ããããåŸã§ïŒåŸ©å·åã®éå§åŸ3é±é以äžïŒãç¶æ³ã¯è¯ããªããŸããã ãã®æéäžãç°ãªãPCã§Trojan.Encoder.225ãšTrojan.Encoder.263ã®2ã€ã®ãŠã€ã«ã¹ãçºçããçŽåŸã«ãããŒã¿ãæ£åžžã«è§£èªããŸããã
æãåºããŠãã ãã ãTrojan.Encoderãã¡ããªãŒã®ããã€ã®æšéŠ¬ã¯ãã³ã³ãã¥ãŒã¿ãŒã®ããŒããã©ã€ãäžã®ãã¡ã€ã«ãæå·åãããããã解èªããããã«ãéãå¿ èŠãšããæªæã®ããããã°ã©ã ã§ãã * .mp3ã* .docã* .docxã* .pdfã* .jpgã* .rarãªã©ã®ãã¡ã€ã«ã¯æå·åãããŠããå ŽåããããŸãã
å人çã«ãã®ãŠã€ã«ã¹ã®ãã¡ããªãŒå šäœãç¥ãããšã¯ã§ããŸããã§ããããå®è·µã瀺ãããã«ãææãæ²»çã解èªã®æ¹æ³ã¯èª°ã§ãã»ãŒåãã§ãã
1.被害è ã¯ãæ·»ä»ãã¡ã€ã«ä»ãã®ã¹ãã ã¡ãŒã«ãä»ããŠææããŸãïŒææã«ããé »åºŠã¯äœãïŒã
2.ãŠã€ã«ã¹ã¯ãææ°ã®ããŒã¿ããŒã¹ãåããã»ãšãã©ãã¹ãŠã®ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã«ãã£ãŠèªèãããåé€ãããŸãïŒæ¢ã«ïŒã
3.ãã¡ã€ã«ã¯ã䜿çšããæå·åã®çš®é¡ã«åãããŠãã¹ã¯ãŒããšããŒãéžæããããšã«ãã埩å·åãããŸãã
ããšãã°ãTrojan.Encoder.225ã¯RC4æå·åïŒå€æŽïŒ+ DESã䜿çšããTrojan.Encoder.263ã¯CTRã¢ãŒãã§BlowFishã䜿çšããŸãã ãããã®ãŠã€ã«ã¹ã¯çŸåšãå人çãªæ £è¡ã«åºã¥ããŠ99ïŒ ã§è§£èªãããŠããŸãã
ãããããã¹ãŠãããã»ã©ã¹ã ãŒãºã§ã¯ãããŸããã æå·åãŠã€ã«ã¹ã®äžã«ã¯ãæ°ãæã®ç¶ç¶çãªåŸ©å·åïŒTrojan.Encoder.102ïŒãå¿ èŠãšãããã®ãããã°ãDoctor Webã¹ãã·ã£ãªã¹ãã§ããå®éã«ã¯åŸ©å·åã§ããªããã®ïŒTrojan.Encoder.283ïŒããããŸãã ã
é çªã«ã
2013幎8æäžæ¬ãTrojan.Encoder.225ãŠã€ã«ã¹ã§æå·åããããã¡ã€ã«ã®åé¡ã«ã€ããŠã¯ã©ã€ã¢ã³ãããã¢ãããŒããããŸããã åœæããã®ãŠã€ã«ã¹ã¯æ°ãããã®ã§ããã誰ãäœãç¥ããŸãããã€ã³ã¿ãŒãããäžã«ã¯ãã€ã³ã¿ãŒãããäžã«Googleããã®2ã3件ã®ãªã³ã¯ããããŸãã ã€ã³ã¿ãŒãããã§é·æéæ€çŽ¢ããçµæããã®ãŠã€ã«ã¹ã®åŸã«ãã¡ã€ã«ã埩å·åããåé¡ã«å¯ŸåŠããå¯äžã®ïŒèŠã€ãã£ãïŒçµç¹ã¯Doctor Webã§ããããšãããããŸããã ã€ãŸããæšå¥šäºé ã®æ瀺ããã¯ãã«ã«ãµããŒããžã®åãåãããç¬èªã®ãã³ãŒããŒã®éçºãªã©ãè¡ããŸãã
è² ã®åŸéã
