[ÄÄÇ»ÅÍ/ÀÎÅͳÝ]

ÆÄÀ̽㠳»¿ë Çѹø¸¸ Çؼ®ÇØÁÖ¼¼¿µ

rank ±òºÀ 2019-02-22 (±Ý) 14:03 Á¶È¸ : 619
# Copyright (C) 2010-2015 Cuckoo Foundation. 2016 Brad Spengler
# This file is part of Cuckoo Sandbox - http://www.cuckoosandbox.org
# See the file 'docs/LICENSE' for copying permission.

from lib.cuckoo.common.abstracts import Signature

class DisablesSecurity(Signature):
    name = "disables_security"
    description = "Disables Windows Security features"
    severity = 3
    categories = ["anti-av"]
    authors = ["Cuckoo Technologies", "Brad Spengler"]
    minimum = "2.0"

    regkeys_re = [
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\\\\EnableLUA", "attempts to disable user access control"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\AntiVirusOverride", "attempts to disable antivirus notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\AntiVirusDisableNotify", "attempts to disable antivirus notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\FirewallDisableNotify", "attempts to disable firewall notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\FirewallOverride", "attempts to disable firewall notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\UpdatesDisableNotify", "attempts to disable windows update notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\UacDisableNotify", "disables user access control notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\EnableFirewall", "attempts to disable windows firewall"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\DoNotAllowExceptions", "attempts to disable firewall exceptions"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\DisableNotifications", "attempts to disable firewall notifications"),
        (".*\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Windows\\ Defender\\\\.*", "attempts to disable windows defender"),
        (".*\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Policies\\\\Microsoft\\\\Windows\\ Defender\\\\.*", "attempts to modify windows defender policies"),
        (".*\\\\SYSTEM\\\\(CurrentControlSet|ControlSet001)\\\\services\\\\WinDefend\\\\.*", "attempts to disable windows defender"),        
    ]

    def on_complete(self):
        for indicator in self.regkeys_re: 
            for regkey in self.check_key(pattern=indicator[0], regex=True, actions=["regkey_written"], all=True):
                self.mark(
                    description=indicator[1],
                    registry=regkey,                     
                )
                self.severity += 1

        self.severity = min(self.severity, 5)
        return self.has_marks()
¿äûÀÚ°¡ ÀÚ½ÅÀÇ 1000Æ÷ÀÎÆ®¸¦ °É¾ú½À´Ï´Ù. ´äº¯ÀÌ Ã¤ÅõǸé 500Æ÷ÀÎÆ®¸¦ µå¸³´Ï´Ù.
´ñ±Û 4°³ ´ñ±Û¾²±â
rankelfinlas 2019-02-22 (±Ý) 23:37
Ç® Äڵ带 Á» ºÁ¾ß ¾Ë°Å °°½À´Ï´Ù¸¸...
ÀÏ´Ü °£´ÜÈ÷ º¸¸é ¾Æ·¡¿Í °°½À´Ï´Ù~

###

  def on_complete(self):  # ÇÔ¼ö
        for indicator in self.regkeys_re:  # regkeys_re ¶ó´Â Ä÷º¼Ç(¸®½ºÆ®)¸¦ ¼øȸ (°¢ ¼øȸÇϸç indicator °ªÀ¸·Î Á¶È¸)
            for regkey in self.check_key(pattern=indicator[0], regex=True, actions=["regkey_written"], all=True):  # check_keyÇÔ¼ö¸¦ È£ÃâÇϴµ¥ ÇÔ¼öÀÇ °á°ú °ªÀº Ä÷º¼Ç(Á¤È®ÇÑ ÀÚ·áÇüÀº Ç®ÄÚµå ºÁ¾ß ¾Ë ¼ö ÀÖÀ½)
                self.mark(
                    description=indicator[1], 
                    registry=regkey,                   
                )  # mark ÇÔ¼ö È£Ãâ(°¢ Àü´ÞÀÎÀÚ¿¡ ÇÔ¼ö Àü´Þ)
                self.severity += 1  # severity °ªÀ» 1 Áõ°¡

        self.severity = min(self.severity, 5)  # severity °ª¿¡ ÇöÀç Áõ°¡µÈ °ª°ú 5 Áß¿¡ ´õ ³·Àº °ªÀ» ´ëÀÔ
        return self.has_marks()  # has_marks() ÇÔ¼ö¸¦ ¹Ýȯ
     
       
rank±òºÀ ±Û¾´ÀÌ 2019-02-23 (Åä) 05:43
Ç®ÄÚµå Àç ¾÷·Îµå Çß½À´Ï´Ù . °¨»çÇÕ´Ï´Ù  ^^ Çѹø¸¸ ´õ ºÎŹµå¸®°Ú½À´Ï´Ù.
          
