ãã«ãŠã§ã¢åæã«ç¹åããäžé£ã®èšäºãç¶ç¶ããŸããã§
Agent Tesla ã¯ãæ£èŠã®ããŒãã¬ãŒè£œåãè£ ã£ãŠãµãŒãã¹ãšããŠã®ãã«ãŠã§ã¢ ã¢ãã«ã䜿çšããŠé åžãããã¢ãžã¥ãŒã«åŒã®ã¹ã〠ãœãããŠã§ã¢ã§ãã ãšãŒãžã§ã³ã Tesla ã¯ããã©ãŠã¶ãé»åã¡ãŒã« ã¯ã©ã€ã¢ã³ããããã³ FTP ã¯ã©ã€ã¢ã³ããããŠãŒã¶ãŒèªèšŒæ å ±ãæœåºããŠãµãŒããŒã«éä¿¡ããæ»æè ã«éä¿¡ããã¯ãªããããŒã ããŒã¿ãèšé²ããããã€ã¹ç»é¢ããã£ããã£ããããšãã§ããŸãã åææç¹ã§ã¯ãéçºè ã®å ¬åŒ Web ãµã€ãã¯å©çšã§ããŸããã§ããã
æ§æãã¡ã€ã«
以äžã®è¡šã¯ã䜿çšããŠãããµã³ãã«ã«é©çšãããæ©èœã瀺ããŠããŸãã
説æ | å€ |
KeyLogger 䜿çšãã©ã° | true |
ScreenLogger 䜿çšãã©ã° | false |
KeyLogger ãã°ã®éä¿¡éé (ååäœ) | 20 |
ScreenLogger ã®ãã°éä¿¡éé (ååäœ) | 20 |
ããã¯ã¹ããŒã¹ããŒåŠçãã©ã°ã False â ãã°ã®ã¿ã True â åã®ããŒãæ¶å»ããŸã | false |
CNCã¿ã€ãããªãã·ã§ã³: smtpãwebpanelãftp | SMTP |
ãªã¹ãã%filter_list%ãããããã»ã¹ãçµäºããããã®ã¹ã¬ããèµ·åãã©ã° | false |
UACç¡å¹ãã©ã° | false |
ã¿ã¹ã¯ãããŒãžã£ãŒç¡å¹ãã©ã° | false |
CMDç¡å¹ãã©ã° | false |
å®è¡ãŠã£ã³ããŠç¡å¹åãã©ã° | false |
ã¬ãžã¹ããªãã¥ãŒã¢ç¡å¹åãã©ã° | false |
ã·ã¹ãã 埩å ãã€ã³ããã©ã°ãç¡å¹ã«ãã | true |
ã³ã³ãããŒã«ããã«ç¡å¹ãã©ã° | false |
MSCONFIG ç¡å¹ãã©ã° | false |
ãšã¯ã¹ãããŒã©ãŒã®ã³ã³ããã¹ã ã¡ãã¥ãŒãç¡å¹ã«ãããã©ã° | false |
ãã³ãã©ã° | false |
ã¡ã€ã³ã¢ãžã¥ãŒã«ãã·ã¹ãã ã«åºå®ãããšãã«ã¡ã€ã³ã¢ãžã¥ãŒã«ãã³ããŒããããã®ãã¹ | %startupfolder% %insfolder%%insname% |
ã·ã¹ãã ã«å²ãåœãŠãããã¡ã€ã³ã¢ãžã¥ãŒã«ã®ãSystemãããã³ãHiddenãå±æ§ãèšå®ããããã®ãã©ã° | false |
ã·ã¹ãã ã«åºå®ããããšãã«åèµ·åãå®è¡ãããã©ã° | false |
ã¡ã€ã³ã¢ãžã¥ãŒã«ãäžæãã©ã«ããŒã«ç§»åããããã®ãã©ã° | false |
UACãã€ãã¹ãã©ã° | false |
ãã®ã³ã°ã®æ¥ä»ãšæå»ã®åœ¢åŒ | yyyy-MM-dd HHïŒmmïŒss |
