Malware/malware analysis 22

[Hancitor ๋ถ„์„ (3)] ๋ณตํ˜ธํ™”๋ฅผ ํ†ตํ•œ C2 ๊ตฌ์„ฑ(configuration) ์ •๋ณด ์ถ”์ถœ

Hancitor ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ๋งˆ์ง€๋ง‰ ๊ธ€์ž…๋‹ˆ๋‹ค.์ƒ˜ํ”Œ(ํŒจํ‚น๋œ dll) ํ•ด์‹œ(SHA256)๋Š” 8ff43b6ddf6243bd5ee073f9987920fa223809f589d151d7e438fd8cc08ce292์ž…๋‹ˆ๋‹ค.  ์ด๋ฒˆ ๊ธ€์—์„œ๋Š” ์ด์ „์— ์–ป์€ ์•”ํ˜ธํ™”๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณตํ˜ธํ™”ํ•ด๋ณด๊ณ  ์–ด๋–ค ์ •๋ณด์ธ์ง€ ์•Œ์•„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜๋Š” ์ด์ „ ํฌ์ŠคํŒ…์—์„œ ์–ป์€ ์•”๋ณตํ˜ธํ™” ์ •๋ณด์ž…๋‹ˆ๋‹ค.์ดˆ๊ธฐ ํ‚ค: C58B00157F8E9288๋ฐ์ดํ„ฐ ์ฃผ์†Œ: 0x10004010 (.data ์„น์…˜)๋ฐ์ดํ„ฐ ํฌ๊ธฐ: 0x2000ํ•ด์‹œ ์•Œ๊ณ ๋ฆฌ์ฆ˜(KDF): SHA1๋ณตํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜: RC4RC4 ํ‚ค ํฌ๊ธฐ: 5๋ฐ”์ดํŠธ  ์•”๋ณตํ˜ธํ™” ์ •๋ณด๋ฅผ ์ด์šฉํ•˜์—ฌ ์•”ํ˜ธํ™”๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณตํ˜ธํ™”ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์•„๋ž˜๋Š” Python์œผ๋กœ ์ž‘์„ฑ๋œ ๋ณตํ˜ธํ™” ์ฝ”๋“œ์ž…๋‹ˆ๋‹ค. (Alexandre Borges์˜ "Malware ..

[Hancitor ๋ถ„์„ (2)] ์•”๋ณตํ˜ธํ™” API ๋ถ„์„ ๋ฐ ๋ฐ์ดํ„ฐ ์ถ”์ถœ

์ง€๋‚œ๋ฒˆ์— ์–ธํŒจํ‚นํ•œ Hancitor ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์ด์–ด์„œ ๋ถ„์„ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์ƒ˜ํ”Œ(ํŒจํ‚น๋œ dll) ํ•ด์‹œ(SHA256)๋Š” 8ff43b6ddf6243bd5ee073f9987920fa223809f589d151d7e438fd8cc08ce292์ž…๋‹ˆ๋‹ค.   ์–ธํŒจํ‚นํ•œ DLL์˜ imports ์ค‘์—์„œ ADVAPI32.dll์ด ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. ํ•ด๋‹น DLL์˜ ์—ฌ๋Ÿฌ ์•”ํ˜ธ ๊ด€๋ จ API๋“ค์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ํฌ์ŠคํŒ…์—์„œ๋Š” ์•”ํ˜ธํ™” ๊ณผ์ •์— ๋Œ€ํ•ด ๋ถ„์„ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.  ์–ธํŒจํ‚นํ•œ DLL์„ IDA pro๋กœ ์—ด์–ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. IDA์˜ ์ƒ‰์ƒ ๋ฐ”์—์„œ ๋ฏธํƒ์ƒ‰ ์˜์—ญ(Unexplored)์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์šฐ์„ ์ ์œผ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ์ฒ˜๋ฆฌํ•˜๋Š” ํ•จ์ˆ˜๋‚˜ ์ƒ‰์ƒ ๋ฐ”์˜ ๋ฏธํƒ์ƒ‰ ์˜์—ญ(Unexplored)์—์„œ ์•”ํ˜ธ ๊ด€๋ จ ์ •๋ณด๋ฅผ ์ฐพ์•„๋ณด๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.  ๋ฏธํƒ์ƒ‰ ์˜์—ญ(Un..

