å°ãåã«ãTurlaã䜿çšããã¯ãŒã¯ã¹ããŒã·ã§ã³ã䟵害ããæ°ããæ¹æ³ãçºèŠããŸããã ãã®ææ³ã¯ããœããšãé£éŠã®å€§äœ¿é€šãé äºé€šã®åŸæ¥å¡ãçã£ãæ»æã§äœ¿çšãããŸãã

1.æŠèŠ
Turlaã¯æ°å¹Žéãåœã®Adââobe Flash Playerã€ã³ã¹ããŒã©ãŒã䜿çšããŠè¢«å®³è ã䟵害ããŸããã ãã®ãããªãã¯ãã«ã¯è€éãªãšã¯ã¹ããã€ããå¿ èŠãšããŸãã;æåã¯ãåœç©ãã€ã³ã¹ããŒã«ããããšã確信ããŠãããŠãŒã¶ãŒã®ä¿¡çšåºŠã«äŸåããŸãã
è¿å¹ŽãTurlaããã¯ãã¢ã®1ã€ã«ææããç°åžžãªæ°ããåäœã確èªãããŠããŸãã çã®Flashã€ã³ã¹ããŒã©ãŒãåããããã±ãŒãžã«ããã±ãŒãžåãããŠããã ãã§ãªããadobe.comããããŠã³ããŒããããŠããããã«ãèŠããŸãã ãšã³ããŠãŒã¶ãŒã®èŠ³ç¹ããèŠããšããªã¢ãŒãIPã¢ãã¬ã¹ã¯ãæ£èŠã®Flash Playerã€ã³ã¹ããŒã©ãŒãé åžããããã«ã¢ããã䜿çšããå ¬åŒã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ïŒCDNïŒã§ããã¢ã«ãã€ãææããŠããŸãã ããã»ã¹ã調ã¹ãçµæãåœã®Flashã€ã³ã¹ããŒã©ãŒïŒmacOSçšã®Snakeããã¯ãã¢ã€ã³ã¹ããŒã©ãŒãå«ãïŒãget.adobe.com URLã«å¯ŸããŠGETãªã¯ãšã¹ããè¡ããæ°ãã䟵害ããããã·ã³ã«é¢ããããŒã¿ãçã¿åºããŠããããšãããããŸããã ãã¬ã¡ããªããŒã¿ã«ãããšãIPã¢ãã¬ã¹ã¯ã¢ããã䜿çšããæ£åœãªIPã¢ãã¬ã¹ã§ããã
ãã®ã¬ããŒãã§ã¯ãåæ§ã®æªæã®ããåäœã«ã€ãªããå¯èœæ§ã®ããæ¹æ³ã«ã€ããŠèª¬æããŸãã ããŒã¿ã«ãããšããã®ãã«ãŠã§ã¢ã¯Adobe Flash Playerã®æ£åœãªæŽæ°ã䜿çšããŠããããAdobe補åã®æ¢ç¥ã®è匱æ§ãšã¯é¢ä¿ãããŸããã ã¢ããã¯äŸµå®³ãããŠããªããšå®å šã«èšããŸãã æ»æè ã¯ãã©ã³ãã䜿çšããŠãŠãŒã¶ãŒã欺ãã ãã§ããã
ãŸããTurlaã°ã«ãŒãã¯ãGoogle Apps ScriptãµãŒãã¹ã§ãã¹ããããŠããWebã¢ããªã±ãŒã·ã§ã³ãJavaScript malvariã®ããŒã ãµãŒããŒïŒCïŒCïŒãšããŠäœ¿çšããŠããããšãçºèŠããŸããã æ»æè ã¯å¯èœãªéãéãã«äœæ¥ããåŸåããããæšççµç¹ã®ãããã¯ãŒã¯ãã©ãã£ãã¯ã§ã®æŽ»åãé ãåŸåãããããšã¯æããã§ãã
ãã¬ã¡ããªã«ãããšãå°ãªããšã2016幎7æ以éãTurlaããã°ã©ã ãget.adobe.com URLã«æ å ±ãéä¿¡ããŠãããšãã蚌æ ããããŸãã 被害è ã¯æ§ãœé£ã®é åã«ããŸãã Turlaãéçºãããã1ã€ã®ãã«ãŠã§ã¢ã§ããGazerã«ã€ããŠã¯ãæ±ãšãŒãããã®åœã®é äºé€šãšå€§äœ¿é€šãæšçãšããŠããŸãã æ°éäŒæ¥ã§ããã€ãã®ææã確èªãããŠããŸãããæ»æã®äž»ãªæšçã§ã¯ãªãããã§ãã æåŸã«ãComRATãGazerãªã©ãTurlaãææããä»ã®ãã«ãŠã§ã¢ã«ææãã被害è ãããŸãã
2.ãªããã®ãã£ã³ããŒã³ãTurlaã°ã«ãŒãã«é¢é£ä»ããã®ã§ããïŒ
ç°åžžãªãããã¯ãŒã¯æ¥ç¶ãåæããåã«ããã®Turlaãã£ã³ããŒã³ã®åå ã説æããŸãã
ãŸããAdobe Flash Playerã®åœã®ã€ã³ã¹ããŒã©ãŒã®äžéšã¯ãäžéšã®IBäŒæ¥ãTurlaã«é¢é£ä»ããŠããMosquitoããã¯ãã¢ãããŠã³ããŒãããŸãã
第äºã«ããã¹ããããããã¯ãã¢ã«é¢é£ä»ããããŠããäžéšã®CïŒCãµãŒããŒã¯ãTurlaã«é¢é£ãã SATCOM IPã¢ãã¬ã¹ã䜿çšãããã以åã«äœ¿çšããããšããããŸãã
第äžã«ããã«ãŠã§ã¢ã¯Turlaã°ã«ãŒãã®ä»ã®ããŒã«ãšå ±éã®æ©èœãåããŠããŸãã é¡äŒŒç¹ã«ã¯ãåäžã®æååé£èªåïŒã¹ã¿ãã¯ã«è¡ãããã·ã¥ãã0x55ã§XORãé©çšããïŒãšåãAPI解å床ãå«ãŸããŸãã
ãªã¹ããããé ç®ã䜿çšãããšããã£ã³ããŒã³ãšTurlaãšã®é¢ä¿ãèªä¿¡ãæã£ãŠå€æã§ããŸãã
3. Adobââe Flashããã³Flashé¢é£ãã¡ã€ã³ã®éæ³ãªäœ¿çš
åœã®Flashã€ã³ã¹ããŒã©ãŒã䜿çšããããšã¯ãTurlaã«ãšã£ãŠæ°ããæŠè¡ã§ã¯ãããŸããã ãã®ããã2014幎ã«å°é家ããã®åäœãææžåããŸããã ãã ããç§ãã¡ã®æèŠã§ã¯ããã«ãŠã§ã¢ã¯ãŸãã¢ããã®æ£åœãªURLãšIPããHTTPçµç±ã§ããŠã³ããŒããããŸãã ããã¯ãçµéšè±å¯ãªãŠãŒã¶ãŒã«ãšã£ãŠãæ··ä¹±ãæãå¯èœæ§ããããŸãã
3.1ã adobe.comãä»ããæš¡å£é åž
2016幎8æã®åããããadmdownload.adobe.comããTurlaã€ã³ã¹ããŒã©ãŒãããŠã³ããŒãããããšããè©Šã¿ãããã€ãèŠã€ãããŸããã
äžèŠãTCPãœã±ãããCïŒCãµãŒããŒã®IPã¢ãã¬ã¹ã«ã€ã³ã¹ããŒã«ãããŠããéã«ãHTTPèŠæ±ã®HostããããŒãèšå®ãããšããå žåçãªããªãã¯ã衚瀺ãããããã«æãããŸããã ãããã詳现ãªåæã®çµæãIPã¢ãã¬ã¹ã¯æ£åœã§ãããæ£åœãªFlashã€ã³ã¹ããŒã©ãŒãé åžããããã«ã¢ããã䜿çšãã倧èŠæš¡ã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ïŒCDNïŒã§ããAkamaiã«å±ããŠããããšãããããŸããã
å®è¡å¯èœãã¡ã€ã«ãæ£åœãªURLïŒããšãã°ã
http://admdownload.adobe.com/bin/live/flashplayer27_xa_install.exe
ïŒããããŠã³ããŒããããå Žåã§ããåç §å ãã£ãŒã«ãã¯å€æŽãããããã«èŠããŸãã ãã®ãã£ãŒã«ãã
http://get.adobe.com/flashplayer/download/?installer=Flash_Player
ã«å€æŽãããAdobeã䜿çšããURLãã¿ãŒã³ãšã¯
http://get.adobe.com/flashplayer/download/?installer=Flash_Player
ããªã¯ãšã¹ãã§404ãšã©ãŒãçºçããããšãããããŸããã
åéãããããŒã¿ã§èŠã€ãã£ããã¹ãŠã®ããŠã³ããŒãè©Šè¡ã¯ãHTTPSã§ã¯ãªãHTTPçµç±ã§è¡ãããããšã«æ³šæããããšãéèŠã§ãã ããã«ããããŠãŒã¶ãŒã®ãã·ã³ããã¢ã«ãã€ãµãŒããŒã«è³ããŸã§ã®å¹ åºãæ»æãå®è¡ã§ããŸãã
次ã®ã»ã¯ã·ã§ã³ã§ã¯ãæœåšçãªäŸµå®³ã·ããªãªã«ã€ããŠèª¬æããŸãã å®éã«äœãèµ·ãã£ãã®ããšããåé¡ã¯æªè§£æ±ºã®ãŸãŸã§ãã è¿œå æ å ±ãããã°ãã£ãŒãããã¯ããå¯ããã ããã
3.2ã 劥åã®ä»®èª¬
å³1ã¯ãTurlaãã«ãŠã§ã¢ãããŠã³ããŒãããããã«ãããããHTTPçµç±ã§æ£åœãªAdobe Webãµã€ãã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã匷å¶ããæ¹æ³ã説æã§ãã仮説ã瀺ããŠããŸãã

