Hunting for enemy infrastructure in Japan
概要 / Overview
Censysの検索機能を用いて、C2とラベル付けされた日本国内のインフラストラクチャを調査しました。調査期間は2025年3月31日から4月6日までです。合計6件のC2サーバーが検出され、Cobalt Strikeをはじめとした複数のツールが利用されていることが確認されました。
I used the Censys search function to investigate the infrastructure in Japan labeled C2. The investigation period was from March 31 to April 6, 2025. A total of 6 C2 servers were detected and it was confirmed that multiple tools, including Cobalt Strike, were in use.
サマリ / Summary
- 期間 / Period: 2025年3月31日~4月6日
- 検出されたC2サーバー数 / Total Number of C2 Servers: 6 IPs
C2種別内訳 / Type of C2 Servers Found
| Censys label | Count |
|---|---|
| Cobalt Strike | 2 |
| NetSupportManager RAT 9 | 2 |
| Brute Ratel C4 | 1 |
| Supershell | 1 |

詳細データ / Aggregate Data
| No | Date | IP | Autonomous System Number | Autonomous System Label | Censys label |
|---|---|---|---|---|---|
| 1 | 3月31日 | 150[.]230[.]194[.]235 | 31898 | ORACLE-BMC-31898 | Cobalt Strike |
| 2 | 4月1日 | 18[.]177[.]187[.]233 | 16509 | AMAZON-02 | Brute Ratel C4 |
| 3 | 4月2日 | 23[.]106[.]140[.]119 | 25820 | IT7NET | Supershell |
| 4 | 4月5日 | 15[.]152[.]42[.]175 | 16509 | AMAZON-02 | NetSupportManager RAT 9 |
| 5 | 4月6日 | 43[.]153[.]162[.]106 | 132203 | Tencent Building, Kejizhongyi Avenue | Cobalt Strike |
| 6 | 4月6日 | 43[.]206[.]154[.]248 | 16509 | AMAZON-02 | NetSupportManager RAT 9 |

This week's threat analysis
Target: Fake CAPTCHA
今月継続してFake CAPTCHAサイトの観測を行ってきましたが、3月31日に見つけた事例を紹介します。
I have been monitoring fake CAPTCHA sites this month and would like to share an example we found on March 29th. This one ended up infecting the user with malware called lummastealer.
感染フロー / Infection Flow
3/31
Fake CAPTCHA → PowerShell → Text File → PowerShell → SmartTV.exe (lummastealer)
関連ドメイン / Associated Domain
review4571-boking.com
- urlscan query
page.title:"Verify Your Request"
スクリーンショットと分析 / Screenshots & Analysis
CAPTCHAページ画面表示例*
アクセスすると以下のような画面でした。
デベロッパーツールでもどのようなコマンドがあるか確認ことができます。

PowerShellコード
スクリプトタグの最後の方にPowershellのコマンドがありました。

Base64をCyberchefでデコードしました。
CurlでTextファイルをGETするもののようです。

Textファイルの内容
このTextファイルの中身は以下のようになっていました。
読みづらいですが、所々にコマンドなどが隠れいます。
変数が隠れていたので、Cyberchefで解析しました。
さらにEXEファイルをダウンロードするもののようでした。

マルウェア分析 / Malware Analysis
これをCAPE Sandboxで解析したところ以下のような結果になりました。
Overview

Behavior Analysis

Special Thanks
この調査はCensys社のResearch Accessによって実施されました。
ご支援に深く感謝いたします。
