顧客ãžã®ãµãŒãã¹ã®æäŸãææ°ã®ç¶æ ã«ä¿ã€åœéäŒæ¥ã倧äŒæ¥ããæ å ±ã»ãã¥ãªãã£ãå«ã掻åã®ãã¹ãŠã®åéã§ããã»ã¹ãæ確ã«æŽçããŠãããšããæèŠããããŸãã æ®å¿µãªãããããã¯åžžã«ããã§ã¯ãããŸããã
ãã°ããåã«ãéçºãããã€ã³ãã©ã¹ãã©ã¯ãã£ãæã€å€§äŒæ¥ãå©ããæ±ããŠããŸããã åé¡ã¯ãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã®å¥åŠãªã€ãã³ãã§ããã
- ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒãçªç¶åèµ·åãããã¡ã€ã³ããåé€ãããŸããã
- ãŠãŒã¶ãŒã¯ã¢ã«ãŠã³ããããã¯ãããŠããããšãçºèŠããŸããã
- äžéšã®åŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã¯ãæãããªçç±ããªããæžéããå§ããŸããã
ç¶æ³ãåæããããã«ãäž»èŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ãœãŒã¹ãSolar JSOCã¯ã©ãŠãã«ããSIEMã·ã¹ãã ã«æ¥ç¶ããŸããã ãããè¡ãããã«ãã客æ§ã®ãµã€ãã§ãã°ãåéããããã®ã³ã¬ã¯ã¿ãŒãµãŒããŒãé 眮ãããµã€ãéã®ãµã€ãéãæ§ç¯ããŸããã 䞊è¡ããŠãäŒç€Ÿã«ã¯ãå¿ èŠãªç£æ»ã¬ãã«ã®èšå®æ¹æ³ã«é¢ããæ瀺ãšããœãŒã¹ãæ¥ç¶ããããã®æºåäœæ¥ã®è©³çŽ°ãªèª¬æãéä¿¡ãããŸããã
æåã®æ®µéã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãšãããã·ããŠã€ã«ã¹å¯Ÿçããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ãã°ãããã³DNSãæ¥ç¶ããŸããã ç¿æ¥ã®å€æ¹ãŸã§ã«ãå¿ èŠãªãã¹ãŠã®ã·ã¹ãã ã®ãã°ããããŸããã
æåã«æ€åºãããã®ã¯ã12å°ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããCorkow / Metel管çãµãŒããŒãžã®ã¢ã¯ã»ã¹ã§ãã Win32 / CorkowãŠã€ã«ã¹ã®ä¿®æ£ã®ã¯ã©ã€ã¢ã³ãéšåã¯ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãååšããã«ããããããã2幎以äžã«ããã£ãŠäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£å ã®èª°ã«ãæ°ä»ãããŠããªãã£ãããšãå€æããŸããã æªæã®ãã人ã ã¯ãé·ãéãªãã«ãªã£ãŠããå¶åŸ¡ãµãŒããŒã«é é枬å®ãéä¿¡ããŸããïŒãµãŒããŒã®ãã¡ã€ã³åã¯ããã·ã¢ã®2人ã®å倧ãªã¢ãŒãã£ã¹ãã«ã¡ãªãã§åœåãããæ å ±ã»ãã¥ãªãã£ã¢ããªã¹ãã«åºãç¥ãããŠããŸãïŒã äŒç€Ÿã§ãœãããŠã§ã¢ã䜿çšãããŠãããŠã€ã«ã¹å¯Ÿçãã³ããŒã¯ãæ¢ç¥ã®çœ²åãããŒã¿ããŒã¹ã«è¿œå ããªãã£ãããããŠã€ã«ã¹ãæ€åºã§ããŸããã§ããã
ãããããã€ã³ãã¯ãã®ã»ã³ã»ãŒã·ã§ãã«ã§ã¯ãªããããå±éºãªãŠã€ã«ã¹ã§ã¯ãããŸããã§ããã æåéãæ°æéã®ç£èŠã®åŸãSolar JSOCã®å®éã®éçšã§åããŠãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è€æ°ã®ãã¹ãããæ å ±ãéä¿¡ããæ¬æ Œçãªéãã¹ãã®DNSãã³ãã«ãçºèŠãããŸããã
