
æè¿ããã¹ã³ãã¯Turlaããã«ãŒãæãåºããŸããããããã¯é·ãéèµ·ããŠããŸããã The Interceptã®ãžã£ãŒããªã¹ãã¯ãTurlaãªãã¬ãŒã¿ãŒã®ãšã©ãŒããªã¹ãããã«ããéä¿¡ã»ãã¥ãªãã£æ©æ§ïŒCSEïŒã®ãã¬ãŒã³ããŒã·ã§ã³ãæãåºããŸããã ãã¬ãŒã³ããŒã·ã§ã³ã®èè ã¯ããµã€ããŒã°ã«ãŒãMAKERSMARKãåŒã³åºããŸããããã¯ã以äžã®ã¹ã©ã€ãã®ç°¡åãªèŠçŽã§ãã

Gazerã¯ãä»ã®TurlaããŒã«ãšåæ§ã«ãæšçã·ã¹ãã ã®ã¹ãã€æŽ»åãšæç¶å¯èœæ§ã®ããã®é«åºŠãªæè¡ã䜿çšããŠããŸãã Gazerã䜿çšããæ»æã«ã€ããŠèª¬æããããã¯ãã¢æ©èœã®æè¡çåæã瀺ããŸãã
ãŸãšã
ESETãã¬ã¡ããªã«ãããšãGazerã¯äžçäžã®ããã€ãã®åœã®ã³ã³ãã¥ãŒã¿ãŒã«ææããŸããããäž»ã«ãšãŒãããã«ãããŸããã ãã¯ããã¯ãæŠè¡ãããã³æé ïŒ TTP ïŒã¯ãTurlaã§é垞芳å¯ãããææšã«å¯Ÿå¿ããŠããŸããæåã®æ®µéã®ããã¯ãã¢ïŒ Skipperãªã©ïŒãããããæšçåãã£ãã·ã³ã°ã«ãã£ãŠé ä¿¡ãããŸãã ææããã·ã¹ãã ïŒãã®å Žåã¯GazerïŒã®ç¬¬2ã¹ããŒãžããã¯ãã¢ã®åºçŸã ç§ãã¡ã®èª¿æ»ã«ãããšãGazerã®äž»ãªç®æšã¯åæ±ãšãŒããããšæ§ãœããšãé£éŠã§ãã
çŸåšãTurlaã°ã«ãŒãã«å±ããGazerã®å æ¬çãªèšŒæ ã¯ãããŸããããããã¯ããã€ãã®ãã³ãã§ç€ºãããŠããŸãã ãŸããã¿ãŒã²ãããªããžã§ã¯ãã¯ãå€åçãšå€§äœ¿é€šã§ããTurlaã®å©çã®ç¯å²å ã«ãããŸãã 第äºã«ãTurlaã¯ãæšçåãã£ãã·ã³ã°ã第1段éã®ããã¯ãã¢ã第2段éã®é ãããããã¯ãã¢ã®ã€ã³ã¹ããŒã«ãªã©ã®æ¹æ³ã§ç€ºãããŸãã ã»ãšãã©ã®å ŽåãGazerãšãšãã«ãTurlaã«é¢é£ä»ããããã¹ããããŒã®ç¬¬1ã¹ããŒãžããã¯ãã¢ãèŠã€ãããŸãã 第äžã«ãGazerãšã CarlaãKazuarãªã©ãTurlaã䜿çšããä»ã®ç¬¬2ã¹ããŒãžããã¯ãã¢ãšã®éã«ã¯å€ãã®é¡äŒŒç¹ããããŸã ã
ãã€ãã®ããã«ãTurlaããŒã ã¯ããã¡ã€ã«ãå®å šã«åé€ããè¡ãå€æŽããã©ã³ãã åããããšã«ãããããŒã«ã®çºèŠãåé¿ããããšããŠããŸãã æåŸã«åŠç¿ããããŒãžã§ã³ã§ã¯ãGazerã®äœæè ã¯ããããªã²ãŒã é¢é£ã®æãã³ãŒãã«è¿œå ããããšã«ãããã»ãšãã©ã®è¡ãå€æŽããŸããã äžå³ã®äŸïŒ

ä»ã®TurlaããŒã«ãšã®é¡äŒŒç¹
Gazerã¯C ++ã§èšè¿°ãããŠãããä»ã®TurlaããŒã«ãšé¡äŒŒããŠããŸãã ããã¯ãã¢ã®GazerãCarbonãããã³Kazuarã¯ããªã¢ãŒãCïŒCãµãŒããŒããæå·åãããã¿ã¹ã¯ãåãåããŸãããã®ã¿ã¹ã¯ã¯ãææããã·ã¹ãã ãšãããã¯ãŒã¯å ã®å¥ã®ãã·ã³ã®äž¡æ¹ã§å®è¡ã§ããŸãã ãããã¯ãã¹ãŠãæªæã®ããããã°ã©ã ã®ã³ã³ããŒãã³ããšæ§æã«æå·åãããã¹ãã¬ãŒãžã䜿çšãããã¡ã€ã«ã«æäœãèšé²ããŸãã
CïŒCãµãŒããŒã®ãªã¹ãã¯æå·åãããPE Gazerã®ãªãœãŒã¹ã«çµã¿èŸŒãŸããŠããŸãã ãããã¯ã第1ã¬ãã«ã®ãããã·ãšããŠæ©èœããæ£åœãªäŸµå®³ãµã€ãïŒäž»ã«WordpressäžïŒã§ãã Turlaã°ã«ãŒãã«ç¹åŸŽçãªæŠè¡ã
ãã1ã€ã®èå³æ·±ãæ¥ç¶ã¯ãGazerãµã³ãã«ã«çµã¿èŸŒãŸããCïŒCãµãŒããŒã®1ã€ããKaspersky Labã«ãã£ãŠå解ãããJScript KopiLuwakã®ããã¯ãã¢ã«ãã£ãŠäœ¿çšãããããšã§ãã
æåŸã«ãªããŸãããã ãã«ãŠã§ã¢ã®3ã€ã®ãã¡ããªïŒGazerãCarbonãããã³KazuarïŒã«ã¯ãCïŒCãµãŒããŒãšã®éä¿¡çšã®ã¢ãžã¥ãŒã«ãå®è£ ããããã®ã¿ãŒã²ãããšããŠäœ¿çšã§ããããã»ã¹ã®åæ§ã®ãªã¹ãããããŸãã ãã®ãªã¹ããå«ããªãœãŒã¹ã¯ããµã³ãã«ããšã«ç°ãªãå ŽåããããŸãã ã»ãšãã©ã®å Žåãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŠãããã®ã«é©å¿ããŸãïŒããšãã°ãsafari.exeããã»ã¹ã¯ãªã¹ãã®äžéšã®ãµã³ãã«ã«è¡šç€ºãããŸãïŒã
ã«ã¹ã¿ã æå·å
Gazerã®äœæè ã¯æå·åãç©æ¥µçã«äœ¿çšããŠããŸãã Windows Crypto APIãä»ã®ãããªãã¯ã©ã€ãã©ãªã®ä»£ããã«ã3DESãšRSAã«ç¬èªã®ã©ã€ãã©ãªã䜿çšããŠããããã§ãã
ãªãœãŒã¹ã«åã蟌ãŸããRSAããŒã«ã¯ãCïŒCãµãŒããŒã«éä¿¡ãããããŒã¿ã®æå·åã«äœ¿çšãããæ»æè ã®å ¬éããŒãšããã€ããªãã¡ã€ã«å ã®ãªãœãŒã¹ã解èªããããã®ç§å¯ããŒãå«ãŸããŸãã åãµã³ãã«ã«ã¯åºæã®ããŒããããŸãã
ãããã®ãªãœãŒã¹ã¯OpenSSLã®RSAãšåãæ¹æ³ã§æ§æãããŠããŸããããããã®å€ïŒpãqãªã©ïŒã¯Gazeräœæè ã®ã«ã¹ã¿ã å®è£ ã§èšç®ãããŸãã
ã°ããŒãã«ã¢ãŒããã¯ãã£
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãGazerã®ã³ã³ããŒãã³ãã詳现ã«èª¬æããŸã-ãã®ã¢ãŒããã¯ãã£ãäžå³ã«ç€ºããŸãã

ããŒãããŒããŒ
