- [Forensics WRITEUP๐ช] Windows Incident Surface ๋ผ์ดํธ์2024๋ 08์ 08์ผ 04์ 30๋ถ 56์ด์ ์ ๋ก๋ ๋ ๊ธ์ ๋๋ค.์์ฑ์: banda โ
๐ชWindows Incident Surface
ํด๋น ๋ฌธ์ ์ WriteUp๋ฅผ ์์ฑํด๋ณผ ๊ฒ์ด๋ค.
https://tryhackme.com/r/room/winincidentsurface
openvpn์ ํตํด kali linux์ vm ๋ฐฐํฌ๋ฅผ ์งํํด ์ค๋น๋ฅผ ์๋ฃํ๋ค.
์ด๋ ๊ฒ ์ฐ๊ฒฐํ๋ฉด tun0์ tryhackme์ ์ธํ ์ด ๋ํ๋๋ ๊ฒ์ ํ์ธํ ์ ์๋ค.
์นผ๋ฆฌ ๋ฆฌ๋ ์ค๋ก๋ถํฐ windows try hack me ์ค์ตํ๊ฒฝ์ ์ง์ ํ๋ค.
task 3๊น์ง๋ ์ธํ ๋ฐ ์๋๋ฆฌ์ค ์ค๋ช ๋ด์ฉ์ด๋ฏ๋ก task 4๋ถํฐ ์งํํ๊ฒ ๋ค.
ํด๋น ๋ช ๋ น์ด๋ฅผ ์ด์ฉํด์ ์นผ๋ฆฌ ๋ฆฌ๋ ์ค RDP์ ์ ์ํด์ฃผ์๋ค.
xfreerdp /u:(username) /p:(password) /v:(Machine IP) /dynamic-resolution
Task 4 Reliability of the System Tools
์์คํ ๋๊ตฌ์ ์ ๋ขฐ์ฑ
cmd ๋๊ตฌ์ ps ๋๊ตฌ๋ฅผ ์ด์ฉํด ์ฌ์ฉ์์ ์ ๋ณด๋ฅผ ์์๋ด๋ ์ค์ต์ด๋ค.
C:\Users\Administrator\Desktop\tools\shells ๊ฒฝ๋ก์์ ๋ค์๊ณผ ๊ฐ์ shells exe๋ฅผ ํ์ธํ ์ ์์๋ค.
CMD์ PowerShell ๋ ๊ฐ์ง ๋ฒ์ ์ด ์์๋ค.
์์คํ ๋๊ตฌ๋ฅผ ์ฌ์ฉํด์ 10.10.166.79 IP ํธ์คํธ์ ์์๋ ํธ์คํธ๋ฅผ ์กฐ์ฌํ๋ ๊ฒ์ด ์๋๋ฆฌ์ค์ด๋ค.
์ด๋ฒ ์ค์ต์์๋ PowerShell, cmd๋ฅผ ์ด์ฉํด์ ์ฌ์ฉ์์ ์ ๋ณด๋ฅผ ํ์ํ๋ ๊ฒ์ด ๋ชฉ์ ์ธ ๊ฒ ๊ฐ๋ค.
์ ๋ขฐํ ์ ์๋ ๋ช ๋ น ์์ด ์๋ ํด๋ ๊ฒฝ๋ก C:\Users\Administrator\Desktop\tools\shells๊ฐ ์ค๋น๋์ด ์๋ค.
DFIR์ ๋์งํธํฌ๋ ์ ์ฌ๊ณ ๋์ ์ฉ์ด๋ค. ๋ฐ์ดํฐ๋ฅผ ์์งํ๊ธฐ ์ํ ํด์ด๋ผ๋ ๊ฒ์ ์ ์ ์๋ค.
CMD-DFIR.exe๋ฅผ ๊ด๋ฆฌ์ ๊ถํ์ผ๋ก ์คํํด์ env_vars.txt๋ฅผ set, type ํด์ฃผ์๋ค.
์ ์ฌ์ ์ผ๋ก ํ์ด์ฌํน๋ ์ ๋ณด๋ฅผ ์ฐพ์๋ด๊ธฐ ์ํด ํ๋๋ฅผ ์คํฌ๋ฆฐํ๋ค.
ComSpec, Path, PSModulePath, Public, TEMP and TMP ๊ฐ path hijacking์ด ๋ง์ด ์ผ์ด๋๋ ์์น๋ผ๊ณ ํ๋ค.
ComSpec=C:\Windows\system32\cmd.exe Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Amazon\cfn-bootstrap\;C:\Program Files\Aurora-Agent;C:\Program Files\dotnet\;C:\Program Files\TortoiseSVN\bin;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\Scripts\;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\;C:\Users\Administrator\AppData\Local\Microsoft\WindowsApps; PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\AWS Tools\PowerShell\
PUBLIC=C:\Users\PublicTEMP=C:\Users\ADMINI~1\AppData\Local\Temp\2
TMP=C:\Users\ADMINI~1\AppData\Local\Temp\2sers\Administrator\Desktop\tools\shells>set > env_vars.txt C:\Users\Administrator\Desktop\tools\shells>type env_vars.txt ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\Administrator\AppData\Roaming CLIENTNAME=kali CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files COMPUTERNAME=CCTL-WS-018-B21 ComSpec=C:\Windows\system32\cmd.exe DriverData=C:\Windows\System32\Drivers\DriverData HOMEDRIVE=C: HOMEPATH=\Users\Administrator LOCALAPPDATA=C:\Users\Administrator\AppData\Local LOGONSERVER=\\CCTL-WS-018-B21 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Amazon\cfn-bootstrap\;C:\Program Files\Aurora-Agent;C:\Program Files\dotnet\;C:\Program Files\TortoiseSVN\bin;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\Scripts\;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\;C:\Users\Administrator\AppData\Local\Microsoft\WindowsApps; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=AMD64 Family 23 Model 1 Stepping 2, AuthenticAMD PROCESSOR_LEVEL=23 PROCESSOR_REVISION=0102 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files PROMPT=$P$G PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\AWS Tools\PowerShell\ PUBLIC=C:\Users\Public SESSIONNAME=RDP-Tcp#0 SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\ADMINI~1\AppData\Local\Temp\2 TMP=C:\Users\ADMINI~1\AppData\Local\Temp\2 USERDOMAIN=CCTL-WS-018-B21 USERDOMAIN_ROAMINGPROFILE=CCTL-WS-018-B21 USERNAME=Administrator USERPROFILE=C:\Users\Administrator windir=C:\Windows
๋ค์๊ณผ ๊ฐ์ ์ ๋ณด๋ฅผ ์ ์ ์์๋ค.
PowerShell ๊ฒฝ๋ก๋ ๋ณ๋ค๋ฅธ ๋ฌธ์ ๊ฐ ๋ณด์ด์ง ์๊ธฐ๋๋ฌธ์ ํ๋กํ ๊ฒฝ๋ก๋ฅผ ํ์ธํด์ฃผ๊ธฐ๋ก ํ๋ค.
powershell๊ณผ profile.ps1์ ์ ๋๊ฒฝ๋ก๋ฅผ where์ ์ด์ฉํด์ ์ฐพ์๋ณธ๋ค.
์ด์ powershell๊ณผ profile.ps1์ ์์น ์ ๋ณด๋ฅผ ์ด์ฉํ ์ ์๊ฒ ๋์๋ค.
C:\Users\Administrator\Desktop\tools\shells>where powershell.exe C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe C:\Users\Administrator\Desktop\tools\shells>where profile.ps1 C:\Users\Administrator\Desktop\tools\shells\profile.ps1 C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1
profile.ps1์ ์์ธ์ค๊ฐ ๊ฐ๋ฅํ์ง ๋ช ๋ น์ด๋ฅผ ์ ๋ ฅํด๋ณธ๋ค.
๊ทธ ๋ค์์๋, profile.ps1์ ๋ด์ฉ์ ๋คํํ๊ณ txtํ์ผ์ ์ฝ์ด๋ณธ๋ค. ์ด๋ก์ event-triggered execution (ATT&CK ID: 1546.013)๋ฅผ ํ์ธํ ์ ์์๋ค.
if exist "C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1" (echo PROFILE EXISTS) else (echo PROFILE DOES NOT EXIST)
type "C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1" > ps_profile_dump.txt
PS-DFIR์ ์์ธ์คํ ๋๋ ๋ฐ๋ก ์คํํด๋ ๋์ง๋ง cmd์ฐฝ์ PS-DFIR.exe๋ฅผ ์ ๋ ฅํด์ค๋ ๋๋ค.
Get-Module | ft ModuleType, Version, Name | tee ps-mods-loaded-modules.txt
PS-DFIR์ ๊ด๋ฆฌ์ ๊ถํ์ผ๋ก ์คํํ๊ณ Get-Module ๋ช ๋ น์ด๋ฅผ ๊ณ์ ์ฌ์ฉํด์ค ์์ ์ด๋ค.
ft ๋ช ๋ น์ด๋ฅผ ํตํด ps ๋ชจ๋์ ps_ModuleType, Version, Name ์ ๋ณด๋ฅผ ๊ฐ์ ธ์จ๋ค.
