åæ
ã«ã¹ãã«ã¹ããŒã¢ã³ããŠã€ã«ã¹ã¯ãä»æ¥æãæè¡çã«é«åºŠãªã¢ã³ããŠã€ã«ã¹ã®1ã€ã§ãã çããŠããŠæ»æãè©Šã¿ãŠããå Žåã§ããããã€ãã®ã¿ã€ãã®ã«ãŒãããããšæŠãããšããã§ããŸãã
Proactive Defense ModuleããããŸããããã¯ãçè«çã«ã¯ãããã°ã©ã ã®åäœãåæããäžæ£ãªã¢ã¯ã·ã§ã³ãé²æ¢ããããšã«ãããæªç¥ã®è åšããã³ã³ãã¥ãŒã¿ãŒãä¿è·ã§ããéšåçãªHIPSå®è£ ã§ãã
ããã¯ãã¹ãŠçè«ãšåºåã®ã¹ããŒã¬ã³ã§ãã çŸå®ã«ã¯ããŸã£ããç°ãªãç¶æ³ããããŸãã ã¢ã³ããŠã€ã«ã¹ã«ãã£ãŠãŸã£ããæ€åºãããªãã«ãŒãããããå€ããããæ»æè ããã©ã€ããŒãããŒãã§ããããã«ããã¢ã¯ãã£ããªé²åŸ¡ãæå¶ããããšãã§ãããã®åŸããã¢ã¯ãã£ããªé²åŸ¡ã¯ãŸã£ãã圹ã«ç«ããªããªããŸãã
ãã®èšäºã¯ããšã©ãŒãšè匱æ§ã®æŠèŠã ãã§ã¯ãããŸãã-åããŒãã®æåŸã«ããŠã€ã«ã¹å¯Ÿçéçºè ã«æšå¥šäºé ã瀺ããŸãããããã®ãšã©ãŒãèªåã§åŠçããããšã¯ã§ããªãããã§ãã ãããŠãæ¯æè ã®ããã«ãããã«äºçŽããããŸãïŒãã¡ããã以äžã«æžãããŠãããã®ã¯ãã¹ãŠé倧ãªè匱æ§ã§ã¯ãããŸãããããããããã=ïŒãªã©ãäžè¬çã«ãå¿ã«ããŸãåããããªãã§ãã ããã
ãã®èšäºã§èª¬æããã«ã¹ãã«ã¹ããŒã®ããŒãžã§ã³ã¯7.0ãæåŸã®ãããªãã¯ãã«ãã¯125ã補åã¿ã€ãã¯ã€ã³ã¿ãŒãããã»ãã¥ãªãã£ã§ãã
ã«ã¹ãã«ã¹ããŒãšã·ã¹ãã ãµãŒãã¹èšè¿°åããŒãã«
ãŠã€ã«ã¹å¯Ÿçã®ãã®éšåã¯ãæãè匱ãªãã®ãšããŠé·ãéç¥ãããŠããŸãã å€ãã®åºæ¬çãªãšã©ãŒãå«ãŸããŠããããã§ãã ãããã®ãšã©ãŒã¯ãäžååãªããã¢ã¯ãã£ããªé²åŸ¡ã®ãã1ã€ã®äŸã§ãã
Windows XPã§ã¯ãKaspersky Anti-Virusã¯SSDTããŒãã«ã«ãµãŒãã¹ãè¿œå ããŸãã Windows 2003ã®ã¿ã«ååšããå€ãã®ãµãŒãã¹ããããã®çªå·ã¯284ã296ã§ããklif.syså ã®ã¢ãã¬ã¹ãæã€çŽ13ã®äžæãªãšã³ããªã
ããã«ãããŸãïŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BD80ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BD90ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BDA0ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BDC0ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BDE0ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BE10ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BE20ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BE40ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BE50ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BF10ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809BFE0ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809C020ããã¯ãã³ãã©ãŒ
