ãµãã©ã€ãã§ãŒã³ãžã®æ»æããŸãã¯ãµãŒãããŒãã£çµç¹ã§ã®ä¿¡é Œã®æªçšã«ããæ»æïŒãµãã©ã€ãã§ãŒã³æ»æïŒã¯ãæšççµç¹ã«ãã«ãŠã§ã¢ãæ¡æ£ããéåžžã«å¹æçãªæ¹æ³ã§ãã ããã¯ããµãã©ã€ãã§ãŒã³ãžã®æ»æã«ãããŠãæ»æè ãã¡ãŒã«ãŒ/ãµãã©ã€ã€ãŒãšã¯ã©ã€ã¢ã³ãéã®ä¿¡é Œé¢ä¿ãå©çšããŠãããŸããŸãªçç±ã§çµç¹ãå人ãæ»æããããã§ãã 2017幎åé ã«ãããã¯ãŒã¯ã«ãªãªãŒã¹ãããPetya / Nyetya / NePetyaã¯ãŒã ã¯ããããã®ã¿ã€ãã®æ»æãã©ãã»ã©å€§ãããã瀺ããŸããã å€ãã®å ŽåãPetyaã®å Žåã®ããã«ãåææ»æãã¯ãã«ã¯ãã°ããé ããããŸãŸã«ãªãããšããããŸãã
æè¿ãTalosã®ç 究è ã¯ãæ£åœãªãœãããŠã§ã¢ããã±ãŒãžãé åžããããã«éçºäŒç€Ÿã䜿çšããããŠã³ããŒããµãŒããŒããçããæããªã被害è ã®ã³ã³ãã¥ãŒã¿ãŒã«ãã«ãŠã§ã¢ãããŠã³ããŒãããããã«äœ¿çšãããã±ãŒã¹ã«æ°ä»ããŸããã äžå®æéãã¢ãã¹ãã«ãã£ãŠé åžãããCCleaner 5.33ã®ããŒãžã§ã³ã«ã¯ããã«ãã¹ããŒãžã®æªæã®ããè² è·ãå«ãŸããŠããŸããã æ¯é±500äžäººã®æ°ãããŠãŒã¶ãŒãCCleanerãããŠã³ããŒãããŠããŸãã åæ§ã®ãµã€ãºã®ææããã³ã³ãã¥ãŒã¿ã®ãããã¯ãŒã¯ã«ãã£ãŠåŒãèµ·ããããå¯èœæ§ã®ããæ害ãèæ ®ããŠãè¿ éã«è¡åããããšã決å®ãããŸããã 2017幎9æ13æ¥ãCisco Talosã¯ã¢ãã¹ãã«éç¥ããŸããã 次ã®ã»ã¯ã·ã§ã³ã§ã¯ããã®æ»æã«é¢ããç¹å®ã®è©³çŽ°ã«ã€ããŠèª¬æããŸãã
æè¡çãªè©³çŽ°
CCleanerã¯ãäžæãã¡ã€ã«ã®ã¯ãªãŒãã³ã°ãã·ã¹ãã ã®åæãããã©ãŒãã³ã¹ãæé©åããæ¹æ³ã®ç¹å®ãã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã管çããããç°¡åãªæ¹æ³ãªã©ã®æ©èœãå«ããŠãŒãã£ãªãã£ã§ãã
å³1ïŒCCleaner 5.33ã®ã¹ã¯ãªãŒã³ã·ã§ãã
2017幎9æ13æ¥ãæ°ãããšã¯ã¹ããã€ãæ€åºãã¯ãããžãŒã䜿çšããŠé¡§å®¢ãããŒã¿ãã¹ãããåŸãCisco Talosã¯ãã«ãŠã§ã¢ãšããŠèå¥ãããå®è¡å¯èœãã¡ã€ã«ãæ€åºããŸããã ããã¯ãæ£åœãªCCleanerããŠã³ããŒããµãŒããŒã®CCleaner v5.33ã€ã³ã¹ããŒã©ãŒã§ãã Talosã¯ãã»ãã¥ãªãã£ã·ã¹ãã ãCCleanerããããã¯ããåå ãç¹å®ããããã«åæåæãå®æœããŸããã ããŠã³ããŒãããå®è¡å¯èœãã¡ã€ã«ã¯æå¹ãªPiriformããžã¿ã«çœ²åã䜿çšããŠçœ²åããããã®ã®ãããŠã³ããŒããããã¢ããªã±ãŒã·ã§ã³ã¯CCleanerã ãã§ã¯ãªããšå€æããŸããã CCleaner 5.33ã®ã€ã³ã¹ããŒã«äžã32ãããã®CCleanerãã€ããªã«ã¯ããã¡ã€ã³çæã¢ã«ãŽãªãºã ïŒDGAïŒãšã³ãã³ãã¢ã³ãã³ã³ãããŒã«ïŒCommand and Control-C2ïŒæ©èœã䜿çšããæ©èœãåããæªæã®ããè² è·ãå«ãŸããŠããŸããã
