| 
                          
                            | 
                                
                                  |  |  
                                  | W32/Mydoom@mm |  
                                  |  |  
                                  | ¹ÙÀÌ·¯½º Á¾·ù |  |  |  | ½ÇÇàȯ°æ 
 |  |  |  
                                  |  |  
                                  | ¹ß°ßÀÏ |  |  |  | Á¦ÀÛÁö |  |  |  
                                  |  |  
                                  | À§Çèµî±Þ |  |  |  | È®»ê¹æ¹ý |  |  |  
                                  |  |  
                                  | ¹ÙÀÌ·¯½º Å©±â |  |  |  | ÷ºÎÆÄÀÏ |  | 
                                      
                                        | 22,528 byte Å©±â·Î EXE, ZIP, PIF, SCR, BAT È®ÀåÀÚ¸¦ °¡Áö¸ç ÷ºÎµÈ ÆÄÀÏÀÇ À̸§Àº ¹«ÀÛÀ§ÀûÀÌ´Ù. |  |  
                                  |  |  
                                  | ¸ÞÀÏÁ¦¸ñ |  | 
                                      
                                        | Hello, Error, Test ¿Ü ´Ù¼ö |  |  
                                  |  |  
                                  | Áõ»ó¿ä¾à |  |  |  
                                  |  |  
                                  | Ä¡·á¹æ¹ý |  | 
                                      
                                        | Åͺ¸¹é½ÅAi, Åͺ¸¹é½Å Online, Åͺ¸¹é½Å 2001 Á¦Ç°±ºÀ¸·Î Ä¡·á°¡´É.
 
 Åͺ¸¹é½Å Ai¸¦ »ç¿ëÇÏ½Ã°í ¾Æ¿ô·èÀ» »ç¿ëÇϽŠ´Ù¸é ¹Ýµå½Ã À̸ÞÀÏ °¨½Ã±â¸¦
 ½ÇÇàÇϽñ⠹ٶø´Ï´Ù.
 
 
     |  |  
                                  |  |  |  
                            |  |  
                            | 
                                
                                  |  |  
                                  | 
                                      
                                        | ÀÌ ¿úÀº 1¿ù 26ÀÏ ¹ß°ßµÇ¾úÀ¸¸ç ±¹³»¿¡´Â 1¿ù 27ÀÏ ¿ÀÀüºÎÅÍ È®»ê µÇ±â ½ÃÀÛ ÇÏ¿´´Ù. UPX ½ÇÇà ÆÄÀÏ ¾ÐÃàµÇ ÀÖÀ¸¸ç, 2¿ù 12ÀÏ ÀÌÈÄ¿¡´Â ½ÇÇàµÇÁö ¾Êµµ·Ï ÄÚµù µÇ ÀÖ´Ù.
 ¶ÇÇÑ ÀÚü SMTP¸¦ ³»ÀåÇÏ¿© ÀÌ ¸ÞÀϰú KaZaA ¶ó´Â P2P °øÀ¯ ÇÁ·Î±×·¥À» ÅëÇØ °¨¿° µÇ¾î È®»êµÇ´Â 2°¡Áö ¹æ½ÄÀ» °¡Áø´Ù.
 
 ¸ÞÀÏÀ» ÅëÇÑ °¨¿°½Ã ´ÙÀ½ ÆÄÀÏ¿¡¼ ¸ÞÀÏ ÁÖ¼Ò¸¦ ÃßÃâ ÇÑ´Ù.
 dbx
 wab
 adb
 tbb
 asp
 php
 sht
 htm
 txt
 
 ¿úÀÌ ½ÇÇà µÇ¸é ¸Þ¸ðÀå¿¡ ±ú¾îÁø ±ÛÀÚ¸¦ Ç¥½ÃÇϸç À©µµ¿ì ½Ã½ºÅÛ Æú´õ
 (Win9x- c:\windows\system, Win2000, NT - c:\Winnt\system32, win XP - c:\windows\system32)
 ¿¡ taskmon.exe(22,528byte) , Shimgapi.dll(4,096byte)¸¦ »ý¼ºÇÑ´Ù.
 
 ´ÙÀ½À¸·Î ·¹Áö½ºÆ®¸®¸¦ Á¶ÀÛÇÏ¿© À©µµ¿ì¸¦ ½ÇÇà ÇÒ °æ¿ì ¸ÕÀú ¿úÀ» ½ÇÇà ½Ã۵µ·Ï ÇÑ´Ù.
 
 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
 Ç׸ñ¿¡
 
 win2000,nt ÀÇ °æ¿ì : TaskMon : c:\winnt\system32\taskmon.exe
 win xp ÀÇ °æ¿ì : TaskMon : c:\windows\system32\taskmon.exe
 
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrnetVersion\Run
 Ç׸ñ¿¡
 
 win2000,nt ÀÇ °æ¿ì : TaskMon : c:\winnt\system32\taskmon.exe
 win xp ÀÇ °æ¿ì : TaskMon : c:\windows\system32\taskmon.exe
 
 HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
 Ç׸ñ¿¡
 
 win2000,nt ÀÇ °æ¿ì : (Default) : C:\WINNT\System32\shimgapi.dll
 win xp ÀÇ °æ¿ì : (Default) : C:\WINNT\System32\shimgapi.dll
 
 ¶ÇÇÑ TCP 3127¹ø Æ÷Æ®¸¦ ¿ÀÇÂÇϱ⠶§¹®¿¡ ¿ÜºÎ¿¡¼ °¨¿°µÈ ½Ã½ºÅÛ¿¡ Á¢±ÙÇÒ ¼öµµ ÀÖ´Ù.
 
 
 ¸ÞÀÏÀÇ Á¦¸ñÀº ÀÏÁ¤Ä¡ ¾ÊÀ¸¸ç ´ÙÀ½ÀÇ ´ë¼Ò¹®ÀÚ ¹®Àå¿¡¼ ·£´ýÇÏ°Ô °áÁ¤µÈ´Ù.
 
 Hi
 HI
 error
 ERROR
 Test
 TEST
 Hello
 HELLO
 Mail Delivery System
 MAIL DELIVERY SYSTEM
 FW: Returned mail: see transcript for details
 
 ¸ÞÀÏ º»¹®Àº ´ÙÀ½°ú °°À¸³ª ÀÏÁ¤Ä¡ ¾ÊÀ¸¸ç ¾øÀ» ¼öµµ ÀÖ´Ù
 
 The message contains Unicode characters and has been sent as a binary attachment.
 
 The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
 
 Mail transaction failed. Partial message is available.
 
 test
 
 ÷ºÎµÈ ÆÄÀÏÀÇ À̸§Àº ¹«ÀÛÀ§ÀûÀÌ¸ç ´ÙÀ½ ó·³ EXE, ZIP, PIF, SCR, BAT È®ÀåÀÚ¸¦ °¡Áø´Ù.
 
 ¿¹¸¦ µé¸é
 ancd.zip
 aqmd.zip
 body.scr
 doc.zip
 document.zip
 document.pif
 message.zip
 test.zip
 text.scr ¿Í °°Àº ÇüÅÂÀÌ´Ù.
 |  |  
                                  |  |  |  
                            |  |  
                            |  |  
                            |  |  
                            | 
                                
                                  | 
                                      
                                        | ¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö |  
                                        | ¿¡ºê¸®Á¸¿¡¼ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù. ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
 À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
 * ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
 |  |  |  
                            |  |  |