TrojanSpy.Win32.QAKBOT.YEAK-A
Trojan:Win32/Qakbot.GQ!MTB(MICROSOFT)
Windows
- マルウェアタイプ: スパイウェア/情報窃取型
- 破壊活動の有無: なし
- 暗号化: はい
- 感染報告の有無: はい
概要
スパイウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
スパイウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
スパイウェアは、以下のファイルを作成します。
- {Malware File Path}\{Malware File Name}.dat
- %User Temp%\~{Malware File Name}.tmp
(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。)
スパイウェアは、感染したコンピュータ内に以下のように自身のコピーを作成します。
- %Application Data%\Microsoft\{Random characters}\{Random characters}.exe
(註:%Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。)
スパイウェアは、以下のプロセスを追加します。
- {Malware File Path}\{Malware File Name}.exe /C ? To check if it is being run in a virtual environment.
- {Malware File Path}\{Malware File Name}.exe /W
- %Windows%\explorer.exe (%System%\mobsync.exe or %Program Files%\Internet Explorer\iexplore.exe if not found)
- %System%\schtasks.exe /create /tn {GUID} /tr "\"{Malware File Path}\{Malware File Name}.exe\"" /sc HOURLY /mo 5 /F
- %System%\cmd.exe /c ping.exe -n 6 127.0.0.1 & type "%System%\calc.exe" > "{Malware Filepath}\{Malware File Name}" ? Overwriting itself with calc.exe
(註:%Program Files%フォルダは、デフォルトのプログラムファイルフォルダです。C:\Program Files in Windows 2000(32-bit)、Server 2003(32-bit)、XP、Vista(64-bit)、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files"です。また、Windows XP(64-bit)、Vista(64-bit)、7(64-bit)、8(64-bit)、8.1(64-bit)、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Program Files(x86)" です。)
スパイウェアは、以下の Mutex を作成し、メモリ上で自身の重複実行を避けます。
- Global\{GUID}
スパイウェアは、感染コンピュータ上のメモリに以下のプロセスを確認すると、自身を終了します。
- Fiddler.exe
- samp1e.exe
- sample.exe
- runsample.exe
- lordpe.exe
- regshot.exe
- Autoruns.exe
- dsniff.exe
- VBoxTray.exe
- HashMyFiles.exe
- ProcessHacker.exe
- Procmon.exe
- Procmon64.exe
- netmon.exe
- vmtoolsd.exe
- vm3dservice.exe
- VGAuthService.exe
- pr0c3xp.exe
- ProcessHacker.exe
- CFF Explorer.exe
- dumpcap.exe
- Wireshark.exe
- idaq.exe
- idaq64.exe
- TPAutoConnect.exe
- ResourceHacker.exe
- vmacthlp.exe
- OLLYDBG.EXE
- windbg.exe
- bds-vision-agent-nai.exe
- bds-vision-apis.exe
- bds-vision-agent-app.exe
- MultiAnalysis_v1.0.294.exe
- x32dbg.exe
- VBoxTray.exe
- VBoxService.exe
- Tcpview.exe
自動実行方法
スパイウェアは、自身のコピーがWindows起動時に自動実行されるよう以下のレジストリ値を追加します。
HKEY_CURENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
{Random Characters} = {Malware File Path}\{Malware Filename}.exe
プロセスの終了
スパイウェアは、感染コンピュータ上で以下のプロセスが常駐されていることを確認した場合、そのプロセスを終了します。
- Microsoftedge.exe
情報漏えい
トロイの木馬化されたアプリケーションが実行されると、[Malware]は、以下の情報を収集します。
- Operating System Information