DNSãã³ãã«ã¯ãèŠåå¡ã®æ¥åžžç掻ã®äžã§ããªã«ãšåŒã°ããããšããããŸãã ãããã¯ãã£ãã«äœ¿çšãããŸããããæè¿ãäŒæ¥ã®å€éšã«æ å ±ãåºåããããã®ãã£ãã«ãšããŠãåœéçãªèŠæš¡ã§å€ãã®æ³šç®ãéããŠããã±ãŒã¹ã§æ³šç®ãããŠããŸãããŸãããã¹ãŠã®å¢çãããã¯ãŒã¯ããã€ã¹ã§å€éšã¢ãã¬ã¹ããããã¯ããããã®å¯Ÿçãè¬ããããŸããã
ããããDNSãã³ãã«ã®å±éºæ§ã¯ããããã®å©ããåããŠãã€ã³ãã©ã¹ãã©ã¯ãã£ããããŒã¿ãéãã«çãããšãã§ãããšããäºå®ã ãã§ã¯ãããŸããã DNSãã³ãã«ã䜿çšãããšãæçµãã¹ãã§ãªããŒã¹ã·ã§ã«ãæ§ç¯ã§ãããã®ã¢ã¯ã·ã§ã³ããªã¢ãŒãã§å¶åŸ¡ã§ããŸãã
DNSãã³ãã«ã¯éåžžã«å€ããããã¯ã§ããããã¹ãŠã®IPSããã³NGFWã¯ã©ã¹ãœãªã¥ãŒã·ã§ã³ãããããæ€åºããå¿ èŠããããšããäºå®ã«ãããããããå®éã«ã¯ããã¯äºå®ãšã¯ã»ã©é ãã§ãã ãã©ã¡ãŒã¿ãŒã®ããããªå€æŽïŒããšãã°ããã€ããŒããããŒãã£ãŒã«ããŸãã¯æšæºDNS圢åŒã®å¥ã®ãã£ãŒã«ãã«è»¢éããããDNSã¯ãšãªã®æšæºãã£ãŒã«ãã®å€åŽã«çœ®ãããããïŒããšã«ãããæšæºçœ²åãç°¡åã«ãã€ãã¹ã§ããŸãã
äŒç€Ÿã®çºèŠçŽåŸã«ãçºèŠãããDNSãã³ãã«ã®ãœãŒã¹ã調æ»ããããã®èŠæ±ãéä¿¡ãããŸããã è€æ°ã®ãã·ã³ãããŒã«ã«ãã°ã¬ãã«ã§æ¥ç¶ãããããã«èª¿æ»ããããã«ã€ã¡ãŒãžã³ã°ããã»ã¹ãéå§ãããŸããã
ãã¹ããæ¥ç¶ãããšãã«ãSolar JSOCã®å°é家ã¯æåã®åé¡ã«çŽé¢ããŸãã-ãã¹ãŠã®ãã·ã³ã§ã»ãã¥ãªãã£ãã°ã空ã§ããã åæã«ãç»åãæ€æ»ãããããã§2çªç®ã®è€éããçããŸãã-USNïŒæŽæ°ã·ãŒã±ã³ã¹çªå·ïŒãšMFTïŒãã¹ã¿ãŒãã¡ã€ã«ããŒãã«ïŒã«ã¯å°ãªããšãéèŠãªæ å ±ãå«ãŸããŠããŸããã§ãããåŸè ã¯é »ç¹ã«ã¹ã±ãžã¥ãŒã«ããããã£ã¹ã¯ã®æé©åã®ããã§ãã
æåã®éèŠãªæ å ±ã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ãã°ã§èŠã€ãããŸãã-ãã¡ã€ã³ç®¡çè ã¢ã«ãŠã³ãã§ãã¹ããžã®ã¢ã¯ã»ã¹ãæããã«ãªããŸããã ãã°ã€ã³ã¯ããã°ãªã³ã¿ã€ã3-ãããã¯ãŒã¯å ¥åã§è¡ãããŸããã
ããã«ãã»ãã¥ãªãã£ã䟵害ãããå¯èœæ§ã®ãããã¹ãŠã®ã·ã¹ãã ãã°ãã¹ããã¯ãªã¢ãããã«åæãããšããã it_helpdeskãµãŒãã¹ã®ã€ã³ã¹ããŒã«ãèŠã€ãããŸããã MD5åèšãåæããåŸããããååãå€æŽããããŠãŒãã£ãªãã£PsExecã§ããããšãæããã«ãªããŸããã å瀟ã®ITéšéã¯ããã®ãœãããŠã§ã¢ã管çã®äŒæ¥æšæºã§ã¯ãªããåŸæ¥å¡ã«ãã£ãŠäœ¿çšãããŠããªãããšã確èªããŠããŸãã
PsExecã¯PsToolsã®äžéšã§ããPsToolsã¯ãSysinternalsãéçºããMicrosoftãè²·åããç¡æã®ãŠãŒãã£ãªãã£ããã±ãŒãžã§ãã Microsoft Windowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ç®¡çãç°¡çŽ åããããã«èšèšãããŠããŸãã PsExecãŠãŒãã£ãªãã£èªäœã«ãããããã»ã¹ããªã¢ãŒãã§å®è¡ã§ããŸãã
