æ¬ããã°ã¯ãè±èªçããã°ãhttps://www.proofpoint.com/us/threat-insight/post/new-modular-downloaders-fingerprint-systems-prepare-more-part-1-marapãã®ç¿»èš³ã§ãã
æŠèŠ
Proofpointã®ç ç©¶è ã¯æè¿ãäž»ã«éèæ©é¢ãçã£ãå€§èŠæš¡ãªïŒæ°çŸäžéã®ã¡ãã»ãŒãžïŒæ»æã§ãæ°ããããŠã³ããŒããŒãã«ãŠã§ã¢ã䜿ãããããšãçºèŠããŸããããMarapãïŒparamãéããèªãã ãã®ïŒãšåä»ãããããã®ãã«ãŠã§ã¢ã¯ãã¢ãžã¥ãŒã«ãšãã€ããŒããããŠã³ããŒãããæ©èœãªã©ã®ç¹åããæ©èœã泚ç®ã«å€ããŸããã¢ãžã¥ãŒã«æ§é ã®ãããæ»æè ã¯æ°ããæ©èœã远å ããããšãã§ããããããã«ãŠã§ã¢ã«å«ããããææåŸã«ããŠã³ããŒããããã§ããŸãããããŸã§ã«ãåçŽãªåµå¯ç®çã®ããã«ã·ã¹ãã ã®ãã£ã³ã¬ãŒããªã³ããåéããæ©èœã確èªããŸããã
æ»æã®åæ
2018幎8æ10æ¥ã«ãç§ãã¡ããã¹ãããŠããã®ãšåãMarapãã«ãŠã§ã¢ãã€ããŒãã«èªå°ããããã€ãã®å€§èŠæš¡ãªã¡ãŒã«æ»æïŒæ°çŸäžéã®ã¡ãã»ãŒãžïŒã芳枬ããŸããããããã®æ»æã¯ãéå»ã«TA505[1]ã«ãã£ãŠè¡ãããæ»æãšå€ãã®ç¹ã§å ±éç¹ããããŸããã¡ãŒã«ã«ã¯æ§ã ãªã¿ã€ãã®ãã¡ã€ã«ãæ·»ä»ãããŠããŸããïŒ
- Microsoft Excelã®Web QueryïŒ.iqyïŒãã¡ã€ã«
- .iqyãã¡ã€ã«ãå«ã¿ããã¹ã¯ãŒãä¿è·ãããZIPã¢ãŒã«ã€ã
- .iqyãã¡ã€ã«ãåã蟌ãã PDFããã¥ã¡ã³ã
- ãã¯ããå«ãã Microsoft Wordããã¥ã¡ã³ã
æ»æã®æŠèŠã¯ä»¥äžã®éãã§ãïŒ
ãsalesãã.iqyãã¢ã¿ããã¡ã³ãæ»æïŒä»¶åããREQUEST [REF:ABCDXYZ]ãïŒ[]å ã¯ã©ã³ãã ãªæååïŒãšãããsales@[random address]ãããã®ã¡ãŒã«ã§ããREP_10.08.iqyãïŒæ»ææ¥ïŒãšãããã¡ã€ã«ãæ·»ä»ãããŠããŸãã

å³1ïŒã.iqyããã¡ã€ã«ãæ·»ä»ãããSalesãããã®ã¡ãŒã«ã®äŸ
ãMajor bankãã.iqyãã¢ã¿ããã¡ã³ãæ»æïŒãIMPORTANT Documents - [Major Bank]ããšããä»¶åã®ã"[recipient name]" <random_name@[major bank].com>ãããã®ã¡ãã»ãŒãžãè£ ãããRequest 1234_10082018.iqyãïŒã©ã³ãã ãªæ°å€ã𿻿æ¥ïŒãæ·»ä»ãããŠããŸããç±³æåéè¡ã®ååãšãã©ã³ããäžæ£äœ¿çšããŠããŸããããµã³ãã«ã«ã¯ã¢ã¶ã€ã¯ããããŠããŸãã

å³2ïŒã.iqyããã¡ã€ã«ãæ·»ä»ãããMajor bankãã¡ãŒã«ã®äŸïŒéè¡åã«ã¯ã¢ã¶ã€ã¯ããããŠããŸã
