æ¬ããã°ã¯ãè±èªçããã°ãhttps://www.proofpoint.com/us/threat-insight/post/urlzone-top-malware-japan-while-emotet-and-line-phishing-round-out-landscape-0ãã®ç¿»èš³ã§ãã
æŠèŠ
æ¥æ¬ã¯å€ãã®ç¹ã§äžçã®ãã¬ã³ããšå ±éããŠããŸãããæ¥æ¬ç¬èªã®åããããããšããããŸããæè¿ã®äžçã®è åšã©ã³ãã¹ã±ãŒãã®ãã¬ã³ãã¯ãEmotetã®å°ååãšæ¡æ£ããããŠæŽç·ŽããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æè¡ã掻çšãããã£ã³ããŒã³ã®çå®ãªå¢å ã§ããã®ã«å¯Ÿããæ¥æ¬ã§ã¯URLZoneãä»ã®å°åãããå€ã芳枬ãããé»åã¡ãŒã«é¢é£ã®æå€§ã®è åšãšãªã£ãŠããŸãã
URLZoneã¯ãæ¥æ¬ã®éè¡åãã®Webã€ã³ãžã§ã¯ã·ã§ã³ãèšå®ããUrsnifãã³ãã³ã°åããã€ã®æšéЬãèªã¿èŸŒãããããã€ããŒããšããŠãUrsnifãæ¥æ¬ã§ãããã§ããEmotet ãäžççã«äž»æµãå ããŠããããšã«å ããéå»ã«URLZoneãã³ã«ãŒ[1]ãVawtrakãä»ã®ãã³ãã³ã°åããã€ã®æšéЬãèªã¿èŸŒãã®ã芳枬ãããããProofpointã§ã¯URLZoneãšEmotetã®äž¡æ¹ã®ååãç£èŠãç¶ããŠããŸããEmotetã¯5ææ«ããæžå°ããŠããããã«èŠããŸãããURLZone/Ursnifã®ãã£ã³ããŒã³ã¯ç¶ç¶ããŠãããä»ã®å°åã§ã®Ursnifã®æŽ»åãç¶ããŠããŸãã
ãã£ã³ããŒã³
Proofpointã§ã¯2019幎ã®å§ã以éã倿°ã®è åšã¢ã¯ã¿ãŒãæ¥æ¬ãçã£ãŠæ°åäžéã®ã¡ãã»ãŒãžã«ããå€§èŠæš¡ãªãã£ã³ããŒã³ãæ°ååã«æž¡ã£ãŠè¡ã£ãããšã芳枬ããŸããããããã®ãã£ã³ããŒã³ã¯ããã³ãã³ã°åããã€ã®æšéЬããã£ãã·ã³ã°æ»æããªãããŸãæ»æããããŠã¹ãã ã¡ãŒã«ã®å€§èŠæš¡é ä¿¡ã«ãã£ãŠæ°åãã®æ¥æ¬ã®çµç¹ã«åœ±é¿ãäžããŸããã
ç¹çãã¹ãã¯ããããã®ãã£ã³ããŒã³ã«URLZoneãã³ãã³ã°åããã€ã®æšéЬãé ä¿¡ããLINEã®ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ãšé£æºããé»åã¡ãŒã«ãå«ãŸããŠããããšã§ãããããã®è åšã®å€ãã¯æ¥æ¬ã ããçã£ããã®ã§ãããæ¥æ¬ã¯ãã®ä»ã®ã°ããŒãã«ãã£ã³ããŒã³ãå€åœç±ãã£ã³ããŒã³ãããé »ç¹ã«çãããŠããŸãããããã®ãã£ã³ããŒã³ã¯éåžžãééçãªåæ©ãæã£ããµã€ããŒç¯çœªè ã«ãã£ãŠè¡ãããŸãã
以äžã¯ãæ¥æ¬ã®çµç¹ãçã£ããã£ã³ããŒã³ã§ããèŠããããã«ãŠã§ã¢ã®ãã€ããŒãã®æŠèŠã§ãã
URLZoneãšUrsnif
