ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ืขืก ื–ืขื ืขืŸ ืคืืจืืŸ ืขื˜ืœื™ื›ืข ื‘ืืงืื ื˜ืข ืกื™ื™ื‘ืขืจ ื’ืจื•ืคืขืก ื•ื•ืขืœื›ืข ืกืคืขืฆื™ืืœื™ื–ื™ืจืŸ ื–ื™ืš ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืคื™ืจืžืขืก. ืžื™ืจ ื”ืึธื‘ืŸ ื’ืขื–ืขืŸ ืื ืคืืœืŸ ื ื™ืฆืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืœื•ืคึผื›ืึธื•ืœื– ื•ื•ืึธืก ืœืึธื–ืŸ ืึทืงืกืขืก ืฆื• ื“ื™ ื ืขืฅ ืคื•ืŸ ื“ื™ ืฆื™ืœ. ืึทืžืึธืœ ื–ื™ื™ ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก, ืึทื˜ืึทืงืขืจื– ืœืขืจื ืขืŸ ื“ื™ ื ืขืฅ ืกื˜ืจื•ืงื˜ื•ืจ ืคื•ืŸ ื“ื™ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืื•ืŸ ืฆืขื•ื•ื™ืงืœืขืŸ ื–ื™ื™ืขืจ ืื™ื™ื’ืขื ืข ืžื›ืฉื™ืจื™ื ืฆื• ื’ืึทื ื•ื•ืขื ืขืŸ ื’ืขืœื˜. ื ืงืœืึทืกื™ืฉ ื‘ื™ื™ึทืฉืคึผื™ืœ ืคื•ืŸ ื“ืขื ื’ืึทื ื’ ืื™ื– ื“ื™ ื”ืขืงืขืจ ื’ืจื•ืคึผืขืก ื‘ื•ื”ื˜ืจืึทืคึผ, ืงืึธื‘ืึทืœื˜ ืื•ืŸ ืงืึธืจืงืึธื•ื•.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ RTM ื’ืจื•ืคึผืข ื•ื•ืึธืก ื“ืขืจ ื‘ืึทืจื™ื›ื˜ ืคืึธื•ืงื™ืกื™ื– ืื•ื™ืฃ ืื™ื– ื˜ื™ื™ืœ ืคื•ืŸ ื“ืขื ื’ืึทื ื’. ืขืก ื ื™ืฆื˜ ืกืคึผืขืฉืึทืœื™ ื“ื™ื–ื™ื™ื ื“ ืžืึทืœื•ื•ืึทืจืข ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ืขืœืคื™, ื•ื•ืึธืก ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ืžืขืจ ื“ืขื˜ืึทืœ ืื™ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืกืขืงืฉืึทื ื–. ื“ื™ ืขืจืฉื˜ืข ื˜ืจืึทืกืขืก ืคื•ืŸ ื“ื™ ืžื›ืฉื™ืจื™ื ืื™ืŸ ื“ื™ ESET ื˜ืขืœืขืžืขื˜ืจื™ ืกื™ืกื˜ืขื ื–ืขื ืขืŸ ื“ื™ืกืงืึทื•ื•ืขืจื“ ืื™ืŸ ื“ื™ ืกื•ืฃ ืคื•ืŸ 2015. ื“ื™ ืžืึทื ืฉืึทืคึฟื˜ ืœืึธื•ื“ื– ืคืึทืจืฉื™ื“ืŸ ื ื™ื™ึทืข ืžืึทื“ื–ืฉื•ืœื– ืื•ื™ืฃ ื™ื ืคืขืงื˜ืึทื“ ืกื™ืกื˜ืขืžืขืŸ ื•ื•ื™ ื“ืืจืฃ. ื“ื™ ืื˜ืืงืขืก ื–ืขื ืขืŸ ื’ืขืฆื™ืœื˜ ืื•ื™ืฃ ื‘ืื ื•ืฆืขืจ ืคื•ืŸ ื•ื•ื™ื™ื˜ืข ื‘ืื ืง ืกื™ืกื˜ืขืžืขืŸ ืื™ืŸ ืจื•ืกืœืื ื“ ืื•ืŸ ืขื˜ืœื™ื›ืข ืืจื•ืžื™ืงืข ืœืขื ื“ืขืจ.

1. ืฆื™ืœืŸ

ื“ื™ RTM ืงืืžืคืื ื™ืข ืื™ื– ืึทื™ืžืขื“ ืฆื• ืคึฟื™ืจืžืข ื ื™ืฆืขืจืก - ื“ืึธืก ืื™ื– ืงืœืึธืจ ื•ื•ื™ ื“ืขืจ ื˜ืึธื’ ืคื•ืŸ ื“ื™ ืคึผืจืึทืกืขืกืึทื– ื•ื•ืึธืก ืึทื˜ืึทืงืขืจื– ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื“ืขื˜ืขืงื˜ ืื™ืŸ ืึท ืงืึทืžืคึผืจืึทืžื™ื™ื–ื“ ืกื™ืกื˜ืขื. ื“ืขืจ ืคืึธืงื•ืก ืื™ื– ืื•ื™ืฃ ืึทืงืึทื•ื ื˜ื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ.

ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ืคึผืจืึทืกืขืกืึทื– ืคื•ืŸ ืื™ื ื˜ืขืจืขืก ืฆื• RTM ืจื™ื–ืขืžื‘ืึทืœื– ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืจืฉื™ืžื” ืคื•ืŸ ื“ื™ ื‘ื•ื”ื˜ืจืึทืคึผ ื’ืจื•ืคึผืข, ืึธื‘ืขืจ ื“ื™ ื’ืจื•ืคึผืขืก ื”ืึธื‘ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื™ื ืคืขืงืฆื™ืข ื•ื•ืขืงื˜ืึธืจืก. ืื•ื™ื‘ Buhtrap ื’ืขื•ื•ื™ื™ื ื˜ ืฉื•ื•ื™ื ื“ืœ ื‘ืœืขื˜ืขืจ ืžืขืจ ืึธืคื˜, RTM ื’ืขื•ื•ื™ื™ื ื˜ ื“ืจื™ื™ื•ื•-ื“ื•ืจืš ืืจืืคืงืืคื™ืข ืื ืคืืœืŸ (ืึทื˜ืึทืงืก ืื•ื™ืฃ ื“ืขื ื‘ืœืขื˜ืขืจืขืจ ืึธื“ืขืจ ื–ื™ื™ึทืŸ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ) ืื•ืŸ ืกืคึผืึทืžื™ื ื’ ื“ื•ืจืš E- ื‘ืจื™ื•ื•. ืœื•ื™ื˜ ื˜ืขืœืขืžืขื˜ืจื™ ื“ืึทื˜ืŸ, ื“ื™ ืกืึทืงืึธื ืข ืื™ื– ืึทื™ืžืขื“ ืฆื• ืจื•ืกืœืึทื ื“ ืื•ืŸ ืขื˜ืœืขื›ืข ื ื™ืจื‘ื™ื™ ืœืขื ื“ืขืจ (ืื•ืงืจื™ื™ื ื, ืงืึทื–ืึทื›ืกื˜ืึทืŸ, ื˜ืฉืขื›ื™ื™, ื“ื™ื™ึทื˜ืฉืœืึทื ื“). ืึธื‘ืขืจ, ืจืขื›ื˜ ืฆื• ื“ืขืจ ื ื•ืฆืŸ ืคื•ืŸ ืžืึทืกืข ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืžืขืงืึทื ื™ื–ืึทืžื–, ื“ื™ื˜ืขืงืฉืึทืŸ ืคื•ืŸ ืžืึทืœื•ื•ืึทืจืข ืึทืจื•ื™ืก ื“ื™ ืฆื™ืœ ืžืงื•ืžื•ืช ืื™ื– ื ื™ืฉื˜ ื—ื™ื“ื•ืฉ.

ื“ื™ ื’ืึทื ืฅ ื ื•ืžืขืจ ืคื•ืŸ ืžืึทืœื•ื•ืึทืจืข ื“ื™ื˜ืขืงืฉืึทื ื– ืื™ื– ืœืขืคื™ืขืจืขืš ืงืœื™ื™ืŸ. ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื”ืึทื ื˜, ื“ื™ RTM ืงืืžืคืื ื™ืข ื ื™ืฆื˜ ืงืึธืžืคึผืœืขืงืก ืžื’ื™ืœื”, ื•ื•ืึธืก ื™ื ื“ื™ืงื™ื™ืฅ ืึทื– ื“ื™ ืึทื˜ืึทืงืก ื–ืขื ืขืŸ ื”ืขื›ืกื˜ ื˜ืึทืจื’ืขื˜ืขื“.

ืžื™ืจ ื”ืึธื‘ืŸ ื“ื™ืกืงืึทื•ื•ืขืจื“ ืขื˜ืœืขื›ืข ื“ืขืงืึธื• ื“ืึธืงื•ืžืขื ื˜ืŸ ื’ืขื ื™ืฆื˜ ื“ื•ืจืš RTM, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื ื™ื˜-ืขื’ื–ื™ืกื˜ืึทื ื˜ ืงืึทื ื˜ืจืึทืงืฅ, ื™ื ื•ื•ื•ื™ืกื™ื– ืึธื“ืขืจ ืฉื˜ื™ื™ืขืจ ืึทืงืึทื•ื ื˜ื™ื ื’ ื“ืึธืงื•ืžืขื ื˜ืŸ. ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ื™ ืœื•ืจื–, ืงืึทืžื‘ื™ื™ื ื“ ืžื™ื˜ ื“ื™ ื˜ื™ืคึผ ืคื•ืŸ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื˜ืึทืจื’ืขื˜ืขื“ ื“ื•ืจืš ื“ื™ ื‘ืึทืคืึทืœืŸ, ื™ื ื“ื™ืงื™ื™ืฅ ืึทื– ื“ื™ ืึทื˜ืึทืงืขืจื– "ืึทืจื™ื™ึทืŸ" ื“ื™ ื ืขื˜ื•ื•ืึธืจืงืก ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก ื“ื•ืจืš ื“ื™ ืึทืงืึทื•ื ื˜ื™ื ื’ ืึธืคึผื˜ื™ื™ืœื•ื ื’. ื“ ื™ ื’ืจื•ืค ืข ื”ื ื˜ ื’ืขื”ื ื˜ ืœื•ื™ื˜ ืŸ ื–ืขืœื‘ื™ืง ืŸ ืกื›ืขืžืข ื‘ื•ื”ื˜ืจืึทืคึผ ืื™ืŸ 2014-2015

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื‘ืขืฉืึทืก ื“ืขืจ ืคืึธืจืฉื•ื ื’, ืžื™ืจ ื–ืขื ืขืŸ ื‘ื™ื›ื•ืœืช ืฆื• ื™ื ื˜ืขืจืึทืงื˜ ืžื™ื˜ ืขื˜ืœืขื›ืข C&C ืกืขืจื•ื•ืขืจืก. ืžื™ืจ ื•ื•ืขืœืŸ ืจืฉื™ืžื” ื“ื™ ืคื•ืœ ืจืฉื™ืžื” ืคื•ืŸ ืงืึทืžืึทื ื“ื– ืื™ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืกืขืงืฉืึทื ื–, ืึธื‘ืขืจ ืื™ืฆื˜ ืžื™ืจ ืงืขื ืขืŸ ื–ืึธื’ืŸ ืึทื– ื“ืขืจ ืงืœื™ืขื ื˜ ื˜ืจืึทื ืกืคืขืจืก ื“ืึทื˜ืŸ ืคื•ืŸ ื“ื™ ืงื™ื™ืœืึธื’ื’ืขืจ ื’ืœื™ื™ึทืš ืฆื• ื“ื™ ืึทื˜ืึทืงื™ื ื’ ืกืขืจื•ื•ืขืจ, ืคึฟื•ืŸ ื•ื•ืึธืก ื ืึธืš ืงืึทืžืึทื ื“ื– ื–ืขื ืขืŸ ื‘ืืงื•ืžืขืŸ.

ืึธื‘ืขืจ, ื“ื™ ื˜ืขื’ ื•ื•ืขืŸ ืื™ืจ ืงืขืŸ ืคืฉื•ื˜ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืึท ื‘ืึทืคึฟืขืœ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ ืื•ืŸ ืงืœื™ื™ึทื‘ืŸ ืึทืœืข ื“ื™ ื“ืึทื˜ืŸ ื•ื•ืึธืก ืื™ืจ ื”ืึธื˜ ืื™ื ื˜ืขืจืขืกื™ืจื˜ ื–ืขื ืขืŸ ื ื™ื˜ืึธ. ืžื™ืจ ืจื™ืงืจื™ื™ื™ื˜ื™ื“ ืจืขืึทืœื™ืกื˜ื™ืฉ ืงืœืึธืฅ ื˜ืขืงืขืก ืฆื• ื‘ืึทืงื•ืžืขืŸ ืขื˜ืœืขื›ืข ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ืงืึทืžืึทื ื“ื– ืคื•ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ.

ื“ืขืจ ืขืจืฉื˜ืขืจ ืคื•ืŸ ื–ื™ื™ ืื™ื– ืึท ื‘ืงืฉื” ืฆื• ื“ื™ ื‘ืึธื˜ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ ื˜ืขืงืข 1c_to_kl.txt - ืึท ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื˜ืขืงืข ืคื•ืŸ โ€‹โ€‹ื“ื™ 1C: ืขื ื˜ืขืจืคึผืจื™ื™ื– 8 ืคึผืจืึธื’ืจืึทื, ื“ื™ ืื•ื™ืกื–ืขืŸ ืคื•ืŸ ื•ื•ืึธืก ืื™ื– ืึทืงื˜ื™ื•ื•ืœื™ ืžืึธื ื™ื˜ืึธืจืขื“ ื“ื•ืจืš ืจื˜ื. 1C ื™ื ื˜ืขืจืึทืงืฅ ืžื™ื˜ ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ ื“ื•ืจืš ื•ืคึผืœืึธืึทื“ื™ื ื’ ื“ืึทื˜ืŸ ืื•ื™ืฃ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผื™ื™ืžืึทื ืฅ ืฆื• ืึท ื˜ืขืงืกื˜ ื˜ืขืงืข. ื“ืขืจื ืึธืš, ื“ื™ ื˜ืขืงืข ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขื ืคึฟืึทืจ ืึธื˜ืึทืžื™ื™ืฉืึทืŸ ืื•ืŸ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ืฆืึธืœื•ื ื’ ืกื“ืจ.

