ե奢֥ : byåȥ塼

ե奢֥

byåȥ塼

ɡ2012ǯȾζҥݡ

2012ǯȾˡ桹դפȤϲäμϡҤ2012ǯȾζҥݡȤˤ롣2012ǯ712ܤˤפʻϡۤܤ٤ƤޤȤƤ롣ѥɤӴĵˤĤƤûǶ̣ɷ㤷³ưʲʬΥǥ˰ܤäƤ

  •  ܥå
  •  ZeroAccess
  •  Zeus
  •  ץ
  •  Web
  •  ޥץåȥեι
  •  Х

ԡɤǤ롣

2013ǯ282012ǯȾζҥݡȤ졢ZeroAccessεεҤΤ褦ѹȤʤäA successful installation in the United States will net the highest payout, with the gang willing to pay USD 500 to 1,000 per installation in that location.ƹǥ󥹥ȡ뤵뤴Ȥ5001,000ƥɥʧѰդ륮󥰤ΤǡƱǼ褯󥹥ȡ뤵줿ȤˤꡢǹλʧۤϿˡפȤʸ[...] to pay USD 500 per 1,000 installations in that location.ƹ1,000˥󥹥ȡ뤵뤴Ȥ500ƥɥʧѰդ륮󥰤ΤǡˡפΤ褦

Exploits

Mac Revir˿ȯ

 Macޥ륦ΰ롣桹Ʊ˵ŤƤꡢե奢ΥޤϤǤݸƤ롣Revir.CΥޥʡʰڥɤˤĤƤϡŪ˲桹9˽񤤤ImulerƱ餯ϡФ򤱤ŪDzѤ줿ΤˤäƱϡ٥åȤο͸ưȤɸŪˤƤ롣

 Ǥв桹̾Τǡ󤬺𤷤ƤʤɤΤХåɥڥɤImulerȸƤФƤ뤬桹ϥɥåѥݡͥȤRevirȤƸФƤ롣ϲ桹ǯǽƱեߥȯݡɥåѤ¾Υޥ륦ڥɤȤ뤿˥ޥ뤫⤷ʤȹͤޤǤΤȤRevirImulerϾƱ˻ȤƤ롣

 桹ϡ򸡽Ф뤿ᡢǡ١򥢥åץǡȤ

 ⥪饤˷ǺܤƤ롣ܺ٤Ϥĺ

  •  Trojan-Dropper:OSX/Revir.D (MD5: 2d84bfbae1f1b7ab0fc1ca9dd372d35e)
  •  Backdoor:OSX/Imuler.B (MD5: 9ccc685f4d95403848ca24d9b8003b5b)

Q3 2012Х붼

 2012ǯ3Ⱦ̤ƸĤäХ붼Ҥ򥫥С롢ե奢ΥХ붼¸Υեߥ꡼οեߥ꡼Ȱ郎67ȯ졢ʿäΥץåȥեʤȤiOSWindows MobileˤߡޥץåȥեFinSpyȥϤΤˡʿ¤𤵤Ƥ롣

Q3MTR chart

 ܺ٤ˤĤƤϡˤ롣ԡPDFϤɤǤ롣

Q3MTR cover

ɡХ붼ҥݡ Q2 2012

 Ĺ餯ԤF-Secure Labs2012ǯ46ޤǤ˳ǧҤܽҤQ2 2012 Mobile Threat Reportפ롣

 ϰʲɤǤ롧Х붼ҥݡ Q2 2012PDF

mtrq22012 (189k image) threat_by_type (50k image)



Java MIDlet򥤥󥹥ȡ뤷ǥХɸŪȤTrojan:Java/SmsSy.A

 Java MIDlet򥤥󥹥ȡ뤷ХǥХɸŪȤ롢SMSȥϤޥ졼ǽвäƤ롣ﳲԤϡSamsungΥåץǡȤΤ褦˸SMSå𤷤Ƥ롣


samsung_update_trojan
SamsungΥåץǡȤΤΤ餻Τ褦˸å



 󥯤򥯥åȡJARեƳ¾Υ󥯡http://mmgbu[...].com:90/[...].jarˤ˥쥯Ȥ롣JARեϡƱޥ륦ʣûʥСSMSå褦ܺ٤¹Ԥ롣

 ¹ԤȡƱȥϤ3ĤSMSåʤƤͭݶֹˡ˥桼Ʊ̵롣ƥĤȼֹϰʲ̤ꡧ
- On GB to 39914
- On DF to 39914
- On HB to 33499


 ˡHOT WEB DLפȤȥȡDANCE CLUBסBEACH GIRLSסFUNNY VIDEOסGT MODELסHOT CAMפȤ5ĤΥʬव줿β롣ץ򤵤ȡOnʥƥġˡפȤȥ󥰤ޤSMSå򡢡ʥʥСˤ롣ƥĤϰʲ̤ꡧ
- HB
- MODEL
- LY
- AV
- GA


 ΥåϡǰʲΥʥС롧
- 33499
- 33499
- 36660
- 36660
- 36989



smssy_manifest
åƥĤȼֹξܺ٤ޤե



smssy_picladies
SmsSy.AפѤ



 ƱȥϤ̤ΥץʬϤȤۤʤ륳ƥĤȼֹ椬ƤƤ뤳Ȥʬä


smssy_manifest2
SmsSy.Aפ¾Υץˤϰۤʤ륳ƥĤȥʥСƤƤ



smssy_picmtv
SmsSy.AפˤѤ줿ۤʤ



 桹ΤURLŬڤ˺ꤷTrojan:Java/SmsSy.AפȤƸФƤ롣

Sha-1: 75a91ac99cb5bc2a755d452393d29fa66a323c3f
Sha-1: bca72058af2a7ddb9577ecb9a61394a31aea5767



Blog post by - Jordan and Raulf

JavaѤ뤵ʤMacޥ륦

 CVE-2012-0507פѤ뿷Macޥ륦ΰ˴ؤ𤬡轵夷Javaȼϡ60ʾMacΤFlashbackѤΤƱΤΤ

 ǽοʶҤTrend Microο͡ˤʬϤ줿MacJavaץåȤϼºݡCVE-2012-0507פѤСڥɤAlienVault Labsȯʿ͸ʸNGOФɸŪǻѤ줿ˤΤƱޥ륦

