ե奢֥ : by쥹ݥ󥹥

ե奢֥

by쥹ݥ󥹥

륨󥸥˥󥰤ԡ

 桹Ϥ2ۤɡѥ᡼𤷤ۤ줿ޥ륦¹ԤƤΤܷ⤷Ƥ롣

 Żҥ᡼åӥޥ륦ϡäܿΤǤϤʤåϵǡǥХꥵӥ˴ϢƤ褦Ƥ롣źդƤΤTrojanޤ൶ZIPե

 ZIPե뤬¹Ԥȡ桼ϰʲΤ褦ʲ̤򸫤뤳Ȥˤʤ롧

DHL Express Services

 ֤DHLξϤƤΤȥå󥰥ʥСåΤˡźսǧʡäԤƤ衣FedExä

 桼ϴǤʤ𤷤Ƥޤ

Threat Solutions post by — Broderick

CVE-2011-0609פѤ

 ɸŪ˰դե򳫤褦ȡԤܤξѤƤ롣ΥϡFlashץȤȼExcelźեեѤΤ

 ʲϡŻҥ᡼Υ꡼󥷥åȤǡContagio󶡤줿

jnr

 ϢXLSץϰʲΥϥåġ

  •  4bb64c1da2f73da11f331a96d55d63e2
  •  4031049fe402e8ba587583c08a25221a
  •  d8aefd8e3c96a56123cd5f07192b7369
  •  7ca4ab177f480503653702b33366111f

 桹ϤExploit.CVE-2011-0609.AפӡExploit:W32/XcelDrop.FפȤƸФƤ롣

 桹ܤˤ¾Υץmd5:20ee090487ce1a670c192f9ac18c9d18ˤϡΤȼCVE-2011-0609ˤѤFlash֥ȤޤExcelեXLSե뤬ȡ϶ExcelץåɥȤɽFlash֥Ȥ𤷤ƥץȥɤ򳫻Ϥ롣

 Flash֥ȤϡʲΥ륳ɤޤҡץץ졼¹Ԥ뤳Ȥ饹Ȥ롧

heapspray

 Υ륳ɤExcelեޤ줿Υ륳ɤˡ¹Ԥɤѥ

shellcode

 Υ륳ɤϡEXEեExcelեޤƤ⤤ˤβɡ¹Ԥ̤

second shellcode

hiew

 Flash֥ȤϡFlash֥Ȥ󥿥Ǻɤ롧

Flash

 Flash֥ȤƱޥ륦μפʥץȤǡCVE-2011-0609פѤƥҡפǥ륳ɤ¹Ԥ롣桹ϰŪƱFlash֥ȤExploit.CVE-2011-0609.AפȤƸФƤ롣

 ;̤ȤơμפʥץȤϡФΤ򤱤褦ȤơΤ褦ʷۤ줿褦ǥɤ뤿ᡢ륹󥸥󤬥ѤǤʪե뤬¸ߤʤExcelե˼פʥץȤɤFlash֥ȤळȤϡ˹򱣤Ȥߤ⤷ʤ

 ʤȤˡդΤExcelեȤȹEXEեϡExploit.D-Encrypted.GenפӡTrojan.Agent.ARKJפȤƸФƤ롣

 AdobeˤȼФѥåƤΤǡ桼Flashץ쥤䡼򥢥åץǡȤ٤ܺ٤ˤĤƤϡCVE-2011-0609פ˴ؤAdobeΥƥɥХ򸫤Ƥۤ

Threat Solutions post by — Broderick

饦ɤ¿Υեå

 桹Ͽʥեå󥰤λߤϡMaybankʥޥ졼μ϶ԤΰġˤΡ֥åʡץޤɸŪȤ줿ѤƤΤŵŪʼˡʤ¾ïθ¤褽˥ޤ˼ʬΥȤǧ褦Transaction Authorisation CodeפɬפǤ뤳ȤפФ뤳Ȥ롣

maybankphishing (48k image)

 ʤĴˤꡢŻҥ᡼ϥѥॵФͳ褹뤳ȤʬäƤ뤬桹ʬäΤϤ¾ΥȥåϤ٤ơŤ˱äƤ롣

 եå󥰤λߤˤϲ鿷Ȥ̵ȯӾդǤΥեå󥰤ưϡǶäƤ褦ΥƥӥƥĥܿͤǤ륰롼פϡե򿷤Ծ˰ܤΤ餯ϡ饤Сʥ󥯤⸡Ф򤯤ȴƨ󥹤ޤȹͤΤƱϰΥޤ餯饤Х󥭥󥰤ǶΤäФǤȤ¤ͤƤ⡢٤ʥ륨󥸥˥󥰼ˡưפ˰äǽϹ⤤

 ͳʤǤ졢κդտޤ뤳ȤϰĤʤԤѤǤͤ롢ȤȤBrowsing ProtectionפΤ褦ʥġϡ桼ʥȤؤΥݸȤʤ뤬Ǥɤˡϼʬΰ˼Ǥ餦Ȥ桼櫤뤳Ȥ򤱤ˤϡդϢˤ̾¹ԤȥåΤäƤɬפ롣

