æŠèŠ
2020幎8æä»¥éããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãAmazon Japanã®ã¯ã¬ãã³ã·ã£ã«(èªèšŒæ å ±)ãå人æ å ±ã®çªåãçã£ãéåžžã«å€§éã®ãã£ãã·ã³ã° ãã£ã³ããŒã³ã远跡ããŠãããçããããæŽ»åã¯2020幎6æãŸã§ããã®ãŒããŸããã¡ãŒã«ã¡ãã»ãŒãžã¯ãAmazon Japanãè£ ããåä¿¡è ã«ãã¢ã«ãŠã³ãæææš©ã®ç¢ºèªãããæ¯æãæ å ±ã®æŽæ°ãã®ããã«ã¢ã«ãŠã³ããèŠçŽãããä¿ããŠããŸããåä¿¡è ãã¡ãã»ãŒãžã®ãªã³ã¯ãã¯ãªãã¯ãããšãAmazonãè£ ã£ãã¯ã¬ãã³ã·ã£ã« ãã£ãã·ã³ã°ã®ã©ã³ãã£ã³ã°ããŒãžã«èªå°ãããã¯ã¬ãã³ã·ã£ã«(èªèšŒæ å ±)ãå人è奿 å ±ïŒPIIïŒãã¯ã¬ãžããã«ãŒãçªå·ãªã©ãåéãããŸããã¡ãã»ãŒãžã¯ãæ¥æ¬ã®çµç¹ã𿥿¬ã«æ ç¹ãããçµç¹ã®äž¡æ¹ã«éãããŠããŸãããã®ããŒãžã¯ãæ¥æ¬ã®åä¿¡è ã®ã¿ãã¯ã¬ãã³ã·ã£ã« ãã£ãã·ã³ã°ããŒãžã«èªå°ãããããã«ããžãªãã§ã³ã¹ïŒå°ççå¢çç·ïŒãèšå®ãããŠããŸãã
Amazonã®ãããªäººæ°ãã©ã³ããã¯ã¬ãã³ã·ã£ã« ãã£ãã·ã³ã° ãã£ã³ããŒã³ã§æªçšãããããšã¯ãããããŸããããããä»åã®æ»æãã£ã³ããŒã³ã®ãã®ã¡ãã»ãŒãžã®éã®å€ãã¯ãä»ã®Amazonãã©ã³ããããŒãã«ããæ»ææŽ»åãšã¯æ¡å€ãã«å€ããã®ãšãªã£ãŠããŸãããã®ãã£ã³ããŒã³ã¯ç¶ç¶çã«è¡ãããŠãããæ¯æ¥äœåäžéãã®ã¡ãã»ãŒãžãéä¿¡ãããŠããŸãã10æäžæ¬ã®æç¹ã§ã¯ã1æ¥ã«100äžä»¶ä»¥äžã®ã¡ãã»ãŒãžãèŠãããããšããããEmotet ã®ã¡ãã»ãŒãžéã«å¹æµããŸãã
ã«ã¢ãŒïŒããšãããŒãïŒãšã©ã³ãã£ã³ã°ããŒãž
ã¡ãã»ãŒãžã¯ãåä¿¡è ã®æ å ±ãæŽæ°ããå¿ èŠãããããšããã¢ã«ãŠã³ããããã¯ãããŠããããšã瀺åãããããªå 容ã§ã粟巧ã«äœãããæ¥æ¬èªã®ã«ã¢ãŒïŒããšãããŒãïŒã§ãã
-
ãAmazon.co.jp ã¢ã«ãŠã³ãæææš©ã®èšŒæïŒååããã®ä»å人æ å ±ïŒã®ç¢ºèªã (å³1)
-
ããæ¯æãæ¹æ³ã®æ å ±ãæŽæ°ã(å³2)
-
ãã¢ã«ãŠã³ããããã¯ãããã®ã§ããæ³šæäžãã ã (å³3)

