NotPetyaã©ã³ãµã ã¦ã§ã¢æ»æã®è©³ç´°åæ
2017å¹´6æ27æ¥é ããã¦ã¯ã©ã¤ããä¸å¿ã¨ãã¦ä¸ççã«çå¨ãæ¯ãã£ã¦ããNotPetyaã©ã³ãµã ã¦ã§ã¢ã«ã¤ãã¦ãUS Lastline社ã解説è¨äºãå
¬éãã¾ããã®ã§ãLastline社ã®è¨±è«¾ã®ãã¨ãå½ç¤¾ã«ã¦ç¿»è¨³çã®è¨äºãå
¬éãã¾ãã
åè¨äºä¸ã§ã¯ãLastlineããå©ç¨ããã ããã¨ã«ãããNotPetyaã©ã³ãµã ã¦ã§ã¢ã®è
å¨ãæ£ç¢ºã«è§£æããè¿
éãªå¯¾å¿ãåããã¨ãå¯è½ã§ãããã¨ã解説ããã¦ããã¾ãã
Lastlineãã使ãããã ãã¦ããã客ãã¾ã®ç°å¢ã«ãããã¾ãã¦ã¯ãLastlineãå©ç¨ãã¦ãNotPetyaã©ã³ãµã ã¦ã§ã¢ã®æ©ææ¤ç¥ãå¯è½ã¨ãªãã¾ãã
å½ç¤¾ã¯ä»å¾ããã»ãã¥ãªãã£ã«é¢ããæ´»åãéãã¦ãããå®å
¨ãªç¤¾ä¼ã®å®ç¾ã«è²¢ç®ãã¦ã¾ããã¾ãã
æ¬è¨äºã¯ãUS Lastline社ã2017/6/27ã«å ¬éããããã°è¨äºãA Deep Dive into the NotPetya Ransomware Attackãï¼https://www.lastline.com/blog/notpetya-ransomware-attack/ï¼ãå½ç¤¾ã翻訳ããLastline社ã®è¨±è«¾ãå¾ã¦å ¬éãããã®ã§ãã
æ稿è Patrick Bedwell, 2017å¹´6æ27æ¥
ã¦ã¯ã©ã¤ãã§å§ã¾ã£ãNotPetyaã©ã³ãµã ã¦ã§ã¢æ»æã«ã¤ãã¦ãããããç¥ã£ã¦ãããã¨
NotPetyaã®æ¦è¦
ããã¯ãWindowsã·ã¹ãã ãæ¨çã¨ããPetyaã©ã³ãµã ã¦ã§ã¢ãã¡ããªã®æ°ããå¤ç¨®ã§ãããã®ã¢ã¦ããã¬ã¼ã¯ã¯ç«ææ¥ã®æã«å§ã¾ãã¾ãããããã¯ãPetrWrapãGoldenEyeãPetya.AãPetya.Cãããã³PetyaCryãªã©ã®è¤æ°ã®ååã§åç §ããã¦ãã¾ãã
ä»åã®ã¢ã¦ããã¬ã¼ã¯ã¯ãå æçºçããWannaCryã®ä¸ççãªã¢ã¦ããã¬ã¼ã¯ã¨ããã¤ãã®é¡ä¼¼æ§ãããã¾ããã以ä¸ã®ç¹ã§é¡èãªéããããã¾ãã
- WannaCryã«åãè¾¼ã¾ãã¦ãããããªããã«ã¹ã¤ãããã¯ããã¾ãããããï¼ãã«ã¹ã¤ããï¼ã«ãããWannaCryã«ããæ»æã¯æ¯è¼çæ©æã«åæãã¾ããã
- ããã¯ãMS17-010ã§ä¿®æ£ãããSMBã®èå¼±æ§ã«ä¾åããã«åºããå¯è½æ§ãããã¾ãã
- ããã¯ã被害è ã®ã³ã³ãã¥ã¼ã¿ãåèµ·åãããã¼ããã©ã¤ãã®Master File Tableï¼MFTï¼ãæå·åããMaster Boot Recordï¼MBRï¼ãåä½ä¸è½ãªç¶æ ã«æ¸ãæãã¾ãã
è å¨ã®ç¯å²
