
çããããã¡ã€ã«ãããã«åæãããšããã®ãã¡ã€ã«ã¯æªæã®ãããã®ã§ãããã¢ããããŒããŒã§è匱æ§ãåŒãèµ·ããããšãããããŸããïŒ KsoftäŒç€Ÿã 以äžã¯ããšã¯ã¹ããã€ãã®è©³çŽ°ãšãã®ãã€ããŒãã®ç°¡åãªèª¬æã§ãã
ãšã¯ã¹ããã€ãèªäœãã€ãŸããçºèŠãããç¹å®ã®ãœãããŠã§ã¢çšã«ç¹å¥ã«æ§æãããæ§æãã¡ã€ã«ã¯ããã®äœæ¥ã«ãããã¡ãŒãªãŒããŒãããŒïŒ BufferOv ïŒè匱æ§ã䜿çšããŸãã ã¢ããããŒããŒïŒ FTPãããã³ã«ã§åäœããããã«èšèšãããŠããŸãã ãªã¢ãŒãFTPãã¹ãã®ã¢ãã¬ã¹ããŠãŒã¶ãŒåãªã©ã®èšå®ã¯ãåè¿°ã®æ§æãã¡ã€ã«ã«uploadpref.datãšããååã§ä¿åãããŸãã
ãã®ãšã¯ã¹ããã€ãã®PoCã³ãŒãã¯2014幎3æã«å ¬éãããŸããã
ã¢ããããŒããŒïŒããŒã«èšå®ãã¡ã€ã« è¡ã®ã»ããã§æ§æãããŸããããã«ã¯ããã¡ã€ã«ãã¢ããããŒãïŒã¢ããããŒãïŒããããã®ã¿ãŒã²ãããµãŒããŒãã¹ãã®ãŠãŒã¶ãŒåãšååãå«ãè¡ãå«ãŸããŸãã ãã¡ã€ã«ããŒã¿ãšãã®åŸã®åæãåŠçããããã«ãã¢ããªã±ãŒã·ã§ã³ã¯std :: ifstreamãšããæšæºC ++å ¥åã¹ããªãŒã ã䜿çšããŸãã ãã¡ã€ã«ããè¡ãèªã¿åããšããã¢ããªã±ãŒã·ã§ã³ã¯C ++é¢æ°in_stream.getïŒbufferãsizeofïŒbufferïŒã '\ n'ïŒã䜿çšããŠãµã€ãºãæ£ãããã§ãã¯ããŸãã ãã ããæå·åããããã¹ã¯ãŒãã§ãã¡ã€ã«ã®æåŸã®ãã£ãŒã«ããåŠçããã¢ããªã±ãŒã·ã§ã³ã³ãŒãã¯ã in_stream >>ãããã¡ã³ãŒãã䜿çšãããããã¡é åã¯ã¹ã¿ãã¯ã«é 眮ãããŸãã ã¢ããªã±ãŒã·ã§ã³ãin_stream.widthïŒ...ïŒé¢æ°ãåŒã³åºããªãå Žåã in_stream >> bufferãåŒã³åºããšããã¡ã€ã«ã®çµãããŸãã¯ç©ºçœèšå·ã«éãããŸã§ã¹ã¿ãã¯äžã®ãââããã¡ãŒãããã¡ãŒããã£ã±ãã«ãªããŸãã

å³ ãã®è匱æ§ã¯ã in_stream >> encrypted_paââsswordã®åŒã³åºãã«ååšããŸããããã«ããããšã¯ã¹ããã€ããã¹ã¿ãã¯äžã®ãââããã¡ãŒããªãŒããŒãããŒãããå¿ èŠãªã³ãŒããå®è¡ããããšãã§ããŸãã
ESETã®å°é家ã¯ããã®ãœãããŠã§ã¢ã®éçºè ã«è¿ éã«é£çµ¡ããèŠã€ãã£ãè匱æ§ãéç¥ããŸããã 24æé以å ã«ãKsoftã®å°é家ãè匱æ§ãä¿®æ£ããUploaderã®æ°ããããŒãžã§ã³ããªãªãŒã¹ããŸããïŒ v 3.6ã
