解析者: Mariefher Grace Villanueva   

 プラットフォーム:

Windows

 危険度:
 ダメージ度:
 感染力:
 感染確認数:
 情報漏えい:

  • マルウェアタイプ:
    スパイウェア/情報窃取型

  • 破壊活動の有無:
    なし

  • 暗号化:
    なし

  • 感染報告の有無 :
    はい

  概要

感染経路 インターネットからのダウンロード, 他のマルウェアからの作成

スパイウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。 スパイウェアは、他のマルウェアに作成され、コンピュータに侵入します。

スパイウェアは、ワーム活動の機能を備えていません。

スパイウェアは、不正リモートユーザからのコマンドを実行し、感染コンピュータを改ざんします。 スパイウェアは、特定のWebサイトにアクセスし、情報を送受信します。

スパイウェアは、特定のWebサイトにアクセスし、情報を送受信します。

  詳細

ファイルサイズ 240,754 bytes
タイプ Other
メモリ常駐 はい
発見日 2026年8月20日
ペイロード URLまたはIPアドレスに接続, 情報収集, その他

侵入方法

スパイウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

スパイウェアは、以下のマルウェアに作成され、コンピュータに侵入します。

インストール

スパイウェアは、以下の Mutex を作成し、メモリ上で自身の重複実行を避けます。

  • LqnCS8W05cPMjMaK

感染活動

スパイウェアは、ワーム活動の機能を備えていません。

バックドア活動

スパイウェアは、不正リモートユーザからの以下のコマンドを実行します。

  • pong → Responds by sending a "pong" string and internal interval counter back to the C2 server.
  • rec → Releases the mutex lock, restarts the application, and terminates the current process.
  • CLOSE → Shuts down the socket connection and terminates the application.
  • uninstall → Triggers the uninstaller routine to clean up malware artifacts.
  • update → Triggers the uninstaller routine and updates the malware stub with a new payload version.
  • DW → Executes a powershell script.
  • FM → Loads and executes an assembly directly in memory.
  • LN → Downloads a file from a specified URL into the temp directory, and executes it.
  • Urlopen → Opens a specified URL visibly (through a browser).
  • Urlhide → Sends a background HTTP GET request to a specified URL.
  • PCShutdown → Forces an immediate system shutdown.
  • PCRestart → Forces an immediate system restart.
  • PCLogoff → Logs off the current Windows session.
  • RunShell → Executes commands silently via the command shell.
  • StartDDos → Starts a multi-threaded HTTP POST flood attack.
  • StopDDos → Aborts the active DDoS attack thread.
  • StartReport → Initiates active window monitoring of running processes.
  • StopReport → Aborts the active window monitoring thread of running processes.
  • Xchat → Sends an "Xchat" string and the ID generated using system information.
  • Hosts → Reads and sends the contents of the Windows hosts file (%System%\drivers\etc\host).
  • Shosts → Modifies Windows hosts file.
  • DDos → Sends a "DDos" string back to the C2.
  • plugin → Checks if the plugin exists in the registry. If stored, it decompresses and executes the plugin. Otherwise, it requests from C2 if missing.
  • savePlugin → Saves the decoded plugin to the registry, then decompresses and executes it.
  • RemovePlugins → Deletes the registry subkey containing the stored plugin data and sends a confirmation message.
  • OfflineGet → Returns an error stating the offline keylogger is not enabled.
  • $Cap → Captures the primary screen, resizes it into a JPEG thumbnail, and exfiltrates it.

(註:%System%フォルダは、システムフォルダで、いずれのオペレーティングシステム(OS)でも通常、"C:\Windows\System32" です。.)

スパイウェアは、以下のWebサイトにアクセスし、情報を送受信します。

  • using TCP:
    • range2021.{BLOCKED}.com:2021
    • {BLOCKED}.{BLOCKED}.31.98:2021
    • {BLOCKED}.{BLOCKED}.112.141:2021

スパイウェアは、以下のWebサイトにアクセスし、不正リモートユーザからのコマンドを送受信します。

  • using TCP:
    • range2021.{BLOCKED}.com:2021
    • {BLOCKED}.{BLOCKED}.31.98:2021
    • {BLOCKED}.{BLOCKED}.112.141:2021

ルートキット機能

スパイウェアは、ルートキット機能を備えていません。

情報漏えい

スパイウェアは、以下の情報を収集します。

  • Processor count
  • Username
  • Computer name
  • OS version and architecture
  • Hard drive size of system drive
  • Malware's last modification/installation date
  • USB spread status → Checks whether the running executable's filename matches the designated USB propagation name (USB.exe).
  • Administrator privileges → Determines if the current user process is running under the Windows Administrator role
  • Installed antivirus products
  • GPU information
  • CPU information
  • RAM information
  • Webcam availability
  • Active window titles → Monitored periodically during window reporting routines or sent via ping check-ins to track running applications.
  • System time → Sent alongside ping check-in packets to track activity timestamps.
  • Windows hosts file contents → Read directly from the system directory when requested by the C2.

その他

スパイウェアは、以下のWebサイトにアクセスし、情報を送受信します。

    スパイウェアは、以下を実行します。

    • It is a Lua script that masquerades as a .TIFF file. It needs LuaJIT or a Lua interpreter in order to be executed.
    • When executed, loads a .NET assembly in memory and executes its payload.

    マルウェアは、脆弱性を利用した感染活動を行いません。

      対応方法

    対応検索エンジン: 9.800
    初回 VSAPI パターンバージョン 21.272.04
    初回 VSAPI パターンリリース日 2026年8月25日
    VSAPI OPR パターンバージョン 21.273.00
    VSAPI OPR パターンリリース日 2026年8月26日

    手順 1

    Windows 7、Windows 8、Windows 8.1、および Windows 10 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

    手順 2

    最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「TrojanSpy.MSIL.XWORM.B」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。


    ご利用はいかがでしたか? アンケートにご協力ください