ãã®æçš¿ã§ã¯ãäžçäžã®ããŸããŸãªçµç¹ããæ©å¯æ
å ±ãçãããã«äœ¿çšãããæšçåæ»æ調æ»ã玹ä»ããŸãã ãã®èª¿æ»ã®éçšã§ããã®æ»æã®çè·¡ãã€ã³ãã«åããããããã¹ã¿ã³ãæã圱é¿ãåããåœã§ããããšãçºèŠãããŸããã ããã«ãæ»æè
ã®è¡åã¯å°ãªããšãéå»2幎éã¯æŽ»çºã§ããã ãã®æ»æã®ç¹åŸŽã¯ãæªæã®ããå®è¡å¯èœãã¡ã€ã«ã«çœ²åããããã«äœ¿çšãããæå¹ãªããžã¿ã«èšŒææžã®äœ¿çšã§ãã ãŸãããµã€ããŒç¯çœªè
ãæªæã®ããã³ãŒããã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããããã«äœ¿çšãããšã¯ã¹ããã€ããçºèŠããŸããã
ãã®ãã£ã³ããŒã³ã®äžç°ãšããŠãæå¹ãªããžã¿ã«èšŒææžã䜿çšãããæªæã®ããå®è¡å¯èœãã¡ã€ã«ã眲åãããŸããã ããã¯ãããé«ãæ©å¯æ§ã確ä¿ããã€ã³ã¹ããŒã«ãããæªæã®ããã³ãŒãã®æ£åœæ§ã®ã€ã¡ãŒãžãäœæããããã«è¡ãããŸããã ãã®èšŒææžã¯ã2011幎7ææ«ã«ã€ã³ãäŒæ¥ã®Technical and Commercial Consulting Pvtã«å¯ŸããŠçºè¡ãããŸããã æ ªåŒäŒç€Ÿããã¥ãŒããªãŒã«æ ç¹ã眮ãã
ããã«VeriSignã«é£çµ¡ããæäŸããæ
å ±ã«ãããšããã®èšŒææžã¯ããã«åãæ¶ãããŸããã åèšã§ããã®äºä»¶ã®èª¿æ»ã®çµæã70以äžã®æªæã®ãããã¡ã€ã«ïŒïŒïŒããã®ããžã¿ã«çœ²åã§çœ²åãããŸããã ãããã®ãã¡ã€ã«ã®ã¿ã€ã ã¹ã¿ã³ãã«åºã¥ããŠããããã®ãã¡ã€ã«ã®çœ²åã®ã¿ã€ã ã©ã€ã³ãåæ ããã¿ã€ã ã©ã€ã³ãäœæããŸããã
åéããæ
å ±ã«åºã¥ããŠãæ»æè
ã2012幎3æãã6æã«æãç©æ¥µçã«æªæã®ãããã¡ã€ã«ã«çœ²åããããšã¯æããã§ãããã®åŸã2012幎6æãã8æã«æŽ»åããããã«æžå°ããŸãã圌ã¯ãã§ã«ãªã³ãŒã«ãããŠããã
ãããã®çœ²åããããã¡ã€ã«ã«å ããŠã調æ»ã§ã¯çœ²åã®ãªãéåžžã®å®è¡å¯èœãã¡ã€ã«ãããã€ãçºèŠãããŸããã ãããã®ãã¡ã€ã«ã®äžéšã¯ã2011幎åé ã«çºèŠãããŸããã
ãããããŒãšåææ»æãã¯ãã«
æ»æãŠãŒã¶ãŒã®ãã¯ãã«ã®1ã€ã§ãæ»æè
ã¯äžè¬çãªè匱æ§CVE-2012-0158ã䜿çšããŸããã ãã®è匱æ§ã®æªçšã¯ãç¹å¥ã«åœ¢æãããMicrosoft Officeãã¡ã€ã«ãä»ããŠçºçãããã®çµæãOSã§ä»»æã®ã³ãŒããå®è¡ãããŸããã è匱ãªã·ã¹ãã ã§éããããšãã«ã2段éã®ã·ã§ã«ã³ãŒããå®è¡ããRTFããã¥ã¡ã³ãã確èªããŸããã ãã®ã·ã§ã«ã³ãŒãã¯ã·ã¹ãã æ
å ±ãfeds.comule.comãã¡ã€ã³ã«éä¿¡ããdigitalapp.orgããæªæã®ãããã¡ã€ã«ãããŠã³ããŒãããŸããã
å¥ã®æ»æãã¯ãã«ã¯ãMicrosoft WordãŸãã¯PDFãã¡ã€ã«ãè£
