{"id":104635,"date":"2018-11-21T06:00:21","date_gmt":"2018-11-21T14:00:21","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=104635"},"modified":"2020-02-17T22:39:43","modified_gmt":"2020-02-18T06:39:43","slug":"unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/","title":{"rendered":"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b"},"content":{"rendered":"<h2><a id=\"post-104635-\u6982\u8981\"><\/a>\u6982\u8981<\/h2>\n<p>\u65e9\u304f\u3082<a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/new-version-azorult-stealer-improves-loading-features-spreads-alongside\">2016\u5e74<\/a>\u306b\u306f\u89b3\u6e2c\u3055\u308c\u3066\u3044\u305fAzorult\u306f\u3001\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u30d5\u30a1\u30df\u30ea\u3067\u3042\u308a\u3001\u30b9\u30d1\u30e0 \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u4ecb\u3057\u3066\u3001\u307e\u305f\u306fRIG\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8 \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e2\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u3001\u60aa\u610f\u306e\u3042\u308b\u30de\u30af\u30ed\u30d9\u30fc\u30b9\u306e\u6587\u66f8\u3067\u914d\u4fe1\u3055\u308c\u3066\u304d\u307e\u3057\u305f\u30022018\u5e7410\u670820\u65e5\u3001\u5f0a\u793e\u306f\u3001\u65b0\u3057\u3044Azorult\u306e\u4e9c\u7a2e\u304c\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305f\u65b0\u305f\u306a\u7d99\u7d9a\u4e2d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u30011\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cFindMyName\u300d\u3068\u547d\u540d\u3057\u307e\u3057\u305f\u3002\u6700\u5f8c\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30da\u30fc\u30b8\u304c\u3059\u3079\u3066findmyname[.]pw\u3068\u3044\u3046\u30c9\u30e1\u30a4\u30f3\u306b\u884c\u304d\u7740\u304f\u305f\u3081\u3067\u3059\u3002\u3053\u306e\u3088\u3046\u306a\u65b0\u3057\u3044Azorult\u30b5\u30f3\u30d7\u30eb\u306e\u4e9c\u7a2e\u306f\u3001\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9\u88fd\u54c1\u3092\u56de\u907f\u3059\u308b\u305f\u3081\u3001API\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0\u3084\u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u5e73\u5766\u5316\u306a\u3069\u3001\u9ad8\u5ea6\u306a\u96e3\u8aad\u5316\u6280\u6cd5\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002\u307e\u305f\u3001Azorult\u306f\u3055\u3089\u306a\u308b\u9032\u5316\u3092\u9042\u3052\u3066\u304a\u308a\u3001\u5f0a\u793e\u304c\u6355\u6349\u3057\u305f\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3088\u308a\u3082\u591a\u304f\u306e\u30d6\u30e9\u30a6\u30b6\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3001\u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u306e\u6a5f\u5bc6\u60c5\u5831\u306e\u7a83\u53d6\u3092\u30b5\u30dd\u30fc\u30c8\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u30d6\u30ed\u30b0\u3067\u306f\u3001FindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3001\u65b0\u3057\u3044Azorult\u30de\u30eb\u30a6\u30a7\u30a2\u3001\u305d\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u96e3\u8aad\u5316\u6280\u6cd5\u306b\u3064\u3044\u3066\u8003\u5bdf\u3057\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-104635-findmyname\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u7b2c1\u6bb5\u968e\"><\/a>FindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u7b2c1\u6bb5\u968e<\/h3>\n<p>10\u670820\u65e5\u306f\u3001\u5f0a\u793e\u304cFindMyName\u3068\u547c\u3076\u65b0\u3057\u3044\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u6700\u521d\u306b\u89b3\u6e2c\u3057\u305f\u65e5\u3067\u3059\u3002\u4ee5\u5f8c3\u65e5\u9593\u3067\u3001\u4ed8\u93321\u306b\u6319\u3052\u305f5\u3064\u306e\u7570\u306a\u308bURL\u30c1\u30a7\u30fc\u30f3\u304cFallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306e\u914d\u4fe1\u306b\u7d50\u3073\u3064\u3044\u3066\u3044\u307e\u3057\u305f\u30025\u3064\u306e\u7570\u306a\u308bURL\u30c1\u30a7\u30fc\u30f3\u306e\u3059\u3079\u3066\u304c\u3001\u88ab\u5bb3\u7aef\u672b\u3092findmyname[.]pw\u3068\u3044\u30461\u3064\u306e\u30c9\u30e1\u30a4\u30f3\u306b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>FindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u7b2c1\u6bb5\u968e\u306b\u304a\u3051\u308b\u30b9\u30c6\u30c3\u30d7\u3092\u3001\u56f31\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"922\" height=\"191\"  class=\"wp-image-104636 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-223.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f31 \u653b\u6483\u306e\u7b2c1\u6bb5\u968e\u306e\u6982\u8981<\/em><\/span><\/p>\n<p>findmyname[.]pw\u306e5\u3064\u306e\u6700\u7d42\u30da\u30fc\u30b8\u306f\u7570\u306a\u308b\u3082\u306e\u306e\u3001\u305d\u308c\u3089\u306e\u4e2d\u8eab\u306f\u985e\u4f3c\u3057\u3066\u3044\u307e\u3059\u3002Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306e\u30e9\u30f3\u30c7\u30a3\u30f3\u30b0 \u30da\u30fc\u30b8\u306e\u4f8b\u3092\u56f32\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"483\"  class=\"wp-image-104638 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-224.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f32 \u96e3\u8aad\u5316\u3055\u308c\u305f\u30e9\u30f3\u30c7\u30a3\u30f3\u30b0 \u30da\u30fc\u30b8<\/em><\/span><\/p>\n<p>Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306f\u3001span\u3001h3\u3001p\u306a\u3069\u3001\u3044\u304f\u3064\u304b\u306ehtml\u30bf\u30b0\u3092\u4f7f\u7528\u3057\u3001\u9ad8\u5ea6\u306b\u96e3\u8aad\u5316\u3057\u305f\u30bf\u30b0 \u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u3088\u3063\u3066\u5b9f\u969b\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u96a0\u3057\u3066\u3044\u307e\u3059\u3002\u5fa9\u53f7\u5f8c\u306e\u5b9f\u969b\u306eVBScript\u30b3\u30fc\u30c9\u306f\u30018\u6708\u306b\u30d1\u30c3\u30c1\u304c\u9069\u7528\u3055\u308c\u305f\u3001<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2018\/09\/fallout-exploit-kit-used-in-malvertising-campaign-to-deliver-gandcrab-ransomware.html\">IE VBScript\u306e\u8106\u5f31\u6027<\/a>(<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-8174\">CVE-2018-8174)<\/a>\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"725\"  class=\"wp-image-104640 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-225.