๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
๐Ÿ”’์ •๋ณด๋ณด์•ˆ/์ทจ์•ฝ์  ๋ถ„์„

์ทจ์•ฝ์  ๋ถ„์„ - Living Off the Land (LOTL)

by Janger 2024. 4. 24.
728x90

 

Living Off the Land (LOTL)

 

Living-off-the-land(๋ฆฌ๋น™ ์˜คํ”„ ๋” ๋žœ๋“œ) ๊ธฐ๋ฒ•์€, ํ•ด์ปค์™€ ๊ฐ™์€ ๊ณต๊ฒฉ์ž๋“ค์ด, ์‹œ์Šคํ…œ์— ์ด๋ฏธ ์„ค์น˜๋˜์–ด ์žˆ๋Š” Tool์„ ์‚ฌ์šฉํ•ด์„œ ํ•ดํ‚น ๊ณต๊ฒฉ์„ ํ•˜๋Š” ๊ธฐ๋ฒ•์„ ์˜๋ฏธ ํ•ฉ๋‹ˆ๋‹ค. ์ฆ‰ ํ”ผํ•ด์ž ์‹œ์Šคํ…œ์— ๊ธฐ๋ณธ์œผ๋กœ ์„ค์น˜๋˜์–ด ์žˆ๋Š” ํ”„๋กœ๊ทธ๋žจ์„ ํ™œ์šฉํ•˜์—ฌ ํ•ดํ‚น์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ๋•Œ๋ฌธ์—, AV(์•ˆํ‹ฐ๋ฐ”์ด๋Ÿฌ์Šค) Software ์˜ ํƒ์ง€๋ฅผ ํ”ผํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค. 

 

 

LoL Tool

 

Living-off-the-land(LoL) ๊ธฐ๋ฒ•์—์„œ ์‚ฌ์šฉํ•˜๋Š” Tool์„ LoL Tool ์ด๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

๊ณต๊ฒฉ์ž์˜ ์ตœ์ข… Payload(์•…์„ฑ์ฝ”๋“œ)๋ฅผ ์นจํˆฌ์‹œํ‚ค๊ธฐ ์œ„ํ•œ ์นจํˆฌ ๋„๊ตฌ๋กœ LoL(Living-off-the-land) Tool์„ ์‚ฌ์šฉํ•œ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.  ์ฆ‰ LoL Tool์€ ํ”ผํ•ด์ž์˜ ์‹œ์Šคํ…œ์— ์„ค์น˜๋˜์–ด ์•…์„ฑํ–‰์œ„๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š” ์ตœ์ข… Payload๊ฐ€ ์•„๋‹ˆ๋ผ, ์ตœ์ข… Payload๋ฅผ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์•„ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•œ ์นจํˆฌ ๋„๊ตฌ๋กœ ์‚ฌ์šฉ๋˜์–ด ์ง‘๋‹ˆ๋‹ค. 

 

 

Windows์— ์žˆ๋Š” LoL Tool


๊ฐœ๋… ํŒŒ์•…์„ ์œ„ํ•ด, ์ž์ฃผ ์–ธ๊ธ‰๋˜๊ณ  ์žˆ๋Š” 4๊ฐ€์ง€ Tool๋งŒ ๊ฐ„๋žตํžˆ ์†Œ๊ฐœํ•˜๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค.

1. regsvr32.exe

regsvr32์˜ ๊ธฐ๋Šฅ์€ DLL์„ Windows Registry์— ๋“ฑ๋กํ•˜์—ฌ, ๋‹ค๋ฅธ Software๊ฐ€ ํ•„์š” ์‹œ ์‚ฌ์šฉํ•˜๋„๋ก ํ—ˆ์šฉํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. 

Parameter๋กœ /i ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด, DLL install ์‹œ scriptlet ํ˜•์‹(XML ์–‘์‹ ์•ˆ์— JScript ๋‚˜ VBScript code๊ฐ€ ๋“ค์–ด ์žˆ๋Š” ๊ฒƒ)์˜ dynamic code๋ฅผ insertํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์„ ๊ฐ€์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ฆ‰ regsvr32 ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด JScript ๋‚˜ VBScript๋ฅผ DLL ์•ˆ์— inject ์‹œ์ผœ ์‹คํ–‰์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Parameter /i ์‚ฌ์šฉ์‹œ URL ์ฃผ์†Œ๋ฅผ ๊ธฐ์ˆ ํ•˜๋ฉด, Remote Site ์— ์žˆ๋Š” scriptlet ํŒŒ์ผ์„ ์‹คํ–‰ ์‹œํ‚ฌ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ํŒŒ์ผ๋ฆฌ์Šค ๊ณต๊ฒฉ์„ ๊ตฌํ˜„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 

