XNUMX ææ«ã«ããªã¢ãŒã ã¢ã¯ã»ã¹ ããã€ã®æšéŠ¬ (RAT) ãã«ãŠã§ã¢ (æ»æè ãææããã·ã¹ãã ããªã¢ãŒãããå¶åŸ¡ã§ããããã«ããããã°ã©ã ) ãé åžãããã£ã³ããŒã³ãçºèŠããŸããã
ç§ãã¡ã調ã¹ãã°ã«ãŒãã¯ãææã®ããã«ç¹å®ã® RAT ãã¡ããªãŒãéžæããªãã£ããšããäºå®ã«ãã£ãŠåºå¥ãããŸããã ãã£ã³ããŒã³å ã®æ»æã§ã¯ãããã€ãã®ããã€ã®æšéŠ¬ãçºèŠãããŸãã (ãããã¯ãã¹ãŠåºãå ¥æå¯èœã§ãã)ã ãã®ç¹åŸŽã«ãããã°ã«ãŒãã¯ã絡ã¿åã£ãå°Ÿãæã€ãã£æ¯é¡ã§æ§æãããç¥è©±äžã®åç©ã§ããããºãã®çãæãåºãããŸããã
åæã¯ãK. N. ãã·ã³ãã®èæžãçµæžçã«æãéèŠãªããŠã¹ãšããŠã¹ã«äŒŒããã£æ¯é¡ãïŒ1908 幎ïŒããåŒçšãããŠããŸãã
ãã®çãç©ã«æ¬æãè¡šããŠãç§ãã¡ã¯ RATKing ãæ€èšããŠããã°ã«ãŒãã«ååãä»ããŸããã ãã®æçš¿ã§ã¯ãæ»æè
ãæ»æãã©ã®ããã«å®è¡ãããã䜿çšããããŒã«ã«ã€ããŠè©³ãã説æãããã®ãã£ã³ããŒã³ã®åž°å±ã«é¢ããç§ãã¡ã®èããå
±æããŸãã
æ»æã®é²è¡ç¶æ³
ãã®ãã£ã³ããŒã³ã«ããããã¹ãŠã®æ»æã¯ã次ã®ã¢ã«ãŽãªãºã ã«åŸã£ãŠè¡ãããŸããã
- ãŠãŒã¶ãŒã¯ãGoogle ãã©ã€ããžã®ãªã³ã¯ãèšèŒããããã£ãã·ã³ã°ã¡ãŒã«ãåãåããŸããã
- 被害è ã¯ãªã³ã¯ã䜿çšããŠãæçµãã€ããŒãã Windows ã¬ãžã¹ããªã«ããŒããã DLL ã©ã€ãã©ãªãæå®ããæªæã®ãã VBS ã¹ã¯ãªãããããŠã³ããŒãããPowerShell ãèµ·åããŠå®è¡ããŸããã
- DLL ã©ã€ãã©ãªã¯ãææãããã·ã³ãžã®è¶³ããããåŸãããã«ãæçµãã€ããŒã (å®éã«ã¯æ»æè ã䜿çšãã RAT ã® XNUMX ã€) ãã·ã¹ãã ããã»ã¹ã«æ¿å ¥ããVBS ã¹ã¯ãªãããèªåå®è¡ã«ç»é²ããŸããã
- æçµçãªãã€ããŒãã¯ã·ã¹ãã ããã»ã¹ã§å®è¡ãããæ»æè ã«ææããã³ã³ãã¥ãŒã¿ãå¶åŸ¡ããèœåãäžããŸããã
æŠç¥çã«ã¯æ¬¡ã®ããã«è¡šãããšãã§ããŸãã
次ã«ããã«ãŠã§ã¢é
ä¿¡ã¡ã«ããºã ã«èå³ããããããæåã® XNUMX ã€ã®æ®µéã«çŠç¹ãåœãŠãŸãã ãã«ãŠã§ã¢èªäœã®åäœã¡ã«ããºã ã«ã€ããŠã¯è©³ãã説æããŸããã ãããã¯å°éã®ãã©ãŒã©ã ã§è²©å£²ããããããªãŒãã³ãœãŒã¹ ãããžã§ã¯ããšããŠé
åžãããããããªã©ãåºãå
¥æå¯èœã§ãããããRATKing ã°ã«ãŒãã«åºæã®ãã®ã§ã¯ãããŸããã