ntkrnlpa.exe-> UNKNOWN_SSDT_ENTRYã[CïŒ\ WINDOWS \ system32 \ drivers \ klif.sys]ã«ãã0xF809C060ããã¯ãã³ãã©ãŒ
ããã¯äœã§ãã å®å šã«ç解äžèœã§ãã ãã ããKAVéçºè ã¯ãWindows XPããã³2003ã§ã®SSDTããŒãã«ã®ãšã³ããªæ°ãç°ãªãåé¡ã解決ããããã«ããããè¿œå ããŠããããã§ããããã3çªç®ã®è³ªåã§ããçç±ã
ãããŠä»ã泚æïŒãããã®ãšã³ããªã®ããããããããã³ã°ãããå¯èœæ§ãããããã®åŸã æå°éã®ç¹æš©ãæã€ã²ã¹ãã¢ã«ãŠã³ãã®äžããã§ããBSODã§ã·ã¹ãã ã¯ã©ãã·ã¥ãçºçããŸãã ç§ãã¡ã¯å°ããªããã°ã©ã ãæžããŸããã SSDTã®ãããã®äžå¯è§£ãªãšã³ããªã«å¯ŸããŠãäžæ£ãªãã©ã¡ãŒã¿ãŒã䜿çšããŠäžæ£ãªã·ã¹ãã ã³ãŒã«ãçæããŸãã ã³ãŒãã¯éåžžã«ã·ã³ãã«ã§ãããå¹æçã§ãã Windowsèªäœããã®ãããªç¶æ³ãæ£ããåŠçãããããçŽç²ãªWindowsã§å®è¡ããŠãäœãèµ·ãããŸããã
var
Services: array[0..12] of ULONG;
ThreadTerminated: boolean = false;
ExecThread: THANDLE;
function MakeSysCall(SysCallNumber: integer; const Stack: PDWORD): DWORD; stdcall;
asm
mov eax, SysCallNumber
mov edx, Stack
int 2eh
mov Result,eax
end;
function exec(p1: pointer): DWORD; stdcall;
var
i: integer;
p2: DWORD;
p3: DWORD;
begin
randomize();
u := 0;
for i := 0 to 12 do Services[i] := 284 + i;
while not ThreadTerminated do
begin
p2 := random($FFFFFFFF);
p3 := Services[random(12)];
MakeSysCall(p3, @p2);
Sleep(100);
end;
CloseHandle(ExecThread);
ExecThread := 0;
result := 0;
end;
var
p2: DWORD;
begin
ThreadTerminated := false;
ExecThread := CreateThread(nil, 0, @exec, nil, 0, p2);
end;
å®è¡çµæïŒã«ã¹ãã«ã¹ããŒã€ã³ã¿ãŒãããã»ãã¥ãªãã£v7.0 125ãã«ã
PAGE_FAULT_IN_NONPAGED_AREAïŒ50ïŒ
ç¡å¹ãªã·ã¹ãã ã¡ã¢ãªãåç §ãããŸããã ããã¯try-exceptã§ã¯ä¿è·ã§ããŸãããã
ãããŒãã§ä¿è·ããå¿ èŠããããŸãã éåžžãã¢ãã¬ã¹ã¯åçŽã«æªããããŸãã¯
解æŸãããã¡ã¢ãªãæããŠããŸãã
åŒæ°ïŒ
Arg1ïŒe0ae15f9ãã¡ã¢ãªåç §ã
Arg2ïŒ00000000ãå€0 =èªã¿åãæäœã1 =æžã蟌ã¿æäœã
Arg3ïŒf8087e8cããŒã以å€ã®å Žåãäžè¯ã¡ã¢ãªãåç §ããåœä»€ã¢ãã¬ã¹
äœæã
Arg4ïŒ00000000ãïŒäºçŽæžã¿ïŒ
ãã¹ãŠã®BSODããã¹ã...
