ãã€ã³ã:
- ãã«ãŒããã€ã³ãã®è åšãªãµãŒãã£ãŒã¯ã2021幎6æäžæ¬ä»¥éãCOVID-19é¢é£ã®è åšã®å¢å ã芳枬
- æ»æè ã¯ããã«ã¿æ ªã«é¢é£ããé¢å¿ã®é«ãŸããšææã®åºãããæªçš
- ãã«ãŒããã€ã³ãã®è åšãªãµãŒãã£ãŒã¯ãRustyBuerãFormbookãAve Mariaãªã©ã®ãã«ãŠã§ã¢ããCOVID-19é¢é£ã®ãã£ã³ããŒã³ã倧éã«çºçããŠããããšã確èª
æŠèŠ
2021å¹Žã®æ¥ããåå€ã«ãããŠCOVID-19ãããŒãã«ããæ»æãã£ã³ããŒã³ã¯æ°ãå°ãªããªã£ãŠããŸããããDeltaæ ªã®æææ¡å€§ã«å¯Ÿããæžå¿µãé«ãŸãäžãCOVID-19ãããŒãã«ãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®å€§èŠæš¡ãªéã®æ»æãã£ã³ããŒã³ãåéããŠããŸãã
æ»æãã£ã³ããŒã³ã®è©³çް
ãã«ãŒããã€ã³ãã¯ãCOVID-19ããã³æ°åã³ãããŠã€ã«ã¹ã«é¢é£ããããŒããæŽ»çšããç¶ç¶çãªè åšãããã³ãããã¯ã®çºçåœåãã远跡ããŠããŸããEmotetãé åžããããšã§ç¥ãããTA452ã¯ã2020幎1æã«åããŠCOVID-19ãEã¡ãŒã«ã®è åšã§äœ¿çšãå§ããŸããããã®æ°åã³ãããŠã€ã«ã¹ã¯æ»æãã£ã³ããŒã³ã§ç¶ç¶çã«äœ¿ãããããŒãã§ããããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãããæ°ã«æã§COVID-19ã®ããŒããæŽ»çšããã¡ãã»ãŒãžã®æ°ãå€§å¹ ã«å¢å ããŠããããšã確èªããŸããã
2021幎6æäžæ¬ä»¥éããã«ãŒããã€ã³ãã¯RustyBuerãFormbookãAve Mariaãšãã£ããã«ãŠã§ã¢ãé åžããCOVID-19ãããŒãã«ããæ»æãã£ã³ããŒã³ã倧éã«èŠ³æž¬ããŠãããããã«MicrosoftãO365ã®èªèšŒæ å ±ãçã¿åºãããšããè€æ°ã®äŒæ¥åãã®ãã£ãã·ã³ã°æ»æã確èªããŠããŸãããŸãããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ããã®æéã«COVID-19ããŒããæŽ»çšããããžãã¹ã¡ãŒã«è©æ¬º(BEC)ã®è åšãå¢å ããŠããããšã確èªããŸããã
ãã«ãŒããã€ã³ãã®è§£æããŒã¿ã«ãããŠCOVID-19ãããŒããšããè åšã®å¢å ã¯ãææåã®åŒ·ãæ°åã³ãããŠã€ã«ã¹ã®ãã«ã¿æ ªãžã®äžè¬ã®äººã ã®é¢å¿ãšäžèŽããŠããŸããGoogleãã¬ã³ãããŒã¿ã«ãããšããDelta variant(ãã«ã¿æ ª)ãã®äžççãªæ€çŽ¢æ°ã¯2021幎6æã®æçµé±ã«åããŠããŒã¯ã«éããæ¬ããã°ãå·çããŠããæç¹ã®2021幎8æãŸã§ç¶ããŠããŸãã

å³ 1. "Delta Variant (ãã«ã¿æ ª)"ã«é¢é£ããæ€çŽ¢ã®Google ãã¬ã³ãããŒã¿
COVID-19é¢é£ã®è åšã¯ãäžçå šäœã§å¢å ããŠããŸãããã«ãŒããã€ã³ãã§ã¯ãäžçäžã®ããŸããŸãªæ¥çš®ã®ã客æ§ã察象ãšããæ°äžéã®ã¡ãã»ãŒãžã芳枬ããŸããããŸãããªãŒãã³ãœãŒã¹ã®ããŒã¿ã«ãããšãæè¿ãæ»æè ãCOVID-19ã®ããŒããããå€ãæ¡çšããŠããããšãåãã£ãŠããŸããäŸãã°ãéåœã§ã¯ãCOVID-19ã«ããææžããã°ã©ã ã«é¢é£ããããŒãã®è åšãå¢å ããããšãåããŠãæè¿ããµã€ããŒè åšã®èŠåã¬ãã«ãåŒãäžããŸããã
