æè¿ãPT ESCã¹ãã·ã£ãªã¹ãã¯ããInvitation November 29-30ã2018.pubãïŒ1edd5b6a02ec82cec381c1a1ec74a67eïŒãšããPublisher圢åŒã®ããã¥ã¡ã³ããçºèŠããŸããã ãã®èšäºã§ã¯ãéåžžã®ããã¥ã¡ã³ããããã€ã®æšéŠ¬ã«ãªããæ»æè ãWebã«ã¡ã©ããç»åããã£ããã£ããããã³ãã³ãã§é³å£°ãé²é³ããããSkypeãŠã£ã³ããŠãæ€åºããããšãã«PowerShellã¹ã¯ãªãããå®è¡ããããã¹ã¯ãªãŒã³ã·ã§ãããæ®ã£ãããã¡ãã£ã¢ããã€ã¹ãããã¡ã€ã«ãã³ããŒãããããæ¹æ³ã説æããŸãã
ãã®ãããããã¥ã¡ã³ããéããšããŒãããããã¥ã¡ã³ãã¹ã¿ããšMicrosoft Publisherã¹ã¯ãªãããå«ããããèŠæ±ãããŠã£ã³ããŠã衚瀺ãããŸãã
ãŠãŒã¶ãŒãæå¹ã«ãããšãããã¥ã¡ã³ãã«çµã¿èŸŒãŸããã¹ã¯ãªãããJavaScriptã§å®è¡ãããŸãã 次ã®ããã«ãªããŸãã
ã¹ã¯ãªããã®çµæã¯ãBase64ããã®2ã€ã®ãã¡ã€ã«ãPDFãšEXEã®ãã³ãŒãã«ãªããŸãã äž¡æ¹ã®ãã¡ã€ã«ã¯CïŒ\ Users \ {Username} \ AppData \ Roaming \ DBFUpdateã«æžã蟌ãŸããŸãã ãããã£ãŠãäž¡æ¹ã®ãã¡ã€ã«ãå®è¡ããããŠãŒã¶ãŒã«ã¯ããã¥ã¡ã³ãç»é¢ã«ãã®ãããªã¹ã¿ãã衚瀺ãããŸãã
ãã¬ãžã£ãŒãã³ã¿ãŒRAT
æ»æè ã¯ãææãããã·ã³ãžã®ãã«ã¢ã¯ã»ã¹ãæäŸããå€æ°ã®æ©èœãåãããã«ãã¢ãžã¥ãŒã«RATã䜿çšããŸãã
ã³ãŒãæ©èœïŒ
- å éšçã«äœ¿çšãããå€æ°ã®STLã³ã³ã¹ãã©ã¯ãã䜿çšããŠãå®å šã«C ++ã§èšè¿°ãããŠããŸãã
- ããŒã¹ãã©ã€ãã©ãªãç¹ã«JSONããã³ã¢ãŒã«ã€ãã®ã¢ããªã±ãŒã·ã§ã³ã
- ãããã°æ©èœïŒã¹ããŒãžã£ãŒã»ã¯ã·ã§ã³ã®è©³çŽ°ïŒã
ã¡ã€ã³ããã€ã®æšéŠ¬
ã¡ã€ã³ã®ããã€ã®æšéŠ¬ã¯è¢«å®³è ã®ãã·ã³ã«åºå®ãããŠãããC2ããæªæã®ããã¢ãžã¥ãŒã«ãããŒãããããã©ãããã©ãŒã ã§ãã
ãŸããstagerã¯äœæ¥ãã£ã¬ã¯ããªãåæåããŸãããã®ãã£ã¬ã¯ããªã«ã¯ãã¢ãžã¥ãŒã«ãã¢ãžã¥ãŒã«ã®åäœã«å¿ èŠãªãŠãŒãã£ãªãã£ãªã©ã«ãã£ãŠåéãããæ å ±ãæ ŒçŽãããŸãã
以äžã¯ãäœæ¥ãã£ã¬ã¯ããªãäœæããããã®ãã¹ã®åæåã§ãã
å¿ èŠãªãã£ã¬ã¯ããªãäœæãããåŸãã¡ã€ã³ã®ããã€ã®æšéŠ¬ã¯ææãããã·ã³ã«é¢ããæ å ±ãåéãããããå¶åŸ¡ãµãŒããŒã«éä¿¡ããŸãã
ããã€ã³ã¯ãã®ãããªããŒã¿ã«èå³ããããŸãïŒ
- ã¡ã€ã³ã®ããã€ã®æšéŠ¬ãå®è¡ãããŠããOSã®ããŒãžã§ã³ã®èå¥åã
- ããã©ã«ãã®ã€ã³ã¿ãŒãã§ãŒã¹èšèª
