支払った身代金の平均額は約17万米ドル、復元できた割合は65% - ランサムウェア被害の現実 (01/17)
https://japan.zdnet.com/paper/20013085/30005356/
https://japan.zdnet.com/paper/20013085/30005356/
今更だが、メモが出てきたので書き留めておく。
Apache Log4jの脆弱性に関する対応について (2021/12/20)
https://help.dstmp.com/news/01211220/
『2021年12月14日までに弊社サービスの本脆弱性に関する対応は完了しております。』
「Apache Log4j」の脆弱性問題によるリコー製品への影響について (2021/12/15-24)
https://jp.ricoh.com/info/notice/2021/1215_1
複合機、プリンター、ソフトウェアなど概ね『影響なし』とのこと。
「RICOH カンタン文書活用 タイプZ」のエージェントソフトに影響あり。V1.7.1にアップデートすれば良い
CVE-2022-22965: Spring Coreにリモートコード実行脆弱性(SpringShell)、
すでに実際のエクスプロイトも (paloalto networks, 2022.03.31)
https://unit42.paloaltonetworks.jp/cve-2022-22965-springshell/
Spring Frameworkの脆弱性 CVE-2022-22965(Spring4shell)についてまとめてみた (piyolog, 2022.04.01)
https://piyolog.hatenadiary.jp/entry/2022/04/01/065946
US-CERTの先週の脆弱性サマリーから、いくつかピックアップする。
以下、次の順に
Primary Vendor -- Product, Description, Published, CVSS Score, Source & Patch Info
Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.
2021-06-28
9.3
CVE-2021-28570 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-28570
MISC https://helpx.adobe.com/ee/security/products/after_effects/apsb21-33.html
Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
2021-06-28
9
CVE-2021-28588 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-28588
MISC https://www.zerodayinitiative.com/advisories/ZDI-21-660/
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.
2021-06-25
9
CVE-2021-35047 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-35047
CONFIRM https://support.fidelissecurity.com/hc/en-us/categories/360001842694-Advisories-News-and-Policies
A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.
2021-06-29
CVE-2020-7868 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-7868
MISC https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36088
There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability. Successfully exploiting this vulnerability, the attacker can execute remote malicious code injection and to control the device.
AnyOfficeは、BYODを視野に入れたセキュリティ管理ツールで、MDMコンポーネントも含まれるらしい。 https://forum.huawei.com/enterprise/en/huawei-anyoffice-v200r002c10-deployment-guide-contents/thread/416297-867
2021-06-29
9.3
CVE-2021-22439 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22439
MISC https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210619-01-injection-en
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.
Takuyaさんという日本のクリエイターが開発したノートアプリとのこと。 https://webdesign-trends.net/entry/4163
2021-06-28
9.3
CVE-2021-20745 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-20745
MISC https://www.inkdrop.app/
MISC https://docs.inkdrop.app/releases/5.3.1
MISC https://jvn.jp/en/jp/JVN29949691/index.html
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.
2021-06-29
9
CVE-2021-31838 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-31838
CONFIRM https://kc.mcafee.com/corporate/index?page=content&id=SB10342
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.
ローカルの非特権ユーザが、設定変更により、外部スクリプトを特権ユーザとして実行できる。最新版にupdateすれば良い。
2021-06-28
7.2
CVE-2021-35523 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-35523
MISC https://github.com/Securepoint/openvpn-client/security/advisories/GHSA-v8p8-4w8f-qh34
MISC https://bogner.sh/2021/04/local-privilege-escalation-in-securepoint-ssl-vpn-client-2-0-30/
FULLDISC http://seclists.org/fulldisclosure/2021/Jun/59
MISC http://packetstormsecurity.com/files/163320/Securepoint-SSL-VPN-Client-2.0.30-Local-Privilege-Escalation.html
Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.
