ãã®æçš¿ã§ã¯ããµã€ã㌠ã°ã«ãŒã OceanLotus (APT32 ããã³ APT-C-00) ãæè¿ãå
¬éãããŠãããšã¯ã¹ããã€ãã® XNUMX ã€ãã©ã®ããã«äœ¿çšãããã説æããŸãã
OceanLotus ã¯ãµã€ããŒã¹ãã€æŽ»åãå°éãšããåªå ã¿ãŒã²ããã¯æ±åã¢ãžã¢è«žåœã§ãã æ»æè ã¯ãæœåšçãªè¢«å®³è ã®æ³šæãåŒãã€ããŠããã¯ãã¢ãå®è¡ãããã説åŸããææžãåœé ããããŒã«ã®éçºã«ãåãçµãã§ããŸãã ãããŒãããã®äœæã«äœ¿çšãããææ³ã¯ããäºéæ¡åŒµåããã¡ã€ã«ãèªå·±è§£åã¢ãŒã«ã€ãããã¯ããå«ãããã¥ã¡ã³ãããæ¢ç¥ã®ãšã¯ã¹ããã€ããŸã§ãæ»æã«ãã£ãŠç°ãªããŸãã
Microsoft æ°åŒãšãã£ã¿ãŒã§ãšã¯ã¹ããã€ãã䜿çšãã
2018 幎åã°ãOceanLotus 㯠CVE-2017-11882 ã®è匱æ§ãæªçšãããã£ã³ããŒã³ãå®æœããŸããã ãµã€ã㌠ã°ã«ãŒãã®æªæã®ããææžã® 360 ã€ããXNUMX è
åšã€ã³ããªãžã§ã³ã¹ ã»ã³ã¿ãŒã®å°é家ã«ãã£ãŠåæãããŸãã (
第1ã¹ããŒãž
ããã¥ã¡ã³ã FW Report on demonstration of former CNRP in Republic of Korea.doc
ïŒSHA-1ïŒ D1357B284C951470066AAA7A8228190B88A5C7C3
) ã¯äžèšã®ç 究ã§è¿°ã¹ããã®ãšåæ§ã§ãã ã«ã³ããžã¢æ¿æ²»ïŒCNRP - ã«ã³ããžã¢æåœå
ã2017幎æ«ã«è§£æ£ïŒã«èå³ã®ãããŠãŒã¶ãŒã察象ãšããŠããã®ã§èå³æ·±ãã .doc æ¡åŒµåã«ãããããããããã¥ã¡ã³ã㯠RTF åœ¢åŒ (äžã®å³ãåç
§) ã§ãã¬ããŒãž ã³ãŒããå«ãŸããŠããããŸãæªãã§ããŸãã
å³ 1. RTF ã®ãã¬ããŒãžã
æååãããèŠçŽ ããã£ãŠããWord ã¯ãã® RTF ãã¡ã€ã«ãæ£åžžã«éããŸãã å³ 2 ãããããããã«ããªãã»ãã 0xC00 ã« EQNOLEFILEHDR æ§é ãããããã®åŸã« MTEF ããããŒããããŠãã©ã³ãã® MTEF ãšã³ã㪠(å³ 3) ãç¶ããŸãã
å³ 2. FONT ãšã³ããªã®å€
å³3ã
ãã£ãŒã«ãã§ã®ãªãŒããŒãããŒã®å¯èœæ§ åã³ããŒããåã«ãµã€ãºããã§ãã¯ãããªãããã§ãã é·ãããååã¯è匱æ§ãåŒãèµ·ãããŸãã RTF ãã¡ã€ã«ã®å
容 (å³ 0 ã®ãªãã»ãã 26xC2) ãããããããã«ããããã¡ãŒã«ã¯ã·ã§ã«ã³ãŒããšããã«ç¶ããã㌠ã³ãã³ã (0x90
ïŒããã³è¿éå
äœæ 0x402114
ã ã¢ãã¬ã¹ã¯ãã€ã¢ãã°èŠçŽ ã§ãã EQNEDT32.exe
ãæ瀺ã瀺ããŸã RET
ã ããã«ãããEIP ã¯ãã£ãŒã«ãã®å
