
1ãæåãç§ã®æ°ããä»äºã®ããŒã¿ã«ããããã³ã°ãããŸããã çµå¶è
ã¯ãã©ã®ããã«ïŒããšçåã«æããŸããã ãµãŒããŒãžã®æ¥ç¶ã®çãæ€çŽ¢ãšåæäžã«ãåŸæ¥å¡ã®PCãèŠã€ãããããããã»ãŒåæã«æ¥ç¶ã確ç«ãããŸããã åŸæ¥å¡ã¯ãããã³ã°ã«ã€ããŠäœãç¥ããŸããã§ããããäŒè©±äžã«1ã€ã®ã±ãŒã¹ãæãåºããŸãã;ãããã³ã°ã®å°ãåã«ã圌ã¯éããŠããªããäŒç€Ÿã®åŸæ¥å¡ãããææžãåãåããŸããã ãã¡ã€ã«ã¯exe圢åŒã§ããããã¹ããŒãªãŒå
šäœã®å§ãŸãã§ãã
åç· åœ¹äŒã®ç®¡çè
ã¯ããã¡ã€ã«ãåæãããã¡ã€ã«ã®å®è¡å
å®¹ãšæ»æè
ã«æ®ãããããŒã¿ãææ¡ããã¿ã¹ã¯ãèšå®ããŸããã ãã«ãŠã§ã¢åæã®ãããã¯ã«åºäŒã£ãããšã¯ãããŸããããæãè«ççãªããšã¯ãGoogleã§æ
å ±ãèŠã€ããããšã§ããã
æ°æ¥ä»¥å
ã«èšå€§ãªæ°ã®ãã«ãŠã§ã¢åæããã¥ã¢ã«ãèŠã€ããŠèªã¿ãŸãããã»ãšãã©ãã¹ãŠã®ããã¥ã¢ã«ã§ã¯ããµã³ãããã¯ã¹ãšããŸããŸãªãŠãŒãã£ãªãã£ã䜿çšããŠãœãããŠã§ã¢ãæåã§åæããããšãææ¡ããŸãããã
malwr.comã¯ãµã³ãããã¯ã¹ã ç§ã¯ç»é²ãããŠã€ã«ã¹ãããŠã³ããŒãããåã«äžŠãã§åŸ
ã£ãŠããŸãããããã®1æ¥åŸã«ã¡ã€ã³ããŒãžã«ãã¥ãŒã¹ã衚瀺ãããŸããã

7æ24æ¥ã®ååŸãè² è·ãå¢å ãããããµãŒãã¹ã¯ç¡æéã«æ©èœããªããªããŸããã
ãµã€ãã®ããŒãžãšèª¬æãèŠãåŸã䜿çšããåæãã©ãããã©ãŒã -Cuckoo Sandbox-ã«èšåããããã°ã©ã ã®è©³çްã確èªããããšã«ããŸããã
ãã®ãã«ãã³ãŠãã¯ã©ããªåç©ã§ããïŒ
Cuckoo Sandboxã¯ããã«ãŠã§ã¢ããšã¯ã¹ããã€ããæªæã®ããã¹ã¯ãªãããããã¥ã¡ã³ããã¢ãŒã«ã€ãããªã³ã¯ãèªåçã«èª¿æ»ããããã®ã·ã¹ãã ã§ãã ã·ã¹ãã ã¯ãpdfãdocãxlsãrtfããã¥ã¡ã³ããPythonã¹ã¯ãªãããJSãDLLã©ã€ãã©ãªããã€ããªãjarãªã©ããã§ãã¯ã§ããŸãã
ã©ã®ããã«æ©èœããŸããïŒ
Python 2.7ã¯ç¹å¥ã«æºåãããä»®æ³ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããCuckooãšãŒãžã§ã³ããã¹ã¿ãŒãã¢ããã«è¿œå ãããŸããããã¯ãµã³ãããã¯ã¹ãšå¯Ÿè©±ãããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãããã¯ãŒã¯ãã©ãã£ãã¯ãã€ã³ã¿ãŒã»ããããã³ããã«åæããããã«ç¹å¥ãªæ¹æ³ã§æ§æãããŸãã ãã¹ãŠã®æäœã®åŸããã¡ã€ã«ã·ã¹ãã ã®ã¹ãããã·ã§ãããååŸãããŸããããã¯ã¹ãããã·ã§ããã§ããããŸãã ãµã³ãããã¯ã¹ã¯ãã¹ããã¡ã€ã«ãããŠã³ããŒããããã®ã¿ã€ããæ±ºå®ãããã¡ã€ã«ã¿ã€ãã«åŸã£ãŠå¿
èŠãªæäœãå®è¡ãããµã³ãããã¯ã¹å
ã®ãã¹ãŠã®å€æŽãã¬ããŒãã«èšé²ãããŸãã äœæ¥åŸãã·ã¹ãã ã¯ã¹ãããã·ã§ããã埩å
ããä»®æ³ã·ã¹ãã ã¯å
ã®ç¶æ
ã«æ»ããŸãã
ã«ãã³ãŠãµã³ãããã¯ã¹ã«ã¯æ¬¡ã®æ©èœããããŸãã
- win32 API颿°åŒã³åºãã®ç£èŠ
- ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãã³ã
- ãã³ãããã³ã¡ã¢ãªåæ
- åæäžã«ã¹ã¯ãªãŒã³ã·ã§ãããæ®ã
- æ€èšŒããã»ã¹äžã«äœæãããããŠã³ããŒãããããã¹ãŠã®ãã¡ã€ã«ã®ã³ããŒãä¿åãã
- æªæã®ããããã»ã¹ã«ãã£ãŠå®è¡ãããåœä»€ããã¬ãŒã¹ãã
- jsonãmmdefãmaecãhtml圢åŒã§äŸ¿å©ãªã¬ããŒããäœæãã
- ãã«ãŠã§ã¢ãèµ·åãããç°å¢ã®å®å
šãªåé¢
å
Œ
±ã®å©çãä¿é²ããããšã«ãããã¹ãã ã¡ãŒã«ã«æ·»ä»ããã1ã€ã®ãã¡ã€ã«ã§ãµã³ãããã¯ã¹ãç¹å®ãã眲åã®å°ããªç»é¢ãæçš¿ããŸãã

