Kev ua tsis tiav: cia peb nthuav tawm AgentTesla los ntxuav dej. Ntu 1
Tsis ntev los no, ib lub chaw tsim khoom nyob sab Europe ntawm cov khoom siv hluav taws xob tau hu rau Pab Pawg-IB - nws cov neeg ua haujlwm tau txais tsab ntawv tsis txaus ntseeg nrog cov ntaub ntawv tsis zoo hauv kev xa ntawv. Ilya Pomerantsev, tus kws tshaj lij kev tshuaj xyuas malware ntawm CERT Group-IB, tau tshawb xyuas cov ncauj lus kom ntxaws ntawm cov ntaub ntawv no, tshawb pom AgentTesla spyware nyob ntawd thiab qhia seb yuav xav li cas los ntawm cov malware thiab nws txaus ntshai li cas.
Nrog rau cov ntawv tshaj tawm no peb tab tom qhib cov kab lus hais txog yuav ua li cas txheeb xyuas cov ntaub ntawv uas muaj peev xwm txaus ntshai, thiab peb tab tom tos qhov xav paub tshaj plaws rau lub Kaum Ob Hlis 5th rau kev sib tham sib tham pub dawb ntawm lub ncauj lus. βMalware Analysis: Analysis of Real Casesβ. Tag nrho cov ntsiab lus yog nyob rau hauv qhov kev txiav.
Kev faib tawm mechanism
Peb paub tias tus malware mus txog tus neeg raug tsim txom lub tshuab ntawm phishing emails. Tus neeg tau txais tsab ntawv yog tej zaum BCCed.
Kev tshuaj xyuas ntawm cov headers qhia tau hais tias tus xa tsab ntawv tau spoofed. Qhov tseeb, tsab ntawv tshuav nrog vps56[.]oneworldhosting[.]com.
Tam sim no cia saib seb lub ecosystem ntawm malware nyob rau hauv kev kawm zoo li cas. Daim duab hauv qab no qhia txog nws cov qauv thiab cov lus qhia ntawm kev sib cuam tshuam ntawm cov khoom.
Tam sim no cia peb saib txhua yam ntawm malware Cheebtsam hauv kev nthuav dav ntxiv.
Loader
Original file QOUTE_JPEG56A.exe yog sau ua ke AutoIt v3 tsab ntawv.
WinAPI muaj nuj nqi yog siv los decrypt cov ntaub ntawv rho tawm CryptDecrypt, thiab qhov kev sib kho qhov tseem ceeb tsim los ntawm tus nqi yog siv los ua tus yuam sij fZgFiZlJDxvuWatFRgRXZqmNCIyQgMYc.
Lub decrypted executable cov ntaub ntawv raug xa mus rau lub function input RunPE, uas ua ProcessInject Π² RegAsm.exe siv built-in ShellCode (tseem hu ua RunPE ShellCode). Authorship belongs rau tus neeg siv ntawm lub rooj sab laj Spanish indetectables [.]net nyob rau hauv lub npe menyuam yaus Wardow.
Nws tseem tsim nyog sau cia tias nyob rau hauv ib qho ntawm cov xov ntawm lub rooj sab laj no, obfuscator rau Ntawm lub ru tsev nrog cov khoom zoo sib xws tau txheeb xyuas thaum kuaj xyuas.
Nws tus kheej ShellCode yooj yim heev thiab nyiam mloog tsuas yog qiv los ntawm pawg hacker AnunakCarbanak. API hu hashing muaj nuj nqi.
Peb kuj paub txog cov ntaub ntawv siv Frenchy Shellcode txawv versions.
Ntxiv nrog rau qhov piav qhia ua haujlwm, peb kuj tau txheeb xyuas cov haujlwm tsis ua haujlwm:
Peb paub tias kev ua haujlwm zoo li no yog qhov zoo rau tus tiv thaiv CypherIT, uas, thaj, yog tus bootloader nug.
Main module ntawm software
Tom ntej no, peb yuav piav qhia luv luv ntawm lub ntsiab module ntawm malware, thiab xav txog nws kom ntxaws ntxiv hauv tsab xov xwm thib ob. Hauv qhov no, nws yog daim ntawv thov rau .NET.
Thaum lub sij hawm soj ntsuam, peb pom tau hais tias ib tug obfuscator tau siv ConfuserEX.
IELibrary.dll
Lub tsev qiv ntawv yog khaws cia raws li ib qho tseem ceeb module peev txheej thiab yog ib tug paub zoo plugin rau Tus neeg saib xyuasTesla, uas muab kev ua haujlwm rau kev rho tawm ntau cov ntaub ntawv los ntawm Internet Explorer thiab Edge browsers.
Tus neeg saib xyuas Tesla yog ib qho modular spying software faib siv tus qauv malware-as-a-service nyob rau hauv lub guise ntawm ib tug raug cai keylogger khoom. Tus neeg saib xyuas Tesla muaj peev xwm rho tawm thiab xa cov ntaub ntawv pov thawj ntawm cov neeg siv los ntawm browsers, email cov neeg siv khoom thiab FTP cov neeg siv khoom mus rau lub server rau cov neeg tawm tsam, kaw cov ntaub ntawv teev cia, thiab ntes lub vijtsam ntaus ntawv. Thaum lub sijhawm kev tshuaj xyuas, lub vev xaib official ntawm cov neeg tsim khoom tsis muaj.
Lub ntsiab lus nkag yog qhov ua haujlwm GetSavedPasswords chav InternetExplorer.
Feem ntau, kev ua lej code yog linear thiab tsis muaj kev tiv thaiv kev tsom xam. Tsuas yog qhov ua tsis tau tiav yuav tsum tau saib xyuas GetSavedCookies. Thaj, kev ua haujlwm ntawm lub plugin yuav tsum tau nthuav dav, tab sis qhov no yeej tsis ua tiav.
Txuas lub bootloader rau lub system
Cia peb kawm yuav ua li cas lub bootloader txuas nrog lub system. Cov qauv hauv kev kawm tsis cuam tshuam, tab sis hauv cov xwm txheej zoo sib xws nws tshwm sim raws li cov txheej txheem hauv qab no: