STUDY.md
  • [Forensics WRITEUP๐ŸŸช] Windows Incident Surface ๋ผ์ดํŠธ์—…
    2024๋…„ 08์›” 08์ผ 04์‹œ 30๋ถ„ 56์ดˆ์— ์—…๋กœ๋“œ ๋œ ๊ธ€์ž…๋‹ˆ๋‹ค.
    ์ž‘์„ฑ์ž: banda โ €



     ๐ŸชŸWindows Incident Surface 

     

    ํ•ด๋‹น ๋ฌธ์ œ์˜ WriteUp๋ฅผ ์ž‘์„ฑํ•ด๋ณผ ๊ฒƒ์ด๋‹ค.

    https://tryhackme.com/r/room/winincidentsurface

     

     

     

     

     

     


     

     

     

     

    openvpn์„ ํ†ตํ•ด kali linux์— vm ๋ฐฐํฌ๋ฅผ ์ง„ํ–‰ํ•ด ์ค€๋น„๋ฅผ ์™„๋ฃŒํ–ˆ๋‹ค.

     

    ์ด๋ ‡๊ฒŒ ์—ฐ๊ฒฐํ•˜๋ฉด tun0์— tryhackme์˜ ์„ธํŒ…์ด ๋‚˜ํƒ€๋‚˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

     

    ์นผ๋ฆฌ ๋ฆฌ๋ˆ…์Šค๋กœ๋ถ€ํ„ฐ windows try hack me ์‹ค์Šตํ™˜๊ฒฝ์— ์ง„์ž…ํ–ˆ๋‹ค.

    task 3๊นŒ์ง€๋Š” ์„ธํŒ… ๋ฐ ์‹œ๋‚˜๋ฆฌ์˜ค ์„ค๋ช… ๋‚ด์šฉ์ด๋ฏ€๋กœ task 4๋ถ€ํ„ฐ ์ง„ํ–‰ํ•˜๊ฒ ๋‹ค.

     

    ํ•ด๋‹น ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•ด์„œ ์นผ๋ฆฌ ๋ฆฌ๋ˆ…์Šค RDP์— ์ ‘์†ํ•ด์ฃผ์—ˆ๋‹ค.

    xfreerdp /u:(username) /p:(password) /v:(Machine IP) /dynamic-resolution

     

     

     

     


     Task 4 Reliability of the System Tools

    ์‹œ์Šคํ…œ ๋„๊ตฌ์˜ ์‹ ๋ขฐ์„ฑ

    cmd ๋„๊ตฌ์™€ ps ๋„๊ตฌ๋ฅผ ์ด์šฉํ•ด ์‚ฌ์šฉ์ž์˜ ์ •๋ณด๋ฅผ ์•Œ์•„๋‚ด๋Š” ์‹ค์Šต์ด๋‹ค.

     

     

    C:\Users\Administrator\Desktop\tools\shells ๊ฒฝ๋กœ์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ shells exe๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

    CMD์™€ PowerShell ๋‘ ๊ฐ€์ง€ ๋ฒ„์ „์ด ์žˆ์—ˆ๋‹ค.

     

    ์‹œ์Šคํ…œ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•ด์„œ 10.10.166.79 IP ํ˜ธ์ŠคํŠธ์˜ ์†์ƒ๋œ ํ˜ธ์ŠคํŠธ๋ฅผ ์กฐ์‚ฌํ•˜๋Š” ๊ฒƒ์ด ์‹œ๋‚˜๋ฆฌ์˜ค์ด๋‹ค.

    ์ด๋ฒˆ ์‹ค์Šต์—์„œ๋Š” PowerShell, cmd๋ฅผ ์ด์šฉํ•ด์„œ ์‚ฌ์šฉ์ž์˜ ์ •๋ณด๋ฅผ ํƒ์ƒ‰ํ•˜๋Š” ๊ฒƒ์ด ๋ชฉ์ ์ธ ๊ฒƒ ๊ฐ™๋‹ค.

     

    ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น ์‰˜์ด ์žˆ๋Š” ํด๋” ๊ฒฝ๋กœ C:\Users\Administrator\Desktop\tools\shells๊ฐ€ ์ค€๋น„๋˜์–ด ์žˆ๋‹ค.

    DFIR์€ ๋””์ง€ํ„ธํฌ๋ Œ์‹ ์‚ฌ๊ณ ๋Œ€์‘ ์šฉ์–ด๋‹ค. ๋ฐ์ดํ„ฐ๋ฅผ ์ˆ˜์ง‘ํ•˜๊ธฐ ์œ„ํ•œ ํˆด์ด๋ผ๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

     

     

     

    CMD-DFIR.exe๋ฅผ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์œผ๋กœ ์‹คํ–‰ํ•ด์„œ env_vars.txt๋ฅผ set, type ํ•ด์ฃผ์—ˆ๋‹ค.

     

    ์ž ์žฌ์ ์œผ๋กœ ํ•˜์ด์žฌํ‚น๋œ ์ •๋ณด๋ฅผ ์ฐพ์•„๋‚ด๊ธฐ ์œ„ํ•ด ํ•„๋“œ๋ฅผ ์Šคํฌ๋ฆฐํ–ˆ๋‹ค.

    ComSpec, Path, PSModulePath, Public, TEMP and TMP ๊ฐ€ path hijacking์ด ๋งŽ์ด ์ผ์–ด๋‚˜๋Š” ์œ„์น˜๋ผ๊ณ  ํ•œ๋‹ค.

     

    ComSpec=C:\Windows\system32\cmd.exe
    Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Amazon\cfn-bootstrap\;C:\Program Files\Aurora-Agent;C:\Program Files\dotnet\;C:\Program Files\TortoiseSVN\bin;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\Scripts\;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\;C:\Users\Administrator\AppData\Local\Microsoft\WindowsApps;
    PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\AWS Tools\PowerShell\
    PUBLIC=C:\Users\Public
    TEMP=C:\Users\ADMINI~1\AppData\Local\Temp\2
    TMP=C:\Users\ADMINI~1\AppData\Local\Temp\2

     

     

     

     

    sers\Administrator\Desktop\tools\shells>set > env_vars.txt
    
    C:\Users\Administrator\Desktop\tools\shells>type env_vars.txt
    ALLUSERSPROFILE=C:\ProgramData
    APPDATA=C:\Users\Administrator\AppData\Roaming
    CLIENTNAME=kali
    CommonProgramFiles=C:\Program Files\Common Files
    CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
    CommonProgramW6432=C:\Program Files\Common Files
    COMPUTERNAME=CCTL-WS-018-B21
    ComSpec=C:\Windows\system32\cmd.exe
    DriverData=C:\Windows\System32\Drivers\DriverData
    HOMEDRIVE=C:
    HOMEPATH=\Users\Administrator
    LOCALAPPDATA=C:\Users\Administrator\AppData\Local
    LOGONSERVER=\\CCTL-WS-018-B21
    NUMBER_OF_PROCESSORS=2
    OS=Windows_NT
    Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Amazon\cfn-bootstrap\;C:\Program Files\Aurora-Agent;C:\Program Files\dotnet\;C:\Program Files\TortoiseSVN\bin;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\Scripts\;C:\Users\Administrator\AppData\Local\Programs\Python\Python310\;C:\Users\Administrator\AppData\Local\Microsoft\WindowsApps;
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE=AMD64
    PROCESSOR_IDENTIFIER=AMD64 Family 23 Model 1 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL=23
    PROCESSOR_REVISION=0102
    ProgramData=C:\ProgramData
    ProgramFiles=C:\Program Files
    ProgramFiles(x86)=C:\Program Files (x86)
    ProgramW6432=C:\Program Files
    PROMPT=$P$G
    PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\AWS Tools\PowerShell\
    PUBLIC=C:\Users\Public
    SESSIONNAME=RDP-Tcp#0
    SystemDrive=C:
    SystemRoot=C:\Windows
    TEMP=C:\Users\ADMINI~1\AppData\Local\Temp\2
    TMP=C:\Users\ADMINI~1\AppData\Local\Temp\2
    USERDOMAIN=CCTL-WS-018-B21
    USERDOMAIN_ROAMINGPROFILE=CCTL-WS-018-B21
    USERNAME=Administrator
    USERPROFILE=C:\Users\Administrator
    windir=C:\Windows

     

    ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋ฅผ ์•Œ ์ˆ˜ ์žˆ์—ˆ๋‹ค.

    PowerShell ๊ฒฝ๋กœ๋Š” ๋ณ„๋‹ค๋ฅธ ๋ฌธ์ œ๊ฐ€ ๋ณด์ด์ง€ ์•Š๊ธฐ๋•Œ๋ฌธ์— ํ”„๋กœํ•„ ๊ฒฝ๋กœ๋ฅผ ํ™•์ธํ•ด์ฃผ๊ธฐ๋กœ ํ•œ๋‹ค.

     

    powershell๊ณผ profile.ps1์˜ ์ ˆ๋Œ€๊ฒฝ๋กœ๋ฅผ where์„ ์ด์šฉํ•ด์„œ ์ฐพ์•„๋ณธ๋‹ค.

     

     

     

    ์ด์ œ powershell๊ณผ profile.ps1์˜ ์œ„์น˜ ์ •๋ณด๋ฅผ ์ด์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜์—ˆ๋‹ค.

     

    C:\Users\Administrator\Desktop\tools\shells>where powershell.exe
    C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    
    C:\Users\Administrator\Desktop\tools\shells>where profile.ps1
    C:\Users\Administrator\Desktop\tools\shells\profile.ps1
    C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1

     

     

     

     

    profile.ps1์— ์—‘์„ธ์Šค๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด๋ณธ๋‹ค.

    ๊ทธ ๋‹ค์Œ์—๋Š”, profile.ps1์˜ ๋‚ด์šฉ์„ ๋คํ”„ํ•˜๊ณ  txtํŒŒ์ผ์„ ์ฝ์–ด๋ณธ๋‹ค. ์ด๋กœ์„œ event-triggered execution (ATT&CK ID: 1546.013)๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

     

     

    if exist "C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1" (echo PROFILE EXISTS) else (echo PROFILE DOES NOT EXIST)

    type "C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1" > ps_profile_dump.txt

     

    PS-DFIR์— ์—‘์„ธ์Šคํ•  ๋•Œ๋Š” ๋”ฐ๋กœ ์‹คํ–‰ํ•ด๋„ ๋˜์ง€๋งŒ cmd์ฐฝ์— PS-DFIR.exe๋ฅผ ์ž…๋ ฅํ•ด์ค˜๋„ ๋œ๋‹ค.

     

    Get-Module | ft ModuleType, Version, Name | tee ps-mods-loaded-modules.txt

    PS-DFIR์„ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์œผ๋กœ ์‹คํ–‰ํ•˜๊ณ  Get-Module ๋ช…๋ น์–ด๋ฅผ ๊ณ„์† ์‚ฌ์šฉํ•ด์ค„ ์˜ˆ์ •์ด๋‹ค.

    ft ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ps ๋ชจ๋“ˆ์˜ ps_ModuleType, Version, Name ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜จ๋‹ค.

     

     

     

     

    Get-Module -ListAvailable | select ModuleType, Version, Name | tee ps-mods-all.txt

     

    ModuleType Version Name
    ---------- ------- ----
      Manifest 3.1.0.0 Microsoft.PowerShell.Management
      Manifest 3.1.0.0 Microsoft.PowerShell.Utility
        Script 2.0.0   PSReadline
    PS C:\Users\Administrator\Desktop\tools\shells> Get-Module -ListAvailable | select ModuleType, Version, Name | tee ps-mods-all.txt
    
    ModuleType Version   Name
    ---------- -------   ----
        Script 0.4.7     powershell-yaml
        Script 1.0.1     Microsoft.PowerShell.Operation.Validation
        Binary 1.0.0.1   PackageManagement
        Script 3.4.0     Pester
        Script 1.0.0.1   PowerShellGet
        Script 2.0.0     PSReadline
      Manifest 1.0.1.0   ActiveDirectory
      Manifest 1.0.0.0   AppBackgroundTask
      Manifest 2.0.0.0   AppLocker
      Manifest 1.0.0.0   AppvClient
      Manifest 2.0.1.0   Appx
      Manifest 1.0       BestPractices
      Manifest 2.0.0.0   BitsTransfer
      Manifest 1.0.0.0   BranchCache
      Manifest 1.0.0.0   CimCmdlets
      Manifest 1.0       ConfigCI
      Manifest 1.0       ConfigDefender
      Manifest 1.0       ConfigDefenderPerformance
      Manifest 1.0       Defender
      Manifest 1.0.1.0   DeliveryOptimization
        Binary 2.0.0.0   DFSR
      Manifest 1.0.0.0   DirectAccessClientComponents
        Script 3.0       Dism
      Manifest 1.0.0.0   DnsClient
      Manifest 1.0.0.0   EventTracingManagement
      Manifest 1.0.0.0   GroupPolicy
        Binary 2.0.0.0   Hyper-V
        Binary 1.1       Hyper-V
      Manifest 2.0.0.0   International
      Manifest 1.0.0.0   iSCSI
      Manifest 2.0.0.0   IscsiTarget
        Script 1.0.0.0   ISE
      Manifest 1.0.0.0   Kds
      Manifest 1.0.1.0   Microsoft.PowerShell.Archive
      Manifest 3.0.0.0   Microsoft.PowerShell.Diagnostics
      Manifest 3.0.0.0   Microsoft.PowerShell.Host
      Manifest 1.0.0.0   Microsoft.PowerShell.LocalAccounts
      Manifest 3.1.0.0   Microsoft.PowerShell.Management
        Script 1.0       Microsoft.PowerShell.ODataUtils
      Manifest 3.0.0.0   Microsoft.PowerShell.Security
      Manifest 3.1.0.0   Microsoft.PowerShell.Utility
      Manifest 3.0.0.0   Microsoft.WSMan.Management
      Manifest 1.0       MMAgent
      Manifest 1.0.0.0   MsDtc
      Manifest 2.0.0.0   NetAdapter
      Manifest 1.0.0.0   NetConnection
      Manifest 1.0.0.0   NetDiagnostics
      Manifest 1.0.0.0   NetEventPacketCapture
      Manifest 2.0.0.0   NetLbfo
      Manifest 1.0.0.0   NetNat
      Manifest 2.0.0.0   NetQos
      Manifest 2.0.0.0   NetSecurity
      Manifest 1.0.0.0   NetSwitchTeam
      Manifest 1.0.0.0   NetTCPIP
      Manifest 1.0.0.0   NetWNV
      Manifest 1.0.0.0   NetworkConnectivityStatus
      Manifest 1.0.0.0   NetworkSwitchManager
      Manifest 1.0.0.0   NetworkTransition
      Manifest 1.0       NFS
      Manifest 1.0.0.0   Nps
      Manifest 1.0.0.0   PcsvDevice
        Binary 1.0.0.0   PersistentMemory
      Manifest 1.0.0.0   PKI
      Manifest 1.0.0.0   PlatformIdentifier
      Manifest 1.0.0.0   PnpDevice
      Manifest 1.1       PrintManagement
        Binary 1.0.11    ProcessMitigations
      Manifest 1.1       PSDesiredStateConfiguration
        Script 1.0.0.0   PSDiagnostics
        Binary 1.1.0.0   PSScheduledJob
      Manifest 2.0.0.0   PSWorkflow
      Manifest 1.0.0.0   PSWorkflowUtility
      Manifest 3.0.0.0   RemoteAccess
      Manifest 2.0.0.0   RemoteDesktop
      Manifest 1.0.0.0   ScheduledTasks
      Manifest 2.0.0.0   SecureBoot
      Manifest 1.0.0.0   SecurityCmdlets
        Script 1.0.0.0   ServerCore
        Script 2.0.0.0   ServerManager
           Cim 1.0.0.0   ServerManagerTasks
      Manifest 2.0.0.0   SmbShare
      Manifest 2.0.0.0   SmbWitness
      Manifest 2.0.0.0   SoftwareInventoryLogging
      Manifest 1.0.0.0   StartLayout
      Manifest 2.0.0.0   Storage
      Manifest 1.0.0.0   StorageBusCache
      Manifest 2.0.0.0   TLS
      Manifest 1.0.0.0   TroubleshootingPack
      Manifest 2.0.0.0   TrustedPlatformModule
        Binary 2.1.639.0 UEV
      Manifest 2.0.0.0   UpdateServices
      Manifest 1.0.0.0   UserAccessLogging
      Manifest 2.0.0.0   VpnClient
      Manifest 1.0.0.0   Wdac
      Manifest 2.0.0.0   Whea
      Manifest 1.0.0.0   WindowsDeveloperLicense
        Script 1.0       WindowsErrorReporting
      Manifest 1.0.0.0   WindowsSearch
      Manifest 1.0.0.0   WindowsUpdate
      Manifest 1.0.0.2   WindowsUpdateProvider
        Binary 4.1.9.0   AWSPowerShell
    
    
    PS C:\Users\Administrator\Desktop\tools\shells>

     

     

     

    HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest

    ํƒˆ์ทจ๋‹นํ•œ ์ •๋ณด์˜ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฒฝ๋กœ๋Š” (HKLM)์ด๋ผ๊ณ  ์ ํžŒ ๋‚ด์šฉ์„ ํ†ตํ•ด ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

    ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ profile.bak์—๋Š” ps_profile_dump.txt์™€ ๊ฒน์น˜๋Š” ๋‚ด์šฉ๋“ค์ด ์ ํ˜€์žˆ์—ˆ๋‹ค.

     

    ๋‘ txt, bak ํŒŒ์ผ์—์„œ log๋ฅผ ์ง€์šฐ๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋œ ํˆด์˜ ์ด๋ฆ„๊ณผ stealํ•˜๊ธฐ ์œ„ํ•œ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฒฝ๋กœ๊ฐ€ ์ ํ˜€์กŒ๋‹ค.

     

     

     

     

     


     

     Task 5 System Profile 

    ์‹œ์Šคํ…œ ์„ธ๋ถ€ ์ •๋ณด ๋ฐ ๊ตฌ์„ฑ / ์‹œ์Šคํ…œ ํ”„๋กœํ•„ ์ •๋ณด ํƒ์ƒ‰ํ•˜๊ธฐ

    ์ด๊ณณ์—์„œ๋Š” ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ์„ธ๋ถ€์ •๋ณด, ํ˜ธ์ŠคํŠธ ๋„ค์ž„, OS ๋ฒ„์ „, ์•„ํ‚คํ…์ฒ˜ ์ •๋ณด, ์‹œ์Šคํ…œ ์‹œ๊ฐ„, ๋กœ์ปฌ ์ •์ฑ… ์„ค์ •์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

     

    Get-CimInstance win32_networkadapterconfiguration -Filter IPEnabled=TRUE | ft DNSHostname, IPAddress, MACAddress | tee interfaces.txt

     

    ์‚ฌ์šฉ์ž์˜ ์ดˆ๊ธฐ ๋งฅ๋ฝ ์ •๋ณด๋ฅผ ์ดํ•ดํ•˜๊ธฐ ์œ„ํ•ด ์‹œ์Šคํ…œ ํ”„๋กœํ•„์„ ํ™•์ธํ•ด์•ผ ํ•œ๋‹ค.

     

    ๋จผ์ € Get-CimInstance๋ฅผ ํ†ตํ•ด ํ˜ธ์ŠคํŠธ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ์ •๋ณด์˜ IP์ฃผ์†Œ์™€ IPv4, IPv6, MAC ์ •๋ณด๋“ค์„ ์•Œ์•„๋ณผ ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•ด๋ณด๊ฒ ๋‹ค.

     

     

     

     

    Get-CimInstance -ClassName Win32_OperatingSystem | fl CSName, Version, BuildNumber, InstallDate, LastBootUpTime, OSArchitecture | tee sysinfo.txt

    ํ•ด๋‹น ๋ช…๋ น์–ด๋Š” ์‹œ๊ฐ„์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์•Œ๋ ค์ค€๋‹ค. InstallDate์™€ LastBootUpTime์€ ์ค‘์š”ํ•˜๊ฒŒ ๋ณผ ๋งŒํ•œ ์ •๋ณด์ธ ๊ฒƒ ๊ฐ™๋‹ค.

    ์ด๋•Œ ํ˜„์žฌ ํ˜ธ์ŠคํŠธ์˜ OS ๋ฒ„์ „๊ณผ ์‹œ์Šคํ…œ ๊ด€๋ฆฌ์ž์˜ ์ •๋ณด๊ฐ€ ์ผ์น˜ํ•˜์ง€ ์•Š๋Š” ๊ฒƒ๊ฐ™๋‹ค. (10.0.17763 - 10.0.25398)

     

    ์ด ์ •๋ณด๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ๋‹ค์Œ ์ •๋ณด๋ฅผ ์ฐพ์•„๋ณธ๋‹ค.

     

    Get-Date | tee systime.txt ; Get-TimeZone | tee systime.txt -Append

    ์‹œ์Šคํ…œ ๋‚ ์งœ์™€ ์‹œ๊ฐ„ ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด์ฃผ์—ˆ๋‹ค.

    Date ID๋Š” Turkey Standard Time์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

     

     

     

     

    System Profile์„ ํ†ตํ•ด ์•Œ์•„๋‚ธ ์ •๋ณด๋“ค์„ ์ฐพ์•„์„œ ์ž…๋ ฅํ•˜๋ฉด ํ†ต๊ณผํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

     

     


     Task 6 Users and Sessions 

    ์‚ฌ์šฉ์ž ๋ฐ ์„ธ์…˜

    ์ด๊ณณ์—์„œ๋Š” ๋กœ์ปฌ ์‚ฌ์šฉ์ž ์‹๋ณ„, ๊ทธ๋ฃน ์‹๋ณ„, ํ™œ์„ฑ ์‚ฌ์šฉ์ž ์„ธ์…˜ ์‹๋ณ„์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

    ์‚ฌ์šฉ์ž ๊ณ„์ • ๋กœ๊ทธ์ธ, ์‹คํ–‰, ํ”„๋กœ์„ธ์Šค ํ™œ๋™์„ ๋ฐœ๊ฒฌํ•˜๊ณ , ์ด ์ค‘ ์•…์šฉ๋œ ์‚ฌ์šฉ์ž๋‚˜ ๊ทธ๋ฃน์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ด๋ณธ๋‹ค.

     

    Get-LocalUser | tee l-users.txt
     Get-CimInstance -Class Win32_UserAccount -Filter "LocalAccount=True" | Format-Table  Name, PasswordRequired, PasswordExpires, PasswordChangeable | Tee-Object "user-details.txt"

    ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋•Œ, Admin ๋กœ์ปฌ ์‚ฌ์šฉ์ž ๊ณ„์ •์€ 3๊ฐœ ์žˆ๋‹ค๋Š” ์ ์— ์œ ์˜ํ•œ๋‹ค.

    Guest์—์„œ PasswordRequired๊ฐ€ False์ด๋‹ค. ๊ฒŒ์ŠคํŠธ ๊ณ„์ •์ด ํŽ˜์Šค์›Œ๋“œ๋ฅผ ์š”๊ตฌ๋ฐ›์ง€ ์•Š๋Š”๋‹ค๋Š” ์ ์ด ์ทจ์•ฝํ•˜๋‹ค.

     

     

    Get-LocalGroup | ForEach-Object { $members = Get-LocalGroupMember -Group $_.Name; if ($members) { Write-Output "`nGroup: $($_.Name)"; $members | ForEach-Object { Write-Output "`tMember: $($_.Name)" } } } | tee gp-members.txt

    ์œ„์—์„œ ๋ดค๋˜ admin ๊ทธ๋ฃน์— ์žˆ๋Š” member์„ ํ™•์ธํ•ด์ค€๋‹ค. ์—ฌ๋Ÿฌ ๊ฐœ์˜ ๊ณ„์ •์ด๋‚˜ admin ๊ทธ๋ฃน์˜ ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค. ์ด ์ˆ˜์ƒํ•œ ์ง•ํ›„๋ฅผ ์œ ์˜ํ•ด์„œ ๊ธฐ์–ตํ•ด๋ณด์•„์•ผ๊ฒ ๋‹ค.

     

    ์ด ๋‹ค์Œ์—๋Š” ์‚ฌ์šฉ์ž ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ๋” ์•Œ์•„๋ณผ ์˜ˆ์ •์ด๋‹ค.

     

     

     

    Guest์˜ SID๋„˜๋ฒ„์™€ ๋งˆ์ง€๋ง‰ ๋กœ๊ทธ์ธ ์‹œ๊ฐ„์„ ์•Œ์•„๋ณธ๋‹ค.

    ์Œ ์–ด๋–ค ์ด์œ ๋กœ PasswordLastSet์ด ํ˜„์žฌ ๋‚ ์งœ๋กœ ๋‚˜ํƒ€๋‚˜๋Š”์ง€ ์ž˜ ๋ชจ๋ฅด๊ฒ ๋‹ค..

     

    ์•„๋ฌดํŠผ Guest ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด ๋” ์„ธ๋ถ€์ ์œผ๋กœ ํ™•์ธํ•ด์ค€ ๋ชจ์Šต์ด๋‹ค.

     

     

    ์ด์ œ tools์˜ utils ํด๋”๋กœ ์ด๋™ํ•ด์„œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด ์ •๋ณด๋ฅผ ํ™•์ธํ•ด๋ณผ ๊ฒƒ์ด๋‹ค.

     

    Users logged on locally์˜ 8์›” 8์ผ๋กœ ๋‚˜์˜ค๋ฉด ์•ˆ๋˜๋Š”๋ฐ ์–ด์งธ์„œ์ธ์ง€ ์ €๋ ‡๊ฒŒ ๋‚˜์˜จ๋‹ค..

