{"id":106783,"date":"2017-02-16T11:00:35","date_gmt":"2017-02-16T19:00:35","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=106783"},"modified":"2020-04-26T19:00:05","modified_gmt":"2020-04-27T02:00:05","slug":"unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/","title":{"rendered":"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit 42\u300d\u306f\u30012016\u5e74\u306e9\u6708\u304b\u308911\u6708\u306b\u304b\u3051\u3066\u3001\u300cmenuPass\u300d\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bAPT\u653b\u6483\uff08\u6301\u7d9a\u578b\u306e\u6a19\u7684\u578b\u653b\u6483\uff09\u304c\u3001\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u304a\u3088\u3073\u88fd\u85ac\u4f01\u696d\u3001\u7c73\u56fd\u306b\u5b50\u4f1a\u793e\u3092\u7f6e\u304f\u88fd\u9020\u696d\u3092\u5bfe\u8c61\u306b\u3057\u3066\u3044\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u653b\u6483\u3067\u306f\u3001\u30c8\u30e9\u30f3\u30d7\u6c0f\u306e\u9078\u6319\u3067\u306e\u52dd\u5229\u306b\u4fbf\u4e57\u3057\u305f\u4ef6\u540d\u306a\u3069\u3092\u4f7f\u7528\u3057\u305f\u3001\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u304c\u7528\u3044\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u304c\u3001PlugX\u304a\u3088\u3073Poison Ivy (PIVY)\u3068\u3044\u3063\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u306f\u77e5\u3089\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u308c\u30892\u3064\u306b\u52a0\u3048\u3001JPCERT\u30b3\u30fc\u30c7\u30a3\u30cd\u30fc\u30b7\u30e7\u30f3\u30bb\u30f3\u30bf\u30fc(JPCERT\/CC)\u304c\u300c<a href=\"https:\/\/www.jpcert.or.jp\/magazine\/acreport-ChChes.html\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">ChChes<\/a>\u300d\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3082\u4f7f\u7528\u3057\u3066\u3044\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u8907\u6570\u306e\u653b\u6483\u6d3b\u52d5\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u308bPlugX\u304a\u3088\u3073PIVY\u3068\u306f\u5bfe\u7167\u7684\u306b\u3001ChChes\u306f\u3053\u306e\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c\u72ec\u81ea\u306b\u4f7f\u7528\u3057\u3066\u3044\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u3060\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u3001Unit 42\u304c\u78ba\u8a8d\u3057\u305fChChes\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u5143\u3005\u30a4\u30bf\u30ea\u30a2\u4f01\u696dHackingTeam\u306b\u3088\u308b\u8a3c\u660e\u66f8\u3001\u304a\u3088\u3073HackingTeam\u304c\u30cf\u30c3\u30ad\u30f3\u30b0\u3092\u53d7\u3051\u305f\u3068\u304d\u306b<a href=\"https:\/\/motherboard.vice.com\/read\/spy-tech-company-hacking-team-gets-hacked\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">\u6f0f\u3048\u3044\u3057\u305f\u30c7\u30fc\u30bf<\/a>\u306e\u5f8c\u534a\u90e8\u3092\u4f7f\u7528\u3057\u3066\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4f01\u696d\u306eWapack labs\u3082\u3001\u65e5\u672c\u3092\u6a19\u7684\u3068\u3059\u308b<a href=\"https:\/\/wapacklabs.blogspot.co.uk\/2017\/01\/japan-spear-phished-by-trojan-bkdrchches.html\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">\u985e\u4f3c\u30b5\u30f3\u30d7\u30eb<\/a>\u309211\u6708\u306b\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u8005\u304c\u3053\u306e\u8a3c\u660e\u66f8\u3092\u4f7f\u7528\u3057\u305f\u7406\u7531\u306f\u4e0d\u660e\u3067\u3059\u3002\u3053\u306e\u8a3c\u660e\u66f8\u306f\u53e4\u304f\u3001\u30cd\u30c3\u30c8\u4e0a\u306b\u6f0f\u3048\u3044\u3057\u305f\u3082\u306e\u3067\u3042\u308a\u3001\u3059\u3067\u306b\u5931\u52b9\u6e08\u307f\u3067\u3059\u3002\u4e00\u822c\u7684\u306b\u3001\u30c7\u30b8\u30bf\u30eb\u8a3c\u660e\u66f8\u306f\u6b63\u5f53\u6027\u306e\u5370\u8c61\u3092\u4e0e\u3048\u308b\u7406\u7531\u304b\u3089\u653b\u6483\u306b\u304a\u3044\u3066\u4f7f\u7528\u3055\u308c\u307e\u3059\u304c\u3001\u3053\u306e\u30c7\u30b8\u30bf\u30eb\u8a3c\u660e\u66f8\u306f\u6c7a\u3057\u3066\u305d\u3046\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>menuPass\u306f\u3001\u7b39\u5ddd\u5e73\u548c\u8ca1\u56e3\u304a\u3088\u3073\u30db\u30ef\u30a4\u30c8\u30cf\u30a6\u30b9\u306b\u95a2\u9023\u306e\u3042\u308b\u516c\u5f0f\u30a2\u30c9\u30ec\u30b9\u306a\u3069\u306b\u9001\u4fe1\u8005\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u507d\u88c5\u3057\u3001\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u3092\u9001\u4fe1\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306f\u3001\u6a19\u7684\u304a\u3088\u3073\u898b\u305b\u304b\u3051\u306e\u9001\u4fe1\u8005\u306b\u3075\u3055\u308f\u3057\u3044\u4ef6\u540d\u3092\u4f7f\u3044\u3001\u60c5\u5831\u306e\u5165\u624b\u3092\u76ee\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u30db\u30ef\u30a4\u30c8\u30cf\u30a6\u30b9\u95a2\u9023\u30a2\u30c9\u30ec\u30b9\u3092\u88c5\u3063\u305f\u653b\u6483\u3067\u306f\u3001<b><u>\u300c\u201c[UNCLASSIFIED] The impact of Trump\u2019s victory to Japan\u201d([\u975e\u6a5f\u5bc6\u6271\u3044] \u30c8\u30e9\u30f3\u30d7\u6c0f\u52dd\u5229\u306e\u65e5\u672c\u3078\u306e\u885d\u6483)\u300d<\/u><\/b>\u3068\u3044\u3046\u4ef6\u540d\u304c\u4f7f\u308f\u308c\u3066\u304a\u308a\u3001\u7c73\u5927\u7d71\u9818\u9078\u306e2\u65e5\u5f8c\u306b\u9001\u4fe1\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u307e\u3067\u306e\u5b66\u8853\u7814\u7a76\u8005\u306b\u5bfe\u3059\u308b\u653b\u6483\u306e\u5927\u591a\u6570\u306f\u3001\u95a2\u4fc2\u3059\u308b\u5b66\u8853\u7814\u7a76\u8005\u306e\u540d\u524d\u306b\u3088\u308b\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u7528\u3044\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u4eca\u56de\u306e\u4e00\u9023\u306e\u653b\u6483\u306f\u3053\u3046\u3057\u305f\u5b66\u8853\u7814\u7a76\u8005\u3068\u306f\u8868\u7acb\u3063\u305f\u7d50\u3073\u4ed8\u304d\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u4e00\u65b9\u3001\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306e\u53d7\u4fe1\u8005\u306f\u3001\u5b66\u8853\u95a2\u4fc2\u8005\u3068\u95a2\u9023\u3059\u308b\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u306e\u6301\u3061\u4e3b\u3067\u3057\u305f\u3002<\/p>\n<figure style=\"width: 973px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-01.png\" alt=\"\u56f31.