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f33 Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306b\u304a\u3051\u308bCVE-2018-8174\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u306e\u30b9\u30cb\u30da\u30c3\u30c8<\/em><\/span><\/p>\n<p>\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u6210\u529f\u3059\u308b\u3068\u3001\u3053\u306eFallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306f\u300c.tmp\u300d\u30d5\u30a1\u30a4\u30eb\u3092%Temp%\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001CreateProcess\u3092\u547c\u3073\u51fa\u3057\u3066\u3001\u305d\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u8a73\u3057\u3044\u5206\u6790\u306b\u3088\u3063\u3066\u3001\u300c.tmp\u300d\u30d5\u30a1\u30a4\u30eb\u304cAzorult\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u6700\u65b0\u306e\u4e9c\u7a2e\u3067\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306e1\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066Azorult\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u65b0\u3057\u3044\u4e9c\u7a2e\u304c\u4f7f\u7528\u3055\u308c\u308b\u306e\u3092\u78ba\u8a8d\u3057\u305f\u306e\u306f\u3053\u308c\u304c\u521d\u3081\u3066\u3067\u3057\u305f\u3002<\/p>\n<h3><a id=\"post-104635-findmyname\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u7b2c2\u6bb5\u968e\"><\/a>FindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u7b2c2\u6bb5\u968e<\/h3>\n<p>\u3053\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u306f\u3001\u5f0a\u793e\u304c\u6355\u6349\u3057\u305fAzorult\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u6700\u65b0\u306e\u4e9c\u7a2e\u306e\u5206\u6790\u306b\u91cd\u70b9\u3092\u7f6e\u304d\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-104635-\u30de\u30eb\u30a6\u30a7\u30a2\u5206\u6790\u306e\u6982\u8981\"><\/a>\u30de\u30eb\u30a6\u30a7\u30a2\u5206\u6790\u306e\u6982\u8981<\/h4>\n<p>Azorult\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u306f\u3001\u5730\u4e0b\u30d5\u30a9\u30fc\u30e9\u30e0\u3067\u8ca9\u58f2\u3055\u308c\u3066\u3044\u308b\u55b6\u5229\u76ee\u7684\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3059\u3002\u5f0a\u793e\u306f\u3001\u6700\u8fd1\u306eFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u30673\u3064\u306e\u65b0\u3057\u3044Azorult\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u305d\u308c\u3089\u3092\u89b3\u6e2c\u3057\u305f\u6642\u70b9\u3067\u306f\u30013\u3064\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u3046\u30612\u3064\u306f\u3001\u307e\u3060\u5b9f\u969b\u306e\u611f\u67d3\u3092\u78ba\u8a8d\u3067\u304d\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u5f0a\u793e\u304c\u6355\u6349\u3057\u3001\u5206\u6790\u3057\u305f\u65b0\u3057\u3044Azorult\u30b5\u30f3\u30d7\u30eb\u306e1\u3064\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u60aa\u610f\u306e\u3042\u308b\u6a5f\u80fd\u304c\u3042\u308a\u307e\u3057\u305f(\u3053\u306e\u3088\u3046\u306a\u6a5f\u80fd\u306e\u4e00\u90e8\u306f\u3001\u6b21\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u8a73\u3057\u304f\u8aac\u660e\u3057\u307e\u3059)\u3002<\/p>\n<ol>\n<li>API\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0\u306b\u3088\u3063\u3066\u3001\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9 \u30a8\u30df\u30e5\u30ec\u30fc\u30bf\u3092\u56de\u907f\u3002<\/li>\n<li>\u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u5e73\u5766\u5316\u6280\u6cd5\u306b\u3088\u3063\u3066\u3001\u30ea\u30d0\u30fc\u30b9 \u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u5206\u6790\u3092\u59a8\u5bb3\u3002<\/li>\n<li>\u30d7\u30ed\u30bb\u30b9\u306e\u7a7a\u6d1e\u5316\u6280\u6cd5\u3092\u4f7f\u7528\u3057\u3066\u3001\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2 \u30a4\u30e1\u30fc\u30b8\u3092\u4f5c\u6210\u3002<\/li>\n<li>\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3088\u308a\u3082\u591a\u304f\u306e\u30d6\u30e9\u30a6\u30b6\u3067\u3001\u8cc7\u683c\u60c5\u5831\u3001cookie\u3001\u5c65\u6b74\u3001\u30aa\u30fc\u30c8\u30d5\u30a3\u30eb\u7528\u306e\u60c5\u5831\u3092\u7a83\u53d6\u3002<\/li>\n<li>\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3088\u308a\u3082\u591a\u304f\u306e\u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u3092\u7a83\u53d6\u3002<\/li>\n<li>\u5fc5\u8981\u306b\u5fdc\u3058\u3001Skype\u3001Telegram\u3001Steam\u3001FTP\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3001\u96fb\u5b50\u30e1\u30fc\u30eb \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306e\u8cc7\u683c\u60c5\u5831\u304a\u3088\u3073\u30c1\u30e3\u30c3\u30c8\u5c65\u6b74\u3092\u7a83\u53d6\u3002<\/li>\n<li>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6e08\u307f\u30d7\u30ed\u30b0\u30e9\u30e0\u3001\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3001\u30de\u30b7\u30f3\u60c5\u5831\u3001\u30e6\u30fc\u30b6\u30fc\u540d\u3001OS\u30d0\u30fc\u30b8\u30e7\u30f3\u3001\u5b9f\u884c\u4e2d\u30d7\u30ed\u30bb\u30b9\u3092\u4ecb\u3057\u3001\u88ab\u5bb3\u7aef\u672b\u306e\u60c5\u5831\u3092\u53ce\u96c6\u3002<\/li>\n<li>\u30e6\u30fc\u30b6\u30fc\u306e\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u53ce\u96c6\u3002<\/li>\n<li>\u30a2\u30f3\u30c1\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3001\u3059\u3079\u3066\u306e\u30c9\u30ed\u30c3\u30d7\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u6d88\u53bb\u3002<\/li>\n<li>C2\u901a\u4fe1\u306b\u3088\u3063\u3066\u958b\u59cb\u3055\u308c\u305f\u7279\u5b9a\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u5b9f\u884c\u3002<\/li>\n<\/ol>\n<h4><a id=\"post-104635-api\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0\u304a\u3088\u3073\u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u5e73\u5766\u5316\u306b\u3088\u308b\u96e3\u8aad\u5316\"><\/a>API\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0\u304a\u3088\u3073\u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u5e73\u5766\u5316\u306b\u3088\u308b\u96e3\u8aad\u5316<\/h4>\n<p>\u6700\u521d\u306eAzorult\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001Microsoft Visual C++ 7.0\u3067\u4f5c\u6210\u3055\u308c\u307e\u3057\u305f\u3002\u7b2c\u4e00\u306b\u3001Azorult\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001<a href=\"https:\/\/github.com\/obfuscator-llvm\/obfuscator\/wiki\/Control-Flow-Flattening\">\u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u5e73\u5766\u5316<\/a>\u306b\u3088\u308b\u96e3\u8aad\u5316\u3092\u4f7f\u7528\u3057\u3066\u3001\u30ea\u30d0\u30fc\u30b9 \u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u5206\u6790\u3092\u59a8\u5bb3\u3057\u307e\u3059(\u56f34\u53c2\u7167)\u3002\u7b2c\u4e8c\u306b\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001API\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0\u6280\u6cd5\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3057\u305f(\u56f35\u53c2\u7167)\u3002API\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0\u306f\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9 \u30a8\u30df\u30e5\u30ec\u30fc\u30bf\u3092\u56de\u907f\u3059\u308b\u305f\u3081\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u6280\u6cd5\u3067\u3059\uff61\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9 \u30a8\u30df\u30e5\u30ec\u30fc\u30bf\u306f\uff64\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u4e0a\u306e\u652f\u969c\u304c\u751f\u3058\u306a\u3044\u3088\u3046\uff64\u30db\u30b9\u30c8 \u30de\u30b7\u30f3\u3067\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30a8\u30df\u30e5\u30ec\u30fc\u30c8\u3059\u308b\u3055\u3044\uff64\u4e00\u5b9a\u6642\u9593\u5185\u3067\u30a8\u30df\u30e5\u30ec\u30fc\u30b7\u30e7\u30f3\u3092\u7d42\u4e86\u3059\u308b\u30bf\u30a4\u30de\u30fc\u3092\u8a2d\u5b9a\u3057\u307e\u3059\uff61\u3053\u3053\u3067\uff64\u6570\u767e\u56de\u306b\u304a\u3088\u3076\u95a2\u6570\u51e6\u7406\u306e\u30a8\u30df\u30e5\u30ec\u30fc\u30c8\u3092\u884c\u308f\u305b\u308b\u3068\uff64\u30bf\u30a4\u30e0 \u30a2\u30a6\u30c8\u304c\u767a\u751f\u3057\uff64\u30d5\u30a1\u30a4\u30eb\u304c\u7121\u5bb3\u3068\u3057\u3066\u30de\u30fc\u30ad\u30f3\u30b0\u3055\u308c\u3066\u3057\u307e\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"550\" height=\"468\"  class=\"wp-image-104642 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-226.