Win32 / Industroyerã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ïŒICSïŒãç¹ã«é»æ°å€é»æã®äœæ¥ããã»ã¹ãäžæããããã«èšèšãããé«åºŠãªãã«ãŠã§ã¢ã§ãã
Win32 / Industroyerã®äœæè
ã¯é«ãè³æ Œãæã¡ãé»åæ¥çã®ç£æ¥çšå¶åŸ¡ã·ã¹ãã ãšéä¿¡ãããã³ã«ãæ·±ãç解ããŠããŸãã ã¿ãŒã²ããç°å¢ã§äœ¿çšãããç¹æ®ãªæ©åšã«ã¢ã¯ã»ã¹ããããšãªããã ãã§ããã®ãããªãœãããŠã§ã¢ãäœæããã³ãã¹ãã§ãããšã¯èããããŸããã
ãã«ãŠã§ã¢ã®äœæè
ã¯ã次ã®æšæºã§èª¬æãããŠãã4ã€ã®ç£æ¥çšãããã³ã«ã®ãµããŒããå®è£
ããŸããã
- IEC 60870-5-101ïŒIEC 101ïŒ
- IEC 60870-5-104ïŒIEC 104ïŒ
- IEC 61850
- ããã»ã¹ã³ã³ãããŒã«ããŒã¿ã¢ã¯ã»ã¹ïŒOPC DAïŒã®OLE
ããã«å ããŠãIndustroyerã®èè
ã¯ãç¹å®ã®ãªã¬ãŒä¿è·ããã€ã¹ãç¹ã«Siemens SIPROTECã©ã€ã³ã察象ãšããDoSæ»æïŒãµãŒãã¹æåŠ-ãµãŒãã¹æåŠïŒã®ããã®ããŒã«ãéçºããŸããã
Win32 / Industroyerã®æ©èœã¯å°è±¡çã§ãã 2015幎ã®
ãŠã¯ã©ã€ãã®ãšãã«ã®ãŒã·ã¹ãã ãžã®æ»æã§äœ¿çšã
ã ã2015幎12æ23æ¥ã«å€§èŠæš¡ãªåé»ãåŒãèµ·ãããããŒã«ïŒBlackEnergyãKillDiskãããã³æ£åœãªãªã¢ãŒãã¢ã¯ã»ã¹ãœãããŠã§ã¢ãå«ããã®ä»ã®ã³ã³ããŒãã³ãïŒãšæ¯èŒãããšãIndustroyerã®èåŸã«ã¯ãµã€ããŒã°ã«ãŒãããããšèšããŸãããé«ãã¬ãã«ã èè
ã¯ãé»æ°å€é»æã®ãããã¯ãŒã¯å
ã®ãµãŒããããã¬ãŒã«ãŒãšãµãŒããããã¬ãŒã«ãŒãçŽæ¥å¶åŸ¡ã§ããæªæã®ããããã°ã©ã ãäœæããŸããã ããã€ãã®å
åã«ãããšã2016幎12æã«Industroyerãããšãã®åé»ã«æ¥ç¶ããå¯èœæ§ããããšæ³å®ããŠããŸãã ãã ããããã¯å·çæç¹ã§ã¯ç¢ºèªãããŠãããã調æ»ã¯é²è¡äžã§ãã ææçµè·¯ã¯ãŸã 確ç«ãããŠããŸããã
Industroyerã¯ããã€ãã®ã¢ãžã¥ãŒã«ã§æ§æãããŠããããã®èª¬æãšåæã¯ã¬ããŒãã®ä»¥äžã®ã»ã¯ã·ã§ã³ã«ç€ºãããŠããŸãã 詳现ã«é²ãåã«ãæªæã®ããããã°ã©ã ã®ã³ã³ããŒãã³ãéã®æ¥ç¶ã瀺ãç°¡ç¥åãããã¹ããŒã ãæäŸããŸãã
å³1. Win32 / Industroyerã³ã³ããŒãã³ãã®ç°¡ç¥å³ãäžéšã®ã³ã³ããŒãã³ãïŒããŒã¿æ¶ããŽã ãå«ãïŒã¯ã2015幎ã«ãŠã¯ã©ã€ãã®ãšãã«ã®ãŒäŒç€Ÿã«å¯ŸããBlackEnergyæ»æã§äœ¿çšãããããŒã«ãšæŠå¿µã䌌ãŠããŸãã ãã ããéå»ã®æ»æãšæ°ãããã«ãŠã§ã¢ã³ãŒãã®éã«ã¯é¢ä¿ããããŸããã
ã¡ã€ã³ããã¯ãã¢
Industroyerã®ã¡ã€ã³ã³ã³ããŒãã³ãã§ããã¡ã€ã³ããã¯ãã¢ã¯ãæ»æè
ãããã°ã©ã ã®æ®ãã®ã³ã³ããŒãã³ããå¶åŸ¡ããããã«äœ¿çšããŸãã
ããã¯ãã¢ã«é©ããŠããããããã®ã³ã³ããŒãã³ãã¯éåžžã«åçŽã§ãã HTTPSçµç±ã§ãªã¢ãŒãCïŒCãµãŒããŒã«æ¥ç¶ããæ»æè
ããã³ãã³ããåãåããŸãã 調æ»ãããã¹ãŠã®ãµã³ãã«ã¯ãããŒã«ã«ãããã¯ãŒã¯äžã«ããåããããã·ã¢ãã¬ã¹ã䜿çšããããã«ããŒãã³ãŒãã£ã³ã°ãããŠããŸãã ãããã£ãŠãããã¯ãã¢ã¯æããã«ç¹å®ã®çµç¹ã§æ©èœããããšãç®çãšããŠããŸãã ãŸããã»ãšãã©ã®ããã¯ãã¢CïŒCãµãŒããŒãTorã䜿çšããŠããããšã«ãèšåãã䟡å€ããããŸãã
ããã¯ãã¢ã®æãèå³æ·±ãæ©èœã¯ããããããæ»æè
ããã«ãŠã§ã¢ãã¢ã¯ãã£ãã«ãªãç¹å®ã®æéãèšå®ã§ããããšã§ãã ããšãã°ãæéåŸã«CïŒCãµãŒããŒã«ã¢ã¯ã»ã¹ããããã«ããã¯ãã¢ãå€æŽã§ããŸãã ããã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ã®ãã§ãã¯ã®ã¿ã«åºã¥ããæ€åºãè€éã«ããŸãã ãããããããŸã§ã«ç 究ããããã¹ãŠã®ãµã³ãã«ã¯ã24æéæ©èœããŠããŸãã
å³2.æéãèšå®ããæ©èœãåããã¡ã€ã³ããã¯ãã¢ã®éã³ã³ãã€ã«ãããã³ãŒããªã¢ãŒãCïŒCãµãŒããŒã«æ¥ç¶ããåŸãã¡ã€ã³ããã¯ãã¢ã¯æ¬¡ã®ããŒã¿ãPOSTãªã¯ãšã¹ãã«éä¿¡ããŸãã
