ç§ã¯æšæ¥ãããæã«å ¥ããä»æ¥ã¯ãããæŽçããŸããã å€ã2012 CVE ïŒSecurityManagerãç§ãæšæž¬ããïŒããã®Javaãšã¯ã¹ããã€ãã®è² è·ã«ãªããŸããã ç§ã¯åœŒå¥³ã0dayãšåŒã³ãŸã[1] ãããã¯ã VirusTotal / MalwrããŒã¿ããŒã¹ã«ã©ã®ãããªåœ¢åŒïŒããã¯ãŸãã¯ã¢ã³ããã¯ïŒã§ãååšããªãããã§ãã
IDAã§ã®åæã®è©Šã¿[2] ãšã©ãŒã§å€±æããŸãïŒ

ãããããå«ããªäººã¯ãç§ã®ãããªèª°ããåæããããšããããšãç¥ã£ãŠããããã§ãã ãããã«ãããéã¢ã»ã³ãã©ãŒãçæ°ã«é§ãç«ãŠãexeä¿®æ£ã®ãªãã·ã§ã³ã¯å€ããããŸããããWindowsã§ã¯ç¡èŠãããŸãã
CFF Explorerã§exeãã¡ã€ã«ã調ã¹ããšãNTããããŒã®1ã€ãã€ãŸãDelay Import Directory RVAã®å€ã®ãData Directoriesãã«ãšã©ãŒããããŸãã CFFã¯ãå€0x00000040ãããã«æ£ãããªããã®ãšããŠåŒ·èª¿è¡šç€ºãããšããç¹ã§åªããŠããŸãã ãšã©ãŒãä¿®æ£ããã«ã¯ãŒãã«ããŸãã

exeãä¿åããIDAã§åæ€åºããŸãããšã©ãŒã¯çºçãããåé¡ãªãéãããšãã§ããŸãã
ç°¡åãªæ€æ»ã§ããããMFCã§ããããšãæããã«ãªããŸãã[3] ã¢ããªã±ãŒã·ã§ã³ã ãããã©ããã£ãŠç解ããã®ã§ããïŒ ããã¯ãã€ã³ããŒãã»ã¯ã·ã§ã³ã®[ã©ã€ãã©ãª]åã«æ瀺çã«èšèŒãããŠããŸãã

ãã¡ãããã¢ããªã±ãŒã·ã§ã³ã¯ããã±ãŒãžåãããŠããŸãã ã¡ã¢ãªããã£ã±ãã§ãã å€æŽãããã»ã¯ã·ã§ã³ããããŒãªããå¹³å¡ãªããã¯ã¡ã¢ãªã

ãŸããéç解æã¯ãªãã·ã§ã³ã§ã¯ãããŸããã ãããªãç 究ã®ããã«ãåç解æãå¿ èŠã§ãã
Immunityãšä»®æ³ãã·ã³ã«é£ã³èŸŒãåã«ãIDAã«ã¯è¡šç€ºãããªããCFFãšã¯ã¹ãããŒã©ãŒã«ã¯è¡šç€ºãããŠããããã€ãã®èå³æ·±ãããšã«æ³šç®ãã䟡å€ããããŸãã ãŸãããã£ããã³ãšããã³ã¹ã®åã³ã®ããã«ããªãœãŒã¹ãã£ã¬ã¯ããªã«é ãããŠãããã¡ã€ã«ãããã€ããããŸãã
æåã¯PNGãã¡ã€ã«ã§ãã

2çªç®ã¯HTMLããŒãžã§ãã

å€ã§ãã PNGãã¡ã€ã«ãIrfanViewïŒç»åã®æé©ãªãã¥ãŒã¢ãŒïŒã«èªã¿èŸŒããšããµã€ãºã55 KBã«åãŸããªãå°ããªé»ãåè§åœ¢ã衚瀺ãããŸãã 確ãã«äœããé ãããŠããŸãã ã¹ãã¬ãã°ã©ãã£ãŒ ïŒ

次ã«ãHTMLããŒãžãèŠãŠãã ããã Notepad ++ã§ããŠã³ããŒãããŠã¯ãªãŒãã³ã°ãããšããã©ãŠã¶ã¿ã€ãæ€åºã¹ã¯ãªããã«äŒŒããã®ãåŸãããŸãã

