{"id":131342,"date":"2023-11-21T06:00:06","date_gmt":"2023-11-21T14:00:06","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=131342"},"modified":"2024-06-17T01:44:43","modified_gmt":"2024-06-17T08:44:43","slug":"two-campaigns-by-north-korea-bad-actors-target-job-hunters","status":"publish","type":"post","link":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/","title":{"rendered":"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3"},"content":{"rendered":"<h2><a id=\"post-131342-_4lt92rr5muov\"><\/a><strong>\u6982\u8981<\/strong><\/h2>\n<p>Unit 42 \u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u6700\u8fd1\u3001\u5317\u671d\u9bae (\u671d\u9bae\u6c11\u4e3b\u4e3b\u7fa9\u4eba\u6c11\u5171\u548c\u56fd DPRK) \u306b\u7d10\u3065\u304f\u56fd\u5bb6\u652f\u63f4\u578b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u95a2\u4e0e\u3057\u305f\u3001\u6c42\u8077\u6d3b\u52d5\u3092\u6a19\u7684\u3068\u3059\u308b 2 \u3064\u306e\u5225\u3005\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f 1 \u3064\u3081\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cContagious Interview (\u611f\u67d3\u9762\u63a5) \u300d\u3068\u547c\u3093\u3067\u3044\u307e\u3059\u3002\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c (\u591a\u304f\u306e\u5834\u5408\u533f\u540d\u307e\u305f\u306f\u66d6\u6627\u306a\u8eab\u5143\u3067) \u96c7\u7528\u8005\u3092\u88c5\u3044\u3001\u9762\u63a5\u904e\u7a0b\u3067\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u306b\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3088\u3046\u306b\u3057\u3080\u3051\u307e\u3059\u3002\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u3055\u307e\u3056\u307e\u306a\u7a2e\u985e\u306e\u7a83\u53d6\u306e\u53ef\u80fd\u6027\u3092\u751f\u307f\u51fa\u3057\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3001Contagious Interview \u304c\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u3088\u308a\u904b\u55b6\u3055\u308c\u3066\u3044\u308b\u3068\u3001\u4e2d\u7a0b\u5ea6\u306e\u78ba\u5ea6\u3067\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8 (\u5e30\u5c5e) \u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u79c1\u305f\u3061\u306f\u30012 \u3064\u3081\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cWagemole (\u8cc3\u91d1+\u30b9\u30d1\u30a4)\u300d\u3068\u547c\u3093\u3067\u3044\u307e\u3059\u3002\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u7c73\u56fd\u3084\u305d\u306e\u307b\u304b\u306e\u5730\u57df\u3092\u62e0\u70b9\u3068\u3059\u308b\u7d44\u7e54\u3067\u306e\u96c7\u7528\u3092\u4e0d\u6b63\u306b\u6c42\u3081\u308b\u3082\u306e\u3067\u3001\u91d1\u92ad\u7684\u5229\u76ca\u3068\u30b9\u30d1\u30a4\u6d3b\u52d5\u306e\u4e21\u65b9\u3092\u72d9\u3046\u3082\u306e\u3067\u3059\u3002\u79c1\u305f\u3061\u306f\u3001Wagemole \u304c\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b\u8105\u5a01\u3067\u3042\u308b\u3068\u3001\u9ad8\u3044\u78ba\u5ea6\u3067\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002\u4e21\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304b\u3089\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u3001\u4eca\u73fe\u5728\u3082\u6d3b\u767a\u306a\u8105\u5a01\u3067\u3059\u3002<\/p>\n<p><iframe loading=\"lazy\" width=\"400\" height=\"711\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" allowfullscreen=\"allowfullscreen\" frameborder=\"0\" src=\"\/\/www.youtube.com\/embed\/Pwk8G3i0PTk\" title=\"\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3 #APT #BeaverTail #cyber\"><\/iframe><\/p>\n<p>\u67b6\u7a7a\u306e\u9762\u63a5\u3092\u901a\u3058\u3066\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u611f\u67d3\u3055\u305b\u3088\u3046\u3068\u3059\u308b\u3053\u3068\u304b\u3089\u3001\u79c1\u305f\u3061\u306f\u6700\u521d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cContagious Interview (\u611f\u67d3\u9762\u63a5)\u300d\u3068\u540d\u4ed8\u3051\u307e\u3057\u305f\u3002\u3082\u3068\u3082\u3068\u79c1\u305f\u3061\u306f\u3001\u9867\u5ba2\u74b0\u5883\u304b\u3089\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u3067 Contagious Interview \u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306e\u8abf\u67fb\u306b\u3088\u308c\u3070\u3001 Contagious Interview \u306f\u5c11\u306a\u304f\u3068\u3082 2022 \u5e74 12 \u6708\u306b\u306f\u59cb\u307e\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u652f\u3048\u308b\u30a4\u30f3\u30d5\u30e9\u306e\u4e00\u90e8\u306f\u4eca\u3082\u30a2\u30af\u30c6\u30a3\u30d6\u3067\u3001\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u4e00\u8cab\u3057\u3066\u8105\u5a01\u3067\u3042\u308a\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002\u6700\u521d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u76ee\u7684\u306f\u3001\u6697\u53f7\u901a\u8ca8\u306e\u7a83\u53d6\u3068\u3001\u4fb5\u5bb3\u3057\u305f\u6a19\u7684\u3092\u8ffd\u52a0\u653b\u6483\u7528\u306e\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883\u3068\u3057\u3066\u5229\u7528\u3059\u308b\u3053\u3068\u3060\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u79c1\u305f\u3061\u306f Contagious Interview \u3092 CL-STA-0240 \u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Contagious Interview \u306e\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u30fc (\u6307\u6a19) \u3092\u8ef8\u306b\u3001\u79c1\u305f\u3061\u306f\u5225\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u7ba1\u7406\u3059\u308b\u30a4\u30f3\u30d5\u30e9\u4e0a\u306b\u9732\u51fa\u3057\u3066\u3044\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u591a\u7a2e\u591a\u69d8\u306a\u7c73\u56fd (US) \u4f01\u696d\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u3068\u3059\u308b\u4e0d\u6b63\u306a\u6c42\u8077\u6d3b\u52d5\u3092\u793a\u3059\u3082\u306e\u3067\u3001\u3055\u307e\u3056\u307e\u306a\u6280\u8853\u30b9\u30ad\u30eb\u306e\u5c65\u6b74\u66f8\u3068\u3001\u3044\u308d\u3044\u308d\u306a\u56fd\u306e\u4eba\u7269\u306b\u306a\u308a\u3059\u307e\u3057\u305f\u8907\u6570\u306e\u8eab\u5206\u8a3c\u306e\u307b\u304b\u3001\u4e00\u822c\u7684\u306a\u9762\u63a5\u306e\u554f\u7b54\u96c6\u3001\u9762\u63a5\u7528\u306e\u53f0\u672c\u3001\u7c73\u56fd\u4f01\u696d\u306e\u6c42\u4eba\u60c5\u5831\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u3082\u306e\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u3053\u3061\u3089\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cWagemole (\u8cc3\u91d1\u30b9\u30d1\u30a4)\u300d\u3068\u547c\u3073\u3001CL-STA-0241\u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u76ee\u7684\u3092\u65ad\u5b9a\u3059\u308b\u3053\u3068\u306f\u3067\u304d\u307e\u305b\u3093\u304c\u3001\u7c73\u53f8\u6cd5\u7701\u3068\u9023\u90a6\u635c\u67fb\u5c40 (FBI) \u306f\u3001\u5317\u671d\u9bae\u304c<a href=\"https:\/\/www.state.gov\/guidance-on-the-democratic-peoples-republic-of-korea-information-technology-workers\/\" target=\"_blank\" rel=\"noopener\">\u30ea\u30e2\u30fc\u30c8\u30ef\u30fc\u30ab\u30fc\u3092\u4f7f\u3063\u3066\u8cc3\u91d1\u3092\u5175\u5668\u30d7\u30ed\u30b0\u30e9\u30e0\u306b\u6d41\u7528<\/a>\u3057\u3066\u3044\u308b\u3068\u5831\u544a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Contagious Interview \u306e\u8abf\u67fb\u4e2d\u3001\u79c1\u305f\u3061\u306f 2 \u3064\u306e\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u3092\u767a\u898b\u3057\u3001\u3053\u308c\u3089\u3092 BeaverTail\u3001InvisibleFerret \u3068\u540d\u4ed8\u3051\u307e\u3057\u305f\u3002BeaverTail \u306f\u3001Node Package Manager<a href=\"https:\/\/docs.npmjs.com\/about-npm\" target=\"_blank\" rel=\"noopener\"> (NPM<\/a>) \u30d1\u30c3\u30b1\u30fc\u30b8\u5185\u306b\u96a0\u3055\u308c\u305f JavaScript \u30d9\u30fc\u30b9\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3059\u3002InvisibleFerret \u306f\u30b7\u30f3\u30d7\u30eb\u3067\u3059\u304c\u5f37\u529b\u306a Python \u30d9\u30fc\u30b9\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3059\u3002\u3069\u3061\u3089\u3082 Windows\u3001Linux\u3001macOS \u4e0a\u3067\u52d5\u4f5c\u3059\u308b\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u578b\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3059\u3002<\/p>\n<p>\u672c\u7a3f\u3067\u306f\u3001\u3053\u308c\u3089 2 \u3064\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u6982\u8981\u3092\u8aac\u660e\u3057\u3001 2 \u3064\u306e\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u3001BeaverTail \u3068 InvisibleFerret \u3092\u691c\u8a3c\u3057\u307e\u3059\u3002<\/p>\n<p>\u672c\u7a3f\u306f\u307e\u305f\u3001\u3053\u308c\u3089\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u81ea\u3089\u306e\u76ee\u7684\u9054\u6210\u306e\u305f\u3081\u306b\u3001\u3069\u306e\u3088\u3046\u306b\u5c31\u8077\u6d3b\u52d5\u3092\u884c\u3044\u3001\u540c\u6642\u306b\u6c42\u8077\u8005\u3089\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u3057\u3066\u3044\u308b\u304b\u306b\u3064\u3044\u3066\u306e\u6d1e\u5bdf\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u4ee5\u4e0b\u3001\u30ea\u30e2\u30fc\u30c8\u30ef\u30fc\u30af\u306e\u9762\u63a5\u3084\u5fdc\u52df\u306b\u3055\u3044\u3057\u3001\u6c42\u8077\u8005\u3001\u96c7\u7528\u8005\u306e\u53cc\u65b9\u304c\u8003\u616e\u3059\u3079\u304d\u63a8\u5968\u4e8b\u9805\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/p>\n<p>\u4f8b:<\/p>\n<ul>\n<li>\u4f1a\u793e\u652f\u7d66\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u3092\u500b\u4eba\u306e\u6d3b\u52d5\u306b\u4f7f\u308f\u306a\u3044\u3088\u3046\u306b\u3057\u307e\u3057\u3087\u3046\u3002<\/li>\n<li>\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u6570\u3084\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306e\u5c11\u306a\u3044 GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u306b\u306f\u7528\u5fc3\u3057\u307e\u3057\u3087\u3046\u3002<\/li>\n<li>\u5fdc\u52df\u5148\u4f01\u696d\u304c\u6b63\u898f\u306e\u4f01\u696d\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046\u3002<\/li>\n<li>\u6c42\u8077\u8005\u306e\u8eab\u5143\u3092\u5fb9\u5e95\u7684\u306b\u8abf\u67fb\u3057\u307e\u3057\u3087\u3046\u3002<\/li>\n<\/ul>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-wildfire\" target=\"_blank\" rel=\"noopener\">Advanced WildFire<\/a>\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/dns-security\" target=\"_blank\" rel=\"noopener\">DNS Security<\/a>\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\">Advanced URL Filtering<\/a> \u306a\u3069\u306e<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/security-subscriptions\" target=\"_blank\" rel=\"noopener\">\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9<\/a>\u3092\u6709\u52b9\u306b\u3057\u305f<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/next-generation-firewall\" target=\"_blank\" rel=\"noopener\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb (NGFW) <\/a> \u306b\u3088\u308a\u3001\u672c\u7a3f\u3067\u53d6\u308a\u4e0a\u3052\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u304b\u3089\u306e\u4fdd\u8b77\u3092\u53d7\u3051\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<td style=\"width: 35%;\"><b>\u95a2\u9023\u3059\u308b Unit 42 \u306e\u30c8\u30d4\u30c3\u30af<\/b><\/td>\n<td style=\"width: 100%;\"><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/apt-ja\/\" target=\"_blank\" rel=\"noopener\"><strong>APT<\/strong><\/a>, <strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/contagious-interview-ja\/\" target=\"_blank\" rel=\"noopener\">Contagious Interview<\/a><\/strong>, <strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/dprk-ja\/\" target=\"_blank\" rel=\"noopener\">DPRK<\/a><\/strong>,\u00a0<strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/north-korea-ja\/\" target=\"_blank\" rel=\"noopener\">North Korea<\/a><\/strong>, <strong><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/wagemole-ja\/\" target=\"_blank\" rel=\"noopener\">Wagemole<\/a>, <a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/invisible-ferret-ja\/\" target=\"_blank\" rel=\"noopener\">Invisible Ferret<\/a>, <a href=\"https:\/\/unit42.paloaltonetworks.jp\/tag\/beavertail-ja\/\" target=\"_blank\" rel=\"noopener\"><b>BeaverTail<\/b><\/a><\/strong><\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<h2><a id=\"post-131342-_jr9et22gfvw6\"><\/a><strong>CL-STA-0240: Contagious Interview (\u611f\u67d3\u9762\u63a5)<\/strong><\/h2>\n<p>\u81ea\u793e\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u3092\u8abf\u67fb\u4e2d\u3001\u79c1\u305f\u3061\u306f\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u3066\u3044\u306a\u304b\u3063\u305f\u30de\u30eb\u30a6\u30a7\u30a2 \u30b5\u30f3\u30d7\u30eb\u306b\u95a2\u308f\u308b\u4e0d\u5be9\u306a\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u306f 2023 \u5e74 3 \u6708\u6642\u70b9\u306b\u306f\u3059\u3067\u306b\u30a2\u30af\u30c6\u30a3\u30d6\u3067\u3001\u305d\u306e\u5f8c\u306e\u8abf\u67fb\u304b\u3089 2 \u3064\u306e\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u304c\u767a\u898b\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u308f\u308c\u305f\u624b\u53e3\u306f\u3001<a href=\"#post-131342-_xkx0jjh1l9jy\">\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30b7\u30e7\u30f3 (\u5e30\u5c5e) \u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u3082\u8ff0\u3079\u3066\u3044\u308b\u901a\u308a<\/a>\u3001\u4ee5\u524d\u306b\u5831\u544a\u3055\u308c\u305f\u5317\u671d\u9bae\u7cfb\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u3088\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u5408\u81f4\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cContagious Interview (CL-STA-0240)\u300d\u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002\u540c\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u30a4\u30f3\u30d5\u30e9\u306f 2022 \u5e74 12 \u6708\u6642\u70b9\u3067\u3059\u3067\u306b\u78ba\u7acb\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>CL-STA-0240 \u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3001\u6c42\u8077\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u4e0a\u306e\u5e83\u544a\u3092\u901a\u3058\u3001\u898b\u8fbc\u307f\u96c7\u7528\u8005\u3092\u88c5\u3063\u3066\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u3092\u72d9\u3044\u307e\u3059\u3002\u540c\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u95a2\u9023\u3065\u3051\u3089\u308c\u305f\u5e83\u544a\u306f\u3001\u533f\u540d\u3060\u3063\u305f\u308a\u610f\u56f3\u7684\u306b\u66d6\u6627\u306b\u3057\u3066\u3042\u3063\u305f\u308a\u3059\u308b\u3053\u3068\u304c\u591a\u304f\u3001\u96c7\u7528\u8005\u304c\u8ab0\u306a\u306e\u304b\u3092\u793a\u3059\u6307\u6a19\u304c\u3042\u308a\u307e\u305b\u3093\u3002\u540c\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u95a2\u9023\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306e\u4e00\u90e8\u304b\u3089\u3059\u308b\u3068\u3001\u3053\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3001\u6b63\u898f\u306e AI\u30fb\u6697\u53f7\u901a\u8ca8\u30fbNFT \u95a2\u9023\u4f01\u696d\u3084\u4eba\u6750\u7d39\u4ecb\u4f1a\u793e\u306b\u306a\u308a\u3059\u307e\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u3082\u3042\u308b\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u307b\u304b\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3068\u540c\u69d8\u306b\u3001\u3053\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3082\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u3001\u30bd\u30fc\u30b7\u30e3\u30eb\u30e1\u30c7\u30a3\u30a2 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u304c\u4f7f\u3046\u30b3\u30df\u30e5\u30cb\u30c6\u30a3 \u30d5\u30a9\u30fc\u30e9\u30e0\u306e\u30c1\u30e3\u30c3\u30c8 \u30c1\u30e3\u30f3\u30cd\u30eb\u3092\u901a\u3058\u3001\u6f5c\u5728\u7684\u88ab\u5bb3\u8005\u306b\u63a5\u89e6\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u9023\u7d61\u3092\u53d6\u308a\u5408\u3063\u305f\u5f8c\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u88ab\u5bb3\u8005\u3092\u30aa\u30f3\u30e9\u30a4\u30f3\u9762\u63a5\u306b\u62db\u304d\u307e\u3059\u3002\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3001\u3053\u306e\u9762\u63a5\u306b\u30d3\u30c7\u30aa\u4f1a\u8b70\u3084\u305d\u306e\u307b\u304b\u306e\u30aa\u30f3\u30e9\u30a4\u30f3 \u30b3\u30e9\u30dc\u30ec\u30fc\u30b7\u30e7\u30f3 \u30c4\u30fc\u30eb\u3092\u4f7f\u3046\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002<\/p>\n<p>\u9762\u63a5\u4e2d\u3001\u3053\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u88ab\u5bb3\u8005\u306b GitHub \u3067\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u308b\u3042\u308b <a href=\"https:\/\/docs.npmjs.com\/about-npm\" target=\"_blank\" rel=\"noopener\">NPM \u30d9\u30fc\u30b9<\/a>\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3088\u3046\u8aac\u5f97\u3057\u307e\u3059\u3002\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3053\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30ec\u30d3\u30e5\u30fc\u306a\u3044\u3057\u5206\u6790\u5bfe\u8c61\u306e\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3068\u3057\u3066\u88ab\u5bb3\u8005\u306b\u63d0\u793a\u3057\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u304c\u3001\u5b9f\u969b\u306b\u306f\u88ab\u5bb3\u8005\u306e\u30db\u30b9\u30c8\u3092\u30d0\u30c3\u30af\u30c9\u30a2\u578b\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u611f\u67d3\u3055\u305b\u308b\u305f\u3081\u306e\u60aa\u610f\u306e\u3042\u308b JavaScript \u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u56f3 1 \u306f CL-STA-0240 \u306e\u30a4\u30d9\u30f3\u30c8 \u30c1\u30a7\u30fc\u30f3\u3092\u307e\u3068\u3081\u305f\u3082\u306e\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_132202\" aria-describedby=\"caption-attachment-132202\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.jp\/wp-content\/uploads\/2023\/11\/word-image-131292-1-ja-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-132202 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.jp\/wp-content\/uploads\/2023\/11\/word-image-131292-1-ja-1.png\" alt=\"\u753b\u50cf 1 \u306f CL-STA-0240 \u306e\u653b\u6483\u30c1\u30a7\u30fc\u30f3\u3067\u3059\u3002\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u6f5c\u5728\u7684\u96c7\u7528\u8005\u3092\u88c5\u3044\u307e\u3059\u3002\u88ab\u5bb3\u8005\u306f\u30aa\u30f3\u30e9\u30a4\u30f3\u3067\u5c31\u8077\u9762\u63a5\u3092\u53d7\u3051\u307e\u3059\u3002\u88ab\u5bb3\u8005\u306f GitHub \u304b\u3089\u60aa\u610f\u306e\u3042\u308b npm \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u88ab\u5bb3\u8005\u304c\u60aa\u610f\u306e\u3042\u308b npm \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002npm \u30d1\u30c3\u30b1\u30fc\u30b8\u304c\u30d0\u30c3\u30af\u30c9\u30a2\u578b\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u53d6\u5f97\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002\u30d0\u30c3\u30af\u30c9\u30a2\u578b\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001\u88ab\u5bb3\u8005\u306e\u30db\u30b9\u30c8\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u78ba\u7acb\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"239\" \/><\/a><figcaption id=\"caption-attachment-132202\" class=\"wp-caption-text\">\u56f3 1. CL-STA-0240 \u653b\u6483\u306e\u30a4\u30d9\u30f3\u30c8 \u30c1\u30a7\u30fc\u30f3 (\u5358\u7d14\u5316\u3057\u305f\u3082\u306e)<\/figcaption><\/figure>\n<p>\u3053\u306e\u30a4\u30d9\u30f3\u30c8 \u30c1\u30a7\u30fc\u30f3\u3078\u306e\u7406\u89e3\u3092\u6df1\u3081\u308b\u306b\u306f\u3001\u307e\u305a\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067 GitHub \u3092\u3069\u306e\u3088\u3046\u306b\u60aa\u7528\u3057\u305f\u304b\u3092\u7406\u89e3\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-131342-_xts0yu6b248a\"><\/a>Contagious Interview \u306b\u3088\u308b GitHub \u60aa\u7528<\/h3>\n<p>\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u306e\u305f\u3081\u306e\u30b3\u30e9\u30dc\u30ec\u30fc\u30b7\u30e7\u30f3\u7a7a\u9593\u3068\u3057\u3066\u8a2d\u8a08\u3055\u308c\u305f<a href=\"https:\/\/docs.github.com\/en\/get-started\/quickstart\/hello-world#introduction\" target=\"_blank\" rel=\"noopener\"> GitHub <\/a>\u306f\u3001\u57fa\u672c\u30b5\u30fc\u30d3\u30b9 \u30aa\u30d7\u30b7\u30e7\u30f3\u304c\u7121\u6599\u306a\u306e\u3067\u3001\u591a\u304f\u306e\u958b\u767a\u8005\u306b\u3068\u3063\u3066\u9b45\u529b\u7684\u3067\u3059\u3002\u3053\u308c\u306f\u307e\u305f\u3001 GitHub \u3092\u72af\u7f6a\u8005\u306b\u3068\u3063\u3066\u3082\u9b45\u529b\u7684\u306a\u3082\u306e\u306b\u3057\u3066\u3044\u307e\u3059\u3002Contagious Interview \u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3082\u307e\u305f\u3001 GitHub \u306e\u7121\u6599\u30b5\u30fc\u30d3\u30b9\u30d7\u30e9\u30f3\u3092\u5229\u7528\u3057\u3066\u4e00\u898b\u7121\u5bb3\u306a<a href=\"https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/about-repositories\" target=\"_blank\" rel=\"noopener\">\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc<\/a>\u3092\u30db\u30b9\u30c8\u3057\u3001\u3053\u308c\u3092\u5f37\u529b\u306a\u4fb5\u5bb3\u7528\u30c4\u30fc\u30eb\u3068\u3057\u3066\u4f7f\u3046\u3001\u591a\u304f\u306e\u72af\u7f6a\u8005\u3089\u306e\u3072\u3068\u308a\u3067\u3059\u3002<\/p>\n<p>Contagious Interview \u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3001 \u3055\u307e\u3056\u307e\u306a ID \u3092\u4f5c\u6210\u3057\u3066 GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u3092\u30db\u30b9\u30c8\u3059\u308b\u3053\u3068\u3067\u3001\u5bfe\u8c61\u88ab\u5bb3\u8005\u306e\u4fe1\u983c\u3092\u5f97\u308b\u305f\u3081\u306e\u30a4\u30f3\u30d5\u30e9\u3092\u69cb\u7bc9\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3067\u3059\u304c\u3088\u304f\u8abf\u3079\u3066\u307f\u308b\u3068\u3001\u3053\u308c\u3089\u306e GitHub \u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306f\u5f53\u521d\u306e\u898b\u7acb\u3066\u307b\u3069\u4fe1\u983c\u3067\u304d\u308b\u3082\u306e\u3067\u306f\u306a\u3044\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n<p>Contagious Interview \u304c\u4f7f\u3063\u3066\u3044\u308b\u7121\u6599 GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u306f\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u304c 1 \u3064\u3057\u304b\u306a\u304f\u3001\u305d\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306b\u306f\u66f4\u65b0\u304c\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u8abf\u67fb\u4e2d\u306b\u898b\u3064\u3051\u305f\u4e0d\u5be9\u306a\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u3092\u3055\u3089\u306b\u8abf\u67fb\u3057\u305f\u3068\u3053\u308d\u3001\u6700\u521d\u306e\u8a55\u4fa1\u3092\u8ffd\u8a8d\u3067\u304d\u307e\u3057\u305f\u3002GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306e <a href=\"https:\/\/docs.github.com\/en\/issues\/tracking-your-work-with-issues\/about-issues\" target=\"_blank\" rel=\"noopener\">Issues<\/a> \u30bb\u30af\u30b7\u30e7\u30f3\u304c\u30d2\u30f3\u30c8\u3092\u304f\u308c\u308b\u3053\u3068\u304c\u3088\u304f\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u56f3 2 \u306f\u3001Contagious Interview \u304c\u4f7f\u3063\u3066\u3044\u308b\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306e Issues \u30bb\u30af\u30b7\u30e7\u30f3\u306e\u30b3\u30e1\u30f3\u30c8\u3067\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">react-ecommerce<\/span> \u3068\u3044\u3046\u540d\u524d\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">brainjobs35<\/span> \u3068\u3044\u3046 GitHub \u30e6\u30fc\u30b6\u30fc \u30a2\u30ab\u30a6\u30f3\u30c8\u306b\u3088\u3063\u3066\u958b\u8a2d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u3068\u30a2\u30ab\u30a6\u30f3\u30c8\u306f\u3059\u3067\u306b\u6d3b\u52d5\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<figure id=\"attachment_131297\" aria-describedby=\"caption-attachment-131297\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131297 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-2.png\" alt=\"\u753b\u50cf 2 \u306f\u3001brainjobs35 \u306e react-ecommerce \u306e GitHub \u30e6\u30fc\u30b6\u30fc \u30b3\u30e1\u30f3\u30c8 \u30da\u30fc\u30b8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002Milagro Martinez #1. \u3053\u308c\u306f\u30e6\u30fc\u30b6\u30fc watasm \u3068\u30e6\u30fc\u30b6\u30fc 0xpaluco \u306e\u4f1a\u8a71\u3067\u3059\u3002\u3053\u3053\u3067\u306f Milagro\u306b\u3064\u3044\u3066\u3001\u307e\u305f\u30b3\u30fc\u30c9\u306e\u4f5c\u8005\u304c\u3069\u3046\u3057\u305f\u3089\u898b\u3064\u304b\u308b\u304b\u3092\u8b70\u8ad6\u3057\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"649\" \/><figcaption id=\"caption-attachment-131297\" class=\"wp-caption-text\">\u56f3 2. \u4e0d\u5be9\u306a GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306e Issues \u30bb\u30af\u30b7\u30e7\u30f3\u306e\u30e6\u30fc\u30b6\u30fc \u30b3\u30e1\u30f3\u30c8<\/figcaption><\/figure>\n<p>GitHub \u306e <a href=\"https:\/\/github.com\/git-insights\/git-insights\" target=\"_blank\" rel=\"noopener\">Insights<\/a> \u6a5f\u80fd\u3082\u30d2\u30f3\u30c8\u306b\u306a\u308a\u307e\u3059\u3002\u4e0b\u306e\u56f3 3 \u306f\u3001Contagious Interview \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u95a2\u9023\u3059\u308b <span style=\"font-family: 'courier new', courier, monospace;\">ServiceWorker.js<\/span> \u3068\u3044\u3046\u60aa\u610f\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u306b\u3064\u3044\u3066\u3001GitHub \u30e6\u30fc\u30b6\u30fc\u304c Insights \u6a5f\u80fd\u3092\u901a\u3058\u3066\u30b3\u30e1\u30f3\u30c8\u3057\u3066\u3044\u308b\u3088\u3046\u3059\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_131299\" aria-describedby=\"caption-attachment-131299\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131299 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-3.png\" alt=\"\u753b\u50cf 3 \u306f\u3001Virus Alert #1 \u306b\u5bfe\u3059\u308b GitHub \u30e6\u30fc\u30b6\u30fc\u306e\u30b3\u30e1\u30f3\u30c8 \u30da\u30fc\u30b8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002Toufique-imam \u306f\u3001\u3053\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306f\u8a50\u6b3a\u3067\u3042\u308b\u3068\u30b3\u30e1\u30f3\u30c8\u3057\u3001\u307b\u304b\u306e\u30e6\u30fc\u30b6\u30fc\u306e\u5b89\u5168\u306e\u305f\u3081\u306b\u6ce8\u610f\u3092\u4fc3\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30b3\u30e1\u30f3\u30c8\u3078\u306e\u8fd4\u4fe1\u3068\u3057\u3066\u3001Xeth4rth \u3068\u3044\u3046\u30e6\u30fc\u30b6\u30fc\u304c\u3001\u3053\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306f\u4ed5\u4e8b\u306e\u30aa\u30d5\u30a1\u30fc\u3068\u3057\u3066\u6e21\u3055\u308c\u305f\u3082\u306e\u3060\u304c\u3001\u8a50\u6b3a\u3060\u3068\u8ff0\u3079\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"589\" \/><figcaption id=\"caption-attachment-131299\" class=\"wp-caption-text\">\u56f3 3. Contagious Interview \u306b\u95a2\u9023\u3059\u308b GitHub Insights \u3078\u306e\u30b3\u30e1\u30f3\u30c8<\/figcaption><\/figure>\n<h3><a id=\"post-131342-_k0sgpihc4bpd\"><\/a>NPM\u3001\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u3001\u30b5\u30d7\u30e9\u30a4\u30c1\u30a7\u30fc\u30f3\u653b\u6483<\/h3>\n<p>\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u306f\u3001\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u52b9\u7387\u5316\u306e\u305f\u3081\u306b\u3001\u3088\u304f\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3 \u30d1\u30c3\u30b1\u30fc\u30b8\u3084\u30e9\u30a4\u30d6\u30e9\u30ea\u30fc\u3092\u4f7f\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306f<a href=\"https:\/\/www.cloudflare.com\/learning\/security\/what-is-a-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">\u30b5\u30d7\u30e9\u30a4\u30c1\u30a7\u30fc\u30f3\u653b\u6483<\/a>\u306e\u624b\u6bb5\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u4e2d\u3067\u3082 NPM \u306f JavaScript \u3092\u4f7f\u3046\u7121\u6570\u306e\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u4e2d\u5fc3\u7684\u30cf\u30d6\u3067\u3001<a href=\"https:\/\/www.npmjs.com\/\" target=\"_blank\" rel=\"noopener\">NPM \u306e Web \u30b5\u30a4\u30c8<\/a>\u306b\u3088\u308c\u3070\u3001\u4e16\u754c\u4e2d\u306b 1,700 \u4e07\u4eba\u306e\u958b\u767a\u8005\u304c\u3044\u308b\u305d\u3046\u3067\u3059\u3002<\/p>\n<p><a href=\"https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/cloning-a-repository\" target=\"_blank\" rel=\"noopener\">NPM \u306f\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9<\/a>\u306a\u306e\u3067\u3001\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30bf\u30fc\u304c\u6b63\u898f NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306b\u6709\u5bb3\u306a\u30b3\u30fc\u30c9\u3092\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3057\u3066 GitHub \u7d4c\u7531\u3067\u914d\u5e03\u3059\u308b\u65b9\u6cd5\u3092\u898b\u3064\u3051\u3084\u3059\u304f\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308c\u3070\u3001\u3053\u308c\u3089\u306e\u4fb5\u5bb3\u3055\u308c\u305f NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306f\u5de7\u5999\u306a\u30d0\u30c3\u30af\u30c9\u30a2\u3068\u3057\u3066\u6a5f\u80fd\u3057\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u6a19\u7684\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3078\u306e\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u3057\u3066\u3057\u307e\u3044\u307e\u3059\u3002<a href=\"https:\/\/github.blog\/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees\/\" target=\"_blank\" rel=\"noopener\">GitHub<\/a> \u3068 <a href=\"https:\/\/blog.phylum.io\/junes-sophisticated-npm-attack-attributed-to-north-korea\/\" target=\"_blank\" rel=\"noopener\">Phylum<\/a> \u306f\u6700\u8fd1\u3001\u540c\u69d8\u306e\u653b\u6483\u3092\u5831\u544a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u60aa\u610f\u306e\u3042\u308b NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u5f93\u6765\u306e\u691c\u77e5\u6280\u8853\u306e\u307b\u3068\u3093\u3069\u3092\u56de\u907f\u3059\u308b\u306e\u306b\u5f79\u7acb\u3061\u307e\u3059:<\/p>\n<ul>\n<li>\u307b\u3068\u3093\u3069\u306e<a href=\"https:\/\/en.wikipedia.org\/wiki\/Static_program_analysis\" target=\"_blank\" rel=\"noopener\">\u9759\u7684\u89e3\u6790<\/a>\/<a href=\"https:\/\/d3fend.mitre.org\/technique\/d3f:DynamicAnalysis\/\" target=\"_blank\" rel=\"noopener\">\u52d5\u7684\u89e3\u6790<\/a>\u691c\u51fa\u30a8\u30f3\u30b8\u30f3\u306f\u3001NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u3092 <a href=\"https:\/\/nodejs.org\/en\" target=\"_blank\" rel=\"noopener\">Node.js<\/a> \u306e\u30e9\u30f3\u30bf\u30a4\u30e0\u74b0\u5883\u3067\u5b9f\u884c\u3067\u304d\u307e\u305b\u3093 (\u30b5\u30dd\u30fc\u30c8\u5bfe\u8c61\u5916\u306e\u30d5\u30a1\u30a4\u30eb \u30bf\u30a4\u30d7\u306e\u305f\u3081)\u3002<\/li>\n<li><a href=\"https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/cloning-a-repository\" target=\"_blank\" rel=\"noopener\">\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u3092\u30af\u30ed\u30fc\u30f3<\/a>\u3057\u3066 Node.js \u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u306f\u3001\u307b\u3068\u3093\u3069\u306e\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u30c1\u30fc\u30e0\u3067\u666e\u901a\u306b\u8a31\u53ef\u3057\u3066\u3044\u308b\u64cd\u4f5c\u306e\u305f\u3081\u3001\u3053\u308c\u304c\u4e0d\u5be9\u304c\u3089\u308c\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u305b\u3093\u3002<\/li>\n<\/ul>\n<p>\u3053\u306e\u305f\u3081\u3001\u3053\u3046\u3057\u305f NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306b\u542b\u307e\u308c\u308b\u60aa\u610f\u306e\u3042\u308b JavaScript \u30d5\u30a1\u30a4\u30eb\u3092\u3001VirusTotal \u306e\u3088\u3046\u306a\u30b5\u30fc\u30d3\u30b9\u306b\u6295\u7a3f\u3057\u3066\u3082\u3001\u691c\u51fa\u7387\u306f\u4f4e\u3044\u304b\u30bc\u30ed\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u3055\u3089\u306b\u3001NPM \u306f\u8907\u6570\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0 \u30b7\u30b9\u30c6\u30e0\u306b\u7c21\u5358\u306b<a href=\"https:\/\/docs.npmjs.com\/downloading-and-installing-node-js-and-npm\" target=\"_blank\" rel=\"noopener\">\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/a>\u3067\u304d\u308b\u306e\u3067\u3001\u60aa\u610f\u306e\u3042\u308b NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u914d\u5e03\u3059\u308b\u306b\u3042\u305f\u308a\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u30a2\u30bf\u30c3\u30af \u30b5\u30fc\u30d5\u30a7\u30b9 (\u653b\u6483\u5bfe\u8c61\u9818\u57df) \u3092\u6700\u5927\u5316\u3067\u304d\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-131342-_8ret9hxdw7wx\"><\/a>\u4fb5\u5bb3\u884c\u70ba<\/h3>\n<p>\u9762\u63a5\u904e\u7a0b\u3067\u88ab\u5bb3\u8005\u306f\u958b\u767a\u74b0\u5883\u3092\u6e96\u5099\u3057\u307e\u3059\u3002\u79c1\u305f\u3061\u304c\u8abf\u67fb\u3057\u305f\u653b\u6483\u3067\u306f\u3001\u307b\u3068\u3093\u3069\u306e\u958b\u767a\u8005\u304c <a href=\"https:\/\/visualstudio.microsoft.com\/\" target=\"_blank\" rel=\"noopener\">Visual Studio Code<\/a> \u3068 <a href=\"https:\/\/marketplace.visualstudio.com\/items?itemName=JohnJane.code-helper\" target=\"_blank\" rel=\"noopener\">Code Helper<\/a> \u306e\u3088\u3046\u306a\u30d7\u30e9\u30b0\u30a4\u30f3\u4e00\u5f0f\u3068 <a href=\"https:\/\/gitextensions.github.io\/\" target=\"_blank\" rel=\"noopener\">Git<\/a> \u3084 <a href=\"https:\/\/code.visualstudio.com\/docs\/nodejs\/nodejs-tutorial\" target=\"_blank\" rel=\"noopener\">Node.js \u306e\u62e1\u5f35\u6a5f\u80fd<\/a> \u3092\u4f7f\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u306f NPM \u3082\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u57fa\u672c\u30b7\u30b9\u30c6\u30e0\u8981\u4ef6\u304c\u6e80\u305f\u3055\u308c\u305f\u5f8c\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u88ab\u5bb3\u8005\u306b\u5bfe\u3057\u3001 GitHub \u4e0a\u306b\u3042\u308b\u6b63\u898f\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3092\u88c5\u3063\u305f\u60aa\u610f\u306e\u3042\u308b NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3088\u3046\u8981\u6c42\u3057\u307e\u3059\u3002\u3053\u306e\u60aa\u610f\u306e\u3042\u308b NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306b\u306f\u3001\u79c1\u305f\u3061\u304c BeaverTail \u3068\u540d\u4ed8\u3051\u305f\u3001\u65b0\u305f\u306b\u767a\u898b\u3055\u308c\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u306e JavaScript \u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>BeaverTail \u306f\u60c5\u5831\u3092\u76d7\u307f\u51fa\u3057\u3001\u7b2c 2 \u6bb5\u968e\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u8ffd\u52a0\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u79c1\u305f\u3061\u304c InvisibleFerret \u3068\u540d\u4ed8\u3051\u305f\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3059\u3002<\/p>\n<p>\u6b21\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u3001BeaverTail \u3068\u3044\u3046\u30ed\u30fc\u30c0\u30fc\u306e\u5206\u6790\u3068\u6d1e\u5bdf\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-131342-_iqv9tr9q82yn\"><\/a>BeaverTail \u306e\u5206\u6790<\/h3>\n<p>NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u5185\u3067 JavaScript \u3068\u3057\u3066\u914d\u5e03\u3055\u308c\u308b BeaverTail \u306f 2 \u3064\u306e\u5f79\u5272\u3092\u679c\u305f\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fc<\/li>\n<li>\u30ed\u30fc\u30c0\u30fc<\/li>\n<\/ul>\n<p>\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fc\u3068\u3057\u3066\u306e BeaverTail \u306f\u3001\u88ab\u5bb3\u8005\u306e Web \u30d6\u30e9\u30a6\u30b6\u30fc\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u6697\u53f7\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u3084\u30af\u30ec\u30b8\u30c3\u30c8 \u30ab\u30fc\u30c9\u60c5\u5831\u3092\u72d9\u3044\u307e\u3059\u3002\u30ed\u30fc\u30c0\u30fc\u3068\u3057\u3066\u306e BeaverTail \u306f\u3001\u7b2c 2 \u6bb5\u968e\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3042\u308b InvisibleFerret \u3092\u53d6\u5f97\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p>NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u5185\u306e BeaverTail JavaScript \u30d5\u30a1\u30a4\u30eb\u306f\u3001\u691c\u51fa\u56de\u907f\u306e\u305f\u3081\u3001\u9ad8\u5ea6\u306b\u96e3\u8aad\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3001\u60aa\u610f\u306e\u3042\u308b NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u5168\u4f53\u3092 GitHub \u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u308b\u3053\u3068\u3082\u3042\u308c\u3070\u3001\u307b\u304b\u306e\u958b\u767a\u8005\u306e\u6b63\u5f53\u306a NPM \u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306b BeaverTail \u306e\u30b3\u30fc\u30c9\u3092\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3059\u308b\u3053\u3068\u3082\u3042\u308a\u307e\u3059\u3002\u56f3 4 \u306f\u3001\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3055\u308c\u305f\u30b9\u30af\u30ea\u30d7\u30c8\u306e<a href=\"https:\/\/www.virustotal.com\/gui\/file\/de42155e14a3c9c4d919316d6ba830229533de5063fcd110f53e2395ef3aa77a\/\" target=\"_blank\" rel=\"noopener\">\u4f8b<\/a>\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_131301\" aria-describedby=\"caption-attachment-131301\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131301 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-4.png\" alt=\"\u753b\u50cf 4 \u306f\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3092\u5206\u5272\u3057\u305f\u3082\u306e\u3067\u3001\u4e0a\u306e\u753b\u50cf\u306f GitHub \u306e\u30b3\u30df\u30c3\u30c8\u30da\u30fc\u30b8\u3067\u3059\u3002\u4e0b\u306e\u753b\u50cf\u306f BeaverTail \u306e\u96e3\u8aad\u5316\u3055\u308c\u305f JavaScript \u3067\u3059\u3002\" width=\"900\" height=\"863\" \/><figcaption id=\"caption-attachment-131301\" class=\"wp-caption-text\">\u56f3 4. \u96e3\u8aad\u5316\u3055\u308c\u305f BeaverTail \u306e JavaScript\u3002\u6b63\u5f53\u306a\u958b\u767a\u8005\u306e\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e NPM \u30d5\u30a1\u30a4\u30eb\u306b\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3055\u308c\u3066\u3044\u308b<\/figcaption><\/figure>\n<p>\u56f3 4 \u306b\u793a\u3057\u305f\u901a\u308a\u3001\u30b3\u30fc\u30c9\u304c\u9ad8\u5ea6\u306b\u96e3\u8aad\u5316\u3055\u308c\u3066\u3044\u308b\u4e0a\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Node.js<\/span> \u74b0\u5883\u306b\u3082\u4f9d\u5b58\u3057\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001BeaverTail \u306e\u5b9f\u884c\u306b\u306f\u4eba\u9593\u306b\u3088\u308b\u64cd\u4f5c\u304c\u5fc5\u8981\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u7279\u5fb4\u306f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u691c\u51fa\u56de\u907f\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/p>\n<p>\u60aa\u610f\u306e\u3042\u308b NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u304c Windows\u3001Linux\u3001macOS \u306e\u30db\u30b9\u30c8\u306b\u6b63\u5e38\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u3068\u3001BeaverTail \u306f\u57fa\u672c\u7684\u306a\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u53ce\u96c6\u3057\u307e\u3059\u3002\u3053\u306e\u8105\u5a01\u306f\u307e\u305f\u3001Binance \u3084 Coinbase \u306e\u3088\u3046\u306a\u6697\u53f7\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u306b\u95a2\u9023\u3059\u308b\u62e1\u5f35\u6a5f\u80fd\u3092\u88ab\u5bb3\u8005\u306e Web \u30d6\u30e9\u30a6\u30b6\u30fc\u5185\u3067\u691c\u7d22\u3057\u307e\u3059\u3002\u8868 1 \u306b\u5168\u30ea\u30b9\u30c8\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 100%;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><b>\u30d6\u30e9\u30a6\u30b6\u30fc\u62e1\u5f35\u6a5f\u80fd\u306e ID<\/b><\/td>\n<td style=\"text-align: center;\"><b>\u30d6\u30e9\u30a6\u30b6\u30fc\u62e1\u5f35\u6a5f\u80fd\u540d<\/b><\/td>\n<td style=\"text-align: center;\"><b>\u30bf\u30fc\u30b2\u30c3\u30c8 \u30d6\u30e9\u30a6\u30b6\u30fc<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">fhbohimaelbohpjbbldcngcnapndodjp\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Binance \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">aeachknmefphepccionboohckonoeemg<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Coin98 \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hnfanknocfeofbddgcijnmhnfnkdnaad\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Coinbase \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hifafgmccdpekplomjjkcfgodnhcellj\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Crypto.com \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">nkbihfbeogaeaoehlefnkodbefgpgknn\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">MetaMask \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ejbalbakoplchlghecdalmeeeajnimhm\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">MetaMask \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Microsoft Edge<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">bfnaelmomeimhlpmgjnjophhpkkoljpa<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Phantom \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">fnjhmkhhmkbjkkabndcnnogagogbneec\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Ronin \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ibnejdfjmmkpcnlpebklmnkoeoihofec<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TRON \u30a6\u30a9\u30ec\u30c3\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Chrome<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 8pt; color: #999999;\"><em>\u8868 1. \u30d6\u30e9\u30a6\u30b6\u30fc\u62e1\u5f35\u6a5f\u80fd BeaverTail \u304c\u63a2\u3059\u6697\u53f7\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8<\/em><\/span><\/p>\n<p>BeaverTail \u306f <span style=\"font-family: 'courier new', courier, monospace;\">~\/.config\/solana\/id.json<\/span> \u3092\u691c\u7d22\u3057\u3066 Solana \u6697\u53f7\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u3082\u30c1\u30a7\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<p>\u30c7\u30fc\u30bf\u6f0f\u51fa\u3068 InvisibleFerret \u306e\u30ed\u30fc\u30c9\u4e2d\u3001BeaverTail \u306f\u4ee5\u4e0b\u306e\u8868 2 \u306b\u793a\u3059\u3088\u3046\u306a Web \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u751f\u6210\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 100%;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><b>URL \u30d1\u30bf\u30fc\u30f3<\/b><\/td>\n<td style=\"text-align: center;\"><b>\u8aac\u660e<\/b><\/td>\n<td style=\"text-align: center;\"><b>\u4fdd\u5b58\u5834\u6240<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/keys<\/span><\/td>\n<td><span style=\"font-weight: 400;\">HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u304c BeaverTail \u304c\u53ce\u96c6\u3057\u305f\u30c7\u30fc\u30bf\u3092\u9001\u4fe1\u00a0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">\u8a72\u5f53\u306a\u3057<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/uploads<\/span><\/td>\n<td><span style=\"font-weight: 400;\">HTTP POST \u30ea\u30af\u30a8\u30b9\u30c8\u304c\u305d\u306e\u307b\u304b\u306e Solana \u6697\u53f7\u901a\u8ca8\u30a6\u30a9\u30ec\u30c3\u30c8\u306e\u30c7\u30fc\u30bf\u306a\u3069\u306e\u53ce\u96c6\u60c5\u5831\u3092\u9001\u4fe1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">\u8a72\u5f53\u306a\u3057<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/node\/&lt;node_js_runtime_environment_version&gt;<\/span><\/td>\n<td><span style=\"font-weight: 400;\">(\u5fc5\u8981\u306b\u5fdc\u3058\u3066) Chrome \u306b\u4fdd\u5b58\u3055\u308c\u305f\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb (\u8a8d\u8a3c\u60c5\u5831) \u3092\u5fa9\u53f7\u3059\u308b\u30d8\u30eb\u30d1\u30fc DLL \u30d5\u30a1\u30a4\u30eb\u3092\u6c42\u3081\u308b HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">%USERPROFILE%\\store.node<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/pdown<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Python \u306e\u5b9f\u884c\u30d5\u30a1\u30a4\u30eb\u3068\u95a2\u9023\u30e9\u30a4\u30d6\u30e9\u30ea\u30fc\u3092\u8981\u6c42\u3059\u308b HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">%TEMP%\\p.zi<\/span><span style=\"font-weight: 400;\"> \u307e\u305f\u306f <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">%HOMEPATH%\\.pyp\\<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/client\/&lt;campaign_id&gt;<\/span><\/td>\n<td><span style=\"font-weight: 400;\">InvisibleFerret \u3092\u6c42\u3081\u308b HTTP GET \u30ea\u30af\u30a8\u30b9\u30c8<\/span><\/td>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">%HOMEPATH%\\.npl<\/span><span style=\"font-weight: 400;\"> \u307e\u305f\u306f <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">~\/.npl<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><em><span style=\"font-size: 8pt;\">\u8868 2. BeaverTail \u30de\u30eb\u30a6\u30a7\u30a2\u304c\u751f\u6210\u3057\u305f\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/span> <\/em><\/span><\/p>\n<p>\u3053\u306e\u6bb5\u968e\u3067\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u76ee\u7acb\u305f\u305a\u30b7\u30f3\u30d7\u30eb\u306a\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0 \u30d0\u30c3\u30af\u30c9\u30a2\u3092\u88ab\u5bb3\u8005\u306e\u30de\u30b7\u30f3\u306b\u30c9\u30ed\u30c3\u30d7\u3059\u308b\u3053\u3068\u306b\u6210\u529f\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-131342-_wloxdan4ner4\"><\/a>InvisibleFerret: \u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u578b Python \u30d0\u30c3\u30af\u30c9\u30a2<\/h3>\n<p>InvisibleFerret \u306f\u65b0\u305f\u306b\u767a\u898b\u3055\u308c\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3001BeaverTail \u306e NPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306b\u3088\u3063\u3066\u53d6\u5f97\u30fb\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u3053\u308c\u306f Python \u3067\u66f8\u304b\u308c\u305f\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3001\u4ee5\u4e0b\u306e\u6a5f\u80fd\u3092\u6301\u3064\u3055\u307e\u3056\u307e\u306a\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30d5\u30a3\u30f3\u30ac\u30fc\u30d7\u30ea\u30f3\u30c6\u30a3\u30f3\u30b0<\/li>\n<li>\u9060\u9694\u64cd\u4f5c<\/li>\n<li>\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0<\/li>\n<li>\u30c7\u30fc\u30bf\u6f0f\u51fa<\/li>\n<li>\u30d6\u30e9\u30a6\u30b6\u30fc \u30b9\u30c6\u30a3\u30fc\u30e9\u30fc\u6a5f\u80fd<\/li>\n<li>AnyDesk \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9 (\u8ffd\u52a0\u3067\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u304c\u5fc5\u8981\u306a\u5834\u5408)<\/li>\n<\/ul>\n<p>\u56f3 5 \u306f\u3001InvisibleFerret \u304c\u30e2\u30b8\u30e5\u30fc\u30eb\u5fd7\u5411\u3067\u3042\u308b\u3053\u3068\u3092\u660e\u3089\u304b\u306b\u3057\u305f\u56f3\u3067\u3059\u3002\u3053\u306e\u56f3\u306f\u3001\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u307b\u304b\u3001\u7570\u306a\u308b\u6a5f\u80fd\u3092\u5b9f\u884c\u3059\u308b 2 \u3064\u306e\u8ffd\u52a0\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_131303\" aria-describedby=\"caption-attachment-131303\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131303 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-5-ja.png\" alt=\"\u753b\u50cf 5 \u306f\u3001InvisibleFerret \u304c\u3069\u306e\u3088\u3046\u306b\u6a5f\u80fd\u3059\u308b\u304b\u3092\u793a\u3059\u56f3\u3067\u3059\u3002BeaverTail \u306e GitHub \u304b\u3089 .npl \u3068\u3044\u3046\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u3064\u306a\u304c\u308a\u3001\u3053\u306e\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306f 2 \u3064\u306b\u679d\u5206\u304b\u308c\u3057\u3066\u3044\u307e\u3059\u30021 \u3064\u306e\u679d\u306f\u30d5\u30a3\u30f3\u30ac\u30fc\u30d7\u30ea\u30f3\u30c8\u3001\u9060\u9694\u64cd\u4f5c\u3001\u60c5\u5831\u7a83\u53d6\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u542b\u3080 .n2\/pay \u3067\u3059\u3002\u3053\u306e\u30d6\u30e9\u30f3\u30c1\u306f .n2\/adc \u306b\u3088\u308b AnyDesk \u3067\u7d42\u4e86\u3057\u3066\u3044\u307e\u3059\u30022 \u672c\u3081\u306e\u30d6\u30e9\u30f3\u30c1\u306f .n2\/bow \u3067\u3001\u3053\u308c\u306f\u30d6\u30e9\u30a6\u30b6\u30fc\u7a83\u53d6\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3067\u3059\u3002 \" width=\"500\" height=\"306\" \/><figcaption id=\"caption-attachment-131303\" class=\"wp-caption-text\">\u56f3 5. InvisibleFerret \u306e\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u3068 