Confickerã¯ãã¯ãŒã ã«é¢é£ãããã«ãŠã§ã¢ã®ãã¡ããªãŒã§ãã Confickerã¯ããã¹ã³ãã§æããã䜿çšãããååã§ãæåã®ããŒãžã§ã³ã®ãã«ãŠã§ã¢ãã¢ã¯ã»ã¹ããtrafficconverter.bizãã¡ã€ã³ã®äžéšã䞊ã¹æ¿ããããšã«ãã£ãŠåœ¢æãããŸããå¥ã®ããŒãžã§ã³ã«ãããšããã®ååã¯è±èªã®åèªæ§æãšãã€ãèªã®åèªfickerïŒè±èªã®ãã¡ãã«ãŒã®å矩èªïŒã«ç±æ¥ããŸãã å€åœã®ãŠã€ã«ã¹å¯ŸçäŒæ¥ã®éã§ã¯ãã«ã¹ãã«ã¹ããŒã®åé¡ã§ãããšåæ§ã«Downadupãšããååã䜿çšãããŠããŸãã æåã®ãµã³ãã«ã¯2008幎11æã«çºèŠãããŸããã 2009幎1æçŸåšãäžçäžã§çŽ900äžå°ã®ã³ã³ãã¥ãŒã¿ãŒã圱é¿ãåããŠããŸãã ãã®ãããªå€§ããªæ°ã¯ãMicrosoft Windowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã MS08-067ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®è匱æ§ãè匱æ§ã®èªåé
åžã«äœ¿çšãããŠããããã§ãã é
åžæã«ããã€ã¯ããœããã¯æ¢ã«ãã®è匱æ§ã«å¯ŸåŠããã»ãã¥ãªãã£æŽæ°ããã°ã©ã ããªãªãŒã¹ããŠããããšã«æ³šæããŠãã ããã ãã ããäžè¬ãŠãŒã¶ãŒã¯ãååãšããŠããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ç¶ç¶çãªæŽæ°ã®ã¡ã«ããºã ïŒãæµ·è³çãã³ããŒã®äœ¿çšãå«ãïŒã«ååãªæ³šæãæã£ãŠããªããšããäºå®ãéèŠãªåœ¹å²ãæãããŸããã æ®å¿µãªããšã«ãå®éã«ããäžåºŠãã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£åé¡ãç¡èŠããããšã瀺ãããŸããã 2009幎4æãããããããã®ãµã€ãºã¯350äžãšæšå®ãããŸããã
Confickerã«ã¯5ã€ã®äž»èŠãªå€æŽããããAïŒ2008幎11æ21æ¥ïŒãBïŒ2008幎12æ29æ¥ïŒãCïŒ2009幎2æ20æ¥ïŒãDïŒ2009幎3æ4æ¥ïŒãEïŒ2009幎4æ7æ¥ïŒã§ç€ºãããŸãã äžéšã®ã¢ã³ããŠã€ã«ã¹äŒæ¥ã®çšèªã§ã¯ãããããååAãBãB ++ãCãDã䜿çšããŠããŸãã
Conficker.A
ãã«ãŠã§ã¢ã³ãŒãã¯Windows Dynamic LibraryïŒPE DLLãã¡ã€ã«ïŒãšããŠã³ã³ãã€ã«ãããUPXã䜿çšããŠããã±ãŒãžåãããŸãã ã³ããŒã«ã€ããŠã¯ãkernel32.dllãã¡ã€ã«ããååŸããäœææ¥ãšå€æŽæ¥ãå²ãåœãŠãŠãæ¥ä»ã§ãœãŒãããããšã«ããæ€åºã®å¯èœæ§ãæé€ããŸãã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ã«å¿ããŠã次åã®ã·ã¹ãã èµ·åæã«ç°ãªãæ¹æ³ã§èªåèµ·åããŸãã Windows 2000ãã€ã³ã¹ããŒã«ãããŠããå Žåãã³ãŒãã¯services.exeããã»ã¹ã«æ¿å