 ϡǽΤϴ˿ޥ륦ΰǤ褦˸롣줿ΥץǡƱޥ륦Backdoor:OSX/Olyx.CפӡBackdoor:OSX/MacKontrol.AפɥåפΤѤ줿MS09-027/CVE-2009-0563פѤƱWordˤɥåפ줿Ȥ餫ˤʤäAlienVaultˤ𤵤줿Τ

 ɤΥޥ륦⸽ߥƥ֤ʤ褦ǡESETKaspersky줾¬Ƥ褦ˡޥ˥奢ǥȥ뤵Ƥ롣ɤƱΰդJava饹ɥåѡݡͥȤѤ롣MD5: 5a7bafcf8f0f5289d079a9ce25459b4b

 ե奢 륹ϤζҤBackdoor:OSX/Olyx.BפӡBackdoor:OSX/Sabpab.AפȤƸФ롣

MD5: 78f9bc441727544ebdc8374da4a48d3f – Backdoor:OSX/Olyx.B (̾Lamadai.A)
MD5: 40c8786a4887a763d8f3e5243724d1c9 – Backdoor:OSX/Sabpab.A (̾Lamadai.B)
MD5: 3aacd24db6804515b992147924ed3811 – Backdoor:OSX/Sabpab.A

 ޥ륦ΰϡ٥åȴϢNGOФɸŪǻѤƤꡢäŪMac桼֥󡦥磻ɡפ뤳Ȥ̵⤷ʤMacѤƤ͸۸ΤʤĥꥹΨۤʤ롣ޤƤʤʤ顢Mac˥륹򥤥󥹥ȡ뤹٤

̤ѥåJavaȼѤMac Flashback

 CVE-2012-0507סJavaȼˤѤ롢FlashbackοʰMacޥ륦ˤȯ줿桹ϤФ餯Τ褦ʤȤͽۤƤ

Flashback.K

 Oracle2ȼ˥ѥåƤ륢åץǡȤ꡼WindowsѤ

  — AppleOS XΥåץǡȤʤޤ˥꡼Ƥʤ

 Flashback󥰤ϥץȡåȳȯκǿξɤäƤ褦轵Brian KrebsBlackholeץȡåȤκǿǤˡCVE-2012-0507ץץȤȤ߹ޤ줿ȤƤǽǤϤʤ̤ǧǤϤΤΡ֤ޤѥåƤƤʤJavaοʷ١פФ롢̤ΥץȤѲǽȤΤ

 äơ⤷ޤJava饤ȤߤƤʤΤʤ顢줬ޤˤĺMacJavaߤˡ˴ؤ륤󥹥ȥ饯ϡ桹εǥåߤ

 Flashback˴Ƥ뤫ɤåˡ˴ؤΥ󥹥ȥ饯ŬѲǽΰǤϡ桼ΥۡեǺ롢̤ΥåץǡݡͥȤ롣ǥեȤǤϡ~/.jupdateפȤƺ롣

 б°ꥹȥե졢桼󤹤뤿Ӥ˼¹Ԥ롣ǥեȤǤϡ°ꥹȤϡ~/Library/LaunchAgents/com.java.update.plistפȤƺ롣

Flashback.K

Flashback.K

 Υե̾ϴƥˤۤʤ뤫⤷ʤϡץȤͿ밭դWebڡˤǽ

Flashback.K

 ܺ٤ˤĤƤϡե奢ˤFlashback.Kפĺ

MD5: 253CAE589867450B2730EF7517452A8B

MS12-020ȼѤġ

 MicrosoftMS12-020󤬸ư衢Remote Desktop ProtocolRDPˤȼѤ褦Ȥ¿ä轵桹ϴϢץȤäɸŪȤRDPӥߤ뤳ȤŪȤRDPKill by: Mark DePalmaפȤġǤ뤳ȤȽ

RDPKill

 ƱġVisual Basic 6.0ǽ񤫤Ƥꡢץʥ桼󥿥եͭƤ롣桹Windows XP 32-bitWindows 7 64-bitưޥǥƥȤ

RDPKill

 Windows XP 32-bitΥޥWindows 7 64-bitΥޥ⡢ɤ⥵ӥ˸DoS˹αƶӥϥå夷Υ֥롼꡼BSoD˾֡Windowså夷˸륨顼꡼ˤ

RDPKill BSoD

 桹ϤΥġHack-Tool:W32/RDPKill.AסSHA-1: 1d131a5f17d86c712988a2d146dc73367f5e5917ˤȤƸФƤ롣

 RDPKill.Aפ¾ˡ褦ʥġMetasploit⥸塼򥪥饤ǸĤ뤳ȤǤ롣餬ǽǤȤȤϡѥåƤƤʤRDPФϡΥġߤƤ뤫⤷ʤԤˤꡢưפDoSɸŪȤǽ롣

 ƥ˥ѥåƤƤʤä˥ޥRDPӥ¹ԤƤˤϡǤ᤯ѥåƤ褦롣

Threat Solutions post by — Azlan and Yeh

MacFlashbackϤ뤫

 ˡFlashbackȥϤˤäMac˾㳲ʤˡ򤴾Ҳ𤷤Flashback򸫤Ĥˡ˴ؤ󶡤롣

 ʲΥƥåפɤ򤹤ˤϡFlashbackˤĤƤ¿ƤɤOS Xޥ륦եߥǡWeb֥饦ˤɽ륳ƥĤ롣ΤˡƱޥ륦MacΥ֥饦Ѥ뵡ǽѤ롣ü뵡ǽϰ老Ȥ˰ۤʤ뤬̤CFReadStreamReadCFWriteStreamWriteޤޤ롧



 ɸŪȤWebڡѹϡ⡼ȥФɤ߽Ф륳ե졼˴ŤƷꤵ롣ʲϥե졼󡦥ǡ



 ǥɤȡɸŪȤ줿Webڡ֡ˤȥ󥸥Ȥ줿ƥġʲˤʬ



 ǽϤϻ¾塢򤢤ΥХåɥˤ롣ΤȤȡƱޥ륦ǽ顢Flash Player󥹥ȡΤդ򤷤ƥ桼ޤȤ¤顢FlashbackȸƤФƤ롣ʹߤϿʲƤꡢǶΰǤϳȻ뤿ᥨץȤȤ߹߻Ϥ᤿䤬٤ƤǡʤȤGoogleɸŪȤƤꡢϼºMac QHostμοʲǤϤʤȹͤä

 ǽѤơFlashback˹ԤΤϥ֥饦ˤɤ뤳Ȥ

 DYLD_INSERT_LIBRARIESĶѿΩĤȤ



 ̤˴ˤ2ढ롣1δϡƱޥ륦¤ĺݤ롣2ΰFlashback.Bפ⤷ϾΥ꡼󥷥åȤΥפδǤϡDYLD_INSERT_LIBRARIESĶѿɸŪȤ줿ץꥱä˥֥饦ΥƥȤˤΤɲä롣ΰSafariFirefoxɸŪȤƤ롣ǶΰǤSafariΤߤɸŪμδ˥桼ŤΤϡ񤷤ǽ롣ƥबꤷƤ뤿

 2ΥפϡƱޥ륦˴¤̵롣ǽΰFlashback.AפΥפδǤϡDYLD_INSERT_LIBRARIESĶѿ桼ΥƥȤɲä롣Ʊޥ륦桼ưƤΥץꥱ˥ɤȤȤ̣Ƥ롣κݡߴΤʤץꥱ˵륯å夬ΤǡƥϤϤ뤫԰ˤʤ롣褹뤿ᡢǶΰϿե륿ݡͥȤƳƤ롧



 嵭Ǥϡե륿ݡͥȤϥץSafariǤ硢ᥤ󥳥ݡͥȤɤΤߤʥ꡼󥷥åȤǡWebPoפ̵뤹뤳ȡϤ餯SafariǤаǤWebProcess򡢥ޥ륦Ԥץߥˡ

 ǤϡΥǤϤɤΤ褦˴ꤹΤǤñʤΤϡ֥饦DYLD_INSERT_LIBRARIESĶѿΥåTerminalǰʲΥޥɤѤɤ

  •  defaults read /Applications/%browser%.app/Contents/Info LSEnvironment



 嵭ϡFirefox꡼Ǥ뤳Ȥ̣Ƥ롣ƤСΤ褦ʤΤ򸫤ˤʤ



 ֤ǰϤޤ줿DYLD_INSERT_LIBRARIESͤդߤե륿ݡͥȤǤ硢ᥤ󥳥ݡͥȤꤹΤˤ줬ɬפ

  •  grep -a -o '__ldpath__[ -~]*' %path_from_previous_step%



 ֤ǰϤޤ줿եFlashbackեʤΤǡդߤۤȤɤΥ桼DYLD_INSERT_LIBRARIESĶѿ̵Ȼפ

 åפǷ̤ʤСϤʤΥƥΰϡե륿ݡͥȤͭƤʤȤ̣Ƥ롣

 󤬼˥åΤϡ2ΥפδƤ硢ʤΥ桼DYLD_INSERT_LIBRARIESĶѿåȤȤ

  •  defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES



 ̤ʤСΥפδϵƤʤȤ̣Ƥ롣

 ե륿ݡͥȤСᥤ󥳥ݡͥȤ򸫤ĤΤˡޤʲΥޥɤѤɤ

  •  grep -a -o ' __ldpath__[ -~]*' %path_from_previous_step%



 ץϤɤ뤫桹äߤĺС¾AV٥ȥץ붦ͭۤΤǡߥ˥ƥνˤʤ롣

 ƥफ饵ץݡDYLD_INSERT_LIBRARIESĶѿɬ뤳ȡʤȡ֥饦⤷Ϲ˰ȤˤȤ󡢥ɤʤ⤷ʤ

 1ΥפδǤϰʲѤߤ

  •  sudo defaults delete /Applications/%browser%.app/Contents/Info LSEnvironment
  •  sudo chmod 644 /Applications/%browser%.app/Contents/Info.plist



 2ΥפδǤϰʲѤ뤳ȡ

  •  defaults delete ~/.MacOSX/environment DYLD_INSERT_LIBRARIES
  •  launchctl unsetenv DYLD_INSERT_LIBRARIES



 ǶFlashback˴ؤܺ٤ϡ桹Trojan-Downloader:OSX/Flashback.IβǥåǤ롣

Ǥϡ
Brod

ܲMacޥ륦

桹ǸMacΥޥ륦ˤĤƽ񤤤Ƥ餺֤ˤʤΤǡ˵Ƥ뤳ȤˤĤơɼԤγ˺ǿ󶡤ɤȹͤǯ桹ӾˤMacǥȥϤȤܤܽҤϤޤХɥΰǤ뤫ɥΥХʥʤΤ¬ƤߤǤϡ郎ȯ졢ܳŪʥץꥱǤꡢⴰƤ뤳Ȥ餫ˤʤäƤ롣

 ԤϤΰversion 1.0סʥȥ륨ǥǡFILEAGENTVer1.0סˤȸƤǤ롣

FILEAGENTVer1.0

 䤬ʬϤץϡIrina ShaykΥͥ/ѤƤ뤬ϤɤFHMSouth Africa˻2012ǯ3椫줿ΤΤ褦ΰդ륢ץꥱХɥϡե륿פ桼ȤȤԤơƱ狼줿¾βȶˡ֥եŸ롣

FHM Feb Cover Girl Irina Shayk H-Res Pics

 ץơ¾˲鿷ϤʤХåɥڥɤƱC&CФѤƤ롣ƱФϸߡʼɮ˥ƥ֤οC&CФޤESETο͡Ƥ롢ΰƱIPɥ쥹򼨤Ƥ뤳Ȥդ뤳Ȥפ桹ϤΥФCERT-FI𤷤ޤС餬طɤΤǤ

 桹ϿʤΰTrojan-Dropper:OSX/Revir.CMD5: 7DBA3A178662E7FF904D12F260F0FFF3ȤƸФƤ롣

Ǹ—¦ˤҤǤ롢⤦ĤΤ꿼OS Xޥ륦Ҥ롣FlashbackȥϤϽᡢRevirƱ˸줿Τߤ⥤󡦥磻ɤϥץȤѤơ桼ȤΥ󥿥饯̵ǡƥ롣ѤƤΤϸŤJavaȼCVE-2011-3544CVE-2008-5353ˤϢ椬ڥ졼򥢥åץ졼ɤѥåƤƤʤȼϤʤ顢OS Xư򸫤ˤʤ뤫⤷ʤ