\u6700\u8fd1\u306emenuPass\u306e\u6d3b\u52d5\u3068\u53e4\u3044\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068\u306e\u3044\u304f\u3064\u304b\u306e\u95a2\u4fc2\" width=\"973\" height=\"317\" \/><figcaption class=\"wp-caption-text\">\u56f31.\u6700\u8fd1\u306emenuPass\u306e\u6d3b\u52d5\u3068\u53e4\u3044\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068\u306e\u3044\u304f\u3064\u304b\u306e\u95a2\u4fc2<\/figcaption><\/figure>\n<p>\u3053\u308c\u3089\u306e\u653b\u6483\u306b\u304a\u3051\u308bC2\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306f\u3001\u5927\u534a\u304c\u653b\u6483\u8005\u306b\u3088\u3063\u3066\u767b\u9332\u3055\u308c\u305f\u3082\u306e\u3067\u3001\u3054\u304f\u5c11\u6570\u306e\u307f\u304cDynamic Domain Name System (\u30c0\u30a4\u30ca\u30df\u30c3\u30af\u30c9\u30e1\u30a4\u30f3\u30cd\u30fc\u30e0\u30b7\u30b9\u30c6\u30e0 - DDNS)\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u4f7f\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u4e00\u822c\u7684\u306b\u3001\u653b\u6483\u6d3b\u52d5\u306b\u304a\u3044\u3066menuPass\u306fDDNS\u3068\u653b\u6483\u8005\u304c\u767b\u9332\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u3092\u6298\u308a\u6df7\u305c\u3066\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u95a2\u9023\u3059\u308b\u30cf\u30c3\u30b7\u30e5\u304a\u3088\u3073C2\u306f\u3001\u3053\u306e\u30d6\u30ed\u30b0\u8a18\u4e8b\u306e\u53c2\u8003\u60c5\u5831\u306b\u8a18\u8f09\u3057\u307e\u3057\u305f\u3002<\/p>\n<h3>menuPass\u3068ChChes\u3068\u306e\u95a2\u4fc2\u6027<\/h3>\n<p>menuPass (\u5225\u540d\u306f<a href=\"https:\/\/www.slideshare.net\/CrowdStrike\/crowd-casts-monthly-you-have-an-adversary-problem\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">Stone Panda<\/a>\u304a\u3088\u3073APT10)\u3068\u547c\u3070\u308c\u308bAPT\u653b\u6483\uff08\u6301\u7d9a\u578b\u306e\u6a19\u7684\u578b\u653b\u6483\uff09\u306b\u95a2\u3059\u308b\u516c\u306e\u60c5\u5831\u306f\u305d\u308c\u307b\u3069\u3042\u308a\u307e\u305b\u3093\u30022013\u5e74\u306bFireEye\u304c\u516c\u8868\u3057\u305f\u30ec\u30dd\u30fc\u30c8\u306b\u3001<a href=\"https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/rpt-poison-ivy.pdf\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">PIVY\u3092\u4f7f\u3063\u305f\u653b\u6483\u6d3b\u52d5\u306e\u3072\u3068\u3064\u3068\u3057\u3066menuPass\u3092\u305d\u3046\u3057\u305f\u653b\u6483\u6d3b\u52d5\u306e\u3072\u3068\u3064\u3068\u3057\u3066\u6319\u3052\u3066\u3044\u307e\u3057\u305f<\/a>\u3002\u305d\u306e\u5f8c\u306e<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2014\/03\/a-detailed-examination-of-the-siesta-campaign.html\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">\u30d6\u30ed\u30b0\u8a18\u4e8b<\/a>\u306b\u3082\u3001\u65b0\u305f\u306a\u8a73\u7d30\u60c5\u5831\u304c\u3044\u304f\u3064\u304b\u52a0\u3048\u3089\u308c\u307e\u3057\u305f\u3002menuPass\u3068\u3044\u3046\u30b0\u30eb\u30fc\u30d7\u540d\u306f\u3001\u653b\u6483\u306b\u304a\u3051\u308bPIVY\u7528\u306b\u4f7f\u3063\u305f\u30d1\u30b9\u30ef\u30fc\u30c9\u306e1\u3064\u306b\u7531\u6765\u3057\u3066\u3044\u307e\u3059\u3002menuPass\u306f2009\u5e74\u306b\u6d3b\u52d5\u3092\u958b\u59cb\u3057\u3001<a href=\"https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/rpt-poison-ivy.pdf\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section: \">\u4e2d\u56fd\u3067\u751f\u307e\u308c\u305f<\/a>\u3068\u8003\u3048\u3089\u308c\u3066\u3044\u308b\u305f\u3081\u3001\u5f53\u521d\u7c73\u56fd\u3084\u6d77\u5916\u306e\u9632\u885b\u95a2\u9023\u4f01\u696d\u3092\u6a19\u7684\u306b\u3057\u3066\u3044\u308b\u3053\u3068\u3067\u77e5\u3089\u308c\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u6642\u304c\u7d4c\u3064\u306b\u3064\u308c\u6a19\u7684\u3092\u62e1\u3052\u3066\u3044\u304d\u307e\u3057\u305f\u3002\u305d\u3057\u3066\u9045\u304f\u3068\u30822014\u5e74\u304b\u3089\u3001\u65e5\u672c\u306e\u7d44\u7e54\u3092\u6a19\u7684\u306b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u65b0\u3057\u3044ChChes\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306f\u30a4\u30f3\u30dd\u30fc\u30c8\u30cf\u30c3\u30b7\u30e5(bb269704ba8647da97377440d403ae4d)\u3092\u4f7f\u3063\u3066\u304a\u308a\u3001\u3053\u306e\u30cf\u30c3\u30b7\u30e5\u3092\u3001menuPass\u304c\u5229\u7528\u3059\u308b\u4ed6\u306e\u30c4\u30fc\u30eb\u3068\u5171\u6709\u3057\u3066\u3044\u307e\u3059\u3002\u305d\u3057\u3066\u3001\u30a4\u30f3\u30dd\u30fc\u30c8\u30cf\u30c3\u30b7\u30e5\u306f\u6700\u521d\u306e\u30ea\u30f3\u30af\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u4e00\u65b9\u3001\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u5206\u6790\u3092\u901a\u3057\u3066\u3001menuPass\u3068\u306e\u95a2\u4fc2\u304c\u6700\u3082\u5f37\u304f\u7acb\u8a3c\u3055\u308c\u307e\u3057\u305f\u3002\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u5206\u6790\u304b\u3089\u3001\u3053\u308c\u3089\u306e\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305f\u65b0\u3057\u3044\u65b9\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u95a2\u9023\u304c\u516c\u306b\u306a\u3063\u3066\u3044\u308b\u5f93\u6765\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068\u306e\u9593\u306b\u3001\u591a\u6570\u306e\u30ea\u30f3\u30af\u304c\u3042\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u56f32\u306b\u3066\u4e38\u3067\u56f2\u3093\u30603\u3064\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u3001menuPass\u3068\u306e\u95a2\u9023\u6027\u304c\u3042\u308b\u3068\u516c\u5f0f\u306b\u5831\u544a\u3055\u308c\u3066\u3044\u308bC2\u3067\u3042\u308a\u3001\u516c\u5f0f\u306b\u95a2\u4fc2\u6027\u304c\u6307\u6458\u3055\u308c\u3066\u3044\u306a\u3044\u30c9\u30e1\u30a4\u30f3\u3068\u30ea\u30f3\u30af\u4ed8\u3051\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306f\u3001Unit 