[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/unit42-prince-of-persia-game-over/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-prince-of-persia-game-over/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# プリンス オブ ペルシャ -- ゲーム オーバー

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Simon Conant](https://unit42.paloaltonetworks.com/ja/author/simon-conant/)
  * [Lior Efraim](https://unit42.paloaltonetworks.com/ja/author/lior-efraim/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2016年6月28日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [C2](https://unit42.paloaltonetworks.com/ja/tag/c2-ja/)
  * [Infy](https://unit42.paloaltonetworks.com/ja/tag/infy-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/unit42-prince-of-persia-game-over/?pdf=download&lg=ja&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/unit42-prince-of-persia-game-over/?pdf=print&lg=ja&_wpnonce=5f0cc26d8b "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=プリンス%20オブ%20ペルシャ%20–%20ゲーム%20オーバー&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-prince-of-persia-game-over%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-prince-of-persia-game-over%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-prince-of-persia-game-over%2F&title=プリンス%20オブ%20ペルシャ%20–%20ゲーム%20オーバー "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-prince-of-persia-game-over%2F&text=プリンス%20オブ%20ペルシャ%20–%20ゲーム%20オーバー "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-prince-of-persia-game-over%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=プリンス%20オブ%20ペルシャ%20–%20ゲーム%20オーバー%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-prince-of-persia-game-over%2F "Share in Mastodon")

## **概要**

Unit 42は、5月初旬に「プリンス オブ ペルシャ」というタイトルの[ブログ](https://blog.paloaltonetworks.com/2016/05/prince-of-persia-infy-malware-active-in-decade-of-targeted-attacks/)を公開しました。  
そこで、以前は未公開のマルウェア ファミリ、Infy を使用して、世界中の政府機関や注目を集めている業界を標的とした10年間に及ぶ活動を発見したことを説明しました。

この記事の公開の後、C2ドメインの責任を担うパーティとの協力を通じて、Unit 42のリサーチャーは、複数のC2ドメインの制御権を得ることに成功しました。これにより、この活動での攻撃者による被害者へのアクセスは無効化され、この活動で現在被害を受けている標的への洞察を深め、影響を受けるパーティに通知することができます。

### **公開後**

元のブログの公開後1週間は、C2インフラストラクチャに異常な変化は見られませんでした。以前に定期的に見られたとおり、既存のドメインは新しいIPアドレスに移行されました。いくつかの新たなインストール ドメインが、現在のドメインの命名規則（新しいIOCの付録を参照のこと）に従って追加されました。

攻撃者が新しいバージョン(31)を開発し、これが単一のカナダの標的に対して仕掛けられたことがわかりました。

ファイルの説明は、基本的には同じままです("CLMediaLibrary Dynamic Link Library V3")。もっとも重要な点は、10年間の活動全体を通じて使用されていたことを発見し、以前のブログで解説した**エンコード キーに何の変更もなかった**ことです(現在はオフセット20と、URLエンコードで2番目に渡す場合はオフセット11を使用)。このことから、攻撃者は私たちの最初のレポートに気付いていないと判断しています。

### **シンクホール**

C2ドメインの責任を担うパーティとの協力を通じて、私たちはそれらの1つではなくすべての制御権を得て、制御下のサーバにAレコードを転送しました。これによって、攻撃者がその後、さらにドメイン構成を変更したり、被害者へコマンドを発行したり、または大半の被害者からさらにデータを取得したりできないように、防御しました。転送後の接続の分析では、攻撃者がサードパーティ サービスを使用して、彼らが突然ほぼすべてのトラフィックを失った理由を突き止めようとしたことが示されました。図1は、被害を受けたC2トラフィックの地理的な場所を示しています。当社のシンクホール サーバと現在通信している時点でのすべてを表しています。  
![図1 被害を受けたC2トラフィックのグラフィカル表示](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PoP-Game-Over-1.png) 図1 被害を受けたC2トラフィックのグラフィカル表示

私たちは、その後、シンクホールの制御を[Shadowserver](https://www.shadowserver.org/wiki/)に移管しました。引き続き被害者への通知と修復を担当していただいていることに感謝します([https://www.shadowserver.org/wiki/pmwiki.php/Involve/GetReportsOnYourNetwork](https://www.shadowserver.org/wiki/pmwiki.php/Involve/GetReportsOnYourNetwork))。

