æŠèŠ
Proofpointã®ç ç©¶è ã7æäžæ¬ã«èŠ³æž¬ãããã£ãã·ã³ã°ãã£ã³ããŒã³ãããã®ããã°ã®å·çæç¹ã§ãç¶ããŠããŸãããã®ãã£ã³ããŒã³ã¯DocuSignã®ãã©ã³ãããã³ã¡ãŒã«ãã©ãŒãããã䜿çšããŠãããŸããŸãªçµç¹ã®ç¹å®ã®åäººãæšçã«ããŠããŸãã
ãã®ãã£ã³ããŒã³ãç®ãã²ãã®ã¯ãã©ã³ãã£ã³ã°ããŒãžãAmazonã®ãšã³ã¿ãŒãã©ã€ãºåãã®ãããªãã¯ã¯ã©ãŠãã¹ãã¬ãŒãžïŒS3ïŒã§ãã¹ããããŠããããšã§ããProofpointãç£èŠããŠãããã£ãã·ã³ã°ã¢ã¯ã¿ãŒã®äžã§ããéåžžã«çãããã¿ãŒã³ã§ãã
çãããšã¯ãããProofpointã¯ä»ã®ãšã³ã¿ãŒãã©ã€ãºã¯ã©ã¹ã®ãããªãã¯ã¯ã©ãŠãã€ã³ãã©ã䜿çšããè åšã¢ã¯ã¿ãŒã«ã€ããŠãã¬ããŒãããŠãããMicrosoftã®GitHubãµãŒãã¹ã®äžæ£äœ¿çšãMicrosoft Azure BLOBã¹ãã¬ãŒãžã掻çšããã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ã¹ããŒã ãªã©ãããã«è©²åœããŸãã
åæ
以äžã¯ãDocuSignãã©ã³ããäžæ£äœ¿çšããé»åã¡ãŒã«ãã³ãã¬ãŒãã®äŸã§ããç¹å®ã®ç£æ¥ãçã£ããã®ã§ã¯ãªããæ»æè ã¯ããŸããŸãªäŒæ¥ã®å°æ°ã®å人ã«éä¿¡ããŸãããèŠãç®ã¯DocuSignãä»ããŠå ±æãããããã¥ã¡ã³ãã§ãããéåžžã«æšæºçãªãã£ãã·ã³ã°ã«ã¢ãŒïŒé€ïŒãšããããšãã§ããŸãïŒ

å³1ïŒäžæ£ãªDocuSignãã©ã³ãã䜿çšããŠããæªæã®ããé»åã¡ãŒã«ãã³ãã¬ãŒã
ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ã®ã©ã³ãã£ã³ã°ããŒãžãããã©ã³ãã£ã³ã°ããã³å šäœçãªãã©ãŒãããã¯DocuSignã«ãã䌌ãŠããŸãããå®éã«ã¯é廿°å¹Žéã«ãããäžè¬çã«äœ¿çšãããŠãããã£ãã·ã³ã°ãã³ãã¬ãŒãã§ãïŒ

å³2ïŒãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžã§äœ¿çšãããŠããäžæ£ãªDocuSignã®ãã©ã³ããšã€ã¡ãŒãžçŽ æ
ãã®ã©ã³ãã£ã³ã°ããŒãžã¯Amazon S3ã§ãã¹ããããŠãããåè¿°ããããã«ããã¯éåžžã«çããã±ãŒã¹ã§ãããã®ç¹å®ã®ããŒãžã¯æ¬¡ã®å Žæã«ãããŸããïŒ
https://s3.us-east-2.amazonaws [.] com/docusign.0rwlhngl7x1w6fktk0xh8m0qhdx4wnbzz1w
/t993zTVQwqXuQLxkegfz1CAUtcrGfe0bRm0V2Cn/eeu69zk7KqAmofMrHr6xrWgrKUoTrOn2BJhhnQg
/eAzUroFtr7Gw9JrkWkX9.html
ãœãŒã¹ã³ãŒãã詳ãã調ã¹ããšãå€ãã®ãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžãšåæ§ã«JavaScriptãšã³ã³ãŒãã£ã³ã°ãããŠããããšãããããŸãããããã¯ããã³ãŒãæã«ããã€ãã®æååã ãã§ãªãæå·æãå«ã16é²ãšã³ã³ãŒããããæååã§å§ãŸãããã®æ¬¡ã«ãšã³ã³ãŒããããblobããã³ãŒãããevalã¹ããŒãã¡ã³ããç¶ããŠããŸãïŒ

