{"id":100066,"date":"2016-07-26T06:00:57","date_gmt":"2016-07-26T13:00:57","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=100066\/"},"modified":"2019-10-08T20:03:26","modified_gmt":"2019-10-09T03:03:26","slug":"unit-42-attack-delivers-9002-trojan-through-google-drive","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/","title":{"rendered":"Google Drive\u3092\u4ecb\u3057\u3066 9002 \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483"},"content":{"rendered":"<h2><strong>\u6982\u8981<\/strong><\/h2>\n<p>\u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google Drive\u304c\u63d0\u4f9b\u3059\u308b\u5171\u6709\u30d5\u30a1\u30a4\u30eb\u3068\u306e\u7d44\u307f\u5408\u308f\u305b\u306e\u5229\u7528\u306b\u3088\u3063\u30669002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304c\u914d\u4fe1\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u306b\u6c17\u4ed8\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u914d\u4fe1\u624b\u6cd5\u3067\u306f\u653b\u6483\u8005\u304c\u5236\u5fa1\u3057\u3066\u3044\u308b\u30b5\u30fc\u30d0\u3082\u4f7f\u308f\u308c\u307e\u3057\u305f\u3002\u30b5\u30fc\u30d0\u306f\u6a19\u7684\u306b\u3055\u308c\u305f\u96fb\u5b50\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u304c\u72d9\u3044\u901a\u308a\u306b\u30af\u30ea\u30c3\u30af\u3055\u308c\u305f\u304b\u8ffd\u8de1\u3059\u308b\u305f\u3081\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001\u3053\u306e9002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u95a2\u9023\u306e\u3042\u308b\u69cb\u9020\u57fa\u76e4\u306f\u3001Poison Ivy\u3092\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u4f7f\u3063\u305f\u30df\u30e3\u30f3\u30de\u30fc\u306a\u3069\u306e\u30a2\u30b8\u30a2\u8af8\u56fd\u306b\u5bfe\u3059\u308b\u653b\u6483(\u6700\u8fd1\u306e\u3001\u3042\u308b\u3044\u306f\u4eca\u3082\u7d9a\u3044\u3066\u3044\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u53f0\u6e7e\u306b\u5bfe\u3059\u308b\u653b\u6483\u6d3b\u52d5\u3092\u542b\u3080)\u3068\u4ee5\u524d\u306b\u7d50\u3073\u3064\u304d\u304c\u3042\u3063\u305f\u3053\u3068\u3082\u5206\u304b\u308a\u307e\u3057\u305f\u3002<!--more--><\/p>\n<h2><b>\u77ed\u304f\u3082\u7518\u3044...<\/b><b><\/b><\/h2>\n<p>\u4eca\u306e\u3068\u3053\u308d\u3001\u3053\u306e\u653b\u6483\u306b\u95a2\u3059\u308b\u5177\u4f53\u7684\u306a\u9060\u9694\u6e2c\u5b9a\u306f\u3057\u3066\u304a\u308a\u307e\u305b\u3093\u304c\u3001\u653b\u6483\u304c\u77ed\u7e2eURL (\u4eca\u56de\u306e\u5834\u5408\u306fURL\u77ed\u7e2e\u30b5\u30fc\u30d3\u30b9TinyURL\u3092\u5229\u7528)\u3092\u62e0\u308a\u3069\u3053\u308d\u306b\u3057\u30669002\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u914d\u4fe1\u3057\u305f\u3082\u306e\u3068\u79c1\u305f\u3061\u306f\u4fe1\u3058\u3066\u3044\u307e\u3059\u3002\u77ed\u7e2eURL\u306f\u4e0b\u8a18\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/tinyurl[.]com\/zmu4dry<\/span><\/p>\n<p>\u3053\u306e\u77ed\u7e2eURL\u306f\u3001\u653b\u6483\u8005\u304c\u5236\u5fa1\u3057\u3066\u3044\u308b\u30b5\u30fc\u30d0\u3078\u3068\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3055\u305b\u307e\u3059\u3002\u3053\u306e\u30b5\u30fc\u30d0\u3092\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b5\u30fc\u30d0\u3068\u547c\u3076\u3053\u3068\u306b\u3057\u307e\u3059\u304c\u3001\u305d\u308c\u306f\u30d6\u30e9\u30a6\u30b6\u3092\u5225\u306e\u4f4d\u7f6e\u306b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3059\u308b\u306e\u306b\u95a2\u308f\u308a\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u304b\u3089\u3067\u3059\u3002\u4e0a\u8a18\u77ed\u7e2eURL\u306f\u4e0b\u8a18\u3092\u6307\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/222.239.91[.]152?&lt;redacted&gt;QGdtYWlsLmNvbWh0dHA6Ly90aW55dXJsLmNvbS9qZmo5b3V2<\/span><\/p>\n<p>\u4e0a\u8a18URL\u306b\u306fbase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u3053\u306e\u30c7\u30fc\u30bf\u306f\u6b21\u306b\u30b5\u30fc\u30d0\u306b\u3088\u3063\u3066\u5fa9\u53f7\u5316\u3055\u308c\u308b\u306f\u305a\u3067\u3059\u3002URL\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u5185\u306ebase64\u7b26\u53f7\u5316\u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u306f\u6b21\u306e\u3068\u304a\u308a\u5fa9\u53f7\u5316\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">&lt;redacted&gt;@gmail.comhttp:\/\/tinyurl[.]com\/jfj9ouv<\/span><\/p>\n<p>\u5fa9\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u5185\u306eGmail\u30a2\u30c9\u30ec\u30b9\u306f\u3001\u30df\u30e3\u30f3\u30de\u30fc\u3067\u3088\u304f\u77e5\u3089\u308c\u3066\u3044\u308b\u653f\u6cbb\u5bb6\u3067\u3042\u308a\u4eba\u6a29\u6d3b\u52d5\u5bb6\u3067\u3042\u308b\u4eba\u7269\u306e\u6b63\u898f\u30a2\u30c9\u30ec\u30b9\u3067\u3059\u3002\u5fa9\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u5185\u306e\u77ed\u7e2eURL (\u5177\u4f53\u7684\u306b\u306f\"hxxp:\/\/tinyurl[.]com\/jfj9ouv\")\u304c\u3055\u3089\u306b\u4e0b\u8a18\u306b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/drive.google[.]com\/uc?id=0B0eVt8dSXzFuN2ltVlVkVl8zNVU&amp;authuser=0&amp;export=download<\/span><\/p>\n<h2><b>\u653b\u6483\u8005\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b5\u30fc\u30d0<\/b><b><\/b><\/h2>\n<p>IP\u30a2\u30c9\u30ec\u30b9\u304c\"222.239.91[.]152\"\u3067\u3042\u308b\u30b5\u30fc\u30d0\u306f\u3001\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u7531\u6765\u3059\u308b\u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u3092\u69cb\u6587\u89e3\u6790\u3059\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u3002\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u6a5f\u80fd\u76ee\u7684\u3092\u3055\u3089\u306b\u8a73\u3057\u304f\u89e3\u660e\u3059\u308b\u305f\u3081\u3001\u79c1\u305f\u3061\u306f\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b5\u30fc\u30d0\u306b\u5bfe\u3057\u4e00\u9023\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u3066URL\u5185\u306ebase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u306e\u76ee\u7684\u3092\u7406\u89e3\u3057\u3001\u30d6\u30e9\u30a6\u30b6\u3092\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3059\u308b\u306e\u306b\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u4f7f\u3063\u3066\u3044\u308b\u6587\u5b57\u5217\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u6700\u521d\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u56f31\u306b\u3042\u308b\u3068\u304a\u308a\u3001\u3053\u306e\u653b\u6483\u306b\u95a2\u9023\u306e\u3042\u308b\u6700\u521d\u306e\u77ed\u7e2eURL\u304c\u6307\u3059URL\u3092\u4f34\u3063\u3066\u3044\u307e\u3059\u3002HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u304b\u3089\u5206\u304b\u308b\u3088\u3046\u306b\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u306fHTTP 