PDFã¢ã¿ããã¡ã³ãæ»æïŒä»¶åã«ãDOC_1234567890_10082018ãïŒã©ã³ãã ãªæ°å€ã𿻿æ¥ïŒä»ã«ãPDFããPDFFILEããSCNããªã©ïŒãšããã"Joan Doe" <netadmin@[random domain]>ãïŒã©ã³ãã ãªãã£ã¹ãã¬ã€ããŒã ïŒããã®ã¡ãŒã«ã§ãä»¶åãšåããDOC_1234567890_10082018.pdfãïŒ.iqyãã¡ã€ã«ãåã蟌ãŸããŠããŸãïŒãšãããã¡ã€ã«ãæ·»ä»ãããŠããŸãã

å³3ïŒ.iqyãã¡ã€ã«ãåã蟌ãã PDFãã¡ã€ã«ãæ·»ä»ããã¡ãã»ãŒãžã®äŸ
ãã¹ã¯ãŒãä»ãZIPãã¡ã€ã«æ»æïŒã"John" <John@[random company]>ãïŒã©ã³ãã ãªååïŒããã®ãEmailing: PIC12345ãïŒã©ã³ãã ãªæ°å€ïŒãšããä»¶åã®ã¡ãã»ãŒãžã§ãä»¶åãšåããPIC12345.zipããšãããã¡ã€ã«ãæ·»ä»ãããŠããŸãã

å³4ïŒ.iqyãã¡ã€ã«ãå«ããã¹ã¯ãŒãä»ãZIPãã¡ã€ã«ãæ·»ä»ãããã¡ãã»ãŒãžã®äŸ
Microsoft Wordã¢ã¿ããã¡ã³ãæ»æïŒã"Joan" <Joan@[random domain]>ãïŒã©ã³ãã ãªååïŒããã®ã¡ãã»ãŒãžãè£ ãããInvoice for 12345.10/08/2018ãïŒã©ã³ãã ãªæ°å€ãšä»æ¥ã®æ¥ä»ïŒãšããä»¶åã§ããInvoice_ 12345.10_08_2018.docããšãããã¡ã€ã«ãæ·»ä»ãããŠããŸãã

å³5ïŒæªæã®ãããã¯ããå«ãMicrosoft Wordãã¡ã€ã«ãæ·»ä»ããã¡ãã»ãŒãžã®äŸïŒã¡ãã»ãŒãžæ¬æã«ãPDF formatããšã®ééã£ãèšèŒãããïŒ
ãã«ãŠã§ã¢ã®è§£æ
åè¿°ããããã«ãMarapã¯æ°ããããŠã³ããŒããŒã§ãããã䜿ãCommand & ControlïŒC&CïŒãµãŒããŒãžã®ã³ãŒã«ããã¯ãã©ã¡ãŒã¿ã§ãããparamãã®ã¹ãã«ãéã«äžŠã¹ããã®ãååã«ãªã£ãŠããŸãããã®ãã«ãŠã§ã¢ã¯Cã§æžãããŠãããè§£æãéããããšããè峿·±ãæ©èœãããã€ãåããŠããŸãã
è§£æéãã®æ©èœ
Windows APIã®é¢æ°åŒã³åºãã¯ã»ãšãã©ã®å Žåãå®è¡æã«ããã·ã¥ã¢ã«ãŽãªãºã ã䜿çšããŠåŠçãããŸãããã«ãŠã§ã¢ãAPIããã·ã³ã°ãæªçšããã¢ããªã¹ããèªåæ€ç¥ããŒã«ã«ãã«ãŠã§ã¢ã®ç®çãç°¡åã«å€æã§ããªããããããšããããããŸããããã®ã¢ã«ãŽãªãºã ã¯Marapå°çšãšæãããŸããç§ãã¡ã䜿ã£ãPythonã§ã®ããã·ã¥ã¢ã«ãŽãªãºã ã®å®è£ ã¯Github[2] ã§ã芧é ããŸããç§ãã¡ã®ã³ãŒãã§äœ¿ãããŠããXORéµã¯ãä»ã®ãµã³ãã«ã§ã¯ç°ãªã£ãŠããå¯èœæ§ããããŸãã