ื“ืขืจ ื˜ืขืงืข ื›ึผื•ืœืœ ืฆืึธืœื•ื ื’ ื“ืขื˜ืึทื™ืœืก. ืื•ื™ื‘ ืึทื˜ืึทืงืขืจื– ื˜ื•ื™ืฉืŸ ื“ื™ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคึผื™ื™ืžืึทื ืฅ, ื“ื™ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉื™ืงื˜ ืžื™ื˜ ืคืึทืœืฉ ื“ืขื˜ืึทื™ืœืก ืฆื• ื“ื™ ืึทืงืึทื•ื ืฅ ืคื•ืŸ ืึทื˜ืึทืงืขืจื–.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื‘ืขืขืจืขืš ืึท ื—ื•ื“ืฉ ื ืึธืš ืจื™ืงื•ื•ืขืกื˜ื™ื ื’ ื“ื™ ื˜ืขืงืขืก ืคึฟื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ, ืžื™ืจ ื‘ืืžืขืจืงื˜ ืึทื– ืึท ื ื™ื™ึทืข ืคึผืœื•ื’ื™ืŸ, 1c_2_kl.dll, ืื™ื– ืœืึธื•ื“ื™ื“ ืื•ื™ืฃ ื“ื™ ืงืึทืžืคึผืจืึทืžื™ื™ื–ื“ ืกื™ืกื˜ืขื. ื“ืขืจ ืžืึธื“ื•ืœืข (ื“ืœืœ) ืื™ื– ื“ื™ื–ื™ื™ื ื“ ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืึทื ืึทืœื™ื™ื– ื“ื™ ืืจืืคืงืืคื™ืข ื˜ืขืงืข ื“ื•ืจืš ื“ื•ืจื›ื“ืจื™ื ื’ ื“ื™ ืึทืงืึทื•ื ื˜ื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืคึผืจืึทืกืขืกืึทื–. ืžื™ืจ ื•ื•ืขืœืŸ ื‘ืึทืฉืจื™ื™ึทื‘ืŸ ืขืก ืื™ืŸ ื“ืขื˜ืึทืœ ืื™ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืกืขืงืฉืึทื ื–.

ื™ื ื˜ืขืจืขืกื˜ื™ื ื’ืœื™, FinCERT ืคื•ืŸ ื“ื™ ื‘ืึทื ืง ืคื•ืŸ ืจื•ืกืœืึทื ื“ ืื™ืŸ ื“ื™ ืกื•ืฃ ืคื•ืŸ 2016 ืืจื•ื™ืก ืึท ื‘ื•ืœื™ื˜ืึทืŸ ื•ื•ืืจืขื ื•ื ื’ ื•ื•ืขื’ืŸ ืกื™ื™ื‘ืขืจ ืงืจื™ืžืึทื ืึทืœื– ื ื™ืฆืŸ 1c_to_kl.txt ืฆื•ืคึฟืขืœื™ืงืขืจ ื˜ืขืงืขืก. ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืคื•ืŸ 1C ืื•ื™ืš ื•ื•ื™ืกืŸ ื•ื•ืขื’ืŸ ื“ืขื ืกื›ืขืžืข ื–ื™ื™ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื’ืขืžืื›ื˜ ืึท ื‘ืึทืึทืžื˜ืขืจ ื•ื™ืกื–ืึธื’ื•ื ื’ ืื•ืŸ ืœื™ืกื˜ืขื“ ืคึผืจื™ืงืึธืฉืึทื ื–.

ืื ื“ืขืจืข ืžืึทื“ื–ืฉื•ืœื– ื–ืขื ืขืŸ ืื•ื™ืš ืœืึธื•ื“ื™ื“ ืคึฟื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืกืขืจื•ื•ืขืจ, ืกืคึผืขืฆื™ืขืœ VNC (ื–ื™ื™ึทืŸ 32 ืื•ืŸ 64-ื‘ื™ืกืœ ื•ื•ืขืจืกื™ืขืก). ืขืก ืจื™ื–ืขืžื‘ืึทืœื– ื“ื™ VNC ืžืึธื“ื•ืœืข ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคืจื™ืขืจ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ืจื™ื“ืขืงืก ื˜ืจืึธื“ื–ืฉืึทืŸ ืื ืคืืœืŸ. ื“ืขืจ ืžืึธื“ื•ืœืข ืื™ื– ืกืึทืคึผืึธื•ื–ืึทื“ืœื™ ื’ืขื ื™ืฆื˜ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืึท ื™ื ืคืขืงื˜ืึทื“ ืงืึธืžืคึผื™ื•ื˜ืขืจ ืื•ืŸ ื“ื•ืจื›ืคื™ืจืŸ ืึท ื“ื™ื˜ื™ื™ืœื“ ืœืขืจื ืขืŸ ืคื•ืŸ ื“ื™ ืกื™ืกื˜ืขื. ื“ืขืจื ืึธืš, ื“ื™ ืึทื˜ืึทืงืขืจื– ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ืžืึทืš ืึทืจื•ื ื“ื™ ื ืขืฅ, ื™ืงืกื˜ืจืึทืงื˜ื™ื ื’ ื‘ืึทื ื™ืฆืขืจ ืคึผืึทืกื•ื•ืขืจื“ื–, ืงืึทืœืขืงื˜ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ื™ื ืฉื•ืจื™ื ื’ ื“ื™ ืงืขืกื™ื™ื“ืขืจื“ื™ืง ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืžืึทืœื•ื•ืึทืจืข.

2. ื•ื•ืขืงื˜ืึธืจืก ืคื•ืŸ ื™ื ืคืขืงืฆื™ืข

ื“ื™ ืคืืœื’ืขื ื“ืข ืคื™ื’ื•ืจ ื•ื•ื™ื™ื–ื˜ ื“ื™ ื™ื ืคืขืงืฆื™ืข ื•ื•ืขืงื˜ืึธืจืก ื“ื™ื˜ืขืงื˜ืึทื“ ื‘ืขืฉืึทืก ื“ื™ ืœืขืจื ืขืŸ ืฆื™ื™ื˜ ืคื•ืŸ ื“ื™ ืงืืžืคืื ื™ืข. ื“ื™ ื’ืจื•ืคึผืข ื ื™ืฆื˜ ืึท ื‘ืจื™ื™ื˜ ืงื™ื™ื˜ ืคื•ืŸ ื•ื•ืขืงื˜ืึธืจืก, ืึธื‘ืขืจ ื“ืขืจ ื”ื•ื™ืคึผื˜ ื“ืจื™ื™ื•ื•ื™ื ื’ ืืจืืคืงืืคื™ืข ืื ืคืืœืŸ ืื•ืŸ ืกืคึผืึทื. ื“ื™ ืžื›ืฉื™ืจื™ื ื–ืขื ืขืŸ ื‘ืึทืงื•ื•ืขื ืคึฟืึทืจ ื˜ืึทืจื’ืขื˜ืขื“ ืื ืคืืœืŸ, ื•ื•ื™ื™ึทืœ ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืคืึทืœ, ืึทื˜ืึทืงืขืจื– ืงืขื ืขืŸ ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื–ื™ื™ื˜ืœืขืš ื‘ืื–ื•ื›ื˜ ื“ื•ืจืš ืคึผืึธื˜ืขื ืฆื™ืขืœ ื•ื•ื™ืงื˜ื™ืžืก, ืื•ืŸ ืื™ืŸ ื“ื™ ืจื’ืข, ื–ื™ื™ ืงืขื ืขืŸ ืฉื™ืงืŸ E- ื‘ืจื™ื•ื• ืžื™ื˜ ืึทื˜ืึทื˜ืฉืžืึทื ืฅ ื’ืœื™ื™ึทืš ืฆื• ื“ื™ ื’ืขื‘ืขื˜ืŸ ืคื™ืจืžืข ืขืžืคึผืœื•ื™ื™ื–.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ื“ื•ืจืš ืงื™ื™ืคืœ ื˜ืฉืึทื ืึทืœื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ RIG ืื•ืŸ Sundown ืขืงืกืคึผืœื•ื™ื˜ ืงื™ืฅ ืึธื“ืขืจ ืกืคึผืึทื ืžื™ื™ืœื™ื ื’ื–, ื•ื•ืึธืก ื™ื ื“ื™ืงื™ื™ืฅ ืงืึทื ืขืงืฉืึทื ื– ืฆื•ื•ื™ืฉืŸ ื“ื™ ืึทื˜ืึทืงืขืจื– ืื•ืŸ ืื ื“ืขืจืข ืกื™ื™ื‘ืขืจืึทื˜ื˜ืึทืงืขืจื– ื•ื•ืึธืก ืคืึธืจืฉืœืึธื’ืŸ ื“ื™ ืกืขืจื•ื•ื™ืกืขืก.

2.1. ื•ื•ื™ ื–ืขื ืขืŸ RTM ืื•ืŸ Buhtrap ืฉื™ื™ึทื›ื•ืช?

ื“ื™ RTM ืงืืžืคืื ื™ืข ืื™ื– ื–ื™ื™ืขืจ ืขื ืœืขืš ืฆื• Buhtrap. ื“ื™ ื ืึทื˜ื™ืจืœืขืš ืงืฉื™ื ืื™ื–: ื•ื•ื™ ื–ืขื ืขืŸ ื–ื™ื™ ืฉื™ื™ึทื›ื•ืช ืฆื• ื™ืขื“ืขืจ ืื ื“ืขืจืขืจ?

ืื™ืŸ ืกืขืคื˜ืขืžื‘ืขืจ 2016, ืžื™ืจ ื‘ืืžืขืจืงื˜ ืึทื– ืึท RTM ืžื•ืกื˜ืขืจ ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืžื™ื˜ ื“ื™ Buhtrap ื•ืคึผืœืึธืึทื“ืขืจ. ืึทื“ื“ื™ื˜ื™ืึธื ืึทืœืœื™, ืžื™ืจ ื’ืขืคึฟื•ื ืขืŸ ืฆื•ื•ื™ื™ ื“ื™ื’ื™ื˜ืึทืœ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื’ืขื ื™ืฆื˜ ืื™ืŸ Buhtrap ืื•ืŸ RTM.

ื“ืขืจ ืขืจืฉื˜ืขืจ, ืึทืœืขื“ื–ืฉืึทื“ืœื™ ืืจื•ื™ืก ืฆื• ื“ื™ ืคื™ืจืžืข DNSTER-M, ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื“ื™ื’ื™ื˜ืึทืœืœื™ ืฆื™ื™ื›ืŸ ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ื“ืขืœืคื™ ืคืึธืจืขื (SHA-1: 025C718BA31E43DB1B87DC13F94A61A9338C11CE) ืื•ืŸ ื“ื™ Buhtrap DLL (SHA-1: 1).

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ ืฆื•ื•ื™ื™ื˜ืข, ืืจื•ื™ืก ืฆื• Bit-Tredj, ืื™ื– ื’ืขื ื•ืฆื˜ ืฆื• ืฆื™ื™ื›ืŸ ื‘ื•ื”ื˜ืจืึทืคึผ ืœืึธื•ื“ืขืจื– (SHA-1: 7C1B6B1713BD923FC243DFEC80002FE9B93EB292 ืื•ืŸ B74F71560E48488D2153AE2FB51207A0AC), ื•ื•ื™ ืื•ื™ืš ืืจืืคืงืืคื™ืข ืื•ืŸ ืืจืืคืงืืคื™ืข ืงืึทืžืคึผืึธื•ื ืึทื ืฅ.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

RTM ืึธืคึผืขืจื™ื™ื˜ืขืจื– ื ื•ืฆืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื•ื•ืึธืก ื–ืขื ืขืŸ ืคึผืจืึธืกื˜ ืคึฟืึทืจ ืื ื“ืขืจืข ืžืึทืœื•ื•ืึทืจืข ืคืึทืžื™ืœื™ืขืก, ืึธื‘ืขืจ ื–ื™ื™ ืื•ื™ืš ื”ืึธื‘ืŸ ืึท ื™ื™ื ืฆื™ืง ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ืœื•ื™ื˜ ESET ื˜ืขืœืขืžืขื˜ืจื™, ืขืก ืื™ื– ืืจื•ื™ืก ืฆื• ืงื™ื˜-ืกื“ ืื•ืŸ ืื™ื– ื‘ืœื•ื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืฆื™ื™ื›ืŸ ืขื˜ืœืขื›ืข RTM ืžืึทืœื•ื•ืึทืจืข (SHA-1: 42A4B04446A20993DDAE98B2BE6D5A797376D4B6).

RTM ื ื™ืฆื˜ ื“ื™ ื–ืขืœื‘ืข ืœืึธื•ื“ืขืจ ื•ื•ื™ Buhtrap, RTM ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ื–ืขื ืขืŸ ืœืึธื•ื“ื™ื“ ืคึฟื•ืŸ ื“ื™ Buhtrap ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ, ืึทื–ื•ื™ ื“ื™ ื’ืจื•ืคึผืขืก ื”ืึธื‘ืŸ ืขื ืœืขืš ื ืขืฅ ื™ื ื“ื™ืงืึทื˜ืึธืจืก. ืึธื‘ืขืจ, ืœื•ื™ื˜ ืื•ื ื“ื–ืขืจ ืขืกื˜ืึทืžืึทืฅ, RTM ืื•ืŸ Buhtrap ื–ืขื ืขืŸ ืคืึทืจืฉื™ื“ืขื ืข ื’ืจื•ืคึผืขืก, ืœืคึผื—ื•ืช ื•ื•ื™ื™ึทืœ RTM ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื™ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขื’ืŸ (ื ื™ื˜ ื‘ืœื•ื™ื– ื ื™ืฆืŸ ืึท "ืคืจืขืžื“" ื“ืึธื•ื•ื ืœืึธืึทื“ืขืจ).