Get-Module -ListAvailable | select ModuleType, Version, Name | tee ps-mods-all.txt
ModuleType Version Name ---------- ------- ---- Manifest 3.1.0.0 Microsoft.PowerShell.Management Manifest 3.1.0.0 Microsoft.PowerShell.Utility Script 2.0.0 PSReadline
PS C:\Users\Administrator\Desktop\tools\shells> Get-Module -ListAvailable | select ModuleType, Version, Name | tee ps-mods-all.txt ModuleType Version Name ---------- ------- ---- Script 0.4.7 powershell-yaml Script 1.0.1 Microsoft.PowerShell.Operation.Validation Binary 1.0.0.1 PackageManagement Script 3.4.0 Pester Script 1.0.0.1 PowerShellGet Script 2.0.0 PSReadline Manifest 1.0.1.0 ActiveDirectory Manifest 1.0.0.0 AppBackgroundTask Manifest 2.0.0.0 AppLocker Manifest 1.0.0.0 AppvClient Manifest 2.0.1.0 Appx Manifest 1.0 BestPractices Manifest 2.0.0.0 BitsTransfer Manifest 1.0.0.0 BranchCache Manifest 1.0.0.0 CimCmdlets Manifest 1.0 ConfigCI Manifest 1.0 ConfigDefender Manifest 1.0 ConfigDefenderPerformance Manifest 1.0 Defender Manifest 1.0.1.0 DeliveryOptimization Binary 2.0.0.0 DFSR Manifest 1.0.0.0 DirectAccessClientComponents Script 3.0 Dism Manifest 1.0.0.0 DnsClient Manifest 1.0.0.0 EventTracingManagement Manifest 1.0.0.0 GroupPolicy Binary 2.0.0.0 Hyper-V Binary 1.1 Hyper-V Manifest 2.0.0.0 International Manifest 1.0.0.0 iSCSI Manifest 2.0.0.0 IscsiTarget Script 1.0.0.0 ISE Manifest 1.0.0.0 Kds Manifest 1.0.1.0 Microsoft.PowerShell.Archive Manifest 3.0.0.0 Microsoft.PowerShell.Diagnostics Manifest 3.0.0.0 Microsoft.PowerShell.Host Manifest 1.0.0.0 Microsoft.PowerShell.LocalAccounts Manifest 3.1.0.0 Microsoft.PowerShell.Management Script 1.0 Microsoft.PowerShell.ODataUtils Manifest 3.0.0.0 Microsoft.PowerShell.Security Manifest 3.1.0.0 Microsoft.PowerShell.Utility Manifest 3.0.0.0 Microsoft.WSMan.Management Manifest 1.0 MMAgent Manifest 1.0.0.0 MsDtc Manifest 2.0.0.0 NetAdapter Manifest 1.0.0.0 NetConnection Manifest 1.0.0.0 NetDiagnostics Manifest 1.0.0.0 NetEventPacketCapture Manifest 2.0.0.0 NetLbfo Manifest 1.0.0.0 NetNat Manifest 2.0.0.0 NetQos Manifest 2.0.0.0 NetSecurity Manifest 1.0.0.0 NetSwitchTeam Manifest 1.0.0.0 NetTCPIP Manifest 1.0.0.0 NetWNV Manifest 1.0.0.0 NetworkConnectivityStatus Manifest 1.0.0.0 NetworkSwitchManager Manifest 1.0.0.0 NetworkTransition Manifest 1.0 NFS Manifest 1.0.0.0 Nps Manifest 1.0.0.0 PcsvDevice Binary 1.0.0.0 PersistentMemory Manifest 1.0.0.0 PKI Manifest 1.0.0.0 PlatformIdentifier Manifest 1.0.0.0 PnpDevice Manifest 1.1 PrintManagement Binary 1.0.11 ProcessMitigations Manifest 1.1 PSDesiredStateConfiguration Script 1.0.0.0 PSDiagnostics Binary 1.1.0.0 PSScheduledJob Manifest 2.0.0.0 PSWorkflow Manifest 1.0.0.0 PSWorkflowUtility Manifest 3.0.0.0 RemoteAccess Manifest 2.0.0.0 RemoteDesktop Manifest 1.0.0.0 ScheduledTasks Manifest 2.0.0.0 SecureBoot Manifest 1.0.0.0 SecurityCmdlets Script 1.0.0.0 ServerCore Script 2.0.0.0 ServerManager Cim 1.0.0.0 ServerManagerTasks Manifest 2.0.0.0 SmbShare Manifest 2.0.0.0 SmbWitness Manifest 2.0.0.0 SoftwareInventoryLogging Manifest 1.0.0.0 StartLayout Manifest 2.0.0.0 Storage Manifest 1.0.0.0 StorageBusCache Manifest 2.0.0.0 TLS Manifest 1.0.0.0 TroubleshootingPack Manifest 2.0.0.0 TrustedPlatformModule Binary 2.1.639.0 UEV Manifest 2.0.0.0 UpdateServices Manifest 1.0.0.0 UserAccessLogging Manifest 2.0.0.0 VpnClient Manifest 1.0.0.0 Wdac Manifest 2.0.0.0 Whea Manifest 1.0.0.0 WindowsDeveloperLicense Script 1.0 WindowsErrorReporting Manifest 1.0.0.0 WindowsSearch Manifest 1.0.0.0 WindowsUpdate Manifest 1.0.0.2 WindowsUpdateProvider Binary 4.1.9.0 AWSPowerShell PS C:\Users\Administrator\Desktop\tools\shells>
HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest
ํ์ทจ๋นํ ์ ๋ณด์ ๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก๋ (HKLM)์ด๋ผ๊ณ ์ ํ ๋ด์ฉ์ ํตํด ํ์ธํ ์ ์์๋ค.
๋ง์ฐฌ๊ฐ์ง๋ก profile.bak์๋ ps_profile_dump.txt์ ๊ฒน์น๋ ๋ด์ฉ๋ค์ด ์ ํ์์๋ค.
๋ txt, bak ํ์ผ์์ log๋ฅผ ์ง์ฐ๊ธฐ ์ํด ์ฌ์ฉ๋ ํด์ ์ด๋ฆ๊ณผ stealํ๊ธฐ ์ํ ๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก๊ฐ ์ ํ์ก๋ค.
Task 5 System Profile
์์คํ ์ธ๋ถ ์ ๋ณด ๋ฐ ๊ตฌ์ฑ / ์์คํ ํ๋กํ ์ ๋ณด ํ์ํ๊ธฐ
์ด๊ณณ์์๋ ๋คํธ์ํฌ ์ธํฐํ์ด์ค ์ธ๋ถ์ ๋ณด, ํธ์คํธ ๋ค์, OS ๋ฒ์ , ์ํคํ ์ฒ ์ ๋ณด, ์์คํ ์๊ฐ, ๋ก์ปฌ ์ ์ฑ ์ค์ ์ ํ์ธํ ์ ์๋ค.
Get-CimInstance win32_networkadapterconfiguration -Filter IPEnabled=TRUE | ft DNSHostname, IPAddress, MACAddress | tee interfaces.txt
์ฌ์ฉ์์ ์ด๊ธฐ ๋งฅ๋ฝ ์ ๋ณด๋ฅผ ์ดํดํ๊ธฐ ์ํด ์์คํ ํ๋กํ์ ํ์ธํด์ผ ํ๋ค.
๋จผ์ Get-CimInstance๋ฅผ ํตํด ํธ์คํธ ๋คํธ์ํฌ ์ธํฐํ์ด์ค ์ ๋ณด์ IP์ฃผ์์ IPv4, IPv6, MAC ์ ๋ณด๋ค์ ์์๋ณผ ์ ์๋์ง ํ์ธํด๋ณด๊ฒ ๋ค.
Get-CimInstance -ClassName Win32_OperatingSystem | fl CSName, Version, BuildNumber, InstallDate, LastBootUpTime, OSArchitecture | tee sysinfo.txt
ํด๋น ๋ช ๋ น์ด๋ ์๊ฐ์ ๋ํ ์ ๋ณด๋ฅผ ์๋ ค์ค๋ค. InstallDate์ LastBootUpTime์ ์ค์ํ๊ฒ ๋ณผ ๋งํ ์ ๋ณด์ธ ๊ฒ ๊ฐ๋ค.
์ด๋ ํ์ฌ ํธ์คํธ์ OS ๋ฒ์ ๊ณผ ์์คํ ๊ด๋ฆฌ์์ ์ ๋ณด๊ฐ ์ผ์นํ์ง ์๋ ๊ฒ๊ฐ๋ค. (10.0.17763 - 10.0.25398)
์ด ์ ๋ณด๋ฅผ ๋ฐํ์ผ๋ก ๋ค์ ์ ๋ณด๋ฅผ ์ฐพ์๋ณธ๋ค.
Get-Date | tee systime.txt ; Get-TimeZone | tee systime.txt -Append
์์คํ ๋ ์ง์ ์๊ฐ ์ ๋ณด๋ฅผ ํ์ธํ ์ ์๋ ๋ช ๋ น์ด๋ฅผ ์ ๋ ฅํด์ฃผ์๋ค.
Date ID๋ Turkey Standard Time์ ํ์ธํ ์ ์๋ค.
System Profile์ ํตํด ์์๋ธ ์ ๋ณด๋ค์ ์ฐพ์์ ์ ๋ ฅํ๋ฉด ํต๊ณผํ ์ ์์๋ค.
Task 6 Users and Sessions
์ฌ์ฉ์ ๋ฐ ์ธ์
์ด๊ณณ์์๋ ๋ก์ปฌ ์ฌ์ฉ์ ์๋ณ, ๊ทธ๋ฃน ์๋ณ, ํ์ฑ ์ฌ์ฉ์ ์ธ์ ์๋ณ์ ํ์ธํ ์ ์๋ค.
์ฌ์ฉ์ ๊ณ์ ๋ก๊ทธ์ธ, ์คํ, ํ๋ก์ธ์ค ํ๋์ ๋ฐ๊ฒฌํ๊ณ , ์ด ์ค ์ ์ฉ๋ ์ฌ์ฉ์๋ ๊ทธ๋ฃน์ด ์๋์ง ํ์ธํด๋ณธ๋ค.
Get-LocalUser | tee l-users.txt
Get-CimInstance -Class Win32_UserAccount -Filter "LocalAccount=True" | Format-Table Name, PasswordRequired, PasswordExpires, PasswordChangeable | Tee-Object "user-details.txt"
์ฌ์ฉ์ ์ ๋ณด๋ฅผ ํ์ธํ ์ ์๋ค. ์ด๋, Admin ๋ก์ปฌ ์ฌ์ฉ์ ๊ณ์ ์ 3๊ฐ ์๋ค๋ ์ ์ ์ ์ํ๋ค.
Guest์์ PasswordRequired๊ฐ False์ด๋ค. ๊ฒ์คํธ ๊ณ์ ์ด ํ์ค์๋๋ฅผ ์๊ตฌ๋ฐ์ง ์๋๋ค๋ ์ ์ด ์ทจ์ฝํ๋ค.
Get-LocalGroup | ForEach-Object { $members = Get-LocalGroupMember -Group $_.Name; if ($members) { Write-Output "`nGroup: $($_.Name)"; $members | ForEach-Object { Write-Output "`tMember: $($_.Name)" } } } | tee gp-members.txt
์์์ ๋ดค๋ admin ๊ทธ๋ฃน์ ์๋ member์ ํ์ธํด์ค๋ค. ์ฌ๋ฌ ๊ฐ์ ๊ณ์ ์ด๋ admin ๊ทธ๋ฃน์ ๊ถํ์ ๊ฐ์ง๊ณ ์๋ค. ์ด ์์ํ ์งํ๋ฅผ ์ ์ํด์ ๊ธฐ์ตํด๋ณด์์ผ๊ฒ ๋ค.
์ด ๋ค์์๋ ์ฌ์ฉ์ ์ธ๋ถ ์ ๋ณด๋ฅผ ๋ ์์๋ณผ ์์ ์ด๋ค.
Guest์ SID๋๋ฒ์ ๋ง์ง๋ง ๋ก๊ทธ์ธ ์๊ฐ์ ์์๋ณธ๋ค.
์ ์ด๋ค ์ด์ ๋ก PasswordLastSet์ด ํ์ฌ ๋ ์ง๋ก ๋ํ๋๋์ง ์ ๋ชจ๋ฅด๊ฒ ๋ค..
์๋ฌดํผ Guest ์ฌ์ฉ์์ ๋ํด ๋ ์ธ๋ถ์ ์ผ๋ก ํ์ธํด์ค ๋ชจ์ต์ด๋ค.
