{"id":130700,"date":"2023-10-18T06:00:17","date_gmt":"2023-10-18T13:00:17","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=130700"},"modified":"2024-06-19T23:22:59","modified_gmt":"2024-06-20T06:22:59","slug":"blackcat-ransomware-releases-new-utility-munchkin","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/","title":{"rendered":"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f"},"content":{"rendered":"<h2><a id=\"post-130700-_4lt92rr5muov\"><\/a>\u6982\u8981<\/h2>\n<p>\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7 BlackCat \u306e\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u6700\u8fd1\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306e\u30c4\u30fc\u30eb\u66f4\u65b0\u306b\u3064\u3044\u3066\u30a2\u30ca\u30a6\u30f3\u30b9\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u306a\u304b\u306b\u306f\u3001BlackCat \u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8 \u30de\u30b7\u30f3\u3084\u88ab\u5bb3\u7d44\u7e54\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5171\u6709\u306b\u62e1\u6563\u3055\u305b\u308b\u306e\u306b\u4f7f\u3048\u308b Munchkin \u3068\u3044\u3046\u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u3053 2 \u5e74\u307b\u3069\u3001BlackCat \u306e\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u3001\u300c\u30b5\u30fc\u30d3\u30b9\u3068\u3057\u3066\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 (RaaS)\u300d\u30d3\u30b8\u30cd\u30b9 \u30e2\u30c7\u30eb\u306e\u4e00\u90e8\u3068\u3057\u3066\u30c4\u30fc\u30eb\u3092\u7d99\u7d9a\u7684\u306b\u9032\u5316\u3055\u305b\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u540c\u30b0\u30eb\u30fc\u30d7\u3092\u8abf\u67fb\u3092\u3057\u3066\u3044\u3066\u3044\u305f\u3055\u3044\u3001Unit 42 \u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u3001\u300c\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3055\u308c\u305f Alpine \u4eee\u60f3\u30de\u30b7\u30f3 (VM) \u306b\u30ed\u30fc\u30c9\u3055\u308c\u308b\u300d\u3068\u3044\u3046\u70b9\u3067\u30e6\u30cb\u30fc\u30af\u306a Munchkin \u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u53d6\u5f97\u3057\u307e\u3057\u305f\u3002\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3055\u308c\u305f VM \u3092\u4f7f\u3063\u3066\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u5c55\u958b\u3059\u308b\u3053\u306e\u65b0\u305f\u306a\u6226\u8853\u306f\u3053\u3053\u6570\u30ab\u6708\u52e2\u3044\u3092\u5897\u3057\u3066\u304a\u308a\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3089\u306f VM \u3092\u4f7f\u3046\u3053\u3068\u3067\u30de\u30eb\u30a6\u30a7\u30a2 \u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5c55\u958b\u6642\u306b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3092\u56de\u907f\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u672c\u7a3f\u3067\u306f\u3053\u306e\u65b0\u305f\u306a\u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u304c\u3069\u306e\u3088\u3046\u306b\u6a5f\u80fd\u3057\u3066\u3044\u308b\u306e\u304b\u3092\u8a73\u3057\u304f\u8aac\u660e\u3057\u3001BlackCat \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u7d99\u7d9a\u5229\u7528\u3057\u3066\u3044\u308b\u6226\u8853\u306b\u3055\u3089\u306b\u5149\u3092\u5f53\u3066\u3066\u3044\u304d\u307e\u3059\u3002\u672c\u7a3f\u304c\u60c5\u5831\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u696d\u754c\u306e\u7686\u3055\u3093\u306e\u3044\u3063\u305d\u3046\u306e\u53d6\u308a\u7d44\u307f\u3092\u4fc3\u3057\u3001\u3053\u306e\u9032\u5316\u3059\u308b\u8105\u5a01\u306b\u5bfe\u3059\u308b\u9632\u5fa1\u5f37\u5316\u306e\u4e00\u52a9\u3068\u306a\u308c\u3070\u5e78\u3044\u3067\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001\u672c\u7a3f\u3067\u53d6\u308a\u4e0a\u3052\u305f\u3053\u306e\u7279\u5b9a\u306e\u8105\u5a01\u306e\u6307\u6a19\u3092\u300c\u60aa\u610f\u306e\u3042\u308b\u3082\u306e\u300d\u3068\u3057\u3066\u9069\u5207\u306b\u8b58\u5225\u3059\u308b\u3053\u3068\u306b\u3088\u308b\u4fdd\u8b77\u3092\u53d7\u3051\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<td style=\"width: 35%;\"><b>\u95a2\u9023\u3059\u308b Unit 42 \u306e\u30c8\u30d4\u30c3\u30af<\/b><\/td>\n<td style=\"width: 100%;\"><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/blackcat-ransomware-ja\/\" target=\"_blank\" rel=\"noopener\"><b>BlackCat Ransomware<\/b><\/a>, <strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/cybercrime-ja\/\" target=\"_blank\" rel=\"noopener\">Cybercrime<\/a><\/strong><\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<h2><a id=\"post-130700-_wven14kmgum2\"><\/a>BlackCat \u306e\u6982\u8981<\/h2>\n<p><a href=\"https:\/\/unit42.paloaltonetworks.jp\/blackcat-ransomware\/\" target=\"_blank\" rel=\"noopener\">BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2<\/a>\u8105\u5a01\u304c\u521d\u3081\u3066\u516c\u3051\u306b\u306a\u3063\u305f\u306e\u306f\u30012021 \u5e74 11 \u6708\u306b\u305d\u306e\u5b58\u5728\u304c\u8868\u9762\u5316\u3057\u305f\u3068\u304d\u3067\u3057\u305f\u3002\u540c\u30b0\u30eb\u30fc\u30d7\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u5185\u90e8\u306e\u6d17\u7df4\u5ea6\u5408\u3044\u3084 Rust \u30d7\u30ed\u30b0\u30e9\u30df\u30f3\u30b0\u8a00\u8a9e\u306e\u4f7f\u7528\u306a\u3069\u306e\u72ec\u81ea\u30a2\u30d7\u30ed\u30fc\u30c1\u3067\u60aa\u540d\u3092\u99b3\u305b\u307e\u3057\u305f\u3002<\/p>\n<p>BlackCat \u306f\u307b\u304b\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3068\u540c\u3058 RaaS \u30d3\u30b8\u30cd\u30b9 \u30e2\u30c7\u30eb\u3092\u63a1\u7528\u3057\u3066\u3044\u307e\u3059\u3002RaaS \u30d3\u30b8\u30cd\u30b9 \u30e2\u30c7\u30eb\u3067\u306f\u3001\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u304c\u30a2\u30af\u30bf\u30fc\u63d0\u4f9b\u306e\u30c4\u30fc\u30eb\u3092\u6d3b\u7528\u3059\u308b\u304b\u308f\u308a\u306b\u3001\u5229\u76ca\u306e\u4e00\u90e8\u3092\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306b\u9084\u5143\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u904e\u53bb\u306e\u5831\u544a\u306b\u57fa\u3065\u304f\u3068\u3001\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u306f\u8eab\u4ee3\u91d1\u652f\u6255\u3044\u984d\u306e\u304a\u3088\u305d 80 \uff5e 90% \u3092\u4fdd\u6301\u3057\u3001\u6b8b\u308a\u3092\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306b\u9001\u91d1\u3057\u307e\u3059\u3002<\/p>\n<p>BlackCat \u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306f\u305d\u306e\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u3082\u542b\u3081\u3001\u6b74\u53f2\u7684\u306b\u7c73\u56fd\u56fd\u5185\u306e\u88ab\u5bb3\u8005\u3092\u91cd\u70b9\u7684\u306b\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u3057\u3066\u304d\u307e\u3057\u305f\u3002\u305f\u3060\u3057\u305d\u306e\u4eba\u6c17\u306e\u9ad8\u307e\u308a\u3068\u6642\u9593\u306e\u7d4c\u904e\u306b\u3064\u308c\u3001\u88ab\u5bb3\u5bfe\u8c61\u306f\u5927\u304d\u304f\u5e83\u304c\u308a\u3001\u6700\u8fd1\u3067\u306f