{"id":106887,"date":"2016-12-15T05:00:20","date_gmt":"2016-12-15T13:00:20","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=106887"},"modified":"2020-04-27T18:17:08","modified_gmt":"2020-04-28T01:17:08","slug":"unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/","title":{"rendered":"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c\"DealersChoice\"\u3068\u547c\u3093\u3067\u3044\u308b<a href=\"https:\/\/blog.paloaltonetworks.com\/2016\/10\/unit42-dealerschoice-sofacys-flash-player-exploit-platform\/\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0<\/a>\u306b\u3064\u3044\u3066\u5831\u544a\u3057\u307e\u3057\u305f\u3002\"DealersChoice\"\u306f<a href=\"https:\/\/en.wikipedia.org\/wiki\/Sofacy_Group\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">Sofacy\u30b0\u30eb\u30fc\u30d7<\/a>(\u5225\u540dAPT28\u3001Fancy Bear\u3001STRONTIUM\u3001Pawn Storm\u3001Sednit)\u304c\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u306e\u6700\u521d\u306e\u8a18\u4e8b\u3067\u6982\u8aac\u3057\u305f\u3088\u3046\u306b\u3001DealersChoice\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306f\u60aa\u610f\u306e\u3042\u308bRTF\u6587\u66f8\u3092\u751f\u6210\u3057\u307e\u3059\u304c\u3001\u3053\u306eRTF\u6587\u66f8\u306f\u3055\u3089\u306b\u57cb\u3081\u8fbc\u307fOLE Word\u6587\u66f8\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002\u305d\u3057\u3066\u3055\u3089\u306b\u3001\u3053\u308c\u3089\u306e\u57cb\u3081\u8fbc\u307fOLE Word\u6587\u66f8\u306b\u306fAbode Flash\u306e\u8106\u5f31\u6027\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3059\u308b\u3088\u3046\u8a2d\u8a08\u3055\u308c\u305f\u57cb\u3081\u8fbc\u307fAdobe Flash (.SWF)\u30d5\u30a1\u30a4\u30eb\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u6700\u521d\u306b\u5831\u544a\u3057\u305f\u6642\u70b9\u3067\u3001\u79c1\u305f\u3061\u306f\u4e9c\u7a2e\u30922\u3064\u767a\u898b\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<ol>\n<li>\u4e9c\u7a2eA: Flash\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3068\u3082\u306b\u30d1\u30c3\u30b1\u30fc\u30b8\u5316\u3057\u305f\u72b6\u614b\u3067\u542b\u3093\u3067\u3044\u308b\u30b9\u30bf\u30f3\u30c9\u30a2\u30ed\u30fc\u30f3\u65b9\u5f0f\u306e\u4e9c\u7a2e\u3002<\/li>\n<li>\u4e9c\u7a2eB: \u30aa\u30f3\u30c7\u30de\u30f3\u30c9\u3067\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u30ed\u30fc\u30c9\u3059\u308b\u3082\u306e\u3060\u304c\u3001\u5f53\u6642\u306f\u52d5\u4f5c\u3057\u3066\u3044\u306a\u3044\u3088\u3046\u306b\u898b\u53d7\u3051\u3089\u308c\u305f\u30e2\u30b8\u30e5\u30fc\u30eb\u65b9\u5f0f\u306e\u4e9c\u7a2e\u3002<\/li>\n<\/ol>\n<p>\u305d\u306e\u3068\u304d\u4ee5\u6765\u3001\u79c1\u305f\u3061\u306fDealersChoice\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u304c\u751f\u6210\u3059\u308b\u6b66\u5668\u5316\u3055\u308c\u305f\u6587\u66f8\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u8ffd\u52a0\u53ce\u96c6\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u305d\u308c\u3089\u6700\u65b0\u306e\u8ffd\u52a0\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u3059\u3079\u3066\u4e9c\u7a2eB\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u3053\u308c\u3089\u30b5\u30f3\u30d7\u30eb\u306e\u3046\u30612\u3064\u304c\u7a3c\u50cd\u4e2d\u306e\u30b3\u30de\u30f3\u30c9\uff06\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30b5\u30fc\u30d0\u3092\u4f7f\u7528\u3057\u3066\u3044\u305f\u305f\u3081\u3001\u79c1\u305f\u3061\u306f\u653b\u6483\u306b\u95a2\u9023\u3059\u308b\u75d5\u8de1\u3092\u3055\u3089\u306b\u53ce\u96c6\u3001\u5206\u6790\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>2016\u5e7410\u6708\u4e0b\u65ec\u3001Adobe\u304cAdobe Security Bulletin\u00a0<a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-36.html\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">APSB16-36<\/a>\u3092\u914d\u5e03\u3057\u3066<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-7855\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">CVE-2016-7855<\/a>\u306b\u5bfe\u5fdc\u3057\u307e\u3057\u305f\u30022016\u5e7411\u6708\u521d\u65ec\u3001Microsoft\u304cMicrosoft Security Bulletin\u00a0<a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-135.aspx\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">MS16-135<\/a>\u3092\u914d\u5e03\u3057\u3066<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-7255\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">CVE-2016-7255<\/a>\u306b\u5bfe\u5fdc\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u4e21\u8005\u306f\u30bc\u30ed\u30c7\u30a4\u8106\u5f31\u6027\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u6d3b\u767a\u3067\u3042\u308b\u3053\u3068\u306b\u5bfe\u5fdc\u3057\u305f\u3082\u306e\u3067\u3057\u305f\u304c\u3001<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/pawn-storm-ramps-up-spear-phishing-before-zero-days-get-patched\/\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">\u3053\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304cSofacy\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u304c\u3042\u308b\u3068\u4ed6\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u8003\u3048\u3066\u3044\u307e\u3057\u305f<\/a>\u3002\u79c1\u305f\u3061\u72ec\u81ea\u306e\u5206\u6790\u3060\u3051\u3067\u306a\u304f\u3001\u5225\u306e\u5831\u544a\u304b\u3089\u3082\u3001Adobe Flash\u306e\u8106\u5f31\u6027CVE-2016-7855\u306b\u5bfe\u3059\u308b\u3053\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u304cDealersChoice\u3092\u4f7f\u3063\u3066\u914d\u4fe1\u3055\u308c\u305f\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001\u793e\u5185\u306e\u30c6\u30b9\u30c8\u304b\u3089\u3082\u3001Palo Alto Networks Traps\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8 \u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u304a\u5ba2\u69d8\u304c\u3001\u3053\u306e\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3082\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<h3>\u4ef2\u9593\u306b\u5165\u308c\u308d: \u6d3b\u52d5\u4e2d\u306e C2 \u30b5\u30fc\u30d0\u3092\u898b\u3064\u3051\u308b<\/h3>\n<p>\u79c1\u305f\u3061\u304c\u524d\u56de\u306e<a