PsExecã䜿çšãããšãSMBããã³ãªã¢ãŒãã·ã¹ãã äžã®$ ADMINé ãå ±æãªãœãŒã¹ã䜿çšããŠããªã¢ãŒãã§å®è¡äžã®å®è¡å¯èœããã°ã©ã ã®å ¥åããã³åºåããŒã¿ããªãã€ã¬ã¯ãã§ããŸãã ãã®ãªãœãŒã¹ã䜿çšããŠãPsExecã¯WindowsãµãŒãã¹ã³ã³ãããŒã«ãããŒãžã£ãŒAPIããã°ã©ãã³ã°ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠãPsExecãå®è¡ãããååä»ããã€ããäœæãããªã¢ãŒãã·ã¹ãã ã§PsExecsvcãµãŒãã¹ãéå§ããŸãã
ãã®åŸãäŒæ¥ã®æ å ±ã»ãã¥ãªãã£éšéã¯ãéäžã€ã³ãã©ç®¡çã·ã¹ãã ã䜿çšããŠããã®ãµãŒãã¹ããããŸã§ã«èµ·åããããã¹ãŠã®ãã¹ããç¹å®ããŸããã ãã®ãããªãã¹ãã®ç·æ°ã¯40ãŠããããè¶ ããŸããã
ããã§ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ç»åã®ç 究ã«æ»ããŸãã ããããã®ãã·ã³ã®ãã¡ã€ã«ã·ã¹ãã ã®çŸåšã®ç¶æ ãåæããç 究宀ã§ææãåçŸããããšã«ãããææã®ç解å¯èœãªå¹Žè¡šãåŸãããŸããã
Iã¹ããŒãž
- å ã®system_dll.dllã©ã€ãã©ãªã®ååãsystem_dll2ã«å€æŽããæªæã®ããsystem_dll.dllãªããžã§ã¯ããäœæããŸãã ãã®å Žåãsystem_dll.dllã¯ããã®ã³ãŒãã§å®çŸ©ãããŠããªãé¢æ°ã®system_dll2ãåŒã³åºããŸãã system_dll.dllã¯ã_________ãdllã©ã€ãã©ãªã®ããŒãã«åœ¹ç«ã€ã¿ã€ãPEã®æªæã®ãããªããžã§ã¯ãã§ãã
- Creating _________ãDll-ã¿ã€ãPEã®æªæã®ãããªããžã§ã¯ãã§ãDNSãããã³ã«ã䜿çšããŠä»»æã®ãµãŒããŒãšã®éä¿¡ã確ç«ããããŸããŸãªã³ãã³ããå®è¡ããŸãã ãã®ã©ã€ãã©ãªã¯ãsystem_dll.dllæªæã®ãããªããžã§ã¯ãã«ãã£ãŠããŒããããŸãã
- ååit-helpdeskããã·ã³ã§å®è¡ããããšãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åèµ·åãéå§ããããã«CïŒ\ Windows \ system32 \ shutdown.exeãªããžã§ã¯ããèµ·åããããšæãããŸãã ãã®åèµ·åã¯ãã·ã¹ãã ãµãŒãã¹ãæªæã®ããã©ã€ãã©ãªSystem_dll.dllããã®ã¢ãã¬ã¹ã¹ããŒã¹ã«ããŒãããããã«å¿ èŠã§ãã
ã¹ããŒãžII
- ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åèµ·ååŸãrandom symbols.xxxxx.suãã¡ã€ã³ã®ãšã©ãŒè§£æ±ºã衚瀺ãããŸããããã¯ãDNSãããã³ã«ã䜿çšããé ãããŒã¿ãã£ãã«ã®æ©èœã瀺ãå ŽåããããŸãïŒä»»æã®ããŒã¿ã¯ãã¡ã€ã³ã¬ãã«3ã®ååã§è»¢éãããŸãïŒã