GetCurrentHwProfile
é¢æ°ã䜿çšããŠååŸããçŸåšã®æ©åšãããã¡ã€ã«ã®GUIDæååïŒã°ããŒãã«ã«äžæãªèå¥åïŒ- ãã«ãŠã§ã¢ããŒãžã§ã³-1.1e
- ããŒãã³ãŒãããããµã³ãã«ID
- 以åã«åä¿¡ããã³ãã³ãã®çµæ
ããŒãã³ãŒããããIDã¯ãææãããã·ã³ã®èå¥åãšããŠæ»æè
ã«ãã£ãŠäœ¿çšãããŸãã 調æ»ãããã¹ãŠã®ãµã³ãã«ã®äžã§ã次ã®IDå€ãèŠã€ãããŸããã
- Def
- Def-c
- Def-ws
- DEF-EP
- DC-2-TEMP
- DC-2
- CES-McA-TEMP
- Ces
- SRV_WSUS
- SRV_DC-2
- SCE-WSUS01
ã¡ã€ã³ããã¯ãã¢ã¯æ¬¡ã®ã³ãã³ãããµããŒãããŠããŸãã
管çè
æš©éãååŸããåŸãæ»æè
ã¯ã€ã³ã¹ããŒã«ãããããã¯ãã¢ã
WindowsãµãŒãã¹ããã°ã©ã ãšããŠå®è¡ãããããç¹æš©çãªããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãã§ããŸãã ãããè¡ãã«ã¯ãæ¢åã®éèŠã§ã¯ãªãWindowsããã»ã¹ãéžæãã
ImagePath
ã¬ãžã¹ããªèšå®ãæ°ãããã€ããªããã¯ãã¢ãã¡ã€ã«ãžã®ãã¹ã«çœ®ãæããå¿
èŠããããŸãã
WindowsãµãŒãã¹ãšããŠå®è¡ãããã¡ã€ã³ããã¯ãã¢ã®æ©èœã¯ã説æãããã®ãšåãã§ãã ãã ãã2ã€ã®å°ããªéãããããŸããããã¯ãã¢ããŒãžã§ã³ã®ååïŒ1.1eã§ã¯ãªã1.1sïŒãšã³ãŒãã®é£èªåã§ãã ãã®ããŒãžã§ã³ã®ããã¯ãã¢ã®ã³ãŒãã¯ãäžå¿
èŠãªã¢ã»ã³ãã©ã³ãã³ããšæ··åšããŠããŸãã
å³3. WindowsãµãŒãã¹ãšããŠå®è¡ãããã¡ã€ã³ããã¯ãã¢ã®é£èªåãããã¢ã»ã³ããªã³ãŒããè¿œå ã®ããã¯ãã¢
è¿œå ã®ããã¯ãã¢ã¯ä»£æ¿ã®å®å®æ§ã¡ã«ããºã ãæäŸããŸããããã«ãããã¡ã€ã³ã®ããã¯ãã¢ãæ€åºãŸãã¯éã¢ã¯ãã£ãåãããå Žåãæ»æè
ã¯ã¿ãŒã²ãããããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãåãæ»ãããšãã§ããŸãã
ããã¯ãã¢ã¯ãWindowsã®ã¡ã¢åž³ã¢ããªã±ãŒã·ã§ã³ã®ããã€ã®æšéŠ¬ããŒãžã§ã³ã§ãã ããã¯ãã«æ©èœã®ã¢ããªã±ãŒã·ã§ã³ã§ããããŠã€ã«ã¹äœæè
ã¯ãèµ·åãããã³ã«å®è¡ãããæªæã®ããã³ãŒããè¿œå ããŠããŸãã ããã«ã管çè
æš©éãååŸãããšãæ»æè
ã¯æªæã®ããã¡ã¢åž³ãæ£åœãªãã®ã«æåã§çœ®ãæããããšãã§ããŸãã
è¿œå ãããæªæã®ããã³ãŒãã¯éåžžã«é£èªåãããŠããŸãã 埩å·ååŸããªã¢ãŒãCïŒCãµãŒããŒïŒCïŒCã¡ã€ã³ããã¯ãã¢ãšã¯ç°ãªãïŒã«æ¥ç¶ãããã€ããŒããããŒãããŸãã ããã¯ãã¡ã¢ãªã«çŽæ¥ããŒããããŠå®è¡ãããã·ã§ã«ã³ãŒã圢åŒã§ãã ããã«ãè¿œå ãããã³ãŒãã¯ããã¡ã€ã«ã®æåŸã«ä¿åãããŠããWindows Notepadã®ãœãŒã¹ã³ãŒãã埩å·åããå®è¡ãæž¡ããŸããããã«ãããã¢ããªã±ãŒã·ã§ã³ãæ£åžžã«åäœããŸãã
å³4.å
ã®ã¡ã¢åž³ã®ãã€ããªã³ãŒãïŒå·ŠïŒãšããã¯ãã¢ã®æ¯èŒãã©ã³ãã£ãŒã³ã³ããŒãã³ã
ã³ã³ããŒãã³ãã¯ããã€ããŒããšããŒã¿æ¶å»ã³ã³ããŒãã³ããå®è¡ããããã«èšèšãããå¥åã®å®è¡å¯èœãã¡ã€ã«ã§ãã
èµ·åã³ã³ããŒãã³ãã«ã¯ãç¹å®ã®æ¥æãå«ãŸããŠããŸãã 調æ»å¯Ÿè±¡ã®ãµã³ãã«ã«ã¯ã2016幎12æ17æ¥ãš20æ¥ã®2ã€ã®æ¥ä»ãèšå®ãããŠããŸãã 2ã€ã®æ¥ä»ã®ãããããå°çãããšããã«ãã³ã³ããŒãã³ãã¯2ã€ã®ã¹ã¬ãããäœæããŸãã 1ã€ç®ã¯æªæã®ããDLLãããŒãããããšãã2ã€ç®ã¯ïŒã³ã³ããŒãã³ãã®ããŒãžã§ã³ã«å¿ããŠïŒ1ã2æéåŸ
æ©ããŠãããããŒã¿æ¶å»ã³ã³ããŒãã³ããããŒãããããšããŸãã äž¡æ¹ã®ã¹ã¬ããã¯æé«ã®åªå
床
THREAD_PRIORITY_HIGHEST
æã£ãŠããŸããããã¯ãCPUãªãœãŒã¹ã®ã·ã§ã¢ãé«ããªãããšãæå³ããŸãã
æªæã®ããDLLã®ååã¯ãã¡ã€ã³ã®ããã¯ãã¢ã®ã³ãã³ãã®1ã€ã§æäŸãããã³ãã³ãã©ã€ã³ãã©ã¡ãŒã¿ãŒïŒãã·ã§ã«ã³ãã³ãã®å®è¡ãïŒãä»ããŠæ»æè
ã«ãã£ãŠè¿œå ãããŸãã ããŒã¿æ¶å»ãã¡ã€ã«ã®ååã¯åžžã«
haslo.dat
ã§ãã äºæ³ãããã³ãã³ãã©ã€ã³ã¯æ¬¡ã®ãšããã§ãã