ããã«ãããåŸæ¥ã®Trojan.GenãŠã€ã«ã¹å¯Ÿçå¿çãããã¯ããã«å€ãã®ãã¡ã€ã«ã«é¢ããæ
å ±ãåŸãããããšãèªããå¿
èŠããããŸãïŒããã¯ã·ãã³ããã¯ã®ãåºã®ç³ããšèããããšãã§ããŸãïŒã
ããã§ã¯ããã¡ã€ã«ãHTML圢åŒã§
åæãããµã³ãããã¯ã¹ã«ãã£ãŠã©ã®ããã«äœæããããã説æããŸããã
Cuckoo Sandboxã¯
ååã«ææžåãããŠãã
ãäžéšã®ãµã€ãã§ã¯ã€ã³ã¹ããŒã«æé ãå«ã
ãã®ã€ã³ã¹ããŒã«ãã¬ã€ã¢ãŠããããŠããŸãããçŸæç¹ã§ã¯èšè¿°ã©ããã«åäœããã€ã³ã¹ãã©ã¯ã·ã§ã³ã¯ãããŸããã ã»ããã¢ããäžã«ããªãã®æ°ã®åé¡ã«ééããåŸãããã§ãã¹ãŠã®ãã¥ã¢ã³ã¹ã远å ãä¿®æ£ãå«ãå®å
šã§ææ°ã®ã€ã³ã¹ããŒã«ããã³æ§æã¬ã€ããæžãããšã«ããŸããã æãæ laãªäººã®ããã«ããµã³ãããã¯ã¹ãèªåçã«æ§æããã³ã€ã³ã¹ããŒã«ããã¹ã¯ãªãããæºåããŸãããå§ããŸãããã
Cuckooãã€ã³ã¹ããŒã«ããŠèšå®ããŸãããã¹ãŠã®è€éããšè¿œå ã®ãŠãŒãã£ãªãã£ãå«ãŸããŠããŸãã
ãã®åŸã®ã€ã³ã¹ããŒã«ã¯ãã¹ãŠãVPS DigitaloceanïŒ2GB Ram / 40GB SSD / Ubuntu 14.04 x32ïŒã§å®è¡ãããŸããã
泚ïŒåããã¹ãã£ã³ã°ã§ãµã³ãããã¯ã¹ãæ§ç¯ããããšããå Žåããã³ãã³DCãéžæããªãã§ãã ãããäžéšã®ãªã³ã¯ã«ã¢ã¯ã»ã¹ããéã«åé¡ãçºçããŸããUbuntuã¯ããµã³ãããã¯ã¹ãçŽæ¥ãã¹ããããã·ã¹ãã ãšããŠéçºè
ã®æšå¥šã«ããéžæãããŸããã
ã€ã³ã¹ããŒã«èšç»ã¯æ¬¡ã®ããã«ãªããŸãã
- ãŠãŒãã£ãªãã£ãšãµã³ãããã¯ã¹ã«å¿
èŠãªäŸåé¢ä¿ãšããã±ãŒãžã®ã€ã³ã¹ããŒã«
- ãŠãŒãã£ãªãã£ãšCuckoo Sandboxãã€ã³ã¹ããŒã«ãã
- ã«ãã³ãŠãµã³ãããã¯ã¹ã®ã«ã¹ã¿ãã€ãº
- Virtualboxãã€ã³ã¹ããŒã«ããŠæ§æãã
- ä»®æ³ã·ã¹ãã ã®ã€ã³ã¹ããŒã«ãŸãã¯ããŒããæ§æ
- Webã€ã³ã¿ãŒãã§ãŒã¹
- ãªãŒãããŒã
- 远å ã®ããã³ããšã«ãã³ãŠã®æ©èœ
- Cuckooãã€ã³ã¹ããŒã«ããã³æ§æããããã®æ¢è£œã®ã¹ã¯ãªãã
- ããŒãã¹
ãŠãŒãã£ãªãã£ãšãµã³ãããã¯ã¹ã«å¿
èŠãªäŸåé¢ä¿ãšããã±ãŒãžã®ã€ã³ã¹ããŒã«
èªåã§ããã®ãé¢åãªå Žåã¯ãçŽæ¥
Readyã¹ã¯ãªããé
ç®ã«ç§»åããŠãã ããã ãã®ã¹ã¯ãªããã¯Ubuntu 14.04 LTS x32ã§ã®ã¿ãã¹ãããã³ãã«ããããŠãããããä»ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®åäœã¯ä¿èšŒãããŠããŸããã ããªããèªåã§ãããçè§£ããããšã«æ±ºãããªããæ¬¡ã®ç« ã¯ããªãã®ããã§ãã
ãã¹ãŠã®äŸåé¢ä¿ãã€ã³ã¹ããŒã«ããŸãã
cd /tmp apt-get update apt-get install git automake mongodb mingw32 dkms unzip wget python python-sqlalchemy python-bson python-pip python-dpkt python-jinja2 python-magic python-mysqldb python-gridfs python-libvirt python-bottle python-pefile python-chardet -y apt-get install python-dev libxml2-dev libxslt1-dev libevent-dev libpcre3 libpcre3-dev zlib1g-dev libtool libpcre++-dev ây apt-get install mariadb-server -y
ç§ãæžããããã«ãäžåºŠã«1ã€ãã€è¡ãã«ã¯ã次ã®èšå®ãæãŸããã§ãã
pip install lxml pip install cybox==2.0.1.4 pip install maec==4.0.1.0 pip install django pip install py3compat pip install pymongo
泚ïŒPymongoã¯PIPããã®ã¿ã€ã³ã¹ããŒã«ããŸããAPTããã€ã³ã¹ããŒã«ããå ŽåãWebã€ã³ã¿ãŒãã§ãŒã¹ã¯æ©èœããŸããããŠãŒãã£ãªãã£ãšCuckoo Sandboxãã€ã³ã¹ããŒã«ãã
SSDEEP
ïŒssdeepã¯ãã³ã³ããã¹ãã®éšåããã·ã¥ãååž°çã«èšç®ããã³æ¯èŒããããã®ããŒã«ã§ããããã¡ãžãŒããã·ã¥ãšããŠç¥ãããŠããŸãïŒ
apt-get install ssdeep python-pyrex subversion libfuzzy-dev -y svn checkout http://pyssdeep.googlecode.com/svn/trunk/ pyssdeep cd pyssdeep python setup.py build python setup.py install pip install pydeep
ãã
ïŒYARAã¯ããŠã€ã«ã¹ã¢ããªã¹ãããã«ãŠã§ã¢ã®äŸãç¹å®ããŠåé¡ããã®ã«åœ¹ç«ã€ããŒã«ã§ãïŒ
cd /tmp wget https://github.com/plusvic/yara/archive/v2.1.0.tar.gz tar xzf v2.1.0.tar.gz cd yara-2.1.0 chmod +x build.sh ./build.sh make install cd yara-python python setup.py build python setup.py install
Distorm3
ïŒDistorm3-éã¢ã»ã³ãã©ãŒïŒ
