2017幎6æ27æ¥ã«ãæ°ãããµã€ããŒæ»æããŠã¯ã©ã€ãããã³ãã®ä»ã®åœã®å€ãã®ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ãæ»æããŸããã ãã®æ»æã¯ãESETãDiskcoder.CïŒå¥åExPetrãPetrWrapãPetyaããŸãã¯NotPetyaïŒãšããŠç¹å®ãããã«ãŠã§ã¢ã«ãã£ãŠåŒãèµ·ããããŸããã
ãã®æ»æã¯ããã£ã¹ã¯äžã®ããŒã¿ãæå·åããããŒã¿ãªã«ããªã«ãããã³ã€ã³ã§300ãã«ãèŠæ±ããäžè¬çãªæå·åæå·ã®æµè¡ãšããŠåœè£
ãããŸããã ããããå®éã«ã¯ãèšç»ã¯æ害ãäžããããšã§ãã£ããããèè
ã¯ããŒã¿ã®è§£èªãè€éã«ããããã«ã§ããéãã®ããšãè¡ããŸããã
ããã°ã§ã¯ããã®æ»æããã§ã«TeleBotsã°ã«ãŒãã«åž°å±ããããŠã¯ã©ã€ãã«å¯Ÿããå¥ã®åæ§ã®æ»æãã§ãŒã³ã®è©³çŽ°ãæããã«ããŸããã ãã®èšäºã§ã¯ãDiskCoder.Cã®æµè¡ã«äœ¿çšãããäž»ãªååžãã¯ãã«ã®è©³çŽ°ãæããã«ããŸãã
ã ãããåœã®æŽæ°ã®ç©èªã
ãŠã¯ã©ã€ãã®ãµã€ããŒèŠå¯å±ã¯ãFacebookããŒãžã§ãDiskCoder.Cãã«ãŠã§ã¢é
åžã®åæ段éã§äººæ°ã®ãã
MEDocäŒèšãœãããŠã§ã¢ã䜿çšããã
ãšå ±åããŸãããããã¯å®è³ªçã«ãŠã¯ã©ã€ãã®ãã®åéã®ç¬å è
ã§ãã ãããããããŸã§ã®ãšããããããã©ã®ããã«è¡ãããã®ãã詳现ã¯äžæã§ãã
調æ»äžã«ãå
¬åŒã®MEDocã¢ãžã¥ãŒã«ã®1ã€ã«çµã¿èŸŒãŸããéåžžã«å·§åŠã«é ãããããã¯ãã¢ãçºèŠããŸããã å®è¡èªäœã¯ãMEDocãœãŒã¹ã³ãŒãã«ã¢ã¯ã»ã¹ããã«å®è¡ããããšã¯éåžžã«é£ããããã«èŠããŸãã
.NET Frameworkã§èšè¿°ãããææã¢ãžã¥ãŒã«ZvitPublishedObjects.dllã®ãã¡ã€ã«ã®ãµã€ãºã¯5ã¡ã¬ãã€ãã§ãããã¡ã€ã³ã®ezvit.exeãã¡ã€ã«ãå«ãä»ã®ãœãããŠã§ã¢ã³ã³ããŒãã³ãããåŒã³åºãããšãã§ãã倧éã®åæ³ã³ãŒããå«ãŸããŠããŸãã
2017幎ã«ãªãªãŒã¹ããããã¹ãŠã®MEDocã¢ããããŒãã調ã¹ãææããã¢ãžã¥ãŒã«ãå«ãå°ãªããšã3ã€ã®ã¢ããããŒããèŠã€ããŸããã
01.175-10.01.176 ã2017幎4æ14æ¥ä»
01.180-10.01.181 ã2017幎5æ15æ¥ä»
01.188-10.01.189 ã2017幎6æ22æ¥ä»
Win32 / Filecoder.AESNI.Cã®é
åžã¯ãã¢ããããŒã
