äž»ãªãã€ã³ã
- ãã«ãŒããã€ã³ãã¯ãTA473ã«ããææ°ã®ãµã€ããŒã¹ãã€æŽ»åïŒç±³åœéžåºãããå ¬åå¡ãè·å¡ãæšçãšããTA473ã®æªå ±åã®äºäŸãå«ãïŒã確èªããŠããŸãã
- TA473ã¯ãã«ãŒããã€ã³ããæ°ãã«è¿œè·¡ããŠããæ»æã°ã«ãŒãã§ããã§ã«å ±åãããŠããWinter Vivernã«é¢ããæ»ææŽ»åãšäžèŽããŠããŸãã
- TA473ã¯ãå°ãªããšã2023幎2æä»¥éãWebã¡ãŒã«ã·ã¹ãã ã§ããZimbraã®æ¢ç¥ã®è匱æ§ãæªçšããŠWebã¡ãŒã«ããŒã¿ã«ãæ»æããæ¬§å·æ¿åºæ©é¢ã®ã¡ãŒã«åä¿¡ç®±ã«å¯Ÿããäžæ£ã¢ã¯ã»ã¹ããããªããŸããã
- TA473ã¯ãåæ¿åºæ©é¢ã®Webã¡ãŒã«ããŒã¿ã«çšã«èšèšãããã«ã¹ã¿ãã€ãºãããJavaScriptãã€ããŒããåäœæãããªããŒã¹ãšã³ãžãã¢ãªã³ã°ããŠããŸãã
- ãã«ãŒããã€ã³ãã¯ãTA473ã®æšçãããã·ã¢ã»ãŠã¯ã©ã€ãæŠäºã«é¢é£ãããã·ã¢ããã©ã«ãŒã·ã®å°æ¿åŠçãªå©çã«äžèŽããŠãããšããSentinel Oneã®åæã«åæããŸãã
æŠèŠ
ãã«ãŒããã€ã³ã ãTA473ãšããŠè¿œè·¡ããŠããAPT (é«åºŠæšçåæ»æã°ã«ãŒã)ããZimbra ã®èåŒ±æ§ CVE-2022-27926 ãæªçšããŠãäžè¬å ¬éãããŠãã Zimbra ãã¹ãã®Webã¡ãŒã«ããŒã¿ã«ãæ»æããŠããããšããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã確èªããŸããããã®æŽ»åã®ç®çã¯ããã·ã¢ã»ãŠã¯ã©ã€ãæŠäºã«é¢äžãããšãŒãããåå°ã®è»ãæ¿åºãå€äº€æ©é¢ã®Eã¡ãŒã«ã«ã¢ã¯ã»ã¹ããããšã§ãããšè©äŸ¡ãããŠããŸãããã®ã°ã«ãŒãã¯ãAcunetixã®ãããªã¹ãã£ã³ããŒã«ãå©çšãããããã®çµç¹ã«å±ãããããæªé©çšã®Webã¡ãŒã«ããŒã¿ã«ãç¹å®ãã被害è ãæšçãšããããã®å®è¡å¯èœãªæ¹æ³ãç¹å®ããŸããæåã®ã¹ãã£ã³ã«ããåµå¯ã®åŸãæ»æã°ã«ãŒãã¯ãé¢é£ããæ¿åºãªãœãŒã¹ãè£ ã£ãè¯æ§ã®ãã£ãã·ã³ã°ã¡ãŒã«ãé ä¿¡ããŸãããã®ã¡ãŒã«æ¬æã«ã¯ãæ¢ç¥ã®è匱æ§ãæªçšããŠè¢«å®³çµç¹ã®Webã¡ãŒã«ããŒã¿ã«å ã§JavaScriptãã€ããŒããå®è¡ããäžæ£ãªURLã®ãã€ããŒãªã³ã¯ãèšèŒãããŠããŸããããã«ãæ»æã°ã«ãŒãã¯ãã¿ãŒã²ããã®åWebã¡ãŒã«ããŒã¿ã«ã®ã€ã³ã¹ã¿ã³ã¹ã調æ»ããWebã¢ããªã±ãŒã·ã§ã³ã«ååšããè匱æ§ããããã¯ãã®è匱æ§ãå©çšããæ»ææ¹æ³ã§ããã¯ãã¹ãµã€ã ãªã¯ãšã¹ã ãã©ãŒãžã§ãªãŒ(CSRF: Cross Site Request