ʴ𡧤εΥȥʸΡPlenty of Phish in the Cloudפ˴Ťޤ

Trojan:Android/BgServ.A

 Google֤˵Trojan:Android/DroidDream.Aפˤ뺮н褹륻ƥ塼

 ƱġΥȥϲ줿СиƤʲ桹ϤTrojan:Android/Bgserv.AפȤƸФƤˡƱȥϤζ̣ͽʬϤSymantec֥ǸƤ롣

 ʪХȥϥСΰ㤤ϡץꥱå뤳ȤdzǧǤ롧

Android Market Security Toolס

android_market_security_tool_installation (121k image)

Trojan:Android/Bgserv.Aס

trojan_android_bgserv_a_installation (129k image)

 ƥ/ѥåΥ꡼󥷥åȡ

trojan_android_bgserv_a_comparison (114k image)

 ä󥤥󥹥ȡ뤵ȡTrojan:Android/Bgserv.AפIMEIֹʤɡ桼þ롣ξϡhxxp:// www. youlubg. com: 81 /Coop/request3.phpפ˥åץɤ롣

 ⡢Υޥ륦ڤΥͥåȥòƤ褦China Mobile Net˴ϢʥС10086˥󥿥ȤꡢcmnetפȤ̾ΤAPNꥹȤAPNѤƤΤ

 Υޥ륦ϡǥХ̤ΥǡѤ桼˹ۤݤǽ롣

 ̣ΰդ륳ɤϡAndroid Market Security ToolפˤΤ¤Ƥ櫓ǤϤʤ褦AegisLab֥ˤСƱͤΤդޤ¾AndroidץꥱǤ⸽뤽


Ǥϡ
Zimry

Androidǥȥϥ顼

 Android Marketפȯ줿ȥϲ줿ץꥱ˴ؤǶΥݡȤ桹ܤαޤäAndroidpolice.comReddit𤷤ơ

 ΰդ륢ץꥱϡ͡ʥǥ٥å̾Ѥƥåץɤ줿ϢץꥱδʥꥹȤϰʲˤ롧http://pastebin.com/Ue8TfLgE

 androidpolice.comפΥݡȤˤСդ륢ץꥱΰĤåȤ롼ȥ뤿ᡢΤΥץȡrageagainstthecageפޤǤ뤳ȤʬäΥץȤϡAndroid 2.2פӤΥСư뤳ȤΤƤ롣

 androidpolice.comפΥꥸʥΥݡȤϡ鰭դ륢ץꥱ󤬡Android Marketפ˺줿ȤɽƤ롣ϡƱޥ륦ޤäɤƤʤ桼ˤȤäơ餷˥塼

 ˥ɤƤޤä桼ϡGoogle⡼ȤǤ饢ץΤԤɬפ뤤ϡưǺ뤫

 桹Ͼ˥³ͽޤʤʬϤΤᡢ桹Ϥȥϲ줿ץꥱΥץõƤ롣⤷դ륵ץ򤪻ʤ顢桹ΡSample Analysis Systemפ뤳ȤƤĺй


Ǥϡ
Zimry

ɵpastebinפΥ󥯤ϤǤͭǤϤʤMashable¾Υ˥塼ȤꥹȤȯɽƤ롣

Pjapps

 躢դ롼ǥѥå줿AndroidSteamy WindowsץꥱǤȯ줿SymantecɤǺܤƤ롣

 ʰ˺ƤȤ򸫤ȡΥޥ륦κԡʤˤϡΥץꥱ򹥤Ǥ褦ϡTrojan:Android/Pjapps.BפȤƸФƤ롣

 Ʊ򤶤äȸȤSMSץꥱΥ󥹥ȡ롢֥åޡɲáC&CФΥޥɤμʤɡդ뵡ǽϤۤѤäƤʤ

 ʲˡTrojan:Android/Pjapps.AפȡTrojan:Android/Pjapps.BפӤ꡼󥷥åȤ礫󤲤롧

Trojan:Android/Pjapps.A

pjapps_a_installation (154k image)

Trojan:Android/Pjapps.B

pjapps_b_installation (143k image)

 ưʲξΥɤΰ餫ˡPjapps.AסʺˤꥸʥСǤꡢPjapps.Bסʱˤ֥С2פǤ뤳Ȥʬ롧

pjapps_info (158k image)

 餯Ǥʬ䤹ѹϡС󤬡ּưŪ˥֡ȤǥȤפȤȤ

 ϲ桹Androidץꥱǡƥȥϲ줿ΤǤϤʤTrojan:Android/Adrd.AˡAndroidޥ륦äƤ뤳ȡƤ֤󡢤ۤɶä٤ǤϤʤΤ濴Ǥ餷Ȥ⤦ĤǤϤ롣

 桹AndroidʤϡǿΥǡ١åץǡȤˤꡢĤΰ򸡽ФƤ롣


- ʬϤZimryˤ롣

MBRե륷ƥ।եפʬ

 Portable ExecutablePE˥ե륤ե륹򸫤뤳Ȥɤ뤳ȤRAWե륷ƥͳե륤եΥǤϡMaster Boot RecordMBR˥ե륷ƥ।եפϡ⤦

 ˤϡPEե𤵤ʤƤ궯Ǥǡȯ䥳ȥ뤬ưפȤͳ⤢롣оŪMBRեϤʣǡ627C00Hˤ˸ꤵƤ롣ޤ顼;Ϥ⾯ʤʤMBRե륷ƥ।եǤξʥߥХϡƥưǽˤΤ

 äơĤ̵ե붦ͭͥåȥˤäۤƤ餷Trojan:W32/Smitnyl.A (98b349c7880eda46c63ae1061d2475181b2c9d7b)פΤ褦MBRե륷ƥ।եϡĤPortable ExecutableƥեɸŪˤƤǤäƤ⡢Ƥδ̤Υ륹ե륤եӤñǤäƤ⡢®ʬϤ뤳ȤϲͤȻפ롣