URLZoneã¯ãBeblohãŸãã¯ShiotobãšãåŒã°ãã2009幎ã«çºèŠãããé·ãæŽå²ãæã€ãã³ãã³ã°åããã€ã®æšéЬã§ããããã¯ãçºèŠåŸ10幎ãçµéããŠãæ¥æ¬ãçã£ããã£ã³ããŒã³ã§å®æçã«èŠ³æž¬ãããŠãããçŸæç¹ã§ã¯åç¬ã®å€§èŠæš¡ãªã¢ã¯ã¿ãŒãURLZoneã®å¯äžã®é ä¿¡å ãšããŠæ®ã£ãŠããããã§ãã
Proofpointã®ç ç©¶è ã¯ãURLZoneãã€ã³ã¹ããŒã«ãããã¯ããå«ããæªæã®ããMicrosoft Excelææžãæ·»ä»ãããé»åã¡ãŒã«ã¡ãã»ãŒãžã芳枬ããŸããïŒå³1ïŒããããã®ãã£ã³ããŒã³ã§ã¯ãURLZoneãæåã®ãã€ããŒããšããŠäœ¿çšãããŠããããã§ããã®ãã€ããŒããUrsnifãã€ã³ã¹ããŒã«ããŸãã

å³1ïŒ æ¥æ¬äººåãã«éä¿¡ãããMicrosoft Excelã¹ãã¬ããã·ãŒãã®äŸïŒ URLZoneãã€ã³ã¹ããŒã«ãããã¯ããå«ãã§ããïŒ
ãããã®ãã£ã³ããŒã³ã®å€ãã¯ãè«æ±æžãŸãã¯æ¯æãã®å¬ä¿ãè£ ã£ãŠããŸããæè¿è¡ããããã£ã³ããŒã³ã§ã¯ãè€æ°ã®ã©ã³ãã ãªéä¿¡ã¢ãã¬ã¹ããæ¬¡ã®ãããªä»¶åãæã€ã¡ãã»ãŒãžãéä¿¡ãããŸããïŒ
"FW: è«æ±æžãéä¿¡èŽããŸã"
"Re: è«æ±æžã®éä»"
"Re: è«æ±æžéä»ã®ãé¡ã"
"å¥çŽæžãã©ãŒã ãæ·»ä»èŽããŸã"
"ãæ¡å [ãæ¯æãæé:06æ18æ¥]"
"è«æ±æž"
"è«æ±æžéä»"
å³2ã¯ããã®ãã£ã³ããŒã³ã§éãããé»åã¡ãŒã«ã®äŸã瀺ããŠããŸãã

å³2ïŒ2019幎6æ17æ¥ã«éä¿¡ãããURLZone/Ursnifãé ä¿¡ããé»åã¡ãŒã«ïŒãµã³ãã«ïŒ
ãããã®ãã£ã³ããŒã³ã®å€§éšåã¯ãæ¥æ¬ãšã€ã¿ãªã¢ã§æŽ»åããŠããåäžã®ã¢ã¯ã¿ãŒãçºä¿¡æºãšãªã£ãŠããããã§ãããã®ã¢ã¯ã¿ãŒã¯ããžãªã¿ãŒã²ãã£ã³ã°ã®äžéšãšããŠé »ç¹ã«ã¹ãã¬ãã°ã©ã㣠[2] ïŒç»åãã¡ã€ã«ã®ã«ã©ãŒããŒã¿ã®ãæäžäœããããã«æªæã®ããã³ãŒããåã蟌ãããšïŒã䜿çšããŸãããã¯ãã¯ãæåã®ãã€ããŒããããŠã³ããŒãããŠãã³ãŒãããåã«ãç ç²ãšãªããã·ã³ãæ¥æ¬ã«ããããšã確èªããããã«ãäœéå±€ãã®é£èªåãšããã±ãŒã«ãèšèªã®ããŸããŸãªãã§ãã¯ãè¡ããŸããæè¿èŠ³æž¬ããããã±ãŒã«ãšèšèªã®ãã§ãã¯ã®äŸã¯æ¬¡ã®ãšããã§ãïŒExcel: "Application.International(xlCountrySetting)" begins with "8" (international Dialling Code for Japan is 81)
PowerShell error for non-existent command contains "çšèª " ("The term" in Japanese)
PowerShell cmdlet: 'Get-date' (needs to contain "幎" - "Year" in Japanese)
