äž»ãªèª¿æ»çµæ
- Proofpoint ã¯ãTryCloudflare ãã³ãã«ãæªçšãããã«ãŠã§ã¢é ä¿¡ã®å¢å ã確èªããŠããŸãã
- ãã®æŽ»åã¯ééçãªåæ©ã«åºã¥ããã®ã§ããªã¢ãŒãã»ã¢ã¯ã»ã¹åã®ããã€ã®æšéЬïŒRATïŒãé ä¿¡ããŠããŸãã
- æåã®èŠ³æž¬ä»¥æ¥ããã£ã³ããŒã³ã®èåŸã«ããè åšã®æŽ»åã¯ãæ€ç¥ãåé¿ããæå¹æ§ãåäžãããããã«ãæŠè¡ãæè¡ãæé ã倿ŽããŠããŠããŸãã
- ãã«ãŒããã€ã³ã瀟ã§ã¯ããã®æŽ»åããããŸã§ã«è¿œè·¡ããŠããã¢ããªãã¥ãŒã·ã§ã³ãããæ»æã°ã«ãŒãïŒãã«ãŒããã€ã³ãã§ã¯TAãé æåãšããŠåœå)ã«ãããã®ã§ã¯ãªããšèããŠããŸãããçŸåšèª¿æ»äžã§ãã
æŠèŠ
Proofpointã¯ãCloudflareãã³ãã«ã掻çšããŠãã«ãŠã§ã¢ãé ä¿¡ãããµã€ããŒç¯çœªã®è åšæŽ»åã远跡ããŠããŸããå ·äœçã«ã¯ãæ»æè ãã¢ã«ãŠã³ããäœæããã«1åéãã®ãã³ãã«ãäœæã§ãã TryCloudflare æ©èœãæªçšãããã®ã§ãããã³ãã«ã¯ãä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ïŒVPNïŒãã»ãã¥ã¢ã·ã§ã«ïŒSSHïŒãããã³ã«ã䜿çšããããã«ãããŒã«ã«ãããã¯ãŒã¯äžã«ãªãããŒã¿ããªãœãŒã¹ã«ãªã¢ãŒãã¢ã¯ã»ã¹ããæ¹æ³ã§ãã
2024幎2æã«åããŠèŠ³æž¬ããããã®ã¯ã©ã¹ã¿ãŒã¯ã5æãã7æã«ãããŠæŽ»åãæŽ»çºåãããããæ°ã«æã¯ã»ãšãã©ã®æ»æãã£ã³ããŒã³ããªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒã§ããXwormã«ã€ãªãããã®ã§ããã
ã»ãšãã©ã®ãã£ã³ããŒã³ã§ã¯ãã¡ãã»ãŒãžã«ã€ã³ã¿ãŒãããã·ã§ãŒãã«ããïŒ.URLïŒãã¡ã€ã«ã«ã€ãªããURLãŸãã¯æ·»ä»ãã¡ã€ã«ãå«ãŸããŠããŸããå®è¡ããããšãéåžžã¯WebDAVçµç±ã§å€éšãã¡ã€ã«å ±æãžã®æ¥ç¶ã確ç«ããLNKãŸãã¯VBSãã¡ã€ã«ãããŠã³ããŒãããŸããå®è¡ããããšãLNK/VBSã¯BATãŸãã¯CMDãã¡ã€ã«ãå®è¡ããPythonã€ã³ã¹ããŒã©ããã±ãŒãžãšãã«ãŠã§ã¢ã®ã€ã³ã¹ããŒã«ã«ã€ãªããäžé£ã®Pythonã¹ã¯ãªãããããŠã³ããŒãããŸããå Žåã«ãã£ãŠã¯ããã¡ã€ã«ã¹ããŒãžã³ã°ã¯search-msãããã³ã«ãã³ãã©ã掻çšããWebDAVå ±æããLNKãååŸããŸããéåžžããã®æ»æãã£ã³ããŒã³ã§ã¯ãæ£èŠã®éä¿¡ã«èŠããããã«è¯æ§ã®PDFããŠãŒã¶ãŒã«è¡šç€ºãããŸãã
6æãš7æã«èŠ³æž¬ããããã£ã³ããŒã³ã®ã»ãŒãã¹ãŠãXwormãé ä¿¡ããŠããŸãããã以åã®ãã£ã³ããŒã³ã§ã¯AsyncRATãVenomRATãGuLoaderãRemcosãé ä¿¡ããŠããŸããããã£ã³ããŒã³ã«ãã£ãŠã¯ãè€æ°ã®ç°ãªããã«ãŠã§ã¢ã®ãã€ããŒãã«ã€ãªãããã®ããããããããåºæã®Pythonã¹ã¯ãªãããç°ãªããã«ãŠã§ã¢ã®ã€ã³ã¹ããŒã«ã«ã€ãªãããŸãã