ื˜ืจืึธืฅ ื“ืขื, ื”ืขืงืขืจ ื’ืจื•ืคึผืขืก ื ื•ืฆืŸ ืขื ืœืขืš ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ืคึผืจื™ื ืฆื™ืคึผืŸ. ื–ื™ื™ ืฆื™ืœืŸ ื’ืขืฉืขืคื˜ืŸ ื ื™ืฆืŸ ืึทืงืึทื•ื ื˜ื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’, ืกื™ืžื™ืœืึทืจืœื™ ืงืึทืœืขืงื˜ื™ื ื’ ืกื™ืกื˜ืขื ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื–ื•ื›ืŸ ืคึฟืึทืจ ืกืžืึทืจื˜ ืงืึทืจื˜ืœ ืœื™ื™ืขื ืขืจ ืื•ืŸ ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึท ืงื™ื™ื˜ ืคื•ืŸ ื‘ื™ื™ื–ืข ืžื›ืฉื™ืจื™ื ืฆื• ืฉืคึผื™ืึธืŸ ืื•ื™ืฃ ื•ื•ื™ืงื˜ื™ืžืก.

3. ืขื•ื•ืึทืœื•ืฉืึทืŸ

ืื™ืŸ ื“ืขื ืึธืคึผื˜ื™ื™ืœื•ื ื’, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ื“ื™ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ืžืึทืœื•ื•ืึทืจืข ื’ืขืคึฟื•ื ืขืŸ ื‘ืขืฉืึทืก ื“ืขื ืœืขืจื ืขืŸ.

3.1. ื•ื•ืขืจืกื™ืข

RTM ืกื˜ืึธืจื– ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื“ืึทื˜ืŸ ืื™ืŸ ืึท ืจืขื’ื™ืกื˜ืจื™ ืึธืคึผื˜ื™ื™ืœื•ื ื’, ื“ื™ ืžืขืจืกื˜ ื˜ืฉื™ืงืึทื•ื•ืข ื˜ื™ื™ืœ ืื™ื– ื‘ืึธื˜ื ืขื˜ ืคึผืจืขืคื™ืงืก. ื ืจืฉื™ืžื” ืคื•ืŸ ืึทืœืข ื“ื™ ื•ื•ืึทืœื•ืขืก ื•ื•ืึธืก ืžื™ืจ ื”ืึธื‘ืŸ ื’ืขื–ืขืŸ ืื™ืŸ ื“ื™ ืกืึทืžืคึผืึทืœื– ืžื™ืจ ื’ืขืœืขืจื ื˜ ืื™ื– ื“ืขืจืœืื ื’ื˜ ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืื•ื ื˜ืŸ.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ืขืก ืื™ื– ืžืขื’ืœืขืš ืึทื– ื“ื™ ื•ื•ืึทืœื•ืขืก ืงืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืจืขืงืึธืจื“ื™ืจืŸ ืžืึทืœื•ื•ืึทืจืข ื•ื•ืขืจืกื™ืขืก. ืึธื‘ืขืจ, ืžื™ืจ ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื‘ืืžืขืจืงื˜ ืคื™ืœ ื—ื™ืœื•ืง ืฆื•ื•ื™ืฉืŸ ื•ื•ืขืจืกื™ืขืก ืึทื–ืึท ื•ื•ื™ ื‘ื™ื˜2 ืื•ืŸ ื‘ื™ื˜3, 0.1.6.4 ืื•ืŸ 0.1.6.6. ื“ืขืจืฆื•, ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืคึผืจืขืคื™ืงืกื™ื– ืื™ื– ื’ืขื•ื•ืขืŸ ืึทืจื•ื ื–ื™ื ื˜ ื“ื™ ืึธื ื”ื™ื™ื‘ ืื•ืŸ ื”ืื˜ ื™ื•ื•ืึทืœื•ื•ื“ ืคื•ืŸ ืึท ื˜ื™ืคึผื™ืฉ C&C ืคืขืœื“ ืฆื• ืึท .ื‘ื™ื˜ ืคืขืœื“, ื•ื•ื™ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื–ืŸ ืื•ื ื˜ืŸ.

3.2. ืคึผืœืึทืŸ

ืžื™ื˜ ื˜ืขืœืขืžืขื˜ืจื™ ื“ืึทื˜ืŸ, ืžื™ืจ ื‘ืืฉืืคืŸ ืึท ื’ืจืึทืคื™ืง ืคื•ืŸ ื“ื™ ืคึผืึทืกื™ืจื•ื ื’ ืคื•ืŸ ืกืึทืžืคึผืึทืœื–.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

4. ื˜ืขื›ื ื™ืฉ ืึทื ืึทืœื™ืกื™ืก

ืื™ืŸ ื“ืขื ืึธืคึผื˜ื™ื™ืœื•ื ื’, ืžื™ืจ ื•ื•ืขืœืŸ ื‘ืึทืฉืจื™ื™ึทื‘ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ืคืึทื ื’ืงืฉืึทื ื– ืคื•ืŸ ื“ื™ RTM ื‘ืึทื ืงื™ื ื’ ื˜ืจืึธื“ื–ืฉืึทืŸ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืงืขื’ื ืฉื˜ืขืœ ืžืขืงืึทื ื™ื–ืึทืžื–, ื–ื™ื™ึทืŸ ืื™ื™ื’ืขื ืข ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ RC4 ืึทืœื’ืขืจื™ื“ืึทื, ื ืขืฅ ืคึผืจืึธื˜ืึธืงืึธืœ, ืกืคึผื™ื™ื™ื ื’ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื•ืŸ ืขื˜ืœืขื›ืข ืื ื“ืขืจืข ืคึฟืขื™ึดืงื™ื™ื˜ืŸ. ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ืžื™ืจ ื•ื•ืขืœืŸ ืคืึธืงื•ืก ืื•ื™ืฃ SHA-1 ืกืึทืžืคึผืึทืœื– AA0FA4584768CE9E16D67D8C529233E99FF1BBF0 ืื•ืŸ 48BC113EC8BA20B8B80CD5D4DA92051A19D1032B.

4.1. ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืื•ืŸ ืฉืคึผืึธืจืŸ

4.1.1. ื™ืžืคึผืœืขืžืขื ื˜ืึทื˜ื™ืึธืŸ

ื“ื™ ืจื˜ื ื”ืึทืจืฅ ืื™ื– ืึท ื“ืœืœ, ื“ื™ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื™ื– ืœืึธื•ื“ื™ื“ ืื•ื™ืฃ ื“ื™ืกืง ื ื™ืฆืŸ. ืขืงืกืข. ื“ื™ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืข ืื™ื– ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืคึผืึทืงื™ื“ื–ืฉื“ ืื•ืŸ ื›ึผื•ืœืœ ื“ืœืœ ืงืึธื“. ืึทืžืึธืœ ืœืึธื ื˜ืฉื˜, ืขืก ืขืงืกื˜ืจืึทืงื˜ ื“ื™ DLL ืื•ืŸ ืœื•ื™ืคื˜ ืขืก ืžื™ื˜ ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืึทืคึฟืขืœ:

rundll32.exe โ€œ%PROGRAMDATA%Winlogonwinlogon.lnkโ€,DllGetClassObject host

4.1.2. ื“ืœืœ

ื“ื™ ื”ื•ื™ืคึผื˜ ื“ืœืœ ืื™ื– ืฉื˜ืขื ื“ื™ืง ืœืึธื•ื“ื™ื“ ืฆื• ื“ื™ืกืง ื•ื•ื™ winlogon.lnk ืื™ืŸ ื“ื™ % PROGRAMDATA% Winlogon ื˜ืขืงืข. ื“ืขืจ ื˜ืขืงืข ื’ืขืฉืคึผืจื™ื™ื˜ ืื™ื– ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืคืืจื‘ื•ื ื“ืŸ ืžื™ื˜ ืึท ื“ื•ืจื›ื•ื•ืขื’, ืึธื‘ืขืจ ื“ื™ ื˜ืขืงืข ืื™ื– ืคืืงื˜ื™ืฉ ืึท ื“ืœืœ ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ืขืœืคื™, ื’ืขื”ื™ื™ืกืŸ ืงืึธืจืข.ื“ืœืœ ื“ื•ืจืš ื“ื™ ื“ืขื•ื•ืขืœืึธืคึผืขืจ, ื•ื•ื™ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ื‘ื™ืœื“ ืื•ื ื˜ืŸ.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ะŸั€ะธะผะตั€ ะฝะฐะทะฒะฐะฝะธั DLL F4C746696B0F5BB565D445EC49DD912993DE6361

ืึทืžืึธืœ ืœืึธื ื˜ืฉื˜, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืึทืงื˜ืึทื•ื•ื™ื™ืฅ ื–ื™ื™ึทืŸ ืงืขื’ื ืฉื˜ืขืœ ืžืขืงืึทื ื™ื–ืึทื. ื“ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ื’ืขื˜ืืŸ ืื™ืŸ ืฆื•ื•ื™ื™ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขื’ืŸ, ื“ื™ืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืคื•ืŸ ื“ื™ ืงืึธืจื‘ืŸ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื. ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืจืขื›ื˜, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืžื•ืกื™ืฃ ืึท Windows Update ืคึผืึธื–ื™ืฆื™ืข ืฆื• ื“ื™ HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun ืจืขื’ื™ืกื˜ืจื™. ื“ื™ ืงืึทืžืึทื ื“ื– ืงืึทื ื˜ื™ื™ื ื“ ืื™ืŸ Windows Update ื•ื•ืขื˜ ืœื•ื™ืคืŸ ืื™ืŸ ื“ื™ ืึธื ื”ื™ื™ื‘ ืคื•ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืก ืกืขืกื™ืข.

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindows Update [REG_SZ] = rundll32.exe โ€œ%PROGRAMDATA%winlogon.lnkโ€,DllGetClassObject host

ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืื•ื™ืš ืคืจื•ื•ื•ื˜ ืฆื• ืœื™ื™ื’ืŸ ืึท ืึทืจื‘ืขื˜ ืฆื• ื“ื™ Windows ื˜ืึทืกืง ืกื˜ืฉืขื“ื•ืœืขืจ. ื“ื™ ืึทืจื‘ืขื˜ ื•ื•ืขื˜ ืงืึทื˜ืขืจ ื“ื™ winlogon.lnk ื“ืœืœ ืžื™ื˜ ื“ื™ ื–ืขืœื‘ืข ืคึผืึทืจืึทืžืขื˜ืขืจืก ื•ื•ื™ ืื•ื™ื‘ืŸ. ืจืขื’ื•ืœืขืจ ื‘ืึทื ื™ืฆืขืจ ืจืขื›ื˜ ืœืึธื–ืŸ ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืฆื• ืœื™ื™ื’ืŸ ืึท Windows Update ืคึผืึธื–ื™ืฆื™ืข ืžื™ื˜ ื“ื™ ื–ืขืœื‘ืข ื“ืึทื˜ืŸ ืฆื• ื“ื™ HKCUSoftwareMicrosoftWindowsCurrentVersionRun ืจืขื’ื™ืกื˜ืจื™:

rundll32.exe โ€œ%PROGRAMDATA%winlogon.lnkโ€,DllGetClassObject host

4.2. ืžืึทื“ืึทืคื™ื™ื“ RC4 ืึทืœื’ืขืจื™ื“ืึทื

ื˜ืจืึธืฅ ื–ื™ื™ืŸ ื‘ืึทื•ื•ื•ืกื˜ ืฉืึธืจื˜ืงืึธืžื™ื ื’ืก, ื“ื™ RC4 ืึทืœื’ืขืจื™ื“ืึทื ืื™ื– ืงืขืกื™ื™ื“ืขืจ ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ืžืึทืœื•ื•ืึทืจืข ืžื—ื‘ืจื™ื. ืึธื‘ืขืจ, ื“ื™ ืงืจื™ื™ื™ื˜ืขืจื– ืคื•ืŸ RTM ืžืึทื“ืึทืคื™ื™ื“ ืขืก ืึท ื‘ื™ืกืœ, ืžื™ืกื˜ืึธืžืข ืฆื• ืžืึทื›ืŸ ื“ื™ ืึทืจื‘ืขื˜ ืคื•ืŸ ื•ื•ื™ืจื•ืก ืึทื ืึทืœื™ืก ืžืขืจ ืฉื•ื•ืขืจ. ื ืžืึทื“ืึทืคื™ื™ื“ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹RC4 ืื™ื– ื•ื•ื™ื™ื“ืœื™ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื‘ื™ื™ื–ืข RTM ืžื›ืฉื™ืจื™ื ืฆื• ืขื ืงืจื™ืคึผื˜ ืกื˜ืจื™ื ื’ืก, ื ืขืฅ ื“ืึทื˜ืŸ, ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื•ืŸ ืžืึทื“ื–ืฉื•ืœื–.

4.2.1. ื“ื™ืคืคืขืจืขื ืกืขืก

ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ RC4 ืึทืœื’ืขืจื™ื“ืึทื ื›ื•ืœืœ ืฆื•ื•ื™ื™ ืกื˜ืึทื’ืขืก: s-ื‘ืœืึธืง ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ (ืึทืงืึท ืงืกืึท - ืฉืœื™ืกืœ-ืกืงืขื“ื–ืฉื•ืœื™ื ื’ ืึทืœื’ืขืจื™ื“ืึทื) ืื•ืŸ ืคึผืกืขื•ื•ื“ืึธ-ืจืึทื ื“ืึธื ืกื™ืงื•ื•ืึทื ืก ื“ื•ืจ (PRGA - ืคึผืกืขื•ื•ื“ืึธ-ืจืึทื ื“ืึธื ื’ืขื ืขืจืึทื˜ื™ืึธืŸ ืึทืœื’ืขืจื™ื“ืึทื). ื“ืขืจ ืขืจืฉื˜ืขืจ ื‘ื™ื ืข ื™ื ื•ื•ืึทืœื•ื•ื– ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื ื’ ื“ื™ s-ื‘ืึธืงืก ื ื™ืฆืŸ ื“ื™ ืฉืœื™ืกืœ, ืื•ืŸ ืื™ืŸ ื“ื™ ืจื’ืข ื‘ื™ื ืข ื“ื™ ืžืงื•ืจ ื˜ืขืงืกื˜ ืื™ื– ืคึผืจืึทืกืขืกื˜ ื ื™ืฆืŸ ื“ื™ s-ื‘ืึธืงืก ืคึฟืึทืจ ืขื ืงืจื™ืคึผืฉืึทืŸ.