2021-06-29
7.2
CVE-2021-20079 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-20079
MISC https://www.tenable.com/security/tns-2021-07
以下「Severity Not Yet Assigned」からピックアップしたもの。
Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
caching proxy server "Apache Traffic Server"への潜在的リモート攻撃脆弱性
2021-06-29
not yet calculated
CVE-2021-27577 https://nvd.nist.gov/vuln/detail/CVE-2021-27577
← Base Score: 7.5 HIGH とされている。
MISC https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cusers.trafficserver.apache.org%3E
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2021-07-02
not yet calculated
CVE-2021-30554 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-30554
← Base Score: 8.8 HIGH となっている。
MISC https://crbug.com/1219857
MISC https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_17.html
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to FOS 6.4.3-08(NEC3.4.2) allow remote authenticated attackers to execute arbitrary OS commands with root privileges via unspecified vectors.
2021-06-28
not yet calculated
CVE-2021-20740 https://nvd.nist.gov/vuln/detail/CVE-2021-20740
← Base Score: 8.8 HIGH とされている。
MISC https://www.hitachi.co.jp/products/it/storage-solutions/global/sec_info/2021/2021_306.html
MISC https://jpn.nec.com/security-info/secinfo/nv21-011.html
MISC https://jvn.jp/en/jp/JVN21298724/index.html
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the device to crash and restart.
2021-06-30
not yet calculated
CVE-2021-22350 https://nvd.nist.gov/vuln/detail/CVE-2021-22350
← Base Score: 7.5 HIGH とされている。
MISC https://consumer.huawei.com/en/support/bulletin/2021/5/
There is a Configuration Defect Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.
2021-06-30
not yet calculated
CVE-2021-22352 https://nvd.nist.gov/vuln/detail/CVE-2021-22352
← Base Score: 7.8 HIGH とされている。
MISC https://consumer.huawei.com/en/support/bulletin/2021/5/
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.
2021-06-28
not yet calculated
CVE-2021-20574 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-20574
← Base Score: 8.8 HIGH (CVSS:3.1 ...) とされている。
CONFIRM https://www.ibm.com/support/pages/node/6465875
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/199252
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
2021-06-30
not yet calculated
CVE-2021-21671 https://nvd.nist.gov/vuln/detail/CVE-2021-21671
← Base Score: 7.5 HIGH とされている。
CONFIRM https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-2371
MLIST http://www.openwall.com/lists/oss-security/2021/06/30/1
LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print).
2021-07-01
not yet calculated
CVE-2019-25048 https://nvd.nist.gov/vuln/detail/CVE-2019-25048
← Base Score: 7.1 HIGH とされている。
MISC https://github.com/libressl-portable/portable/commit/17c88164016df821df2dff4b2b1291291ec4f28a
MISC https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13914
MISC https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libressl/OSV-2020-1923.yaml
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).
2021-07-02
not yet calculated
CVE-2021-36125 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-36125
← Base Score: 7.5 HIGH とされている。
MISC https://phabricator.wikimedia.org/T260865
MISC https://gerrit.wikimedia.org/r/q/I97d8b3236b5abed8ba9a9c4d3ab5050c2e782c22
Windows Print Spooler Remote Code Execution Vulnerability
2021-07-02
not yet calculated
CVE-2021-34527 https://nvd.nist.gov/vuln/detail/CVE-2021-34527
← Base Score: 8.8 HIGH (CVSS 3.1)とされている。Criticalじゃないのか?
※ PrintNightmare 過去記事
MISC https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34527
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the ¤tsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).
2021-06-30
not yet calculated
CVE-2021-35973 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-35973
← Base Score: 9.8 CRITICAL とされている。
MISC https://gynvael.coldwind.pl/?lang=en&id=736
MISC https://kb.netgear.com/000063785/Security-Advisory-for-Authentication-Bypass-on-WAC104-PSV-2021-0075
Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.
2021-06-30
not yet calculated
CVE-2021-34384 https://nvd.nist.gov/vuln/detail/CVE-2021-34384
← Base Score: 7.8 HIGH (CVSS:3.1)とされている。
CONFIRM https://nvidia.custhelp.com/app/answers/detail/a_id/5205
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor
2021-06-29
not yet calculated
CVE-2021-34550 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-34550
← Base Score: 7.5 HIGH とされている。
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40392
CONFIRM https://blog.torproject.org/node/2041
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.
