æçš¿ã§ã¯ãOceanLotusãµã€ããŒã°ã«ãŒãïŒAPT32ããã³APT-C-00ïŒãæè¿Microsoft Officeã®ã¡ã¢ãªç Žæè匱æ§ã§ãã
CVE-2017-11882ã®ãããªãã¯ãšã¯ã¹ããã€ãã®1ã€ã䜿çšããæ¹æ³ãããã³ã°ã«ãŒãã®ãã«ãŠã§ã¢ã䟵害ãããã·ã¹ãã ã§çè·¡ãæ®ããã«æ°žç¶æ§ãæäŸããæ¹æ³ã«ã€ããŠèª¬æããŸãã æ¬¡ã«ã2019幎ã®åã以éãã°ã«ãŒããèªå·±è§£åã¢ãŒã«ã€ãã䜿çšããŠã³ãŒããå®è¡ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
OceanLotusã¯ããµã€ããŒã¹ãã€ãå°éãšããŠãããæ±åã¢ãžã¢ãåªå
ç®æšãšããŠããŸãã æ»æè
ã¯ãæœåšçãªè¢«å®³è
ã®æ³šæãåŒãææžãåœé ããŠãããã¯ãã¢ãå®è¡ããããã«ä»åãããŸãããŒã«ã®éçºã«åãçµã¿ãŸãã ããšããäœæããããã«äœ¿çšãããæ¹æ³ã¯ãããŸããŸãªæ»æã§ç°ãªããŸã-ãäºéæ¡åŒµåãã®ãã¡ã€ã«ãèªå·±è§£åã¢ãŒã«ã€ãããã¯ããå«ãããã¥ã¡ã³ããããããç¥ãããŠãããšã¯ã¹ããã€ããŸã§ã
Microsoft Equation Editorã§ãšã¯ã¹ããã€ãã䜿çšãã
2018幎åã°ã«ãOceanLotusã¯CVE-2017-11882è匱æ§ã䜿çšãããã£ã³ããŒã³ãéå§ããŸããã ãµã€ããŒã°ã«ãŒãã®æªæã®ããããã¥ã¡ã³ãã®1ã€ã¯ã360åã®è
åšã€ã³ããªãžã§ã³ã¹ã»ã³ã¿ãŒã®å°éå®¶ïŒ
äžåœèªã®èª¿æ» ïŒã«ãã£ãŠããšã¯ã¹ããã€ãã®è©³çްãªèª¬æãå«ããŠåæãããŸããã 以äžã®æçš¿-ãã®ãããªæªæã®ããããã¥ã¡ã³ãã®æŠèŠã
ç¬¬äžæ®µé
FW Report on demonstration of former CNRP in Republic of Korea.doc
ïŒSHA-1ïŒ
D1357B284C951470066AAA7A8228190B88A5C7C3
ïŒã¯ãäžèšã®ç ç©¶ã§èšåããããã®ãšé¡äŒŒããŠããŸãã è峿·±ãã®ã¯ãã«ã³ããžã¢ã®æ¿æ²»ã«é¢å¿ã®ãããŠãŒã¶ãŒãã¿ãŒã²ããã«ããŠããç¹ã§ãïŒCNRP-ã«ã³ããžã¢ã®åœå®¶æå©å
ã2017幎æ«ã«è§£æ£ïŒã æ¡åŒµåã¯.docã§ãããããã¥ã¡ã³ãã¯RTF圢åŒïŒäžå³ãåç
§ïŒã§ããããžã£ã³ã¯ã³ãŒããå«ãŸããŠãããæªãã§ããŸãã
å³1. RTFã®ãŽãç®±äžæ£ãªåœ¢åŒã®èŠçŽ ãååšããã«ãããããããWordã¯ãã®RTFãã¡ã€ã«ãæ£åžžã«éããŸãã å³2ããåããããã«ããªãã»ããã0xC00ã§ããEQNOLEFILEHDRæ§é ãããããã®åŸã«ãã©ã³ãã®MTEFããããŒãMTEFãšã³ããªïŒå³3ïŒãç¶ããŸãã
å³2. FONTã¬ã³ãŒãå€
å³3. ãã©ã³ãã®èšé²åœ¢åŒã³ããŒããåã«ãµã€ãºããã§ãã¯ãããªãããã
