ืืืืจืื ื ืืฆืจื ืืืจืืคืื ืฉื ืฆืืื ืืชืงื ื ืืฉืืื ืืฆืจ ืงืฉืจ ืขื Group-IB - ืขืืืื ืงืืื ืืืืืจ ืืืชื ืืฉืื ืขื ืงืืืฅ ืืฆืืจืฃ ืืืื ื. ืืืืื ืคืืืจื ืฆื, ืืืืื ืื ืืชืื ืชืืื ืืช ืืืื ืืืช ื-CERT Group-IB, ืืืฆืข ื ืืชืื ืืคืืจื ืฉื ืืงืืืฅ ืืื, ืืืื ืฉื ืืช ืชืืื ืช ืืจืืืื ืฉื AgentTesla ืืกืืคืจ ืืื ืืฆืคืืช ืืชืืื ืืช ืืืื ืืืช ืืืื ืืืืฆื ืืื ืืกืืื ืช.
ืขื ืืคืืกื ืืื ืื ืื ื ืคืืชืืื ืกืืจืช ืืืืจืื ืขื ืืื ืื ืชื ืงืืฆืื ืฉืขืืืืื ืืืืืช ืืกืืื ืื ืืืื, ืืื ื ืืืืื ืืกืงืจื ืื ืืืืชืจ ื-5 ืืืฆืืืจ ืืกืืื ืจ ืืื ืืจื ื ืืื ืืจืืงืืืื ืืืื ื ืื ืืฉื "ื ืืชืื ืชืืื ืืช ืืืื ืืืช: ื ืืชืื ืืงืจืื ืืืืชืืื". ืื ืืคืจืืื ื ืืฆืืื ืชืืช ืืชื.
ืื ืื ืื ืืคืฆื
ืื ื ืืืืขืื ืฉืืชืืื ื ืืืืื ืืช ืืืืขื ืืืืฉื ืฉื ืืงืืจืื ืืืืฆืขืืช ืืืืขืืช ืืืื. ืื ืืขื ืฉื ืืืืชื ืืื ืื ืจืื ืืืกืชืจ.
ืื ืืชืื ืืืืชืจืืช ืขืืื ืฉืฉืืื ืืืืชื ืืืืฃ. ืืืขืฉื, ืืืืชื ื ืฉืืจ ืขื vps56[.]oneworldhosting[.]com.
ืงืืืฅ ืืืืืืื ืืืฆืืจืฃ ืืืื ืืจืืืื WinRar qoute_jpeg56a.r15 ืขื ืงืืืฅ ืืคืขืื ืืืื ื QOUTE_JPEG56A.exe ืึผึฐืชืึนื.
ืืขืจืืช ืืงืืืืืืช ืฉื ืชืืื ืืช ืืืื ืืืช
ืขืืฉืื ืืืื ื ืจืื ืืื ื ืจืืืช ืืืขืจืืช ืืืงืืืืืืช ืฉื ืืชืืื ื ืืืืื ืืช ืื ืืงืจืช. ืืชืจืฉืื ืฉืืืื ืืฆืื ืืช ืืืื ื ืฉืื ืืืช ืืืืื ื ืืืื ืืจืืงืฆืื ืฉื ืืจืืืืื.
ืืขืช ืืืื ื ืกืชืื ืขื ืื ืืื ืืืจืืืื ืืชืืื ื ืืืืื ืืช ืืืชืจ ืคืืจืื.
ืืืขืื
ืงืืืฅ ืืงืืจื QOUTE_JPEG56A.exe ืืื ืืืืืจ AutoIt v3 ืชึทืกืจึดืื.
ืืื ืืืฉืืฉ ืืช ืืชืกืจืื ืืืงืืจื, ืขืจืคื ืขื ืืืื PELock AutoIT-Obfuscator ืืืคืืื ืื.