2çªç®ã®è§£æéãã®ææ³ã¯ãéèŠãªæ©èœã®éå§æã«ã¿ã€ãã³ã°ãã§ãã¯ã䜿çšããæ¹æ³ã§ãïŒå³6ïŒããããã®ãã§ãã¯ã¯ããã«ãŠã§ã¢ã®ãããã°ããµã³ãããã¯ã¹åã劚ããå¯èœæ§ããããŸããèšç®ãããã¹ãªãŒãæéãçãããå Žåããã«ãŠã§ã¢ã¯çµäºããŸãã

å³6ïŒè§£æéãã®ããã®ã¿ã€ãã³ã°ãã§ãã¯
ãã«ãŠã§ã¢å ã®æååã¯ã以äžã®3ã€ã®æ¹æ³ã®ããããã䜿ã£ãŠé£èªåãããŠããŸãïŒ
- ã¹ã¿ãã¯äžã«äœæïŒStack StringsïŒ
- åºæ¬çãªXORãšã³ã³ãŒãã£ã³ã°ïŒãµã³ãã«ã§ã¯0xCEã䜿ãããŠããŸããããµã³ãã«æ¯ã«ç°ãªãå¯èœæ§ããããŸãïŒ
- å°ãè€éãªXORãšã³ã³ãŒãã£ã³ã°ïŒåŸ©å·åã®ããã®IDA Proã¹ã¯ãªãããGithub[3]ã§å ¬éããŠããŸãïŒ
æåŸã®ææ³ã¯ãã·ã¹ãã ã®MACã¢ãã¬ã¹ãä»®æ³ãã·ã³ãã³ããŒã®ãªã¹ããšç §åããããšã§ããä»®æ³ãã·ã³ãæ€ç¥ãããã³ã³ãã£ã°ã¬ãŒã·ã§ã³ãã©ã°ãã»ãããããŠããå Žåããã«ãŠã§ã¢ã¯çµäºããŸãã
ã³ã³ãã£ã°ã¬ãŒã·ã§ã³
Marapã®ã³ã³ãã£ã°ã¬ãŒã·ã§ã³æ
å ±ã¯ããã«ãŠã§ã¢ã®ãã€ããªã«æå·åãããŠåã蟌ãŸãããããã«ãŠã§ã¢ã®ã¯ãŒãã³ã°ãã£ã¬ã¯ããªã«ãããSign.binããšãããã¡ã€ã«ïŒããšãã°C:\Users\[username]\AppData\
Roaming\Intel\Sign.binïŒã«ä¿åãããŠããŸããããã¯CBCã¢ãŒãã®DESã§æå·åãããŠãããIVã¯ã\x00\x00\x00\x00\x00\x00\x00\x00ãã§ããéµã¯ä»¥äžã®ããã»ã¹ã§çæãããŸãïŒ
- ç·åœ¢ååæ³ïŒLCGïŒãš2ã€ã®ããŒãã³ãŒããããã·ãŒãïŒã·ãŒãã¯ãµã³ãã«æ¯ã«éãå¯èœæ§ããããŸãïŒã䜿ã£ãŠ164ãã€ãã®ããŒã¿ãçæããŸããPythonã«ããLCGã®å®è£ ãGithubã«äžããŠãããŸãã[4]
- SHA1ã䜿ã£ãŠããŒã¿ãããã·ã¥ããŸã
- CryptDeriveKeyãšããã·ã¥ã䜿ã£ãŠ8ãã€ãã®DESéµãçæããŸã
埩å·åãããã³ã³ãã£ã°ã¬ãŒã·ã§ã³æ å ±ã®äŸã¯ä»¥äžã®æ§ãªãã®ã§ãïŒ
15|1|hxxp://185.68.93[.]18/dot.php|hxxp://94.103.81[.]71/dot.php|hxxp://89.223.92[.]202/dot.php
ã|ãã§åºåãããŠããã以äžã®ã³ã³ãã£ã°ã¬ãŒã·ã§ã³ãã©ã¡ãŒã¿ãå«ãã§ããŸãïŒ
- C&Cãšã®éä¿¡ã«ãããã¹ãªãŒãæé
- ãã«ãŠã§ã¢ãä»®æ³ãã·ã³ã§åäœããŠããããšãèªèº«ã§æ€ç¥ããéã«åäœã忢ãããã©ãããèšå®ãããã©ã°
- æå€§3ã€ãŸã§ã®C&C URL
ã³ãã³ã&ã³ã³ãããŒã«