 Smitnyl.AפϺǽˡRAWǥ𤷤MBR롣ˤ򡢥ե륤ե롼ޤభդMBR֤ʥ32¸ˡ

12ꥸʥMBR񤭡ѡ1ʾˤȥѡ2ʲ
1: Overwriting original MBR

2: Overwriting original MBR

 ʤMBRե륷ƥ।եʤΤ餯ϡ줬Windows File ProtectionWFPˤХѥ뤳ȤǤ뤫WFPϥץƥȥ⡼ɤưƤΤǡ⤷֤С٤ƤWFPݸե¨¤˥ꥹȥ롣

 եڥɤA00Hǥ39鳫ϤǡꥸʥMBRϥ5¸롣ΥڥɤϡWindowsΥƥ륷ƥեuserinit.exeפ˾񤭤롣

3416ˡˤ봶MBRʺˤȥꥸʥMBRʲ
3: Hex view of infected MBR

4: Hex view of original MBR

516ˡˤMBRե륷ƥ।ե롼
5: Hex View MBR File System Infector Routine

616ˡˤUserinitեڥ
6: Hex View Userinit Infector Payload

 ʤUserinitפʤΤ餯ϡƥबȤȼưŪ˥ץΰĤǤꡢƥॹȻ˥ޥ륦ưŪ˼¹Բǽˤʤ뤿

 Smitnylפϥ֡ȥ󥹤κǽΥơ顢Userinit롣MBR0x7C00˥ɤݡѡƥơ֥롢ˤϥ֡ȥstarting offset饢ƥ֥ѡƥ¬ꤹ롣

 ˥ޥΥե륷ƥॿפå롧

7֡ȥפ¬
7: Determine Boot Sector Type

 NTFSե륷ƥबĤСޥեơ֥MFTˤϤMFTϤȲꤷơ˥ǥΡUserinitפǡꤹ뤿ᡢ$ROOT (.)ե쥳ɤ°ɤ$INDEX_ALLOCATION°õSmitnylפϡuserinit.exe֤Ƥ롢$ROOTSystem32ǥ쥯ȥޤWindowsΥѥå롣

89Userinit.exeΰ֤ꤹ롣ѡ1
8: Locate Userinit.exe, Part 1

9: Locate Userinit.exe, Part 1

 Υޥ륦ϡuserinit.exeե򸫤ĤΤˡget_userinit_data_content_addrץ롼ѤExtended Write Functionʥե󥯥ʥС ah = 43HˤѤơ39ǥեڥɤ񤭹ࡣuserinit.exe롼δ֡Ʊޥ륦offset 0x28Ǵޡ¸ߤʸ夫ܤ˥å롣

1011Userinit.exeΰ֤ꤹ롣ѡ2
10: Locate Userinit.exe, Part 2

11: Locate Userinit.exe, Part 2

 ޥ󤬴MBRȤȤˡޤ֡Ȥȡuserinit.exeϴ졢ưŪ˥Ϥuserinit.exeǧĤˡϡեץѥƥΥå

1213userinit.exeץѥƥꥸʥȴ
userinit.exe Properties, original userinit.exe Properties, infected

 ʤȤˡ㤤Ϥʤ

 16ɽǡե򸫤Ƥߤ褦

14Userinit
14: Infected Userinit

 ե롼󤬡˴ޡ0x55AAåȻŦȤפФǤϤ줬¹Ԥݡ򤷤褦ȤΤפʥڥɤϥ45ˤ롢󥳡ɤ줿¹ԥե뤳Ȥ

1545Υ󥳡ɤ줿¹ԥե
15: Encoded Executable File at Sector 45

 ϥǥɤ򳫻ϤǽڥɤˡĤνԤ

  •  360safe륹¸ߤå롣⤷ĤС360safe IE֥饦ץƥ̵ˤ롣

16360safe IEץƥ󡦥쥸ȥꥭå
16: 360safe IE Protection Registry Key Checking

  •  ե˵explorer.exe롣ϡǥɤ줿¹ԥե

17ǥɤ줿¹ԥեˤ뵶Explorer
17: Fake Explorer with Decoded Executable

18ǥɤ줿¹ԥեˤ뵶Explorer
18: Fake Explorer with Decoded Executable

  •  ǥǥ󥰸塢ShellExecuteѤơ%temp%\explorer.exeפ롣ϴ򱣤ǥȤѤ롣ƱˡWinexecפѤʪΡexplorer.exeפ¹Ԥ롣

Ρexplorer.exeפ¹ԤꥸʥΡexplorer.exeפ
19: Execute fake explorer.exe and launch original explorer.exe

