{"id":109590,"date":"2020-11-17T21:30:53","date_gmt":"2020-11-18T05:30:53","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=109590"},"modified":"2020-11-17T21:30:53","modified_gmt":"2020-11-18T05:30:53","slug":"vatet-pyxie-defray777","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/","title":{"rendered":"\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u79c1\u305f\u3061\u306f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5b9f\u52d9\u8005\u3068\u3057\u3066\u3001\u304d\u308f\u3081\u3066\u5927\u304d\u306a\u30c0\u30e1\u30fc\u30b8\u3092\u3082\u305f\u3089\u3059\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3092\u5229\u7528\u3057\u305f\u308a\u3001\u81a8\u5927\u306a\u6570\u306e\u88ab\u5bb3\u8005\u306b\u5f71\u97ff\u3092\u53ca\u307c\u3057\u305f\u308a\u3059\u308b\u653b\u6483\u8005\u3084\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3092\u9577\u3044\u6642\u9593\u3092\u304b\u3051\u3066\u6ce8\u8996\u3057\u3066\u3044\u307e\u3059\u3002\u3057\u304b\u3057\u3001\u653b\u6483\u8005\u304c\u6c17\u4ed8\u304b\u308c\u308b\u3053\u3068\u306a\u304f\u3086\u3063\u304f\u308a\u3068\u884c\u52d5\u3057\u305f\u3089\u3069\u3046\u306a\u308b\u3067\u3057\u3087\u3046\u3002\u3053\u306e\u3088\u3046\u306a\u653b\u6483\u8005\u306f\u3001\u4f55\u5ea6\u3082\u653b\u6483\u3092\u4ed5\u639b\u3051\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u6bd4\u8f03\u3057\u3066\u3001\u6700\u7d42\u7684\u306b\u306f\u3088\u308a\u5927\u304d\u306a\u30c0\u30e1\u30fc\u30b8\u3092\u3082\u305f\u3089\u3059\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u8a00\u3048\u308b\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>Vatet\u30ed\u30fc\u30c0\u30fc\u3001PyXie\u30ea\u30e2\u30fc\u30c8 \u30a2\u30af\u30bb\u30b9 \u30c4\u30fc\u30eb(RAT)\u3001\u304a\u3088\u3073Defray777\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u9593\u306b\u95a2\u9023\u304c\u3042\u308a\u305d\u3046\u3060\u3068\u5f0a\u793e\u304c\u6700\u521d\u306b\u6c17\u3065\u3044\u305f\u306e\u306f\u3001\u3055\u307e\u3056\u307e\u306a<a href=\"https:\/\/www.crypsisgroup.com\/\">\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc<\/a>\u3084<a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/managed-threat-hunting\">\u30de\u30cd\u30fc\u30b8\u30c9\u8105\u5a01\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0<\/a>\u3068\u95a2\u308f\u308b\u4e2d\u3067\u3001\u3053\u306e3\u3064\u304c\u63c3\u3063\u3066\u73fe\u308c\u308b\u5f62\u8de1\u3084\u691c\u51fa\u7d50\u679c\u3092\u898b\u3064\u3051\u305f\u3068\u304d\u3067\u3057\u305f\u3002\u305d\u308c\u305e\u308c\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3092\u8a73\u7d30\u306b\u8abf\u67fb\u3059\u308b\u3068\u3001Vatet\u3001PyXie\u3001Defray777\u306f\u3044\u305a\u308c\u3082\u30012018\u5e74\u306b\u306f\u6d3b\u52d5\u3092\u958b\u59cb\u3057\u3066\u3044\u305f\u3001\u91d1\u878d\u6a5f\u95a2\u3092\u72d9\u3063\u305f\u306e\u3068\u540c\u3058\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u304c\u3042\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001<a href=\"https:\/\/blogs.blackberry.com\/en\/2019\/12\/meet-pyxie-a-nefarious-new-python-rat\">BlackBerry Cylance<\/a>\u3067\u306fPyXie\u3001SecureWorks\u3067\u306f<a href=\"https:\/\/www.secureworks.com\/research\/threat-profiles\/gold-dupont\">GOLD DUPONT<\/a>\u3068\u3082\u547c\u3070\u308c\u3066\u304a\u308a\u3001\u533b\u7642\u3001\u6559\u80b2\u3001\u653f\u5e9c\u3001\u30c6\u30af\u30ce\u30ed\u30b8\u306a\u3069\u3001\u591a\u6570\u306e\u5206\u91ce\u306e\u7d44\u7e54\u306b\u30c0\u30e1\u30fc\u30b8\u3092\u4e0e\u3048\u305f\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u3092\u5b9f\u884c\u3057\u3001\u6c17\u4ed8\u304b\u308c\u308b\u3053\u3068\u306a\u304f\u6d3b\u52d5\u3057\u3066\u304d\u307e\u3057\u305f\u3002\u672c\u7a3f\u306e\u72d9\u3044\u306f\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3092\u89e3\u660e\u3057\u3001\u305d\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3068\u653b\u6483\u624b\u6cd5\u306e\u5553\u767a\u3092\u901a\u3058\u3066\u5f7c\u3089\u306e\u653b\u6483\u3092\u4e2d\u65ad\u3055\u305b\u308b\u3053\u3068\u3067\u3059\u3002\u8981\u3059\u308b\u306b\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306e\u52d5\u304d\u3092<em>\u6349\u3048\u305f\u3044<\/em>\u306e\u3067\u3059\u3002<\/p>\n<p>\u5f0a\u793e\u306e\u8abf\u67fb\u306b\u3088\u308a\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304cVatet\u30ed\u30fc\u30c0\u30fc\u3092\u958b\u767a\u3057\u3001\u30e1\u30f3\u30c6\u30ca\u30f3\u30b9\u3057\u3066\u304d\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u30ed\u30fc\u30c0\u30fc\u306e\u9032\u5316\u3068\u4e26\u884c\u3057\u3066\u3001\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3067\u306f\u3001PyXie\u3084Cobalt Strike\u306a\u3069\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u5143\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u6539\u5909\u3057\u3066\u3001\u8907\u6570\u306e\u30aa\u30fc\u30d7\u30f3 \u30bd\u30fc\u30b9 \u30c4\u30fc\u30eb\u3092\u6d3b\u7528\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u6b21\u306b\u3001\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u5f0a\u793e\u3067PyXie Lite\u3068\u547c\u3093\u3067\u3044\u308bPyXie\u306e\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u7248\u3092\u4f7f\u7528\u3057\u3066\u3001\u5075\u5bdf\u3092\u884c\u3044\u3001\u88ab\u5bb3\u3092\u53d7\u3051\u305f\u7d44\u7e54\u306e\u6a5f\u5bc6\u60c5\u5831\u3068\u8003\u3048\u3089\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u898b\u3064\u3051\u3066\u6f0f\u51fa\u3055\u305b\u3066\u3044\u307e\u3059\u3002\u5f0a\u793e\u304c\u591a\u6570\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3092\u8abf\u67fb\u3057\u305f\u3068\u3053\u308d\u3001\u653b\u6483\u8005\u306f\u3001IcedID\u3084<a href=\"https:\/\/unit42.paloaltonetworks.com\/tag\/trickbot\/\">Trickbot<\/a>\u306a\u3069\u3001\u9280\u884c\u306b\u3088\u304f\u4ed5\u639b\u3051\u3089\u308c\u308b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u4f7f\u7528\u3057\u3066\u3001\u88ab\u5bb3\u8005\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306b\u4fb5\u5165\u3059\u308b\u6700\u521d\u306e\u8db3\u304c\u304b\u308a\u3092\u4f5c\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u653b\u6483\u8005\u306f\u305d\u306e\u8db3\u304c\u304b\u308a\u3092\u5229\u7528\u3057\u3066\u3001Vatet\u3001PyXie\u3001Cobalt Strike\u3092\u5c55\u958b\u5f8c\u306b\u5b8c\u5168\u306b\u30e1\u30e2\u30ea\u5185\u3060\u3051\u3067Defray777\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u3092\u5b9f\u884c\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u7d50\u679c\u3001\u30ed\u30fc\u30ab\u30eb\u30c9\u30e9\u30a4\u30d6\u3068\u30d5\u30a1\u30a4\u30eb\u5171\u6709\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u5b9f\u884c\u7d42\u4e86\u524d\u306b\u6697\u53f7\u5316\u3055\u308c\u307e\u3059\u3002\u307e\u305f\u3001\u3053\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001\u6697\u53f7\u5316\u30d5\u30a1\u30a4\u30eb\u3068\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u4ee5\u5916\u306b\u306f\u5b9f\u884c\u306e\u75d5\u8de1\u3092\u6b8b\u3057\u307e\u305b\u3093\u3002Defray777\u306b\u95a2\u3057\u3066\u306f\u3001\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u64cd\u308b\u30b0\u30eb\u30fc\u30d7\u3082\u3001\u81ea\u5206\u305f\u3061\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u3092Windows\u304b\u3089Linux\u306b\u79fb\u690d\u3057\u3066\u304a\u308a\u3001Defray777\u304c\u73fe\u308c\u308b\u524d\u3067\u540c\u69d8\u306e\u3082\u306e\u306f\u3001\u6a19\u7684\u578b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u4e2d\u3067\u306f\u307e\u3060\u898b\u3064\u304b\u3063\u3066\u3044\u307e\u305b\u3093\u3002Defray777\u3092\u767a\u898b\u3059\u308b\u524d\u306f\u3001Windows\u3068Linux\u306e\u4e21\u30b7\u30b9\u30c6\u30e0\u306b\u5f71\u97ff\u3092\u53ca\u307c\u3059\u80fd\u529b\u3092\u6301\u3063\u305f\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001Java\u307e\u305f\u306fPython\u306a\u3069\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u8a00\u8a9e\u3067\u8a18\u8ff0\u3055\u308c\u305f\u3001\u4e21\u30b7\u30b9\u30c6\u30e0\u3067\u6a5f\u80fd\u3059\u308b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306b\u9650\u3089\u308c\u3066\u3044\u307e\u3057\u305f\u3002Defray777\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001Linux\u3078\u306e\u79fb\u690d\u306b\u3088\u308a\u3001Windows\u3068Linux\u5411\u3051\u306b\u30b9\u30bf\u30f3\u30c9\u30a2\u30ed\u30f3\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u6301\u3064\u6700\u521d\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>3\u7a2e\u985e\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3059\u3079\u3066\u3092\u78ba\u8a8d\u3059\u308b\u3068\u3001\u8003\u616e\u3059\u3079\u304d\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u6570\u591a\u304f\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u5f0a\u793e\u3067\u306f\u3001\u5404\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306e\u8a73\u7d30\u60c5\u5831\u3092\u591a\u6570\u5165\u624b\u3057\u3066\u304a\u308a\u307e\u3059\u304c\u3001\u8aad\u8005\u306e\u7686\u3055\u307e\u306f1\u3064\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u7279\u306b\u3054\u95a2\u5fc3\u3092\u304a\u6301\u3061\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3057\u3001\u3054\u81ea\u8eab\u3067\u306e\u8abf\u67fb\u3092\u3054\u5e0c\u671b\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002\u3054\u5e0c\u671b\u306b\u5fdc\u3058\u3066\u3001\u4ee5\u4e0b\u306e\u30ea\u30f3\u30af\u304b\u3089\u6700\u3082\u3054\u95a2\u5fc3\u306e\u9ad8\u3044\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306e\u8aac\u660e\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u304b\u3001\u76f4\u63a5IoC\u3092\u3054\u89a7\u306b\u306a\u308a\u3001\u6d3b\u52d5\u3092\u7d9a\u3051\u308b\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u6355\u6349\u3084\u691c\u51fa\u306b\u304a\u5f79\u7acb\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h2>\u76ee\u6b21<\/h2>\n<ul>\n<li>\u6700\u521d\u306e\u8a18\u4e8b: Vatet\u30ed\u30fc\u30c0\u30fc<\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/2\">\u6b21\u306e\u8a18\u4e8b: PyXie Lite<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/3\">\u6700\u5f8c\u306e\u91cd\u8981\u306a\u8a18\u4e8b: Defray777<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/4\">Vatet\u3001PyXie\u3001Defray777\u306e\u3064\u306a\u304c\u308a<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/5\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4fb5\u5bb3\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u30fc (IOC)<\/a><\/li>\n<\/ul>\n<h2><a id=\"post-109455-_4drsj28ju9ok\"><\/a>\u6700\u521d\u306e\u8a18\u4e8b: Vatet\u30ed\u30fc\u30c0\u30fc<\/h2>\n<p>Vatet\u306f\u3001\u30ed\u30fc\u30ab\u30eb\u30c7\u30a3\u30b9\u30af\u307e\u305f\u306f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5171\u6709\u304b\u3089\u3001XOR\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u30ab\u30b9\u30bf\u30e0\u30ed\u30fc\u30c0\u30fc\u3067\u3059\u3002\u3053\u306e\u30ed\u30fc\u30c0\u30fc\u306f\u3001GitHub\u3084\u305d\u306e\u4ed6\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u306b\u3042\u308b\u4e00\u822c\u7684\u306a\u30aa\u30fc\u30d7\u30f3 \u30bd\u30fc\u30b9 \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u3059\u304c\u3001\u653b\u6483\u8005\u306f\u3053\u306e\u30ed\u30fc\u30c0\u30fc\u3092\u5909\u66f4\u3057\u3066\u81ea\u5206\u305f\u3061\u306e\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u3092\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u307b\u3068\u3093\u3069\u306e\u5834\u5408\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u6700\u7d42\u7684\u306bCobalt Strike\u306e\u30d3\u30fc\u30b3\u30f3\u3084\u30b9\u30c6\u30fc\u30b8\u30e3\u30fc\u306b\u306a\u308a\u307e\u3059\u304c\u3001\u6700\u8fd1\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u4e2d\u306b\u306fPyXie RAT\u306e\u66f4\u65b0\u3055\u308c\u305f\u30d0\u30fc\u30b8\u30e7\u30f3\u3060\u3063\u305f\u3082\u306e\u3082\u3042\u308a\u307e\u3059\u3002Vatet\u306f\u3001\u30a8\u30f3\u30bf\u30fc\u30d7\u30e9\u30a4\u30ba\u5168\u4f53\u306b\u5bfe\u3059\u308b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u306e\u524d\u89e6\u308c\u3067\u3042\u308b\u3053\u3068\u304c\u3088\u304f\u3042\u308a\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/04\/28\/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk\/\">2020\u5e744\u6708\u306eVatet\u30ed\u30fc\u30c0\u30fc\u306b\u95a2\u3059\u308bMicrosoft\u306e\u8a18\u8ff0<\/a>\u306b\u3088\u308b\u3068\u3001\u3053\u306e\u30ed\u30fc\u30c0\u30fc\u306f\u3001Cobalt Strike\u3092\u5b9f\u884c\u7528\u306e\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3059\u308b\u76ee\u7684\u3067\u30012018\u5e74\u306e11\u6708\u306b\u306f\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u305d\u306e\u5f8c\u3053\u306e\u30ed\u30fc\u30c0\u30fc\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30aa\u30fc\u30d7\u30f3 \u30bd\u30fc\u30b9 \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u8907\u6570\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u4f7f\u7528\u3057\u3066\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u3092\u30ed\u30fc\u30c9\u3057\u305f\u306e\u304c\u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 101.849%; height: 120px;\">\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 78.97%; height: 24px;\">\u30d0\u30fc\u30b8\u30e7\u30f3<\/td>\n<td style=\"width: 267.811%; height: 24px;\">\u521d\u56de\u78ba\u8a8d<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 78.97%; height: 24px;\">\u518d\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f<a href=\"https:\/\/github.com\/VincentJYZhang\/tetris-game\">Tetris\u30b2\u30fc\u30e0<\/a><\/td>\n<td style=\"width: 267.811%; height: 24px;\">2019-06-28<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 78.97%; height: 24px;\">\u518d\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f<a href=\"https:\/\/github.com\/wine-mirror\/wine\/tree\/master\/programs\/notepad\">Notepad<\/a><\/td>\n<td style=\"width: 267.811%; height: 24px;\">2020-05-03<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 78.97%; height: 24px;\">\u518d\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f\u30c7\u30b9\u30af\u30c8\u30c3\u30d7 \u30ab\u30b9\u30bf\u30de\u30a4\u30ba \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e<a href=\"https:\/\/github.com\/rainmeter\/rainmeter\">Rainmeter<\/a><\/td>\n<td style=\"width: 267.811%; height: 24px;\">2020-06-24<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 78.97%; height: 24px;\">\u518d\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fNotepad++<\/td>\n<td style=\"width: 267.811%; height: 24px;\">2020-09-24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88681: Vatet\u306e\u30d0\u30fc\u30b8\u30e7\u30f3<\/em><\/span><\/p>\n<p>\u5f0a\u793e\u306e\u8abf\u67fb\u3067\u306f\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b\u304c\u4e00\u756a\u65e9\u3044\u3082\u306e\u30672019\u5e74\u306eVatet\u30b5\u30f3\u30d7\u30eb\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u3053\u306e\u4e9c\u7a2e\u306f\u3001\u4ee5\u964d\u4f55\u5ea6\u304b\u5909\u66f4\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Vatet\u306e\u6700\u521d\u671f\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u5206\u6790\u3059\u308b\u3068\u3001\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">\\\\<strong>{IP}<\/strong>\\<strong>{EPOCHTIME}<\/strong>\\<strong>{PAYLOAD}<\/strong>.dat<\/span>\u306e\u3088\u3046\u306a\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u306e\u30d1\u30b9\u3092\u4f7f\u7528\u3057\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5171\u6709\u3092\u901a\u3058\u3066\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3057\u304b\u3057\u3001\u5206\u6790\u3055\u308c\u305f\u6700\u65b0\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30c7\u30a3\u30b9\u30af\u304b\u3089\u30ed\u30fc\u30ab\u30eb\u3067\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u307e\u305f\u3001\u5b9f\u884c\u4e2d\u306b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c7\u30b3\u30fc\u30c9\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bXOR\u30ad\u30fc\u5185\u306e\u5909\u7570\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u5f0a\u793e\u306e\u8abf\u67fb\u3067\u306f\u3055\u3089\u306b\u3001Vatet\u30ed\u30fc\u30c0\u30fc\u304cPyXie\u3092\u30ed\u30fc\u30c9\u3067\u304d\u308b\u3088\u3046\u306b\u30da\u30a4\u30ed\u30fc\u30c9\u6a5f\u80fd\u3092\u62e1\u5927\u3057\u3001\u3055\u3089\u306b\u6700\u8fd1\u78ba\u8a8d\u3055\u308c\u305fCobalt Strike\u306e\u30d3\u30fc\u30b3\u30f3\u304a\u3088\u3073\u30b9\u30c6\u30fc\u30b8\u30e3\u30fc\u306e\u30ed\u30fc\u30c9\u3082\u53ef\u80fd\u306b\u306a\u3063\u305f\u3082\u306e\u3068\u5224\u65ad\u3057\u307e\u3057\u305f\u3002\u6700\u5f8c\u306b\u3001\u5f0a\u793e\u304c\u5206\u6790\u3057\u305fVatet\u30ed\u30fc\u30c0\u30fc\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5b9f\u884c\u7528\u306e\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3057\u305f\u5f8c\u3067\u6d88\u53bb\u3059\u308b\u3001\u30a2\u30f3\u30c1\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af\u6a5f\u80fd\u3092\u5f37\u5316\u3059\u308b\u6bb5\u968e\u3078\u3068\u9032\u5316\u3057\u59cb\u3081\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 876px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109461 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-14.png\" alt=\"Vatet\u306e\u5b9f\u884c\u30d5\u30ed\u30fc\u306f\u3001Vatet\u30ed\u30fc\u30c0\u30fc\u306b\u59cb\u307e\u308a\u3001PyXie Lite\u306e\u30ed\u30fc\u30c9\u3001\u307e\u305f\u306fCobalt Strike\u306e\u30ed\u30fc\u30c9\u3068\u305d\u308c\u306b\u7d9a\u304fDefray777\u306e\u30ed\u30fc\u30c9\u306b\u5206\u304b\u308c\u307e\u3059\u3002\" width=\"876\" height=\"465\" \/><figcaption class=\"wp-caption-text\">\u56f31: Vatet\u5b9f\u884c\u30d5\u30ed\u30fc<\/figcaption><\/figure>\n<p>\u3067\u306f\u3001Rainmeter\u306e\u60aa\u610f\u306e\u3042\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u4f7f\u7528\u3059\u308bVatet\u3092\u8a73\u7d30\u306b\u898b\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-109455-_75pitfxdps3w\"><\/a><strong>Vatet\u30ed\u30fc\u30c0\u30fc\u5185\u90e8\u306e\u52d5\u304d: Rainmeter\u306e\u5fa9\u7fd2<\/strong><\/h4>\n<p>Rainmeter\u306f\u3001\u300c\u30b9\u30ad\u30f3\u300d\u3092\u4f7f\u7528\u3057\u3066\u30e6\u30fc\u30b6\u30fc\u304c\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u30c7\u30b9\u30af\u30c8\u30c3\u30d7 \u30ab\u30b9\u30bf\u30de\u30a4\u30ba \u30c4\u30fc\u30eb\u3067\u3059\u3002\u6b63\u898f\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fRainmeter\u306f\u3001\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306e<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.exe<\/span>\u3068\u5bfe\u5fdc\u3059\u308bDLL\u306e<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u901a\u5e38\u3001<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u306f\u3001\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306e\u8aad\u307f\u8fbc\u307f\u3068\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u306e\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u652f\u63f4\u306b\u5bfe\u5fdc\u3057\u307e\u3059\u3002\u78ba\u8a8d\u3055\u308c\u305f\u72b6\u6cc1\u3067\u306f\u3001\u7f72\u540d\u3055\u308c\u305f\u6b63\u898f\u30d0\u30fc\u30b8\u30e7\u30f3\u306e<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.exe<\/span>\u3068\u60aa\u610f\u306e\u3042\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u306e<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u304c\u88ab\u5bb3\u3092\u53d7\u3051\u305f\u30b7\u30b9\u30c6\u30e0\u306b\u30b3\u30d4\u30fc\u3055\u308c\u3001Cobalt Strike\u30d3\u30fc\u30b3\u30f3\u3092\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3059\u308b\u305f\u3081\u306b\u3001\u7f72\u540d\u3055\u308c\u305f\u6b63\u898f\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u305f\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-109455-_yg6gdl9chfsr\"><\/a><strong>\u9759\u7684\u7279\u6027\u306e\u78ba\u8a8d<\/strong><\/h4>\n<p>\u5f0a\u793e\u306f\u307e\u305a\u3001\u7591\u308f\u3057\u3044<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.exe<\/span>\u30d5\u30a1\u30a4\u30eb\u3068<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u30d5\u30a1\u30a4\u30eb\u3092\u78ba\u8a8d\u3057\u3001<a href=\"https:\/\/github.com\/rainmeter\/rainmeter\">GitHub\u306e\u516c\u958b\u30da\u30fc\u30b8<\/a>\u306b\u3042\u308b\u30012019\u5e749\u6708\u306b\u516c\u5f0f\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305fRainmeter\u30a4\u30f3\u30b9\u30c8\u30fc\u30e9\u3092\u4f7f\u3063\u3066\u30b7\u30b9\u30c6\u30e0\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u306eRainmeter\u3068\u3001\u7591\u308f\u3057\u3044\u30d5\u30a1\u30a4\u30eb\u3092\u6bd4\u8f03\u3057\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.exe<\/span>\u3092\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d\u3001\u6c17\u306b\u306a\u308b\u3053\u3068\u306f\u3042\u307e\u308a\u898b\u3064\u304b\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002<a href=\"https:\/\/www.winitor.com\/\">PEStudio<\/a>\u3067\u4e21\u65b9\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u8abf\u67fb\u3059\u308b\u3068\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30b7\u30ca\u30ea\u30aa\u3067\u5fa9\u5143\u3055\u308c\u305f\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u6a19\u6e96\u306eRainmeter\u30a4\u30f3\u30b9\u30c8\u30fc\u30e9\u306b\u3088\u3063\u3066\u751f\u6210\u3055\u308c\u305f\u3082\u306e\u3068\u540c\u3058\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3060\u3063\u305f\u3053\u3068\u304cSHA256\u30cf\u30c3\u30b7\u30e5\u3092\u3082\u3068\u306b\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u307e\u305f\u3001\u3069\u3061\u3089\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3082\u3001\u540c\u3058\u6709\u52b9\u306a\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\u3092\u6301\u3063\u3066\u3044\u305f\u3053\u3068\u3082\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109463 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-15.png\" alt=\"\u9759\u7684\u7279\u6027\u306e\u521d\u671f\u6bd4\u8f03\u3092\u793a\u3059\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 \" width=\"900\" height=\"304\" \/><figcaption class=\"wp-caption-text\">\u56f32: \u300crainmeter.exe\u300d\u306e\u9759\u7684\u7279\u6027\u306e\u521d\u671f\u6bd4\u8f03<\/figcaption><\/figure>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u6bd4\u8f03\u3057\u305f\u3068\u3053\u308d\u3001\u591a\u304f\u306e\u6c17\u306b\u306a\u308b\u70b9\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u307e\u305a\u3001\u30cf\u30c3\u30b7\u30e5\u304c\u9806\u756a\u306b\u4e26\u3093\u3067\u3044\u306a\u304b\u3063\u305f\u305f\u3081\u3001\u660e\u3089\u304b\u306b2\u3064\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u540c\u3058\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u30d5\u30a1\u30a4\u30eb\u306e\u30b5\u30a4\u30ba\u306f2\u3064\u306e\u30b5\u30f3\u30d7\u30eb\u9593\u3067\u5927\u304d\u304f\u7570\u306a\u3063\u3066\u304a\u308a\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u65e5\u4ed8\u3082\u307e\u3063\u305f\u304f\u5225\u306e\u3082\u306e\u3067\u3057\u305f\u3002\u307e\u305f\u3001\u30a4\u30f3\u30dd\u30fc\u30c8\u3001\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3001\u6587\u5b57\u5217\u3001\u305d\u306e\u4ed6\u306e\u30d7\u30ed\u30d1\u30c6\u30a3\u306b\u3044\u304f\u3064\u304b\u306e\u3070\u3089\u3064\u304d\u304c\u3042\u308a\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001\u60aa\u610f\u304c\u7591\u308f\u308c\u308bDLL\u306b\u306f\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\u304c\u306a\u3055\u308c\u3066\u304a\u3089\u305a\u3001\u6b63\u898f\u306eRainmeter DLL\u3067\u306f\u898b\u3089\u308c\u306a\u3044\u8ffd\u52a0\u30bb\u30af\u30b7\u30e7\u30f3\u304c\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109465 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-16.png\" alt=\"rainmeter.dll\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u6bd4\u8f03\u3057\u305f\u3068\u3053\u308d\u3001\u3053\u3053\u3067\u793a\u3059\u3088\u3046\u306b\u3001\u591a\u304f\u306e\u6c17\u306b\u306a\u308b\u70b9\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u60aa\u610f\u304c\u7591\u308f\u308c\u308bDLL\u306b\u306f\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\u304c\u306a\u3055\u308c\u3066\u304a\u3089\u305a\u3001\u6b63\u898f\u306eRainmeter DLL\u3067\u306f\u898b\u3089\u308c\u306a\u3044\u8ffd\u52a0\u30bb\u30af\u30b7\u30e7\u30f3\u304c\u3042\u308a\u307e\u3057\u305f\u3002 \" width=\"900\" height=\"310\" \/><figcaption class=\"wp-caption-text\">\u56f33: \u300crainmeter.dll\u300d\u306e2\u3064\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u6bd4\u8f03<\/figcaption><\/figure>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109467 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-17.png\" alt=\"\u3053\u306e\u56f3\u306f\u3001rainmeter.dll\u30b5\u30f3\u30d7\u30eb\u9593\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u6bd4\u8f03\u3092\u8a73\u7d30\u306b\u8868\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u60aa\u610f\u304c\u7591\u308f\u308c\u308bDLL\u306b\u306f\u3001\u6b63\u898f\u306eRainmeter DLL\u3067\u306f\u898b\u3089\u308c\u306a\u3044\u8ffd\u52a0\u30bb\u30af\u30b7\u30e7\u30f3\u304c\u3042\u308a\u307e\u3057\u305f\u3002\" width=\"900\" height=\"382\" \/><figcaption class=\"wp-caption-text\">\u56f34: \u300crainmeter.dll\u300d\u30b5\u30f3\u30d7\u30eb\u9593\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u6bd4\u8f03<\/figcaption><\/figure>\n<p><a href=\"https:\/\/github.com\/rainmeter\/rainmeter\">Rainmeter\u306e\u30b3\u30fc\u30c9\u30d9\u30fc\u30b9<\/a>\u304cGNU General Public License v2.0\u306e\u9069\u7528\u3092\u53d7\u3051\u305fGitHub\u3067\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u306f\u3001\u7559\u610f\u3059\u3079\u304d\u91cd\u8981\u306a\u30dd\u30a4\u30f3\u30c8\u3067\u3059\u3002\u3053\u306e\u305f\u3081\u3001\u653b\u6483\u8005\u304c\u65e2\u5b58\u306e<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u30d5\u30a1\u30a4\u30eb\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u516c\u7136\u3068\u78ba\u8a8d\u3057\u3066\u5909\u66f4\u3057\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u3057\u3066\u3001\u5f0a\u793e\u306e\u8abf\u67fb\u3067\u78ba\u8a8d\u3055\u308c\u305f\u60aa\u610f\u304c\u7591\u308f\u308c\u308bDLL\u3092\u4f5c\u6210\u3067\u304d\u305f\u306e\u3060\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u3088\u3046\u306a\u6bd4\u8f03\u3092\u5b8c\u4e86\u3057\u3066Rainmeter DLL\u306b\u60aa\u610f\u304c\u3042\u308b\u53ef\u80fd\u6027\u3092\u78ba\u8a8d\u3057\u3066\u304b\u3089\u3001\u30b5\u30f3\u30d7\u30eb\u3092\u3088\u308a\u8a73\u7d30\u306b\u8abf\u67fb\u3059\u308b\u305f\u3081\u3001\u30c7\u30d0\u30c3\u30ac\u3092\u4f7f\u7528\u3057\u3066\u52d5\u7684\u5206\u6790\u3092\u884c\u3044\u307e\u3057\u305f\u3002<\/p>\n<h4><a id=\"post-109455-_jwg560r37r5b\"><\/a><strong>\u60aa\u610f\u306e\u3042\u308bRainmeter\u30b5\u30f3\u30d7\u30eb\u306e\u52d5\u7684\u5206\u6790<\/strong><\/h4>\n<p>\u3088\u308a\u8a73\u7d30\u306a\u8abf\u67fb\u3092\u884c\u3046\u30b5\u30f3\u30d7\u30eb\u3092\u7279\u5b9a\u3057\u305f\u306e\u3067\u3001\u6b63\u898f\u306eRainmeter\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u306e\u6bd4\u8f03\u3092\u3053\u3053\u3067\u505c\u6b62\u3057\u3001\u5fa9\u5143\u3055\u308c\u305f\u7591\u308f\u3057\u3044\u30b5\u30f3\u30d7\u30eb\u306e\u5206\u6790\u306b\u7740\u624b\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.exe<\/span>\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u3001\u8abf\u67fb\u306b\u3088\u3063\u3066\u5fa9\u5143\u3055\u308c\u305f<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u5206\u6790\u74b0\u5883\u306b\u914d\u7f6e\u3057\u3001Rainmeter\u306e\u30c7\u30d0\u30c3\u30b0\u3092\u59cb\u3081\u307e\u3057\u305f\u3002\u4e88\u60f3\u3057\u305f\u3068\u304a\u308a\u3001\u5206\u6790\u3092\u59cb\u3081\u3066\u3059\u3050<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.exe<\/span>\u306f<span style=\"font-family: 'courier new', courier, monospace;\">rainmeter.dll<\/span>\u3092\u30ed\u30fc\u30c9\u3057\u3001\u305d\u306e\u5f8c\u5e8f\u65701\u3067\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u305f\u95a2\u6570\u3092\u547c\u3073\u51fa\u3057\u307e\u3057\u305f\u3002\u5b9f\u884c\u3092\u7d9a\u3051\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">CreateFileA<\/span>\u306e\u547c\u3073\u51fa\u3057\u304c\u3042\u308a\u3001\u3053\u306e<span style=\"font-family: 'courier new', courier, monospace;\">CreateFileA<\/span>\u306e\u4e2d\u3067\u30b5\u30f3\u30d7\u30eb\u306f\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30d1\u30b9<span style=\"font-family: 'courier new', courier, monospace;\">C:\\Windows\\help\\options.dat<\/span>\u3092\u63a2\u3057\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109469 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-18.png\" alt=\"\u30b5\u30f3\u30d7\u30eb\u306fCreateFileA\u3092\u547c\u3073\u51fa\u3057\u3066\u3001\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30d1\u30b9\u300cC:\\Windows\\help\\options.dat\u300d\u3092\u63a2\u3057\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"50\" \/><figcaption class=\"wp-caption-text\">\u56f35: \u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30d1\u30b9\u3092\u63a2\u3057\u3066\u300cCreateFileA\u300d\u3092\u547c\u3073\u51fa\u3057<\/figcaption><\/figure>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">CreateFileA<\/span>\u3092\u547c\u3073\u51fa\u3057\u305f\u5f8c\u3001<span style=\"font-family: 'courier new', courier, monospace;\">CreateFileA<\/span>\u547c\u3073\u51fa\u3057\u306e\u7d50\u679c\u3068<span style=\"font-family: 'courier new', courier, monospace;\">FFFFFFFF<\/span>\u3092\u6bd4\u8f03\u3057\u3001\u30d5\u30a1\u30a4\u30eb\u306b\u5bfe\u3057\u3066\u6709\u52b9\u306a\u30cf\u30f3\u30c9\u30eb\u304c\u3042\u308b\u304b\u3069\u3046\u304b\u3092\u5224\u65ad\u3057\u307e\u3059\u3002\u6709\u52b9\u306a\u30cf\u30f3\u30c9\u30eb\u304c\u306a\u3044\u5834\u5408\u306f\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u7d42\u4e86\u3057\u307e\u3059\u3002<\/p>\n<p>\u5143\u3005\u3001\u60aa\u610f\u306e\u3042\u308bRainmeter\u30b5\u30f3\u30d7\u30eb\u306e\u5206\u6790\u306b<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u304c\u5fc5\u8981\u3067\u3042\u308b\u304b\u3069\u3046\u304b\u306f\u306f\u3063\u304d\u308a\u3057\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002<span style=\"font-family: 'courier new', courier, monospace;\">.dat<\/span>\u30d5\u30a1\u30a4\u30eb\u306f\u901a\u5e38\u306eRainmeter\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u306f\u542b\u307e\u308c\u3066\u3044\u306a\u3044\u304b\u3089\u3067\u3059\u3002\u3057\u304b\u3057\u3001\u5206\u6790\u3092\u7d99\u7d9a\u3059\u308b\u305f\u3081\u3001<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u5fa9\u5143\u3057\u307e\u3057\u305f\u3002\u60f3\u5b9a\u3057\u305f\u5834\u6240\u306b\u300cdat\u300d\u30d5\u30a1\u30a4\u30eb\u304c\u914d\u7f6e\u3055\u308c\u308b\u3068\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u306f\u30d2\u30fc\u30d7\u306b\u30b9\u30da\u30fc\u30b9\u3092\u5272\u308a\u5f53\u3066\u3066<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u30e1\u30e2\u30ea\u306b\u8aad\u307f\u8fbc\u307f\u307e\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u30e1\u30e2\u30ea\u306b\u8aad\u307f\u8fbc\u307e\u308c\u308b\u3068\u3001\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u5bfe\u3057\u3066\u5024<span style=\"font-family: 'courier new', courier, monospace;\">FE<\/span>\u3068\u306eXOR\u6f14\u7b97\u3092\u884c\u3044\u3001\u7b2c1\u6bb5\u968e\u306e\u30c7\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109471 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-19.png\" alt=\"options.dat\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u30e1\u30e2\u30ea\u306b\u8aad\u307f\u8fbc\u307e\u308c\u308b\u3068\u3001\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u5bfe\u3057\u3066\u5024FE\u3092\u4f7f\u3063\u3066XOR\u6f14\u7b97\u3092\u3092\u884c\u3044\u3001\u7b2c1\u6bb5\u968e\u306e\u30c7\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"259\" \/><figcaption class=\"wp-caption-text\">\u56f36: \u6700\u521d\u306eXOR\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30d7<\/figcaption><\/figure>\n<p>\u6700\u521d\u306e\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u304c\u5b8c\u4e86\u3059\u308b\u3068\u3001\u60aa\u610f\u306e\u3042\u308bRainmeter\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306f<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u306b\u5bfe\u3059\u308b\u30cf\u30f3\u30c9\u30eb\u3092\u30af\u30ed\u30fc\u30ba\u3057\u307e\u3059\u3002\u30d7\u30ed\u30b0\u30e9\u30e0\u304c<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u306b\u5bfe\u3059\u308b\u30cf\u30f3\u30c9\u30eb\u3092\u30af\u30ed\u30fc\u30ba\u3059\u308b\u3068\u3001dat\u30d5\u30a1\u30a4\u30eb\u306f\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u304b\u3089\u6d88\u53bb\u3055\u308c\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u5206\u6790\u3092\u76ee\u7684\u3068\u3057\u305f<span style=\"font-family: 'courier new', courier, monospace;\">.dat<\/span>\u30d5\u30a1\u30a4\u30eb\u306e\u5fa9\u5143\u3092\u59a8\u3052\u308b\u305f\u3081\u306b\u5229\u7528\u3055\u308c\u308b\u3001\u7d44\u307f\u8fbc\u307f\u306e\u5206\u6790\u56de\u907f\u624b\u6cd5\u3067\u3059\u3002\u3053\u306e\u6642\u70b9\u3067\u306f\u307e\u3060\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u306b\u8aad\u307f\u8fbc\u307e\u308c\u305f\u30c7\u30fc\u30bf\u306f\u3001\u30b3\u30fc\u30c9\u3092\u8a8d\u8b58\u3067\u304d\u306a\u3044Blob\u306e\u72b6\u614b\u3067\u3059\u3002\u3057\u304b\u3057\u3001XOR\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u7d42\u4e86\u6642\u306e<span style=\"font-family: 'courier new', courier, monospace;\">CALL EBX<\/span>\u547d\u4ee4\u306b\u3088\u3063\u3066\u3001\u76f4\u8fd1\u306b\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306e\u5b9f\u884c\u306b\u79fb\u308a\u307e\u3059\u3002\u305d\u306e\u5f8c\u9006\u30a2\u30bb\u30f3\u30d6\u30eb\u8868\u793a\u3055\u308c\u305f<span style=\"font-family: 'courier new', courier, monospace;\">EBX<\/span>\u306f\u3001\u3053\u306e\u30c7\u30fc\u30bf\u304c\u6709\u52b9\u306a\u30b3\u30fc\u30c9\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u3053\u307e\u3067\u306e\u5206\u6790\u3067\u3001Rainmeter\u306f<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c7\u30b3\u30fc\u30c9\u3057\u3001\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u305d\u306e\u5f8c\u306e\u5206\u6790\u3067\u3001\u3053\u308c\u3067Vatet\u30ed\u30fc\u30c0\u30fc\u30eb\u30fc\u30c1\u30f3\u306f\u7d42\u4e86\u3057\u3001\u5b9f\u884c\u304cCobalt Strike\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u30ed\u30fc\u30c0\u30fc\u306b\u79fb\u3063\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109473 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-20.png\" alt=\"XOR\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u306e\u7d42\u4e86\u6642\u306b\u3001CALL EBX\u547d\u4ee4\u306b\u3088\u3063\u3066\u3001\u76f4\u8fd1\u306b\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306e\u5b9f\u884c\u306b\u79fb\u308a\u307e\u3059\u3002\u3053\u306e\u30c7\u30fc\u30bf\u306f\u6709\u52b9\u306a\u30b3\u30fc\u30c9\u3067\u3059\u3002\u305d\u306e\u5f8c\u306e\u5206\u6790\u3067\u3001\u3053\u308c\u304cVatet\u30ed\u30fc\u30c0\u30fc\u30eb\u30fc\u30c1\u30f3\u306e\u7d42\u4e86\u3060\u3063\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002 \" width=\"900\" height=\"149\" \/><figcaption class=\"wp-caption-text\">\u56f37: XOR\u30c7\u30b3\u30fc\u30c9\u5f8c\u306e\u6709\u52b9\u306a\u30b3\u30fc\u30c9\u306e\u5b9f\u884c\u306b\u79fb\u884c<\/figcaption><\/figure>\n<p>\u3053\u306e\u6642\u70b9\u3067\u3001Vatet\u306e\u30ed\u30fc\u30c7\u30a3\u30f3\u30b0\u30e1\u30ab\u30cb\u30ba\u30e0\u304c\u5b8c\u4e86\u3057\u305f\u3053\u3068\u306f\u308f\u304b\u308a\u307e\u3057\u305f\u304c\u3001\u6700\u5f8c\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306eID\u3092\u691c\u8a3c\u3057\u305f\u304b\u3063\u305f\u306e\u3067\u5206\u6790\u3092\u7d9a\u3051\u307e\u3057\u305f\u3002\u5b9f\u884c\u304c\u3055\u3089\u306b\u9032\u3080\u3068\u30012\u756a\u76ee\u306e\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u304c\u3042\u308a\u3001\u5225\u306e\u52d5\u7684XOR\u30eb\u30fc\u30d7\u3092\u4f7f\u7528\u3057\u3066\u5b9f\u884c\u53ef\u80fd\u30b3\u30fc\u30c9\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u30c7\u30b3\u30fc\u30c9\u3057\u3001\u66f8\u304d\u63db\u3048\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u30eb\u30fc\u30c1\u30f3\u306b\u899a\u3048\u306e\u3042\u308b\u65b9\u306f\u3001Cobalt Strike\u306e\u30c7\u30b3\u30fc\u30c9\u30e1\u30ab\u30cb\u30ba\u30e0\u306b\u304a\u6c17\u4ed8\u304d\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002\u3053\u306e\u30eb\u30fc\u30c1\u30f3\u3067\u306f\u307e\u305a\u3001\u30a4\u30f3\u30dd\u30fc\u30c8\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30b3\u30fc\u30c9\u306e\u6700\u521d\u306e4\u30d0\u30a4\u30c8\u306b\u5bfe\u3059\u308b\u30dd\u30a4\u30f3\u30bf\u3092\u53d6\u5f97\u3057\u3001\u6700\u521d\u306eXOR\u30ad\u30fc\u306b\u30bb\u30c3\u30c8\u3057\u307e\u3059\u3002\u6b21\u306b\u3053\u306e\u30b3\u30fc\u30c9\u306f\u30011\u5ea6\u306b4\u30d0\u30a4\u30c8\u3092\u51e6\u7406\u3059\u308b\u30eb\u30fc\u30d7\u3092\u5b9f\u884c\u3057\u3001\u6700\u521d\u306eXOR\u30ad\u30fc\u3092\u4f7f\u7528\u3057\u3066\u30a4\u30f3\u30dd\u30fc\u30c8\u3055\u308c\u305f\u30b3\u30fc\u30c9\u306bXOR\u6f14\u7b97\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u30eb\u30fc\u30d7\u306f\u6b21\u306b\u3001XOR\u6f14\u7b97\u5f8c\u306e\u5024\u3092\u30c7\u30fc\u30bf\u30bb\u30b0\u30e1\u30f3\u30c8\u306b\u623b\u3057\u3001\u7d9a\u3044\u3066\u65b0\u3057\u3044XOR\u30ad\u30fc\u3092\u30bb\u30c3\u30c8\u3057\u307e\u3059\u3002\u65b0\u3057\u3044XOR\u30ad\u30fc\u306f\u3001\u73fe\u5728\u306e\u30ad\u30fc\u3067\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5024\u3092\u4f7f\u7528\u3057\u3066\u73fe\u5728\u306eXOR\u30ad\u30fc\u306b\u5bfe\u3057\u3066XOR\u6f14\u7b97\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u6c7a\u5b9a\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30eb\u30fc\u30d7\u304c\u7d42\u4e86\u3059\u308b\u3068\u3001\u30b5\u30f3\u30d7\u30eb\u306f<span style=\"font-family: 'courier new', courier, monospace;\">JMP ECX<\/span>\u3092\u4f7f\u7528\u3057\u3066\u3001\u76f4\u8fd1\u306b\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u306a\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u5b9f\u884c\u3092\u79fb\u3057\u307e\u3059\u3002<\/p>\n<figure style=\"width: 830px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109475 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-21.png\" alt=\"Vatet\u30ed\u30fc\u30c0\u30fc\u306e2\u756a\u76ee\u306e\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u3067\u306f\u3001\u5225\u306e\u52d5\u7684XOR\u30eb\u30fc\u30d7\u3092\u4f7f\u7528\u3057\u3066\u3001\u5b9f\u884c\u53ef\u80fd\u30b3\u30fc\u30c9\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u30c7\u30b3\u30fc\u30c9\u3068\u66f8\u304d\u63db\u3048\u304c\u884c\u308f\u308c\u307e\u3059\u3002 \" width=\"830\" height=\"835\" \/><figcaption class=\"wp-caption-text\">\u56f38: 2\u756a\u76ee\u306e\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30d7\u306e\u958b\u59cb\u3002\u30c0\u30f3\u30d71\u306e\u30e1\u30e2\u30ea\u9818\u57df\u306b\u6ce8\u76ee\u3002<\/figcaption><\/figure>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109477 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-22.png\" alt=\"Vatet\u30ed\u30fc\u30c0\u30fc\u306e2\u756a\u76ee\u306e\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u304c\u5b8c\u4e86\u3057\u305f\u3089\u3001\u30c0\u30f3\u30d72\u306e\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u306a\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u6ce8\u76ee\u3057\u3066\u304f\u3060\u3055\u3044\u3002\" width=\"900\" height=\"759\" \/><figcaption class=\"wp-caption-text\">\u56f39: 2\u756a\u76ee\u306e\u30c7\u30b3\u30fc\u30c9\u30eb\u30fc\u30c1\u30f3\u306e\u5b8c\u4e86\u5f8c\u3001\u30c0\u30f3\u30d72\u306e\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u306a\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u6ce8\u76ee\u3002<\/figcaption><\/figure>\n<p>\u3053\u3053\u307e\u3067\u306e\u5206\u6790\u3067\u3001<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u306b\u542b\u307e\u308c\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u306f\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u3067\u3042\u308a\u3001\u305d\u306e\u5f8c\u52d5\u7684XOR\u30eb\u30fc\u30c1\u30f3\u3067\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3001Rainmeter\u306e\u30d7\u30ed\u30bb\u30b9\u30e1\u30e2\u30ea\u306e\u5b9f\u884c\u53ef\u80fd\u30b3\u30fc\u30c9\u3092\u4f5c\u308a\u51fa\u3059\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u3046\u3057\u3066\u3001\u30e1\u30e2\u30ea\u3067\u5229\u7528\u3067\u304d\u308b<span style=\"font-family: 'courier new', courier, monospace;\">options.dat<\/span>\u304b\u3089\u3001XOR\u6f14\u7b97\u51e6\u7406\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30b3\u30fc\u30c9\u306b\u3088\u308b\u5b9f\u884c\u53ef\u80fd\u306a\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u78ba\u4fdd\u3067\u304d\u305f\u306e\u3067\u3001<a href=\"https:\/\/x64dbg.com\/#start\">x64bdg<\/a>\u5185\u306e\u30e1\u30e2\u30ea \u30de\u30c3\u30d7 \u30bb\u30af\u30b7\u30e7\u30f3\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u30c0\u30f3\u30d7\u306b\u51fa\u529b\u3057\u3001\u3053\u306e\u30b3\u30fc\u30c9\u306e\u6a5f\u80fd\u3092\u660e\u3089\u304b\u306b\u3059\u308b\u305f\u3081\u5206\u6790\u3092\u9032\u3081\u307e\u3059\u3002<\/p>\n<p>\u5b9f\u884c\u53ef\u80fd\u30b3\u30fc\u30c9\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u30c0\u30f3\u30d7\u306b\u79fb\u52d5\u3057\u3001\u52d5\u7684\u5206\u6790\u306e\u7d50\u679c\u3068\u306e\u660e\u3089\u304b\u306a\u76f8\u95a2\u304c\u898b\u3089\u308c\u308b\u304b\u3069\u3046\u304b\u3092\u5224\u65ad\u3059\u308b\u305f\u3081\u3001\u6587\u5b57\u5217\u306e\u5206\u6790\u3092\u884c\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u5206\u6790\u306e\u4e2d\u3067\u3001<span style=\"font-family: 'courier new', courier, monospace;\">beacon.dll<\/span>\u306e\u53c2\u7167\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u3053\u306eDLL\u306f\u3001\u307b\u3068\u3093\u3069\u306e\u5834\u5408\u3001Cobalt Strike\u30d3\u30fc\u30b3\u30f3\u306eDLL\u30d0\u30fc\u30b8\u30e7\u30f3\u306b\u5bfe\u5fdc\u4ed8\u3051\u3089\u308c\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u5206\u96e2\u3055\u308c\u305fPE\u3092PeStudio\u306b\u30ed\u30fc\u30c9\u3057\u305f\u3068\u3053\u308d\u3001\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u95a2\u6570\u306e<span style=\"font-family: 'courier new', courier, monospace;\">_ReflectiveLoader@4<\/span>\u3092\u7d9a\u3044\u3066\u53c2\u7167\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u793a\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u306e\u95a2\u6570\u306f\u3001Cobalt Strike\u306e\u65e2\u77e5\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u95a2\u6570\u3067\u3059\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109479 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-23.png\" alt=\"\u5206\u96e2\u3055\u308c\u305fPE\u3092PeStudio\u306b\u30ed\u30fc\u30c9\u3057\u305f\u3068\u3053\u308d\u3001\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u95a2\u6570\u306e_ReflectiveLoader@4\u3092\u53c2\u7167\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u793a\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u306e\u95a2\u6570\u306f\u3001Cobalt Strike\u306e\u65e2\u77e5\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u95a2\u6570\u3067\u3059\u3002 \" width=\"900\" height=\"617\" \/><figcaption class=\"wp-caption-text\">\u56f310: PeStudio\u3067\u62bd\u51fa\u3055\u308c\u305fPE\u3092\u5206\u6790<\/figcaption><\/figure>\n<p>\u62bd\u51fa\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u304cCobalt Strike\u30d3\u30fc\u30b3\u30f3\u3067\u3042\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306b\u3001Cobalt Strike\u30d3\u30fc\u30b3\u30f3\u306e\u89e3\u6790\u30c4\u30fc\u30eb\u3092\u4f7f\u7528\u3057\u3001\u30d3\u30fc\u30b3\u30f3\u306e\u8a2d\u5b9a\u3092\u30c7\u30b3\u30fc\u30c9\u3057\u3066\u30c0\u30f3\u30d7\u3092\u53d6\u5f97\u3057\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109481 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-24.png\" alt=\"\u30c7\u30b3\u30fc\u30c9\u304c\u5b8c\u4e86\u3057\u3066\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d\u3001\u3053\u306eCobalt Strike\u30d3\u30fc\u30b3\u30f3\u304b\u3089\u3001\u9069\u5fdc\u6027\u306e\u9ad8\u3044C2\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u7528\u3059\u308bCobalt Strike\u306eHTTPS\u30d3\u30fc\u30b3\u30f3\u304c\u6a19\u6e96\u7684\u306a\u65b9\u6cd5\u3067\u5b9f\u88c5\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"588\" \/><figcaption class=\"wp-caption-text\">\u56f311: Cobalt Strike\u30d3\u30fc\u30b3\u30f3\u306e\u8a2d\u5b9a<\/figcaption><\/figure>\n<p>\u78ba\u8a8d\u3055\u308c\u305fCobalt Strike\u30d3\u30fc\u30b3\u30f3\u304b\u3089\u3001\u9069\u5fdc\u6027\u306e\u9ad8\u3044C2\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u7528\u3059\u308bCobalt Strike\u306eHTTPS\u30d3\u30fc\u30b3\u30f3\u304c\u3001\u6a19\u6e96\u7684\u306a\u65b9\u6cd5\u3067\u5b9f\u88c5\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u3053\u306e\u30d3\u30fc\u30b3\u30f3\u3067\u306f\u3001harmjoy\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u305f<a href=\"https:\/\/raw.githubusercontent.com\/rsmudge\/Malleable-C2-Profiles\/master\/normal\/amazon.profile\">Amazon browsing traffic profile<\/a>\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u7d9a\u304d\u3092\u8aad\u3080: <a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/2\">\u6b21\u306e\u8a18\u4e8b: \u300cPyXie Lite\u300d<\/a><\/p>\n<p><!