Stantinkoã¯åºåè©æ¬ºã«ç¹åããŠããŸãããæè¡çãªè€éãã®äžè¬çãªèæ¯ã«ã¯éç«ã£ãŠããŸãã ãŠã€ã«ã¹å¯Ÿçæ€åºããä¿è·ããããã®ã³ãŒãã®æå·åãšéçšã®é©å¿ã«ãããStantinkoã®ãªãã¬ãŒã¿ãŒã¯å°ãªããšã5幎éã¯èŠçããé¢ããããšãã§ããŸããã ããã«ãStantinkoã®èŠæš¡ã«æ³šç®ãéãŸã£ãŠããŸããããã¯ãã·ã¢ã§æãäžè¬çãªãµã€ããŒè åšã®1ã€ã§ãããããããããã«ã¯çŽ500,000å°ã®ããã€ã¹ããããŸãã

埩ç¿
Stantinkoã®ãªãã¬ãŒã¿ãŒã¯ãã·ã¹ãã ã«ææããããã«ãæµ·è³çãœãããŠã§ã¢ãæ€çŽ¢ããå®è¡å¯èœãã¡ã€ã«ãããŠã³ããŒãããŠãããŠãŒã¶ãŒã誀解ãããŸãã 次ã«ãæåã®ææãã¯ã¿ãŒã§ããFileTourã¯ãå€ãã®ããã°ã©ã ã«åæçã«ã€ã³ã¹ããŒã«ããããã¯ã°ã©ãŠã³ãã§ã®æåã®StantinkoãµãŒãã¹ã®é ããã€ã³ã¹ããŒã«ãããŠãŒã¶ãŒã®æ³šæãããããŸãã ãããª1ã¯ããŠãŒã¶ãŒãæªæã®ãã.exeãã¡ã€ã«ãèµ·åããæ¹æ³ã瀺ããŠããŸãã
ãããª1.ãŠãŒã¶ãŒãæªæã®ãããã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ãã
Stantinkoã®ãªãã¬ãŒã¿ãŒã¯ãäž»ã«åºåãã¯ãªãã¯è©æ¬ºã®äžæ£å°å ¥ã®ããã«æªæã®ãããã©ãŠã¶ãŒæ¡åŒµæ©èœãã€ã³ã¹ããŒã«ããããšã«ãããããããããã管çããã³åçåããŸãã åé¡ã¯ã圌ããããã§æ¢ãŸããªãããšã§ãã æªæã®ãããµãŒãã¹ã«ãããææããã·ã¹ãã äžã§äœã§ãå®è¡ã§ããŸãã ãã«æ©èœã®ããã¯ãã¢ãGoogleã§ã®å€§éæ€çŽ¢çšããããããã³JoomlaãšWordPressã³ã³ãããŒã«ããã«ïŒãããã³ã°ãšå販ã®å¯èœæ§ã®ããã«èšèšãããïŒã«å¯Ÿãããã«ãŒããã©ãŒã¹æ»æã®ãŠãŒãã£ãªãã£ã®éä¿¡ã確èªããŸããã
以äžã®å³ã¯ãææãã¯ã¿ãŒããç¶ç¶çãªãµãŒãã¹ããã³å¯Ÿå¿ãããã©ã°ã€ã³ãŸã§ãã¹ã¿ã³ãã£ã³ã³ã®ãµã€ããŒãã£ã³ããŒã³ã®å®å šãªã¹ããŒã ã瀺ããŠããŸãã

