ã€ã³ãã
Zeusãããã¯ãããããæªæã®ãããœãããŠã§ã¢ã®æãæåãªä»£è¡šã®1ã€ã§ãã Zeusã®æŽå²ã¯2007幎ïŒãŸãã¯2006幎ïŒããã§ãã å€ãã®äººãããŒãŠã¹ã¯åãªãããã€ã®æšéŠ¬ã§ãããšèª€è§£ããŠããŸãããããã§ã¯ãããŸããã å®éãZeusã¯ããããã¯ã©ã€ã ãŠã§ã¢ã®äŸã§ããéæ³è¡çºãè¡ãããã«èšèšããããœãããŠã§ã¢ã§ãã ãã®å Žåãã¯ã©ã€ã ãŠã§ã¢Zeusã®äž»ãªç®çã¯ãéèååŒã®å®è¡ã«äœ¿çšãããè³æ Œæ å ±ãçãããšã§ãã ã¢ããªã¹ãã«ãããšã圌ã¯äžçã®éè¡è©æ¬ºäºä»¶ã®90ïŒ ãæ åœããŠããŸãã
ãã1ã€ã®èª€è§£ã¯ã1ã€ã®å·šå€§ãªZeusããããããããããšãã䞻匵ã§ãã å®éãZeusã¯éåžžã«å€æ°ïŒããããæ°çŸïŒã®ããŸããŸãªããããããã®åºç€ã§ããããããã¯ãã¹ãŠãµã€ããŒç¯çœªè ã®ç°ãªãã°ã«ãŒãã«ãã£ãŠå¶åŸ¡ãããŠããŸãã Zeusã®äœæè ã¯ãé¢å¿ã®ããé¢ä¿è ã«ããã販売ããã ãã§ããã§ã«ããã䜿çšããŠç¬èªã®ãããããããäœæããŠããŸãã ãããã£ãŠãZeusããããããã§ã¯ãªããZeusã§äœæãããããããããã«ã€ããŠè©±ãã®ã¯æ£ããããšã§ãã 2009幎2æãã¹ã€ã¹ã®ã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã§ããRoman Hussyã¯ãZeusããŒã ãµãŒããŒã«é¢ããæ å ±ã远跡ããZeusTracker Webãµã€ããäœæããŸããã
ãŒãŠã¹ãããŒãžã§ã³1
ZeuSéçºè ã¯ãSlavikãšMonstrãšããããã¯ããŒã ã§ç¥ãããŠããŸãã2010幎ãŸã§åœŒã®è£œåã販売ããã³ãµããŒãããã®ã¯åœŒã§ããã
æ§é çã«ãZeusã¯ããã€ãã®éšåã§æ§æãããŠããŸã-ãããã®äœæè ãšç®¡çããã«ã
ã¡ã€ã³ã®Zeusãããã¢ãžã¥ãŒã«ããã³ãã«ããŒã¯ãVisual Studioã®Cããã³éšåçã«C ++ã§èšè¿°ãããŠããŸãã Zeusãããã®æçµçãªå®è¡å¯èœã³ãŒãã¯ããã«ããŒã«ãã£ãŠäœæãããã¡ã€ã³ã¢ãžã¥ãŒã«èªäœãšæ§æãã¡ã€ã«ãå«ãŸããŠããŸããã æ§æãã¡ã€ã«ã«ã¯ãã³ã³ãããŒã«ã»ã³ã¿ãŒã®ã¢ãã¬ã¹ãã¹ã¯ãªãããžã®ãã¹ãããã³äœæ¥ã«å¿ èŠãªãã®ä»ã®ããŒã¿ãå«ãŸããŠããŸãã ãã«ããŒã«ã¯ãè³Œå ¥è ã®ã³ã³ãã¥ãŒã¿ãŒãžã®ããŒããŠã§ã¢ãã€ã³ãããããŸããã€ãŸããç¹å®ã®æ§æãããå Žåã«ã®ã¿èµ·åã§ããŸãã
ç 究è ã¯ãZeusãã¡ããªãŒãã«ãŒããããããšã¯ã¹ããã€ããã¯ããã¯ã䜿çšããŠã·ã¹ãã äžã®æš©éã匷åããããšã¯ãªããšææããŠããŸãã äž»ãªéç¹ã¯ãéããããŠãŒã¶ãŒæš©éã§äœæ¥ããå Žåãå«ããæäœã®å®å®æ§ã«çœ®ãããŸããã
ããŒãžã§ã³1.3.4.xã®äŸã«é¢ãã第1äžä»£ã®Zeusã®æ©èœã2010幎3æïŒ ãœãŒã¹ ïŒïŒ
