ã³ãã³ããšã³ã³ãããŒã«
ãã¹ãŠã®éšåãžã®ãªã³ã¯ïŒããŒã1.åæã¢ã¯ã»ã¹ã®ååŸïŒåæã¢ã¯ã»ã¹ïŒããŒã2.å®è¡ããŒã3.åºå®ïŒæ°žç¶æ§ïŒããŒã4.ç¹æš©ãšã¹ã«ã¬ãŒã·ã§ã³ããŒã5.é²è¡åé¿ããŒã6.è³æ Œæ
å ±ã¢ã¯ã»ã¹ã®ååŸïŒè³æ Œæ
å ±ã¢ã¯ã»ã¹ïŒããŒã7.çºèŠããŒã8.暪æ¹åã®åãããŒã9.ããŒã¿åéïŒã³ã¬ã¯ã·ã§ã³ïŒããŒã10.æŒåºããŒã11.ã³ãã³ããšã³ã³ãããŒã«ãã³ãã³ããšã³ã³ãããŒã«ãã»ã¯ã·ã§ã³ïŒ
ç¥èª-C2ãCïŒC ïŒã¯ã
ãšã³ã¿ãŒãã©ã€ãºåãATTïŒCK Matrixã§å°å
¥ãããæ»æãã§ãŒã³ã®æçµæ®µéã§ãã
ã³ãã³ããšå¶åŸ¡ã«ã¯ãæ»æè
ãæ»æããããããã¯ãŒã¯ã«æ¥ç¶ããããã®å¶åŸ¡äžã«ããã·ã¹ãã ãšéä¿¡ããæè¡ãå«ãŸããŸãã ã·ã¹ãã ã®æ§æãšã¿ãŒã²ãããããã¯ãŒã¯ã®ããããžã«å¿ããŠãé ããã£ãã«C2ãç·šæããæ¹æ³ã¯å€æ°ãããŸãã æãäžè¬çãªææ³ã¯catã§èª¬æãããŠããŸãã C2ãé²æ¢ããã³æ€åºããããã®å¯Ÿçã®ç·šæã«é¢ããäžè¬çãªæšå¥šäºé
ã¯ãå¥ã®ãããã¯ã§åŒ·èª¿è¡šç€ºãããã»ã¯ã·ã§ã³ã®æåŸã«é
眮ãããŸãã
èè
ã¯ãèšäºã«èšèŒãããŠããæ
å ±ãé©çšããããšã§çããå¯èœæ§ã®ããçµæã«ã€ããŠè²¬ä»»ãè² ããããŸããããã€ãã®è£œå€ãçšèªã§è¡ãããå¯èœæ§ã®ããäžæ£ç¢ºãã«ã€ããŠè¬çœªããŸãã å
¬éãããŠããæ
å ±ã¯ã MITRE ATTïŒCKã®å
容ãç¡æã§æ¹ãããããã®ã§ããã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒãã¡ã€ã¢ãŠã©ãŒã«ããã€ãã¹ããæªæã®ãããã©ãã£ãã¯ãéåžžã®ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãšæ··åããããã«ãæ»æè
ã¯éåžžã®ã¢ããªã±ãŒã·ã§ã³ã§äžè¬çã«äœ¿çšãããæšæºããŒããä»ããŠæ»æ察象ã®ã·ã¹ãã ãšéä¿¡ã§ããŸãã
TCP: 80 (HTTP)
TCP: 443 (HTTPS)
TCP: 25 (SMTP)
TCP/UDP: 53 (DNS)
ããšãã°ããããã·ãµãŒããŒãšä»ã®ããŒãã®éãªã©ãæµã®é£ã³å°å
ã§ãããã¯ãŒã¯æ¥ç¶ãæŽçããããã®ããŒãã®äŸã¯æ¬¡ã®ãšããã§ãã
TCP/UDP: 135 (RPC)
TCP/UDP: 22
TCP/UDP: 3389
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæµã¯ç©ççã«éé¢ãããããŒãéã§C2ã€ã³ãã©ã¹ãã©ã¯ãã£ãç·šæãããªã ãŒããã«ã¹ãã¬ãŒãžã¡ãã£ã¢ã䜿çšããŠã·ã¹ãã ããã·ã¹ãã ã«ã³ãã³ãã転éã§ããŸãã äž¡æ¹ã®ã·ã¹ãã ã䟵害ããå¿
èŠããããŸãã ã€ã³ã¿ãŒãããæ¥ç¶ãåããã·ã¹ãã ã¯ãæåã®ã·ã¹ãã ã«ãã£ãŠäŸµå®³ãããå¯èœæ§ãæãé«ãã2çªç®ã®ã·ã¹ãã ã¯ããªã ãŒããã«ã¡ãã£ã¢ãä»ããŠãã«ãŠã§ã¢ãè€è£œããããšã«ããã暪æ¹åã®ç§»åäžã«äŸµå®³ãããŸãïŒ
ããŒã8ãåç
§ïŒã ã³ãã³ããšãã¡ã€ã«ã¯ãéé¢ãããã·ã¹ãã ãããã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããã·ã¹ãã ã«äžç¶ãããŸãããã®ã·ã¹ãã ã«ã¯ãæ»æè