302 Moved Temporarily\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u767a\u884c\u3057\u3066\u3001\"Location\"\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306eURL\u3078\u3068\u30d6\u30e9\u30a6\u30b6\u3092\u79fb\u52d5\u3055\u305b\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u79fb\u52d5\u5148URL\u306fHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u9001\u4fe1\u3055\u308c\u308bbase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u306b\u7531\u6765\u3059\u308b\u3082\u306e\u3068\u540c\u3058URL\u3067\u3059\u3002<\/p>\n<pre class=\"lang:default decode:true \">$ curl -i -A \"Mozzarella\/4.0\" 222.239.91[.]152?&lt;redacted&gt;QGdtYWlsLmNvbWh0dHA6Ly90aW55dXJsLmNvbS9qZmo5b3V2\r\nHTTP\/1.1 302 Moved Temporarily\r\nConnection: close\r\nContent-Length: 0\r\nDate: Mon, 18 Jul 2016 16:25:28 GMT\r\nLocation: http:\/\/tinyurl[.]com\/jfj9ouv\r\n<\/pre>\n<div><i>\u56f31 \u6700\u521d\u306e\u914d\u4fe1URL\u3078\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3059\u308b\u30ec\u30b9\u30dd\u30f3\u30b9<\/i><\/div>\n<p>2\u756a\u76ee\u306b\u767a\u884c\u3057\u305f\u30c6\u30b9\u30c8\u7528\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u306f\u6587\u5b57\u5217\"fake@gmail.comhttp:\/\/yahoo.com\"\u306ebase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u3092\u4f7f\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u56f32\u3067\u5206\u304b\u308b\u3068\u304a\u308aHTTP 302\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u4ecb\u3057\u3066\u30d6\u30e9\u30a6\u30b6\u304c\"http:\/\/yahoo.com\"\u3078\u3068\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u3053\u3068\u304b\u3089\u4f3a\u3048\u308b\u306e\u306f\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u6587\u5b57\u5217\u304c\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9 \u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3057\u3066\u3044\u304b\u306a\u308b\u7a2e\u985e\u306e\u8a8d\u8a3c\u3068\u3057\u3066\u3082\u7528\u3044\u3089\u308c\u305a\u3001\u305d\u306e\u4ee3\u308a\u3001\u6a19\u7684\u306b\u3055\u308c\u305f\u96fb\u5b50\u30e1\u30fc\u30eb\u304c\u72d9\u3044\u901a\u308a\u306b\u30af\u30ea\u30c3\u30af\u3055\u308c\u305f\u304b\u8ffd\u8de1\u3059\u308b\u306e\u306b\u8105\u5a01\u306e\u653b\u6483\u8005\u304c\u96fb\u5b50\u30e1\u30fc\u30eb\u6587\u5b57\u5217\u3092\u4f7f\u3063\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u3044\u3046\u3053\u3068\u3067\u3059\u3002<\/p>\n<pre class=\"lang:default decode:true \">$ curl -i -A \"Mozzarella\/4.0\" http:\/\/222.239.91[.]152\/?ZmFrZUBnbWFpbC5jb21odHRwOi8veWFob28uY29t\r\nHTTP\/1.1 302 Moved Temporarily\r\nConnection: close\r\nContent-Length: 0\r\nDate: Mon, 18 Jul 2016 17:10:33 GMT\r\nLocation: http:\/\/yahoo.com\r\n<\/pre>\n<div><i>\u56f32 \u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b5\u30fc\u30d0\u304cbase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u3092\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u306b\u5229\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u304b\u3081\u308b\u30c6\u30b9\u30c8\u7528\u30ea\u30af\u30a8\u30b9\u30c8<\/i><\/div>\n<p>\u79c1\u305f\u3061\u306f\u6587\u5b57\u5217\"fake@gmail.comyahoo.com\"\u306ebase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u3092\u4f7f\u3063\u3066HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u307e\u3057\u305f\u3002\u56f33\u304b\u3089\u30b5\u30fc\u30d0\u304cHTTP 200 OK\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u8fd4\u3057\u3066\u304d\u3066\u306f\u3044\u308b\u3082\u306e\u306e\u3001\u3053\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u304c\u30d6\u30e9\u30a6\u30b6\u306e\u30a6\u30a3\u30f3\u30c9\u30a6\u306b\"403 Forbidden\"\u3068\u8868\u793a\u3059\u308b\u3053\u3068\u3067HTTP 403 Forbidden\u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u4f3c\u305b\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u3082\u306e\u3067\u3042\u308b\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3059\u3002\u3053\u306e\u30a8\u30e9\u30fc\u304b\u3089\u3001\u30b5\u30fc\u30d0\u4e0a\u306b\u3042\u308b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b9\u30af\u30ea\u30d7\u30c8\u304cbase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u3092\u69cb\u6587\u89e3\u6790\u3057\u3066\u6587\u5b57\u5217\"http\"\u3092\u63a2\u3057\u3001\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u5148\u3092\u6c7a\u5b9a\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u4f3a\u3048\u307e\u3059\u3002<\/p>\n<pre class=\"lang:default decode:true\">$ curl -i -A \"Mozzarella\/4.0\" http:\/\/222.239.91[.]152\/?ZmFrZUBnbWFpbC5jb215YWhvby5jb20\r\nHTTP\/1.1 200 OK\r\nConnection: close\r\nContent-Type: text\/html; charset=ISO-8859-1\r\nContent-Length: 89\r\nDate: Mon, 18 Jul 2016 17:11:10 GMT\r\n\r\n&lt;html&gt;&lt;head&gt;&lt;title&gt;403 Forbidden&lt;\/title&gt;&lt;\/head&gt;&lt;body&gt;&lt;h1&gt;403 Forbidden&lt;\/h1&gt;&lt;\/body&gt;&lt;\/html&gt;\r\n<\/pre>\n<div><i>\u56f33 \u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b5\u30fc\u30d0\u304cbase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u5185\u306e\"http\"\u3092\u8981\u6c42\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3059\u30c6\u30b9\u30c8\u7528\u30ea\u30af\u30a8\u30b9\u30c8<\/i><\/div>\n<p>\u79c1\u305f\u3061\u306f\u30b9\u30af\u30ea\u30d7\u30c8\u304cbase64\u7b26\u53f7\u5316\u30c7\u30fc\u30bf\u5185\u3067\u78ba\u8a8d\u5bfe\u8c61\u3068\u3057\u3066\u3044\u308b\u6587\u5b57\u5217\u3092\u65b0\u305f\u306b\u898b\u3064\u3051\u308b\u305f\u3081\u3001\u5f15\u304d\u7d9a\u304d\u30c6\u30b9\u30c8\u7528\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u307e\u3057\u305f\u3002\u305d\u306e\u6587\u5b57\u5217\u306f\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u30d6\u30e9\u30a6\u30b6\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u5148\u3068\u306a\u308b\u4f4d\u7f6e\u3092\u5224\u5b9a\u3059\u308b\u306e\u306b\u4f7f\u308f\u308c\u307e\u3059\u304c\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u304c\"https\"\u3067\u59cb\u307e\u308bURL\u3082\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u5148\u3068\u3057\u3066\u6271\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u5927\u6587\u5b57\u5c0f\u6587\u5b57\u3092\u533a\u5225\u3057\u3001\"HTTP\"\u304a\u3088\u3073\"HTTPS\"\u3092\u4f7f\u3063\u305fURL\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u7d50\u679c\u3068\u3057\u3066\u56f33\u306e\u3088\u3046\u306b\u540c\u3058403 Forbidden\u30ec\u30b9\u30dd\u30f3\u30b9\u3068\u306a\u308a\u307e\u3057\u305f\u3002\u6700\u5f8c\u306b\u79c1\u305f\u3061\u306f\u30b9\u30af\u30ea\u30d7\u30c8\u304c\"http\"\u3084\"https\"\u306e\u5f8c\u306b\":\/\/\"\u3068\u3044\u3046\u6587\u5b57\u5217\u3092\u5fc5\u8981\u3068\u3057\u306a\u3044\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<h2><b>\u30af\u30e9\u30a6\u30c9\u304b\u3089\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac<\/b><b><\/b><\/h2>\n<p>\u3053\u306e\u653b\u6483\u306e\u914d\u4fe1\u3067\u306f\u3001\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 \u30b5\u30fc\u30d0\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u5148\u3068\u306a\u308b\u77ed\u7e2e\u30ea\u30f3\u30af\u304c\u3001Google Drive\u3067\u30db\u30b9\u30c8\u3055\u308c\u305fZip\u30d5\u30a1\u30a4\u30eb\u3092\u30dd\u30a4\u30f3\u30c8\u3057\u307e\u3059\u3002Zip\u30d5\u30a1\u30a4\u30eb\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306f\u201c2nd Myanmar Industrial Human Resource Development Symposium.zip\u201d (SHA256: c11b963e2df167766e32b14fb05fd71409092092db93b310a953e1d0e9ec9bc3)\u3067\u30012016\u5e747\u670813\u65e5\u306b\u8ffd\u52a0\u3055\u308c\u305f1\u3064\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306eZip\u30a2\u30fc\u30ab\u30a4\u30d6\u5185\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306f\u3001\u201c2nd Myanmar Industrial Human Resource Development Symposium.exe\u201d (SHA256: 49ac6a6c5449396b98a89709b0ad21d078af783ec8f1cd32c1c8b5ae71bec129)\u3067\u3059\u3002\u3053\u308c\u306f\u3001\u304a\u3068\u308a\u6587\u66f8\u3068\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30b7\u30b9\u30c6\u30e0\u306b\u4fdd\u5b58\u3057\u3001\u305d\u306e\u5f8c\u4e21\u65b9\u3092\u958b\u304f\u30c9\u30ed\u30c3\u30d1\u30fc\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3059\u3002\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u56f34\u306b\u793a\u3059\u3088\u3046\u306b\u3001PowerPoint\u30a2\u30a4\u30b3\u30f3\u3092\u4f7f\u7528\u3057\u3066\u3001\u30e6\u30fc\u30b6\u30fc\u306b\u30d5\u30a1\u30a4\u30eb\u304cPowerPoint\u30d7\u30ec\u30bc\u30f3\u30c6\u30fc\u30b7\u30e7\u30f3\u3067\u3042\u308b\u3068\u601d\u308f\u305b\u308b\u3053\u3068\u3067\u3001\u88ab\u5bb3\u8005\u304c\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u8d77\u52d5\u3059\u308b\u3088\u3046\u306b\u4ed5\u5411\u3051\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_16204\" aria-describedby=\"caption-attachment-16204\" style=\"width: 220px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.paloaltonetworks.com\/?attachment_id=16204\" rel=\"attachment wp-att-16204\"><img  class=\"wp-image-16204 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE-4-.jpg\" alt=\"\u56f34 \u88ab\u5bb3\u8005\u304c\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30d6\u30eb\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u306b\u4ed5\u5411\u3051\u308b\u305f\u3081\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u306fPowerPoint\u30a2\u30a4\u30b3\u30f3\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\" width=\"220\" height=\"58\" \/><\/a><figcaption id=\"caption-attachment-16204\" class=\"wp-caption-text\">\u56f34 \u88ab\u5bb3\u8005\u304c\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30d6\u30eb\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u306b\u4ed5\u5411\u3051\u308b\u305f\u3081\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u306fPowerPoint\u30a2\u30a4\u30b3\u30f3\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b<\/figcaption><\/figure>\n<div><\/div>\n<p>\u56f35\u306b\u793a\u3059\u304a\u3068\u308a\u6587\u66f8\u306f\u3001PowerPoint\u30d7\u30ec\u30bc\u30f3\u30c6\u30fc\u30b7\u30e7\u30f3\u3067\u30012016\u5e747\u670830\u65e5\u306b\u30df\u30e3\u30f3\u30de\u30fc\u3067\u958b\u50ac\u3055\u308c\u308b\u201cRole of JMVTI Aung San and Building of Clean and Safe Automobile Society\u201d\u3068\u3044\u3046\u30bf\u30a4\u30c8\u30eb\u306e\u4f1a\u8b70\u306e\u8a73\u7d30\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002Japan Myanmar Vocational Training Institute (JMVTI) Aung San (\u65e5\u672c\u30df\u30e3\u30f3\u30de\u30fc\u8077\u696d\u8a13\u7df4\u5b66\u6821)\u306f\u3001\u30df\u30e3\u30f3\u30de\u30fc\u306e\u79d1\u5b66\u7701\u306e\u7ba1\u8f44\u4e0b\u306eAsia Environmental Technology Promotion Institute (\u30a2\u30b8\u30a2\u74b0\u5883\u6280\u8853\u63a8\u9032\u6a5f\u69cb)\u306b\u3088\u3063\u3066\u8a2d\u7acb\u3055\u308c\u3001\u307e\u3082\u306a\u304f\u958b\u6821\u3055\u308c\u308b\u8077\u696d\u8a13\u7df4\u30bb\u30f3\u30bf\u30fc\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_16207\" aria-describedby=\"caption-attachment-16207\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.paloaltonetworks.com\/?attachment_id=16207\" rel=\"attachment wp-att-16207\"><img  class=\"wp-image-16207 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE5.png\" alt=\"\u56f35 9002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6642\u306b\u958b\u304b\u308c\u305f\u304a\u3068\u308a\u6587\u66f8\" width=\"900\" height=\"795\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE5.