ãã®èšäºããããšããã©ããã®ãªããã«ãŠã§ã¢ã«é¢ããäžé£ã®åºçç©ãéå§ããŸãã ãã¡ã€ã«ã¬ã¹ ãããã³ã° ããã°ã©ã ãšãåŒã°ãããã¡ã€ã«ã¬ã¹ ãããã³ã° ããã°ã©ã ã¯ãéåžžãWindows ã·ã¹ãã äžã§ PowerShell ã䜿çšããŠã貎éãªã³ã³ãã³ããæ€çŽ¢ããŠæœåºããã³ãã³ãããµã€ã¬ã³ãã«å®è¡ããŸãã æªæã®ãããã¡ã€ã«ãªãã§ããã«ãŒã®æŽ»åãæ€åºããããšã¯å°é£ãªäœæ¥ã§ãããªããªã... ãŠã€ã«ã¹å¯Ÿçããã®ä»ã®å€ãã®æ€åºã·ã¹ãã ã¯ãã·ã°ããã£åæã«åºã¥ããŠæ©èœããŸãã ãããè¯ããã¥ãŒã¹ã¯ããã®ãããªãœãããŠã§ã¢ãååšãããšããããšã§ãã äŸãã°ã
ç§ãæåã«å¶æªãªããã«ãŒãšããããŒãã«ã€ããŠç 究ãå§ãããšãã
çŽ æŽããã匷å㪠PowerShell
ãããã®ã¢ã€ãã¢ã®ããã€ãã«ã€ããŠã¯ä»¥åã«æžããããšããããŸã
ãµã³ãã«èªäœã«å ããŠããµã€ãã§ã¯ãããã®ããã°ã©ã ãäœãè¡ãããèŠãããšãã§ããŸãã ãã€ããªããåæã¯ãç¬èªã®ãµã³ãããã¯ã¹ã§ãã«ãŠã§ã¢ãå®è¡ããã·ã¹ãã ã³ãŒã«ãå®è¡äžã®ããã»ã¹ããããã¯ãŒã¯ ã¢ã¯ãã£ããã£ãç£èŠããçãããããã¹ãæååãæœåºããŸãã ãã€ããªããã³ãã®ä»ã®å®è¡å¯èœãã¡ã€ã«ã®å Žåãã€ãŸãå®éã®é«ã¬ãã«ã®ã³ãŒããèŠãããšããã§ããªãå Žåããã€ããªããåæã¯ããœãããŠã§ã¢ãæªæã®ãããã®ã§ããããå®è¡æã®ã¢ã¯ãã£ããã£ã«åºã¥ããŠåã«çããããã®ã§ããããå€æããŸãã ãã®åŸããµã³ãã«ã¯ãã§ã«è©äŸ¡ãããŠããŸãã
PowerShell ããã®ä»ã®ãµã³ãã« ã¹ã¯ãªãã (Visual BasicãJavaScript ãªã©) ã®å Žåã¯ãã³ãŒãèªäœã確èªããããšãã§ããŸããã ããšãã°ã次㮠PowerShell ã€ã³ã¹ã¿ã³ã¹ãèŠã€ããŸããã
æ€åºãåé¿ããããã«ãPowerShell ã Base64 ãšã³ã³ãŒãã§å®è¡ããããšãã§ããŸãã Noninteractive ãã©ã¡ãŒã¿ãš Hidden ãã©ã¡ãŒã¿ã®äœ¿çšã«æ³šæããŠãã ããã
é£èªåã«é¢ããç§ã®æçš¿ãèªãã ããšãããæ¹ãªãã-e ãªãã·ã§ã³ãã³ã³ãã³ãã Base64 ã§ãšã³ã³ãŒããããŠããããšãæå®ããŠããããšããåç¥ã§ãããã ã¡ãªã¿ã«ããã€ããªããåæã¯ããã¹ãŠããã³ãŒããçŽãããšã§ããã«ã圹ç«ã¡ãŸãã Base64 PowerShell (以äžãPS) ãèªåã§ãã³ãŒãããŠã¿ããå Žåã¯ã次ã®ã³ãã³ããå®è¡ããå¿ èŠããããŸãã
[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($EncodedText))
ããã«æ·±ãé²ã
ãã®æ¹æ³ã䜿çšã㊠PS ã¹ã¯ãªããããã³ãŒãããŸããã以äžã¯ããã°ã©ã ã®ããã¹ãã§ãããç§ãå°ãå€æŽããŸããã
ã¹ã¯ãªãã㯠4 幎 2017 æ XNUMX æ¥ã®æ¥ä»ã«é¢é£ä»ããããŠãããã»ãã·ã§ã³ Cookie ãéä¿¡ããŠããããšã«æ³šæããŠãã ããã
ãã®æ»æã¹ã¿ã€ã«ã«ã€ããŠã¯ã
ããã¯äœã®ããã«ããã®ïŒ