cd /tmp wget http://distorm.googlecode.com/files/distorm3.zip unzip distorm3.zip cd distorm3 python setup.py build python setup.py install
ãã©ãã£ãªãã£
ïŒæ®çºæ§ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã¡ã¢ãªãã³ãã調æ»ããããã«èšèšãããPythonãã¬ãŒã ã¯ãŒã¯ã§ãïŒ
add-apt-repository ppa:pi-rho/security apt-get update apt-get install volatility
泚ïŒãœãŒã¹ããããã±ãŒãžãã³ã³ãã€ã«ããªãã§ãã ããïŒ2012-2013ã®äžéšã®ã€ã³ã¹ããŒã«ããã¥ã¢ã«ã§èª¬æãããŠããããã«ïŒããã®èšäºã®ããã«ã¬ããžããªããã€ã³ã¹ããŒã«ããªãã§ãã ããMongoããªããã°ãæ°ããWebã€ã³ã¿ãŒãã§ãŒã¹ã¯æ©èœããŸããïŒããªããžããªã®ããŒãžã§ã³ã«ã¯ãã®ãããªåé¡ã¯ãããŸãããCuckoo Sandboxãã€ã³ã¹ããŒã«ãã
ãŸãããŠãŒã¶ãŒã远å ããŸãã
useradd cuckoo usermod -a -G vboxusers cuckoo id cuckoo
ä»ããã€ã³ã¹ããŒã«ïŒ
å®å®ãã cd /opt wget http://downloads.cuckoosandbox.org/1.1/cuckoo_1.1.tar.gz tar xzf cuckoo_1.1.tar.gz
éçº cd /opt git clone https://github.com/cuckoobox/cuckoo.git
泚ïŒä»¥äžã®äŸã§ã¯ãå®å®ããŒãžã§ã³ã䜿çšãããŠããŸãããå®å®ããŒãžã§ã³ã®äœ¿çšããå§ãããŸããCuckoo Sandboxã®æ§æ
Cuckooã³ãã¥ããã£ã®çœ²åãèšå®ãã
cd /opt/cuckoo ./utils/community.py --signatures --force
CuckooããŒã¿ããŒã¹ãæ§æããŸãã
mysql -u root -p > create database cuckoo; > grant all privileges on cuckoo.* to cuckoo@localhost identified by 'cuck00pass' ; > flush privileges; > quit;
ã«ãã³ãŠãã«ã¹ã¿ãã€ãºãã
- ãã¡ã€ã«/opt/cuckoo/conf/cuckoo.conf
ã¡ã¢ãªãã³ãã¬ã³ãŒãããªã³ã«ããŸãã
memory_dump = on
ããŒã¿ããŒã¹ãžã®æ¥ç¶ãæ§æããŸãã
connection = mysql://cuckoo:cuck00pass\@localhost/cuckoo
ãµãŒããŒã¯åŒ±ããããæéå¶éãå¢ãããŸãã
default = 240 critical = 1200 vm_state = 600
- /opt/cuckoo/conf/memory.confãã¡ã€ã«
ãµãŒããŒã«ã¯40 GBãããªããããã¡ã¢ãªãã³ãã®ä¿åããªãã«ããŸãã
delete_memdump = yes
- ãã¡ã€ã«/opt/cuckoo/conf/processing.conf
RAMã®åæããªã³ã«ããŸãã
memory = yes
泚ïŒkeyãã©ã¡ãŒã¿ãŒã«ã¯ãç¬èªã®virustotal.comãµãŒãã¹ããŒAPIãå
¥åã§ããŸã - vim /opt/cuckoo/conf/virtualbox.conf
Virtualboxã®åäœã¢ãŒãã倿ŽããŸãã
mode = headless
ä»®æ³ãã·ã³ã®ååãcuckoo1ããWindowsXPã«å€æŽããŸãã
machines = WindowsXP [WindowsXP] label = WindowsXP
- ãã¡ã€ã«/opt/cuckoo/conf/reporting.conf
Webã€ã³ã¿ãŒãã§ã€ã¹ã®MongoDBã§ã¬ããŒãã®ã€ã³ããŒããæå¹ã«ããŸã
[mongodb] enabled = yes
ããã§Cuckooã®ã»ããã¢ãããå®äºããŸãããæ¬¡ã«ãVirtualboxãšã²ã¹ãOSããå§ããŸãããã
Virtualboxãã€ã³ã¹ããŒã«ããŠæ§æãã
Virtualboxããã³å¿
èŠãªãã¹ãŠã®ã³ã³ããŒãã³ã
wget -q http://download.virtualbox.org/virtualbox/debian/oracle_vbox.asc -O- | sudo apt-key add â sh -c 'echo "deb http://download.virtualbox.org/virtualbox/debian trusty contrib" >> /etc/apt/sources.list.d/virtualbox.list' apt-get update apt-get install virtualbox-4.3 cd /tmp VBOX_LATEST_VERSION=$(curl http://download.virtualbox.org/virtualbox/LATEST.TXT) wget http://download.virtualbox.org/virtualbox/${VBOX_LATEST_VERSION}/Oracle_VM_VirtualBox_Extension_Pack-{VBOX_LATEST_VERSION}.vbox-extpack vboxmanage extpack install /tmp/Oracle_VM_VirtualBox_Extension_Pack-${VBOX_LATEST_VERSION}.vbox-extpack cd /opt wget http://dlc.sun.com.edgesuite.net/virtualbox/${VBOX_LATEST_VERSION}/VBoxGuestAdditions_${VBOX_LATEST_VERSION}.iso
ä»®æ³ã·ã¹ãã ã®ã€ã³ã¹ããŒã«ãŸãã¯ããŒããæ§æ
OSãã€ã³ã¹ããŒã«ããããã®2ã€ã®ãªãã·ã§ã³ããããŸãã
- ãµã€ãããããŠã³ããŒãããŠãã ãã