ããããããã ãã§ã¯ãããŸããïŒ
SSDTã®æ¢åã®è匱æ§ã®å ±åã«ãããããããã«ã¹ãã«ã¹ããŒã®éçºè ã¯ãŸã ããããä¿®æ£ããŠããŸããïŒ
NTCALLãšåŒã°ããåçŽãªããã°ã©ã ã§ããã蚌æã§ããŸãã èµ·ååŸãäžæ£ãªã·ã¹ãã ã³ãŒã«ã®çæãéå§ããŸãã
NtCreateSection-ç¡å¹ãªãã©ã¡ãŒã¿ãŒã§ãã®é¢æ°ãåŒã³åºããšãklif.sysã§BSODãçºçããŸãã
ãããBSODã§ãã
KERNEL_MODE_EXCEPTION_NOT_HANDLED_MïŒ1000008eïŒ
ããã¯éåžžã«äžè¬çãªãã°ãã§ãã¯ã§ãã éåžžãäŸå€ã¢ãã¬ã¹ã¯ç¹å®ããŸã
åé¡ã®åå ãšãªã£ããã©ã€ããŒ/æ©èœã åžžã«ãã®ã¢ãã¬ã¹ã«æ³šæããŠãã ãã
ãã®ã¢ãã¬ã¹ãå«ããã©ã€ããŒ/ã€ã¡ãŒãžã®ãªã³ã¯æ¥ä»ãåæ§ã§ãã
äžè¬çãªåé¡ã«ã¯ãäŸå€ã³ãŒã0x80000003ããããŸãã ããã¯ããŒããæå³ããŸã
ã³ãŒãåããããã¬ãŒã¯ãã€ã³ããŸãã¯ã¢ãµãŒã·ã§ã³ããããããŸãããããã®ã·ã¹ãã ã¯èµ·åããŸãã
/ NODEBUGã éçºè ãæã€ã¹ãã§ã¯ãªãã®ã§ãããã¯èµ·ããã¯ãããããŸãã
å°å£²ã³ãŒãã«ãã¬ãŒã¯ãã€ã³ããããŒãã³ãŒãã£ã³ã°ããŸãããã...
ãã®å Žåã¯ããããã¬ãŒãæ¥ç¶ãããŠããããšã確èªãã
ã·ã¹ãã ãèµ·å/ãããã°ãããŸãã ããã«ããããã®ãã¬ãŒã¯ãã€ã³ãããªãã§ããããããããŸãã
èµ·ãã£ãŠããã
åŒæ°ïŒ
Arg1ïŒc0000005ãåŠçãããªãã£ãäŸå€ã³ãŒã
Arg2ïŒ805883eaãäŸå€ãçºçããã¢ãã¬ã¹
Arg3ïŒf669a95cããã©ãããã¬ãŒã
Arg4ïŒ00000000
ãããã°ã®è©³çŽ°ïŒ
-åæïŒãµã€ãºãäžæãªã«ãŒãã«ã æ¢ç¥ã®ãµã€ãºã®ã·ã³ãã«ã匷å¶çã«ãªããŒãããŸãã
åæïŒåŒ·å¶åèªã¿èŸŒã¿ã³ãã³ãïŒ.reload / f ntoskrnl.exe = FFFFFFFF804D7000,214600,41108004
*****ã«ãŒãã«ã·ã³ãã«ãééã£ãŠããŸãã åæãè¡ãã«ã¯ã·ã³ãã«ãä¿®æ£ããŠãã ããã
MODULE_NAMEïŒklif
ãã¹ãŠã®BSODããã¹ã...