¥ãããŸãã ãã以å€ã®å Žåãsvchost.exeãå®è¡ããnetsvcsãšãããµãŒãã¹ãäœæãããŸãã
ãã®ããŒãžã§ã³ã«ã¯ããµãŒããŒãµãŒãã¹ïŒMS08-067ïŒã®è匱æ§ãæªçšãã1ã€ã®é
åžæ¹æ³ã®ã¿ãå«ãŸããŠããŸããã ãããè¡ãããã«ãConfickerã¯ã©ã³ãã ãªTCPããŒãã§HTTPãµãŒããŒãèµ·åããŸãããã®ããŒãã¯ãä»ã®ã³ã³ãã¥ãŒã¿ãŒãžã®ããŠã³ããŒãã«äœ¿çšãããŸãã Confickerã¯ãã¹ãã£ã³ã«ãããããã¯ãŒã¯ç°å¢ã®ã³ã³ãã¥ãŒã¿ãŒã®IPã¢ãã¬ã¹ã®ãªã¹ããååŸããŸãã ãããã¯ãŒã¯ã®é«éäŒæã確ä¿ããããã«ãã¯ãŒã ã¯ãã¡ã¢ãªã«ããŒããããtcpip.sysã·ã¹ãã ãã©ã€ããŒã€ã¡ãŒãžã®å€æŽãšãã©ã¡ãŒã¿ãŒã®å€æŽã䜿çšããŠãã·ã¹ãã å
ã®ãããã¯ãŒã¯æ¥ç¶ã®å¯èœãªæ°ãå¢ãããŸãã
'TcpNumConnections' = [dwordïŒ0x00FFFFFE '[HKLM \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters]ã¬ãžã¹ããªãã©ã³ãã 次ã«ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãæ»æããŸãã ãããè¡ãã«ã¯ãnetapi32.dllã©ã€ãã©ãªã§wcscpy_sé¢æ°ãåŒã³åºããããšãç¹å¥ã«çæãããRPCèŠæ±ãéä¿¡ããããããã¡ãŒãªãŒããŒãããŒãçºçããŸãã ãã®çµæãå¶åŸ¡ã¯ããŒãããŒããŒã«è»¢éãããããŒãããŒããŒã¯ææããã³ã³ãã¥ãŒã¿ãŒããConfickerãããŠã³ããŒãããå®è¡ããããã«èµ·åããŸãã MS08-067è匱æ§ã®åå©çšãé²ãããïŒä»ã®ãã«ãŠã§ã¢ãã³ã³ãã¥ãŒã¿ãŒã«ææã§ããªãããã«ããããïŒãConfickerã¯netapi32.dllã©ã€ãã©ãªã®NetpwPathCanonicalizeé¢æ°ãåŒã³åºãããã®ãã©ãããèšå®ãããããã¡ãŒãªãŒããŒãããŒãé²ãããããããããã¯ãããžãŒãå®è£
ããŸãïŒåèµ·åããã«æŽæ°ãã€ã³ã¹ããŒã«ããŸãããå®éããããã¯ã€ã³ã¹ããŒã«ãããŠããŸããïŒã
管ççšã®ã³ãã³ãã»ã³ã¿ãŒã®ååã¯ããŒãã³ãŒããããŠãããã5ã€ã®ãããã¬ãã«ãã¡ã€ã³ã®ãã¬ãã£ãã¯ã¹ã䜿çšããæ¬äŒŒã©ã³ãã ã¢ã«ãŽãªãºã ã䜿çšããŠãæ¯æ¥250ãã¡ã€ã³ãçæãããŸãã ãããã£ãŠãäœæè
ã¯ããŠã€ã«ã¹å¯ŸçäŒç€Ÿã®åŸæ¥å¡ããã©ãã¯ãªã¹ãã«ã³ãã³ãã»ã³ã¿ãŒã®ã¢ãã¬ã¹ãå