æ»æ段éã®åæ
ã¹ããŒãž 1. ãã£ãã·ã³ã°ã¡ãŒã«
æ»æã¯ã被害è
ãæªæã®ããæçŽãåãåãããšããå§ãŸããŸãã (æ»æè
ã¯ããã¹ããå«ãããŸããŸãªãã³ãã¬ãŒãã䜿çšããŸããã以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãã®äžäŸã瀺ããŠããŸã)ã ã¡ãã»ãŒãžã«ã¯æ£èŠã®ãªããžããªãžã®ãªã³ã¯ãå«ãŸããŠããŸãã drive.google.com
ããããã PDF ããã¥ã¡ã³ãã®ããŠã³ããŒã ããŒãžã«èªå°ããããšèããããŸãã
ãã£ãã·ã³ã°ã¡ãŒã«ã®äŸ
ããããå®éã«ã¯ãèªã¿èŸŒãŸããã®ã¯ PDF ããã¥ã¡ã³ãã§ã¯ãªããVBS ã¹ã¯ãªããã§ããã
äžã®ã¹ã¯ãªãŒã³ã·ã§ããã«ããé»åã¡ãŒã«ã®ãªã³ã¯ãã¯ãªãã¯ãããšã次ã®ååã®ãã¡ã€ã«ã衚瀺ãããŸãã Cargo Flight Details.vbs
ã ãã®å Žåãæ»æè
ã¯ãã¡ã€ã«ãæ£èŠã®ææžãšããŠåœè£
ããããšãããŸããã§ããã
åæã«ããã®ãã£ã³ããŒã³ã®äžç°ãšããŠããšããååã®ã¹ã¯ãªãããçºèŠããŸããã Cargo Trip Detail.pdf.vbs
ã Windows ã¯ããã©ã«ãã§ãã¡ã€ã«æ¡åŒµåãé衚瀺ã«ãããããæ£èŠã® PDF ãšããŠã¯ãã§ã«åæ ŒããŠããå¯èœæ§ããããŸãã 確ãã«ããã®å ŽåãVBS ã¹ã¯ãªããã«å¯Ÿå¿ããã¢ã€ã³ã³ã«ãã£ãŠäŸç¶ãšããŠçæãåŒãââèµ·ããããå¯èœæ§ããããŸãã
ãã®æ®µéã§ã被害è ã¯ãããŠã³ããŒãããããã¡ã€ã«ãå°ãã®é詳ããèŠãã ãã§ããã®æ¬ºçã«æ°ã¥ãããšãã§ããŸãã ãã ãããã®ãããªãã£ãã·ã³ã° ãã£ã³ããŒã³ã§ã¯ãæ»æè ã¯å€ãã®å Žåãäžæ³šæãªãŠãŒã¶ãŒãæ¥ãã§ãããŠãŒã¶ãŒã«äŸåããŸãã
ã¹ããŒãž 2. VBS ã¹ã¯ãªããã®æäœ
ãŠãŒã¶ãŒã誀ã£ãŠéãã VBS ã¹ã¯ãªããã«ãããWindows ã¬ãžã¹ããªã« DLL ã©ã€ãã©ãªãç»é²ãããå¯èœæ§ããããŸããã ã¹ã¯ãªããã¯é£èªåãããŠãããã¹ã¯ãªããå ã®è¡ã¯ä»»æã®æåã§åºåããããã€ããšããŠæžã蟌ãŸããŠããŸããã
é£èªåãããã¹ã¯ãªããã®äŸ
é£èªå解é€ã¢ã«ãŽãªãºã ã¯éåžžã«åçŽã§ããé£èªåãããæååãã 16 æåããšã«é€å€ããããã®åŸãçµæã BaseXNUMX ããå
ã®æååã«ãã³ãŒããããŸãã ããšãã°ãå€ãã 57Q53s63t72s69J70r74e2El53v68m65j6CH6Ct
(äžã®ã¹ã¯ãªãŒã³ã·ã§ããã§åŒ·èª¿è¡šç€ºãããŠãã) çµæã®è¡ã¯æ¬¡ã®ãšããã§ãã WScript.Shell
.
