äž»ãªèª¿æ»çµæ
- Proofpoint瀟ã¯ããªãµãŒãã£ãŒããDTPackerããšåä»ãããã«ãŠã§ã¢ããã«ãŒã確èªããŸããã
- ãã€ããŒãã®ãã³ãŒãã«ã¯ãããã«ãã»ãã©ã³ãå 米倧統é ã®ååãå«ãåºå®ãã¹ã¯ãŒãã䜿çšãããŠããŸãã
- æ°é±éã«ãããããã®ããŠã³ããŒããŒã®äºçš®ã¯ãLiverpool Football ClubãããŒãã«ããããŠã³ããŒãå ã䜿çšããŠããŸããã
- ãã®ãã«ãŠã§ã¢ã¯ãéåžžãæ å ±ãçãã ããã©ã³ãµã ãŠã§ã¢ãªã©ã®åŸç¶ã®ãã€ããŒããããŒãããããã®ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬãããã¯ããããã«äœ¿çšãããŸãã
æŠèŠ
ããã°ãCommodity .NET Packers use Embedded Images to Hide Payloadsãã§ã¯ã.NETããã«ãŒã®ãCyaXãããã³ãHectobmpããã¡ããªãŒã«ã€ããŠèª¬æããŸããã
ãã®ããã°ã§ã¯ã2段éã®ã³ã¢ãã£ãã£.NETããã«ãŒãŸãã¯ããŠã³ããŒããŒã«ã€ããŠèª¬æããŸãããã®ããã«ãŒãŸãã¯ããŠã³ããŒããŒã¯ã第1段éã§ã¯ããªã倿§æ§ããããã®ã®ã第2段éã§ã¯ãã³ãŒãã®äžéšãšããŠåºå®ãã¹ã¯ãŒãã䜿çšããŸããããã«ãŒãšããŠã³ããŒããŒã®äž»ãªéãã¯ãåè ã§ã¯åã蟌ãŸããåŸè ã§ã¯ããŠã³ããŒãããããã€ããŒãããŒã¿ã®å Žæã§ããDTPackerã¯äž¡æ¹ã®åœ¢æ ã䜿çšããŠããŸãã1ã€ã®ãã«ãŠã§ã¢ãããã«ãŒãšããŠã³ããŒããŒã®äž¡æ¹ãå Œããããšã¯çããããšã§ãã
Proofpointã§ã¯ãDTPackerãAgent TeslaãAve MariaãAsyncRATãFormBookãªã©ã®è€æ°ã®ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒãæ å ±çªåãã«ãŠã§ã¢ãé åžããŠããã®ã確èªããŠããŸãããã®ãã«ãŠã§ã¢ã¯ãè€æ°ã®é£èªåæè¡ãçšããŠãã¢ã³ããŠã€ã«ã¹ããµã³ãããã¯ã¹ãããã³åæãåé¿ããŸãããã®ãã«ãŠã§ã¢ã¯ãããããã¢ã³ããŒã°ã©ãŠã³ãã®ãã©ãŒã©ã ã§é åžãããŠããŸãããã«ãŒããã€ã³ãã¯ã2020幎以éãTA2536ãTA2715ãå«ãæ°åã®ãã£ã³ããŒã³ãè€æ°ã®è åšã¢ã¯ã¿ãŒãšDTPackerãé¢é£ããŠããããšã確èªããŠããŸãããã«ãŒããã€ã³ãã¯ãDTPackerãé«åºŠæšçåæ»æã°ã«ãŒãïŒAPTïŒãšãµã€ããŒç¯çœªã®äž¡æ¹ã®æ»æã°ã«ãŒãã«ãã£ãŠäœ¿çšãããŠããããšã確èªããŠããŸãã確èªããããã£ã³ããŒã³ã«ã¯æ°åã®ã¡ãã»ãŒãžãå«ãŸããè€æ°ã®æ¥çã®æ°çŸã®é¡§å®¢ã«åœ±é¿ãäžããŸããã
æ»æçµè·¯ã®äŸ
芳枬ãããå€ãã®ãã£ã³ããŒã³ã§ã¯ãåæã®ææçµè·¯ãšããŠé»åã¡ãŒã«ã䜿çšãããŠããŸããæ·»ä»ãã¡ã€ã«ã¯éåžžãæªæã®ããææžãå§çž®ãããå®è¡ãã¡ã€ã«ã§ããŠãŒã¶ãŒããããæäœãããšãããã«ãŒã®å®è¡ãã¡ã€ã«ãããŠã³ããŒããããŸãããã®ãã«ãŠã§ã¢ã¯ãåã蟌ãŸããããŸãã¯ããŠã³ããŒãããããªãœãŒã¹ãããã«ãŠã§ã¢ã®ãã€ããŒããå«ãDLLã«ãã³ãŒããããã«ãŠã§ã¢ãå®è¡ããŸãã
å³1ïŒDTPackerã®æ»æçµè·¯ã®äŸ
ã«ã¹ã¿ã XORãã³ãŒãã£ã³ã°
Proofpointã¯ãè€æ°ã®åŸ©å·æ¹æ³ãšãããã«ãã»ãã©ã³ããããŒãã«ãã2ã€ã®åºå®éµã芳枬ããããšããããDT "Packer"ããšåä»ããŸãããå€ãã®ããã«ãŒãããŒããŒã¯ã2段éã®æ©èœã§äœãããŠããŸããDTPackerã®åæã®ããŒãžã§ã³ã§ã¯ãã«ã¹ã¿ã ã®XORã«ãŒãã³ã䜿çšããŠãäž¡æ¹ã®ã¹ããŒãžã§æªæã®ããã³ã³ãã³ãããã³ãŒãããŠããŸãããDTPackerã®ç¬¬1ã¹ããŒãžã§ã¯ãåã蟌ã¿ãŸãã¯ããŠã³ããŒãããããªãœãŒã¹ãäžéã¹ããŒãž(éåžžã¯DLL)ã«ãã³ãŒããã第2ã¹ããŒãžã§ã¯ãã®DLLãããã€ããŒããæœåºããŠå®è¡ããŸãã
ã«ã¹ã¿ã XORã«ãŒãã³ã¯ãããŒãšã®XORã«å ããŠã次ã®ããŒã¿å€ãæžç®ãããã®ã§ããã®Pythonã¹ã¯ãªããïŒGithubäžïŒdecoder-xor-sub.pyã§å®è£ ãããŠããŸãã
Windows Portable Executableã®å Žåãããªãã®æ°ã®ãã«ãã€ããååšãããããæå·æã1ãã€ãã·ãããããã®ãšXORãããšããã«ãã€ãã«å¯Ÿå¿ããäœçœ®ã«éµãããããšãããããŸãã
äŸãã°ããã®ãµã³ãã« (SHA256: 512b2f1f4b659930900abcc8f51d175e88c81b0641b7450a6618b77848fa3b40)ã§ã¯ãäžéã¹ããŒãžã¯ãã«ã¹ã¿ã XORã«ãŒãã³ãšã㌠"P"ïŒä»åã¯Unicode UTF-16ã§ã¯ãªãASCIIïŒã§ãšã³ã³ãŒãããã.NETãªãœãŒã¹ã«æ ŒçŽãããŠããŸãã