ååãã£ãŒã«ãã§ãªãŒããŒãããŒãçºçããå¯èœæ§ããããŸãã ååãé·ããããšãè匱æ§ãåŒãèµ·ããããŸãã RTFãã¡ã€ã«ã®å
容ïŒå³2ã®ãªãã»ãã0xC26ïŒãããããããã«ããããã¡ãŒã¯ã·ã§ã«ã³ãŒãã§åãããããã®åŸã«ãããŒã³ãã³ãïŒ
0x90
ïŒãç¶ããã¢ãã¬ã¹
0x402114
è¿ãããŸãã ã¢ãã¬ã¹ã¯ã
RET
ã¹ããŒãã¡ã³ããæã
EQNEDT32.exe
ãã€ã¢ãã°é
ç®ã§ãã ããã«ãããEIPã¯ã·ã§ã«ã³ãŒããå«ã
ååãã£ãŒã«ãã®å
é ãæããŸãã
å³4.ãšã¯ã¹ããã€ãã·ã§ã«ã³ãŒãã®éå§ã¢ãã¬ã¹
0x45BD3C
ã¯ãçŸåšããŒããããŠãã
MTEFData
æ§é ãžã®ãã€ã³ã¿ãŒã«å°éãããŸã§éæ¥åç
§ããã倿°ãæ ŒçŽããŸãã ããã¯ã·ã§ã«ã³ãŒãã®æ®ãã®éšåã§ãã
ã·ã§ã«ã³ãŒãã®ç®çã¯ãéããŠããããã¥ã¡ã³ãã«åã蟌ãŸããã·ã§ã«ã³ãŒãã®2çªç®ã®ãã©ã°ã¡ã³ããå®è¡ããããšã§ãã ãŸãããœãŒã¹ã·ã§ã«ã³ãŒãã¯éããŠããããã¥ã¡ã³ãã®ãã¡ã€ã«èšè¿°åãèŠã€ããããšãããã¹ãŠã®ã·ã¹ãã èšè¿°åïŒ
SystemExtendedHandleInformation
åŒæ°ãæã€
NtQuerySystemInformation
ã
NtQuerySystemInformation
ããèšè¿°å
PIDãš
WinWord
ããã»ã¹ã®
PIDã WinWord
ãããã©ãããããã³ããã¥ã¡ã³ããã¢ã¯ã»ã¹ãã¹ã¯
0x12019F
éããããã©ããã確èªããŸãã
æ£ããèšè¿°åïŒå¥ã®éããŠããææžã®èšè¿°åã§ã¯ãªãïŒã®æ€åºã確èªããããã«ããã¡ã€ã«ã®å
容ã¯
CreateFileMapping
颿°ã䜿çšããŠè¡šç€ºãããã·ã§ã«ã³ãŒãã¯ææžã®æåŸã®4ãã€ããã
yyyy
ãïŒåµç©ãæ¹æ³ïŒãšäžèŽãããã©ããã確èªããŸãã äžèŽãèŠã€ãããšããã«ãããã¥ã¡ã³ãã¯
ole.dll
ãšããŠäžæãã©ã«ããŒïŒ
GetTempPath
ïŒã«ã³ããŒãããŸãã æ¬¡ã«ãããã¥ã¡ã³ãã®æåŸã®12ãã€ããèªã¿åãããŸãã
å³5.ææžã®çµããã®ããŒã«ãŒAABBCCDD
ããŒã«ãŒãš
yyyy
ããŒã«ãŒã®éã®32ãããå€ã¯ã次ã®
AABBCCDD
ãªãã»ããã§ãã
CreateThread
颿°ã䜿çšããŠåŒã³åºãããŸãã 以åã«OceanLotusã§äœ¿çšãããŠãããã®ãšåãã·ã§ã«ã³ãŒããæœåºããŸããã 2018幎3æã«ãªãªãŒã¹ãã
Pythonãšãã¥ã¬ãŒã·ã§ã³ã¹ã¯ãªããã¯ã第2段éããã³ãããããã«åŒãç¶ãæ©èœããŸãã
ç¬¬äºæ®µé
ã³ã³ããŒãã³ãæ€çŽ¢
ãã¡ã€ã«åãšãã£ã¬ã¯ããªåã¯åçã«éžæãããŸãã ãã®ã³ãŒãã¯ã
C:\Windows\system32
ã«ããå®è¡å¯èœãã¡ã€ã«ãŸãã¯DLLãã¡ã€ã«ã®ååãã©ã³ãã ã«éžæããŸãã æ¬¡ã«ã圌ã¯èªåã®ãªãœãŒã¹ã«ãªã¯ãšã¹ããè¡ãããã©ã«ãåãšããŠäœ¿çšãã