- Service Pack OSã®ã¡ãžã£ãŒããŒãžã§ã³çªå·ã
- ã³ã³ãã¥ãŒã¿åãšãã·ã³èå¥åïŒãã·ã³èå¥åã®ååŸã®è©³çŽ°ã«ã€ããŠã¯ããããã¯ãŒã¯ãããã³ã«ã®ã»ã¯ã·ã§ã³ãåç §ããŠãã ããïŒã
ããã¯ãææãããã·ã³ã«é¢ããæ å ±ã®åéæ¹æ³ã§ãã
次ã«ãHKCU \ Environment \ UserInitMprLogonScriptã«ããã¬ãžã¹ããªã®å€ãå€æŽããããšã«ãããææãããã·ã³ã§ã¡ã€ã³ã®ããã€ã®æšéŠ¬ãä¿®æ£ãããŸãã äœæ¥ãã£ã¬ã¯ããªã®åæåäžã«å²ãåœãŠãããå®è¡å¯èœãã¡ã€ã«ã®ååãããã«æžã蟌ãŸããŸãããã®å ŽåããDCTHOST.exeããšåãã§ãã ãã®æ¹æ³ã¯Hexacornããã°ã§èª¬æãããŠãããAPT28ãšCoDLLtã°ã«ãŒãã®ComDLLDroperã§ã䜿çšãããŠããŸããã
ã¡ã€ã³ã®ããã€ã®æšéŠ¬ãåæåããæåŸã®æé ã¯ãå®è¡å¯èœãã¡ã€ã«ãçŸåšã®å Žæãããäœæ¥ãã£ã¬ã¯ããªãåæåããããšãã«éžæãããã®ãšåãååã®äœæ¥ãã£ã¬ã¯ããªã«ã³ããŒããããšã§ãã
ã¡ã€ã³ã®ããã€ã®æšéŠ¬ãåæåãããåŸãã³ãã³ããåä¿¡ããããã®æºåãå®è¡ãããŸãã ã³ã¢ã¢ãžã¥ãŒã«ãå®è¡äžã®ã¢ãžã¥ãŒã«ã®ãªã¹ãã«è¿œå ãããŸããããã¯ã¡ã€ã³ã®ããã€ã®æšéŠ¬ã§ãã 次ã«ãèå¥å0ã®ã³ã¢ã¢ãžã¥ãŒã«ããã³ãã³ããèµ·åãããŸããã¡ã€ã³ã¢ãžã¥ãŒã«ã«ã¯ãã®ã³ãã³ãã®å®è£ ã¯ãªããåãªãã¹ã¿ãã§ãã Coreã¢ãžã¥ãŒã«ã®ãªããžã§ã¯ãã®ã³ã³ã¹ãã©ã¯ã¿ãŒã以äžã«ç€ºããŸãã
æåŸã«ã2ã€ã®ã¹ã¬ãããéå§ãããŸãã ã¹ã¬ããã®1ã€ãã¿ã€ããŒãéå§ããŸããã¿ã€ããŒã¯ããã©ã«ãã§æ¯ç§èµ·åããC2ããã³ãã³ããèŠæ±ããããšããŸãã
2çªç®ã®ã¹ããªãŒã ã¯ãè¿œå ã®ã©ã€ãã©ãªãšæšæºã¢ãžã¥ãŒã«ãããŒãããŸãã ã¢ãžã¥ãŒã«ãšåæ§ã«ãã©ã€ãã©ãªã«ã¯èå¥åããããŸãããã¢ãžã¥ãŒã«ãšã¯ç°ãªããã©ã€ãã©ãªèå¥åã¯ãã€ãã¹ã§ã-1ããå§ãŸããæ°åãå°ããã»ã©å€§ãããªããŸãã 以äžã¯ãC2ããããŠã³ããŒããããã©ã€ãã©ãªã®ãªã¹ãã§ãã
ã¡ã€ã³ã®ããã€ã®æšéŠ¬ã®ãããã°æ©èœ
äœæ¥ã®æåã®åæåçŽåŸã«ãã¡ã€ã³ã®ããã€ã®æšéŠ¬ã¯ãèå³æ·±ãæ©èœãå«ãSetUnhandledExceptionFilterãä»ããŠäŸå€ãã³ãã©ãèšå®ããŸãã äŸå€ãçºçãããšããã³ãã©ãŒã«åé¡ãããã¢ããªã±ãŒã·ã§ã³ã®ãããã³ããæžã蟌ãŸããŸãããäŸå€ã«é¢ããæ å ±ãä¿åãããŸãã ãã®åŸãèªåçã«åèµ·åããŸãã ç»é¢äž-ãããã³ãã®äœæïŒ
ãããã¯ãŒã¯ãããã³ã«
