1幎åãESETã®å°é家ã¯ããã©ãžã«ã®2ã€ã®ã¿ã€ãã®æªæããããã°ã©ã -éè¡ã®ããã€ã®æšéŠ¬ãšãã®ããŠã³ããŒããŒïŒããŠã³ããŒããŒïŒã®æé«ã®æŽ»åãèšé²ããŸããã ããŠã³ããŒããŒã¯ãããã€ã®æšéŠ¬ã®ã¡ã€ã³ã®å®è¡å¯èœãã¡ã€ã«ã䟵å
¥å
ã®ã·ã¹ãã ã«ããŒãããããšã«ç¹åããã³ã³ãã¯ããµã€ãºã®å®è¡å¯èœãã¡ã€ã«ã§ãã ä»æ¥ãç¶æ³ã¯å€ãããŸããããç¹ã«ããã€ãã®å€æŽãå ããŠããã©ãžã«ã®æãã¢ã¯ãã£ããªè
åšã®ãªã¹ãã«ã¯ãæªæã®ããJava .jarãã¡ã€ã«ãšVisual Basicã¹ã¯ãªããããã³JavaScriptã¹ã¯ãªãããå«ãŸããŸããã
ãããã£ãŠãæªæã®ããã¹ã¯ãªãããã¡ã€ã«ããã®å°åã®ãµã€ããŒç¯çœªè
ã®éã§éåžžã«äººæ°ãé«ãŸã£ãŠããããšã¯æããã§ãã ãã®æçš¿ã§ã¯ãããã€ãã®æªæã®ããã¹ã¯ãªãããšããããã®äœæ¥ã®ã¡ã«ããºã ã«ã€ããŠèª¬æããŸãã ãã®ãããªã¹ã¯ãªããã¯ãæ»æè
ã«ãã£ãŠããŠã³ããŒããŒãšããŠã䜿çšãããŸãããæ»æè
ã¯åçŽã«WebããŒãžã«çµ±åã§ãããããããæè»ãªé
åžã¹ããŒã ãæäŸããŸãã
2016幎ã®æåã®5ãæéã®ãã©ãžã«ã§ã®ãã«ãŠã§ã¢ã®ååžã®çµ±èšãèŠããšãäžè¬çãªïŒäžè¬çãªïŒæ€åºã¿ã€ãã®æªè³ªãªé£èªåã¹ã¯ãªãããå«ãŸããŠããããšãããããŸãã ããŒããããã€ããŒãã¯ç°ãªãå¯èœæ§ããããšããäºå®ã«ããããããããã®ã¿ã€ãã®çºèŠãšéè¡ã®ããã€ã®æšéŠ¬ã®éã«ã¯é¢é£ãããããšãããããŸãã ãã©ãžã«ã®æãäžè¬çãªè
åšã®è¡šã«ããä»ã®æªæã®ããããã°ã©ã ã¯ãããŸããŸãªããã°ã©ãã³ã°èšèªã§æžãããŠããããšã«æ³šæããŠãã ããã
ã©ãã³ã¢ã¡ãªã«ã®ã¢ã³ããŠã€ã«ã¹ç 究æã®å°é家ã¯ãæ£èŠã®MEOã¯ã©ãŠããµãŒãã¹ã䜿çšããŠãã«ãŠã§ã¢ãã¡ã€ã«ããã¹ãããŠããããšã確èªããŠããŸãã ã»ãšãã©ã®å Žåã圌ãã¯éè¡ã®ããã€ã®æšéŠ¬ã§ããã é
åžãã¯ãã«ãšããŠããã«ãŠã§ã¢ãããŠã³ããŒããããªã³ã¯ãå«ããã£ãã·ã³ã°ã¡ãŒã«ãéžæãããŸããã
äŸãšããŠãBoleto_NFe_1405201421.PDF.jsãšããæªæã®ããã¹ã¯ãªãããèããŠã¿ãŸããããããã¯ãESETãŠã€ã«ã¹å¯Ÿç補åã«ãã£ãŠVBS / Obfuscated.GãšããŠæ€åºãããŸãã
ã¹ã¯ãªããã³ãŒããé£èªåãããŠãããšããäºå®ã«ãããããããããã«äœ¿çšãããæ¹æ³ã¯éåžžã«ç°¡åã§ãã 埩å·åãè¡ããªããŠããç»åãè£
ã£ããã¡ã€ã«ãæå®ãããURLã§flashplayer.exeãšããååã§ProgramDataãã£ã¬ã¯ããªã«ããŒããããå®è¡ãããããšãããããŸãã
