¥¦¥¤¥ë¥¹Âкö¥×¥í¥»¥¹¤ò¶¯À©½ªÎ»¤¹¤ë¥é¥ó¥µ¥à¥¦¥§¥¢¤ËÃí°Õ
Trend Micro¤Ï1·î23Æü(Êƹñ»þ´Ö)¡¢¡ÖKasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver¡×¤Ë¤ª¤¤¤Æ¡¢ÀȼåÀ¤Î¸ºß¤¹¤ë¥É¥é¥¤¥Ð¤ò°ÍѤ·¤¿¹¶·â¼êË¡¡ÖBYOVD(Bring Your Own Vulnerable Driver)¡×¤ò»ÈÍѤ¹¤ë¥é¥ó¥µ¥à¥¦¥§¥¢¥°¥ë¡¼¥×¡ÖKasseika¡×¤Ë´Ø¤¹¤ëÄ´ºº·ë²Ì¤ò¸ø³«¤·¤¿¡£Kasseika¤ÏºÇ¶á¡¢Â¸ºß¤¬³Îǧ¤µ¤ì¤¿¥°¥ë¡¼¥×¤Ç¡¢¡ÖAkira¡×¡ÖBlackByte¡×¡ÖAvosLocker¡×¤ÈƱÍͤ˥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò̵¸ú²½¤¹¤ëÀï½Ñ¤ò»ÈÍѤ¹¤ë¤È¤ß¤é¤ì¤ë¡£
Kasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver
¡ûKasseika¤Î¿¯³²·ÐÏ©
Trend Micro¤ÎʬÀϤˤè¤ë¤È¡¢Kasseika¤Î¿¯³²·ÐÏ©¤Ï¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖBlackMatter¡×¤Ë»÷¤¿Ãû¸õ¤¬¤¢¤ë¤È¤¤¤¦¡£Trend Micro¤ÎÄ´ººÂоݤȤʤä¿»ö°Æ¤Ë¤ª¤¤¤Æ¡¢Kasseika¤¬»ÈÍѤ·¤¿¹¶·â¤ËBlackMatter¤Î¥½¡¼¥¹¥³¡¼¥É¤ÎÂçÉôʬ¤¬»ÈÍѤµ¤ì¤Æ¤¤¤¿¤³¤È¤¬È½ÌÀ¤·¤Æ¤¤¤ë¡£BlackMatter¤Î¥½¡¼¥¹¥³¡¼¥É¤ÏÍưפËÆþ¼ê¤Ç¤¤Ê¤¤¤¿¤á¡¢Kasseika¤Î¹¶·â¼Ô¤Ï¤³¤Î¥½¡¼¥¹¥³¡¼¥É¤òÆþ¼ê¤Þ¤¿¤Ï¹ØÆþ¤·¤¿¤â¤Î¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£
Trend Micro¤ÎÄ´ººÂоݤȤʤä¿»ö°Æ¤Ë¤ª¤¤¤Æ¡¢Kasseika¤Ï¥á¡¼¥ë¤Ë¤è¤ëɸŪ·¿¥Õ¥£¥Ã¥·¥ó¥°¹¶·â¤ò¼Â¹Ô¤·¤Æ¤¤¤ë¡£É¸Åª¤Î½¾¶È°÷¤«¤é»ñ³Ê¾ðÊó¤òÀà¼è¤·¤Æ¥·¥¹¥Æ¥à¤Ë¿¯Æþ¡¢¥ê¥â¡¼¥È¥Ç¥¹¥¯¥È¥Ã¥×¥½¥Õ¥È¥¦¥§¥¢¤ÈMimikatz¤ò»ÈÍѤ·¤ÆÆø¢¥¢¥¯¥»¥¹¤ò¼èÆÀ¤¹¤ë¡£