å³1.被害è ãšãªãå¯èœæ§ã®ãããã·ã³ãšã¢ããã®ãµãŒããŒãšã®éã®çµè·¯äžã§èµ·ããããååãã€ã³ã
IPã¢ãã¬ã¹ã¯AdobeãFlashãé åžããããã«äœ¿çšãããµãŒããŒã«å¯Ÿå¿ããŠãããããäžæ£ãªDNSãµãŒããŒã®ä»®èª¬ããã°ããæé€ããŸããã ã¢ãããšã®è©±ãåããšèª¿æ»ã«åºã¥ããã·ããªãª5ã¯ãæ»æè ãFlash PlayerããŠã³ããŒããµã€ãã䟵害ããªãã£ããããããããã«ãªãããã§ãã ãããã£ãŠã次ã®ãªãã·ã§ã³ãæ®ããŸãã
1ïŒããŒã«ã«ãããã¯ãŒã¯å ã®äŸµå®³ããããã·ã³ã䜿çšãããäžéè ãïŒMitMïŒã«ããæ»æã
2ïŒäŸµå®³ããããããã¯ãŒã¯ã²ãŒããŠã§ã€ãŸãã¯ãããã·çµç¹
3ïŒã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒïŒISPïŒã®ã¬ãã«ã§ã®MitMæ»æã
4ïŒBGPã«ãŒã¿ãŒã«å¯Ÿããæ»æïŒ Border Gateway Protocolãã€ãžã£ã㯠ïŒã«ãããTurlaãå¶åŸ¡ãããµãŒããŒã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ãããŸãã
3.2.1ã MitMããŒã«ã«æ»æ
Turlaã®ãªãã¬ãŒã¿ãŒã¯ã被害ãåããçµç¹ã®ãããã¯ãŒã¯ã§æ¢ã«äŸµå®³ããããã·ã³ã䜿çšããŠãããŒã«ã«ã®MitMæ»æãå®è¡ããå¯èœæ§ããããŸãã ARPã¹ããŒãã£ã³ã°ã䜿çšããŠãã¿ãŒã²ãããã·ã³ãã䟵害ããããã·ã³ã«å³åº§ã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ãã§ããŸãã ãããŠãTurlaã®å µåšåº«ã§ãã®ãããªããŒã«ãå©çšã§ããããšãèªèããŠããŸãããããã®ã°ã«ãŒãã®æè¡çèœåãèãããšãéçºããã®ã¯é£ãããããŸããã
ããããããŸããŸãªçµç¹ã§å€ãã®ç ç²è ãèŠã€ãããŸããã ããã¯ãTurlaããããã®åçµç¹å ã®å°ãªããšã1å°ã®ã³ã³ãã¥ãŒã¿ãŒããŸãã¯åªå ã¿ãŒã²ããã®ãµããããå ã®ã³ã³ãã¥ãŒã¿ãŒã䟵害ããå¿ èŠãããããšãæå³ããŸãã
3.2.2ã 䟵害ãããã²ãŒããŠã§ã€
ãã®æ»æã¯åã®æ»æãšäŒŒãŠããŸãããæ»æè ã«ãšã£ãŠã¯ã¯ããã«èå³æ·±ããã®ã§ã-ã²ãŒããŠã§ã€ãšãããã·ã¯éåžžãã€ã³ãã©ããããšã€ã³ã¿ãŒãããéã®ãã¹ãŠã®çä¿¡ããã³çºä¿¡ãã©ãã£ãã¯ãèŠããããARPã¹ããŒãã£ã³ã°ãªãã§çµç¹å šäœã®ãã©ãã£ãã¯ãååã§ããŸãã Turlaã§åæ§ã®åé¡ã解決ããããŒã«ã®æç¡ã«ã€ããŠã¯ç¥ããŸãããã圌ãã®ã«ãŒããããUroburosã«ã¯ããã±ãŒãžãåæããæ©èœããããŸãã ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããããã·ãšããŠäœ¿çšããŠããããªãã¯IPã¢ãã¬ã¹ãæããªãææãããã·ã³ã«ã¿ã¹ã¯ãåæ£ã§ããŸã ã Turlaã«ã¯ããŠãããã¹ã³ãŒããå€æŽããŠãã©ãã£ãã¯ãå³åº§ã«ååããæªæã®ããã³ã³ããŒãã³ããå°å ¥ããããæå·åãããŠããªãã³ã³ãã³ããå€æŽãããããããã®ååãªå°éç¥èãšãªãœãŒã¹ããããŸãã
3.2.3ã ãããã€ããŒMitMæ»æ
çµç¹ã®å éšãããã¯ãŒã¯ãé¢ããåã«ãã©ãã£ãã¯ãååãããªãã£ãå Žåããã©ãã£ãã¯ã¯åŸã§å€æŽãããAdobeãµãŒããŒã«å°éããŸãã ãã®ã»ã°ã¡ã³ãã®äž»ãªã¢ã¯ã»ã¹ãã€ã³ãã¯ãã€ã³ã¿ãŒããããããã€ããŒã§ãã ESETã¯ä»¥å ãISPã¬ãã«ã§ã®ããã±ãŒãžã®å®è£ ã«ããFinFisherã¹ãã€ãŠã§ã¢ã®é åžãçºè¡šããŸããã
ç§ãã¡ãç¥ã£ãŠãããã¹ãŠã®ç ç²è ã¯æ§ãœé£ã®åœã«ããŸãã å°ãªããšã4ã€ã®ã€ã³ã¿ãŒããããããã€ããŒã®ãµãŒãã¹ã䜿çšããŸãã ãããã£ãŠããã®ã·ããªãªã§ã¯ãTurlaãããŸããŸãªåœãŸãã¯ããŒã¿äŒéãã£ãã«ã®ãã©ãã£ãã¯ãç£èŠããæ©èœãæã£ãŠãããšæ³å®ããŠããŸãã