ãœãããŠã§ã¢ãšC2ã®éã®äº€æã¯ãèªå·±èšè¿°ã®ãã€ããªãããã³ã«ã䜿çšããŠè¡ãããŸãã åã¡ãã»ãŒãžã¯BinPackageïŒRTTIããåãããååïŒã䜿çšããŠèšè¿°ãããŸãã åBinPackageã¯ãæ¬è³ªçã«std :: vectorã®ã©ãããŒã§ãããPackageRecordã»ãããä¿åããŸãïŒååã¯çºæãããŠããŸãïŒã PackageRecordã¯ãããŒã¿ãä¿åããããã®æå°åäœã§ãã
struct PackageRecord { _DWORD dataId; _DWORD datatype; _DWORD szData; char[] data; };
ãã®æ§é äœã®ãã£ãŒã«ãã®è©³çŽ°ïŒ
- dataId-ã¬ã³ãŒãã®ã¿ã€ãã瀺ããŸãã ã¬ã³ãŒãã¯ãã¢ãžã¥ãŒã«èå¥åãã³ãã³ãèå¥åããŸãã¯ãã€ããŒãã®ããããã§ãã
- szData-ã¬ã³ãŒãã«ä¿åãããŠããããŒã¿ã®ãµã€ãºã
- ããŒã¿åã¯ããŒã¿åã§ãã
åèšã§ã3ã€ã®ããŒã¿ã¿ã€ãã®äœ¿çšãèšé²ãããŸããã
- ã0ãã®å€ã¯ãã¬ã³ãŒãã«æ ŒçŽãããŠããããŒã¿ãDWORDãšããŠè§£éããå¿ èŠãããããšãæå³ããŸãã
- å€ã1ã-ã¬ã³ãŒãã«ä¿åãããŠããããŒã¿ã¯ãASCIIZæååãšããŠè§£éãããå¿ èŠããããŸãã
- å€ã2ã-ã¬ã³ãŒãã«ä¿åãããŠããããŒã¿ã¯ãæå·åãããããŒã¿/çã®ãããã¡ãšããŠè§£éãããå¿ èŠããããŸãã
BinPackageãå¶åŸ¡ãµãŒããŒã«éä¿¡ãããšããã·ã³èå¥åãè¿œå ãããŸãã èå¥åã¯ããã¹ãŠã®ç¹æ®æåãåãåãããã»ã¯ã·ã§ã³ã®GUIDã§ãã å³-ãã·ã³èå¥åã®ååŸïŒ
éä¿¡ããåã«ãBinPackageã«ä¿åãããŠãããã¹ãŠã®ã¬ã³ãŒããåäžã®ãããã¡ãŒã«é çªã«åéãããæå·åãããŸãã æå·åã«ã¯ã WinAESã©ã€ãã©ãªãç¹ã«AES-128-CBCã䜿çšãããŸãã
CryptoAPI Windowsã䜿çšããŠã2ã€ã®16ãã€ãã®æ¬äŒŒã©ã³ãã é åãçæãããŸãã IVçšã«1ã€ãããŒçšã«1ã€ã æå·åãå®è¡ãããæå·åãããããŒã¿ãBinPackageã«è¿œå ãããŸããBinPackageã¯æå·åããããã±ãããå«ã¿ã3ã€ã®ãšã³ããªã§æ§æãããŸãã
- ID 0x777ã®ã¬ã³ãŒã-æå·åã«äœ¿çšãããããŒãå«ãŸããŠããŸãã
- ID 0x555ã®ã¬ã³ãŒã-æå·åã«äœ¿çšãããIVãå«ãŸããŠããŸãã
- ID 0x999ã®ã¬ã³ãŒã-æå·åãããããŒã¿ãå«ã¿ãŸãïŒäžè¬ã«ããã®IDã®ã¬ã³ãŒãã¯ãã€ããŒãã瀺ããæå·åãããããŒã¿ã®ä¿åã ãã§ãªã䜿çšãããŸãïŒã
æå·åããã»ã¹ã®çµäºåŸãçæãããBinPackageã¯åã³åäžã®ãããã¡ãŒã«åéãããHTTP POSTèŠæ±ãä»ããŠç®¡çãµãŒããŒ151.80.237.222ã«éä¿¡ãããŸãã
以äžã¯ããã·ã³æ å ±ãå«ãããã±ãŒãžã®äŸã§ãã
ãããŠãããã¯ã·ã¹ãã æ å ±ãæã€æå·åããããã±ããã®äŸã§ãïŒ