é ãæãããã«ãªããŸãã åã·ã§ã«ã³ãŒããå«ãŸããŠããŸãã
å³ 4. ãšã¯ã¹ããã€ã ã·ã§ã«ã³ãŒãã®å§ãŸã
ã¢ãã¬ã¹ 0x45BD3C
çŸåšããŒããããŠããæ§é äœãžã®ãã€ã³ã¿ãŒã«å°éãããŸã§éåç
§ãããå€æ°ãæ ŒçŽããŸãã MTEFData
ã æ®ãã®ã·ã§ã«ã³ãŒãã¯ããã«ãããŸãã
ã·ã§ã«ã³ãŒãã®ç®çã¯ãéããŠããããã¥ã¡ã³ãã«åã蟌ãŸããŠããã·ã§ã«ã³ãŒãã® XNUMX çªç®ã®éšåãå®è¡ããããšã§ãã å
ã®ã·ã§ã«ã³ãŒãã¯ãæåã«ãã¹ãŠã®ã·ã¹ãã èšè¿°åãå埩åŠçããŠãéããŠããããã¥ã¡ã³ãã®ãã¡ã€ã«èšè¿°åãèŠã€ããããšããŸã (NtQuerySystemInformation
åŒæ°ä»ã SystemExtendedHandleInformation
) äžèŽãããã©ããã確èªããŸã PID èšè¿°åãš PID ããã»ã¹ WinWord
ããã¥ã¡ã³ããã¢ã¯ã»ã¹ãã¹ã¯ã§éããããã©ãã - 0x12019F
.
æ£ãããã³ãã«ãèŠã€ãã£ãããš (éããŠããå¥ã®ããã¥ã¡ã³ããžã®ãã³ãã«ã§ã¯ãªãããš) ã確èªããããã«ãé¢æ°ã䜿çšããŠãã¡ã€ã«ã®å
容ã衚瀺ãããŸãã CreateFileMapping
ãã·ã§ã«ã³ãŒãã¯ããã¥ã¡ã³ãã®æåŸã® XNUMX ãã€ããäžèŽãããã©ããããã§ãã¯ããŸããyyyy
ãïŒãšãã°ãã³ãã£ã³ã°æ³ïŒã äžèŽãããã®ãèŠã€ãããšãããã¥ã¡ã³ãã¯äžæãã©ã«ã㌠(GetTempPath
ïŒ ã©ããã£ãŠ ole.dll
ã 次ã«ãããã¥ã¡ã³ãã®æåŸã® 12 ãã€ããèªã¿åãããŸãã
å³ 5. ææžã®çµããã®ããŒã«ãŒ
ããŒã«ãŒéã® 32 ãããå€ AABBCCDD
О yyyy
次ã®ã·ã§ã«ã³ãŒãã®ãªãã»ããã§ãã é¢æ°ã䜿çšããŠåŒã³åºãããŸã CreateThread
ã 以åã« OceanLotus ã°ã«ãŒãã«ãã£ãŠäœ¿çšãããŠãããã®ãšåãã·ã§ã«ã³ãŒããæœåºããŸããã
第2æ
ã³ã³ããŒãã³ãã®åé€
ãã¡ã€ã«åãšãã£ã¬ã¯ããªåã¯åçã«éžæãããŸãã ã³ãŒãã¯ãå®è¡å¯èœãã¡ã€ã«ãŸã㯠DLL ãã¡ã€ã«ã®ååãã©ã³ãã ã«éžæããŸãã C:Windowssystem32
ã 次ã«ããã®ãªãœãŒã¹ã«ãªã¯ãšã¹ããéä¿¡ãããã£ãŒã«ããååŸããŸãã FileDescription
ãã©ã«ããŒåãšããŠäœ¿çšããŸãã ãããæ©èœããªãå Žåãã³ãŒãã¯ãã£ã¬ã¯ããªãããã©ã«ããŒåãã©ã³ãã ã«éžæããŸãã %ProgramFiles%
ãŸã㯠C:Windows
(GetWindowsDirectoryW ãã)ã æ¢åã®ãã¡ã€ã«ãšç«¶åããå¯èœæ§ã®ããååã®äœ¿çšãåé¿ãã次ã®åèªãå«ãŸããªãããã«ããŸãã windows
