æåã®Potaoãµã³ãã«ã«ã¯ãæå·åãããGlobalPotaoæååãå«ãŸããŠããŸãã ã ESETãŠã€ã«ã¹å¯Ÿç補åã§ãæ€åºããããã®ä»ã®Potaoãµã³ãã«ã«ã¯ã Sapotaoããã³node69ãšããååãå«ãŸããŠããŸãã ãããã®åèªã¯ãPotaoã©ã€ãã©ãªDLLãã¡ã€ã«ã®ååãããã³å®è¡å¯èœãã¡ã€ã«å ã®PDBãã¹è¡ã§äœ¿çšãããŠããŸããã 以äžã¯ãPotaoãããã°ã·ã³ãã«ãå«ãPDBãã¡ã€ã«ãžã®ãã¹ãæã€æååã®äŸã§ãã
å³ 21.ãã«ãŠã§ã¢ãã¡ã€ã«ã®æ¬æã«ããPDBãã¡ã€ã«ãžã®ãã¹ã
å³ 22.ãã«ãŠã§ã¢ãã¡ã€ã«ã®æ¬æã«ããPDBãã¡ã€ã«ãžã®ãã¹ã
å³ 23.ãã«ãŠã§ã¢ãã¡ã€ã«ã®æ¬æã«ããPDBãã¡ã€ã«ãžã®ãã¹ã
å³ 24.ãã«ãŠã§ã¢ãã¡ã€ã«ã®æ¬æã«ããPDBãã¡ã€ã«ãžã®ãã¹ã
Potaoãã«ãŠã§ã¢ãã¡ããªã¯ããµã€ããŒç¯çœªè ããµã€ããŒã¹ãã€æŽ»åã«äœ¿çšããææããã³ã³ãã¥ãŒã¿ãŒããããŸããŸãªæ©å¯æ å ±ãæœåºãããªã¢ãŒãã®ãµã€ããŒç¯çœªè ãµãŒããŒã«éä¿¡ããããŒã«ã®å žåçãªäŸã§ãã
ä»ã®å€ãã®æªæã®ããããã°ã©ã ãšåæ§ã«ãPotaoã¯ãããããŒãšåŒã°ããç¹å¥ãªæªæã®ãããã¡ã€ã«ãä»ããŠã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŸãã PotaoãããããŒã®å¯èœãªé åžãã¯ãã«ã以äžã«å瀺ããŸãã
- ãããããŒãã¡ã€ã«ãžã®ãªã³ã¯ãå«ããã£ãã·ã³ã°ã¡ãŒã«ãšSMSã¡ãã»ãŒãžã ãããããŒå®è¡å¯èœãã¡ã€ã«ã¯ãWordãExcelãPDFãªã©ã®ããã¥ã¡ã³ãã®ã¢ã€ã³ã³ã䜿çšããŠãã¹ã¯ãããŸãã
- 以åã«äŸµå®³ããããªã ãŒããã«USBãã©ã€ãã䜿çšããææã
- TrueCryptæå·åãœãããŠã§ã¢ïŒWin32 / FakeTCïŒã®æªæã®ããå€æŽã䜿çšããé åžã
ãããããŒãã¿ãªã¯2段éã§å®è¡ãããŸãã æåã®æ®µéã§ãå®è¡å¯èœãªPEãã¡ã€ã«ãããèªäœããæœåºããäžæãã¡ã€ã«ïŒ tempïŒ ãå«ããã£ã¬ã¯ããªã«ãã³ãããŸãã ãŸããããšãããã¥ã¡ã³ããã¡ã€ã«ãçŸåšã®ãã£ã¬ã¯ããªã«ãã³ããããããéããŠOSã®ã¢ã¯ã·ã§ã³ããã¹ã¯ããæªæã®ããããã°ã©ã ãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããŸãã ãããããŒã«ãã£ãŠæœåºãããå®è¡å¯èœãã¡ã€ã«ã¯ã RtlDecompressBuffer APIé¢æ°ã䜿çšããŠããèªäœããDLLã©ã€ãã©ãªãŒãæœåºããŸãã ã©ã€ãã©ãªã¯æ¬¡ã®å Žæã«ãã©ãã·ã¥ãããŸãã
