{"id":119951,"date":"2021-07-27T18:40:59","date_gmt":"2021-07-28T01:40:59","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=119951"},"modified":"2021-07-27T19:31:37","modified_gmt":"2021-07-28T02:31:37","slug":"thor-plugx-variant","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/","title":{"rendered":"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u30012021\u5e743\u6708\u306b\u767a\u751f\u3057\u305fMicrosoft Exchange Server\u3078\u306e\u653b\u6483\u3092\u76e3\u8996\u3057\u3066\u3044\u305f\u969b\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u4e0a\u306b\u3042\u308b\u4fb5\u5165\u5f8c\u306e\u30ea\u30e2\u30fc\u30c8\u30a2\u30af\u30bb\u30b9\u30c4\u30fc\u30eb (RAT) \u3068\u3057\u3066\u914d\u4fe1\u3055\u308c\u305f<a href=\"https:\/\/logrhythm.com\/blog\/deep-dive-into-plugx-malware\/\">PlugX <\/a>\u306e\u4e9c\u7a2e\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u89b3\u6e2c\u3055\u308c\u305f\u4e9c\u7a2e\u306f\u30b3\u30a2\u3068\u306a\u308b\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u306b\u5909\u66f4\u304c\u52a0\u3048\u3089\u308c\u3066\u3044\u308b\u70b9\u304c\u7279\u5fb4\u3067\u3001\u30c8\u30ec\u30fc\u30c9\u30de\u30fc\u30af\u306e\u5358\u8a9e\u3067\u3042\u308b\u300cPLUG\u300d\u304c\u300cTHOR\u300d\u306b\u7f6e\u304d\u63db\u3048\u3089\u308c\u3066\u3044\u307e\u3059\u3002\u767a\u898b\u3055\u308c\u305f\u6700\u3082\u53e4\u3044THOR\u30b5\u30f3\u30d7\u30eb\u306f2019\u5e748\u6708\u306e\u3082\u306e\u3067\u3001\u3053\u308c\u304c\u30d6\u30e9\u30f3\u30c9\u5909\u66f4\u3055\u308c\u305f\u30b3\u30fc\u30c9\u30b5\u30f3\u30d7\u30eb\u3068\u3057\u3066\u306f\u6700\u3082\u53e4\u3044\u3082\u306e\u3067\u3059\u3002\u3053\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u914d\u4fe1\u30e1\u30ab\u30cb\u30ba\u30e0\u306e\u5f37\u5316\u3084\u3001\u4fe1\u983c\u3055\u308c\u305f\u30d0\u30a4\u30ca\u30ea\u306e\u60aa\u7528\u306a\u3069\u3001\u65b0\u305f\u306a\u6a5f\u80fd\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>2008\u5e74\u306b\u521d\u3081\u3066\u767a\u898b\u3055\u308c\u305fPlugX\u306f\u3001\u4e2d\u56fd\u306e\u30b5\u30a4\u30d0\u30fc\u30b9\u30d1\u30a4\u653b\u6483\u30b0\u30eb\u30fc\u30d7<a href=\"https:\/\/unit42.paloaltonetworks.jp\/pkplug_chinese_cyber_espionage_group_attacking_asia\/\">PKPLUG<\/a> (\u5225\u540d: Mustang Panda) \u306a\u3069\u306e\u30b0\u30eb\u30fc\u30d7\u304c\u4f7f\u7528\u3057\u3066\u304d\u305f\u7b2c2\u6bb5\u968e\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u3067\u3059\u3002PlugX\u306f\u30012015\u5e74\u306b\u767a\u751f\u3057\u305f<a href=\"https:\/\/www.wired.com\/2016\/10\/inside-cyberattack-shocked-us-government\/\">\u7c73\u56fd\u653f\u5e9c\u4eba\u4e8b\u7ba1\u7406\u5c40 (OPM) <\/a>\u3078\u306e\u91cd\u5927\u4fb5\u5165\u4e8b\u4ef6\u3092\u306f\u3058\u3081\u3068\u3059\u308b\u8907\u6570\u306e\u8457\u540d\u306a\u653b\u6483\u306b\u9577\u5e74\u306b\u308f\u305f\u3063\u3066\u4f7f\u7528\u3055\u308c\u3066\u304d\u305f\u3053\u3068\u306b\u52a0\u3048\u3001\u30e2\u30b8\u30e5\u30fc\u30eb\u6027\u304c\u9ad8\u304f\u3001\u30d7\u30e9\u30b0\u30a4\u30f3\u5f62\u5f0f\u3092\u3068\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u958b\u767a\u624b\u6cd5\u3067\u3082\u77e5\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3055\u3089\u306a\u308b\u8abf\u67fb\u3068\u5206\u6790\u306e\u7d50\u679c\u3001\u3044\u304f\u3064\u304b\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u305d\u308c\u306b\u95a2\u9023\u3059\u308bPlugX\u306e\u30b3\u30de\u30f3\u30c9\uff06\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb (C2) \u30a4\u30f3\u30d5\u30e9\u304c\u8ffd\u52a0\u3067\u7279\u5b9a\u3055\u308c\u307e\u3057\u305f\u3002\u672c\u7a3f\u3067\u306f\u3001\u767a\u898b\u3055\u308c\u305fPlugX\u4e9c\u7a2e\u306e\u6280\u8853\u7684\u6982\u8981\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u3067PlugX\u4e9c\u7a2e\u3092\u8b58\u5225\u3059\u308b\u305f\u3081\u306eIoC (Indicator of compromise \u4fb5\u5bb3\u6307\u6a19) \u3001Unit 42\u304c\u958b\u767a\u3057\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u5fa9\u53f7\u51e6\u7406\u30c4\u30fc\u30eb\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/wildfire\">WildFire<\/a>\u3068<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/subscriptions\/threat-prevention\">\u8105\u5a01\u9632\u5fa1<\/a>\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u3092\u6709\u52b9\u5316\u3057\u305f<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/next-generation-firewall\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/a> \u3068<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/cortex-xdr\"> Cortex XDR<\/a>\u306b\u3088\u3063\u3066PlugX\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/autofocus\">AutoFocus <\/a>\u3092\u304a\u4f7f\u3044\u306e\u304a\u5ba2\u69d8\u306f<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PlugX\">PlugX<\/a>\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PKPLUG\">PKPLUG<\/a>\u306e\u5404\u30bf\u30b0\u3092\u4f7f\u7528\u3057\u3066PlugX\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8ffd\u8de1\u3067\u304d\u307e\u3059\u3002\u89b3\u6e2c\u3055\u308c\u305f\u30c6\u30af\u30cb\u30c3\u30af\u3084\u3001\u305d\u308c\u306b\u5bfe\u5fdc\u3057\u3066\u3068\u308b\u3079\u304d\u884c\u52d5\u65b9\u91dd\u5168\u4f53\u3092\u8996\u899a\u5316\u3057\u305f\u5185\u5bb9\u306f\u3001<a href=\"https:\/\/unit42.paloaltonetworks.com\/atoms\/pkplug\/\">Unit 42\u306eATOM\u30d3\u30e5\u30fc\u30a2<\/a>\u304b\u3089\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002<\/p>\n<h2>PlugX\u306e\u914d\u4fe1<\/h2>\n<p>2021\u5e743\u670819\u65e5\u3001IP\u30a2\u30c9\u30ec\u30b9<span style=\"font-family: 'courier new', courier, monospace;\">101.36.120[.]227<\/span>\u3092\u767a\u4fe1\u5143\u3068\u3057\u3001\u4e00\u9023\u306e\u30bc\u30ed\u30c7\u30a4\u8106\u5f31\u6027 (CVE-2021-26855\u304a\u3088\u3073CVE-2021-27065) \u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u3088\u308a<a href=\"https:\/\/proxylogon.com\/\">Exchange Server<\/a>\u3092\u653b\u6483\u3057\u3066\u3044\u308b\u653b\u6483\u8005\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u6210\u529f\u3059\u308b\u3068\u3001\u30d1\u30d6\u30ea\u30c3\u30af\u306b\u30a2\u30af\u30bb\u30b9\u304c\u53ef\u80fd\u306aWeb\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306bWeb\u30b7\u30a7\u30eb\u304c\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u3001\u6700\u9ad8\u30ec\u30d9\u30eb\u306e\u7279\u6a29\u3067\u30b3\u30fc\u30c9\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u305d\u306e\u5f8c\u306f<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2018\/09\/27\/out-of-sight-but-not-invisible-defeating-fileless-malware-with-behavior-monitoring-amsi-and-next-gen-av\/\">\u300cliving off the land (\u653b\u6483\u5148\u306e\u74b0\u5883\u306b\u3082\u3068\u304b\u3089\u5b58\u5728\u3059\u308b\u30c4\u30fc\u30eb\u3092\u4f7f\u3046)\u300d<\/a>\u3068\u547c\u3070\u308c\u308b\u624b\u6cd5\u3092\u4f7f\u3044\u307e\u3059\u3002\u3053\u306e\u624b\u6cd5\u306f\u3001\u4fe1\u983c\u3055\u308c\u3066\u3044\u308b\u30d0\u30a4\u30ca\u30ea\u3092\u4f7f\u3063\u3066\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9\u306b\u3088\u308b\u691c\u51fa\u3092\u56de\u907f\u3057\u307e\u3059\u3002\u3053\u306e\u4e8b\u4f8b\u3067\u306f\u3001\u30a2\u30af\u30bf\u30fc\u304c\u7ba1\u7406\u4e0b\u306b\u304a\u304f GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u304b\u3089 Aro.dat (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">59BA902871E98934C054649CA582E2A01707998ACC78B2570FEF43DBD10F7B6F<\/span>) \u3068\u3044\u3046\u7121\u5bb3\u306a\u30d5\u30a1\u30a4\u30eb\u3092 Microsoft Windows \u306e\u30d0\u30a4\u30ca\u30ea bitsadmin.exe \u3092\u4f7f\u3063\u3066\u6a19\u7684\u74b0\u5883\u306b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u3044\u307e\u3057\u305f (\u5b9f\u884c\u3055\u308c\u305f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30b3\u30de\u30f3\u30c9\u306b\u3064\u3044\u3066\u306f\u56f31\u3092\u53c2\u7167) \u3002<\/p>\n<figure id=\"attachment_119894\" aria-describedby=\"caption-attachment-119894\" style=\"width: 554px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119895 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-38.png\" alt=\"Microsoft Windows\u306e\u30d0\u30a4\u30ca\u30ea\u3067\u3042\u308bbitsadmin.exe\u304c\u5b9f\u884c\u3059\u308b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30b3\u30de\u30f3\u30c9\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\" width=\"554\" height=\"81\" \/><figcaption id=\"caption-attachment-119894\" class=\"wp-caption-text\">\u56f31 Bitsadmin \u306e\u30b3\u30de\u30f3\u30c9\u4f8b<\/figcaption><\/figure>\n<h2>Aro.Dat \u306e\u6982\u8981<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u306e\u6700\u521d\u306e1,000\u30d0\u30a4\u30c8 (\u56f32\u53c2\u7167) \u3092\u773a\u3081\u308b\u3068\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u6697\u53f7\u5316\u306a\u3044\u3057\u5727\u7e2e\u5316\u3055\u308c\u3066\u3044\u305d\u3046\u306a\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u7d50\u8ad6\u304b\u3089\u3044\u3046\u3068\u3053\u306e\u30c7\u30fc\u30bf\u306f\u30e9\u30f3\u30c0\u30e0\u306a\u30d1\u30c7\u30a3\u30f3\u30b0\u7528\u306e\u30c7\u30fc\u30bf\u3067\u3001\u304a\u305d\u3089\u304f\u306f\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9\u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u56de\u907f\u3057\u3066\u691c\u51fa\u3092\u59a8\u5bb3\u3059\u308b\u305f\u3081\u306b\u30d5\u30a1\u30a4\u30eb\u30d8\u30c3\u30c0\u3068\u3057\u3066\u8ffd\u52a0\u3055\u308c\u305f\u3082\u306e\u3067\u3057\u305f\u3002\u30d1\u30c7\u30a3\u30f3\u30b0\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306e\u7d42\u308f\u308a\u306f\u30cc\u30eb\u3067\u7d42\u7aef\u3055\u308c\u3066\u3044\u3066\u3001\u3053\u3053\u304c\u5b9f\u969b\u306e\u30c7\u30fc\u30bf\u30a8\u30f3\u30c8\u30ea\u30dd\u30a4\u30f3\u30c8\u8b58\u5225\u5b50\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002NULL\u30d0\u30a4\u30c8 <span style=\"font-family: 'courier new', courier, monospace;\">(0x00)<\/span> \u306e\u3059\u3050\u5f8c\u308d\u306b\u306f\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30f3\u30d1\u30c3\u30af\u7528x86\u30a2\u30bb\u30f3\u30d6\u30ea\u547d\u4ee4\u304c\u7d9a\u304d\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306fx86\u30a2\u30bb\u30f3\u30d6\u30ea\u306f\u30aa\u30da\u30b3\u30fc\u30c9 <span style=\"font-family: 'courier new', courier, monospace;\">0x77<\/span>\u3092\u3082\u3064\u30d5\u30a1\u30a4\u30eb\u30aa\u30d5\u30bb\u30c3\u30c8<span style=\"font-family: 'courier new', courier, monospace;\">0x4EC<\/span>\u304b\u3089\u306f\u3058\u307e\u308a\u307e\u3059\u3002\u3053\u308c\u306f\u30a2\u30bb\u30f3\u30d6\u30ea\u306e\u30cb\u30fc\u30e2\u30cb\u30c3\u30af\u3067\u300cJA\u300d(\u7b26\u53f7\u306a\u3057\u6574\u6570\u306e\u5927\u5c0f\u6bd4\u8f03\u3067\u5024\u304c\u5927\u304d\u3044\u5834\u5408\u306f\u30b8\u30e3\u30f3\u30d7\u3059\u308b) \u306b\u5909\u63db\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u56f32\u306f<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u30d5\u30a1\u30a4\u30eb\u30d8\u30c3\u30c0\u306e\u3046\u3061NULL\u30d0\u30a4\u30c8\u307e\u3067\u3092\u793a\u3057\u305f\u3082\u306e\u3067\u3059\u3002NULL\u307e\u3067\u306e\u30d0\u30a4\u30c8\u306b\u306f\u3068\u304f\u306b\u610f\u5473\u304c\u306a\u3044\u306e\u3067\u3053\u3053\u3067\u306f\u9014\u4e2d\u3092\u7701\u7565\u3057\u3066\u3044\u307e\u3059\u3002<span style=\"color: #ff0000;\"><strong>\u8d64<\/strong><\/span>\u304cNULL\u30d0\u30a4\u30c8\u3001 <span style=\"color: #00ff00;\"><strong>\u7dd1<\/strong><\/span>\u304c\u30b3\u30fc\u30c9\u5b9f\u884c\u306e\u958b\u59cb\u4f4d\u7f6e\u3067\u3059\u3002<\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0000h: 49 79 7A 45 48 4C 4B 78 75 77 55 48 66 77 46 65 IyzEHLKxuwUHfwFe<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0010h: 6C 46 44 6D 6D 55 6E 42 50 47 76 63 70 75 68 50 lFDmmUnBPGvcpuhP<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0020h: 78 57 5A 67 45 48 62 66 4A 45 57 53 76 74 44 6E xWZgEHbfJEWSvtDn<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0030h: 75 61 75 72 56 4C 63 77 41 79 44 58 6A 72 6E 69 uaurVLcwAyDXjrni<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0040h: 6F 74 70 77 67 73 71 52 67 7A 4D 64 50 6D 46 6A otpwgsqRgzMdPmFj<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0050h: 5A 4E 64 6F 70 72 50 77 70 68 6C 42 6E 6E 56 43 ZNdoprPwphlBnnVC<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0060h: 79 6B 52 45 59 6B 75 50 61 75 63 56 54 55 73 51 ykREYkuPaucVTUsQ<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0070h: 68 73 41 4A 4E 7A 4F 49 61 51 75 4D 46 6C 54 42 hsAJNzOIaQuMFlTB<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0080h: 77 42 44 6B 4A 55 76 43 6C 51 47 68 46 66 69 56 wBDkJUvClQGhFfiV<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">0090h: 66 62 6A 4C 46 77 78 41 68 50 67 44 46 6F 47 44 fbjLFwxAhPgDFoGD<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\"><strong>.