ե奢֥ : סȯ

ե奢֥

סȯ

Dridexβ

ѹNCANational Crime AgencyȺкģˤFBIӥꥫ罰ˡʤȤȤˡBugatCridexDridexκԤʤAndrey Ghinkul2015ǯ828˥ץᤵ줿ߡƹϿΰϤƤ롣󤸤ƤȤǤϡDridexƹǶͻؤͻȼԤ˿ɴɥ»򾷤

DridexϡΥե˸դޥɤޤ줿Microsoft WordɥȤ̤Ť뤳ȤʬäƤ롣ޥϤ졢C&CФ俯줿WebȤ¹ԥեɤ뤳Ȥˤʤ롣ե奢ǤϡOfficeɥȤòƥեΰդޥõŪʸΤԤäƤTrojan:W97M/MaliciousMacro.GENˡ

ɤDridexܥåȥͥåȤˤĤ졢ҤΥХåɤ׾˰դΤޥȯΤ졢줿

ҤθܵҤϡHydraʥ󥨥󥸥ˤDeepGuardʥӥإӥ١ˤξѤˤƼƤ롣

Virus and spyware history Trojan:W97M/MaliciousMacro.GEN
Trojan:W97M/MaliciousMacro.GENθ

F-Secure Internet Security, Harmful file removed
Τե뤬줿

Ūʥ˥ˤäưդޥθΤԤäƤۤӥإӥ󥸥ǤDeepGuardǤ֥å롣1ؤ2ؤݸΤۤͥƤ롣

F-Secure Internet Security, Application blocked
ʥӥإӥΤ˥֥å줿ץꥱ

WordɥȤ¹ԥեɥåפäơɤȤʤ1Ĥʤ

QDridexưϡ٤ɤܥåȥͥåȤΤȤȴطΤ
AҤǤʬʤ

Ǥ륤󥿡ͥåȡƻ륽եȥȤ饹ѥ㤦ͤïΤ

̩˽ϪΤϡϥåϥå󥰤줿ȤꥢȤƻ뵻ѤδHacking TeamҤ75ϥå󥰤줿ϥåɡ᡼ޤ400GBtorrentե̤˸ˤϸܵҤΥꥹȤ60᤯ޤޤƤ롣

ƱҤϰȤȤμˤꤷƤ뤬ΥꥹȤˤϥ󡢥ե󡢥ӥȤäȤܤäƤ롣ޤϳϡϰΥ󥬥ݡ롢ޥ졼ɤRCSRemote Control Systemˤ̾κüΥѥƤȤ줿

Citizen LabʥȥθˤθԤˤȡΥѥ³ƿ롣ХüΥޥ䥫ưSkype䥤󥹥ȥå˵󤫤C&CФؤפΤ򤹤뤿ˡץФˤƿ̾ͥåȥѤΤ

PastebinƤ줿ܵҥꥹȤ˴ŤȡΥեȥϥޥ졼Ǥϥޥ졼ɻ߰ѰMIMalaysia Intelligenceˡ괱šǹ줿

hacking_team_client_list (86k image)

medium.comƤ줿ϳɲòǤϡΥѥMiliserv Technologies (M) Sdb BhdȤ̾ΡϤΥޥ졼ȡʥޥ졼̳ʤϿˤ̤䤵줿ȤƤ롣ƱҤϥǥե󥸥åƥꥸȤʼ¥ӥ󶡤òƤ롣

hacking_team_hack_1 (95k image)

hacking_team_hack_2 (72k image)

괱šƻ륽եȥɬפȤͳϡΤޤޤ褯ʹƤۤץͤΥѥϰ¤Ϥʤ饤󥹤Υåץ졼ɤˤ40ޥ졼󥮥åȡ1,300ߡˤ뤷ݼιˤ16ޥ졼󥮥åȡ500ߡˤפ롣

ޥ졼ήɤΥǥˤ뤳λƻˤС2013ǯظơʸп˵ǥޥ륦FinFisher줿ޥ졼ܵؤϤ餯ȯѥȤäƤȤȤ

ˤ⡢ޥ졼ǯISS World AsiaȤܻԤγϤˤˤʤäƤ롣ǤϡˡԵؤ䡢̿ҡܤôԤФơȤֹˡŪʡ״ƻ륽եȥȤץ⡼󤷤Ƥ롣2014ǯƱ٥ȤHacking TeamҤϻäƤꡢƱǺΥݥ󥵡ȤʤäƤ

MiliServ TechnologiesϸߤΤȤסǼ˳Ť2015 ISS World Asia˴ͿƤ롣Ʊ٥Ȥ˻äˤϾԤɬפHacking TeamҤǯ⻲äƤ뤫ǧ⤷ʤ


Post by – Su Gim

ȥ饤ʤγ˴ͿƤΤʤBlackEnergyˤդ

αϡ֥åͥ륮פƤ롣ƥСڡƱͤ桹VirusTotalͳȯBlackEnergyեߥ꡼ˤĤ񤤤ΤϡۤɰΤȤǤϤʤƤȤǤϡΥեߥ꡼ϡ2008ǯΥ른ؤΥСѤ줿ΤƱǤ롣轵ζΥХꥢȤVirusTotalƤ줿ƺϡɤΤ褦ۤ줿ˤĤơΤˤʤäϡ¹ԥեޤzipեäǤˤäƱ͡ΥץϤޤ饤ʤƤ줿