ãçŽæ¥ã¢ã¯ã»ã¹ããŸãã
ä¿è·ã«é¢ããæšå¥šäºé
ïŒãªã ãŒããã«ããã€ã¹ã®èªåå®è¡ãç¡å¹ã«ããŸãã çµç¹ã®ããªã·ãŒã¬ãã«ã§ãªã ãŒããã«ã¡ãã£ã¢ã®äœ¿çšãçŠæ¢ãŸãã¯å¶éããŸãã ãªã ãŒããã«ã¡ãã£ã¢ãæ¥ç¶ãããšãã«å®è¡ãããããã»ã¹ã®ç£æ»ãæŽçããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæ»æè
ã¯ãããã·ãµãŒããŒã䜿çšããŠãã·ã¹ãã éã§ãããã¯ãŒã¯ãã©ãã£ãã¯ããªãã€ã¬ã¯ããããããããã¯ãŒã¯éä¿¡ã®åªä»ãšããŠäœ¿çšãããã§ããŸãã å€ãã®ããŒã«ïŒHTRANãZXProxyãZXPortMapãªã©ïŒã䜿çšãããšããã©ãã£ãã¯ããªãã€ã¬ã¯ãããããããŒãã転éãããã§ããŸãã
ãããã·ã®æŠå¿µã«ã¯ããã¢ããŒãã¢ïŒp2pïŒãã¡ãã·ã¥ãããã¯ãŒã¯ããŸãã¯ãããã¯ãŒã¯éã®ä¿¡é Œã§ããæ¥ç¶ã«ãããä¿¡é Œãå«ãŸããŸãã ãããã¯ãŒã¯ã¯ãçµç¹å
ãŸãã¯ä¿¡é Œé¢ä¿ã®ããçµç¹éã«ååšã§ããŸãã æ»æè
ã¯ããããã¯ãŒã¯ã®ä¿¡é Œã䜿çšããŠC2ãã£ãã«ãå¶åŸ¡ããããåæéä¿¡ãããã¯ãŒã¯æ¥ç¶ã®æ°ãæžããããããã©ãŒã«ããã¬ã©ã³ã¹ãæäŸããããä¿¡é Œã§ããæ¥ç¶ã䜿çšããŠç念ãåé¿ãããã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæ»æè
ã¯ãã³ãã³ã/ããŒã¿ãæ¢åã®æšæºã¢ããªã±ãŒã·ã§ã³å±€ãããã³ã«ã«ã«ãã»ã«åãã代ããã«ãç¬èªã®ãããã¯ãŒã¯ãããã³ã«ã䜿çšããŠC2ãã£ãã«ãç·šæã§ããŸãã æµã®C2ãããã³ã«ã®å®è£
ã¯ãTCP / IPãŸãã¯å¥ã®æšæºãããã¯ãŒã¯ã¹ã¿ãã¯ã§æ瀺ãããåºç€ãšãªããããã³ã«ã®äžã«ãæ¢ç¥ã®ãããã³ã«ãŸãã¯ãŠãŒã¶ãŒãããã³ã«ïŒrawãœã±ãããå«ãïŒãæš¡å£ã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒ C2ãã£ãã«ãä»ããŠéä¿¡ããããã©ãã£ãã¯ãé ãããã«ãæ»æè
ã¯èªåã®æå·åãããã³ã«ãŸãã¯æå·åã¢ã«ãŽãªãºã ã䜿çšã§ããŸãã åºå®ããŒã䜿çšãããã¬ãŒã³ããã¹ãã®XORæå·åãªã©ã®åçŽãªã¹ããŒã ã¯ãæå·ããã¹ããæäŸããŸãïŒéåžžã«è匱ã§ããïŒã
ç¬èªã®æå·åã¹ããŒã ã®è€éãã¯ããŸããŸã§ãã ãã«ãŠã§ã¢ãµã³ãã«ã®åæãšãªããŒã¹ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠã䜿çšããã¢ã«ãŽãªãºã ãšæå·åããŒãæ£åžžã«æ€åºã§ããŸãã äžéšã®æ»æè
ã¯ãæ¢ç¥ã®ã©ã€ãã©ãªã䜿çšãã代ããã«ãæ¢ç¥ã®æå·åã¢ã«ãŽãªãºã ã®ç¬èªã®ããŒãžã§ã³ãå®è£
ããããšããå ŽåããããŸããããã«ãããæµãœãããŠã§ã¢ã®æäœã§æå³ããªããšã©ãŒãçºçããå¯èœæ§ããããŸãã
ä¿è·ã«é¢ããæšå¥šäºé
ïŒãã«ãŠã§ã¢ã察称ããŒã䜿çšããŠç¬èªã®æå·åã䜿çšããå ŽåããœãããŠã§ã¢ãµã³ãã«ããã¢ã«ãŽãªãºã ãšããŒãååŸããŠããããã¯ãŒã¯ãã©ãã£ãã¯ããã³ãŒããããã«ãŠã§ã¢ã·ã°ããã£ãèå¥ããããšãã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒ C2ãã£ãã«ãä»ããŠéä¿¡ãããæ
