è åšãã³ãã£ã³ã°ãŸãã¯THã¯ãæšæºçãªä¿è·æ段ã§ã¯æ€åºãããªããã«ãŠã§ã¢ã®çè·¡ããããã³ã°ã®ããã¢ã¯ãã£ããªæ€çŽ¢ã§ããä»æ¥ã¯ããã®ããã»ã¹ãã©ã®ããã«æ©èœããããè åšãæ€çŽ¢ããããã«äœ¿çšã§ããããŒã«ãããã³ä»®èª¬ãäœæããŠãã¹ããããšãã«çæãã¹ãããšã«ã€ããŠè©±ããŸãã
è åšãã³ãã£ã³ã°ãšã¯äœãããªããããå¿ èŠãªã®ã
è åšãã³ãã£ã³ã°ã®ããã»ã¹ã§ã¯ãã¢ããªã¹ãã¯ä¿è·ã·ã¹ãã ã®ã»ã³ãµãŒãããªã¬ãŒããããŸã§åŸ æ©ãããæå³çã«äŸµå®³ã®çè·¡ãæ¢ããŸãããããè¡ãããã«ãæ»æè ãã©ã®ããã«ãããã¯ãŒã¯ã«äŸµå ¥ã§ãããã«ã€ããŠã®ä»®å®ãäœæããæ€èšŒããŸãããã®ãããªãã§ãã¯ã¯ãäžè²«æ§ãããå®æçã«è¡ãå¿ èŠããããŸãã
ããã»ã¹ãæ£ããå®è£ ããã«ã¯ã次ã®ååãèæ ®ããå¿ èŠããããŸãã
- ã·ã¹ãã ããã§ã«äŸµå®³ãããŠãããšæ³å®ããå¿ èŠããããŸããäž»ãªç®æšã¯ãäŸµå ¥ã®çè·¡ãèŠã€ããããšã§ãã
- æ€çŽ¢ããã«ã¯ãã·ã¹ãã ãã©ã®çšåºŠæ£ç¢ºã«äŸµå®³ããããã«ã€ããŠã®ä»®èª¬ãå¿ èŠã§ãã
- æ€çŽ¢ã¯ç¹°ãè¿ãå®è¡ããå¿ èŠããããŸããã€ãŸãã次ã®ä»®èª¬ããã¹ãããåŸãã¢ããªã¹ãã¯æ°ãã仮説ãæ瀺ããŠæ€çŽ¢ãç¶è¡ããŸãã
å€ãã®å ŽåãåŸæ¥ã®èªåé²åŸ¡ã¯é«åºŠãªæšçåæ»æãèŠéããŸãããã®çç±ã¯ããã®ãããªæ»æã¯æéã®çµéãšãšãã«åºããããšãå€ããããã»ãã¥ãªãã£ããŒã«ã¯æ»æã®2ã€ã®ãã§ãŒãºãé¢é£ä»ããããšãã§ããªãããã§ããåæã«ãæ»æè ã¯äŸµå ¥ãã¯ãã«ã泚ææ·±ãæ€èšããã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã®ã¢ã¯ã·ã§ã³ã®ã·ããªãªãäœæããŸããããã«ããã圌ãã¯ãã¹ãã³ã°è§£é€ã¢ã¯ã·ã§ã³ãå®è¡ãããæ£åœãªãã®ãšããŠåœŒãã®æŽ»åãåœãããšãã§ããŸããæ»æè ã¯åžžã«ç¥èãåäžãããæ°ããããŒã«ãè³Œå ¥ãŸãã¯éçºããŠããŸãã
æšçåæ»æã®ç¹å®ã«é¢ããåé¡ã¯ã以åã«ãããã³ã°ãããçµç¹ã«ç¹ã«é¢é£ããŠããŸããã¬ããŒãã«ãããšFireEye M-Trendsã以åã«äŸµå®³ãããçµç¹ã®64ïŒ ãåã³æ»æãããŸããããããã³ã°ãããäŒæ¥ã®åæ°ä»¥äžãäŸç¶ãšããŠå±éºã«ãããããŠããããšãå€æããŸãããããã¯ã劥åã®äºå®ãæ©æã«çºèŠããããã®å¯Ÿçãé©çšããå¿ èŠãããããšãæå³ããŸã-ããã¯THã®å©ããåããŠéæã§ããŸãã