Forgery)ãè¡ãããã®ã«ã¹ã¿ãã€ãºãããJavaScriptãã€ããŒããäœæããããã«ãããªãã®æéãè²»ãããŠããããã§ãããããã®æéã®ãããã«ã¹ã¿ãã€ãºããããã€ããŒãã«ãããæ»æã°ã«ãŒãã¯ãŠãŒã¶ãŒåããã¹ã¯ãŒããçã¿ãCookieããã¢ã¯ãã£ããªã»ãã·ã§ã³ãšCSRFããŒã¯ã³ãä¿åããNATOãšé£æºããçµç¹ã®å ¬éãããWebã¡ãŒã«ããŒã¿ã«ãžã®ãã°ã€ã³ã容æã«ããããšãã§ããŸãã
ãã«ãŒããã€ã³ãã®ãªãµãŒãããŒã ã¯æè¿ãTA473ãå ¬ã«è¿œè·¡ããæ»æã°ã«ãŒãã«ã«ããŽãªãææ ŒãããŸããããªãŒãã³ãœãŒã¹ãªãµãŒãã§ã¯Winter VivernãšããŠç¥ãããŠããããã«ãŒããã€ã³ãã¯å°ãªããšã2021幎ãããã®æŽ»å矀ã远跡ããŠããŸãã
æ»æã°ã«ãŒãTA473ãšã¯?
TA473ã¯ãDomainToolsã Lab52ãSentinel OneãUkrainian CERTãªã©ã®ã»ãã¥ãªãã£ãã³ããŒã«ãã£ãŠãWinter Vivernããã³UAC-0114ãšããŠå ¬è¡šãããŠããæ»æã°ã«ãŒãã§ãããã®æ»æã°ã«ãŒãã¯ãæŽå²çã«ãã£ãã·ã³ã°ãã£ã³ããŒã³ã掻çšããŠPowerShellãšJavaScriptã®äž¡æ¹ã®ãã€ããŒããé ä¿¡ããŠããããŸããã£ãã·ã³ã°ã¡ãŒã«ã䜿ã£ãã¯ã¬ãã³ã·ã£ã«ããŒãã¹ãã£ã³ã°ãã£ã³ããŒã³(èªèšŒæ å ±ãçªåããæ»æãã£ã³ããŒã³)ãç¹°ãè¿ãè¡ã£ãŠããŸãã2021幎以éããã«ãŒããã€ã³ãã¯ãç©æ¥µçãªãã£ãã·ã³ã°ãã£ã³ããŒã³ã«ãããŠãæ¬§å·æ¿åºãè»ãå€äº€æ©é¢ãžã®éäžçãªæ»æã芳枬ããŠããŸãããããã2022幎åŸåã«ã¯ããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãç±³åœå ã®éžåºè°å¡ãè·å¡ãæšçãšãããã£ãã·ã³ã°ãã£ã³ããŒã³ã芳枬ããŠããŸãããã·ã¢ã»ãŠã¯ã©ã€ãæŠäºãå§ãŸã£ãŠä»¥æ¥ããªãµãŒãã£ãŒã¯ã芳枬ãããã¿ãŒã²ããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®ã«ã¢ãŒããªãããŸãã«äœ¿ãããŠãã人ç©ã«ã¯å ±éç¹ãããããšã確èªããŠããŸããå€ãã®å Žåãæšçãšãªã£ã人ç©ã¯ãçŸåšé²è¡äžã®çŽäºã®åœ±é¿ãåããŠããå°åã«é¢é£ãããšãŒãããã®æ¿æ²»ãçµæžã®äžé¢ã«è©³ããå°éå®¶ã§ãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã§äœ¿ãããã«ã¢ãŒïŒããšãïŒã®å 容ããªãããŸãã«äœ¿ãããŠããçµç¹ã¯ãæŠåçŽäºäžã®ãŠã¯ã©ã€ãã«é¢é£ããããšãå€ããã®ã«ãªã£ãŠããŸãã
TA473ãã£ãã·ã³ã° ãã£ã³ããŒã³ã®è©³çް
ãã«ãŒããã€ã³ãã¯ã2021幎以éãTA473ãã£ãã·ã³ã°ãã£ã³ããŒã³ã®é²åã芳枬ããŠããŸãããã®æ»æã°ã«ãŒãã¯ã2022幎5æã«å ¬éãããCVE-2022-30190ïŒFollinaïŒãšã¯ã¹ããã€ãã®ãããªäººæ°ã®ããã¯ã³ãã€è匱æ§ãå«ãè匱æ§å ¬éã®æ©äŒã«äŸ¿ä¹ãããšã¯ã¹ããã€ããæ¡çšããŠè¢«å®³çµç¹ãçã£ãŠããããšã芳枬ãããŠããŸããããããäžè¬çã«ã¯ããã®æ»æã°ã«ãŒãã¯ããã¹ãŠã®Eã¡ãŒã«æ»æãã£ã³ããŒã³ã«ãããŠãç¹°ãè¿ããã£ãã·ã³ã°ææ³ã䜿çšããŠããŸãã以äžã®ãã£ãã·ã³ã°ææ³ã¯ãç±³åœã𿬧å·ã®äž¡æ¹ã®ã¿ãŒã²ããã«å¯ŸããŠäžè²«ããŠèŠ³æž¬ãããŠãããã¯ã¬ãã³ã·ã£ã« ããŒãã¹ãã£ã³ã°ããã«ãŠã§ã¢é ä¿¡ãã¯ãã¹ãµã€ã ãªã¯ãšã¹ã ãã©ãŒãžã§ãªïŒCSRFïŒã®æ»æãã£ã³ããŒã³ã§ã芳å¯ãããŠããŸãã
- TA473ã¯ã䟵害ãããEã¡ãŒã«ã¢ãã¬ã¹ããEã¡ãŒã«ãéä¿¡ããŸããå€ãã®å Žåããããã®ã¡ãŒã«ã¯WordPressã§ãã¹ãããããã¡ã€ã³ããçºä¿¡ãããŠããŸããã ãããã¯äŸµå®³æç¹ã§ãããããæªé©çšã§ãã£ãããèšå®ãå®å šã§ãªãã£ããã®ãªã©ã§ãã
- TA473ã¯ãã¡ãŒã«ã®éä¿¡å ãåœè£ ããŠãæšçãšãªãçµç¹ã®ãŠãŒã¶ãŒã«ãªãããŸããããã¡ãŒã«ã®éä¿¡å ãåœè£ ããŠãäžçæ¿æ²»ã«é¢ãã忥è ã®çµç¹ã«èŠããããŸãã
- TA473ã¯ãæšççµç¹ãŸãã¯é¢é£ãã忥çµç¹ã«å¯ŸããŠãè¯æ§ã®URLãã¡ãŒã«æ¬æã«èšèŒããŸãã
- ãããŠãTA473ã¯ãã®è¯æ§ã®URLããæ»æè ã管çããããããã¯äŸµå®³ããã€ã³ãã©ã«ãã€ããŒãªã³ã¯ãããç¬¬äžæ®µéã®ãã€ããŒããé ä¿¡ããããèªèšŒæ å ±ã®åéçšã®ã©ã³ãã£ã³ã°ããŒãžã«ãªãã€ã¬ã¯ãããããããŸãã
- TA473ã¯ãã¿ãŒã²ãããšãªãå人ã®ããã·ã¥å€ãã¿ãŒã²ãããšãªãçµç¹ã®éãšã³ã³ãŒã衚瀺ããããŠå Žåã«ãã£ãŠã¯ã¿ãŒã²ãããžã®æåã®é»åã¡ãŒã«ã§ãã€ããŒãªã³ã¯ãããè¯æ§URLã®ãšã³ã³ãŒããŸãã¯ãã¬ãŒã³ããã¹ãããŒãžã§ã³ãç€ºãæ§é åURIãã¹ããã°ãã°äœ¿çšããŸãã
å³1. æ»æã°ã«ãŒãã管çãããªãœãŒã¹ã«ãªãã€ã¬ã¯ããããã€ããŒãªã³ã¯ä»ãURLãå«ãTA473ã®ã¡ãŒã«
æ¢ç¥ã®Zimbraã®è匱æ§ãæªçšãããå ¬éãããŠããWebã¡ãŒã«ããŒã¿ã«ãžã®ãšã¯ã¹ããã€ã