ã£ãå®è¡å¯èœãã¡ã€ã«ã®äœ¿çšã§ãã ãããã®ãã¡ã€ã«ã¯é»åã¡ãŒã«ãä»ããŠé
åžãããŸããã ãŠãŒã¶ãŒããã¡ã€ã«ãèµ·åãããšããã«ããã®æªæã®ããããã°ã©ã ã¯å®è¡ã®ããã«è¿œå ã®æªæã®ããã¢ãžã¥ãŒã«ãããŠã³ããŒãããŠèµ·åããŸããã æªæã®ããã³ãŒããé ãããã«ããŠãŒã¶ãŒã¯å®éã«ç¹å®ã®ã³ã³ãã³ããå«ãWordææžã衚瀺ããŸãããããŸããŸãªãããã¯ã«é¢ããããã€ãã®ãã®ãããªææžãèŠãŸããã
çºèŠãããææžã®1ã€ã¯ãã€ã³ãè»ã®ããŒãã䜿çšããŠããŸããã å®éããããã®ãã¡ã€ã«ãã©ã®ç¹å®ã®äººãŸãã¯çµç¹ã察象ãšããŠãããã«ã€ããŠã®ç¹å®ã®æ
å ±ã¯ãããŸããã ãã ãããã¬ã¡ããªã·ã¹ãã ã«åºã¥ããŠãç®æšã¯ããã¹ã¿ã³ã®äººã
ãšæè²æ©é¢ã§ãããšæ³å®ããŠããŸãã
以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ããããã®PDFããã¥ã¡ã³ãã®1ã€ã瀺ããŠããŸããå®éã«ã¯ããã®å
容ã¯ããŸããŸãªãœãŒã¹ããã®ç·šéã§ãã ãã®ããã¥ã¡ã³ãã¯ããpakistandefencetoindiantopmiltrysecreat.exeããšåŒã°ããèªå·±è§£åã¢ãŒã«ã€ããéããŠé
ä¿¡ãããŸããã
次ã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãpakterrisiomforindian.exeå®è¡å¯èœãã¡ã€ã«ãä»ããŠé
ä¿¡ãããPDFããã¥ã¡ã³ãã瀺ããŠããŸãã ãã®å Žåãããã¥ã¡ã³ãã®ã³ã³ãã³ãã¯ãã¢ãžã¢é²è¡ããã°ã®ããã¹ãã«åºã¥ããŠããŸãã ãã®ããã°ã¯ãã¢ãžã¢å°åã®è»äºãããã¯ã«é¢ãããã¥ãŒã¹ãéããŠããŸãã ãã¬ã¡ããªã·ã¹ãã ã®ããŒã¿ã¯ããã®ãã¡ã€ã«ã2011幎8æã«ããã¹ã¿ã³ã®ã³ã³ãã¥ãŒã¿ãŒã§æåã«çºèŠãããããšã瀺ããŠããŸãã
ãã€ããŒã
ãã®æ»æã§äœ¿çšãããååãªçš®é¡ã®ãã€ããŒããèŠã€ãããŸããã ä»ã®å Žåãšåæ§ã«ãã€ã³ã¹ããŒã«ã«ã¯ãããããŒã䜿çšãããŸããã ãã®äž»ãªã¿ã¹ã¯ã¯ãææããã³ã³ãã¥ãŒã¿ãŒãããªã¢ãŒãã®æ»æãµãŒããŒã«éèŠãªããŒã¿ãéä¿¡ããããšã§ãã 次ã®è¡šã«ã¯ãå®è¡å¯èœãã¡ã€ã«ã®ãã¡ããªãŒãšãã®æ©èœã®èª¬æãå«ãã¢ãžã¥ãŒã«ãå«ãŸããŠããŸãã ãããã®ã¢ãžã¥ãŒã«ã¯ãã¹ãŠãæšçåæ»æã§äœ¿çšãããŸããã
ææããã³ã³ãã¥ãŒã¿ãŒããçãŸããæ
å ±ã¯ãæå·åãããŠããªã圢åŒã§æ»æè
ã®ãµãŒããŒã«éä¿¡ãããŸãã ãã®ãããªãœãªã¥ãŒã·ã§ã³ã¯ãæªæã®ããã³ãŒããã³ã³ãã¥ãŒã¿ãŒäžã§è²»ããæéãå±éºã«ãããããããæšçåæ»æã®éèŠãªèŠå ãšãªããããæ¬åœã«å°æããŠããŸãã ãã®å Žåããããã¯ãŒã¯ãã©ãã£ãã¯ã®åæã«ããæªæã®ããã¢ã¯ãã£ããã£ãæ€åºã§ããŸãã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãããŒãã¬ãŒã®ãã°ãã¡ã€ã«ã®äžéšã瀺ããŠããŸãã