ืืกืจืช ืืขืจืคืื ืืชืืฆืขืช ืืฉืืืฉื ืฉืืืื:
- ืืกืจืช ืขืจืคืื ืืฉืืื ืื
ืืฆืขื ืืจืืฉืื ืืื ืฉืืืืจ ืืจืืืช ืืืงืจื ืฉื ืืกืงืจืืคื. ืฉืืืื ืืจืืืช ืืงืจื ืืื ืืืช ืืืจืืื ืื ืคืืฆืืช ืืืืชืจ ืืืื ืขื ืงืื ืืื ืืจื ืฉื ืืืฉืืืื ืืคื ื ื ืืชืื. ืืจื ืกืคืืจืืฆืืืช ืืืืืืืช ืืืืืืืช ืืืืคื ืืจืืื ืืช ืืืืจืืืืช ืฉื ืืืืืฅ ืืืืืื ืืืืืจืืชืืื ืืืื ื ื ืชืื ืื.
- ืฉืืืืจ ืฉืืจืืช
ืฉืชื ืคืื ืงืฆืืืช ืืฉืืฉืืช ืืืฆืคื ืช ืืืจืืืืช:
- gdorizabegkvfca - ืืืฆืข ืคืขื ืื ืืืื Base64
- xgacyukcyzxz - XOR ืืืื-ืืืื ืคืฉืื ืฉื ืืืืจืืืช ืืจืืฉืื ื ืืืืจื ืืฉื ืืื
- ืืกืจืช ืขืจืคืื BinaryToString ะธ ืืืฆืข
ืืขืืืก ืืขืืงืจื ืืืืืกื ืืฆืืจื ืืืืืงืช ืืกืคืจืืื ืืืคื ืื ืืืงื ืืฉืืืื ืฉื ืืงืืืฅ.
ืกืืจ ืืืืืงื ืืื ืืืืงืื: TIEQHCXWFG, IME, SPDGUHIMPV, KQJMWQQAQTKTFXTUOSW, AOCHKRWWSKWO, JSHMSJPS, NHHWXJBMTTSPXVN, BFUTIFWWXVE, HWJHO, AVZOUMVFRDWFLWU.
ืืคืื ืงืฆืื WinAPI ืืฉืืฉืช ืืคืขื ืื ืื ืชืื ืื ืฉืืืืฆื CryptDecrypt, ืืืคืชื ืืืคืขืื ืฉื ืืฆืจ ืขื ืกืื ืืขืจื ืืฉืืฉ ืืืคืชื fZgFiZlJDxvuWatFRgRXZqmNCIyQgMYc.
ืงืืืฅ ืืืคืขืื ืืืคืืขื ื ื ืฉืื ืืงืื ืืคืื ืงืฆืื RunPE, ืืฉืจ ืืืฆืขืช ProcessInject ะฒ RegAsm.exe ืืืืฆืขืืช ืืืื ื ShellCode (ืืืืข ืื ื RunPE ShellCode). ืืืืืจ ืฉืืื ืืืฉืชืืฉ ืืคืืจืื ืืกืคืจืื ืืืชื ื ืืชื ืืืืืื[.]ื ืื ืชืืช ืืืื ืื Wardow.
ืจืืื ืื ืืฆืืื ืฉืืืื ืืฉืจืฉืืจืื ืฉื ืืคืืจืื ืืื, ืืขืจืคื ืขืืืจ ืืืืืืืืช ืขื ืืืคืืื ืื ืืืืื ืฉืืืื ืืืืื ื ืืชืื ืืืืื.
ืืช ืขืฆืื ShellCode ืื ืคืฉืื ืืืืฉื ืชืฉืืืช ืื ืจืง ืืืฉืืื ืืงืืืฆืช ืืืืงืจืื AnunakCarbanak. ืคืื ืงืฆืืืช ืืืืื ืฉื ืงืจืืืช API.
ืื ื ืืืืขืื ืื ืืืงืจื ืฉืืืืฉ Frenchy Shellcode ืืจืกืืืช ืฉืื ืืช.