ãã³ãããã¯ã®æéäžãæ»æè ã¯ãããããå°åã®ã³ãã¥ããã£ãæããŠããææãäžå®ãå©çšããŠãããæ°åã³ãããŠã€ã«ã¹ã¯ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æŽ»åããããªãã«ããã£ãŠãæ Œå¥œã®ããšãããŒããšãªããŸãããã¯ã¯ãã³ãå ¥æã§ããããã«ãªããšãæ»æè ã¯ã¯ã¯ãã³ã®æ¥çš®ç¶æ³ã«é¢é£ããããŒãã䜿çšããããã«ãªããŸããããŸããæ°åã³ãããŠã€ã«ã¹ã®ããŒããããã³ãããã¯ã«ããçµæžçæ¯æŽãå»çæ å ±ãè£ ã£ãã¡ãã»ãŒãžãšçµã¿åãããããšããããŸããããã®åŸåã¯ããã«ã¿æ ªãåºãŸããäŒæ¥ãåŸæ¥å¡ã®è·å ŽåŸ©åž°åã«ã¯ã¯ãã³æ¥çš®ãæ¡ä»¶ããããã«ãªã£ãä»ãç¶ããŠããŸãã
èªèšŒæ å ±ã®çªå
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãäžçäžã®äœåãã®çµç¹ã察象ãšããMicrosoftã®èªèšŒæ å ±ãçªåããæ»æãã£ã³ããŒã³ãå«ããæ°åã³ãããŠã€ã«ã¹ã«é¢é£ããè€æ°ã®å€§èŠæš¡ãªèªèšŒæ å ±çªå(ã¯ã¬ãã³ã·ã£ã«ã»ãã£ãã·ã³ã°)ãã£ã³ããŒã³ã確èªããŠããŸãããããã®ã¡ãã»ãŒãžã¯ã察象çµç¹ã®äººäºéšéããéãããã¯ã¯ãã³æ¥çš®ã®èªå·±ç³åå ±åæžãè£ ã£ãŠããŸããã
ãã®åœã®Eã¡ãŒã«ã«ã¯ãäŸãã°ä»¥äžã®ãããªç¹åŸŽããããŸãã:
From: "HR@[organizationname.tld]" <various senders>
Subject: Covid-19 Vaccination Self Compliance Report. (æ°åã³ããã¯ã¯ãã³æ¥çš® ã»ã«ãã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒã)
ãã®ã¡ãã»ãŒãžã«ã¯ããŠãŒã¶ãŒã®èªèšŒæ å ±ãååŸããããã®åœã®MicrosoftèªèšŒããŒãžã«ã€ãªããå¯èœæ§ã®é«ãURLãå«ãŸããŠããŸããã

å³ 2. æ°åã³ãããŠã€ã«ã¹ã®ã¯ã¯ãã³æ¥çš®ã®èªå·±ç³åæžãè£ ã£ããã¡ã€ã«ãžã®ãªã³ã¯ãå«ãåœã¡ãŒã«
æè¿ã§ã¯ãã¢ã¡ãªã«ã®å€§æäŒæ¥ã®å€ããããªãã£ã¹ã«æ»ãåã«åŸæ¥å¡ã«ã¯ã¯ãã³æ¥çš®ã矩åä»ããããã«ãªããŸãããã¯ã¯ãã³æ¥çš®ã®çŸ©ååãéçšè ã®éã§åºãŸãã«ã€ãããã®ãããªããšãã®ããŒããæ»æè ã«ããã«å©çšãããããã«ãªããšèããããŸãã
åŸæ¥å¡ã®ã¹ããŒã¿ã¹
ãŸããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãäººäºæ åœè ãè£ ã£ãŠæ°çŸã®çµç¹ã«éãããæ°ãã倧éã®Formbookæ»æãã£ã³ããŒã³ã芳枬ããŸããããã®ã¡ãŒã«ã«ã¯zipãã¡ã€ã«ïŒäŸïŒScan.Salary.zipïŒãå«ãŸããŠãããåä¿¡è ã«æ°åã³ãããŠã€ã«ã¹ã«ããäŒæ¥è²¡æ¿ãžã®åœ±é¿ã«ããè·ã倱ãããšã«ãªããšäŒããŠããŸãã

å³ 3.çµç¹ã®äººäºéšãè£ ã£ãŠéä¿¡ãããã¡ãŒã«
ãã®ã¡ãŒã«ã¯äžè¬çãªãã®ã§ãããçã£ãçµç¹ã«åãããŠã«ã¹ã¿ãã€ãºãããŠããŸããåä¿¡è ã«æªæã®ãããã¡ã€ã«ãéãããããã«ãã¡ãŒã«ã«ã¯ã2ã¶æåã®çµŠäžã®é åæžããæ·»ä»ãããŠãããšèšèŒãããŠããŸãããã®ã¡ãŒã«ã«ã¯æªæã®ãã.ZIP圢åŒã®æ·»ä»ãã¡ã€ã«ãå«ãŸããŠããããããè§£åã»å®è¡ãããšFormbookãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ãããŸãããã®æ»æãã£ã³ããŒã³ã¯ãå¹ åºãçµç¹ã察象ã«7,000é以äžã®ã¡ãŒã«ã§æ§æãããŠããŸããã