BlackCat \u304c\u4e16\u754c\u4e2d\u306e\u3055\u307e\u3056\u307e\u306a\u696d\u754c\u3084\u696d\u7a2e\u3092\u307e\u305f\u304c\u308b\u88ab\u5bb3\u8005\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u3057\u3066\u3044\u308b\u3088\u3046\u3059\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>BlackCat \u306e\u30c4\u30fc\u30eb \u30bb\u30c3\u30c8\u306f\u9577\u5e74\u9032\u5316\u3092\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002\u30aa\u30ea\u30b8\u30ca\u30eb \u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u306f\u3001\u96e3\u8aad\u5316\u3084\u6697\u53f7\u5316\u306e\u3055\u308c\u3066\u3044\u306a\u3044\u57cb\u3081\u8fbc\u307f\u306e JSON \u69cb\u6210\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u6642\u9593\u7d4c\u904e\u3068\u3068\u3082\u306b\u3053\u306e\u8105\u5a01\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u3092\u66f4\u65b0\u3057\u3001\u3053\u306e\u57fa\u76e4\u306e\u69cb\u6210\u3082\u96e3\u8aad\u5316\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u307e\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u5b9f\u884c\u306b\u306f\u3001\u30e6\u30cb\u30fc\u30af\u306a\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3 \u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u3092\u8981\u6c42\u3059\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u305d\u3046\u3059\u308b\u3053\u3068\u3067 BlackCat \u306f\u3001\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3 \u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u3092\u77e5\u3089\u306a\u3044\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b3\u30df\u30e5\u30cb\u30c6\u30a3\u306e\u4eba\u3005\u304c\u57fa\u76e4\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u3064\u3044\u3066\u306e\u6d1e\u5bdf\u3092\u5f97\u3089\u308c\u306a\u3044\u3088\u3046\u306b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u306f\u9032\u5316\u3057\u7d9a\u3051\u3066\u304a\u308a\u3001\u8105\u5a01\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u3055\u3089\u306b\u6a5f\u80fd\u3068\u96e3\u8aad\u5316\u30e1\u30ab\u30cb\u30ba\u30e0\u3092\u62e1\u5145\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u3053\u6570\u30ab\u6708\u3001BlackCat \u306f\u300cMunchkin\u300d\u3068\u3044\u3046\u540d\u524d\u306e\u65b0\u3057\u3044\u30c4\u30fc\u30eb\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u30c4\u30fc\u30eb\u306f\u3001Sphynx (\u6700\u65b0\u306e BlackCat \u4e9c\u7a2e) \u3092\u5b9f\u884c\u3059\u308b Linux \u30d9\u30fc\u30b9\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0 \u30b7\u30b9\u30c6\u30e0 (OS) \u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u8105\u5a01\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u3053\u306e\u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u3092\u4f7f\u3044\u3001\u30ea\u30e2\u30fc\u30c8 \u30de\u30b7\u30f3\u4e0a\u3067 BlackCat \u3092\u5b9f\u884c\u3057\u305f\u308a\u3001\u30ea\u30e2\u30fc\u30c8\u306b\u3042\u308b SMB (Server Message Block) \u30d5\u30a1\u30a4\u30eb\u5171\u6709\u3084 CIFS (Common Internet File System) \u30d5\u30a1\u30a4\u30eb\u5171\u6709\u306b BlackCat \u3092\u5c55\u958b\u3057\u3066\u6697\u53f7\u5316\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_130695\" aria-describedby=\"caption-attachment-130695\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-130696 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/10\/1965-F1-BlackCat-ja.png\" alt=\"\u753b\u50cf 1 \u306f\u3001Munchkin \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u304c\u3069\u306e\u3088\u3046\u306b\u6a5f\u80fd\u3059\u308b\u304b\u3092\u793a\u3059\u56f3\u3067\u3059\u3002Virtualbox \u306f\u88ab\u5bb3\u30db\u30b9\u30c8\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u3066\u3001\u3053\u308c\u304c\u30ab\u30b9\u30bf\u30e0 ISO\/\u4eee\u60f3\u30de\u30b7\u30f3\u3092\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u3053\u306e\u6642\u70b9\u304b\u3089\u3001\u30ea\u30e2\u30fc\u30c8\u306e SMB \u30d5\u30a1\u30a4\u30eb\u5171\u6709\u304c\u6697\u53f7\u5316\u3055\u308c\u3001BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30b3\u30d4\u30fc\u304c\u30ea\u30e2\u30fc\u30c8\u306e\u30de\u30b7\u30f3\u306b\u30d7\u30c3\u30b7\u30e5\u3055\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"423\" \/><figcaption id=\"caption-attachment-130695\" class=\"wp-caption-text\">\u56f3 1. Munchkin \u30c4\u30fc\u30eb\u306e\u30d7\u30ed\u30bb\u30b9\u56f3<\/figcaption><\/figure>\n<p>\u4eee\u60f3\u30de\u30b7\u30f3\u3092\u4f7f\u3046\u30de\u30eb\u30a6\u30a7\u30a2\u5b9f\u884c\u306f\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30b3\u30df\u30e5\u30cb\u30c6\u30a3\u3067\u5897\u52a0\u50be\u5411\u306b\u3042\u308a\u307e\u3059\u3002\u307b\u304b\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u7d44\u7e54\u3082\u540c\u3058\u3088\u3046\u306b<a href=\"https:\/\/tech.hindustantimes.com\/tech\/news\/a-new-ransomware-uses-virtual-machine-to-dodge-security-71590409211492.html\" target=\"_blank\" rel=\"noopener\">\u3053\u306e\u65b0\u305f\u306a\u6226\u8853\u3092\u6d3b\u7528\u3057\u3066\u3044\u308b\u3068\u5831\u544a\u3055\u308c\u3066\u3044\u307e\u3059<\/a>\u3002<\/p>\n<p>\u3053\u306e\u30a2\u30d7\u30ed\u30fc\u30c1\u306e\u5229\u70b9\u3068\u3057\u3066\u3001\u30a6\u30a4\u30eb\u30b9\u5bfe\u7b56\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u306a\u3069\u3001\u30db\u30b9\u30c8\u306e OS \u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3084\u4fdd\u8b77\u3092\u56de\u907f\u3067\u304d\u308b\u3053\u3068\u304c\u6319\u3052\u3089\u308c\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u306f\u7d44\u307f\u8fbc\u307f\u306e\u4eee\u60f3 OS \u306b\u5bfe\u3059\u308b\u30a4\u30f3\u30c8\u30ed\u30b9\u30da\u30af\u30b7\u30e7\u30f3\u3092\u6301\u305f\u306a\u3044\u3053\u3068\u304c\u591a\u304f\u3001\u305d\u3053\u306b\u3042\u308b\u30c1\u30a7\u30c3\u30af\u6a5f\u80fd\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u30d0\u30a4\u30d1\u30b9\u3055\u308c\u308b\u3053\u3068\u304c\u5c11\u306a\u304f\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u6700\u8fd1\u884c\u3063\u305f\u8abf\u67fb\u306e\u306a\u304b\u3067\u3001Unit 42 \u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u3053\u306e VM \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u306e\u30b3\u30d4\u30fc\u3092\u5165\u624b\u3067\u304d\u3001\u305d\u306e\u304a\u304b\u3052\u3067\u3053\u308c\u304c\u3069\u306e\u3088\u3046\u306b\u6a5f\u80fd\u3059\u308b\u304b\u306b\u95a2\u3059\u308b\u6d1e\u5bdf\u3092\u63d0\u4f9b\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<h2><a id=\"post-130700-_fxlpi3lm4yu0\"><\/a>Alpine Linux \u3092\u63a1\u7528<\/h2>\n<p>Munchkin \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u306f ISO \u30d5\u30a1\u30a4\u30eb\u3068\u3057\u3066\u63d0\u4f9b\u3055\u308c\u3001\u3053\u308c\u304c\u4eee\u60f3\u5316\u88fd\u54c1 VirtualBox \u306e\u65b0\u305f\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305f\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306b\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002\u3053\u306e ISO \u30d5\u30a1\u30a4\u30eb\u306f\u3001<a href=\"https:\/\/www.alpinelinux.org\/about\/\" target=\"_blank\" rel=\"noopener\">Alpine OS<\/a> \u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3057\u305f\u5b9f\u88c5\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u8105\u5a01\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u305d\u306e\u30d5\u30c3\u30c8\u30d7\u30ea\u30f3\u30c8\u304c\u5c0f\u3055\u3055\u304b\u3089\u3053\u306e OS \u3092\u9078\u629e\u3057\u305f\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0 \u30b7\u30b9\u30c6\u30e0\u3092\u5b9f\u884c\u3059\u308b\u3068\u3001\u30d6\u30fc\u30c8\u6642\u306b\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<!