æååã®é£èªåã解é€ããã«ã¯ãPython é¢æ°ã䜿çšããŸããã
def decode_str(data_enc):
return binascii.unhexlify(''.join([data_enc[i:i+2] for i in range(0, len(data_enc), 3)]))
以äžã® 9 ïœ 10 è¡ç®ã§ãé£èªå解é€ã«ãã£ãŠ DLL ãã¡ã€ã«ã«ãªã£ãå€ã匷調衚瀺ããŸãã PowerShell ã䜿çšããŠæ¬¡ã®æ®µéã§èµ·åãããã®ã¯åœŒã§ããã
é£èªåããã DLL ãå«ãæåå
VBS ã¹ã¯ãªããã®åé¢æ°ã¯ãæååã®é£èªåã解é€ããããšãã«å®è¡ãããŸããã
ã¹ã¯ãªããã®å®è¡åŸãé¢æ°ãåŒã³åºãããŸãã wscript.sleep
â é
延å®è¡ãå®è¡ããããã«äœ¿çšãããŸããã
次ã«ãã¹ã¯ãªãã㯠Windows ã¬ãžã¹ããªãæäœããŸããã 圌ã¯ããã« WMI ãã¯ãããžãŒã䜿çšããŸããã ãã®å©ããåããŠãäžæã®ããŒãäœæãããå®è¡å¯èœãã¡ã€ã«ã®æ¬äœããã®ãã©ã¡ãŒã¿ã«æžã蟌ãŸããŸããã 次ã®ã³ãã³ãã䜿çšããŠãWMI çµç±ã§ã¬ãžã¹ããªã«ã¢ã¯ã»ã¹ããŸããã
GetObject(winmgmts {impersonationLevel=impersonate}!\.rootdefault:StdRegProv)
VBS ã¹ã¯ãªããã«ãã£ãŠã¬ãžã¹ããªã«äœæããããšã³ããª
ã¹ããŒãž 3. DLL ã©ã€ãã©ãªã®æäœ
第 XNUMX 段éã§ã¯ãæªæã®ãã DLL ãæçµãã€ããŒããããŒãããŠã·ã¹ãã ããã»ã¹ã«æ¿å ¥ãããŠãŒã¶ãŒã®ãã°ã€ã³æã« VBS ã¹ã¯ãªãããèªåèµ·åãããããã«ããŸããã
PowerShellçµç±ã§å®è¡
DLL ã¯ãPowerShell ã§æ¬¡ã®ã³ãã³ãã䜿çšããŠå®è¡ãããŸããã
[System.Threading.Thread]::GetDomain().Load((ItemProperty HKCU:///Software///<rnd_sub_key_name> ).<rnd_value_name>);
[GUyyvmzVhebFCw]::EhwwK('WScript.ScriptFullName', 'rWZlgEtiZr', 'WScript.ScriptName'),0
ãã®ã³ãã³ãã¯æ¬¡ã®ããšãè¡ããŸããã
- ååä»ãã®ã¬ãžã¹ããªå€ããŒã¿ãåä¿¡ããŸãã
rnd_value_name
â ãã®ããŒã¿ã¯ .Net ãã©ãããã©ãŒã ã§æžããã DLL ãã¡ã€ã«ã§ããã - çµæãšããŠåŸããã .Net ã¢ãžã¥ãŒã«ãããã»ã¹ ã¡ã¢ãªã«ããŒãããŸãã
powershell.exe
é¢æ°ã䜿çšããŠ[System.Threading.Thread]::GetDomain().Load()
(Load()é¢æ°ã®è©³çŽ°ãªèª¬æMicrosoft Web ãµã€ãã§å ¥æå¯èœ ); - æ©èœãå®è¡ãã
GUyyvmzVhebFCw]::EhwwK()
- DLL ã©ã€ãã©ãªã®å®è¡ã¯ããããå§ãŸããŸãã - ãã©ã¡ãŒã¿ä»ãvbsScriptPath
,xorKey
,vbsScriptName
ã ãã©ã¡ãŒã¿xorKey
æçµãã€ããŒãã埩å·åããããã®ããŒãšãã©ã¡ãŒã¿ãä¿åvbsScriptPath
ОvbsScriptName
VBS ã¹ã¯ãªãããèªåå®è¡ã«ç»é²ããããã«è»¢éãããŸããã
DLLã©ã€ãã©ãªã®èª¬æ
éã³ã³ãã€ã«ããã圢åŒã§ã¯ãããŒãããŒããŒã¯æ¬¡ã®ããã«ãªããŸãã
éã³ã³ãã€ã«ããã圢åŒã®ããŒã㌠(DLL ã©ã€ãã©ãªã®å®è¡ãéå§ãããé¢æ°ã«ã¯èµ€ãäžç·ãä»ããŠããŸã)
ããŒãããŒããŒã¯ .Net Reactor ãããã¯ã¿ãŒã«ãã£ãŠä¿è·ãããŠããŸãã de4dot ãŠãŒãã£ãªãã£ã¯ããã®ãããã¯ã¿ãŒãåé€ããåªããä»äºãããŸãã
ãã®ããŒããŒ:
- ãã€ããŒããã·ã¹ãã ããã»ã¹ã«æ¿å
¥ããŸã (ãã®äŸã§ã¯ã
svchost.exe
); - èªåå®è¡ãã VBS ã¹ã¯ãªãããè¿œå ããŸããã
ãã€ããŒãã€ã³ãžã§ã¯ã·ã§ã³
PowerShell ã¹ã¯ãªãããåŒã³åºããé¢æ°ãèŠãŠã¿ãŸãããã
PowerShell ã¹ã¯ãªããã«ãã£ãŠåŒã³åºãããé¢æ°
ãã®é¢æ°ã¯æ¬¡ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸããã
- XNUMX ã€ã®ããŒã¿ã»ããã埩å·åããŸãã (
array
Оarray2