ïŒ APPDATAïŒ \ Microsoft \ïŒ LUIDïŒ .dll
ãã®åŸãã©ã€ãã©ãªã¯ããã»ã¹explorer.exeã«åã蟌ãŸããŸãã DLLãçŽæ¥ãã£ã¹ã¯ã«ãã©ãã·ã¥ããåã«ãæªæã®ããããã°ã©ã ã®å®è¡å¯èœãã¡ã€ã«ã¯ç¹å¥ãªã¢ã¯ã·ã§ã³ãå®è¡ããŸãã ãšã¯ã¹ããŒãããŒãã«ã®é¢é£èŠçŽ ã«ãããšã¯ã¹ããŒããããé¢æ°ã®ååã®1ã€ãLUIDã®ç¹å¥ãªå€ã«ä¿®æ£ããŸãã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ããã®æäœãå®è¡ããæå®ãããé¢æ°åãã_85fcãã«å€æŽããæªæã®ããããã°ã©ã ã®æ©èœã³ãŒãã瀺ããŠããŸãã ãã®çµæããã£ã¹ã¯ã«ãã©ãã·ã¥ãããåDLLã¯ç°ãªãããã·ã¥ãæã¡ãŸãã
å³25. PotaoãããããŒé¢æ°ãã¡ã¢ãªå ã®DLLãšã¯ã¹ããŒãã®ååã®å€æŽã«ç¹åããŠããŸãã
å³26.ãšã¯ã¹ããŒããããã©ã€ãã©ãªé¢æ°ã®ååã®å€æŽã®çµæã
ãã®DLLãå®è¡ããããã«ãPotaoã¯rundll32.exeãšåŒã°ããæšæºã®Windowsã¢ããªã±ãŒã·ã§ã³ã䜿çšããã·ã¹ãã å ã§ã®çåã確ä¿ããããã«ãïŒ LUIDïŒ ãã©ã¡ãŒã¿ãŒãæã€æ¬¡ã®ã¬ãžã¹ããªããŒã䜿çšããŸãã
HKCU \ãœãããŠã§ã¢\ Microsoft \ Windows \ CurrentVersion \ Run
ãã§ã«ç€ºããããã«ãPotaoã¯ã¢ãžã¥ã©ãŒã¢ãŒããã¯ãã£ã䜿çšããè¿œå ã®ãã©ã°ã€ã³ã䜿çšããŠãã®æ©èœãæ¡åŒµã§ããŸãã
å³ 27. Win32 / Potaoã®äžè¬çãªã¢ãŒããã¯ãã£ã
æªæã®ããããã°ã©ã ãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããéããããããŒã¯äžèšã®DLLãexplorer.exeããã»ã¹ã«æ¿å ¥ããŸãã ã·ã¹ãã å ã®ç¹å¥ãªãã¥ãŒããã¯ã¹ã®ååšã確èªããåŸãæªæã®ããã³ãŒãã¯ãWebãã©ãŠã¶ãŒãSkypeãuTorrentãªã©ã®äœæ¥ããã»ã¹ã®ã¢ãã¬ã¹ç©ºéã«ãåã蟌ãŸããŸãã explorer.exeã³ã³ããã¹ãã«åã蟌ãŸããæªæã®ããã³ãŒãã®äžéšã¯ãPotaoãã©ã°ã€ã³ã®ããŠã³ããŒããšå®è¡ãæ åœãããããã¯ãŒã¯æ¥ç¶ã®ããããã°ã©ã ã«åã蟌ãŸããã³ãŒãã¯ãCïŒCãµãŒããŒãšã®å¯Ÿè©±ãæ åœããŸãã ãããã®éšåéã®çžäºäœçšã¯ãååä»ããã€ããä»ããŠè¡ãããŸãã