<\/strong><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\"><strong>.<\/strong><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\"><strong>.<\/strong><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\"><strong>.<\/strong><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\"><strong>.<\/strong><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">04B0h: 37 35 38 37 35 35 30 39 37 38 32 36 39 30 33 36 7587550978269036<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">04C0h: 39 39 33 32 33 32 36 38 39 36 33 30 35 35 39 30 9932326896305590<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">04D0h: 37 35 35 35 37 39 35 32 39 38 30 32 33 35 38 33 7555795298023583<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">04E0h: 30 36 32 37 36 36 30 32 35 37 36 <strong><span style=\"color: #ff0000;\">00<\/span> <span style=\"color: #00ff00;\">77 06 81 EE<\/span><\/strong> 06276602576.w.<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u56f32 Aro.dat\u306e\u30d5\u30a1\u30a4\u30eb\u30d8\u30c3\u30c0<\/em><\/sup><\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u306f\u691c\u51fa\u3088\u3051\u3092\u610f\u56f3\u3057\u305f\u8a2d\u8a08\u306b\u306a\u3063\u3066\u3044\u308b\u306e\u3067\u7279\u5b9a\u306e\u30ed\u30fc\u30c0\u304c\u4ecb\u5165\u3057\u306a\u3044\u3068\u5b9f\u884c\u3067\u304d\u307e\u305b\u3093\u3002\u3053\u308c\u307e\u3067\u306e PlugX \u306e\u4e9c\u7a2e\u3068\u540c\u69d8\u306b\u3053\u306e\u30b3\u30fc\u30c9\u5b9f\u884c\u306b\u306f<a href=\"https:\/\/attack.mitre.org\/techniques\/T1574\/002\/\">DLL \u30b5\u30a4\u30c9\u30ed\u30fc\u30c7\u30a3\u30f3\u30b0<\/a>\u3068\u547c\u3070\u308c\u308b\u30c6\u30af\u30cb\u30c3\u30af\u304c\u4f7f\u308f\u308c\u307e\u3059\u3002\u9759\u7684\u89e3\u6790\u3092\u884c\u3063\u3066\u307f\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span> \u306f\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3055\u308c\u308b\u3068\u81ea\u8eab\u306e\u30a2\u30f3\u30d1\u30c3\u30af\u3092\u958b\u59cb\u3057\u3001C2 \u30b5\u30fc\u30d0\u30fc\u3068\u901a\u4fe1\u3057\u59cb\u3081\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span> \u306f\u5b9f\u969b\u306e\u3068\u3053\u308d\u6697\u53f7\u5316\u30fb\u5727\u7e2e\u5316\u3055\u308c\u305f PlugX \u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span> \u5185\u306e\u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3\u306f\u8907\u6570\u306e\u5fa9\u53f7\u9375\u3068\u30d3\u30c3\u30c8\u30b7\u30d5\u30c8\u6f14\u7b97\u3092\u4f34\u3046\u70b9\u3067\u65e7\u6765\u306e PlugX \u4e9c\u7a2e\u3068\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059 (\u4ee5\u4e0b\u56f33\u53c2\u7167) \u3002\u5fa9\u53f7\u5f8c\u306f Windows API \u306e <span style=\"font-family: 'courier new', courier, monospace;\">RtlDecompressBuffer<\/span> \u3092\u4ecb\u3057\u3066 Windows\u30e2\u30b8\u30e5\u30fc\u30eb (DLL) \u306b\u89e3\u51cd\u3055\u308c\u307e\u3059\u3002\u5727\u7e2e\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u306f LZ \u5727\u7e2e<span style=\"font-family: 'courier new', courier, monospace;\"> (COMPRESSION_FORMAT_LZNT1) <\/span>\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_119959\" aria-describedby=\"caption-attachment-119959\" style=\"width: 665px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-39-jp.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-119959 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-39-jp.png\" alt=\"\u56f33\u3067\u30cf\u30a4\u30e9\u30a4\u30c8\u3057\u3066\u3044\u308b\u9805\u76ee\u306f Aro.dat \u3068 2012 \u5e74\u306e\u53e4\u3044 PlugX \u30b5\u30f3\u30d7\u30eb\u304c\u4f7f\u7528\u3057\u3066\u3044\u305f\u9759\u7684\u5fa9\u53f7\u9375\u3067\u3059 (SHA-256: A68CA9D35D26505A83C92202B0220F7BB8F615BC1E8D4E2266AADDB0DFE7BD15) \u3002\u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3\u306f\u3001PlugX \u306e\u30d3\u30eb\u30c9\u3054\u3068\u306b\u3001\u7570\u306a\u308b\u9759\u7684\u9375\u3092\u4f7f\u7528\u3057\u305f\u308a\u3001\u52a0\u7b97\u3084\u6e1b\u7b97\u306e\u65b9\u6cd5\u3092\u5909\u3048\u305f\u308a\u3059\u308b\u3053\u3068\u3067\u3001\u82e5\u5e72\u306e\u9055\u3044\u304c\u3042\u308a\u307e\u3059\u3002\" width=\"665\" height=\"247\" \/><\/a><figcaption id=\"caption-attachment-119959\" class=\"wp-caption-text\">\u56f33 PlugX\u306e\u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3\u306e\u6bd4\u8f03 (\u5de6: Aro.Dat \u306e\u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3 \u53f3: \u53e4\u3044 2012\u5e74\u306e PlugX \u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3)<\/figcaption><\/figure>\n<p>\u56f33\u3067\u30cf\u30a4\u30e9\u30a4\u30c8\u3057\u305f\u9805\u76ee\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u3068 2012 \u5e74\u306e\u53e4\u3044 PlugX \u30b5\u30f3\u30d7\u30eb\u304c\u4f7f\u7528\u3057\u3066\u3044\u305f\u9759\u7684\u306a\u5fa9\u53f7\u9375\u3067\u3059 (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">A68CA9D35D26505A83C92202B0220F7BB8F615BC1E8D4E2266AADDB0DFE7BD15<\/span>) \u3002\u5fa9\u53f7\u30eb\u30fc\u30c1\u30f3\u306f\u3001PlugX \u306e\u30d3\u30eb\u30c9\u3054\u3068\u306b\u3001\u7570\u306a\u308b\u9759\u7684\u9375\u3092\u4f7f\u7528\u3057\u305f\u308a\u3001\u52a0\u7b97\u3084\u6e1b\u7b97\u306e\u65b9\u6cd5\u3092\u5909\u3048\u305f\u308a\u3059\u308b\u3053\u3068\u3067\u3001\u82e5\u5e72\u306e\u9055\u3044\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u5fa9\u53f7\u3055\u308c\u3001\u89e3\u51cd\u3055\u308c\u305f<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u306f\u3001x86 Windows \u7528 DLL \u306a\u3044\u3057 PE \u30d5\u30a1\u30a4\u30eb\u3067\u3059\u3002<\/p>\n<h2>Aro.Dat\u306e\u30b3\u30fc\u30c9\u5b9f\u884c<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u30d5\u30a1\u30a4\u30eb\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">aross.dll\u3001aro.exe<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">aro.dat<\/span>\u3068\u3044\u3046\u6587\u5b57\u5217\u540d\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e3\u3064\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u95a2\u9023\u3092\u898b\u3066\u3044\u304f\u3068\u30b3\u30fc\u30c9\u5b9f\u884c\u304c\u3069\u306e\u3088\u3046\u306b\u884c\u308f\u308c\u308b\u304b\u304c\u308f\u304b\u308a\u307e\u3059\u3002VirusTotal\u3067\u306f\u4ee5\u4e0b\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">Aro.exe<\/span> (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">18A98C2D905A1DA1D9D855E86866921E543F4BF8621FAEA05EB14D8E5B23B60C<\/span>)<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">Aross.dll<\/span> (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">9FFFB3894B008D5A54343CCF8395A47ACFE953394FFFE2C58550E444FF20EC47<\/span>)<\/li>\n<\/ul>\n<p>\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u306e\u8abf\u67fb\u306b\u3088\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Aro.exe<\/span>\u306f\u3001\u300c\u9ad8\u5ea6\u306a\u4fee\u5fa9\u30fb\u6700\u9069\u5316\u30c4\u30fc\u30eb<a href=\"https:\/\/www.techspot.com\/downloads\/5277-aro.html\">ARO 2012<\/a>\u300d\u306e\u4e00\u90e8\u3067\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u3001Windows\u306e\u30ec\u30b8\u30b9\u30c8\u30ea\u30a8\u30e9\u30fc\u3092\u4fee\u6b63\u3059\u308b\u3053\u3068\u3092\u3046\u305f\u3046\u30d5\u30ea\u30fc\u30c4\u30fc\u30eb\u3067\u3001\u30c7\u30b8\u30bf\u30eb\u7f72\u540d\u3055\u308c\u3066\u3044\u307e\u3059\u3002PlugX\u30ed\u30fc\u30c0\u3068\u306e\u95a2\u9023\u304c\u77e5\u3089\u308c\u3066\u304a\u308a\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Aross.dll<\/span>\u3092\u52d5\u7684\u306b\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">Aross.dll<\/span>\u306f\u3001\u6697\u53f7\u5316\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u30d5\u30a1\u30a4\u30eb<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u306e\u8aad\u307f\u8fbc\u307f\u3092\u306b\u306a\u3046\u30a2\u30af\u30bf\u30fc\u306eDLL\u30d5\u30a1\u30a4\u30eb\u3067\u3059\u3002\u3053\u3046\u3057\u305f\u60c5\u5831\u304b\u3089\u3001\u3053\u308c\u30892\u3064\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u3001\u6697\u53f7\u5316\u3055\u308c\u305fTHOR\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3042\u308b<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u3092\u30ed\u30fc\u30c9\u3059\u308b\u306e\u306b\u5fc5\u8981\u306a\u3082\u306e\u3067\u3001\u304b\u3064\u305d\u306e\u30ed\u30fc\u30c9\u3092\u62c5\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u63a8\u6e2c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u30b3\u30fc\u30c9\u306e\u5b9f\u884c\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306f\u3001\u56f34\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<figure id=\"attachment_119961\" aria-describedby=\"caption-attachment-119961\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-40-jp.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-119961 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-40-jp.png\" alt=\"DLL\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9\u306b\u95a2\u3059\u308b\u4e00\u9023\u306e\u6d41\u308c\u3092\u6700\u521d\u304b\u3089\u6700\u5f8c\u307e\u3067\u306e\u64ec\u4f3c\u30b3\u30fc\u30c9\u3092\u4ea4\u3048\u3066\u8aac\u660e\u3057\u305f\u3082\u306e\u6ce8\u76ee\u3059\u3079\u304d\u306fPlugX\u4e9c\u7a2e\u3067\u3042\u308bTHOR\u304c\u65b0\u305f\u306b\u5272\u308a\u5f53\u3066\u3089\u308c\u305f\u30d0\u30c3\u30d5\u30a1\u306b\u5bfe\u3057\u3066Windows API\u306eIstrlenA\u3092\u547c\u3073\u51fa\u3057\u3066\u3044\u308b\u70b9IstrlenA API\u306f\u3001NULL\u30d0\u30a4\u30c8\u307e\u3067\u306e\u8aad\u307f\u8fbc\u307f\u3092\u884c\u3044\u3001\u30d5\u30a1\u30a4\u30eb\u30d8\u30c3\u30c0\u306e\u30b8\u30e3\u30f3\u30af\u30b3\u30fc\u30c9\u90e8\u5206\u3092\u8aad\u307f\u98db\u3070\u3059\u306e\u306b\u4f7f\u308f\u308c\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"696\" \/><\/a><figcaption id=\"caption-attachment-119961\" class=\"wp-caption-text\">\u56f34 Aro.dat\u306eDLL\u30b5\u30a4\u30c9\u30ed\u30fc\u30c7\u30a3\u30f3\u30b0\u306e\u6982\u8981<\/figcaption><\/figure>\n<h2>Aro.Dat\u306e\u30e9\u30f3\u30bf\u30a4\u30e0\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3<\/h2>\n<p>\u89e3\u8aad\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u3072\u3068\u305f\u3073\u30e1\u30e2\u30ea\u4e0a\u3067\u5b9f\u884c\u3055\u308c\u308b\u3068\u4ee5\u524d\u306ePlugX \u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u306e\u4e9c\u7a2e\u3068\u540c\u3058\u3088\u3046\u306a\u632f\u308b\u821e\u3044\u3092\u3057\u307e\u3059\u3002\u307e\u305a\u3001\u57cb\u3081\u8fbc\u307e\u308c\u305fPlugX\u306e\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u69cb\u6210\u8a2d\u5b9a\u3092\u5fa9\u53f7\u3059\u308b\u3053\u3068\u304b\u3089\u59cb\u3081\u307e\u3059\u3002\u5fa9\u53f7\u306e\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3068XOR\u30ad\u30fc\u306f\u3001\u8907\u6570\u306ePlugX\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u3067\u307b\u307c\u4e00\u8cab\u3057\u3066\u3044\u307e\u3059\u3002\u30b3\u30fc\u30c9\u306e\u632f\u308b\u821e\u3044\u306f\u3001\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0<a