๋ณด์•ˆ/CTF

[ํฌ๋ Œ์‹] OlympicDestroyer - Volatility Contest 2018

vinn๐Ÿ‘ฉ‍๐Ÿ’ป 2024. 11. 19. 01:11
728x90

[๋ฌธ์ œ]

https://www.kaspersky.com/blog/olympic-destroyer/21494/

 

Olympic Destroyer: who hacked the Olympics?

Experts from Kaspersky Lab studied digital evidence related to the hacking attack on the 2018 Olympics in search of the actual attacker.

www.kaspersky.com

  • ์˜ฌ๋ฆผํ”ฝ ๋‹ด๋‹น์ž๊ฐ€ ์ˆ˜์‹ ํ•œ ์ผ์ • ์—…๋ฐ์ดํŠธ ๋ฉ”์ผ์— ์ฒจ๋ถ€๋œ ํŒŒ์ผ Olympic_Session_V10์„ ์‹คํ–‰ํ•จ์œผ๋กœ์จ ์•…์„ฑ์ฝ”๋“œ์— ๊ฐ์—ผ

 

 

  • ํ•ด๋‹น ํŒŒ์ผ์—์„œ ํ„ฐ๋ฏธ๋„์„ ์—ด๊ณ  ์šด์˜์ฒด์ œ๋ฅผ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•ด volatility -f "filename" imageinfo ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅ.
  • ํ”„๋กœ์„ธ์Šค ๋ฆฌ์ŠคํŠธ ๋ถ„์„์„ ์œ„ํ•ด volatility -f "filename" --profile="์šด์˜์ฒด์ œ" pslist ์ž…๋ ฅํ•ด์„œ ํ”„๋กœ์„ธ์Šค ๋ฆฌ์ŠคํŠธ ์ถ”์ถœ(์šด์˜์ฒด์ œ = Win7SP1x86_23418)

  • ๊ทธ๋‹ค์Œ pslist.log ํŒŒ์ผ์„ notepad++ ํ”„๋กœ๊ทธ๋žจ์„ ํ†ตํ•ด ๋ถ„์„ํ•ด ๋ณด๋‹ˆ OlympicDestroy๋ฅผ ํฌํ•จํ•˜์—ฌ ocxip.exe, teikv.exe, _xut.exe ๋“ฑ์€ ์ผ๋ฐ˜์ ์ธ ์‹œ์Šคํ…œ ํ”„๋กœ์„ธ์Šค์™€ ์ผ์น˜ํ•˜์ง€ ์•Š๋Š” ์ด๋ฆ„๊ณผ ํ–‰๋™ ํŒจํ„ด์„ ๋ณด์ด๋ฉฐ, OlympicDestroy๋Š” ๋‹ค๋ฅธ ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ”„๋กœ์„ธ์Šค๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ถ€๋ชจ ํ”„๋กœ์„ธ์Šค๋กœ ๋ณด์ธ๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ๋˜ํ•œ, OSPPSVC.EXE๋„ ์ด๋ฒˆ ์‚ฌ๊ฑด์ด ์—‘์…€์„ ํ†ตํ•œ ์นจ์ž…์œผ๋กœ ์ผ์–ด์ง„ ์ผ์ด๊ธฐ ๋•Œ๋ฌธ์— ์ด ํ”„๋กœ์„ธ์Šค๋„ ์˜์‹ฌ์Šค๋Ÿฝ์Šต๋‹ˆ๋‹ค.

  • ๊ทธ๋‹ค์Œ ํŒŒ์ผ์„ ์ถ”์ถœํ•˜๊ธฐ ์œ„ํ•ด filescan ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ–ˆ๊ณ  ์œ„์— ์˜์‹ฌ์Šค๋Ÿฌ์šด ํŒŒ์ผ๋“ค์˜ ์˜คํ”„์…‹์„ ์ถ”์ถœํ–ˆ์Šต๋‹ˆ๋‹ค.

  • .\volatility_2.6_win64_standalone.exe -f "Windows 7-1a1299dc.vmem" --profile=Win7SP1x86_23418 dumpfiles -Q 0x000000007fc8b888 -D ./ -n 
  • ๋จผ์ € OlympicDestroy ํŒŒ์ผ์˜ ์˜คํ”„์…‹์„ ์ถ”์ถœํ•ด์„œ ์œ„์˜ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด์„œ ํŒŒ์ผ์„ ์ถ”์ถœํ–ˆ์Šต๋‹ˆ๋‹ค. 

  • ์ถ”์ถœํ•˜์ž๋งˆ์ž ์•…์„ฑ์ฝ”๋“œ๋กœ ์ธ์‹๋˜์–ด ๋ณด์•ˆ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์ฐจ๋‹จ์ด ๋์Šต๋‹ˆ๋‹ค.

  • ๊ทธ๋‹ค์Œ ocxip.exe ํŒŒ์ผ์˜ ์˜คํ”„์…‹์„ ์ถ”์ถœํ•ด ํŒŒ์ผ์„ ์ถ”์ถœํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ocxip.exe ํŒŒ์ผ ๋˜ํ•œ ๋ฐ”๋กœ ์•…์„ฑํŒŒ์ผ๋กœ ๊ฐ์ง€๋˜์–ด ์ฐจ๋‹จ์ด ๋์Šต๋‹ˆ๋‹ค.

  • ๊ทธ๋‹ค์Œ์—๋Š” teikv.exe ํŒŒ์ผ๊ณผ _xut.exe๋„ ์ถ”์ถœํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ๋‘˜ ๋‹ค ์•…์„ฑํŒŒ์ผ์ž„์„ ํŒŒ์•…ํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ๋งˆ์ง€๋ง‰์œผ๋กœ, OSPPSVC.EXEํŒŒ์ผ๋„ ์ถ”์ถœํ•ด์„œ ๋ถ„์„ํ–ˆ๋”๋‹ˆ ์˜์‹ฌ์Šค๋Ÿฌ์šด ํŒŒ์ผ์ด์—ˆ์Œ์„ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.