위협 데이터베이스 바이러스 바이러스.와포미.B

바이러스.와포미.B

Virus.Wapomi.B는 악성 소프트웨어의 바이러스 범주에 속하는 것으로 분류됩니다. 이 범주에 속하는 많은 위협 요소와 마찬가지로, Virus.Wapomi.B는 컴퓨터의 파일을 감염시키고 사용자의 인지나 동의 없이 다른 시스템으로 확산되도록 설계되었습니다. 이 특정 변종에 대한 자세한 기술적 사양은 아직 확인되지 않았으므로, 다음 설명은 Virus.Wapomi.B가 공유하는 것으로 추정되는 파일 감염 바이러스 및 웜 유형의 일반적인 동작을 반영합니다.

이 위협의 기능은 무엇인가요?

Virus.Wapomi.B와 같이 바이러스 범주로 분류되는 위협은 일반적으로 감염된 컴퓨터에 저장된 실행 파일이나 기타 정상 프로그램에 악성 코드를 첨부하는 방식으로 작동합니다. 파일이 감염되면 해당 파일을 실행하여 바이러스가 활성화되고 시스템 전체로 확산되어 연결된 다른 장치나 드라이브로 전파될 수 있습니다. 이러한 유형의 바이러스는 일반적으로 스스로 복제하여 가능한 한 많은 파일을 감염시키려고 시도하므로 감염 기간이 길어질수록 완전히 제거하기가 더 어려워집니다.

많은 경우, 이러한 위협은 추가적인 악성 페이로드를 전달하는 수단으로도 사용됩니다. 여기에는 감염된 컴퓨터에 원치 않거나 유해한 프로그램을 다운로드하거나 설치하는 것이 포함될 수 있으며, 이는 초기 감염 범위를 넘어 피해 범위를 확대할 수 있습니다.

바이러스가 컴퓨터에 침투하는 일반적인 경로

이 범주의 바이러스는 일반적으로 USB 플래시 드라이브, 외장 하드 디스크 또는 공유 네트워크 드라이브와 같은 감염된 이동식 저장 매체를 통해 확산됩니다. 또한 불법 복제 소프트웨어, 크랙된 프로그램 설치 파일 또는 P2P 네트워크에서 공유되는 파일을 통해서도 유포될 수 있습니다. 이메일 첨부 파일, 신뢰할 수 없는 웹사이트에서 다운로드하는 악성 파일, 다른 소프트웨어와의 번들링 또한 이러한 유형의 위협에 대한 일반적인 감염 경로가 될 수 있습니다. Virus.Wapomi.B의 정확한 유포 방식은 아직 확인되지 않았으므로 사용자는 이러한 일반적인 감염 경로 모두에 주의해야 합니다.

사용자에게 미치는 위험

이러한 유형의 감염은 감염된 컴퓨터와 사용자에게 여러 가지 위험을 초래할 수 있습니다. 시스템 성능 저하, 불안정성, 손상된 파일로 인한 시스템 충돌 등이 그 예입니다. 이러한 바이러스는 다른 파일이나 드라이브로 확산되는 경우가 많으므로, 감염을 신속하게 해결하지 않으면 시스템이나 네트워크 전체에 광범위한 손상을 초래할 위험이 있습니다. 또한, 이러한 위협은 추가적인 악성 소프트웨어를 유포하는 데 사용될 수 있으므로, 사용자는 데이터 도난, 무단 접근, 바이러스가 전달하는 악성 코드로 인한 추가 감염과 같은 2차적인 위험에 직면할 수 있습니다.

감염 징후

이러한 유형의 바이러스에 감염된 경우 사용자는 몇 가지 경고 신호를 발견할 수 있습니다. 예를 들어, 예기치 않은 속도 저하, 프로그램 실행 실패 또는 예기치 않은 충돌, 시스템에 알 수 없는 파일 출현, 명확한 원인 없이 디스크 또는 네트워크 활동 증가 등이 있습니다. 보안 소프트웨어는 의심스러운 파일을 감염된 것으로 표시하거나 자동으로 격리할 수도 있습니다. 시스템 동작에 설명할 수 없는 변화가 나타나면 감염 가능성을 염두에 두어야 합니다.

자신을 보호하는 방법

Virus.Wapomi.B 및 유사 위협으로부터 감염 위험을 줄이려면 사용자는 신뢰할 수 없거나 비공식적인 출처에서 소프트웨어를 다운로드하지 말고, 출처를 알 수 없는 이동식 저장 장치를 사용할 때 주의해야 합니다. 운영 체제와 설치된 소프트웨어를 최신 상태로 유지하면 악성 프로그램이 악용할 수 있는 보안 취약점을 차단하는 데 도움이 됩니다. 최신 보안 도구를 사용하여 시스템을 정기적으로 검사하고, 의심스러운 이메일 첨부 파일을 피하고, 중요한 파일을 백업하면 잠재적인 감염의 영향을 최소화하고 감염 발생 시 더 빠른 복구를 지원할 수 있습니다.