ãã®æ»æã¯åºãè¡ããã¦ãããç¹å®ã®ç£æ¥ãå°åããããã¯å½ãã¿ã¼ã²ããã«ãã¦ããããã«ã¯è¦ãã¾ããããé»åä¼ç¤¾ã空港ãå ¬å ±äº¤éæ©é¢ãä¸å¤®éè¡ããå«ãã¦ã¯ã©ã¤ãã®çµç¹ãä¼æ¥ãæ»æãããã¨ã®å¤æ°ã®ã¬ãã¼ããåå¨ãã¦ãããåæ§ã«æ±æ¬§ãã¢ã¸ã¢ãã¨ã¼ããããç±³å½ã§ãå¹ åºã被害ã®çºçãå ±åããã¦ãã¾ããã¾ãããã®æ»æã¯ãã§ã«ããã¤ãªã®æ¾å°ç·ã¢ãã¿ãªã³ã°ã·ã¹ãã ã«ãå½±é¿ãä¸ãã¾ããã
Lastline Enterpriseã«ããè å¨ã®Deep Content Inspectionã¨åé¡
以ä¸ã¯ãæã ãåãåã£ããã«ã¦ã§ã¢ãµã³ãã«ã®1ã¤ããçæãããåæã¬ãã¼ãã®ã¹ã¯ãªã¼ã³ã·ã§ããã§ãã
Lastlineã®Deep Content Inspection™ã¯ããã«ã¦ã§ã¢ã®ãã¹ã¦ã®æªæã®ããåä½ãç¹å®ãã¾ãããã®å¯è¦æ§ã«ãããæ¤ç¥ãããæ´»åã®ãªã¹ãã®ä¸ããããªã¢ã¼ãå®è¡ã«ãã£ã¦ãã«ã¦ã§ã¢ãä¼æããæ©è½ã¨ãMBRï¼ãã¹ã¿ã¼ãã¼ãã¬ã³ã¼ãï¼ãä¸æ¸ãããæ©è½ãæã ãç¹å®ãã¦ãããã¨ããç解ããã ããã¨æãã¾ãã
Lastlineã«ããNotPetyaã®æªæã®ããè¡çºã®åæ
ã©ããã£ã¦åºããã®ã
ãã®ã©ã³ãµã ã¦ã§ã¢ãæ¡æ£ãã¦ããã¨è¦ãªãããã¤ãã®æ¹æ³ãããã¾ãï¼
- ããã¯ãEternalBlueã¨ã¯ã¹ããã¤ãã使ç¨ãã¦å±æçã«æ¡æ£ããå¯è½æ§ãããã¾ãããã®ã¨ã¯ã¹ããã¤ãã¯ãMS17-010ã§ä¿®æ£ãããèå¼±æ§ãçªããããããã¯psExecã¨ããããªã¢ã¼ãã·ã¹ãã ä¸ã§ããã»ã¹ãå®è¡ããããã®ã¦ã¼ãã£ãªãã£ãç¨ãã¾ãã
- Talosï¼ã·ã¹ã³ï¼ã®ã¬ãã¼ãã«ããã°ãæ½å¨çãªæ¡æ£æºã¯MeDocã¨ããååã®ã¦ã¯ã©ã¤ãã®ç¨åä¼è¨ããã±ã¼ã¸ã®ã½ããã¦ã§ã¢æ´æ°ã·ã¹ãã ã¨ãªãã¾ããï¼ããã¯ãã¦ã¯ã©ã¤ãã®é常ã«å¤ãã®çµç¹ãç ç²è ã¨ãªã£ãçç±ã®èª¬æã«ãªãã¨èãããã¾ãï¼
- Kasperskyã®ã¬ãã¼ãã«ããã°ããã(ã©ã³ãµã ã¦ã§ã¢)ã¯ãEternalRomanceã¨å¼ã°ãããWindows XPããWindows 2008ã¾ã§ã®ã·ã¹ãã ãæ¨çã¨ãããªã¢ã¼ãã³ã¼ãå®è¡ãè¡ãã¨ã¯ã¹ããã¤ããä»ãã¦åºããå¯è½æ§ãããã¨å ±åãã¦ãã¾ããã¾ãããã®ã©ã³ãµã ã¦ã§ã¢ã¯Mimikatzã使ç¨ãã¦lsass.exeããã»ã¹ãã管çè ã®è³æ ¼æ å ±ãæ½åºãããã®æ å ±ãPsExecãã¼ã«ãããã¯WMICã«å¼ã渡ãããããã¯ã¼ã¯å ã§é å¸ãè¡ããã¨ã«ãããEternalBlueãEternalRomanceã¨ã¯ã¹ããã¤ãã«å¯¾ãã¦èå¼±ã§ã¯ãªãã·ã¹ãã ã«å¯¾ãã¦ããã«ã¦ã§ã¢ãæ¡æ£ãã¾ãã