å ±ã¯ãæšæºã®ããŒã¿ãšã³ã³ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããŠãšã³ã³ãŒããããŸãã ããŒã¿ãšã³ã³ãŒãã£ã³ã°ã®äœ¿çšã¯ãæ¢åã®ãããã³ã«ä»æ§ã«æºæ ããããã§ãããASCIIãUnicodeãBase64ãMIMEãUTF-8ããŸãã¯ãã®ä»ã®ãã€ããªããã¹ãããã³æåãšã³ã³ãŒãã£ã³ã°ã®äœ¿çšãå«ãŸããŸãã gzipãªã©ã®äžéšã®ãšã³ã³ãŒãã·ã¹ãã ã§ã¯ãããã«ããŒã¿ãå§çž®ã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒéä¿¡ãããã³ã³ãã³ãã®æ€åºãšè§£èªãå°é£ã«ããéä¿¡ããã»ã¹ãç®ç«ããªãããéä¿¡ãããã³ãã³ããé ãããã«ããã£ãã«C2ã®ããŒã¿ãé衚瀺ã«ããããšãã§ããŸãïŒãã ããå¿
ãããæå·åã䜿çšããå¿
èŠã¯ãããŸããïŒã ãããã³ã«ãã©ãã£ãã¯ã«äžèŠãªããŒã¿ãè¿œå ãããã¹ãã¬ãã°ã©ãã£ã䜿çšãããæ£åœãªãã©ãã£ãã¯ãC2ãã©ãã£ãã¯ãšçµã¿åããããHTTPèŠæ±ã¡ãã»ãŒãžã®æ¬æã«å€æŽãããBase64ãªã©ã®éæšæºã®ããŒã¿ãšã³ã³ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšãããªã©ãå€ãã®é£èªåæ¹æ³ããããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒ Domain Frontingã®æ¬è³ªã¯ãCDNãããã¯ãŒã¯ïŒContent Delivery NetwoksïŒã®HTTPãã±ããã®å®éã®å®å
ã¢ãã¬ã¹ãé ãæ©èœã§ãã
äŸïŒãã¡ã€ã³Xãšãã¡ã€ã³Yãããããããã¯åãCDNã®ã¯ã©ã€ã¢ã³ãã§ãã ãã¡ã€ã³ã¢ãã¬ã¹XãTLSããããŒã«ç€ºããããã¡ã€ã³Yã¢ãã¬ã¹ãHTTPããããŒã«ãããã±ããã¯ããœãŒã¹ã¢ãã¬ã¹ãšå®å
ã¢ãã¬ã¹éã®ãããã¯ãŒã¯éä¿¡ãçŠæ¢ãããŠããå Žåã§ãããã¡ã€ã³Yã¢ãã¬ã¹ã«é
ä¿¡ãããå¯èœæ§ãé«ãã§ããHTTPsãã±ããã«ã¯2ã»ããã®ããããŒãå«ãŸããŸããæåã®TLSã¯ãã±ããã®éããéšåã«ããã2çªç®ã®HTTPã¯ãã±ããã®æå·åãããéšåãæããŸãã ããã«ãåããããŒã«ã¯ãå®å
IPã¢ãã¬ã¹ãæå®ããããã®ç¬èªã®ãã£ãŒã«ãããããŸãã Domain Frontingã®æ¬è³ªã¯ãTLSããããŒã®ãSNIããã£ãŒã«ããšHTTPããããŒã®ãHostããã£ãŒã«ãã§ç°ãªããã¡ã€ã³åãæå³çã«äœ¿çšããããšã§ãã ãããã£ãŠãèš±å¯ãããå®å
ã¢ãã¬ã¹ã¯ãSNIããã£ãŒã«ãã«ç€ºãããé
ä¿¡å®å
ã¢ãã¬ã¹ã¯ããã¹ãããã£ãŒã«ãã«ç€ºãããŸãã äž¡æ¹ã®ã¢ãã¬ã¹ãåãCDNã«å±ããå Žåããã®ãããªãã±ãããåä¿¡ãããšãã«ãŒãã£ã³ã°ããŒãã¯èŠæ±ãã¿ãŒã²ããã¢ãã¬ã¹ã«äžç¶ã§ããŸãã
ãã®ææ³ã«ã¯ããã¡ã€ã³ã¬ã¹ããã³ãã£ã³ã°ãšåŒã°ããå¥ã®ããªââãšãŒã·ã§ã³ããããŸãã ãã®å ŽåããSNIããã£ãŒã«ãïŒTLSããããŒïŒã¯æå³çã«ç©ºçœã®ãŸãŸã«ãªããŸããããã«ãããCDNããSNIããã£ãŒã«ããšãHOSTããã£ãŒã«ãã®äžèŽããã§ãã¯ããŠãïŒç©ºã®SNIãã£ãŒã«ããç¡èŠãããå ŽåïŒããã±ããã¯ç®æšãéæã§ããŸãã
