ESET/ãã«ã¦ã§ã¢æ å ±å±
macOSãçã£ããã«ã¦ã§ã¢ãã¢ãããã¼ãã§æ©è½è¿½å
ãæ¬è¨äºã¯ãã¤ãã³ãã¼ã±ãã£ã³ã°ã¸ã£ãã³ãæä¾ããããã«ã¦ã§ã¢æ å ±å±ãã«æ²è¼ããããOceanLotusãmacOSãæ¨çã¨ãããã«ã¦ã§ã¢ãã¢ãããã¼ãããåç·¨éãããã®ã§ãã
ã2019å¹´3æä¸æ¬ã人æ°ã®ãªã³ã©ã¤ã³ã¹ãã£ã³ãµã¼ãã¹ã§ããVirusTotalä¸ã«ãAPTã°ã«ã¼ããOceanLotusãã«ããmacOSãã¿ã¼ã²ããã¨ããæ°ããªãã«ã¦ã§ã¢ã®ãµã³ãã«ãã¢ãããã¼ããããããã®ããã¯ãã¢ã®å®è¡ãã¡ã¤ã«ã¯ã以åã®macOSåãäºç¨®ã¨åãç¹å¾´ãæã£ã¦ããããããããã®æ§é ã¯å¤§ããå¤è²ãéããæ¤åºãããã¨ãé常ã«é£ãããªã£ã¦ãããæ®å¿µãªãããESETã§ã¯ãã®ãµã³ãã«ã«é¢ããããããã¼ãçºè¦ã§ããªãã£ããããæåã®æææºãç¹å®ã§ãã¦ããªãã
ãå æ¥ãESETã¯OceanLotusã®ã¢ãããã¼ãã«é¢ãã詳細ãçºè¡¨ããããã®ãã«ã¦ã§ã¢ã¯ãã¾ãã¾ãªææ³ãé§ä½¿ãã¦ã³ã¼ããå®è¡ããå·æã«æ»æãç¶ãããããã«ãWindowsã·ã¹ãã ä¸ã«ã»ã¨ãã©çè·¡ãæ®ããªãããã«ãªã£ã¦ãããOceanLotusã¯ãmacOSã«è¢«å®³ãããããã³ã³ãã¼ãã³ããå«ãã§ãããã¨ãç¥ããã¦ãããä»åã®ãã®è¨äºã§ã¯ããã¬ã³ããã¤ã¯ã社ãåæãã以åã®macOSãã¼ã¸ã§ã³ããã®å¤æ´ç¹ã詳ãã解説ãããããã«ããã®äºç¨®ã®ã³ã¼ããåæããéã«IDA Hex-Rays APIã§æååãèªåçã«å¾©å·ããæ¹æ³ã«ã¤ãã¦ã説æããã
åæ
ãæ¬è¨äºã§åãä¸ãã以ä¸ã®3ã¤ã®ã»ã¯ã·ã§ã³ã§ã¯ãSHA-1ããã·ã¥å¤E615632C9998E4D3E5ACD8851864ED09B02C77D2ãç¨ãããµã³ãã«ã®åæçµæã«ã¤ãã¦èª¬æããããã®ãã¡ã¤ã«ã¯ãã©ãã·ã¥ã©ã¤ãåï¼flashlightï¼ã¨å¼ã°ããESET製åã§ã¯OSX/OceanLotus.Dã¨ãã¦æ¤åºãããã
ã¢ã³ããããã°ã¨ã¢ã³ããµã³ãããã¯ã¹
ãOceanLotusã®macOSç¨ãã¤ããªã¼ã§ã¯å¾æ¥ã©ããããµã³ãã«ãUPXã§å§ç¸®ããã¦ãããããããã»ã¨ãã©ã®ããã«ã¼èå¥ãã¼ã«ã§ã¯ãããèªèã§ããªããããã¯ãæååãUPXããå©ç¨ããã·ã°ããã£ãå«ã¾ãã¦ãããã¨ãå¤ãããã§ãããããã«ãMach-Oã®ã·ã°ããã£ã¯ãã¾ãä¸è¬çã§ã¯ãªããå®æçã«ã¢ãããã¼ãããã¦ããªãã¨ããçç±ãããããã®ç¬èªã®ç¹å¾´ã®ãããéçã«æ¤åºããã®ã¯ããã«é£ãããªã£ã¦ãããããã§èå³æ·±ãã®ã¯ã解åãããã¨ã.TEXTã»ã°ã¡ã³ãã®__cfstringã»ã¯ã·ã§ã³ã®æåãã¨ã³ããªã¼ãã¤ã³ãã«ãªããã¨ã§ããããã®ã»ã¯ã·ã§ã³ã¯ãå³1ã®ã¨ãããã©ã°å±æ§ãæã£ã¦ããã