¥åããŠå¶åŸ¡ã倱ãããšãã身ãå®ãããšããŸããã Confickerã¯ããããããã€ã³ã¿ãŒãããããä»ã®æªæã®ããããã°ã©ã ãããŠã³ããŒãããŠèµ·åããã³ãã³ããååŸããããšããŸãã ããã«ã圌ã¯trafficconverter.bizãã¡ã€ã³ã«ç®ãåããããããããŠã³ããŒãããŠãloadadv.exeãšããåºå®åã®ãã¡ã€ã«ãå®è¡ããããšããŸãã
ããŠã³ããŒãããããã¡ã€ã«ã®çœ®æãé²ãããã«ãæå·åãšããžã¿ã«çœ²åã䜿çšããæå·åã¢ã«ãŽãªãºã ã䜿çšãããŸããã ããŠã³ããŒããããã¡ã€ã«ã«å¯ŸããŠ512ãããã®SHA-1ããã·ã¥ãèšç®ãããRC4ã¢ã«ãŽãªãºã ã䜿çšããŠæå·åããŒãšããŠäœ¿çšãããŸãã;ãã®ããã·ã¥ã¯ã1024ãããããŒã§RSAã«ããžã¿ã«çœ²åããããã«ã䜿çšãããŸããã 次ã®ãªãã·ã§ã³ãšã¯ç°ãªããèªå·±é²è¡ã®æ©èœã¯å«ãŸããŠããŸããã§ããã
Conficker.Aã¯ãŠã¯ã©ã€ãã®ããŒããŒãã¬ã€ã¢ãŠãããã§ãã¯ãããã®å Žåã¯èªå·±ç Žå£ãããããConfickerããŠã¯ã©ã€ãã§éçºãããããšã瀺åãããŠããŸãã ããã«ãGeoIPããŒã¿ããŒã¹ã¯maxmind.comããããŠã³ããŒããããã¹ãã£ã³ããããšããã®ãã«ãã§ç¹å®ããããŠã¯ã©ã€ãã®ã¢ãã¬ã¹ã¯ææããŸããã å°æ¥ã®ããŒãžã§ã³ã§ã¯ããã®æ©èœã¯å®è£
ãããŠããŸããã
Conficker.B
ãã®ããŒãžã§ã³ã§ã¯ãã匱ãããã¹ã¯ãŒãã䜿çšãããããã¯ãŒã¯ãªãœãŒã¹ïŒãã£ã¬ã¯ããªïŒãšautorun.infãä»ããŠèµ·åããUSBââ-Flashã¡ãã£ã¢ã«ææããã¢ã«ãŽãªãºã ã䜿çšããŠããçæ¯å°ããæ¡å€§ãã2ã€ã®é
åžã¡ã«ããºã ãè¿œå ãããŸããã Confickerã¯ã管çè
ã¢ã«ãŠã³ãã§ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãžã®æ¥ç¶ãè©Šã¿ãŸã;ãã®ããããã¹ã¯ãŒãã¯ã³ãŒãã§æå®ããããªã¹ãã«åŸã£ãŠé çªã«åæãããŸãã éžæãæåãããšãã¯ãŒã ãã¡ã€ã«ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã«ã³ããŒãããregsvr32ã䜿çšããŠãµãŒãã¹ãšããŠå®è¡ããTask Shedulerã¿ã¹ã¯ãäœæãããŸãã USB-Flashã¡ãã£ã¢ããã®èªåå®è¡ã§ã¯ãé£èªåãããautorun.infãã¡ã€ã«ãäœæãããŸããdllãã¡ã€ã«èªäœã¯ãRECYCLERé ããã£ã¬ã¯ããªã«vmxæ¡åŒµåãæã€ã©ã³ãã ãªååã§é
眮ãããŸãã
