Excel¤ò°ÍѤ·¤Æ¥Þ¥ë¥¦¥§¥¢¤òŸ³«¤¹¤ë¥¦¥¯¥é¥¤¥Ê¤òÁÀ¤¦¥µ¥¤¥Ð¡¼¹¶·âÆÃÄê
Fortinet¤Ï2024ǯ6·î3Æü(Êƹñ»þ´Ö)¡¢¡ÖMenace Unleashed: Excel File Deploys Cobalt Strike at Ukraine¡ÃFortinet Blog¡×¤Ë¤ª¤¤¤Æ¡¢Microsoft Excel¤ò°ÍѤ·¤¿¥¦¥¯¥é¥¤¥Ê¤òɸŪ¤È¤¹¤ë¹âÅ٤ʥµ¥¤¥Ð¡¼¹¶·â¤òÆÃÄꤷ¤¿¤ÈÅÁ¤¨¤¿¡£¤³¤Î¹¶·â¤Ç¤ÏExcel¤Ë°°Õ¤Î¤¢¤ëVBA¥Þ¥¯¥í¤òËä¤á¹þ¤ß¡¢Â¿Ãʳ¬¤Î¥Þ¥ë¥¦¥§¥¢Àïά¤ò»ÈÍѤ·¤Æ¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¤Î¡ÖCobalt Strike¡×¤òŸ³«¤¹¤ë¤È¤¤¤¦¡£
Menace Unleashed: Excel File Deploys Cobalt Strike at Ukraine¡ÃFortinet Blog
¡û¿¯³²·ÐÏ©
Fortinet¤Ë¤è¤ë¤È¡¢Æþ¼ê¤·¤¿Excel¥Õ¥¡¥¤¥ë¤Ë¤Ï¥æ¡¼¥¶¡¼¤òͶÏǤ¹¤ë¥¦¥¯¥é¥¤¥Ê¸ì¤Îʸ¾Ï¤¬½ñ¤«¤ì¤Æ¤ª¤ê¡¢¥Þ¥¯¥í¤Î͸ú²½¤òµá¤á¤ë¤È¤¤¤¦¡£¥Þ¥¯¥í¤ò͸ú²½¤¹¤ë¤È¡Ö·³»ö¥æ¥Ë¥Ã¥È¤Ë³ä¤êÅö¤Æ¤é¤ì¤¿Í½»»³Û¡×¤òɽ¼¨¤¹¤ë¤È¤µ¤ì¤ë¡£
°°Õ¤Î¤¢¤ëExcel¥Õ¥¡¥¤¥ë¤ÎÎã¡¡°úÍÑ¡§Fortinet
¤³¤Îͽ»»³Û¤Îɽ¼¨¤Ï¡Ö¤ª¤È¤ê¡×¤È¤ß¤é¤ì¡¢¥Þ¥¯¥í¤Ïʸ»úÎó¤Ë¥¨¥ó¥³¡¼¥É¤µ¤ì¤¿DLL(Dynamic Link Library¡§¥À¥¤¥Ê¥ß¥Ã¥¯¥ê¥ó¥¯¥é¥¤¥Ö¥é¥ê)¤ò¥Ð¥Ã¥¯¥°¥é¥¦¥ó¥É¤ÇŸ³«¤¹¤ë¡£¤½¤Î¸å¡¢rundll32.exe¤ò²ð¤·¤Æregsvr32¤ò¼Â¹Ô¤·¡¢Å¸³«¤·¤¿DLL¤ò¼Â¹Ô¤¹¤ë¡£
¿¯³²·ÐÏ© ¡¡°úÍÑ¡§Fortinet
DLL¤ÏÆñÆɲ½¤µ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¥í¡¼¥À¡¼¤Ç¡¢¼Â¹Ô¤¹¤ë¤È°ìÉô¤Î¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò¸¡½Ð¤·¤Æ½ªÎ»¤·¤è¤¦¤È¤¹¤ë¡£¼¡¤Ë¡¢¹¶·â¼Ô¤Î¥µ¡¼¥Ð¤«¤é¸å³¤Î¥Ú¥¤¥í¡¼¥É¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤è¤¦¤È¤¹¤ë¤¬¡¢Èï³²¼Ô¤Î¥Ç¥Ð¥¤¥¹¤¬¥¦¥¯¥é¥¤¥Ê¤Ë¸ºß¤¹¤ë¾ì¹ç¤Ë¸Â¤ê¥Ú¥¤¥í¡¼¥É¤Î¥À¥¦¥ó¥í¡¼¥É¤ËÀ®¸ù¤¹¤ë¡£
