{"id":106084,"date":"2016-05-09T06:30:19","date_gmt":"2016-05-09T13:30:19","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=106084"},"modified":"2020-04-07T22:45:17","modified_gmt":"2020-04-08T05:45:17","slug":"unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/","title":{"rendered":"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0 \u30b5\u30fc\u30d3\u30b9\u306f\u9577\u5e74\u306b\u308f\u305f\u308a\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u306e\u4e00\u756a\u306e\u6a19\u7684\u3068\u306a\u3063\u3066\u304a\u308a\u3001\u653b\u6483\u304c\u5897\u52a0\u3057\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u653b\u6483\u306e\u80cc\u5f8c\u306b\u3044\u308b\u72af\u7f6a\u8005\u306b\u3068\u3063\u3066\u306f\u3001\u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0\u306e\u5229\u7528\u8005\u3092\u6a19\u7684\u306b\u3057\u3066\u8cc7\u683c\u60c5\u5831\u3092\u76d7\u3081\u3070\u83ab\u5927\u306a\u5229\u76ca\u3092\u5f97\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002Unit 42 \u306f\u6628\u5e74\u306e\u7d42\u308f\u308a\u304b\u3089\u300cKRBanker\u300d\u3001\u5225\u540d\u300cBlackmoon\u300d\u3092\u8ffd\u8de1\u8abf\u67fb\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u653b\u6483\u306f\u7279\u306b\u5927\u97d3\u6c11\u56fd\u306e\u9280\u884c\u3092\u6a19\u7684\u306b\u3057\u3066\u3044\u307e\u3059\u30024\u670823\u65e5\u3001Fortinet\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u304c\u30d6\u30ed\u30b0\u3092\u516c\u958b\u3057\u3001\u6700\u8fd1\u306e\u300cBlackmoon\u300d\u653b\u6483\u306e\u8af8\u6a5f\u80fd\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3057\u305f\u3002\u672c\u30d6\u30ed\u30b0\u306e\u76ee\u7684\u306f\u3001KRBanker\u307e\u305f\u306fBlackmoon\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u653b\u6483\u306e\u914d\u4fe1\u304a\u3088\u3073KRBanker\u30b5\u30f3\u30d7\u30eb\u306e\u5146\u5019\u3068\u306a\u308b\u3082\u306e\u306b\u95a2\u3057\u3066\u3055\u3089\u306b\u8a73\u7d30\u3092\u5171\u6709\u3059\u308b\u3053\u3068\u306b\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u653b\u6483\u306e\u521d\u671f\u306b\u304a\u3051\u308b\u4e9c\u7a2e\u306f\u30012015\u5e749\u6708\u7d42\u308f\u308a\u306b\u59ff\u3092\u73fe\u3057\u59cb\u3081\u307e\u3057\u305f\u30022015\u5e74\u3067\u306fKRBanker\u3078\u306e\u611f\u67d3\u306e\u8a66\u884c\u56de\u6570\u306f\u6bd4\u8f03\u7684\u5c11\u306a\u3044\u3082\u306e\u3067\u3057\u305f\u304c\u3001\u79c1\u305f\u3061\u306f2016\u5e74\u306e\u521d\u3081\u304b\u3089\u30bb\u30c3\u30b7\u30e7\u30f3\u6570\u304c\u5f90\u3005\u306b\u5897\u52a0\u3057\u3066\u304d\u3066\u3044\u308b\u3053\u3068\u3092\u8a8d\u8b58\u3057\u3066\u304a\u308a\u3001KRBanker\u306e2,000\u500b\u8fd1\u3044\u4e00\u610f\u7684\u306a\u30b5\u30f3\u30d7\u30eb\u304a\u3088\u3073200\u500b\u3042\u307e\u308a\u306e\u30d5\u30a1\u30fc\u30df\u30f3\u30b0 \u30b5\u30fc\u30d0 \u30a2\u30c9\u30ec\u30b9\u3092\u3053\u306e6\u304b\u6708\u9593\u3067\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png\" alt=\"\u56f31 Autofocus\u3067\u306eKRBanker\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9 \u30bb\u30c3\u30b7\u30e7\u30f3\" width=\"500\" height=\"176\" \/><figcaption class=\"wp-caption-text\">\u56f31 Autofocus\u3067\u306eKRBanker\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9 \u30bb\u30c3\u30b7\u30e7\u30f3<\/figcaption><\/figure>\n<\/div>\n<h3><b>\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03<\/b><b><\/b><\/h3>\n<p>\u79c1\u305f\u3061\u306e\u5206\u6790\u304b\u3089\u3001KRBanker\u306fWeb\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8(EK)\u304a\u3088\u3073\u60aa\u610f\u306e\u3042\u308b\u30a2\u30c9\u30a6\u30a7\u30a2\u653b\u6483\u3092\u4ecb\u3057\u3066\u914d\u4fe1\u3055\u308c\u3066\u304d\u305f\u3053\u3068\u304c\u4f3a\u3048\u307e\u3059\u3002KRBanker\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306b\u4f7f\u308f\u308c\u3066\u3044\u308b\u3053\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u306fKaiXin\u3068\u3057\u3066\u77e5\u3089\u308c\u3066\u304a\u308a\u3001KRBanker\u3092\u914d\u4fe1\u3059\u308b\u30a2\u30c9\u30a6\u30a7\u30a2\u306fNEWSPOT\u3068\u547c\u3070\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>2016\u5e743\u6708\u3001Unit 