TrojanSpy.MSIL.XWORM.B
Windows


マルウェアタイプ:
スパイウェア/情報窃取型
破壊活動の有無:
なし
暗号化:
なし
感染報告の有無 :
はい
概要
スパイウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。 スパイウェアは、他のマルウェアに作成され、コンピュータに侵入します。
スパイウェアは、ワーム活動の機能を備えていません。
スパイウェアは、不正リモートユーザからのコマンドを実行し、感染コンピュータを改ざんします。 スパイウェアは、特定のWebサイトにアクセスし、情報を送受信します。
スパイウェアは、特定のWebサイトにアクセスし、情報を送受信します。
詳細
侵入方法
スパイウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
スパイウェアは、以下のマルウェアに作成され、コンピュータに侵入します。
インストール
スパイウェアは、以下の Mutex を作成し、メモリ上で自身の重複実行を避けます。
- LqnCS8W05cPMjMaK
感染活動
スパイウェアは、ワーム活動の機能を備えていません。
バックドア活動
スパイウェアは、不正リモートユーザからの以下のコマンドを実行します。
- pong → Responds by sending a "pong" string and internal interval counter back to the C2 server.
- rec → Releases the mutex lock, restarts the application, and terminates the current process.
- CLOSE → Shuts down the socket connection and terminates the application.
- uninstall → Triggers the uninstaller routine to clean up malware artifacts.
- update → Triggers the uninstaller routine and updates the malware stub with a new payload version.
- DW → Executes a powershell script.
- FM → Loads and executes an assembly directly in memory.
- LN → Downloads a file from a specified URL into the temp directory, and executes it.
- Urlopen → Opens a specified URL visibly (through a browser).
- Urlhide → Sends a background HTTP GET request to a specified URL.
- PCShutdown → Forces an immediate system shutdown.
- PCRestart → Forces an immediate system restart.
- PCLogoff → Logs off the current Windows session.
- RunShell → Executes commands silently via the command shell.
- StartDDos → Starts a multi-threaded HTTP POST flood attack.
- StopDDos → Aborts the active DDoS attack thread.
- StartReport → Initiates active window monitoring of running processes.
- StopReport → Aborts the active window monitoring thread of running processes.
- Xchat → Sends an "Xchat" string and the ID generated using system information.
- Hosts → Reads and sends the contents of the Windows hosts file (%System%\drivers\etc\host).
- Shosts → Modifies Windows hosts file.
- DDos → Sends a "DDos" string back to the C2.
- plugin → Checks if the plugin exists in the registry. If stored, it decompresses and executes the plugin. Otherwise, it requests from C2 if missing.
- savePlugin → Saves the decoded plugin to the registry, then decompresses and executes it.
- RemovePlugins → Deletes the registry subkey containing the stored plugin data and sends a confirmation message.
- OfflineGet → Returns an error stating the offline keylogger is not enabled.
- $Cap → Captures the primary screen, resizes it into a JPEG thumbnail, and exfiltrates it.
(註:%System%フォルダは、システムフォルダで、いずれのオペレーティングシステム(OS)でも通常、"C:\Windows\System32" です。.)
スパイウェアは、以下のWebサイトにアクセスし、情報を送受信します。
- using TCP:
- range2021.{BLOCKED}.com:2021
- {BLOCKED}.{BLOCKED}.31.98:2021
- {BLOCKED}.{BLOCKED}.112.141:2021
スパイウェアは、以下のWebサイトにアクセスし、不正リモートユーザからのコマンドを送受信します。
- using TCP:
- range2021.{BLOCKED}.com:2021
- {BLOCKED}.{BLOCKED}.31.98:2021
- {BLOCKED}.{BLOCKED}.112.141:2021
ルートキット機能
スパイウェアは、ルートキット機能を備えていません。
情報漏えい
スパイウェアは、以下の情報を収集します。
- Processor count
- Username
- Computer name
- OS version and architecture
- Hard drive size of system drive
- Malware's last modification/installation date
- USB spread status → Checks whether the running executable's filename matches the designated USB propagation name (USB.exe).
- Administrator privileges → Determines if the current user process is running under the Windows Administrator role
- Installed antivirus products
- GPU information
- CPU information
- RAM information
- Webcam availability
- Active window titles → Monitored periodically during window reporting routines or sent via ping check-ins to track running applications.
- System time → Sent alongside ping check-in packets to track activity timestamps.
- Windows hosts file contents → Read directly from the system directory when requested by the C2.
その他
スパイウェアは、以下のWebサイトにアクセスし、情報を送受信します。
スパイウェアは、以下を実行します。
- It is a Lua script that masquerades as a .TIFF file. It needs LuaJIT or a Lua interpreter in order to be executed.
- When executed, loads a .NET assembly in memory and executes its payload.
マルウェアは、脆弱性を利用した感染活動を行いません。
対応方法
手順 1
Windows 7、Windows 8、Windows 8.1、および Windows 10 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「TrojanSpy.MSIL.XWORM.B」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
ご利用はいかがでしたか? アンケートにご協力ください