2021-06-29
not yet calculated
CVE-2021-34549 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-34549
← Base Score: 7.5 HIGH とされている。
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40391
CONFIRM https://blog.torproject.org/node/2041
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.
2021-06-29
not yet calculated
CVE-2021-34548 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-34548
← Base Score: 7.5 HIGH とされている。
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40389
CONFIRM https://blog.torproject.org/node/2041
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.
2021-06-29
not yet calculated
CVE-2021-28691 https://nvd.nist.gov/vuln/detail/CVE-2021-28691
← Base Score: 7.8 HIGH とされている。
MISC https://xenbits.xenproject.org/xsa/advisory-374.txt
Bulletin (SB21-186) Vulnerability Summary for the Week of June 28, 2021 (07/05)
https://us-cert.cisa.gov/ncas/bulletins/sb21-186
事件報告他に『更新プログラムでは、電話会議ソフトウェアプロバイダーはデフォルトで会議のパスワードを追加し、参加する会議をランダムにスキャンする機能を無効にしました』ってアレゲだ。
2020年3月下旬、マサチューセッツ州の高校で、教師がテレビ会議ソフトウェアZoomを使用してオンラインクラスを行っている間に、身元不明の個人が教室にダイヤルしたと報告しました。 この個人は冒とく的な言葉を叫び、それから指導の途中で先生の自宅の住所を叫びました。
マサチューセッツにある2番目の学校は、身元不明の個人がZoomミーティングにアクセスしていることを報告しました。 この事件では、個人はビデオカメラで見ることができ、卍の入れ墨が表示されていました。
電話会議の乗っ取りの脅威を軽減するには、次の手順を実行
・会議や教室を公開しない。ミーティングパスワードを要求するか、待合室機能を使用してゲストの許可を制御する。
・SNSで、テレビ会議や教室へのリンクを共有しない。
・画面共有オプションを管理。画面共有を「ホストのみ」に変更する。
・最新のバージョンを使用する。
・最後に、組織のテレワークポリシーまたはガイドが物理的および情報セキュリティの要件に対応していることを確認してください。
技術情報サイトの「Bleeping Computer」は2020年3月31日、Zoom Windowsクライアントのチャット機能にUNCパス関連の脆弱性が見つかったと伝えた。悪用された場合、不正なリンクをクリックしたユーザーのWindows認証情報が盗まれる恐れがある。
ユーザーがこのUNCパスのリンクをクリックすると、WindowsはSMBファイル共有プロトコルを使ってリモートのサイトに接続し、指定されたファイルを開こうとする。その際にWindowsはデフォルトで、ユーザーのログイン名とNTLMパスワードハッシュを送信する。これを「Hashcat」のような無料ツールでクラッキングすれば、ユーザーのパスワードを見破ることが可能だという。
セキュリティ専門家はこれについて「UNCリンクをクリックさせてプログラムを起動させることも可能だ」と指摘している。
Zoomについては、ユーザーの情報がFacebookに送られていたことが発覚するなど、セキュリティやプライバシーを巡る問題が立て続けに浮上している。
CVSS Score 6.8
macOSの4.4.53932.0709以前のZoom Clientでは、CVE-2019-13450とは異なる脆弱性であるリモートコードの実行が可能です。ZoomOpener デーモン(別名:隠しウェブサーバ)が実行されているにもかかわらず、Zoom Client がインストールされていないか、または開くことができない場合、攻撃者は悪意を持って細工された起動 URL を使ってリモートでコードを実行することができます。注意: ZoomOpenerは、このツールが有効で2019-07-10 MRTConfigDataを持っている場合、Apple Malware Removal Tool (MRT)によって削除されます。