ç§ã¯äœãšèšãããšãã§ããŸããïŒ.. SSDTã§ã®å€æ ããããSSDTã¬ã³ãŒãã®éåžžã®ãã³ãã©ãŒãæžãæãæ¥ãŸããã è¯ãããŠã ãªã¬ã°ã»ã¶ã€ããšãã«SSDTã§ããã¯ãæ£ããèšå®ããæ¹æ³ãèããŠãã ãã;ïŒ
ã«ã¹ãã«ã¹ããŒãšã·ã£ããŠSSDTïŒã·ã£ããŠSSDTïŒ
ã·ã£ããŠSSDTã¯ããŠãŒã¶ãŒã°ã©ãã£ãã¯ã€ã³ã¿ãŒãã§ã€ã¹ïŒGDIïŒã®è¡šç€ºã«é¢é£ããã·ã¹ãã æ©èœã®ã¢ãã¬ã¹ãå«ãwin32k.sysã®ç¹å¥ãªããŒãã«ã§ãã ã«ã¹ãã«ã¹ããŒã¯ãããŒãã¬ãŒãé²ãããã®ãµãŒãã¹ãèªå·±é²è¡ã®ããã«ãããã«ããã¯ãã€ã³ã¹ããŒã«ããŸãã
ãŸããããã¯ã®èšå®ãäžååã§ãã
NtUserSendInputã®ãã©ã¡ãŒã¿ãŒãæ£ãããªãã...->ãããæ°ããBSODãããã¯BSODãžã§ãã¬ãŒã¿ãŒãæãåºãããŸãããïŒ =ïŒ
PAGE_FAULT_IN_NONPAGED_AREAïŒ50ïŒ
ç¡å¹ãªã·ã¹ãã ã¡ã¢ãªãåç §ãããŸããã ããã¯try-exceptã§ã¯ä¿è·ã§ããŸãããã
ãããŒãã§ä¿è·ããå¿ èŠããããŸãã éåžžãã¢ãã¬ã¹ã¯åçŽã«æªããããŸãã¯
解æŸãããã¡ã¢ãªãæããŠããŸãã
åŒæ°ïŒ
Arg1ïŒe1f83004ãã¡ã¢ãªåç §ã
Arg2ïŒ00000000ãå€0 =èªã¿åãæäœã1 =æžã蟌ã¿æäœã
Arg3ïŒf9417eeeããŒã以å€ã®å Žåãäžè¯ã¡ã¢ãªãåç §ããåœä»€ã¢ãã¬ã¹
äœæã
Arg4ïŒ00000001ãïŒäºçŽæžã¿ïŒ
ãããã°ã®è©³çŽ°ïŒ
-åæïŒãµã€ãºãäžæãªã«ãŒãã«ã æ¢ç¥ã®ãµã€ãºã®ã·ã³ãã«ã匷å¶çã«ãªããŒãããŸãã
åæïŒåŒ·å¶åèªã¿èŸŒã¿ã³ãã³ãïŒ.reload / f ntoskrnl.exe = FFFFFFFF804D7000,214600,41108004
*****ã«ãŒãã«ã·ã³ãã«ãééã£ãŠããŸãã åæãè¡ãã«ã¯ã·ã³ãã«ãä¿®æ£ããŠãã ããã
MODULE_NAMEïŒklif
ãã¹ãŠã®BSODããã¹ã...
ãã®éšåã®æšå¥šäºé ã¯ç°¡åã§ã-ãããã¬ãŒã®äžã§ãã©ã€ããŒãå®è¡ããŸãã
次ã®ã³ãŒã
var
p1ïŒPChar;
å§ãã
p1ïŒ= PCharïŒ$ ffffffffïŒ;
LoadLibraryAïŒp1ïŒ;
çµãã;
ã¯ã¢ã¯ã»ã¹éåã«ã€ãªãããããã¯æ£åžžã§ããé¢æ°ã«èª€ã£ããã©ã¡ãŒã¿ãŒã䜿çšããããã§ãããæ£åžžã§ã¯ãªãã®ã¯ã¢ãã¬ã¹-0xF80B3306ã§ã¢ã¯ã»ã¹éåãçºçããå Žæã§ãã
ããã¯åè«ã§ã¯ãããŸãã-0xF80B3306ã ã³ã¢ããã»ã¹ã§ïŒ ãããŠãããæ£ç¢ºã«ã¯-klif.sysã§ã
äœãèµ·ãããèŠãŠã¿ãŸãããã