์ด์ tools์ utils ํด๋๋ก ์ด๋ํด์ ๋ช ๋ น์ด๋ฅผ ์ ๋ ฅํด ์ ๋ณด๋ฅผ ํ์ธํด๋ณผ ๊ฒ์ด๋ค.
Users logged on locally์ 8์ 8์ผ๋ก ๋์ค๋ฉด ์๋๋๋ฐ ์ด์งธ์์ธ์ง ์ ๋ ๊ฒ ๋์จ๋ค..
์๋ฌดํผ ์ด๊ณณ์์๋ Administrator๊ณผ Guest์ ์์ํ ๋ ๋ช ์ ๋ก๊ทธ์ธ ์ฌ์ฉ์ ๋ก๊ทธ๊ฐ ๋ํ๋๋ค.
์๋ฌด๋๋ Administrator์ ์ฐ๋ฆฌ๊ฐ ์๋ ๊ณณ์ด๋๊น ์ ๋ ๊ฒ ์ถ๋ ฅ๋๋๊ฒ ๋ง๋ ๊ฒ ๊ฐ๊ณ , Guest์์ ์์ํ ์ ๊ทผ์ด ๋ฐ๊ฒฌ๋์๋ค๋ ์ ์ด ์ ์ํ ๋ง ํ๋ค.
๋ง์ฐฌ๊ฐ์ง๋ก ์์์ ์ป์ ์ ๋ณด๋ฅผ ํตํด Guest์ ๊ด๋ จ๋ ์ ๋ณด์ ๋ก๊ทธ์ธํ ์๊ฐ๋๋ฅผ ์ ๋ ฅํด๋ณธ๋ค. ๊ทธ๋ผ ์ ๋ต์ธ ๊ฒ์ ์ ์ ์๋ค.
Task 7 Network Scope
๋คํธ์ํฌ ๋ฒ์
๋คํธ์ํฌ ํ์ฑ ํฌํธ, ์ฐ๊ฒฐ ์ ๋ณด๋ฅผ ํ์ธํ๊ณ , ๋คํธ์ํฌ ์์น์ ๋ฐฉํ๋ฒฝ ๊ท์น์ ํ์ธํ๋ค.
TCP, UDP์์์ ์์ฌ์ค๋ฌ์ด ์ฐ๊ฒฐ์ ํ์ธํ๊ณ , ๋ฐฉํ๋ฒฝ์์ ์์ธ๊ฐ ์๋ ์์ํ ํ๋ก์ธ์ค ํ๋์ ๋งคํํด๋ณธ๋ค.
์.. ๋ฒํผ์ฌ์ด์ฆ ๋๋ฌธ์ ํ ์คํธ๊ฐ ์ผ๋ถ ์๋ต๋์ด์ ๋์ ์ฐ์ฌ๊ณก์ ์ ์กฐ๊ธ ๊ฒช์๋ค.
์ผ๋จ ์ต๋ํ ํ์์ ๊ธ์๊ฐ ๋ชจ๋ ์ถ๋ ฅ๋ ์ ์๋๋ก ํ๊ณ ๋ต์ ์ฐพ์๋ณด์๋ค.
TCP-conn.txt๋ฅผ ํตํด TCP ํ์ฑ ํฌํธ์ ์ฐ๊ฒฐ์ ๊ฒํ ํด๋ณธ๋ค.
INITIAL_LANTERN์์ 50119์ 8888 ํฌํธ, ๊ทธ๋ฆฌ๊ณ ๊ฒฝ๋ก๋ฅผ ํ์ธํด๋ณด์.
ํด๋น ๊ฒฝ๋ก์์ ์์๋ ํ๋ก์ธ์ค๊ฐ ์ํํ๋ค๋ ๊ฒ์ ์ ์ ์๋ค. INITIAL_LANTERN์ ์ ์ฑ ํ๋ก์ธ์ค๋ค.
์ถ๊ฐ๋ก ๊ฐ์ ๋ฐฉ์์ผ๋ก UDP ํ๋์ ๊ฒํ ํ ์ ์๋ค.
๊ณต์ ๋ ๋คํธ์ํฌ ์ ๋ณด๋ฅผ ํ์ธํ ์ ์๋ ๋ช ๋ น์ด๋ ์๋ค.
๊ณต์ ํด๋๋ฅผ ํตํด ์ทจ์ฝ์ ์ด ๋ํ๋ ์ ์๋์ง ํ์ธํด๋ณด์.
FirewallProfile์ ๋ฐฉํ๋ฒฝ ์ ๋ณด๋ฅผ ํ์ธํ๋ ๊ณณ์ด๋ค. ๋ฐฉํ๋ฒฝ์์ ์๋์ ์ผ๋ก ๋ณ๊ฒฝ๋๊ฑฐ๋ ์ ์๋๋ ๊ท์น๋ค์ ์๋ณํ๋ค๋ฉด,
๊ทธ๊ฒ์ ๋งค์ฐ ์ค๋ํ ์ฌํญ์ด๋ค.
์ด๊ณณ์์ ํฐ ๋ฌธ์ ์ ์ ๋ํ๋์ง ์๋๋ค.
...
์ด๊ณณ์์ ๋ฐฉํ๋ฒฝ์ ๋น ๋ฅธ ๋ชฉ๋ก์ ์ ๊ณตํ๋ค. ์ด ๋ฆฌ์คํธ์์ ์ฃผ์ํด์ ํ์ธํด๋ด์ผํ ์ ์ AnyDesk์ LMV Co.์ด๋ค.
AnyDesk์ ๊ฒฝ๋ก์ LMV Co.์ ๋ฐฉํ๋ฒฝ ๊ท์น์ ์ ํ์ธํด๋ณด์.
์ถ๊ฐ๋ก, ์ด fw rules๋ ์กฐ๊ธ ์ ์ฌํ ๋ณด์๋ฌ์ผ ํ๋ค.
๋์ค์ ๋์ฌ NetSh๊ฐ ๋ฐฉํ๋ฒฝ๊ณผ ์ฐ๊ด๋์ด์์ผ๋ฏ๋ก, ์ด ๋ถ๋ถ์ ๊ฑด๋ค์ธ๋ค๋ ์ํ ์์ธก๋ ํด๋ณผ ์ ์์ ๊ฒ ๊ฐ๋ค.
์์ ์๋ฃ์ ์ ์ํด๋ณธ๋ค๋ฉด ์ ๋ต์ ์ ๋ ฅํ ์ ์๋ค.
Task 8 Background Activities I: Startup and Registry
์คํํธ์ ๊ณผ ๋ ์ง์คํธ๋ฆฌ
Task 8์์๋ ์์ ์ํ์ค์ ๋ ์ง์คํธ๋ฆฌ ์ธ๋ถ์ ๋ณด๋ฅผ ํ์ธํด๋ณธ๋ค. ๋ค์ํ ํ๋ก์ธ์ค๋ฅผ ํ์ธํ๊ณ ์๋ ์์ ํ๋ก๊ทธ๋จ, ๋ถํ ์คํ ํ์ผ, ๋ถํธ ํ์ผ ๋ฑ์ ํ์ ํ๋ค. ๋ชจ๋ ํ์ผ์ ์ถ์ ํ์ง ์๊ณ ์์ํ๊ฒ ๋ณด์ฌ์ง๋ ํ์ผ๋ค์ ์ค์ฌ์ ์ผ๋ก ๊ฒ์ฌํด๋ณด๋ ์ ๊ทผ ๋ฐฉ์์ ์ฌ์ฉํด๋ณด๊ฒ ๋ค.
๋ถํ ํ๋ก์ธ์ค์ ์ด์ ์ ๋ง์ถ boot.txt ์ ๋ณด๋ฅผ ์ฌ์ฉํ์ฌ HKLM ์ ๋ณด๋ฅผ ํ์ธํ๋ค. ๋ด์ฉ์ด ์๋นํ ๊ธธ์๋ ๊ฒ์ผ๋ก ๊ธฐ์ตํ๋ค.
์ฐ๊ฒฐ๋ ์คํ ํ์ผ, ์ฌ์ฉ์ ๊ณ์ , ํน์ DLL, ๋ ์ง์คํธ๋ฆฌ ๋ฑ์ ๋ํ ์์ธํ ์ ๋ณด๋ฅผ ์ฐพ์๋ณธ๋ค.
ํด๋น ์ธ ๊ฐ์ง์ ๋ด์ฉ์ ๋ค๋ฅธ ์ฌ์ฉ์ ํ๋กํ์ ํ ๋น๋์๋ค๋ ๊ฒ์ ์ ์ ์๋ค.
๋ก๊ทธ์จ ์ ๋ณด๋ฅผ ํ์ธํด๋ณด๋ ๋ช ๋ น์ด๋ฅผ ์ฌ์ฉํ๋ค. ๋ด์ฉ์ด ์ข ๊ธธ๊ธฐ๋๋ฌธ์ ๋์ค์ ์ฐธ๊ณ ํด๋ณด๋ ค๊ณ ์ ์ ๊ธ์ ์ ์ฒด ๋ด์ฉ์ ๋ฌ์๋์๋ค. userinit[.]exeํ์ผ์ ์ธ์ ์ ์ด๊ธฐํํ ๋ ๊ธฐ๋ณธ์ ์ผ๋ก ์ฌ์ฉ๋๋ค. ์ถ๊ฐ ์คํํ์ผ์ ๊ฐ์ง๊ณ ์๋ค๋ฉด ์กฐ๊ธ ์ด๋ก์ ์ธ ์ํฉ์ด๋ผ๊ณ ํด๋ณผ ์ ์๋ ๊ฒ ๊ฐ๋ค.
