반적인 경로

이러한 유형의 트로이 목마는 일반적으로 다음과 같은 일반적인 감염 경로를 통해 확산됩니다.

  • 청구서, 영수증 또는 기타 합법적으로 보이는 문서로 위장한 악성 이메일 첨부 파일 또는 링크
  • 가짜 소프트웨어 업데이트 또는 불법 복제/불법 복제 소프트웨어 다운로드
  • 신뢰할 수 없는 다운로드 사이트에서 제공되는 번들 설치 프로그램
  • 자동 다운로드를 유발하는 해킹당했거나 악의적인 웹사이트
  • 감염된 이동식 드라이브(예: USB 스틱)

사용자들은 종종 예상치 못한 첨부 파일을 열거나, 사기성 링크를 클릭하거나, 비공식 출처에서 소프트웨어를 다운로드하는 과정에서 자신도 모르게 이러한 트로이 목마를 설치하게 됩니다.

사용자에게 미치는 위험

이러한 트로이목마가 시스템에 남아 있을 경우 사용자는 다음과 같은 여러 위험에 노출될 수 있습니다.

  • 개인 정보, 금융 정보 또는 로그인 정보 도용
  • 감염된 기기에 대한 무단 원격 접근
  • 랜섬웨어 또는 스파이웨어와 같은 추가 악성 프로그램 설치
  • 백그라운드 악성 활동으로 인해 시스템 성능이 저하되었습니다.
  • 보안 설정이 손상되어 기기가 향후 공격에 더욱 취약해졌습니다.

감염 징후

트로이 목마는 은밀하게 작동하도록 설계되었기 때문에 눈에 띄는 증상이 거의 없거나 전혀 없을 수 있습니다. 그러나 다음과 같은 징후가 있을 수 있습니다.

  • 컴퓨터 속도가 이유 없이 느려지거나 멈추는 현상
  • 비정상적인 네트워크 활동 또는 데이터 사용량 증가
  • 보안 소프트웨어가 비활성화되었거나 업데이트할 수 없음
  • 예기치 않은 팝업 창, 새로운 툴바 또는 브라우저 설정 변경
  • 사용자가 모르는 사이에 실행 중인 알 수 없는 프로그램이나 프로세스

자신을 보호하는 방법

이와 같은 트로이목마 감염 위험을 줄이려면 사용자는 다음 사항을 고려해야 합니다.

  • 알 수 없거나 예상치 못한 발신자로부터 온 이메일 첨부 파일을 열거나 링크를 클릭하지 마십시오.
  • 공식 또는 검증된 출처에서만 소프트웨어를 다운로드하십시오.
  • 운영 체제와 설치된 애플리케이션을 보안 패치로 최신 상태로 유지하십시오.
  • 신뢰할 수 있는 보안 소프트웨어를 사용하고 최신 상태로 유지하여 진화하는 위협을 감지할 수 있도록 하십시오.
  • 중요 파일은 정기적으로 별도의 안전한 장소에 백업하십시오.
  • 무료 다운로드, 불법 복제 소프트웨어, 의심스러운 팝업 광고에 주의하세요.
  • Trojan.Kryptik.Gen.GCC와 같은 탐지는 종종 일반적이며 다양한 악성 행위를 나타낼 수 있으므로 이러한 탐지를 심각하게 받아들이고 위협을 제거하고 영향을 받는 시스템을 보호하기 위해 신속하게 조치를 취하는 것이 중요합니다.

    분석 보고서

    일반 정보

    성씨: Trojan.Kryptik.Gen.GCC
    서명 상태: No Signature

    알려진 샘플

    MD5: 048b233ca361b30f703945dd913d94f7
    샤1: eb127ff64e7eba31401238e72d42ed094e02aafa
    샤256: 858F5A4C68C0BA31BAFCF4C7F43CDF5C037628DD6D4E612328BA1F9ADDF51612
    파일 크기: 411.23 KB,411228 바이트

    Windows 휴대용 실행 파일 속성

    • File doesn't have "Rich" header
    • File doesn't have debug information
    • File doesn't have exports table
    • File doesn't have security information
    • File has TLS information
    • File is 64-bit executable
    • File is either console or GUI application
    • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
    • File is Native application (NOT .NET application)
    • File is not packed
    더 보기
    • IMAGE_FILE_DLL is not set inside PE header (Executable)
    • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

    파일 특성

    • big overlay
    • HighEntropy
    • No Version Info
    • x64

    블록 정보

    총 블록 수: 58
    잠재적으로 악의적인 차단: 1
    허용된 블록: 55
    알 수 없는 블록: 2

    시각적 지도

    0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
    0 - 안전 블록 가능성 높음
    ? - 알 수 없는 블록
    x - 잠재적으로 악의적인 차단