42\u306e\u30a2\u30ca\u30ea\u30b9\u30c8\u304cmenuPass\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3092\u30ea\u30b5\u30fc\u30c1\u3057\u3066\u3044\u308b\u4e2d\u3067\u767a\u898b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u305f\u3001\u3054\u304f\u308f\u305a\u304b\u306a\u8907\u6570\u306e\u5171\u901a\u90e8\u5206\u3067\u3059\u3002\u4e38\u3067\u56f2\u3093\u3060\u65e2\u77e5\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u4ee5\u4e0b\u306e\u3046\u3061\u306e\u6700\u521d\u306e3\u3064\u3067\u3059\u3002<\/p>\n<ul>\n<li>apple[.]cmdnetview[.]com<\/li>\n<li>fbi[.]sexxxy[.]biz<\/li>\n<li>cvnx[.]zyns[.]com<\/li>\n<li>cia[.]toh[.]info<\/li>\n<li>2014[.]zzux[.]com<\/li>\n<li>iphone[.]vizvaz[.]com<\/li>\n<\/ul>\n<figure style=\"width: 969px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-02.png\" alt=\"\u56f32. menuPass\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u5171\u901a\u90e8\u5206\" width=\"969\" height=\"344\" \/><figcaption class=\"wp-caption-text\">\u56f32. menuPass\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u5171\u901a\u90e8\u5206<\/figcaption><\/figure>\n<p>\u3055\u3089\u306b\u3001\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u306e\u3046\u30612\u3064\u306f\u3001\u65b0\u3057\u3044\u65b9\u306eC2\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068\u95a2\u9023\u4ed8\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u3084\u306f\u308a\u3053\u308c\u3089\u3082\u3001menuPass\u304c\u4f7f\u3063\u3066\u3044\u308b\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3092\u5206\u6790\u3059\u308b\u3053\u3068\u3067\u660e\u3089\u304b\u306b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u305f\u3001\u3054\u304f\u308f\u305a\u304b\u306a\u5171\u901a\u90e8\u5206\u3067\u3059\u3002\u4e0b\u306e\u56f3\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li>cia[.]toh[.]info<\/li>\n<li>2014[.]zzux[.]com<\/li>\n<li>wchildress[.]com<\/li>\n<li>lion[.]wchildress[.]com<\/li>\n<li>kawasaki[.]unham[.]com<\/li>\n<li>sakai[.]unhamj[.]com<\/li>\n<li>kawasaki[.]cloud-maste[.]com<\/li>\n<li>fukuoka[.]cloud-maste[.]com<\/li>\n<li>yahoo[.]incloud-go[.]com<\/li>\n<li>msn[.]incloud-go[.]com<\/li>\n<li>www[.]mseupdate[.]ourhobby[.]com<\/li>\n<li>contractus[.]qpoe[.]com<\/li>\n<\/ul>\n<figure style=\"width: 973px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-03.png\" alt=\"\u56f33.\u65b0\u65e7\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u9593\u306e\u95a2\u4fc2\" width=\"973\" height=\"346\" \/><figcaption class=\"wp-caption-text\">\u56f33.\u65b0\u65e7\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u9593\u306e\u95a2\u4fc2<\/figcaption><\/figure>\n<p>\u3053\u306e\u307b\u304b\u3001PIVY\u30b5\u30f3\u30d7\u30eb\u306e\u30d1\u30b9\u30ef\u30fc\u30c9\u3082\u3001\u30b0\u30eb\u30fc\u30d7\u304c\u4f7f\u3063\u3066\u3044\u308b\u65e2\u77e5\u306e\u30d1\u30b9\u30ef\u30fc\u30c9\u306b\u5f53\u3066\u306f\u307e\u308a\u307e\u3059\u3002\u3059\u306a\u308f\u3061\u30013\u500b\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u201cmenuPass\u201d\u3092\u4f7f\u3044\u3001\u305d\u308c\u4ee5\u5916\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u201ckeaidestone\u201d\u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u3046\u3057\u305f\u30c7\u30fc\u30bf\u3092\u3082\u3068\u306b\u3001Unit 42\u306f\u3001\u6700\u8fd1\u306e\u653b\u6483\u304cmenuPass\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u3063\u3066\u884c\u308f\u308c\u305f\u3068\u5f37\u304f\u78ba\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3>\u30de\u30eb\u30a6\u30a7\u30a2\u5206\u6790<\/h3>\n<p>ChChes\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u306e\u5206\u6790\u7d50\u679c\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002\u3053\u306e\u5206\u6790\u7528\u306b\u3001Unit 42\u306f\u4ee5\u4e0b\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u8abf\u67fb\u3057\u307e\u3057\u305f\u3002<\/p>\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td width=\"77\"><b>MD5<\/b><\/td>\n<td width=\"391\">c0c8dcc9dad39da8278bf8956e30a3fc<\/td>\n<\/tr>\n<tr>\n<td width=\"77\"><b>SHA1<\/b><\/td>\n<td width=\"391\">009b639441ad5c1260f55afde2d5d21fc5b4f96c<\/td>\n<\/tr>\n<tr>\n<td width=\"77\"><b>SHA256<\/b><\/td>\n<td width=\"391\">6605b27e95f5c3c8012e4a75d1861786fb749b9a712a5f4871adbad81addb59e<\/td>\n<\/tr>\n<tr>\n<td width=\"77\"><b>\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b<\/b><\/td>\n<td width=\"391\">2016-11-24 01:31:37 UTC<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u56f34\u306e\u753b\u50cf\u306e\u3088\u3046\u306aMicrosoft Word\u306e\u3088\u3046\u306b\u898b\u3048\u308b\u30a2\u30a4\u30b3\u30f3\u306b\u3088\u3063\u3066\u914d\u5e03\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure style=\"width: 190px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-04.png\" alt=\"\u56f34.ChChes\u7528\u306b\u4f7f\u308f\u308c\u3066\u3044\u308b\u30a2\u30a4\u30b3\u30f3\" width=\"190\" height=\"333\" \/><figcaption