3.2.4ã BGPã«ãŒã¿ãŒãžã®æ»æ
ãã©ãã£ãã¯ããµãŒãã¹ãããã€ããŒã«ãã£ãŠå€åãããAdobeãµãŒããŒã«å°éããªãå ŽåãTurlaãªãã¬ãŒã¿ãŒã«ãã£ãŠå¶åŸ¡ãããŠããå¥ã®ãµãŒããŒã«ãªãã€ã¬ã¯ããããããšãæå³ããŸãã ããã¯ã次ã®ããããã®æ¹æ³ã䜿çšããŠBGPã«ãŒã¿ãŒãæ»æããããšã§å®è¡ã§ããŸãã
äžæ¹ã§ã¯ãTurlaã®ãªãã¬ãŒã¿ãŒã¯ãèªåŸã·ã¹ãã ïŒASïŒã䜿çšããŠãadobe.comãææãããã¬ãã£ãã¯ã¹ãã¢ããã¿ã€ãºã§ããŸãã ãã®ããã«ããŠãTurla ASã«ãã£ãŠå¶åŸ¡ãããå Žæã«è¿ãå Žæããadobe.comã«éä¿¡ããããã©ãã£ãã¯ã¯ããµãŒããŒã«éä¿¡ãããŸãã ãã®ãããªæªæã®ãã掻åã®äŸã¯ã RIPE ã«ãã£ãŠåæãããŸãã ã ãã ããããã¯ã¢ãããŸãã¯BGPç£èŠãå®è¡ãããµãŒãã¹ã§ããã«èªèãããŸãã ããã«ãRIPEstatã®çµ±èšæ å ±ã確èªããŸãããããã®ãã£ã³ããŒã³ã§äœ¿çšãããAdobe IPã¢ãã¬ã¹ã®çãããã«ãŒãåºåã«æ°ä»ããŸããã§ããã
äžæ¹ãTurlaãªãã¬ãŒã¿ãŒã¯ãASã䜿çšããŠãAdobeãµãŒããŒãžã®ä»ã®ASãããçããã¹ã宣èšã§ããŸãã ãããã£ãŠããã©ãã£ãã¯ãã«ãŒã¿ãŒãééãããªã¢ã«ã¿ã€ã ã§ååããã³å€æŽãããå¯èœæ§ããããŸãã ãã ããã¢ããã®ãµãŒããŒãžã®ãã©ãã£ãã¯ã®ã»ãšãã©ã¯èš±å¯ãããŠããªãã«ãŒã¿ãŒã«ãªãã€ã¬ã¯ããããŸãããã®ãããªæŠè¡ã¯åœè£ ããã®ãé£ããã2016幎8æã®éå§åŸããã«ãã£ã³ããŒã³ãæ€åºãããå¯èœæ§ããããŸãã
3.2.5ã ãŸãšã
å³1ã«ç€ºãããŠãã5ã€ã®ã·ããªãªã®ãã¡ãAdobeã䟵害ãããŠããªããšç¢ºä¿¡ããŠããããã4ã€ã ãã調æ»ããŸããã BGPã«ãŒã¿ãŒãžã®æ»æãšãµãŒãã¹ãããã€ããŒã¬ãã«ã§ã®MitMæ»æã¯ãä»ã®ãã®ãããè€éã§ãã Turlaã°ã«ãŒãã¯ãã¿ãŒã²ããçµç¹ã®ããŒã«ã«ã²ãŒããŠã§ã€ã«ã€ã³ã¹ããŒã«ãããç¹å¥ãªããŒã«ã䜿çšãããšæ³å®ããŠããŸããããã«ããããã©ãã£ãã¯ãã€ã³ãã©ããããé¢ããåã«ååããã³å€æŽã§ããããã«ãªããŸãã
3.3ã get.adobe.com URLããæ å ±ãååŸãã
ãŠãŒã¶ãŒãåœã®ã€ã³ã¹ããŒã©ãŒFlashãããŠã³ããŒãããŠèµ·åãããšã䟵害ã®ããã»ã¹ãå§ãŸããŸãã Turlaããã¯ãã¢ã®å°å ¥ããå§ãŸããŸãã ããã¯ãã»ã¯ã·ã§ã³4ã§èª¬æãã32ãããWindowsçšã®ãã«ãŠã§ã¢Mosquitoã§ããå¯èœæ§ããããŸãã ã»ã¯ã·ã§ã³5ã§èª¬æããGoogle Apps Script Webã¢ããªã±ãŒã·ã§ã³ãšéä¿¡ããæªæã®ããJavaScriptãã¡ã€ã«ã ãŸãã¯ãã¢ããã®åœã®URLããããŠã³ããŒããããäžæãªãã¡ã€ã«ïŒ
http://get.adobe.com/flashplayer/download/update/[x32|x64]
åŸè ã®å Žåããã®ãããªURLã¯AdobeãµãŒããŒäžã«ååšããªããããã³ã³ãã³ããTurlaã°ã«ãŒãã«è»¢éããã«ã¯ã䟵害ããããã·ã³ãšAdobeãµãŒããŒéã®ãã¹ã«MitMãªã©ãå¿ èŠã§ãã
次ã«ãæ°ãã䟵害ããããã·ã³ã«é¢ããæ å ±ã衚瀺ããã¯ãšãªã衚瀺ãããŸãã ããã¯
http://get.adobe.com/stats/AbfFcBebD/q=<base64-encoded data>
GETãªã¯ãšã¹ãã§ãã èšé²ã«ãããšãã¢ããã¯æ£åœãªIPã¢ãã¬ã¹ã䜿çšããŠããŸãããURLãã¿ãŒã³ã¯ã¢ããã䜿çšããŠãããã®ãšé¡äŒŒããŠããªãããããªã¯ãšã¹ãæã«404ãšã©ãŒãçºçããŸãã èŠæ±ã¯HTTPçµç±ã§ãããããã»ã¯ã·ã§ã³3.2ã§åè¿°ããMitMæ»æã¹ã¯ãªããã䜿çšãããå¯èœæ§ãæãé«ããªããŸãã