ื“ื™ RTM ืžื—ื‘ืจื™ื ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื™ื ื˜ืขืจืžื™ื“ื™ื™ื˜ ืฉืจื™ื˜ ืฆื•ื•ื™ืฉืŸ s-ื‘ืึธืงืก ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ืื•ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ. ื“ืขืจ ื ืึธืš ืฉืœื™ืกืœ ืื™ื– ื•ื•ืขืจื™ืึทื‘ืึทืœ ืื•ืŸ ืื™ื– ื‘ืึทืฉื˜ื™ืžื˜ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜ ื•ื•ื™ ื“ื™ ื“ืึทื˜ืŸ ืฆื• ื–ื™ื™ืŸ ื™ื ืงืจื™ืคึผื˜ื™ื“ ืื•ืŸ ื“ืขืงืจื™ืคึผื˜ื™ื“. ื“ื™ ืคึฟื•ื ืงืฆื™ืข ื•ื•ืึธืก ืคึผืขืจืคืึธืจืžื– ื“ืขื ื ืึธืš ืฉืจื™ื˜ ืื™ื– ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ืคื™ื’ื•ืจ ืื•ื ื˜ืŸ.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

4.2.2. ืฉื˜ืจื™ืงืœ ืขื ืงืจื™ืคึผืฉืึทืŸ

ืื™ืŸ ืขืจืฉื˜ืขืจ ื‘ืœื™ืง, ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ืœื™ื™ื ืขื•ื•ื“ื™ืง ืฉื•ืจื•ืช ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ื“ืœืœ. ื“ื™ ืจืขืฉื˜ ื–ืขื ืขืŸ ื™ื ืงืจื™ืคึผื˜ื™ื“ ืžื™ื˜ ื“ื™ ืึทืœื’ืขืจื™ื“ืึทื ื“ื™ืกืงืจื™ื™ื‘ื“ ืื•ื™ื‘ืŸ, ื“ื™ ืกื˜ืจื•ืงื˜ื•ืจ ืคื•ืŸ ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืคื™ื’ื•ืจ. ืžื™ืจ ื’ืขืคึฟื•ื ืขืŸ ืžืขืจ ื•ื•ื™ 25 ืคืึทืจืฉื™ื“ืขื ืข RC4 ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ ืฉื˜ืจื™ืงืœ ืขื ืงืจื™ืคึผืฉืึทืŸ ืื™ืŸ ื“ื™ ืึทื ืึทืœื™ื™ื–ื“ ืกืึทืžืคึผืึทืœื–. ื“ื™ XOR ืฉืœื™ืกืœ ืื™ื– ืึทื ื“ืขืจืฉ ืคึฟืึทืจ ื™ืขื“ืขืจ ืจื•ื“ืขืจืŸ. ื“ื™ ื•ื•ืขืจื˜ ืคื•ืŸ ื“ื™ ื ื•ืžืขืจื™ืง ืคืขืœื“ ืกืขืคึผืขืจื™ื™ื˜ื™ื ื’ ืฉื•ืจื•ืช ืื™ื– ืฉื˜ืขื ื“ื™ืง 0xFFFFFFFF.

ืื™ืŸ ื“ื™ ืึธื ื”ื™ื™ื‘ ืคื•ืŸ ื“ื•ืจื›ืคื™ืจื•ื ื’, RTM ื“ืขืงืจื™ืคึผื˜ ื“ื™ ืกื˜ืจื™ื ื’ืก ืื™ืŸ ืึท ื’ืœืื‘ืืœืข ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง. ื•ื•ืขืŸ ื ื™ื™ื˜ื™ืง ืฆื• ืึทืงืกืขืก ืึท ืฉื˜ืจื™ืงืœ, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืงืึทืœืงื™ืึทืœื™ื™ืฅ ื“ื™ื ืึทืžื™ืงืึทืœืœื™ ื“ื™ ืึทื“ืจืขืก ืคื•ืŸ ื“ื™ ื“ืขืงืจื™ืคึผื˜ื™ื“ ืกื˜ืจื™ื ื’ืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ื‘ืึทื–ืข ืึทื“ืจืขืก ืื•ืŸ ืคืึธื˜ืึธ.

ื“ื™ ืกื˜ืจื™ื ื’ืก ืึทื ื˜ื”ืึทืœื˜ืŸ ื˜ืฉื™ืงืึทื•ื•ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืคืึทื ื’ืงืฉืึทื ื– ืคื•ืŸ ื“ื™ ืžืึทืœื•ื•ืึทืจืข. ืขื˜ืœืขื›ืข ื‘ื™ื™ืฉืคึผื™ืœ ืกื˜ืจื™ื ื’ืก ื–ืขื ืขืŸ ืฆื•ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ืึธืคึผื˜ื™ื™ืœื•ื ื’ 6.8.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

4.3. ื ืขืฅ

ื“ื™ ื•ื•ืขื’ RTM ืžืึทืœื•ื•ืึทืจืข ืงืึธื ื˜ืึทืงื˜ ื“ื™ C&C ืกืขืจื•ื•ืขืจ ื•ื•ืขืจื™ื– ืคื•ืŸ ื•ื•ืขืจืกื™ืข ืฆื• ื•ื•ืขืจืกื™ืข. ื“ื™ ืขืจืฉื˜ืข ืžืึธื“ื™ืคื™ืงืึทื˜ื™ืึธื ืก (ืืงื˜ืื‘ืขืจ 2015 - ืืคืจื™ืœ 2016) ื’ืขื•ื•ื™ื™ื ื˜ ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ ืคืขืœื“ ื ืขืžืขืŸ ืฆื•ื–ืืžืขืŸ ืžื™ื˜ ืึท RSS ืงืึธืจืžืขืŸ ืื•ื™ืฃ livejournal.com ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ืงืึทืžืึทื ื“ื–.

ื–ื™ื ื˜ ืืคืจื™ืœ 2016, ืžื™ืจ ื”ืึธื‘ืŸ ื’ืขื–ืขืŸ ืึท ื™ื‘ืขืจืจื•ืง ืฆื• .ื‘ื™ื˜ ื“ืึธื•ืžื™ื™ื ื– ืื™ืŸ ื˜ืขืœืขืžืขื˜ืจื™ ื“ืึทื˜ืŸ. ื“ืึธืก ืื™ื– ื‘ืืฉื˜ืขื˜ื™ืงื˜ ื“ื•ืจืš ื“ื™ ืคืขืœื“ ืจืขื’ื™ืกื˜ืจืึทืฆื™ืข ื˜ืึธื’ - ื“ืขืจ ืขืจืฉื˜ืขืจ RTM ืคืขืœื“ fde05d0573da.bit ืื™ื– ืจืขื’ื™ืกื˜ืจื™ืจื˜ ืื•ื™ืฃ 13 ืžืขืจืฅ 2016.

ืึทืœืข ื“ื™ URL ืก ื•ื•ืึธืก ืžื™ืจ ื”ืึธื‘ืŸ ื’ืขื–ืขืŸ ื‘ืฉืขืช ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื“ื™ ืงืืžืคืื ื™ืข ื”ืื˜ ืึท ืคึผืจืึธืกื˜ ื“ืจืš: /r/z.php. ื“ืึธืก ืื™ื– ื’ืึทื ืฅ ื•ืžื’ืขื•ื•ื™ื™ื ื˜ืœืขืš ืื•ืŸ ืขืก ื•ื•ืขื˜ ื”ืขืœืคึฟืŸ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ RTM ืจื™ืงื•ื•ืขืก ืื™ืŸ ื ืขืฅ ืคืœืึธื•ื–.

4.3.1. ืงืึทื ืึทืœ ืคึฟืึทืจ ืงืึทืžืึทื ื“ื– ืื•ืŸ ืงืึธื ื˜ืจืึธืœ

ืœืขื’ืึทื˜ ื‘ื™ื™ืฉืคื™ืœืŸ ื’ืขื ื™ืฆื˜ ื“ืขื ืงืึทื ืึทืœ ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื–ื™ื™ืขืจ ืจืฉื™ืžื” ืคื•ืŸ ื‘ืึทืคึฟืขืœืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจืก. ื”ืึธืกื˜ื™ื ื’ ืื™ื– ืœื™ื’ืŸ ื‘ื™ื™ livejournal.com, ืื™ืŸ ื“ืขืจ ืฆื™ื™ื˜ ืคื•ืŸ ืฉืจื™ื™ื‘ืŸ ื“ืขื ื‘ืึทืจื™ื›ื˜ ืขืก ืื™ื– ื’ืขื‘ืœื™ื‘ืŸ ืื•ื™ืฃ ื“ื™ URL hxxp://f72bba81c921(.)livejournal(.)com/data/rss.

ืœื™ื•ื•ืขื“ื–ืฉื•ืจื ืึทืœ ืื™ื– ืึท ืจื•ืกื™ืฉ-ืืžืขืจื™ืงืื ืขืจ ืคื™ืจืžืข ื•ื•ืึธืก ื’ื™ื˜ ืึท ื‘ืœืึธื’ื’ื™ื ื’ ืคึผืœืึทื˜ืคืึธืจืžืข. RTM ืึธืคึผืขืจื™ื™ื˜ืขืจื– ืฉืึทืคึฟืŸ ืึท LJ ื‘ืœืึธื’ ืื™ืŸ ื•ื•ืึธืก ื–ื™ื™ ืคึผืึธืกื˜ืŸ ืึทืŸ ืึทืจื˜ื™ืงืœ ืžื™ื˜ ืงืึธื“ืขื“ ืงืึทืžืึทื ื“ื– - ื–ืขืŸ ืกืงืจืขืขื ืฉืึธื˜.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื‘ืึทืคึฟืขืœืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืฉื•ืจื•ืช ื–ืขื ืขืŸ ืงืึธื“ืขื“ ืžื™ื˜ ืึท ืžืึทื“ืึทืคื™ื™ื“ RC4 ืึทืœื’ืขืจื™ื“ืึทื (ืึธืคึผื˜ื™ื™ืœื•ื ื’ 4.2). ื“ื™ ืงืจืึทื ื˜ ื•ื•ืขืจืกื™ืข (ื ืื•ื•ืขืžื‘ืขืจ 2016) ืคื•ืŸ ื“ืขื ืงืึทื ืึทืœ ื›ึผื•ืœืœ ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืึทืคึฟืขืœืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ ืึทื“ืจืขืกืขืก:

  • hxxp://cainmoon(.)net/r/z.php
  • hxxp://rtm(.)dev/0-3/z.php
  • hxxp://vpntap(.)top/r/z.php

4.3.2. .ื‘ื™ื˜ ื“ืึธื•ืžื™ื™ื ื–

ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข RTM ืกืึทืžืคึผืึทืœื–, ืžื—ื‘ืจื™ื ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• C&C ื“ืึธื•ืžื™ื™ื ื– ื ื™ืฆืŸ ื“ื™ .bit TLD ืฉืคึผื™ืฅ-ืžื“ืจื’ื” ืคืขืœื“. ืขืก ืื™ื– ื ื™ืฉื˜ ืื•ื™ืฃ ื“ื™ ICANN (Domain Name and Internet Corporation) ืจืฉื™ืžื” ืคื•ืŸ ืฉืคึผื™ืฅ-ืžื“ืจื’ื” ื“ืึธื•ืžื™ื™ื ื–. ืึทื ืฉื˜ืึธื˜, ืขืก ื ื™ืฆื˜ ื“ื™ Namecoin ืกื™ืกื˜ืขื, ื•ื•ืึธืก ืื™ื– ื’ืขื‘ื•ื™ื˜ ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ ื‘ื™ื˜ืงืึธื™ืŸ ื˜ืขื›ื ืึธืœืึธื’ื™ืข. ืžืึทืœื•ื•ืึทืจืข ืžื—ื‘ืจื™ื ื˜ืึธืŸ ื ื™ื˜ ืึธืคื˜ ื ื•ืฆืŸ ื“ื™ .bit TLD ืคึฟืึทืจ ื–ื™ื™ืขืจ ื“ืึธื•ืžื™ื™ื ื–, ื›ืึธื˜ืฉ ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืึทื–ืึท ื ื•ืฆืŸ ืื™ื– ืคืจื™ืขืจ ื‘ืืžืขืจืงื˜ ืื™ืŸ ืึท ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ Necurs ื‘ืึธื˜ื ืขื˜.