href=\"https:\/\/www.recordedfuture.com\/reddelta-targets-catholic-organizations\/\">Insikt Group<\/a>\u304c\u5831\u544a\u3057\u305fRedDelta PlugX\u306e\u3082\u306e\u3068\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u304c\u3001\u4ed6\u306e\u3059\u3079\u3066\u306e\u65e2\u77e5\u306ePlugX\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3068\u6bd4\u3079\u3066\u660e\u3089\u304b\u306b\u9055\u3046\u306e\u306f\u3001PlugX \u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u521d\u671f\u5316\u6642\u306b\u5b9f\u884c\u3055\u308c\u308b\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u306e\u30c1\u30a7\u30c3\u30af\u90e8\u5206\u3067\u3059\u3002\u6b74\u53f2\u7684\u306b\u306f\u3001\u3053\u306e\u6570\u5b57\u306f\u5e38\u306b<span style=\"font-family: 'courier new', courier, monospace;\">0x504C5547<\/span>\u3067\u3001\u3053\u308c\u306fASCII\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3067<strong>\u300cPLUG\u300d<\/strong>\u3068\u3044\u3046\u5024\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3053\u306e\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u304c<span style=\"font-family: 'courier new', courier, monospace;\">0x54484F52<\/span>\u3067\u3001\u3053\u308c\u306fASCII\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u306e<strong>\u300cTHOR\u300d<\/strong>\u3068\u3044\u3046\u5024\u306b\u3042\u305f\u308a\u307e\u3059\u3002<\/p>\n<p>\u305d\u306e\u9055\u3044\u3092\u56f35\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_119957\" aria-describedby=\"caption-attachment-119957\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-41-jp.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-119957 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-41-jp.png\" alt=\"\u5fa9\u53f7\u3055\u308c\u305fAro.Dat\u3068\u65e7\u578b\u306ePlugX\u306e\u9055\u3044\u3092\u793a\u3059\u30c1\u30e3\u30fc\u30c8\u3002\" width=\"900\" height=\"346\" \/><\/a><figcaption id=\"caption-attachment-119957\" class=\"wp-caption-text\">\u56f35 DLL PlugX\u306e\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u6bd4\u8f03 (\u5de6: \u5fa9\u53f7\u3055\u308c\u305f Aro.Dat \u53f3: \u53e4\u3044 PlugX \u4e9c\u7a2e)<\/figcaption><\/figure>\n<p>\u30b5\u30f3\u30d7\u30eb\u5185\u3067\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u308bPlugX\u306e\u8a2d\u5b9a\u306f\u4ee5\u4e0b\u306e\u5024\u306b\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u307e\u3057\u305f (\u4e00\u90e8\u7701\u7565) \u3002<\/p>\n<figure id=\"attachment_119918\" aria-describedby=\"caption-attachment-119918\" style=\"width: 515px\" class=\"wp-caption aligncenter\"><img  class=\"size-full wp-image-119919 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/image1.png\" alt=\"\u30b5\u30f3\u30d7\u30eb\u5185\u3067\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u308bPlugX\u306e\u8a2d\u5b9a\u306f\u3053\u306e\u56f3\u3067\u793a\u3057\u305f\u5024\u306b\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u308b \" width=\"515\" height=\"951\" \/><figcaption id=\"caption-attachment-119918\" class=\"wp-caption-text\">\u56f36 \u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u8a2d\u5b9a\u306e\u5fa9\u53f7\u7d50\u679c<\/figcaption><\/figure>\n<p>\u56f36\u306b\u793a\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u3001\u3053\u306e\u7279\u5b9a\u306ePlugX\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"color: #ff0000;\"><strong>rainydaysweb[.]com <\/strong><\/span>\u306e4\u3064\u306eC2\u30c9\u30e1\u30a4\u30f3\u3002<\/li>\n<li><span style=\"color: #ff9900;\">80<\/span>\u3001<span style=\"color: #ff9900;\">443<\/span>\u3001<span style=\"color: #ff9900;\">53<\/span>\u3001<span style=\"color: #ff9900;\">8000<\/span>\u30dd\u30fc\u30c8\u3068\u306e\u901a\u4fe1\u3002<strong>TCP <\/strong>\u3068<strong>UDP <\/strong>\u306e\u4e21\u30d7\u30ed\u30c8\u30b3\u30eb\u3067\u30c7\u30fc\u30bf\u304c\u9001\u4fe1\u3055\u308c\u308b\u3002\u30c7\u30d0\u30c3\u30b0<span style=\"font-family: 'courier new', courier, monospace;\"> (outputdebugstringW<\/span>) \u7528\u306b\u9001\u4fe1\u3057\u305f\u30c7\u30fc\u30bf\u3092\u30c7\u30d0\u30c3\u30ac (\u30a2\u30bf\u30c3\u30c1\u3055\u308c\u3066\u3044\u308c\u3070) \u306b\u51fa\u529b\u3002\u4f8b:\n<p><figure id=\"attachment_119920\" aria-describedby=\"caption-attachment-119920\" style=\"width: 503px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119921 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/image5.png\" alt=\"TCP\u3068UDP\u306e\u4e21\u30d7\u30ed\u30c8\u30b3\u30eb\u3067\u9001\u4fe1\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306e\u30b5\u30f3\u30d7\u30eb\u3002\u30db\u30b9\u30c8\u3068\u30d7\u30ed\u30ad\u30b7\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u3002\" width=\"503\" height=\"121\" \/><figcaption id=\"caption-attachment-119920\" class=\"wp-caption-text\">\u56f37 \u30c7\u30d0\u30c3\u30b0\u306e\u51fa\u529b\u4f8b<\/figcaption><\/figure><\/li>\n<\/ul>\n<ul>\n<li><span style=\"color: #3366ff;\">HTTP<\/span>\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3002C2\u3068\u306e\u6700\u521d\u306e\u30cf\u30f3\u30c9\u30b7\u30a7\u30a4\u30af\u306fHTTP\u3067<em>\u306f\u306a\u304f<\/em>\u3001\u53ef\u5909\u9577\u306e\u30e9\u30f3\u30c0\u30e0\u306a\u30d0\u30a4\u30c8\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u308b\u3002\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u306f\u300116\u30d0\u30a4\u30c8\u306e\u30c7\u30fc\u30bf\u304c\u8fd4\u3063\u3066\u304f\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u3066\u304a\u308a\u3001\u8fd4\u308a\u5024 (\u30b3\u30de\u30f3\u30c9) \u306b\u5fdc\u3058\u3066HTTP\u901a\u4fe1\u3092\u958b\u59cb\u3059\u308b\u3002PlugX\u306e<span style=\"font-family: 'courier new', courier, monospace;\">SxWorkProc<\/span>\u30b9\u30ec\u30c3\u30c9\u306fHTTP\u901a\u4fe1\u306e\u51e6\u7406\u3092\u62c5\u5f53\u3059\u308b\u3002HTTP\u30d8\u30c3\u30c0\u306e\u4f8b\u306f\u6b21\u306e\u3088\u3046\u306a\u3082\u306e\u3002\n<p><figure id=\"attachment_119922\" aria-describedby=\"caption-attachment-119922\" style=\"width: 507px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119923 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/image4.png\" alt=\"PlugX SxworkProc\u30b9\u30ec\u30c3\u30c9\u304b\u3089\u306eHTTP\u30d8\u30c3\u30c0\u306e\u4f8b\u3002 \" width=\"507\" height=\"211\" \/><figcaption id=\"caption-attachment-119922\" class=\"wp-caption-text\">\u56f38 HTTP POST\u306e\u4f8b<\/figcaption><\/figure><\/li>\n<\/ul>\n<ul>\n<li>\u56f38\u306e\u5185\u8a33\u306f\u6b21\u306e\u901a\u308a\u3002\n<ul>\n<li>POST\u30c7\u30fc\u30bf\u306f\u30e9\u30f3\u30c0\u30e0\u306a\u30d0\u30a4\u30c8\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u308b\u3002<\/li>\n<li>User-agent\u306f\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5024 <em><span style=\"font-family: 'courier new', courier, monospace;\">Mozilla\/4.0 (compatible; MSIE 9.0; Windows NT 10.0; .NET4.0C; .NET4.0E; Tablet PC 2.0) <\/span><\/em><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">utmcn\u3001utmcs\u3001utmsr\u3001<\/span> <span style=\"font-family: 'courier new', courier, monospace;\">utmsc<\/span>\u306f\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306e\u5024\u3002<\/li>\n<li><span style=\"color: #ff0000;\"><strong>61456 <\/strong><\/span>\u306f\u3001\u65e2\u77e5\u306ePlugX\u306e\u5b9a\u6570\u5024\u3002<\/li>\n<li>HTTP\u30d8\u30c3\u30c0\u306fRecorded Future\u306b\u3088\u308b<a href=\"https:\/\/www.recordedfuture.com\/reddelta-targets-catholic-organizations\/\">RedDelta PlugX \u4e9c\u7a2e<\/a>\u30ec\u30dd\u30fc\u30c8\u306e11\u30da\u30fc\u30b8\u306e\u3082\u306e\u3068\u985e\u4f3c\u3002<\/li>\n<\/ul>\n<\/li>\n<li><span style=\"color: #00ff00;\">HP Digital Image<\/span>\u3068\u3044\u3046\u540d\u524d\u3068\u8aac\u660e\u3067Windows\u30b7\u30b9\u30c6\u30e0\u30b5\u30fc\u30d3\u30b9\u3092\u4f5c\u6210\u3059\u308b\u3002<\/li>\n<\/ul>\n<figure id=\"attachment_119908\" aria-describedby=\"caption-attachment-119908\" style=\"width: 893px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119909 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-45.png\" alt=\"PlugX \u306f\u3001\u3053\u3053\u306b\u793a\u3057\u305f\u3088\u3046\u306b\u300cHP Digital Image\u300d\u3068\u3044\u3046\u540d\u524d\u3068\u8aac\u660e\u3067Windows \u30b7\u30b9\u30c6\u30e0\u30b5\u30fc\u30d3\u30b9\u3092\u4f5c\u6210\u3059\u308b \" width=\"893\" height=\"709\" \/><figcaption id=\"caption-attachment-119908\" class=\"wp-caption-text\">\u56f39 HP Digital Image\u3068\u3057\u3066\u52d5\u4f5c\u3059\u308bPlugX\u306e\u30b5\u30f3\u30d7\u30eb<\/figcaption><\/figure>\n<ul>\n<li>\u30ad\u30e3\u30f3\u30da\u30fc\u30f3ID\u306f<span style=\"color: #800080;\">1234<\/span>\u3067\u3042\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002<\/li>\n<\/ul>\n<p>\u5b9f\u884c\u4e2d\u306f\u3001\u30d7\u30ed\u30bb\u30b9\u306e\u4f5c\u6210\u3001\u65e5\u6642\u3001\u30e6\u30fc\u30b6\u30fc\u540d\u306a\u3069\u306e\u30b7\u30b9\u30c6\u30e0\u30a4\u30d9\u30f3\u30c8\u304c<span style=\"font-family: 'courier new', courier, monospace;\">C:\\ProgramData\\MSDN\\6.0<\/span>\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3042\u308bNTUSER.DAT\u3068\u3044\u3046\u96a0\u3057\u30d5\u30a1\u30a4\u30eb\u306b\u8a18\u9332\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306f<span style=\"font-family: 'courier new', courier, monospace;\">0x4F6F<\/span>\u3068\u3044\u30462\u30d0\u30a4\u30c8\u306e\u9375\u3067\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>PlugX\u306b\u306f\u4ed6\u306b\u30822\u3064\u306e\u8b58\u5225\u53ef\u80fd\u306a\u5c5e\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>1. \u96a0\u308c\u305fWindows\u306e\u30af\u30e9\u30b9\u540d <span style=\"font-family: 'courier new', courier, monospace;\">Static<\/span> (\u56f310\u53c2\u7167)\u3002\u3053\u306e\u30a6\u30a3\u30f3\u30c9\u30a6\u306f\u30d7\u30ed\u30bb\u30b9\u5185\u306e\u901a\u4fe1\u306b\u4f7f\u7528\u3055\u308c\u308b\u3002<\/p>\n<figure id=\"attachment_119910\" aria-describedby=\"caption-attachment-119910\" style=\"width: 755px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119911 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-46.png\" alt=\"PlugX\u306f\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306bWindows\u306e\u96a0\u3057\u30af\u30e9\u30b9\u540d\u3068\u3057\u3066 Static \u3068\u3044\u3046\u540d\u524d\u3092\u4f7f\u7528\u3059\u308b\u3002 \" width=\"755\" height=\"220\" \/><figcaption id=\"caption-attachment-119910\" class=\"wp-caption-text\">\u56f310 PlugX \u306e Windows \u30af\u30e9\u30b9\u540d<\/figcaption><\/figure>\n<p>2. RWX \u30a4\u30f3\u30e1\u30e2\u30ea\u30e2\u30b8\u30e5\u30fc\u30eb\u306e MZ \u304a\u3088\u3073 PE \u30d8\u30c3\u30c0\u3092\u524a\u9664\u3057\u3066 ASCII \u306e ROHT (THOR \u3092\u9006\u306b\u3057\u305f\u3082\u306e) \u306b\u7f6e\u304d\u63db\u3048\u308b (\u56f311\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_119912\" aria-describedby=\"caption-attachment-119912\" style=\"width: 878px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119913 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-47.png\" alt=\"MZ\u3068PE\u30d8\u30c3\u30c0\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\" width=\"878\" height=\"94\" \/><figcaption id=\"caption-attachment-119912\" class=\"wp-caption-text\">\u56f311 \u30a4\u30f3\u30e1\u30e2\u30ea\u30e2\u30b8\u30e5\u30fc\u30eb\u306e\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8<\/figcaption><\/figure>\n<p>\u4ee5\u4e0b\u306e\u88681\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u500b\u3005\u306b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u3092\u6301\u3064\u6b21\u306ePlugX\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u6301\u3061\u307e\u3059\u3002<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/TA17-117A\">\u3053\u308c\u3089\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u306b\u3064\u3044\u3066\u306f\u3001<\/a>\u3059\u3067\u306b\u591a\u304f\u306e\u5831\u544a\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u8981\u3059\u308b\u306b\u653b\u6483\u8005\u304c\u76ee\u7684\u3092\u9054\u6210\u3059\u308b\u305f\u3081\u306b\u4fb5\u5bb3\u30b7\u30b9\u30c6\u30e0\u306e\u76e3\u8996\u30fb\u66f4\u65b0\u30fb\u64cd\u4f5c\u3092\u884c\u3046\u3055\u307e\u3056\u307e\u306a\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308b\u3082\u306e\u3067\u3059\u3002<\/p>\n<table style=\"width: 97.5479%;\">\n<tbody>\n<tr>\n<td style=\"width: 35.1792%;\"><b>\u30d7\u30e9\u30b0\u30a4\u30f3\u540d<\/b><\/td>\n<td style=\"width: 416.612%;\"><b>\u65e5\u4ed8\u3001\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u306e\u5024<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Disk<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120325<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Keylog<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120324<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">NetHood<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120213<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">NetStat<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120215<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Option<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120128<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">PortMap<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120325<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Process<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120204<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">RegEdit<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120315<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Screen<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120220<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Service<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120117<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Shell<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120305<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">SQL<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120323<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 35.1792%;\"><span style=\"font-weight: 400;\">Telnet<\/span><\/td>\n<td style=\"width: 416.612%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0x20120225<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u88681 PlugX\u30d7\u30e9\u30b0\u30a4\u30f3<\/em><\/sup><\/span><\/p>\n<p>\u307e\u305f\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">20180209<\/span>\u3068\u3044\u3046\u30ad\u30fc\u307e\u305f\u306f\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u65e5\u4ed8\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u3002\u3053\u306e\u65e5\u4ed8\u306f\u3001\u69cb\u9020\u4f53\u306e\u4e2d\u3067\u4f7f\u7528\u3055\u308c\u3001\u95a2\u6570\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u547c\u3073\u51fa\u3055\u308c\u308b\u305f\u3073\u306b\u6e21\u3055\u308c\u307e\u3059\u3002<\/p>\n<h2>PKPLUG\u3068\u306e\u30ea\u30f3\u30af<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span>\u306e\u3088\u3046\u306aPlugX\u30e2\u30b8\u30e5\u30fc\u30eb\u306b\u306f\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u8a2d\u5b9a\u60c5\u5831\u304c\u542b\u307e\u308c\u3066\u3044\u3066\u8907\u6570\u306eC2\u30a2\u30c9\u30ec\u30b9\u3092\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u304a\u304b\u3052\u3067\u3001\u4fb5\u5bb3\u6d3b\u52d5\u6642\u306b\u4e00\u90e8\u306e\u30ea\u30e2\u30fc\u30c8\u30b5\u30fc\u30d3\u30b9\u304c\u5229\u7528\u3067\u304d\u306a\u304f\u3066\u3082\u3001\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u30d5\u30a9\u30fc\u30eb\u30d0\u30c3\u30af\u30aa\u30d7\u30b7\u30e7\u30f3\u304c\u5229\u7528\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u7279\u5b9a\u306ePlugX\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8 (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">59BA902871E98934C054649CA582E2A01707998ACC78B2570FEF43DBD10F7B6F<\/span>) \u3067\u306f\u3001\u4e0a\u306e\u56f36\u306b\u793a\u3059\u3088\u3046\u306b\u30014\u3064\u306eC2\u69cb\u6210\u30aa\u30d7\u30b7\u30e7\u30f3\u3059\u3079\u3066\u304c\u30c9\u30e1\u30a4\u30f3\u540d<span style=\"font-family: 'courier new', courier, monospace;\">rainydaysweb[.]com<\/span>\u3092\u53c2\u7167\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u6700\u8fd1\u767a\u898b\u3055\u308c\u305f THOR \u3068\u3044\u3046\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc (\u30a4\u30f3\u30d5\u30e9) \u3092\u6301\u3064 PlugX \u30b5\u30f3\u30d7\u30eb\u3068\u3001\u65e2\u77e5\u306e PKPLUG \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u95a2\u9023\u3059\u308b\u4ed6\u306e\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u3068\u306e\u91cd\u8907\u3092\u3001\u4ee5\u4e0b\u306e\u56f3 12 \u306b\u30cf\u30a4\u30e9\u30a4\u30c8\u3057\u3066\u8868\u793a\u3057\u307e\u3057\u305f\u3002\u305d\u308c\u305e\u308c\u3001\u30aa\u30ec\u30f3\u30b8\u8272\u306e\u77e9\u5f62\u3068\u8d64\u306e\u77e9\u5f62\u3067\u56f2\u3063\u3066\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u524d\u8ff0\u306e\u3088\u3046\u306b\u3001\u3053\u306e\u30a2\u30af\u30bf\u30fc\u306f\u81ea\u8eab\u306e\u7ba1\u7406\u3059\u308bGitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">bitsadmin<\/span>\u3092\u4f7f\u7528\u3057\u3066\u6a19\u7684\u306eMicrosoft Exchange Server\u306b<span style=\"font-family: 'courier new', courier, monospace;\">Aro.dat<\/span> (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">59BA902871E98934C054649CA582E2A01707998ACC78B2570FEF43DBD10F7B6F<\/span>) \u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u305f\u3081\u3001\u30e2\u30b8\u30e5\u30fc\u30eb\u306e\u8aad\u307f\u8fbc\u307f\u3068\u5fa9\u53f7\u3092\u3069\u306e\u7279\u5b9a\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u304c\u884c\u3063\u305f\u306e\u304b\u306f\u308f\u304b\u308a\u307e\u305b\u3093\u3002\u305f\u3060\u3057\u305d\u3053\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">rainydaysweb[.]com<\/span>\u3078\u306e\u3064\u306a\u304c\u308a\u306f\u3001\u56f312\u306e\u9752\u3044\u6955\u5186\u5f62\u3067\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_119924\" aria-describedby=\"caption-attachment-119924\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-119925 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/plugx_Figure12.jpg\" alt=\"THOR\u304c\u65e2\u5b58PKPLUG\u30a4\u30f3\u30d5\u30e9\u3068\u3069\u306e\u3088\u3046\u306b\u91cd\u8907\u3057\u3066\u3044\u308b\u304b\u3092\u793a\u3059\u30ea\u30f3\u30af\u3092\u30de\u30c3\u30d4\u30f3\u30b0\u3057\u305f\u3082\u306e\" width=\"900\" height=\"892\" \/><figcaption id=\"caption-attachment-119924\" class=\"wp-caption-text\">\u56f312 THOR\u3068\u65e2\u5b58PKPLUG\u30a4\u30f3\u30d5\u30e9\u3068\u306e\u91cd\u8907\u3092\u8868\u3059Maltego\u30c1\u30e3\u30fc\u30c8<\/figcaption><\/figure>\n<p>\u95a2\u9023\u30a4\u30f3\u30d5\u30e9\u306e\u91cd\u8907\u3084\u4e21\u8005\u306b\u5171\u901a\u3059\u308b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304c\u5224\u660e\u3057\u305f\u3068\u3053\u308d\u3067\u3001\u56f312\u306e\u5404\u90e8\u5206\u3092\u793a\u3059\u53c2\u7167\u756a\u53f7\u8868\u8a18 [X] (\u56f3 12 \u306e\u30d4\u30f3\u30af\u8272\u306e\u6570\u5b57) \u3092\u4f7f\u3063\u3066\u3001\u4ee5\u4e0b\u306b\u8aac\u660e\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<p>2021\u5e743\u670819\u65e5\u306b\u521d\u3081\u3066\u78ba\u8a8d\u3055\u308c\u305fPlugX\u30b5\u30f3\u30d7\u30eb (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">93D33626886E97ABF4087F5445B2A02738EA21D8624B3F015625CD646E9D986E<\/span>) [1]\u306f\u3001\u5f93\u6765\u306ePLUG (THOR\u3067\u306f\u306a\u3044) \u8b58\u5225\u5b50\u3092\u4f7f\u7528\u3057\u3001\u540c\u3058C2 <span style=\"font-family: 'courier new', courier, monospace;\">rainydaysweb[.]com<\/span>\u3068\u901a\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u3001\u4ed6\u306ePlugX\u30b5\u30f3\u30d7\u30eb\u3068\u5171\u901a\u306e\u632f\u308b\u821e\u3044\u3082\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002\u3064\u307e\u308a\u3001<span style=\"font-family: 'courier new', courier, monospace;\">HKLM\\\\Software\\\\CLASSES\\\\ms-pu\\\\PROXY[2]<\/span>\u3068\u3044\u3046\u30ad\u30fc\u306e\u4f5c\u6210\u306b\u7279\u5316\u3057\u305f\u30ec\u30b8\u30b9\u30c8\u30ea\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u884c\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u4e2d\u306b\u306f\u904e\u53bb\u306ePKPLUG\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u95a2\u9023\u3059\u308bC2\u30a4\u30f3\u30d5\u30e9\u3092\u5229\u7528\u3059\u308b\u3082\u306e\u3082\u3042\u308a\u307e\u3059\u3002\u305f\u3068\u3048\u30702020\u5e74\u5f8c\u534a\u306ePlugX\u30b5\u30f3\u30d7\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">A15FED60E69EC07BFD01A23BEEC2C8E9B14AD457EA052BA29BD7A7B806AB63B4<\/span>) [3]\u306f\u3001C2\u3068\u3057\u3066 manager2013[.]com\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u5171\u901a\u306e\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u3092\u4f7f\u7528\u3059\u308b\u30bb\u30c3\u30c8\u306e\u4ed6\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3001\u5171\u901a\u3059\u308b\u30a4\u30f3\u30d5\u30e9\u306e\u4f7f\u7528\u304b\u3089\u3001\u7b2c3\u30ec\u30d9\u30eb\u306e\u30c9\u30e1\u30a4\u30f3<span style=\"font-family: 'courier new', courier, monospace;\">upload.ukbbcnews[.]com<\/span>[4]\u306b\u95a2\u9023\u3059\u308b C2 \u901a\u4fe1\u60c5\u5831\u3092\u542b\u3080\u3001\u8ffd\u52a0\u306e\u30b5\u30f3\u30d7\u30eb\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u3001\u82f1\u56fdBBC\u653e\u9001\u306e\u6b63\u898f\u30c9\u30e1\u30a4\u30f3\u3068\u306f\u3044\u304b\u306a\u308b\u6642\u70b9\u3067\u3082\u7e01\u3082\u3086\u304b\u308a\u3082\u306a\u3044\u30c9\u30e1\u30a4\u30f3\u3067\u3059\u304c\u3001\u88ab\u5bb3\u8005\u306b\u305d\u3046\u898b\u3048\u308b\u3088\u3046\u306b\u3057\u3080\u3051\u308b\u305f\u3081\u306b\u767b\u9332\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u30012021\u5e744\u670812\u65e5\u307e\u3067IPv4\u30a2\u30c9\u30ec\u30b9<span style=\"font-family: 'courier new', courier, monospace;\">45.248.87[.]217<\/span>\u306b\u89e3\u6c7a\u3055\u308c\u30012020\u5e748\u6708\u521d\u65ec\u304b\u3089THOR\u30e2\u30b8\u30e5\u30fc\u30eb mmsvc.ui (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">64E2FE0E9D52812D2DA956B1D92B51E7C215E579241649316CF996F9721E466E<\/span>) \u3092\u542b\u3080PlugX \u30b5\u30f3\u30d7\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">690C488A9902978F2EF05AA23D21F4FA30A52DD9D11191F9B49667CD08618D87<\/span>) [5]\u306bC2\u30c1\u30e3\u30cd\u30eb\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u305d\u306e\u4ed6\u306e\u300cukbbcnews\u300d\u7b2c3\u30ec\u30d9\u30eb\u30c9\u30e1\u30a4\u30f3 (\u4f8b: <span style=\"font-family: 'courier new', courier, monospace;\">bbc.\u3001news.