href=\"https:\/\/blog.paloaltonetworks.com\/2016\/10\/unit42-dealerschoice-sofacys-flash-player-exploit-platform\/\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">\u30d6\u30ed\u30b0\u3067DealersChoice\u306b\u3064\u3044\u3066\u8003\u5bdf\u3057\u305f\u969b\u3001<\/a>\u4e9c\u7a2eB\u304c\u8e0f\u3080\u3068\u601d\u308f\u308c\u3066\u3044\u305f\u624b\u9806\u304c\u88ab\u5bb3\u8005\u306e\u30db\u30b9\u30c8\u4e0a\u3067\u4e00\u5ea6\u5b9f\u884c\u3055\u308c\u308b\u3068\u3053\u308d\u306f\u7a81\u304d\u6b62\u3081\u307e\u3057\u305f\u304c\u3001\u305d\u306e\u3068\u304d\u306f\u7279\u5b9a\u3057\u305f\u30b3\u30de\u30f3\u30c9\uff06\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb(C2)\u30b5\u30fc\u30d0\u3068\u3046\u307e\u304f\u5bfe\u8a71\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u3002<\/p>\n<p>\u305d\u306e\u5f8c\u3001\u79c1\u305f\u3061\u306f\u30d5\u30eb\u7a3c\u50cd\u3057\u3066\u3044\u308b\u6d3b\u52d5\u4e2d\u306eC2\u30b5\u30fc\u30d0(versiontask[.]com and postlkwarn[.]com)\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u306eC2\u30b5\u30fc\u30d0\u306f\u3001\u79c1\u305f\u3061\u304c\u30d6\u30ed\u30b0\u3067\u6982\u8aac\u3057\u305f\u901a\u308a\u3001\u305d\u306e\u624b\u9806\u3092\u305f\u3069\u308a\u307e\u3057\u305f\u3002\u3064\u307e\u308a\u3001\u8ffd\u52a0\u306eFlash\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3057\u3001\u5f15\u304d\u7d9a\u304d\u95a2\u9023\u3059\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3082\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3057\u307e\u3057\u305f\u3002\u56f31\u306f\u88ab\u5bb3\u8005\u306eC2\u901a\u4fe1\u306b\u95a2\u3059\u308b\u4f5c\u696d\u306e\u6d41\u308c\u3067\u3059\u3002<\/p>\n<figure style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_1.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_1.png\" alt=\"\u56f31 DealersChoice\u306e\u4f5c\u696d\u306e\u6d41\u308c\" width=\"675\" height=\"684\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f31 DealersChoice\u306e\u4f5c\u696d\u306e\u6d41\u308c<\/figcaption><\/figure>\n<p>\u4e9c\u7a2eB\u306b\u542b\u307e\u308c\u308bActionScript\u304cC2\u30b5\u30fc\u30d0\u3068\u5bfe\u8a71\u3092\u3057\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u53d6\u5f97\u3059\u308b\u306e\u304c\u76ee\u7684\u3067\u3059\u3002\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u306fC2\u30b5\u30fc\u30d0\u3078\u306e\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\u304b\u3089\u59cb\u307e\u308a\u307e\u3059\u304c\u3001\u3053\u306e\u30d3\u30fc\u30b3\u30f3\u306b\u306f\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u304a\u3088\u3073\u88ab\u5bb3\u8005\u306eAdobe Flash Player\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u56f32\u306fActionScript\u304cC2\u30b5\u30fc\u30d0\u306b\u5411\u3051\u3066\u9001\u308b\u30d3\u30fc\u30b3\u30f3\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_2.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_2.png\" alt=\"\u56f32 DealersChoice\u304b\u3089C2\u30b5\u30fc\u30d0\u3078\u306e\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\" width=\"675\" height=\"149\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f32 DealersChoice\u304b\u3089C2\u30b5\u30fc\u30d0\u3078\u306e\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3<\/figcaption><\/figure>\n<p>C2\u306f\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\u306b\u5bfe\u3057\u3066\u5fdc\u7b54\u3057\u6587\u5b57\u5217\u3092\u8fd4\u3057\u307e\u3059\u304c\u3001\u3053\u306e\u6587\u5b57\u5217\u3092DealersChoice\u306eActionScript\u304c\u305d\u306e\u5f8c\u306e\u6d3b\u52d5\u3067\u5909\u6570\u3068\u3057\u3066\u4f7f\u7528\u3057\u307e\u3059\u3002\u6d3b\u52d5\u306b\u306f\u3001\u4f8b\u3048\u3070\u8ffd\u52a0\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3084\u305d\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3059\u308b\u5fdc\u7b54\u306e\u5fa9\u53f7\u5316\u306a\u3069\u304c\u3042\u308a\u307e\u3059\u3002\u56f33\u306f\u30d3\u30fc\u30b3\u30f3\u306b\u5bfe\u3059\u308bC2\u30b5\u30fc\u30d0\u306e\u5fdc\u7b54\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306fk1\u3001k2\u3001k3\u304a\u3088\u3073k4\u306e\u5024\u3092\u542b\u3093\u3067\u3044\u307e\u3059\u3002<\/p>\n<figure style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_3.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_3.png\" alt=\"\u56f33 \u30d3\u30fc\u30b3\u30f3\u306b\u5bfe\u3059\u308bC2\u5fdc\u7b54\u304c\u3001\u30c7\u30fc\u30bf\u306e\u5fa9\u53f7\u5316\u306b\u5fc5\u8981\u306a\u30c8\u30fc\u30af\u30f3\u304a\u3088\u3073\u30ad\u30fc\u3092DealersChoice\u306b\u4e0e\u3048\u308b\" width=\"675\" height=\"304\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f33 \u30d3\u30fc\u30b3\u30f3\u306b\u5bfe\u3059\u308bC2\u5fdc\u7b54\u304c\u3001\u30c7\u30fc\u30bf\u306e\u5fa9\u53f7\u5316\u306b\u5fc5\u8981\u306a\u30c8\u30fc\u30af\u30f3\u304a\u3088\u3073\u30ad\u30fc\u3092DealersChoice\u306b\u4e0e\u3048\u308b<\/figcaption><\/figure>\n<p>\u3059\u308b\u3068ActionScript\u306fC2\u5fdc\u7b54\u30c7\u30fc\u30bf\u306e\u4e2d\u304b\u3089\u5f97\u305fk1\u5909\u6570\u3092\u30c8\u30fc\u30af\u30f3\u3068\u3057\u3066\u4f7f\u7528\u3057\u307e\u3059\u3002\u3053\u306e\u30c8\u30fc\u30af\u30f3\u306f\u3001\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u3092\u53d6\u5f97\u3059\u308b\u76ee\u7684\u3067C2\u30b5\u30fc\u30d0\u306b\u9001\u308a\u8fd4\u3055\u308c\u308bHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u4e2d\u306b\u542b\u307e\u308c\u3066\u3044\u307e\u3059(\u56f34\u53c2\u7167)\u3002<\/p>\n<p>C2\u30b5\u30fc\u30d0\u306f\u3053\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5fdc\u7b54\u3057\u3066\u30c7\u30fc\u30bf\u3092\u9001\u308a\u3001\u3053\u306e\u30c7\u30fc\u30bf\u306e\u5fa9\u53f7\u5316\u3092ActionScript\u304ck3\u5909\u6570\u306e\u5024\u3092\u4f7f\u7528\u3057\u3066\u884c\u3044\u307e\u3059\u3002<\/p>\n<p>\u6d3b\u52d5\u4e2d\u306eC2\u30b5\u30fc\u30d0\u306f\u4e9c\u7a2eB\u306b\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u3001<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-7645\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">CVE-2015-7645<\/a>\u00a0(2016\u5e7410\u6708\u306bAdobe Security Bulletin\u00a0<a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa15-05.html\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">APSA15-05<\/a>\u3067\u5bfe\u5fdc\u6e08\u307f)\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u305f\u540c\u3058SWF\u30d5\u30a1\u30a4\u30eb\u3067\u3042\u308a\u3001\u4e9c\u7a2eA\u306e\u30b5\u30f3\u30d7\u30eb\u5185\u3067\u767a\u898b\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p style=\"padding-left: 40px;\">c42a0d50eac9399914090f1edc2bda9ac1079edff4528078549c824c4d023ff9<br \/>\n45a4a376cb7a36f8c7851713c7541cb7e347dafb08980509069a078d3bcb1405<\/p>\n<figure style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_4.