ãå³2ã®ã¨ãããã³ã¼ãã__cfstringã»ã¯ã·ã§ã³å ã«è¨è¿°ããã¦ããã¨ãéã¢ã»ã³ããªãã¼ã«ã¯èª¤ã£ã¦ã³ã¼ããæååã¨ãã¦è¡¨ç¤ºãã¦ãã¾ãã
ããã¤ããªã¼ã¯å®è¡ãããã¨ãæåã«ã¢ã³ããããã°æ©è½ãæã£ãã¦ã©ããããã°(watchdog) *1ã¨ãã¦ã¹ã¬ãããä½æããããã®å¯ä¸ã®ç®çã¯ããããã¬ãåå¨ããªãã絶ãã確èªãããã¨ã§ããããã®ããããã®ã¹ã¬ããã¯ã
*1 å訳ãçªç¬ããã転ããã·ã¹ãã ã®åä½ç¶æ³ãç£è¦ããããã¤ã¹ãã½ãããæ©è½å ¨è¬ãæããããã§ã¯ãããã¬ã®åå¨ã常æ確èªããåå¨ã確èªãããå ´åãexité¢æ°ãå¼ã³åºãããããã°ã©ã ããã¦ããã
- è¦æ±ãã©ã¡ã¼ã¿ã§ããPT_DENY_ATTACHã§ptraceãå¼ã³åºãã¦ããããã¬ãåãé¢ããã¨ãã
- task_get_exception_portsé¢æ°ãå¼ã³åºãã¦ã対象å¤ãã¼ããéãã¦ããªãã確èªãã
- ç¾å¨ã®ããã»ã¹ã§P_TRACEDãã©ã°ãè¨å®ããã¦ããããæ¤è¨¼ãããããã¬ãå³3ã®ã¨ããã¢ã¿ããããã¦ããã確èªãã
ãã¦ã©ããããã°ããããã¬ã®åå¨ãæ¤åºããã¨ãexité¢æ°ãå¼ã³åºããããããã«ããµã³ãã«ã¯ä»¥ä¸äºã¤ã®ã³ãã³ããéä¿¡ãã¦ãã®ç°å¢ã確èªããã
ioreg -l | grep -e âManufacturerâ
sysctl hw.model
ãããã¦æ¢ç¥ã®ä»®æ³åã·ã¹ãã ã®æåå (oracleãvmwareãvirtualboxã¾ãã¯parallels) ã®ãã¼ãã³ã¼ãããããªã¹ãã¨æ»ãå¤ãç
§åãããæå¾ã«ã以ä¸ã®ã³ãã³ãã¯ããã·ã³ããMBPãããMBAãããMBãããMMãããIMãããMPãããXSãã®ãããã«ç¸å½ããã®ã確èªããããããã®ã³ã¼ãã¯ã·ã¹ãã ã®ã¢ãã«ã表ãã¦ãããä¾ãã°ããMBPãã¯MacBook ProãããMBAãã¯MacBook Airã表ãã¦ããã
system_profiler SPHardwareDataType 2>/dev/null | awk â/Boot ROM Version/ {split($0, line, â:â);printf(â%sâ, line[2]);}
ã¡ã¸ã£ã¼ã¢ãããã¼ã
ããã¬ã³ããã¤ã¯ã社ã®è¨äºä»¥éãããã¯ãã¢ã®ã³ãã³ãã¯å¤æ´ããã¦ããªããããããESETã¯è¥å¹²ã®ä¿®æ£ãçºè¦ããããã®ãµã³ãã«ã«ä½¿ç¨ããã¦ããC&Cãµã¼ãã¼ã¯æ¯è¼çæè¿ã®ãã®ã§ããã2018å¹´10æ22æ¥ã«ä½æããã¦ããã