発行日 : 2019-07-12 最終更新日 : 2019-08-30
CVSS Score 4.3
macOS上のZoom Client 4.4.4.4~RingCentral 7.0.136380.0312 では、リモート攻撃者がビデオカメラをアクティブにした状態でユーザーにビデオ通話に強制的に参加させることができます。これは、任意の Web サイトがローカルホストポート 19421 または 19424 で Zoom Web サーバーと対話できるために発生します。注: Zoom クライアントが過去にインストールされた後にアンインストールされた場合、マシンは脆弱なままです。悪用をブロックするには、ZDisableVideo環境設定および/またはWebサーバーを殺す、~/.zoomusディレクトリを削除する、~/.zoomusプレーンファイルを作成するなどの追加の手順が必要です。
公開日 : 2019-07-09 最終更新日 : 2019-07-16
CVSS Score 7.5
Windows (バージョン 4.1.34814.1119 以前)、Mac OS (バージョン 4.1.34801.1116 以前)、および Linux (2.4.129780.0915 以下) の Zoom クライアントは、不正なメッセージ処理に対して脆弱です。リモートの認証されていない攻撃者は、ターゲット クライアントの機能を呼び出すために、会議の出席者または Zoom サーバからの UDP メッセージを詐称することができます。これにより、攻撃者は会議の出席者を削除したり、ユーザーからのメッセージを詐称したり、共有画面を乗っ取ったりすることが可能になります。
公開日 : 2018-11-30 最終更新日 : 2019-10-09
CVSS Score 5.4
Android用アプリ「ZOOM Cloud Meetings (aka.us.zoom.videomeetings)」の@7F060008は、SSLサーバーからのX.509証明書を検証していないため、中間者攻撃者がサーバーになりすまし、細工された証明書を介して機密情報を取得することができます。
公開日 : 2014-09-09 最終更新日 : 2014-09-20
Pulse Secureの「情報漏えいの脆弱性(CVE-2019-11510)」や「コマンドインジェクションの脆弱性(CVE-2019-11539)」などは、実証コードを含む情報が公開されており、これら脆弱性を組み合わせることで遠隔の攻撃者から製品が動作する機器をroot権限にて乗っ取ることも可能という非常に大きなリスクとなっています。』
最近の被害事例として、大手外貨両替サービスを提供するTravelex社がREvil(Sodinokibi)ランサムウェアに大規模感染した
VPN製品にもセキュリティ修正が含まれる最新のアップデートを適用するための組織ポリシーが不可欠です。
しかしながら、VPN製品へのアップデート適用は、多くの場合クライアントソフトウェアのアップデートなどが伴うことで利用者への負担が大きくなったり、製品ベンダーからのアップデート提供が遅れ、いわゆる0day脆弱性の期間が発生する可能性もないとは言えません。
即時のアップデート適用が難しい場合には、製品ベンダーが提供しているワークアラウンド(緩和策)があればそれを実施したり、IPSや次世代ファイアウォールなどのセキュリティ製品を予めネットワーク内に組み込んでおくことで脆弱性を突く攻撃を検知・防御できる可能性があるため、これらをアップデート適用までの暫定対処として実施いただくことを強く推奨します。
Pulse Secure、Palo Alto Networks、Fortinet、Citrixの企業VPNサーバ等へのハックについて。。。。だそうです。
イラン政府支援ハッキングユニットは「IT、通信、石油およびガス、航空、政府、およびセキュリティの各セクターの企業」を標的に。実力はロシア、中国、北朝鮮などと並びうる。
本APTグルーブは1-day vulnerabilityの悪用能力や、カスタマイズドマルウェア開発能力がある。2019年、Pulse Secure「Connect」VPN(CVE-2019-11510)、Fortinet FortiOS VPN(CVE-2018-13379)、およびPalo Alto Networksの「Global Protect」で開示された脆弱性を迅速に武器化した。後にCitrix "ADC" VPNで公開された脆弱性であるCVE-2019-19781も。
