Proofpointã®ãªãµãŒãã£ãŒã¯ä»é±ãTA530ãšåŒã°ããã¢ã¯ã¿ãŒã䜿çšãããã¯ãã«èµ·ããé¡èãªå€åãæ°ä»¶èªããŸãããTA530ã¯ãå人ãç¹å®ãããå€§èŠæš¡ãªãã«ãŠã§ã¢ãã£ã³ããŒã³[4][5]ã«é¢é£ããŠã以ååŒç€Ÿã§èª¿æ»ãè¡ã£ãã¢ã¯ã¿ãŒã§ãã ãã®æ°ãããã£ã³ããŒã³ã«ã¯æ°ããªã€ãã€ã·ããªãã¯ããå«ãŸããããŒã«ããã¯ããã¯ã«ç¶ç¶ããå€åãèŠãããŸããæ»æè ãé²åããé²åŸ¡ãšãµã³ãããã¯ã¹äœ¿çšã®æ®åã«é©å¿ããŠããããšã瀺ããŠããŸãã
以åç§ãã¡ã¯ãæ·»ä»ããã¥ã¡ã³ãã®ãã¯ããææãããã·ã³ã®ãããªãã¯IPã¢ãã¬ã¹ãMaxMind[3]ã䜿çšããŠèª¿ã¹ãæè¿ã¢ã¯ã»ã¹ãããMicrosoft Wordãã¡ã€ã«ã®æ°ããã§ãã¯ããæ¹æ³ã説æããŸããã 9æ19æ¥ã«ã¯ããããããµã³ãããã¯ã¹ãåé¿ãããã§ãã¯ã«ããã€ã远å ãããããšãèªããŸããã ãããã®ãã§ãã¯ã«ããããã¯ãã¯æ¬¡ãè¡ããŸãïŒ
- ãã¡ã€ã«åã«ã¯ãæ¡åŒµåã®åã«16鲿°ã®æåã®ã¿äœ¿çšãããŠãããã©ããããã§ãã¯ãã
- Application.Tasks.Count[1]ãéããŠãã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã«å°ãªããšã50ã®å®è¡äžã®ããã»ã¹ãããããšã確èªãã
- Application.Tasks[2]ã䜿çšããããã»ã¹ãã©ãã¯ãªã¹ããå«ãã
- MaxMindã䜿çšããŠããã§ãã¯ããæååã®ãªã¹ããæ¡åŒµãã
ããäžã€ã®é¡èãªå€åã¯ãPainted Event[3]ã³ã³ãããŒã«ã®äœ¿çšã¯ãããã¥ã¡ã³ããéããŠããæã«ãã¯ãå®è¡ã®Img_PaintedãšããŠç¢ºèªãããããšã§ãã ããã¯ãMicrosoft Inkpictureã³ã³ãããŒã«ãã®ãªãã·ã§ã³ã®äžäœã«ããActiveXã³ã³ãããŒã«ã§ãã ãã®æ¹æ³ã¯ãDocument_Open()ã®ãããªããã¯ãå®è¡çšã®éåžžã®èªåå®è¡ãªãã·ã§ã³ãšã¯ç°ãªããŸãã 8æäžæ¬ã«ãJoe Securityãéåžžã«äŒŒéã£ããã¯ããã¯ã䜿çšããåæ§ã®ãã¯ãã«ã€ããŠèª¬æããŸããã
Eã¡ãŒã«ãã£ã³ããŒã³
9æ19æ¥ãTA530ã¯éåžžã®åäœ[2]ãç¶ããªãããWordããã¥ã¡ã³ãïŒå³2ïŒãéããããäŒç€Ÿåãå人åãè©æžçã䜿çšããŠå人ãç¹å®ããã¡ãã»ãŒãžïŒå³1ïŒãéä¿¡ããŸããã ããã¥ã¡ã³ãã®èªãã¯ããæ¬ããã¥ã¡ã³ãã¯ç¡èš±å¯ã®äœ¿çšããä¿è·ãããŠããŸããã³ã³ãã³ããé²èЧããã«ã¯ãç·šéãšã³ã³ãã³ããæå¹åããŠãã ãããããšã®ã¡ãã»ãŒãžã«ãããã¯ããæå¹åãããããŠãŒã¶ãŒã®æ°ãåŒãã éåžžã«å æ¬çãªãããããµããæ¹æ³ãçšããŠããŸãããã®ãã£ã³ããŒã³ã§äŒéããããã€ããŒãã¯ãUrsnif IDã30030ãã§ãã€ã³ãžã§ã¯ã[6]ã§ãªãŒã¹ãã©ãªã¢ã®éè¡ãµã€ããæšçãšããŠããŸãã

å³1: æªæã®ããããã¥ã¡ã³ããéãEã¡ãŒã«

å³2: ãã¯ããå«ãŸããæªæã®ããããã¥ã¡ã³ã
ãã¯ãè§£æ