å³1: ã«ã¢ãŒä»¶åãAmazon.co.jp ã¢ã«ãŠã³ãæææš©ã®èšŒæïŒååããã®ä»å人æ
å ±ïŒã®ç¢ºèªã

å³2: ã«ã¢ãŒä»¶åããæ¯æãæ¹æ³ã®æ
å ±ãæŽæ°ã

å³3: ã«ã¢ãŒä»¶åãã¢ã«ãŠã³ããããã¯ãããã®ã§ããæ³šæäžãã ã
ã¡ãã»ãŒãžã«å«ãŸããAmazonã®ããŽãªã©ã®ç»åã¯ãç¡æã®ç»åãã¹ãã£ã³ã°ãµãŒãã¹ããçŽã«ãªã³ã¯ãããŠãããè€æ°ã®ãã£ã³ããŒã³ã§åãç»åã®URLã確èªãããŠããŸãã
ãããã®ã¡ãã»ãŒãžã¯Amazonããã®ãã®ã§ããããšãè£ ã£ãŠããŸãããåæã®ãã®ã¯ããŸãããŸãåœè£ ãããŠããªãã¡ãŒã«ã¢ãã¬ã¹ããæ¥ãŠããŸãããã¢ãã¬ã¹äŸã¯æ¬¡ã®ãšããã§ãïŒ
-
rmlirozna[@]pw[.]com
-
fwgajk[@]zfpx[.]cn
-
info[@]bnwuabd[.]xyz
-
dc[@]usodeavp[.]com
ããã2020幎10æåæ¬ã«ã¯ãéä»å ã¢ãã¬ã¹ãããçšåºŠæ£åœãªãã®ã«èŠããããšããåããèŠãããããã«ãªããŸããã
-
amaozn[@]ama2on[.]buzz
-
accout-update[@]amazon[.]co.jp
-
account-update[@]amazon[.]com
-
admin[@]amazon-mail[.]golf
ã¡ãã»ãŒãžã®URLã調ã¹ããšãAmazon Japanã䜿çšããŠããèªèšŒãããã³ã«ã§ããOpenIDã®ãã©ã¡ãŒã¿ãå«ãŸããŠããããšãããããŸãïŒå³4ïŒããããã®URLã¯ãŠãŒã¶ãŒãOpenIDã®å®è£ ã«èªå°ãããã®ã§ã¯ãªãããã§ãããURLã®æååã«å«ãŸãããã©ã¡ãŒã¿ã¯è¡çºã«æ£åœæ§ãäžããããã«ååšããŠããŸãã
ããã€ãã®URLã«ã¯ãã¬ãŒã¹ãã«ããŒå€ãšæããããã®ãå«ãŸããŠãããã¡ãã»ãŒãžã®éä¿¡ãæ©ãŸã£ããã察å¿ããå€ãå©çšã§ããªãã£ãããšã瀺åããŠããŸãïŒå³4ïŒã

å³4: ãBRECEIVER_ADDRESSããBRAND_TEXTãã®å€æ°ãå«ãŸããURL
ãŸããããã€ãã®URLã§ã¯ããa@b.cããšãããã¬ãŒã¹ãã«ããŒã®ã¡ãŒã«ã¢ãã¬ã¹ãšæããããã®ã䜿çšãããŠããããšã確èªãããŸããïŒå³5ïŒãä»ã®URLã§ã¯ãåä¿¡è ã®ã¡ãŒã«ã¢ãã¬ã¹ããã®ãã©ã¡ãŒã¿ãå ¥åããŠããŸãã

å³5: 倿°ã®ãããã«ãa@b.cããšOpenIDã®è»è·¡ãå«ãŸããURL
ãŠãŒã¶ãŒãã¯ãªãã¯ãããšãã¡ãã»ãŒãžå ã®ãžãªãã§ã³ã¹ãªã³ã¯ã¯ãåœè£ ããAmazon Japanã®ãã°ã€ã³ããŒãžïŒå³6ïŒãžèªå°ããŸãããŠãŒã¶ãŒãæ¥æ¬åœå€ã«ãããšå€æãããå Žåã¯ãå®éã®Amazon Japanã®ãã°ã€ã³ããŒãžã«èªå°ããŸãã