<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">www<\/span>.) \u3082\u5b58\u5728\u3057\u3001\u3053\u308c\u3089\u306f\u53e4\u304f\u306f2019\u5e745\u6708\u304b\u30892021\u5e743\u6708\u307e\u3067\u3001\u540c\u3058<span style=\"font-family: 'courier new', courier, monospace;\">45.248.87[.]217<\/span>\u306eIPv4\u30a2\u30c9\u30ec\u30b9\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3057\u305f\u30022018\u5e74\u306b\u306f\u3001\u540c\u3058\u7b2c3\u30ec\u30d9\u30eb\u30c9\u30e1\u30a4\u30f3\u304c\u3001<span style=\"font-family: 'courier new', courier, monospace;\">185.239.226[.]65\u3001185.239.226[.]76<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">185.239.226[.]14<\/span>\u306a\u3069\u3001AS134835\u306e\u7bc4\u56f2\u306b\u3042\u308b\u8907\u6570\u306eIPv4\u30a2\u30c9\u30ec\u30b9\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30a2\u30c9\u30ec\u30b9\u306f\u30012018\u5e74\u30012019\u5e74\u30012020\u5e74\u3092\u901a\u3058\u3001\u3055\u307e\u3056\u307e\u306aPlugX\u30b5\u30f3\u30d7\u30eb\u306eC2\u30c1\u30e3\u30f3\u30cd\u30eb\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u3066\u3044\u305f\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u30022018\u5e746\u6708\u306ePlugX\u30b5\u30f3\u30d7\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">3CDD33DEA12F21A4F222EB060E1E8CA8A20D5F6CA0FD849715F125B973F3A257<\/span>) [6]\u306f\u3001\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc<span style=\"font-family: 'courier new', courier, monospace;\">HKLM\\SOFTWARE\\Classes\\KET.FAST\\CLSID<\/span>[7]\u306e\u5024\u3092<span style=\"font-family: 'courier new', courier, monospace;\">-1<\/span>\u306b\u8a2d\u5b9a\u3059\u308b\u3068\u3044\u3046\u6319\u52d5\u304c\u904e\u53bb3\u5e74\u9593\u306e\u4ed6\u306e2\u3064\u306ePlugX\u30b5\u30f3\u30d7\u30eb\u306e\u7279\u5fb4\u3068\u5171\u901a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Unit 42\u304c\u628a\u63e1\u3057\u3066\u3044\u308b\u3001\u3053\u3046\u3057\u305f\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u5024\u3092\u5909\u66f4\u3059\u308b3\u3064\u306ePlugX\u30b5\u30f3\u30d7\u30eb\u30bb\u30c3\u30c8\u306e\u3046\u3061\u3001\u3042\u308b 1 \u3064\u306e\u30b5\u30f3\u30d7\u30eb (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">A9511CDAA96ED59DE73A7C7DC375DE204BEE7A9511C5EE71BF013010324A91<\/span>) [8]\u306f\u3001\u540c\u3058\u6642\u671f (2018\u5e746\u6708) \u306b\u3001C2\u901a\u4fe1\u306e\u305f\u3081\u306b\u30c9\u30e1\u30a4\u30f3<span style=\"font-family: 'courier new', courier, monospace;\">tibetsl[.]com<\/span>\u3068\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u304b\u3089\u306e\u591a\u6570\u306e\u7b2c3\u30ec\u30d9\u30eb\u30c9\u30e1\u30a4\u30f3\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u30bb\u30c3\u30c8\u306e 3 \u3064\u76ee\u306e PlugX \u30b5\u30f3\u30d7\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">80DEED939A5206968335D1BB2A9FCCE7053C0156F679BA261824D0A2D44967<\/span>) [9]\u3082\uff0cTHOR \u3068\u3044\u3046\u8b58\u5225\u5b50\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3057\u305f\uff0e2019\u5e7411\u6708\u304b\u3089\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u305d\u306e\u69cb\u6210\u30e2\u30b8\u30e5\u30fc\u30eb<span style=\"font-family: 'courier new', courier, monospace;\">aross.dat<\/span> (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">C5DCD3073904FAD5D9A8FE1026141A832E05C9CA03A88FEE96587921F42773D4<\/span>) \u306f\u3001C2\u901a\u4fe1\u306b<span style=\"font-family: 'courier new', courier, monospace;\">108.61.182[.]34<\/span>\u3092\u4f7f\u3044\u30012019\u5e749\u6708\u304b\u30892020\u5e742\u6708\u306e\u9593\u306b indonesiaport[.]info [10] \u30c9\u30e1\u30a4\u30f3\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u3068\u540c\u3058\u30c9\u30e1\u30a4\u30f3\u304c\u3001Unit 42\u304cPKPLUG\u306b\u95a2\u9023\u3059\u308b\u3082\u306e\u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u305f\u4ed6\u306e\u8907\u6570\u306ePlugX\u30b5\u30f3\u30d7\u30eb (PLUG\u8b58\u5225\u5b50\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u3082\u306e) \u306b\u3088\u308a2017\u5e748\u6708\u307e\u3067\u3055\u304b\u306e\u307c\u3063\u3066C2\u901a\u4fe1\u306b\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>THOR\u8b58\u5225\u5b50\u3092\u4f7f\u7528\u3057\u305f\u3082\u3046\u4e00\u3064\u306e\u69cb\u6210\u30e2\u30b8\u30e5\u30fc\u30eb\u3067\u3042\u308b<span style=\"font-family: 'courier new', courier, monospace;\">acrobat.chm<\/span> (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">B5C0DB62184325FFBE2B8EF7E6F13F5D5926DEAC331EF6D542C5FA50144E0280<\/span>) [11]\u306f\u3001PlugX\u30b5\u30f3\u30d7\u30eb\u306e<span style=\"font-family: 'courier new', courier, monospace;\">Acrobat.dll<\/span> (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">3C5E2A4AFE58634F45C48F4E800DC56BAE3907DDE308FF97740E9CD5684D1C53<\/span>) \u306b\u3088\u3063\u3066\u8aad\u307f\u8fbc\u307e\u308c\u307e\u3059\u3002\u3053\u306e Acrobat.chm \u304c\u521d\u3081\u3066\u78ba\u8a8d\u3055\u308c\u305f\u306e\u306f\u30012020\u5e7410\u6708\u672b\u306e\u3053\u3068\u3067\u3057\u305f\u3002\u3053\u306e\u8a2d\u5b9a\u3067\u306eC2\u30c1\u30e3\u30cd\u30eb\u306f<span style=\"font-family: 'courier new', courier, monospace;\">tools.scbbgroup[.]com<\/span>\u3067\u3001\u5f53\u6642\u306f<span style=\"font-family: 'courier new', courier, monospace;\">167.88.180[.]131<\/span>\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3057\u305f\u304c\u30012021\u5e742\u6708\u4e0a\u65ec\u4ee5\u964d\u306f\u3001AS6134\u3068AS134835\u3067\u305d\u308c\u305e\u308c<span style=\"font-family: 'courier new', courier, monospace;\">103.85.24[.]158<\/span>\u306b\u89e3\u6c7a\u3055\u308c\u7d9a\u3051\u3066\u3044\u307e\u3059[12]\u3002\u305d\u306e\u4ed6\u306e\u65e2\u77e5\u306e PKPLUG \u30a4\u30f3\u30d5\u30e9\u306f\u3053\u308c\u3089\u4e21 AS \u7bc4\u56f2\u306b\u3042\u308b\u8ffd\u52a0\u306e IP \u30a2\u30c9\u30ec\u30b9\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u308c\u3089\u306e IP \u30a2\u30c9\u30ec\u30b9\u306f Unit 42 \u3092\u306f\u3058\u3081\u3068\u3059\u308b\u30d9\u30f3\u30c0\u306b\u3088\u308b\u8ffd\u8de1\u304c\u884c\u308f\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u305f\u3068\u3048\u30702020\u5e744\u6708\u30685\u6708\u306b\u305d\u308c\u305e\u308c<span style=\"font-family: 'courier new', courier, monospace;\">103.85.24[.]190<\/span>\u306b\u89e3\u6c7a\u3057\u305f<span style=\"font-family: 'courier new', courier, monospace;\">www.ixiaoyver[.]com<\/span>\u3068<span style=\"font-family: 'courier new', courier, monospace;\">www.systeminfor[.]com<\/span>\u306f\u3001\u8907\u6570\u306ePlugX\u30b5\u30f3\u30d7\u30eb (PLUG\u8b58\u5225\u5b50\u3092\u4f7f\u7528) \u306eC2\u30c1\u30e3\u30f3\u30cd\u30eb\u3068\u3057\u3066\u6a5f\u80fd\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">www.systeminfor[.]com<\/span>\u306f\u30012\u65e5\u9593\u3068\u3044\u3046\u77ed\u3044\u671f\u9593\u3060\u3051<span style=\"font-family: 'courier new', courier, monospace;\">103.85.24[.]190<\/span>\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u305d\u306e\u76f4\u5f8c\u3001\u89e3\u6c7a\u5148\u304c<span style=\"font-family: 'courier new', courier, monospace;\">167.88.180[.]32<\/span> (AS6134) \u306b\u4e00\u6642\u7684\u306b\u5909\u66f4\u3055\u308c\u3001\u4ed6\u306ePKPLUG\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u304c2020\u5e74\u3092\u901a\u3058\u3066\u3053\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u305d\u3046\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u306e 1 \u3064\u304c<span style=\"font-family: 'courier new', courier, monospace;\">www.cabsecnow[.]com<\/span>\u3067\u3001\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u30012020\u5e748\u6708\u3001THOR\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u4f7f\u3046\u5225\u306e PlugX \u30b5\u30f3\u30d7\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">A9CBCE007A7467BA1394EED32B9C1774AD09A9A9FB74EB2CCC584749273FAC<\/span>01) [13] \u3068\u8a2d\u5b9a\u30e2\u30b8\u30e5\u30fc\u30eb Smadav.dat (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">E2D21B5E34189FA1ACA39A13A405C792B19EDF020907FB9840AF1AAFBAA2F4<\/span>) \u306e C2 \u30c1\u30e3\u30cd\u30eb\u3068\u3057\u3066\u4f7f\u308f\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>THOR\u3068\u3044\u3046\u8b58\u5225\u5b50[14]\u3092\u4f7f\u7528\u3057\u305f\u6700\u5f8c\u306ePlugX\u30b5\u30f3\u30d7\u30eb\u306f\uff0c<span style=\"font-family: 'courier new', courier, monospace;\">SmadHook32.dll<\/span> (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">125FDF108DC1AD6F572CBDDE74B0C7FA938A9ADCE0CC80CB5CE00F1C030B0C93<\/span>) \u3068\uff0c\u305d\u306e\u69cb\u6210\u30e2\u30b8\u30e5\u30fc\u30eb\u3067\u3042\u308b<span style=\"font-family: 'courier new', courier, monospace;\">Smadav<\/span>.<span style=\"font-family: 'courier new', courier, monospace;\">dat<\/span> (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">CC1AFB373F8286C08869CD786FEE75B8002DF595586E00255F52892016FD7A4F<\/span>) \u3067\u3001Unit 42 \u304c\u767a\u898b\u3057\u305f\u6700\u65b0\u306eTHOR\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u30022021\u5e743\u6708\u306b\u521d\u3081\u3066\u78ba\u8a8d\u3055\u308c\u305f\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306eC2\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">news.cqpeizi[.]com<\/span>\u3092\u53c2\u7167\u3057\u3066\u304a\u308a\u30012019\u5e74\u5f8c\u534a\u4ee5\u964d\u306f\u30eb\u30fc\u30d7\u30d0\u30c3\u30af\u30a2\u30c9\u30ec\u30b9<span style=\"font-family: 'courier new', courier, monospace;\">127.0.0[.]1<\/span>\u306b\u89e3\u6c7a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>\u305d\u306e\u4ed6\u306ePlugX\u306e\u63a2\u7d22<\/h2>\n<p>\u6697\u53f7\u5316\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u30d5\u30a1\u30a4\u30eb\u304c\u3069\u306e\u3088\u3046\u306b\u69cb\u6210\u3055\u308c\u3066\u3044\u308b\u304b\u3092\u7406\u89e3\u3057\u305f\u3068\u3053\u308d\u3067Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306fx86\u306e\u30a2\u30bb\u30f3\u30d6\u30ea\u547d\u4ee4\u306b\u57fa\u3065\u3044\u3066\u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u4f5c\u6210\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u547d\u4ee4\u306f\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30a2\u30f3\u30d1\u30c3\u30af\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059 (\u767a\u898b\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u30ea\u30b9\u30c8\u306f\u88682\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044)\u3002<\/p>\n<p>\u4eca\u56de\u306e\u8abf\u67fb\u3067\u306f\u3001\u30a8\u30f3\u30b3\u30fc\u30c9\u65b9\u5f0f\u3084\u30d5\u30a1\u30a4\u30eb\u30d8\u30c3\u30c0\u304c\u7570\u306a\u308b\u4ed6\u306ePlugX\u6697\u53f7\u5316\u6e08\u307f\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u30d5\u30a1\u30a4\u30eb\u30aa\u30d5\u30bb\u30c3\u30c8 0 \u304b\u3089\u59cb\u307e\u308bNULL\u30d0\u30a4\u30c8\u307e\u3067\u306e\u30d0\u30a4\u30c8\u3067\u69cb\u6210\u3055\u308c\u305f\u5fa9\u53f7\u9375\u3067XOR\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u901a\u5e38\u3001\u30ad\u30fc\u306e\u9577\u3055\u306f10\u30d0\u30a4\u30c8\u3067\u3059\u3002\u5fa9\u53f7\u3055\u308c\u308b\u3068\u30b5\u30f3\u30d7\u30eb\u306fPE\u30d5\u30a1\u30a4\u30eb (DLL) \u306b\u306a\u308a\u307e\u3059 (\u767a\u898b\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u3046\u3061\u3053\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3092\u3082\u3064\u3082\u306e\u306e\u30ea\u30b9\u30c8\u306f\u88683\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044) \u3002<\/p>\n<p>\u3053\u306e\u307b\u304b\u306b\u3082\u7570\u306a\u308b\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u65b9\u5f0f\u3067\u6697\u53f7\u5316\u3055\u308c\u305f PlugX \u306e\u30da\u30a4\u30ed\u30fc\u30c9\u30d5\u30a1\u30a4\u30eb\u304c 2 \u3064\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u624b\u52d5\u3067\u5fa9\u53f7\u3057\u305f\u3068\u3053\u308d\u3001PlugX\u306e\u4e9c\u7a2e\u3067\u3042\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f (\u88684\u53c2\u7167) \u3002<\/p>\n<h2>Unit 42\u306b\u3088\u308bPlugX\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u5fa9\u53f7\u30b9\u30af\u30ea\u30d7\u30c8<\/h2>\n<p>Unit 42 \u3067\u30da\u30a4\u30ed\u30fc\u30c9\u5fa9\u53f7\u7528\u306ePython\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f7f\u3046\u3068\u3001\u95a2\u9023\u3059\u308bPlugX\u30ed\u30fc\u30c0\u304c\u306a\u304f\u3066\u3082\u3001\u6697\u53f7\u5316\u3055\u308c\u305fPlugX\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u30fb\u30a2\u30f3\u30d1\u30c3\u30af\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306fPlugX\u306e\u6697\u53f7\u5316\u3055\u308c\u305f\u30b5\u30f3\u30d7\u30eb\u306e\u7a2e\u985e\u306e\u691c\u51fa\u3092\u8a66\u307f\u3066\u3001\u6b21\u306e\u5185\u5bb9\u3092\u51fa\u529b\u3057\u307e\u3059\u3002<\/p>\n<ol>\n<li>PlugX\u30e2\u30b8\u30e5\u30fc\u30eb (DLL) \u3092\u5fa9\u53f7\u3057\u3066\u89e3\u51cd\u3057\u305f\u7d50\u679c\u3002\u30e1\u30e2\u30ea\u5185\u30e2\u30b8\u30e5\u30fc\u30eb\u306b\u306fMZ\u30d8\u30c3\u30c0\u304c\u5b58\u5728\u3057\u3066\u3044\u306a\u3044\u306e\u3067\u30d5\u30a1\u30a4\u30eb\u306b\u306fMZ\u30d8\u30c3\u30c0\u3092\u8ffd\u52a0\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u30e9\u30f3\u30c0\u30e0\u306a\u30d0\u30a4\u30c8\u30d8\u30c3\u30c0\u3092\u6301\u3064\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9 (THOR\u30da\u30a4\u30ed\u30fc\u30c9) \u306b\u306e\u307f\u9069\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305fPlugX\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb (C2\u60c5\u5831) (\u30b5\u30dd\u30fc\u30c8\u3055\u308c\u3066\u3044\u308b\u5834\u5408) \u3002<\/li>\n<\/ol>\n<p>\u30c4\u30fc\u30eb\u306e\u4f7f\u7528\u4f8b\u306f\u4ee5\u4e0b\u306e\u30a2\u30cb\u30e1\u30fc\u30b7\u30e7\u30f3\u3067\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p><img  class=\"wp-image-119917 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/word-image-48.png\" width=\"1\" height=\"1\" \/><img  class=\"aligncenter size-full wp-image-119927 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2021\/07\/U42PlugxDecrypter.gif\" alt=\"Unit 42\u306e\u4f5c\u6210\u3057\u305fPlugX\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u5fa9\u53f7\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u5b9f\u969b\u306e\u52d5\u4f5c\u306e\u4f8b\" width=\"1920\" height=\"770\" \/><\/p>\n<p>\u3053\u306e\u5fa9\u53f7\u30c4\u30fc\u30eb\u306f<a href=\"https:\/\/github.com\/pan-unit42\/public_tools\/tree\/master\/DecryptPlugX\">Unit 42\u304c\u516c\u958b\u3057\u3066\u3044\u308b\u30c4\u30fc\u30eb<\/a>\u306eGitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u3067\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u521d\u8a8d\u304b\u308913\u5e74\u7d4c\u3063\u305f\u4eca\u3067\u3082PlugX\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306f\u8105\u5a01\u3067\u3042\u308a\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u958b\u767a\u8005\u306f10\u5e74\u4ee5\u4e0a\u306b\u308f\u305f\u308a\u4e00\u8cab\u3057\u305f\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u63d0\u4f9b\u3057\u3066\u304d\u307e\u3057\u305f\u304c\u3001\u5510\u7a81\u306b\u30c8\u30ec\u30fc\u30c9\u30de\u30fc\u30af\u306e\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u300cPLUG\u300d\u304b\u3089\u300cTHOR\u300d\u3078\u3068\u5909\u66f4\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u4e9c\u7a2e\u3067\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u914d\u4fe1\u30e1\u30ab\u30cb\u30ba\u30e0\u306e\u5f37\u5316\u3001\u4fe1\u983c\u3055\u308c\u305f\u30d0\u30a4\u30ca\u30ea\u306e\u60aa\u7528\u306a\u3069\u3001\u65b0\u305f\u306a\u6a5f\u80fd\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5f15\u304d\u7d9a\u304dUnit 42\u306fTHOR\u3092\u8b58\u5225\u3059\u308b\u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u3082\u3068\u306b\u3053\u306e\u65b0\u3057\u3044PlugX\u306e\u4e9c\u7a2e\u3068\u306e\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u8ffd\u52a0\u30b5\u30f3\u30d7\u30eb\u3084\u4e9c\u7a2e\u306e\u63a2\u7d22\u3092\u7d9a\u3051\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/wildfire\">WildFire<\/a>\u3068<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/subscriptions\/threat-prevention\">\u8105\u5a01\u9632\u5fa1<\/a>\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u3092\u6709\u52b9\u5316\u3057\u305f<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/next-generation-firewall\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/a> \u3068<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/cortex-xdr\"> Cortex XDR<\/a>\u306b\u3088\u3063\u3066PlugX\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/autofocus\">AutoFocus <\/a>\u3092\u304a\u4f7f\u3044\u306e\u304a\u5ba2\u69d8\u306f<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PlugX\">PlugX<\/a>\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PKPLUG\">PKPLUG<\/a>\u306e\u5404\u30bf\u30b0\u3092\u4f7f\u7528\u3057\u3066PlugX\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8ffd\u8de1\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u672c\u7a3f\u3067\u898b\u3064\u304b\u3063\u305f\u30d5\u30a1\u30a4\u30eb\u30b5\u30f3\u30d7\u30eb\u3084\u4fb5\u5bb3\u306e\u5146\u5019\u306a\u3069\u3092\u3075\u304f\u3080\u8abf\u67fb\u7d50\u679c\u3092Cyber Threat Alliance (CTA \u30b5\u30a4\u30d0\u30fc\u8105\u5a01\u30a2\u30e9\u30a4\u30a2\u30f3\u30b9) \u306e\u30e1\u30f3\u30d0\u30fc\u3068\u5171\u6709\u3057\u307e\u3057\u305f\u3002CTA \u306e\u30e1\u30f3\u30d0\u30fc\u306f\u3053\u306e\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u7528\u3057\u3066\u3001\u304a\u5ba2\u69d8\u306b\u4fdd\u8b77\u3092\u8fc5\u901f\u306b\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u3092\u4f53\u7cfb\u7684\u306b\u963b\u5bb3\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002Cyber Threat Alliance\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001<a href=\"https:\/\/www.cyberthreatalliance.org\/\">Cyber Threat Alliance<\/a>\u306eWeb\u30b5\u30a4\u30c8\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002<\/p>\n<h4>\u8ffd\u52a0\u8cc7\u6599<\/h4>\n<ul>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/pkplug_chinese_cyber_espionage_group_attacking_asia\/\">PKPLUG: \u6771\u5357\u30a2\u30b8\u30a2\u3092\u72d9\u3044\u7d9a\u3051\u308b\u4e2d\u56fd\u306e\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306e\u8ffd\u8de1<\/a><\/li>\n<\/ul>\n<h4>IoC<\/h4>\n<h5>THOR \u306e\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u542b\u3080PlugX\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9<\/h5>\n<table style=\"width: 100.614%;\">\n<tbody>\n<tr>\n<td style=\"width: 71.1112%;\">\n<p style=\"text-align: center;\"><b>SHA256\u5024<\/b><\/p>\n<\/td>\n<td style=\"width: 14.9041%;\">\n<p style=\"text-align: center;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/p>\n<\/td>\n<td style=\"width: 75.1856%;\">\n<p style=\"text-align: center;\"><b>\u521d\u51fa<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">b3c735d3e8c4fa91ca3e1067b19f54f00e94e79b211bec8dc4c044d93c119635<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">pdvdlib.dat<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">04-16-2021<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">59BA902871E98934C054649CA582E2A01707998ACC78B2570FEF43DBD10F7B6F<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">aro.dat<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">03-29-2021<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">67E626B7304A0B14E84EC587622EE07DC0D6ECAC5A2FD08E8A2B4EDD432D2EBC<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">pdvdlib.dat<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">03-19-2021<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">CC1AFB373F8286C08869CD786FEE75B8002DF595586E00255F52892016FD7A4F<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Smadav.dat<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">03-18-2021<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">C28D0D36F5860F80492D435DF5D7D1C6258C6D7FC92076867DB89BC5BD579709<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Samsunghelp.chm<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">02-22-2021<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3d9d004e82553f0596764f858345dcc7d2baee875fd644fa573a37e0904bde88<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ldvpsvc.hlp<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">11-29-2020<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">b5c0db62184325ffbe2b8ef7e6f13f5d5926deac331ef6d542c5fa50144e0280<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">acrobat.chm<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">10-29-2020<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">e2d21b5e34189fa1aca39a13a405c792b19b6edf020907fb9840af1aafbaa2f4<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Smadav.dat<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">08-13-2020<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">89D36FE8B1ED5F937C43CB18569220F982F7FCCAA17EC57A35D53F36A5D13CD6<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">mpsvc.ui<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">08-04-2020<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">64e2fe0e9d52812d2da956b1d92b51e7c215e579241649316cf996f9721e466e<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">mpsvc.ui<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">08-03-2020<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">A2F15D3305958A361E31887E0613C6D476169DB65C72BE4E36721AD556E6FA01<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ui.mdb<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">06-11-2020<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 71.1112%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">C5DCD3073904FAD5D9A8FE1026141A832E05C9CA03A88FEE96587921F42773D4<\/span><\/td>\n<td style=\"width: 14.9041%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">aross.dat<\/span><\/td>\n<td style=\"width: 75.1856%;\"><span style=\"font-weight: 400;\">11-28-2019<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u88682 THOR \u306e\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u542b\u3080PlugX\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9<\/em><\/sup><\/span><\/p>\n<h5>THOR\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u4f7f\u7528\u3057\u305fPlugX\u30ed\u30fc\u30c0<\/h5>\n<table style=\"width: 100.063%;\">\n<tbody>\n<tr>\n<td style=\"width: 73.7864%;\"><b>SHA256\u5024<\/b><\/td>\n<td style=\"width: 95.267%;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 73.7864%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">9FFFB3894B008D5A54343CCF8395A47ACFE953394FFFE2C58550E444FF20EC47<\/span><\/td>\n<td style=\"width: 95.267%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">Aross.dll<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 73.7864%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">125fdf108dc1ad6f572cbdde74b0c7fa938a9adce0cc80cb5ce00f1c030b0c93<\/span><\/td>\n<td style=\"width: 95.267%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">SmadHook32.dll<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 73.7864%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">80deed939a520696968335d1bb2a9fcce7053c0156f679ba261824d0a2d44967<\/span><\/td>\n<td style=\"width: 95.267%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">EndPoint Network Agent.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 73.7864%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3c5e2a4afe58634f45c48f4e800dc56bae3907dde308ff97740e9cd5684d1c53<\/span><\/td>\n<td style=\"width: 95.267%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">acrobat.dll<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 73.7864%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">a9cbce007a7467ba1394eed32b9c1774ad09a9a9fb74eb2ccc584749273fac01<\/span><\/td>\n<td style=\"width: 95.267%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">smadhook32.dll<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 73.7864%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">690c488a9902978f2ef05aa23d21f4fa30a52dd9d11191f9b49667cd08618d87<\/span><\/td>\n<td style=\"width: 95.267%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">mpsvc.dll<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u88683 THOR\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u4f7f\u7528\u3057\u305fPlugX\u30ed\u30fc\u30c0<\/em><\/sup><\/span><\/p>\n<h5>PlugX\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9: XOR\u30d8\u30c3\u30c0<\/h5>\n<table style=\"width: 100.874%;\">\n<tbody>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-family: 'courier new', courier, monospace;\"><b>SHA256\u5024<\/b><\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-family: 'courier new', courier, monospace;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0510e5415689ee5111c5f6ef960a58d0d037864ceaad8f66d57d752a1c1126f4<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">mp.