¤½¤Î¸å¡¢±Ê³À¤ò³ÎΩ¤¹¤ëDLL¤òŸ³«¡¢¼Â¹Ô¤¹¤ë¡£ºÇ½ªÃʤÎDLL¤Ë¤Ï¹âÅ٤ʥµ¥ó¥É¥Ü¥Ã¥¯¥¹¸¡½Ðµ¡Ç½¤ä¥¢¥ó¥Á¥Ç¥Ð¥Ã¥°µ¡Ç½¤¬¤¢¤ê¡¢¥»¥¥å¥ê¥Æ¥£¸¦µæ¼Ô¤Ë¤è¤ëʬÀϤò˸³²¤¹¤ë¡£Ê¬ÀÏ˸³²¤ò½ª¤¨¤ë¤È¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¤Î¡ÖCobalt Strike¡×¤ò¥á¥â¥ê¤ËŸ³«¤·¤Æ¼Â¹Ô¤¹¤ë¡£
¡û¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¤Î¡ÖCobalt Strike¡×
Cobalt Strike¤ÏFortra¤¬ÈÎÇ䤹¤ë¥Ú¥Í¥È¥ì¡¼¥·¥ç¥ó¥Æ¥¹¥È¥Ä¡¼¥ë¤Ç¡¢¤µ¤Þ¤¶¤Þ¤Ê¥µ¥¤¥Ð¡¼¹¶·â¤ò¥Æ¥¹¥ÈÌÜŪ¤Ç¼Â¹Ô¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤½¤Î¶¯ÎϤʵ¡Ç½¤Ï¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤Ë¹¥¤Þ¤ì¤Æ¤ª¤ê¡¢³¤Â±ÈǤÎCobalt Strike¤¬ÀѶËŪ¤Ë°ÍѤµ¤ì¤Æ¤¤¤ë¡£
¡ûÂкö
Microsoft OfficeÀ½ÉʤˤÏ¿¿ô¤Î¥×¥é¥°¥¤¥ó¤ä¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤¹¤ëËÉ٤ʵ¡Ç½¤¬¤¢¤ê¡¢¥µ¥¤¥Ð¡¼¹¶·â¤Ë°ÍѲÄǽ¤À¡£¤³¤ì¤éÀ½ÉʤΥե¡¥¤¥ë¤ò³«¤¯¾ì¹ç¤Ï¡¢»öÁ°¤Ë¿®Íê¤Ç¤¤ëºîÀ®¼Ô¤Î¥Õ¥¡¥¤¥ë¤«³Îǧ¤¹¤ëɬÍפ¬¤¢¤ê¡¢¤Þ¤¿¡¢¥Þ¥¯¥í¤Î¼Â¹Ô¤Ïµö²Ä¤·¤Ê¤¤¤³¤È¤¬¿ä¾©¤µ¤ì¤ë¡£
Fortinet¤Ï¤³¤Î¹¶·â¤ò²óÈò¤¹¤ë¤¿¤á¤Ë¥¢¥ó¥Á¥¦¥¤¥ë¥¹¥½¥Õ¥È¥¦¥§¥¢¤òƳÆþ¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Ä´ºº¤Î²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡û¿¯³²·ÐÏ©
Fortinet¤Ë¤è¤ë¤È¡¢Æþ¼ê¤·¤¿Excel¥Õ¥¡¥¤¥ë¤Ë¤Ï¥æ¡¼¥¶¡¼¤òͶÏǤ¹¤ë¥¦¥¯¥é¥¤¥Ê¸ì¤Îʸ¾Ï¤¬½ñ¤«¤ì¤Æ¤ª¤ê¡¢¥Þ¥¯¥í¤Î͸ú²½¤òµá¤á¤ë¤È¤¤¤¦¡£¥Þ¥¯¥í¤ò͸ú²½¤¹¤ë¤È¡Ö·³»ö¥æ¥Ë¥Ã¥È¤Ë³ä¤êÅö¤Æ¤é¤ì¤¿Í½»»³Û¡×¤òɽ¼¨¤¹¤ë¤È¤µ¤ì¤ë¡£
°°Õ¤Î¤¢¤ëExcel¥Õ¥¡¥¤¥ë¤ÎÎã¡¡°úÍÑ¡§Fortinet
¤³¤Îͽ»»³Û¤Îɽ¼¨¤Ï¡Ö¤ª¤È¤ê¡×¤È¤ß¤é¤ì¡¢¥Þ¥¯¥í¤Ïʸ»úÎó¤Ë¥¨¥ó¥³¡¼¥É¤µ¤ì¤¿DLL(Dynamic Link Library¡§¥À¥¤¥Ê¥ß¥Ã¥¯¥ê¥ó¥¯¥é¥¤¥Ö¥é¥ê)¤ò¥Ð¥Ã¥¯¥°¥é¥¦¥ó¥É¤ÇŸ³«¤¹¤ë¡£¤½¤Î¸å¡¢rundll32.exe¤ò²ð¤·¤Æregsvr32¤ò¼Â¹Ô¤·¡¢Å¸³«¤·¤¿DLL¤ò¼Â¹Ô¤¹¤ë¡£