ãã©ã°ã€ã³ã®æŠèŠ
äžèšã®ã¡ã€ã³DLLã¯ãæªæã®ããããã°ã©ã ã®æãåºæ¬çãªæ©èœã®ã¿ãå®è¡ããŸãã ã¹ãã€æŽ»åã®æ©èœãå®è£ ãã責任ã¯ãããŠã³ããŒãå¯èœãªãã©ã°ã€ã³ïŒã¢ãžã¥ãŒã«ïŒã«ãããŸãã æªæã®ããã³ãŒãã¯ãã·ã¹ãã ã§èµ·åããããã³ã«ãã©ã°ã€ã³ãããŒãããŸããããã¯ããã©ã°ã€ã³ãããŒããã©ã€ãã«ä¿åãããŠããªãããšã瀺ããŠããŸãã ãã©ã°ã€ã³ã«ã¯ãæåã®Fullãš2çªç®ã®Lightã®2çš®é¡ããããŸãã æåã®ã¿ã€ãã®ãã©ã°ã€ã³ã®å®è¡å¯èœãã¡ã€ã«ã¯Plugãšããååã®é¢æ°ããšã¯ã¹ããŒããã2çªç®ã®ã¿ã€ãã®ãã©ã°ã€ã³ã®ãã¡ã€ã«ã¯ã¹ãã£ã³é¢æ°ããšã¯ã¹ããŒãããŸãã 2ã€ã®ã¿ã€ãã®éãã¯ããããããå¿ èŠãªæ å ±ãåéããŠã¯ã©ã€ã¢ã³ãã«è¿ãæ¹æ³ã§ãã å®å šãªãã©ã°ã€ã³ã¯ãã·ã¹ãã ãåèµ·åãããŸã§ç¶ç¶çã«æ©èœããŸã; Lightãã©ã°ã€ã³ã¯ãå¿ èŠãªæ å ±ãå«ããããã¡ãŒãè¿ãããçŽåŸã«äœæ¥ãçµäºããŸãã
Potaoããããããã®ã¢ã¯ãã£ããã£ã远跡ããéçšã§ãããžã¿ã«çœ²åã§çœ²åããããã©ã°ã€ã³ãçºèŠããŸããïŒå³28ïŒã
å³ 28.äžéšã®Potaoãã©ã°ã€ã³ã眲åãããããžã¿ã«èšŒææžã«é¢ããæ å ±ã
蚌ææžãçºè¡ãããçµç¹ãGrand Torgãã®ååã¯ããBig Marketããšè§£éã§ããŸãã ãããããã®ååã®çµç¹ã¯èŠã€ãããŸããã§ããã 蚌ææžã®ã·ãªã¢ã«çªå·ã¯0453B96EB039AFD6C9988C8CB698E7C9ã§ããããã®å€±å¹ã¯æ¬¡ã®æéã«å®è¡ãããŸããïŒAug 19 00:00:00 2014 GMTã 倱å¹æ¥ã¯å®éã«çºè¡æ¥ãšäžèŽããããããã®èšŒææžã«ãã£ãŠäœæããããã¹ãŠã®ããžã¿ã«çœ²åã¯ç¡å¹ã§ããã ãã®äºå®ã¯ã蚌ææžãæªæã®ããç®çã®ããã«æåããæªæã®ãããŠãŒã¶ãŒã«ãã£ãŠäœ¿çšãããã©ã®ãã³ããŒãããçãŸããªãã£ããšããçµè«ã«å°ããŸãã
äžã®è¡šã¯ãç§ãã¡ã«ç¥ãããŠããPotaoãã©ã°ã€ã³ã®ãªã¹ãã§ãã
管çCïŒCãµãŒããŒãšã®çžäºäœçš