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE5-300x265.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE5-768x678.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE5-370x327.png 370w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/a><figcaption id=\"caption-attachment-16207\" class=\"wp-caption-text\">\u56f35 9002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6642\u306b\u958b\u304b\u308c\u305f\u304a\u3068\u308a\u6587\u66f8<\/figcaption><\/figure>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u95a2\u3057\u3066\u3001\u30c9\u30ed\u30c3\u30d1\u30fc\u306f\u73fe\u5728\u306e\u30e6\u30fc\u30b6\u30fc\u306e\u30d5\u30a9\u30eb\u30c0(%USERPROFILE%)\u5185\u306b\u30e9\u30f3\u30c0\u30e0\u306b\u547d\u540d\u3055\u308c\u305f\u30d5\u30a9\u30eb\u30c0\u3092\u4f5c\u6210\u3057\u3001\u6b21\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u305d\u308c\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">RealNetwork.exe (SHA256: 10d40c51d85ea9ced6050b8951802aaebe81f7db13f42fe5a5589172af481a7e)<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">main.dll (SHA256: 53671fe98a0c8c85f6f8eabfa851e27b437f6c392b46e42ddea3f0a656591b12)<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">mpaplugins\\MPAMedia.dll (SHA256: f76f639f2a7b8f39abf83737c6d3e533be66398c85ec95526e4b13561e15fbae)<\/span><\/li>\n<\/ul>\n<p>\"RealNetwork.exe\"\u30d5\u30a1\u30a4\u30eb\u306f\u3001\"RealNetworks, Inc.\"\u306b\u7f72\u540d\u3055\u308c\u305f\u6b63\u898f\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3067\u3001\"mpaplugins\\MPAMedia.dll\"\u3092\u30ed\u30fc\u30c9\u3057\u3066\"BuildDeviceDatabase\"\u3068\u3044\u3046\u540d\u524d\u306e\u95a2\u6570\u3092\u547c\u3073\u51fa\u3057\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u653b\u6483\u8005\u306f\u3001\"mpaplugins\\MPAMedia.dll\"\u3092\u30c9\u30ed\u30c3\u30d1\u30fc\u306b\u3088\u3063\u3066\u30e9\u30f3\u30c0\u30e0\u306b\u547d\u540d\u3055\u308c\u305f\u30d5\u30a9\u30eb\u30c0\u306b\u4fdd\u5b58\u3059\u308b\u3053\u3068\u3067\u3001\u6b63\u898f\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u5229\u7528\u3057\u3066\u5f7c\u3089\u304c\u4f5c\u6210\u3057\u305fDLL\u3092<a href=\"https:\/\/attack.mitre.org\/wiki\/DLL_side-loading\" data-page-track=\"true\" data-page-track-value=\"company:160727-unit-42-attack-delivers-9002-trojan-through-google-drive: text::\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9\">\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9<\/a>\u3057\u307e\u3059\u3002<\/p>\n<p>\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9\u3055\u308c\u305f\"MPAMedia.dll\" DLL\u306f\u3001\u30b5\u30f3\u30c9\u30dc\u30c3\u30af\u30b9\u56de\u907f\u3092\u8a66\u307f\u308b\u305f\u3081\u304b\u3001\u6700\u521d\u306b\u3001\u30b7\u30b9\u30c6\u30e0\u6642\u9593\u304c2016\u5e745\u670820\u65e5\u4ee5\u964d\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001\u521d\u671f\u306b\u30c9\u30ed\u30c3\u30d1\u30fc\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u30e9\u30f3\u30c0\u30e0\u306b\u547d\u540d\u3055\u308c\u305f\u30d5\u30a9\u30eb\u30c0\u306b\u4fdd\u5b58\u6e08\u307f\u306e\"main.dll\"\u30d5\u30a1\u30a4\u30eb\u3092\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30ed\u30fc\u30c9 \u30d7\u30ed\u30bb\u30b9\u5168\u4f53\u306f\u3001\u56f36\u3067\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_16210\" aria-describedby=\"caption-attachment-16210\" style=\"width: 244px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.paloaltonetworks.com\/?attachment_id=16210\" rel=\"attachment wp-att-16210\"><img  class=\"wp-image-16210 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/figure6-1.jpg\" alt=\"\u56f36 DLL\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9 \u30d7\u30ed\u30bb\u30b9\u306e\u6982\u8981\" width=\"244\" height=\"105\" \/><\/a><figcaption id=\"caption-attachment-16210\" class=\"wp-caption-text\">\u56f36 DLL\u30b5\u30a4\u30c9\u30ed\u30fc\u30c9 \u30d7\u30ed\u30bb\u30b9\u306e\u6982\u8981<\/figcaption><\/figure>\n<p>\"MPAMedia.dll\u201d DLL\u306f\u3001\"main.dll\"\u5185\u304b\u3089\u3001\u201cstdInstall\u201d\u304a\u3088\u3073\u201cCreateFunc\u201d\u3068\u3044\u3046\u540d\u524d\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3055\u308c\u305f\u95a2\u6570\u3092\u547c\u3073\u51fa\u3057\u307e\u3059\u3002\"stdInstall\"\u95a2\u6570\u306f\u3001\u6301\u7d9a\u6027\u3092\u76ee\u7684\u306b\u3001\u6b21\u306e\u81ea\u52d5\u5b9f\u884c\u30ec\u30b8\u30b9\u30c8\u30ea \u30ad\u30fc\u3092\u4f5c\u6210\u3059\u308b\u5f79\u5272\u3092\u62c5\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">Software\\Microsoft\\Windows\\CurrentVersion\\Run\\RealNetwork<\/span><\/p>\n<p>\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3055\u308c\u305f\u95a2\u6570\u306e\"CreateFunc\"\u306f\u3001\"main.dll\"\u30d5\u30a1\u30a4\u30eb\u5185\u306e\u30aa\u30d5\u30bb\u30c3\u30c8\u3092\u30019002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u5b9f\u969b\u306e\u95a2\u6570\u30b3\u30fc\u30c9\u304c\u542b\u307e\u308c\u308b\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u306b\u8fd4\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001\"MPAMedia.dll\" DLL\u304c\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u30b9\u30ec\u30c3\u30c9\u3092\u4f5c\u6210\u3057\u307e\u3059\u30029002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u5b9f\u884c\u6642\u306b\u3001F16ME\u304a\u3088\u3073widfasdf\u3068\u3044\u30462\u3064\u306e\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30d5\u30a9\u30eb\u30c0(%USERPROFILE%)\u3078\u306e\u30d1\u30b9\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3059\u308b\u6b21\u306e\u30ec\u30b8\u30b9\u30c8\u30ea \u30ad\u30fc\u3082\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">HKCU\\Software\\Microsoft\\F6\\uid<\/span><\/p>\n<p>\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u3053\u306e\u30ec\u30b8\u30b9\u30c8\u30ea \u30ad\u30fc\u306b\u4fdd\u5b58\u3055\u308c\u305f\u30d1\u30b9\u3092\u4f7f\u7528\u3057\u3066\u3001\u305d\u306e\u8a2d\u5b9a\u3092\u898b\u3064\u3051\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u8907\u6570\u30d0\u30a4\u30c8\u306eXOR\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3068\u30ad\u30fc\u201c1pKFmjw\u201d\u3092\u4f7f\u7528\u3057\u3066\u5fa9\u53f7\u5316\u3055\u308c\u307e\u3059\u3002\u56f37\u306f\u3001\u3053\u306e9002\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u5fa9\u53f7\u5316\u3055\u308c\u305f\u8a2d\u5b9a\u306e16\u9032\u30c0\u30f3\u30d7\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_16213\" aria-describedby=\"caption-attachment-16213\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.paloaltonetworks.com\/?attachment_id=16213\" rel=\"attachment wp-att-16213\"><img  class=\"wp-image-16213 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE7.png\" alt=\"\u56f37 9002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u8a2d\u5b9a\" width=\"900\" height=\"1002\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE7.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE7-269x300.png 269w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE7-768x855.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE7-370x412.png 370w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/a><figcaption id=\"caption-attachment-16213\" class=\"wp-caption-text\">\u56f37 9002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u8a2d\u5b9a<\/figcaption><\/figure>\n<p>9002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u4e0a\u8a18\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u7528\u3057\u3066\u3001\u30b3\u30de\u30f3\u30c9 \u30a2\u30f3\u30c9 \u30b3\u30f3\u30c8\u30ed\u30fc\u30eb(C2)\u30b5\u30fc\u30d0\u3068\u3057\u3066\u52d5\u4f5c\u3059\u308b\u6b21\u306e\u30c9\u30e1\u30a4\u30f3\u3068\u901a\u4fe1\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">logitechwkgame[.]com<\/span><\/p>\n<p>\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u30012\u901a\u308a\u306e\u7570\u306a\u308b\u65b9\u6cd5\u3092\u4f7f\u7528\u3057\u3066\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30d3\u30fc\u30b3\u30f3\u3092\u305d\u306eC2\u30b5\u30fc\u30d0\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002\u7b2c1\u306e\u65b9\u6cd5\u3067\u306f\u3001\u56f38\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u30c4\u30fc\u30eb\u540d\u306e\u57fa\u672c\u3067\u3042\u308b\u6587\u5b57\u5217\"9002\"\u3067\u59cb\u307e\u308b\u30ab\u30b9\u30bf\u30e0 \u30d7\u30ed\u30c8\u30b3\u30eb\u3092TCP\u30dd\u30fc\u30c880\u3067\u4f7f\u7528\u3057\u307e\u3059\u3002C2\u30b5\u30fc\u30d0\u304c\u5fdc\u7b54\u3059\u308b\u3068\u3001\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u6587\u5b57\u5217\u201cjackhex\u201d\u304a\u3088\u3073\u201c2016\u201d\u3068\u3068\u3082\u306b\u3001\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u5185\u306e\u30b7\u30b9\u30c6\u30e0\u56fa\u6709\u306e\u60c5\u5831\u3092\u9001\u4fe1\u3057\u307e\u3059\u3002\u201cjackhex\u201d\u306fC2\u5185\u306b\u3082\u898b\u3089\u308c\u3001\u3053\u306e\u30d6\u30ed\u30b0\u306e\u5f8c\u534a\u3067\u7c21\u5358\u306b\u8aac\u660e\u3057\u307e\u3059\u304c\u3001Poison Ivy\u6d3b\u52d5\u306b\u95a2\u9023\u3057\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_16216\" aria-describedby=\"caption-attachment-16216\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.paloaltonetworks.com\/?attachment_id=16216\" rel=\"attachment wp-att-16216\"><img  class=\"wp-image-16216 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE8.png\" alt=\"\u56f38 \u30ab\u30b9\u30bf\u30e09002\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3059\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30d3\u30fc\u30b3\u30f3\" width=\"900\" height=\"68\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE8.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE8-300x23.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE8-768x58.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE8-370x28.png 370w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/a><figcaption id=\"caption-attachment-16216\" class=\"wp-caption-text\">\u56f38 \u30ab\u30b9\u30bf\u30e09002\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3059\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30d3\u30fc\u30b3\u30f3<\/figcaption><\/figure>\n<div class=\"mceTemp\"><\/div>\n<p>2\u756a\u76ee\u306e\u30d3\u30fc\u30b3\u30f3\u624b\u6cd5\u3082TCP\u30dd\u30fc\u30c880\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u306e\u624b\u6cd5\u306fHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f7f\u7528\u3057\u3066C2\u30b5\u30fc\u30d0\u3068\u901a\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002\u56f39\u306f\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306b\u3088\u3063\u3066\u767a\u884c\u3055\u308c\u305fHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u3001\u201clynx\u201d\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u304a\u3088\u3073\u201cAA\u201d\u306ePOST\u30c7\u30fc\u30bf\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u3053\u308c\u3089\u306f\u4e21\u65b9\u3068\u3082\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_16219\" aria-describedby=\"caption-attachment-16219\" style=\"width: 413px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.paloaltonetworks.com\/?attachment_id=16219\" rel=\"attachment wp-att-16219\"><img  class=\"wp-image-16219 size-full lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE9.png\" alt=\"\u56f39 HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f7f\u7528\u3057\u305f9002\u304b\u3089\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30d3\u30fc\u30b3\u30f3\" width=\"413\" height=\"286\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE9.png 413w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE9-300x208.