Dridexã®ææ°ããŒãžã§ã³ã«é¢ããã¬ããŒããã玹ä»ããŸããDridexã¯ãææããã³ã³ãã¥ãŒã¿ãŒäžã§ãèŠéããããã¡ãªè€éããšèœåã§æåã«ãªã£ãæåãªéè¡ã®ããã€ã®æšéŠ¬ã§ãã
1.ã¯ããã«
Dridexã¯ãææããããã€ã¹äžã§èŠéããããè€éããšæ©èœã§ç¥ãããéè¡ã®ããã€ã®æšéŠ¬ã§ãã ææããŠãããããã®ããã€ã¹ã¯ãã¢ãžã¥ãŒã«ãŸãã¯ã©ã€ãã©ãªãéããŠæªæã®ããç¹æ§ïŒå€éšãŸãã¯ç¬èªã®ç¹æ§ïŒãèªç±ã«è¿œå ã§ããã¢ãžã¥ã©ãŒããããããã«çµã¿èŸŒãŸããŠããŸãã
æåã®ããŒãžã§ã³ã¯2014幎æ«ã«ç»å ŽããŸããã 2015幎ã®åãã«ãæ°ããã¡ãžã£ãŒã¢ããããŒãããªãªãŒã¹ããã2çªç®ã®ããŒãžã§ã³ã«åœãå¹ã蟌ãŸããŸããã Dridexã®ä»¥åã®ããŒãžã§ã³ã衚瀺ãããšãã«æãå®å®ããŠå®å®ããã®ã¯2015幎4æã«ç»å Žãã3çªç®ã®ããŒãžã§ã³ã§ã2017幎2æã«ç»å ŽããæåŸã®æ¢ç¥ã®ããŒãžã§ã³ã§ãã4çªç®ã®ããŒãžã§ã³ãŸã§ããç¥ããããµã€ããŒæ»æã§äœ¿çšãããŠããŸããã
2015幎ã«ç¹å¥ãµãŒãã¹ã«ãã£ãŠå®è¡ãããããããããã®äž»èŠã³ã³ããŒãã³ãã®åé€ä»¥éãDridexã®ãã®ä»ã®äž»èŠãªæŽæ°ã¯èŠã€ãããŸããã§ãã[1]ã
éè¡ã®ããã€ã®æšéŠ¬ã®ãã®æ°ããããŒãžã§ã³ã«ã¯ãæ°ããæ©èœãå«ãŸããŠããŸãã ãããã®1ã€ã¯AtomBombingãšåŒã°ããŸã-ããã¯ãçãããAPIãåŒã³åºããã«ã³ãŒããåã蟌ã¿ãç£èŠã·ã¹ãã ã«ããæ€åºãåé¿ããããã«èšèšãããæ©èœã§ãã DLLããããã³ã°ããŠãã®åç¶å¯èœæ§ãé«ããããã®ææ³ãå«ãŸããŠããŸãã æåŸã«ãæ§æã®ååŸã«äœ¿çšãããããŸããŸãªæå·åæ¹æ³ãæé©åãããŠããŸãã [2]
2.ããã€ã®ç¹æ§
以äžã¯ãåæããããã¡ã€ã«ã®ããã€ãã®éçããããã£ã§ãã ããã€ã®æšéŠ¬ããã·ã¥ïŒ
åæããããµã³ãã«ã®å éšäœææ¥ã¯2017幎5æ16æ¥ã§ãã åé¡ã®ãã¡ã€ã«ã¯ãMicrosoftã®æ£åœãªdllãã·ãã¥ã¬ãŒãããããã«ã64ãããç°å¢ã§å®è¡ããããã«ã³ã³ãã€ã«ãããŸããã
å³1.ãã¡ã€ã«ã®ããããã£
ããã«å ããŠããã¡ã€ã«ã¯ç¬èªã®ã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããããããŠã€ã«ã¹å¯Ÿçãœããã«æ°ä»ãããããšã¯ãããŸããã
å®è¡å¯èœãã¡ã€ã«ã«ã¯ããªãå€ãã®ã»ã¯ã·ã§ã³ïŒåèšã§11ïŒãããããšãããããŸããïŒå³2ãåç §ïŒã