ãã£ããã¢ã¯ãã£ãã«ãªã£ãå ´åã®ç¹å®ã®åä½
ãã£ããã¤ã³ã¹ãã¼ã«ãããã¨ãNotPetyaã¯ããã¤ãã®ãã¨ãè¡ãã¾ãï¼
- Mischaã¨ããã以ååå¨ããPetyaã©ã³ãµã ã¦ã§ã¢ã®äºç¨®ã®ä¸ã¤ãæããã³ã³ãã¼ãã³ããå®è¡ããåã ã®ãã¡ã¤ã«ãæå·åãã¾ã
- ã·ã¹ãã ãåèµ·åããMFTï¼ãã¹ã¿ã¼ãã¡ã¤ã«ãã¼ãã«ï¼ãæå·åãããã¹ã¿ã¼ãã¼ãã¬ã³ã¼ãï¼MBRï¼ãåä½ä¸è½ã«ãã¾ãã ã¾ããMBRãã©ã³ãµã ãã¼ãï¼èº«ä»£éè¦æ±æï¼ã表示ãããã¡ã¤ã«ã§ä¸æ¸ãããã·ã¹ãã ãèµ·åã§ããªããã¾ãã
ææããã·ã¹ãã ã®ã¦ã¯ã©ã¤ãå¯é¦ç¸ãPavlo Rozenkoã®ã¹ã¯ãªã¼ã³ã·ã§ãã
https://twitter.com/RozenkoPavlo/status/879677026256510976/photo/1
追跡ããé²å¾¡ããããã«ããªãã¼ãæã«ã¤ãã³ããã°ãæ¶å»ãã"ããªã¥ã¼ã å ã®ãã¡ã¤ã«ã¾ãã¯ãã£ã¬ã¯ããª"ã¸ã®å¤æ´ãç£è¦ããããã®ã¦ã¼ãã£ãªãã£ã§ããUSNå¤æ´ã¸ã£ã¼ãã«ãåé¤ãã¾ãã
USNã¸ã£ã¼ãã«ãå¤æ´ããransomwareã®Lastlineåæ
- Bitcoinã§$300ãè¦æ±ãã¾ãã
使ç¨ããããã®ä»ã®ãã¯ããã¯
ãã¹ããã¨
- MS17-010ãé©ç¨ããï¼WannaCryã®å¾ã«ããããå½ã¦ãããã«è¨ã£ã¦ãããã¨ãè¦ãã¦ãã¾ããï¼ãã¡ãããæã ãããããªããã£ã¦è¨ã£ã¦ãã§ãããã¨ã¾ã§è¨ãã¤ããã¯ããã¾ããã...ï¼
- PsExecã¨WIMCãAppLockerã¦ã¼ãã£ãªãã£ã使ç¨ãã¦å®è¡ãããªãããã«ãã
- ããªãã®ã·ã¹ãã ãææããã®ãé²ãæ¹æ³ã«ã¤ãã¦ã¯ããã®ããã°è¨äºãåç §ãã¦ãã ãã
IOCãç¨ãããããã¯
- æååï¼1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX
- ã¡ã¼ã«ã¢ãã¬ã¹ï¼[email protected]ï¼ã¡ã¼ã«ãããã¤ãããã®ã¢ã«ã¦ã³ãããããã¯ãã¦ãã¾ãï¼
ãã詳細ãªæ å ±ãå¾ãããã«
Lastline Labsã¯ãã©ã³ãµã ã¦ã§ã¢ã«é¢ãã2ã¤ã®ããã°ãå ¬éãã¦ããã第2é¨ã®è§£èª¬ã§ãªãªã¸ãã«ã®Petyaã©ã³ãµã ã¦ã§ã¢ãã¡ããªã¼ã«ã¤ãã¦åãä¸ãã¦ãã¾ãã
èè ã«ã¤ãã¦
Patrick Bedwellã¯ãããã20å¹´ã«ãããããããã¯ã¼ã¯ã»ãã¥ãªãã£è£½åã®ãããã¯ããã¼ã±ãã£ã³ã°æ¦ç¥ãçå®ããå®è¡ãã¦ãã¾ããå½¼ã¯ã«ãªãã©ã«ãã¢å¤§å¦ãã¼ã¯ã¬ã¼æ ¡ã§å¦å£«å·ããµã³ã¿ã¯ã©ã©å¤§å¦ã§MBAãåå¾ãã¾ããã
Tweet