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f34 \u5236\u5fa1\u30d5\u30ed\u30fc\u306e\u5e73\u5766\u5316<\/em><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><img width=\"545\" height=\"552\"  class=\"wp-image-104644 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-227.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f35 API\u30d5\u30e9\u30c3\u30c7\u30a3\u30f3\u30b0<\/em><\/span><\/p>\n<h4><a id=\"post-104635-\u30d7\u30ed\u30bb\u30b9\u306e\u7a7a\u6d1e\u5316\"><\/a>\u30d7\u30ed\u30bb\u30b9\u306e\u7a7a\u6d1e\u5316<\/h4>\n<p>Azorult\u306f\u3001\u30d7\u30ed\u30bb\u30b9\u306e\u7a7a\u6d1e\u5316\u6280\u6cd5\u3092\u4f7f\u7528\u3057\u3001\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2 \u30a4\u30e1\u30fc\u30b8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u307e\u305a\uff64\u30e1\u30e2\u30ea\u5185\u3067\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u3057\u307e\u3059\u3002\u6b21\u306b\u81ea\u8eab\u306e\u4e00\u6642\u505c\u6b62\u3057\u305f\u30d7\u30ed\u30bb\u30b9\u3092\u65b0\u3057\u304f\u4f5c\u6210\u3057\uff64\u305d\u306e\u306e\u3061\u306b\u5fa9\u53f7\u3057\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u65b0\u3057\u3044\u30d7\u30ed\u30bb\u30b9\u306b\u633f\u5165\u3057\u307e\u3059\u3002\u6700\u5f8c\u306b\u65b0\u3057\u3044\u30d7\u30ed\u30bb\u30b9\u5b9f\u884c\u3092\u518d\u958b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u632f\u308b\u821e\u3044\u3092\u884c\u3044\u307e\u3059\u3002\u30b5\u30f3\u30d7\u30eb\u5b9f\u884c\u306e\u6982\u8981\u3092\u56f36\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"912\" height=\"362\"  class=\"wp-image-104646 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-228.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f36 \u30b5\u30f3\u30d7\u30eb\u306e\u30d7\u30ed\u30bb\u30b9\u7a7a\u6d1e\u5316<\/em><\/span><\/p>\n<h3><a id=\"post-104635-c2\u901a\u4fe1\"><\/a>C2\u901a\u4fe1<\/h3>\n<p>\u30d7\u30ed\u30bb\u30b9\u304b\u3089\u30c0\u30f3\u30d7\u3055\u308c\u305f\u65b0\u3057\u3044\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u30d5\u30a1\u30a4\u30eb\u306f\u3001Delphi\u3067\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u30b5\u30f3\u30d7\u30eb\u306f\u5b9f\u884c\u6642\u306b\u3001\u5373\u5ea7\u306bC2\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3057\u3066\u3055\u3089\u306a\u308b\u6307\u793a\u3092\u53d7\u3051\u307e\u3059\u3002\u4fb5\u5165\u9632\u5fa1\u30b7\u30b9\u30c6\u30e0(IPS)\u3092\u56de\u907f\u3059\u308b\u305f\u3081\u3001C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u96e3\u8aad\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002C2\u306b\u9001\u308a\u8fd4\u3055\u308c\u308b\u30c7\u30fc\u30bf\u306b\u306f\u3001\u88ab\u5bb3\u306b\u3042\u3063\u305f\u500b\u3005\u306e\u30de\u30b7\u30f3\u56fa\u6709\u306e\u88ab\u5bb3\u7aef\u672bID\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u30de\u30b7\u30f3\u306eGUID\u3001Windows\u88fd\u54c1\u540d\u3001\u30e6\u30fc\u30b6\u30fc\u540d\u3001\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u540d\u304c\u30cf\u30c3\u30b7\u30e5 \u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001C2\u30a2\u30c9\u30ec\u30b9\u3092\u5fa9\u53f7\u3057\u3001\u6697\u53f7\u5316\u3055\u308c\u305f\u88ab\u5bb3\u7aef\u672b\u306eID\u3067\u3001POST\u30ea\u30af\u30a8\u30b9\u30c8\u309251[.]15[.]196[.]30\/1\/index.php\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u56f37\u306b\u793a\u3057\u307e\u3059\u3002\u30cf\u30c3\u30b7\u30e5 \u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3068\u6697\u53f7\u5316\u306b\u95a2\u3059\u308b\u8a73\u3057\u3044\u4f8b\u306f\u3001\u4ed8\u93321\u306b\u6319\u3052\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"354\"  class=\"wp-image-104648 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-229.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f37 C2\u30ea\u30af\u30a8\u30b9\u30c8<\/em><\/span><\/p>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001C2\u5fdc\u7b54\u3092\u5fa9\u53f7\u3057\u3001\u691c\u8a3c\u3057\u307e\u3059\u3002\u5fa9\u53f7\u3055\u308c\u305fC2\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u306f3\u3064\u306e\u90e8\u5206\u304c\u3042\u308a\u307e\u3057\u305f\u3002&lt;n&gt;&lt;\/n&gt;\u30bf\u30b0\u3067\u56f2\u307e\u308c\u305f\u90e8\u5206\u306b\u306f\u300148\u500b\u306e\u6b63\u898fDLL\u304c\u542b\u307e\u308c\u3001\u3053\u308c\u3089\u306f\u4ee5\u5f8c\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u8aac\u660e\u3059\u308b\u60c5\u5831\u7a83\u53d6\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002&lt;d&gt;&lt;\/d&gt;\u30bf\u30b0\u3067\u56f2\u307e\u308c\u305f\u90e8\u5206\u306b\u306f\u3001\u60c5\u5831\u7a83\u53d6\u7528\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u60c5\u5831\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30d1\u30b9\u3001\u95a2\u9023\u30ec\u30b8\u30b9\u30c8\u30ea\u3001\u8cc7\u683c\u60c5\u5831\u30d5\u30a1\u30a4\u30eb\u540d\u3067\u3059\u3002&lt;c&gt;&lt;\/c&gt;\u30bf\u30b0\u3067\u56f2\u307e\u308c\u305f\u90e8\u5206\u306b\u306f\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306eC2\u69cb\u6210\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002C2\u69cb\u6210\u3092\u56f38\u306b\u793a\u3057\u307e\u3059\u3002pcap\u5206\u6790\u306b\u3088\u3063\u3066\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u4ee5\u4e0b\u306e\u6587\u5b57\u304c\u30c1\u30a7\u30c3\u30af\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<ol>\n<li>\u300c+\u300d: \u7279\u5b9a\u306e\u60aa\u610f\u306e\u3042\u308b\u6a5f\u80fd\u3092\u6709\u52b9\u5316\u3057\u307e\u3059\u3002<\/li>\n<li>\u300c-\u300d: \u7279\u5b9a\u306e\u60aa\u610f\u306e\u3042\u308b\u6a5f\u80fd\u3092\u7121\u52b9\u5316\u3057\u307e\u3059\u3002<\/li>\n<li>\u300cI\u300d: \u30db\u30b9\u30c8IP\u60c5\u5831\u3092\u53ce\u96c6\u3057\u307e\u3059\u3002<\/li>\n<li>\u300cL\u300d: \u30ea\u30e2\u30fc\u30c8 \u30b5\u30fc\u30d0\u30fc\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002<\/li>\n<\/ol>\n<p><span style=\"font-size: 10pt;\"><img width=\"972\" height=\"122\"  class=\"wp-image-104650 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-230.