[ÄÄÇ»ÅÍ/ÀÎÅͳÝ]

ÆÄÀ̽㠳»¿ë Çѹø¸¸ Çؼ®ÇØÁÖ¼¼¿µ

rank ±òºÀ 2019-02-22 (±Ý) 14:03 Á¶È¸ : 621
# Copyright (C) 2010-2015 Cuckoo Foundation. 2016 Brad Spengler
# This file is part of Cuckoo Sandbox - http://www.cuckoosandbox.org
# See the file 'docs/LICENSE' for copying permission.

from lib.cuckoo.common.abstracts import Signature

class DisablesSecurity(Signature):
    name = "disables_security"
    description = "Disables Windows Security features"
    severity = 3
    categories = ["anti-av"]
    authors = ["Cuckoo Technologies", "Brad Spengler"]
    minimum = "2.0"

    regkeys_re = [
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\System\\\\EnableLUA", "attempts to disable user access control"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\AntiVirusOverride", "attempts to disable antivirus notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\AntiVirusDisableNotify", "attempts to disable antivirus notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\FirewallDisableNotify", "attempts to disable firewall notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\FirewallOverride", "attempts to disable firewall notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\UpdatesDisableNotify", "attempts to disable windows update notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Microsoft\\\\Security\\ Center\\\\UacDisableNotify", "disables user access control notifications"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\EnableFirewall", "attempts to disable windows firewall"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\DoNotAllowExceptions", "attempts to disable firewall exceptions"),
        ("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\services\\\\SharedAccess\\\\Parameters\\\\FirewallPolicy\\\\StandardProfile\\\\DisableNotifications", "attempts to disable firewall notifications"),
        (".*\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Windows\\ Defender\\\\.*", "attempts to disable windows defender"),
        (".*\\\\SOFTWARE\\\\(Wow6432Node\\\\)?Policies\\\\Microsoft\\\\Windows\\ Defender\\\\.*", "attempts to modify windows defender policies"),
        (".*\\\\SYSTEM\\\\(CurrentControlSet|ControlSet001)\\\\services\\\\WinDefend\\\\.*", "attempts to disable windows defender"),        
    ]

    def on_complete(self):
        for indicator in self.regkeys_re: 
            for regkey in self.check_key(pattern=indicator[0], regex=True, actions=["regkey_written"], all=True):
                self.mark(
                    description=indicator[1],
                    registry=regkey,                     
                )
                self.severity += 1

        self.severity = min(self.severity, 5)
        return self.has_marks()
¿äûÀÚ°¡ ÀÚ½ÅÀÇ 1000Æ÷ÀÎÆ®¸¦ °É¾ú½À´Ï´Ù. ´äº¯ÀÌ Ã¤ÅõǸé 500Æ÷ÀÎÆ®¸¦ µå¸³´Ï´Ù.
´ñ±Û 4°³ ´ñ±Û¾²±â
rankelfinlas 2019-02-22 (±Ý) 23:37
Ç® Äڵ带 Á» ºÁ¾ß ¾Ë°Å °°½À´Ï´Ù¸¸...
ÀÏ´Ü °£´ÜÈ÷ º¸¸é ¾Æ·¡¿Í °°½À´Ï´Ù~

###

  def on_complete(self):  # ÇÔ¼ö
        for indicator in self.regkeys_re:  # regkeys_re ¶ó´Â Ä÷º¼Ç(¸®½ºÆ®)¸¦ ¼øȸ (°¢ ¼øȸÇϸç indicator °ªÀ¸·Î Á¶È¸)
            for regkey in self.check_key(pattern=indicator[0], regex=True, actions=["regkey_written"], all=True):  # check_keyÇÔ¼ö¸¦ È£ÃâÇϴµ¥ ÇÔ¼öÀÇ °á°ú °ªÀº Ä÷º¼Ç(Á¤È®ÇÑ ÀÚ·áÇüÀº Ç®ÄÚµå ºÁ¾ß ¾Ë ¼ö ÀÖÀ½)
                self.mark(
                    description=indicator[1], 
                    registry=regkey,                   
                )  # mark ÇÔ¼ö È£Ãâ(°¢ Àü´ÞÀÎÀÚ¿¡ ÇÔ¼ö Àü´Þ)
                self.severity += 1  # severity °ªÀ» 1 Áõ°¡