CCleanerããŠã³ããŒããµã€ãã®ããŒãžã§ã³å±¥æŽããŒãžã衚瀺ãããšããã®ããŒãžã§ã³ïŒ5.33ïŒã2017幎8æ15æ¥ã«ãªãªãŒã¹ãããããšãããããŸããã 2017幎9æ12æ¥ã« ãããŒãžã§ã³5.34ããªãªãŒã¹ãããŸããã æªæã®ããè² è·ãå«ãããŒãžã§ã³ïŒ5.33ïŒã¯ããããã®æ¥ä»ã®éã«é åžãããŸããã ãã®ããŒãžã§ã³ã¯ãPiriform Ltdã«çºè¡ãããæå¹ãªèšŒææžã䜿çšããŠçœ²åãããŸãããPiriformLtdã¯ãæè¿ã·ãã³ããã¯ã®ã¢ãã¹ãã«ãã£ãŠååŸããã2018幎10æ10æ¥ãŸã§æå¹ã§ãã
å³2ïŒCCleaner 5.33ã®ããžã¿ã«çœ²å
ãã®è åšã«é¢é£ãã2çªç®ã®ã€ã³ã¹ããŒã©ãŒãµã³ãã«ãçºèŠãããŸããã ãã®ãµã³ãã«ãæå¹ãªããžã¿ã«èšŒææžã䜿çšããŠçœ²åãããŸããããã¿ã€ã ã¹ã¿ã³ãã¯æåã®ã¢ã»ã³ããªã眲åãããŠããçŽ15ååŸã§ããã
CCleaneræªæã®ãããã€ããªã«æå¹ãªããžã¿ã«çœ²åãååšããããšã¯ãéçºãŸãã¯çœ²åããã»ã¹äžã«éåãåŒãèµ·ãããé倧ãªåé¡ã瀺ããŠããå¯èœæ§ããããŸãã çæ³çã«ã¯ããã®èšŒææžã¯åãæ¶ãããã¹ãã§ãã æ°ãã蚌ææžãäœæãããšãã¯ãæ»æè ãæ°ãã蚌ææžã䟵害ãããå¯èœæ§ã®ããç°å¢ã«ããªãããšã確èªããå¿ èŠããããŸãã ãã®åé¡ã®ç¯å²ãšãã®æé©ãªè§£æ±ºæ¹æ³ã«é¢ãã詳现ãªæ å ±ãåéã§ããã®ã¯ã調æ»äžã®ã¿ã§ãã
次ã®ã³ã³ãã€ã«ã¢ãŒãã£ãã¡ã¯ããCCleanerãã€ããªã§èŠã€ãããŸããã
SïŒ\ workspace \ ccleaner \ branches \ v5.33 \ bin \ CCleaner \ Release \ CCleaner.pdb
ãã®ã³ã³ãã€ã«ã¢ãŒãã£ãã¡ã¯ããšæå¹ãªèšŒææžã䜿çšããŠãã€ããªãããžã¿ã«çœ²åããããšããäºå®ãèãããšãå€éšã®æ»æè ãéçºç°å¢ãŸãã¯ã¢ã»ã³ããªç°å¢ã®äžéšã䟵害ãããã®ã¢ã¯ã»ã¹ã䜿çšããŠæªæã®ããã³ãŒããCCleanerã¢ã»ã³ããªã«æ¿å ¥ããå¯èœæ§ããããŸãçµç¹ã«ãã£ãŠçºè¡ãããŸããã çµç¹å ã®éçºç°å¢ãŸãã¯ã¢ã»ã³ããªç°å¢ã«ã¢ã¯ã»ã¹ã§ããã€ã³ãµã€ããŒããæªæã®ããã³ãŒããæå³çã«ãªã³ã«ããããæ»æè ãã³ãŒããå€æŽã§ããããã«äŸµå®³ãããã¢ã«ãŠã³ããæã£ãŠããå¯èœæ§ããããŸãã