Kasseika¤Î¿¯³²·ÐÏ© ¡¡°úÍÑ¡§Trend Micro
Æø¢¥¢¥¯¥»¥¹¤ò³ÍÆÀ¤·¤¿¹¶·â¼Ô¤ÏWindows¤Î¥æ¡¼¥Æ¥£¥ê¥Æ¥£¥Ä¡¼¥ë½¸¡ÖPsTools¡×¤Ë´Þ¤Þ¤ì¤ë¡ÖPsExec¡×¤ò»ÈÍѤ·¡¢¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤«¤é°°Õ¤Î¤¢¤ë¥Ð¥Ã¥Á¥¹¥¯¥ê¥×¥È¤ò¥À¥¦¥ó¥í¡¼¥É¡¢¼Â¹Ô¤¹¤ë¡£¼¡¤Ë¥Ð¥Ã¥Á¥¹¥¯¥ê¥×¥È¤Ï¥Þ¥ë¥¦¥§¥¢¡ÖPINCAV¡×¤Î¥¤¥ó¥¹¥¿¥ó¥¹¤ò1¤Ä¤À¤±ºîÀ®¤¹¤ë¡£PINCAV¤Ï½ð̾ÉÕ¤¥É¥é¥¤¥Ð¡ÖMartini.sys¡×¤¬C¡õC¥µ¡¼¥Ð¤«¤éÀµ¾ï¤Ë¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤Æ¤¤¤ë¤«³Îǧ¤·¡¢Â¸ºß¤¹¤ë¾ì¹ç¤Ï¥µ¡¼¥Ó¥¹¤È¤·¤ÆÅÐÏ¿¤¹¤ë¡£
Martini.sys¤ÎËÜÍè¤Î¥Õ¥¡¥¤¥ë̾¤Ï¡Öviragt64.sys¡×¤Ç¡¢TG Soft¤Ë¤è¤Ã¤Æ³«È¯¤µ¤ì¤¿¡ÖVirIT Agent System¡×¤Î°ìÉô¤È¤µ¤ì¤ë¡£¤³¤Î¥É¥é¥¤¥Ð¤Ë¤ÏÀȼåÀ¤¬Â¸ºß¤·¡¢°ÍѤ¹¤ë¤ÈǤ°Õ¤Î¥×¥í¥»¥¹¤ò¥«¡¼¥Í¥ë¥â¡¼¥É¤Ç¶¯À©½ªÎ»¤µ¤»¤ë¤³¤È¤¬¤Ç¤¤ë¡£
PINCAV¤Ï¥·¥¹¥Æ¥àÆâ¤Î¤¹¤Ù¤Æ¤Î¥×¥í¥»¥¹¾ðÊó¤ò¼èÆÀ¤·¡¢´ûÃΤΥ»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò¸¡½Ð¤¹¤ë¤ÈMartini.sys¤ÎÀȼåÀ¤ò»ÈÍѤ·¤Æ¤³¤ì¤ò¶¯À©½ªÎ»¤µ¤»¤ë¡£¤³¤Î¤è¤¦¤Ë¤·¤Æ¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò°ìÁݤ·¤¿¸å¡¢¥Ð¥Ã¥Á¥¹¥¯¥ê¥×¥È¤«¤é¥é¥ó¥µ¥à¥¦¥§¥¢¤ò¼Â¹Ô¤¹¤ë¡£
¡û¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖKasseika¡×