๋๋ณด๊ธฐPS C:\Users\Administrator\Desktop\tools\utils> .\autorunsc64.exe -a l * -h | tee logon.txt Sysinternals Autoruns v14.10 - Autostart program viewer Copyright (C) 2002-2023 Mark Russinovich Sysinternals - www.sysinternals.com HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms rdpclip rdpclip RDP Clipboard Monitor Microsoft Corporation 10.0.17763.1697 c:\windows\system32\rdpclip.exe 11/27/1964 2:17 PM MD5: BFE0CEE883BD55C7691E7C1027E2332B SHA1: 50E594B78FF88CE4E93E7293BBD15AD3C5AB3E5A PESHA1: AC638AA87A8FCF006D24DE029DF4EE04A906B069 SHA256: 4972CF79E61A6FF0C4EA410D55C7DEB00D7F799EA958946FCC2EE7FABF13FFEB PESHA256: 5533D791C16FF754A315497807ECB5707C2437E85C4C8D5BD55A7D3001E76025 IMPHASH: E3F33CEBF67721DAC951AFBD20321206 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit C:\Windows\system32\userinit.exe C:\Windows\system32\userinit.exe Userinit Logon Application Microsoft Corporation 10.0.17763.1 c:\windows\system32\userinit.exe 12/31/1958 2:49 PM MD5: BF8825D08BC235F0609CA8BBEF4E179C SHA1: 470C3E60F9B2B6D83F95C7916A5361E34DEC3471 PESHA1: DF688108336B5E2AC79D652521CAE6F14BC4D450 SHA256: 1FE7F7C59EC7EAA276739FA85F7DDA6136D81184E0AEB385B6AC9FEAAA8C4394 PESHA256: A5160EF5F4B97E938DA7E956A3331FB66EA3F9EA7E7D8BEEF313F318F2C11B98 IMPHASH: 8419D97ABDFEB6C320F0C39028647572 cmd.exe cmd.exe Windows Command Processor Microsoft Corporation 10.0.17763.1697 c:\windows\system32\cmd.exe 5/30/2008 3:32 AM MD5: 911D039E71583A07320B32BDE22F8E22 SHA1: DED8FD7F36417F66EB6ADA10E0C0D7C0022986E9 PESHA1: 8F4C943F540AB1BFD6DD2A2820FA9EE7794CE550 SHA256: BC866CFCDDA37E24DC2634DC282C7A0E6F55209DA17A8FA105B07414C0E7C527 PESHA256: 5F98D08805D4EEE36337C81914F0D82191A4D58D24EA2FF2E522A95A5D6E5B73 IMPHASH: 272245E2988E1E430500B852C4FB5E18 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet SystemPropertiesPerformance.exe SystemPropertiesPerformance.exe Change Computer Performance Settings Microsoft Corporation 10.0.17763.1 c:\windows\system32\systempropertiesperformance.exe 12/27/1907 4:03 AM MD5: AB32E55D2DAC9E9427F89D835054F8D7 SHA1: 5ED9658FA4DD4D1EC70157F148D4AE7ABDDE4B66 PESHA1: 284D49497AB1D71F4F6AB471A42B322BA185D5A5 SHA256: 357BDAD469524CDF42680FF44E17CE41C64B38872C4F55E89DE0560FBD003693 PESHA256: E0B8AB13E07B8599AE6187EBAE82422D6D9AC879C2264DE3E8E32D1A816A6340 IMPHASH: 835402499FB5903791DBBE73881263B5 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell explorer.exe explorer.exe Windows Explorer Microsoft Corporation 10.0.17763.1697 c:\windows\explorer.exe 9/21/2012 3:10 AM MD5: 85352486405EFFBAE1240DECDA20C2A0 SHA1: 6FC4D5F0A813473CC44297EE165355028CE7C090 PESHA1: 8C3C012F72305B667CC3CC8DC21D8073393D1C14 SHA256: E2B62E2A745CA56AA4E2EB7B9369DA7714E481304B29F3DE884369EB27D835D4 PESHA256: 05E296AC3EDCEA8B93629D1B931F115277FF040D85EF5F0EB0F8ED28A27156BF IMPHASH: 3EF052F18C0AF035F409392A87FD0B19 HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell cmd.exe cmd.exe Windows Command Processor Microsoft Corporation 10.0.17763.1697 c:\windows\system32\cmd.exe 5/30/2008 3:32 AM MD5: 911D039E71583A07320B32BDE22F8E22 SHA1: DED8FD7F36417F66EB6ADA10E0C0D7C0022986E9 PESHA1: 8F4C943F540AB1BFD6DD2A2820FA9EE7794CE550 SHA256: BC866CFCDDA37E24DC2634DC282C7A0E6F55209DA17A8FA105B07414C0E7C527 PESHA256: 5F98D08805D4EEE36337C81914F0D82191A4D58D24EA2FF2E522A95A5D6E5B73 IMPHASH: 272245E2988E1E430500B852C4FB5E18 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells\AvailableShells 30000 cmd.exe /c "cd /d "%USERPROFILE%" & start cmd.exe /k runonce.exe /AlternateShellStartup" File not found: cd /d 60000 explorer.exe Windows Explorer Microsoft Corporation 10.0.17763.1697 c:\windows\explorer.exe 9/21/2012 3:10 AM MD5: 85352486405EFFBAE1240DECDA20C2A0 SHA1: 6FC4D5F0A813473CC44297EE165355028CE7C090 PESHA1: 8C3C012F72305B667CC3CC8DC21D8073393D1C14 SHA256: E2B62E2A745CA56AA4E2EB7B9369DA7714E481304B29F3DE884369EB27D835D4 PESHA256: 05E296AC3EDCEA8B93629D1B931F115277FF040D85EF5F0EB0F8ED28A27156BF IMPHASH: 3EF052F18C0AF035F409392A87FD0B19 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SecurityHealth %windir%\system32\SecurityHealthSystray.exe Windows Security notification icon Microsoft Corporation 10.0.17763.1 c:\windows\system32\securityhealthsystray.exe 7/2/1906 5:12 AM MD5: 09F3F2298DDA6EBB57B12C530D35C52C SHA1: D7FC50DC0A08C9EC089E428A03606EE4A2E8C759 PESHA1: 258864A6871EEA36380479F2885C0B1B327DC455 SHA256: 48F852164EF4747FCDDFF463034CAD33167E341D241536B122AE74FC8841C941 PESHA256: 4A942D68E3E6456C8D940B868E8512B01FA753CD662B29F2AFB3ADE88E722092 IMPHASH: 44315EF1FEB6193B3AB5492033CEFAAE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup AnyDesk.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk AnyDesk AnyDesk Software GmbH 8.0.10.0 c:\program files (x86)\anydesk\anydesk.exe 4/24/2024 3:53 PM MD5: AEE6801792D67607F228BE8CEC8291F9 SHA1: BF6BA727FF14CA2FDDF619F292D56DB9D9088066 PESHA1: 83127A3EBEF4B2456465B43B6CF3E8878D3EA080 SHA256: 1CDAFBE519F60AAADB4A92E266FFF709129F86F0C9EE595C45499C66092E0499 PESHA256: 7A27A90AFDE3731D85C6A950746A3A5EF5A7321646E8F74679B3D6AD39C28241 HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /ShowWMP Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.17763.1 c:\windows\system32\unregmp2.exe 9/30/1990 10:30 AM MD5: 9CF8E80F71544316E5F90F2B87F2350C SHA1: 5D5BF791D38DF29D52F4585A6853FC8242CDB73C PESHA1: 60A53C9A311C3DBB32BC22517FAC97750D01C716 SHA256: DF160ACED402899269A07872038E7CEBE64CBB24DD09D8A4474B12AA6F760653 PESHA256: B05E2B6C7C1DA403546ED91EEAEE303357ED400BFD36E0A36EA175767D41C2F2 IMPHASH: 1DE1DA351E000239456F4F921473BDC8 Themes Setup themeui.dll Windows Theme API Microsoft Corporation 10.0.17763.1697 c:\windows\system32\themeui.dll 12/19/1948 5:05 PM MD5: 00CA0E4BEC8DD38B6026B431F813B00F SHA1: 195BF8AF3659065B24CB0A7603F856311B6C9A72 PESHA1: FD56F156F2436321C2D054582B9D7CF9773DDDE2 SHA256: CC1BD1B9771E1DC6424F4955FE537A84C215A6B0C4D46D44A33251F8F362CE4A PESHA256: 575265F6C1EAFF465D041CEEF954EA2DB4626738342E0DFBA3B5566F856F7138 IMPHASH: 3377BF4AD60C0566FBECF4212621B1A1 Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /FirstLogon Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.17763.1 c:\windows\system32\unregmp2.exe 9/30/1990 10:30 AM MD5: 9CF8E80F71544316E5F90F2B87F2350C SHA1: 5D5BF791D38DF29D52F4585A6853FC8242CDB73C PESHA1: 60A53C9A311C3DBB32BC22517FAC97750D01C716 SHA256: DF160ACED402899269A07872038E7CEBE64CBB24DD09D8A4474B12AA6F760653 PESHA256: B05E2B6C7C1DA403546ED91EEAEE303357ED400BFD36E0A36EA175767D41C2F2 IMPHASH: 1DE1DA351E000239456F4F921473BDC8 Windows Desktop Update shell32.dll Windows Shell Common Dll Microsoft Corporation 10.0.17763.1790 c:\windows\system32\shell32.dll 3/3/2006 6:59 AM MD5: 1B9EE5E4CEDD2F92BEF642FB702D6D69 SHA1: 2A8CAD3EA362363DBC8DD0B5EC85C81E2729A362 PESHA1: AC500D1C23DD77B5654AE07EF3DCE4A24ABA1196 SHA256: 79A2D653304A352E6BCF7E33E0C3EC42B5A629505DF09D40432F5F4094872A1A PESHA256: 00D718B7A32FF336FF493B8EDCCAE41303B400EC00BD512225A48019A9BD5ADA IMPHASH: 4C6A425B69AD3E18ACE611520E54E884 Web Platform Customizations C:\Windows\System32\ie4uinit.exe -UserConfig IE Per-User Initialization Utility Microsoft Corporation 11.0.17763.652 c:\windows\system32\ie4uinit.exe 7/11/1981 12:04 AM MD5: A52B135E1865F98C90BF23B3807E51C0 