Zip file screenshot

zipե̾ϥʸǤĤŤƤꡢ֥ѥɥꥹȡפȤ̣¹ԥեΤۤϡ̣ƱƥʸǤĤŤƤ롣¹ԥեγĥҤ.docǤ뤳ȤƤԤΥץɤΤ褦˵ưΤϡΤˤʤäƤʤ桹ο¬ǤϡäƤ륿åȤȤäƤ뤢zipץꥱ󤬤ꡢ줬ĥҤ˴ؤ餺Υեμ˴Ťƥץ򳫤ǽ򥵥ݡȤƤ롢ȤߤƤ롣󹶷Ԥñ˴ְ㤤Ȥǽ⤢롣

VirusTotalμ¹ԥեΥץǧȡ鷺ʬ᤯٥륮Ƥ줿饤ʤθߤξ䡢٥륮EUܤ濴Ǥ뤳ȡʤNATO֤Ƥ뤳ȡˤդߤȡ餬ϢƤȤ̵뤹뤳ȤϤǤʤ

桹ϤΥץϡΥѥɤ򤱤褦˷ٹ𤹤ITϤδäԥեå󥰥᡼źեեȤդ줿ǽȹͤƤ롣

ХꥢȰۤʤꡢץϤϤsvchost.exeˡ桼⡼ɤDLL륫ͥ⡼ɥݡͥȤѤƤϤʤϡñ˥桼⡼ɤΥɥåѡѤơrundll32.exeͳDLLɤ߹ࡣͥ⡼ɥݡͥȤӽϡǶWindowsƥǸ롢̾դɥ饤Ф»ܤݸȴ褦Ȥ뤿ᤫ⤷ʤ

桼⡼DLLѹ򥵥ݡȤ뤿˽񤭴Ƥ⤤ʥॹפ2014ǯ626ˡǤեޥåȤϰۤʤ뤬ޤƱIPɥ쥹֥å˽°C&CФѤƤ롣

New BlackEnergy configuration

ޤɥåѡϰդΤ԰٤򱣤ڤ뤿ˡɥȤޤdz

Decoy document

եȥȼ䥨ץȤȤϰڴطʤȤդɬפɥȤϥɥåѡˤäơץư롣ϤĤܤˤĤޤOS Xˤ뤪餯ǽΥɥȤѤAPTλ˻Ƥ롣ʤ餳Υޥ륦DEPۥȥץrundll32.exeˤŬѤʤäϾ迯뤿ˡ¦̤ڤ곫Τ⤷ʤ

Routine that disables DEP via registry

ȥ饤ʤγ˴ͿƤΤʤBlackEnergyˤդ

BlackEnergy롼ȥåȤߤʤ

ǶBlackEnergyեߥ꡼Υץ뤬饤ʤVirusTotalإåץɤ줿Ҥ٤ƤȤǤϡΥեߥ꡼2008ǯΥ른Ф륵СѤ줿ΤƱΥޥ륦ԤϡΥޥ륦ˤ괶ۥȤؤΥ¤򤹤٤Ƽ롣եߥ꡼˴ؤ뤵˾ܺ٤ʾˤĤƤϡSecureWorksˤ2010ǯܺ٤ʬǧƤۤ

οʥץϡ⤦ե쥸ȥ򱣤ڤʤˤơϤ롼ȥåȤȤǤϤʤޤƤXMLˤСߤΥӥɤϡ0D0B15aaaפǤ롣

Embedded XML

Ѥ櫓ǤϤʤΥץϤޤץ򱣤ڤ롼äƤ롣DKOMѤƤ롣Τʤsvchost.exeٹǽʾ֤ǧ뤿ˡޥ륦ϡWindowsΤޤޤʥСǻѤ륫ͥ빽¤˥ϡɥǥ󥰤줿եåȰġ̣ΤϡΥץWindows 8ǰƬ߷פ줿

Offsets in Windows 8 kernel structures

ץˤϽ̾ƤʤΤǡưˤϡǶWindowsˤ롢ɥ饤Фؤν̾μ»ܤ̵ˤɬפ롣

2014ǯ1ȾХ붼ҥݡ

Ҥ2014ǯ1ȾΥХ붼ҥݡ줿äƤƤˤĤơʲˤĤ夲롣

ȯ줿ҤΰŪ¿AndroidФΤǡʤ˶äϤʤˡ֤ܤˤޥ륦եߥ꡼277Τ275롣iOSSymbianοޥ륦Ϥ줾1Ĥ˲᤮ʤ

ҤMobile SecurityʤΥ桼ΤۤȤɤ1Ⱦ˥ȥϤ˸줿Ȥ𤵤줿ϡʼFakeinstSMSSendξեߥ꡼ˤΤǡSMS뤫֤롣Android OS4.2ؤιʥץߥ졼ȤSMSå˥桼γǧˤȥϤˤɤΤ褦ʱƶ⤿餹̣äƤ롣

ȾϥХޥ륦ȯǡΡֽơפ𤵤줿ޤC&CФȤ̿򱣤ڤŪTorȤ줿ƤΥХޥ륦Trojan:Android/Torsm.A롣Υ֡ȥåTrojan:Android/Oldboot.A䡢õŹ̲ߤ뤫ʥޥʡˤ褦ȤȥϡTrojan:Android/CoinMiner.Aˤ𤵤줿