FileDescription
ãã£ãŒã«ããååŸããŸãã ãããæ©èœããªãå Žåãã³ãŒãã¯
%ProgramFiles%
ãŸãã¯
C:\Windows
ãã£ã¬ã¯ããªïŒGetWindowsDirectoryWããïŒãããã©ã«ãåãã©ã³ãã ã«éžæããŸãã æ¢åã®ãã¡ã€ã«ãšç«¶åããå¯èœæ§ã®ããååã®äœ¿çšãåé¿ãã
windows
ã
Microsoft
ã
desktop
ã
system
ã
system32
ã
syswow64
åèªãå«ãŸããªãããã«ããŸãã ãã£ã¬ã¯ããªãæ¢ã«ååšããå ŽåããNLS_ {6 characters}ããååã«è¿œå ãããŸãã
ãªãœãŒã¹
0x102
åæããããã¡ã€ã«ã
%ProgramFiles%
ãŸãã¯
%AppData%
ã§ã©ã³ãã ã«éžæããããã©ã«ããŒã«ãã³ããããŸãã
kernel32.dll
ãšåãå€ã«ãªãããã«äœææéã倿ŽãããŸããã
ããšãã°ã次ã®ãã©ã«ããšãå®è¡å¯èœãã¡ã€ã«
C:\Windows\system32\TCPSVCS.exe
ãããŒã¿ãœãŒã¹ãšããŠéžæããŠäœæããããã¡ã€ã«ã®ãªã¹ãããããŸãã
å³6.ããŸããŸãªã³ã³ããŒãã³ãã®åé€ãããããŒã®
0x102
ãªãœãŒã¹ã®æ§é ã¯éåžžã«è€éã§ãã äžèšã§èšãã°ã次ã®ãã®ãå«ãŸããŸãã
-ãã¡ã€ã«å
-ãã¡ã€ã«ã®ãµã€ãºãšå
容
-å§çž®åœ¢åŒïŒ
RtlDecompressBuffer
颿°ã§äœ¿çšããã
COMPRESSION_FORMAT_LZNT1
ïŒ
æåã®ãã¡ã€ã«ã¯
TCPSVCS.exe
ãšããŠãªã»ãããã
TCPSVCS.exe
ãããã¯æ£åœãª
AcroTranscoder.exe
ïŒ
FileDescription
ãSHA-1ã«ãããšïŒ
2896738693A8F36CC7AD83EF1FA46F82F32BE5A3
ïŒã
äžéšã®DLLãã¡ã€ã«ã11 MBãã倧ããããšã«æ°ã¥ãããããããŸããã ããã¯ãã©ã³ãã ããŒã¿ã®å€§ããªé£ç¶ãããã¡ãå®è¡å¯èœãã¡ã€ã«å
ã«ããããã§ãã ããã¯ãäžéšã®ã»ãã¥ãªãã£è£œåã«ããæ€åºãåé¿ããæ¹æ³ã§ããå¯èœæ§ããããŸãã
æç¶æ§
ãããããŒã®
0x101
ãªãœãŒã¹ã«ã¯ãæ°žç¶æ§ã確ä¿ããæ¹æ³ã決å®ãã2ã€ã®32ãããæŽæ°ãå«ãŸããŠããŸãã æåã®å€ã¯ããã«ãŠã§ã¢ã管çè
æš©éãªãã§æ°žç¶æ§ãç¶æããæ¹æ³ã瀺ããŸãã
衚1.管çè
æš©éã®ãªãæ°žç¶åã¡ã«ããºã 2çªç®ã®æŽæ°ã®å€ã¯ã管çè
ãšããŠåããŠããéããã«ãŠã§ã¢ãæç¶æ§ã確ä¿ããæ¹æ³ã瀺ããŸãã
衚2.管çè
æš©éãæã€æ°žç¶åã¡ã«ããºã ãµãŒãã¹åã¯ãæ¡åŒµåã®ãªããã¡ã€ã«åã§ãã 衚瀺å-ãã©ã«ããŒã®ååã§ãããæ¢ã«ååšããå Žåã¯ãã
Revision 1
ããšããè¡ã远å ãããŸãïŒæªäœ¿çšã®ååãèŠã€ãããŸã§çªå·ãå¢ããŸãïŒã ãªãã¬ãŒã¿ãŒã¯ããµãŒãã¹å