    ์•„๋ฌดํŠผ ์ด๊ณณ์—์„œ๋Š” Administrator๊ณผ Guest์˜ ์ˆ˜์ƒํ•œ ๋‘ ๋ช…์˜ ๋กœ๊ทธ์ธ ์‚ฌ์šฉ์ž ๋กœ๊ทธ๊ฐ€ ๋‚˜ํƒ€๋‚œ๋‹ค.

     

    ์•„๋ฌด๋ž˜๋„ Administrator์€ ์šฐ๋ฆฌ๊ฐ€ ์žˆ๋Š” ๊ณณ์ด๋‹ˆ๊นŒ ์ €๋ ‡๊ฒŒ ์ถœ๋ ฅ๋˜๋Š”๊ฒŒ ๋งž๋Š” ๊ฒƒ ๊ฐ™๊ณ , Guest์—์„œ ์ˆ˜์ƒํ•œ ์ ‘๊ทผ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ๋‹ค๋Š” ์ ์ด ์œ ์˜ํ• ๋งŒ ํ•˜๋‹ค.

     

     

     

     

    ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ์œ„์—์„œ ์–ป์€ ์ •๋ณด๋ฅผ ํ†ตํ•ด Guest์— ๊ด€๋ จ๋œ ์ •๋ณด์™€ ๋กœ๊ทธ์ธํ•œ ์‹œ๊ฐ„๋Œ€๋ฅผ ์ž…๋ ฅํ•ด๋ณธ๋‹ค. ๊ทธ๋Ÿผ ์ •๋‹ต์ธ ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

     


     Task 7 Network Scope 

    ๋„คํŠธ์›Œํฌ ๋ฒ”์œ„

    ๋„คํŠธ์›Œํฌ ํ™œ์„ฑ ํฌํŠธ, ์—ฐ๊ฒฐ ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๊ณ , ๋„คํŠธ์›Œํฌ ์œ„์น˜์™€ ๋ฐฉํ™”๋ฒฝ ๊ทœ์น™์„ ํ™•์ธํ•œ๋‹ค.

    TCP, UDP์—์„œ์˜ ์˜์‹ฌ์Šค๋Ÿฌ์šด ์—ฐ๊ฒฐ์„ ํ™•์ธํ•˜๊ณ , ๋ฐฉํ™”๋ฒฝ์—์„œ ์˜ˆ์™ธ๊ฐ€ ์žˆ๋Š” ์ˆ˜์ƒํ•œ ํ”„๋กœ์„ธ์Šค ํ™œ๋™์„ ๋งคํ•‘ํ•ด๋ณธ๋‹ค.

     

    ์Œ.. ๋ฒ„ํผ์‚ฌ์ด์ฆˆ ๋•Œ๋ฌธ์— ํ…์ŠคํŠธ๊ฐ€ ์ผ๋ถ€ ์ƒ๋žต๋˜์–ด์„œ ๋‚˜์™€ ์šฐ์—ฌ๊ณก์ ˆ์„ ์กฐ๊ธˆ ๊ฒช์—ˆ๋‹ค.

    ์ผ๋‹จ ์ตœ๋Œ€ํ•œ ํŒŒ์›Œ์‰˜ ๊ธ€์ž๊ฐ€ ๋ชจ๋‘ ์ถœ๋ ฅ๋  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๊ณ  ๋‹ต์„ ์ฐพ์•„๋ณด์•˜๋‹ค.

     

    TCP-conn.txt๋ฅผ ํ†ตํ•ด TCP ํ™œ์„ฑ ํฌํŠธ์™€ ์—ฐ๊ฒฐ์„ ๊ฒ€ํ† ํ•ด๋ณธ๋‹ค.

     

    INITIAL_LANTERN์—์„œ 50119์™€ 8888 ํฌํŠธ, ๊ทธ๋ฆฌ๊ณ  ๊ฒฝ๋กœ๋ฅผ ํ™•์ธํ•ด๋ณด์ž.

    ํ•ด๋‹น ๊ฒฝ๋กœ์—์„œ ์‹œ์ž‘๋œ ํ”„๋กœ์„ธ์Šค๊ฐ€ ์œ„ํ—˜ํ•˜๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. INITIAL_LANTERN์€ ์•…์„ฑ ํ”„๋กœ์„ธ์Šค๋‹ค.

     

     

    ์ถ”๊ฐ€๋กœ ๊ฐ™์€ ๋ฐฉ์‹์œผ๋กœ UDP ํ™œ๋™์„ ๊ฒ€ํ† ํ•  ์ˆ˜ ์žˆ๋‹ค.

     

    ๊ณต์œ ๋œ ๋„คํŠธ์›Œํฌ ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น์–ด๋„ ์žˆ๋‹ค.

    ๊ณต์œ  ํด๋”๋ฅผ ํ†ตํ•ด ์ทจ์•ฝ์ ์ด ๋‚˜ํƒ€๋‚  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•ด๋ณด์ž.

     

     

    FirewallProfile์€ ๋ฐฉํ™”๋ฒฝ ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๋Š” ๊ณณ์ด๋‹ค. ๋ฐฉํ™”๋ฒฝ์—์„œ ์˜๋„์ ์œผ๋กœ ๋ณ€๊ฒฝ๋˜๊ฑฐ๋‚˜ ์ œ์ž‘๋˜๋Š” ๊ทœ์น™๋“ค์„ ์‹๋ณ„ํ•œ๋‹ค๋ฉด,

    ๊ทธ๊ฒƒ์€ ๋งค์šฐ ์ค‘๋Œ€ํ•œ ์‚ฌํ•ญ์ด๋‹ค.

     

    ์ด๊ณณ์—์„œ ํฐ ๋ฌธ์ œ์ ์€ ๋‚˜ํƒ€๋‚˜์ง€ ์•Š๋Š”๋‹ค.

     

     

    ...

    ์ด๊ณณ์—์„œ ๋ฐฉํ™”๋ฒฝ์˜ ๋น ๋ฅธ ๋ชฉ๋ก์„ ์ œ๊ณตํ•œ๋‹ค. ์ด ๋ฆฌ์ŠคํŠธ์—์„œ ์ฃผ์˜ํ•ด์„œ ํ™•์ธํ•ด๋ด์•ผํ•  ์ ์€ AnyDesk์™€ LMV Co.์ด๋‹ค.

    AnyDesk์˜ ๊ฒฝ๋กœ์™€ LMV Co.์˜ ๋ฐฉํ™”๋ฒฝ ๊ทœ์น™์„ ์ž˜ ํ™•์ธํ•ด๋ณด์ž.

     

    ์ถ”๊ฐ€๋กœ, ์ด fw rules๋Š” ์กฐ๊ธˆ ์œ ์‹ฌํžˆ ๋ณด์•„๋‘ฌ์•ผ ํ•œ๋‹ค.

    ๋‚˜์ค‘์— ๋‚˜์˜ฌ NetSh๊ฐ€ ๋ฐฉํ™”๋ฒฝ๊ณผ ์—ฐ๊ด€๋˜์–ด์žˆ์œผ๋ฏ€๋กœ, ์ด ๋ถ€๋ถ„์„ ๊ฑด๋“ค์ธ๋‹ค๋Š” ์œ„ํ—˜ ์˜ˆ์ธก๋„ ํ•ด๋ณผ ์ˆ˜ ์žˆ์„ ๊ฒƒ ๊ฐ™๋‹ค.

     

     

     

     

    ์œ„์˜ ์ž๋ฃŒ์— ์œ ์˜ํ•ด๋ณธ๋‹ค๋ฉด ์ •๋‹ต์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋‹ค.

     

     

     


     Task 8 Background Activities I: Startup and Registry 

    ์Šคํƒ€ํŠธ์—…๊ณผ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ

    Task 8์—์„œ๋Š” ์‹œ์ž‘ ์‹œํ€€์Šค์™€ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ์„ธ๋ถ€์ •๋ณด๋ฅผ ํ™•์ธํ•ด๋ณธ๋‹ค. ๋‹ค์–‘ํ•œ ํ”„๋กœ์„ธ์Šค๋ฅผ ํ™•์ธํ•˜๊ณ  ์ž๋™ ์‹œ์ž‘ ํ”„๋กœ๊ทธ๋žจ, ๋ถ€ํŒ… ์‹คํ–‰ ํŒŒ์ผ, ๋ถ€ํŠธ ํŒŒ์ผ ๋“ฑ์„ ํŒŒ์•…ํ•œ๋‹ค. ๋ชจ๋“  ํŒŒ์ผ์„ ์ถ”์ ํ•˜์ง€ ์•Š๊ณ  ์ˆ˜์ƒํ•˜๊ฒŒ ๋ณด์—ฌ์ง€๋Š” ํŒŒ์ผ๋“ค์„ ์ค‘์‹ฌ์ ์œผ๋กœ ๊ฒ€์‚ฌํ•ด๋ณด๋Š” ์ ‘๊ทผ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•ด๋ณด๊ฒ ๋‹ค.

    ๋ถ€ํŒ… ํ”„๋กœ์„ธ์Šค์— ์ดˆ์ ์„ ๋งž์ถ˜ boot.txt ์ •๋ณด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ HKLM ์ •๋ณด๋ฅผ ํ™•์ธํ•œ๋‹ค. ๋‚ด์šฉ์ด ์ƒ๋‹นํžˆ ๊ธธ์—ˆ๋˜ ๊ฒƒ์œผ๋กœ ๊ธฐ์–ตํ•œ๋‹ค.

     

     

     

    ์—ฐ๊ฒฐ๋œ ์‹คํ–‰ ํŒŒ์ผ, ์‚ฌ์šฉ์ž ๊ณ„์ •, ํŠน์ • DLL, ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๋“ฑ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์ •๋ณด๋ฅผ ์ฐพ์•„๋ณธ๋‹ค.

    ํ•ด๋‹น ์„ธ ๊ฐ€์ง€์˜ ๋‚ด์šฉ์€ ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž ํ”„๋กœํ•„์— ํ• ๋‹น๋˜์—ˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

     

     

    ๋กœ๊ทธ์˜จ ์ •๋ณด๋ฅผ ํ™•์ธํ•ด๋ณด๋Š” ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ–ˆ๋‹ค. ๋‚ด์šฉ์ด ์ข€ ๊ธธ๊ธฐ๋•Œ๋ฌธ์— ๋‚˜์ค‘์— ์ฐธ๊ณ ํ•ด๋ณด๋ ค๊ณ  ์ ‘์€ ๊ธ€์— ์ „์ฒด ๋‚ด์šฉ์„ ๋‹ฌ์•„๋†“์•˜๋‹ค. userinit[.]exeํŒŒ์ผ์€ ์„ธ์…˜์„ ์ดˆ๊ธฐํ™”ํ•  ๋•Œ ๊ธฐ๋ณธ์ ์œผ๋กœ ์‚ฌ์šฉ๋œ๋‹ค. ์ถ”๊ฐ€ ์‹คํ–‰ํŒŒ์ผ์„ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค๋ฉด ์กฐ๊ธˆ ์ด๋ก€์ ์ธ ์ƒํ™ฉ์ด๋ผ๊ณ  ํ•ด๋ณผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ ๊ฐ™๋‹ค. 