- æåã§ã€ã³ã¹ããŒã«ãã
æåã®ãªãã·ã§ã³ã¯æéã§ãããæãå®å®ããŠããŸããã éå¶å©ç®çã§ã®ãã®OSã®äœ¿çšã¯èš±å¯ãããŠãããã©ã€ã»ã³ã¹ã«åé¡ã¯ãããŸããã
2çªç®ã®ãªãã·ã§ã³ã¯ããé·ããããä¿¡é Œæ§ãé«ããããåŸè
ãéžæããŸããããäž¡æ¹ãé çªã«èª¬æããŸãã
ãµã€ãããä»®æ³OSãããŠã³ããŒããã wget https://az412801.vo.msecnd.net/vhd/VMBuild_20131127/VirtualBox/IE6_WinXP/Linux/IE6.WinXP.For.LinuxVirtualBox.sfx chmod +x IE6.WinXP.For.LinuxVirtualBox.sfx ./IE6.WinXP.For.LinuxVirtualBox.sfx vboxmanage import IE6\ -\ WinXP.ova --vsys 0 --unit 10 --disk=/root/VirtualBox\ VMs/WindowsXP/WindowsXP.vmdk --memory 1024 --vmname WindowsXP
æåOSã€ã³ã¹ããŒã« vboxmanage createvm --name "WindowsXP" --ostype WindowsXP --register vboxmanage modifyvm "WindowsXP" --memory 1000 --acpi on --boot1 dvd vboxmanage createhd --filename "WindowsXP.vdi" --size 20000 vboxmanage storagectl "WindowsXP" --name "IDE" --add ide --controller PIIX4 vboxmanage storageattach "WindowsXP" --storagectl "IDE" --port 0 --device 0 --type hdd --medium "WindowsXP.vdi"
æ³šïŒæ¬¡ã®æé ã¯ãäž¡æ¹ã®æ¹æ³ã«çããé©çšã§ããŸãããããã¯ãŒã¯ãèšå®ããŸãã vboxmanage hostonlyif create vboxmanage modifyvm "WindowsXP" --nic1 hostonly --hostonlyadapter1 vboxnet0 --nicpromisc1 allow-all --hwvirtex off --vtxvpid off
å
±æãã©ã«ããŒãæ§æãã mkdir -p /opt/cuckoo/shares/setup mkdir -p /opt/cuckoo/shares/WindowsXP vboxmanage sharedfolder add "WindowsXP" --name "WindowsXP" --hostpath /opt/cuckoo/shares/WindowsXP --automount vboxmanage sharedfolder add "WindowsXP" --name setup --hostpath /opt/cuckoo/shares/setup --automount --readonly vboxmanage modifyvm "WindowsXP" --nictrace1 on --nictracefile1 /opt/cuckoo/shares/WindowsXP/dump.pcap
RDPã¢ã¯ã»ã¹ãæå¹ã«ãã vboxmanage modifyvm "WindowsXP" --vrdeport 5000 --vrde on
ä»»æã®ããŒããæå®ã§ããŸãããã§ãä»®æ³ã³ã³ããã®æ§æã¯å®å
šã«å®äºããiptablesãtcpdumpãæ§æããæåããã€ã³ã¹ããŒã«ããããšãéžæããå Žåã¯ãã®ãŸãŸ-å®éã«Windowsãã€ã³ã¹ããŒã«ããŸãã
iptablesã«ãŒã«ãšã«ãŒãã«ãã©ã¡ãŒã¿ãŒã®å€æŽ iptables -A FORWARD -o eth0 -i vboxnet0 -s 192.168.56.0/24 -m conntrack --ctstate NEW -j ACCEPT iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT iptables -A POSTROUTING -t nat -j MASQUERADE sysctl -w net.ipv4.ip_forward=1
tcpdump setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump getcap /usr/sbin/tcpdump
ã€ã³ã¿ãŒãã§ãŒã¹ãäžãã ifconfig vboxnet0 192.168.56.1
次ã«ãã²ã¹ãOSèªäœã«çŽæ¥ç§»åããŸãã
Windowsã€ã³ã¹ããŒã«ã€ã¡ãŒãžããµãŒããŒã«ã¢ããããŒãããŠãä»®æ³ãã·ã³ã«æ¥ç¶ããŸãã
vboxmanage storageattach "WindowsXP" --storagectl "IDE" --port 0 --device 1 --type dvddrive --medium /patch/to/licensed/windows.iso
ãªã³ã«ãã
vboxmanage startvm "WindowsXP" --type headless
ãã®ã³ãã³ãã®åŸãããŒã5000ã§RDPçµç±ã§ä»®æ³OSã«æ¥ç¶ããã€ã³ã¹ããŒã«ã§ããŸãã ã€ã³ã¹ããŒã«åŸãVBoxGuestAdditionsãæ¥ç¶ããŠã€ã³ã¹ããŒã«ããŸãã
vboxmanage storageattach "WindowsXP" --storagectl "IDE" --port 0 --device 1 --type dvddrive --medium /opt/VBoxGuestAdditions_4.3.14.iso
泚ïŒã¢ããªã³ã®ããŒãžã§ã³ã¯ç°ãªãå ŽåããããŸããæ¢è£œã®ä»®æ³ã·ã¹ãã ãããŠã³ããŒãããå Žåã¯ããããã«ããŠããGuestAdditionsãæŽæ°ããå¿
èŠããããŸãã
ã€ã³ã¹ããŒã«åŸãåèµ·åããŸãã
ã²ã¹ãOSã䞻匵- æ¬¡ã®æ¹æ³ã§ãããã¯ãŒã¯æ¥ç¶ãæ§æããŸãïŒä»»æã®DNSãæå®ã§ããŸãïŒã