ã¢ãžã¥ãŒã«
Coreãé€ãåã¢ãžã¥ãŒã«ã¯ãã³ã³ãããŒã«ãµãŒããŒããããŒããããŸãã ãã¹ãŠã®ã¢ãžã¥ãŒã«ã¯ãèªåçã«ããŒããããã¢ãžã¥ãŒã«ãšãå¶åŸ¡ãµãŒããŒããã®èŠæ±ã«å¿ããŠããŒããããã¢ãžã¥ãŒã«ã®2ã€ã®ã«ããŽãªã«åé¡ã§ããŸãã
ã¢ãžã¥ãŒã«ãèŠæ±ããããã±ãŒãžã®äŸïŒ
ã¢ãžã¥ãŒã«èŠæ±ãžã®å¿çïŒ
åã¢ãžã¥ãŒã«ã«ã¯ãInitã¢ãžã¥ãŒã«ã®ããŒãæã«åŒã³åºãããfiniã®å®äºæã«åŒã³åºããã3ã€ã®é¢æ°ãšãã¢ãžã¥ãŒã«ã®æ§æãå€æŽããé¢æ°ã§æ§æãããã·ã³ãã«ãªã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã åã¢ãžã¥ãŒã«ã«ã¯GetModuleãšããååã®ãšã¯ã¹ããŒãããããŸããããã¯ããã®ã¢ãžã¥ãŒã«ãè¡šããªããžã§ã¯ããæ§ç¯ããã¡ã€ã³ã®ããã€ã®æšéŠ¬ã«è¿ããŸãã ç§ãã¡ãçºèŠãããã¹ãŠã®ã¢ãžã¥ãŒã«ã¯ãåå°ããŒãã£ã³ã°ã䜿çšããŠã¡ã¢ãªå ã§èµ·åãããŸãã
ããã«ãã¢ãžã¥ãŒã«ã®ååã¯ãã¯ã©ã¹åãšããŠRTTIã«ååšãã圢åŒã§æäŸãããŸãã
CCoreã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã¯åºæ¬çãªæ©èœãè¡šããã¡ã€ã³ã®ããã€ã®æšéŠ¬ã«çŽæ¥çµã¿èŸŒãŸããŠããŸãã ãã®ã³ã³ã¹ãã©ã¯ã¿ãŒã¯ã以äžã®è¡šã§èŠãããšãã§ããŸãïŒ
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
0 | 0 | åºæ¬çã«ãã³ãã³ãã§ã¯ãªãããã€ã®æšéŠ¬ã¯ã¹ã¿ãã§ããããã®æ£ç¢ºãªç®çã¯ç¢ºç«ã§ããŸããã§ãã |
1 | ã¢ãžã¥ãŒã«æ§æã®å€æŽ | |
2 | ã³ã³ãã¥ãŒã¿ãŒæ å ±ãèŠæ±ãã | |
3 | å¶åŸ¡ãµãŒããŒãããŠãŒãã£ãªãã£ãããŠã³ããŒãããŸã | |
4 | ãŠãŒãã£ãªãã£ãå«ããã£ã¬ã¯ããªã®ãªã¹ããèŠæ±ãã | |
5 | ã¢ãžã¥ãŒã«ãããŠã³ããŒãããŠå®è¡ãã |
CShellã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã¯ãææãããã·ã³ã«ãªã¢ãŒãã·ã§ã«ãæäŸããŸãã ã¢ãžã¥ãŒã«ãåæåããããšãcmd.exeããã»ã¹ãäœæããã2ã€ã®ãã€ããæ¥ç¶ãããŸãã1ã€ã¯æšæºå ¥åçšããã1ã€ã¯æšæºåºåçšã§ãã³ã³ãããŒã«ãµãŒããŒããã³ãã³ããéåä¿¡ããŸãã ãŸãããã®æç¹ã§ã¹ã¬ãããéå§ããããã¹ãŠã®åºåãèªåçã«ååŸãããŠå¶åŸ¡ãµãŒããŒã«éä¿¡ãããŸãã ãã®å³ã¯ãCShellã¢ãžã¥ãŒã«ã®åæåã瀺ããŠããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
2 | 0 | ã³ãã³ããã·ã§ã«ã«éä¿¡ãã |