Trycloudflareãã³ãã«ã掻çšããé¢é£ãã£ã³ããŒã³ã§ç¢ºèªããããã«ãŠã§ã¢
æ»æãã£ã³ããŒã³ã¡ãã»ãŒãžã®éã¯ãæ°çŸããæ°äžã«åã³ãäžçäžã®æ°åããæ°åã®çµç¹ã«åœ±é¿ãäžããŠããŸããè±èªã ãã§ãªãããã©ã³ã¹èªãã¹ãã€ã³èªããã€ãèªã®ã«ã¢ãŒã確èªãããŠããŸããXwormãAsyncRATãVenomRATã®ãã£ã³ããŒã³ã¯ãRemcosãGuLoaderãé ä¿¡ãããã£ã³ããŒã³ãããéãå€ãããšãã»ãšãã©ã§ããã«ã¢ãŒã®ããŒãã¯ããŸããŸã§ãããäžè¬çã«ã¯è«æ±æžãææžèŠæ±ãè·ç©ã®é éãçšéãªã©ãããžãã¹ã«é¢é£ãããããã¯ãå«ãŸããŠããŸãã
æ»æãã£ã³ããŒã³ã®æŠè¡ãæè¡ãæé ïŒTTPïŒã¯äžè²«ããŠããŸãããæ»æè ã¯æ»æãã§ãŒã³ã®ããŸããŸãªéšåã倿Žããå·§åŠåãšé²åŸ¡åé¿ãé«ããŠããããã§ããããšãã°ãåæã®ãã£ã³ããŒã³ã§ã¯ããã«ã㌠ã¹ã¯ãªããã®é£èªåã¯ã»ãšãã©è¡ãããŠããŸããã§ãããã¹ã¯ãªããã«ã¯ãã³ãŒãã®æ©èœæ§ã«é¢ãã詳现ãªã³ã¡ã³ããå«ãŸããŠããããšããããããŸããããããã6æã«å ¥ããæ»æè ãã³ãŒãã«é£èªåãçµã¿èŸŒãããã«ãªããšããã®ç¶æ³ã¯äžå€ããŸããã

é£èªåãªãã®ãã«ããŒã¹ã¯ãªããïŒ2024幎5æã®ãã£ã³ããŒã³ã®äŸïŒ

é£èªåãæœãããã«ããŒã¹ã¯ãªããïŒ2024幎6æãã£ã³ããŒã³ã®äŸïŒ
TryCloudflare ãã³ãã«ã®è
åšè
ã«ããæªçšã¯2022å¹Žã«æµè¡ãããµã€ããŒç¯çœªè
ã®éã§å¢å ããŠããããã§ãã TryCloudflareãã³ãã«ã®å䜿çšã¯ãäŸãã°ride-fatal-italic-information[.]trycloudflare[.]comã®ããã«ãtrycloudflare[.]comäžã«ã©ã³ãã ãªãµããã¡ã€ã³ãçæããŸãããµããã¡ã€ã³ãžã®ãã©ãã£ãã¯ã¯ãCloudflareãä»ããŠéå¶è
ã®ããŒã«ã«ãµãŒããŒã«ãããã·ãããŸãã
æ»æãã£ã³ããŒã³äŸ
AsyncRAT / Xworm æ»æãã£ã³ããŒã³ïŒ2024幎5æ28æ¥ïŒ
ãã«ãŒããã€ã³ãã¯ã2024幎5æ28æ¥ã« AsyncRAT ãš Xworm ãé ä¿¡ãããã£ã³ããŒã³ã芳枬ããŸããããã®æ»æãã£ã³ããŒã³ã§ã¯ãçšéãããŒãã«ããã¡ãã»ãŒãžã«zip圢åŒã®.URLãã¡ã€ã«ã«ã€ãªããURLãå«ãŸããŠããŸããããã®ãã£ã³ããŒã³ã¯æ³åŸãšéèã®çµç¹ãæšçãšããŠãããåèš50ä»¶æªæºã®ã¡ãã»ãŒãžãå«ãŸããŠããŸããã

