äž»ãªãã€ã³ã
- 2023幎7æãã10æã«ãããŠããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãTA402ãIronWindãšåä»ããããæ°ããåæã¢ã¯ã»ã¹ããŠã³ããŒããŒãé ä¿¡ãããã£ãã·ã³ã°æ»æãã£ã³ããŒã³ã«é¢äžããŠããããšã確èªããŸããããã®ããŠã³ããŒããŒã«ã¯ãããŠã³ããŒããããã·ã§ã«ã³ãŒããããªã远å ã®æ»æã¹ããŒãžãç¶ããŸããã
- åæéäžãTA402ã¯é ä¿¡æ¹æ³ã調æŽããDropboxã®ãªã³ã¯ããXLLãRARãã¡ã€ã«ã®æ·»ä»ãã¡ã€ã«ã«ç§»è¡ããŸããã
- ãã®æ»æã°ã«ãŒãã¯ãäžè²«ããŠæ¥µããŠæšçãçµã£ã掻åãè¡ã£ãŠããã1åã®ãã£ã³ããŒã³ã§è¿œæ±ããçµç¹ã¯5ã€ä»¥äžã§ãããŸããäžæ±ããã³åã¢ããªã«ãæ ç¹ãšããæ¿åºæ©é¢ã«ã匷ãé¢å¿ãå¯ããŠããŸãã
- ãã«ãŒããã€ã³ãã¯2020幎ããTA402ã远跡ããŠããŸããåœç€Ÿã®ãªãµãŒãã£ãŒã¯ããã®è
åšäž»äœã¯äžæ±ã®APTïŒAdvanced Persistent Threat: é«åºŠæšçåæ»æã°ã«ãŒãïŒã°ã«ãŒãã§ãããæŽå²çã«ãã¬ã¹ããèªæ²»åºã«é¢å¿ãæã£ãп޻åããŠãããMoleratsãGaza CybergangãFrankensteinãWIRTEãšããŠå ±åãããŠããå
¬éæ
å ±ãšéè€ããŠãããšè©äŸ¡ããŠããŸãã
æŠèŠ
2023幎åã°ããã«ãŒããã€ã³ãã®ç ç©¶è ã¯ãäžæ±ã®æ¿åºãæšçã«ããã«ãŒããã€ã³ãããIronWindããšåä»ããæ°ããªåæã¢ã¯ã»ã¹ããŠã³ããŒããŒãçšããè¿·å®®ã®ãããªææãã§ãŒã³ã䜿çšããTA402ïŒMoleratsãGaza CybergangãFrankensteinãWIRTEïŒã®æŽ»åãåããŠç¢ºèªããŸããã2023幎7æãã10æã«ãããŠãTA402ã¯ãã®ææãã§ãŒã³ã®3ã€ã®ããªãšãŒã·ã§ã³ïŒDropboxãªã³ã¯ãXLLãã¡ã€ã«ã®æ·»ä»ãã¡ã€ã«ãRARãã¡ã€ã«ã®æ·»ä»ãã¡ã€ã«ïŒãå©çšããåããªãšãŒã·ã§ã³ã¯äžè²«ããŠå€æ©èœãã«ãŠã§ã¢ãå«ãDLLã®ããŠã³ããŒãã«ã€ãªãã£ãŠããŸããããããã®ãã£ã³ããŒã³ã«ãããŠãTA402ã¯ãŸããProofpointã®ãªãµãŒãã£ãŒã2021幎ãš2022å¹Žã®æŽ»åã§èŠ³æž¬ããDropbox APIã®ãããªã¯ã©ãŠããµãŒãã¹ã®å©çšãããC2éä¿¡ã®ããã«æ»æã°ã«ãŒããå¶åŸ¡ããã€ã³ãã©ã¹ãã©ã¯ãã£ã®å©çšã«è»žè¶³ãç§»ããŠããŸããã
2023幎10æäžæ¬ã®æç¹ã§ããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãæŽå²çã«ãã¬ã¹ããèªæ²»åºã«é¢å¿ãæã£ãп޻åããŠããAPTã°ã«ãŒãã§ããTA402ã«ããã¿ãŒã²ãã£ã³ã°ã®å€æŽã芳枬ããŠãããããŸãããã®å°åã«ãããçŸåšã®çŽäºã«ããããããããã³ããŒãã倿Žãããå
åã確èªããŠããŸããããã®æ»æã°ã«ãŒãããäºæ