ããŒãããŒããŒã¯ãã·ã¹ãã ã§å®è¡ãããæªæã®ããããã°ã©ã ã®æåã®ã³ã³ããŒãã³ãã§ãã 2ã€ã®ãªãœãŒã¹ã¯ãæå·åãããã«ãã€ããªãã¡ã€ã«ã«ä¿åãããŸãã
101ïŒãªãŒã±ã¹ãã¬ãŒã¿ãŒãåã蟌ãŸããŠããããã»ã¹ã®åå
102ïŒãªãŒã±ã¹ãã¬ãŒã¿ãŒ
次ã®ãã¥ãŒããã¯ã¹ã¯ããã«ãŠã§ã¢ã®1ã€ã®ã€ã³ã¹ã¿ã³ã¹ã®ã¿ã®å®è¡ãæäŸããŸãã
{531511FA-190D-5D85-8A4A-279F2F592CC7}
ååä»ããã€ãã®äœæ
Gazerã³ã³ããŒãã³ãéã®éä¿¡ãã£ãã«ã確ç«ããããã«ãååä»ããã€ããèµ·åãããŸãã 次ã®è¡ããäœæãããŸãã
\\\\.\\pipe\\Winsock2\\CatalogChangeListener-FFFF-F
FFFF-Fãã¿ãŒã³ã¯ãçŸåšã®ãŠãŒã¶ãŒã®ã»ãã¥ãªãã£èå¥åïŒSIDïŒãšã¿ã€ã ã¹ã¿ã³ãããèšç®ãããå€ã«çœ®ãæããããŸãã
ããšãã°ãçŸåšã®æ¥ä»2017/04/24ããã³SIDïŒ
S-1-5-21-84813077-3085987743-2510664113-1000
ååä»ããã€ãã®æåŸã«ãã³ãã¬ãŒããäœæããã«ã¯ã次ã®èšç®ãå®è¡ãããŸãã
time = SystemTime.wDay * Systemtime.wMonth * SystemTime.wYear = 24 * 04 * 2017 = 0x2f460
xsid = (1 * 21 * 84813077 * 3085987743 * 2510664113 * 1000) & 0xFFFFFFFF = 0xefa252d8
((time >> 20) + (time & 0xFFF) + ((time >> 12) & 0xFFF)) % 0xFF = 0x93
((xsid >> 20) + (xsid & 0xFFF) + ((xsid >> 12) & 0xFFF)) % 0xFF = 0x13
((time * xsid >> 24) + (uint8_t)(time * xsid) + ((uint16_t)(time * xsid) >> 8) + (uint8_t)(time * xsid >> 16)) % 0xf) = 0xa
ãã®å Žåã®ååä»ããã€ãïŒ
\\\\.\\pipe\\Winsock2\\CatalogChangeListener-9313-a
çŸåšã®ãŠãŒã¶ãŒã®SIDã埩å ã§ããªãå Žåãããã©ã«ãã§æ¬¡ã®ååä»ããã€ãã䜿çšãããŸãã
\\\\.\\pipe\\\Winsock2\\CatalogChangeListener-FFFE-D
ã¹ããªãŒã ååã«ããã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³
ãªã¢ãŒãããã»ã¹ã§ãªãŒã±ã¹ãã¬ãŒã¿ãŒãå®è£ ããã«ã¯ãããŸãäžè¬çã§ã¯ãªãæ¹æ³ã䜿çšãããŸãã
ãªã¢ãŒãããã»ã¹ããã®å®è¡å¯èœã¹ã¬ããã¯ãéä¿¡ã¢ãžã¥ãŒã«ã®ãšã³ããªãã€ã³ããå®è¡ããã·ã§ã«ã³ãŒããå®è¡ããããã«ã€ã³ã¿ãŒã»ãããããŸãã
1.ã¢ãžã¥ãŒã«ãšã·ã§ã«ã³ãŒãããªã¢ãŒãããã»ã¹ã«ã³ããŒãããŸãã
2.
ZwQuerySystemInformation
é¢æ°
ZwQuerySystemInformation
䜿çšããŠãã¿ãŒã²ããããã»ã¹ã§å®è¡ãããŠããã¹ã¬ããã®ç·æ°ãååŸããŸãã
3.åã¹ã¬ããã§ã次ã®æäœãå®è¡ãããŸãã
-
OpenThread/SuspendThread
ã«ãã£ãŠäžæãããã¹ã¬ããã - ã¹ã¬ããã³ã³ããã¹ãã¯
GetThreadContext
ã䜿çšããŠååŸãããŸãã - ã¹ã¬ããã³ãã³ããã€ã³ã¿ãŒãä¿åãããã·ã§ã«ã³ãŒããæãããã«å€æŽãããŸãïŒ
SetThreadContext
ïŒã - ã¹ã¬ããã¯
ResumeThread
ã䜿çšããŠåéãResumeThread
ã
4.åã®æäœã®ãããããå®è¡ãããªãå Žåãã¹ã¬ãããåéããåãæäœãå¥ã®ã¹ã¬ããã§å®è¡ãããŸãã
launcher:
push rax
sub rsp, 38h
movabs rax, 5D20092 ; @ end of payload
mov qword ptr ss:[rsp+28], rax ; lpThreadId
mov qword ptr ss:[rsp+20], 0 ; dwCreationFlags
xor r9d, r9d ; lpParameter
movabs r8, 5D20046 ; lpStartAddress => @payload
xor edx, edx ; dwStackSize = 0
xor ecx, ecx ; lpThreadAttributes = NULL
call qword ptr ds:[CreateThread]
movabs rax, 90A7FACE90A7FACE ; replaced by the saved instruction pointer from thread context ;)
add rsp, 38h
xchg qword ptr ss:[rsp], rax
ret
payload:
sub rsp, 28
movabs r8, 5D20096
mov edx, 1
movabs rcx, 4000000000000000
call qword ptr ds: [DllEntryPoint]
xor ecx, ecx
call ExitThread
int 3
xxxx; @DllEntryPoint
xxxx ; @CreateThread
xxxx; @ExitThread
xxxx
xxxx
xxxx
xxxx ; TID
ã·ã§ã«ã³ãŒãã¯ãæ°ããã¹ã¬ããã®ã¢ãžã¥ãŒã«ãšã³ããªãã€ã³ããå®è¡ããããŒããŒã§ãã
ããŒã¿ä¿å
ããŒããŒã¯ãååä»ããã€ããä»ããŠãªãŒã±ã¹ãã©ã«ãã€ããªããŒã¿ãéä¿¡ããŸãã Blobã«å«ãŸãããã®ïŒ
- ããŒã èå¥åïŒ
CMC_TAKE_LOADER_BODY
- ããŒãããŒããŒã®ãã¡ã€ã«ãã¹
- PEããŒãããŒããŒ
ãªãŒã±ã¹ãã©ãã¡ãã»ãŒãžãåä¿¡ãããšããã¡ã€ã«ã®å 容ãäžæžããã