, Microsoft
, desktop
, system
, system32
ãŸã㯠syswow64
ã ãã£ã¬ã¯ããªããã§ã«ååšããå Žåã¯ãååã«ãNLS_{6 æå}ããè¿œå ãããŸãã
ãªãœãŒã¹ 0x102
ãåæããããã¡ã€ã«ããã³ããããŸã %ProgramFiles%
ãŸã㯠%AppData%
ãã©ã³ãã ã«éžæããããã©ã«ããŒã«ä¿åãããŸãã äœææéãåãå€ã«ãªãããã«å€æŽããŸããã kernel32.dll
.
ããšãã°ãå®è¡å¯èœãã¡ã€ã«ãéžæããŠäœæããããã©ã«ããŒãšãã¡ã€ã«ã®ãªã¹ãã¯æ¬¡ã®ãšããã§ãã C:Windowssystem32TCPSVCS.exe
ããŒã¿ãœãŒã¹ãšããŠã
å³ 6. ããŸããŸãªã³ã³ããŒãã³ãã®æœåº
ãªãœãŒã¹æ§é 0x102
ã¹ãã€ãã®å Žåã¯éåžžã«è€éã§ãã äžèšã§èšãã°ã次ã®ãã®ãå«ãŸããŸãã
â ãã¡ã€ã«å
â ãã¡ã€ã«ãµã€ãºãšå
容
â å§çž®åœ¢åŒ (COMPRESSION_FORMAT_LZNT1
ãé¢æ°ã«ãã£ãŠäœ¿çšãããŸã RtlDecompressBuffer
)
æåã®ãã¡ã€ã«ã¯æ¬¡ã®ããã«ãªã»ãããããŸã TCPSVCS.exe
ãããã¯åæ³ã§ã AcroTranscoder.exe
ïŒã«ãããš FileDescription
ãSHA-1: 2896738693A8F36CC7AD83EF1FA46F82F32BE5A3
).
äžéšã® DLL ãã¡ã€ã«ã¯ 11 MB ãè¶ ããŠããããšã«æ°ã¥ãããããããŸããã ããã¯ãã©ã³ãã ããŒã¿ã®å€§ããªé£ç¶ãããã¡ãå®è¡å¯èœãã¡ã€ã«å ã«é 眮ãããããã§ãã ããã¯ãäžéšã®ã»ãã¥ãªãã£è£œåã«ããæ€åºãåé¿ããæ¹æ³ã§ããå¯èœæ§ããããŸãã
æ°žç¶æ§ã®ç¢ºä¿
ãªãœãŒã¹ 0x101
ãããããŒã«ã¯ãæ°žç¶æ§ãæäŸããæ¹æ³ãæå®ãã 32 ã€ã® XNUMX ãããæŽæ°ãå«ãŸããŠããŸãã æåã®å€ã¯ããã«ãŠã§ã¢ã管çè
æš©éãªãã§ã©ã®ããã«åç¶ããããæå®ããŸãã
è¡š 1. 管çè
æš©éã®ãªãæ°žç¶åã¡ã«ããºã
XNUMX çªç®ã®æŽæ°ã®å€ã¯ã管çè æš©éã§å®è¡ãããšãã«ãã«ãŠã§ã¢ãæç¶æ§ãéæããæ¹æ³ãæå®ããŸãã
è¡š 2. 管çè
æš©éãæã€æ°žç¶åã¡ã«ããºã
ãµãŒãã¹åã¯æ¡åŒµåã®ãªããã¡ã€ã«åã§ãã 衚瀺åã¯ãã©ã«ããŒã®ååã§ããããã©ã«ããŒããã§ã«ååšããå Žåã¯ãæååãããè¿œå ãããŸããRevision 1
â (æªäœ¿çšã®ååãèŠã€ãããŸã§çªå·ãå¢å ããŸã)ã ãªãã¬ãŒã¿ãŒã¯ããµãŒãã¹ã®æ°žç¶æ§ãå