ä¿è·ã«é¢ããæšå¥šäºé
ïŒ HTTPSãã©ãã£ãã¯ãæ€æ»ã§ããå Žåããã¡ã€ã³ããã³ãã£ã³ã°ã«é¡äŒŒããæ¥ç¶ããã£ããã£ããŠåæã§ããŸãã SSLã€ã³ã¹ãã¯ã·ã§ã³ãå®è¡ããããããã©ãã£ãã¯ãæå·åãããªãå ŽåããHOSTããã£ãŒã«ãããSNIããã£ãŒã«ããšäžèŽããŠããããæå®ãããã¢ãã¬ã¹ããã¯ã€ããªã¹ããŸãã¯ãã©ãã¯ãªã¹ãã«ååšãããã©ããã確èªã§ããŸãã ãã¡ã€ã³ããã³ãã£ã³ã°ãå®è£
ããã«ã¯ãæ»æè
ã¯ããããã䟵害ãããã·ã¹ãã ã«è¿œå ã®ããŒã«ãå±éããå¿
èŠãããããã®ã€ã³ã¹ããŒã«ã¯ããŒã«ã«ãã¹ãä¿è·ããŒã«ãã€ã³ã¹ããŒã«ããããšã§é²æ¢ã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒå¶åŸ¡ãã£ãã«ã®ä¿¡é Œæ§ã確ä¿ããéä¿¡ããŒã¿ã®ãããå€ãè¶
ããªãããã«ãããããæ»æè
ã¯ã¡ã€ã³ãã£ãã«C2ãå±æ®åãŸãã¯å©çšã§ããªãå Žåã«ããã¯ã¢ãããŸãã¯ä»£æ¿éä¿¡ãã£ãã«ã䜿çšã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæ»æè
ã¯ãããŸããŸãªæ¡ä»¶ãŸãã¯ç¹å®ã®æ©èœã§äœ¿çšãããC2ãã«ãã¹ããŒãžãã£ãã«ãäœæã§ããŸãã ããã€ãã®æé ã䜿çšãããšãC2ãã£ã³ãã«ãæ··ä¹±ãé£èªåããããããæ€åºãå°é£ã«ãªããŸãã
ã¿ãŒã²ãããã¹ãã§å®è¡ãããŠããRATã¯ã第1å±€ãµãŒããŒC2ãžã®æ¥ç¶ãéå§ããŸãã æåã®ã¹ãããã«ã¯ããã¹ãã«é¢ããåºæ¬æ
å ±ãåéããæŽæ°ããŒã«ãå®è¡ããè¿œå ã®ãã¡ã€ã«ãããŠã³ããŒãããããã®èªååæ©èœããããŸãã 次ã«ã2çªç®ã®RATããŒã«ãèµ·åããŠããã¹ãã2çªç®ã®å±€ã®ãµãŒããŒC2ã«ãªãã€ã¬ã¯ãã§ããŸãã C2ã®2çªç®ã®æ®µéã¯ãã»ãšãã©ã®å Žåå®å
šã«æ©èœããæµããªããŒã¹ã·ã§ã«ãšè¿œå ã®RATæ©èœãä»ããŠã¿ãŒã²ããã·ã¹ãã ãšå¯Ÿè©±ã§ããããã«ããŸãã
ã»ãšãã©ã®å Žåãã¹ãããC2ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã暪æããããšãªããäºãã«å¥ã
ã«é
眮ãããŸãã ããŒãããŒããŒã«ã¯ãå
ã®ç¬¬1ã¹ããŒãžãã£ãã«ãæ€åºãããŠãããã¯ãããå Žåã«åããŠãåé·ãªç¬¬1ã¹ããŒãžãã£ãŒãããã¯ãŸãã¯ã¹ãã¢ãã£ãã«ãçšæãããŠããå ŽåããããŸãã
ä¿è·ã«é¢ããæšå¥šäºé
ïŒãã«ãã¹ããŒãžãã£ãã«ã®ç·šæã«äœ¿çšãããC2ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãäºåã«ããã£ãŠããå Žåã¯ãããã¯ãããå ŽåããããŸãã C2ãã©ãã£ãã¯ã«äžæã®çœ²åãååšããå Žåããããã䜿çšããŠãã£ãã«ãèå¥ããã³ãããã¯ã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæªæã®ãããã©ãã£ãã¯ã®ãœãŒã¹ãåœè£
ããããã«ãæ»æè