Marapã¯C&Céä¿¡ã«HTTPã䜿çšããŠããŸãããæåã«ãããã·ã䜿çšããå¿ èŠããããã©ããã䜿çšããå Žåã¯ã©ã®ãããªãããã·ã䜿çšãããã倿ããããã«ãæ£èŠã®WinHTTP颿°ãäœåãå®è¡ããŸããäžã®å³7ã«C&CããŒã³ã³ã®äŸã瀺ããŸãã

å³7ïŒC&CããŒã³ã³ã®äŸ
ãã®ãªã¯ãšã¹ãã«ãparamããšãããã©ã¡ãŒã¿ãå«ãŸããŠãããã³ã³ãã£ã°ã¬ãŒã·ã§ã³æ å ±ãšåãææ³ã§æå·åãããŠãããbase64ãšã³ã³ãŒããå ããŠããŸããå¹³æã®ãªã¯ãšã¹ãã®äŸã¯ã以äžã®æ§ãªãã®ã§ãïŒ
62061c6bcdec4fba|0|0
ã|ãã§åºåãããŠããã以äžãå«ãã§ããŸãïŒ
- ãããIDïŒãã¹ãåããŠãŒã¶ãŒåãMACã¢ãã¬ã¹ãäžèšã®APIããã·ã³ã°ãšåãã¢ã«ãŽãªãºã ã§ããã·ã¥ãããã®ïŒ
- ããŒãã³ãŒããããã0ã
- ããŒãã³ãŒããããã0ã
ã¬ã¹ãã³ã¹ããŸãæå·åãããŠããã埩å·åããäŸã¯ä»¥äžã®æ§ã«ãªããŸãïŒ
319&1&0&hxxp://89.223.92[.]202/mo.enc
ã&ãã§åºåãããŠããã以äžãå«ãã§ããŸãïŒ
- ã³ãã³ãID
- ã³ãã³ã
- ã¬ã¹ãã³ã¹ã¿ã€ããå¶åŸ¡ãããã©ã°
- ã³ãã³ãåŒæ°ïŒ2ã€ã®åŒæ°ãã#ãã§åºåã£ãŠäœ¿çšå¯èœïŒ
ç¹å®ãããã³ãã³ã
- 0: ã¹ãªãŒãããŠããäžåºŠããŒã³ã³
- 1: URLãããŠã³ããŒããDESã§æå·åãããã¥ã¢ã«ã§MZãã¡ã€ã«ãããŒãïŒãããã¡ãã¢ãã±ãŒããPEããããšã»ã¯ã·ã§ã³ãã³ããŒãåã¢ãã±ãŒããã€ã³ããŒãããŒãã«ã解決ïŒ
- C&CãžããŒã¿ã転éå¯èœ
- 2: ã³ã³ãã£ã°ã¬ãŒã·ã§ã³ãã¢ããããŒããããSign.binãã«DESæå·åããããŒãžã§ã³ãæžèŸŒã¿
- 3: URLãããŠã³ããŒããDESã§æå·åãã%TEMP%/evtãã«MZãã¡ã€ã«ãä¿åããŠã³ãã³ãã©ã€ã³åŒæ°ãšå ±ã«å®è¡
- 4: URLãããŠã³ããŒããDESã§æå·åãããã»ã¹ïŒãã«ãŠã§ã¢ãšåãå®è¡ãã¡ã€ã«ïŒãçæããŠç©ºæŽã«ããããŠã³ããŒãããMZãã¡ã€ã«ãæ³šå ¥
- 5: URLãããŠã³ããŒããDESã§æå·åãã%TEMP%/zvtãã«MZãã¡ã€ã«ãä¿åããŠLoadLibrary APIã«ãã£ãŠããŒã
- 6: URLãããŠã³ããŒããDESã§æå·åãããã¥ã¢ã«ã§MZãã¡ã€ã«ãããŒã
- 7: èªèº«ãåé€ããŠåæ¢
- 8: èªèº«ãã¢ããããŒã
ã³ãã³ãå®è¡åŸãC&Cã«ã¬ã¹ãã³ã¹ã¡ãã»ãŒãžãéä¿¡å¯èœãã|ãã§åºåããã以äžãå«ã¿ãŸãïŒ
- ãããID
- ããŒãã³ãŒããããã1ã
- ã³ãã³ãID
- ã³ãã³ã
- ã¬ã¹ãã³ã¹ã¿ã€ããå¶åŸ¡ãããã©ã°
- ã³ãã³ãæ»ãå€
- ã³ãã³ãã¹ããŒã¿ã¹ã³ãŒãïŒæ§ã ãªãšã©ãŒã³ãŒãïŒ
