ESETã®å°éå®¶ ã¯ãäžçäžã®HPCã¯ã©ã¹ã¿ãŒãæšçãšããæ°ãããã«ãŠã§ã¢ã«ã€ããŠè©±ããŸãããããã¯ããã€ãã®çç±ã§è峿·±ãã§ããã³ãŒãããŒã¹ã®ãµã€ãºãæ¯èŒçå°ããïŒåæããããµã³ãã«ã®ãµã€ãºã¯25 KBã§ããïŒã«ããããããããã«ãŠã§ã¢ã¯LinuxãBSDãããã³Solarisã«å¯Ÿããæ»æãå®è¡ããã®ã«ååè€éã§ãããAIXããã³MicrosoftWindowsã«å¯Ÿããæ»æã«é©ããŠããå¯èœæ§ããããŸãã ããã1ã€ã®éç«ã£ãæ©èœã¯ããªãã¬ãŒã¿ãŒã®ã³ãã³ãã§ææãããµãŒããŒãæ°ããCïŒCã«å€æããæ©èœã§ããå€ãã®ããªãã¯ãšã³ãŒãã®ãµã€ãºãå°ãããããç ç©¶è ãã¡ã¯ãããã³ããã¹ãšåä»ããŸãã-ãã€ãŠãã©ã¯ã¬ã¹ã奪ãã人ã ãæ¬ºããŠæããããããšãåŽæãããããã奜ããªå€ä»£ã®ãªã·ã£ã®ç²Ÿéã«ã¡ãªãã§ã
å°éå®¶ã«ãã£ãŠå ¬éããã調æ»ã§ã¯ãäŸµå®³ã®æšå®åæãã¯ãã«ãèªèšŒãšé åžã®ã¡ã«ããºã ãçµã¿èŸŒã¿é¢æ°ã«ã€ããŠèª¬æããæªæã®ããã³ãŒãã®ãã¯ãã«ã«åæãæäŸããŠããŸãããã®åŸãå°éå®¶ã¯åŠ¥åã®å åãšMITRE ATTïŒCKã®é©ç𿹿³ãææããŸãã
ç§ãã¡ã¯ãè±èªãèŠæã§ããããæ å ±ã»ãã¥ãªãã£ã®åéãç¹ã«ãã«ãŠã§ã¢ã®åæã«ç¡é¢å¿ã§ã¯ãªã人ã ãããã®ãããªåæã翻蚳ããã®ã«è峿·±ãã圹ç«ã€ã ãããšããèããæã£ãŠããŸãããç§ãã¡ã®æèŠãçãããã«ãŠã§ã¢ã
ESET Researchã¯ãLinuxãFreeBSDãããã³Solarisã§å®è¡ããããã«èšèšãããããããŸã§ç¥ãããŠããªãã£ãè€éãªãã«ããã©ãããã©ãŒã ãã«ãŠã§ã¢ã§ããKobalosãåæããŸããã被害è ã¯äž»ã«æåãªçµç¹ã§ããããããœãããŠã§ã¢ã®æšçã«ãããããšã¯ééããããŸããã Kobalosãå±éãããšãäŸµå ¥å ã®ãã¹ãã®ãã¡ã€ã«ã·ã¹ãã ãšãªã¢ãŒãã¿ãŒããã«ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããæ»æè ã¯ä»»æã®ã³ãã³ããå®è¡ã§ããããã«ãªããŸãã
Kobalosã«ã¯åªãããããã¯ãŒã¯æ©èœããããŸããããã·ãã¢ãŒããŸãã¯ããããšããŠæ©èœããCïŒCãµãŒããŒã«ã¢ã¯ãã£ãã«æ¥ç¶ããŸãããããã®ãµãŒããŒèªäœãKobalosã«ãã£ãŠäŸµå®³ãããŠããã®ã¯äžæè°ã§ãããããã䜿çšããããã®ã³ãŒãã¯ããã®ãã«ãŠã§ã¢ã®ãã¹ãŠã®ãµã³ãã«ã«å«ãŸããŠããŸãã
ESET Researchã¯ãåºç¯ãªãããã¯ãŒã¯èª¿æ»ãéããŠãã³ããã¹ã®è¢«å®³è ãç¹å®ããŠéç¥ããããšãã§ããŸããããã®ãœãããŠã§ã¢ããã€éçºããããã¯äžæã§ããã被害è ã«ãã£ãŠç¢ºèªãããæåã®æ¢ç¥ã®æŽ»åã¯ã2019幎ã®çµããã«èšé²ãããŸãããKobalosãå®è¡ããŠããæ»æè ã®ã°ã«ãŒãã¯ã2020幎ãéããŠç¶ç¶ããŸãããLinuxã®æ»æææ³ã¯é²åãç¶ããŠããããã«ãŠã§ã¢ã®äœæè ã¯èšèšã®æ¹åã«å€å€§ãªåªåãæã£ãŠããŸããKobalosã¯ãã®ãããªããã°ã©ã ã®1ã€ã§ãã
äž»ãªçµè«
- Kobalosã¯ãLinuxãFreeBSDãããã³Solarisã§å®è¡ããããã«ããã©ãããã©ãŒã ã®ããã¯ãã¢ã§ãããã®ãœãããŠã§ã¢ãAIXããã³Windowsã«ããååšããå¯èœæ§ããããšããå åããããŸãã
- Kobalos , , , -. Kobalos , .
- Kobalos , .
- Kobalos C&C- . , .
- OpenSSH. Kobalos.
- Kobalos. , , - . , SSH.
è¿å¹ŽESETResearchããã©ããŒããŠããå Žåã¯ãLinuxããã®ä»ã®ããŸãäžè¬çã§ã¯ãªããªãã¬ãŒãã£ã³ã°ã·ã¹ãã çšã«éçºããããµãŒããŒãµã€ããã«ãŠã§ã¢ãæ€çŽ¢ããŠææžåããããšã奜ãããšã«æ°ä»ãããããããŸããããã®ãããªæåã®ã¬ããŒãã®1ã€ã¯ããŠã£ã³ãã£ãŽäœæŠã«æ§ããã㊠ãããã€ã³ã¿ãŒããããã©ãã£ãã¯ã®ãªãã€ã¬ã¯ããã¹ãã ã®éä¿¡ãããã³ãã®ä»ã®æªæã®ããã¢ã¯ãã£ããã£ã飿ºãããããã€ãã®ãœãããŠã§ã¢ãã¡ããªã«ã€ããŠèª¬æããŠããŸãããªãã¬ãŒã·ã§ã³Windigoã¯ãè³æ Œæ å ±ãçãOpenSSHããã¯ãã¢ã§ããEburyã«åºã¥ããŠããŸãã Eburyã¯ãOpenSSHå®è¡å¯èœãã¡ã€ã«ã倿Žããã«SSHã¯ã©ã€ã¢ã³ããšãµãŒããŒãå±éºã«ãããå¯èœæ§ããããŸãã代ããã«ãããŒãããŠããã©ã€ãã©ãªã倿Žããããã¯ãã¢ã®ããŒãåŸã«è³æ Œæ å ±ãéå§ããŠçãããšãã§ããããã«é¢æ°ã«ããããé©çšããŸããã¿ã¹ã¯ã¯ç°¡åã§ã¯ãããŸããããEburyã®äœè ã¯ãªããšãããã解決ããŸããã
æäœWindigoåŸãæã ã¯çºèŠãããã®ããã«ãLinuxã§ããã€ãã®ä»ã®ãã«ãŠã§ã¢ã説æ Mumblehardã ã ãŒã¹ã Shishigaããšãã«OpenSSHã®ããã«ããã¯ãã¢ã®æ°åã説æ ForSSHeã¬ããŒãã®ããŒã¯ãµã€ãã
ãããŸã§ãEburyã»ã©åæãå°é£ãªLinuxãã«ãŠã§ã¢ã«ééããããšã¯ãããŸãããããããä»åã¯ç¶æ³ãç°ãªããŸãããšããªãŒãšã¯ç°ãªããã³ããã¹ã®è¡åã¯ããã»ã©å€§èŠæš¡ã«èŠããŸããã圌ãã«ãã£ãŠå±éºã«ãããããè»ã®æ°ã¯æ°åå°ã§ããããšããªãŒã®å Žåã¯æ°äžå°ã§ãããã®èšäºã§ã¯ãæ»æè ã®æšçã§ããKobalosã®å®å šãªãã¯ãã«ã«åæãšãæœåšçãªè¢«å®³è ããã«ãŠã§ã¢ãèŠã€ããŠé§é€ããã®ã«åœ¹ç«ã€äŸµå ¥ã®çè·¡ã«ã€ããŠèª¬æããŸãã
ç ç²è
ãã«ãŠã§ã¢ãåæããåŸãESETã¯ã³ããã¹ã®ç ç²è ãæ¢ãããã«åºç¯ãªã€ã³ã¿ãŒãããã¹ãã£ã³ã宿œããŸãããç¹å®ã®çºä¿¡ããŒããã䟵害ããããã¹ããšã®TCPæ¥ç¶ã確ç«ããããšãç¹åŸŽãšããç¹å®ã®ããã¯ãã¢ã®åäœãæ¢ããŠããŸããã
ãã®ãœãããŠã§ã¢ã®è€éããèãããšã被害è ã®æ°ãéåžžã«å°ãªãããšã«é©ããŸããããã ããç®æšèªäœã¯æããã«å¶ç¶ã«éžæããããã®ã§ã¯ãããŸããããããã¯ãç§åŠããã³ç ç©¶ãããã¯ãŒã¯ã®äžéšã§ãã髿§èœã³ã³ãã¥ãŒã¿ãŒïŒHPCïŒããã³ãµãŒããŒã§ãããããã®ã³ã³ãã¥ãŒã¿ãŒã®1ã€ã«ã¯ãå°ãªããšã512GBã®RAMãšã»ãŒãã¿ãã€ãã®ãã£ã¹ã¯ã¹ãã¬ãŒãžããããŸããããŸãããšã³ããã€ã³ãã»ãã¥ãªãã£ãã³ããŒïŒç§ãã¡ã§ã¯ãããŸããïŒïŒãªã©ãä»ã®æåãªè¢«å®³è çµç¹ãèŠã€ãããŸããã