DendroidȤġ륭åȤ󤲤롣ϡĤΥܥ򥯥åAndroidѤΥȥϤǤ뤳ȤäƤꡢޤɤʵݾǤ褦ĤPC١ζҤȤơ륹ۥåȤ䥨ץȥåȤǤä褦ˡDendroidϵѥΤʤͤȤǥޥ륦Τ򤰤äȿȶˤ롣

ƤϤ٤2014ǯκǽ3ΤȤʤΤ


ܺ٤ˤĤƤϥХ붼ҥݡȤˤ롣ܤΥʲβ򥯥åǤ롣2ĤΥСѰդƤ롣

   •  WebѡPDF

2014Q1_MTR_web_small

   •  ѡPDF

q12014_mtr_banner_print_small

TDLɥåѡοʥХꥢȤCVE-2013-3660򿯳

Ƕᡢ桹TDLХꥢȤο郎ϤäƤΤܤˤƤ롣ΥХꥢȤϡBitdefenderҤθ꤬𤷤ɾι⤤TDL4ޥ륦Ρˤʤꤽ

桹ܤˤTDLɥåѡοХꥢȡSHA1: abf99c02caa7bba786aecb18b314eac04373dc97ˤϡҤHIPSѡʰʲβ򥯥åȳ礵DeepGuardˤäơܵҤΥޥª줿̾顢ХꥢȤϥץȥåȤ̤ۤƤ뤳Ȥʬ롣

TDL4_clone_exploited_in_the_wild (295k image)

ǯESETҤѤѤTDL4ХꥢȡʰΥ륹٥PiharȸƤǤˤˤĤڤѤȤϡHIPS򱪲󤹤뤿ΤΤȡץθ¤夲ƴԤȤƤΥ¤뤿ΤΤ桹ǶḫХꥢȤΥɥåѡ⡢ESETҤΥ֥εǽҤ٤ƤΤƱѤȤäƤ뤬ĤΥޥʡʹʤƤ롣

TDL4Microsoft WindowsΥ 塼 ӥȼMS10-092򿯳ơޥ륦Υץθ¤夲ơ롼ȥåȥɥ饤Фɤ߹ࡣХꥢȤϡƥԤTavis Ormandyˤäȯ줿EPATHOBJȼCVE-2013-3660򤫤˿롣

TDL4_clone_ExploitingCVE_2013_3660 (30k image)

ʥХꥢȤȡ餢TDL4Ȥɮ٤㤤1ĤϡեϡɥåѡΥ꥽ˡRC4ǥ󥳡ɤ줿ǡȤޤƤ롣

TDL4_clone_config_ini (6k image)

줬CVE-2013-3660򿯳ǽΥޥ륦եߥ꡼ȤȤϤۤܤʤޥ륦κԤɤ᤯ץȥɤ̤ѲǽȤ뤫򡢤ϤäȼƤ롣ξ硢ץȥɤ3˸줿

Post by — Wayne

롼ȥåȥե

󥿡ͥåȥեWebƤ֡ǥȥåפ֥饦ɽ뤳Ȥ빭ˤĤơȤϤʤҤΥʥꥹȤ1Wayneϡ˻פä

WayneϺǶᤢ륵ץSHA1: c8c643df81df5f60d5cd8cf46cb3902c5f630e96ˤʬϤ̣ΥץϤΥɤˤʤLanEx̿̾줿롼ȥåȤǡҤǤRootkit:W32/Sfuzuan.AȤƸΤ롣

LanEx (55k image)

WayneϥץĴơ58wangweiȾΤιȤé夤βҤϥեηбļԸˡPC򸫤ưή줫顢פ粽뤳Ȥܻؤեꥨȥץ»ܤƤ롣Υ塼ϡեΥ桼ˡ󼨤뤳Ȥ

ι𥵥ȤΡޡƥ󥰾ʸǤϡ֥󥿡ͥåȥեPC1ϡPCΥɥ֤ơʿѤ120ưƤפȤƤ롣μĥ岡פˤĤƤΤʤ˸ĿŪʸ΢դˤʤäƤ褦˻פ롣

Ȥ⤫եηбļԤ̣Ĥȡեȥѥåʥ롼ȥåȤΥ󥹥ȡߤǡ˥ɤǤWebڡؤƳ롣Υڡˤϥȥѥͥ뤬ꡢ롼ȥåȤ͡ʵǽǤ롣ȤWeb֥饦ꤹǥեȥڡʤɤѰդƤƼϡۤ㳰ʤ٤ڤŪʤä󥸥ơȤФ븡󥸥ˬ줿ˡ桼1000ͤȤ26ʤɡ褴Ȥ˶ۤƤ롣

бļԤѥå򥳥ԥ塼˥ޥ˥奢ǥ󥹥ȡ뤹ȡ³ƥ롼ȥåȤɤˡԻ׵ġ⤬ɤɤäƤǤ硩䡢ǤʤбļԤˤȤäơʤˤ⤫Ȥ櫓ǤϤʤʤȤݡȥե1ΤߡˤǤϡѥå˴ؤƤξܺ٤ҤͤꡢޥBSoDBlue Screen of DeathˤȤˤĤƤʿ򤤤бļԤ롣

LanEX_BSOD (427k image)