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_4.png\" alt=\"\u56f34 DealersChoice\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8(Adobe Flash Player\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3059\u308b\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u3082\u306e)\" width=\"675\" height=\"290\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f34 DealersChoice\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8(Adobe Flash Player\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3059\u308b\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u3082\u306e)<\/figcaption><\/figure>\n<p>\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u3092\u53d7\u3051\u53d6\u308b\u3068\u3001\u4e9c\u7a2eB\u306f\u305d\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u30c8\u30fc\u30af\u30f3\u3068\u3057\u3066k2\u5909\u6570\u3092\u4f7f\u7528\u3059\u308bHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u307e\u3059(\u56f35\u53c2\u7167)\u3002C2\u30b5\u30fc\u30d0\u306f\u3053\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5fdc\u7b54\u3057\u3066\u30c7\u30fc\u30bf\u3092\u9001\u308a\u3001\u3053\u306e\u30c7\u30fc\u30bf\u306e\u5fa9\u53f7\u5316\u3092\u4e9c\u7a2eB\u304ck4\u5909\u6570\u306e\u5024\u3092\u30ad\u30fc\u3068\u3057\u3066\u4f7f\u7528\u3057\u3066\u884c\u3044\u307e\u3059\u3002\u7d50\u679c\u3068\u3057\u3066\u5f97\u3089\u308c\u308b\u5fa9\u53f7\u5316\u6e08\u307f\u30c7\u30fc\u30bf\u306b\u306f\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u304c\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u5316\u3057\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<figure style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_5.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_5.png\" alt=\"\u56f35 DealersChoice\u306eHTTP \u30ea\u30af\u30a8\u30b9\u30c8(\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u6210\u529f\u6642\u306b\u5b9f\u884c\u3059\u308b\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u3082\u306e)\" width=\"675\" height=\"316\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f35 DealersChoice\u306eHTTP \u30ea\u30af\u30a8\u30b9\u30c8(\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u6210\u529f\u6642\u306b\u5b9f\u884c\u3059\u308b\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u3082\u306e)<\/figcaption><\/figure>\n<p>\u6d3b\u52d5\u4e2d\u306eC2\u30b5\u30fc\u30d0versiontask[.]com\u304a\u3088\u3073postlkwarn[.]com\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u5316\u3057\u5b9f\u884c\u3059\u308b\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u4e21\u8005\u3044\u305a\u308c\u306e\u5834\u5408\u3082\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u30ed\u30fc\u30c0\u30fc\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3042\u308a\u3001\u30b7\u30b9\u30c6\u30e0\u306b\u4fdd\u5b58\u3057\u3066\u3042\u308b\u57cb\u3081\u8fbc\u307f\u578bDLL\u3092\u62bd\u51fa\u3057\u5fa9\u53f7\u5316\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\">5dd3066a8ee3ab5b380eb7781c85e4253683cd7e3eee1c29013a7a62cd9bef8c fa8b4f64bff799524f6059c3a4ed5d169e9e7ef730f946ac7ad8f173e8294ed8<\/p>\n<p>\u307e\u305f\u3001\u3044\u305a\u308c\u306e\u5834\u5408\u3082\u3001\u30b7\u30b9\u30c6\u30e0\u306b\u4fdd\u5b58\u3057\u3066\u3042\u308bDLL\u306fCarberp\u30bd\u30fc\u30b9 \u30b3\u30fc\u30c9\u3092\u4f7f\u7528\u3059\u308bSofacy\u306e\u30c4\u30fc\u30eb\u306e\u4e9c\u7a2e\u3067\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\">82213713cf442716eac3f8c95da8d631aab2072ba44b17dda86873e462e10421 3ff1332a84d615a242a454e5b29f08143b1a89ac9bd7bfaa55ba0c546db10e4b<\/p>\n<p>Seduploader\u30c4\u30fc\u30eb\u306e\u3053\u306e2\u3064\u306e\u4e9c\u7a2e\u306f\u540c\u3058C2\u30c9\u30e1\u30a4\u30f3apptaskserver[.]com\u3092\u5171\u6709\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u306eC2\u30c9\u30e1\u30a4\u30f3\u306fappservicegroup[.]com\u304a\u3088\u3073joshel[.]com\u3068\u3044\u3046\u7570\u306a\u308b\u3082\u306e\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3>\u6700\u5f8c\u306e\u5207\u308a\u672d: \u88ab\u5bb3\u8005\u306e\u30d5\u30a3\u30f3\u30ac\u30fc\u30d7\u30ea\u30f3\u30c6\u30a3\u30f3\u30b0\u3092\u5206\u6790\u3059\u308b<\/h3>\n<p>\u4e9c\u7a2eB\u306e\u6d3b\u52d5\u4e2d\u306eC2\u30b5\u30fc\u30d0\u3092\u5206\u6790\u3057\u3066\u3044\u308b\u904e\u7a0b\u3067\u3001\u79c1\u305f\u3061\u306f\u3001C2\u30b5\u30fc\u30d0\u304c\u88ab\u5bb3\u8005\u306e\u30d5\u30a3\u30f3\u30ac\u30fc\u30d7\u30ea\u30f3\u30c6\u30a3\u30f3\u30b0\u306b\u57fa\u3065\u3044\u3066\u3001\u7570\u306a\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u30ed\u30fc\u30c9\u3059\u308b\u3068\u3044\u3046\u4eee\u8aac\u3092\u30c6\u30b9\u30c8\u3057\u305f\u3044\u3068\u601d\u3046\u306b\u81f3\u308a\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306fC2\u30b5\u30fc\u30d0\u306b\u5bfe\u3057\u3066\u3055\u307e\u3056\u307e\u306a\u5fdc\u7b54\u3092\u4e0e\u3048\u308b\u3053\u3068\u3067\u3053\u308c\u3092\u30c6\u30b9\u30c8\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u307e\u305a\u3001C2\u30b5\u30fc\u30d0\u306b\u5bfe\u3057\u3066\u7c73\u56fd\u30ab\u30ea\u30d5\u30a9\u30eb\u30cb\u30a2\u306b\u3042\u308bVPN\u304b\u3089\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u307e\u3057\u305f\u304c\u3001\u30b5\u30fc\u30d0\u306f\u3053\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5fdc\u7b54\u3057\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u6b21\u306b\u3001\u4e2d\u6771\u306b\u3042\u308b\u5225\u306eVPN\u306b\u63a5\u7d9a\u3057\u3001\u540c\u3058\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u5730\u70b9\u3060\u3068C2\u30b5\u30fc\u30d0\u306f\