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f38 C2\u69cb\u6210<\/em><\/span><\/p>\n<p>C2\u3067\u6307\u5b9a\u3055\u308c\u305f\u60aa\u610f\u306e\u3042\u308b\u6a5f\u80fd:<\/p>\n<ol>\n<li>\u30d6\u30e9\u30a6\u30b6 \u30d1\u30b9\u30ef\u30fc\u30c9\u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6\u3002<\/li>\n<li>\u30d6\u30e9\u30a6\u30b6\u306ecookie\u3001\u30aa\u30fc\u30c8\u30d5\u30a3\u30eb\u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6\u3002FTP\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3084\u96fb\u5b50\u30e1\u30fc\u30eb \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304b\u3089\u306e\u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6\u3002<\/li>\n<li>\u30d6\u30e9\u30a6\u30b6\u5c65\u6b74\u306e\u7a83\u53d6\u3002<\/li>\n<li>\u30d3\u30c3\u30c8\u30b3\u30a4\u30f3 \u30a6\u30a9\u30ec\u30c3\u30c8\u306e\u7a83\u53d6\u3002<\/li>\n<li>Skype\u306e\u30c1\u30e3\u30c3\u30c8 \u30e1\u30c3\u30bb\u30fc\u30b8main.db\u306e\u7a83\u53d6\u3002<\/li>\n<li>Telegram\u306e\u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6\u3002<\/li>\n<li>Steam\u306e\u8cc7\u683c\u60c5\u5831(ssfn)\u304a\u3088\u3073\u30b2\u30fc\u30e0 \u30e1\u30bf\u30c7\u30fc\u30bf(.vdf)\u306e\u7a83\u53d6\u3002<\/li>\n<li>\u6700\u7d42\u7684\u306b\u653b\u6483\u8005\u306b\u9001\u3089\u308c\u308b\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306e\u53d6\u5f97\u3002<\/li>\n<li>\u4e00\u6642\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30a4\u30eb\u306e\u6d88\u53bb\u3002<\/li>\n<li>\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u304b\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u53ce\u96c6\u3002<\/li>\n<li>GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092ip-api[.]com\/json\u306b\u9001\u4fe1\u3059\u308b\u3053\u3068\u306b\u3088\u308b\u30db\u30b9\u30c8IP\u60c5\u5831\u306e\u53d6\u5f97\u3002<\/li>\n<li>C2\u3067\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3068\u5b9f\u884c\u3002<\/li>\n<\/ol>\n<p>\u56f39\u306f\u3001Firefox\u304a\u3088\u3073Thunderbird\u304b\u3089\u6a5f\u5bc6\u60c5\u5831\u3092\u7a83\u53d6\u3059\u308b\u305f\u3081\u306eC2\u69cb\u6210\u306e\u4f8b\u3067\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"929\" height=\"279\"  class=\"wp-image-104652 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-231.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f39 \u60c5\u5831\u7a83\u53d6\u7528\u306eC2\u69cb\u6210<\/em><\/span><\/p>\n<p>C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u6982\u8981\u3092\u56f310\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"414\"  class=\"wp-image-104654 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-232.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f310 C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u6982\u8981<\/em><\/span><\/p>\n<h3><a id=\"post-104635-\u60c5\u5831\u7a83\u53d6\"><\/a>\u60c5\u5831\u7a83\u53d6<\/h3>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001Chrome\u3001Firefox\u3001Qihoo 360\u306a\u3069\u300132\u306e\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u8cc7\u683c\u60c5\u5831\u304a\u3088\u3073\u30e6\u30fc\u30b6\u30fc \u30c7\u30fc\u30bf\u3092\u7a83\u53d6\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u30d6\u30e9\u30a6\u30b6\u306e\u5168\u30ea\u30b9\u30c8\u306f\u4ed8\u93322\u306b\u3042\u308a\u307e\u3059\u3002\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u8cc7\u683c\u60c5\u5831\u3092\u7a83\u53d6\u3059\u308b\u305f\u3081\u3001\u30b5\u30f3\u30d7\u30eb\u306fC2\u306e\u5fdc\u7b54\u304b\u308948\u500b\u306e\u6b63\u898fDLL\u30d5\u30a1\u30a4\u30eb\u3092 %AppData%\\Local\\Temp\\2fda \u30d5\u30a9\u30eb\u30c0\u306b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u3044\u307e\u3057\u305f(\u56f311\u53c2\u7167)\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"343\" height=\"708\"  class=\"wp-image-104656 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-233.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f311 \u5408\u6cd5\u306adll\u30d5\u30a1\u30a4\u30eb<\/em><\/span><\/p>\n<p>\u3053\u306e\u52d5\u4f5c\u306e\u76ee\u7684\u306f\u3001nss3.dll\u3092\u30ed\u30fc\u30c9\u3057\u3066\u3001\u4ee5\u4e0b\u306e\u95a2\u6570\u3092\u30ed\u30fc\u30c9\u3059\u308b\u3053\u3068\u3067\u3059\u3002<\/p>\n<ul>\n<li>sqlite3_open<\/li>\n<li>sqlite3_close<\/li>\n<li>sqlite3_prepare_v2<\/li>\n<li>sqlite3_step<\/li>\n<li>sqlite3_column_text<\/li>\n<li>sqlite3_finalize<\/li>\n<li>NSS_Init<\/li>\n<li>PK11_GetInternalKeySlot<\/li>\n<li>PK11_Authenticate<\/li>\n<li>PK11SDR_Decrypt<\/li>\n<li>NSS_Shutdown<\/li>\n<li>PK11_FreeSlot<\/li>\n<\/ul>\n<p>\u3053\u308c\u3089\u306e\u95a2\u6570\u306f\u3001\u30d6\u30e9\u30a6\u30b6\u306e\u6a5f\u5bc6\u60c5\u5831\u3092\u30c0\u30f3\u30d7\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001sqlite3_*\u95a2\u6570\u3092\u4f7f\u7528\u3057\u3066\u3001Firefox\u30d6\u30e9\u30a6\u30b6\u306e\u5c65\u6b74\u60c5\u5831\u3092\u53d6\u5f97\u3057\u3088\u3046\u3068\u3057\u307e\u3059(\u56f312\u53c2\u7167)\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"291\"  class=\"wp-image-104658 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-234.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f312 nss3.dll\u306eAPI\u3092\u4f7f\u7528\u3057\u305fFirefox\u6a5f\u5bc6\u60c5\u5831\u306e\u7a83\u53d6<\/em><\/span><\/p>\n<p>\u30e6\u30fc\u30b6\u30fc\u540d\u3068\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u7a83\u53d6\u3059\u308b\u5225\u306e\u4f8b\u3092\u793a\u3057\u307e\u3059\u3002\u3053\u306e\u5834\u5408\u306f\u3001\u4fdd\u5b58\u3055\u308c\u305fChrome\u30c7\u30fc\u30bf\u304b\u3089\u7a83\u53d6\u3057\u3066\u3044\u307e\u3059\u3002\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u30d1\u30b9\u300c%LOCALAPPDATA%\\Google\\Chrome\\User Data\\\u300d\u3067\u30d5\u30a1\u30a4\u30eb\u300cLogin Data\u300d\u3092\u691c\u7d22\u3057\u307e\u3059\u3002\u898b\u3064\u304b\u3063\u305f\u3089\u3001\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u300cLogin Data\u300d\u30d5\u30a1\u30a4\u30eb\u3092%AppData%\\Local\\Temp\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u30b3\u30d4\u30fc\u3057\u3066\u3001nss3.dll\u304b\u3089sqlite3_prepare_v2\u95a2\u6570\u3092\u547c\u3073\u51fa\u3057\u3066\u3001SQL\u30af\u30a8\u30ea\u3001\u300cSELECT origin_url, username_value, password_value FROM logins\u300d\u3092\u4f7f\u7528\u3057\u3066\u8cc7\u683c\u60c5\u5831\u3092\u76d7\u307f\u51fa\u3057\u307e\u3059(\u56f313\u53c2\u7167)\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"972\" height=\"477\"  class=\"wp-image-104660 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-235.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f313 \u30d6\u30e9\u30a6\u30b6\u306e\u8cc7\u683c\u60c5\u5831\u3092\u7a83\u53d6\u3059\u308b\u305f\u3081\u306eselect\u6587\u5b57\u5217<\/em><\/span><\/p>\n<p>\u307e\u305f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u524d\u8ff0\u306e\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u3001cookie\u3001\u30d6\u30c3\u30af\u30de\u30fc\u30af\u3001\u30aa\u30fc\u30c8\u30d5\u30a3\u30eb\u60c5\u5831\u3082\u76d7\u307f\u51fa\u3057\u307e\u3059\u3002\u8cc7\u683c\u60c5\u5831\u306f\u3001PasswordsList.txt\u306b\u3001cookie\u306f\u3001CookieList.txt\u306b\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u307e\u305f\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3001\u4ee5\u4e0b\u306e\u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u3092\u7a83\u53d6\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li>Ethereum<\/li>\n<li>Electrum<\/li>\n<li>Electrum-LTC<\/li>\n<li>Jaxx<\/li>\n<li>Exodus<\/li>\n<li>MultiBitHD<\/li>\n<\/ul>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u306e\u6a5f\u5bc6\u60c5\u5831\u3092\u542b\u3080\u3001\u7279\u5b9a\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u898b\u3064\u3051\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u300cCoins\\MultiBitHD\u300d\u306b\u3042\u308b\u300cmbhd.wallet.aes\u300d\u30d5\u30a1\u30a4\u30eb\u3092\u898b\u3064\u3051\u3066\u9001\u4fe1\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3057\u305f(\u56f314\u53c2\u7167)\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"727\" height=\"1225\"  class=\"wp-image-104662 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-236.