ã¯è€æ°ã®ãããã·ãµãŒããŒã®ãã§ãŒã³ã䜿çšã§ããŸãã ååãšããŠãé²åŸ¡åŽã¯æåŸã®ãããã·ã®ã¿ã決å®ã§ããŸãã ãã«ããããã·ã䜿çšãããšãæªæã®ãããã©ãã£ãã¯ã®ãœãŒã¹ãç¹å®ããã®ãé£ãããªããé²åŸ¡åŽã¯è€æ°ã®ãããã·ãµãŒããŒãä»ããŠæªæã®ãããã©ãã£ãã¯ãç£èŠããå¿
èŠããããŸãã
ä¿è·ã«é¢ããæšå¥šäºé
ïŒãã©ãã¯ãªã¹ããšãã¯ã€ããªã¹ããæŽçããããšã«ãããæ¢ç¥ã®å¿åãããã¯ãŒã¯ïŒTorãªã©ïŒããã³C2ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®ãã©ãã£ãã¯ããããã¯ã§ããŸãã ãã ãããã®ãããã¯æ¹æ³ã¯ããã¡ã€ã³ããã³ãã£ã³ã°ãšåæ§ã®ææ³ã䜿çšããŠåé¿ã§ããããšã«æ³šæããŠãã ããã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒäžéšã®å¯ŸæŠçžæã¯ãç°ãªããããã³ã«éã§C2ããŒã¿ãã£ãã«ãå
±æããå ŽåããããŸãã çä¿¡ã³ãã³ãã¯1ã€ã®ãããã³ã«ã§éä¿¡ã§ããçºä¿¡ããŒã¿ã¯ç°ãªãæ¹æ³ã§éä¿¡ã§ãããããç¹å®ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®å¶éãåé¿ã§ããŸãã åäžã®ã¡ãã»ãŒãžã®ãããå€ãè¶
éããããšã«é¢ããèŠåãåé¿ããããã«ãåé¢ã¯å¶çºçãªå ŽåããããŸãã
ã»ãã¥ãªãã£ã«é¢ããæšå¥šäºé
ïŒãã±ããã®å
容ãåæããŠã䜿çšäžã®ããŒãã§äºæããããããã³ã«ã®åäœãšäžèŽããªãæ¥ç¶ãèŠã€ããŸãã è€æ°ã®éä¿¡ãã£ãã«éã§ã¢ã©ãŒããäžèŽãããããšããC2ã®æ€åºã«åœ¹ç«ã¡ãŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæ»æè
ã¯ããã€ãã®ã¬ãã«ã®C2ãã©ãã£ãã¯æå·åãé©çšã§ããŸãã ååãšããŠïŒãã ããä»ã®ãªãã·ã§ã³ã¯é€å€ãããŸããïŒãHTTPSãŸãã¯SMTPSæå·åã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯ãç¬èªã®æå·åã¹ããŒã ã«ãã£ãŠè¿œå ã®ãã³ããªã³ã°ã䜿çšãããŸãã
ã»ãã¥ãªãã£ã®ãã³ãïŒæå·åãããã³ã«ã䜿çšãããšã眲åããŒã¹ã®ãã©ãã£ãã¯åæã«åºã¥ããäžè¬çãªC2æ€åºãè€éã«ãªãå ŽåããããŸãã ãã«ãŠã§ã¢ãæšæºã®æå·åãããã³ã«ã䜿çšããŠããå ŽåãSSL / TLSæ€æ»ã䜿çšããŠãäžéšã®æå·åããããã£ãã«ã§C2ãã©ãã£ãã¯ãæ€åºã§ããŸãã SSL / TLSæ€èšŒã«ã¯ã
äžå®å
šãªèšŒææžæ€èšŒãªã©ãæœåšçãªã»ãã¥ãªãã£åé¡ãåé¿ããããã«å®è£
åã«èæ
®ããå¿
èŠãããç¹å®ã®ãªã¹ã¯ãå«ãŸããŸãã SSL / TLSæ€èšŒåŸã第2ã¬ãã«ã®æå·åã«ã¯è¿œå ã®æå·åæãå¿
èŠã«ãªãå ŽåããããŸãã
ã·ã¹ãã ïŒ LinuxãmacOS
æš©å©ïŒãŠãŒã¶ãŒ
説æïŒæ»æè
ã¯ããŒããããã³ã°æ¹æ³ã䜿çšããŠãã·ã¹ãã ãžã®æ¥ç¶ã«äœ¿çšããéããŠããããŒããé ãããšãã§ããŸãã
ã»ãã¥ãªãã£ã®ãã³ã
ïŒã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšãããšãäžéšã®ããŒããããã³ã°ãªãã·ã§ã³ã®å®è£