01.10.180-10.01.181ã® 3æ¥åŸã«
å§ãŸã ã
DiskCoder.Cã®é
åžã¯ãã¢ããããŒã
01.10.188-10.01.189ã® 5æ¥åŸã«
å§ãŸããŸãã ã
èå³æ·±ãã®ã¯ã2017幎4æ24æ¥ãã2017幎5æ10æ¥ãŸã§ã®4ã€ã®æŽæ°ãšã5æ17æ¥ãã6æ21æ¥ãŸã§ã®7ã€ã®æŽæ°ã«ã¯ãããã€ã®æšéŠ¬ã¢ãžã¥ãŒã«ãå«ãŸããŠããªãã£ãããšã§ãã
5æ15æ¥ãã5æ17æ¥ãŸã§ã®ã¢ããããŒãã«ã¯ãããã€ã®æšéŠ¬ã¢ãžã¥ãŒã«ããããŸããã5æ17æ¥ä»¥éã¯ããã€ã®æšéŠ¬ã¢ãžã¥ãŒã«ã¯ãããŸãããããããããããæåã®ãã«ãŠã§ã¢ãã€ãŸãWin32 / Filecoder.AESNI.Cãããã»ã©æ®åããªãã£ãçç±ã®1ã€ã§ãã
ããããã5æ17æ¥ã®æŽæ°ã¯æ»æè
ã«ãšã£ãŠäºæ³å€ã§ããã ãããã圌ãã¯åã³è匱æ§ã5æ18æ¥ã®ã¢ããããŒãã«ã¢ããããŒãããŸããããã»ãšãã©ã®MEDocãŠãŒã¶ãŒã¯ãã§ã«ãæšæ¥ã®ããããã§ã¢ããããŒãããŠãããæåã®æ»æã¯ããŸãç®ç«ã¡ãŸããã§ããã
ãã¡ã€ã«ã®ã¡ã¿ããŒã¿ã¯ãã¿ã€ã ãŸãŒã³ã«å¿ããŠãã©ã€ãã©ãªãæŽæ°ã®æ¥ã«ã³ã³ãã€ã«ãããå¯èœæ§ãããããšã瀺ããŠããŸãã
ã¿ã€ã ã¹ã¿ã³ãã¯ãããã€ã®æšéŠ¬ã¢ãžã¥ãŒã«ã5æ15æ¥ã«äœæãããããšã瀺ããŠããŸãã
ããã§ã¯ãILSpy .NETãã³ã³ãã€ã©ã䜿çšããŠãææããã¢ãžã¥ãŒã«ãšéåžžã®ã¢ãžã¥ãŒã«ã®ã¯ã©ã¹ã®éãã確èªããŸãã å·ŠåŽã®ææããã¢ãžã¥ãŒã«ã®ã¯ã©ã¹ã
ã¡ã€ã³ã®ããã¯ãã¢ã¯ã©ã¹ã¯
MeCom㧠ãå³3ã«ç€ºãããã«ãZvitPublishedObjects.Serveråå空éã«ãããŸãã
ILSpy .NET Decompilerã®ããã€ã®æšéŠ¬ã³ãŒããå«ãMeComã¯ã©ã¹ãMeComã¯ã©ã¹ã®ã¡ãœããã¯ãUpdaterUtilsããã³ZvitPublishedObjects.Serveråå空éã®
IsNewUpdateã¡ãœããããåŒã³åºãããŸãã
IsNewUpdateã¡ãœãã
èªäœãå®æçã«åŒã³åºãããæ°ããæŽæ°ããã°ã©ã ãå©çšå¯èœãã©ããã確èªããŸãã 5æ15æ¥ã®ææã¢ãžã¥ãŒã«ã®åäœã¯å°ãç°ãªãã6æ22æ¥ã®ã¢ãžã¥ãŒã«ãããæ©èœãå°ãªãã§ãã
ãŠã¯ã©ã€ãã®åç»é²çµç¹ã«ã¯ãäžæã®ã³ãŒã
EDRPOUããããŸãã ããã¯éåžžã«éèŠã§ããEDRPOUã䜿çšãããšãç¹å®ã®äŒç€ŸãŸãã¯çµç¹ã«å¯ŸããŠæšçåæ»æãè¡ãããšãã§ããããã§ãã å