šäœã®æ°žç¶æ§ãå®å®ããŠããããšã確èªããŸãããé害ãçºçããå Žåã1ç§åŸã«ãµãŒãã¹ãåèµ·åããå¿
èŠããããŸãã æ¬¡ã«ãæ°ãããµãŒãã¹ã¬ãžã¹ããªããŒã®
WOW64
å€ã¯4ã«èšå®ããã32ããããµãŒãã¹ã§ããããšã瀺ããŸãã
ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã¯ãããã€ãã®COMã€ã³ã¿ãŒãã§ã€ã¹ãéããŠäœæãããŸãïŒ
ITaskScheduler
ã
ITask
ã
ITaskTrigger
ã
IPersistFile
ãããã³
ITaskScheduler
ã åºæ¬çã«ããã«ãŠã§ã¢ã¯é ãããã¿ã¹ã¯ãäœæããçŸåšã®ãŠãŒã¶ãŒãŸãã¯ç®¡çè
ã«é¢ããæ
å ±ãšãšãã«ã¢ã«ãŠã³ãæ
å ±ãèšå®ããããªã¬ãŒãèšå®ããŸãã
ããã¯ã24æéã®æç¶æéãš10åéã®2ã€ã®å®è¡ã®ééãæã€æ¯æ¥ã®ã¿ã¹ã¯ã§ããã€ãŸããç¶ç¶çã«å®è¡ãããŸãã
æªæã®ããããã
ãã®äŸã§ã¯ãå®è¡å¯èœãã¡ã€ã«
TCPSVCS.exe
ïŒ
AcroTranscoder.exe
ïŒã¯ããã³ããããDLLãããŠã³ããŒãããæ£åœãªãœãããŠã§ã¢ã§ãã ãã®å Žåã
Flash Video Extension.dll
ãéèŠã§ãã
ãã®
DLLMain
颿°ã¯ãåã«å¥ã®é¢æ°ãåŒã³åºããŸãã ãããŸããªè¿°èªãããã€ããããŸãã
å³7.ãã¡ãžã£è¿°èªãããã®èª€è§£ãæããã§ãã¯ã®åŸãã³ãŒãã¯
TCPSVCS.exe
ãã¡ã€ã«ã®
.text
ã»ã¯ã·ã§ã³ãåãåããä¿è·ã
PAGE_EXECUTE_READWRITE
倿ŽããŠäžæžããããããŒã®åœä»€ã远å ããŸãã
å³8.åœä»€ã®ã·ãŒã±ã³ã¹æåŸã«ã
Flash Video Extension.dll
ã«ãã£ãŠãšã¯ã¹ããŒãããã
FLVCore::Uninitialize(void)
颿°ã®ã¢ãã¬ã¹ã«
CALL
åœä»€ã远å ãã
Flash Video Extension.dll
ã ã€ãŸããæªæã®ããDLLãããŒãããåŸãã©ã³ã¿ã€ã ã
TCPSVCS.exe
ã§
WinMain
ã
TCPSVCS.exe
ãšãåœä»€ãã€ã³ã¿ãŒãNOPãæããæ¬¡ã®ã¹ãããã§ãã
FLVCore::Uninitialize(void)
åŒã³åºããŸãã
ãã®é¢æ°ã¯ã
{181C8480-A975-411C-AB0A-630DB8B0A221}
ã§
{181C8480-A975-411C-AB0A-630DB8B0A221}
ããã®åŸã«çŸåšã®ãŠãŒã¶ãŒåãç¶ãmutexãäœæããã ãã§ãã æ¬¡ã«ãäœçœ®ã«äŸåããªãã³ãŒããå«ã* .db3æ¡åŒµåã®ãã³ããã¡ã€ã«ãèªã¿åãã
CreateThread
ã䜿çšããŠå
容ãå®è¡ããŸãã
* .db3ãã¡ã€ã«ã®å
容ã¯ãOceanLotusã°ã«ãŒããäžè¬çã«äœ¿çšããã·ã§ã«ã³ãŒãã§ãã ç¹°ãè¿ãã«ãªããŸãã
ãGitHubã§å
¬éãããšãã¥ã¬ãŒã¿ã¹ã¯ãªããã䜿çšããŠããã€ããŒããæ£åžžã«ã¢ã³ããã¯ããŸããã