ãã®ãã°ãã¡ã€ã«ã¯éåžžã«æçã§ããããŠãŒã¶ãŒãå
¥åããæåãããã³ãŠãŒã¶ãŒãå
¥åãããŠã£ã³ããŠãšãã®æå»ã«é¢ããæ
å ±ã衚瀺ããŸãã ãããã®ãã¡ã€ã«ã¯æå·åãããŠããªã圢åŒã§ãµãŒããŒã«éä¿¡ããããããã³ã³ãã¥ãŒã¿ãŒã§æªæã®ããã³ãŒããæ€åºããã¿ã¹ã¯ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ãåæããã ãã§ç°¡åã«è§£æ±ºã§ããŸãã
ãã®æªæã®ããã³ãŒãã¯ããŠãŒã¶ãŒã®èª€è§£ãæãååã§èŠçŽ ã[ã¹ã¿ãŒã]ã¡ãã¥ãŒã«è¿œå ããããšã«æ³šæããŠãã ããã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ããã®ãããªã¡ãã¥ãŒé
ç®ã®äŸã瀺ããŠããŸãã
ãã®ããã€ã®æšéŠ¬ã¯ãããŸããŸãªã³ã³ããŒãã³ããåèµ·ååŸãçåã§ããããã«ããã¡ãœããã䜿çšããŸãã ããããåæã«ãç®ç«ããªããšã¯èšããŸããã éåžžãæšçåæ»æã¯ã·ã¹ãã å
ã§ã§ããã ãé·ãèŠããªãããã«ããããšããããããã®è
åšã«å¯Ÿããé©åãªã¡ã«ããºã ããªãããšã«é©ããŸããã
CïŒCæ§é
åæããã»ãšãã©ã®æªæã®ãããã¡ã€ã«ã«ã¯ãè¿œå ã®ã¢ãžã¥ãŒã«ãããŠã³ããŒãããããææããã·ã¹ãã ããæ»æè
ã®ãµãŒããŒã«ããŒã¿ãéä¿¡ãããããããã«äœ¿çšãããåã蟌ã¿URLãå«ãŸããŠããŸãã CïŒCå¶åŸ¡ãµãŒããŒã®URLã¯ãæå·åãããŠããªã圢åŒã§æªæã®ããã³ãŒãã®æ¬äœã«ä¿åãããå ŽåããããŸãã ãã以å€ã®å Žåã以äžã«ç€ºãããã«ãåäžã®1æåå転ïŒROT-1ïŒæäœã䜿çšãããããªãåºæ¬çãªæå·åæ¹æ³ã䜿çšãããŸãã
ãGjmftbttpdjbuf / ofuã->ãfilesassociate.netã
ãã®ãã£ã³ããŒã³ã§äœ¿çšããã20以äžã®ãã¡ã€ã³ãèŠã€ãããŸããã ãããã®ãã¡ã€ã³ã®äžéšã¯ãŸã ã¢ã¯ãã£ããšããŠããŒã¯ãããŠããŸããããããã®ã»ãšãã©ã¯IPã¢ãã¬ã¹ã«å€æãããªããªããŸããã ãããã®ãã¡ã€ã³ã®ã»ãšãã©ã«ã€ããŠããã¹ãã£ã³ã°ã¯OVHã®ãµãŒããŒã§è¡ãããŸããã ãã®Webãã¹ãã£ã³ã°ã¯ãã¹ãã ããã«ãŠã§ã¢ã®é
åžæäœã§ãã䜿çšããããããåŠå®çãªè©å€ããããŸãã æè¿ã®HOSTExploitã¬ããŒãã§ã¯ãæªæã®ããã³ã³ãã³ããæäŸãã50ã®Webãã¹ãã®ã©ã³ãã³ã°ã§5äœã«ãªããŸããïŒèªåŸã·ã¹ãã ããæäŸãããæªæã®ããã¢ã¯ãã£ããã£ãéäžããŠããäžäœ50ã®ãã¹ãïŒã