- ã·ã¹ãã ã«æ¥ç¶ãããŠãããã£ã¹ã¯ããVboxToolsãã€ã³ã¹ããŒã«ããŸãã
- Pyton 2.7ãã€ã³ã¹ããŒã«ããŸãïŒ http ://python.org/download/
- http://www.activestate.com/activepythonãã€ã³ã¹ããŒã«ããŸã
- PIL Pythonã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããŠã¹ã¯ãªãŒã³ã·ã§ãããæ®ããŸã ïŒ http : //www.pythonware.com/products/pil/
- Windowsã®èªåæŽæ°ããªãã«ããŸãã
- ãã¡ã€ã¢ãŠã©ãŒã«ããªãã«ããŸãã
- ãããã¯ãŒã¯ã»ããã¢ãããã©ã«ããŒãããã©ã«ããŒCïŒ\ Python27ã«ãšãŒãžã§ã³ããã³ããŒããŸãã
ãšãŒãžã§ã³ããèµ·åæã«é
眮ããŸãããã®ãããã¬ãžã¹ããªãã©ã³ãã«æååãã©ã¡ãŒã¿ãŒã远å ããŸãïŒstart-> execute-> regeditïŒHKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
ååïŒããšãŒãžã§ã³ãã
ã¿ã€ãïŒ 'REG_SZ'
å
容ïŒãCïŒ\ Python27 \ agent.pywã

