æŠèŠ
Kronosãã³ãã³ã°åããã€ã®æšéЬã¯ã2014å¹Žã«æåã«çºèŠãããçªç¶å§¿ãæ¶ããŸã§ã®æ°å¹Žéãè åšç°å¢ã«ãããŠå€§ããªååšæãæã£ãŠããŸããããã®Kronosã®æ°ããå€çš®ããã®æ¥ç»å ŽãããããŸã§ã«ãã€ããæ¥æ¬ãããŒã©ã³ããã¿ãŒã²ããã«ããæ»æãå°ãªããšã3åè¡ãããŸããã
2018幎4æããã³ãã³ã°åããã€ã®æšéŠ¬ã®æ°ããå€çš®ã®æåã®ãµã³ãã«ããã£ãŒã«ãã§çºèŠãããŸãã[2]ãæã泚ç®ãã¹ãæ°æ©èœã¯ãC&CïŒCommand and ControlïŒã®ã¡ã«ããºã ãTorã®å¿ååãããã¯ãŒã¯ã䜿çšããããã«ãªãã¡ã¯ã¿ãªã³ã°ãããŠããããšã§ããKronosã®ãã®æ°ããããŒãžã§ã³ã "Osiris"ãšæ¹åãããéåžå Žã§è²©å£²ãããŠããããšã瀺åããããã€ãã®æšå®ããã³ç¶æ³èšŒæ ããããŸãããã®ããã°ã§ã¯ããã€ããæ¥æ¬ãããŒã©ã³ããçã£ãæ»æã«é¢ããæ å ±ãšãæªã éçºäžãšã¿ããããã¹ãäžã®ç¬¬4ã®æ»æã«ã€ããŠç޹ä»ããŸãã
æ»æã®è§£æ
ãã€ããçã£ãæ»æã2018幎6æ27-30æ¥
2018幎6æ27æ¥ã«ããã€ãã®ãŠãŒã¶ãŒã察象ãšããæªæã®ããããã¥ã¡ã³ãã䌎ãEã¡ãŒã«æ»æãè¡ãããŸãããã¡ãã»ãŒãžïŒå³1ïŒã¯ãã€ãã®éèäŒç€Ÿããéããããã®ã§ãä»¶åã¯ä»¥äžã«ãªã£ãŠããŸãïŒ
Aktualisierung unsere AGBs (translated: âUpdating our terms and conditionsâ)
Mahnung: 9415166 (translated: âReminder: 9415166â)
æ·»ä»ãããããã¥ã¡ã³ããåãããŒãã§äœãããŠãããæ¬¡ã®ãããªãã¡ã€ã«åã§ããïŒ
agb_9415166.doc
Mahnung_9415167.

å³1ïŒãã€ãã®æ»æã§äœ¿çšãããEã¡ãŒã«ã®äŸ
ãã®Wordææžã«ã¯ãKronosãã³ãã³ã°åããã€ã®æšéŠ¬ã®æ°ããäºçš®ãããŠã³ããŒãããŠå®è¡ãããã¯ããå«ãŸããŠããŸããããã¯ããæå¹ã«ãªã£ãŠããã°ãå®è¡ãããŠããŸããŸããããã€ãã®ã±ãŒã¹ã§ã¯ãæ»æã®äžæ®µã§Smoke Loaderã䜿çšãããŠããŸãããKronosã¯C&C URLãšããŠhttp://jhrppbnh4d674kzh[.]onion/kpanel/connect.phpã䜿çšããããã«èšå®ããããã€ãã®5ã€ã®éèæ©é¢ã察象ãšããWebinjectãããŠã³ããŒãããŸããå³2ã«ãWebinjectã®äŸã瀺ããŸãã