å³2.åæããããã€ããªãã¡ã€ã«ã®éçæ å ±
DATAã»ã¯ã·ã§ã³ã§ã¯ããšã³ããããŒã7,799ã§ãããéåžžã«å€§ããããšãããããŸãã ãã®ã»ã¯ã·ã§ã³ã«ãããè€éã«æå·åãããå§çž®ããããã€ããªãã¡ã€ã«ãèŠã€ããããšãã§ããŸãïŒåŸ©å·åãããšãå®éã®æªæã®ããã³ãŒãã«ãªããŸãïŒã å³3ã«ç€ºãããã«ãæåã®åŸ©å·åãããã¬ã€ã€ãŒã§ã¯ãå®è¡å¯èœãã¡ã€ã«ãããã»ã¹ã«ã¡ã¢ãªãä¿åãããã®åŸã³ãŒããã³ããŒããæçµçã«ãããåŒã³åºããŠå®è¡ããŸãã
å³ 3.ã·ã«ã¯ã³ãŒããžã®ç§»è¡
ã³ãŒããæåã«è¡ãããšã¯ã䜿çšããé¢æ°ã®ã¢ãã¬ã¹ãååŸããããšã§ãã 圌ã¯ãããã°ã©ã ã«ãã£ãŠããŒããããã©ã€ãã©ãªãŒãä»ããåçæ€çŽ¢ã䜿çšããŠãããè¡ããŸãã ãã®ã¿ã¹ã¯ãå®è¡ããã«ã¯ãPEB_LDR_DATAæ§é ãšLDR-MODULEæ§é ãä»ããŠå®è¡ãããããŒããããdllã®ã¡ã€ã³ã¢ãã¬ã¹ãèŠã€ããŸãã dllã«ãã£ãŠãšã¯ã¹ããŒãããããã¹ãŠã®æ©èœãå®è¡ããã³ã³ãã¥ãŒã¿ãŒã®ã¡ã¢ãªã§ç®çã®æ©èœã®ã¢ãã¬ã¹ãèŠã€ããããã«ããšã¯ã¹ããŒãããŒãã«ã®éå§ã¢ãã¬ã¹ãåç §ããŸãã
å³ 4.ããŒããããã¢ãžã¥ãŒã«ã®åæ
次ã«ãã·ã§ã«ã³ãŒãã¯ãã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ããæåã®ããããE9ïŒjmpã¢ã»ã³ãã©ãŒãšåçïŒãšåããã©ããã確èªããããšã«ãããããã¥ã¡ã³ãåãããŠããªãé¢æ°LdrLoadDllã«ãããã¯ãããããã©ããã確èªããŸãã
å³ 5.ããã¯æ€èšŒ
åã®æ€èšŒãæåããå Žåã圌ã¯ãµã³ãããã¯ã¹å ã®ããã»ã¹ãç£èŠããããã®ããã¯ãäœæããã¢ãã¹ãããã³AVGã©ã€ãã©ãªã§ãããsnxhk.dllããšããååã§dllã¡ã¢ãªããã»ã¹ãã¢ã³ããã¯ããŸãã
å³ 6.ã©ã€ãã©ãªïŒsnxhk.dll
æåŸã«ãã·ã§ã«ã³ãŒãã¯ã³ã³ãã¥ãŒã¿ãŒã®ã¡ã¢ãªã®DATAã»ã¯ã·ã§ã³ã«ããå®è¡å¯èœãã¡ã€ã«ã埩å·åãããããããŒã¹ã€ã¡ãŒãžã®ã¢ãã¬ã¹ã«ã³ããŒããŠãããæ°ããçµæã®å®è¡å¯èœãã¡ã€ã«ãèµ·åããŸãã
å³ 7.埩å·åãããå®è¡å¯èœãã¡ã€ã«
ãããã£ãŠããµã³ãã«ãé梱ããå®å šãªããã»ã¹ãå³8ã«ç€ºããŸãã
å³ 8.é梱ããã»ã¹ãå®äºããŸã
3.ææããã»ã¹
3.1ã ææãã¯ã¿ãŒ