éšãããããã€ã®æšéŠ¬ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ãããŠããã³ã³ãã¥ãŒã¿ãŒãããæ»æè
ã®æå³ã«å¿ããŠããŸããŸãªæŠè¡ã䜿çšã§ããŸãã
MEDocã¯éåžžã«äººæ°ããã£ããããã»ãŒãã¹ãŠã®äŒèšå£«ã®ã³ã³ãã¥ãŒã¿ãŒã§èŠã€ããããšãã§ããŸãã 1ã€ã®MEDocã¯äžåºŠã«è€æ°ã®çµç¹ã«ãµãŒãã¹ãæäŸã§ããŸããã€ã³ã¹ããŒã«ãããããã€ã®æšéŠ¬ã¯ããã®ãã·ã³äžã®ãã¹ãŠã®EDRPOUãèªèããŠæ»æè
ã«éä¿¡ããŸãã
EDRPOUãåéããã³ãŒããããã€ã®æšéŠ¬ã¯ãEDRPOUã«å ããŠ
ãææããMEDocã¢ããªã±ãŒã·ã§ã³ã®
ãã°ã€ã³ãšãã¹ã¯ãŒããå«ããããã·ãšã¡ãŒã«ã®èšå®ãåéããŸãã
泚æïŒ MEDocã䜿çšãããã¹ãŠã®ãããã·ããã³ã¡ãŒã«ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããå€æŽããããšããå§ãããŸãããŸããæªæã®ããã³ãŒãã¯ãåéãããæ
å ±ãããŒåCredããã³Prxã䜿çšããŠã
HKEY_CURRENT_USER \ SOFTWARE \ WCã® Windowsã¬ãžã¹ããªã«æžã蟌ã¿ãŸãã ã³ã³ãã¥ãŒã¿ãŒã§åæ§ã®ã¬ãžã¹ããªæ
å ±ãèŠã€ãã£ãå Žåãå°ãªããšãã³ã³ãã¥ãŒã¿ãŒã§ããã€ã®æšéŠ¬ã³ãŒããå®è¡ãããŸããã
ãããŠæåŸã«ãæãããªãããŒãªéšåã ããã€ã®æšéŠ¬ã¢ãžã¥ãŒã«ã¯ãå€éšãµãŒããŒãã³ã³ãããŒã«ã»ã³ã¿ãŒãšããŠäœ¿çšããŸããã§ããã 圌ã¯å
¬åŒãµãŒããŒ
upd.me-doc.com [ã] Uaã® MEDocããã®æšæºã¢ããªã±ãŒã·ã§ã³æŽæ°ã䜿çšããŸããã æ³çèŠæ±ãšã®å¯äžã®éãã¯ãããã€ã®æšéŠ¬ã³ãŒããåéããæ
å ±ãCookieçµç±ã§ãµãŒããŒã«éãè¿ããããšã§ãã
Cookieã«EDRPOUãå«ãTrojasnkaã¢ãžã¥ãŒã«ããã®HTTPèŠæ±ãMEDocãµãŒããŒã®ãã©ã¬ã³ãžãã¯åæã¯è¡ããŸããã§ããã ãã§ã«ããã°ã§ãæŽæ°ãµãŒããŒã䟵害ãããå
åãããããšãæžããŸããã ãããã£ãŠãæ»æè
ãæŽæ°ãµãŒããŒã«ããããåœãŠãŠãææãããã·ã³ãšææããŠããªããã·ã³ããã®ãªã¯ãšã¹ããåºå¥ããŠäœ¿çšã§ããããã«ãªã£ãã®ã§ã¯ãªãããšçãããšãã§ããŸãã
Cookieããªã¯ãšã¹ãã«è¿œå ããããã¯ãã¢ã³ãŒãããããŠãã¡ãããæ»æè
ã¯ææãããã·ã³ãå¶åŸ¡ããæ¹æ³ãè¿œå ããå¿