ãããŠããã®æ©äŒãå©çšããŠãã«ã¹ãã«ã¹ããŒã®2ã€ã®ãã€ãã¹é¢ã«æ³šç®ããããšæããŸãã ãã¯ãã«ã«ãµããŒãã«é£çµ¡ãããšãããã®åé¡ã«åãçµãã§ããŸããçµæãã¡ãŒã«ã§éç¥ããŸãããšåŽäžããŸãã ãããããã€ãã¹ã¯ããªã¯ãšã¹ãã«å¯Ÿããå¿çãåãåã£ãããšããªãããšã§ãã 4ã¶æåŸã ãããŒã¹ã©ãã£ãã·ã¥ããåå¿æéãæ³åããŸããã ãããŠãããã§ç§ã¯ãã¢ããªã±ãŒã·ã§ã³ãã1æé以å ããšããæšæºãç®æããŠããŸãã
ã«ã¹ãã«ã¹ããŒç 究æé·ã®ãšãã²ããŒã»ã«ã¹ãã«ã¹ããŒåå¿ã®æ¥ãã¹ãããšã§ãã ããããç§ã¯ãã¹ãŠã®äŒæ¥ã®ããªãã®ååãããã«ã座ã£ãŠãããŸãã ãŸãã倧äžå€«ãã©ã€ã»ã³ã¹ã¯2014幎1æãã3æã«å€±å¹ããŸãã èšããŸã§ããªããã©ã€ã»ã³ã¹ãæŽæ°ããŸããïŒ;ïŒ
ç§ã¯ãã¢ã³ããŠã€ã«ã¹æ¥çã®éãžã£ã€ã¢ã³ãã®ãããã°ãåçŽãªãäŒæ¥ã®ãå°é家ãã®é¡ãè¡šããŠããŸãã ããããäžè¬çã«ã¯ããé ã«é ããŠããããšãéãã«æ³£ãããã
ãããããã§ã«ããã«ãããã®ã¯ã絶察ã«èª°ããæ倧éã«ãééã£ããã ãŠã€ã«ã¹å¯Ÿçã¯ãååãšããŠããã®ãŠã€ã«ã¹ãã³ã³ãã¥ãŒã¿ã«äŸµå ¥ããããšãèš±å¯ãã¹ãã§ã¯ãããŸããã§ããã ç¹ã«çŸä»£ã®æè¡ãèæ ®ããŠããŸãã ãããŠãã¢ã³ããŠã€ã«ã¹æ¥çã®GIANTSã®ãããããã¯ãããã¥ãŒãªã¹ãã£ãã¯åæãããããªãšã³ããã£ãã·ã¹ãã ãããããã¢ã¯ãã£ããªé²åŸ¡ãã®ãã¹ãŠãæŒåããããšæãããŸã...
ãããã®ãã¹ãŠã®ã¹ãŒããŒã·ã¹ãã ã¯ãåŸæ¥å¡éšéããããã¯ãSUMMARYãã§ãå®å šãªãã¬ã¿ãŒãéãããšãã«ã©ãã«ãããŸãããïŒ
åŸæ¥å¡ã¯äœãèããŠããã®ã§ããããïŒ
ããªããç§ãã¡ãå®ãããšãã§ããªããªãããªãç§ãã¡ã¯ããªããå¿ èŠãªã®ã§ããããïŒ
ãããŠãDoctor Webãªãäœã§ãåé¡ãããŸããããå©ããåŸãããã«ã¯ãåœç¶ããœãããŠã§ã¢è£œåã®ã©ã€ã»ã³ã¹ãå¿ èŠã§ãã ãã¯ãã«ã«ãµããŒãïŒä»¥äžTPïŒã«é£çµ¡ããå ŽåãDr.Webã·ãªã¢ã«çªå·ãæäŸããå¿ èŠããããŸãããRequest CategoryïŒãè¡ã§ãæ²»çãªã¯ãšã¹ãããéžæããããåã«æå·åãã¡ã€ã«ãã©ãã«æäŸããããšãå¿ããªãã§ãã ããã ã€ã³ã¿ãŒãããäžã«ãããã§é 眮ããããããããDr.Webãžã£ãŒãã«ããŒãã¯ããœãããŠã§ã¢è£œåã®è³Œå ¥ã確èªãããTPã¹ãã·ã£ãªã¹ãã«ãã£ãŠ1ã€ã2ã€åé€ããããããé©åã§ã¯ãªãããšãããã«èšããªããã°ãªããŸããã æããå®ããã©ã€ã»ã³ã¹ãè³Œå ¥ããæ¹ãç°¡åã§ãã 埩å·åãè¡ã£ãå Žåããã®ã©ã€ã»ã³ã¹ã¯ãæ°çŸäžãã®æéã§å ±ãããããã§ãã ç¹ã«åçãEgypt 2012ãã®ãããã©ã«ãã1ã€ã®ã³ããŒã«å«ãŸããŠããå Žå...