ã¹ã¯ãªãŒã³ã·ã§ããã§ïŒã ãããã¯å ã gzip ã䜿çšããŠå§çž®ãããããŒã䜿çšãã XOR ã¢ã«ãŽãªãºã ã§æå·åãããŠããŸãããxorKey
; - å²ãåœãŠãããã¡ã¢ãªé åã«ããŒã¿ãã³ããŒããŸãã ããã®ããŒã¿
array
- æå®ãããã¡ã¢ãªé åãžintPtr
(payload pointer
ã¹ã¯ãªãŒã³ã·ã§ããå ïŒ; ããã®ããŒã¿array2
- æå®ãããã¡ã¢ãªé åãžintPtr2
(shellcode pointer
ã¹ã¯ãªãŒã³ã·ã§ããå ïŒ; - é¢æ°ãšåŒã°ãã
CallWindowProcA
(説æ ãã®æ©èœã¯ Microsoft ã® Web ãµã€ãããå ¥æã§ããŸã) 次ã®ãã©ã¡ãŒã¿ãŒã䜿çšããŸã (ãã©ã¡ãŒã¿ãŒã®ååã¯ä»¥äžã«ãªã¹ããããŠããŸããã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ããããã¯åãé åºã§ãããå®éã®å€ã瀺ãããŠããŸã)ãlpPrevWndFunc
- ããŒã¿ãžã®ãã€ã³ã¿array2
;hWnd
â å®è¡å¯èœãã¡ã€ã«ãžã®ãã¹ãå«ãæååãžã®ãã€ã³ã¿svchost.exe
;Msg
- ããŒã¿ãžã®ãã€ã³ã¿array
;wParam
,lParam
â ã¡ãã»ãŒãžãã©ã¡ãŒã¿ (ãã®å Žåããããã®ãã©ã¡ãŒã¿ã¯äœ¿çšããããå€ã¯ 0 ã§ãã);
- ãã¡ã€ã«ãäœæããŸãã
%AppData%MicrosoftWindowsStart MenuProgramsStartup<name>.url
ã©ã<name>
- ãããã¯ãã©ã¡ãŒã¿ã®æåã® 4 æåã§ãvbsScriptName
(ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ããã®ã¢ã¯ã·ã§ã³ãå«ãã³ãŒãéšåã¯æ¬¡ã®ã³ãã³ãã§å§ãŸããŸã)File.Copy
ïŒã ãã®ããã«ããŠããã«ãŠã§ã¢ã¯ãŠãŒã¶ãŒããã°ã€ã³ãããšãã«èªåå®è¡ãã¡ã€ã«ã®ãªã¹ãã« URL ãã¡ã€ã«ãè¿œå ããææããã³ã³ãã¥ãŒã¿ã«æ¥ç¶ãããããã«ãªããŸãã URL ãã¡ã€ã«ã«ã¯ãã¹ã¯ãªãããžã®ãªã³ã¯ãå«ãŸããŠããŸããã
[InternetShortcut]
URL = file : ///<vbsScriptPath>
ã€ã³ãžã§ã¯ã·ã§ã³ãã©ã®ããã«å®è¡ãããããç解ããããã«ãããŒã¿é
åã埩å·ããŸããã array
О array2
ã ãããè¡ãã«ã¯ã次㮠Python é¢æ°ã䜿çšããŸããã
def decrypt(data, key):
return gzip.decompress(
bytearray([data[i] ^ key[i % len(key)] for i in range(len(data))])[4:])
ãã®çµæã次ã®ããšãåãããŸããã
array
PE ãã¡ã€ã«ã§ãã - ãããæçµãã€ããŒãã§ããarray2
ã€ã³ãžã§ã¯ã·ã§ã³ãå®è¡ããããã«å¿ èŠãªã·ã§ã«ã³ãŒãã§ããã
é
åããã®ã·ã§ã«ã³ãŒã array2
é¢æ°å€ãšããŠæž¡ããã lpPrevWndFunc
é¢æ°ã« CallWindowProcA
. lpPrevWndFunc
â ã³ãŒã«ããã¯é¢æ°ã®ãããã¿ã€ãã¯æ¬¡ã®ããã«ãªããŸãã
LRESULT WndFunc(
HWND hWnd,
UINT Msg,
WPARAM wParam,
LPARAM lParam
);
ãããã£ãŠãé¢æ°ãå®è¡ãããš CallWindowProcA
ãã©ã¡ãŒã¿ä»ã hWnd
, Msg
, wParam
, lParam
é
åã®ã·ã§ã«ã³ãŒããå®è¡ããã array2
åŒæ°ä»ã hWnd
О Msg
. hWnd
å®è¡å¯èœãã¡ã€ã«ãžã®ãã¹ãå«ãæååãžã®ãã€ã³ã¿ã§ãã svchost.exe
ãš Msg
â æçµãã€ããŒããžã®ãã€ã³ã¿ã
ã·ã§ã«ã³ãŒãã¯é¢æ°ã¢ãã¬ã¹ã次ããåãåããŸããã kernel32.dll
О ntdll32.dll
ååã®ããã·ã¥å€ã«åºã¥ããŠãæçµçãªãã€ããŒããããã»ã¹ ã¡ã¢ãªã«æ¿å
¥ããŸã svchost.exe
Process Hollowing ãã¯ããã¯ã䜿çšããŸã (詳现ã«ã€ããŠã¯ããã®èšäºãåç
§ããŠãã ãã)
- ããã»ã¹ãäœæããŸãã
svchost.exe
é¢æ°ã䜿çšããŠãµã¹ãã³ãç¶æ ã«ããCreateProcessW
; - 次ã«ãããã»ã¹ã®ã¢ãã¬ã¹ç©ºéã§ã»ã¯ã·ã§ã³ã®è¡šç€ºãé衚瀺ã«ããŸã
svchost.exe
é¢æ°ã䜿çšããŠNtUnmapViewOfSection
