[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/tutorial-qakbot-infection/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/tutorial-qakbot-infection/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [ラーニング ハブ](https://unit42.paloaltonetworks.com/ja/category/learning-hub-ja/ "ラーニング ハブ")
* [サイバーセキュリティ チュートリアル](https://unit42.paloaltonetworks.com/ja/category/cybersecurity-tutorials-ja/ "サイバーセキュリティ チュートリアル")  
  [サイバーセキュリティ チュートリアル](https://unit42.paloaltonetworks.com/ja/category/cybersecurity-tutorials-ja/)

# Wiresharkによるパケット解析講座 7: Qakbot感染の調査

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/ja/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2020年2月13日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [サイバーセキュリティ チュートリアル](https://unit42.paloaltonetworks.com/ja/category/cybersecurity-tutorials-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [ラーニング ハブ](https://unit42.paloaltonetworks.com/ja/category/learning-hub-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Pcap](https://unit42.paloaltonetworks.com/ja/tag/pcap-ja/)
  * [Qakbot](https://unit42.paloaltonetworks.com/ja/tag/qakbot-ja/)
  * [Wireshark](https://unit42.paloaltonetworks.com/ja/tag/wireshark-ja/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/ja/tag/wireshark-tutorial-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/tutorial-qakbot-infection/?pdf=download&lg=ja&_wpnonce=48697d1bdd "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/tutorial-qakbot-infection/?pdf=print&lg=ja&_wpnonce=48697d1bdd "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Wiresharkによるパケット解析講座%207:%20Qakbot感染の調査&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ftutorial-qakbot-infection%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ftutorial-qakbot-infection%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ftutorial-qakbot-infection%2F&title=Wiresharkによるパケット解析講座%207:%20Qakbot感染の調査 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ftutorial-qakbot-infection%2F&text=Wiresharkによるパケット解析講座%207:%20Qakbot感染の調査 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ftutorial-qakbot-infection%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Wiresharkによるパケット解析講座%207:%20Qakbot感染の調査%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ftutorial-qakbot-infection%2F "Share in Mastodon")

## 概要

[Qakbot](https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32%2FQakbot)はQbotという名前でも知られる情報窃取を行うマルウェアです。長年にわたり活発に利用され、非常に特徴的なトラフィックパターンがあります。今回の[Wireshark](https://www.wireshark.org)チュートリアルでは、最近のQakbot感染トラフィックのパケットキャプチャ（pcap）を確認していくことにしましょう。セキュリティ専門家がQakbotによる感染を検出・調査するには、同マルウェアによる感染トラフィックパターンを理解することが重要です。

注意: 本チュートリアルは、Wiresharkに関する基本的知識があることを前提としています。また、以前の [チュートリアル](https://unit42.paloaltonetworks.com/ja/unit42-customizing-wireshark-changing-column-display/)で設定したカスタマイズ済みの列表示を使います。また[この回](https://unit42.paloaltonetworks.com/ja/using-wireshark-display-filter-expressions/)で解説したWiresharkディスプレイフィルタもすでに実装されているものとしています。

本チュートリアルで説明する内容は次のとおりです。

* Qakbotの配布方法
* マルスパム内のリンクからの最初のzipアーカイブ
* QakbotのWindows実行可能ファイル
* 感染後のHTTPS活動
* その他の感染後トラフィック

本稿のチュートリアルに利用する pcap ファイルは [こちら](https://www.malware-traffic-analysis.net/2020/01/29/index.html)から取得してください｡このpcapは、パスワードで保護されたzipアーカイブファイル ***2020-01-29-Qbot-infection-traffic.pcap.zip*** 内にありますのでダウンロード後展開してください。パスワードは「infected」です。図1は、以前のチュートリアルで設定したWireshark環境で開いた上記pcapの見えかたを示しています。

![Figure 1. The pcap for this tutorial.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-1-the-pcap-for-this-tutorial-.jpeg)