     

     

    ๋”๋ณด๊ธฐ
    PS C:\Users\Administrator\Desktop\tools\utils> .\autorunsc64.exe -a l * -h | tee logon.txt
    
    Sysinternals Autoruns v14.10 - Autostart program viewer
    Copyright (C) 2002-2023 Mark Russinovich
    Sysinternals - www.sysinternals.com
    
    
    HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
       rdpclip
         rdpclip
         RDP Clipboard Monitor
         Microsoft Corporation
         10.0.17763.1697
         c:\windows\system32\rdpclip.exe
         11/27/1964 2:17 PM
         MD5:      BFE0CEE883BD55C7691E7C1027E2332B
         SHA1:     50E594B78FF88CE4E93E7293BBD15AD3C5AB3E5A
         PESHA1:   AC638AA87A8FCF006D24DE029DF4EE04A906B069
         SHA256:   4972CF79E61A6FF0C4EA410D55C7DEB00D7F799EA958946FCC2EE7FABF13FFEB
         PESHA256: 5533D791C16FF754A315497807ECB5707C2437E85C4C8D5BD55A7D3001E76025
         IMPHASH:  E3F33CEBF67721DAC951AFBD20321206
    
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
       C:\Windows\system32\userinit.exe
         C:\Windows\system32\userinit.exe
         Userinit Logon Application
         Microsoft Corporation
         10.0.17763.1
         c:\windows\system32\userinit.exe
         12/31/1958 2:49 PM
         MD5:      BF8825D08BC235F0609CA8BBEF4E179C
         SHA1:     470C3E60F9B2B6D83F95C7916A5361E34DEC3471
         PESHA1:   DF688108336B5E2AC79D652521CAE6F14BC4D450
         SHA256:   1FE7F7C59EC7EAA276739FA85F7DDA6136D81184E0AEB385B6AC9FEAAA8C4394
         PESHA256: A5160EF5F4B97E938DA7E956A3331FB66EA3F9EA7E7D8BEEF313F318F2C11B98
         IMPHASH:  8419D97ABDFEB6C320F0C39028647572
       cmd.exe
         cmd.exe
         Windows Command Processor
         Microsoft Corporation
         10.0.17763.1697
         c:\windows\system32\cmd.exe
         5/30/2008 3:32 AM
         MD5:      911D039E71583A07320B32BDE22F8E22
         SHA1:     DED8FD7F36417F66EB6ADA10E0C0D7C0022986E9
         PESHA1:   8F4C943F540AB1BFD6DD2A2820FA9EE7794CE550
         SHA256:   BC866CFCDDA37E24DC2634DC282C7A0E6F55209DA17A8FA105B07414C0E7C527
         PESHA256: 5F98D08805D4EEE36337C81914F0D82191A4D58D24EA2FF2E522A95A5D6E5B73
         IMPHASH:  272245E2988E1E430500B852C4FB5E18
    
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet
       SystemPropertiesPerformance.exe
         SystemPropertiesPerformance.exe
         Change Computer Performance Settings
         Microsoft Corporation
         10.0.17763.1
         c:\windows\system32\systempropertiesperformance.exe
         12/27/1907 4:03 AM
         MD5:      AB32E55D2DAC9E9427F89D835054F8D7
         SHA1:     5ED9658FA4DD4D1EC70157F148D4AE7ABDDE4B66
         PESHA1:   284D49497AB1D71F4F6AB471A42B322BA185D5A5
         SHA256:   357BDAD469524CDF42680FF44E17CE41C64B38872C4F55E89DE0560FBD003693
         PESHA256: E0B8AB13E07B8599AE6187EBAE82422D6D9AC879C2264DE3E8E32D1A816A6340
         IMPHASH:  835402499FB5903791DBBE73881263B5
    
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
       explorer.exe
         explorer.exe
         Windows Explorer
         Microsoft Corporation
         10.0.17763.1697
         c:\windows\explorer.exe
         9/21/2012 3:10 AM
         MD5:      85352486405EFFBAE1240DECDA20C2A0
         SHA1:     6FC4D5F0A813473CC44297EE165355028CE7C090
         PESHA1:   8C3C012F72305B667CC3CC8DC21D8073393D1C14
         SHA256:   E2B62E2A745CA56AA4E2EB7B9369DA7714E481304B29F3DE884369EB27D835D4
         PESHA256: 05E296AC3EDCEA8B93629D1B931F115277FF040D85EF5F0EB0F8ED28A27156BF
         IMPHASH:  3EF052F18C0AF035F409392A87FD0B19
    
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell
       cmd.exe
         cmd.exe
         Windows Command Processor
         Microsoft Corporation
         10.0.17763.1697
         c:\windows\system32\cmd.exe
         5/30/2008 3:32 AM
         MD5:      911D039E71583A07320B32BDE22F8E22
         SHA1:     DED8FD7F36417F66EB6ADA10E0C0D7C0022986E9
         PESHA1:   8F4C943F540AB1BFD6DD2A2820FA9EE7794CE550
         SHA256:   BC866CFCDDA37E24DC2634DC282C7A0E6F55209DA17A8FA105B07414C0E7C527
         PESHA256: 5F98D08805D4EEE36337C81914F0D82191A4D58D24EA2FF2E522A95A5D6E5B73
         IMPHASH:  272245E2988E1E430500B852C4FB5E18
    
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells\AvailableShells
       30000
         cmd.exe /c "cd /d "%USERPROFILE%" & start cmd.exe /k runonce.exe /AlternateShellStartup"
         File not found: cd /d
    
       60000
         explorer.exe
         Windows Explorer
         Microsoft Corporation
         10.0.17763.1697
         c:\windows\explorer.exe
         9/21/2012 3:10 AM
         MD5:      85352486405EFFBAE1240DECDA20C2A0
         SHA1:     6FC4D5F0A813473CC44297EE165355028CE7C090
         PESHA1:   8C3C012F72305B667CC3CC8DC21D8073393D1C14
         SHA256:   E2B62E2A745CA56AA4E2EB7B9369DA7714E481304B29F3DE884369EB27D835D4
         PESHA256: 05E296AC3EDCEA8B93629D1B931F115277FF040D85EF5F0EB0F8ED28A27156BF
         IMPHASH:  3EF052F18C0AF035F409392A87FD0B19
    
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
       SecurityHealth
         %windir%\system32\SecurityHealthSystray.exe
         Windows Security notification icon
         Microsoft Corporation
         10.0.17763.1
         c:\windows\system32\securityhealthsystray.exe
         7/2/1906 5:12 AM
         MD5:      09F3F2298DDA6EBB57B12C530D35C52C
         SHA1:     D7FC50DC0A08C9EC089E428A03606EE4A2E8C759
         PESHA1:   258864A6871EEA36380479F2885C0B1B327DC455
         SHA256:   48F852164EF4747FCDDFF463034CAD33167E341D241536B122AE74FC8841C941
         PESHA256: 4A942D68E3E6456C8D940B868E8512B01FA753CD662B29F2AFB3ADE88E722092
         IMPHASH:  44315EF1FEB6193B3AB5492033CEFAAE
    
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
       AnyDesk.lnk
         C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk
         AnyDesk
         AnyDesk Software GmbH
         8.0.10.0
         c:\program files (x86)\anydesk\anydesk.exe
         4/24/2024 3:53 PM
         MD5:      AEE6801792D67607F228BE8CEC8291F9
         SHA1:     BF6BA727FF14CA2FDDF619F292D56DB9D9088066
         PESHA1:   83127A3EBEF4B2456465B43B6CF3E8878D3EA080
         SHA256:   1CDAFBE519F60AAADB4A92E266FFF709129F86F0C9EE595C45499C66092E0499
         PESHA256: 7A27A90AFDE3731D85C6A950746A3A5EF5A7321646E8F74679B3D6AD39C28241
    
    HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
       Microsoft Windows Media Player
         %SystemRoot%\system32\unregmp2.exe /ShowWMP
         Microsoft Windows Media Player Setup Utility
         Microsoft Corporation
         12.0.17763.1
         c:\windows\system32\unregmp2.exe
         9/30/1990 10:30 AM
         MD5:      9CF8E80F71544316E5F90F2B87F2350C
         SHA1:     5D5BF791D38DF29D52F4585A6853FC8242CDB73C
         PESHA1:   60A53C9A311C3DBB32BC22517FAC97750D01C716
         SHA256:   DF160ACED402899269A07872038E7CEBE64CBB24DD09D8A4474B12AA6F760653
         PESHA256: B05E2B6C7C1DA403546ED91EEAEE303357ED400BFD36E0A36EA175767D41C2F2
         IMPHASH:  1DE1DA351E000239456F4F921473BDC8
       Themes Setup
         themeui.dll
         Windows Theme API
         Microsoft Corporation
         10.0.17763.1697
         c:\windows\system32\themeui.dll
         12/19/1948 5:05 PM
         MD5:      00CA0E4BEC8DD38B6026B431F813B00F
         SHA1:     195BF8AF3659065B24CB0A7603F856311B6C9A72
         PESHA1:   FD56F156F2436321C2D054582B9D7CF9773DDDE2
         SHA256:   CC1BD1B9771E1DC6424F4955FE537A84C215A6B0C4D46D44A33251F8F362CE4A
         PESHA256: 575265F6C1EAFF465D041CEEF954EA2DB4626738342E0DFBA3B5566F856F7138
         IMPHASH:  3377BF4AD60C0566FBECF4212621B1A1
       Microsoft Windows Media Player
         %SystemRoot%\system32\unregmp2.exe /FirstLogon
         Microsoft Windows Media Player Setup Utility
         Microsoft Corporation
         12.0.17763.1
         c:\windows\system32\unregmp2.exe
         9/30/1990 10:30 AM
         MD5:      9CF8E80F71544316E5F90F2B87F2350C
         SHA1:     5D5BF791D38DF29D52F4585A6853FC8242CDB73C
         PESHA1:   60A53C9A311C3DBB32BC22517FAC97750D01C716
         SHA256:   DF160ACED402899269A07872038E7CEBE64CBB24DD09D8A4474B12AA6F760653
         PESHA256: B05E2B6C7C1DA403546ED91EEAEE303357ED400BFD36E0A36EA175767D41C2F2
         IMPHASH:  1DE1DA351E000239456F4F921473BDC8
       Windows Desktop Update
         shell32.dll
         Windows Shell Common Dll
         Microsoft Corporation
         10.0.17763.1790
         c:\windows\system32\shell32.dll
         3/3/2006 6:59 AM
         MD5:      1B9EE5E4CEDD2F92BEF642FB702D6D69
         SHA1:     2A8CAD3EA362363DBC8DD0B5EC85C81E2729A362
         PESHA1:   AC500D1C23DD77B5654AE07EF3DCE4A24ABA1196
         SHA256:   79A2D653304A352E6BCF7E33E0C3EC42B5A629505DF09D40432F5F4094872A1A
         PESHA256: 00D718B7A32FF336FF493B8EDCCAE41303B400EC00BD512225A48019A9BD5ADA
         IMPHASH:  4C6A425B69AD3E18ACE611520E54E884
       Web Platform Customizations
         C:\Windows\System32\ie4uinit.exe -UserConfig
         IE Per-User Initialization Utility
         Microsoft Corporation
         11.0.17763.652
         c:\windows\system32\ie4uinit.exe
         7/11/1981 12:04 AM
         MD5:      A52B135E1865F98C90BF23B3807E51C0
         SHA1:     BF142E7FA17591BAF7D97E342781C8BCA8545C63
         PESHA1:   5F223F5350D78F32C311B521A04233DF8966A9D9
         SHA256:   46A3D721ADB36114A5141E5795E4DFC02644FDF8F6C602BCCFDC057784F29DB0
         PESHA256: 12C51A253AD15B14BA64730360801B3A1D5DCF8DCB82C9C9ACA996852D2692DB
         IMPHASH:  B898E7CB8AA65CE3FA6187EE093D7F6B
       n/a
         C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
         Microsoft .NET IE SECURITY REGISTRATION
         Microsoft Corporation
         2.0.50727.9031
         c:\windows\system32\mscories.dll
         8/8/2018 6:18 AM
         MD5:      55E13DD52266781390123239FCB59E7B
         SHA1:     91037E05C0F49595C230E26789A936CF492FF830
         PESHA1:   9CA91E3C8E0008B1DEB963FEBEB03DD323B4E111
         SHA256:   B2E30D3E728A1960F7C847C2E3B0EB616F56D309359796D543EB910B8DF07CA5
         PESHA256: B5899C49522601181D36D9FBF8DD4EC6366B41CA9D81E70002F5D4EC22939468
         IMPHASH:  AB8FA7A93A14C9EDE0B84EB9ECAFBAC2
       Google Chrome
         "C:\Program Files\Google\Chrome\Application\126.0.6478.114\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable
         Google Chrome Installer
         Google LLC
         126.0.6478.114
         c:\program files\google\chrome\application\126.0.6478.114\installer\chrmstp.exe
         6/17/2024 11:55 PM
         MD5:      36F9F0B7186D6D8E52ED2A794D3A0CE1
         SHA1:     5C79C4E65581239412BF19C0B2C8C27B94A866E6
         PESHA1:   6ABCAF28B9FA3438564703FFBA57D41E8F06DD67
         SHA256:   40C45622685F5F54588D5C397B7FB8FC509AC9F8446B0963AF314A541F18A69E
         PESHA256: 648721845B8F523CD8ADA22E899B48FD363A808B5D35D9084EC3529CF8D14D61
         IMPHASH:  5EE2AB762FA8D4FC5F9A047C2ED853EA
       Applying Enhanced Security Configuration
         "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenAdmin
         IOD Version Map
         Microsoft Corporation
         11.0.17763.1
         c:\windows\system32\iesetup.dll
         4/26/1955 4:49 AM
         MD5:      06D9E39994E9CB486B07E05CAAC321C1
         SHA1:     CB8936D04D9A992163B8F236EFC3B8BAFD4F26D3
         PESHA1:   73268C53C41034163A91399059DA2B30E892DCDE
         SHA256:   BE2C5ADB7445D8102848E51BF77A03C7A731C456F241C2A0B39CC852DEE5CD97
         PESHA256: B90BA7691A93810CBD2D099A0971A7B0AF4EE1360FEEC084937C5CDA5E885D7E
         IMPHASH:  FFD26F19E29CEF9F551DED1D2FA50CF8
       Applying Enhanced Security Configuration
         "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iesetup.dll",IEHardenUser
         IOD Version Map
         Microsoft Corporation
         11.0.17763.1
         c:\windows\system32\iesetup.dll
         4/26/1955 4:49 AM
         MD5:      06D9E39994E9CB486B07E05CAAC321C1
         SHA1:     CB8936D04D9A992163B8F236EFC3B8BAFD4F26D3
         PESHA1:   73268C53C41034163A91399059DA2B30E892DCDE
         SHA256:   BE2C5ADB7445D8102848E51BF77A03C7A731C456F241C2A0B39CC852DEE5CD97
         PESHA256: B90BA7691A93810CBD2D099A0971A7B0AF4EE1360FEEC084937C5CDA5E885D7E
         IMPHASH:  FFD26F19E29CEF9F551DED1D2FA50CF8
    