Kasseika¤Ï¶¯ÎϤʥ³¡¼¥ÉÆñÆɲ½¤È¥Ç¥Ð¥Ã¥°Êݸ½Ñ¤¬ÁȤ߹þ¤Þ¤ì¤Æ¤ª¤ê¡¢Ê¬ÀϤÏÈó¾ï¤Ëº¤Æñ¤È¤µ¤ì¤ë¡£Kasseika¤¬¼Â¹Ô¤µ¤ì¤ë¤È¥·¥¹¥Æ¥àÆâ¤Î¥Õ¥¡¥¤¥ë¤¬°Å¹æ²½¤µ¤ì¡¢¿ÈÂå¶â¤òÀÁµá¤¹¤ë¥Õ¥¡¥¤¥ë¤¬³Æ¥Ç¥£¥ì¥¯¥È¥ê¤ËÊݸ¤µ¤ì¤ë¡£¤Þ¤¿¡¢°Å¹æ²½¤ò´°Î»¤¹¤ë¤È¥·¥¹¥Æ¥à¤ÎÊɻ椬¿ÈÂå¶â¤ÎÀÁµá²èÁü¤Ëº¹¤·Âؤ¨¤é¤ì¤ë¡£
Kasseika¤Ë¤è¤Ã¤Æº¹¤·Âؤ¨¤é¤ì¤¿Êɻ桡°úÍÑ¡§Trend Micro
¡ûÂкö
Trend Micro¤ÏKasseika¤Ë¤è¤ëÈï³²¤òºÇ¾®¸Â¤Ë¤¹¤ë¤¿¤á¡¢ÁÈ¿¥¤¬ºÎÍѤǤ¤ë¥Ù¥¹¥È¥×¥é¥¯¥Æ¥£¥¹¤È¤·¤Æ¼¡¤Î¤è¤¦¤ÊÂкö¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£
½¾¶È°÷¤Î¥¢¥¯¥»¥¹¸¢¤ËºÇ¾®¸¢¸Â¤Î¸¶Â§¤òŬÍѤ¹¤ë
¥»¥¥å¥ê¥Æ¥£À½ÉʤòÄê´üŪ¤Ë¹¹¿·¤¹¤ë¡£¤Þ¤¿¡¢Äê´üŪ¤Ë¥¹¥¥ã¥ó¤ò¼Â»Ü¤¹¤ë
½ÅÍפʥǡ¼¥¿¤òÄê´üŪ¤Ë¥¤¥ß¥å¡¼¥¿¥Ö¥ë¥Ð¥Ã¥¯¥¢¥Ã¥×¤¹¤ë
ÅŻҥ᡼¥ë¤ÈWeb¥µ¥¤¥È¤Î¥»¥¥å¥ê¥Æ¥£¤òŬÀڤ˰ݻý¤¹¤ë¡£¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ï¿®Íê¤Ç¤¤ë¥½¡¼¥¹¤«¤é¼èÆÀ¤·¤¿¤â¤Î¤À¤±¤ò»ÈÍѤ¹¤ë
ÉÔ¿³¤Ê¥á¡¼¥ë¤ä¥Õ¥¡¥¤¥ë¤Ï¥»¥¥å¥ê¥Æ¥£Ã´Åö¼Ô¤ËÊó¹ð¤¹¤ë¡£°°Õ¤Î¤¢¤ë¥á¡¼¥ë¤ò¥Ö¥í¥Ã¥¯¤Ç¤¤ë¥Ä¡¼¥ë¤ÎƳÆþ¤ò½¾¶È°÷¤Ë¾©Î夹¤ë
¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¤Î´í¸±À¤ÈºÇ¿·¤Î¹¶·â¼êË¡¤òÄê´üŪ¤Ë¼Ò°÷¶µ°é¤¹¤ë
¡ûKasseika¤Î¿¯³²·ÐÏ©
Trend Micro¤ÎʬÀϤˤè¤ë¤È¡¢Kasseika¤Î¿¯³²·ÐÏ©¤Ï¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖBlackMatter¡×¤Ë»÷¤¿Ãû¸õ¤¬¤¢¤ë¤È¤¤¤¦¡£Trend Micro¤ÎÄ´ººÂоݤȤʤä¿»ö°Æ¤Ë¤ª¤¤¤Æ¡¢Kasseika¤¬»ÈÍѤ·¤¿¹¶·â¤ËBlackMatter¤Î¥½¡¼¥¹¥³¡¼¥É¤ÎÂçÉôʬ¤¬»ÈÍѤµ¤ì¤Æ¤¤¤¿¤³¤È¤¬È½ÌÀ¤·¤Æ¤¤¤ë¡£BlackMatter¤Î¥½¡¼¥¹¥³¡¼¥É¤ÏÍưפËÆþ¼ê¤Ç¤¤Ê¤¤¤¿¤á¡¢Kasseika¤Î¹¶·â¼Ô¤Ï¤³¤Î¥½¡¼¥¹¥³¡¼¥É¤òÆþ¼ê¤Þ¤¿¤Ï¹ØÆþ¤·¤¿¤â¤Î¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£