図1 本チュートリアルで使うpcapをWireSharkで開いたところ

## Qakbotの配布方法

Qakbotはほとんどの場合、悪意のあるスパム（マルスパム）を介して配布されますが、[最近(2019年11月)では](https://www.malware-traffic-analysis.net/2019/11/25/index3.html)エクスプロイトキットを介しても配布されています。[2019年3月のこちらの報告](https://isc.sans.edu/forums/diary/Malspam+pushes+Emotet+with+Qakbot+as+the+followup+malware/24738/)でも指摘されているとおり、Qakbotは[Emotet](https://www.us-cert.gov/ncas/alerts/TA18-201A)をはじめとするさまざまな別種マルウェアのフォローアップ感染に利用されることもあります。

Qakbotの最近のマルスパムベース配布キャンペーンでは、図2のフローチャートに示した経過をたどります。

![Figure 2. Flow chart from recent Qakbot distribution campaigns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-2-flow-chart-from-recent-qakbot-distributi.jpeg)

図2 最近のQakbot配布キャンペーンのフローチャート

### マルスパム内のリンクからの最初のzipアーカイブ

Qakbotを配布する最近のマルスパムは、正当な電子メールアドレスを偽装し、偽のメールスレッドの体裁をとっています。そうした例の1つを図3に示します。

![Figure 3. Recent malspam example pushing Qakbot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-3-recent-malspam-example-pushing-qakbot-.jpeg)

図3 Qakbotをプッシュする最近のマルスパムサンプル

こうしたメールに含まれるURLは一連の短い数字の後ろに\*\*\*.zip\*\*\* がついています。[URLhaus](https://urlhaus.abuse.ch/browse/)と[Twitter](https://twitter.com/search?q=Qakbot%20zip&f=live)で最近報告されていたQakbotマルスパムのURLサンプルをいくつか表1にまとめましたので参考にしてください。

|---------------|-----------------------------------------------------------------------------------|
| **最初に報告された日** | **初期zipアーカイブのURL**                                                                |
| 2019-12-27    | hxxps://prajoon.000webhostapp\[.\]com/wp-content/uploads/2019/12/last/033/033.zip |
| 2019-12-27    | hxxps://psi-uae\[.\]com/wp-content/uploads/2019/12/last/870853.zip                |
| 2019-12-27    | hxxps://re365\[.\]com/wp-content/uploads/2019/12/last/85944289/85944289.zip       |
| 2019-12-27    | hxxps://liputanforex.web\[.\]id/wp-content/uploads/2019/12/last/794/794.zip       |
| 2020-01-06    | hxxp://eps.icothanglong.edu\[.\]vn/forward/13078.zip                              |
| 2020-01-22    | hxxp://hitechrobo\[.\]com/wp-content/uploads/2020/01/ahead/84296848/84296848.zip  |
| 2020-01-22    | hxxp://faithoasis.000webhostapp.com/wp-content/uploads/2020/01/ahead/550889.zip   |
| 2020-01-27    | hxxps://madisonclubbar\[.\]com/fast/invoice049740.zip                             |
| 2020-01-29    | hxxp://zhinengbao\[.\]wang/wp-content/uploads/2020/01/lane/00571.zip              |
| 2020-01-29    | hxxp://bhatner\[.\]com/wp-content/uploads/2020/01/ahead/9312.zip                  |
| 2020-02-03    | hxxp://santedeplus\[.\]info/wp-content/uploads/2020/02/ending/1582820/1582820.zip |

*表1 Qakbot感染チェーンを開始する最初のzipアーカイブのURLサンプル*

さて、今回のpcapの場合、Wiresharkフィルタに***http.request.uri contains .zip***というフィルタを指定すれば、zipアーカイブを含むHTTPリクエストを見つけることができます(図4参照)。

![Figure 4. Finding the URL for the initial zip archive.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-4-finding-the-url-for-the-initial-zip-arch.jpeg)