- daff.faybilodeau[.]com
- sarc.onteagleroad[.]com
- au.charlineopkesston[.]com
ã使ç¨ããã¦ããURLãªã½ã¼ã¹ã¯ã以ä¸ã«å¤æ´ããã¦ããã/dp/B074WC4NHW/ref=gbps_img_m-9_62c3_750e6b35
ãC&Cãµã¼ãã¼ã«éä¿¡ãããæåã®ãã±ããã«ã¯ããã¹ããã·ã³ã«é¢ãã詳細æ å ±ãå«ã¾ãã¦ãããä¸è¡¨ã®ã³ãã³ãã§åéããããã¼ã¿ãã¹ã¦ãå«ãã§ããã
ã³ãã³ã | system_profiler SPHardwareDataType 2>/dev/null | awk '/Processor / {split($0,line,":"); printf("%s",line[2]);}' machdep.cpu.brand_string |
system_profiler SPHardwareDataType 2>/dev/null | awk '/Memory/ {split($0,line, ":"); printf("%s", line[2]);}' | ifconfig -l | ioreg -rd1 -c IOPlatformExpertDevice | awk ' /IOPlatformSerialNumber/ { split($0, line, "\""); printf("%s", line[4]); }' |
---|---|---|---|---|
説æ | ããã»ããµã¼ã®æ å ±ãåé | ã¡ã¢ãªã¼ã®æ å ±ãåé | ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ã®MACã¢ãã¬ã¹ãåé | ããã¤ã¹ã®ã·ãªã¢ã«çªå·ãåå¾ |
ããã®ãµã³ãã«ã¯ãä¸è¨ã®ã¨ããæ§æãå¤æ´ãããä¸ã«ããããã¯ã¼ã¯ããæã¡åºãããã®libcurlã©ã¤ãã©ãªã使ç¨ãã¦ããªãã代ããã¨ãã¦ãå¤é¨ã©ã¤ãã©ãªã使ç¨ãã¦ããããããçªãæ¢ãããããããã¯ãã¢ã¯ã¼ãããã£ã³ã°*2ããããã¼gFjMXBgyXWULmVVVzyxyãç¨ããAES-256-CBCã§ãã«ã¬ã³ããã£ã¬ã¯ããªã«åãããã¦ããåãã¡ã¤ã«ã®å¾©å·ã試ã¿ãã
ãåãã¡ã¤ã«ã¯ã復å·åããããã/tmp/storeãã¨ãã¦ä¿åããããããã«ãdlopené¢æ°ã§ä½æãããã©ã¤ãã©ãªã¨ãã¦ãã¡ã¤ã«ã®ãã¼ãã試ã¿ãã復å·åã§dlopenã®å¼ã³åºãã«æåããã¨ãããã¯ãã¢ã¯ã¨ã¯ã¹ãã¼ããããé¢æ°Boriryã¨ChadylonVãåå¾ããããããã¯ããµã¼ãã¼ã¨ã®ãããã¯ã¼ã¯éä¿¡ããããªãã¨èãããã¦ããããã§ãããESETã¯å ã®ãµã³ãã«ããããããã¼ãä»ã®ãã¡ã¤ã«ãå ¥æãã¦ããªãããããã®ã©ã¤ãã©ãªãåæã§ããªãã£ããããã«ãã³ã³ãã¼ãã³ããæå·åããã¦ããããããããã®æååã«åºã¥ãã¦ä½æãããYARAã«ã¼ã«*3ã¯ãã£ã¹ã¯ä¸ã§æ¤åºããããã¡ã¤ã«ã¨ä¸è´ããªãã