ãªãããããã¹ãŠããªãœãŒã¹ã»ã¯ã·ã§ã³ã«ããã®ããããã«ã¯å±éããã圢ã§ãã£ãŠã-è¬ã®ãŸãŸã§ãã ãªãœãŒã¹ã»ã¯ã·ã§ã³ã«æ»ããŸãã ãããŸã§ã®éãé梱ãç¶ããŠãã ããã
Immunity DebuggerãšVirtual Boxãèµ·åããanti-anti-debug pythonãã©ã°ã€ã³ãããŒãããŸãã

ããã»ã¹ãå®äºããããã¡ã¢ãªãããŒãžããŠãã®åæãå®è¡ã§ããŸãã

èªã¿åãæžã蟌ã¿å®è¡ïŒRWEïŒãšããã©ãã«ã®ä»ããã¡ã¢ãªé åãããã€ãèŠã€ãããŸããã ãããã®1ã€ã¯0x00910000ãå¥ã®1ã€ã¯0x00930000ã次ã¯0x00940000ãæåŸã¯0x00970000ã§ãã ããã«åæãããšã4ã€ã®ãã¡3ã€ã ããããã°ã©ã ãå«ãã§ããããšãããããŸãã ãã ãã3ã€ã®ããã°ã©ã ã1ã€ã«é ããŸããïŒ çŽ æµãªã€ãŒã¹ã¿ãŒãšãã°ã

ããã§ãããã«åæããããã«ããã°ã©ã ããã³ãããŸãã OllyDumpExãããŒãã ã0090ãšãªã¢ã«ãã£ãŒãããŸãã ã¢ãã¬ã¹0x00910000ããã³0x00970000ã®ããã°ã©ã ã¯ããµã€ãºãã»ã¯ã·ã§ã³ããããŒãããã³ç¹æ§ããå€æããŠãå ã®ããã°ã©ã ãšäžèŽããŠããããšãããããŸãã ãããŠã0x00950000ã®é åã¯ããããšã¯ç°ãªããŸãïŒä»ã®ã»ã¯ã·ã§ã³ããããŒãç°ãªããµã€ãºã ããã¯åãéã®åµã§ãªããã°ãªããŸããïŒå°æ¥ãèè ãã¹ã¯ãªãŒã³ã·ã§ããã§éã®åµã䜿çšãããããç§ã¯æåéãã®ç¿»èš³ãæ®ããŸãã-ãããTranslãïŒã

ãã³ãã®æŽåæ§ãç¶æããããã«ããªãã«ãã¢ãŒãã§ã¯ãªããã€ããªïŒRawïŒã¢ãŒãã䜿çšããŠexeããã³ãããŸãã

2ã€ã®ã»ã¯ã·ã§ã³ããããŒã¯ãããã°ã©ã ãUPXã䜿çšããŠããã±ãŒãžåãããŠããããšã瀺ããŸã[4] ã upxãŠãŒãã£ãªãã£ãå®è¡ãããšãããã確èªãããŸãã ç°¡åã«åµãéããããšãã§ããŸãã

æ°ããexeã¯çŽ40 KB倧ãããæ£ãã解åãããŠããã®ã§ãããããIDAã«ããŒã¿ãéä¿¡ã§ããŸãã è¡ãèŠããšãé¢çœãããšãããããŸãã

ããã¯HTTPãªã¯ãšã¹ãã§ãã ãã®ããšã¯ãPOSTèŠæ±ã䜿çšããŠãæ¯ããã«éãããŠããããã§ãã
ããªãã¯å°ããããšãã§ããŸã-CïŒCãµãŒããŒã¯ã©ãã§ããïŒ ããã°ã©ã ã«ãã¬ãŒã³ããã¹ã圢åŒã§å«ãŸããŠããããã«ã¯èŠããŸããã èŠããŠãããŠãã ãããç§ã¯ããªãã«ãªãœãŒã¹ã»ã¯ã·ã§ã³ãå¿ããªãããã«é Œãã ã®ã§ããïŒ golden_egg.exeã®ãªãœãŒã¹ã»ã¯ã·ã§ã³ãã芧ãã ããã

