Securonix¤Ï1·î9Æü(Êƹñ»þ´Ö)¡¢¡ÖSecuronix Threat Research Security Advisory: New RE#TURGENCE Attack Campaign: Turkish Hackers Target MSSQL Servers to Deliver Domain-Wide MIMIC Ransomware - Securonix¡×¤Ë¤ª¤¤¤Æ¡¢¥È¥ë¥³¤Î¶¼°Ò¥¢¥¯¥¿¡¼¤Ë¤è¤ëMicrosoft SQL¥µ¡¼¥Ð¤òɸŪ¤È¤·¤¿¿Ê¹ÔÃæ¤Î¥µ¥¤¥Ð¡¼¹¶·â¤Î¥­¥ã¥ó¥Ú¡¼¥ó¡ÖRE#TURGENCE¡×¤òȯ¸«¤·¤¿¤ÈÊ󤸤¿¡£¤³¤Î¥­¥ã¥ó¥Ú¡¼¥ó¤Ç¤Ï¡ÖMIMIC¡×¤È¸Æ¤Ð¤ì¤ë¥é¥ó¥µ¥à¥¦¥§¥¢¤¬»ÈÍѤµ¤ì¤Æ¤¤¤ë¤È¤¤¤¦¡£

Securonix Threat Research Security Advisory: New RE#TURGENCE Attack Campaign: Turkish Hackers Target MSSQL Servers to Deliver Domain-Wide MIMIC Ransomware - Securonix

¡ûMicrosoft SQLÁÀ¤¦¥é¥ó¥µ¥à¥¦¥§¥¢¹¶·â¤Î³µÍ×

Securonix¶¼°ÒʬÀÏ¥Á¡¼¥à¤Ë¤è¤ë¤È¡¢¤³¤Î¥­¥ã¥ó¥Ú¡¼¥ó¤ÏÊƹñ¡¢²¤½£Ï¢¹ç(EU: European Union)¡¢ÃæÆîÊÆÃÏ°è¤Ç³èÆ°¤¬¤ß¤é¤ì¡¢·ÐºÑŪÍø±×¤òÌÜŪ¤Ë¤·¤Æ¤¤¤ë¤È¤¤¤¦¡£¶¼°Ò¥¢¥¯¥¿¡¼¤Ï¸ø³«¤µ¤ì¤Æ¤¤¤ëMicrosoft SQL¥µ¡¼¥Ð¤Ø¥Ö¥ë¡¼¥È¥Õ¥©¡¼¥¹¹¶·â¤ò¹Ô¤¦¤³¤È¤Ç¥·¥¹¥Æ¥à¤Ë¿¯Æþ¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï̵¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡Öxp_cmdshell¡×¤ò°­ÍѤ·¤Æ¥³¥Þ¥ó¥É¤ò¼Â¹Ô¡¢¥·¥¹¥Æ¥à¤ò¿¯³²¤¹¤ë¡£

¶ñÂÎŪ¤Ë¤Ïxp_cmdshell¤ò»ÈÍѤ·¤Æ°­°Õ¤Î¤¢¤ë¥·¥§¥ë¥¹¥¯¥ê¥×¥È¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¼Â¹Ô¤¹¤ë¡£¥·¥§¥ë¥¹¥¯¥ê¥×¥È¤ÏÆñÆɲ½¤µ¤ì¤¿Ê̤Υ·¥§¥ë¥¹¥¯¥ê¥×¥È¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¼Â¹Ô¤·¡¢ºÇ½ªÅª¤Ë¡ÖCobalt Strike¡×¤ò¥á¥â¥ê¶õ´Ö¤ËŸ³«¤·¤Æ¼Â¹Ô¡£¤½¤Î¸å¡ÖAnyDesk¡×¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤ÈƱ»þ¤Ë´ÉÍý¼Ô¸¢¸Â¤ò¤â¤Ä¥æ¡¼¥¶¡¼¡Öwindows¡×¤òºîÀ®¤¹¤ë¡£¤³¤Î¤È¤­¡¢Â¸ºß¤¹¤ë¾ì¹ç¤Ï¡Öadministradores¡×¥°¥ë¡¼¥×¤Ë¥æ¡¼¥¶¤òÄɲᣤ³¤¦¤·¤Æ¶¼°Ò¥¢¥¯¥¿¤ÏAnyDesk¤òÄ̤¸¤¿±Ê³À­¤ò³ÎÊݤ¹¤ë¤È¤µ¤ì¤ë¡£