ื ื™ื˜ ืขื ืœืขืš ื‘ื™ื˜ืงืึธื™ืŸ, ื ื™ืฆืขืจืก ืคื•ืŸ ื“ื™ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ Namecoin ื“ืึทื˜ืึทื‘ื™ื™ืก ื”ืึธื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ ื“ืึทื˜ืŸ. ื“ื™ ื”ื•ื™ืคึผื˜ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขื ืฉื˜ืจื™ืš ืื™ื– ื“ื™ .ื‘ื™ื˜ ืฉืคึผื™ืฅ-ืžื“ืจื’ื” ืคืขืœื“. ืื™ืจ ืงืขื ืขืŸ ืจืขื’ื™ืกื˜ืจื™ืจืŸ ื“ืึธื•ืžื™ื™ื ื– ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืกื˜ืึธืจื“ ืื™ืŸ ืึท ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ื“ืึทื˜ืึทื‘ื™ื™ืก. ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืื™ื™ื ืกืŸ ืื™ืŸ ื“ื™ ื“ืึทื˜ืึทื‘ื™ื™ืก ืึทื ื˜ื”ืึทืœื˜ืŸ IP ื•ื•ืขื ื“ื˜ ืจื™ื–ืึทืœื•ื•ื“ ื“ื•ืจืš ื“ื™ ืคืขืœื“. ื“ืขื ื˜ืœื“ ืื™ื– "ืฆืขื ื–ื•ืจ-ืงืขื’ื ืฉื˜ืขืœื™ืง" ื•ื•ื™ื™ึทืœ ื‘ืœื•ื™ื– ื“ืขืจ ืจืขื’ื™ืกื˜ืจืึทื ื˜ ืงืขื ืขืŸ ื˜ื•ื™ืฉืŸ ื“ื™ ื”ืึทื›ืœืึธื˜ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ .ื‘ื™ื˜ ืคืขืœื“. ื“ืขื ืžื™ื˜ืœ ืึทื– ืขืก ืื™ื– ืคื™ืœ ืžืขืจ ืฉื•ื•ืขืจ ืฆื• ื”ืึทืœื˜ืŸ ืึท ื‘ื™ื™ื–ืข ืคืขืœื“ ื ื™ืฆืŸ ื“ืขื ื˜ื™ืคึผ ืคื•ืŸ TLD.

ื“ื™ RTM Trojan ื˜ื•ื˜ ื ื™ืฉื˜ ื™ืžื‘ืขื“ ื“ื™ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื ื™ื™ื˜ื™ืง ืฆื• ืœื™ื™ืขื ืขืŸ ื“ื™ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ื ืึทืžืขืงืึธื™ืŸ ื“ืึทื˜ืึทื‘ื™ื™ืก. ืขืก ื ื™ืฆื˜ ื”ื•ื™ืคื˜ ื“ื ืก ืกืขืจื•ื•ืขืจืก ืึทื–ืึท ื•ื•ื™ dns.dot-bit.org ืึธื“ืขืจ OpenNic ืกืขืจื•ื•ืขืจืก ืฆื• ื”ืึทืœื˜ืŸ .ื‘ื™ื˜ ื“ืึธื•ืžื™ื™ื ื–. ื“ืขืจื™ื‘ืขืจ, ืขืก ื”ืื˜ ื“ื™ ื–ืขืœื‘ืข ื’ืขื•ื•ืขืจ ื•ื•ื™ ื“ื ืก ืกืขืจื•ื•ืขืจืก. ืžื™ืจ ื‘ืืžืขืจืงื˜ ืึทื– ืขื˜ืœืขื›ืข ืžืึทื ืฉืึทืคึฟื˜ ื“ืึธื•ืžื™ื™ื ื– ื–ืขื ืขืŸ ื ื™ื˜ ืžืขืจ ื“ื™ื˜ืขืงื˜ืึทื“ ื ืึธืš ื“ืขืจืžืื ื˜ ืื™ืŸ ืึท ื‘ืœืึธื’ ืคึผืึธืกื˜ืŸ.

ืืŸ ืื ื“ืขืจ ืžื™ื™ึทืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ .bit TLD ืคึฟืึทืจ ื›ืึทืงืขืจื– ืื™ื– ืคึผืจื™ื™ึทื–. ืฆื• ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ืึท ืคืขืœื“, ืึธืคึผืขืจื™ื™ื˜ืขืจื– ื“ืึทืจืคึฟืŸ ืฆื• ืฆืึธืœืŸ ื‘ืœื•ื™ื– 0,01 NK, ื•ื•ืึธืก ืงืึธืจืึทืกืคึผืึทื ื“ื– ืฆื• $ 0,00185 (ื•ื•ื™ ืคื•ืŸ 5 ื“ืขืฆืขืžื‘ืขืจ 2016). ืคึฟืึทืจ ืคืึทืจื’ืœื™ื™ึทืš, domain.com ืงืึธืก ื‘ื™ื™ึท ืžื™ื ื“ืกื˜ืขืจ $ 10.

4.3.3. ืคึผืจืึธื˜ืึธืงืึธืœ

ืฆื• ื™ื‘ืขืจื’ืขื‘ืŸ ืžื™ื˜ ื“ื™ ื‘ืึทืคึฟืขืœ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ, RTM ื ื™ืฆื˜ HTTP POST ืจื™ืงื•ื•ืขืก ืžื™ื˜ ื“ืึทื˜ืŸ ืคืึธืจืžืึทื˜ื˜ืขื“ ืžื™ื˜ ืึท ืžื ื”ื’ ืคึผืจืึธื˜ืึธืงืึธืœ. ื“ืขืจ ื“ืจืš ื•ื•ืขืจื˜ ืื™ื– ืฉื˜ืขื ื“ื™ืง /r/z.php; ืžืึธื–ื™ืœืœืึท/5.0 ื‘ืึทื ื™ืฆืขืจ ืึทื’ืขื ื˜ (ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ; MSIE 9.0; Windows NT 6.1; Trident/5.0). ืื™ืŸ ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ, ื“ื™ ื“ืึทื˜ืŸ ื–ืขื ืขืŸ ืคืึธืจืžืึทื˜ื˜ืขื“ ื•ื•ื™ ื’ื™ื™ื˜, ื•ื•ื• ื“ื™ ืคืึธื˜ืึธ ื•ื•ืึทืœื•ืขืก ื–ืขื ืขืŸ ืื•ื™ืกื’ืขื“ืจื™ืงื˜ ืื™ืŸ ื‘ื™ื˜ืขืก:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื‘ื™ื˜ืขืก 0 ืฆื• 6 ื–ืขื ืขืŸ ื ื™ืฉื˜ ืงืึธื“ืขื“; ื‘ื™ื˜ืขืก ืกื˜ืึทืจื˜ื™ื ื’ ืคื•ืŸ 6 ื–ืขื ืขืŸ ืขื ืงืึธื•ื“ื™ื“ ืžื™ื˜ ืึท ืžืึทื“ืึทืคื™ื™ื“ RC4 ืึทืœื’ืขืจื™ื“ืึทื. ื“ื™ ืกื˜ืจื•ืงื˜ื•ืจ ืคื•ืŸ ื“ื™ C&C ืขื ื˜ืคืขืจ ืคึผืึทืงืึทื˜ ืื™ื– ืกื™ืžืคึผืœืขืจ. ื‘ื™ื˜ืขืก ื–ืขื ืขืŸ ืขื ืงืึธื•ื“ื™ื“ ืคื•ืŸ 4 ืฆื• ืคึผืึทืงืึทื˜ ื’ืจื™ื™ืก.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ืžืขื’ืœืขืš ื•ื•ืึทืœื•ืขืก ืคื•ืŸ ืงืึทืžืฃ ื‘ื™ื™ื˜ ืื™ื– ื“ืขืจืœืื ื’ื˜ ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืื•ื ื˜ืŸ:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืฉื˜ืขื ื“ื™ืง ืงืึทืœืงื™ืึทืœื™ื™ืฅ ื“ื™ CRC32 ืคื•ืŸ ื“ื™ ื“ืขืงืจื™ืคึผื˜ื™ื“ ื“ืึทื˜ืŸ ืื•ืŸ ืงืึทืžืคึผืขืจื– ืขืก ืžื™ื˜ ื•ื•ืึธืก ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ืคึผืึทืงืึทื˜. ืื•ื™ื‘ ื–ื™ื™ ืึทื ื“ืขืจืฉ, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื˜ืจืืคื ืก ื“ื™ ืคึผืึทืงืึทื˜.
ื“ื™ ื ืึธืš ื“ืึทื˜ืŸ ืงืขืŸ ืึทื ื˜ื”ืึทืœื˜ืŸ ืคืึทืจืฉื™ื“ืŸ ืึทื‘ื“ื–ืฉืขืงืฅ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึท PE ื˜ืขืงืข, ืึท ื˜ืขืงืข ืฆื• ื–ื•ื›ืŸ ืื™ืŸ ื“ืขืจ ื˜ืขืงืข ืกื™ืกื˜ืขื, ืึธื“ืขืจ ื ื™ื™ึทืข ื‘ืึทืคึฟืขืœ URL ืก.

4.3.4. ื˜ืึทืคืœื™ืข

ืžื™ืจ ื‘ืืžืขืจืงื˜ ืึทื– RTM ื ื™ืฆื˜ ืึท ื˜ืึทืคืœื™ืข ืื•ื™ืฃ C&C ืกืขืจื•ื•ืขืจืก. ืกืงืจืขืขื ืฉืึธื˜ ืื•ื ื˜ืŸ:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

4.4. ื›ืึทืจืึทืงื˜ืขืจื™ืกื˜ื™ืฉ ืฆื™ื™ื›ืŸ

ืจื˜ื ืื™ื– ืึท ื˜ื™ืคึผื™ืฉ ื‘ืึทื ืงื™ื ื’ ื˜ืจืึธื“ื–ืฉืึทืŸ. ืขืก ืื™ื– ืงื™ื™ืŸ ื™ื‘ืขืจืจืึทืฉืŸ ืึทื– ืึธืคึผืขืจื™ื™ื˜ืขืจื– ื•ื•ื™ืœืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืงืึธืจื‘ืŸ ืก ืกื™ืกื˜ืขื. ืื•ื™ืฃ ื“ื™ ืื™ื™ืŸ ื”ืึทื ื˜, ื“ื™ ื‘ืึธื˜ ืงืึทืœืขืงืฅ ืึทืœื’ืขืžื™ื™ื ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืึทืก. ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื”ืึทื ื˜, ืขืก ื’ืขืคื™ื ื˜ ืื•ื™ืก ืฆื™ ื“ื™ ืงืึทืžืคึผืจืึทืžื™ื™ื–ื“ ืกื™ืกื˜ืขื ื›ึผื•ืœืœ ืึทื˜ืจื™ื‘ื™ื•ืฅ ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ืจื•ืกื™ืฉ ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ.

4.4.1. ืึทืœื’ืขืžื™ื™ื ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข

ื•ื•ืขืŸ ืžืึทืœื•ื•ืึทืจืข ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืึธื“ืขืจ ืœืึธื ื˜ืฉื˜ ื ืึธืš ืึท ืจืขื‘ืึธืึธื˜, ืึท ื‘ืึทืจื™ื›ื˜ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ ืžื™ื˜ ื’ืขื ืขืจืึทืœ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜:

  • ืฆื™ื™ึทื˜ ื–ืึธื ืข;
  • ืคืขืœื™ืงื™ื™ึทื˜ ืกื™ืกื˜ืขื ืฉืคึผืจืึทืš;
  • ืึธื˜ืขืจื™ื™ื–ื“ ื‘ืึทื ื™ืฆืขืจ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–;
  • ืคึผืจืึทืกืขืก ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜ ืžื“ืจื’ื”;
  • ื ืืžืขืŸ;
  • ืงืึธืžืคึผื™ื•ื˜ืขืจ ื ืึธืžืขืŸ;
  • OS ื•ื•ืขืจืกื™ืข;
  • ื ืึธืš ืื™ื ืกื˜ืึทืœื™ืจืŸ ืžืึทื“ื–ืฉื•ืœื–;
  • ืื™ื ืกื˜ืึทืœื™ืจืŸ ืึทื ื˜ื™ื•ื•ื™ืจื•ืก ืคึผืจืึธื’ืจืึทื;
  • ืจืฉื™ืžื” ืคื•ืŸ ืงืœื•ื’ ืงืึธืจื˜ ืœื™ื™ืขื ืขืจ.

4.4.2 ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขื

ื ื˜ื™ืคึผื™ืฉ ื˜ืจืึธื“ื–ืฉืึทืŸ ืฆื™ืœ ืื™ื– ืึท ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขื, ืื•ืŸ RTM ืื™ื– ืงื™ื™ืŸ ื•ื™ืกื ืขื. ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืžืึทื“ื–ืฉื•ืœื– ืคื•ืŸ ื“ื™ ืคึผืจืึธื’ืจืึทื ืื™ื– ื’ืขืจื•ืคืŸ TBdo, ื•ื•ืึธืก ืคึผืขืจืคืึธืจืžื– ืคืึทืจืฉื™ื“ืŸ ื˜ืึทืกืงืก, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืกืงืึทื ื™ื ื’ ื“ื™ืกืงืก ืื•ืŸ ื‘ืจืึทื•ื–ื™ื ื’ ื’ืขืฉื™ื›ื˜ืข.