u60aa\u610f\u306e\u3042\u308bSWF\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u4f34\u3046\u5fdc\u7b54\u3092\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u4e8b\u5b9f\u304b\u3089\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u304c\u5730\u7406\u4f4d\u7f6e\u60c5\u5831\u3092\u4f7f\u3063\u3066\u3001\u9001\u4fe1\u5143\u306e\u4f4d\u7f6e\u304c\u3001\u30b0\u30eb\u30fc\u30d7\u304c\u6a19\u7684\u3068\u3059\u308b\u4f4d\u7f6e\u3068\u4e00\u81f4\u3057\u306a\u3044\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9664\u5916\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u4f3a\u3048\u307e\u3059\u3002<\/p>\n<p>\u305d\u3053\u3067\u79c1\u305f\u3061\u304cC2\u3092\u30c6\u30b9\u30c8\u3059\u308b\u305f\u3081\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u3044\u304f\u3064\u304b\u767a\u884c\u3057\u305f\u3068\u3053\u308d\u3001\u30b5\u30fc\u30d0\u304c\u6bce\u56de\u7570\u306a\u308b\u5909\u6570k1\u3001k2\u3001k3\u304a\u3088\u3073k4\u3092\u4f34\u3063\u3066\u5fdc\u7b54\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u3053\u3068\u304b\u3089\u3001\u30b5\u30fc\u30d0\u304c\u53d7\u4fe1\u3057\u305f\u5404\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3057\u3066\u3053\u308c\u3089\u306e\u5024\u3092\u30e9\u30f3\u30c0\u30e0\u306b\u9078\u3093\u3067\u3044\u308b\u3053\u3068\u304c\u4f3a\u3048\u307e\u3059\u3002<\/p>\n<p>C2\u30b5\u30fc\u30d0\u306e\u30ed\u30b8\u30c3\u30af\u3092\u3055\u3089\u306b\u30c6\u30b9\u30c8\u3059\u308b\u305f\u3081\u3001\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u3068Flash Player\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u793a\u3059\u3055\u307e\u3056\u307e\u306a\u5024\u3092\u542b\u3093\u3060\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3057\u305f\u3002C2\u30b5\u30fc\u30d0\u306b\u5bfe\u3057\u3066Adobe Flash Player\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u309223.0.0.185\u306b\u8a2d\u5b9a\u3057\u305fHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u4fe1\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306fCVE-2016-7855\u306b\u5bfe\u3057\u3066\u8106\u5f31\u6027\u306e\u3042\u308bFlash\u306e\u4e00\u756a\u65b0\u3057\u3044\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u3059\u3002\u3059\u308b\u3068\u3001\u30b5\u30fc\u30d0\u306f\u5727\u7e2e\u6e08\u307f\u306eSWF\u30d5\u30a1\u30a4\u30eb(SHA256: c993c1e10299162357196de33e4953ab9ab9e9359fa1aea00d92e97e7d8c5f2c)\u3092\u4f34\u3046\u5fdc\u7b54\u3092\u3057\u3066\u304d\u307e\u3057\u305f\u304c\u3001\u307e\u3055\u306b\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u3001\u3053\u306e\u8106\u5f31\u6027\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u6700\u5f8c\u306b\u79c1\u305f\u3061\u304cC2\u30b5\u30fc\u30d0\u306b\u5bfe\u3057\u3066\u88ab\u5bb3\u8005\u304cMacOS\u30b7\u30b9\u30c6\u30e0\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3059\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3059\u308b\u3068\u3001C2\u30b5\u30fc\u30d0\u306f\u524d\u56de\u540c\u69d8\u3001\u540c\u3058\u60aa\u610f\u306e\u3042\u308bSWF\u30d5\u30a1\u30a4\u30eb\u304a\u3088\u3073Windows\u7528\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u5fdc\u7b54\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u3053\u3068\u304b\u3089\u3001\u3053\u306e\u6642\u70b9\u3067Sofacy\u30b0\u30eb\u30fc\u30d7\u304c\u88ab\u5bb3\u8005\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0 \u30b7\u30b9\u30c6\u30e0\u306e\u7a2e\u985e\u3092\u8abf\u3079\u308b\u306e\u306bDealersChoice\u3092\u4f7f\u3063\u3066\u3044\u306a\u3044\u3053\u3068\u304c\u4f3a\u3048\u307e\u3059\u3002<\/p>\n<p>\u3059\u3079\u3066\u306e\u5834\u5408\u306b\u304a\u3044\u3066\u3001C2\u30b5\u30fc\u30d0\u304c\u914d\u4fe1\u3059\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u30ed\u30fc\u30c0\u30fc\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac(SHA256: 3bb47f37e16d09a7b9ba718d93cfe4d5ebbaecd254486d5192057c77c4a25363)\u3067\u3042\u308a\u3001\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304cSeduploader\u306e\u4e9c\u7a2e(SHA256: 4cbb0e3601242732d3ea7c89b4c0fd1074fae4a6d20e5f3afc3bc153b6968d6e)\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u3053\u306e\u4e9c\u7a2e\u304cC2\u30b5\u30fc\u30d0akamaisoftupdate[.]com\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n<h3>\u624b\u672d\u3092\u898b\u305b\u308d: \u304a\u3068\u308a\u306e\u6587\u66f8<\/h3>\n<p>\u3053\u306eDealersChoice\u306e\u653b\u6483\u6ce2\u306b\u95a2\u3057\u3066\u6587\u66f8\u304c6\u500b\u53ce\u96c6\u3055\u308c\u307e\u3057\u305f\u304c\u3001\u3059\u3079\u3066\u4e9c\u7a2eB\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u3053\u308c\u3089\u306f\u3001\u4ee5\u524d\u306e\u653b\u6483\u6ce2\u3067\u79c1\u305f\u3061\u304c\u89b3\u5bdf\u3057\u305f\u3082\u306e\u306b\u985e\u4f3c\u3059\u308b\u304a\u3068\u308a\u3092\u4f7f\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u767a\u898b\u3057\u305f6\u500b\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li>Operation_in_Mosul.rtf \u2014 \u30e2\u30b9\u30eb\u306e\u30c8\u30eb\u30b3\u8ecd\u306b\u95a2\u3059\u308b\u8a18\u4e8b<\/li>\n<li>NASAMS.doc \u2014 \u30ea\u30c8\u30a2\u30cb\u30a2\u306e\u56fd\u9632\u7701\u306b\u3088\u308b\u30ce\u30eb\u30a6\u30a7\u30fc\u306e\u30df\u30b5\u30a4\u30eb\u9632\u885b\u30b7\u30b9\u30c6\u30e0\u8cfc\u5165\u306b\u95a2\u3059\u308b\u8a18\u4e8b\u306e\u5199\u3057\u3067\u3042\u308b\u6587\u66f8<\/li>\n<li>Programm_Details.doc \u2014 \u30ed\u30f3\u30c9\u30f3\u3067\u958b\u50ac\u3055\u308c\u308b\u30b5\u30a4\u30d0\u30fc\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9 \u30ab\u30f3\u30d5\u30a1\u30ec\u30f3\u30b9\u306e\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u306e\u5199\u3057\u3067\u3042\u308b\u6587\u66f8(\u6b27\u5dde\u306e\u3042\u308b\u56fd\u306e\u9632\u885b\u7701\u3092\u6a19\u7684\u3068\u3059\u308b)<\/li>\n<li>DGI2017.doc \u2014 \u4e2d\u592e\u30a2\u30b8\u30a2\u306e\u3042\u308b\u56fd\u306e\u5916\u52d9\u7701\u3092\u6a19\u7684\u3068\u3059\u308b\u6587\u66f8(\u30ed\u30f3\u30c9\u30f3\u306b\u96c6\u7d50\u3059\u308b\u9632\u885b\u5730\u7406\u7a7a\u9593\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u306e\u8b70\u984c\u306b\u95a2\u3059\u308b\u3082\u306e)<\/li>\n<li>Olympic-Agenda-2020-20-20-Recommendations.doc \u2014 2020\u5e74\u306e\u30aa\u30ea\u30f3\u30d4\u30c3\u30af\u306b\u95a2\u3059\u308b\u8a73\u7d30\u306a\u5408\u610f\u4e8b\u9805\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u6587\u66f8<\/li>\n<li>ARM-NATO_ENGLISH_30_NOV_2016.doc \u2014 \u30a2\u30eb\u30e1\u30cb\u30a2\u5171\u548c\u56fd\u3068NATO\u306e\u9593\u306e\u5354\u5b9a\u306e\u6982\u8981\u3092\u8a18\u8f09\u3057\u3066\u3044\u308b\u6587\u66f8<\/li>\n<\/ul>\n<figure style=\"width: 687px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_6.