è©Šè¡çªå·1
ãã®ãããnåã®éé¡ã§ã1幎é2å°ã®PCã®ã©ã€ã»ã³ã¹ããè³Œå ¥ããTPã«é£çµ¡ããŠããã€ãã®ãã¡ã€ã«ãæäŸãããšãte225decrypt.exe埩å·åãŠãŒãã£ãªãã£ããŒãžã§ã³1.3.0.0ãžã®ãªã³ã¯ãåŸãããŸããã æåãèŠè¶ããŠããŠãŒãã£ãªãã£ãå®è¡ããŸãïŒæå·åããã* .docãã¡ã€ã«ã®ããããããã€ã³ãããå¿ èŠããããŸãïŒã ãŠãŒãã£ãªãã£ã¯éžæãéå§ããå€ãE5300 DualCoreããã»ããµã2600 MHzïŒãªãŒããŒã¯ããã¯3.46 GHzïŒ/ 8192 MB DDR2-800ãHDD 160Gb Western Digitalã90-100ïŒ ã«å®¹èµŠãªãããŒãããŸãã
ããã§ã¯ãç§ãšäžŠè¡ããŠãã³ã¢i5 2500k PCïŒ4.5ghzãžã®ãªãŒããŒã¯ããã¯ïŒ/ 16 ram 1600 / ssd Intelã®ååãäœæ¥ã«å«ãŸããŠããŸãïŒããã¯èšäºã®æåŸã«è²»ãããæéãæ¯èŒããããã§ãïŒã
6æ¥åŸãç§ã®ãŠãŒãã£ãªãã£ã¯7277ãã¡ã€ã«ã®åŸ©å·åã«ã€ããŠå ±åããŸããã ãããã幞çŠã¯é·ãã¯ç¶ããªãã£ãã ãã¹ãŠã®ãã¡ã€ã«ã¯ãäžæ£ã«ã解èªãããŸããã ã€ãŸããããšãã°ãMicrosoft Officeããã¥ã¡ã³ãã¯éããŸãããã* .docxããã¥ã¡ã³ãã®ã³ã³ãã³ãã«å«ãŸããWordãèŠã€ãããŸããã§ããããŸãã¯ãã³ã³ãã³ãã®ãšã©ãŒã«ãã* .docxãã¡ã€ã«ãéããŸããããšãããšã©ãŒãçºçããŸãã * .Jpgãã¡ã€ã«ããšã©ãŒã§éãããç»åã®95ïŒ ãé»ã衚瀺ãããããèæ¯ãèç·-ç·ã«ãªããŸãã ãã¡ã€ã«* .rar-ãã¢ãŒã«ã€ãã®äºæããªãçµäºãã
äžè¬çã«ãå®å šãªé害ã
è©Šè¡çªå·2
çµæã«ã€ããŠTPã«æžã蟌ã¿ãŸãã ããã€ãã®ãã¡ã€ã«ãèŠæ±ããŸãã 1æ¥åŸã圌ãã¯åã³te225decrypt.exeãŠãŒãã£ãªãã£ãžã®ãªã³ã¯ãæäŸããŸããããã§ã«ããŒãžã§ã³1.3.2.0ã§ãã ããŠãç«ã¡äžããŸãããããŸã 代æ¿æ段ã¯ãããŸããã§ããã çŽ6æ¥ãããããŠãŒãã£ãªãã£ã¯ãæå·åèšå®ãéžæã§ããŸããããšãããšã©ãŒã§äœæ¥ãçµäºããŸãã åèš13æ¥éã®ãææ°Žæºãã
ããããã¢ã«ãŠã³ãäžã§ãåºæ¬ããã¯ã¢ãããªãã®*æããª*ã¯ã©ã€ã¢ã³ãã®éèŠãªããã¥ã¡ã³ãããããããŸããã
è©Šè¡çªå·3