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">055b44336e0d3de5f2a9432dce476ee18c2824dda6fda37613d871f0f4295cd5<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">1833943858e3d7fe1cec0459090f7f3b2bc2d80c774abc4b45b52529a3011e85<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AvastAuth.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">1848c8eb7c18214398dfc1a64a1ab16aced8cc26ed14453045730c2491166f25<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">35a46bdd2f1788fe2a66b1adfe1b21361ebfc3fb597e932e6a0094422637fa48<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">38914419eaf8f3b68fd84f576b6657a68aa894b49bc6d7aa4c52adc4027912c8<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3b1a08ea826921fe12515afa96f2596bca098465c27bb950808b0887f2e2ed84<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3e8e8c2951edd51b3a97b3fc996060ba63ebdaaffa8adfbd374b3693c0e97aee<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3fbbf30015b64b50912c09c43052ac48b1983e869cebfb88dd1271fcb4e60d10<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">http_dll.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">432a07eb49473fa8c71d50ccaf2bc980b692d458ec4aaedd52d739cb377f3428<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">4c8405e1c6531bcb95e863d0165a589ea31f1e623c00bcfd02fbf4f434c2da79<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">56e9b0c2b87d45ee0c109fb71d436621c7ada007f1bd3d43c3e8cf89c0182b90<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">5b16347c180c8a2e25033ec31ac8728e72a0812b01ea7a312cbb341c6c927d06<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">5eaaf8ac2d358c2d7065884b7994638fee3987f02474e54467f14b010a18d028<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AvastAuth.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">6097cc6d6fdd5304029ccedfd3ef49f0656bcf1c60d769b3344dc5129fcb6224<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AvastAuth.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">6a94b9a22bcdadb69e8ae21af2819b0c891896564660049d7e21d5c3053a8d43<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">70457e0cc1b5be30a8774a2528724bc8041969b2c7dca22b64775a4fba3d5501<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AvastAuth.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">776a7e29e3d1288fbbbc11057b800dc4559e4f2b77b827757779213b0d49c22b<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">83eb4e75c332667cdd87c0d61fb00917020329a089dc9294b3dfc172d3299f1d<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">8b8adc6c14ed3bbeacd9f39c4d1380835eaf090090f6f826341a018d6b2ad450<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">8ec409c1537e3030405bc8f8353d2605d1e88f1b245554383682f3aa8b5100ec<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">9f0f962ae8dc444d3774d3f3a72421c2c01ee09d2234378df99c19205362d6fc<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">9f7a911ba583205775b0005a6ce8783fbec50bc91bc747546b0e0ddf386155a0<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AvastAuth.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ab6a11effc5442c220d099385b4790b114c9cb795f484a30fba86f5c626abc26<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">af4844c867ecb3105e92fe4fa6836c5fd463dac1c1e12233b4fb00b00d4ee719<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">af70349513573ef003ca13b88dd6858f843b29525b9e053c89f8508866a1acb0<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">http_dll.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">afa06df5a2c33dc0bdf80bbe09dade421b3e8b5990a56246e0d7053d5668d917<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">bda6f53d37e51385ed739ab51055420254defafff0db669aa55229e0eda9fc66<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">d1f848a8477f171430b339acc4d0113660907705d85fa8ea4fbd9bf4ae20a116<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">d634759a262dc423aa5bb95c3046886516ad60b83197c695d07ab4fce960132b<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">d69d200513a173aff3a4b2474ccc11812115c38a5f27f7aafe98b813c3121208<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">d8882948a7fe4b16fb4b7c16427fbdcf0f0ab8ff3c4bac34f69b0a7d4718183e<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dc42d5d3c7c166a54dffec9e7c36b10a0735432948f7c333b306e27bfbef336c<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">jkljk'kle<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">e1c85ede49a2017e103aa13dfbbf9f7400d3520ee4d6a394ebb0e035c1e016bc<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">e74182800eb247a9e0dfb7e6274dec2839571b650143bcd30423abe10f8daac4<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">main.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">e84f77210840bc508df1c695de01f3a45715f5a02a20e94237f1c0a39c551666<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AvastAuth.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">f0f2ff31b869fdb9f2ef67bfb0cc7840f098a37b6b21e6eb4983134448e3d208<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.0dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">f51ee36cdb86b210a91db98d85ae64acdb5b091a7899b7569955a6b25b65d6b6<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">f7a7eca072cb07af2a769bff4729478a9ec714c59e3c1c25410184014ccee18e<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">main.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">E4C94CC2E53BEB61184F587936EE8134E3ED81872D6EE763CAC20557A5F1077C<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">265E1FAB92C2AA97FA8D5587E6378DBEE024BC3FC23458DF95E97354C6B4235E<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">loggerupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">E8ADA4BC075B6CA47C11C5C747D0F49702323AD13D87BF9459D12F4961CF169E<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">http_dll.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">f224f513c1bad901bf05c719003b1e605543d2a32cfe5aa580f77a63ec882c4c<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">http_dll.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">589e87d4ac0a2c350e98642ac53f4940fcfec38226c16509da21bb551a8f8a36<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">de0f65a421ce8ee4a927f4f9228f29ff12be69ac71edecb18c35cb5101e4c3cf<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u4e0d\u660e<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 78.1605%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0246BAE3D010D2ADD808ECC97D8BF8B68F20301BD99F5CEF85503894E3AD75CC<\/span><\/td>\n<td style=\"width: 104.131%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">adobeupdate.dat<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u88684 PlugX\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9: XOR\u30d8\u30c3\u30c0<\/em><\/sup><\/span><\/p>\n<h5>PlugX\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9: \u672a\u77e5\u306e\u6697\u53f7<\/h5>\n<table style=\"width: 100.471%;\">\n<tbody>\n<tr>\n<td style=\"width: 83.4711%;\"><b>SHA-256\u5024<\/b><\/td>\n<td style=\"width: 107.989%;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 83.4711%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">2194B0E5ED25E31749CB8EA9685951CA47D67210DC7A8116807928DEA4DC2B44<\/span><\/td>\n<td style=\"width: 107.989%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ACLUI.DLL.UI<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 83.4711%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">5c60bee8f311b67d453d793c230399c05693eaab69a4b932bf271f2ac18a74cb<\/span><\/td>\n<td style=\"width: 107.989%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ACLUI.DLL.UI<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u88685 PlugX\u6697\u53f7\u5316\u30da\u30a4\u30ed\u30fc\u30c9: \u672a\u77e5\u306e\u6697\u53f7<\/em><\/sup><\/span><\/p>\n<h5>PLUG\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u4f7f\u7528\u3057\u305fPlugX\u30ed\u30fc\u30c0<\/h5>\n<table style=\"width: 100.853%;\">\n<tbody>\n<tr>\n<td style=\"width: 75.2703%;\"><b>SHA-256\u5024<\/b><\/td>\n<td style=\"width: 113.784%;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">282eef984c20cc334f926725cc36ab610b00d05b5990c7f55c324791ab156d92<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">zVIm1lVT.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">7deb52227f6e08441b2695d0c783a380ebc771ca1fa4dcec96283d41a4ff7905<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">WEXTRACT.EXE<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">f949b78b040cbfc95aafb50ef30ac3e8c16771c6b926b6f8f1efe44a1f437d51<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AcroRd32DQe.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">8a07c265a20279d4b60da2cc26f2bb041730c90c6d3eca64a8dd9f4a032d85d3<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">acrord32.dll<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">lgNdgPd3.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">d64afd9799d8de3f39a4ce99584fa67a615a667945532cfa3f702adbe27724c4<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">AAM UpdatesHtA.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">75ad7745e2b81cb5ffc6d1e267b6c06f56f260452edf09ef4d6fd3ecad584e66<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">csKMR5Bh.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">033c3a372d4d780faa14648c7de93a87d4584afd547609795fb7e9ba370912eb<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">WEXTRACT.EXE<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">26f814e4db5aee02451a628e0b16f945c6141d201cc1c8e63395d4e29e1baa64<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">WEXTRACT.EXE<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">93d33626886e97abf4087f5445b2a02738ea21d8624b3f015625cd646e9d986e<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">unknown<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">769863ec7ba1e28a77c7cc0bda19bb79e6869cae63ecdfab97c669fc40348a0c<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">install_flash_player.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">792eba5ba91a52bfb3b369107f38fb9a7e7b7987cd870f465338eae59e81f3f6<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">avg.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">9699c3f5dd99345b04aaf5e7dc5002de7dbabf922e43125a10eb3f5fc574e51e<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">7Po6BzAx.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">a9511cdaa96ed59de73a7a7c7dc375de204bee7a9511c5ee71bf013010324a91<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">mcinsupd.