æ°ããESETã®èª¿æ»ã§ã¯ãDridexäœæè ãå¥ã®æåãªãã«ãŠã§ã¢ãã¡ããªã®èåŸã«ããããšã蚌æãããŠããŸããããã¯ãWin32 / Filecoder.FriedExãWin64 / Filecoder.FriedExãªã©ã®ESETã®ãŠã€ã«ã¹å¯Ÿç補åã«ãã£ãŠæ€åºãããæŽç·ŽãããBitPaymeræå·åã§ãã
ããªããã¯ã¹
Dridexãã³ãã³ã°åããã€ã®æšéŠ¬ã¯2014幎ã«åããŠçºèŠãããå€ããããžã§ã¯ãã«åºã¥ããæ¯èŒçåçŽãªãããã§ããã ããããäœè ã¯ããã«ãããåžå Žã§æãæŽç·Žãããéè¡ããã€ã®æšéŠ¬ã®1ã€ã«å€ããŸããã éçºãç¶ç¶ããŠããããã§ã-ãã€ããŒãªä¿®æ£ãšæŽæ°ã䌎ããããã®æ°ããããŒãžã§ã³ãã»ãŒæ¯é±ãªãªãŒã¹ãããŸãã éæãæ°ããæ©èœãŸãã¯éèŠãªå€æŽã䌎ãã¡ãžã£ãŒã¢ããããŒãã衚瀺ãããŸãã ããŒãžã§ã³3ããããŒãžã§ã³4ãžã®ææ°ã®æŽæ°ããã°ã©ã ã¯2017幎ã®åãã«å°å ¥ããã Atom Bombingã€ã³ãžã§ã¯ã·ã§ã³æè¡ãå°å ¥ãããŸããã 2017幎åŸåãèè ã¯Microsoft Wordã®è匱æ§ãæªçšããæ°ãã0ãã€ãšã¯ã¹ããã€ããå°å ¥ããäœçŸäžãã®è¢«å®³è ã«å°éããŸããã
ãã®æçš¿ã®å·çæç¹ã§ãDridex 4.80ã®ææ°ããŒãžã§ã³ã«ã¯ãChromeããŒãžã§ã³63ã§ã®Webã€ã³ãžã§ã¯ã·ã§ã³ã®ãµããŒããå«ãŸããŠããŸããDridex4.80ã¯2017幎12æ14æ¥ã«ãªãªãŒã¹ãããŸããã
泚ïŒæšå¹Žã人æ°ã®ããWebãã©ãŠã¶ãŒã§æªæã®ããããã¯ãèå¥ããããŒã«ããªãªãŒã¹ããŸããã ãã®ããŒã«ã¯ãDridexãå«ãéè¡ã®ããã€ã®æšéŠ¬ã®æœåšçãªææã®æ€åºã«åœ¹ç«ã€ããã«èšèšãããŠããŸãã
ããªãŒããã¯ã¹
å ã BitPaymerãšåŒã°ããŠããŸããïŒèº«ä»£éãµã€ãã®ããã¹ãã«åºã¥ãïŒããšã³ã³ãŒããŒã¯ã2017幎7æäžæ¬ã«Michael Gillespieã«ãã£ãŠéãããŸããã 8æããã®ãã«ãŠã§ã¢ã¯ã¹ã³ããã©ã³ãåœç«ä¿å¥å±ã®æ©é¢ãžã®æ»æãæåããåŸã«æ³šç®ãéããŸããã
FriedExã¯ãäžè¬çãªãŠãŒã¶ãŒã§ã¯ãªããé«ã¬ãã«ã®ç®æšãšäŒæ¥ã«çŠç¹ãåœãŠãŠãããéåžžã¯RDP bruteforceãä»ããŠé ä¿¡ãããŸãã ããã°ã©ã ã¯ãã©ã³ãã ã«çæãããRC4ããŒã䜿çšããŠåãã¡ã€ã«ãæå·åããŸã
.readme_txt
ããŒã¯ãããŒãã³ãŒãããã1024ãããRSAå ¬éããŒã䜿çšããŠæå·åããã察å¿ãã
.readme_txt
ãã¡ã€ã«ã«ä¿åãããŸãã
2017幎12æã«ãFriedExãµã³ãã«ã®1ã€ã調ã¹ããšãããã»ãšãã©ããã«Dridexãšã³ãŒãã®é¡äŒŒæ§ãèŠã€ãããŸããã ãã®çºèŠã«èå³ãæã£ãŠã詳现ãªèª¿æ»ãå®æœããFriedExã¯Dridexãšåãæ¹æ³ã§è¡åã«é¢ããæ å ±ãé èœããŠããããšãçºèŠããŸããã