KeyLogger ã®ããã°ã©ã ãã£ã«ã¿ãŒã䜿çšããããã®ãã©ã° | true |
çªçµãã£ã«ã¿ãªã³ã°ã®çš®é¡ã 1 â ããã°ã©ã åããŠã£ã³ããŠã®ã¿ã€ãã«ããæ€çŽ¢ãããŸãã 2 â ããã°ã©ã åã¯ãŠã£ã³ããŠã®ããã»ã¹åã§æ€çŽ¢ãããŸãã |
1 |
ããã°ã©ã ãã£ã«ã¿ãŒ | "ãã§ã€ã¹ããã¯" "ãã€ãã¿ãŒ" ãgmailã "ã€ã³ã¹ã¿ã°ã©ã " "æ ç»" ãã¹ã«ã€ãã ããã«ãã "ããã¯" ãã¯ããã¢ããã "äžå" |
ã¡ã€ã³ã¢ãžã¥ãŒã«ãã·ã¹ãã ã«æ¥ç¶ãã
察å¿ãããã©ã°ãèšå®ãããŠããå Žåãã¡ã€ã³ ã¢ãžã¥ãŒã«ã¯ãã·ã¹ãã ã«å²ãåœãŠããããã¹ãšããŠæ§æã§æå®ããããã¹ã«ã³ããŒãããŸãã
æ§æã®å€ã«å¿ããŠããã¡ã€ã«ã«ã¯ãHiddenãããã³ãSystemãå±æ§ãäžããããŸãã
èªåå®è¡ã¯ã次㮠2 ã€ã®ã¬ãžã¹ã㪠ãã©ã³ãã«ãã£ãŠæäŸãããŸãã
- HKCU ãœãããŠã§ã¢MicrosoftWindowsCurrentVersionRun%insregname%
- HKCUSOFTWAREMicrosoftWindowsçŸåšã®ããŒãžã§ã³ãšã¯ã¹ãããŒã©ãŒã¹ã¿ãŒãã¢ããæ¿èªæžã¿å®è¡ %insregname%
ããŒãããŒããŒãããã»ã¹ã«æ¿å ¥ãããããã ã¬ã¬ãºã ãã¡ã€ã³ã¢ãžã¥ãŒã«ã®æ°žç¶ãã©ã°ãèšå®ãããšãéåžžã«èå³æ·±ãçµæãåŸãããŸãããã«ãŠã§ã¢ã¯èªåèªèº«ãã³ããŒãã代ããã«ãå ã®ãã¡ã€ã«ãã·ã¹ãã ã«æ·»ä»ããŸããã RegAsm.exeããã®éã«æ³šå°ãè¡ãããŸããã
C&C ãšã®å¯Ÿè©±
䜿çšããæ¹æ³ã«é¢ä¿ãªãããããã¯ãŒã¯éä¿¡ã¯ããªãœãŒã¹ã䜿çšããŠè¢«å®³è
ã®å€éš IP ãååŸããããšããå§ãŸããŸãã
以äžã«ããœãããŠã§ã¢ã§æäŸããããããã¯ãŒã¯å¯Ÿè©±æ¹æ³ã«ã€ããŠèª¬æããŸãã
ãŠã§ãããã«
察話㯠HTTP ãããã³ã«çµç±ã§è¡ãããŸãããã«ãŠã§ã¢ã¯ã次ã®ããããŒãå«ã POST ãªã¯ãšã¹ããå®è¡ããŸãã
- ãŠãŒã¶ãŒãšãŒãžã§ã³ã: Mozilla/5.0 (Windows U Windows NT 6.1 ru rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
- æ¥ç¶ïŒããŒãã¢ã©ã€ã
- ã³ã³ãã³ãã¿ã€ã: application/x-www-form-urlencoded
ãµãŒããŒã¢ãã¬ã¹ã¯å€ã§æå®ãããŸã %æçš¿URL%ãæå·åãããã¡ãã»ãŒãžã¯ãã©ã¡ãŒã¿ã§éä¿¡ãããŸã «P»ãæå·åã¡ã«ããºã ã«ã€ããŠã¯ã»ã¯ã·ã§ã³ã§èª¬æãããŠããŸãã ãæå·åã¢ã«ãŽãªãºã ã(æ¹æ³2).
