äž»ãªãã€ã³ã
- ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãèªç©ºãèªç©ºå®å®ãé茞ã補é ãé²è¡æ¥çãæšçãšããæç¶çã«æ»æãè¡ããµã€ããŒç¯çœªã°ã«ãŒãã®æŽ»åãé·å¹Žã«ããã远跡ããŠããŸãã
- ãã®æ»æã°ã«ãŒãã¯ã䟵害ããããã·ã³ãé éæäœããããã«äœ¿çšãããé éæäœãŠã€ã«ã¹ (RAT)ãäžè²«ããŠäœ¿çšããŠããŸãã
- ãã®æ»æã°ã«ãŒãã¯ãèªç©ºã茞éãæ è¡ã«é¢é£ããäžè²«ããããŒãã䜿çšããŠããã2017幎以éãåæ§ã®ããŒããçšããŠåæ§ã®æšçãçã£ãŠããŸãã
- ãã«ãŒããã€ã³ãã¯ãã®æ»æã°ã«ãŒããTA2541ãšåŒãã§ããŸãã
æŠèŠ
TA2541ã¯ãèªç©ºãèªç©ºå®å®ã茞éãé²è¡ç£æ¥ãªã©ãæšçãšããããŸããŸãªé éæäœãŠã€ã«ã¹ (RAT)ãé åžããæç¶çã«æŽ»åãããµã€ããŒç¯çœªè ã§ãããã«ãŒããã€ã³ãã¯2017幎ãããã®æ»æã°ã«ãŒãã远跡ããŠããããã®éããã®æ»æè ã¯äžè²«ããæŠè¡ãæè¡ãæé ïŒTTPïŒã䜿çšããŠããŸãã察象ãšãªãã»ã¯ã¿ãŒã®äºæ¥è ã¯ããã®æ»æè ã®TTPãèªèããæäŸãããæ å ±ãè åšãã³ãã£ã³ã°ãšæ€ç¥ã«å©çšããå¿ èŠããããŸãã
TA2541ã¯ãèªç©ºã茞éãæ è¡ã«é¢ããããŒãã䜿çšããŠããŸãããã«ãŒããã€ã³ãããã®æ»æã°ã«ãŒãã®è¿œè·¡ãéå§ããåœåããã®ã°ã«ãŒãã¯ãRATãã€ããŒããããŠã³ããŒããããã¯ããå«ãMicrosoft Wordã®æ·»ä»ãã¡ã€ã«ãéä¿¡ããŠããŸããããããããã®ã°ã«ãŒãã¯ãçŸåšã§ã¯ããã€ããŒãããã¹ãã£ã³ã°ãã Google Drive ãªã©ã®ã¯ã©ãŠããµãŒãã¹ãžã®ãªã³ã¯ãå«ãã¡ãã»ãŒãžãé »ç¹ã«éä¿¡ããŠããŸãããã«ãŒããã€ã³ãã¯ãTA2541ããç¹å®ã®ã³ã¢ãã£ãã£ãã«ãŠã§ã¢ã®äœ¿çšã倧éã®ã¡ãã»ãŒãžã«ããåºç¯ãªæšçèšå®ãããã³ã³ãã³ãïŒã³ã³ãããŒã«ã€ã³ãã©ã«ããããµã€ããŒç¯çœªã®æ»æè ã§ãããšè©äŸ¡ããŠããŸãã
åæ§ã®è åšæŽ»åã®è©³çްã瀺ãå ¬éå ±åã¯å°ãªããšã2019幎ããååšããŸããããã«ãŒããã€ã³ããTA2541ãšåŒã¶1ã€ã®è åšæŽ»å矀ã®äžã§å ¬å ±ããŒã¿ãšå人ããŒã¿ãçµã³ã€ããå æ¬çãªè©³çްãå ±æããã®ã¯ä»åãåããŠãšãªããŸãã
æ»æãã£ã³ããŒã³è©³çް
TA2541ã¯ãã³ã¢ãã£ãã£åãã«ãŠã§ã¢ãé åžããå€ãã®ãµã€ããŒç¯çœªã®æ»æè ãšç°ãªããéåžžããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®ã«ã¢ãŒ(ããšãææž)ã«æäºåé¡ããã¬ã³ããããã¯ããã¥ãŒã¹ã¢ã€ãã ã䜿çšããããšã¯ãããŸããã芳枬ãããã»ãŒãã¹ãŠã®ãã£ã³ããŒã³ã«ãããŠãTA2541ã¯ããã©ã€ããèªç©ºæ©ãçæããšããããã£ãŒã¿ãŒãªã©ã茞éé¢é£ã®çšèªãå«ãã«ã¢ãŒã®ããŒãã䜿çšããŠããŸãã

