[ÄÄÇ»ÅÍ/ÀÎÅͳÝ]

ÆÄÀ̽㠳»¿ë Çѹø¸¸ Çؼ®ÇØÁÖ¼¼¿µ

rank ±òºÀ 2019-02-22 (±Ý) 14:03 Á¶È¸ : 618
# Copyright (C) 2010-2015 Cuckoo Foundation. 2016 Brad Spengler
# This file is part of Cuckoo Sandbox - http://www.cuckoosandbox.org
# See the file 'docs/LICENSE' for copying permission.

from lib.cuckoo.common.abstracts import Signature

class DisablesSecurity(Signature):
    name = "disables_security"
    description = "Disables Windows Security features"
    severity = 3
    categories = ["anti-av"]
    authors = ["Cuckoo Technologies", "Brad Spengler"]
    minimum = "2.0"

    regkeys_re = [
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\\\\EnableLUA", "attempts to disable user access control"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\AntiVirusOverride", "attempts to disable antivirus notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\AntiVirusDisableNotify", "attempts to disable antivirus notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\FirewallDisableNotify", "attempts to disable firewall notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\FirewallOverride", "attempts to disable firewall notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\UpdatesDisableNotify", "attempts to disable windows update notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\UacDisableNotify", "disables user access control notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\EnableFirewall", "attempts to disable windows firewall"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\DoNotAllowExceptions", "attempts to disable firewall exceptions"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\DisableNotifications", "attempts to disable firewall notifications"),
        (".*\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Windows\\ Defender\\\\.*", "attempts to disable windows defender"),
        (".*\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Policies\\\\Microsoft\\\\Windows\\ Defender\\\\.*", "attempts to modify windows defender policies"),
        (".*\\\\SYSTEM\\\\(CurrentControlSet|ControlSet001)\\\\services\\\\WinDefend\\\\.*", "attempts to disable windows defender"),        
    ]

    def on_complete(self):
        for indicator in self.regkeys_re: 
            for regkey in self.check_key(pattern=indicator[0], regex=True, actions=["regkey_written"], all=True):
                self.mark(
                    description=indicator[1],
                    registry=regkey,                     
                )
                self.severity += 1

        self.severity = min(self.severity, 5)
        return self.has_marks()
¿äûÀÚ°¡ ÀÚ½ÅÀÇ 1000Æ÷ÀÎÆ®¸¦ °É¾ú½À´Ï´Ù. ´äº¯ÀÌ Ã¤ÅõǸé 500Æ÷ÀÎÆ®¸¦ µå¸³´Ï´Ù.
´ñ±Û 4°³ ´ñ±Û¾²±â
rankelfinlas 2019-02-22 (±Ý) 23:37
Ç® Äڵ带 Á» ºÁ¾ß ¾Ë°Å °°½À´Ï´Ù¸¸...
ÀÏ´Ü °£´ÜÈ÷ º¸¸é ¾Æ·¡¿Í °°½À´Ï´Ù~

###

  def on_complete(self):  # ÇÔ¼ö
        for indicator in self.regkeys_re:  # regkeys_re ¶ó´Â Ä÷º¼Ç(¸®½ºÆ®)¸¦ ¼øȸ (°¢ ¼øȸÇϸç indicator °ªÀ¸·Î Á¶È¸)
            for regkey in self.check_key(pattern=indicator[0], regex=True, actions=["regkey_written"], all=True):  # check_keyÇÔ¼ö¸¦ È£ÃâÇϴµ¥ ÇÔ¼öÀÇ °á°ú °ªÀº Ä÷º¼Ç(Á¤È®ÇÑ ÀÚ·áÇüÀº Ç®ÄÚµå ºÁ¾ß ¾Ë ¼ö ÀÖÀ½)
                self.mark(
                    description=indicator[1], 
                    registry=regkey,                   
                )  # mark ÇÔ¼ö È£Ãâ(°¢ Àü´ÞÀÎÀÚ¿¡ ÇÔ¼ö Àü´Þ)
                self.severity += 1  # severity °ªÀ» 1 Áõ°¡

        self.severity = min(self.severity, 5)  # severity °ª¿¡ ÇöÀç Áõ°¡µÈ °ª°ú 5 Áß¿¡ ´õ ³·Àº °ªÀ» ´ëÀÔ
        return self.has_marks()  # has_marks() ÇÔ¼ö¸¦ ¹Ýȯ
     
       
rank±òºÀ ±Û¾´ÀÌ 2019-02-23 (Åä) 05:43
Ç®ÄÚµå Àç ¾÷·Îµå Çß½À´Ï´Ù . °¨»çÇÕ´Ï´Ù  ^^ Çѹø¸¸ ´õ ºÎŹµå¸®°Ú½À´Ï´Ù.
          