- Processor Information
- Installed Anti-Virus Products
- Running Processes
- Computer Name
- User Name
- IP Address
情報収集
スパイウェアは、HTTPポスト を介して、収集した情報を以下のURLに送信します。
- http://{BLOCKED}.{BLOCKED}.158.61:443/t3
- http://{BLOCKED}.{BLOCKED}.107.192:995/t3
- http://{BLOCKED}.{BLOCKED}.154.10:443/t3
- http://{BLOCKED}.{BLOCKED}.160.116:443/t3
- http://{BLOCKED}.{BLOCKED}.107.192:2222/t3
- http://{BLOCKED}.{BLOCKED}.107.192:443/t3
- http://{BLOCKED}.{BLOCKED}.242.138;0;465
- http://{BLOCKED}.{BLOCKED}.176.32:443/t3
- http://{BLOCKED}.{BLOCKED}.223.148:443/t3
- http://{BLOCKED}.{BLOCKED}.39.147:443/t3
- http://{BLOCKED}.{BLOCKED}.13.128:8443/t3
- http://{BLOCKED}.{BLOCKED}.209.42:2222/t3
- http://{BLOCKED}.{BLOCKED}.8.10:995/t3
- http://{BLOCKED}.{BLOCKED}.105.194:443/t3
- http://{BLOCKED}.{BLOCKED}.69.242:443/t3
- http://{BLOCKED}.{BLOCKED}.87.107:443/t3
- http://{BLOCKED}.{BLOCKED}.40.155:443/t3
- http://{BLOCKED}.{BLOCKED}.3.6:443/t3
- http://{BLOCKED}.{BLOCKED}.145.30:443/t3
- http://{BLOCKED}.{BLOCKED}.181.98:443/t3
- http://{BLOCKED}.{BLOCKED}.42.12:995/t3
- http://{BLOCKED}.{BLOCKED}.161.32:995/t3
- http://{BLOCKED}.{BLOCKED}.15.223:443/t3
- http://{BLOCKED}.{BLOCKED}.99.97:995/t3
- http://{BLOCKED}.{BLOCKED}.16.80:443/t3
- http://{BLOCKED}.{BLOCKED}.155.12:443/t3
- http://{BLOCKED}.{BLOCKED}.99.97:2222/t3
- http://{BLOCKED}.{BLOCKED}.99.97:443/t3
- http://{BLOCKED}.{BLOCKED}.130.172:995/t3
- http://{BLOCKED}.{BLOCKED}.252.177:995/t3
- http://{BLOCKED}.{BLOCKED}.112.10:995/t3
- http://{BLOCKED}.{BLOCKED}.36.238:443/t3
- http://{BLOCKED}.{BLOCKED}.9.69:995/t3
- http://{BLOCKED}.{BLOCKED}.100.129:443/t3
- http://{BLOCKED}.{BLOCKED}.25.63:443/t3
- http://{BLOCKED}.{BLOCKED}.1.237:443/t3
- http://{BLOCKED}.{BLOCKED}.36.241:443/t3
- http://{BLOCKED}.{BLOCKED}.155.12:2222/t3
- http://{BLOCKED}.{BLOCKED}.198.161:443/t3
- http://{BLOCKED}.{BLOCKED}.27.132:443/t3
- http://{BLOCKED}.{BLOCKED}.165.134:443/t3
- http://{BLOCKED}.{BLOCKED}.104.123:443/t3
- http://{BLOCKED}.{BLOCKED}.70.216:443/t3
- http://{BLOCKED}.{BLOCKED}.38.31:993/t3
- http://{BLOCKED}.{BLOCKED}.24.29:443/t3
- http://{BLOCKED}.{BLOCKED}.24.21:2222/t3
- http://{BLOCKED}.{BLOCKED}.127:995/t3
- http://{BLOCKED}.{BLOCKED}.15.220:443/t3
- http://{BLOCKED}.{BLOCKED}.13.151:443/t3
- http://{BLOCKED}.{BLOCKED}.60.189:995/t3
- http://{BLOCKED}.{BLOCKED}.103.146:2222/t3
- http://{BLOCKED}.{BLOCKED}.227.86:443/t3
- http://{BLOCKED}.{BLOCKED}.221.232:443/t3
- http://{BLOCKED}.{BLOCKED}.50.62:995/t3
- http://{BLOCKED}.{BLOCKED}.26.119:443/t3
- http://{BLOCKED}.{BLOCKED}.132.233:2222/t3