最初の足場を獲得すると、C2サーバーと通信して、バックドアを植えるために使用できる一連のカスタムVBScriptファイルをダウンロードするThe Hacker News はCVEへのリンクなど、使いやすい印象。
さらに、ウイルス対策ソフトウェアによる検出を回避するために、バックドアコード自体をチャンクでダウンロードする。これらの個々のファイルをつなぎ合わせて実行可能ファイルを作成するのは、「combine.bat」。
これらのタスクを実行して持続性を実現するために、Juicy PotatoやInvoke the Hashなどのツールを悪用して、高レベルの特権を獲得し、ネットワークを横切って移動する。
攻撃者が開発した他のツールには次のものがある。
・STSRCheck-ターゲットネットワークのデータベース、サーバー、および開いているポートをマッピングし、デフォルトの資格情報でログ記録することでブルートフォースするツール。
・Port.exe-定義済みのポートとサーバーをスキャンするツール。
攻撃者がlateral movement能力を獲得すると、攻撃者は最終段階に移動します:関連情報について、侵害されたシステムをスキャンし、(POWSSHNETと呼ばれる自己開発ツールを使用して)リモートデスクトップ接続を確立して、またはハードコードされたIPアドレスへのソケットベースの接続を開いて、ファイルを盗み出します。
TTP(Tactics, Techniques and Procedures)より考察する脅威の検出と緩和策
マルウェアの配送について
海外拠点向けには、日本とは異なる現地文化を考慮したメール訓練や注意喚起が必要であると思われます。又、マルウェアの配送よりも後フェーズの攻撃、侵入拡大フェーズで使われるTickのテクニックが検知できるかの確認も有効と考えられます。
攻撃について
Officeのゼロデイ攻撃や新しい脆弱性を悪用した攻撃は観測されていませんが、攻撃者の侵入し易さをコントロールするという点で、日常的なパッチマネージメントは有効な緩和策になると思われます。特にインターネットからアクセス可能な機器の脆弱性は優先して対応する必要があります。
インストールされるRAT、遠隔操作(C&Cについて)
検出が困難になっています。メモリ上でのみ悪性コードが動くタイプのローダーには、メモリスキャンによる検出が可能です。
正規サイトを改ざんしC&Cとして悪用するため、シグネチャベースのネットワークセンサーでは検出が困難になっています。
但し、攻撃者の変更が難しい(もしくは注意が行き届いていない)と思われるケースもあり、固定のユーザエージェントを使う検体も存在します。その場合は、その特徴を踏まえたルールで検出が可能です。
ネットワーク検出観点でいうと、アノマリな通信を検出するNDR(Network Detection & Response)製品に効果が期待できます。
侵入拡大・目的実行』
特に標的型攻撃がEDR製品の導入前に始まっていたケースでは、足場をつくるフェーズが完了しているため、製品が持つ検知パターンでの検出漏れが懸念されます。
EDR群の製品を導入した場合には、定期的に収集したログに含まれる正規コマンドの実行状況やそのコマンドがIT技術者以外の所有する端末によって頻繁に実行されていないかどうかといった視点で分析して、攻撃の検出漏れがないように注意...
Daserfの検出方法
Daserf は C2 サーバとの通信を確立するために、10 秒間に 1 回程度の頻度で C2 サーバ上にある特定の ASP ファイルに向け、HTTP POST 通信を発生させます。
プロキシログには同一の PC から発生した大量の POST 通信が記録されることになる ...
通信を行う際に HTTP ヘッダに付与される User-Agent は、マルウェアの中にハードコードされており、最近の Daserf のバージョンでは "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; SV1)"
Autoruns6などを利用して Windows 起動時に自動実 行するスタートアップやサービスのレジストリ値を確認する方法です。
図 10では、Daserf がAdobe ARMというファイル名を利用し、スタートアップ時に AdobeARM.exeが実行するよう設定されていることが見て取れます。
Daserf を利用する攻撃者の手口
季節のグリーティングメールに見せかけた標的型メールにファイルを添付し、それを開かせるように誘導してマルウェアに感染させます。
メールの受信者が添付ファイルを開くと、図 16のような Flash アニメーションが現れますが、その裏ではマルウェア ( ダウンローダ ) が実行されることになります。
攻撃者は、クリスマスやお正月というイベントに乗じて標的型メールを送り付けていると見られます。
Microsoft Office の脆弱性であるCVE-2015-2545 を突いた手法も利用されている可能性が高い ...