å³2ïŒãã€ãã®æ»æã§äœ¿ãããWebinjectã®äŸ
æ¥æ¬ãçã£ãæ»æã2018幎7æ13æ¥
Proofpointã¯ã»ãã¥ãªãã£ç ç©¶è ã®ãã€ãŒã[3]ã«åºã¥ããæªæã®ããJavaScriptã€ã³ãžã§ã¯ã·ã§ã³ãå«ããµã€ãã«ç ç²è ãéããããã«ãã¿ã€ãžã³ã°ãã§ãŒã³ã調ã¹ãŸããããã®JavaScriptã¯ãSmokeLoaderããŠã³ããŒããŒãã«ãŠã§ã¢ãé åžããŠããRIGãšã¯ã¹ããã€ããããã«ç ç²è ããªãã€ã¬ã¯ãããŸãããã®ããŠã³ããŒããŒã®ããã®C&Cã¯ä»¥äžã®éãã§ãïŒ
hxxp://lionoi.adygeya[.]su
hxxp://milliaoin[.]info
以åãã®æ»æã«é¢ãã£ãè åšã¢ã¯ã¿ãŒã®è¿œè·¡çµæãããZeus Pandaãã³ãã³ã°åããã€ã®æšéЬïŒå³3ïŒãçŸããããšãæåŸ ããŸããããããä»åãæçµçãªãã€ããŒãã¯Kronosã®æ°ããããŒãžã§ã³ã§ããïŒå³4ïŒã

å³3ïŒãã®è åšã¢ã¯ã¿ãŒãéå»ã«SmokeLoaderãšZeus Pandaãé ä¿¡ããæ»æ

å³4ïŒåãè åšã¢ã¯ã¿ãŒã7æ14æ¥ã«è¡ã£ãKronosã䜿ã£ãæ°ããæ»æ
ãã®ãã£ã³ããŒã³ã§ã¯ãKronosã¯C&CãšããŠhttp://jmjp2l7yqgaj5xvv[.]onion/kpanel/connect.phpã䜿çšãããã®Webinjectã¯13ç®æã®æ¥æ¬ã®éèæ©é¢ã察象ãšããŠããŸãããå³5ã«ããã®ãã£ã³ããŒã³ã®Webinjectã®äŸã瀺ããŸãã

å³5ïŒæ¥æ¬ã®æ»æã§äœ¿ãããWebinjectã®äŸ
ããŒã©ã³ããçã£ãæ»æã2018幎7æ15-16æ¥
2018幎7æ15æ¥ãããããŒã©ã³ãã®ãŠãŒã¶ãŒã察象ãšããæªæã®ããããã¥ã¡ã³ãã䌎ãEã¡ãŒã«æ»æãè¡ãããŸãããã¡ãã»ãŒãžã«ã¯ãFaktura 2018.07.16ããªã©ã®åœã®è«æ±æžã«é¢é£ããä»¶åã䜿çšããããfaktura 2018.07.16.docããšããæ·»ä»ãã¡ã€ã«ãå«ãŸããŠããŸããïŒå³6ïŒããã®ããã¥ã¡ã³ãã§ã¯ãhttp://mysit[.]space/123//v/0jLHzUWããæ°ããããŒãžã§ã³ã®KronosãããŠã³ããŒãããŠå®è¡ããããã®CVE-2017-11882ïŒãEquation Editorããšã¯ã¹ããã€ãïŒã䜿çšããŠããŸãã