å³1ïŒèªç©ºæ©éšåã®æ å ±ãèŠæ±ããã¡ãŒã«ã®èªãæå¥

å³2ïŒå€æ¥äŸ¿ã®æ å ±ãèŠæ±ããã¡ãŒã«ã®èªãæå¥
TA2541ã¯ã2017幎1æä»¥éãæç¶çãã€ç¶ç¶çãªè åšæŽ»åã瀺ããŠããŸããéåžžããã®ãã«ãŠã§ã¢ãã£ã³ããŒã³ã«ã¯æ°çŸããæ°åã®ã¡ãã»ãŒãžãå«ãŸããŸãããTA2541ãäžåºŠã«1äžãè¶ ããã¡ãã»ãŒãžãéä¿¡ããããšã¯çšã§ãããã£ã³ããŒã³ã¯ãåç±³ãæ¬§å·ãäžæ±ã®æšçãç¹°ãè¿ããªãããäžçåå°ã®æ°çŸã®çµç¹ã«åœ±é¿ãäžããŸããã¡ãã»ãŒãžã¯ã»ãŒåžžã«è±èªã§ãã
2020幎æ¥ãTA2541ã¯äžæçã«ã貚ç©ããã©ã€ãã®è©³çްãšããå šäœçãªããŒããšäžèŽããCOVIDé¢é£ã®ã«ã¢ãŒã®ããŒããæ¡çšããæ¹åã«èµãåããŸãããäŸãã°ãå人çšä¿è·å ·ïŒPPEïŒãCOVID-19æ€æ»ãããã®è²šç©èŒžéã«é¢é£ããã«ã¢ãŒãé åžããŸããã

å³3ïŒTA2541ã䜿çšããå人çšä¿è·å ·ïŒPPEïŒãããŒããšããã«ã¢ãŒ
COVID-19ã®ããŒãã¯çæéã ãæ¡çšãããæ»æè ã¯ããã«äžè¬çãªè²šç©ãé£è¡ããã£ãŒã¿ãŒäŸ¿ãªã©ãããŒãã«ããã«ã¢ãŒã«æ»ããŸããã
2019幎以éãCisco TalosãMorphisecãMicrosoftãMandiantãç¬ç«ç³»ãªãµãŒãã£ãŒãªã©ãè€æ°ã®ç ç©¶è ãåæ§ã®æŽ»åã«é¢ããããŒã¿ãçºè¡šããŠããŸãããã«ãŒããã€ã³ãã¯ããããã®ã¬ããŒãã®æŽ»åããTA2541ãšããŠè¿œè·¡ãããŠããè åšã°ã«ãŒããšéè€ããŠããããšã確èªããããšãã§ããŸãã
é éãšã€ã³ã¹ããŒã«
ãã«ãŒããã€ã³ãã¯ãæè¿ã®ãã£ã³ããŒã³ã§ããã®ã°ã«ãŒãããé£èªåãããVisual Basic ScriptïŒVBSïŒãã¡ã€ã«ã«ã€ãªããGoogle Driveã®URLãã¡ãŒã«ã«äœ¿çšããŠããããšã確èªããŸãããå®è¡ããããšãPowerShellã¯ãPastetextãSharetextãGitHubãªã©ãããŸããŸãªãã©ãããã©ãŒã ã§ãã¹ããããŠããããã¹ããã¡ã€ã«ããå®è¡ãã¡ã€ã«ãåŒã³åºããŸããæ»æè ã¯ãããŸããŸãªWindowsããã»ã¹ã«PowerShellãå®è¡ããã¢ã³ããŠã€ã«ã¹ããã¡ã€ã¢ãŠã©ãŒã«ãœãããŠã§ã¢ãªã©ã®ã»ãã¥ãªãã£è£œåã®Windows Management InstrumentationïŒWMIïŒãçšããŠãå èµã®ã»ãã¥ãªãã£ä¿è·ãç¡å¹åããããšè©Šã¿ãŸããæ»æè ã¯ããã¹ãäžã§RATãããŠã³ããŒãããåã«ãã·ã¹ãã æ å ±ãåéããŸãã

å³4ïŒã¢ã¿ãã¯ãã§ãŒã³ã®äŸ