        self.severity = min(self.severity, 5)  # severity °ª¿¡ ÇöÀç Áõ°¡µÈ °ª°ú 5 Áß¿¡ ´õ ³·Àº °ªÀ» ´ëÀÔ
        return self.has_marks()  # has_marks() ÇÔ¼ö¸¦ ¹Ýȯ
     
       
rank±òºÀ ±Û¾´ÀÌ 2019-02-23 (Åä) 05:43
Ç®ÄÚµå Àç ¾÷·Îµå Çß½À´Ï´Ù . °¨»çÇÕ´Ï´Ù  ^^ Çѹø¸¸ ´õ ºÎŹµå¸®°Ú½À´Ï´Ù.
          
            
rankelfinlas 2019-02-24 (ÀÏ) 00:06
À½....
Signature ¶ó´Â Ŭ·¡½º¸¦ »ó¼Ó¹Þ¾Ò´Âµ¥ ÀÌ Å¬·¡½º ¾È¿¡ ¸î °¡Áö ÇÔ¼öµéÀÌ À־ ÀÌ ºÎºÐÀ» ºÁ¾ß Çϴµ¥  ÀÌ ºÎºÐÀº ÀÛ¼ºÀÚ ºÐ²²¼­ ¿Ã·ÁÁֽðųª Á÷Á¢ ºÐ¼®Çغ¸¼­¾ß ÇÒ °Å °°½À´Ï´Ù.
±×¸®°í ÀÛ¼ºÀÚ ºÐÀÇ ÆÄÀ̽㠽ºÅ³ÀÌ ¾î´ÀÁ¤µµ ÀÎÁö ¸ô¶ó¼­ (Á¤È®È÷´Â °³¹ß°æ·Â µî) ÀÏ´Ü º¸Åë ÆÄÀ̽ã 1³âÂ÷ ¶ó »ý°¢ÇÏ°í ´äº¯À» µå¸®°Ú½À´Ï´Ù

¸ÕÀú on_complete ÇÔ¼ö¶ó´Â°Ô ¹» Çϴ°ÇÁö ±Ã±ÝÇϼż­ Áú¹®À» ³²±â½Å °Í °°Àºµ¥¿ä~
ÀÌ Ä£±¸´Â regkeys_re ¶ó´Â Ä÷º¼Ç(¸®½ºÆ® ¾ÈÀÇ Æ©ÇÃ)À» ¼øȸÇϸ鼭 °ªÀ» ã°í ´Ù¸¥ ÇÔ¼ö È£Ãâ ¹× °ª ¹ÝȯÀ» ÇÏ´Â °Í °°½À´Ï´Ù.
±×¸®°í DisablesSecurity Ŭ·¡½º´Â Signature¸¦ »ó¼Ó ¹Þ¾Ò´Âµ¥ ¾Æ¸¶ Àú Signature Ŭ·¡½º ³»¿¡ ¾Æ·¡ÀÇ ÇÔ¼ö µéÀÌ ¼±¾ðµÇ¾î ÀÖÀ»°Ì´Ï´Ù.
check_key, mark, has_marks
À§ ÇÔ¼öµéÀÇ ¼±¾ð ¹× ±¸Á¶¸¦ ¾Ë¾Æ¾ß on_complete ÇÔ¼öÀÇ ¿ªÇÒÀ» ¾Ë ¼ö ÀÖ°ÚÁÒ?
(¸¶Ä¡ ÀÚ¹Ù¿¡¼­ Ãß»óÈ­µÈ ÀÎÅÍÆäÀ̽º¸¦ º¸´Â °Í°ú °°Àº ÀÌÄ¡ÁÒ)

¹«Æ° Á¤¸®Çϸé..
À§ Äڵ常À¸·Î´Â ÇØ´ç Ŭ·¡½ºÀÇ on_complete ÇÔ¼ö°¡ Á¤È®È÷ ¹«¾ùÀ» ¼öÇàÇÏ´ÂÁö ¾Ë ¼ö ¾ø½À´Ï´Ù....
ÀÏ´Ü Âü°íÇÑ ¶óÀ̺귯¸®¸¦ º¸´Ï Cuckoo Sandbox ¶ó´Â ¸Ö¿þ¾î ºÐ¼®? ±×·± ¶óÀ̺귯¸® ÀÎ °Í °°½À´Ï´Ù.
±êÇéÀ» °¡ºÃ´Âµ¥ Àú Ŭ·¡½º°¡ ¾îµð¿¡ ÀÖ´ÂÁö ¸ø ã°Ú³×¿ä.
               