- IEããªã³ã«ããããŒã ããŒãžã空ã®ã¿ãã«èšå®ããèšå®ã§ãå¿
èŠã«å¿ããŠããã©ãŠã¶ãŒããããã£ã®ãã¹ãŠã®ä¿è·ã¡ã«ããºã ããªãã«ããŸãã
- SSDPãç¡å¹ã«ããŸãïŒstart-> execute-> msconfigãšãµãŒãã¹ã»ã¯ã·ã§ã³ã§ãSSDP Discovery Serviceããç¡å¹ã«ããŠãã¬ããŒãã§ãã®ãµãŒãã¹ããã®ãããã¯ãŒã¯èŠæ±ãé²ããŸãã

- åèµ·åããããŒãæã«è¡šç€ºããããŠã£ã³ããŠã§ãåèµ·åæã«ãã®ã¡ãã»ãŒãžã衚瀺ããªãããéžæããŠãOKããã¯ãªãã¯ããŸãã
- ã²ã¹ãOSãåèµ·åããåŸãstart-> execute-> cmdãå®è¡ããã³ã³ãœãŒã«ã§netstat -naãšå
¥åããŠã8000çªç®ã®ããŒãã«ãšãŒãžã§ã³ãããããã©ããã確èªããŸã

- æã®ãŸãŸã«ãå€ãããŒãžã§ã³ã®ããŸããŸãªè匱ãªãœãããŠã§ã¢ïŒãã©ãŠã¶ãŒãFlashãã¬ãŒã€ãŒãJavaãAcrobat Readerãªã©ïŒãã€ã³ã¹ããŒã«ããŸãïŒ http : //www.oldapps.com
泚ïŒãªãã£ã¹ã©ã€ã»ã³ã¹ããæã¡ã®å Žåã¯ãã€ã³ã¹ããŒã«ããããšããå§ãããŸãããšã«ãããã¹ã«ã€ããICQãã¡ãŒã«ã¯ã©ã€ã¢ã³ããã§ããã ãå€ãã€ã³ã¹ããŒã«ããã®ãæåã§ãã ããšãã°ãç§ãã¡ã®ãµã€ãããããã³ã°ããããã«ãŒã¯ããããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ã«äœåºŠã倱æããåŸãè匱æ§CVE2012-0158ãæªçšãããŠã€ã«ã¹ãåéããŸããã
ããã§ã²ã¹ãOSã®ã€ã³ã¹ããŒã«ãå®äºããŸããã
ã¹ãããã·ã§ããã®äœæïŒã²ã¹ãOSããªãã«ããªãïŒ
vboxmanage snapshot "WindowsXP" take "WindowsXPSnap01" --pause
ãªãã«ããŸãã
vboxmanage controlvm "WindowsXP" poweroff
Webã€ã³ã¿ãŒãã§ãŒã¹
Cuckoo Sandboxã«ã¯ãæ°æ§ã®2ã€ã®Webã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã å€ããã®ã¯ãæ°ãããã®ããæ
å ±éãå°ãªããæ©èœãå°ãªããã¯ããã«äŸ¿å©ã§ã¯ãããŸããã
å€ãã€ã³ã¿ãŒãã§ãŒã¹ïŒ

æ°ããã€ã³ã¿ãŒãã§ãŒã¹ïŒ

å€ãã€ã³ã¿ãŒãã§ã€ã¹ã¯ãããŒã¿ããŒã¹ãªãã§ãDjangoãªãã§ãutilsãã©ã«ããŒããweb.pyã¹ã¯ãªãããå®è¡ããã ãã§äžæãããããããã§ååã§ããã°ãããã䜿çšããŠãã ããã
Apacheãã€ã³ã¹ããŒã«ããŸãã
apt-get install apache2
Apacheãéžãã ã®ã¯ ç§ã¯åœŒã®ããšãããç¥ã£ãŠããã圌ãšãã£ãšé·ãä»äºãããŸãããå¿
èŠã«å¿ããŠãNginxãŸãã¯Unicornãèšå®ã§ããŸãã
ãã¡ã€ã«/etc/apache2/sites-enabled/000-default.confãåé€ãããŸã
次ã®å
容ã§/etc/apache2/sites-enabled/cuckoo.confãã¡ã€ã«ãäœæããŸãã
<VirtualHost *:80> ServerName cuckoo.local ServerAdmin webmaster@localhost DocumentRoot /opt/cuckoo/web ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined WSGIScriptAlias / /opt/cuckoo/web/web/wsgi.py <Directory /opt/cuckoo/web/web> <Files wsgi.py> Require all granted </Files> </Directory> Alias /static /opt/cuckoo/web/static <Directory /opt/cuckoo/web/static/> Require all granted </Directory> </VirtualHost>
ãã¡ã€ã«/opt/cuckoo/web/web/wsgi.pyã«ã¯æ¬¡ã®ãã®ããããŸãã
import os os.environ.setdefault("DJANGO_SETTINGS_MODULE", "web.settings")
ãããŠæ¬¡ã®ããã«å€æŽããŸãïŒ
import os, sys sys.path.append('/opt/cckoo') sys.path.append('/opt/cuckoo/web') os.chdir('/opt/cuckoo/web/') os.environ.setdefault("DJANGO_SETTINGS_MODULE", "web.settings")
æš©å©ãä¿®æ£ããŸãã
chown -R cuckoo:cuckoo /opt/cuckoo/
ãã¡ã€ã«/ etc / apache2 / envvarsã§apacheãèµ·åãããŠãŒã¶ãŒã倿ŽããŸã
APACHE_RUN_USER=www-data APACHE_RUN_GROUP=www-data
ã«
APACHE_RUN_USER=cuckoo APACHE_RUN_GROUP=cuckoo
wsgiãµããŒãã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããŸãã
aptitude install libapache2-mod-wsgi -y
ãœãããŠã§ã¢ã®èµ·å
ã€ã³ã¿ãŒãã§ã€ã¹ã®èµ·å
è¡exit 0ã®åã®ãã¡ã€ã«/etc/rc.localã«ã次ã®ããã«èšè¿°ããŸãã
VBoxManage list vms > /dev/null ifconfig vboxnet0 192.168.56.1
ãµã³ãããã¯ã¹ã¹ã¿ãŒãã¢ãã
apt-get install supervisor
次ã®å
容ã§/etc/supervisor/conf.d/cuckoo.confãã¡ã€ã«ãäœæããŸãã
[program:cuckoo] command=python cuckoo.py directory=/opt/cuckoo [program:cuckoo-api] command=python api.py directory=/opt/cuckoo/utils
ç§ãã¡ã¯å®æœããŸãïŒ
supervisord -c /etc/supervisor/supervisord.conf supervisorctl -c /etc/supervisor/supervisord.conf reload
iptablesã«ãŒã«ã®èªåããŒã
apt-get install iptables-persistent
å®äºããŸãããåèµ·ååŸããã¹ãŠã®ãµãŒãã¹ãéå§ããããã¹ãŠãæ©èœããŸãã
远å ã®ããã³ããšã«ãã³ãŠã®æ©èœ
PEID眲å
æ°ãã眲åããŒã¿ããŒã¹ãã€ã³ã¹ããŒã«ããŸããæ°ããããŒã¿ããŒã¹ã«ã¯2åã®æ°ããããŸã
cd /tmp wget http://research.pandasecurity.com/blogs/images/userdb.txt mv userdb.txt /opt/cuckoo/data/peutils/UserDB.TXT
Yara + AlienVault Labs APTè
åšã·ã°ããã£ã®ClamAVã«ãŒã«
泚ïŒãã³ãã³ã®ããžã¿ã«æµ·æŽã»ã³ã¿ãŒããClamAV-Yaraã«ãŒã«å€æã¹ã¯ãªãããããŠã³ããŒãããããšãããšããããªãã®åœããã®ãªã¯ãšã¹ãã¯èš±å¯ãããŠããŸããããšãããšã©ãŒã衚瀺ãããŸãã apt-get install clamav -y wget http://db.local.clamav.net/main.cvd wget http://db.local.clamav.net/daily.cvd sigtool -u main.cvd sigtool -u daily.cvd wget http://malwarecookbook.googlecode.com/svn-history/r5/trunk/3/3/clamav_to_yara.py python clamav_to_yara.py -f main.ndb -o main.yar python clamav_to_yara.py -f daily.ndb -o daily.yar mkdir /opt/cuckoo/data/yara/clamav mv *.yar /opt/cuckoo/data/yara/clamav/
倿ãããããŒã¿ããŒã¹ã¯ãç¡å¹ãªçœ²åEOL_0_94_2ãåç
§ããŠãšã©ãŒãã¹ããŒããåé€ããŸãã
è¡/opt/cuckoo/data/yara/clamav/main.yarããè¡ãåé€
«rule EOL_0_94_2 { strings: $a0 = { This ClamAV version has reached End of Life! Please upgrade to version 0.95 or later. For more information see www.clamav.net/eol-clamav-094 and www.clamav.net/download }^M condition: $a0 }»
ãŸãã¯ãåã«æ¬¡ã®ã³ãã³ããå®è¡ããŸãã
RM_EOL=$(sed -n '/EOL_0_94_2/{=}' main.yar) for n in {1..8}; do sed -i "${RM_EOL}d" main.yar; done
次ã«ãAlienVaultsããAPTè
åšã«ãŒã«ãèšå®ããŸãã
git clone https://github.com/AlienVault-Labs/AlienVaultLabs.git mv AlienVaultLabs/malware_analysis/ /opt/cuckoo/data/yara/
ãããŠããããã®ã«ãŒã«ãCuckooã«æ¥ç¶ããŸãïŒ
ãã¡ã€ã«/opt/cuckoo/data/yara/index_binary.yarã«æ¬¡ã®è¡ãèšè¿°ããŸãã
include "clamav/main.yar" include "clamav/daily.yar" include "malware_analysis/CommentCrew/apt1.yara" include "malware_analysis/FPU/fpu.yar" include "malware_analysis/Georbot/GeorBotBinary.yara" include "malware_analysis/Georbot/GeorBotMemory.yara" include "malware_analysis/Hangover/hangover.yar" include "malware_analysis/KINS/kins.yar" include "malware_analysis/OSX_Leverage/leverage.yar" include "malware_analysis/TheMask_Careto/mask.yar" include "malware_analysis/Urausy/urausy_skypedat.yar"
Zer0m0nãŸãã¯ãµã³ãããã¯ã¹ãé衚瀺ã«ãã
æªæã®ãããã¡ã€ã«ã¯ãå®è¡åã«ãããã¬ãŒãŸãã¯ä»®æ³ç°å¢ããã§ãã¯ããããšããå Žåããããçµæã¯æåŸ
ã¯ããã§ãã 以äžã¯ãæ€èšŒã®ããã«å®è¡å¯èœãã¡ã€ã«ãããŠã³ããŒããããšãã«
Paranoid Fishãã¹ãã衚瀺ãããã®ã§ãã