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_6.png\" alt=\"\u56f36\u73fe\u5728\u306e\u653b\u6483\u6ce2\u306b\u95a2\u3059\u308b\u3001\u53ce\u96c6\u6e08\u307f\u306e\u304a\u3068\u308a\u6587\u66f8\" width=\"687\" height=\"457\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f36\u73fe\u5728\u306e\u653b\u6483\u6ce2\u306b\u95a2\u3059\u308b\u3001\u53ce\u96c6\u6e08\u307f\u306e\u304a\u3068\u308a\u6587\u66f8<\/figcaption><\/figure>\n<p>\u6700\u521d\u306eDealersChoice\u653b\u6483\u3068\u9055\u3044\u3001\u4f7f\u7528\u3055\u308c\u305f\u3053\u308c\u3089\u6587\u66f8\u306f\u3001\u3044\u3063\u305d\u3046\u306e\u96e3\u8aad\u5316\u3092\u56f3\u308b\u305f\u3081\u30e1\u30bf\u30c7\u30fc\u30bf\u3092\u9664\u53bb\u307e\u305f\u306f\u507d\u9020\u3057\u307e\u3057\u305f\u30022\u3064\u306e\u6587\u66f8NASAMS.doc\u304a\u3088\u3073Programm_Details.doc\u306f\u3001\u6700\u7d42\u4fdd\u5b58\u8005\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u3042\u308a\u3075\u308c\u305f\u4e00\u610f\u306e\u30e6\u30fc\u30b6\u30fc\u540dpain\u3092\u5171\u6709\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001\u3053\u306e\u6b66\u5668\u5316\u3055\u308c\u305f\u6587\u66f8\u306f\u3069\u308c\u3082\u3001<a href=\"https:\/\/blog.paloaltonetworks.com\/2016\/07\/unit42-technical-walkthrough-office-test-persistence-method-used-in-recent-sofacy-attacks\/\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">\u524d\u56de<\/a>\u79c1\u305f\u3061\u304c\u5831\u544a\u3057\u305fOfficeTestSideloading\u306e\u624b\u6cd5\u3092\u4f7f\u3044\u7d9a\u3051\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306f\u3053\u306e\u590f\u306e\u9593\u306bSofacy\u30b0\u30eb\u30fc\u30d7\u304c\u4f7f\u3044\u59cb\u3081\u305f\u624b\u6cd5\u3067\u3042\u308b\u3068\u6c17\u4ed8\u304d\u307e\u3057\u305f\u3002\u88ab\u5bb3\u8005\u306e\u30db\u30b9\u30c8\u4e0a\u3067\u6c38\u7d9a\u6027\u3092\u4fdd\u6301\u3059\u308b\u305f\u3081\u3060\u3051\u3067\u306a\u304f\u3001Microsoft Office\u30b9\u30a4\u30fc\u30c8\u306b\u7d44\u307f\u8fbc\u307e\u308c\u305f\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u8a66\u9a13\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u5229\u7528\u3059\u308bDLL\u30d5\u30a1\u30a4\u30eb\u3092\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9\u3059\u308b\u305f\u3081\u306e\u65b9\u6cd5\u3068\u3057\u3066\u3082\u4f7f\u308f\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<table border=\"0\" width=\"751\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"169\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/td>\n<td valign=\"top\" width=\"120\"><b>\u4f5c\u6210\u8005<\/b><\/td>\n<td valign=\"top\" width=\"127\"><b>\u6700\u7d42\u4fdd\u5b58\u8005<\/b><\/td>\n<td valign=\"top\" width=\"240\"><b>\u30c6\u30fc\u30de<\/b><\/td>\n<td valign=\"top\" width=\"95\"><b>SHA256<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"169\">Operation_in_Mosul.rtf<\/td>\n<td valign=\"top\" width=\"120\">Robert Tasevski<\/td>\n<td valign=\"top\" width=\"127\">\u2014<\/td>\n<td valign=\"top\" width=\"240\">\u30e2\u30b9\u30eb\u306b\u304a\u3051\u308b\u30c8\u30eb\u30b3\u8ecd<\/td>\n<td valign=\"top\" width=\"95\">f5d3e827\u2026<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"169\">NASAMS.doc<\/td>\n<td valign=\"top\" width=\"120\">\u0410\u043d\u0442\u043e\u043d \u0413\u043b\u0430\u0434\u043d\u0438\u0448\u043a\u0438<\/td>\n<td valign=\"top\" width=\"127\">pain<\/td>\n<td valign=\"top\" width=\"240\">\u30ce\u30eb\u30a6\u30a7\u30fc\u306e\u30df\u30b5\u30a4\u30eb\u9632\u885b\u30b7\u30b9\u30c6\u30e0<\/td>\n<td valign=\"top\" width=\"95\">1f81609d\u2026<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"169\">Programm_Details.doc<\/td>\n<td valign=\"top\" width=\"120\">Laci Bonivart<\/td>\n<td valign=\"top\" width=\"127\">pain<\/td>\n<td valign=\"top\" width=\"240\">\u30ab\u30f3\u30d5\u30a1\u30ec\u30f3\u30b9\u306e\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb<\/td>\n<td valign=\"top\" width=\"95\">1579c7a1\u2026<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"169\">DGI2017.doc<\/td>\n<td valign=\"top\" width=\"120\">\u041d\u0435\u0432\u0435\u043d\u0430 \u0413\u0430\u043c\u0438\u0437\u043e\u0432<\/td>\n<td valign=\"top\" width=\"127\">\u041d\u0435\u0432\u0435\u043d\u0430 \u0413\u0430\u043c\u0438\u0437\u043e\u0432<\/td>\n<td valign=\"top\" width=\"240\">\u30ab\u30f3\u30d5\u30a1\u30ec\u30f3\u30b9\u306e\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb<\/td>\n<td valign=\"top\" width=\"95\">c5a389fa\u2026<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"169\">Olympic-Agenda-2020-20-20-Recommendations.doc<\/td>\n<td valign=\"top\" width=\"120\">admin<\/td>\n<td valign=\"top\" width=\"127\">User<\/td>\n<td valign=\"top\" width=\"240\">2020\u5e74\u306e\u30aa\u30ea\u30f3\u30d4\u30c3\u30af\u306b\u95a2\u3059\u308b\u52a9\u8a00<\/td>\n<td valign=\"top\" width=\"95\">13718586\u2026<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"169\">ARM-NATO_ENGLISH_30_NOV_2016.doc<\/td>\n<td valign=\"top\" width=\"120\">User<\/td>\n<td valign=\"top\" width=\"127\">User<\/td>\n<td valign=\"top\" width=\"240\">NATO\u5354\u5b9a<\/td>\n<td valign=\"top\" width=\"95\">73ea2cce\u2026<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u6b66\u5668\u5316\u3055\u308c\u305f\u6587\u66f8\u7528\u306e6\u500b\u306e\u7b2c1\u30b9\u30c6\u30fc\u30b8C2\u30c9\u30e1\u30a4\u30f3\u306f\u3001\u3059\u3079\u3066\u4e00\u610f\u306e\u767b\u9332\u8005\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u3067\u767b\u9332\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002Versiontask[.]com\u304a\u3088\u3073Uniquecorpind[.]com\u306f\u5b8c\u5168\u306b\u65b0\u3057\u3044\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3067\u3042\u308b\u3088\u3046\u306b\u898b\u3048\u307e\u3059\u3002\u3053\u308c\u3089\u306f\u4ee5\u524d\u89b3\u5bdf\u3055\u308c\u305fSofacy\u30b0\u30eb\u30fc\u30d7\u306e\u653b\u6483\u6d3b\u52d5\u3068\u306f\u75d5\u8de1\u3092\u4f55\u3089\u5171\u6709\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<table