CCleanerã€ã³ã¹ããŒã©ãŒã®ä»¥åã®ããŒãžã§ã³ã¯çŸåšããŠã³ããŒããµãŒããŒã§å©çšå¯èœã§ãããæªæã®ãããã¡ã€ã«ãå«ãããŒãžã§ã³ã¯åé€ãããå©çšã§ããªããªã£ãŠããããšã«æ³šæããããšãéèŠã§ãã
ãŠã€ã«ã¹ã®ã€ã³ã¹ããŒã«ããã»ã¹
ã__scrt_get_dyn_tls_init_callbackãã¯ãCC_InfectionBaseïŒ0x0040102CïŒã³ãŒããå®è¡ããŠãéåžžã®CCleaneræäœãç¶è¡ããåã«ã³ãŒãå®è¡ã¹ã¬ããããã«ãŠã§ã¢ã«ãªãã€ã¬ã¯ãããããã«å€æŽãããŸããã åŒã³åºãããã³ãŒãã¯ãPICããŒããŒïŒäœçœ®ã«äŸåããªãããã°ã©ã ã³ãŒãïŒãšDLLãã¡ã€ã«ã®2ã€ã®ã¬ãã«ã®æªæã®ããè² è·ãå«ãããŒã¿ã解èªããŸãã
HeapCreateïŒHEAP_CREATE_ENABLE_EXECUTEã0,0ïŒã䜿çšããŠãå®è¡å¯èœããŒããäœæãããŸãã ãã«ãŠã§ã¢ãå«ã埩å·åãããããŒã¿ã®ã³ã³ãã³ãã¯ããŒãã«ã³ããŒãããå ã®ããŒã¿ã¯æ¶å»ãããŸãã 次ã«ãPEããŒããŒãåŒã³åºããããã®äœæ¥ãéå§ãããŸãã ææããã»ã¹ãå§ãŸããšããã«ããã€ããªã³ãŒãã¯ã以åã«PEããŒããŒãšDLLãã¡ã€ã«ãå«ãã§ããã¡ã¢ãªé åãæ¶å»ãã以åã«å²ãåœãŠãããã¡ã¢ãªã解æŸããããŒããç Žå£ããéåžžã®CCleaneræäœã§å®è¡ãç¶ããŸãã
PEããŒããŒã¯ãäœçœ®ã«äŸåããªãã³ãŒãã£ã³ã°ææ³ã䜿çšããŠãã¡ã¢ãªå ã®.dllãã¡ã€ã«ãèŠã€ããŸãã 次ã«ãDLLãå®è¡å¯èœã¡ã¢ãªã«è»¢éããDLLEntryPointãåŒã³åºããŠå®è¡ãéå§ããŸãã
CCBkrdr_GetShellcodeFromC2AndCallã¯ããã®ãã«ãŠã§ã¢ã®åæäžã«Talosã«ãã£ãŠæ€åºãããæªæã®ããæäœã®å€ããæ åœããŠããŸãã ãŸããçŸåšã®ã·ã¹ãã æå»ãèšé²ããŸãã ãã®åŸãæããæå®ã®æéãããã¬å ã®ãŠã€ã«ã¹ãã¹ãã£ã³ããããã«æ§æãããèªååæã·ã¹ãã ãåé¿ããç®çã§ãæªæã®ããã³ãŒãã®å®è¡ã601ç§é ãããŸãã ãã®é 延æ©èœãå®è£ ããããã«ããã«ãŠã§ã¢ã¯ã601ç§ã«èšå®ãããdelay_in_secondsã¿ã€ã ã¢ãŠãã䜿çšããŠ224.0.0.0ãpingããããšããæ©èœãåŒã³åºããŸãã 次ã«ãçŸåšã®ã·ã¹ãã æéãå€å¥ããŠã600ç§ãçµéãããã©ããã確èªããŸãã ãã®æ¡ä»¶ãæºããããªãå ŽåããŠã€ã«ã¹ã¯CCleanerãå®è¡ããç¶ããŠããéã«çµäºããŸãã ãã«ãŠã§ã¢ãIcmpCreateFileãå®è¡ã§ããªãç¶æ³ã§ã¯ãSleepïŒïŒé¢æ°ã䜿çšããŠåãé 延æ©èœãå®è£ ããããšã«æ»ããŸãã ãã«ãŠã§ã¢ã¯ãŸããçŸåšã®ã·ã¹ãã æå»ã次ã®ã¬ãžã¹ããªããŒã«ä¿åãããŠããå€ãšæ¯èŒããŸãã