å³6: åœè£ ããAmazon Japanã®ãã°ã€ã³ããŒãž
Amazonã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã§ããã°ã€ã³ããããšããŠãŒã¶ãŒã¯äœæãèªçæ¥ãé»è©±çªå·ãªã©ã®ããŸããŸãªå人æ
å ±ãåéãããã©ãŒã ã«ç§»åããŸãïŒå³7ïŒã

å³7: ãŠãŒã¶ãŒã®åœåãæ°åãèªçæ¥ãéµäŸ¿çªå·ãéœéåºçãäœæãäŒç€ŸåïŒä»»æïŒãé»è©±çªå·ãèŠæ±ããæ å ±ãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãž
ãã®ãã©ãŒã ã§ã¯ãåããµã€ãã§ãã¹ããããŠããã¹ã¯ãªãããçšããŠãã¯ã¬ãžããã«ãŒãçªå·ãæ£åœãªãã®ããç°¡åã«ãã§ãã¯ããæ©èœãšããµãŒãããŒãã£ã®ãµãŒãã¹ãžã®APIã³ãŒã«ãä»ããŠéµäŸ¿çªå·ããã§ãã¯ãããããã®æ å ±ãåéããŠããŸãïŒå³8ãå³9ïŒãè峿·±ãããšã«ãæã ãæäŸããéµäŸ¿çªå·ã¯æ£èŠã®æ¥æ¬ã®éµäŸ¿çªå·ã§ã¯ãªããã®ã§ããããæ å ±ãéä¿¡ããŠããšã©ãŒã«ã¯ãªããŸããã§ããã

å³8: æåã«å ¥åããã¯ã¬ãžããã«ãŒãçªå·(ééã£ãé·ãã®ã©ã³ãã ãªæ°åå)ãç¡å¹ã§ããããšã瀺ããšã©ãŒ

å³9: ååãããã©ãã£ãã¯ã¯ãéµäŸ¿çªå·èªèšŒã®ããã® "zipcloud.ibsnet[...]co.jp" ãžã®åŒã³åºããšãã¯ã¬ãžããã«ãŒãçªå·èªèšŒã®ããã® "/ap/actions/validate?cxdi=" ãžã®åŒã³åºãã瀺ããŠããŸãã
æå¹ãªæ å ±ãéä¿¡ããåŸããŠãŒã¶ãŒã®æ å ±ãæŽæ°ãããã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ãªã£ãããšãåããããå®éã®Amazon Japanã®ãµã€ãïŒamazon.co[...]jpïŒã«ãªãã€ã¬ã¯ããããŸãã
å³10: ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ãªã£ãããšããŠãŒã¶ãŒã«éç¥ããéä¿¡åŸã®ããŒãž
Eã¡ãŒã« ã¡ãã»ãŒãžã®éã®æšç§»