 λȡڥɤ롣

20ǽڥ
20: Final Downloader Payload

 ˤ⡢κǽڥɤˤϲ̤ʤȤ̵ñʤuserinit.exeפϡ360safeIE֥饦ݸ̵ˤˤ⡼ȥСhttp://[...]פեФȤǽˤʤ롣

ƤLow Chin Yickˤ롣

Trojan:Android/Adrd.A

 23ߥåADRDפȤ̾οAndroid trojanʲ桹ϤTrojan:Android/Adrd.AפȤƸФƤˤˤĤƥĥȤ

 AdrdפϡʬΥɥѡƥץꥱץХˤ롢ĤΥץꥱ˥ȥϤŹޤƥѥåƤ֤ȯ줿ޤǤΤȤץꥱʬϡڡѡϢΤΤ

 ʲϡץꥱ



 󥹥ȡ뤵줿AdrdפץꥱϡʲΤ褦ʥѡߥå򼨤⤷ʤ



 ΥѡߥåϡüΥȥåˡAdrdפΥ롼򳫻Ϥ뤳Ȥǽˤͥåȥǡε/ػߤȤäǡ³ѹԤѡߥåˤϡSDɡüAccess Point NameAPNؤΥޤޤǽ롣

 AdrdפεǽˤϡʲΤ褦ʥ⡼ȥۥȤؤιޤޤ褦

- adrd.tax[..].net
- adrd.xiax[..].com

ơüξä˹ݰưֹּIMEIˤȡưԼֹIMSIˤ롣ǡϡDESǰŹ沽Ƥ롣

 ⡼ȥۥȤϥ󥯤ΥꥹȤǥץ饤롣ΤΰĤAdrdפ˥쥯Ȥ¢륷ץͥ졼Ѥ³롣򤵤줿󥯤򿮤ȡѤߤΥʸ֤AdrdפХå饦ɤǸ¹Ԥ롣


1. Adrdפͥ졼ϡ⡼ȥۥȤꥹȤ򼨤롣㤨 http: //59.[...].12.105 /g /g.[...]?w=959a_w1 ȤäΤ
2. Υ󥯤ϼºݡAdrdפѤ븡ޤǤꡢϰʲͤˤʤ롧

http://wap.baidu.com/s?word=%e5%[...]e5%89%a7%e7%85%a7 &vit=uni&from=979a

AdrdפϤХå饦ɤǽ¹Ԥ롣

 ⤦Ĥεǽϡmyupdate.apkפȤ̾APKɤ뤳Ȥǡ/sdcard/uc /ե¸롣Ϥ餯åץǡȥݡͥѤ

 AdrdפΥͥåȥϡ®ǡѤ˷ҤꡢϷɡؤȷӤĤǽ롣桹ϡAdrdפcmnetסcmwapסChina Mobile NetˡuniwapסuninetסChina Unicomˤ³ƤΤǧƤꡢAdrdפΥޡåȤˤΤۤƤ褦ǡΥͥåȥˤΤͭʤΤǤǽ롣


- ʬϤZimry Ongˤ롣

ͭ̾ʤǤŤ

 桼륹ץ̾顢ʪʪʬ뤳ȤĹƤƤ뤿ᡢκԤϸߡ˸äƤ롣ʥץΥǥƥƥߡʬεʤǤѤƤΤǶᤢ桼㤤ƤεAV褦ऱ٤AVGΥȿι⤤̾ΤȤѤƤΤȯ줿

 εʤϡ¾ΥǻѤƤŵŪʥ᥽åɤƤʤƥ򥹥󤹤դ򤷡ʣΰդեȯȼĥΤ̵Ǥϵǽ¤Ƥ뤿ᡢΥե뤿ˤϡ桼ϥեСʵΡˤ˥åץ졼ɤʤФʤʤ

 AVGΥСΥΥ󥿥եˤϡΡAVG Anti-Virus Free Edition 2011פȻƤ̵

ʪ
Fake AVG

vs.

ʪ
AVG

 Ʊʤ褯Τʤ桼ϡΰ㤤˵ŤʪʤꤷƤȹͤǽ⤢롣

 äȤɥХġ󶡸˵Ĥ뤳ȡƤΥ륹Ȥϡʤ̵/ȥ饤Ǥ򥵥Ȥľ󶡤Ƥ롣äơǤʤͥϥåפľAV٥ꤹ뤳Ȥ

Х륻ƥƥåץ

 CES 2011פХ륳ԥ塼ƥ󥰤̤˴ؤץӥ塼Ǻǯ򳫤餯NVIDIA Tegra 2ʤɤΥǥ奢륳CPUܤϥڥåΥޡȥե䥿֥åȤ¿꡼뤳ȤԤ롣桹ˤϡLG Optimus 2XפMotorola Atrix 4GפȤäüSneak Peek̥λƤԤ⤪ꡢ餬Ⱦ꡼뤳Ȥְ㤤ʤڤߤˤƤ롣

