ç§ãã¡ã®èª¿æ»ã§ã¯ãLazarusã2017幎æ«ã«äžå€®ã¢ã¡ãªã«ã®ãªã³ã©ã€ã³ã«ãžãããã®ä»ã®ã¿ãŒã²ããã«å¯Ÿããæ»æã®èåŸã«ããå¯èœæ§ãéåžžã«é«ãããšãããããŸããã ãããã®äºä»¶ã§ã¯ãæ»æè ã¯äŸµå®³ãããããã€ã¹äžã§å®è¡ãããKillDiskãå«ãåãããŒã«ã䜿çšããŸããã
ã©ã¶ãã®ããŒã«
Lazarusããã«ãŒã¯ã2016幎2æã®Novetta Operation Blockbusterã¬ããŒãã§æåã«ç¹å®ãããŸããã US CERTãšFBIã¯ããã®ãµã€ããŒã°ã«ãŒããHidden CobraãšåŒã³ãŸããã ãã®ã°ã«ãŒãã¯ãSony Pictures Entertainmentãžã®æ»æã®åŸãåºãç¥ãããããã«ãªããŸãã ã
ã©ã¶ãã«é¢é£ãããã®åŸã®æ»æã¯ã ãããã¿ã®è³æããã®ä»ã®ç 究ã«äŸåããæ å ±ã»ãã¥ãªãã£ã®å°é家ã®æ³šç®ãéããŸãã-æ»æããŒã«ã®èª¬æã®æ°çŸããŒãžïŒ ããŒã©ã³ããšã¡ãã·ã³ã®éè¡ ãžã®æ»æ ãWannaCryã®æµè¡ ã ç±³åœåœé²ç·çã®è«è² æ¥è ãžã®ãã£ãã·ã³ã°æ»æãªã©ãããã®ç 究ã¯ãã¹ãŠãã©ã¶ããæ»æã®ãœãŒã¹ã§ããããšã瀺ããŠããŸãã
LazarusããŒã«ïŒæ å ±ã»ãã¥ãªãã£ã®å°é家ãã°ã«ãŒãã®æŽ»åã«é¢é£ä»ããŠãããã¹ãŠã®ãã¡ã€ã«ïŒã®ãªã¹ãã¯éåžžã«åºãããã®ãµããã¡ããªãŒã®å€ãããããšèããŠããŸãã ä»ã®ãµã€ããŒã°ã«ãŒãã§äœ¿çšãããŠããããŒã«ããããšã¯ç°ãªããLazarusããŒã«ã®ãœãŒã¹ã³ãŒãã¯ãäžè¬å ¬éããããªãŒã¯ã®çµæãšããŠæããã«ãããŸããã§ããã
Lazarusã¯ãç¹å¥ãªããã°ã©ã ã«å ããŠãGitHubã§å©çšå¯èœãªãããžã§ã¯ããŸãã¯åæ¥ããŒã¹ã§æäŸããããããžã§ã¯ãã䜿çšããŠããŸãã
Lazarusãªã³ã©ã€ã³ã«ãžãæ»æããŒã«
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãäžå€®ã¢ã¡ãªã«ã®ãªã³ã©ã€ã³ã«ãžããããã¯ãŒã¯ã®ãµãŒããŒãšã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ããããŒã«ã®ããã€ããèŠãŠãã©ã¶ããšã®æ¥ç¶ã確ç«ããæ¹æ³ã説æããŸãã ESETãŠã€ã«ã¹å¯Ÿç補åã¯ãWin32 / NukeSpedãWin64 / NukeSpedãªã©ã®ã°ã«ãŒããã«ãŠã§ã¢ãæ€åºããŸãã KillDiskã®ç Žå£çãªãœãããŠã§ã¢ãµã³ãã«ãšçµã¿åãããŠäœ¿çšââãããŸããã
ãããã®ããŒã«ã®ã»ãšãã©ãã¹ãŠã¯ãWindowsãµãŒãã¹ãšããŠå®è¡ããããã«èšèšãããŠããŸãã ãããè¡ãã«ã¯ã管çè æš©éãå¿ èŠã§ããã€ãŸããéçºè ãŸãã¯ã³ã³ãã€ã«äžã«æ»æè ã¯ãããã®æš©éãæã£ãŠããå¿ èŠããããŸãã
TCPããã¯ãã¢
Win64 / NukeSped.Wã¯ãã·ã¹ãã ãšããŠãµãŒãã¹ãšããŠã€ã³ã¹ããŒã«ãããã³ã³ãœãŒã«ã¢ããªã±ãŒã·ã§ã³ã§ãã å®è¡ã®æåã®ã¹ãããã®1ã€ã¯ãå¿ èŠãªDLLåãã¹ã¿ãã¯ã«åçã«ããŒãããããšã§ãã