éä¿¡ãããã¡ãã»ãŒãžã¯æ¬¡ã®ããã«ãªããŸãã
type={0}nhwid={1}ntime={2}npcname={3}nlogdata={4}nscreen={5}nipadd={6}nwebcam_link={7}nclient={8}nlink={9}nusername={10}npassword={11}nscreen_link={12}
ãã©ã¡ãŒã¿ãŒ type ã¡ãã»ãŒãžã®çš®é¡ã瀺ããŸãã
ããŒã â MD5 ããã·ã¥ã¯ããã¶ãŒããŒãã®ã·ãªã¢ã«çªå·ãšããã»ããµãŒ ID ã®å€ããèšé²ãããŸããã»ãšãã©ã®å ŽåããŠãŒã¶ãŒ ID ãšããŠäœ¿çšãããŸãã
æé â çŸåšã®æå»ãšæ¥ä»ãéä¿¡ããããã«æ©èœããŸãã
ããœã³ã³å - ãšããŠå®çŸ© /.
ãã°ããŒã¿ â ãã°ããŒã¿ã
ãã¹ã¯ãŒããéä¿¡ãããšãã®ã¡ãã»ãŒãžã¯æ¬¡ã®ããã«ãªããŸãã
type={0}nhwid={1}ntime={2}npcname={3}nlogdata={4}nscreen={5}nipadd={6}nwebcam_link={7}nscreen_link={8}n[passwords]
以äžã¯ãçãŸããããŒã¿ã®åœ¢åŒã§ã®èª¬æã§ãã nclient[]={0}nlink[]={1}nusername[]={2}npassword[]={3}.
SMTP
察話㯠SMTP ãããã³ã«çµç±ã§è¡ãããŸããéä¿¡ãããã¬ã¿ãŒã¯HTML圢åŒã§ãããã©ã¡ãŒã¿ BODY ã®åœ¢åŒã¯æ¬¡ã®ãšããã§ãã
ã¬ã¿ãŒã®ããããŒã®äžè¬çãªåœ¢åŒã¯æ¬¡ã®ãšããã§ãã / ãã¬ã¿ãŒã®å
容ããã³æ·»ä»ãã¡ã€ã«ã¯æå·åãããŸããã
察話㯠FTP ãããã³ã«çµç±ã§è¡ãããŸãããšããååã®ãã¡ã€ã«ãæå®ããããµãŒããŒã«è»¢éãããŸã _-_.htmlããã¡ã€ã«ã®å
容ã¯æå·åãããŸããã
æå·åã¢ã«ãŽãªãºã
ãã®ã±ãŒã¹ã§ã¯ã次ã®æå·åæ¹åŒã䜿çšãããŸãã
1ã¡ãœãã
ãã®ã¡ãœããã¯ãã¡ã€ã³ ã¢ãžã¥ãŒã«å ã®æååãæå·åããããã«äœ¿çšãããŸããæå·åã«äœ¿çšãããã¢ã«ãŽãªãºã ã¯ã AES.
å ¥å㯠6 æ¡ã® 10 é²æ°ã§ãã次ã®å€æãããã«å¯ŸããŠå®è¡ãããŸãã
f(x) = (((x >> 2 - 31059) ^ 6380) - 1363) >> 3
çµæã®å€ã¯ãåã蟌ã¿ããŒã¿é åã®ã€ã³ããã¯ã¹ã§ãã
é åã®åèŠçŽ ã¯ã·ãŒã±ã³ã¹ã§ã DWORDãåæµæ DWORD ãã€ãã®é åãååŸãããŸããæåã® 32 ãã€ããæå·åããŒããã®åŸã« 16 ãã€ãã®åæåãã¯ãã«ãæ®ãã®ãã€ããæå·åãããããŒã¿ã§ãã
2ã¡ãœãã
䜿çšãããã¢ã«ãŽãªãºã 3DES ã¢ãŒã㧠ECB å šãã€ãã®ããã£ã³ã°ä»ã (PKCS7).