TA2541ã¯äžè²«ããŠGoogle Driveãæã«ã¯OneDriveã䜿çšããŠæªæã®ããVBSãã¡ã€ã«ããã¹ãããŠããŸããã2021幎åŸåããããã®ã°ã«ãŒããAgentTeslaãŸãã¯Iminent Monitorã«ã€ãªããå§çž®ãã¡ã€ã«ã«ãªã³ã¯ããDiscordApp URLã䜿çšãå§ããã®ããã«ãŒããã€ã³ãã¯èгå¯ããŠããŸããDiscordã¯ãæ»æè ã䜿çšããã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ïŒCDNïŒãšããŠãŸããŸã人æ°ãé«ãŸã£ãŠããŸãã
TA2541ã¯éåžžãé ä¿¡ã®äžéšãšããŠURLã䜿çšããŸããããã«ãŒããã€ã³ã瀟ã§ã¯ããã®æ»æè ãé»åã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«ã掻çšããããšã確èªããŠããŸããäŸãã°ããã®æ»æè ã¯ããã«ãŠã§ã¢ã®ãã€ããŒãããã¹ãããCDNãžã®URLãå«ãå®è¡ãã¡ã€ã«ãåã蟌ãã RARãªã©ã®å§çž®ãããå®è¡ãã¡ã€ã«ãæ·»ä»ããŠéä¿¡ããå ŽåããããŸãã
以äžã¯ãStrReverse颿°ãšPowerShellã®RemoteSignedæ©èœã掻çšããæè¿ã®æ»æãã£ã³ããŒã³ã§äœ¿çšãããVBSãã¡ã€ã«ã®äŸã§ããVBSãã¡ã€ã«ã¯éåžžãã¡ãŒã«å šäœã®ããŒããšäžèŽããããã«åœåãããŠããããšã¯æ³šç®ã«å€ããŸãïŒæŠéãèªç©ºæ©ãçæããšããããã£ãŒã¿ãŒãªã©ã

å³5ïŒãµã³ãã«VBSãã¡ã€ã«ã®å 容
é£èªåãããã³ãã³ã:
https://paste[.]ee/r/01f2w/0
äžå³ã¯ãæè¿ã®ãã£ã³ããŒã³ã®äŸã§ãPowerShellã³ãŒããpaste.eeã®URLã§ãã¹ããããŠããæ§åã瀺ããŠããŸãã

å³6ïŒURLã®è²Œãä»ãã®äŸ
ããŒã·ã¹ãã³ã¹(æ°žç¶æ§ç¢ºç«):
éåžžãTA2541 㯠Visual Basic Script (VBS) ãã¡ã€ã«ã䜿çšããŠã圌ãã®ãæ°ã«å ¥ãã®ãã€ããŒãã® 1 ã€ã§ãã AsyncRAT ãšå ±ã«ããŒã·ã¹ãã³ã¹ã確ç«ããããšã«ãªããŸããããã¯ãPowerShell ã¹ã¯ãªãããæã VBS ãã¡ã€ã«ãã¹ã¿ãŒãã¢ãããã£ã¬ã¯ããªã«è¿œå ããããšã§å®çŸãããŸããæ³šïŒäœ¿çšãããVBSãšPowerShellã®ãã¡ã€ã«åã¯ãã»ãšãã©ãWindowsãã·ã¹ãã ã®æ©èœãæš¡å£ããŠåœåãããŠããŸããæè¿ã®ãã£ã³ããŒã³ã§ã®äŸã¯ä»¥äžã®éãã§ãã
æ°žç¶æ§ç¢ºç«ã®äŸ:
C:\Users[User]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemFramework64Bits.vbs
VBSãã¡ã€ã«ã®å 容:
Set Obj = CreateObject("WScript.Shell")
Obj.Run "PowerShell -ExecutionPolicy RemoteSigned -File " & "C:\Users\[User]\AppData\Local\Temp\RemoteFramework64.ps1", 0
Other Recent VBS File Names Observed