%LAUNCHER%.exe %WORKING_DIRECTORY% %PAYLOAD%.dll %CONFIGURATION%.ini
åã³ãã³ãã©ã€ã³åŒæ°ã¯æ¬¡ã瀺ããŸãã
â¢
%LAUNCHER%.exe
ã©ã³ãã£ãŒã³ã³ããŒãã³ãã®ãã¡ã€ã«å
â¢
%WORKING_DIRECTORY%
-æªæã®ããDLLããã³æ§æãä¿åãããŠãããã£ã¬ã¯ããª
â¢
%PAYLOAD%.dll
æªæã®ããDLLã®ãã¡ã€ã«å
â¢
%CONFIGURATION%.ini
ç¹å®ã®ãã€ããŒãã®æ§æããŒã¿ãä¿åãããã¡ã€ã«ã ãã®ãã¡ã€ã«ãžã®ãã¹ã¯ãã¹ã¿ãŒãã¢ããã³ã³ããŒãã³ãã«ãã£ãŠæªæã®ããDLLã«ãã£ãŠæž¡ãããŸãã
ãã€ããŒãããã³ããŒã¿æ¶å»ã³ã³ããŒãã³ãã¯ãæšæºã®Windows DLLãã¡ã€ã«ã§ãã ã©ã³ãã£ãŒã«ãã£ãŠããŒãããã«ã¯ãå³ã«ç€ºãããã«
Crash
æ©èœããšã¯ã¹ããŒãããå¿
èŠããããŸãã 5ã
å³5.å
éšåCrash101.dll
ãšãšã¯ã¹ããŒããããCrash
é¢æ°ãæã€æªæã®ããDLLã®äŸã³ã³ããŒãã³ã101
ãã¡ã€ã«å
101.dll
æªæã®ããDLLã¯ãé»åã·ã¹ãã ã®ç£èŠãšå¶åŸ¡ã®ããã®ãããã³ã«ãèšè¿°ããåœéæšæºIEC 101ïŒå¥å
IEC 60870-5-101 ïŒã«ã¡ãªãã§åœåãããŠããŸãã ãã®ãããã³ã«ã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ãšãªã¢ãŒãã¿ãŒããã«ãŠãããïŒRTUïŒéã®éä¿¡ãæäŸããŸãã ããŒã¿ã¯ã·ãªã¢ã«æ¥ç¶ãä»ããŠäº€æãããŸãã
ã³ã³ããŒãã³ã101ã¯ãIEC 101æšæºã§èª¬æãããŠãããããã³ã«ãéšåçã«å®è£
ããŠãããRTUããã³ãã®ãããã³ã«ããµããŒãããä»ã®ããã€ã¹ãšéä¿¡ã§ããŸãã
å®è¡åŸãã³ã³ããŒãã³ã101ã¯INIãã¡ã€ã«ã«ä¿åãããŠããæ§æãåæããŸãã æ§æã«ã¯ãããã»ã¹åãWindowsããã€ã¹åïŒéåžžã¯COMããŒãïŒãç¯å²ã®æ°ãæ
å ±ãªããžã§ã¯ãã¢ãã¬ã¹ïŒIOAïŒã®ç¯å²å€ãªã©ãããã€ãã®ãšã³ããªãå«ããããšãã§ããŸãã IOAã¯ãããã€ã¹å
ã®ç¹å®ã®ããŒã¿é
ç®ãèå¥ããçªå·ã§ãã å³ å³6ã¯ã10ã15ããã³20ã25ã®2ã€ã®IOAç¯å²ãå®çŸ©ãããã³ã³ããŒãã³ã101ã®æ§æãã¡ã€ã«ã瀺ããŠããŸãã
å³6.ã³ã³ããŒãã³ã101ã®æ§æäŸãæ§æã§æå®ãããããã»ã¹ã®ååã¯ãæ»æè
ã被害è
ã®ã·ã¹ãã ã§å®è¡ãããŠãããšæ³å®ããã¢ããªã±ãŒã·ã§ã³ã«å±ããŸãã ããã¯ããã·ã³ãã·ãªã¢ã«æ¥ç¶ãä»ããŠRTUãšéä¿¡ããããã«äœ¿çšããã¢ããªã±ãŒã·ã§ã³ã§ãªããã°ãªããŸããã ã³ã³ããŒãã³ã101ã¯ããã®ããã»ã¹ã®å®äºãè©Šã¿ãWindows APIã®
CreateFile
ã
WriteFile
ããã³
ReadFile
ã䜿çšããŠãæå®ãããããã€ã¹ã«ã¢ã¯ã»ã¹ããŸãã æ§æãã¡ã€ã«ã®æåã®COMããŒãã¯å®éã®éä¿¡ã«äœ¿çšãããä»ã®2ã€ã¯ä»ã®ããã»ã¹ãã¢ã¯ã»ã¹ã§ããªãããã«éããŠããŸãã ãããã£ãŠãã³ã³ããŒãã³ã101ã¯RTUããã€ã¹ãå¶åŸ¡ã§ããŸãã
ã³ã³ããŒãã³ãã¯ããã¹ãŠã®IOAç¯å²ã«ããã£ãŠç¹°ãè¿ãããŸãã åIOAã«ã€ããŠã1ããžã·ã§ã³ïŒ
C_SC_NA_1
ïŒããã³2ããžã·ã§ã³ã³ãã³ãïŒ
C_DC_NA_1
ïŒã®selectããã³executeã³ãã³ãã®ãã±ãããäœæããRTUããã€ã¹ã«éä¿¡ããŸãã ã³ã³ããŒãã³ãã®äž»ãªç®çã¯ãã·ã³ã°ã«ããžã·ã§ã³ããã³2ããžã·ã§ã³ã®ã³ãã³ãã¿ã€ãIOAã®ãªã³/ãªãã¹ã€ããã®å€ãå€æŽããããšã§ãã ãã®ãããæåã®æ®µéã§ã¯ãã³ã³ããŒãã³ãã¯IOAããªãã«åãæ¿ãã2çªç®ã®æ®µéã§ã¯ãªã³ãæåŸã®æ®µéã§ã¯ãªãã«æ»ããŸãã
å³7. Kaitai Struct WebIDEã§è§£æããããã€ããŒãããã±ãŒãžã®äŸãã³ã³ããŒãã³ã104
ãã¡ã€ã«åã
104.dll
ã®DLLã¯ãIEC 104
æšæº ïŒ
IEC 60870-5-104 ïŒã«
104.dll
ãŠåœåãããŠããŸãã IEC 104ãããã³ã«ã¯IEC 101ãè£å®ããŠãTCP / IPãä»ããŠããŒã¿ãéä¿¡ããŸãã æè»ãªæ§æã®ãããã§ãããŸããŸãªæ©åšã®æ»æè
ãã³ã³ããŒãã³ããæ§æã§ããŸãã å³ 8ã¯ãæ§æãã¡ã€ã«ãã©ã®ããã«èŠãããã瀺ããŠããŸãã