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f314 \u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u306e\u7a83\u53d6<\/em><\/span><\/p>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001Thunderbird\u3001FileZilla\u3001Outlook\u3001WinSCP\u3001Skype\u3001Telegram\u3001Steam\u306a\u3069\u3001\u3088\u304f\u4f7f\u7528\u3055\u308c\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304b\u3089\u8cc7\u683c\u60c5\u5831\u304a\u3088\u3073\u30e6\u30fc\u30b6\u30fc \u30c7\u30fc\u30bf\u3092\u7a83\u53d6\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u304b\u3089\u3082\u30d5\u30a1\u30a4\u30eb\u3092\u7a83\u53d6\u3057\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u300c%appdata%\\Telegram Desktop\\tdata\u300d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3042\u308b\u300cD877F783D5*.map*\u300d\u30d5\u30a1\u30a4\u30eb\u3092\u898b\u3064\u3051\u3066\u3001Telegram\u304b\u3089\u6a5f\u5bc6\u60c5\u5831\u3092\u7a83\u53d6\u3057\u3088\u3046\u3068\u3057\u307e\u3059(\u56f315\u53c2\u7167)\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"385\"  class=\"wp-image-104664 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-237.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f315 \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6<\/em><\/span><\/p>\n<p>\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u73fe\u884c\u30d7\u30ed\u30bb\u30b9\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6e08\u307f\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3001\u30b7\u30b9\u30c6\u30e0\u8a00\u8a9e\u3001\u30bf\u30a4\u30e0 \u30be\u30fc\u30f3\u306a\u3069\u3001\u30e6\u30fc\u30b6\u30fc\u60c5\u5831\u3092\u53ce\u96c6\u3057\u307e\u3059\u3002\u53ce\u96c6\u3055\u308c\u305f\u8cc7\u683c\u60c5\u5831\u304a\u3088\u3073\u30e6\u30fc\u30b6\u30fc\u60c5\u5831\u306f\u3001C2\u306b\u9001\u308a\u8fd4\u3055\u308c\u307e\u3059\u3002\u4ee5\u4e0b\u306b\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u7a83\u53d6\u306b\u95a2\u3059\u308b\u8981\u70b9\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u88ab\u5bb3\u306b\u3042\u3063\u305f\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3092\u53d6\u5f97\u3057\u3066\u3001scr.jpg\u3068\u3044\u3046\u540d\u524d\u306e\u30a4\u30e1\u30fc\u30b8 \u30d5\u30a1\u30a4\u30eb\u306b\u4fdd\u5b58\u3057\u307e\u3059(\u56f316\u53c2\u7167)\u3002<\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt;\"><img width=\"722\" height=\"137\"  class=\"wp-image-104666 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-238.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f316 \u753b\u9762\u306e\u30ad\u30e3\u30d7\u30c1\u30e3<\/em><\/span><\/p>\n<ul>\n<li>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001C2\u5fdc\u7b54\u3067\u6307\u5b9a\u3055\u308c\u305f\u30d1\u30b9\u304a\u3088\u3073\u30c9\u30e9\u30a4\u30d0\u30fc \u30bf\u30a4\u30d7\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/li>\n<li>GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092ip-api[.]com\/json\u306b\u9001\u4fe1\u3059\u308b\u3053\u3068\u306b\u3088\u3063\u3066\u30db\u30b9\u30c8IP\u60c5\u5831\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002json\u5fdc\u7b54\u3092ip.txt\u306b\u683c\u7d0d\u3057\u307e\u3059\u3002<\/li>\n<li>\u4ee5\u4e0b\u306e\u30e6\u30fc\u30b6\u30fc\u60c5\u5831\u3092\u53ce\u96c6\u3057\u3066\u3001system.txt\u306b\u4fdd\u5b58\u3057\u307e\u3059\u3002\n<ul>\n<li>\u30de\u30b7\u30f3\u306eGUID<\/li>\n<li>Windows\u88fd\u54c1\u540d<\/li>\n<li>\u30e6\u30fc\u30b6\u30fc\u540d<\/li>\n<li>\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u540d<\/li>\n<li>\u30b7\u30b9\u30c6\u30e0 \u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3<\/li>\n<li>\u753b\u9762\u306e\u9ad8\u3055\u3068\u5e45<\/li>\n<li>\u30b7\u30b9\u30c6\u30e0\u8a00\u8a9e<\/li>\n<li>\u73fe\u5728\u306e\u30ed\u30fc\u30ab\u30eb\u6642\u9593<\/li>\n<li>\u30bf\u30a4\u30e0 \u30be\u30fc\u30f3<\/li>\n<li>CPU\u30b3\u30a2\u6570<\/li>\n<li>CreateToolhelp32Snapshot\u306e\u547c\u3073\u51fa\u3057\u306b\u3088\u308b\u73fe\u884c\u30d7\u30ed\u30bb\u30b9 \u30ea\u30b9\u30c8<\/li>\n<li>\u30c7\u30a3\u30b9\u30d7\u30ec\u30a4 \u30d0\u30fc\u30b8\u30e7\u30f3\u304a\u3088\u3073\u540d\u524d<\/li>\n<li>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6e08\u307f\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2(Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\)<\/li>\n<li>\u73fe\u5728\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u6a29\u9650\u306e\u53d6\u5f97<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u53ce\u96c6\u3059\u308b\u3059\u3079\u3066\u306e\u60c5\u5831\u3092\u56f317\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"560\"  class=\"wp-image-104668 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-239.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f317 \u30de\u30eb\u30a6\u30a7\u30a2\u304c\u53ce\u96c6\u3059\u308b\u60c5\u5831<\/em><\/span><\/p>\n<h3><a id=\"post-104635-\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u3088\u3063\u3066\u6307\u5b9a\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u5b9f\u884c\"><\/a>\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u3088\u3063\u3066\u6307\u5b9a\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u5b9f\u884c<\/h3>\n<p>\u653b\u6483\u8005\u306f\u3001\u611f\u67d3\u3057\u305f\u30b7\u30b9\u30c6\u30e0\u3092\u30ea\u30e2\u30fc\u30c8\u3067\u5236\u5fa1\u3057\u3066\u3001Create Process\u307e\u305f\u306fShellExecute\u306b\u3088\u3063\u3066\u3001\u4efb\u610f\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059(\u56f318\u53c2\u7167)\u3002\u307e\u305f\u3001\u60aa\u610f\u306e\u3042\u308bURL\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066plugin-update[.]space\/download\/10.17.18.exe\u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u3092\u53d6\u5f97\u3059\u308b\u52d5\u4f5c\u3082\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"570\" height=\"422\"  class=\"wp-image-104670 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-240.