図4 初期zipアーカイブのURLを見つける

ではここで、図5と6に示した手順でTCPストリームを追跡し、これがzipアーカイブであることを確認してください。その後、図7に示した手順でpcapからzipアーカイブをエクスポート可能かどうかを確認してみましょう。

![Figure 5. Following the TCP stream for the HTTP request from our filter results.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-5-following-the-tcp-stream-for-the-http-re.jpeg)

図5 フィルタ結果からHTTPリクエストのTCPストリームを追跡する(パケットを右クリックして\[追跡\]、\[TCPストリーム\]の順にクリックする)

![Figure 6. Indicators this URL returned a zip archive.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-6-indicators-this-url-returned-a-zip-archi.jpeg)

図6 このURLがzipアーカイブを返したことを示すインジケータ(痕跡)を確認する  
(zipの最初の2バイトは、ASCII文字でPK。VBC\_60372.vbsがこのzipアーカイブに含まれていることがわかる)

![Figure 7. Exporting objects from HTTP traffic in the pcap.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-7-exporting-objects-from-http-traffic-in-t.jpeg)

図7 pcapのHTTPトラフィックからオブジェクトをエクスポートできるか確認  
(\[ファイル\]メニューで\[オブジェクトをエクスポート\]、\[HTTP\]の順にクリック)

ほとんどの場合、***\[ファイル\]、\[オブジェクトのエクスポート\]、\[HTTP\]*** の順でメニューをたどれば、HTTP経由で送信されたzipアーカイブをエクスポートできるはずですが、残念ながらこのケースでは、この方法で単純に***9312.zip***をエクスポートすることができません。図8に示したとおり、\[エクスポート HTTPオブジェクト一覧\]ウィンドウ内でファイルが数百個の小さなチャンクに分割されてしまっているためです。

![Figure 8. 9312.zip is broken up into hundreds of objects within the list, so we cannot export it this way.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-8-9312-zip-is-broken-up-into-hundreds-of-o.jpeg)

図8 9312.zipが一覧上数百のオブジェクトに分割されているためこの方法でエクスポートすることはできない

幸いこれでもエクスポートする方法はあります。\[TCPストリーム\]のウィンドウからデータをエクスポートし、バイナリエディタで開いてHTTPのレスポンスヘッダを削除すれば大丈夫です。では\[エクスポート HTTPオブジェクト一覧\]ウィンドウをいったん閉じて、次の手順でこのpcapからzipアーカイブを抽出してください。

1. 最初の「http.request.uri contains .zip」のフィルタをもう一度実行し、図5に示した手順で9312.zipのHTTPリクエストのTCPストリームを追跡します。
2. 図9を参考にして、TCPストリームウィンドウ上の\[全体の対話\]が選択されているドロップダウンボックスから「103.91.92.1:80 → 10.1.29.101:49679 (2177 kB)」を選択し、サーバーからのレスポンストラフィックのみを表示させます。
3. 図10を参考にして、\[としてデータを表示して保存する\]ドロップダウンボックスを\[ASCII\]から\[Raw(無加工)形式\]に変更します。
4. 図11を参考にして、データをバイナリとして保存します。この例では「9312.zip.bin」というファイル名で保存しています。
5. 図12を参考にして、任意のバイナリエディタで保存したバイナリデータ(9312.zip.bin)を開き、zipアーカイブの最初の2バイト（ASCIIでは「PK」と表示）より前にあるHTTPリクエストヘッダを削除します。たいていのバイナリエディタでは、カーソルで先頭から「PK」より前の部分をなぞって選択した上でDeleteキーを押下すれば削除できるでしょう。
6. 図13を参考にして、バイナリエディタ上でファイルをzipアーカイブとして保存します（ここでは「9312.zip」として保存しました）。
7. 図14を参考にして、ターミナルないしコマンドプロンプトを開き、fileコマンドでファイルをチェックし、これが実際にzipアーカイブであることを確認します。次に、unzip コマンドでzipアーカイブを展開し、.vbsファイルを取得後、fileコマンドでこの.vbsファイルをチェックしてからshasumコマンドでSHA256値を計算します。