è åšãã³ãã£ã³ã°ã¯ãæ å ±ã»ãã¥ãªãã£ã®å°é家ã䟵害ãæ€åºããæéãççž®ããä¿è·ãããã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢ããç¥èãæŽæ°ããã®ã«åœ¹ç«ã¡ãŸããTHã¯è åšã€ã³ããªãžã§ã³ã¹ïŒTIïŒã䜿çšããå Žåã«ã圹ç«ã¡ãŸããç¹ã«ã仮説ãç«ãŠããšãã«TIã€ã³ãžã±ãŒã¿ãŒã䜿çšããå Žåã«åœ¹ç«ã¡ãŸãã
ãã¹ãã®ä»®èª¬ãç«ãŠãæ¹æ³
THãå®æœããå Žåãæ»æè ã¯ãã§ã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã«äŸµå ¥ããŠããããšãäºåã«æ³å®ãããŠãããããæåã«è¡ãããšã¯ããããã³ã°ã®çè·¡ãæ¢ãå Žæãç¹å®ããããšã§ããããã¯ãäŸµå ¥ãã©ã®ããã«çºçãããããã€ã³ãã©ã¹ãã©ã¯ãã£ã§ç¢ºèªã§ãããã«ã€ããŠã®ä»®èª¬ãç«ãŠãããšã«ãã£ãŠæ±ºå®ã§ããŸãã仮説ãç«ãŠããšãã¢ããªã¹ãã¯åœŒã®ä»®å®ã®çå®ããã§ãã¯ããŸãã仮説ã確èªãããªãå Žåãå°é家ã¯æ°ãã仮説ã®éçºãšãã¹ãã«é²ã¿ãŸãã仮説ããã¹ãããçµæããããã³ã°ã®çè·¡ãèŠã€ãã£ããããã«ãŠã§ã¢ã®ååšã確èªãããããããšã調æ»ãå§ãŸããŸãã
å³2.è åšãã³ãã£ã³ã°
ã®ã¹ããŒã 仮説ã®ã¢ã€ãã¢ã¯ãã¢ããªã¹ãã®å人çãªçµéšããçãŸãããããããŸãããããã®æ§ç¯ã«ã¯ä»ã®ãœãŒã¹ããããŸããããšãã°ã次ã®ãããªãã®ããããŸãã
- threat intelligence (TI-). , : X, MD5- Y.
- , (TTPs). TTPs MITRE ATT&CK. : .
- . . , asset management . .
- , .
threat hunting
仮説ãç«ãŠãããããããã¹ãããããã®æ å ±ãå«ãããšãã§ããããŒã¿ãœãŒã¹ãç¹å®ããå¿ èŠããããŸããå€ãã®å Žåããã®ãããªãœãŒã¹ã«ã¯å€ãããããŒã¿ãå«ãŸããŠããããã®äžã§é¢é£æ§ãèŠã€ããå¿ èŠããããŸãããããã£ãŠãTHããã»ã¹ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§çºçããŠããããšã«é¢ããèšå€§ãªéã®ããŒã¿ã®èª¿æ»ããã£ã«ã¿ãªã³ã°ãããã³åæã«èŠçŽãããŸããïŒæ å ±ãæ€çŽ¢ä»®èª¬ããã¹ãããããã«èŠã€ããããšãã§ãããæ å ±æºãæ€èš
THãè¡ãããã®æ å ±æºã®å³3.åé¡