ç¢ã§ããããšã確èªããŸãããé害ãçºçããå Žåã¯ããµãŒãã¹ã¯ 1 ç§åŸã«åèµ·åãããå¿
èŠããããŸãã 次ã«ãå€ WOW64
æ°ãããµãŒãã¹ã®ã¬ãžã¹ã㪠ããŒã¯ 4 ã«èšå®ãããããã 32 ããã ãµãŒãã¹ã§ããããšã瀺ããŸãã
ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã¯ãããã€ãã® COM ã€ã³ã¿ãŒãã§ã€ã¹ãéããŠäœæãããŸãã ITaskScheduler
, ITask
, ITaskTrigger
, IPersistFile
О ITaskScheduler
ã åºæ¬çã«ããã«ãŠã§ã¢ã¯é ãã¿ã¹ã¯ãäœæããçŸåšã®ãŠãŒã¶ãŒãŸãã¯ç®¡çè
ã®æ
å ±ãšãšãã«ã¢ã«ãŠã³ãæ
å ±ãèšå®ããããªã¬ãŒãèšå®ããŸãã
ããã¯æ¯æ¥ã®ã¿ã¹ã¯ã§ãæé㯠24 æéã10 åã®å®è¡éé㯠XNUMX åã§ããã€ãŸããç¶ç¶çã«å®è¡ãããŸãã
æªæã®ããããã
ãã®äŸã§ã¯ãå®è¡å¯èœãã¡ã€ã« TCPSVCS.exe
(AcroTranscoder.exe
) ã¯ãäžç·ã«ãªã»ããããã DLL ãããŒãããæ£èŠã®ãœãããŠã§ã¢ã§ãã ãã®å Žåãèå³æ·±ãã®ã¯ã Flash Video Extension.dll
.
ãã®æ©èœ DLLMain
å¥ã®é¢æ°ãåŒã³åºãã ãã§ãã ããã€ãã®ãããŸããªè¿°èªãååšããŸãã
å³ 7. ãã¡ãžãŒè¿°èª
ãããã®èª€è§£ãæããã§ãã¯ã®åŸãã³ãŒãã«ã¯ã»ã¯ã·ã§ã³ãè¿œå ãããŸãã .text
ãã¡ã€ã« TCPSVCS.exe
ãé²åŸ¡åã次ã®ããã«å€æŽããŸãã PAGE_EXECUTE_READWRITE
ãããŒåœä»€ãè¿œå ããŠæžãæããŸãã
å³ 8. åœä»€ã®ã·ãŒã±ã³ã¹
æåŸã«é¢æ°ã¢ãã¬ã¹ãž FLVCore::Uninitialize(void)
ã茞åºããã Flash Video Extension.dll
ãæ瀺ãè¿œå ãããŸã CALL
ã ããã¯ãæªæã®ãã DLL ãããŒããããåŸãã©ã³ã¿ã€ã ãåŒã³åºãããšãã« WinMain
в TCPSVCS.exe
ãåœä»€ãã€ã³ã¿ã NOP ãæãããšã«ãªãã FLVCore::Uninitialize(void)
ã 次ã®ã¹ããŒãžã
ãã®é¢æ°ã¯åçŽã«æ¬¡ã§å§ãŸããã¥ãŒããã¯ã¹ãäœæããŸãã {181C8480-A975-411C-AB0A-630DB8B0A221}
ãã®åŸã«çŸåšã®ãŠãŒã¶ãŒåãç¶ããŸãã 次ã«ãäœçœ®ã«äŸåããªãã³ãŒããå«ããã³ãããã *.db3 ãã¡ã€ã«ãèªã¿åãã CreateThread
ã³ã³ãã³ããå®è¡ããŸãã
*.db3 ãã¡ã€ã«ã®å
容ã¯ãOceanLotus ã°ã«ãŒããé垞䜿çšããã·ã§ã«ã³ãŒãã§ãã å
¬éãããšãã¥ã¬ãŒã¿ ã¹ã¯ãªããã䜿çšããŠããã€ããŒããåã³æ£åžžã«è§£åããŸããã