å³1.䟵害ãããçµç¹ãå±ããæ¥çãšå°åã
äžéšã®çµç¹ã§ã¯ãè€æ°ã®ãµãŒããŒãåæã«ææããŸãããçºèŠãããã¹ãŠã®è¢«å®³è ã«éç¥ããååããŠãã«ãŠã§ã¢ãåé€ããŸããããã®èª¿æ»ã«åœ¹ç«ã£ãæ å ±ãåçããå ±æããŠããããã¹ãŠã®äººã«æè¬ããŸãã
劥åã®åæãã¯ãã«
æ»æè ãKobalosãã€ã³ã¹ããŒã«ããããã®ç®¡çã¢ã¯ã»ã¹ãååŸã§ããããã«ãã·ã¹ãã ãã©ã®ããã«äŸµå®³ãããããçŽæ¥ç¥ãããšã¯ã§ããŸãããåéããã蚌æ ã«åºã¥ããŠã®ã¿æšæž¬ããããšãã§ããŸãã
sysadminã調æ»ã«åå ãã䟵害ããããã·ã³ã§ãSSHè³æ Œæ å ±ãçãããã°ã©ã ãããã€ã®æšéЬåãããOpenSSHã¯ã©ã€ã¢ã³ããšããŠæç€ºãããŠããããšãçºèŠããŸããããã¡ã€ã«
/usr/bin/ssh
ãŠãŒã¶ãŒåããã¹ã¯ãŒããã¿ãŒã²ãããã¹ãåãèšé²ããæå·åããããã¡ã€ã«ã«ä¿åãã倿Žãããå®è¡å¯èœãã¡ã€ã«ã«çœ®ãæããããŸããããããã£ãŠãå人æ å ±ã®çé£ã¯ãã³ããã¹ãé åžãããæ¹æ³ã®1ã€ã§ãããšèããŠããŸãããŸããå€ãã®åŠè¡ãããã¯ãŒã¯ã䟵害ãããçç±ã説æããããšãã§ããŸããSSHã¯ã©ã€ã¢ã³ããè€æ°ã®å€§åŠã®åŠçãç ç©¶è ã«ãã£ãŠäœ¿çšãããå Žåãããããã¹ãŠã®ãµãŒãããŒãã£ã·ã¹ãã ã®è³æ Œæ å ±ãçãŸããå¯èœæ§ããããŸãã
å¥ã®å¯èœæ§ã®ãããšã³ããªãã€ã³ãã¯ãæ¢ç¥ã®è匱æ§ã®æªçšã§ããå¯èœæ§ããããŸããäžéšã®äŸµå®³ããããã·ã³ã¯ãå€ãããµããŒããããŠããªãããŸãã¯ããããé©çšãããŠããªãOSããã³ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããŠãããããæ¢ç¥ã®æªçšã䜿çšãããªãã·ã§ã³ãèããããŸãããã ããçŸåšäžæãªè匱æ§ã䜿çšããå¯èœæ§ãæé€ããã¹ãã§ã¯ãããŸããã
ãã€ããã©ãŒãã³ã¹ã³ã³ãã¥ãŒãã£ã³ã°ã®ããã®ãããã¯ãŒã¯ãžã®æ»æ
ESETã¯ãCERN Computer Security Teamãªã©ãç ç©¶ããã³åŠè¡ã·ã¹ãã ã®ã€ã³ã·ãã³ãã解決ããäžã§éèŠãªåœ¹å²ãæããçµç¹ãšæ å ±ãå ±æããŠããŸãã圌ãã¯ã2019幎åŸåãã2020幎åã°ã«ãããŠãHPCã³ãã¥ããã£ã3ã€ã®ç°ãªãæ»æã®æ³¢ã«èŠèããããã®ãã¡ã®ããã€ãã¯å ¬ã«çºè¡šããã ããšã確èªããŸããã
äœã¶æã«ãããã調æ»ã®çµæããããã®3ã€ã®æ³¢ãäºãã«é¢é£ããŠããã®ãããããšãåãªãäºæãã¬å¶ç¶ã ã£ãã®ãã¯ãŸã äžæã§ãããã«ãŠã§ã¢ã®ãªãã¬ãŒã¿ãŒã¯ãããŸããŸãªæŠè¡ãææ³ãããã³é£æåºŠã䜿çšããŸãããäžæ¹ãããŸããŸãªæ»æã§ããã€ãã®IPã¢ãã¬ã¹ãäžèŽããã®ã¯å¥åŠãªããšã§ãã
- æåã®æ³¢ã¯ããã®ç ç©¶ã§èª¬æãããŠããKobalosã䜿çšããŸããã
- 第2ã®æ³¢ã¯ãéåžžã«ç°ãªãããŒã«ã»ããã䜿çšããæå·é貚ã®ãã€ãã³ã°ã«çŠç¹ãåœãŠãŸããã
- 3çªç®ã®æ³¢ã¯æå€§ã§ãããããã®ãã€ããŒãã¯ãŸã 決å®ãããŠããŸããã
第2æ³¢ãšç¬¬3æ³¢ã®çµæãšããŠã®äŸµå®³ã®éæ¥çãªå åã¯ã欧å·ã°ãªããã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ãã¥ãŒã¿ã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿ããŒã ã«ãã£ãŠãã€ã³ã·ãã³ãïŒEGI20200421ããã³ïŒEGI2020512ã®åœ¢ã§èª¬æãããŸãã ã
ãããã®æ»æã®ç ç²è ã®äžã§HPCã³ãã¥ããã£ãæ¯é çã§ããçç±ã¯äžæã§ãããã¡ãããHPCã¯è峿·±ããã®ã§ãããéåžžãä»ã®RïŒDãµãŒããŒãããäŸµå ¥ãå°é£ã§ãã忣åã®ã³ãã¥ããã£ããŒã¹ã®ã€ã³ã·ãã³ã察å¿ããã»ã¹ãéããŠãCERNããã³é¢ä¿ããä»ã®ããŒã ã¯ãæ»æã®æ¥å¢ã«éèŠãªåœ¹å²ãæãããŠããå€ãã®å€ãã¢ãŒããã¯ãã£ã𿬡åã®ã»ãã¥ãªãã£æ £è¡ãç¹å®ããŸãããããã«ãHPCã³ãã¥ããã£ã®è¢«å®³è ã®ã»ãšãã©ã¯ãç¹ã«ã·ã¹ãã ã¢ã¯ãã£ããã£ã®ç£èŠã«é¢ããŠã調æ»ã宿œããããã®èšåãæŽã£ãŠããŸããã§ããã
ã³ããã¹ã¬ãã¥ãŒ
Kobalosã«ã¯ã䟵害ãããã·ã¹ãã ã«ã¢ã¯ã»ã¹ãããããã®äœ¿çšã®çè·¡ãé ãããã®å€æ°ã®æ©èœããããŸãã
䟵害ãããã·ã¹ãã ãžã®ã¢ã¯ã»ã¹
ãŸããKobalosã¯ããã¡ã€ã«ã·ã¹ãã ã®èªã¿åããšæžã蟌ã¿ãããã³ç«¯æ«ã®èµ·åãšä»»æã®ã³ãã³ãã®å®è¡ã®ããã®äžè¬çãªã³ãã³ããæäŸããŸããæ®å¿µãªãããããã°ã©ã ã«ã¯ãäœè ã®æå³ã瀺åããç¹å®ã®ãã€ããŒãã¯ãããŸãããã»ãšãã©ã®å Žåããªãã¬ãŒã¿ãŒã¯ã¿ãŒããã«ãä»ããŠã³ãã³ãã·ã§ã«ãå®è¡ããå¿ èŠãªã³ãã³ããå®è¡ããŸãã
å¯çšæ§
第äºã«ãKobalosã«ã¯ããªãã¬ãŒã¿ãŒãšå®è¡äžã®ãã«ãŠã§ã¢ãšã®éã«ãããã¯ãŒã¯æ¥ç¶ã確ç«ã§ããããã«ããå€ãã®æ©èœããããŸãããœãããŠã§ã¢ã¯ãããã€ãã®æ¹æ³ã§å€éšã¢ã¯ã»ã·ããªãã£ãæäŸããŸãã
- TCPããŒããéããçä¿¡æ¥ç¶ãåŸ ã¡ãŸãïŒãã®ã¢ãŒãã¯ããã·ãããã¯ãã¢ãšåŒã°ããããšããããŸãïŒã
- CïŒCãµãŒããŒãšããŠæ§æãããŠããå¥ã®Kobalosã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ããŸãã
- ç¹å®ã®TCPããŒãããçºä¿¡ããããã§ã«å®è¡ãããŠããæ£èŠã®ãµãŒãã¹ãžã®æ¥ç¶ãåŸ æ©ããŠããŸãã
åŸè ã®æ¹æ³ã§ã¯ãå®è¡äžã®ãµãŒãã¹ãKobalosã³ãŒããå«ãå¥ã®ãµãŒãã¹ã«çœ®ãæããå¿ èŠããããŸãããã®æ¹æ³ã®äœ¿çšã«æ°ä»ãããã¹ãŠã®å Žåã«ãããŠãæ»æè ã¯å®è¡äžã®OpenSSHãµãŒããŒã倿Žããå¿ èŠããããŸããããã¡ã€ã«ã¯
sshd
å®å šã«çœ®ãæããããããããµãŒãã¹ãŸãã¯ã·ã¹ãã ãåèµ·åããŠãããã°ã©ã ã¯æ©èœãç¶ããŸããã
èªèšŒãšãããã¯ãŒã¯æå·å