ã®é²å±ã«å¿ããŠãªãœãŒã¹ã倿Žããå¯èœæ§ã¯æ®ã£ãŠããŸãã
ãã£ã³ããŒã³ã®è©³çŽ°ãš IronWind
2023幎7æã®æŽ»å2023幎7æããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ã2021幎ããã³2022幎以åã®ãã£ã³ããŒã³æŽ»åãšæ¯èŒããŠãTA402ã®æ°ãããããè€éãªææãã§ãŒã³ã®æåã®æ»æã芳枬ããŸããïŒå³1ããã³2ïŒã

å³1.2021幎11æãã2022幎1æãŸã§äœ¿çšãããTA402ææãã§ãŒã³

å³2.2023幎7æã®ãã£ã³ããŒã³ã§äœ¿çšãããTA402ææãã§ãŒã³
TA402ã¯ãæŒæŽ©ããå€åçã®é»åã¡ãŒã«ã¢ã«ãŠã³ãã䜿çšããäžæ±ã®æ¿åºæ©é¢ãæšçãšãããã£ãã·ã³ã°ã»ãã£ã³ããŒã³ãè¡ããŸãããã¡ãŒã«ã§ã¯ãçµæžãããŒãã«ãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®èªãæå¥ïŒãØšØ±ÙØ§Ù ج Ø§ÙØªØ¹Ø§ÙÙ Ø§ÙØ¥Ùتصاد٠٠ع دÙÙ Ù Ø¬ÙØ³ Ø§ÙØªØ¹Ø§ÙÙ Ø§ÙØ®ÙÙØ¬Ù 2023-2024ãïŒ»æ©æ¢°ç¿»èš³ïŒæ¹Ÿå²žååäŒè°è«žåœãšã®çµæžååããã°ã©ã 2023-2024"]]ïŒã䜿ã£ãŠDropboxãªã³ã¯ãé ä¿¡ããæªæã®ããMicrosoft PowerPointã¢ãã€ã³ïŒPPAMïŒãã¡ã€ã«ãããŠã³ããŒããããŸãããPPAMãã¡ã€ã«ã«ã¯ãversion.dllïŒIronWindïŒãtimeout.exeãgatherNetworkInfo.vbsã®3ã€ã®ãã¡ã€ã«ããããããããã¯ããå«ãŸããŠããŸãããtimeout.exeã¯IronWindã®ãµã€ãããŒãã«äœ¿ãããŸããããµã€ãããŒãããããšãIronWindã¯æ¢ç¥ã®TA402 C2ãã¡ã€ã³ã§ããtheconomics[.]netã«HTTP GETãªã¯ãšã¹ããéä¿¡ããŸããtheconomics[.]netã¯ã2023幎8æã®åææç¹ã§191.101.78[.]189ã«ãã¹ããããŠããŸãããProofpointã®ç ç©¶è ã¯ãå°ãªããšã2021幎12æä»¥éãTA402ããã«ãŠã§ã¢é ä¿¡ã«DropboxãæŽ»çšããŠããããšã確èªããŠããŸãã
HTTP GET ãªã¯ãšã¹ããåä¿¡ãã C2 ã¯ãææãã§ãŒã³ã®ç¬¬ 3 段éã衚ãã·ã§ã«ã³ãŒãã§å¿çããŸããããã«ãŒããã€ã³ãã®åæã§ã¯ããã®ã·ã§ã«ã³ãŒãã¯ãªãã¬ã¯ãã£ã.NETããŒãã䜿çšããŠWMIã¯ãšãªãå®è¡ããŠããŸããããã®ã·ã§ã«ã³ãŒãã¯å€ç®çããŒããŒãšããŠãæ©èœããC#ã§èšè¿°ããã.NETãã¹ã ãšã¯ã¹ããã€ã ã©ã€ãã©ãªã§ããSharpSploitã䜿çšãã.NETå®è¡ãã¡ã€ã«ã第4ã¹ããŒãžã«ããŠã³ããŒãããŸããã