ã·ã¹ãã å ã®ããã»ã¹ããšã«IATïŒ 1ã2 ïŒã®åŒ·åãªä¿®æ£ãèŠã€ãããŸããã explorer.exeã§äœãèµ·ããããèŠã
[420] explorer.exe-> kernel32.dll-> LoadLibraryExAãã¿ã€ãïŒ ã¢ãã¬ã¹ 0x010010A8ã®IATå€æŽ -> [kernel32.dll]ã«ãã7C882FB0ããã¯ãã³ãã©ãŒ
[420] explorer.exe-> kernel32.dll-> LoadLibraryExWãã¿ã€ãïŒ ã¢ãã¬ã¹ 0x010010F8ã®IATå€æŽ -> [kernel32.dll]ã«ãã7C882FD8ããã¯ãã³ãã©ãŒ
[420] explorer.exe-> kernel32.dll-> LoadLibraryAãã¿ã€ãïŒ ã¢ãã¬ã¹ 0x01001150ã®IATå€æŽ -> [kernel32.dll]ã«ãã7C882F9Cããã¯ãã³ãã©ãŒ
[420] explorer.exe-> kernel32.dll-> LoadLibraryWãã¿ã€ãïŒ[AT]ã®ã¢ãã¬ã¹0x010011D0ã§ã®å€æŽ-> [kernel32.dll]ã«ãã7C882FC4ããã¯ãã³ãã©ãŒ
[420] explorer.exe-> kernel32.dll-> GetProcAddressãã¿ã€ãïŒã¢ãã¬ã¹0x010011E4ã®IATå€æŽ-> [kernel32.dll]ã«ãã7C882FECããã¯ãã³ãã©ãŒ
å¥åŠã§ããã LoadLibraryAã®åŒã³åºãã远跡ããŸãããã
KERNEL32.LoadLibraryAïŒ
ebpãããã·ã¥
mov ebpãesp
ãã
ãããebp
jmp + $ 7b830b4a //-klif.sysãžã®ãªãã€ã¬ã¯ã
ãã
ãã
ãã
ãã
ãã
ãã
ãã
ãã
ãã
ãã
ããã¯ãKaspersky Anti-Virusã«ãã£ãŠIATããªãã€ã¬ã¯ããããåŸã®kernel32.dllå ã®LoadLibraryAã®å€èŠ³ã§ãã ããã¯åé¯ã§ã¯ãããŸãããïŒ
ãã®ã¢ã³ããŠã€ã«ã¹ãã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããšãã«ã¹ãã«ã¹ããŒã¢ã³ããŠã€ã«ã¹ã®ãããã§äœæãããè¿œå ã®è匱æ§ãšããã¯ãã¢ãèŠã€ããããã«ïŒãªããšç®èãªããšã§ãããïŒïŒ ç¬ãããããŠãã以äžã
ãã®éšåã§ã¯ãKasperskyéçºè ã補åããåé¯ãåé€ããããšããå§ãããŸãã 第äžã«ãã«ãŒãã«ããã»ã¹ãšéä¿¡ããããã®ããåªãããããç°¡åãªæ¹æ³ãããã第äºã«ãããã¯åãªãåé¯ã§ãã
ã«ã¹ãã«ã¹ããŒã¢ã³ããŠã€ã«ã¹ãšèªå·±é²è¡
ã»ãšãã©ã®äººãç¥ã£ãŠããããã«ãKaspersky Anti-Virusã¯æ»æããç©æ¥µçã«ä¿è·ããŸãã ãã®ããã»ã¹ã¯ãäžæ£ã¢ã¯ã»ã¹ãæªæã®ããããã°ã©ã ã«ããç Žå£ããä¿è·ãããŠããŸãã ããããåé¡ã¯ãã©ãã ãä¿è·ãããŠããã®ããšããããšã§ãã