42\u306eBrad Duncan\u306f<a href=\"https:\/\/isc.sans.edu\/diary\/Recent+example+of+KaiXin+exploit+kit\/20827\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">SANS<\/a>\u304a\u3088\u3073<a href=\"https:\/\/www.malware-traffic-analysis.net\/2016\/03\/22\/index.html\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">Malware-Traffic-Analysis.Net<\/a>\u306e\u305f\u3081\u306b2\u3064\u306e\u8a18\u4e8b\u3092\u66f8\u304d\u307e\u3057\u305f\u304c\u3001\u305d\u306e\u969b\u3001KaiXin EK\u304c\u5927\u97d3\u6c11\u56fd\u3067\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u306b\u8a00\u53ca\u3057\u307e\u3057\u305f\u3002\u305d\u308c\u3089\u306e\u4e8b\u4f8b\u3067\u306f\u3001\u4fb5\u5bb3\u3092\u53d7\u3051\u305fWeb\u30b5\u30a4\u30c8\u307e\u305f\u306f\u5e83\u544a\u3092\u4ecb\u3057\u3066\u3001\u60aa\u610f\u306e\u3042\u308bJavaScript\u304cAdobe Flash\u306e\u8106\u5f31\u6027CVE-2014-0569\u307e\u305f\u306fCVE-2015-3133\u3092\u7a81\u304fEK\u3078\u3068\u8a98\u5c0e\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306f\u30012\u3064\u306e\u4e8b\u4f8b\u306b\u304a\u3051\u308b\u6700\u5f8c\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304cKRBanker\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u5225\u306e\u914d\u5e03\u7d4c\u8def\u3068\u3057\u3066NEWSPOT\u3068\u547c\u3070\u308c\u308b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30c9\u30a6\u30a7\u30a2 \u30d7\u30ed\u30b0\u30e9\u30e0\u304c\u3042\u308a\u307e\u3059\u3002NEWSPOT\u3068\u3044\u3046\u5546\u54c1\u306e\u30de\u30fc\u30b1\u30c6\u30a3\u30f3\u30b0\u8cc7\u6599\u306b\u3088\u308c\u3070\u3001\u30aa\u30f3\u30e9\u30a4\u30f3 \u30b7\u30e7\u30c3\u30d4\u30f3\u30b0 \u30b5\u30a4\u30c8\u306b\u95a2\u3057\u3066300%\u306e\u53ce\u76ca\u5897\u5927\u304c\u4fdd\u8a3c\u3055\u308c\u3066\u3044\u307e\u3059\u3002NEWSPOT\u306f\u30d6\u30e9\u30a6\u30b6\u306b\u5e83\u544a\u3092\u8868\u793a\u3059\u308b\u57fa\u672c\u7684\u306a\u5e83\u544a\u30d7\u30ed\u30b0\u30e9\u30e0\u3067\u3059\u304c\u3001\u5c11\u306a\u304f\u3068\u30822015\u5e7411\u6708\u4ee5\u964d\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3092\u958b\u59cb\u3057\u307e\u3057\u305f\u3002\u97d3\u56fd\u306e\u4e00\u90e8\u306eWeb\u30b5\u30a4\u30c8\u3092\u8a2a\u308c\u305f\u969b\u3001\u30e6\u30fc\u30b6\u30fc\u306fNEWSPOT\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3092\u8981\u6c42\u3059\u308b\u30d6\u30e9\u30a6\u30b6 \u30a2\u30c9\u30aa\u30f3\u306e\u30dd\u30c3\u30d7\u30a2\u30c3\u30d7\u306b\u6c17\u4ed8\u304f\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-2.png\" alt=\"\u56f32 NEWSPOT\u30c4\u30fc\u30eb\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\" width=\"500\" height=\"111\" \/><figcaption class=\"wp-caption-text\">\u56f32 NEWSPOT\u30c4\u30fc\u30eb\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/figcaption><\/figure>\n<\/div>\n<p>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u3068\u3001\u3053\u306e\u30a2\u30c9\u30a6\u30a7\u30a2\u306f\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u4e0a\u3067\u5b9f\u884c\u3055\u308c\u3001\u4e0b\u8a18URL\u304b\u3089\u8a2d\u5b9a\u306e\u53d6\u5f97\u3092\u958b\u59cb\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">www.newspot[.]kr\/config.php?sUID=[web site name]<\/span><\/p>\n<p>\u30b5\u30fc\u30d0\u304c\u8fd4\u3057\u3066\u304d\u305f\u8a2d\u5b9a\u30c7\u30fc\u30bf\u306b\u306f&lt;update&gt;\u30bb\u30af\u30b7\u30e7\u30f3\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u306e\u3067\u3001\u305d\u3053\u306b\u8a18\u8ff0\u3055\u308c\u3066\u3044\u308bURL\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-3.png\" alt=\"\u56f33 \u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306b\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u305f\u3081\u306e\u30ea\u30f3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u308b\" width=\"500\" height=\"312\" \/><figcaption class=\"wp-caption-text\">\u56f33 \u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306b\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u305f\u3081\u306e\u30ea\u30f3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u308b<span style=\"font-size: 16px;\">\u3000<\/span><\/figcaption><\/figure>\n<\/div>\n<p>\u3053\u308c\u306f\u5143\u6765NEWSPOT\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u306e\u66f4\u65b0\u306b\u4f7f\u308f\u308c\u3066\u304d\u305f\u3082\u306e\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u304c\u3001KRBanker\u304a\u3088\u3073Venik\u306e\u3088\u3046\u306a\u30d0\u30f3\u30ad\u30f3\u30b0\u7528\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304c\u3053\u306e\u66f4\u65b0\u7d4c\u8def\u3092\u4ecb\u3057\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u79c1\u305f\u3061\u306f\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u56f34\u306b\u305d\u3046\u3057\u305fURL\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-4.png\" alt=\"\u56f34 NEWSPOT\u66f4\u65b0\u7d4c\u8def\u304b\u3089\u30d0\u30f3\u30ad\u30f3\u30b0\u7528\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\" width=\"500\" height=\"282\" \/><figcaption class=\"wp-caption-text\">\u56f34 NEWSPOT\u66f4\u65b0\u7d4c\u8def\u304b\u3089\u30d0\u30f3\u30ad\u30f3\u30b0\u7528\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9<\/figcaption><\/figure>\n<\/div>\n<h3><b>\u5b9f\u884c<\/b><b><\/b><\/h3>\n<p>KRBanker\u306f<a href=\"https:\/\/attack.mitre.org\/wiki\/Process_hollowing\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">Process Hollowing<\/a>\u3092\u5229\u7528\u3057\u3066\u611f\u67d3\u3057\u3066\u3044\u306a\u3044(\u7591\u308f\u3057\u304f\u306a\u3044)\u5b9f\u884c\u5f62\u5f0f\u30d5\u30a1\u30a4\u30eb\u306e\u4e2d\u306e\u30e1\u30a4\u30f3 \u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u30d7\u30ed\u30bb\u30b9\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u52d5\u4f5c\u3057\u307e\u3059\u3002<\/p>\n<ol>\n<li>KRBanker\u306f\u30b7\u30b9\u30c6\u30e0 \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3042\u308b\u611f\u67d3\u3057\u3066\u3044\u306a\u3044PE\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c\u3059\u308b\u3002<\/li>\n<li>Windows\u304c\u3053\u306ePE\u30d5\u30a1\u30a4\u30eb\u3092\u30e1\u30e2\u30ea\u306b\u30ed\u30fc\u30c9\u3059\u308b\u3002<\/li>\n<li>KRBanker\u306f\u81ea\u8eab\u306e(\u60aa\u610f\u306e\u3042\u308b)\u30e1\u30a4\u30f3 \u30e2\u30b8\u30e5\u30fc\u30eb\u3067\u3053\u306e\u611f\u67d3\u3057\u3066\u3044\u306a\u3044\u30d7\u30ed\u30bb\u30b9\u3092\u4e38\u3054\u3068\u4e0a\u66f8\u304d\u3059\u308b\u3002<\/li>\n<li>\u4e0a\u66f8\u304d\u3055\u308c\u305f\u30d7\u30ed\u30bb\u30b9\u304c\u60aa\u610f\u306e\u3042\u308b\u6d3b\u52d5\u3092\u958b\u59cb\u3059\u308b\u3002<\/li>\n<\/ol>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-5.png\" alt=\"\u56f35 \u5b9f\u884c\u30b9\u30c6\u30c3\u30d7\" width=\"500\" height=\"375\" \/><figcaption class=\"wp-caption-text\">\u56f35 \u5b9f\u884c\u30b9\u30c6\u30c3\u30d7<\/figcaption><\/figure>\n<\/div>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-6.png\" alt=\"\u56f36 \u5b9f\u884c\u30b9\u30c6\u30c3\u30d7(\u7d9a\u304d)\" width=\"500\" height=\"375\" \/><figcaption class=\"wp-caption-text\">\u56f36 \u5b9f\u884c\u30b9\u30c6\u30c3\u30d7(\u7d9a\u304d)<\/figcaption><\/figure>\n<\/div>\n<p>\u5b9f\u884c\u304c\u6210\u529f\u3059\u308b\u3068\u3001\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u304c\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u3053\u3068\u304cWindows\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u304b\u3089\u30e6\u30fc\u30b6\u30fc\u306b\u901a\u77e5\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u304c\u3001\u5143\u3005\u3001\u611f\u67d3\u3057\u3066\u3044\u306a\u3044Microsoft\u30d5\u30a1\u30a4\u30eb\u306b\u95a2\u9023\u3057\u305f\u3082\u306e\u3067\u3042\u308b\u305f\u3081\u3001\u591a\u304f\u306e\u30e6\u30fc\u30b6\u30fc\u306f\u3053\u306e\u6d3b\u52d5\u3092\u8a31\u53ef\u3057\u3066\u3057\u307e\u3044\u304c\u3061\u3067\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-7.png\" alt=\"\u56f37 Windows\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u901a\u77e5\" width=\"500\" height=\"288\" \/><figcaption class=\"wp-caption-text\">\u56f37 Windows\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u901a\u77e5<\/figcaption><\/figure>\n<\/div>\n<h3><b>\u30d5\u30a1\u30fc\u30df\u30f3\u30b0<\/b><\/h3>\n<p>Dridex\u3084Vawtrak\u306a\u3069\u306e\u30d0\u30f3\u30ad\u30f3\u30b0\u7cfb\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u4e3b\u306b\u3001Man-in-the-browser(MitB)\u624b\u6cd5\u3092\u4f7f\u7528\u3057\u3066\u3001\u76ee\u7684\u306e\u88ab\u5bb3\u8005\u304b\u3089\u8a8d\u8a3c\u60c5\u5831\u3092\u76d7\u307f\u51fa\u3057\u307e\u3059\u3002\u3057\u304b\u3057\u3001KRBanker\u306f\u300c\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u300d\u3068\u3057\u3066\u77e5\u3089\u308c\u308b\u7570\u306a\u308b\u624b\u6cd5\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002\u3053\u306e\u624b\u6cd5\u3067\u306f\u3001\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u306b\u3088\u3063\u3066\u6a19\u7684\u306b\u3055\u308c\u3066\u3044\u308b\u30d0\u30f3\u30ad\u30f3\u30b0 \u30b5\u30a4\u30c8\u306e\u3044\u305a\u308c\u304b\u306b\u30e6\u30fc\u30b6\u30fc\u304c\u30a2\u30af\u30bb\u30b9\u3092\u8a66\u307f\u305f\u3068\u304d\u306b\u3001\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u507d\u88c5Web\u30b5\u30a4\u30c8\u3078\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3057\u307e\u3059\u3002\u507d\u306e\u30b5\u30fc\u30d0\u304c\u30aa\u30ea\u30b8\u30ca\u30eb\u306e\u30b5\u30fc\u30d0\u306b\u306a\u308a\u3059\u307e\u3057\u3001\u8a2a\u554f\u8005\u306b\u5f7c\u3089\u306e\u60c5\u5831\u3068\u8a8d\u8a3c\u60c5\u5831\u3092\u9001\u4fe1\u3059\u308b\u3088\u3046\u306b\u8981\u6c42\u3057\u307e\u3059\u3002<\/p>\n<h3><b>\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7<\/b><b><\/b><\/h3>\n<p>\u8a50\u6b3a\u7684\u306a\u30b5\u30fc\u30d0\u306e IP \u30a2\u30c9\u30ec\u30b9\u306f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u306f\u30cf\u30fc\u30c9 \u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002KRBanker\u306f\u3001Web API\u3092\u901a\u3058\u3066\u4e2d\u56fd\u306eSNS\u3001Qzone\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3053\u3068\u3067\u30b5\u30fc\u30d0 \u30a2\u30c9\u30ec\u30b9\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002API\u306f\u3001\u6b21\u306eURL\u306bQQ\u756a\u53f7\u3092\u9001\u4fe1\u3059\u308b\u3053\u3068\u3067\u3001\u57fa\u672c\u7684\u306a\u30e6\u30fc\u30b6\u30fc\u60c5\u5831\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">users.qzone.qq.com\/fcg-bin\/cgi_get_portrait.fcg?uins=[QQ ID Number]<\/span><\/p>\n<p>\u305d\u306e\u5f8c\u3001\u30b5\u30fc\u30d0\u306f\u3001QQ ID\u756a\u53f7\u306b\u3088\u3063\u3066\u7279\u5b9a\u3055\u308c\u305fSNS\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u304b\u3089\u53d6\u5f97\u3057\u305f\u3001QQ ID\u756a\u53f7\u3001\u5199\u771f\u3078\u306e\u30ea\u30f3\u30af\u3001\u30cb\u30c3\u30af\u30cd\u30fc\u30e0\u304a\u3088\u3073\u305d\u306e\u4ed6\u306e\u60c5\u5831\u3067\u5fdc\u7b54\u3057\u307e\u3059\u3002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u4f5c\u6210\u8005\u306f\u3001\u300cnickname(\u30cb\u30c3\u30af\u30cd\u30fc\u30e0)\u300d\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u30d5\u30a1\u30fc\u30df\u30f3\u30b0 \u30b5\u30fc\u30d0 \u30a2\u30c9\u30ec\u30b9\u3092\u5165\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306f\u3001\u5f8c\u304b\u3089\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u306e\u305f\u3081\u306bKRBanker\u306b\u3088\u3063\u3066\u62bd\u51fa\u3055\u308c\u308bIP\u30a2\u30c9\u30ec\u30b9\u300123.107.204[.]38\u3092\u542b\u3080\u5fdc\u7b54\u4f8b\u3067\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-8.png\" alt=\"\u56f38 QZone\u304b\u3089\u53d7\u4fe1\u3057\u305f\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u7528IP\u30a2\u30c9\u30ec\u30b9\" width=\"500\" height=\"264\" \/><figcaption class=\"wp-caption-text\">\u56f38 QZone\u304b\u3089\u53d7\u4fe1\u3057\u305f\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u7528IP\u30a2\u30c9\u30ec\u30b9<span style=\"font-size: 16px;\">\u3000<\/span><\/figcaption><\/figure>\n<\/div>\n<p>\u6b21\u306b\u3001KRBanker\u306f\u3001\u4fb5\u5165\u3057\u305f\u30b7\u30b9\u30c6\u30e0\u3067GetOEMCP() API\u3092\u5b9f\u884c\u3057\u3001\u57cb\u3081\u8fbc\u307f\u306eVBScript\u3068\u30b3\u30fc\u30c9 \u30da\u30fc\u30b8\u3092\u4f7f\u7528\u3057\u3066MAC\u30a2\u30c9\u30ec\u30b9\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001\u6b21\u306eHTTP GET\u8981\u6c42\u3092\u9001\u4fe1\u3057\u3066\u3001\u4fb5\u5165\u3057\u305f\u30b7\u30b9\u30c6\u30e0\u306bC2\u30b5\u30fc\u30d0\u3092\u767b\u9332\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">http:\/\/[IP address]\/ca.php?m=[encoded MAC Address]&amp;h=[code page]<\/span><\/p>\n<h3><b>Proxy Auto-Config<\/b><b><\/b><\/h3>\n<p>ALYac\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u304c\u3001\u4ee5\u524d\u306b\u3001<a href=\"https:\/\/blog.alyac.co.kr\/135\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">\u30db\u30b9\u30c8 \u30d5\u30a1\u30a4\u30eb\u306e\u5909\u66f4<\/a>\u304a\u3088\u3073<a href=\"https:\/\/blog.alyac.co.kr\/172\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">\u30ed\u30fc\u30ab\u30ebDNS\u30d7\u30ed\u30ad\u30b7<\/a>\u624b\u6cd5\u3092\u4f7f\u7528\u3057\u3066HTTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3059\u308bKRBanker\u306b\u3064\u3044\u3066\u30ec\u30dd\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u8105\u5a01\u306f\u3001JavaScript\u3092\u8a18\u8ff0\u3059\u308b\u3053\u3068\u3067\u5404URL\u306e\u9069\u5207\u306a\u30d7\u30ed\u30ad\u30b7 \u30a2\u30c9\u30ec\u30b9\u3092\u5b9a\u7fa9\u3067\u304d\u308bWindows\u7ba1\u7406\u8005\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7ba1\u7406\u8005\u306b\u3068\u3063\u3066\u6b63\u898f\u306e\u95a2\u6570\u3067\u3042\u308bProxy Auto-Config (PAC)\u3092\u5229\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u3053\u3068\u306f\u3001Fortinet\u306e<a href=\"https:\/\/blog.fortinet.com\/post\/over-100-000-south-korean-users-affected-by-blackmoon-campaign\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">\u30d6\u30ed\u30b0\u306e\u6295\u7a3f<\/a>\u3067\u3082\u8ff0\u3079\u3089\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u653b\u6483\u8005\u306f\u3001\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u306e\u305f\u3081\u306b\u3053\u306e\u6a5f\u80fd\u3092\u60aa\u7528\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3092\u8a2d\u5b9a\u3059\u308b\u305f\u3081\u3001\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u30ed\u30fc\u30ab\u30eb \u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u3092\u8d77\u52d5\u3057\u3001\u6b21\u306e\u30ec\u30b8\u30b9\u30c8\u30ea \u30a8\u30f3\u30c8\u30ea\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL = http:\/\/127.0.0.1:[random]\/[random]<\/span><\/p>\n<p>\u30ed\u30fc\u30ab\u30eb \u30d7\u30ed\u30ad\u30b7 \u30db\u30b9\u30c8\u304cJavaScript\u3092\u6697\u53f7\u5316\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-9.png\" alt=\"\u56f39 Proxy Auto-Config\u7528\u306e\u60aa\u610f\u3042\u308bJavaScript\" width=\"500\" height=\"110\" \/><figcaption class=\"wp-caption-text\">\u56f39 Proxy Auto-Config\u7528\u306e\u60aa\u610f\u3042\u308bJavaScript<\/figcaption><\/figure>\n<\/div>\n<p>JavaScript\u3092\u5fa9\u53f7\u5316\u3059\u308b\u3068\u3001\u6a19\u7684\u3068\u3059\u308b\u30b5\u30a4\u30c8\u306e\u30ea\u30b9\u30c8\u3092\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308bPAC\u306e\u95a2\u6570\u3001FindProxyForURL()\u3092\u691c\u51fa\u3067\u304d\u307e\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-10.png\" alt=\"\u56f310 \u5fa9\u53f7\u5316\u3055\u308c\u305f\u60aa\u610f\u3042\u308bJavaScript\" width=\"500\" height=\"92\" \/><figcaption class=\"wp-caption-text\">\u56f310 \u5fa9\u53f7\u5316\u3055\u308c\u305f\u60aa\u610f\u3042\u308bJavaScript<span style=\"font-size: 16px;\">\u3000<\/span><\/figcaption><\/figure>\n<\/div>\n<p>\u30d6\u30e9\u30a6\u30b6\u304cWeb\u30b5\u30fc\u30d0\u3078\u306e\u63a5\u7d9a\u3092\u8a66\u307f\u308b\u3068\u3001\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u30ed\u30fc\u30ab\u30eb \u30d7\u30ed\u30ad\u30b7\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u30d7\u30ed\u30ad\u30b7PAC\u306e\u60aa\u610f\u3042\u308bJavaScript\u306f\u3001FindProxyForURL()\u95a2\u6570\u3092\u4f7f\u7528\u3057\u3001\u6a19\u7684\u306e\u30ea\u30b9\u30c8\u3068\u7167\u5408\u3057\u3066\u30c9\u30e1\u30a4\u30f3\u3092\u30c1\u30a7\u30c3\u30af\u3057\u307e\u3059\u3002\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u304c\u30ea\u30b9\u30c8\u5185\u306e\u6a19\u7684\u306e\u3044\u305a\u308c\u304b\u3068\u4e00\u81f4\u3059\u308b\u5834\u5408\u306f\u3001\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u8a50\u6b3a\u7684\u306a\u30b5\u30fc\u30d0\u3078\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u4e00\u81f4\u3057\u306a\u3044\u5834\u5408\u306f\u3001\u8981\u6c42\u3055\u308c\u305f\u6b63\u898f\u306e\u30c9\u30e1\u30a4\u30f3\u3078\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-11.png\" alt=\"\u56f311 Proxy Auto-Config\u306b\u3088\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\" width=\"500\" height=\"281\" \/><figcaption class=\"wp-caption-text\">\u56f311 Proxy Auto-Config\u306b\u3088\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8<\/figcaption><\/figure>\n<\/div>\n<div>\u73fe\u5728\u3001KRBanker\u306f\u3001\u975e\u5e38\u306b\u591a\u304f\u306e\u97d3\u56fd\u306e\u91d1\u878d\u6a5f\u95a2\u3092\u3001\u3053\u306e\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u653b\u6483\u306e\u6a19\u7684\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/div>\n<p>\u4fb5\u5bb3\u3055\u308c\u305f\u30e6\u30fc\u30b6\u30fc\u304c\u6a19\u7684\u3068\u3055\u308c\u3066\u3044\u308bWeb\u30b5\u30a4\u30c8\u306e\u3044\u305a\u308c\u304b\u3092\u8a2a\u554f\u3059\u308b\u3068\u3001\u30e6\u30fc\u30b6\u30fc\u306b\u306f\u4ee5\u4e0b\u306e\u56f312\u306b\u793a\u3059\u3088\u3046\u306a\u30da\u30fc\u30b8\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002\u30d6\u30e9\u30a6\u30b6\u306e\u30a2\u30c9\u30ec\u30b9 \u30d0\u30fc\u306b\u6709\u52b9\u306aURL\u304c\u8868\u793a\u3055\u308c\u3001\u6b63\u898f\u306eWeb\u30da\u30fc\u30b8\u3067\u3042\u308b\u304b\u306e\u3088\u3046\u306b\u898b\u3048\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u3053\u308c\u306f\u88ab\u5bb3\u8005\u306e\u8a8d\u8a3c\u60c5\u5831\u3068\u30a2\u30ab\u30a6\u30f3\u30c8\u60c5\u5831\u3092\u76d7\u3080\u305f\u3081\u306e\u507d\u306eWeb\u30da\u30fc\u30b8\u3067\u3059\u3002<\/p>\n<div>\n<figure style=\"width: 500px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-12.png\" alt=\"\u56f312 \u507d\u306e\u66f4\u65b0\u7528\u8a8d\u8a3c\u30bb\u30f3\u30bf\u30fc\" width=\"500\" height=\"287\" \/><figcaption class=\"wp-caption-text\">\u56f312 \u507d\u306e\u66f4\u65b0\u7528\u8a8d\u8a3c\u30bb\u30f3\u30bf\u30fc<\/figcaption><\/figure>\n<\/div>\n<p>\u307e\u305f\u3001KRBanker\u306f\u6b21\u306e\u6d3b\u52d5\u3082\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30aa\u30f3\u30e9\u30a4\u30f3\u9280\u884c\u53e3\u5ea7\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306bNPKI\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u8a8d\u8a3c\u60c5\u5831\u3092\u76d7\u3080<\/li>\n<li>Ahnlab\u306eV3\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3092\u7d42\u4e86\u3055\u305b\u308b<\/li>\n<\/ul>\n<h2><b>\u7d50\u8ad6<\/b><b><\/b><\/h2>\n<p>\u30d0\u30f3\u30ad\u30f3\u30b0\u7cfb\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u4f7f\u7528\u3059\u308b\u653b\u6483\u8005\u306e\u7b2c1\u306e\u52d5\u6a5f\u306f\u3001\u5229\u76ca\u3067\u3059\u3002KRBanker\u306e\u80cc\u5f8c\u306e\u653b\u6483\u8005\u306f\u3001\u88ab\u5bb3\u8005\u304b\u3089\u306e\u53ce\u76ca\u3092\u6700\u5927\u5316\u3059\u308b\u305f\u3081\u306b\u3001\u65b0\u305f\u306a\u914d\u4fe1\u30c1\u30e3\u30cd\u30eb\u3092\u958b\u767a\u3057\u3001\u4f55\u5ea6\u3082\u30d5\u30a1\u30fc\u30df\u30f3\u30b0\u624b\u6cd5\u3092\u9032\u5316\u3055\u305b\u3001\u65e5\u3005\u65b0\u3057\u3044\u4e9c\u7a2e\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u8a18\u4e8b\u3067\u8aac\u660e\u3057\u305f\u3068\u304a\u308a\u3001\u8105\u5a01\u306f\u3001\u53e4\u3044\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3068\u624b\u52d5\u3067\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u30a2\u30c9\u30a6\u30a7\u30a2\u3092\u901a\u3058\u3066\u914d\u4fe1\u3055\u308c\u307e\u3059\u3002\u5f71\u97ff\u3092\u6700\u5c0f\u9650\u306b\u3059\u308b\u306b\u306f\u3001\u3053\u306e\u3088\u3046\u306a\u6d3b\u52d5\u306e\u611f\u67d3\u7d4c\u8def\u3092\u7406\u89e3\u3059\u308b\u3053\u3068\u304c\u4e0d\u53ef\u6b20\u3067\u3059\u3002Palo Alto Networks Autofocus\u30e6\u30fc\u30b6\u30fc\u306f\u3001\u300cKRBanker\u300dAutofocus\u30bf\u30b0\u3092\u4f7f\u7528\u3057\u3066\u3053\u306e\u8105\u5a01\u3092\u8ffd\u8de1\u3067\u304d\u307e\u3059\u3002<\/p>\n<h3><b>\u5146\u5019<\/b><b><\/b><\/h3>\n<p>KRBanker\u306e\u5146\u5019\u306f\u3001\u4ee5\u4e0b\u306eUnit 42\u306eGitHub\u30da\u30fc\u30b8\u3067\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/krbanker\/hashes.txt\" data-page-track=\"true\" data-page-track-value=\"company:160510-unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2: section: \">https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/krbanker\/hashes.txt<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0 \u30b5\u30fc\u30d3\u30b9\u306f\u9577\u5e74\u306b\u308f\u305f\u308a\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u306e\u4e00\u756a\u306e\u6a19\u7684\u3068\u306a\u3063\u3066\u304a\u308a\u3001\u653b\u6483\u304c\u5897\u52a0\u3057\u7d9a\u3051\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u653b\u6483\u306e\u80cc\u5f8c\u306b\u3044\u308b\u72af\u7f6a\u8005\u306b\u3068\u3063\u3066\u306f\u3001\u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0\u306e\u5229\u7528\u8005\u3092\u6a19\u7684\u306b\u3057\u3066\u8cc7\u683c\u60c5\u5831\u3092\u76d7\u3081\u3070\u83ab\u5927\u306a\u5229<\/p>\n","protected":false},"author":260,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4324,4434,1974,4428],"tags":[5619,4717,7673,7675,7677,7678,7005],"product_categories":[],"coauthors":[176,473],"class_list":["post-106084","post","type-post","status-publish","format-standard","hentry","category-cybercrime","category-cybercrime-ja","category-malware-ja","category-threat-research-ja","tag-adware-ja","tag-banking-trojan-ja","tag-blackmoon-ja","tag-exploitkit-ja","tag-krbanker-ja","tag-pharming","tag-republic-of-korea-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b<\/title>\n<meta