*2 ãã¼ãï¼0ï¼ãããããã£ã³ã°ï¼åããï¼ãè¡çºã®ãã¨ãæããä¾ãã°ã6æ¡æå®ã®é¨åã«4æ¡ãããªãå ´åã2æ¡åã®ã0ãã追å ããã¨ã©ã¼ãåé¿ããã
*3 ãã«ã¦ã§ã¢ã®æ¤åºãåæã®ããã®ããã°ã©ã ãYARAãã«ããããè¨è¿°ã«ã¼ã«ã®ãã¨ãYARAã¯Pythonããã¼ã¹ã¨ãããªã¼ãã³ã½ã¼ã¹ã§ãããGitHubãªã©ã§é
å¸ããã¦ããã
â»GitHub URLï¼https://github.com/VirusTotal/yaraï¼
ã以åã®macOSåãäºç¨®ã®åæã®ã¨ããã§è§£èª¬ããã¨ãããã¯ã©ã¤ã¢ã³ãIDãä½æãããããã®IDã¯ã以ä¸ã®ã³ãã³ãã®ããããã®æ»ãå¤ã§ããMD5ããã·ã¥å¤ã§ããã
- ioreg -rd1 -c IOPlatformExpertDevice | awk â/IOPlatformSerialNumber/ { split($0, line, â\ââ); printf(â%sâ, line[4]); }â
- ioreg -rd1 -c IOPlatformExpertDevice | awk â/IOPlatformUUID/ { split($0, line, â\ââ); printf(â%sâ, line[4]); }â
- ifconfig en0 | awk \â/ether /{print $2}\â (MACã¢ãã¬ã¹ãåå¾)
- 以åã®ãµã³ãã«ã§ãuuidgenãã¨ãã¦ä½¿ç¨ãããä¸æãªã³ãã³ã (ã\x1e\x72\x0aã)
ãããã·ã¥åããåã«ãroot権éã示ãæ»ãå¤ã«æåã0ãã¾ãã¯ã1ãã追å ãããããã§ãªãå ´åããã®ã¯ã©ã¤ã¢ã³ãIDã¯ä»¥ä¸ã«æ ¼ç´ãããã
/Library/Storage/File System/HFS/25cf5d02-e50b-4288-870a-528d56c3cf6e/pivtoken.appex ~/Library/SmartCardsServices/Technology/PlugIns/drivers/snippets.ecgML
é常ããã®ãã¡ã¤ã«ã¯chflagsé¢æ°ã§é ãã¦ãããã¿ã¤ã ã¹ã¿ã³ãã¯ä¹±æ°å¤ã«ãããtouch âtãã³ãã³ããç¨ãã¦ä¿®æ£ãããã
æååã®å¾©å·
ã以åã®ãã¼ã¸ã§ã³ã¨åæ§ã«ãæååã¯CCCrypté¢æ°ãç¨ããAES-256-CBC (16é²æ°ã¨ã³ã³ã¼ãããããã¼:ã¼ãããã£ã³ã°ããã 9D7274AD7BCEF0DED29BDBB428C251DF8B350B92ãIV*4ã¯ã¼ãã§åãã) ã§æå·åããã¦ããã