2 \u3064\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8<\/figcaption><\/figure>\n<h4><a id=\"post-131342-_6fzwx1u2hmwy\"><\/a><strong>\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8<\/strong><\/h4>\n<p>BeaverTail \u306f\u8868 2 \u306e\u6700\u7d42\u884c\u306e URL \u30d1\u30bf\u30fc\u30f3\u3092\u4f7f\u3063\u3066 InvisibleFerret \u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002InvisibleFerret \u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b URL \u306e\u4f8b\u3092\u4ee5\u4e0b\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/client\/&lt;campaign_id&gt;<\/span><\/li>\n<\/ul>\n<p>InvisibleFerret \u306e\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30db\u30fc\u30e0 \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u4ee5\u4e0b\u306b <span style=\"font-family: 'courier new', courier, monospace;\">.npl<\/span> \u3068\u3044\u3046\u540d\u524d\u3067\u4fdd\u5b58\u3055\u308c\u3066 Python \u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002Windows \u30db\u30b9\u30c8\u4e0a\u3067\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c\u3059\u308b\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u306e\u4f8b\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">C:\\Users\\$USER$\\.pyp\\python.exe C:\\Users\\$USER$\\.npl<\/span><\/li>\n<\/ul>\n<p>InvisibleFerret \u306e\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u96e3\u8aad\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u4f7f\u3044\u307e\u3059\u3002\u305d\u306e<a href=\"https:\/\/www.virustotal.com\/gui\/file\/8d8bdbb31bfdb0540b6a79fad3b89695e9751c98b39bc99b0c6a64de10ae2dae\" target=\"_blank\" rel=\"noopener\">\u4f8b<\/a>\u3092\u56f3 6 \u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_131305\" aria-describedby=\"caption-attachment-131305\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131305 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-6.png\" alt=\"\u753b\u50cf 6 \u306f\u591a\u6570\u306e\u30b3\u30fc\u30c9\u884c\u304b\u3089\u306a\u308b\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002 \" width=\"600\" height=\"318\" \/><figcaption id=\"caption-attachment-131305\" class=\"wp-caption-text\">\u56f3 6. InvisibleFerret \u306e Python\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u4f8b<\/figcaption><\/figure>\n<p>\u56f3 6 \u306e1\u756a\u4e0b\u306e\u90e8\u5206\u306f InvisibleFerret \u3068\u305d\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u304c\u4f7f\u3046\u5168\u30b9\u30af\u30ea\u30d7\u30c8\u30d5\u30a1\u30a4\u30eb\u306b\u5171\u901a\u3059\u308b\u30c7\u30b3\u30fc\u30c9 \u30eb\u30fc\u30c1\u30f3\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">temp<\/span> \u6587\u5b57\u5217\u306e\u6700\u521d\u306e 8 \u6587\u5b57\u306f\u30c7\u30b3\u30fc\u30c9\u7528\u306e\u30ad\u30fc\u3092\u8868\u3057\u307e\u3059\u3002<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">temp<\/span> \u6587\u5b57\u5217\u306e\u6b8b\u308a\u306e\u90e8\u5206\u306f Base64 \u304b\u3089\u5909\u63db\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>\u3053\u306e\u7d50\u679c\u306f\u3001 8 \u6587\u5b57\u306e\u30ad\u30fc\u3092\u4f7f\u3063\u3066 XOR \u30eb\u30fc\u30d7\u3067\u51e6\u7406\u3055\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>\u3053\u306e\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001<a href=\"https:\/\/pypi.org\/project\/pip\/\" target=\"_blank\" rel=\"noopener\">pip<\/a> \u3092\u4f7f\u3063\u3066\u5fc5\u8981\u306a Python \u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002\u307e\u305f\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u5909\u6570\u3082\u5b9a\u7fa9\u3057\u3001\u30b3\u30de\u30f3\u30c9 &amp; \u30b3\u30f3\u30c8\u30ed\u30fc\u30eb (C2) \u30b5\u30fc\u30d0\u30fc\u3068\u30dd\u30fc\u30c8\u3092\u8b58\u5225\u3059\u308b\u305f\u3081\u306e\u5024\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p>\u521d\u671f\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u4e3b\u306a\u76ee\u7684\u306f\u3001InvisibleFerret \u306e 2 \u3064\u306e\u7570\u306a\u308b\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u53d6\u5f97\u3057\u3066\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306f\u8868 3 \u306b\u793a\u3059\u901a\u308a\u306b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30fb\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002<\/p>\n<table style=\"width: 100%;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><b>\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306e\u30ea\u30af\u30a8\u30b9\u30c8<\/b><\/td>\n<td style=\"text-align: center;\"><b>\u4fdd\u5b58\u5834\u6240<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hxxp:\/\/&lt;c2_server&gt;:1224\/payload\/&lt;campaign_id&gt;<\/span><\/td>\n<td><span style=\"font-weight: 400;\">\u30ed\u30fc\u30ab\u30eb \u30d5\u30a1\u30a4\u30eb \u30d1\u30b9 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">.n2\/pay<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: 'courier new', courier, monospace;\"><span style=\"font-weight: 400;\">http:\/\/&lt;c2_server&gt;:1225\/bow\/&lt;campaign_id&gt;<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/span><\/td>\n<td><span style=\"font-weight: 400;\">\u30ed\u30fc\u30ab\u30eb \u30d5\u30a1\u30a4\u30eb \u30d1\u30b9 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">.n2\/bow<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><em><span style=\"font-size: 8pt;\">\u8868 3. BeaverTail \u30de\u30eb\u30a6\u30a7\u30a2\u304c\u751f\u6210\u3057\u305f\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/span> <\/em><\/span><\/p>\n<p>\u306a\u304a\u3001 2 \u3064\u3081\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306f\u3001\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0 \u30b7\u30b9\u30c6\u30e0\u304c macOS <strong>\u3067\u306f\u306a\u3044<\/strong>\u5834\u5408\u306b\u306e\u307f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-131342-_ob001oucojj\"><\/a><strong>InvisibleFerret \u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8<\/strong><\/h3>\n<p>InvisibleFerret \u306e\u6700\u521d\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306f\u3001\u30d5\u30a3\u30f3\u30ac\u30fc\u30d7\u30ea\u30f3\u30c8\u4f5c\u6210\u7528\u306e\u30b7\u30b9\u30c6\u30e0 \u30c7\u30fc\u30bf\u3092\u53ce\u96c6\u3057\u3066 C2 \u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002\u6700\u521d\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u304c\u53ce\u96c6\u3059\u308b\u5185\u5bb9\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li>\u5185\u90e8 IP \u30a2\u30c9\u30ec\u30b9<\/li>\n<li>IP \u306e\u30b8\u30aa\u30ed\u30b1\u30fc\u30b7\u30e7\u30f3\u60c5\u5831<\/li>\n<li>OS \u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3001\u30ea\u30ea\u30fc\u30b9\u3001\u30db\u30b9\u30c8\u3001\u30e6\u30fc\u30b6\u30fc\u60c5\u5831\u3092\u542b\u3080\u30b7\u30b9\u30c6\u30e0\u60c5\u5831<\/li>\n<\/ul>\n<p>\u3053\u306e\u60c5\u5831\u3092 JSON \u5f62\u5f0f\u3067\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002<\/p>\n<p>InvisibleFerret \u306e 2 \u3064\u3081\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306f\u3001\u9060\u9694\u64cd\u4f5c\u6a5f\u80fd\u3068\u60c5\u5831\u7a83\u53d6\u6a5f\u80fd\u3092\u5c55\u958b\u3057\u307e\u3059\u3002\u5b9f\u884c\u3055\u308c\u308b\u3068\u3001\u4ee5\u4e0b\u306e Python \u30d1\u30c3\u30b1\u30fc\u30b8\u304c\u30b7\u30b9\u30c6\u30e0\u306b\u5b58\u5728\u3057\u3066\u3044\u306a\u3044\u5834\u5408\u306f\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u74b0\u5883\u3092\u6574\u3048\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/pypi.org\/project\/pyWinhook\/\" target=\"_blank\" rel=\"noopener\">pyWinhook<\/a>: \u30b0\u30ed\u30fc\u30d0\u30eb\u306a\u30de\u30a6\u30b9\u5165\u529b\/\u30ad\u30fc\u5165\u529b\u30a4\u30d9\u30f3\u30c8\u3078\u306e\u30b3\u30fc\u30eb\u30d0\u30c3\u30af\u3092\u63d0\u4f9b\u3059\u308b\u3001Windows \u306e\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u5916\u5165\u529b\u30d5\u30c3\u30af\u7528\u306e Python \u30e9\u30c3\u30d1\u30fc\u3002<\/li>\n<li><a href=\"https:\/\/pypi.org\/project\/pyperclip\/\" target=\"_blank\" rel=\"noopener\">pyperclip<\/a>: \u30af\u30ea\u30c3\u30d7\u30dc\u30fc\u30c9\u5185\u5bb9\u306e\u30b3\u30d4\u30fc\/\u30da\u30fc\u30b9\u30c8\u306e\u305f\u3081\u306e\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0 Python \u30e2\u30b8\u30e5\u30fc\u30eb\u3002<\/li>\n<li><a href=\"https:\/\/pypi.org\/project\/psutil\/\" target=\"_blank\" rel=\"noopener\">psutil<\/a>: \u30d7\u30ed\u30bb\u30b9\u3068\u30b7\u30b9\u30c6\u30e0\u3092\u76e3\u8996\u3059\u308b\u305f\u3081\u306e\u30af\u30ed\u30b9\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0 Python \u30e9\u30a4\u30d6\u30e9\u30ea\u30fc\u3002<\/li>\n<li><a href=\"https:\/\/pypi.org\/project\/pywin32\/\" target=\"_blank\" rel=\"noopener\">pywin32<\/a>: Windows \u62e1\u5f35\u6a5f\u80fd\u7528\u306e Python \u30e9\u30a4\u30d6\u30e9\u30ea\u30fc\u3002<\/li>\n<\/ul>\n<h3><a id=\"post-131342-_y3hjk2pt4a7b\"><\/a><strong>C2 \u901a\u4fe1<\/strong><\/h3>\n<p>InvisibleFerret \u306f TCP \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3067 C2 \u30b5\u30fc\u30d0\u30fc\u3068\u306e\u63a5\u7d9a\u3092\u78ba\u7acb\u3057\u3001\u5b9a\u671f\u7684\u306b\u30c1\u30a7\u30c3\u30af\u30a4\u30f3\u3057\u3066\u6b21\u306e\u6307\u793a\u3092\u5f85\u3061\u307e\u3059\u3002\u3053\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f JSON \u30e1\u30c3\u30bb\u30fc\u30b8\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u611f\u67d3\u30db\u30b9\u30c8\u306f\u3001\u56f3 7 \u306b\u793a\u3059\u3088\u3046\u306b\u3001\u5024\u304c 0 \u306e <span style=\"font-family: 'courier new', courier, monospace;\">code<\/span> \u3068\u3001args \u306e\u30ad\u30fc\u3092\u3082\u3064 JSON \u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u6307\u5b9a\u3057\u305f<a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/MINIFI\/C2+Design#C2Design-Heartbeats\" target=\"_blank\" rel=\"noopener\">\u30cf\u30fc\u30c8\u30d3\u30fc\u30c8 \u30e1\u30c3\u30bb\u30fc\u30b8<\/a>\u3092\u4f7f\u3063\u3066\u30c1\u30a7\u30c3\u30af\u30a4\u30f3\u3057\u307e\u3059\u3002\u3053\u306e\u30cf\u30fc\u30c8\u30d3\u30fc\u30c8 \u30e1\u30c3\u30bb\u30fc\u30b8\u306b\u306f\u3001\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u8b58\u5225\u5b50 <span style=\"font-family: 'courier new', courier, monospace;\">(sType<\/span>) \u3068\u88ab\u5bb3\u8005\u306e\u30db\u30b9\u30c8\u540d <span style=\"font-family: 'courier new', courier, monospace;\">(sHost<\/span>) \u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_131307\" aria-describedby=\"caption-attachment-131307\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131307 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-7-ja-1.png\" alt=\"\u753b\u50cf 7 \u306f\u3001\u30cf\u30fc\u30c8\u30d3\u30fc\u30c8 \u30b3\u30de\u30f3\u30c9\u3068\u5236\u5fa1\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u8868\u3059\u56f3\u3067\u3059\u3002\u88ab\u5bb3\u8005\u306f\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u5185\u3067\u3001\u76d7\u8074\u3055\u308c\u305f\u30ce\u30fc\u30c8 \u30d1\u30bd\u30b3\u30f3\u306e\u30a2\u30a4\u30b3\u30f3\u3068\u3057\u3066\u8868\u73fe\u3055\u308c\u3066\u3044\u307e\u3059\u3002JSON \u306f TCP \u30dd\u30fc\u30c8 1245 \u3067\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u64cd\u308a\u4eba\u5f62\u306e\u7cf8\u306b\u3064\u306a\u304c\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u3068\u30ce\u30fc\u30c8 \u30d1\u30bd\u30b3\u30f3\u306e\u30a2\u30a4\u30b3\u30f3\u3067\u8c61\u5fb4\u3055\u308c\u308bC2 \u30b5\u30fc\u30d0\u30fc\u3078\u3064\u306a\u304c\u308b\u77e2\u5370\u304c\u63cf\u304b\u308c\u3066\u3044\u307e\u3059\u3002JSON \u30c6\u30ad\u30b9\u30c8\u306e\u4e0b\u306b\u306f\u30b3\u30fc\u30c9 \u30b9\u30cb\u30da\u30c3\u30c8\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"600\" height=\"264\" \/><figcaption id=\"caption-attachment-131307\" class=\"wp-caption-text\">\u56f3 7. C2 \u3078\u306e\u30cf\u30fc\u30c8\u30d3\u30fc\u30c8 \u30e1\u30c3\u30bb\u30fc\u30b8<\/figcaption><\/figure>\n<p>C2 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u30d0\u30c3\u30af\u30c9\u30a2\u306b\u6b21\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u6307\u793a\u3059\u308b JSON \u30c7\u30fc\u30bf\u3092\u8fd4\u3057\u307e\u3059\u3002JSON \u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u306f\u3001\u540c\u3058 2 \u3064\u306e\u4e3b\u8981\u30ad\u30fc\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">code<\/span>: \u30a2\u30af\u30b7\u30e7\u30f3\u3084\u30b3\u30de\u30f3\u30c9\u3092\u6307\u5b9a\u3059\u308b\u5024<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">args<\/span>: \u6307\u5b9a\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\u306b\u5fc5\u8981\u306a\u5f15\u6570\u3092\u542b\u3080\u3001\u8907\u6570\u306e\u30ad\u30fc\u3068\u5024\u306e\u30da\u30a2\u3092\u6301\u3064\u6587\u5b57\u5217\u307e\u305f\u306f JSON \u8f9e\u66f8<\/li>\n<\/ul>\n<p>InvisibleFerret \u306f\u3001\u4ee5\u4e0b\u306e\u8868 4 \u306b\u793a\u3059\u5408\u8a08 8 \u3064\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u88c5\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 100%; height: 695px;\">\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 17.691%; height: 24px; text-align: center;\"><b>\u30b3\u30de\u30f3\u30c9<\/b><\/td>\n<td style=\"width: 81.6446%; height: 24px; text-align: center;\"><b>\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr style=\"height: 75px;\">\n<td style=\"width: 17.691%; height: 75px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_cmd<\/span><\/td>\n<td style=\"width: 81.6446%; height: 75px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">args<\/span> \u306e\u5024\u304c <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">delete<\/span><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> \u3068\u7b49\u3057\u3044\u304b<\/span><span style=\"font-weight: 400;\">\u3069\u3046\u304b\u3092\u30c1\u30a7\u30c3\u30af<\/span>\u3057\u3001\u7b49\u3057\u3051\u308c\u3070\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u9589\u3058\u307e\u3059\u3002C2 \u30b5\u30fc\u30d0\u30fc\u306b\u901a\u77e5\u3059\u308b\u305f\u3081\u306b\u3001\u30e1\u30c3\u30bb\u30fc\u30b8\u6587\u5b57\u5217 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">[close]<\/span> \u3092\u9001\u4fe1\u3057\u307e\u3059<span style=\"font-weight: 400;\">\u3002<\/span><\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"width: 17.691%; height: 72px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_obj<\/span><\/td>\n<td style=\"width: 81.6446%; height: 72px;\"><span style=\"font-weight: 400;\">\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">args['cmd']<\/span><span style=\"font-weight: 400;\"> \u304b\u3089\u30b3\u30de\u30f3\u30c9\u5024\u3092\u53d6\u308a\u51fa\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002C2 \u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u308b JSON \u7d50\u679c\u306f\u3001<\/span><span style=\"font-weight: 400;\">code<\/span><span style=\"font-weight: 400;\"> \u306b\u5024 <\/span><span style=\"font-weight: 400;\"> 1 <\/span><span style=\"font-weight: 400;\"> \u304c\u8a2d\u5b9a\u3055\u308c\u308b\u307b\u304b\u3001<\/span><span style=\"font-weight: 400;\">\u7d50\u679c\u3092\u8868\u3059 <\/span><span style=\"font-weight: 400;\">args<\/span> \u304c\u6307\u5b9a\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"width: 17.691%; height: 48px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_clip<\/span><\/td>\n<td style=\"width: 81.6446%; height: 48px;\"><span style=\"font-weight: 400;\">\u30ad\u30fc\u30ed\u30ac\u30fc \u30d0\u30c3\u30d5\u30a1\u30fc\u3068\u30af\u30ea\u30c3\u30d7\u30dc\u30fc\u30c9 \u30c7\u30fc\u30bf\u306e\u5185\u5bb9\u3092\u9001\u4fe1\u3057\u307e\u3059\u3002C2 \u30b5\u30fc\u30d0\u30fc\u306b\u3001JSON <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">code<\/span> \u306e<span style=\"font-weight: 400;\">\u5024<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\"> 3 <\/span><span style=\"font-weight: 400;\"> \u3068\u3001<\/span><span