ããã¯Zer0m0nã§ç°¡åã«ä¿®æ£ã§ããŸãã
zer0m0nã¯ããã«ãŠã§ã¢ã®å®è¡äžã«ã«ãŒãã«åæãå®è¡ããCuckoo Sandboxã®ãã©ã€ããŒã§ãã OSã®ãä»®æ³æ§ããã»ãŒå®å
šã«é ãããšãã§ããCuckooã®æªæã®ãããã¡ã€ã«ã®æ€åºããã€ãã¹ã§ããŸãã
ã€ã³ã¹ããŒã«ããŠãã ããïŒ
cd /tmp git clone https://github.com/conix-security/zer0m0n.git cd zer0m0n/bin cp cuckoo.patch /opt/cuckoo cd /opt/cuckoo patch -p1 < ./cuckoo.patch cp /tmp/zer0m0n/bin/logs_dispatcher.exe /opt/cuckoo/analyzer/windows/dll/ cp /tmp/zer0m0n/bin/zer0m0n.sys /opt/cuckoo/analyzer/windows/dll/ cp -rf /tmp/zer0m0n/signatures/* /opt/cuckoo/modules/signatures/
æš©å©ãä¿®æ£ããŸãã
chown -R cuckoo:cuckoo /opt/cuckoo/
ãã®åŸãWebã€ã³ã¿ãŒãã§ãŒã¹ã§ã远å ãªãã·ã§ã³ã§ã¹ãã£ã³ãéžæã§ããŸããããã©ã«ãã§ã¯ãUserlandãŸãã¯zer0m0n Kernellandã䜿çšããŸãã

ã³ã³ãœãŒã«ã§ã¹ãã£ã³ãå®è¡ããå Žå-kernel_analysis = yesãªãã·ã§ã³ã䜿çšããŸã
ãã§ãã¯ãå床å®è¡ããŸãã