- ã¬ã¹ãã³ã¹ããŒã¿
- ã·ã³ãã«ãªã¹ããŒã¿ã¹ã¡ãã»ãŒãž
- ãŸãã¯è€æ°ã®ã¢ãžã¥ãŒã«ããã®ã#ãã§åºåãããé·ãããŒã¿
ã·ã¹ãã ãã£ã³ã¬ãŒããªã³ãã£ã³ã°ã¢ãžã¥ãŒã«
ããã°å·çæç¹ã§èŠ³æž¬ãããŠããã®ã¯ãC&CãµãŒããŒããéä¿¡ãããã·ã¹ãã ãã£ã³ã¬ãŒããªã³ãã£ã³ã°ã¢ãžã¥ãŒã«ã§ããããã¯ãhxxp://89.223.92[.]202/mo.encãããããŠã³ããŒãããããmod_Init.dllããšããå éšåãå«ãã§ããŸãããã¢ãžã¥ãŒã«ã¯Cã§æžãããDLLã§ããã以äžã®ã·ã¹ãã æ å ±ãåéããŠC&CãµãŒããŒã«éä¿¡ããŸãã
ãŠãŒã¶ãŒå
ãã¡ã€ã³å
ãã¹ãå
IPã¢ãã¬ã¹
èšèª
åœ
Windowsã®ããŒãžã§ã³
Microsoft Outlook ã®.ostãã¡ã€ã«ã®ãªã¹ã
æ€ç¥ãããã¢ã³ããŠã€ã«ã¹ãœãããŠã§ã¢
çµè«
ã³ã¢ãã£ãã£åã®ãã«ãŠã§ã¢ãæ€ç¥ããããã®æè¡ãé²åãããããè åšã¢ã¯ã¿ãŒããã«ãŠã§ã¢ã®äœæè ã¯ãæ»æã®å¹çãé«ããã«ãŠã§ã¢ã®çè·¡ãšåºæã®ããã€ãºããæžããããã®æ°ããã¢ãããŒããæš¡çŽ¢ãç¶ããŠããŸããä»å¹Žã¯ã©ã³ãµã ãŠã§ã¢ã®é åžãæ¿æžããããã€ã®æšéЬãããŠã³ããŒããŒããã®ä»ã®ãã«ãŠã§ã¢ããã®ç©ºéãåããŠãããè åšã¢ã¯ã¿ãŒãããã€ã¹ããããã¯ãŒã¯ã«æ°žç¶çã«é¢äžããåŸåã匷ããªã£ãŠããŸãã
ãã®æ°ããããŠã³ããŒããŒãšçŽæ¥ã®é¢ä¿ã¯ç¡ããã®ã®ãé¡äŒŒãããã«ãŠã§ã¢ãçºèŠãããŠããŸããïŒæ¬¡åã®ããã°ã§è§£èª¬ããŸãïŒãããã®å°åã§å€æ§ãªãã«ãŠã§ã¢ã¯å¢å ããåŸåã«ãããå°æ¥ã®æ»æã®åºç€ãšãªãæ»æå¯Ÿè±¡ã®ã·ã¹ãã ãç¹å®ããæè»æ§ãã¢ã¯ã¿ãŒã«äžããããšã§ãããæ·±å»ãªäŸµå®³ãåŒãèµ·ãããŸãã
ãªãã¡ã¬ã³ã¹
[1] https://www.proofpoint.com/us/threat-insight/post/ta505-shifts-times
[2] https://github.com/tildedennis/malware/blob/master/marap/func_hashes.py
[3] https://github.com/tildedennis/malware/blob/master/marap/str_decrypt3.py
[4] https://github.com/tildedennis/malware/blob/master/marap/lcg.py
Indicators of Compromise (IOCs)

ET and ETPRO Suricata/Snort Signatures
2832142 || ETPRO TROJAN Win32/Marap CnC Beacon
2832143 || ETPRO TROJAN Win32/Marap CnC Beacon Response