ã¹ã¯ãªããã¯æçµæ®µéãæœåºããŸãã ãã®ã³ã³ããŒãã³ãã¯ããã¯ãã¢ã§ããããã§ã«åæããŸããã {A96B020F-0000-466F-A96D-A91BBF8EAC96}
ãã€ããªãŒãã¡ã€ã«ã ãã«ãŠã§ã¢æ§æ㯠PE ãªãœãŒã¹å
ã§åŒãç¶ãæå·åãããŸãã æ§æã¯ã»ãŒåãã§ãããC&C ãµãŒããŒã¯ä»¥åã®ãã®ãšã¯ç°ãªããŸãã
- andreagahuvrauvin[.]com
- byronorenstein[.]com
- stienollmache[.]xyz
OceanLotus ããŒã ã¯ãæ€åºãåé¿ããããã®ããŸããŸãªãã¯ããã¯ã®çµã¿åãããå床ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ããŸãã 圌ãã¯ãææããã»ã¹ã®ãæŽç·Žããããå³ãæºããŠæ»ã£ãŠããŸããã ã©ã³ãã ãªååãéžæããå®è¡å¯èœãã¡ã€ã«ã«ã©ã³ãã ãªããŒã¿ãåã蟌ãããšã§ã(ããã·ã¥ãšãã¡ã€ã«åã«åºã¥ã) ä¿¡é Œã§ãã IoC ã®æ°ãæžããŸãã ããã«ããµãŒãããŒãã£ã® DLL ããŒãã䜿çšããŠãããããæ»æè
ã¯æ£èŠã®ãã€ããªãåé€ããã ãã§æžã¿ãŸãã AcroTranscoder
.
èªå·±è§£åã¢ãŒã«ã€ã
RTF ãã¡ã€ã«ã®åŸãã°ã«ãŒãã¯ãŠãŒã¶ãŒãããã«æ··ä¹±ãããããã«ãäžè¬çãªããã¥ã¡ã³ã ã¢ã€ã³ã³ãåããèªå·±è§£å (SFX) ã¢ãŒã«ã€ãã«ç§»è¡ããŸããã Threatbook ã¯ããã«ã€ããŠæžããŠããŸã ({A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
ã 2019 幎 XNUMX æäžæ¬ä»¥æ¥ãOceanLotus ã¯ãã®æè¡ãåå©çšããŠããŸãããæéã®çµéãšãšãã«äžéšã®æ§æãå€æŽããŠããŸãã ãã®ã»ã¯ã·ã§ã³ã§ã¯ããã®ãã¯ããã¯ãšå€æŽç¹ã«ã€ããŠèª¬æããŸãã
ã«ã¢ãŒã®äœæ
ããã¥ã¡ã³ã THICH-THONG-LAC-HANH-THAP-THIEN-VIET-NAM (1).EXE
ïŒSHA-1ïŒ AC10F5B1D5ECAB22B7B418D6E98FA18E32BBDEAB
ïŒã¯2018幎ã«åããŠçºèŠãããŸããã ãã® SFX ãã¡ã€ã«ã¯è³¢æã«äœæãããŸãã - 説æ (ããŒãžã§ã³æ
å ±) ãã㯠JPEG ç»åã§ãããšè¡šç€ºãããŸãã SFX ã¹ã¯ãªããã¯æ¬¡ã®ããã«ãªããŸãã
å³ 9. SFX ã³ãã³ã
ãã«ãŠã§ã¢ããªã»ããããã {9ec60ada-a200-4159-b310-8071892ed0c3}.ocx
ïŒSHA-1ïŒ EFAC23B0E6395B1178BCF7086F72344B24C04DCC
ïŒãåçã ãã§ãªã 2018 thich thong lac.jpg.