style=\"font-weight: 400;\"> \u53ce\u96c6\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u542b\u3080 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">args<\/span> \u3092\u30ec\u30dd\u30fc\u30c8\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"width: 17.691%; height: 88px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_run<\/span><\/td>\n<td style=\"width: 81.6446%; height: 88px;\"><span style=\"font-weight: 400;\">\u30d6\u30e9\u30a6\u30b6\u30fc\u7a83\u53d6\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002JSON<\/span> <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">code<\/span> \u306b\u306f<span style=\"font-weight: 400;\">\u5024<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\"> 4 <\/span><span style=\"font-weight: 400;\"> \u3092\u6307\u5b9a\u3057\u3001 <\/span><span style=\"font-weight: 400;\">\u3053\u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u7528\u306e\u30d5\u30a1\u30a4\u30eb \u30d1\u30b9\u3092 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">args<\/span> \u306b\u542b\u3081\u3066 C2 \u30b5\u30fc\u30d0\u30fc\u306b\u30ec\u30dd\u30fc\u30c8\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr style=\"height: 640px;\">\n<td style=\"width: 17.691%; height: 172px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_upload<\/span><\/td>\n<td style=\"width: 81.6446%; height: 172px;\"><span style=\"font-weight: 400;\">C2 \u30b5\u30fc\u30d0\u30fc\u306b\u30c7\u30fc\u30bf\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u30b5\u30d6\u30b3\u30de\u30f3\u30c9\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002 <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u7279\u5b9a\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u306e\u5168\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u7279\u5b9a\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a9\u30eb\u30c0\u30fc\u5185\u3067\u3001\u6307\u5b9a\u3055\u308c\u305f\u30d1\u30bf\u30fc\u30f3\u306b\u30de\u30c3\u30c1\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u518d\u5e30\u7684\u306b\u691c\u7d22\u3057\u3066\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">\u30b3\u30f3\u30c6\u30f3\u30c4\u306f\u30a2\u30af\u30bf\u30fc\u304c\u5236\u5fa1\u3059\u308b FTP \u30b5\u30fc\u30d0\u30fc\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002 <\/span>\u3053\u306e FTP \u30b5\u30fc\u30d0\u30fc\u306f\u4ee5\u4e0b\u306e JSON \u30ec\u30b9\u30dd\u30f3\u30b9\u5185\u306e\u4ee5\u4e0b\u306e <span style=\"font-weight: 400;\">args<\/span><span style=\"font-weight: 400;\"> \u3067\u6307\u5b9a\u3055\u308c\u307e\u3059\u3002<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">hn<\/span><span style=\"font-weight: 400;\">: FTP \u30db\u30b9\u30c8\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">un<\/span><span style=\"font-weight: 400;\">: \u30e6\u30fc\u30b6\u30fc\u540d\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">pw<\/span><span style=\"font-weight: 400;\">: \u30d1\u30b9\u30ef\u30fc\u30c9\u3002<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">\u3053\u306e\u30ed\u30b8\u30c3\u30af\u306b\u306f\u3001\u7279\u5b9a\u306e\u30d5\u30a1\u30a4\u30eb\u3084\u30d5\u30a9\u30eb\u30c0\u30fc\u306e\u9664\u5916\u30ea\u30b9\u30c8\u3068\u3001\u898b\u3064\u304b\u3063\u305f\u5834\u5408\u306f\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u3079\u304d\u30d1\u30b9\u306e\u4e00\u89a7\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30d1\u30b9\u306f\u3001\u6587\u66f8 (<span style=\"font-family: 'courier new', courier, monospace;\">.xls<\/span> \u3084 <span style=\"font-family: 'courier new', courier, monospace;\">.doc<\/span>) \u306e\u307b\u304b\u3001\u6697\u53f7\u901a\u8ca8\u306b\u7279\u6709\u306e\u30d5\u30a1\u30a4\u30eb\u30d1\u30b9 (metamask\u3001wallet \u306a\u3069) \u306b\u3082\u30d5\u30a9\u30fc\u30ab\u30b9\u3057\u3066\u3044\u307e\u3059\u3002<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u4e2d\u3001\u3053\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u306f <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">code<\/span> \u306b\u306f<span style=\"font-weight: 400;\">\u5024<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\"> 5 <\/span><span style=\"font-weight: 400;\"> \u3092\u6307\u5b9a\u3057\u3001<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">args<\/span><span style=\"font-weight: 400;\"> \u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u72b6\u6cc1\u3092\u77e5\u3089\u305b\u308b\u5024\u3092\u6307\u5b9a\u3057\u305f JSON \u30c7\u30fc\u30bf\u3067\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u308a\u7d9a\u3051\u307e\u3059\u3002<\/span><\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"width: 17.691%; height: 72px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_kill<\/span><\/td>\n<td style=\"width: 81.6446%; height: 72px;\"><span style=\"font-weight: 400;\">Chrome \u30d6\u30e9\u30a6\u30b6\u30fc\u3068 Brave \u30d6\u30e9\u30a6\u30b6\u30fc\u306e\u30d7\u30ed\u30bb\u30b9\u3092\u7d42\u4e86\u3057\u307e\u3059\u3002\u7d42\u4e86\u3057\u305f\u5834\u5408\u3001<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">code<\/span><span style=\"font-weight: 400;\"> \u306b\u306f\u5024 <\/span><span style=\"font-weight: 400;\"> 6 <\/span>\u3092\u6307\u5b9a\u3057\u3001\u3053\u308c\u3089\u306e\u30d7\u30ed\u30bb\u30b9\u304c\u7d42\u4e86\u3057\u305f\u3053\u3068\u3092\u793a\u3059 <span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">args<\/span> \u5024\u3092\u6307\u5b9a\u3057\u3066 JSON \u3092\u9001\u4fe1\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"width: 17.691%; height: 72px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_any<\/span><\/td>\n<td style=\"width: 81.6446%; height: 72px;\"><span style=\"font-weight: 400;\">AnyDesk \u7528\u306e\u60aa\u610f\u306e\u3042\u308b\u30d0\u30a4\u30ca\u30ea\u30fc\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002AnyDesk \u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u306e\u524d\u306b\u3001<\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">code<\/span><span style=\"font-weight: 400;\"> \u306b\u306f\u5024 <\/span><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\"> 7 <\/span><span style=\"font-weight: 400;\"> \u3092\u6307\u5b9a\u3057\u3001<\/span><span style=\"font-weight: 400;\">\u88ab\u5bb3\u8005\u306e OS <\/span>\u3092\u793a\u3059 <span style=\"font-weight: 400;\">args<\/span><span style=\"font-weight: 400;\"> \u5024<\/span>\u3092\u542b\u3081\u305f JSON \u3092\u9001\u4fe1\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"width: 17.691%; height: 72px;\"><span style=\"font-weight: 400; font-family: 'courier new', courier, monospace;\">ssh_env<\/span><\/td>\n<td style=\"width: 81.6446%; height: 72px;\"><span style=\"font-weight: 400;\">\u7279\u5b9a\u306e\u30d5\u30a9\u30eb\u30c0\u30fc (Windows\u306e\u5834\u5408\u306f \"Documents \"\u3068 \"Downloads\"\u3001\u305d\u306e\u307b\u304b\u306e\u5834\u5408\u306f <span style=\"font-family: 'courier new', courier, monospace;\">\/home<\/span> \u3068 <span style=\"font-family: 'courier new', courier, monospace;\">\/Volumes<\/span>) \u304b\u3089\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u53ce\u96c6\u3057\u3066 FTP \u30b5\u30fc\u30d0\u30fc\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"color: #999999; font-size: 8pt;\"><em>\u8868 4. InvisibleFerret \u306e\u30b3\u30de\u30f3\u30c9<\/em><\/span><\/p>\n<p>InvisibleFerret \u306f\u30bf\u30b9\u30af\u3092\u7d42\u3048\u308b\u3068\u7d50\u679c\u3092 C2 \u30b5\u30fc\u30d0\u30fc\u306b\u30ec\u30dd\u30fc\u30c8\u3057\u307e\u3059\u3002\u30ec\u30dd\u30fc\u30c8\u306e\u3055\u3044\u306f\u3001\u8868 4 \u3067\u8aac\u660e\u3057\u305f\u3082\u306e\u3068\u540c\u3058 JSON \u306e <span style=\"font-family: 'courier new', courier, monospace;\">code<\/span> \u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u3068 <span style=\"font-family: 'courier new', courier, monospace;\">args<\/span> \u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u306b\u7279\u5b9a\u306e\u5024\u3092\u8a2d\u5b9a\u3057\u3066\u4f7f\u3044\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-131342-_alvzdpef0m\"><\/a><strong>\u30ad\u30fc\u30ed\u30ac\u30fc\u6a5f\u80fd<\/strong><\/h4>\n<p>InvisibleFerret \u306f\u307e\u305f\u3001\u30ad\u30fc\u30ed\u30ac\u30fc\u3092\u8d77\u52d5\u3057\u3001\u30ad\u30fc\u30dc\u30fc\u30c9\u3001\u30de\u30a6\u30b9\u3001\u30af\u30ea\u30c3\u30d7\u30dc\u30fc\u30c9\u306e\u30c7\u30fc\u30bf\u3092\u7d99\u7d9a\u7684\u306b\u53ce\u96c6\u3057\u307e\u3059\u3002\u3053\u306e\u30c7\u30fc\u30bf\u306f\u3001\u524d\u8ff0\u306e <span style=\"font-family: 'courier new', courier, monospace;\">ssh_clip<\/span> \u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3063\u3066 C2 \u30b5\u30fc\u30d0\u30fc\u304b\u3089\u3044\u3064\u3067\u3082\u8981\u6c42\u3067\u304d\u307e\u3059\u3002<\/p>\n<h4><a id=\"post-131342-_mvwy0nb32nrc\"><\/a><strong>\u30d6\u30e9\u30a6\u30b6\u30fc \u30b9\u30c6\u30a3\u30fc\u30e9\u30fc\u6a5f\u80fd<\/strong><\/h4>\n<p>Python \u30d9\u30fc\u30b9\u306e InvisibleFerret \u306f\u3001Windows\u3001Linux\u3001macOS \u4e0a\u306e\u4e00\u822c\u7684\u306aWeb \u30d6\u30e9\u30a6\u30b6\u30fc\u3092\u6a19\u7684\u306b\u3057\u3001\u30ed\u30b0\u30a4\u30f3 \u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u306a\u3069\u306e\u6a5f\u5fae\u30c7\u30fc\u30bf\u3092\u7a83\u53d6\u3057\u307e\u3059\u3002\u3053\u306e\u6a5f\u80fd\u306b\u306f\u3001\u30d6\u30e9\u30a6\u30b6\u30fc\u306e\u30ed\u30b0\u30a4\u30f3 \u30c7\u30fc\u30bf\u306e\u53d6\u5f97\u3001\u60c5\u5831\u306e\u5fa9\u53f7\u3001\u88ab\u5bb3\u8005\u306e\u30ed\u30b0\u30a4\u30f3 \u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u306e\u7a83\u53d6\u304c\u542b\u307e\u308c\u307e\u3059\u3002InvisibleFerret \u306f\u88ab\u5bb3\u8005\u304c\u4f7f\u3063\u305f\u30af\u30ec\u30b8\u30c3\u30c8 \u30ab\u30fc\u30c9\u60c5\u5831\u3092 Web \u30d6\u30e9\u30a6\u30b6\u30fc\u7d4c\u7531\u3067\u53d6\u5f97\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u60c5\u5831\u3092\u53ce\u96c6\u5f8c\u3001InvisibleFerret \u306f\u3001\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u8868\u3059\u3055\u307e\u3056\u307e\u306a\u30ad\u30fc\u3092\u6301\u3064 JSON \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3092\u4f7f\u3063\u3066\u3001\u30c7\u30fc\u30bf\u3092C2 \u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3057\u307e\u3059 (\u56f3 8)\u3002<\/p>\n<figure id=\"attachment_131309\" aria-describedby=\"caption-attachment-131309\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131309 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-8.png\" alt=\"\u753b\u50cf 8 \u306f\u3001\u76d7\u307e\u308c\u305f\u30d6\u30e9\u30a6\u30b6\u30fc \u30c7\u30fc\u30bf\u3092\u9001\u4fe1\u3059\u308b\u3055\u3044\u306b\u4f7f\u308f\u308c\u308b JSON \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002 \" width=\"600\" height=\"146\" \/><figcaption id=\"caption-attachment-131309\" class=\"wp-caption-text\">\u56f3 8. \u76d7\u3093\u3060\u30d6\u30e9\u30a6\u30b6\u30fc \u30c7\u30fc\u30bf\u3092\u9001\u4fe1\u3059\u308b\u3055\u3044\u306b\u4f7f\u3046 JSON \u30d5\u30a9\u30fc\u30de\u30c3\u30c8<\/figcaption><\/figure>\n<h4><a id=\"post-131342-_ldgvsjv8n8ks\"><\/a><strong>\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7 \u30de\u30eb\u30a6\u30a7\u30a2 AnyDesk<\/strong><\/h4>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">ssh_any<\/span> \u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3059\u308b\u3068\u3001InvisibleFerret \u306f\u4ee5\u4e0b\u306e URL \u30d1\u30bf\u30fc\u30f3\u3092\u4f7f\u3063\u3066\u8ffd\u52a0\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">http:\/\/&lt;c2_server&gt;:1224\/adc\/&lt;campaign_id&gt;<\/span><\/li>\n<\/ul>\n<p>\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u4ee5\u4e0b\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u3067 C2 \u30b5\u30fc\u30d0\u30fc\u306b\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">any_&lt;campaign_id&gt;.py<\/span><\/li>\n<\/ul>\n<p>InvisibleFerret \u306f\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30c7\u30a3\u30b9\u30af\u4e0a\u306e\u4ee5\u4e0b\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u306b\u4fdd\u5b58\u3057\u3066\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">.n2\/adc<\/span><\/li>\n<\/ul>\n<p>\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u3001InvisibleFerret \u7528\u306e\u307b\u304b\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u78ba\u8a8d\u3055\u308c\u305f\u3082\u306e\u3068\u540c\u3058\u3088\u3046\u306a\u96e3\u8aad\u5316\u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u88ab\u5bb3\u8005\u306e\u30db\u30b9\u30c8\u306b AnyDesk \u30d0\u30a4\u30ca\u30ea\u30fc\u304c\u307e\u3060\u5b58\u5728\u3057\u306a\u3044\u5834\u5408\u306f\u3001C2 \u30b5\u30fc\u30d0\u30fc\u304b\u3089 AnyDesk \u30d0\u30a4\u30ca\u30ea\u30fc\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u306b\u3088\u308a\u3001AnyDesk \u306e\u69cb\u6210\u304c\u66f4\u65b0\u3055\u308c\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u304c\u3059\u3067\u306b\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u5834\u5408\u306f\u518d\u8d77\u52d5\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>Contagious Interview \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u95a2\u9023\u306e\u30a4\u30f3\u30d5\u30e9\u3092\u8abf\u3079\u3066\u3044\u305f\u3068\u304d\u3001\u5225\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u4f7f\u308f\u308c\u3066\u3044\u305f\u30d5\u30a1\u30a4\u30eb\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u3053\u306e\u5225\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u300cWagemole\u300d\u3068\u540d\u4ed8\u3051\u3001CL-STA-0241\u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-131342-_xverrwpmy9xe\"><\/a><strong>CL-STA-0241: Wagemole<\/strong><\/h2>\n<p>Contagious Interview (CL-STA-0240) \u95a2\u9023\u306e GitHub \u30a4\u30f3\u30d5\u30e9\u3092\u8ef8\u306b\u8abf\u67fb\u7bc4\u56f2\u3092\u5e83\u3052\u305f\u3068\u3053\u308d\u3001\u5225\u306e GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u306e GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306b\u8aa4\u3063\u3066\u30d5\u30a1\u30a4\u30eb\u304c\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u306e\u3092\u898b\u3064\u3051\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306b\u306f\u4ee5\u4e0b\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li>\u3055\u307e\u3056\u307e\u306a\u56fd\u7c4d\u306e\u4eba\u7269\u306b\u306a\u308a\u3059\u307e\u3057\u305f\u507d\u306e\u8eab\u5206\u8a3c\u3092\u4f7f\u3063\u305f\u5c65\u6b74\u66f8<\/li>\n<li>\u9762\u63a5\u306e\u60f3\u5b9a\u554f\u7b54\u96c6<\/li>\n<li>\u306a\u308a\u3059\u307e\u3057\u305f\u8eab\u5206\u8a3c\u306e\u500b\u4eba\u60c5\u5831\u3092\u542b\u3080\u3001\u81ea\u5df1\u7d39\u4ecb\u7528\u306e\u53f0\u672c<\/li>\n<li>\u7c73\u56fd\u4f01\u696d\u306e IT \u6c42\u4eba\u5e83\u544a\u306e\u30b3\u30d4\u30fc<\/li>\n<li>\u76d7\u307e\u308c\u305f\u7c73\u56fd\u6c38\u4f4f\u6a29\u30ab\u30fc\u30c9\u306e\u30b9\u30ad\u30e3\u30f3\u306e\u30b3\u30d4\u30fc<\/li>\n<li>\u672a\u78ba\u8a8d\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u8ca9\u58f2\u8005\u306e\u9023\u7d61\u5148\u30ea\u30b9\u30c8<\/li>\n<\/ul>\n<p>\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c 2022 \u5e74 8 \u6708\u306b\u59cb\u307e\u3063\u305f\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u3066\u3001\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u306f 2022 \u5e74 12 \u6708\u521d\u65ec\u307e\u3067\u7d9a\u3044\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3053\u306e\u4e00\u9023\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u66f4\u65b0\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u305b\u3093\u304c\u3001\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u73fe\u5728\u9032\u884c\u5f62\u306e\u8105\u5a01\u3067\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u507d\u306e\u8eab\u5206\u8a3c\u3092\u4f7f\u3063\u3066 IT \u7cfb\u306e\u30ea\u30e2\u30fc\u30c8 \u30ef\u30fc\u30af\u306b\u5fdc\u52df\u3059\u308b\u5225\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u793a\u3059\u3082\u306e\u3067\u3001\u79c1\u305f\u3061\u306f\u3053\u308c\u3092 Wagemole (\u8cc3\u91d1\u30b9\u30d1\u30a4) \u3068\u547c\u3093\u3067\u3044\u307e\u3059\u3002\u3044\u304f\u3064\u304b\u306e\u6587\u66f8\u304b\u3089\u3001<a href=\"#post-131342-_xkx0jjh1l9jy\">\u3053\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u5317\u671d\u9bae\u306b\u95a2\u9023<\/a>\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30d5\u30a1\u30a4\u30eb\u306b\u542b\u307e\u308c\u3066\u3044\u305f\u5c65\u6b74\u66f8\u304b\u3089\u306f\u3001\u6a19\u7684\u3068\u306a\u3063\u305f\u306e\u304c\u5e45\u5e83\u3044\u7c73\u56fd\u4f01\u696d\u3084\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u306e\u6c42\u4eba\u5e02\u5834\u3067\u3042\u3063\u305f\u3053\u3068\u304c\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u304a\u305d\u3089\u304f\u3001\u5317\u671d\u9bae\u304c<a href=\"https:\/\/apnews.com\/article\/north-korea-weapons-program-it-workers-f3df7c120522b0581db5c0b9682ebc9b\" target=\"_blank\" rel=\"noopener\">\u30ea\u30e2\u30fc\u30c8 \u30ef\u30fc\u30ab\u30fc\u3092\u4f7f\u3063\u3066\u8cc3\u91d1\u3092\u5175\u5668\u30d7\u30ed\u30b0\u30e9\u30e0\u306b\u6d41\u7528\u3057\u3066\u3044\u308b<\/a>\u3068\u3044\u3046\u6700\u8fd1\u306e\u5831\u544a\u306b\u95a2\u9023\u3057\u3066\u3044\u308b\u3068\u601d\u308f\u308c\u307e\u3059\u3002<\/p>\n<p>\u4e0b\u306e\u56f3 9 \u306f\u5c65\u6b74\u66f8\u306e\u4e00\u4f8b\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_131311\" aria-describedby=\"caption-attachment-131311\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131311 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-9.png\" alt=\"\u753b\u50cf 9 \u306f\u3001\u6c42\u8077\u8005\u306e\u9854\u3092\u542b\u3080\u4e00\u90e8\u306e\u60c5\u5831\u3092\u4f0f\u305b\u3066\u3042\u308b\u5c65\u6b74\u66f8\u306e\u4f8b\u3067\u3059\u3002\u6280\u80fd\u306e\u4e00\u89a7\u3084\u5b8c\u5168\u306a\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u304c\u3042\u308a\u3001\u6c42\u8077\u8005\u306f\u30d6\u30ed\u30c3\u30af\u30c1\u30a7\u30fc\u30f3\u958b\u767a\u8005\u306e\u8077\u52d9\u3092\u5e0c\u671b\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"658\" \/><figcaption id=\"caption-attachment-131311\" class=\"wp-caption-text\">\u56f3 9. \u540c\u30a4\u30f3\u30d5\u30e9\u4e0a\u3067\u898b\u3064\u304b\u3063\u305f\u5c65\u6b74\u66f8\u306e\u4f8b<\/figcaption><\/figure>\n<p>\u305d\u308c\u305e\u308c\u306e\u507d\u5c65\u6b74\u66f8\u306b\u306f\u500b\u4eba\u9023\u7d61\u7528\u306b\u7c73\u56fd\u306e\u500b\u5225\u306e\u96fb\u8a71\u756a\u53f7\u304c\u8a18\u8f09\u3055\u308c\u3066\u3044\u3066\u3001\u3068\u304f\u306b VoIP (Voice over Internet Protocol) \u306e\u756a\u53f7\u304c\u4f7f\u308f\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u306a\u304b\u306b\u306f LinkedIn \u306e\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u3084 GitHub \u30b3\u30f3\u30c6\u30f3\u30c4\u3078\u306e\u30ea\u30f3\u30af\u3092\u542b\u3080\u5c65\u6b74\u66f8\u3082\u3042\u308a\u307e\u3057\u305f\u3002\u56f3 10 \u306f\u3001\u3042\u308b\u6c42\u8077\u8005\u304c\u7ba1\u7406\u3057\u3066\u3044\u308b GitHub \u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_131313\" aria-describedby=\"caption-attachment-131313\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131313 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-10.png\" alt=\"\u753b\u50cf 10 \u306f\u3001\u3042\u308b\u6c42\u8077\u8005\u304c\u7ba1\u7406\u3057\u3066\u3044\u308b GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u5408\u8a08\u3067 1,108 \u4ef6\u306e\u8ca2\u732e\u304c\u3042\u308a\u307e\u3059\u3002\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u5199\u771f\u306f\u3068\u308a\u305f\u3066\u3066\u7279\u5fb4\u306e\u306a\u3044\u5b9d\u77f3\u306e\u753b\u50cf\u3067\u3059\u3002\u500b\u4eba\u60c5\u5831\u306e\u4e00\u90e8\u306f\u4f0f\u305b\u3066\u3042\u308a\u307e\u3059\u3002 \" width=\"900\" height=\"665\" \/><figcaption id=\"caption-attachment-131313\" class=\"wp-caption-text\">\u56f3 10. \u6c42\u8077\u8a50\u6b3a\u5e2b\u306e 1 \u4eba\u304c\u7ba1\u7406\u3059\u308b GitHub \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc<\/figcaption><\/figure>\n<p>\u3053\u308c\u3089\u306e GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u306f\u3088\u304f\u7ba1\u7406\u3055\u308c\u3066\u3044\u3066\u3001\u6d3b\u52d5\u5c65\u6b74\u3082\u9577\u304f\u3001\u983b\u7e41\u306b\u30b3\u30fc\u30c9\u304c\u66f4\u65b0\u3055\u308c\u3001\u307b\u304b\u306e\u958b\u767a\u8005\u3068\u306e\u4ea4\u6d41\u3082\u3042\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3064\u307e\u308a\u3053\u308c\u3089\u306e GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u306f\u307e\u3068\u3082\u306a\u30a2\u30ab\u30a6\u30f3\u30c8\u3068\u307b\u307c\u898b\u5206\u3051\u304c\u3064\u304d\u307e\u305b\u3093\u3002<\/p>\n<p>\u56f3 11 \u306b\u96fb\u8a71\u9762\u63a5\u306b\u5099\u3048\u305f\u53f0\u672c\u306e\u4e00\u90e8\u3092\u793a\u3057\u307e\u3059\u3002\u3053\u306e\u6587\u66f8\u304b\u3089\u306f\u3001\u5bfe\u8c61\u3068\u306a\u3063\u305f\u4ed5\u4e8b\u306f\u82e5\u5e72\u306f\u30aa\u30f3\u30b5\u30a4\u30c8\u3067\u3084\u308b\u3079\u304d\u3082\u306e\u3067\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u56f3 11 \u306b\u793a\u3059\u901a\u308a\u3001\u3053\u306e\u6c42\u8077\u8a50\u6b3a\u5e2b\u306f\u81ea\u5206\u306e\u62e0\u70b9\u306f\u7c73\u56fd\u3060\u3068\u4e3b\u5f35\u3057\u3001\u9762\u63a5\u5b98\u306b\u306f\u300c\u65b0\u578b\u30b3\u30ed\u30ca\u611f\u67d3\u75c7\u304c\u7406\u7531\u3067\u73fe\u5728\u306f\u6d77\u5916\u306b\u3044\u308b\u5bb6\u65cf\u3092\u8a2a\u306d\u3066\u56fd\u5916\u306b\u3044\u308b\u304c\u30ea\u30e2\u30fc\u30c8\u3067\u4ed5\u4e8b\u3092\u59cb\u3081\u3089\u308c\u308b\u300d\u3068\u4f1d\u3048\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_131315\" aria-describedby=\"caption-attachment-131315\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131315 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-11.png\" alt=\"\u753b\u50cf 11 \u306f\u9762\u63a5\u6e96\u5099\u7528\u66f8\u985e\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002[Common Questions]I flied to [redacted] several weeks ago. My parents got Covid and I decide to be with family members for awhile. Now, I am planning to go back to Los Angeles in 3 months. I am thinking that I could start work remotely right now, then I will be on board when I go back to LA. \" width=\"900\" height=\"181\" \/><figcaption id=\"caption-attachment-131315\" class=\"wp-caption-text\">\u56f3 11. \u9762\u63a5\u6e96\u5099\u7528\u306e\u53f0\u672c\u306e\u4e00\u90e8<\/figcaption><\/figure>\n<p>\u3053\u308c\u3089\u306e\u66f8\u985e\u306f\u3001\u7c73\u56fd\u62e0\u70b9\u4f01\u696d\u306e\u30ea\u30e2\u30fc\u30c8 IT \u6c42\u4eba\u306b\u9650\u5b9a\u3055\u308c\u308b\u3082\u306e\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u3044\u304f\u3064\u304b\u306e\u6587\u66f8\u304b\u3089\u3001\u3053\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u8907\u6570\u306e\u6c42\u4eba\u5e02\u5834\u3067\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u306e\u4ed5\u4e8b\u3082\u63a2\u3057\u3066\u304a\u308a\u3001\u30a2\u30d5\u30ea\u30ab\u3092\u542b\u3080\u3001\u3055\u3089\u306b\u5e83\u304f\u30b0\u30ed\u30fc\u30d0\u30eb\u306a\u6c42\u4eba\u5e02\u5834\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u6c42\u8077\u8a50\u6b3a\u5e2b\u306f\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u306e Web \u30b5\u30a4\u30c8\u3001\u30bd\u30fc\u30b9 \u30b3\u30fc\u30c9 \u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u3001\u6c42\u4eba\u4ef2\u4ecb\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u7528\u306b\u8907\u6570\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u7ba1\u7406\u3057\u3066\u3044\u307e\u3059\u3002\u4ed5\u4e8b\u306e\u5165\u672d\u3067\u52dd\u3061\u3001\u6b63\u4f53\u3092\u96a0\u3059\u305f\u3081\u306e\u6226\u8853\u3068\u3057\u3066\u3001\u5f7c\u3089\u306f\u30a2\u30ab\u30a6\u30f3\u30c8\u8ca9\u58f2\u30de\u30fc\u30b1\u30c3\u30c8\u30d7\u30ec\u30a4\u30b9\u3067\u8a55\u4fa1\u306e\u9ad8\u3044\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u8cfc\u5165\u306a\u3044\u3057\u30ec\u30f3\u30bf\u30eb\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u56f3 12 \u306f\u3001\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u308f\u308c\u305f\u6c42\u8077\u8a50\u6b3a\u5e2b\u306e 1 \u4eba\u304c\u9001\u3063\u305f\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u6c42\u4eba\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u4e0a\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u3067\u3059\u3002\u56f3 13 \u306f\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u6c42\u4eba\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3067\u8a55\u4fa1\u304c\u9ad8\u3044\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u8cfc\u5165\u3084\u30ec\u30f3\u30bf\u30eb\u3092\u6c42\u3081\u308b\u3001\u30a2\u30f3\u30c0\u30fc\u30b0\u30e9\u30a6\u30f3\u30c9 \u30de\u30fc\u30b1\u30c3\u30c8\u30d7\u30ec\u30a4\u30b9\u3067\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u3084\u308a\u3068\u308a\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_131317\" aria-describedby=\"caption-attachment-131317\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131317 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-12.png\" alt=\"\u753b\u50cf 12 \u306f\u3042\u308b\u52b4\u50cd\u8005\u304b\u3089\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u60c5\u5831\u306e\u4e00\u90e8\u306f\u5272\u611b\u3057\u3066\u3042\u308a\u307e\u3059\u3002Dear client. I have checked your job description and I am really interested in your project. As a senior developer, I have 5+ years of experience of python development. As you can see my profile, I have finished very difficult type of app a few days ago and other developers can't solve this app but I have done. I have already published 10+ apps like you want to so I am sure that I can finish your job perfectly. If you want to hire a reliable developer, please contact me. I am waiting for your contact. I'll do my best for you. Thank you. Best regards. \u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306e\u307b\u304b\u306e\u8a00\u8a9e\u306e\u4e00\u90e8\u306f\u30b9\u30da\u30a4\u30f3\u8a9e\u3067\u3059\u3002\" width=\"500\" height=\"588\" \/><figcaption id=\"caption-attachment-131317\" class=\"wp-caption-text\">\u56f3 12. \u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u6c42\u4eba\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3067\u4ed5\u4e8b\u3092\u63a2\u3059\u30a2\u30af\u30bf\u30fc<\/figcaption><\/figure>\n<figure id=\"attachment_131319\" aria-describedby=\"caption-attachment-131319\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-131319 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/11\/word-image-131292-13.png\" alt=\"\u753b\u50cf 13 \u306f\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u8ca9\u58f2\u3059\u308b\u30a2\u30f3\u30c0\u30fc\u30b0\u30e9\u30a6\u30f3\u30c9 \u30de\u30fc\u30b1\u30c3\u30c8\u3067\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u4e00\u90e8\u306e\u60c5\u5831\u306f\u4f0f\u305b\u3089\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306f\u3059\u3079\u3066\u3001Andrew JackSon \u304c 2023 \u5e74 2 \u6708 9 \u65e5\u306b\u6295\u7a3f\u3057\u305f\u3082\u306e\u3067\u3059\u3002 \" width=\"900\" height=\"666\" \/><figcaption id=\"caption-attachment-131319\" class=\"wp-caption-text\">\u56f3 13. \u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u6c42\u4eba\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u7528\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u6c42\u3081\u308b\u30a2\u30f3\u30c0\u30fc\u30b0\u30e9\u30a6\u30f3\u30c9 \u30de\u30fc\u30b1\u30c3\u30c8\u306e\u30e1\u30c3\u30bb\u30fc\u30b8<\/figcaption><\/figure>\n<p>\u3053\u306e\u30a4\u30f3\u30d5\u30e9\u306b\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u305f\u7c73\u56fd\u306e\u6c42\u4eba\u5e83\u544a\u30b3\u30d4\u30fc\u306e\u306a\u304b\u3067\u4e00\u756a\u591a\u304b\u3063\u305f\u306e\u306f IT \u3068\u63a1\u7528\u6d3b\u52d5\u306b\u304b\u304b\u308f\u308b\u3082\u306e\u3067\u3057\u305f\u3002IT \u30b5\u30fc\u30d3\u30b9\u3084\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u7cfb\u306e\u6c42\u4eba\u306f\u3001Wagemole \u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u3088\u308b\u4e0b\u6d41\u30b5\u30d7\u30e9\u30a4\u30c1\u30a7\u30fc\u30f3\u3078\u306e\u653b\u6483\u6a5f\u4f1a\u3092\u5e83\u3052\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u307e\u305f\u3001\u63a1\u7528\u6d3b\u52d5\u306e\u4ed5\u4e8b\u306f\u3001Wagemole \u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u5229\u7528\u53ef\u80fd\u306a\u6c42\u8077\u8005\u306e\u8eab\u5206\u8a3c\u3084\u5c65\u6b74\u66f8\u306a\u3069\u3001\u500b\u4eba\u306e\u8eab\u5206\u8a3c\u8cc7\u6599\u3092\u653b\u6483\u8005\u304c\u5165\u624b\u3059\u308b\u6a5f\u4f1a\u3092\u5e83\u3052\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-131342-_xkx0jjh1l9jy\"><\/a><strong>\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30b7\u30e7\u30f3 (\u5e30\u5c5e)<\/strong><\/h2>\n<p>\u300cContagious Interview\u300d (CL-STA-0420) \u3068\u300cWagemole\u300d (CL-STA-0421) \u306e\u4e21\u65b9\u3067\u89b3\u5bdf\u3055\u308c\u305f\u6226\u8853\u30fb\u6280\u8853\u30fb\u624b\u9806 (TTP) \u306f\u3001\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u306b\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8 (\u5e30\u5c5e) \u3055\u308c\u305f\u904e\u53bb\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u4e00\u81f4\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30b7\u30e7\u30f3\u306e\u78ba\u5ea6\u306f 2 \u3064\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u7570\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Wagemole \u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u3064\u3044\u3066\u306f\u3001\u79c1\u305f\u3061\u304c\u767a\u898b\u3057\u305f\u6587\u66f8\u306e\u3044\u304f\u3064\u304b\u306b\u3001\u5317\u671d\u9bae\u3092\u3088\u308a\u6c7a\u5b9a\u7684\u306b\u6307\u3057\u793a\u3059\u60c5\u5831\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u6587\u66f8\u306b\u95a2\u9023\u3059\u308b\u30d1\u30b9\u30ef\u30fc\u30c9\u306e\u591a\u304f\u306f US \u30ad\u30fc\u30dc\u30fc\u30c9\u3067\u5165\u529b\u3055\u308c\u305f\u97d3\u56fd\u8a9e\u3067\u4f5c\u3089\u308c\u3066\u304a\u308a\u3001\u30d1\u30b9\u30ef\u30fc\u30c9\u306e\u4e2d\u306b\u306f\u5317\u671d\u9bae\u3067\u3057\u304b\u4f7f\u308f\u308c\u306a\u3044\u5358\u8a9e\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u97d3\u56fd\u8a9e\u306e\u30ad\u30fc\u30dc\u30fc\u30c9\u8a00\u8a9e\u8a2d\u5b9a\u306f\u3001\u3053\u308c\u3089\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u4f7f\u3046\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u4e0a\u3067\u3082\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u6587\u66f8\u306f\u3001<a href=\"https:\/\/www.state.gov\/guidance-on-the-democratic-peoples-republic-of-korea-information-technology-workers\/\" target=\"_blank\" rel=\"noopener\">\u7c73\u56fd\u653f\u5e9c<\/a>\u3084 <a href=\"https:\/\/ofac.treasury.gov\/media\/923126\/download?inline\" target=\"_blank\" rel=\"noopener\">FBI \u306e\u767a\u8868<\/a>\u306b\u57fa\u3065\u3044\u3066\u591a\u304f\u306e\u30e1\u30c7\u30a3\u30a2\u304c\u5831\u3058\u305f\u3082\u306e\u3068\u540c\u69d8\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u7406\u7531\u304b\u3089\u3001\u79c1\u305f\u3061\u306f Wagemole \u304c\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u306b\u5e30\u5c5e\u3059\u308b\u3082\u306e\u3068\u9ad8\u3044\u78ba\u5ea6\u3067\u8a55\u4fa1\u3057\u3001\u3053\u308c\u3092 CL-STA-0241 \u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Contagious Interview \u3082\u307e\u305f\u3001\u5317\u671d\u9bae\u7cfb\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u3082\u3064\u9855\u8457\u306a\u7279\u5fb4\u3092\u5099\u3048\u3066\u3044\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u5317\u671d\u9bae\u306e\u3042\u308b\u30b0\u30eb\u30fc\u30d7\u306f\u4ee5\u524d\u3001<a