US-CERTãåæé®®HIDDEN COBRAã®ãã«ã¦ã§ã¢âVolgmerâã«é¢ãã注æåèµ·(TA17-318B)ãçºè¡¨ã(å¾ç·¨)
â»ãã®è¨äºã¯ãæ¨æ¥(2017/11/15)æ¸ããTA17-318Aã®å 容ã®âå¾ç·¨âã¨ãã¦ãTA17-318Bã®å 容ãã¾ã¨ãã¦ããã¾ãã
TA17-318Bã®æ¦è¦
TA17-318Bã¯ãHIDDEN COBRAã使ç¨ãããã«ã¦ã§ã¢ã»ãVolgmerãã«é¢ããIOCãé¢é£IPã¢ãã¬ã¹ããã«ã¦ã§ã¢ã®èª¬æãã·ã°ããã£ã«é¢ããè¨è¿°ãããã¦ããã
ã¾ããTA17-318Bã«ã¯ãVolgmerã¸ã®å¯¾çæ¹æ³ããã¤ã³ã·ãã³ãã®ã¬ãã¼ãæ¹æ³ãè¨è¿°ãã¦ããã
ããä¸ãä¸ãVolgmerã®è¢«å®³ã«éã£ãå ´åãç´ã¡ã«DHSãFBI Cyber Watch(CyWatch)ã«å ±åãã¦ã»ããæ¨ãæ¸ããã¦ããã
TA17-318Aã®æ¦è¦æ¬ã«ã¯ãIOCã並ã³ã«ãã«ã¦ã§ã¢åæã¬ãã¼ã(MAR)ã«é¢ããææ¸ãè¨è¼ããã¦ããã®ã§ãèå³ã®ãã人ã¯åç §ããã¨ããã ããã
ç´ãªã³ã¯ãè²¼ãã®ã¯ã»ãã¥ãªãã£çã«åé¡ãããã®ã§ããã¦ã³ãã¼ããªã³ã¯ã®ããå ´æããå®éã®ãã¼ã¸ã®ã¹ã¯ãªã¼ã³ã·ã§ããç»åã¨ãã¦ç¤ºãã¦ããã
(TA17-318Bã®âOverviewâé ä¸ã«IOCã®ãªã³ã¯ãããã)
Volgmerã«ã¤ãã¦ã®èª¬æ
調æ»ã«ããã°ãHIDDEN COBRAã¯Volgmerã2013å¹´ãã使ç¨ãã¦ããã¨ãããã
Volgmerã®ã¿ã¼ã²ããã¯ã主ã«ä»¥ä¸ã®æ¥çã
- æ¿åºæ©é¢
- éèæ©é¢
- èªåè»
- ãã¹ã¡ãã£ã¢
Volgmerã¯ãbackdoor Trojan(ããã¯ãã¢ã¨ãã¦ã¿ã¼ã²ãã端æ«ã«æ½ä¼ããããã¤ã®æ¨é¦¬)ã§ãæ»æè ã¨ã¿ã¼ã²ãã端æ«éã§éä¿¡ãè¡ãçºã«æ½ä¼ããã
HIDDEN COBRAã¯ã主ã«æ¨çåã¡ã¼ã«æ»æã使ã£ã¦Volgmerãæ¡æ£ããããã ã
ãã ãHIDDEN COBRAã¯ãã¿ã¼ã²ãããã¨ã¯ã¹ããã¤ãããããã«å¿ è¦ãªæ§ã ãªãªãã¼ã«ã使ç¨ããäºã確èªããã¦ããã
ãã®çºãVolgmerãã¿ã¼ã²ãã端æ«ã«æ½ä¼ãããçºã«ãæ¨çåã¡ã¼ã«ä»¥å¤ã®æ»æææ³ã使ç¨ããå¯è½æ§ãããã
è¨ãæããã¨ãVolgmerã«ææãã端æ«ã«ã¯ãVolgmer以å¤ã®ãã«ã¦ã§ã¢ãæ½ä¼ãã¦ããã±ã¼ã¹ãããäºã«ãªãã