--nextpage--><\/p>\n<h2><a id=\"post-109455-_qo7r73oluyu7\"><\/a>\u6b21\u306e\u8a18\u4e8b: \u300cPyXie Lite\u300d<\/h2>\n<p>\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u306b\u3064\u3044\u3066\u306f\u3001<a href=\"https:\/\/blogs.blackberry.com\/en\/2019\/12\/meet-pyxie-a-nefarious-new-python-rat\">2019\u5e7412\u6708<\/a>\u306bBlackBerry Cylance\u304c\u8a73\u3057\u304f\u8aac\u660e\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u3053\u3067\u306f\u4e3b\u306b\u3001\u66f4\u65b0\u3055\u308c\u305f\u4e9c\u7a2e\u306b\u3064\u3044\u3066\u3001\u305d\u3057\u3066\u5f0a\u793e\u304c\u78ba\u8a8d\u3057\u305f\u91cd\u8981\u306a\u5909\u66f4\u70b9\u3092\u3044\u304f\u3064\u304b\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n<p>\u5909\u66f4\u70b9\u306b\u306f\u6b21\u306e\u3088\u3046\u306a\u3082\u306e\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u5f37\u56fa\u306b\u306a\u3063\u305f\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf<\/li>\n<li>\u65b0\u305f\u306b\u30de\u30c3\u30d4\u30f3\u30b0\u3057\u76f4\u3055\u308c\u305f\u30aa\u30da\u30b3\u30fc\u30c9\u30c6\u30fc\u30d6\u30eb<\/li>\n<li>\u30c7\u30fc\u30bf\u7a83\u76d7\u304a\u3088\u3073\u5075\u5bdf\u30c4\u30fc\u30eb\u3068\u3057\u3066\u306e\u518d\u5229\u7528<\/li>\n<li>\u5185\u90e8\u30b5\u30fc\u30d0\u30fc\u306b\u3088\u308b\u30c7\u30fc\u30bf\u306e\u6f0f\u51fa<\/li>\n<\/ul>\n<p>\u30b3\u30fc\u30c9\u30d9\u30fc\u30b9\u304c\u5927\u5e45\u306b\u5c0f\u3055\u304f\u306a\u3063\u305f\u305f\u3081\u3001\u5f0a\u793e\u3067\u306f\u3053\u306e\u4e9c\u7a2e\u3092PyXie Lite\u3068\u547c\u3093\u3067\u3044\u307e\u3059\u304c\u3001\u540d\u524d\u306b\u60d1\u308f\u3055\u308c\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002\u304b\u306a\u308a\u306e\u5a01\u529b\u3067\u3059\u3002<\/p>\n<h4><a id=\"post-109455-_6xcb4vjgo4el\"><\/a><strong>\u30ed\u30fc\u30c0\u30fc<\/strong><\/h4>\n<p>\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u3092\u30ed\u30fc\u30c9\u3059\u308b\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Goopdate.dll<\/span>\u304a\u3088\u3073<span style=\"font-family: 'courier new', courier, monospace;\">LMIGuardianDll.dll<\/span>\u306e\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u3088\u304f\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u5f0a\u793e\u304c\u5206\u6790\u3057\u305f\u6700\u8fd1\u306e\u4e9c\u7a2e\u3067\u306f\u3001Vatet\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u5fa9\u53f7\u3055\u308c\u305fVatet\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u306f\u3001\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u30ed\u30fc\u30c0\u30fc\u306b\u3088\u3063\u3066\u8ffd\u52a0\u3055\u308c\u308bPyXie\u306e\u7b2c1\u6bb5\u968e\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u30ed\u30fc\u30c0\u30fc\u306f\u3001PyXie\u306e\u7b2c1\u6bb5\u968e\u3092\u30e1\u30e2\u30ea\u306b\u30de\u30c3\u30d4\u30f3\u30b0\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u30ed\u30fc\u30c0\u30fc\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">MurmurHash3<\/span>\u30cf\u30c3\u30b7\u30e5\u3092\u5229\u7528\u3057\u3066\u3001\u30d7\u30ed\u30bb\u30b9\u5b9f\u884c\u6642\u306b\u5fc5\u8981\u306aAPI\u3092\u7279\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 100.759%;\">\n<tbody>\n<tr>\n<td style=\"width: 28.6604%;\"><strong>dll<\/strong><\/td>\n<td style=\"width: 38.0062%;\"><strong>\u95a2\u6570<\/strong><\/td>\n<td style=\"width: 426.435%;\"><strong>API\u30cf\u30c3\u30b7\u30e5<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.6604%;\">Kernel32.dll<\/td>\n<td style=\"width: 38.0062%;\">GetProcAddress<\/td>\n<td style=\"width: 426.435%;\">0x261C88ED<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.6604%;\">Kernel32.dll<\/td>\n<td style=\"width: 38.0062%;\">VirtualAlloc<\/td>\n<td style=\"width: 426.435%;\">0xC17E7EB2<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.6604%;\">Kernel32.dll<\/td>\n<td style=\"width: 38.0062%;\">LoadLibraryExA<\/td>\n<td style=\"width: 426.435%;\">0x4B9B30B9<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><em>\u88682: MurmurHash3 API\u30cf\u30c3\u30b7\u30e5<\/em><\/p>\n<h4><a id=\"post-109455-_ie4iusq6vrb6\"><\/a><strong>\u7b2c1\u6bb5\u968e<\/strong><\/h4>\n<p>\u7b2c1\u6bb5\u968e\u306e\u76ee\u7684\u306f\u3001\u7b2c2\u6bb5\u968e\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u3057\u3066\u30e1\u30e2\u30ea\u5185\u3067\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u3059\u3002<\/p>\n<h6><a id=\"post-109455-_ksv0olun6j6o\"><\/a><strong>\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9<\/strong><\/h6>\n<p>\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u306f\u3001\u8907\u6570\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u540c\u6642\u5b9f\u884c\u3092\u9632\u3050\u305f\u3081\u306b\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002\u6b21\u306e\u30ed\u30b8\u30c3\u30af\u304c\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">GetComputerNameA<\/span>\u3092\u547c\u3073\u51fa\u3057\u3066\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u540d\u3092\u53d6\u5f97\u3059\u308b\u3002\u5931\u6557\u3057\u305f\u5834\u5408\u3001<span style=\"font-family: 'courier new', courier, monospace;\">DEFAULTCOMPNAME<\/span>\u306b\u30d5\u30a9\u30fc\u30eb\u30d0\u30c3\u30af\u3059\u308b\u3002<\/li>\n<li>\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u540d\u306eMD5\u30cf\u30c3\u30b7\u30e5\u3092\u8a08\u7b97\u3059\u308b\u3002<\/li>\n<li>\u8a08\u7b97\u3055\u308c\u305f\u30cf\u30c3\u30b7\u30e5\u3068<span style=\"font-family: 'courier new', courier, monospace;\">0x2<\/span>\u3068\u306eXOR\u6f14\u7b97\u3092\u5b9f\u884c\u3059\u308b\u3002<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">StringFromGUID2<\/span>\u3067\u6f14\u7b97\u7d50\u679c\u3092\u6587\u5b57\u5217\u306b\u5909\u63db\u3059\u308b\u3002<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">CreateMutexW<\/span>\u3092\u547c\u3073\u51fa\u3057\u3001\u5909\u63db\u3055\u308c\u305f\u6587\u5b57\u5217\u3092\u4f7f\u3063\u3066\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f5c\u6210\u3059\u308b\u3002<\/li>\n<\/ul>\n<h6><a id=\"post-109455-_rtcx80iprc6k\"><\/a><strong>\u6587\u5b57\u5217\u306e\u6697\u53f7\u5316<\/strong><\/h6>\n<p>\u91cd\u8981\u306a\u610f\u5473\u3092\u6301\u3064\u6587\u5b57\u5217\u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u304a\u308a\u3001\u6697\u53f7\u5316\u306b\u306f\u3042\u308b\u30eb\u30fc\u30c1\u30f3\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305d\u306e\u30eb\u30fc\u30c1\u30f3\u306f\u3001\u6697\u53f7\u5316\u30c6\u30ad\u30b9\u30c8\u306e\u5404\u30d0\u30a4\u30c8\u5024\u306b\u30a4\u30f3\u30c7\u30c3\u30af\u30b9\u5024\u3092\u52a0\u7b97\u3057\u3001\u305d\u306e\u7d50\u679c\u3092<span style=\"font-family: 'courier new', courier, monospace;\">0x7F<\/span>(ASCII\u6587\u5b57\u30bb\u30c3\u30c8\u306e\u6700\u5927\u5024)\u3067\u30de\u30b9\u30af\u3057\u3001\u3055\u3089\u306b\u9577\u3055\u306e\u7b49\u3057\u3044\u30ad\u30fc\u3068\u306eXOR\u6f14\u7b97\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p><img  class=\"aligncenter wp-image-109523 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/Screen-Shot-2020-11-06-at-5.55.54-PM.png\" alt=\"Vatet\u30ed\u30fc\u30c0\u30fc\u306e\u6587\u5b57\u5217\u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3\u306e\u4f8b\" width=\"900\" height=\"539\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88683: \u6587\u5b57\u5217\u306e\u5fa9\u53f7\u4f8b<\/em><\/span><\/p>\n<h6><a id=\"post-109455-_ly2sx5gwryfy\"><\/a><strong>\u5fa9\u53f7\u3055\u308c\u305f\u6587\u5b57\u5217<\/strong><\/h6>\n<table style=\"width: 102.556%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">uiAccess=true\u201d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">-q -s {%S} -p %u<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">werfault.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">vsjitdebugger.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">dvdplay.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">onedrivesetup.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">openwith.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">%windir%\\syswow64\\<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">%windir%\\system32\\<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">kernel32.dll<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">KiUserExceptionDispatcher<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">RtlCreateUser<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">IsWow64Process<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\StringFileInfo\\%04x%04x\\ProductName<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88684: \u5fa9\u53f7\u3055\u308c\u305f\u7b2c1\u6bb5\u968e\u306e\u6587\u5b57\u5217<\/em><\/span><\/p>\n<h6><a id=\"post-109455-_u0eh98rbd8ce\"><\/a><strong>\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5fa9\u53f7\u5316<\/strong><\/h6>\n<p>\u6b21\u306e\u6bb5\u968e\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30d0\u30a4\u30ca\u30ea\u306e<span style=\"font-family: 'courier new', courier, monospace;\">.gfids<\/span>\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u3042\u308b\u6697\u53f7\u5316\u3055\u308c\u305f7z\u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u4ee5\u524dBlackBerry Cylance\u306e\u8a18\u4e8b\u3067\u53d6\u308a\u4e0a\u3052\u3089\u308c\u305f\u3001\u5909\u66f4\u3055\u308c\u305fRC4\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3067\u5fa9\u53f7\u3055\u308c\u307e\u3059\u3002\u5fa9\u53f7\u306b\u306f\u3001\u6b21\u306e\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30ad\u30fc\u3092\u4f7f\u7528\u3057\u307e\u3059: <span style=\"font-family: 'courier new', courier, monospace;\">2C01443389BDFC7330A3386981C43E154AE8B60EC6646D916F93D18137A53544<\/span><\/p>\n<figure style=\"width: 617px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109483 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-25.png\" alt=\"\u6b21\u306e\u6bb5\u968e\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30d0\u30a4\u30ca\u30ea\u306e.gfids\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u3042\u308b\u6697\u53f7\u5316\u3055\u308c\u305f7z\u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u3059\u3067\u306b\u5fa9\u53f7\u3055\u308c\u305f7z\u30a2\u30fc\u30ab\u30a4\u30d6\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"617\" height=\"84\" \/><figcaption class=\"wp-caption-text\">\u56f312: \u5fa9\u53f7\u3055\u308c\u305f7z\u30a2\u30fc\u30ab\u30a4\u30d6<\/figcaption><\/figure>\n<h6><a id=\"post-109455-_w504ogsardrf\"><\/a><strong>\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5b9f\u884c<\/strong><\/h6>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">OpenProcessToken<\/span>\u304a\u3088\u3073<span style=\"font-family: 'courier new', courier, monospace;\">GetTokenInformation<\/span>\u304c\u547c\u3073\u51fa\u3055\u308c\u3001<span style=\"font-family: 'courier new', courier, monospace;\">LocalSystem<\/span>\u30a2\u30ab\u30a6\u30f3\u30c8\u3067\u30d7\u30ed\u30bb\u30b9\u304c\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u3053\u306e\u78ba\u8a8d\u306f\u3001\u6b21\u306e\u6bb5\u968e\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5b9f\u884c\u65b9\u6cd5\u3092\u5224\u65ad\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">LocalSystem<\/span>\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u3068\u5224\u65ad\u3057\u305f\u5834\u5408\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001Windows\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u9078\u629e\u3055\u308c\u305f\u3001\u65b0\u305f\u306b\u4f5c\u6210\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306b\u633f\u5165\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u306f\u6b21\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u306b\u3057\u305f\u304c\u3063\u3066\u304a\u308a\u3001\u4fb5\u5bb3\u6307\u6a19\u306b\u4f7f\u3048\u307e\u3059\u3002<\/p>\n<pre class=\"lang:default decode:true \">-q -s {{GUID}} -p NUMBER<\/pre>\n<figure style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109485 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-26.png\" alt=\"LocalSystem\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u3068\u5224\u65ad\u3057\u305f\u5834\u5408\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001Windows\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u9078\u629e\u3055\u308c\u305f\u3001\u65b0\u305f\u306b\u4f5c\u6210\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306b\u633f\u5165\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u306f\u3001\u3053\u3061\u3089\u306b\u793a\u3059\u7279\u6709\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u306b\u5f93\u3044\u3001\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3068\u3057\u3066\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002 \" width=\"900\" height=\"648\" \/><figcaption class=\"wp-caption-text\">\u56f313: \u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u5f15\u6570<\/figcaption><\/figure>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">LocalSystem<\/span>\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u306a\u3044\u5834\u5408\u306f\u3001\u73fe\u5728\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u30e1\u30e2\u30ea\u9818\u57df\u5185\u3067\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-109455-_y92tpqiupsh4\"><\/a><strong>\u7b2c2\u6bb5\u968e<\/strong><\/h4>\n<p>\u7b2c2\u6bb5\u968e\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30ab\u30b9\u30bf\u30e0\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fPython\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u3067\u3059\u3002PyXie\u306e\u4ee5\u524d\u306e\u4e9c\u7a2e\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u305f\u3082\u306e\u3068\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h6><a id=\"post-109455-_kne836v7aob3\"><\/a><strong>\u8a2d\u5b9a<\/strong><\/h6>\n<p>\u8a2d\u5b9a\u306f\u3001zlib\u5727\u7e2e\u3055\u308c\u305fjson Blob\u306b\u4fdd\u5b58\u3055\u308c\u3066\u304a\u308a\u3001\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306e<span style=\"font-family: 'courier new', courier, monospace;\">.gfids<\/span>\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u3042\u308a\u307e\u3059\u3002\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u3068\u306f\u7570\u306a\u308a\u3001\u4eca\u56de\u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002\u5909\u6570<span style=\"font-family: 'courier new', courier, monospace;\">sys.builtin_json_cfg<\/span>\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">PySys_SetObject<\/span>\u3092\u547c\u3073\u51fa\u3057\u3066\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002\u5727\u7e2e\u3055\u308c\u3066\u3044\u308b\u8a2d\u5b9aBlob\u306f\u3001\u3053\u306e\u5909\u6570\u306b\u4fdd\u5b58\u3055\u308c\u3001\u305d\u306e\u5f8c\u6700\u7d42\u6bb5\u968e\u306ePython\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3067\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure style=\"width: 859px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109487 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-27.png\" alt=\"\u5909\u6570sys.builtin_json_cfg\u306f\u3001PySys_SetObject\u3092\u547c\u3073\u51fa\u3057\u3066\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002\u5727\u7e2e\u3055\u308c\u3066\u3044\u308b\u8a2d\u5b9aBlob\u306f\u3001\u3053\u306e\u5909\u6570\u306b\u4fdd\u5b58\u3055\u308c\u3001\u5f8c\u3067\u6700\u7d42\u6bb5\u968e\u306ePython\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3067\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002 \" width=\"859\" height=\"228\" \/><figcaption class=\"wp-caption-text\">\u56f314: sys.builtin_json_cfg\u5909\u6570\u306e\u4f5c\u6210<\/figcaption><\/figure>\n<h6><a id=\"post-109455-_jtpysmg0ze57\"><\/a><strong>\u5fa9\u53f7\u3055\u308c\u305f\u6587\u5b57\u5217<\/strong><\/h6>\n<p>\u7b2c2\u6bb5\u968e\u3067\u306f\u3001\u7b2c1\u6bb5\u968e\u3067\u8ff0\u3079\u305f\u3082\u306e\u3068\u540c\u3058\u6587\u5b57\u5217\u6697\u53f7\u5316\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 102.209%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">kernel32.dll<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">openwith.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">onedrivesetup.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">dvdplay.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">vsjitdebugger.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">werfault.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">-q -s {%S} -p %u<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">oleout32.dll<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">VariantClear<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">Mozilla\\Firefox<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">Mozilla\\Firefox\\profiles.ini<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">SOFTWARE\\Clients\\StartMenuInternet\\firefox.exe\\shell\\open\\command<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">I_CryptUIProtect<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cryptui.dll<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">RtlCreateUserThread<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">import core.modules.winapi_stubs as winapi_stubs<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">import core.zip_logs as zip_logs<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">import os<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">zip_logs.send_zip_log(winapi_stubs.get_self_executable_path(), os.getpid(), \u2018CERTS\u2019, r\u2019%s\u2019)<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">KiUserExceptionDispatcher<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">uiAccess=\u201dtrue\u201d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\StringFileInfo\\%04x%04x\\ProductName<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\VarFileInfo\\Translation<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\\\?\\globalroot\\systemroot\\system32\\drivers\\null.sys<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">SystemDrive<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">IsWow64Process<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">core.entry_point<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">zipimporter<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">memzipimport<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">libs_zip_ctx<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">start_bind_port<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88685: \u5fa9\u53f7\u3055\u308c\u305f\u7b2c2\u6bb5\u968e\u306e\u6587\u5b57\u5217<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_70kh1iakf82s\"><\/a><strong>\u6700\u7d42\u6bb5\u968e: Libs.zip<\/strong><\/h4>\n<p>\u6700\u7d42\u6bb5\u968e\u306ePyXie\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u306f\u3001\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306e\u30d0\u30a4\u30ca\u30ea\u5185\u306b\u7d44\u307f\u8fbc\u307e\u308c\u305f\u3001\u6697\u53f7\u5316\u3055\u308c\u305fZIP\u30d5\u30a1\u30a4\u30eb\u306b\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u3067\u306f\u3001\u30e1\u30e2\u30ea\u304b\u3089\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3092\u30a4\u30f3\u30dd\u30fc\u30c8\u3059\u308b\u305f\u3081\u306b<a href=\"https:\/\/github.com\/zyobi\/memzipimport\">memzipimport<\/a>\u30e9\u30a4\u30d6\u30e9\u30ea\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<h6><a id=\"post-109455-_czx1akq6jpx4\"><\/a><strong>PyXie Lite<\/strong><\/h6>\n<p>\u3053\u306e\u4e9c\u7a2e\u5185\u306e\u300c\u30b3\u30a2\u300d\u30e2\u30b8\u30e5\u30fc\u30eb\u304c41\u500b\u306e\u30d5\u30a1\u30a4\u30eb\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u308b\u306e\u306b\u5bfe\u3057\u3001\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u3067\u306f\u3001BlackBerry Cylance\u306e\u5206\u6790\u306b\u3088\u308b\u306879\u500b\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u76f8\u9055\u306f\u3001\u6b21\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u53d6\u308a\u4e0a\u3052\u308b\u6a5f\u80fd\u306e\u5909\u5316\u306b\u3088\u308b\u3082\u306e\u3067\u3059\u3002<\/p>\n<figure style=\"width: 899px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109489 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-28.png\" alt=\" \" width=\"899\" height=\"748\" \/><figcaption class=\"wp-caption-text\">\u56f315: \u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u306e\u30ea\u30b9\u30c8<\/figcaption><\/figure>\n<h6><strong><br \/>\n<\/strong><a id=\"post-109455-_7141qyirsuzf\"><\/a><strong>\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306e\u5f37\u5316<\/strong><\/h6>\n<p>\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3092\u7c21\u5358\u306b\u5206\u6790\u3057\u305f\u3068\u3053\u308d\u3001\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u3068\u540c\u69d8\u306b\u30d8\u30c3\u30c0\u304c\u53d6\u308a\u9664\u304b\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u307e\u305f\u3001\u30aa\u30da\u30b3\u30fc\u30c9\u30c6\u30fc\u30d6\u30eb\u304c\u518d\u5ea6\u5909\u66f4\u3055\u308c\u3066\u304a\u308a\u3001\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u304b\u3089\u5fa9\u5143\u3055\u308c\u305f\u30aa\u30da\u30b3\u30fc\u30c9\u306f\u3001\u3053\u306e\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u306e\u9006\u30b3\u30f3\u30d1\u30a4\u30eb\u306b\u306f\u4f7f\u7528\u3067\u304d\u306a\u304f\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 847px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109491 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-29.png\" alt=\"\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3092\u7c21\u5358\u306b\u5206\u6790\u3057\u305f\u3068\u3053\u308d\u3001\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u3068\u540c\u69d8\u306b\u30d8\u30c3\u30c0\u304c\u53d6\u308a\u9664\u304b\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u30aa\u30da\u30b3\u30fc\u30c9\u30c6\u30fc\u30d6\u30eb\u304c\u518d\u5ea6\u5909\u66f4\u3055\u308c\u3066\u304a\u308a\u3001\u4ee5\u524d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306ePyXie\u304b\u3089\u5fa9\u5143\u3055\u308c\u305f\u30aa\u30da\u30b3\u30fc\u30c9\u306f\u3001\u3053\u306e\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u306e\u9006\u30b3\u30f3\u30d1\u30a4\u30eb\u306b\u306f\u4f7f\u7528\u3067\u304d\u306a\u304f\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002 \" width=\"847\" height=\"373\" \/><figcaption class=\"wp-caption-text\">\u56f316: \u4ee5\u524d\u306ePyXie\u304b\u3089\u5fa9\u5143\u3055\u308c\u305f\u30aa\u30da\u30b3\u30fc\u30c9\u3092\u4f7f\u7528\u3057\u3066\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3092\u9006\u30b3\u30f3\u30d1\u30a4\u30eb\u3059\u308b\u8a66\u307f\u306f\u30a8\u30e9\u30fc\u306b\u7d42\u308f\u308b<\/figcaption><\/figure>\n<p>\u3053\u306e\u72b6\u6cc1\u306f\u7406\u89e3\u3057\u3064\u3064\u3082\u3001\u30aa\u30da\u30b3\u30fc\u30c9\u306e\u5fa9\u5143\u306b\u4f7f\u7528\u3067\u304d\u308b\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3092\u751f\u6210\u3067\u304d\u308b\u306e\u3067\u306f\u306a\u3044\u304b\u3068\u3044\u3046\u671b\u307f\u306b\u304b\u3051\u3066\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306bDeDrop\u306e<a href=\"https:\/\/github.com\/kholia\/dedrop\/blob\/master\/src\/dedrop\/all.py\">all.py<\/a>\u3092\u5f37\u5236\u7684\u306b\u30a4\u30f3\u30dd\u30fc\u30c8\u3057\u3066\u307f\u305f\u306e\u3067\u3059\u304c\u3001\u6b8b\u5ff5\u306a\u304c\u3089\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30a4\u30f3\u30dd\u30fc\u30c8\u3059\u308b\u3060\u3051\u3067\u306f\u3001\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306b\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3092\u51fa\u529b\u3055\u305b\u308b\u3053\u3068\u306f\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u3002<\/p>\n<p>\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u3092\u3088\u304f\u8abf\u3079\u3066\u307f\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">sys.dont_write_bytecode<\/span>\u5909\u6570\u304ctrue\u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u8a2d\u5b9a\u306f\u3001\u30e2\u30b8\u30e5\u30fc\u30eb\u304c\u30a4\u30f3\u30dd\u30fc\u30c8\u3055\u308c\u305f\u3068\u304d\u306b\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u304c\u30c7\u30a3\u30b9\u30af\u306b\u66f8\u304d\u51fa\u3055\u308c\u308b\u306e\u3092\u9632\u6b62\u3059\u308b\u52b9\u679c\u304c\u3042\u308a\u307e\u3059\u3002\u5206\u6790\u4f5c\u696d\u3092\u59a8\u3052\u308b\u305f\u3081\u306b\u3001\u958b\u767a\u8005\u304c\u610f\u56f3\u7684\u306b\u3053\u306e\u3088\u3046\u306a\u64cd\u4f5c\u3092\u3057\u305f\u3088\u3046\u306b\u898b\u3048\u307e\u3059\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109493 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-30.png\" alt=\"\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u3092\u3088\u304f\u8abf\u3079\u3066\u307f\u308b\u3068\u3001sys.dont_write_bytecode\u5909\u6570\u304ctrue\u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u8a2d\u5b9a\u306f\u3001\u30e2\u30b8\u30e5\u30fc\u30eb\u304c\u30a4\u30f3\u30dd\u30fc\u30c8\u3055\u308c\u305f\u3068\u304d\u306b\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u304c\u30c7\u30a3\u30b9\u30af\u306b\u66f8\u304d\u51fa\u3055\u308c\u308b\u306e\u3092\u9632\u6b62\u3059\u308b\u52b9\u679c\u304c\u3042\u308a\u307e\u3059\u3002 \" width=\"900\" height=\"31\" \/><figcaption class=\"wp-caption-text\">\u56f317: sys.dont_write_bytecode\u304ctrue\u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u308b<\/figcaption><\/figure>\n<h6><a id=\"post-109455-_6j5qe161p83y\"><\/a><strong>\u691c\u7d22\u9806\u5e8f\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u3066\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u3092\u30cf\u30a4\u30b8\u30e3\u30c3\u30af<\/strong><\/h6>\n<p>\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u3092\u5206\u6790\u3057\u3066\u3044\u308b\u9593\u306b\u3001\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u304c\u73fe\u5728\u306e\u4f5c\u696d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u591a\u6570\u306e\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u30ed\u30fc\u30c9\u3057\u3088\u3046\u3068\u8a66\u307f\u3066\u304a\u308a\u3001\u691c\u7d22\u9806\u5e8f\u306e\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u5bfe\u3057\u3066\u8106\u5f31\u3067\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109495 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-31.png\" alt=\"PyXie\u304c\u73fe\u5728\u306e\u4f5c\u696d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u591a\u6570\u306e\u30e2\u30b8\u30e5\u30fc\u30eb\u306e\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u3001\u691c\u7d22\u9806\u5e8f\u306e\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u5bfe\u3057\u3066\u8106\u5f31\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3059\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 \" width=\"900\" height=\"240\" \/><figcaption class=\"wp-caption-text\">\u56f318: \u73fe\u5728\u306e\u4f5c\u696d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u308bPyXie<\/figcaption><\/figure>\n<p>\u5f0a\u793e\u3067\u306f\u3001PyXie\u304c\u30a4\u30f3\u30dd\u30fc\u30c8\u3092\u8a66\u307f\u305f\u30e2\u30b8\u30e5\u30fc\u30eb\u306e1\u3064\u306b\u7c21\u5358\u306aPython\u30b7\u30a7\u30eb\u3092\u30c9\u30ed\u30c3\u30d7\u3057\u3066\u3001\u3053\u306e\u8106\u5f31\u6027\u3092\u6709\u5229\u306b\u5229\u7528\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306b\u81ea\u7531\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u305f\u306e\u3067\u3001<span