ã®é¢é£æ å ±ã®æ倧éã¯ããã°ããããã¯ãŒã¯ãã©ãã£ãã¯ã«å«ãŸããŠããŸããSIEMïŒã»ãã¥ãªãã£æ å ±ãšã€ãã³ã管çïŒããã³NTAïŒãããã¯ãŒã¯ãã©ãã£ãã¯åæïŒã¯ã©ã¹ã®è£œåã¯ããããã®æ å ±ã®åæã«åœ¹ç«ã¡ãŸããå€éšãœãŒã¹ïŒTIãã£ãŒããªã©ïŒãåæããã»ã¹ã«å«ããå¿ èŠããããŸãã
å®éã®ä»çµã¿
THã®äž»ãªç®çã¯ãèªåã»ãã¥ãªãã£ããŒã«ã§ã¯æ€åºãããªãã£ãéåãæ€åºããããšã§ãã
ããšãã°ã2ã€ã®ä»®èª¬ããã¹ãããããšãæ€èšããŠãã ãããå®éã«ã¯ããã©ãã£ãã¯åæãšãã°åæã·ã¹ãã ã仮説ãã¹ãã®ããã»ã¹ã§ã©ã®ããã«çžäºè£å®ãããã瀺ããŸãã
仮説1ïŒæ»æè ã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ãä»ããŠãããã¯ãŒã¯ã«å ¥ããWMIã³ãã³ãã®å®è¡ã䜿çšããŠãããã¯ãŒã¯äžã®ä»ã®ããŒããå¶åŸ¡ããããšããŸãã
æ»æè ã¯rootãŠãŒã¶ãŒã®è³æ Œæ å ±ãå ¥æããŸããããã®åŸã貎éãªããŒã¿ãæã€ãã¹ãã«å°éããããã«ããããã¯ãŒã¯å ã®ä»ã®ããŒããå¶åŸ¡ããããšããŸãããªã¢ãŒãã·ã¹ãã ã§ããã°ã©ã ãèµ·åããæ¹æ³ã®1ã€ã¯ãWindows Management InstrumentationïŒWMIïŒãã¯ãããžã䜿çšããããšã§ãã圌女ã¯ãã³ã³ãã¥ãŒã¿ãŒã€ã³ãã©ã¹ãã©ã¯ãã£ã®ããŸããŸãªéšåã®éäžç®¡çãšç£èŠãæ åœããŠããŸãããã ããäœæè ã¯ããã®ã¢ãããŒããåäžã®ãã¹ãã ãã§ãªããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã®ã³ã³ããŒãã³ãããªãœãŒã¹ã«ãé©çšã§ããå¯èœæ§ãäºèŠããŸããããã®ãããDCERPCãããã³ã«ãä»ããã³ãã³ããšå¿çã®éä¿¡ãå®è£ ãããŸããã
ãããã£ãŠã仮説ããã¹ãããã«ã¯ãDCERPCã¯ãšãªã調ã¹ãå¿ èŠããããŸãããã©ãã£ãã¯åæãšSIEMã·ã¹ãã ã䜿çšããŠããããã©ã®ããã«å®è¡ã§ããããèŠãŠã¿ãŸããããå³ã§ã¯4ã¯ããã¹ãŠã®ãã£ã«ã¿ãªã³ã°ãããDCERPCãããã¯ãŒã¯ã®çžäºäœçšã瀺ããŠããŸããããšãã°ã06ïŒ58ãã12:58ãŸã§ã®æéééãéžæããŸãããå³4.ãã£ã«ã¿ãªã³ã°ãDCERPCã»ãã·ã§ã³ ã 4 2ã€ã®ããã·ã¥ããŒãã衚瀺ãããŸããå·ŠåŽã¯DCERPCæ¥ç¶ãéå§ããããŒãã§ããå³åŽã¯ãã¯ã©ã€ã¢ã³ããæ¥ç¶ããŠããããŒãã§ããå³ãããããããã«ããããã¯ãŒã¯äžã®ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã¯ãã¡ã€ã³ã³ã³ãããŒã©ã«ã®ã¿ã¢ã¯ã»ã¹ããŸãã Active Directoryãã¡ã€ã³ã«çµ±åããããã¹ãã¯DCERPCãããã³ã«ã䜿çšããŠåæã®ããã«ãã¡ã€ã³ã³ã³ãããŒã©ãŒã«æ¥ç¶ãããããããã¯æ£åœãªã¢ã¯ãã£ããã£ã§ãããã®ãããªãŠãŒã¶ãŒãã¹ãéã®éä¿¡ã¯ãçããããšèŠãªãããŸãã