第3ã«ãããã¯ãã¢ãå®è¡ããã«ã¯ãã¯ã©ã€ã¢ã³ããèªèšŒããå¿ èŠããããŸããã¯ã©ã€ã¢ã³ãã«ã¯ãRSA-512ã®ç§å¯éµãšãã¹ã¯ãŒããå¿ èŠã§ãããããããã§ãã¯ããåŸãKobalosã¯RSA-512ã¢ã«ãŽãªãºã ã䜿çšããŠ2ã€ã®16ãã€ãå ¬ééµéµãçæããã³æå·åããæ»æè ã«éä¿¡ããŸãããããã®2ã€ã®ããŒã¯ãåŸç¶ã®ã€ã³ããŠã³ãããã³ã¢ãŠãããŠã³ããã©ãã£ãã¯ã®RC4æå·åã«äœ¿çšãããŸãã
ããŒãã®å€æŽ
第4ã«ãèªèšŒäžããªãã¬ãŒã¿ãŒã¯å¥ã®TCPæ¥ç¶ãä»ããŠå¯Ÿè©±ãç¶ããããšãã§ããŸããèŠæ±ã«å¿ããŠãKobalosã¯ç®çã®ããŒãã®ãªãã¹ã³ãéå§ãããã®åŸã®ãã¹ãŠã®éä¿¡ããã®ããŒãã«è»¢éã§ããŸãããã®ãã£ãã«ãééããããŒã¿ã¯ãèªèšŒäžã«äœæãããRC4ããŒã䜿çšããŠæå·åãããŸãã
ä»ã®äŸµå®³ããããã·ã³ãžã®ãããã·
第5ã«ãKobalosã¯ã䟵害ããä»ã®ãµãŒããŒã«æ¥ç¶ããããã®ãããã·ãšããŠäœ¿çšã§ããŸããããã¯éåžžã®TCPãããã·ã§ã¯ãããŸãããç¹å¥ãªãã±ããã«ããŒã¿ãã«ãã»ã«åããå¿ èŠããããäžèšã®ããŒã倿ŽããµããŒãããŸãããã®ããã«ãæ¥ç¶ããåãæ¿ãããã³ãã³ããéä¿¡ãããŸãã
ãããã·ãé£éãããããšãã§ããŸããã€ãŸãããªãã¬ãŒã¿ãŒã¯è€æ°ã®Kobalosã䟵害ããããã·ã³ã䜿çšããŠãã¿ãŒã²ãããµãŒããŒã«æ¥ç¶ã§ããŸãã
å¯èœæ§ã®ã»ãã
å³2.Kobalosã®æ©èœã®æŠèŠãšã䟵害ããããµãŒããŒã«ã¢ã¯ã»ã¹ããããã®èããããã·ããªãªã
æåã®ã·ããªãªã¯ã䟵害ããããµãŒããŒã«çŽæ¥æ¥ç¶ããŠãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšã§ãããã®å³ã§ã¯ãããã¯ãã¢ã¯OpenSSHãµãŒããŒããã»ã¹å ã§å®è¡ãããæ¥ç¶ã«éä¿¡å ããŒããããããšãæ³å®ããŠããŸãããªãã¬ãŒã¿ã¯ãæ£ããéä¿¡å TCPããŒãã䜿çšããŠããã¯ãã¢ãšéä¿¡ããå¿ èŠããããŸãã
2çªç®ã®ã·ããªãªã¯ééããªãæãå°é£ã§ãããKobalosã®ç¬èªã®æ©èœãä»å±ããŠããŸãããªãã¬ãŒã¿ãŒã¯ããã®ãœãããŠã§ã¢ãå®è¡ããŠããä»»æã®ãµãŒããŒããCïŒCãµãŒããŒãå®è¡ã§ããŸããããã«è¿œå ã®ã³ãŒãã¯å¿ èŠãããŸããããã¹ãŠã®æ©èœããã§ã«çµã¿èŸŒãŸããŠããŸããèµ·ååŸãCïŒCãµãŒããŒã¯æ¥ç¶ãããŠãããããã®ãªã¹ãããã§ãã¯ãããªãã¬ãŒã¿ãŒã¯ãããã®ããããã«æ¥ç¶ã§ããŸããæåŸã®ããŒãã¯èªèšŒãå¿ èŠãšããRC4ããŒäº€æã䜿çšããŠãšã³ãããŒãšã³ãã®æå·åã宿œããŸãããã®ãããªäœæ¥ã¹ããŒã ã確ä¿ããã«ã¯ããµãŒããŒBã®Kobalosã€ã³ã¹ã¿ã³ã¹ã«ãµãŒããŒAã§å®è¡ãããŠããCïŒCãµãŒããŒã®IPã¢ãã¬ã¹ãšããŒããå¿ èŠã§ãããµãŒããŒBã¯ãµãŒããŒAãšã®ã¿ãã©ãã£ãã¯ã亀æãããªãã¬ãŒã¿ãŒã®IPã¢ãã¬ã¹ãé衚瀺ã«ããŸãã
3çªç®ã®ã·ããªãªã§ã¯ããµãŒããŒAã䜿çšããŠãµãŒããŒCãžã®æ¥ç¶ããããã·ããŸããããã¯ãèªèšŒãšåŒ·å¶çãªãšã³ãããŒãšã³ãæå·åã«ãé©çšãããŸãããªãã¬ãŒã¿ãŒã¯ããµãŒããŒAããCã«æ¥ç¶ãããšãã«éä¿¡å ããŒããèšå®ã§ããŸããããã¯ããµãŒããŒAã䜿çšããŠãç¹å®ã®ããŒãããã®æ¥ç¶ãåŸ æ©ããŠããKobalosã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ã§ããããšãæå³ããŸãã
ã³ããã¹ãã¯ãã«ã«åæ
åããŠãããã€ã®æšéЬåãããOpenSSHãµãŒããŒãåæããŸãããKobalosã®æªæã®ããã³ãŒããšããŒã¿ã®ãµã€ãºã¯éåžžã«å°ãããx86-64ãµã³ãã«ã®å Žåã¯çŽ25KBã§ããäžæè°ãªããšã«ããã¹ãŠã®ã³ãŒãã1ã€ã®é¢æ°ã«ããã¯ãããŠããŸããæ£åœãªOpenSSHã³ãŒãã§ã¯ããã®é¢æ°ãžã®åŒã³åºãã¯1ã€ã ãã§ãã
Kobalosã¯è€éãªãœãããŠã§ã¢ã§ããæããã«ããã®éçºè ã¯ãã®äœæã«å€å€§ãªåªåãæã£ãŠããŸããèè ã¯å€ãã®æ©èœãå®è£ ããç¬èªã®é£èªåãå®è£ ããŸããã
é£èªå
å¶åŸ¡ãããŒã®äŸå€çãªå¹³åŠå
ã³ãŒãã1ã€ã®é¢æ°ã«åãŸããšããäºå®ã¯ãå¶åŸ¡ãããŒãç·åœ¢ã§ããããšãæå³ããŸãããKobalosã¯ãã®é¢æ°ãååž°çã«åŒã³åºããŠãå¿ èŠãªãµãã¿ã¹ã¯ãå®è¡ããŸãã
å³3.Kobaloså¶åŸ¡ãããŒã°ã©ãã
颿°ã®æåã®ãã©ã¡ãŒã¿ãŒã¯ãå®è¡ããã¢ã¯ã·ã§ã³ã§ãã Kobalosã¯37ã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸãããããã¯ãKobalosã®çµã¿èŸŒã¿æ©èœã®ä»é²ã«èšèŒãããŠãã ããã®ãœãããŠã§ã¢ã®çŸåšããã³å°æ¥ã®ããŒãžã§ã³ãåæããã®ã«åœ¹ç«ã¡ãŸãããã®é¢æ°
SIGCHLD
ã¯ãåããã»ã¹ãæ£åžžã«çµäºã
SIGALRM
ãæ¥ç¶ã¿ã€ã ã¢ãŠããåŠçããããã®ã·ã°ãã«ãã³ãã©ãŒãšããŠãæ©èœããŸã ã
Kobalosã®ãœãŒã¹ã³ãŒãã«é¢ããéãã以äžã®Cã³ãŒããã³ã³ãã€ã«ãããããªãã®ã§ãã倿ã®äžéšã¯ãã³ã³ãã€ã©ã«ãã颿°ã®ã€ã³ã©ã€ã³åã«ãã£ãŠèªååã§ããŸããããã¹ãŠã®é¢æ°ã«æ°å€èå¥åãå²ãåœãŠã颿°å ã§åãæ°ã®åŒæ°ãåŠçããŸããæäœæ¥ãŸãã¯ç¹å¥ãªå·¥å ·ãå¿ èŠã§ãã
| å | åŸ |
|---|---|
|
|
å³4.ãã®Cã³ãŒãã¯ãå¶åŸ¡ãããŒã調æŽããåŸã®KobalosãœãŒã¹ã³ãŒãã®å€èгã瀺ããŠããŸãã
æå·åãããæååå€
Kobalosã®ã³ãŒããšããŒã¿ã«ã¯ããã¬ãŒã³ããã¹ãã®æååå€ã¯å«ãŸããŠããŸãããããã§ã¯ãRC4ã§æå·åãããçãæååãããã€ã䜿çšããŠããŸãããããã¯ãããã°ã©ã ãšã®æåã®å¯Ÿè©±ã®çŽåŸã§ãèªèšŒã®åã«åŸ©å·åãããŸããåæãããã¹ãŠã®ãµã³ãã«ã«å¯ŸããŠã1ã€ã®ããŒã䜿çšãããŸã-
AE 0E 05 09 0F 3A C2 B5 0B 1B C6 E9 1D 2F E3 CE
ã
ãã³ãŒããããæååå€ïŒ
- ïŒ sïŒ s
- / dev / ptmx
- ptem
- ldterm
- ttcompat
- / dev / tty
- ïŒ s
- ïŒ d
- /
- \
- ïŒ dãïŒ d
- win3.11
- win95
- winNT
- åã€??