åºæ¥äžããã http://31.207.6.161ã ã¯ãªã¢ããã¹ãã§äœæããç¥ããããã ããã°å¹žãã§ãã ãããŸããã«ããã»ãã¥ãªãã£ãåã³æ»æãããŸãã
ã¡ã€ã³ã¢ããªã±ãŒã·ã§ã³ã®å®è¡æã«äœãèµ·ãããçåã«æããããããŸããã èŠãŠã¿ãŸãããïŒ
ããŒãæã«ã ããã»ã¹ãšã¯ã¹ãããŒã©ãŒãèªåçã«éããããã¿ã¹ã¯ãããŒãžã£ãŒãããŠã³ããŒãããããšãããšããã¿ã¹ã¯ãããŒãžã£ãŒã管çè ã«ãã£ãŠç¡å¹ã«ãããŸããããšããã¡ãã»ãŒãžã衚瀺ãããããã«éããããŸãã ã¹ã¯ãªãŒã³ã·ã§ãããæ®ãããã£ãã®ã§ãããããã»ã©éããªãããšãããããŸããã ã€ãã¥ããã£ã«ç®ãåãããšãå ã®ããã°ã©ã ãgolden_egg.exeãããã§ã«å®äºããŠããããšãããããŸãã 亀æ-äžæãã£ã¬ã¯ããªããèµ·åããããzpNvNKSi.exeããšããååã®ä»ã®ããã°ã©ã ã ããã·ã¥ãæ¯èŒããŸã-ãããŠãããã¯åãããã§ãïŒ

ïŒç§ã®ããã·ã¥ã奜ãã§ããïŒ ç»é²ãšSMSãªãã§ããããããŠã³ããŒãã§ããŸãïŒ
åºåã®äžæã¯çµãããŸãããããã°ã©ã ã®æ©èœãæ確ã«ãªããŸãã-ã¿ã¹ã¯ãããŒãžã£ããªãã«ãªããã奜ãŸãããªããã¢ããªã±ãŒã·ã§ã³ã匷å¶çµäºãããäžæãã£ã¬ã¯ããªããèµ·åãããŸãã msconfigãã§ãã¯ã§ã¯ãèµ·åæã«2ã€ã®æ°ãããšã³ããªã衚瀺ãããŸãã

ç§ã¯äž¡æ¹ã®ãã¡ã€ã«ããã§ãã¯ããŸãããããããã¯ãã€ãããšã«å ã®ããã°ã©ã ãšäžèŽããŠããŸããã
Immunityã䜿çšããŠããã°ã©ã ã«ã¢ã¿ããããã¡ã¢ãªãšã¹ã¬ããã®æ°ã確èªããŸãïŒãtãããŒãæŒããŠïŒ-ããã°ã©ã ããã«ãã¹ã¬ããã§ããããšãããããŸãã 12åã®ã¹ã¬ãããã«ãŠã³ãããŸããã

åã¹ã¬ããã¯ãä»ã®ã¹ã¬ããã®1ã€ã匷å¶çµäºããããã©ããã远跡ãããšæ³å®ããŠããŸãã ãã ããããã»ã¹ãäžæããããšã«ãããProcess Explorerã䜿çšããŠãã®ã¡ã¢ãªã調ã¹ãããšãã§ããŸãã åæã§ã¯ãIDAã«è¡šç€ºãããªãã£ãè¡ãããããšã瀺ãããŠããŸãã

çªç¶ã ããã°ã©ã ã¯ãããã®ãŠãŒãã£ãªãã£ããã§ãã¯ããå®è¡äžã®å Žåã¯åŒ·å¶çã«éãããšæããŸãã ããã¯ãããã°ã©ã ã®å®è¡äžã«Process Explorerã䜿çšã§ããªãã£ãçç±ã説æããŠããŸãã ãããã®ãŠãŒãã£ãªãã£ã®èµ·åãè€éã«ããå³åº§ã«ãããã殺ãããšã¯éåžžã«æ¹æ³ã§ãã ãªã¹ãã«ã¯ãregeditãLordPEãWiresharkãregmonãfilemonãprocmonãtcpviewãtaskmgrãããã«ã¯Windows DefenderããããŸãã èŸãã 確ãã«ãProcess Explorer'a- Process Hackerã®ããšãã¯èŠåœãããŸããã
ç§ãã¡ã®èšæ¶ã®