åæããæªæã®ããuploadpref.datãã¡ã€ã«ã«ãããããã°ã©ã ã¯å¿ èŠãªéã®ããŒã¿ãã¹ã¿ãã¯ã«ã³ããŒãããããã¡ãŒããªãŒããŒãããŒãããŸãããããã¡ãŒã®ãµã€ãºã¯80ãã€ãã«åºå®ãããŠããŸãã ãããã¡å€æ°ã®åã«é 眮ãããããŒã¿ãäžæžãããçµæããšã¯ã¹ããã€ãã¯SEHïŒæ§é åäŸå€ãã³ãã©ïŒãã¬ãŒã ã«æå·ãäžããã·ã§ã«ã³ãŒããšãããžã®ãã€ã³ã¿ããã¬ãŒã ã«é 眮ããŸãã ãªãŒããŒãããŒãããããã¡ãžã®ããŒã¿ã®ã³ããŒã¯ãã¹ã¿ãã¯ã®æäžéšã«å°éããç¡å¹ãªã¡ã¢ãªã¢ãã¬ã¹ã«ãã£ãŠã¢ã¯ã»ã¹ãããïŒã¢ã¯ã»ã¹éåïŒããšãéç¥ããäŸå€ïŒäŸå€ïŒã«ãã£ãŠåæ¢ãããŸãã äŸå€ã®çµæãšããŠãWindowsã¯SEHãã¬ãŒã ããã®ãã€ã³ã¿ãŒã§é¢æ°ãåŒã³åºããŸãããSEHãã¬ãŒã ã¯æ¢ã«ãšã¯ã¹ããã€ãã«ãã£ãŠäžæžããããŠããŸãã ãã®æ°ããã¢ãã¬ã¹ã¯ãUploaderã¢ãã¬ã¹ç©ºéããã®ã³ãŒããå«ãã¬ãžã§ãããæããŸãïŒ..ã¬ãžã§ããã¯ãåœä»€ãããecxã®ã»ããã§ãã ãããecx; ret ã ãããã®åœä»€ã®å®è¡åŸãå®è¡ãããŒã¯ãæ¢ã«ã¹ã¿ãã¯äžã«ãããšã¯ã¹ããã€ãã®æåã®ã·ã§ã«ã³ãŒãã«è»¢éãããŸãã

å³ ã¹ã¿ãã¯äžã®ã¡ã¢ãªãžã®ã¢ã¯ã»ã¹ã«éåããå Žåã«äŸå€ãããªã¬ãŒãããç¶æ³ããããã¬ãŒãã衚瀺ããŸãã ã³ãã³ããŠã£ã³ããŠã§ãå¶åŸ¡ãã·ã§ã«ã³ãŒãã«è»¢éãããã¬ãžã§ããã®æ瀺ã確èªã§ããŸãã
SEHãã³ãã©ãŒãæžãæããæ¹æ³ã¯ãã§ã«ããªãå€ããCorelanããŒã ãWebãµã€ãã§è©³çŽ°ã«èª¬æããŠããŸã ã Windows Vista SP1 +ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ã¯ãæ§é åäŸå€åŠçäžæžãä¿è·ïŒSEHOPïŒãšåŒã°ããç¹å¥ãªæ©èœãå«ãŸããŠããŸããããã¯ãOSã¬ãã«ã§ã®SEHãã³ãã©ãŒã®äžæ£ãªäžæžãããã¢ããªã±ãŒã·ã§ã³ãä¿è·ããŸãã ãã®æ©èœã¯ãWindowsã®ã¯ã©ã€ã¢ã³ããšãã£ã·ã§ã³ã§ã¯ããã©ã«ãã§ç¡å¹ã«ãªãããµãŒããŒãšãã£ã·ã§ã³ã§ã¯ããã©ã«ãã§æå¹ã«ãªããŸãã Windowsã®ã¯ã©ã€ã¢ã³ããšãã£ã·ã§ã³ã§ãã®æ©èœãæå¹ã«ããã«ã¯ãEMETããŒã«ãŸãã¯ãã®æé ã䜿çšããŸãã ããã«ãSEHOPã¡ã«ããºã ã®ãµããŒãã¯ã/ SAFESEHãªãã·ã§ã³ïŒUploaderã§ã¯äœ¿çšäžå¯ïŒïŒã䜿çšããŠã³ã³ãã€ã«ããå¿ èŠãããã¢ããªã±ãŒã·ã§ã³èªäœã«ãã£ãŠæäŸãããå¿ èŠããããŸãã