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">af6cb7f9aaa2e1cff577888164f689c4bdb62490bd78915595d7fdd6462d09c4<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hex.dll<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 75.2703%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">3cdd33dea12f21a4f222eb060e1e8ca8a20d5f6ca0fd849715f125b973f3a257<\/span><\/td>\n<td style=\"width: 113.784%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">web.dll<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt; color: #999999;\"><sup><em>\u88686 PLUG\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u4f7f\u7528\u3057\u305fPlugX\u30ed\u30fc\u30c0<\/em><\/sup><\/span><\/p>\n<h5>\u30b3\u30de\u30f3\u30c9\uff06\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb IoC<\/h5>\n<p><strong>Microsoft Exchange\u306e\u8106\u5f31\u6027\u306b\u95a2\u9023\u3059\u308bPlugX (THOR\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc)<br \/>\n<\/strong><span style=\"font-family: 'courier new', courier, monospace;\">rainydaysweb[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">154.211.14[.]156<\/span><\/p>\n<p><strong>\u305d\u306e\u4ed6\u306ePlugX (THOR\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc)<br \/>\n<\/strong><span style=\"font-family: 'courier new', courier, monospace;\">upload.ukbbcnews[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">indonesiaport[.]info<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">tools.scbbgroup[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.cabsecnow[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">news.cqpeizi[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">45.248.87[.]217<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">103.85.24[.]158<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">167.88.180[.]131<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">167.88.180[.]32<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">108.61.182[.]34<\/span><\/p>\n<p><strong>\u305d\u306e\u4ed6\u306ePlugX (PLUG\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc)<\/strong><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">web.flashplayerup[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">downloads.flashplayerup[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">help.flashplayerup[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">index.flashplayerup[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.destroy2013[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.fitehook[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.manager2013[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.mmfhlele[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">detail.misecure[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.quochoice[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.systeminfor[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.emicrosoftinterview[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">down.emicrosoftinterview[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">news.petalossccaf[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.msdntoolkit[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">www.apple-net[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hdviet.tv-vn[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">103.56.53[.]106<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">185.239.226[.]65<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">103.192.226[.]100<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">45.248.87[.]140<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">45.142.166[.]112<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">103.107.104[.]38<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">42.99.117[.]92<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">45.251.240[.]55<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">103.56.53[.]46<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">154.223.150[.]105<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">45.248.87[.]162<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">103.200.97[.]150<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">42.99.117[.]95<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">43.254.217[.]165<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">45.248.87[.]217<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u30012021\u5e743\u6708\u306b\u767a\u751f\u3057\u305fMicrosoft Exchange Server\u3078\u306e\u653b\u6483\u3092\u76e3\u8996\u3057\u3066\u3044\u305f\u969b\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u4e0a\u306b\u3042\u308b\u4fb5\u5165\u5f8c\u306e\u30ea\u30e2\u30fc\u30c8\u30a2\u30af\u30bb\u30b9\u30c4\u30fc\u30eb (RAT) \u3068\u3057\u3066\u914d\u4fe1\u3055<\/p>\n","protected":false},"author":46,"featured_media":134330,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[5433,4651,5950],"product_categories":[4346,4442,4448,4456],"coauthors":[635,831],"class_list":["post-119951","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-pkplug-ja","tag-plugx-ja","tag-thor","product_categories-advanced-threat-prevention","product_categories-advanced-threat-prevention-ja","product_categories-cortex-xdr-ja","product_categories-next-generation-firewall-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e<\/title>\n<meta name=\"description\" content=\"Unit 42\u306fMicrosoft Exchange Server\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u653b\u6483\u3092\u76e3\u8996\u3059\u308b\u306a\u304b\u3067\u3001\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u305f\u3053\u3068\u306e\u306a\u3044THOR\u3068\u3044\u3046\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u3082\u3064PlugX\u4e9c\u7a2e\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u95a2\u9023\u30ed\u30fc\u30c0\u304c\u306a\u304f\u3066\u3082PlugX\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u30fb\u30a2\u30f3\u30d1\u30c3\u30af\u3067\u304d\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3082\u516c\u958b\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e\" \/>\n<meta property=\"og:description\" content=\"Unit 42\u306fMicrosoft Exchange Server\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u653b\u6483\u3092\u76e3\u8996\u3059\u308b\u306a\u304b\u3067\u3001\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u305f\u3053\u3068\u306e\u306a\u3044THOR\u3068\u3044\u3046\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u3082\u3064PlugX\u4e9c\u7a2e\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u95a2\u9023\u30ed\u30fc\u30c0\u304c\u306a\u304f\u3066\u3082PlugX\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u30fb\u30a2\u30f3\u30d1\u30c3\u30af\u3067\u304d\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3082\u516c\u958b\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-28T01:40:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-28T02:31:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Malware_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Alex Hinchliffe, Mike Harbison\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e","description":"Unit 42\u306fMicrosoft Exchange Server\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u653b\u6483\u3092\u76e3\u8996\u3059\u308b\u306a\u304b\u3067\u3001\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u305f\u3053\u3068\u306e\u306a\u3044THOR\u3068\u3044\u3046\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u3082\u3064PlugX\u4e9c\u7a2e\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u95a2\u9023\u30ed\u30fc\u30c0\u304c\u306a\u304f\u3066\u3082PlugX\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u30fb\u30a2\u30f3\u30d1\u30c3\u30af\u3067\u304d\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3082\u516c\u958b\u3057\u307e\u3057\u305f\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/","og_locale":"ja_JP","og_type":"article","og_title":"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e","og_description":"Unit 42\u306fMicrosoft Exchange Server\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u653b\u6483\u3092\u76e3\u8996\u3059\u308b\u306a\u304b\u3067\u3001\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u305f\u3053\u3068\u306e\u306a\u3044THOR\u3068\u3044\u3046\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u3082\u3064PlugX\u4e9c\u7a2e\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u95a2\u9023\u30ed\u30fc\u30c0\u304c\u306a\u304f\u3066\u3082PlugX\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u30fb\u30a2\u30f3\u30d1\u30c3\u30af\u3067\u304d\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3082\u516c\u958b\u3057\u307e\u3057\u305f\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/","og_site_name":"Unit 42","article_published_time":"2021-07-28T01:40:59+00:00","article_modified_time":"2021-07-28T02:31:37+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Malware_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Alex Hinchliffe, Mike Harbison","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/"},"author":{"name":"Alex Hinchliffe","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d51f04a2afcca497cde7076d89d516f"},"headline":"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e","datePublished":"2021-07-28T01:40:59+00:00","dateModified":"2021-07-28T02:31:37+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/"},"wordCount":2437,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Malware_Category_1920x900.jpg","keywords":["PKPLUG","PlugX","THOR"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/","name":"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Malware_Category_1920x900.jpg","datePublished":"2021-07-28T01:40:59+00:00","dateModified":"2021-07-28T02:31:37+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d51f04a2afcca497cde7076d89d516f"},"description":"Unit 42\u306fMicrosoft Exchange Server\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u653b\u6483\u3092\u76e3\u8996\u3059\u308b\u306a\u304b\u3067\u3001\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u305f\u3053\u3068\u306e\u306a\u3044THOR\u3068\u3044\u3046\u30de\u30b8\u30c3\u30af\u30ca\u30f3\u30d0\u30fc\u3092\u3082\u3064PlugX\u4e9c\u7a2e\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u95a2\u9023\u30ed\u30fc\u30c0\u304c\u306a\u304f\u3066\u3082PlugX\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5fa9\u53f7\u30fb\u30a2\u30f3\u30d1\u30c3\u30af\u3067\u304d\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3082\u516c\u958b\u3057\u307e\u3057\u305f\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Malware_Category_1920x900.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Malware_Category_1920x900.jpg","width":1920,"height":900,"caption":"A close-up view of a computer screen displaying lines of code in red and pink shades, highlighting a central circular warning icon with a biohazard symbol. The word 'DETECTED' is prominently displayed in the lower right corner, indicating a cybersecurity alert and the end of a phrase."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/thor-plugx-variant\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"THOR: PKPLUG\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308bMicrosoft Exchange Server\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305f\u672a\u77e5\u306ePlugX\u4e9c\u7a2e"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d51f04a2afcca497cde7076d89d516f","name":"Alex Hinchliffe","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Alex Hinchliffe"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/alex-hinchliffe\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/119951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=119951"}],"version-history":[{"count":6,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/119951\/revisions"}],"predecessor-version":[{"id":119963,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/119951\/revisions\/119963"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134330"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=119951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=119951"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=119951"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=119951"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=119951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}