- Windows / System32 / Malware_dll.dllã©ã€ãã©ãªã®äœæãããã¯ãããŒããŒãããå ¥åãããããŒã¿ãååããããã«äœ¿çšãããPEã¿ã€ãã®æªæã®ãããªããžã§ã¯ãã§ãã ããŒã¿ã®ååã¯ããã¡ã€ã«ïŒ USERïŒ / AppData / LocalLow / NTUSER.DATã«ä¿åãããŸãã ãã¡ã€ã«å ã®ããŒã¿ã¯ã10Hãã€ããæžç®ãããã€ããšã³ã³ãŒãã䜿çšããŠãšã³ã³ãŒããããŸãã
- æ»æããããã¹ãäžã«æªè³ªãªãªããžã§ã¯ãjusched.exeãäœæããŸããããã¯ãmalware_dll.dllã©ã€ãã©ãªãåããŒãããã®ã«åœ¹ç«ã¡ãŸãã ãã®å Žåãjusched.exeãªããžã§ã¯ãã¯èµ·åæã«ç»é²ãããŸãïŒã¬ãžã¹ããªãã©ã³ãHKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ RunïŒãããã¯ãã·ã¹ãã ãã»ãã·ã§ã³ã®éå§æã«ãã¹ãŠã®ãŠãŒã¶ãŒãããã®ãªããžã§ã¯ããããŒãããããšãæå³ããŸãã
ã¹ããŒãžIII
- 次åãŠãŒã¶ãŒã»ãã·ã§ã³ãäœæããããšããããã¡ã€ã«ãèªã¿èŸŒãŸããããŒãã¬ãŒãèµ·åãããLocalLow / NTUSER.DATãã¡ã€ã«ãäœæããããŠãŒã¶ãŒã»ãã·ã§ã³å šäœã§ããŒãã¬ãŒã®äœæ¥çµæãèšé²ãããŸãã
- ãŸãããã®æ®µéã§ãã¢ãŒã«ã€ãCïŒ\ ProgrammData \ 0.0ãäœæããããã«ãrar.exeã³ãã³ãã©ã€ã³ããã¢ãŒã«ã€ããèµ·åããŸãã ãã®ã¢ãŒã«ã€ãã«ã¯ãSAMãã¡ã€ã«ãšã¬ãžã¹ããªãã©ã³ãHKLM \ SYSTEMã®ã·ã£ããŠã³ããŒãå«ãŸããŠããŸãã ãã®äžé£ã®ãã¡ã€ã«ã䜿çšããŠãSAMãã¡ã€ã«ããã¢ã«ãŠã³ãããã·ã¥ãæœåºã§ããŸãã
- å Žåã«ãã£ãŠã¯ããã®æ®µéã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®è€æ°ã®åèµ·åãwevtutilãgpscriptãnslookupãcmdkeyãããã³ãã®ä»ã®ã³ãã³ãã®å®è¡ãããã³ã¢ããªã±ãŒã·ã§ã³ãã°ã®ã¯ãªãŒãã³ã°ã䌎ããŸãã
- 調æ»äžã®ãã·ã³ã®1ã€ã§ãtvnserver.exeãªããžã§ã¯ãã®äœæãšè€æ°ã®èµ·åãèšé²ãããæªæã®ããusers.exeãªããžã§ã¯ãããã·ã³äžã«åæã«åºçŸãããã«ãŠã§ã¢æ§æãå«ãããŒ000ããã³001ãHKLM \ Software \ Corporationã¬ãžã¹ããªãã©ã³ãã«æžã蟌ã¿ãŸããã
äžè¬çãªææã¹ããŒã ã¯æ¬¡ã®ãšããã§ãã
æ»æã®å®è£
ã«äœ¿çšãããããŒã«ã®èª¬æ
次ã®ãã«ãŠã§ã¢ã³ã³ããŒãã³ãã䜿çšããŠã調æ»å¯Ÿè±¡ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒã®ã€ã¡ãŒãžã®ãã¬ãŒã ã¯ãŒã¯å ã§æ»æãå®è£ ããŸããã
ã³ã³ããŒãã³ãå
| ã³ã³ããŒãã³ãã®å²ãåœãŠ
|
Malware_dll.dll
| ããŒãã¬ãŒïŒ32ãããïŒ
|
Malware_dll64.dll
| ããŒãã¬ãŒïŒ64ãããïŒ
|
Bach.dll
| SystemServiceã§ããå
ã®System_dll.dllã©ã€ãã©ãªã®ååãå€æŽããŸãã
|
System_dll.dll
| System_ServiceãµãŒãã¹ã®éå§æã«svchost.exeã«ãã³ããããã©ã€ãã©ãªã System_dll.dllã¯ããããã®ãã¹ãŠã®é¢æ°ãsystem_dll2.dllã«ãªãã€ã¬ã¯ãããããšã«ãããsystem_dll2.dllãšåãåŒã³åºãããµããŒãããŸãã ç· ããŸã_________ã 32ãããããŒãžã§ã³ã§ã