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
       Microsoft Windows Media Player
         %SystemRoot%\system32\unregmp2.exe /ShowWMP
         Microsoft Windows Media Player Setup Utility
         Microsoft Corporation
         12.0.17763.1
         c:\windows\syswow64\unregmp2.exe
         1/3/2036 12:22 PM
         MD5:      33A85B3DCFFEADA67C98EAC342B93DCB
         SHA1:     33856AD378DB2ECEAEF0C7F4817995A277F25592
         PESHA1:   34E5C7262181A1476F88271FA43385C7BAB7F6CD
         SHA256:   1DF2F5FC3369F5901068AD9463D7A165FD8E7EE7A12CA6C1A88992BB1484632E
         PESHA256: F78219179657C76950961DE298BE9A5875E7A643646F21DD533DDDA1FA319067
         IMPHASH:  567DEBB2A156B506ED421C435F1B2E33
       Microsoft Windows Media Player
         %SystemRoot%\system32\unregmp2.exe /FirstLogon
         Microsoft Windows Media Player Setup Utility
         Microsoft Corporation
         12.0.17763.1
         c:\windows\syswow64\unregmp2.exe
         1/3/2036 12:22 PM
         MD5:      33A85B3DCFFEADA67C98EAC342B93DCB
         SHA1:     33856AD378DB2ECEAEF0C7F4817995A277F25592
         PESHA1:   34E5C7262181A1476F88271FA43385C7BAB7F6CD
         SHA256:   1DF2F5FC3369F5901068AD9463D7A165FD8E7EE7A12CA6C1A88992BB1484632E
         PESHA256: F78219179657C76950961DE298BE9A5875E7A643646F21DD533DDDA1FA319067
         IMPHASH:  567DEBB2A156B506ED421C435F1B2E33
       n/a
         C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
         Microsoft .NET IE SECURITY REGISTRATION
         Microsoft Corporation
         2.0.50727.9031
         8/8/2018 6:28 AM
         MD5:      7A0B0FBB84ADECDCDF8DBAE89298B3DE
         SHA1:     4C2EFC4FE459CBF8D9B7784815169769A221E1DF
         PESHA1:   B3AAF6C889C93561075CFBC96080B4C6C57F3229
         SHA256:   6B46626A1EEF501F527160B10675862368887258766EFE8CEFAAE1E13C88B887
         IMPHASH:  08A027E94DD9452BDF5B6AF03B573759
    
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\IconServiceLib
       IconCodecService.dll
         IconCodecService.dll
         Converts a PNG part of the icon to a legacy bmp icon
         Microsoft Corporation
         10.0.17763.1
         c:\windows\system32\iconcodecservice.dll
         5/9/1956 3:37 AM
         MD5:      6B67CE980C9D91D60015E0CB12945A04
         SHA1:     C3139884E31F50184C6C33B429B1260460562316
         SHA256:   80621FCB7C569830404A0355C57B35FDEDB9E74B773B539E84AC3674C8283705
         PESHA256: B979B6A3F3380266FBD05320B8BE935A78DE123DAA6C50B61AC4FFB8F808DCEC
         IMPHASH:  BC4916A3897FAE424D0E5B39B694361B
    
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup
       RunWallpaperSetup.cmd
         C:\Users\Adminstrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunWallpaperSetup.cmd
         c:\users\adminstrator\appdata\roaming\microsoft\windows\start menu\programs\startup\runwallpapersetup.cmd
         2/27/2024 2:45 PM
         MD5:      FA9D7A03029739B5B2001E922E850A64
         SHA1:     05276AE99DCAF6C6F1B9765EF8A035AA86060B86
         PESHA1:   05276AE99DCAF6C6F1B9765EF8A035AA86060B86
         SHA256:   73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7
         PESHA256: 73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7
    
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup
       RunWallpaperSetup.cmd
         C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunWallpaperSetup.cmd
         c:\users\guest\appdata\roaming\microsoft\windows\start menu\programs\startup\runwallpapersetup.cmd
         2/28/2024 10:58 AM
         MD5:      FA9D7A03029739B5B2001E922E850A64
         SHA1:     05276AE99DCAF6C6F1B9765EF8A035AA86060B86
         PESHA1:   05276AE99DCAF6C6F1B9765EF8A035AA86060B86
         SHA256:   73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7
         PESHA256: 73BA33FE75051877AFED93B3644B9B824E82E68E2A11EA1694A445EB4A5EBFD7

     

     

    ์ฃผ์˜๊นŠ๊ฒŒ ํ™•์ธํ•ด๋ณด๋ผ๊ณ  ์ œ์‹œ๋œ ์ ์€ cmd.exe ํŒŒ์ผ๊ณผ userinit.exe๋‹ค.

    ์™œ ์ฃผ์˜๋ฅผ ๊ธฐ์šธ์—ฌ์•ผ ํ•˜๋Š”์ง€ ์กฐ๊ธˆ ๋” ์•Œ ๊ฒƒ ๊ฐ™๋‹ค. Winlogon ๊ณผ์ •์—์„œ ๋ณดํ†ต์€ userinit.exe๋งŒ์„ ๊ธฐ๋ณธ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜์ง€๋งŒ, cmd.exe๊ฐ€ ํ•จ๊ป˜ ์‹คํ–‰ ํ”„๋กœ์„ธ์Šค๋กœ ์ œ์‹œ๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค. ์ผ๋‹จ์€ ์ด ๋ถ€๋ถ„์„ ์ค‘์š”ํ•˜๊ฒŒ ๋‘˜ ๋งŒํ•œ ์ •๋ณด๋กœ ๊ธฐ๋กํ•ด๋‘”๋‹ค.

     

     

    ๊ทธ๋Ÿฌ๋ฏ€๋กœ Winlogon์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์กฐ๊ธˆ ๋” ํ™•์ธํ•ด์ฃผ์—ˆ๋‹ค.

    userinit ํ‚ค์—๋Š” ๋‘ ๊ฐœ์˜ ๊ฐ’์ด ํฌํ•จ๋˜์–ด ์žˆ๋‹ค.

     

    cmd.exe์—

    "start /min netsh.exe -c"

    ์ด๋Ÿฐ ๋‚ด์šฉ์ด ์žˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ cmd๋กœ netsh.exe๋ฅผ ๊ตณ์ด ์กฐ์šฉํžˆ ์‹œ์ž‘ํ•  ํ•„์š”๊ฐ€ ์žˆ์„๊นŒ..? ์ˆ˜์ƒํ•˜๋‹ค. ์—ฌ๊ธฐ์„œ ์‹คํ–‰ ํŒŒ์ผ์ด ์‚ฌ์šฉ์ž ๋ชฐ๋ž˜ ์‹คํ–‰๋œ๋‹ค๋ฉด ๊ทธ๊ฑด ํ™•์‹คํžˆ ์˜์‹ฌ์Šค๋Ÿฝ๋‹ค. ์ด ํ™œ๋™์„ ์กฐ๊ธˆ ๋” ์ถ”์ ํ•ด๋ณผ ์ˆ˜ ์žˆ์„ ๊ฒƒ ๊ฐ™๋‹ค. netsh.exe์— ๋Œ€ํ•ด์„œ๋„ ์ข€ ๋” ์•Œ์•„๋ณผ ์ˆ˜ ์žˆ์—ˆ์œผ๋ฉด ์ข‹๊ฒ ๋‹ค.

     

     

    ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธ์„ ํ–ˆ์„ ๋•Œ ์ž๋™์œผ๋กœ ์‹œ์ž‘๋˜์–ด์•ผ ํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ๊ณผ ๊ธฐ๋ณธ ์œ„์น˜๋ฅผ ์‚ดํŽด๋ณด๋Š” ์ •๋ณด๋ฅผ ์ฝ์–ด๋ณด๊ฒ ๋‹ค.

    CurrentVersion\Run

    ํ•ด๋‹น ์œ„์น˜๋ฅผ ๋‚˜ํƒ€๋‚ด๊ณ  ์žˆ๋‹ค. ๊ทธ๋ ‡๋‹ค๋ฉด NetSH๋Š”?

     

     

    NetSh๋Š” ์‚ฌ์šฉ์ž์˜ ๋ˆˆ์— ๋„์ง€ ์•Š๋Š” ๊ณณ์—์„œ ์ž ์žฌ์ ์ธ ํ™œ๋™์„ ํ•˜๊ณ ์žˆ๋‹ค. netshell ์‹คํ–‰ ํŒŒ์ผ์€ dll์„ ๋กœ๋“œํ•˜๊ณ  ์žˆ๋‹ค.

    ์—ฌ๊ธฐ์„œ ๋ˆˆ์— ๋„๋Š” dll ๋ช…์€ .\fwshield.dll์ด๋‹ค. ์ผ๊ด€์ ์ด์ง€ ์•Š์€ ๋‹ค๋ฅธ ํ•ญ๋ชฉ์„ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ๋‹ค.

    ๋ญ”๊ฐ€ ๋ฐฉํ™”๋ฒฝ ๊ทœ์น™์— ๊ด€๋ จ๋œ ์ •๋ณด๋ฅผ ํŒŒ์•…ํ–ˆ์„ ๋•Œ NetSh๊ฐ€ ์ž ์žฌ์ ์œผ๋กœ ์‹คํ–‰๋  ์œ„ํ—˜์ด ์žˆ๋Š” ๊ฒƒ ๊ฐ™๋‹ค.

     

     

     

     

     


     Task 9 Background Activities II: Services and Scheduled Items 

    ์„œ๋น„์Šค, ์˜ˆ์•ฝ๋œ ํ•ญ๋ชฉ

    ์ด ์‹ค์Šต์—์„œ๋Š” ๋ฐฑ๊ทธ๋ผ์šด๋“œ์—์„œ ์ž‘๋™ํ•˜๋Š” ์ง€์†์ ์ธ ์‚ฌ์šฉ ์„œ๋น„์Šค ํŒจํ„ด์„ ํ™•์ธํ•ด๋ณด๊ฒŒ ๋œ๋‹ค. ์ˆœ์„œ์— ๋”ฐ๋ผ ์„œ๋น„์Šค์™€ ์˜ˆ์•ฝ๋œ ์ž‘์—…์ด ์ž˜ ์ง„ํ–‰๋˜๊ณ  ์žˆ๋Š”์ง€ ์‹๋ณ„ํ•ด๋‚ด๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•œ ์‹œ์Šคํ…œ์˜ ๊ณผ์ •์ด๋‹ค. ํŠน์ •ํ•œ ํ”„๋กœ์„ธ์Šค์˜ ์‹œ์ž‘ ์ˆœ์„œ๊ฐ€ ์ˆ˜์ƒํ•˜์ง€๋Š” ์•Š์€์ง€, ์‹คํ–‰ ์ค‘์ธ ์„œ๋น„์Šค์— ์ด์ƒ์€ ์—†๋Š”์ง€ ํ™•์ธํ•ด๋ด์•ผ ํ•œ๋‹ค.

     

     

     

    "Running Services:"; Get-CimInstance -ClassName Win32_Service | 
    Where-Object { $_.State -eq "Running" } | 
    Select-Object Name, DisplayName, State, StartMode, PathName, ProcessId | 
    ft -AutoSize | tee services-active.txt

    ๋‹ค์Œ์€ ์‹คํ–‰ ์ค‘์ธ ํ”„๋กœ์„ธ์Šค ์ •๋ณด๋ฅผ ๋‚˜์—ดํ•˜๋Š” ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•œ ๊ฒƒ์ด๋‹ค. State, StartMode, PathName, ProcessId ์ •๋ณด๋Š” ์ด์ƒ์ด ์žˆ๋Š” ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๊ณ  ๊ฒ€์‚ฌํ•  ๋•Œ ์œ ์šฉํ•œ ๋ถ€๋ถ„์ด ๋  ์ˆ˜ ์žˆ๋‹ค.