            
rankelfinlas 2019-02-24 (ÀÏ) 00:06
À½....
Signature ¶ó´Â Ŭ·¡½º¸¦ »ó¼Ó¹Þ¾Ò´Âµ¥ ÀÌ Å¬·¡½º ¾È¿¡ ¸î °¡Áö ÇÔ¼öµéÀÌ À־ ÀÌ ºÎºÐÀ» ºÁ¾ß Çϴµ¥  ÀÌ ºÎºÐÀº ÀÛ¼ºÀÚ ºÐ²²¼­ ¿Ã·ÁÁֽðųª Á÷Á¢ ºÐ¼®Çغ¸¼­¾ß ÇÒ °Å °°½À´Ï´Ù.
±×¸®°í ÀÛ¼ºÀÚ ºÐÀÇ ÆÄÀ̽㠽ºÅ³ÀÌ ¾î´ÀÁ¤µµ ÀÎÁö ¸ô¶ó¼­ (Á¤È®È÷´Â °³¹ß°æ·Â µî) ÀÏ´Ü º¸Åë ÆÄÀ̽ã 1³âÂ÷ ¶ó »ý°¢ÇÏ°í ´äº¯À» µå¸®°Ú½À´Ï´Ù

¸ÕÀú on_complete ÇÔ¼ö¶ó´Â°Ô ¹» Çϴ°ÇÁö ±Ã±ÝÇϼż­ Áú¹®À» ³²±â½Å °Í °°Àºµ¥¿ä~
ÀÌ Ä£±¸´Â regkeys_re ¶ó´Â Ä÷º¼Ç(¸®½ºÆ® ¾ÈÀÇ Æ©ÇÃ)À» ¼øȸÇϸ鼭 °ªÀ» ã°í ´Ù¸¥ ÇÔ¼ö È£Ãâ ¹× °ª ¹ÝȯÀ» ÇÏ´Â °Í °°½À´Ï´Ù.
±×¸®°í DisablesSecurity Ŭ·¡½º´Â Signature¸¦ »ó¼Ó ¹Þ¾Ò´Âµ¥ ¾Æ¸¶ Àú Signature Ŭ·¡½º ³»¿¡ ¾Æ·¡ÀÇ ÇÔ¼ö µéÀÌ ¼±¾ðµÇ¾î ÀÖÀ»°Ì´Ï´Ù.
check_key, mark, has_marks
À§ ÇÔ¼öµéÀÇ ¼±¾ð ¹× ±¸Á¶¸¦ ¾Ë¾Æ¾ß on_complete ÇÔ¼öÀÇ ¿ªÇÒÀ» ¾Ë ¼ö ÀÖ°ÚÁÒ?
(¸¶Ä¡ ÀÚ¹Ù¿¡¼­ Ãß»óÈ­µÈ ÀÎÅÍÆäÀ̽º¸¦ º¸´Â °Í°ú °°Àº ÀÌÄ¡ÁÒ)

¹«Æ° Á¤¸®Çϸé..
À§ Äڵ常À¸·Î´Â ÇØ´ç Ŭ·¡½ºÀÇ on_complete ÇÔ¼ö°¡ Á¤È®È÷ ¹«¾ùÀ» ¼öÇàÇÏ´ÂÁö ¾Ë ¼ö ¾ø½À´Ï´Ù....
ÀÏ´Ü Âü°íÇÑ ¶óÀ̺귯¸®¸¦ º¸´Ï Cuckoo Sandbox ¶ó´Â ¸Ö¿þ¾î ºÐ¼®? ±×·± ¶óÀ̺귯¸® ÀÎ °Í °°½À´Ï´Ù.
±êÇéÀ» °¡ºÃ´Âµ¥ Àú Ŭ·¡½º°¡ ¾îµð¿¡ ÀÖ´ÂÁö ¸ø ã°Ú³×¿ä.
               