おわりに』
Daserf による被害範囲や漏えいした可能性のあるデータはある程度、特定することができます。事案対応から痕跡として見つかったマルウェアを解析し、マルウェアによって暗号化された通信をデコードすることで特定しますが、そのためにもプロキシサーバの通信ログはもちろん、DNS サーバの通信ログも日常的に記録しておくことを推奨します。加えて、ディスク容量やシステムの負荷などの問題もありますが、通信パケットについてもスイッチングハブやルータのミラーポートを利用して記録しておくとなお良いでしょう。
エグゼクティブサマリー
機密情報を窃取するサイバーエスピオナージの被害は、即座に影響が出ない上、技術盗用などの実被害との因果関係が表面化しづらいため、経営者の耳に届かず、現場のマネージャーで処理されてしまうことが多々あります。しかしながら、窃取された機密情報は中国政府や中国企業の手に渡ることで、結果として日本企業の産業競争力を徐々に低下させていくことになります。
2018年度に観測された標的業種と目的
・メディア、シンクタンク by APT10, DarkHote: 政治、外交上の機密情報の入手
・製造業(主に化学、重工、海洋技術)by Tick, WINNTI, BlackTech: 設計図、製造技術など知的財産の入手
・テレコム by Taidoor: 顧客情報、将来の攻撃インフラ情報の入手
RAT Loader
RATローダーは、DLLファイルで、攻撃者によりサービスプログラムとして登録され、rundll32.exe経由で起動する ...
下記パラメータで起動されるものがありました。
rundll32.exe "c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg32.dll", win7load SCPolicys
このDLL自体はRAT機能を有しておらず、通信先からダウンロードするコードをメモリ上で実行するローダータイプのマルウェアである
TTPsより考察する脅威の検出と緩和策
攻撃について
Officeのゼロデイ攻撃や新しい脆弱性を悪用した攻撃は観測されていませんが、攻撃者の侵入し易さをコントロールするという点で、日常的なパッチマネージメントは有効な緩和策になると思われます
インストールされるRAT、遠隔操作 (C&Cについて)
現在のところ、インシデントレスポンスや脅威の検出においては、攻撃者の変更が難しい (もしくは注意が行き届いていない)と思われる、TickグループDatperのMutex値やUser-Agent値、DragonOKのUser-Agent値などがあり、攻撃者のRATやC&C通信の特徴を利用する事で脅威の検出が可能です
侵入拡大・目的実行
EDRの監視ログを積極的に分析するハンティングにより攻撃が発見されました。
スレットハンティングの必要性』
センサーによるパターンドリブンな検出が悪性(Malicious)な攻撃痕跡だけを拾い上げるのに対し、ヒューマンドリブン、つまり人間(アナリスト)による検出は、パターンドリブンなアプローチでは誤検知のリスクがあって検出対象とならない痕跡を、分析対象として積極的に拾い上げることからスタートします。
『NECは「不正ログインを受けたことについては18年7月以降、防衛省に説明し了解を得た。NECと防衛省の1対1の話であり、情報が流出した証拠もなく、被害が出ているわけでもないので発表しなかった」と説明した』
『その大手メーカーを単独で狙うようなハッキングに対しては無力であり、万全とはとても言えない』と言って経営が納得するか?不正アクセスの原因となった製品名は「ノーコメント」とする日経BP、
『「社内調査に時間がかかった」というより「流出してしまった情報が何であるかすら把握できないぐらい、気づくのが遅れた」ことを意味するならば、この問題を報じる側も相当なリテラシーの高さでないと正確な報道はむつかしいのでは』
『トレンドマイクロのOfficeScanバージョン11.0およびXG(12.0)は、ディレクトリトラバーサルの脆弱性を利用して、任意のzipファイルからウイルスバスターCorp.サーバー上の特定のフォルダにファイルを抽出する攻撃者によって悪用される可能性があり、リモートコード実行(RCE)につながる可能性があります。 リモートプロセスの実行はWebサービスアカウントにバインドされており、使用するWebプラットフォームによっては、許可が制限されている場合があります。 攻撃を試みるには、ユーザー認証が必要です。HIGH以上のものは原則対応、というのがベストプラクティス。
... Base Score: 7.5 HIGH 』(機械翻訳)
『管理サーバーにアクセスできるクライアント端末を操作できることも条件 ...