                 
rank±òºÀ ±Û¾´ÀÌ 2019-02-24 (ÀÏ) 09:29
Á¤¼º½º·¯¿î ´äº¯ Á¤¸» °¨»çµå¸³´Ï´Ù ^^
Cuckoo sandbox ¾Ç¼ºÄÚµå ÀÚµ¿È­ºÐ¼® ÅøÀÔ´Ï´Ù^^
¾î¶² ¾Ç¼ºÄڵ尡 ŽÁö°¡ µÇ´Âµ¥ ÀÌ°Ô ¾î¶»°Ô ŽÁö°¡ µÇ´ÂÁö ±Ã±ÝÇؼ­ º¸´Ù°¡ Ç®ÀÌ°¡ Àß ¾ÈµÇ¼­ Áú¹® µå·È½À´Ï´Ù ^^

¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ »óÅ Æ÷ÀÎÆ® ³¯Â¥ Á¶È¸
[°øÁö]  ¡Ø Áö½ÄiN °Ô½ÃÆÇ ÀÌ¿ë¾È³» rankeToLAND
0 03-28
[°øÁö]  ¡Ø Å䷻Ʈ»çÀÌÆ®Áú¹®,ÀúÀÛ±Ç ÀÚ·á¿äû ±ÝÁö rankeToLAND
0 08-25
[º¸Çè»ó´ã½Ç]  ½Ç¼Õº¸Çè 1¼¼´ë ¹®ÀÇ À͸í
114593 [TV/¿µ»ó]  ¿À´Ã ¼ÕÈï¹Î Ã౸°æ±â Áß°è ÁÂÇ¥Á» ºÎŹµå¸³´Ï´Ù. (3) rankÀÌ¿¬Èñ¤ÑÆÒ1È£
500 02-23 874
114592 [Ãë¹Ì/»ýÈ°]  ¼ýÀÚÆÛÁñ(½½¶óÀ̵ùÆÛÁñ) ¸¶Áö¸·ÁÙ ¸ÂÃß´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù (3) rank¼ö¸·ÀÌ
200 02-23 5057
114591 [°ÔÀÓ]  ½ºÆ®¸®Æ® ÆÄÀÌÅÍ 4¸¦ ´Ù¿î¹Þ¾Ò´Âµ¥¿ä.... (2) rank°õ³ª¶óÅÊ
700 02-23 818
114590 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ÄÄÇ»ÅÍ Áú¹®ÀÔ´Ï´Ù. (16) rank´©°¡³Ä³ÍÀÌ´À
500 02-23 594
114589 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¸ð´ÏÅÍ hdmi Àüȯ ´ÜÃàÅ°·Î º¯°æ Çϴ¹ý ¾øÀ»±î¿ä? (2) rankÀáÀÌ
500 02-23 13495
114588 [Ãë¹Ì/»ýÈ°]  . (2) rank¼Ò¶±°­Á¤
200 02-23 518
114587 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ³ëÆ®ºÏ ÃßõÇØÁÖ¼¼¿ä~ (5) rankSâÈÆ
500 02-23 534
114586 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ÀÏüÇüpcÀε¥ Æ÷¸ËÀÌ ¾ÈµÅ¿ä. µµ¿ÍÁÖ¼¼¿ä. ¤Ð¤Ð (5) rankõ¿¬»çÀÌ´Ù
1000 02-23 861
114585 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¾àÁ¤±â°£ (2) ranksmileaga
200 02-23 617
114584 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  Áß°í ÄÄÅÍ »ì¶ó´Âµ¥ ÇÔ ºÁÁֽǼö ÀÖ³ª¿ë? (9) rank´©°¡³Ä³ÍÀÌ´À
800 02-23 822
114583 [±³À°/Çй®]  Áß¼Ò±â¾÷ ´Ù´Ï½Ã´ÂºÐ Çʵ¶!!!!!! ¼Òµæ¼¼°¨¸é70->90% ²À µ¹·Á¹ÞÀ¸¼¼¿ä (4) rankÑûí­