éžæããæéã«çããããã®ã¯äœãç¹å®ãããŠããªããããã¿ã€ã ã©ã€ã³ã«æ²¿ã£ãŠç§»åããŠããããã次ã®4æéãéžæããŸããçŸåšã¯12:59ãã16:46ãŸã§ã®ã€ã³ã¿ãŒãã«ã§ãããã®äžã§ãå®å ãã¹ãã®ãªã¹ãã®å¥åŠãªå€åã«æ°ã¥ããŸããïŒå³5ãåç §ïŒãå³5.æéééãå€æŽãããšã2ã€ã®æ°ããããŒãããµãŒã㌠ãªã¹ãã«è¡šç€ºãããå®å ãã¹ãã®ãªã¹ãã«ã¯2ã€ã®æ°ããããŒãããããŸãã DNSåã®ãªããã®ïŒ10.125.4.16ïŒãæ€èšããŠãã ããã10.125.4.16ã«æ¥ç¶ãããŠãã人ãèŠã€ããããã«ããã£ã«ã¿ã®å³6.æŽç·Ž ããªããå³ãããããããã«ã 6ããã¡ã€ã³ã³ã³ãããŒã©ãŒ10.125.2.36ãã¢ã¯ã»ã¹ããŸãïŒå³4ãåç §ïŒãããã¯ããã®çžäºäœçšãæ£åœã§ããããšãæå³ããŸãã
次ã«ãå³2ã®2çªç®ã®æ°ããããŒãã«æ¥ç¶ãããŠãŒã¶ãŒãåæããå¿ èŠããããŸãã 5ã¯win-admin-01.ptlab.ruïŒ10.125.3.10ïŒã§ããããŒãã®ååãããããã¯ç®¡çè ã®ã³ã³ãã¥ãŒã¿ã§ããããšãããããŸãããã£ã«ã¿ãŒã調æŽãããåŸã2ã€ã®ã»ãã·ã§ã³ãœãŒã¹ããŒãã®ã¿ãæ®ããŸããå³7.ãã£ã«ã¿ãŒãçµã蟌ãã§win-admin-01 ã«æ¥ç¶ãããŠãŒã¶ãŒãèŠã€ããåã®ã±ãŒã¹ãšåæ§ã«ãã€ãã·ãšãŒã¿ãŒã®1ã€ã¯ãã¡ã€ã³ã³ã³ãããŒã©ãŒã§ããããããã®ã»ãã·ã§ã³ã¯ãActive Directoryç°å¢ã§ã¯äžè¬çã§ãããããäžå¯©ã§ã¯ãããŸããããã ããååã§å€æãããšã2çªç®ã®ããŒãïŒw-user-01.ptlab.ruïŒã¯ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã§ãããã®ãããªæ¥ç¶ã¯ç°åžžã§ãããã®ãã£ã«ã¿ãŒã䜿çšããŠ[ã»ãã·ã§ã³]ã¿ãã«ç§»åãããšããã©ãã£ãã¯ãããŠã³ããŒãããŠãWiresharkã§è©³çŽ°ã確èªã§ããŸããå³8.é¢é£ããã»ãã·ã§ã³ã®ããŠã³ããŒã