¶¼°Ò¥¢¥¯¥¿¤Ï±Ê³À­¤ò³ÎÊݤ¹¤ë¤È¡ÖMimikatz¡×¤ò»ÈÍѤ·¤Æ»ñ³Ê¾ðÊó¤òÀà¼è¤·¡¢¥É¥á¥¤¥ó´ÉÍý¼Ô¸¢¸Â¤ò»ÈÍѤ·¤Æ²£Êý¸þ¤Ø¤Î°ÜÆ°¤ò¹Ô¤¦¡£²£Êý¸þ¤Î°ÜÆ°¤ò°ìÄ̤꽪¤¨¤ë¤È¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖMIMIC¡×¤òŸ³«¤·¡¢¥·¥¹¥Æ¥àÆâ¤Î¥Õ¥¡¥¤¥ë¤ò°Å¹æ²½¡¢¿ÈÂå¶â¤ÎÍ×µá¤ò¹Ô¤¦¡£

Securonix¶¼°ÒʬÀÏ¥Á¡¼¥à¤Ï¥­¥ã¥ó¥Ú¡¼¥ó¤ÎʬÀÏÃæ¤Ë¶¼°Ò¥¢¥¯¥¿¤¬»ÈÍѤ·¤¿¥ê¥â¡¼¥È´Æ»ë¤ª¤è¤Ó´ÉÍý(RMM: Remote Monitoring and Management)¥Ä¡¼¥ë¤ò»ÈÍѤ·¤Æ¡¢¶¼°Ò¥¢¥¯¥¿¤Î³èÆ°¤ò´Ñ»¡¤·¤Æ¤¤¤ë¡£¤½¤Î³èÆ°¤Î¤¤¤¯¤Ä¤«¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢¤½¤ÎÃæ¤Ë¤Ï¹¶·â¼Ô´Ö¤Î¤ä¤ê¼è¤ê¤È¤ß¤é¤ì¤ë¶½Ì£¿¼¤¤¥á¥Ã¥»¡¼¥¸¤â´Þ¤Þ¤ì¤Æ¤¤¤ë¡£

¡û¥é¥ó¥µ¥à¥¦¥§¥¢¹¶·â¤Ø¤ÎÂкö

Securonix¤Ï¤³¤Î¤è¤¦¤Ê¹¶·â¤«¤é¥·¥¹¥Æ¥à¤òÊݸ¤ë¤¿¤á¤Ë¡¢¼¡¤ÎÂкö¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£

½ÅÍפʥµ¡¼¥Ð¤ò¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËľÀܸø³«¤¹¤ë¤³¤È¤ÏÈò¤±¤ë¡£²Äǽ¤Ç¤¢¤ì¤Ð²¾Áۥץ饤¥Ù¡¼¥È¥Í¥Ã¥È¥ï¡¼¥¯(VPN: Virtual Private Network)¤Ê¤É¤Î¥¤¥ó¥Õ¥é¥¹¥È¥é¥¯¥Á¥ã¤ÎÇظå¤Ë¥µ¡¼¥Ð¤òÀßÃÖ¤¹¤ë

Microsoft SQL¥µ¡¼¥Ð¤Îxp_cmdshell¥×¥í¥·¡¼¥¸¥ã¤ò̵¸ú¤Ë¤¹¤ë

°­°Õ¤Î¤¢¤ë¥×¥í¥»¥¹¤ò¸¡½Ð¤¹¤ë¤¿¤á¤Ë¡¢¥¨¥ó¥É¥Ý¥¤¥ó¥È¤ª¤è¤Ó¥µ¡¼¥Ð¤ÎÁÐÊý¤Ç¥×¥í¥»¥¹¥ì¥Ù¥ë¤Î¥í¥°¤òÍ­¸ú²½¤¹¤ë

ÄÉ²Ã¤Î¥×¥í¥»¥¹¥ì¥Ù¥ë¤Î¥í¥°¤òƳÆþ¤·¤Æ¡¢PowerShell¤Ê¤É¤Î³èÆ°¤ò´Æ»ë¤Ç¤­¤ë¤è¤¦¤Ë¤¹¤ë

½ÅÍפʥµ¡¼¥Ð¤Ç¤Ï¿·¤·¤¤¥æ¡¼¥¶¡¼¤ÎºîÀ®¤ò´Æ»ë¤¹¤ë

Securonix¤Ï¡¢¤³¤Î¥­¥ã¥ó¥Ú¡¼¥ó¤ÎÄ´ºº¤Ë¤ª¤¤¤ÆȽÌÀ¤·¤¿¶¼°Ò¥¢¥¯¥¿¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤Î¾ðÊó¤Ê¤É¡¢¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿(IoC: Indicator of Compromise)¤ËÁêÅö¤¹¤ë¾ðÊó¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢Microsoft SQL¥µ¡¼¥Ð¤ò±¿ÍѤ¹¤ë´ÉÍý¼Ô¤Ë¤ÏɬÍפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£