class=\"wp-caption-text\">\u56f34.ChChes\u7528\u306b\u4f7f\u308f\u308c\u3066\u3044\u308b\u30a2\u30a4\u30b3\u30f3<\/figcaption><\/figure>\n<p>\u65e5\u672c\u306e\u7d44\u7e54\u3078\u306e\u653b\u6483\u3067\u7279\u5b9a\u3055\u308c\u305f\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u30a4\u30bf\u30ea\u30a2\u4f01\u696dHackingTeam\u304c\u5143\u3005\u4f7f\u3063\u3066\u3044\u305f\u8a3c\u660e\u66f8\u3092\u4f7f\u3063\u3066\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3057\u305f\u3002\u8aad\u8005\u306e\u4e2d\u306b\u306f\u3001HackingTeam\u304c2015\u5e747\u6708\u306b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4fb5\u5bb3\u3092\u53d7\u3051\u3001\u305d\u306e\u5f8c\u3001\u5927\u91cf\u306e\u5185\u90e8\u30c7\u30fc\u30bf\u304c\u6f0f\u6d29\u3057\u305f\u3053\u3068\u3092\u601d\u3044\u51fa\u3059\u65b9\u3082\u3044\u308b\u3067\u3057\u3087\u3046\u3002\u6f0f\u6d29\u3057\u305f\u30c7\u30fc\u30bf\u306b\u306f\u3001\u3053\u306e\u4f01\u696d\u304c\u4f7f\u7528\u3057\u3066\u3044\u305f\u5927\u91cf\u306e\u30b3\u30fc\u30c9\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u305d\u306e\u4e2d\u306b\u8a3c\u660e\u66f8\u3082\u3042\u308a\u307e\u3057\u305f\u3002\u4eca\u56de\u4f7f\u308f\u308c\u305f\u8a3c\u660e\u66f8\u306f\u6975\u3081\u3066\u53e4\u304f\u30012012\u5e748\u67084\u65e5\u306b\u6709\u52b9\u671f\u9650\u304c\u5207\u308c\u3066\u3044\u307e\u3057\u305f\u30022015\u5e747\u670810\u65e5\u306b\u306f\u5931\u52b9\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-05.png\" alt=\"\u56f35. ChChes\u306e\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\" width=\"975\" height=\"771\" \/><figcaption class=\"wp-caption-text\">\u56f35. ChChes\u306e\u30c7\u30b8\u30bf\u30eb\u7f72\u540d<\/figcaption><\/figure>\n<figure style=\"width: 854px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-06.png\" alt=\"\u56f36. \u8a3c\u660e\u66f8\u306e\u5931\u52b9\" width=\"854\" height=\"1073\" \/><figcaption class=\"wp-caption-text\">\u56f36. \u8a3c\u660e\u66f8\u306e\u5931\u52b9<\/figcaption><\/figure>\n<p>HackingTeam\u306e\u8a3c\u660e\u66f8\u304c2015\u5e74\u306b\u6f0f\u3048\u3044\u3057\u3066\u4ee5\u6765\u3001\u8907\u6570\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3053\u306e\u8a3c\u660e\u66f8\u304c\u4f7f\u308f\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002menuPass\u304c\u3001\u65e2\u77e5\u306e\u60aa\u610f\u3042\u308b\u30b5\u30f3\u30d7\u30eb\u3068\u95a2\u4fc2\u306e\u3042\u308b\u3053\u306e\u8a3c\u660e\u66f8\u3092\u81ea\u5206\u305f\u3061\u306e\u30b5\u30f3\u30d7\u30eb\u7528\u306b\u4f7f\u7528\u3057\u305f\u7406\u7531\u306f\u308f\u304b\u308a\u307e\u305b\u3093\u30021\u3064\u306e\u53ef\u80fd\u6027\u3068\u3057\u3066\u3001\u300c\u3053\u308c\u3089\u306e\u8105\u5a01\u3092\u30ea\u30b5\u30fc\u30c1\u3057\u3066\u3044\u308b\u30a2\u30ca\u30ea\u30b9\u30c8\u304b\u3089\u898b\u3066\u653b\u6483\u8005\u306e\u7279\u5b9a\u304c\u3055\u3089\u306b\u56f0\u96e3\u306b\u306a\u308b\u306e\u3092\u72d9\u3063\u305f\u300d\u3068\u3044\u3046\u3053\u3068\u304c\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u6700\u521d\u306b\u5b9f\u884c\u3055\u308c\u305f\u3068\u304d\u306b\u3001\u4e2d\u306b\u57cb\u3081\u8fbc\u307e\u308c\u305f\u30b3\u30fc\u30c9\u306e\u30b9\u30bf\u30d6\u3092\u5fa9\u53f7\u5316\u3057\u3066\u304b\u3089\u3001\u305d\u308c\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u3053\u306e\u30b9\u30bf\u30d6\u306f\u3001\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u306b\u591a\u6570\u306e\u7279\u5fb4\u304c\u898b\u3089\u308c\u3001\u65b0\u3057\u3044\u30a4\u30f3\u30dd\u30fc\u30c8 \u30a2\u30c9\u30ec\u30b9 \u30c6\u30fc\u30d6\u30eb(IAT)\u3092\u4f5c\u6210\u3059\u308b\u3053\u3068\u304b\u3089\u958b\u59cb\u3057\u307e\u3059\u3002\u3053\u306e\u65b0\u3057\u3044IAT\u306f\u3001\u30b3\u30fc\u30c9\u306e\u6b8b\u308a\u90e8\u5206\u3092\u901a\u3058\u3066\u3001Windows API\u3092\u547c\u3073\u51fa\u3057\u305f\u3068\u304d\u306b\u53c2\u7167\u3055\u308c\u307e\u3059\u3002\u4ee5\u4e0b\u306e\u30a2\u30bb\u30f3\u30d6\u30ea\u306e\u30b9\u30cb\u30da\u30c3\u30c8\u306f\u3001GetProcessHeap\u3001RtlAllocateHeap\u3001RtlReAllocateHeap\u3001InternetReadFile\u306a\u3069\u306e\u3055\u307e\u3056\u307e\u306a\u95a2\u6570\u3092\u547c\u3073\u51fa\u3059\u305f\u3081\u306b\u53c2\u7167\u3055\u308c\u3066\u3044\u308b\u65b0\u305f\u306b\u4f5c\u6210\u3055\u308c\u305fIAT\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure style=\"width: 973px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-07.png\" alt=\"\u56f37 Windows API\u95a2\u6570\u3092\u547c\u3073\u51fa\u3059\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u65b0\u305f\u306b\u4f5c\u6210\u3055\u308c\u305fIAT\" width=\"973\" height=\"1106\" \/><figcaption class=\"wp-caption-text\">\u56f37 Windows API\u95a2\u6570\u3092\u547c\u3073\u51fa\u3059\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u65b0\u305f\u306b\u4f5c\u6210\u3055\u308c\u305fIAT<\/figcaption><\/figure>\n<p>IAT\u3092\u751f\u6210\u3057\u305f\u5f8c\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f%TEMP%\u306e\u30d1\u30b9\u3092\u5224\u5225\u3057\u3001\u73fe\u5728\u306e\u4f5c\u696d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u3053\u306e\u5024\u306b\u8a2d\u5b9a\u3057\u307e\u3059\u3002ChChes\u306f\u3001\u88ab\u5bb3\u8005\u306b\u95a2\u3059\u308b\u4ee5\u4e0b\u306e\u60c5\u5831\u306e\u53ce\u96c6\u306b\u9032\u307f\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30db\u30b9\u30c8\u540d<\/li>\n<li>\u30d7\u30ed\u30bb\u30b9ID (PID)<\/li>\n<li>\u73fe\u5728\u306e\u4f5c\u696d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea(%TEMP%)<\/li>\n<li>\u30a6\u30a3\u30f3\u30c9\u30a6\u306e\u89e3\u50cf\u5ea6<\/li>\n<li>Microsoft