- ãã©ãŠã¶ã«å ¥åãããè³æ Œæ å ±ã®çé£;
- Windows Protected Storageã«ä¿åãããŠããå人æ å ±ã®çé£ã
- ã¯ã©ã€ã¢ã³ã蚌ææžX.509ã®çé£ã
- FTPããã³POPè³æ Œæ å ±ã®çé£
- HTTPããã³Flash Cookieã®çé£ãšåé€ã
- åŸç¶ã®å人æ å ±çé£ïŒWebã€ã³ãžã§ã¯ã·ã§ã³ïŒã®ããã«èŠæ±ãããHTMLããŒãžã®å€æŽã
- ãŠãŒã¶ãŒãªã¯ãšã¹ããä»ã®ãµã€ãã«ãªãã€ã¬ã¯ãããŸãã
- ã¹ã¯ãªãŒã³ã·ã§ããã®äœæã
- ãã¡ã€ã«ãæ€çŽ¢ããŠãªã¢ãŒããµãŒããŒã«ã¢ããããŒãããŸãã
- ãã¹ããã¡ã€ã«ã®å€æŽã
- ãªã¢ãŒããµãŒããŒããã®ãã¡ã€ã«ã®ããŠã³ããŒããšãã®åŸã®èµ·åã
- ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããŒãã§ããªãããã®éèŠãªã¬ãžã¹ããªãã©ã³ãã®åé€ã
ããŒãžã§ã³1.4以éãFirefoxã«Web Injectsãå®è£ ããæ©èœãç»å ŽããŸããã Webã€ã³ãžã§ã¯ã-å®éã®ã·ã¹ãã ãã·ãã¥ã¬ãŒããããªã¢ãŒããã³ãã³ã°ã·ã¹ãã ã®è³æ Œæ å ±ã®å ¥åãã©ãŒã ã®è¡šç€ºãæäŸããHTMLããã³JavaScriptã³ãŒãã®ã»ããã ãã©ãŠã¶ãä»ããŠRBã·ã¹ãã ã®ãµã€ãã«ã¢ã¯ã»ã¹ããããšãããšãããã€ã®æšéŠ¬ã¯ãªã¯ãšã¹ããååããåœã®ãã©ãŒã ã衚瀺ããŸãã ãã®ããã«ããŠçãŸããè³æ Œæ å ±ã¯ãæ»æè ã®ã³ãã³ãã»ã³ã¿ãŒã«éä¿¡ãããŸãã ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®æ€åºãããå°é£ã«ããããã«ãZeusã¯ããªã¢ãŒãã£ãã¯æå·åãšãã¡ã€ã«ã®ãµã€ãºå€æŽã¡ã«ããºã ã䜿çšãå§ããŸããã åæã«ãææããåã·ã¹ãã ã®Zeusãã¡ã€ã«ã¯æ°ãããã©ã¡ãŒã¿ãŒã§æ°ãã«æå·åããããããç°ãªãã³ã³ãã¥ãŒã¿ãŒã§ã®åããã«ãã¯ãŸã£ããç°ãªã£ãŠèŠããŸããã
ããŒãžã§ã³Zeus 1.3.4.xã®ã³ã³ããŒãã³ãã®äŸ¡æ ŒïŒ
- ãã«ããŒãšç®¡çããã«-3000ãã«ãã4000ãã«ãŸã§ã
- Back Connectã¢ãžã¥ãŒã«ïŒããšãã°ãã©ã®ããŒãã§ãRDPçµç±ã§æ¥ç¶ã§ããŸãïŒ-1,500ãã«ã
- Firefoxè³æ Œæ å ±çé£ã¢ãžã¥ãŒã«ïŒãã©ãŒã ã°ã©ããŒïŒ-2000ãã«ã
- Jabberãä»ããçé£æ å ±ã®éç¥ããã³éä¿¡çšã¢ãžã¥ãŒã«-500ãã«ã
- ãã©ã€ããŒãïŒã«ã¹ã¿ã ã¡ã€ãïŒVNCïŒãªã¢ãŒãã³ã³ãããŒã«ãRDPã¢ããã°ïŒã¢ãžã¥ãŒã«-10,000ãã«ã
- Windows Vista / SevenãµããŒã-2000ãã«ã