å³3ïŒãšã³ã³ãŒãããããã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžã®éå§éšå

å³4ïŒãã³ãŒãã®ããã®evalã¹ããŒãã¡ã³ã
ã¡ã€ã³ããŒã¿å ã®ãã£ãŒã«ãã¯ã衚é¢äžã¯åçŽã«16é²ãšã³ã³ãŒããããŠããã ãã§ãããProofpointã®ç ç©¶è ã¯ãã©ã³ãã£ã³ã°ããŒãžã®ãããã€ã¡ã³ãããšã«ãšã³ã³ãŒãã£ã³ã°ãšå€æ°åãé »ç¹ã«å€ããããšã芳枬ããŠããŸããæè¿èгå¯ããããã®ãããã®ãããã€ã¡ã³ãã§è€æ°åã®ãšã³ã³ãŒãã£ã³ã°åŠçãè¡ãããŠããããšã¯ã泚ç®ã«å€ããŸãã以äžã¯3ã€ã®ç°ãªãã©ã³ãã£ã³ã°ããŒãžããã®16é²ãã³ãŒããããã³ã³ãã³ãã§ãæ»æè ãæ€åºåé¿ã«å€å€§ãªåªåãæã£ãŠããããšã瀺ããŠããŸãã

å³5ïŒãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžã®JavaScriptã®ASCIIã³ã³ãã³ã
16鲿°ãASCIIã«ãã³ãŒãããåŸã®ããŒã¿ã®çµããè¿ãã§ããã³ãŒãããã»ã¹å ã§äœ¿çšããããã¬ãŒã³ããã¹ãæååã確èªã§ããŸãã

å³6ïŒASCIIãã³ãŒããããããã¹ããããã¯ã®æåŸã®ãã¬ãŒã³ããã¹ãæåå
ãã®ãã³ãŒããå®äºãããšããã£ãã·ã³ã°ãã£ã³ããŒã³ã§ããèŠããããããäžè¬çãªå¥ã®JavaScript unescape ãšã³ã³ãŒãã£ã³ã°ã衚瀺ãããŸãïŒ

å³7ïŒJavaScriptã®unescapeãšã³ã³ãŒãã£ã³ã°
ããããã³ãŒããããšãããã«è¿œå ã®ãšã³ã³ãŒãã£ã³ã°ãçŸãããŸãïŒ

å³8ïŒè¿œå ã®ãšã³ã³ãŒãã£ã³ã°
ããããã³ãŒããããšãProofpointã®ç ç©¶è ã2016幎2æã®Threat Insightããã°ãHiding in Plain SightïŒObfuscation Techniques in Phishing Attacksãã§åæãããã«ããã€ãXORãšã³ã³ãŒãã£ã³ã°ãçŸãããŸãïŒ

å³9ïŒãã«ããã€ãXORãšã³ã³ãŒãã£ã³ã°
ãã ãããã®ç¹å®ã®äŸã§ã¯ããã£ãã·ã³ã°ã©ã³ãã£ã³ã°ã¯4ã€ã®ã»ã¯ã·ã§ã³ã«åå²ããããã¹ãŠç°ãªãå€ã䜿çšããŠãã®ã¿ã€ãã®ãšã³ã³ãŒããå®è¡ããŠããŸãã

å³10ïŒãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžã®4ã€ã®XORãšã³ã³ãŒãéš
ãããã®4ã€ã®ã»ã¯ã·ã§ã³ãã¹ãŠããã³ãŒããããšãæçµçã«çã®HTMLãåŸãããå žåçãªãã£ãã·ã³ã°ã³ãŒããçŸãããŸãã以äžã¯ãã¯ã¬ãã³ã·ã£ã«ã®POST URLãšãè€æ°ã®Webã¡ãŒã«ãããã€ããŒãå«ãã¡ãŒã«ã¢ãã¬ã¹ã®ããããããŠã³ã³ã³ãã³ãã§ãã