FriedExã¯ããªã³ã¶ãã©ã€ãã§ã·ã¹ãã ã®APIãžã®ãã¹ãŠã®åŒã³åºããèªèããããã·ã¥ã䜿çšããŠããããæ€çŽ¢ãããã¹ãŠã®æååãæå·å圢åŒã§ä¿åããããã·ã¥ã䜿çšããŠã¬ãžã¹ããªããŒãšå€ã調ã¹ãŸããçµæã®ãã€ããªãã¡ã€ã«ã¯éçããããã£ã«é¢ããŠã»ãšãã©ç®ç«ã¡ãŸããã ãã«ãŠã§ã¢ãäœãããããèŠã€ããããšã¯ããã詳现ãªåæãªãã§ã¯åé¡ããããŸãã
ãã®ãããããã«åæãè¡ããçããè£ä»ããè¿œå ã®å±æ§ãæããã«ããŸããã2ã€ã®ãã«ãŠã§ã¢ãã¡ããªãåãéçºè ã«ãã£ãŠäœæãããŸããã
ã³ãŒãã®é¡äŒŒç¹
å³1. Dridexããã³FriedExãµã³ãã«ã®GetUserIDé¢æ°ã®æ¯èŒ-10ã®éããèŠã€ãã
å³1ã¯ããã¹ãŠã®ãã€ããªDridexãã¡ã€ã«ïŒããŒãããŒããŒãšãããã¢ãžã¥ãŒã«ïŒã«ããUserIDã®çæã«äœ¿çšãããé¢æ°ã®äžéšã瀺ããŠããŸãã Dridexåºæã®é¢æ°ã¯ãFriedExãã€ããªã§ã䜿çšãããŸãã é¢æ°ã®ã¿ã¹ã¯ã¯åãã§ã-被害è ã®ãã·ã³ã®ããã€ãã®å±æ§ã®æååãçæããäžæã®èå¥åãšããŠæ©èœããŸã-Dridexã«ã€ããŠè©±ããŠããå ŽåãšãFriedExã®å Žåã®æå·åè£ çœ®ã«ã€ããŠã¯ãããããããã§
Dridexãšã®ãã®é¡äŒŒæ§ã¯ããã¹ãŠã®FriedExãã€ããªã«ååšããŸãã ãšã³ã³ãŒããŒã®ç¹å®ã®æ©èœïŒèº«ä»£éã¡ãã»ãŒãžã䜿çšããæå·åããã³ãã¡ã€ã«äœæãµã€ã¯ã«ïŒã«é¢é£ããèŠåãšããŠãããå°æ°ã®æ©èœã®ã¿ãDridexãµã³ãã«ãšäžèŽããŸããã
å³2. Dridexããã³FriedExãµã³ãã«ã®é¢æ°ã®é åºã®æ¯èŒã å¥ã®ãµã³ãã«ã§äœ¿çšã§ããªãæ©èœã¯åŒ·èª¿è¡šç€ºãããŠããŸãã
å¥ã®äžè¬çãªæ©èœã¯ãåãã³ãŒãããŒã¹ãŸãã¯éçã©ã€ãã©ãªãè€æ°ã®ãããžã§ã¯ãã§äœ¿çšããããšãã«çºçãããã€ããªãã¡ã€ã«å ã®é¢æ°ã®ã·ãŒã±ã³ã¹ã§ãã å³2ã§ãããããã«ãFriedExãµã³ãã«ã«ã¯Dridexãµã³ãã«ã«ååšããé¢æ°ã®äžéšãæ¬ ããŠããŸããããã®éãåæ§ã§ãããé åºã¯å€ãããŸããã
泚ïŒã³ãŒãå ã®ã¢ãã¬ã¹ã«åºã¥ããŠèªåçã«çæãããé¢æ°åã®ãã¢ïŒ
sub_CA5191
ããã³
sub_2A56A2
ãªã©ïŒã¯æããã«äžèŽããŸããããåç §ããã³ãŒãã¯äžèŽããŸãã
DridexãšFriedExã®äž¡æ¹ãåãæªæã®ããããã«ãŒã䜿çšããŠããããšã«èšåãã䟡å€ããããŸãã ãã ãããã®ããã«ãŒã¯çŸåšéåžžã«äººæ°ããããŸããããã¯ãããããæ€åºãé²æ¢ããåæãè€éã«ããå¹æãããããã§ãã QBotãEmotetãUrsnifãªã©ã®ä»ã®ãã«ãŠã§ã¢ãã¡ããªã§äœ¿çšãããŠããããããã®ååšã決å®çãªèšŒæ ãšã¯èŠãªããŸããã