Zeusãããã¯ããŸããŸãªæ¹æ³ã§é åžãããŸããã ããšãã°ã2009幎ã®ç§ã«ã¯ãç±³åœã®çšåãµãŒãã¹ã«ä»£ãã£ãŠéä¿¡ãããã¹ãã ã¡ãã»ãŒãžã§é ä¿¡ãããŸããã å¥ã®ã±ãŒã¹ã§ã¯ãæçŽã¯è±ã€ã³ãã«ãšã³ã¶H1N1ã«å¯Ÿããæ®éçãªã¯ã¯ãã³æ¥çš®ãè¡ããããšè¿°ã¹ãŸããã æçŽã®ãªã³ã¯ã¯ããµã€ããŒç¯çœªè ã«ãã£ãŠäœæãããåœã®ãµã€ãã«ã€ãªãããŸããã ãããã®ãµã€ãã¯ãç¹å®ã®æ瀺ãå«ããšæãããexe圢åŒã®å®è¡å¯èœãã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ããããšãææ¡ããŸããã å®éããã¡ã€ã«ã¯Zeusãããã§ããã ã¹ãããŒã¯ãCutwailããããããïŒPushdoããã³OficlaãšãåŒã°ããïŒã®ããã¯ãŒãã䜿çšããŠã¹ãã ãéä¿¡ããŸããã ãã®åŸãæŠè¡ãå€æŽããããšã¯ã¹ããã€ãããã¯ã«ã€ãªããiframeãŸãã¯jscriptãå«ããµã€ããžã®ãªã³ã¯ãã¬ã¿ãŒã§éä¿¡ãããããã«ãªããŸããã ããã«ããããŠãŒã¶ãŒã®æäœãªãã§ææããããšãå¯èœã«ãªããŸãã-ãã¡ããããã©ãŠã¶ãè匱æ§ã«ãããããå ŽåïŒé©åãªã»ãã¥ãªãã£ã¢ããããŒãããªãå ŽåïŒããªã³ã¯ããã©ãã ãã§ãZeusãèªåçã«ã€ã³ã¹ããŒã«ãããŸããã æçŽãæžãéçšã§ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®æ¹æ³ãåºã䜿ãããŸããã
äžéšã®Zeus管çããã«ã«ã¯ãFTPã¢ã«ãŠã³ããããªã³ã¶ãã©ã€ãã§ãã§ãã¯ããæ©èœããããŸãããçãŸããè³æ Œæ å ±ã®æ°ããéšåãéä¿¡ããããšããã«ãFTPã¢ã«ãŠã³ãã®ååšããã§ãã¯ããããã®ãããªã¢ã«ãŠã³ããããã«ãã§ãã¯ãããŸããã ãã§ãã¯ã®çµæãã¢ã¯ã»ã¹ãããããšãå€æããå Žåãå¥ã®ã¹ã¯ãªãããæ¡åŒµå.htmã.htmlããã³.phpã®ãã¡ã€ã«ããªã¢ãŒãFTPãµãŒããŒã§æ€çŽ¢ãïŒFTPãµãŒãã¹ã¯ãµã€ããžã®ã³ã³ãã³ãã®ã¢ããããŒãã«ãã䜿çšãããããïŒãiframeãŸãã¯jscriptããããã®ãã¡ã€ã«ã«æ¿å ¥ãããŸãããšã¯ã¹ããã€ãããã¯ã«ã€ãªãããŸãã ãããã£ãŠããµã€ãã¯èªåçã«ææããŸããã
2010幎4æãZeusã¯ãããããŒãå®è¡å¯èœãã¡ã€ã«ïŒ source ïŒã«å°å ¥ããããã®è¿œå æ©èœãåãåãã512ãã€ãã®åã蟌ã¿ã³ãŒãã次ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸããã
- URLãå éšã§èšå®ããããªã¢ãŒããã¡ã€ã«ãããŠã³ããŒãããŸãã
- ããŠã³ããŒããããã¡ã€ã«ãå®è¡ã®ããã«èµ·åããã
- ææããããã°ã©ã ã®å ã®ã³ãŒããå®è¡ããŸãã