ãã©ãã£ãã¯ã§ã¯ãWMIæ¥ç¶ã®äœ¿çšã瀺ãIWbemServicesã€ã³ã¿ãŒãã§ã€ã¹ãžã®åŒã³åºãã確èªã§ããŸããå³9. IWbemServicesïŒWiresharkïŒã€ã³ã¿ãŒãã§ãŒã¹ã® åŒã³åºãããã«ãéä¿¡ãããåŒã³åºãã¯æå·åãããŠãããããç¹å®ã®ã³ãã³ãã¯äžæã§ããå³10. DCERPCãã©ãã£ãã¯ã¯æå·åãããŠãããããéä¿¡ãããã³ãã³ãã¯è¡šç€ºãããŸããïŒWiresharkïŒ ãã®ãããªéä¿¡ãäžæ£ã§ãããšãã仮説ãæçµçã«ç¢ºèªããã«ã¯ããã¹ããã°ã確èªããå¿ èŠããããŸãããã¹ãã«ç§»åããŠããŒã«ã«ã§ã·ã¹ãã ãã°ã衚瀺ã§ããŸãããSIEMã·ã¹ãã ã䜿çšããæ¹ã䟿å©ã§ãã SIEMã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯ãDCERPCæ¥ç¶ã®ç¢ºç«æã«ã¿ãŒã²ããããŒãã®ãã°ã®ã¿ãæ®ãæ¡ä»¶ããã£ã«ã¿ãŒã«å°å ¥ãã次ã®ç»åãèŠãŸããã
å³11. DCERPCæ¥ç¶ã®ç¢ºç«æã®ã·ã¹ãã ãã°win-admin-01
ãã°ã§ã¯ãæåã®ã»ãã·ã§ã³ã®éå§æå»ãšå®å šã«äžèŽããŠããããšãããããŸããïŒå³9ãåç §ïŒãæ¥ç¶ã®éå§è ã¯ãã¹ãw-user-01ã§ãããã°ãããã«åæãããšãPTLAB \ Adminã¢ã«ãŠã³ãã§æ¥ç¶ããŠã³ãã³ãïŒå³12ãåç §ïŒãå®è¡ãããŠãŒã¶ãŒjohnããã¹ã¯ãŒãpassword !!!ã§äœæããããšãããããŸããnetuser john password !!! / è¿œå ãå³12.æ¥ç¶äžã«å®è¡ãããã³ãã³ã
ããŒã10.125.3.10ãããPTLAB \ Adminã¢ã«ãŠã³ãã«ä»£ãã£ãŠWMIã䜿çšããŠãã誰ããæ°ãããŠãŒã¶ãŒããã¹ãwin-admin-01.ptlab.ruã«è¿œå ããããšãããããŸãããå®éã®THãå®æœããå Žåã®æ¬¡ã®ã¹ãããã¯ãããã管ç掻åã§ãããã©ããã確èªããããšã§ãããããè¡ãã«ã¯ãPTLAB \ Adminã¢ã«ãŠã³ãã®ææè ã«é£çµ¡ããŠã説æãããŠããã¢ã¯ã·ã§ã³ãå®è¡ãããã©ããã確èªããå¿ èŠããããŸããæ€èšããäŸã¯åæã§ããããããã®ã¢ã¯ãã£ããã£ã¯äžæ£ã§ãããšæ³å®ããŸãããŸããæ¬ç©ã®TNãå®æœããéã«ãã¢ã«ãŠã³ãã®äžæ£å©çšã®äºå®ãå€æããå Žåã¯ãã€ã³ã·ãã³ããäœæãã詳现ãªèª¿æ»ãè¡ãå¿ èŠããããŸãã
仮説2ïŒæ»æè ããããã¯ãŒã¯ã«äŸµå ¥ããããŒã¿æŒããã®æ®µéã«ããããã©ãã£ãã¯ãã³ããªã³ã°ã䜿çšããŠããŒã¿ãåºåããŠããã
ãã³ããªã³ã°ãã©ãã£ãã¯-ãããããã¯ãŒã¯ãããã³ã«ã®ãã±ãããïŒããããå€æŽããã圢åŒã§ïŒå¥ã®ãããã¯ãŒã¯ãããã³ã«ã®ãã£ãŒã«ãå ã«éä¿¡ãããããã«ãã£ãã«ãç·šæããŸãããã³ããªã³ã°ã®äžè¬çãªäŸã¯ãSSHã®ãããªæå·åããããã€ãã®æ§ç¯ã§ããæå·åããããã£ãã«ã¯ãéä¿¡ãããæ å ±ã®æ©å¯æ§ã確ä¿ããçŸä»£ã®äŒæ¥ãããã¯ãŒã¯ã§ã¯äžè¬çã§ãããã ããICMPãã³ãã«ãDNSãã³ãã«ãªã©ã®ãšããŸããã¯ãªãªãã·ã§ã³ããããŸãããã®ãããªãã³ãã«ã¯ããµã€ããŒç¯çœªè ãåæ³çã«ãã®æŽ»åãåœè£ ããããã«äœ¿çšãããŸãã