UserInterfaceLogin.vbs
HandlerUpdate64Bits.vbs
WindowsCrashReportFix.vbs
SystemHardDrive.vbs
ãŸããTA2541ã¯ãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã®äœæãã¬ãžã¹ããªãžã®ãšã³ããªã®è¿œå ã«ãããæ°žç¶æ§ã確ç«ããŠããŸããããšãã°ã2021幎11æã«TA2541ã¯ããããã®äž¡æ¹ã®æ¹æ³ã䜿çšããŠãã€ããŒãImminent Monitorãé åžããŸãããæè¿ã®ãã£ã³ããŒã³ã§ã¯ãvjw0rmãšSTRRATãã¿ã¹ã¯ã®äœæãšã¬ãžã¹ããªãžã®ãšã³ããªã®è¿œå ãæŽ»çšããŠããŸããããšãã°ã以äžã®ãããªãã®ã§ãã
ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯:
schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
schtasks /create /sc minute /mo 1 /tn Skype /tr "C:\Users\[Use]\AppData\Roaming\xubntzl.txt"
ã¬ãžã¹ããªãŒããŒ:
Key: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost
Data: C:\Users[User]\AppData\Roaming\server\server.exe
Key: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xubntzl
Data: C:\Users\User\AppData\Roaming\xubntzl.txt
ãã«ãŠã§ã¢:
ãã«ãŒããã€ã³ãã¯ã2017幎以éãTA2541ãåæ°çš®é¡ã®ãã«ãŠã§ã¢ãã€ããŒãã䜿çšããŠããããšã芳枬ããŠããŸããæ»æè ã¯ãç¯çœªè ãã©ãŒã©ã ã§è³Œå ¥å¯èœãªã³ã¢ãã£ãã£ãã«ãŠã§ã¢ãããªãŒãã³ãœãŒã¹ãªããžããªã§å ¥æå¯èœãªãã«ãŠã§ã¢ã䜿çšããŠããŸããçŸåšãTA2541ã¯AsyncRATã奜ãã§äœ¿çšããŠããŸããããã®ä»ã®äººæ°ã®ããRATã«ã¯ãNetWireãWSH RATãParallaxããããŸãã

å³7ïŒã¡ãã»ãŒãžéã«é¢é£ããTA2541ã䜿çšãããã«ãŠã§ã¢
TA2541ã䜿çšãããã¹ãŠã®ãã«ãŠã§ã¢ã¯ãæ å ±åéç®çãææãããã·ã³ãé éæäœããããã«äœ¿çšããããšãã§ããŸããçŸæç¹ã§ã¯ãè åšè ãæåã®äŸµå®³ãéæããåŸã®æçµçãªç®æšãç®çã«ã€ããŠã¯ããã«ãŒããã€ã³ã瀟ã§ã¯ææ¡ããŠããŸããã
çŸåšã¯AsyncRATãéžæãããŠãããã«ãŠã§ã¢ã§ãããTA2541ã¯2017幎以éãæ¯å¹Žãã«ãŠã§ã¢ã®äœ¿ç𿹿³ãå€åãããŠããŸããæ»æè ã¯éåžžã芳枬ããããã£ã³ããŒã³ã§1ã€ãŸãã¯å°æ°ã®RATã®ã¿ã䜿çšããŸããã2020幎ãProofpointã¯TA2541ã10çš®é¡ä»¥äžã®ãã«ãŠã§ã¢ãé åžãããã¹ãŠåãæåã®ææãã§ãŒã³ã䜿çšããŠããããšã芳枬ããŸããã