ãã®æ©èœã¯ããã€ã©ã«æ©èœã«äŒŒãŠããŸãã ãã ãããŠã€ã«ã¹å¯Ÿçãææãã¡ã€ã«ãé§é€ããå ŽåããŠã€ã«ã¹ã¯èµ·åã§ããªããªããŸããã ãã®å ŽåããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãã¡ã€ã³ã®Zeusã¢ãžã¥ãŒã«ãåé€ãããããããŒã«è§Šããªãå¯èœæ§ããããŸãããããã«ãããããããæ°ããããŒãžã§ã³ã®Zeusã§ã³ã³ãã¥ãŒã¿ãŒã«å床ææããããšãã§ããŸãã
競åä»ç€Ÿ
2009幎12æé ãZeusã®ã©ã€ãã«SpyEyeãããã©ãã¯ããŒã±ãããã«ç»å ŽããŸãããæ©èœãšæ§æïŒãã«ããŒããã³ç®¡çããã«ïŒã¯Zeusãšéåžžã«äŒŒãŠããŸããããäŸ¡æ Œã¯äœããåºæ¬ã¢ãžã¥ãŒã«ã®å Žåã¯çŽ500ãã«ã§ããã ãã®åŸã競äºã¯2010幎2æã®SpyEyeããŒãžã§ã³1.0.7ã«ç»å Žããæ©èœãZeus Killerãã¯Zeusãåé€ããããã«èšèšãããŸããã ãã¹ãŠã®Zeusã³ããŒãã·ã£ããããŠã³ããããã«ãSpyEyeã¯ååä»ããã€ããä»ããŠã³ãã³ããéä¿¡ããåZeusã³ããŒã¯ãã®ããŒãºã«åãããŠéããŸãã SpyEyeã¯ãZeusãã³ããŒãæ€åºããŠåèµ·åãé²ãããã«äœ¿çšããç¹å®ã®ãã¥ãŒããã¯ã¹åã§Zeusãæ€åºããŸããã ããã«ãSpyEyeã¯Zeusããéä¿¡ãããã¬ããŒããååããå¯èœæ§ããããããäºéã®äœæ¥ãè¡ããŸããã ãã1ã€ã®ç®æ°ããã¯ãZeusã«å¯Ÿæããããã«äœæããããã©ãŠã¶ã«ãã«ãŠã§ã¢ãäŸµå ¥ããå¯èœæ§ããããã¯ããããšãç®çãšããTrusteerã®Rapportã»ãã¥ãªãã£ã·ã¹ãã ããã€ãã¹ããããã«èšèšãããã¢ãžã¥ãŒã«ã§ãã Zeusãã«ããŒã®ãããªSpyEyeãã«ããŒã«ã¯ãç¹å®ã®ããŒããŠã§ã¢æ§æãžã®ãã€ã³ãã«åºã¥ãã©ã€ã»ã³ã¹ã·ã¹ãã ãå«ãŸããŠããŸããã VMProtectãã³ãžä¿è·ã䜿çšããŠå®è£ ãããŸããã
ãã©ãŒã©ã ã®æ å ±ã«ãããšã2010幎10æã«Zeus Slavikã®äœæè ã¯ããœãŒã¹ã³ãŒãã競åä»ç€Ÿã§ããéçºè SpyEyeã«è»¢éãããããªãéçºãåæ¢ããŸããã ã³ãŒãã¯ãGribodemonãšããŠãç¥ãããHardermanãšããããã¯ããŒã ãæã€äººã«è»¢éãããŸããã Hardermanã«ãããšã圌ã¯ãœãŒã¹ã³ãŒããç¡æã§åãåãã以åã®Slavikã®ãã¹ãŠã®é¡§å®¢ã®äžè©±ãããŸãããåŸã«ãZeusãšSpyEyeã®ãœãŒã¹ã³ãŒãã®äœããã®çš®é¡ã®å䜵ãæ³å®ãããŸããã å®éã2011幎1æ以éããŠã€ã«ã¹å¯ŸçäŒæ¥ã®ç 究è ã¯SpyEyeã®æ°ãããã€ããªããããŒãžã§ã³ã®æ€åºãéå§ããããŒãžã§ã³1.3ããçªå·ä»ããéå§ãããŸããã
SpyEyeããŒãžã§ã³1.3.45ã2011幎8æã®ã³ã³ããŒãã³ãã®äŸ¡æ ŒïŒ
- ãã«ããŒãšç®¡çããã«-2000ãã«ã
- Firefoxãã©ãŠã¶çšã®Web Injectsã¢ãžã¥ãŒã«-2000ãã«ã
- Rapportä¿è·ãã€ãã¹ã¢ãžã¥ãŒã«-500ãã«;
- Socks5ãããã·ã¢ãžã¥ãŒã«-1000ãã«ã