### **被害者**

被害を受けたC2トラフィックを分析し、Infy活動の被害者が誰であったかがわかりました。35カ国の326の被害者システムにインストールされた456のマルウェア エージェントを特定しました。図2は、被害者の場所の地理的な詳細を示しています。元のブログで、この活動では大勢のイラン市民が標的とされ、すべての犠牲者のほぼ1/3がイラン人だったと判明したことを述べました。また、たとえば、クライムウェア攻撃に比べると、被害者の総数はそれほど多くないことも述べました。  
![図2 被害者の地理的な場所。被害者が発見されなかったため、この地図ではニュージーランドが省略されています。](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PoP-Game-Over-2.png) 図2 被害者の地理的な場所。被害者が発見されなかったため、この地図ではニュージーランドが省略されています。

### **バージョン**

元のブログでは、Infyマルウェアには、はっきり異なる2つの基本的な亜種があると述べました。本来の"Infy"亜種に加え、より新しい、精巧でインタラクティブなフル機能装備の"Infy M"亜種が、より高価値と思われる標的に対して導入されました。総計すると、すべての被害者の93%がInfyに感染し、60%がInfy "M"に感染しました(図3)。犠牲者の総数が少ないことと合わせると、これは、活動の個々の標的にきめ細かく注意を払ったことを示唆しています。犠牲者の大半は、無料の機能セットに関連している可能性があります。また、本来の亜種に感染した被害者のシステムには、標的が攻撃者にとってより価値が高いと思える場合に、後から"M"亜種を追加するための"アップグレード"パスが提供された可能性もあります。  
![図3 InfyおよびInfy “M”感染の内訳](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PoP-Game-Over-3.png) 図3 InfyおよびInfy "M"感染の内訳

Infy "M"の場合は、大半の標的で最新バージョン(7.8)が使用され、古い6.xバージョンはまったく使用されていません(図4)。これは、これらのより価値の高い標的には、最新バージョンを使って最新の状態を保持するために、かなりの注意が払われたことを示しています。

これに対し、より基本的な元のInfy亜種に関して、多種多様なバージョンがインストールされていることが分かります(図5)。これによると旧バージョンによる被害者が多くおり、旧バージョンの中には、10年経った最初のバージョンもあります。これはこうした個々の標的に対する関心がはるかに低いことを示しています(なお、私たちは少数の古い6.xバージョンを確認することは確認しましたが、これらは接続時にバージョンを通知してきません)。  
![図4 Infy「M」被害に関するバージョン](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PoP-Game-Over-4.png) 図4 Infy「M」被害に関するバージョン  
![図5 「元の」Infy被害に関するバージョン](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PoP-Game-Over-5.png) 図5 「元の」Infy被害に関するバージョン

### **ゲーム オーバー**

捕捉の直後、Infyの新バージョン(31)においても、過去に確認済みのパターンの利用により、複数のドメインが既知の攻撃活動用IPアドレスに対して登録されていることを私たちは確認しました。パターン範囲box4035\[.\]net -- box4090\[.\]net (138.201.0.134)におけるほとんどどのドメインが該当します。しかし、これらはどのサンプルC2リストの中にも確認されませんでした。Bestwebstat\[.\]comは別の運用者によるシンクホールでした。

バージョン15-24のInfyに感染した一部の被害者は、まだ攻撃者の管理下にあるC2サーバus1s2\[.\]strangled\[.\]netを引き続き利用していました。6月上旬、攻撃者はこのC2を利用して新型のInfy「M」バージョン8.0をus1s2\[.\]strangled\[.\]net/bdc.tmpからダウンロードするよう指示しました。私たちはこのようにInfy亜種がInfy「M」に直接更新されているところを初めて目撃しました。その際、偽装名称「Macromedia v4」が使われましたが、これはInfy v31で見られた「v3」を変更したものです。また、攻撃者はこのバージョンで音声録音機能を削除しました。

uvps1\[.\]cotbm\[.\]comがデータを秘密裏に盗み出すのに用いられましたが、以前はアドレスが138.201.47.150であったのが私たちの最初のブログの公開後には144.76.250.205へと変わりました。また、/themes/u.phpにおいてマルウェアの更新が提供されていました。

不思議なC2エントリ「hxxp://box」も追加されていました(注: 記事公開にあたり無害化した表記にしてあります)。これがどのように機能するのかは不明です。ことによると、セキュリティ侵害を受けた被害者のイントラネットのデバイス、または攻撃者によって、被害者のコンピューター上にあるHOSTSファイルが変更された結果かもしれません。