ã¢ã¡ãªã«æ¿åºã®èª¿æ»ã«ããã°ãVolgmerã«ã¯éçã»åçIPã¢ãã¬ã¹ã®2種é¡ãè¨å®ããã¦ããããã ã
éçIPã¢ãã¬ã¹ã«é¢ãã¦è¨ãã°ãæä½ã§ã94ã®éçIPã¢ãã¬ã¹ãæå®ããã¦ããã
åçIPã¢ãã¬ã¹ã¯ãæ§ã ãªå½ã®ãã¡ã¤ã³ãµã¼ãã¹ããåå¾ããã¦ããã主ã«ä»¥ä¸ã®å½ã ã«éä¸ãã¦ããã¨ããã
- ã¤ã³ãâ¦25.40%
- ã¤ã©ã³â¦12.30%
- ããã¹ã¿ã³â¦11.30%
- ãµã¦ã¸ã¢ã©ãã¢â¦6%
- å°æ¹¾â¦5.60%
- ã¿ã¤â¦4.60%
- ã¹ãªã©ã³ã«â¦4%
- ä¸å½(é¦æ¸¯å«ã)â¦2.70%
- ãããã â¦2.60%
- ã¤ã³ããã·ã¢â¦2.20%
- ãã·ã¢â¦2.20%
- ãã®ä»â¦21.10%
以ä¸ã®ãªã¹ãã ãã§ã¯ã¤ã¡ã¼ã¸ãæ´ã¿ã«ããã®ã§ã以ä¸ã«åã°ã©ããæ²è¼ãã¦ããã
Technical Details
Volgmerã®æã¤æ©è½ã«ã¤ãã¦
Volgmerã¯ãbackdoor Trojan(ããã¯ãã¢ã»ããã¤ã®æ¨é¦¬)ã¨ãã¦ä»¥ä¸ã®æ©è½ãæã¤ã
- ã·ã¹ãã æ å ±ã®åé
- ãµã¼ãã¹ã¬ã¸ã¹ããªãã¼ã®æ´æ°
- ãã¡ã¤ã«ã®ãã¦ã³ãã¼ã/ã¢ãããã¼ã
- ã³ãã³ãã®å®è¡
- ããã»ã¹ã®çµäº
- ãªã¹ã
- ããããããã®ã³ã³ããã¼ã«
ãã¤ãã¼ã
Volgmerã®ãã¤ãã¼ãã¯ã32bitã®*.exeãã¡ã¤ã«ãã*.dllãã¡ã¤ã«ã¨è¨ããã¦ããã
Volgmerã¯ãTCPãã¼ã8080çªã8088çªã使ã£ã¦ãã«ã¹ã¿ã ããããã¤ããªè»¢éãããã³ã«ã§C&Cãµã¼ãã¼ã¨ã®éä¿¡ãè¡ãã
å°ãéä¿¡ã¯SSLã§æå·åããã¦ããããã ã
åè: ãã¤ããªè»¢éãããã³ã«(Wikipedia)
æ¤ç¥ã¨ã¬ã¹ãã³ã¹
TA17-318Bã«è¨è¼ããã¦ããIOCã«ã¯ãHIDDEN COBRAãæ¤ç¥ããçºã«å¿ è¦ãªæ å ±ãè¨è¼ãã¦ããã
DHSã¨FBIã¯ããããã¯ã¼ã¯ç®¡çè ã¯ãIOCãåç §ããããã«è¨è¼ããã¦ããIPã¢ãã¬ã¹ãèªèº«ã®ç®¡çããIPã¢ãã¬ã¹ã«è©²å½ãããã©ãããã§ãã¯ãããã¨ããè¦ããã¦ããã
ãããã¯ã¼ã¯ã·ã°ããã£ã¨Host-Basedã«ã¼ã«
TA17-318Bã«ã¯ããããã¯ã¼ã¯ã·ã°ããã£ãè¨è¼ããã¦ããã
ãããã¯ã¼ã¯ã·ã°ããã£ã使ãã«ããã£ã¦ã誤æ¤ç¥ã¢ã©ã¼ã(False Positive)ãä¸ããå¯è½æ§ã¯æããããªãã®ã§ããããã¾ã§åèã¨ãã¦ä½¿ç¨ãã¦ããããããã¨è¿°ã¹ã¦ããã