å³6ïŒããŒã©ã³ãã®æ»æã§äœ¿çšãããæªæã®ããããã¥ã¡ã³ãã®äŸ
ãã®Kronosã®ã€ã³ã¹ã¿ã³ã¹ã¯ãC&CãšããŠhttp://suzfjfguuis326qw[.]onion/kpanel/connect.phpã䜿çšããããã«èšå®ãããŠããŸãããã®èª¿æ»ã®æç¹ã§ã¯ããããªãWebã€ã³ãžã§ã¯ã·ã§ã³ãè¿ã£ãŠããŸããã§ããã
2018幎7æ20æ¥ã®ãäœæ¥äžãã®ãã£ã³ããŒã³
2018幎7æ20æ¥ã«ã¯ãæªã éçºæ®µéã§ãã¹ãäžã®ããã«èŠããæ°ããæ»æãè¡ãããŸãããProofpointã¯ãŸã ããã®ãã£ã³ããŒã³ã®æ£ç¢ºãªçµè·¯ãç¹å®ããŠããŸãããããã®Kronosã®ã€ã³ã¹ã¿ã³ã¹ã¯ãã®C&CãšããŠhxxp://mysmo35wlwhrkeez[.]onion/kpanel/connect.phpã䜿çšããããã«èšå®ãããŠããŸããã¹ããªãŒãã³ã°ãã¥ãŒãžãã¯ãã¬ãŒã€ãŒãè£ ãWebãµã€ãã®ãGET IT NOWããã¿ã³ãã¯ãªãã¯ããããšã§ããŠã³ããŒããããŸãïŒå³7ïŒã

å³7ïŒãäœæ¥äžãã®æ»æã§Kronosã®æ°ããŒãžã§ã³ãé åžããŠããWebãµã€ã
調æ»ã®æç¹ã§ã¯ããã®æ»æã¯å³8ã«ç€ºããã¹ãçã®Webinjectã䜿çšããŠããŸããã

å³8ïŒãäœæ¥äžãã®æ»æã§äœ¿çšãããŠããWebinject
ãã«ãŠã§ã¢ã®è§£æ
Kronosãã«ãŠã§ã¢ã«ã€ããŠã¯ããããŸã§ã«å€ãã®å ±åããããŸãïŒ[4] [5] [6] [7]ïŒãããã¯ãWebInjectã«ãŒã«ã䜿çšãããã³ã»ã€ã³ã»ã¶ã»ãã©ãŠã¶ãŒæè¡ã«ãã£ãŠéèæ©é¢ã®WebããŒãžãæ¹å€ããäžæ£ãªååŒã«ãã£ãŠãŠãŒã¶ãŒã®ã¯ã¬ãã³ã·ã£ã«ãã¢ã«ãŠã³ãæ å ±ããã®ä»ã®ãŠãŒã¶ãŒæ å ±ãééã®çé£ãå©ãããã³ãã³ã°åããã€ã®æšéЬã§ãããŸããBankerãšããŠã®æŽ»åãæ¯æŽããããŒãã®ã³ã°ãšãé èœãããVNCæ©èœãåããŠããŸãã
æ°ãã2018幎ããŒãžã§ã³ã«ã¯ãæ§ããŒãžã§ã³ãšå€ãã®é¡äŒŒç¹ããããŸãã
- åºç¯ãªããã°ã©ã ã®éè€
- åãWindows APIããã·ã¥æè¡ãšããã·ã¥
- åãæååæå·åæè¡
- åºç¯å²ãªæååã®éè€
- åãC&Cæå·åã¡ã«ããºã
- åãC&Cãããã³ã«ãšæå·å
- åãWebinjectãã©ãŒãããïŒZeusãã©ãŒãããïŒ
- åæ§ã®C&Cããã«ãã¡ã€ã«ã¬ã€ã¢ãŠã
ãããããæ°ãããã«ãŠã§ã¢ãKronosã§ãããšããæãç®ç«ã€ç¹åŸŽã¯ããããäŸç¶ãšããŠèªå·±è奿ååãå«ãã§ãããšããããšã§ãïŒå³9ïŒã

å³9ïŒKronosã®èªå·±è奿åå
æ°ããŒãžã§ã³ãšæ§ããŒãžã§ã³ã®å€§ããªéãã®1ã€ã¯ã.onion C&C URLãšTorã䜿çšããŠéä¿¡ãå¿ååããããšã§ããC&Cã¯æå·åãããŠä¿åããïŒå³10ïŒãå³11ã«ç€ºãããã»ã¹ã䜿çšããŠåŸ©å·åããããšãã§ããŸãã