SHA1: BF142E7FA17591BAF7D97E342781C8BCA8545C63 PESHA1: 5F223F5350D78F32C311B521A04233DF8966A9D9 SHA256: 46A3D721ADB36114A5141E5795E4DFC02644FDF8F6C602BCCFDC057784F29DB0 PESHA256: 12C51A253AD15B14BA64730360801B3A1D5DCF8DCB82C9C9ACA996852D2692DB IMPHASH: B898E7CB8AA65CE3FA6187EE093D7F6B n/a C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install Microsoft .NET IE SECURITY REGISTRATION Microsoft Corporation 2.0.50727.9031 c:\windows\system32\mscories.dll 8/8/2018 6:18 AM MD5: 55E13DD52266781390123239FCB59E7B SHA1: 91037E05C0F49595C230E26789A936CF492FF830 PESHA1: 9CA91E3C8E0008B1DEB963FEBEB03DD323B4E111 SHA256: B2E30D3E728A1960F7C847C2E3B0EB616F56D309359796D543EB910B8DF07CA5 PESHA256: B5899C49522601181D36D9FBF8DD4EC6366B41CA9D81E70002F5D4EC22939468 IMPHASH: AB8FA7A93A14C9EDE0B84EB9ECAFBAC2 Google Chrome "C:\Program Files\Google\Chrome\Application\126.0.6478.114\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable Google Chrome Installer Google LLC 126.0.6478.114 c:\program files\google\chrome\application\126.0.6478.114\installer\chrmstp.exe 6/17/2024 11:55 PM MD5: 36F9F0B7186D6D8E52ED2A794D3A0CE1 SHA1: 5C79C4E65581239412BF19C0B2C8C27B94A866E6 PESHA1: 6ABCAF28B9FA3438564703FFBA57D41E8F06DD67 SHA256: 40C45622685F5F54588D5C397B7FB8FC509AC9F8446B0963AF314A541F18A69E PESHA256: 648721845B8F523CD8ADA22E899B48FD363A808B5D35D9084EC3529CF8D14D61 IMPHASH: 5EE2AB762FA8D4FC5F9A047C2ED853EA Applying Enhanced Security Configuration "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin IOD Version Map Microsoft Corporation 11.0.17763.1 c:\windows\system32\iesetup.dll 4/26/1955 4:49 AM MD5: 06D9E39994E9CB486B07E05CAAC321C1 SHA1: CB8936D04D9A992163B8F236EFC3B8BAFD4F26D3 PESHA1: 73268C53C41034163A91399059DA2B30E892DCDE SHA256: BE2C5ADB7445D8102848E51BF77A03C7A731C456F241C2A0B39CC852DEE5CD97 PESHA256: B90BA7691A93810CBD2D099A0971A7B0AF4EE1360FEEC084937C5CDA5E885D7E IMPHASH: FFD26F19E29CEF9F551DED1D2FA50CF8 Applying Enhanced Security Configuration "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser IOD Version Map Microsoft Corporation 11.0.17763.1 c:\windows\system32\iesetup.dll 4/26/1955 4:49 AM MD5: 06D9E39994E9CB486B07E05CAAC321C1 SHA1: CB8936D04D9A992163B8F236EFC3B8BAFD4F26D3 PESHA1: 73268C53C41034163A91399059DA2B30E892DCDE SHA256: BE2C5ADB7445D8102848E51BF77A03C7A731C456F241C2A0B39CC852DEE5CD97 PESHA256: B90BA7691A93810CBD2D099A0971A7B0AF4EE1360FEEC084937C5CDA5E885D7E IMPHASH: FFD26F19E29CEF9F551DED1D2FA50CF8 HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /ShowWMP Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.17763.1 c:\windows\syswow64\unregmp2.exe 1/3/2036 12:22 PM MD5: 33A85B3DCFFEADA67C98EAC342B93DCB SHA1: 33856AD378DB2ECEAEF0C7F4817995A277F25592 PESHA1: 34E5C7262181A1476F88271FA43385C7BAB7F6CD SHA256: 1DF2F5FC3369F5901068AD9463D7A165FD8E7EE7A12CA6C1A88992BB1484632E PESHA256: F78219179657C76950961DE298BE9A5875E7A643646F21DD533DDDA1FA319067 IMPHASH: 567DEBB2A156B506ED421C435F1B2E33 Microsoft Windows Media Player %SystemRoot%\system32\unregmp2.exe /FirstLogon Microsoft Windows Media Player Setup Utility Microsoft Corporation 12.0.17763.1 c:\windows\syswow64\unregmp2.exe 1/3/2036 12:22 PM MD5: 33A85B3DCFFEADA67C98EAC342B93DCB SHA1: 33856AD378DB2ECEAEF0C7F4817995A277F25592 PESHA1: 34E5C7262181A1476F88271FA43385C7BAB7F6CD SHA256: 1DF2F5FC3369F5901068AD9463D7A165FD8E7EE7A12CA6C1A88992BB1484632E PESHA256: F78219179657C76950961DE298BE9A5875E7A643646F21DD533DDDA1FA319067 IMPHASH: 567DEBB2A156B506ED421C435F1B2E33 n/a C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install Microsoft .NET IE SECURITY REGISTRATION Microsoft Corporation 2.0.50727.9031 8/8/2018 6:28 AM MD5: 7A0B0FBB84ADECDCDF8DBAE89298B3DE SHA1: 4C2EFC4FE459CBF8D9B7784815169769A221E1DF PESHA1: B3AAF6C889C93561075CFBC96080B4C6C57F3229 SHA256: 6B46626A1EEF501F527160B10675862368887258766EFE8CEFAAE1E13C88B887 IMPHASH: 08A027E94DD9452BDF5B6AF03B573759 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\IconServiceLib IconCodecService.dll IconCodecService.dll Converts a PNG part of the icon to a legacy bmp icon Microsoft Corporation 10.0.17763.1 c:\windows\system32\iconcodecservice.dll 5/9/1956 3:37 AM MD5: 6B67CE980C9D91D60015E0CB12945A04 SHA1: C3139884E31F50184C6C33B429B1260460562316 SHA256: 80621FCB7C569830404A0355C57B35FDEDB9E74B773B539E84AC3674C8283705 PESHA256: B979B6A3F3380266FBD05320B8BE935A78DE123DAA6C50B61AC4FFB8F808DCEC IMPHASH: BC4916A3897FAE424D0E5B39B694361B HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup RunWallpaperSetup.cmd C:\Users\Adminstrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunWallpaperSetup.cmd c:\users\adminstrator\appdata\roaming\microsoft\windows\start menu\programs\startup\runwallpapersetup.cmd 2/27/2024 2:45 PM MD5: FA9D7A03029739B5B2001E922E850A64 SHA1: 05276AE99DCAF6C6F1B9765EF8A035AA86060B86 PESHA1: 05276AE99DCAF6C6F1B9765EF8A035AA86060B86 SHA256: 73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7 PESHA256: 73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup RunWallpaperSetup.cmd C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunWallpaperSetup.cmd c:\users\guest\appdata\roaming\microsoft\windows\start menu\programs\startup\runwallpapersetup.cmd 2/28/2024 10:58 AM MD5: FA9D7A03029739B5B2001E922E850A64 SHA1: 05276AE99DCAF6C6F1B9765EF8A035AA86060B86 PESHA1: 05276AE99DCAF6C6F1B9765EF8A035AA86060B86 SHA256: 73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7 PESHA256: 73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7
์ฃผ์๊น๊ฒ ํ์ธํด๋ณด๋ผ๊ณ ์ ์๋ ์ ์ cmd.exe ํ์ผ๊ณผ userinit.exe๋ค.
์ ์ฃผ์๋ฅผ ๊ธฐ์ธ์ฌ์ผ ํ๋์ง ์กฐ๊ธ ๋ ์ ๊ฒ ๊ฐ๋ค. Winlogon ๊ณผ์ ์์ ๋ณดํต์ userinit.exe๋ง์ ๊ธฐ๋ณธ์ ์ผ๋ก ์ฌ์ฉํ์ง๋ง, cmd.exe๊ฐ ํจ๊ป ์คํ ํ๋ก์ธ์ค๋ก ์ ์๋์๊ธฐ ๋๋ฌธ์ด๋ค. ์ผ๋จ์ ์ด ๋ถ๋ถ์ ์ค์ํ๊ฒ ๋ ๋งํ ์ ๋ณด๋ก ๊ธฐ๋กํด๋๋ค.
๊ทธ๋ฌ๋ฏ๋ก Winlogon์ ๋ํ ์ ๋ณด๋ฅผ ์กฐ๊ธ ๋ ํ์ธํด์ฃผ์๋ค.
userinit ํค์๋ ๋ ๊ฐ์ ๊ฐ์ด ํฌํจ๋์ด ์๋ค.
cmd.exe์
"start /min netsh.exe -c"
์ด๋ฐ ๋ด์ฉ์ด ์๋ค. ๊ทธ๋ฐ๋ฐ cmd๋ก netsh.exe๋ฅผ ๊ตณ์ด ์กฐ์ฉํ ์์ํ ํ์๊ฐ ์์๊น..? ์์ํ๋ค. ์ฌ๊ธฐ์ ์คํ ํ์ผ์ด ์ฌ์ฉ์ ๋ชฐ๋ ์คํ๋๋ค๋ฉด ๊ทธ๊ฑด ํ์คํ ์์ฌ์ค๋ฝ๋ค. ์ด ํ๋์ ์กฐ๊ธ ๋ ์ถ์ ํด๋ณผ ์ ์์ ๊ฒ ๊ฐ๋ค. netsh.exe์ ๋ํด์๋ ์ข ๋ ์์๋ณผ ์ ์์์ผ๋ฉด ์ข๊ฒ ๋ค.
์ฌ์ฉ์๊ฐ ๋ก๊ทธ์ธ์ ํ์ ๋ ์๋์ผ๋ก ์์๋์ด์ผ ํ๋ ํ๋ก๊ทธ๋จ๊ณผ ๊ธฐ๋ณธ ์์น๋ฅผ ์ดํด๋ณด๋ ์ ๋ณด๋ฅผ ์ฝ์ด๋ณด๊ฒ ๋ค.
CurrentVersion\Run
ํด๋น ์์น๋ฅผ ๋ํ๋ด๊ณ ์๋ค. ๊ทธ๋ ๋ค๋ฉด NetSH๋?
NetSh๋ ์ฌ์ฉ์์ ๋์ ๋์ง ์๋ ๊ณณ์์ ์ ์ฌ์ ์ธ ํ๋์ ํ๊ณ ์๋ค. netshell ์คํ ํ์ผ์ dll์ ๋ก๋ํ๊ณ ์๋ค.
์ฌ๊ธฐ์ ๋์ ๋๋ dll ๋ช ์ .\fwshield.dll์ด๋ค. ์ผ๊ด์ ์ด์ง ์์ ๋ค๋ฅธ ํญ๋ชฉ์ ๋ฐ๊ฒฌํ ์ ์๋ค.
๋ญ๊ฐ ๋ฐฉํ๋ฒฝ ๊ท์น์ ๊ด๋ จ๋ ์ ๋ณด๋ฅผ ํ์ ํ์ ๋ NetSh๊ฐ ์ ์ฌ์ ์ผ๋ก ์คํ๋ ์ํ์ด ์๋ ๊ฒ ๊ฐ๋ค.
Task 9 Background Activities II: Services and Scheduled Items
์๋น์ค, ์์ฝ๋ ํญ๋ชฉ
์ด ์ค์ต์์๋ ๋ฐฑ๊ทธ๋ผ์ด๋์์ ์๋ํ๋ ์ง์์ ์ธ ์ฌ์ฉ ์๋น์ค ํจํด์ ํ์ธํด๋ณด๊ฒ ๋๋ค. ์์์ ๋ฐ๋ผ ์๋น์ค์ ์์ฝ๋ ์์ ์ด ์ ์งํ๋๊ณ ์๋์ง ์๋ณํด๋ด๋ ๊ฒ์ด ์ค์ํ ์์คํ ์ ๊ณผ์ ์ด๋ค. ํน์ ํ ํ๋ก์ธ์ค์ ์์ ์์๊ฐ ์์ํ์ง๋ ์์์ง, ์คํ ์ค์ธ ์๋น์ค์ ์ด์์ ์๋์ง ํ์ธํด๋ด์ผ ํ๋ค.
"Running Services:"; Get-CimInstance -ClassName Win32_Service | Where-Object { $_.State -eq "Running" } | Select-Object Name, DisplayName, State, StartMode, PathName, ProcessId | ft -AutoSize | tee services-active.txt
๋ค์์ ์คํ ์ค์ธ ํ๋ก์ธ์ค ์ ๋ณด๋ฅผ ๋์ดํ๋ ๋ช ๋ น์ด๋ฅผ ์ ๋ ฅํ ๊ฒ์ด๋ค. State, StartMode, PathName, ProcessId ์ ๋ณด๋ ์ด์์ด ์๋ ์ ๋ณด๋ฅผ ํ์ธํ๊ณ ๊ฒ์ฌํ ๋ ์ ์ฉํ ๋ถ๋ถ์ด ๋ ์ ์๋ค.