この一連の手順を行うさいは、図9〜14を参考にしてください。

![Figure 9. Step 2 – When viewing the TCP stream, switch from viewing the entire conversation to viewing only data returned from the server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-9-step-2-when-viewing-the-tcp-stream-sw.jpeg)

図9 TCPストリームウィンドウ上の\[全体の対話\]が選択されているドロップダウンボックスから「103.91.92.1:80 → 10.1.29.101:49679 (2177 kB)」を選択し、サーバーからのレスポンストラフィックのみを表示させる

![Figure 10. Step 3 – Show and save data as Raw instead of ASCII.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-10-step-3-show-and-save-data-as-raw-inst.jpeg)

図10 \[としてデータを表示して保存する\]ドロップダウンボックスを\[ASCII\]から\[Raw(無加工)形式\]に変更する

![Figure 11. Step 4 – Save this raw data from the TCP stream as a binary.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-11-step-4-save-this-raw-data-from-the-tc.jpeg)

図11 データをバイナリとして保存。この例では「9312.zip.bin」というファイル名で保存している

![Figure 12. Step 5 – Open your saved binary in a hex editor and remove any HTTP response data before the first two bytes of the zip archive (that show as PK in ASCII).](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-12-step-5-open-your-saved-binary-in-a-he.jpeg)

図12 任意のバイナリエディタで保存したバイナリデータ(9312.zip.bin)を開き、zipアーカイブの最初の2バイト（ASCIIでは「PK」と表示）より前にあるHTTPリクエストヘッダを削除。たいていのバイナリエディタでは、カーソルで先頭から「PK」より前の部分をなぞって選択した上でDeleteキーを押下すれば削除できる

![Figure 13. Step 6 – Save your edited binary as a zip archive.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-13-step-6-save-your-edited-binary-as-a-z.jpeg)

図13 バイナリエディタ上でファイルをzipアーカイブとして保存（ここでは「9312.zip」として保存）

![Figure 14. Step 7 – Confirm the edited file is a zip archive, then extract the VBS file and check the file hashes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-14-step-7-confirm-the-edited-file-is-a-z.jpeg)

図14 ターミナルないしコマンドプロンプトを開き、fileコマンドでファイルをチェックし、これが実際にzipアーカイブであることを確認後、unzip コマンドでzipアーカイブを展開。.vbsファイルを取得後、fileコマンドでこの.vbsファイルをチェックしてからshasumコマンドでSHA256値を計算

図14は、DebianベースのLinuxディストリビューション ターミナル ウィンドウでファイルをチェックした例です。このpcapから抽出したzipアーカイブは、[VirusTotalに提供されているこのファイル](https://www.virustotal.com/gui/file/5121c89e898eadeff9eeef660d92f3cff75700c7f017b33c913a951018a3df9a)と同じものになるはずです。また、zipアーカイブから抽出したVBSファイルも[VirusTotalに送信済みのこちらのファイル](https://www.virustotal.com/gui/file/51758a9ddf92d19be7c69a60125fb3dfc303152e9bbc77478dfff497422f3d25)と同じもののはずです。

[抽出されたVBSファイルをこちらのパブリックなサンドボックス分析](https://app.any.run/tasks/e2c36659-1070-4665-991c-245e900245b7)にかけた結果からは、これが感染チェーンにおける次のQakbot関連URL、すなわちQakbotのWindows実行可能ファイルを返すURLを生成していることがわかります。