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f318 CreateProcess\u307e\u305f\u306fShellExecute\u3092\u547c\u3073\u51fa\u3057\u3066\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c<\/em><\/span><\/p>\n<p>\u3053\u306eAzorult\u306e\u65b0\u3057\u3044\u4e9c\u7a2e\u306f\u3001\u30ed\u30fc\u30ab\u30eb \u30b7\u30b9\u30c6\u30e0\u6a29\u9650\u3067\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u5b9f\u884c\u3059\u308b\u6a5f\u80fd\u3082\u4fdd\u6709\u3057\u3066\u3044\u307e\u3059\u3002\u4ee5\u4e0b\u306e\u30ed\u30b8\u30c3\u30af\u3067\u73fe\u5728\u306eSID\u304a\u3088\u3073\u30c8\u30fc\u30af\u30f3\u3092\u30c1\u30a7\u30c3\u30af\u3057\u307e\u3059(\u56f319\u53c2\u7167)\u3002<\/p>\n<ul>\n<li>\u73fe\u5728\u306e\u6574\u5408\u6027\u30ec\u30d9\u30eb\u304clocal_system\u306e\u5834\u5408\n<ul>\n<li>WTSQueryUserToken\u304a\u3088\u3073CreateProcessAsUser\u3092\u547c\u3073\u51fa\u3057\u3066\u3001\u56f320\u306e\u3088\u3046\u306b\u30b7\u30b9\u30c6\u30e0\u6a29\u9650\u3067\u65b0\u3057\u3044\u30d7\u30ed\u30bb\u30b9\u3092\u958b\u59cb\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"362\"  class=\"wp-image-104672 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-241.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f319 SID\u304a\u3088\u3073\u30c8\u30fc\u30af\u30f3\u306e\u30c1\u30a7\u30c3\u30af<\/em><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><img width=\"974\" height=\"443\"  class=\"wp-image-104674 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-242.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f320 \u30ed\u30fc\u30ab\u30eb \u30b7\u30b9\u30c6\u30e0\u6a29\u9650\u3067\u30d7\u30ed\u30bb\u30b9\u3092\u4f5c\u6210<\/em><\/span><\/p>\n<h3><a id=\"post-104635-\u624b\u639b\u304b\u308a\u306e\u6d88\u53bb\u3068\u30d5\u30a1\u30a4\u30eb\u306e\u524a\u9664\"><\/a>\u624b\u639b\u304b\u308a\u306e\u6d88\u53bb\u3068\u30d5\u30a1\u30a4\u30eb\u306e\u524a\u9664<\/h3>\n<p>\u5f0a\u793e\u306f\u3001\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u3001\u300c%temp%\\2fda\u300d\u306b\u3042\u308b\u3059\u3079\u3066\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u6d88\u53bb\u3057\u3001C2\u306e\u30b3\u30de\u30f3\u30c9\u306b\u5f93\u3063\u3066\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3059\u308b\u3053\u3068\u3082\u767a\u898b\u3057\u307e\u3057\u305f(\u56f321\u304a\u3088\u3073\u56f322\u53c2\u7167)\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"606\" height=\"427\"  class=\"wp-image-104676 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-243.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f321 \u611f\u67d3\u306e\u624b\u639b\u304b\u308a\u306e\u6d88\u53bb<\/em><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><img width=\"543\" height=\"377\"  class=\"wp-image-104678 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/02\/word-image-244.png\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u56f322 C2\u30b3\u30de\u30f3\u30c9\u306b\u3088\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u524a\u9664<\/em><\/span><\/p>\n<h2><a id=\"post-104635-\u7d50\u8ad6\"><\/a>\u7d50\u8ad6<\/h2>\n<p>\u63a8\u5b9a\u3055\u308c\u308b\u65b0\u3057\u3044\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306f\u300110\u6708\u5f8c\u534a\u306b\u660e\u3089\u304b\u306b\u306a\u308a\u3001\u5f0a\u793e\u306e\u76ee\u306b\u7559\u307e\u308a\u307e\u3057\u305f\u30023\u65e5\u9593\u3067\u30015\u3064\u306eFallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306eURL\u30c1\u30a7\u30fc\u30f3\u304c\u89b3\u6e2c\u3055\u308c\u3001\u3059\u3079\u3066\u304cfindmyname[.]pw\u3068\u3044\u3046\u30c9\u30e1\u30a4\u30f3\u3067\u30db\u30b9\u30c8\u3055\u308c\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30da\u30fc\u30b8\u306b\u884c\u304d\u7740\u304d\u307e\u3057\u305f\u3002Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u3001\u65b0\u3057\u3044Azorult\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3068\u6bd4\u3079\u3066\u6a5f\u80fd\u304c\u66f4\u65b0\u3055\u308c\u3066\u304a\u308a\u3001\u3088\u308a\u591a\u304f\u306e\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u304a\u3088\u3073\u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u304b\u3089\u306e\u7a83\u53d6\u304c\u30b5\u30dd\u30fc\u30c8\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u6700\u65b0\u306eWindows\u30db\u30b9\u30c8\u3092\u88c5\u5099\u3057\u3066\u3044\u308b\u7d44\u7e54\u306f\u3001\u611f\u67d3\u306e\u30ea\u30b9\u30af\u304c\u304b\u306a\u308a\u4f4e\u304f\u306a\u308a\u307e\u3059\u3002\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u3053\u306e\u8105\u5a01\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5f0a\u793e\u306e\u8105\u5a01\u9632\u5fa1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306f\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3068Azorult\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4e21\u65b9\u3092\u691c\u51fa\u3057\u307e\u3059\u3002AutoFocus\u3092\u3054\u4f7f\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.AzoRult\">AzoRult<\/a>\u30bf\u30b0\u3067\u3001\u3053\u306e\u6d3b\u52d5\u3092\u8abf\u3079\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-104635-ioc\"><\/a>IOC<\/h2>\n<h3><a id=\"post-104635-url\u30c1\u30a7\u30fc\u30f3\"><\/a>URL\u30c1\u30a7\u30fc\u30f3<\/h3>\n<h4><a id=\"post-104635-url\u30c1\u30a7\u30fc\u30f31\"><\/a>URL\u30c1\u30a7\u30fc\u30f31<\/h4>\n<ul>\n<li>hxxp:\/\/sax[.]peakonspot[.]com\/dep.php?pid=6639&amp;format=POPUP&amp;subid=&amp;cid=M2018102013-11642b318a12196b7fae1559b32a45c2<\/li>\n<li>hxxps:\/\/gfobhk[.]peak-serving[.]com\/?&amp;id=15400452977053288308437914&amp;tid=6639&amp;sr=ep<\/li>\n<li>hxxp:\/\/sp[.]popcash[.]net\/go\/161339\/449201<\/li>\n<li>hxxp:\/\/sp[.]popcash[.]net\/sgo\/ad?p=161339&amp;w=449201&amp;t=33fd7220adb3c003&amp;r=&amp;vw=0&amp;vh=0<\/li>\n<li>hxxp:\/\/findmyname[.]pw\/1981_06_18\/spumier\/04_05_1952\/E4bI5EK9?FYpUsha=Hangmen-Avowedly-Political-montreal&amp;JAb1I5xAS=Reeled_chateaus_funduck_royalize_unconvert_Joysome&amp;Outdraft=Tr6mHo5&amp;VX1m7hhu=ugaritic_Shying_fleece_15919<\/li>\n<\/ul>\n<h4><a id=\"post-104635-url\u30c1\u30a7\u30fc\u30f32\"><\/a>URL\u30c1\u30a7\u30fc\u30f32<\/h4>\n<ul>\n<li>hxxp:\/\/tania[.]web[.]telrock[.]net\/<\/li>\n<li>hxxp:\/\/api[.]clickaine[.]com\/v1\/apop\/redirect\/zone\/15450<\/li>\n<li>hxxp:\/\/findmyname[.]pw\/M6rpEF\/lifted\/7013-Tiddley-toadyisms-11956-8965\/peevedly_Oversured_tungstic.cfml<\/li>\n<\/ul>\n<h4><a id=\"post-104635-url\u30c1\u30a7\u30fc\u30f33\"><\/a>URL\u30c1\u30a7\u30fc\u30f33<\/h4>\n<ul>\n<li>hxxp:\/\/manuela[.]w[.]telrock[.]org\/<\/li>\n<li>hxxp:\/\/api[.]clickaine[.]com\/v1\/apop\/redirect\/zone\/15450<\/li>\n<li>hxxp:\/\/findmyname[.]pw\/hoivSZVRX\/NV1uI\/vpLnq.shtml?nXslO=indult-Cadere&amp;sAoiIFu=Tirracke&amp;KaaM=Uncloak_Becloaked<\/li>\n<\/ul>\n<h4><a