Trend Micro¤ÎÄ´ººÂоݤȤʤä¿»ö°Æ¤Ë¤ª¤¤¤Æ¡¢Kasseika¤Ï¥á¡¼¥ë¤Ë¤è¤ëɸŪ·¿¥Õ¥£¥Ã¥·¥ó¥°¹¶·â¤ò¼Â¹Ô¤·¤Æ¤¤¤ë¡£É¸Åª¤Î½¾¶È°÷¤«¤é»ñ³Ê¾ðÊó¤òÀà¼è¤·¤Æ¥·¥¹¥Æ¥à¤Ë¿¯Æþ¡¢¥ê¥â¡¼¥È¥Ç¥¹¥¯¥È¥Ã¥×¥½¥Õ¥È¥¦¥§¥¢¤ÈMimikatz¤ò»ÈÍѤ·¤ÆÆø¢¥¢¥¯¥»¥¹¤ò¼èÆÀ¤¹¤ë¡£
Kasseika¤Î¿¯³²·ÐÏ© ¡¡°úÍÑ¡§Trend Micro
Æø¢¥¢¥¯¥»¥¹¤ò³ÍÆÀ¤·¤¿¹¶·â¼Ô¤ÏWindows¤Î¥æ¡¼¥Æ¥£¥ê¥Æ¥£¥Ä¡¼¥ë½¸¡ÖPsTools¡×¤Ë´Þ¤Þ¤ì¤ë¡ÖPsExec¡×¤ò»ÈÍѤ·¡¢¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤«¤é°°Õ¤Î¤¢¤ë¥Ð¥Ã¥Á¥¹¥¯¥ê¥×¥È¤ò¥À¥¦¥ó¥í¡¼¥É¡¢¼Â¹Ô¤¹¤ë¡£¼¡¤Ë¥Ð¥Ã¥Á¥¹¥¯¥ê¥×¥È¤Ï¥Þ¥ë¥¦¥§¥¢¡ÖPINCAV¡×¤Î¥¤¥ó¥¹¥¿¥ó¥¹¤ò1¤Ä¤À¤±ºîÀ®¤¹¤ë¡£PINCAV¤Ï½ð̾ÉÕ¤¥É¥é¥¤¥Ð¡ÖMartini.sys¡×¤¬C¡õC¥µ¡¼¥Ð¤«¤éÀµ¾ï¤Ë¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤Æ¤¤¤ë¤«³Îǧ¤·¡¢Â¸ºß¤¹¤ë¾ì¹ç¤Ï¥µ¡¼¥Ó¥¹¤È¤·¤ÆÅÐÏ¿¤¹¤ë¡£
Martini.sys¤ÎËÜÍè¤Î¥Õ¥¡¥¤¥ë̾¤Ï¡Öviragt64.sys¡×¤Ç¡¢TG Soft¤Ë¤è¤Ã¤Æ³«È¯¤µ¤ì¤¿¡ÖVirIT Agent System¡×¤Î°ìÉô¤È¤µ¤ì¤ë¡£¤³¤Î¥É¥é¥¤¥Ð¤Ë¤ÏÀȼåÀ¤¬Â¸ºß¤·¡¢°ÍѤ¹¤ë¤ÈǤ°Õ¤Î¥×¥í¥»¥¹¤ò¥«¡¼¥Í¥ë¥â¡¼¥É¤Ç¶¯À©½ªÎ»¤µ¤»¤ë¤³¤È¤¬¤Ç¤¤ë¡£
PINCAV¤Ï¥·¥¹¥Æ¥àÆâ¤Î¤¹¤Ù¤Æ¤Î¥×¥í¥»¥¹¾ðÊó¤ò¼èÆÀ¤·¡¢´ûÃΤΥ»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò¸¡½Ð¤¹¤ë¤ÈMartini.sys¤ÎÀȼåÀ¤ò»ÈÍѤ·¤Æ¤³¤ì¤ò¶¯À©½ªÎ»¤µ¤»¤ë¡£¤³¤Î¤è¤¦¤Ë¤·¤Æ¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò°ìÁݤ·¤¿¸å¡¢¥Ð¥Ã¥Á¥¹¥¯¥ê¥×¥È¤«¤é¥é¥ó¥µ¥à¥¦¥§¥¢¤ò¼Â¹Ô¤¹¤ë¡£