ã¹ã¯ãªããã¯æçµæ®µéãååŸããŸãã ãã®ã³ã³ããŒãã³ãã¯ã
以åã®OceanLotusã®èª¿æ»ã§ãã§ã«åæããããã¯ãã¢ã§ãã ãã
{A96B020F-0000-466F-A96D-A91BBF8EAC96}
ãã€ããªãã¡ã€ã«ã®GUID
{A96B020F-0000-466F-A96D-A91BBF8EAC96}
ã«ãã£ãŠæ±ºå®ã§ããŸãã ãã«ãŠã§ã¢æ§æã¯ãPEãªãœãŒã¹ã§æå·åããããŸãŸã§ãã ã»ãŒåãæ§æã§ãããCïŒCãµãŒããŒã¯ä»¥åã®ãã®ãšã¯ç°ãªããŸãã
- andreagahuvrauvin[.]com
- byronorenstein[.]com
- stienollmache[.]xyz
OceanLotusã¯ãæ€åºãåé¿ããããã®ããŸããŸãªææ³ã®çµã¿åããã瀺ããŠããŸãã 圌ãã¯ãææããã»ã¹ã®ãæŽç·ŽããããæŠèŠãšãšãã«æ»ã£ãŠããŸããã ã©ã³ãã ãªååãéžæããå®è¡å¯èœãã¡ã€ã«ã«ã©ã³ãã ãªããŒã¿ãå
¥åããããšã«ãããïŒããã·ã¥ãšãã¡ã€ã«åã«åºã¥ããŠïŒä¿¡é Œã§ããIoCã®æ°ãæžãããŸãã ããã«ããµãŒãããŒãã£ã®DLLããŒãã®äœ¿çšã«ãããæ»æè
ã¯æ£åœãª
AcroTranscoder
ãã€ããªãåé€ããã ãã§
AcroTranscoder
ãŸãã
èªå·±è§£åã¢ãŒã«ã€ã
RTFãã¡ã€ã«ã®åŸãã°ã«ãŒãã¯ããŠãŒã¶ãŒãããã«æ··ä¹±ãããããã«ãäžè¬çãªããã¥ã¡ã³ãã¢ã€ã³ã³ãæã€èªå·±è§£åïŒSFXïŒã¢ãŒã«ã€ãã«åãæ¿ããŸããã ããã¯Threatbookã«ãã£ãŠæžãããŸããïŒ
äžåœèªã®ãªã³ã¯ ïŒã éå§åŸãèªå·±è§£ååRARãã¡ã€ã«ããã³ããããæ¡åŒµå.ocxã®DLLãå®è¡ãããŸãããã®æçµãã€ããŒãã¯ä»¥åã«
{A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
ææžåãããŠããŸããã 2019幎1æäžæ¬ä»¥éãOceanLotusã¯ãã®ææ³ãåå©çšããŠããŸãããäžéšã®æ§æã¯æéãšãšãã«å€åããŸãã ãã®ã»ã¯ã·ã§ã³ã§ã¯ããã¯ãããžãŒãšå€æŽã«ã€ããŠèª¬æããŸãã
é€ã®äœæ
ããã¥ã¡ã³ã
THICH-THONG-LAC-HANH-THAP-THIEN-VIET-NAM (1).EXE
ïŒSHA-1ïŒ
AC10F5B1D5ECAB22B7B418D6E98FA18E32BBDEAB
ïŒã¯ã2018幎ã«åããŠçºèŠãããŸããã ãã®SFXãã¡ã€ã«ã¯è³¢æã«äœæãããŸãã-説æïŒ
ããŒãžã§ã³æ
å ± ïŒã¯ããããJPEGç»åã§ããããšã瀺ããŠããŸãã SFXã¹ã¯ãªããã¯æ¬¡ã®ãšããã§ãã
å³9. SFXã³ãã³ããã«ãŠã§ã¢ã¯
{9ec60ada-a200-4159-b310-8071892ed0c3}.ocx
ïŒSHA-1ïŒ
EFAC23B0E6395B1178BCF7086F72344B24C04DCC
ïŒãšç»å
2018 thich thong lac.jpg.