     

     

    PS C:\Users\Administrator\Desktop\tools\utils> "Running Services:"; Get-CimInstance -ClassName Win32_Service | Where-Object { $_.State -eq "Running" } | Select-Object Name, DisplayName, State, StartMode, PathName, ProcessId | ft -AutoSize | tee services-active.txt
    Running Services:
    
    Name                   DisplayName                                      State   StartMode PathName                                                                        ProcessId
    ----                   -----------                                      -----   --------- --------                                                                        ---------
    AmazonSSMAgent         Amazon SSM Agent                                 Running Auto      "C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe"                                   3488
    AnyDesk                AnyDesk Service                                  Running Auto      "C:\Program Files (x86)\AnyDesk\AnyDesk.exe" --service                               1904
    BFE                    Base Filtering Engine                            Running Auto      C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p                  1308
    BrokerInfrastructure   Background Tasks Infrastructure Service          Running Auto      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                      748
    CDPSvc                 Connected Devices Platform Service               Running Auto      C:\Windows\system32\svchost.exe -k LocalService -p                                   1116
    CertPropSvc            Certificate Propagation                          Running Manual    C:\Windows\system32\svchost.exe -k netsvcs                                           1472
    CoreMessagingRegistrar CoreMessaging                                    Running Auto      C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p                          1572
    CryptSvc               Cryptographic Services                           Running Auto      C:\Windows\system32\svchost.exe -k NetworkService -p                                 1176
    DcomLaunch             DCOM Server Process Launcher                     Running Auto      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                      748
    Dhcp                   DHCP Client                                      Running Auto      C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                  1064
    Dnscache               DNS Client                                       Running Auto      C:\Windows\system32\svchost.exe -k NetworkService -p                                 1176
    DPS                    Diagnostic Policy Service                        Running Auto      C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p                          1572
    DsmSvc                 Device Setup Manager                             Running Manual    C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    DsSvc                  Data Sharing Service                             Running Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    EventLog               Windows Event Log                                Running Auto      C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                  1064
    EventSystem            COM+ Event System                                Running Auto      C:\Windows\system32\svchost.exe -k LocalService -p                                   1116
    FontCache              Windows Font Cache Service                       Running Auto      C:\Windows\system32\svchost.exe -k LocalService -p                                   1116
    gpsvc                  Group Policy Client                              Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    IKEEXT                 IKE and AuthIP IPsec Keying Modules              Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    iphlpsvc               IP Helper                                        Running Auto      C:\Windows\System32\svchost.exe -k NetSvcs -p                                         952
    KeyIso                 CNG Key Isolation                                Running Manual    C:\Windows\system32\lsass.exe                                                         644
    LanmanServer           Server                                           Running Auto      C:\Windows\System32\svchost.exe -k smbsvcs                                           2036
    LanmanWorkstation      Workstation                                      Running Auto      C:\Windows\System32\svchost.exe -k NetworkService -p                                 1176
    LicenseManager         Windows License Manager Service                  Running Manual    C:\Windows\System32\svchost.exe -k LocalService -p                                   1116
    lmhosts                TCP/IP NetBIOS Helper                            Running Manual    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                  1064
    LMVCSS                 Less Murphy Ventures Service Shield              Running Auto      C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe                            1972
    LSM                    Local Session Manager                            Running Auto      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                      748
    mpssvc                 Windows Defender Firewall                        Running Auto      C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p                  1308
    MSDTC                  Distributed Transaction Coordinator              Running Auto      C:\Windows\System32\msdtc.exe                                                         356
    NcbService             Network Connection Broker                        Running Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    netprofm               Network List Service                             Running Manual    C:\Windows\System32\svchost.exe -k LocalService -p                                   1116
    NlaSvc                 Network Location Awareness                       Running Auto      C:\Windows\System32\svchost.exe -k NetworkService -p                                 1176
    nsi                    Network Store Interface Service                  Running Auto      C:\Windows\system32\svchost.exe -k LocalService -p                                   1116
    PcaSvc                 Program Compatibility Assistant Service          Running Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    PlugPlay               Plug and Play                                    Running Manual    C:\Windows\system32\svchost.exe -k DcomLaunch -p                                      748
    PolicyAgent            IPsec Policy Agent                               Running Manual    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p                1436
    Power                  Power                                            Running Auto      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                      748
    ProfSvc                User Profile Service                             Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    RasMan                 Remote Access Connection Manager                 Running Auto      C:\Windows\System32\svchost.exe -k netsvcs                                           1472
    RpcEptMapper           RPC Endpoint Mapper                              Running Auto      C:\Windows\system32\svchost.exe -k RPCSS -p                                           864
    RpcSs                  Remote Procedure Call (RPC)                      Running Auto      C:\Windows\system32\svchost.exe -k rpcss -p                                           864
    SamSs                  Security Accounts Manager                        Running Auto      C:\Windows\system32\lsass.exe                                                         644
    Schedule               Task Scheduler                                   Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    SENS                   System Event Notification Service                Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    SessionEnv             Remote Desktop Configuration                     Running Manual    C:\Windows\System32\svchost.exe -k netsvcs -p                                         952
    ShellHWDetection       Shell Hardware Detection                         Running Auto      C:\Windows\System32\svchost.exe -k netsvcs -p                                         952
    Spooler                Print Spooler                                    Running Auto      C:\Windows\System32\spoolsv.exe                                                      1540
    SstpSvc                Secure Socket Tunneling Protocol Service         Running Manual    C:\Windows\system32\svchost.exe -k LocalService -p                                   1116
    StateRepository        State Repository Service                         Running Manual    C:\Windows\system32\svchost.exe -k appmodel -p                                       3904
    StorSvc                Storage Service                                  Running Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    SysMain                SysMain                                          Running Auto      C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    Sysmon                 Sysmon                                           Running Auto      C:\Windows\Sysmon.exe                                                                1912
    SystemEventsBroker     System Events Broker                             Running Auto      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                      748
    TabletInputService     Touch Keyboard and Handwriting Panel Service     Running Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    TermService            Remote Desktop Services                          Running Manual    C:\Windows\System32\svchost.exe -k termsvcs                                           960
    Themes                 Themes                                           Running Auto      C:\Windows\System32\svchost.exe -k netsvcs -p                                         952
    TimeBrokerSvc          Time Broker                                      Running Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                  1064
    TokenBroker            Web Account Manager                              Running Manual    C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    TrkWks                 Distributed Link Tracking Client                 Running Auto      C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    UALSVC                 User Access Logging Service                      Running Auto      C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    UmRdpService           Remote Desktop Services UserMode Port Redirector Running Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    UserManager            User Manager                                     Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    UsoSvc                 Update Orchestrator Service                      Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    W32Time                Windows Time                                     Running Auto      C:\Windows\system32\svchost.exe -k LocalService                                      1800
    Wcmsvc                 Windows Connection Manager                       Running Auto      C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                  1168
    WdiSystemHost          Diagnostic System Host                           Running Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                    264
    WinDefend              Windows Defender Antivirus Service               Running Auto      "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\MsMpEng.exe"      1944
    WinHttpAutoProxySvc    WinHTTP Web Proxy Auto-Discovery Service         Running Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                  1064
    Winmgmt                Windows Management Instrumentation               Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    WinRM                  Windows Remote Management (WS-Management)        Running Auto      C:\Windows\System32\svchost.exe -k NetworkService -p                                 1176
    WpnService             Windows Push Notifications System Service        Running Auto      C:\Windows\system32\svchost.exe -k netsvcs -p                                         952
    WSearch                Windows Search                                   Running Auto      C:\Windows\system32\SearchIndexer.exe /Embedding                                     4680
    CDPUserSvc_367238      Connected Devices Platform User Service_367238   Running Auto      C:\Windows\system32\svchost.exe -k UnistackSvcGroup                                  1036
    WpnUserService_367238  Windows Push Notifications User Service_367238   Running Auto      C:\Windows\system32\svchost.exe -k UnistackSvcGroup                                  1036

     

     

    LMVCSS
    C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe

     

    ์‹คํ–‰ ์ค‘์ธ ํ”„๋กœ์„ธ์Šค์—์„œ LMVCSS ๋ชฉ๋ก์„ ํ™•์ธํ–ˆ์„ ๋•Œ ์ˆ˜์ƒํ•œ ๊ฒฝ๋กœ๋ฅผ ํ™•์ธํ–ˆ๋‹ค.

    ์•ž์„œ ์•ž์—์„œ ์ง„ํ–‰ ์ค‘์ธ ์‹ค์Šต์—์„œ INITIAL_LANTERN.exe ์•…์„ฑ ํ”„๋กœ์„ธ์Šค๋ฅผ ํ™•์ธํ–ˆ์—ˆ๋Š”๋ฐ, LMVCSS๋Š” ์ด ๊ฒฝ๋กœ๋ฅผ ๋‚˜ํƒ€๋‚ด๊ณ  ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ LMVCSS๋Š” ์กฐ๊ธˆ ๋” ๋ถ„์„ํ•ด๋ณผ๋งŒ ํ•˜๋‹ค.

     

    E9AA7564B2D1D612479E193A9F8CB70DF9CFBE02A39900EEE22FE266F5320EBF

     

    LMVCSS๋Š” ์•„๋งˆ๋„ ์•…์„ฑ ํ”„๋กœ์„ธ์Šค์˜ ์ง€์†์„ฑ์„ ์œ„ํ•ด ์„œ๋น„์Šค์˜ ํ˜•ํƒœ๋กœ ์ฃผ์–ด์ ธ์žˆ์Œ์„ ์˜ˆ์ธกํ•ด๋ณผ ์ˆ˜ ์žˆ๊ฒ ๋‹ค.

    LMVCSS ๊ฒฝ๋กœ์˜ Hash๊ฐ’์„ ํ™•์ธํ•ด๋ณด๊ธฐ ์œ„ํ•ด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ถœ๋ ฅํ•œ๋‹ค.

     

     

     

    aurora-agent           Aurora Agent                                  Stopped Auto      "C:\Program Files\Aurora-Agent\aurora-agent-64.exe" --service --config "C:\P...

    C:\Program Files\Aurora-Agent\aurora-agent-64.exe

     

    Aurora Agent๋Š” Non-Running-Service๋กœ์„œ ์‹คํ–‰ ์ค‘์ด ์•„๋‹ˆ๋‹ค.

    ์‹œ์ž‘ ๋ชจ๋“œ๊ฐ€ Auto๋กœ ์„ค์ •๋˜์–ด์žˆ์ง€๋งŒ ๋ณด์•ˆ ์„œ๋น„์Šค์ธ Aurora Agent๊ฐ€ ์‹คํ–‰ํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ์ ์€ ๋” ์•Œ์•„๋ณผ ๋งŒํ•˜๋‹ค.

    ์ด Aurora Agent๋ฅผ ์œ ์‹ฌํžˆ ์‚ดํŽด๋ณด๋ฉฐ Hash๊ฐ’๊ณผ ๊ฐ์ข… ์ •๋ณด๋“ค์„ ํ™•์ธํ•ด๋ณด๋ ค๊ณ  ํ•œ๋‹ค.

     