åæããWin32 / Potaoãµã³ãã«ã«ã¯ãCïŒCãµãŒããŒã³ã³ãããŒã«çšã®ããã€ãã®ç°ãªãIPã¢ãã¬ã¹ãå«ãŸããŠããŸããã ã¢ãã¬ã¹ã¯ãæªæã®ããããã°ã©ã ã®æ¬äœã§æå·åãããŸããã 以äžã¯ãããã®ã¢ãã¬ã¹ã®ãªã¹ãã§ãã
87.106.44.200:8080
62.76.42.14-00-0043
62.76.42.14:8080
94.242.199.78-00-0043
178.239.60.96:8080
84.234.71.215:8080
67.103.159.141:8080
62.76.184.245:80
62.76.184.245-00-0043
62.76.184.245:8080
ãã«ãŠã§ã¢ã¯ãããã®ã¢ãã¬ã¹ã®1ã€ãéžæããæ¥ç¶ã確ç«ããããšããŸãã 䜿çšãããŠããããŒãã®ãªã¹ããããããããã«ãHTTPãšHTTPSã®äž¡æ¹ã§çžäºäœçšãå®è¡ã§ããŸãã ãµãŒããŒãšã®å¯Ÿè©±ã«ã¯ã2段éã§åŒ·åãªæå·åã¢ã«ãŽãªãºã ã䜿çšãããŸãã æåã®æ®µéã§ã¯ããŒã亀æããã2çªç®ã®æ®µéã§ã¯çŽæ¥ããŒã¿äº€æãè¡ãããŸãã å³ 29ãã®ããã»ã¹ã¯ããæ確ã«ç€ºãããŠããŸãã
å³ 29.ããããšCïŒCãµãŒããŒéã®ããŒäº€æã®ããã»ã¹ãããã³ãããã®éã®ãããã¯ãŒã¯çžäºäœçšã
ããããæåã«CïŒCãµãŒããŒãšå¯Ÿè©±ãããšãïŒ1ïŒãHTTPãããã³ã«ã®POST圢åŒã§ãªã¯ãšã¹ããéä¿¡ããŸãã ãããã«ãã£ãŠéä¿¡ãããããŒã¿ã¯ãXML-RPCãããã³ã«ã䜿çšããŠã«ãã»ã«åãããŸãã èå³æ·±ãã®ã¯ãåæãããã©ãã£ãã¯ã«ã¯ã10a7d030-1a61-11e3-beea-001c42e2a08bã«çããmethodNameãã©ã¡ãŒã¿ãŒãåžžã«ååšããŠããããšã§ãã
å³ 30.ãããããµãŒããŒã«éä¿¡ããHTTPãããã³ã«ã®æåã®POSTèŠæ±ã
äžèšã®ãªã¯ãšã¹ããåä¿¡ãããšãCïŒCãµãŒããŒã¯RSA-2048ïŒ2ïŒå ¬éããŒãçæããå¥ã®RSA-2048ïŒ3ïŒãã©ã€ããŒãéçããŒã§çœ²åããŸãã
å³31.æåã®ãããèŠæ±ã«å¯ŸããCïŒCãµãŒããŒã®å¿çãããã¯ãbase64ã䜿çšããŠãšã³ã³ãŒããããç§å¯éµã§çœ²åãããRSA-2048å ¬ééµã§ãã
ãããã¯ããµãŒããŒã«ãã£ãŠçœ²åãããRSA-2048å ¬éããŒãåãåããšãæªæã®ããããã°ã©ã ãã¡ã€ã«ã«ãã察å¿ããéçå ¬éããŒã䜿çšããŠçœ²åïŒçœ²åïŒããã§ãã¯ããŸãïŒ5ïŒã æ€èšŒãæåããå ŽåïŒããŒçœ²åãæå¹ãªå ŽåïŒãåä¿¡ããããŒïŒ6ïŒã¯æ¬¡ã®ã¹ãããã§ããŒã¿ãæå·åããããã«äœ¿çšãããŸãã ãã«ãŠã§ã¢ã®æ¬äœã«çµã¿èŸŒãŸããå ¬éRSA-2048ããŒã«ã¯ã次ã®åœ¢åŒããããŸãã