Windows\u306e\u30d0\u30fc\u30b8\u30e7\u30f3<\/li>\n<\/ul>\n<p>\u3053\u306e\u60c5\u5831\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u6587\u5b57\u5217\u306b\u96c6\u7d04\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>WBQTLJRH9553618*2564?3618468394?C:\\\\Users\\\\ADMINI~1\\\\AppData\\\\Local\\\\Temp?1.4.1 (1024\u00d7768)*6.1.7601.17514<\/p>\n<p>\u4e0a\u8a18\u306e\u6587\u5b57\u5217\u3067\u3001\u6587\u5b57\u5217\u20183618468394\u2019\u304a\u3088\u3073\u20181.4.1\u2019\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u81ea\u4f53\u306b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u5316\u3055\u308c\u3066\u3044\u308b\u70b9\u306b\u6ce8\u610f\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u3053\u308c\u3089\u306f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u307e\u305f\u306f\u653b\u6483\u6d3b\u52d5\u306eID\u3092\u793a\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<p>\u3053\u306e\u30c7\u30fc\u30bf\u306f\u96c6\u7d04\u3055\u308c\u305f\u5f8c\u3001HTTP\u3092\u4ecb\u3057\u3066\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u5316\u3055\u308c\u305fC2\u30b5\u30fc\u30d0\u30fc\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002\u30c7\u30fc\u30bf\u306f\u3001\u4ee5\u4e0b\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u2018Cookie\u2019 HTTP\u30d8\u30c3\u30c0\u30fc\u306b\u57cb\u3081\u8fbc\u307e\u308c\u307e\u3059\u3002<\/p>\n<figure style=\"width: 973px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-08.png\" alt=\"\u56f38 ChChes\u306e\u521d\u671fHTTP\u30d3\u30fc\u30b3\u30f3\" width=\"973\" height=\"388\" \/><figcaption class=\"wp-caption-text\">\u56f38 ChChes\u306e\u521d\u671fHTTP\u30d3\u30fc\u30b3\u30f3<\/figcaption><\/figure>\n<p>\u4e0a\u8a18\u3067\u4f7f\u7528\u3055\u308c\u305fURI\u306f\u3001ChChes\u306b\u3088\u3063\u3066HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u4f5c\u6210\u3055\u308c\u308b\u305f\u3073\u306b\u30e9\u30f3\u30c0\u30e0\u306b\u751f\u6210\u3055\u308c\u307e\u3059\u3002Cookie\u30d8\u30c3\u30c0\u30fc\u306b\u57cb\u3081\u8fbc\u307e\u308c\u305f\u30c7\u30fc\u30bf\u306f\u72ec\u81ea\u306e\u624b\u6cd5\u3092\u4f7f\u3063\u3066\u6697\u53f7\u5316\u3055\u308c\u307e\u3059\u3002\u30ad\u30fc\/\u5024\u30da\u30a2\u3054\u3068\u306b\u2018;\u2019\u3067\u533a\u5207\u3089\u308c\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u6700\u521d\u306b\u30ad\u30fc\u306eMD5\u30cf\u30c3\u30b7\u30e5\u3092\u5b9f\u884c\u3057\u3001\u4e2d\u9593\u306e16\u30d0\u30a4\u30c8\u3092\u62bd\u51fa\u3057\u307e\u3059\u3002\u5024\u306f\u3001\u6587\u5b57\u5217\u306e\u5f15\u7528\u7b26\u3092\u5916\u3057\u305f\u5f8c\u306b\u3001base64\u3067\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002\u6700\u5f8c\u306b\u3001base64\u3067\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306f\u3001\u4ee5\u524d\u306b\u53d6\u5f97\u3057\u305f16\u30d0\u30a4\u30c8\u3068\u3068\u3082\u306bRC4\u3092\u4f7f\u7528\u3057\u3066\u3001\u5fa9\u53f7\u5316\u3055\u308c\u307e\u3059\u3002\u30c7\u30fc\u30bf\u306f\u3059\u3079\u3066\u7d50\u5408\u3055\u308c\u3001\u6700\u7d42\u7684\u306a\u5fa9\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u5f62\u6210\u3057\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306ePython\u30b3\u30fc\u30c9\u306f\u3001\u63d0\u4f9b\u3055\u308c\u305fCookie\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u30c7\u30b3\u30fc\u30c9\u3059\u308b\u4f8b\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-09.png\" \/><\/p>\n<p>\u4e0a\u8a18\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u4ee5\u4e0b\u306e\u51fa\u529b\u3092\u751f\u6210\u3057\u307e\u3059\u3002<\/p>\n<p><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-10.png\" \/><\/p>\n<p>\u4e0a\u8a18\u306e\u51fa\u529b\u306b\u898b\u3089\u308c\u308b\u6700\u521d\u306e\u2018A\u2019\u6587\u5b57\u306f\u3001\u3053\u308c\u304c\u521d\u671f\u30d3\u30fc\u30b3\u30f3\u3067\u3042\u308b\u3053\u3068\u3001\u307e\u305f\u306f\u6700\u521d\u306b\u4e88\u671f\u3055\u308c\u305fChChes\u306b\u3088\u3063\u3066\u9001\u4fe1\u3055\u308c\u308b\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u3042\u308b\u3053\u3068\u3092\u30ea\u30e2\u30fc\u30c8 \u30b5\u30fc\u30d0\u30fc\u306b\u77e5\u3089\u305b\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>C2\u306f\u3001\u30db\u30b9\u30c8\u540d\u3068PID\u306b\u5bfe\u3057\u3066\u5b9f\u884c\u3055\u308c\u305fMD5\u30cf\u30c3\u30b7\u30e5\u306e\u4e2d\u959316\u30d0\u30a4\u30c8\u3092\u542b\u3080\u2018Set-Cookie\u2019\u30d8\u30c3\u30c0\u30fc\u3067\u5fdc\u7b54\u3057\u307e\u3059\u3002\u4e0a\u8a18\u306e\u4f8b\u3092\u4f7f\u7528\u3059\u308b\u3068\u3001C2\u306f\u2018WBQTLJRH9553618*2564\u2019\u306b\u5bfe\u3057\u3066MD5\u3092\u5b9f\u884c\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-11.png\" \/><\/p>\n<p>\u7d50\u679c\u306e\u4e2d\u9593\u306e16\u6587\u5b57\u306f\u3001\u2018b331106210b6364c\u2019\u3067\u3059\u3002<\/p>\n<p>ChChes\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u305f\u305d\u308c\u4ee5\u964d\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<figure style=\"width: 973px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-12.png\" alt=\"\u56f39 ChChes\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u305f2\u756a\u76ee\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30ea\u30af\u30a8\u30b9\u30c8\" width=\"973\" height=\"165\" \/><figcaption class=\"wp-caption-text\">\u56f39 ChChes\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u305f2\u756a\u76ee\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30ea\u30af\u30a8\u30b9\u30c8<\/figcaption><\/figure>\n<p>\u5fa9\u53f7\u5316\u3059\u308b\u3068\u3001Cookie\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u4fdd\u5b58\u3055\u308c\u305f\u4ee5\u4e0b\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>Bb331106210b6364c<\/p>\n<p>\u6700\u521d\u306e\u6587\u5b57\u2018B\u2019\u306f\u3001\u3053\u308c\u304c2\u756a\u76ee\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u304a\u308a\u3001\u6b8b\u308a\u306e\u30c7\u30fc\u30bf\u306fC2\u30ec\u30b9\u30dd\u30f3\u30b9\u3067\u4ee5\u524d\u306b\u76ee\u306b\u3057\u305fSet-Cookie\u30d8\u30c3\u30c0\u30fc\u5185\u306e16\u30d0\u30a4\u30c8\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e\u6bb5\u968e\u3067\u306f\u3001C2\u30b5\u30fc\u30d0\u30fc\u306f\u3001\u4ee5\u4e0b\u306e\u5f62\u5f0f\u3067\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u8fd4\u3059\u3082\u306e\u3068\u4e88\u671f\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>[Middle MD5][Base64-Encoded Data][Middle MD5]<\/p>\n<p>\u2018Middle MD5\u2019\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u306f\u3001\u2018b331106210b6364c\u2019\u6587\u5b57\u5217\u306b\u5bfe\u3059\u308bMD5\u30cf\u30c3\u30b7\u30e5\u306e\u4e2d\u9593\u306e16\u30d0\u30a4\u30c8\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u3053\u306e\u7279\u5b9a\u306e\u4f8b\u3067\u306f\u3001\u7d50\u679c\u3068\u3057\u3066\u6587\u5b57\u5217\u2018500089dadf52ae0b\u2019\u306b\u306a\u308a\u307e\u3059\u3002\u2018Base64-Encoded Data\u2019\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u306f\u3001\u304b\u306a\u308a\u8907\u96d1\u306a\u69cb\u9020\u304c\u542b\u307e\u308c\u3001\u305d\u308c\u306b\u306fChChes\u306b\u3088\u3063\u3066\u30ed\u30fc\u30c9\u3055\u308c\u3001\u305d\u306e\u5f8c\u5b9f\u884c\u3055\u308c\u308b\u30e2\u30b8\u30e5\u30fc\u30eb\u304c\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u901a\u4fe1\u3092\u8996\u899a\u5316\u3059\u308b\u3068\u3001\u4ee5\u4e0b\u306e\u56f3\u306b\u793a\u3059\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<figure style=\"width: 496px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/81331\/jp-menu-pass-returns-new-malware-new-attacks-against-japanese-ac-13.png\" alt=\"\u56f310 ChChes\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30d5\u30ed\u30fc\" width=\"496\" height=\"473\" \/><figcaption class=\"wp-caption-text\">\u56f310 ChChes\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30d5\u30ed\u30fc<\/figcaption><\/figure>\n<p>ChChes\u306f\u3001\u88ab\u5bb3\u8005\u306e\u30de\u30b7\u30f3\u306e\u521d\u671f\u6f5c\u5165\u30dd\u30a4\u30f3\u30c8\u3068\u3057\u3066\u52d5\u4f5c\u3057\u307e\u3059\u3002\u8ffd\u52a0\u306e\u30b3\u30fc\u30c9\u3092\u30ed\u30fc\u30c9\u3057\u3001\u305d\u306e\u5f8c\u3001\u591a\u6570\u306e\u30bf\u30b9\u30af\u3092\u9042\u884c\u3059\u308b\u6a5f\u80fd\u3092\u5099\u3048\u3066\u3044\u307e\u3059\u3002\u5206\u6790\u6642\u306b\u306f\u3001\u30a2\u30af\u30c6\u30a3\u30d6\u306aC2\u30b5\u30fc\u30d0\u30fc\u306f\u898b\u3064\u304b\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002Unit 42\u306f\u3001ChChes\u306b\u3088\u3063\u3066\u30ed\u30fc\u30c9\u3055\u308c\u308b\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u7279\u5b9a\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001JPCERT\u304c\u6700\u8fd1\u3053\u306e\u30d5\u30a1\u30df\u30ea\u3092\u5206\u6790\u3057\u3001ChChes\u306b\u6a5f\u80fd\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u53ce\u96c6\u3057\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li>AES\u306b\u3088\u308b\u901a\u4fe1\u306e\u6697\u53f7\u5316<\/li>\n<li>\u30b7\u30a7\u30eb \u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c<\/li>\n<li>\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3068\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9<\/li>\n<li>DLL\u306e\u30ed\u30fc\u30c9\u3068\u5b9f\u884c<\/li>\n<li>\u30dc\u30c3\u30c8 \u30b3\u30de\u30f3\u30c9\u306e\u30bf\u30b9\u30af \u30ea\u30b9\u30c8<\/li>\n<\/ul>\n<p>\u73fe\u72b6\u3067\u306f\u3001ChChes\u306b\u6301\u7d9a\u6027\u306e\u3042\u308b\u6a5f\u80fd\u304c\u7d44\u307f\u8fbc\u307e\u308c\u3066\u3044\u306a\u3044\u70b9\u306f\u3001\u88ab\u5bb3\u8005\u306e\u30de\u30b7\u30f3\u3067\u9577\u671f\u9593\u5b9f\u884c\u3059\u308b\u610f\u56f3\u304c\u306a\u3044\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002\u4fb5\u5165\u3092\u6210\u529f\u3055\u305b\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306e\u8db3\u5834\u3068\u3057\u3066\u6b63\u3057\u3044\u65b9\u5411\u306b\u5411\u304b\u3046\u305f\u3081\u306b\u3001\u653b\u6483\u8005\u304c\u4f7f\u7528\u3059\u308b\u7b2c1\u6bb5\u968e\u306e\u30c4\u30fc\u30eb\u306b\u904e\u304e\u306a\u3044\u306e\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002\u653b\u6483\u8005\u304c\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u3092\u79fb\u52d5\u3059\u308b\u306b\u3064\u308c\u3001\u4ed6\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u6301\u7d9a\u6027\u3068\u8ffd\u52a0\u306e\u30a2\u30af\u30bb\u30b9\u306e\u6a5f\u80fd\u3092\u6301\u3063\u305f\u7b2c2\u6bb5\u968e\u306e\u30ec\u30a4\u30e4\u30fc\u3068\u3057\u3066\u5c0e\u5165\u3055\u308c\u308b\u306e\u3067\u3057\u3087\u3046\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3001\u4f9d\u7136\u3068\u3057\u3066\u65e5\u672c\u304cAPT\u653b\u6483\u6d3b\u52d5\u306b\u3068\u3063\u3066\u95a2\u5fc3\u306e\u9ad8\u3044\u6a19\u7684\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002menuPass\u306f\u9045\u304f\u3068\u30822014\u5e74\u4ee5\u964d\u304b\u3089\u65e5\u672c\u306e\u500b\u4eba\u3068\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3001\u540c\u3058\u7d44\u7e54\u3068\u6559\u80b2\u6a5f\u95a2\u3092\u4e3b\u306a\u6a19\u7684\u3068\u3057\u6bce\u6708\u653b\u6483\u3092\u884c\u3063\u3066\u304d\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001menuPass\u304c\u3053\u308c\u3089\u306e\u6a19\u7684\u3092\u4fb5\u5bb3\u3059\u308b\u8a66\u307f\u306b\u7d42\u59cb\u3057\u3066\u3044\u308b\u3053\u3068\u3082\u660e\