äžæ¹ãflashplayer.exeãã¡ã€ã«ã¯ãEdge.exeãšãã3çªç®ã®ãã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ãããã³ãã³ã°åããã€ã®æšéŠ¬ããŠã³ããŒããŒã§ãã ãã®3çªç®ã®ãã¡ã€ã«ã¯ãAV補åã«ãã£ãŠWin32 / Spy.KeyLogger.NDWãšããŠæ€åºãããŸãã ãã®çºèŠã®ååã«ãããããããããŒã¹ãããŒã¯ã®èšé²ã«å ããŠããã³ãã³ã°åããã€ã®æšéŠ¬ã®æ©èœãå«ãŸããŠããŸãã ãã®å€ãã®æ©èœã®äžã§ããŠãŒã¶ãŒã蚪åããWebãµã€ãã®ã¢ãã¬ã¹ãååŸãã Dynamic Data ExchangeïŒDDEïŒ ã¡ã«ããºã ã䜿çšããŠããªã³ã©ã€ã³ãã³ãã³ã°Webãµã€ãã®ãªã¹ãã§ãããããã§ãã¯ããŸãã 以åã®ãã£ã³ããŒã³ã§ãããã€ã®æšéŠ¬ã«ãããã®æ¹æ³ã®äœ¿çšã以åã«èšé²ããŸããã ãã®ã±ãŒã¹ãšä»¥åã®ã±ãŒã¹ã®éãã¯ãä»åã¯ããã€ã®æšéŠ¬ãããŸããŸãªWebãã©ãŠã¶ãŒã䟵害ããããšãç®çãšããŠããããšã§ãã
ãã¡ã€ã«å
ã®è¡ã¯ãåçŽãªXORæäœã«åºã¥ãã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸãã ãããã®è¡ã®äžéšã次ã®å³ã«ç€ºããŸãã ããã€ã®æšéŠ¬ã¯ãã©ãžã«ã®ãªã³ã©ã€ã³ãã³ãã³ã°ãµã€ãã®è³æ Œæ
å ±ãçãããšãå°éãšããŠããããšã圌ããããããã
äžèšã®è
åšçµ±èšã¯ããã©ãžã«ã®æ»æè
ããŠã€ã«ã¹å¯Ÿç補åã«ããæªæã®ããã³ãŒãã®æ€åºãåé¿ããããšããŠãæ°ãããã©ãããã©ãŒã ãšããã°ã©ãã³ã°èšèªã«åãæ¿ãå§ããããšã瀺ããŠããŸãã ãã ããæ»æè
ã®æšçã«éãã¯ãªãããªã³ã©ã€ã³ãã³ãã³ã°æ
å ±ã®çé£ã¯äŸç¶ãšããŠæãåçæ§ã®é«ãæ»æ圢æ
ã§ãããããæãäžè¬çã§ãã
æ£åœãªã¯ã©ãŠãã¹ãã¬ãŒãžãµãŒãã¹ã¯ããµã€ããŒç¯çœªè
ãJavaScriptã§ãã«ãŠã§ã¢ããã¹ãããããã«ã䜿çšãããŸãããããã¯ããã©ãžã«ã§æã掻çºãªè
åšã®ããã10ã®1ã€ã§ãã ç¹ã«ã Java / TrojanDownloader.Banload.AKã®ãããªESET AV補åã«ãã£ãŠæ€åºãããå€ãã®æªæã®ãããã¡ã€ã«ãèŠã€ãããŸããã
ãããã®ãã¡ã€ã«ã¯ãBoleto_CobrancaãPedido_AtualizacaoããŸãã¯Imprimir_Debitosãªã©ã®ååã®.jarã¿ã€ãã§ãã ã³ãŒããéã³ã³ãã€ã«ããåŸãå€æ°ãšã¡ãœããã®éåžžã«é·ãååãæã€é£èªåããã圢åŒã§ååŸããŸãã