å³2.åœã®URL get.adobe.comã®ãªã¯ãšã¹ããå®è¡ããã³ãŒã
Base64ã§æå·åãããããŒã¿ã«ã¯ã被害è ã®ãã·ã³ã«é¢ããæ©å¯æ å ±ãå«ãŸããŠããŸãã 圌女ãå®éã«ã¢ããã®ãµãŒããŒã«è¡ã£ãã®ã¯å¥åŠã ããã å³3ã¯ã埩å·åãããã¬ããŒãã®äŸã瀺ããŠããŸãã ããŒã¿ã«ã¯ãäžæã®IDïŒå³4ã«ç€ºãããã«ãFlashã€ã³ã¹ããŒã©ãŒã®åœã®ã€ã³ã¹ããŒã©ãŒã®æåŸã®8ãã€ãïŒããŠãŒã¶ãŒåãã€ã³ã¹ããŒã«ãããŠããã»ãã¥ãªãã£è£œåã®ãªã¹ããããã³ARPããŒãã«ãå«ãŸããŸãã

å³3.åœã®URL URL get.adobe.comã«éä¿¡ãããã€ã³ã¹ããŒã«ã¬ããŒã

å³4.ã€ã³ã¹ããŒã©ãŒã®æåŸã«ããäžæã®ID
èå³æ·±ãããšã«ã macOSçšã®Snakeã€ã³ã¹ããŒã©ãŒ ïŒTurlaé¢é£ã®ããã¯ãã¢ïŒã¯ãå³5ãšåãURLã䜿çšããŸããéä¿¡ãããæ å ±ã¯ããŠãŒã¶ãŒåãšããã€ã¹åã®ã¿ãå«ããããbase64ã§ãšã³ã³ãŒããããŸããããããã«ç°ãªããŸãã ãã ãããã®åäœã¯ãåæã®å ¬éæã«Fox-ITã«ãã£ãŠææžåãããŠããŸããã§ããã

å³5. macOSã®Snakeã€ã³ã¹ããŒã©ãŒã®ä»£æ¿URL get.adobe.comã§ãªã¯ãšã¹ããå®è¡ããã³ãŒã
æåŸã«ãåœã®ã€ã³ã¹ããŒã©ãŒãæ£åœãªFlash Playerã¢ããªã±ãŒã·ã§ã³ãæ¿å ¥ãŸãã¯ããŠã³ããŒãããŠèµ·åããŸãã æ£èŠã®ã€ã³ã¹ããŒã©ãŒã¯ãåœã®ã€ã³ã¹ããŒã©ãŒã«çµã¿èŸŒãŸããããGoogleãã©ã€ãURLãžã®æ¬¡ã®ãã¹ã䜿çšããŠããŠã³ããŒããããŸãïŒ
https://drive.google[.]com/uc?authuser=0&id=0B_LlMiKUOIstM0RRekVEbnFfaXc&export=download
:
https://drive.google[.]com/uc?authuser=0&id=0B_LlMiKUOIstM0RRekVEbnFfaXc&export=download
4. Win32ããã¯ãã¢åæ
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãäž»ã«2017幎ã«ã€ã³ã¶ã¯ã€ã«ãã§çºèŠããããµã³ãã«ã«ã€ããŠèª¬æããŸãã ãã£ã³ããŒã³ãæ°å¹Žéç¶ããŠãããšãã蚌æ ãèŠã€ãããŸããã2017幎ã®ãµã³ãã«ã¯ã
InstructionerDLL.dll
ãã¡ã€ã«ãžã®ããã¯ãã¢ã®é²åã®çµæã§ãã 以åã®ãµã³ãã«ã¯é£èªåãããŠããŸããã§ãã;ããŒããŒãªãã®ããã¯ãã¢DLLã®ã¿ãå«ãŸããŠããŸããã å€ããµã³ãã«ã®äžéšã«ã¯ã2009幎ã®ã³ã³ãã€ã«ã¿ã€ã ã¹ã¿ã³ãããããŸãããã»ãšãã©ã®å Žå調æŽãããŠããŸãã
4.1ã ã€ã³ã¹ããŒã©ãŒ
åœã®Flashã€ã³ã¹ããŒã©ãŒãšããŠæäŸãããããã«ãã£ã¹ã¯ã«ãã©ãã·ã¥ããã2ã€ã®è¿œå ã³ã³ããŒãã³ããä»å±ããŠããŸãã äžèšã§èª¬æããããã«ãã¢ãããæ£èŠã®ã€ã³ã¹ããŒã©ãŒãé åžããããã«äœ¿çšããURLããã³IPããåœã®Flashã€ã³ã¹ããŒã©ãŒãããŠã³ããŒããããŠãŒã¶ãŒãããã€ãèŠã€ãããŸããã
4.1.1ã æå·å
æ°ããããŒãžã§ã³ã§ã¯ãæå·åã䜿çšããŠãã€ã³ã¹ããŒã©ãŒã¯åžžã«é£èªåãããŠããŸãã å³6ã¯ããã®ããŒã«ã§é£èªåãããé¢æ°ã®äŸã瀺ããŠããŸãã

å³6.é£èªåãããé¢æ°
ãŸãããã®æå·åããã°ã©ã ã¯ãç®è¡æŒç®ãšãšãã«ãã¡ãžãŒè¿°èªãåºã䜿çšããŸãã ããšãã°ãé£èªåãããé¢æ°ã¯ãããŒãã³ãŒãã£ã³ã°ãããå€ããæ°å€ãèšç®ããå¥ã®ããŒãã³ãŒãã£ã³ã°ãããå€ãšå€§ãããæ¯èŒããŸãã ãããã£ãŠãåå®è¡äžãããã»ã¹ã®ãããŒã¯åãã«ãªããŸãããæ£ãããã¹ã決å®ããã«ã¯ãšãã¥ã¬ãŒã·ã§ã³ãå¿ èŠã§ãã ãã®ãããã¢ããªã¹ããšèªåã»ãã¥ãªãã£ãœãããŠã§ã¢ã¢ã«ãŽãªãºã ã®äž¡æ¹ãåæããã«ã¯ãã³ãŒããè€éãããŸãã ããã«ãããæéå¶éã®ããã«ãªããžã§ã¯ããã¹ãã£ã³ãããªãçšåºŠã«ãšãã¥ã¬ãŒã·ã§ã³ãé ããªãããã®çµæã瀺ãããïŒé£èªåãããŠããªãå ŽåïŒãã«ãŠã§ã¢ãæ€åºãããªããªããŸãã
次ã«ãé£èªå解é€ã®æåã®æ®µéã®åŸãWin32 API
SetupDiGetClassDevs(0,0,0,0xFFFFFFFF)
åŒã³åºããè¡ãããæå·åããã°ã©ã ã¯åä¿¡ããå€ã0xE000021AãšäžèŽãããã©ããã確èªããŸãã ãã®é¢æ°ã¯éåžžãã·ã¹ãã å ã®ããã€ã¹ã«é¢ããæ å ±ãååŸããããã«äœ¿çšãããŸãã ãã¹ãã«ãããšã
Flags (0xFFFFFFFF)
ã®ç¹å®ã®å€ã¯ææžåãããŠããŸããããWindows 7ããã³Windows 10ã®ãã·ã³ã§ã¯ãçµæã®å€ã¯åžžã«
0xE000021A
ã«å¯Ÿå¿ããŸããæ¹æ³ã
第äžã«ããã®ã³ãŒãã¯ããã€ãã®ãã©ã°ã¡ã³ãã«åå²ãããç¹å¥ãªé¢æ°ã䜿çšããŠè§£èªãããå®è¡æã«ã¡ã¢ãªå ã«PEãäœæããããã«é åºä»ããããŸãã 次ã«ãPEãšã³ã³ãŒããŒã®ããŒãããŒããŒæ©èœã䜿çšããŠå®è¡ãããŸãã ãã®PEããŒããŒã«ã¯ãå³7ã«ç€ºãããã«ãããã€ãã®ãããã°è¡ãå«ãŸããŠããŸãã

