²Ä0039´Á¡E2016.12.20 µo¦æ
ISSN 2077-8813

­º­¶ >±MÃD³ø¾É

BOT¡GH-Worm´c·Nµ{¦¡ÀË´ú»P­×¸É

§@ªÌ¡G§õ¬ü¶² / »OÆW¤j¾Ç­pºâ¾÷¤Î¸ê°Tºô¸ô¤¤¤ßµ{¦¡³]­p®v
¥»¤åÂà¸ü¦Û»OÆW¤j¾Ç­p¸ê¤¤¤ß¥_°Ï¾Ç³N¸ê°T¦w¥þºû¹B¤¤¤ß

H-Worm¬O¥_°ÏASOCÁÒ¤U¥x¥_°Ïºô¤¤¤ßªñ´Á°»´ú¼Æ¶q³Ì¦hªº´c·N¦æ¬°¡C¥»³ø§i»¡©úH-Worm´c·Nµ{¦¡ªº¯S¼x¤Î¼vÅT¡A¨ÃÄÄ­z¥_°ÏASOCÀË´ú»P¤ÀªRH-Worm´c·Nµ{¦¡¤§¦æ¬°¡A¥H¤Î´£¨Ñ¨Ï¥ÎªÌ¨¾½d¤Î²¾°£¦¹´c·Nµ{¦¡ªº¤èªk¡C

H-Worm´c·Nµ{¦¡Â²¤¶
įÂÎ(Worm)»P¯f¬r(Virus)¬Û¦ü¡A¬O¤@ºØ¯à°÷¦Û§Ú½Æ»sªº¹q¸£µ{¦¡¡C»P¯f¬r¤£¦Pªº¬O¡AįÂΤ£»Ý­nªþ¥[¦b¥ô¦óµ{¦¡¤º¡A¤]¤£»Ý­n¨Ï¥ÎªÌ¾Þ§@´N¯à°÷¦Û§Ú½Æ»s©Î°õ¦æ¡C
¯f¬rªº§ðÀ»¤è¦¡¤j¦h¬Oª½±µ¯}Ãa¨ü·P¬Vªº¨t²Î¡CįÂÎÁöµM¤]·|·´·l©Î­×§ï¥D¾÷¤ºªºÀɮסA¦ý¥¦­Ì¤j¦h¤´±Ä¨ú¤À´²¦¡ªýÂ_ªA°È§ðÀ»(DDoS)ªº¤è¦¡¡A¶ëÃz¥Ø¼Ð¥D¾÷ªººô¸ôÀW¼e¡A­°§C¥Ø¼Ð¥D¾÷ªº°õ¦æ®Ä²v¡A¶i¦Ó¼vÅT¥D¾÷ªº¥¿±`¨Ï¥Î¡C[µù1]¡C
¦ÓH«¬Ä¯ÂÎ(H-Worm)¬O¤@­Ó¥H¦hºØ³~®|´²¼½ªº´c·N VBScript µ{¦¡¡C·í¨Ï¥ÎªÌ¥¼ª`·N©Î¤£¤p¤ß¶}±Ò¨ü·P¬Vªº¹q¤l¶l¥ó®É¡AįÂΥߧY³Q°õ¦æ¡A·j´M¯S©wªºÀÉ®×Ãþ«¬¨Ã­×§ï©ÎÂмgÀɮפº®e¡C¥Ñ©óH-Wormªºµ{¦¡½X±Ä¨úªº§ðÀ»¤è¦¡¬°Âл\©Î­×§ï¦Ó«D§R°£¸ÓÀɮסA©Ò¥H¦bÀɮתº´_­ì¤W¬Û¹ï§xÃø¡C
¦ÓH-WormÁÙ¦³¤@­Ó¯S©Ê¡A±q¤w¸g³QíL«Íºô¸ô(botnets)·P¬V±±¨îªº¥D¾÷·í¤¤¡AÀu¥ý¬D¿ï¥i¥H¥[§Ö§ðÀ»³W¼Ò©Î³t«×ªº¥D¾÷¨Ï¥Î¡A¥H«K´£¤É§ðÀ»»P·P¬V¤§®Ä²v¡C