- \\ã\ãã€ã\ 2
- ïŒ sïŒ sãïŒ s
- / dev / ptc
åæããKobalosãµã³ãã«ã§ã¯ãââ倪åã®å€ïŒ1ãš6-9ïŒã®ã¿ã䜿çšãããŠããŸããä»ã®ããã€ãã®ããŒãžã§ã³ã§äœ¿çšãããå¯èœæ§ããããŸãããä»ã®ãã®ã¯èšåãããŠããŸãããç¹ã«ïŒ
- 10è¡ç®ãš12ã16è¡ç®ã¯Windowsåºæã®ããã§ãã
- 18è¡ç®ã¯ãAIXäžã®ç䌌端æ«ããã€ã¹ãã©ã€ããŒãžã®ãã¹ã§ãã
- 3ã5è¡ç®ã¯ãSolarisç䌌端æ«ã·ã¹ãã ã³ãŒã«ã§äœ¿çšãããŸãã
ä»ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ã®ååšã«ã€ããŠç ç©¶è ã«èª€ã£ãæ å ±ãæäŸããããšãããªãã·ã§ã³ãæé€ããããšã¯ã§ããŸããã3ã€ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãµããŒãã確èªããããšãèãããšãããã«å€ãã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããããšããŠãåœç¶ã®ããšã§ããäžæ¹ãWindows3.11ãšWindows95ã¯25幎以äžåã®ãã®ã§ãããããã®ã¬ã¬ã·ãŒã·ã¹ãã çšã®Kobalosã®ããŒãžã§ã³ã¯ãããŸããïŒ
調æ»ã«å察
èªèšŒããããšã調æ»ã劚ããããã«ããã€ãã®ææ³ãããã¯ãã¢ããã»ã¹ã«é©çšãããŸãã
RLIMIT_CORE
ããã»ã¹ãã¯ã©ãã·ã¥ããå Žåã«ã«ãŒãã«ãã³ããçæãããªãããã«ãå€ã¯ã¯ãªã¢ãããŸãã- ããã»ã¹ã®äžæãå°é£ã«ããããã«ãã»ãšãã©ã®ä¿¡å·ã¯ç¡èŠãããŸãã
å³5.Kobalosã¯ãã¯ã©ãã·ã¥æã®ã«ãŒãã«ãã³ããåé¿ããã»ãšãã©ã®ã·ã°ãã«ãç¡èŠããŸãã ããšãã°ãgdbã䜿çšããŠããã»ã¹ãæåã§ãã³ãã
ãŠããæ§æã«åé¡
RLIMIT_CORE
ããªã ããšã«æ³šæããããšãéèŠ
gcore
ã§ãããã®å¶éã¯ãããã»ã¹ãã¯ã©ãã·ã¥ãããšãã®ã¡ã¢ãªãã³ãã®æå€§ãµã€ãºã決å®ããããã«ã«ãŒãã«ã«ãã£ãŠäœ¿çšãããŸãã
ã¿ã€ã ã¹ã¿ã³ã
䟵害ããããµãŒããŒã®ãã¡ã€ã«ã·ã¹ãã ã®åæã§ã¯ãèšå®åŸã眮ãæãããããã¡ã€ã«ã®ã¿ã€ã ã¹ã¿ã³ãïŒ
ssh
è³æ Œæ å ±ã®çé£ã¢ãžã¥ãŒã«ã®è¿œå ã
sshd
Kobalosã®å±éãªã©ïŒãæ¹ãããããŠçæãåé¿ããŠããããšã瀺ãããŸããã
æ§æ
Kobalosã«ã¯ããœãããŠã§ã¢æ©èœãæå¹ãŸãã¯ç¡å¹ã«ããéçæ§æããããŸãã衚1ã«ãæ§æã®äžéšãšèŠãªããããã£ãŒã«ãã瀺ããŸããå³6ã«ãå®éã®äŸã瀺ããŸãã
衚1.éçæ§æKobalosã®æ§é ïŒ
| ãµã€ãºïŒãã€ãïŒ | 説æ |
|---|---|
| 2 | ããããããŒãžã§ã³çªå·ã§ããèªèšŒãæåãããšéä¿¡ãããŸããèŠã€ãã£ããã¹ãŠã®ãµã³ãã«ã§éèŠã§ã0xB03
ïŒä»ã®ãã¹ãŠã®KobalosããŒã¿ãšåæ§ã«ãæé«ããæäœã®åœ¢åŒã§éä¿¡ãããããšãèæ ®ããŠïŒã |
| 320 | RSAå ¬ééµã¢ãžã¥ãŒã«ãç¹å¥ãªãã€ããªåœ¢åŒã§æå·åãããŸãã |
| 2 | ãªãã¹ã³ããTCPããŒãããŒãã«èšå®ãããšãKobalosã¯ããŒãããªãã¹ã³ããŸããããä»ã®æ¹æ³ã䜿çšããŠããã¯ãã¢ãžã®æ¥ç¶ãåŸ æ©ããŸãã |
| 2 | C&C-, . , â . |
| 2 | . ( ) ( ). |
| 4 | IP- C&C- . Kobalos . |
| 2 x 16 | TCP-, C&C-. |
| 16 | MD5- , . |
å³6.sshdã«åã蟌ãŸããKobalosãµã³ãã«ã®ãµã³ãã«æ§æã
Kobalosãå éšã§å®è¡ãããå Žå
sshd
ããŸãã¯åå¥ã®å®è¡å¯èœãã¡ã€ã«ãšããŠå®è¡ãããå Žåãæ§æã®äžéšã¯ç°ãªã ãŸããåŸè ã®å Žåããªã¢ãŒãCïŒCãµãŒããŒã®ã¢ãã¬ã¹ïŒ
remote_c2_addr
ïŒãŸãã¯ãªã¹ãã³ã°ããŒãïŒ
listen_port
ïŒãå¿ èŠã§ã ã
å±éãšä¿å
KobalosãOpenSSHãµãŒããŒã®äžéšãšããŠå®è¡ããããã«ãããã€ãããŠããå Žå
sshd
ãæªæã®ããã³ãŒãã远å ããã«ã¯ãã¡ã€ã«ã åã³ã³ãã€ã«ããå¿ èŠããããŸããããã€ã®æšéЬåãããããŒãžã§ã³ã®OpenSSHãšãããšãã°ããã±ãŒãžãããŒãžã£ãŒããã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããå¿ èŠãããããŒãžã§ã³ãæ¯èŒããŸããããªãã¬ãŒã¿ãŒã¯ããµãŒããŒã«ãã§ã«ã€ã³ã¹ããŒã«ãããŠããæ£ãããœãŒã¹OpenSSHã«åºã¥ããŠKobalosãã³ã³ãã€ã«ããŠããããã§ããææããå®è¡å¯èœãã¡ã€ã«ã¯ãå ã®å®è¡å¯èœãã¡ã€ã«ã眮ãæããåã«ã被害è ã®ãã·ã³ã§ã³ã³ãã€ã«ãããå¯èœæ§ããããŸããã»ãšãã©ã®å Žåããã®ãããªã¹ããŒã ã¯ãããŒãžã§ã³ã®äžäžèŽã鲿¢ããããšã«ãã£ãŠãœãããŠã§ã¢ã®å®å šæ§ã確ä¿ããããã«éžæãããŸãããããã«ãããã©ã€ãã©ãªã®éäºææ§ãçºçããå¯èœæ§ããããŸãã
亀æããããšã«æ³šæããå¿ èŠããããŸã
sshd
rootæš©éãå¿ èŠã§ãããã ããCïŒCãµãŒããŒã«æ¥ç¶ããããTCPããŒãã§ãªãã¹ã³ãããããåå¥ã®ãã¡ã€ã«ãšããŠã®Kobalosã®ããŒãžã§ã³ããããŸããããããå®è¡ããããã«ç®¡çè æš©éã¯å¿ èŠãããŸãããããã¡ã€ã«ã·ã¹ãã ãšã³ãã³ãã®ã»ãããžã®ã¢ã¯ã»ã¹ã¯ãçŸåšã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ã¬ãã«ã«ãã£ãŠå¶éãããŸãã
ããã¯ãã¢ã®çžäºäœçš
ããã¯ãã¢æ¥ç¶
Kobalosã®æ³šç®ãã¹ãæ©èœã®1ã€ã¯ããªãã¬ãŒã¿ãŒãšäŸµå ¥å ã®ãã¹ãéã®æ¥ç¶ã確ç«ããéã®æè»æ§ã§ããããã¯ã次ã®3ã€ã®æ¹æ³ã§å®è¡ã§ããŸãã
- æå®ãããTCPããŒãããªãã¹ã³ããŸãïŒããã·ãã¢ãŒãïŒã
- CïŒCãµãŒããŒã«æ¥ç¶ãïŒã¢ã¯ãã£ãã¢ãŒãïŒããªãã¬ãŒã¿ãŒããã®ãµãŒããŒãä»ããŠæ¥ç¶ããã®ãåŸ ã¡ãŸãã
- TCPããŒãã§ãªãã¹ã³ããæ¢åã®ãµãŒãã¹ã眮ãæããç¹å®ã®éä¿¡å TCPããŒãããã®æ¥ç¶ãåŸ æ©ããã
Kobalosã®éçæ§æã䜿çšãããšãäžåºŠã«è€æ°ã®ã¡ãœãããã¢ã¯ãã£ãåã§ããŸãããåæããåãµã³ãã«ã§ã¯ãââ1ã€ã ããã¢ã¯ãã£ãåãããŸããã
åŸè ã®æ¹æ³ã§ã¯ãå®è¡å¯èœããŒã¢ã³ã倿Žããå¿ èŠããããŸããããã€ã®æšéЬåãããããŒãžã§ã³ã¯ãå³7ã«ç€ºãããã«ãæ°ããTCPæ¥ç¶ãåãå ¥ãããã³ã«Kobalosã³ãŒããåŒã³åºããŸããæ¥ç¶ãç¹å®ã®TCPããŒãããã®ãã®ã§ããå Žåãããã¯ãã¢ã¯ãããåãå ¥ããããšãã§ããŸããããŒãçªå·ãäžèŽããå Žåã颿°ã¯äœãè¿ãããæ¥ç¶ãéãããããšãµãããã»ã¹ã¯çµäºããŸããããŒããèŠå®ã®ããŒãã«å¯Ÿå¿ããŠããªãå Žåãããã°ã©ã ã¯äœããããæ£åžžã«æ©èœãç¶ããæ£åœãªãµãŒãã¹ã®ã³ãŒãã«äœæ¥ã転éããŸãã
å³7. æ°ããTCPæ¥ç¶ãåãå ¥ããåŸãããã€ã®æšéЬåãããOpenSSH颿°ãã颿°ãåŒã³åºããããã¯ç§ãã¡ãæãããèŠããã®ã§ãããOpenSSHãµãŒããŒã«ãã£ãŠã®ã¿æªçšãããŠããŸãããã ããããã¯ã€ã³ã¿ãŒããããã¹ãã£ã³ãããšãã«æ€åºã§ããæ¹æ³ã§ãããããããŒã¿ã«èª€ããããå¯èœæ§ããããŸãã å³8ã«ç€ºãããã«ãKobalosã¯TCPããŒã55201ã§ãªãã¹ã³ããŠããŸãã