- http://{BLOCKED}.{BLOCKED}.174.49:995/t3
- http://{BLOCKED}.{BLOCKED}.116.226:995/t3
- http://{BLOCKED}.{BLOCKED}.247.224:443/t3
- http://{BLOCKED}.{BLOCKED}.189.64:443/t3
- http://{BLOCKED}.{BLOCKED}.155.12:995/t3
- http://{BLOCKED}.{BLOCKED}.162.253:443/t3
- http://{BLOCKED}.{BLOCKED}.22.145:443/t3
- http://{BLOCKED}.{BLOCKED}.202.234:443/t3
- http://{BLOCKED}.{BLOCKED}.97.227:995/t3
- http://{BLOCKED}.{BLOCKED}.141.42:995/t3
- http://{BLOCKED}.{BLOCKED}.211.239:443/t3
- http://{BLOCKED}.{BLOCKED}.56.171:443/t3
- http://{BLOCKED}.{BLOCKED}.255.159:995/t3
- http://{BLOCKED}.{BLOCKED}.217.98:443/t3
- http://{BLOCKED}.{BLOCKED}.206.170:995/t3
- http://{BLOCKED}.{BLOCKED}.5.157:443/t3
- http://{BLOCKED}.{BLOCKED}.244.118:995/t3
- http://{BLOCKED}.{BLOCKED}.191.27:443/t3
- http://{BLOCKED}.{BLOCKED}.18.250:443/t3
- http://{BLOCKED}.{BLOCKED}.47.123:443/t3
- http://{BLOCKED}.{BLOCKED}.96.164:443/t3
- http://{BLOCKED}.{BLOCKED}.152.231:443/t3
- http://{BLOCKED}.{BLOCKED}.144.238:443/t3
- http://{BLOCKED}.{BLOCKED}.227.124:443/t3
- http://{BLOCKED}.{BLOCKED}.151.218:2222/t3
- http://{BLOCKED}.{BLOCKED}.238.30:443/t3
- http://{BLOCKED}.{BLOCKED}.32.167:443/t3
- http://{BLOCKED}.{BLOCKED}.17.223:995/t3
- http://{BLOCKED}.{BLOCKED}.191.38;0;0
- http://{BLOCKED}.{BLOCKED}.247.242:443/t3
- http://{BLOCKED}.{BLOCKED}.204.240:995/t3
- http://{BLOCKED}.{BLOCKED}.75.201:443/t3
- http://{BLOCKED}.{BLOCKED}.149.212:443/t3
- http://{BLOCKED}.{BLOCKED}.193.83:443/t3
- http://{BLOCKED}.{BLOCKED}.26.178:443/t3
- http://{BLOCKED}.{BLOCKED}.204.189:995/t3
- http://{BLOCKED}.{BLOCKED}.33.182:2222/t3
- http://{BLOCKED}.{BLOCKED}.112.234:443/t3
- http://{BLOCKED}.{BLOCKED}.59.46:2222/t3
- http://{BLOCKED}.{BLOCKED}.8.10:443/t3
- http://{BLOCKED}.{BLOCKED}.89.245:2222/t3
- http://{BLOCKED}.{BLOCKED}.35.237:995/t3
- http://{BLOCKED}.{BLOCKED}.96.127;0;990
- http://{BLOCKED}.{BLOCKED}.112.197:443/t3
- http://{BLOCKED}.{BLOCKED}.119.125:443/t3
- http://{BLOCKED}.{BLOCKED}.49;0;2078
- http://{BLOCKED}.{BLOCKED}.47.70:443/t3
- http://{BLOCKED}.{BLOCKED}.177.152:443/t3
- http://{BLOCKED}.{BLOCKED}.231.35:443/t3
- http://{BLOCKED}.{BLOCKED}.207.104:443/t3
- http://{BLOCKED}.{BLOCKED}.227.208:443/t3
- http://{BLOCKED}.{BLOCKED}.223.253:443/t3
- http://{BLOCKED}.{BLOCKED}.15.10:995/t3
- http://{BLOCKED}.{BLOCKED}.39.108:443/t3
- http://{BLOCKED}.{BLOCKED}.76:443/t3
- http://{BLOCKED}.{BLOCKED}.136.237:443/t3
- http://{BLOCKED}.{BLOCKED}.14.130;0;22
- http://{BLOCKED}.{BLOCKED}.234.36:2222/t3
- http://{BLOCKED}.{BLOCKED}.216.202:443/t3
- http://{BLOCKED}.{BLOCKED}.69:995/t3