ʥbbs.icafe8.com

бļԤȾϡ롼ȥåȤޥDz򤷤ƤΤ˵ŤƤʤΥץϼ˹ɽ뤳ȤŪȤƤ롣

   •  SSDTեå̤ơ⥸塼°ץ򱣤ڤ
   •  SSDTեåˤꡢ⥸塼Υץλ뤳Ȥ򤹤
   •  NDISեåѤơURLIPɥ쥹ӥݡֹ˴ŤWebڡؤΥ˸

бļԤ롼ȥåȤΥ󥹥ȡɤWebڡˤ륳ȥѥͥˤϡ⥸塼ϢΥץ˲äơڤץ򤹤뤿Υץ⤢롣ϡǥեȤǤϱƤ롣

ŪˤΥ롼ȥåȤǤäȤⶽ̣ʬϡͥåȥۤդ뤹٤ƤHTTPꥯȤȥ쥹ݥ󥹤Υåե륿뤿NDISեåѤ⤷ػߤƤHTTPꥯȤä顢롼ȥåȤˤäƥѥåȤ󤵤졢˺줿HTMLڡ֤롣

HTMLڡɽiframeޤHTTP 302쥯Ȥǡ桼Υ֥饦WebȤ˥쥯Ȥ롣

lanex_redirection (107k image)

桼ˤȤäƤϡΥޥˤΥ롼ȥåȤȤȤϡϪФ򤱤ʤȤȤˤʤ롣뤤ϡ׵ᤷƤʤWebȤ˥쥯Ȥ뤳Ȥ⤢롣

Υ롼ȥåȤϼ˹ɽ뤳ȤظΤɥǤϤʤƥǤϤ뤫˰դ¹Ԥ롢ǽϤΤơ󥿡ͥåȥեηбļԤ顢ҤΥޥ˲򥤥󥹥ȡ뤷ΤˤäİƤ櫓ǤϤʤ褦˸롣

ϥåιоݼԥꥹȾAppleγȯԤ

աΥݥȤϡDigital New Asia˴ƤεȴǤ롣

2AppleҤΡMaciPhoneiPadץȯԸWebե饤ˤʤäθ֤ʤơȤؤäݡAppleҤȯɽä

ľˡ쥤ϥåȤǥƥԤǤ⤢롢ɥ߽Υȥ륳Ibrahim BalicȤYouTubeͥƤưΤʤǡˤĤƤȹФưˤơBalicWebȤؤιΩХݡȤդȼĥƤ롣

BalicμĥФAppleҤϲɲäΥȤϤʤAppleҤϤν򿼹˼ߤƤ褦˸롣ޤߤΤȤ³WebӥȤʤƤ롣

ʤΤϡʤȯԡäiOSȯԤĤƤʤۤɸŪˤʤäƤΤ γȯԥȤؤϡȤǤϳդʤԤ줿ΤΡȯԥȤݸ뤳Ȥν䡢Ȥ찭Ѥ줿ŪʽˤĤơؤդ򴭵

ΩiOSХ볫ȯԤο͵եǤiPhoneDevSDKФƺǯԤ졢AppleFacebookTwitterʤɵ絻ѴȤޤޤȵԤФϡιƧޤƤ롣

Notice from IPhoneDevSDK Admin

϶ʽ̤ο߾췿ĤޤꡢΥ桼򹶷⤷ϥåϡޤ桼ˬ줽ʥȤ򿯳ɸŪ򤵤ľܹ⤹ݤ˻Ȥ䥢롣ΥǤϡɸŪϤΥȤˬƤȯԤ

˳ȯԥȤ򿯳Τ˻ȤʡץꥱȯԤθĿ;إǤƤޤȡȤ櫓iOSץåȥեǤϡγȯԤʤɾȽꤹ桼ˤ礭ʳȤʤ롣

ޥ륦κԤˤȤäƤϡGoogle Play䡢¾AndroidץåȥեѤΥץꥱ䥵ȤȰۤʤꡢAppleҤApp Store˿ƳΤ륢ץꥱ򥢥åץɤ뤳ȤϡĹֲǤäȤ櫓AppleҤθӥ塼ݥꥷΤǡǽiPhoneо줷ư6ǯϤäơ̤ΰդ륢ץꥱγư˻ߤΤƤΤ

ɤ򱪲󤹤뤿ˡǤϥޥ륦κԤϳȯԼΤäƤ롣ޥ륦ԤŪϡApp StoreγȯԤΥȤإ뤳Ȥ顢ȯԤɾʤϥåơޥ륦ԼȤΥץ򲡤դ뤳ȤܼŪ˲ǽˤʤΤ

ʸAre Apple developers on the hacker hit list?Su Gim Goh

WindowsǤJanicabޥ륦

轵Mac桼ɸŪˤץȥ١Υޥ륦ˤĤ񤤤ˤʤäơavast!οͤWindows餫ˤ

tweet from Jindrich Kubec

WindowsǤOS XǤΰ㤤ʲ󤹤롣

Summary table

ҤWindows桼ϡ饦ɵˤäơǤݸƤ롣

RLOΥȥåȤäMacν̾Ѥߥޥ륦

RLORight-to-left overrideȤϡΥƥȥ󥳡ɥƥǻȤüʸǡƥȤ򱦤麸ؤɽڤؤؼΤ¹ԲǽեγĥҤäŪǡǯBredolab٤ʥȥMahdiȤäWindowsޥ륦ǰŪ˻ȤƤ롣ȥåξܺ٤ˤĤƤϡKrebs on SecurityΤǧƤۤ