 εǡFlashbackꤹˡܽҤͽδ֡򤱤Ǥưפˡϡ֥饦Java򥪥դˤƤȤ桹ĴˤСWebݡۤȤɤΥ桼JavaɬפȤƤʤ餫ͳǡȤХ饤󡦥Х󥭥󥰤ʤɤJavaɬפʤСɬפʻˤ뤳Ȥƽλ顢ޤդˤ뤳ȡ

 SafariǤϡĶΥƥ֤ǡJavaͭˤפΥåϤɤ

Safari, Java settings

 뤤ϡSnow LeopardLionϥǥեȤǤJavaܤƤʤˤ顢ץꥱ󡢥桼ƥƥJava˹ԤȤJava򥪥դˤǤ롣̥֤Ǥ٤ƤΥåϤ

Java Preferences

Ǥ
Brod








Trojan:Android/OpFake.Dפե졼ե򥳡ɲ

桹ϥޥ륦¾Υڥ졼ƥ󥰥ƥо줷Android˰ܿ륱ɤƤ롣ʲϤξʥȥϤ

 OpfakeSymbianWindows Mobileǡǽȯ줿ǶAndroidǤǤϡƱȥϤϡʤޤOpera MiniץǤ褦˸ĥѡߥåΥꥯȤϡSMSå뤳Ȥ:

Android OpFake, permission

 Ʊץʲ桹ϡTrojan:Android/OpFake.DפȤƸФƤˤϡκݥå뤳Ȥʬä

Android OpFake, SMS

 ΥǤ̾饹˥ϡɥɤ줿SMSå򸫤ϥåƥĤֹϡconfig.xmlץե¸졢󥳡ɤ롣ʲʸɤ

Android OpFake, garbled code

 Υȥ󥰤base64ǥǥ󥰤Ѥƥǥɤɤ߽ФǽȤʤꡢ¹Ի˥åץˤ뤳Ȥ򼨤Ƥ롧

Android OpFake, decoded code /><br /><br /> AndroidǡSHA1: 4b4af6d0dfb797f66edd9a8c532dc59e66777072ˤϡΥե졼ե򥨥󥳡ɤopFakeΡפѤǤꡢΤǤϤʤϡʬϤ饳ɤ䥢򱣤ᡢޤޤ󥳡ǥ󥰤¾Υƥ˥å¾ΥץåȥեĹǯɸäΡˤѤ롢Androidޥ륦θߤΥȥɤƤϤޤäƤ롣<br /><br />ThreatSolutions post by — Irene<br /><br /><div style=
ThreatSolutions post by — Irene

丶ʸؤΥ

Androidޥ륦ŻƩѡ ۤɤǤ

 䤬ĤΤ褦Androidޥ륦ʬϤԤäƤݡΥץΥ饹⥸塼ˤäܤ̤ƤȡʲΤ褦ʥɤ򸫤Ĥ

fig1_finding_tEXT_chunk (4k image)
1




 ǯȾPortable Network GraphicsPNG˲եޥåȡä˥ƥȾĥեɤˤĤơܺ٤˥åƤɤ򸫤ƤȡʤΥץꥱPNGեΡtEXtץ󥯤¸ߤƤ뤫ɤåɬפΤȤȤˤĤơ˵ǰ

 ϥɤܤ̤³ꥳɤեꤹ뤿ᡢɤǥ뤵뤫ȯ

fig2_method_checking_tEXT (85k image)
2



 ƱɤΤʬϡե뤬꥽̾icon.pngפѤץꥱȥХɥ뤵Ƥ뤳Ȥ򼨤Ƥ롣줫餳βϳ졢PNG󥯡ʿ1ˤå륳ɤ뤵ˡؤ롣

 APKѥåΥ꥽򸡺뤳Ȥǡ褦̾Τ3ĤΥե뤬롣tEXt󥯤νȯˤ̣äƤʤᡢϤHEXӥ塼ФեκǽtEXt󥯤Ĵ٤ϳΥѤƱΥХʥǡޤǤʲϡβɽȡHEXӥ塼ǥ󥰤κݤˤɤ뤫򼨤Ƥ롣

fig3_tEXT_chunk_marker (161k image)
3



 βϡץꥱΥȤƤѤƤ롣äơǥХؤΥ󥹥ȡ⥤󥹥ȡ⡢ɤܤˤ롣

fig4_app_icon (139k image)
4



 ǡ3ΥǡϻˤϤۤȤɰ̵̣tEXt󥯤Хʥǡ⤷ɤʤȥ󥰤ĤΤ̤ǤϤʤǿ1λĤΥɤʬϤ³ʬϤʬäΤϡ줬3α줿ǡɤߡϡɥɤ줿text streamʡ֥סˤФƥӥåȤȤXOR黻򡢤ɤΥХɤ߽ФǤ»ܤ뤳Ȥ

fig5_hidden_data_decryption (39k image)
5



 PythonɤʤΤǡ3鱣줿ǥɤ뤿ᡢʲΤ褦ʾʥץȤΥ르ꥺϡ5ΥɤʬäȤ˴ŤƤ롣ץȡʿ6.aˤ¹Ԥ塢äȤˡɤ߼ǽʱñȿĤä

 Υץ졼ƥȾ󤬡ץꥱФƲ̣ΤϡȤƥϥåꤷʤǡΥǡʿ6.bˤPNGեʿ3ˤtEXt󥯥ǡ鱣ᡢŻƩѤƤ뤳ȤʬäŻƩθ̩򸫤ȡΥץ뤬ŻƩŪǤȹͤΤɤϡ;Ϥ롣PNGեΥ󥯤ΰĤǡ󥳡ɤ줿ǡΥץߤ˲᤮ʤ

fig6_decrypt_hidden_data(79k image)
6



 5λĤΥɤʬϤ³ȡ鱣줿ʬŪʥ꡼󥷥åȤϰʲ̤ˤץꥱμפưʤʤֹͭSMSȤȡˤ򥵥ݡȤ뤿˻ѤƤȤ¤˶ǤȤʤä

fig7_hidden_info_screenshot (125k image)
7



 ΥɤȯۤSMSڥ졼Τᡢºݤ˻ѤƤ뤳ȤΤ뤿ᡢAndroidǥХߥ졼ǥץꥱμ¹ԤԤäƤǤϡФSMS٥ȤϿ졢6.bΥǥɤ줿ǡȤ褯ܺ٤줿Υ٥Ȥϡ䤬˥󥹥ȡ뤵줿ץꥱΥᥤUI顢NextץܥҥåȤü˵ä

fig8_outgoing_sms_event (65k image)
8



 Υץꥱsha1ϡac118892190417c39a9ccbc81ce740cf4777fde1פǡTrojan:Android/FakeRegSMS.BפȤƸФ롣