私たちによる捕捉の後、攻撃者はサーバのドメイン名だけでなくIPアドレスを自分たちのマルウェアC2リストに追加し始めました。さらに、ZIPパスワードをわずかに「Z8(2000\_2001ul」から「Z8(2000\_2001uIEr3」へと変更しました。マルウェアの新バージョンにはKaspersky Labs、AvastおよびTrend Microがないか調べるアンチウイルス検査機能が追加されました。マルウェアのデータ キャプチャは以下のファイル拡張子を検索します。

*.doc, .docx, .xls, .xlsx, .xlr, .pps, .ppt, .pptx, .mdb, .accdb, .db, .dbf, .sql, .jpg, .jpeg, .psd, .tif, .mp4, .3gp, .txt, .rtf, .odt, .htm, .html, .pdf, .wps, .contact, .csv, .nbu, .vcf, .pst, .zip, .rar, .7z, .zipx, .pgp, .tc, .vhd, .p12, .crt.pem,.key.pfx, .asc, .cer, .p7b, .sst, .doc, .docx, .xls, .xlsx, .xlr, .pps, .ppt, .pptx.*

また、以下のフォルダー位置を検索します。

*:\\$recycle.bin, :\\documents and settings, :\\msocache, :\\program files, :\\program files (x86), :\\programdata, :\\recovery, :\\system volume information:\\users, :\\windows, :\\boot, :\\inetpub, :\\i386.*

マルウェアは、この攻撃活動で当初から現在に至るまで確認されている**同一の復号化キー**を使い続けていました。

6月中旬、C2ドメインの管理責任者と法執行当局の協力により、私たちは残りのC2ドメインをnullルート化して、IPアドレスで直接指定されていたサーバを無効化することに成功しました。これにより10年にわたる攻撃活動は終焉を迎えましたが、当然、やがてこの攻撃者が何か別のものを装って戻ってくるものと思われます。

捕捉作業をお手伝いしていただいたマルウェア リサーチ チーム(Yaron Samuel、Artiom Radune、Mashav Sapir、Netanel Rimer)に感謝いたします。

### 付録1 -- 秘密裏に持ち出すためのアルゴリズム

このマルウェアは、マルウェア文字列を暗号化するのに使われるものとは別のアルゴリズムを使って、秘密裏に持ち出すデータを暗号化します。そのアルゴリズムには次のものがあります。

1. キーロガー データ＋言語
2. マルウェア ログ―インストール時刻、DLLのパスと名称、ログのパス、ダウンロード回数、成功/失敗した接続の数
3. 被害者のコンピューターに関する情報: タイム ゾーン、ドライブとその種類の一覧、実行中のプロセス、ディスク情報

まず、このマルウェアはすべてのバイトに1を加え、次いで被害者のコンピューター名に基づいて暗号化キーを初期化します(キーにおけるオフセットは「コンピューター名の各文字コードの合計」%「キーの長さ」で計算されます)。その後、キーがデータの暗号化に使われます(復号化関数を参照のこと)。暗号化されたデータは引き続きbase64でコード化されます。