第2段éã§ããããã¯AES-256察称ããŒãçæããŸãïŒ7ïŒã ããã¯ãããã ã»ãã·ã§ã³ããŒã¯ãåä¿¡ããRSA-2048å ¬éããŒïŒ8ïŒã䜿çšããŠæå·åãããCïŒCãµãŒããŒïŒ9ïŒã«éä¿¡ãããŸãã
ãµãŒããŒãããããã«éä¿¡ãããããŒã¿ã¯ãAES-256ããŒã䜿çšããŠæå·åããïŒ12ïŒïŒ13ïŒããµãŒããŒåŽã§è§£èªãããŸãïŒ14ïŒã
æªæã®ããã³ãŒãã§ã®äžèšã®æå·åã¢ã«ãŽãªãºã ã®å®è£ ã®æè¡çãªè©³çŽ°ã¯å¥ãšããŠãããããšãµãŒããŒéã®çžäºäœçšã®ãããã³ã«ã®åœ¢åŒãèããŠã¿ãŸãããã ãããã¯æå·åããã圢åŒã§ãµãŒããŒã«ãªã¯ãšã¹ããéä¿¡ããŸãããªã¯ãšã¹ãã®åœ¢åŒã¯ä»¥äžã®ãšããã§ãã
id = 4699807581825067201maptïŒcode = 0ïŒsdata = verïŒ5.1.2600 lvïŒ2.8.0002 compïŒCOMPUTER admïŒ1 xïŒ0 pïŒfirefox.exeïŒmd5 =ïŒdlen = 0
ãªã¯ãšã¹ãã«ã¯ãã³ã³ãã¥ãŒã¿ãŒã®èå¥åïŒIDïŒããã£ã³ããŒã³IDãOSããŒãžã§ã³ããã«ãŠã§ã¢ããŒãžã§ã³ãã³ã³ãã¥ãŒã¿ãŒåãçŸåšã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãæš©éãOSããããµã€ãºïŒ32ãŸãã¯64ãããïŒãããã³çŸåšã®ããã»ã¹ã®ååãå«ãŸããŠããããšãããããŸãã
ãµãŒããŒã¯ã次ã®åœ¢åŒã®ããŒã¿ã§å¿çããŸãã
ã³ãŒã=ïŒ CMDïŒ ïŒããŒã¿=ïŒ PAYLOAD_BASE64_ENCODEDïŒ ïŒdlen =ïŒ PAYLOAD_LENGTHïŒ ïŒmd5 =ïŒ MD5ïŒ
codeãã©ã¡ãŒã¿ãŒã®å€ã¯ãããããå®è¡ããã³ãã³ãã®ã¿ã€ããè¡šããŸãã ããããå®è¡ã§ããã³ãã³ãã®ãªã¹ãã以äžã®è¡šã«ç€ºããŸãã
ãªã ãŒããã«USBã¡ãã£ã¢ãä»ããé åž
ããã€ãã®æªæã®ãããã£ã³ããŒã³ã§ãæ»æè ã¯å¥ã®Potaoé åžãã¯ãã«ã䜿çšãããªã ãŒããã«USBãã©ã€ãã®ææã䜿çšããŸããã Potaoã¯ãä»ã®ã¯ãŒã ïŒèªåå®è¡ã¯ãŒã ïŒãšã¯ç°ãªãæ¹æ³ã䜿çšããŠããªã ãŒããã«ã¡ãã£ã¢ã«ææããŸãã ãã©ã€ãã®ãã¡ã€ã«ã·ã¹ãã ã®ã«ãŒãã«autorun.infãã¡ã€ã«ãäœæãã代ããã«ããã®å®è¡å¯èœãã¡ã€ã«ããã®åŸã®èµ·åã§ã¡ãã£ã¢ã«ä¿åããç°¡åã§å¹ççãªæ¹æ³ã䜿çšããŸãã