[Hancitor ๋ถ„์„ (1)] ์–ธํŒจํ‚น(Unpacking) ๋ฐ IAT ์ถ”์ถœ

Hancitor ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์ฐจ๊ทผ์ฐจ๊ทผ ๋ถ„์„ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์ด๋ฒˆ ํฌ์ŠคํŒ…์—์„œ๋Š” ํŒจํ‚น๋˜์–ด ์žˆ๋Š” DLL์„ ์–ธํŒจํ‚นํ•˜๊ณ  IAT๋ฅผ ์ถ”์ถœํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์ƒ˜ํ”Œ ํ•ด์‹œ(SHA256)๋Š” 8ff43b6ddf6243bd5ee073f9987920fa223809f589d151d7e438fd8cc08ce292์ž…๋‹ˆ๋‹ค.  ์ƒ˜ํ”Œ์„ PE-bear๋กœ ํ™•์ธํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.๋จผ์ € import๋œ ํ•ญ๋ชฉ๋“ค์„ ๋ณด๋ฉด ํฅ๋ฏธ๋กœ์šด DLL์ด๋‚˜ API๋Š” ์—†์Šต๋‹ˆ๋‹ค. (์ด ์ƒ˜ํ”Œ์ด ํŒจํ‚น๋œ ์•…์„ฑ์ฝ”๋“œ์ž„์„ ์•Œ๊ณ  ์žˆ๊ธด ํ•˜์ง€๋งŒ) ๋„คํŠธ์›Œํฌ ํ†ต์‹ , ์•”ํ˜ธํ™” ๊ด€๋ จ DLL์ด ์—†๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์•„ ์ƒ˜ํ”Œ์ด ํŒจํ‚น๋˜์—ˆ๋‹ค๊ณ  ์˜์‹ฌํ•ด๋ณผ ์ˆ˜ ์žˆ๋Š” ํŠน์ง•์ž…๋‹ˆ๋‹ค.  ๋˜ pestudio ํˆด๋กœ sections๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด .data ์„น์…˜์˜  raw ํฌ๊ธฐ์™€ virtual ํฌ๊ธฐ ๊ฐ„์˜ ์ฐจ์ด๊ฐ€ ํฐ ๊ฒƒ์„ ํ™•์ธํ•ด๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. .dat..

ModeLoader #Anderial #Lazarus

ModeLoader[ ๊ฐœ์š” ] - Andariel ๊ทธ๋ฃน์ด ์ฃผ๋กœ ์‚ฌ์šฉํ•˜๋Š” JS ์•…์„ฑ์ฝ”๋“œ - ํŒŒ์ผ ์ž์ฒด์ ์œผ๋กœ ์ƒ์„ฑ๋˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ mshta๋ฅผ ํ†ตํ•˜์—ฌ ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ ๋‹ค์šด๋กœ๋“œ๋˜์–ด ๋™์ž‘ * ์ฃผ๋กœ ์ž์‚ฐ ๊ด€๋ฆฌ ์†”๋ฃจ์…˜์„ ์•…์šฉํ•˜์—ฌ mshta๋ฅผ ๋™์ž‘ (Andariel ๊ทธ๋ฃน์€ ๊ณผ๊ฑฐ Innorix Agent๋ถ€ํ„ฐ ์•…์„ฑ์ฝ”๋“œ ์œ ํฌ๋ฅผ ์œ„ํ•ด ๊ตญ๋‚ด ์—…์ฒด์˜ ์ž์‚ฐ ๊ด€๋ฆฌ ์†”๋ฃจ์…˜๋“ค์„ ์ง€์†์ ์œผ๋กœ ์•…์šฉ) - ์ดˆ๊ธฐ ์นจํˆฌ์šฉ์œผ๋กœ, ์ถ”ํ›„ ๋ฏธ๋ฏธ์นด์ธ ์™€ ๊ฐ™์€ ์ถ”๊ฐ€ ์•…์„ฑ์ฝ”๋“œ๋ฅผ ๋‹ค์šด๋กœ๋“œ [ ๋ถ„์„ ๋‚ด์šฉ ] - ๋‚œ๋…ํ™”๋œ ๋ฌธ์ž์—ด ๋ฆฌ์ŠคํŠธ์—์„œ ์ถ”์ถœ(๋ณตํ˜ธ)ํ•˜์—ฌ ์‚ฌ์šฉ - C&C ์„œ๋ฒ„์— ์ ‘์†ํ•˜์—ฌ ๋‹ค์šด๋กœ๋“œํ•œ ์‘๋‹ต ๋ฐ์ดํ„ฐ์— ๋”ฐ๋ผ ํ–‰์œ„๋ฅผ ์ˆ˜ํ–‰ 1) ์‘๋‹ต ๋ฐ์ดํ„ฐ๊ฐ€ ’kill'์ธ ๊ฒฝ์šฐ: ์‹คํ–‰ ์ฐฝ ์ข…๋ฃŒ 2) ์‘๋‹ต ๋ฐ์ดํ„ฐ๊ฐ€ ’kill'์ด ์•„๋‹Œ ๊ฒฝ์šฐ: ์‘๋‹ต ๋ฐ์ดํ„ฐ๋ฅผ ์‹คํ–‰์‹œํ‚ด - ์ž์ฒด ๋””์ฝ”๋”ฉ ..

2023๋…„ 11์›” ์ฒญ๊ตฌ๋‚ด์—ญ.zip #APT37

IOCsMD5: B58E06FC0EF74ABFD5EDE1E44AA8DE4C SHA256: 7387D00194ADF8A8F15E12E191BFAA8DBD6C7AF227DDC14D7FEC742B30ADC245 File name: 2023๋…„ 11์›” ์ฒญ๊ตฌ๋‚ด์—ญ File type: ZIP File size: 42,247MB MD5: 015BA89BCE15C66BAEBC5FD94D03D19E File name: 2000215005_20231107_20231127_rvim.html.lnk File type: LNK File size: 42,240MB MD5: 77EE19F76A09A51941F3E9AE48821817 SHA256: B77ECFDDB35EC517D44E437D5CD032801D8C538893948EF66..