HKLM \ãœãããŠã§ã¢\ Piriform \ AgomoïŒTCID
TCIDã«ä¿åãããŠããæéããŸã å°çããŠããªãå ŽåããŠã€ã«ã¹ã¯å®è¡ãåæ¢ããŸãã
å³3ïŒé 延æé
次ã«ããŠãŒã¶ãŒã«å²ãåœãŠãããç¹æš©ããã§ãã¯ãããŸãã çŸåšã®ãŠãŒã¶ãŒã管çè ã§ãªãå Žåããã«ãŠã§ã¢ã¯å®è¡ãåæ¢ããŸãã
å³4ïŒç¹æš©ãã§ãã¯
ãã«ãŠã§ã¢ãå®è¡ãããŠãŒã¶ãŒã«ç®¡çè æš©éãããå Žåãææããã·ã¹ãã ã§SeDebugPrivilegeãã¢ã¯ãã£ãã«ãªããŸãã ãã®åŸããã«ãŠã§ã¢ã¯ãInstallIDãå€ãèªã¿åããŸãããã®å€ã¯ã次ã®ã¬ãžã¹ããªããŒã«ä¿åãããŸãã
HKLM \ãœãããŠã§ã¢\ Piriform \ AgomoïŒMuid
ãã®å€ãååšããªãå Žåããã«ãŠã§ã¢ã¯ãïŒïŒrandïŒïŒ* randïŒïŒ^ GetTickCountïŒïŒïŒãã䜿çšããŠäœæããŸãã
äžèšã®æé ãå®äºãããšããŠã€ã«ã¹ã¯ã·ã¹ãã æ å ±ã®åéãéå§ããã·ã¹ãã æ å ±ã¯åŸã§C2ãµãŒããŒã«éä¿¡ãããŸãã ã·ã¹ãã æ å ±ã¯ã次ã®ããŒã¿æ§é ã«ä¿åãããŸãã
å³5ïŒCCBkdr_System_InformationããŒã¿æ§é
ã·ã¹ãã ã«é¢ããæ å ±ãåéããåŸãä¿®æ£ãããBase64ã䜿çšããŠæå·åããã³ãšã³ã³ãŒããããŸãã ãã®åŸããã«ãŠã§ã¢ã¯æ¬¡ã®ã»ã¯ã·ã§ã³ã§èª¬æããããã«ãã³ãã³ããµãŒããŒïŒC2ïŒãšã®éä¿¡ã確ç«ããŸãã
ã³ãã³ããšã³ã³ãããŒã«ïŒC2ïŒ
åè¿°ã®ã·ã¹ãã æ å ±ãåéãããC2ãµãŒããŒãžã®éä¿¡ã®æºåãæŽããšãPOST HTTPSèŠæ±ã䜿çšããŠ216 [ã] 126 [ã] 225 [ã] 148ã«è»¢éããè©Šã¿ãéå§ãããŸãã
C2ãµãŒããŒããåä¿¡ããããŒã¿ã¯ãCCBkdr_ShellCode_Payloadã§äœ¿çšããããã®æ£ãã圢åŒã§ããããšã確èªããããã«ãã§ãã¯ãããŸãã 以äžã«äŸã瀺ããŸãã
å³6ïŒCCBkdr_ShellCode_PayloadããŒã¿æ§é
ãŠã€ã«ã¹ãã€ã³ã¹ããŒã«ãããåŸãéåžžã®CCleaneræäœãç¶è¡ãããŸãã 以äžã¯ããã®ãã«ãŠã§ã¢ãé«ã¬ãã«ã§ã©ã®ããã«æ©èœãããã説æããå³ã§ãã
å³7ïŒãã«ãŠã§ã¢ã®èµ·åããã»ã¹ã®æŠç¥å³
ãã¡ã€ã³çæã¢ã«ãŽãªãºã
ã¡ã€ã³C2ãµãŒããŒãåã®ã»ã¯ã·ã§ã³ã§èª¬æããHTTP POSTèŠæ±ãžã®å¿çãè¿ããªãç¶æ³ã§ã¯ãæªæã®ããããã°ã©ã ã¯DGAã¢ã«ãŽãªãºã ã䜿çšããŸãã ãã®å ŽåãæéããŒã¹ã§ãããçŸåšã®å¹Žãšæã®å€ã䜿çšããŠèšç®ã§ããŸãã 以äžã¯ãDGAãã¡ã€ã³ã®ãªã¹ãã§ãã
å³8ïŒ12ãæéã®ãã¡ã€ã³çæ