å³11ïŒWebã¡ãŒã«ãããã€ããŒã§ã®ãŠãŒã¶ãŒã¯ã¬ãã³ã·ã£ã«ã®ãã£ãã·ã³ã°ã³ãŒã
ã¡ãŒã«ããã³ãã¹ã¯ãŒããã£ãŒã«ããæ€èšŒããå žåçãªã³ãŒããå«ãŸããŠããŸãïŒ

å³12ïŒã¡ãŒã«ãšãã¹ã¯ãŒãã®æ€èšŒ
å¹³æã®ãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžããããã®ãããããã¡ã€ã³åã«ãdancelikejosephããå«ãè€æ°ã®Webãµã€ãããããã€ãã®ãªã¢ãŒããªãœãŒã¹ãåéããŠããããšãããããŸãããããã¯ãŒã¯ãã©ãã£ãã¯ãã°ã«ãããã®DNS/TLS SNIãªã¯ãšã¹ããååšããŠãããšããããšã¯ããŠãŒã¶ãŒããããã®ããŒãžã«ã¢ã¯ã»ã¹ããããšããå¯èœæ§ããããŸãã
ãããã®ãã¡ã€ã³ã«ã¯çŸåšãLet's Encryptãããã®TLSèšŒææžãèšçœ®ãããŠããããã¹ãŠããphasephaser@yandex.comãã«ãã£ãŠç»é²ãããŠããããã§ãã
ãã®ããŒãžã§ã¯ã¯ã¬ãã³ã·ã£ã«ã®ååŸã詊ã¿ãŸããããã®åŸèšªåè ãDocuSignã®ã©ã³ãã£ã³ã°ããŒãžã§æ å ±ãå ¥åããå Žåãæå®ããWebã¡ãŒã«ãµãŒãã¹ã«é¡äŒŒãããµã€ãã«ãªãã€ã¬ã¯ããããå¥ã®ãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžãå床ã¯ã¬ãã³ã·ã£ã«ãçãããšããŸãã

å³13ïŒMicrosoft Webã¡ãŒã«ãã°ã€ã³ç»é¢ãè£ ã£ããã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãž
ãã®ããŒãžã¯ãDocuSignããŒãžãšåãã¿ã€ãã®ãšã³ã³ãŒã/ãã³ãŒãããã»ã¹ã䜿çšããŸãããã®ããŒãžã®äŸã§ã¯ãåŸæ¥ã®ã¯ã¬ãã³ã·ã£ã«POSTã䜿çšãã代ããã«ãAJAXã䜿çšããŠã¯ã¬ãã³ã·ã£ã«POSTãäœæããŠããŸããã¯ã¬ãã³ã·ã£ã«ã®éä¿¡å ã¯ãDocuSignã©ã³ãã£ã³ã°ããŒãžã«äœ¿çšãããŠãããã¡ã€ã³ãšåãã§ãã