1 | ãã¡ã€ã«ãå°å·ããŸãã ãã¡ã€ã«ãèªã¿åãããå¶åŸ¡ãµãŒããŒããéä¿¡ããããã¹ãæå®ããããã®ãã¡ã€ã«ã®å 容ãå¶åŸ¡ãµãŒããŒã«ã¢ããããŒããããŸã | |
2 | ã·ã¹ãã ã«ååšãããã¹ãŠã®ãã£ã¹ã¯ã®ãªã¹ããååŸããŸãã ããŒã¿ã¯JSON圢åŒã§å¶åŸ¡ãµãŒããŒã«éä¿¡ãããŸã | |
3 | å¶åŸ¡ãµãŒããŒãããã¡ã€ã«ãããŠã³ããŒãããŸãã ãã¡ã€ã«ãä¿åãããã¹ãããã³å¶åŸ¡ãµãŒããŒããããŒã¿ãåä¿¡ããŸã |
CFileSystemBrowserã¢ãžã¥ãŒã«
ããã¯ããã·ãã¢ãžã¥ãŒã«ã§ãããèŠæ±ã«å¿ããŠãã¡ã€ã«ã·ã¹ãã ã®æ§é ã«é¢ããæ å ±ãåãåãããšãã§ããŸãã CFileSystemBrowserã¢ãžã¥ãŒã«ã®åæåã¯æ¬¡ã®ããã«è¡ãããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
3 | 0 | ã·ã¹ãã ã«ååšãããã¹ãŠã®ãã£ã¹ã¯ã®ãªã¹ããååŸããŸãã ããŒã¿ã¯JSON圢åŒã§C2ã«éä¿¡ãããŸã |
1 | ãã£ã¬ã¯ããªãªã¹ããååŸããŸãã ãªã¹ãã¯JSON圢åŒã§çæãããŸã | |
2 | ãã¡ã€ã«ãå°å·ããŸãã ãã¡ã€ã«ãèªã¿åãããC2ããéä¿¡ããããã¹ãšããã®ãã¡ã€ã«ã®å 容ãC2ã«ã¢ããããŒããããŸã | |
3 | ãã¡ã€ã«ãåé€ããŸãã ãã¡ã€ã«ãžã®ãã¹ã¯C2ãã転éãããŸã |
CScreenShotã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã䜿çšãããšãã¹ã¯ãªãŒã³ã·ã§ãããæ®ã£ããããŠã§ãã«ã¡ã©ããç»åããã£ããã£ãããã§ããŸãã ããã¯ãèŠæ±æãšã¿ã€ããŒã®ç¹å®ã®æéã®äž¡æ¹ã§ãããè¡ãããšãã§ããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
4 | 0 | ã¹ã¯ãªãŒã³ã·ã§ãããæ®ãããããå¶åŸ¡ãµãŒããŒã«éä¿¡ããŸã |
1 | ã¿ã€ããŒãéå§ãããšããã·ã³ã®ç»é¢ããã¹ã¯ãªãŒã³ã·ã§ãããååŸãããŸãã çµæã®ã¹ã¯ãªãŒã³ã·ã§ããã¯BinPackageã«ããã±ãŒãžåãããlogsãã©ã«ããŒã«ä¿åãããŸãã ãã¡ã€ã«ã®ååã¯ãæ¥é èŸãMS_ããä»ããGetTempFileName APIã䜿çšããŠçæãããŸãã | |
2 | ææãããã·ã³ã§å©çšå¯èœãªããã€ã¹ã®ãããªãååŸãã | |
3 | Webã«ã¡ã©ãããã¬ãŒã ããã£ããã£ããå¶åŸ¡ãµãŒããŒã«éä¿¡ããŸã |
CSenderã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã¯æåã¯ã¢ã¯ãã£ãåãããŠããŸããã logsãã©ã«ããŒã®ã³ã³ãã³ããå¶åŸ¡ãµãŒããŒã«ã¢ããããŒãããŸãã æ€èšŒæéãå«ãæ§æãå€æŽããèŠæ±ãæ¥ããšã¢ã¯ãã£ãã«ãªããŸãã