kobalos
main
å³
8.55201ãšã®éä¿¡å ããŒãã®æ¯èŒãKobalosã¯ãåä¿¡TCPæ¥ç¶ããã£ã«ã¿ãªã³ã°ããããã®è¿œå ã®æ¹æ³ãå®è£ ããéä¿¡å ããŒãã16ããŒãã®ãªã¹ããšæ¯èŒããŸãã
å³9.éä¿¡å ããŒããš16ããŒãã®ãªã¹ãã®æ¯èŒã
16ããŒãã®ãªã¹ãïŒ
| 20 | 567 | 2734 | 22392 |
| 21 | 982 | 5392 | 33921 |
| 53 | 1821幎 | 11568 | 44983 |
| 230 | 1912幎 | 19678 | 55201 |
ãã ããèŠã€ãã£ããµã³ãã«ã®ãããããã®ãã£ã«ã¿ãŒã䜿çšããŠããŸããã以åã®ããŒãžã§ã³ã®ããã¯ãã¢ã§äœ¿çšãããŠããå¯èœæ§ããããŸãã
èªèšŒ
æ¥ç¶ã確ç«ãããåŸãèªèšŒãå®è¡ãããŸããããã«äœæ¥ãé²ããã«ã¯ãRSAç§å¯éµãš32ãã€ãã®ãã¹ã¯ãŒããå¿ èŠã§ããKobalosã¯ã©ã€ã¢ã³ãã¯ãææãããµãŒããŒã«æåã®320ãã€ãã®ãã±ãããéä¿¡ããŸãããã®æ§é ã衚2ã«ç€ºããŸãã
衚2.èªèšŒãã±ããã®æ§é ïŒç§å¯RSAããŒã䜿çšããŠæå·åïŒïŒ
| ãµã€ãºïŒãã€ãïŒ | 説æ | å€ |
|---|---|---|
| å | äžæè°ãªãã©ã¡ãŒã¿ãŒ | 0x7FFF000A
|
| 2 | ãã€ã³ãã£ã³ã°ããŒã | ã®å Žå0x0000
ãKobalosã¯ã©ã³ãã ãªããŒããéžæããŸããã®å Žå 0xFFFF
ãæ¢åã®TCPæ¥ç¶ã䜿çšããŸãã |
| 1 | éä¿¡ãã£ãã«èå¥å | åžžã«ãšããŠèšå®ãããŠãããã0xFF
ã§ãã |
| 32 | ãã¹ã¯ãŒã | ãã¹ã¯ãŒãå€ã¯ãéçæ§æã®MD5ããã·ã¥ãšäžèŽããŸãã |
| 280 | å å¡« |
ãã±ããã®æåã®64ãã€ãã¯ãæ§æãããRSA-512å ¬ééµã®ã¢ãžã¥ã©ã¹ãšææ°ã䜿çšããŠåŸ©å·åãããŸã
0x10001
ïŒå³11ãåç §ïŒã次ã«ãå³10ã«ç€ºãããã«ãMD5ããã·ã¥ã32ãã€ãã®ãã¹ã¯ãŒãã«é©çšããããã®çµæãéçæ§æããã®æ å ±ãšæ¯èŒãããŸãã
å³10.320ãã€ããåä¿¡ããåŸãèªèšŒãå®è¡ãããŸãã
å³11.RSA-512å ¬ééµã®ããŒãã
Kobalosã¯ãå ¬éRSAããŒã䜿çšããŠããããªãéä¿¡ã«äœ¿çšãããRC4ããŒãæå·åããŠèšå®ããŸãã1ã€ã¯çä¿¡ãã©ãã£ãã¯çšããã1ã€ã¯çºä¿¡ãã©ãã£ãã¯çšã§ããKobalosã¯ãå¿çã§æå·åãããããŒãéä¿¡ããŸãã
衚3.Kobaloså¿çã®æ§é ïŒRSAå ¬ééµã§æå·åïŒïŒ
| ãµã€ãºïŒãã€ãïŒ | 説æ | å€ |
|---|---|---|
| å | äžæè°ãªãã©ã¡ãŒã¿ãŒ | 0x7FFF000A
|
| 16 | çä¿¡ãã©ãã£ãã¯çšã®RC4ã㌠| 䟵害ããããã¹ããžã®ãã©ãã£ãã¯ã«äœ¿çšãããRC4ããŒã |
| 16 | çºä¿¡ãã©ãã£ãã¯çšã®RC4ã㌠| 䟵害ããããã¹ãããã®ãã©ãã£ãã¯ã«äœ¿çšãããRC4ããŒã |
| 2 | ãã€ã³ããããããŒã | ã¢ã¯ãã£ããã£ãã«ãšããŠäœ¿çšãããTCPããŒããå€0xFFFF
ã¯ãçŸåšã®æ¥ç¶ã䜿çšããããšãæå³ããŸãã |
| 282 | å å¡« |
ã¢ã¯ãã£ããã£ãã«
èªèšŒã«åæ Œãããšãã¢ã¯ãã£ããã£ãã«ã¯å¥ã®ããŒãã䜿çšã§ããŸããã¯ã©ã€ã¢ã³ãèªèšŒã§ã¯ãæå·åãããã¡ãã»ãŒãžã«ããã€ã³ãããŒãããæå®ããå¿ èŠãããããšã«æ°ä»ãããããããŸããã
- ãã®å€ããšç°ãªãå Žåã
0xFFFF
Kobalosã¯æå®ãããTCPããŒãã®ãªãã¹ã³ãéå§ããŸãã - å€ããŒãã®å Žåãããã¯ãã¢ã¯1024ãè¶ ããã©ã³ãã ããŒãã®ãªãã¹ã³ãéå§ããŸãã
åè¿°ã®ããã«ãèªèšŒå¿çã§ã¯ãRC4ããŒã®ãã¢ãšãšãã«ãæ°ããéããããŒãã®çªå·ãéä¿¡ãããŸããå¿ èŠã«å¿ããŠã远å ã®TCPæ¥ç¶ãäœæã§ããŸããå€ããã€ã³ãã£ã³ã°ããŒããšããŠéä¿¡ããã
0xFFFF
å ŽåãçŸåšã®æ¥ç¶ã䜿çšãããŸãã
ãããã®TCPæ¥ç¶ãä»ããåŸç¶ã®éä¿¡ã¯ãã±ããã«ã«ãã»ã«åããããã®åœ¢åŒã
衚4ã«ç€ºããŸãã 衚4. Kobalosãã±ããæ§é ïŒ
| ãµã€ãºïŒãã€ãïŒ | å€ |
|---|---|
| 1 | äžæè°ãªæå³ïŒ0x7F
ïŒ |
| 2 | ãã€ããŒã |
| 1 | éä¿¡ãã£ãã«èå¥åã |
| 1 | éä¿¡ãã£ãã«èå¥åã |
| ãã€ããŒããµã€ãº | ãã€ããŒãïŒRC4ã§æå·åïŒã |
Kobalosã¯ãæ¥ç¶ããããªãã¬ãŒã¿ãŒã«ãã±ãããéä¿¡ããæåã®äŒæ¥ã§ããããã±ãŒãžã«ã¯ããã¹ãåãã«ãŒãã«ããŒãžã§ã³ãªã©ããã·ã³ã«é¢ããåºæ¬æ å ±ãå«ãŸããŠããŸããå³12ã¯ãããã±ãŒãžå ã®ã«ãã»ã«åã®ã¬ãã«ã瀺ããŠããŸãã
å³12.䟵害ããããã¹ããããªãã¬ãŒã¿ãŒã«éä¿¡ãããæ å ±ã
å³13ã¯ãKobalosãšãã®é¡§å®¢ã®éã®éä¿¡ããã»ã¹ã瀺ããŠããŸãã
å³13.Kobalosãããã¯ãŒã¯ãããã³ã«ã®ã·ãŒã±ã³ã¹å³ã
ããã¯ãã¢ç®¡ç
èªèšŒåŸããªãã¬ãŒã¿ãŒã¯ããã¯ãã¢ã«ããŸããŸãªã³ãã³ããçºè¡ã§ããŸããããããã«ããŽãªã«åé¡ããŸããã
- Kobalosã«ææããä»ã®ãµãŒããŒã«æ¥ç¶ãããããã·ãšããŠæ©èœããŸãã
- ãã¡ã€ã«ã·ã¹ãã ãžã®ãã¡ã€ã«ã®èªã¿åããšæžã蟌ã¿ã
- äŸµå ¥å ã®ãã¹ãã§ç䌌端æ«ãèµ·åããŠã¢ã¯ã»ã¹ããŸãã
- æ¥ç¶ããããããã«ã¢ã¯ã»ã¹ã§ããKobalosCïŒCãµãŒããŒã®èµ·åãšç®¡çã
ã³ãã³ãã¯ã¢ã¯ãã£ããã£ãã«ã«ã«ãã»ã«åãããŸãããããã¯èå¥ãã€ãã§å§ãŸãããã®ã³ãã³ãã«ãã£ãŠè§£æããããã©ã¡ãŒã¿ãŒãç¶ããŸãããã®äœæ¥ã§èª¬æãããŠããã³ãã³ãã¯Kobalosã«ãã£ãŠåŠçãããŸããã€ãŸãããªãã¬ãŒã¿ãŒã¯ç¹å¥ãªã¯ã©ã€ã¢ã³ãã䜿çšããŠã䟵害ãããã·ã¹ãã ã«ã³ãã³ããéä¿¡ããŸããKobalosã¯ãæåã®èå¥åãã€ãã䜿çšããŠåã圢åŒã§å¿çããå¿çã¯åãã¯ã©ã€ã¢ã³ãã«ãã£ãŠåŠçãããŸããããšãã°ãèªèšŒåŸãã³ãã³ãããã¹ãæ å ±ã®éä¿¡ãïŒ
0x04
ïŒãæå®ã§ããŸã ã
ãããã·ãšããŠäœ¿çšãã
ãªãã¬ãŒã¿ãŒã¯ãäŸµå ¥å ã®ãã·ã³ã«ã€ã³ã¹ããŒã«ãããŠããKobalosã䜿çšããŠãä»ã®ã·ã¹ãã ã®ããã¯ãã¢ã®ä»ã®ã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ã§ããŸãããããã·ã¢ãŒãã¯ãèªèšŒãšã«ãã»ã«åã«äžèšã®ç¹å¥ãªãã±ãããµã€ãºã䜿çšããŸããã€ãŸããéåžžã®TCPãããã·ã§ã¯ãããŸããã
ãµãŒãããŒãã£ã®ãã·ã³ã«æ¥ç¶ããå Žåããªãã¬ãŒã¿ãŒã¯éä¿¡å TCPããŒããéžæã§ããŸããããã«ãããç¹å®ã®ããŒãããã®æ¥ç¶ãåŸ æ©ããŠããKobalosã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ã§ããŸãã代æ¿ããŒããä»ããã¢ã¯ãã£ããã£ãã«ã®åæ¥ç¶ããµããŒããããŠããŸãããã®ããã«ãç¹å¥ãªã³ãã³ããäžããããŸãã