|
System_dll.dll_
| System_dll.dllã®64ãããããŒãžã§ã³
|
_________ãdll
| BackDoor 32ããã
|
_________ãdll_ver2
| 64ããã_________ãDll
|
S64
| x64ã¢ãŒããã¯ãã£çšã®ã¢ããã°System_dll.dll
|
P64
| ã¢ããã°_________ãx64ã¢ãŒããã¯ãã£çšã®DLL
|
It_helpdesk.exe
| ååãå€æŽãããPsExesvc.exeïŒæå®ãããã¢ã¯ã·ã§ã³ãå®è¡ããããã«ãªã¢ãŒããã·ã³ã§äœæããã³å®è¡ãããPSExecã³ã³ããŒãã³ã
|
Users.exe
| ããã¯ã㢠æ©èœã¯_________ Dllã«äŒŒãŠããŸãããjusched.exeãè£
ã£ããJava Update Schedulerã
|
æªæã®ããã³ã³ããŒãã³ãã®ã¢ã¯ãã£ããã£
- Malware_dll.dllïŒ
- ãã¡ã€ã«ã\ïŒ APPDATAïŒ \ LocalLow \ NTUSER.DATããäœæããŸãã
- mbowefvncwiomcowermg32ãã¥ãŒããã¯ã¹ã®äœæã
- ããŒããŒãã®ããŒã¹ãããŒã¯ã®ãã£ããã£ãèšå®ããŸãã
- åä¿¡ããããŒã¿ã®æå·åãšãæåã®æ®µèœããã®ãã¡ã€ã«ãžã®åŸç¶ã®èšé²ã
- System_dll.dllïŒ
- ã·ã¹ãã ãµãŒãã¹ã«ããèªåèµ·åã
- _________ãããŠã³ããŒãããŸãã
- _________ãdllããã³users.exeïŒ
- DNSã¢ãã¬ã¹ã®è§£æ±ºïŒ
-www.gf8ealht9d22________________.com
-832v1hda31sqfcl5bh81lmqk74z.xxxxxxxxx.com
-13bmvqdr1ju64dqm6n8877hbo0z.xxxxxxxxx.com - 管çãµãŒããŒïŒxxxxx.suïŒã«DNSãã±ãããéä¿¡ããŸãã
- 管çãµãŒããŒããåä¿¡ããã³ãã³ãã®å®è¡ã
- HKLMãŸãã¯HKCUãã©ã³ãã§ã®ããã»ã¹ã®åèµ·åã®éã«ããŒã¿ãä¿åããããã®ã¬ãžã¹ããªããŒãäœæããããšãã§ããŸãã
-\ãœãããŠã§ã¢\ Corporation \ 000
-\ãœãããŠã§ã¢\ Corporation \ 001
-\ãœãããŠã§ã¢\ Corporation \ 002
- DNSã¢ãã¬ã¹ã®è§£æ±ºïŒ
ã¯ã©ã€ã¢ã³ããµãŒããŒéä¿¡
ã¯ã©ã€ã¢ã³ããšã®ãµãŒããŒéä¿¡ã¯ãã¹ãŠæå·åãããŸãã æå·åããŒïŒ25 d9 01 4c 21 c9 ed 89 86 14 8d 05 _________
ãŠã€ã«ã¹ã¯ã解決ã®ããã«ç®¡çãµãŒããŒã«DNSãã±ãããéä¿¡ããŸãã 3çªç®ã®ãµããã¡ã€ã³ã§å§ãŸãDNSåã¯ããšã³ã³ãŒããããããŒã¿ã§ãã
<27ã·ã³ãã«> .xxxxx.suãšãã圢åŒã®ãã±ããããµãŒããŒã«éä¿¡ãããŸãã ã·ãŒã±ã³ã¹ã¯27æåãè¶ ããããšãã§ããŸãããæå°ãã±ããã¯27æåã§ãã 27æåã®ã·ãŒã±ã³ã¹ã¯ãã¯ã©ã€ã¢ã³ãããµãŒããŒã«éä¿¡ããæå·ååŸã«ãšã³ã³ãŒããããããŒã¿ã§ãã ãã®ããã±ãŒãžã«ã¯ãæ¬äŒŒä¹±æ°ãšããã±ãŒãžã®ããã·ã¥ä»¥å€ã®æ å ±ã¯å«ãŸããŠããŸããã ãã¹ãŠã®å€æåŸããã±ãããäºãã«é¡äŒŒããªãããã«ãæ¬äŒŒä¹±æ°ãå¿ èŠã§ãã 27æåã®ãã±ããã¯ãåŠçã³ãã³ããåãå ¥ããæºåãã§ããŠããããšããµãŒããŒã«äŒããŸãã ãã®ãããªããã±ãŒãžã®äŸïŒ