åçïŒæªãã
ã«ã¹ãã«ã¹ããŒã¯ãSSDTã«ããã€ãã®ããã¯ïŒNtOpenProcessãNtOpenThreadãNtTerminateProcessãªã©ïŒãšShadow SSDTã«ããã€ãã®ããã¯ïŒNtUserFindWindowExãNtUserBuildHwndListãªã©ïŒãã€ã³ã¹ããŒã«ããŠãæ»æããããã«ä¿è·ããŸãã
æçµçã«ããšã©ãŒãçºçãããšãåèµ·åèšå®ã䜿çšããŠãµãŒãã¹ãšããŠèªèº«ãã€ã³ã¹ããŒã«ããŸãã ãµãŒãã¹èšå®ã¯ãSSDTã®ããã€ãã®ããã¯ã«ãã£ãŠã¬ãžã¹ããªã§ä¿è·ãããŠããŸãã ããã§ã¯ããã®ãŠã€ã«ã¹å¯Ÿçãã©ã®ããã«æ®ºãããšãã§ããŸããïŒ ãããŠã圌ã殺ãå¿ èŠããããŸããïŒ avp.exeã®èŠèŠéšåã匷å¶çµäºãããšããµãŒãã¹ã«ãã£ãŠåèµ·åãããŸãã ãµãŒãã¹ã匷å¶çµäºãããšããµãŒãã¹ã³ã³ãããŒã«ãããŒãžã£ãŒïŒSCMïŒã«ãã£ãŠèµ·åãããŸãã ããã§ã¯ãã©ãããŠãã®ã¢ã³ããŠã€ã«ã¹ãç Žå£ã§ããŸããïŒãã¡ãããæè²ç®çã§ïŒïŒ 質åã¯è¯ãã§ãã
çãã¯ç°¡åã§ãããã©ã€ããŒãããŠã³ããŒãããŠãã ããããã®åŸãKAVã®å¯Ÿè±¡ãŸãŒã³ããå€ããŸãã ããããæåã«ããã®æ©äŒãåŸãããã«ãããäžæããå¿ èŠããããŸãããïŒ ããã§ããªãã ã«ã¹ãã«ã¹ããŒããã¢ã¯ãã£ããã£ãã§ã³ã¹7.0ãããããã«åå¿ããããšãªãããã©ã€ããŒãéãã«ããŠã³ããŒãã§ããå°ãªããšã3ã€ã®æ¹æ³ããããŸãã ãããŠãç§ã¯ãŸã æ¹æ³ããããšç¢ºä¿¡ããŠããŸãã ãã®å ŽåãKaspersky Anti-Virusããã»ã¹ã®ãã¹ãŠã®ã¹ã¬ãããäžæåæ¢ããŸãã ãã äžæåæ¢ãããã以äžã¯äœããããŸãã-ããã§ååã§ãã
SSDTã®ææè ã¯PDMã§ãããããKasperskyããã»ã¹ã«çŽæ¥ã¢ã¯ã»ã¹ããããšã¯ã§ããŸããã ããã§ã¯ã csrss.exeãšåŒã°ããããæ°ã«å ¥ããã®ããã¯ãã¢ããã»ã¹ã䜿çšããŸãã
ãã®äŸã§ã¯ãKAVã¢ããªã±ãŒã·ã§ã³ã®ååãavp.exeã§ãããcsrss.exeã1ã€ã®ã€ã³ã¹ã¿ã³ã¹ã«ååšãããšä»®å®ããŸãïŒLOLãã¯ããring3ã§å®è¡ãããŠãããã«ãŠã§ã¢ãcsrss.exeã«åœè£ ããŠããå Žåããã®ã³ãŒãã«ã¯ç¹å®ã®åé¡ããããŸãïŒ ïŒ
...
pBuffer.dwSizeïŒ= sizeofïŒPROCESSENTRY32WïŒ;
SnapShotHandleïŒ= CreateToolHelp32SnapShotïŒTH32CS_SNAPPROCESSã0ïŒ;
...
ifïŒZwOpenProcessïŒ@phãPROCESS_ALL_ACCESSã@attrã@ cid1ïŒ<> STATUS_SUCCESSïŒãã®åŸçµäºããŸã;
...