èŠããããŸããã ãã®ã³ãŒãã¯ãå
¬åŒã®MEDocæŽæ°ãµãŒããŒãããã€ããªããŒã¿ãåä¿¡ããTriple Desã¢ã«ãŽãªãºã ã§æå·åã解é€ããGZipããã¢ã³ããã¯ããŸãããçµæã¯ãäžé£ã®åœä»€ãå«ãXMLãã¡ã€ã«ã§ããã ãããã£ãŠããã®ããã€ã®æšéŠ¬ã¯ããµã€ããŒã¹ãã€ãšãµã€ããŒç Žå£ã®æ¬æ Œçãªãã©ãããã©ãŒã ã«ãªããŸããã
ææãããã·ã³ã§å®è¡ãããåœä»€ã®ãªã¹ãããã³ãŒãããããã€ã®æšéŠ¬ã®ã³ãŒããå¯èœãªã³ãã³ãã®è¡šïŒã³ãã³ãå²ãåœãŠ
0-RunCmd Run shellã³ãã³ã
1-DumpData㯠Base64ããŒã¿ããã³ãŒããããã¡ã€ã«ã«ä¿åããŸã
2-MinInfoã³ã³ãã¥ãŒã¿ãŒæ
å ±ã®åé
-OSããŒãžã§ã³ãããã深床ãçŸåšã®ç¹æš©ãUACèšå®ããããã·ããã³ã¡ãŒã«èšå®ïŒãã°ã€ã³ãšãã¹ã¯ãŒããå«ãïŒ
3-GetFileææããã³ã³ãã¥ãŒã¿ãŒãããã¡ã€ã«ãååŸ
4-ãã€ããŒã㯠Base64ããŒã¿ããã³ãŒãããå®è¡å¯èœãã¡ã€ã«ã«ä¿åããŠå®è¡ããŸã
5-AutoPayloadã¯ä»¥åã®ãã®ãšåãã§ããããã¡ã€ã«ã¯ã©ã€ãã©ãªãšããŠä¿åããå¿
èŠããããrundll32.exeãä»ããŠå®è¡ãããã¯ãã§ããã ãŸããç¹å®ã®DLLãäžæžãããå¿
èŠããããŸãã
ãã«ãŠã§ã¢äœæè
ããAutoPayloadããšåä»ããã®ã¯ãŸãã«ã³ãã³ãçªå·5ã§ãããDiskCoder.Cãæåã«ãŒãæ£è
ïŒæåã«ææãããã·ã³ïŒã«é
åžãããæ¹æ³ã«å®å
šã«äžèŽããããšã«æ³šæããŠãã ããã
DiskCoder.Cã©ã³ãµã ãŠã§ã¢ã®å®è¡ã«äœ¿çšãããAutoPayloadã¡ãœãããçµè«åæã瀺ãããã«ãããã¯éåžžã«æ
éã«èšç»ãããååã«å®è¡ãããæäœã§ããã æ»æè
ã¯MEDocã®ãœãŒã¹ã³ãŒãã«ã¢ã¯ã»ã¹ã§ãããšæ³å®ããŠããŸãã 圌ãããã®ã³ãŒããç 究ããé ããè匱æ§ãå®è£
ããã®ã«ååãªæéããã£ãããšã MEDocã€ã³ã¹ããŒã«ããã±ãŒãžã®åèšãµã€ãºã¯çŽ1.5ã®ã¬ãã€ãã§ãããä»ã®ããã¯ããŒã¯ãè匱æ§ããã°ãã確èªããæ¹æ³ã¯ãããŸããã
ãŸã 質åããããŸãã ãã®ããã€ã®æšéŠ¬ã¯ã©ã®ããã䜿çšãããŠããŸããïŒ ãã«ãŠã§ã¢DiskCoder.Cããã³Win32 / Filecoder.AESNI.Cãéä¿¡ãã以å€ã«ããã®ãã£ãã«ãä»ããŠèµ·åãããä»ã®ã³ãã³ãã¯äœã§ããïŒ çŸåšã®ç¶æ³ã®ãã£ãšåã«ééã§ããããæ°ã¥ããªãã£ãä»ã®æ»æã¯äœã§ããïŒ