-- Crayon Syntax Highlighter v_2.7.2_beta --><\/p>\n<pre class=\"lang:default decode:true\">echo -n \"root:[password]\" | chpasswd\r\ntmux new-session -A -s controller \\; send -t controller \"\/app\/controller &amp;&amp; poweroff\" ENTER \\; detach -s controller\r\neject\r\n<\/pre>\n<p><!-- [Format Time: 0.0004 seconds] --><\/p>\n<p>\u3053\u3053\u3067\u3001\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u6700\u521d\u306b VM \u306e root \u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u9078\u3093\u3060\u30d1\u30b9\u30ef\u30fc\u30c9\u306b\u5909\u66f4\u3057\u3066\u3044\u307e\u3059\u3002\u6b21\u306b\u3001\u7d44\u307f\u8fbc\u307f\u306e tmux \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u3092\u4ecb\u3057\u3001\u65b0\u305f\u306a\u30bf\u30fc\u30df\u30ca\u30eb \u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u751f\u6210\u3057\u3001\u3053\u306e\u30bf\u30fc\u30df\u30ca\u30eb \u30bb\u30c3\u30b7\u30e7\u30f3\u3092 <span style=\"font-family: 'courier new', courier, monospace;\">controller<\/span> \u3068\u3044\u3046\u540d\u524d\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30d0\u30a4\u30ca\u30ea\u30fc\u3092\u5b9f\u884c\u3059\u308b\u306e\u306b\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u304c\u5b8c\u4e86\u3059\u308b\u3068 VM \u306e\u96fb\u6e90\u306f\u30aa\u30d5\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e <span style=\"font-family: 'courier new', courier, monospace;\">controller<\/span> \u3068\u3044\u3046\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">\/app<\/span> \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u5185\u306b\u307b\u304b\u306e\u95a2\u9023\u30d5\u30a1\u30a4\u30eb\u3068\u3044\u3063\u3057\u3087\u306b\u30db\u30b9\u30c8\u3055\u308c\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u307b\u304b\u306e\u95a2\u9023\u30d5\u30a1\u30a4\u30eb\u3084\u6ce8\u76ee\u3059\u3079\u304d\u30d5\u30a1\u30a4\u30eb\u3082\u3053\u306e VM OS \u5185\u306b\u306f\u542b\u307e\u308c\u3066\u3044\u307e\u3059 (\u4ee5\u4e0b\u8868 1 \u53c2\u7167)\u3002<\/p>\n<table style=\"width: 100%; height: 490px;\">\n<tbody>\n<tr style=\"height: 56px;\">\n<td style=\"text-align: center; height: 56px;\"><b>\u30d5\u30a1\u30a4\u30eb \u30d1\u30b9<\/b><\/td>\n<td style=\"text-align: center; height: 56px;\"><b>\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr style=\"height: 57px;\">\n<td style=\"height: 57px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/app\/controller<\/span><\/td>\n<td style=\"height: 57px;\"><span style=\"font-weight: 400;\">Munchkin \u30de\u30eb\u30a6\u30a7\u30a2 \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3<\/span><\/td>\n<\/tr>\n<tr style=\"height: 80px;\">\n<td style=\"height: 80px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/app\/config<\/span><\/td>\n<td style=\"height: 80px;\"><span style=\"font-weight: 400;\">Munchkin \u304c\u4f7f\u3046\u30b7\u30ea\u30a2\u30eb\u30e9\u30a4\u30ba\u3055\u308c\u305f\u69cb\u6210\u30d5\u30a1\u30a4\u30eb<\/span><\/td>\n<\/tr>\n<tr style=\"height: 80px;\">\n<td style=\"height: 80px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/app\/payload<\/span><\/td>\n<td style=\"height: 80px;\"><span style=\"font-weight: 400;\">\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3068\u306a\u308b BlackCat \u30de\u30eb\u30a6\u30a7\u30a2 \u30b5\u30f3\u30d7\u30eb\u3002\u5b9f\u884c\u6642\u306b Munchkin \u304c\u3053\u308c\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3059\u308b<\/span><\/td>\n<\/tr>\n<tr style=\"height: 80px;\">\n<td style=\"height: 80px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/scripts\/smb_common.py<\/span><\/td>\n<td style=\"height: 80px;\"><span style=\"font-weight: 400;\">SMB \u95a2\u9023\u306e\u64cd\u4f5c\u7528\u306e Python \u30d8\u30eb\u30d1\u30fc \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3<\/span><\/td>\n<\/tr>\n<tr style=\"height: 80px;\">\n<td style=\"height: 80px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/scripts\/smb_copy_and_exec.py<\/span><\/td>\n<td style=\"height: 80px;\"><span style=\"font-weight: 400;\">Python \u30b9\u30af\u30ea\u30d7\u30c8\u3002SMB \u7d4c\u7531\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u30b3\u30d4\u30fc\u3057\u3066\u5b9f\u884c\u3059\u308b\u305f\u3081\u306b\u4f7f\u3046<\/span><\/td>\n<\/tr>\n<tr style=\"height: 57px;\">\n<td style=\"height: 57px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">\/scripts\/smb_exec.py<\/span><\/td>\n<td style=\"height: 57px;\"><span style=\"font-weight: 400;\">Python \u30b9\u30af\u30ea\u30d7\u30c8\u3002\u30ea\u30e2\u30fc\u30c8 \u30d5\u30a1\u30a4\u30eb\u306e\u5b9f\u884c\u306b\u4f7f\u3046<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><a id=\"post-130700-_l9vdscld644w\"><\/a><span style=\"font-size: 8pt; color: #999999;\"><em>\u8868 1. VM OS \u5185\u306b\u542b\u307e\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u30d5\u30a1\u30a4\u30eb \u30d1\u30b9\u3068\u305d\u306e\u8aac\u660e<\/em><\/span><\/p>\n<p>\u4e0a\u8a18\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u307b\u304b\u306b\u3082\u591a\u6570\u306e Python \u30b9\u30af\u30ea\u30d7\u30c8\u304c <span style=\"font-family: 'courier new', courier, monospace;\">\/usr\/bin<\/span> \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u306b\u306f\u5b58\u5728\u3057\u3066\u3044\u307e\u3059\u3002BlackCat \u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u3053\u308c\u3089\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u3053\u306e\u3042\u3068 VM \u5185\u3067\u884c\u3046\u66f4\u65b0\u51e6\u7406\u3067\u5229\u7528\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">DumpNTLMInfo.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">Get-GPPPassword.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">GetADUsers.