2024幎5æ28æ¥ 2023幎ã®çšéãããŒãã«ããããšãã¡ãŒã«
.URLãã¡ã€ã«ã¯ãªã¢ãŒãã®.LNKãã¡ã€ã«ãæããŠããŸãããå®è¡ããããšãCMDãã«ããŒã¹ã¯ãªãããPowerShellãåŒã³åºããå§çž®ãããPythonããã±ãŒãžãšPythonã¹ã¯ãªãããããŠã³ããŒãããŸããPythonããã±ãŒãžãšã¹ã¯ãªããã¯ãAsyncRATãšXwormã®ã€ã³ã¹ããŒã«ã«ã€ãªãããŸããã

2024幎5æ28æ¥ã®æ»æãã§ãŒã³
2024幎7æ11æ¥ïŒAsyncRAT / Xworm æ»æãã£ã³ããŒã³
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ã2024幎7æ11æ¥ã«Cloudflareã®ãã³ãã«ã掻çšããŠAsyncRATãšXwormãé åžããå¥ã®æ»æãã£ã³ããŒã³ã芳枬ããŸããããã®æ»æãã£ã³ããŒã³ã«ã¯ãéèã補é ããã¯ãããžãŒãªã©ã®çµç¹ãæšçãšãã1,500ãè¶ ããã¡ãã»ãŒãžãå«ãŸããŠããŸããã

7æ11æ¥ãè«æ±æžçºè¡ã®ããŒããçšããããšãã¡ãŒã«
è峿·±ãããšã«ããã®æ»æãã£ã³ããŒã³ã®ã¡ãã»ãŒãžã«ã¯ãLNKãã¡ã€ã«ãæãsearch-msã¯ãšãªãå«ãHTMLæ·»ä»ãã¡ã€ã«ãå«ãŸããŠãããå®è¡ããããšãé£èªåãããBATãã¡ã€ã«ã«ã€ãªãããPowerShellãåŒã³åºããŠPythonã€ã³ã¹ããŒã©ã»ããã±ãŒãžãšAsyncRATããã³Xwormãå®è¡ããã¹ã¯ãªãããããŠã³ããŒãããŸãã

