ååã«åŒãç¶ããä»åãKrakenããããããã«ã€ããŠDVLabsãè¡ã£ã調æ»(http://dvlabs.tippingpoint.com/blog/2008/04/28/owning-kraken-zombies)ã玹ä»ããããã ããä»åã¯èŠ³æž¬ã«ãã£ãŠåŸãããããŒã¿ã§ã¯ãªããã©ã®ãããªäºå調æ»ãè¡ãããšã§ããããããã®èŠ³æž¬ãå¯èœã«ããã®ãããšãã£ãæè¡çãªåæææ³ã«äž»çŒã眮ãããšã«æ³šæããããã
ãã€ããªã®Obfuscation(é£èªå)
DVLabsã«ãããšããŸãKrakenã®æ€äœãOffensive Computingããå ¥æããåæãè¡ã£ãã®ã ãšããããã®çµæãKrakenã¯UDP 447çªããŒãã䜿çšããæå·åãããã³ã«ãéããŠæä»€(C&C)ãµãŒããšéä¿¡ãè¡ãããšã倿ãããéä¿¡å ã®C&CãµãŒãã¯ããã€ãããã¯DNSãããã€ã(DDNSäºæ¥è )ã«ãããµãŒãã¹ã䜿çšããããµããã¡ã€ã³åã«ã©ã³ãã ãªåç§°ãä»ããããŠãããã¡ãªã¿ã«DDNSäºæ¥è ã®ãµãŒãã¹ãããããããããããã®åºç€ãšããŠäœ¿çšãããŠããäŸã¯ææã«æããªãããã®ãµããã¡ã€ã³åã¯ãããã¢ã«ãŽãªãºã ã«ãã£ãŠçæããããçæããããµããã¡ã€ã³åã«ãDDNSäºæ¥è ã®æäŸãããã¡ã€ã³åãä»ãå ããããéä¿¡å C&CãµãŒãåè£ãšããŠãªã¹ãã«è¿œå ãããã
ãªãããã®ãããªã¢ã«ãŽãªãºã ããããã䜿çšããŠC&CãµãŒãã®ãã¡ã€ã³åããããããã°ã©ã ã®ãªãã§çæããŠããããšãããšãããã¯ã¢ã«ãŽãªãºã ã«ããåŠçãè¡ãããªãéããéä¿¡å ãå²ãåºãããšãã§ããªãããã ããã£ãšå ·äœçã«èšãæããããå³2ã¯ãçè ãããå¥ã®ãã«ãŠã§ã¢æ€äœãåæããéã«ç¹å®ããéä¿¡å ã®URLã§ãããã¡ãªã¿ã«åç §ãããã¡ã€ã«ã®æ¡åŒµåã¯txtã ããå®è¡å¯èœãã€ããªãããŠã³ããŒããããã
|
|
å³2 ãã«ãŠã§ã¢ã«å«ãŸããéä¿¡å ã®äŸ |
ãã®ããã«ããã«ãŠã§ã¢ã®ããã°ã©ã ã³ãŒãåæãããŸãããã°ããããŠãã¯ãã®éä¿¡å ãç¹å®ããããšãã§ããããã£ãšç«¯çãªèšãæ¹ãããã°ããã«ãŠã§ã¢æ€äœã«éä¿¡å ã®FQDNãIPã¢ãã¬ã¹ã®æååã(ãããŠãã¯)åãŸã£ãŠãããã®ã ã仿¹ã§ãKrakenã¯ããã§ã¯ãªããSEEDãšåŒã°ããæååãããã¢ã«ãŽãªãºã ã䜿çšããŠå å·¥ãããµããã¡ã€ã³åãšããŠçæããŠããããã£ãŠãdyndns.orgãyi.orgãšãã£ãDDNSäºæ¥è ã®äœ¿çšãããã¡ã€ã³ã®æååã¯Krakenæ€äœã®äžã«åãŸã£ãŠããããããããæ¬åœã®éä¿¡å ã?ããšããã°ãããã§ã¯ãªãã®ã§ããããããããããããObfuscation(é£èªå)ãã®å ·äœäŸã§ãããããã°ã©ã ã³ãŒããåæãããšããã§ããã®éä¿¡å ãããã«å²ãåºãããšãã§ããªããããããã«åæè ã«æéããããããä»çµã¿ãçµã¿èŸŒãŸããŠããã®ã ã
5幎ã»ã©åã§ããã°ããããã¯ãŒã¯çµç±ã§å€§èŠæš¡ãªææãè¡ããã«ãŠã§ã¢ã®æ€äœãå ¥æãããã®ããã°ã©ã ã³ãŒãåæãè¡ãã°ããã®æ€äœãã©ã®ãããªææåäœãåŒãèµ·ããã¢ããªã®ããå²ãåºãããšã¯å®¹æã§ãã£ããããããçŸåšã¯ãã®ãããªé£èªåãæœãããŠããããšãæ°èŠã«çºçãããã«ãŠã§ã¢æ€äœã®å€§åãå ããŠããããã®æ€äœãã©ããªåäœãè¡ãã¢ãã?ããç¹å®ããããšããåçŽã«ããã°ã©ã ã³ãŒãåæãè¡ãããšã®ã¿ã§ã¯å°é£ã«ãªã£ãŠãããKrakenã¯ãã®ããšãåŠå®ã«èªã£ãŠãããšæããããå°ãTippingPoint DVLabsã®åœè©²ããã°ã§ã¯Krakenã®äœ¿çšããC&Cã®ãªã¹ãã1äž5åãã¡ã€ã³åå ¬éãããŠããã
Krakenã®äœ¿çšããæå·åãããã³ã«
次ã«ãDVLabsãæããã«ããããšã¯Krakenãåœä»€ã®éåä¿¡ã«äœ¿çšããŠããéä¿¡ãã£ãã«ã®æå·åãããã³ã«ã§ãããå³3ã®ããã«ãsocketã䜿çšããéä¿¡ã«éããŠã¯ãæå·åãããã®äœ¿çšãèªããããã
|
|
å³3 Krakenã®éä¿¡åŒã³åºãåŠç(åºå ž: TippingPoint DVLabs Blog) |
å³3ã®ããã«ãäœããã®æå·åã®ããã®éµãååŸãããããŠããããæ§æãããã§ããã®ãããèªèº«ãéä¿¡åã«æå·åããã®ã§ãã(å³äžã®åŒã³åºã颿°åç§°ã¯äŸ¿å®äžãDVLabsãä»äžãããã®ã§ããç¹ã«æ³šæ)ã仿¹ã§ãKrakenã«ãã£ãŠè¡ãããéä¿¡ã®è©³çŽ°ãæ§ã ãªããã°ã§ç޹ä»ãããŠããããããŠããã®éä¿¡ã®æåã®8ãã€ããåºå®å€ã§ãããšææããŠãããDVLabsã¯ããã®çç±ã¯Krakenã®æå·åãããã³ã«ã§äœ¿çšãããŠããéµããã®8ãã€ãã®å€ã§ããããšãæããã«ããã®ã ã