style=\"font-family: 'courier new', courier, monospace;\">sys.dont_write_bytecode<\/span>\u5909\u6570\u3092\u4e0a\u66f8\u304d\u3057\u305f\u308a\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u30e2\u30b8\u30e5\u30fc\u30eb\u306e\u30aa\u30da\u30b3\u30fc\u30c9\u3092\u751f\u6210\u3057\u305f\u308a\u3001PyXie\u306e\u8a2d\u5b9a\u306e\u30c0\u30f3\u30d7\u307e\u3067\u53d6\u5f97\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109497 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-32.png\" alt=\"PyXie\u304c\u30a4\u30f3\u30dd\u30fc\u30c8\u3092\u8a66\u307f\u305f\u30e2\u30b8\u30e5\u30fc\u30eb\u306e1\u3064\u306b\u7c21\u5358\u306aPython\u30b7\u30a7\u30eb\u3092\u30c9\u30ed\u30c3\u30d7\u3057\u3066\u3001PyXie\u306e\u691c\u7d22\u9806\u5e8f\u306e\u8106\u5f31\u6027\u3092\u6709\u5229\u306b\u5229\u7528\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002 \" width=\"900\" height=\"424\" \/><figcaption class=\"wp-caption-text\">\u56f319: \u691c\u7d22\u9806\u5e8f\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u3066\u30a4\u30f3\u30bf\u30fc\u30d7\u30ea\u30bf\u306e\u5236\u5fa1\u6a5f\u80fd\u3092\u638c\u63e1<\/figcaption><\/figure>\n<p>\u79c1\u305f\u3061\u304c\u9078\u629e\u3057\u305f\u30e2\u30b8\u30e5\u30fc\u30eb\u306e\u30d0\u30a4\u30c8\u30b3\u30fc\u30c9\u3055\u3048\u51fa\u529b\u3067\u304d\u308c\u3070\u3001\u30de\u30c3\u30d4\u30f3\u30b0\u3057\u76f4\u3055\u308c\u305f\u30aa\u30da\u30b3\u30fc\u30c9\u306e\u5fa9\u5143\u3068PyXie\u306e\u9006\u30b3\u30f3\u30d1\u30a4\u30eb\u306f\u3054\u304f\u7c21\u5358\u3067\u3059\u3002\u3053\u306e\u4e9c\u7a2e\u306e\u30aa\u30da\u30b3\u30fc\u30c9\u306e\u30b3\u30d4\u30fc\u306f\u3001\u4ed8\u9332\u306b\u8a18\u8f09\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h6><a id=\"post-109455-_uqw9x1c1lli\"><\/a><strong>\u6a5f\u80fd<\/strong><\/h6>\n<p>\u3053\u308c\u307e\u3067\u306b\u8ff0\u3079\u305f\u3088\u3046\u306b\u3001PyXie Lite\u306f\u3001\u30c7\u30fc\u30bf\u306e\u53ce\u96c6\u3068\u6f0f\u51fa\u306e\u81ea\u52d5\u5316\u306b\u7126\u70b9\u3092\u5f53\u3066\u3066\u518d\u5229\u7528\u3055\u308c\u305f\u3082\u306e\u3067\u3059\u3002<\/p>\n<p>\u5b9f\u884c\u3092\u958b\u59cb\u3059\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">tempfile.NamedTemporaryFile()<\/span>\u30b3\u30de\u30f3\u30c9\u306e\u51fa\u529b\u306b\u57fa\u3065\u3044\u305f\u540d\u524d\u3092\u6301\u3064\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 100.138%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">%temp%\\<em>tmp1rjvhglo<\/em><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88686: \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u540d\u524d\u306e\u4f8b<\/em><\/span><\/p>\n<p>\u6b21\u306b\u3001PyXie\u5b9f\u884c\u6642\u306e\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u306b\u3088\u3063\u3066\u6c7a\u5b9a\u3055\u308c\u308b\u30eb\u30fc\u30c1\u30f3\u306e\u7d44\u307f\u5408\u308f\u305b\u3092\u5b9f\u884c\u3057\u3066\u3001\u30b7\u30b9\u30c6\u30e0\u304b\u3089\u30c7\u30fc\u30bf\u3092\u53ce\u96c6\u3057\u307e\u3059\u3002\u88687\u306f\u3001\u3053\u308c\u3089\u306e\u5404\u30eb\u30fc\u30c1\u30f3\u3068\u3001\u3069\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u30bf\u30a4\u30d7\u306e\u5834\u5408\u306b\u3069\u306e\u30eb\u30fc\u30c1\u30f3\u3092\u5b9f\u884c\u3059\u308b\u304b\u3092\u8a73\u7d30\u306b\u793a\u3057\u305f\u3082\u306e\u3067\u3059\u3002<\/p>\n<table style=\"width: 100.378%;\">\n<tbody>\n<tr>\n<td style=\"width: 12.9918%;\"><strong>\u30eb\u30fc\u30c1\u30f3<\/strong><\/td>\n<td style=\"width: 7.50229%;\"><strong>\u30e6\u30fc\u30b6\u30fc\u30bf\u30a4\u30d7<\/strong><\/td>\n<td style=\"width: 126.624%;\"><strong>\u8aac\u660e<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_mimi_redirector<\/td>\n<td style=\"width: 7.50229%;\">\u3059\u3079\u3066<\/td>\n<td style=\"width: 126.624%;\">\u30e1\u30e2\u30ea\u5185\u3067Mimikatz\u3092\u5b9f\u884c\u3059\u308b\u3002\u6b21\u306e\u30ea\u30b9\u30c8\u5185\u306e\u65b0\u305f\u306b\u4f5c\u6210\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306b\u633f\u5165\u3059\u308b: write.exe\u3001notepad.exe\u3001explorer.exe<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_main_routine<\/td>\n<td style=\"width: 7.50229%;\">\u3059\u3079\u3066<\/td>\n<td style=\"width: 126.624%;\">\n<ul>\n<li>\u30b7\u30b9\u30c6\u30e0\u306b\u95a2\u3059\u308b\u57fa\u672c\u7684\u306a\u8a73\u7d30\u60c5\u5831\u306e\u53ce\u96c6<\/li>\n<li>\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u306e\u30a4\u30f3\u30d9\u30f3\u30c8\u30ea\u306e\u53d6\u5f97<\/li>\n<li>cookie\u306e\u53ce\u96c6<\/li>\n<li>LogMeIn\u30c7\u30fc\u30bf\u306e\u53ce\u96c6<\/li>\n<li>Citrix\u30c7\u30fc\u30bf\u306e\u53ce\u96c6<\/li>\n<li>KeePass\u306e\u91d1\u5eab\u60c5\u5831\u306e\u53ce\u96c6<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_save_sysinfo<\/td>\n<td style=\"width: 7.50229%;\">\u3059\u3079\u3066<\/td>\n<td style=\"width: 126.624%;\">\u30ec\u30b8\u30b9\u30c8\u30ea\u304b\u3089\u30a2\u30f3\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u30ea\u30b9\u30c8\u3092\u53ce\u96c6<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_get_passwords<\/td>\n<td style=\"width: 7.50229%;\">\u3059\u3079\u3066<\/td>\n<td style=\"width: 126.624%;\">Lazagne\u3092\u4f7f\u7528\u3057\u3066\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u53ce\u96c6<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_find_files<\/td>\n<td style=\"width: 7.50229%;\">\u30b7\u30b9\u30c6\u30e0<\/td>\n<td style=\"width: 126.624%;\">\u8a2d\u5b9a\u3067\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u30ad\u30fc\u30ef\u30fc\u30c9\u3001\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3001\u62e1\u5f35\u5b50\u306b\u57fa\u3065\u3044\u3066\u30d5\u30a1\u30a4\u30eb\u304a\u3088\u3073\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u691c\u7d22\u3057\u3001\u53ce\u96c6\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_scan_network<\/td>\n<td style=\"width: 7.50229%;\">\u30b7\u30b9\u30c6\u30e0<\/td>\n<td style=\"width: 126.624%;\">\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_run_shell_cmds<\/td>\n<td style=\"width: 7.50229%;\">\u30b7\u30b9\u30c6\u30e0<\/td>\n<td style=\"width: 126.624%;\">\u30b7\u30b9\u30c6\u30e0\u306e\u8a73\u7d30\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306e\u4e00\u9023\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_get_desktop_files<\/td>\n<td style=\"width: 7.50229%;\">\u30e6\u30fc\u30b6\u30fc<\/td>\n<td style=\"width: 126.624%;\">find_files\u306b\u4f3c\u3066\u3044\u308b\u304c\u3001\u73fe\u5728\u306e\u30e6\u30fc\u30b6\u30fc\u306e\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u3092\u691c\u7d22\u3059\u308b\u306e\u307f<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_take_screenshot<\/td>\n<td style=\"width: 7.50229%;\">\u30e6\u30fc\u30b6\u30fc<\/td>\n<td style=\"width: 126.624%;\">\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3092\u53d6\u5f97\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12.9918%;\">_get_ps_history<\/td>\n<td style=\"width: 7.50229%;\">\u30e6\u30fc\u30b6\u30fc<\/td>\n<td style=\"width: 126.624%;\">Powershell\u306e\u5c65\u6b74\u3092\u53ce\u96c6\u3059\u308b<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88687: PyXie\u306e\u30eb\u30fc\u30c1\u30f3<\/em><\/span><\/p>\n<p>\u8a2d\u5b9a\u3067\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u3001\u4ee5\u4e0b\u306e\u30ad\u30fc\u30ef\u30fc\u30c9\u3068\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u30ea\u30b9\u30c8\u304b\u3089\u3001\u653b\u6483\u8005\u304c\u95a2\u5fc3\u3092\u6301\u3063\u3066\u3044\u308b\u30c7\u30fc\u30bf\u306e\u30bf\u30a4\u30d7\u306b\u3064\u3044\u3066\u3044\u304f\u3064\u304b\u306e\u30d2\u30f3\u30c8\u304c\u5f97\u3089\u308c\u307e\u3059\u3002<\/p>\n<table style=\"width: 99.894%;\">\n<tbody>\n<tr>\n<td style=\"width: 25.3886%;\">passw<\/td>\n<td style=\"width: 22.5389%;\">logins<\/td>\n<td style=\"width: 24.8705%;\">wallet<\/td>\n<td style=\"width: 335.107%;\">private<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">confidential<\/td>\n<td style=\"width: 22.5389%;\">username<\/td>\n<td style=\"width: 24.8705%;\">wire<\/td>\n<td style=\"width: 335.107%;\">access<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">treason<\/td>\n<td style=\"width: 22.5389%;\">vault<\/td>\n<td style=\"width: 24.8705%;\">operation<\/td>\n<td style=\"width: 335.107%;\">bribery<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">contraband<\/td>\n<td style=\"width: 22.5389%;\">censored<\/td>\n<td style=\"width: 24.8705%;\">instruction<\/td>\n<td style=\"width: 335.107%;\">credent<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">cardholder<\/td>\n<td style=\"width: 22.5389%;\">secret<\/td>\n<td style=\"width: 24.8705%;\">explosive<\/td>\n<td style=\"width: 335.107%;\">suspect<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">personal<\/td>\n<td style=\"width: 22.5389%;\">cyber<\/td>\n<td style=\"width: 24.8705%;\">restricted<\/td>\n<td style=\"width: 335.107%;\">balance<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">passport<\/td>\n<td style=\"width: 22.5389%;\">victim<\/td>\n<td style=\"width: 24.8705%;\">submarine<\/td>\n<td style=\"width: 335.107%;\">checking<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">saving<\/td>\n<td style=\"width: 22.5389%;\">routing<\/td>\n<td style=\"width: 24.8705%;\">esxi<\/td>\n<td style=\"width: 335.107%;\">vsphere<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">spy<\/td>\n<td style=\"width: 22.5389%;\">admin<\/td>\n<td style=\"width: 24.8705%;\">newswire<\/td>\n<td style=\"width: 335.107%;\">bitcoin<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">ethereum<\/td>\n<td style=\"width: 22.5389%;\">n-csr<\/td>\n<td style=\"width: 24.8705%;\">10-sb<\/td>\n<td style=\"width: 335.107%;\">10-q<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">convict<\/td>\n<td style=\"width: 22.5389%;\">tactical<\/td>\n<td style=\"width: 24.8705%;\">engeneering<\/td>\n<td style=\"width: 335.107%;\">military<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">disclosure<\/td>\n<td style=\"width: 22.5389%;\">attack<\/td>\n<td style=\"width: 24.8705%;\">infrastruct<\/td>\n<td style=\"width: 335.107%;\">marketwired<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">agreement<\/td>\n<td style=\"width: 22.5389%;\">illegal<\/td>\n<td style=\"width: 24.8705%;\">nda<\/td>\n<td style=\"width: 335.107%;\">hidden<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">privacy<\/td>\n<td style=\"width: 22.5389%;\">fraud<\/td>\n<td style=\"width: 24.8705%;\">statement<\/td>\n<td style=\"width: 335.107%;\">finance<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">marketwired<\/td>\n<td style=\"width: 22.5389%;\">clandestine<\/td>\n<td style=\"width: 24.8705%;\">compromate<\/td>\n<td style=\"width: 335.107%;\">concealed<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.3886%;\">investigation<\/td>\n<td style=\"width: 22.5389%;\">security<\/td>\n<td style=\"width: 24.8705%;\"><\/td>\n<td style=\"width: 335.107%;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88688: PyXie Lite\u306e\u8a2d\u5b9a\u306b\u6307\u5b9a\u3055\u308c\u305f\u30ad\u30fc\u30ef\u30fc\u30c9(\u30b9\u30da\u30eb\u306e\u9593\u9055\u3044\u306f\u305d\u306e\u307e\u307e\u8a18\u8f09)<\/em><\/span><\/p>\n<p>\u30c7\u30fc\u30bf\u53ce\u96c6\u30eb\u30fc\u30c1\u30f3\u306e\u4e00\u90e8\u3068\u3057\u3066\u3001\u30b7\u30b9\u30c6\u30e0\u306e\u8a73\u7d30\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306b\u591a\u6570\u306e\u30b3\u30de\u30f3\u30c9\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<table style=\"width: 100.171%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">netstat -an<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net user<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net use<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net view \/all<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net view \/all \/domain<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net share<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net config workstation<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net group \u201cDomain Admins\u201d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net group \u201cEnterprise Admins\u201d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">route print<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net localgroup<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ipconfig \/all<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">tasklist \/V<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">wmic process<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">arp -a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">gpresult \/z<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cmdkey \/list<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net config workstation<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">nslookup -type=any %userdnsdomain%<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">vssadmin List Shadows<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">wmic qfe list<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">klist<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">manage-bde -status<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">nltest \/domain_trusts<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">nltest \/domain_trusts \/all_trusts<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">qwinsta<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ipconfig \/displaydns<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">systeminfo<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">dclist<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net group \u201cdomain admins\u201d \/domain<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">net localgroup \u201cadministrators\u201d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">wmic path win32_VideoController get name<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">wmic cpu get name<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">reg.exe save hklm\\security %LOCALAPPDATA%\\temp\\[RANDOM]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">reg.exe save hklm\\system %LOCALAPPDATA%\\temp\\[RANDOM]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">reg.exe save hklm\\sam %LOCALAPPDATA%\\temp\\[RANDOM]<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u88689: \u5b9f\u884c\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9<\/em><\/span><\/p>\n<figure style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109499 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-33.png\" alt=\"PyXie\u5b9f\u884c\u6642\u306e\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u306b\u3088\u3063\u3066\u6c7a\u5b9a\u3055\u308c\u308b\u30eb\u30fc\u30c1\u30f3\u306e\u7d44\u307f\u5408\u308f\u305b\u3092\u5b9f\u884c\u3057\u3066\u3001\u30b7\u30b9\u30c6\u30e0\u304b\u3089\u30c7\u30fc\u30bf\u304c\u53ce\u96c6\u3055\u308c\u307e\u3059\u304c\u3001\u30c7\u30fc\u30bf\u3092\u5f15\u304d\u51fa\u3059\u524d\u306b\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u53ce\u96c6\u3055\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"573\" \/><figcaption class=\"wp-caption-text\">\u56f320: \u30c7\u30fc\u30bf\u6f0f\u51fa\u306e\u524d\u306b\u3001\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u5185\u306e\u30eb\u30fc\u30c1\u30f3\u304b\u3089\u53ce\u96c6\u3055\u308c\u305f\u30c7\u30fc\u30bf<\/figcaption><\/figure>\n<h6><a id=\"post-109455-_o7pl0ka6v440\"><\/a><strong>\u30c7\u30fc\u30bf\u306e\u6f0f\u51fa<\/strong><\/h6>\n<p>\u53ce\u96c6\u3055\u308c\u305f\u30c7\u30fc\u30bf\u304c\u542b\u307e\u308c\u308b\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306f\u3001\u5727\u7e2e\u3055\u308c\u305fZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u8ffd\u52a0\u3055\u308c\u3001\u6697\u53f7\u5316\u3055\u308c\u305f\u5f8c\u306b\u8a2d\u5b9a\u306e<span style=\"font-family: 'courier new', courier, monospace;\">gates<\/span>\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u6307\u5b9a\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30a2\u30fc\u30ab\u30a4\u30d6\u306e\u6697\u53f7\u5316\u306b\u306fAES\u65b9\u5f0f\u3092CBC\u30e2\u30fc\u30c9\u3067\u4f7f\u7528\u3057\u3001\u30ad\u30fc\u3068\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">THIS_KEY_IS_FOR_INTERNAL_USE_ONLY<\/span>\u3092\u4f7f\u7528\u3057\u307e\u3059\u300216\u30d0\u30a4\u30c8\u306e\u30e9\u30f3\u30c0\u30e0\u306a\u521d\u671f\u5316\u30d9\u30af\u30c8\u30eb(IV)\u3092\u4f7f\u7528\u3057\u3066\u6697\u53f7\u5316\u3055\u308c\u305f\u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u8ffd\u52a0\u3057\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u30b5\u30f3\u30d7\u30eb\u3092\u78ba\u8a8d\u3057\u3066\u304d\u305f\u4e2d\u3067\u3001\u30c7\u30fc\u30bf\u306e\u6f0f\u51fa\u306b\u5229\u7528\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u306f\u3001\u901a\u5e38\u3001\u88ab\u5bb3\u3092\u53d7\u3051\u305f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u4e0a\u306b\u3042\u308b\u3001\u5185\u90e8\u306e\u4fb5\u5bb3\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u3067\u3057\u305f\u3002\u3053\u306e\u3088\u3046\u306a\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3067\u306f\u3001\u30dd\u30fc\u30c8<span style=\"font-family: 'courier new', courier, monospace;\">31337\/tcp\u3001900\/tcp<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u3001<\/span><span style=\"font-family: 'courier new', courier, monospace;\">8443\/tcp<\/span>\u3067\u30ea\u30b9\u30cb\u30f3\u30b0\u3057\u3066\u3044\u307e\u3059\u3002\u4eca\u56de\u88ab\u5bb3\u3092\u53d7\u3051\u305f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u304b\u3089\u3001\u653b\u6483\u8005\u304c\u3069\u306e\u3088\u3046\u306b\u30c7\u30fc\u30bf\u3092\u6f0f\u51fa\u3055\u305b\u305f\u306e\u304b\u306f\u78ba\u8a8d\u3067\u304d\u306a\u304b\u3063\u305f\u306e\u3067\u3059\u304c\u3001\u5c11\u306a\u304f\u3068\u30821\u3064\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3067\u306f\u3001\u30c7\u30fc\u30bf\u6f0f\u51fa\u306b\u5229\u7528\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u3067Cobalt Strike\u304c\u5b9f\u884c\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u7d9a\u304d\u3092\u8aad\u3080: <a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/3\">\u6700\u5f8c\u306e\u91cd\u8981\u306a\u8a18\u4e8b: Defray777<\/a><\/p>\n<p><!--nextpage--><\/p>\n<h2><a id=\"post-109455-_oc4r5v9i6abw\"><\/a>\u6700\u5f8c\u306e\u91cd\u8981\u306a\u8a18\u4e8b: Defray777<\/h2>\n<p>Defray777\u306f\u3001<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack\/\">Ransom X<\/a>\u3084<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/montreals-stm-public-transport-system-hit-by-ransomware-attack\/?_hsenc=p2ANqtz--TMeD-DcOlE_JbE5-1DKkStefcr1qAFppJIfTyGcye3y_Z5SsaryNC0zrBu7qu5iPsiwx0&amp;utm_campaign=Ad%20hoc%20social%20posts%20&amp;utm_content=143516149&amp;utm_medium=social&amp;utm_source=twitter&amp;hss_channel=tw-29175108\">RansomExx<\/a>\u3068\u3082\u547c\u3070\u308c\u308b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30d5\u30a1\u30df\u30ea\u3067\u3001\u305d\u306e\u5b9f\u50cf\u306f\u307e\u3060\u6349\u3048\u3089\u308c\u3066\u3044\u307e\u305b\u3093\u3002\u6700\u8fd1\u306f\u3001\u65b0\u305f\u306a\u30d5\u30a1\u30df\u30ea\u3068\u3057\u3066\u30cb\u30e5\u30fc\u30b9\u3067\u53d6\u308a\u4e0a\u3052\u3089\u308c\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u304d\u307e\u3057\u305f\u304c\u30012018\u5e74\u306b\u306f\u3059\u3067\u306b\u4f7f\u7528\u3055\u308c\u3066\u304a\u308a\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3092\u591a\u6570\u5f15\u304d\u8d77\u3053\u3057\u3066\u6ce8\u76ee\u3092\u96c6\u3081\u3066\u3044\u307e\u3059\u3002\u8a73\u7d30\u306f\u30ea\u30f3\u30af\u5148\u306e\u8a18\u4e8b\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>Defray777\u306f\u3001\u5b8c\u5168\u306b\u30e1\u30e2\u30ea\u5185\u3067\u5b9f\u884c\u3055\u308c\u308b\u306e\u3067\u3001\u30b5\u30f3\u30d7\u30eb\u306b\u3064\u3044\u3066\u516c\u306b\u8b70\u8ad6\u3055\u308c\u308b\u3053\u3068\u306f\u3053\u308c\u307e\u3067\u307b\u3068\u3093\u3069\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u6700\u8fd1\u8d77\u304d\u305f\u3044\u304f\u3064\u304b\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3067\u306f\u3001Vatet\u30ed\u30fc\u30c0\u30fc\u304c\u9001\u308a\u8fbc\u3093\u3060Cobalt Strike\u306b\u3088\u3063\u3066Defray777\u304c\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3055\u308c\u3001\u5b9f\u884c\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>\u5f0a\u793e\u304c\u8abf\u67fb\u3092\u59cb\u3081\u3066\u304b\u3089\u3001\u65e9\u304f\u30822018\u5e74\u306b\u306f\u3001\u3053\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u3092\u8907\u6570\u767a\u898b\u3057\u3066\u3044\u307e\u3057\u305f\u30022018\u5e74\u304b\u3089\u73fe\u5728\u307e\u3067\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u3092\u78ba\u8a8d\u3059\u308b\u3068\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6697\u53f7\u5316\u3084\u5fa9\u53f7\u624b\u6cd5\u3001\u5fa9\u53f7\u30c4\u30fc\u30eb\u3092\u30d1\u30c3\u30af\u3059\u308b\u305f\u3081\u306e<a href=\"https:\/\/www.oreans.com\/themida.php\">Themida<\/a>\u306e\u4f7f\u7528\u306b\u4e00\u8cab\u6027\u304c\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u886810\u306f\u3001Defray777\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u304c<a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/autofocus\">AutoFocus<\/a>\u3067\u898b\u3064\u304b\u3063\u305f\u65e5\u4ed8\u3068\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u3092\u53d7\u3051\u305f\u7d44\u7e54\u306e\u30ea\u30b9\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3092\u898b\u308b\u3068\u3001Defray777\u306f2018\u5e74\u304b\u3089\u4e00\u8cab\u3057\u3066\u6d3b\u767a\u306b\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n<table style=\"width: 100.625%; height: 408px;\">\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\"><strong>\u65e5\u4ed8<\/strong><\/td>\n<td style=\"width: 376.866%; height: 24px;\"><strong>\u88ab\u5bb3\u8005<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2018\/12\/07<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u6559\u80b2\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/02\/04<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u533b\u7642\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/03\/01<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u30c6\u30af\u30ce\u30ed\u30b8\u7cfb\u306e\u7d44\u7e54<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/03\/15<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u6559\u80b2\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/08\/08<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u533b\u7642\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/08\/25<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u6559\u80b2\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/08\/28<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u904b\u8f38\u30fb\u7269\u6d41\u7d44\u7e54<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/09\/03<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u6cd5\u5f8b\u95a2\u9023\u7d44\u7e54<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/09\/06<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u6559\u80b2\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/09\/26<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u533b\u7642\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/10\/30<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u653f\u5e9c\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2019\/11\/01<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u533b\u7642\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2020\/02\/04<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u30c6\u30af\u30ce\u30ed\u30b8\u7cfb\u306e\u7d44\u7e54<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2020\/02\/10<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u653f\u5e9c\u6a5f\u95a2<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2020\/03\/16<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u98df\u54c1\u95a2\u9023\u7d44\u7e54<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 22.3881%; height: 24px;\">2020\/10\/17<\/td>\n<td style=\"width: 376.866%; height: 24px;\">\u91d1\u878d\u6a5f\u95a2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886810: Defray777\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u306e\u65e5\u4ed8\u3068\u88ab\u5bb3\u7d44\u7e54\u30ea\u30b9\u30c8<\/em><\/span><\/p>\n<figure style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109501 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-34.png\" alt=\"Defray777\u5fa9\u53f7\u30c4\u30fc\u30eb\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u3002\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u5185\u5bb9\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002 \" width=\"900\" height=\"560\" \/><figcaption class=\"wp-caption-text\">\u56f321: Defray777\u5fa9\u53f7\u30c4\u30fc\u30eb<\/figcaption><\/figure>\n<p>\u5f0a\u793e\u306f\u6700\u8fd1\u306eDefray777\u30b5\u30f3\u30d7\u30eb\u304b\u3089\u3044\u304f\u3064\u304b\u3092\u8abf\u67fb\u3057\u307e\u3057\u305f\u3002\u305d\u306e\u3046\u3061\u306e1\u3064\u306f\u3001\u6700\u8fd1\u3001\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u767a\u751f\u4e2d\u306b\u30e1\u30e2\u30ea\u304b\u3089\u76f4\u63a5\u53d6\u5f97\u3055\u308c\u305f\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u5f0a\u793e\u306e\u8a73\u7d30\u306a\u5206\u6790\u306e\u7d50\u679c\u3001\u5f97\u3089\u308c\u305f\u77e5\u898b\u306e\u6982\u8981\u3092\u4ee5\u4e0b\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-109455-_qtjhrt0ziud\"><\/a><strong>\u5fa9\u53f7\u3055\u308c\u305f\u6587\u5b57\u5217<\/strong><\/h4>\n<p>\u6587\u5b57\u5217\u306e\u5fa9\u53f7\u30d7\u30ed\u30bb\u30b9\u306f\u3001PyXie\u3067\u78ba\u8a8d\u3057\u305f\u3082\u306e\u3068\u540c\u3058\u3067\u3059\u3002\u6b21\u306e\u6587\u5b57\u5217\u306f\u3001\u6700\u8fd1\u306eDefray777\u30b5\u30f3\u30d7\u30eb\u304b\u3089\u5fa9\u53f7\u3057\u305f\u3082\u306e\u3067\u3059\u3002<\/p>\n<table style=\"width: 97.1467%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">Already active [%s]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">+%u (%u) files done [%s] [%u KB\/s]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">Started (PID: %u; Workers: %u; AES-%s) [%s]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">Complete (+%u (%u) files done) [%s]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">Work time: %d:%02d:%02d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">Unable to get computer name<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">CryptoGuard<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">kernel32.dll<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ConvertStringSecurityDescriptorToSecurityDescriptorW<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">advapi32.dll<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">IsWow64Process<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">SystemDrive<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">KiUserExceptionDispatcher<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886811: Defray777\u306e\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u305f\u6587\u5b57\u5217<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_eln66ql0fl9h\"><\/a><strong>\u88ab\u5bb3\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067Defray777\u3092\u512a\u5148<\/strong><\/h4>\n<p>\u5fa9\u5143\u3055\u308c\u305fDefray777\u3092\u8a73\u7d30\u306b\u8abf\u67fb\u3057\u305f\u3068\u3053\u308d\u3001\u30b9\u30ec\u30c3\u30c9\u3068\u30d7\u30ed\u30bb\u30b9\u306e\u512a\u5148\u9806\u4f4d\u4ed8\u3051\u306b\u95a2\u3057\u3001Defray777\u304c\u4ee5\u4e0b\u306e\u6ce8\u76ee\u3059\u3079\u304d\u7279\u5fb4\u3092\u793a\u3059\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li>\u3053\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001\u5b9f\u884c\u4e2d\u306b<span style=\"font-family: 'courier new', courier, monospace;\">SetProcessPriorityBoost<\/span>\u3092\u4f7f\u7528\u3057\u3066Defray777\u30d7\u30ed\u30bb\u30b9\u306e\u30b9\u30ec\u30c3\u30c9\u3092\u512a\u5148\u3057\u307e\u3059\u3002<\/li>\n<li>\u3055\u3089\u306b\u3001Defray777\u306f<span style=\"font-family: 'courier new', courier, monospace;\">SetThreadAffinityMask<\/span>\u3068<span style=\"font-family: 'courier new', courier, monospace;\">SetThreadPriorityBoost<\/span>\u3092\u547c\u3073\u51fa\u3057\u3001\u6697\u53f7\u5316\u306e\u30b9\u30ec\u30c3\u30c9\u3092\u4f5c\u6210\u3057\u3066\u512a\u5148\u3059\u308b\u51e6\u7406\u306b\u91cd\u70b9\u3092\u7f6e\u304d\u307e\u3059\u3002<\/li>\n<li>Defray777\u306f\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u5411\u4e0a\u306e\u305f\u3081\u306b\u30de\u30eb\u30c1\u30b9\u30ec\u30c3\u30c9\u3092\u5229\u7528\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<figure style=\"width: 826px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109503 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-35.png\" alt=\"Defray777\u306f\u3001\u3053\u3053\u3067\u793a\u3059\u3088\u3046\u306bSetThreadAffinityMask\u3068SetThreadPriorityBoost\u3092\u547c\u3073\u51fa\u3057\u3001\u6697\u53f7\u5316\u306e\u30b9\u30ec\u30c3\u30c9\u3092\u4f5c\u6210\u3057\u3066\u512a\u5148\u3059\u308b\u4f5c\u696d\u306b\u91cd\u70b9\u3092\u7f6e\u304d\u307e\u3059\u3002 \" width=\"826\" height=\"123\" \/><figcaption class=\"wp-caption-text\">\u56f322: \u5b9f\u884c\u4e2dDefray777\u306e\u30b9\u30ec\u30c3\u30c9\u3092\u512a\u5148\u3059\u308b<\/figcaption><\/figure>\n<h4><a id=\"post-109455-_7ckqcxg3mhb\"><\/a><strong>\u300c\u597d\u307e\u3057\u304f\u306a\u3044\u300d\u30d7\u30ed\u30bb\u30b9\u306e\u7d42\u4e86<\/strong><\/h4>\n<p>\u5b9f\u884c\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u4e2d\u3001Defray777\u306f\u653b\u6483\u8005\u304c\u300c\u597d\u307e\u3057\u304f\u306a\u3044\u300d\u3068\u307f\u306a\u3059\u30d7\u30ed\u30bb\u30b9\u3092\u7d42\u4e86\u3055\u305b\u308b\u30b9\u30ec\u30c3\u30c9\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u307e\u305a<span style=\"font-family: 'courier new', courier, monospace;\">CreateToolhelp32Snapshot<\/span>\u3092\u4f7f\u3063\u3066\u30d7\u30ed\u30bb\u30b9\u4e00\u89a7\u3092\u53d6\u5f97\u3057\u3001Defray777\u4ee5\u5916\u306e\u3059\u3079\u3066\u306e\u6709\u52b9\u306a\u30d7\u30ed\u30bb\u30b9\u3092\u30a4\u30c6\u30ec\u30fc\u30c8\u3057\u3066\u3059\u3079\u3066\u306e\u300c\u597d\u307e\u3057\u304f\u306a\u3044\u300d\u30d7\u30ed\u30bb\u30b9\u3092\u7d42\u4e86\u3055\u305b\u3066\u304b\u3089\u5b9f\u884c\u3092\u7d99\u7d9a\u3057\u307e\u3059\u3002\u7279\u306bDefray777\u304c\u6a19\u7684\u3068\u3059\u308b\u306e\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">SYNCHRONIZE | PROCESS_QUERY_INFORMATION | PROCESS_VM_WRITE | PROCESS_VM_READ | PROCESS_VM_OPERATION | PROCESS_CREATE_THREAD<\/span>\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u3064\u304d\u3067\u30aa\u30fc\u30d7\u30f3\u3055\u308c\u308b\u30d7\u30ed\u30bb\u30b9\u3067\u3059\u3002<\/p>\n<p>Defray777\u306f\u3001\u30a4\u30e1\u30fc\u30b8\u306e\u30d5\u30eb\u30d1\u30b9\u306b\u30b7\u30b9\u30c6\u30e0 \u30d5\u30a1\u30a4\u30eb \u30d1\u30b9\u3092\u542b\u3080\u3059\u3079\u3066\u306e\u30d7\u30ed\u30bb\u30b9\u3092\u9664\u5916\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u5b9f\u884c\u4e2d\u306b\u7d42\u4e86\u3055\u305b\u308b\u30d7\u30ed\u30bb\u30b9\u304b\u3089\u4ee5\u4e0b\u3092\u9664\u5916\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 99.9418%;\">\n<tbody>\n<tr>\n<td style=\"width: 52.381%;\">powershell.exe<\/td>\n<td style=\"width: 716.667%;\">rundll32.exe<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 52.381%;\">wefault.exe<\/td>\n<td style=\"width: 716.667%;\">explorer.exe<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 52.381%;\">vmnat.exe<\/td>\n<td style=\"width: 716.667%;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886812: \u9664\u5916\u3055\u308c\u308b\u30d7\u30ed\u30bb\u30b9<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_l9q7bg25nkj8\"><\/a><strong>\u30b7\u30b9\u30c6\u30e0\u30b5\u30fc\u30d3\u30b9\u306e\u505c\u6b62<\/strong><\/h4>\n<p>\u5b9f\u884c\u4e2d\u3001Defray777\u306f\u4ee5\u4e0b\u306e\u30b5\u30fc\u30d3\u30b9\u5b9f\u884c\u3092\u505c\u6b62\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 101.288%;\">\n<tbody>\n<tr>\n<td style=\"width: 24.3339%;\">Acronis VSS Provider<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeADTopology<\/td>\n<td style=\"width: 22.7353%;\">MSSQLSERVER<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$PRACTTICEMGT<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">AcronisAgent<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeAntispamUpdate<\/td>\n<td style=\"width: 22.7353%;\">MSSQLServerADHelper<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$PROD<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">AcronixAgent<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeEdgeSync<\/td>\n<td style=\"width: 22.7353%;\">MSSQLServerADHelper100<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$PROFXENGAGEMENT<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">AcrSch2Svc<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeES<\/td>\n<td style=\"width: 22.7353%;\">MSSQLServerOLAPService<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$SBSMONITORING<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">Antivirus<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeFBA<\/td>\n<td style=\"width: 22.7353%;\">MySQL57<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$SHAREPOINT<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">ARSM<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeFDS<\/td>\n<td style=\"width: 22.7353%;\">MySQL80<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$SOPHOS<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">AVP<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeIS<\/td>\n<td style=\"width: 22.7353%;\">NetMsmqActivator<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$SQL_2008<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecAgentAccelerator<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeMailboxAssistants<\/td>\n<td style=\"width: 22.7353%;\">nginx<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$SQLEXPRESS<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecAgentBrowser<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeMailboxReplication<\/td>\n<td style=\"width: 22.7353%;\">ntrtscan<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$SYSTEM_BGC<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecDeviceMediaService<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeMailSubmission<\/td>\n<td style=\"width: 22.7353%;\">OracleClientCache80<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$TPS<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecJobEngine<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeMGMT<\/td>\n<td style=\"width: 22.7353%;\">OracleServiceXE<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$TPSAMA<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecManagementService<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeMTA<\/td>\n<td style=\"width: 22.7353%;\">OracleXETNSListener<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$VEEAMSQL2008R2<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecRPCService<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeProtectedServiceHost<\/td>\n<td style=\"width: 22.7353%;\">PDVFSService<\/td>\n<td style=\"width: 67.2291%;\">SQLAgent$VEEAMSQL2012<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">BackupExecVSSProvider<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeRepl<\/td>\n<td style=\"width: 22.7353%;\">POP3Svc<\/td>\n<td style=\"width: 67.2291%;\">SQLBrowser<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">bedbg<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeRPC<\/td>\n<td style=\"width: 22.7353%;\">ReportServer<\/td>\n<td style=\"width: 67.2291%;\">SQLsafe Backup Service<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">DbxSvc<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeSA<\/td>\n<td style=\"width: 22.7353%;\">ReportServer$SQL_2008<\/td>\n<td style=\"width: 67.2291%;\">SQLsafe Filter Service<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">DCAgent<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeSearch<\/td>\n<td style=\"width: 22.7353%;\">ReportServer$SYSTEM_BGC<\/td>\n<td style=\"width: 67.2291%;\">SQLSafeOLRService<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">EhttpSrv<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeServiceHost<\/td>\n<td style=\"width: 22.7353%;\">ReportServer$TPS<\/td>\n<td style=\"width: 67.2291%;\">SQLSERVERAGENT<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">ekrn<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeSRS<\/td>\n<td style=\"width: 22.7353%;\">ReportServer$TPSAMA<\/td>\n<td style=\"width: 67.2291%;\">SQLTELEMETRY<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">Enterprise Client Service<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeThrottling<\/td>\n<td style=\"width: 22.7353%;\">RESvc<\/td>\n<td style=\"width: 67.2291%;\">SQLTELEMETRY$ECWDB2<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">EPSecurityService<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeTransport<\/td>\n<td style=\"width: 22.7353%;\">sacsvr<\/td>\n<td style=\"width: 67.2291%;\">SQLWriter<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">EPUpdateService<\/td>\n<td style=\"width: 29.0409%;\">MSExchangeTransportLogSearch<\/td>\n<td style=\"width: 22.7353%;\">SamSs<\/td>\n<td style=\"width: 67.2291%;\">SstpSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">EraserSvc11710<\/td>\n<td style=\"width: 29.0409%;\">msftesql$PROD<\/td>\n<td style=\"width: 22.7353%;\">SAVAdminService<\/td>\n<td style=\"width: 67.2291%;\">svcGenericHost<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">EsgShKernel<\/td>\n<td style=\"width: 29.0409%;\">MSOLAP$SQL_2008<\/td>\n<td style=\"width: 22.7353%;\">SAVService<\/td>\n<td style=\"width: 67.2291%;\">swi_filter<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">ESHASRV<\/td>\n<td style=\"width: 29.0409%;\">MSOLAP$SYSTEM_BGC<\/td>\n<td style=\"width: 22.7353%;\">SDRSVC<\/td>\n<td style=\"width: 67.2291%;\">swi_service<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">FA_Scheduler<\/td>\n<td style=\"width: 29.0409%;\">MSOLAP$TPS<\/td>\n<td style=\"width: 22.7353%;\">SepMasterService<\/td>\n<td style=\"width: 67.2291%;\">swi_update<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">IISAdmin<\/td>\n<td style=\"width: 29.0409%;\">MSOLAP$TPSAMA<\/td>\n<td style=\"width: 22.7353%;\">ShMonitor<\/td>\n<td style=\"width: 67.2291%;\">swi_update_64<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">IMAP4Svc<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$BKUPEXEC<\/td>\n<td style=\"width: 22.7353%;\">Smcinst<\/td>\n<td style=\"width: 67.2291%;\">Symantec System Recovery<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">KAVFS<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$ECWDB2<\/td>\n<td style=\"width: 22.7353%;\">SmcService<\/td>\n<td style=\"width: 67.2291%;\">TmCCSF<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">KAVFSGT<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$PRACTICEMGT<\/td>\n<td style=\"width: 22.7353%;\">SMTPSvc<\/td>\n<td style=\"width: 67.2291%;\">tmlisten<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">kavfsslp<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$PRACTTICEBGC<\/td>\n<td style=\"width: 22.7353%;\">SNAC<\/td>\n<td style=\"width: 67.2291%;\">TrueKey<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">klnagent<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$PROD<\/td>\n<td style=\"width: 22.7353%;\">SntpService<\/td>\n<td style=\"width: 67.2291%;\">TrueKeyScheduler<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">macmnsvc<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$PROFXENGAGEMENT<\/td>\n<td style=\"width: 22.7353%;\">Sophos Agent<\/td>\n<td style=\"width: 67.2291%;\">TrueKeyServiceHelper<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">masvc<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$SBSMONITORING<\/td>\n<td style=\"width: 22.7353%;\">Sophos AutoUpdate Service<\/td>\n<td style=\"width: 67.2291%;\">UI0Detect<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MBAMService<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$SHAREPOINT<\/td>\n<td style=\"width: 22.7353%;\">Sophos Clean Service<\/td>\n<td style=\"width: 67.2291%;\">Veeam Backup Catalog Data Service<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MBEndpointAgent<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$SOPHOS<\/td>\n<td style=\"width: 22.7353%;\">Sophos Device Control Service<\/td>\n<td style=\"width: 67.2291%;\">VeeamBackupSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">McAfeeEngineService<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$SQL_2008<\/td>\n<td style=\"width: 22.7353%;\">Sophos File Scanner Service<\/td>\n<td style=\"width: 67.2291%;\">VeeamBrokerSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">McAfeeFramework<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$SQLEXPRESS<\/td>\n<td style=\"width: 22.7353%;\">Sophos Health Service<\/td>\n<td style=\"width: 67.2291%;\">VeeamCatalogSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">McAfeeFrameworkMcAfeeFramework<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$SYSTEM_BGC<\/td>\n<td style=\"width: 22.7353%;\">Sophos MCS Agent<\/td>\n<td style=\"width: 67.2291%;\">VeeamCloudSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">McShield<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$TPS<\/td>\n<td style=\"width: 22.7353%;\">Sophos MCS Client<\/td>\n<td style=\"width: 67.2291%;\">VeeamDeploymentService<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">McTaskManager<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$TPSAMA<\/td>\n<td style=\"width: 22.7353%;\">Sophos Message Router<\/td>\n<td style=\"width: 67.2291%;\">VeeamDeploySvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">mfefire<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$VEEAMSQL2008R2<\/td>\n<td style=\"width: 22.7353%;\">Sophos Safestore Service<\/td>\n<td style=\"width: 67.2291%;\">VeeamEnterpriseManagerSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">mfemms<\/td>\n<td style=\"width: 29.0409%;\">MSSQL$VEEAMSQL2012<\/td>\n<td style=\"width: 22.7353%;\">Sophos System Protection Service<\/td>\n<td style=\"width: 67.2291%;\">VeeamHvIntegrationSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">mfevtp<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher<\/td>\n<td style=\"width: 22.7353%;\">Sophos Web Control Service<\/td>\n<td style=\"width: 67.2291%;\">VeeamMountSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MMS<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$PROFXENGAGEMENT<\/td>\n<td style=\"width: 22.7353%;\">sophossps<\/td>\n<td style=\"width: 67.2291%;\">VeeamNFSSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MongoDB<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$SBSMONITORING<\/td>\n<td style=\"width: 22.7353%;\">SQL Backups<\/td>\n<td style=\"width: 67.2291%;\">VeeamRESTSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">mozyprobackup<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$SHAREPOINT<\/td>\n<td style=\"width: 22.7353%;\">SQLAgent$BKUPEXEC<\/td>\n<td style=\"width: 67.2291%;\">VeeamTransportSvc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MsDtsServer<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$SQL_2008<\/td>\n<td style=\"width: 22.7353%;\">SQLAgent$CITRIX_METAFRAME<\/td>\n<td style=\"width: 67.2291%;\">W3Svc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MsDtsServer100<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$SYSTEM_BGC<\/td>\n<td style=\"width: 22.7353%;\">SQLAgent$CXDB<\/td>\n<td style=\"width: 67.2291%;\">wbengine<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MsDtsServer110<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$TPS<\/td>\n<td style=\"width: 22.7353%;\">SQLAgent$ECWDB2<\/td>\n<td style=\"width: 67.2291%;\">WRSVC<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.3339%;\">MSExchangeAB<\/td>\n<td style=\"width: 29.0409%;\">MSSQLFDLauncher$TPSAMA<\/td>\n<td style=\"width: 22.7353%;\">SQLAgent$PRACTTICEBGC<\/td>\n<td style=\"width: 67.2291%;\">Zoolz 2 Service<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886813: Defray777\u306b\u3088\u3063\u3066\u505c\u6b62\u3055\u308c\u308b\u30b5\u30fc\u30d3\u30b9<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_i8966fmn81x4\"><\/a><strong>\u30d5\u30a1\u30a4\u30eb\u306e\u6697\u53f7\u5316<\/strong><\/h4>\n<p>\u30e1\u30e2\u30ea\u304b\u3089\u5fa9\u5143\u3055\u308c\u305f\u6700\u8fd1\u306eDefray777\u30b5\u30f3\u30d7\u30eb\u3092\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d\u3001\u3053\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">GetLogicalDriveStringsW<\/span>\u547c\u3073\u51fa\u3057\u3092\u4f7f\u7528\u3057\u3066\u30b7\u30b9\u30c6\u30e0\u306e\u8ad6\u7406\u30c9\u30e9\u30a4\u30d6\u306e\u3059\u3079\u3066\u306e\u30ea\u30b9\u30c8\u3092\u53d6\u5f97\u3057\u3066\u304b\u3089\u3001\u4ee5\u4e0b\u306e\u30d7\u30ed\u30bb\u30b9\u3092\u4f7f\u7528\u3057\u3066\u5404\u30c9\u30e9\u30a4\u30d6\u306e\u30d5\u30a1\u30a4\u30eb\u6697\u53f7\u5316\u3092\u53cd\u5fa9\u51e6\u7406\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u306f\u3058\u3081\u306b\u3001\u5f71\u97ff\u3092\u53ca\u307c\u3059\u30b7\u30b9\u30c6\u30e0\u306b\u30d7\u30ed\u30bb\u30c3\u30b5\u6a5f\u80fd<span style=\"font-family: 'courier new', courier, monospace;\">PF_XMMI64_INSTRUCTIONS_AVAILABLE<\/span>\u304c\u5b58\u5728\u3059\u308b\u304b\u3092\u30c1\u30a7\u30c3\u30af\u3057\u307e\u3059\u3002\n<ul>\n<li>\u3053\u306e\u6a5f\u80fd\u304c\u6709\u52b9\u3067\u3042\u308c\u3070\u3001Defray777\u306f\u3001SSE2\u304c\u30b5\u30dd\u30fc\u30c8\u3055\u308c\u3066\u304a\u308a\u3001\u6bd4\u8f03\u7684\u8907\u96d1\u306a\u6570\u5b66\u6f14\u7b97\u304c\u53ef\u80fd\u3067\u3042\u308b\u3053\u3068\u3092\u628a\u63e1\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<\/li>\n<li>Defray777\u306f\u307e\u305f\u3001\u6697\u53f7\u5316\u306e\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u5411\u4e0a\u306e\u305f\u3081\u306b\u3001\u30d7\u30ed\u30bb\u30c3\u30b5\u304cAES-NI\u3092\u4f7f\u7528\u3067\u304d\u308b\u304b\u3069\u3046\u304b\u3082\u5224\u65ad\u3057\u307e\u3059\u3002<\/li>\n<li>\u6697\u53f7\u5316\u304c\u59cb\u307e\u308b\u3068\u3001\u30d5\u30a1\u30a4\u30eb\u3092\u6697\u53f7\u5316\u3059\u308b\u5404\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3067\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\n<ul>\n<li>\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u306e\u540d\u524d\u306f\u3055\u307e\u3056\u307e\u3067\u3059\u3002\u3057\u304b\u3057\u3001\u5f0a\u793e\u306e\u8abf\u67fb\u306b\u3088\u308b\u3068\u3001\u307b\u3068\u3093\u3069\u306e\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u306b\u306f\u3001\u611f\u5606\u7b26\u3001\u300cREADME\u300d\u306e\u6587\u5b57\u5217\u3001\u88ab\u5bb3\u8005\u540d\u3092\u793a\u3059\u5185\u5bb9\u306e\u7d44\u307f\u5408\u308f\u305b\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/li>\n<li>\u4f8b: <span style=\"font-family: 'courier new', courier, monospace;\">!!!