200 02-23 802
114582 [TV/¿µ»ó]  ¿äÁò ´í½ºÆÀ Á÷Ä·Àº ¾îµð¼­ º¸´Â°Ô ÁÁÀº°¡¿ä ¤Ð¤Ð (2) rank±¸½ÊÀϺ¯°æ³ë³ë
1000 02-23 1171
114581 [±âŸ]  Ä«¼¾ÅÍ Ã¢¾÷ ¾î¶»°Ô ½ÃÀÛÇؾߵdzª¿ä? (2) ranke»·ÇѼ¼»ó
200 02-23 741
114580 [Ãë¹Ì/»ýÈ°]  ´ã±Ý ¸Å½ÇÁÖ °³ºÀÇߴµ¥ ¾´¸ÀÀÌ ¸¹ÀÌ ³³´Ï´Ù. (7) rankasdream
300 02-23 855
114579 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  Àü¿¡ ÀÌÅäȸ¿øºÐÁß¿¡ ÇѺÐÀÌ ¸¸µé¾ú´Ù¸ç À¯Åõºê Ç÷¹À̾ ¼Ò°³ÇϽźÐÀÌ °è½Åµ¥ (2) rankButelr
200 02-23 513
114578 [TV/¿µ»ó]  È²ÈÄÀÇ Ç°°Ý º¸½ÅºÐµé¿¡°Ô Áú¹®Á» µå¸±°Ô¿ä. (2) rank¿µÀ屺
300 02-23 763
114577 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  °ÔÀÓ¿¡¼­ ¸¶ÀÌÅ© ¸®¹öºê rank´Ù¿µÀÌ22
200 02-23 663
114576 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® ¿§Áö ¿À·ù (2) rankÈ«°è¸®
200 02-23 1098
114575 [±âŸ]  °°ÀÌ »ì°íÀִ ģµ¿»ýÀ» ³»ÂÑ°í ½ÍÀºµ¥¿ä. (11) rankdaaken
500 02-23 2896
114574 [¼îÇÎ]  ¾Ë¸®¹è¼Û ¹°°ÇÀ» ¿ìüºÎ°¡ ¹è´Þ ÇÒ ¶§¿ä (5) rankÈòµÕÈòµÕ
200 02-23 902
114573 [°æÁ¦/ÀçÅ×Å©]  ÁÖÅà ¼Ò¹æ°Ë»çºñ ºÎ´ãÀº ´©°¡??? (2) rankÇÏ´ÃMaru
1000 02-23 883
114572 [TV/¿µ»ó]  Á¦ ÇÁ»ç À̹ÌÁö ´©±ºÁö¿ä? (1) rankÇϴÿ¡³õÀºµ¹
200 02-23 1588
114571 [À½¾Ç]  ºÏÀ¯·´ÂÊ Ãâ½Å ³²¼º°¡¼öÀÇ ¹Âºñ¸¦ ã½À´Ï´Ù. rank¶ôÁ¤±â
295 02-23 746
114570 [±âŸ]  °ø±â¾÷ÀÇ Áö¿ªÀÎÀç ä¿ë°ú ºí¶óÀεå (5) rank´À¸®°Ô°È´Â»ç¶÷
500 02-23 766
114569 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  Àü¸éºÎ ½Ã½ºÅÛÄð·¯°¡ Àü¿øÀ» ²¨µµ ¾È¸ØÃ߳׿ä (7) À̹ÌÁö rank¸ÛÅë
200 02-22 753
114568 [TV/¿µ»ó]  [Àϵå] ¹«¸¶½ÃŲ °Ü¿ï ~¿ì¸® Áý ¹®Á¦´Â ¾ø¾ú´ø ÀÏ·Î~ ÀÚ¸· ±¸Çغ¾´Ï´Ù. (1) rank±è¸ù½Ç
200 02-22 1456
114567 [¼îÇÎ]  ¿Á¼Ç ÆíÀÇÁ¡ÅÃ¹è ¹ÝÇ° Áú¹® ÀÔ´Ï´Ù. (2) rank¿ì¸®¹Ù
500 02-22 1390