href=\"https:\/\/www.pcmag.com\/news\/north-korean-hackers-posing-as-facebook-recruiters-hit-job-hunters-with\" target=\"_blank\" rel=\"noopener\">Meta \u306e\u6c42\u4eba\u62c5\u5f53\u8005\u3092\u88c5\u3044<\/a>\u3001\u540c\u69d8\u306e\u624b\u53e3\u3067\u6c42\u8077\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u611f\u67d3\u3055\u305b\u3066\u3044\u307e\u3057\u305f\u3002\u5317\u671d\u9bae\u306eAPT\u300cLazarus Group\u300d\u304c\u5b9f\u884c\u3057\u305f\u300c<a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/lazarus-dream-job-chemical\" target=\"_blank\" rel=\"noopener\">Operation Dream Job<\/a>\u300d\u3067\u306f\u3001\u30bd\u30fc\u30b7\u30e3\u30eb \u30e1\u30c7\u30a3\u30a2\u3092\u5229\u7528\u3057\u3066\u88ab\u5bb3\u8005\u3092\u9a19\u3057\u3001\u507d\u306e\u5c31\u8077\u9762\u63a5\u306e\u4e00\u74b0\u3068\u3057\u3066<a href=\"https:\/\/thehackernews.com\/2023\/10\/lazarus-group-targeting-defense-experts.html\" target=\"_blank\" rel=\"noopener\">\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u5316\u3055\u308c\u305f VNC \u30a2\u30d7\u30ea\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u305b\u305f<\/a>\u3053\u3068\u304c\u5831\u544a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u30b0\u30eb\u30fc\u30d7\u306f\u3001\u6f5c\u5728\u7684\u88ab\u5bb3\u8005\u3092\u30d0\u30c3\u30af\u30c9\u30a2\u578b\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u611f\u67d3\u3055\u305b\u308b\u305f\u3081\u3001\u3057\u3070\u3057\u3070<a href=\"https:\/\/www.menlosecurity.com\/blog\/template-injection-attacks-part-3-following-the-bread-crumbs-to-north-korea\/\" target=\"_blank\" rel=\"noopener\">\u63a1\u7528\u62c5\u5f53\u8005\u3092\u88c5\u3063\u3066<\/a>\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>Contagious Interview \u306e\u8abf\u67fb\u904e\u7a0b\u3067\u306f\u3001BeaverTail \u3068 InvisibleFerret \u306e\u958b\u767a\u8005\u304c\u3001Wagemole \u3068\u76f4\u63a5\u306e\u95a2\u9023\u304c\u3042\u308b\u3079\u3064\u306e GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u3068\u3084\u308a\u3068\u308a\u3057\u305f\u308a\u3001\u5171\u540c\u4f5c\u696d\u3092\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3059\u6307\u6a19\u3082\u79c1\u305f\u3061\u306f\u89b3\u6e2c\u3057\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3001Contagious Interview \u306e\u80cc\u5f8c\u306b\u3044\u308b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3092 CL-STA-0240 \u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u304a\u308a\u3001\u3053\u306e\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3082\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3067\u3042\u308b\u3068\u4e2d\u7a0b\u5ea6\u306e\u78ba\u5ea6\u3067\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8 (\u5e30\u5c5e) \u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u5206\u6790\u306b\u9451\u307f\u3001\u79c1\u305f\u3061\u306f\u4e21\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306b\u3088\u308b\u3082\u306e\u3067\u3042\u308b\u3068\u3001\u4e2d\u7a0b\u5ea6\u306e\u78ba\u5ea6\u3067\u30a2\u30c8\u30ea\u30d3\u30e5\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-131342-_lampclrzzfrp\"><\/a><strong>\u7d50\u8ad6<\/strong><\/h2>\n<p>Unit 42 \u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u304c\u81ea\u793e\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u304b\u3089\u4e0d\u5be9\u306a\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8abf\u67fb\u3057\u3066\u3044\u305f\u3068\u3053\u308d\u3001Contagious Interview\u3001Wagemole \u3068\u3044\u3046 2 \u3064\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u305d\u308c\u305e\u308c CL-STA-0240\u3001CL-STA-0241 \u3068\u3057\u3066\u8ffd\u8de1\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u904e\u7a0b\u3067\u306f Contagious Interview \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u308f\u308c\u305f 2 \u3064\u306e\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u304c\u898b\u3064\u304b\u308a\u3001\u79c1\u305f\u3061\u306f\u3053\u308c\u3092 BeaverTail\u3001InvisibleFerret \u3068\u540d\u4ed8\u3051\u307e\u3057\u305f\u3002<\/p>\n<p>\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u306f\u3057\u3070\u3057\u3070\u3001\u30b5\u30d7\u30e9\u30a4\u30c1\u30a7\u30fc\u30f3\u653b\u6483\u306b\u304a\u3051\u308b<a href=\"https:\/\/blog.sonatype.com\/why-developers-are-becoming-the-weakest-link-in-supply-chain-attacks\" target=\"_blank\" rel=\"noopener\">\u6700\u3082\u5f31\u3044\u30ea\u30f3\u30af<\/a>\u3067\u3059\u3002\u307e\u305f<a href=\"https:\/\/www.shrm.org\/hr-today\/news\/hr-news\/pages\/beware-fraudulent-job-postings-aim-to-steal-your-money-identity-.aspx\" target=\"_blank\" rel=\"noopener\">\u6c42\u4eba\u8a50\u6b3a<\/a>\u306f\u5f15\u304d\u7d9a\u304d\u61f8\u5ff5\u4e8b\u9805\u3067\u3001Contagious Interview \u306b\u3088\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u7d9a\u304f\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u307e\u305f\u3001Wagemole \u306f\u3001\u6a19\u7684\u4f01\u696d\u306b\u5185\u90e8\u8105\u5a01\u3092\u9001\u308a\u8fbc\u3080\u6a5f\u4f1a\u3092\u63d0\u4f9b\u3059\u308b\u3082\u306e\u3067\u3059\u3002\u79c1\u305f\u3061\u306f\u3053\u308c\u3089\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u542b\u3080\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304b\u3089\u306e\u3055\u3089\u306a\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u3064\u3044\u3066\u4eca\u5f8c\u3082\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u76e3\u8996\u3092\u7d9a\u3051\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-131342-_ekxhltnxpvpw\"><\/a>\u63a8\u5968\u4e8b\u9805\u3068\u4fdd\u8b77<\/h2>\n<p>\u3053\u308c\u3089\u306e\u8105\u5a01\u306b\u6709\u52b9\u306a\u6226\u7565\u3068\u306f\u3069\u306e\u3088\u3046\u306a\u3082\u306e\u3067\u3057\u3087\u3046\u304b\u3002Contagious Interview \u3092\u542b\u3080\u591a\u304f\u306e\u8105\u5a01\u306b\u3064\u3044\u3066\u3044\u3048\u3070\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u306f\u3001\u4f1a\u793e\u652f\u7d66\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u3092\u500b\u4eba\u306e\u6d3b\u52d5\u3084\u4ed5\u4e8b\u3068\u95a2\u4fc2\u306e\u306a\u3044\u5c31\u8077\u9762\u63a5\u306e\u3088\u3046\u306a\u6d3b\u52d5\u306b\u306f\u4f7f\u308f\u306a\u3044\u3088\u3046\u306b\u3057\u306a\u3051\u308c\u3070\u306a\u308a\u307e\u305b\u3093\u3002\u4f1a\u793e\u652f\u7d66\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u3067\u306e\u500b\u4eba\u7684\u6d3b\u52d5\u306f\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u30de\u30eb\u30a6\u30a7\u30a2\u7d4c\u7531\u3067\u4f01\u696d\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u6a5f\u4f1a\u3092\u63d0\u4f9b\u3057\u304b\u306d\u307e\u305b\u3093\u3002<\/p>\n<p>\u958b\u767a\u8005\u306f\u307e\u305f\u3001\u30ea\u30dd\u30b8\u30c8\u30ea\u30fc\u304c 1 \u3064\u3057\u304b\u306a\u304f\u3001\u66f4\u65b0\u306e\u307b\u3068\u3093\u3069\u306a\u3044 GitHub \u30a2\u30ab\u30a6\u30f3\u30c8\u3082\u7591\u3046\u3079\u304d\u3067\u3059\u3002\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u3057\u3070\u3057\u3070 GitHub \u306e\u3088\u3046\u306a\u7121\u6599\u30b5\u30fc\u30d3\u30b9\u3092\u60aa\u7528\u3057\u3066\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u914d\u5e03\u3057\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u8ab0\u3067\u3042\u3063\u3066\u3082\u3001\u51fa\u3069\u3053\u308d\u306e\u308f\u304b\u3089\u306a\u3044\u30d5\u30a1\u30a4\u30eb\u3092\u8077\u5834\u3084\u81ea\u5b85\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u306f\u3044\u3051\u307e\u305b\u3093\u3002<\/p>\n<p>\u6c42\u8077\u8005\u306f\u5341\u5206\u306a\u6ce8\u610f\u3092\u6255\u3044\u3001\u9762\u63a5\u3092\u7533\u3057\u51fa\u305f\u4f01\u696d\u306e\u5b58\u5728\u3068\u6b63\u5f53\u6027\u3092\u78ba\u8a8d\u3057\u3001\u9762\u63a5\u5b98\u304c\u5b9f\u969b\u306b\u540d\u4e57\u3063\u3066\u3044\u308b\u3068\u304a\u308a\u306e\u4f01\u696d\u306b\u52e4\u52d9\u3057\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3059\u3079\u304d\u3067\u3057\u3087\u3046\u3002\u307e\u305f\u3001\u4e00\u822c\u7684\u3067\u306a\u3044\u3088\u3046\u306a\u901a\u4fe1\u30bd\u30d5\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\/\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u305b\u305f\u308a\u3001\u9762\u63a5\u306e\u524d\u63d0\u6761\u4ef6\u3068\u3057\u3066\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 \u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3092\u6c42\u3081\u3066\u304f\u308b\u30b1\u30fc\u30b9\u306b\u3082\u6ce8\u610f\u3059\u308b\u306e\u304c\u8ce2\u660e\u3067\u3059\u3002<\/p>\n<p>Wagemole \u306b\u3064\u3044\u3066\u3044\u3048\u3070\u3001\u96c7\u7528\u8005\u306f\u5168\u5fdc\u52df\u8005\u3092\u5165\u5ff5\u306b\u8abf\u67fb\u3059\u3079\u304d\u3067\u3059\u3002<a href=\"https:\/\/www.npr.org\/2022\/03\/27\/1088140809\/fake-linkedin-profiles\" target=\"_blank\" rel=\"noopener\">\u4ed5\u4e8b\u95a2\u9023\u306e\u30bd\u30fc\u30b7\u30e3\u30eb\u30e1\u30c7\u30a3\u30a2 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0<\/a>\u3067\u306f\u3001\u507d\u306e ID \u304c<a href=\"https:\/\/www.npr.org\/2022\/03\/27\/1088140809\/fake-linkedin-profiles\" target=\"_blank\" rel=\"noopener\">\u307e\u3059\u307e\u3059\u61f8\u5ff5\u3055\u308c\u308b<\/a>\u3088\u3046\u306b\u306a\u3063\u3066\u304d\u3066\u304a\u308a\u3001\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306f\u30ea\u30e2\u30fc\u30c8\u30ef\u30fc\u30af\u7528\u306e\u507d\u540d\u3092\u7c21\u5358\u306b\u4f5c\u308a\u51fa\u305b\u307e\u3059\u3002\u5bfe\u9762\u3067\u306e\u9762\u63a5\u304c\u96e3\u3057\u3044\u5834\u5408\u306f\u3001\u96fb\u8a71\u4f1a\u8b70\u3067\u6c42\u8077\u8005\u3068\u306e\u9762\u63a5\u3092\u884c\u3044\u307e\u3057\u3087\u3046\u3002\u30aa\u30f3\u30b5\u30a4\u30c8\u306e\u4ed5\u4e8b\u306b\u5fdc\u52df\u3057\u3001\u305d\u306e\u6642\u70b9\u3067\u306f\u305d\u306e\u5730\u57df\u3092\u96e2\u308c\u3066\u3044\u308b\u3068\u8ff0\u3079\u3001\u305d\u306e\u5f8c\u3059\u3050\u306b\u30ea\u30e2\u30fc\u30c8\u30ef\u30fc\u30af\u304c\u53ef\u80fd\u3068\u7533\u3057\u51fa\u308b\u4eba\u306b\u306f\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002\u30ea\u30e2\u30fc\u30c8\u306e\u307f\u306e\u8077\u7a2e\u3067\u3042\u308c\u3070\u3001\u96c7\u7528\u8005\u306f\u63a1\u7528\u904e\u7a0b\u3067\u6c42\u8077\u8005\u306b\u306a\u306b\u304b\u666e\u901a\u3067\u306a\u3044\u3068\u3053\u308d\u304c\u898b\u3089\u308c\u306a\u3044\u304b\u3092\u7591\u3046\u3079\u304d\u3067\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-wildfire\" target=\"_blank\" rel=\"noopener\">Advanced WildFire<\/a>\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-threat-prevention\" target=\"_blank\" rel=\"noopener\">Advanced Threat Prevention<\/a>\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\">Advanced URL Filtering<\/a> \u306a\u3069\u306e<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/security-subscriptions\" target=\"_blank\" rel=\"noopener\">\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9<\/a>\u3092\u6709\u52b9\u306b\u3057\u305f<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/next-generation-firewall\" target=\"_blank\" rel=\"noopener\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb (NGFW) <\/a> \u3068 <a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/cortex-xdr\" target=\"_blank\" rel=\"noopener\">Cortex XDR<\/a> \u306b\u3088\u308a\u3001\u672c\u7a3f\u3067\u53d6\u308a\u4e0a\u3052\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u304b\u3089\u306e\u4fdd\u8b77\u3092\u53d7\u3051\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/docs.paloaltonetworks.com\/ngfw\" target=\"_blank\" rel=\"noopener\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/a>\u3067 Advanced Threat Prevention \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u3092\u6709\u52b9\u306b\u3057\u3066\u3044\u308b\u5834\u5408\u3001Threat Prevention \u30b7\u30b0\u30cd\u30c1\u30e3\u30fc <\/span><a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=86817\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">86817<\/span><\/a><span style=\"font-weight: 400;\">\u3001 <\/span><a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=86818\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">86818<\/span><\/a><span style=\"font-weight: 400;\">\u3001<\/span><a href=\"https:\/\/threatvault.paloaltonetworks.com\/?query=86819\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">86819<\/span><\/a><span style=\"font-weight: 400;\"> \u3092\u901a\u3058\u305f\u30d9\u30b9\u30c8 \u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306b\u3088\u308a\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e C2 \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d6\u30ed\u30c3\u30af\u3067\u304d\u307e\u3059\u3002<\/span><\/p>\n<p>\u4fb5\u5bb3\u306e\u61f8\u5ff5\u304c\u3042\u308a\u5f0a\u793e\u306b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u95a2\u3059\u308b\u3054\u76f8\u8ac7\u3092\u306a\u3055\u308a\u305f\u3044\u5834\u5408\u306f\u3001<a href=\"https:\/\/start.paloaltonetworks.jp\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\">\u3053\u3061\u3089<\/a>\u306e\u554f\u3044\u5408\u308f\u305b\u30d5\u30a9\u30fc\u30e0\u304b\u3089\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001infojapan@paloaltonetworks.com \u307e\u3067\u96fb\u5b50\u30e1\u30fc\u30eb\u306b\u3066\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001\u4e0b\u8a18\u306e\u96fb\u8a71\u756a\u53f7\u307e\u3067\u304a\u554f\u3044\u5408\u308f\u305b\u304f\u3060\u3055\u3044(\u3054\u76f8\u8ac7\u306f\u5f0a\u793e\u88fd\u54c1\u306e\u304a\u5ba2\u69d8\u306b\u306f\u9650\u5b9a\u3055\u308c\u307e\u305b\u3093)\u3002<\/p>\n<ul>\n<li>\u5317\u7c73\u30d5\u30ea\u30fc\u30c0\u30a4\u30e4\u30eb: 866.486.4842 (866.4.UNIT42)<\/li>\n<li>EMEA: +31.20.299.3130<\/li>\n<li>APAC: +65.6983.8730<\/li>\n<li>\u65e5\u672c: (+81) 50-1790-0200<\/li>\n<\/ul>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u3001\u3053\u308c\u3089\u306e\u8abf\u67fb\u7d50\u679c\u3092 Cyber Threat Alliance (CTA: \u30b5\u30a4\u30d0\u30fc\u8105\u5a01\u30a2\u30e9\u30a4\u30a2\u30f3\u30b9) \u306e\u30e1\u30f3\u30d0\u30fc\u3068\u5171\u6709\u3057\u307e\u3057\u305f\u3002CTA \u306e\u30e1\u30f3\u30d0\u30fc\u306f\u3053\u306e\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u3063\u3066\u3001\u304a\u5ba2\u69d8\u306b\u4fdd\u8b77\u3092\u8fc5\u901f\u306b\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u3092\u4f53\u7cfb\u7684\u306b\u963b\u5bb3\u3067\u304d\u307e\u3059\u3002\u8a73\u7d30\u306f <a href=\"https:\/\/www.cyberthreatalliance.org\/\" target=\"_blank\" rel=\"noopener\">Cyber Threat Alliance<\/a> \u306b\u3066\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\uff61<\/p>\n<h2><a id=\"post-131342-_6n6fflyzyu52\"><\/a><strong>IoC (\u4fb5\u5bb3\u6307\u6a19)<\/strong><\/h2>\n<p>BeaverTail \u95a2\u9023\u30d5\u30a1\u30a4\u30eb\u306e SHA256 \u30cf\u30c3\u30b7\u30e5:<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">09a508e99b905330a3ebb7682c0dd5712e8eaa01a154b45a861ca12b6af29f86<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">0ce264819c7af1c485878ce795fd4727952157af7ffdea5f78bfd5b9d7806db1<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">104926c2c937b4597ea3493bccb7683ae812ef3c62c93a8fb008cfd64e05df59<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1123fea9d3a52989ec34041f791045c216d19db69d71e62aa6b24a22d3278ef9<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">121ca625f582add0527f888bb84b31920183e78c7476228091ff2199ec5d796b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">12c0f44a931b9d0d74a2892565363bedfa13bec8e48ff5cd2352dec968f407ee<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1b21556fc8ecb9f8169ba0482de857b1f8a5cb120b2f1ac7729febe76f1eea83<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1c905fa3a108f4c9bc0578882ce7af9682760b80af5232f130aa4f6463156b25<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1f9169492d18bffacebe951a22495d5dec81f35b0929da7783b5f094efef7b48<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2618a067e976f35f65aee95fecc9a8f52abea2fffd01e001f9865850435694cf<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">40645f9052e03fed3a33a7e0f58bc2c263eeae02cbc855b9308511f5dc134797<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">41a912d72ba9d5db95094be333f79b60cae943a2bd113e20cc171f86ebcb86cf<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4c465e6c8f43f7d13a1b887ff26d9a30f77cf65dd3b6f2e9f7fe36c8b6e83003<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4c605c6ef280b4ed5657fe97ba5b6106b10c4de02a40ae8c8907683129156efd<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">592769457001374fac7a44379282ddf28c2219020c88150e32853f7517896c34<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">61dff5cbad45b4fe0852ac95b96b62918742b9c90dd47c672cbe0d1dafccb6c5<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">6465f7ddc9cf8ab6714cbbd49e1fd472e19818a0babbaf3764e96552e179c9af<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">6b3fce8f2dad7e803418edd8dfc807b0252705c11ec77114498b01766102e849<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">700a582408cbda7ee79723b3969b8d10d67871ea31bb17c8ca3c0d94b481aa8c<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">709820850127201a17caab273e01bb36ce185b4c4f68cd1099110bb193c84c42<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">72ebfe69c69d2dd173bb92013ab44d895a3367f91f09e3f8d18acab44e37b26d<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">75f9f99295f86de85a8a2e4d73ed569bdb14a56a33d8240c72084f11752b207e<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">785f65f1853a08b0e86db5638fbd76e8cad5fe1359655716166a76035261c0be<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">7b718a46ae4de09ed4f2513df6e989afe1fbb1a0f59511a4689fac5e1745547d<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">7f8bb754f84a06b3e3617dd1138f07a918d11717cc63acaef8eb5c6d10101377<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">845d7978682fa19161281a35b62f4c447c477082a765d6fedb219877d0c90f31<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9867f99a66e64f6bce0cfca18b124194a683b8e4cb0ced44f7cb09386e1b528d<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9ae24a1912e4b0bab76ae97484b62ea22bdc27b7ea3e6472f18bf04ca66c87de<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">a2f8de3c5f5f6ecbf29c15afd43a7c13a5bf60023ecb371d39bcca6ceef1d2b7<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b5f151f0a4288e148fd10e19c78399f5b7bdff2ad66940fadd20d6eae4b7518b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b833f40b2f3439f317cf95980b29bddd2245d2acc2d5c11e9690dd2fa4289585<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c8c11f9b308ea5983eebd8a414684021cc4cc1f67e7398ff967a18ae202fb457<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ceb59dbaf58a8de02f9d5e9b497321db0a19b7db4affd5b8d1a7e40d62775f96<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">d8f065d264b1112d6ee3cf34979289e89d9dcb30d2a3bd78cc797a81d3d56f56<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">db6e75987cabdbfc21d0fdcb1cdae9887c492cab2b2ff1e529601a34a2abfd99<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">de42155e14a3c9c4d919316d6ba830229533de5063fcd110f53e2395ef3aa77a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">e2a940c7d19409e960427749519dc02293abe58a1bef78404a8390f818e40d08<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">fc9bb03998a89524ce5a0f859feb45806983aa4feb5f4d436107198ca869ff6f<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ff620bd560485c13a58a0de941bd3e52943036e6a05306e928f7c626998822fb<\/span><\/li>\n<\/ul>\n<p>BeaverTail\u306b\u3088\u3063\u3066\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u305fDLL\u30d5\u30a1\u30a4\u30eb\u306eSHA256\u30cf\u30c3\u30b7\u30e5:<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">da6d9c837c7c2531f0dbb7ce92bfceba4a9979953b6d49ed0862551d4b465adc<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2d8a5b637a95de3b709780898b7c3957f93d72806e87302f50c40fe850471a44<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c5a73896dc628c23a0b6210f50019445e2b8bfc9770f4c81e1fed097f02dfade<\/span><\/li>\n<\/ul>\n<p>InvisibleFerret \u95a2\u9023\u30d5\u30a1\u30a4\u30eb\u306e SHA256 \u30cf\u30c3\u30b7\u30e5:<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">35434e903bc3be183fa07b9e99d49c0b0b3d8cf6cbd383518e9a9d753d25b672<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">305de20b24e2662d47f06f16a5998ef933a5f8e92f9ecadf82129b484769bbac<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">39e7f94684129efce4d070d89e27508709f95fa55d9721f7b5d52f8b66b95ceb<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ab198c5a79cd9dedb271bd8a56ab568fbd91984f269f075d8b65173e749a8fde<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">444f56157dfcf9fc2347911a00fe9f3e3cb7971dccf67e1359d2f99a35aed88e<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4f50051ae3cb57f10506c6d69d7c9739c90ef21bfb82b14da6f4b407b6febac0<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">276863ee7b250419411b39c8539c31857752e54b53b072dffd0d3669f2914216<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">617c62da1c228ec6d264f89e375e9a594a72a714a9701ed3268aa4742925112b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c547b80e1026d562ac851be007792ae98ddc1f3f8776741a72035aca3f18d277<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">03185038cad7126663550d2290a14a166494fdd7ab0978b98667d64bda6e27cc<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2d300410a3edb77b5f1f0ff2aa2d378425d984f15028c35dfad20fc750a6671a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">92aeea4c32013b935cd8550a082aff1014d0cd2c2b7d861b43a344de83b68129<\/span><\/li>\n<\/ul>\n<p>Contagious Interview \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u95a2\u9023\u306e\u30c9\u30e1\u30a4\u30f3\u3068 IP \u30a2\u30c9\u30ec\u30b9:<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">blocktestingto[.]com<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">144.172.74[.]48<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">144.172.79[.]23<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">167.88.168[.]152<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">167.88.168[.]24<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">172.86.123[.]35<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">45.61.129[.]255<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">45.61.130[.]0<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">45.61.160[.]14<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">45.61.169[.]187<\/span><\/li>\n<\/ul>\n<p class=\"p1\"><i>2023-12-01 14:00 JST \u82f1\u8a9e\u7248\u66f4\u65b0\u65e5 2023-12-01 14:40 PST \u306e\u5185\u5bb9\u3092\u53cd\u6620 (\u88fd\u54c1\u306b\u3088\u308b\u4fdd\u8b77\u7bc4\u56f2\u3092\u62e1\u5927)\u00a0<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 Unit 42 \u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u6700\u8fd1\u3001\u5317\u671d\u9bae (\u671d\u9bae\u6c11\u4e3b\u4e3b\u7fa9\u4eba\u6c11\u5171\u548c\u56fd DPRK) \u306b\u7d10\u3065\u304f\u56fd\u5bb6\u652f\u63f4\u578b\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u304c\u95a2\u4e0e\u3057\u305f\u3001\u6c42\u8077\u6d3b\u52d5\u3092\u6a19\u7684\u3068\u3059\u308b 2 \u3064\u306e\u5225\u3005\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f 1 \u3064\u3081\u306e\u30ad\u30e3<\/p>\n","protected":false},"author":23,"featured_media":134314,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1974,4433,4428],"tags":[4499,4833,4841,4835,4837,4839],"product_categories":[4442,4443,4444,4446,4448,4456],"coauthors":[1025],"class_list":["post-131342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-ja","category-nation-state-cyberattacks-ja","category-threat-research-ja","tag-advanced-persistent-threat-ja","tag-beavertail-ja","tag-contagious-interview-ja","tag-dprk-ja","tag-north-korea-ja","tag-wagemole-ja","product_categories-advanced-threat-prevention-ja","product_categories-advanced-url-filtering-ja","product_categories-advanced-wildfire-ja","product_categories-cloud-delivered-security-services-ja","product_categories-cortex-xdr-ja","product_categories-next-generation-firewall-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3<\/title>\n<meta name=\"description\" content=\"\u5317\u671d\u9bae\u56fd\u5bb6\u652f\u63f4\u578bAPT\u306e\u7279\u5fb4\u3092\u3082\u30642\u3064\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u7c73\u56fd\u3092\u542b\u3080\u5168\u4e16\u754c\u306e\u6c42\u4eba\/\u6c42\u8077\u5e02\u5834\u3067\u4e0d\u6b63\u306a\u6c42\u4eba\/\u6c42\u8077\u6d3b\u52d5\u3092\u884c\u3044\u3001\u96c7\u7528\u8005\u3092\u88c5\u3063\u3066\u6c42\u8077\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u611f\u67d3\u3055\u305b\u3001\u6697\u53f7\u901a\u8ca8\u3084\u500b\u4eba\u60c5\u5831\u3092\u7a83\u53d6\u3057\u305f\u308a\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u3092\u88c5\u3063\u3066\u96c7\u7528\u8005\u3092\u9a19\u3057\u3001\u7d44\u7e54\u306b\u6f5c\u5165\u3057\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3\" \/>\n<meta property=\"og:description\" content=\"\u5317\u671d\u9bae\u56fd\u5bb6\u652f\u63f4\u578bAPT\u306e\u7279\u5fb4\u3092\u3082\u30642\u3064\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u7c73\u56fd\u3092\u542b\u3080\u5168\u4e16\u754c\u306e\u6c42\u4eba\/\u6c42\u8077\u5e02\u5834\u3067\u4e0d\u6b63\u306a\u6c42\u4eba\/\u6c42\u8077\u6d3b\u52d5\u3092\u884c\u3044\u3001\u96c7\u7528\u8005\u3092\u88c5\u3063\u3066\u6c42\u8077\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u611f\u67d3\u3055\u305b\u3001\u6697\u53f7\u901a\u8ca8\u3084\u500b\u4eba\u60c5\u5831\u3092\u7a83\u53d6\u3057\u305f\u308a\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u3092\u88c5\u3063\u3066\u96c7\u7528\u8005\u3092\u9a19\u3057\u3001\u7d44\u7e54\u306b\u6f5c\u5165\u3057\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-21T14:00:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-17T08:44:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Hactivism_Overview_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Unit 42\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3","description":"\u5317\u671d\u9bae\u56fd\u5bb6\u652f\u63f4\u578bAPT\u306e\u7279\u5fb4\u3092\u3082\u30642\u3064\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u7c73\u56fd\u3092\u542b\u3080\u5168\u4e16\u754c\u306e\u6c42\u4eba\/\u6c42\u8077\u5e02\u5834\u3067\u4e0d\u6b63\u306a\u6c42\u4eba\/\u6c42\u8077\u6d3b\u52d5\u3092\u884c\u3044\u3001\u96c7\u7528\u8005\u3092\u88c5\u3063\u3066\u6c42\u8077\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u611f\u67d3\u3055\u305b\u3001\u6697\u53f7\u901a\u8ca8\u3084\u500b\u4eba\u60c5\u5831\u3092\u7a83\u53d6\u3057\u305f\u308a\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u3092\u88c5\u3063\u3066\u96c7\u7528\u8005\u3092\u9a19\u3057\u3001\u7d44\u7e54\u306b\u6f5c\u5165\u3057\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/","og_locale":"ja_JP","og_type":"article","og_title":"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3","og_description":"\u5317\u671d\u9bae\u56fd\u5bb6\u652f\u63f4\u578bAPT\u306e\u7279\u5fb4\u3092\u3082\u30642\u3064\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u7c73\u56fd\u3092\u542b\u3080\u5168\u4e16\u754c\u306e\u6c42\u4eba\/\u6c42\u8077\u5e02\u5834\u3067\u4e0d\u6b63\u306a\u6c42\u4eba\/\u6c42\u8077\u6d3b\u52d5\u3092\u884c\u3044\u3001\u96c7\u7528\u8005\u3092\u88c5\u3063\u3066\u6c42\u8077\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u611f\u67d3\u3055\u305b\u3001\u6697\u53f7\u901a\u8ca8\u3084\u500b\u4eba\u60c5\u5831\u3092\u7a83\u53d6\u3057\u305f\u308a\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u3092\u88c5\u3063\u3066\u96c7\u7528\u8005\u3092\u9a19\u3057\u3001\u7d44\u7e54\u306b\u6f5c\u5165\u3057\u307e\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/","og_site_name":"Unit 42","article_published_time":"2023-11-21T14:00:06+00:00","article_modified_time":"2024-06-17T08:44:43+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Hactivism_Overview_1920x900.jpg","type":"image\/jpeg"}],"author":"Unit 42","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/"},"author":{"name":"Unit 42","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"headline":"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3","datePublished":"2023-11-21T14:00:06+00:00","dateModified":"2024-06-17T08:44:43+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/"},"wordCount":1561,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Hactivism_Overview_1920x900.jpg","keywords":["Advanced Persistent Threat","BeaverTail","Contagious Interview","DPRK","North Korea","Wagemole"],"articleSection":["\u30de\u30eb\u30a6\u30a7\u30a2","\u56fd\u5bb6\u652f\u63f4\u578b\u30b5\u30a4\u30d0\u30fc\u653b\u6483","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/","name":"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#primaryimage"},"thumbnailUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Hactivism_Overview_1920x900.jpg","datePublished":"2023-11-21T14:00:06+00:00","dateModified":"2024-06-17T08:44:43+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"description":"\u5317\u671d\u9bae\u56fd\u5bb6\u652f\u63f4\u578bAPT\u306e\u7279\u5fb4\u3092\u3082\u30642\u3064\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u7c73\u56fd\u3092\u542b\u3080\u5168\u4e16\u754c\u306e\u6c42\u4eba\/\u6c42\u8077\u5e02\u5834\u3067\u4e0d\u6b63\u306a\u6c42\u4eba\/\u6c42\u8077\u6d3b\u52d5\u3092\u884c\u3044\u3001\u96c7\u7528\u8005\u3092\u88c5\u3063\u3066\u6c42\u8077\u8005\u3092\u30de\u30eb\u30a6\u30a7\u30a2\u611f\u67d3\u3055\u305b\u3001\u6697\u53f7\u901a\u8ca8\u3084\u500b\u4eba\u60c5\u5831\u3092\u7a83\u53d6\u3057\u305f\u308a\u3001\u30d5\u30ea\u30fc\u30e9\u30f3\u30b9\u3092\u88c5\u3063\u3066\u96c7\u7528\u8005\u3092\u9a19\u3057\u3001\u7d44\u7e54\u306b\u6f5c\u5165\u3057\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#primaryimage","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Hactivism_Overview_1920x900.jpg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Hactivism_Overview_1920x900.jpg","width":1920,"height":900,"caption":"A vivid, close-up image of a digital screen displaying lines of programming code in white text with the word \"System\" prominently highlighted in the center as well as \"System Hack.\" The background consists of blurred blue and red digital binary code, creating a sense of depth and focusing on the highlighted text."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/two-campaigns-by-north-korea-bad-actors-target-job-hunters\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u6c42\u8077\u6226\u7dda\u7570\u72b6\u3042\u308a: \u5317\u671d\u9bae\u306e\u56fd\u5bb6\u652f\u63f4\u578b APT \u8105\u5a01\u30a2\u30af\u30bf\u30fc\u306e\u7279\u5fb4\u3092\u3082\u3064 2 \u3064\u306e\u6c42\u4eba\u30fb\u6c42\u8077\u30cf\u30c3\u30af \u30ad\u30e3\u30f3\u30da\u30fc\u30f3"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63","name":"Unit 42","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/4ffb3c2d260a0150fb91b3715442f8b3","url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Unit 42"},"url":"https:\/\/unit42.paloaltonetworks.com\/ja\/author\/unit42\/"}]}},"_links":{"self":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/131342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=131342"}],"version-history":[{"count":18,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/131342\/revisions"}],"predecessor-version":[{"id":135046,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/131342\/revisions\/135046"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134314"}],"wp:attachment":[{"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=131342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=131342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=131342"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=131342"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=131342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}