å³11: 2020幎8æïœ10æçŸåšã®ã¡ãã»ãŒãžé
ãã«ãŒããã€ã³ãã¯8æäžæ¬ä»¥éããããã®ã¡ãã»ãŒãžã远跡ããŠããŸãããç§ãã¡ã¯2020幎6æã®æç¹ã§ãåãæ»æè ã«é¢ä¿ããŠãããšæãããæŽ»åã確èªããŠããŸããã¡ãã»ãŒãžã¯æ¥æ¬èªã§æžãããŠãããã©ã³ãã£ã³ã°ããŒãžã¯æ¥æ¬ã®IPã«ãžãªãã§ã³ã¹ããŠããŸãããåä¿¡è ãæ¥çš®ã«ãããŠãæ¥æ¬ã«æ ç¹ãããããšãæ¥æ¬ã§äºæ¥å±éããŠããããšä»¥å€ã«æç¢ºãªãã¿ãŒã³ã¯èŠãããŸããã8æäžæ¬ãã9æã«ãããŠèŠ³æž¬ããã1æ¥ã®ã¡ãã»ãŒãžéã®ãããããªçŽç·çãªè»è·¡ãèãããšãä»åŸæ°ã¶æã«ããã£ãŠã¡ãã»ãŒãžéãå¢å ãç¶ããå¯èœæ§ããããŸãã
| æé | ïŒæ¥ãããã®å¹³åã¡ãã»ãŒãžé |
| 8æ (8/18-8/30) | 122,000 |
| 9æ | 424,000 |
| 10æçŸåš | 750,000 |
æ»æã€ã³ãã©
éåžžãã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ã®ã©ã³ãã£ã³ã°ããŒãžã¯ãIPã¢ãã¬ã¹ã®åŸã«ã/ap/signinããç¶ããŸãïŒ
-
hxxp://103.192.179[.]54/ap/signin
IPã¢ãã¬ã¹ã®ä»£ããã«ãã¡ã€ã³ã䜿çšãããããšãå°ãªããããŸããïŒ
-
00pozrjbpm[.]xyz/ap/signin
æ»æè ã¯IPã¢ãã¬ã¹ãåå©çšããã®ã§ã¯ãªãããã£ã³ããŒã³ããšã«æ°ããIPã¢ãã¬ã¹ãæ¡çšããåŸåããããããè€æ°ã®ãã£ã³ããŒã³ããŸããã§äœçŸãã®IPã¢ãã¬ã¹ã䜿çšãããŠããŸããIPã¢ãã¬ã¹ã¯æ§ã ãªèªåŸã·ã¹ãã ã«å±ããŠãããå°åããããã€ããŒã«ãããæç¢ºãªãã¿ãŒã³ã¯ãããŸããã