u3089\u304b\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u307e\u305fmenuPass\u306f\u4e3b\u306b\u60c5\u5831\u5165\u624b\u306e\u305f\u3081\u306b\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3092\u4ed5\u639b\u3051\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u4e8b\u5b9f\u3068\u3001\u653b\u6483\u306e\u6301\u7d9a\u6027\u304b\u3089\u3001\u6a19\u7684\u3068\u306a\u308a\u3046\u308b\u500b\u4eba\u3068\u7d44\u7e54\u306e\u4e21\u65b9\u304c\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306b\u3064\u3044\u3066\u30c8\u30ec\u30fc\u30cb\u30f3\u30b0\u3092\u53d7\u3051\u3001\u8a8d\u8b58\u3092\u6df1\u3081\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002menuPass\u306f\u3001\u5e83\u7bc4\u306b\u7d99\u7d9a\u3055\u308c\u3066\u3044\u308bAPT\u653b\u6483\u6d3b\u52d5\u3067\u3001\u4eca\u5f8c\u3082\u5f15\u304d\u7d9a\u304d\u65e5\u672c\u3092\u6a19\u7684\u3068\u3057\u3066\u304f\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>Palo Alto Networks\u306e\u304a\u5ba2\u69d8\u306f\u3001\u3053\u308c\u3089\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u3068C2\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u304b\u3089\u4ee5\u4e0b\u306b\u3088\u3063\u3066\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u3059\u3079\u3066\u306eC2\u30c9\u30e1\u30a4\u30f3\u306f\u3001Threat Prevention\uff08\u8105\u5a01\u9632\u5fa1\uff09\u6a5f\u80fd\u3068PAN-DB\u3067\u60aa\u610f\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u30d5\u30e9\u30b0\u4ed8\u3051\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li>\u3059\u3079\u3066\u306e\u3053\u308c\u3089\u306e\u30d5\u30a1\u30df\u30ea\u306f\u3001\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30c8\u30af\u30e9\u30a6\u30c9\u300cWildFire\u300d\u306b\u3088\u3063\u3066\u9069\u5207\u306b\u30bf\u30b0\u4ed8\u3051\u3055\u308c\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3059\u3002\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30c8\u30b5\u30fc\u30d3\u30b9\u300cAutofocus\u300d\u306e\u5229\u7528\u8005\u306f\u3001\u8a72\u5f53\u3059\u308b\u30bf\u30b0\u3092\u4ecb\u3057\u3066\u5404\u30d5\u30a1\u30df\u30ea\u306e\u8a73\u7d30\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002\n<ul>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.ChChes\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section:\u7d50\u8ad6\">ChChes<\/a><\/li>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PoisonIvy\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section:\u7d50\u8ad6\">Poison Ivy<\/a><\/li>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PlugX\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section:\u7d50\u8ad6\">PlugX<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u3055\u3089\u306b\u3001Autofocus\u306e\u5229\u7528\u8005\u306f\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.menuPass\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-jp-menu-pass-returns-with-new-malware-new-attacks-against-japanese-ac: section:\u7d50\u8ad6\">menuPass<\/a>\u30bf\u30b0\u3067\u7d10\u4ed8\u3051\u3089\u308c\u305f\u6d3b\u52d5\u3092\u8abf\u3079\u308b\u3053\u3068\u3067\u3001\u8a73\u7d30\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n<h3>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4fb5\u5bb3\u306e\u75d5\u8de1<\/h3>\n<h4><b>SHA256\u30cf\u30c3\u30b7\u30e5<\/b><\/h4>\n<h5><b>ChChes<\/b><\/h5>\n<ul>\n<li>5961861d2b9f50d05055814e6bfd1c6291b30719f8a4d02d4cf80c2e87753fa1<\/li>\n<li>e90064884190b14a6621c18d1f9719a37b9e5f98506e28ff0636438e3282098b<\/li>\n<li>ae6b45a92384f6e43672e617c53a44225e2944d66c1ffb074694526386074145<\/li>\n<li>fd6a956a7708708cddff78c8505c7db73d7c4e961da8a3c00cc5a51171a92b7b<\/li>\n<li>2c71eb5c781daa43047fa6e3d85d51a061aa1dfa41feb338e0d4139a6dfd6910<\/li>\n<li>316e89d866d5c710530c2103f183d86c31e9a90d55e2ebc2dda94f112f3bdb6d<\/li>\n<li>efa0b414a831cbf724d1c67808b7483dec22a981ae670947793d114048f88057<\/li>\n<li>6605b27e95f5c3c8012e4a75d1861786fb749b9a712a5f4871adbad81addb59e<\/li>\n<li>fadf362a52dcf884f0d41ce3df9eaa9bb30227afda50c0e0657c096baff501f0<\/li>\n<li>2965c1b6ab9d1601752cb4aa26d64a444b0a535b1a190a70d5ce935be3f91699<\/li>\n<li>e88f5bf4be37e0dc90ba1a06a2d47faaeea9047fec07c17c2a76f9f7ab98acf0<\/li>\n<li>d26dae0d8e5c23ec35e8b9cf126cded45b8096fc07560ad1c06585357921eeed<\/li>\n<li>e6ecb146f469d243945ad8a5451ba1129c5b190f7d50c64580dbad4b8246f88e<\/li>\n<li>4521a74337a8b454f9b80c7d9e57b4c9580567f84e513d9a3ce763275c55e691<\/li>\n<li>bc2f07066c624663b0a6f71cb965009d4d9b480213de51809cdc454ca55f1a91<\/li>\n<li>c21eaadf9ffc62ca4673e27e06c16447f103c0cf7acd8db6ac5c8bd17805e39d<\/li>\n<li>f251485a62e104dfd8629dc4d2dfd572ebd0ab554602d682a28682876a47e773<\/li>\n<li>b20ce00a6864225f05de6407fac80ddb83cd0aec00ada438c1e354cdd0d7d5df<\/li>\n<li>c6b8ed157eed54958da73716f8db253ba5124a0e4b649f08de060c4aa6531afc<\/li>\n<li>9a6692690c03ec33c758cb5648be1ed886ff039e6b72f1c43b23fbd9c342ce8c<\/li>\n<li>cb0c8681a407a76f8c0fd2512197aafad8120aa62e5c871c29d1fd2a102bc628<\/li>\n<li>4cc0adf4baa1e3932d74282affb1a137b30820934ad4f80daceec712ba2bbe14<\/li>\n<li>312dc69dd6ea16842d6e58cd7fd98ba4d28eefeb4fd4c4d198fac4eee76f93c3<\/li>\n<li>45d804f35266b26bf63e3d616715fc593931e33aa07feba5ad6875609692efa2<\/li>\n<li>19aa5019f3c00211182b2a80dd9675721dac7cfb31d174436d3b8ec9f97d898b<\/li>\n<\/ul>\n<h5><b>PlugX<\/b><\/h5>\n<ul>\n<li>f1ca9998ca9078c27a6dab286dfe25fcdfb1ad734cc2af390bdcb97da1214563<\/li>\n<li>6392e0701a77ea25354b1f40f5b867a35c0142abde785a66b83c9c8d2c14c0c3<\/li>\n<li>6c7e85e426999579dd6a540fcd827b644a79cda0ad50211d585a0be513571586<\/li>\n<li>9f01dd2b19a1032e848619428dd46bfeb6772be2e78b33723d2fa076f1320c57<\/li>\n<li>6c7e85e426999