ãããã®ãã¡ã€ã³ã®å€ãã®ååã¯ã綎ãã«ãã£ãŠãæ£åœãªãµã€ããäŒç€Ÿã®ååãšéåžžã«äŒŒãŠããŸãã ãã®ã¢ãããŒãã¯ãCïŒCããŒã ãµãŒããŒãšããŠæ©èœãããã¡ã€ã³ã䜿çšããçã®ç®æšãé ãããã®äžè¬çãªæŠè¡ã§ãã ããšãã°ããwearwellgarments.euãããsecuina.comããªã©ã®ãã¡ã€ã³åã䜿çšãããŸãããããã¯ãæ£åœãªWebãµã€ããwearwellgarments.comãããsecunia.comããšãã䌌ãŠããŸããåŸè
ã¯æåãªã»ãã¥ãªãã£äŒç€ŸSecuniaã«å±ããŸãã
æªæã®ãããã¡ã€ã«ã®èµ·æº
ãã®ãã£ã³ããŒã³ã®åæã«ãããæªæã®ãããã¡ã€ã«ã®å°ççèµ·æºãç¹å®ããããšãã§ããŸããã ããã€ãã®éèŠãªææšã䜿çšããŠããããã®ãã¡ã€ã«ãã€ã³ãã§åéãããããšãããããŸããã æªæã®ãããã¡ã€ã«ã¯ãã€ã³ãã®äŒç€Ÿã«ãã£ãŠããžã¿ã«çœ²åãããŠããŸãã ããã«ã眲åã®ã¿ã€ã ã¹ã¿ã³ãã¯ãUTC 5:06ãã13:45ã®éã§å€åããŸããããã¯ãã€ã³ãã®ã¿ã€ã ãŸãŒã³ã®10:36ãã19:15ãŸã§ã®8æéã®çšŒåæ¥ã«å¯Ÿå¿ããŸãã èè
ã¯ãã®æé垯ã«äœãã§ãããšæãããŸãã
ããã€ãã®æªæã®ãããã¡ã€ã«ãã€ã³ãæåã«é¢é£ããæååãæ€åºããäžéšã®ã¹ã¯ãªããã¯ramukakaãšããå€æ°ã䜿çšããŠããŸãã
ãã©ã ã«ã«ãã®çµã¿åããã¯ã ããªãŠããæ ç»ã§ã¯éåžžã«äžè¬çã§ãããä»æ·»äººãæå³ããŸãã ãã®å€æ°ã¯ãã·ã¹ãã ã«æªæã®ããã³ãŒããåžžã«ååšããããã«ããããšãç®çãšããé¢æ°ã§äœ¿çšãããããããã®ååã¯å®éã®é¢æ°ãšéåžžã«ããçµã¿åããããŠããŸãã
ããããæªæã®ãããã¡ã€ã«ã®çºä¿¡åœã§ããã€ã³ããæ¯æããæã説åŸåã®ããè°è«ã¯ããã¬ã¡ããªã·ã¹ãã ã®ããŒã¿ã§ãã ããã€ã®æšéŠ¬ããã°ã©ã ã®å€ãã®äºçš®ããçæéã®ãã¡ã«åãå°åã§èšé²ãããŠããããšãããããŸããã æªæã®ããã³ãŒãã®åããŒãžã§ã³ã«ã¯ãäºãã«ããããªéãããããŸããã
ææçµ±èš
ãã¬ã¡ããªã·ã¹ãã ã«ãããšãããã¹ã¿ã³ãæ»æã®è¢«å®³ãæãåããå°åã§ãã£ãããšã¯æããã§ãã 次ã®å³ã¯ãéå»2幎éã«ãã®ãã£ã³ããŒã³ã«é¢é£ä»ãããããã¹ãŠã®æªæã®ãããã¡ã€ã«ã«ã€ããŠèšé²ãããæ€åºã®ååžã瀺ããŠããŸãã
ããã«å ããŠãåæããŒã¿ã«åºã¥ããŠçµ±èšãåéããŸããã ããã«ã¯3ã€ã®ãã¡ã€ã³ã䜿çšãããŸããããç»é²ããããã¡ã€ã³ã«ã¢ã¯ã»ã¹ããIPã¢ãã¬ã¹ã«åºã¥ããŠãææãããã¹ãã®ååžã®å°çãååŸããããšãã§ããŸããã
æããã«ã2ã€ã®å³ã®çµ±èšã¯å®å
šã«ç°ãªããŸãã åæä¿æã«ãã£ãŠååŸãããçµ±èšã®å ŽåããŠã¯ã©ã€ããšã«ã¶ãã¹ã¿ã³ã¯ãä¿®æ£ã§ãããã¹ãŠã®ãã¹ãIPã¢ãã¬ã¹ã®4åã®3ãå ããŠããŸãã ã©ãããåæã®å©ããåããŠãææããã·ã¹ãã ã®ããäžéšããæ€åºãããªãã£ãããã§ãããæ€åºã®çµ±èšã¯ããå