PowerShell cmdlet: 'Get-Culture."LCID"' needs to contain "04" (Japanese LCID is "1041")
ãã¹ãç°å¢ãé©åã§ãããšå€æãããšãURLZoneã¯UrsnifãããŠã³ããŒãããŸããããã¯æ å ±ãçã¿å§ãããããå žåçããªãã³ã«ãŒãšããŠæ©èœãå§ããŸãã[3]
Proofpointã®ç ç©¶è ã¯å°ãªããšã2017幎3æãããæ¥æ¬ãçã£ããã£ã³ããŒã³ã«ãããŠUrsnifã远跡ããŠããŸãããåæã®æåãå¹ãå¥ããTA544ãšåŒã°ããã¢ã¯ã¿ãŒãæè¿ã®Ursnifã®ããªã¥ãŒã ã®å€§éšåãå ããŠããŸãããProofpointã§ã¯ä»ã®ã¢ã¯ã¿ãŒãUrsnifã®äºçš®ãçŽæ¥é ä¿¡ããŠããããšã確èªããŠããŸããçŸæç¹ã§ã¯ãUrsnifã¯äžçã§ãæ¥æ¬ã§ããæãäžè¬çãªã³ã¢ãã£ãã£ãã³ã«ãŒã§ãã
Emotet
Emotetã¯ãã¹ãã éä¿¡ãã¯ã¬ãã³ã·ã£ã«æ å ±ã®çªåããããã¯ãŒã¯å ã§ã®æ¡æ£ãããã³ã¡ãŒã«ã¢ãã¬ã¹ã®åéã«äœ¿çšããããµãŒãããŒãã£ã®ãã«ãŠã§ã¢ããã³ç¬èªã®ã¢ãžã¥ãŒã«ã䜿çšãããå ç¢ãªäžçèŠæš¡ã®ããããããã§ãã
Proofpointã®ç ç©¶è ãTA542 [4]ãšããŠè¿œè·¡ããŠããã¢ã¯ã¿ãŒã¯ã4æ12ã15ãããã³16æ¥ã«åºç¯å²ã®æ¥çãæšçãšãã倧éã®ãã£ã³ããŒã³ãéå§ããæ¥æ¬ã«åœ±é¿ãäžããŸããããããã®ãã£ã³ããŒã³ã®ã¡ãã»ãŒãžã®å€§éšåã¯æ¥æ¬ã®çµç¹ã«éä¿¡ãããŸããããæ¥æ¬ã¯ãããŸã§Emotetãã¿ãŒã²ãããšããŠããäžå¿çãªå°åã«ã¯å«ãŸããŠããªãã£ããããããã¯æ³šç®ã«å€ããåãã§ããEmotetã®èåŸã«ããã¢ã¯ã¿ãŒã¯ããŒã«ã©ã€ãºã«ç²ŸéããŠããã宿çã«æ°ããå°åã«æŽ»åãæ¡å€§ããŠããŸãã5ææ«ä»¥éEmotetãã£ã³ããŒã³ã¯ã»ãŒåæ¢ããŠãããç§ãã¡ã¯æ¥æ¬ãã¯ãããšããä»ã®å°åã§ã®æ°ããæŽ»åãç£èŠãç¶ããŸãã
å³3ã¯ãæªæã®ããMicrosoft Wordææžãæ·»ä»ãããäžè¬çãªã¡ãã»ãŒãžã瀺ããŠããŸãããããã®ææžã«ã¯ãæå¹ã«ãããšEmotetã®ã€ã³ã¹ã¿ã³ã¹ãã€ã³ã¹ããŒã«ãããã¯ããå«ãŸããŠããŸããã

å³3ïŒæ¥æ¬åãã«éä¿¡ãããé»åã¡ãŒã«ã®äŸïŒ Emotetãã€ã³ã¹ããŒã«ãããã¯ããå«ãææžãæ·»ä»ãããŠããïŒ
TA505ãšFlawedAmmyy
Proofpointã§ã¯2019幎2æãè åšã¢ã¯ã¿ãŒã®TA505 [5]ã«ããæ¥æ¬ãçã£ãæ°ãããã£ã³ããŒã³ãçºèŠããŸãããTA505ã¯ãæè¿ã§ã¯äžåœãéåœãã©ãã³ã¢ã¡ãªã«ãããã³äžæ±ãäž»ã«çã£ãŠFlawedAmmyy Remote Access Trojan (RAT) [6]ãé ä¿¡ããŠããŸããã