¿¯³²·ÐÏ© ¡¡°úÍÑ¡§Fortinet
DLL¤ÏÆñÆɲ½¤µ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¥í¡¼¥À¡¼¤Ç¡¢¼Â¹Ô¤¹¤ë¤È°ìÉô¤Î¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ò¸¡½Ð¤·¤Æ½ªÎ»¤·¤è¤¦¤È¤¹¤ë¡£¼¡¤Ë¡¢¹¶·â¼Ô¤Î¥µ¡¼¥Ð¤«¤é¸å³¤Î¥Ú¥¤¥í¡¼¥É¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤è¤¦¤È¤¹¤ë¤¬¡¢Èï³²¼Ô¤Î¥Ç¥Ð¥¤¥¹¤¬¥¦¥¯¥é¥¤¥Ê¤Ë¸ºß¤¹¤ë¾ì¹ç¤Ë¸Â¤ê¥Ú¥¤¥í¡¼¥É¤Î¥À¥¦¥ó¥í¡¼¥É¤ËÀ®¸ù¤¹¤ë¡£
¤½¤Î¸å¡¢±Ê³À¤ò³ÎΩ¤¹¤ëDLL¤òŸ³«¡¢¼Â¹Ô¤¹¤ë¡£ºÇ½ªÃʤÎDLL¤Ë¤Ï¹âÅ٤ʥµ¥ó¥É¥Ü¥Ã¥¯¥¹¸¡½Ðµ¡Ç½¤ä¥¢¥ó¥Á¥Ç¥Ð¥Ã¥°µ¡Ç½¤¬¤¢¤ê¡¢¥»¥¥å¥ê¥Æ¥£¸¦µæ¼Ô¤Ë¤è¤ëʬÀϤò˸³²¤¹¤ë¡£Ê¬ÀÏ˸³²¤ò½ª¤¨¤ë¤È¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¤Î¡ÖCobalt Strike¡×¤ò¥á¥â¥ê¤ËŸ³«¤·¤Æ¼Â¹Ô¤¹¤ë¡£
¡û¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¤Î¡ÖCobalt Strike¡×
Cobalt Strike¤ÏFortra¤¬ÈÎÇ䤹¤ë¥Ú¥Í¥È¥ì¡¼¥·¥ç¥ó¥Æ¥¹¥È¥Ä¡¼¥ë¤Ç¡¢¤µ¤Þ¤¶¤Þ¤Ê¥µ¥¤¥Ð¡¼¹¶·â¤ò¥Æ¥¹¥ÈÌÜŪ¤Ç¼Â¹Ô¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤½¤Î¶¯ÎϤʵ¡Ç½¤Ï¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤Ë¹¥¤Þ¤ì¤Æ¤ª¤ê¡¢³¤Â±ÈǤÎCobalt Strike¤¬ÀѶËŪ¤Ë°ÍѤµ¤ì¤Æ¤¤¤ë¡£
¡ûÂкö
Microsoft OfficeÀ½ÉʤˤÏ¿¿ô¤Î¥×¥é¥°¥¤¥ó¤ä¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤¹¤ëËÉ٤ʵ¡Ç½¤¬¤¢¤ê¡¢¥µ¥¤¥Ð¡¼¹¶·â¤Ë°ÍѲÄǽ¤À¡£¤³¤ì¤éÀ½ÉʤΥե¡¥¤¥ë¤ò³«¤¯¾ì¹ç¤Ï¡¢»öÁ°¤Ë¿®Íê¤Ç¤¤ëºîÀ®¼Ô¤Î¥Õ¥¡¥¤¥ë¤«³Îǧ¤¹¤ëɬÍפ¬¤¢¤ê¡¢¤Þ¤¿¡¢¥Þ¥¯¥í¤Î¼Â¹Ô¤Ïµö²Ä¤·¤Ê¤¤¤³¤È¤¬¿ä¾©¤µ¤ì¤ë¡£
Fortinet¤Ï¤³¤Î¹¶·â¤ò²óÈò¤¹¤ë¤¿¤á¤Ë¥¢¥ó¥Á¥¦¥¤¥ë¥¹¥½¥Õ¥È¥¦¥§¥¢¤òƳÆþ¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Ä´ºº¤Î²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£