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/07\/FIGURE9-370x256.png 370w\" sizes=\"(max-width: 413px) 100vw, 413px\" \/><\/a><figcaption id=\"caption-attachment-16219\" class=\"wp-caption-text\">\u56f39 HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f7f\u7528\u3057\u305f9002\u304b\u3089\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30d3\u30fc\u30b3\u30f3<\/figcaption><\/figure>\n<p>\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u3088\u3063\u3066\u751f\u6210\u3055\u308c\u305f2\u3064\u306e\u30d3\u30fc\u30b3\u30f3\u306f\u3001\u4ee5\u524d\u5206\u6790\u3057\u305f9002\u306e\"<a href=\"https:\/\/blog.paloaltonetworks.com\/2015\/09\/chinese-actors-use-3102-malware-in-attacks-on-us-government-and-eu-media\/\" data-page-track=\"true\" data-page-track-value=\"company:160727-unit-42-attack-delivers-9002-trojan-through-google-drive: text::3102\">3102\"<\/a>\u4e9c\u7a2e\u306b\u3088\u3063\u3066\u751f\u6210\u3055\u308c\u305f\u3082\u306e\u3068\u975e\u5e38\u306b\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059\u3002\u3053\u306e9002\u30b5\u30f3\u30d7\u30eb\u5185\u306e\u6a5f\u80fd\u306f\u3001\u305d\u306e\u4e3b\u6a5f\u80fd\u304cC2\u30b5\u30fc\u30d0\u306b\u3088\u3063\u3066\u63d0\u4f9b\u3055\u308c\u308b\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u30ed\u30fc\u30c9\u3057\u3001\u201cCreatePluginObj\u201d\u3068\u3044\u3046\u540d\u524d\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3055\u308c\u305f\u95a2\u6570\u3092\u547c\u3073\u51fa\u3059\u3053\u3068\u3067\u3042\u308a\u3001\u53d6\u308a\u4e0a\u3052\u305f3102\u4e9c\u7a2e\u3068\u975e\u5e38\u306b\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2><b>\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3068Poison Ivy\u306e\u5171\u901a\u70b9<\/b><b><\/b><\/h2>\n<p>C2\u30b5\u30fc\u30d0\"logitechwkgame[.]com\"\u306fIP\u30a2\u30c9\u30ec\u30b9\"222.239.91[.]30\"\u306b\u89e3\u6c7a\u3055\u308c\u307e\u3059\u304c\u3001\u3053\u308c\u306f\"logitechwkgame[.]com\"\u3068\u540c\u6642\u306b\"admin.nslookupdns[.]com\"\u306b\u3082\u89e3\u6c7a\u3055\u308c\u3001\u3053\u308c\u30892\u3064\u306e\u30c9\u30e1\u30a4\u30f3\u304c\u540c\u3058\u653b\u6483\u8005\u306b\u95a2\u9023\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002\"admin.nslookupdns[.]com\"\u306f\u3001Arbor Networks\u304c\u516c\u958b\u3057\u305f<a href=\"https:\/\/www.arbornetworks.com\/blog\/asert\/recent-poison-iv\/\" data-page-track=\"true\" data-page-track-value=\"company:160727-unit-42-attack-delivers-9002-trojan-through-google-drive: text::\u30d6\u30ed\u30b0\">\u30d6\u30ed\u30b0<\/a>\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u3001\u30df\u30e3\u30f3\u30de\u30fc\u304a\u3088\u3073\u305d\u306e\u4ed6\u306e\u30a2\u30b8\u30a2\u8af8\u56fd\u3067\u306e\u653b\u6483\u306b\u95a2\u9023\u3059\u308bPoison Ivy\u30b5\u30f3\u30d7\u30eb\u306eC2\u3067\u3082\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u6d3b\u52d5\u306e\u3055\u3089\u306a\u308b\u5171\u901a\u70b9\u306fPoison Ivy C2 \"jackhex.md5c[.]net\"\u3067\u3059\u3002\u201cjackhex\u201d\u304c\u4e00\u822c\u7684\u306a\u5358\u8a9e\u3084\u53e5\u3067\u306f\u306a\u304f\u3001\u524d\u8a18\u306e9002\u30b5\u30f3\u30d7\u30eb\u306b\u3088\u308b\u30d3\u30fc\u30b3\u30f3\u6d3b\u52d5\u3067\u3082\u898b\u3089\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u305d\u306e\u7406\u7531\u3067\u3059\u3002<\/p>\n<p>Arbor Networks\u306e\u30d6\u30ed\u30b0\u306b\u8a18\u8ff0\u3055\u308c\u3066\u3044\u308b\u30b5\u30f3\u30d7\u30eb\u306b\u52a0\u3048\u3066\u3001\u540c\u3058\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f7f\u7528\u3059\u308b\u5225\u306ePoison Ivy\u30b5\u30f3\u30d7\u30eb\u3092\u3044\u304f\u3064\u304b\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306f\u3001\u540c\u3058\u89aa\u30d7\u30ed\u30bb\u30b9\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u3001\u540c\u3058C2\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u307b\u3068\u3093\u3069\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u305f\u3060\u3057\u3001\u53ce\u96c6\u3057\u305f\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u3001\u30ad\u30e3\u30f3\u30da\u30fc\u30f3ID\u304c\u306a\u304f\u3001\u3059\u3079\u3066\u304c\u901a\u4fe1\u3092\u6697\u53f7\u5316\u3059\u308b\u30d1\u30b9\u30ef\u30fc\u30c9\u3068\u3057\u3066\u201cversion2013\u201d\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u8ffd\u52a0\u306ePoison Ivy\u30b5\u30f3\u30d7\u30eb\u304b\u3089\u6b21\u306e3\u3064\u306e\u65b0\u3057\u3044C2\u30c9\u30e1\u30a4\u30f3\u304c\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">outhmail[.]com<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">mxdnsv6[.]com<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">microsoftserve[.]com<\/span><\/li>\n<\/ul>\n<p>\u307e\u305f\u3001\u3053\u308c\u3089\u306ePoison Ivy\u30b5\u30f3\u30d7\u30eb\u306b\u95a2\u9023\u3059\u308bC2\u30c9\u30e1\u30a4\u30f3\u306e\u4e00\u90e8\u306f\u3001\u95a2\u4fc2\u304c\u3042\u308b\u304b\u3082\u3057\u308c\u306a\u3044\u4ee5\u4e0b\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u767b\u9332\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u305f\u96fb\u5b50\u30e1\u30fc\u30eb\u3067\u767b\u9332\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">gooledriveservice[.]com<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">queryurl[.]com<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">appupdatemoremagic[.]com<\/span><\/li>\n<\/ul>\n<p>\u3053\u308c\u3089\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u95a2\u9023\u3059\u308b\u5b8c\u5168\u306a\u6a19\u7684\u60c5\u5831\u306f\u3042\u308a\u307e\u305b\u3093\u304c\u3001\u304a\u3068\u308a\u30d5\u30a1\u30a4\u30eb\u306e\u3044\u304f\u3064\u304b\u306f\u4e2d\u56fd\u8a9e\u3067\u3001\u53f0\u6e7e\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3059\u308b\u6700\u8fd1\u306e\uff08\u9032\u884c\u4e2d\u3067\u3042\u308b\u53ef\u80fd\u6027\u3082\u3042\u308b\uff09\u6d3b\u52d5\u306e\u4e00\u90e8\u306e\u3088\u3046\u3067\u3059\u3002\u304a\u3068\u308a\u306e\u30c6\u30fc\u30de\u306f\u4e3b\u306b\u4e21\u5cb8\u95a2\u4fc2\u304a\u3088\u3073\u53f0\u6e7e\u306e\u884c\u653f\u9662\u5927\u9678\u59d4\u54e1\u4f1a\uff08MAC\uff09\u306b\u95a2\u3059\u308b\u3082\u306e\u3067\u3057\u305f\u3002MAC\u306f\u3001\u53f0\u6e7e\u3068\u4e2d\u83ef\u4eba\u6c11\u5171\u548c\u56fd\uff08PRC\uff09\u306e\u9593\u306e\u653f\u7b56\u3092\u4f5c\u6210\u3001\u5b9f\u65bd\u3001\u76e3\u7763\u3059\u308b\u95a3\u50da\u7d1a\u306e\u7d44\u7e54\u3067\u3059\u3002<\/p>\n<h2><b>\u7d50\u8ad6<\/b><b><\/b><\/h2>\n<p>Google