ã ãããã£ãŠãããã°ã©ã ã¯å ã®ããã»ã¹ã®ã¡ã¢ãªã解æŸããŸãããsvchost.exe
次ã«ããã®ã¢ãã¬ã¹ã«ãã€ããŒãçšã®ã¡ã¢ãªãå²ãåœãŠãŸãã - ããã»ã¹ã¢ãã¬ã¹ç©ºéå
ã®ãã€ããŒãã«å²ãåœãŠãããã¡ã¢ãª
svchost.exe
é¢æ°ã䜿çšããŠVirtualAllocEx
;
å°åºããã»ã¹ã®éå§
- ãã€ããŒãã®å
容ãããã»ã¹ã®ã¢ãã¬ã¹ç©ºéã«æžã蟌ã¿ãŸãã
svchost.exe
é¢æ°ã䜿çšããŠWriteProcessMemory
(以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã®ããã«); - ããã»ã¹ãåéãã
svchost.exe
é¢æ°ã䜿çšããŠResumeThread
.
泚å
¥ããã»ã¹ã®å®äº
ããŠã³ããŒãå¯èœãªãã«ãŠã§ã¢
äžèšã®ã¢ã¯ã·ã§ã³ã®çµæãããã€ãã® RAT ã¯ã©ã¹ã®ãã«ãŠã§ã¢ã®ãã¡ã® XNUMX ã€ãææã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŸããã 以äžã®è¡šã¯ãæ»æã«äœ¿çšããããã«ãŠã§ã¢ã®ãªã¹ãã§ãããµã³ãã«ãåãã³ãã³ã ã¢ã³ã ã³ã³ãããŒã« ãµãŒããŒã«ã¢ã¯ã»ã¹ãããããããã㯠XNUMX ã€ã®æ»æè ã°ã«ãŒãã«ãããã®ã§ãããšç¢ºä¿¡ã§ããŸãã
ãã«ãŠã§ã¢ã®åå
æåã«èŠã
SHA-256
CïŒC
æ³šå ¥ãå®è¡ãããããã»ã¹
ããŒã¯ãã©ãã¯
16-04-2020
ea64fe672c953adc19553ea3b9118ce4ee88a14d92fc7e75aa04972848472702
kimjoy007.dyndns[.]org:2017
svchost
èŠå·®
24-04-2020
b4ecd8dbbceaadd482f1b23b712bcddc5464bccaac11fe78ea5fd0ba932a4043
kimjoy007.dyndns[.]org:2019
svchost
ã¯ã«ãŸãŒã³
18-05-2020
3786324ce3f8c1ea3784e5389f84234f81828658b22b8a502b7d48866f5aa3d3
kimjoy007.dyndns[.]org:9933
svchost
ãããã¯ã€ã€ãŒ
20-05-2020
6dac218f741b022f5cad3b5ee01dbda80693f7045b42a0c70335d8a729002f2d
kimjoy007.dyndns[.]org:2000
svchost
åãå¶åŸ¡ãµãŒããŒã§åæ£ããããã«ãŠã§ã¢ã®äŸ
ããã§æ³šç®ãã¹ãç¹ã XNUMX ã€ãããŸãã
ãŸããæ»æè ãè€æ°ã®ç°ãªã RAT ãã¡ããªãåæã«äœ¿çšãããšããäºå®ã§ãã ãã®åäœã¯ãããç¥ããããµã€ã㌠ã°ã«ãŒãã§ã¯äžè¬çã§ã¯ãªãããã䜿çšãããŠããã»ãŒåãããŒã« ã»ããã䜿çšããããšããããããŸãã
次ã«ãRATKing ã¯ãå°éã®ãã©ãŒã©ã ã§äœäŸ¡æ Œã§è²©å£²ãããŠãããããªãŒãã³ãœãŒã¹ ãããžã§ã¯ãã§ãããã«ãŠã§ã¢ã䜿çšããŠããŸããã
ãã®ãã£ã³ããŒã³ã§äœ¿çšããããã«ãŠã§ã¢ã®ããå®å šãªãªã¹ãã¯ãéèŠãªæ³šæç¹ã XNUMX ã€ãããŸãããèšäºã®æåŸã«èšèŒãããŠããŸãã
ã°ã«ãŒãã«ã€ããŠ
説æãããŠããæªæã®ãããã£ã³ããŒã³ãæ¢ç¥ã®æ»æè ã®ãã®ã§ãããšã¯èããããŸããã ä»ã®ãšããããããã®æ»æã¯æ ¹æ¬çã«æ°ããã°ã«ãŒãã«ãã£ãŠå®è¡ããããšèããããŸãã åé ã§ãæžããŸããããç§ãã¡ã¯ãããRATKingãšåŒãã§ããŸãã
VBS ã¹ã¯ãªãããäœæããããã«ãã°ã«ãŒãã¯ãããããŠãŒãã£ãªãã£ã«äŒŒãããŒã«ã䜿çšããŸããã
- é¢æ°ã䜿çšããŠé
延å®è¡ãå®è¡ãã
Sleep
; - WMI ã䜿çšããŸãã
- å®è¡å¯èœãã¡ã€ã«ã®æ¬äœãã¬ãžã¹ã㪠ã㌠ãã©ã¡ãŒã¿ãšããŠç»é²ããŸãã
- PowerShell ã䜿çšããŠãç¬èªã®ã¢ãã¬ã¹ç©ºéã§ãã®ãã¡ã€ã«ãå®è¡ããŸãã
æ確ã«ããããã«ãã¬ãžã¹ããªãããã¡ã€ã«ãå®è¡ãã PowerShell ã³ãã³ããæ¯èŒããŠãã ããããã®ã³ãã³ãã¯ãVBS-Crypter ã䜿çšããŠäœæãããã¹ã¯ãªããã§äœ¿çšãããŸãã
((Get-ItemPropertyHKCU:SoftwareNYANxCAT).NYANxCAT);$text=-join$text[-1..-$text.Length];[AppDomain]::CurrentDomain.Load([Convert]::FromBase64String($text)).EntryPoint.Invoke($Null,$Null);