ãé²ãããšãã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒã€ã³ã¿ã©ã¯ãã£ããªã³ãã³ãããã³å¶åŸ¡ã¢ãŒãã確ç«ããããã«ãæ»æè
ã¯ãããã®ããã«èšèšãããæ£åœãªãœãããŠã§ã¢ã䜿çšã§ããŸãã TeamViewerãGo2AssistãLogMainãAmmyAdminãªã©ããªã¢ãŒãã¢ã¯ã»ã¹çšã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãµããŒãããã³ãœãããŠã§ã¢ãéåžžããã¯ãã«ã«ãµããŒããµãŒãã¹ã§äœ¿çšããããã¯ã€ããªã¹ãã«ç»é²ã§ããŸãã VNCãAmmyãTeamviewãªã©ã®ãªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ã¯ããã¯ãã«ã«ãµããŒããšã³ãžãã¢ãæããã䜿çšããæ»æè
ããã䜿çšããŸãã
ã·ã¹ãã ã代æ¿C2ãã£ãã«ãšããŠäœ¿çšãããããã«äŸµå®³ãããåŸããªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ãã€ã³ã¹ããŒã«ã§ããŸãã ãŸãããã«ãŠã§ã¢ã®ã³ã³ããŒãã³ããšããŠäœ¿çšããŠãæ»æè
ã«ãã£ãŠå¶åŸ¡ãããŠãããµãŒããŒãŸãã¯ã·ã¹ãã ãšã®éæ¥ç¶ã確ç«ããããšãã§ããŸãã
TeamViewerãªã©ã®ç®¡çããŒã«ã¯ããã·ã¢ã®å·ããã³ç¯çœªäŒæ¥ãé¢å¿ãæã£ãŠããåœã®æ¿åºæ©é¢ã察象ãšããããã€ãã®ã°ã«ãŒãã§äœ¿çšãããŠããŸããã
ä¿è·ã«é¢ããæšå¥šäºé
ïŒãªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ã¯ããã¡ã€ã³ããã³ãã£ã³ã°ãã¯ããã¯ãšçµã¿åãããŠäœ¿çšââã§ããããããã¹ãã»ãã¥ãªãã£ããŒã«ã䜿çšããŠæµãRATããŒã«ãã€ã³ã¹ããŒã«ããªãããã«ããããšããå§ãããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒãã¡ã€ã«ãããã·ã¹ãã ããå¥ã®ã·ã¹ãã ã«ã³ããŒããŠãæµã®ããŒã«ãŸãã¯ä»ã®ãã¡ã€ã«ãå±éã§ããŸãã ãã¡ã€ã«ã¯ãæ»æè
ãå¶åŸ¡ããå€éšã·ã¹ãã ãããCïŒCãã£ãã«ãä»ããŠããŸãã¯FTPãªã©ã®ä»£æ¿ãããã³ã«ã䜿çšããä»ã®ããŒã«ã䜿çšããŠã³ããŒã§ããŸãã scpãrsyncãsftpãªã©ã®çµã¿èŸŒã¿ããŒã«ã䜿çšããŠããã¡ã€ã«ãMacããã³Linuxã«ã³ããŒããããšãã§ããŸãã
çžæã¯ãå
éšã®è¢«å®³è
ã·ã¹ãã éã§ãã¡ã€ã«ã暪æ¹åã«ã³ããŒããŠããããã¯ãŒã¯ã®ç§»åãšãªã¢ãŒãã³ãã³ãã®å®è¡ããµããŒãããããšãã§ããŸãã ããã¯ãSMBãä»ããŠãããã¯ãŒã¯ãªãœãŒã¹ãæ¥ç¶ããããWindows Admin SharesãŸãã¯RDPãžã®èªèšŒæžã¿æ¥ç¶ã䜿çšããŠããã¡ã€ã«å
±æãããã³ã«ã䜿çšããŠå®è¡ã§ããŸãã
ä¿è·ã®æšå¥šäºé
ïŒæ€åºã®æ段ãšããŠãSMBãããã³ã«ãä»ããŠãããã¯ãŒã¯äžã®ãã¡ã€ã«ã®äœæãšè»¢éãç£èŠããããšããå§ãããŸãã ã·ã¹ãã å
ã§ãã¡ã€ã«ãäœæããå€éšãããã¯ãŒã¯æ¥ç¶ã䜿çšããç°åžžãªããã»ã¹ãçãããã¯ãã§ãã FTPãªã©ã®ãŠãŒãã£ãªãã£ã®éå