2023幎åé ããããã«ãŒããã€ã³ãã¯ãCVE-2022-27926ãå©çšããæ¬§å·æ¿åºæ©é¢ãæšçãšããTA473ãã£ãã·ã³ã°ãã£ã³ããŒã³ã®åŸåã芳枬ããŸããããã®è匱æ§ã¯ãäžè¬åãã®Webã¡ãŒã«ããŒã¿ã«ããã¹ãããããã«äœ¿çšãããZimbra CollaborationïŒä»¥åã¯ãZimbra Collaboration SuiteãïŒã®ããŒãžã§ã³9.0.0ã«åœ±é¿ããŸãããã®è匱æ§ã¯ã"Zimbra Collaboration (å¥å ZCS) 9.0 ã® ã³ã³ããŒãã³ãã§ãã /public/launchNewWindow.jsp å ã®ãªãã¬ã¯ãXSS(ã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°)ã®è匱æ§ã§ãããèªèšŒãããŠããªãæ»æè ããªã¯ãšã¹ããã©ã¡ãŒã¿ãä»ããŠä»»æã®ãŠã§ãã¹ã¯ãªãããŸã㯠HTML ãå®è¡ã§ãã"ãšãããŠããŸãã
å®éã«ã¯ãTA473ã¯ãã£ãã·ã³ã°ã¡ãŒã«ã®æ¬æäžã«ããè¯æ§ã®URLãããCVE-2022-27926ãå©çšããURLã«ãªã³ã¯ãããŠããŸããæªæã®ããURLã¯ãè匱ãªZimbra Collaboration Suiteã€ã³ã¹ã¿ã³ã¹ãæã€Webã¡ãŒã«ãã¡ã€ã³ã䜿çšããä»»æã®16鲿°ã§ç¬Šå·åãŸãã¯å¹³æã®JavaScriptã¹ãããããä»å ããæåã®Webãªã¯ãšã¹ãã§åãåã£ããšãã«ãšã©ãŒãã©ã¡ãŒã¿ãšããŠå®è¡ãããŸãããã®JavaScriptãè§£èªããããšãæ¬¡ã®æ®µéã®ç¹å¥ã«äœãããJavaScriptãã€ããŒããããŠã³ããŒãããããŠãŒã¶ãŒåããã¹ã¯ãŒããCSRFããŒã¯ã³ããŠãŒã¶ãŒããååŸããããã«CSRFãè¡ãããŸãã

å³2. TA473ã®CSRFã«ããææãã§ãŒã³å³
ãã®è匱æ§ã®æªçšã¯ãããå¹ åºãZimbra CollaborationããŒãžã§ã³ã«åœ±é¿ãäžããCVE-2021-35207ã®æªçšãšå®éã«ã¯éåžžã«äŒŒãŠãããç¹ã«Webã¡ãŒã«ã®ãã°ã€ã³URLã®loginErrorCodeãã©ã¡ãŒã¿ã«å®è¡å¯èœãªJavaScriptã远å ããå¿ èŠããããšãªãµãŒãã£ãŒã¯è¿°ã¹ãŠããŸãããããããã®æªçšã¯CVE-2022-27926ãšã¯ç°ãªããéå®çã§ãããšèããããŠããŸããCVE-2022-27926ãå©çšããTA473ã®ããªãšãŒã·ã§ã³ã¯ã以äžã®ãã®ã確èªãããŠããŸãïŒ
1. JavaScriptã®å€ã16鲿°ã§ãšã³ã³ãŒãããURL

å³3. CyberChef ããã³ãŒããã16鲿°ã®JavaScript
2. ãã¬ãŒã³ããã¹ãã®JavaScriptå€ãå«ãURL

ã«ã¹ã¿ãã€ãºãããã¯ãã¹ãµã€ã ãªã¯ãšã¹ã ãã©ãŒãžã§ãª(CSRF)