ืื ืืกืฃ ืืคืื ืงืฆืืื ืืืืช ืืืชืืืจืช, ืืืืื ื ืื ืคืื ืงืฆืืืช ืื ืคืขืืืืช:
- ืืกืืืช ืกืืื ืชืืืื ืืื ื ืืื ืื ืืืฉืืืืช
- ืืคืขืื ืืืืฉ ืฉื ืชืืืื ืฆืืฆื ืืืฉืจ ืืื ืืกืชืืื
- ืขืืงืฃ ืืช UAC
- ืฉืืืจืช ืืืืขื ืืงืืืฅ
- ืืืืื ืฉื ืืืื ืืช ืืืืืืืื
- ืืืชืื ืืฉืื ืื ืืืงืื ืกืื ืืขืืืจ
- AntiVM ื-AntiSandbox
- ืืจืก ืขืฆืื
- ืฉืืืืช ืืืขื ืืืจืฉืช
ืื ื ืืืืขืื ืฉืคืื ืงืฆืืื ืืืืช ืืื ืืืคืืื ืืช ืืืื CypherIT, ืฉืืื, ืืื ืื ืจืื, ืืืขื ืืืชืืื ืืืืืืจ.
ืืืืื ืจืืฉื ืฉื ืชืืื ื
ืืืืจ ืืื, ื ืชืืจ ืืงืฆืจื ืืช ืืืืืื ืืจืืฉื ืฉื ืืชืืื ื ืืืืื ืืช, ืื ืฉืงืื ืืืชื ืืืชืจ ืคืืจืื ืืืืืจ ืืฉื ื. ืืืงืจื ืื, ืืืืืจ ืืืืฉืื ืขื NET..
ืืืืื ืื ืืชืื, ืืืืื ื ืฉื ืขืฉื ืฉืืืืฉ ืืืขืืจืคื ConfuserEX.
IELibrary.dll
ืืกืคืจืืื ืืืืืกื ืช ืืืฉืื ืืืืื ืจืืฉื ืืืื ืชืืกืฃ ืืืืข ืขืืืจ ืืกืืื ืืกืื, ืืืกืคืง ืคืื ืงืฆืืื ืืืืช ืืืืืืฅ ืืืืข ืฉืื ืื ืืืคืืคื ื Internet Explorer ื-Edge.
ืืกืืื ืืกืื ืืื ืชืืื ืช ืจืืืื ืืืืืืจืืช ืืืืคืฆืช ืืืืฆืขืืช ืืืื ืชืืื ื ืืืื ืืช ืืฉืืจืืช ืืืกืืื ืฉื ืืืฆืจ keylogger ืืืืืืื. ืืกืืื ืืกืื ืืกืืื ืืืืฅ ืืืฉืืจ ืืืฉืืจื ืืฉืชืืฉ ืืืคืืคื ืื, ืืงืืืืช ืืืืจ ืืืงืืจืื ื ืืืืงืืืืช FTP ืืฉืจืช ืืชืืงืคืื, ืืืงืืื ื ืชืื ื ืืื ืืืชืคืืก ืืช ืืกื ืืืืฉืืจ. ืืืื ืื ืืชืื, ืืืชืจ ืืจืฉืื ืฉื ืืืคืชืืื ืื ืืื ืืืื.
ื ืงืืืช ืืื ืืกื ืืื ืืคืื ืงืฆืื GetSavedPasswords ืืืืงื InternetExplorer.
ืืืืคื ืืืื, ืืืฆืืข ืืงืื ืืื ืืื ืืืจื ืืืื ื ืืืื ืืื ื ืืคื ื ื ืืชืื. ืจืง ืืคืื ืงืฆืื ืืื ืืืืืฉืช ืจืืืื ืืชืฉืืืช ืื GetSavedCookies. ืืื ืื ืจืื, ืืคืื ืงืฆืืื ืืืืช ืฉื ืืชืืกืฃ ืืืืชื ืืืืจื ืืืชืจืื, ืื ืืืืจ ืืขืืื ืื ื ืขืฉื.