é£èªåãããŠããã«ãããããããã€ã³ããŒããããé¢æ°ã®ããã€ãã®ååããã¡ã€ã«ã«è¡šç€ºãããŸãã ã€ã³ããŒããããæåŸã®5ã€ã®ã¯ã©ã¹ã¯ã察称DESã¢ã«ãŽãªãºã ã䜿çšãããããæå·åæäœã«é¢é£ããŠããŸãã ãããã£ãŠãããã§äœ¿çšããã埩å·åã¡ãœããã決å®ããã¡ãœãããšå€æ°ã®ååãããç解ãããããã®ã«çœ®ãæããããšãã§ããã°ã次ã®å³ã®ããã«æ¬¡ã®ã³ãŒããåŸãããŸãã
æååã®åŸ©å·åã«äœ¿çšãããããŒã¯ãJavaã¯ã©ã¹ã®ååã§ãã ãããã£ãŠãæªæã®ããããã°ã©ã ã®ã¡ã€ã³ã¡ãœããã®ã³ãŒããèªåèªèº«ã«é©å¿ããããšãæ¬æã®è¡ã解èªã§ããŸãã ã¡ã€ã³ã¯ã©ã¹ã解æããŠãããã®è¡ãæ€çŽ¢ããå€æŽãããã³ãŒãã«æž¡ããŠåŸ©å·åããã»ã¹ãå®è¡ã§ããŸãã 以äžã¯ã解èªãããæååãšæå·åããã察å¿ãããã®ã§ãã
äžã®ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ãæªæã®ããããã°ã©ã ãéä¿¡ãããµãŒããŒã®IPã¢ãã¬ã¹ã匷調ããŸããã åæãããã«ãŠã§ã¢ã®ããŸããŸãªãµã³ãã«ã§ããªã¢ãŒãCïŒCãµãŒããŒã®ã¢ãã¬ã¹ãå€ããããšã«æ³šæããŠãã ããã 次ã«ãVisual Basic Scââriptã§ãã¡ã€ã«ãäœæãããcscript.exeã€ã³ã¿ãŒããªã¿ãŒã«ãã£ãŠå®è¡ãããŸãã
åæãããã«ãŠã§ã¢ãã¡ã€ã«ã«ã¯ãã€ã³ããŒããããã¯ã©ã¹ã®ååã§èå¥ã§ããæ©èœãå«ãŸããŠããããšã¯æ³šç®ã«å€ããŸãã ãã«ãŠã§ã¢ã®æãèå³æ·±ãæ©èœã®1ã€ã¯ãä»®æ³åãããç°å¢ãæ€åºããæ©èœã§ãã ãã®ãããªç°å¢ãæ€åºããããšãæªæã®ããã³ãŒãã®å®è¡ã¯çµäºããŸãã ä»ã®ã€ã³ããŒããããæ©èœã®ããã€ãã¯ãã€ã³ã¿ãŒãããããã®ãã¡ã€ã«ã®ããŠã³ããŒãã«ç¹åããŠããŸããããã¯ãæ®ãã®ã€ã³ããŒãã§ãèŠãããšãã§ããŸãã
åè¿°ã®ãšãããæ»æè
ã¯ããŸããŸãªããã°ã©ãã³ã°èšèªã䜿çšããŠããã«ãããããããæ»æè
ãè¿œæ±ããç®æšã¯å€æŽãããŠããŸããã åæãã2ã€ã®ããŒãããŒããŒã¯ããã«ãã¬ã«ã®ããŒã¿ã¹ãã¬ãŒãžãµãŒãã¹ã§ãã¹ããããŠããŸããã ãã ããå¥ã®ã¯ã©ãŠããµãŒãã¹ã§ãã¹ããããŠããå¥ã®ããŒãããŒããŒãçºèŠããŸããã ãã®ææ°ã®ããŒãããŒããŒã¯ãVisual Basic Scââriptã§èšè¿°ãããŠããŸãã
ãããã®è
åšã¯ãã¹ãŠåãé
åžæ¹æ³ã䜿çšããŸã-éè¡ããéä¿¡ãããæ£åœãªã¡ãŒã«ãè£
ã£ãè©æ¬ºã¡ãŒã«ã ãã®.vbsãã¡ã€ã«ãèªç±ã«åãåã£ãåŸãé£èªåãããŠããããšãããããŸãã
ã¹ã¯ãªããã®äž»ãªæ©èœã¯16é²ãšã³ã³ãŒã圢åŒã§æäŸãããXORæäœã䜿çšããŠæå·åãããŸãã ãã®Visual Basicã¹ã¯ãªããã³ãŒãã®å
ã®å€èŠ³ã埩å