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãäžèšã®CVE-2022-27926ã®æªçšãšããã£ãã·ã³ã°ã¡ãŒã«æ¬æã®è¯æ§URLã®ãã€ããŒãªã³ã¯ããçããTA473å¶åŸ¡ã®ã€ã³ãã©é ä¿¡ãªã©ã®ä»¥åã®é ä¿¡ã¡ã«ããºã ã®äž¡æ¹ãéããŠãã«ã¹ã¿ãã€ãºãããCSRF JavaScriptãã€ããŒããšæãããè€æ°ã®äºäŸã確èªããŸããããããã®CSRF JavaScriptã³ãŒããããã¯ã¯ãè匱ãªWebã¡ãŒã«ã€ã³ã¹ã¿ã³ã¹ããã¹ããããµãŒããŒã§å®è¡ãããŸããããã«ããã®JavaScriptã¯ãã¿ãŒã²ããã®ãŠãŒã¶ãŒåããã¹ã¯ãŒããCSRFããŒã¯ã³ã瀺ãäž»èŠãªWebãªã¯ãšã¹ãã®è©³çްãè¿ãããã«ããã€ãã£ãã®Webã¡ãŒã«ããŒã¿ã«ã®JavaScriptãè€è£œãããšãã¥ã¬ãŒã·ã§ã³ã«äŸåããŠããŸããããã€ãã®äŸã§ã¯ãTA473ãRoundCubeã®Webã¡ãŒã«ãªã¯ãšã¹ãããŒã¯ã³ãç¹ã«ã¿ãŒã²ããã«ããŠããããšã確èªãããŠããŸãããã®ããã«ãæšçãšãªã欧å·ã®æ¿åºæ©é¢ãã©ã®Webã¡ãŒã«ããŒã¿ã«ã䜿çšããŠãããã詳现ã«èª¿ã¹ãããšã¯ãTA473ãçµç¹ã«ãã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ããåã«è¡ãåµå¯ã®ã¬ãã«ã瀺ããŠããŸãããããã®æ¬¡ã®æ®µéã®TA473 CSRF JavaScriptãã€ããŒãã¯ãJavaScriptã®æ©èœãé£èªåããããã«ãäœå±€ãã®Base64ãšã³ã³ãŒãã£ã³ã°ã䜿çšããŠããŸãããã®æ»æã°ã«ãŒãã¯ãé ä¿¡ããããã€ããŒãã®åæãè€éã«ããããã«ãBase64ãšã³ã³ãŒããããJavaScriptã®ã€ã³ã¹ã¿ã³ã¹ã3ã€å ¥ãåã«ããŠæ¿å ¥ããŸããããããã¹ã¯ãªãããè§£èªããããšã¯ç°¡åã§ãæå³ããæªæã®ããæ©èœãæããã«ããããšãã§ããŸãã
å³4. Base64ãšã³ã³ãŒããããCSRF JavaScriptã®ãã€ããŒãïŒé·ããèæ ®ããŠæç²ïŒ
ç¹å®ãããæªæã®ããJavaScriptã®åãã€ããŒãã¯ããã€ãã£ãã®Webã¡ãŒã«ããŒã¿ã«ã§å®è¡ãããæ£èŠã®JavaScriptã倧ããåã蟌ãã§ããŸãããããã®ãã£ã³ããŒã³ã«ãã£ãŠåœ±é¿ãåããæ¬§å·æ¿åºæ©é¢ãç¹å®ããªãããã«ããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãã¹ã¯ãªããã®é«ã¬ãã«ã®æ©èœãç¹ã«ã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªãŒãå®çŸããããã«TA473ã«ãã£ãŠæ¿å ¥ãããéšåã«çŠç¹ãåœãŠãŸããããªãµãŒãã£ãŒã¯ã2023幎2æã«é ä¿¡ãããæªæã®ããJavaScriptã芳å¯ãã以äžã®æ©èœãåããŠããããšã確èªããŸããïŒ
- ãŠãŒã¶ãŒåã®çªå
- ãŠãŒã¶ãŒ ãã¹ã¯ãŒãã®çªå
- Webãªã¯ãšã¹ãã®ã¬ã¹ãã³ã¹ã«å«ãŸããCookieãããã¢ã¯ãã£ããªCSRFããŒã¯ã³ãçªå
- çãã å€ãæ»æã°ã«ãŒãã管çãããµãŒããŒã«ãã£ãã·ã¥