.NETãªãœãŒã¹ã1ãã€ãã·ããããèªåèªèº«ãšXORãããšããã¹ã¯ãŒã "P "ã衚瀺ãããŸã:

ã㌠"P "ã§ãã³ãŒããããšã第2段ã®å®è¡ãã¡ã€ã«ãåŸãããŸã:

2段ç®ã«ã¯ã.NETãªãœãŒã¹ïŒååã¯ã00112266ãïŒãå ¥ã£ãŠããŸã:

èªåèªèº«ã1ãã€ãã·ãããããã®ãšXORãããšä»¥äžãšãªããUnicode UTF-16ã® "trump2020 "ãšããéµãåŸãããŸã:

è åšã®äž»äœã¯ããã®éµã1幎éäžè²«ããŠäœ¿çšããŠããããããããã«ãŒã®ååã®çç±ã§ãã
ãtrump2020ãã®éµã§ãã³ãŒããããšãæçµçãªãã€ããŒããåŸãããŸã:

ãã®ã±ãŒã¹ã§ã¯ããã€ããŒãã¯ãäžè¬çãªæ å ±çªåãã«ãŠã§ã¢ã§ããAgent Teslaã§ããã
å€åœ©ãªãã¡ãŒã¹ãã¹ããŒãžã»ãšã³ã³ãŒãã£ã³ã°
ãã®ããŠã³ããŒããŒã®ãµã³ãã« (SHA256: 9d713d2254e529286ed3ac471e134169d2c7279b0eaf82eb9923cd46954d5d27)ã§ã¯ãããŠã³ããŒãURLã¯ãžã£ã³ã¯ãªUnicodeæåã§é£èªåãããæååãšããŠä¿åãããŠããŸãã
ãã®å Žåãåè§£ãããã³ãŒãã¯æ¬¡ã®ããã«ãªããŸãã