id=\"post-104635-url\u30c1\u30a7\u30fc\u30f34\"><\/a>URL\u30c1\u30a7\u30fc\u30f34<\/h4>\n<ul>\n<li>hxxp:\/\/sl[.]ivankatraff[.]com\/sl?vId\\=bmconv_20181024052548_bea8e890_2113_4ecc_951b_c90aeffde1e6&amp;publisherId\\=40152&amp;source\\=5348_8482&amp;ua\\=Mozilla%2F5.0+%28iPhone%3B+CPU+iPhone+OS+11_3+like+Mac+OS+X%29+AppleWebKit%2F605.1.15+%28KHTML%2C+like+Gecko%29+Mobile%2F15E302&amp;ip\\=124.35.82.126&amp;campaignI<\/li>\n<li>hxxp:\/\/damneddevastator[.]com\/l\/18358235b03f965b74d5?sub=&amp;source=&amp;code2=Y3RtATE1NDAzOTM4OTI1MDEAc3JjAWlvAHZlcgExOQBwbHQBV2luMzIAdGNoATEAaXcBNzkyAGloATUwNABhdwExNDQwAGFoATg1NgB0egE0ODAAYnVpZAEAY2tlATEAb3JudAEAdm5kAQBoc2ZjAXRydWUAZnJtAWZhbHNlAHVhAU1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgVHJpZGVudC83LjA7IFNMQ0MyOyAuTkVUIENMUiAyLjAuNTA3Mjc7IC5ORVQgQ0xSIDMuNS4zMDcyOTsgLk5FVCBDTFIgMy4wLjMwNzI5OyBNZWRpYSBDZW50ZXIgUEMgNi4wOyAuTkVUNC4wQzsgLk5FVDQuMEU7IHJ2OjExLjApIGxpa2UgR2Vja28AYTQzATEwMTEwMQBhNDQBMTEAc2YBMTExMABmZgExMTAAY2hkATAAZmx2AWZhbHNlAGNobQEwMDEAbG5nATExMTEAc3RyZwExMTEwMTAwAG9zY3B1AQBwcmRzdWIBAGV2bG4BMzkAcmVmAQByYmNjATEwMjUxMTUzAGNudHABdHJ1ZQB3bm0BAHdnbHYBMABjZGcBMDAwMDAwMDAwMDAwMDAwMDAxMTExMDAxMDEwMDAwMDAwMTAyMjEyMDAwMDAwMDIyMjIyMjIyMjIyMjIyMjIyMgB3dXQBdy5wYW53X2hhc190aW1lb3V0X3NldDt3LnBhbndfQWN0aXZlWE9iamVjdF9BcmdzX0FycmF5O3cubXNJbmRleGVkREI7dy5jbGlwYm9hcmREYXRhO3cubWF4Q29ubmVjdGlvbnNQZXJTZXJ2ZXI7dy5vbmZvY3VzaW47dy5vbmZvY3Vzb3V0O3cub25oZWxwO3cuYW5pbWF0aW9uU3RhcnRUaW1lO3cubXNBbmltYXRpb25TdGFydFRpbWU7dy5tc0NyeXB0bzt3Lm9ubXNnZXN0dXJlY2hhbmdlO3cub25tc2dlc3R1cmVkb3VibGV0YXA7dy5vbm1zZ2VzdHVyZWVuZDt3Lm9ubXNnZXN0dXJlaG9sZDt3Lm9ubXNnZXN0dXJlc3RhcnQ7dy5vbm1zZ2VzdHVyZXRhcDt3Lm9ubXNpbmVydGlhc3RhcnQ7dy5vbm1zcG9pbnRlcmNhbmNlbDt3Lm9ubXNwb2ludGVyZG93bjt3Lm9ubXNwb2ludGVyZW50ZXI7dy5vbm1zcG9pbnRlcmxlYXZlO3cub25tc3BvaW50ZXJtb3ZlO3cub25tc3BvaW50ZXJvdXQ7dy5vbm1zcG9pbnRlcm92ZXI7dy5vbm1zcG9pbnRlcnVwO3cub25yZWFkeXN0YXRlY2hhbmdlO3cuaXRlbTt3Lm1zV3JpdGVQcm9maWxlck1hcms7dy5uYXZpZ2F0ZTt3LnNob3dIZWxwO3cuc2hvd01vZGVsZXNzRGlhbG9nO3cudG9TdGF0aWNIVE1MO3cubXNDYW5jZWxSZXF1ZXN0QW5pbWF0aW9uRnJhbWU7dy5tc0lzU3RhdGljSFRNTDt3Lm1zTWF0Y2hNZWRpYTt3Lm1zUmVxdWVzdEFuaW1hdGlvbkZyYW1lO3cudG9TdHJpbmc7dy5jbGVhckltbWVkaWF0ZTt3Lm1zQ2xlYXJJbW1lZGlhdGU7dy5tc1NldEltbWVkaWF0ZTt3LnNldEltbWVkaWF0ZQBrbG5nAWVuLVVTAHJ0dAEhAGxhbwEtMQBobHMBMA__<\/li>\n<li>hxxp:\/\/damneddevastator[.]com\/gw?sub=&amp;source=Unknown&amp;url=https%3A%2F%2Fsax.peakonspot.com%2Fdep.php%3Fpid%3D2457%26subid%3D2_Unknown%26cid%3Dbmconv_20181024091133_7532cd6e_41dc_445b_a538_a0f29d2af047%26ref%3D&amp;vId=bmconv_20181024091133_7532cd6e_41dc_445b_a538_a0f29d2af047&amp;hash=18358235b03f965b74d5&amp;ete=true<\/li>\n<li>https:\/\/sax.peakonspot.com\/dep.php?pid=2457&amp;subid=2_Unknown&amp;cid=bmconv_20181024091133_7532cd6e_41dc_445b_a538_a0f29d2af047&amp;ref=<\/li>\n<li>hxxp:\/\/findmyname[.]pw\/pysV15\/olt8uPj1\/1969_04_11<\/li>\n<\/ul>\n<h4><a id=\"post-104635-url\u30c1\u30a7\u30fc\u30f35\"><\/a>URL\u30c1\u30a7\u30fc\u30f35<\/h4>\n<ul>\n<li>hxxp:\/\/whitepages[.]review\/prpllr?cost=0.001850&amp;currency=USD&amp;external_id=76427570563780608&amp;ad_campaign_id=1382277&amp;source=PropellerAds&amp;sub_id_1=1774896<\/li>\n<li>hxxp:\/\/findmyname[.]pw\/cymbalo\/13345\/13231?potteries=icL8gc96<\/li>\n<\/ul>\n<h3>\u30d0\u30a4\u30ca\u30eaSHA256<\/h3>\n<h4>\u30b5\u30f3\u30d7\u30eb1:<\/h4>\n<p>3354a1d18aa861de2e17eeec65fc6545bc52deebe86c3ef12ccb372c312d8af8<\/p>\n<h4>\u30b5\u30f3\u30d7\u30eb2:<\/h4>\n<p>7a99eb3e340f61f800ab3b8784f718bbe2e38159a883c2fc009af740df944431<\/p>\n<h4>\u30b5\u30f3\u30d7\u30eb3:<\/h4>\n<p>0e27bbfa70b399182f030ee18531e100d4f6e8cb64e592276b02c18b7b5d69e6<\/p>\n<h2>\u4ed8\u9332<\/h2>\n<h3>\u4ed8\u93321: \u30cf\u30c3\u30b7\u30e5 \u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u304a\u3088\u3073\u6697\u53f7\u5316<\/h3>\n<p>C2\u306b\u9001\u3089\u308c\u308b\u88ab\u5bb3\u7aef\u672bID\u306e\u30cf\u30c3\u30b7\u30e5 \u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u304a\u3088\u3073\u6697\u53f7\u5316:<\/p>\n<pre>from pwn import *\r\n\r\ndef hash_func(input):\r\n    x = 0\r\n    for i in input:\r\n        x += ord(i) ^ 0x6521458a\r\n        x &amp;= 0xFFFFFFFF\r\n        x -= ((x &lt;&lt; 0xD) &amp; 0xFFFFFFFF) | (x &gt;&gt; 0x13)\r\n        x &amp;= 0xFFFFFFFF\r\n\r\n    return format(x, 'X').rjust(8, '0')\r\n\r\ndef format_hash_str(hash_str):\r\n    y = len(hash_str)\r\n    format_hash = []\r\n    format_hash.append(hash_str[:7])\r\n\r\n    hash_str = hash_str[7:]\r\n    i = 0\r\n    while i &lt;= y: if i % 8 == 0 and y - i &gt;= 16:\r\n            format_str = hash_str[i:i+8]\r\n            if y - i &lt; 24: format_str = hash_str[i:] format_hash.append(format_str) i += 1 return '-'.join(format_hash) def obfuscate_hash_str(hash_str): obfuscated_hash_str = '' for i in hash_str: t = (ord(i) - ord('A')) &amp; 0xFF q = (ord(i) - ord('a')) &amp; 0xFF if t &gt;= 0x1A and q &gt;= 0x1A:\r\n            obfuscated_hash_str += '%' + format(ord(i), 'X')\r\n        else:\r\n            obfuscated_hash_str += i\r\n    return obfuscated_hash_str\r\n\r\ndef xor_encrypt(hash_str):\r\n    key = (0xD, 0xA, 0xC8)\r\n    encrypted_str = ''\r\n    print hash_str\r\n    for i in range(len(hash_str)):\r\n        encrypted_str += chr(ord(hash_str[i]) ^ key[i % len(key)])\r\n\r\n    return encrypted_str\r\n<\/pre>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u30de\u30b7\u30f3\u306eGUID\u3001\u88fd\u54c1\u540d\u3001\u30e6\u30fc\u30b6\u30fc\u540d\u3001\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u540d\u3092\u53d6\u5f97\u3059\u308b\u3068\u3001\u524d\u8ff0\u306e\u30cf\u30c3\u30b7\u30e5 \u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3068\u6697\u53f7\u5316\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3092\u4f7f\u7528\u3057\u3066\u3001\u6697\u53f7\u5316\u3055\u308c\u305f\u88ab\u5bb3\u7aef\u672bID\u3092\u751f\u6210\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"\">user_info = ('8699cdcd-cd9c-49ca-a44a-6c7e984575dc', 'Windows 7 Professional', 'test',\r\n'WIN-GKIQOSL71B3')\r\n\r\nhash_str = ''\r\nfor i in user_info:\r\n    hash_str += hash_func(i)\r\n\r\nhash_str += hash_func(''.join(user_info)) # 344FB5D5343A2EC681928A0244CA6CE98647CCAA\r\nhash_str = format_hash_str(hash_str) # 344FB5D-5343A2EC-681928A0-244CA6CE-98647CCAA\r\n\r\nhash_str = 'G' + obfuscate_hash_str(hash_str) # G%33%34%34FB%35D%2D%35%33%34%33A%32EC%2D%36%38%31%39%32%38A%30%2D%32%34%34CA%36CE%2D%39%38%36%34%37CCAA\r\nencrypted_victim_id = xor_encrypt(hash_str)\r\n<\/pre>\n<p>C2\u30a2\u30c9\u30ec\u30b9\u5fa9\u53f7:<\/p>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001xor\u30ad\u30fc[0x09, 0xff, 0x20]\u3092\u4f7f\u7528\u3057\u3066.data\u30bb\u30af\u30b7\u30e7\u30f3\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u5fa9\u53f7\u3057\u3001\u6587\u5b57\u5217\u300caHR0cDovLzUxLjE1LjE5Ni4zMC8xL2luZGV4LnBocA\u300d\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002\u6b21\u306b\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001base64\u30c7\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u3066\u3001C2\u30a2\u30c9\u30ec\u30b9\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002<\/p>\n<h3>\u4ed8\u93322: \u6a19\u7684\u3068\u306a\u308b\u30d6\u30e9\u30a6\u30b6\u306e\u30ea\u30b9\u30c8<\/h3>\n<ul>\n<li>GoogleChrome<\/li>\n<li>InternetMailRu<\/li>\n<li>YandexBrowser<\/li>\n<li>ComodoDragon<\/li>\n<li>Amigo<\/li>\n<li>Orbitum<\/li>\n<li>Bromium<\/li>\n<li>Chromium<\/li>\n<li>Nichrome<\/li>\n<li>RockMelt<\/li>\n<li>360Browser<\/li>\n<li>Vivaldi<\/li>\n<li>Opera<\/li>\n<li>GoBrowser<\/li>\n<li>Sputnik<\/li>\n<li>Kometa<\/li>\n<li>Uran<\/li>\n<li>QIPSurf<\/li>\n<li>Epic<\/li>\n<li>Brave<\/li>\n<li>CocCoc<\/li>\n<li>CentBrowser<\/li>\n<li>7Star<\/li>\n<li>ElementsBrowser<\/li>\n<li>TorBro<\/li>\n<li>Suhba<\/li>\n<li>SaferBrowser<\/li>\n<li>Mustang<\/li>\n<li>Superbird<\/li>\n<li>Chedot<\/li>\n<li>Torch<\/li>\n<li>Internet