## QakbotのWindows実行可能ファイル

抽出されたVBSファイルは、QakbotのWindows実行可能ファイルを返すURLを生成します。2019年12月以降のQakbot実行可能ファイル用URLは44444.pngまたは444444.pngで終わっています。弊社[AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus)脅威インテリジェンスサービスで見つかったこれらQakbot URLの最近のサンプルを表2にまとめましたので参考にしてください。

|------------|---------------------------------------------------------------------------------------|
| **初出**     | **Qakbot実行可能ファイルのURL**                                                                |
| 2019-12-27 | hxxp://centre-de-conduite-roannais\[.\]com/wp-content/uploads/2019/12/last/444444.png |
| 2020-01-06 | hxxp://newsinside\[.\]info/wp-content/uploads/2020/01/forward/44444.png               |
| 2020-01-15 | hxxp://iike.xolva\[.\]com/wp-content/themes/keenshot/fast/444444.png                  |
| 2020-01-17 | hxxp://deccolab\[.\]com/fast/444444.png                                               |
| 2020-01-21 | hxxp://myrestaurant.coupoly\[.\]com/wp-content/uploads/2020/01/along/444444.png       |
| 2020-01-22 | hxxp://alphaenergyeng\[.\]com/wp-content/uploads/2020/01/ahead/444444.png             |
| 2020-01-23 | hxxp://claramohammedschoolstl\[.\]org/wp-content/uploads/2020/01/upwards/444444.png   |
| 2020-01-23 | hxxp://creationzerodechet\[.\]com/choice/444444.png                                   |
| 2020-01-26 | hxxp://productsphotostudio\[.\]com/wp-content/uploads/2020/01/lane/444444.png         |
| 2020-01-27 | hxxp://sophistproduction\[.\]com/wp-content/uploads/2020/01/choice/444444.png         |
| 2020-01-30 | hxxp://uofnpress\[.\]ch/wp-content/uploads/2020/01/side/444444.png                    |
| 2020-02-03 | hxxp://csrkanjiza\[.\]rs/wp-content/uploads/2020/02/ending/444444.png                 |

*表2 Qakbot実行可能ファイルのURL*

それでは、WireSharkに戻り、現在のpcapで「***hxxp.request.uri contains .png***」とフィルタに指定して(実際には図15に示したように文字列hxxpはhttpに変更してください)、Qakbot実行可能ファイルのHTTP GETリクエストを見つけましょう(図15参照)。

![Figure 15. Finding the URL for our Qakbot executable.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-15-finding-the-url-for-our-qakbot-executab.jpeg)

図15 分析中のpcapからQakbot実行可能ファイルのURLを見つける

ではここで図16を参考に、このオブジェクトをpcapから ***\[ファイル\]メニュー、\[オブジェクトのエクスポート\]、\[HTTP\]*** の順にクリックしてエクスポートしてください。つづいて図17を参考にエクスポートした結果をチェックしてください。

![Figure 16. Exporting our Qakbot executable from the pcap.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-16-exporting-our-qakbot-executable-from-th.jpeg)

図16 pcapからQakbotのWindows実行可能ファイルをエクスポートしたところ  
(\[ファイル\]メニュー、\[オブジェクトのエクスポート\]、\[HTTP\]の順にクリックし、パケット2957のalphaenergyeng\[.\]comの行を選択して\[Save\]をクリックする)

![Figure 17. Checking the exported file in a Debian-based Linux terminal window.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-17-checking-the-exported-file-in-a-debian-.jpeg)

図17 DebianベースのLinuxターミナル ウィンドウでエクスポートしたファイルを確認しているところ  
(fileコマンドおよびshasumコマンド)

このpcapから抽出したQakbotのWindows実行ファイルは[VirusTotalに提供されているこのファイル](https://www.virustotal.com/gui/file/56ee803fa903ab477f939b3894af6771aebf0138abe38ae8e3c41cf96bbb0f2a)と同じものになるはずです。 [こちらのパブリックなサンドボックス分析にかけた結果(\[THREATS\]タブの\[Message\]列参照)](https://app.any.run/tasks/fb9cffb1-7797-4827-8446-05fee3d6a3de) からはQakbot関連のインジケータが生成され、これがQbotとして識別されたことがわかります。

