æ¬é£èŒãçµäºããã¯ã±ã§ã¯ãããŸãã!!
æ°ãã€ãã°ããæ°å¹Žæ¥ãšæãããæ¢ éšãããæ¢ éšã®å£ç¯ã§ããããã®çš¿ãæžããŠããä»ãããã€éšãéããšããããªãã©ãããé²ã¯åã空ãèŠã£ãŠããâŠâŠããããé çã§ç³ãèš³ãªããååã®ã³ã©ã ããæ°ããŠ5ã«æçãé²ãŸãªãã£ããããªã®ã§ãçµäºãã©ã°ãšæã£ã人ãå€ããããããããããã¯ãã¢ããŸããšååãã«é²ããŠãããããšæãã(âæ¬åœã§ãã!? >æ åœç·šé)
ãšããããã§ãä»åã¯ãããããããææããããšããã¡ãã£ãšå€ãã£ãèŠ³æž¬æ¹æ³ã«ã€ããŠç޹ä»ãããããã ããçè ã¯æ³åŸå®¶ã§ã¯ãªãããæ³šææžããšããŠãããšåãæ¹æ³ãåœå ã§å®æœãããšãæ³ä»€ããšãã°äžæ£ã¢ã¯ã»ã¹çŠæ¢æ³ãªã©ã«æµè§Šããæããããããšãå ã«è¿°ã¹ãŠããã
40äžå°ä»¥äžã®ãããã§æ§æããã"Kraken"ã®ååšå ±åãšåè«
ãã£ããã¯4æã®ã¯ããã®ããšã§ãããKrakenãšåŒã°ãããããããããç±³Damballa瀟ã«ããçºèŠããããã®æ§æå°æ°(ãããææPCæ°)ã¯40äžå°ä»¥äžã«ã®ãŒããšãã調æ»çµæãæããã«ãªã£ãã®ã ã
ãã®å ±ã«éãããŠã€ã«ã¹å¯Ÿçãœãããã³ããã¯ãããå°éå®¶ããæ¬¡ã ãšåè«ãå¯ãããããããšãã°ãThe Washington PostçŽã®"Security Fix"ãšããããã°ãžã®Brian Krebsèšè ã®æçš¿ã¯ãå瀟ã¯KrakenãC&CãµãŒãçšã«äœ¿çšããŠãã100以äžã®ãã¡ã€ã³ã®äžéšãå æ ãããã®ææPCæ°ãèšæž¬ããŠããããšææããããã®ææãããã«èª¿æ»ããã®ãF-Secureã§ããããã®ããã°ã«ãããŠããã®ãã«ãŠã§ã¢ã®äºçš®ãæåã«ç®ã«ããã®ã¯2006幎ã®å€ããã§ãããä»è©±é¡ãšãªã察象ã§ã¯ãªãã ããããŸãããã®ãããªDNSã䜿çšããæ€ç¥æ³ã«ããçµ±èšã¯éå»ã®ãä»ã䜿çšãããªããªã£ãäºçš®ã®ããŒã¿ãå«ãã§ããå¯èœæ§ããããããã«Krakenã®ããããããã®æ§æå°æ°ã¯æ°Žå¢ããããŠããæããããããšè«ããããŸããSymantecã«ãããšãã®ãµã³ãã«ãå ¥æããBackdoor.Spakrabããšããåç§°ã§æ€ç¥å¯èœã«ããããã«ãã¿ãŒã³ãã¡ã€ã«ãžåæ ãè¡ã£ããšããããã§ã«Bloodhound.SONAR.1ãªããHacktool.Spammerãšããåç§°ã§æ€ç¥å¯èœã§ãã£ããšãããããã«ãç±³SecureWorks瀟ã¯ãKrakenã¯Bobaxã§ããããšäž»åŒµãããã®ããããããæ§æå°æ°ã¯ãããã18äž5,000å°ã§ãããšããŠããã