Ave Maria
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãäž»ã«ãšãã«ã®ãŒé¢é£äŒæ¥ãå·¥æ¥é¢é£äŒæ¥ãæšçãšããæ°ãã Ave Maria ãã«ãŠã§ã¢ãã£ã³ããŒã³ã確èªããŸãããAve Mariaã¯ãC++ã§èšè¿°ããããªã¢ãŒãã¢ã¯ã»ã¹åã®ããã€ã®æšéЬã§ãããã»ã¹ããã¡ã€ã«ã·ã¹ãã ã®æäœãã³ãã³ãã·ã§ã«ãžã®ã¢ã¯ã»ã¹ããŠã§ãã«ã¡ã©ã®å¶åŸ¡ãããŒãã®ã³ã°ããã¹ã¯ãŒãã®çªåããªã¢ãŒããã¹ã¯ããããžã®ã¢ã¯ã»ã¹ãªã©ã®æ©èœãåããŠããŸããæåã«èŠ³æž¬ãããäžé£ã®Eã¡ãŒã«ã¯ãCOVID-19ã«é¢é£ããå¥åº·ãžã®ã¢ããã€ã¹ãè£ ããå¯Ÿè±¡äŒæ¥ã®ããªã·ãŒã«é¢é£ãããäºé²çããèšèŒãããŠãããšããŠããŸãã1,000é以äžã®ã¡ãŒã«ãæ°å人ã®é¡§å®¢ãã¿ãŒã²ããã«ããŠãããæšçã®90%以äžããšãã«ã®ãŒé¢é£äŒæ¥ã§ããããã®åŸã®é¢é£ãã£ã³ããŒã³ã§ã¯ãCOVID-19ãšã¯é¢ä¿ã®ãªãããŒãã䜿ãããŸããã
ãŠã€ã«ã¹é¢é£ã®ã¡ãã»ãŒãžã¯ãäŸãã°ã次ã®ãããªãã®ã§ãã:â¯
From: HEALTH CARES <admin@ledfarm[.]store>â¯
Subject: COVID-19 PREVENTIVE MEASURES⯠(æ°åã³ãããŠã€ã«ã¹äºé²ç)
Attachments: covid-19_preventive measures.xlsxâ¯
ãŸãã¡ãŒã«ã®æ¬æã«ã¯ã healthcare@[æšçãšãããäŒæ¥ã®ãã¡ã€ã³].com ãªã©ãå¯Ÿè±¡äŒæ¥ã«åºæã®ã¡ãŒã«ãå«ãŸããŠããŸãããã¡ãŒã«ã®å 容ã¯ãæ·»ä»ãã¡ã€ã«ã«å«ãŸããæ°ããæ°åã³ãããŠã€ã«ã¹ãžã®äºé²çã«ã€ããŠã®ãã®ã§ãããããã«ãã¡ãŒã«ã«ã¯æ°åã³ãããŠã€ã«ã¹ã®çäŸãæ»äº¡äŸãæäžãããã¯ã¯ãã³ã®éãèšèŒãããŠããŸããã
â¯
å³ 4. Email purporting to be related to COVID-19 measures. æ°åã³ãããŠã€ã«ã¹å¯ŸçãããšãããŒãã«ããæ»æã¡ãŒã«
ãã®ç¿é±ããã«ãŒããã€ã³ãã¯ãæ°åã³ãããŠã€ã«ã¹ãããŒãã«ããã¡ãã»ãŒãžãé ä¿¡ããAve Mariaãã«ãŠã§ã¢ã®æ»æãã£ã³ããŒã³ã芳枬ããŸãã:
From: customercareservicesY
Subject: COVID-19 SELF SERVICE CERTIFICATE/PREVENTIVE MEASURES (æ°åã³ãããŠã€ã«ã¹ã®å¯Ÿããèªå·±èšŒææž/äºé²æªçœ®)
芳枬ãããæ°åã³ãããŠã€ã«ã¹ãããŒãã«ããAve Mariaæ»æãã£ã³ããŒã³ã®ã¡ãã»ãŒãžã«ã¯ãMicrosoftã®æ°åŒãšãã£ã¿â(Equation Editor)ã®æ§ã ãªè匱æ§ãæªçšããExcelã®æ·»ä»ãã¡ã€ã«ãå«ãŸããŠããŸããããã®ãã«ãŠã§ã¢ã®ã³ãã³ãïŒã³ã³ãããŒã«ã€ã³ãã©ã¯ããã€ãããã¯DNSãšããŒã5200ã®éä¿¡ãå©çšããŠããŸããã
RustyBuer