_IMPACTED_Client_README_!!!.txt<\/span><\/li>\n<\/ul>\n<\/li>\n<li>\u30d5\u30a1\u30a4\u30eb\u30b3\u30f3\u30c6\u30f3\u30c4\u306f\u3001\u305d\u306e\u5834\u3067\u751f\u6210\u3055\u308c\u305fAES\u30ad\u30fc\u3067\u6697\u53f7\u5316\u3055\u308c\u307e\u3059\u3002AES\u30ad\u30fc\u306f\u3001RSA(4096\u30d3\u30c3\u30c8)\u3067\u6697\u53f7\u5316\u3055\u308c\u3001\u30d6\u30ed\u30c3\u30af\u9577512\u30d0\u30a4\u30c8\u306e\u30d6\u30ed\u30c3\u30af\u3067\u30d5\u30a1\u30a4\u30eb\u30d5\u30c3\u30bf\u30fc\u306b\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>\u6697\u53f7\u5316\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u88ab\u5bb3\u8005\u306e\u4e00\u610f\u8b58\u5225\u5b50\u3068\u30e9\u30f3\u30c0\u30e0\u306a8\u6841\u306e16\u9032\u6570\u3092\u542b\u3080\u62e1\u5f35\u5b50\u3092\u4ed8\u52a0\u3057\u305f\u540d\u524d\u306b\u5909\u66f4\u3055\u308c\u307e\u3059\u3002\n<ul>\n<li>\u4f8b: <span style=\"font-family: 'courier new', courier, monospace;\">.v1ct1m-1bc461ac<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<figure id=\"attachment_109504\" aria-describedby=\"caption-attachment-109504\" style=\"width: 743px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109505 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-36.png\" alt=\"\u6700\u8fd1\u306eDefray777\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u306e\u4f8b\u306b\u306f\u3053\u3046\u66f8\u304b\u308c\u3066\u3044\u307e\u3059\u3002\u56de\u5fa9\u306b\u554f\u984c\u304c\u751f\u3058\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u6697\u53f7\u5316\u3055\u308c\u305f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8(\u672c\u307b\u3069\u5927\u304d\u304f\u306f\u3042\u308a\u307e\u305b\u3093)\u3092\u30e1\u30fc\u30eb\u3067\u9001\u4fe1\u3057\u3066\u3044\u305f\u3060\u3051\u308c\u3070\u3001\u56de\u5fa9\u3067\u304d\u307e\u3059\u3002\u5f71\u97ff\u3092\u53d7\u3051\u305f\u30d5\u30a1\u30a4\u30eb\u306b\u306f\u6a5f\u5bc6\u60c5\u5831\u306f\u542b\u307e\u308c\u3066\u3044\u306a\u3044\u306f\u305a\u3067\u3059\u3002\u6b8b\u308a\u306e\u30c7\u30fc\u30bf\u306f\u3001\u304a\u652f\u6255\u3044\u5f8c\u306b\u3054\u5229\u7528\u3044\u305f\u3060\u3051\u307e\u3059\u3002\u8b66\u5bdf\u3078\u306e\u3054\u9023\u7d61\u306f\u304a\u63a7\u3048\u304f\u3060\u3055\u3044\u3002\u672a\u6255\u3044\u52d8\u5b9a\u304c\u51cd\u7d50\u3055\u308c\u3066\u304a\u652f\u6255\u3044\u304c\u3067\u304d\u306a\u304f\u306a\u308a\u307e\u3059\u3002\u696d\u52d9\u3092\u6ede\u308a\u306a\u304f\u9032\u3081\u305f\u3051\u308c\u3070\u3001\u3054\u9023\u7d61\u304f\u3060\u3055\u3044\u3002\u300d\" width=\"743\" height=\"229\" \/><figcaption id=\"caption-attachment-109504\" class=\"wp-caption-text\">\u56f323: \u6700\u8fd1\u306eDefray777\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u306e\u4f8b<\/figcaption><\/figure>\n<p>\u5177\u4f53\u7684\u306b\u306f\u3001\u6697\u53f7\u5316\u30e1\u30ab\u30cb\u30ba\u30e0\u306b\u306f\u6b21\u306e\u30b9\u30c6\u30c3\u30d7\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>32\u30d0\u30a4\u30c8\u306eAES\u30ad\u30fc\u3092\u52d5\u7684\u306b\u751f\u6210\u3057\u307e\u3059\u3002<\/li>\n<li>\u30d6\u30ed\u30c3\u30af\u957716\u30d0\u30a4\u30c8\u306e\u30d6\u30ed\u30c3\u30af\u3092\u4f7f\u7528\u3059\u308bECB\u30e2\u30fc\u30c9\u306eAES(256\u30d3\u30c3\u30c8)\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u6697\u53f7\u5316\u3057\u307e\u3059\u3002<\/li>\n<li>RSA(4096\u30d3\u30c3\u30c8)\u3067AES\u30ad\u30fc\u3092\u6697\u53f7\u5316\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">0x200<\/span>\u30d0\u30a4\u30c8\u306e\u6697\u53f7\u5316\u30c6\u30ad\u30b9\u30c8\u3092\u6697\u53f7\u5316\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u6700\u5f8c\u306b\u4ed8\u52a0\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_wcfsalo9gu4b\"><\/a><strong>\u6697\u53f7\u5316\u306e\u7d50\u679c<\/strong><\/h4>\n<p>\u6697\u53f7\u5316\u30d7\u30ed\u30bb\u30b9\u306e\u9593\u3001Defray777\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u306e\u30b3\u30a2\u6a5f\u80fd\u306b\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u3053\u3068\u306a\u304f\u3067\u304d\u308b\u3060\u3051\u591a\u304f\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u6697\u53f7\u5316\u3092\u76ee\u6307\u3057\u307e\u3059\u3002\u3053\u306e\u3053\u3068\u3092\u5b9f\u73fe\u3059\u308b\u305f\u3081\u306b\u3001Defray777\u306f\u3001\u5b9f\u884c\u4e2d\u306b\u6697\u53f7\u5316\u306e\u5bfe\u8c61\u3068\u3057\u306a\u3044\u3001\u9664\u5916\u3055\u308c\u308b\u30d5\u30a9\u30eb\u30c0\u3001\u30d5\u30a1\u30a4\u30eb\u3001\u30d5\u30a1\u30a4\u30eb\u62e1\u5f35\u5b50\u306e\u30bb\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n<p>\u9664\u5916\u3055\u308c\u308b\u30d5\u30a9\u30eb\u30c0\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<table style=\"width: 101.292%;\">\n<tbody>\n<tr>\n<td style=\"width: 33.691%;\">\\windows\\system32\\<\/td>\n<td style=\"width: 34.7639%;\">\\windows\\syswow64\\<\/td>\n<td style=\"width: 277.897%;\">\\windows\\system\\<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.691%;\">\\windows\\winsxs\\<\/td>\n<td style=\"width: 34.7639%;\">\\appdata\\roaming\\<\/td>\n<td style=\"width: 277.897%;\">\\appdata\\local\\<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.691%;\">\\appdata\\locallow\\<\/td>\n<td style=\"width: 34.7639%;\">\\all users\\microsoft\\<\/td>\n<td style=\"width: 277.897%;\">\\inetpub\\logs\\<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.691%;\">:\\boot\\<\/td>\n<td style=\"width: 34.7639%;\">:\\perflogs\\<\/td>\n<td style=\"width: 277.897%;\">:\\programdata\\<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.691%;\">:\\drivers\\<\/td>\n<td style=\"width: 34.7639%;\">:\\wsus\\<\/td>\n<td style=\"width: 277.897%;\">:\\efstmpwp\\<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.691%;\">:\\$recycle.bin\\<\/td>\n<td style=\"width: 34.7639%;\">:\\EFSTMPWP\\<\/td>\n<td style=\"width: 277.897%;\">crypt_detect<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.691%;\">cryptolocker<\/td>\n<td style=\"width: 34.7639%;\">ransomware<\/td>\n<td style=\"width: 277.897%;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886814: Defray777\u306e\u6697\u53f7\u5316\u5bfe\u8c61\u304b\u3089\u9664\u5916\u3055\u308c\u308b\u30d5\u30a9\u30eb\u30c0<\/em><\/span><\/p>\n<p>\u9664\u5916\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<table style=\"width: 100.697%;\">\n<tbody>\n<tr>\n<td style=\"width: 25.9358%;\">iconcache.db<\/td>\n<td style=\"width: 21.6578%;\">thumbs.db<\/td>\n<td style=\"width: 25.9358%;\">ransomware<\/td>\n<td style=\"width: 359.279%;\">ransom<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.9358%;\">debug.txt<\/td>\n<td style=\"width: 21.6578%;\">boot.ini<\/td>\n<td style=\"width: 25.9358%;\">desktop.ini<\/td>\n<td style=\"width: 359.279%;\">autorun.inf<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.9358%;\">ntuser.dat<\/td>\n<td style=\"width: 21.6578%;\">ntldr<\/td>\n<td style=\"width: 25.9358%;\">ntdetect.com<\/td>\n<td style=\"width: 359.279%;\">bootfont.bin<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.9358%;\">bootsect.bak<\/td>\n<td style=\"width: 21.6578%;\"><\/td>\n<td style=\"width: 25.9358%;\"><\/td>\n<td style=\"width: 359.279%;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886815: Defray777\u306e\u6697\u53f7\u5316\u5bfe\u8c61\u304b\u3089\u9664\u5916\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb<\/em><\/span><\/p>\n<p>Defray777\u304c\u9664\u5916\u5bfe\u8c61\u30d5\u30a1\u30a4\u30eb\u30ea\u30b9\u30c8\u306b\u8eab\u4ee3\u91d1\u8981\u6c42\u6587\u306e\u540d\u524d\u3092\u8ffd\u52a0\u3059\u308b\u3053\u3068\u3082\u3001\u7559\u610f\u3059\u308b\u3079\u304d\u91cd\u8981\u306a\u30dd\u30a4\u30f3\u30c8\u3067\u3059\u3002<\/p>\n<p>\u9664\u5916\u5bfe\u8c61\u306e\u62e1\u5f35\u5b50\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<table style=\"width: 100.786%;\">\n<tbody>\n<tr>\n<td style=\"width: 20.7101%;\">.ani<\/td>\n<td style=\"width: 25.7396%;\">.cab<\/td>\n<td style=\"width: 21.0059%;\">.cpl<\/td>\n<td style=\"width: 11.2426%;\">.cur<\/td>\n<td style=\"width: 398.521%;\">.diagcab<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.diagpkg<\/td>\n<td style=\"width: 25.7396%;\">.dll<\/td>\n<td style=\"width: 21.0059%;\">.drv<\/td>\n<td style=\"width: 11.2426%;\">.hlp<\/td>\n<td style=\"width: 398.521%;\">.icl<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.icns<\/td>\n<td style=\"width: 25.7396%;\">.ico<\/td>\n<td style=\"width: 21.0059%;\">.iso<\/td>\n<td style=\"width: 11.2426%;\">.ics<\/td>\n<td style=\"width: 398.521%;\">.lnk<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.idx<\/td>\n<td style=\"width: 25.7396%;\">.mod<\/td>\n<td style=\"width: 21.0059%;\">.mpa<\/td>\n<td style=\"width: 11.2426%;\">.msc<\/td>\n<td style=\"width: 398.521%;\">.msp<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.msstyles<\/td>\n<td style=\"width: 25.7396%;\">.msu<\/td>\n<td style=\"width: 21.0059%;\">.nomedia<\/td>\n<td style=\"width: 11.2426%;\">.ocx<\/td>\n<td style=\"width: 398.521%;\">.prf<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.rtp<\/td>\n<td style=\"width: 25.7396%;\">.scr<\/td>\n<td style=\"width: 21.0059%;\">.shs<\/td>\n<td style=\"width: 11.2426%;\">.spl<\/td>\n<td style=\"width: 398.521%;\">.sys<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.theme<\/td>\n<td style=\"width: 25.7396%;\">.themepack<\/td>\n<td style=\"width: 21.0059%;\">.exe<\/td>\n<td style=\"width: 11.2426%;\">.bat<\/td>\n<td style=\"width: 398.521%;\">.cmd<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.7101%;\">.url<\/td>\n<td style=\"width: 25.7396%;\">.mui<\/td>\n<td style=\"width: 21.0059%;\"><\/td>\n<td style=\"width: 11.2426%;\"><\/td>\n<td style=\"width: 398.521%;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886816: Defray777\u306e\u6697\u53f7\u5316\u5bfe\u8c61\u304b\u3089\u9664\u5916\u3055\u308c\u308b\u62e1\u5f35\u5b50<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_bpc5tupva9l4\"><\/a><strong>\u30de\u30c3\u30d4\u30f3\u30b0\u3055\u308c\u3066\u3044\u306a\u3044\u30d5\u30a1\u30a4\u30eb\u5171\u6709\u306e\u691c\u7d22<\/strong><\/h4>\n<p>Defray777\u306f\u5b9f\u884c\u4e2d\u3001<span style=\"font-family: 'courier new', courier, monospace;\">WNetOpenEnumW<\/span>\u304a\u3088\u3073<span style=\"font-family: 'courier new', courier, monospace;\">WNetEnumResourceW<\/span>\u3092\u4f7f\u7528\u3057\u3066\u3001\u6697\u53f7\u5316\u3067\u304d\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u542b\u3080\u53ef\u80fd\u6027\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u5171\u6709\u3092\u691c\u7d22\u3057\u307e\u3059\u3002\u3053\u306e\u624b\u6cd5\u306f\u3001\u305d\u306e\u4ed6\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u3067\u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u3066\u304a\u308a\u3001\u30de\u30c3\u30d4\u30f3\u30b0\u3055\u308c\u3066\u3044\u306a\u3044\u30d5\u30a1\u30a4\u30eb\u5171\u6709\u3092\u901a\u3058\u3066\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30d5\u30a1\u30a4\u30eb\u3092\u6697\u53f7\u5316\u3057\u307e\u3059\u3002<\/p>\n<figure style=\"width: 737px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109507 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-37.png\" alt=\"Defray777\u306f\u5b9f\u884c\u4e2d\u3001WNetOpenEnumW\u304a\u3088\u3073WNetEnumResourceW\u3092\u4f7f\u7528\u3057\u3066\u3001\u6697\u53f7\u5316\u3067\u304d\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u542b\u3080\u53ef\u80fd\u6027\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u5171\u6709\u3092\u691c\u7d22\u3057\u307e\u3059\u3002 \" width=\"737\" height=\"455\" \/><figcaption class=\"wp-caption-text\">\u56f324: Defray777\u304c\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30ea\u30bd\u30fc\u30b9\u3092\u5217\u6319<\/figcaption><\/figure>\n<h4><a id=\"post-109455-_4phllgwsz8vh\"><\/a><strong>\u30a2\u30f3\u30c1\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af\u624b\u6cd5<\/strong><\/h4>\n<p>\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u3059\u3079\u3066\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u6697\u53f7\u5316\u3055\u308c\u308b\u3068\u3001Defray777\u306f\u3001\u591a\u304f\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u3068\u540c\u69d8\u306e\u4e00\u822c\u7684\u306a\u30a2\u30f3\u30c1\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af\u624b\u6cd5\u3068\u3057\u3066\u3001\u3067\u304d\u308b\u9650\u308a\u591a\u304f\u306e\u4fb5\u5165\u306e\u75d5\u8de1\u3092\u6d88\u53bb\u3057\u3001\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u304c\u306a\u3051\u308c\u3070\u30b7\u30b9\u30c6\u30e0\u306e\u56de\u5fa9\u304c\u304d\u308f\u3081\u3066\u56f0\u96e3\u306a\u72b6\u614b\u306b\u3057\u307e\u3059\u3002\u3053\u306e\u3088\u3046\u306a\u30b3\u30de\u30f3\u30c9\u306f\u3001\u305d\u306e\u4ed6\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u3067\u306f\u4e00\u822c\u7684\u3067\u3059\u304c\u3001Defray777\u306f\u30b3\u30de\u30f3\u30c9\u3092\u6697\u53f7\u5316\u306e\u7d42\u4e86\u5f8c\u306b\u5b9f\u884c\u3057\u307e\u3059\u3002\u3064\u307e\u308a\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c4\u30fc\u30eb\u304c\u30a2\u30e9\u30fc\u30c8\u3092\u3042\u3052\u305f\u308a\u3001Defray777\u306b\u5bfe\u3057\u3066\u5bfe\u7b56\u3092\u8b1b\u3058\u305f\u308a\u3059\u308b\u3068\u304d\u306b\u306f\u3001\u30d5\u30a1\u30a4\u30eb\u306f\u3059\u3067\u306b\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Defray777\u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u308b\u30b3\u30de\u30f3\u30c9\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<table style=\"width: 100.308%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">cipher.exe \/w:[DRIVE]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">fsutil.exe usn deletejournal \/D [DRIVE]<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">wbadmin.exe delete catalog -quiet<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">bcdedit.exe \/set {default} recoveryenabled no<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">bcdedit.exe \/set {default} bootstatuspolicy ignoreallfailures<br \/>\nschtasks.exe \/Change \/TN \u201c\\Microsoft\\Windows\\SystemRestore\\SR\u201d \/disable<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">wevtutil.exe cl Application<br \/>\nwevtutil.exe cl System<br \/>\nwevtutil.exe cl Setup<br \/>\nwevtutil.exe cl Security<br \/>\nwevtutil.exe sl Security \/e:false<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886817: Defray777\u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u308b\u30a2\u30f3\u30c1\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af\u30b3\u30de\u30f3\u30c9<\/em><\/span><\/p>\n<p>\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u5909\u66f4\u3055\u308c\u307e\u3059\u3002<\/p>\n<table style=\"width: 101.42%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"font-family: 'courier new', courier, monospace;\">\\Software\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\Software\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableSR<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableConfig<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886818: Defray777\u306b\u3088\u3063\u3066\u5909\u66f4\u3055\u308c\u305f\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_s966ggi4j0r\"><\/a><strong>Defray777\u306eLinux\u3078\u306e\u79fb\u690d<\/strong><\/h4>\n<p>\u5f0a\u793e\u304c\u8abf\u67fb\u3092\u9032\u3081\u308b\u4e2d\u3067\u3001Defray777\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u304cLinux\u306b\u79fb\u690d\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002Defray777\u304c\u73fe\u308c\u308b\u4ee5\u524d\u306b\u306f\u3001Windows\u3068Linux\u306e\u4e21\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u306b\u5f71\u97ff\u3092\u53ca\u307c\u3059\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001Java\u307e\u305f\u306fPython\u306a\u3069\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u8a00\u8a9e\u306b\u3088\u308b\u8a18\u8ff0\u306b\u9650\u3089\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u3088\u3046\u306a\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u4e9c\u7a2e\u306f\u3001\u4e21\u65b9\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u306b\u3088\u308b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3068\u30b5\u30dd\u30fc\u30c8\u304c\u5fc5\u8981\u306a\u5358\u4e00\u306e\u8a00\u8a9e\u3067\u8a18\u8ff0\u3055\u308c\u3066\u3044\u308b\u306e\u3067\u3001\u4e21\u30b7\u30b9\u30c6\u30e0\u3067\u6a5f\u80fd\u3059\u308b\u3068\u8003\u3048\u3089\u308c\u308b\u3067\u3057\u3087\u3046\u3002Defray777\u306eLinux\u3078\u306e\u79fb\u690d\u306b\u3088\u308a\u3001\u3053\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001\u5916\u90e8\u4f9d\u5b58\u95a2\u4fc2\u306e\u306a\u3044\u3001\u30b9\u30bf\u30f3\u30c9\u30a2\u30ed\u30f3\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u5404\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306b\u5bfe\u3057\u3066\u78ba\u4fdd\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>Defray777\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u3068\u3057\u3066\u78ba\u8a8d\u3055\u308c\u305fWindows\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u542b\u3080ZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u306f\u30012020\u5e7410\u670817\u65e5\u306b\u516c\u958b\u30de\u30eb\u30a6\u30a7\u30a2\u30ea\u30dd\u30b8\u30c8\u30ea\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001\u3053\u306eZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u306f<span style=\"font-family: 'courier new', courier, monospace;\">decryptor64<\/span>\u3068\u3044\u3046\u540d\u524d\u306eELF\u5f62\u5f0f\u306e\u30d0\u30a4\u30ca\u30ea\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30d0\u30a4\u30ca\u30ea\u306e\u5206\u6790\u304b\u3089\u3001Linux\u306b\u79fb\u690d\u3055\u308c\u305f\u5225\u306eDefray777\u5fa9\u53f7\u30c4\u30fc\u30eb\u304c\u5b58\u5728\u3059\u308b\u3068\u5224\u65ad\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>Defray777\u306eLinux\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u5b9f\u969b\u306b\u5b58\u5728\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u3044\u3046\u8003\u3048\u306e\u4e0b\u3001\u5f0a\u793e\u3067\u306fAutoFocus\u3067\u6355\u6349\u3092\u59cb\u3081\u3001ELF\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u6697\u53f7\u5316\u30c4\u30fc\u30eb\u3092\u8fc5\u901f\u306b\u898b\u3064\u3051\u51fa\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u78ba\u8a8d\u3092\u3055\u3089\u306b\u9032\u3081\u308b\u3068\u30012020\u5e748\u6708\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u305f\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3057\u305f\u30022020\u5e7410\u6708\u4e0a\u65ec\u306e\u6642\u70b9\u3067\u3001Linux\u30d0\u30fc\u30b8\u30e7\u30f3\u306eDefray\u306f\u3001VirusTotal\u306e\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9(AV)\u3067\u306f\u691c\u51fa\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<p>Defray777\u306eLinux\u304a\u3088\u3073Windows\u306e\u4e9c\u7a2e\u305d\u308c\u305e\u308c\u3092\u8a73\u7d30\u306b\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d\u3001\u6697\u53f7\u5316\u304a\u3088\u3073\u5fa9\u53f7\u5316\u306b\u4f7f\u7528\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306f\u307b\u3068\u3093\u3069\u540c\u3058\u3067\u3042\u308b\u3068\u5224\u65ad\u3057\u307e\u3057\u305f\u3002\u5b9f\u969b\u306b\u3001\u5f0a\u793e\u72ec\u81ea\u306eRSA\u30ad\u30fc\u30da\u30a2\u3092\u751f\u6210\u3057\u3001\u30d0\u30a4\u30ca\u30ea\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u3067\u3001\u4e21\u65b9\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u306e\u6697\u53f7\u5316\u30c4\u30fc\u30eb\u3068\u5fa9\u53f7\u30c4\u30fc\u30eb\u306b\u4e92\u63db\u6027\u304c\u3042\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u958b\u767a\u8005\u306f\u3001Windows\u30d0\u30fc\u30b8\u30e7\u30f3\u3068\u306f\u7570\u306a\u308a\u3001Linux\u30b5\u30f3\u30d7\u30eb\u306e\u4fdd\u8b77\u306b\u306f\u3042\u307e\u308a\u529b\u3092\u5165\u308c\u306a\u304b\u3063\u305f\u3088\u3046\u3067\u3059\u3002\u9a5a\u3044\u305f\u3053\u3068\u306b\u3001\u79c1\u305f\u3061\u304c\u5206\u6790\u3057\u305f\u30d0\u30a4\u30ca\u30ea\u306b\u306f\u3001\u4e21\u65b9\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u7c21\u5358\u306b\u5165\u308c\u66ff\u3048\u308b\u305f\u3081\u306e\u8a18\u53f7\u304c\u5143\u306e\u307e\u307e\u6b8b\u3063\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 600px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-109509 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-38.png\" alt=\"\u958b\u767a\u8005\u306f\u3001Windows\u30d0\u30fc\u30b8\u30e7\u30f3\u3068\u306f\u7570\u306a\u308a\u3001Linux\u30b5\u30f3\u30d7\u30eb\u306e\u4fdd\u8b77\u306b\u306f\u3042\u307e\u308a\u529b\u3092\u5165\u308c\u306a\u304b\u3063\u305f\u3088\u3046\u3067\u3059\u3002\u79c1\u305f\u3061\u304c\u5206\u6790\u3057\u305f\u30d0\u30a4\u30ca\u30ea\u306b\u306f\u3001\u4e21\u65b9\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u7c21\u5358\u306b\u5165\u308c\u66ff\u3048\u308b\u305f\u3081\u306e\u8a18\u53f7\u304c\u5143\u306e\u307e\u307e\u6b8b\u3063\u3066\u3044\u307e\u3057\u305f\u3002 \" width=\"600\" height=\"388\" \/><figcaption class=\"wp-caption-text\">\u56f325: Defray777\u306eELF\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u30ea\u30b9\u30c8\u3055\u308c\u305f\u540d\u524d\u4ed8\u304d\u95a2\u6570<\/figcaption><\/figure>\n<p>Windows\u306e\u4e9c\u7a2e\u3068Linux\u306e\u4e9c\u7a2e\u306e\u9593\u3067\u898b\u3089\u308c\u308b\u6700\u5927\u306e\u9055\u3044\u306e1\u3064\u306f\u3001\u6697\u53f7\u5316\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u6c7a\u5b9a\u3059\u308b\u30ed\u30b8\u30c3\u30af\u3067\u3059\u3002Windows\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u3092\u518d\u5e30\u7684\u306b\u547c\u3073\u51fa\u3057\u3001\u660e\u793a\u7684\u306b\u9664\u5916\u3055\u308c\u3066\u3044\u306a\u3044\u30d5\u30a1\u30a4\u30eb\u306f\u3059\u3079\u3066\u6697\u53f7\u5316\u3057\u307e\u3059\u3002Linux\u3067\u306f\u5bfe\u7167\u7684\u306b\u3001\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u5f15\u6570\u3067\u6307\u5b9a\u3055\u308c\u305f\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u307f\u3092\u6697\u53f7\u5316\u3057\u307e\u3059\u3002<\/p>\n<p>\u7d9a\u304d\u3092\u8aad\u3080: <a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/4\">Vatet\u3001PyXie\u3001Defray777\u306e\u3064\u306a\u304c\u308a<\/a><!