border=\"0\" width=\"752\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"129\"><b>\u30bf\u30a4\u30d7<\/b><\/td>\n<td valign=\"top\" width=\"213\"><b>\u30c9\u30e1\u30a4\u30f3<\/b><\/td>\n<td valign=\"top\" width=\"133\"><b>\u767b\u9332\u65e5<\/b><\/td>\n<td valign=\"top\" width=\"277\"><b>\u767b\u9332\u8005\u306e\u96fb\u5b50\u30e1\u30fc\u30eb<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">First stage C2<\/td>\n<td valign=\"top\" width=\"213\">Versiontask[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-10-24<\/td>\n<td valign=\"top\" width=\"277\">dalchi0@europe.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">First stage C2<\/td>\n<td valign=\"top\" width=\"213\">Uniquecorpind[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-10-25<\/td>\n<td valign=\"top\" width=\"277\">yasiner@myself.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">First stage C2<\/td>\n<td valign=\"top\" width=\"213\">Securityprotectingcorp[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-08-19<\/td>\n<td valign=\"top\" width=\"277\">ottis.davis@openmailbox.org<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">First stage C2<\/td>\n<td valign=\"top\" width=\"213\">Postlkwarn[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-11-11<\/td>\n<td valign=\"top\" width=\"277\">fradblec@centrum.cz<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">First stage C2<\/td>\n<td valign=\"top\" width=\"213\">adobeupgradeflash[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-11-22<\/td>\n<td valign=\"top\" width=\"277\">nuevomensaje@centrum.cz<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">First stage C2<\/td>\n<td valign=\"top\" width=\"213\">globalresearching[.]org<\/td>\n<td valign=\"top\" width=\"133\">2016-11-18<\/td>\n<td valign=\"top\" width=\"277\">carroz.g@mail.com<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>DealersChoice\u306b\u3088\u3063\u3066\u914d\u4fe1\u3055\u308c\u305fSeduploader\u30da\u30a4\u30ed\u30fc\u30c9\u7528\u306e\u7b2c2\u30b9\u30c6\u30fc\u30b8C2\u30c9\u30e1\u30a4\u30f3\u304c6\u500b\u7279\u5b9a\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<table border=\"0\" width=\"751\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"129\"><b>\u30bf\u30a4\u30d7<\/b><\/td>\n<td valign=\"top\" width=\"213\"><b>\u30c9\u30e1\u30a4\u30f3<\/b><\/td>\n<td valign=\"top\" width=\"133\"><b>\u767b\u9332\u65e5<\/b><\/td>\n<td valign=\"top\" width=\"276\"><b>\u767b\u9332\u8005\u306e\u96fb\u5b50\u30e1\u30fc\u30eb<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">Seduploader C2<\/td>\n<td valign=\"top\" width=\"213\">Joshel[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-11-11<\/td>\n<td valign=\"top\" width=\"276\">germsuz86@centrum.cz<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">Seduploader C2<\/td>\n<td valign=\"top\" width=\"213\">Appservicegroup[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-10-19<\/td>\n<td valign=\"top\" width=\"276\">olivier_servgr@mail.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">Seduploader C2<\/td>\n<td valign=\"top\" width=\"213\">Apptaskserver[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-10-22<\/td>\n<td valign=\"top\" width=\"276\">partanencomp@mail.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">Seduploader C2<\/td>\n<td valign=\"top\" width=\"213\">Akamaisoftupdate[.]com<\/td>\n<td valign=\"top\" width=\"133\">2016-10-26<\/td>\n<td valign=\"top\" width=\"276\">mahuudd@centrum.cz<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">Seduploader C2<\/td>\n<td valign=\"top\" width=\"213\">globaltechresearch[.]org<\/td>\n<td valign=\"top\" width=\"133\">2016-11-21<\/td>\n<td valign=\"top\" width=\"276\">morata_al@mail.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"129\">Seduploader C2<\/td>\n<td valign=\"top\" width=\"213\">researchcontinental[.]org<\/td>\n<td valign=\"top\" width=\"133\">2016-12-02<\/td>\n<td valign=\"top\" width=\"276\">Sinkholed<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u7b2c1\u30b9\u30c6\u30fc\u30b8\u306eC2\u30c9\u30e1\u30a4\u30f3\u3068\u307b\u307c\u540c\u69d8\u306b\u30015\u500b\u306e\u975e\u30b7\u30f3\u30af\u30db\u30fc\u30eb\u306e\u7b2c2\u30b9\u30c6\u30fc\u30b8C2\u30c9\u30e1\u30a4\u30f3\u304c\u6700\u8fd1\u767b\u9332\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306f\u767b\u9332\u8005\u306e\u4e00\u610f\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u4f7f\u3063\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u3053\u308c\u307e\u3067Sofacy\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u3063\u3066\u4f7f\u7528\u3055\u308c\u305f\u3053\u3068\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u3057\u304b\u3057\u3001\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u3044\u305a\u308c\u3082\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u3068\u5171\u901a\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u30cd\u30fc\u30e0\u30b5\u30fc\u30d0\u3067\u3042\u308bns*.carbon2u[.]com\u304a\u3088\u3073ns*.ititch[.]com\u3092\u4f7f\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u30c9\u30e1\u30a4\u30f3akamaisoftupdate[.]com\u306f\u3001\u4ee5\u524d\u306eSofacy\u30b0\u30eb\u30fc\u30d7\u653b\u6483\u6d3b\u52d5\u306b\u3064\u306a\u304c\u308a\u306e\u3042\u308b\u5225\u306e\u75d5\u8de1\u3092\u660e\u3089\u304b\u306b\u3057\u307e\u3057\u305f\u3002\u30d1\u30c3\u30b7\u30d6DNS\u30c7\u30fc\u30bf\u306b\u57fa\u3065\u3044\u3066\u3001\u79c1\u305f\u3061\u306fakamaisoftupdate[.]com\u304c89.45.67.20\u306b\u89e3\u6c7a\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u306b\u6c17\u4ed8\u304d\u307e\u3057\u305f\u3002\u540c\u3058\u30af\u30e9\u30b9C\u306e\u30b5\u30d6\u30cd\u30c3\u30c8\u4e0a\u306789.45.67.189\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