å³1. Stantinkoã®å®å šãªè åšå³
äž»ãªãã©ã¡ãŒã¿ãŒ
Stantinkoã®ç¹åŸŽçãªæ©èœã¯ããŠã€ã«ã¹å¯Ÿçã®æ€åºããã€ãã¹ããæªæã®ããåäœãå®çŸ©ãããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«å¯Ÿæããããšã§ãã å æ¬çãªè åšåæã«ã¯ãããŒãããŒããŒãšæå·åãããã³ã³ããŒãã³ããšãã£ãè€æ°ã®ã³ã³ããŒãã³ããå¿ èŠã§ãã æªæã®ããã³ãŒãã¯ããã£ã¹ã¯ãŸãã¯Windowsã¬ãžã¹ããªã«ããæå·åãããã³ã³ããŒãã³ãã«é ãããŠããŸãã ã³ãŒãã¯ããŠã³ããŒããããäžèŠç¡å®³ãªå®è¡å¯èœãã¡ã€ã«ã«ãã£ãŠè§£èªãããŸãã ææããšã«ããŒãçæãããŸãã äžéšã®ã³ã³ããŒãã³ãã¯ãããèå¥åã䜿çšãããã®ä»ã®ã³ã³ããŒãã³ãã¯è¢«å®³è ã®PCããŒããã©ã€ãããªã¥ãŒã ã®ã·ãªã¢ã«çªå·ã䜿çšããŸãã ãã£ã¹ã¯ã«ä¿åãããã¢ãŒãã£ãã¡ã¯ãã¯å®è¡åã«æªæã®ããåäœã瀺ããªããããæå·åãããŠããªãã³ã³ããŒãã³ãã«ããæ€åºã¯éåžžã«é£ããã¿ã¹ã¯ã§ãã
ããã«ãStantinkoã¯å埩ã¡ã«ããºã ãæäŸããŸãã ææãæåãããšãWidnowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã€ã³ã¹ããŒã«ããã2ã€ã®æªæã®ãããµãŒãã¹ã被害è ã®ãã·ã³ã«ã€ã³ã¹ããŒã«ãããŸãã ãµãŒãã¹ã®ãããããåé€ãããå ŽåããµãŒãã¹ã¯çžäºã«åã€ã³ã¹ããŒã«ã§ããŸãã ãããã£ãŠãè åšãæ£åžžã«é€å»ããã«ã¯ã2ã€ã®ãµãŒãã¹ãåæã«åé€ããå¿ èŠããããŸãã ãã以å€ã®å ŽåãCïŒCãµãŒããŒã¯ããŸã æ€åºãããŠããªãããæ°ããæ§æãå«ããªã¢ãŒããµãŒãã¹ã®æ°ããããŒãžã§ã³ã転éããŸãã
Stantinkoã®äž»ãªæ©èœã¯ãæªæã®ãããã©ãŠã¶ãŒæ¡åŒµæ©èœãææããã·ã¹ãã ãžã®ã»ãŒããµãŒãã£ã³ããã³ããã£ãããã¯ã·ã§ã³ã®ã€ã³ã¹ããŒã«ã§ãã åæã®æç¹ã§ã¯ãäž¡æ¹ã®æ¡åŒµæ©èœãChromeãŠã§ãã¹ãã¢ã§å©çšå¯èœã§ããã äžèŠãããšããããã¯äžèŠãªURLããããã¯ããæ£åœãªãã©ãŠã¶æ¡åŒµæ©èœã§ãã ããããStantinkoã¹ããŒã ã®ãã¬ãŒã ã¯ãŒã¯ã«ã€ã³ã¹ããŒã«ãããšãæ¡åŒµæ©èœã¯ã¯ãªãã¯è©æ¬ºãäžæ£ãªåºåãå«ãå¥ã®æ§æãååŸããŸãã ãããª2ã¯ã Safe Surfingæ¡åŒµæ©èœã®ã€ã³ã¹ããŒã«ããã»ã¹ã瀺ããŠããŸãã ãªã³ã¯ãã¯ãªãã¯ãããšããŠãŒã¶ãŒã¯Rambleræ€çŽ¢ãšã³ãžã³ã«ãªãã€ã¬ã¯ããããŸãã

å³2. ChromeãŠã§ãã¹ãã¢ã®Teddy Protection

å³3. ChromeãŠã§ãã¹ãã¢ã§ã®å®å šãªãµãŒãã£ã³
ãããª2.ãã©ãã£ãã¯ãRamblerãŠã§ããµã€ãã«ãªãã€ã¬ã¯ããã
Stantinkoã¯ã¢ãžã¥ãŒã«åŒã®ããã¯ãã¢ã§ãã ãã®ã³ã³ããŒãã³ãã«ã¯ãCïŒCãµãŒããŒãã¡ã¢ãªã«çŽæ¥éä¿¡ããWindowså®è¡å¯èœãã¡ã€ã«ãå®è¡ã§ããããŒãããŒããŒãå«ãŸããŠããŸãã ãã®æ©èœã¯æè»ãªãã©ã°ã€ã³ã·ã¹ãã ã®åœ¢åŒã§å®è£ ãããŠããããªãã¬ãŒã¿ã¯ææããã·ã¹ãã äžã§äœã§ãã§ããããã«ãªããŸãã 以äžã®è¡šã¯ãç§ãã¡ãç¥ã£ãŠããStantinkoãã©ã°ã€ã³ã説æããŠããŸãã

åçå
Stantinkoéçºè ã¯ãAPTãã£ã³ããŒã³ã§ããäžè¬çãªæ¹æ³ã䜿çšããŸãã ãããã圌ãã®äž»ãªç®æšã¯ãéã§ãã ãªãã¬ãŒã¿ãŒã¯ãæãåçæ§ã®é«ãã³ã³ãã¥ãŒã¿ãŒç¯çœªåžå Žã§ãµãŒãã¹ãæäŸããŠããŸãã
ãŸããä»æ¥ã®ã¯ãªãã¯è©æ¬ºã¯ããµã€ããŒç¯çœªãšã³ã·ã¹ãã ã®äž»èŠãªåå ¥æºã§ãã White Opsãšå šç±³åºåäž»åäŒïŒç±³åœïŒã«ãã調æ»ã§ã¯ã2017幎ã®ã¯ãªãã¯è©æ¬ºã«ããã°ããŒãã«ã³ã¹ãã¯65åãã«ãšæšå®ãããŸããã
äžèšã®ããã«ãStantinkoã¯2ã€ã®ãã©ãŠã¶æ¡åŒµæ©èœãã€ã³ã¹ããŒã«ããŸã- ã»ãŒããµãŒãã£ã³ãšããã£ãããã¯ã·ã§ã³ã¯ ãåºåã衚瀺ãŸãã¯ãªãã€ã¬ã¯ãããŸãã ããã«ãããStantinkoã®ãªãã¬ãŒã¿ãŒã¯ãåºåäž»ã«æäŸãããã©ãã£ãã¯ã«å¯ŸããŠãéãåãåãããšãã§ããŸãã 次ã®å³ã¯ã転éã¹ããŒã ã瀺ããŠããŸãã

å³4. Clickfrodããªãã€ã¬ã¯ãããã»ã¹
åŸæ¥ã®ã¯ãªãã¯è©æ¬ºã¹ããŒã ã¯ããã©ãã£ãã¯ããæŽãæµããããã«ãè€æ°ã®åºåãããã¯ãŒã¯éã®äžé£ã®ãªãã€ã¬ã¯ãã«åºã¥ããŠæ§ç¯ãããŠããŸãã ããããStantinkoã®å Žåããªãã¬ãŒã¿ãŒã¯åºåäž»ã«ããè¿ã-å Žåã«ãã£ãŠã¯ïŒå³4ãåç §ïŒããŠãŒã¶ãŒã¯Stantinkoãããã¯ãŒã¯ããçŽæ¥åºåäž»ã®Webãµã€ãã«ã¢ã¯ã»ã¹ããŸãã ããã¯ãStantinkoãã£ã³ããŒã³ã®èåŸã«ããæ»æè ããã«ãŠã§ã¢ãå¹æçã«é ãããšãã§ããã ãã§ãªããåŸæ¥ã®åºåçµæžãæ··ä¹±ãããããšãã§ããããšãæå³ããŸãã
第äºã«ãStantinkoã®ãªãã¬ãŒã¿ãŒã¯JoomlaãšWordPressã®ãµã€ãã®ã³ã³ãããŒã«ããã«ã«ã¢ã¯ã»ã¹ããããšããŠããŸãã ãã®æ»æã¯ããªã¹ãäžã®ãã°ã€ã³ãšãã¹ã¯ãŒãã®åæã䜿çšãããã«ãŒããã©ãŒã¹ã«åºã¥ããŠããŸãã ç®æšã¯ãäœäžãã®çµã¿åãããè©ŠããŠãã¹ã¯ãŒããæšæž¬ããããšã§ãã ãããã³ã°ãããã¢ã«ãŠã³ãã¯å販ã§ããããã«ãµã€ã蚪åè ãäžé£ã®ãšã¯ã¹ããã€ãã«ãªãã€ã¬ã¯ãããããæªæã®ããã³ã³ãã³ãããã¹ããããããããã«äœ¿çšã§ããŸãã
第äžã«ãStantinkoããœãŒã·ã£ã«ãããã¯ãŒã¯ã§ã©ã®ããã«æ©èœãããã調æ»ããŸããã Linux / Mooseã®ã¬ããŒãã§ã¯ããã®ã¿ã€ãã®è©æ¬ºã«ã€ããŠæ¢ã«èª¬æããŠããŸãã ãã®ã¹ããŒã ã¯æ¬åœã«å©çãçã¿ãŸã-1000ã®Facebookã®å¥œããªã³ã¹ãã¯çŽ15ãã«ã§ãïŒããšãããããããããããã®åœã®ã¢ã«ãŠã³ãã«ãã£ãŠçæããããšããŠãïŒã
Stantinkoã®ãªãã¬ãŒã¿ãŒã¯ãFacebookãšããåããããã©ã°ã€ã³ãéçºããŸããã ãšãããã圌ã¯ããŒãžã®ãããªã¢ã«ãŠã³ããäœæããåéãè¿œå ããããšãã§ããŸãã Facebookã§ãã£ããã£ãåé¿ããããã«ãç¹å¥ãªãµãŒãã¹ã䜿çšããŸãïŒå³5ïŒã Stantinkoãããã¯ãŒã¯ã®èŠæš¡ã¯ããã¹ãŠã®ãããéã§ãªã¯ãšã¹ããé ä¿¡ã§ããããããªãã¬ãŒã¿ãŒã«ãšã£ãŠæå©ã§ããããã«ãããFacebookã®ã¿ã¹ã¯ãè©æ¬ºãèªèãã«ãããªããŸãã