å³14ïŒAJAXã䜿çšããã¯ã¬ãã³ã·ã£ã«ã®éä¿¡
ãã®æç¹ã§ã被害è ã¯æ¬ç©ã®office.comã«ãªãã€ã¬ã¯ããããŸãã
ãã£ã³ããŒã³æ å ±
ãã®ã¢ã¯ãã£ããã£ã«é¢äžããŠããã¢ã¯ã¿ãŒã¯ãAWSã§ã®ãã¹ãã£ã³ã°ã«æ £ããŠããŸããProofpointã¯å¹ŽéãéããŠåæ§ã®ãã£ã³ããŒã³ã芳枬ã§ããŠããŸããAWSãã¡ã€ã³ä»¥å€ã¯ãã¹ãŠãLet's EncryptãTLSèšŒææžãå©çšããŠãããã»ãšãã©ããã·ã¢ã®ãã¡ã€ã³ç»é²ãµãŒãã¹ã«ç»é²ãããŠããããã§ãããã®ãã£ã³ããŒã³ã®æéäžããã¹ãŠã®ãã£ãã·ã³ã°ããŒãžã¯AWSã§ãã¹ããããŠããŸããããããã€ãã®ã±ãŒã¹ã§ã¯ãä»ã®ãããªãã¯ã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã©ã³ãã£ã³ã°ããŒãžã®ãªãœãŒã¹ããã¹ãããŠããŸããã
ãããŸã§ã®ãã£ã³ããŒã³ãšç¹åŸŽããšã³ã³ãŒãã£ã³ã°ã¬ãã«ã«ã€ããŠä»¥äžã«èŠçŽããŸãïŒ
|
Timeframe (2019) |
Phished credentials/ abused brands |
Landing pages encoded |
Host for page resources |
Stolen credentials receiving address |
|
February |
DocuSign Microsoft Office |
No |
Local AWS instance storage.googleapis.com |
whistleobohemian [.] info |
|
Early March |
ShareFile (Figure 15) DocuSign Microsoft Office |
No |
Microsoft Azure |
whistleobohemian [.] info |
|
Late March to early April |
ShareFile DocuSign Microsoft Office |
No |
dataanarchyofsons [.] site |
whistleobohemian [.] info |
|
Early to mid-April |
ShareFile DocuSign Microsoft Office Chalbai template (produced by a prolific reseller of general-purpose phishing templates) |
No |
dataanarchyofsons [.] site |
postmasterpledge [.] ru |
|
Late April through mid-May |
DocuSign |
No |
dataanarchyofsons [.] site |
postmasterpledge [.] ru |
|
Mid-June |
ShareFile DocuSign Microsoft Office |
Yes - simplified version of current encoding; Figure 16 and 17 |
dataanarchyofsons [.] site |
dancelikejoseph [.] xyz |
|
Late June through August |
DocuSign Microsoft Office |
Yes - current iteration as described in this blog |
300spartans [.] dancelikejoseph [.] xyz and dancelikejoseph [.] site |
dancelikejoseph [.] xyz and xplicate [.] dancelikejoseph [.] info |
å³15ïŒShareFileã®ãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžïŒ2019幎3æïŒ
å³16ïŒãã«ããã€ãXORã䜿ã£ããã®ã¢ã¯ã¿ãŒã®æåã®ãšã³ã³ãŒãã£ã³ã°ã®åæã®ã€ãã¬ãŒã·ã§ã³ïŒåäžã¹ããŒãã¡ã³ãïŒ
Proofpointã¯Microsoft Officeã®ãã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžã®ããã€ãã§ã以äžã®æ§ã«ã¢ã¯ã¿ãŒãç°ãªããšã³ã³ãŒãã£ã³ã°æè¡ã䜿ãããšããŠããããšã芳枬ããŸããïŒ
å³17ïŒæåã®ã©ã³ãã£ã³ã°ããŒãžã§èŠ³æž¬ãããã¢ã¯ã¿ãŒã«ããå¥ã®ãšã³ã³ãŒãã£ã³ã°ã€ãã¬ãŒã·ã§ã³
6æäžæ¬ã«ããã®ã¢ã¯ã¿ãŒã«ãããšã³ã³ãŒãã£ã³ã°ã®çŸåšã®ã€ãã¬ãŒã·ã§ã³ã®æåã®ã€ã³ã¹ã¿ã³ã¹ã芳枬ããŸããã
çµè«
è åšã¢ã¯ã¿ãŒããã£ãã·ã³ã°è©æ¬ºåž«ã¯ãæªæã®ãããã£ãã·ã³ã°ãããããã¹ãããããã«æåã§ä¿¡é Œã§ããã³ã³ã·ã¥ãŒãåãã¯ã©ãŠããµãŒãã¹ããœãŒã·ã£ã«ãããã¯ãŒãã³ã°ãããã³ã³ããŒã·ã£ã«ãµãŒãã¹ã䜿çšããããšã§æ€ç¥ãåé¿ããŠããŸããã
äžéšã®ã¢ã¯ã¿ãŒã¯ãGoogle DriveãDropboxãªã©ã®ã³ã³ã·ã¥ãŒãåãã¯ã©ãŠãã¹ãã¬ãŒãžãããAmazon Web ServicesïŒAWSïŒãMicrosoft Azureãªã©ã®ãšã³ã¿ãŒãã©ã€ãºã¯ã©ã¹ã®ãããªãã¯ã¯ã©ãŠãã¹ãã¬ãŒãžãããã€ããŒã«ç§»è¡ããã©ã³ãã£ã³ã°ããŒãžã§JavaScriptã䜿ã£ãããŸããŸãªãšã³ã³ãŒãæè¡ãåŒãç¶ã䜿çšããŠæ€åºãåé¿ããããšããŠããŸãã