Unicodeãšã³ã³ãŒãã£ã³ã°ã®æååã®1ã€ã®ã¡ã¢ãªæ€çŽ¢ãå®è¡ãããšãæååãtaskmgrãã.dataã»ã¯ã·ã§ã³ã«ããããšãããããŸãã IDAã¯æååã«ã€ããŠåãã€ããŠããŸããïŒ ããã§ããªãã äœéã®ãã€ããªæ€çŽ¢ïŒAlt + BïŒã䜿çšããŠåè©Šè¡ããããã«è¡ãèŠã€ããŸãã ã©ããããIDAã¯ããã©ã«ãã§æ€çŽ¢ãããšãã«Unicodeæååã衚瀺ããŸããã Alt + AãæŒããŠUnicodeãéžæãããšãIDAã®æ€çŽ¢ãªãã·ã§ã³ãå€æŽã§ããŸãã

æ°ããè¡ã®åæã«ãããæªæã®ããããã°ã©ã ã®ããå€ãã®æ©èœãæããã«ãªããŸããã

é¢çœãã
Wiresharkãèµ·åããããšããè©Šã¿ãããã°ã©ã ã«ãã£ãŠãããã¯ãããããšãèãããšãããã°ã©ã ã®åŒ·å¶çµäºã®åå ãšãªãæ©èœãèŠã€ããŠãããããé©çšããå¿ èŠããããŸãã ã©ããã£ãŠããã®ïŒ api TerminateProcessïŒïŒåŒã³åºããæ¢ããŸãããã
IDAã®äœ¿çšã¯ããã»ã©é£ãããããŸããã ã€ã³ããŒãã»ã¯ã·ã§ã³ã«ã¯ãTerminateProcessãžã®ãªã³ã¯ããããŸãã

CreateToolhelp32SnapshotãåŒã³åºããŠããã»ã¹ã®ååã調ã¹ãäœããã®æ¡ä»¶ãæºããå Žåã«ããã»ã¹ãçµäºãããµã€ã¯ã«ã®ããã«èŠããŸãã å ã»ã©èŠãããã»ã¹åã®ãªã¹ããããã§äœ¿çšãããŠããããã§ãã
ããã§ãç§ãã¡ã¯äœãã§ããŸããïŒ TerminateProcessãåŒã³åºã代ããã«ããã°ã©ã ããžãã¯ãå€æŽããããšãã§ããŸãããäœãèµ·ãããŸããã XrefïŒeXternal REFerencesïŒã§ã«ãŒãã³ããã§ãã¯ãããšãé¢æ°ãã«ãŒãã³0x00401D2AããåŒã³åºãããŠããããšãããããŸãã ããã«ã¯ãããã»ã¹ãã¹ãã£ã³ããŠçµäºãããµãã«ãŒãã³ãžã®æ¡ä»¶ä»ãé·ç§»ãè¡ãjnzåœä»€ãå«ãŸããŠããŸãã ãã®ãµãã«ãŒãã³ãåŒã³åºãããªãããã«ããã°ã©ã ã«ããããé©çšã§ããå Žåã¯ããã©ãã¯ãªã¹ãããä»»æã®ãŠãŒãã£ãªãã£ãå®è¡ã§ããŸãã

è¢ããŸãããŸãããã ç§ã¯Immunityã䜿çšããŠããããé©çšããããšã奜ã¿ãŸã-ããã¯éåžžã«ç°¡åã§ããããããç¥ã£ãŠããŸãã exeã§ãµãã«ãŒãã³ãæ¢ãããšããå§ããŸãããã æ¡ä»¶ä»ããžã£ã³ãåœä»€ã¯0x00401D4Eã«ãããŸãã é åå šäœãæããŸã-ãããã£ãŠã奜ãŸãããªãããã»ã¹ã®å®äºãçºçããã¢ãã¬ã¹0x00401D2Cã«ç§»åãã代ããã«ãããã«åå®è¡ã«é²ã¿ãŸãã