桹ϤMacѤΥޥ륦RLOΥȥåѤƤ뤳Ȥ˵դ轵ζVirusTotalƤ

RLO character

ǤŪϡKrebƤǿƤΤۤʣǤϤʤñγĥҤäΥޥ륦ǤϡRecent News.pdf.appפȤե̾ȤϤäOS XϤǤˤθƤꡢͽ֤ȤƼºݤγĥҤɽƤ롣

RLO trick in Finder
RLO trick in Terminal

Υޥ륦PythonǵҤ졢ۤpy2appѤƤ롣HackbackȤޤäƱͤˡAppleҤDeveloper IDǽ̾Ƥ롣

Apple Developer ID

OS X̾Υե븡ֻ˼ΤRLOʸΤKrebξƱͤ˵դޤˤʤäƤ롣.

OS X file quarantine notification

Υޥ륦¹ԤȥǥΥɥȤ֤ơ

Decoy document

³ƥޥ륦ϵưΤcron֤˴桼Υۡǥ쥯ȥˡݡͥȷǼ뤿αե롣

Launch point and drop files

ޥ륦C&CФΥɥ쥹뤿ᡢʲWebڡ³롣

  •  http://www.youtube.com/watch?v=DZZ3tTTBiTs
  •  http://www.youtube.com/watch?v=ky4M9kxUM7Y
  •  http://hjdullink.nl/images/re.php

just something i made up for fun, check out my website at (address) bye byeʳڤߤΤˤΤäΡʥɥ쥹ˤWebȤǧƤ͡ХХˡפȤʸϤƥɥ쥹롣

YouTubeΥڡϰʲΤ褦ˤʤäƤ롣

YouTube page

ʸGoogleǸȡǵ󤲤ΰʳˤⰭѤƤ륵Ȥ뤳Ȥʬ롣

Google search

θޥ륦Ϸ³Ū˥꡼󥷥åȤ򻣤ꡢϿSoXȤɥѡƥΥեȥѤƤˡC&CФ˥åץɤ롣ޤC&CФФơ¹ԥޥɤη³Ūʥݡ󥰤ԤäƤ롣

Υޥ륦ϡҤǤBackdoor:Python/Janicab.AȤƸФ롣

ɵ

C&CФξ򼨤˻ȤƤYouTubeư1Ĥ׾ʲ˼

Python_Janicab_YouTube_stats

Python_Janicab_YouTube_stats_daily

ưդJanicab.AΥХʥդ⾯ʤȤ1ˤΤܤ롣׾˴ŤȡºݤˤϤäХꥢȤ¸ߤ褦

ޥ졼ˤͥåȾǤư

ޥ졼κǯϡ2013ǯ55ͽꤵƤ롣ɼ˸Ʊޤ֤κǸ˥ȥåפƤΤǡߡSNSȤޤƻؤ˥塼󤻤ƤƤ롣

ƻؤδؿι⤵ޥ륦ԤФΩѤߤΥ륨󥸥˥󥰵ѤѤƿʵԤ߽Ф󶡤뤳Ȥˤʤ롣ƺCitizen Labȯɽ줿Ƥꡢƻޥ륦FinFisher̾FinSpyˤץ뤬òƺ줿WordɥȤˤƸФ줿ȤƤ롣

Υޥ륦ϡSENARAI CADANGAN CALON PRU KE-13 MENGIKUT NEGERI.docʡֽˤ13θ԰פΰաˤȤ̾Υޥ졼Microsoft WordɥȤ˻ųݤ졢ۤ줿

SENARAI CADANGAN CALON PRU KE-13 MENGIKUT NEGERI.doc

ǤϡιɥȤϡƱˤǰ֤ȤʤäƤ˴ϢõƤޥ졼ͤɸŪˤƤ롢ȿ¬Ƥ롣ե奢WordɥȤTrojan:W32/FinSpy.D.ȤƸФ롣

FinfisherGamma GroupȤ̾Υ衼åѴȤȯǿ줿ȤꡢδȤϥޥ졼ΥסˤƳŤ줿ISS World 2011νޤ˻äISSIntelligence Support Systems˴Ϣ٥Ȥϴƻ륽եȥθܻԤ̤ʻäˤϡ־ԡפɬפǡ̿ҡܡˡԵءפ°Ƥͤ˸¤ˡ

ISS World Kuala Lumpur

äơYouTubeFacebookMalaysiakinʥޥ졼ο͵˥塼ȡˤޤʣΥ˥塼ȤSNSȤѡDoS⡢ե륿󥰤Ȥäޤޤʷ֤ιƤȼĥ𤬽ФƤƤ롣

ե奢ܤǤϾ뤷Ƥ롣2013ǯ4δ֡ޥ졼Ǥϥޥ륦θзä򸫤ʤ顢äϢγưʤΤ̤ΤΤʤΤȽ̤ǤƤʤ

Malaysia, detections

Mac桼ɸŪˤWordɥ

2̤뤬桹ϥФ륵СǻѤ줿WordɥȤοХꥢȤ˵Ť

ΥХꥢȤ411񤫤VirusTotal˽Ͽ줿ΤȤԡAuthorˤȤCaptainǤϤʤInternational Uyghur Human Rights and Democracy FoundationؤȻפIUHRDFȤƤ