ื“ื•ืจืš ืกืงืึทื ื™ื ื’ ื“ื™ ื“ื™ืกืง, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื˜ืฉืขืงืก ืฆื™ ื‘ืึทื ืงื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ื™ืฃ ื“ื™ ืžืึทืฉื™ืŸ. ื“ื™ ืคื•ืœ ืจืฉื™ืžื” ืคื•ืŸ ืฆื™ืœ ืžื’ื™ืœื” ืื™ื– ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืื•ื ื˜ืŸ. ื ืึธืš ื“ื™ื˜ืขืงื˜ืึทื“ ืึท ื˜ืขืงืข ืคื•ืŸ โ€‹โ€‹ืื™ื ื˜ืขืจืขืก, ื“ื™ ืคึผืจืึธื’ืจืึทื ืกืขื ื“ื– ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœ ืกืขืจื•ื•ืขืจ. ื“ื™ ื•ื•ื™ื™ึทื˜ืขืจ ืึทืงืฉืึทื ื– ืึธืคืขื ื’ืขืŸ ืื•ื™ืฃ ื“ื™ ืœืึธื’ื™ืง ืกืคึผืขืกื™ืคื™ืขื“ ื“ื•ืจืš ื“ื™ ื‘ืึทืคึฟืขืœ ืฆืขื ื˜ืขืจ (C&C) ืึทืœื’ืขืจื™ื“ืึทืžื–.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

RTM ืื•ื™ืš ื–ื•ื›ื˜ ืคึฟืึทืจ URL ืคึผืึทื˜ืขืจื ื– ืื™ืŸ ื“ื™ื™ืŸ ื‘ืœืขื˜ืขืจืขืจ ื’ืขืฉื™ื›ื˜ืข ืื•ืŸ ืขืคืขื ืขืŸ ื˜ืึทื‘ืก. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ ืคึผืจืึธื’ืจืึทื ื™ื’ื–ืึทืžืึทื ื– ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ FindNextUrlCacheEntryA ืื•ืŸ FindFirstUrlCacheEntryA ืคืึทื ื’ืงืฉืึทื ื–, ืื•ืŸ ืื•ื™ืš ื˜ืฉืขืง ื™ืขื“ืขืจ ืคึผืึธื–ื™ืฆื™ืข ืฆื• ื’ืœื™ื™ึทื›ืŸ ื“ื™ URL ืฆื• ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืคึผืึทื˜ืขืจื ื–:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื ืึธืš ื“ื™ื˜ืขืงื˜ืึทื“ ืขืคืขื ืขืŸ ื˜ืึทื‘ืก, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืงืึธื ื˜ืึทืงื˜ Internet Explorer ืึธื“ืขืจ Firefox ื“ื•ืจืš ื“ื™ ื“ื™ื ืึทืžื™ืฉ ื“ืึทื˜ืึท ืขืงืกื˜ืฉืึทื ื’ืข (DDE) ืžืขืงืึทื ื™ื–ืึทื ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืฆื™ ื“ื™ ืงื•ื•ื™ื˜ืœ ืฉื•ื•ืขื‘ืขืœืขืš ืฆื• ื“ืขื ืžื•ืกื˜ืขืจ.

ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื™ื™ืŸ ื‘ืจืึทื•ื–ื™ื ื’ ื’ืขืฉื™ื›ื˜ืข ืื•ืŸ ืขืคืขื ืขืŸ ื˜ืึทื‘ืก ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืื™ืŸ ืึท WHILE ืฉืœื™ื™ืฃ (ืึท ืฉืœื™ื™ืฃ ืžื™ื˜ ืึท ืคึผืจื™ืงืึทื ื“ื™ืฉืึทืŸ) ืžื™ื˜ ืึท 1 ืจื’ืข ื‘ืจืขื›ืŸ ืฆื•ื•ื™ืฉืŸ ื˜ืฉืขืงืก. ืื ื“ืขืจืข ื“ืึทื˜ืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืžืึธื ื™ื˜ืึธืจืขื“ ืื™ืŸ ืคืึทืงื˜ื™ืฉ ืฆื™ื™ื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ืกืงืึทืกื˜ ืื™ืŸ ืึธืคึผื˜ื™ื™ืœื•ื ื’ 4.5.

ืื•ื™ื‘ ืึท ืžื•ืกื˜ืขืจ ืื™ื– ื’ืขืคึฟื•ื ืขืŸ, ื“ื™ ืคึผืจืึธื’ืจืึทื ืจื™ืคึผืึธืจืฅ ื“ืขื ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœ ืกืขืจื•ื•ืขืจ ื ื™ืฆืŸ ืึท ืจืฉื™ืžื” ืคื•ืŸ ืกื˜ืจื™ื ื’ืก ืคื•ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ื˜ื™ืฉ:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

4.5 ืžืึธื ื™ื˜ืึธืจื™ื ื’

ื‘ืฉืขืช ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืื™ื– ืคืœื™ืกื ื“ื™ืง, ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื›ืึทืจืึทืงื˜ืขืจื™ืกื˜ื™ืฉ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืคื•ืŸ ื“ื™ ื™ื ืคืขืงื˜ืึทื“ ืกื™ืกื˜ืขื (ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื‘ืึทื ืงื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’) ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ. ืคื™ื ื’ืขืจืคึผืจื™ื ื˜ื™ื ื’ ืึทืงืขืจื– ื•ื•ืขืŸ RTM ืขืจืฉื˜ืขืจ ืœื•ื™ืคื˜ ื“ื™ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืกื™ืกื˜ืขื ืžื™ื“ ื ืึธืš ื“ื™ ืขืจืฉื˜ ืึทืก ื™ื‘ืขืจืงื•ืงืŸ.

4.5.1. ื•ื•ื™ื™ึทื˜ ื‘ืึทื ืงื™ื ื’

ื“ื™ TBdo ืžืึธื“ื•ืœืข ืื™ื– ืื•ื™ืš ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืคึฟืึทืจ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื‘ืึทื ืงื™ื ื’-ืคึฟืึทืจื‘ื•ื ื“ืขื ืข ืคึผืจืึทืกืขืกืึทื–. ืขืก ื ื™ืฆื˜ ื“ื™ื ืึทืžื™ืฉ ื“ืึทื˜ืŸ ื•ื•ืขืงืกืœ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื˜ืึทื‘ืก ืื™ืŸ Firefox ืื•ืŸ Internet Explorer ื‘ืขืฉืึทืก ื“ืขืจ ืขืจืฉื˜ ื™ื‘ืขืจืงื•ืงืŸ. ืืŸ ืื ื“ืขืจ TShell ืžืึธื“ื•ืœืข ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืžืึธื ื™ื˜ืึธืจ ื‘ืึทืคึฟืขืœืŸ ืคึฟืขื ืฆื˜ืขืจ (Internet Explorer ืึธื“ืขืจ File Explorer).

ื“ืขืจ ืžืึธื“ื•ืœืข ื ื™ืฆื˜ ื“ื™ ืงืึทื ื™ื ื˜ืขืจืคื™ื™ืกื™ื– IShellWindows, iWebBrowser, DWebBrowserEvents2 ืื•ืŸ IConnectionPointContainer ืฆื• ืžืึธื ื™ื˜ืึธืจ ืคึฟืขื ืฆื˜ืขืจ. ื•ื•ืขืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ื ืึทื•ื•ื™ื’ื™ืจืŸ ืฆื• ืึท ื ื™ื™ึทืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ, ื“ื™ ืžืึทืœื•ื•ืึทืจืข ื”ืขืจื•ืช ื“ืึธืก. ื“ืขืจื ืึธืš ืงืึทืžืคึผืขืจื– ื“ื™ URL ืคื•ืŸ ื“ื™ ื‘ืœืึทื˜ ืžื™ื˜ ื“ื™ ืื•ื™ื‘ืŸ ืคึผืึทื˜ืขืจื ื–. ื ืึธืš ื“ื™ื˜ืขืงื˜ืึทื“ ืึท ื’ืœื™ื™ึทื›ืŸ, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื ืขืžื˜ ื–ืขืงืก ืงืึธื ืกืขืงื•ื˜ื™ื•ื•ืข ืกืงืจืขืขื ืฉืึธืฅ ืžื™ื˜ ืึท ืžืขื”ืึทืœืขืš ืคื•ืŸ 5 ืกืขืงื•ื ื“ืขืก ืื•ืŸ ืกืขื ื“ื– ื–ื™ื™ ืฆื• ื“ื™ C&S ื‘ืึทืคึฟืขืœืŸ ืกืขืจื•ื•ืขืจ. ื“ืขืจ ืคึผืจืึธื’ืจืึทื ืื•ื™ืš ื˜ืฉืขืง ืขื˜ืœืขื›ืข ืคึฟืขื ืฆื˜ืขืจ ื ืขืžืขืŸ ืฉื™ื™ึทื›ื•ืช ืฆื• ื‘ืึทื ืงื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’ - ื“ื™ ืคื•ืœ ืจืฉื™ืžื” ืื™ื– ืื•ื ื˜ืŸ:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

4.5.2. ืกืžืึทืจื˜ ืงืึธืจื˜

RTM ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืžืึธื ื™ื˜ืึธืจ ืกืžืึทืจื˜ ืงืึทืจื˜ืœ ืœื™ื™ืขื ืขืจ ืคืืจื‘ื•ื ื“ืŸ ืฆื• ื™ื ืคืขืงื˜ืึทื“ ืงืึธืžืคึผื™ื•ื˜ืขืจืก. ื“ื™ ื“ืขื•ื•ื™ืกืขืก ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืขื˜ืœืขื›ืข ืœืขื ื“ืขืจ ืฆื• ืฉืึธืœืขืž ืžืึทื›ืŸ ืฆืึธืœื•ื ื’ ืึธืจื“ืขืจืก. ืื•ื™ื‘ ื“ืขื ื˜ื™ืคึผ ืคื•ืŸ ืžื™ื˜ืœ ืื™ื– ืึทื˜ืึทื˜ืฉื˜ ืฆื• ืึท ืงืึธืžืคึผื™ื•ื˜ืขืจ, ืขืก ืงืขืŸ ืึธื ื•ื•ื™ื™ึทื–ืŸ ืฆื• ืึท ื˜ืจืึธื“ื–ืฉืึทืŸ ืึทื– ื“ื™ ืžืึทืฉื™ืŸ ืื™ื– ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื‘ืึทื ืงื™ื ื’ ื˜ืจืึทื ื–ืึทืงืฉืึทื ื–.

ื ื™ื˜ ืขื ืœืขืš ืื ื“ืขืจืข ื‘ืึทื ืงื™ื ื’ ื˜ืจืึธื“ื–ืฉืึทื ืก, RTM ืงืขืŸ ื ื™ืฉื˜ ื™ื ื˜ืขืจืึทืงื˜ ืžื™ื˜ ืึทื–ืึท ืงืœื•ื’ ืงืึทืจื“ืก. ื˜ืึธืžืขืจ ื“ื™ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื™ื– ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ืึทืŸ ื ืึธืš ืžืึธื“ื•ืœืข ื•ื•ืึธืก ืžื™ืจ ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื’ืขื–ืขืŸ ื ืึธืš.

4.5.3. ืงื™ื™ืœืึธื’ื’ืขืจ

ืึท ื•ื•ื™ื›ื˜ื™ืง ื˜ื™ื™ืœ ืคื•ืŸ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืึท ื™ื ืคืขืงื˜ืึทื“ ืคึผื™ืกื™ ืื™ื– ืงืึทืคึผื˜ืฉืขืจื™ื ื’ ืงื™ืกื˜ืจืึธื•ืงืก. ืขืก ืžื™ื™ื ื˜ ืึทื– ื“ื™ RTM ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืคืขืœื ื“ื™ืง ืงื™ื™ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื•ื•ื™ื™ึทืœ ื–ื™ื™ ืžืึธื ื™ื˜ืึธืจ ื ื™ื˜ ื‘ืœื•ื™ื– ืจืขื’ื•ืœืขืจ ืฉืœื™ืกืœืขืŸ, ืึธื‘ืขืจ ืื•ื™ืš ื“ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ืงืœืึทื•ื•ื™ืึทื˜ื•ืจ ืื•ืŸ ืงืœื™ืคึผื‘ืึธืจื“.

ืฆื• ื˜ืึธืŸ ื“ืึธืก, ื ื•ืฆืŸ ื“ื™ SetWindowsHookExA ืคึฟื•ื ืงืฆื™ืข. ืึทื˜ืึทืงืขืจื– ืงืœืึธืฅ ื“ื™ ืงื™ื– ื’ืขื“ืจื™ืงื˜ ืึธื“ืขืจ ื“ื™ ืฉืœื™ืกืœืขืŸ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืฆื• ื“ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ืงืœืึทื•ื•ื™ืึทื˜ื•ืจ, ืฆื•ื–ืืžืขืŸ ืžื™ื˜ ื“ื™ ื ืึธืžืขืŸ ืื•ืŸ ื“ืึทื˜ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืคึผืจืึธื’ืจืึทื. ื“ืขืจ ื‘ืึทืคืขืจ ืื™ื– ื“ืขืจื ืึธืš ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ C&C ื‘ืึทืคึฟืขืœืŸ ืกืขืจื•ื•ืขืจ.

ื“ื™ SetClipboardViewer ืคื•ื ืงืฆื™ืข ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื™ื ื˜ืขืจืกืขืคึผื˜ ื“ื™ ืงืœื™ืคึผื‘ืึธืจื“. ื›ืึทืงืขืจื– ืงืœืึธืฅ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ื™ ืงืœื™ืคึผื‘ืึธืจื“ ื•ื•ืขืŸ ื“ื™ ื“ืึทื˜ืŸ ื–ืขื ืขืŸ ื˜ืขืงืกื˜. ื“ืขืจ ื ืึธืžืขืŸ ืื•ืŸ ื“ืึทื˜ืข ื–ืขื ืขืŸ ืื•ื™ืš ืœืึธื’ื“ ืื™ื™ื“ืขืจ ื“ื™ ื‘ืึทืคืขืจ ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ.

4.5.4. ืกืงืจืขืขื ืฉืึธืฅ

ืืŸ ืื ื“ืขืจ RTM ืคื•ื ืงืฆื™ืข ืื™ื– ืกืงืจืขืขื ืฉืึธื˜ ื™ื ื˜ืขืจืกืขืคึผืฉืึทืŸ. ื“ืขืจ ืฉื˜ืจื™ืš ืื™ื– ื’ืขื•ื•ืขื ื“ื˜ ื•ื•ืขืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืžืึธื“ื•ืœืข ื“ื™ื˜ืขืงืฅ ืึท ืคึผืœืึทืฅ ืึธื“ืขืจ ื‘ืึทื ืงื™ื ื’ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืคื•ืŸ ืื™ื ื˜ืขืจืขืก. ืกืงืจืขืขื ืฉืึธืฅ ื–ืขื ืขืŸ ื’ืขื ื•ืžืขืŸ ืžื™ื˜ ืึท ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืคื•ืŸ ื’ืจืึทืคื™ืง ื‘ื™ืœื“ืขืจ ืื•ืŸ ื˜ืจืึทื ืกืคืขืจื“ ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœ ืกืขืจื•ื•ืขืจ.