çŸåšãæã掻çºãªæ°åã³ãããŠã€ã«ã¹é¢é£ã®è åšã®1ã€ã¯ã2021幎4æã«ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒãåããŠç¢ºèªããRustããŒã¹ã®Buer Loaderã®æ°çš®ã§ãããRustyBuerãã§ããBuerâ¯ã¯ã䟵害ããããããã¯ãŒã¯ã®è¶³ããããæ§ç¯ããããã«äœ¿ããããã€ã©ã³ãµã ãŠã§ã¢ãå«ãä»ã®äºæ¬¡ãã€ããŒããé åžããããã®ãåæã¢ã¯ã»ã¹ãããŒã«ãŒããšããŠäœ¿çšãããããŠã³ããŒããŒã§ãã
ãã³ãããã¯ã®ããŒããå©çšããæè¿ã®ãã£ã³ããŒã³ã«ã¯ãå»çé¢ä¿è ãè£ ã£ãŠéä¿¡ãããã®ããããã¯ã¯ãã³ã®çŸ©ååãå ¬å¹³ãªå»çæ©äŒãçŸåšã®ææçãªã©ãããŒãã«ããŠããŸãããããŸã§BuerãRustyBuerãå©çšããæ»æè ã¯ãæ°åã³ãããŠã€ã«ã¹ã®ããŒãã䜿çšããŠããŸããã§ããããæè¿ã¯å©çšããããã«ãªã£ãŠããŸãã
æè¿èгå¯ãããæ»æãã£ã³ããŒã³ã§ã¯ã以äžã®ãããªéä¿¡è ãè£ ã£ãã¡ãã»ãŒãžããããŸãã:
info@covidhospitalgeer[.]com
info@covidadministration[.]com
ã¡ãŒã«ã®ä»¶åã«ã¯ä»¥äžã®ãããªæç« ãå«ãŸããŠããŸã:
COVID-19 infections at higher than Covid and rubbed his restaurants and
COVID-19 vaccinations for its mask mandate for the ongoing disaster which
芳枬ãããã¡ãã»ãŒãžã«ã¯ããã¹ã¯ãŒãã§ä¿è·ãããzip圢åŒã®Microsoft Excelã®æ·»ä»ãã¡ã€ã«ãå«ãŸããŠããããããæå¹ã«ãããšRustyBuerãããŠã³ããŒãããŠå®è¡ãããã¯ããå«ãŸããŠããŸãããã®ã¡ãã»ãŒãžã¯ãå ¬çææžãæš¡å£ãããã®ã§ã¯ãªãããã°ãã°ææ³çã«æå³ããªããããã¥ãŒã¹å ±éã®æçãå«ãã§ããããã«ãèŠããŸãããããã䜿çšãããŠããèšèãç»åã¯ãåä¿¡è ã«ç·æ¥æ§ã瀺åããŠãããæ·»ä»ãã¡ã€ã«ãã¯ãªãã¯ããããã«ä»åããŠããå¯èœæ§ããããŸãã

å³5. æ°åã³ãããŠã€ã«ã¹ãããŒãã«ããããšãææž(ã«ã¢ãŒ)ãé åžããRustyBuerã®ã¡ãŒã«
çµæ
ãããæ°åã³ãããŠã€ã«ã¹ã®ãã«ã¿æ ªã®æ·±å»åºŠãå¢ããšãäžçäžã§ã¡ãã£ã¢ã«åãäžããããæ©äŒãå¢ããããšãäºæ³ãããŸããéå»ã®äºäŸãããã¡ãã£ã¢ã®æ³šç®åºŠãé«ãŸãã°ããœãŒã·ã£ã«ã»ãšã³ãžãã¢ãªã³ã°ã®çŽ æãšããŠæ°åã³ãããŠã€ã«ã¹ãæ»æã®ããšãããŒããšããŠåºãæ¡çšããåŸåã«ããããã®ããŒããããããã®å°åå¥ç¹åŸŽã«åãããŠæªçšããå¯èœæ§ãé«ãŸããŸãããŸããææçãé«ãããŠã€ã«ã¹ãé²åŸ¡çãžã®é¢å¿ãé«ããã¡ã«ãä»åŸã®æ»æãã£ã³ããŒã³ã§å©çšãå§ããæ»æè ãå¢ããå¯èœæ§ããããŸãã
以äžã¯ãæè¿ã®æ°åã³ãããŠã€ã«ã¹ãããŒãã«æªçšããè åšIoC(䟵害ã®çè·¡)ã®äžäŸã§ãã
|
Indicator |
Description |
|
http://sweetdreambymoon[.]stars[.]bz/a2/p3.exe⯠|
Ave Maria / Warzoneâ¯Payload URL⯠|
|
a2ba3e1a002cd3c7d5be4ff05d6001692a1a516096159ac77b78f0ddd9c3060e⯠|
Payloadâ¯SHA256⯠|
|
warzonlogs[.]duckdns[.]org⯠|