ããã€ã¹ã®ææãã©ã®æ¹åã§å®è¡ããããã¯ããŸã æåŸãŸã§æ確ã§ã¯ãããŸããã ããã¯ãæªçšã«ãããã®ããã¹ãã ãã£ã³ããŒã³ã®äžéšã§ããå¯èœæ§ããããŸãã
3.2ã ææããã·ã¹ãã ãšã®çžäºäœçš
ããã€ã®æšéŠ¬ã¯ãèµ·åããããšãããã€ã¹äžã§å®è¡ãããŠãããã«ãŠã§ã¢ã®å¯äžã®ã€ã³ã¹ã¿ã³ã¹ã§ãããã©ããã確èªããexplorer.exeããã»ã¹ã«æ¢ã«å°å ¥ãããŠãããã©ããã確èªããŸãã
ããã¯ãã¹ãŠããã¥ãŒããã¯ã¹ãäœæããŠéãããšã«ãã£ãŠè¡ãããŸãã ãããå®çŸããããã«ã圌ã¯æåã«ããã€ã¹åãšãŠãŒã¶ãŒåãäžç·ã«äœæãã次ã«ãããã®MD5ããã·ã¥ãèšç®ããŸãã
å³ 9.ããã·ã¥èšç®
次ã«ã圌ã¯è§ãã£ããæåãšæåŸã«è¿œå ããCOMãªããžã§ã¯ãã®ããã«ããã·ã¥ã§åºåããŸãã
å³10.ã·ã¹ãã ã§äœæããããã¥ãŒããã¯ã¹ã
ãã®ã¢ã«ãŽãªãºã ã䜿çšãããšãããã€ã®æšéŠ¬Dridexãžã®ææãé²ãããã«ãã·ã¹ãã ã§ãããã®ãã¥ãŒããã¯ã¹ãäœæããã¯ã¯ãã³ãéçºã§ããŸãã å®è¡ãããŠããªãæªæã®ããããã°ã©ã ã¯ãïŒ WINDOWSïŒ \ system32 \ [0-9] {4]ã«ãã©ã«ããŒãäœæããŸã
å³ 11.äœæããããã©ã«ããŒ
æªæã®ããããã°ã©ã ã¯ãæ£åœãª.exeã察å¿ãã.dllãŸãã¯.cplãšãšãã«ãã©ã«ããŒã«ã³ããŒããŸãã ãã®.dllãŸãã¯.cplã¯æ£åœã§ã¯ãããŸãã-ããã¯ããã€ã®æšéŠ¬ã§ãã ãã©ã«ããã.exeãå®è¡ãããšãæªæã®ãã.dllãŸãã¯.cplããã€ãžã£ãã¯ãšåŒã°ããææ³ã䜿çšããŠããŒããããŸãã
ãŸããã©ã³ãã ãªååïŒãã®äŸã§ã¯ãå³12ã¯ãDomitxtdoiãïŒã§ã¿ã¹ã¯ãããã°ã©ã ããŸããããã¯60åããšã«å®è¡ãããŸãã
å³ 12.ã¿ã¹ã¯ãäœæãã
ãã®äŸã§ã¯ãtcmsetup.exeãèµ·åãããåŸãæªæã®ããdllïŒTAPI32.dllïŒãèªã¿èŸŒãŸããææããã»ã¹ãéå§ãããŸãã
ã¿ã¹ã¯ã®ããã°ã©ãã³ã°åŸãäžé£ã®ã³ãã³ããèµ·åãããexplorer.exeã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ã«ãŒã«ãäœæãããŸãã
netsh advfirewallãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«åã®è¿œå =ãã³ã¢ãããã¯ãŒãã³ã°-ãã«ããã£ã¹ããªã¹ããŒã®å®äºïŒICMPv4-InïŒãããã°ã©ã =ãCïŒ\ Windows \ Explorer.EXEãdir =åäœäž=èš±å¯ãããã³ã«= TCPããŒã«ã«ããŒã=ä»»æ