#### 秘密裏に持ち出すデータを暗号化するpythonコード:

import os,sys import string import base64 import fileinput FIRST\_PHASE = "OQTJEqtsK0AUB9YXMwr8idozF7VWRPpnhNCHI6Dlkaubyxf5423jvcZ1LSGmge" SECOND\_PHASE = "PqOwI1eUrYtT2yR3p4E5o6WiQu7ASlDkFj8GhHaJ9sKdLfMgNzBx0ZcXvCmVnb" global FULL\_KEY FULL\_KEY= "" def sub\_1\_for\_hex(str\_input): str\_output = "" for letter in str\_input: try: str\_output += chr(ord(letter)-1) except: print "sub\_1\_for\_hex func problem" continue return str\_output def sum\_comp\_name(comp\_name): sum = 0 for letter in comp\_name: sum+= ord(letter) return sum def init\_key(comp): comp\_name\_sum = sum\_comp\_name(comp) carry = divmod(comp\_name\_sum, 62) index = carry\[1\] -1 end\_key = FIRST\_PHASE\[:index\] key = FIRST\_PHASE\[index:\] key = key + end\_key key = key + key return key def decrypt(num\_list,offset): global FULL\_KEY input = "" for num\_str in num\_list: try: input += num\_str.decode('hex') except: input += ')' result = "" for i, c in enumerate(input): i = i % 62 +1 try: index = FULL\_KEY.index(c)-1 except ValueError: result += c continue translated = SECOND\_PHASE\[(index - i +offset) % len(SECOND\_PHASE)\] result += translated return result def found\_infy\_enc\_data(line): found\_infy\_str = "show=\\"---------- Administration Reporting Service " found\_infy\_index = line.find(found\_infy\_str) if not found\_infy\_index==-1: return True,found\_infy\_index else: return False,found\_infy\_index def extract\_comp\_name(line): comp = r"\\xd\\xa-----" comp\_index = line.find(comp) comp\_name = line\[comp\_index+len(comp):\] comp\_name = comp\_name\[:comp\_name.find("-----")\] print "(((=)))" + comp\_name return comp\_name def extract\_enc\_data(line): header = r"\\xd\\xa\_\_\_\_\_" start\_index = line.find(header)+len(header) line = line\[start\_index:\] endindex = line.index("\_\_\_\_\_\\" value=") line = line\[:endindex\] return line def write\_enc\_infy\_data\_to\_file(dec\_line,comp\_name,filename): file1 = open(filename + "\\\\" + comp\_name + ".txt",'ab') file1.writelines(dec\_line) file1.close() def enc\_wrapper(enc,comp\_name): global FULL\_KEY print FULL\_KEY FULL\_KEY = init\_key(comp\_name) enc\_final = "" for letter in enc: if len(hex(ord(letter))\[2:\])==1: enc\_final += "0" + hex(ord(letter))\[2:\] elif len(hex(ord(letter))\[2:\])==2: enc\_final += hex(ord(letter))\[2:\] else: print "not good hex length" exit() enc = enc\_final.upper() enc = enc.replace("2E","21") enc = enc.replace("C5DC5A","") enc = enc.replace("D03D00","") enc = enc.replace("0B0E","2121") enc = enc.replace("01","21") enc\_len = len(enc) enc\_rev = "" num\_list = \[\] enc\_print ="" for i in range(0,enc\_len/2): enc\_rev = enc\[-2:\] if not enc\_rev=="0B" and not enc\_rev=="0E" and not enc\_rev=="00" and not enc\_rev=="D0": enc\_print +=enc\_rev num\_list.append(enc\_rev) enc= enc\[:-2\] #the first part is always ok dec\_str = decrypt(num\_list,0) final = sub\_1\_for\_hex(dec\_str) index = final.find("OK: Sent") if index==-1: print comp\_name + " - did not found OK: Sent !!!!\\n\\n\\n\\n" #exit() decrypt\_data = comp\_name + " ++==++ " + str(i) + ": " + final + "\\n" final\_start = final\[0:500\] if final\_start in UNIQUE\_DATA: print comp\_name + " already have this data" return UNIQUE\_DATA.append(final\_start) index = final.find("Installed Date:") if index==-1: for i in range(1,61): dec\_str = decrypt3(num\_list,i) final = sub\_1\_for\_hex(dec\_str) ##print all 62 options index2 = final.find("PROGRAM START:") index3 = final.find("Installed Date:") if not index2 ==-1 or not index3 ==-1: decrypt\_data += str(i) + ": " + final + "\\n" write\_enc\_infy\_data\_to\_file(decrypt\_data,comp\_name,FILE\_OUTPUT\_NAME) def read\_enc\_data\_files(): for root,dir,files in os.walk(PDML\_PATH): for file in files: filename = root+ "\\\\" + file if os.path.isfile(filename): print filename for line in fileinput.input(\[filename\]): line = line.strip() is\_found,found\_infy\_index= found\_infy\_enc\_data(line) if not is\_found: continue line = line\[found\_infy\_index:\] #get computer name (for use in init\_key() later) comp\_name = extract\_comp\_name(line) UNIQUE\_COMP.append(comp\_name) #get the infy encrypted data line = extract\_enc\_data(line) #base64 decode enc\_data dec\_line = line.decode('base64') #append enc\_data to file write\_enc\_infy\_data\_to\_file(dec\_line,comp\_name,FILE\_ENC\_OUTPUT\_NAME) enc\_wrapper(dec\_line,comp\_name) try: read\_enc\_data\_files() except: print "exception!!!!"