Unicodeæåãåé€ãããšä»¥äžã«ãªããŸã:
![]()
ããŠã³ããŒãã¯äžç·ã«ãããŠãããBase64ãšã³ã³ãŒããããæååãå«ãŸããŠããŸã:

ãããã¯ä»¥äžã®ããã«ãã³ãŒããã

ãã€ã0x02ãšXORããåŸã次ã®ããã«ãªããŸã:

ããã¯ãå ã»ã©ãšåæ§ã«ãtrump2020ãããŒã§ãšã³ã³ãŒããããã00112266ããªãœãŒã¹ãå«ã第2段ã®å®è¡ãã¡ã€ã«ã§ãããããã³ãŒããããšAgent Teslaã«ãªããŸãã
10鲿åã³ãŒã
ãã®çš®ã®ããã«ãŒã«å ±éããŠèŠãããããŒãã¯ãæ°åãä»ã®æåã§çœ®ãæãã10鲿³ã®æåã³ãŒãã䜿çšããŠããããšã§ãã
äŸãã°ããã®ãµã³ãã« (SHA256: 285f4e79ae946ef179e45319caf11bf0c1cdaa376924b83bfbf82ed39361911b)ã¯ã第2段éã.NET StringsããŒãã«ã«åã蟌ãã ããã«ãŒã§ã:

ããã¯ãã³ã³ãã§åºåããã10鲿°ã®ASCIIæåã³ãŒãã§ãæ°åã®0ã9㯠"!@#$%[X]&*()" ã«çœ®ãæããããŠããŸã:

ããã¯ãéµããtrump2020ãã®ã00112266ããªãœãŒã¹ãå«ãäžéPEã«ãã³ãŒããããAve MariaïŒWarzone RATãšããŠãç¥ãããŠããïŒã«ãã³ãŒããããŸãã
ãã®ãµã³ãã« (SHA256: 1312912d725d45bcd1b63922ec9a84abca7a8c9c669c13efbd03472c764be056 )ã¯äžèšãšäŒŒãŠããŸããã2段ç®ãUser StringsããŒãã«ã«æ ŒçŽãããŠããŸã:

ããã¯æ°åã®0ïœ9ã "zxcasdwqru"ïŒQWERTYããŒããŒãã®åã®æåã®3æåãšéšåçã«äžèŽïŒã«çœ®ãæããããAsyncRATã«ãã³ãŒããããŸãã
ä»ã®ãµã³ãã« (SHA256: ba0f9be7cf006404bcfab6b6adbad0cef7281c3792490903632a4010d8a74f42) ã¯ãããŠã³ããŒãæååãSample 1ãšåæ§ã®æ¹æ³ã§é£èªåãããããŒããŒã§ãé£èªåãè§£é€ãããšïŒdefangedïŒã«ãªããŸãã
hxxps://ahgwqrq[.]xyz/getrandombase64.php?get=E2E813E9694BE43CAD964C0453632F91@@@hxxps://ahgwqrq[.]xyz/getrandombase64.php?get=63DC49E5D8F5F50F8838551347009928@@@hxxps://ahgwqrq[.]xyz/getrandombase64.php?get=D13B96F0619AC39B44A32D3E0A260C89@@@hxxps://ahgwqrq[.]xyz/getrandombase64.php?get=85530E49BB23CD9DBD8461A2FC5D18A2
ããŠã³ããŒãã¯ããµã³ãã«3ããã³4ãšåæ§ã®æ¹æ³ã§é£èªåãããŠããã0ïœ9ã®æ°åãAïœJã®æåã«çœ®ãæããããŠããŸã:

ããŠã³ããŒãã¯éåžžã®ã»ã«ã³ãã¹ããŒãžã«ãã³ãŒããããããã«Agent Tesla.ã«ãã³ãŒããããŸãã
倧æåã³ãŒããªãã»ããã«ããæååé£èªå
ãã®ãµã³ãã«(SHA256 5d555eddfc23183dd821432fd2a4a04a543c8c1907b636440eb6e7d21829576c) ã¯é£èªåãããUnicodeæååã«ãã®æåã³ãŒãããå·®ãåŒãæŽæ°ãä»å ããããŒãã§ãã