- RDPãããã³ã«ã¢ã¯ã»ã¹ã¢ãžã¥ãŒã«-3000ãã«ã
- FTP Back Connectã¢ãžã¥ãŒã«-300ãã«ã
- Mozilla Firefoxãã©ãŠã¶ãŒèšŒææžçé£ã¢ãžã¥ãŒã«-300ãã«ã
- ã¯ã¬ãžããã«ãŒãã®è³æ Œæ å ±ã®çé£ã¢ãžã¥ãŒã«-200ãã«ã
- OperaïŒChromeïŒãã©ãŒã ã°ã©ããŒïŒã¯ã¬ãã³ã·ã£ã«çé£ã¢ãžã¥ãŒã«-1000ãã«ã
ãã®ããŒãžã§ã³ã®ãŠãŒã¶ãŒã¬ã€ãã¯ãXyliBoxå人ããã°ã§å ¥æã§ããŸã ã
ZeusãããŒãžã§ã³2.1
åæã«ãRSAã®ç 究è ã¯ãããžãã¹ããããããšã«ã€ããŠã®ã¹ã©ãŽã£ãã¯ã®èšèã«çåãæããããããã€ãã®äºå®ãçºèŠããŸããã 2010幎8æãã€ãŸãZeusã§ã®äœæ¥çµäºã®ãå ¬åŒãçºè¡šã®2ãæåã«ãããŒãžã§ã³2.1.0.10ã®Zeusãããã䜿çšããŠãããããããçºèŠãããŸããã 調æ»ã¯ã瀺ãããããŒãžã§ã³ã®ãããããéåžå Žãã§è²©å£²ãããªãã£ãããšã瀺ããŸããã ãã®ã¿ã€ãã®ãããã®ãã®åŸã®çºèŠã«ãããRSAã®å°é家ã¯ãã®å€æŽã1人ïŒãŸãã¯ã°ã«ãŒãïŒã®ã¿ãææããŠããããšã確èªããŸããã Zeusã«åºã¥ããç¬èªã®æ§æãã¡ã€ã«ã䜿çšããŸããïŒã
Zeus 2.1.0.10ã®äž»èŠãªæ©èœã¯ã管çãµãŒããŒãšã®éä¿¡ã¹ããŒã ã®å€æŽã§ããã ãµãŒããŒã®ã¢ãã¬ã¹ã¯ãæ§æãã¡ã€ã«ã«ããŒãã³ãŒãã£ã³ã°ãããŠããŸããã ã¢ãã¬ã¹ãªã¹ãã¯ãDGAïŒãã¡ã€ã³çæã¢ã«ãŽãªãºã ïŒã䜿çšããŠçæãããŸããã 以åã¯ãBobaxãKrakenãSinowalïŒå¥åTorpigïŒãSrizbiãConfickerãªã©ã®ãã«ãŠã§ã¢ãµã³ãã«ã§åæ§ã®ææ³ãç¹°ãè¿ã䜿çšãããŠããŸããã Zeusã¯ãçæãããã¢ãã¬ã¹ã§ã³ãã³ããµãŒããŒãæ¢ããŠããŸããã å¶åŸ¡ã®ååããä¿è·ããããã«ãããŠã³ããŒãäžã®ãã¡ã€ã«ã®ããžã¿ã«çœ²åãæŽæ°äžã«æ€èšŒãããŸããïŒWindows Crypto APIã䜿çšïŒã ãããè¡ãããã«ãZeusã³ãŒãã«ã¯1024ãããé·ã®RSAå ¬éããŒãå«ãŸããŠããŸããã
2011幎ã«RSAã®ç 究è ã¯ãZeusãµãŒããŒããŒãžã§ã³2.1.0.10ã®ããããã«ã¢ã¯ã»ã¹ã§ããŸããã 2010幎8æãã2011幎8æã®éã«ã210,000å°ãè¶ ããã³ã³ãã¥ãŒã¿ãŒããã®ãµãŒããŒã«æ¥ç¶ããææããã³ã³ãã¥ãŒã¿ãŒããçŽ200ã®ã¬ãã€ãã®ããŒã¿ãåä¿¡ããããšãããããŸããã ææããã³ã³ãã¥ãŒã¿ãŒã®çŽ42ïŒ ã¯ç±³åœã«ãããŸããã ãŸãããã®ã³ãã³ããµãŒããŒãžã®ã¢ã¯ã»ã¹ãèš±å¯ããããã®ãã°ã€ã³ã®1ã€ããSlavikãã§ããããšãããããŸããã ãããã£ãŠãRSAã®å°é家ã¯ãSlavikãå®éã«ç¬èªã®ããããããïŒãããã1ã€ã§ã¯ãªãïŒã®äœæã«çæããããšã瀺åããŠããŸãã
ããã«ç¶ããŸã ã