Threat Solutions post by ? Jessie

----

2012ǯ130ŻƩˤĤƤ˾ܽҤ뤿ᡢȥȥƥȤ˽äƹ

Androidѡߥå:ץΤᡩΤᡩ

 AndroidץꥱѥåAPKˤʣΥ⥸塼ޤळȤǽİʾΤ⥸塼ϡSDK⤷ʤߡ¿AndroidȯԤ̵Ǽʬãʤ桼󶡤뤿ᡢ⥸塼ѤƤ뤿ᡢǤϤϤʤɤ뤳ȤǤϡץϥ꡼⥸塼뤬路Ϥɤ

 桼ᥤΥץФƥѡߥåͿƥ󥹥ȡ뤷ʵƤѡߥåˤĤơɤ򤷤ƤꡢˤƤȲꤹˡ桼Ϲ⥸塼ˤƱѡߥåѤ뤳ȤĤ뤳Ȥˤʤ롣ޡѡߥåϥᥤΥץꥱǤϤʤ⥸塼ˤäƤΤ߻Ѥ롣

 ߡAndroidץϥᥤΥץ꤬Ѥѡߥȡ⥸塼뤬ѤѡߥåȤ̤ʤƥƥ˴ؤƤϡ桼ȥʥꥹȤˤȤäơϤޤˡɤ̯ȤСʲϸAndroid Marketɤ줿򥵥ݡȤ륢ץΥѡߥå󡦥֤Υ꡼󥷥åȤǡѡߥå˴ؤ˰Ū񤫤Ƥ롧

android_market_permission (18k image)

 ᥤΥץȹ⥸塼ɤΤ褦˥ѡߥåѤѡߥå󡦥֤С桼ˤȤäƤʬ䤹Ϥʤ뤤ϤɤΤϡ⥸塼ѤΥѡߥå󡦥֤ȤСᥤΥץ/⥸塼뤬򤹤뤫桼ˤʬ䤹ʤꡢ󥹥ȡ³ɤӤ䤹ʤ

 躢Ȥ򼨤㤬äᥤΥץϥ꡼ä⥸塼꤬äSpyware:Android/AdBoo.Aפλϡ桼ε̩⡼ȥФƤ

 ߡʬι𥵡ӥϡ֥åȤʤä׹󶡤뤿ᡢäμ㴳ξɬפȤƤ뤬AdBooDz桹ϡƱ⥸塼뤬ޤ¿ξ׵ᤷƤȹͤƱ⥸塼뤬ŪˡᥤΥۥȥץΥѡߥåͭƤᡢ⥸塼֥åᥤΥץĤˡ̵

 ץ˥ѡߥåͿȡ⥸塼˿ʤळȤǤ롣ιɽʤ顢ɤ⤷Υ⥸塼뤬路롼ޤʤ顢ϤޤɤȤǤϤʤAdBooΥǤϡ⥸塼äܺ٤뤬ʲΥ꡼󥷥åȤǤΤĤĴƤ롧

spyware_adboo_leak_1 (74k image)

 ưʲбSmaliɤǡξ󤬼ºݡХʡ󶡤˼Ƥ롧

spyware_adboo_smali (35k image)

 ߡƱץ꤬ޤǤ뤫ɤ뤤ϥ󥹥ȡ⤷ϺˡɤΤ褦ʹɽ뤫ϤäȤʬʤγȯԤϥޥ˥奢ǡץ꤬ޤळȤƤ뤬ƤγȯԤۤɤȤƤ櫓ǤϤʤץֹ꤬פ⤷ϡ̵ֹפȤϤäɽƤС桼ˤȤäƤǤϤʤ

 ƺǽŪϡƤγȯԤʬãʤɽ빭Υפ򡢥ȥǤ櫓ǤϤʤȤ⥸塼̾ɥѡƥιץХ顢ˤʣΥӥޥƥꥢä뤿ᡢɽ빭Υפ򥳥ȥ뤹뤳Ȥϡ갷ˤʤäƤ롣ǰξ硢ҤɤѤΥץ͸ιɽ⤢褦


----

ThreatSolutions post by Jessie

ǯδꤤ - ǡդ

 2011ǯȤƤ롣ꥹޥ᤮ǯդĤĤ뤿ᡢ¿Τ񤤤θդ䵨ΰʤɤƤ롣Ԥʾ٤ơ˻ä褦ȷᡢƱˤäȤǡԤȷդ褦

 Spyware:Android/AdBoo.AפϡΤ/ͥ/򤤥åοͤ褦ˤץΰĤ¹ԤȡƱץϿǯδꤤȤͧ𡢰𡢥硼Ȥä͡ʥƥʬव줿ƥȥåΥꥹȤɽ롧

AdBoo text

 桼åΰĤ򤹤ȡƱץϥ桼Ϣ衢Խ󥻥Ȥιư֤褦ܥåɽ롧

AdBoo message

 Ϣ襪ץ򤹤ȡץ¸ƤϢǡɤ߹⤦Ȥ롣餯ƱץϥåïΤΤɬפΤ

AdBoo choices

 桢桹ΥƥѷäˤϢ褬¸ƤʤäᡢƱץϤλDzʤä

 ʵΡϢѤƺƥƥȤȡƥȥå줺桼ϡԡפȤåȤܥåФä

AdBoo sending fail

 桹ϤƱץ꤬̤ΤȤ򤷤ƤΤ˵ŤϢ襪ץ򤹤ȡƱץϰʲξ򤳤äüΤ

1üΥǥ
2AndroidΥС

4˹ݰưֹּIMEI

 줿ϼ˥⡼ȥФ롣

 ʤߤˡ桹μ긵ˤAdbooץξ򸫤ȡTrojan:Android/Zsone.AפƱȯԤΤΤǤ褦

AdBoo:

AdBoo SHA1

Zsone:

Zsone SHA1

Threat Solutions post by — Irene

Trojan:Android/FakeNotifyפåץǡ

 Ϥ˲桹ͭݶⷿSMSȥϤ˴ؤǺܤTrojan:Android/FakeNotify.AפȤƸФΤߡƱȥϤåץǡȤ졢ʬϤȸФˤѹäƤ뤳ȤʬäƤ롣

 ̾񤫤ʬ褦ˡСƱȯԤΤȥϤŪʤդޤѹ̵ǥ󥰥ץϤʤѤäƤꡢŪϥġʤɤԤΤ˽ʬ

 㤨ʬ桢ϥꥸʥȸԥСSMS롼ӤΤꥷץʥǥ󥰥ץʥߥåˤʤäƤ뤳Ȥ˵Ť

 FakeNotifyפΥꥸʥСǤϡ롼Ϥ줬Ǥ뤫˴ñˡɤפȤǤñˡǼƤ

FakeNotify, original send
FakeNotify.A

 СϡʥꥹȤɤɤפȤ񤷤ȤȤˡƱɸã뤿JavaReflection/Dynamic InvocationǽѤƤ롣

 ȯԤϡȤΥ󥳡ǥ/ǥǥ󥰥르ꥺѤơȥ󥰰𤵤뤳ȤˤꤵʤƤʤϥץʴŪʰŹ˲᤮ʤˡʲǥɲ줿ե򸫤뤳ȤǤ롧

FakeNotify, update encoded
FakeNotify.B, SHA1: df866cf4312cf9c929a9a7dc384eebb19d2b2c2d

 ǥ󥰥ץѹϡʬŪϥġưפ̵뤳ȤǤ롣

нʬ桢Windows LoadLibraryGetProcAddress combo APIؿJava ReflectionΤĤεǽȤ˵Ť¾APIؿɥ쥹Windowsˤӥ饹⤷Object handleΥ᥽åɡJavaˤ˴ؤƤϡȤⳫȯԤǶˡ⤷ϴؿ򥳡뤹뤫¹Ԥ뤳Ȥǽˤ롣

 ˤ衢AndroidFakeNotifyСʬϤưפˤ뤿ᡢϥץPythonץȤɲ줿ȥ󥰤Υ󥹥󥹤򡢰դ륢ץꥱǥǥѥ뤵ƤJavaƤʿʸΤؤ

 ѥå󥰤θ塢SMS롼class SmsManagerȤgetDefault method/functionΥϥɥ󥰤θ塢SmsManager classsendTextMessageե󥯥Ѥ뤿ᡢư/뤵뤫Ŭڤ˽ɬפ롧

FakeNotify, update decoded

 Τˡ䤬Androidޥ륦ˤJava ReflectionǽѤΤ򸫤Τϡ줬ƤǤϤʤȥ󥰤ɲʣǤϤʤAndroidޥ륦γȯԤʬãΡʡפǿˤФʤ褦ˤ뤿ᡢεѤ򼡡Ŭåץ졼ɤˡΤʤȸ롣

Threat Solutions post by — Jessie

ǽʤAndroidݶⷿSMSȥ

 桹ϲݶⷿSMSֹSMSå褦ȤAndroidȥϤȯϤʤۤʤäƤΤϡΥȥϤưʤȤȤ

 ȥϡʡTrojan:Android/RuFailedSMS.AפȤƸФƤˤϡʲΥѡߥåѤ롧

RuFailedSMS, permissions

 ưդΤ륢ץꥱϤ줾졢ʿ͵ΥץΤ褦˻פ˥ѥåΥɤ򥪥ե͡ʥץꥱΥ󥹥ȡΤդ򤹤롧

RuFailedSMS, main UI

 ֥եץץꥱˤϰʲΤΤ롧

  •  Add_It_Up
  •  Advanced_Launcher_Lite
  •  AmazingMaze_supLitesup
  •  Analog_Clock_Collection
  •  Animal_Sudoku
  •  AnySoftKeyboard
  •  AnySoftKeyboard_Slovak_Language_Pack
  •  AppInventor_Toggle
  •  Arrow_Caz
  •  Astronomical_Flashlight
  •  BentoCam!
  •  Bimaru_-_Battleship_Sudoku
  •  BlackJack
  •  Carve_a_Pumpkin_supLitesup
  •  Chinese_Chess
  •  Christmas_Ringtones
  •  Coloring_pages
  •  Contact_Finder_supLitesup
  •  Converter
  •  Countdown_Widget
  •  Crayon_Ball
  •  Cyan_aHome_Theme

 ʤȤˡɤªʤä㳰뤿ᡢƱȥϡSHA1: 0d2d3317c6ca1a9812d357741f45af6bb360d89cˤϡΰդưλå夷ߤƤޤ

RuFailedSMS, crashed

 桹100ĶȥϤΥԡȯƤ뤬ʤοŪ˹٤ʤΤǤϤʤΥԡϴŪƱɤѤƤ뤬ۤʤѥåѤ˰ۤʤ륳ե졼˲¤Ƥ˲᤮ʤΤ.