DeleteFile
é¢æ°ã䜿çšããŠããŒãããŒããŒãå®å šã«åé€ããŸãã
æ°žç¶æ å ±ã¯ãªãœãŒã¹105ããååŸãããGazerã«ä¿åãããŸãã ãã®ããŒã¿ã®äžã«ã¯ãããŒã¿ã¹ãã¬ãŒãžã¢ãŒããéžæããããã«äœ¿çšããã
dword
å€ããããŸãã
ãªãœãŒã¹105ã¯æ¬¡ã®ããã«æ§æãããŠããŸãã
-
dword
å€ã¯ããŒã¿ã¹ãã¬ãŒãžã¢ãŒãã瀺ããŸã -
dword
å€ã¯ããŒã¿ã®éã瀺ããŸã - ããŒã¿ä¿ææ å ±
6ã€ã®ç°ãªãããŒã¿ã¹ãã¬ãŒãžã¢ãŒãããããŸãã
0ïŒShellAutorun
æ°žç¶æ§ã¯ã次ã®ããŒã®å€
explorer.exe, %malware_pathfile%
ã䜿çšããŠã·ã§ã«ãã©ã¡ãŒã¿ãŒãè¿œå ããããšã«ãããWindowsã¬ãžã¹ããªãä»ããŠå®çŸãããŸãã
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
1ïŒHiddenTaskAutorun
以äžã§èª¬æããTaskScheduler AutorunïŒ4ïŒã¡ãœããã«éåžžã«äŒŒãŠããŸãã äž»ãªéãã¯ã
TASK_FLAG_HIDDEN
ïŒ
Itask
ã€ã³ã¿ãŒãã§ã€ã¹ãã
SetFlags
ã¡ãœãããä»ããŠèšå®ïŒã䜿çšããŠãã¿ã¹ã¯ããŠãŒã¶ãŒããé ãããŠããããšã§ãã
2ïŒScreenSaverAutorun
ãã®ã¢ãŒãã§ã¯ãGazerã¯ã¹ã¯ãªãŒã³ã»ãŒããŒãšããŠäœ¿çšãããå®è¡å¯èœãã¡ã€ã«ãWindowsã¬ãžã¹ããªã«ã€ã³ã¹ããŒã«ããããšã§æ°žç¶æ§ãæäŸããŸãã
ã»ãšãã©ã®ãã©ã¡ãŒã¿ãŒã¯ãã¬ãžã¹ããªãã©ã³ã
HKCU\Control Panel\Desktop
äœæãã
HKCU\Control Panel\Desktop
ã
- æªæã®ããå®è¡å¯èœãã¡ã€ã«ãžã®
SCRNSAVE.exe
ãã¹ -
ScreenSaveActive
å€ã¯1ã§ãïŒã¹ã¯ãªãŒã³ã»ãŒããŒãæå¹ã«ããŸã -
ScreenSaverIsSecure
å€ã¯0ïŒã¹ã¯ãªãŒã³ã»ãŒããŒã¯ãã¹ã¯ãŒãã§ä¿è·ãããŠããŸãã -
ScreenSaveTimeout
ããªãœãŒã¹ã§æå®ãããå€ã«èšå®ãããŸãã ã¹ã¯ãªãŒã³ã»ãŒããŒïŒãã®å Žåã¯ãã«ãŠã§ã¢ïŒãèµ·åããåã«ãã·ã¹ãã ãã¹ã¿ã³ãã€ã¢ãŒãã®ãŸãŸã§ããæéã瀺ããŸãã
3ïŒStartupAutorun
ãªãœãŒã¹105ãå€
dword
3ã§å§ãŸãå Žåã[ã¹ã¿ãŒã]ã¡ãã¥ãŒã«LNKãã¡ã€ã«ãäœæãããŸãã ãã®ãªãœãŒã¹ã¯ãLNKã®ã·ã§ãŒãã«ãããã¡ã€ã«ã®èª¬æããã¹ãããã³ãã¡ã€ã«åãæäŸããŸãã
IshellLink
ã€ã³ã¿ãŒãã§ã€ã¹
IshellLink
ãã·ã§ã«åç §ãäœæããããã«äœ¿çšãããŸãã
4ïŒTaskSchedulerAutorun
ãã®ã¡ãœããã¯ãèšç»ãããã¿ã¹ã¯ãäœæããŠæ°žç¶æ§ãå®çŸããããã«äœ¿çšãããŸãã
ã¿ã¹ã¯ã¯ãã¿ã¹ã¯ïŒ
ITaskService, ITaskSettings, âŠ
ïŒã«é¢é£ä»ããããCOMã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠäœæããã³æ§æãããŸãã
äžéšã®æ å ±ãç¹ã«ã¿ã¹ã¯ã®ååãšãã®èª¬æã¯ããªãœãŒã¹ããæœåºãããŸãã ããšãã°ããµã³ãã«ãªãœãŒã¹ã®1
TaskSchedulerAutorun
ãããŒã¿ã¹ãã¬ãŒãžã¢ãŒãã¯ããŒã¿ã䜿çšããŠ04ïŒ
TaskSchedulerAutorun
ïŒã«èšå®ãããŸãã
%APPDATA%\Adobe\adobeup.exe Adobe Acrobat Reader Updater. This task was generated by Adobe Systems, Inc to keep your Adobe Software up-to-data. \Adobe\AcrobatReader.Adobe
ãã®äŸã§ã¯ã次ã®ããã«ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ãäœæããã³æ§æãããŸãã
1.ã¿ã¹ã¯åïŒ
"Adobe Acrobat Reader Updater"
2.å®è¡å¯èœãã¡ã€ã«ïŒ
"%APPDATA%\Adobe\adobeup.exe"
ãªãŒã±ã¹ãã©ã¯ããã®å Žæã®ååä»ããã€ãã§åä¿¡ããããŒãããŒããŒãã³ããŒããŸã
3.ã¿ã¹ã¯ã®èª¬æïŒ
" Adobe Systems, Inc Adobe"
4.ã¿ã¹ã¯ãã©ã«ããŒïŒ
\Adobe\AcrobatReader.Adobe
\Adobe\AcrobatReader.Adobe
æåŸã«ãã¿ã¹ã¯ã¯ãã¹ã±ãžã¥ãŒã«ãããæéãçµéããåŸããã€ã§ãã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã«ãã£ãŠèµ·åãããããã«æ§æãããŸãã çŸåšã®ãŠãŒã¶ãŒããã°ã€ã³ãããšãã¿ã¹ã¯ãèµ·åãããŸãã
5ïŒLinkAutorun
ãã®ã¡ãœããã¯ãcmd.exeãä»ããŠãã«ãŠã§ã¢ãå®è¡ããããã«æ¢åã®LNKãã¡ã€ã«ãå€æŽããŸãã
ãªãœãŒã¹ã§æå®ããããã©ã«ããŒå ã®åLNKãã¡ã€ã«ã«ã€ããŠãã¢ã€ã³ã³ãšåŒæ°ãåé€ãããŸãã cmd.exeã®ãã¹ã¯ãåŒæ°ã§æå®ãããŸãã
/q /c start "%s" && start "%s"
調æ»ããã»ãšãã©ã®ãµã³ãã«ã§ãæ§æãã¡ã€ã«ã¯TaskSchedulerAutorunã¡ãœããã䜿çšããå¿ èŠãããããšã瀺ããŠããŸãã
éèª
3ã€ã®Gazerã³ã³ããŒãã³ãã¯ãã¹ãŠããã°ãã¡ã€ã«ã«ã¢ã¯ã·ã§ã³ãæžã蟌ã¿ãŸãã ãããã¯åãã¢ã«ãŽãªãºã -3DESã䜿çšããŠæå·åãããŸãã