å³7. PEããŒããŒæ©èœã®ãããã°è¡
4.1.2ã èšçœ®
埩å·ååŸãã€ã³ã¹ããŒã©ãŒã¯
%APPDATA%
ãµããã©ã«ããŒãæ€çŽ¢ãã2ã€ã®ãã¡ã€ã«ãæé·ãã¹ã®ãã©ã«ããŒã«ããããããŸãã ãã®ãããªãã©ã«ããŒãæ€çŽ¢ããå Žåãååã«
AVAST
ãšããåèªãå«ãŸãããã©ã«ããŒã¯ãã¹ãŠãã€ãã¹ãããŸãã 次ã«ããã®ãã©ã«ããŒå ã®é ãããŠããªããã¡ã€ã«ã®1ã€ã®ååããæ¡åŒµåãåãåããããã®ããã³ããã¡ã€ã«ã®ããŒã¹åãšããŠäœ¿çšããŸãã ãã£ã¬ã¯ããªå ã®ãã¹ãŠã®ãã¡ã€ã«ãé衚瀺ã®å ŽåããŸãã¯ãã£ã¬ã¯ããªã空ã®å Žåã
%WINDIR%\System32
DLLåã䜿çšãããŸãã ãªã»ããããŒãããŒããŒã®æ¡åŒµåã¯
.tlb
ã§ãã¡ã€ã³ã®ããã¯ãã¢ã¯
.pdb
ã§ãã èå³æ·±ãããšã«ã2ã€ã®DLLããã©ãã·ã¥ããããã«
WriteFile
ã䜿çšããŸããã 代ããã«ããã¡ã€ã«ãäœæããŠã¡ã¢ãªå ã«ããŒã¯ãã
memmove
ãåŒã³åºããŠããŒã¿ãã³ããŒããŸãã ããããããã¯ã
WriteFile
ã»ãã¥ãªãã£è£œåãšãµã³ãããã¯ã¹ãžã®ããã¯ããã€ãã¹ããããã«è¡ãããŸãã
ãŸãã
.tlb
æ¡åŒµåãæã€ãã¡ã€ã«ã1ã€ã ãããŠã³ããŒããã以åã®ã€ã³ã¹ããŒã©ãŒãªãã·ã§ã³ã確èªããŸããã ãã®å Žåãåããã¡ã€ã«ã«ããŒãããŒããŒæ©èœãšããã¯ãã¢æ©èœãå«ãŸããŠããŸãã
DllMain
ã¯ãå®è¡ããã³ãŒããéžæããŸãã
圌ã¯ãåçŽãªæå·åãããŠããªããã°ãã¡ã€ã«ã
%APPDATA%\kb6867.bin
ãŸãã å®å šãªãã¡ã€ã«ã¯ãããã2ã€ã®DLLãšåããã£ã¬ã¯ããªã«äœæãããæ¡åŒµåã¯
.tnl
ã§ãã

å³8.ã©ã³ãã ãªåãã£ã¬ã¯ããªã«äœæããããã¡ã€ã«ïŒ APPDATAïŒ
次ã«ãRunã¬ãžã¹ããªããŒã䜿çšãããã COMãã€ã³ã¿ãŒã»ããããŠæ°žç¶æ§ãæäŸããŸãã Windows Management InstrumentationïŒWMIïŒã«ãã£ãŠååŸããããŠã€ã«ã¹å¯Ÿç衚瀺åãTotal SecurityãšäžèŽããå Žåã
rundll32.exe
[ããã¯ãã¢ãžã®ãã¹]ãšã³ããª
StartRoutine
ã
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\auto_update
ãŸãã
ãã以å€ã®å Žåã
HKCR\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32
ãŸãã¯
HKCR\CLSID\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\InprocServer32
ã®ã¬ãžã¹ããªãšã³ããªã眮ãæããŸãã ãããã®CLSIDã¯ããããã
EhStorShell.dll
ãš
ntshrui.dll
ã§ãã ãããã®DLLã¯ã
explorer.exe
ïŒWindows GUIïŒãå«ãå€ãã®ããã»ã¹ã«ãã£ãŠæ£åœã«èµ·åãããŸãã ãããã£ãŠãããŒãããŒããŒã¯
explorer.exe
èµ·åããããã³ã«åŒã³åºãããŸãã æåŸã«ãå³9ã«ç€ºãããã«ãå ã®ã€ã³ã¿ãŒã»ãããããDLLãšã¡ã€ã³ããã¯ãã¢ãžã®ãã¹ãæ ŒçŽããã¬ãžã¹ããªãšã³ããªãè¿œå ããŸãã

å³9.æç¶å¯èœæ§ã®ããã®ã¬ãžã¹ããªã®å€æŽ
æ®ãã®CLSIDã¯ãã€ããªã«ããŒãã³ãŒãã£ã³ã°ãããŠããŸããã䜿çšãããããšã¯ç¢ºèªããŠããŸããã å®å šãªãªã¹ãã¯ã䟵害ã®å åã瀺ãã»ã¯ã·ã§ã³ã§å ¥æã§ããŸãã
åã®ã»ã¯ã·ã§ã³ã§èª¬æããããã«ãã€ã³ã¹ããŒã©ãŒã¯äžæã®ãµã³ãã«IDããŠãŒã¶ãŒåãARPããŒãã«ãªã©ã®æ å ±ãAdobeãã¡ã€ã³URL
get.adobe.com
éä¿¡ããŸãã ãŸããå®éã®Adobe Flashã€ã³ã¹ããŒã©ãŒãèµ·åããŸããããã¯ãGoogleãã©ã€ãããããŠã³ããŒãããããåœã®ã€ã³ã¹ããŒã©ãŒã«çµã¿èŸŒãããšãã§ããŸãã
ã¡ã€ã³ããã¯ãã¢ãéå§ããåã«ãã€ã³ã¹ããŒã©ãŒã¯
sysQ!123
ãã¹ã¯ãŒãã§
HelpAssistant
管çè
HelpAssistant
ïŒãŸãã¯äžéšã®ãµã³ãã«ã§ã¯
sysQ!123
ïŒã
sysQ!123
ãŸãã
LocalAccountTokenFilterPolicy
ã
1
ã«å€æŽããããªã¢ãŒã管çã¢ã¯ã·ã§ã³ãèš±å¯ãããŸãã ãã®ã¢ã«ãŠã³ãåã¯æ£åœãªãªã¢ãŒãã¢ã·ã¹ã¿ã³ã¹ã»ãã·ã§ã³äžã«äœ¿çšãããããããã®ã¢ã«ãŠã³ãåã¯æ°ä»ããªãããã«å¿ èŠã§ãããšèããŠããŸãã
4.2ã DebugParserïŒã©ã³ãã£ãŒïŒ
DebugParser.dll
ãšåŒã°ããã©ã³ãã£ãŒã¯ãã€ã³ã¿ãŒã»ãããããCOMãªããžã§ã¯ãã®èªã¿èŸŒã¿äžã«åŒã³åºãããŸãã 圌ã¯ãã¡ã€ã³ã®ããã¯ãã¢ãèµ·åããã€ã³ã¿ãŒã»ãããããCOMãªããžã§ã¯ããããŒããã責任ããããŸãã ã³ã³ããŒãã³ãã®ç°¡ç¥åãããæ¬äŒŒã³ãŒããå³10ã«ç€ºããŸãã