ããã¯ä»¥äžã«ãã³ãŒããããŸã:

ããŠã³ããŒãã¯åã³ASCIIã®æåã³ãŒãã§ã0ïœ9ã®æ°åã"PxfnVCKsAi"ã®æåã«çœ®ãæããããŠããŸãã
ãããä»åã¯ãã«ã¹ã¿ã XORã«ãŒãã³ãš "trump2020 "ããŒã«ããäžéã¹ãããããªãããã€ããŒãã¯Agent Teslaã§ããã
ãµãã«ãŒã¯ã©ããããŒãã«ãããã€ããŒãæ ŒçŽå Žæ
2021幎3æä»¥éããã«ãŒããã€ã³ãã¯ããµãã«ãŒã¯ã©ãããã®ãã¡ã³ã®ããã®ãŠã§ããµã€ããããŠã³ããŒãå ãšããŠäœ¿çšãããµã³ãã«ã芳枬ããŸããããããã®Webãµã€ãã¯ããšãã§ãå®éã®ãã€ããŒãã®å Žæã¯ãªã¹ãã«åã蟌ãŸããŠããããã§ãã
äŸãã°ããã®ãµã³ãã« (SHA256 b53558a85b8bb10ce70cb0592a81e540683d459b9d8666b7927c105f1141a189)ã§ã¯ãåè§£ãããã³ãŒãã¯æ¬¡ã®ããã«ãªããŸã:

ããã¯é£èªåããããšä»¥äžã«ãªããŸã:

ãã®ãã€ããŒãã¯ããã®å ŽåãSnake Keyloggerã§ããã
ãã®åŸã®ãµã³ãã«ã§ã¯ããªãããŒã«ã»ãããããŒã«ã»ã¯ã©ããããŒãã«ããããŠã³ããŒãå ã䜿çšãããŠããŸãã
ãã®ãµã³ãã«ã§ã¯ (SHA256: 9cc817f0205da4bde1d938e1817aa98fe4f4a5dcbcaffbe8b45041e24c105aa0)ãããŠã³ããŒãå ã¯ãžã£ã³ã¯ãªUnicodeé åãæååã®çµã¿ç«ãŠã§é£èªåãããŠããŸãã

ããã¯ãéASCIIæåãåãé€ããåŸã¯ä»¥äžã®ããã«ãªããŸã:

ããã¯ä»¥äžã®ããŠã³ããŒãå Žæ (ç¡ååæž)ã«å°ãããŸãã:
hxxp://liverpoolofcfanclub[.]com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-1FE8F2E05D5035C0446552639B8336B8.html
hxxp://liverpoolofcfanclub[.]com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-EC7D4835EC6F56BD999A943FEDF8D489.html
hxxp://liverpoolofcfanclub[.]com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-DE7C2CE9F7D38544A851414C40C46A3F.html
ãã®äžã«ã¯ãliverpool.comããåŒçšãããšæãããããŒãžã®äžã«ã次ã®ã¹ããŒãžã0ã9ã®æ°åã"GIucvPNTOs"ã«çœ®ãæããASCIIæåã³ãŒãã§æ²èŒããŠããŸã:

æåŸã«ãéåžžã®ã00112266ããªãœãŒã¹ããtrump2020ãããŒã§ãšã³ã³ãŒããããæçµçãªãã€ããŒãã§ãããAgent Teslaããä¿æããŠããããšãããããŸãã
ãã®åŸã®ãµã³ãã«ã§ã¯ããã¡ã€ã³åãå€ããŠããŸããããã¹ã¯éåžžã«äŒŒéã£ãŠãããåãããã«äžèŠç¡å®³ãããªããŒãžã衚瀺ãããŠããŸãã