PS C:\Users\Administrator\Desktop\tools\utils> "Running Services:"; Get-CimInstance -ClassName Win32_Service | Where-Object { $_.State -eq "Running" } | Select-Object Name, DisplayName, State, StartMode, PathName, ProcessId | ft -AutoSize | tee services-active.txt Running Services: Name DisplayName State StartMode PathName ProcessId ---- ----------- ----- --------- -------- --------- AmazonSSMAgent Amazon SSM Agent Running Auto "C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe" 3488 AnyDesk AnyDesk Service Running Auto "C:\Program Files (x86)\AnyDesk\AnyDesk.exe" --service 1904 BFE Base Filtering Engine Running Auto C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p 1308 BrokerInfrastructure Background Tasks Infrastructure Service Running Auto C:\Windows\system32\svchost.exe -k DcomLaunch -p 748 CDPSvc Connected Devices Platform Service Running Auto C:\Windows\system32\svchost.exe -k LocalService -p 1116 CertPropSvc Certificate Propagation Running Manual C:\Windows\system32\svchost.exe -k netsvcs 1472 CoreMessagingRegistrar CoreMessaging Running Auto C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p 1572 CryptSvc Cryptographic Services Running Auto C:\Windows\system32\svchost.exe -k NetworkService -p 1176 DcomLaunch DCOM Server Process Launcher Running Auto C:\Windows\system32\svchost.exe -k DcomLaunch -p 748 Dhcp DHCP Client Running Auto C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p 1064 Dnscache DNS Client Running Auto C:\Windows\system32\svchost.exe -k NetworkService -p 1176 DPS Diagnostic Policy Service Running Auto C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p 1572 DsmSvc Device Setup Manager Running Manual C:\Windows\system32\svchost.exe -k netsvcs -p 952 DsSvc Data Sharing Service Running Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 EventLog Windows Event Log Running Auto C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p 1064 EventSystem COM+ Event System Running Auto C:\Windows\system32\svchost.exe -k LocalService -p 1116 FontCache Windows Font Cache Service Running Auto C:\Windows\system32\svchost.exe -k LocalService -p 1116 gpsvc Group Policy Client Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 IKEEXT IKE and AuthIP IPsec Keying Modules Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 iphlpsvc IP Helper Running Auto C:\Windows\System32\svchost.exe -k NetSvcs -p 952 KeyIso CNG Key Isolation Running Manual C:\Windows\system32\lsass.exe 644 LanmanServer Server Running Auto C:\Windows\System32\svchost.exe -k smbsvcs 2036 LanmanWorkstation Workstation Running Auto C:\Windows\System32\svchost.exe -k NetworkService -p 1176 LicenseManager Windows License Manager Service Running Manual C:\Windows\System32\svchost.exe -k LocalService -p 1116 lmhosts TCP/IP NetBIOS Helper Running Manual C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p 1064 LMVCSS Less Murphy Ventures Service Shield Running Auto C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe 1972 LSM Local Session Manager Running Auto C:\Windows\system32\svchost.exe -k DcomLaunch -p 748 mpssvc Windows Defender Firewall Running Auto C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p 1308 MSDTC Distributed Transaction Coordinator Running Auto C:\Windows\System32\msdtc.exe 356 NcbService Network Connection Broker Running Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 netprofm Network List Service Running Manual C:\Windows\System32\svchost.exe -k LocalService -p 1116 NlaSvc Network Location Awareness Running Auto C:\Windows\System32\svchost.exe -k NetworkService -p 1176 nsi Network Store Interface Service Running Auto C:\Windows\system32\svchost.exe -k LocalService -p 1116 PcaSvc Program Compatibility Assistant Service Running Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p 264 PlugPlay Plug and Play Running Manual C:\Windows\system32\svchost.exe -k DcomLaunch -p 748 PolicyAgent IPsec Policy Agent Running Manual C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p 1436 Power Power Running Auto C:\Windows\system32\svchost.exe -k DcomLaunch -p 748 ProfSvc User Profile Service Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 RasMan Remote Access Connection Manager Running Auto C:\Windows\System32\svchost.exe -k netsvcs 1472 RpcEptMapper RPC Endpoint Mapper Running Auto C:\Windows\system32\svchost.exe -k RPCSS -p 864 RpcSs Remote Procedure Call (RPC) Running Auto C:\Windows\system32\svchost.exe -k rpcss -p 864 SamSs Security Accounts Manager Running Auto C:\Windows\system32\lsass.exe 644 Schedule Task Scheduler Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 SENS System Event Notification Service Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 SessionEnv Remote Desktop Configuration Running Manual C:\Windows\System32\svchost.exe -k netsvcs -p 952 ShellHWDetection Shell Hardware Detection Running Auto C:\Windows\System32\svchost.exe -k netsvcs -p 952 Spooler Print Spooler Running Auto C:\Windows\System32\spoolsv.exe 1540 SstpSvc Secure Socket Tunneling Protocol Service Running Manual C:\Windows\system32\svchost.exe -k LocalService -p 1116 StateRepository State Repository Service Running Manual C:\Windows\system32\svchost.exe -k appmodel -p 3904 StorSvc Storage Service Running Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 SysMain SysMain Running Auto C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p 264 Sysmon Sysmon Running Auto C:\Windows\Sysmon.exe 1912 SystemEventsBroker System Events Broker Running Auto C:\Windows\system32\svchost.exe -k DcomLaunch -p 748 TabletInputService Touch Keyboard and Handwriting Panel Service Running Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 TermService Remote Desktop Services Running Manual C:\Windows\System32\svchost.exe -k termsvcs 960 Themes Themes Running Auto C:\Windows\System32\svchost.exe -k netsvcs -p 952 TimeBrokerSvc Time Broker Running Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p 1064 TokenBroker Web Account Manager Running Manual C:\Windows\system32\svchost.exe -k netsvcs -p 952 TrkWks Distributed Link Tracking Client Running Auto C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 UALSVC User Access Logging Service Running Auto C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p 264 UmRdpService Remote Desktop Services UserMode Port Redirector Running Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 UserManager User Manager Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 UsoSvc Update Orchestrator Service Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 W32Time Windows Time Running Auto C:\Windows\system32\svchost.exe -k LocalService 1800 Wcmsvc Windows Connection Manager Running Auto C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p 1168 WdiSystemHost Diagnostic System Host Running Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p 264 WinDefend Windows Defender Antivirus Service Running Auto "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe" 1944 WinHttpAutoProxySvc WinHTTP Web Proxy Auto-Discovery Service Running Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p 1064 Winmgmt Windows Management Instrumentation Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 WinRM Windows Remote Management (WS-Management) Running Auto C:\Windows\System32\svchost.exe -k NetworkService -p 1176 WpnService Windows Push Notifications System Service Running Auto C:\Windows\system32\svchost.exe -k netsvcs -p 952 WSearch Windows Search Running Auto C:\Windows\system32\SearchIndexer.exe /Embedding 4680 CDPUserSvc_367238 Connected Devices Platform User Service_367238 Running Auto C:\Windows\system32\svchost.exe -k UnistackSvcGroup 1036 WpnUserService_367238 Windows Push Notifications User Service_367238 Running Auto C:\Windows\system32\svchost.exe -k UnistackSvcGroup 1036
LMVCSS C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe
์คํ ์ค์ธ ํ๋ก์ธ์ค์์ LMVCSS ๋ชฉ๋ก์ ํ์ธํ์ ๋ ์์ํ ๊ฒฝ๋ก๋ฅผ ํ์ธํ๋ค.
์์ ์์์ ์งํ ์ค์ธ ์ค์ต์์ INITIAL_LANTERN.exe ์ ์ฑ ํ๋ก์ธ์ค๋ฅผ ํ์ธํ์๋๋ฐ, LMVCSS๋ ์ด ๊ฒฝ๋ก๋ฅผ ๋ํ๋ด๊ณ ์๋ค. ๋ฐ๋ผ์ LMVCSS๋ ์กฐ๊ธ ๋ ๋ถ์ํด๋ณผ๋ง ํ๋ค.
E9AA7564B2D1D612479E193A9F8CB70DF9CFBE02A39900EEE22FE266F5320EBF
LMVCSS๋ ์๋ง๋ ์ ์ฑ ํ๋ก์ธ์ค์ ์ง์์ฑ์ ์ํด ์๋น์ค์ ํํ๋ก ์ฃผ์ด์ ธ์์์ ์์ธกํด๋ณผ ์ ์๊ฒ ๋ค.
LMVCSS ๊ฒฝ๋ก์ Hash๊ฐ์ ํ์ธํด๋ณด๊ธฐ ์ํด ๋ค์๊ณผ ๊ฐ์ ๋ช ๋ น์ด๋ฅผ ์ ๋ ฅํด ์ธ๋ถ์ ๋ณด๋ฅผ ์ถ๋ ฅํ๋ค.
aurora-agent Aurora Agent Stopped Auto "C:\Program Files\Aurora-Agent\aurora-agent-64.exe" --service --config "C:\P...
C:\Program Files\Aurora-Agent\aurora-agent-64.exe
Aurora Agent๋ Non-Running-Service๋ก์ ์คํ ์ค์ด ์๋๋ค.
์์ ๋ชจ๋๊ฐ Auto๋ก ์ค์ ๋์ด์์ง๋ง ๋ณด์ ์๋น์ค์ธ Aurora Agent๊ฐ ์คํํ์ง ์๋๋ค๋ ์ ์ ๋ ์์๋ณผ ๋งํ๋ค.
์ด Aurora Agent๋ฅผ ์ ์ฌํ ์ดํด๋ณด๋ฉฐ Hash๊ฐ๊ณผ ๊ฐ์ข ์ ๋ณด๋ค์ ํ์ธํด๋ณด๋ ค๊ณ ํ๋ค.