åæ§ã«ãWindows APIã®ããã·ãŒãžã£åã¯åçã«æ§ç¯ãããŸãã ãã®ç¹å®ã®ãã¿ãŒã³ã§ã¯ããã¬ãŒã³ããã¹ãã§è¡šç€ºãããŸãã åæããä»ã®éå»ã®ãµã³ãã«ã§ã¯ãââbase64ã§ãšã³ã³ãŒããæå·åããŸãã¯æåããšã«ã¹ã¿ãã¯ãããŠããŸããã
ãããã®çç¶ã¯ãLazarusãã«ãŠã§ã¢ã®å žåçãªç¹åŸŽã§ãã Lazarusããã¯ãã¢ã®ãã1ã€ã®å žåçãªç¹æ§ã¯ããã®ããã¯ãã¢ã«ãèŠãããŸããç¹å®ã®ããŒãã§ãªãã¹ã³ããŸããããã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãããããã¯ã®ææšã§ãã
ããã¯ãã¢ã¯20ããŒã ããµããŒããããã®æ©èœã¯ä»¥åã«åæãããLazarusãµã³ãã«ã«äŒŒãŠããŸãïŒããã§ã®ã³ãã³ãåã¯æ»æè ã«ãã£ãŠäžãããããã®ã§ã¯ãªããESETãŠã€ã«ã¹ã¢ããªã¹ãã«ãã£ãŠäœæããããã®ã§ãïŒã
ããã¯ãã¢ã¯ããã¡ã€ã«ã·ã¹ãã ã«ããã€ãã®ãã¡ã€ã«ãäœæããŸãã ãªã¹ãã³ã°ããŒãã¯ã
%WINDOWS%\Temp\p
ãšããååã®ããã¹ããã¡ã€ã«ã«ä¿åãããŸãã ãã¡ã€ã«
%WINDOWS%\Temp\perflog.evt
ã«ã¯ãæååã®æåã®æåã«å¿ããŠãæ³šå ¥ãå®è¡ããŸãã¯ã¬ãžã¹ããªãžã®æžã蟌ã¿çšã®ãã€ããªãã¡ã€ã«ãã¹ã®ãªã¹ããå«ãŸããŠããŸãã
â +âãªãã·ã§ã³ã®å Žåã
cmd.exe / c «% s 2 »% s»
ïŒãŸãã¯
cmd.exe / c «% s »% s 2> 1»
ïŒã®åºåã¯
% WINDOWS% \ Temp \ perflog.dat
ã
ã»ãã·ã§ã³ã¯ã©ãã«ãŒ
Win64 / NukeSped.ABã³ã³ãœãŒã«ã¢ããªã±ãŒã·ã§ã³ã¯ã被害è ã®ã·ã¹ãã ã«çŸåšç»é²ãããŠããå¥ã®ãŠãŒã¶ãŒã«ä»£ãã£ãŠããã»ã¹ãäœæããŸãïŒåè¿°ã®TCPããã¯ãã¢ããã®ã³ãã³ãçªå·17ãšåæ§ïŒã
ããã¯ãã«ã¹ãã«ã¹ããŒã«ãã£ãŠèšè¿°ãããThemidaä¿è·ããŒãžã§ã³ã§ãã ç§ãã¡ã®å Žåã
C:\ Users\public\ps.exe
ãšããŠã€ã³ã¹ããŒã«ãã
C:\ Users\public\ps.exe
ã 3ã€ã®ãã©ã¡ãŒã¿ãŒããããŸãã
éçã¹ãã£ã³ã¯ããããã®ãµã³ãã«ã®äž¡æ¹ã§åããã¡ã€ã«ããããã£ã瀺ããŸããåãPEã³ã³ãã€ã«ã¿ã€ã ã¹ã¿ã³ããåäžã®ãªããããããŒãªã³ã«ãŒããŒã¿ïŒVisual Studio 2010ãªã³ã«ãŒïŒ10.00ïŒãæãïŒãããã³ãªãœãŒã¹ããŒãžã§ã³æ å ±ã®äžéšã¯åãã§ãã
PEã¿ã€ã ã¹ã¿ã³ããšãªãœãŒã¹ã¯Windows 7 SP1ã®æ£åœãªMicrosoft
PREVHOST.EXE
ãã¡ã€ã«ããçãŸããŸããããã¡ã€ã«ã®ãªã³ã¯æ å ±ã¯ãããŸãããå ã®Microsoftãã¡ã€ã«ã¯ã³ã³ãã€ã«ãããVisual Studio 2008ïŒ9.00ïŒã«ãªã³ã¯ãããŸããã