Script์„ ๊ทธ๋ƒฅ ์‹คํ–‰์‹œํ‚ค๋ฉด AppLocker ๊ฐ™์€ software์— ์˜ํ•ด ํƒ์ง€๋˜์–ด ์‹คํ–‰์ด ๋ฐฉ์ง€ ๋  ์ˆ˜ ์žˆ์ง€๋งŒ, DLL ์•ˆ์— inject ์‹œ์ผœ ์‹คํ–‰์‹œํ‚ค๋ฉด, ํƒ์ง€๋ฅผ ๋ชปํ•œ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ฐธ๊ณ ๋กœ, Windows 10์˜ update๋œ Windows Defender ATP ์—์„œ๋Š” ํƒ์ง€ ํ•œ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

 

https://www.youtube.com/watch?v=t8SpYn5GkHA

regsvr32.exe๋ฅผ ์ด์šฉํ•œ ๋žœ์„ฌ์›จ์–ด ๊ฐ์—ผ ์‚ฌ๋ก€

 


2. mshta.exe

mshta๋Š” HTA(HTML Application)์„ ์‹คํ–‰์‹œํ‚ค๋Š” software ์ž…๋‹ˆ๋‹ค. HTA์˜ file extension์€ “.hta” ์ž…๋‹ˆ๋‹ค. IE(Internet Explorer)์—์„œ ๋” ์ด์ƒ HTA๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š๊ธฐ์—, ์ด์ „์— ๊ฐœ๋ฐœ๋œ HTA๋ฅผ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด, mshta.exe๋ฅผ ์ œ๊ณตํ•˜๊ณ  ์žˆ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

HTA๋Š” HTML ์–‘์‹์œผ๋กœ ๋œ Application์ด๊ธฐ ๋•Œ๋ฌธ์— ๋‚ด๋ถ€์— script๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ๊ณต๊ฒฉ์ž๋Š” “์•…์„ฑ script”๊ฐ€ ํฌํ•จ๋œ HTA ํŒŒ์ผ์„, ํ”ผ์‹ฑ ์ด๋ฉ”์ผ์— ์ฒจ๋ถ€ํ•˜์—ฌ, ํฌ์ƒ์ž์—๊ฒŒ ์ „๋‹ฌํ•˜์—ฌ, ์ฒจ๋ถ€ ํŒŒ์ผ์„ ์‹คํ–‰์‹œํ‚ค๋„๋ก ์œ ๋„ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. “์•…์„ฑ script”์˜ ์˜ˆ๋ฅผ ๋“ค๋ฉด, ์™ธ๋ถ€์—์„œ ์‹คํ–‰ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›๊ณ  ์‹คํ–‰์‹œํ‚ค๋Š” ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•˜๋„๋ก ์ž‘์„ฑ๋œ PowerShell script๋ฅผ ์‹คํ–‰์‹œํ‚ค๋Š” JavaScript ์ž…๋‹ˆ๋‹ค. JavaScript Obfuscator(๋‚œ๋…ํ™”)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ, script ๋‚ด์šฉ์„ ๋ฐ”๋กœ ํŒŒ์•…ํ•˜์ง€ ๋ชปํ•˜๋„๋ก ํ•˜๊ธฐ๋„ ํ•ฉ๋‹ˆ๋‹ค.


3. rundll32.exe

rundll32.exe๋Š” DLL(Dynamic Link Library)๋ฅผ ์‹คํ–‰(DLL ์†์— ์žˆ๋Š” ํ•จ์ˆ˜๋“ค์„ memory์ƒ์— load ์‹œํ‚ค๋Š” ๊ฒƒ)์‹œํ‚ค๋Š” ์šฉ๋„๋กœ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. DLL์€ ๋…๋ฆฝ Application์ด ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์— ๋…์ž์ ์œผ๋กœ ๋ฐ”๋กœ ์‹คํ–‰๋  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

rundll32.exe๋Š” Command Line ์—์„œ Input Parameter๋กœ JavaScript๋ฅผ ๋ฐ”๋กœ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

4. certutil.exe

certutil์˜ ์ฃผ ๊ธฐ๋Šฅ์€, CA(Certification Authority) ์ •๋ณด๋ฅผ configure, dump, display ํ•˜๋Š” ๊ฒƒ์ด์ง€๋งŒ, remote file์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋„๋ก ํ•ด ์ฃผ๋Š” ๊ธฐ๋Šฅ๋„ ์ œ๊ณตํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. 