CKeyloggerã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ãæåã¯ã¢ã¯ãã£ãåãããŠããŸããã ãã°ãä¿åããããããã¡ã®ãµã€ãºãå«ãæ§æå€æŽã®ãªã¯ãšã¹ããå°çãããšã¢ã¯ãã£ãã«ãªããŸãã å ¥åã®ååã¯rawinputãä»ããŠå®è¡ãããŸã ã ããã«ãããŒãã¬ãŒã¯ããŠãŒã¶ãŒãå ¥åãããŠã£ã³ããŠãç£èŠãããã®ã¿ã€ãã«ãèšé²ããŸãã
CDictaphoneã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã¯ãã³ãã³ããŸãã¯SkypeãŠã£ã³ããŠã®æ€åºæã«é³å£°ãèšé²ããŸãã èµ·åãããšãã·ã¹ãã å ã®ãã¹ãŠã®ãŠã£ã³ããŠãšãã®åãŠã£ã³ããŠããªã¹ãããã¹ã¬ãããéå§ããã¯ã©ã¹åãTLiveConversationãŸãã¯TCallMonitorControlã§ããã¯ã©ã¹ã®äžãããŠã£ã³ããŠãæ¢ããŸãã ãã®ãããªãŠã£ã³ããŠãèŠã€ãã£ãå Žåãèšé²ãéå§ãããŸãã 以äžã¯ãCDictaphoneã¢ãžã¥ãŒã«ã®åæåã§ãã
SkypeãŠã£ã³ããŠæ€çŽ¢
èšé²ã¯ãç¹å¥ãªã³ãã³ããéä¿¡ããããšã«ãããMCIãä»ããŠè¡ãããŸãã CDictaphoneã¢ãžã¥ãŒã«ã®æžã蟌ã¿ãµã€ã¯ã«ã¯æ¬¡ã®ããã«ãªããŸãã
ãŠã£ã³ããŠãéããããèšé²ãå®äºããããã®ã³ãã³ããåä¿¡ãããšãåä¿¡ããããŒã¿ã¯äžæãã©ã«ããŒã«ä¿åãããã©ã¡MP3ãšã³ã³ãŒããŒã«ãã£ãŠãšã³ã³ãŒããããŸãïŒãŠãŒãã£ãªãã£ãšèŠãªãããæ¢ã«èªã¿èŸŒãŸããŠããã¯ãã§ããå¶åŸ¡ãµãŒããŒããååŸããããšã¯ã§ããŸããã§ããïŒã ãšã³ã³ãŒãããããã¡ã€ã«ã¯ããã°ãã©ã«ããŒã«ä¿åãããŸãã ãã©ã«ããŒåã®çæã¯ãã¹ã¯ãªãŒã³ã·ã§ããã®ååã®çæã«äŒŒãŠããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
7 | 0 | èšé²ãéå§ãã15ååŸã«å®äºããŸã |
1 | èšé²ãåæ¢ | |
2 | ã¹ããŒã¿ã¹ã®ç¢ºèªïŒèšé²äžã§ã |
CProcessesManagerã¢ãžã¥ãŒã«
ããã¯ãèŠæ±ã«å¿ããŠããã·ãã¢ãžã¥ãŒã«ã§ãããããã»ã¹ã®ãªã¹ããè¿ãããæž¡ãããPIDã§çµäºã§ããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
8 | 0 | ããã»ã¹ã®ãªã¹ããè¿ããŸãïŒããã»ã¹ã®ååãPIDãããã³ããã»ã¹ãææãããŠãŒã¶ãŒã®ååã |
1 | PIDããã»ã¹ã®å®äº |