Explorer<\/li>\n<li>Microsoft Edge<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u65e9\u304f\u30822016\u5e74\u306b\u306f\u89b3\u6e2c\u3055\u308c\u3066\u3044\u305fAzorult\u306f\u3001\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u30d5\u30a1\u30df\u30ea\u3067\u3042\u308a\u3001\u30b9\u30d1\u30e0 \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u4ecb\u3057\u3066\u3001\u307e\u305f\u306fRIG\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8 \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e2\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u3001\u60aa\u610f\u306e\u3042\u308b\u30de\u30af\u30ed\u30d9\u30fc\u30b9\u306e\u6587\u66f8\u3067\u914d<\/p>\n","protected":false},"author":57,"featured_media":103976,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4324,4434,1974,4428],"tags":[6357,6849,5073,6677,6851,6853,6855,6857,6859,6861,6863,6865,6866],"product_categories":[],"coauthors":[71,1000,921,72],"class_list":["post-104635","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybercrime","category-cybercrime-ja","category-malware-ja","category-threat-research-ja","tag-azorult-ja","tag-coins-ja","tag-cryptocurrency-ja","tag-cve-2018-8174-ja","tag-electrum-ja","tag-electrum-ltc-ja","tag-ethereum-ja","tag-exodus-ja","tag-fallout-exploit-kit-ja","tag-findmyname-ja","tag-jaxx-ja","tag-multibithd-ja","tag-wallet"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b<\/title>\n<meta name=\"description\" content=\"2018\u5e7410\u670820\u65e5\u3001\u5f0a\u793e\u306f\u3001\u65b0\u3057\u3044Azorult\u306e\u4e9c\u7a2e\u304c\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305f\u65b0\u305f\u306a\u7d99\u7d9a\u4e2d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u30011\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cFindMyName\u300d\u3068\u547d\u540d\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b\" \/>\n<meta property=\"og:description\" content=\"2018\u5e7410\u670820\u65e5\u3001\u5f0a\u793e\u306f\u3001\u65b0\u3057\u3044Azorult\u306e\u4e9c\u7a2e\u304c\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305f\u65b0\u305f\u306a\u7d99\u7d9a\u4e2d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u30011\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cFindMyName\u300d\u3068\u547d\u540d\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-21T14:00:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-02-18T06:39:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit42-blog-600x300-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tao Yan, Xingyu Jin, Zhanglin He, Bo Qu\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b","description":"2018\u5e7410\u670820\u65e5\u3001\u5f0a\u793e\u306f\u3001\u65b0\u3057\u3044Azorult\u306e\u4e9c\u7a2e\u304c\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305f\u65b0\u305f\u306a\u7d99\u7d9a\u4e2d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u30011\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cFindMyName\u300d\u3068\u547d\u540d\u3057\u307e\u3057\u305f\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/","og_locale":"ja_JP","og_type":"article","og_title":"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b","og_description":"2018\u5e7410\u670820\u65e5\u3001\u5f0a\u793e\u306f\u3001\u65b0\u3057\u3044Azorult\u306e\u4e9c\u7a2e\u304c\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305f\u65b0\u305f\u306a\u7d99\u7d9a\u4e2d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u30011\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cFindMyName\u300d\u3068\u547d\u540d\u3057\u307e\u3057\u305f\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/","og_site_name":"Unit 42","article_published_time":"2018-11-21T14:00:21+00:00","article_modified_time":"2020-02-18T06:39:43+00:00","og_image":[{"width":600,"height":300,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit42-blog-600x300-1.jpg","type":"image\/jpeg"}],"author":"Tao Yan, Xingyu Jin, Zhanglin He, Bo Qu","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/"},"author":{"name":"Tao Yan","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/44772c337a792f6bacb73db69aa39563"},"headline":"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b","datePublished":"2018-11-21T14:00:21+00:00","dateModified":"2020-02-18T06:39:43+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/"},"wordCount":948,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit42-blog-600x300-1.jpg","keywords":["Azorult","Coins","Cryptocurrency","CVE-2018-8174","Electrum","Electrum-LTC","Ethereum","Exodus","Fallout Exploit Kit","FindMyName","Jaxx","MultiBitHD","Wallet"],"articleSection":["Cybercrime","\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/","name":"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit42-blog-600x300-1.jpg","datePublished":"2018-11-21T14:00:21+00:00","dateModified":"2020-02-18T06:39:43+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/44772c337a792f6bacb73db69aa39563"},"description":"2018\u5e7410\u670820\u65e5\u3001\u5f0a\u793e\u306f\u3001\u65b0\u3057\u3044Azorult\u306e\u4e9c\u7a2e\u304c\u3001Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305f\u65b0\u305f\u306a\u7d99\u7d9a\u4e2d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u30011\u6b21\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cFindMyName\u300d\u3068\u547d\u540d\u3057\u307e\u3057\u305f\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit42-blog-600x300-1.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit42-blog-600x300-1.jpg","width":600,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u65b0\u3057\u3044\u30ef\u30a4\u30f3\u3092\u53e4\u3044\u30dc\u30c8\u30eb\u3067: Fallout\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u305fFindMyName\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u65b0\u305f\u306aAzorult\u306e\u4e9c\u7a2e\u3092\u767a\u898b"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/44772c337a792f6bacb73db69aa39563","name":"Tao Yan","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Tao Yan"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/tao-yan\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/104635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=104635"}],"version-history":[{"count":5,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/104635\/revisions"}],"predecessor-version":[{"id":104685,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/104635\/revisions\/104685"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/103976"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=104635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=104635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=104635"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=104635"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=104635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}