분석 보고서

일반 정보

성씨: Virus.Wapomi.B
패커스: ASPack v2.12
서명 상태: No Signature

알려진 샘플

MD5: 1aa4c64363b68622c9426ce96c4186f2
샤1: 6d30a08e63beec01478959d96a792d43bf03fb23
샤256: 7936DEB5E6A236E8DCE91352D0617E3DB3BBE0FBAEBA5FB08BBEAC7590338C4D
파일 크기: 89.60 KB,89600 바이트

Windows 휴대용 실행 파일 속성

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

파일 특성

  • .adata
  • .aspack
  • 2+ executable sections
  • ASPack v2.12
  • HighEntropy
  • No Version Info
  • packed
  • upx
  • x86

블록 정보

총 블록 수: 388
잠재적으로 악의적인 차단: 134
허용된 블록: 45
알 수 없는 블록: 209

시각적 지도

? x x x x x 0 x x x x x ? x x 0 x x ? ? x x x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? x x ? x x x ? 0 ? x x x ? x ? ? x ? 0 x ? ? x ? ? x ? ? ? ? ? ? ? 0 x x 0 x x ? x ? x ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? ? 0 ? ? ? x ? x ? ? x x 0 x x x ? ? ? ? ? ? ? ? ? ? ? x x x x x x x x ? x x 0 x ? ? x x x x 0 x x ? 0 x ? 0 ? x ? x x x x x x x ? ? x x x x x ? x x ? ? ? x 0 x ? ? 0 ? ? ? 0 0 x ? 0 ? ? 0 0 x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? x ? x x ? x x x x x x ? ? x ? x 0 x x ? ? 0 x x x 0 0 x x x ? x ? ? x ? x ? x x x x x ? x x x x x x x x x 0 x 0 ? x ? x 0 0 x 0 x x x x x 0 ? ? ? ? ? x x 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? x ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? 0 ? ? ? ? ? ? 0 ? ?
0 - 안전 블록 가능성 높음
? - 알 수 없는 블록
x - 잠재적으로 악의적인 차단

수정된 파일

파일 속성
\device\namedpipe\{d952f2d0-0bce-4b2b-8fff-2317f120fcc3} Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\infotmp.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\2dec7a46.log Generic Write,Read Attributes
c:\windows\syswow64\2dec12c8.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\appmgmt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\bits.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\certpropsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\fastuserswitchingcompatibility.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\gpsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\helpsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
더 보기
c:\windows\syswow64\ias.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\iphlpsvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\irmon.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\lanmanserver.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\logonhours.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\msiscsi.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\nla.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\ntmssvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\nwcworkstation.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\nwsapagent.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\pcaudit.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\rasauto.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\rasman.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\remoteaccess.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\schedule.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\scpolicysvc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\sens.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\sessionenv.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\sharedaccess.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\shellhwdetection.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\srservice.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\tapisrv.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\tokenbroker.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\uploadmgr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\usermanager.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\winmgmt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\wmdmpmsp.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\wmi.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\wuauserv.dll Generic Read,Write Data,Write Attributes,Write extended,Append data

레지스트리 수정

키::값 데이터 API 이름
HKLM\system\controlset001\control\keyboard layouts\e0010409::layout file KBDUS.DLL RegNtPreCreateKey
HKLM\system\controlset001\control\keyboard layouts\e0010409::layout text +�Y� RegNtPreCreateKey
HKLM\system\controlset001\services\certpropsvc\parameters::servicedll C:\WINDOWS\system32\CertPropSvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\scpolicysvc\parameters::servicedll C:\WINDOWS\system32\SCPolicySvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\lanmanserver\parameters::servicedll C:\WINDOWS\system32\lanmanserver.dll RegNtPreCreateKey
HKLM\system\controlset001\services\gpsvc\parameters::servicedll C:\WINDOWS\system32\gpsvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\iphlpsvc\parameters::servicedll C:\WINDOWS\system32\iphlpsvc.dll RegNtPreCreateKey
HKLM\system\controlset001\services\msiscsi\parameters::servicedll C:\WINDOWS\system32\msiscsi.dll RegNtPreCreateKey
HKLM\system\controlset001\services\schedule\parameters::servicedll C:\WINDOWS\system32\schedule.dll RegNtPreCreateKey
HKLM\system\controlset001\services\winmgmt\parameters::servicedll C:\WINDOWS\system32\winmgmt.dll RegNtPreCreateKey
더 보기
HKLM\system\controlset001\services\sessionenv\parameters::servicedll C:\WINDOWS\system32\SessionEnv.dll RegNtPreCreateKey
HKLM\system\controlset001\services\tokenbroker\parameters::servicedll C:\WINDOWS\system32\TokenBroker.dll RegNtPreCreateKey
HKLM\system\controlset001\services\usermanager\parameters::servicedll C:\WINDOWS\system32\UserManager.dll RegNtPreCreateKey
HKLM\system\controlset001\services\rasauto\parameters::servicedll C:\WINDOWS\system32\Rasauto.dll RegNtPreCreateKey
HKLM\system\controlset001\services\rasman\parameters::servicedll C:\WINDOWS\system32\Rasman.dll RegNtPreCreateKey
HKLM\system\controlset001\services\remoteaccess\parameters::servicedll C:\WINDOWS\system32\Remoteaccess.dll RegNtPreCreateKey
HKLM\system\controlset001\services\sens\parameters::servicedll C:\WINDOWS\system32\SENS.dll RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters::servicedll C:\WINDOWS\system32\Sharedaccess.dll RegNtPreCreateKey
HKLM\system\controlset001\services\tapisrv\parameters::servicedll C:\WINDOWS\system32\Tapisrv.dll RegNtPreCreateKey
HKLM\system\controlset001\services\wuauserv\parameters::servicedll C:\WINDOWS\system32\wuauserv.dll RegNtPreCreateKey
HKLM\system\controlset001\services\bits\parameters::servicedll C:\WINDOWS\system32\BITS.dll RegNtPreCreateKey
HKLM\system\controlset001\services\shellhwdetection\parameters::servicedll C:\WINDOWS\system32\ShellHWDetection.dll RegNtPreCreateKey
HKLM\system\controlset001\services\appmgmt\parameters::servicedll C:\WINDOWS\system32\AppMgmt.dll RegNtPreCreateKey

Windows API 사용법

범주 API
Service Control
  • OpenSCManager
  • StartService