- ã¢ã¯ãã£ãããŒã¯ã³ã§æ£èŠã®ã¡ãŒã«ããŒã¿ã«ãžã®ãã°ã€ã³ã詊ã¿ã
- ã¹ã¯ãªããã¯ããã®æ©èœã«ãããŠè¿œå ã®URLãå©çšããïŒ
- æ»æã°ã«ãŒãã管çãããµãŒããŒã«ãã¹ããããŠããPop3ããã³IMAPã®æç€ºã衚瀺ããã
- ãã€ãã£ãURLçµç±ã§æ£èŠã®Webã¡ãŒã«ããŒã¿ã«ãžã®ãã°ã€ã³ã詊ã¿ãã
芳å¯ãããã¹ã¯ãªããã®åäœã®æ¡åŒµã·ãŒã±ã³ã¹ã¯ä»¥äžã®éãã§ãïŒ
- çãŸãããŠãŒã¶ãŒå€ã®ãã£ãã·ã¥ã®ããã«æªæã®ãããµãŒããŒã®ãã¡ã€ã³ã確ç«ãã
- 察象ãšãªãã¢ã«ãŠã³ãåãåç §ãã
- æ¥ä»ãšæå»ãååŸãã
- ã¢ã«ãŠã³ãåã®å€æ°ãååŸãã
- ã¿ã€ã ã¢ãŠããŠã£ã³ããŠã1000ç§ã«èšå®
- "ã¯ãªãã¯æ "ã«ã¯ã¬ãã³ã·ã£ã«ãéä¿¡ããæ©èœ
- ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããURIãšã³ã³ãŒãããŠéä¿¡
- ãã¹ã¯ãŒãã®é·ãã0ã§å€±æããå Žå (å¥å no password)ãã¹ã¯ãªããã¯ãŠãŒã¶ãŒã«æ¬¡ã®ãããªããã³ãããè¡šç€ºïŒ "The username or password is incorrect. Verify that CAPS LOCK is not on, and then retype the current username and password."(ãŠãŒã¶ãŒåãŸãã¯ãã¹ã¯ãŒããæ£ãããããŸãããCAPS LOCKããªã³ã«ãªã£ãŠããªãããšã確èªããçŸåšã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããåå ¥åããŠãã ããã) ; return;"
- 次ã«ãã¹ã¯ãªããã¯ãWebãªã¯ãšã¹ãã®ã¬ã¹ãã³ã¹ããããŠãŒã¶ãŒåããã¹ã¯ãŒããããã³CSRFããŒã¯ã³ããã°ã«èšé²
- JavaScriptã¯åã³ãã°ã€ã³ã«å€±æããããšã確èªããããšããæ»æè
ãå
¥åãããšã©ãŒã¡ãã»ãŒãžã衚瀺ããèšé²ãããCSRããŒã¯ã³ãæ£èŠã®Webã¡ãŒã«ãµãŒããŒã«ãã¹ãïŒãã°ã€ã³ã®è©Šã¿ïŒã
- ãã®è©Šã¿ã倱æããå Žåãã¹ã¯ãªããã¯åã³å¯Ÿè±¡ãµãŒããŒãžã®æçš¿ã詊ã¿ãElementbyID "lic34yo8o" ãååŸããã¬ã¹ãã³ã¹å ã® "body" ãšããã¿ã°ãä»ãããã®èŠçŽ ãåé€
- ãã®åŸãåã³ãaccountnameã倿°ããusernameã倿°ããpasswordã倿°ã®ä¿åã詊ã¿ã
- ã¹ã¯ãªããã¯ãã¿ãŒã²ãããã¡ã€ã³ã«åºæãšæãããããŒãã³ãŒããããã«ã¹ã¿ã URIæ§é ã䜿çšããŠãæ£èŠã®Webã¡ãŒã«ããŒã¿ã«ã«ãã°ã€ã³ããããšãããŠãŒã¶ãŒåããã¹ã¯ãŒããCSRFããŒã¯ã³ãã以åã«ååŸããURIæ§é ã«ä»å ãã
