
Spicy 기반의 Facefish 루트킷용 Zeek 프로토콜 분석기입니다.
이 Zeek+Spicy 분석기는 다음에 설명된 Facefish Linux 루트킷 C2를 탐지합니다:
이 분석기 개발에 대한 심층 블로그 및 웨비나 슬라이드는 다음에서 확인할 수 있습니다:
탐지 결과는 "facefish_rootkit.log"에서 확인할 수 있으며, "Facefish_Rootkit::FACEFISH_ROOTKIT_C2" 공지(notice)도 함께 발생합니다.
테스트용 pcap(KeyEx2가 없으므로 탐지되지 않아야 함)은 다음 명령으로 생성했습니다:
echo -n -e \\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00 | nc 127.0.0.1 9999
전체 C2 트래픽의 PCAP는 여기에서 확인할 수 있습니다(이 프로토콜에 사용된 두 번째 테스트):
https://www.joesandbox.com/analysis/355141/0/html#network
출력은 다음과 같습니다:
$ zeek -Cr dump-38fb322cc6d09a6ab85784ede56bc5a7.pcap spicy-analyzers
$ cat conn.log
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path conn
#open 2021-06-03-14-53-30
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig local_resp missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
#types time string addr port addr port enum string interval count count string bool bool count string count count count count set[string]
1613702572.079957 CWc0UD3fGLX0c6bj89 192.168.2.20 43448 176.111.174.26 443 tcp - 3.002074 0 0 S0 - - 0 S 3 180 0 0 -
1613702572.190619 CCo5Jp4eSxYMobOp3i 192.168.2.20 43450 176.111.174.26 443 tcp - 3.003396 0 0 S0 - - 0 S 3 180 0 0 -
1613702579.089432 CbPIFh4Olo8i1G0KV2 192.168.2.20 43448 176.111.174.26 443 tcp - - - - S0 - - 0 S 1 60 0 0 -
1613702579.201449 CPyuMa4IZGRzzBEOvh 192.168.2.20 43450 176.111.174.26 443 tcp - - - - S0 - - 0 S 1 60 0 0 -
1613702587.104275 C7nx2B1vfFr2VroO59 192.168.2.20 43448 176.111.174.26 443 tcp - - - - S0 - - 0 S 1 60 0 0 -
1613702603.150049 CUcCUW2x5WZS1yWyci 192.168.2.20 43448 176.111.174.26 443 tcp - - - - S0 - - 0 S 1 60 0 0 -
1613702635.209441 ChmbMq44oJeZIR6tVf 192.168.2.20 43448 176.111.174.26 443 tcp - - - - S0 - - 0 S 1 60 0 0 -
1613702587.216303 Clfyzh4ifzsqqUzvqc 192.168.2.20 43450 176.111.174.26 443 tcp spicy_facefish_rootkit 29.625531 4304 32 S1 - - 0 ShADTad 19 5348 12 688 -
#close 2021-06-03-14-53-30
$ cat facefish_rootkit.log
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path facefish_rootkit
#open 2021-06-03-14-53-30
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p is_orig payload_len command crc32_payload
#types time string addr port addr port bool count string count
1613702587.313451 Clfyzh4ifzsqqUzvqc 192.168.2.20 43450 176.111.174.26 443 T 0 KeyEx1 0
1613702616.553325 Clfyzh4ifzsqqUzvqc 192.168.2.20 43450 176.111.174.26 443 F 24 KeyEx2 707025536
1613702616.557061 Clfyzh4ifzsqqUzvqc 192.168.2.20 43450 176.111.174.26 443 T 8 KeyEx3 2984358853
1613702616.746288 Clfyzh4ifzsqqUzvqc 192.168.2.20 43450 176.111.174.26 443 T 4272 Registration 2325026424
#close 2021-06-03-14-53-30
$ cat notice.log
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2021-06-03-14-53-30
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] interval string string string double double
1613702587.313451 Clfyzh4ifzsqqUzvqc 192.168.2.20 43450 176.111.174.26 443 - - - tcp Facefish_Rootkit::FACEFISH_ROOTKIT_C2 Potential Facefish rootkit C2 detected. More info: https://blog.netlab.360.com/ssh_stealer_facefish_en/ 192.168.2.20 176.111.174.26 443 - - Notice::ACTION_LOG 60.000000 - - - -
#close 2021-06-03-14-53-30