å³10.æ¬äŒŒã³ãŒãã®èµ·å
ãã ããã€ã³ã¿ãŒã»ãããããã©ã€ãã©ãªãããŒãããŠæ£ããã¢ãã¬ã¹ã«æ»ãããã«ããã€ãã®ããªãã¯ã䜿çšããŸãã ããã»ã¹ã¯ä»¥äžã®ãšããã§ãã
1.
LoadLibrary
æ£åœãªåŒã³åºãã®åŸãå ã®è¿ä¿¡å ã¢ãã¬ã¹ãååŸããŸãã
DllMain
ã®éå§æ
DllMain
ESPã¬ãžã¹ããªå€ãä¿åãããŸãã 次ã«ã圌ã¯ESP-6ã§
FF 15
ïŒãªãã¬ãŒã·ã§ã³ã³ãŒãCALLã®åŒã³åºãïŒããã§ãã¯ããŸããååšããå Žåãã¬ãžã¹ããªã¯å ã®è¿ä¿¡å ã¢ãã¬ã¹ãæ®ããŸãã

å³11. LoadLibraryãåŒã³åºããåŸã®ã¢ãã¬ã¹ã®æ€çŽ¢
2.次ã®å€ãå«ãRWXã¡ã¢ãªãå²ãåœãŠãŸãã

å³12.ã¡ã¢ãªå²ãåœãŠ
3.
DllMain
å¿ç
DllMain
å€æŽããŠã代è¡åä¿¡æ©èœã«ç§»åã
DllMain
ã
4.ã€ã³ã¿ãŒã»ããæ©èœã§ïŒ
aã
ntshrui.dll
ïŒãŸãã¯ä»ã®ã€ã³ã¿ãŒã»ãããããã©ã€ãã©ãªïŒã®èªã¿èŸŒã¿ãæ åœããé¢æ°ã®åŒã³åºã
bã
DebugParser.dll
ïŒããã¯ãã¢ããŒããŒïŒãžã®
FreeLibrary
åŒã³åºã
cã 代è¡åä¿¡åã®å ã®å¿çã¢ãã¬ã¹ãžã®ããã²ãŒã·ã§ã³ã
å ã®DLLãããŒããããŠããããããŠãŒã¶ãŒã¯ããã¯ãã¢ãå®è¡ãããŠããããšã«æ°ä»ããªãã§ãããã
ããŒãããŒããŒãšããã¯ãã¢ã®æ©èœã1ã€ã®ãã¡ã€ã«ã«ãŸãšããããŠããåæã®ããŒãžã§ã³ã§ã¯ã
DllMain
ã¯å®è¡ããã³ãŒããéžæããŸãïŒå³13ãåç §ïŒã

å³13. 1ã€ã®ã©ã€ãã©ãªã®ããŒããŒãšããã¯ãã¢
4.3ã ã¡ã€ã³ããã¯ãã¢
ãã®ãã£ã³ããŒã³ã®ã¡ã€ã³ã®ããã¯ãã¢ã§ãã
CommanderDLL.dll
ã¯ãäœæè ã«ãã£ãŠåœåããããã®ã§ãããéžæãããæ°žç¶åã¡ã«ããºã ãã¬ãžã¹ããªã®RunããŒã§ããå Žåãäžèšã®ããŒãããŒããŒã«ãã£ãŠèµ·åãããããèµ·åæã«çŽæ¥èµ·åãããŸãã ã©ã¡ãã®å Žåããå³14ã«ç€ºãããã«ã
StartRoutine
ã©ã€ãã©ãªã®ãšã¯ã¹ããŒãã
StartRoutine
ããŸããããã®ãšã¯ã¹ããŒãã¯DLLãšã¯ã¹ããŒãããŒãã«ã«ã¯ãããŸããã

å³14. DLLã®.relocã»ã¯ã·ã§ã³ã«EXPORTã¢ãã¬ã¹ããŒãã«ããããŸãã
DllMain
é¢æ°ã§ãåºåçšã®ãšã¯ã¹ããŒãããŒãã«ãäœæãããŸãã
1.åäžã®ãšã¯ã¹ããŒãã®ååãšããŠ
IMAGE_EXPORT_DIRECTORY
ã䜿çšããŠ
IMAGE_EXPORT_DIRECTORY
æ§é ãäœæããŸã
2.ã¡ã¢ãªå ã®PEã€ã¡ãŒãžã®æåŸã«ããããŒãã£ã·ã§ã³ã移åããåŸããã®æ§é ãã³ããŒããŸã
3.ãšã¯ã¹ããŒãããŒãã«ã®çžå¯Ÿä»®æ³ã¢ãã¬ã¹ïŒRVAïŒãå«ãPEã®ããããŒãã£ãŒã«ãããæ°ããäœæããããšã¯ã¹ããŒãããŒãã«ã®ã¢ãã¬ã¹ã«å€æŽããŸãã
ãããã®å€æŽã«ãããå³15ããã³16ã«ç€ºãããã«ãã€ã³ã¡ã¢ãªã©ã€ãã©ãªã«ã¯
StartRoutine
ãšãããšã¯ã¹ããŒãããããŸããå³17ã¯ããã®ãšã¯ã¹ããŒããè¿œå ããããã»ã¹å šäœã®ã³ãŒãã瀺ãHex-Raysã
StartRoutine
ã®ã¹ã¯ãªãŒã³ã·ã§ããã§ãã

å³15.æ°ããäœæããããšã¯ã¹ããŒãããŒãã«

å³16.æ°ãããšã¯ã¹ããŒãã®åå

å³17.ãšã¯ã¹ããŒãããŒãã«ã®ãããé©çšããã»ã¹
4.3.1ã ã«ã¹ã¿ãã€ãº
ãŸãã
CommanderDLL
ã¢ãžã¥ãŒã«ã¯ãããããŒãã¡ã€ã«ïŒåœã®Flashã€ã³ã¹ããŒã©ãŒïŒãåé€ããŸãã ãã¹ã¯ã
\\.\pipe\namedpipe
ãšããååã®ãã€ããä»ããŠãããããŒããæž¡ãããŸãã 次ã«ãæ°ããããã»ã¹ã§ã2çªç®ã®ååä»ããã€ã
\\.\pipe\ms32loc
ãäœæããå¥ã®ããã»ã¹ããã®ãã£ãã«ã«æ¥ç¶ãããŸã§åŸ æ©ããŸãããã®åŸãããã°ã©ã ã¯çµäºããŸãã
次ã«ãCommanderDLLã¯ããã€ãã®å éšæ§é ãæ§æããæ§æå€ãã¬ãžã¹ããªã«ä¿åããŸãã è¡š1ã§ã¯ã
HKCU\Software\Microsoft\[dllname]
æ ŒçŽãããŠããããŸããŸãªã¬ãžã¹ããªå€ã«ã€ããŠèª¬æããŠããŸãã
è¡š1.ã¬ãžã¹ããªã®ããã¯ãã¢å€

