Weekly Threat Infrastructure Investigation(Week14)

Hunting for enemy infrastructure in Japan

概要 / Overview

Censysの検索機能を用いて、C2とラベル付けされた日本国内のインフラストラクチャを調査しました。調査期間は2025年3月31日から4月6日までです。合計6件のC2サーバーが検出され、Cobalt Strikeをはじめとした複数のツールが利用されていることが確認されました。

I used the Censys search function to investigate the infrastructure in Japan labeled C2. The investigation period was from March 31 to April 6, 2025. A total of 6 C2 servers were detected and it was confirmed that multiple tools, including Cobalt Strike, were in use.


サマリ / Summary

  • 期間 / Period: 2025年3月31日~4月6日
  • 検出されたC2サーバー数 / Total Number of C2 Servers: 6 IPs

C2種別内訳 / Type of C2 Servers Found

Censys label Count
Cobalt Strike 2
NetSupportManager RAT 9 2
Brute Ratel C4 1
Supershell 1

詳細データ / Aggregate Data

No Date IP Autonomous System Number Autonomous System Label Censys label
1 3月31日 150[.]230[.]194[.]235 31898 ORACLE-BMC-31898 Cobalt Strike
2 4月1日 18[.]177[.]187[.]233 16509 AMAZON-02 Brute Ratel C4
3 4月2日 23[.]106[.]140[.]119 25820 IT7NET Supershell
4 4月5日 15[.]152[.]42[.]175 16509 AMAZON-02 NetSupportManager RAT 9
5 4月6日 43[.]153[.]162[.]106 132203 Tencent Building, Kejizhongyi Avenue Cobalt Strike
6 4月6日 43[.]206[.]154[.]248 16509 AMAZON-02 NetSupportManager RAT 9

This week's threat analysis

Target: Fake CAPTCHA

今月継続してFake CAPTCHAサイトの観測を行ってきましたが、3月31日に見つけた事例を紹介します。

I have been monitoring fake CAPTCHA sites this month and would like to share an example we found on March 29th. This one ended up infecting the user with malware called lummastealer.

感染フロー / Infection Flow

3/31

Fake CAPTCHA → PowerShell → Text File → PowerShell → SmartTV.exe (lummastealer)

関連ドメイン / Associated Domain

review4571-boking.com

VirusTotal

  • urlscan query
page.title:"Verify Your Request"

スクリーンショットと分析 / Screenshots & Analysis

CAPTCHAページ画面表示例*
アクセスすると以下のような画面でした。 デベロッパーツールでもどのようなコマンドがあるか確認ことができます。

PowerShellコード
スクリプトタグの最後の方にPowershellのコマンドがありました。

Base64をCyberchefでデコードしました。 CurlでTextファイルをGETするもののようです。

Textファイルの内容
このTextファイルの中身は以下のようになっていました。 読みづらいですが、所々にコマンドなどが隠れいます。 変数が隠れていたので、Cyberchefで解析しました。 さらにEXEファイルをダウンロードするもののようでした。


マルウェア分析 / Malware Analysis

これをCAPE Sandboxで解析したところ以下のような結果になりました。

Overview

Behavior Analysis

Special Thanks

この調査はCensys社のResearch Accessによって実施されました。
ご支援に深く感謝いたします。

docs.censys.com