ããã¼ã¯ä»¥åã®ãã¼ã¸ã§ã³ããå¤æ´ããã¦ãããããã®ã°ã«ã¼ãã¯æååãæå·åããã®ã«åãã¢ã«ã´ãªãºã ã使ç¨ãã¦ãããããèªåçã«å¾©å·ãããã¨ãã§ãããä»åã®ãã®è¨äºã¨ä½µããESETã§ã¯ãã¤ããªã¼å ã«ããæååã復å·ããããã«Hex-Rays APIãå©ç¨ããIDAã¹ã¯ãªãããå ¬éãã¦ããããã®ã¹ã¯ãªããã«ãã£ã¦ãä»å¾OceanLotusã®ã¨ã¯ã¹ããã¤ããåæããESETãã¾ã å ¥æã§ãã¦ããªãæ¢åãµã³ãã«ã®åæã«è²¢ç®ãããã¨ãæå¾ ãããã
ããã®ã¹ã¯ãªããã§éè¦ãªã®ã¯ãé¢æ°ã«æ¸¡ãå¼æ°ãå ¥æããä¸è¬çãªã¡ã½ããã®é¨åã§ãããããã«ããã®ã¹ã¯ãªããã¯ããã®å¤ãæ±ããããã«ãã©ã¡ã¼ã¿ã®å²ãå½ã¦ãæ¢ãåºãããã®ã¡ã½ãããåå©ç¨ããã¨ãé¢æ°ã®å¼æ°ãªã¹ããåå¾ããå¼æ°ãã³ã¼ã«ããã¯é¢æ°ã«æ¸¡ããã¨ãã§ããã
*4 initialization vectorã®ç¥ã§å訳ã¯ãåæåãã¯ãã«ããæå·åã¨åæã«çæãããæ°å¤ã®ãã¨ãåãå¹³æãåãæå·æã«ãªããªãããã«ä½¿ç¨ããã
ããã®ã¹ã¯ãªããã¯decrypté¢æ°ã®ãããã¿ã¤ããææ¡ããä¸ã§ãæåã«ãã®é¢æ°ã¸ã®ç¸äºåç §ããã¹ã¦æ¤ç´¢ããã次ã«ãå¼æ°ããã¹ã¦è¦ã¤ãåºãã¦ããã¼ã¿ã復å·ããç¸äºåç §ã®ã¢ãã¬ã¹ã«ããã³ã¡ã³ãã«å¹³æãåãè¾¼ãã
ãã¹ã¯ãªãããæ£å¸¸ã«æ©è½ããããã«ãbase64*5ã®ãã³ã¼ãé¢æ°ã§ä½¿ç¨ããã«ã¹ã¿ã ã®ã¢ã«ãã¡ããããã¹ã¯ãªããã«ããã¦è¨å®ããªããã°ãªããªããã¾ãããã®ãã¼ã®é·ããå«ãã°ãã¼ãã«å¤æ°ãå®ç¾©ããå¿ è¦ãããï¼ãã®å ´åãDWORDã¨ãã¦å®ç¾©ãå³4ãåç §ï¼ã
*5 ãã¼ã¿ã®ã¨ã³ã³ã¼ãæ¹å¼ã®ä¸ã¤ã§ã64種é¡ã®è±æ°åã«éå®ãã¦éä¿¡ããããªãã
ãé¢æ°ã¦ã£ã³ãã¦å ã®å¾©å·é¢æ°ãå³ã¯ãªãã¯ãããå¼æ°ã®æ½åºã¨å¾©å·ããã¯ãªãã¯ãããã¹ã¯ãªããã¯ãå³5ã®ã¨ãã復å·ãããæååãã³ã¡ã³ãã«åãè¾¼ãã
ãããã«ãããå³6ã®ã¨ããé¢æ°ã¦ã£ã³ãã¦ã¸ã®IDAã®ç¸äºåç §ã«å¾©å·ãããæååãã¾ã¨ãã¦ç°¡åã«ãªã¹ãã¢ãããããã¨ãã§ããã
ãESETã§ã¯ãGithubã®ã¬ãã¸ããªã¼ã§æçµã¹ã¯ãªãããå ¬éãã¦ããã
çµè«