Gazerã®äžéšã®ããŒãžã§ã³ã§ã¯ããããã®ãã¡ã€ã«ã¯ãã€ããªãã¡ã€ã«ã«ããŒãã³ãŒãã£ã³ã°ãããŠããããããããã®ãã¡ã€ã«ãç°¡åã«ååŸã§ããŸãã
-
%TEMP%\CVRG72B5.tmp.cvr
ïŒããŒãããŒããŒãã° -
%TEMP%\CVRG1A6B.tmp.cvr
ïŒãªãŒã±ã¹ãã©ãã° -
%TEMP%\CVRG38D9.tmp.cvr
ïŒéä¿¡ã¢ãžã¥ãŒã«ã®ãã°
åãã°ãã¡ã€ã«ã®æ§é ã¯æ¬¡ã®ãšããã§ãã
[LOGSIZE] [DECRYPTION_KEY] [ENCRYPTED_LOG]
- logsizeïŒãã®å€ïŒ2ãã€ãïŒãããžãã¯çªå·0xf18bããæžç®ããããšãæå·åããããã°ã®ãµã€ãºãååŸãããŸãã
- encryption_keyïŒãã®12ãã€ãã®blobãã䜿çšããŠ12ãã€ãã®å¥ã®ããŒãã³ãŒããããããŒã§æå·åããããšããã°ã解èªããããã«äœ¿çšã§ãã3DESããŒãååŸããŸã
- encrypted_logïŒãã°ã¯CBCã¢ãŒãã§3DESã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸã
埩å·ååŸãåãã°ãšã³ããªã¯æ¬¡ã®ããã«ãã©ãŒããããããŸãã
|æéïŒæå°ïŒç§ïŒMs | [ãã°ID] [ãã°]
以äžã¯ã埩å·åããããªãŒã±ã¹ãã¬ãŒã¿ãŒãã°ãã¡ã€ã«ã®äŸã§ãã
|10:29:56:197| [1556]
|10:29:56:197| [1557] ******************************************************************************************
|10:29:56:197| [1558] DATE: 25.05.2017
|10:29:56:197| [1559] PID=900 TID=2324 Heaps=32 C:\Windows\Explorer.EXE
|10:29:56:197| [1565] DLL_PROCESS_ATTACH
|10:29:56:197| [1574] 4164
|10:29:58:197| [0137] ==========================================================================
|10:29:58:197| [0138] Current thread = 2080
|10:29:58:197| [0183] Heap aff0000 [34]
|10:29:58:197| [0189] ### PE STORAGE ###
|10:29:58:197| [0215] ### PE CRYPTO ###
|10:29:58:197| [0246] ### EXTERNAL STORAGE ###
|10:29:58:197| [1688] Ok
|10:29:58:197| [0279] Path = \HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ScreenSaver
|10:29:58:197| [0190] \HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ScreenSaver
|10:29:58:197| [0338] ---FAILED
|10:29:58:197| [0346] Initializing standart reg storage...
|10:29:58:197| [0190] Software\Microsoft\Windows\CurrentVersion\Explorer\ScreenSaver
|10:29:58:197| [2605] Storage is empty!
|10:29:58:197| [0392] ### EXTERNAL CRYPTO ###
|10:29:59:666| [1688] Ok
|10:29:59:713| [1473] Ok
|10:29:59:760| [1688] Ok
|10:29:59:775| [1473] Ok
|10:29:59:775| [1688] Ok
|10:29:59:775| [1473] Ok
|10:29:59:791| [1688] Ok
|10:29:59:791| [1473] Ok
|10:29:59:806| [1688] Ok
|10:29:59:806| [1473] Ok
|10:29:59:806| [0270] 08-00-27-90-05-2A
|10:29:59:806| [0286] _GETSID_METHOD_1_
|10:29:59:806| [0425] 28 7 8 122
|10:29:59:806| [0463] S-1-5-21-84813077-3085987743-2510664113-1000
|10:29:59:806| [0471]
|10:29:59:806| [0787] Ok
|10:29:59:806| [1473] Ok
|10:29:59:822| [0514] ### QUEUES ###
|10:29:59:822| [0370] T Empty
|10:29:59:822| [0482] R Empty
|10:29:59:822| [1754] Ok
|10:29:59:822| [1688] Ok
|10:29:59:822| [1473] Ok
|10:29:59:838| [0505] R #4294967295 PR_100 TR_00000000 SZ_172 SC_0(50) --+- EX_0
|10:29:59:838| [0625] ### TRANSPORT ###
|10:29:59:838| [0286] _GETSID_METHOD_1_
|10:29:59:838| [0425] 28 7 25 122
|10:29:59:838| [0463] S-1-5-21-84813077-3085987743-2510664113-1000
|10:29:59:838| [0471]
|10:29:59:838| [0165] \\.\pipe\Winsock2\CatalogChangeListener-2313-4
|10:29:59:838| [0131] PipeName = \\.\pipe\Winsock2\CatalogChangeListener-2313-4
|10:29:59:838| [0041] true
[...]