å³: DTPackerã¯ãæçµçãªãã€ããŒãã«ãªãããŒã«FCãããŒãã«ããããŠã³ããŒããµã€ãã䜿çš
ãããã®ãµã€ãã¯ãæ£èŠã®ãªãããŒã«FCããã³ãã¡ã³é¢é£ã®ãŠã§ããµã€ããè£
ã£ãŠããŸããã
é£èªåãããæåã³ãŒãé åãçšããæååé£èªå
ãã®ãµã³ãã« (SHA256: 281cdbf590c22cd684700dcde609d6be48ddf3e4d988d48e65d9c688ce76f7af) ã¯ãé£èªåããã.NETã³ãŒãã䜿çšããŠãéèŠãªæååãASCIIæåã³ãŒãã®é åãšããŠæ ŒçŽããŠããŸã:
[0] : qHWXhtvYuc
[1] : Append
[2] : hxxp://mmwrlridbhmibnr[.]ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-40505C0917C3E190B486745F4941F177.html
[3] : <meta name="keywords" content="([\w\d ]*)">
[4] : UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41
[5] : GetType
[6] : Assembly
[7] : ToArray
[8] : Load
[9] : EntryPoint
[10] : Invoke
[11] : LoginForm
URLã®æååã«ã€ããŠã¯ãïŒILSPYã§åè§£ãããšïŒæ¬¡ã®ããã«ãªããŸã:

4ã€ã®å²ãåœãŠã®åãããã¯ã§ã¯ãæåã®3ã€ããžã£ã³ã¯ã«ãªããæ¬¡ã®ãã®ã§äžæžããããŸãã
ããã¯ãåºç€ãšãªãMSILïŒäžéèšèªïŒã³ãŒãã§è¡ãããŠããããã§ã:


é£èªåã®ããã®åœä»€ã¯ãå®éã«ã¯éåžžã®ã³ã³ãã€ã©ããæåŸ ããããããªæçã®åœ¢åŒã§ã¯ãããŸãããäŸãã°ã以äžã®ããã«æçµèª²é¡ãè¡ãèšåã®ãããªåœ¢åŒã§ãã
(05) 2000000000 : ldc.i4 0x0
ããã¯ä»¥äžãçšããŠéæã§ããã¯ãã§ãã
(01) 16 : ldc.i4.0
ãã®å Žåã®æçµçãªãã€ããŒãã¯Agent Teslaã§ããã
ãã®Pythonã¹ã¯ãªããïŒGithubäžïŒdecoder-dup-array-strings.pyã¯ããã®æè¡ã䜿ã£ãŠ.NETãã€ããªããé£èªåãããæååãåºåããŸãã
ã¹ãã¬ãŒãXORã«ãã "Trump2026 "ã®å€çš®
2021幎8æä»¥éããã«ãŒããã€ã³ã瀟ã¯ãã»ã«ã³ãã¹ããŒãžãã«ã¹ã¿ã XORã«ãŒãã³ãšåºå®ããŒãtrump2020ãã䜿çšããªããªãã代ããã«åºå®ASCIIããŒãTrump2026ããšã¹ãã¬ãŒãXORã䜿çšããŠãããµã³ãã«ã芳枬ããŸããã
ä»åã®ãµã³ãã« (SHA256: a564eb282800ed662b1c55ae65fbba86b6feca00a2e15ebb36a61fc53ac47c3a) ã§ã¯ãäžé段éãASCIIæåã³ãŒããšããŠãStringsãããŒãã«ã«æ ŒçŽããŠããŸã:

ãã€ããŒãã¯ãäžéã¹ããŒãžã®ãªãã»ãã 0x250 ããæ ŒçŽãããŸã:

ãããã㌠"Trump2026 "ãšã®XORåŠçãè¡ããšä»¥äžã«ãªããŸã:

ãã®ãã€ããŒãã¯Agent Teslaã§ããã
ãã®ãµã³ãã« (SHA256 affea9c276ded88eea1e39ac39fb19373c4b62d4251fb1d06f37a05e35dfa463)ã¯ãããŠã³ããŒãURLãUser StringsïŒdefangedïŒã§ã¯ãªã¢ã«ä¿åããããŠã³ããŒããŒã§ã(ç¡ååãããŠããŸã):
hxxps://cdn.discordapp[.]com/attachments/893177342426509335/897124528768032848/9722D04C.jpg
hxxps://cdn.discordapp[.]com/attachments/893177342426509335/897124531213336656/F526E587.jpg
ããŠã³ããŒãã¯ASCIIã®æåã³ãŒãã§ã:

ãããã€ãªãåãããŠãã³ãŒããããšã次ã®ãããªäžéã¹ããŒãžãåŸãããŸã:

XORããŒãTrump2026ãã§åŸ©å·ãããšãæçµçãªãã€ããŒãã¯FormBookã§ããã
åãä¿®æ£ãããXORã«ãŒãã³ã䜿çšããCyaX Packer
2021幎11æä»¥éããã«ãŒããã€ã³ã瀟ã¯ãCyaX-packerããtrump2020ãããŒã䜿çšããDTPackerãšéåžžã«ãã䌌ãã»ã«ã³ãã¹ããŒãžã䜿çšããŠããã®ã確èªããŸããã
ãããä»åã¯ãUTF-16ã§ãšã³ã³ãŒãããããtrump2020ãã§ã¯ãªããã©ã³ãã ã«çæããããASCIIãã¢ã«ãã¡ãããæ··åã8ïœ14æåã®éµã䜿çšããŠããŸãã
ãã®ãµã³ãã« (SHA256: 4053206d66d627d145d9da8d8e208d08c85755036a5393ccc6e8afd6117df864)ã§ã¯ãäžéã¹ããŒãžã«ã¯ã.NETãªãœãŒã¹ãã¡ã€ã«ã18Ocjj4dc4ããèµ·åããŠããŸã:
jCcPzKq+9JLar8eO2ILnqfrkj8Wj64Lqo7XsiMaV85jStPyV/bTiu9+RwqTPheOrwqrjteyIxpXzmNK0/BV9NGItKqrrjTJvPFOC ...
ãããããŒã¹64ã«ãã³ãŒããããšä»¥äžã®éããšãªããŸã:

ããã1ãã€ãã·ããããèªåèªèº«ãšXORãããšä»¥äžã®éããšãªããŸã:

éµãdNSfkJfHihIVYãã§ãã£ãã¯ã¹ããXORã«ãŒãã³ã䜿ããšä»¥äžã®éããšãªããŸã:

1ãã€ãç®ããã£ãã¯ã¹ããåŸãAgent TeslaãšãªããŸãã
ããã¯ããtrump2020ãããŒãžã§ã³ã®DTPackerãšææ°ã®CyaXã®ç¬¬2段éã®ãœãŒã¹ãå ±éããŠããããšã瀺åããŠããŸããDTPackerãšCyaXã®éã§ãªãœãŒã¹ãéè€ããŠããå¯èœæ§ããããŸããäŸãã°ãäž¡æ¹ã®äœè ãåãDLLãšã³ã³ãŒããè³Œå ¥ããŠããå¯èœæ§ããããŸãããProofpointã¯ããã確èªã§ããŸããã
çµè«
DTPackerã¯ãããã«ãŒãšããŠã³ããŒããŒã®äž¡æ¹ã«äœ¿çšãããé ä¿¡ãšé£èªåã®ããªãšãŒã·ã§ã³ãæã¡ãªãããè§£èªã®äžéšãšããŠãã®ãããª2ã€ã®ãŠããŒã¯ãªããŒãä¿æããŠããã®ã¯éåžžã«çããããšã§ãã
ãã«ãŠã§ã¢ã®äœè ãããã«ãŠã§ã¢ã®åºå®ãã¹ã¯ãŒãã«ããã«ãã»ãã©ã³ãæ°ãæèšããçç±ã¯äžæã§ããããã¯ãæ¿æ²»å®¶ãæ¿æ²»å£äœãç¹å¥ã«çãããã«äœ¿çšããããã®ã§ã¯ãªããæå³ãã被害è ãç®ã«ããããšã¯ãªãããã§ãããã«ãŒããã€ã³ãã§ã¯ããã®ãã«ãŠã§ã¢ã¯ä»åŸãè€æ°ã®æ»æã°ã«ãŒãã«ãã£ãŠäœ¿çšããããšè©äŸ¡ããŠããŸãã
ãããã¯ãŒã¯ IDS ã«ãŒã«:
Proofpoint Emerging Threatsã«ã¯ããã®ãã«ãŠã§ã¢ã«å¯Ÿããè€æ°ã®æ€ç¥ã«ãŒã«ããããŸãã
2031127 - ET MALWARE DTLoader Binary Request
2031128 - ET MALWARE DTLoader Encoded Binary - Server Response
2031129 - ET MALWARE DTLoader Domain (ahgwqrq .xyz in TLS SNI)
2033356 - ET MALWARE DTLoader Binary Request M2
2844913 - ETPRO MALWARE Haskell Downloader/DTLoader CnC Activity
2846706 - ETPRO MALWARE DTLoader Variant Activity
2847389 - ETPRO MALWARE DTLoader CnC Activity
2847503 - ETPRO MALWARE DTLoader Variant Activity
2847916 - ETPRO MALWARE DTLoader Obfuscated HTML Payload Inbound
2847940 - ETPRO MALWARE DTLoader Activity
2850461 - ETPRO MALWARE DTLoader Retrieving Encoded Payload
IoC(䟵害ã®çè·¡)ã®ãµã³ãã«
|
Indicator |
Description |
Associated Malware |
|
9d713d2254e529286ed3ac471e134169d2c7279b0eaf82eb9923cd46954d5d27 |
DTPacker SHA256 |
Agent Tesla |
|
hxxps://hastebin[.]com/raw/azipitojuj hxxps://hastebin[.]com/raw/urafehisiv |
Payload Download Location |
Agent Tesla |
|
285f4e79ae946ef179e45319caf11bf0c1cdaa376924b83bfbf82ed39361911b |
DTPacker SHA256 |
Ave Maria RAT |
|
512b2f1f4b659930900abcc8f51d175e88c81b0641b7450a6618b77848fa3b40 |
DTPacker SHA256 |
Agent Tesla |
|
1312912d725d45bcd1b63922ec9a84abca7a8c9c669c13efbd03472c764be056 |
DTPacker SHA256 |
AsyncRAT |
|
ba0f9be7cf006404bcfab6b6adbad0cef7281c3792490903632a4010d8a74f42 |
DTPacker SHA256 |
Agent Tesla |
|
hxxps://ahgwqrq[.]xyz/getrandombase64.php?get=E2E813E9694BE43CAD964C0453632F91
|
Payload Download Location |
Agent Tesla |
|
5d555eddfc23183dd821432fd2a4a04a543c8c1907b636440eb6e7d21829576c |
DTPacker SHA256 |
Agent Tesla |
|
hxxp://193.239.147[.]103/base/264712C97B662289D6644F926525A252.html |
Payload Download Location |
Agent Tesla |
|
b53558a85b8bb10ce70cb0592a81e540683d459b9d8666b7927c105f1141a189 |
DTPacker SHA256 |
Snake Keylogger |
|
hxxp://osndjdjjjdjshgaggdkf[.]com/base/377A23697621555ED2123D80005200D7.html hxxp://osndjdjjjdjshgaggdkf[.]com/base/650D6251494D3B160CBC93685F2FA1E4.html hxxp://osndjdjjjdjshgaggdkf[.]com/base/2A812C716BD7EB40F36227E584D97524.html |
Payload Download Location |
Snake Keylogger |
|
9cc817f0205da4bde1d938e1817aa98fe4f4a5dcbcaffbe8b45041e24c105aa0 |
DTPacker SHA256 |
Agent Tesla |
|
hxxp://liverpoolofcfanclub[.]com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-1FE8F2E05D5035C0446552639B8336B8.htm hxxp://liverpoolofcfanclub[.]com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-EC7D4835EC6F56BD999A943FEDF8D489.html hxxp://liverpoolofcfanclub[.]com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-DE7C2CE9F7D38544A851414C40C46A3F.html |
Payload Download Location |
Agent Tesla |
|
281cdbf590c22cd684700dcde609d6be48ddf3e4d988d48e65d9c688ce76f7af |
DTPacker SHA256 |
Agent Tesla |
|
hxxp://mmwrlridbhmibnr[.]ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-40505C0917C3E190B486745F4941F177.html
|
DTPacker Download URL |
Agent Tesla |
|
a564eb282800ed662b1c55ae65fbba86b6feca00a2e15ebb36a61fc53ac47c3a |
DTPacker SHA256 |
Agent Tesla |
|
affea9c276ded88eea1e39ac39fb19373c4b62d4251fb1d06f37a05e35dfa463 |
DTPacker SHA256 |
FormBook |
|
hxxps://cdn.discordapp[.]com/attachments/ hxxps://cdn.discordapp[.]com/attachments/ 893177342426509335/897124531213336656/F526E587.jpg
|
DTPacker Download URL |
FormBook |
|
4053206d66d627d145d9da8d8e208d08c85755036a5393ccc6e8afd6117df864 |
DTPacker SHA256 |
Agent Tesla |
â»æ¬ããã°ã®æ å ±ã¯ãè±èªã«ããåæãDTPacker â a .NET Packer with a Curious Passwordãã®ç¿»èš³ã§ããè±èªåæãšã®éã§å 容ã®éœéœ¬ãããå Žåã«ã¯ãè±èªåæãåªå ããŸãã