æªæã®ããããã°ã©ã ã¯ã DGAã¢ã«ãŽãªãºã ã«ãã£ãŠçæãããåãã¡ã€ã³ã®DNSã«ãã¯ã¢ãããéå§ããŸãã DNSã«ãã¯ã¢ãããIPã¢ãã¬ã¹ãè¿ããªãå Žåããã®ããã»ã¹ã¯ç¶è¡ããŸãã ãã®ãã«ãŠã§ã¢ã¯ãã¢ã¯ãã£ããªDGAãã¡ã€ã³ã®DNSã¯ãšãªãå®è¡ãããã¡ã€ã³ããŒã ãµãŒããŒãã2ã€ã®IPã¢ãã¬ã¹ãåä¿¡ããããšãæ³å®ããŠããŸãã 次ã«ãæªæã®ããããã°ã©ã ã¯ãåä¿¡ããIPã¢ãã¬ã¹ã§äžé£ã®ãããæäœãå®è¡ããããããçµã¿åãããŠã³ãã³ããµãŒããŒã®æ°ããå®éã®ã¢ãã¬ã¹ã決å®ããããšã«ãããã»ã«ã³ããªãµãŒããŒC2ãèšç®ããŸãã ãã®ããã»ã¹ã瀺ãå³ã以äžã«ç€ºããŸãã
å³9ïŒã³ãã³ããµãŒããŒã¢ãã¬ã¹ã®å®çŸ©
åæäžãCisco Talosã¯DGAãã¡ã€ã³ãå æãããŠããªããšå€æãããããæ»æè ãèªåã®ç®çã«äœ¿çšã§ããªãããã«ç»é²ããã³ãããã¯ãããŸããã
æœåšçãªæå·
éåžžã«å€æ°ã®ã·ã¹ãã ãèããããããããã®æ»æã®åœ±é¿ã¯æ·±å»ã§ãã CCleanerã¯ã2016幎11æçŸåšãäžçäžã§20åãè¶ ããããŠã³ããŒãããããæ°èŠãŠãŒã¶ãŒã®å¢å ã¯1é±éããã500äžäººã§ãããšå ±åãããŠããŸãã
å³10ïŒCCleanerã®çµ±èš
ãŠã€ã«ã¹ã®æ¡æ£äžã«CCleanerãã€ã³ã¹ããŒã«ãããã·ã¹ãã ã¯ã2017幎8æ15æ¥ã®ç¶æ ã«åŸ©å ããããåã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã ãŸãããŠãŒã¶ãŒã¯ææãé²ãããã«å©çšå¯èœãªææ°ã®CCleanerã«ã¢ããã°ã¬ãŒãããå¿ èŠããããŸãã ãã®ããŒãžã§ã³ãæžããŠããæç¹ã§ã¯ãããŒãžã§ã³5.34ã§ããã CCleanerããŠã³ããŒãããŒãžã«ãããšãCCleanerã®ç¡æçã¯èªåæŽæ°ãæäŸããªããããããã¯æåã§è¡ãå¿ èŠãããããšã«æ³šæããããšãéèŠã§ãã
ãã®æ»æã«é¢é£ãããã¡ã€ã³ã«é¢ããCisco Umbrellaãã¬ã¡ããªããŒã¿ãåæããéãTalosã¯ã察å¿ããDNSã¯ãšãªãäœæããããªãã®æ°ã®ã·ã¹ãã ãç¹å®ããŸããã ãããã®ãã¡ã€ã³ã¯äžåºŠãç»é²ãããããšããªãããããã®ãŠã€ã«ã¹ãå¯äžã®åå ã§ãããšçµè«ä»ããã®ã劥åœã§ãã 8æãš9æã«é¢é£ãããã¡ã€ã³ïŒãã®è åšãã¢ã¯ãã£ãã ã£ãæéãšçžé¢ããŠããïŒã®ã¿ãéèŠãªã¢ã¯ãã£ããã£ã瀺ããŠããŸãã
å³11ïŒ7æã®DGAãã¡ã€ã³ã¢ã¯ãã£ããã£
åè¿°ã®ããã«ããã®ãã«ãŠã§ã¢ãå«ãCCleanerããŒãžã§ã³ã¯2017幎8æ15æ¥ã«ãªãªãŒã¹ãããŸããã 次ã®ã°ã©ãã¯ã2017幎8æã«äœ¿çšãããDGAãã¡ã€ã³ã«é¢é£ããDNSã¢ã¯ãã£ããã£ã®å€§å¹ ãªå¢å ã瀺ããŠããŸãã