CDownloaderã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã¯ã倧ããªãã¡ã€ã«ãå¶åŸ¡ãµãŒããŒã«ã¢ããããŒãããããã«èšèšãããŠããŸãã ãã£ã³ã¯ã«ããããŒã¿éä¿¡ãå®è¡ããŸãããã£ã³ã¯ã®ãµã€ãºã¯ãæ§æã«ãã£ãŠç¢ºç«ãããŸãã ã¢ãžã¥ãŒã«ã¯ããã¡ã€ã«ãã³ã³ãããŒã«ãµãŒããŒããåä¿¡ãããã¹ããããŒã¿ãèªã¿åããBinPackageã«ãã£ã³ã¯ãããã¯ããŸãã ãã£ã³ã¯ãå«ãåBinPackageã«å¯ŸããŠããã¡ã€ã«ãžã®ãã¹ãå«ãèå¥å0x888ã®ãšã³ããªãè¿œå ãããŸãã åãã£ã³ã¯ãééããåŸãã¹ãªãŒãã5ç§éå®è¡ãããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
9 | 0 | ã¹ã¿ããæ£ç¢ºãªå€ãèšå®ã§ããŸããã§ãã |
1 | 倧éã®ããŒã¿ïŒ0x500000ãã€ãïŒã転éããåŸã転éã«ããã£ãæéã枬å®ãããã®å€ãC2ã«éä¿¡ããŸã | |
2 | ãã·ã³ãããã¡ã€ã«ãããŠã³ããŒããã |
CPSã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã䜿çšãããšãPowerShellã¹ã¯ãªãããå®è¡ã§ããŸãã
ã¢ãžã¥ãŒã«ID | ããŒã ID | 説æ |
---|---|---|
10 | 0 | C2ããPowerShellã¹ã¯ãªãããåãåããå®è¡ããŸã |
CDeviceMonitorã¢ãžã¥ãŒã«
æ¥ç¶ãããã¡ãã£ã¢ããã€ã¹ãç£èŠããããããããã¡ã€ã«ãã³ããŒããããã·ãã¢ãžã¥ãŒã«ã WM_DEVICECHANGEãããŒããã£ã¹ãã¡ãã»ãŒãžã䜿çšããŠãããã€ã¹ã®æ¥ç¶ãæ€åºããŸãã ããã€ã¹ãå¶åŸ¡ãµãŒããŒã«æ¥ç¶ãããšãããã€ã¹ããã€æ¥ç¶ããããããã®ããªã¥ãŒã ã©ãã«ãããã³ããã€ã¹ãžã®ãã¹ã«é¢ããæ å ±ãéä¿¡ãããŸãã ããã€ã¹ãžã®ãã¹ãååŸããããã«äœ¿çšãããã³ãŒãã¯ããã«éåžžã«äŒŒãŠããŸãã ãã¹ãŠã®ãã¡ã€ã«ããã°ãã©ã«ããŒã«ã³ããŒãããŸãã ã¹ã¯ãªãŒã³ã·ã§ããã®å Žåãšåãæ¹æ³ã§ååãçæãããŸãã ãã¡ã€ã«fsIndex.datãåå¥ã«äœæãããããã«boost ::ã¢ãŒã«ã€ãã§ã·ãªã¢ã«åãããèŸæžããããŸãã ãã®èŸæžã«ã¯ãã³ããŒããããã¡ã€ã«ãžã®å ã®ãã¹ãšãã®MD5ããã·ã¥ãæ ŒçŽãããŸãã 以äžã¯ãDevicePathã®åä¿¡ã§ãã
ãšãããŒã°ãšããŠãããã€ãã®æšå¥šäºé ïŒ
- äžæãªåä¿¡è ããã®ã¬ã¿ãŒã®æ·»ä»ãã¡ã€ã«ãéãå¿ èŠã¯ãããŸãããMicrosoftPublisherã¹ã¯ãªããã¯ã»ãšãã©å«ãŸããŠããŸããã
- æªç¥ã®éä¿¡è ã®æçŽã«ãããªã³ã¯ãã¯ãªãã¯ããããšãåæ§ã«å±éºã§ãã 移åå ã®ãµã€ãã¯ãPCã«èªåçã«ããŠã³ããŒãããããã«ãŠã§ã¢ããã¹ãã§ããŸãã
- ãœãããŠã§ã¢ãç¹ã«Microsoft WindowsãšMicrosoft Officeãå®æçã«æŽæ°ããå¿ èŠããããŸãããããã®ãœãããŠã§ã¢ã¯ãããŸããŸãªãã«ãŠã§ã¢ãžã®ã¢ã¯ã»ã¹ãéããŸãã