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">GetNPUsers.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">GetUserSPNs.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">addcomputer.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">atexec.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">changepasswd.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">dcomexec.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">dpapi.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">esentutl.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">exchanger.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">findDelegation.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">flask<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">futurize<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">getArch.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">getPac.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">getST.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">getTGT.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">goldenPac.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">karmaSMB.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">keylistattack.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">kintercept.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ldapdomaindump<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ldd2bloodhound<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ldd2pretty<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">lookupsid.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">machine_role.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">mimikatz.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">mqtt_check.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">mssqlclient.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">mssqlinstance.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">net.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">netview.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">nmapAnswerMachine.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">normalizer<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ntfs-read.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ntlmrelayx.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">pasteurize<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ping.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ping6.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">pip<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">pip3<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">pip3.11<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">psexec.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">raiseChild.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">rbcd.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">rdp_check.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">reg.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">registry-read.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">rpcdump.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">rpcmap.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">sambaPipe.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">samrdump.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">secretsdump.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">services.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">smbclient.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">smbexec.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">smbpasswd.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">smbrelayx.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">smbserver.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">sniff.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">sniffer.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">split.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ticketConverter.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ticketer.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">tstool.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">wmiexec.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">wmipersist.py<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">wmiquery.py<\/span><\/li>\n<\/ul>\n<p>\u653b\u6483\u8005\u306f\u3001\u4e0a\u8a18\u306e Python \u30b9\u30af\u30ea\u30d7\u30c8\u3092\u591a\u6570\u4f7f\u3044\u3001\u88ab\u5bb3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u4e0a\u3067\u306e\u3055\u3089\u306a\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u5b9f\u884c\u3001\u30e9\u30c6\u30e9\u30eb\u30e0\u30fc\u30d6\u3001\u30d1\u30b9\u30ef\u30fc\u30c9 \u30c0\u30f3\u30d7\u306a\u3069\u3092\u884c\u3048\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e controller \u3068\u3044\u3046\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001BlackCat \u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u3068\u975e\u5e38\u306b\u3088\u304f\u4f3c\u305f\u65b9\u6cd5\u3067 Rust \u30d7\u30ed\u30b0\u30e9\u30df\u30f3\u30b0\u8a00\u8a9e\u3067\u66f8\u304b\u308c\u3066\u3044\u307e\u3059\u3002\u5b9f\u884c\u3059\u308b\u3068\u3001controller \u306f\u307e\u305a\u72ec\u81ea\u306e\u30b7\u30f3\u30b0\u30eb\u30d0\u30a4\u30c8 XOR \u6f14\u7b97\u3067\u591a\u6570\u306e\u6587\u5b57\u5217\u3092\u5fa9\u53f7\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_130686\" aria-describedby=\"caption-attachment-130686\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-130687 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/10\/word-image-130681-2-ja.png\" alt=\"\u753b\u50cf 2 \u306f\u30012 \u3064\u306e\u30b3\u30fc\u30c9\u3092\u6bd4\u8f03\u3057\u305f\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u5de6\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306f\u30aa\u30ea\u30b8\u30ca\u30eb\u3067\u3059\u3002\u53f3\u5074\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306f\u5fa9\u53f7\u3057\u305f\u30e9\u30f3\u30bf\u30a4\u30e0 \u30b3\u30fc\u30c9\u3067\u3059\u3002 \" width=\"900\" height=\"471\" \/><figcaption id=\"caption-attachment-130686\" class=\"wp-caption-text\">\u56f32. \u30e9\u30f3\u30bf\u30a4\u30e0\u306e\u6587\u5b57\u5217\u306e\u5fa9\u53f7<\/figcaption><\/figure>\n<p>\u6587\u5b57\u5217\u306e\u5fa9\u53f7\u5f8c\u3001\u57fa\u672c\u7684\u306a\u30c1\u30a7\u30c3\u30af\u3092\u5b9f\u884c\u3057\u3001\u671f\u5f85\u3057\u305f\u69cb\u6210\u30d5\u30a1\u30a4\u30eb\u3084\u30da\u30a4\u30ed\u30fc\u30c9 \u30d5\u30a1\u30a4\u30eb\u304c <span style=\"font-family: 'courier new', courier, monospace;\">\/app<\/span> \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u5185\u306b\u5b58\u5728\u3059\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001<span