Properties of poadasjkdasuodrr.doc

ե̾C&CФ̤ΤΤȤƤ뤬ڥɤϤäѤäƤʤ

C&CФȤƤϡalma.apple.cloudns.orgפѤƤ롣

Command and control server name

ΥХꥢȤϰʲμʥԡȼưư롣

~/Library/Application Support/.realPlayerUpdate
~/library/launchagents/realPlayerUpdate.plist

뤤ϡ2ĤΥѥ᡼ȶ˼¹Ԥˤϡ˰ʲǽ롣

/Library/Application Support/.realPlayerUpdate
/library/LaunchDaemons/realPlayerUpdate.plist

Ʊޥ륦Τޤޤǡ2ʹߡ̤Backdoor:OSX/CallMe.AȤƸΤƤ롣

MD5: ee84c5d626bf8450782f24fd7d2f3ae6 - poadasjkdasuodrr.doc
MD5: 544539ea546e88ff462814ba96afef1a - .realPlayerUpdate

ڹΥ磻ѡظWhois

ƻˤС轵ڹ磻ѡޥ륦äݤˡڹLG桼ץ饹ҤWebȤ񤭴ƤȤΤȤ

ʲThe RegisterΰѤ

The Register Report

δطԤˤС磻ѡβóԤȤơWhois Teamפ˷Ƥ롣ˤϤޤ롣

Ars TechnicaʲѤ롣

Ars Technica Report

桹磻ѡΥץ뷲򸫤ƲäȤƥWebɥȡʡ.htmlס.aspxס.phpפʤɡˤ򸡺롼󤬴ޤޤХꥢ򸡽ФΥޥ륦ϤɥȤ򡢰ʲưȤޤäƱ褦˸ɥȤؾ񤭤롣



ΥץϡLG桼ץ饹ҤWebȤν񤭴Ѥ줿Τ餫˴ϢȹͤƤ롣

ץˤϡ¾Υ磻ѡΥץƱͤΥॹפ롣

ˤäDLL磻ѡΥץΥॹפϼΤ褦ˤʤäƤ롣

DLL Wiper Timestamp

񤭴Ԥä磻ѡΥץΥॹפϰʲ

Defacer-wiper Timestamp

ԤΥХꥢȤǤϥɥ饤֤ξõˤޤäۤʤˡѤƤMBRMaster Boot Recordˤ˰ʲΥɤư˥ǥõ롣

Bootstrap Wiper

ޤ¾ΥХꥢȤȰۤʤꡢΥץϥե륷ƥõݤˡHASTATIסPRINCIPESפȤäʸѤƤʤե0פǾ񤭤ʥե̾ѹƤǽŪ˥եõƤ롣ޤWindowsProgram Filesǥ쥯ȥǸĤäեϲ򤹤롣ԤϾ񤭤ڡǴWebФ󶡤³ä櫓ʤΤǡǤ٤ự̤롣

ǤϡƱΤϢƤȻפ뤫ϢƤȤΤäȤ⤢롣̤ιСˤäƼ¹Ԥ줿

ڹΥ磻ѡȥԥեå󥰤Υ᡼

轵ڹζԤɤ˱ƶͿ֥磻ѡץޥ륦˥塼󤸤줿ڹNSHC SecurityҤRed Alert TeamϡΥޥ륦ξܺ٤ʬϷ̤ǸɽƤ롣ƱݡͥȤФϥåͤĤƤꡢƱΥڡΤȡʣΥڥ졼󤬤äȤ򼨺Ƥ롣

ǤϡƶΤäȤϤɤΤ褦ˤƴΤïˤΤʤȤϤ狼äƤʤ桹Ϥ򸫤Ĥ

Archive

֥ե̾ȡ褽ָܵҤθפȤạ̈ˤʤ롣ʤߤƻˤСƶȤ1Ĥ˿ڶԤ롣

ԤܤäͤϤŤΥޥ륦Ĺե̾˳ĥҤŤˤĤʤΤѤƤꡢºݤγĥҤ򱣤Ƥ롣ϥ륨󥸥˥󥰤ڤƤѤǡ10ǯ絬Ϥʥ᡼λ˻ϤޤääơΥ֤ϥԥեå󥰥᡼źդĤ줿ǽ⤤ȡ桹ϹͤƤ롣

ޥ륦Υॹפ2013ǯ317ǡȯΤ鷺Internet ExplorerΥѤƤꡢ¹ԤȰʲΥǥ򳫤

HTML decoy document

Хå饦ɤǤϡޥ륦ʲɤƼ¹Ԥ롣

   hxxp://www.6885.com/uploads/fb9c6013f1b269b74c8cd139471b96fc/feng.jpg
   %systemdirectory%\hzcompl.dllȤ¸

   hxxp://www.clickflower.net/board/images/start_car.gif
   %systemdirectory%\%random%.dllȤ¸

   hxxp://mailimg.nate.com/mail/img/button/btn_mycomputer.gif
   %systemdirectory%\sotd.dllȤ¸