å³8ïŒTA2541ã®ãã«ãŠã§ã¢ã®çµå¹Žååž
ã€ã³ãã©
TA2541ã¯ãã¡ãŒã«éä¿¡ã€ã³ãã©ã®äžéšãšããŠVirtual Private Serversã䜿çšããŠãããC2ã€ã³ãã©ã«ã¯Dynamic DNSïŒDDNSïŒãé »ç¹ã«äœ¿çšããŠããŸãã
C2ã€ã³ãã©ãšã¡ãã»ãŒãžã®ã¢ãŒãã£ãã¡ã¯ãã«ã¯ãè€æ°ã®ãã¿ãŒã³ãååšããŸããããšãã°ãéå»ã®ãã£ã³ããŒã³ã§ã¯ããkimjoyããšããçšèªãC2ãã¡ã€ã³åãè åšè ã®è¿ä¿¡å ã¢ãã¬ã¹ã«å«ãŸããŠããŸããããŸããTA2541ã®C2ãã¡ã€ã³ãšãã€ããŒãã®ã¹ããŒãžã³ã°URLã«ã¯ããkimjoyãããh0peãããgraceããšãã£ãããŒã¯ãŒããå«ãå ±éã®ãã¿ãŒã³ã確èªãããŠããããããé¡èãªTTPã®1ã€ãšãããŸãããŸããTA2541ã¯ãNetdormãNo-IP DDNSãªã©ã®ãã¡ã€ã³ã¬ãžã¹ãã©ãxTom GmbHãDanilenko, Artyomãªã©ã®ãã¹ãã£ã³ã°ãããã€ããŒã宿çã«äœ¿çšããŠããŸãã
æ»æã®ã¿ãŒã²ãã
å€ãã®å Žåããã£ã³ããŒã³ã«ã¯ãæ°åã®ç°ãªãçµç¹ã«å¯Ÿããæ°çŸããæ°åã®é»åã¡ãŒã«ã¡ãã»ãŒãžãå«ãŸããŠããŸããããã«ãŒããã€ã³ãã¯ãTA2541ãäœåãã®çµç¹ãæšçã«ããŠããããšã確èªããŠããŸãããèªç©ºãèªç©ºå®å®ã茞éã補é ãããã³é²è¡ç£æ¥ã«ãããè€æ°ã®çµç¹ãããã£ã³ããŒã³ã®æšçãšããŠå®æçã«è¡šç€ºãããŠããŸããTA2541 ã¯ãç¹å®ã®åœ¹å²ãæ©èœãæã€äººç©ãæšçã«ããŠããããã§ã¯ãªãããšããåä¿¡è å šäœã«åºãååžããŠããããã§ãã
çµè«
TA2541ã¯ãç¹ã«æãé »ç¹ã«æšçãšãªãã»ã¯ã¿ãŒã®äŒæ¥ã«å¯ŸããŠãäžè²«ããŠæŽ»çºãªãµã€ããŒç¯çœªã®è åšãäžãç¶ããŠããŸãããã«ãŒããã€ã³ãã¯ããã®æ»æè ããã«ã¢ãŒã®ããŒããé ä¿¡ãã€ã³ã¹ããŒã«ã«æå°éã®å€æŽãå ããã ãã§ãéå»ã®æŽ»åã§èгå¯ãããã®ãšåãTTPãåŒãç¶ã䜿çšãããšãé«ãä¿¡é Œæ§ããã£ãŠè©äŸ¡ããŠããŸããTA2541 ã¯ãä»åŸã®ãã£ã³ããŒã³ã§ã AsyncRAT ãš vjw0rm ã䜿ãç¶ãããã®ç®çãéæããããã«ä»ã®ã³ã¢ãã£ãã£ãã«ãŠã§ã¢ã䜿çšããå¯èœæ§ãé«ããšæãããŸãã
IoC (Indicators of Compromise / 䟵害ã®çè·¡)
C2 ãã¡ã€ã³
|
IoC |
説æ |
èŠ³æž¬æ¥ |
|
joelthomas[.]linkpc[.]net |
AsyncRAT C2 Domain |
Throughout 2021 |
|
rick63[.]publicvm[.]com |
AsyncRAT C2 Domain |
January 2022 |
|
tq744[.]publicvm[.]com |
AsyncRAT C2 Domain |
January 2022 |
|
bodmas01[.]zapto[.]org |