Windows ã€ãã³ã ãã°ããã¡ã€ã¢ãŠã©ãŒã«ãã¹ãã£ã³ããã»ãã¥ãªã㣠ãœãããŠã§ã¢ã®å Žåãbase64 ãšã³ã³ãŒãã«ãããæååãWebClientãããã¬ãŒã³ ããã¹ã ãã¿ãŒã³ã«ãã£ãŠæ€åºãããã®ãé²ãããã®ãã㪠Web ãªã¯ãšã¹ãã®å®è¡ãé²ããŸãã ãããŠããã«ãŠã§ã¢ã®ãã¹ãŠã®ãæªããããŠã³ããŒããã㊠PowerShell ã«æž¡ãããããããã®ã¢ãããŒãã«ããæ€åºãå®å šã«åé¿ããããšãã§ããŸãã ãšããããæåã¯ããæã£ãŠãŸããã
Windows PowerShell ã®é«åºŠãªãã°æ©èœãæå¹ã«ãããš (ç§ã®èšäºãåç
§)ãã€ãã³ã ãã°ã«èªã¿èŸŒãŸããè¡ã衚瀺ãããããšãããããŸããã ç§ã¯äŒŒãŠããŸã
è¿œå ã®ã·ããªãªãè¿œå ããŸããã
ããã«ãŒã¯ãVisual Basic ããã®ä»ã®ã¹ã¯ãªããèšèªã§èšè¿°ããã Microsoft Office ãã¯ãã« PowerShell æ»æãå·§åŠã«é ããŸãã ãã®èãæ¹ã¯ã被害è ãã.doc 圢åŒã®ã¬ããŒããæ·»ä»ãããã¡ãã»ãŒãžãé ä¿¡ãµãŒãã¹ãªã©ããåä¿¡ãããšãããã®ã§ãã ãã¯ããå«ããã®ããã¥ã¡ã³ããéããšãæªæã®ãã PowerShell èªäœãèµ·åãããŠããŸããŸãã
å€ãã®å ŽåãVisual Basic ã¹ã¯ãªããèªäœã¯é£èªåãããŠããããããŠã€ã«ã¹å¯Ÿçããã®ä»ã®ãã«ãŠã§ã¢ ã¹ãã£ããŒãèªç±ã«åé¿ã§ããŸãã äžèšã®ç²Ÿç¥ã«åºã¥ããŠãæŒç¿ãšããŠäžèšã® PowerShell ã JavaScript ã§ã³ãŒãã£ã³ã°ããããšã«ããŸããã ç§ã®ä»äºã®çµæã¯ä»¥äžã®ãšããã§ãã
PowerShell ãé ãé£èªåããã JavaScriptã æ¬ç©ã®ããã«ãŒã¯ããã XNUMX åã XNUMX åè¡ããŸãã
ããã¯ãWeb äžã§ããèŠããããã XNUMX ã€ã®ãã¯ããã¯ã§ããWscript.Shell ã䜿çšããŠãã³ãŒãåããã PowerShell ãå®è¡ããŸãã ã¡ãªã¿ã«JavaScriptèªäœã¯
ãã®äŸã§ã¯ãæªæã®ãã JS ã¹ã¯ãªãã㯠.doc.js æ¡åŒµåã®ãã¡ã€ã«ãšããŠåã蟌ãŸããŠããŸãã éåžžãWindows ã¯æåã®ãµãã£ãã¯ã¹ã®ã¿ã衚瀺ããããã被害è
ã«ã¯ããã Word ææžãšããŠè¡šç€ºãããŸãã
JS ã¢ã€ã³ã³ã¯ã¹ã¯ããŒã« ã¢ã€ã³ã³ã«ã®ã¿è¡šç€ºãããŸãã å€ãã®äººããã®æ·»ä»ãã¡ã€ã«ã Word ææžã ãšæã£ãŠéãã®ãäžæè°ã§ã¯ãããŸããã
ãã®äŸã§ã¯ãWeb ãµã€ãããã¹ã¯ãªãããããŠã³ããŒãããããã«äžèšã® PowerShell ãå€æŽããŸããã ãªã¢ãŒã PS ã¹ã¯ãªããã¯ãEvil Malwareããåºåããã ãã§ãã ã芧ã®ãšããã圌ã¯ãŸã£ããæªäººã§ã¯ãããŸããã ãã¡ãããæ¬ç©ã®ããã«ãŒã¯ãããšãã°ã³ãã³ã ã·ã§ã«ãéããŠã©ãããããããµãŒããŒã«ã¢ã¯ã»ã¹ããããšã«èå³ãæã£ãŠããŸãã 次ã®èšäºã§ã¯ãPowerShell Empire ã䜿çšããŠãããè¡ãæ¹æ³ã説æããŸãã
æåã®çŽ¹ä»èšäºã§ã¯ããã®ãããã¯ã«ã€ããŠããŸãæ·±ãæãäžããªãã§ããã ããã°å¹žãã§ãã ããã§äžæ¯ã€ããŠã次åã¯äžå¿
èŠãªå眮ããæºåãããã«ããã¡ã€ã«ã¬ã¹ ãã«ãŠã§ã¢ã䜿çšããæ»æã®å®äŸãèŠãŠââãããŸãã
åºæïŒ habr.com