¾ˤ⤤ĤHTTPꥯȤԤ뤬Ϥ餯ڥɤ¸եɤꡢ뤤ñ˥ͥåȥȥեåƻ뤷ƤԤ鰭դΤHTTPꥯȤä뤿ΤΤ

桹ʬ桢ǤˤURL̵ޤϥ꡼ˤʤäƤʤ顢ե̾ԤΥˤĤƼ꤬ͿƤƤ롣ȤХեγĥҤˤꡢڥɤDLLեäǽƤ롣ޤbtn_mycomputer.gifפȤ̾顢URLκDzβȤơڥɤä줿ǽ롣Υ磻ѡڥɤؤΥ󥯤ȤƤʤΤĴ³ư衢ºߤΥץܤˤ褦ˤʤäƤ

ԤäפΤϸĤʤä礹磻ѡݡͥȤ2Ĥä1ܤƱͤ˹줿ե̾mb_join.gifפѤƤ롣ϤХХ󥭥󥰤WebȤjoinϿ˥ܥβȤƵ¤褦ȤƤǽ롣⤦1Ĥϡ֤ȥꥬˤDLLΥץ

Time trigger

Υɤϡ(month * 100 + day) * 100 + hour >= 32,015פƱǡ32015ʹߤΤ߾

ԥեå󥰥᡼ˤĤƤϤƤƶäƥब٤ƴƤȤϸ¤ʤĤΥХꥢȤϥ⡼ȤΥƥ磻פΤˡƥ˥󥹥ȡ뤵ƤSSH饤ȤեˤѤ롣äơƶƥǤä1ͤΥ桼ȼSSH饤ȤѤƤơܤˤƤޤȤȤ⤢롣

RAR֤ȶFelix DeimelVanDyke2ĤSSH饤ȤѤ줿Ȥ϶̣Ϥ⥵ɥѡƥΥץꥱǡWindowsΥͥƥ֥ץꥱȤƥݡȤƤʤǤϡ⡼ȤLinuxUnix١Υƥ濴˥磻פȤϸޤǤʤͤϤ٤ơɸŪȤΰݤͿ롣

ϥå󡦥ޥ졼 2013

24֥ǥ󥰤ǮϤ

hackathon2013 (62k image)

ʤ24֤ǥ顼ץꥱȯƤ뤫ƥΥ١䥳ǥ󥰡ڤळȤʤɡ٤Ƥ

⤷ʤ顢Webץꥱΰ򼡤ʳؤȳ׿ʤ뵡񤬤롣ޥ졼Υե奢ˤƺƤӥϥå򳫺Ť롣Υ٥ȤǤϳȯԤȤΥᥤȤ24ֽ椷ơ桹ˤȤäWebʾꤿ餷륢ץꥱȯ롣

ǯΥơޤϡWebΥӥˤ뤳ȡפǡȯԤˤҤΥ饦ɥͥåȥWebԥơꥢ륿Υޥ륦ΤȤäܺ٤ʴϢФƼAPI󶡤롣

Υ٥ȤBangsar Southˤ륯ס륪ե41213˳Ť롣Ԥˤ°ΥߥåҥåݥͥȤΥǥʡȤʤͿ롣Ūͭ̾ʥޥ륦Ԥηäڤ뤹Ф餷Ȥʤ

ܺپϿϡϥå󡦥ޥ졼Υڡ󥵥Ȥ顣

ɡ2012ǯȾζҥݡ

2012ǯȾˡ桹դפȤϲäμϡҤ2012ǯȾζҥݡȤˤ롣2012ǯ712ܤˤפʻϡۤܤ٤ƤޤȤƤ롣ѥɤӴĵˤĤƤûǶ̣ɷ㤷³ưʲʬΥǥ˰ܤäƤ

  •  ܥå
  •  ZeroAccess
  •  Zeus
  •  ץ
  •  Web
  •  ޥץåȥեι
  •  Х

ԡɤǤ롣

2013ǯ282012ǯȾζҥݡȤ졢ZeroAccessεεҤΤ褦ѹȤʤäA successful installation in the United States will net the highest payout, with the gang willing to pay USD 500 to 1,000 per installation in that location.ƹǥ󥹥ȡ뤵뤴Ȥ5001,000ƥɥʧѰդ륮󥰤ΤǡƱǼ褯󥹥ȡ뤵줿ȤˤꡢǹλʧۤϿˡפȤʸ[...] to pay USD 500 per 1,000 installations in that location.ƹ1,000˥󥹥ȡ뤵뤴Ȥ500ƥɥʧѰդ륮󥰤ΤǡˡפΤ褦

Exploits

С󥸥˥󥰤ӥޥ륦ʬϤˤĤƤؤιֵ

եɤEspooѥˤˤơС󥸥˥󥰡ޥ륦ֺΡ2013ǯմνƤιֵŤαӤȤʤ롣

ιֺ¤ϡιֺƱ͡إ륷󥭤ΥƥθãܤȤ롣դΤ륳ɤȤϲɤФʬϤǤΤWindowsAndroidʤɰۤʤץåȥեѤμ¹ԷΥɤС󥸥˥󥰤ˤϤɤΤ褦ˤ뤫ˤĤƳã˻Ƴ롣Хʥɲ䥨ץȤޤᡢޤޤˤĤơãõ᤹뤳ȤˤʤޤιֵǤϵŪʥȥԥåʳˤ⡢󥻥ƥ˴ϢΤŪ뤤ˡŪʤɤ夲롣