AsyncRAT C2 Domain |
January 2022 |
|
bigdips0n[.]publicvm[.]com |
AsyncRAT C2 Domain |
December 2021 |
|
6001dc[.]ddns[.]net |
AsyncRAT C2 Domain |
September 2021 |
|
kimjoy[.]ddns[.]net |
Revenge RAT C2 Domain |
March 2021 |
|
h0pe[.]ddns[.]net |
AsyncRAT C2 Domain |
April/May 2021 |
|
e29rava[.]ddns[.]net |
AsyncRAT C2 Domain |
June 2021 |
|
akconsult[.]ddns[.]net |
AsyncRAT C2 Domain |
July 2021 |
|
grace5321[.]publicvm[.]com |
StrRAT C2 Domain |
January 2022 |
|
grace5321[.]publicvm[.]com |
Imminent Monitor C2 Domain |
November 2021 |
VBS SHA256 ããã·ã¥
VBS SHA256 hashes observed in recent December and January campaigns.
File Name: Aircrafts PN#_ALT PN#_Desc_&_Qty Details.vbs
SHA256: 67250d5e5cb42df505b278e53ae346e7573ba60a06c3daac7ec05f853100e61c
File Name: charters details.pdf.vbs
SHA256: ebd7809cacae62bc94dfb8077868f53d53beb0614766213d48f4385ed09c73a6
File Name: charters details.pdf.vbs
SHA256: 4717ee69d28306254b1affa7efc0a50c481c3930025e75366ce93c99505ded96
File Name: 4Pax Trip Details.pdf.vbs
SHA256: d793f37eb89310ddfc6d0337598c316db0eccda4d30e34143c768235594a169c
ETâ¯ã·ã°ããã£â¯
2034978 - ET POLICY Pastebin-style Service (paste .ee) in TLS SNI
2034979 - ET HUNTING Powershell Request for paste .ee Page
2034980 - ET MALWARE Powershell with Decimal Encoded RUNPE Downloaded
2850933 - ETPRO HUNTING Double Extension VBS Download from Google Drive
2850934 - ETPRO HUNTING Double Extension PIF Download from Google Drive
2850936 - ETPRO HUNTING VBS Download from Google Drive
â»æ¬ããã°ã®æ å ±ã¯ãè±èªã«ããåæãCharting TA2541's Flightãã®ç¿»èš³ã§ããè±èªåæãšã®éã§å 容ã®éœéœ¬ãããå Žåã«ã¯ãè±èªåæãåªå ããŸãã