                 
rank±òºÀ ±Û¾´ÀÌ 2019-02-24 (ÀÏ) 09:29
Á¤¼º½º·¯¿î ´äº¯ Á¤¸» °¨»çµå¸³´Ï´Ù ^^
Cuckoo sandbox ¾Ç¼ºÄÚµå ÀÚµ¿È­ºÐ¼® ÅøÀÔ´Ï´Ù^^
¾î¶² ¾Ç¼ºÄڵ尡 ŽÁö°¡ µÇ´Âµ¥ ÀÌ°Ô ¾î¶»°Ô ŽÁö°¡ µÇ´ÂÁö ±Ã±ÝÇؼ­ º¸´Ù°¡ Ç®ÀÌ°¡ Àß ¾ÈµÇ¼­ Áú¹® µå·È½À´Ï´Ù ^^

¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ »óÅ Æ÷ÀÎÆ® ³¯Â¥ Á¶È¸
[°øÁö]  ¡Ø Áö½ÄiN °Ô½ÃÆÇ ÀÌ¿ë¾È³» rankeToLAND
0 03-28
[°øÁö]  ¡Ø Å䷻Ʈ»çÀÌÆ®Áú¹®,ÀúÀÛ±Ç ÀÚ·á¿äû ±ÝÁö rankeToLAND
0 08-25
[ºñ¹Ð»óÁ¡]  ´ë¿ë·® ÀÏȸ¿ë ÀüÀÚ´ã¹è ºñ¹ÐƯ°¡! (6977) ºñ¹Ð»óÁ¡
129610 [À½¾Ç]  ¾Èµå·ÎÀ̵å À½¾Ç ¾îÇà Áß¿¡ (1) rankJKinnaman
400 00:43 49
129609 [ÀüÀÚ±â±â]  WIFI Áö¿øµÇ´Â ȨķÀ» ÀÌ¿ëÇÏ¿© DVR·Î ÀúÀå ÇÒ ¼ö ÀÖ´Â ±â±â°¡ ÀÖ³ª¿ä? (1) rankInteli
1000 00:34 36
129608 [±âŸ]  ÇÕÀÇÇÒ¶§ Àΰ¨Áõ¸í¼­¿Í ½ÅºÐÁõ »çº» º¸³»´Þ¶ó´Âµ¥ ±¦ÂúÀ»±î¿ä? rankÈåÇÏÈåÇÏÇÏ
300 04-24 75
129607 [±âŸ]  ÀÚµ¿Â÷ À߾ƽôºР°è½Å°¡¿ä? Â÷·® ±¸¸ÅÇϽŠÁöÀο¡°Ô Â÷¿¡ °ü·ÃµÈ ¼±¹°À» ÁÖ°í½ÍÀºµ¥¿ä...txt (2) rank¿©Àڿ;ÆÀ̴³öÁà
2000 04-24 75
129606 [¼îÇÎ]  ÀÌ ¹ÙÁö ¾îµð °ÍÀÎÁö ¾Æ½Ã´ÂºÐ.. À̹ÌÁö rank¿ÀÇÏ»§
5000 04-23 169
129605 [Ãë¹Ì/»ýÈ°]  Çѱ¹µå¶ó¸¶ Áß¿¡ °¡Á· ±¸¼º¿øÀÌ.. (1) rankÀú°¡ÁÖ»ç³É²Û
1000 04-23 141
129604 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  youtube¿¡¼­ ¹«¼Õ½Ç À½¿øÀ¸·Î ´Ù¿î¹Þ´Â Ç÷¯±×ÀÎÀ̳ª È®ÀåÇÁ·Î±×·¥ÀÌ ÀÖ³ª¿ä? (5) rank·¹µå·¹¿À
500 04-23 113
129603 [±âŸ]  ¼ÂÅé¹Ú½º¿¡ apkÆÄÀÏ ³Ö´Â ¹æ¹ýÀÌ ÀÖÀ»±î¿ä? (3) rank·Îº¸Æ®°¡¾Æ´Ï¾ß
1000 04-23 160
129602 [±âŸ]  Àü¼±À» ¿¬°áÇؾßÇϴµ¥ ³¡ÀÌ (»çÁø) µÇ¾îÀÖ´Â°Ç ¾î¶»°Ô ÇؾßÇϳª¿ä? (5) rankÁñ°Üã
200 04-23 128
129601 [ÀüÀÚ±â±â]  led µîÀÌ ³ª°£°Í °°Àºµ¥ ¾Æ¹«°Å³ª »ç¸é µÇ³ª¿ä? (3) À̹ÌÁö rankÇູÀº°¡±îÀÌ
1000 04-23 131
129600 [±âŸ]  ¹ý¿ø º¸³¾ ¼­·ù °ü·Ã Áú¹®µå¸³´Ï´Ù (2) rank¼ÒÁÖ¶û´ß¶ËÁý
3000 04-22 82
129599 [±âŸ]  È¤½Ã ÀÚµ¿Â÷ ±¸¸ÅÇÒ ¶§ ÆÁÀ̳ª ÁÖÀÇ»çÇ× ÀÖÀ»±î¿ä?.txt (6) rank¿©Àڿ;ÆÀ̴³öÁà