äžè²«ããåçåæã«ããã䟵害ããããªã³ã©ã€ã³ã«ãžããããã¯ãŒã¯ã§èŠã€ãã£ããã®ãã¡ã€ã«ã¯ãããŒã©ã³ãããã³ã¡ãã·ã³ã®ãµã€ãã«å¯Ÿããæ»æã§äœ¿çšãããã»ãã·ã§ã³ã¯ã©ãã«ãŒã«é¢é£ä»ããããŠããããšã確èªãããŸããã
ããŒãããŒããŒ/ã€ã³ã¹ããŒã©ãŒ
ããã¯ãããã€ãã®ãªãã·ã§ã³ãåãå ¥ããåçŽãªã³ãã³ãã©ã€ã³ããŒã«ã§ãã ããã»ã¹ïŒPIDãŸãã¯ååã䜿çšããŠããã»ã¹ãæ¿å ¥/åé€ïŒããµãŒãã¹ïŒãµãŒãã¹ãçµäº/åã€ã³ã¹ããŒã«ïŒããŸãã¯ãã¡ã€ã«ïŒãªã»ãã/åé€ïŒã§åäœããããã«èšèšãããŠããŸãã æ©èœã¯ãã©ã¡ãŒã¿ãŒã«ãã£ãŠæ±ºãŸããŸãã
KillDiskããŒãžã§ã³
KillDiskã¯ãESET補åããã£ã¹ã¯ãæ¶å»ããæ©èœãåããç Žå£çãªãã«ãŠã§ã¢ãæ€åºããäžè¬çãªååã§ã-ããŒãã»ã¯ã¿ãŒã®æå·ãšäžæžãããããŠïŒã·ã¹ãã ïŒãã¡ã€ã«ã®åé€ãããã«ç¶ãåèµ·åã«ãããããã€ã¹ã䜿çšã§ããªããªããŸãã
KillDiskã®ãã¹ãŠã®ããŒãžã§ã³ã«åæ§ã®æ©èœããããšããäºå®ã«ããããããããµã³ãã«ã®ã³ãŒãããŒã¹ã¯åžžã«äžèŽãããšã¯éããŸããã KillDiskã«ã¯ããµãã£ãã¯ã¹ã«ãã£ãŠååãç°ãªããµããã¡ããªãŒãå€æ°ãããŸãïŒãã®äŸã§ã¯ãWin32 / KillDisk.NBOïŒã å ±éã®ã³ãŒããã©ã°ã¡ã³ããæã€ãµããã¡ããªãŒã®äºçš®ã¯ãç°ãªããµã€ããŒãã£ã³ããŒã³ã§äœ¿çšãããããšããããŸããããã¯ããã®å Žåã®ããã«ãæ»æã®äžè¬çãªãœãŒã¹ã瀺ãå ŽåããããŸãã
KillDiskã®ä»ã®ããŒãžã§ã³ã¯ã 2015幎12æããã³2016幎 12æã«ãŠã¯ã©ã€ãã®æšçã«å¯Ÿããæšçåæ»æã§äœ¿çšãããŸãããããããã®ãµã³ãã«ã¯ä»ã®ãµããã¡ããªãŒã«å±ããããããæ°ããæ»æã«é¢é£ããŠããŸããã
äžå€®ã¢ã¡ãªã«ã§ã®äºä»¶ã調æ»ãããšããã䟵害ããããããã¯ãŒã¯ã§Win32 / KillDisk.NBOã®2ã€ã®äºçš®ãèŠã€ãããŸããã çµç¹å ã®100å°ä»¥äžã®ãã·ã³ããã«ãŠã§ã¢ã«ææããŸããã ãã®å€èŠ³ã«ã¯ããã€ãã®èãããã説æããããŸããæ»æè ã¯ãæ»æåŸã«çè·¡ãé ãããšãã§ããŸãããããã¯ãæDiskããµã€ããŒç Žå£ã®ããã«KillDiskã䜿çšã§ããŸãã ãããã«ãããããã¯1ã€ã®çµç¹å ã§ã®å€§èŠæš¡ãªææã§ãã
ç§ãã¡ã®ãã¬ã¡ããªããŒã¿ãããã³Win32 / KillDisk.NBOã®ããŒãžã§ã³ãšäŸµå®³ããããããã¯ãŒã¯ã§ã®ãã®ä»ã®æåãªLazarusããŒã«ã®åæ䜿çšã¯ãKillDiskãå±éããã®ã¯Lazarusããã«ãŒã§ãããä»ã®ãµã€ããŒã°ã«ãŒãã§ã¯ãªãããšã瀺ããŠããŸãã
2ã€ã®ãµã³ãã«ã®åæã«ãããå€ãã®äžè¬çãªã³ãŒããã©ã°ã¡ã³ããããããšãããããŸããã ããã«ã ãã¬ã³ããã€ã¯ãã調æ»ããã©ãã³ã¢ã¡ãªã«ã®éèæ©é¢ã«å¯Ÿããæ»æã§äœ¿çšãããKillDiskã®ããŒãžã§ã³ãšã»ãŒåãã§ãã
ãªã³ã©ã€ã³ã«ãžããããã¯ãŒã¯ã§èŠã€ãã£ãKillDiskãµã³ãã«ã¯ã次ã®ãã¹ã䜿çšããŸã
C:\Windows\Temp\dimens.exe
å®éã®ãã«ãã€ã³ãã€ããŒãã¯ã
werfault.exe
ã·ã¹ãã ããã»ã¹ã«æ¿å ¥ãããŸãã
1ã€ã®ãªãã·ã§ã³ã¯ã第3äžä»£ã®åçšVMProtectã§ä¿è·ãããŠãããé梱ãå°é£ã§ãã ã»ãšãã©ã®å Žåãæ»æè ã¯VMProtectã©ã€ã»ã³ã¹ãè³Œå ¥ããŠããŸããããã€ã³ã¿ãŒãããäžã§å ¥æå¯èœãªæµ·è³çãŸãã¯ãªãŒã¯ãããã³ããŒã䜿çšããŠããŸãã ãœãããŠã§ã¢ä¿è·ããŒã«ã®äœ¿çšã¯ãã©ã¶ãã°ã«ãŒãã«ãšã£ãŠå žåçã§ãã2017幎2æã®ããŒã©ã³ãããã³ã¡ãã·ã³ã®éè¡ãžã®æ»æã§ã¯ããšãã°ããããã¯ã¿ãŒã䜿çšããŸããã Palo Alto Networksã«ãã£ãŠå ±åãããäžéšã®Operation Blockbusterãµã³ãã«ã¯ ãVMProtectã®å€ãããŒãžã§ã³ã䜿çšããŠããŸããã
å žåçãªã©ã¶ãæåå圢åŒ
ãµã³ãã«ã®äœæè ãšæ»æã®çºä¿¡å ãã©ã¶ãã°ã«ãŒãã«åž°å±ãããããšãã§ããå€ãã®ç¹æ§ã®äžã§ãè¡ã®åœ¢åŒã«æ³šæããå¿ èŠããããŸãã 以äžã®è¡šã¯ãäžèšã®ãµã³ãã«ãããã³Lazarusã«é¢é£ããä»ã®TCPããã¯ãã¢ã§èŠã€ãã£ããã©ãŒããããããæååã瀺ããŠããŸãã
ãã®äºå®ã ãã§ã¯èšŒæ ãšã¯ãªããŸããããESETã«ãã£ãŠã³ã³ãã€ã«ããããã«ãŠã§ã¢ã®ãã¹ãŠã®ãµã³ãã«ã§åæ§ã®æååãã©ãŒããããæ¢ãããšãããLazarusã«é¢é£ãããšæããããµã³ãã«ã§ã®ã¿èŠã€ãããŸããã ãããã£ãŠããããã®è¡ã®ååšã¯ãã©ã¶ãã®åäœè ã瀺ããŠãããšæ³å®ã§ããŸãã
è¿œå ã®ããŒã«
æ»æè ã䜿çšããå°ãªããšã2ã€ã®å©çšå¯èœãªããŒã«ããããŸãã
ãã©ãŠã¶ãã¹ã¯ãŒããã³ã
ãã®ããŒã«ã¯ãäžè¬çãªWebãã©ãŠã¶ãŒãããã¹ã¯ãŒããå埩ããããã«èšèšãããŠããŸãã 2014幎12æ以æ¥ã圌ã¯å€ããŠæåãªæ¹æ³ã䜿çšããŠããŸãã Google ChromeïŒ64.0.3282.186ïŒãChromiumïŒ67.0.3364.0ïŒãMicrosoft EdgeïŒ41.16299.15.0ïŒãMicrosoft Internet ExplorerïŒ11.0.9600.17843ïŒã®ææ°ããŒãžã§ã³ã§äœ¿çšã§ããŸãã FirefoxãŸãã¯Operaã®ææ°ããŒãžã§ã³ãšäºææ§ããããŸããã
ããã«ãã
æ»æè ã¯ãWindowsè³æ Œæ å ±ãæœåºããããã«èšèšãããMimikatzããŒã«ã®ä¿®æ£ããŒãžã§ã³ã䜿çšããŸããã 1ã€ã®ãã©ã¡ãŒã¿ãŒ-åºåãä¿åãããã¡ã€ã«ã®ååãåããŸãã æå®ããªãå Žåã
~Temp1212.tmp
ãšãã
~Temp1212.tmp
åºåãã¡ã€ã«ã
~Temp1212.tmp
ãšåããã£ã¬ã¯ããªã«ä¿åãããŸãã åºåã«ã¯ãèš±å¯ããããŠãŒã¶ãŒã®Windowsè³æ Œæ å ±ã®ããã·ã¥ãå«ãŸããŸãã ãã®ããŒã«ã¯ãç¹ã«Petyaæµè¡ã® Telebotsã°ã«ãŒããOperation Buhtrapã«ããæšçåæ»æã§ãã䜿çšãããŸãã