style=\"font-family: 'courier new', courier, monospace;\">\/app\/config<\/span> \u30d5\u30a1\u30a4\u30eb\u3092\u30c7\u30b7\u30ea\u30a2\u30e9\u30a4\u30ba\u3057\u3066\u30d1\u30fc\u30b9\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u3044\u305a\u308c\u304b\u304c\u5b58\u5728\u3057\u306a\u3044\u5834\u5408\u3001\u307e\u305f\u306f\u30d5\u30a1\u30a4\u30eb\u3092\u30d1\u30fc\u30b9\u3067\u304d\u306a\u3044\u5834\u5408\u3001\u30a8\u30e9\u30fc \u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u8868\u793a\u3057\u3066\u7d42\u4e86\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">\/app\/config<\/span> \u30d5\u30a1\u30a4\u30eb\u306b\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u60c5\u5831\u304c\u8c4a\u5bcc\u306b\u542b\u307e\u308c\u3066\u3044\u3066\u3001\u3053\u308c\u3089\u306e\u60c5\u5831\u3092 controller \u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30b5\u30f3\u30d7\u30eb\u304c\u5f8c\u3067\u4f7f\u3046\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30a2\u30af\u30bb\u30b9 \u30c8\u30fc\u30af\u30f3<\/li>\n<li>\u30bf\u30b9\u30af\u306e\u8b58\u5225\u5b50<\/li>\n<li>\u88ab\u5bb3\u8005\u306e\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb (\u30e6\u30fc\u30b6\u30fc\u540d\u3001\u30d1\u30b9\u30ef\u30fc\u30c9\u3001\u30c9\u30e1\u30a4\u30f3\u3092\u542b\u3080)<\/li>\n<li>BlackCat \u88ab\u5bb3\u8005\u306e URL<\/li>\n<li>\u30d6\u30ed\u30c3\u30af\u30ea\u30b9\u30c8\u306b\u767b\u9332\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u7a2e\u985e\u3068\u30d1\u30b9<\/li>\n<li>\u6697\u53f7\u5316\u306e\u5bfe\u8c61\u3068\u306a\u308b\u30db\u30b9\u30c8\u3068\u5171\u6709<\/li>\n<\/ul>\n<p>\u69cb\u6210\u3092\u30d1\u30fc\u30b9\u3057\u305f\u5f8c\u3001controller \u306f <span style=\"font-family: 'courier new', courier, monospace;\">\/payloads\/<\/span> \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u3092\u4f5c\u6210\u3057\u3066\u30de\u30a6\u30f3\u30c8\u3057\u3001\u3053\u308c\u3092\u305d\u306e\u5f8c\u4f5c\u6210\u3059\u308b BlackCat \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30db\u30b9\u30c8\u306b\u4f7f\u3044\u307e\u3059\u3002controller \u306f\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3057\u305f BlackCat \u30b5\u30f3\u30d7\u30eb\u3092\u4f5c\u6210\u3059\u308b\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3068\u3057\u3066\u524d\u8ff0\u306e <span style=\"font-family: 'courier new', courier, monospace;\">\/app\/payload<\/span> \u3092\u4f7f\u3044\u307e\u3059\u3002\u3053\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8 \u30d5\u30a1\u30a4\u30eb\u5185\u306b\u306f\u3001controller \u304c\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u5909\u66f4\u6642\u306b\u691c\u7d22\u30fb\u4f7f\u7528\u3059\u308b\u7279\u5b9a\u306e\u30de\u30fc\u30ab\u30fc\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_130688\" aria-describedby=\"caption-attachment-130688\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-130689 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/10\/word-image-130681-3-ja.png\" alt=\"\u753b\u50cf 3 \u306f\u30012 \u3064\u306e BlackCat \u30b5\u30f3\u30d7\u30eb\u306e\u6bd4\u8f03\u3067\u3059\u3002\u5de6\u5074\u306f BlackCat \u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8 \u30d5\u30a1\u30a4\u30eb\u3067\u3059\u3002\u305d\u306e\u884c\u306e\u591a\u304f\u306f\u9752\u3067\u5f37\u8abf\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u53f3\u306f\u4fee\u6b63\u5f8c\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u305d\u306e\u884c\u306e\u591a\u304f\u306f\u8d64\u3067\u5f37\u8abf\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"415\" \/><figcaption id=\"caption-attachment-130688\" class=\"wp-caption-text\">\u56f33. \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3068\u69cb\u6210\u3092\u3082\u3068\u306b\u65b0\u305f\u306a BlackCat \u30b5\u30f3\u30d7\u30eb\u3092\u4f5c\u6210<\/figcaption><\/figure>\n<p>\u4f5c\u6210\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u306f\u63d0\u4f9b\u3055\u308c\u305f\u69cb\u6210\u3092\u3082\u3068\u306b\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u30d5\u30a1\u30a4\u30eb\u540d\u306f\u5024\u3092\u30a4\u30f3\u30af\u30ea\u30e1\u30f3\u30c8\u3057\u3066\u4ed8\u3051\u3089\u308c\u307e\u3059 (\u4ee5\u4e0b\u53c2\u7167)\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">\/payloads\/0<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">\/payloads\/1<\/span><\/li>\n<\/ul>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u4f5c\u6210\u3057\u7d42\u308f\u308b\u3068\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u6307\u5b9a\u3055\u308c\u305f SMB\/CIFS \u30c9\u30e9\u30a4\u30d6\u306b\u611f\u67d3\u3059\u308b\u305f\u3081\u3001\u6307\u5b9a\u3055\u308c\u305f\u69cb\u6210\u3092\u7e70\u308a\u8fd4\u3057\u51e6\u7406\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u8a66\u307f\u306f\u3001\u6a19\u6e96\u51fa\u529b (STDOUT) \u306b\u66f8\u304d\u8fbc\u307e\u308c\u308b\u3055\u307e\u3056\u307e\u306a\u51fa\u529b\u5185\u5bb9\u304b\u3089\u5927\u307e\u304b\u306b\u63b4\u3081\u307e\u3059\u3002\u305d\u306e\u4f8b\u3092\u4ee5\u4e0b\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p>(\u6ce8: \u4ee5\u4e0b\u306e\u51fa\u529b\u3067\u306f\u3001\u5b9f\u969b\u306e IP \u30a2\u30c9\u30ec\u30b9\u3068\u5171\u6709\u540d\u3092\u4f0f\u305b\u3066\u3042\u308a\u307e\u3059\u3002)<\/p>\n<p><!-- Crayon Syntax Highlighter v_2.7.2_beta --><\/p>\n<pre class=\"lang:default decode:true\">05:21:40 [INFO] Loading Config\r\n05:21:40 [INFO] Initializing System\r\n05:21:40 [INFO] Initializing Array\r\n05:21:40 [INFO] Pass #1\r\n05:21:40 [INFO] Executing tasks\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Encode Shares [IP \u30a2\u30c9\u30ec\u30b9] -&gt; [\u5171\u6709\u306e\u30d1\u30b9]\r\n05:21:40 [INFO] Scanning [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Encode Shares [IP \u30a2\u30c9\u30ec\u30b9] -&gt; [\u5171\u6709\u306e\u30d1\u30b9]\r\n05:21:40 [INFO] Scanning [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Encode Shares [IP \u30a2\u30c9\u30ec\u30b9] -&gt; [\u5171\u6709\u306e\u30d1\u30b9]\r\n05:21:40 [INFO] Scanning [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n[\u7701\u7565]\r\n05:21:40 [INFO] Pass #2\r\n05:21:40 [INFO] Executing tasks\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Encode Shares [IP \u30a2\u30c9\u30ec\u30b9] -&gt; [\u5171\u6709\u306e\u30d1\u30b9]\r\n05:21:40 [INFO] Scanning [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Encode Shares [IP \u30a2\u30c9\u30ec\u30b9] -&gt; [\u5171\u6709\u306e\u30d1\u30b9]\r\n05:21:40 [INFO] Scanning [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Task [IP \u30a2\u30c9\u30ec\u30b9]\r\n05:21:40 [INFO] Encode Shares [IP \u30a2\u30c9\u30ec\u30b9] -&gt; [\u5171\u6709\u306e\u30d1\u30b9]\r\n[\u7701\u7565]\r\n05:21:40 [INFO] Done!