å€ãããŒãžã§ã³ã®Gazerã§ã¯ãããã°IDãã¯çŸåšã®é¢æ°ã®ååã«çœ®ãæããããããšã«æ³šæããŠãã ããã
äœæ¥ãã£ã¬ã¯ããª
Windowsã¬ãžã¹ããªã䜿çšãã
ãã¹ãŠã®Gazeré¢é£ãã¡ã€ã«ïŒãã°ãé€ãïŒã¯ãæå·åããã圢åŒã§ã¬ãžã¹ããªã«ä¿åãããŸãã
OrchestratorãªãœãŒã¹109ã«ã¯ãããŒã«ãã®
%RootStoragePath%
ïŒã¬ããŒãã§ã¯
%RootStoragePath%
ãšåŒã°ããïŒãå«ãŸããŠããŸãã 調æ»ããåãµã³ãã«ã§ããã®ãªãœãŒã¹ã¯åãã¹ãã¬ãŒãžãã¹ãæããŠããŸããã
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ScreenSaver
ãã®ãªãœãŒã¹ã空ã®å Žåãããã©ã«ãã§ã¬ãžã¹ããªããŒã䜿çšãããŸãã RSAããŒãé€ããã¹ãã¬ãŒãžå ã®ãã¹ãŠã®ããŒã¿ã¯æå·åãããŸãã
ããã€ãã®ãµããã£ã¬ã¯ããªãäœæãããŸãïŒãããã®ååã¯ãã€ããªåœ¢åŒã§ããŒãã³ãŒãã£ã³ã°ãããŠããŸãïŒïŒ
%RootStoragePath%{119D263D-68FC-1942-3CA3-46B23FA652A0}
ãªããžã§ã¯ãIDïŒè¢«å®³è ãèå¥ããäžæã®ID
%RootStoragePath%{1DC12691-2B24-2265-435D-735D3B118A70}
ã¿ã¹ã¯ãã¥ãŒïŒãªã³ã¯ãããã¿ã¹ã¯ãªã¹ã
%RootStoragePath%{28E74BDA-4327-31B0-17B9-56A66A818C1D}
ãã©ã°ã€ã³
%RootStoragePath%{31AC34A1-2DE2-36AC-1F6E-86F43772841F}
éä¿¡ã¢ãžã¥ãŒã«ïŒCïŒCãµãŒããŒãšã®éä¿¡çšDLL
%RootStoragePath%{3CDC155D-398A-646E-1021-23047D9B4366}
èªåå®è¡ïŒæ°žç¶åã¡ãœãã
%RootStoragePath%{4A3130BD-2608-730F-31A7-86D16CE66100}
ããŒã«ã«ãã©ã³ã¹ããŒãèšå®ïŒåããããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒã®IPã¢ãã¬ã¹
%RootStoragePath%{56594FEA-5774-746D-4496-6361266C40D0}
æçµæ¥ç¶ïŒCïŒCãµãŒããŒãžã®æçµæ¥ç¶ã®æå»ïŒSYSTEMTIMEïŒ
%RootStoragePath%{629336E3-58D6-633B-5182-576588CF702A}
RSAç§å¯éµïŒããã»ã¹ã§çæãããGazerããŒã¿ã®è§£èªã«äœ¿çšãããŸã
%RootStoragePath%{6CEE6FE1-10A2-4C33-7E7F-855A51733C77}
çµæãã¥ãŒïŒã¿ã¹ã¯çµæã®ãªã³ã¯ãªã¹ã
%RootStoragePath%{81A03BF8-60AA-4A56-253C-449121D61CAF}
æ¿å ¥èšå®ïŒéä¿¡ã¢ãžã¥ãŒã«ã®å®è£ ã«äœ¿çšãããããã»ã¹ã®ãªã¹ã
%RootStoragePath%{8E9810C5-3014-4678-27EE-3B7A7AC346AF}
CïŒCãµãŒããŒ
代æ¿ããŒã¿ã¹ããªãŒã ã®äœ¿çš
ã¬ãžã¹ããªã¢ã¯ã»ã¹ãå©çšã§ããªãå Žåããããã®æ§æã¢ã€ãã ã¯ä»£æ¿ããŒã¿ã¹ããªãŒã ã䜿çšããŠä¿åãããŸãã
GetVolumeInformation()
é¢æ°ã¯ãCïŒ\\ãã©ã€ããADSã䜿çšããããã®ååä»ãã¹ããªãŒã ããµããŒãããŠããããšã確èªããããã«
GetVolumeInformation()
ããŸãã
äžèšãšåãGUIDã䜿çšããŠããã¡ã€ã«ã®ããŒã¿ãADSã§é衚瀺ã«ããŸãïŒãã€ããªåœ¢åŒã§ããŒãã³ãŒããããŠããŸãïŒïŒ
"%TEMP%\\KB943729.log"
ããšãã°ããªããžã§ã¯ãIDã«ã¢ã¯ã»ã¹ããããã®å®å šãªãã¹ã¯æ¬¡ã®ãšããã§ãã
%TEMP%\KB943729.log:{1DC12691-2B24-2265-435D-735D3B118A70}
ãªãŒã±ã¹ãã¬ãŒã¿ãŒ
GazerãªãœãŒã¹
Gazeré¢é£ã®ãã¡ã€ã«ã¯ããªãŒã±ã¹ãã©ã®ãªãœãŒã¹ã«ä¿åãããŸãã
ãã¡ã€ã«åœ¢åŒ
åèš11ã®ãªãœãŒã¹ïŒ101ã111ïŒã¯ã次ã®ããã«æ§æãããŠããŸãã
ããŒã¿ã¿ã€ã| ãµã€ãº| ããŒã¿| ããã£ã³ã°
DATATYPEïŒ
dword
ã¯ãªãœãŒã¹ã®ããŒã¿åãå®çŸ©ããŸãïŒ
- 0ïŒäžæ¬¡ããŒã¿
- 0xFFFFFFFFïŒç©º
- 0x4ïŒå®çŸ©ãããŠããŸãã
- 0x1030001ïŒæååã®é å
- 0x1ïŒãã€ããªåœ¢åŒ
ãµã€ãºïŒããŒã¿éïŒå å¡«ãªãïŒ
æå·å
RSAããŒã§ãããªãœãŒã¹101ããã³102ãé€ããåãªãœãŒã¹ã¯Bzipã䜿çšããŠããã¯ããã3DESã§æå·åãããŸãã
[RSAEncryptedBlob] [SignatureBlob] [3DESBlob]
- RSAEncryptedBlobïŒããŒã¿ã®æåã®1024ãããã¯ã3DESããŒãå«ãblobã§ãã Blobã¯RSAã䜿çšããŠæå·åããããªãœãŒã¹101ã䜿çšããŠåŸ©å·åã§ããŸãã
- SignatureBlobïŒ2çªç®ã®ããŒã¿ã¯ã埩å·åãããæåŸã®ããŒã¿ã®çœ²åãå«ã1024ãããã®blobã§ãã
- 3DESBlobïŒæåŸã®éšåã¯ãæåã®blobã®3DESããŒã§æå·åãããå®éã®ããŒã¿ã§ãã
åãªãœãŒã¹ã¯åçã«åŸ©å·åãããŸãã 眲åã¯åŸ©å·åãããããŒã¿ã«å¯ŸããŠæ€èšŒãããæŽåæ§ãæ€èšŒãããŸãã 次ã«ããªãœãŒã¹ã¯ãªãŒã±ã¹ãã¬ãŒã¿ãŒã³ãŒãã§ã©ã³ãã ã«çæãããæ°ããRSAããŒã§æå·åãããŸãã ç§å¯ããŒãšæå·åããããªãœãŒã¹ã¯ãç¹å®ã®GUIDãµãããŒã®äžã®ã¬ãžã¹ããªã«ä¿åãããŸãã
ãªãœãŒã¹ãªã¹ãïŒ
- 101ïŒãªãœãŒã¹ã«ç§å¯RSAããŒãå«ãŸããŠããŸãã ä»ã®ãªãœãŒã¹ã埩å·åããããã«äœ¿çšãããŸãã
- 102ïŒRSAå ¬ééµã