žåçãªäœ¿çšãçãããå ŽåããããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒ C2ãã©ãã£ãã¯ã®æ€åºããã³æ¢åã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãšã®æ··åãåé¿ããããã«ãæ»æè
ã¯HTTPãHTTPSãSMTPãDNSãªã©ã®æšæºçãªã¢ããªã±ãŒã·ã§ã³å±€ãããã³ã«ã䜿çšã§ããŸãã ããšãã°ããããã·ãµãŒããŒãšãã¹ã¿ãŒããŒãããã³ä»ã®ããŒããšã®éã®C2ãã£ãã«ïŒãšã³ã¯ã¬ãŒãïŒå
ã®æ¥ç¶ã§ã¯ãéåžžãRPCãSSHããŸãã¯RDPãããã³ã«ã䜿çšãããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒçžæã¯ãããç¥ãããŠããæå·åã¢ã«ãŽãªãºã ã䜿çšããŠãC2ãã©ãã£ãã¯ãé ãããšãã§ããŸãã å
ç¢ãªã¢ã«ãŽãªãºã ã䜿çšããŠããã«ãããããããç§å¯ããŒããã«ãŠã§ã¢ã«ãã£ãŠæå·åããã³çæãããæ§æãã¡ã€ã«ã«ä¿åãããŠããå ŽåããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠC2ãã©ãã£ãã¯ãé瀺ã§ããŸãã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒ OSIã¢ãã«ã®éã¢ããªã±ãŒã·ã§ã³å±€ãããã³ã«ã¯ãææãããã¹ããšãµãŒããŒéã®éä¿¡ããŸãã¯ãããã¯ãŒã¯äžã®ææãããã¹ãã®çžäºäœçšã«äœ¿çšã§ããŸãã ããç¥ãããå®è£
ã§ã¯ããããã¯ãŒã¯å±€ãããã³ã«â ICMPããã©ã³ã¹ããŒãå±€â UDPãã»ãã·ã§ã³å±€â SOCKSãããã³Serial over LANïŒSOLïŒãªã©ã®ãªãã€ã¬ã¯ã/ãã³ãã«ãªã©ã®ãããã³ã«ã䜿çšãããŸããã
ICMPã¯ããã¹ãéã®éä¿¡ãé ãããã«ãµã€ããŒç¯çœªè
ã«ãã£ãŠãã䜿çšãããŸãã ICMPã¯ã€ã³ã¿ãŒããããããã³ã«ã¹ã€ãŒãã®äžéšã§ããããã¹ãŠã®IPäºæããã€ã¹ã§å®è£
ããå¿
èŠããããããTCPãUDPãªã©ã®ä»ã®ãããã³ã«ã»ã©é »ç¹ã«ç£èŠãããŸããã
ã·ã¹ãã ïŒ WindowsãLinuxãmacOS
説æïŒæ»æè
ã¯ãéæšæºããŒããä»ããŠC2ãä»ããŠéä¿¡ããæ£ããæ§æãããŠããªããããã·ãµãŒããŒãšãã¡ã€ã¢ãŠã©ãŒã«ããã€ãã¹ã§ããŸãã
ã·ã¹ãã ïŒ Windows
æš©å©ïŒãŠãŒã¶ãŒ
説æïŒæ»æè
ã¯ãå®è¡äžã®æ£åœãªå€éšWebãµãŒãã¹ã䜿çšããŠãææããã·ã¹ãã ãå¶åŸ¡ããã³ãã³ããéä¿¡ããããšãã§ããŸãã 管çãµãŒããŒã¯ãã³ãã³ãã¢ã³ãã³ã³ãããŒã«ïŒCïŒCãŸãã¯C2ïŒãšåŒã°ããŸãã 人æ°ã®ããWebãµã€ãããœãŒã·ã£ã«ãããã¯ãŒã¯ã¯C2ã®ã¡ã«ããºã ãšããŠæ©èœããGoogleãTwitterãªã©ã®ããŸããŸãªå
Œ
±ãµãŒãã¹ã䜿çšã§ããŸãã ããã¯ãã¹ãŠãäžè¬çãªãã©ãã£ãã¯ãããŒã§æªæã®ããã¢ã¯ãã£ããã£ãé ãã®ã«åœ¹ç«ã¡ãŸãã WebãµãŒãã¹ã¯éåžžSSL / TLSã䜿çšãããããæ»æè
ã¯è¿œå ã®ä¿è·ã¬ã€ã€ãŒãååŸããŸãã
ã»ãã¥ãªãã£ã«é¢ããæšå¥šäºé
ïŒãã¡ã€ã¢ãŠã©ãŒã«ãšWebãããã·ã䜿çšããŠãå€éšãããã¯ãŒã¯éä¿¡ãå¶éããããªã·ãŒãå®è£
ã§ããŸãã
C2ã®äºé²ãšæ€åºã®ããã®å¯Ÿçã®ç·šæã«é¢ããäžè¬çãªæšå¥šäºé