Drive\u3092\u4f7f\u7528\u3057\u3066\u60aa\u610f\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u30db\u30b9\u30c8\u3059\u308b\u3053\u3068\u306f\u65b0\u3057\u3044\u653b\u6483\u6226\u8853\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u3057\u304b\u3057\u3001\u6709\u540d\u306a\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3092\u4f7f\u7528\u3059\u308b\u3068\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u304c\u3001\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u30d7\u30ed\u30d0\u30a4\u30c0\u306e\u5225\u306e\u5408\u6cd5\u7684\u306a\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u7d1b\u308c\u8fbc\u3080\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u4f9d\u7136\u3068\u3057\u3066\u4e3b\u8981\u306a\u653b\u6483\u65b9\u6cd5\u306b\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u306e\u624b\u6cd5\u306f\u5e83\u304f\u516c\u958b\u3055\u308c\u305f\u305f\u3081\u3001\u304a\u305d\u3089\u304f\u6a19\u7684\u306b\u3055\u308c\u308b\u88ab\u5bb3\u8005\u306f\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u3084\u30ea\u30f3\u30af\u3092\u958b\u304f\u3053\u3068\u306b\u3064\u3044\u3066\u3088\u308a\u6ce8\u610f\u6df1\u304f\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306e\u6210\u529f\u7387\u304c\u4f4e\u4e0b\u3057\u305f\u305f\u3081\u3001\u653b\u6483\u8005\u306f\u3001\u7d99\u7d9a\u3057\u3066\u65b0\u3057\u3044\u624b\u6cd5\u306b\u9806\u5fdc\u3057\u3001\u65b0\u3057\u3044\u624b\u6cd5\u3092\u767a\u898b\u3057\u3066\u30de\u30eb\u30a6\u30a7\u30a2\u914d\u4fe1\u3092\u6210\u529f\u3055\u305b\u308b\u5fc5\u8981\u304c\u751f\u3058\u3066\u3044\u307e\u3059\u3002URL\u77ed\u7e2e\u30b5\u30fc\u30d3\u30b9\u304a\u3088\u3073\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u7528\u30b5\u30fc\u30d0\u3092\u4f7f\u7528\u3059\u308b\u3068\u3001\u30ea\u30f3\u30af\u77ed\u7e2e\u6a5f\u80fd\u306b\u3088\u3063\u3066\u30ea\u30f3\u30af\u306e\u5185\u5bb9\u304c\u8b58\u5225\u4e0d\u80fd\u306b\u306a\u308a\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u5185\u306e\u30ea\u30f3\u30af\u306e\u6b63\u5f53\u6027\u3092\u5224\u5b9a\u3057\u3065\u3089\u304f\u306a\u3063\u3066\u653b\u6483\u6210\u529f\u306e\u53ef\u80fd\u6027\u304c\u3055\u3089\u306b\u9ad8\u307e\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u306fWildFire\u306b\u3088\u3063\u3066\u6b63\u3057\u304f\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u5206\u985e\u3055\u308c\u307e\u3059\u3002AutoFocus\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.9002\" data-page-track=\"true\" data-page-track-value=\"company:160727-unit-42-attack-delivers-9002-trojan-through-google-drive: text::9002\">9002<\/a>\u3068<a href=\"https:\/\/autofocus.paloaltonetworks.com\/#\/tag\/Unit42.PoisonIvy\" data-page-track=\"true\" data-page-track-value=\"company:160727-unit-42-attack-delivers-9002-trojan-through-google-drive: text::poison ivy\">Poison Ivy<\/a>\u306e\u4e21\u65b9\u306b\u3064\u3044\u3066\u3001\u305d\u308c\u305e\u308c\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u30bf\u30b0\u3092\u4f7f\u7528\u3057\u3066\u8a73\u7d30\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n<h2><b>IOC<\/b><b><\/b><\/h2>\n<h3><b>9002\u30b5\u30f3\u30d7\u30eb<\/b><\/h3>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">C11b963e2df167766e32b14fb05fd71409092092db93b310a953e1d0e9ec9bc3<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">49ac6a6c5449396b98a89709b0ad21d078af783ec8f1cd32c1c8b5ae71bec129<\/span><\/p>\n<h3><b>Poison Ivy\u30b5\u30f3\u30d7\u30eb<\/b><\/h3>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">193ae4da14874aa29902052d08064395afa5e4763f949e7369157d893fa08653<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">ac8fc264c7ec3cf70836e1bb21f9a20174b04ad49731b8797d7d8bb95cb353e2<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">12759f7fd01ffdea97954be5404d7e43a3941a7388129e7b6ace85f56b500cd8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0940602e7d47941f36c975afa9d2c6b1b0d2bd15bbea6ad4baf0f828420d72bf<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">6bdd45cb6c021512c203cf01a051dce28449e364627e1366412c0051094f60a0<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">f0ab826ea65b4a9eb66528ad74c4d3e747c1ecebfca6bdafd2504e0f794195d9<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">e2fb4a53e54774f1645c940f905e76beb5fc729e9e968b736b8377312cb2454a<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">0af768b4ba8fe7aac7a7da7fd5f21e7496d5617dccdf2321f526fd1091d64a6d<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">fd21cd1846f25d42b1997ec1fd5ae6e14ea9b5bb0161ab7edf0ce184174e6da6<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">12759f7fd01ffdea97954be5404d7e43a3941a7388129e7b6ace85f56b500cd8<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">08dee1f5ced372716ad5c6e3f2041bcdeb25e905efc19d3749fe637d0a589ccc<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">269c03e205c403ab8fa1033caa1c8e3a86a1495cc33a7f3a3a3c9b8a9ea77490<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">3a9ab623c8a0a9f6c65e108e83c90da7620d2d6b22192c857556117587d0d038<\/span><\/p>\n<h3><b>C2\u30c9\u30e1\u30a4\u30f3<\/b><\/h3>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">logitechwkgame[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">jackhex.md5c[.]net<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">webserver.servehttp[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">admin.nslookupdns[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">outhmail[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">mxdnsv6[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">microsoftdefence[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">microsoftserve[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">gooledriveservice[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">queryurl[.]com<\/span><br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">appupdatemoremagic[.]com<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google