ãã®å Žåã®ã¿ã¹ã¯ã®1ã€ã¯ãäžå®ã¬ãã«ã®ãªãã¬ãŒã¿ãŒã®å¿åæ§ã確ä¿ããããšã§ãããšã³ãããŒãã¯ãä»ã®äŸµå®³ããããã·ã³ã®IPã¢ãã¬ã¹ã®ã¿ãèªèãããªãã¬ãŒã¿ãŒã®IPã¢ãã¬ã¹ã¯èªèããŸããããªãã¬ãŒã¿ãŒã®ã¢ãã¬ã¹ãããã«é ãããã«ã䟵害ããããããã·ãã·ã³ã®ãã§ãŒã³ãäœæã§ããŸããå³14ã¯ããã®ãããªã·ããªãªã瀺ããŠããŸãã
å³14.Kobalosããããã·ãšããŠäœ¿çšãããŠããŸãã
ãããã·å¶åŸ¡ã³ãã³ãã«ã€ããŠã¯ã衚5ã§èª¬æããŠããŸãã
衚5. Kobalosããããã·ãšããŠäœ¿çšããããã®ã³ãã³ãïŒ
| ã³ãã³ã | 説æ | ãªãã·ã§ã³ |
|---|---|---|
| 0x01 | Kobalosã«ãã£ãŠäŸµå®³ãããå¥ã®ãã¹ããžã®æ¥ç¶ã確ç«ããŸãã | ãªã¢ãŒãã¢ãã¬ã¹ãéä¿¡å ããŒãããšã³ãããŒããèªèšŒã¡ãã»ãŒãžïŒ320ãã€ãïŒã |
| 0x03 | . , TCP-. | . |
| 0x05 | . |
èªèšŒåŸããªãã¬ãŒã¿ãŒã¯ã·ã¹ãã ã«å¯ŸããŠä»»æã®ãã¡ã€ã«ãèªã¿æžãã§ããŸããKobalosãããã¯ãŒã¯ãããã³ã«ã§ã¯ãã«ãã»ã«åããããã€ããŒãã¯16ãããæŽæ°ã䜿çšããŠå®çŸ©ãããŸããããã¯ããªãã¬ãŒã¿ãŒãéä¿¡ã§ããã®ã¯64Kãã±ããã®ã¿ã§ããããšãæå³ããŸããããšãã°ããã¡ã€ã«ã«200 KBãæžã蟌ã¿ããå Žåã4ã€ã®æ£åžžãªæžã蟌ã¿ã³ãã³ããå®è¡ããå¿ èŠããããŸããreadã³ãã³ãã«ã¯ãããã«å³ããå¶éããããŸããäžåºŠã«èªã¿åãããã³éä¿¡ã§ããã®ã¯1000ãã€ãã®ã¿ã§ãã
衚6ã«ããã¡ã€ã«ã·ã¹ãã ãæäœããããã®ã³ãã³ãã瀺ããŸãã
衚6.ãã¡ã€ã«ãèªã¿æžãããããã®ã³ãã³ãïŒ
| ã³ãã³ã | 説æ | ãªãã·ã§ã³ |
|---|---|---|
| 0x18 | æžã蟌ã¿çšã«ãã¡ã€ã«ãéããããã§ãªãå Žåã¯ããã¡ã€ã«ãäœæãããŸãã | æ€çŽ¢äœçœ®ããã¡ã€ã«ãžã®ãã¹ã |
| 0x1A | ãã¡ã€ã«ãžã®æžã蟌ã¿ã | æžã蟌ãããŒã¿ãæ€çŽ¢äœçœ®ããäžæžããããŸãã |
| 0x1C | èšé²åŸã«ãã¡ã€ã«ãéããã | |
| 0x1D | ãã¡ã€ã«ãéããŠèªã¿åãã | æ€çŽ¢äœçœ®ããã¡ã€ã«ãžã®ãã¹ã |
| 0x20 | èªã¿åãåŸã«ãã¡ã€ã«ãéããã |
ç䌌端æ«ã®äœæ
ãã®æ©èœã«ãããèªèšŒããããªãã¬ãŒã¿ãŒã¯ãæ°ããç䌌端æ«ã«ã·ã§ã«ãäœæããä»»æã®ã³ãã³ããå®è¡ã§ããŸãããããè¡ãã«ã¯ã
衚7ã®ã³ãã³ãã䜿çšããŸãã 衚7.ç䌌端æ«ãäœæããã³ç®¡çããããã®ã³ãã³ãïŒ
| ã³ãã³ã | 説æ | ãªãã·ã§ã³ |
|---|---|---|
| 0x12 | æ°ããæ¬äŒŒç«¯æ«ã®çºå£²ã | ã·ã§ã«ãžã®ãã¹ïŒããšãã°/bin/sh
ïŒãåŒæ°ã |
| 0x0D | ç䌌端æ«ãŠã£ã³ããŠã®ãµã€ãºãæå®ããŸãã | TIOCSWINSZwinsize
ã«ãã£ãŠåãå ¥ããããæ§é å€ã |
| 0x14 | ç䌌端æ«ãéããã | |
| 0x16 | ç䌌端æ«ãžã®æžã蟌ã¿ã | æžã蟌ãããŒã¿ã |
端æ«ããã®ããŒã¿ã¯ãªãã¬ãŒã¿ãŒã«éä¿¡ãããããŒã¿ã®åŸã«çµäºã³ãã³ãIDãéä¿¡ãã
0x17
ãŸãããªãã¬ãŒã¿ãŒã䜿çšããã¯ã©ã€ã¢ã³ãã«å®è£ ãããŸãã
CïŒCãµãŒããŒãšããŠäœ¿çš
Kobalosã®æãçããæ©èœã®1ã€ã¯ãCïŒCãµãŒããŒã³ãŒãããã§ã«ããã¯ãã¢èªäœã«çµã¿èŸŒãŸããŠããããšã§ããããã«ãããæ»æè ã¯1ã€ã®ã³ãã³ãã§ææãããã·ã³ãïŒä»ã®ãããçšã®ïŒCïŒCãµãŒããŒã«å€ããããšãã§ããŸãããµãŒããŒãèµ·åããåŸããªãã¬ãŒã¿ãŒã¯ãä»ã®ãã¹ãã«ãããã€ãããå°æ¥ã®Kobalosã€ã³ã¹ã¿ã³ã¹ã®æ§æã§IPã¢ãã¬ã¹ãšããŒããèšå®ã§ããŸããããã«ãããæ¬¡ã®ããšãå¯èœã«ãªããŸãã
- éåžžã®ãããã€ããŒãããµãŒããŒãã¬ã³ã¿ã«ããã®ã§ã¯ãªãã䟵害ããããªãœãŒã¹ãCïŒCãµãŒããŒãšããŠäœ¿çšããŸããããã«ããããµãŒããŒã䜿çšã§ããªããªãå¯èœæ§ãäœããªããŸãã
- ã€ã³ã¿ãŒãããããçŽæ¥æ¥ç¶ãããŠããªããã¡ã€ã¢ãŠã©ãŒã«ã®èåŸã«ãããã·ã³ã®äžéããŒããšããŠCïŒCãµãŒããŒã䜿çšããŸãã
ãªãã¬ãŒã¿ãŒããCïŒCã¢ãŒããžã®ç§»è¡ãïŒ
0x21
ïŒã³ãã³ããéä¿¡ãããšã ããŒãçªå·ããã©ã¡ãŒã¿ãŒãšããŠæž¡ãããŸããKobalosã¯ããããªãã¹ã³ãå§ãããããã¯ãã®ããŒãã䜿çšããŠCïŒCãµãŒããŒã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ããŸãããã ããããã¯ãã¢ã¯æ¬¡ã«å€§ããããŒãçªå·ããªãã¹ã³ããŸããããšãã°ãããããTCPããŒã7070ã䜿çšããå ŽåãCïŒCã¢ãŒãã§ã¯Kobalosã7071ããªãã¹ã³ããŸãã2çªç®ã®ããŒãã¯ããããã®äžèŠ§è¡šç€ºãããããžã®ãã³ãã«ã®ç¢ºç«ãªã©ãCïŒCæ©èœãå¶åŸ¡ããããã«ãªãã¬ãŒã¿ãŒã«ãã£ãŠäœ¿çšãããŸãããã®å³ãå³15ã«ç€ºããŸãã
å³15.ãªãã¬ãŒã¿ãŒKobalosã¯ãCïŒCãµãŒããŒã«èªåèªèº«ãå ±åããããããåŒã³åºããŸãã
衚8ã«ãCïŒCãµãŒããŒã®æ©èœãå¶åŸ¡ããããã®ã³ãã³ãã瀺ããŸãã
衚8.CïŒCãµãŒããŒã®æ©èœãå¶åŸ¡ããããã®ã³ãã³ãïŒ
| ã³ãã³ã | 説æ | ãªãã·ã§ã³ |
|---|---|---|
| 0x21 | CïŒCãµãŒããŒã®ç«ã¡äžãã | CïŒCãµãŒããŒã®TCPããŒãã |
| 0x23 | CïŒCãéå§ãããŠããã®ã¢ã¯ãã£ããªæ¥ç¶ã®æ°ãšåèšãååŸããŸãã | |
| 0x25 | ã³ãã³ããå®è¡ããæºåãã§ããŠãããã¹ãŠã®ãããã®ãªã¹ãã | |
| 0x29 | CïŒCãµãŒããŒãåæããŸãã | |
| 0x2B | ãããã«æ¥ç¶ããŸãã | æ¥ç¶ããæºåãã§ããŠãããããã®ãªã¹ãããã®ãããã€ã³ããã¯ã¹ãèªèšŒã¡ãã»ãŒãžïŒ320ãã€ãïŒã |
| 0x2D | èªèšŒãªãã§ãããã«æ¥ç¶ããŠããŸãã | æ¥ç¶ããæºåãã§ããŠãããããã®ãªã¹ãããã®ãããã€ã³ããã¯ã¹ã |
ã³ãã³ã
0x23
-
0x2D
CïŒCãµãŒããŒã®ãµãããã»ã¹ã«ãã£ãŠåŠçãããŸããå³16ã«ç€ºãããã«ãã¢ã¯ãã£ããã£ãã«ã§éä¿¡ãããåŸãããŒã¿ã¯TCPãä»ããŠCïŒCãµãŒããŒã®å¶åŸ¡ããŒãïŒãããã䜿çšããããŒãçªå·ãã1ã€å€ãïŒã®ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã«ãªãã€ã¬ã¯ããããŸãã
å³16.CïŒCãµãŒããŒç®¡çã«é¢é£ãããã±ããã¯ãTCPãä»ããŠãµãããã»ã¹ã«è»¢éãããŸãã
ãã®ä»ã®ã³ãã³ã
ç°å¢å€æ°
ããã¯ãã¢ããã»ã¹ã«ã¯ãç°å¢å€æ°ãèšå®ããããã®ã³ãã³ãããããŸããæååããã©ã¡ãŒã¿ãšããŠåãåãããããputenvã«æž¡ãã ãã§ã ãputenvã¯ããVAR = valueãã®åœ¢åŒã®ããŒã¿ãæåŸ ããŸãã
衚9.Kobalosãçè§£ãããã®ä»ã®ã³ãã³ãïŒ
| ã³ãã³ã | 説æ | ãªãã·ã§ã³ |
|---|---|---|
| 0x0E | ã»ãã·ã§ã³ã®ç°å¢å€æ°ãèšå®ããŸãã | ã«æž¡ãæååputenv
ã |
ç©ºã®æäœ
ããã«2ã€ã®ã³ãã³ããå®è£ ãããŠããŸãããäœãå®è¡ãããŸãããããã«ã¯2ã€ã®èª¬æããããŸãã