.NETå®è¡ãã¡ã€ã«ã¯ãC2çšã®theconomics[.]netãžã®HTTPS POSTãšGETã䜿çšãç¶ããJSONå¿çãåä¿¡ããŸãããã«ã¹ã¿ã UserAgentæååãMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:<tag>) Gecko/<auth> Firefox/3.15ããä»ããŠèªèšŒãééããã»ãŒç¢ºå®ã«è¿œå ã®ã·ã§ã«ã³ãŒããã€ããŒããããŠã³ããŒãããŸããããã«ãŒããã€ã³ãã®åæã«ãããšããã®UserAgentã¯æ€åºç®çã«äœ¿çšã§ããã»ã©ãŠããŒã¯ãªãã®ã§ãããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãåæã®æç¹ã§ã¯ç¬¬5ã¹ããŒãžã芳枬ããŠããŸããã§ããããæçµã¹ããŒãžã®ãã€ããŒãã«æªäœ¿çšã®ã³ãŒããå«ãŸããŠããããšã«æ³šç®ããŠãããTA402ããã«ãŠã§ã¢ã®ãããªãæŽæ°ãšèª¿æŽãè¡ã£ãŠããå¯èœæ§ã瀺åããŠããŸãã
2023幎8æã®æŽ»åïŒ2023幎8æãTA402㯠"ÙØ§ØŠÙ Ø© Ø§ÙØ£ØŽØ®Ø§Øµ ÙØ§ÙÙÙØ§Ùات (اÙ٠صÙÙØ© Ø¥Ø±ÙØ§ØšÙØ©) Ù Ù "ã䜿çšããŠIronWindãããŒãããããã«æ·»ä»ã®XLLãã¡ã€ã«ãéä¿¡ããããã«å€æŽããŸãããÙØšÙ ÙÙØŠØ© Ù ÙØ§ÙØØ© غسÙÙ Ø§ÙØ£Ù ÙØ§Ù ÙØªÙ ÙÙÙ Ø§ÙØ¥Ø±Ùاؚ "ããDropboxçµç±ã§é ä¿¡ãããæªæã®ããPPAMãã¡ã€ã«ã䜿çšãã代ããã«ã«ã¢ãŒãšããŠäœ¿çšããŸãããã®ã«ã¢ãŒãæ©æ¢°ç¿»èš³ãããšä»¥äžã®ããã«ãªããŸãïŒ"åãããŒãã³ããªã³ã°ããã³ããè³é調éå±ã«ããïŒãããªã¹ããšããŠæå®ãããïŒå人ããã³å£äœã®ãªã¹ã"ãTA402ã¯ã7æã®æŽ»åã§ç¢ºèªãããã®ãšåã屿®åããå€åçã®é»åã¡ãŒã«ã¢ã«ãŠã³ãã䜿çšããŠããŸãããæåã®ææããã»ã¹ã®äžç°ãšããŠãTA402ã¯Request InspectorïŒHTTPãªã¯ãšã¹ãçšã®ãšã³ããã€ã³ããäœæãããµãŒãããŒãã£ãµãŒãã¹ïŒã«base64ãšã³ã³ãŒãããããã§ãã¯ã€ã³ãéä¿¡ããããã€ãã®ã·ã¹ãã æ å ±ãæµåºãããŸããã
2023幎10æã®æŽ»åïŒ2023幎10æãTA402ã¯åã³ææçµè·¯ã®äžéšã倿ŽããŸãããä»åã¯ãDropboxçµç±ã§é ä¿¡ãããæªæã®ããPPAMãã¡ã€ã«ãæ·»ä»ãããXLLãã¡ã€ã«ã䜿çšããŠãã«ãŠã§ã¢ãããŒãããã®ã§ã¯ãªããIronWindãšpropsys.dllïŒIronWindïŒããµã€ãããŒãããããã®tabcal.exeã®ãªããŒã ããŒãžã§ã³ãå«ãRARãã¡ã€ã«ãæ·»ä»ããŠéä¿¡ããŸãããé ä¿¡ããããã«ãŠã§ã¢ã¯ãåæãã§ãã¯ã€ã³ã«Request Inspectorãåã³äœ¿çšããæ°ããTA402 C2ãã¡ã€ã³ã§ããinclusive-economy[.]comã䜿çšããŸããã
TA402ã¯ãŸããæŒæŽ©ããå€åçã®é»åã¡ãŒã«ã»ã¢ã«ãŠã³ããå©çšããŠã"ØªÙØ±ÙÙÙØ± ÙØªÙصÙÙÙØ§Øª اÙÙÙÙØ±Ø© (110) ØšØ®ØµÙØµ Ø§ÙØØ±Øš عÙÙØºØ²Ø© "[æ©æ¢°ç¿»èš³ïŒã¬ã¶æŠäºã«é¢ãã第110äŒæã®å ±åãšå§å]ãšããèªãæå¥ã®ãã£ãã·ã³ã°ã»ã¡ãŒã«ãéãç¶ããŸãããçŸåšãTA402ã¯çŽäºããã³ãå¯ããç®çã§å©çšããŠããããã«ããèŠããŸãããããã«ãTA402ã¯ãã£ãã·ã³ã°ãç¶ããŠãããçŽäºãã°ã«ãŒãã®æŽ»åã倧ãã劚害ããŠããªãããšã瀺ããŠããŸãã