ãªã ãŒããã«ã¡ãã£ã¢ãžã®ææãæ åœãããã«ãŠã§ã¢ã³ãŒãã¯ããããããŒãã·ã¹ãã ã«æ¥ç¶ãããŠãããã¹ãŠã®ãã©ã€ãã®ã«ãŒããã£ã¬ã¯ããªã«ã³ããŒããŸãã ãã®å Žåããªã ãŒããã«ã¡ãã£ã¢ã®ã©ãã«ããããããŒãã¡ã€ã«ã®ååãšããŠéžæããããã®ã¡ãã£ã¢ã®ã·ã¹ãã ã¢ã€ã³ã³ãã¢ã€ã³ã³ãšããŠéžæãããŸãã ãã®ã¡ãã£ã¢ã®ã«ãŒããã£ã¬ã¯ããªã«ããæ®ãã®ãã£ã¬ã¯ããªãšãã¡ã€ã«ã«ã¯ãé衚瀺å±æ§ãšã·ã¹ãã å±æ§ãå²ãåœãŠãããŸãã ãŠãŒã¶ãŒã¯ããã£ã¹ã¯ãéãããã«ã¢ã€ã³ã³ãããäžåºŠã¯ãªãã¯ããå¿ èŠããããšããå°è±¡ãåããŠããŸãã ãã®ã¢ã¯ã·ã§ã³ã®çµæã圌ã¯å®è¡ã®ããã«ãããããŒãèµ·åããŸãã
å³ 32.ãªã ãŒããã«ã¡ãã£ã¢ã®ã«ãŒããã£ã¬ã¯ããªã«ãããããããŒã¢ã€ã³ã³ãšãã®ãã¡ã€ã«åã¯ããªã ãŒããã«ã¡ãã£ã¢ãšåãããŒã¿ãšäžèŽããŸãã
æããã«ãç»é²æžã¿ã®ãã¡ã€ã«ã¿ã€ãã®æ¡åŒµåãé衚瀺ã«ã§ããWindowsã®ããã©ã«ãèšå®ã§ã¯ããŠãŒã¶ãŒã«ã¯ãããããŒå®è¡å¯èœãã¡ã€ã«ã®æ¡åŒµåã¯è¡šç€ºãããŸããã ãŸããå±æ§ãå€æŽãããŠããããããã£ã¹ã¯ã®ã«ãŒãã«ããä»ã®ãã¡ã€ã«ã衚瀺ãããŸããã ãã®ãã«ãŠã§ã¢ã®ããªãã¯ã¯ãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãææ³ã«èµ·å ããå¯èœæ§ããããŸãã
æªæã®ããããã°ã©ã ã«ã¯ãå®è¡å¯èœãã¡ã€ã«ã®åæãè€éã«ããç¹å¥ãªæ¹æ³ãå«ãŸããŠããŸãã ãããã®ã¡ãœããã®1ã€ã¯ãAPIé¢æ°åã®ããã·ã¥ã䜿çšããŠåŒã³åºãããšã§ãã
å³ 33.ååã®ããã·ã¥å€ã䜿çšããŠWinAPIé¢æ°ã®ã¢ãã¬ã¹ãååŸããŸãã
ãã®Windows APIé¢æ°ã®ã¢ãã¬ã¹ãååŸããæ¹æ³ã¯ãå€ãã®æªæã®ããããã°ã©ã ã§äœ¿çšãããŠããŸããæªæã®ããããã°ã©ã ã®äœæè ãæªæã®ããããã°ã©ã ã®æ¬äœã«é¢æ°ã®ååãæ®ããªãããã«ãããããã¢ã³ããŠã€ã«ã¹äŒæ¥ã®ã¢ããªã¹ãã®åæããã»ã¹ãå€§å¹ ã«è€éã«ãªããŸãã APIé¢æ°ã®ååã®ããã·ã¥å€ãèšç®ããããã«ãæªæã®ããããã°ã©ã ã¯MurmurHash2ã¢ã«ãŽãªãºã ã䜿çšããŸãã