ã¬ã€ã¢ãŠããšã³ããªãé€ããã¹ãŠã®ã¬ãžã¹ããªå€ã¯ãã»ã¯ã·ã§ã³4.3.2ã§èª¬æãããŠããç¹å¥ãªã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸãã
3 çªç®ã«ãCïŒCãµãŒããŒã®è¿œå ã¢ãã¬ã¹ã¯ãGoogle Docs ïŒhttps://docs.google [ã] Com / ucïŒAuthuser = 0ïŒid = 0B_wY-Tu90pbjTDllRENWNkNma0kïŒexport = downloadïŒã«ä¿åãããŠããããã¥ã¡ã³ãããããŠã³ããŒããããŸãã 4.3.2ã§èª¬æãããŠããã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸãã
4.3.1ã æå·å
ããã¯ãã¢ã¯ç¹å¥ãªæå·åã¢ã«ãŽãªãºã ã䜿çšããŸãããã¬ãŒã³ããã¹ãã®åãã€ãã¯ãBlum Blum Shubã¢ã«ãŽãªãºã ã«é¡äŒŒããé¢æ°ã«ãã£ãŠçæãããã¹ããªãŒã ã«ã¢ãžã¥ã2ã§è¿œå ãããŸããæå·åãŸãã¯åŸ©å·åã®å ŽåãããŒãšã¢ãžã¥ãŒã«ã¯æå·åæ©èœã«è»¢éãããŸãã
ç°ãªããµã³ãã«ã¯ç°ãªãããŒãšã¢ãžã¥ãŒã«ã䜿çšããŸããäžéšã¯ããŒãã³ãŒãã£ã³ã°ãããŠãããäžéšã¯å®è¡äžã«çæãããŸããè¡š2ã«ããã«ãŠã§ã¢ã䜿çšããããŸããŸãªããŒãšã¢ãžã¥ãŒã«ã瀺ããŸãã
è¡š2.æå·åããŒãšã¢ãžã¥ãŒã«

4.3.3ããã°
ããã°ã©ã ã¯ãšåŒã°ãããã°ãã¡ã€ã«ãä¿æããŸã
[dllname].tnl
ãèå³æ·±ãããšã«ãåã¬ã³ãŒãã®ã¿ã€ã ã¹ã¿ã³ããå«ãŸããŠããããã䟵害ããããã·ã³ã§çºçããäžé£ã®ã€ãã³ãã远跡ã§ããŸããããã¯ããµã€ããŒç¯çœªè ã«ãšã£ãŠæçšã§ããäžèšã®ã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸããããŒã¯ããã°ãã¡ã€ã«ã®ããããŒã®0x20ã®ã€ã³ãã³ãã®åŸã«ãããã¢ãžã¥ãŒã«ã¯åžžã«0x5DEE0B89ã§ããå³18ã«ããã®ãã¡ã€ã«ã®æ§é ã瀺ããŸãã

å³18.ãã°ãã¡ã€ã«ã®æ§é

å³19.ãã°ãã¡ã€ã«ã®éå§
4.3.4ãCïŒCãµãŒããŒã®ããŒã¿äº€æãšããã¯ãã¢ã³ãã³ã
ã¡ã€ã³ã®ããã¯ãã¢ã«ãŒãã¯ãCïŒCãµãŒããŒãšã®ããŒã¿äº€æã管çããéä¿¡ãããã³ãã³ããå®è¡ããŸãããããã®ããããã®éå§æã«ã圌ã¯ã©ã³ãã ãªæééã¢ã¯ãã£ãã§ãããéåžžã¯çŽ12åã§ãã
ãµãŒããŒãžã®èŠæ±ã¯åžžã«åãã¹ããŒã ã«URLã䜿çšããŠããŸã
https://[C&C server domain]/scripts/m/query.php?id=[base64(encrypted data)]
ããŠãŒã¶ãšãŒãžã§ã³ãã¯ãããŒãã³ãŒããããè©Šæã§ãããå€æŽããããšã¯ã§ããŸããã
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
ãã®ããã©ã«ãå€ã¯ãGoogle Chromeã®41ã®ãã©ã¡ãŒã¿ã®æ§æã«äœ¿çšããã
id
å³20ã«èšèŒãããŠãã

å³20ã®CïŒCãžã®ã¯ãšãªã®æ§é -ãã©ã¡ãŒã¿IDã®ããŒã¿ãšGETãµãŒãèŠæ±
åã®ãã¿ãŒã³-
id
GETèŠæ±ãã©ã¡ãŒã¿ãŒã«æ§é ãå«ãŸããå Žå
Data
ããã ããããŒã¿ã¯CookieïŒãã«ããŒã ïŒãŸãã¯POSTãªã¯ãšã¹ãã«å«ãŸããŠããå ŽåããããŸããå³21ã¯ãããŸããŸãªå¯èœæ§ã説æããŠããŸãã
ããããã¹ãŠã®å Žåã«ãããŠãæå·åããŒã¯
id
URL æ§é ã®æåã®DWORDã§ãã 0x7DFDC101ã¢ãžã¥ãŒã«ãšçµã¿åãããããŒã¯ãæ§é
id
ãPOSTããŒã¿ãããã³Cookieå€ã解èªã§ããŸãã次ã«ãããŒã¿æ§é ããã®ãã€ããŒãã埩å·åãããŸãã

å³21ã¯ãèŠæ±ãéžæãã
å ã®èŠæ±ã¯ãã³ãã³ãã®çµæãšããŠäŸµå ¥ãããã·ã³ã®äžè¬çãªæ å ±ãå«ãŸã
ipconfig
ã
set
ã
whoami
ããã³
tasklist
ã
ãã®åŸãCïŒCãµãŒããŒã¯äžé£ã®æ瀺ã®1ã€ãå¿çãšããŠçºè¡ããŸãããã®çãã®æ§é ãå³21ã«ç€ºããŸãããã±ããã¯ãã»ã¯ã·ã§ã³4.3.2ã§èª¬æããBlum Blum Shubããåçšããåãã¢ã«ãŽãªãºã ã§å®å šã«æå·åãããŸãïŒæåã®4ãã€ããé€ãïŒãååœä»€ã»ããã¯ãããŒã0x3EB13ãã¢ãžã¥ãŒã«ã0x7DFDC101ã§åå¥ã«æå·åãããŸãã

å³22. CïŒCå¿çãã±ããã®æ§é
ããã¯ãã¢ã¯ããã€ããªãã¡ã€ã«ã«ããŒãã³ãŒããããäºåå®çŸ©æžã¿ã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸããè¡š3ã«ã䜿çšå¯èœãªã³ãã³ãã®ç°¡åãªèª¬æã瀺ããŸãã
è¡š3.䜿çšå¯èœãªããã¯ãã¢ã³ãã³ãã®èª¬æ