 ǡ⤬²ˡХ롦ԥ塼ƥ󥰤ΥƥΥѥեˤʤ뤳ȤǡХ뵡ϾΥѥˤŤƹԤˡ桼ñ˶Ԥμ䥪饤󥷥åԥ󥰡ե饤ȤͽʤΥ֥֥饦󥰤ʤɤԤΤ륢ץꥱ󤬼䤹ʤ뤳Ȥǡ桼Υޡȥեؤΰ¸®롣

 Х롦ԥ塼ƥ󥰿͵ιޤϡդ빶˿򳫤Ƥ롣ŪΰǤ뤿ᡢԤƤꥹ˵ŤƤ餺Ȥˡ褯狼ʤͤ⤤ǼϤȤơʲˤĤΩĥƥåץ󤲤Ƥ

  1. ƥ˥åץǡȤ
     ȻפʤȤХ롦ڥ졼ƥ󥰥ƥ򥢥åץǡȤƤȤǡ桼ϺǿεǽǤǤʤƥȤʤ롣ѥƱͤˡƥǿˤ뤳ȤϡƤʤƥۡȼѤ밭դ빶ؤɸȤʤ롣

  2. ü˥ƥץꥱ򥤥󥹥ȡ뤹
     Х뵡ϥߥ˥ԥ塼¤ߤεǽͭƤ뤿ᡢ̥ŪɸŪȤʤ롣ƤϡեǥХȴޤޤǡݸɬפࡣȤХե奢ΡMobile SecurityץץꥱϡǡݸҤɸ椷ʶ⤷ˤäü򸫤ĤȤʤ뵡ǽ󶡤Ƥ롣

  3. å夹˵դ
     Ŀ;䥯쥸åȥɾ륹եå󥰤ϡХ桼ФäȤ⥢ƥ֤ʹȤʤ뤳Ȥͽ롣륨󥸥˥󥰤μˡϡ桼˰դ󥯤򥯥åꡢͭפʾ󶡤ꤹ뤿Ѥ롣äơ֥ȤhttpsפǻϤޤäƤ뤳Ȥ򡢵̩Ϥ˳ǧ뤳Ȥ

  4. ѥ֥åͥåȥǤξ򹵤
     ѥ֥åͥåȥͭפǡǡ󤹤Ȥʤ롣ʬä³Ƥѥ֥åWi-Fiϡ奢ǤϤʤ⤷ʤȤ򿴤ˤȤƤɬפ롣뤿ᡢưϥ֥饦󥰤¤ԤΤ򤱤뤳Ȥ

  5. ץꥱΥ󥹥ȡ롢ϿѤǤ륽Ԥ
     ޡȥեͭ뤳Ȥγڤߡʤˤˤϡ͡ʤȤǤ¿̤ʥץꥱ󤬳ѤǤȤȤ롣¿Υץꥱ¸ߤΩ˥Ƥʤ̤ͥ󶡤Ƥ롣ʬ󥹥ȡ뤷ΤդΥդ뤳Ȥˤϡդ륳ƥĤޤѥå줿ץꥱޤΤ⤢뤫⤷ʤ

  6. üǤγƥץꥱΥǡΥå򽬴
     ץꥱˤϡ桼ΥǡĿ;˥Τ⤢롣ץꥱϰϳŪΥѿ뤳ȡȤСSMSɤ߽񤭤ˤ䥳롢Ģȥꡢƥե˥륲ॢץꥱϡʤʥɬפʤΤȵ򴶤ɬפץꥱФƲ餫εʤ顢󥹥ȡ뤷ƤϤʤ


 ǯ桹ϥХζҤ˿˵ư򡢤ĴƹԤͽХ륻ƥ˴ؤǿĴ̤˥塼ܤߤ


--Zimry OngƤˤ롣

٤CPUϥޥ륦ɸ

 ܤǤε路Хʥ򰷤äƤ롣ʹ֤θԤŪʥ롼פΤ褦̤갷ͣˡϡ󥪡ȥ᡼󲽤桹Υޥ륦ץƥ˥ݡȤ줿ץϥ󤵤졢ʬव졢۴ĶǼ¹Ԥ롣Ͽ졢桹ʹ֤ʬϤ롣

 ޥ륦Ԥϡ륹Υ٥ǿΰΥ饤եѥ򹶷⤹뤿ᡢȥ᡼󲽤Ȳ۲ѤΤäƤ롣ʤ줬餬¿ΰͳ̤¿Ȥ˲äơ¿Υޥ륦ΰϡ桹Υꥵ˸ǽʸ¤ĹФʤ褦ˤ뤿ᡢСޥ󸡽ФȥǥХå󥰥ɤޤǤ롣

 ˤϡΥǥХå󥰤Ϥޤ˹ŪǡոȤȤ⤢롣

 轵ϥǥХå¸ߤ򸡽Ф뤿ᡢʣΥ᥽åɤѤƤZbot̾ZeuSˤΰʬϤƤǥХåФȡExitProcess¨¤˸ƤӤդ륳ɤϼ¹ԤʤΥǥХåȥåĹ餯ΤƤΤΰĤˤѤ롣

 ʲ֥ꥳɤ

IDA

 ǽˡRDTSCRead Time-Stamp Counter˥󥹥ȥ饯󤬼¹Ԥ롣ॹץ󥿤ϡƥåͤä롣󥿤ι̤32ӥåȤEDX˥ɤ졢å˥ץå夵롣ˡ2ôּ¹ԤߤSleep0x7D0ˤƤӽФ롣ǸRDTSCƤӼ¹Ԥ졢դ32ӥåȤϥå¸줿ͤӤ롣ͤСʤRDTSC¹Ԥ¹Ԥ뤿ӤˡEDXƱͤȤʤ顢ץϥǥХå¸ߤƤ˰㤤ʤȽǤ롣ϡʤȤ2ô֤2^32å뤬EDXͤäʤФʤʤȤ˴ŤƤ롣