ããšãç»åã¯æ¬¡ã®ããã«ãªããŸãã
å³ 10. ããšãç»å
SFX ã¹ã¯ãªããã®æåã® XNUMX è¡ã§ OCX ãã¡ã€ã«ã XNUMX ååŒã³åºããŠããããšã«æ°ã¥ãããããããŸããããããã¯ãšã©ãŒã§ã¯ãããŸããã
{9ec60ada-a200-4159-b310-8071892ed0c3}.ocx (ShLd.dll)
OCX ãã¡ã€ã«ã®å¶åŸ¡ãããŒã¯ãä»ã® OceanLotus ã³ã³ããŒãã³ããšéåžžã«äŒŒãŠãããå€ãã®ã³ãã³ã ã·ãŒã±ã³ã¹ã䜿çšãããŸãã JZ/JNZ
О PUSH/RET
ãã¬ããŒãžã³ãŒããšäº€äºã«ãªããŸãã
å³ 11. é£èªåãããã³ãŒã
ãžã£ã³ã¯ã³ãŒããé€å€ããåŸããšã¯ã¹ããŒãããŸã DllRegisterServer
ããšåŒã°ãã regsvr32.exe
ãã®ããã«ãªããŸãïŒ
å³ 12. åºæ¬çãªã€ã³ã¹ããŒã©ãŒ ã³ãŒã
åºæ¬çã«ã¯æåã®é»è©±ã§ DllRegisterServer
ãšã¯ã¹ããŒãã»ããã®ã¬ãžã¹ããªå€ HKCUSOFTWAREClassesCLSID{E08A0F4B-1F65-4D4D-9A09-BD4625B9C5A1}Model
DLL å
ã®æå·åããããªãã»ããã®å Žå (0x10001DE0
).
é¢æ°ã XNUMX åç®ã«åŒã³åºããããšããåãå€ãèªã¿åããããã®ã¢ãã¬ã¹ã§å®è¡ãããŸãã ãããããRAM å ã®ãªãœãŒã¹ãšå€ãã®ã¢ã¯ã·ã§ã³ãèªã¿åãããŠå®è¡ãããŸãã
ã·ã§ã«ã³ãŒãã¯ãéå»ã® OceanLotus ãã£ã³ããŒã³ã§äœ¿çšããããã®ãšåã PE ããŒããŒã§ãã ã䜿çšããŠãšãã¥ã¬ãŒãã§ããŸã db293b825dcc419ba7dc2c49fa2757ee.dll
ããããã¡ã¢ãªã«ããŒãããŠå®è¡ããŸã DllEntry
.
DLL ã¯ãªãœãŒã¹ã®å 容ãæœåºãã埩å·å (AES-256-CBC) ããŠå§çž®è§£é€ (LZMA) ããŸãã ãªãœãŒã¹ã«ã¯ãéã³ã³ãã€ã«ããããç¹å®ã®åœ¢åŒããããŸãã
å³ 13. ã€ã³ã¹ããŒã©ãŒæ§ææ§é (KaitaiStruct Visualizer)
æ§æã¯æ瀺çã«æå®ãããŸããç¹æš©ã¬ãã«ã«å¿ããŠããã€ã㪠ããŒã¿ãæžã蟌ãŸããŸãã %appdata%IntellogsBackgroundUploadTask.cpl
ãŸã㯠%windir%System32BackgroundUploadTask.cpl
ïŒãŸã㯠SysWOW64
64 ããã ã·ã¹ãã ã®å Žå)ã
次ã®ååã®ã¿ã¹ã¯ãäœæããããšã§ãããã«æ°žç¶æ§ã確ä¿ãããŸãã BackgroundUploadTask[junk].job
ã©ã [junk]
ãã€ãã®ã»ãããè¡šããŸã 0x9D
О 0xA0
.