ææãã¯ã¿ãŒ
äžèšã®ããŒã«ã®ã»ãšãã©ã¯ãæ»æã®åæ段éã§äœ¿çšãããæªæã®ãããããããŒãšããŒãããŒããŒã䜿çšããŠãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ããŠã³ããŒãããã³ã€ã³ã¹ããŒã«ãããŸããã ããã«ã Radmin 3ãLogMeInãªã©ã®ãªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ã䜿çšããŠã¿ãŒã²ããããã€ã¹ãç£èŠããŠããããšã瀺ãã€ã³ãžã±ãŒã¿ãŒãèŠãŸããã
çµè«
äžå€®ã¢ã¡ãªã«ã®ãªã³ã©ã€ã³ã«ãžãã«å¯Ÿããæè¿ã®æ»æã¯ãæ°ãããã£ã³ããŒã³ã®åã«Lazarusããã«ãŒãããŒã«ãåã³ã³ãã€ã«ããããšã瀺åããŠããŸãïŒä»ã®å Žæã§åããµã³ãã«ãèŠãããšã¯ãããŸããïŒã ããã¯è€éãªå€æ®µéæ»æã§ãããä¿è·ãããå€æ°ã®ããŒã«ã䜿çšãããèªåŸåã§ããããããã®ãããªãã€ããã¯ã¹ã¯å®èšŒãããŸããã§ããã
KillDiskã®äœ¿çšã¯ã次ã®2ã€ã®ç®çã®ããããã«åœ¹ç«ã€å¯èœæ§ããããŸããæ»æè ã¯ãã¹ãã€æŽ»åã®åŸã«çè·¡ãé ããããç Žå£ãœãããŠã§ã¢ã䜿çšããŠåŒ·èŠãŸãã¯åŠšå®³ããŸããã ãããã«ãããçµç¹ã®100ãè¶ ããã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒã§ãã«ãŠã§ã¢ãæ€åºãããããšã¯ãæ»æè ãå€å€§ãªãªãœãŒã¹ãæ¶è²»ããŠããããšã瀺ããŠããŸãã
ãµã³ãã«
429B750D7B1E3B8DFC2264B8143E97E5C32803FF Win32/KillDisk.NBO
7DFE5F779E46855B32612D168B9CC5334F25B5F6 Win32/KillDisk.NBO
5042C16076AE6346AF8CF2B40553EEEEA98D5321 Win64/NukeSped.W trojan (VMProtect-ed)
7C55572E8573D08F3A69FB15B7FEF10DF1A8CB33 Win64/NukeSped.W trojan (Themida-protected)
E7FDEAB60AA4203EA0FF24506B3FC666FBFF759F Win64/NukeSped.Z trojan (Themida-protected)
18EA298684308E50E3AE6BB66D7321A5CE664C8E Win64/NukeSped.Z trojan (VMProtect-ed)
8826D4EDBB00F0A45C23567B16BEED2CE18B1B6A Win64/NukeSped.AB trojan (Themida-protected)
325E27077B4A71E6946735D32224CA0421140EF4 Win64/Riskware.Mimikatz.A application
D39311C74DEB60C736982C1AB74D6684DD1E1264 Win32/SecurityXploded.T (VMProtect-ed)
E4B763B4E74DE3EF24DB6F19108E70C494CD18C9 Win32/SecurityXploded.T (Themida-protected)