é€ã®ç»åã¯æ¬¡ã®ãšããã§ãã
å³10.é€ã®ç»åSFXã¹ã¯ãªããã®æåã®2è¡ãOSXãã¡ã€ã«ã2ååŒã³åºãããšã«æ°ã¥ãããããããŸããããããã¯ãšã©ãŒã§ã¯ãããŸããã
{9ec60ada-a200-4159-b310-8071892ed0c3} .ocxïŒShLd.dllïŒ
OXãã¡ã€ã«ã®å¶åŸ¡ãããŒã¯ä»ã®OceanLotusã³ã³ããŒãã³ããšéåžžã«äŒŒãŠããŸã
JZ/JNZ
ããã³
PUSH/RET
ã³ãã³ãã®å€ãã®ã·ãŒã±ã³ã¹ããžã£ã³ã¯ã³ãŒããšäº€äºã«ãããŸãã
å³11.é£èªåãããã³ãŒããžã£ã³ã¯ã³ãŒãããã£ã«ã¿ãªã³ã°ãããšã
regsvr32.exe
ã«ãã£ãŠåŒã³åºããã
DllRegisterServer
ãšã¯ã¹ããŒãã¯æ¬¡ã®ããã«ãªããŸãã
å³12.åºæ¬çãªã€ã³ã¹ããŒã©ãŒã³ãŒãå®éãåããŠ
DllRegisterServer
åŒã³åºããã
DllRegisterServer
ãšã¯ã¹ããŒãã¯ã¬ãžã¹ããªå€
HKCU\SOFTWARE\Classes\CLSID\{E08A0F4B-1F65-4D4D-9A09-BD4625B9C5A1}\Model
DLLã®æå·åãªãã»ããã®
HKCU\SOFTWARE\Classes\CLSID\{E08A0F4B-1F65-4D4D-9A09-BD4625B9C5A1}\Model
ïŒ
0x10001DE0
ïŒãèšå®ããŸãã
颿°ã2åç®ã«åŒã³åºããããšãåãå€ãèªã¿åãããã®ã¢ãã¬ã¹ã§å®è¡ãããŸãã ããããããªãœãŒã¹ãèªã¿åãããŠå®è¡ãããRAMã®å€ãã®ã¢ã¯ã·ã§ã³ãå®è¡ãããŸãã
ã·ã§ã«ã³ãŒãã¯ã以åã®OceanLotusãã£ã³ããŒã³ã§äœ¿çšãããPEããŒããŒãšåãã§ãã
ã¹ã¯ãªããã䜿çšã
ãŠãšãã¥ã¬ãŒãã§ããŸãã ãã®çµæã圌ã¯
db293b825dcc419ba7dc2c49fa2757ee.dll
ããã³ããããããã¡ã¢ãªã«ããŒãããŠ
DllEntry
ãå®è¡ã
DllEntry
ã
DLLã¯ããã®ãªãœãŒã¹ã®ã³ã³ãã³ããæœåºãã埩å·åïŒAES-256-CBCïŒããã³è§£åïŒLZMAïŒããŸãã ãªãœãŒã¹ã«ã¯ãç°¡åã«éã³ã³ãã€ã«ã§ããç¹å®ã®åœ¢åŒããããŸãã
å³13.ã€ã³ã¹ããŒã©ãŒæ§ææ§é ïŒKaitaiStruct VisualizerïŒæ§æã¯æç€ºçã«æå®ãããŸã-ç¹æš©ã¬ãã«ã«å¿ããŠããã€ããªããŒã¿ã¯
%appdata%\Intel\logs\BackgroundUploadTask.cpl
ãŸãã¯
%windir%\System32\BackgroundUploadTask.cpl
ïŒãŸãã¯64ãããã·ã¹ãã ã®å Žåã¯