ããŒã¯ãã©ã¡ãŒã¿ã§æå®ããŸã %urlkey%ãã ããæå·åã«ã¯ MD5 ããã·ã¥ã䜿çšãããŸãã
æªæã®ããæ©èœ
調æ»äžã®ãµã³ãã«ã¯ã次ã®ããã°ã©ã ã䜿çšããŠæªæã®ããæ©èœãå®è£ ããŠããŸãã
KeyLogger
WinAPIé¢æ°ã䜿çšããŠã察å¿ãããã«ãŠã§ã¢ãã©ã°ãããå Žå SetWindowsHookEx ããŒããŒãäžã®ããŒæŒäžã€ãã³ãã«ç¬èªã®ãã³ãã©ãŒãå²ãåœãŠãŸãããã³ãã©ãŒé¢æ°ã¯ãã¢ã¯ãã£ããªãŠã£ã³ããŠã®ã¿ã€ãã«ãååŸããããšããå§ãŸããŸãã
ã¢ããªã±ãŒã·ã§ã³ ãã£ã«ã¿ãªã³ã° ãã©ã°ãèšå®ãããŠããå Žåãæå®ãããã¿ã€ãã«å¿ããŠãã£ã«ã¿ãªã³ã°ãå®è¡ãããŸãã
- ããã°ã©ã åã¯ãŠã£ã³ããŠã®ã¿ã€ãã«ããæ€çŽ¢ãããŸã
- ããã°ã©ã åã¯ãŠã£ã³ããŠã®ããã»ã¹åã§æ€çŽ¢ãããŸãã
次ã«ãã¢ã¯ãã£ããªãŠã£ã³ããŠã«é¢ããæ å ±ãå«ãã¬ã³ãŒãã次ã®åœ¢åŒã§ãã°ã«è¿œå ãããŸãã
次ã«ãæŒãããããŒã«é¢ããæ
å ±ãèšé²ãããŸãã
ã㌠| èšé² |
ããã¯ã¹ããŒã¹ | Backspace ããŒã®åŠçãã©ã°ã«å¿ããŠ: False â {BACK} True â åã®ããŒãæ¶å»ããŸã |
ãã£ããã¹ãã㯠| {ãã£ããã¹ããã¯} |
ESC | {ESC} |
PageUpã㌠| {ããŒãžã¢ãã} |
Down | â |
DELETE | {ãã«} |
ã | ã |
F5 | {F5} |
& | ãš |
F10 | {F10} |
TAB | {ã¿ã} |
< | < |
> | > |
ã¹ããŒã¹ã㌠| |
F8 | {F8} |
F12 | {F12} |
F9 | {F9} |
Alt + Tab | {ALT+TAB} |
çµãã | {çµãã} |
F4 | {F4} |
F2 | {F2} |
CTRL | {CTRL} |
F6 | {F6} |
å³ | â |
Up | â |
F1 | {F1} |
å·Š | â |
PageDownã㌠| {ããŒãžããŠã³} |
ã€ã³ã»ãã | {å ¥ãã} |
Win | {åã€} |
NumLockã㌠| {NumLock} |
F11 | {F11} |
F3 | {F3} |
ããŒã | {家} |
ENTER | {å ¥å} |
ALT + F4 | {ALT+F4} |
F7 | {F7} |