çµæã«ã€ããŠTPã«æžã蟌ã¿ãŸãã ããã€ãã®ãã¡ã€ã«ãèŠæ±ããŸãã ãããŠããæ³åã®ãšããã1æ¥åŸã«ã¯åãte225decrypt.exeãŠãŒãã£ãªãã£ãžã®ãªã³ã¯ãæäŸãããŸããããã§ã«ããŒãžã§ã³1.4.2.0ãæäŸãããŠããŸãã ããã§ã¯ãã«ã¹ãã«ã¹ããŒã©ããESET NOD32ããŸãã¯ä»ã®ãŠã€ã«ã¹å¯Ÿçãœãªã¥ãŒã·ã§ã³ã¡ãŒã«ãŒããã®ä»£æ¿åã¯ãããŸããã§ããã ãããŠä»ã5æ¥3æé14åïŒ123.5æéïŒåŸã«ããŠãŒãã£ãªãã£ã¯ãã¡ã€ã«ã®åŸ©å·åãå ±åããŸãïŒã³ã¢i5埩å·åã®ååã¯21æé10åããããããŸããã§ããïŒã
ãŸããããã§ã¯ãªãã£ããšæãã ãããŠèŠãïŒå®å šãªæåïŒ ãã¹ãŠã®ãã¡ã€ã«ãæ£ãã埩å·åãããŸãã ãã¹ãŠãé©åã«éããéããå€èŠãç·šéãä¿åãããŸãã
ã¿ããªå¹žãã§ããçµããã
ããããŠãTrojan.Encoder.263ãŠã€ã«ã¹ã«ã€ããŠã®è©±ã¯ã©ãã«ãããŸããïŒããšãããªãã¯å°ããŸãã ãããŠæ¬¡ã®PCã§ã¯ãããŒãã«ã®äžã«...ããã£ãã ããã§ã¯ãã¹ãŠãç°¡åã§ãããDoctorWebã®TPã§èšè¿°ããte263decrypt.exeãŠãŒãã£ãªãã£ãååŸããŠèµ·åãã6.5æ¥éåŸ æ©ããŸãã èŠçŽãããšãç·šéãªãã£ã¹ã®Doctor Webãã©ãŒã©ã ããããã€ãã®ãã³ããæäŸã§ããŸãã
æå·åãŠã€ã«ã¹ã«ææããå Žåã«è¡ãå¿ èŠãããããšïŒ
-ãŠã€ã«ã¹ç 究æã«éã£ãŠãã ãã WebãŸãã¯ãçããããã¡ã€ã«ãéä¿¡ãããæå·åãããããã¥ã¡ã³ããã¡ã€ã«ã®åœ¢åŒã
-Dr.WebåŸæ¥å¡ã®åçãåŸ ã£ãŠããã圌ã®æ瀺ã«åŸããŸãã
çŠæ¢äºé ïŒ
-æå·åããããã¡ã€ã«ã®æ¡åŒµåãå€æŽããŸãã ãã以å€ã®å Žåãé©åã«éžæãããããŒã䜿çšãããšããŠãŒãã£ãªãã£ã¯åã«åŸ©å·åããå¿ èŠã®ãããã¡ã€ã«ãã衚瀺ãããŸããã
-å°é家ãšçžè«ããããšãªããããŒã¿ã埩å·å/埩å ããããã®ããã°ã©ã ãåå¥ã«äœ¿çšããã
ä»ã®ã¿ã¹ã¯ãããµãŒããŒã解æŸããããšã«æ³šæããŠãç§ã¯ããªãã®ããŒã¿ã解èªããããã®ç§ã®ç¡æãµãŒãã¹ãæäŸããŸãã *ç¹å®ã®åšæ³¢æ°*ã16GBã®RAMããã³Vertex 4 SSDãžã®ãªãŒããŒã¯ããã¯ãåãããµãŒããŒã³ã¢i7-3770Kã
ãHabrãã®ãã¹ãŠã®ã¢ã¯ãã£ããªãŠãŒã¶ãŒã«å¯ŸããŠãç§ã®ãªãœãŒã¹ã®äœ¿çšã¯ç¡æã§ã!!!