ãã¯ãã®äžé£ã®æ°ãããã§ãã¯ã®ãã¡ãæåã®ãã®ã¯Microsoft Wordã®ãã¡ã€ã«åèªäœããã§ãã¯ããŸãã ãã¡ã€ã«åããæ¡åŒµåã®åã«ïŒã0123456789ABCDEFabcdefãã®ã»ããããïŒ16鲿³ã®æåã®ã¿ãå«ãã§ãããã©ããããã§ãã¯ããŸãããããå«ãŸããŠããå Žåããã¯ãã¯ç¶è¡ããŠè¢«å®³è ãææãããããšã¯ããŸããã ããã¯ãµã³ãããã¯ã¹ã«æåºããããã¡ã€ã«ã§ããçºçããŠããã16鲿³ã®æåã®ã¿ãå«ãSHA256ãŸãã¯MD5ã®ããã·ã¥ããã¡ã€ã«åãšããŠå€ã䜿çšããŠããŸãã ãfãããåŸã®æåããã¢ã³ããŒã¹ã³ã¢ãã¹ããŒã¹ãªã©ãä»ã®æåãå«ãŸããŠããå Žåããã®ãã§ãã¯ã¯åé¡ãªãæžã¿ããã¯ãã¯ç¶è¡ããŸãã ããã«ããã¡ã€ã«åã«ã¯ãæ¡åŒµåã®åã«ã.ãããªããŠã¯ãªããŸããã
å³3: ãã¡ã€ã«åã®16鲿³ã®æåã®ãã§ãã¯
ãã®ãã¯ãã®2çªç®ã®æ°ãããã§ãã¯ã§ã¯ãMicrosoft Wordã®Application.Tasks.Count[1]ããããã£ãéããŠãã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã«50以äžã®å®è¡äžã®ããã»ã¹ãããããšã確èªããŸãã å®éã®ã·ã¹ãã ã§ã¯ãç°¡åãªç¢ºèªã§50ãè¶ ããã¿ã¹ã¯æ°ãäžè¬çã§ããããšãããããŸããäžæ¹ããµã³ãããã¯ã¹ã·ã¹ãã ã§ã¯ãã¿ã¹ã¯æ°ããªãã¹ãå°ãªãããããæé©åãããŠããŸãã
å³4: å®è¡äžã®ããã»ã¹æ°ã®ãã§ãã¯
ãã®åŸãã¯ãã¯ãMicrosoft Wordã®Application.Tasksããããã£[2]ã䜿çšãããã¹ãã®ã·ã¹ãã ã§å®è¡ãããŠããå¯èœæ§ã®ããããã»ã¹ã®ãã©ãã¯ãªã¹ãã«ç §ãããŠã倧æåå°æåã®åºå¥ããããã§ãã¯ãè¡ããŸãã ãã©ãã¯ãªã¹ãã«èšèŒãããããã»ã¹åã«ã¯çŸåšãäžè¬çãªè§£æããŒã«ãšãµã³ãããã¯ã¹ç°å¢ã§å®è¡ãããŠããå¯èœæ§ãããã®ä»ã®ããã»ã¹ãå«ãŸããŸãïŒãfiddlerãããvxstreamãããvboxãããtcpviewãããvmwareãããprocess explorerãããvmtoolsãããautoitãããwiresharkãããvisual basicãããprocess monitorãã
å³5: ããã»ã¹ãã©ãã¯ãªã¹ãã®ãã§ãã¯
以åã®æçš¿ã§ããã®ãã¯ããæåãªå°çäœçœ®æ å ±ãµãŒãã¹MaxMindã«å¯ŸããŠã¯ãšãªãŒãè¡ããåãµãŒãã¹ããè¿ãããçµæã®ãã§ãã¯ãè¡ã£ãããšãæ«é²ããŸããã ãã®ç¹å®ã®ãã£ã³ããŒã³ã¯ãªãŒã¹ãã©ãªã¢ãæšçãšããŠãããããã¢ããããŒãããããã¯ãã¯æ£ããå°åã§å®è¡ããããããã§ãã¯ããæ©èœãçµã¿å ¥ããŠããŸãã å ·äœçã«ã¯ããªãŒã¹ãã©ãªã¢ãå«ãç±åž¯å€ªå¹³æŽã®å³¶ã ãäžå¿ãšããå°åãOCEANIAããçµæãå«ããããã¯ãããã§ãã¯ããŸãã
å³6: MaxMindã®ã¯ãšãªãšãOCEANIAãã®æååãã¯ãšãªã«ãã£ãŠè¿ãããã確èªãããã§ãã¯
æåŸã«ãMaxMindã®ã¯ãšãªâã®çµæãããã©ãã¯ãªã¹ãã«èšèŒããããããã¯ãŒã¯ã®æ¡åŒµãªã¹ãã«ç §ãããŠãã§ãã¯ïŒå€§æåå°æåãåºå¥ãªãïŒãããŸãã ãã®ããã¥ã¡ã³ãããããããã³ããŒã«å±ãããããã¯ãŒã¯ã§éãããŠãããšMaxMindã®çµæã瀺ããå Žåããã·ã³ã¯ææããŠããŸããã çè«çã«ã¯ãå€ãã®ã»ãã¥ãªãã£ãã³ããŒããã®ãªã¹ãã«å«ãŸããŸãããè峿·±ãããšã«ããhospitalãããuniversityãããschoolãããscienceãããarmyãããveteransãããgovernmentãããnuclearãã«å±ãããããã¯ãŒã¯ããŸãææããŠããŸããã æ£ç¢ºãªçç±ã¯å®ãã§ã¯ãããŸããããç ç©¶è ãè»éãŸãã¯æ¿åºãªã©ã®çµç¹ãžã®é²åºãæå°éã«ãšã©ããããšããæå³ã§ãããšèããããŸãã