ã¿ã¹ã¯ã¢ããªã±ãŒã·ã§ã³å %windir%System32control.exe
ããã©ã¡ãŒã¿å€ã¯ããŠã³ããŒãããããã€ã㪠ãã¡ã€ã«ãžã®ãã¹ã§ãã é衚瀺ã®ã¿ã¹ã¯ã¯æ¯æ¥å®è¡ãããŸãã
æ§é çã«ã¯ãCPL ãã¡ã€ã«ã¯å
éšåãæ〠DLL ã§ãã ac8e06de0a6c4483af9837d96504127e.dll
ãé¢æ°ããšã¯ã¹ããŒãããŸã CPlApplet
ã ãã®ãã¡ã€ã«ã¯ãã®å¯äžã®ãªãœãŒã¹ã埩å·åããŸã {A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
次ã«ããã® DLL ãããŒããããã®å¯äžã®ãšã¯ã¹ããŒããåŒã³åºããŸãã DllEntry
.
ããã¯ãã¢èšå®ãã¡ã€ã«
ããã¯ãã¢èšå®ã¯æå·åããããã®ãªãœãŒã¹ã«åã蟌ãŸããŸãã æ§æãã¡ã€ã«ã®æ§é ã¯ãåã®ãã®ãšéåžžã«ãã䌌ãŠããŸãã
å³14. ããã¯ãã¢æ§ææ§é ïŒKaitaiStruct VisualizerïŒ
æ§é ã¯äŒŒãŠããŸããããã£ãŒã«ãå€ã®å€ãã¯ãå³ã«ç€ºãããã®ããæŽæ°ãããŠããŸãã
ãã€ããªé
åã®æåã®èŠçŽ ã«ã¯ DLL (HttpProv.dll
MD5ïŒ 2559738D1BD4A999126F900C7357B759
),
è¿œå ã®ç 究
ãµã³ãã«ãåéããŠãããšãã«ãããã€ãã®ç¹åŸŽã«æ°ã¥ããŸããã å ã»ã©èª¬æããæšæ¬ã¯ 2018 幎 2019 æé ã«åºçŸããåæ§ã®åäœãæè¿ã§ã¯ XNUMX 幎 XNUMX æäžæ¬ãã XNUMX æåæ¬ã«åºçŸããŸããã SFX ã¢ãŒã«ã€ãã¯ææãã¯ãã«ãšããŠäœ¿çšãããæ£èŠã®ããšãããã¥ã¡ã³ããšæªæã®ãã OSX ãã¡ã€ã«ãæäžãããŸããã
OceanLotus ã¯åœã®ã¿ã€ã ã¹ã¿ã³ãã䜿çšããŸãããSFX ãã¡ã€ã«ãš OCX ãã¡ã€ã«ã®ã¿ã€ã ã¹ã¿ã³ãã¯åžžã«åãã§ããããšã«æ°ä»ããŸãã (0x57B0C36A
(08 幎 14 æ 2016 æ¥ @ ååŸ 7 æ 15 å UTC) ããã³ 0x498BE80F
(02 幎 06 æ 2009 æ¥ @ 7:34am UTC) ãããã)ã ããã¯ãããããäœæè
ã«ãåããã³ãã¬ãŒãã䜿çšããããã€ãã®ç¹æ§ãå€æŽããã ãã®ãããçš®ã®ããã¶ã€ããŒããããããšã瀺ããŠããŸãã
2018 幎ã®åãããç§ãã¡ã調æ»ããææžã®äžã«ã¯ãæ»æè ãé¢å¿ãå¯ããŠããåœã瀺ãããŸããŸãªååããããŸãã