5000 04-22 123
129598 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  »êÀÇ ³ôÀÌ, Á¹Á¹ È帣´Â ¹° ¾Ë ¼ö ÀÖ´Â Áöµµ¾îÇà ¹¹°¡ ÁÁÀº°¡¿ä (2) rankÀÏ»ó»ýÈ°¸ðÇè
369 04-21 133
129597 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ²ÜÀÌ °áÁ¤ÀÌ ¸Î¾îÁö¸é ??? °¡Â¥Àΰ¡¿ä ???? (2) rankÀÏ»ó»ýÈ°¸ðÇè
369 04-21 142
129596 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  Æ®À§ÅÍ °Ë»ö»çÀÌÆ® (1) rank¿¤·»ÆäÀÌÁö
3000 04-21 110
129595 [¼îÇÎ]  °í¼ö´ÔµéÀÇ µµ¿òÀÌ ÇÊ¿äÇÕ´Ï´Ù. (2) À̹ÌÁö rank¿ÀÇÏ»§
1000 04-21 111
129594 [°ÔÀÓ]  POE °ÔÀÓ ¾Æ½Ã´ÂºÐ °è½Å°¡¿ä? ¹» ¼³Ä¡ÇؾßÇϳª¿ä? (5) rank¿©Àڿ;ÆÀ̴³öÁà
500 04-20 147
129593 [TV/¿µ»ó]  ÇØ¿Ü¿¡¼­ ¿¾³¯ Çѱ¹ ¿¹´É µîÀ» ¹«·á·Î º¸´Â »çÀÌÆ®¸¦ ã°í ÀÖ½À´Ï´Ù. (7) rank¥É¥É¥É¥É¥É¥É¥É¥É
1000 04-19 153
129592 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  MsMpEng.exe ÆÄÀÏ ¾ø¾Ö´Â °Ç Á¤³ç ¹æ¹ýÀÌ ¾ø´Â °Ç°¡¿ä? (2) rankwpfhfh
2000 04-19 110
129591 [°æÁ¦/ÀçÅ×Å©]  ºÒ¾ÈÇؼ­ ¿©ÇàÀÚº¸ÇèÀÌ¶óµµ Á» Àß µé¾îº¸·Á°í Çϴµ¥¿ä (2) rank¼ö¸·ÀÌ
300 04-19 89
129590 [°ÔÀÓ]  ¼Ò¿ï½ºÅæ ¼­¹ÙÀ̹ú ÀßÇϽôºР°è½Å°¡¿ä? rankenrilj
1000 04-19 72
129589 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À©µµ¿ìµðÆæ´õ Äѱâ~ (6) À̹ÌÁö rankÇÔ³ÄÇÔ³ÄÇÔ
2000 04-19 192
129588 [TV/¿µ»ó]  2007 Mnet KM Music Festival Redcafet ¿µ»ó ã¾Æ¿ä. rank´Þ´öÀÌ
3000 04-18 81
129587 [°Ç°­/ÀÇÇÐ]  ÀÌ´¢Á¦ Àå±âº¹¿ëÇصµ µÉ±î¿ä? (6) rankÁß´ëÀåÀÌ´Ù
1000 04-18 132
129586 [Ãë¹Ì/»ýÈ°]  Èçµé¸®´Â °Ç ±ê¹ßÀÌ ¾Æ´Ï¶ó ³× ¸¶À½ÀÌ´Ù - ¿µ¾î·Î - rankÀÏ»ó»ýÈ°¸ðÇè
333 04-18 121
129585 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À¯Æ©ºê À½¾Ç _ ¿øº» ¼öÁØ mp3 ·Î ´Ù¿î ¹Þ´Â ¹æ¹ý ÀÖÀ»±î¿ä ??? (5) rankÀÏ»ó»ýÈ°¸ðÇè
333 04-17 169
129584 [±âŸ]  ½Å¹ß µÚ²ÞÄ¡ ¾µ·Á¼­ ¾ÆÇÁ³×¿ä, (2) rankÁ¤´Ù¼Ø