579dd6a540fcd827b644a79cda0ad50211d585a0be513571586<\/li>\n<li>76721d08b83aae945aa00fe69319f896b92c456def4df5b203357cf443074c03<\/li>\n<li>dcff19fc193f1ba63c5dc6f91f00070e6912dcec3868e889fed37102698b554b<\/li>\n<li>7eeaa97d346bc3f8090e5b742f42e8900127703420295279ac7e04d06ebe0a04<\/li>\n<li>a6b6c66735e5e26002202b9d263bf8c97e278f6969c141853857000c8d242d24<\/li>\n<li>5412cddde0a2f2d78ec9de0f9a02ac2b22882543c9f15724ebe14b3a0bf8cbda<\/li>\n<li>92dbbe0eff3fe0082c3485b99e6a949d9c3747afa493a0a1e336829a7c1faafb<\/li>\n<\/ul>\n<h5><b>PIVY<\/b><\/h5>\n<ul>\n<li>f0002b912135bcee83f901715002514fdc89b5b8ed7585e07e482331e4a56c06<\/li>\n<li>412120355d9ac8c37b5623eea86d82925ca837c4f8be4aa24475415838ecb356<\/li>\n<li>44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce<\/li>\n<li>9edf191c6ca1e4eddc40c33e2a2edf104ce8dfff37b2a8b57b8224312ff008fe<\/li>\n<\/ul>\n<h5><b>C2s<\/b><\/h5>\n<ul>\n<li>dick[.]ccfchrist[.]com<\/li>\n<li>trout[.]belowto[.]com<\/li>\n<li>sakai[.]unhamj[.]com<\/li>\n<li>zebra[.]wthelpdesk[.]com<\/li>\n<li>area[.]wthelpdesk[.]com<\/li>\n<li>kawasaki[.]cloud-maste[.]com<\/li>\n<li>kawasaki[.]unhamj[.]com<\/li>\n<li>fukuoka[.]cloud-maste[.]com<\/li>\n<li>scorpion[.]poulsenv[.]com<\/li>\n<li>lion[.]wchildress[.]com<\/li>\n<li>fbi[.]sexxxy[.]biz<\/li>\n<li>cia[.]toh[.]info<\/li>\n<li>2014[.]zzux[.]com<\/li>\n<li>nttdata[.]otzo[.]com<\/li>\n<li>iphone[.]vizvaz[.]com<\/li>\n<li>app[.]lehigtapp[.]com<\/li>\n<li>jimin[.]jimindaddy[.]com<\/li>\n<li>Jepsen[.]r3u8[.]com<\/li>\n<li>inspgon[.]re26[.]com<\/li>\n<li>nunluck[.]re26[.]com<\/li>\n<li>yahoo[.]incloud-go[.]com<\/li>\n<li>msn[.]incloud-go[.]com<\/li>\n<li>www[.]mseupdate[.]ourhobby[.]com<\/li>\n<li>contractus[.]qpoe[.]com<\/li>\n<li>apple[.]cmdnetview[.]com<\/li>\n<li>cvnx[.]zyns[.]com<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit 42\u300d\u306f\u30012016\u5e74\u306e9\u6708\u304b\u308911\u6708\u306b\u304b\u3051\u3066\u3001\u300cmenuPass\u300d\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bAPT\u653b\u6483\uff08\u6301\u7d9a\u578b\u306e\u6a19\u7684\u578b\u653b\u6483\uff09\u304c\u3001\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005<\/p>\n","protected":false},"author":51,"featured_media":106755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[7453,7454,4651,4587,4783],"product_categories":[],"coauthors":[105,933],"class_list":["post-106783","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-menupass-ja","tag-pivy","tag-plugx-ja","tag-spear-phishing-ja","tag-trojan-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483<\/title>\n<meta name=\"description\" content=\"\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2017-02-16T19:00:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-27T02:00:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"650\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jen Miller-Osborn, Josh Grunzweig\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483","description":"\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/","og_locale":"ja_JP","og_type":"article","og_title":"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483","og_description":"\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/","og_site_name":"Unit 42","article_published_time":"2017-02-16T19:00:35+00:00","article_modified_time":"2020-04-27T02:00:05+00:00","og_image":[{"width":650,"height":300,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","type":"image\/jpeg"}],"author":"Jen Miller-Osborn, Josh Grunzweig","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/"},"author":{"name":"Jen Miller-Osborn","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/c5032b4c146b46d71669b248ad6e8142"},"headline":"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483","datePublished":"2017-02-16T19:00:35+00:00","dateModified":"2020-04-27T02:00:05+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/"},"wordCount":1048,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","keywords":["MenuPass","PIVY","PlugX","Spear Phishing","Trojan"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/","name":"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","datePublished":"2017-02-16T19:00:35+00:00","dateModified":"2020-04-27T02:00:05+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/c5032b4c146b46d71669b248ad6e8142"},"description":"\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0\u300cUnit","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","width":650,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u65e5\u672c\u306e\u5b66\u8853\u7814\u7a76\u8005\u3068 \u7d44\u7e54\u3092\u72d9\u3063\u305f\u65b0\u305f\u306a\u653b\u6483"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/c5032b4c146b46d71669b248ad6e8142","name":"Jen Miller-Osborn","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Jen Miller-Osborn"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/jen-miller-osborn\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=106783"}],"version-history":[{"count":3,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106783\/revisions"}],"predecessor-version":[{"id":106786,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106783\/revisions\/106786"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/106755"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=106783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=106783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=106783"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=106783"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=106783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}