            
rankelfinlas 2019-02-24 (ÀÏ) 00:06
À½....
Signature ¶ó´Â Ŭ·¡½º¸¦ »ó¼Ó¹Þ¾Ò´Âµ¥ ÀÌ Å¬·¡½º ¾È¿¡ ¸î °¡Áö ÇÔ¼öµéÀÌ À־ ÀÌ ºÎºÐÀ» ºÁ¾ß Çϴµ¥  ÀÌ ºÎºÐÀº ÀÛ¼ºÀÚ ºÐ²²¼­ ¿Ã·ÁÁֽðųª Á÷Á¢ ºÐ¼®Çغ¸¼­¾ß ÇÒ °Å °°½À´Ï´Ù.
±×¸®°í ÀÛ¼ºÀÚ ºÐÀÇ ÆÄÀ̽㠽ºÅ³ÀÌ ¾î´ÀÁ¤µµ ÀÎÁö ¸ô¶ó¼­ (Á¤È®È÷´Â °³¹ß°æ·Â µî) ÀÏ´Ü º¸Åë ÆÄÀ̽ã 1³âÂ÷ ¶ó »ý°¢ÇÏ°í ´äº¯À» µå¸®°Ú½À´Ï´Ù

¸ÕÀú on_complete ÇÔ¼ö¶ó´Â°Ô ¹» Çϴ°ÇÁö ±Ã±ÝÇϼż­ Áú¹®À» ³²±â½Å °Í °°Àºµ¥¿ä~
ÀÌ Ä£±¸´Â regkeys_re ¶ó´Â Ä÷º¼Ç(¸®½ºÆ® ¾ÈÀÇ Æ©ÇÃ)À» ¼øȸÇϸ鼭 °ªÀ» ã°í ´Ù¸¥ ÇÔ¼ö È£Ãâ ¹× °ª ¹ÝȯÀ» ÇÏ´Â °Í °°½À´Ï´Ù.
±×¸®°í DisablesSecurity Ŭ·¡½º´Â Signature¸¦ »ó¼Ó ¹Þ¾Ò´Âµ¥ ¾Æ¸¶ Àú Signature Ŭ·¡½º ³»¿¡ ¾Æ·¡ÀÇ ÇÔ¼ö µéÀÌ ¼±¾ðµÇ¾î ÀÖÀ»°Ì´Ï´Ù.
check_key, mark, has_marks
À§ ÇÔ¼öµéÀÇ ¼±¾ð ¹× ±¸Á¶¸¦ ¾Ë¾Æ¾ß on_complete ÇÔ¼öÀÇ ¿ªÇÒÀ» ¾Ë ¼ö ÀÖ°ÚÁÒ?
(¸¶Ä¡ ÀÚ¹Ù¿¡¼­ Ãß»óÈ­µÈ ÀÎÅÍÆäÀ̽º¸¦ º¸´Â °Í°ú °°Àº ÀÌÄ¡ÁÒ)

¹«Æ° Á¤¸®Çϸé..
À§ Äڵ常À¸·Î´Â ÇØ´ç Ŭ·¡½ºÀÇ on_complete ÇÔ¼ö°¡ Á¤È®È÷ ¹«¾ùÀ» ¼öÇàÇÏ´ÂÁö ¾Ë ¼ö ¾ø½À´Ï´Ù....
ÀÏ´Ü Âü°íÇÑ ¶óÀ̺귯¸®¸¦ º¸´Ï Cuckoo Sandbox ¶ó´Â ¸Ö¿þ¾î ºÐ¼®? ±×·± ¶óÀ̺귯¸® ÀÎ °Í °°½À´Ï´Ù.
±êÇéÀ» °¡ºÃ´Âµ¥ Àú Ŭ·¡½º°¡ ¾îµð¿¡ ÀÖ´ÂÁö ¸ø ã°Ú³×¿ä.
               