200 04-17 127
129583 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À¯ÅõºÎ Àç»ý¹Ù°¡ ÀÌ»óÇØÁ³³×¿ä. rankÀÚÀÛ±Ø
500 04-17 162
129582 [TV/¿µ»ó]  °¡Àå ÃÖ±ÙÀÇ 3D ¿µÈ­´Â? (1) rankº£ÁöŸ¸Æ½º
800 04-16 122
129581 [±âŸ]  ¼ö¾Ð ½ë Çعٶó±â »þ¿ö±â Çìµå ÃßõºÎŹµå·Á¿ä (3) rankºñ¹öu
2000 04-16 160
129580 [TV/¿µ»ó]  ¼Âž¹Ú½º¿Í TV hdmi ÄÉÀÌºí¿¡ ´ëÇؼ­ Áú¹®ÇÕ´Ï´Ù (2) rank·£µð113
300 04-16 111
129579 [°Ç°­/ÀÇÇÐ]  ÇöÀç ¼­¿ï TOP5 ´ëÇк´¿ø ¿¹¾àÇÏ´Â ¹æ¹ý ÀÖÀ»±î¿ä? (1) rankIlIIllIll
1000 04-16 134
129578 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ÀÎÅÍ³Ý ¾øÀÌ ¿ÍÀÌÆÄÀ̸¸ »ç¿ë°¡´ÉÇÒ±î¿ä? (4) rankKingÅ·½º¸Ç
500 04-16 223
129577 [±âŸ]  ¼ö½À±â°£Áß Á÷¿øÇØ°í½Ã ½Ç¾÷ ±Þ¿© ¹× ±Þ¿© °è»ê¹ý ¹®ÀÇ [ÀÚÇÊ] (7) rank¿¡·ÎÁ
2000 04-15 260
129576 [±âŸ]  ¾Ë¶ã¿ä±ÝÁ¦ À߾ƽôºР°è½Å°¡¿ä?.txt (4) rank¿©Àڿ;ÆÀ̴³öÁà
2000 04-13 167
129575 [°ÔÀÓ]  ÅÁÅÁƯ°ø´ë ¾²´ø Æù °èÁ¤À¸·Î PC¿¬µ¿ ÇÏ´Â ¹æ¹ý Á» ¤Ð (2) rank23455
3000 04-13 148
129574 [±âŸ]  ÀÌ°Ô ¹«½¼ ¹ú·¹ÀÎÁö ¾Ë¼öÀÖÀ»±î¿ä?.jpg (2) À̹ÌÁö rankMr·ç
300 04-12 220
129573 [Ãë¹Ì/»ýÈ°]  ÁÖº¯ ´Ù¸¥ ¾ÆÆÄÆ® ºÐ¸®¼ö°ÅÀÏ ±Ã±Ý..¤» ¾²·¡±â ½ºÆ¿·¯~~~~@ (3) rankÀÏ»ó»ýÈ°¸ðÇè
369 04-12 147
129572 [±âŸ]  Á¦°¡ ¿ø·ë»ç´Âµ¥ ¿ÍÀκ´ ¹ö¸®´Â°Å ¶§¹®¿¡ ±Ã±ÝÇÑ°Ô;; (2) rank123dcf
1000 04-12 273
129571 [¼îÇÎ]  ¾Ë¸®¿¡¼­ ȯºÒ ¸Þ¼¼Áö°¡ ¿Ô´Âµ¥¿ä, ¾îµð·Î ¿Â°Ç°¡¿ä? (1) rank·¹µå·¹¿À
500 04-12 209

Áú¹®°ú´äº¯ ¿ù°£ ÃÖ´ÙäÅà ¿ì¼ö´äº¯È¸¿ø

  • rank¿©Àڿ;ÆÀ̴³öÁà äÅô亯¼ö (10)
  • rank±×±îÀ̲¨¹¹¶ó°í äÅô亯¼ö (6)
  • rankÀáÀûÁß Ã¤Åô亯¼ö (3)
  • rankdasari äÅô亯¼ö (2)
  • rank´É±ÛÀÌ3 äÅô亯¼ö (2)
  • rankÈ£Á¶ äÅô亯¼ö (2)
  • rank±ä¼Ö äÅô亯¼ö (2)
  • rankÈå¹Ì¾ß äÅô亯¼ö (1)
  • rankcoulf äÅô亯¼ö (1)
     1  2  3  4  5  6  7  8  9  10  ´ÙÀ½

    °øÀ¯Çϱâ

    ÀÌÅä·£µå ·Î°í

    °èÁ¤ ã±â ȸ¿ø°¡ÀÔ
    ¼Ò¼È·Î±×ÀÎ