ä¿®æ£ããããŠã³ããŒãããããã¡ã€ã«ã®æå·ä¿è·ã¡ã«ããºã ã¯å€æŽããã MD6ã¢ã«ãŽãªãºã ïŒ2008幎ã«éçºãããåœæã®ææ°ïŒãããã·ã¥ã¢ã«ãŽãªãºã ãšããŠäœ¿çšãããRSAããŒã®é·ãã4096ãããã«å¢å ããŸããã ãã®ã³ãŒãã¯ãããããã¡ãªãŒããŒãããŒããªã©ã®è匱æ§ãæå·åã¢ã«ãŽãªãºã ã®å®è£
ã®è匱æ§ã䜿çšãããã¹ãŠã®æœåšçãªæ©äŒãæé€ããããšãèè
ãæãã§ããããšãæ確ã«ç€ºããŠããŸãã
ãã®ããŒãžã§ã³ã§ã¯ãèªå·±é²è¡æ©èœãå°å
¥ãããŸããã ç¹ã«ã次ã®ãµãŒãã¹ã¯ç¡å¹ã«ãªããŸãããWindowsèªåæŽæ°ãµãŒãã¹ã ããã¯ã°ã©ãŠã³ãã€ã³ããªãžã§ã³ã転éãµãŒãã¹ã
Windowsã»ãã¥ãªãã£ã»ã³ã¿ãŒãµãŒãã¹ã Windows DefenderãµãŒãã¹ã Windowsãšã©ãŒå ±åãµãŒãã¹ã ãã®ããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®æŽæ°ã¡ã«ããºã ãç¡å¹ã«ãªããMicrosoftããç¹å¥ãªåé€ããŒã«ãã€ã³ã¹ããŒã«ãããå¯èœæ§ããããŸããã ã€ã³ã¿ãŒã»ããã¯ãdnsrslvr.dllã©ã€ãã©ãªã®æ¬¡ã®é¢æ°ãåŒã³åºãããã«ã€ã³ã¹ããŒã«ãããŸãããDNS_Query_A; DNS_Query_UTF8; DNS_Query_W; Query_Main SendTo; NetpwPathCanonicalize; InternetGetConnectedStateã åæã«ãDNSãµãŒãã¹ãä»ããŠèŠæ±ããããªãœãŒã¹ã®ååã¯ããã¡ã€ã³ã®ç¹å®ã®ãªã¹ããžã®ã¢ã¯ã»ã¹ãå¶éããããã«ãã£ã«ã¿ãŒãããŸããã ãã®ãããã¡ã€ã³ãµã€ããžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ããããã¯ãããŸãããããã§ã¯ããŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã®æŽæ°ãŸãã¯ç¹å¥ãªãã«ãŠã§ã¢åé€ãŠãŒãã£ãªãã£ãããŠã³ããŒãã§ããŸãã
Conficker.C
äž»ãªå€æŽã¯ãã¡ã€ã³çæã¡ã«ããºã ã®ã¿ã«é¢ä¿ãããããäžéšã®ãŠã€ã«ã¹å¯ŸçäŒæ¥ã¯ãã®ããŒãžã§ã³ãB ++ãšåŒãã§ããŸãã Confickerãæ¬äŒŒã©ã³ãã ã¢ã«ãŽãªãºã ã䜿çšããŠçæãããã¡ã€ã³åãäºçŽããConficker Working Groupã®åãçµã¿ã«å¿ããŠãéçºè
ã¯1æ¥ãããã®æ°ã250ãã50,000ã«å¢ãããŸããã çæã«ã¯ããã§ã«5ã€ã®ä»£ããã«8ã€ã®ãããã¬ãã«ãã¡ã€ã³ã®ãã¬ãã£ãã¯ã¹ã䜿çšããã50,000ãã500ãéžæãããŸãããããã¯ãææãããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã®çŽ1ïŒ