ãã®ä»ã®ã㌠| CapsLock ããŒãš Shift ããŒã®äœçœ®ã«å¿ããŠãæåã¯å€§æåãŸãã¯å°æåã«ãªããŸãã |
åéããããã°ã¯ãæå®ãããé »åºŠã§ãµãŒããŒã«éä¿¡ãããŸãã転éã倱æããå Žåããã°ã¯ãã¡ã€ã«ã«ä¿åãããŸã %TEMP%log.tmp 圢åŒ:
ã¿ã€ããŒãäœåãããšããã¡ã€ã«ããµãŒããŒã«è»¢éãããŸãã
ã¹ã¯ãªãŒã³ãã¬ãŒ
æå®ãããé »åºŠã§ããã«ãŠã§ã¢ã¯æ¬¡ã®åœ¢åŒã§ã¹ã¯ãªãŒã³ã·ã§ãããäœæããŸãã Jpegã æå³ã®ãã å質 50 ã«çããã®ã§ãã¡ã€ã«ã«ä¿åããŸã %APPDATA %.jpgã転éåŸããã¡ã€ã«ã¯åé€ãããŸãã
ã¯ãªããããŒããã¬ãŒ
é©åãªãã©ã°ãèšå®ãããŠããå Žåã次ã®è¡šã«åŸã£ãŠãã€ã³ã¿ãŒã»ãããããããã¹ãã®çœ®æãè¡ãããŸãã
ãã®åŸãããã¹ãããã°ã«æ¿å
¥ãããŸãã
ãã¹ã¯ãŒãã¹ãã£ãŒã©ãŒ
ãã®ãã«ãŠã§ã¢ã¯ã次ã®ã¢ããªã±ãŒã·ã§ã³ãããã¹ã¯ãŒããããŠã³ããŒãã§ããŸãã
ãã©ãŠã¶ | ã¡ãŒã«ã¯ã©ã€ã¢ã³ã | FTPã¯ã©ã€ã¢ã³ã |
ã¯ãã | Outlook | FileZillaã |
Firefoxã® | ãµã³ããŒããŒã | WS_FTP |
IE/ãšããž | Foxmailã® | WinSCPã® |
Safari | ãªãã©ã¡ãŒã« | CoreFTP |
Operaãã©ãŠã¶ | IncrediMailã® | FTPããã²ãŒã¿ãŒ |
Yandexã® | ãã³ã¡ãŒã« | ã®FlashFXP |
ã³ã¢ã | ãŠãŒãã© | SmartFTPã® |
ã¯ãã ãã©ã¹ | ããã | FTPã³ãã³ã㌠|
ã¯ãã | éµäŸ¿ãã¹ã | |
ããŒã | çªã¡ãŒã« | |
7Star | ||
ã¢ããŒãŽ | ||
ãã¬ã€ããœãããŠã§ã¢ | Jabber ã¯ã©ã€ã¢ã³ã | VPNã¯ã©ã€ã¢ã³ã |
ã»ã³ããã©ãŠã¶ | ãµã€/ãµã€+ | ãªãŒãã³VPN |
ãã§ããã | ||
ã³ãã³ã¯ | ||
èŠçŽ ãã©ãŠã¶ | ããŠã³ããŒããããŒãžã£ãŒ | |
ãšããã¯ãã©ã€ãã·ãŒãã©ãŠã¶ | ã€ã³ã¿ãŒãããã®ããŠã³ããŒããããŒãžã£ | |
ã³ã¡ã¿ | JDownloader | |
è»é | ||