ãã®ãšã¯ã¹ããã€ãã¯ãäžèšã§åŒçšãããªã³ã¯ã§ããPoCã«åºã¥ããŠãããããã«é¡äŒŒãããããã³ãã³ãã®ã·ãŒã±ã³ã¹ãå«ãŸããŠããŸãã ããã; ãã¡ã€ã«ã®å é ã«æ»ããŸãã å ã®PoCã®å Žåããããã¯ããªãå€ããåèš178ããŒã ããããŸãã ã·ã§ã«ã³ãŒãããã®å®è¡ã¬ãã«ãªã©ããšã¯ã¹ããã€ãã®ä»ã®éšåã¯ãäœæè èªèº«ã«ãã£ãŠè¿œå ãããŸããã

å³ PoCã®uploadpref.datããããŒã

å³ ãšã¯ã¹ããã€ãããã®uploadpref.datã®ããããŒã
ãã€ããŒããèµ·åããåã«ããšã¯ã¹ããã€ãã¯ã³ãŒãã®ããã€ãã®æ®µéãå®äºããå¿ èŠããããŸãã
ãŒãã¹ããŒãžïŒã¹ããŒãž0ïŒã§ã¯ãã·ã§ã«ã³ãŒãã¯SEHãã³ãã©ãŒã®ã³ãŒãããå¶åŸ¡ãåãåããŸããSEHãã³ãã©ãŒã¯ãäžé£ã®åœä»€pop ecxãæã€ã¬ãžã§ãããæããŸãã ãããecx; ret ã æåã®ã·ã§ã«ã³ãŒãåœä»€ã¯ã次ã®ã¬ãã«ã®ã³ãŒãïŒ shell_code_1 ïŒã解åããŸãã 2ãã€ãã®åèªãã1ãã€ãã®å€ãèšç®ããåãã¡ã¢ãªäœçœ®ã«æžã蟌ã¿ãŸãã

å³ ã·ã§ã«ã³ãŒãã®åŸç¶éšåãå±éããããã®ã³ãŒãã
æåã®ã¬ãã«ïŒã¹ããŒãž1ïŒã®æåŸã«ãuploadpref.datãã¡ã€ã«å šäœã®å 容ãã¡ã¢ãªã«ã³ããŒãããŸãã ãã®ç®çã®ããã«ãã·ã§ã«ã³ãŒãã¯Windows APIã®æ©èœã䜿çšãã察å¿ããWindowsã·ã¹ãã ã©ã€ãã©ãªã®ãšã¯ã¹ããŒãããŒãã«ãçŽæ¥åæããŠã¢ãã¬ã¹ãååŸããŸãã é¢æ°æ€çŽ¢ã¯ããã®ååã®èšç®ãããããã·ã¥ã«åºã¥ããŠå®è¡ãããŸãã ããã·ã¥ã¯ãå°æåã®é¢æ°åããæåã®åã ã®16é²è¡šçŸãåèšããå埩ã®äžéåèšã«2ãæããŠèšç®ãããŸãã 以äžã¯ããã®ã¢ã«ãŽãªãºã ãå®è£ ããPythonã³ãŒãã§ãã
def hash_nameïŒnameïŒïŒ
çµæ= 0
ååã®cã®å ŽåïŒ
çµæ= 2 *ïŒçµæ+ïŒord©| 0x60ïŒïŒ
çµæãè¿ã
ãã®ããã·ã¥èšç®ã¢ã«ãŽãªãºã ã¯ãèè ã®Chris AnleyãšJohn Heasmanã®ãThe Shellcoder's HandbookïŒDiscovering and Exploiting Security Holesããšããæ¬ã®äŸã§æå®ãããŠãããã®ãšåäžã§ããããšã«æ³šæããŠãã ããã Cã§ã®å®è£ ã¯ãæ¬ã®ç¬¬2çã®145ããŒãžã«ãããŸãã
察å¿ããé¢æ°ã¢ãã¬ã¹ãåãåã£ãåŸãã³ãŒãshell_code_1ã¯ãã¡ã¢ãªå ã«uploadpref.datãã¡ã€ã«ã®ãµã€ãºã®2ã€ã®ãããã¡ãå²ãåœãŠãŸãã ãã¡ã€ã«å šäœã®å 容ã¯ããããã®ãããã¡ãŒã«ã³ããŒããã2çªç®ã®ãããã¡ãŒã¯ãã®ãŸãŸæ®ããŸãã ãã®åŸãã·ã§ã«ã³ãŒãã¯ããã¡ã€ã«ã®å é ãããªãã»ãã0x10ã«ãããã®ãã¡ã€ã«ã®ã³ãŒãã«å¶åŸ¡ã移ããŸãã ãã®ã³ãŒãã®äžã¯Cã§ãã
ãã³ãã«f = CreateFileAïŒâ uploadpref.datâãGENERIC_READãFILE_SHARE_READã0ãOPEN_EXISTINGã0ã0ïŒ;
DWORD uploadpref_size = GetFileSizeïŒfã0ïŒ;
char * memblock1 = VirtualAllocïŒNULLãuploadpref_sizeãMEM_COMMIT | MEM_RESERVEãPAGE_READWRITEïŒ;
char * memblock2 = VirtualAllocïŒNULLãuploadpref_sizeãMEM_COMMIT | MEM_RESERVEãPAGE_READWRITEïŒ;
ReadFileïŒfãmemblock1ãuploadpref_sizeïŒ;
stage_2 =ïŒmemblock1 [0x10];
stage_2ïŒïŒmemblock1 [0x650]ãmemblock2ïŒ;
// memblock2ãããã¡ã¢ãã¬ã¹ããšã¯ã¹ããã€ãã³ãŒãã«åŒæ°ãšããŠæž¡ããããšã¯ã¹ããã€ãã¯ãã®åŸã³ã³ãããŒã«ãããã«è»¢éããŸã
2çªç®ã®ã¬ãã«ïŒã¹ããŒãž2ïŒã§ãé¢æ°ã¯ããŒã¿ãå é ãããªãã»ãã0x650ã§memblock2ãããã¡ãŒã«è§£åããŸãã ããªãéå¹ççãªã¢ã«ãŽãªãºã ã䜿çšããŠããŒã¿ã解åããŸãããã®åŸããã®ãµã€ãºã¯3.632ãã€ãã«ãªããŸãã ãã®æäœã®åŸãå¶åŸ¡ã¯memblock2ãããã¯ã®å é ã«è»¢éãããŸãããã®ãããã¯ã«ã¯ã第3ã¬ãã«ïŒã¹ããŒãž3ïŒã®ã·ã§ã«ã³ãŒããå«ãŸããŠããŸãã
ã¹ããŒãž3ã¬ãã«ã§ããšã¯ã¹ããã€ãã³ãŒãã¯uploadpref.datãã¡ã€ã«ãå床éããããããPEãã¡ã€ã«ãæœåºããŸããPEãã¡ã€ã«ã¯ãªãã»ãã0x1600ã«ãããŸãã ãã¡ã€ã«ã¯ãå²ãåœãŠãããã¡ã¢ãªãããã¡ã«ãããŸãã 解åã¢ã«ãŽãªãºã ã¯ãåã®ã¬ãã«ã§äœ¿çšããããã®ãšåãã§ãã ãã®åŸããšã¯ã¹ããã€ãã¯ãµã¹ãã³ãã¢ãŒãã§æ°ããããã»ã¹ãäœæããããã«å®è¡å¯èœãã¡ã€ã«ãæ¿å ¥ããŠèµ·åããŸãã uploadpref.datããæœåºãããPEãã¡ã€ã«ã®ãµã€ãºã¯56.832ãã€ãã§ãGh0st RATãããããŒã®ããŠã³ããŒããšå®è¡ã«ç¹åããŠããŸãã
以äžã®è¡šã¯ãuploadpref.datãã¡ã€ã«ã®æ§é ã瀺ããŠããŸãã