¡û¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖKasseika¡×
Kasseika¤Ï¶¯ÎϤʥ³¡¼¥ÉÆñÆɲ½¤È¥Ç¥Ð¥Ã¥°Êݸ½Ñ¤¬ÁȤ߹þ¤Þ¤ì¤Æ¤ª¤ê¡¢Ê¬ÀϤÏÈó¾ï¤Ëº¤Æñ¤È¤µ¤ì¤ë¡£Kasseika¤¬¼Â¹Ô¤µ¤ì¤ë¤È¥·¥¹¥Æ¥àÆâ¤Î¥Õ¥¡¥¤¥ë¤¬°Å¹æ²½¤µ¤ì¡¢¿ÈÂå¶â¤òÀÁµá¤¹¤ë¥Õ¥¡¥¤¥ë¤¬³Æ¥Ç¥£¥ì¥¯¥È¥ê¤ËÊݸ¤µ¤ì¤ë¡£¤Þ¤¿¡¢°Å¹æ²½¤ò´°Î»¤¹¤ë¤È¥·¥¹¥Æ¥à¤ÎÊɻ椬¿ÈÂå¶â¤ÎÀÁµá²èÁü¤Ëº¹¤·Âؤ¨¤é¤ì¤ë¡£
Kasseika¤Ë¤è¤Ã¤Æº¹¤·Âؤ¨¤é¤ì¤¿Êɻ桡°úÍÑ¡§Trend Micro
¡ûÂкö
Trend Micro¤ÏKasseika¤Ë¤è¤ëÈï³²¤òºÇ¾®¸Â¤Ë¤¹¤ë¤¿¤á¡¢ÁÈ¿¥¤¬ºÎÍѤǤ¤ë¥Ù¥¹¥È¥×¥é¥¯¥Æ¥£¥¹¤È¤·¤Æ¼¡¤Î¤è¤¦¤ÊÂкö¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£
½¾¶È°÷¤Î¥¢¥¯¥»¥¹¸¢¤ËºÇ¾®¸¢¸Â¤Î¸¶Â§¤òŬÍѤ¹¤ë
¥»¥¥å¥ê¥Æ¥£À½ÉʤòÄê´üŪ¤Ë¹¹¿·¤¹¤ë¡£¤Þ¤¿¡¢Äê´üŪ¤Ë¥¹¥¥ã¥ó¤ò¼Â»Ü¤¹¤ë
½ÅÍפʥǡ¼¥¿¤òÄê´üŪ¤Ë¥¤¥ß¥å¡¼¥¿¥Ö¥ë¥Ð¥Ã¥¯¥¢¥Ã¥×¤¹¤ë
ÅŻҥ᡼¥ë¤ÈWeb¥µ¥¤¥È¤Î¥»¥¥å¥ê¥Æ¥£¤òŬÀڤ˰ݻý¤¹¤ë¡£¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ï¿®Íê¤Ç¤¤ë¥½¡¼¥¹¤«¤é¼èÆÀ¤·¤¿¤â¤Î¤À¤±¤ò»ÈÍѤ¹¤ë
ÉÔ¿³¤Ê¥á¡¼¥ë¤ä¥Õ¥¡¥¤¥ë¤Ï¥»¥¥å¥ê¥Æ¥£Ã´Åö¼Ô¤ËÊó¹ð¤¹¤ë¡£°°Õ¤Î¤¢¤ë¥á¡¼¥ë¤ò¥Ö¥í¥Ã¥¯¤Ç¤¤ë¥Ä¡¼¥ë¤ÎƳÆþ¤ò½¾¶È°÷¤Ë¾©Î夹¤ë
¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¤Î´í¸±À¤ÈºÇ¿·¤Î¹¶·â¼êË¡¤òÄê´üŪ¤Ë¼Ò°÷¶µ°é¤¹¤ë