ืืืืืจ ืืืขื ืืืชืืื ืืืขืจืืช
ืืืื ื ืืื ืืืฆื ืืืขืื ืืืชืืื ืืืืืจ ืืืขืจืืช. ืืืืืื ืื ืืงืจืช ืืื ื ืืืฆืขืช ืขืืืื, ืื ืืืืจืืขืื ืืืืื ืืื ืืชืจืืฉืช ืขื ืคื ืืชืืื ืืช ืืืื:
- ืืชืืงืืื C:UsersPublic ื ืืฆืจ ืกืงืจืืคื Visual Basic
ืืืืื ืืกืงืจืืคื:
- ืืชืืื ืฉื ืงืืืฅ ืืืขื ืืืชืืื ืืจืืคื ืืชื ืจืืง ืื ืฉืืจ ืืชืืงืืื %Temp%<ืฉื ืชืืงืืื ืืืชืืืช ืืืฉืืช><ืฉื ืงืืืฅ>
- ืืคืชื ืืคืขืื ืืืืืืืืช ื ืืฆืจ ืืจืืฉืื ืขืืืจ ืงืืืฅ ืืกืงืจืืคื HKCUSoftwareMicrosoftWindowsCurrentVersionRun<ืฉื ืกืงืจืืคื>
ืื, ืืืชืืกืก ืขื ืชืืฆืืืช ืืืืง ืืจืืฉืื ืฉื ืื ืืชืื, ืืฆืืื ื ืืงืืืข ืืช ืฉืืืช ืืืฉืคืืืช ืฉื ืื ืืจืืืื ืืชืืื ื ืืืืื ืืช ืื ืืงืจืช, ืื ืชื ืืช ืืคืืก ืืืืืงื, ืืื ืืืฉืื ืืืืืืงืืื ืืืชืืืช ืืชืืืืช. ื ืืฉืื ืืช ืื ืืชืื ืฉืื ื ืฉื ืืืืืืงื ืื ืืืืืจ ืืื, ืฉืื ื ืกืชืื ืขื ืืืืืื ืืจืืฉื ืืืชืจ ืคืืจืื ืืกืืื ืืกืื. ืื ืชืคืกืคืกื!
ืืื, ื-5 ืืืฆืืืจ ืื ื ืืืืื ืื ืืช ืื ืืงืืจืืื ืืกืืื ืจ ืืงืืื ืืื ืืจืืงืืืื ืืืื ื ืื ืืฉื "ื ืืชืื ืชืืื ืืช ืืืื ืืืช: ื ืืชืื ืืงืจืื ืืืืชืืื", ืฉืื ืืืืจ ืืืืืจ, ืืืืื CERT-GIB, ืืจืื ืืืื ืืจื ื ืืช ืืฉืื ืืจืืฉืื ืฉื ื ืืชืื ืชืืื ืืช ืืืื ืืืช - ืคืจืืงื ืืฆื ืืืืืืืืช ืฉื ืืืืืืช ืชืื ืฉืืืืฉ ืืืืืื ืฉื ืฉืืืฉื ืืื ื ืืงืจืื ืืืืชืืื ืืืชืจืืื, ืืชืืืื ืืงืืช ืืืง ืื ืืชืื. ืืืืืื ืจ ืืชืืื ืืืืืืื ืฉืืืจ ืืฉ ืืื ื ืืกืืื ืื ืืชืื ืงืืฆืื ืืืื ืืื. ืืืจืฉืื ืืื ืื ืืจืง ืืืืืื ืืืจืืื ื:
ืืืืจืฉื . ืืืื ืื!