SSHãããã³ã«ãä»ããŠãã©ãã£ãã¯ããã³ããªã³ã°ããæãäžè¬çãªæ¹æ³ãèŠã€ããããšããå§ããŸãããããããè¡ãã«ã¯ãSSHãããã³ã«ã䜿çšããŠãã¹ãŠã®ã»ãã·ã§ã³ããã£ã«ã¿ãªã³ã°ããŸããå³13.ãã©ãã£ãã¯å ã®DNSã»ãã·ã§ã³ã®æ€çŽ¢
ãã®å³ã§ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã«SSHãã©ãã£ãã¯ããªãããããã³ããªã³ã°ã«äœ¿çšã§ãã次ã®ãããã³ã«ãéžæããå¿ èŠããããŸããäŒæ¥ãããã¯ãŒã¯ã§ã¯DNSãã©ãã£ãã¯ãåžžã«èš±å¯ãããŠããããã以äžã§æ€èšããŸãã
DNSã§ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ãããšãããŒãã®1ã€ã«ç°åžžã«å€æ°ã®DNSã¯ãšãªãããããšãããããŸãã
å³14. DNSã¯ã©ã€ã¢ã³ãã»ãã·ã§ã³ã®çµ±èšãå«ããŠã£ãžã§ãã
ãªã¯ãšã¹ãã®éä¿¡å ã§ã»ãã·ã§ã³ããã£ã«ã¿ãªã³ã°ããåŸããã®ç°åžžãªéã®ãã©ãã£ãã¯ãéä¿¡ãããå Žæãšãå®å ããŒãéã§ã©ã®ããã«åæ£ãããããåŠã³ãŸãããå³ã§ã¯å³15ã¯ãäžéšã®ãã©ãã£ãã¯ãããŒã«ã«DNSãµãŒããŒãšããŠæ©èœãããã¡ã€ã³ã³ã³ãããŒã©ãŒã«éä¿¡ãããããšã瀺ããŠããŸãããã ããèŠæ±ã®å€§éšåã¯äžæãªãã¹ãã«éãããŸãã Active Directoryäžã«æ§ç¯ãããäŒæ¥ãããã¯ãŒã¯ã§ã¯ãDNSåå解決ã®ããã®ãŠãŒã¶ãŒã³ã³ãã¥ãŒã¿ãŒã¯ãäŒæ¥ã®DNSãµãŒããŒããã€ãã¹ããããã«å€éšDNSãµãŒããŒã䜿çšããªãã§ãã ããããã®ãããªã¢ã¯ãã£ããã£ãæ€åºãããå Žåã¯ããã©ãã£ãã¯ã§éä¿¡ãããŠãããã®ãšããããã®ãã¹ãŠã®èŠæ±ãéä¿¡ãããå ŽæãèŠã€ããå¿ èŠããããŸããå³15. SSHã»ãã·ã§ã³ã®ãã©ãã£ãã¯ã®æ€çŽ¢
ãã»ãã·ã§ã³ãã¿ãã«ç§»åãããšãäžå¯©ãªãµãŒããŒãžã®ãªã¯ãšã¹ãã§äœãéä¿¡ãããŠãããã確èªã§ããŸãããªã¯ãšã¹ãéã®æéã¯ããªãçããå€ãã®ã»ãã·ã§ã³ããããŸãããã®ãããªãã©ã¡ãŒã¿ã¯ãæ£åœãªDNSãã©ãã£ãã¯ã§ã¯äžè¬çã§ã¯ãããŸããã
å³16. DNSãã©ãã£ãã¯ã®ãã©ã¡ãŒã¿ãŒ