4.6. ื•ื ื™ื ืกื˜ืึทืœืœืึทื˜ื™ืึธืŸ

ื“ื™ C&C ืกืขืจื•ื•ืขืจ ืงืขื ืขืŸ ื”ืึทืœื˜ืŸ ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืคื•ืŸ โ€‹โ€‹ืคืœื™ืกื ื“ื™ืง ืื•ืŸ ืจื™ื™ืŸ ื“ื™ื™ืŸ ืงืึธืžืคึผื™ื•ื˜ืขืจ. ื“ืขืจ ื‘ืึทืคึฟืขืœ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ื™ืกืžืขืงืŸ ื˜ืขืงืขืก ืื•ืŸ ืจืขื’ื™ืกื˜ืจื™ ืื™ื™ื ืกืŸ ื‘ืืฉืืคืŸ ื‘ืฉืขืช RTM ืื™ื– ืคืœื™ืกื ื“ื™ืง. ื“ืขืจ ื“ืœืœ ืื™ื– ื“ืขืžืึธืœื˜ ื’ืขื ื™ืฆื˜ ืฆื• ื‘ืึทื–ื™ื™ึทื˜ื™ืงืŸ ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืื•ืŸ ื“ื™ ื•ื•ื™ื ืœืึธื’ืึธืŸ ื˜ืขืงืข, ื ืึธืš ื•ื•ืึธืก ื“ื™ ื‘ืึทืคึฟืขืœ ืคืึทืจืžืึทื›ืŸ ื“ื™ ืงืึธืžืคึผื™ื•ื˜ืขืจ. ื•ื•ื™ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ื‘ื™ืœื“ ืื•ื ื˜ืŸ, ื“ื™ ื“ืœืœ ืื™ื– ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ื“ื•ืจืš ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื ื™ืฆืŸ erase.dll.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ืขืจ ืกืขืจื•ื•ืขืจ ืงืขื ืขืŸ ืฉื™ืงืŸ ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืึท ื“ืขืกื˜ืจื•ืงื˜ื™ื•ื•ืข ื ืขื ืึทื•ื•ืขืง-ืฉืœืึธืก ื‘ืึทืคึฟืขืœ. ืื™ืŸ ื“ืขื ืคืึทืœ, ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืจืขื›ื˜, RTM ื•ื•ืขื˜ ื•ื™ืกืžืขืงืŸ ื“ื™ MBR ืฉื˜ื™ื•ื•ืœ ืกืขืงื˜ืึธืจ ืื•ื™ืฃ ื“ื™ ืฉื•ื•ืขืจ ืคืึธืจ. ืื•ื™ื‘ ื“ืึธืก ืงืขืŸ ื ื™ืฉื˜ ืึทืจื‘ืขื˜ืŸ, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื•ื•ืขื˜ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื™ื‘ืขืจืจื•ืง ื“ื™ MBR ืฉื˜ื™ื•ื•ืœ ืกืขืงื˜ืึธืจ ืฆื• ืึท ื˜ืจืึทืค ืกืขืงื˜ืึธืจ - ื“ืขืจ ืงืึธืžืคึผื™ื•ื˜ืขืจ ื•ื•ืขื˜ ื ื™ืฉื˜ ืงืขื ืขืŸ ืฆื• ืฉื˜ื™ื•ื•ืœ ื“ื™ ืึทืก ื ืึธืš ืฉืึทื˜ื“ืึทื•ืŸ. ื“ืึธืก ืงืขืŸ ืคื™ืจืŸ ืฆื• ืึท ื’ืึทื ืฅ ืจื™ื™ื ืกื˜ืึทืœืžืึทื ื˜ ืคื•ืŸ ื“ื™ ืึทืก, ื•ื•ืึธืก ืžื™ื˜ืœ ื“ื™ ืฆืขืฉื˜ืขืจื•ื ื’ ืคื•ืŸ ื–ืึธื’ืŸ.

ืึธืŸ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–, ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืฉืจื™ื™ื‘ื˜ ืึทืŸ. ืขืงืกืข ืงืึธื“ืขื“ ืื™ืŸ ื“ื™ ืึทื ื“ืขืจืœื™ื™ื™ื ื’ ืจื˜ื ื“ืœืœ. ื“ื™ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ืขืงืกืึทืงื™ื•ืฅ ื“ื™ ืงืึธื“ ื“ืืจืฃ ืฆื• ืคืึทืจืžืึทื›ืŸ ื“ื™ ืงืึธืžืคึผื™ื•ื˜ืขืจ ืื•ืŸ ืจืขื“ื–ืฉื™ืกื˜ืขืจื– ื“ื™ ืžืึธื“ื•ืœืข ืื™ืŸ ื“ื™ HKCUCurrentVersionRun ืจืขื’ื™ืกื˜ืจื™ ืฉืœื™ืกืœ. ื™ืขื“ืขืจ ืžืึธืœ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืกื˜ืึทืจืฅ ืึท ืกืขืกื™ืข, ื“ืขืจ ืงืึธืžืคึผื™ื•ื˜ืขืจ ืžื™ื“ ืฉืึทื˜ ืึทืจืึธืคึผ.

4.7. ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข

ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, RTM ื”ืื˜ ื›ึผืžืขื˜ ืงื™ื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข, ืึธื‘ืขืจ ื“ื™ ื‘ืึทืคึฟืขืœ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ ืงืขื ืขืŸ ืฉื™ืงืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื•ื•ืึทืœื•ืขืก ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืกื˜ืึธืจื“ ืื™ืŸ ื“ื™ ืจืขื’ื™ืกื˜ืจื™ ืื•ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ื“ื™ ืคึผืจืึธื’ืจืึทื. ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืฉืœื™ืกืœืขืŸ ืื™ื– ื“ืขืจืœืื ื’ื˜ ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืื•ื ื˜ืŸ:

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื™ื– ืกื˜ืึธืจื“ ืื™ืŸ ื“ื™ ื•ื•ื™ื™ื›ื•ื•ืืจื’ [ืคึผืกืขื•ื•ื“ืึธ-ืจืึทื ื“ืึธื ืฉื˜ืจื™ืงืœ] ืจืขื’ื™ืกื˜ืจื™ ืฉืœื™ืกืœ. ื™ืขื“ืขืจ ื•ื•ืขืจื˜ ืงืึธืจืึทืกืคึผืึทื ื“ื– ืฆื• ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืจืึธื•ื– ื“ืขืจืœืื ื’ื˜ ืื™ืŸ ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ื˜ื™ืฉ. ื•ื•ืึทืœื•ืขืก ืื•ืŸ ื“ืึทื˜ืŸ ื–ืขื ืขืŸ ืงืึธื“ืขื“ ืžื™ื˜ ื“ื™ RC4 ืึทืœื’ืขืจื™ื“ืึทื ืื™ืŸ RTM.

ื“ื™ ื“ืึทื˜ืŸ ื”ืึธื‘ืŸ ื“ื™ ื–ืขืœื‘ืข ืกื˜ืจื•ืงื˜ื•ืจ ื•ื•ื™ ืึท ื ืขืฅ ืึธื“ืขืจ ืกื˜ืจื™ื ื’ืก. ื ืคื™ืจ-ื‘ื™ื˜ืข XOR ืฉืœื™ืกืœ ืื™ื– ืžื•ืกื™ืฃ ืื™ืŸ ื“ื™ ืึธื ื”ื™ื™ื‘ ืคื•ืŸ ื“ื™ ืขื ืงืึธื•ื“ื™ื“ ื“ืึทื˜ืŸ. ืคึฟืึทืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื•ื•ืึทืœื•ืขืก, ื“ื™ XOR ืฉืœื™ืกืœ ืื™ื– ืึทื ื“ืขืจืฉ ืื•ืŸ ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ื“ื™ ื•ื•ืขืจื˜. ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืงืึทืœืงื™ืึทืœื™ื™ื˜ื™ื“ ื•ื•ื™ ื’ื™ื™ื˜:

ืงืกืึธืจ_ืงื™ื™ = (ืœืขื  (ืงืึธื ืคื™ื’_ื•ื•ืึทืœื™ื•) <<24) | (len (config_value) <<16)
| len(config_value)| (len (config_value) <<8)

4.8. ืื ื“ืขืจืข ืคึฟืขื™ึดืงื™ื™ื˜ืŸ

ื“ืขืจื ืึธืš, ืœืึธืžื™ืจ ื–ืขืŸ ืื ื“ืขืจืข ืคืึทื ื’ืงืฉืึทื ื– ื•ื•ืึธืก RTM ืฉื˜ื™ืฆื˜.

4.8.1. ื ืึธืš ืžืึทื“ื–ืฉื•ืœื–

ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื›ื•ืœืœ ื ืึธืš ืžืึทื“ื–ืฉื•ืœื–, ื•ื•ืึธืก ื–ืขื ืขืŸ ื“ืœืœ ื˜ืขืงืขืก. ืžืึธื“ื•ืœืขืก ื’ืขืฉื™ืงื˜ ืคึฟื•ืŸ ื“ื™ C&C ื‘ืึทืคึฟืขืœืŸ ืกืขืจื•ื•ืขืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ื•ื•ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืžื’ื™ืœื”, ืฉืคื™ื’ืœื˜ ืื™ืŸ ื‘ืึทืจืึทืŸ ืื•ืŸ ืœืึธื ื˜ืฉื˜ ืื™ืŸ ื ื™ื™ึทืข ืคึฟืขื“ืขื. ืคึฟืึทืจ ืกื˜ืึธืจื™ื“ื–ืฉ, ืžืึทื“ื–ืฉื•ืœื– ื–ืขื ืขืŸ ื’ืขืจืื˜ืขื•ื•ืขื˜ ืื™ืŸ. ื“ื˜ื˜ ื˜ืขืงืขืก ืื•ืŸ ืงืึธื“ืขื“ ื ื™ืฆืŸ ื“ื™ RC4 ืึทืœื’ืขืจื™ื“ืึทื ืžื™ื˜ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฉืœื™ืกืœ ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื ืขืฅ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข.

ื‘ื™ื– ืื™ืฆื˜, ืžื™ืจ ื”ืึธื‘ืŸ ื‘ืืžืขืจืงื˜ ื“ื™ ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ VNC ืžืึธื“ื•ืœืข (8966319882494077C21F66A8354E2CBCA0370464), ื“ื™ ื‘ืœืขื˜ืขืจืขืจ ื“ืึทื˜ืŸ ื™ืงืกื˜ืจืึทืงืฉืึทืŸ ืžืึธื“ื•ืœืข (03DE8622BE6B2F75A364A275995C3411626C4E9C1C2C1F) 562FBA1B 69BE6D58B88753E7CFAB).

ืฆื• ืœืึธื“ืŸ ื“ื™ ื•ื•ื ืง ืžืึธื“ื•ืœืข, ื“ื™ C&C ืกืขืจื•ื•ืขืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทืคึฟืขืœ ืจื™ืงื•ื•ืขืกื˜ื™ื ื’ ืงืึทื ืขืงืฉืึทื ื– ืฆื• ื“ื™ ื•ื•ื ืง ืกืขืจื•ื•ืขืจ ืื™ืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ื™ืคึผ ืึทื“ืจืขืก ืื•ื™ืฃ ืคึผืึธืจื˜ 44443. ื“ืขืจ ื‘ืœืขื˜ืขืจืขืจ ื“ืึทื˜ืŸ ืจื™ื˜ืจื™ื•ื•ืึทืœ ืคึผืœื•ื’ื™ืŸ ืขืงืกืึทืงื™ื•ืฅ ื˜ื‘ืจืึธื•ื•ืกืขืจื“ืึทื˜ืึทืงืึธืœืœืขืงื˜ืึธืจ, ื•ื•ืึธืก ืงืขื ืขืŸ ืœื™ื™ืขื ืขืŸ ื”ื™ื™ืกื˜ ื‘ืจืึทื•ื–ื™ื ื’ ื’ืขืฉื™ื›ื˜ืข. ื“ืขืจื ืึธืš ืขืก ืกืขื ื“ื– ื“ื™ ืคื•ืœ ืจืฉื™ืžื” ืคื•ืŸ ื‘ืื–ื•ื›ื˜ URL ืก ืฆื• ื“ื™ C&C ื‘ืึทืคึฟืขืœืŸ ืกืขืจื•ื•ืขืจ.

ื“ื™ ืœืขืฆื˜ืข ืžืึธื“ื•ืœืข ื“ื™ืกืงืึทื•ื•ืขืจื“ ืื™ื– ื’ืขืจื•ืคืŸ 1c_2_kl. ืขืก ืงืขื ืขืŸ ื™ื ื˜ืขืจืึทืงื˜ ืžื™ื˜ ื“ื™ 1C Enterprise ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืคึผืขืงืœ. ื“ืขืจ ืžืึธื“ื•ืœืข ื›ื•ืœืœ ืฆื•ื•ื™ื™ ืคึผืึทืจืฅ: ื“ืขืจ ื”ื•ื™ืคึผื˜ ื˜ื™ื™ืœ - ื“ืœืœ ืื•ืŸ ืฆื•ื•ื™ื™ ืื’ืขื ื˜ืŸ (32 ืื•ืŸ 64 ื‘ื™ืกืœ), ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื™ื ื“ื–ืฉืขืงื˜ื™ื“ ืื™ืŸ ื™ืขื“ืขืจ ืคึผืจืึธืฆืขืก, ืจืขื“ื–ืฉื™ืกื˜ืขืจื™ื ื’ ืึท ื‘ื™ื™ื ื“ื™ื ื’ ืฆื• WH_CBT. ื ืึธืš ื‘ืึทืงืขื ืขื  ืื™ืŸ ื“ื™ 1C ืคึผืจืึธืฆืขืก, ื“ืขืจ ืžืึธื“ื•ืœืข ื‘ื™ื™ื ื“ื– ื“ื™ CreateFile ืื•ืŸ WriteFile ืคืึทื ื’ืงืฉืึทื ื–. ื•ื•ืขืŸ ื“ื™ CreateFile ื’ืขื‘ื•ื ื“ืŸ ืคึฟื•ื ืงืฆื™ืข ืื™ื– ื’ืขืจื•ืคืŸ, ื“ื™ ืžืึธื“ื•ืœืข ืกื˜ืึธืจื– ื“ื™ ื˜ืขืงืข ื“ืจืš 1c_to_kl.txt ืื™ืŸ ื–ื›ึผืจื•ืŸ. ื ืึธืš ื™ื ื˜ืขืจืกืขืคึผื˜ื™ื ื’ ื“ื™ WriteFile ืจื•ืคืŸ, ืขืก ืจื•ืคื˜ ื“ื™ WriteFile ืคึฟื•ื ืงืฆื™ืข ืื•ืŸ ืกืขื ื“ื– ื“ื™ ื˜ืขืงืข ื“ืจืš 1c_to_kl.txt ืฆื• ื“ื™ ื”ื•ื™ืคึผื˜ ื“ืœืœ ืžืึธื“ื•ืœืข, ืื•ืŸ ืคืึธืจืŸ ื“ื™ ืงืจืึทืคื˜ืขื“ Windows WM_COPYDATA ืึธื ื–ืึธื’.