114566 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  À©10 ½ÇÇàâ(µ¸º¸±â) ¸í·É¾î¸¦ ±î¸Ô¾ú½À´Ï´Ù. ¾Ë¼öÀÖÀ»±î¿ä? (5) rankCubeSI
200 02-22 721
114565 [°æÁ¦/ÀçÅ×Å©]  °æ±âµµ °æ±âħü?? (5) rankgwonm
300 02-22 665
114564 [±âŸ]  ½Ç¾÷±Þ¿© Áú¹® µå¸³´Ï´Ù. (6) rankÀÌÁ¦È­
1000 02-22 611
114563 [TV/¿µ»ó]  btn ³ìÈ­¿¡ °üÇØ Áú¹®µå¸³´Ï´Ù (2) rank´ÙÀ̵¹ÇÉ
500 02-22 704
114562 [±âŸ]  ºñµ¥ Á÷Á¢ ¼³Ä¡ÇÏ´Ù°¡ ±âÁ¸ º¼Æ®°¡ µÎµ¿°­ ³µ¾î¿ä;; (5) rank½áºêµà
200 02-22 727
114561 [±âŸ]  ÇÇ¾î ´õ ¿öÅ·µ¥µå S04E15 ÇѱÛÀÚ¸· ±¸ÇØ¿ä (1) rank¸¶Æ¾°í¾î
500 02-22 687
114560 [±³À°/Çй®]  ÇöÁ÷ ¼Ò¹æÁ¡°Ë °ü·Ã Á÷Á¾¿¡ ±Ù¹«ÇÏ´Â ÀÌÅäÀÎ °è½Å°¡¿ä? (2) rankÑûí­
500 02-22 821
114559 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¿ë·® Å« ÆÄÀÏ º¹»ç/À̵¿ ¾ÈµÇ´Â Çö»ó (2) rank¸·Ãâ
200 02-22 682
114558 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¿ÜÀå ssd¼Óµµ Áú¹®ÀÌ¿ä (5) rankÈ«ÀÌ¿ä
500 02-22 531
114557 [À½¾Ç]  °¶·°½Ã j3 2016Àä (2) rankÁÖ¹éÅë
200 02-22 829
114556 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ¿ÍÀÌÆÄÀÌ ¼Óµµ ÃøÁ¤°á°ú¿¡ ´ëÇؼ­ Áú¹®ÀÌ¿ä~ (4) rankÇÁ·ÎÀÌÄ«
200 02-22 548
114555 [ÄÄÇ»ÅÍ/ÀÎÅͳÝ]  ÆÄÀ̽㠳»¿ë Çѹø¸¸ Çؼ®ÇØÁÖ¼¼¿µ (4) rank±òºÀ
1000 02-22 621
114554 [TV/¿µ»ó]  ½ºÄ«À̶óÀÌÇÁ À§¼º ÄÉÀÌºí¿¡ ´ëÇؼ­ Áú¹® µå¸³´Ï´Ù. (4) rankdlfjswps
1000 02-22 1194

Áú¹®°ú´äº¯ ¿ù°£ ÃÖ´ÙäÅà ¿ì¼ö´äº¯È¸¿ø

  • rank¿©Àڿ;ÆÀ̴³öÁà äÅô亯¼ö (16)
  • rank±×±îÀ̲¨¹¹¶ó°í äÅô亯¼ö (5)
  • rankdasari äÅô亯¼ö (4)
  • rankÀáÀûÁß Ã¤Åô亯¼ö (3)
  • rank±ä¼Ö äÅô亯¼ö (2)
  • rankÈ£Á¶ äÅô亯¼ö (2)
  • rank°ø±¸¸®¹Ú äÅô亯¼ö (1)
  • rankÄ«ÆäÀΠäÅô亯¼ö (1)
  • rankÀå±â¹é äÅô亯¼ö (1)
    óÀ½  ÀÌÀü  371  372  373  374  375  376  377  378  379  380  ´ÙÀ½

    °øÀ¯Çϱâ

    ÀÌÅä·£µå ·Î°í

    °èÁ¤ ã±â ȸ¿ø°¡ÀÔ
    ¼Ò¼È·Î±×ÀÎ