name=\"description\" content=\"\u6982\u8981 \u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8981 \u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2016-05-09T13:30:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-08T05:45:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png\" \/>\n<meta name=\"author\" content=\"Vicky Ray, Kaoru Hayashi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b","description":"\u6982\u8981 \u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/","og_locale":"ja_JP","og_type":"article","og_title":"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b","og_description":"\u6982\u8981 \u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/","og_site_name":"Unit 42","article_published_time":"2016-05-09T13:30:19+00:00","article_modified_time":"2020-04-08T05:45:17+00:00","og_image":[{"url":"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png","type":"","width":"","height":""}],"author":"Vicky Ray, Kaoru Hayashi","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/"},"author":{"name":"Vicky Ray","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/bd04d8ae883e5da60e5f60e1eb8793e6"},"headline":"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b","datePublished":"2016-05-09T13:30:19+00:00","dateModified":"2020-04-08T05:45:17+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/"},"wordCount":274,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#primaryimage"},"thumbnailUrl":"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png","keywords":["Adware","Banking Trojan","Blackmoon","ExploitKit","KRBanker","Pharming","Republic of Korea"],"articleSection":["Cybercrime","\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja"},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/","name":"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#primaryimage"},"thumbnailUrl":"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png","datePublished":"2016-05-09T13:30:19+00:00","dateModified":"2020-04-08T05:45:17+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/bd04d8ae883e5da60e5f60e1eb8793e6"},"description":"\u6982\u8981 \u30aa\u30f3\u30e9\u30a4\u30f3 \u30d0\u30f3\u30ad\u30f3\u30b0","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#primaryimage","url":"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png","contentUrl":"https:\/\/www.paloaltonetworks.jp\/content\/dam\/paloaltonetworks-com\/ja_JP\/Images\/blog\/KRBanker-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-krbanker-targets-south-korea-through-adware-and-exploit-kits-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"KRBanker\u3001\u30a2\u30c9\u30a6\u30a7\u30a2\u3068\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30ad\u30c3\u30c8\u3092\u4ecb\u3057\u3066\u97d3\u56fd\u3092\u6a19\u7684\u306b"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/bd04d8ae883e5da60e5f60e1eb8793e6","name":"Vicky Ray","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Vicky Ray"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/vicky-khan\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/260"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=106084"}],"version-history":[{"count":3,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106084\/revisions"}],"predecessor-version":[{"id":106087,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106084\/revisions\/106087"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=106084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=106084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=106084"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=106084"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=106084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}