ããŸããã 圌ã¯ããã¹ã¯ãŒããæäŸãããã¢ãŒã«ã€ãã®ããŠã³ããŒããå°éãšããŠããŸãã ãã®ã¢ãŒã«ã€ãã¯ã7za.exeãšããå¥ã®ããŠã³ããŒãå¯èœãªã¹ã¯ãªããã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠè§£åãããŸãã ãã®ã¢ããªã±ãŒã·ã§ã³ã¯æªæã®ãããã®ã§ã¯ãªããããŠã³ããŒããã.zipã¢ãŒã«ã€ãããå®è¡å¯èœãã¡ã€ã«ãæœåºããããã ãã«äœ¿çšãããŸãã å®è¡å¯èœãã¡ã€ã«ãæœåºããåŸãå®è¡ã®ããã«èµ·åãããŸãã
ãœãŒã¹ã³ãŒãã¹ããããã®ãã«ãã¬ã«èªã®ã³ã¡ã³ããlink do seu do moduloãã¯ããã¢ãžã¥ãŒã«ãžã®ãªã³ã¯ããšããŠç¿»èš³ã§ããŸãã ãã®ã³ã¡ã³ãã¯ãã¹ã¯ãªãããç¹å¥ãªã¹ã¯ãªãããžã§ãã¬ãŒã¿ãŒã䜿çšããŠäœæãããããã³ãŒããå¥ã®ãœãŒã¹ããã³ããŒããããšããèãã«ã€ãªãããŸãã
æªæã®ããã¹ã¯ãªããã«ãã£ãŠæœåºããã³èµ·åããããã¡ã€ã«ã¯ãESET AV補åã«ãã£ãŠWin32 / Packed.Autoit.RãšããŠæ€åºãããŸãã ãããã£ãŠãæ»æè
ã䜿çšããããŸããŸãªããã°ã©ãã³ã°èšèªãèŠãããšãã§ããŸãã ãã®Autoitã¹ã¯ãªããã¯ãéè¡ã®ããã€ã®æšéŠ¬ã®ã³ãŒããã¡ã¢ãªã«ããŒãããŸãã ããã€ã®æšéŠ¬ããã»ã¹èªäœã¯ãµã¹ãã³ãã¢ãŒãã§éå§ããããã®ã€ã¡ãŒãžã¯ã¡ã¢ãªå
ã§æªæã®ããããã°ã©ã ã«çœ®ãæããããŸãããã®åŸãã³ãŒãã®å®è¡ãç¶ç¶ãããŸãïŒãã®ææ³ã¯RunPEãšããŠç¥ãããŠããŸãïŒã
ããã»ã¹ã¡ã¢ãªã«åã蟌ãŸããå®è¡å¯èœãã¡ã€ã«ã¯ã Win32 / Spy.Banker.ACSJãšããŠESET AV補åã«ãã£ãŠæ€åºãããDelphiã§èšè¿°ããããã³ãã³ã°ããã€ã®æšéŠ¬ã§ãïŒããã¯ãã©ãžã«ã§éåžžèŠããããã®ã§ãïŒã æ¬äœã«ã¯æå·åãããæååãå«ãŸããJavaScriptã®ããŒããŒã«ãã£ãŠã€ã³ã¹ããŒã«ãããåè¿°ã®ããã€ã®æšéŠ¬ã®å Žåã®ããã«ãç¬èªã®åŸ©å·åã¢ã«ãŽãªãºã ã䜿çšããŸãã
ãã®éè¡ã®ããã€ã®æšéŠ¬ã®å®è£
ã®è©³çŽ°ã«ã€ããŠã¯èª¬æããŸããããJavaScriptããŠã³ããŒããŒã«ãã£ãŠã€ã³ã¹ããŒã«ãããããã€ã®æšéŠ¬ãè¡ãããã«ãäžèšã®DDEã¡ãœããã䜿çšããªãããšã瀺ããŸãã 代ããã«ãoleaut32.dllã©ã€ãã©ãªããé¢æ°ãã€ã³ããŒãããŸããããã«ãããInternet Explorerãã©ãŠã¶ãŒã䜿çšããŠç¹å®ã®éè¡ã®Webãµã€ãã蚪åããŠãã被害è
ãæ€åºãããšãæªæã®ããã¿ã¹ã¯ãèªåå®è¡ã§ããŸãã 被害è
ããããã®Webãµã€ãã®ãããããé²èŠ§ãããšããã³ãã³ã°ããã€ã®æšéŠ¬ã¯ããªã³ã©ã€ã³ãã³ãã³ã°ã¢ã«ãŠã³ãã®è³æ Œæ