ืืขืจื
rule AgentTesla_clean{
meta:
author = "Group-IB"
file = "78566E3FC49C291CB117C3D955FA34B9A9F3EEFEFAE3DE3D0212432EB18D2EAD"
scoring = 5
family = "AgentTesla"
strings:
$string_format_AT = {74 00 79 00 70 00 65 00 3D 00 7B 00 30 00 7D 00 0D 00 0A 00 68 00 77 00 69 00 64 00 3D 00 7B 00 31 00 7D 00 0D 00 0A 00 74 00 69 00 6D 00 65 00 3D 00 7B 00 32 00 7D 00 0D 00 0A 00 70 00 63 00 6E 00 61 00 6D 00 65 00 3D 00 7B 00 33 00 7D 00 0D 00 0A 00 6C 00 6F 00 67 00 64 00 61 00 74 00 61 00 3D 00 7B 00 34 00 7D 00 0D 00 0A 00 73 00 63 00 72 00 65 00 65 00 6E 00 3D 00 7B 00 35 00 7D 00 0D 00 0A 00 69 00 70 00 61 00 64 00 64 00 3D 00 7B 00 36 00 7D 00 0D 00 0A 00 77 00 65 00 62 00 63 00 61 00 6D 00 5F 00 6C 00 69 00 6E 00 6B 00 3D 00 7B 00 37 00 7D 00 0D 00 0A 00 73 00 63 00 72 00 65 00 65 00 6E 00 5F 00 6C 00 69 00 6E 00 6B 00 3D 00 7B 00 38 00 7D 00 0D 00 0A 00 5B 00 70 00 61 00 73 00 73 00 77 00 6F 00 72 00 64 00 73 00 5D 00}
$web_panel_format_string = {63 00 6C 00 69 00 65 00 6E 00 74 00 5B 00 5D 00 3D 00 7B 00 30 00 7D 00 0D 00 0A 00 6C 00 69 00 6E 00 6B 00 5B 00 5D 00 3D 00 7B 00 31 00 7D 00 0D 00 0A 00 75 00 73 00 65 00 72 00 6E 00 61 00 6D 00 65 00 5B 00 5D 00 3D 00 7B 00 32 00 7D 00 0D 00 0A 00 70 00 61 00 73 00 73 00 77 00 6F 00 72 00 64 00 5B 00 5D 00 3D 00 7B 00 33 00 7D 00 00 15 55 00 52 00 4C 00 3A 00 20 00 20 00 20 00 20 00 20 00 20 00 00 15 55 00 73 00 65 00 72 00 6E 00 61 00 6D 00 65 00 3A 00 20 00 00 15 50 00 61 00 73 00 73 00 77 00 6F 00 72 00 64 00 3A 00}
condition:
all of them
}
rule AgentTesla_obfuscated {
meta:
author = "Group-IB"
file = "41DC0D5459F25E2FDCF8797948A7B315D3CB075398D808D1772CACCC726AF6E9"
scoring = 5
family = "AgentTesla"
strings:
$first_names = {61 66 6B 00 61 66 6D 00 61 66 6F 00 61 66 76 00 61 66 79 00 61 66 78 00 61 66 77 00 61 67 6A 00 61 67 6B 00 61 67 6C 00 61 67 70 00 61 67 72 00 61 67 73 00 61 67 75 00}
$second_names = "IELibrary.resources"
condition:
all of them
}
rule AgentTesla_module_for_IE{
meta:
author = "Group-IB"
file = "D55800A825792F55999ABDAD199DFA54F3184417215A298910F2C12CD9CC31EE"
scoring = 5
family = "AgentTesla_module_for_IE"
strings:
$s0 = "ByteArrayToStructure"
$s1 = "CryptAcquireContext"
$s2 = "CryptCreateHash"
$s3 = "CryptDestroyHash"
$s4 = "CryptGetHashParam"
$s5 = "CryptHashData"
$s6 = "CryptReleaseContext"
$s7 = "DecryptIePassword"
$s8 = "DoesURLMatchWithHash"
$s9 = "GetSavedCookies"