 ȥϤϡɥѡƥAndroidޡåȤȯƤꡢ٥롼ե󤪤ӥХΥ桼ɸŪȤƤ롣

 ΥȥϤϥå夷ǽʤˤƤ⡢դ롼Τᡢޤԡ̤˽вäƤ뤿⤢äơФϹԤäƤ롣

Threat Solutions post by — Jessie

AndroidޡåȤκץ

 ޥ륦κԤˤ⡢͵Υץѥå̾ӥѤΥޥ륦AndroidޡåȤȯɽȤץ饯ƥƤ褦ʥץ̵/饤ǤǤ뤫Τ褦ʵɽΤȡΤʤ桼ޥ륦ɤǽ롣

 Logastrod and Miriada ProductionˤѤ줿ץ饯ƥƱ͡Eldar LimitedCut the RopeפȡAssassin's Creedץץ̵Ǥޥ륦ͣAndroidޡåȤǥץ륵ԤäƤ⡢Cut the Rope̵Ǥη̤äʤȤ餯AndroidץåȥեǤñ̵Ǥ¸ߤʤΤiOSѤ̵Cut the Rope Liteפ¸ߤ롣ǥ桼𤹤뤫⤷줺άεˤʤǽ롣

Eldar Limited, Android Market

 GoogleΥץݥꥹϤκȯAndroidޡåȤ᤯饢ץAppBrainAndroidZoomˤϤޤǺܤƤ뤬ϥ桼򡢤Ǥ˥ץ꤬ƤAndroidޡåȤƳ

EldarLimited, AppBrain

EldarLimited, AndroidZoom

 桼ˤϡץͭǤ򸡺ȯ̾ܤȤƥåפΩĤͭǤ̵Ǥ̾ΤפСϰʥץǤΨ˹⤤ʤСɤƤϤʤ

Trojan:Android/SMStado.AפȡTrojan:Android/FakeNotify.A

 桹ϡĤAndroidݶⷿSMSȥϤˤ⡢ɤΥ桼ɸŪˤΤ

 ǽˡTrojan:Android/SMStado.ASHA1: 718b8fbab302b3eb652ee0a5f43a5a2c5c0ad087ˡפˤĤơ

 ̤̾ꡢ˴ؤǽΥҥȤȤʤΤϡꥯȤѡߥå

trojan_android_smstado_a_permission_1 (80k image) trojan_android_smstado_a_permission_2 (64k image)

 ¹ԤȡƱȥϤhttp://[...]6.antiddos.bizФưʲξܺ٤꡼롧

  •  ݰưֹּIMEI
  •  ѥå̾
  •  ֹ
  •  üǥ

trojan_android_smstado_a_code (54k image)

trojan_android_smstado_a_run (67k image) trojan_android_smstado_a_run_2 (58k image)

 ξܺ٤ϡץꡦѥåres\rawեˤ¸롣

 ˡƱץ꤬¹Ԥݡ桼꡼Υܥ򥯥åȡSMSåꤵ줿ݶֹⷿ롣ޤǤΤȤ٤Ƥֹ椬ι̥ɡä˥⥹泌ꥢΤΤ¿ˤѤƤ롣SMSåˤϤ٤ơʲΥƥʸ󤬴ޤޤƤ롧

  •  hm78929201647+1188+51+0+1+b92be

 ΥȥϤϥ⡼ȥȤ顢love_position_v1.5.0.apkפȤ̾Υѥåɤ롧
(SHA1: 9cb4cc996fb165055e57e53ab5293c48567e9765)

trojan_android_smstado_a_download (73k image)

 桹ΥƥȤǤϡϥ顼Τᡢɤ줿þǤϥץ뤬ưʤä

trojan_android_smstado_a_download_error (22k image)

 ɡѥå̤Ρ꡼ʥƥõΩʬϤȤϵưκݡХå饦ɤǰդ륵ӥⳫϤȤ㤤Ϥ뤬Trojan:Android/SMStado.AפȤۤȤƱդޤ򤹤뤳Ȥʬä

trojan_android_smstado_a_service (96k image)

 Υޥ륦ϡTrojan:Android/FakeNotify.Aפ

 ϥåץǡΥץꥱʲϥץ꤬Ѥѡߥåȡü˥󥹥ȡ뤵ݤͻҤ

trojan_android_fakenotify_permissions (83k image) trojan_android_fakenotify_downloaded (114k image)

⡧Stados.AסFakeNotify.AפΤɤƱ̾ʧѧߧӧܧѡˤGoogle TranslateˤСϡ֥󥹥ȡפȤ̣ץ̾դΤˡޥ륦ΰ֤δط򼨤⡢ŪʸդѤ줿ȤȤƤΤ

 ä󥤥󥹥ȡ뤵졢¹Ԥȡ桼ζ̣Ҥ˿͵ΤХ륲̾ѤơץꥱΥɤ˥桼εĤåɽ롧

trojan_android_fakenotify_download_ui (36k image)

 nextץܥ򥯥åȡХå饦ɤFakeNotifyľ3ȤSMSå롣åϡβݶֹⷿ졢ʲΥեޥåȤΥƥʸޤǤ롧

  •  [24 digit string].1/316623

 Ѥ줿SMSξܺ٤ϡץꥱ󤫤ޤ줿ǡ١եͳ褹롣

 ¾ǥ桼ץꥱΥɤ򸫤뤳Ȥ̵ꡢ̤Υ꡼ɽ졢դΤǤǽΤ롢ä¿Υץ󶡤WebȤƳ

trojan_android_fakenotify_download_agreement (32k image)

FakeNotifyץSHA1ϥå塧

  •  28fdc27048d7460cda283c83c1276f3c2f443897
  •  f2eb2af5b289f771996546f65a771df80d4e44da
  •  cdc4b430eb6d6e3a9ce4eb4972e808778c0c7fb1

ThreatSolutions post by — Irene and Jessie

DevilRobberפΥåץǡǤо

 桹ϡBackdoor:OSX/DevilRobberפΥåץǡǤȯˤĤƤǺܤƤ롣

 ΥåץǡǤϡʥץꥱ˵뤿ᡢΤΤƱͤΥƥ˥åѤƤ뤬ϡPixelMatorפȼΤƤ롣

Pixel_mator

 Ʊޥ륦Ρdump.txtץեˤСκǿǥХåɥϡVersion 3v3ˡפȤƤ롣

DevilRobber v3

 DevilRobberV3פ˸礭ʰ㤤ϡۤˡۤʤꡢֽ跿ΡץǤȤˤ롣

 桹ʬϤDevilRobberV3ץץ1c49632744b19d581af3d8e86dabe9de12924d3cˤϡFTP ServerӥץХХåɥ󥹥ȡ顦ѥåɤFTP