ããŒãããŒããŒã¯ãå ã®ãšã¯ã¹ããã€ããã¡ã€ã«ïŒuploadpref.datïŒãšãããããæœåºãããmsfeedssync.exeãšããç¬èªã®ãã¡ã€ã«ãçŸåšã®ãŠãŒã¶ãŒã®ã¢ããªã±ãŒã·ã§ã³ããŒã¿ãã£ã¬ã¯ããªã«ã³ããŒããŸãã ãã®åŸãå®è¡å¯èœãã¡ã€ã«ãžã®ã·ã§ãŒãã«ãããäœæãã[ã¹ã¿ãŒã]ã¡ãã¥ãŒã®èªåå®è¡ãã£ã¬ã¯ããªã«é 眮ããŸãã ãããã£ãŠãåèµ·ååŸããšã¯ã¹ããã€ãã¯åã³æ©èœãããã¹ãŠã®æé ãå床å®è¡ãããŸãã


å³ ãã«ãŠã§ã¢ãã¡ã€ã«ã®å®è¡ã瀺ãã¹ã¿ãŒãã¢ãããã©ã«ãå ã®ã·ã§ãŒãã«ããã
äžèšã®æäœãå®è¡ããåŸãããŒãããŒããŒã¯ã·ã¹ãã ã«æ£åžžã«ã€ã³ã¹ããŒã«ããããšèŠãªãããåèµ·ååŸã«Gh0st RATãããããŒãããŠã³ããŒããããšããäž»èŠãªæ©èœãæ£åžžã«å®è¡ã§ããŸãã ãããããŒã¯HTTPãããã³ã«ã䜿çšããŠããŒããããŸãã ãããè¡ãããã«ããã«ãŠã§ã¢ã¯30åééã§èµ·åããŸãã 2ã€ã®ã¹ã¬ããã HTTPãããã³ã«ã®ãŠãŒã¶ãŒãšãŒãžã§ã³ãæååã«åºã¥ããŠãããããããªã¢ãŒããµãŒããŒãæäœããããã«äœ¿çšãããããæåã®ã¹ããªãŒã ã«Alan_function ã2çªç®ã®BFunctionã«ååãä»ããŸããã ãããããåããã¡ã€ã³åã䜿çšããç°ãªãURLããGh0st RATãããããŒãããŠã³ããŒãããããšããŠããŸãã ãã¡ã€ã«ãããŠã³ããŒãããåŸããã¡ã€ã«ã¯è§£åãããåã¹ã¬ããã¯ãããããŒã³ãŒãã®ç°ãªãã»ã¯ã·ã§ã³ãåŒã³åºãããšããŸãã
- Alan_functionã¹ã¬ããã¯ãããŠã³ããŒãããããã¡ã€ã«ãå®è¡å¯èœãªPEãã¡ã€ã«ã§ãããšæ³å®ãããããå®è¡ããããã«åã«èµ·åãããšã³ããªãã€ã³ãã«å¶åŸ¡ãæž¡ããŸãã
- BFunctionã¹ã¬ããã¯ãããŠã³ããŒãããããã¡ã€ã«ãDLLã§ãããšæ³å®ããŠããŸãã ãã®å ŽåãããããTestFunctionãšåŒã°ãããšã¯ã¹ããŒããããé¢æ°ãåŒã³åºããŸã ã

2015幎3æã«äœ¿çšãããæåã®ãã«ãŠã§ã¢ãããããŒé åžæ¹æ³ãæ€åºããããšãã§ããŸããããã®æç¹ã§ããŠã³ããŒããŒã«ãã£ãŠããŠã³ããŒããããå®è¡å¯èœãã¡ã€ã«ã¯ããŠã³ããŒããŒèªäœã«é¢é£ä»ããããŠããŸããã TestFunction ã ãã®ã©ã€ãã©ãªãBFunctionã¹ã¬ããã«é ä¿¡ããŠãåãçµæãåŸãããšãã§ããŸãã
ãã®æ¹æ³ã§ããŒããããå®è¡å¯èœãã¡ã€ã«Gh0st RATã¯ããã®æªæã®ããããã°ã©ã ã®ãããããŒã§ãã Gh0st RATã¯ãAVäŒæ¥ã®ããŸããŸãªç 究è ã«ãã£ãŠãã§ã«ææžåãããŠããŸãã ããã¯ãã¢ãããã¯ãŒã¯ãããã³ã«ã«ã¯ãæªæã®ãããã£ã³ããŒã³ãèå¥ãã5æåã®æååãå«ãŸããŠããŸãã ãã®äŸã§ã¯ãèå¥åã¯æååãA1CEAãã§ããã ãã®ãã£ã³ããŒã³IDã§ããã¯ãã¢æ å ±ãæäŸãã次ã®ãªã³ã¯ãèŠã€ããããšãã§ããŸãã