å³ 8.ãµã³ãã«ã®ã³ã³ããŒãã³ãæ§æDLLãã¡ã€ã«104ãã³ã³ããŒãã³ãïŒïŒïŒãå®è¡ããåŸãæ§æãã¡ã€ã«ãèªã¿åãããšããã æ§æãã¡ã€ã«ãžã®ãã¹ã¯ãããŒããŒã³ã³ããŒãã³ãããååŸãããŸãã
æ§æã«ã¯
STATION
ã»ã¯ã·ã§ã³ãå«ãŸãããã®åŸã«ã³ã³ããŒãã³ã104ã®åäœã決å®ããããããã£ãç¶ããŸããæ§æã«ã¯å€ãã®
STATION
ã¬ã³ãŒããå«ãŸããå ŽåããããŸãã
ãã®ã³ã³ããŒãã³ãã®åæã§ã¯ã次ã®å¯èœãªæ§æãã©ã¡ãŒã¿ãŒã瀺ãããŠããŸãã
æ§æãã¡ã€ã«ãèªã¿åã£ãåŸãã³ã³ããŒãã³ã104ã¯ãå
STATION
ãã©ã°ã¡ã³ãããšã«ããã»ã¹ãäœæããŸãã ã³ã³ããŒãã³ã104ã¯ããã®ãããªåããã»ã¹ã§ãIEC 104æšæºã«èšè¿°ãããŠãããããã³ã«ã䜿çšããŠæå®ãããIPã¢ãã¬ã¹ãšã®éä¿¡ãè©Šã¿ãŸããæ¥ç¶ã確ç«ããåã«ãããã€ã¹ãšã®éä¿¡ãæ
åœããæ£åœãªããã»ã¹ã®å®äºãè©Šã¿ãŸãã ãã
stop_comm_service
ã
stop_comm_service
ããããã£
stop_comm_service
æ§æã§æå®ãããŠããå Žåã«ã®ã¿çºçããŸãã ããã©ã«ãã§ã¯ãã³ã³ããŒãã³ã104ã¯
D2MultiCommService.exe
ãšããååã§ããŸãã¯ãã®æ§æã§æå®ãããååã§ããã»ã¹ãçµäºããŸãã
ã³ã³ããŒãã³ã104ã䜿çšããåºæ¬çãªèãæ¹ã¯æ¯èŒçåçŽã§ãã æå®ãããIPã«æ¥ç¶ããæ§æã§æå®ãããASDUã¢ãã¬ã¹ã§ãã±ããã®éä¿¡ãéå§ããŸãã ãã®ããŒã¿äº€æã®ç®çã¯ãIOAãªã³/ãªãã¿ã€ãã®ããŒã ã«é£çµ¡ããããšã§ãã æ§æãã¡ã€ã«ã§ãæ»æè
ã¯
operation
ããããã£ãå®çŸ©ããŠãåäžäœçœ®ã¿ã€ãã®IOAã¢ãã¬ã¹ãããŒãªã³ã°ãããæ¹æ³ã瀺ãããšãã§ããŸãã
æåã®ãã®ãããª
operation
ã¢ãŒãã¯
range
ã§ãã ããã«ãŒã¯ããã䜿çšããŠã察象ã®ããã€ã¹ã§çºçããå¯èœæ§ã®ããIOAãæ€åºããŸãã IEC 104èŠæ Œã§èª¬æãããŠãããããã³ã«ã¯ãã®æ
å ±ãååŸããããã®ç¹å®ã®æ¹æ³ãæäŸããŠããªãããã圌ãã¯ãã®ã¢ãããŒããé©çšããå¿
èŠããããŸãã
range
ã¯2段éã§æ©èœããŸãã æåã«ãæ§æãã¡ã€ã«ããIOAç¯å²ãåãåã£ãåŸãã³ã³ããŒãã³ã104ã¯å®å
IPã¢ãã¬ã¹ã«æ¥ç¶ããæå®ãããIOAãããŒãªã³ã°ããŸãã ãããã®ïŒ©ïŒ¯ïŒ¡ã®ããããã«ã€ããŠãã³ã³ããŒãã³ãïŒïŒïŒã¯ãéžæããã³å®è¡åœä»€ã®ãã±ãããéä¿¡ããŠãç¶æ
ãå€æŽãããã·ã³ã°ã«ãã€ã³ãåœä»€ã¿ã€ãã§ãããã©ãããæ€èšŒããã
å³ 9. Wiresharkã§ãã³ãŒããããã³ã³ããŒãã³ã104ã®äŸãç¹å®ã®ç¯å²ã®ãã¹ãŠã®å¯èœãªIOAãããŒãªã³ã°ããããšããã«ãã³ã³ããŒãã³ã104ã¯
range
ã¢ãŒãã®ç¬¬2段éã«é²ã¿ãŸãã ãã°ãžã®æžã蟌ã¿æ©èœãæå¹ã«ãªã£ãŠããå Žåãã³ã³ããŒãã³ãã¯ã
Starting only success
ãæžã蟌ã¿ãŸãã 2çªç®ã®ã¹ããŒãžã®æ®ãã®éšåã¯ã以åã«çºèŠãããã·ã³ã°ã«ããžã·ã§ã³ã¿ã€ãã®IOAã䜿çšããç¡éã®ãµã€ã¯ã«ã§æ§æãããŠããŸãã ã«ãŒãã§ã¯ãã³ã³ããŒãã³ãã¯ç¶ç¶çã«éžæããã³å®è¡ã³ãã³ãã®ãã±ãããéä¿¡ããŸãã ããã«ã
change
ãªãã·ã§ã³ãæå®ãããŠããå Žåãã³ã³ããŒãã³ãã¯ãµã€ã¯ã«ã®ã¹ããŒãžéã§ãªã³/ãªãç¶æ
ãåãæ¿ããŸãã
å³ å³10ã¯ãåæäžã«ã³ã³ããŒãã³ã104ãäœæãããã°ãã¡ã€ã«ã瀺ããŠããŸãã ãããããã³ã³ããŒãã³ããIOAã10ãã15ãŸã§ããŒãªã³ã°ããåäžäœçœ®ã¿ã€ãã®IOAãæ€åºããããšãã«ãŒãã§ãããã䜿çšãå§ããããšãããããŸãã æ§æã§ã¯ã
change
ãªãã·ã§ã³ããªã³ã«ãªã£ãŠããããããµã€ã¯ã«ã®éã«ã³ã³ããŒãã³ãã¯ã¹ã€ããå€ããªã³ãããªãã«åãæ¿ããããããã°ã«æžã蟌ã¿ãŸããã
å³ 10.ã³ã³ããŒãã³ã104ã®ãã°ã®äŸã2çªç®ã®
operation
ã¢ãŒãã¯
shift
ã§ãã
range
ã¢ãŒãã«éåžžã«äŒŒãŠ
range
ãŸãã æ»æè
ã¯ãæ§æãã¡ã€ã«ã§IOAç¯å²ãšå¯å€å€ãå®çŸ©ããŸãã ã³ã³ããŒãã³ã104ãã¢ã¯ãã£ãã«ãªã£ãåŸã¯ããã¹ãŠãç¯å²ã¢ãŒããšãŸã£ããåãããã«çºçããŸãã ãã ããç¹å®ã®ç¯å²å
ã®ãã¹ãŠã®IOAãããŒãªã³ã°ããããšããã«ãæ°ããç¯å²ã®ããŒãªã³ã°ãéå§ããŸãã æ°ããç¯å²ã¯ãããã©ã«ãã®ç¯å²ãšã·ããå€ãè¿œå ããŠèšç®ãããŸãã
3çªç®ã®
operation
ã¢ãŒãã¯
sequence
ã§ãã ããã«ãŒã¯ãæ¥ç¶ãããããã€ã¹ã§ãµããŒããããŠãããã¹ãŠã®IOAã·ã³ã°ã«ãã€ã³ãã¿ã€ãã³ãã³ãã®å€ãåŠç¿ããåŸã«äœ¿çšã§ããŸãã ãã®ã³ã³ããŒãã³ãã¯ãç¡éã«ãŒãã®å®è¡ãããã«éå§ããéžæããã³å®è¡ãã±ãããæ§æãã¡ã€ã«ã§æå®ãããIOAã«æž¡ããŸãã
ãã°ã«æžã蟌ãæ©èœã«å ããŠãã³ã³ããŒãã³ã104ã¯ãå³2ã«ç€ºãããã«ããããã°æ
å ±ãã³ã³ãœãŒã«ã«åºåã§ããŸãã 11ã
å³ 11.ã³ã³ãœãŒã«ã³ã³ããŒãã³ã104ã®åºåãã³ã³ããŒãã³ã61850
ã³ã³ããŒãã³ã101ããã³104ãšã¯ç°ãªãã
61850.exe
ããã³DLL
61850.dll
ãšåŒã°ããå®è¡å¯èœãã¡ã€ã«ã§æ§æãããå¥ã®æªæã®ããããŒã«ãšããŠååšããŸãã
IEC 61850æšæºã«ã¡ãªãã§åä»ããããŸããã ãã®èŠæ Œã¯ãå€é»æã®èªååã·ã¹ãã ã®ä¿è·ãèªååã枬å®ãç£èŠãããã³å¶åŸ¡ã®æ©èœãå®è¡ããããŸããŸãªã¡ãŒã«ãŒã®ããã€ã¹éã§ã®ããŒã¿äº€æã«äœ¿çšããããããã³ã«ã«ã€ããŠèª¬æããŠããŸãã ããã¯è€éã§ä¿¡é Œæ§ã®é«ããããã³ã«ã§ãããã³ã³ããŒãã³ã61850ã¯ããå°æ°ã®ãã©ã¡ãŒã¿ãŒã®ã¿ã䜿çšããŠå£æ»
çãªçµæããããããŸãã
DLLã³ã³ããŒãã³ããå®è¡ããåŸã61850ã¯æ§æãã¡ã€ã«ã®èªã¿åããè©Šè¡ããŸãããã®ãã¡ã€ã«ã®ãã¹ã¯ãã¹ã¿ãŒãã¢ããã³ã³ããŒãã³ãã«ãã£ãŠæäŸãããŸãã ããã©ã«ãã§ã¯ãåå¥ã®ããŒãžã§ã³ã
i.ini
ããæ§æã
i.ini
ãŸãã æ§æãã¡ã€ã«ã«ã¯ãIEC 61850èŠæ Œã§èª¬æãããŠãããããã³ã«ã䜿çšããŠããŒã¿ã亀æã§ããããã€ã¹ã®IPã¢ãã¬ã¹ã®ãªã¹ããå«ãŸããŠããããšãæåŸ
ãããŸãã
æ§æãã¡ã€ã«ãèŠã€ãããªãå Žåãã³ã³ããŒãã³ã61850ã¯ãæ¥ç¶ãããŠãããã¹ãŠã®ãããã¯ãŒã¯ã¢ããã¿ãŒã«çªå·ãä»ããŠãTCP / IPãµãããããã¹ã¯ã決å®ããŸãã 次ã«ãã³ã³ããŒãã³ãã¯åãµãããããã¹ã¯ã®ãã¹ãŠã®å¯èœãªIPã¢ãã¬ã¹ã«çªå·ãä»ããåã¢ãã¬ã¹ã®ããŒã102ãžã®æ¥ç¶ãè©Šã¿ãŸãã ãããã£ãŠãã³ã³ããŒãã³ãã¯ãããã¯ãŒã¯äžã®é©åãªããã€ã¹ãèªåçã«æ€åºã§ããŸãã
å¥ã®ã±ãŒã¹ã§ã¯ãæ§æãã¡ã€ã«ãèŠã€ãããã¿ãŒã²ããIPã¢ãã¬ã¹ãå«ãŸããŠããå Žåãã³ã³ããŒãã³ãã¯ãããã®ã¢ãã¬ã¹ã§ããŒã102ã«æ¥ç¶ããèªåçã«æ€åºãããŸãã
ãã®ã³ã³ããŒãã³ãã¯ãã¿ãŒã²ãããã¹ãã«æ¥ç¶ãããšããã«ãå³1ã«ç€ºãããã«ãæ¥ç¶æåã®ãã©ã³ã¹ããŒããããã³ã«ã䜿çšããŠæ¥ç¶èŠæ±ãã±ãããéä¿¡ããŸãã 12ã
å³ 12 Wiresharkã®ãã³ãŒããããæ¥ç¶èŠæ±ãã±ãããã¿ãŒã²ããããã€ã¹ãé©åã«å¿çããå Žåãã³ã³ããŒãã³ã61850ã¯
Production Message Specification ïŒMMSïŒã䜿çšããŠ
InitiateRequest
ãã±ãããéä¿¡ããŸãã äºæ³ãããå¿çãåä¿¡ããå ŽåãMMS
getNameList
èŠæ±ãéä¿¡ããŸãã ãããã£ãŠãã³ã³ããŒãã³ãã¯ãä»®æ³è£œé è£
眮ïŒVMDïŒã®ãªããžã§ã¯ãåã®ãªã¹ããã³ã³ãã€ã«ããŸãã
ãã®ã³ã³ããŒãã³ã61850ã¯ãåã®ã¹ãããã§èŠã€ãã£ãã³ã³ããŒãã³ãã«çªå·ãä»ããåãªããžã§ã¯ãåã§ãªããžã§ã¯ãæåã®
getNameList
ãªã¯ãšã¹ããéä¿¡ããŸãã ãããã£ãŠãã³ã³ããŒãã³ãã¯ç¹å®ã®ãã¡ã€ã³ã®ååä»ãå€æ°ã«çªå·ãä»ããŸãã
å³ 13. Wiresharkã§ãã³ãŒããããMMSèŠæ±getNameList
ã
次ã«ãã³ã³ããŒãã³ã61850ã¯ãããã®èŠæ±ã«å¿ããŠåä¿¡ããæ
å ±ã解æãã次ã®æååã·ãŒã±ã³ã¹ãå«ãå€æ°ãæ¢ããŸãã
- CSWãCFãPosããã³ã¢ãã«
- CSWãSTãPosããã³stVal
- CSWãCOãPosãOperããã ã$ T
- CSWãCOãPosãSBOããã ã$ T