èè ã¯ãPotaoã®æ¬äœã«ååšããã¯ãã®æååãæå·åããã¡ã«ããºã ã䜿çšããŸããã å³ å³ïŒïŒã¯ãã¹ããªã³ã°ã解èªããæ©èœã瀺ãã
å³ 34.æååããã³ãŒãããæ©èœã
æååã¯ãXORæäœãš4ãã€ãããŒã䜿çšããŠæå·åãããŸãã ããŒã¯æªæã®ãããã¡ã€ã«ããšã«ç°ãªãå ŽåããããŸãã
Win32 / FakeTC-TrueCryptæªæã®ããåæ
æ»æè ããµã€ããŒãã£ã³ããŒã³ã«æ£åœãªTrueCryptãœãããŠã§ã¢ã®æªæã®ããå€æŽã䜿çšããããšã¯æ¢ã«è¿°ã¹ãŸããã ãã®å€æŽã¯ãŠã€ã«ã¹å¯Ÿç補åã«ãã£ãŠWin32 / FakeTCãšããŠæ€åºããããµã€ããŒç¯çœªè ã被害è ã®æå·åããããã©ã€ããããã¡ã€ã«ãæœåºããããã«äœ¿çšãããŸãã FakeTCã¯ãå Žåã«ãã£ãŠã¯ææããã³ã³ãã¥ãŒã¿ãŒã«åŸè ã®ãããããŒãããŠã³ããŒãã§ãããšããç¹ã§ã®ã¿ãPotaoã«é¢é£ä»ããããŠããŸãã
å³ 35.ããŸããŸãªåœã®Win32 / FakeTCæ€åºçµ±èšã
å³ å³36ã¯ãTrueCryptã®æªæã®ããããŒãžã§ã³ã®ã€ã³ã¿ãŒãã§ãŒã¹ã瀺ããŠããŸãã
å³ 36. TrueCryptã®æªæã®ããããŒãžã§ã³ã®ã€ã³ã¿ãŒãã§ãŒã¹ã
æªæã®ããã³ãŒãã¯ãä»ã®æ£åœãªTrueCrypté¢æ°ãšã¯å¥ã®ã¹ã¬ããã§å®è¡ãããŸãã ã¹ããªãŒã ã¯ã ããŠã³ãæ©èœã®æåŸã«äœæãããã·ã¹ãã ã«ããŠã³ããããæå·åããããã©ã€ãäžã®ãã¡ã€ã«ã®ãªã¹ãã®ååŸã«ç¹åããŠããŸãã ç¹å®ã®æ¡ä»¶ãæºãããããšã管çCïŒCãµãŒããŒã«æ¥ç¶ããå®è¡ã®ããã®ã³ãã³ããæåŸ ããŸãã æªæã®ããã³ãŒãã¯ãæªæã®ãããŠãŒã¶ãŒã«ãã£ãŠãããžã¿ã«çœ²åãããã«ãŒãã«ã¢ãŒããã©ã€ããŒãå«ãŸãããŠãŒã¶ãŒã¢ãŒãã®TrueCryptå®è¡å¯èœãã¡ã€ã«ã«ã®ã¿è¿œå ããããã®ãŸãŸæ®ãããŸããã
ããããCïŒCãµãŒããŒã«æ¥ç¶ããã«ã¯ã次ã®æ¡ä»¶ãæºãããŠããå¿ èŠããããŸãã
- æå·åããããã£ã¹ã¯äžã®ãã¡ã€ã«ã®æ°ã¯10ãè¶ ããå¿ èŠããããŸãã
- æå·åããããã©ã€ãã¯4å以äžããŠã³ãããå¿ èŠããããŸãã
ãµããŒããããŠããFakeTCã³ãã³ãã®ãªã¹ãã以äžã®è¡šã«ç€ºããŸãã
FakeTCã§ãµããŒããããŠããã³ãã³ãã®ãªã¹ããããããããã«ããµã€ããŒç¯çœªè ã¯ã¹ãã€ãŠã§ã¢ãšããŠäœ¿çšããè¿œå ã®ãã©ã°ã€ã³ã䜿çšããŠæ¡åŒµã§ããŸãã æ»æè ã¯ç¹å¥ãªã¡ã«ããºã ã䜿çšããŠãFakeTCãpr玢奜ããªç®ããé ããéžæããããŠãŒã¶ãŒã®ã¿ã«Webãµã€ãã§é åžããŸããã ããã«ãããæ»æè ã¯é·ãéæ°ä»ãããªããŸãŸã§ããã