- http://{BLOCKED}.{BLOCKED}.35.201:443/t3
- http://{BLOCKED}.{BLOCKED}.16.93:443/t3
- http://{BLOCKED}.{BLOCKED}.2.92:995/t3
- http://{BLOCKED}.{BLOCKED}.7.143:443/t3
- http://{BLOCKED}.{BLOCKED}.195.67:443/t3
- http://{BLOCKED}.{BLOCKED}.19.192:443/t3
- http://{BLOCKED}.{BLOCKED}.106:2222/t3
- http://{BLOCKED}.{BLOCKED}.199.79:443/t3
- http://{BLOCKED}.{BLOCKED}.32.182:443/t3
- http://{BLOCKED}.{BLOCKED}.42.241:443/t3
- http://{BLOCKED}.{BLOCKED}.160.110:443/t3
- http://{BLOCKED}.{BLOCKED}.219.88:2222/t3
- http://{BLOCKED}.{BLOCKED}.208.68:443/t3
- http://{BLOCKED}.{BLOCKED}.189.105:443/t3
- http://{BLOCKED}.{BLOCKED}.234.132:995/t3
- http://{BLOCKED}.{BLOCKED}.21.66:443/t3
- http://{BLOCKED}.{BLOCKED}.32.224:443/t3
- http://{BLOCKED}.{BLOCKED}.154.100:443/t3
- http://{BLOCKED}.{BLOCKED}.140.236:80/t3
- http://{BLOCKED}.{BLOCKED}.125.94:443/t3
- http://{BLOCKED}.{BLOCKED}.252.243:443/t3
- http://{BLOCKED}.{BLOCKED}.26.41:443/t3
- http://{BLOCKED}.{BLOCKED}.88.59:443/t3
- http://{BLOCKED}.{BLOCKED}.27.6:443/t3
- http://{BLOCKED}.{BLOCKED}.142.48:995/t3
- http://{BLOCKED}.{BLOCKED}.219.143:443/t3
- http://{BLOCKED}.{BLOCKED}.1.164:443/t3
- http://{BLOCKED}.{BLOCKED}.55.77:443/t3
- http://{BLOCKED}.{BLOCKED}.173.134:443/t3
- http://{BLOCKED}.{BLOCKED}.10.71:2222/t3
- http://{BLOCKED}.{BLOCKED}.67.0:443/t3
- http://{BLOCKED}.{BLOCKED}.65.191:443/t3
- http://{BLOCKED}.{BLOCKED}.52.142:443/t3
- http://{BLOCKED}.{BLOCKED}.220.196:2222/t3
- http://{BLOCKED}.{BLOCKED}.196:2222/t3
その他
スパイウェアは、以下のWebサイトにアクセスして感染コンピュータのIPアドレスを収集します。
- http://www.ip-adress.com
スパイウェアは、以下を実行します。
- It checks the presence of the following Anti-Virus and Security Applications:
- ccSvcHst.exe
- avgcsrvx.exe
- vgsvcx.exe
- avgcsrva.exe
- MsMpEng.exe
- mcshield.exe
- avp.exe
- egui.exe
- ekrn.exe
- bdagent.exe
- vsserv.exe
- vsservppl.exe
- AvastSvc.exe
- coreServiceShell.exe
- PccNTMon.exe
- NTRTScan.exe
- SAVAdminService.exe
- SavService.exe
- fshoster32.exe
- WRSA.exe
- vkise.exe
- isesrv.exe
- cmdagent.exe
- ByteFence.exe
- MBAMService.exe
- fmon.exe
- bamgui.exe
- It terminates itself if the following DLL is loaded on its memory:
- ivm-inject.dll
- SbieDll.dll
- It terminates itself if its filename is one of the following:
- sample
- mlwr_smpl
- artifact.exe
- It checks the presence of the following network capturing tools:
- tcpdump.exe
- windump.exe
- ethereal.exe
- wireshark.exe
- ettercap.exe
- rtsniff.exe
- packetcapture.exe
- capturenet.exe
- It attempts to drop copies of itself to other machines in the same network via IPC$ shares.