SysWOW64
ïŒã«æžã蟌ãŸããŸãã
BackgroundUploadTask[junk].job
ãšããååã®ã¿ã¹ã¯ãäœæããããšã«ãããæ°žç¶æ§ã確ä¿ãããŸãã
[junk]
ã¯ãã€ã
0x9D
ããã³
0xA0
ã§ãã
ã¿ã¹ã¯ã®ã¢ããªã±ãŒã·ã§ã³åã¯
%windir%\System32\control.exe
ã§ããã©ã¡ãŒã¿ãŒå€ã¯ã¢ã³ããŒãããããã€ããªãã¡ã€ã«ãžã®ãã¹ã§ãã é衚瀺ã®ã¿ã¹ã¯ã¯æ¯æ¥å®è¡ãããŸãã
æ§é çã«ã¯ãCPLãã¡ã€ã«ã¯å
éšå
ac8e06de0a6c4483af9837d96504127e.dll
DLLã§ããã
CPlApplet
颿°ããšã¯ã¹ããŒãããŸãã ãã®ãã¡ã€ã«ã¯ããã®å¯äžã®ãªãœãŒã¹
{A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
埩å·åãããã®DLLãããŒãããŠããã®å¯äžã®
DllEntry
ãšã¯ã¹ããŒããåŒã³åºããŸãã
ããã¯ãã¢æ§æãã¡ã€ã«
ããã¯ãã¢æ§æã¯æå·åããããã®ãªãœãŒã¹ã«çµ±åãããŸãã æ§æãã¡ã€ã«ã®æ§é ã¯ãåã®ãã®ãšéåžžã«äŒŒãŠããŸãã
å³14.ããã¯ãã¢æ§ææ§é ïŒKaitaiStruct VisualizerïŒåæ§ã®æ§é ã«ãããããããå€ãã®ãã£ãŒã«ãã®å€ã¯
ã以åã®ã¬ããŒãã§äžããããããŒã¿ãšæ¯èŒããŠæŽæ°ãããŸããã
ãã€ããªé
åã®æåã®èŠçŽ ã«ã¯ã
Tencentã«ãã£ãŠèå¥ããã DLLïŒ
HttpProv.dll
MD5ïŒ
2559738D1BD4A999126F900C7357B759
ïŒãå«ãŸããŠããŸãã ãã ãããšã¯ã¹ããŒãåããã€ããªããåé€ãããŠãããããããã·ã¥ã¯äžèŽããŸããã
远å ã®ç ç©¶
ãµã³ãã«ãåéããããã€ãã®ç¹æ§ã«æ³šæãåŒããŸããã 説æãããµã³ãã«ã¯ã2018幎7æé ã«ç»å Žããæè¿ã§ã¯1æäžæ¬ãã2019幎2æåæ¬ã«ãããŠç»å ŽããŸããã SFXã¢ãŒã«ã€ãã¯ææãã¯ã¿ãŒãšããŠäœ¿çšãããæ£åœãªãã€ãããã¥ã¡ã³ããšæªæã®ããOSXãã¡ã€ã«ããã³ãããŸããã
OceanLotusã¯åœã®ã¿ã€ã ã¹ã¿ã³ãã䜿çšããŸãããSFXãã¡ã€ã«ãšOCXãã¡ã€ã«ã®ã¿ã€ã ã¹ã¿ã³ãã¯åžžã«åãïŒ
0x57B0C36A
ïŒ08/14/2016 @ 7:15 pm UTCïŒããã³
0x498BE80F
ïŒ02/06/2009 @ 7:34 am UTCïŒã§ããããšã«
0x498BE80F
ïŒããããïŒã ããã¯ãããããèè
ãåããã³ãã¬ãŒãã䜿çšããããã€ãã®ç¹æ§ã倿Žããç¹å®ã®ãã³ã³ã¹ãã©ã¯ã¿ããæã£ãŠããããšã瀺ããŠããŸãã