    Name                   DisplayName                                   State   StartMode PathName
    ----                   -----------                                   -----   --------- --------
    AJRouter               AllJoyn Router Service                        Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
    ALG                    Application Layer Gateway Service             Stopped Manual    C:\Windows\System32\alg.exe
    AppIDSvc               Application Identity                          Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
    Appinfo                Application Information                       Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs -p
    AppMgmt                Application Management                        Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs -p
    AppReadiness           App Readiness                                 Stopped Manual    C:\Windows\System32\svchost.exe -k AppReadiness -p
    AppVClient             Microsoft App-V Client                        Stopped Disabled  C:\Windows\system32\AppVClient.exe
    AppXSvc                AppX Deployment Service (AppXSVC)             Stopped Manual    C:\Windows\system32\svchost.exe -k wsappx -p
    AudioEndpointBuilder   Windows Audio Endpoint Builder                Stopped Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
    Audiosrv               Windows Audio                                 Stopped Manual    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
    aurora-agent           Aurora Agent                                  Stopped Auto      "C:\Program Files\Aurora-Agent\aurora-agent-64.exe" --service --config "C:\P...
    AWSLiteAgent           AWS Lite Guest Agent                          Stopped Auto      "C:\Program Files\Amazon\XenTools\LiteAgent.exe"
    AxInstSV               ActiveX Installer (AxInstSV)                  Stopped Disabled  C:\Windows\system32\svchost.exe -k AxInstSVGroup
    BITS                   Background Intelligent Transfer Service       Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    BTAGService            Bluetooth Audio Gateway Service               Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
    BthAvctpSvc            AVCTP service                                 Stopped Manual    C:\Windows\system32\svchost.exe -k LocalService -p
    bthserv                Bluetooth Support Service                     Stopped Manual    C:\Windows\system32\svchost.exe -k LocalService -p
    camsvc                 Capability Access Manager Service             Stopped Manual    C:\Windows\system32\svchost.exe -k appmodel -p
    cfn-hup                CloudFormation cfn-hup                        Stopped Manual    "C:\Program Files\Amazon\cfn-bootstrap\winhup.exe"
    ClipSVC                Client License Service (ClipSVC)              Stopped Manual    C:\Windows\System32\svchost.exe -k wsappx -p
    COMSysApp              COM+ System Application                       Stopped Manual    C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC7...
    CscService             Offline Files                                 Stopped Disabled  C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
    defragsvc              Optimize drives                               Stopped Manual    C:\Windows\system32\svchost.exe -k defragsvc
    DeviceAssociationSe... Device Association Service                    Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    DeviceInstall          Device Install Service                        Stopped Manual    C:\Windows\system32\svchost.exe -k DcomLaunch -p
    DevQueryBroker         DevQuery Background Discovery Broker          Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    diagnosticshub.stan...                                               Stopped Manual    C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
    DiagTrack              Connected User Experiences and Telemetry      Stopped Disabled  C:\Windows\System32\svchost.exe -k utcsvc -p
    DmEnrollmentSvc        Device Management Enrollment Service          Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs -p
    dmwappushservice                                                     Stopped Disabled  C:\Windows\system32\svchost.exe -k netsvcs -p
    DoSvc                  Delivery Optimization                         Stopped Auto      C:\Windows\System32\svchost.exe -k NetworkService -p
    dot3svc                Wired AutoConfig                              Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    Eaphost                Extensible Authentication Protocol            Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    EFS                    Encrypting File System (EFS)                  Stopped Manual    C:\Windows\System32\lsass.exe
    embeddedmode           Embedded Mode                                 Stopped Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
    EntAppSvc              Enterprise App Management Service             Stopped Manual    C:\Windows\system32\svchost.exe -k appmodel -p
    fdPHost                Function Discovery Provider Host              Stopped Manual    C:\Windows\system32\svchost.exe -k LocalService -p
    FDResPub               Function Discovery Resource Publication       Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
    FrameServer            Windows Camera Frame Server                   Stopped Manual    C:\Windows\System32\svchost.exe -k Camera
    GoogleChromeElevati...                                               Stopped Manual    "C:\Program Files\Google\Chrome\Application\126.0.6478.114\elevation_service...
    GoogleUpdaterIntern...                                               Stopped Auto      "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --sys...
    GoogleUpdaterServic...                                               Stopped Auto      "C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe" --sys...
    GraphicsPerfSvc        GraphicsPerfSvc                               Stopped Disabled  C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup
    hidserv                Human Interface Device Service                Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    HvHost                 HV Host Service                               Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    icssvc                 Windows Mobile Hotspot Service                Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
    InstallService         Microsoft Store Install Service               Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    KPSSVC                 KDC Proxy Server service (KPS)                Stopped Manual    C:\Windows\system32\svchost.exe -k KpsSvcGroup
    KtmRm                  KtmRm for Distributed Transaction Coordinator Stopped Manual    C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p
    lfsvc                  Geolocation Service                           Stopped Disabled  C:\Windows\system32\svchost.exe -k netsvcs -p
    lltdsvc                Link-Layer Topology Discovery Mapper          Stopped Disabled  C:\Windows\System32\svchost.exe -k LocalService -p
    MapsBroker             Downloaded Maps Manager                       Stopped Disabled  C:\Windows\System32\svchost.exe -k NetworkService -p
    MSiSCSI                Microsoft iSCSI Initiator Service             Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs -p
    msiserver              Windows Installer                             Stopped Manual    C:\Windows\system32\msiexec.exe /V
    NcaSvc                 Network Connectivity Assistant                Stopped Manual    C:\Windows\System32\svchost.exe -k NetSvcs -p
    Netlogon               Netlogon                                      Stopped Manual    C:\Windows\system32\lsass.exe
    Netman                 Network Connections                           Stopped Manual    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p
    NetSetupSvc            Network Setup Service                         Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    NetTcpPortSharing      Net.Tcp Port Sharing Service                  Stopped Disabled  C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    NgcCtnrSvc             Microsoft Passport Container                  Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
    NgcSvc                 Microsoft Passport                            Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    PerfHost               Performance Counter DLL Host                  Stopped Manual    C:\Windows\SysWow64\perfhost.exe
    PhoneSvc               Phone Service                                 Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalService -p
    pla                    Performance Logs & Alerts                     Stopped Manual    C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p
    PrintNotify            Printer Extensions and Notifications          Stopped Manual    C:\Windows\system32\svchost.exe -k print
    PushToInstall          Windows PushToInstall Service                 Stopped Disabled  C:\Windows\System32\svchost.exe -k netsvcs -p
    QWAVE                  Quality Windows Audio Video Experience        Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
    RasAuto                Remote Access Auto Connection Manager         Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    RemoteAccess           Routing and Remote Access                     Stopped Disabled  C:\Windows\System32\svchost.exe -k netsvcs
    RemoteRegistry         Remote Registry                               Stopped Auto      C:\Windows\system32\svchost.exe -k localService -p
    RmSvc                  Radio Management Service                      Stopped Disabled  C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    RpcLocator             Remote Procedure Call (RPC) Locator           Stopped Manual    C:\Windows\system32\locator.exe
    RSoPProv               Resultant Set of Policy Provider              Stopped Manual    C:\Windows\system32\RSoPProv.exe
    sacsvr                 Special Administration Console Helper         Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    SCardSvr               Smart Card                                    Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    ScDeviceEnum           Smart Card Device Enumeration Service         Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    SCPolicySvc            Smart Card Removal Policy                     Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs
    seclogon               Secondary Logon                               Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs -p
    SecurityHealthService  Windows Security Service                      Stopped Manual    C:\Windows\system32\SecurityHealthService.exe
    SEMgrSvc               Payments and NFC/SE Manager                   Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalService -p
    Sense                                                                Stopped Manual    "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe"
    SensorDataService      Sensor Data Service                           Stopped Disabled  C:\Windows\System32\SensorDataService.exe
    SensorService          Sensor Service                                Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    SensrSvc               Sensor Monitoring Service                     Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
    SgrmBroker             System Guard Runtime Monitor Broker           Stopped Manual    C:\Windows\system32\SgrmBroker.exe
    SharedAccess           Internet Connection Sharing (ICS)             Stopped Disabled  C:\Windows\System32\svchost.exe -k netsvcs -p
    shpamsvc               Shared PC Account Manager                     Stopped Disabled  C:\Windows\System32\svchost.exe -k netsvcs -p
    smphost                Microsoft Storage Spaces SMP                  Stopped Manual    C:\Windows\System32\svchost.exe -k smphost
    SNMPTRAP               SNMP Trap                                     Stopped Manual    C:\Windows\System32\snmptrap.exe
    sppsvc                 Software Protection                           Stopped Auto      C:\Windows\system32\sppsvc.exe
    SSDPSRV                SSDP Discovery                                Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
    ssh-agent              OpenSSH Authentication Agent                  Stopped Disabled  C:\Windows\System32\OpenSSH\ssh-agent.exe
    stisvc                 Windows Image Acquisition (WIA)               Stopped Manual    C:\Windows\system32\svchost.exe -k imgsvc
    svsvc                  Spot Verifier                                 Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    swprv                  Microsoft Software Shadow Copy Provider       Stopped Manual    C:\Windows\System32\svchost.exe -k swprv
    tapisrv                Telephony                                     Stopped Manual    C:\Windows\System32\svchost.exe -k NetworkService -p
    TieringEngineService   Storage Tiers Management                      Stopped Manual    C:\Windows\system32\TieringEngineService.exe
    TrustedInstaller       Windows Modules Installer                     Stopped Manual    C:\Windows\servicing\TrustedInstaller.exe
    tzautoupdate           Auto Time Zone Updater                        Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalService -p
    UevAgentService        User Experience Virtualization Service        Stopped Disabled  C:\Windows\system32\AgentService.exe
    upnphost               UPnP Device Host                              Stopped Disabled  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p
    VaultSvc               Credential Manager                            Stopped Manual    C:\Windows\system32\lsass.exe
    vds                    Virtual Disk                                  Stopped Manual    C:\Windows\System32\vds.exe
    vmicguestinterface     Hyper-V Guest Service Interface               Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    vmicheartbeat          Hyper-V Heartbeat Service                     Stopped Manual    C:\Windows\system32\svchost.exe -k ICService -p
    vmickvpexchange        Hyper-V Data Exchange Service                 Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    vmicrdv                Hyper-V Remote Desktop Virtualization Service Stopped Manual    C:\Windows\system32\svchost.exe -k ICService -p
    vmicshutdown           Hyper-V Guest Shutdown Service                Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    vmictimesync           Hyper-V Time Synchronization Service          Stopped Manual    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
    vmicvmsession          Hyper-V PowerShell Direct Service             Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    vmicvss                Hyper-V Volume Shadow Copy Requestor          Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    VSS                    Volume Shadow Copy                            Stopped Manual    C:\Windows\system32\vssvc.exe
    WaaSMedicSvc           Windows Update Medic Service                  Stopped Manual    C:\Windows\system32\svchost.exe -k wusvcs -p
    WalletService          WalletService                                 Stopped Disabled  C:\Windows\System32\svchost.exe -k appmodel -p
    WarpJITSvc             WarpJITSvc                                    Stopped Manual    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    WbioSrvc               Windows Biometric Service                     Stopped Manual    C:\Windows\system32\svchost.exe -k WbioSvcGroup
    WdiServiceHost         Diagnostic Service Host                       Stopped Manual    C:\Windows\System32\svchost.exe -k LocalService -p
    WdNisSvc                                                             Stopped Manual    "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24050.7-0\NisSrv.exe"
    Wecsvc                 Windows Event Collector                       Stopped Manual    C:\Windows\system32\svchost.exe -k NetworkService -p
    WEPHOSTSVC             Windows Encryption Provider Host Service      Stopped Manual    C:\Windows\system32\svchost.exe -k WepHostSvcGroup
    wercplsupport                                                        Stopped Manual    C:\Windows\System32\svchost.exe -k netsvcs -p
    WerSvc                 Windows Error Reporting Service               Stopped Manual    C:\Windows\System32\svchost.exe -k WerSvcGroup
    WiaRpc                 Still Image Acquisition Events                Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
    wisvc                  Windows Insider Service                       Stopped Disabled  C:\Windows\system32\svchost.exe -k netsvcs -p
    wlidsvc                Microsoft Account Sign-in Assistant           Stopped Manual    C:\Windows\system32\svchost.exe -k netsvcs -p
    wmiApSrv               WMI Performance Adapter                       Stopped Manual    C:\Windows\system32\wbem\WmiApSrv.exe
    WMPNetworkSvc          Windows Media Player Network Sharing Service  Stopped Manual    "C:\Program Files\Windows Media Player\wmpnetwk.exe"
    WPDBusEnum             Portable Device Enumerator Service            Stopped Manual    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    CaptureService_4d465   CaptureService_4d465                          Stopped Manual    C:\Windows\system32\svchost.exe -k LocalService -p
    cbdhsvc_4d465          Clipboard User Service_4d465                  Stopped Manual    C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p
    CDPUserSvc_4d465       Connected Devices Platform User Service_4d465 Stopped Auto      C:\Windows\system32\svchost.exe -k UnistackSvcGroup
    ConsentUxUserSvc_4d465 ConsentUX_4d465                               Stopped Manual    C:\Windows\system32\svchost.exe -k DevicesFlow
    DevicePickerUserSvc... DevicePicker_4d465                            Stopped Disabled  C:\Windows\system32\svchost.exe -k DevicesFlow
    DevicesFlowUserSvc_... DevicesFlow_4d465                             Stopped Manual    C:\Windows\system32\svchost.exe -k DevicesFlow
    PimIndexMaintenance... Contact Data_4d465                            Stopped Manual    C:\Windows\system32\svchost.exe -k UnistackSvcGroup
    PrintWorkflowUserSv... PrintWorkflow_4d465                           Stopped Manual    C:\Windows\system32\svchost.exe -k PrintWorkflow
    UnistoreSvc_4d465      User Data Storage_4d465                       Stopped Manual    C:\Windows\System32\svchost.exe -k UnistackSvcGroup
    UserDataSvc_4d465      User Data Access_4d465                        Stopped Manual    C:\Windows\system32\svchost.exe -k UnistackSvcGroup
    WpnUserService_4d465   Windows Push Notifications User Service_4d465 Stopped Auto      C:\Windows\system32\svchost.exe -k UnistackSvcGroup
    CaptureService_1d8ddd  CaptureService_1d8ddd                         Stopped Manual    C:\Windows\system32\svchost.exe -k LocalService -p
    cbdhsvc_1d8ddd         Clipboard User Service_1d8ddd                 Stopped Manual    C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p
    ConsentUxUserSvc_1d... ConsentUX_1d8ddd                              Stopped Manual    C:\Windows\system32\svchost.exe -k DevicesFlow
    DevicePickerUserSvc... DevicePicker_1d8ddd                           Stopped Disabled  C:\Windows\system32\svchost.exe -k DevicesFlow
    DevicesFlowUserSvc_... DevicesFlow_1d8ddd                            Stopped Manual    C:\Windows\system32\svchost.exe -k DevicesFlow
    PimIndexMaintenance... Contact Data_1d8ddd                           Stopped Manual    C:\Windows\system32\svchost.exe -k UnistackSvcGroup
    PrintWorkflowUserSv... PrintWorkflow_1d8ddd                          Stopped Manual    C:\Windows\system32\svchost.exe -k PrintWorkflow
    UnistoreSvc_1d8ddd     User Data Storage_1d8ddd                      Stopped Manual    C:\Windows\System32\svchost.exe -k UnistackSvcGroup
    UserDataSvc_1d8ddd     User Data Access_1d8ddd                       Stopped Manual    C:\Windows\system32\svchost.exe -k UnistackSvcGroup

     

    Get-FileHash " C:\Program Files\Aurora-Agent\aurora-agent-64.exe " | tee service-file-2.txt

    Get-Item -Path " C:\Program Files\Aurora-Agent\aurora-agent-64.exe " | fl Name, FullName, Length, CreationTime, LastAccessTime, LastWriteTime, VersionInfo | tee service-file-2-details.txt

     

     

     

     

    D5C8BF2D3B56B21639D8152DB277DD714BA1A61BDAF2350BD0FF7E61D2A99003

     

    ๋‹ค์Œ๊ณผ ๊ฐ™์€ aurora-agent-64.exe์˜ ํ•ด์‹œ ๊ฐ’ ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. ๋˜ํ•œ ๊ฒฝ๋กœ๋„ ํ™•์ธ๋˜์—ˆ๋‹ค.