## 感染後のHTTPS活動

まずは、[以前のWIresharkチュートリアル](https://unit42.paloaltonetworks.com/ja/using-wireshark-display-filter-expressions/)で作成した「basic」フィルタを使い、pcapのWebトラフィックをざっと眺めてみましょう。Qakbot実行可能ファイルを返しているalphaenergyeng\[.\]comへのHTTP GETリクエスト後の活動までスクロールダウンしてください。図18に示すように、関連付けられたドメインのない68.1.115\[.\]106へのHTTPSトラフィックやSSL/TLSトラフィックのインジケータが複数表示されるはずです。

![Figure 18. HTTPS or SSL/TLS traffic caused by Qakbot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-18-https-or-ssl-tls-traffic-caused-by-qakb.jpeg)

図18 QakbotによるHTTPSトラフィックとSSL/TLSトラフィック

このトラフィックには、Qakbot感染時によく見られる異常な証明書発行者データが含まれています。以前、[Ursnif感染の解析をしたWIresharkチュートリアル](https://unit42.paloaltonetworks.com/ja/using-wireshark-display-filter-expressions/)で、こうした異常な証明書発行者を確認する方法を学習しましたね。やりかたを忘れてしまったかたは、こちらのチュートリアルでおさらいしておいてください。

では、以下のWiresharkフィルタを指定してQakbot証明書発行者データを確認しましょう。

***Ip.addr eq 68.1.115.186 and ssl.handshake.type eq 11 (WireShark 2.xの場合)***

Wireshark 3.0以降をお使いの場合は、***ssl.handshake.type*** の代わりに***tls.handshake.type***を指定してください。次に、図18に示したQakbot生成トラフィックの最初のフレーム(フレーム3173)を選択して右クリックし、\[追跡\]、\[TCPストリーム\]の順にクリックします (これによりtcp.stream eq 24が表示されます)。この結果「Server Hello, Certificate, Server Hello Done」と Info 列に表示される行(フレーム3174)が見つかりますので、この行を選択して図19に示した手順で証明書発行者データが見つかるまでフレームの詳細ウィンドウを展開していきます。

![Figure 19. Reviewing certificate issuer data from Qakbot traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-19-reviewing-certificate-issuer-data-from.jpeg)

図19 Qakbotトラフィックから証明書発行者データを確認したところ(フレーム3174)。  
Wireshark3.x系では、Secure Socket Layer の部分が Transport Layer Security になる

市区町村名(Locality Name)、組織名(Organization Name)、コモンネーム(Common Name)のパターンは通常のものからの乖離が見られ、正当なHTTPS、SSL、TLSトラフィックで見られる証明書のパターンを踏襲していません。このケースでの発行者データは次のようになっています。

* id-at-countryName=**ES**
* id-at-stateOrProvinceName=**IA**
* id-at-localityName=**Uorh Ofwa**
* id-at-organizationName=**Coejdut Mavmtko Qxyemk Dxsjie LLC.**
* id-at-commonName=**gaevietovp.mobi**

### その他の感染後トラフィック

さて、このpcapには、Qakbot感染に関連した他の活動も含まれています。これらの活動はそれ自体に悪意のあるものではありませんが、これまでの調査結果に照らせば、ここでのQakbotによる感染はすでに完了しているものと想定できます。

また、Qakbot感染のもう1つのインジケータとなるのが、cdn.speedof\[.\]meへのHTTPSトラフィックです。ドメインspeedof\[.\]meは、正規のインターネット速度テストサービスに使用されるものでこれ自体は悪意のあるトラフィックではありません。ただし、Qakbotに感染するとcdn.speedof\[.\]meへのトラフィックが頻繁に見られるようになります。図20は、pcapから抽出したこの活動を示しています。

![Figure 20. The domain cdn.speedof\[.\]me within the Qakbot traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-20-the-domain-cdn-speedof-me-within-the.jpeg)