攻撃者が外部から遠隔で直接的に該当製品のサーバーにあるファイルを変更できるものではない』
でも、ここまでの侵害が起きた。社内のシステム管理PCが先に侵害され、さらにそこに至るための他の侵害もあった、と考えるのが自然だろう。それぞれ公表されれば、大いに参考になると思うのだが。。。
機械翻訳 https://translate.google.com/translate?sl=en&tl=ja&u=https%3A%2F%2Fwww.welivesecurity.com%2F2018%2F10%2F01%2Fprotecting-your-smart-tv%2F
1–ルーターの資格情報を保護する
2-ネットワークとデバイスを並べ替える
3-スマートTVの構成
4-最新のアップデートをインストールする
5-完全なセキュリティソリューションを使用する
6-注意してアプリケーションをダウンロードする
7-ストリーミングを注意して使用する
- セキュリティスキャン
- 05:28:27.911212 IP 9tpro.40576 > 161.117.97.169.443:
- 05:31:53.863714 IP 9tpro.47980 > 161.117.96.220.443:
- アプリを管理
- 05:32:41.040942 IP 9tpro.49908 > 31.13.82.1.443:(edge-star-shv-01-nrt1.facebook.com):
- テーマ
- 05:36:13.615951 IP 9tpro.38778 > 47.88.216.202.443:
- アプリ情報
- 05:38:51.270767 IP 9tpro.48287 > 172.217.161.74.443: UDP (nrt20s09-in-f10.1e100.net)
- プライバシーポリシー
- 05:44:45.376614 IP 9tpro.38920 > 172.217.25.106.443: (nrt13s51-in-f106.1e100.net)
- SIM挿入
- 05:50:49.604603 IP 9tpro.38930 > 172.217.25.106.443: (nrt13s51-in-f106.1e100.net)
- システムアプリアップデーター
- 05:55:08.934297 IP 9tpro.37536 > 47.74.233.137.443:
- 壁紙
- 05:59:12.892563 IP 9tpro.38990 > 47.88.216.202.443:
- 壁紙
- 05:59:12.893150 IP 9tpro.47566 > 103.208.1.44.80:
- SIM挿入&指紋追加登録後の電源オフ→オン時
- 06:02:57.562357 IP 9tpro.42352 > 161.117.71.89.443:
- SIM挿入&指紋追加登録後の電源オフ→オン時
- 06:02:59.997131 IP 9tpro.37478 > 47.74.170.156.5222:
- Gmail設定
- 06:44:30.442075 IP 9tpro.41684 > 172.217.25.77.443:
1 t3.market.mi-img.com.
1 thm.market.intl.xiaomi.com.
2 sa.api.intl.miui.com.
3 find.api.micloud.xiaomi.net.
4 privacy.mi.com.
7 t5.market.mi-img.com.
8 api.zhuti.intl.xiaomi.com.
8 global.market.xiaomi.com.
8 www.miui.com.
30 api.ad.intl.xiaomi.com.
40 data.mistat.intl.xiaomi.com.