æ»æè ã®ã¹ã¯ãªããã䜿çšããã®ãšåæ§ã®ã³ãã³ãã䜿çšããŸãã
[System.Threading.Thread]::GetDomain().Load((ItemProperty HKCU:///Software///<rnd_sub_key_name> ).<rnd_value_name>);
[GUyyvmzVhebFCw]::EhwwK('WScript.ScriptFullName', 'rWZlgEtiZr', 'WScript.ScriptName'),0
æ»æè
㯠NYAN-x-CAT ã®å¥ã®ãŠãŒãã£ãªãã£ããã€ããŒãã® XNUMX ã€ãšããŠäœ¿çšããããšã«æ³šæããŠãã ããã
C&C ãµãŒããŒã®ã¢ãã¬ã¹ã¯ãRATKing ã®ãã XNUMX ã€ã®ç¹åŸŽã瀺ããŠããŸããã€ãŸãããã®ã°ã«ãŒãã¯ãã€ããã㯠DNS ãµãŒãã¹ã奜ã¿ãŸã (IoC ããŒãã«ã® C&C ã®ãªã¹ããåç §)ã
IoC
以äžã®è¡šã¯ã説æããããã£ã³ããŒã³ã«èµ·å ããå¯èœæ§ãæãé«ã VBS ã¹ã¯ãªããã®å®å šãªãªã¹ãã瀺ããŠããŸãã ãããã®ã¹ã¯ãªããã¯ãã¹ãŠé¡äŒŒããŠãããã»ãŒåãäžé£ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸãã ãããã¯ãã¹ãŠãRAT ã¯ã©ã¹ã®ãã«ãŠã§ã¢ãä¿¡é Œã§ãã Windows ããã»ã¹ã«æ¿å ¥ããŸãã ãããã¯ãã¹ãŠããã€ããã㯠DNS ãµãŒãã¹ã䜿çšããŠç»é²ããã C&C ã¢ãã¬ã¹ãæã£ãŠããŸãã
ãã ããåã C&C ã¢ãã¬ã¹ (kimjoy007.dyndns.org ãªã©) ãæã€ãµã³ãã«ãé€ããŠããããã®ã¹ã¯ãªããããã¹ãŠåãæ»æè ã«ãã£ãŠé åžããããšã¯èšããŸããã
ãã«ãŠã§ã¢ã®åå
SHA-256
CïŒC
æ³šå ¥ãå®è¡ãããããã»ã¹
èŠå·®
b4ecd8dbbceaadd482f1b23b712bcddc5464bccaac11fe78ea5fd0ba932a4043
kimjoy007.dyndns.org
svchost
00edb8200dfeee3bdd0086c5e8e07c6056d322df913679a9f22a2b00b836fd72
Hope.doomdns.org
svchost
504cbae901c4b3987aa9ba458a230944cb8bd96bbf778ceb54c773b781346146
kimjoy007.dyndns.org
svchost
1487017e087b75ad930baa8b017e8388d1e99c75d26b5d1deec8b80e9333f189
kimjoy007.dyndns.org
svchost
c4160ec3c8ad01539f1c16fb35ed9c8c5a53a8fda8877f0d5e044241ea805891
franco20.dvrdns.org
svchost
515249d6813bb2dde1723d35ee8eb6eeb8775014ca629ede017c3d83a77634ce
kimjoy007.dyndns.org
svchost
1b70f6fee760bcfe0c457f0a85ca451ed66e61f0e340d830f382c5d2f7ab803f
franco20.dvrdns.org
svchost
b2bdffa5853f29c881d7d9bff91b640bc1c90e996f85406be3b36b2500f61aa1
Hope.doomdns.org
svchost
c9745a8f33b3841fe7bfafd21ad4678d46fe6ea6125a8fedfcd2d5aee13f1601
kimjoy007.dyndns.org
svchost
1dfc66968527fbd4c0df2ea34c577a7ce7a2ba9b54ba00be62120cc88035fa65
franco20.dvrdns.org
svchost
c6c05f21e16e488eed3001d0d9dd9c49366779559ad77fcd233de15b1773c981
kimjoy007.dyndns.org
CMD
3b785cdcd69a96902ee62499c25138a70e81f14b6b989a2f81d82239a19a3aed
Hope.doomdns.org
svchost
4d71ceb9d6c53ac356c0f5bdfd1a5b28981061be87e38e077ee3a419e4c476f9
2004para.ddns.net
svchost
00185cc085f284ece264e3263c7771073a65783c250c5fd9afc7a85ed94acc77
Hope.doomdns.org
svchost
0342107c0d2a069100e87ef5415e90fd86b1b1b1c975d0eb04ab1489e198fc78
