ããæ°æ¥ã倧æäŒæ¥ã§ã®ææå ±åãçžæ¬¡ããæ°èçŽäžãã«ããããŠãããã¬ã³ãã©ãŒã(JS_GUMBLAR)ããã¬ã³ããã€ã¯ãã®çºè¡šã«ãããšã2009幎12æã®äžæ£ããã°ã©ã ææè¢«å®³å ±åæ°ã©ã³ãã³ã°ã§4äœ(33ä»¶)ãšãªã£ãŠãããçŸåšããŸãã«çåšããµãã£ãŠããæäžã ã
|
|
説æãè¡ã£ãããã¬ã³ããã€ã¯ã Threat Monitoring Center 課é·ã®é£¯ç°ææŽæ° |
ããŸããŸãªå ±éãè³ã«ãããææããªãããæ³šæããªããã°ããšæ°ãåŒãç· ããŠããæ¹ãå€ããšæãããããããã®ããã°ã©ã ãã©ã®ãããªæ¯ãèããããã®ããææ¡ããŠããæ¹ãã©ãã ãããã ãããã
å®ã¯ãã®ã¬ã³ãã©ãŒãä»ã®çš®é¡ã®äžæ£ããã°ã©ã ãåŒã³åºããªã©ãã»ãã¥ãªãã£åéã«æãããªããŠãŒã¶ãŒã«ã¯æ³åãã€ããªããããªåãããããããããç®ç«ãã¬ããã¡ã§æŽ»åãããããç¥ããªããã°ãããããææããŠããŸã£ããæ°ã¥ãããšã¯ãªãã ããã
ããã§ããã§ã¯ãã2009å¹ŽåºŠäžæ£ããã°ã©ã ææè¢«å®³å ±åæ°ã©ã³ãã³ã°ã説æäŒã§ã®ãã¬ã³ããã€ã¯ãã«ãã解説ãåºã«ããã®æ¯ãèããç°¡åã«ç޹ä»ããã
ã¬ã³ãã©ãŒããã£ãããšããæææŽ»å
|
|
ãã¢ãæ åœããããã¬ã³ããã€ã¯ã Threat Monitoring Center ã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãã®æŸå·åè±æ° |
ã¬ã³ãã©ãŒã«é¢é£ããäžé£ã®æææŽ»åã¯ãäžæ£ã«å ¥æãããã¢ã«ãŠã³ãæ å ±ã«ãããã°ã€ã³ãSQLã€ã³ãžã§ã¯ã·ã§ã³ãªã©ã«ãããWebããŒãžãæ¹ããããããšããå§ãŸãã
æ¹ãããããWebãµã€ãã«ã¯ãäžæ£ãªWebãµã€ããžãªãã€ã¬ã¯ãããããã°ã©ã ãåã蟌ãŸããããã®ããã°ã©ã ãã¬ã³ãã©ãŒãšåŒã°ãããã®ã ããªãã€ã¬ã¯ãã¯ãWebããŒãžã®è¡šç€ºåŠçãå®è¡ãããè£åŽã§è¡ãããããããŠãŒã¶ãŒã¯ãæ°ã¥ãã¬éã«äžæ£ãµã€ãã«ã¢ã¯ã»ã¹ããŠããŸãããšã«ãªãã
ãªããã¬ã³ãã©ãŒ(GUMBLAR)ãšããåç§°ã¯ããã®è åšãçºèŠãããåœåããªãã€ã¬ã¯ãå ã®äžæ£ãµã€ãåããGUMBLARãã§ãã£ãããšããä»ããããŠããããã ã
ä»å玹ä»ãããã±ãŒã¹ã®å Žåãæå³ããã¢ã¯ã»ã¹ããŠããŸã£ãäžæ£ãµã€ãããã¯ããTROJ_DROPR.GBããšåŒã°ããããã°ã©ã ããŠãŒã¶ãŒã®PCã«éã蟌ãŸããããã®ããã°ã©ã ã¯PCå ã§èªåçã«å®è¡ããããTSPY_KATES.SMODã(ã«ãã¹)ãšåŒã°ããäžæ£ããã°ã©ã (å®éã®ãã¡ã€ã«åã¯æ¡åŒµåãå«ããŠã©ã³ãã ãªæåå)ãäœæããã
ããã«TROJ_DROPR.GBã¯ãåãã¡ã€ã«ãèªåå®è¡ãããããã¬ãžã¹ããªå€(Windowsã®åçš®èšå®æ å ±)ãæžãæããããã®åŸãåèµ·åæã«èªèº«ãåé€ãããèšå®ãè¡ã£ãŠåœ¹å²ãçµããã
ã¬ãžã¹ããªãæžãæããããããšã«ãããInternet Explorerã®èµ·åæãªã©ã«TSPY_KATES.SMODãåŒã³åºãããåããã°ã©ã ããããã¯ãŒã¯ãã©ãã£ãã¯ã®ç£èŠãã¯ãããããã©ãã£ãã¯ç£èŠäžã®TSPY_KATES.SMODã¯ãéä¿¡ããŒã¿å ã«FTPã¢ã«ãŠã³ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããçºèŠãããšããããã®æ å ±ãã67.215.246.34ãããã³ã195.24.76.250ããžéä¿¡ãããããã«ãããFTPã¢ã«ãŠã³ãã®æ å ±ãæ»æè ã®æã«æž¡ãããšã«ãªãã
|
|
|