FlawedAmmyyã¯ãAmmyy Adminãªã¢ãŒããã¹ã¯ããããœãããŠã§ã¢ïŒITãµããŒãã®ç®çã§äœ¿çšãããã·ã§ã¢ãŠã§ã¢ãŠãŒãã£ãªãã£ïŒã®ããŒãžã§ã³3ã®æµåºãããœãŒã¹ã³ãŒããããŒã¹ã«ããŠããŸãããã®ããFlawedAmmyyã«ã¯ã次ã®ãããªæ©èœãå«ãŸããŠããŸãïŒ
ãªã¢ãŒããã¹ã¯ãããå¶åŸ¡
ãã¡ã€ã«ã·ã¹ãã ãããŒãžã£
ãããã·ãµããŒã
ãªãŒãã£ãªãã£ãã
FlawedAmmyyã¯æ·»ä»ãã¡ã€ã«ä»ãã®é»åã¡ãŒã«ã§é åžãããŸãããããã®æ·»ä»ãã¡ã€ã«ã¯ããã¯ããæå¹ã«ãªã£ãŠããå Žåã«FlawedAmmyyãããŠã³ããŒãããMicrosoft ExcelïŒ.xlsïŒãŸãã¯WordïŒ.docïŒãã¡ã€ã«ã§ãïŒå³4ïŒã

å³4ïŒMicrosoft Officeæ·»ä»ãã¡ã€ã«ã«ããé åžãããFlawedAmmy RAT
ãããã®ãã£ã³ããŒã³ã®èŠæš¡ã¯ã¡ãã»ãŒãžæ°åéåã«ãããŸããã§ããããTA505ã¯ãããŸã§ã¢ãžã¢ãšäžæ±ã«ç¹ã«çŠç¹ãåœãŠãŠããŸããããã®æŽ»åçãªã¢ã¯ã¿ãŒãæ°ããå°åãã¿ãŒã²ããã«ããããšã¯ã泚ç®ã«å€ããŸãã
人äžå¿ã®è åš
ãããã®ãã«ãŠã§ã¢ãé åžããããŸããŸãªé»åã¡ãŒã«ã¯ãæ¥æ¬ã ããçã£ãæ»æããã€ããŒãã§ãããåœéçã«åºãŸã£ãŠãããã£ãã·ã³ã°æ»æãããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒãããã³ãã®ä»ã®ãªãããŸãæ»æã倧ããªè åšã§ããããšã«å€ããã¯ãããŸãããç¹ã«ãProofpointã宿çã«èŠ³æž¬ããŠããã®ã¯ïŒ
ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°
ããã¯ãProofpointã®ç ç©¶è ã«ãã£ãŠèŠ³æž¬ãããæãäžè¬çãªçš®é¡ã®ãã£ãã·ã³ã°æ»æã§ãããããã®é»åã¡ãŒã«ã¯ãããŸããŸãªãµã€ãããµãŒãã¹ã®ãŠãŒã¶ãŒåããã¹ã¯ãŒããªã©ã®ãã°ã€ã³ã¯ã¬ãã³ã·ã£ã«æ å ±ãçã£ãŠããŸãããããã¯å€§éã®é»åã¡ãŒã«ã䜿ã£ããã£ã³ããŒã³ã§ãéè¡ã倧åŠãé»å眲åãµãŒãã¹ããœãŒã·ã£ã«ã¡ãã£ã¢ããã³ãã¡ã€ã«å ±æãã©ãããã©ãŒã ãªã©ã®ä¿¡é Œã§ããæ©é¢ãéšã£ãã³ã³ãã³ããåã蟌ãã ãããã°ã€ã³ããŒãžãžã®ãªã³ã¯ãå«ãã ãããŠããŸããå³5ã¯ãããŸããŸãªå人ããŒã¿ãçãããšãããæ¥æ¬ã®ããã¡ãéè¡ã®é¡§å®¢ãçã£ããã£ãã·ã³ã°ã©ã³ãã£ã³ã°ããŒãžã§ãã

å³5ïŒããã¡ãéè¡ã®é¡§å®¢ãžã®ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°
(https://www.antiphishing.jp/news/alert/jpbank_japanpost_20190304.html)