Amazonã¯ãã®çš®ã®ãããªã¢ã«ããã¹ãããã¢ã«ãŠã³ãã®æªçšãéåžžã«èŠæããŠãããç©æ¥µçã«åé€ããŠããŸãããé²åŸ¡åŽããŸãAWS S3ã¯ã©ãŠãã¹ãã¬ãŒãžã§ãã¹ããããŠããWebããŒãžäžã®æœåšçãªæªæã®ããã³ã³ãã³ãã«æ³šæããå¿ èŠããããŸãã
Indicators of Compromise (IOCs)
|
IOC |
IOC Type |
Description |
|
300spartans [.] dancelikejoseph [.] xyz |
Domain |
Loads up resources |
|
xplicate [.] dancelikejoseph [.] info |
Domain |
Stolen credentials sent here |
|
dancelikejoseph [.] site |
Domain |
Loads up resources |
|
phasephaser@yandex.com |
|
Registrant |
|
185.255.79 [.] 118 |
IP |
Hosting |
|
194.58.112 [.] 174 |
IP |
Hosting |
|
postmasterpledge [.] ru |
Domain |
Historical. Stolen credentials sent here (04/19-05/19) |
|
dataanarchyofsons [.] site |
Domain |
Historical. Loaded up resources (03/19-05/19) |
|
whistleobohemian [.] info |
Domain |
Historical. Stolen credentials sent here (02/19-04/19) |
ã©ã³ãã£ã³ã°ããŒãžã®URL
çŽè¿ã®ãã£ã³ããŒã³ã§ã以äžã®URLã䜿ãããŠããããšã確èªããŸããïŒ
ãããã¯èªã¿ãããããããã«èŠçŽãããŠããããã¹ãŠã®URLã¯ä»¥äžã®æ£èŠè¡šçŸã«åŸã£ãŠããŸãã
https://s3.us-east-2.amazonaws [.] com/ *Phrase* [A-Za-z0-9/]{100,}\.html
https://s3.us-east-2.amazonaws [.] com/alan.d0cus1gn
https://s3.us-east-2.amazonaws [.] com/alan.interactive.business.services.
https://s3.us-east-2.amazonaws [.] com/aland0cus.1gn
https://s3.us-east-2.amazonaws [.] com/alanprat.doc.sign
https://s3.us-east-2.amazonaws [.] com/c0nnecticut.d0.cusig.n
https://s3.us-east-2.amazonaws [.] com/c0nnecticut.g0vernment
https://s3.us-east-2.amazonaws [.] com/c0nnecticut.government
https://s3.us-east-2.amazonaws [.] com/connecticut.government
https://s3.us-east-2.amazonaws [.] com/connecticut.government.d0cu
https://s3.us-east-2.amazonaws [.] com/d0cu
https://s3.us-east-2.amazonaws [.] com/d0cu.sign
https://s3.us-east-2.amazonaws [.] com/d0cudig.n
https://s3.us-east-2.amazonaws [.] com/d0cusign
https://s3.us-east-2.amazonaws [.] com/d0cusigned
https://s3.us-east-2.amazonaws [.] com/diarylandseed
https://s3.us-east-2.amazonaws [.] com/docu.s1gn
https://s3.us-east-2.amazonaws [.] com/docus.ign
https://s3.us-east-2.amazonaws [.] com/docusign
https://s3.us-east-2.amazonaws [.] com/docusigned
https://s3.us-east-2.amazonaws [.] com/homecredit.philippines
https://s3.us-east-2.amazonaws [.] com/interactive.business.service
https://s3.us-east-2.amazonaws [.] com/interactivebusiness.services
Proofpointã¯æ¬èšäºã®å ¬éåã«ãããã®URLãAmazonã«éç¥ããåé€ãäŸé ŒããŸããã
ETããã³ETPRO Suricata/Snortã·ã°ããã£
2837889 ETPRO CURRENT_EVENTS AWS S3 Hosted Phishing Landing M1
2837890 ETPRO CURRENT_EVENTS AWS S3 Hosted Phishing Landing M2
2837891 ETPRO CURRENT_EVENTS AWS S3 Hosted Phishing Landing M3