å³12ïŒ2017幎8æã®ãã¡ã€ã³ã®ã¢ã¯ãã£ããã£
å³13ïŒ2017幎9æã®ãã¡ã€ã³ã¢ã¯ãã£ããã£
ã¢ãã¹ãã«é£çµ¡ããåŸãææããã·ã¹ãã ãããã©ã«ãã®C2ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããªããªã£ãããšãããããŸããã ãã®çµæãDGAãã¡ã€ã³ã«åãããããªã¯ãšã¹ãã®æ°ãå€§å¹ ã«å¢å ããŸããã
å³14ïŒãµãŒããŒã®ã·ã£ããããŠã³åŸã®ãã©ãã£ãã¯
9æ18æ¥ã®æç¹ã§ããã®è åšã®ãŠã€ã«ã¹å¯Ÿçã«ããæ€åºã¯éåžžã«äœãïŒ1/64ïŒãŸãŸã§ããããšã«æ³šæããŠãã ããã
å³15ïŒãŠã€ã«ã¹æ€åºãã§ãã¯
ãã£ãšå¿é
ãã®åŸã調æ»äžã«ãC2ãµãŒããŒã«ä¿åããããã¡ã€ã«ãå«ãã¢ãŒã«ã€ããæäŸãããŸããã ç§ãã¡ã®ç 究掻åã¯ãã¢ãŒã«ã€ããã¡ã€ã«ã«å«ãŸããMySQLããŒã¿ããŒã¹ã®å 容ã«åæ ãããããŒã¿ã®ä¿¡é Œæ§ã確èªãããŸããã
C2ãµãŒããŒããã®ã³ãŒããåæãããšãã第2ã¬ãã«ã®ããŒãããŒããŒé ä¿¡ãç®çãšããçµç¹ã®ãªã¹ããããã«åŒ·èª¿è¡šç€ºãããŸã ã 9æã®4æ¥éã®ã¿ã察象ãšããC2远跡ããŒã¿ããŒã¹ã®ã¬ãã¥ãŒã«åºã¥ããŠãå°ãªããšã20å°ã®è¢«å®³è ã®ãã·ã³ãç¹æ®ãªãã«ãŠã§ã¢è² è·ã«ææããŠããããšã確èªã§ããŸãã 以äžã¯ãæ»æè ãæšçã«ããããšãããã¡ã€ã³ã®ãªã¹ãã§ãã .phpãã¡ã€ã«ã§ç¹å®ããããã¹ãŠã®äŒæ¥ã«ã€ããŠã¯ãC2ãµãŒããŒãšã®äº€æã¯èªããããŸããã§ããã
å³16
PHPã¹ã¯ãªããã¯ãææãããã·ã³ããåä¿¡ããã·ã¹ãã ããŒã³ã³ãã$ DomainListã$ IPListãããã³HostListã®3ã€ã®å€ãšæ¯èŒããŸãã ããã¯ãææããã·ã¹ãã ãã¹ããŒãž2ã®æªæã®ããè² è·ãé ä¿¡ããå¿ èŠããããã©ãããå€æããããã«å¿ èŠã§ãã
å³17
C2ããŒã¿ããŒã¹ã«ã¯2ã€ã®ããŒãã«ãå«ãŸããŠããŸããïŒ1ã€ã¯ãµãŒããŒãšãéä¿¡ããããã¹ãŠã®ãã·ã³ã説æããã¹ããŒãž2ã®ããŒããåä¿¡ãããã¹ãŠã®ãã·ã³ã®èª¬æã ãã®æéã«ã700,000å°ãè¶ ãããã·ã³ãC2ãµãŒããŒã«éä¿¡ããã20å°ãè¶ ãããã·ã³ãã¹ããŒãž2ã®è² è·ãåããŸããã ãµãŒããŒãã¢ã¯ãã£ãã«ãªã£ãŠã¿ãŒã²ããçµç¹ã«ææããŠããéã«ã¿ãŒã²ãããªã¹ããå€æŽã§ããããšãç解ããããšãéèŠã§ãã
ææäžããã«ãŠã§ã¢ã¯å®æçã«C2ãµãŒããŒã«æ¥ç¶ããææããã·ã¹ãã ã«é¢ããæ å ±ãéä¿¡ããŸããã ãã®æ å ±ã«ã¯ãIPã¢ãã¬ã¹ãæéããã¹ãåããã¡ã€ã³ãããã»ã¹ãªã¹ããªã©ãå«ãŸããŠããŸããã ãã®æ å ±ã¯ããããããµã€ããŒç¯çœªè ãæ»æã®æçµæ®µéã§æšçãšããè»äž¡ã決å®ããããã«äœ¿çšãããŸããã