- 以åã®ããŒãžã§ã³ã§äœ¿çšãããŠãããããäœæè ã¯ã³ãã³ãã®æ©èœãåé€ããäžèŠã«ãªããŸããã
- ã³ãã³ãã¯ãã©ãããã©ãŒã åºæã§ãããåæããKobalosã®Linuxããã³FreeBSDããŒãžã§ã³ã«ã¯é©çšãããŸããã
å³17.ããŒã ãšäœãããŸãããSolarisãAIXãããã³Windowsã®æååå€ãããã£ãŠããããã2çªç®ã®èª¬æã®å¯èœæ§ãé«ããªããŸãïŒæå·åãããæååå€ã®ç« ãåç §ïŒã
0x07
0x09
OpenSSHè³æ Œæ å ±çé£ããã°ã©ã
Kobalosã«ãã£ãŠäŸµå®³ãããã»ãšãã©ã®ã·ã¹ãã ã§ã¯ãããã¯ãã¢ã¯ãããã€ã®æšéЬåãããSSHã¯ã©ã€ã¢ã³ããä»ããŠSSHè³æ Œæ å ±ãçãããã°ã©ã ãå±éããŸããã LinuxãFreeBSDãªã©ããããã®ãã¡ã€ã«ã®ããŸããŸãªããŒãžã§ã³ãèŠã€ãããŸããã Kobalosãšã¯ç°ãªãããã®ããã°ã©ã ã®æ©èœã¯ã»ãšãã©é£èªåãããŠããŸããããã®äž»ãªæ©èœã¯ããã¹ãåãããŒãçªå·ããŠãŒã¶ãŒåãšãã¹ã¯ãŒããçãã§ã䟵害ããããã¹ãããSSHæ¥ç¶ã確ç«ããããšã§ããããŒã¿ã¯æå·åããããã¡ã€ã«ã«ä¿åãããŸããæ°ããããŒãžã§ã³ã®ããã€ã®æšéЬãUDPãä»ããŠãããã¯ãŒã¯çµç±ã§æ å ±ãéä¿¡ã§ããŸããããã®æ©èœã¯ãèŠã€ãã£ãã»ãšãã©ã®ãµã³ãã«ã®æ§æã§ã¯ã¢ã¯ãã£ãåãããŠããŸããã§ããã
ããããOpenSSHããã¯ãã¢ã«é¢ãã以åã®èª¿æ»ãForSSHEã®ããŒã¯ãµã€ãããå ¬éãããæç¹ã§ã¯ããã®ããã€ã®æšéЬã«ã€ããŠç¥ããªãã£ãããããã®äœæ¥ã§ã¯èšåãããŠããŸããããŸãããªãŒãã³ãœãŒã¹ã§èª¬æãããŠããOpenSSHè³æ Œæ å ±ãçãããã°ã©ã ã«ãªã³ã¯ããããšãã§ããŸããã
çãŸããããŒã¿ãã¡ã€ã«ã®å Žæã¯ãããã°ã©ã ã®ããŒãžã§ã³ã«ãã£ãŠç°ãªããŸãããã¹ãŠã®ãµã³ãã«ã¯ããã£ã¬ã¯ããªã«
/var/run
.pidæ¡åŒµåã®ãã¡ã€ã«ãäœæããŸãã ããã®ãã£ã¬ã¯ããªå ã®å€ãã®ãã¡ã€ã«ã§äœ¿çšãããŠããŸããã䟵害ã®å åãã®ç« ã§ãããŸããŸãªãµã³ãã«ããã®ãã¡ã€ã«åãšãã¡ã€ã«ãžã®ãã¹ã®äŸã確èªã§ããŸãã
èŠã€ãã£ããã¹ãŠã®ãµã³ãã«ã¯ã1ã€ã®åçŽãªæå·ã䜿çšããŠãã¡ã€ã«ã®å 容ãæå·åããŸããå³18ã«ç€ºãããã«ãããã€ã®æšéЬã¯ãæ ŒçŽããããŒã¿ã®ãã¹ãŠã®ãã€ãã«123ã远å ããã ãã§ãã
å³18.çãŸããSSHè³æ Œæ å ±ã®æå·åãšãã¡ã€ã«ãžã®æžã蟌ã¿ã
FreeBSDããŒãžã§ã³ã¯åããã©ãŒããããšæå·ã䜿çšããŸãããã ããå®è£ æ¹æ³ã¯å°ãç°ãªããŸããããšãã°ãããã°ã©ã ã§ã¯ããã¡ã€ã«ãžã®ãã¹ã¯ã·ã³ã°ã«ãã€ãXORã䜿çšããŠæå·åãããŸãã
ããã°ã©ã ãã¡ããªãŒã®éçº
被害è ã®çµç¹ã®1ã€ã«éç¥ããåŸã圌ãã¯è³æ Œæ å ±ãçãããã€ã®æšéЬã®ããæ°ããããŒãžã§ã³ã®ããã«èŠãããã®ãçºèŠããŸãããæå·åãããæ§æãå«ãŸããŠãããçãŸããæ å ±ãUDPãä»ããŠæ§æã§æå®ããããªã¢ãŒããã¹ãã«éä¿¡ã§ããŸãã EburyããBonadanãKesselãChandrilaãªã©ã®ä»ã®SSHè³æ Œæ å ±ãçãããã°ã©ã ã«ããã®æ©èœããããŸããããããUDPã¯ããã¡ã€ã¢ãŠã©ãŒã«ããã€ãã¹ããä¿¡é Œã§ããªãå¯èœæ§ã®ãããã¹ããžã®TCPæ¥ç¶ãè¡ããªãããã«éžæãããŸããããã®ããã€ã®æšéЬã¯ãã¿ãŒã²ãããã¹ãã®ååãšãã¡ã€ã«ãžã®ãã¹ãåã倿°ã«æ ŒçŽãããŠããããããã¡ã€ã«ãŸãã¯ãããã¯ãŒã¯ãä»ãã1ã€ã®éä¿¡æ¹æ³ã®ã¿ã䜿çšããŸãã
å³19ã¯ãUDPãä»ããŠããŒã¿ãéä¿¡ããããã®éã³ã³ãã€ã«ãããã³ãŒãã瀺ããŠããŸãããŸããå³20ã¯ãèŠã€ãã£ããµã³ãã«ã®æ§æã瀺ããŠããŸããçãŸããæ å ±ãã«èšé²ããããã«æ§æãããŸãã
/var/run/sshd/sshd.pid
ã
å³19.ããã€ã®æšéЬã¯UDPãä»ããŠè³æ Œæ å ±ãéä¿¡ããŸãã
å³20.ãã¡ã€ã«ã䜿çšããŠçãŸããããŒã¿ããã£ããã£ããæ§æã®äŸã
äžæè°ãªããšã«ãæ§æã«ã¯è¢«å®³è ã®ãã¹ãã®ååãå«ãŸããŠããŸãããããããããŒã¿ãœãŒã¹ã瀺ãããã«æŒç®åã«ãã£ãŠäœ¿çšãããŸãããŸãã䟵害ãããåãµãŒããŒãããã€ã®æšéЬã®äžæã®ã€ã³ã¹ã¿ã³ã¹ãåä¿¡ããããšãæå³ããŸãã
çµè«
倿°ã®é©åã«å®è£ ããããããã¯ãŒã¯åé¿æ©èœãšææ³ã¯ãKobalosã®äœæè ããLinuxããã®ä»ã®Windows以å€ã®ã·ã¹ãã ã®å€ãã®ãã«ãŠã§ã¢äœæè ãããã¯ããã«çç·ŽããŠããããšã瀺ããŠããŸããã¿ãŒã²ãã£ã³ã°ïŒããªãæåãªçµç¹ïŒã¯ãKobalosã®ãªãã¬ãŒã¿ãŒãã§ããã ãå€ãã®ã·ã¹ãã ã«ææããããšãç®æããŠããªãããšã瀺ããŠããŸããäœãã¬ãŒã¹ãšãããã¯ãŒã¯ãã€ãã¹æè¡ãããããã¯ãŒã¯ã¹ãã£ã³ã®çµæã被害è ã«éç¥ãããŸã§ããã¯ãã¢ãèŠéããããŠããçç±ã§ããå¯èœæ§ããããŸãã
æ»æè ã®æå³ã«ã€ããŠã®è³ªåã«ã¯çããããŸãããããã¯ãã¢ã®æ©èœã«ãããããã¯ãã¢ã䜿çšããŠåé¡ã解決ã§ããŸããSSHè³æ Œæ å ±ãçãããã€ã®æšéЬãé€ããŠã䟵害ããããã·ã³äžã«è¿œå ã®ãœãããŠã§ã¢ã¯èŠã€ãããŸããã§ããããããã£ãŠããã€ããŒãã§ã¯ãªããSSHããšã³ããªãã€ã³ããšèŠãªããŸãã䟵害ãããHPCã·ã¹ãã ã®ã·ã¹ãã 管çè ããã®äŸµå®³ãããHPCæ å ±ã·ã¹ãã ã®ã·ã¹ãã 管çè ããã®æ å ±ã«ãããšãæå·é貚ããã€ãã³ã°ãããã倧ããªèšç®èœåãå¿ èŠãšããä»ã®ã¿ã¹ã¯ãèµ·åããããšãã人ã¯èª°ãããŸããã§ããã
æ»æè ã¯äœã远æ±ããŠããŸããïŒ
ãŸãããã®ãœãããŠã§ã¢ãã©ã®ãããã®æé䜿çšãããŠããããç¥ãããšãã§ããŸããã§ããã 25幎以äžåã«çºå£²ãããWindows3.11ãšWindows95ã«é¢é£ããè¡ãèŠã€ãããŸããã Kobalosã®WindowsããŒãžã§ã³ã¯ãããŸããïŒãã®ããã°ã©ã ã¯ãã£ãšåã«äœæãããŸãããïŒ 2019幎ãš2020å¹Žã«æ°ããªææãçºçããããšã¯ããã£ãŠããŸããã以åã«äœ¿çšããã蚌æ ã¯èŠã€ãããŸããã§ããã
ãã®ãœãããŠã§ã¢ã®äœæè ã¯ã被害è ã®ãããã¯ãŒã¯ãããã³ã«ãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®æäœã«ç²ŸéããŠããããã«èŠããŸãããKobalosã«ã¯ããã€ãã®åŒ±ç¹ããããŸãã第äžã«ãã³ããã¹ãæ¬åœã«éåžžã«é·ãééçºãããŠããå Žåãæå·åã®åé¡ã¯ãããããã®æ¥çã®çºå±ã«ãããã®ã§ããæ¬¡ã«ãç¹ã«ç¹å®ã®éä¿¡å TCPããŒããå¿ èŠãªå Žåã¯ãååçã«ãªãã¹ã³ããŠããã€ã³ã¹ã¿ã³ã¹ãããããšã«æ°ä»ããããããŸããããã®æ©èœãããŸãå©çšãã被害è ã«éç¥ããŠãææãããã¹ãã®æ°ãæžããããã®æ°ãã«çºèŠãããè åšãããããçè§£ããŸããã
æã ã¯ãŸãã®ä»äºã«å ±å ããã§ã€Kotowicz ãã MalwareLab PL ç¬ç«Kobalosãåæããèª°ãšæã ã調æ»çµæã亀æããã圌 ã¯èšã£ã Oh My H@ck 2020.
. Kobalos
| 1003 | INITIALIZE | socket, filter | Kobalos , ( enum). |