- It terminates itself when executed in the following Virtual Environments:
- Virtual HD
- Red Hat
- QEMU
- CWSandbox
- VirtualBox
- VMWare
以下のスケジュールされたタスクを追加します:
- Task name: {GUID}
Trigger: Every 5 hours
Action: Start a program: {Malware File Path}\{Malware File Name}.exe - Task name: {Random characters}
Trigger: One-time
Action: Start a program: {Malware Filepath}\{Malware filename} /I {Random characters}
対応方法
手順 1
トレンドマイクロの機械学習型検索は、マルウェアの存在を示す兆候が確認された時点で検出し、マルウェアが実行される前にブロックします。機械学習型検索が有効になっている場合、弊社のウイルス対策製品はこのマルウェアを以下の機械学習型検出名として検出します。
- Troj.Win32.TRX.XXPE50FFF038
手順 2
Windows 7、Windows 8、Windows 8.1、および Windows 10 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 3
このマルウェアもしくはアドウェア等の実行により、手順中に記載されたすべてのファイル、フォルダおよびレジストリキーや値がコンピュータにインストールされるとは限りません。インストールが不完全である場合の他、オペレーティングシステム(OS)の条件によりインストールがされない場合が考えられます。手順中に記載されたファイル/フォルダ/レジストリ情報が確認されない場合、該当の手順の操作は不要ですので、次の手順に進んでください。
手順 4
Windowsをセーフモードで再起動します。
手順 5
スケジュールされたタスクを削除する
タスク削除の手順に含まれる{タスク名} - {実行するタスク}には以下が当てはまります。
Windows 2000、Windows XP、Windows Server 2003の場合:
- [スタート]→[プログラム]→[アクセサリ]→[システムツール]→[スケジュールされたタスク]をクリックして、スケジュールされたタスクを開きます。
- 上記の{タスク名} を、[名前]の欄に入力します。
- 入力した{タスク名} 持つファイルを右クリックします。
- [プロパティ]をクリックします。 [実行]フィールドで、表示されている{実行するタスク}を確認します。
- 上記の{実行するタスク}と文字列が一致するタスクを削除します。
Windows Vista、Windows 7、Windows Server 2008、Windows 8、Windows 8.1、およびWindows Server 2012の場合:
- Windowsタスクスケジューラを開きます。
• Windows Vista、Windows 7、Windows Server 2008の場合、[スタート]をクリックし、[検索]フィールドに「taskchd.msc」と入力してEnterキーを押します。
• Windows 8、Windows 8.1、Windows Server 2012の場合、画面の左下隅を右クリックし、[実行]をクリックし、「taskchd.msc」と入力してEnterキーを押します。 - 左側のパネルで、[タスクスケジューラライブラリ]をクリックします。
- 中央上部のパネルで、上記の{タスク名}を[名前]の欄に入力します。
- 中央下部のパネルで、[アクション]タブをクリックします。 [詳細]の欄で、{実行するタスク}を確認します。
- 文字列が一致するタスクを削除します。
手順 6
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
手順 7
以下のファイルを検索し削除します。
- {Malware File Path}\{Malware File Name}.dat
- %User Temp%\~{Malware File Name}.tmp
手順 8
コンピュータを通常モードで再起動し、最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「TrojanSpy.Win32.QAKBOT.YEAK-A」と検出したファイルの検索を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 9
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「TrojanSpy.Win32.QAKBOT.YEAK-A」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
ご利用はいかがでしたか? アンケートにご協力ください