<\/pre>\n<p><!-- [Format Time: 0.0025 seconds] --><\/p>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u304c\u5b8c\u5168\u306b\u884c\u308f\u308c\u305f\u5f8c\u3067 VM \u306e\u96fb\u6e90\u306f\u30aa\u30d5\u306b\u306a\u308a\u3001\u305d\u308c\u4ee5\u4e0a\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u306f\u5b9f\u884c\u3055\u308c\u307e\u305b\u3093\u3002<\/p>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30b5\u30f3\u30d7\u30eb\u306b\u306f\u6b21\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u57cb\u3081\u8fbc\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u4f7f\u308f\u308c\u3066\u306f\u3044\u307e\u305b\u3093\u304c\u3001\u304a\u305d\u3089\u304f\u958b\u767a\u306e\u7279\u5b9a\u6bb5\u968e\u3067\u7d44\u307f\u8fbc\u307e\u308c\u3001\u305d\u306e\u5f8c\u4f7f\u308f\u308c\u306a\u304f\u306a\u3063\u305f\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002<\/p>\n<p><!-- Crayon Syntax Highlighter v_2.7.2_beta --><\/p>\n<pre class=\"lang:default decode:true\">ATTENTION:\r\n    At the time there is NO CONFIG ENCRYPTION, meaning chat access token is NOT ENCRYPTED in the ISO.\r\n    Leaking the ISO will result in chat access token leak!\r\n    It's highly recommended to EJECT and DELETE the ISO right after system boot.\r\n    DO NOT LEAVE THE ISO ON TARGET SYSTEMS!\r\n\r\nUsage:\r\n    Controller is launched at boot time in tmux session named \"controller\".\r\n    It will execute all the tasks and exit.\r\n    If you've set \"shutdown\" option at config time it will also shutdown the machine after finishing tasks.\r\n    If \"shutdown\" option is not set you can relaunch Controller by running \"\/app\/controller\".\r\n\r\nMonitoring:\r\n    Monitor progress by running \"tmux a\" with either terminal or ssh connection.\r\n<\/pre>\n<p><!-- [Format Time: 0.0007 seconds] --><\/p>\n<p>\u3053\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u3001BlackCat \u306e\u4f5c\u6210\u8005\u304b\u3089\u305d\u306e\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u306b\u5411\u3051\u3001\u4fb5\u5bb3\u3057\u305f\u74b0\u5883\u304b\u3089\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3059\u308b\u3088\u3046\u306b\u4fc3\u3057\u3066\u3044\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u305f\u3060\u3001\u304f\u3060\u3093\u306e\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u306f\u3053\u306e\u30a2\u30c9\u30d0\u30a4\u30b9\u306b\u8033\u3092\u50be\u3051\u306a\u304b\u3063\u305f\u3088\u3046\u3067\u3059\u3002<\/p>\n<h2><a id=\"post-130700-_2an8ryq91inv\"><\/a>\u7d50\u8ad6<\/h2>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u4f5c\u6210\u8005\u3001\u3068\u304f\u306b BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u8105\u5a01\u306e\u80cc\u5f8c\u306b\u3044\u308b\u30a2\u30af\u30bf\u30fc\u306f\u3001\u305d\u306e\u6280\u8853\u3068\u6226\u8853\u3092\u7e70\u308a\u8fd4\u3057\u9032\u5316\u3055\u305b\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u3053\u3068\u306f\u3001\u5f7c\u3089\u304c\u958b\u767a\u3057\u3066\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u306b\u63d0\u4f9b\u3057\u305f Munchkin \u306e\u6700\u8fd1\u306e\u30ea\u30ea\u30fc\u30b9\u304b\u3089\u3082\u5b8c\u5168\u306b\u660e\u3089\u304b\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e\u30c4\u30fc\u30eb\u306f\u3001VM \u3092\u6d3b\u7528\u3057\u3066\u30db\u30b9\u30c8\u4e0a\u306b\u3042\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u59a8\u5bb3\u3057\u3001\u3053\u306e\u7a2e\u306e\u8105\u5a01\u306b\u5bfe\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b3\u30df\u30e5\u30cb\u30c6\u30a3\u306e\u9632\u5fa1\u3092\u51fa\u3057\u629c\u304f\u3001\u3068\u3044\u3046\u3053\u3053\u306e\u3068\u3053\u308d\u306e\u30c8\u30ec\u30f3\u30c9\u306b\u5023\u3046\u3082\u306e\u3067\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u4ee5\u4e0b\u306e\u88fd\u54c1\u3092\u901a\u3058\u3066\u3001\u4e0a\u8a18\u306e\u8105\u5a01\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/docs.paloaltonetworks.com\/wildfire\" target=\"_blank\" rel=\"noopener\">WildFire<\/a>\u306a\u3069<a href=\"https:\/\/docs.paloaltonetworks.com\/cdss\" target=\"_blank\" rel=\"noopener\">\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9<\/a>\u3092\u6709\u52b9\u306b\u3057\u305f<a href=\"https:\/\/docs.paloaltonetworks.com\/ngfw\" target=\"_blank\" rel=\"noopener\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/a>\u306f\u672c\u7a3f\u3067\u89e3\u8aac\u3057\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u60aa\u610f\u306e\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u691c\u51fa\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>\u4fb5\u5bb3\u306e\u61f8\u5ff5\u304c\u3042\u308a\u5f0a\u793e\u306b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u95a2\u3059\u308b\u3054\u76f8\u8ac7\u3092\u306a\u3055\u308a\u305f\u3044\u5834\u5408\u306f\u3001<a href=\"https:\/\/start.paloaltonetworks.jp\/contact-unit42.html\">\u3053\u3061\u3089\u306e\u30d5\u30a9\u30fc\u30e0<\/a>\u304b\u3089\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001infojapan@paloaltonetworks.com\u307e\u3067\u30e1\u30fc\u30eb\u306b\u3066\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001\u4e0b\u8a18\u306e\u96fb\u8a71\u756a\u53f7\u307e\u3067\u304a\u554f\u3044\u5408\u308f\u305b\u304f\u3060\u3055\u3044(\u3054\u76f8\u8ac7\u306f\u5f0a\u793e\u88fd\u54c1\u306e\u304a\u5ba2\u69d8\u306b\u306f\u9650\u5b9a\u3055\u308c\u307e\u305b\u3093)\u3002<\/p>\n<ul>\n<li>\u5317\u7c73\u30d5\u30ea\u30fc\u30c0\u30a4\u30e4\u30eb\uff1a866.486.4842 (866.4.UNIT42)<\/li>\n<li>EMEA: +31.20.299.3130<\/li>\n<li>APAC: +65.6983.8730<\/li>\n<li>\u65e5\u672c: (+81) 50-1790-0200<\/li>\n<\/ul>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u3001\u30d5\u30a1\u30a4\u30eb \u30b5\u30f3\u30d7\u30eb\u3084 IoC (\u4fb5\u5bb3\u6307\u6a19) \u3092\u3075\u304f\u3080\u8abf\u67fb\u7d50\u679c\u3092 Cyber Threat Alliance (CTA: \u30b5\u30a4\u30d0\u30fc\u8105\u5a01\u30a2\u30e9\u30a4\u30a2\u30f3\u30b9) \u306e\u30e1\u30f3\u30d0\u30fc\u3068\u5171\u6709\u3057\u307e\u3057\u305f\u3002CTA \u306e\u30e1\u30f3\u30d0\u30fc\u306f\u3053\u306e\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u3063\u3066\u3001\u304a\u5ba2\u69d8\u306b\u4fdd\u8b77\u3092\u8fc5\u901f\u306b\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u3092\u4f53\u7cfb\u7684\u306b\u963b\u5bb3\u3067\u304d\u307e\u3059\u3002\u8a73\u7d30\u306f <a href=\"https:\/\/www.cyberthreatalliance.org\">Cyber Threat Alliance<\/a> \u306b\u3066\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\uff61<\/p>\n<h2><a id=\"post-130700-_v8176g40kstn\"><\/a>IoC (\u4fb5\u5bb3\u6307\u6a19)<\/h2>\n<h3><a id=\"post-130700-_763h15eckspk\"><\/a>\/app\/controller - Munchkin \u30d0\u30a4\u30ca\u30ea\u30fc<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1a4082c161eafde7e367e0ea2c98543c06dce667b547881455d1984037a90e7d<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-130700-_t0vobferidaf\"><\/a>\/app\/payload - BlackCat \u30b9\u30bf\u30d6<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-130700-_d35przqffglx\"><\/a>\/scripts\/smb_common.py - Python \u306e SMB \u30af\u30e9\u30b9<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">41c0b2258c632ee122fb52bf2f644c7fb595a5beaec71527e2ebce7183644db2<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-130700-_7dgwriywxp9f\"><\/a>\/scripts\/smb_copy_and_exec.py - Python \u306e SMB \u30b3\u30d4\u30fc\/\u5b9f\u884c \u30b9\u30af\u30ea\u30d7\u30c8<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2e808fc1b2bd960909385575fa9227928ca25c8665d3ce5ad986b03679dace90<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-130700-_mupgtdj2avay\"><\/a>\/app\/payload - BlackCat \u30b9\u30bf\u30d6<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-130700-_rxguwpij0wtc\"><\/a>YARA \u30eb\u30fc\u30eb<\/h3>\n<p><!-- Crayon Syntax Highlighter v_2.7.2_beta --><\/p>\n<pre class=\"lang:default decode:true\">rule u42_crime_nix_munchkin\r\n{\r\n    meta:\r\n        author = \"Unit 42 Threat Intelligence\"\r\n        date = \"2023-10-12\"\r\n        description = \"Identifies a scanning utility leveraged by the BlackCat operators that is used to propagate the malware payload to additional hosts via SMB.\"\r\n        hash = \"1a4082c161eafde7e367e0ea2c98543c06dce667b547881455d1984037a90e7d\"\r\n        reference = \"https:\/\/unit42.paloaltonetworks.com\/blackcat-ransomware\/\"\r\n\r\n    strings:\r\n        $str0 = \"At the time there is NO CONFIG ENCRYPTION, meaning chat access token is NOT ENCRYPTED in the ISO.\" xor(1-255)\r\n        $str1 = \"Leaking the ISO will result in chat access token leak!\" xor(1-255)\r\n        $str2 = \"It's highly recommended to EJECT and DELETE the ISO right after system boot.\" xor(1-255)\r\n        $str3 = \"DO NOT LEAVE THE ISO ON TARGET SYSTEMS!\" xor(1-255)\r\n        $str4 = \"Controller is launched at boot time in tmux session named \\\"controller\\\".\" xor(1-255)\r\n        $str5 = \"It will execute all the tasks and exit.\" xor(1-255)\r\n        $str6 = \"If you've set \\\"shutdown\\\" option at config time it will also shutdown the machine after finishing tasks.\" xor(1-255)\r\n        $str7 = \"If \\\"shutdown\\\" option is not set you can relaunch Controller by running \\\"\/app\/controller\" xor(1-255)\r\n        $str8 = \"Monitor progress by running \\\"tmux a\\\" with either terminal or ssh connection\" xor(1-255)\r\n        $str9 = \"controller::smb\" xor(1-255)\r\n        $str10 = \": Failed, either no credentials or no ADMIN$ share found\" xor(1-255)\r\n        $str11 = \"bin\/controller\/src\/program.rs\" xor(1-255)\r\n        $str12 = \"\/scripts\/smb_exec.py\" xor(1-255)\r\n        $str13 = \"No payload configs provided!\" xor(1-255)\r\n        $str14 = \"Can't deserialize config\" xor(1-255)\r\n        $str15 = \"controller::program\" xor(1-255)\r\n\r\n    condition:\r\n        any of them\r\n}\r\n<\/pre>\n<p><!-- [Format Time: 0.0017 seconds] --><\/p>\n<p><!-- Crayon Syntax Highlighter v_2.7.2_beta --><\/p>\n<pre class=\"lang:default decode:true\">rule u42_crime_win_blackcat\r\n{\r\n    meta:\r\n        author = \"Unit 42 Threat Intelligence\"\r\n        date = \"2023-10-12\"\r\n        description = \"Identifies the BlackCat ransomware malware family, which is written in the Rust programming language.\"\r\n        hash = \"b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2\"\r\n        reference = \"https:\/\/unit42.paloaltonetworks.com\/blackcat-ransomware\/\"\r\n\r\n    strings:\r\n        $str0 = \"paths_file\" xor(1-255)\r\n        $str1 = \"override_credentials\" xor(1-255)\r\n        $str2 = \"disable_recursion\" xor(1-255)\r\n        $str3 = \"disable_network\" xor(1-255)\r\n        $str4 = \"disable_elevate_to_system\" xor(1-255)\r\n        $str5 = \"disable_self_propagation\" xor(1-255)\r\n        $str6 = \"self_destruct\" xor(1-255)\r\n        $str7 = \"The following required argument was not provided: Path to resource to be processed.\" xor(1-255)\r\n        $str8 = \"Resource is one of:\" xor(1-255)\r\n        $str9 = \"Path to local or remote File\" xor(1-255)\r\n        $str10 = \"Path to local or remote Directory\" xor(1-255)\r\n        $str11 = \"Path to remote server, i.e. \\\"\\\\10.0.0.1\\\"\" xor(1-255)\r\n        $str12 = \"If no paths provided:\" xor(1-255)\r\n        $str13 = \"A full scan in all available resources will be performed.\" xor(1-255)\r\n        $str14 = \"(you can provide multiple, single or no paths, i.e.: \\\"-p \/home -p \/opt\\\")\" xor(1-255)\r\n        $str15 = \"Override config credentials:\\n\\nFormat:\\n\\nusername:password\\n\\n\" xor(1-255)\r\n        $str16 = \"If Resource is a directory and this option is defined, only direct children of that directory will be processed\" xor(1-255)\r\n        $str17 = \"disable-recursion\" xor(1-255)\r\n        $str18 = \"DISABLE_NETWORK\" xor(1-255)\r\n        $str19 = \"Disable automatic network discovery\" xor(1-255)\r\n        $str20 = \"disable-network\" xor(1-255)\r\n        $str21 = \"DISABLE_ELEVATE_TO_SYSTEM\" xor(1-255)\r\n        $str22 = \"Do not attempt to elevalte access token to system\" xor(1-255)\r\n        $str23 = \"disable-elevate-to-system\" xor(1-255)\r\n        $str24 = \"DISABLE_SELF_PROPAGATION\" xor(1-255)\r\n        $str25 = \"Disable network self propagation\" xor(1-255)\r\n        $str26 = \"Network propagation is disabled by default in case you provided &lt;\" xor(1-255)\r\n        $str27 = \"Attach to parent console instead of allocating new one\" xor(1-255)\r\n        $str28 = \"If no command provided an interactive client will be launched, otherwise client will send provided command and exit.