ãã¢ã®æ§åãFTPã¢ã«ãŠã³ãã®IDãšãã¹ã¯ãŒããéããš(å³)ããããååŸããŠã67.215.246.34ããã195.24.76.250ãã«éä¿¡ãã(å·Š) |
|
|
|
éä¿¡ãããããŒã¿ã®å 容ãSOãšããé ç®ã®æ«å°Ÿã«IDãšãã¹ã¯ãŒããéé ã§äžŠã¹ãããŠãã |
ããããŠå ¥æããæ°ããªWebãµã€ãã®FTPã¢ã«ãŠã³ãæ å ±ãå©çšããŠãåã³äžæ£ããã°ã©ã ãåã蟌ã¿ãè¢«å®³ãæ¡å€§ããããšããã
ãæ°ã¥ãã®ãšããããã®äžé£ã®åŠçã§ã¯FTPã¯ã©ã€ã¢ã³ããå©çšããªããã°æªããããããšããªããã€ãŸããWebãµã€ãã®ç®¡çè /ç·šéè ãäž»ãªã¿ãŒã²ããã«ãããã®ã«ãªãããã ããããã§ç޹ä»ããŠããã®ã¯ãä»åã®èª¬æäŒã§åãäžããããã¿ã€ãã®ã¬ã³ãã©ãŒã®æ¯ãèãã§ããããã®ã»ãã®ã¿ã€ããååšããå¯èœæ§ãããã®ã§ãäžè¬ãŠãŒã¶ãŒãåœç¶æ³šæãå¿ èŠã ã
ãã·ã¹ãã ããéçšãããŠãŒã¶ãŒãããã¹ãŠã®ã¬ãã«ã¢ããã
ã¬ã³ãã©ãŒã«ã€ããŠã¯çŸåšè©±é¡ãšãªã£ãŠããã ãã«ä»åã®èª¬æäŒã§ã倧ãã玹ä»ãããããã€ã³ã¿ãŒãããäžã®è åšãšããŠã¯ãã»ãã«ã泚èŠãã¹ããã®ãããããããã
äŸãã°ãçŸåšãUSBã¡ã¢ãªã®èªåå®è¡ãã¡ã€ã«ãå©çšããäžæ£ããã°ã©ã ãæµè¡ããŠãããUSBã¡ã¢ãªã«ããææã¯ããããã¯ãŒã¯äžã«èšçœ®ããäœéãã®ã»ãã¥ãªãã£å¯Ÿçãç¡æå³ã«ãªã£ãŠããŸãããã管çè ã«ãšã£ãŠã¯é ã®çãåé¡ã ã
ãŸããé£èªåãæœãããäžæ£ããã°ã©ã ãæ¥æ¿ã«å¢å ããŠããããŠã£ã«ã¹å¯Ÿçãœããã«ããæ€åºãéãããã®ãå°ãªããããããšããã
|
|
é£èªåãæœããŠãŠã£ã«ã¹å¯Ÿçãœããã«ããæ€åºãéããäžæ£ããã°ã©ã ãæ¥å¢ |
ããã«ãã¯ã¬ãžããã«ãŒãæ å ±ã以äžã®ãããªå䟡ã§ååŒãããŠãããšãã£ã宿 ããããééç®çã®å¶æªãªæ»æãè¡ãããã±ãŒã¹ãå¢ããŠããã
å ããŠãäžæ£ããã°ã©ã ã®æ°ãå¢ããŠãããä»ã2.5ç§ã«1ã€ã®ããŒã¹ã§äžæ£ããã°ã©ã ãçæãããŠããããã®ãããæ°æéïœ1æ¥ã«1åã®ãã¿ãŒã³ãã¡ã€ã«ã®æŽæ°ã§ã¯éã«åããªãã±ãŒã¹ãããã
ããããç¶æ³ã®äžãå®å šã«éçšãç¶ããããã«ã¯ãããã·ã¹ãã ãããéçšããããŠãŒã¶ãŒãã®3èŠçŽ ãã¹ãŠãã¬ãã«ã¢ããããå¿ èŠãããã(ãã¬ã³ããã€ã¯ã Threat Monitoring Center èª²é· é£¯ç°ææŽæ°)ãšããã
ã·ã¹ãã ã«ãããŠã¯ãåŸæ¥ããã®ã»ãã¥ãªãã£å¯Ÿçã«å ããŠãææ°ã®ãœãªã¥ãŒã·ã§ã³ãæ€èšããããšã倧åã ãäŸãã°ãåWebãµã€ãã®å±éºåºŠãè©äŸ¡ãããã®è©äŸ¡çµæã«å¿ããŠã¢ã¯ã»ã¹ãå¶åŸ¡ãããWebã¬ãã¥ããŒã·ã§ã³ãµãŒãã¹ããªã©ã®ææ°ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããããšã§ããã¿ãŒã³ãã¡ã€ã«ã®æŽæ°ã§è¶³ããªãéšåãè£ãããšãã§ããã
ãŸããéçšã«ãããŠã¯ãUSBã¡ã¢ãªã®éçšããªã·ãŒããã¹ã¯ãŒãã®æŽæ°ããªã·ãŒãªã©ãèŠçŽãããšã§é²ããè åšã倿°ãããããŠãŒã¶ãŒã«é¢ããŠã¯ãææ°ã®æ»ææå£ãé ã«å ¥ããŠããããšã§ãæè¿å¢ããŠããå·§åŠãªäœãã®äžæ£ã³ã³ãã³ããªã©ã«éšãããã±ãŒã¹ãå°ãªããªããšããã
*ãã*ãã*
çŸåšã®ã€ã³ã¿ãŒãããç°å¢ã«ã¯ãã©ãã«è åšããããããããªããæãã¬èœãšã穎ã«ã¯ãŸããªãããã«ãä»å¹Žãã»ãã¥ãªãã£ååã«ã¯åžžã«æ³šèŠããŠããããã