IronWind: PDB åæ
ãã«ãŠã§ã¢ã®åæã«ãããŠãProofpointã®ãªãµãŒãã£ãŒã¯ãTA402ããã«ãŠã§ã¢éçºäžã«ã°ã«ãŒãã®PDBãã¹ãè€æ°ã®æ®µéã§ãµãã¿ã€ãºããŠããªãã£ãããšãç¹å®ããŸããããã³ãã£ã³ã°ãç®çãšããYARAã«ãŒã«ã¯ããã®ããã°ã®æåŸã«æ·»ä»ãããŠããŸãã
以äžã®PDBãã¹ã«åºã¥ãããã«ãŒããã€ã³ã瀟ã®ç ç©¶è ã¯ãIronWindãã«ãŠã§ã¢ã®ãããžã§ã¯ãåã¯ã \tornado ãã§ããããã«ãŠã§ã¢ã®éçºã¯IAïŒIronWindãããããŒïŒãã¹ããŒãžã£ãŒïŒã¹ããŒãžã£ãŒDLLïŒããã€ããŒããå«ãæ©èœå¥ã«åãããŠãããšãäžçšåºŠã®ä¿¡é Œæ§ããã£ãŠè©äŸ¡ããŠããŸãã
- VT ã¹ããŒãž 1: C:\Users\Win\Desktop\Reno\NewTor\27-07-2023\tornado\tornado\Payloads\BAR_33\I.A\out\IA.pdb
- 2023幎7æ ã¹ããŒãž2: C:\Users\User\Desktop\tornado\Payloads\WKS_10\I.A\out\stagerx64.pdb
- 2023幎8æ ã¹ããŒãž 1: C:\Users\Win\Desktop\Reno\NewTor\27-07-2023\tornado\tornado\Payloads\BAR_38\I.A\out\IA.pdb
- 2023幎8æ ã¹ããŒãž 2: C:\Users\Win\Desktop\Reno\NewTor\NewIA-Tornado-WithStealer\Payloads\KIL_03\I.A\out\stagerx64.pdb
- ã¹ããŒãž 4: K:\prj\WIP\C# - Payload\Client-Side\https\client-Divided\KALV\obj\Release\KALV.pdb
ãžãªãã§ã³ã·ã³ã°
TA402ã¯å®æçã«ãžãªãã§ã³ã·ã³ã°ã®ãã¯ããã¯ãæ¡çšããæªæã®ããæŽ»åã®æ€ç¥ãå°é£ã«ããŠããŸããæ»æã°ã«ãŒãã®æŠè¡ãæè¡ãæé ã®ãã®åŽé¢ã¯ãå°ãªããšã2020幎以éäžè²«ããŠããŸãã2023幎ã«èŠ³æž¬ããããããç²Ÿå·§ãªææãã§ãŒã³ã«ãããŠããTA402ã¯ããžãªãã§ã³ã·ã³ã°ãåé¿ãããªãå Žåãæ£èŠã®ããã¥ã¡ã³ããã¹ãã£ã³ã°ãã©ãããã©ãŒã ã§ãã¹ããããŠããããšãããã¥ã¡ã³ãã«ãªãã€ã¬ã¯ããããURLãåŒãç¶ãå«ãã§ããŸãã
ã¢ããªãã¥ãŒã·ã§ã³
ãã«ãŒããã€ã³ãã®ç ç©¶è ã¯ãæŠè¡ããã¯ããã¯ã被害è ã®ç¹åŸŽããããããã®ãã£ã³ããŒã³ã¯TA402ã®ãã®ã§ãããšæšå®ããŠããŸãã2023幎ã®ãã£ã³ããŒã³ã¯ãéå»ã®TA402ã®æŽ»åãšé¡äŒŒããããŒãã®èªãæå¥ãå ±æããŠãããäžæ±ã«äœçœ®ããã¢ã©ãã¢èªã話ãã¿ãŒã²ããã«çŠç¹ãåœãŠãŠããŸããé·å¹Žã«ããããTA402ã¯äžè²«ããŠäžæ±ããã³åã¢ããªã«ã«æ ç¹ãçœ®ãæ¿åºæ©é¢ãæšçãšããŠãããæã«ã¯åãæšçãç¹°ãè¿ãçãããšããããŸãããTA402ã¯ãå€åçã®é»åã¡ãŒã«ã¢ã«ãŠã³ãã®æŒæŽ©ããžãªãã§ã³ã·ã³ã°ãããã³ããšãææžã䜿çšããŠããããšããä»åã®ã¢ããªãã¥ãŒã·ã§ã³ã®äžèŠçŽ ãšãªããŸããã
ãŸãããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãTA402ãæ
å ±åéã«éç¹ã眮ãããã¬ã¹ããã®ã¹ãã€æŽ»åãæ¯æŽããŠãããšè©äŸ¡ããŠããŸããããã¯ããã®æ»æã°ã«ãŒãã«é¢ãããã«ãŒããã€ã³ãã®éå»ã®å
¬éã¬ããŒããšäžèŽããŠããŸãããã«ãŒããã€ã³ãã¯ãTA402ãMoleratsãWIRTEãFrankensteinãªã©ãå
¬ã«å ±åãããŠããå€ãã®æ»æã°ã«ãŒããšéè€ããŠããããšãèªèããŠããŸããããã«ãŒããã€ã³ãã®ç ç©¶è
ã¯ã瀟å
ã®ãã«ãŠã§ã¢åæããã³èª¿æ»ã«åºã¥ããŠç¬èªã«åé¡ããŠããŸãã
çµè«
2020幎以éããã«ãŒããã€ã³ãããã®è
åšã远跡ããçµæãTA402ã¯äŸç¶ãšããŠæç¶çãã€é©æ°çãªè
åšã§ããããµã€ããŒã¹ãã€æŽ»åãæ¯æŽããããã«æ»æææ³ããã«ãŠã§ã¢ãæ¥åžžçã«æŽæ°ããŠããŸãããžãªãã§ã³ã·ã³ã°ãããšãææžã®ç¶ç¶çãªäœ¿çšã¯ãæ€ç¥ãåé¿ããããã®åªåãç¶ããŠããŸããTA402ã¯äžæ±ãåã¢ããªã«ã®æ¿åºæ©é¢ã«ç¹åããæ
å ±åéã«éç¹ãçœ®ãæ»æã°ã«ãŒãã§ãããçŸåšé²è¡äžã®ã€ã¹ã©ãšã«ãšããã¹ã®çŽäºã«åå¿ããŠãã¿ãŒã²ããããœãŒã·ã£ã«ã»ãšã³ãžãã¢ãªã³ã°ã®èªãæå¥ã調æŽããããæç€ºãããå¯èœæ§ããããŸãã
IoC(Indicators of Compromise/ 䟵害ã®çè·¡)
|
INDICATOR |
TYPE |
|
9b2a16cbe5af12b486d31b68ef397d6bc48b2736e6b388ad8895b588f1831f47
5d773e734290b93649a41ccda63772560b4fa25ba715b17df7b9f18883679160
19f452239dadcd7544f055d26199cb482c1f6ae5486309bde1526174e926146a
A4bf96aee6284effb4c4fe0ccfee7b32d497e45408e253fb8e1199454e5c65a3
26cb6055be1ee503f87d040c84c0a7cacb245b4182445e3eee47ed6e073eca47
cbb89aac5a2c93a02305846f9353b013e6703813d4b6baff8eb89ee938647af3
c98dc0b930ea67992921d9f0848713deaa5bba8b4ba21effd0b00595dd9ed28c
ac227dd5c97a36f54e4fa02df4e4c0339b513e4f8049616e2a815a108e34552f
6ab5a0b7080e783bba9b3ec53889e82ca4f2d304e67bd139aa267c22c281a368
e2ba2d3d2c1f0b5143d1cd291f6a09abe1c53e570800d8ae43622426c1c4343c