Xiaomi端末から不要アプリを削除する (2020/01/13)https://akasaka-taro.blogspot.com/2020/01/xiaomi_13.html (以上、2021/07/22追記)
https://bey.jp/?p=37414『adups(バックドアを仕掛けている会社)のIPアドレスは(略)』
https://forum.xda-developers.com/redmi-note-3/help/discussions-plz-dev-look-analyst-t3463321『AnalyticsCore.apk = com.miui.analytics』
>find "pm " tmp-web.txt | find /v ".xiaomi." | find /v ".miui." | find /v ".mi"ここまでやるか。
---------- TMP-WEB.TXT
pm uninstall -k-ユーザー0 com.android.browser
pm uninstall -k-ユーザー0 com.android.calendar
pm uninstall -k-ユーザー0 com.android.email
pm uninstall -k --user 0 com.android.soundrecorder
pm uninstall -k --user 0 com.google.android.apps.docs
pm uninstall -k --user 0 com.google.android.gm
pm uninstall -k-ユーザー0 com.google.android.music
pm uninstall -k-ユーザー0 com.google.android.videos
pm uninstall -k-ユーザー0 com.google.android.apps.photos
pm uninstall -k-ユーザー0 com.google.android.marvin.talkback
pm uninstall -k --user 0 com.facebook.appmanager
pm uninstall -k --user 0 com.facebook.services
pm uninstall -k --user 0 com.facebook.system
一応チェックすると、
https://www.virustotal.com/gui/url/a3616b17f297ef3ecbf764644b71394b297124d0ee141fd7797c22af8bcbe6b5/detection unratedな6件を除き、目下 100%のベンダーで clean との評価
・Disabled package installer, stuck in bootloop (2017/08/25)
・How do I disable App Vault in MIUI? (2018/08/09)
Xiaomi Super bloatware List 2020・System Apps Updater: com.xiaomi.discover は削除しない
https://lucacesarano.medium.com/xiaomi-super-bloatware-list-2020-db38ace9e9e1『But since this is Miui and there are eternal troubles, with the application settings configured in the background. I will not touch and do not advise you.』
Debloating (removing bloatware) applications from MIUI・Battery & performance: com.miui.powerkeeper
https://devcondition.com/article/removing-unneeded-miui-applications/『URGENT CLEAR_DATA + FREEZ com.xiaomi.discover System app updater Gizmo, for updating, first of all, MIUI applications: browser, downloads, notes, etc., etc. But it can hook other applications. Decide for yourself. I do not delete, but FREEZe. Periodically including, to check for updates.』
『0patchのマイクロパッチは常駐プログラム「0patch Agent」により、実行中のプロセスに対して直接適用される。パッチ適用に再起動は必要なく、適用の有無も切り替え可能だ。』と、『仮想パッチ記事』よりも、動作原理が明快に示されている点は好印象。
『0patchのパッチ作成計画としては、Windowsの月例更新に合わせて出されるMicrosoftのセキュリティアドバイザリからWindows 7/Server 2008にも適用されそうな脆弱性を特定し、Windows 10の更新プログラムの変更部分から同じコードがWindows 7/Server 2008にも存在するかどうかを確認する。あとはPOCの収集とマイクロパッチの作成を行い、POCによるテストとその他の副作用に関するテストを経てパッチをリリースするとのこと。』
『We've just produced a micropatch for #shadowbrokers EsteemAudit! Organizations with Windows Server 2003 and Windows XP, we got your back.』
関連
・OpenVPN linux client automatically at boot、メモ
https://akasaka-taro.blogspot.com/2019/12/openvpn-linux-client-automatically-at.html
関連3. ラズパイに有線LANアダプタを追加、eth1として稼働済みとします。
・raspberry pi を access point 化 (2018/01/09)
https://akasaka-taro.blogspot.com/2018/06/raspiap.html
関連
・有線LANアダプタ、ラズパイ(Debian系)用
https://akasaka-taro.blogspot.com/2020/01/landebian.html
$DHCP-ETH01: ケーブル接続クライアント向けにeth1で割り当てるDHCPレンジ
$DNS-ETH01: 上記レンジのDNSサーバIP
$DHCP-WLAN0: Wi-Fiクライアント向けにwlan0で割り当てるDHCPレンジ
$DNS-WLAN0: 上記レンジのDNSサーバIP
$MANSION-ROUTER: マンションの(直結・上位の)ルータIP
$SSL-VPN-ADDR-IN-UTM: UTM自身に割り当てられたSSL-VPNのIP
[main]
plugins=ifupdown,keyfile
dns = none # この行を追加
参考
・[RHEL7]/etc/resolv.conf 強制上書き無効 (2017/10/20)
https://qiita.com/a-hiroyuki/items/559ccde6d948d31af939