Name DisplayName State StartMode PathName ---- ----------- ----- --------- -------- AJRouter AllJoyn Router Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p ALG Application Layer Gateway Service Stopped Manual C:\Windows\System32\alg.exe AppIDSvc Application Identity Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p Appinfo Application Information Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs -p AppMgmt Application Management Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs -p AppReadiness App Readiness Stopped Manual C:\Windows\System32\svchost.exe -k AppReadiness -p AppVClient Microsoft App-V Client Stopped Disabled C:\Windows\system32\AppVClient.exe AppXSvc AppX Deployment Service (AppXSVC) Stopped Manual C:\Windows\system32\svchost.exe -k wsappx -p AudioEndpointBuilder Windows Audio Endpoint Builder Stopped Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p Audiosrv Windows Audio Stopped Manual C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p aurora-agent Aurora Agent Stopped Auto "C:\Program Files\Aurora-Agent\aurora-agent-64.exe" --service --config "C:\P... AWSLiteAgent AWS Lite Guest Agent Stopped Auto "C:\Program Files\Amazon\XenTools\LiteAgent.exe" AxInstSV ActiveX Installer (AxInstSV) Stopped Disabled C:\Windows\system32\svchost.exe -k AxInstSVGroup BITS Background Intelligent Transfer Service Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p BTAGService Bluetooth Audio Gateway Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted BthAvctpSvc AVCTP service Stopped Manual C:\Windows\system32\svchost.exe -k LocalService -p bthserv Bluetooth Support Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalService -p camsvc Capability Access Manager Service Stopped Manual C:\Windows\system32\svchost.exe -k appmodel -p cfn-hup CloudFormation cfn-hup Stopped Manual "C:\Program Files\Amazon\cfn-bootstrap\winhup.exe" ClipSVC Client License Service (ClipSVC) Stopped Manual C:\Windows\System32\svchost.exe -k wsappx -p COMSysApp COM+ System Application Stopped Manual C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC7... CscService Offline Files Stopped Disabled C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p defragsvc Optimize drives Stopped Manual C:\Windows\system32\svchost.exe -k defragsvc DeviceAssociationSe... Device Association Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p DeviceInstall Device Install Service Stopped Manual C:\Windows\system32\svchost.exe -k DcomLaunch -p DevQueryBroker DevQuery Background Discovery Broker Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p diagnosticshub.stan... Stopped Manual C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe DiagTrack Connected User Experiences and Telemetry Stopped Disabled C:\Windows\System32\svchost.exe -k utcsvc -p DmEnrollmentSvc Device Management Enrollment Service Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs -p dmwappushservice Stopped Disabled C:\Windows\system32\svchost.exe -k netsvcs -p DoSvc Delivery Optimization Stopped Auto C:\Windows\System32\svchost.exe -k NetworkService -p dot3svc Wired AutoConfig Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p Eaphost Extensible Authentication Protocol Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p EFS Encrypting File System (EFS) Stopped Manual C:\Windows\System32\lsass.exe embeddedmode Embedded Mode Stopped Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p EntAppSvc Enterprise App Management Service Stopped Manual C:\Windows\system32\svchost.exe -k appmodel -p fdPHost Function Discovery Provider Host Stopped Manual C:\Windows\system32\svchost.exe -k LocalService -p FDResPub Function Discovery Resource Publication Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p FrameServer Windows Camera Frame Server Stopped Manual C:\Windows\System32\svchost.exe -k Camera GoogleChromeElevati... Stopped Manual "C:\Program Files\Google\Chrome\Application\126.0.6478.114\elevation_service... GoogleUpdaterIntern... Stopped Auto "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --sys... GoogleUpdaterServic... Stopped Auto "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --sys... GraphicsPerfSvc GraphicsPerfSvc Stopped Disabled C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup hidserv Human Interface Device Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p HvHost HV Host Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p icssvc Windows Mobile Hotspot Service Stopped Disabled C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p InstallService Microsoft Store Install Service Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p KPSSVC KDC Proxy Server service (KPS) Stopped Manual C:\Windows\system32\svchost.exe -k KpsSvcGroup KtmRm KtmRm for Distributed Transaction Coordinator Stopped Manual C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p lfsvc Geolocation Service Stopped Disabled C:\Windows\system32\svchost.exe -k netsvcs -p lltdsvc Link-Layer Topology Discovery Mapper Stopped Disabled C:\Windows\System32\svchost.exe -k LocalService -p MapsBroker Downloaded Maps Manager Stopped Disabled C:\Windows\System32\svchost.exe -k NetworkService -p MSiSCSI Microsoft iSCSI Initiator Service Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs -p msiserver Windows Installer Stopped Manual C:\Windows\system32\msiexec.exe /V NcaSvc Network Connectivity Assistant Stopped Manual C:\Windows\System32\svchost.exe -k NetSvcs -p Netlogon Netlogon Stopped Manual C:\Windows\system32\lsass.exe Netman Network Connections Stopped Manual C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p NetSetupSvc Network Setup Service Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p NetTcpPortSharing Net.Tcp Port Sharing Service Stopped Disabled C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe NgcCtnrSvc Microsoft Passport Container Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p NgcSvc Microsoft Passport Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p PerfHost Performance Counter DLL Host Stopped Manual C:\Windows\SysWow64\perfhost.exe PhoneSvc Phone Service Stopped Disabled C:\Windows\system32\svchost.exe -k LocalService -p pla Performance Logs & Alerts Stopped Manual C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p PrintNotify Printer Extensions and Notifications Stopped Manual C:\Windows\system32\svchost.exe -k print PushToInstall Windows PushToInstall Service Stopped Disabled C:\Windows\System32\svchost.exe -k netsvcs -p QWAVE Quality Windows Audio Video Experience Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p RasAuto Remote Access Auto Connection Manager Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p RemoteAccess Routing and Remote Access Stopped Disabled C:\Windows\System32\svchost.exe -k netsvcs RemoteRegistry Remote Registry Stopped Auto C:\Windows\system32\svchost.exe -k localService -p RmSvc Radio Management Service Stopped Disabled C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted RpcLocator Remote Procedure Call (RPC) Locator Stopped Manual C:\Windows\system32\locator.exe RSoPProv Resultant Set of Policy Provider Stopped Manual C:\Windows\system32\RSoPProv.exe sacsvr Special Administration Console Helper Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p SCardSvr Smart Card Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation ScDeviceEnum Smart Card Device Enumeration Service Stopped Disabled C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted SCPolicySvc Smart Card Removal Policy Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs seclogon Secondary Logon Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs -p SecurityHealthService Windows Security Service Stopped Manual C:\Windows\system32\SecurityHealthService.exe SEMgrSvc Payments and NFC/SE Manager Stopped Disabled C:\Windows\system32\svchost.exe -k LocalService -p Sense Stopped Manual "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe" SensorDataService Sensor Data Service Stopped Disabled C:\Windows\System32\SensorDataService.exe SensorService Sensor Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p SensrSvc Sensor Monitoring Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p SgrmBroker System Guard Runtime Monitor Broker Stopped Manual C:\Windows\system32\SgrmBroker.exe SharedAccess Internet Connection Sharing (ICS) Stopped Disabled C:\Windows\System32\svchost.exe -k netsvcs -p shpamsvc Shared PC Account Manager Stopped Disabled C:\Windows\System32\svchost.exe -k netsvcs -p smphost Microsoft Storage Spaces SMP Stopped Manual C:\Windows\System32\svchost.exe -k smphost SNMPTRAP SNMP Trap Stopped Manual C:\Windows\System32\snmptrap.exe sppsvc Software Protection Stopped Auto C:\Windows\system32\sppsvc.exe SSDPSRV SSDP Discovery Stopped Disabled C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p ssh-agent OpenSSH Authentication Agent Stopped Disabled C:\Windows\System32\OpenSSH\ssh-agent.exe stisvc Windows Image Acquisition (WIA) Stopped Manual C:\Windows\system32\svchost.exe -k imgsvc svsvc Spot Verifier Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p swprv Microsoft Software Shadow Copy Provider Stopped Manual C:\Windows\System32\svchost.exe -k swprv tapisrv Telephony Stopped Manual C:\Windows\System32\svchost.exe -k NetworkService -p TieringEngineService Storage Tiers Management Stopped Manual C:\Windows\system32\TieringEngineService.exe TrustedInstaller Windows Modules Installer Stopped Manual C:\Windows\servicing\TrustedInstaller.exe tzautoupdate Auto Time Zone Updater Stopped Disabled C:\Windows\system32\svchost.exe -k LocalService -p UevAgentService User Experience Virtualization Service Stopped Disabled C:\Windows\system32\AgentService.exe upnphost UPnP Device Host Stopped Disabled C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p VaultSvc Credential Manager Stopped Manual C:\Windows\system32\lsass.exe vds Virtual Disk Stopped Manual C:\Windows\System32\vds.exe vmicguestinterface Hyper-V Guest Service Interface Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p vmicheartbeat Hyper-V Heartbeat Service Stopped Manual C:\Windows\system32\svchost.exe -k ICService -p vmickvpexchange Hyper-V Data Exchange Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p vmicrdv Hyper-V Remote Desktop Virtualization Service Stopped Manual C:\Windows\system32\svchost.exe -k ICService -p vmicshutdown Hyper-V Guest Shutdown Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p vmictimesync Hyper-V Time Synchronization Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p vmicvmsession Hyper-V PowerShell Direct Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p vmicvss Hyper-V Volume Shadow Copy Requestor Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p VSS Volume Shadow Copy Stopped Manual C:\Windows\system32\vssvc.exe WaaSMedicSvc Windows Update Medic Service Stopped Manual C:\Windows\system32\svchost.exe -k wusvcs -p WalletService WalletService Stopped Disabled C:\Windows\System32\svchost.exe -k appmodel -p WarpJITSvc WarpJITSvc Stopped Manual C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted WbioSrvc Windows Biometric Service Stopped Manual C:\Windows\system32\svchost.exe -k WbioSvcGroup WdiServiceHost Diagnostic Service Host Stopped Manual C:\Windows\System32\svchost.exe -k LocalService -p WdNisSvc Stopped Manual "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe" Wecsvc Windows Event Collector Stopped Manual C:\Windows\system32\svchost.exe -k NetworkService -p WEPHOSTSVC Windows Encryption Provider Host Service Stopped Manual C:\Windows\system32\svchost.exe -k WepHostSvcGroup wercplsupport Stopped Manual C:\Windows\System32\svchost.exe -k netsvcs -p WerSvc Windows Error Reporting Service Stopped Manual C:\Windows\System32\svchost.exe -k WerSvcGroup WiaRpc Still Image Acquisition Events Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p wisvc Windows Insider Service Stopped Disabled C:\Windows\system32\svchost.exe -k netsvcs -p wlidsvc Microsoft Account Sign-in Assistant Stopped Manual C:\Windows\system32\svchost.exe -k netsvcs -p wmiApSrv WMI Performance Adapter Stopped Manual C:\Windows\system32\wbem\WmiApSrv.exe WMPNetworkSvc Windows Media Player Network Sharing Service Stopped Manual "C:\Program Files\Windows Media Player\wmpnetwk.exe" WPDBusEnum Portable Device Enumerator Service Stopped Manual C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted CaptureService_4d465 CaptureService_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k LocalService -p cbdhsvc_4d465 Clipboard User Service_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p CDPUserSvc_4d465 Connected Devices Platform User Service_4d465 Stopped Auto C:\Windows\system32\svchost.exe -k UnistackSvcGroup ConsentUxUserSvc_4d465 ConsentUX_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k DevicesFlow DevicePickerUserSvc... DevicePicker_4d465 Stopped Disabled C:\Windows\system32\svchost.exe -k DevicesFlow DevicesFlowUserSvc_... DevicesFlow_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k DevicesFlow PimIndexMaintenance... Contact Data_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k UnistackSvcGroup PrintWorkflowUserSv... PrintWorkflow_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k PrintWorkflow UnistoreSvc_4d465 User Data Storage_4d465 Stopped Manual C:\Windows\System32\svchost.exe -k UnistackSvcGroup UserDataSvc_4d465 User Data Access_4d465 Stopped Manual C:\Windows\system32\svchost.exe -k UnistackSvcGroup WpnUserService_4d465 Windows Push Notifications User Service_4d465 Stopped Auto C:\Windows\system32\svchost.exe -k UnistackSvcGroup CaptureService_1d8ddd CaptureService_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k LocalService -p cbdhsvc_1d8ddd Clipboard User Service_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p ConsentUxUserSvc_1d... ConsentUX_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k DevicesFlow DevicePickerUserSvc... DevicePicker_1d8ddd Stopped Disabled C:\Windows\system32\svchost.exe -k DevicesFlow DevicesFlowUserSvc_... DevicesFlow_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k DevicesFlow PimIndexMaintenance... Contact Data_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k UnistackSvcGroup PrintWorkflowUserSv... PrintWorkflow_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k PrintWorkflow UnistoreSvc_1d8ddd User Data Storage_1d8ddd Stopped Manual C:\Windows\System32\svchost.exe -k UnistackSvcGroup UserDataSvc_1d8ddd User Data Access_1d8ddd Stopped Manual C:\Windows\system32\svchost.exe -k UnistackSvcGroup
Get-FileHash " C:\Program Files\Aurora-Agent\aurora-agent-64.exe " | tee service-file-2.txt
Get-Item -Path " C:\Program Files\Aurora-Agent\aurora-agent-64.exe " | fl Name, FullName, Length, CreationTime, LastAccessTime, LastWriteTime, VersionInfo | tee service-file-2-details.txt
D5C8BF2D3B56B21639D8152DB277DD714BA1A61BDAF2350BD0FF7E61D2A99003
๋ค์๊ณผ ๊ฐ์ aurora-agent-64.exe์ ํด์ ๊ฐ ์ ๋ณด๋ฅผ ํ์ธํ ์ ์์๋ค. ๋ํ ๊ฒฝ๋ก๋ ํ์ธ๋์๋ค.