PDBãã¹
Windowså®è¡å¯èœãã¡ã€ã«ãäœæãããšãããªã³ã«ãŒã¯ãéçºè ããšã©ãŒãä¿®æ£ããŠé害ãç¹å®ããã®ã«åœ¹ç«ã€ãããã°ã·ã³ãã«ãå«ããã¡ã€ã«ãæãPDBïŒããã°ã©ã ããŒã¿ããŒã¹ïŒãã¹ãå«ããããšãã§ããŸãã å®éãPDBãã¡ã€ã«ã¯ãé åžã«å«ãŸããªãç¬ç«ãããã¡ã€ã«ã§ããããããã«ãŠã§ã¢ã«ã¯ã»ãšãã©å«ãŸããŸããã
PDBãã¡ã€ã«ã¯ããã©ã«ãã§ã³ã³ãã€ã«ãããå®è¡å¯èœãã¡ã€ã«ãšåããã£ã¬ã¯ããªã«ãããéåžžã¯åãããŒã¹åã«.pdbæ¡åŒµåãä»ããŠããããããã¹ã¯è²Žéãªæ å ±ãæäŸããŸãã èè ãæ å ±ãé瀺ããããšãæãŸãªããããPDBãã¹ãéåžžãã«ãŠã§ã¢ã«å«ãŸããªãããšã¯è«ççã§ãã 幞ããªããšã«ãäžéšã®Dridexããã³FriedExãµã³ãã«ã«ã¯PDBãã¹ããããŸãã
å³3. Dridexããã³FriedExãããžã§ã¯ãã§èŠã€ãã£ããã¹ãŠã®PDBãã¹
å³3ã«ç€ºãããã«ãäž¡æ¹ã®ãããžã§ã¯ãã®ãã€ããªãã¡ã€ã«ã¯åããã£ã¬ã¯ããªã«åéãããŸãã å©çšå¯èœãªãã«ãŠã§ã¢ãµã³ãã«ã®ã¡ã¿ããŒã¿ã®æ€çŽ¢ã«åºã¥ããŠã
S:\Work\_bin\
ã¯Dridexããã³FriedExãããžã§ã¯ãã«åºæã§ãããšçµè«ä»ããŸããã
ã¿ã€ã ã¹ã¿ã³ã
åãã³ã³ãã€ã«æ¥ã§DridexãšFriedExãæ€åºããã€ã³ã¹ã¿ã³ã¹ãããã€ããããŸãã ããã¯å¶ç¶ãããããŸãããã詳ãã調ã¹ãçµæããã®ãããªããŒãžã§ã³ã¯é€å€ãããŸããã
åãæ¥ä»ã®ã³ã³ãã€ã«ã¯æ°åç°ãªãã ãã§ãªãïŒDridexã®äœæè ãäž¡æ¹ã®ãããžã§ã¯ããåæã«ã³ã³ãã€ã«ãããšä»®å®ã§ããŸãïŒããããã®ãµã³ãã«ã§ã©ã³ãã ã«çæãããå®æ°ãåãã§ãã å®æ°ã¯ãåæãå°é£ã«ããæ€åºãåé¿ããããã«ãããªã¢ãŒãã£ãºã ã®åœ¢åŒãšããŠåã³ã³ãã€ã«ã§å€æŽãããŸãã ããã¯ãã³ã³ãã€ã«ããšã«å®å šã«ã©ã³ãã åããããšããçŸåšã®æ¥ä»ãªã©ã®å€æ°ã«åºã¥ããŠã©ã³ãã åããããšãã§ããŸãã
å³4. 3æ¥éã®ã³ã³ãã€ã«æéå·®ãããDridexãµã³ãã«ã®GetAPIByHashé¢æ°ã ãã€ã©ã€ããããå®æ°ã¯ç°ãªããŸã
å³4ã§ã¯ãDridexããŒãããŒããŒã®2ã€ã®ãµã³ãã«ãšã3æ¥éã®ã³ã³ãã€ã«æéã®éããæ¯èŒããŠããŸãã ããŒããŒã¯ã»ãšãã©åãã§ãããå¯äžã®éãã¯ãæå·åããŒãCïŒCãµãŒããŒã®IPã¢ãã¬ã¹ãªã©ã®ããŒãã³ãŒããããããŒã¿ã§ãã ãã®å Žåãå®æ°ã¯ç°ãªãããããã¹ãŠã®ããã·ã¥ã¯ãããã«åºã¥ããŠããŸãã