å³5. Stantinkoã䜿çšãããã£ããã£ãã€ãã¹ãµãŒãã¹
ãããã«
Stantinkoã¯ãåºåè©æ¬ºã«ç¹åããããããããã§ãã ã³ãŒãã®æå·åãWindowsã¬ãžã¹ããªãžã®ã³ãŒãã®ä¿åãªã©ã®é«åºŠãªæè¡ã«ããããªãã¬ãŒã¿ãŒã¯5幎éæ°ä»ãããªããŸãŸã«ãªããŸããã
ããã«ãStantinkoã®ãªãã¬ãŒã¿ãŒã¯ãChrome Web Storeã«äžæ£ãªåºåãå®è¡ãã2ã€ã®ãã©ãŠã¶ãŒæ¡åŒµæ©èœãè¿œå ããããšãã§ããŸããã ãããã®1ã€ã¯2015幎11æã«ChromeãŠã§ãã¹ãã¢ã«åããŠç»å ŽããŸããã
è åšã¯CPUã«éè² è·ããããªããããã·ã¹ãã å ã«Stantinkoãååšããããšã«ãŠãŒã¶ãŒãæ°ä»ãããšã¯ã»ãšãã©ãããŸããã äžæ¹ãStantinkoã¯åºåäž»ã«æ倱ããããããéä¿¡äºæ¥è ã«å€§ããªåçããããããŸãã ããã«ããã«æ©èœã®ããã¯ãã¢ãååšãããããæ»æè ã¯ææãããã¹ãŠã®ãã·ã³ãç£èŠã§ããŸãã
äž»ãªèª¿æ»çµæïŒ
- Stantinkoã«ãã£ãŠäŸµå®³ãããçŽ500,000å°ã®ã³ã³ãã¥ãŒã¿ãŒ
- äž»ãªç®æšã¯ãã·ã¢ïŒ46ïŒ ïŒãšãŠã¯ã©ã€ãïŒ33ïŒ ïŒã§ãã
- Stantinkoäºæ¥è ã¯ãäžæ£ãªåºåé ä¿¡ã®ããã«ãã©ãŠã¶æ¡åŒµæ©èœãã€ã³ã¹ããŒã«ããããšã«ããããããããããåçåããŸã
- ãã£ã¹ã¯ã«æ®ã£ãŠããã³ã³ããŒãã³ãã¯ãã«ã¹ã¿ã ã³ãŒãé£èªåããŒã«ã䜿çšãããããè åšåæããã»ã¹ãè€éã«ãªããŸãã
- Stantinkoã®ã»ãšãã©ã®ã³ã³ããŒãã³ãã§ã¯ãæªæã®ããã³ãŒãã¯ãä¿®æ£ããã³åã³ã³ãã€ã«ãããæ£åœãªç¡æã®ãªãŒãã³ãœãŒã¹ãœãããŠã§ã¢å ã«é ãããŠããŸãã
- Stantinkoã¯ãã·ã¹ãã ããã®åé€ãé²ãããã«ãçžäºã«ä¿®åŸ©ã§ããããã€ãã®æ°žç¶çãªãµãŒãã¹ãã€ã³ã¹ããŒã«ããŸã
- Stantinkoã®æãäžè¬çãªçšéã¯ãåºåè©æ¬ºã§ãã ãã ãããã®æ©èœã¯ã¯ããã«åºããªã£ãŠããŸãã ãªã¢ãŒã管ççšã®ãã«æ©èœã®ããã¯ãã¢ãGoogleã§ã®å€§éæ€çŽ¢çšããããJoomlaããã³WordPressã³ã³ãããŒã«ããã«ã§ã®ãã«ãŒããã©ãŒã¹æ»æçšãŠãŒãã£ãªãã£ã®éä¿¡ãç£èŠããŸãã
ææã€ã³ãžã±ãŒã¿ã¯ã GitHubã¢ã«ãŠã³ãã§å ¥æã§ããŸãã ãµã³ãã«ã®è»¢éãªã©ãStantinkoã«é¢é£ãã質åã«ã€ããŠã¯ãthreatintel @ eset.comãŸã§ãåãåãããã ããã