d8cde28cf2a5884daddf6e3bc26c80f66bc3737e426b4ba747d49d154999fbc1
81fc4a5b1d22efba961baa695aa53201397505e2a6024743ed58da7bf0b4a97f
3b2a6c7a39f49e790286185f2d078e17844df1349b713f278ecef1defb4d6b04
7bddde9708118f709b063da526640a4132718d3d638505aafce5a20d404b2761
883e035f893483b9921d054b3fa014cef90d90b10dcba7d342def8be2e98ce3c
4b0a48d698240504c4ff6275dc735c8162e57f92224fb1d2d6393890b82a4206
4018b462f2fcf1b0452ecd88ab64ddc5647d1857481f50fa915070f5f1858115
3d80ea70b0c00d12f2ba2c7b1541f7d0f80005a38a173e6962b24f01d4a2a1de |
SHA256 |
|
theconomics[.]net |191.101.78[.]189 |
Domain | IP (C2) |
|
inclusive-economy[.]com healthcaption[.]com |
Domains |
ET Signatures
- 2049153 - ET MALWARE Win32/TA402 CnC User-Agent
- 2049154 - ET MALWARE Win32/TA402 CnC Response M1
- 2049155 - ET MALWARE Win32/TA402 CnC Response M2
- 2049158 - ET MALWARE Win32/TA402 Checkin
- 2049159 - ET MALWARE Win32/TA402 Checkin M2
- 2049160 - ET MALWARE TA402 CnC Domain in DNS Lookup
- 2049161 - ET MALWARE Observed TA402 Domain in TLS SNI
- 2049162 - ET MALWARE TA402 CnC Domain in DNS Lookup
- 2049163 - ET MALWARE Observed TA402 Domain in TLS SNI
- 2049164 - ET MALWARE Win32/TA402 CnC Activity (POST)
- 2049165 - ET MALWARE Win32/TA402 CnC Activity (GET)
YARA Rule
rule TA402_PDB
{ meta:
author = "Proofpoint inc."
description = "Finds TA402 related PDB paths"
date = â2023-09-27â
strings:
$pdb1 = "C:\\Users\\Win\\Desktop\\Reno\\NewTor" ascii wide
$pdb2 = "C:\\Users\\User\\Desktop\\tornado\\" ascii wide
$pdb3 = "K:\\prj\\WIP\\C# - Payload\\Client-Side\\https\\client-Divided\\KALV\\obj\\Release\\KALV.pdb" ascii wide
$pdb4 = "K:\\prj\\WIP\\C# - Payload\\Client-Side" ascii wide
condition:
any of them
}