â ã«ã³ããžã¢ã¡ãã£ã¢ã®æ°ããé£çµ¡å
æ
å ±(æ°èŠ).xls.exe
â æå»ºéŠ (䞪人ç®å).exe (å±¥æŽæžã®åœã® PDF ããã¥ã¡ã³ã)
â ãã£ãŒãããã¯ã28 幎 29 æ 2018 ïœ XNUMX æ¥ã®ç±³åœã©ãªãŒ.exe
ããã¯ãã¢ãçºèŠãããŠãã {A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
ãããŠæ°äººã®ç 究è
ã«ãããã®åæã®å
¬éã«ããããã«ãŠã§ã¢æ§æããŒã¿ã«ããã€ãã®å€åã芳å¯ãããŸããã
ãŸããäœæè
ã¯ãã«ã㌠DLL ããååãåé€ãå§ããŸãã (DNSprov.dll
ãããŠXNUMXã€ã®ããŒãžã§ã³ HttpProv.dll
ïŒã ãã®åŸããªãã¬ãŒã¿ãŒã¯ XNUMX çªç®ã® DLL (XNUMX çªç®ã®ããŒãžã§ã³) ã®ããã±ãŒãžåãäžæ¢ããŸããã HttpProv.dll
)ãXNUMX ã€ã ãåã蟌ãããšãéžæããŸãã
第 XNUMX ã«ãå€ãã® IoC ãå©çšå¯èœã«ãªãã«ã€ããŠãå€ãã®ããã¯ãã¢æ§æãã£ãŒã«ããå€æŽãããæ€åºãåé¿ããå¯èœæ§ããããŸãã äœæè ã«ãã£ãŠå€æŽãããéèŠãªãã£ãŒã«ãã«ã¯æ¬¡ã®ãã®ããããŸãã
- AppX ã¬ãžã¹ã㪠ããŒãå€æŽãããŸãã (IoC ãåç §)
- ãã¥ãŒããã¯ã¹ãšã³ã³ãŒãã£ã³ã°æåå ("def"ã"abc"ã"ghi")
- ããŒãçªå·
æåŸã«ãåæããããã¹ãŠã®æ°ããããŒãžã§ã³ã«ã¯ãIoC ã»ã¯ã·ã§ã³ã«æ°ãã C&C ããªã¹ããããŠããŸãã
æèŠ
OceanLotus ã¯éçºãç¶ããŠããŸãã ãã®ãµã€ã㌠ã°ã«ãŒãã¯ãããŒã«ãšãã³ã€ã®æ¹è¯ãšæ¡åŒµã«éç¹ã眮ããŠããŸãã äœæè ã¯ã察象ãšãªã被害è ã«é¢é£ãããããã¯ãå«ã泚ç®ãéããææžã䜿çšããŠãæªæã®ãããã€ããŒããåœè£ ããŸãã 圌ãã¯æ°ããã¹ããŒã ãéçºããæ°åŒãšãã£ã¿ãŒã®ãšã¯ã¹ããã€ããªã©ã®å ¬çã«å ¥æå¯èœãªããŒã«ã䜿çšããŸãã ããã«ã被害è ã®ãã·ã³ã«æ®ãã¢ãŒãã£ãã¡ã¯ãã®æ°ãæžããããã®ããŒã«ãæ¹è¯ããããã«ãã£ãŠãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã«ããæ€åºã®å¯èœæ§ãæžãããŠããŸãã
äŸµå ¥ã®çè·¡
䟵害ã®ææšãš MITRE ATT&CK å±æ§ãå©çšå¯èœ
åºæïŒ habr.com