ã»ãã·ã§ã³ã«ãŒããéããšãèŠæ±ãšå¿çã®è©³çŽ°ãªèª¬æã衚瀺ãããŸãããµãŒããŒããã®å¿çã«ã¯ãšã©ãŒã¯ãããŸãããããã¹ãã«ã¯éåžžãããçããŠæå³ã®ããDNSåããããããèŠæ±ãããã¬ã³ãŒãã¯éåžžã«çãããèŠããŸããå³17.çãããDNSã¬ã³ãŒãèŠæ± ãã©ãã£ãã¯åæã«ãããwin-admin-01ãã¹ãã§DNSèŠæ±ã®éä¿¡ã«é¢ããçãããã¢ã¯ãã£ããã£ãè¡ãããŠããããšãããããŸããã次ã¯ããããã¯ãŒã¯ããŒãã®ãã°ãåæããŸãããã®ã¢ã¯ãã£ããã£ã®ãœãŒã¹ã§ãããããè¡ãã«ã¯ãSIEMã«ç§»åããŸãã
ã·ã¹ãã ãã°win-admin-01ãèŠã€ããŠã17ïŒ06ãããã«äœãèµ·ãã£ããã確èªããå¿ èŠããããŸããçãããPowerShellã¹ã¯ãªãããåæã«å®è¡ãããŠããããšãããããŸããå³18.çãããèŠæ± ã®éä¿¡ãšåæã«PowerShellãå®è¡ãã°ã«ã¯ãå®è¡ãããã¹ã¯ãªãããèšé²ãããŸããå³19.ãã°å ã®å®è¡äžã®ã¹ã¯ãªããã®ååã®ä¿®æ£ å®è¡ãããã¹ã¯ãªããã®ååadmin_script.ps1ã¯æ£åœæ§ã瀺ããŠããŸããã管çè ã¯éåžžãç¹å®ã®æ©èœã®ã¹ã¯ãªããã«ååãä»ããŠããŸãããããã§ã¯ååãäžè¬çã§ããããã«ãã¹ã¯ãªããã¯äžæãã¡ã€ã«ã®ãã©ã«ããŒã«ãããŸããéèŠãªç®¡çã¹ã¯ãªãããããã€ã§ã空ã«ãªãå¯èœæ§ã®ãããã©ã«ãã«æ ŒçŽãããããšã¯ã»ãšãã©ãããŸããã
çºèŠãããã€ãã³ãã®äžã«ã¯ãLogos.Utilityã©ã€ãã©ãªããã®ç°åžžãªæå·ã¯ã©ã¹ã®äœæããããŸããããã®ã©ã€ãã©ãªã¯ãŸãã§ãããéçºè ã«ãã£ãŠãµããŒããããªããªã£ãããããã®ã¯ã©ã¹ã®äœæã¯çãããã®ã§ããããã䜿çšãããããžã§ã¯ããèŠã€ããŸããããå³20.ã«ã¹ã¿ã æå·ã¯ã©ã¹ã®äœæ æ€çŽ¢ã䜿çšãããšãDNSãã³ãã«ãç·šæãã2çªç®ã®ãªã³ã¯ã䜿çšããŠãã®ã¯ã©ã¹ã䜿çšãããŠãŒãã£ãªãã£ãèŠã€ããããšãã§ããŸããå³21.ã¯ã©ã¹åã«ããã¹ã¯ãªããã«é¢ããæ å ±ã®æ€çŽ¢ ãããæçµçã«å¿ èŠãªãŠãŒãã£ãªãã£ã§ããããšã確èªããããã«ããã°ã§è¿œå ã®å åãæ¢ããŸããããããã§èšŒæ ãæããã«ãªããŸããã 1ã€ã¯ãã¹ã¯ãªããã䜿çšããŠnslookupãŠãŒãã£ãªãã£ãå®è¡ããããšã§ããå³22.ã¹ã¯ãªããã«ããnslookupãŠãŒãã£ãªãã£ã®å®è¡