CSWã·ãŒã±ã³ã¹ã¯ããµãŒããããã¬ãŒã«ãŒãšãµãŒããããã¬ãŒã«ãŒã®å¶åŸ¡ã«äœ¿çšãããè«çããŒãã®ååã§ãã
ã¢ãã«ãŸãã¯stValã·ãŒã±ã³ã¹ãå«ãå€æ°ã®å Žåãã³ã³ããŒãã³ã61850ã¯è¿œå ã®
Read
MMSèŠæ±ãéä¿¡ããŸãã ãããã®å€æ°ã®äžéšã«ã€ããŠã¯ãã³ã³ããŒãã³ãã¯MMS
Write
èŠæ±ãéä¿¡ããããšãã§ããŸããããã«ãããçŸåšã®ç¶æ
ãå€æŽãããŸãã
ã³ã³ããŒãã³ã61850ã¯ãIPã¢ãã¬ã¹ãMMSãã¡ã€ã³ãååä»ãå€æ°ãããã³ç®æšã®ããŒãã®ç¶æ
ïŒãªãŒãã³ãŸãã¯ã¯ããŒãºïŒãå«ãæäœãã°ãå«ããã¡ã€ã«ãäœæããŸãã
OPC DAã³ã³ããŒãã³ã
OPC DAã³ã³ããŒãã³ãã¯ã
OPCããŒã¿ã¢ã¯ã»ã¹ä»æ§ã§èª¬æãããŠãããããã³ã«ã®ã¯ã©ã€ã¢ã³ããå®è£
ããŸãã
OPCïŒOLE for Process ControlïŒã¯ãOLEãCOMãDCOMãªã©ã®Microsoftãã¯ãããžãŒã«åºã¥ããœãããŠã§ã¢æšæºããã³ä»æ§ã§ãã OPCä»æ§ã®ããŒã¿ã¢ã¯ã»ã¹ïŒDAïŒã«é¢é£ããéšåã§ã¯ãã¯ã©ã€ã¢ã³ããµãŒããŒã¢ãã«ã®ååã«åŸã£ãŠãåæ£ã³ã³ããŒãã³ãéã§ãªã¢ã«ã¿ã€ã ã®ããŒã¿äº€æãå¯èœã§ãã
ãã®ã³ã³ããŒãã³ãã¯ã
OPC.exe
ããã³DLLãšãããã¡ã€ã«åãæã€å¥åã®æªæã®ããããŒã«ãšããŠååšãã61850ããã³OPC DAã³ã³ããŒãã³ãã®äž¡æ¹ã®æ©èœã䜿çšããŸãã ãšã¯ã¹ããŒããããPEããŒãã«ã®DLLã®å
éšåã¯
OPCClientDemo.dll
ãããã¯ããã®ã³ã³ããŒãã³ãããªãŒãã³ãœãŒã¹ãããžã§ã¯ã
OPC Clientã«åºã¥ããŠããå¯èœæ§ãããããšã瀺ããŠããŸãã
å³ 14. PEããŒãã«ã«ã¯ãOPC DAã³ã³ããŒãã³ãã®å
éšDLLåã衚瀺ãããŸããOPC DAã³ã³ããŒãã³ãã«ã¯ãæ§æãã¡ã€ã«ã¯å¿
èŠãããŸããã æ»æè
ã«ããå®è¡åŸãæ»æè
ã¯ãã«ããŽãªèå¥å
CATID_OPCDAServer20
ããã³
IOPCServer::GetStatus
ã䜿çšããŠ
ICatInformation::EnumClassesOfCategories
ã䜿çšããŠã
ICatInformation::EnumClassesOfCategories
ãµãŒããŒã決å®ããŸãã
次ã®ã³ã³ããŒãã³ãã¯ã
IOPCBrowseServerAddressSpace
ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠããã¹ãŠã®OPCãµãŒããŒèŠçŽ ã«çªå·ãä»ããŸãã ç¹å¥ãªæ¹æ³ã§ã圌ã¯ååã«æ¬¡ã®ã·ãŒã±ã³ã¹ãå«ãèŠçŽ ãæ€çŽ¢ããŸãã
- ctlSelOn
- ctlOperOn
- ctlSelOff
- ctlOperOff
- \ Posããã³stVal
èŠçŽ åã¯ãæ»æè
ã
MicroSCADAã©ã€ã³ãªã©ã®
ABBãœãªã¥ãŒã·ã§ã³ã«é¢é£ããOPCãµãŒããŒã«ãã£ãŠæäŸãããOPCèŠçŽ ã«é¢å¿ãããããšã瀺åããŠããŸãã å³ å³15ã¯ãé¡äŒŒããæååã·ãŒã±ã³ã¹ãæã€ååãå«ããµã³ãã«OPCèŠçŽ ã瀺ããŠããŸãã ãã®OPCã¢ã€ãã ã®ãªã¹ãã¯ãABB OPCããã»ã¹ãªããžã§ã¯ããªã¹ãããŒã«ã«ãã£ãŠååŸãããŸãã
å³ 15. OPCããã»ã¹ãªããžã§ã¯ããªã¹ãããŒã«ã䜿çšããŠååŸããINãã£ãŒã«ãã®OPCèŠçŽ ã®ååã®äŸãæ»æè
ã¯ãæ°ããOPCã°ã«ãŒããè¿œå ãããšãã«
Abdul
ã©ã€ã³ã䜿çšããŸãã ããããããã®è¡ã¯ãæ»æè
ãABBãœãªã¥ãŒã·ã§ã³ã®ã¹ã©ã³ã°åãšããŠäœ¿çšããŠããå¯èœæ§ããããŸãã
å³ 16. Abdul
æååã䜿çšããOPC DAã³ã³ããŒãã³ãã®éã¢ã»ã³ãã«ã³ãŒããæçµæ®µéã§ãOPC DAã³ã³ããŒãã³ãã¯
IOPCSyncIO
ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠãæ€åºãããOPCèŠçŽ ã®ç¶æ
ãå€æŽããããšããå€0x01ã2åæžã蟌ã¿ãŸãã
å³ 17. IOPCSyncIO
ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããOPC DAã³ã³ããŒãã³ãã®éã¢ã»ã³ãã«ã³ãŒããã³ã³ããŒãã³ãã¯ãOPCãµãŒããŒã®ååãOPCãšã¬ã¡ã³ãã®ååã®ç¶æ
ãå質ã³ãŒããããã³å€ããã°ãã¡ã€ã«ã«æžã蟌ã¿ãŸãã èšé²ãããå€ã¯ã次ã®ããããŒè¡ã§åºåãããŸãã
- [* ServerNameïŒïŒ
SERVERNAMEïŒ
] [ç¶æ
ïŒå€æŽå]