u304c\u3001\u3053\u308c\u306f\u4ee5\u524dupdmanager[.]net\u306b\u89e3\u6c7a\u3057\u305f\u3082\u306e\u3067\u3042\u308a\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u304c\u4f7f\u3063\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u3067\u3042\u308b\u3068\u591a\u304f\u5831\u544a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u30c9\u30e1\u30a4\u30f3securityprotectingcorp[.]com\u3082\u3001\u4ee5\u524d\u306eSofacy\u30b0\u30eb\u30fc\u30d7\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068\u306e\u95a2\u9023\u6027\u304c\u3042\u308b\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u308c\u306f2\u30013\u304b\u6708\u524d\u306b\u767b\u9332\u3055\u308c\u307e\u3057\u305f\u304c\u3001\u767b\u9332\u8005\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u5206\u6790\u3057\u305f\u3068\u3053\u308d\u3001microsoftsecurepolicy[.]org\u3092\u767b\u9332\u3059\u308b\u306e\u306b\u3082\u4f7f\u308f\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3057\u305f\u3002microsoftsecurepolicy[.]org\u306f\u30d1\u30c3\u30b7\u30d6DNS\u30c7\u30fc\u30bf\u3092\u4f7f\u3063\u3066\u304a\u308a\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u6027\u306e\u9ad8\u3044IP\u30a2\u30c9\u30ec\u30b940.112.210.240\u306b\u89e3\u6c7a\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306eIP\u30a2\u30c9\u30ec\u30b9\u3068\u5bfe\u5fdc\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u306e\u89e3\u6c7a\u306f\u3001Azzy\u307e\u305f\u306fXagent\u3068\u3044\u3063\u305f\u8907\u6570\u306e\u30c4\u30fc\u30eb\u7528\u306eC2\u3068\u3057\u3066\u3001\u3042\u308b\u3044\u306f\u6a19\u7684\u304b\u3089\u8cc7\u683c\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306e\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0 \u30b5\u30a4\u30c8\u3092\u904b\u7528\u3059\u308b\u76ee\u7684\u3067\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u3063\u3066\u8907\u6570\u306e\u76ee\u7684\u306e\u305f\u3081\u306b\u4f55\u5e74\u306b\u3082\u308f\u305f\u308a\u4f7f\u308f\u308c\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_7.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_7.png\" alt=\"\u56f37 DealersChoice\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u56f3\" width=\"675\" height=\"456\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f37 DealersChoice\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u56f3<\/figcaption><\/figure>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u3053\u306e\u6642\u70b9\u3067\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u304c\u6d3b\u767a\u306bDealersChoice\u30c4\u30fc\u30eb\u3001\u3068\u308a\u308f\u3051\u4e9c\u7a2eB\u3092\u4f7f\u3063\u3066\u3001\u95a2\u5fc3\u306e\u3042\u308b\u6a19\u7684\u3092\u653b\u6483\u3057\u3066\u3044\u308b\u3053\u3068\u306f\u660e\u3089\u304b\u306b\u306a\u3063\u305f\u3068\u601d\u308f\u308c\u307e\u3059\u3002Flash\u306f\u6700\u8fd1\u30d1\u30c3\u30c1\u304c\u63d0\u4f9b\u3055\u308c\u307e\u3057\u305f\u304c\u3001Flash\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3057\u3066\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9(\u30bc\u30ed\u30c7\u30a4\u653b\u6483\u306b\u4f7f\u308f\u308c\u305f)\u304c\u914d\u4fe1\u3055\u308c\u305f\u3053\u3068\u304b\u3089\u660e\u3089\u304b\u306a\u3088\u3046\u306b\u3001\u3044\u304b\u306b\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u624b\u6cd5\u306b\u67d4\u8edf\u6027\u3092\u3082\u305f\u305b\u3001\u307e\u3055\u306b\u305d\u308c\u81ea\u4f53\u3067\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3067\u3042\u308b\u304b\u304c\u7406\u89e3\u3067\u304d\u307e\u3059\u3002\u65b0\u305f\u306a\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u304cDealersChoice\u306e\u305f\u3081\u306b\u69cb\u7bc9\u3055\u308c\u305f\u3088\u3046\u306b\u898b\u3048\u307e\u3059\u304c\u3001\u904e\u53bb\u306e\u7d4c\u9a13\u304b\u3089\u5206\u304b\u308b\u901a\u308a\u3001Sofacy\u30b0\u30eb\u30fc\u30d7\u306f\u3053\u308c\u307e\u3067\u306e\u653b\u6483\u6d3b\u52d5\u306e\u75d5\u8de1\u3092\u518d\u5229\u7528\u3059\u308b\u50be\u5411\u304c\u3042\u308a\u3001\u4eca\u56de\u3082\u4f8b\u5916\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u3057\u304b\u3057Palo Alto Networks\u306e\u304a\u5ba2\u69d8\u306f\u3001\u4ee5\u4e0b\u306e\u5bfe\u7b56\u306b\u3088\u308a\u72b6\u6cc1\u3092\u3055\u3089\u306b\u8a73\u3057\u304f\u628a\u63e1\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u3066\u3001\u540c\u6642\u306b\u4fdd\u8b77\u3055\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li>WildFire\u306b\u304a\u3044\u3066\u3001\u60aa\u610f\u306e\u3042\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u3068\u3057\u3066\u3001\u95a2\u9023\u3059\u308b\u30b5\u30f3\u30d7\u30eb\u3092\u7684\u78ba\u306b\u8b58\u5225\u3059\u308b<\/li>\n<li>DealersChoice\u30c9\u30e1\u30a4\u30f3\u304a\u3088\u3073C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u60aa\u610f\u306e\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u5206\u985e\u3055\u308c\u308b<\/li>\n<li>Traps\u304c\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u7684\u78ba\u306b\u8b58\u5225\u3057\u3066\u5b9f\u884c\u3092\u963b\u6b62\u3059\u308b<\/li>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.DealersChoice\" data-page-track=\"true\" data-page-track-value=\"company:unit42_let_ride_sofacy_groups_dealerschoice_attacks: section: \">DealersChoice\u306eAutoFocus\u30bf\u30b0\u304c\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u3092\u8b58\u5225\u3057\u8ffd\u8de1\u3059\u308b\u306e\u306b\u4f7f\u7528\u3067\u304d\u308b<\/a><\/li>\n<\/ul>\n<p>\u306a\u304a\u3001CVE-2016-7855\u304c\u30bc\u30ed\u30c7\u30a4\u8106\u5f31\u6027\u3060\u3063\u305f\u3068\u3057\u3066\u3082\u3001Palo Alto Networks\u306e\u304a\u5ba2\u69d8\u3060\u3063\u305f\u306a\u3089\u3001Traps\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8 \u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306b\u3088\u308a\u4fdd\u8b77\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u3067\u3057\u3087\u3046(\u56f38\u53c2\u7167)\u3002<\/p>\n<figure style=\"width: 671px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_8.png\" rel=\"wpdevart_lightbox\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2016\/dealerschoice\/dealerschoice_8.png\" alt=\"\u56f38 