æªæã®ããã¿ã¹ã¯ãäœæãã
schtasks.exe /äœæ/ F / TN "Utdcm" / SCå/ MO 60 / TR "CïŒ\ Windows \ system32 \ 3007 \ tcmsetup.exe" / RLæé«
ãã®ããã»ã¹äžã«ãAtomBombingã®ææ³ã䜿çšããŠãæªè³ªãª.dllãexplorer.exeããã»ã¹ã«çµã¿èŸŒãŸããŸãã ãã®åŸããŠãŒã¶ãŒããã©ãŠã¶ïŒInternet ExplorerãFirefoxãChromeãªã©ïŒãéãç¬éãåŸ ã¡ãŸãã
ãŠãŒã¶ãŒããã©ãŠã¶ãŒãéããšãæ°ããAtomBombingãã¯ããã¯ã䜿çšããŠãexplorer.exeãããã©ãŠã¶ãŒã«æ°ããã·ã§ã«ã³ãŒããåã蟌ãŸããŸãã
4.ã·ã¹ãã å ã®ååš
ã·ã¹ãã ã«ååšããããšã確èªããã«ã¯ã次ã®æé ãå®è¡ããŸãã CïŒ\ Windows \ System32ã«4æ¡ã®ã©ã³ãã ãªæ°åã®ãã©ã«ããŒãäœæãããã®äžã«æ£èŠã®Windowså®è¡å¯èœãã¡ã€ã«ïŒåžžã«åãå®è¡å¯èœãã¡ã€ã«ã§ã¯ãªãïŒãšããã®å®è¡å¯èœãã¡ã€ã«ã«ãã£ãŠããŒãããå¿ èŠããã.dllãã³ããŒããŸãã ãã®.dllã ããæªæã®ããã³ãŒãã«ãã£ãŠå€æŽãããŸãã
å³ 13.ã·ã¹ãã å ã®ååš
ãã®ææ³ã¯ãDLLãã€ãžã£ãã¯ãšããŠç¥ãããŠããŸãã 圌女ã¯ãã·ã¹ãã ã圌女ãããŠã³ããŒã/䜿çšããããšããŠããã©ã€ãã©ãª/ãã¡ã€ã«ãæ€çŽ¢ã§ããããã«ããã³ãã³ãã䜿çšããŸãã äžã®å³ã®å Žåãå®è¡å¯èœãã¡ã€ã«ãSystemPropertiesPerformance.exeãã¯ä»ã®ã©ã€ãã©ãªã®äžãããSYââSDM.CPLããããŒãããŸãã ããã©ã«ãã§ã¯ããSYSDM.CPLããã¡ã€ã«ã®æ€çŽ¢ã¯ãã¢ããªã±ãŒã·ã§ã³ãèµ·åããããã©ã«ããŒã§æåã«å®è¡ãããŸãã ãã®äŸã§ã¯ãããã¯CïŒ\ Windows \ System32 \ 1365ã§ãã ãã®ãã¡ã€ã«ãããã«èŠã€ãããªãå Žåãã·ã¹ãã ã§ã®.dllãã¡ã€ã«ã®æ€çŽ¢é åºã®èšå®ã«å¿ããŠãä»ã®ãã©ã«ããŒã§æ€çŽ¢ãå®è¡ãããŸãã
å®è¡å¯èœãã¡ã€ã«ãšå€æŽããã.dllãåããã©ã«ããŒã«ã³ããŒãããåŸãDridexã¯çãããããã«ã§ããã ãäœãããå¿ èŠããããããæ£åœãªããã°ã©ã ãä»ããŠæªæã®ããã¢ã¯ã·ã§ã³ãå®è¡ãããŸãã
åã®ç« ã§ç€ºããããã«ããã¡ã€ã«ãå®è¡ããããã«ã1æéããšã«ã©ã³ãã ãªçªå·ïŒCïŒ\ Windows \ System32 \ 1365ïŒã®ãã©ã«ããŒã§å®è¡ããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæããŸãã
å³ 14.ããã°ã©ã ãããã¿ã¹ã¯ã®äœæ
æ¢ã«è¿°ã¹ãããã«ããã©ã«ããŒã®ååã«ã¯4ã€ã®ã©ã³ãã ãªæ°åãå«ãŸããäœæãããå®è¡å¯èœãã¡ã€ã«ã®ååã¯åžžã«.dllãšåãã§ã¯ãããŸãããããã«ãŠã§ã¢ã¯åžžã«ã©ã€ãã©ãªãããŒãããå®è¡å¯èœãã¡ã€ã«ãèªèããæå®ãããã©ã€ãã©ãªãŒãåžžã«å€æŽã§ããŸãæªæã®ããã³ãŒãã䜿çšããŸãã
åæãç¶ãããšã次ã®ããã«åäœããããšãããããŸãã
- ãCïŒ\ Windows \ System32 \ãã«ãã¹ãŠã®å®è¡å¯èœãã¡ã€ã«ããªã¹ããããŸã
- åå®è¡å¯èœãã¡ã€ã«ã®ååãããã·ã¥ãã以åã«ä¿åãããå€ãšæ¯èŒããŸãã äžèŽããå Žåããã®å®è¡å¯èœãã¡ã€ã«ã§åŒãç¶ãåäœããŸãã
- éžæããå®è¡å¯èœãã¡ã€ã«ã®IATãèªã¿åãããããã.dllãéžæããŠããã«å€æŽããŸãã
- æé 3ã§éžæããIAT .dllãèªã¿åããŸãã
- 圌ã¯æªæã®ããã³ãŒãã®ã³ããŒïŒ.dllèªäœïŒãäœæããæåŸã«ã©ã³ãã ãªååã®ã»ã¯ã·ã§ã³ãè¿œå ããŠãã¹ããã4ã§ååŸããIATãã³ããŒããŸãã
- éžæããå®è¡å¯èœãã¡ã€ã«ïŒpã3ïŒãšå€æŽãããæªæã®ãã.dllïŒpã5ïŒãã©ã³ãã ãªãã©ã«ããŒã«ã³ããŒããŸãã
ãã®å Žåãã·ã¹ãã ã«ååšãååŸããå®è¡å¯èœãã¡ã€ã«ãå®è¡ãããã³ã«ãæªæã®ãã.dllãããŒãããŸãã
ãŸããæªæã®ããããã°ã©ã ã¯ããHKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Runãã®ã«ãŒãã䜿çšããŠãAppData \ Roaming \ [ã©ã³ãã ãªãã©ã«ãå]ã®ã¬ãžã¹ããªããŒãšãšãã«ãå®è¡å¯èœåœ¢åŒã§èªåèªèº«ã®ã³ããŒãäœæããŸãã
å³ 15.ã¬ãžã¹ããªããŒ
5.ååç匟ã«ããåºè«
Dridexã¯AtomBombingãã¯ããã¯ã䜿çšããŠãçããåŒãèµ·ããããšãªãã·ã§ã«ã³ãŒããä»ã®ããã»ã¹ã«æžã蟌ã¿ãŸãã ããã¯ãAPCããã³AtomãšåŒã°ããæãäžè¬çã«äœ¿çšãããWindows Executiveãªããžã§ã¯ãã®1ã€ãåŒã³åºãããšã§å®çŸãããŸãã 以äžã¯ãå¥ã®ããã»ã¹ã®å®è£ ã«å«ãŸããããŸããŸãªã¹ãããã§ãã
5.1ã 察象ããã»ã¹ãæ€çŽ¢