ãããã«
äžèšã§ã¯ãWin32 / PotaoãWin32 / FakeTCãªã©ã®ESETãŠã€ã«ã¹å¯Ÿç補åã«ãã£ãŠæ€åºããããã«ãŠã§ã¢ã®åæãæ瀺ãããµã€ããŒç¯çœªè ã®ããŸããŸãªãµã€ããŒãã£ã³ããŒã³ã詳现ã«èª¿æ»ããŸããã Win32 / Potaoãã«ãŠã§ã¢ã¯ãµã€ããŒã¹ãã€ããŒã«ã®äŸã§ãããããã䜿çšãããµã€ããŒæ»æã¯APTã«åé¡ã§ããããšã瀺ããŸããããåæã«ãPotaoèªäœã¯é«åºŠãªé«åºŠãªãã«ãŠã§ã¢ã«èµ·å ãããã®ã§ã¯ãããŸããã
ãµã€ããŒæ»æã«ããããã¿ãªã®äœ¿çšã®èåŸã«ãããµã€ããŒç¯çœªè ã¯ããšã¯ã¹ããã€ãã®ä»£ããã«æŽç·ŽããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãã¯ããã¯ã䜿çšããããšã®æå¹æ§ãå®èšŒããŠããŸãã ãã®ãããªææ ®æ·±ãããªãã¯ã«ã¯ãæªæã®ããããã°ã©ã ãã¡ã€ã«ãžã®ãªã³ã¯ãå«ãç¹å¥ãªSMSã¡ãã»ãŒãžã®äœ¿çšãããã³ãªã ãŒããã«ã¡ãã£ã¢ã«ææããç¹å¥ãªããªãã¯ãå«ãŸããŸãã ãã®ãµã€ããŒãã£ã³ããŒã³ã®æãèå³æ·±ãæ©èœã®1ã€ã¯ãæ£åœãªTrueCryptæå·åãœãããŠã§ã¢ã®æªæã®ããããŒãžã§ã³ããµã€ããŒç¯çœªè ã䜿çšããããšã§ãã æªæã®ããããã°ã©ã èªäœã¯truecryptrussia.ru Webãµã€ãã«æçš¿ãããŠããããã¹ãŠã®ãŠãŒã¶ãŒãåä¿¡ã§ããããã§ã¯ãããŸããã ããã«ããã®ãµã€ãèªäœããã«ãŠã§ã¢ã®ç®¡çCïŒCãµãŒããŒãšããŠæ©èœããŸããã
äžèšã®äºå®ã¯ããã¿ãªã®ãµã€ããŒãã£ã³ããŒã³ããçŽç²ã«æåæ§ããšããŠç¹åŸŽä»ããŠããŸãã é¢å¿ã®ããåé¡ã¯æªè§£æ±ºã®ãŸãŸã§ããã€ãŸãããŠã¯ã©ã€ãã®è»ãšæ¿åºã®éšéã®åŸæ¥å¡ãé信瀟ãããã³MMMéèãã©ãããã®åå è ã«å¯ŸããŠåæ§ã®ãµã€ããŒã¹ãã€æŽ»åãè¡ãããšã«èå³ãæã£ãŠãã人ã§ãã åŸè ã¯ãŠã¯ã©ã€ããšãã·ã¢ã®äž¡æ¹ã§äººæ°ããããŸãã 確åºãã蚌æ ããªããã°ããã®è³ªåã«å¯Ÿããçãã®æ€çŽ¢ãæšæž¬ããããªãã®ã§ããã®è³ªåã¯æªè§£æ±ºã®ãŸãŸã§ãã
以äžã¯ãPotaoãšBlackEnergyã®æ¯èŒä»æ§ã§ãã