å³7: ãããã¯ãŒã¯çµç¹ã®ãã©ãã¯ãªã¹ã
çµè«
å人ãç¹å®ããæ°ã ã®å€§èŠæš¡ãªæ»æã®èåŸã«ååšããã¢ã¯ã¿ãŒãTA530ã¯ãæè¿ã®ãã£ã³ããŒã³ã«äœ¿çšãããŠããæªæãããã¯ãã«ãåŒãç¶ãæ°ããåé¿ãã¯ããã¯ãçµã¿å ¥ããŠããŸãã åŒç€Ÿã確èªããææ°ã®ãã¯ããã¯ã¯ãäž»ã«ãµã³ãããã¯ã¹ã·ã¹ãã ã§ã®å®è¡ãšå°çäœçœ®æ å ±ã®é»æ¢ããã»ãã¥ãªãã£ãã³ããŒïŒããã³åŠè¡ãå»çãæ¿åºæ©é¢ïŒé¢é£ã®ãããã¯ãŒã¯ã®åé¿ã«é¢ä¿ããŠããŸãã ããæ°å¹Žããã«ãŠã§ã¢çšãµã³ãããã¯ã¹ã¯ãçµç¹ãäŒæ¥ããŠãŒã¶ãŒãããŒã¿ã®ä¿è·ã«åããŠå±éããŠããé²åŸ¡ã®ã³ã³ããŒãã³ããšããŠãŸããŸãäžè¬çã«ãªã£ãŠããŠããŸãã ãã®åæã®äŸã瀺ãããã«ãè åšã¢ã¯ã¿ãŒã¯ã被害è åŽã®é²åŸ¡ã«é ãããšããŸããšãã«ãŠã§ã¢çšãµã³ãããã¯ã¹åé¿ã®ç ç©¶ãšé©æ°ã«å°å¿µããŠããŸãã
æ»æãããããšã瀺ãçè·¡ïŒIOCïŒ
|
IOC |
IOCã®ã¿ã€ã |
詳现 |
|
6464cf93832a5188d102cce498b4f3be0525ea1b080fec9c4e12fae912984057 |
SHA256 |
æ·»ä»ããã¥ã¡ã³ã |
|
hxxp://deekayallday[.]com/data/office |
URL |
ããŠã³ããŒãããããã€ããŒã |
|
0b05fb5b97bfc3c82f46b8259a88ae656b1ad294e4c1324d8e8ffd59219005ac |
SHA256 |
Ursnif/DreambotããŒããŒïŒdocã®ããŠã³ããŒãïŒ |
|
hxxp://62.138.9[.]11/30030u |
URL |
Ursnifã¢ããããŒã |
|
hxxp://62.138.9[.]11/vnc32.dll |
URL |
Ursnif VNC |
|
hxxp://62.138.9[.]11/vnc64.dll |
URL |
Ursnif VNC |
|
62.138.9[.]9 |
IP |
UrsnifããŒã㌠C2 |
|
62.75.195[.]103 |
IP |
Ursnif C2 |
|
62.75.195[.]117 |
IP |
Ursnif C2 |
|
ca-tda[.]com |
ãã¡ã€ã³ |
Ursnif Webinjects C2 |
|
au-tdc[.]com |
ãã¡ã€ã³ |
Ursnif Webinjects C2 |
|
au-tda[.]com |
ãã¡ã€ã³ |
Ursnif Webinjects C2 |
|
109.236.87[.]82:443 |
IP |
Ursnif Socks |
åç §ïŒ
[1]https://msdn.microsoft.com/en-us/library/office/ff198203.aspx
[2]https://msdn.microsoft.com/en-us/library/office/ff839740.aspx
[3]https://msdn.microsoft.com/en-us/library/aa510893.aspx
[4]https://www.proofpoint.com/us/threat-insight/post/phish-scales-malicious-actor-target-execs
[5]https://www.proofpoint.com/us/threat-insight/post/malicious-macros-add-to-sandbox-evasion-techniques-to-distribute-new-dridex
[6]https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality




