{"id":3543,"date":"2022-01-13T08:03:06","date_gmt":"2022-01-13T07:03:06","guid":{"rendered":"https:\/\/sajberinfo.com\/2022\/11\/21\/text-84\/"},"modified":"2022-12-04T13:22:47","modified_gmt":"2022-12-04T12:22:47","slug":"sysjoker-napada-windows-macos-i-linux-operativne-sisteme","status":"publish","type":"post","link":"https:\/\/sajberinfo.com\/en\/2022\/01\/13\/sysjoker-napada-windows-macos-i-linux-operativne-sisteme\/","title":{"rendered":"SysJoker napada Windows, macOS i Linux operativne sisteme"},"content":{"rendered":"<p style=\"text-align: left;\"><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">Sigurnosni istra\u017eiva\u010di kompanije <em><a href=\"https:\/\/www.intezer.com\/blog\/malware-analysis\/new-backdoor-sysjoker\/\" target=\"_blank\" rel=\"noopener\">Intezer<\/a><\/em> su otkrili <a href=\"https:\/\/sajberinfoleksikon.blogspot.com\/2021\/09\/malware.html\" target=\"_blank\" rel=\"noopener\">zlonamjerni softver<\/a> nazvan <em>SysJoker<\/em> koji napada <em>Windows, macOS<\/em> i <em>Linux<\/em> sisteme sa sposobno\u0161\u0107u izbjegavanja otkrivanja na sva tri operativna sistema.<\/span><\/span><\/p>\n<div id=\"attachment_3610\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3610\" class=\"size-full wp-image-3610\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/11\/SysJoker.jpg\" alt=\"SysJoker malware\" width=\"1024\" height=\"685\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/11\/SysJoker.jpg 1024w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/11\/SysJoker-300x201.jpg 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/11\/SysJoker-768x514.jpg 768w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/11\/SysJoker-18x12.jpg 18w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-3610\" class=\"wp-caption-text\"><em>SysJoker<\/em> zlonamjerni softver; Design by Sa\u0161a \u0110uri\u0107<\/p><\/div>\n<p class=\"MsoNormal\" style=\"text-align: left;\"><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">Sigurnosni istra\u017eiva\u010di su ga primijetili u decembru 2021. godine prilikom istrage napada na <em>Linux<\/em> server. Daljim istra\u017eivanjem utvr\u0111eno je da su se uzorci ovog zlonamjernog softvera pojavili na <em>VirusTotal <\/em>servisu u drugoj polovini 2021. godine. Napisan u programskom jeziku <em>C++<\/em> i prilago\u0111en svakom operativnom sistemu posebno, pro\u0161ao je neopa\u017eeno na <em>VirusTotal <\/em>servisu koji sadr\u017ei 57 razli\u010ditih antivirusnih skenera<span lang=\"SR-LATN-RS\"> u verzijama prilago\u0111enim za <\/span><em>macOS<\/em> i <em>Linux<\/em> operativne sisteme.<\/span><\/span><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">\u00a0<\/span><\/span><\/p>\n<p class=\"MsoNormal\" style=\"text-align: left;\"><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">Internet stranica <em><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-sysjoker-backdoor-targets-windows-macos-and-linux\/\" target=\"_blank\" rel=\"noopener\">BleepingComputer <\/a><\/em>je objavila detaljnu analizu <em>SysJoker<\/em> zlonamjernog softvera.<em>Windows<\/em>verzija ovog zlonamjernog softvera ima, za razliku od <em>macOS<\/em> i <em>Linux<\/em>verzije, prvu fazu napada. U toj fazi koristi se <em>DLL<\/em>fajl koji koristi <em>PowerShell<\/em>komande za preuzimanje<em>ZIP<\/em> arhive sa <em>GitHub<\/em>-a u kojoj se nalazi <em>SysJoker<\/em>. Arhiva se raspakuje na adresu \u201c<\/span><em>C:\\ProgramData\\RecoverySystem\\<\/em><span style=\"font-family: inherit;\">\u201d i pokrene aktivni dio virusa. Nakon pokretanja, ide u re\u017eim mirovanja od 90 do 120 sekundi i onda se maskira kao <em>Intel Graphics Common User Interface Service<\/em>, odnosno <em>igfxCUIService.exe<\/em>.<\/span><\/span><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">\u00a0<\/span><\/span><\/p>\n<p class=\"MsoNormal\" style=\"text-align: left;\"><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">U sljede\u0107em koraku prikuplja informacije u ure\u0111aju upisuju\u0107i informacije u razne privremene tekstualne dokumente. Na kraju sve informacije se kodiraju i upisuju u fajl pod nazivom\u00a0 \u201c<em>microsoft_Windows.dll<\/em>\u201d, dok se privremeni tekstualni dokumenti bri\u0161u. Nakon prikupljana informacija, zlonamjerni softver \u0107e napraviti upori\u0161te dodavaju\u0107i novi <em>registry<\/em> klju\u010d \u201c<em>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run<\/em>\u201d uz nekoliko nasumi\u010dnih stanja mirovanja izme\u0111u svakog koraka.<\/span><\/span><\/p>\n<div id=\"attachment_3611\" style=\"width: 747px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3611\" class=\"size-full wp-image-3611\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/XOR.jpg\" alt=\"hardcoded XOR key\" width=\"737\" height=\"607\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/XOR.jpg 737w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/XOR-300x247.jpg 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/XOR-15x12.jpg 15w\" sizes=\"auto, (max-width: 737px) 100vw, 737px\" \/><p id=\"caption-attachment-3611\" class=\"wp-caption-text\">Source: <a href=\"https:\/\/www.intezer.com\/blog\/malware-analysis\/new-backdoor-sysjoker\/\" target=\"_blank\" rel=\"noopener\"><em>Intezer<\/em><\/a><\/p><\/div>\n<p class=\"MsoNormal\" style=\"text-align: left;\"><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">Naredni korak je uspostavljanje veze sa kontrolnim serverom putem kodirane veze ka <em>Google Drive<\/em>-u. Tu se nalazi fajl pod nazivom\u00a0 \u201c<em>domain.txt<\/em>\u201d koji je redovno a\u017euriran od strane napada\u010da sa listom kontakt servera, \u0161to dalje omogu\u0107ava da se izbjegne detekcija ili blokiranje. Odmah po uspostavljanju veze, prikupljene informacije se \u0161alju komandom serveru, koji kao odgovor na to zara\u017eenom ure\u0111aju dodjeljuje jedinstveni identifikator. Nakon ovoga, komandi server mo\u017ee isporu\u010diti novi zlonamjerni softver, pokretati naredbe na zara\u017eenom ure\u0111aju ili obrisati zlonamjerni softver.<\/span><\/span><\/p>\n<div id=\"attachment_3612\" style=\"width: 772px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3612\" class=\"size-full wp-image-3612\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/c2-coms.jpg\" alt=\"communication with the C2\" width=\"762\" height=\"520\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/c2-coms.jpg 762w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/c2-coms-300x205.jpg 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2022\/01\/c2-coms-18x12.jpg 18w\" sizes=\"auto, (max-width: 762px) 100vw, 762px\" \/><p id=\"caption-attachment-3612\" class=\"wp-caption-text\">Komunikacija sa komandnim serverom; Source: <em><a href=\"https:\/\/www.intezer.com\/blog\/malware-analysis\/new-backdoor-sysjoker\/\" target=\"_blank\" rel=\"noopener\">Intezer<\/a><\/em><\/p><\/div>\n<p class=\"MsoNormal\" style=\"text-align: left;\"><span style=\"font-size: 14pt;\"><span style=\"font-family: inherit;\">Kompanija <em>Intezer<\/em> je dala detaljne instrukcije pomo\u0107u kojih administratori mogu ustanoviti da li su njihovi ure\u0111aji zara\u017eeni sa zlonamjernim softverom <em>SysJoker<\/em>. Pored toga su objavili i korake koje bi trebalo preduzeti. Vi\u0161e detaljnijih informacija mo\u017eete na\u0107i <a href=\"https:\/\/www.intezer.com\/blog\/malware-analysis\/new-backdoor-sysjoker\/\" target=\"_blank\" rel=\"noopener\">ovdje<\/a>.<\/span><\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>Sigurnosni istra\u017eiva\u010di kompanije Intezer su otkrili zlonamjerni softver nazvan SysJoker koji napada Windows, macOS i Linux sisteme sa sposobno\u0161\u0107u izbjegavanja otkrivanja na sva tri operativna sistema. Sigurnosni istra\u017eiva\u010di su ga primijetili u decembru 2021.&#46;&#46;&#46;<\/p>","protected":false},"author":1,"featured_media":3610,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[77,142,141,144,93,54,143],"class_list":["post-3543","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hronike","tag-antivirusni-softver","tag-backdoor","tag-linux","tag-macos","tag-malware","tag-sajber-bezbjednost","tag-windows"],"_links":{"self":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/3543","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/comments?post=3543"}],"version-history":[{"count":0,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/3543\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media\/3610"}],"wp:attachment":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media?parent=3543"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/categories?post=3543"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/tags?post=3543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}