- [* ServerNameïŒïŒ
SERVERNAMEïŒ
] [ç¶æ
ïŒONåŸ]
- [* ServerNameïŒïŒ
SERVERNAMEïŒ
] [ç¶æ
ïŒãªãåŸ]
ããŒã¿æ¶å»ã³ã³ããŒãã³ã
ããŒã¿ã¯ã€ããŒã³ã³ããŒãã³ãã¯ãæ»æã®æçµæ®µéã§äœ¿çšãããç Žå£çãªã³ã³ããŒãã³ãã§ãã ããã«ãŒã¯ãã®ã³ã³ããŒãã³ãã䜿çšããŠã远跡ãã«ããŒãã埩æ§ããã»ã¹ãè€éã«ããŸãã
ãã®ã³ã³ããŒãã³ãã®ãã¡ã€ã«å
haslo.dat
ãŸãã¯
haslo.exe
ã¯ãèµ·åã³ã³ããŒãã³ãã«ãã£ãŠå®è¡ãããããå¥ã®æªæã®ããããŒã«ãšããŠäœ¿çšãããå¯èœæ§ããããŸãã
å®è¡åŸãã³ã³ããŒãã³ãã¯WindowsãµãŒãã¹ããªã¹ãããã¬ãžã¹ããªå
ã®ãã¹ãŠã®ããŒã«çªå·ãä»ããããšããŸãã
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
æ€åºãããåã¬ã³ãŒãã§ç©ºã®æååã䜿çšããŠ
ImagePath
ã¬ãžã¹ããªå€ãèšå®ããããšããŸãã ããã«ããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®èªã¿èŸŒã¿ãåæ¢ããŸãã
次ã®ã¹ãããã¯ããã¡ã€ã«ã®å
容ãåé€ããããšã§ãã ã³ã³ããŒãã³ãçªå·ã¯ãã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ãããŠãããã¹ãŠã®ãã©ã€ãäžã®ç¹å®ã®æ¡åŒµåãæã€ãã¡ã€ã«ïŒCïŒ\ããZïŒ\ïŒãŸã§ã§ãã çªå·ä»ãäžãã³ã³ããŒãã³ãã¯ãååã«
Windows
ãšããåèªãå«ããµããã£ã¬ã¯ããªã«ãããã¡ã€ã«ãã¹ãããããããšã«æ³šæããŠãã ããã
ã³ã³ããŒãã³ãã¯ããã¡ã€ã«ã®å
容ããæ°ããå²ãåœãŠãããã¡ã¢ãªã®å
容ããååŸããç¡æå³ãªæ
å ±ã«çœ®ãæããŸãã ãã®æäœãé©åã«å®è¡ããããã«ãã³ã³ããŒãã³ãã¯ãã¡ã€ã«ã2åæžãæããããšããŸãã ãã©ã€ãã§ãã¡ã€ã«ãæ€åºããããšãæåã®è©Šè¡ãè¡ãããŸãã æåã®è©Šè¡ã倱æããå Žåãã³ã³ããŒãã³ãã¯2åç®ã®è©Šè¡ãè¡ããŸããããã®åã«éèŠãªã·ã¹ãã ããã»ã¹ã®ãªã¹ãã«å«ãŸããŠããããã»ã¹ãé€ããã¹ãŠã®ããã»ã¹ãçµäºããŸãã ããã»ã¹ã®ãªã¹ããå³ã«ç€ºããŸãã 18ã
æ¶å»ããã»ã¹ãé«éåããããã«ãã³ã³ããŒãã³ãã¯ãã¡ã€ã«ã®æåã®éšåã®ã¿ãäžæžãããŸãã æžãæããããæ
å ±ã®éã¯ããã¡ã€ã«ãµã€ãºã«ãã£ãŠç°ãªããŸãã
æå°éã®æ
å ±ã¯ããµã€ãºã1 MBïŒ4096ãã€ãïŒä»¥äžã®ãã¡ã€ã«ã§äžæžããããŸãããµã€ãºã10 MbïŒ32768ãã€ãïŒä»¥äžã®ãã¡ã€ã«ã«ã€ããŠã¯ãæ倧éã®æ
å ±ãæžãæããããŸããæåŸã«ããã®ã³ã³ããŒãã³ãã¯ãã·ã¹ãã ã³ã³ããŒãã³ããå«ããã¹ãŠã®ããã»ã¹ã®çµäºãè©Šã¿ãŸããããã«ãããã·ã¹ãã ãå¿çãåæ¢ããæçµçã«å€±æããŸããå³ 18. 2åç®ã®è©Šè¡äžã«çµäºããªãããã»ã¹ã®ãªã¹ããæ¶ããŽã ã³ã³ããŒãã³ããäžæžããããã¡ã€ã«åã®ãã¹ã¯ïŒ- SYS_BASCON.COM
- * .v
- * .PL
- * .paf
- * .v
- * .XRF
- * .trc
- * .SCL
- * .bak
- * .cid
- * .scd
- * .pcmp
- * .pcmi
- * .pcmt
- * .xml
- * .CIN
- * .ini
- * .prj
- * .cxm
- * .elb
- * .epl
- * .mdf
- * .ldf
- * .bak
- * .bk
- * .bkp
- * .log
- * .zip
- * .rar
- * .tar
- * .7z
- * .exe
- * .dll
ãã®ãªã¹ãã«ã¯ãWindowsãã€ããªïŒ.exe / .dllïŒãã¢ãŒã«ã€ãïŒ.7z /.tar/.rar/.zipïŒãããã¯ã¢ãããã¡ã€ã«ïŒ.bak / .bk /ãïŒãªã©ãæšæºç°å¢ã§äœ¿çšããããã¡ã€ã«åæ¡åŒµåãå«ãŸããŠããŸãã bkpïŒãMicrosoft SQLãµãŒããŒãã¡ã€ã«ïŒ.mdf / .ldfïŒããã³ããŸããŸãªæ§æãã¡ã€ã«ïŒ.ini / .xmlïŒãããã«ãã³ã³ããŒãã³ãã¯ç£æ¥å¶åŸ¡ã·ã¹ãã ã§äœ¿çšã§ãããã¡ã€ã«ãããšãã°ãå€é»ææ§æèšè¿°èšèªïŒ.scl / .cid / .scdïŒã䜿çšããŠèšè¿°ããããã¡ã€ã«ãããã³ABB補åã§äœ¿çšããããã¡ã€ã«ãšæ¡åŒµåãæ¶å»ããŸããããšãã°ãSYS_BASCON.COM