ã¡ã€ã³æ¥ç¶ããŒã¿ã¯ããµãŒããŒããŒãã«ã«ä¿åãããŸãã ãã®ããŒã¿ããŒã¹ããŒãã«ã®TalosããŒãã®1ã€ã®äŸã次ã«ç€ºããŸãã
å³18
ã€ã³ã¹ããŒã«ãããŠããããã°ã©ã ã®ãªã¹ããšåæ§ã
å³19
ãããŠãããã»ã¹ã®ãªã¹ãã
å³20
2çªç®ã®ããŒã¿ããŒã¹ããŒãã«ã«ã¯ãã¹ããŒãž2ã®ããŒããå®éã«é ä¿¡ãããã·ã¹ãã ã«é¢é£ä»ããããè¿œå ã®ããŒã¿ã»ãããå«ãŸããŠããããã®ããŒãã«ã«ã¯åæ§ã®æ å ±ãå«ãŸããŠããŸããã
å³21
è¡šã®åæã«åºã¥ããŠããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãæ»æè ã«å€ãã®ç°ãªãã¿ãŒã²ãããžã®ã¢ã¯ã»ã¹ãæäŸããããšã¯æããã§ãã C2ãµãŒããŒã§ã®ãã£ã«ã¿ãªã³ã°ãèãããšãæ»æè ã¯ãã¿ãŒã²ãããšããç°å¢ãŸãã¯çµç¹ã«å¿ããŠããã€ã§ããã¡ã€ã³ãè¿œå ãŸãã¯åé€ã§ããŸãã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãã·ã¹ãã ãããã¡ã€ã«ã®ä¿åã«äœ¿çšãããããŒã¿ããŒã¹ããŒãã«ã«å«ãŸããŠããã¬ã³ãŒãã®æ°ã瀺ããŠããŸãã
å³22
次ã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãäžçäžã®åœ±é¿ãåããæ¿åºã·ã¹ãã ã®æ°ã瀺ããŠããŸãã
å³23
ãbankããšããåèªãå«ããã¡ã€ã³ãæã€è匱ãªã·ã¹ãã ïŒ
å³24
ããã¯ããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããããšã§åŸãããæ»æè ã®ã¢ã¯ã»ã¹ã¬ãã«ã瀺ãããã®æ»æã®æ·±å»ããšæœåšçãªåœ±é¿ã匷調ããŠããŸãã
ã³ãŒãã®åå©çš
Talosã¯ãKaspersky Labã®ç 究è ãäœæããã¢ããªã±ãŒã·ã§ã³ããã³ãŒããGroup 72ã§äœ¿çšãããããšãããã£ãŠãããã«ãŠã§ã¢ãµã³ãã«ãšäžèŽããããšã調æ»ããŸããã ããã¯æ±ºããŠèšŒæ ã§ã¯ãããŸããããåæã確èªãããããéèŠãªæ å ±ã§ããããšã«åæããããšãã§ããŸãã
å·ŠïŒ2bc2dee73f9f854fe1e0e409e1257369d9c0a1081cf5fb503264aa1bfe8aa06fïŒCCBkdr.dllïŒ
å³ïŒ0375b4216334c85a4b29441a3d37e61d7797c2e1cb94b14cf6292449fb25c7b2ïŒMisslããã¯ãã¢-APT17 /ã°ã«ãŒã72ïŒ
å³25
çµè«