 󥹥ȡΤˡƱޥ륦ϥϡɥɤ줿桼̾ȥѥɤ3ĤFTP URL뤬ϥץऽΤΤ˥ɲƤ롣ѥåϡbin.copפȤ̾ǡFTPСΥ롼ȥե¸롣

DevilRobberV3 downloader

 ˡѹƤ뤳Ȥ˲äDevilRobberV3פǤϾץȤ˰ʲѹ롧

  •  Τ褦˥꡼󥷥åȤȤʤ
  •  Τ褦LittleSnitchʥե륢ץꥱˤ¸ߤåʤ
  •  ۤʤݥ̾Ѥ
  •  륳ޥ
  •  1ѥɥƥĤAgileBitsΥѥɥޥ͡
  •  ϥƥե

 BitcoinåȥƥĤ褦Ȥ롣

Threat Solutions post by — Wayne

DroidKungFuפåץǡȹ

 桹Ϻʴ٥ѤȤܤDroidKungfuץץ˴ؤñƤ

 «̤ꡢ굻Ūʾܺ٤򤴾Ҳ𤹤롣

DroidKungFu, Chinese market

 桹ʬϤƤ륢ץꥱϡcom.ps.keepaccountפȤ̾ǡΥƥĤ򤶤äȥåȤ󡢻ΤȤ餫ˤʤä

 ǽ˸ȤꥸʥΥץꥱSHA-1: 5e2fb0bef9048f56e461c746b6a644762f0b0b54ˤˡDroidKungFuפκפ̵

DroidKungFu, Original install
 ƥĤȥ󥹥ȡΥѡߥå

 ä󥤥󥹥ȡ뤵ȡƱץꥱϥ桼˥åץǡȤǽΤ餻롣ƥ桼򥤥󥹥ȡ뤹ȡåץǡȤ줿ץꥱϡDroidKungFuץޥ륦ȯ줿ΤȤ褯ɲõǽ롣

 ʲΥ꡼󥷥åȤϡåץǡȥץDz뤫򼨤Ƥ롧

droidkungfu_update1droidkungfu_update2droidkungfu_update3

droidkungfu_update4droidkungfu_update5

 ꥸʥСӤơåץǡȤ줿ץꥱϡSMSMMSåȡǥХΥ˥Ǥ褦2ĤΥѡߥå׵ᤷ

 ѡߥåΰ㤤ϡåץǡȤդΤɤʬɤˡǤϤʤ⤷ʤǤ⥢ץꥱΥåץǡȤ̤Υѡߥå׵ᤷƤ뤫ɤդäƤߤ뤳Ȥɤˡ

 ˽פʤΤϡåץǡȤ줿ץꥱϡ롼ȸ¤뤿˥ץȤѤˤꤵ˰տޤ̹԰٤Ԥǽ뤳Ȥ

 ǸΥ꡼󥷥åȤǡƱץꥱߤȤƤ롣Ϥ餯ΡDroidKungFuפΰ郎ޤAndroid OS version 2.2ѤΥץȤѤƤꡢƥȤüϡAndroid OS version 2.3פѤƤ뤿Υ顼

 ʲϡåץǡȤ줿ץꥱΥ򼨤åץǡȥץΥѥåȥץ

droidkungfu_packet_capture

 SHA-1: 7cd1122966da7bc4adfabb28be6bfae24072c1c6פǥåץǡȤ줿ץꥱΥƥĤΥåӥ塼

droidkungfu_encrypted_apk

 Ρinit.dbץեϡ¤ϡDroidKungFuפΥɥ󥳥ԡǡǡ١եǤϤʤ롼ȸ¤ȥץꥱ󤬥󥹥ȡ뤹Ź沽줿APKե

 Υץꥱ󤬼ºݡDroidKungFuפǤ뤳Ȥǧ뤿ᡢɤ򸫤Ƥߤ褦

droidkungfu_verify

 WPפϡASCIIɽǤɤΤΥǡСȤȡDeta_C1*T#RuOPrsפˤʤ롣

 ˸ڤԤäȤΥץꥱ󤬼ºݤˡDroidKungFuפΰǤ뤳Ȥʬä桹Ϥ2011ǯ818顢Trojan:Android/DroidKungFu.CפȤƸФƤ롣

 ץʥåץǡȤȸξˤθڥХåVirusTotalǥåȤʲη̤줿ȤDroidKungFuפ˥åץǡȤ륪ꥸʥΥץꥱ

droidkungfu_old_vtscan

 ƥåץǡȤ줿ץꥱ

droidkungfu_updated_vtscan

Threat Solutions post by /mdash; Zimry, Irene and Yeh

—————

1025ɵεϡ꡼󥷥åȤ˴Ϣܺ٤뤿ᡢԽ줿ʤǽοѥ饰դϡΥȥԥå˴ϢƤ뤳Ȥϥåꤵ뤿ľ졢󥯤ϥ꡼󥷥åդVirusTotalΥݡȤ֤줿

ХåʥС
ǥطԤγͤ
ե奢֥С
ե奢֥С
ߥåҥåݥͥ
ե奢 CROʥƥʸˡʥإ륷󥭡
(Twitter)
(Twitter)
硼󡦥Х
ե奢 ƥɥХʥإ륷󥭡
(Twitter)
ŵ
᥿ɽ
(֥)
(Twitter)
߷ ͵
ҥ奢֥쥤 ǹ⵻Ǥ
(֥)
(ʪҲ)
ǥ ȡޥ ꥹӥ (2013ǯ3 ҥå) 󥻥ƥرءҰ
(Twitter)

(ʪҲ)
ʡ
ҥСǥե󥹸 ʬϴ
CDI-CIRTС
(ʪҲ)
͵
FFRI ɽĹ
(ʪҲ)
ʡܡ
ŷ

OWASP Japan
ɥХ꡼ܡ
Rakuten-CERT representative
(ʪҲ)
ե奢 ץȥ롼 Ĺ
ٰ β
ե奢 ץȥ롼
ݥ졼ȥ륹
ե奢
(ե奢֥Twitter)


ҥ᡼ɡ
ե奢᡼ޥ

֥˺ܤʤޥ䡢Ѽԥ󥿥ӥ塼ʾ󡢵ѲǺܤۿޤɥ쥹ΤߤϿǹ̵

ե奢֥ѣҥ
QR