äžéšã®åæãµã³ãã«ã§ã¯ãââããã¯ãã¢ã¯PowerShellã¹ã¯ãªãããå®è¡ã§ããŸãã
5. JavaScriptããã¯ãã¢åæ
äžéšã®åœã®Flashã€ã³ã¹ããŒã©ãŒã¯ãMosquitoã®ä»£ããã«2ã€ã®JavaScriptããã¯ãã¢ãæäŸããŸãããããã®ãã¡ã€ã«ã¯ããã©ã«ããŒå ã®ãã£ã¹ã¯ã«ãã©ãã·ã¥ãããŸã
%APPDATA%\Microsoft\
ã圌ãã¯åŒã°ã
google_update_checker.js local_update_checker.js
ãŸãã
æåã¯ãGoogle Apps ScriptãµãŒãã¹ã§ãã¹ããããŠããWebã¢ããªã±ãŒã·ã§ã³ãšããåãã
(https://script.google[.]com/macros/s/AKfycbwF_VS5wHqlHmi4EQoljEtIsjmglLBO69n_2n_k2KtBqWXLk3w/exec)
ãŸããbase64ã§ãšã³ã³ãŒããããå¿çãæåŸ ããŠããŸãã次ã«ãevalã䜿çšããŠãã³ãŒããããã³ã³ãã³ããå®è¡ããŸããè¿œå ã®ããã¯ãã¢ã®æ£ç¢ºãªç®çã¯ããããŸããããè¿œå ã®ããªããªãããŠã³ããŒãããããæªæã®ããJavaScriptã³ãŒããçŽæ¥å®è¡ãããããããã«äœ¿çšã§ããŸããæ°žç¶æ§ã確ä¿ããããã«ãå€
Shell
ãã«è¿œå ããŸã
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ã
2çªç®ã®JavaScriptãã¡ã€ã«ã¯
%ProgramData%\1.txt
ãé¢æ°ã䜿çšããŠã³ã³ãã³ããèªã¿åããå®è¡ããŸã
eval
ãæ°žç¶æ§ã確ä¿ããããã«ã䟡å€ãè¿œå ããŸã
local_update_check
c
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ã
6.çµè«
ãã®ãã£ã³ããŒã³ã¯ãTurlaãµã€ããŒã°ã«ãŒããæªæã®ãããã©ãã£ãã¯ãæ£åœãªãã®ãšããŠãã¹ã¯ããå€ãã®ããŒã«ãæã£ãŠããããšã瀺ããŠããŸãã䜿çšããæ¹æ³ã¯ãçµéšè±å¯ãªãŠãŒã¶ãŒã«ãšã£ãŠãæ··ä¹±ãæãå¯èœæ§ããããŸãã HTTPã䜿çšãããšããã®ãããªæ»æã®æå¹æ§ãäœäžããå¯èœæ§ããããŸãããã®ãããã³ã«ã§ã¯ããã·ã³ãããªã¢ãŒããµãŒããŒãžã®éäžã§æå·åããããã©ãã£ãã¯ãååããŠçœ®ãæããããšã¯ããå°é£ã§ãã Adobeã€ã³ã¹ããŒã©ãŒãšã¯ç°ãªããTurlaã䜿çšãããã¡ã€ã«ã¯çœ²åãããŠããªãããããã¡ã€ã«çœ²åã®æ€èšŒã¯çãããã¯ãã§ãã
ããã«ããã®æ°ãããã£ã³ããŒã³ã¯ãæ±ãšãŒãããã«ããé äºé€šãšå€§äœ¿é€šã«å¯Ÿãããã¥ã«ã©ã®é¢å¿ã瀺ããŠããŸããã°ã«ãŒãã¯ããããã®æ å ±æºãžã®ã¢ã¯ã»ã¹ãæäŸããããã«å€ãã®åªåãããŠããŸãã
ãã£ã³ããŒã³é¢é£ã®è³ªåã«ã€ããŠã¯ãthreatintel @ eset.comã«ãåãåãããã ããã
7.䟵害ã®ææš
7.1ã ã³ãã³ããµãŒããŒã¢ãã¬ã¹ïŒå¹ŽåäœïŒ
2017: smallcloud.ga
2017: fleetwood.tk
2017: docs.google.com/uc?authuser=0&id=0B_wY-Tu90pbjTDllRENW
NkNma0k&export=download (adstore.twilightparadox.com)
2017: bigpen.ga
2017: https://script.google.com/macros/s/AKfycbxxPPyGP3Z5wgwbs
mXDgaNcQ6DCDf63vih-Te_jKf9SMj8TkTie/exec
2017: https://script.google.com/macros/s/AKfycbwF_VS5wHqlH
mi4EQoljEtIsjmglLBO69n_2n_k2KtBqWXLk3w/exec
2017-2015: ebay-global.publicvm.com
2017-2014: psychology-blog.ezua.com
2016: agony.compress.to
2016: gallop.mefound.com
2016: auberdine.etowns.net
2016: skyrim.3d-game.com
2016: officebuild.4irc.com
2016: sendmessage.mooo.com
2016, 2014: robot.wikaba.com
2015: tellmemore.4irc.com
7.2ã ã¢ããã®åœã¢ãã¬ã¹
http://get.adobe[.]com/stats/AbfFcBebD/?q=<base64-encoded data>
http://get.adobe[.]com/flashplayer/download/update/x32
http://get.adobe[.]com/flashplayer/download/update/x64
7.3ã æ£åœãªFlashã€ã³ã¹ããŒã©ãŒã®éå ¬åŒã¢ãã¬ã¹
https://drive.google[.]com/uc?authuser=0&id=0B_LlMiKUOIsteEtraEJYM0QxQVE&export=download
https://drive.google[.]com/uc?authuser=0&id=0B_LlMiKUOIstM0RRekVEbnFfaXc&export=download
7.4ã ããã·ã¥


7.5ã Windowsã¢ãŒãã£ãã¡ã¯ã
7.5.1ãã€ã³ã¿ãŒã»ãããããCLSID
{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
{08244EE6-92F0-47F2-9FC9-929BAA2E7235}
{4E14FBA2-2E22-11D1-9964-00C04FBBB345}
{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}
{603D3801-BD81-11D0-A3A5-00C04FD706EC}
{F82B4EF1-93A9-4DDE-8015-F7950A1A6E31}
{9207D8C7-E7C8-412E-87F8-2E61171BD291}
{A3B3C46C-05D8-429B-BF66-87068B4CE563}
{0997898B-0713-11D2-A4AA-00C04F8EEB3E}
{603D3801-BD81-11D0-A3A5-00C04FD706EC}
{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}
7.5.2ã ãã¡ã€ã«
ãã©ã«ããŒå ã®åãååã§ç°ãªãæ¡åŒµåïŒ.tlbã.pdbãããã³.tnlïŒãæã€3ã€ã®ãã¡ã€ã«
%APPDATA%
%APPDATA%\kb6867.bin
ïŒç°¡ç¥åããããã°ãã¡ã€ã«ïŒ
7.6ãESETæ€åº
7.6.1ãæè¿ã®ãµã³ãã«
Win32/Turla.CQ
Win32/Turla.CP
Win32/Turla.CR
Win32/Turla.CS
Win32/Turla.CT
Win32/Turla.CU
Win32/Turla.CV
Win32/Turla.CW
Win32/Turla.CX
7.6.2ãå€ããªãã·ã§ã³
Win32/TrojanDownloader.CAM
Win32/TrojanDownloader.DMU
7.6.3ãJavaScriptããã¯ãã¢
JS/Agent.NWB
JS/TrojanDownloader.Agent.REG