H-Worm´c·Nµ{¦¡ªº¼vÅT
H-Worm°£¤F¥i¥H¶i¦æ²³æªº»·µ{©R¥O»P¾Þ§@¥~¡A§ðÀ»ªÌ¤]¥i»·µ{§Ö³t¤É¯ÅíL«Í¹q¸£(Bot)¥\¯à¡A´£«e¦b¨t²Î­×¸Éº|¬}¤§«e¶i¦æ§ðÀ»¡C¨å«¬ªºBot¬¡°Ê¥]§t§ðÀ»ªÌ±q³o¨Ç¨ü§ðÀ»ªº¨t²Î¤¤¡A¤U¸ü·sªº§ðÀ»¼Ò²Õ¥HÀò¨ú±Ó·P°T®§¡]¨Ò¦pWindows serial number, AOL accountµ¥µ¥¡^¡A¨Ã§Q¥Î³o¨Ç¨ü·P¬Vªº¨t²Î¹ï¨ä¥L¨t²Î¶i¦æDDoS§ðÀ»¡C

H-Worm´c·Nµ{¦¡ªº¯S¼x
1. H-Worm¶i¦æºô¸ô¬¡°Ê®Éªº«Ê¥]¤º®e¥i¯à¥]§t¤U¦CÃöÁä¦r¡G
„I /is-sending
„I /is-recving
„I /is-enum-driver
„I /is-enum-process
„I /is-cmd-shell
„I /is-ready
„I \x3c\x7c\x3eplus\x3c\x7c\x3e
„I \x3c\x7c\x3eunderworld final\x3c\x7c\x3e
2. «Ê¥]¤º®e¥i¥HÆ[¹î¨ì¨ü·P¬Vªº¥D¾÷¡A·|³z¹LHTTP¤è¦¡¦V¯S©wC&C Server (Command and Control Server)¦^³ø¡G


¹Ï¤@ ®×¨Ò«Ê¥]¤¤¨ü·P¬V¥D¾÷³z¹LHTTP¤è¦¡¦Vlovesyr.sytes.net:8844¶i¦æ¦^³ø


¹Ï¤G Snort rule¬°°»´ú·P¬VH-worm«á¡A¦V¯S©w´c·Ndomain¬d¸ß

H-Worm´c·Nµ{¦¡¥i¯à³y¦¨ªº¦M®`
¬°¤FÁA¸Ñ·P¬V¦¹´c·N³nÅé«á»PC&C Server¶¡ªº¤¬°Ê¡A§Ú­Ì¦b§@·~¨t²ÎWindows 7 Professional 64¦ì¤¸ªºVMÀô¹Ò¤U¶i¦æ¹ê´ú¡C±q¹Ï¤T¤¤¥i¥Hµo²{¡A¨ü·P¬Vªº¥D¾÷¨äClient ID¡BComputer Name¡BUser Name¤ÎOperation System¬ÛÃö°T®§¬Ò·|¥X²{¦b¨ä²M³æ¤º¡A±q¹Ï¤T¡B¹Ï¥|¤¤¥i¥Hµo²{§ðÀ»ªÌ°£¤F¥i¥H¨Ï¥Î¦¹´c·Nµ{¦¡¤¤ªºprocess list¥\¯àÀH®É§ó·s(refresh)¨ü·P¬V¥D¾÷ªº¤u§@²M³æ¡A¤]¥i¥HÀH®É°±¤î(exit process)¥¿¦b°õ¦æªº¤u§@µ{§Ç¡C


¹Ï¤T ¨ü·P¬Vªº¥D¾÷²M³æ


¹Ï¥| §ó·s©ÎÃö³¬process list¤¤ªºµ{§Ç

±q¥H¤U¹Ï¡^¡B¹Ï¤»Åã¥Ü§ðÀ»ªÌ¥i¥H¥ô·NÂsÄý¨ü·P¬V¥D¾÷ªºµwºÐ¡A¨Ã¥i¤U¸ü´c·Nµ{¦¡¡A¤]¥i¥H¤W¶Ç·Q­nÅѨúªºÀɮסC¦pªG§ðÀ»ªÌ¨S¦³¤W¶Ç»P¤U¸ü¥ô¦ó¸ê®Æ¡A¤]¥i¥H¿ï¾Üª½±µ§R°£·P¬V¥D¾÷ªº¥ô·N¸ê®Æ¥H¹F¨ì¯}Ãa¤§¥Øªº¡C


¹Ï¤­ Àɮ׸ê®ÆªººÞ²z


¹Ï¤» ¤W¶Ç»P¤U¸ü¸ê®Æ

°£¤F¤W­zªºÂ²©ö«ü¥O¥i¥H¹F¨ì¬YºØµ{«×ªº¯}Ãa©Î¦M®`¤§¥~¡A¦¹´c·Nµ{¦¡¥]§t¤Fcmd shell§ðÀ»¤è¦¡¡C¥i¥H°õ¦æ»·µ{ªºCommand«ü¥O¡A³o¨Ç«ü¥O¥]§t¤Fª½±µÃö¾÷(shutdown /s)©Î­«·s¶}¾÷(shutdown /r)µ¥¡C