- 103ïŒç©º
- 104ïŒå®çŸ©ãããŠããŸãã
- 105ïŒããŒã¿ã¹ãã¬ãŒãžæ å ±
- 106ïŒéä¿¡ã¢ãžã¥ãŒã«ã®å®è£ ã«äœ¿çšãããããã»ã¹ã®ãªã¹ã
- 107ïŒCããã³CãµãŒããŒãšã®éä¿¡çšDLL
- 108ïŒCïŒCãµãŒããŒã®ãªã¹ã
- 109ïŒGazeräœæ¥ãã£ã¬ã¯ããªãžã®ãã¹
- 110ïŒãã©ã°ã€ã³ãªã¹ã
- 111ïŒããŒã«ã«ããŒã¿è»¢éæ å ±
ã¿ã¹ã¯å®äº
CïŒCãµãŒããŒããåä¿¡ããã¿ã¹ã¯ã¯ãææãããã·ã³ãŸãã¯ãããã¯ãŒã¯äžã®å¥ã®ã³ã³ãã¥ãŒã¿ãŒã«ãã£ãŠP2Pã¡ã«ããºã ãä»ããŠå®è¡ãããŸãïŒCarbonããã³Snakeã®å Žåãšåæ§ïŒã
å¯èœãªã¿ã¹ã¯ïŒ
- ãã¡ã€ã«ãéä¿¡
- ãã¡ã€ã«ãã¢ããããŒã
- æ§æãæŽæ°ãã
- ã³ãã³ããå®è¡ãã
çµæã¯ãã¥ãŒã«ä¿åãããã¢ãžã¥ãŒã«ã«éä¿¡ãããŸããã¢ãžã¥ãŒã«ã¯ãã€ã³ã¿ãŒããããå©çšå¯èœãªãšãã«CïŒCãµãŒããŒã«æ¥ç¶ããŸãã
ã¯ã©ã¹éå±€
ãã«ãŠã§ã¢ã¯C ++ã§èšè¿°ãããŠãããã³ãŒãã§äœ¿çšãããŠãããªããžã§ã¯ãã«é¢ããæ å ±ãå«ãRTTIã¯äžæžããããŸããã
5ã€ã®æœè±¡ã¯ã©ã¹ããããŸãã


éä¿¡ã¢ãžã¥ãŒã«
éä¿¡ã¢ãžã¥ãŒã«ã¯ãCïŒCãµãŒããŒããã¿ã¹ã¯ãæœåºãããªãŒã±ã¹ãã©ã«è»¢éããããã«äœ¿çšãããŸãã
ã©ã€ãã©ãªã¯ãåæ³çã«ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããããã»ã¹ã«çµã¿èŸŒãŸããŠããŸãã ã©ã€ãã©ãªã¯ã
explorer.exe
ãªãŒã±ã¹ãã©ã«å ¥ãããã«äœ¿çšãããããŒãããŒããŒãšåãã§ãã
éä¿¡ã®åæå
ãããã·ãµãŒããŒãååšããå ŽåãGazerãHTTPãªã¯ãšã¹ããå®è¡ããããã«ååŸããŠäœ¿çšããŸãã ãã®å€ãååŸããã«ã¯ã2ã€ã®æ¹æ³ããããŸãã
ã¬ãžã¹ããªãããããã·ãµãŒããŒãååŸã§ããªãå Žåã¯ããã®ã¬ãžã¹ããª
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
èŠæ±ãããã
INTERNET_OPTION_PROXY
ãã©ã°ãæå®ããŠ
InternetQueryOption
é¢æ°ã䜿çšããŸãã
次ã«ãã·ã¹ãã ãŠãŒã¶ãŒãšãŒãžã§ã³ããæ§æãããŸãã
- ããŒ
HKCU\Software\Microsoft\Windows\Current Version\Internet Settings
ã®ãŠãŒã¶ãŒãšãŒãžã§ã³ãããŒã¿ããŒã®å€ãååŸããŸãã - ããŒå€ã¯ã
HKLM\Software\Microsoft\Windows\Current Version\Internet Settings\5.0\User Agent\Post Platform
ã»ã¯ã·ã§ã³ã«ãªã¹ããããŠãHKLM\Software\Microsoft\Windows\Current Version\Internet Settings\5.0\User Agent\Post Platform
ã IEAKããŒã¿ãæã€ãã®ã¯ãŠãŒã¶ãŒãšãŒãžã§ã³ãã«æ¥ç¶ãããŸãã - ã¬ãžã¹ããªã«ãŠãŒã¶ãŒãšãŒãžã§ã³ããèŠã€ãããªãå Žåã¯ãããŒãã³ãŒããããUA
Mozilla/4.0 (compatible; MSIE 6.0)
CïŒCãµãŒããŒãžã®ã¢ã¯ã»ã¹ãè©Šã¿ãåã«ãã€ã³ã¿ãŒãããæ¥ç¶ã確èªãããŸãã 次ã®ãµãŒããŒã次ã ãšèŠæ±ãããŸãã
-
update.microsoft.com
-
microsoft.com
-
windowsupdate.microsoft.com
-
yahoo.com
-
google.com
CïŒCãµãŒããŒãšã®éä¿¡
ãã«ãŠã§ã¢ã¯CïŒCãµãŒããŒãšããåãããŠã¿ã¹ã¯ãååŸãïŒHTTP GETãªã¯ãšã¹ãçµç±ïŒãå®è¡çµæãéä¿¡ããŸãïŒHTTP POSTãªã¯ãšã¹ãçµç±ïŒã
ãµãŒããŒã«èŠæ±ãéä¿¡ããåã«ã
CMC_GIVE_SETTINGS
ã³ãã³ããéä¿¡ãã£ãã«ïŒæ¬¡ã®ã»ã¯ã·ã§ã³ã§è©³ãã説æãããã£ãã«ãšåŒã°ããïŒãä»ããŠ
CMC_GIVE_SETTINGS
éä¿¡ãããŸãã ãã®å Žåããã±ããã«å«ãŸããã¡ãã»ãŒãžïŒ
MSG
ïŒã¯ãã¹ããŒã¿ã¹ã«ã€ããŠãªãŒã±ã¹ãã©ã«ãã£ãŠèšå®ããã1ãã€ãã§ãã
CïŒCã®ãªã¯ãšã¹ããéä¿¡ããåã«ãCMC_GIVE_SETTINGSããŒã ã¯éä¿¡ãã£ãã«ïŒãã£ãã«ãšåŒã°ããŸããããã«ã€ããŠã¯æ¬¡ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãïŒãä»ããŠãªãŒã±ã¹ãã©ã«éä¿¡ãããŸãã ãã®å Žåããã±ããã«å«ãŸããã¡ãã»ãŒãžCMC_GIVE_SETTINGSã¯ãã³ãã³ãã®çµæã®ã¹ããŒã¿ã¹ã«å¯ŸããŠãªãŒã±ã¹ãã©ã«ãã£ãŠèšå®ããã1ãã€ãã§ãã
ãªãŒã±ã¹ãã¬ãŒã¿ãŒã¯ããªããžã§ã¯ãèå¥åãCïŒCãµãŒããŒã®ãªã¹ããããã³æåŸã®æ¥ç¶ã®æ¥ä»ã䜿çšããŠãäœæ¥ãã£ã¬ã¯ããªããååŸããèšå®ã䜿çšããŠåããã£ãã«ã§å¿çããŸãã
CïŒCãµãŒããŒããã¿ã¹ã¯ãååŸããã«ã¯ãGETãªã¯ãšã¹ããå®è¡ãããŸãã
GETãªã¯ãšã¹ããã©ã¡ãŒã¿ã¯ãçããããšæãããªãããŒãã³ãŒããããããŒã¯ãŒãã®ãªã¹ãããéžæãããŸãã ãšã³ã³ãŒã[a-z0-9]ã§å€ãã©ã³ãã ã«çæãããåãã©ã¡ãŒã¿ãŒã®ãµã€ãºãã©ã³ãã ã«ãªããŸãã
â¢
id
[6-12]
â¢
hash
[10-15]
â¢
session
[10-15]
â¢
photo
[6-10]
â¢
video
[6-10]
â¢
album
[6-10]
â¢
client
[5-10]
â¢
key
[5-10]
â¢
account
[6-12]
â¢
member
[6-12]
â¢
partners
[5-10]
â¢
adm
[6-12]
â¢
author
[6-12]
â¢
contact