ã¹ããŒãã㯠| ||
uCozMedia | ||
ããã«ã㣠| ||
SeaMonkeyã® | ||
ãããã¯ãã©ãŠã¶ | ||
UCã®ãã©ãŠã¶ | ||
ãã©ãã¯ããŒã¯ | ||
ãµã€ããŒãã©ãã¯ã¹ | ||
Kã¡ã¬ãªã³ | ||
ã¢ã€ã¹ãã£ãã | ||
Icedragon | ||
ããŒã«ã ãŒã³ | ||
ãŠã©ãŒã¿ãŒãã©ãã¯ã¹ | ||
ãã¡ã«ã³ã³ãã©ãŠã¶ |
åç解æãžã®å¯Ÿæ
- æ©èœã®äœ¿çš ã¹ãªãŒããã¿ã€ã ã¢ãŠãã«ãã£ãŠäžéšã®ãµã³ãããã¯ã¹ããã€ãã¹ã§ããããã«ããŸã
- ã¹ã¬ããã®ç Žæ£ ãŸãŒã³.èå¥åãã€ã³ã¿ãŒããããããã¡ã€ã«ãããŠã³ããŒããããšããäºå®ãé ãããšãã§ããŸã
- ãã©ã¡ãŒã¿ã§ %filter_list% ãã«ãŠã§ã¢ã 1 ç§ééã§çµäºããããã»ã¹ã®ãªã¹ããæå®ããŸã
- åæ UAC
- ã¿ã¹ã¯ãããŒãžã£ãŒãç¡å¹ã«ãã
- åæ CMD
- ãŠã£ã³ããŠãç¡å¹ã«ãã "èµ°ã"
- ã³ã³ãããŒã«ããã«ãç¡å¹ã«ãã
- ããŒã«ãç¡å¹ã«ãã RegEditã
- ã·ã¹ãã ã®åŸ©å ãã€ã³ããç¡å¹ã«ãã
- ãšã¯ã¹ãããŒã©ãŒã®ã³ã³ããã¹ã ã¡ãã¥ãŒãç¡å¹ã«ãã
- åæ MSCONFIG
- ãã€ãã¹ UAC:
ã¡ã€ã³ã¢ãžã¥ãŒã«ã®éã¢ã¯ãã£ããªæ©èœ
ã¡ã€ã³ã¢ãžã¥ãŒã«ã®åæäžã«ããããã¯ãŒã¯å šäœã«æ¡æ£ããããŠã¹ã®äœçœ®ã远跡ããæ©èœãç¹å®ããŸããã
ã¯ãŒã
ãªã ãŒããã« ã¡ãã£ã¢ãæ¥ç¶ããããã®ã€ãã³ãã¯ãå¥ã®ã¹ã¬ããã§ç£èŠãããŸããæ¥ç¶ãããšããã®ååã®ãã«ãŠã§ã¢ããã¡ã€ã« ã·ã¹ãã ã®ã«ãŒãã«ã³ããŒãããŸã scr.exeããã®åŸãæ¡åŒµåãä»ããŠãããã¡ã€ã«ãæ€çŽ¢ããŸã LNKãã¿ããªã®ããŒã LNK ã«å€ãã cmd.exe /c start scr.exe&start & exit.
ã¡ãã£ã¢ã®ã«ãŒãã«ããåãã£ã¬ã¯ããªã«ã¯å±æ§ãäžããããŸãã "é ãã" æ¡åŒµåãä»ããŠãããã¡ã€ã«ãäœæãããŸã LNK é ããã£ã¬ã¯ããªã®ååãšã³ãã³ã cmd.exe /c start scr.exe&explorer /root,"%CD%" & çµäº.