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 | import os,sys import string import base64 import fileinput FIRST\_PHASE = "OQTJEqtsK0AUB9YXMwr8idozF7VWRPpnhNCHI6Dlkaubyxf5423jvcZ1LSGmge" SECOND\_PHASE = "PqOwI1eUrYtT2yR3p4E5o6WiQu7ASlDkFj8GhHaJ9sKdLfMgNzBx0ZcXvCmVnb" global FULL\_KEY FULL\_KEY= "" def sub\_1\_for\_hex(str\_input): str\_output = "" for letter in str\_input: try: str\_output += chr(ord(letter)-1) except: print "sub\_1\_for\_hex func problem" continue return str\_output def sum\_comp\_name(comp\_name): sum = 0 for letter in comp\_name: sum+= ord(letter) return sum def init\_key(comp): comp\_name\_sum = sum\_comp\_name(comp) carry = divmod(comp\_name\_sum, 62) index = carry\[1\] -1 end\_key = FIRST\_PHASE\[:index\] key = FIRST\_PHASE\[index:\] key = key + end\_key key = key + key return key def decrypt(num\_list,offset): global FULL\_KEY input = "" for num\_str in num\_list: try: input += num\_str.decode('hex') except: input += ')' result = "" for i, c in enumerate(input): i = i % 62 +1 try: index = FULL\_KEY.index(c)-1 except ValueError: result += c continue translated = SECOND\_PHASE\[(index - i +offset) % len(SECOND\_PHASE)\] result += translated return result def found\_infy\_enc\_data(line): found\_infy\_str = "show=\\"---------- Administration Reporting Service " found\_infy\_index = line.find(found\_infy\_str) if not found\_infy\_index==-1: return True,found\_infy\_index else: return False,found\_infy\_index def extract\_comp\_name(line): comp = r"\\xd\\xa-----" comp\_index = line.find(comp) comp\_name = line\[comp\_index+len(comp):\] comp\_name = comp\_name\[:comp\_name.find("-----")\] print "(((=)))" + comp\_name return comp\_name def extract\_enc\_data(line): header = r"\\xd\\xa\_\_\_\_\_" start\_index = line.find(header)+len(header) line = line\[start\_index:\] endindex = line.index("\_\_\_\_\_\\" value=") line = line\[:endindex\] return line def write\_enc\_infy\_data\_to\_file(dec\_line,comp\_name,filename): file1 = open(filename + "\\\\" + comp\_name + ".txt",'ab') file1.writelines(dec\_line) file1.close() def enc\_wrapper(enc,comp\_name): global FULL\_KEY print FULL\_KEY FULL\_KEY = init\_key(comp\_name) enc\_final = "" for letter in enc: if len(hex(ord(letter))\[2:\])==1: enc\_final += "0" + hex(ord(letter))\[2:\] elif len(hex(ord(letter))\[2:\])==2: enc\_final += hex(ord(letter))\[2:\] else: print "not good hex length" exit() enc = enc\_final.upper() enc = enc.replace("2E","21") enc = enc.replace("C5DC5A","") enc = enc.replace("D03D00","") enc = enc.replace("0B0E","2121") enc = enc.replace("01","21") enc\_len = len(enc) enc\_rev = "" num\_list = \[\] enc\_print ="" for i in range(0,enc\_len/2): enc\_rev = enc\[-2:\] if not enc\_rev=="0B" and not enc\_rev=="0E" and not enc\_rev=="00" and not enc\_rev=="D0": enc\_print +=enc\_rev num\_list.append(enc\_rev) enc= enc\[:-2\] #the first part is always ok dec\_str = decrypt(num\_list,0) final = sub\_1\_for\_hex(dec\_str) index = final.find("OK: Sent") if index==-1: print comp\_name + " - did not found OK: Sent !!!!\\n\\n\\n\\n" #exit() decrypt\_data = comp\_name + " ++==++ " + str(i) + ": " + final + "\\n" final\_start = final\[0:500\] if final\_start in UNIQUE\_DATA: print comp\_name + " already have this data" return UNIQUE\_DATA.append(final\_start) index = final.find("Installed Date:") if index==-1: for i in range(1,61): dec\_str = decrypt3(num\_list,i) final = sub\_1\_for\_hex(dec\_str) ##print all 62 options index2 = final.find("PROGRAM START:") index3 = final.find("Installed Date:") if not index2 ==-1 or not index3 ==-1: decrypt\_data += str(i) + ": " + final + "\\n" write\_enc\_infy\_data\_to\_file(decrypt\_data,comp\_name,FILE\_OUTPUT\_NAME) def read\_enc\_data\_files(): for root,dir,files in os.walk(PDML\_PATH): for file in files: filename = root+ "\\\\" + file if os.path.isfile(filename): print filename for line in fileinput.input(\[filename\]): line = line.strip() is\_found,found\_infy\_index= found\_infy\_enc\_data(line) if not is\_found: continue line = line\[found\_infy\_index:\] #get computer name (for use in init\_key() later) comp\_name = extract\_comp\_name(line) UNIQUE\_COMP.append(comp\_name) #get the infy encrypted data line = extract\_enc\_data(line) #base64 decode enc\_data dec\_line = line.decode('base64') #append enc\_data to file write\_enc\_infy\_data\_to\_file(dec\_line,comp\_name,FILE\_ENC\_OUTPUT\_NAME) enc\_wrapper(dec\_line,comp\_name) try: read\_enc\_data\_files() except: print "exception!!!!" |