nslookup.exrãŠãŒãã£ãªãã£ã¯ãããã¯ãŒã¯èšºæäžã«äœ¿çšãããéåžžã®ãŠãŒã¶ãŒãå®è¡ããããšã¯ã»ãšãã©ãããŸãããéå§ã¯ããŠãŒãã£ãªãã£ã®ãœãŒã¹ã³ãŒãã«è¡šç€ºãããŸããå³23. nslookupãŠãŒãã£ãªãã£ïŒGitHubïŒãèµ·åããããã®ã³ãŒã 2çªç®ã®èšŒæã¯ãã©ã³ãã ãªå€ãçæããããã®ããªããŠããŒã¯ãªæååã§ããå³24.ã¹ã¯ãªããã«ããã©ã³ãã ãªå€ã®çæ ãœãŒã¹ã³ãŒãã§æ€çŽ¢ã䜿çšãããšããã®è¡ã衚瀺ãããŸããå³25.ã©ã³ãã ãªå€ãçæããããã®ã³ãŒã ãã³ãã«ã®ä»®èª¬ã¯ç¢ºèªãããŸããããå®è¡ãããã¢ã¯ã·ã§ã³ã®æ¬è³ªã¯äžæã®ãŸãŸã§ããããã®åŸã®ãã°ã®åæäžã«ã2ã€ã®ããã»ã¹ã®èµ·åã«æ°ä»ããŸãããå³26.ãããªãåŒãåºãã®ããã®ãªãã£ã¹ææžã®æ€çŽ¢
èŠã€ãã£ãããã»ã¹ã®èµ·åè¡ã¯ãããŠã³ããŒãããããã¥ã¡ã³ãã®æ€çŽ¢ã瀺ããŠããŸãããããã£ãŠã仮説ã¯å®å šã«ç¢ºèªãããæ»æè ã¯å®éã«ãã©ãã£ãã¯ãã³ããªã³ã°ã䜿çšããŠããŒã¿ãããŠã³ããŒãããŸããã
çµè«
ææ°ã®èª¿æ»ã¬ããŒãã瀺ãããã«ãæ»æè ãã€ã³ãã©ã¹ãã©ã¯ãã£ã«çãŸãå¹³åæéã¯é·ããŸãŸã§ãããããã£ãŠãèªåé²åŸ¡ããã®ä¿¡å·ãåŸ ããã«ãç©æ¥µçã«è¡åããŠãã ãããã€ã³ãã©ã¹ãã©ã¯ãã£ãšææ°ã®æ»ææ¹æ³ã調æ»ããTIããŒã ïŒFireEyeãCiscoãPT Expert Security CenterïŒãå®æœãã調æ»ã䜿çšããŸãã
èªååãããä¿è·ã®æŸæ£ãæ±ããŠããã®ã§ã¯ãããŸããããã ãããã®ãããªã·ã¹ãã ã®ã€ã³ã¹ããŒã«ãšæ£ããæ§æãæçµçãªãã€ã³ãã§ãããšã¯éããŸãããããã¯æåã®å¿ èŠãªã¹ãããã«ãããŸããã次ã«ãå¶åŸ¡ããããããã¯ãŒã¯ç°å¢ã®éçºãšæ©èœãç£èŠããåžžã«ææ°æ å ±ãææ¡ããå¿ èŠããããŸãã
次ã®ãã³ãã圹ç«ã¡ãŸãã
- . . , .
- . , .
- . , . . , TH , .
- æ¥åžžæ¥åãèªååããŠãåµé åãçºæ®ããåµé çãªè§£æ±ºçãè©Šãæéãå¢ããããšãã§ããŸãã
- 倧éã®ããŒã¿ãåæããããã»ã¹ãç°¡çŽ åããŸãããããè¡ãã«ã¯ãåææ åœè ããããã¯ãŒã¯ãšãããã¯ãŒã¯ããŒãã§äœãèµ·ãã£ãŠãããã1ã€ã®ç»åãšããŠç¢ºèªããã®ã«åœ¹ç«ã€ããŒã«ã䜿çšãããšäŸ¿å©ã§ãããããã®ããŒã«ã¯ãTIã®ææšã亀æããããã®ãã©ãããã©ãŒã ããã©ãã£ãã¯åæã·ã¹ãã ãšSIEMã·ã¹ãã ãã
Positive Technologiesã®PT Expert Security CenterãAnton Kutepov ã«ããæçš¿ã
åæå šäœã¯ãPT Network Attack Discoveryãã©ãã£ãã¯åæã·ã¹ãã ãšMaxPatrol SIEMã»ãã¥ãªãã£ã€ãã³ã管çã·ã¹ãã ã§å®è¡ãããŸããã