ZwAllocateVirtualMemoryïŒGetCurrentProcessïŒïŒã buf ã0ã@bytesIOãMEM_COMMITãPAGE_READWRITEïŒ;
ZwQuerySystemInformationïŒSystemHandleInformationãbufã4194304ã@ bytesIOïŒ;
ãã¹ãŠã®ããã°ã©ã ããã¹ã...
ãã®åŸãäž¡æ¹ã®å®è¡å¯èœãªKasperskyã¢ãžã¥ãŒã«ãäžæããããã©ã€ããŒãããŒãããŠéãã«äœæ¥ãè¡ãããšãã§ããŸã=ïŒ
ããã©ã«ãèšå®ã§KIS v7.0ãã«ã125ã§ãã¹ãæžã¿ã
Windws XP SP2ã管çè æš©éã
ãŠãŒã¶ãŒã¢ã«ãŠã³ããHANDLE_TABLEã«ç§»åãããã®ããã»ã¹ã®ãã³ãã©ãŒã®ã¢ã¯ã»ã¹æš©ãå€æŽããããšããå§ãããŸãã ããã«ãNtDuplicateObjectã®ããã¯ãæ¹åãããšããæ¥ãŸããã
ãšãããŒã°
ããªãã¯ããããããªããã®ãããªæãããªãšã©ãŒãªã®ããæã人æ°ã®ããã¢ã³ããŠã€ã«ã¹ã®1ã€ã«æ¬åœã«ããã¯ãã¢ãååšããã®ããšèªåããŠããŸããïŒ ã¯ããKaspersky Labã®äžã§èª°ããè¯ãä»äºãããã¹ãã ããã§ãã
å°ãåã«ãç§ãã¡ã¯KAVãšã©ãŒã®å¥ã®ã¬ãã¥ãŒãå ¬éããŸããã åå¿ãäºæ³ãããŸããã 圌ãã¯ãå¿é ããªãã§ãã ããããããã¯é倧ãªãšã©ãŒã§ã¯ãããŸãããã ãããã¯ããããããã²ã¹ãã¢ã«ãŠã³ãã®äžããã®æ»ã®ãã«ãŒã¹ã¯ãªãŒã³ã¯ãäŒç€Ÿã«ãšã£ãŠããã»ã©å€§ããªåé¡ã§ã¯ãããŸããã ãæ¬åœã«ã äžè¬çã«BSODã®ããã®ãã§ïŒ ã§ãããããªã©ãã¯ã¹ããŠãã ãã ":)ããããäœããå€ãã£ãŠããŸã-圌ãã¯å ¬éãããããã€ãã®è匱æ§ãéããã®ã§ãç§ãã¡ã«å°ãæè¬ããå¿ èŠããããŸãã 代ããã«ã$ @ïŒ $ïŒïŒã®æãååŸããŸãïŒ ïŒãã¡ããéå ¬åŒã«ïŒããªãã®äœæã«ã ãŸããç§ãã¡ã¯ãã®ãããªåå¿ãå¿é ããªãã®ã§ãèªåèªèº«ãæ°ã«ããªãã§ãã ããïŒçä¿¡è ïŒïŒã ç§ãã¡ã¯èªå·±å®£äŒãæãã§ããããã«ã¹ãã«ã¹ããŒããã®æããªBSODãèŠãããªãã
Kaspersky Labã®éçºè ã®çæ§ãã䜿ãã®ãŠã€ã«ã¹å¯Ÿçã¯éåžžã«åªããŠããŸããçãã¯ãããŸãããããããã®ãã°ãä¿®æ£ããæãæ¥ãã®ã§ã¯ãªãã§ããããã SSDT / IATããåé¯ãåé€ããŸãã ãã©ã€ããŒã®é倧ãªç¶æ³ãããæ éã«åŠçããŠãã ããã çå£ã§ã¯ãããŸããããäœãåé¡ãªã®ã§ããããïŒ klif.sysãèŠããšã 倧ããªãã°ã®ãããã©ã€ããŒã1ã€ãããããŸããã