図20 Qakbotトラフィック内で見つかる cdn.speedof\[.\]me ドメインへの接続

Qakbotはまた、感染Windowsホスト上のすべてのブラウザのウィンドウを開きます。[こちらでのサンドボックス分析](https://app.any.run/tasks/fb9cffb1-7797-4827-8446-05fee3d6a3de)からのビデオの再生では約13分5秒後、QakbotがWindows 7ホスト上でChromeを開き、次にFirefoxを開き、Internet Explorerを開いている様子がわかります。またこの分析からはQakbotが次のURLへのトラフィックを生成した様子もわかります。

* hxxp://store.nvprivateoffice\[.\]com/redir\_chrome.html
* hxxp://store.nvprivateoffice\[.\]com/redir\_ff.html
* hxxp://store.nvprivateoffice\[.\]com/redir\_ie.html

ドメインnvprivateoffice\[.\]comは2012年からGoDaddy経由で登録されているドメインで、store.nvprivateoffice\[.\]comはFedoraサーバー上のnginxのデフォルトwebページを表示します。

このチュートリアルのpcapは、ChromeもFirefoxもインストールされていないWindows 10ホストでのQakbot感染によるものです。このためこのpcapでは、Internet Explorerと新しいChromiumベースのMicrosoft Edgeのwebトラフィックのみが表示されています。どちらのブラウザでもQakbotが生成したURLはhxxp://store.nvprivateoffice\[.\]com/redir\_ie.htmlです。

このトラフィックを見つけるには次のWiresharkフィルタを使用します(図21参照)。

***hxxp.request.full\_uri contains store.nvprivateoffice
(ここでも安全のため「hxxp」と記載していますが、実際にフィルタに指定するさいは「http」と入力してください)***

![Figure 21. Finding Qakbot traffic that opens web browsers on an infected Windows host.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-21-finding-qakbot-traffic-that-opens-web-b.jpeg)

図21 感染Windowsホストでwebブラウザを開くQakbotのトラフィックを見つける

redir\_ie.htmlで終わる2つのHTTP GETリクエストそれぞれについて、TCPストリームを追跡しましょう。図22に示すように、最初のリクエストのInternet ExplorerのHTTPヘッダにはUser-Agentが含まれています。また図23に示すように、同じURLに対する2番目のリクエストでは、新しいChromiumベースのMicrosoft EdgeのHTTPヘッダにUser-Agentが含まれています。

![Figure 22. Qakbot traffic to store.nvprivateoffice\[.\]com using Internet Explorer 11.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-22-qakbot-traffic-to-store-nvprivateoffice.jpeg)

図22 Internet Explorer 11を使用するstore.nvprivateoffice\[.\]comへのQakbotトラフィック。  
User-Agent設定は Windows 10 ホスト上の Internet Explorer 11 のもの

![Figure 23. Qakbot traffic to store.nvprivateoffice\[.\]com using the new Chromium-based Microsoft Edge.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-23-qakbot-traffic-to-store-nvprivateoffice.jpeg)

図23 ChromiumベースのMicrosoft Edgeを使用するstore.nvprivateoffice\[.\]comへのQakbotトラフィック。  
User-Agent設定は Windows 10 ホスト上の新しいChromiumベースのMicrosoft Edge ブラウザのもの

最後に、今回のQakbotに感染したホストのpcapには、SMTP、IMAP、POP3など、さまざまな電子メールプロトコル用ポートに対する電子メール関連TCPトラフィックが含まれています。このweb以外のトラフィックがどんなものであるかを把握するには、次のWiresharkフィルタを使用します(図25参照)。

***tcp.flags eq 0x0002 and !(tcp.port eq 80) and !(tcp.port eq 443)***

![Figure 25. Getting an idea of the non-web-related traffic from this Qakbot infection.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-25-getting-an-idea-of-the-non-web-related.jpeg)

図25 Qakbot感染トラフィックに含まれるweb以外のトラフィックがどのようなものかをおおまかにつかむ

図25は、さまざまな電子メールプロトコルで一般的に使用されている25、110、143、465、587、993、995などのポートへのTCP接続と、試行されたTCP接続を示しています。結果の最初の2行は65400/tcpへのトラフィックを示していますが、関連するTCPストリームを確認すると、これも電子メール関連のトラフィックであることがわかります。