å³10ïŒæå·åãããC&C

å³11ïŒPythonã䜿ã£ãC&C埩å·åã®äŸ
Osirisãã³ãã³ã°åããã€ã®æšéЬ
åãææã«ãæ°ããããŒãžã§ã³ã®Kronosã®ãµã³ãã«ããã£ãŒã«ãã«çŸããŸãããã¢ã³ããŒã°ã©ãŠã³ãã®ãããã³ã°ãã©ãŒã©ã ïŒå³12ïŒã«ãOsirisãïŒåŸ©æŽ»ã象城ãããšãžããã®ç¥ïŒãšåŒã°ããæ°ããªãã³ãã³ã°åããã€ã®æšéЬã®åºåãç»å Žããã®ã§ãã

å³12ïŒOsirisãã³ãã³ã°åããã€ã®æšéЬã®åºå
åºåã§åŒ·èª¿ãããŠããæ©èœïŒC ++ããã³ãã³ã°åããã€ã®æšéЬããã€ã®æšéЬãTorã䜿çšãããã©ãŒã ã°ã©ããšããŒãã¬ãŒæ©èœãZeus圢åŒã®Webinjectã䜿çšïŒãšãç§ãã¡ã芳枬ããæ°ããããŒãžã§ã³ã®Kronosã§èŠãããæ©èœãéè€ããŠããŸãã
ãã®åºåã§ã¯ããããã®ãµã€ãºã¯350 KBãšãããŠããŸããããã¯ãç§ãã¡ããã£ãŒã«ãã§èŠã€ããæ°ããããŒãžã§ã³ã®Kronosã®åæã®è§£åæžãµã³ãã«ã®ãµã€ãºïŒ351 KBïŒã«éåžžã«è¿ããã®ã§ã[8]ããã®ãµã³ãã«ã¯ãos.exeããšããååã§ããããOsirisãã®ç¥èªãšèããããŸãã
ããã«ãæ¥æ¬ã§ã®æ»æã§äœ¿çšããããã¡ã€ã«åã®äžéšã«ãåãååãèŠã€ããããšãã§ããŸãïŒ
hxxp://fritsy83[.]website/Osiris.exe
hxxp://oo00mika84[.]website/Osiris_jmjp_auto2_noinj.exe
ãããã®é¢ä¿ã«ã€ããŠã¯æšæž¬ã§ãããããŸãããããã®è åšã«é¢ãã調æ»ã¯ç¶ç¶äžã§ãããããããã®é¢ä¿ã®å¯èœæ§ã¯å¿µé ã«çœ®ããŠããã¹ãããšã§ãã
ãŸãšã
倧ããªæåãåããé«ãè©äŸ¡ãåŸãŠãããã³ãã³ã°åããã€ã®æšéЬãKronosãã®åŸ©æŽ»ã¯ãè åšç°å¢å šäœã«èå»¶ããBankerã®å¢å ãšæ¹åæ§ãåãã§ããä»å¹Žã®äžåæã¯æªæã®ããEã¡ãŒã«æ»æã«ããªãã®å€æ§æ§ããããŸãããããã®äžã§ããã³ãã³ã°åããã€ã®æšéЬã¯äž»æµãå ããŠããŸãããKronosã¯æ¯èŒçé·ãè峿·±ãæŽå²ãæã¡ãä»ã®ãšãããã®ãŸãŸå®çããŠããããã«èŠããŸãããã®ãšã³ããªãŒã¯æè¿ç»å Žããæ°ããããŒãžã§ã³ã®ãã«ãŠã§ã¢ã«ã€ããŠã®æŠèŠã§ããããã®äž»ãªæ°æ©èœã¯Torã®äœ¿çšã§ãããã®ãã«ãŠã§ã¢ã¯ãKronosã®æ°ããããŒãžã§ã³ãŸãã¯äºçš®ã§ãããšããéèŠãªèšŒæ ããããŸããããããæ¹åãããOsirisãšããŠè²©å£²ãããŠããããšã瀺åããç¶æ³èšŒæ ããããŸãã
ãªãã¡ã¬ã³ã¹
[1] https://securityintelligence.com/the-father-of-zeus-kronos-malware-discovered/
[2] https://twitter.com/tildedennis/status/982354212695584768
[3] https://twitter.com/nao_sec/status/1017810198931517440
[4] https://www.lexsi.com/securityhub/overview-kronos-banking-malware-rootkit/?lang=en
[5] https://www.lexsi.com/securityhub/kronos-decrypting-the-configuration-file-and-injects/?lang=en
[6] https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
[7] https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware-p2/
Indicators of Compromise (IOCs)
|
IOC |
IOC Type |
Description |
|
bb308bf53944e0c7c74695095169363d1323fe9ce6c6117feda2ee429ebf530d |
SHA256 |
Mahnung_9415171.doc used in German campaign |
|
https://dkb-agbs[.]com/25062018.exe |
URL |