2018幎ã®åããã調æ»ããããã¥ã¡ã³ãã®äžã«ã¯ãæ»æã®å¯Ÿè±¡åœã瀺ãããŸããŸãªååããããŸãã
-ã«ã³ããžã¢ã¡ãã£ã¢ã®æ°ããé£çµ¡å
æ
å ±ïŒæ°èŠïŒ.xls.exe
-æå»ºéŠïŒäžªäººç®åïŒ.exeïŒCVã®åœPDFããã¥ã¡ã³ãïŒ
-ãã£ãŒãããã¯ã2018幎7æ28æ¥ãã29æ¥ãŸã§ã®ç±³åœã§ã®éäŒ.exeããã¯ãã¢
{A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
ã®çºèŠãšããã€ãã®ç ç©¶è
ã«ãããã®åæã®å
Ž
{A96B020F-0000-466F-A96D-A91BBF8EAC96}.dll
ããã«ãŠã§ã¢ã®æ§æããŒã¿ã«ããã€ãã®å€æŽãèŠãããŸããã
æåã«ãäœæè
ã¯è£å©DLLïŒ
DNSprov.dll
ãš2ã€ã®ããŒãžã§ã³ã®
HttpProv.dll
ïŒããååãåé€ãå§ããŸããã ãã®åŸããªãã¬ãŒã¿ãŒã¯3çªç®ã®DLLïŒ
HttpProv.dll
ã®2çªç®ã®ããŒãžã§ã³ïŒã®ãããã³ã°ã忢ãã1ã€ã ããåã蟌ãããšãéžæããŸããã
次ã«ãå€ãã®IoCãå©çšå¯èœã«ãªã£ããããããããæ€åºãé¿ããããã«ãå€ãã®ããã¯ãã¢èšå®ãã£ãŒã«ãã倿ŽãããŸããã èè
ã«ãã£ãŠå€æŽãããéèŠãªãã£ãŒã«ãã«ã¯ã次ã®ãã®ããããŸãã
- AppXã¬ãžã¹ããªããŒã®å€æŽïŒIoCãåç
§ïŒ
- ãã¥ãŒããã¯ã¹ãšã³ã³ãŒãã£ã³ã°æååïŒ "def"ã "abc"ã "ghi"ïŒ
- ããŒãçªå·
æåŸã«ãåæããããã¹ãŠã®æ°ããããŒãžã§ã³ã§ãæ°ããCïŒCãIoCã»ã¯ã·ã§ã³ã«ãªã¹ããããŸãã
çµè«
OceanLotusã¯é²åãç¶ããŠããŸãã ãµã€ããŒã°ã«ãŒãã¯ãããŒã«ãšã«ã¢ãŒã®æ¹è¯ãšæ¡åŒµã«éç¹ã眮ããŠããŸãã äœæè
ã¯ã被害è
ãšããããŠãŒã¶ãŒã«é¢é£ããæ³šæãåŒãææžã®å©ããåããŠãæªæã®ãããã€ããŒããåœè£
ããŸãã 圌ãã¯æ°ãããã¶ã€ã³ãéçºãããšã¯ã¹ããã€ãæ¹çšåŒãšãã£ã¿ãŒãªã©ã®å
¬éããŒã«ã䜿çšããŸãã ããã«ã被害è
ã®ãã·ã³ã«æ®ãã¢ãŒãã£ãã¡ã¯ãã®æ°ãæžããããã®ããŒã«ãæ¹åãããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã«ããæ€åºã®æ©äŒãæžãããŠããŸãã
䟵害ã€ã³ãžã±ãŒã¿
Welivesecurityããã³
GitHubã§ ã䟵害ã€ã³ãžã±ãŒã¿ãŒãšMITER ATTïŒCK屿§ãå©çšã§ã
ãŸã ã