ã®æ¯æ¥ã®æ¥ç¶ãæå³ããã³ã³ãããŒã«ã»ã³ã¿ãŒã®è² è·ã軜æžããŸããã ããšãã°ã1000äžãšããæ°åã䜿çšãããšããµãŒããŒã¯å®éã«100,000å°ã®ã³ã³ãã¥ãŒã¿ãŒããã®DDOSæ»æãåããããšãæå³ããŸãã
Conficker.D
ãã¡ã€ã³ã®çæã«äœ¿çšããããã¬ãã£ãã¯ã¹ã®æ°ã¯8ãã110ã«å¢å ããŸãããã¢ã«ãŽãªãºã éçºè
ã®Ronald Rivestã«ãã£ãŠäœæããã2009幎2æ19æ¥ã«å
¬éãããMD6ã¿ã€ãããããã¡ãªãŒããŒãããŒãã®å®è£
ã®ãšã©ãŒãä¿®æ£ãããŸããã èªå·±é²è¡ã·ã¹ãã ãæ¹åãããŸãã-ãã»ãŒãã¢ãŒããã§èµ·åããæ©èœããªãã«ãªããååã«ç¹å®ã®è¡ãå«ãŸããããã°ã©ã ïŒã¢ã³ããŠã€ã«ã¹ããã°ã©ã ïŒã®ããã»ã¹ãçµäºããããšããŸããã
ç¬èªã®é
åžã®ã¡ã«ããºã ã¯å®å
šã«åé€ãããŸããã æŽæ°ã®ããã®ãã¢ããŒãã¢ã¡ã«ããºã ãå°å
¥ãããŸããã ã¯ãŒã ã®ä»ã®ã³ããŒããæ
å ±ãåä¿¡ããããã«ã2ã€ã®ããµãŒããŒãã¹ããªãŒã ãäœæãããŸãã1ã€ã¯TCPäžã§å®è¡ããããã1ã€ã¯UDPäžã§å®è¡ãããŸãã p2på®è£
ã®èå³æ·±ãæ©èœã¯ããã¢ã®å
ã®ãªã¹ãã®æåŠã§ãã ãã®ãªã¹ãã¯éåžžââãå®è¡å¯èœã³ãŒãå
ã§æå®ããããããããªãã¯ãµãŒããŒã«é
眮ãããŸãã Confickerã¯ãIPã¢ãã¬ã¹ãã¹ãã£ã³ããŠãã¢ãèŠã€ããŸãã èŠã€ãã£ãIPã¢ãã¬ã¹ããšã«ãConfickerãæ©èœããŠãããã©ããã確èªããŸããã ãã®å Žåããªã¢ãŒãã³ããŒãšéä¿¡ããããã®ãã¯ã©ã€ã¢ã³ããã¹ã¬ãããäœæãããŸããã ã¹ãã£ã³äžã«ãã¢ã³ããŠã€ã«ã¹äŒç€Ÿã®ã¢ãã¬ã¹ã®ãã©ãã¯ãªã¹ãã®IPããã§ãã¯ãããŸãããããããã¯ã¢ã¯ã»ã¹ãããŸããã ãµãŒããŒã¹ããªãŒã ã¯ãæ¥ç¶ãããã¯ã©ã€ã¢ã³ãã®ã¢ãã¬ã¹ããã¢ãªã¹ãã«è¿œå ããŸããã ã¯ãŒã ã®çŸåšã®ããŒãžã§ã³ããªã¢ãŒãããŒãžã§ã³ãšäžèŽããå Žåãã¢ãã¬ã¹ã¯ã¯ã©ã€ã¢ã³ãã¹ã¬ããã«ãã£ãŠã®ã¿è¿œå ãããŸãã ç°ãªãããŒãžã§ã³ã®å Žåãææ°ã®ããŒãžã§ã³ã¯ããµãŒããŒããã¯ã©ã€ã¢ã³ãã«ãã£ãŠããŸãã¯ã¯ã©ã€ã¢ã³ããããµãŒããŒã«ãã£ãŠããŠã³ããŒããããŸãã p2pã¡ã«ããºã ã¯ãããŠã³ããŒãããããã¡ã€ã«ãåŸç¶ã®ãé
åžãã®ããã«ä¿åããã¢ãŒããšãã¢ãã¬ã¹ç©ºéã§ã¹ããªãŒã ãšããŠèµ·åã¢ãŒãã®2çš®é¡ã®é