ãµãã©ã€ãã§ãŒã³æ»æã¯ãé床ãšè€éããå¢ããŠããŸãã ãã®ç¹å®ã®äŸã§ã¯ãæ»æè ã¯ãèšå€§ãªæ°ã®ãã·ã³ã䟵害ããããã«ããã¯ãããžãŒäŒæ¥ãç¹ã«æšçãšããã·ã¹ãã ãéçºããŸããã ããã«ããããããã®ã€ãã³ãã«é¢ããæžå¿µãé«ãŸããææäžã«CClenaerãããŠã³ããŒããããŠãŒã¶ãŒã¯ãææããããŒãžã§ã³ã®CCleanerãåé€ãããææ°ããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãããã ãã§ãªãããââãã¯ã¢ããããããŒã¿ã埩å ããŠãã«ãŠã§ã¢ãå®å šã«åé€ããå¿ èŠããããšããæšå¥šäºé ã確èªãããŸãã
以äžã¯ããã®æ»æã«é¢é£ãã䟵害ã®ææšã§ãã
ãã¡ã€ã«ããã·ã¥
6f7840c77f99049d788155c1351e1560b62b8ad18ad0e9adda8218b9f432f0a9
1a4a5123d7b2c534cb3e3168f7032cf9ebf38b9a2a97226d0fdb7933cf6030ff
36b36ee9515e0a60629d2c722b006b33e543dce1c8c2611053e0651a0bfdb2e9
DGAãã¡ã€ã³
ab6d54340c1a [ã] com
aba9a949bc1d [ã] com
ab2da3d400c20 [ã] com
ab3520430c23 [ã] com
ab1c403220c27 [ã] com
ab1abad1d0c2a [ã] com
ab8cee60c2d [ã] com
ab1145b758c30 [ã] com
ab890e964c34 [ã] com
ab3d685a0c37 [ã] com
ab70a139cc3a [ã] com
IPã¢ãã¬ã¹
216 [ã] 126 [ã] 225 [ã] 148
CCã®ã€ã³ã¹ããŒã©ãŒïŒ dc9b5e8aa6ec86db8af0a7aa897ca61db3e5f3d2e0942e319074db1aaccfdc83ïŒGeeSetup_x86.dllïŒ
64ãããã®ããã€ã®æšéŠ¬åãã€ããª
128aca58be325174f0220bd7ca6030e4e206b4378796e82da460055733bb6f4fïŒEFACli64.dllïŒ
32ãããã®ããã€ã®æšéŠ¬ãã€ããªïŒ 07fb252d2e853a9b1b32f30ede411f2efbb9f01e4a7782db5eacf3f55cf34902ïŒTSMSISrv.dllïŒ
ã¬ãžã¹ããªå ã®DLLïŒ f0d1f88c59a005312faad902528d60acbf9cd5a7b36093db8ca811f763e1292a
ã¬ãžã¹ããªããŒïŒ
HKLM \ãœãããŠã§ã¢\ Microsoft \ Windows NT \ CurrentVersion \ WbemPerf \ 001
HKLM \ãœãããŠã§ã¢\ Microsoft \ Windows NT \ CurrentVersion \ WbemPerf \ 002
HKLM \ãœãããŠã§ã¢\ Microsoft \ Windows NT \ CurrentVersion \ WbemPerf \ 003
HKLM \ãœãããŠã§ã¢\ Microsoft \ Windows NT \ CurrentVersion \ WbemPerf \ 004
HKLM \ãœãããŠã§ã¢\ Microsoft \ Windows NT \ CurrentVersion \ WbemPerf \ HBP