Mahnung_9415171.doc payload used in German campaign |
|
4af17e81e9badf3d03572e808e0a881f6c61969157052903cd68962b9e084177 |
SHA256 |
New version of Kronos used in German campaign |
|
http://jhrppbnh4d674kzh[.]onion/kpanel/connect.php |
URL |
Kronos C&C used in German campaign |
|
https://startupbulawayo[.]website/d03ohi2e3232/ |
URL |
Webinject C&C used in the German campaign |
|
http://envirodry[.]ca |
URL |
Contains malicious redirect to RIG EK used in the Japan campaign |
|
5[.]23[.]54[.]158 |
IP |
RIG EK used in the Japan campaign |
|
3cc154a1ea3070d008c9210d31364246889a61b77ed92b733c5bf7f81e774c40 |
SHA256 |
SmokeLoader used in the Japan campaign |
|
http://lionoi.adygeya[.]su |
URL |
SmokeLoader C&C used in the Japan campaign |
|
http://milliaoin[.]info |
URL |
SmokeLoader C&C used in the Japan campaign |
|
http://fritsy83[.]website/Osiris.exe |
URL |
New version of Kronos download link used in the Japan campaign |
|
http://oo00mika84[.]website/Osiris_jmjp_auto2_noinj.exe |
URL |
New version of Kronos download link used in the Japan campaign |
|
3eb389ea6d4882b0d4a613dba89a04f4c454448ff7a60a282986bdded6750741 |
SHA256 |
New version of Kronos used in the Japan campaign |
|
http://jmjp2l7yqgaj5xvv[.]onion/kpanel/connect.php |
URL |
Kronos C&C used in the Japan campaign |
|
https://kioxixu.abkhazia[.]su/ |
URL |
Webinject C&C used in the Japan campaign |
|
045acd6de0321223ff1f1c579c03ea47a6abd32b11d01874d1723b48525c9108 |
SHA256 |
âFaktura 2018.07.16.docâ used in the Poland campaign |
|
http://mysit[.]space/123//v/0jLHzUW |
URL |
New version of Kronos download link used in the Poland campaign |
|
e7d3181ef643d77bb33fe328d1ea58f512b4f27c8e6ed71935a2e7548f2facc0 |
SHA256 |
New version of Kronos used in the Poland campaign |
|
http://suzfjfguuis326qw[.]onion/kpanel/connect.php |
URL |
Kronos C&C used in the Poland campaign |
|
http://gameboosts[.]net/app/Player_v1.02.exe |
URL |
New version of Kronos download link used in âWork in progressâ campaign |
|
93590cb4e88a5f779c5b062c9ade75f9a5239cd11b3deafb749346620c5e1218 |
SHA256 |
New version of Kronos used in âWork in progressâ campaign |
|
http://mysmo35wlwhrkeez[.]onion/kpanel/connect.php |
URL |
Kronos C&C used in âWork in progressâ campaign |