๋ฐ๊ฒฌ๋ ๊ฒฝ๋ก๋ฅผ ํตํด Name, FullName, Length, CreationTime, LastAccessTime, LastWriteTime, VersionInfo๋ฅผ ํ์ธํ๋๋ก ํ๋ค. ์ด๋ ๋ฐ๊ฒฌ๋ ์ ์๋ OriginalFilename์ x3xv5weg, ์ฆ ์๋น์ค ์คํ ํ์ผ aurora-agent์ ์ด๋ฆ์ด ๋ํ๋๋ค. ์ด ์ ๋ณด๋ ๋งค์ฐ ์ค์ํ๋ค. ๋ฌด์ธ๊ฐ ํฉ๋ฒ์ ์ด์ง ์์ ์ธ์คํด์ค๊ฐ ํด๋น info์์ ๋ํ๋๋ค.
์ด๋ฒ์๋ scheduled task(์์ฝ๋ ์์ )์ ํ์ธํด๋ณผ ๊ฒ์ด๋ค. ์ฌ๊ธฐ์ Aurora-agent์ ์ฐ๊ฒฐ๋์ด ์๋ ์์ ์ ํ์ธํด๋ณด์์ผ ํ๋ค. ์๋ณด๋ฉด ๋ ๊ฐ์ scheduled task๊ฐ C:\Program Files\Aurora-Agent\aurora-agent-util.exe์ ์ฐ๊ฒฐ๋์ด ์๋ ๊ฒ์ ํ์ธํ ์ ์๋ค.
ํ์ฌ ์์คํ ์ ๋ฑ๋ก๋ ์์ฝ๋ ์์ ์ ๋์ดํด๋ณด๋๋ฐ, ๋น ๋ฅธ ๊ฒ์ฌ๋ ์์คํ ์ ๋ฑ๋ก๋ ์์ฝ ์์ ์ด ์์์ ๋ํ๋ด๊ณ ์๋ค.
์์ ์ ๋ณด๋ค์ ํตํด ํต์ฌ ๋ด์ฉ๋ค์ submitํ๋ฉด ๋ค์ ๋จ๊ณ๋ก ์ง์ ํ ์ ์๋ค.
Task 10 Background Activities III: Processes and Directories
๋์ ํ๋ ํ๋ก์ธ์ค
ํ๋ก์ธ์ค์ ์ด์ ์งํ๋ฅผ ๋ช ํํ๊ฒ ํ์ ํ๊ธฐ ์ํด์ ํด๋น ์ค์ต์ ์งํํ๋ค.
ํ๋ก์ธ์ค์ ๋น์ ์์ ์ธ ์ด๋ฆ, ๊ฒฝ๋ก, ํ๋ก์ธ์ค ๋ถ๋ชจ-์์ ๊ด๊ณ, ๋ช ๋ น๊ณผ ๊ทธ ์ด์ ์ ๋จ๊ณ์ ๊ฒฐ๊ณผ๋ฅผ ํ์ ํ๊ธฐ ์ํ ์์ ์ ํด์ฃผ๋๋ก ํ๊ฒ ๋ค. ํ๋ก์ธ์ค ์ธ๋ถ ์ ๋ณด๋ค์ ๋์ดํ ๊ฒ์ด๋ฏ๋ก ๋ค์ ์ ๋ณด๋ฅผ ํ ๋๋ก ์ ๋ต์ ์ ์ถํด๋ณด์.
๋ค์ ํ๋ก์ธ์ค ์ ๋ณด์์ ์ ์ํด๋ณผ๋งํ ์ ์ INTIAL_LANTERN[.]exe์ ssh.exe, aurora-agent-64.exe์ด๋ค.
ํด๋น ํ๋ก์ธ์ค ์ ๋ณด๋ฅผ ๋ฐ๋ก ๋นผ์์ ์ฝ๋๋ก ์ ์ด๋ณด๋๋ก ํ๊ฒ ๋ค.
aurora-agent-64.exe 3848 960 SYSTEM "C:\Program Files\Aurora-Agent\aurora-agent-64.exe" C:\Program Files\Aurora-Agent\aurora-agent-64.exe conhost.exe 544 3848 SYSTEM \??\C:\Windows\system32\conhost.exe 0x4 C:\Windows\system32\conhost.exe ssh.exe 4280 3848 SYSTEM "C:\Windows\System32\OpenSSH\ssh.exe" james@10.10.10.10 C:\Windows\System32\OpenSSH\ssh.exe
ssh ์ฐ๊ฒฐ ์๋์ james@10.10.10.10๊ฐ ์ฌ์ฉ๋์๋ค. ๋ํ ํ๋ก์ธ์ค์ ์์ฌ์ค๋ฌ์ด ๊ฒฝ๋ก๋ ํ์ธ๋๋ค.
aurora-agent์ ssh๋ ์์-๋ถ๋ชจ ๊ด๊ณ๋ฅผ ํ์ฑํ๊ณ ์๋ค.
INTIAL_LANTERN[.]exe์ ํ๋ก์ธ์ค๋ฅผ ๋ ์์ธํ ํ์ธํด๋ณด๋๋ก ํ๊ฒ ๋ค.
Get-FileHash C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe | tee process-file-1.txt
C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe
์ด์ ์ ์งํํ๋ ๊ฒ๊ณผ ๊ฐ์ด Hash๊ฐ๊ณผ ๊ฒฝ๋ก๋ฅผ ํ์ธํ๋ค.
Get-FileHash C:\Users\Default\AppData\Local\Temp\jmp.exe
C:\Users\Default User\AppData\Local\Temp\jmp.exe
์ด์ ๋๋ ํ ๋ฆฌ ๊ฒ์ฌ๋ฅผ ์งํํด์ค ๊ฒ์ด๋ค. aurora-agent์ ssh์์ ์์ํ ๊ฒฝ๋ก๋ Temp์๋ค. ์ด ๊ฒฝ๋ก๋ฅผ ์กฐ๊ธ ๋ ํ์ธํด๋ณด๊ธฐ๋ก ํ๋ค. \AppData\Local\Temp๋ฅผ ์ฌ์ฉํ ์ฌ์ฉ์ ์ ๋ณด์ ํ์ผ ์ ๋ณด๋ฅผ ํ์ธํ๋ค.
Default User๊ฐ jmp.exe๋ผ๋ EXE ํ์ผ์ ์ฌ์ฉํ๋ค. ์ด ์ ์ ์กฐ๊ธ ๋ ์ ์ํ๋ค.
jmp.exe์ hash๊ฐ์ ๋ถ๋ฌ์จ๋ค.
๋ํ jmp.exe์ ํ์ผ ์ธ๋ถ ์ ๋ณด๋ ๋ถ๋ฌ์๋ค. ๊ทธ ๊ฒฐ๊ณผ ์๊น ๋ฐ๊ฒฌํ๋ aurora-agent์ OriginalFilename๊ณผ ์์ ํ ์ผ์นํ๋ x3xv5weg.exe๋ฅผ ํ์ธํ ์ ์์๋ค! ์ด๋ก์ jmp.exe๋ ์์ฌ์ค๋ฌ์ด ํ์ผ์ด๋ผ๋ ๊ฒ์ด ์ฆ๋ช ๋์๋ค.
์ด๋ฒ์๋ SpcTmp๊ฒฝ๋ก๋ ๋ค์ ํ๋ฒ ํ์ธํด๋ณธ๋ค. ์ญ๋ฐฉํฅ ํ๋ก์ ์ ํธ๋ฆฌํฐ์ ์ฌ์ฉ๋๋ ์ ์ฌ ์คํฌ๋ฆฝํธ Invoke-SocksProxy.pm1์ด ํ์ธ๋์๋ค. INITIAL_LANTERN.exe ๋ ์ญ์ ํ์ธ๋์๋ค.
C: ๋๋ผ์ด๋ธ๊ฐ ์๋ ๋ฌธ์๊ฐ ์๋ ์จ๊ฒจ์ง ๋์คํฌ ๋ณผ๋ฅจ์ด ๋ํ๋ฌ๊ณ , ํด๋น ๋์คํฌ์ ๋ผ๋ฒจ์ Setups์ด๋ค.
๋๋ผ์ด๋ธ ์ด๋ฆ์ ๋ฌธ์๋ฅผ ๋ฃ์ง ์์๋ค๋ ๊ฒ์ ๊ฒ์ฌ์์ ํ์ง๋ฅผ ์จ๊ธฐ๊ธฐ ์ํ ํ๋์ด๋ผ๊ณ ๋ณผ ์ ์๋ ๊ฒ ๊ฐ๋ค.
์ฌ๊ธฐ๊น์ง ๋ฐ๋ผ์๋ค๋ฉด ๋ต์ ๋ฌด๋ํ๊ฒ ์ ๋ ฅํด๋ณผ ์ ์๋ค.
๋ค์๊ธ์ด ์์ต๋๋ค.์ด์ ๊ธ์ด ์์ต๋๋ค.๋๊ธ