å¿çãšããŠãã³ãã³ãã¯6ã€ã®IPv4ã¢ãã¬ã¹-24ãã€ãã®ããŒã¿ã®åœ¢åŒã§æäŸãããŸãã ã¢ãã¬ã¹ããŒã¿ã¯é çªã«æžã蟌ãŸããäœãªã¯ãããã§ãœãŒããããŸãã äžäœãªã¯ããããç Žæ£ãããšã18ãã€ãã®ã·ãŒã±ã³ã¹ãåŸãããŸãã
æåã®ãã€ãã¯æªäœ¿çšããŒã¿ã®éã§ãïŒn = 1-3ïŒã
æåŸã®nãã€ãã¯æ¬äŒŒã©ã³ãã ã§ãããå°æ¥äœ¿çšãããŸããã
æ®ãã®ãã€ãã¯ãäžèšã®ããŒã§æå·åãããããŒã¿ã§ãã
æåã®3ãã€ãã¯ãç䌌乱æ°ãšãã±ããã®ããã·ã¥ã§ããããµãŒããŒããã®åãã³ãã³ããèŠèŠçã«ç°ãªããããIPã¢ãã¬ã¹ãã©ã³ãã ã«èŠããã®ã¯ãã®ããã§ãã æ®ãã¯ããŒã ã§ãã
次ã®ã¹ããããšç·©åç
ã€ã³ãžã±ãŒã¿ã®æ€çŽ¢ã®æåã®æ®µéã§ãã¢ã¯ãã£ããªDNSãã³ãã«ãèšé²ããã4ã€ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ç»åãåæãããŸããã
ãã¹ããšãããã¯ãŒã¯ã®ã€ã³ãžã±ãŒã¿ãŒãããã³æ»æè ã®ã¢ã¯ã·ã§ã³ã®äžè¬çãªãã¿ãŒã³ãç¹å®ããåŸãæææºãç¹å®ãã䟵害ããããã¹ãŠã®ããŒããæ€çŽ¢ããããã«ãã€ã³ãã©ã¹ãã©ã¯ãã£å šäœããã§ãã¯ããå¿ èŠããããŸããã
䟵害ã®å åã®æ€çŽ¢ã®å šäœåã¯æ¬¡ã®ãšããã§ãã
æ€çŽ¢ã¯ãSolar JSOCã®å°é家ãšåŸæ¥å¡ã®äž¡æ¹ãå®æœããŸããã åèšã§ãæ€çŽ¢ã«ã¯3æ¥ããããŸããã ææããã·ã¹ãã ã®ã¹ã«ãŠãã¯64ã«å¢å ãã䟵害ããããã·ã³ã®1ã€ããã¡ã€ã³ã³ã³ãããŒã©ãŒã§ãã£ãããã䟵害ãããã¢ã«ãŠã³ãã®æ°ã¯äŒç€Ÿã®åŸæ¥å¡ã®ç·æ°ãŸã§å¢å ããå¯èœæ§ããããŸããã
第äºæ®µéã§ã¯ãããã«ããã€ãã®ãã·ã³ã調æ»ã®ããã«éžæããã䟵害ã®è¿œå ææšãæ€çŽ¢ããŸããã ã€ã¡ãŒãžããã³ããåé€ããã䟵害ããããã¹ãã®ããªããŒããããã»ã¹ãéå§ããããšãã§ããŸããã
ãã®ãããªå€§èŠæš¡ã§é·æã«ãããæ·±ãææãæ€åºãããå Žåããå°Ÿãããããã«ããããã»ã¹ã¯éåžžã«å°é£ã§é·ããªããŸãã ã¢ã¯ã·ã§ã³ã®ã·ãŒã±ã³ã¹ã¯æ¬¡ã®ãšããã§ãã
- ã¢ã«ãŠã³ããæäœããïŒ
- ããžãã¹ã¢ããªã±ãŒã·ã§ã³ã®ã¢ã«ãŠã³ããå«ããæå®ããããã¹ãŠã®äŸµå®³ãããã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããå€æŽããŸãã
- ãµãŒãã¹ã¢ã«ãŠã³ãã®ç¹æš©ã¯å¶éãããŠããããµãŒãã¹ã®æäœã®ããã®ãã¡ã€ã³ç®¡çè æš©éãæã€ã¢ã«ãŠã³ãã®äœ¿çšãçŠæ¢ãããŸããã
- ã¢ã«ãŠã³ãã§ã®äœæ¥äžã«ãIT管çè ãé€ãåŸæ¥å¡ã®ãªã¢ãŒãã¢ã¯ã»ã¹ã®äœ¿çšã«é¢ããã¢ã©ããªã¢ã ãå°å ¥ãããŸããã 䞊è¡ããŠã圌ãã®ããã«2çªç®ã®èªèšŒèŠçŽ ãéå§ãããŸããã
- éçºãããã€ã³ãã©ã¹ãã©ã¯ãã£ãæã€çµç¹ã®å
žåçãªã®ã£ãããåããŸããïŒ