ãã®å Žåãã¿ãŒã²ããããã»ã¹ã¯ããã»ã¹explorer.exeã§ãããããã«æœå ¥ããããã«ã次ã®é¢æ°ã䜿çšããŠåå ããã»ã¹ããªã¹ããããšãã«æåã«å©çšå¯èœã§ãªããã°ãªããŸããã
å³ 16.ããã»ã¹ã®åæ
explorer.exeããã»ã¹ãèŠã€ãããšãOpenProcessé¢æ°ãåŒã³åºããŠãã¢ã©ãŒãå¯èœãªã¹ã¬ããã®åæãéå§ããŸãã
5.2ã ã¢ã©ãŒãå¯èœãªã¹ã¬ãããæ€çŽ¢ãã
å³ 17.ã¢ã©ãŒãå¯èœãªã¹ã¬ãã
ãã®æç¹ã§ããã«ãŠã§ã¢ã¯ã¢ã©ãŒãå¯èœãªç¶æ ã®ã¹ã¬ãããèŠã€ããããšããŸãã ããã«ããã圌女ã¯ã¿ãŒã²ããããã»ã¹ã§ã³ãŒããå®è¡ããããã®APCåŒã³åºããè¡ãããšãã§ããŸãã
ã¢ã©ãŒãå¯èœãªã¹ã¬ãããèŠã€ããããã«ãããã€ã®æšéŠ¬ã¯æåã«explorer.exeã®åã¹ã¬ããã®ãã³ãã«ãåãåããŸãã 次ã«ãNtSetEventãšããŠNtQueueApcThreadã®åŒã³åºããéå§ããã¹ã¬ããã®ãããããå¿çããã®ãåŸ ã¡ãŸãã
ãã¹ãŠãæ£åžžã«æ©èœããå ŽåãåŒã³åºãã«å¿çããæåã®ã¹ã¬ãããåãåãããã®åŸã³ãŒãã®å®è£ ãéå§ããŸãã
5.3ã ã¿ãŒã²ããããã»ã¹ã§ã®ã·ã§ã«ã³ãŒãã®å°å ¥
ãŸããæªæã®ãã.dllãGlobalAddAtomWãåŒã³åºããã¿ãŒã²ããããã»ã¹ïŒãã®å Žåã¯explorer.exeïŒã«åã蟌ãã³ã³ãã³ããå«ãæ°ããAtomãäœæããŸãã
第äºã«ãæªæã®ãã.dllã¯NtQueueApcThreadãåŒã³åºããexplorer.exeããã»ã¹ã«ãã£ãŠèµ·åãããé¢æ°ããã©ã¡ãŒã¿ãŒãšããŠéä¿¡ããŸãã
ãããåããŠè¡ããããšãããã€ã®æšéŠ¬ã¯memsetãåŒã³åºããŠãã·ã«ã¯ã³ãŒããæžã蟌ãŸããé åã0ã§ããããšã確èªããŸãã
å³ 18.ã¡ã¢ãªãŒã®æ¶å»
R8ã§ãããããã«ãDridexãã·ã§ã«ã³ãŒãã®ã³ããŒãéžæãããŸãŒã³ãntdllã«ããããšã瀺ãããšãéèŠã§ãã ããã¯ãASLRã«é¢ä¿ãªãããã¹ãŠã®ããã»ã¹ã§ntdllãåžžã«åãéå§çªå·ã§ããŒããããããã§ãã
次ã®å埩ã§ã¯ãNtQueueApcThreadãã©ã¡ãŒã¿ãŒãšããŠæž¡ãããé¢æ°ã¯GlobalAtomGetAtomNameWã«ãªããŸãããã®çµæãã¿ãŒã²ããããã»ã¹ã¯ãæªæã®ãã.dllã«ãã£ãŠäœæãããã°ããã®Atomãåãåãããã®å 容ãexplorer.exeã®å éšã«æžã蟌ãŸãªãããã«æå®ããããŸãŒã³ã«æžã蟌ã¿ãŸãç念ãçããããŸãã
ãŸãã圌ã¯ã·ã«ã¯ã³ãŒãã®IATãäœæããŸãã
å³ 19. explorer.exeã§IATãäœæãã