ãããã¯ã¼ã¯ã·ã°ããã£
â»æ大é注æãæã£ã¦ã³ãããã¦æ²è¼ãã¦ãããã誤è¨å ¥ãã¦ããå¯è½æ§ãããã®ã§ã念ã®ããã·ã°ããã£ã¯å ãã¼ã¸ããåç §é ãããã
以ä¸ã¯åèã¨ãã¦ã³ãããããã®ãæ²è¼ãã¦ããã
alert tcp any any -> any any (msg:"Malformed_UA"; content:"User-Agent: Mozillar/"; depth:500; sid:99999999;)
YARA Rule
rule volgmer
{
meta:
   description = "Malformed User Agent"
strings:
   $s = "Mozillar/"
condition:
   (uint16(0) == 0x5A4D and uint16(uint32(0x3c)) == 0x4550) and $s
}
Volgmerã«ããææã®å½±é¿
Volgmerããããã¯ã¼ã¯ã«ä¾µå ¥ã§ããå ´åãæ©å¯æ å ±æ¼æ´©ãªã©ãæ·±å»ãªå½±é¿ãåã¼ãå¯è½æ§ãããã
- ä¸æçãåã¯æ°¸ç¶çãªéè¦/æ©å¯æ å ±ã®åªå¤±
- é常ãªãã¬ã¼ã·ã§ã³ã®å¦¨å®³
- æãªãããã·ã¹ãã ããã¡ã¤ã«å¾©å ã«é¢ããééçæ失
- 被害ã«ãã£ãçµç¹ã®ç¤¾ä¼çä¿¡ç¨ã®æ失
対çæ¹æ³Â
- ã¢ããªã±ã¼ã·ã§ã³ã®ãã¯ã¤ããªã¹ããè¨å®ããçµç¹ã§èªè¨¼ããã¦ããªãã¢ããªã±ã¼ã·ã§ã³ã«ãã£ã¦éä¿¡ãè¡ãããã®ãé²ã
- OSã¨ã½ããã¦ã§ã¢ãææ°ã®ç¶æ ã«ã¢ãããã¼ããã
- ã¢ã³ãã¦ã¤ã«ã¹ã½ããã¨å®ç¾©ãã¼ã¿ãã¼ã¹ãææ°ã®ç¶æ ã«ã¢ãããã¼ããã
- çµç¹å ã®ã¦ã¼ã¶ã¼ã®ã¢ã¯ã»ã¹ã³ã³ããã¼ã«ãè¡ããã¢ããªã±ã¼ã·ã§ã³ã®ã¤ã³ã¹ãã¼ã«å¶éãè¡ãã
- Eã¡ã¼ã«ã«æ·»ä»ããã¦ããææ¸ã®ãã¯ãã®å®è¡ãå¶éãã
- Eã¡ã¼ã«ã«æ¸ããã¦ããè¡ãå ä¸æã®ãªã³ã¯ãè¸ã¾ãªãÂ
Volgmerã«ããææ被害ã確èªããå ´å
ç´ã¡ã«DHSãFBIãªãã£ã¹ã«é£çµ¡ããäºã
- DHS NCCIC(NCCICCustomerService[at]hq.dhs.gov)åã¯+1-888-282-0870
- FBIâs Cyber Division(CyWatch[at]fbi.gov)åã¯+1-855-292-3937
åããã¦èªã¿ãã: US-CERTãåæé®®HIDDEN COBRAã®ãã«ã¦ã§ã¢âVolgmerâã«é¢ãã注æåèµ·(TA17-318A)ãçºè¡¨ã(åç·¨)