ããŠã¹ãã©ãã«ãŒ
ã€ã³ã¿ãŒã»ãããå®è¡ããæ¹æ³ã¯ãããŒããŒãã§äœ¿çšãããæ¹æ³ãšäŒŒãŠããŸãããã®æ©èœã¯ãŸã éçºäžã§ãã
ãã¡ã€ã«ã¢ã¯ãã£ããã£
ãã¹ | 説æ |
%Temp%temp.tmp | UAC ãã€ãã¹è©Šè¡ã®ã«ãŠã³ã¿ãŒãå«ãŸããŠããŸã |
%startupfolder%%insfolder%%insname% | HPE ã·ã¹ãã ã«å²ãåœãŠããã¹ |
%Temp%tmpG{ããªç§åäœã®çŸåšã®æå»}.tmp | ã¡ã€ã³ã¢ãžã¥ãŒã«ã®ããã¯ã¢ãããã¹ |
%Temp%log.tmp | ãã°ãã¡ã€ã« |
%AppData%{ä»»æã® 10 æåã®ã·ãŒã±ã³ã¹}.jpeg | ã¹ã¯ãªãŒã³ã·ã§ãã |
C:UsersPublic{10 æåã®ä»»æã®ã·ãŒã±ã³ã¹}.vbs | ããŒãããŒããŒãã·ã¹ãã ã«æ¥ç¶ããããã«äœ¿çšã§ãã vbs ãã¡ã€ã«ãžã®ãã¹ |
%Temp%{ã«ã¹ã¿ã ãã©ã«ããŒå}{ãã¡ã€ã«å} | ããŒãããŒããŒãã·ã¹ãã ã«æ¥ç¶ããããã«äœ¿çšãããã¹ |
æ»æè ã®ãããã£ãŒã«
ããŒãã³ãŒããããèªèšŒããŒã¿ã®ãããã§ãã³ãã³ã ã»ã³ã¿ãŒã«ã¢ã¯ã»ã¹ããããšãã§ããŸããã
ããã«ãããæ»æè
ã®æçµçãªé»åã¡ãŒã«ãç¹å®ããããšãã§ããŸããã
junaid[.]in***@gmail[.]com.
ã³ãã³ãã»ã³ã¿ãŒã®ãã¡ã€ã³åãã¡ãŒã«ã«ç»é²ãããŸã sg***@gmail[.]com.
ãŸãšã
æ»æã«äœ¿çšããããã«ãŠã§ã¢ã詳现ã«åæããçµæããã®æ©èœã確ç«ãããã®ã±ãŒã¹ã«é¢é£ãã䟵害ã®çè·¡ã®æãå®å šãªãªã¹ããååŸããããšãã§ããŸããããã«ãŠã§ã¢éã®ãããã¯ãŒã¯çžäºäœçšã®ã¡ã«ããºã ãç解ããããšã§ãæ å ±ã»ãã¥ãªã㣠ããŒã«ã®åäœã調æŽããããã®æšå¥šäºé ãæ瀺ããããå®å®ãã IDS ã«ãŒã«ãäœæãããã§ããããã«ãªããŸããã
äž»ãªå±éº ãšãŒãžã§ã³ããã¹ã© ã·ã¹ãã ã«ã³ãããããããå¶åŸ¡ã³ãã³ããã¿ã¹ã¯ãå®è¡ããã®ãåŸ ã€å¿ èŠããªããšããç¹ã§ DataStealer ãšåæ§ã§ãããã·ã³ã«æ¥ç¶ããããšãããã«å人æ å ±ã®åéãéå§ãããããã CnC ã«è»¢éãããŸãããã®æ»æçãªåäœã¯ãããæå³ã§ã©ã³ãµã ãŠã§ã¢ã®åäœã«äŒŒãŠããŸãããå¯äžã®éãã¯ãåŸè ã¯ãããã¯ãŒã¯æ¥ç¶ããå¿ èŠãšããªãããšã§ãããã®ãã¡ããªãŒã«ééããå Žåã¯ãææããã·ã¹ãã ãããã«ãŠã§ã¢èªäœãé§é€ããåŸãå°ãªããšãçè«çã«ã¯äžèšã®ã¢ããªã±ãŒã·ã§ã³ã®ããããã«ä¿åãããŠããå¯èœæ§ã®ãããã¹ãŠã®ãã¹ã¯ãŒããå¿ ãå€æŽããå¿ èŠããããŸãã
ä»åŸã®ããšãèããŠãæ»æè ã次ã®ãããªã¡ãã»ãŒãžãéä¿¡ãããšããŸãã ãšãŒãžã§ã³ããã¹ã©ãåæããŒãããŒããŒã¯éåžžã«é »ç¹ã«å€æŽãããŸããããã«ãããæ»ææã«éçã¹ãã£ããŒããã¥ãŒãªã¹ãã£ã㯠ã¢ãã©ã€ã¶ãŒã«æ°ã¥ãããã«æžã¿ãŸãããããŠããã®å®¶æã¯ãââãã«æŽ»åãéå§ããåŸåããããããã·ã¹ãã ã¢ãã¿ãŒã¯åœ¹ã«ç«ã¡ãŸããã AgentTesla ã«å¯Ÿæããæåã®æ¹æ³ã¯ããµã³ãããã¯ã¹ã§ã®äºååæã§ãã