å³12: 2020幎8æãã10æãŸã§ã®éã«ã«ã¢ãŒã§äœ¿çšãããIPã¢ãã¬ã¹ã®èªåŸã·ã¹ãã ïŒASïŒåããã10
䜿çšãããŠãããã¡ã€ã³ã¯ã*.xyzããŸãã¯ã*.cnãã®TLDïŒãããã¬ãã«ãã¡ã€ã³ïŒã§ãè€æ°ã®ãã£ã³ããŒã³ã«ãŸããã£ãŠèŠ³æž¬ãããŠãããã®ããããŸãã.xyzãã¡ã€ã³ã¯GoDaddyãéããŠç»é²ãããŠããã*.cnãã¡ã€ã³ã¯é¿éäºè®¡ç®æéå ¬åžïŒäžçœïŒïŒAlibaba Cloud ComputingïŒã®ã¹ãã³ãµãŒã¬ãžã¹ãã©ãååšããŸãã
8æ30æ¥ïœ9æ5æ¥ã®æ»æãã£ã³ããŒã³ã©ã³ãã£ã³ã°ããŒãžã®ãã¡ã€ã³æ å ±
| ãã¡ã€ã³ | äœææ¥ | ç»é²è ã®è©³çްæ å ± |
| 00pozrjbpm[.]xyz | 2020-04-24 |
Registrant State/Province: Xiang Gang |
| 1mmmms2jy8[.]xyz | 2020-06-14 |
Registrant State/Province: Xiang Gang |
| 4lz1qen0ls[.]xyz | 2020-06-14 |
Registrant State/Province: Xiang Gang |
| 5b0rnizmhn[.]xyz | 2020-04-24 |
Registrant State/Province: Xiang Gang |
ãã¡ã€ã³ã®ç»é²è ããŒã¿ã®å€ãã¯ãç§ãã¡ããã§ãã¯ããæç¹ã§ã¯ç·šéãããŠããŸãããããäœææ¥ããšããã€ãã®ç»é²è 詳现ãã£ãŒã«ãã«å ±éç¹ãããããšã«æ°ä»ããŸããã
9æ6æ¥ïœ12æ¥ã®æ»æãã£ã³ããŒã³ã©ã³ãã£ã³ã°ããŒãžã®ãã¡ã€ã³
| ãã¡ã€ã³ | äœææ¥ | ç»é²è ã®è©³çްæ å ± |
| 00pozrjbpm[.]xyz | 2020-04-24 |
Registrant State/Province: Xiang Gang |
| jiyingkou[.]cn | 2019-09-20 |
Registrant: çåž
åœ |
| enjinchang[.]cn | 2019-09-19 |
Registrant: çåž
åœ |
| juhaicheng[.]cn | 2019-09-20 |
Registrant: çåž
åœ |
| getongliao[.]cn | 2019-09-20 |
Registrant: çåž
åœ |
8æ30æ¥ãã9æ5æ¥ã®ãã£ã³ããŒã³ã§åå©çšããã00pozrjbpm[.]xyzãé€ãã°ã9æ6æ¥ãã12æ¥ã®ãã£ã³ããŒã³ã®ãã¡ã€ã³ã¯å ±éã®ç¹åŸŽãæã£ãŠããŸãã以åã®äžé£ã®ãã¡ã€ã³ãšåæ§ã«ãäœææ¥ãšç»é²è æ å ±ãããããããäœããã®åœ¢ã§é¢é£ããŠããå¯èœæ§ã瀺åãããŸããããã«ããrxbnn3[@]163[...]comãã¯å€§éã®ãã¡ã€ã³ç»é²è ã§ããããã®ã¢ãã¬ã¹ã¯ããã®å ¬éæç¹ã§251ã®ãã¡ã€ã³ç»é²è ã®é£çµ¡å ãšããŠè¡šç€ºãããŠããŸããäžèšã®ãrxbnn3[@]163[...]comãã«é¢é£ãããã¡ã€ã³ã«å ããŠããã®ã¡ãŒã«ã«ã¯ãã¡ã€ã³çæã¢ã«ãŽãªãºã (DGA)ã«äŒŒããã¡ã€ã³ã倿°ãªã³ã¯ãããŠããŸãã
-
swwkppe[.]cn
-
lmkafwgi[.]cn
-
pdscmkq[.]cn
-
awsmgrc[.]cn
çµè«
Amazonãã©ã³ãã¯äžè¬çã«ãã¯ã¬ãã³ã·ã£ã«ïŒèªèšŒæ å ±ïŒãçªåããããšããæ»æè ã«ãã£ãŠãªãããŸãããŠããŸããããããã®ãã£ã³ããŒã³ã®éãšç¶ç¶æ§ã¯ãAmazonãããŒãã«ããä»ã®æ»ææŽ»åãšã¯æ¡å€ãã«å€ããã®ãšãªã£ãŠããŸããã¡ãã»ãŒãžã¢ã»ãããã©ã³ãã£ã³ã°ããŒãžãããã³çå®ã«å¢å ããã¡ãã»ãŒãžéã®äžè²«ããåå©çšã¯ããã®æŽ»åãããããããã«ãã£ãŠè¡ãããŠããå¯èœæ§ãããããšã瀺ããŠããŸããããã«ãèªååãããŠããªããªãã¬ãŒã·ã§ã³ã§æã èŠããããããªã鱿«ã®ã¡ãã»ãŒãžéã®ãããããªåæ»ã¯ãããŸããããããå®éã«ããããããã«ãã£ãŠå®è¡ãããŠããå Žåãã¡ãã»ãŒãžéãããã«æžå°ããããšã¯ãããŸãããæ»æè ã¯ããã®éçšã«æ®µéçãªå€æŽãå ããããšãå€ããç°ãªããã©ã³ãããããã«ç°ãªãæ å ±ã®åéãšãã£ãèŠçŽ ã¯ããã®æ»æè ã«ãšã£ãŠä»åŸæ°ã«æéã®ãã¡ã«å®¹æãªè»¢æç¹ãšãªãå¯èœæ§ããããŸãã
IOCæ å ±
| IOC | IOC Type | Description |
| hxxp://182.16.26[.]194/ap/signin | URL | Amazon Japan credential phish landing page |
| hxxp://23.133.5[.]144/ap/signin | URL | Amazon Japan credential phish landing page |
| hxxp://43.249.30[.]212/ap/signin | URL | Amazon Japan credential phish landing page |
| 00pozrjbpm[.]xyz/ap/signin | URL | Amazon Japan credential phish landing page |
| jiyingkou[.]cn/ap/signin | URL | Amazon Japan credential phish landing page |
| enjinchang[.]cn/ap/signin | URL | Amazon Japan credential phish landing page |