 ϡץCPU2GHzʾưꤷƤ뤳Ȥ̣Ƥ롣С2GHzʲCPUǤϡץϥǥХåƤ뤫Τ褦˿񤤡¹Ԥߤƥ˴ʤȤȤϤΥץIBM T421.86GHz˥ΡȾǥƥȤƱƥϥԡɤ٤äᡢ򤱤뤳ȤǤ

 ZbotΥǥХåɸΤ⤦̤ѤϡƱץ뤬뤳Ȥνɤʥԥ塼⡢ܥåȤιʥ쥯˽ȤȤ⤷顢ZbotФޤƤϢˤϡðۤʼ̣Τ

 εϥ쥹ݥ󥹥Timoˤ롣

𤵤줿⥵ȡ - ƥġκǿΥȥå

 ⥵Ȥ֥åFirefoxǽϤѤơʥ륹ץꥱSecurity ToolפʥȥåߤƤ롣Ʊץꥱ󤬡ʤץå夹ΤFirefox Update FlashǽѤΤϡۤΤȤǤϤʤ

 ѿʥ桼ڡ˥ȡˤʪ餷FirefoxΥ֥åڡɽ롣

Reported Attack Page

 ϡ̾Υ֥åڡǤϤʤ֥饦򥢥åץǡȤ뤿ᡢ󥹥ȡ뤬Ԥɤ󶡤ƤȤ̤ʤΤ

Reported Attack Page

 餷Ǥ礦ǡѿʥ桼ϡff_secure_upd.exeפɤAV򥤥󥹥ȡ뤹뤳Ȥˤʤ뤫⤷ʤ

 ºݤ…ץȤ֥饦ǵĤȡDownload Updatesץܥ򥯥åɬפʤ桼AV򥪥եΤ

Reported Attack Page

 ơCancelפ򥯥åƤ⡢ݤ롣

Reported Attack Page

 ɡ桼Firefox򥢥åץǡȤ٤ȤȤơƱץꥱϤ⤦٥ɤܤεͿǴ

 ʤΤϡƱڡֹڡˤϡΰդͭʥեȥۤƤΤ⤢פȤޤǤ뤳Ȥ֤ɤ򤹤뤫ʲΥܥ򥯥åƲפȤäƤɤä⤷ʤ

 餷ȥåʤ©ƾ꤯Ԥ⤷ʤäơFirefoxץ֥åڡ򸫤鿵ŤˡʪΥڡϥ桼ˡɤ褦¥ϤʤʲϡʪFirefox֥åڡγѤ

Reported Attack Page

 ɤ˥ꥻåȤβΤΰĤפФ…

ɵή̤뤳ȤܻؤWebȤϸȤGoogle ChromeѤΥ֥åڡѰդƤ褦

Malware Detected!

 AVեѤˡchrome_secure_upd.exe פȤե̾ѤƤ롣

 Ǹˡ̤ΥȤPhoenixץȥåȤɤڡiframe롣

 ʤɲþΥ쥸åȤϡWebsensePatrik Runaldˤ롣꤬ȤPatrik :)

 ƤChristineMinaˤ롣

βѤʤΤ狼ޤ

SpotTheOdd (107k image)

 ǤȤICICI BankΥڡȤURLäƤʤΤ˵Ťޤ͡⤦Ťˤʤä⤷ʤΤϡStep 1δְ㤤ºݤΥڡǤϡ桼URLǤ뤫ɤΤ褦¥뤫2Ĥΰ㤤СξΥڡƱΤ˸롣

 ٤ƤϡǶդλʤΤ롢ɤνǶɤŻҥ᡼ǻϤޤä꿮괶ᡢFromץɥ쥹ϤʤꤹޤƤ줫ɤʤ뤫¸Τ󥯤򥯥åǧھϤȡϢ椬ʤζԸ¤˥롣

 ɤΤ褦ʸؤ⡢Żҥ᡼𤷤Ƶ̩ι⤤ưȤäꡢ̩ǡ餫ˤ褦¥ϤʤȤϡ˿αƤΥǤϡǼǿ򤹤ݤɬפȤ󤬤٤ƼƤ롣ɤνǶɤΥȤǤϡΥեå󥰤λߤˤĤƷٹ𤷤Ƥꡢ桼ˤΤ褦ʥ᡼̵뤹褦˥ɥХƤ롣

 ɤɼԤˤϡʤ⤷ޤʤС˽Ǥο˺ʤ褦夲롣

 ξ󤻤Ƥ줿KandruVenu˴դ롣


եå̤Υ顼ȡ

 ԤƤ桹ˤʤꤹޤȤƤꡢʲΤ褦Żҥ᡼Ƥ롧


From: Account Support
Date: Saturday, August 28, 2010 4:33 AM
To: none
Subject: Account Alert!!!