ื“ื™ ื”ื•ื™ืคึผื˜ ื“ืœืœ ืžืึธื“ื•ืœืข ืึธืคึผืขื ืก ืื•ืŸ ืคึผืึทืจืกืขืก ื“ื™ ื˜ืขืงืข ืฆื• ื‘ืึทืฉืœื™ืกืŸ ืฆืึธืœื•ื ื’ ืึธืจื“ืขืจืก. ืขืก ืื ืขืจืงืขื ื˜ ื“ื™ ืกื•ืžืข ืื•ืŸ ื˜ืจืึทื ืกืึทืงื˜ื™ืึธืŸ ื ื•ืžืขืจ ืงืึทื ื˜ื™ื™ื ื“ ืื™ืŸ ื“ืขืจ ื˜ืขืงืข. ื“ื™ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœ ืกืขืจื•ื•ืขืจ. ืžื™ืจ ื’ืœื•ื™ื‘ืŸ ืึทื– ื“ืขื ืžืึธื“ื•ืœืข ืื™ื– ื“ืขืจื•ื•ื™ื™ึทืœ ืื•ื ื˜ืขืจ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื•ื•ื™ื™ึทืœ ืขืก ื›ึผื•ืœืœ ืึท ื“ื™ื‘ืึทื’ ืึธื ื–ืึธื’ ืื•ืŸ ืงืขืŸ ื ื™ืฉื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืžืึธื“ื™ืคื™ืฆื™ืจืŸ 1c_to_kl.txt.

4.8.2. ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืขืกืงืึทืœื™ืจื•ื ื’

RTM ืงืขืŸ ืคึผืจื•ื•ื•ืŸ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื“ื•ืจืš ื•ื•ื™ื™ึทื–ื ื“ื™ืง ืคืึทืœืฉ ื˜ืขื•ืช ืึทืจื˜ื™ืงืœืขืŸ. ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืกื™ืžื™ืึทืœื™ื™ืฅ ืึท ืจืขื’ื™ืกื˜ืจื™ ื˜ืฉืขืง (ื–ืขืŸ ื‘ื™ืœื“ ืื•ื ื˜ืŸ) ืึธื“ืขืจ ื ื™ืฆื˜ ืึท ืคืึทืงื˜ื™ืฉ ืจืขื’ื™ืกื˜ืจื™ ืจืขื“ืึทืงื˜ืึธืจ ื™ื™ืงืึทืŸ. ื‘ื™ื˜ืข ื˜ืึธืŸ ื“ื™ ืžื™ืกืคึผืขืœื™ื ื’ ื•ื•ืึทืจื˜ืŸ - ื•ื•ื™ื™ื˜. ื ืึธืš ืึท ื‘ื™ืกืœ ืกืขืงื•ื ื“ืขืก ืคื•ืŸ ืกืงืึทื ื™ื ื’, ื“ื™ ืคึผืจืึธื’ืจืึทื ื“ื™ืกืคึผืœื™ื™ื– ืึท ืคืึทืœืฉ ื˜ืขื•ืช ืึธื ื–ืึธื’.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื ืคืึทืœืฉ ืึธื ื–ืึธื’ ื•ื•ืขื˜ ืœื™ื™ื›ื˜ ืึธืคึผื ืึทืจืŸ ื“ื™ ื“ื•ืจื›ืฉื ื™ื˜ืœืขืš ื‘ืึทื ื™ืฆืขืจ, ื˜ืจืึธืฅ ื’ืจืึทืžืึทื˜ื™ืง ืขืจืจืึธืจืก. ืื•ื™ื‘ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืงืœื™ืงื˜ ืื•ื™ืฃ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืฆื•ื•ื™ื™ ืœื™ื ืงืก, RTM ื•ื•ืขื˜ ืคึผืจื•ื•ื•ืŸ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื–ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื.

ื ืึธืš ืกืึทืœืขืงื˜ื™ื ื’ ืื™ื™ื ืขืจ ืคื•ืŸ ืฆื•ื•ื™ื™ ืึธืคึผื–ื•ืš ืึธืคึผืฆื™ืขืก, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืœืึธื ื˜ืฉื™ื– ื“ื™ ื“ืœืœ ืžื™ื˜ ื“ื™ Runas ืึธืคึผืฆื™ืข ืื™ืŸ ื“ื™ ShellExecute ืคื•ื ืงืฆื™ืข ืžื™ื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–. ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื•ื•ืขื˜ ื–ืขืŸ ืึท ืคืึทืงื˜ื™ืฉ Windows ืคึผื™ื ื˜ืœืขืš (ื–ืขืŸ ื‘ื™ืœื“ ืื•ื ื˜ืŸ) ืคึฟืึทืจ ื”ื™ื™ืš. ืื•ื™ื‘ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื’ื™ื˜ ื“ื™ ื ื™ื™ื˜ื™ืง ืคึผืขืจืžื™ืฉืึทื ื–, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื•ื•ืขื˜ ืœื•ื™ืคืŸ ืžื™ื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–.

ื“ื™ RTM ืกื™ื™ื‘ืขืจ ื’ืจื•ืคึผืข ืกืคึผืขืฉืึทืœื™ื™ื–ื™ื– ืื™ืŸ ื’ื ื‘ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืจื•ืกื™ืฉืข ืงืึธืžืคึผืึทื ื™ืขืก

ื“ืขืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืฉืคึผืจืึทืš ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื, ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ื“ื™ืกืคึผืœื™ื™ื– ื˜ืขื•ืช ืึทืจื˜ื™ืงืœืขืŸ ืื™ืŸ ืจื•ืกื™ืฉ ืึธื“ืขืจ ืขื ื’ืœื™ืฉ.

4.8.3. ืกืขืจื˜ื™ืคื™ืงืึทื˜

RTM ืงืขื ืขืŸ ืœื™ื™ื’ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืฆื• ื“ื™ Windows ืกื˜ืึธืจ ืื•ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืจื™ืœื™ื™ืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ื™ ืึทื“ื™ืฉืึทืŸ ื“ื•ืจืš ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื’ืขื‘ืŸ ืึท ืงืœื™ืง ื“ืขื "ื™ืึธ" ืงื ืขืคึผืœ ืื™ืŸ ื“ื™ csrss.exe ื“ื™ืึทืœืึธื’ ืงืขืกื˜ืœ. ื“ืขื ืึธืคึผืคื™ืจื•ื ื’ ืื™ื– ื ื™ืฉื˜ ื ื™ื™ึท, ืœืžืฉืœ, ื“ื™ ื‘ืึทื ืงื™ื ื’ ื˜ืจืึธื“ื–ืฉืึทืŸ ืจืขื˜ืขืคืข ืงืึทื ืคืขืจืžื– ืื•ื™ืš ื™ื ื“ื™ืคึผืขื ื“ืึทื ื˜ืœื™ ื“ื™ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืคื•ืŸ ืึท ื ื™ื™ึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ.

4.8.4. ืคืึทืจืงืขืจื˜ ืงืฉืจ

ื“ื™ RTM ืžื—ื‘ืจื™ื ืื•ื™ืš ื‘ืืฉืืคืŸ ื“ืขื Backconnect TCP ื˜ื•ื ืขืœ. ืžื™ืจ ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื’ืขื–ืขืŸ ื“ืขื ืฉื˜ืจื™ืš ืื™ืŸ ื ื•ืฆืŸ ื ืึธืš, ืึธื‘ืขืจ ืขืก ืื™ื– ื“ื™ื–ื™ื™ื ื“ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ืžืึธื ื™ื˜ืึธืจ ื™ื ืคืขืงื˜ืึทื“ ืคึผื™ืกื™.

4.8.5. ื”ืึธืกื˜ ื˜ืขืงืข ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’

ื“ื™ C&C ืกืขืจื•ื•ืขืจ ืงืขื ืขืŸ ืฉื™ืงืŸ ืึท ื‘ืึทืคึฟืขืœ ืฆื• ื“ื™ ื˜ืจืึธื“ื–ืฉืึทืŸ ืฆื• ืžืึธื“ื™ืคื™ืฆื™ืจืŸ ื“ื™ Windows ื‘ืึทืœืขื‘ืึธืก ื˜ืขืงืข. ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ื˜ืขืงืข ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืฉืึทืคึฟืŸ ืžื ื”ื’ ื“ื ืก ืจืขื–ืึทืœื•ืฉืึทื ื–.

4.8.6. ื’ืขืคึฟื™ื ืขืŸ ืื•ืŸ ืฉื™ืงืŸ ืึท ื˜ืขืงืข

ื“ืขืจ ืกืขืจื•ื•ืขืจ ืงืขืŸ ื‘ืขื˜ืŸ ืฆื• ื–ื•ื›ืŸ ืื•ืŸ ืืจืืคืงืืคื™ืข ืึท ื˜ืขืงืข ืื•ื™ืฃ ื“ื™ ื™ื ืคืขืงื˜ืึทื“ ืกื™ืกื˜ืขื. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื‘ืขืฉืึทืก ื“ื™ ืคืึธืจืฉื•ื ื’ ืžื™ืจ ื‘ืืงื•ืžืขืŸ ืึท ื‘ืงืฉื” ืคึฟืึทืจ ื“ื™ ื˜ืขืงืข 1c_to_kl.txt. ื•ื•ื™ ืคืจื™ืขืจ ื“ื™ืกืงืจื™ื™ื‘ื“, ื“ื™ ื˜ืขืงืข ืื™ื– ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ื“ื™ 1C: Enterprise 8 ืึทืงืึทื•ื ื˜ื™ื ื’ ืกื™ืกื˜ืขื.

4.8.7. ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ

ืฆื•ื ืกื•ืฃ, RTM ืžื—ื‘ืจื™ื ืงืขื ืขืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื“ื™ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื“ื•ืจืš ืคืึธืจืœื™ื™ื’ืŸ ืึท ื ื™ื™ึท ื“ืœืœ ืฆื• ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื“ื™ ืงืจืึทื ื˜ ื•ื•ืขืจืกื™ืข.

5. ืžืกืงื ื

RTM ืก ืคืึธืจืฉื•ื ื’ ื•ื•ื™ื™ื–ื˜ ืึทื– ื“ื™ ืจื•ืกื™ืฉืข ื‘ืึทื ืงื™ื ื’ ืกื™ืกื˜ืขื ื ืึธืš ืึทื˜ืจืึทืงืฅ ืกื™ื™ื‘ืขืจ ืึทื˜ืึทืงืขืจื–. ื’ืจื•ืคึผืขืก ืึทื–ืึท ื•ื•ื™ ื‘ื•ื”ื˜ืจืึทืคึผ, ืงืึธืจืงืึธื•ื• ืื•ืŸ ืงืึทืจื‘ืึทื ืึทืง ื”ืฆืœื—ื” ื’ืึทื ื•ื•ืขื ืขืŸ ื’ืขืœื˜ ืคื•ืŸ ืคื™ื ืึทื ืฆื™ืขืœ ืื™ื ืกื˜ื™ื˜ื•ืฆื™ืขืก ืื•ืŸ ื–ื™ื™ืขืจ ืงืœื™ื™ืึทื ืฅ ืื™ืŸ ืจื•ืกืœืึทื ื“. RTM ืื™ื– ืึท ื ื™ื™ึทืข ืฉืคึผื™ืœืขืจ ืื™ืŸ ื“ืขื ืื™ื ื“ื•ืกื˜ืจื™ืข.

ื‘ื™ื™ื–ืข RTM ืžื›ืฉื™ืจื™ื ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืื™ืŸ ื ื•ืฆืŸ ื–ื™ื ื˜ ื‘ื™ื™ึท ืžื™ื ื“ืกื˜ืขืจ ืฉืคึผืขื˜ 2015, ืœื•ื™ื˜ ESET ื˜ืขืœืขืžืขื˜ืจื™. ื“ืขืจ ืคึผืจืึธื’ืจืึทื ื”ืื˜ ืึท ืคื•ืœ ืงื™ื™ื˜ ืคื•ืŸ ืกืคึผื™ื™ื™ื ื’ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืœื™ื™ืขื ืขืŸ ืกืžืึทืจื˜ ืงืึทืจื“ืก, ื™ื ื˜ืขืจืกืขืคึผื˜ื™ื ื’ ืงื™ืกื˜ืจืึธื•ืงืก ืื•ืŸ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื‘ืึทื ืงื™ื ื’ ื˜ืจืึทื ื–ืึทืงืฉืึทื ื–, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื–ื•ื›ืŸ ืคึฟืึทืจ 1C: Enterprise 8 ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื˜ืขืงืขืก.

ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืึท ื“ื™ืกืขื ื˜ืจืึทืœื™ื™ื–ื“, ืึทื ืกืขื ืกืขืจื“ .ื‘ื™ื˜ ืฉืคึผื™ืฅ-ืžื“ืจื’ื” ืคืขืœื“ ื™ื ืฉื•ืจื– ื”ืขื›ืกื˜ ืจื™ื–ื™ืœื™ืึทื ื˜ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’