franco20.dvrdns.org
svchost
de33b7a7b059599dc62337f92ceba644ac7b09f60d06324ecf6177fff06b8d10
kimjoy007.dyndns.org
svchost
80a8114d63606e225e620c64ad8e28c9996caaa9a9e87dd602c8f920c2197007
kimjoy007.dyndns.org
svchost
acb157ba5a48631e1f9f269e6282f042666098614b66129224d213e27c1149bb
Hope.doomdns.org
CMD
bf608318018dc10016b438f851aab719ea0abe6afc166c8aea6b04f2320896d3
franco20.dvrdns.org
svchost
4d0c9b8ad097d35b447d715a815c67ff3d78638b305776cde4d90bfdcb368e38
Hope.doomdns.org
svchost
e7c676f5be41d49296454cd6e4280d89e37f506d84d57b22f0be0d87625568ba
kimjoy007.dyndns.org
svchost
9375d54fcda9c7d65f861dfda698e25710fda75b5ebfc7a238599f4b0d34205f
franco20.dvrdns.org
svchost
128367797fdf3c952831c2472f7a308f345ca04aa67b3f82b945cfea2ae11ce5
kimjoy007.dyndns.org
svchost
09bd720880461cb6e996046c7d6a1c937aa1c99bd19582a562053782600da79d
Hope.doomdns.org
svchost
0a176164d2e1d5e2288881cc2e2d88800801001d03caedd524db365513e11276
paradickhead.homeip.net
svchost
0af5194950187fd7cbd75b1b39aab6e1e78dae7c216d08512755849c6a0d1cbe
Hope.doomdns.org
svchost
Warzone
3786324ce3f8c1ea3784e5389f84234f81828658b22b8a502b7d48866f5aa3d3
kimjoy007.dyndns.org
svchost
db0d5a67a0ced6b2de3ee7d7fc845a34b9d6ca608e5fead7f16c9a640fa659eb
kimjoy007.dyndns.org
svchost
ãããã¯ã€ã€ãŒ
6dac218f741b022f5cad3b5ee01dbda80693f7045b42a0c70335d8a729002f2d
kimjoy007.dyndns.org
svchost
ããŒã¯ãã©ãã¯
ea64fe672c953adc19553ea3b9118ce4ee88a14d92fc7e75aa04972848472702
kimjoy007.dyndns.org
svchost
WSHã©ãã
d410ced15c848825dcf75d30808cde7784e5b208f9a57b0896e828f890faea0e
ã¢ãã±ãœãªã¥ãŒã·ã§ã³.linkpc.net
ã¬ã¬ãºã
ã©ã€ã
896604d27d88c75a475b28e88e54104e66f480bcab89cc75b6cdc6b29f8e438b
ãœããããŒ.duckdns.org
ã¬ã¬ãºã
ã¯ãšãŒãµãŒRAT
bd1e29e9d17edbab41c3634649da5c5d20375f055ccf968c022811cd9624be57
darkhate-23030.portmap.io
ã¬ã¬ãºã
12044aa527742282ad5154a4de24e55c9e1fae42ef844ed6f2f890296122153b
darkhate-23030.portmap.io
ã¬ã¬ãºã
be93cc77d864dafd7d8c21317722879b65cfbb3297416bde6ca6edbfd8166572
darkhate-23030.portmap.io
ã¬ã¬ãºã
933a136f8969707a84a61f711018cd21ee891d5793216e063ac961b5d165f6c0
darkhate-23030.portmap.io
ã¬ã¬ãºã
71dea554d93728cce8074dbdb4f63ceb072d4bb644f0718420f780398dafd943
chrom1.myq-see.com
ã¬ã¬ãºã
0d344e8d72d752c06dc6a7f3abf2ff7678925fde872756bf78713027e1e332d5
darkhate-23030.portmap.io
ã¬ã¬ãºã
0ed7f282fd242c3f2de949650c9253373265e9152c034c7df3f5f91769c6a4eb
darkhate-23030.portmap.io
ã¬ã¬ãºã