๋”ฐ๋ผ์„œ certutil์„ ์‚ฌ์šฉํ•˜๋ฉด, ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ PowerShell script ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ๋ฐ, ํƒ์ง€ software๋Š” certutil์„ ํ•ฉ๋ฒ•์ ์ธ tool๋กœ ๊ฐ„์ฃผํ•˜๋ฏ€๋กœ, ์•…์„ฑ ํ–‰์œ„๊ฐ€ ํƒ์ง€๋˜์ง€ ์•Š๋Š”๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

 

5. Powershell, JScript, VBScript...

 

 

 

 

 

 

์š”์•ฝ) ๊ณต๊ฒฉ์ž๋Š” ๊ธฐ์กด์˜ AV์†”๋ฃจ์…˜์„ ํšŒํ”ผํ•˜๊ณ  ์ตœ๋Œ€ํ•œ ํ”์ ์„ ๋‚จ๊ธฐ์ง€ ์•Š๋„๋ก Fileless๊ธฐ๋ฒ•์„ ์‚ฌ์šฉํ•œ๋‹ค. ๊ธฐ์กด์˜ ๋ณด์•ˆ ์†”๋ฃจ์…˜์œผ๋กœ๋Š” ์ด๋Ÿฌํ•œ ์œ ํ˜•์˜ ๊ณต๊ฒฉ์„ ํƒ์ง€ํ•˜๊ธฐ ์–ด๋ ต๊ธฐ ๋•Œ๋ฌธ์— ์ด๋ฅผ ๋Œ€์‘ํ•˜๊ณ ์ž ํ–‰์œ„์— ์ง‘์ค‘ํ•˜๋Š” EDR์ œํ’ˆ์ด ๋“ฑ์žฅ

 

 

LOTL ์‚ฌ๋ก€ : ๋ผ์ž๋ฃจ์Šค ์‚ฌ๋ฒ•๋ถ€ ํ•ดํ‚น ๊ณต๊ฒฉ

 

 

 

 

https://www.asiatoday.co.kr/view.php?key=20240424010013055

 

ํ”ผํ•ด ๊ทœ๋ชจ์กฐ์ฐจ ๋ชจ๋ฅธ์ฑ„… ๅŒ—ํ•ดํ‚น์— ๋ฐฉ์‚ฐ์—…์ฒด 10์—ฌ๊ณณ ๋šซ๋ ธ๋‹ค

๋ถํ•œ ํ•ดํ‚น์กฐ์ง๋“ค์ด ๋ฐฉ์‚ฐ๊ธฐ์ˆ  ํƒˆ์ทจ๋ฅผ ์œ„ํ•ด ๋ฐฉ์‚ฐ์—…์ฒด๋Š” ๋ฌผ๋ก  ์ƒ๋Œ€์ ์œผ๋กœ ๋ณด์•ˆ์ด ์ทจ์•ฝํ•œ ๋ฐฉ์‚ฐ ํ˜‘๋ ฅ์—…์ฒด๊นŒ์ง€ ์ „๋ฐฉ์œ„์ ์œผ๋กœ ๊ณต๊ฒฉํ•œ ์‚ฌ์‹ค์ด 23์ผ ํ™•์ธ๋๋‹ค. ๊ฒฝ์ฐฐ์ฒญ ๊ตญ๊ฐ€์ˆ˜์‚ฌ๋ณธ๋ถ€๋Š” ์ด๋‚  “๊ตญ๋‚ด ๋ฐฉ์‚ฐ

www.asiatoday.co.kr

 

https://blog.naver.com/aepkoreanet/221980190942

 

Living-off-the-land(LoL) ๋„๊ตฌ(Tool)

Living-off-the-land(๋ฆฌ๋น™ ์˜คํ”„ ๋” ๋žœ๋“œ) ๊ธฐ๋ฒ•์€, ํ•ด์ปค์™€ ๊ฐ™์€ ๊ณต๊ฒฉ์ž๋“ค์ด, ์‹œ์Šคํ…œ์— ์ด๋ฏธ ์„ค์น˜๋˜์–ด ์žˆ๋Š” ...

blog.naver.com

 

https://frsecure.com/blog/living-off-the-land-attacks/

 

Living Off the Land Attacks | FRSecure

Living Off the Land attacks occur when attackers use your own internal business tools in your environment against you. Learn more about how to prevent them.

frsecure.com

 

https://rninche01.tistory.com/entry/%ED%8C%8C%EC%9D%BC%EB%A6%AC%EC%8A%A4Fileless%EA%B8%B0%EB%B2%95-%EC%84%A4%EB%AA%85-1

 

ํŒŒ์ผ๋ฆฌ์Šค(Fileless)๊ธฐ๋ฒ• ์„ค๋ช…

0. ๋ชฉ์ฐจContents0. ๋ชฉ์ฐจ1. ์†Œ๊ฐœ1.1 ๋ฐฐ๊ฒฝ1.2 ํŒŒ์ผ๋ฆฌ์Šค(Fileless)๊ธฐ๋ฒ•1) AVT(Advanced Volatile Threat)2) ์‚ฌ์šฉ ์ด์œ 3) ๋ฌธ์ œ์ 2. ํŒŒ์ผ๋ฆฌ์Šค(Fileless) ๊ณต๊ฒฉ 2.1 ๊ณต๊ฒฉ ์ ˆ์ฐจ2.2 Powershell ์˜ˆ์ œ ๋ฐ ์˜ต์…˜1) Powershell ์‹คํ–‰ ์ •์ฑ…2) Powersh

rninche01.tistory.com

 

728x90