åžãæäŸããŸãã ããã«ãããå®è¡å¯èœã³ãŒãããã¡ã€ã«ãšããŠä¿åããã«å®è¡äžã«çœ®ãæããããšãã§ããŸãã åæã«ãçæããããã¡ã€ã³ã«ãã£ãŠããŠã³ããŒãããããã¡ã€ã«ãèµ·åãããå®è¡äžã®Confickerã«é¢ä¿ãªãæ©èœããŸãã
Conficker.E
ç¹°ãè¿ãã«ãªããŸãããããã€ãã®ã€ãããŒã·ã§ã³ãå°å
¥ãããŸããã ããšãã°ãææã®ããã«å©çšå¯èœãªIPãã¹ãã£ã³ããïŒP2Pã¡ã«ããºã ãä»ããŠïŒæŽæ°ãéä¿¡ããæé ã¯ãã€ã³ã¿ãŒãããäžã®ãã£ãã«å¹
ãæšå®ãããã®è©äŸ¡ã«åŸã£ãŠããã®é
åžãšã¹ãã£ã³ã¢ã¯ãã£ããã£ãèŠå¶ããŸãã ããã¯ãLAN管çè
ã®æ³šæãåŒãä»ããªãããã«ããããã§ãã å¥ã®æ©èœã¯ããã®é
åžã®ããã®ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€æŽã§ãã ææã¢ã«ãŽãªãºã ã§ã¯ãConfickerã³ãŒããããŠã³ããŒãããããã«ãææãã¹ããææãã¹ããšã®æ¥ç¶ãéå§ããå¿
èŠããããŸãïŒãšã¯ã¹ããã€ãMS08-067ãæ£åžžã«ããªã¬ãŒãããåŸïŒã éåžžãã¢ãã ãšã«ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ããããã¡ã€ã¢ãŠã©ãŒã«ã¯ããã®ã¢ã¯ãã£ããã£ããããã¯ããŸãã ããã«ãææããã³ã³ãã¥ãŒã¿ãŒã¯NATã®èåŸã«ããå¯èœæ§ãé«ãã§ãã ãããã£ãŠãConfickerã¯ããŒã«ã«ãããã¯ãŒã¯ã®ã²ãŒããŠã§ã€ãäºåã«æ€åºããŸãã ãããè¡ãã«ã¯ããããã¯ãŒã¯å
šäœã«ã¡ãã»ãŒãžããããŒããã£ã¹ãããç¬èªã®SSDPãµãŒããŒãå®è¡ããŸãã SSDPããµããŒããããããã¯ãŒã¯ããã€ã¹ãå¿çãéä¿¡ããŸãã ãã®æ¹æ³ã§ã²ãŒããŠã§ã€ãæ€åºãããšãã¯ãŒã ã¯UPnPã¡ã«ããºã ãä»ããŠæ©åšãåæ§æããã²ãŒããŠã§ã€ãå察æ¹åã«ïŒå
éšã®å€éšãããã¯ãŒã¯ããïŒééãããã£ãã«ãäœæãããã®ãã£ãã«ã䜿çšããŠä»ã®ã³ã³ãã¥ãŒã¿ãŒã«ææããŸãã
æææé ã¯ãMS08-067ã®è匱æ§ãæªçšããŠè¿ãããŸããã
çŸåšã®æ¥ä»ã2009幎5æ3æ¥ä»¥éã®å ŽåãConficker.Eã¯èªèº«ãåé€ããŸããããã³ã³ãã¥ãŒã¿ãŒã«ä»¥åã®ããŒãžã§ã³ãæ®ããŸããã
æåŸã«ããã®ããŒãžã§ã³ãããå©çã®åçåããå§ãŸãã2çš®é¡ã®ãã«ãŠã§ã¢ãããŠã³ããŒããããŸããã 1ã€ç®ã¯ããŠã¯ã©ã€ãã«ãããµãŒããŒããããŠã³ããŒãããåœã®Spyware Protect 2009ã¢ã³ããŠã€ã«ã¹ã§ãã éå§ãããšãã·ã¹ãã ã§æ€åºããããŠã€ã«ã¹ã«é¢ããã¡ãã»ãŒãžãå®æçã«è¡šç€ºããæ²»çã®å¯èœæ§ãããææã®ãã«ããŒãžã§ã³ã賌å