ãæè¿ãESETã®å¥ã®è¨äºã§åãä¸ããã¨ãããOceanLotusã°ã«ã¼ãã¯ãã®ãã¼ã«ã»ããã常ã«æ¹åããã¢ãããã¼ããç¹°ãè¿ãã¦ãããä»åããMacã¦ã¼ã¶ã¼ãæ¨çã¨ãããã¼ã«ãæ¹åããã°ããã§ãããã³ã¼ãã¯å¤§ãã¦å¤æ´ããã¦ããªããããããå¤ãã®Macã¦ã¼ã¶ã¼ãèªèº«ã®ãã·ã³ã§ã»ãã¥ãªãã£ã½ããã¦ã§ã¢ã使ç¨ãã¦ããªããããæ¤åºãåé¿ããå¿ è¦æ§ã¯è»½è¦ããã¦ããããã ãESETã¯ãã®ãã¡ã¤ã«ãçºè¦æ¬¡ç¬¬ããã¿ããã«è£½åã«é©ç¨ãæ¤åºã§ããããã«ãã¦ãããä¸æ¹ã§ãC&Céä¿¡ã§ä½¿ç¨ããã¦ãããããã¯ã¼ã¯ã©ã¤ãã©ãªã¯ãã£ã¹ã¯ä¸ã§æå·åããã¦ããããã使ç¨ããã¦ããæ£ç¢ºãªãããã¯ã¼ã¯ãããã³ã«ã¯ç¾æç¹ã§ãä¾ç¶ã¨ãã¦ä¸æã®ã¾ã¾ã§ããã
ææã®çãã確èªããããã®ææ¨ = (å±æ®åææ¨ãIoC )
ãESETã¯ãGithubã®ã¬ãã¸ããªã¼ã§æ¬è¨äºã«æ²è¼ãã¦ããIoCã ãã§ãªããMITRE ATT&CK *6ããã®æ å ±ãå ¬éãã¦ããã
*6 ç±³å½ã®éå¶å©ç 究æ©é¢ã§ãããMITREããéå¶ããããµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ãããã¬ãã¸ãã¼ã¿ãã¼ã¹ã®ãã¨ã
ãã¡ã¤ã³å
- daff.faybilodeau[.]com
- sarc.onteagleroad[.]com
- au.charlineopkesston[.]com
URLãªã½ã¼ã¹
- /dp/B074WC4NHW/ref=gbps_img_m-9_62c3_750e6b35
ãã¡ã¤ã«ãã¹
- ~/Library/SmartCardsServices/Technology/PlugIns/drivers/snippets.ecgML
- /Library/Storage/FileSystem/HFS/25cf5d02-e50b-4288-870a-528d56c3cf6e/pivtoken.appex
- /tmp/store
åæãããµã³ãã« | ãã©ãã·ã¥ã©ã¤ãå |
---|---|
SHA-1ããã·ã¥å¤ | E615632C9998E4D3E5ACD8851864ED09B02C77D2 |
ESETæ¤åºå | OSX/OceanLotus.D |
MITRE ATT&CKä¸ã«ãããææ³ | ||||||||
---|---|---|---|---|---|---|---|---|
æ¦è¡ | é²å¾¡åé¿ | é²å¾¡åé¿ | é²å¾¡åé¿ | é²å¾¡åé¿ | é²å¾¡åé¿ | æ¤ç¥ | æã¡åºã | ã³ãã³ã&ã³ã³ããã¼ã« |
ID | T1158 | T1107 | T1222 | T1027 | T1099 (macOS) | T1082 | T1022 | T1094 |
åå | é ããã¡ã¤ã«ã¨ãã£ã¬ã¯ã㪠| ãã¡ã¤ã«ã®åé¤ | ãã¡ã¤ã«ãã¼ããã·ã§ã³ã®ä¿®æ£ | é£èªåããããã¡ã¤ã«ã¾ãã¯æ å ± | ã¿ã¤ã ã¹ã¿ã³ã | ã·ã¹ãã æ å ±ã®æ¤ç¥ | ãã¼ã¿ã®æå·å | ã«ã¹ã¿ã ã®C&Cãããã³ã« |