[6-12]
â¢
content
[6-12]
â¢
user
[6-12]
ãã®ãããªã¯ãšãªã®äŸã次ã«ç€ºããŸãã
xxx.php?album=2ildzq&key=hdr2a&partners=d2lic33f&session=nurvxd2x0z8bztz&video=sg508tujm&photo=4d4idgk
xxx.php?photo=he29zms5fc&user=hvbc2a&author=xvfj5r0q9c&client=7mvvc&partners=t4mgmuy&adm=lo3r6v4
xxx.php?member=ectwzo820&contact=2qwi15&album=f1qzoxuef4&session=x0z8bztz8hrs65f&id=t3x0ftu9
xxx.php?partners=ha9hz9sn12&hash=5740kptk3acmu&album=uef4nm5d&session=dpeb67ip65f&member=arj6x3ljj
xxx.php?video=nfqsz570&client=28c7lu2&partners=818eguh70&contact=ibj3xch&content=1udm9t799ixr&session=5fjjt61qred9uo
èŠæ±ïŒéä¿¡ãåä¿¡ãæ¥ç¶ïŒããšã«ã
InternetSetOption
ã䜿çšããŠ10åã®ã¿ã€ã ã¢ãŠããèšå®ãã
InternetSetOption
ã
èŠæ±ãéä¿¡ããåŸãå¿çã¯ãè¿ãããHTTPã¹ããŒã¿ã¹èå¥åã404ã®å Žåã«ã®ã¿åŠçãããŸãã
å¿çã³ã³ãã³ãã¯æå·åããããªãŒã±ã¹ãã©ã«ãã£ãŠçæãããRSAç§å¯éµã䜿çšããŠåŸ©å·åã§ããŸãã ããã«ã¯blobãšMD5ããŒã¿ããã·ã¥ãå«ãŸããŸãã
å¿çãµã€ãºã20ãã€ãïŒ4ãã€ãã®blob +ããã·ã¥ïŒã®å ŽåãååŸããã¿ã¹ã¯ã¯ãããŸããã
CMC_TAKE_TASK
ã³ãã³ã
CMC_TAKE_TASK
ãCïŒCãµãŒããŒããåä¿¡ããæå·åãããã¿ã¹ã¯ãšãã®ãµã€ãºãšãšãã«ãªãŒã±ã¹ãã¬ãŒã¿ãŒã«éä¿¡ãããŸãã ãªãŒã±ã¹ãã©ã¯ãã¿ã¹ã¯ãå®äºããçµæãéä¿¡ã¢ãžã¥ãŒã«ã«éä¿¡ãã責任ãè² ããŸãã ïŒãªãŒã±ã¹ãã©ã«ãã£ãŠæå·åãããïŒå®è¡ã®çµæã¯ãGETãªã¯ãšã¹ãã®å Žåãšåãæ¹æ³ïŒã©ã³ãã ãªå€ãæã€ãã©ã¡ãŒã¿ãŒã䜿çšïŒã§POSTãªã¯ãšã¹ãã䜿çšããŠCïŒCãµãŒããŒã«éä¿¡ãããŸãã
ã³ã³ããŒãã³ãéã®ã¡ãã»ãŒãž
ã°ããŒãã«ååä»ããã€ãã¯ãç°ãªãã³ã³ããŒãã³ãéã®éä¿¡ã«äœ¿çšãããŸãã ãããä»ããŠéä¿¡ãããããŒã¿ã¯ã次ã®ããã«ãã©ãŒããããããŸãã

å³4.ã¡ãã»ãŒãžåœ¢åŒ
DATATYPEïŒåãå®æ°ããªãœãŒã¹ã«äœ¿çšãããŸãïŒãªãœãŒã¹ã®ç« ã®ãã¡ã€ã«åœ¢åŒã»ã¯ã·ã§ã³ïŒ
ID_CMDïŒã³ãã³ãåïŒä»¥äžãåç §ïŒ
MSGïŒéä¿¡ããããŒã¿
ã¡ãã»ãŒãžãªã¹ãïŒ
CMC_TAKE_TASK (ID_CMD: 1)
CïŒCãµãŒããŒããåä¿¡ããã¿ã¹ã¯ã¯ãªãŒã±ã¹ãã©ã«éä¿¡ããããªãŒã±ã¹ãã©ã¯ã¿ã¹ã¯ãã¥ãŒã«ä¿åããŸãã
CMC_TAKE_LOADER_BODY (ID_CMD: 2)
GazerããŒãããŒããŒãã¡ã€ã«ãåé€ãããªãœãŒã¹ã®1ã€ã«åŸã£ãŠããŒãããŒããŒãšãã®æ°žç¶ã¹ãã¬ãŒãžã®ã³ããŒãæ§æããŸã
CMC_GIVE_RESULT (ID_CMD: 4)
ã¡ãã»ãŒãžãåä¿¡ããåŸããªãŒã±ã¹ãã©ã¯çµæãã¥ãŒããã¿ã¹ã¯ã®çµæãæœåºããããã±ãŒãžåããå ¬éRSAããŒïŒãªãœãŒã¹102ïŒã䜿çšããŠæå·åããŠãããããéä¿¡ã¢ãžã¥ãŒã«ã«éä¿¡ããŸããéä¿¡ã¢ãžã¥ãŒã«ã¯ãµãŒããŒã«éä¿¡ããŸãïŒPOSTèŠæ±ïŒã
CMC_GIVE_SETTINGS (ID_CMD: 5)
éä¿¡ã¢ãžã¥ãŒã«ã¯ãã®ã¡ãã»ãŒãžããªãŒã±ã¹ãã©ã«éä¿¡ããŠããµãŒããŒãšã®æ¥ç¶ã«å¿ èŠãªæ å ±ïŒCïŒCãµãŒããŒã®ãªã¹ããæçµæ¥ç¶æéã被害è èå¥åïŒãèŠæ±ããŸãã
CMC_TAKE_CONFIRM_RESULT (ID_CMD: 6)
éä¿¡ã¢ãžã¥ãŒã«ãã¿ã¹ã¯ã®çµæããµãŒããŒã«éä¿¡ãããšããªãŒã±ã¹ãã¬ãŒã¿ãŒã«ã¡ãã»ãŒãžãéä¿¡ãããçµæããã¥ãŒããåé€ããããã«æ瀺ãããŸãã
CMC_TAKE_CAN_NOT_WORK (ID_CMD: 7)
æäœã倱æããå ŽåïŒããšãã°ãéä¿¡ã¢ãžã¥ãŒã«ããªãŒã±ã¹ãã©ããåä¿¡ããããŒã¿ãæ£ãã解éã§ããªãå ŽåïŒãæåŸã®ãšã©ãŒã³ãŒããå«ãã¡ãã»ãŒãžããªãŒã±ã¹ãã©ã«éä¿¡ãããŸãã ãã°ãã¡ã€ã«ã«ã³ãŒããè¿œå ã§ããŸãã
CMC_TAKE_UNINSTALL (ID_CMD: 8)
ãã£ã¹ã¯ãããã¡ã€ã«ãåé€ããããã«äœ¿çšãããŸãã
CMC_TAKE_NOP (ID_CMD: 9)
æäœãªã
CMC_NO_CONNECT_TO_GAZER (ID_CMD: 0xA)
éä¿¡ã¢ãžã¥ãŒã«ãã©ã®ãµãŒããŒãšãéä¿¡ã§ããªãå Žåãã³ãã³ãã¯ãªãŒã±ã¹ãã©ã«éä¿¡ãããŸãã ãã®å Žåãã¿ã¹ã¯ã®çµæããã¥ãŒã«ããå Žåãæå·åãããŠGazerã·ã¹ãã ã«ä¿åãããŸãã
CMC_TAKE_LAST_CONNECTION (ID_CMD: 0xB)
ã³ãã³ãã¯ãæ»æè ãã³ã³ãããŒã©ãŒãµãŒããŒãšã®éä¿¡ã確ç«ãããã³ã«ãéä¿¡ã¢ãžã¥ãŒã«ãããªãŒã±ã¹ãã©ã«éä¿¡ãããŸãã SystemTimeæ§é ïŒçŸåšã®ã·ã¹ãã æå»ãå«ãïŒãå«ãŸããŸãã ãªãŒã±ã¹ãã©ãã¡ãã»ãŒãžãåä¿¡ãããšãæåŸã®æ¥ç¶ã®æå»ãããã±ãŒãžåãããGazerãªããžããªïŒã¬ãžã¹ããªãŸãã¯ADSïŒã«æå·åãããŸãã
CMC_GIVE_CACHE / CMC_TAKE_CACHE (ID_CMD: 0xC / 0xD)
å®è£ ãããŠããŸãã
GazerããŒãžã§ã³
ãã«ãŠã§ã¢ã®4ã€ã®ããŒãžã§ã³ãæ€åºãããŸããã