$s10 = "GetSavedPasswords"
$s11 = "GetURLHashString"
condition:
all of them
}
rule RunPE_shellcode {
meta:
author = "Group-IB"
file = "37A1961361073BEA6C6EACE6A8601F646C5B6ECD9D625E049AD02075BA996918"
scoring = 5
family = "RunPE_shellcode"
strings:
$malcode = {
C7 [2-5] EE 38 83 0C // mov dword ptr [ebp-0A0h], 0C8338EEh
C7 [2-5] 57 64 E1 01 // mov dword ptr [ebp-9Ch], 1E16457h
C7 [2-5] 18 E4 CA 08 // mov dword ptr [ebp-98h], 8CAE418h
C7 [2-5] E3 CA D8 03 // mov dword ptr [ebp-94h], 3D8CAE3h
C7 [2-5] 99 B0 48 06 // mov dword ptr [ebp-90h], 648B099h
C7 [2-5] 93 BA 94 03 // mov dword ptr [ebp-8Ch], 394BA93h
C7 [2-5] E4 C7 B9 04 // mov dword ptr [ebp-88h], 4B9C7E4h
C7 [2-5] E4 87 B8 04 // mov dword ptr [ebp-84h], 4B887E4h
C7 [2-5] A9 2D D7 01 // mov dword ptr [ebp-80h], 1D72DA9h
C7 [2-5] 05 D1 3D 0B // mov dword ptr [ebp-7Ch], 0B3DD105h
C7 [2-5] 44 27 23 0F // mov dword ptr [ebp-78h], 0F232744h
C7 [2-5] E8 6F 18 0D // mov dword ptr [ebp-74h], 0D186FE8h
}
condition:
$malcode
}
rule AgentTesla_AutoIT_module{
meta:
author = "Group-IB"
file = "49F94293F2EBD8CEFF180EDDD58FA50B30DC0F08C05B5E3BD36FD52668D196AF"
scoring = 5
family = "AgentTesla"
strings:
$packedexeau = {55 ED F5 9F 92 03 04 44 7E 16 6D 1F 8C D7 38 E6 29 E4 C8 CF DA 2C C4 E1 F3 65 48 25 B8 93 9D 66 A4 AD 3C 39 50 00 B9 60 66 19 8D FC 20 0A A0 56 52 8B 9F 15 D7 62 30 0D 5C C3 24 FE F8 FC 39 08 DF 87 2A B2 1C E9 F7 06 A8 53 B2 69 C3 3C D4 5E D4 74 91 6E 9D 9A A0 96 FD DB 1F 5E 09 D7 0F 25 FB 46 4E 74 15 BB AB DB 17 EE E7 64 33 D6 79 02 E4 85 79 14 6B 59 F9 43 3C 81 68 A8 B5 32 BC E6}
condition:
all of them
}
ืืืฉ
ืฉื | qoute_jpeg56a.r15 |
MD5 | 53BE8F9B978062D4411F71010F49209E |
SHA1 | A8C2765B3D655BA23886D663D22BDD8EF6E8E894 |
SHA256 | 2641DAFB452562A0A92631C2849B8B9CE880F0F8F
890E643316E9276156EDC8A |
ืกืึผื | ืืจืืืื WinRAR |
ืืืื | 823014 |
ืฉื | QOUTE_JPEG56A.exe |
MD5 | 329F6769CF21B660D5C3F5048CE30F17 |
SHA1 | 8010CC2AF398F9F951555F7D481CE13DF60BBECF |
SHA256 | 49F94293F2EBD8CEFF180EDDD58FA50B30DC0F08
C05B5E3BD36FD52668D196AF |
ืกืึผื | PE (ืกืงืจืืคื AutoIt ืืืจืื) |
ืืืื | 1327616 |
ืฉื ืืงืืจื | ืื ืืืืข |
ืืืชืืช ืชืืจืื | 15.07.2019 |
ืืื ืงืจ | Microsoft Linker(12.0)[EXE32] |
MD5 | C2743AEDDADACC012EF4A632598C00C0 |
SHA1 | 79B445DE923C92BF378B19D12A309C0E9C5851BF |
SHA256 | 37A1961361073BEA6C6EACE6A8601F646C5B6ECD
9D625E049AD02075BA996918 |
ืกืึผื | ShellCode |
ืืืื | 1474 |
ืืงืืจ: www.habr.com