¹Ï¤C °õ¦æ»·µ{ªºCommand«ü¥O

¦p¦ó¨¾½dH-Worm´c·Nµ{¦¡
¥D¾÷¦b¤U¦C±¡ªp¤U®e©ö¾D¨üH-Worm´c·Nµ{¦¡·P¬V¡G
1. ¥¼¦w¸Ë¨¾¬r³nÅé©ó¹q¸£¥D¾÷©Î¨¾¬r³nÅé¤w¥¢®Ä¡C
2. ¨Ï¥Î«Dªk©Î¨Ó¸ô¤£©úªº³nÅé¡C
3. ¨S¦³©w´Á§ó·s§@·~¨t²Î¡C
4. H-Wormªº§ðÀ»³~®|¤j¦h¸g¥Ñ¹q¤l¶l¥ó¡A©Ò¥H¯Ê¥F¹ï¶l¥óªÀ¥æ¤uµ{§ðÀ»ªº¤F¸Ñ»P»{ÃѤ]¬O¤@¤j­ì¦]¡C
¸Ó¦p¦ó¨¾½dH-Worm´c·Nµ{¦¡¡AÀ³¸¨¹ê¥H¤U¨Ï¥Î¦æ¬°¡G
1. ½T«O¨¾¬r³nÅ骺¦w¸Ë»P¨Ï¥Î¥\¯à¥¿±`¡C
2. ¤£¨Ï¥Î«Dªk©Î¨Ó¸ô¤£©úªº³nÅé¡A¥ô¦ó¥iºÃÀɮ׬Ҷ·¸g¥Ñ¨¾¬r³nÅé±½´y«á¨Ï¥Î¬°§´¡C
3. °È¥²¸¨¹ê§@·~¨t²Î¤§§ó·s¡C
4. ¶}±Ò¹q¤l¶l¥óªºªþ¥ó©ÎÂIÀ»¹q¤l¶l¥ó¤¤ªº³sµ²¡A¬Ò¶·¼f·V¬°¤§¡C
¡°H-Wormªº¨¾¬r³nÅé°»´ú²v«D±`°ª¡A°È¥²¸¨¹ê¨¾¬r³nÅ骺¨¾Å@»P±½´y¡C

¦p¦óÀË´ú¤Î²¾°£H-Worm´c·Nµ{¦¡
Ãö©óH-WormªºÀË´ú¡A­º¥ý§Ú­Ì¦bvirustotal¤W¶Ç¨ü·P¬Vªº¼Ë¥»ÀÉ®×(SHA256:a6bd7ae00b55b684c10e7c708b00ce46b091115fc0e4d2d8bc3e415b5dfca496)¡A¥i¥Hµo²{¥¦³Q°»´ú¨ìªº¾÷²v«D±`°ª(¹Ï8)(¼Ë«~ 81c153256efd9161f4d89fe5fd7015bc©M4543daa6936dde54dda8782b89d5daf1¤]¬OH-Wormªº¼Ë¥»)¡C
§Ú­Ì°w¹ïH-WormªºÀË´ú©Ò¨Ï¥Îªº¨¾¬r³nÅ鬰Microsoft Security Essentials¡A¨Ï¥Î¦¹®M¤u¨ã¡A§Ú­Ì¥i¥H°»´ú¨Ã²¾°£´c·Nªº¤å¥ó¸ê®Æ¡A¸Ó¦p¦óÀË´ú¤Î²¾°£H-Worm´c·Nµ{¦¡¡A©ó¤U¤è¨BÆJ¤¤»¡©ú¡G


¹Ï¤K H-Worm©óvirustotalªº°»´úµ²ªG

¹ï©óH-WormįÂΪºÀË´ú¤Î²¾°£¤è¦¡§Ú­Ì¶É¦V©ó¨¾¬r³nÅ骺¸¨¹ê¡C¥H¤U¥ÎMicrosoft Security Essentials¨¾¬r³nÅ黡©ú¡G


¹Ï¤E ¥D¾÷ÀÉ®×±½´y


¹Ï¤Q H-Wormªº¨¾¬r³nÅé°»´ú²v«D±`°ª


¹Ï¤Q¤@ ²¾°£H-Worm´c·Nµ{¦¡

°Ñ¦Ò¸ê®Æ
[µù1]¤Þ¦ÛWikipedia¡A
http://zh.wikipedia.org/wiki/%E9%9B%BB%E8%85%A6%E8%A0%95%E8%9F%B2
[µù2]¤Þ¦ÛFireEye¡A
http://www.fireeye.com/blog/technical/threat-intelligence/2013/09/now-you-see-me-h-worm-by-houdini.html
[µù3]
https://www.virustotal.com/zh-tw/