ãããŠãäœåºŠãç¹°ãè¿ããåŸãã·ã§ã«ã³ãŒããexplorer.exeã«å®å šã«ã³ããŒããŸãã
å³ 20. explorer.exeã®ã·ã§ã«ã³ãŒã
5.4ã ã¿ãŒã²ããããã»ã¹ã§ã·ã§ã«ã³ãŒããå®è¡ãã
ã·ã§ã«ã³ãŒããexplorer.exeã«ã³ããŒããããå®è¡ããå¿ èŠããããŸãã ãããè¡ãããã«ãDridexã¯ãAtomã䜿çšããŠã·ã§ã«ã³ãŒããå®è£ ãããã®ãšåãæ¹æ³ã§GlobalAtomGetAtomNameAé¢æ°ãå€æŽããŸãã é¢æ°ã®ãœãŒã¹ã³ãŒãïŒ
å³ 21.ãªãªãžãã«æ©èœ
é¢æ°ã®å€æŽæ¹æ³ã¯æ¬¡ã®ãšããã§ãã
å³ 22.å€æŽãããæ©èœ
ã芧ã®ãšãããexplorer.exeã§GlobalAtomGetAtomNameAãåŒã³åºããšãããã°ã©ã ã¯ã·ã§ã«ã³ãŒããå®è¡ããŸãã æªæã®ãã.dllããå€æŽããåŸãNtQueueApcThreadã䜿çšããŠGlobalAtomGetAtomNameAãåŒã³åºããŸãã
å³ 23.ã·ã§ã«ã³ãŒãã®ãªã¢ãŒãå®è¡
ãã®æç¹ã§ãã·ã«ã¯ã³ãŒãã®å®è¡ãéå§ãããŸãã ãã®åŸãGlobalAtomGetAtomNameAã¯çããåŒãèµ·ãããªãããã«å ã®ç¶æ ã«æ»ããŸãã
6.ãããã¯ãŒã¯æ¥ç¶
explorer.exeããã»ã¹ã«ããã€ã®æšéŠ¬ãå°å ¥ããããšãããŒã443ïŒéåžžã¯HTTPSãããã³ã«ã«äœ¿çšãããŸãïŒãéãããç¹å®ã®æ¥ç¶ãæåŸ ãããŸãã
å³ 24.ããŒã443ãéããŸã
7.ã€ã³ãžã±ãŒã¿
ãã®ããŒãžã§ã³ã®Dridexã«ãã£ãŠã³ã³ãã¥ãŒã¿ãŒã䟵害ãããŠãããã©ããã確èªããã«ã¯ã次ã®ç¹ãèæ ®ããå¿ èŠããããŸãã
- explorer.exeããã»ã¹ã¯ããŒã443ã§ãªãã¹ã³ãããã¡ã€ã¢ãŠã©ãŒã«ã«ã¯ãã®ããã»ã¹ã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãèš±å¯ããã«ãŒã«ããããŸãã
- åŒïŒ SYSTEMïŒ \ [0-9] {4}ã«å¯Ÿå¿ãããã©ã«ããŒããããæ£åœãªå®è¡å¯èœãã¡ã€ã«ãšãæ¡åŒµåã.dllãŸãã¯.cplã®ãã¡ã€ã«ãå«ãŸããŠããŸãã
- 60åããšã«ïŒ SYSTEMïŒ \ [0-9] {4}ãã©ã«ããŒãããã¡ã€ã«ãå®è¡ããã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ããããŸãã
8.ãªã³ã¯
[1] Dridex Malware Takedownã®å éš
[2] Dridex v4-AtomBombingãšãã®ä»ã®é©ã
[3] Dridex Banking Malwareãµã³ãã«ã®ãã¯ãã«ã«åæãšãœãªã¥ãŒã·ã§ã³