     

     

    ๋ฐœ๊ฒฌ๋œ ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด Name, FullName, Length, CreationTime, LastAccessTime, LastWriteTime, VersionInfo๋ฅผ ํ™•์ธํ•˜๋„๋ก ํ•œ๋‹ค. ์ด๋•Œ ๋ฐœ๊ฒฌ๋  ์ˆ˜ ์žˆ๋Š” OriginalFilename์€ x3xv5weg, ์ฆ‰ ์„œ๋น„์Šค ์‹คํ–‰ ํŒŒ์ผ aurora-agent์˜ ์ด๋ฆ„์ด ๋‚˜ํƒ€๋‚œ๋‹ค. ์ด ์ •๋ณด๋Š” ๋งค์šฐ ์ค‘์š”ํ•˜๋‹ค. ๋ฌด์–ธ๊ฐ€ ํ•ฉ๋ฒ•์ ์ด์ง€ ์•Š์€ ์ธ์Šคํ„ด์Šค๊ฐ€ ํ•ด๋‹น info์—์„œ ๋‚˜ํƒ€๋‚œ๋‹ค.

     

    ์ด๋ฒˆ์—๋Š” scheduled task(์˜ˆ์•ฝ๋œ ์ž‘์—…)์„ ํ™•์ธํ•ด๋ณผ ๊ฒƒ์ด๋‹ค. ์—ฌ๊ธฐ์„œ Aurora-agent์™€ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” ์ž‘์—…์„ ํ™•์ธํ•ด๋ณด์•„์•ผ ํ•œ๋‹ค. ์ž˜๋ณด๋ฉด ๋‘ ๊ฐœ์˜ scheduled task๊ฐ€ C:\Program Files\Aurora-Agent\aurora-agent-util.exe์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. 

     

    ํ˜„์žฌ ์‹œ์Šคํ…œ์— ๋“ฑ๋ก๋œ ์˜ˆ์•ฝ๋œ ์ž‘์—…์„ ๋‚˜์—ดํ•ด๋ณด๋Š”๋ฐ, ๋น ๋ฅธ ๊ฒ€์‚ฌ๋Š” ์‹œ์Šคํ…œ์— ๋“ฑ๋ก๋œ ์˜ˆ์•ฝ ์ž‘์—…์ด ์—†์Œ์„ ๋‚˜ํƒ€๋‚ด๊ณ  ์žˆ๋‹ค.

     

     

     

    ์œ„์˜ ์ •๋ณด๋“ค์„ ํ†ตํ•ด ํ•ต์‹ฌ ๋‚ด์šฉ๋“ค์„ submitํ•˜๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋กœ ์ง„์ž…ํ•  ์ˆ˜ ์žˆ๋‹ค.

     


     Task 10 Background Activities III: Processes and Directories

    ๋™์  ํ™œ๋™ ํ”„๋กœ์„ธ์Šค

    ํ”„๋กœ์„ธ์Šค์˜ ์ด์ƒ ์ง•ํ›„๋ฅผ ๋ช…ํ™•ํ•˜๊ฒŒ ํŒŒ์•…ํ•˜๊ธฐ ์œ„ํ•ด์„œ ํ•ด๋‹น ์‹ค์Šต์„ ์ง„ํ–‰ํ•œ๋‹ค.

    ํ”„๋กœ์„ธ์Šค์˜ ๋น„์ •์ƒ์ ์ธ ์ด๋ฆ„, ๊ฒฝ๋กœ, ํ”„๋กœ์„ธ์Šค ๋ถ€๋ชจ-์ž์‹ ๊ด€๊ณ„, ๋ช…๋ น๊ณผ ๊ทธ ์ด์ „์˜ ๋‹จ๊ณ„์˜ ๊ฒฐ๊ณผ๋ฅผ ํŒŒ์•…ํ•˜๊ธฐ ์œ„ํ•œ ์ž‘์—…์„ ํ•ด์ฃผ๋„๋ก ํ•˜๊ฒ ๋‹ค. ํ”„๋กœ์„ธ์Šค ์„ธ๋ถ€ ์ •๋ณด๋“ค์„ ๋‚˜์—ดํ•  ๊ฒƒ์ด๋ฏ€๋กœ ๋‹ค์Œ ์ •๋ณด๋ฅผ ํ† ๋Œ€๋กœ ์ •๋‹ต์„ ์œ ์ถ”ํ•ด๋ณด์ž.

     

     

    ๋‹ค์Œ ํ”„๋กœ์„ธ์Šค ์ •๋ณด์—์„œ ์œ ์˜ํ•ด๋ณผ๋งŒํ•œ ์ ์€ INTIAL_LANTERN[.]exe์™€ ssh.exe, aurora-agent-64.exe์ด๋‹ค.

    ํ•ด๋‹น ํ”„๋กœ์„ธ์Šค ์ •๋ณด๋ฅผ ๋”ฐ๋กœ ๋นผ์™€์„œ ์ฝ”๋“œ๋กœ ์ ์–ด๋ณด๋„๋ก ํ•˜๊ฒ ๋‹ค.

     

    aurora-agent-64.exe     3848   960 SYSTEM          "C:\Program Files\Aurora-Agent\aurora-agent-64.exe"             C:\Program Files\Aurora-Agent\aurora-agent-64.exe
    conhost.exe              544  3848 SYSTEM          \??\C:\Windows\system32\conhost.exe 0x4                         C:\Windows\system32\conhost.exe
    ssh.exe                 4280  3848 SYSTEM          "C:\Windows\System32\OpenSSH\ssh.exe" james@10.10.10.10         C:\Windows\System32\OpenSSH\ssh.exe

    ssh ์—ฐ๊ฒฐ ์‹œ๋„์— james@10.10.10.10๊ฐ€ ์‚ฌ์šฉ๋˜์—ˆ๋‹ค. ๋˜ํ•œ ํ”„๋กœ์„ธ์Šค์˜ ์˜์‹ฌ์Šค๋Ÿฌ์šด ๊ฒฝ๋กœ๋„ ํ™•์ธ๋œ๋‹ค.

    aurora-agent์™€ ssh๋Š” ์ž์‹-๋ถ€๋ชจ ๊ด€๊ณ„๋ฅผ ํ˜•์„ฑํ•˜๊ณ  ์žˆ๋‹ค.

     

    INTIAL_LANTERN[.]exe์˜ ํ”„๋กœ์„ธ์Šค๋ฅผ ๋” ์ž์„ธํžˆ ํ™•์ธํ•ด๋ณด๋„๋ก ํ•˜๊ฒ ๋‹ค.

     

     

     

    Get-FileHash C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe | tee process-file-1.txt

    C:\Users\Administrator\AppData\SpcTmp\INITIAL_LANTERN.exe

     

    ์ด์ „์— ์ง„ํ–‰ํ–ˆ๋˜ ๊ฒƒ๊ณผ ๊ฐ™์ด Hash๊ฐ’๊ณผ ๊ฒฝ๋กœ๋ฅผ ํ™•์ธํ–ˆ๋‹ค.

     

     

     

    Get-FileHash C:\Users\Default\AppData\Local\Temp\jmp.exe

    C:\Users\Default User\AppData\Local\Temp\jmp.exe

     

    ์ด์ œ ๋””๋ ‰ํ† ๋ฆฌ ๊ฒ€์‚ฌ๋ฅผ ์ง„ํ–‰ํ•ด์ค„ ๊ฒƒ์ด๋‹ค. aurora-agent์™€ ssh์—์„œ ์ˆ˜์ƒํ•œ ๊ฒฝ๋กœ๋Š” Temp์˜€๋‹ค. ์ด ๊ฒฝ๋กœ๋ฅผ ์กฐ๊ธˆ ๋” ํ™•์ธํ•ด๋ณด๊ธฐ๋กœ ํ–ˆ๋‹ค. \AppData\Local\Temp๋ฅผ ์‚ฌ์šฉํ•œ ์‚ฌ์šฉ์ž ์ •๋ณด์™€ ํŒŒ์ผ ์ •๋ณด๋ฅผ ํ™•์ธํ•œ๋‹ค.

     

    Default User๊ฐ€ jmp.exe๋ผ๋Š” EXE ํŒŒ์ผ์„ ์‚ฌ์šฉํ–ˆ๋‹ค. ์ด ์ ์— ์กฐ๊ธˆ ๋” ์œ ์˜ํ•œ๋‹ค.

     

     

    jmp.exe์˜ hash๊ฐ’์„ ๋ถˆ๋Ÿฌ์˜จ๋‹ค.

     

     

    ๋˜ํ•œ jmp.exe์˜ ํŒŒ์ผ ์„ธ๋ถ€ ์ •๋ณด๋„ ๋ถˆ๋Ÿฌ์™”๋‹ค. ๊ทธ ๊ฒฐ๊ณผ ์•„๊นŒ ๋ฐœ๊ฒฌํ–ˆ๋˜ aurora-agent์˜ OriginalFilename๊ณผ ์™„์ „ํžˆ ์ผ์น˜ํ•˜๋Š” x3xv5weg.exe๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค! ์ด๋กœ์„œ jmp.exe๋„ ์˜์‹ฌ์Šค๋Ÿฌ์šด ํŒŒ์ผ์ด๋ผ๋Š” ๊ฒƒ์ด ์ฆ๋ช…๋˜์—ˆ๋‹ค.

     

     

     

    ์ด๋ฒˆ์—๋Š” SpcTmp๊ฒฝ๋กœ๋„ ๋‹ค์‹œ ํ•œ๋ฒˆ ํ™•์ธํ•ด๋ณธ๋‹ค. ์—ญ๋ฐฉํ–ฅ ํ”„๋ก์‹œ ์œ ํ‹ธ๋ฆฌํ‹ฐ์— ์‚ฌ์šฉ๋˜๋Š” ์ž ์žฌ ์Šคํฌ๋ฆฝํŠธ Invoke-SocksProxy.pm1์ด ํ™•์ธ๋˜์—ˆ๋‹ค. INITIAL_LANTERN.exe ๋„ ์—ญ์‹œ ํ™•์ธ๋˜์—ˆ๋‹ค.

     

     

     

    C: ๋“œ๋ผ์ด๋ธŒ๊ฐ€ ์•„๋‹Œ ๋ฌธ์ž๊ฐ€ ์—†๋Š” ์ˆจ๊ฒจ์ง„ ๋””์Šคํฌ ๋ณผ๋ฅจ์ด ๋‚˜ํƒ€๋‚ฌ๊ณ , ํ•ด๋‹น ๋””์Šคํฌ์˜ ๋ผ๋ฒจ์€ Setups์ด๋‹ค.

    ๋“œ๋ผ์ด๋ธŒ ์ด๋ฆ„์— ๋ฌธ์ž๋ฅผ ๋„ฃ์ง€ ์•Š์•˜๋‹ค๋Š” ๊ฒƒ์€ ๊ฒ€์‚ฌ์—์„œ ํƒ์ง€๋ฅผ ์ˆจ๊ธฐ๊ธฐ ์œ„ํ•œ ํ–‰๋™์ด๋ผ๊ณ  ๋ณผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ ๊ฐ™๋‹ค.

     

     

     

     

    ์—ฌ๊ธฐ๊นŒ์ง€ ๋”ฐ๋ผ์™”๋‹ค๋ฉด ๋‹ต์„ ๋ฌด๋‚œํ•˜๊ฒŒ ์ž…๋ ฅํ•ด๋ณผ ์ˆ˜ ์žˆ๋‹ค.

     

     

     

    ๋Œ“๊ธ€