ãã®å·®ç°ã«ã€ããŠç®ãã€ããã®ããç±³TippingPointã®ç ç©¶æ©é¢ã§ããDVLabsã®Pedram Aminiæ°ãšCody Pierceæ°ã§ããããšãã«Pierceæ°ã¯Krakenã®äœ¿çšãããããã³ã«ãåæããæå·åã«ãŒãã³ã詳解ããããšã§ããã»ã®KrakenãµãŒãããäœæãããªãã€ã¬ã¯ãããããããææPCãææãã --äºå®äžã®ä¹ã£åã-- ãå¯èœã«ãããšããããããŠããã®ãããããããææããããã®éèŠãªç¹ã¯ãã¯ã©ã€ã¢ã³ããµãŒãã®ã¢ãŒããã¯ãã£ãè§£ãã»ãããšããã«ãã£ããšèªããKrakenã¯ãµãC&CãµãŒããšããŠãããšãã°dyndns.comã«ä»£è¡šããããã€ãããã¯DNSãµãŒãã¹ãè€æ°äœ¿çšãããã¹ã¿ãŒã®C&CãµãŒãããåœä»€ãåãåãæ§é ã«ãªã£ãŠããããããŠãKrakenã®äœ¿çšããŠãããã€ãããã¯DNSãµãŒãã¹ã®FQDNãç»é²ãããµãŒãã®ãšãã¥ã¬ãŒã·ã§ã³ãè¡ãããšã§ãããææPCãæ¬¡ã ã«ä¹ã£åã£ãŠãã£ãã®ã ãšããã
ãæµåãããå«çæããããããšãâŠ
DVLabsã§ã¯ãã®æ¹æ³ã䜿çšããããšã§1é±é芳枬ãè¡ããäžçäžãã180äžä»¥äžã®æ¥ç¶èŠæ±ãåãåã£ããšããããããŠãããã®æ¥ç¶èŠæ±ã®ãã¡ããŠããŒã¯ãªIPã¢ãã¬ã¹ã¯6äž5,000ã§ããŸãããããIPã¢ãã¬ã¹ã®éåŒãçµæãããææè ã®å€§åã¯äžè¬å®¶åºã®ãããŒããã³ãå©çšè ã§ãã£ããšãããåœå¥ã®å èš³ã¯åç±³ãäžçªå€ããæ¬¡ãã§ã¹ãã€ã³ãã€ã®ãªã¹ãã³ãã³ãã¢ã®é ã§ãã£ãããŸããããããããææPCã®ç¹å®ã¯ãããŸã§ããæ°èŠã®ææè ãã§ãããããçŸåšã®Krakenã®å€§ãããæž¬ãæ¹æ³ã«ã¯ãªã£ãŠããªããšããã
ããã§ãDVLabsã®èŠ³æž¬æ³ã¯èŠ³æž¬ã®ã¿ãªããããã¢ããããŒããææPCã«ä¿ããããšãã§ãããšããç¹ã«ã«ããã«æ³šç®ããããã€ãŸããã®èŠ³æž¬æ³ã§ã¯ãããææPCã«æä»€ãåºãããšãå¯èœã§ãããèšãæããã°ãé§é€ããããã°ã©ã ãå®è¡ãããããšã§ãããããããæµåãããããšãå¯èœã«ãªãã®ã ããããã«ãæè¡çææ®µãçšããŠããããããã壿» ãããããšãã§ããã°ããç®ã«ã¯ç®ããã§éçšããã®ãããããªãããã ãããã®ãããªãæµåæ³ãã«ã€ããŠã¯ãææ³ããç°ãªããCodeRedã¯ãŒã çºçæã®CodeGreenã®ãããªå«ççãªåé¡ãšããããããããããæ³ä»€ã«æµè§Šããå¯èœæ§ãã¯ããã§ããããããŠçŸåšããã®ããšãç¶Žã£ãããã°ã®ãšã³ããªã¯è³åŠäž¡è«ãããŸããŸãªã³ã¡ã³ããå¯ããããŠããã