¥ããããšãç³ãåºãŸãã 2çªç®ã¯ã2009幎1æã«çºèŠãããKaspersky Labã®åé¡ã«ãããšIksmaãšããŠãç¥ãããWaledacããã€ã®æšéŠ¬ã§ãã Waledacã®äž»ãªæ©èœã¯ãå人æ
å ±ã®çé£ãšã¹ãã ã§ãã 2010幎2æãããŒãžãã¢å·é£éŠè£å€æã¯Microsoftã«èšŽèšãèªããWaledacãããããã管çã·ã¹ãã ã«é¢é£ãã277ãã¡ã€ã³ãäžæåæ¢ããããšãèš±å¯ããŸããã ãããã®ãã¡ã€ã³ã¯ãã¹ãŠãã¢ã¡ãªã«ã®äŒç€Ÿã§ããVeriSignãéå¶ãã.comãŸãŒã³ã«ç»é²ãããŠããŸããã
ããšãã
Confickeråæã¯ãéåžžã«ççŸããææ
ãåŒã³èµ·ãããŸãã äžæ¹ã§-éåžžã«é«ãã¬ãã«ã®æèã äžæ¹ãæçµçã«åºãŸã£ãŠããããã€ããŒããã¯ãæ»æè
ãæ¯æãã·ã¹ãã ã®ã¢ã«ãŠã³ããçããªã©ãæšçã®ã³ã³ãã¥ãŒã¿ãŒã«ä»»æã®æ°ã®ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ããéåžžã«å€§ããªæ©äŒãæã£ãŠãããšããäºå®ã«ã¯ãŸã£ããé©åããŸããã ã€ãŸã-ã¹ãºã¡ã®éããã éçºè
ã¯äž»ã«ç 究ç®æšãè¿œæ±ããããã§ãã ãŠã¯ã©ã€ãããã®ãã«ãŠã§ã¢ã®çºç¥¥ã®å°ã§ãããã©ããã¯ãŸã æããã§ã¯ãããŸããã äžéšã®ç 究è
ã¯ãMS08-067è匱æ§ã®æå¹ãªãšã¯ã¹ããã€ããäžåœã§æåã«ç»å Žãããã®ã³ãŒãã¯Confickerã§ã»ãŒå®å
šã«åçŸãããŠãããšææããŠããŸãã ãããã ã®ã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£äŒç€ŸBKISã¯ãConfickerãäžåœã§äœæããããšäž»åŒµããŠããŸãã BKISã®å°é家ã¯ãConfickerã¯ãŒã ã¯ã2001幎ã®æµè¡ã®ç¯äººã§ããNimdaãšå
±éããã³ãŒããåæããåŸãäžåœããæ¥ããšçµè«ä»ããŸããã Nimdaã¯äžåœã§éçºããããšèããããŠããŸããã³ãŒãããã®åœã®å
åãçºèŠããããã§ãã å
¬åŒã«ã¯ããããã®ããŒã¿ã¯ç¢ºèªãããŠããŸããã
åç
§ïŒ
ã·ãã³ããã¯ã®åæã¬ããŒããThe Downadup Codexã ããšãã£ã·ã§ã³2.0ïŒengãpdfïŒã
ããŒãžã§ã³AãBãB ++ã®æ©èœã®åæ©SRI Internationalãã© Confickerã®ããžãã¯ãšã©ã³ãããŒãã€ã³ãã®åæ ïŒengãhtmïŒã
SRI International Conficker C Analysis ïŒengãhtmïŒã®ããŒãžã§ã³CïŒDïŒã®ããã©ãŒãã³ã¹åæã
SRI International Conficker C P2PãªããŒã¹ãšã³ãžãã¢ãªã³ã°ã¬ããŒã ïŒengãhtmïŒã®ãã¢ããŒãã¢ã¡ã«ããºã ã®èª¬æã