次のWiresharkフィルタを使用して、感染ホストからの電子メール関連のトラフィックの詳細を確認してください(図26参照)。

***smtp or imap or pop***

![Figure 26. Finding email-related traffic caused by Qakbot in this pcap.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/figure-26-finding-email-related-traffic-caused-by.jpeg)

図26 pcap内でQakbotが生成した電子メール関連のトラフィックを見つける

この手の電子メールトラフィックについてもっとよく把握するにはいくつかTCPストリームを追跡してみるとよいでしょう。通常であれば、WindowsクライアントからパブリックなIPアドレスに対してこのように暗号化されていない電子メールのトラフィックを見かけることはまずありません。他のインジケータと合わせれば、この***smtp、imap、pop***フィルタからQakbotによる活動が明らかになることもあります。

## 結論

本チュートリアルでは、QakbotマルウェアによるWindows感染を調べるさいのヒントを見ていきました。Qakbotによる最近の活動サンプルについては [malware-traffic-analysis.net](https://www.malware-traffic-analysis.net)にも多数掲載しています。

『Wiresharkによるパケット解析講座』シリーズの以前の講座は以下から確認してください。

* [Wireshark によるパケット解析講座 1: Wiresharkの表示列をカスタマイズする](https://unit42.paloaltonetworks.com/ja/unit42-customizing-wireshark-changing-column-display/)
* [Wireshark によるパケット解析講座 2: 脅威インテリジェンス調査に役立つフィルタリング設定](https://unit42.paloaltonetworks.com/ja/using-wireshark-display-filter-expressions/)
* [Wireshark によるパケット解析講座 3: ホストとユーザーを特定する](https://unit42.paloaltonetworks.com/ja/using-wireshark-identifying-hosts-and-users/)
* [Wireshark によるパケット解析講座 4: Pcapからのオブジェクトのエクスポート](https://unit42.paloaltonetworks.com/ja/using-wireshark-exporting-objects-from-a-pcap/)
* [Wireshark によるパケット解析講座 5: Trickbot感染の調査](https://unit42.paloaltonetworks.com/ja/wireshark-tutorial-examining-trickbot-infections/)
* [Wireshark によるパケット解析講座 6: Ursnif感染の調査](https://unit42.paloaltonetworks.com/ja/wireshark-tutorial-examining-ursnif-infections/)
  トップに戻る

### タグ

* [Pcap](https://unit42.paloaltonetworks.com/ja/tag/pcap-ja/ "pcap")
* [Qakbot](https://unit42.paloaltonetworks.com/ja/tag/qakbot-ja/ "Qakbot")
* [Wireshark](https://unit42.paloaltonetworks.com/ja/tag/wireshark-ja/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/ja/tag/wireshark-tutorial-ja/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:SharePointの脆弱性を悪用した中東政府関連組織への攻撃はいまだ継続中](https://unit42.paloaltonetworks.com/ja/actors-still-exploiting-sharepoint-vulnerability/ "SharePointの脆弱性を悪用した中東政府関連組織への攻撃はいまだ継続中")

### 目次

* 

### 関連記事

* [\[2024-03-04 JST 改訂\] Wireshark によるパケット解析講座 4: Pcapからのオブジェクトのエクスポート](https://unit42.paloaltonetworks.com/ja/using-wireshark-exporting-objects-from-a-pcap/ "article - table of contents")
* [Unit 42 脅威インテリジェンス速報まとめ: DarkGate から AsyncRAT まで 2023 年 10 月〜 12 月に SNS に投稿した速報の振り返り](https://unit42.paloaltonetworks.com/ja/unit42-threat-intelligence-roundup/ "article - table of contents")
* [Wireshark によるパケット解析講座 3: ホストとユーザーを特定する (2023-10-11 更新)](https://unit42.paloaltonetworks.com/ja/using-wireshark-identifying-hosts-and-users/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/medical-iot-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