| 1004 | START_LISTENING | C&C- . | |
| 1005 | START_C2_SERVER | socket_1, socket_2 | C&C-. |
| 1006 | SEND_PACKET | socket_fd, &channel_1,
&channel_2, data, data_len |
Kobalos socket_fd. |
| 1007 | RECV_PACKET | socket_fd, &channel_1,
&channel_2, data, data_len |
Kobalos socket_fd. |
| 1008 | GET_RANDOM_INT | random_int | 32- . PRNG . |
| 1009 | GET_HOST_INFO | out_buf, returns buf_len | , IP- . |
| 1010 | SET_COMMON_SOCKOPT | socket | SO_REUSEADDR SO_KEEPALIVE
true, SO_LINGER â 15 . |
| 1011 | RC4_DECRYPT_STRING_INPLACE | str, len | str RC4- . |
| 1012 | CLEANUP_THINGS | what_to_close, send_report | . . . |
| 1013 | RC4_INIT | context, key_size, key | RC4 . |
| 1014 | RC4_CRYPT | context, len, data_in, data_out | RC4- . |
| 1015 | MD5 | input, input_len, output_digest | MD5-. |
| 1016
to 1037 |
, . | ||
| 1038 | RSA_PUBLIC_DECRYPT | ||
| 1039 | LOAD_PUB_KEY | key_bin_data, public_key | key_bin_dataããpublic_keyãžã®å ¬éRSAããŒã䜿çšããŠBLOBãããŒãããŸãã |
劥åã®å å
ESETã«ãã£ãŠæ€åºãããåå
- Linux / Kobalos
- Linux / Agent.IV
- Linux / SSHDoor.EV
- Linux / SSHDoor.FB
- Linux / SSHDoor.FC
ãµã³ãã«
ã³ããã¹
| SHA-1 | ã¿ãŒã²ããOS | çµã¿èŸŒã¿ | å¯çšæ§ |
|---|---|---|---|
FBF0A76CED2939D1F7EC5F9EA58C5A294207F7FE
|
RHEL | sshd | éä¿¡å ããŒã55201ããã®æ¥ç¶ãåŸ æ©ããŠããŸãã |
479F470E83F9A5B66363FBA5547FDFCF727949DA
|
Debian | ã¹ã¿ã³ãã¢ãã³ |
151.80.57ã«æ¥ç¶ããŸã[ã] 191ïŒ7070 |
AFFA12CC94578D63A8B178AE19F6601D5C8BB224
|
FreeBSD | sshd | éä¿¡å ããŒã55201ããã®æ¥ç¶ãåŸ æ©ããŠããŸãã |
325F24E8F5D56DB43D6914D9234C08C888CDAE50
|
Ubuntu | sshd | éä¿¡å ããŒã55201ããã®æ¥ç¶ãåŸ æ©ããŠããŸãã |
A4050A8171B0FA3AE9031E0F8B7272FACF04A3AA
|
Arch Linux | sshd | éä¿¡å ããŒã55201ããã®æ¥ç¶ãåŸ æ©ããŠããŸãã |
SSHè³æ Œæ å ±ãçãããã®ããã€ã®æšéЬ
| SHA-1 | ã¿ãŒã²ããOS | æžã蟌㿠|
|---|---|---|
6616DE799B5105EE2EB83BBE25C7F4433420DFF7
|
RHEL | /var/run/nscd/ns.pid
|
E094DD02CC954B6104791925E0D1880782B046CF
|
RHEL | /var/run/udev/ud.pid
|
1DD0EDC5744D63A731DB8C3B42EFBD09D91FED78
|
FreeBSD | /var/run/udevd.pid
|
C1F530D3C189B9A74DBE02CFEB29F38BE8CA41BA
|
Arch Linux | /var/run/nscd/ns.pid
|
659CBDF9288137937BB71146B6F722FFCDA1C5FE
|
Ubuntu | /var/run/sshd/sshd.pid
|
ããŒ
RSAå ¬ééµ
-----BEGIN PUBLIC KEY----- MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAOUgD8sEF1kZ04QxCd60HrB+TxWnLQED wzb0sZ8vMMD6xnUAJspdYzSVDnRnKYjTOM43qtLNcJOwVj6cuC1uHHMCAwEAAQ== -----END PUBLIC KEY-----
æååå€ã®éçRC4ããŒ
AE0E05090F3AC2B50B1BC6E91D2FE3CE
YARAã®ã«ãŒã«
rule kobalos { meta: = âKobalos malwareâ author = âMarc-Etienne M.Léveilléâ date = â2020-11-02â reference = «http://www.welivesecurity.com» source = «https://github.com/eset/malware-ioc/» license = «BSD 2-Clause» version = â1â strings: $encrypted_strings_sizes = { 05 00 00 00 09 00 00 00 04 00 00 00 06 00 00 00 08 00 00 00 08 00 00 00 02 00 00 00 02 00 00 00 01 00 00 00 01 00 00 00 05 00 00 00 07 00 00 00 05 00 00 00 05 00 00 00 05 00 00 00 0A 00 00 00 } $password_md5_digest = { 3ADD48192654BD558A4A4CED9C255C4C } $rsa_512_mod_header = { 10 11 02 00 09 02 00 } $strings_RC4_key = { AE0E05090F3AC2B50B1BC6E91D2FE3CE } condition: any of them } rule kobalos_ssh_credential_stealer { meta: = âKobalos SSH credential stealer seen in OpenSSH clientâ author = âMarc-Etienne M.Léveilléâ date = â2020-11-02â reference = «http://www.welivesecurity.com» source = «https://github.com/eset/malware-ioc/» license = «BSD 2-Clause» version = â1â strings: $ = âuser: %.128s host: %.128s port %05d user: %.128s password: %.128sâ condition: any of them }
MITER ATTïŒCKãã¯ããã¯
ãã®è¡šã¯ãATTïŒCKãã¬ãŒã ã¯ãŒã¯ã®8çªç®ã®ããŒãžã§ã³ã䜿çšããŠã³ã³ãã€ã«ãããŸããã
| æŠè¡ | èå¥å | åå | 説æ |
|---|---|---|---|
| æç¶å¯èœæ§ | T1554 | ClientSoftwareãã€ããªãå±éºã«ããã | Kobalos OpenSSH- sshd
.Kobalos SSH- . |
| T1205 | Traffic Signaling | Kobalos TCP- . | |
| Defense Evasion | T1070.003 | Clear Command History | Kobalos , . |
| T1070.006 | Timestomp | Kobalos . | |
| T1027.002 | Software Packing | Kobalos . | |
| Command And Control | T1573.001 | Encrypted Channel: Symmetric Cryptography | RC4. |
| T1573.002 | Encrypted Channel: Asymmetric Cryptography | RSA-512. | |
| T1090.003 | Proxy: Multi-hop Proxy | Kobalos , Kobalos. |