--nextpage--><\/p>\n<h2><a id=\"post-109455-_sbdlwpvcz6qo\"><\/a>Vatet\u3001PyXie\u3001Defray777\u306e\u3064\u306a\u304c\u308a<\/h2>\n<p>\u3053\u308c\u3089\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3092\u8abf\u67fb\u3057\u3066\u3044\u308b\u9593\u306b\u3001\u5f0a\u793e\u3067\u306f\u3001Vatet\u3001PyXie\u3001Defray777\u306e\u9593\u306b\u3044\u304f\u3064\u304b\u306e\u4e00\u81f4\u70b9\u304c\u3042\u308b\u3053\u3068\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u4e00\u81f4\u70b9\u306f\u30013\u3064\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3059\u3079\u3066\u304c\u3001\u91d1\u878d\u6a5f\u95a2\u3092\u72d9\u3063\u305f\u306e\u3068\u540c\u3058\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u3063\u3066\u958b\u767a\u3055\u308c\u3001\u73fe\u5728\u3082\u30e1\u30f3\u30c6\u30ca\u30f3\u30b9\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u5f37\u304f\u793a\u5506\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<h4><a id=\"post-109455-_2gg529peqhsa\"><\/a><strong>PDB\u30d1\u30b9\u306e\u518d\u4f7f\u7528<\/strong><\/h4>\n<p>Defray777\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u306e\u8a18\u4e8b\u3067\u78ba\u8a8d\u3057\u305f\u3088\u3046\u306b\u3001Defray777\u306b\u3088\u308b\u88ab\u5bb3\u3092\u53d7\u3051\u305f\u7d44\u7e54\u306f\u591a\u6570\u306b\u306e\u307c\u308a\u307e\u3059\u3002\u3057\u304b\u3057\u3001\u3053\u308c\u3089\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u306b\u306f\u3001PyXie\u3068\u91cd\u306a\u308b\u70b9\u3082\u3044\u304f\u3064\u304b\u898b\u3089\u308c\u307e\u3059\u3002\u5f0a\u793e\u304c\u5206\u6790\u3057\u305f\u5fa9\u53f7\u30c4\u30fc\u30eb\u306e1\u3064\u306f\u3001Pyxie\u306e\u6bd4\u8f03\u7684\u521d\u671f\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u304a\u3088\u3073Cobalt Mode\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u30fc\u3068\u5171\u901a\u306e\u30d1\u30b9\u3092\u5171\u6709\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 100.71%;\">\n<tbody>\n<tr>\n<td style=\"width: 24.7136%;\">Defray777\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb<\/td>\n<td style=\"width: 237.976%;\">Z:\\coding\\pyproject\\compiled\\ransom\\ransom.pdb<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.7136%;\">PyXie<\/td>\n<td style=\"width: 237.976%;\">z:\\coding\\pyproject\\python_static_2.7.15\\<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 24.7136%;\">Cobalt Mode<\/td>\n<td style=\"width: 237.976%;\">Z:\\coding\\pyproject\\compiled\\cobalt_mode\\cobalt_mode.pdb<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886819: Defray777\u3001PyXie\u3001Cobalt Mode\u304c\u5171\u6709\u3059\u308bPDB\u30d1\u30b9<\/em><\/span><\/p>\n<p>\u307e\u305f\u3001\u5f0a\u793e\u304c\u78ba\u8a8d\u3057\u305fVatet\u306e\u4e9c\u7a2e\u306e\u4e00\u90e8\u306b\u3082PDB\u30d1\u30b9\u306e\u91cd\u8907\u304c\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n<table style=\"width: 100.938%;\">\n<tbody>\n<tr>\n<td style=\"width: 11.8949%;\">Tetris<\/td>\n<td style=\"width: 211.203%;\">C:\\Users\\1\\Downloads\\tetris-game-master\\Release\\TetrisGame_zjy.pdb<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 11.8949%;\">Notepad<\/td>\n<td style=\"width: 211.203%;\">C:\\Users\\1\\Downloads\\notepad-master\\Debug\\notepad.pdb<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 11.8949%;\">Rainmeter<\/td>\n<td style=\"width: 211.203%;\">C:\\Users\\1\\Downloads\\rainmeter-master\\x32-Release\\Obj\\Library\\Rainmeter.pdb<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 11.8949%;\">Rainmeter<\/td>\n<td style=\"width: 211.203%;\">C:\\Users\\1\\Downloads\\rainmeter-master\\x32-Release\\Obj\\Application\\Rainmeter.pdb<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 11.8949%;\">Notepad++<\/td>\n<td style=\"width: 211.203%;\">C:\\Users\\1\\Downloads\\notepad-plus-plus-master\\PowerEditor\\bin\\npp.pdb<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><em>\u886820: \u8907\u6570\u306eVatet\u306e\u4e9c\u7a2e\u3067\u5171\u6709\u3055\u308c\u308bPDB\u30d1\u30b9<\/em><\/span><\/p>\n<h4><a id=\"post-109455-_6atbksm00wts\"><\/a><strong>\u6587\u5b57\u5217\u306e\u6697\u53f7\u5316<\/strong><\/h4>\n<p>\u5f0a\u793e\u306e\u8abf\u67fb\u3067\u306f\u3001\u5404\u4e9c\u7a2e\u306e\u6587\u5b57\u5217\u6697\u53f7\u5316\u624b\u6cd5\u306b\u4e00\u8cab\u6027\u304c\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u3066\u3044\u307e\u3059\u3002Defray777\u306f\u3001PyXie\u3067\u4f7f\u308f\u308c\u3066\u3044\u305f\u306e\u3068\u540c\u3058\u6587\u5b57\u5217\u6697\u53f7\u5316\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001Vatet\u30ed\u30fc\u30c0\u30fc\u3067\u3042\u308bTetris\u306e\u4e9c\u7a2e\u3067\u3082\u3001\u540c\u3058\u6587\u5b57\u5217\u6697\u53f7\u5316\u624b\u6cd5\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<figure style=\"width: 707px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109511 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-39.png\" alt=\"Defray777\u306f\u3001PyXie\u3067\u4f7f\u308f\u308c\u3066\u3044\u305f\u306e\u3068\u540c\u3058\u6587\u5b57\u5217\u6697\u53f7\u5316\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001Vatet\u30ed\u30fc\u30c0\u30fc\u3067\u3042\u308bTetris\u306e\u4e9c\u7a2e\u3067\u3082\u3001\u540c\u3058\u6587\u5b57\u5217\u6697\u53f7\u5316\u624b\u6cd5\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002 \" width=\"707\" height=\"231\" \/><figcaption class=\"wp-caption-text\">\u56f326: Defray777\u306e\u6587\u5b57\u5217\u5fa9\u53f7\u5316\u306e\u4f8b<\/figcaption><\/figure>\n<h4><a id=\"post-109455-_1s9bgzx5evon\"><\/a><strong>\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u306e\u4f5c\u6210<\/strong><\/h4>\n<p>Defray777\u306f\u3001DEFAULTCOMPNAME\u3078\u306e\u30d5\u30a9\u30fc\u30eb\u30d0\u30c3\u30af\u306a\u3069\u3001\u5f0a\u793e\u3067\u5206\u6790\u3057\u305f\u3001\u66f4\u65b0\u3055\u308c\u305fPyXie\u30b5\u30f3\u30d7\u30eb\u3068\u540c\u3058\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u30eb\u30fc\u30c1\u30f3\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002Defray777\u304c\u7570\u306a\u3063\u305f\u52d5\u304d\u3092\u3059\u308b\u306e\u306f\u3001\u8a08\u7b97\u3055\u308c\u305fMD5\u30cf\u30c3\u30b7\u30e5\u3068<span style=\"font-family: 'courier new', courier, monospace;\">0x2<\/span>\u3068\u306eXOR\u6f14\u7b97\u3092\u5b9f\u884c\u3059\u308b\u30b9\u30c6\u30c3\u30d7\u304c\u7701\u7565\u3055\u308c\u3066\u3044\u308b\u70b9\u3067\u3059\u3002<\/p>\n<figure style=\"width: 794px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-109513 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/11\/word-image-40.png\" alt=\"Defray777\u306f\u3001DEFAULTCOMPNAME\u3078\u306e\u30d5\u30a9\u30fc\u30eb\u30d0\u30c3\u30af\u306a\u3069\u3001\u5f0a\u793e\u3067\u5206\u6790\u3057\u305f\u3001\u66f4\u65b0\u3055\u308c\u305fPyXie\u30b5\u30f3\u30d7\u30eb\u3068\u540c\u3058\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u30eb\u30fc\u30c1\u30f3\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002Defray777\u304c\u7570\u306a\u3063\u305f\u52d5\u304d\u3092\u3059\u308b\u306e\u306f\u3001\u8a08\u7b97\u3055\u308c\u305fMD5\u30cf\u30c3\u30b7\u30e5\u306b\u5bfe\u3057\u30010x2\u3092\u4f7f\u3063\u3066XOR\u6f14\u7b97\u3092\u5b9f\u884c\u3059\u308b\u30b9\u30c6\u30c3\u30d7\u304c\u7701\u7565\u3055\u308c\u3066\u3044\u308b\u70b9\u3067\u3059\u3002\" width=\"794\" height=\"112\" \/><figcaption class=\"wp-caption-text\">\u56f327: Defray777\u306e\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u4f5c\u6210\u30d7\u30ed\u30bb\u30b9<\/figcaption><\/figure>\n<h2><a id=\"post-109455-_hnv40789grb5\"><\/a>\u7d50\u8ad6<\/h2>\n<p>2018\u5e74\u4ee5\u964d\u3001\u91d1\u878d\u6a5f\u95a2\u3092\u72d9\u3063\u305f\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u3001Vatet\u30ed\u30fc\u30c0\u30fc\u3001PyXie RAT\u3001Defray777\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e<em>\u7d44\u307f\u5408\u308f\u305b<\/em>\u3092\u4f7f\u7528\u3057\u3001\u653f\u5e9c\u3001\u533b\u7642\u3001\u6559\u80b2\u3001\u30c6\u30af\u30ce\u30ed\u30b8\u306e\u5404\u30bb\u30af\u30bf\u306e\u7d44\u7e54\u3092\u3001\u8ab0\u306b\u3082\u6c17\u4ed8\u304b\u308c\u308b\u3053\u3068\u306a\u304f\u6a19\u7684\u306b\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u305d\u306e\u6d3b\u52d5\u306f\u307b\u3068\u3093\u3069\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<p>\u672c\u7a3f\u3067\u79c1\u305f\u3061\u306f\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u304cVatet\u30ed\u30fc\u30c0\u30fc\u3092\u5c55\u958b\u3059\u308b\u624b\u6bb5\u3068\u3057\u3066\u30aa\u30fc\u30d7\u30f3 \u30bd\u30fc\u30b9 \u30c4\u30fc\u30eb\u3092\u5229\u7528\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u660e\u3089\u304b\u306b\u3057\u3001\u5075\u5bdf\u5b9f\u65bd\u3084\u30c7\u30fc\u30bf\u767a\u898b\u30fb\u6f0f\u51fa\u306bPyXie\u304c\u3069\u306e\u3088\u3046\u306b\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u304b\u3092\u8aac\u660e\u3057\u3066\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u304cCobalt Strike\u3092\u4f7f\u7528\u3057\u3066Defray777\u3092\u30e1\u30e2\u30ea\u306b\u9001\u308a\u8fbc\u307f\u3001\u30d5\u30a1\u30a4\u30eb\u3092\u6697\u53f7\u5316\u3057\u3066\u3001\u88ab\u5bb3\u8005\u306b\u58ca\u6ec5\u7684\u306a\u30c0\u30e1\u30fc\u30b8\u3092\u4e0e\u3048\u308b\u65b9\u6cd5\u3082\u8aac\u660e\u3057\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u5f0a\u793e\u3067\u306f\u3001\u3053\u3046\u3057\u3066\u3053\u306e\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u3092\u3088\u308a\u8a73\u3057\u304f\u89e3\u660e\u3059\u308b\u3053\u3068\u304c\u3001\u5f7c\u3089\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u80fd\u529b\u306e\u59a8\u3052\u306b\u306a\u308c\u3070\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002\u73fe\u5728\u306f\u5f7c\u3089\u306e\u52d5\u304d\u3092\u628a\u63e1\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u305f\u306e\u3067\u3001\u306d\u3089\u3044\u3092\u5b9a\u3081\u3066\u8ffd\u3044\u7d9a\u3051\u306a\u3051\u308c\u3070\u306a\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u4ee5\u4e0b\u306e\u65b9\u6cd5\u3067\u3053\u306e\u8105\u5a01\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u3053\u306e\u30ec\u30dd\u30fc\u30c8\u306e\u3059\u3079\u3066\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.com\/products\/secure-the-network\/wildfire\">WildFire<\/a>\u3067\u300cmalicious (\u60aa\u610f\u304c\u3042\u308b)\u300d\u3068\u5224\u5b9a\u3055\u308c\u307e\u3059\u3002<\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/endpoint-protection\">Cortex XDR<\/a>\u306f\u3001\u3053\u308c\u3089\u306e\u8105\u5a01\u3092\u691c\u51fa\u3057\u307e\u3059\u3002<\/li>\n<li>\u30b3\u30de\u30f3\u30c9&amp;\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.com\/products\/threat-detection-and-prevention\/web-security\">URL Filtering<\/a>\u3067\u60aa\u610f\u304c\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u5206\u985e\u6e08\u307f\u3067\u3059\u3002<\/li>\n<li>\u8ffd\u52a0\u3067\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3092\u5f97\u308b\u306b\u306f\u6b21\u306eAutoFocus\u30bf\u30b0\u3092\u5229\u7528\u3057\u3066\u304f\u3060\u3055\u3044\u3002\n<ul>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PyXie\">PyXie<\/a><\/li>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.RansomX\">RansomX<\/a> (\u5225\u540dDefray777)<\/li>\n<li><a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.Vatet\">Vatet<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u7d9a\u304d\u3092\u8aad\u3080: <a href=\"https:\/\/unit42.paloaltonetworks.jp\/vatet-pyxie-defray777\/5\">IoC (\u4fb5\u5bb3\u6307\u6a19)<\/a><!--nextpage--><\/p>\n<h2><a id=\"post-109455-_5gy2zx3w16b4\"><\/a>IoC (\u4fb5\u5bb3\u6307\u6a19)<\/h2>\n<h4><a id=\"post-109455-_jnxhfzbhytfh\"><\/a><strong>Cobalt Strike \u306e C2<\/strong><\/h4>\n<ul>\n<li>192.169.7[.]160<\/li>\n<li>51.79.42[.]156<\/li>\n<li>5.135.230[.]132<\/li>\n<li>162.216.240[.]7<\/li>\n<li>172.245.21[.]224<\/li>\n<li>192.169.6[.]180<\/li>\n<li>cloud[.]falconoasisdubai[.]com<\/li>\n<li>syvansoft[.]com<\/li>\n<li>gue[.]life<\/li>\n<li>m33[.]bar<\/li>\n<li>j3qq4[.]club<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_8h9c0ojezak3\"><\/a><strong>PyXie \u306e C2<\/strong><\/h4>\n<ul>\n<li>sarymar[.]com<\/li>\n<li>benreat[.]com<\/li>\n<li>planlamaison[.]com<\/li>\n<li>teamchuan[.]com<\/li>\n<li>tedxns[.]com<\/li>\n<li>mustome[.]com<\/li>\n<li>hekutn[.]com<\/li>\n<li>safealyzer[.]com<\/li>\n<li>bookrah[.]com<\/li>\n<li>c1oudflare[.]com<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_4wg72h6isgve\"><\/a><strong>Defray777 \u306e SHA256 \u30cf\u30c3\u30b7\u30e5\u5024<\/strong><\/h4>\n<ul>\n<li>4cae449450c07b7aa74314173c7b00d409eabfe22b86859f3b3acedd66010458<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_uw5ygjfnq6rv\"><\/a><strong>Defray777 \u306e Linux SHA256 \u30cf\u30c3\u30b7\u30e5\u5024<\/strong><\/h4>\n<ul>\n<li>78147d3be7dc8cf7f631de59ab7797679aba167f82655bcae2c1b70f1fafc13d<\/li>\n<li>cb408d45762a628872fa782109e8fcfc3a5bf456074b007de21e9331bb3c5849<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_7fa62ahwof2b\"><\/a><strong>PyXie Lite \u306e SHA256 \u30cf\u30c3\u30b7\u30e5\u5024<\/strong><\/h4>\n<ul>\n<li>5d26300ad2fc008fe278f17f98f173236c8bd7eeb6382062d677d1d6fd37c5b5<\/li>\n<li>82a2149aa09b2b59ee7c97e05d7200d4ccbcd8444182aca2f8c4913f1f59a42c<\/li>\n<li>0ad10472f7aedfd241ecb65a53d5cafdeb94672d92883d161cb37f769e60f013<\/li>\n<li>61b9b7e1329eb540dd751d1db6c00cc45d91b6f58db75ab0212976d4ec4c848e<\/li>\n<li>84428ece8efcb6298435b15d3c4ea281592accf0990cc840ef3a7a0644191061<\/li>\n<li>4d0176e2d6e30e31352f420a4dec79d26cb00f1e6c789b31e84cd05eb4d50956<\/li>\n<li>5e90a331bafd98e41bcf36419c44bd7ff8296ac18cce652e944ae22db15a5366<\/li>\n<li>fe564fb38a99dbb94cc8a66d8955b0b7f8e67bf0a5eb820c4a5d0c3efb96c1e5<\/li>\n<li>b2b3a199291c3651b1d7413c7dba92566a893010a50e770e1802f173f1c2c7a4<\/li>\n<li>5736e167e234e06b33e8d8d6bb80e13b1bacca8d7cd3271695220cdec2e4a79e<\/li>\n<li>a7affc0d93e27165ce44c55ae28189e8b55967443f9e464232f230ab4ba175ca<\/li>\n<li>b3c6f365819864340a8a8fe3076fb326c1debfdbbc826384cb2978aea82edc48<\/li>\n<li>c7ddbc24a57d1353d73533c47a65e5e3a74e3b666c1fed685fc90de1f089c72b<\/li>\n<li>510cf6e1c55a190490e93d222ea606ed888d222ecedda18bfb2f32bb73f33cab<\/li>\n<li>f80bcc60e79b387f63edfe0f1fc66492af4ff201ad5eb8080b1249ca43f6f30f<\/li>\n<li>6485bec374f255831b7ddbfed9925e988dcd7e893f610842809dd7cd1988cffc<\/li>\n<li>c58f5b3f7300a13fd9a0a61757e20399fc5e86544befdafae15e8809a02c2db0<\/li>\n<li>9847cea40cec394c947de06010ad1f3033316903b5c822ba16f9574acb30f0cd<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_e1olhlw2bg4j\"><\/a><strong>PyXie Lite \u306e\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u5f15\u6570<\/strong><\/h4>\n<p style=\"padding-left: 40px;\">-q -s {{}} -p<\/p>\n<h4><a id=\"post-109455-_sagz511zm6ow\"><\/a><strong>Pyxie Lite Exfil \u306e\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u30d1\u30b9<\/strong><\/h4>\n<ul>\n<li>%temp%\\tmp\\wifi_info.txt<\/li>\n<li>%temp%\\tmp\\software.txt<\/li>\n<li>%temp%\\tmp\\screen.jpg<\/li>\n<li>%temp%\\tmp\\pwds.txt<\/li>\n<li>%temp%\\tmp\\general.txt<\/li>\n<li>%temp%\\tmp\\disks_info.txt<\/li>\n<li>%temp%\\tmp\\desk_files.txt<\/li>\n<li>%temp%\\tmp\\cpu_ram.txt<\/li>\n<li>%temp%\\tmp\\arp_a.txt<\/li>\n<li>%temp%\\tmp\\cmdkey_list.txt<\/li>\n<li>%temp%\\tmp\\cpu_ram.txt<\/li>\n<li>%temp%\\tmp\\disks_info.txt<\/li>\n<li>%temp%\\tmp\\files.txt<\/li>\n<li>%temp%\\tmp\\general.txt<\/li>\n<li>%temp%\\tmp\\gpresult_z.txt<\/li>\n<li>%temp%\\tmp\\ipconfig_all.txt<\/li>\n<li>%temp%\\tmp\\ipconfig_displaydns.txt<\/li>\n<li>%temp%\\tmp\\mimi.txt<\/li>\n<li>%temp%\\tmp\\net_config_workstation.txt<\/li>\n<li>%temp%\\tmp\\net_group_domain_admins_domain.txt<\/li>\n<li>%temp%\\tmp\\net_group_domain_admins.txt<\/li>\n<li>%temp%\\tmp\\net_group_enterprise_admins.txt<\/li>\n<li>%temp%\\tmp\\net_localgroup_administrators.txt<\/li>\n<li>%temp%\\tmp\\net_localgroup.txt<\/li>\n<li>%temp%\\tmp\\net_share.txt<\/li>\n<li>%temp%\\tmp\\net_use.txt<\/li>\n<li>%temp%\\tmp\\net_user.txt<\/li>\n<li>%temp%\\tmp\\net_view_all_domain.txt<\/li>\n<li>%temp%\\tmp\\net_view_all.txt<\/li>\n<li>%temp%\\tmp\\netstat_an.txt<\/li>\n<li>%temp%\\tmp\\nslookup_typeany_userdnsdomain.txt<\/li>\n<li>%temp%\\tmp\\portscan.txt<\/li>\n<li>%temp%\\tmp\\pwds.txt<\/li>\n<li>%temp%\\tmp\\route_print.txt<\/li>\n<li>%temp%\\tmp\\soft.txt<\/li>\n<li>%temp%\\tmp\\software.txt<\/li>\n<li>%temp%\\tmp\\systeminfo.txt<\/li>\n<li>%temp%\\tmp\\tasklist_v.txt<\/li>\n<li>%temp%\\tmp\\wmic_process.txt<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_y5u3e1mzyzln\"><\/a><strong>PyXie \u306e SHA256 \u30cf\u30c3\u30b7\u30e5\u5024<\/strong><\/h4>\n<ul>\n<li>70dfa6b21f5eea28ccb77ddac876cf6eac58b2ac55ab7b9ee52d79b1b5f3734d<\/li>\n<li>8d2b3b0cbb32618b86ec362acd142177f5890917ae384cb58bd64f61255e9c7f<\/li>\n<li>260be87cd75f304272094d3bef02eff6ef6b605f01ffe2983361e6e2f6116769<\/li>\n<li>09bb81e5a6c716f14c625ff36beb3b184d0089ed29252af10635b604b69f22ef<\/li>\n<li>70dfa6b21f5eea28ccb77ddac876cf6eac58b2ac55ab7b9ee52d79b1b5f3734d<\/li>\n<li>744d0c4b89e1b2ddd70d614b4dc009afa8f3a528c821c371cf72e60cc3367f19<\/li>\n<li>37268f0ade3050fa2008b546920c4f2052732c092de04a6e108257f5de22ff48<\/li>\n<li>80bd15267756343f028cbe77afe810068b0e6a36ce32f52be63f620ef5b5ed89<\/li>\n<li>e2d4aa8662b3db2f3857dbacada1ff0da0ceaf75bbba579bc5ef1a555c065206<\/li>\n<li>aed5b487e13e920835b0ba5ca964e25a815f8a10011d8e1eb29278ae254771d9<\/li>\n<li>f9da4d61344457c3d68ef0525139c2cf6ee28d3f09220168ba2be601b5c54d6f<\/li>\n<li>e03680e0af40a6fa1a12bed2f701c6137335d28b3d222579552658e951cbd13c<\/li>\n<li>e2faf6586f8ac70cd98e4ec648f79435bfabaf84d440044aedce0c5c59b662e8<\/li>\n<li>814357417aa8a57e43d50cb3347c9d287b99955b0b8aee4e53e12b463f7441a0<\/li>\n<li>de44656b4a3dde6e0acdc6f59f73114ce6bb6342bec0dcd45da8676d78b0042e<\/li>\n<li>78471db16d7bd484932c8eb72f7001db510f4643b3449d71d637567911ca363b<\/li>\n<li>e0f22863c84ee634b2650b322e6def6e5bb74460952f72556715272c6c18fe8e<\/li>\n<li>563dd5a95f439bc2b4170a74c8be565a1af076e6cbebd1d018b2809a1e8bc908<\/li>\n<li>411eb20988f57317c177ea64c8bb4c059cc39da6e91eb1e7b9b8da96775d93d5<\/li>\n<li>ed675db1e7c93526141d40ba969bdc5bbdfd013932aaf1e644c66db66ff008e0<\/li>\n<li>f9290cd938d134a480b41d99ac2c5513a964de001602ed34c6383dfeb577b8f7<\/li>\n<li>d271569d5557087aecc340bb570179b73265b29bed2e774d9a2403546c7dd5ff<\/li>\n<li>3a47e59c37dce42304b345a16ba6a3d78fc44b21c4d0e3a0332eee21f1d13845<\/li>\n<li>92a8b74cafa5eda3851cc494f26db70e5ef0259bc7926133902013e5d73fd285<\/li>\n<li>ea27862bd01ee8882817067f19df1e61edca7364ce649ae4d09e1a1cae14f7cc<\/li>\n<li>c3b3f46a5c850971e1269d09870db755391dcbe575dc7976f90ccb1f3812d5ea<\/li>\n<li>edd1480fe3d83dc4dc59992fc8436bc1f33bc065504dccf4b14670e9e2c57a89<\/li>\n<li>3aa746bb94acee94c86a34cb0b355317de8404c91de3f00b40e8257b80c64741<\/li>\n<li>1d970f2e7af9962ae6786c35fcd6bc48bb860e2c8ca74d3b81899c0d3a978b2b<\/li>\n<li>56e96ce15ebd90c197a1638a91e8634dbc5b0b4d8ef28891dcf470ca28d08078<\/li>\n<li>5937746fc1a511d9a8404294b0caa2aedae2f86b5b5be8159385b6c7a4d6fb40<\/li>\n<li>0da9e149ba324f20a390140e9d7913b13ababa07f5b65e4d25e3555c1119e768<\/li>\n<li>a765df03fffa343aa7a420a0a57d4b5c64366392ab6162c3561ff9f7b0ad5623<\/li>\n<li>7330fa1ca4e40cdfea9492134636ef06cd999efb71f510074d185840ac16675d<\/li>\n<li>c9400b2fff71c401fe752aba967fa8e7009b64114c9c431e9e91ac39e8f79497<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_2dq2czgt6jmf\"><\/a><strong>PyXie \u306e\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u5f15\u6570<\/strong><\/h4>\n<ul>\n<li>%SYSTEMROOT%\\system32\\worker.exe<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_rw40mchc41t7\"><\/a><strong>Vatet \u306e SHA256 \u30cf\u30c3\u30b7\u30e5\u5024<\/strong><\/h4>\n<ul>\n<li>bacc02fd23c4f95da0fbc5c490b1278d327fea0878734ea9a55f108ef9f4312e<\/li>\n<li>5e0062def3e1d2ac206aa43854a60e23b0d1158fa982e99e0ba8190e77290dbf<\/li>\n<li>4421720e0321ac8b3820f8178eb8a5ff684388438b62c85f93df9743a1d9fdb9<\/li>\n<li>915e660ec51abea9ffd5716fb2c9b8593643adc5e9ea0834a88d8ea4016899f0<\/li>\n<li>0b42bf15b77cfe9f9e693f2776691647e78a91be27f5bdb8d1a366be510a773f<\/li>\n<li>57eea67e3eebde707c3fb3473a858e7f895ae12aad37cc664f9c0512c0382e6a<\/li>\n<li>2f149a79f721bb78eb956f70183b531fb6a1b233ceb4a3d6385759a0b0c16fd3<\/li>\n<li>6ac07424e5c9b87d76645aa041772ac8af12e30dc670be8adf1cf9f48e32944b<\/li>\n<li>382d9bf5da142d44de5fda544de4fffe2915a3ffc67964b993f3c051aa8c2989<\/li>\n<li>ef7e21d874a387f07a9f74f01f2779a280ff06dff3dae0d41906d21e02f9c975<\/li>\n<li>e5ce1c1b69bd12640c604971be311f9544adb3797df15199bd754d3aefe0a955<\/li>\n<li>37e8d3ae4c34441b30098d7711df8ef0bcc12c395f265106b825221744b956bc<\/li>\n<li>10c4067908181cebb72202d92ff7a054b19ef3aada939bf76178e35be9506525<\/li>\n<li>b159fadb829a206c9a59ec547aa9e2a3ee83e8a3cc1441de04f58fd02a43c760<\/li>\n<li>6c1b17c8d8eca38b9926b40637cb793d0997a6183156d9e6353b53d7b3955f20<\/li>\n<li>375afe90771e63dbec77de439625267d723dc6bbb37cc5e94cf4d281d16c2ca8<\/li>\n<li>4d39782ccdb902e8e5348b8b3ce92f0834c713c565cca82be67a0a8eb6468df6<\/li>\n<li>6497d14f6dd14c39c037cb7da24b51d90b7040af64c245aaab6c6cc80cde7f3b<\/li>\n<li>95e5e83b10df32f06080bd6f8428592d81febbf55e72ec5f843dd6188bef25da<\/li>\n<li>01a2404fcf56027be610c65bbfb0f2dda9cfaf67385cb7f93f0b586e3aa6803a<\/li>\n<li>b7fbbbdf7e8795022a41f4e6a94be1de432ae1911e49625f73555e01a5fdc719<\/li>\n<li>d7bcb52f027f66c988e595dc29a343e27af7599e3659901f85a92c26440a5e1f<\/li>\n<li>d353eeb623e96b32c086a9b64991dfedbc8d31254aec2c3cda51042ceb07ee82<\/li>\n<li>66c2038c6d86333cbc51726bc54d3b8a00162493b2c92ca7f839b50435eaa314<\/li>\n<li>47d6cc0a05218d0c1078dabf8d0ca7b7b424cdd73eaf3bf6261fa1b42f92fe0b<\/li>\n<li>5dc7f70a0d20f97c30c25bd927235deec713cde5d1c41916e23dd0c3431ffacd<\/li>\n<li>7ad92c9d63bd9ed305acbe217c40f9945deb98ed5ecced8b92b93332dc27d3c6<\/li>\n<li>d46f72b8598ff80de5661205f6cac0b47831778f70b5edd7525e23418706cc1a<\/li>\n<li>ccc162d3a3d6136a9c472d7d2d07acbae47f88a9a7d9b2c9b97b331e7ab7605d<\/li>\n<li>3cd581621d9a16ebe724e9ba7445aa82162307ff6b2a31be572e87dbce2aa8ad<\/li>\n<li>e1653fe62e8d90153557324ffe4470d9c9262fe3bddad2bf555680b6078cf66a<\/li>\n<li>75728bc96c934c1521ae08e03ec916e20628e000b056c55b6ee04ccc18c602f6<\/li>\n<li>a50a25a312adb9103e52e94018013ebdb6dbfe792a34122cacd53cfa3bbb26ac<\/li>\n<li>87210d6f1773473d28b51de21ed55ecfb6a9bd34f56d2d37f483ed05a1d7efd8<\/li>\n<li>d7d28af8af5be22ecca267bdc7e142667f584550cf8a3bbebdb1368725bb6469<\/li>\n<li>d7641089fd5d0474b835a633d6d852028b3481c18b3574023b021bfa1e3c1cc1<\/li>\n<li>5aec2fa9e954473d9c6b5233512f833e63541965e2d2e4af2419a457676c440d<\/li>\n<li>fcdd72fd2e03badfac13eed5e2d17054bbdcea7c1743179095ce109bf40a7f0f<\/li>\n<li>350926c6bb7419330e55e687c9f00520a560c41f6013528cbb9ea42faeeb3201<\/li>\n<li>8eef012c2eecb7f8a776464f52e12f62c466cfc85adf4eef0d2bc270e7a19212<\/li>\n<li>3928bd8f2fd2db4891b320fa85b37c2598706d27283818ad33a0eeac16d59192<\/li>\n<li>8373be56ddab97188a8606eb5f529187bfb819f5cb5a50c56f6a7878c94c7f86<\/li>\n<li>a098b5455fd1e9d0dea067405cd891b94cc42a0067cbd21d385f9c1254c21fdd<\/li>\n<li>2b13dae3c35eb3958253dbf945f6609e59978c2aedbd163608f03920d7d3623b<\/li>\n<li>01011bb45dec3b520ea09e5d9d3c9fb4acce74de72261f68ff1011f9ea6ccebb<\/li>\n<li>80c9d6cf4e8119dc2d0e263f3f4d5c3bf4221715117505d9d6a02e3671337bf8<\/li>\n<li>bec5a3cfd7332241e3a7463d951b8f9a9e771d4f436d7776a426074a82d19a7d<\/li>\n<li>c7f96f8b15c324bd6bf1aa16f6697d6d407f91ad2d7628a14d70f146334d34be<\/li>\n<li>c5ca45581da0bbb3e4d0c6e51d602512fa52833cd16eebed351397a9a0326518<\/li>\n<li>6f1e8f91773609087a417cb34887f292a0be5c246dab667195854f979a45349a<\/li>\n<li>e07dd37c92d24ac20b94a183e1f0a22a4eec0f950f441761c065faf0afd2abdd<\/li>\n<li>0d14a1b5574dc12f6286d37d0a624232fb63079416b98c2e1cb5c61f8c2b66ff<\/li>\n<li>e5fede5eb43732c7f098acf7b68b1350c6524962215b476de571819b6e5a71fc<\/li>\n<li>ecf3f4ba8dd16551908488cfbf2afd18a55584dbf81c28623026a29b9fa4a62d<\/li>\n<li>edecfdd2a26b4579ecacf453b9dff073233fb66d53c498632464bca8b3084dc5<\/li>\n<li>1309b052618c6301901ec75cf552e7b49f93d66fb47d4de59b82d37d6ac39039<\/li>\n<li>2ceb5de547ad250140c7eb3c3d73e4331c94cf5a472e2806f93bf0d9df09d886<\/li>\n<li>3259dd0efed1d28a149d4e8c4f980a19199d9bead951ee1231e3a26521185f2f<\/li>\n<li>3a3b7b198769de3e5d81a92aa166f783b611a39a7fcea1b5ec762b54295dbc8d<\/li>\n<li>56934547dcf0d7ecf61868ae2f620f60e94c094dbd5c3b5aaf3d3a904d20a693<\/li>\n<li>608f34a79e5566593b284ef0d24f48ea89bc007e5654ae0969e6d9f92ec87d32<\/li>\n<li>625c22b21277c8a7e1b701da9c1c21b64bfa02baef5d7a530a38f6d70a7a16d0<\/li>\n<li>73609f8ebd14c6970d9162ec8d7786f5264e910573dff73881f85b03163bd40e<\/li>\n<li>840985b782648d57de302936257ba3d537d21616cb81f9dce000eaf1f76a56c8<\/li>\n<li>88565b4c707230eac34d4528205056264cd70d797b6b4eb7d891821b00187a69<\/li>\n<li>91c62841844bde653e0357193a881a42c0bc9fcc798a69f451511c6e4c46fd18<\/li>\n<li>a50b58e24eb261157c4f85d02412d80911abe8501b011493c7b393c1905fc234<\/li>\n<li>b1f54b88c9b7680877981f6bebde6aea9effbc38a0a8b27a565fb35331094680<\/li>\n<li>bd7da341a28a19618b53e649a27740dfeac13444ce0e0d505704b56335cc55bd<\/li>\n<li>cb2619b7aab52d612012386d88a0d983c270d9346169b75d2a55010564efc55c<\/li>\n<li>ce0936366976f07ea24e86733888e97e421393829ecfd0fde66bd943d4b992ab<\/li>\n<li>d50f28cf5012e1ffde1cd28655e07519dadcf94218b15c701c526ab0f6acb915<\/li>\n<li>d612144c1f6d4a063530ba5bfae7ef4e4ae134bc55dcf067439471934b841b00<\/li>\n<li>ddf83c02effea8ae9ec2c833bf40187bed23ec33c6b828af49632ef98004ea82<\/li>\n<li>e48e88542ec4cd6f1aa794abc846f336822b1104557c0dfe67cff63e5231c367<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_10is3tbvelb3\"><\/a><strong>Vatet \u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e SHA256 \u30cf\u30c3\u30b7\u30e5\u5024<\/strong><\/h4>\n<ul>\n<li>a512e5ffd33da906fdf896c536bf64adc59599ec2227f60dace4a4ef23d3d21a<\/li>\n<li>56f6084d84bd6371918c3ae7b555099474cdb6665bed0d969f6b5762b8cf5cc9<\/li>\n<li>2f1e047e840620460bdf7371e62e966919f25f763a53248357f890a4ff11791f<\/li>\n<li>6812190b1dec8c2a4c5d2b327d1bdbe72974fc017d86d2337ea06e9d3337959e<\/li>\n<li>77f2df32060e5125c6d4a3ab2a2a0c862eb44bc44614d494d23f4690a45d08a3<\/li>\n<li>309af51a8d86e031e25c2c928101b9afc9bcd1dcadbf4ef27ed3c0e8d7da0c98<\/li>\n<li>c2861e5626c5ba40d28ec6c7d4ac32edc972a969d2454e74dc50829d02b5de2a<\/li>\n<li>8a7dc1c39321d972a21bf4fdd24f6f2ef3a03e4ea95c49f383ba03902010210c<\/li>\n<li>0e7824dfb7668af175a2b887e592773517f17213555c3b9af4f98d54278621d5<\/li>\n<li>d389e2fc1515b8a2d8d365d072c201a308f776c873fdb185f826a35fde6fbf2b<\/li>\n<li>bde87df68407fafc3ebd95665838eb5476cb854b338fb97252d153a2250f28b8<\/li>\n<li>ab432a84b05de381c2f96a000c318ec78c98e39abfa7eea3210840c85b0cbee7<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_xo9fwugbv6l0\"><\/a><strong>Vatet \u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30d1\u30b9<\/strong><\/h4>\n<ul>\n<li>\\\\\\\\settings.dat<\/li>\n<li>\\\\\\\\upgrade.dat<\/li>\n<li>\\\\\\\\vodafone.dat<\/li>\n<li>\\\\\\\\winint2.sto<\/li>\n<li>c:\\windows\\INF\\Rainmeter.dat<\/li>\n<li>c:\\windows\\INF\\notepad.dat<\/li>\n<li>c:\\windows\\INF\\options.dat<\/li>\n<li>c:\\windows\\debug\\Rainmeter.dat<\/li>\n<li>c:\\windows\\debug\\config.dat<\/li>\n<li>c:\\windows\\debug\\notepad.dat<\/li>\n<li>c:\\windows\\debug\\options.dat<\/li>\n<li>c:\\windows\\help\\Rainmeter.dat<\/li>\n<li>c:\\windows\\help\\notepad.dat<\/li>\n<li>c:\\windows\\help\\options.dat<\/li>\n<li>c:\\windows\\media\\notepad.dat<\/li>\n<li>c:\\windows\\notepad.dat<\/li>\n<li>c:\\windows\\options.dat<\/li>\n<li>c:\\windows\\system\\options.dat<\/li>\n<li>c:\\windows\\temp\\options.dat<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_d7fuvnn503l1\"><\/a><strong>PDB \u306e\u30d1\u30b9<\/strong><\/h4>\n<ul>\n<li>C:\\Users\\1\\Downloads\\notepad-plus-plus-master\\PowerEditor\\bin\\npp.pdb<\/li>\n<li>C:\\Users\\1\\Downloads\\rainmeter-master\\x32-Release\\Obj\\Library\\Rainmeter.pdb<\/li>\n<li>C:\\Users\\1\\Downloads\\rainmeter-master\\x32-Release\\Obj\\Application\\Rainmeter.pdb<\/li>\n<li>C:\\Users\\1\\Downloads\\notepad-master\\Debug\\notepad.pdb<\/li>\n<li>C:\\Users\\1\\Downloads\\tetris-game-master\\Release\\TetrisGame_zjy.pdb<\/li>\n<li>Z:\\coding\\pyproject\\compiled\\cobalt_mode\\cobalt_mode.pdb<\/li>\n<li>Z:\\coding\\pyproject\\compiled\\ransom\\ransom.pdb<\/li>\n<\/ul>\n<h4><a id=\"post-109455-_dimgtjrik8vy\"><\/a><strong>PyXie Lite \u306e\u8a2d\u5b9a<\/strong><\/h4>\n<table>\n<tbody>\n<tr>\n<td>{<br \/>\n\u201clogs\u201d: {<br \/>\n\u201cgates\u201d: [<br \/>\n\u201c:8443\/data\u201d<br \/>\n],<br \/>\n\u201caes_key\u201d: \u201cTHIS_KEY_IS_FOR_INTERNAL_USE_ONLY\u201d,<br \/>\n\u201csend_attempts\u201d: 10,<br \/>\n\u201csend_attempts_timeout\u201d: 5<br \/>\n},<br \/>\n\u201cdirs_keys\u201d: [\u201cactifio\u201d,<br \/>\n\u201caldelo\u201d,<br \/>\n\u201caltaro\u201d,<br \/>\n\u201cavamar\u201d,<br \/>\n\u201cavs\u201d,<br \/>\n\u201cback-up\u201d,<br \/>\n\u201cbackup\u201d,<br \/>\n\u201cbank\u201d,<br \/>\n\u201cbitmessage\u201d,<br \/>\n\u201cclient\u201d,<br \/>\n\u201ccobaltstrike\u201d,<br \/>\n\u201ccoin\u201d,<br \/>\n\u201cdiebold\u201d,<br \/>\n\u201cfilemaker\u201d,<br \/>\n\u201chtape\u201d,<br \/>\n\u201cmagtek\u201d,<br \/>\n\u201cncr\u201d,<br \/>\n\u201cpassw\u201d,<br \/>\n\u201cpayment\u201d,<br \/>\n\u201crapid7\u201d,<br \/>\n\u201creplication\u201d,<br \/>\n\u201cscreenconnect\u201d,<br \/>\n\u201cswift\u201d,<br \/>\n\u201ctivoli\u201d,<br \/>\n\u201cunitrends\u201d,<br \/>\n\u201cvault\u201d,<br \/>\n\u201cveeam\u201d,<br \/>\n\u201cvranger\u201d,<br \/>\n\u201cwallet\u201d,<br \/>\n\u201cwincor\u201d],<br \/>\n\u201cshell_cmds\u201d: [\u201carp -a\u201d,<br \/>\n\u201ccmdkey \/list\u201d,<br \/>\n\u201cdclist\u201d,<br \/>\n\u201cgpresult \/z\u201d,<br \/>\n\u201cipconfig \/all\u201d,<br \/>\n\u201cipconfig \/displaydns\u201d,<br \/>\n\u201cklist\u201d,<br \/>\n\u201cmanage-bde -status\u201d,<br \/>\n\u201cnet config workstation\u201d,<br \/>\n\u201cnet group \\\u201ddomain admins\\\u201d \/domain\u201d,<br \/>\n\u201cnet group \\\u201dDomain Admins\\\u201d\u201d,<br \/>\n\u201cnet group \\\u201dEnterprise Admins\\\u201d\u201d,<br \/>\n\u201cnet localgroup \\\u201dadministrators\\\u201d\u201d,<br \/>\n\u201cnet localgroup\u201d,<br \/>\n\u201cnet share\u201d,<br \/>\n\u201cnet use\u201d,<br \/>\n\u201cnet user\u201d,<br \/>\n\u201cnet view \/all \/domain\u201d,<br \/>\n\u201cnet view \/all\u201d,<br \/>\n\u201cnetstat -an\u201d,<br \/>\n\u201cnltest \/domain_trusts \/all_trusts\u201d,<br \/>\n\u201cnltest \/domain_trusts\u201d,<br \/>\n\u201cnslookup -type=any %userdnsdomain%\u201d,<br \/>\n\u201cqwinsta\u201d,<br \/>\n\u201croute print\u201d,<br \/>\n\u201csysteminfo\u201d,<br \/>\n\u201ctasklist \/V\u201d,<br \/>\n\u201cvssadmin List Shadows\u201d,<br \/>\n\u201cwmic process\u201d,<br \/>\n\u201cwmic qfe list\u201d],<br \/>\n\u201cdirs\u201d: [\u201c%ALLDRIVESROOTS%\\\\Alliance\u201d,<br \/>\n\u201c%APPDATA%\\\\Agama\u201d,<br \/>\n\u201c%APPDATA%\\\\Armory\u201d,<br \/>\n\u201c%APPDATA%\\\\B3-CoinV2\u201d,<br \/>\n\u201c%APPDATA%\\\\BeerMoney\u201d,<br \/>\n\u201c%APPDATA%\\\\Bitcloud\u201d,<br \/>\n\u201c%APPDATA%\\\\Bitcoin\u201d,<br \/>\n\u201c%APPDATA%\\\\BitcoinZ\u201d,<br \/>\n\u201c%APPDATA%\\\\bitconnect\u201d,<br \/>\n\u201c%APPDATA%\\\\Bither\u201d,<br \/>\n\u201c%APPDATA%\\\\bitmonero\u201d,<br \/>\n\u201c%APPDATA%\\\\BlocknetDX\u201d,<br \/>\n\u201c%APPDATA%\\\\Cybroscoin\u201d,<br \/>\n\u201c%APPDATA%\\\\Daedalus\u201d,<br \/>\n\u201c%APPDATA%\\\\DashCore\u201d,<br \/>\n\u201c%APPDATA%\\\\DeepOnion\u201d,<br \/>\n\u201c%APPDATA%\\\\DigiByte\u201d,<br \/>\n\u201c%APPDATA%\\\\Dogecoin\u201d,<br \/>\n\u201c%APPDATA%\\\\ElectronCash\u201d,<br \/>\n\u201c%APPDATA%\\\\Electrum\u201d,<br \/>\n\u201c%APPDATA%\\\\Electrum-LTC\u201d,<br \/>\n\u201c%APPDATA%\\\\Ember\u201d,<br \/>\n\u201c%APPDATA%\\\\EmeraldWallet\u201d,<br \/>\n\u201c%APPDATA%\\\\Ethereum Wallet\u201d,<br \/>\n\u201c%APPDATA%\\\\Exodus\u201d,<br \/>\n\u201c%APPDATA%\\\\FairCoin\u201d,<br \/>\n\u201c%APPDATA%\\\\faircoin2\u201d,<br \/>\n\u201c%APPDATA%\\\\Florincoin\u201d,<br \/>\n\u201c%APPDATA%\\\\FORT\u201d,<br \/>\n\u201c%APPDATA%\\\\GambitCoin\u201d,<br \/>\n\u201c%APPDATA%\\\\GeyserCoin\u201d,<br \/>\n\u201c%APPDATA%\\\\GreenCoinV2\u201d,<br \/>\n\u201c%APPDATA%\\\\GridcoinResearch\u201d,<br \/>\n\u201c%APPDATA%\\\\Gulden\u201d,<br \/>\n\u201c%APPDATA%\\\\Hush\u201d,<br \/>\n\u201c%APPDATA%\\\\IOTA Wallet\u201d,<br \/>\n\u201c%APPDATA%\\\\Komodo\u201d,<br \/>\n\u201c%APPDATA%\\\\Learncoin\u201d,<br \/>\n\u201c%APPDATA%\\\\lisk-nano\u201d,<br \/>\n\u201c%APPDATA%\\\\Litecoin\u201d,<br \/>\n\u201c%APPDATA%\\\\Minexcoin\u201d,<br \/>\n\u201c%APPDATA%\\\\mSIGNA_Bitcoin\u201d,<br \/>\n\u201c%APPDATA%\\\\MultiBitHD\u201d,<br \/>\n\u201c%APPDATA%\\\\MultiDoge\u201d,<br \/>\n\u201c%APPDATA%\\\\Neon\u201d,<br \/>\n\u201c%APPDATA%\\\\NXT\u201d,<br \/>\n\u201c%APPDATA%\\\\Parity\u201d,<br \/>\n\u201c%APPDATA%\\\\Particl\u201d,<br \/>\n\u201c%APPDATA%\\\\Peercoin\u201d,<br \/>\n\u201c%APPDATA%\\\\pink2\u201d,<br \/>\n\u201c%APPDATA%\\\\PPCoin\u201d,<br \/>\n\u201c%APPDATA%\\\\Qtum\u201d,<br \/>\n\u201c%APPDATA%\\\\RainbowGoldCoin\u201d,<br \/>\n\u201c%APPDATA%\\\\RoboForm\u201d,<br \/>\n\u201c%APPDATA%\\\\StartCOIN-v2\u201d,<br \/>\n\u201c%APPDATA%\\\\straks\u201d,<br \/>\n\u201c%APPDATA%\\\\Stratis\u201d,<br \/>\n\u201c%APPDATA%\\\\StratisNode\u201d,<br \/>\n\u201c%APPDATA%\\\\TREZOR Bridge\u201d,<br \/>\n\u201c%APPDATA%\\\\TrumpCoinV2\u201d,<br \/>\n\u201c%APPDATA%\\\\VeriCoin\u201d,<br \/>\n\u201c%APPDATA%\\\\Verium\u201d,<br \/>\n\u201c%APPDATA%\\\\Viacoin\u201d,<br \/>\n\u201c%APPDATA%\\\\VivoCore\u201d,<br \/>\n\u201c%APPDATA%\\\\Xeth\u201d,<br \/>\n\u201c%APPDATA%\\\\Zcash\u201d,<br \/>\n\u201c%APPDATA%\\\\ZcashParams\u201d,<br \/>\n\u201c%APPDATA%\\\\Zetacoin\u201d,<br \/>\n\u201c%LOCALAPPDATA%\\\\bisq\u201d,<br \/>\n\u201c%LOCALAPPDATA%\\\\copay\u201d,<br \/>\n\u201c%LOCALAPPDATA%\\\\programs\\\\zap-desktop\u201d,<br \/>\n\u201c%LOCALAPPDATA%\\\\RippleAdminConsole\u201d,<br \/>\n\u201c%LOCALAPPDATA%\\\\StellarWallet\u201d,<br \/>\n\u201c%PROGRAMDATA%\\\\bitmonero\u201d,<br \/>\n\u201c%PROGRAMDATA%\\\\electroneum\u201d,<br \/>\n\u201c%PROGRAMDATA%\\\\Tiger Technology\u201d,<br \/>\n\u201c%PROGRAMDATA%\\\\tivoli\u201d],<br \/>\n\u201cfile_find\u201d: {<br \/>\n\u201cenabled\u201d: 1,<br \/>\n\u201cpatterns\u201d: [\u201c10-q\u201d,<br \/>\n\u201c10-sb\u201d,<br \/>\n\u201caccess\u201d,<br \/>\n\u201cavamar\u201d,<br \/>\n\u201cadmin\u201d,<br \/>\n\u201cattack\u201d,<br \/>\n\u201caws\u201d,<br \/>\n\u201camazon\u201d,<br \/>\n\u201cbackup\u201d,<br \/>\n\u201cbalance\u201d,<br \/>\n\u201cbitcoin\u201d,<br \/>\n\u201cbitlocker\u201d,<br \/>\n\u201cbribery\u201d,<br \/>\n\u201ccardholder\u201d,<br \/>\n\u201ccensored\u201d,<br \/>\n\u201cchecking\u201d,<br \/>\n\u201cclandestine\u201d,<br \/>\n\u201ccompromate\u201d,<br \/>\n\u201cconcealed\u201d,<br \/>\n\u201cconfidential\u201d,<br \/>\n\u201ccontraband\u201d,<br \/>\n\u201cconvict\u201d,<br \/>\n\u201ccredent\u201d,<br \/>\n\u201ccyber\u201d,<br \/>\n\u201cdisclosure\u201d,<br \/>\n\u201cengineering\u201d,<br \/>\n\u201cesxi\u201d,<br \/>\n\u201cethereum\u201d,<br \/>\n\u201cexplosive\u201d,<br \/>\n\u201cfinance\u201d,<br \/>\n\u201cfraud\u201d,<br \/>\n\u201chidden\u201d,<br \/>\n\u201cillegal\u201d,<br \/>\n\u201cinfrastruct\u201d,<br \/>\n\u201cinstruction\u201d,<br \/>\n\u201cinvestigation\u201d,<br \/>\n\u201clogins\u201d,<br \/>\n\u201cmarketwired\u201d,<br \/>\n\u201cmilitary\u201d,<br \/>\n\u201cn-csr\u201d,<br \/>\n\u201cnasdaq\u201d,<br \/>\n\u201cnda\u201d,<br \/>\n\u201cnewswire\u201d,<br \/>\n\u201coperation\u201d,<br \/>\n\u201cpassport\u201d,<br \/>\n\u201cpassw\u201d,<br \/>\n\u201cpersonal\u201d,<br \/>\n\u201cprivacy\u201d,<br \/>\n\u201cprivate\u201d,<br \/>\n\u201crestricted\u201d,<br \/>\n\u201crouting\u201d,<br \/>\n\u201csaving\u201d,<br \/>\n\u201csecret\u201d,<br \/>\n\u201csecurity\u201d,<br \/>\n\u201cspy\u201d,<br \/>\n\u201cstatement\u201d,<br \/>\n\u201cstorage\u201d,<br \/>\n\u201csubmarine\u201d,<br \/>\n\u201csuspect\u201d,<br \/>\n\u201ctactical\u201d,<br \/>\n\u201ctreason\u201d,<br \/>\n\u201cusername\u201d,<br \/>\n\u201cvault\u201d,<br \/>\n\u201cvictim\u201d,<br \/>\n\u201cvsphere\u201d,<br \/>\n\u201cwallet\u201d,<br \/>\n\u201cwasabi\u201d,<br \/>\n\u201cwire\u201d<br \/>\n],<br \/>\n\u201cextentions\u201d: [\u201c.doc\u201d,<br \/>\n\u201c.docx\u201d,<br \/>\n\u201c.xls\u201d,<br \/>\n\u201c.xlsx\u201d,<br \/>\n\u201c.pdf\u201d,<br \/>\n\u201c.txt\u201d,<br \/>\n\u201c.rtf\u201d],<br \/>\n\u201cgold_masks\u201d: [\u201c*.rdp\u201d,<br \/>\n\u201c*.kdbx\u201d,<br \/>\n\u201c*.vnc\u201d,<br \/>\n\u201c*.cpp\u201d,<br \/>\n\u201c*.c\u201d,<br \/>\n\u201c*.sln\u201d,<br \/>\n\u201c*.vcproj\u201d,<br \/>\n\u201c*.h\u201d,<br \/>\n\u201c*.asm\u201d,<br \/>\n\u201c*cobaltstrike*\u201d,<br \/>\n\u201c*.ovpn\u201d,<br \/>\n\u201c*.pcf\u201d,<br \/>\n\u201c*.conf\u201d],<br \/>\n\u201cblack_files\u201d: [\u201cDefault.rdp\u201d,<br \/>\n\u201cMicrosoft June\u201d,<br \/>\n\u201cRelease_Note\u201d,<br \/>\n\u201cRelease Note\u201d,<br \/>\n\u201cdesktop.ini\u201d,<br \/>\n\u201cMicrosoft Silverlight\u201d,<br \/>\n\u201clocalhost_access_log\u201d,<br \/>\n\u201cdd_clwireg.txt\u201d],<br \/>\n\u201cblack_dirs\u201d: [\u201c\\\\microsoft\\\\windows\u201d,<br \/>\n\u201c\\\\gfi\\\\languard\u201d,<br \/>\n\u201c\\\\microsoft\\\\windows\\\\cookies\u201d,<br \/>\n\u201c\\\\vmware\\\\vcenterserver\u201d,<br \/>\n\u201c\\\\autoupdate\\\\cache\u201d,<br \/>\n\u201c\\\\microsoft office\\\\root\u201d],<br \/>\n\u201cmax_size\u201d: 5242880<br \/>\n},<br \/>\n\u201csoftware\u201d: [\u201d OPOS\u201d,<br \/>\n\u201cAldelo\u201d,<br \/>\n\u201cActifio\u201d,<br \/>\n\u201cAlliance WebStation\u201d,<br \/>\n\u201cAlliance Workstation\u201d,<br \/>\n\u201cAltaro\u201d,<br \/>\n\u201cBack-up\u201d,<br \/>\n\u201cRapid7\u201d,<br \/>\n\u201cBackup\u201d,<br \/>\n\u201cBank\u201d,<br \/>\n\u201cBlockchain\u201d,<br \/>\n\u201cBoot Camp\u201d,<br \/>\n\u201cBox Sync\u201d,<br \/>\n\u201cBridgeHead\u201d,<br \/>\n\u201cCAM Commerce Solutions\u201d,<br \/>\n\u201cCard Processing\u201d,<br \/>\n\u201cCash\u201d,<br \/>\n\u201cCisco\u201d,<br \/>\n\u201cCitrix\u201d,<br \/>\n\u201cCloud\u201d,<br \/>\n\u201cCoin\u201d,<br \/>\n\u201cDashlane\u201d,<br \/>\n\u201cDiskeeper\u201d,<br \/>\n\u201cDouble-Take\u201d,<br \/>\n\u201cDropbox\u201d,<br \/>\n\u201cElcomsoft\u201d,<br \/>\n\u201cFileZilla Server\u201d,<br \/>\n\u201cFortiClient\u201d,<br \/>\n\u201cFund\u201d,<br \/>\n\u201ciDrive\u201d,<br \/>\n\u201cLedger\u201d,<br \/>\n\u201cLexisNexis\u201d,<br \/>\n\u201cLogMeIn\u201d,<br \/>\n\u201cM262x\u201d,<br \/>\n\u201cMicrosoft Dynamics RMS Store Operations\u201d,<br \/>\n\u201cMicrosoft POS\u201d,<br \/>\n\u201cvRanger\u201d,<br \/>\n\u201cMoney\u201d,<br \/>\n\u201cmRemoteNG\u201d,<br \/>\n\u201cMSR\u201d,<br \/>\n\u201cPassword\u201d,<br \/>\n\u201cPayment\u201d,<br \/>\n\u201cPrivate\u201d,<br \/>\n\u201cProtect\u201d,<br \/>\n\u201cPuTTY\u201d,<br \/>\n\u201cQuickBooks\u201d,<br \/>\n\u201cReplication\u201d,<br \/>\n\u201cScreenConnect\u201d,<br \/>\n\u201cShadow\u201d,<br \/>\n\u201cSII RP-D10\u201d,<br \/>\n\u201cStorage\u201d,<br \/>\n\u201cSWIFT\u201d,<br \/>\n\u201cTeamViewer\u201d,<br \/>\n\u201cToken\u201d,<br \/>\n\u201cTrade\u201d,<br \/>\n\u201cTreasury\u201d,<br \/>\n\u201cTrezor\u201d,<br \/>\n\u201cVault\u201d,<br \/>\n\u201cUnitrends\u201d,<br \/>\n\u201cVIP Access\u201d,<br \/>\n\u201cVMware\u201d,<br \/>\n\u201cVnc\u201d,<br \/>\n\u201cVPN\u201d,<br \/>\n\u201cWallet\u201d,<br \/>\n\u201cWithdraw\u201d],<br \/>\n\u201cregistry\u201d: [\u201cSOFTWARE\\\\Ammyy\u201d,<br \/>\n\u201cSOFTWARE\\\\Cppcheck\u201d,<br \/>\n\u201cSOFTWARE\\\\DASH\u201d,<br \/>\n\u201cSOFTWARE\\\\Dash\u201d,<br \/>\n\u201cSOFTWARE\\\\DeterministicNetworks\u201d,<br \/>\n\u201cSOFTWARE\\\\GitForWindows\u201d,<br \/>\n\u201cSOFTWARE\\\\GlavSoft LLC.\u201d,<br \/>\n\u201cSOFTWARE\\\\GnuPG\u201d,<br \/>\n\u201cSOFTWARE\\\\Hex-Rays\u201d,<br \/>\n\u201cSOFTWARE\\\\Hex-Rays SA\u201d,<br \/>\n\u201cSOFTWARE\\\\HexaD\u201d,<br \/>\n\u201cSOFTWARE\\\\ITarian\u201d,<br \/>\n\u201cSOFTWARE\\\\LogMeIn Ignition\u201d,<br \/>\n\u201cSOFTWARE\\\\LogMeIn\u201d,<br \/>\n\u201cSOFTWARE\\\\MetaQuotes Software\u201d,<br \/>\n\u201cSOFTWARE\\\\Microsoft\\\\ResKit\\\\Robocopy\u201d,<br \/>\n\u201cSOFTWARE\\\\Nmap\u201d,<br \/>\n\u201cSOFTWARE\\\\Pulse Secure\u201d,<br \/>\n\u201cSOFTWARE\\\\PyBitmessage\u201d,<br \/>\n\u201cSOFTWARE\\\\PyBitmessage\u201d,<br \/>\n\u201cSOFTWARE\\\\S.W.I.F.T.\u201d,<br \/>\n\u201cSOFTWARE\\\\ShrewSoft\u201d,<br \/>\n\u201cSOFTWARE\\\\SimonTatham\u201d,<br \/>\n\u201cSOFTWARE\\\\SonicWall\u201d,<br \/>\n\u201cSOFTWARE\\\\TortoiseSVN\u201d,<br \/>\n\u201cSOFTWARE\\\\Veeam\u201d,<br \/>\n\u201cSOFTWARE\\\\VisualSVN\u201d,<br \/>\n\u201cSOFTWARE\\\\Whole Tomato\u201d,<br \/>\n\u201cSOFTWARE\\\\WinLicense\u201d],<br \/>\n\u201cportscan\u201d: {\u201cBitcoin\u201d: [8332,8333],<br \/>\n\u201cDNS\u201d: [53],<br \/>\n\u201cElasticsearch\u201d: [9200,9300],<br \/>\n\u201cFTP\u201d: [21],<br \/>\n\u201cHorizon Agent\u201d: [22443,4172,9427,32111],<br \/>\n\u201cHTTP\u201d: [80,5000,9043],<br \/>\n\u201cHTTPS\u201d: [443,8443,1311,5001,8200],<br \/>\n\u201cJAVA-RMI\u201d: [34571,1099,1090,1098,1099,4444,11099,47001,47002,10999],<br \/>\n\u201cMongoDB\u201d: [27017],<br \/>\n\u201cMSSQL\u201d: [1433],<br \/>\n\u201cMySQL\u201d: [3306],<br \/>\n\u201cneo4j\u201d: [7687],<br \/>\n\u201cNetBackup\u201d: [5637],<br \/>\n\u201cNETBIOS\u201d: [139],<br \/>\n\u201cOracle\u201d: [1521],<br \/>\n\u201cPOP3\u201d: [110],<br \/>\n\u201cPOP3s\u201d: [995],<br \/>\n\u201cPostgreSQL\u201d: [5432],<br \/>\n\u201cPPTP\u201d: [1723],<br \/>\n\u201cRADMIN\u201d: [4899],<br \/>\n\u201cRDP\u201d: [3389],<br \/>\n\u201cSMTP\u201d: [25],<br \/>\n\u201cSonicWall-VPN\u201d: [4433],<br \/>\n\u201cSSH\u201d: [22],<br \/>\n\u201cTelnet\u201d: [23],<br \/>\n\u201cTivoli\u201d: [1500,1581],<br \/>\n\u201cTOR\u201d: [9050],<br \/>\n\u201cAcronixBackup\u201d: [9877],<br \/>\n\u201cvCenter\u201d: [22024,902,903,10080,10443],<br \/>\n\u201cVeeam\u201d: [9392,9393,9394,9397,9398,9399],<br \/>\n\u201cVNC\u201d: [5900, 5800],<br \/>\n\u201cWinRM\u201d: [5985,5986],<br \/>\n\u201cZabbix\u201d: [10050,10051],<br \/>\n\u201cJDWP\u201d: [45000,45001],<br \/>\n\u201cJMX\u201d: [8686,9012,50500],<br \/>\n\u201cjBoss\u201d: [11111,4444,4445],<br \/>\n\u201cCisco Smart Install\u201d: [4786],<br \/>\n\u201cHP Data Protector\u201d: [5555,5556],<br \/>\n\u201cGlassFish\u201d: [4848]<br \/>\n}<br \/>\n}<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4><a id=\"post-109455-_hfeex2kbk281\"><\/a><strong>PyXie Lite \u306e\u30ea\u30de\u30c3\u30d7\u3055\u308c\u305f\u30aa\u30da\u30b3\u30fc\u30c9<\/strong><\/h4>\n<table>\n<tbody>\n<tr>\n<td>def_op(\u2018PRINT_ITEM\u2019, 78)<br \/>\ndef_op(\u2018PRINT_NEWLINE\u2019, 63)<br \/>\ndef_op(\u2018POP_TOP\u2019, 85)<br \/>\ndef_op(\u2018RETURN_VALUE\u2019, 88)<br \/>\ndef_op(\u2018ROT_TWO\u2019, 29)<br \/>\ndef_op(\u2018ROT_THREE\u2019, 9)<br \/>\ndef_op(\u2018STORE_MAP\u2019, 55)<br \/>\ndef_op(\u2018INPLACE_ADD\u2019, 28)<br \/>\ndef_op(\u2018ROT_FOUR\u2019, 72)<br \/>\ndef_op(\u2018UNARY_POSITIVE\u2019, 12)<br \/>\ndef_op(\u2018UNARY_NEGATIVE\u2019, 64)<br \/>\ndef_op(\u2018UNARY_NOT\u2019, 66)<br \/>\ndef_op(\u2018UNARY_CONVERT\u2019, 20)<br \/>\ndef_op(\u2018UNARY_INVERT\u2019, 65)<br \/>\ndef_op(\u2018GET_ITER\u2019, 83)<br \/>\ndef_op(\u2018BINARY_MULTIPLY\u2019, 80)<br \/>\ndef_op(\u2018BINARY_POWER\u2019, 79)<br \/>\ndef_op(\u2018BINARY_DIVIDE\u2019, 15)<br \/>\ndef_op(\u2018BINARY_MODULO\u2019, 76)<br \/>\ndef_op(\u2018BINARY_ADD\u2019, 84)<br \/>\ndef_op(\u2018BINARY_SUBTRACT\u2019, 89)<br \/>\ndef_op(\u2018BINARY_SUBSCR\u2019, 57)<br \/>\ndef_op(\u2018BINARY_FLOOR_DIVIDE\u2019, 68)<br \/>\ndef_op(\u2018INPLACE_FLOOR_DIVIDE\u2019, 24)<br \/>\ndef_op(\u2018INPLACE_DIVIDE\u2019, 82)<br \/>\ndef_op(\u2018INPLACE_SUBTRACT\u2019, 22)<br \/>\ndef_op(\u2018INPLACE_MULTIPLY\u2019, 13)<br \/>\ndef_op(\u2018INPLACE_MODULO\u2019, 70)<br \/>\ndef_op(\u2018STORE_SUBSCR\u2019, 54)<br \/>\ndef_op(\u2018DELETE_SUBSCR\u2019, 77)<br \/>\ndef_op(\u2018BINARY_LSHIFT\u2019, 60)<br \/>\ndef_op(\u2018BINARY_RSHIFT\u2019, 21)<br \/>\ndef_op(\u2018BINARY_AND\u2019, 3)<br \/>\ndef_op(\u2018BINARY_XOR\u2019, 73)<br \/>\ndef_op(\u2018BINARY_OR\u2019, 56)<br \/>\ndef_op(\u2018INPLACE_POWER\u2019, 23)<br \/>\ndef_op(\u2018POP_BLOCK\u2019, 2)<br \/>\ndef_op(\u2018DUP_TOP\u2019, 75)<br \/>\ndef_op(\u2018PRINT_ITEM_TO\u2019, 5)<br \/>\ndef_op(\u2018PRINT_NEWLINE_TO\u2019, 11)<br \/>\ndef_op(\u2018INPLACE_LSHIFT\u2019, 59)<br \/>\ndef_op(\u2018INPLACE_RSHIFT\u2019, 74)<br \/>\ndef_op(\u2018INPLACE_AND\u2019, 61)<br \/>\ndef_op(\u2018INPLACE_XOR\u2019, 27)<br \/>\ndef_op(\u2018INPLACE_OR\u2019, 71)<br \/>\ndef_op(\u2018BREAK_LOOP\u2019, 58)<br \/>\ndef_op(\u2018WITH_CLEANUP\u2019, 19)<br \/>\ndef_op(\u2018END_FINALLY\u2019, 4)<br \/>\ndef_op(\u2018BUILD_CLASS\u2019, 87)<br \/>\ndef_op(\u2018EXEC_STMT\u2019, 10)<br \/>\ndef_op(\u2018LOAD_LOCALS\u2019, 67)<br \/>\ndef_op(\u2018IMPORT_STAR\u2019, 26)<br \/>\ndef_op(\u2018YIELD_VALUE\u2019, 25)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Vatet, PyXie and Defray777 are all associated with a financially motivated threat group. We aim to get these malware families on the radar.  <\/p>\n","protected":false},"author":323,"featured_media":134362,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4322,1974,3057,4431],"tags":[6071,5007,6211,6212],"product_categories":[4348,4455,4465],"coauthors":[2550,2551],"class_list":["post-109590","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-actor-groups","category-malware-ja","category-ransomware-ja","category-threat-actor-groups-ja","tag-defray777-ja","tag-prying-libra-ja","tag-pyxie-ja","tag-vatet","product_categories-managed-threat-hunting","product_categories-managed-threat-hunting-ja","product_categories-unit-42-incident-response-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30<\/title>\n<meta name=\"description\" content=\"Vatet\u3001PyXie\u3001Defray777\u306f\u3044\u305a\u308c\u3082\u55b6\u5229\u76ee\u7684\u306e\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3067\u3059\u30025\u90e8\u69cb\u6210\u306e\u672c\u7a3f\u3067\u306f\u3001\u52d5\u304d\u304c\u76ee\u7acb\u305f\u305a\u6355\u6349\u3057\u306b\u304f\u3044\u3053\u308c\u3089\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306a\u8abf\u67fb\u3092\u884c\u3044\u307e\u3057\u305f\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30\" \/>\n<meta property=\"og:description\" content=\"Vatet\u3001PyXie\u3001Defray777\u306f\u3044\u305a\u308c\u3082\u55b6\u5229\u76ee\u7684\u306e\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3067\u3059\u30025\u90e8\u69cb\u6210\u306e\u672c\u7a3f\u3067\u306f\u3001\u52d5\u304d\u304c\u76ee\u7acb\u305f\u305a\u6355\u6349\u3057\u306b\u304f\u3044\u3053\u308c\u3089\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306a\u8abf\u67fb\u3092\u884c\u3044\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-18T05:30:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Ransomware_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ryan Tracey, Drew Schmitt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30","description":"Vatet\u3001PyXie\u3001Defray777\u306f\u3044\u305a\u308c\u3082\u55b6\u5229\u76ee\u7684\u306e\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3067\u3059\u30025\u90e8\u69cb\u6210\u306e\u672c\u7a3f\u3067\u306f\u3001\u52d5\u304d\u304c\u76ee\u7acb\u305f\u305a\u6355\u6349\u3057\u306b\u304f\u3044\u3053\u308c\u3089\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306a\u8abf\u67fb\u3092\u884c\u3044\u307e\u3057\u305f\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/","next":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/2\/","og_locale":"ja_JP","og_type":"article","og_title":"\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30","og_description":"Vatet\u3001PyXie\u3001Defray777\u306f\u3044\u305a\u308c\u3082\u55b6\u5229\u76ee\u7684\u306e\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3067\u3059\u30025\u90e8\u69cb\u6210\u306e\u672c\u7a3f\u3067\u306f\u3001\u52d5\u304d\u304c\u76ee\u7acb\u305f\u305a\u6355\u6349\u3057\u306b\u304f\u3044\u3053\u308c\u3089\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306a\u8abf\u67fb\u3092\u884c\u3044\u307e\u3057\u305f\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/","og_site_name":"Unit 42","article_published_time":"2020-11-18T05:30:53+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Ransomware_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Ryan Tracey, Drew Schmitt","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/"},"author":{"name":"Ayako Kimijima","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/5502567dd627cdd5a306432cd651a90e"},"headline":"\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30","datePublished":"2020-11-18T05:30:53+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/"},"wordCount":5178,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Ransomware_Category_1920x900.jpg","keywords":["Defray777","Prying Libra","PyXie","Vatet"],"articleSection":["Threat Actor Groups","\u30de\u30eb\u30a6\u30a7\u30a2","\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","\u8105\u5a01\u30a2\u30af\u30bf\u30fc \u30b0\u30eb\u30fc\u30d7"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/","name":"\u77e5\u3089\u308c\u3056\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3001Vatet\u3001PyXie\u3001Defray777 \u306e\u8a73\u7d30","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Ransomware_Category_1920x900.jpg","datePublished":"2020-11-18T05:30:53+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/5502567dd627cdd5a306432cd651a90e"},"description":"Vatet\u3001PyXie\u3001Defray777\u306f\u3044\u305a\u308c\u3082\u55b6\u5229\u76ee\u7684\u306e\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u3068\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3067\u3059\u30025\u90e8\u69cb\u6210\u306e\u672c\u7a3f\u3067\u306f\u3001\u52d5\u304d\u304c\u76ee\u7acb\u305f\u305a\u6355\u6349\u3057\u306b\u304f\u3044\u3053\u308c\u3089\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306a\u8abf\u67fb\u3092\u884c\u3044\u307e\u3057\u305f\u3002","inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/vatet-pyxie-defray777\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Ransomware_Category_1920x900.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Ransomware_Category_1920x900.jpg","width":1920,"height":900,"caption":"A digital illustration of a glowing red padlock symbol superimposed over a detailed circuit board background, emphasizing themes of cybersecurity and data protection. The image features vibrant red and blue lights to highlight the technological context."},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/5502567dd627cdd5a306432cd651a90e","name":"Ayako Kimijima","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Ayako Kimijima"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/akimijima\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/109590","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/323"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=109590"}],"version-history":[{"count":9,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/109590\/revisions"}],"predecessor-version":[{"id":109599,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/109590\/revisions\/109599"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134362"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=109590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=109590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=109590"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=109590"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=109590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}