Drive\u304c\u63d0\u4f9b\u3059\u308b\u5171\u6709\u30d5\u30a1\u30a4\u30eb\u3068\u306e\u7d44\u307f\u5408\u308f\u305b\u306e\u5229\u7528\u306b\u3088\u3063\u30669002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304c\u914d\u4fe1\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u306b\u6c17\u4ed8\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u914d\u4fe1\u624b\u6cd5\u3067\u306f\u653b\u6483\u8005\u304c\u5236\u5fa1\u3057\u3066\u3044\u308b\u30b5\u30fc\u30d0\u3082\u4f7f\u308f\u308c\u307e<\/p>\n","protected":false},"author":22,"featured_media":99566,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[7615,6805,7617,7047,7618,4783],"product_categories":[4340,4444],"coauthors":[935,105],"class_list":["post-100066","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-9002-trojan-ja","tag-google-drive-ja","tag-http-ja","tag-poison-ivy-ja","tag-tinyurl","tag-trojan-ja","product_categories-advanced-wildfire","product_categories-advanced-wildfire-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Google Drive\u3092\u4ecb\u3057\u3066 9002 \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483<\/title>\n<meta name=\"description\" content=\"\u6982\u8981 \u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google Drive\u3092\u4ecb\u3057\u30669002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8981 \u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2016-07-26T13:00:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-10-09T03:03:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2019\/10\/unit42-blog-600x300.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Robert Falcone, Jen Miller-Osborn\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Google Drive\u3092\u4ecb\u3057\u30669002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Google Drive\u3092\u4ecb\u3057\u3066 9002 \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483","description":"\u6982\u8981 \u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/","og_locale":"ja_JP","og_type":"article","og_title":"Google Drive\u3092\u4ecb\u3057\u30669002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483","og_description":"\u6982\u8981 \u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/","og_site_name":"Unit 42","article_published_time":"2016-07-26T13:00:57+00:00","article_modified_time":"2019-10-09T03:03:26+00:00","og_image":[{"width":600,"height":300,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2019\/10\/unit42-blog-600x300.jpg","type":"image\/jpeg"}],"author":"Robert Falcone, Jen Miller-Osborn","twitter_card":"summary_large_image","twitter_title":"Google Drive\u3092\u4ecb\u3057\u30669002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/"},"author":{"name":"Robert Falcone","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1"},"headline":"Google Drive\u3092\u4ecb\u3057\u3066 9002 \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483","datePublished":"2016-07-26T13:00:57+00:00","dateModified":"2019-10-09T03:03:26+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/"},"wordCount":707,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2019\/10\/unit42-blog-600x300.jpg","keywords":["9002 Trojan","Google Drive","HTTP","Poison Ivy","TinyURL","Trojan"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/","name":"Google Drive\u3092\u4ecb\u3057\u3066 9002 \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2019\/10\/unit42-blog-600x300.jpg","datePublished":"2016-07-26T13:00:57+00:00","dateModified":"2019-10-09T03:03:26+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1"},"description":"\u6982\u8981 \u6700\u8fd1Unit 42\u306f\u77ed\u7e2eURL\u3068Google","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2019\/10\/unit42-blog-600x300.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2019\/10\/unit42-blog-600x300.jpg","width":600,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit-42-attack-delivers-9002-trojan-through-google-drive\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"Google Drive\u3092\u4ecb\u3057\u3066 9002 \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u914d\u4fe1\u3059\u308b\u653b\u6483"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1","name":"Robert Falcone","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Robert Falcone"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/robertfalcone\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/100066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=100066"}],"version-history":[{"count":6,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/100066\/revisions"}],"predecessor-version":[{"id":100074,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/100066\/revisions\/100074"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/99566"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=100066"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=100066"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=100066"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=100066"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=100066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}