Cuckooãã€ã³ã¹ããŒã«ããã³æ§æããããã®æ¢è£œã®ã¹ã¯ãªãã
çŽæã©ããã宿ããã¹ã¯ãªãããæçš¿ããŸãã ã²ã¹ãOS以å€ã®ãã¹ãŠãèªåçã«æ§æããŸãã ã¹ã¯ãªããã®å®è¡åŸã
ã²ã¹ãOSã®ã»ããã¢ããã«é¢ããé
ç®ã«æ»ã£ãŠæ§æããå¿
èŠããããŸãã
ããŒãã¹
ããŒãã¹ãšããŠãCuckoo Sandboxã
Maltegoããã°ã©ã ãšçµ±åããæé ãæ²èŒããŸãã
ã·ã¹ãã ãããŒã8090ã§å®è¡ããã
REST APIãµã³ãããã¯ã¹ãµãŒãã¹ãšçµ±åããŸãã
ç§ã¯Macã§äœæ¥ããmac os 10.9.4ã§æ¬¡ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸããããLinuxã·ã¹ãã ã§ã¯ãã¹ãŠãåé¡ãªãã€ã³ã¹ããŒã«ãããåãããã«åäœããã¯ãã§ãïŒ
éå§ããã«ã¯ããµã€ãããMaltegoãããŠã³ããŒãããã¢ããªã±ãŒã·ã§ã³ãã©ã«ããŒã«è§£åããŸãã
ããã°ã©ã ãéããåŸïŒ

圌女ã¯ããã°ã€ã³ããããç»é²ãç»é²ããã°ã€ã³ïŒãã£ããã£ãæäœããªãã§ãäœãå
¥åããªããæ©èœããªãïŒãææ¡ããéçºè
ã®ãªããžããªããSandboxãMaltegoãšçµ±åããããã«å¿
èŠãªãã¡ã€ã«ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸãã
sudo -s git clone https://github.com/bostonlink/cuckooforcanari.git cd cuckooforcanari python setup.py install canari create-profile cuckooforcanari
cuckooèšå®ãMatlegoã«ã€ã³ããŒãããå¿
èŠããããŸãã
å·Šäžé
ã®ããã°ã©ã ã¢ã€ã³ã³ãã¯ãªãã¯ãã[ã€ã³ããŒã]ã[æ§æã®ã€ã³ããŒã]ã®é ã«ã¯ãªãã¯ããŠãgithubããããŠã³ããŒããããã©ã«ããŒããæ§æãéžæããŸãã

ãã¹ãŠãã€ã³ããŒãããŸãã

å®äºãæ§æãã¡ã€ã«ãéããŠããã«ãŠã§ã¢ãé
眮ãããã¹ããããŒãããã©ã«ããŒãå
¥åããŸãã
vim ~/.canari/cuckooforcanari.conf
ããã°ã©ã ã§æ°ããã¹ã±ãžã¥ãŒã«ãäœæããCuckoo Malware Sampleã¢ã€ã³ã³ããã£ãŒãã«ãã©ãã°ãããã¡ã€ã«ã®ååããŠã€ã«ã¹ã®ååã«å€æŽããAnalysysã«ãã¡ã€ã«ãéä¿¡ããŠã¢ããããŒãããŸãã

ããŠã³ããŒãåŸããžã§ãçªå·ã衚瀺ãããŸãïŒ

ã¹ãã£ã³ãå®äºãããšãã°ã©ã圢åŒã®ããŒã¿ãåãåãããšãã§ããŸãã

éçºè
ããã®å
¬åŒãããªã§ããã«ã€ããŠã®è©³çްãèŠãããšãã§ããŸãïŒ
å¥ã®ããŒãã¹ããããã§èŠã€ããæ¬ã¯ãCuckoo Sandboxã䜿çšããŠæªæã®ãããã¡ã€ã«ãåæããããã®è¯ãã¬ã€ãã§ãããŸããSymantec Endpoint Protection 12.1ã¢ã³ããŠã€ã«ã¹ãè·å Žã§äœ¿çšããŠããå Žåãã·ãã³ããã¯ãå
¬åŒã«ãµããŒãããŠããªãWindows SEPQuarantineTool.zipã®ã³ã³ãœãŒã«ãŠãŒãã£ãªãã£ã䜿çšã§ããŸããããµããŒããžã®ãªã³ã¯ãèŠã€ãããŸããããã®ãŠãŒãã£ãªãã£ã䜿çšãããšãåããŠãŒãã£ãªãã£ã§æ€ç«ãããã¡ã€ã«ãåŒãåºããŠåŸ©å
ããREST APIã䜿çšããŠWindowsã®curlã䜿çšããŠãµãŒããŒã«ãã¡ã€ã«ãã¢ããããŒããããã¡ã€ã«ãæ€ç«ã«æ»ãããšãã§ããŸãããããã£ãŠãè
åšã®åæãèªååãããŠã€ã«ã¹ã䟵å
¥ãããµã€ããšãµãŒããŒã®ãã©ãã¯ãªã¹ããäœæããŸããçµè«ãšããŠããã®ããŒã«ã¯ãã¹ãŠã®ã¿ã¹ã¯ãå®äºããã®ã«åœ¹ç«ã¡ãèšäºã®åé ã§èšåããããã«ãŒã®ãã°ãšæªæã®ãããã¡ã€ã«ã¯æåéãæ°åã§åæãããããã«ãŒã䜿çšãããã«ãŠã§ã¢ã®å
šäœåãçè§£ã§ããããã«ãªããŸããïŒãæž
èŽããããšãããããŸããã
䜿çšããããœãŒã¹ã®ãªã¹ã
docs.cuckoosandbox.orgxakep.ru/articles/57409lanswer.blogspot.ru/2012/11/add-cucksandbox-to-ubuntu-service.htmlreverselab.info/page/cuckoo-sandboxwww.alienvault.com/blogs/tag/yarawww.securitylab.ru/analytics/441524.phpwww.modern.ie/ru-ruwww.aldeid.com/wiki/PEiDblog.prowling.nu/2014/08/cuckoo-sandbox-django-interface-with.htmlgithub.com/conix-security/zer0m0ngithub.com/bostonlink/cuckooforcanarisanti-bassett.blogspot.ru/2013/01/installing-cuckoo-sandbox-on-virtualbox.html