Ave Maria / Warzone C2⯠|
|
admin@ledfarm[.]store⯠|
Ave Maria Sender Email⯠|
|
contact@wmbtole-com[.]uno⯠|
Ave Maria Sender Email⯠|
|
contact@yumaletab-net[.]uno⯠|
Ave Maria Sender Email⯠|
|
â¯info@taxpunishdep[.]com |
RustyBuer Sender Email |
|
info@loveshipper[.]com |
RustyBuer Sender Email |
|
https://luareraopy[.]com/api/v3/dacryorrhea/cardholders/nympholepsies
|
RustyBuer Document Payload |
|
cerionetya[.]com |
RustyBuer C2 |
|
88689636f4b2287701b63f42c12e7e2387bf4c3ecc45eeb8a61ea707126bad9b
|
RustyBuer Hash (Sample) |
|
info@deliverydhlexpress[.]com |
RustyBuer Sender Email |
|
info@deliveryeatstreet[.]com |
RustyBuer Sender Email |
|
https://seryanjek[.]com/api/v3/disambiguate/nonequivalent/ditrigonal |
RustyBuer Document Payload |
|
e3a11be133a98c05ab7aa90f7ca8037cfdad66b0159b5522a85dab5d54f6eb71 |
RustyBuer Hash (Sample) |
|
info@covidhospitalgeer[.]com |
RustyBuer Sender Email |
|
info@covidadministration[.]com |
RustyBuer Sender Email |
|
info@covidbooksinfo[.]com |
RustyBuer Sender Email |
|
info@discountfreeals[.]com |
RustyBuer Sender Email |
|
lebatyo[.]com |
RustyBuer C2 |
|
https://hejoysa[.]com/ssl/v1/getkey |
RustyBuer Excel Payload |
|
eurolord.duckdns[.]org |
Ave Maria C2 |
|
6b4a4244409dc7dd0e538b98fbb886b51d626202bdc8501af5c9c4e84daecd82 |
Ave Maria Hash (Sample) |
|
http://sassyladywrites[.]com/a1/b7[.]exe |
Ave Maria Payload URL |
|
https://00f74ba44bd85135df3aa07960343eeeec89e0088b-apidata[.]googleusercontent[.]com/download/storage/v1/b/dhngw6p6rwrwnuv6vnuse.appspot.com/o/index.html |
Microsoft Credential Theft Phishing Landing Page |
|
https://storage[.]cloud[.]google[.]com/dhngw6p6rwrwnuv6vnuse.appspot.com/index.html#username@organizationname.tld |
Microsoft Credential Theft Phishing URL |
|
24cf6db04d0882f124750e4b7025455d11b02f23ad088a334e449a82d672e64a |
Formbook Hash (Scan.Salary.zip) |
|
www.aozhengaodi[.]com/bkbk/ |
Formbook C2 |