- ãããã·ããã€ãã¹ããçŽæ¥ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã
- ãŠã€ã«ã¹ã§ã¯ãªããšåé¡ãããã€ã³ã¿ãŒããããç©æ¥µçã«äœ¿çšããŠãããœãããŠã§ã¢ãåé€ããŸããã
- å¢çäžã®éããŠããããŒãã®ãããã¡ã€ã«ãçµã¿ç«ãŠãããäžå¿ èŠãªãããããªãããŒããæ€èšŒãããŠéããããŸããã
- ã¢ããªã±ãŒã·ã§ã³ç®¡çè ã¯ãéèŠãªããžãã¹ã¢ããªã±ãŒã·ã§ã³ã§å®è¡ãããã¢ã¯ã·ã§ã³ãšãã©ã³ã¶ã¯ã·ã§ã³ãç¹ã«éèãã©ã³ã¶ã¯ã·ã§ã³ãããŒãã¹ããã³ãã€ã€ã«ãã£ããã°ã©ã å ã®ãã©ã³ã¶ã¯ã·ã§ã³ãã¯ã©ã€ã¢ã³ãããã³ããŒãããŒããŒã¹ãžã®ã¢ã¯ã»ã¹ãªã©ã«é¢é£ããã¢ã¯ã·ã§ã³ã®å¶åŸ¡ãå³ããããŠããŸãã
- IT管ââçè åãã«ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ããŒã«ã«ã¢ã«ãŠã³ãã§éèŠãªããžãã¹ã¢ããªã±ãŒã·ã§ã³ãæäœããããšã«å¯Ÿããå®å šãªçŠæ¢ãå°å ¥ãããŸããã ç£èŠã·ã¹ãã ã®å¶åŸ¡äžã§ããã¹ãŠãå¶éãããç¹æš©ãæã€ãã¡ã€ã³ã¢ã«ãŠã³ãã«è»¢éãããŸããã
äž»ãªæšå¥šäºé
ãšç£èŠæ段
æ»æè ã¯åžžã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®ã¢ã¯ã»ã¹ãäºçŽããŠããããã䞊è¡ããŠã€ã³ã·ãã³ãã®å®å šãªç£èŠãšãã¹ãŠã®ã¢ã¯ãã£ããã£ã®ãããã¡ã€ãªã³ã°ãå®è¡ãããŸããã
åŸè ã«ã¯å¥ã®åé¡ããããŸããã2é±éã§ãããã¡ã€ã«ãåéãããããæ»æè ãã€ã³ãã©ã¹ãã©ã¯ãã£å ã«ããå¯èœæ§ããããããèªä¿¡ãæã£ãŠæ£åœãšåŒã¶ããšã¯ã§ããŸããã ãããã£ãŠãåéããããã¹ãŠã®æŽ»åãäŒç€Ÿãšèª¿æŽããå°æ¥çã«ã¯åéããããããã¡ã€ã«ãä¿®æ£ããæé ãå¿ èŠã§ããã ããã¯ã¢ããã¢ã¯ã»ã¹ãèå¥ããããã®äžè¬çãªæšå¥šäºé ã¯æ¬¡ã®ãšããã§ãã
- ãªã¢ãŒãã³ã³ãããŒã«ããŒã«ãšäžæ£ãªãœãããŠã§ã¢ãèå¥ããããã«ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãç£æ»ããã
- äŒç€Ÿã®éèŠãªã³ã³ãã¥ãŒã¿ãŒããã³ãµãŒããŒã§ã®ããã°ã©ã ã®èµ·åãå¶åŸ¡ããèš±å¯ããããœãããŠã§ã¢ã®ããã¯ã€ããªã¹ãããå°å ¥ããŸããç¹ã«ãªã¢ãŒãã³ã³ãããŒã«ããŒã«ã«é¢é£ããŸãã
åæã«ãSolar JSOCã¯ã次ã®åéã®éèŠãªãµãŒããŒãšã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ã¢ã¯ãã£ããã£ãç£èŠããŸããã
- æ¢ç¥ã®å±éºãªãªãœãŒã¹ãšæªæã®ãããªãœãŒã¹ãžã®ãããã¯ãŒã¯ã¯ãšãªãããã³æªæã®ãããã¡ã€ã³ãžã®DNSã¯ãšãªã®è©Šè¡ã
- ç¹æš©ã¢ã«ãŠã³ãã¢ã¯ãã£ããã£-ã¢ã¯ã·ã§ã³ã®æ€èšŒã®ããã«ãã¬ããŒãã責任ããåŸæ¥å¡ãšã¢ã«ãŠã³ãææè ã«æ¯æ¥éä¿¡ãããŸããã
- ç¹æš©ãŠãŒã¶ãŒã°ã«ãŒãã®å€æŽã
- éèŠãªãµãŒããŒããã³ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ããã»ã¹ãèµ·åããŸããã