    비슷한 가족

    • Trojan.Agent.Gen.GDO
    • Trojan.Downloader.Gen.ATQ
    • Trojan.Kryptik.Gen.GCC
    • Trojan.Kryptik.Gen.IUR
    • Trojan.Kryptik.Gen.IZT
    더 보기
    • Trojan.Kryptik.Gen.JAX

    수정된 파일

    파일 속성
    c:\users\user\appdata\local\temp\tmp7d62.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
    c:\users\user\downloads\amsi.dll Generic Write,Read Attributes
    c:\users\user\downloads\pkr0hs21.dll Generic Write,Read Attributes

    Windows API 사용법

    범주 API
    Syscall Use
    • ntdll.dll!NtAllocateLocallyUniqueId
    • ntdll.dll!NtAlpcSendWaitReceivePort
    • ntdll.dll!NtApphelpCacheControl
    • ntdll.dll!NtClearEvent
    • ntdll.dll!NtClose
    • ntdll.dll!NtCreateEvent
    • ntdll.dll!NtCreateMutant
    • ntdll.dll!NtCreatePrivateNamespace
    • ntdll.dll!NtCreateSection
    • ntdll.dll!NtCreateSemaphore
    더 보기
    • ntdll.dll!NtCreateThreadEx
    • ntdll.dll!NtDelayExecution
    • ntdll.dll!NtDeviceIoControlFile
    • ntdll.dll!NtDuplicateObject
    • ntdll.dll!NtEnumerateKey
    • ntdll.dll!NtEnumerateValueKey
    • ntdll.dll!NtFreeVirtualMemory
    • ntdll.dll!NtMapViewOfSection
    • ntdll.dll!NtOpenDirectoryObject
    • ntdll.dll!NtOpenEvent
    • ntdll.dll!NtOpenFile
    • ntdll.dll!NtOpenKey
    • ntdll.dll!NtOpenKeyEx
    • ntdll.dll!NtOpenProcess
    • ntdll.dll!NtOpenProcessToken
    • ntdll.dll!NtOpenSection
    • ntdll.dll!NtOpenThreadToken
    • ntdll.dll!NtProtectVirtualMemory
    • ntdll.dll!NtQueryAttributesFile
    • ntdll.dll!NtQueryDirectoryFileEx
    • ntdll.dll!NtQueryFullAttributesFile
    • ntdll.dll!NtQueryInformationFile
    • ntdll.dll!NtQueryInformationJobObject
    • ntdll.dll!NtQueryInformationProcess
    • ntdll.dll!NtQueryInformationThread
    • ntdll.dll!NtQueryInformationToken
    • ntdll.dll!NtQueryKey
    • ntdll.dll!NtQueryLicenseValue
    • ntdll.dll!NtQueryObject
    • ntdll.dll!NtQueryPerformanceCounter
    • ntdll.dll!NtQuerySecurityAttributesToken
    • ntdll.dll!NtQuerySecurityObject
    • ntdll.dll!NtQuerySystemInformation
    • ntdll.dll!NtQuerySystemInformationEx
    • ntdll.dll!NtQueryValueKey
    • ntdll.dll!NtQueryVirtualMemory
    • ntdll.dll!NtQueryVolumeInformationFile
    • ntdll.dll!NtQueryWnfStateData
    • ntdll.dll!NtReadFile
    • ntdll.dll!NtReadRequestData
    • ntdll.dll!NtReleaseMutant
    • ntdll.dll!NtReleaseWorkerFactoryWorker
    • ntdll.dll!NtResumeThread
    • ntdll.dll!NtSetEvent
    • ntdll.dll!NtSetInformationKey
    • ntdll.dll!NtSetInformationObject
    • ntdll.dll!NtSetInformationProcess
    • ntdll.dll!NtSetInformationThread
    • ntdll.dll!NtSetInformationVirtualMemory
    • ntdll.dll!NtSetInformationWorkerFactory
    • ntdll.dll!NtTestAlert
    • ntdll.dll!NtTraceControl
    • ntdll.dll!NtUnmapViewOfSection
    • ntdll.dll!NtUnmapViewOfSectionEx
    • ntdll.dll!NtWaitForMultipleObjects
    • ntdll.dll!NtWaitForSingleObject
    • ntdll.dll!NtWaitForWorkViaWorkerFactory
    • ntdll.dll!NtWaitLowEventPair
    • ntdll.dll!NtWorkerFactoryWorkerReady
    • ntdll.dll!NtWriteFile
    • ntdll.dll!NtYieldExecution
    • UNKNOWN
    User Data Access
    • GetUserDefaultLocaleName
    • GetUserObjectInformation
    Encryption Used
    • BCryptOpenAlgorithmProvider
    Anti Debug
    • IsDebuggerPresent
    • NtQuerySystemInformation