šäœçãªç»åã瀺ããŠããŸãã
ãããã«
åæã§ã¯ãæšçåæ»æã調æ»ãããã®æ»æãäžçäžã®ããŸããŸãªæšçãçã£ã蚌æ ãæäŸããŸããã æããã«ãã€ã³ãã«ã«ãŒãããããŸãã äžçã®å€ãã®åœã§æªæã®ãã掻åãèšé²ãããŠãããšããäºå®ã«ãããããããããã¹ã¿ã³ã§ã¯æãå€ãã®ææãçºçããŠããŸãã å®éãæšçåæ»æã¯é·ãéåžå°æ§ã倱ããŸãããããã®å Žåãæªæã®ããã³ãŒããã·ã¹ãã å
ã§è¯å¥œãªã¹ãã«ã¹ãæäŸã§ããããã«ããæ¯èŒçå°æ°ã®ããŒã«ãšãã¯ããã¯ã泚ç®ãããŸãã æ»æè
ã¯ãå®è¡å¯èœãã¡ã€ã«å
ã®æååã®åçŽãªé£èªåã䜿çšãããããã¯ãŒã¯çµç±ã§ãã©ãã£ãã¯ãéä¿¡ããéã«æå·åã䜿çšãããã¹ã¿ãŒãã¡ãã¥ãŒã«è¿œå ã®ã¢ã€ãã ãåã蟌ãããšã§ãã«ãŠã§ã¢ãæ£åœåããæ¢åã®å
¬éããŒã«ã䜿çšããŠææã·ã¹ãã ã«é¢ããæ
å ±ãåéããŸããã ãããã®æ¹æ³ã¯ãæ»æè
ãé©åãªã¢ãããŒããªãã§ãã®æäœã«åå¿ããããšã瀺ããŠããŸãã äžæ¹ãæ¢åã®æ¹æ³ã§ã¯ååãªæå°éã®å€è£
ããæäŸãããªãã£ãããããããã圌ãã¯é èœããŒââã«ã䜿çšããå¿
èŠæ§ãèªèããŠããŸããã§ããã
ã·ãã³ããã¯ã¯ãåæãå
¬éããåŸããã®æ»æã®åœ±é¿ãæãåããå°åã瀺ããŸããã ã·ãã³ããã¯ã¯ããã¬ã¡ããªã·ã¹ãã ãšåæ§ã«ãåã¢ãžã¢ã§æã䟵害ãããŠãããã¹ããã€ãŸãããã¹ã¿ã³ãããããšã確èªããŸããã ã€ã³ãã¯ããã®æ»æã®æœåšçãªçºçåœãšããŠç€ºãããŠããŸãã
[ã·ãã³ããã¯ã®ããŒã¿]
ãªããžã§ã¯ãå
ESETã¯ããã®ãã£ã³ããŒã³ã§æ¬¡ã®ååã§äœ¿çšãããæªæã®ãããªããžã§ã¯ããæ€åºããŸãã
Win32 / Agent.NLDã¯ãŒã
Win32 / Spy.Agent.NZDããã€ã®æšéŠ¬
Win32 / Spy.Agent.OBFããã€ã®æšéŠ¬
Win32 / Spy.Agent.OBVããã€ã®æšéŠ¬
Win32 / Spy.KeyLogger.NZLããã€ã®æšéŠ¬
Win32 / Spy.KeyLogger.NZNããã€ã®æšéŠ¬
Win32 / Spy.VB.NOFããã€ã®æšéŠ¬
Win32 / Spy.VB.NRPããã€ã®æšéŠ¬
Win32 / TrojanDownloader.Agent.RNTããã€ã®æšéŠ¬
Win32 / TrojanDownloader.Agent.RNVããã€ã®æšéŠ¬
Win32 / TrojanDownloader.Agent.RNWããã€ã®æšéŠ¬
Win32 / VB.NTCããã€ã®æšéŠ¬
Win32 / VB.NVMããã€ã®æšéŠ¬
Win32 / VB.NWBããã€ã®æšéŠ¬
Win32 / VB.QPKããã€ã®æšéŠ¬
Win32 / VB.QTVããã€ã®æšéŠ¬
Win32 / VB.QTYããã€ã®æšéŠ¬
Win32 / Spy.Agent.NVLããã€ã®æšéŠ¬
Win32 / Spy.Agent.OAZããã€ã®æšéŠ¬