### 付録2 -- IoC

Infyバージョン31: f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27

Infy「M」バージョン8.0: 583349B7A2385A1E8DE682A43351798CA113CBBB80686193ECF9A61E6942786A

5\.9.94.34  
138\.201.0.134  
138\.201.47.150  
144\.76.250.205  
138\.201.47.158  
138\.201.47.153  
us1s2\[.\]strangled\[.\]net  
uvps1\[.\]cotbm\[.\]com  
gstat\[.\]strangled\[.\]net  
secup\[.\]soon\[.\]it  
p208\[.\]ige\[.\]es  
lu\[.\]ige\[.\]es  
updateserver1\[.\]com  
updateserver3\[.\]com  
updatebox4\[.\]com  
bestupdateserver\[.\]com  
bestupdateserver2\[.\]com  
bestbox3\[.\]com  
safehostline\[.\]com  
youripinfo\[.\]com  
bestupser\[.\]awardspace\[.\]info  
box4035\[.\]net  
box4036\[.\]net  
box4037\[.\]net  
box4038\[.\]net  
box4039\[.\]net  
box4040\[.\]net  
box4041\[.\]net  
box4042\[.\]net  
box4043\[.\]net  
box4044\[.\]net  
box4045\[.\]net  
box4046\[.\]net  
box4047\[.\]net  
box4048\[.\]net  
box4049\[.\]net  
box4050\[.\]net  
box4051\[.\]net  
box4052\[.\]net  
box4053\[.\]net  
box4054\[.\]net  
box4055\[.\]net  
box4056\[.\]net  
box4057\[.\]net  
box4058\[.\]net  
box4059\[.\]net  
box4060\[.\]net  
box4061\[.\]net  
box4062\[.\]net  
box4063\[.\]net  
box4064\[.\]net  
box4065\[.\]net  
box4066\[.\]net  
box4067\[.\]net  
box4068\[.\]net  
box4069\[.\]net  
box4070\[.\]net  
box4071\[.\]net  
box4072\[.\]net  
box4075\[.\]net  
box4078\[.\]net  
box4079\[.\]net  
box4080\[.\]net  
box4081\[.\]net  
box4082\[.\]net  
box4083\[.\]net  
box4084\[.\]net  
box4085\[.\]net  
box4086\[.\]net  
box4087\[.\]net  
box4088\[.\]net  
box4089\[.\]net  
box4090\[.\]net
トップに戻る

### タグ

* [C2](https://unit42.paloaltonetworks.com/ja/tag/c2-ja/ "C2")
* [Infy](https://unit42.paloaltonetworks.com/ja/tag/infy-ja/ "Infy")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:日本でのElirks亜種を追跡: 過去の攻撃との類似点](https://unit42.paloaltonetworks.com/ja/unit42-tracking-elirks-variants-in-japan-similarities-to-previous-attacks/ "日本でのElirks亜種を追跡: 過去の攻撃との類似点")

### 関連記事

* [AdaptixC2:実世界の攻撃で活用される新しいオープンソース フレームワーク](https://unit42.paloaltonetworks.com/ja/adaptixc2-post-exploitation-framework/ "article - table of contents")
* [南太平洋で緊張が高まるなか Stately Taurus がフィリピンを標的に](https://unit42.paloaltonetworks.com/ja/stately-taurus-targets-philippines-government-cyberespionage/ "article - table of contents")
* [PowerShell Empire フレームワークによる C2 検出のための ML (機械学習) ベースの堅牢な学習システムのトレーニング](https://unit42.paloaltonetworks.com/ja/empire-c2-helps-train-machine-learning-framework/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