An HTK4S virus has been detected in your Email Account, and your email account has to be upgraded immediately to our new F-Secure HTK4S anti-virus/anti-Spam version 2010 to prevent damage to the email and important files in your email account. You are therefore required fill the columns below to enable us verify your email account or your email account will be suspended temporarily from our services.

Username:
Password:
Date of Birth:
Telephone Number:

Copyright© Customer Care Center 2010 All Rights Reserved.



 ᡼̵뤷׵ᤵƤܺ٤˱ʤߤF-Secure HTK4S anti-virus/anti-SpamפȤ̾ʤ¸ߤƤʤ桹ܵҤФơΤ褦ʤҤɤʸ̤Υ᡼褦ʤȤ̵

̵iPadؤ2ƥåפ󤶤

 ľʤȤ󥯤򥯥å뤳Ȥ̵βȤ󤢤…ѥȥϡѥϡ̵βȤϥȤʤ

 桹躢ץꥱƥˡ̵iPadץ쥼ȤȤȯ餫ˤΥȤϡiPadץꥱƥȥץ˻ä褦͡ͶߡƱȤΥʡSMSΥ㡼ȥեꥨȥץफפȤȤߤƱץ˻äˤϡ֥ƥפ2ĤΥƥåפλ뤳Ȥ׵ᤵ롣

iPad scam website

ƥå1Twitterͥȡ֥ƥפϼʬTwitterȤ˥󤷡Keep it to hendפȤ̾Υץꥱ󤬡ʬξ˥Ǥ褦ˤ뤳Ȥ롣

iPad scam Twitter

 ȡƥͧͤϡiPadAppsTestingWebȤؤΥ󥯤ޤĤ֤䤭ȤꡢJennt0kvqtפȤեͧãե뤳Ȥˤʤ롣

iPad scam, Twitter spam

iPad scam, Twitter Jenny

 ǤJennȤïʤΤΥڡ򸫤Ƥ礷ʬʤμ̿ؤΥ󥯡ʥȤ˻ä褦ï꼡ͤ󽷤Ϳ륢ȥȤ˥ˤȡ㴳Τդ줿Ĥ֤䤭Τߤ

ƥå2ܥ򥯥åϿλƥ¾ΥȤͶƳ롣

 iPad뤿μ˲ȡ˷äֹϤ1֤2ĤSMSȤ뤳ȤƱդ褦롣SMS1ܤˤĤ8ޥ졼󥮥åȤ롣

iPad scam SMS

 ɤΤȤ«줿iPadϤޤǧƤ餺ƥTwitterѥȥХХSMSå뤳Ȥˤʤ롣

 ƤChoon Hongˤ롣

Firefox/FlashåץǡȤAV

 Ԥϡ桼Υƥ˲ݤλȤŤ줿ȥåˡ˰Ƥޤä褦ޤǤΥȥåϡٹ𡢤Ƽ˵AVؤȻ롢ڡäΤ

 ߡFirefoxΡJust UpdatedץڡȤʤäƤ롣Firefox֥饦򥢥åץǡȤȡɽ뤳ΥڡΤäƤơǽFirefox򥪡ץ󤷤ˡʶȤ꤬롣FirefoxåץǡȤ줿ȤƤ⡢Adobe Flash PlayerϥåץǡȤƤʤȡ桼˹𤲤åΤΤᡢޤåץǡȤɬפȤ¤Ω…