ããã°ã©ã ãåéããçŠæ¢ãããŠããããã°ã©ã ã®ãããããå®è¡ããããšããŸãã regeditãéå§ãããProcess Explorerã匷å¶çã«çµäºãããªããã°ããã¹ãŠãæ©èœããããã§ãã


æåŸã«ãWiresharkã䜿çšããŠãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã®è©³çŽ°ãªåæãè¡ããšãšãã«ãprocmonã䜿çšããŠãã¡ã€ã«ã·ã¹ãã ãšã¬ãžã¹ããªã®ã¢ã¯ãã£ããã£ãå®è¡ããProcess Explorerã§å®éã«åäœããããã°ã©ã ã§éã¶ããšãã§ããŸãã
Process Explorerã¯ãSYNãéä¿¡ãããããšã瀺ããŸã[5] ããŒã80ãžã®CïŒCãµãŒããŒïŒã¯ãããªãœãŒã¹ã»ã¯ã·ã§ã³ããã¢ãã¬ã¹ãååŸãããµãŒããŒïŒãžã®ãã±ããã

Wiresharkã¯ããå°ãæ å ±ãæäŸããŸãã ããã§ã¯ãHTTP CïŒCãµãŒããŒã«éä¿¡ãããSYNãã±ããã ãã§ãªããå¥åŠãªãã¡ã€ã³ã«é¢ããæ å ±ãååŸããããã®å€æ°ã®DNSã¯ãšãªã確èªã§ããŸãã 次ã¯ïŒ

ãµãŒããŒã¯åŒãç¶ã家ãããã¯ããŸãããç§ã¯ãããå¿ èŠãšããŸããã ãgolden_egg.exeãã®ãªãœãŒã¹ã»ã¯ã·ã§ã³ãå€æŽããŠèªåã®HTTPãµãŒããŒã«ã©ãããããã®æ©èœã調ã¹ãããšãã§ããŸãããããã¯ããªãé¢åã§ãã CïŒCãµãŒããŒã解åãããããã°ã©ã ããã®HTTP眲åããããŠãã®åäœã«ã€ããŠãç¥ã£ãŠããŸãã ã±ãŒã¹ã¯éããããŸããã ããã«æ°Žææ¥ã®0dayãæ¥ãŠè¡ããŸããã
ãã«ãŠã§ã¢ãããŠã³ããŒããããããããããããå Žåã¯ã ãã¡ãããå ¥æã§ããŸã ã ãã¹ã¯ãŒãã¯ãææãããŠããŸãã
ãã®å°ããªç 究ãããªãã®ã圹ã«ç«ãŠã°å¹žãã§ãã ããã²ã³ããããŸãïŒ
æçš¿è Joe Giron
ãªãªãžãã«èšäº
1. â 0dayïŒè±èªã®ãŒããã€ïŒã¯ãé²åŸ¡ã¡ã«ããºã ãŸãã¯è匱æ§ããŸã 解決ãããŠãããã解決ãããŠããªãæªæã®ããããã°ã©ã ãæãçšèªã§ãã
2. â IDA Pro DisassemblerïŒEngãInteractive DisAssemblerïŒ-ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«åºã䜿çšãããŠããã€ã³ã¿ã©ã¯ãã£ããªéã¢ã»ã³ãã©ã
3. â Microsoft Foundation ClassesïŒMFCïŒããã±ãŒãžã¯ãMicrosoftãéçºããC ++ã©ã€ãã©ãªã§ãã©ã€ãã©ãªã¯ã©ã¹ã®è±å¯ãªã»ããã䜿çšããŠMicrosoft Windowsçšã®GUIã¢ããªã±ãŒã·ã§ã³ã®éçºã容æã«ããããã«èšèšãããŠããŸãã
4. â UPXïŒeXecutablesçšUltimate PackerïŒ-ããã€ãã®ç°ãªããã©ãããã©ãŒã ãšãã¡ã€ã«åœ¢åŒããµããŒãããå®è¡å¯èœãã¡ã€ã«ããã«ãŒã
5. â SYN-æ¥ç¶ã確ç«ããããã«ã¯ã©ã€ã¢ã³ããããµãŒããŒã«éä¿¡ããããã±ããã