ãŸããæ³šç®ã«å€ããã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ã®äŸãšããŠãLINEã®ãŠãŒã¶ãŒãçã£ããã®ããããŸããLINEã¯ãæ¥æ¬ãã¿ã€ãå°æ¹Ÿã§æã人æ°ã®ããã¡ãã»ãŒãžã³ã°ã¢ããªã®ã²ãšã€ã§ããããã®åœã ã«çŽ1å6,500äžäººã®ãŠãŒã¶ãŒãããŸããLINEã¯WhatsappãFacebook MessengerãŸãã¯äžåœã®WeChatã«äŒŒããµãŒãã¹ã§ãæ¥æ¬ã«ã¯æ¯æçŽ7800äžã®ã¢ã¯ãã£ããŠãŒã¶ãŒãååšããŸãã
Proofpointã§ã¯ãæ¥æ¬ã®çµç¹ãçããLINEã®ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ãªã³ã¯ãå«ãã ã¡ãŒã«ã¡ãã»ãŒãžã芳å¯ããŠããŸããïŒå³6ïŒããããã®ã¡ãã»ãŒãžã¯"LINEå®å šèªèšŒ"ãšããä»¶åã䜿ã£ãŠããŸãã

å³6. LINEã¢ããªã®ãã£ãã·ã³ã°ã«ã¢ãŒã®äŸ ïŒåºå žïŒCyamax.comïŒ
ãã®ã¿ã€ãã®äººçèŠå ã®äŸµå®³ã¯ããã®å®è£ ã«ãããŠã¯ããªãåçŽïŒç¥å床ã®é«ãåæ³çãªãã©ã³ããççšããæšæºçãªã¿ã€ãã®ãã£ãã·ã³ã°æ»æïŒã§ãããæ¥æ¬ã§ã¯LINEã®ã·ã§ã¢ãé«ããããéåžžã«æå¹ã§ããããã«ãå€ãã®ãŠãŒã¶ãŒãããŸããŸãªãµãŒãã¹ã§åãã¯ã¬ãã³ã·ã£ã«æ å ±ã䜿ãåããããè åšã¢ã¯ã¿ãŒã¯LINEã®ã¯ã¬ãã³ã·ã£ã«æ å ±ãçãããšã§ãä»ã®å€ãã®ã¢ããªããã©ãããã©ãŒã ã®ããã®ã¯ã¬ãã³ã·ã£ã«æ å ±ãåŸãããšãã§ããŸãã
ãªãããŸãã®è åš
ãªãããŸãã®è åšã«ã¯ãå人ã忥å£äœããŸãã¯éè¡ãã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒãªã©ã®æåãã©ã³ãã«ãªãããŸãããšãç®çãšããæªæã®ããé»åã¡ãŒã«ãå«ãŸããŸãããã®çš®ã®è©æ¬ºè¡çºã¯ãä»ã®ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã¡ã«ããºã ãšçµã¿åãããŠããã«ãŠã§ã¢ã®é ä¿¡ãã¯ã¬ãã³ã·ã£ã«æ å ±ãã£ãã·ã³ã°ããŸãã¯ãããªããããã¯ãŒã¯ã®äŸµå®³ã«ãããããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒãªã©ã®ééç®çã®äžæ£ã«äœ¿çšãããå¯èœæ§ããããŸãã

å³7ïŒæ¥æ¬ãã¿ãŒã²ããã«ããããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒã®äŸãBECã¯ããã«ãŠã§ã¢ããã£ãã·ã³ã°ãããã«èªå°ãããªã³ã¯ãæ·»ä»ãã¡ã€ã«ããªãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã«äŸåãããªãããŸãã®äžçš®ã§ããïŒhttps://www.ipa.go.jp/security/announce/201808-bec.htmlïŒ