PMãŸãã¯ä»ã®é£çµ¡å ã«ã¡ãŒã«ããã ããã ç§ã¯ãã§ã«ãç¬ããé£ã¹ãŸããã ãã®ãããå€éã«ãµãŒããŒã埩å·åããã®ãæ ãå¿ èŠã¯ãããŸããã
ãã®ãŠã€ã«ã¹ã¯çŸä»£æ§ã®ãæšåãã§ããã仲éã®å µå£«ãããç¥å¥ªããããããšã¯äººéçã§ã¯ãããŸããã ãã ãã誰ããç§ã®Yandex.Moneyã¢ã«ãŠã³ã410011278501419ã«æ°ãã«ããæãããã°ãç§ã¯æ°ã«ããŸããã ããããããã¯ãŸã£ããå¿ èŠãããŸããã ãåãåããã 空ãæéã«ã¢ããªã±ãŒã·ã§ã³ãåŠçããŸãã
æ°ããæ å ±ïŒ
2013幎12æ12æ¥ãããåãTrojan.Encoderã·ãªãŒãºããã®æ°ãããŠã€ã«ã¹ã®æ¡æ£ã¯ãDoctor WebãTrojan.Encoder.263ã®åé¡ã®äžã§éå§ãããŸããããRSAæå·åã䜿çšãããŠããŸããã ä»æ¥ã®æ¥ä»ïŒ2013幎12æ20æ¥ïŒã®ãã®ãã¥ãŒã¯ãéåžžã«åŒ·åãªæå·åæ¹åŒã䜿çšããŠããããã 埩å·åã§ããŸãã ã
ç§ã¯ãã®ãŠã€ã«ã¹ã«èŠããã§ãã人ã«ãå§ãããŸãïŒ
1.çµã¿èŸŒã¿ã®Windowsæ€çŽ¢ã䜿çšããŠã.perfectæ¡åŒµåãå«ããã¹ãŠã®ãã¡ã€ã«ãèŠã€ããå€éšã¡ãã£ã¢ã«ã³ããŒããŸãã
2. CONTACT.txtãšåããã¡ã€ã«ãã³ããŒããŸã
3.ãã®å€éšã¡ãã£ã¢ããæ£ã«ã眮ããŸãã
4.ãã³ãŒããŒãŠãŒãã£ãªãã£ã衚瀺ããããŸã§åŸ ã¡ãŸãã
çŠæ¢äºé ïŒ
äŸµå ¥è ããããå¿ èŠã¯ãããŸããã ããã¯æãã§ãã 50ïŒ ä»¥äžã®ã±ãŒã¹ã§ã¯ãçŽ5000ã«ãŒãã«ã§ãæ¯æãããããåŸãäœãåŸãããŸããã ãéããæ£åžãããããŸããã
å ¬å¹³ã«èšããšãã€ã³ã¿ãŒãããäžã«ã¯ããç¥å¥ªãã®ããã«åŸ©å·åã«ãã£ãŠãã¡ã€ã«ãåãåã£ãã幞éãªäººããããããšã«æ³šæãã䟡å€ããããŸãã ããããããªãã¯ãããã®äººã ãä¿¡ããã¹ãã§ã¯ãããŸããã ç§ããŠã€ã«ã¹äœæè ã ã£ãå Žåãç§ãæåã«ããããšã¯ããç§ã¯æ¯æããæžãŸãããã³ãŒããéãããŠãã!!!ããªã©ã®æ å ±ãåºããããšã§ããã
ãããã®ãã©ãããŒãªãã®ãã®èåŸã«ã¯ãåãæ»æè ãããå¯èœæ§ããããŸãã
ããŠ... Trojan.Encoderã°ã«ãŒãã®ãŠã€ã«ã¹ã®åŸã«ãã¡ã€ã«ã埩å·åãããŠãŒãã£ãªãã£ãäœæããããšã§ãä»ã®ãŠã€ã«ã¹å¯ŸçäŒæ¥ã«å¹žéãç¥ããŸãã
Doctor Webãã©ãŒã©ã ããv.martyanovã®ä»²éã«ãã³ãŒããŠãŒãã£ãªãã£ãäœæããããã«è¡ãããäœæ¥ã«ç¹å¥ãªæè¬ãç³ãäžããŸãã