æåã®ããŒãžã§ã³ã§ã¯ããã°ãèšé²ããããã«äœ¿çšãããé¢æ°ã¯ããã©ã¡ãŒã¿ãŒãšããŠé¢æ°ã®å®éã®ååãæã¡ãŸãã ã³ãŒããå®è£ ããã«ã¯ããŸããŸãªæ¹æ³ããããŸãã
2çªç®ã®ããŒãžã§ã³ã§ã¯ããã©ã¡ãŒã¿ãŒãšããŠäœ¿çšãããé¢æ°åã¯èå¥åã«çœ®ãæããããŸãã ã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ã«äœ¿çšãããã¡ãœããã¯1ã€ã ãã§ãã
æåã®ããŒãžã§ã³ã®äžéšã®ãµã³ãã«ã¯ãSolid Loop Ltdãçºè¡ããæå¹ãªComodo蚌ææžã§çœ²åãããŠããŸãã ç·šéã®æ¥ä»ã¯2002幎ã§ããã蚌ææžã2015幎ã«ãªãªãŒã¹ããããããåœé ããããšãã§ããŸãã 以äžã¯ãGazerããŒãžã§ã³ã®çœ²åã«äœ¿çšããã蚌ææžã§ãã

ææ°ããŒãžã§ã³ã¯ãå¥ã®èšŒææžã§çœ²åãããŠããŸã-Ultimate Computer Support Ltd. 䟵害ã®ææšãšããŠäœ¿çšã§ããæååãé£èªåããããã«ãããã€ãã®åªåãè¡ãããŸããã ãã¥ãŒããã¯ã¹åãšååä»ããã€ãã¯ã¯ãªã¢ããã¹ãã§è¡šç€ºãããªããªããXORããŒã§ãšã³ã³ãŒããããããã«ãªããŸããã
以åã®ããŒãžã§ã³ã§ã¯ããã°ãã¡ã€ã«åã¯ãã€ããªãã¡ã€ã«ã«ããŒãã³ãŒããããŠããŸããã çŸåšã§ã¯ãGetTempFileNameAé¢æ°ã䜿çšããŠã©ã³ãã ãªãã¡ã€ã«åãçæããŠããŸãã
2017幎ã«åéãããææ°ããŒãžã§ã³ã«ã¯ãç°ãªããžã£ãŒãã«ã¡ãã»ãŒãžããããŸãïŒãã ãããããã®æå³ã¯åãã§ãïŒã ããšãã°ã
PE STORAGE
EXE SHELTER
ã
PE CRYPTO
ã¯
EXE CIPHER
ãªã©ã«çœ®ãæããããŸãã
æåŸã«ãåœã®ã³ã³ãã€ã«ã¿ã€ã ã¹ã¿ã³ãã¯äœ¿çšãããªããªããŸããã
䟵害ã€ã³ãžã±ãŒã¿ã®å®å šãªãªã¹ãã¯ãGitHub ã¢ã«ãŠã³ãã§å ¥æã§ããŸã ã Turla / Gazerã«é¢é£ãã質åã«ã€ããŠã¯ãthreatintel @ eset.comãŸã§ãåãåãããã ããã
IoC
ãã¡ã€ã«åïŒ
%TEMP%\KB943729.log
%TEMP%\CVRG72B5.tmp.cvr
%TEMP%\CVRG1A6B.tmp.cvr
%TEMP%\CVRG38D9.tmp.cvr
%TEMP%\~DF1E06.tmp
%HOMEPATH%\ntuser.dat.LOG3
%HOMEPATH%\AppData\Local\Adobe\AdobeUpdater.exe
ã¬ãžã¹ããªããŒïŒ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ScreenSaver
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Explorer\ScreenSaver
CïŒCïŒ
daybreakhealthcare.co.uk/wp-includes/themees.php
simplecreative.design/wp-content/plugins/calculated-fields-form/single.php
169.255.137.203/rss_0.php
outletpiumini.springwaterfeatures.com/wp-includes/pomo/settings.php
zerogov.com/wp-content/plugins.deactivate/paypal-donations/src/PaypalDonations/SimpleSubsribe.
php
ales.ball-mill.es/ckfinder/core/connector/php/php4/CommandHandler/CommandHandler.php
dyskurs.com.ua/wp-admin/includes/map-menu.php
warrixmalaysia.com.my/wp-content/plugins/jetpack/modules/contact-form/grunion-table-form.php
217.171.86.137/config.php
217.171.86.137/rss_0.php
shinestars-lifestyle.com/old_shinstar/includes/old/front_footer.old.php
www.aviasiya.com/murad.by/life/wp-content/plugins/wp-accounting/inc/pages/page-search.php
baby.greenweb.co.il/wp-content/themes/san-kloud/admin.php
soligro.com/wp-includes/pomo/db.php
giadinhvabe.net/wp-content/themes/viettemp/out/css/class.php
tekfordummies.com/wp-content/plugins/social-auto-poster/includes/libraries/delicious/Delicious.php
kennynguyen.esy.es/wp-content/plugins/wp-statistics/vendor/maxmind-db/reader/tests/MaxMind/Db/
test/Reader/BuildTest.php
sonneteck.com/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/licence/templates/panel/
activation/activation.php
chagiocaxuanson.esy.es/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/
ngglegacy/admin/templates/manage_gallery/gallery_preview_page_field.old.php
hotnews.16mb.com/wp-content/themes/twentysixteen/template-parts/content-header.php
zszinhyosz.pe.hu/wp-content/themes/twentyfourteen/page-templates/full-hight.php
weandcats.com/wp-content/plugins/broken-link-checker/modules/checkers/http-module.php
ãã¥ãŒããã¯ã¹ïŒ
{531511FA-190D-5D85-8A4A-279F2F592CC7}