\" xor(1-255)\r\n\r\n    condition:\r\n        3 of them\r\n}\r\n<\/pre>\n<h2><a id=\"post-130700-_570cbe1pdhwx\"><\/a>\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9<\/h2>\n<ul>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/blackcat-ransomware\/\" target=\"_blank\" rel=\"noopener\">\u8105\u5a01\u306e\u8a55\u4fa1: BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2<\/a> \u2013 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9 Unit 42<\/li>\n<li><a href=\"https:\/\/securityintelligence.com\/posts\/blackcat-ransomware-levels-up-stealth-speed-exfiltration\/\" target=\"_blank\" rel=\"noopener\">BlackCat (ALPHV) ransomware levels up for stealth, speed and exfiltration<\/a> \u2013 IBM X-Force<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7 BlackCat \u306e\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u306f\u6700\u8fd1\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306e\u30c4\u30fc\u30eb\u66f4\u65b0\u306b\u3064\u3044\u3066\u30a2\u30ca\u30a6\u30f3\u30b9\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u306a\u304b\u306b\u306f\u3001BlackCat \u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8 \u30de\u30b7\u30f3\u3084\u88ab\u5bb3\u7d44\u7e54\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5171\u6709\u306b\u62e1\u6563<\/p>\n","protected":false},"author":23,"featured_media":134364,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4434,3057,4428],"tags":[4601,4708,4605],"product_categories":[4444,4446,4456,4465],"coauthors":[1025],"class_list":["post-130700","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybercrime-ja","category-ransomware-ja","category-threat-research-ja","tag-alphv-ja","tag-ambitious-scorpius","tag-blackcat-ransomware-ja","product_categories-advanced-wildfire-ja","product_categories-cloud-delivered-security-services-ja","product_categories-next-generation-firewall-ja","product_categories-unit-42-incident-response-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f<\/title>\n<meta name=\"description\" content=\"BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c Munchkin \u3068\u3044\u3046\u30c4\u30fc\u30eb\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30c4\u30fc\u30eb\u3092\u4f7f\u3048\u3070\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8\u306e\u30de\u30b7\u30f3\u306b\u62e1\u6563\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u30c4\u30fc\u30eb\u3092\u5206\u6790\u3057\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f\" \/>\n<meta property=\"og:description\" content=\"BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c Munchkin \u3068\u3044\u3046\u30c4\u30fc\u30eb\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30c4\u30fc\u30eb\u3092\u4f7f\u3048\u3070\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8\u306e\u30de\u30b7\u30f3\u306b\u62e1\u6563\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u30c4\u30fc\u30eb\u3092\u5206\u6790\u3057\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-18T13:00:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-20T06:22:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Ransomware_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Unit 42\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f","description":"BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c Munchkin \u3068\u3044\u3046\u30c4\u30fc\u30eb\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30c4\u30fc\u30eb\u3092\u4f7f\u3048\u3070\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8\u306e\u30de\u30b7\u30f3\u306b\u62e1\u6563\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u30c4\u30fc\u30eb\u3092\u5206\u6790\u3057\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/","og_locale":"ja_JP","og_type":"article","og_title":"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f","og_description":"BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c Munchkin \u3068\u3044\u3046\u30c4\u30fc\u30eb\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30c4\u30fc\u30eb\u3092\u4f7f\u3048\u3070\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8\u306e\u30de\u30b7\u30f3\u306b\u62e1\u6563\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u30c4\u30fc\u30eb\u3092\u5206\u6790\u3057\u307e\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/","og_site_name":"Unit 42","article_published_time":"2023-10-18T13:00:17+00:00","article_modified_time":"2024-06-20T06:22:59+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Ransomware_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Unit 42","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/"},"author":{"name":"Unit 42","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"headline":"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f","datePublished":"2023-10-18T13:00:17+00:00","dateModified":"2024-06-20T06:22:59+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/"},"wordCount":425,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Ransomware_Category_1920x900.jpg","keywords":["ALPHV","Ambitious Scorpius","BlackCat ransomware"],"articleSection":["\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a","\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/","name":"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Ransomware_Category_1920x900.jpg","datePublished":"2023-10-18T13:00:17+00:00","dateModified":"2024-06-20T06:22:59+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"description":"BlackCat \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c Munchkin \u3068\u3044\u3046\u30c4\u30fc\u30eb\u3092\u516c\u958b\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30c4\u30fc\u30eb\u3092\u4f7f\u3048\u3070\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30ea\u30e2\u30fc\u30c8\u306e\u30de\u30b7\u30f3\u306b\u62e1\u6563\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u30c4\u30fc\u30eb\u3092\u5206\u6790\u3057\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Ransomware_Category_1920x900.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Ransomware_Category_1920x900.jpg","width":1920,"height":900,"caption":"A digital illustration of a laptop with cybersecurity imagery including a padlock hologram, surrounded by stacks of coins and a credit card, emphasizing financial security. The setting is illuminated in blue, pink, and purple tones."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/blackcat-ransomware-releases-new-utility-munchkin\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"BlackCat \u306b\u65b0\u305f\u306a\u6226\u8853: VM \u3068 Alpine Linux \u306e\u63a1\u7528\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u56de\u907f"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63","name":"Unit 42","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Unit 42"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/unit42\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/130700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=130700"}],"version-history":[{"count":9,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/130700\/revisions"}],"predecessor-version":[{"id":135169,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/130700\/revisions\/135169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134364"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=130700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=130700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=130700"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=130700"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=130700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}