å ±ãååŸããããã«ãæ£åœãªWebãµã€ãã®WebããŒãžã§äœ¿çšãããŠããç»åãšéåžžã«ãã䌌ãç»åãå«ãåœã®ãã©ãŒã ãããŠã³ããŒãããŸãã
è€æ°ã®ããã°ã©ãã³ã°èšèªãŸãã¯ãã©ãããã©ãŒã ã§éçºãããäžèšã®è
åšããåããã£ã³ããŒã³ã«çµã³ä»ããããšãã§ããŸããã ãµã€ããŒç¯çœªè
ããã©ãžã«ã«è
åšãåºããããã«äœ¿çšããããŸããŸãªæ¹æ³ãšãªãœãŒã¹ãã©ãã ãããã®ãçåã«æãã ãã§ãã ãããã®æ»æã®æçµæ®µéã¯Delphiã§äœæãããéè¡ã®ããã€ã®æšéŠ¬ã®ã€ã³ã¹ããŒã«ã§ãããšããäºå®ã«ããããããããã®ããã€ã®æšéŠ¬ã®ã³ãŒãã®æŽæ°ã確èªãããŠããŸãã ãã®ãããªæŽæ°ã«ããããµã€ããŒç¯çœªè
ã¯ãã©ãžã«ã®éè¡ã®æ°ããä¿è·æ©èœãã¿ã€ã ãªãŒã«å
æã§ããŸãã
䟵害ã®å
åïŒIoCïŒ
SHA-1ïŒ8ceaae91d20c9d1aa1fbd579fcfda6ecfdef8070
ãã¡ã€ã«åïŒBoleto_NFe_1405201421.PDF.js
æ€åºåïŒVBS / Obfuscated.G
SHA-1ïŒ016bd00717c69f85f003cbffb4ebc240189893ad
ãã¡ã€ã«åïŒflashplayer.exe
æ€åºåïŒWin32 / TrojanDownloader.Banload.XGT
SHA-1ïŒc4c4f2a12ed69b95520e5d824854d12c8c4f80ab
ãã¡ã€ã«åïŒEdge.exe
æ€åºåïŒWin32 / Spy.KeyLogger.NDW
SHA-1ïŒ2c8385fbe7c4a57345bf72205a7c963f9f781900
ãã¡ã€ã«åïŒImprimir_Debitos9874414541555.jar
æ€åºåïŒJava / TrojanDownloader.Banload.AK
SHA-1ïŒ363f04edd57087f9916bdbf502a2e8f1874f292c
ãã¡ã€ã«åïŒAtualizacao_de_Boleto_Vencido_10155455096293504.jar
æ€åºåïŒJava / TrojanDownloader.Banload.AK
SHA-1ïŒ8b50c2b5bb4fad5a0049610efc980296af43ddcd
ãã¡ã€ã«åïŒLU 1.jar
æ€åºåïŒJava / TrojanDownloader.Banload.AK
SHA-1ïŒd588a69a231aeb695bbc8ebc4285ca0490963685
ãã¡ã€ã«åïŒComprovante Deposito-Acordo N7656576lïŒ3ïŒïŒ4ïŒïŒ4ïŒ.vbs
æ€åºåïŒVBS / TrojanDownloader.Agent.OGG
SHA-1ïŒdde2af50498d30844f151b76cb6e39fc936534a7
ãã¡ã€ã«åïŒ7b0gct262q.exe
æ€åºåïŒWin32 / Packed.Autoit.R
SHA-1ïŒ256ad491d9d011c7d51105da77bf57e55c47f977
æ€åºåïŒWin32 / Spy.Banker.ACSJ