Firefox Update

 ƥ桼ϲ⥯åɬפʤڡɤȤˡɥܥå뤫…

Binary

 桼ե¹Ԥ…ߤΰAV…

Security Tool

 ɤ櫓ϢFirefoxFlash Playerʤä褦…ΤξԤ򾯡ȤȤˤʤäΤ

ΰդ륵Ȥϴ˥֥åƤꡢƱϥե奢κǿǡ١åץǡȤǸФƤ롣

 Ƥϥ쥹ݥ󥹥Mina & Christineˤ롣

WoWȥեå

 World of WarcraftפΥȤϡץ쥤䡼Υ٥˱ơեå㡼ˤȤäƶΤʤڤȤʤ롣⥢ƥˤϼפꡢºݤΥå㤵뤳ȤǽʤᡢWoWȤϿ͵Τեå󥰥åȤȤʤäƤ롣

 ե奢Response LabΥʥꥹȤ躢BlizzardWoWΥꥨˤ顢ȳǧ򤹤褦ˤȤŻҥ᡼Ȥä츫Υ᡼ϡʪΥ褿᡼Τ褦äFromץɥ쥹򸫤ߤ路Ȥϲ̵

WoW Phishing, Normal View

 Żҥ᡼Ƥ򤵤ɤȡʾβ򥯥åȳĺˡ롣ΥȤγǧϡBlizzardȴϢΤʤȤǹԤͤФʤʤΤ᡼ˤϸʸˡߥ¿

 Ĵ٤ƤߤȡƱ᡼ϸĿͤΥ᡼륢ȤƤ뤳ȤʬäեåSMTP졼ѤơFromץɥ쥹ΤʤꤹޤԤäƤ뤿ᡢƱ᡼BlizzardΤΤ˸Τʲβ򥯥åȳĺˡ

WoW Phishing, Full headers

 BlizzardΥࡢäWoWStarcraft IIDiablo IIIΥȤϸߡBattle.netˤ갷Ƥ롣ȤѹˤϡʳǧץɬפȤ졢κݡͭID󼨤ɬפ뤳Ȥդߤ

Battlenet TOC

 եå㡼ϤޤޤʤäƤꡢΥ륨󥸥˥󥰤ϡ깪̯ˤʤ긡Ф񤷤ʤäƤ롣դߤƤΥꤷʤȤϥ桼Ǥ

åΥꥹѥǥ

 ν桹Υܤϥѥǥ󥰤̤åΥꥹο͵ѤꥵȤθ󥸥󡦥󥭥󥰤󤲤褦Ȥ륹ѥܥåȡץꥱ򸫤Ĥϸ̤ΤѤ졢󥸥ޤơ̤ΥꥹȤξ̤˥Ȥ󥭥󥰤Τ

 Υѥܥåȡ󥹥ȡϡApplication:W32/Spambot.AפȤƸФƤꡢPEե򥤥󥹥ȡȤspambot.plȤƥꥹȤ줿֥Ȥ³褦Ȥ롣ΥȤϡPHPܡɡեåɡåȡեåѤ͡ʥץ䤷Υץꥱ֤ʤΥȤ򸡺̤ǹ̤˥󥭥󥰤ǹΥץꥱפƤ롣

ChuckNorris (10k image)

 ֥åΥꥹפȤȥ󥰤ϡ桼ȥ꡼¹Ԥݡ̥ڡΥϥ饤Ȥ¿Υȥ󥰡ʬϥݡɸˤΰĤɤΥϥ饤Ȥ˲äƱץꥱŻҥ᡼롦ɥ쥹μ䡢åμưΥȤ˥ȥեåƳΥȾΥʤɤˤѤǽ롣

֥ե奢 󥿡ͥå ƥ 2011 ١פ

 ե奢Ρ֥󥿡ͥå ƥ 2011 ١פɲǽˤʤä

Internet Security 2011 Beta

 ١ƥϡ6֡ƱեȥѤǤեʥ롦꡼˸ոҤ٤뵡롣

 ǽΤܤθǺΤΤȹͤƤΤϡ֥ǥץ 3ץƥΥǡϥ饦ɡ١Υԥơ󡦥ƥࡢΨǯʤɤѤƤ롣

 η̡桹ΤʤѤʤΤϡʤ˥֥å뤳Ȥˤʤ롣

 ʲϡɾƤʤץȤ顢֥쥢ʡץե뤬֥åƤͻҤ򼨤꡼󥷥åȤΰϡޤɾƤʤȤФк쥢ʥ󥹥ȡ롦եѤȤߤΥޥ륦/Υʥꥪ

Internet Security 2011 Beta

 ҥ١ǤѤߤɥڡˤϡ꡼ΡȤȥեɥХåեؤΥ󥯤ǺܤƤ롣

ӥǥ - 2010ǯ5ƥ

 ܤΥ硼ȥߥå躢ǯ14ޤǤ˵äƥȥɤˤĤơä礦ä

 ͻҤ᤿3ܤΥӥǥF-Secure LabYouTubeͥ뤫F-Secure NewsΤɤ餫Ǥĺ롣

May 2010: Security Summary

  •  äΥƥ
  •  Ⱥȷȳ
  •  ɸŪȥ

ХåʥС
ǥطԤγͤ
ե奢֥С
ե奢֥С
ߥåҥåݥͥ
ե奢 CROʥƥʸˡʥإ륷󥭡
(Twitter)
(Twitter)
硼󡦥Х
ե奢 ƥɥХʥإ륷󥭡
(Twitter)
ŵ
᥿ɽ
(֥)
(Twitter)
߷ ͵
ҥ奢֥쥤 ǹ⵻Ǥ
(֥)
(ʪҲ)
ǥ ȡޥ ꥹӥ (2013ǯ3 ҥå) 󥻥ƥرءҰ
(Twitter)

(ʪҲ)
ʡ
ҥСǥե󥹸 ʬϴ
CDI-CIRTС
(ʪҲ)
͵
FFRI ɽĹ
(ʪҲ)
ʡܡ
ŷ

OWASP Japan
ɥХ꡼ܡ
Rakuten-CERT representative
(ʪҲ)
ե奢 ץȥ롼 Ĺ
ٰ β
ե奢 ץȥ롼
ݥ졼ȥ륹
ե奢
(ե奢֥Twitter)


ҥ᡼ɡ
ե奢᡼ޥ

֥˺ܤʤޥ䡢Ѽԥ󥿥ӥ塼ʾ󡢵ѲǺܤۿޤɥ쥹ΤߤϿǹ̵

ե奢֥ѣҥ
QR