CVE-2016-7855\u8106\u5f31\u6027\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3092\u30d6\u30ed\u30c3\u30af\u3057\u3066\u3044\u308bPalo Alto Networks\u306eTraps\" width=\"671\" height=\"372\" \/><\/a><figcaption class=\"wp-caption-text\">\u56f38 CVE-2016-7855\u8106\u5f31\u6027\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3092\u30d6\u30ed\u30c3\u30af\u3057\u3066\u3044\u308bPalo Alto Networks\u306eTraps<\/figcaption><\/figure>\n<h3>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4fb5\u5bb3\u306e\u5146\u5019<\/h3>\n<h4>\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u30cf\u30c3\u30b7\u30e5\u5024:<\/h4>\n<p style=\"padding-left: 40px;\">f5d3e827c3a312d018ef4fcbfc7cb5205c9e827391bfe6eab697cc96412d938e<br \/>\n1f81609d9bbdc7f1d2c8846dcfc4292b3e2642301d9c59130f58e21abb0001be<br \/>\n1579c7a1e42f9e1857a4d1ac966a195a010e1f3d714d68c598a64d1c83aa36e4<br \/>\nc5a389fa702a4223aa2c2318f38d5fe6eba68c645bc0c41c3d8b6f935eab3f64<br \/>\n137185866649888b7b5b6554d6d5789f7b510acd7aff3070ac55e2250eb88dab<br \/>\n73ea2ccec2cbf22d524f55b101d324d89077e5718922c6734fef95787121ff22<\/p>\n<h4>DealersChoice C2:<\/h4>\n<p style=\"padding-left: 40px;\">Versiontask[.]com<br \/>\nUniquecorpind[.]com<br \/>\nSecurityprotectingcorp[.]com<br \/>\npostlkwarn[.]com<br \/>\nadobeupgradeflash[.]com<br \/>\nresearchcontinental[.]org<\/p>\n<h4>Seduploader C2:<\/h4>\n<p style=\"padding-left: 40px;\">Appservicegroup[.]com<br \/>\nApptaskserver[.]com<br \/>\nAkamaisoftupdate[.]com<br \/>\nJoshel[.]com<br \/>\nglobaltechresearch[.]org<br \/>\nresearchcontinental[.]org<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c\"DealersChoice\"\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306b\u3064\u3044\u3066\u5831\u544a\u3057\u307e\u3057\u305f\u3002\"DealersChoice\"\u306fSofacy<\/p>\n","protected":false},"author":25,"featured_media":106755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4322,1974,4431,4428],"tags":[7030,4809,6613,6391],"product_categories":[],"coauthors":[934,935],"class_list":["post-106887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-actor-groups","category-malware-ja","category-threat-actor-groups-ja","category-threat-research-ja","tag-dealerschoice","tag-fighting-ursa-ja","tag-sofacy-ja","tag-threat-research-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f<\/title>\n<meta name=\"description\" content=\"\u6982\u8981 \u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c&quot;DealersChoice&quot;\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8981 \u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c&quot;DealersChoice&quot;\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2016-12-15T13:00:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-28T01:17:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"650\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Bryan Lee, Robert Falcone\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f","description":"\u6982\u8981 \u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c\"DealersChoice\"\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/","og_locale":"ja_JP","og_type":"article","og_title":"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f","og_description":"\u6982\u8981 \u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c\"DealersChoice\"\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/","og_site_name":"Unit 42","article_published_time":"2016-12-15T13:00:20+00:00","article_modified_time":"2020-04-28T01:17:08+00:00","og_image":[{"width":650,"height":300,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","type":"image\/jpeg"}],"author":"Bryan Lee, Robert Falcone","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/"},"author":{"name":"Bryan Lee","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d78a8f5ae42058baeccf9ca6d6235e4"},"headline":"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f","datePublished":"2016-12-15T13:00:20+00:00","dateModified":"2020-04-28T01:17:08+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/"},"wordCount":5506,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","keywords":["DealersChoice","Fighting Ursa","Sofacy","threat research"],"articleSection":["Threat Actor Groups","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30a2\u30af\u30bf\u30fc \u30b0\u30eb\u30fc\u30d7","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/","name":"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","datePublished":"2016-12-15T13:00:20+00:00","dateModified":"2020-04-28T01:17:08+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d78a8f5ae42058baeccf9ca6d6235e4"},"description":"\u6982\u8981 \u6700\u8fd1\u3001Palo Alto Networks\u306eUnit 42\u306f\u3001\u79c1\u305f\u3061\u304c\"DealersChoice\"\u3068\u547c\u3093\u3067\u3044\u308b\u65b0\u578b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/unit42-web-banner-650x300-1.jpg","width":650,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u30ec\u30c3\u30c8\u30a4\u30c3\u30c8\u30e9\u30a4\u30c9: Sofacy\u30b0\u30eb\u30fc\u30d7\u306eDealersChoice\u653b\u6483\u7d9a\u304f"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d78a8f5ae42058baeccf9ca6d6235e4","name":"Bryan Lee","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Bryan Lee"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/bryanlee\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106887","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=106887"}],"version-history":[{"count":4,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106887\/revisions"}],"predecessor-version":[{"id":106890,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106887\/revisions\/106890"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/106755"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=106887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=106887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=106887"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=106887"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=106887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}