äžæ¹ãå³5ã§ã¯ã1æ¥ã§ã³ã³ãã€ã«ãããDridexããŒãããŒããŒãšFriedExããŒãããŒããŒã®æ¯èŒãèŠãããšãã§ããŸãïŒã¿ã€ã ã¹ã¿ã³ãã®å·®ã¯2åã§ãïŒã å®æ°ã¯åãã§ããããã¯ãåãã³ã³ãã€ã«ã»ãã·ã§ã³äžã«äž¡æ¹ã®ãµã³ãã«ãäœæãããããšã瀺ããŸãã
å³5. 1æ¥ã§ã³ã³ãã€ã«ãããDridexããã³FriedExãã€ããªã®GetAPIByHashé¢æ° éžæããå®æ°ã¯ãäž¡æ¹ã®ãµã³ãã«ã§åäžã§ãã
ã³ã³ãã€ã©ãŒæ å ±
ã³ã³ãã€ã©ãŒæ å ±ã¯ãåè¿°ã®èšŒæ ã確èªããŸãâ Dridexããã³FriedExãã€ããªãŒã¯Visual Studio 2015ã§ã³ã³ãã€ã«ãããŸãããããã«ãããPEããããŒãšãªããããããŒããŒã¿ã§èŠã€ãã£ããªã³ã«ãŒããŒãžã§ã³ã確èªãããŸãã
å³6. Dridexããã³FriedExãµã³ãã«ã®ãªããããããŒããŒã¿
Dridexãšã®æãããªé¡äŒŒæ§ã«å ããŠã以åã¯ææžåãããŠããªãã£ããšã³ã³ãŒãã®64ãããããŒãžã§ã³ã«çŽé¢ããŠããŸãã éåžžã®32ãããããŒãžã§ã³ã¯x86ããã³x64ã·ã¹ãã åãã§ããããããã®ãµã³ãã«ã¯éåžžã«èå³æ·±ããã®ã§ãã
ãããã«
äžèšã®èšŒæ ã«åºã¥ããŠãFriedExã¯Dridexã®äœæè ã®äœåã§ãããšèããŠããŸãã ãã®çºèŠã«ããããµã€ããŒã°ã«ãŒãã®æŽ»åã®ããå®å šãªå šäœåãåŸãããŸã-ããã«ãŒã¯éåžžã«æŽ»çºã§ããããã³ãã³ã°ããã€ã®æšéŠ¬ïŒChromeã®ææ°ããŒãžã§ã³ã®Webã€ã³ãžã§ã¯ã·ã§ã³ãŸãã¯Atom Bombingãå«ãæ°æ©èœã®å°å ¥ã®ãµããŒãïŒã絶ããæŽæ°ããã ãã§ãªããææ°ã®ãã¬ã³ãããã©ããŒããŠããããšãããããŸããç¬èªã®ãšã³ã³ãŒããŒãäœæããŸãã
å°æ¥ãäºæž¬ããããšã¯å°é£ã§ãããDridexã°ã«ãŒãã¯è¿ãå°æ¥ãã®æŽ»åãçž®å°ãããå€ããããžã§ã¯ããåŒãç¶ããµããŒãããããããæ°ãããµã³ãã«ã®å©ããåããŠããŒããã©ãªãªãæ¡å€§ãããšèããŠããŸãã
é·ãéãDridexã¯éè¡ã®ããã€ã®æšéŠ¬ã«çŠç¹ãåœãŠããåäžããŒã«ã®ã¢ã¯ã¿ãŒããšèŠãªãããŠããŸããã ä»æ¥ãããã¯ããã§ã¯ãªãããšãããããŸããã ããã«ãŒã¯æ°ãããã¬ã³ãã«ç°¡åã«é©å¿ããä»ã®ã¿ã€ãã®ãã«ãŠã§ã¢ãäœæããŠããã®ã«ããŽãªã§æãé«åºŠãªãã®ãšç«¶åããããšãã§ããŸãã
䟵害ã€ã³ãžã±ãŒã¿
Win32/Dridex.BE C70BD77A5415B5DCF66B7095B22A0DEE2DDA95A0
Win64/FriedEx.A CF1038C9AED9239B6A54EFF17EB61CAB2EE12141
Win32/FriedEx.A 8AE1C1869C42DAA035032341804AEFC3E7F3CAF1