- 2013幎12æã«çºèŠããã MalwrããŒã¿ããŒã¹ã«ã¢ããããŒãããããµã³ãã« ã
- 2015幎3æ3æ¥ã«è¿œå ããã Snortã«ãŒã«
- Korean WinsããŒã¿ã«ã®ãã«ãŠã§ã¢ãµã³ãã«ã®åæã
ãµã³ãã«ã®Gh0st RATã§ã¯ãã¢ãã¬ã¹www.phw2015.comããã³TCPããŒã2015ã®CïŒCãµãŒããŒã䜿çšããŸãããåæã®æç¹ã§ããã¡ã€ã³ã¯IPã¢ãã¬ã¹112.67.10.110ã«å¯Ÿå¿ããŠããŸããã
Gh0stã®ãã®å€æŽã¯ãå ã®ããã¯ãã¢ãšãããã«ç°ãªãã次ã®æ©èœãå«ãŸããŠããŸããã
- ã³ã³ãã¥ãŒã¿ãŒã®ç¹æ§ã«é¢ããããŒã¿ãåéããæ©èœã
- ããã¯ãã¢ã®ä»ã®æªæã®ããã³ã³ããŒãã³ããããŒããããTestFunctionããšåŒã°ããç¹å¥ãªæ©èœã
åæãããµã³ãã«ã§ã¯ãââããŒãã¬ãŒãå«ãGh0stã®ãã¹ãŠã®æ©èœãã¢ã¯ãã£ãã§ããã
ãããã«
åæããããšã¯ã¹ããã€ãã¯ç¹å¥ãªãã®ã§ã¯ãªããéèŠãªãã®ã§ããããŸãããKsoftã¢ããããŒããŒïŒã¯ãåºã䜿çšãããŠããã¢ããªã±ãŒã·ã§ã³ã§ã¯ãªãããã§ãã ç§ãã¡ã¯ãããã䜿çšãããç®çãšäŸµå ¥è ã«ãã£ãŠããŸããã®ååžã®ãã¯ãã«ãäœã§ãã£ããã«ã€ããŠãäºå®äžäœãç¥ããŸããã ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®æ¹æ³ãé åžã«äœ¿çšããããšãã§ããŸããããã®å Žåãæ»æè ã¯ã³ã³ãã¥ãŒã¿ãŒäžã®ãœãããŠã§ã¢ã®è¢«å®³è ã®ååšã«é¢ããæ å ±ãæã£ãŠããå¿ èŠããããããæ»æã¯æ瀺ãããŠããã¯ãã§ãã äœããã®æ¹æ³ã§ãæ»æè ã¯ãã®ãã¡ã€ã«ãããŠã³ããŒãããããã«æœåšçãªè¢«å®³è ãèªãããã®åŸããŠãŒã¶ãŒã«ãã®ãã¡ã€ã«ã䜿çšããŠããã°ã©ã èªäœã®ãããã£ã¬ã¯ããªã«é 眮ããããã«æ瀺ããå¿ èŠããããŸããã
Gh0st RATã¯ã以äžã®ç 究ã§èª¬æãããŠããŸãã
Michael G. SpohnïŒMcAfeeïŒãKnow Your Digital EnemyïŒAnatomy of a Gh0st RATã2012
www.mcafee.com/ca/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
Snorre FagerlandïŒããŒãã³ïŒãGh0st Ratã®å€ãã®é¡ã2012幎
download01.norman.no/documents/ThemanyfacesofGh0stRat.pdf
䟵害èå¥åïŒIoCïŒ

ããã¯ãã¢ã¯ã次ã®ååã®ãã¥ãŒããã¯ã¹ã䜿çšããŸãã
www.phw2015.comwww.phw2015.comwww.phw2015.com