- ã¹ã¯ãªããã«ã¯ãçãã ã¯ã¬ãã³ã·ã£ã«ãšããŒã¯ã³ã®å 容ã§ãã°ã€ã³ããæ©èœãã
- ã¹ã¯ãªããã«ã¯ãæ»æè ã管çããã€ã³ãã©ã«ãã¹ããããZimbra Pop3ããã³IMAPã®ãã°ã€ã³æ å ±ããŒãžã衚瀺ããæ©èœãã
- ã¹ã¯ãªããã«ã¯ãæ£èŠã®ãŠã§ãã¡ãŒã«ããŒã¿ã«ã®ãã°ã€ã³ãŠã£ã³ããŠã衚瀺ããæ©èœãã
- ã¹ã¯ãªããã«ã¯ãinitLoginFieldããšãã颿°ããããæ£èŠã®ãŠã§ãã¡ãŒã«ã®ãã°ã€ã³ãŠã£ã³ããŠã«ãŠãŒã¶ãŒåãšã¢ã«ãŠã³ãåãå ¥åãããã衚瀺ããã
- ã¡ãŒã«ãµãŒããŒããã°ãªããããã°ã¢ãŠãæã«CSRFããŒã¯ã³ã®ååŸã詊ã¿ãæ»æè ã管çãããµãŒããŒã«éä¿¡ããæ©èœãã
- ã¹ã¯ãªããã«ã¯ãCSRFããŒã¯ã³ãååŸãã颿°ãã
- JavaScriptã®ãªã¯ãšã¹ãã¬ã¹ãã³ã¹ããã¥ã¡ã³ãããèŠçŽ ãè§£æããDOMParseræ©èœãå©çšããŠãæååããCSRFããŒã¯ã³ãååŸããæ©èœãã
å³5. CSRFããŒã¯ã³ãçãæ¹æ³ã詳ãã説æããCSRF JavaScriptã®ã¹ãããã
å é²çãªæ©èœãçæ³çã ããè¿·ã£ããšãã¯ç²ã匷ããéèŠ
TA473ã¯ãäžè¬å ¬éãããŠããWebã¡ãŒã«ããŒã¿ã«ã«åœ±é¿ãäžãããããæªé©çšã®è匱æ§ãã¹ãã£ã³ããæªçšããããã®æç¶çãªã¢ãããŒãããšã£ãŠããŸãããã®ã°ã«ãŒãã¯ããŠãŒã¶ãŒåããã¹ã¯ãŒããCSRFããŒã¯ã³ãçãããã®JavaScriptããªããŒã¹ãšã³ãžãã¢ãªã³ã°ããããã«ãäžè¬ã«å ¬éãããŠããWebã¡ãŒã«ããŒã¿ã«ãç¶ç¶çã«åµå¯ãã䞹念ã«ç ç©¶ããããšã«æ³šåããŠãããç¹å®ã®ã¿ãŒã²ããïŒãã®å Žåã¯æ¬§å·æ¿åºéšéïŒã䟵害ããããšãžã®æè³ã瀺ããŠããŸããTA473ã¯ã1ã€ã®ããŒã«ããã€ããŒãã§ãã¹ãŠããŸããªãã®ã§ã¯ãªããç¹å®ã®ãšã³ãã£ãã£ã䟵害ããããã«æéãšãªãœãŒã¹ãè²»ãããåJavaScriptãã€ããŒãã¯æšçãšãªãWebã¡ãŒã«ããŒã¿ã«çšã«ã«ã¹ã¿ãã€ãºãããŠããŸãã
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãç¹ã«æ¬§å·ã®æ¿åºæ©é¢ã«ãããŠãäžè¬ã«å ¬éãããŠããWebã¡ãŒã«ããŒã¿ã«ã§äœ¿çšãããŠããZimbra Collaborationã®ãã¹ãŠã®ããŒãžã§ã³ã«ããããé©çšããããšãåŒ·ãæšå¥šããŸããããã«ãTA473ã®ãããªã°ã«ãŒãããèªèšŒæ å ±ãçãã§ãŠãŒã¶ãŒã®Webã¡ãŒã«ã¢ã«ãŠã³ãã«ãã°ã€ã³ããããšãã§ããã«ã¹ã¿ã ã¹ã¯ãªãããåæ§ç¯ãããšã³ãžãã¢ãªã³ã°ããã®ãé²ãããã«ãäžè¬ã«å ¬éãããŠããWebã¡ãŒã«ããŒã¿ã«ã®ãªãœãŒã¹ãå ¬å ±ã®ã€ã³ã¿ãŒãããããå¶éããããšãåŒ·ãæšå¥šããŸããTA473ã¯ã欧å·ã®ãµã€ããŒç°å¢ãæšçãšããAPTæ»æã°ã«ãŒãã®äžã§ãæŽç·Žãããéå£ã®å é ã«ç«ã€ããšã¯ãããŸããããéäžåãæç¶åããããŠå°æ¿åŠçãªæšçã䟵害ããããã®å埩å¯èœãªããã»ã¹ã瀺ããŠããŸããäžäžã«èªããããã©ãŽã³ã®é ãæã¡2æ¬ã®è¶³ãš1察ã®ç¿Œããæããªãå¬ã®ã¢ã³ã¹ã¿ãŒã§ãããŽã¡ã€ãŽã¡ãŒã³ã®ããã«ããã®è åšã¯1幎äžåç¶ããå¯èœæ§ããããŸãã
IOC ( 䟵害ã®çè·¡ / Indicators of CompromiseïŒ
|
IOC |
Type of IOC |
Description |
|
hxxps://oscp-avanguard[.]com/asn15180YHASIFHOP_<redacted>_ASNfas21/auth.js
hxxps://oscp-avanguard[.]com/settingPopImap/SettingupPOPandIMAPaccounts.html
hxxps://troadsecow[.]com/cbzc.policja.gov.pl
hxxps://bugiplaysec[.]com/mgu/auth.js
hxxps://nepalihemp[.]com/assets/img/images/623930va
hxxps://ocs-romastassec[.]com/redirect/?id=[target specific ID]&url=[Base64 Encoded Hyperlink URL hochuzhit-com.translate.goog/?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en-US&x_tr_pto=wapp]
hxxps://ocspdep[.]com/inotes.sejm.gov.pl?id=[Target Specific SHA256 Hash] |
URLs |
Observed payload delivery URLs |
|
ocspdep[.]com bugiplaysec[.]com oscp-avanguard[.]com troadsecow[.]com nepalihemp[.]com |
Domain |
C2 Domains |
ET Signatures
2034117 â ET TROJAN Wintervivern Activity M5 (GET)
2034116 â ET TROJAN Wintervivern Activity M4 (GET)
2034115 â ET TROJAN Wintervivern Retrieving Commands
2034109 â ET TROJAN Wintervivern Activity (GET) M3
2034108 â ET TROJAN Wintervivern Checkin
2034107 â ET TROJAN Wintervivern Retrieving TaskÂ
2034106 â ET TROJAN Wintervivern Activity M2 (GET)
2034105 â ET TROJAN Wintervivern Activity (GET)