ABBãœãªã¥ãŒã·ã§ã³ãšåŒã°ãããã¡ã€ã«ã¯æ§ææ
å ±ãä¿åããããã«äœ¿çšãããæ¡åŒµå.paf
ïŒProduct Authorization File
ïŒãä»ãããã¡ã€ã«ã¯ABB MicroSCADA補åã®ã©ã€ã»ã³ã¹æ
å ±ãä¿åããããã«äœ¿çšãããŸããè¿œå ããŒã«ïŒããŒãã¹ãã£ããŒ
æ»æè
ã®æŠåšã«ã¯ããŒãã¹ãã£ããŒãå«ãŸããŠãããããã䜿çšããŠãããã¯ãŒã¯ããããããæ»æã«é¢é£ããã³ã³ãã¥ãŒã¿ãŒãæ€çŽ¢ã§ããŸããèå³æ·±ãããšã«ãããã«ãŒã¯æ¢åã®ãœãããŠã§ã¢ã䜿çšãã代ããã«ãç¬èªã®ããŒãã¹ãã£ããŒãäœæããŸãããå³ãããããããã« 19ã圌ãã¯ãã®ããŒã«ã«ãã£ãŠã¹ãã£ã³ãããIPã¢ãã¬ã¹ã®ç¯å²ãšãããã¯ãŒã¯ããŒãã®ç¯å²ãå²ãåœãŠãããšãã§ããŸããå³ 19.ããŒãã¹ãã£ããŒã®äœ¿çšäŸãè¿œå ããŒã«ïŒDoSããŒã«
ããã«ãŒã®æŠåšã®ãã1ã€ã®ããŒã«ã¯ãSiemens SIPROTECããã€ã¹ã察象ãšãããµãŒãã¹æåŠïŒDoSïŒããŒã«ã§ãããã®ããŒã«ã¯è匱æ§CVE-2015-5374ãæªçšããŠããã€ã¹ãããªãŒãºãããŸãããã®è匱æ§ãæªçšããããšãããã€ã¹ã¯æåã§åèµ·åããããŸã§ã³ãã³ããžã®å¿çãåæ¢ããŸãããã®è匱æ§ãæªçšããããã«ãæ»æè
ã¯DoSããŒã«ã§ããã€ã¹ã®IPã¢ãã¬ã¹ãããŒãã³ãŒãã£ã³ã°ããŸããããã®ããŒã«ã䜿çšãããšãUDPïŒUser Datagram ProtocolïŒã䜿çšããŠãç¹å¥ã«çŽ°å·¥ããããã±ãããããŒã50,000ããå®å
IPã¢ãã¬ã¹ã«éä¿¡ãããŸããUDPãã±ããã«ã¯18ãã€ãããå«ãŸããŠããŸãããå³ 20.è匱æ§CVE-2015-5374ã®æªçšã«é¢ä¿ããUDPãã±ããã®å
容ããããã«
2016幎12æã®åé»ã®èª¿æ»ã¯ãŸã å®äºããŠããŸãããçŸåšãIndustroyerã倱æã®çŽæ¥ã®åå ã§ãã£ããšãã蚌æ ã¯ãããŸãããããã«ãããããããæªæã®ããããã°ã©ã ã«ãããICSãããã³ã«ã䜿çšããŠé»æ°å€é»æã®ãããã¯ãŒã¯å
ã®ãµãŒããããã¬ãŒã«ãšãµãŒããããã¬ãŒã«ãçŽæ¥å¶åŸ¡ã§ãããŸããåé»ã®æ¥ã«2016幎12æ17æ¥ã«ã¢ã¯ãã£ããŒã·ã§ã³ã¿ã€ã ã¹ã¿ã³ããå«ãŸããŠããããããã®ããŒãžã§ã³ã¯ããªãå¯èœæ§ãé«ããšèããããŸããWin32 / Industroyerãã¡ããªãŒã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã察象ãšããé«åºŠã§è€éãªãã«ãŠã§ã¢ã§ãããšèªä¿¡ãæã£ãŠèšããŸããåé¡ã¯ããã«ãŠã§ã¢ãããã«é«åºŠã§çç·Žãã䟵å
¥è
ã®æã«ããåãªãããŒã«ã§ãããšããããšã§ããIndustroyerã®èåŸã«ãããµã€ããŒã°ã«ãŒãã¯ããã®ãããªç°å¢ã«åãããŠããã°ã©ã ã調æŽã§ããŸããIndustroyerã䜿çšããåºç¯ãªæ¥çãããã³ã«ã¯ãã»ãã¥ãªãã£ã«é¢ä¿ãªãæ°å幎åã«äœæãããŸããããããã£ãŠããããã®ãããã³ã«ãé©çšãããç£æ¥çšãããã¯ãŒã¯ã®éçšã«ãããããã«ãŒã«ããå¹²æžã¯ãæããã«æ·±å»ãªçµæã«ã€ãªãããŸããææã€ã³ãžã±ãŒã¿ïŒIoCïŒ
SHA-1ããã·ã¥ïŒ CïŒCãµãŒããŒã®IPã¢ãã¬ã¹ïŒF6C21F8189CED6AE150F9EF2E82A3A57843B587D
CCCCE62996D578B984984426A024D9B250237533
8E39ECA1E48240C01EE570631AE8F0C9A9637187
2CB8230281B86FA944D3043AE906016C8B5984D9
79CA89711CDAEDB16B0CCCCFDCFBD6AA7E57120A
94488F214B165512D2FC0438A581F5C9E3BD4D4C
5A5FAFBC3FEC8D36FD57B075EBF34119BA3BFF04
B92149F046F00BB69DE329B8457D32C24726EE00
B335163E6EB854DF5E08E85026B2C3518891EDA8
195.16.88[.]6
46.28.200[.]132
188.42.253[.]43
5.39.218[.]152
93.115.27[.]57
泚æïŒ
ãããã®IPã¢ãã¬ã¹ãæã€ã»ãšãã©ã®ãµãŒããŒã¯ãTorãããã¯ãŒã¯ã®äžéšã§ãããã€ãŸããã€ã³ãžã±ãŒã¿ãŒã䜿çšãããšã誀æ€åºãçºçããå¯èœæ§ããããŸãããã®ä»ã®è³ªåãWin32 / Industroyerã«é¢é£ãããã«ãŠã§ã¢ã®ãµã³ãã«ãéä¿¡ããã«ã¯ãthreatintel @ eset.comã«ã¡ãŒã«ããŠãã ããã