â¢ã·ã°ããã£ããŒã¹ã®ãã©ãã£ãã¯åæã䜿çšããIDS / DLPã·ã¹ãã ã䜿çšããŠãæ¢ç¥ã®ç¹å®ã®C2ããŒã«ããã³ãã«ãŠã§ã¢ãæ€åºããã³ãããã¯ã§ãããããæ»æè
ã¯äœ¿çšããããŒã«ãçµæçã«å€æŽããããããŒã¿è»¢éãããã³ã«ãèšå®ããŠãæ¢ç¥ã®æ段ã«ããæ€åºãåé¿ããå¯èœæ§ãé«ãä¿è·;
â¢ãŠã€ã«ã¹å¯Ÿçãšã³ããã€ã³ãä¿è·ããŒã«ã䜿çšããŠãæ¢ç¥ã®ç¹å®ã®C2ããŒã«ãšãã«ãŠã§ã¢ããããã¯ããŸãã
â¢å
éšãããã¯ãŒã¯äžã®ãã¹ãã¯ãèš±å¯ãããã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠã®ã¿ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
â¢å¯Ÿå¿ãããããã¯ãŒã¯ã²ãŒããŠã§ã€ãééãããã¡ã€ã¢ãŠã©ãŒã«ãšãããã·ã®å¿
èŠãªããŒãã®ã¿ãèš±å¯ããããšã«ãããçºä¿¡ãã©ãã£ãã¯ãå¶éããŸãã
â¢æ¢ç¥ã®C2ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãã¡ã€ã³ãšIPã¢ãã¬ã¹ããããã¯ããŸãã ãã ããããã¯å¹æçã§é·æçãªãœãªã¥ãŒã·ã§ã³ã§ã¯ãªãããšã«æ³šæããŠãã ããã çžæã¯ãã°ãã°C2ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãå€æŽã§ããŸãã
â¢ã¢ããªã±ãŒã·ã§ã³ãã¯ã€ããªã¹ãããŒã«ã䜿çšããŠããµãŒãããŒãã£ãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ãšå®è¡ãå°é£ã«ããŸãã
â¢ãã¡ã€ã¢ãŠã©ãŒã«ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãããã³ãããã·ã䜿çšããŠãããç¥ãããŠãããªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ïŒTeamViewerãGo2AssistãLogMainãAmmyAdminãªã©ïŒã䜿çšãããµã€ãããã³ãµãŒãã¹ãžã®çºä¿¡ãã©ãã£ãã¯ãå¶éããŸãã
â¢ãã«ãŠã§ã¢ã察称ããŒã䜿çšããŠç¬èªã®æå·åã䜿çšããŠããå ŽåããœãããŠã§ã¢ãµã³ãã«ã®ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠããããã¯ãŒã¯ãã©ãã£ãã¯ããã³ãŒããããã«ãŠã§ã¢ã·ã°ããã£ãèå¥ããããã®ã¢ã«ãŽãªãºã ãšããŒãååŸã§ããŸããâ¢ä»£æ¿éä¿¡ãã£ãã«ã®å
å«ãŸãã¯äœ¿çšã«é¢é£ããAPIé¢æ°ã®åŒã³åºããç£èŠããŸããâ¢ICMPã¡ãã»ãŒãžãŸãã¯ç°åžžãªããŒã¿ãå«ãããéåžžã¯ãããã¯ãŒã¯äžãŸãã¯ãããã¯ãŒã¯å€ã«è¡šç€ºãããªãä»ã®ãããã³ã«ã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãåæããŸããâ¢ãããã¯ãŒã¯ãããŒãåæããŠç°åžžãªãããŒãèå¥ããŸããããšãã°ãã¯ã©ã€ã¢ã³ãããµãŒããŒããåä¿¡ãããããã¯ããã«å€ãã®ããŒã¿ãéä¿¡ããå ŽåããŸãã¯éåžžãããã¯ãŒã¯ã䜿çšããªãããã»ã¹ããããã¯ãŒã¯æ¥ç¶ãéãå Žåãâ¢ãããã¯ãŒã¯ãããŒãåæããŠã䜿çšããããŒãã®ãããã³ã«æšæºã«æºæ ããŠããªããã±ãããç¹å®ããŸãã