説æ | ããã¯ãã¢ã¯ãchflagé¢æ°ã§clientIDãã¡ã¤ã«ãé ãã | ããã¯ãã¢ã¯ããåé¤ãã³ãã³ããåä¿¡ã§ããã | ããã¯ãã¢ã¯ãå®è¡ããããã¡ã¤ã«ãã¼ããã·ã§ã³ã755*7ã«å¤æ´ããã | ãããã¯ã¼ã¯ããã®æã¡åºãã«ä½¿ç¨ããã©ã¤ãã©ãªããCBCã¢ã¼ã*8ã§AES-256ãç¨ãã¦æå·åããã | clientIDãæ ¼ç´ãããã¡ã¤ã«ã®ã¿ã¤ã ã¹ã¿ã³ãããä¹±æ°å¤ã§ä¿®æ£ããã | ããã¯ãã¢ã¯ãC&Cãµã¼ãã¼ã¸ã®ååæ¥ç¶æã«ãã·ã³ã®ãã£ã³ã¬ã¼ããªã³ã *9ãä½æããã | ããã¯ãã¢ã¯ãæã¡åºãåã«ãã¼ã¿ãæå·åããã | ããã¯ãã¢ã¯ãä¹±æ°å¤ãå«ããã±ããå°ç¨ã®ãã©ã¼ããããå®è£ ããããã¬ã³ããã¤ã¯ã社ã®è¨äºãåç §ã |
*7 ãã¡ã¤ã«ã®ãã¼ããã·ã§ã³ãã755ãã«å¤æ´ããã¨ãèªã¿åºãã»å®è¡ã¯ãã¹ã¦ã®ã¦ã¼ã¶ã¼ãå¯è½ãæ¸ãè¾¼ã¿ã®ã¿ãªã¼ãã¼ãå¯è½ã¨ãã権éè¨å®ã¨ãªãã
*8 ãCBCï¼Cipher Block Chainingï¼ã¢ã¼ããã¯æå·åå©ç¨ã¢ã¼ãã®ä¸ã¤ãåºãå©ç¨ããã¦ããã»ã©å®å ¨æ§ã¯é«ããã®ã®ã並åå¦çã§ããªããããæå·åã«æéãè¦ããã
*9å訳ãæç´ãã転ããæ¥ç¶ãã·ã³ã®æ å ±ã®èå¥ã®ããã«çæãããåºæã®å¤ã®ãã¨ãæãã
[å¼ç¨ã»åºå
¸å
]
OceanLotus: macOS malware update by Romain Dumont 9 Apr 2019 - 11:30AM
https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/
ãã®è¨äºã®ç·¨éè ã¯ä»¥ä¸ã®è¨äºããªã¹ã¹ã¡ãã¦ãã¾ã
-
ãã¸ã¿ã«
PCã使ããªãä¸ä»£ã«ã©ããªã»ãã¥ãªãã£ã¼å¯¾çæè²ãããã¹ããï¼ -
ãã¸ã¿ã«
ãã£ã¼ãªã³ã¯ã®ã«ã¡ã©ã«èå¼±æ§ããããªçã¿è¦ã«ãã¡ã¼ã ã¦ã§ã¢æä½ã -
ãã¸ã¿ã«
ã¨ã¯ã¹ããã¤ãã使ã£ãæ»æãæ¯æ¥æ°10ä¸ä»¶ãèµ·ãã¦ãã -
ãã¸ã¿ã«
macOSãWindowsãçã£ãçããã¿ã¤ãã®ãã¤ãã³ã°ãã«ã¦ã§ã¢ãLoudMinerã -
ãã¸ã¿ã«
Windowsã®ã¼ããã¤èå¼±æ§ãä¿®æ£ããããããªãªã¼ã¹ -
ãã¸ã¿ã«
å·§å¦åããæ¨çåã¡ã¼ã«ã®è¦åãæ¹ã¨å¯¾å¿æ¹æ³ -
ãã¸ã¿ã«
ã¹ãã¤ã°ã«ã¼ããTurlaãã®PowerShell使ç¨æ¹æ³ãåæ -
ãã¸ã¿ã«
é«ãã»ãã¥ãªãã£ãèªãã¦ã©ã¬ããã¢ããªãKyashã -
ãã¸ã¿ã«
æ¥æ¬èªç°å¢ãçã£ãã°ãã¾ãåã¡ã¼ã«ã観測 6æã®ã»ãã¥ãªãã£ã¼æ å ±ã¾ã¨ã