                 
rank±òºÀ ±Û¾´ÀÌ 2019-02-24 (ÀÏ) 09:29
Á¤¼º½º·¯¿î ´äº¯ Á¤¸» °¨»çµå¸³´Ï´Ù ^^
Cuckoo sandbox ¾Ç¼ºÄÚµå ÀÚµ¿È­ºÐ¼® ÅøÀÔ´Ï´Ù^^
¾î¶² ¾Ç¼ºÄڵ尡 ŽÁö°¡ µÇ´Âµ¥ ÀÌ°Ô ¾î¶»°Ô ŽÁö°¡ µÇ´ÂÁö ±Ã±ÝÇؼ­ º¸´Ù°¡ Ç®ÀÌ°¡ Àß ¾ÈµÇ¼­ Áú¹® µå·È½À´Ï´Ù ^^

¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ »óÅ Æ÷ÀÎÆ® ³¯Â¥ Á¶È¸
[°øÁö]  ¡Ø Áö½ÄiN °Ô½ÃÆÇ ÀÌ¿ë¾È³» rankeToLAND
0 03-28
[°øÁö]  ¡Ø Å䷻Ʈ»çÀÌÆ®Áú¹®,ÀúÀÛ±Ç ÀÚ·á¿äû ±ÝÁö rankeToLAND
0 08-25
[ºñ¹Ð»óÁ¡]  ´ë¿ë·® ÀÏȸ¿ë ÀüÀÚ´ã¹è ºñ¹ÐƯ°¡! (6977) ºñ¹Ð»óÁ¡
129607 [¼îÇÎ]  ÀÌ ¹ÙÁö ¾îµð °ÍÀÎÁö ¾Æ½Ã´ÂºÐ.. À̹ÌÁö rank¿ÀÇÏ»§
5000 04-23 154
129606 [°ÔÀÓ]  ¼Ò¿ï½ºÅæ ¼­¹ÙÀ̹ú ÀßÇϽôºР°è½Å°¡¿ä? rankenrilj
1000 04-19 72
129605 [TV/¿µ»ó]  2007 Mnet KM Music Festival Redcafet ¿µ»ó ã¾Æ¿ä. rank´Þ´öÀÌ
3000 04-18 81
129604 [Ãë¹Ì/»ýÈ°]  Èçµé¸®´Â °Ç ±ê¹ßÀÌ ¾Æ´Ï¶ó ³× ¸¶À½ÀÌ´Ù - ¿µ¾î·Î - rankÀÏ»ó»ýÈ°¸ðÇè
333 04-18 121
129603 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À¯ÅõºÎ Àç»ý¹Ù°¡ ÀÌ»óÇØÁ³³×¿ä. rankÀÚÀÛ±Ø
500 04-17 160
129602 [±âŸ]  ÀÚÀÏ´ë¿ìÁßÇü¹ö½º ·¹½ºÅ¸ Á¤ºñ¼Ò rankGoldT
500 04-11 110
129601 [À½¾Ç]  ³ë·¡ ¾Æ½Ã´ÂºÐ? rank¿ÀÁöÄ¡Áî
500 04-06 122
129600 [Ãë¹Ì/»ýÈ°]  µµ¿Ã ³í¾îÀ̾߱⠰øÀÚ°¡ ÀÚ½ÅÀÇ Áö³ª¿Â »îÀ» À̾߱âÇÏ´Â rankÀÏ»ó»ýÈ°¸ðÇè
369 04-05 120
129599 [±âŸ]  »ï´Þ¸® ÃÔ¿µÁö ¾Ë·ÁÁÖ¼¼¿ä À̹ÌÁö rank±¤°í¹ÌħÀÌ
600 04-05 159
129598 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  OTT 3¹è¼Ó ½Ãû rankÀú°¡ÁÖ»ç³É²Û
5000 03-29 179
129597 [ÀüÀÚ±â±â]  Ä«µå»ç ÇÚµåÆù º¸Çè Áߺ¹¿©ºÎ rank½´ÀÌÄ¡
200 03-29 152
129596 [Ãë¹Ì/»ýÈ°]  ³» BIZ Áöµµ¾îÇÿ¡ ¶ß°Ô ¸¸µé·Á¸é ¾î¶»°Ô Çϳª¿ä ??? rankÀÏ»ó»ýÈ°¸ðÇè
369 03-26 125
129595 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¤· ºí·Î±×¸¦ ÇÏ°í ½ÍÀº Ã浿ÀÌ ÀϾ½À´Ï´Ù. ¤· À̹ÌÁö rankÀÏ»ó»ýÈ°¸ðÇè
369 03-20 145
129594 [°æÁ¦/ÀçÅ×Å©]  ¸»¼Ò±âÁرǸ® Àü/ÈÄ·Î ÀüÀÔ/È®Á¤ÀÏÀÚ°¡ ºÐ¸®µÈ °æ¿ì¿¡ ´ëÇØ Áú¹® µå¸³´Ï´Ù. rank¼ö¸·ÀÌ
500 03-18 113
129593 [°ÔÀÓ]  mvp ¾ß±¸ °ÔÀÓ [ÀÚÇÊ] rankºñ¹ÐÈ­¿ø
200 03-17 156
129592 [Ãë¹Ì/»ýÈ°]  ¿¹Àü¿¡ Ä¿¹Â´ÏƼ ±Û ¿øº»À» ã½À´Ï´Ù rank¹èº¡º¡
1500 03-13 138
129591 [À½¾Ç]  Áß±¹³ë·¡Àε¥ rankÇϾá¼Ó»èÀÓ
200 03-10 149
129590 [±âŸ]  ÄíÆÎ ¹°·ù¼¾ÅÍ ´Ü±â¾Ë¹Ù Çغ¸½Å ºÐ °è½Å°¡¿ä? rank±àÁ¤°ú¿ôÀ½
500 03-07 143
129589 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¿¢¼¿ ½ÃÆ®À̸§À» ÀÛ¼º,º¯°æ ÇÒ ¶§ ±ÛÀÚ°¡ ¾Èº¸ÀÔ´Ï´Ù À̹ÌÁö rank¾Æ³îµåÁ¤
1000 03-07 170
129588 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  - À¯Æ©ºê - À̸ÞÀÏÁÖ¼Ò Ç¥½Ã¿À·ù rankÁ¤»ó¿¡¼­¸¸³³½Ã´Ù
333 03-07 113
129587 [±³À°/Çй®]  ¾ßÈ£ ' ´Â ¾ðÁ¦ºÎÅÍ »ý°åÀ»±î¿ä rankÀÏ»ó»ýÈ°¸ðÇè
369 03-01 160
129586 [°æÁ¦/ÀçÅ×Å©]  ½Å¿ëºÒ·®ÀÚµµ û¾à½Åû °¡´ÉÇÑ°¡¿ä? rankÈıî·ç·ç
300 02-26 215
129585 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  µ¶°Å¹Ì Å°º¸µå »ç·Á°í Çϴµ¥ ¸Â´Â Űĸ Á» ºÁÁÖ¼¼¿ä rankÁ¦ÀÌÇÇ¿¡ÀÌ
1000 02-19 279
129584 [±âŸ]  ¾ÆÆÄÆ® Àç°è¾à½Ã 1³â°è¾à¿¡ ´ëÇØ µµ¿ò ÁÖ½Ç ¼ö ÀִºР°è½Ç±î¿ä? rank¹Ù¹ã¹Ù
3000 02-14 255
129583 [°æÁ¦/ÀçÅ×Å©]  Çö´ëÄ«µå Àß ¾Æ½Ã´ÂºÐ²², Çö¾ÆÇà ¹× Ä«µå Ãßõ Çϳª¸¸ ºÎŹµå·Áº¾´Ï´Ù. rank¼ö¸·ÀÌ
500 02-11 446
129582 [Ãë¹Ì/»ýÈ°]  °úÅ·á, ¼¼±Ý µîµî ÆíÇϱ⠺¸°í Á¤¸®ÇÏ´Â »çÀÌÆ® ???? rankÀÏ»ó»ýÈ°¸ðÇè
586 02-09 412
129581 [ÀüÀÚ±â±â]  °¶·°½Ã ¹®ÀÚ°¡ ÀÌ»óÇÑ ÇüÅ·Πµé¾î¿À´Âµ¥ ±âÁ¸ ¹æ½ÄÀ¸·Î µ¹¸± ¼ö ¾øÀ»±î¿ä? À̹ÌÁö rank¼ö¸·ÀÌ
300 02-08 534
129580 [ÀüÀÚ±â±â]  androidÅÂºí¸´¿¡ ºí·¢¹Ú½º±â´É¿ë dvr¾ÛÀ» ¼³Ä¡ÇÒ·Á°í ÇÕ´Ï´Ù rank·¹µå·¹¿À
500 02-06 457
129579 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À©µµ¿ì 11 - explorer.exe ¿¡·¯ À̹ÌÁö rankÆÄ¿ö¼Ò´Ð
200 01-31 236
129578 [ÀüÀÚ±â±â]  Å×ºí·¿PC ¼±ÅÃÀ» µµ¿ÍÁÖ¼¼¿ä!! rank²¿¸¶º£º£
200 01-31 220
129577 [±âŸ]  »ï¼º ÆòÅà ÇöÀå¿¡¼­ ÇÏ°íÀÖ´Â smcs¿¡´ëÇØ ¾Ë·ÁÁÖ¼¼¿ä.. rankÀ¸¾Ç¤©¤±
500 01-28 296
129576 [±³À°/Çй®]  À¯Æ©ºê¿¡ ±¦ÂúÀº ¿Àµð¿ÀºÏ ä³Î rank½î´Ð´Ô
2000 01-27 229
129575 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À©µµ¿ì pe macrium reflect Çѱ۹öÀü ÀÚµ¿½ÇÇàµÇ´Â ¹öÁ¯ Á¤º¸ ¾Ë°í °è½Ã´ÂºÐ °è½Ã³ª¿ä? rankº¿´ë2
5000 01-25 189
129574 [°æÁ¦/ÀçÅ×Å©]  ºÎµ¿»ê °æ¸Å - ¾îÇà ÃßõÇØÁÖ¼¼¿ä rankÀÏ»ó»ýÈ°¸ðÇè
555 01-24 168
129573 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  Ä«Ä«¿ÀÅå µ¿¿µ»ó ÇÁ·ÎÇÊ ´Ù¿î ¹Þ´Â ¹æ¹ý ÀÖ³ª¿ä? rank°¡ÀÏ
200 01-23 215
129572 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ³×À̹ö¿þÀÏ Á¦¸ñ ÀÚµ¿¿Ï¼º ±â´É ¾î¶»°Ô ¾ø¾Ö³ª¿ä? rankÁÙ±âÂù²æ
200 01-22 191
129571 [TV/¿µ»ó]  Hdmi ½ºÀ§Ä¡·Î pc¿Í ½ºÄ«À̶óÀÌÇÁ ¼Âž¹Ú½º¸¦ [ÀÚÇÊ] rank¡°ü
1000 01-21 206
129570 [Ãë¹Ì/»ýÈ°]  ÀϺ» cf ¹è¿ì À̸§Á» ¾Ë·ÁÁÖ¼¼¿ä.jpg À̹ÌÁö rank¾ÆÀÌ¿ìµð
200 01-20 275
129569 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ÆÌij½ºÆ® ¿Ë²Ù¶ó ½ÃÁð 1&2 ¾îµð¼­ µéÀ» ¼ö ÀÖ´ÂÁö ¾Æ½Ã´ÂºÐ? rank»õºñ»õºñ
900 01-20 185
129568 [±âŸ]  ¿ò© Ãâó ¾Ë·ÁÁÖ¼¼¿ä! (´Ù¸¥±Û Æ÷ÀÎÆ®+200) À̹ÌÁö rank³×¹ös2
300 01-18 209

Áú¹®°ú´äº¯ ¿ù°£ ÃÖ´ÙäÅà ¿ì¼ö´äº¯È¸¿ø

  • rank¿©Àڿ;ÆÀ̴³öÁà äÅô亯¼ö (10)
  • rank±×±îÀ̲¨¹¹¶ó°í äÅô亯¼ö (5)
  • rankÀáÀûÁß Ã¤Åô亯¼ö (3)
  • rankdasari äÅô亯¼ö (2)
  • rank´É±ÛÀÌ3 äÅô亯¼ö (2)
  • rankÈ£Á¶ äÅô亯¼ö (2)
  • rank±ä¼Ö äÅô亯¼ö (2)
  • rankÈå¹Ì¾ß äÅô亯¼ö (1)
  • rank°í¸£78 äÅô亯¼ö (1)
     1  2  3  4  5  6  7  8  9  10  ´ÙÀ½

    °øÀ¯Çϱâ

    ÀÌÅä·£µå ·Î°í

    °èÁ¤ ã±â ȸ¿ø°¡ÀÔ
    ¼Ò¼È·Î±×ÀÎ