ã¡ãªã¿ã«ããã®çŽ ââæŽãããèšäºã§ã以åã®klif.sysã®ã¬ãã¥ãŒã«å¯ŸããKaspersky Labããã®éå ¬åŒã®åçãèªãããšãã§ããŸããããã«ã¯ãããã€ãã®éŠ¬é¹¿ãã声æãç¡æå³ãªã³ã¡ã³ããå«ãŸããŠããŸãã ç°¡åã«èšããšããã®èšäºã®èè ã¯ãå€ã補åãšæ°ãã補åã®è匱æ§ã«é¢ããæ å ±ãå ¬éããŠãããšéšåçã«éé£ããŸããã
www.viruslist.ru/analysis?pubid=204007553
èšäºã¯ãã·ã¢èªã§ãããè±èªçãèŠã€ããã¯ãã§ãã
楜ããã§ãã ãã
VX倩åœãã
EP_X0FF / UGå
rootkit.com
smartovïŒåœŒããæåŸã«èªãèšäºããã®åŒçš
è¿å¹Žã以äžã®ç¶æ³ãéåžžã«éèŠã§ãã ãµã€ããŒç¯çœªè ïŒãŸãã¯çœãåžœåã®åŸãã«é ããŠãããç 究è ãïŒã®ç°å¢ã®èª°ãããçŸä»£ã®ä¿è·æ段ãè¿åããã³ãŒãã³ã³ã»ãããéçºããŠããŸããé²æ©ã®äžè©±ãããããã«èŠããããèªå·±PRã®ç®çã§ãããããæ€åºäžèœããšããŠå ¬éããŠããŸãã ç§ãã¡ã¯åŒ·èª¿ããŸãïŒãã¡ãããå®éã«ã¯ããã®ãããªæŠå¿µã¯åºæ¬çã«æ€åºäžå¯èœã§ã¯ãããŸããããä¿è·è£ 眮ã®æ¢ç¥ã®æ©èœã®1ãŸãã¯2段éãã€ãã¹ã®ã¬ãã«ã§ã¯æ€åºã§ããŸããã ä¿è·ã¡ã«ããºã ãããã£ãŠããå Žåããã®ãããª1ã¹ãããã®ãã€ãã¹ãäœæããã®ã¯éåžžã«ç°¡åã§ãã
ãã®ãããªå ¬éã«ããããã«ãŠã§ã¢ããŠã€ã«ã¹å¯Ÿçã®åäœåçã«è©³ãããªããŠãŒã¶ãŒã®äžå®ã®å²åãå¿é ããããã«ãªããŸãïŒããŠã€ã«ã¹å¯ŸçããŒã«ã¯ãã®æ°ããçš®é¡ã®è åšããä¿è·ããŸããïŒãïŒã ãã®ãããªç¶æ³ã§ã¯ãä¿è·è£ 眮ã®ã¡ãŒã«ãŒã¯ãä¿¡é Œæ§ãå埩ããããã«ãªãœãŒã¹ã®äžéšãæå ¥ããããšããã§ããŸããã説æãããæŠå¿µãåé¿ããããã®æè¡ãéçºããŸãã ãã®çµæãæš©éã埩å ãããŸããïŒä»ã®æ¹æ³ã¯ïŒïŒãã·ã¹ãã ããã«ãŠã§ã¢-ãŠã€ã«ã¹å¯Ÿç-ãŠãŒã¶ãŒãã¯å ã®ç¶æ ã«ãªããããã»ã¹ã¯ã«ãŒãã§çµäºããŸãã ãã®æ°ããå埩ã®ããããã¯ããŸããŸãæŽç·Žããããã«ãŠã§ã¢ãšãŸããŸãéãã»ãã¥ãªãã£ããŒã«ãçæããŸãã
KVNã®å ŽåïŒãçŽ æŽãããèšç»ïŒãã ãã®ãããªèåœèªäœãè匱æ§ãå ¬éããŠããããã貧匱ãªã¢ã³ããŠã€ã«ã¹ã¡ãŒã«ãŒã¯
psæãã€ã³ã¹ããŒã«ãããŠããKAV 7.0.0.125 ...