- äžæ£ãªå®è¡å¯èœãã¡ã€ã«ãã©ã€ãã©ãªãããã³ãã©ã¡ãŒã¿ãŒã®ã·ã¹ãã ãã£ã¬ã¯ããªããã³éèŠãªã¬ãžã¹ããªãã©ã³ãã®å€æŽã
- ãªã¢ãŒãã³ã³ãããŒã«ã·ã¹ãã ã䜿çšããã
- DNSãã©ãã£ãã¯ã®ç°åžžã
- éèŠãªãã¹ãã§ã®ãŠã€ã«ã¹æŽ»åã
- æªæã®ããã¡ãŒãªã³ã°ãªã¹ãã
- éèŠãªãµãŒããŒã«æ¥ç¶ãããããã¡ã€ã«ã®ç°åžžã
- ãµãŒãã¹ã¢ã«ãŠã³ãã®èª€çšã
äž»ãªèª¿æ»çµæãšã€ã³ã·ãã³ã調æ»ã®èª¿æ»çµæ
è åšããããã¯ããããã®éçšäžã®æªçœ®ãè¬ããåŸãã€ã³ã·ãã³ãã«é¢ããå®å šãªã¬ããŒãã®æéãç»å ŽããŸããã
- ãã«ãŠã§ã¢ãææãããã·ã³ã«å°éããããã®ãã£ãã«ã¯ãæææã«ãã§ã«äŸµå®³ãããŠãããäŒç€Ÿã®LANå ã®è€æ°ã®ã³ã³ãã¥ãŒã¿ãŒãã䜿çšãããŠãããã¡ã€ã³ç®¡çè æš©éãæã€ã¢ã«ãŠã³ãã§ããã
- PsExecããŒã«ã¯ãæªæã®ãããã¡ã€ã«ããã·ã³ã«è»¢éãããªã¢ãŒãã³ã³ãããŒã«ã³ãã³ããå®è¡ããããŒãã¬ãŒã§ãã·ã³ã®ææãå®äºããããã«äœ¿çšãããŸããã
- æ°å¹Žåã«ããã«èŠã€ãã£ãä»ã®ãªã¢ãŒãã³ã³ãããŒã«ãœãããŠã§ã¢ã®çè·¡ããææããææãã·ã³ã§èŠã€ãããŸããã RATã«ã¯TIghtVNCãWinVNCãPointdevããããŸããã
- ããŒãã¬ãŒã®çµæãšããŠãååãšããŠãOSããã³å€æ°ã®ããžãã¹ã¢ããªã±ãŒã·ã§ã³ããã®ãŠãŒã¶ãŒè³æ Œæ å ±ãã¡ãŒã«éä¿¡ãäž»èŠãªããžãã¹ã¢ããªã±ãŒã·ã§ã³ãµãŒããŒããã®ãã¹ã¯ãŒãæ å ±ãå«ãéèŠãªãã¡ã€ã«ãããã³åŸæ¥å¡ã®ãã¹ããŒãããŒã¿ã䟵害ãããŸããã
- ãã®åŸã®æ»æè åãã®ãªã¢ãŒãå¶åŸ¡ããã³æ å ±è»¢éãã£ãã«ã¯DNSãã³ãã«ã§ããã
æåŸã«ãåæ§ã®ã€ã³ã·ãã³ããæ€åºããããšã¯ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒã®ã¿ã¹ã¯ã§ããããšã«æ³šæããããšæããŸãããããããªããã°ãäŒç€Ÿã®æ®éã®åŸæ¥å¡ãšäœæ¥ãæŽçããåžžã«ã»ãã¥ãªãã£æèãé«ããããšãã§ããŸãã
ãããã®ã«ããŽãªã®åŸæ¥å¡ã¯æ å ±ã»ãã¥ãªãã£ã®åéã§æèœã§ãããããŸããŸãªç°åžžãå€éšã®åœ±é¿ã«ãã£ãŠåŒãèµ·ããããå¯èœæ§ãããããšãç解ããŠãããããæ»æè ã¯ãã°ãã°æŽ»åãæ å ±ã»ãã¥ãªãã£ãµãŒãã¹ããã³IT管çè ããé ãããšããŸãã åæã«ãããã«ãŒã¯éåžžãèªåã®è¡åãäžè¬ãŠãŒã¶ãŒããé ãããšãæ ã£ãŠããŸãã ã³ã³ãã¥ãŒã¿ãŒã®è² è·ã®å¢å ãã·ã¹ãã ã§ã®å¥åŠãªã¢ã¯ã·ã§ã³ãçªç¶ééããã¢ããªã±ãŒã·ã§ã³ãæ°ãããã¡ã€ã«ã®å€èŠ³ãã¢ã€ã³ã³ããŠãŒã¶ãŒãæ°ä»ãã€ã³ã¹ããŒã«æžã¿ã¢ããªã±ãŒã·ã§ã³ã¯ãã·ã¹ãã ã®äŸµå®³ã®ææšãšããŠæ©èœããŸãã ãããã£ãŠãèŠåå¡ã¯ãå ¥ã£ãŠããèŠæ±ãäŒç€Ÿã®è·å¡ããã®èŠæ ã«æ³šæãæãå¿ èŠããããåŸæ¥å¡ãäžèšã®ç°åžžã®è²¬ä»»è ã«éç¥ããããã«åæ©ä»ãããå¿ èŠããããŸãã