aabb6759ce408ebfa2cc57702b14adaec933d8e4821abceaef0c1af3263b1bfa
darkhate-23030.portmap.io
ã¬ã¬ãºã
1699a37ddcf4769111daf33b7d313cf376f47e92f6b92b2119bd0c860539f745
darkhate-23030.portmap.io
ã¬ã¬ãºã
3472597945f3bbf84e735a778fd75c57855bb86aca9b0a4d0e4049817b508c8c
darkhate-23030.portmap.io
ã¬ã¬ãºã
809010d8823da84cdbb2c8e6b70be725a6023c381041ebda8b125d1a6a71e9b1
darkhate-23030.portmap.io
ã¬ã¬ãºã
4217a2da69f663f1ab42ebac61978014ec4f562501efb2e040db7ebb223a7dff
darkhate-23030.portmap.io
ã¬ã¬ãºã
08f34b3088af792a95c49bcb9aa016d4660609409663bf1b51f4c331b87bae00
darkhate-23030.portmap.io
ã¬ã¬ãºã
79b4efcce84e9e7a2e85df7b0327406bee0b359ad1445b4f08e390309ea0c90d
darkhate-23030.portmap.io
ã¬ã¬ãºã
12ea7ce04e0177a71a551e6d61e4a7916b1709729b2d3e9daf7b1bdd0785f63a
darkhate-23030.portmap.io
ã¬ã¬ãºã
d7b8eb42ae35e9cc46744f1285557423f24666db1bde92bf7679f0ce7b389af9
darkhate-23030.portmap.io
ã¬ã¬ãºã
def09b0fed3360c457257266cb851fffd8c844bc04a623c210a2efafdf000d5c
darkhate-23030.portmap.io
ã¬ã¬ãºã
50119497c5f919a7e816a37178d28906fb3171b07fc869961ef92601ceca4c1c
darkhate-23030.portmap.io
ã¬ã¬ãºã
ade5a2f25f603bf4502efa800d3cf5d19d1f0d69499b0f2e9ec7c85c6dd49621
darkhate-23030.portmap.io
ã¬ã¬ãºã
189d5813c931889190881ee34749d390e3baa80b2c67b426b10b3666c3cc64b7
darkhate-23030.portmap.io
ã¬ã¬ãºã
c3193dd67650723753289a4aebf97d4c72a1afe73c7135bee91c77bdf1517f21
darkhate-23030.portmap.io
ã¬ã¬ãºã
a6f814f14698141753fc6fb7850ead9af2ebcb0e32ab99236a733ddb03b9eec2
darkhate-23030.portmap.io
ã¬ã¬ãºã
a55116253624641544175a30c956dbd0638b714ff97b9de0e24145720dcfdf74
darkhate-23030.portmap.io
ã¬ã¬ãºã
d6e0f0fb460d9108397850169112bd90a372f66d87b028e522184682a825d213
darkhate-23030.portmap.io
ã¬ã¬ãºã
522ba6a242c35e2bf8303e99f03a85d867496bbb0572226e226af48cc1461a86
darkhate-23030.portmap.io
ã¬ã¬ãºã
fabfdc209b02fe522f81356680db89f8861583da89984c20273904e0cf9f4a02
darkhate-23030.portmap.io
ã¬ã¬ãºã
08ec13b7da6e0d645e4508b19ba616e4cf4e0421aa8e26ac7f69e13dc8796691
darkhate-23030.portmap.io
ã¬ã¬ãºã
8433c75730578f963556ec99fbc8d97fa63a522cef71933f260f385c76a8ee8d
darkhate-23030.portmap.io
ã¬ã¬ãºã
99f6bfd9edb9bf108b11c149dd59346484c7418fc4c455401c15c8ac74b70c74
darkhate-23030.portmap.io
ã¬ã¬ãºã
d13520e48f0ff745e31a1dfd6f15ab56c9faecb51f3d5d3d87f6f2e1abe6b5cf
darkhate-23030.portmap.io
ã¬ã¬ãºã
9e6978b16bd52fcd9c331839545c943adc87e0fbd7b3f947bab22ffdd309f747
darkhate-23030.portmap.io
ã¬ã°ã¢ãºã â
åºæïŒ habr.com