ãã®ã·ãªãŒãºã® 3 åç®ã®èšäºã§ã¯ã䜿çšãããŠããä»ã®ããŒãããŒããŒã«ã€ããŠèŠãŠãããŸãã ãšãŒãžã§ã³ããã¹ã©ããŸããåèªå解åã®ããã»ã¹ãç 究ããŸãããèŠéããªãïŒ
ããã·ã¥
SHA1 |
A8C2765B3D655BA23886D663D22BDD8EF6E8E894 |
8010CC2AF398F9F951555F7D481CE13DF60BBECF |
79B445DE923C92BF378B19D12A309C0E9C5851BF |
15839B7AB0417FA35F2858722F0BD47BDF840D62 |
1C981EF3EEA8548A30E8D7BF8D0D61F9224288DD |
CïŒC
URL |
sina-c0m[.]icu |
smtp[.]sina-c0m[.]icu |
ç»é²ããŒ
ã¬ãžã¹ã㪠|
HKCUSoftwareMicrosoftWindowsCurrentVersionRun{ã¹ã¯ãªããå} |
HKCUSoftwareMicrosoftWindowsCurrentVersionRun%insregname% |
HKCUSOFTWAREMicrosoftWindowsCurrentVersionExplorerStartupApprovedRun%insregname% |
ãã¥ãŒããã¯ã¹
ææšã¯ãããŸããã
ãã¡ã€ã«ã¢ã¯ãã£ãã㣠|
%Temp%temp.tmp |
%startupfolder%%insfolder%%insname% |
%Temp%tmpG{ããªç§åäœã®çŸåšã®æå»}.tmp |
%Temp%log.tmp |
%AppData%{ä»»æã® 10 æåã®ã·ãŒã±ã³ã¹}.jpeg |
C:UsersPublic{10 æåã®ä»»æã®ã·ãŒã±ã³ã¹}.vbs |
%Temp%{ã«ã¹ã¿ã ãã©ã«ããŒå}{ãã¡ã€ã«å} |
ãµã³ãã«æ å ±
åå | æªç¥ã® |
MD5 | F7722DD8660B261EA13B710062B59C43 |
SHA1 | 15839B7AB0417FA35F2858722F0BD47BDF840D62 |
SHA256 | 41DC0D5459F25E2FDCF8797948A7B315D3CB0753 98D808D1772CACCC726AF6E9 |
ã¿ã€ã | PE (.NET) |
ãµã€ãº | 327680 |
å ã®åå | AZZRIDKGGSLTYFUUBCCRRCUMRKTOXFVPDKGAGPUZI_20190701133545943.exe |
æ¥ä»ã¹ã¿ã³ã | 01.07.2019 |
ã³ã³ãã€ã© | VB.NET |
åå | IELibrary.dll |
MD5 | BFB160A89F4A607A60464631ED3ED9FD |
SHA1 | 1C981EF3EEA8548A30E8D7BF8D0D61F9224288DD |
SHA256 | D55800A825792F55999ABDAD199DFA54F3184417 215A298910F2C12CD9CC31EE |
ã¿ã€ã | PE (.NET DLL) |
ãµã€ãº | 16896 |
å ã®åå | IELibrary.dll |
æ¥ä»ã¹ã¿ã³ã | 11.10.2016 |
ã³ã³ãã€ã© | Microsoft ãªã³ã«ãŒ(48.0*) |
åºæïŒ habr.com