調æ»ã«ååããŠãããååã®
ãã¬ããªãã¯ã»ãŽã¡ã·ã§ã³ãš
ããŒãã¹ã»ãã¥ãã¥ã€ã«æè¬ããŸãã
䟵害ã®å
åïŒIoCïŒ
ESETæ€åºåïŒ
MSIL / TeleDoor.A
ãã«ãŠã§ã¢äœæè
ã«ãã£ãŠæªçšãããæ£åœãªãµãŒããŒïŒ
upd.me-doc.com [ã] ua
SHA-1ããã·ã¥ïŒ
7B051E7E7A82F07873FA360958ACC6492E4385DD
7F3B1C56C180369AE7891483675BEC61F3182F27
3567434E2E49358E8210674641A20B147E0BD23C
PS
翻蚳è
ããïŒ
ãã®ç¶æ³ã¯ãåœå®¶ããµã€ããŒç¯çœªã®å±éºæ§ãã©ãã»ã©ããèªèããŠããªããããµã€ããŒç¯çœªè
ãšæŠãæ¹æ³ãå°é家ãšè°è«ãããŠããªãããšã¯ã©ãã»ã©æªãã®ãã瀺ããŠããããã®çµæãå®å
šã«åœ¹ã«ç«ãããå¹æããªããæ害ãªæ±ºå®ãæœé ãçŠæ¢ã®åœ¢ã§è¡ãããŸãã
ãã®åœã«ã¯ãæ°çŸã®å€§èŠæš¡ããã³æ°åã®å€§æITäŒæ¥ããããåªããäžçã¯ã©ã¹ã®ãœãããŠã§ã¢ãäœæããŠããŸãã ãããŠããããã®äŒæ¥ã¯ãé©åãªå
¥æãšå°éç¥èãæã€å°é家ã®é¢äžãšããããã¹ãŠã®å±æ§ãåããå·ã®ITãµãŒãã¹ãäœæããããã®å·ã®ãµãŒãã¹ãç¹°ãè¿ãæäŸããŠããŸããã
å
¥æã§ãããããã€ãã®äŒç€Ÿãå®è¡ã®ããã«éžã°ãããããªæ¹æ³ã§çµç¹åããããšãã§ããŸã-èè
ãšããŠã®èª°ããç¬ç«ç£æ»äººãšããŠã®èª°ãã
ãã®ãããªå¯Ÿè©±ãå¿
èŠã§ãããåºã䜿çšãããŠãããœãããŠã§ã¢ã¯ãåœå®¶çã«éèŠãªãœãããŠã§ã¢ãšããŠèªå®ãããå¿
èŠãããããšã¯æããã§ãã
æŽæ°ïŒ
www.securitylab.ru/news/487160.php-ãã¡ã€ã«ã¯æ¬åœã«åŸ©å·åã§ããŸãã NoPetyaã®äœæè
ã¯ãéãå¿
èŠãšãã蚌æ ãšããŠéä¿¡ãããã¡ã€ã«ã解èªããŸããã
www.securitylab.ru/news/487159.php-ãã«ãŠã§ã¢äœæè
ã®ãããã³ã€ã³è²¡åžãããéãåŒãåºãããŸããã
Update2ïŒ
blog.talosintelligence.com/2017/07/the-medoc-connection.htmlè±èªã§æžãããéåžžã«åœ¹ç«ã€èšäºã§ãMedkaæŽæ°ãµãŒããŒãå®éã«å£ããŠãããããããææã¯åœŒã®ãªãã£ã¹ããã§ã¯ãªããåœã®æŽæ°ãµãŒããŒããåºãã£ãŠããããšã確èªãã調æ»ãè¡ãããŸããã ãã°ã®ã¹ã¯ãªãŒã³ã·ã§ãã圢åŒã®èšŒæãæ·»ä»ãããŠããŸãã