ä»ã®åœã ãšæ¯èŒããŠãæ¥æ¬ã§ã¯BECã¯éåžžã«å°ãªããããã¯èšèªã®ãŠããŒã¯ãã®ããã«éãã€ãã£ãã¹ããŒã«ãŒãæ¥æ¬èªã§å¯Ÿè©±ããããšãé£ããã广çãªã«ã¢ãŒãäœãããšãé£ããããšã瀺ããŠããŸããäžççã«ã¯ããã®ã¿ã€ãã®äººçèŠå ãçãæ»æãå¢ããŠããŸãã
çµè«
2019幎ã¯ãæ¥æ¬ã®ãã©ã³ããžã®ãªãããŸããå°åãã¿ãŒã²ãããšãããã«ãŠã§ã¢ããã³ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ãã£ã³ããŒã³ã«ããæ¥æ¬ã®çµç¹ãããžãã¹ãžã®è åšã®ããã«ãæ¥æ¬äŒæ¥ã®é²åŸ¡æ åœè ã¯é«åºŠãªæšçåæ»æãšåæã«åœéçãªæ»æã«ãæ°ãã€ããå¿ èŠããããŸãã
UrsnifãšEmotetããããããã¯ãæ¥æ¬ãçãæãäžè¬çãªè åšã§ãããé åçãªã«ã¢ãŒãšæŽç·ŽããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã¡ã«ããºã ãå©çšããããšã«ãã£ãŠãçµç¹ãšå人ã«ãšã£ãŠæãããªè åšãšãªããŸãã
æ¥æ¬ãçã£ãŠããè åšã¯ç¹ã«ç®æ°ãããã®ã§ã¯ãããŸããããURLZoneã«ã€ããŠã¯ãã®ã¢ã¯ã¿ãŒãéåžžã«æŽ»çºã§ã¢ããªã±ãŒã·ã§ã³ããŠããŒã¯ãªãããä»ã®å°åãšã¯éããªã¹ã¯ãšãªã£ãŠããŸããæ¥æ¬ã«ãããŠã¯èšèªãé害ãšãªããããéãã€ãã£ãã¹ããŒã«ãŒã广çãªãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã¢ãããŒããæ§ç¯ããããšãé£ãããªã£ãŠããŸãããUrsnifãšEmotetã«ããå€§èŠæš¡ãªæ»æãèµ·ããŠããããšã¯ãçµæžçåæ©ã®ããã¢ã¯ã¿ãŒããã³ãŒããã¯ã©ãã¯ãããŠãã®å°åã®é²åŸ¡æ åœè ãçµç¹ãããã³æ¶è²»è ã«æ°ããªãªã¹ã¯ãçã¿åºããããšã瀺åããŠããŸããæ¥æ¬ãæšçãšããæ»æã®å¢å ã«å¯Ÿå¿ããŠãããŒã¿ãç¥ç財ç£ãããã³éèŠãªã€ã³ãã©ãä¿è·ããããã«ã¯ãå€éå±€é²åŸ¡ãšãšã³ããŠãŒã¶ãŒæè²ã®çµã¿åãããéèŠã«ãªããŸãã
References
[1] https://www.proofpoint.com/us/threat-insight/post/Vawtrak-UrlZone-Banking-Trojans-Target-Japan
[2] https://www.crowdstrike.com/blog/cutwail-spam-campaign-uses-steganography-to-distribute-urlzone/
[3] https://www.cybereason.com/blog/new-ursnif-variant-targets-japan-packed-with-new-features
[5] https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta505-dridex-globeimposter