Ҥιֺ¤ǤϤĤΤȤã˼½ŪʼˡdzؽƤˤϡҤθʲΤ褦ʥС󥸥˥󥰤Υѥ򤯤Ȥޤޤ롣

homework

ϵȿ¦Υסʥޥ졼ˤˤҤ̤Υƥ꤬롣Ǥʥξ󵻽ѳعSunwayѥˤιֻդȶϤơƱͤιֺ¤Ω夲

monash

Androidץåȥեäޥ륦ʬϤˡäȽ줿ХȤʤäƤ롣Τ褦ʥޥ륦ʬϤιֵФƽ󶡤롣

ιֺ¤Ǥϡֵȼ½˺ǿߡʬˤĤƤ깭Ūʻޥ륦ʬϤɬפ祹ȤˤĤȤʤ褦ˤ롣ֵ½Ǽ夲ˤϡAndroidΥƥե졼䡢OSե륷ƥࡢˤϥޥ륦Ū뤤ưŪʬϤޤޤ롣

CFRΥȤäǥ

ꥹޥäᤴΤǤϤʤ򤷤Ʋᤴͤ褦 FreeBeaconˤȡ2012ǯ1226ƹγϢȿCFRCouncil on Foreign RelationsɾIJˤΥȤ줿

ˤHTMLΥץȡե뤬Ѥ줿ͤǡΥե뤫ȽǤȡιΥ桼åȤˤʤäԤϡWindowsƥθΤʲѤ褦˥֥饦ꤵƤ뤫ܤƤΤ

  •  ()
  •  ()
  •  Ѹ

ο줿ȤϹ⸡θ®䤫˽줿ȡȤ𤷤Ƥ롣ʤ顢桹¾Υ饤󹶷Ǥ˹ϤץȤѤͽ¬Ƥꡢ䤳ΥץȤMetasploit Frameworkɲä줿

ץȤInternet ExplorerΥС8ʲ˱ƶڤܤäơƶ桼ˤϡInternet ExplorerΥС9ޤ10˾夲뤫¾Υ֥饦˾괹뤳Ȥ򴫤롣

ƱˡޥեȼҤϾܺپ򼨤ƥɥХȡﳲ桼ΤΥ饦ɤȯɽ

—————

2013ǯ12ɸŪˤʤäθĴ뤿˺Խ

Post by — Wayn

Mac Revir˿ȯ

 Macޥ륦ΰ롣桹Ʊ˵ŤƤꡢե奢ΥޤϤǤݸƤ롣Revir.CΥޥʡʰڥɤˤĤƤϡŪ˲桹9˽񤤤ImulerƱ餯ϡФ򤱤ŪDzѤ줿ΤˤäƱϡ٥åȤο͸ưȤɸŪˤƤ롣

 Ǥв桹̾Τǡ󤬺𤷤ƤʤɤΤХåɥڥɤImulerȸƤФƤ뤬桹ϥɥåѥݡͥȤRevirȤƸФƤ롣ϲ桹ǯǽƱեߥȯݡɥåѤ¾Υޥ륦ڥɤȤ뤿˥ޥ뤫⤷ʤȹͤޤǤΤȤRevirImulerϾƱ˻ȤƤ롣

 桹ϡ򸡽Ф뤿ᡢǡ١򥢥åץǡȤ

 ⥪饤˷ǺܤƤ롣ܺ٤Ϥĺ

  •  Trojan-Dropper:OSX/Revir.D (MD5: 2d84bfbae1f1b7ab0fc1ca9dd372d35e)
  •  Backdoor:OSX/Imuler.B (MD5: 9ccc685f4d95403848ca24d9b8003b5b)

Q3 2012Х붼

 2012ǯ3Ⱦ̤ƸĤäХ붼Ҥ򥫥С롢ե奢ΥХ붼¸Υեߥ꡼οեߥ꡼Ȱ郎67ȯ졢ʿäΥץåȥեʤȤiOSWindows MobileˤߡޥץåȥեFinSpyȥϤΤˡʿ¤𤵤Ƥ롣

Q3MTR chart

 ܺ٤ˤĤƤϡˤ롣ԡPDFϤɤǤ롣

Q3MTR cover

ХåʥС
ǥطԤγͤ
ե奢֥С
ե奢֥С
ߥåҥåݥͥ
ե奢 CROʥƥʸˡʥإ륷󥭡
(Twitter)
(Twitter)
硼󡦥Х
ե奢 ƥɥХʥإ륷󥭡
(Twitter)
ŵ
᥿ɽ
(֥)
(Twitter)
߷ ͵
ҥ奢֥쥤 ǹ⵻Ǥ
(֥)
(ʪҲ)
ǥ ȡޥ ꥹӥ (2013ǯ3 ҥå) 󥻥ƥرءҰ
(Twitter)

(ʪҲ)
ʡ
ҥСǥե󥹸 ʬϴ
CDI-CIRTС
(ʪҲ)
͵
FFRI ɽĹ
(ʪҲ)
ʡܡ
ŷ

OWASP Japan
ɥХ꡼ܡ
Rakuten-CERT representative
(ʪҲ)
ե奢 ץȥ롼 Ĺ
ٰ β
ե奢 ץȥ롼
ݥ졼ȥ륹
ե奢
(ե奢֥Twitter)


ҥ᡼ɡ
ե奢᡼ޥ

֥˺ܤʤޥ䡢Ѽԥ󥿥ӥ塼ʾ󡢵ѲǺܤۿޤɥ쥹ΤߤϿǹ̵

ե奢֥ѣҥ
QR