2024 幎 7 æ 11 æ¥ æ»æãã§ãŒã³
ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®çŽã¥ãïŒ
ãã£ã³ããŒã³ã§èгå¯ãããæŠè¡ãæè¡ãæé ïŒTTPïŒã«åºã¥ãããã«ãŒããã€ã³ãã¯ããããã®æŽ»åãé¢é£ãã1ã€ã®ã¯ã©ã¹ã¿ãŒã«èµ·å ãããšè©äŸ¡ããŠããŸãããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ããã®æŽ»åãç¹å®ã®æ»æã°ã«ãŒããšæå®ããŠããŸãããã調æ»ã¯ç¶ç¶äžã§ãã
ãªããããéèŠãªã®ã
Cloudflareãã³ãã«ã®äœ¿çšã¯ãæ»æè ãäžæçãªã€ã³ãã©ã䜿çšããŠæ¥åãæ¡åŒµããæ¹æ³ãæäŸããã¿ã€ã ãªãŒã«ã€ã³ã¹ã¿ã³ã¹ãæ§ç¯ããã³åæ¢ããæè»æ§ãæäŸããŸããããã«ãããé²åŸ¡åŽãéçãããã¯ãªã¹ãã«äŸåãããããªåŸæ¥ã®ã»ãã¥ãªãã£å¯Ÿçã¯å°é£ã«ãªããŸããäžæçãªCloudflareã€ã³ã¹ã¿ã³ã¹ã«ãããæ»æè ã¯äœã³ã¹ãã§ãã«ããŒã¹ã¯ãªããã䜿ã£ãæ»æãè¡ãããšãã§ããŸãã
æ»æè ããã«ãŠã§ã¢ã®é ä¿¡ã«Pythonã¹ã¯ãªããã䜿çšããŠããããšã¯æ³šç®ã«å€ããŸããPythonã¹ã¯ãªãããšäžç·ã«Pythonã©ã€ãã©ãªãšå®è¡å¯èœãªã€ã³ã¹ããŒã©ãããã±ãŒãžåããããšã§ãPythonãã€ã³ã¹ããŒã«ãããŠããªããã¹ãã§ããã«ãŠã§ã¢ãããŠã³ããŒãããŠå®è¡ã§ããããã«ããŠããŸããPythonãå人ã®è·åã«å¿ èŠã§ãªãå Žåãçµç¹ã¯Pythonã®äœ¿çšãå¶éãã¹ãã§ãããªãµãŒãã£ãŒããã«ãŠã§ã¢ãã¡ã€ã«ãšäžç·ã«ãœãããŠã§ã¢ããã±ãŒãžãé ä¿¡ãããã®ã確èªããã®ã¯ä»åãåããŠã§ã¯ãããŸãããããæ°ã«æããã«ãŒããã€ã³ãã¯ãããŠã³ããŒããŒããããããŒãå®è¡ããåã«æ£ãããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããŠããããšã確èªããããã«ãJARãšJavaå®è¡ç°å¢ïŒJREïŒãZIPå ã«ãã³ãã«ããJavaããŒã¹ã®ãã«ãŠã§ã¢ãé ä¿¡ããæ»æãã£ã³ããŒã³ã確èªããŠããŸãã
ãã®æ»æãã§ãŒã³ã§ã¯ãæªæã®ãããªã³ã¯ãã¯ãªãã¯ããããLNKãVBSãã¡ã€ã«ãªã©ã®è€æ°ã®ãã¡ã€ã«ãããã«ã¯ãªãã¯ããããå§çž®ãããã¹ã¯ãªãããè§£åããããããªã©ãæçµçãªãã€ããŒããççºãããããã«è¢«å®³è ãå€å€§ãªæäœãè¡ãå¿ èŠããããŸãããã®ãããåä¿¡è ã¯äžå¯©ãªæŽ»åãç¹å®ããæ»æãæåããåã«æ»æãã§ãŒã³ãäžæãããæ©äŒãäœåºŠãåŸãããšãã§ããŸãã
ãµã€ããŒç¯çœªè
ã®ãšã³ã·ã¹ãã ãããŸããŸãªTTPã詊ãç¶ããŠããããããã€ããŒãã®ã¹ããŒãžã³ã°ãé
ä¿¡ã«WebDAVãSMBïŒServer Message BlockïŒã䜿çšããè
åšè
ãå¢ããŠããŸããçµç¹ã¯ãå€éšã®ãã¡ã€ã«å
±æãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ããæ¢ç¥ã®å®å
šãªãµãŒãã®ã¿ã«å¶éããå¿
èŠããããŸãã
Emerging Threats ã·ã°ããã£
Emerging Threatsã«ãŒã«ã»ããã«ã¯ããããã®ãã£ã³ããŒã³ã§ç¢ºèªããããã«ãŠã§ã¢ã®æ€åºãå«ãŸããŠããŸãã
Examples:
2853193 | ETPRO MALWARE Win32/Xworm V3 CnC Command â PING Outbound
2852870 | ETPRO MALWARE Win32/Xworm CnC Checkin â Generic Prefix Bytes
2852923 | ETPRO MALWARE Win32/Xworm CnC Checkin â Generic Prefix Bytes (Client)
2855924 | ETPRO MALWARE Win32/Xworm V3 CnC Command â PING Outbound
2857507 | ETPRO ATTACK_RESPONSE Suspicious HTML Serving Abused URL Linking Method Observed
IoC (Indicators of Compromise: äŸµå®³ææšïŒã®ãµã³ãã«
|
Indicator |
Description |
First Observed |
|
spectrum-exactly-knitting-rural[.]trycloudflare[.]com |
Trycloudflare Host |
May 2024 |
|
53c32ea384894526992d010c0c49ffe250d600b9b4472cce86bbd0249f88eada |
.URL SHA256 |
May 2024 |
|
a79fbad625a5254d4f7f39461c2d687a1937f3f83e184bd62670944462b054f7 |
LNK SHA256 |
May 2024 |
|
0f1118b30b2da0b6e82f95d9bbf87101d8298a85287f4de58c9655eb8fecd3c6 |
CMD SHA256 |
May 2024 |
|
157[.]20[.]182[.]172 |
Xworm C2 IP |
May 2024 |
|
dcxwq1[.]duckdns[.]org |
AsyncRAT C2 |
May 2024 |
|
a40f194870b54aeb102089108ecf18b3af9b449066a240f0077ff4edbb556e81 |
HTML SHA256 |
July 2024 |
|
3867de6fc23b11b3122252dcebf81886c25dba4e636dd1a3afed74f937c3b998 |
LNK SHA256 |
July 2024 |
|
ride-fatal-italic-information[.]trycloudflare[.]com |
Trycloudflare Host |
July 2024 |
|
0fccf3d1fb38fa337baf707056f97ef011def859901bb922a4d0a1f25745e64f |
BAT SHA256 |
July 2024 |
|
todfg[.]duckdns[.]org |
AsyncRAT C2 |
July 2024 |
|
welxwrm[.]duckdns[.]org |
Xworm C2 |
July 2024 |
|
xwor3july[.]duckdns[.]org |
Xworm C2 |
July 2024 |