{"id":106267,"date":"2017-05-03T14:08:28","date_gmt":"2017-05-03T21:08:28","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=106267"},"modified":"2020-04-09T18:54:10","modified_gmt":"2020-04-10T01:54:10","slug":"unit42-kazuar-multiplatform-espionage-backdoor-api-access","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/","title":{"rendered":"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>Kazuar\u30c4\u30fc\u30eb\u306fTurla\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7(<a href=\"https:\/\/blog.gdatasoftware.com\/2014\/02\/23968-uroburos-highly-complex-espionage-software-with-russian-roots\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">Uroburos<\/a>\u304a\u3088\u3073Snake\u3068\u3057\u3066\u3082\u77e5\u3089\u308c\u3066\u3044\u308b)\u3068\u95a2\u9023\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u5f0a\u793e\u3067\u306f\u898b\u3066\u3044\u307e\u3059\u3002Turla\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u306f\u4e16\u754c\u4e2d\u306e\u5927\u4f7f\u9928\u3001\u9632\u885b\u8acb\u8ca0\u696d\u8005\u3001\u6559\u80b2\u6a5f\u95a2\u304a\u3088\u3073\u30ea\u30b5\u30fc\u30c1\u7d44\u7e54\u306b\u5bfe\u3057\u3066\u4fb5\u5bb3\u3092\u50cd\u3044\u305f\u3053\u3068\u304c\u5831\u3058\u3089\u308c\u3066\u3044\u307e\u3059\u3002Turla\u306e\u653b\u6483\u6d3b\u52d5\u306e\u7279\u5fb4\u306f\u81ea\u524d\u306e\u30c4\u30fc\u30eb\u306e\u53cd\u5fa9\u5229\u7528\u3067\u3042\u308a\u3001Kazuar\u306b\u304a\u3051\u308b\u30b3\u30fc\u30c9\u306e\u7cfb\u7d71\u306f\u5c11\u306a\u304f\u3068\u30822005\u5e74\u307e\u3067<a href=\"https:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/waterbug-attack-group.pdf\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">\u9061\u308b<\/a>\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u4eee\u5b9a\u304c\u6b63\u3057\u304f\u3001Turla\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u304cKazuar\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u306e\u3067\u3042\u308c\u3070\u3001Carbon\u304a\u3088\u3073\u305d\u306e\u6d3e\u751f\u5f62\u306e\u4ee3\u308f\u308a\u306b\u306a\u308b\u3082\u306e\u3068\u3057\u3066\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u304cKazuar\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u5f0a\u793e\u3067\u306f\u898b\u3066\u3044\u307e\u3059\u3002Turla\u306b\u3088\u308b\u5229\u7528\u304c\u89b3\u6e2c\u3055\u308c\u305f\u7121\u6570\u306e\u30c4\u30fc\u30eb\u306e\u3046\u3061\u3001Carbon\u304a\u3088\u3073\u305d\u306e\u4e9c\u7a2e\u306f\u7b2c2\u30b9\u30c6\u30fc\u30b8\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u3068\u3057\u3066\u3001\u6a19\u7684\u306b\u3055\u308c\u305f\u74b0\u5883\u5185\u306b\u5c0e\u5165\u3055\u308c\u308b\u306e\u304c\u4e00\u822c\u7684\u306a\u306e\u3067\u3001\u4eca\u3067\u306fKazuar\u304cTurla\u653b\u6483\u6d3b\u52d5\u306b\u95a2\u3057\u3066\u4f3c\u305f\u3088\u3046\u306a\u5f79\u5272\u3092\u62c5\u3063\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u5f0a\u793e\u306f\u78ba\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3>Kazuar\u30de\u30eb\u30a6\u30a7\u30a2<\/h3>\n<p>Kazuar\u306f.NET Framework\u3092\u4f7f\u3063\u3066\u66f8\u304b\u308c\u305f\u30d5\u30eb\u6a5f\u80fd\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u3067\u3042\u308a\u3001<a href=\"https:\/\/yck1509.github.io\/ConfuserEx\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">ConfuserEx<\/a>\u3068\u3044\u3046\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u306e\u30d1\u30c3\u30ab\u30fc\u3092\u4f7f\u3063\u3066\u96e3\u8aad\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5f0a\u793e\u306f\u3001\u7dbf\u5bc6\u306a\u5206\u6790\u3092\u76ee\u7684\u3068\u3057\u3066\u30b3\u30fc\u30c9\u306e\u96e3\u8aad\u5316\u3092\u89e3\u9664\u3059\u308b\u305f\u3081\u3001<a href=\"https:\/\/github.com\/CodeShark-Dev\/NoFuserEx\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">NoFuserEx<\/a>\u3001ConfuserEx Fixer\u3001ConfuserEx Switch Killer\u304a\u3088\u3073<a href=\"https:\/\/github.com\/0xd4d\/de4dot\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">de4d0t<\/a>\u306a\u3069\u306e\u30c4\u30fc\u30eb\u3092\u7d44\u307f\u5408\u308f\u305b\u3066\u5229\u7528\u3057\u307e\u3057\u305f\u3002\u305d\u3046\u3057\u3066\u304a\u3044\u3066\u304b\u3089\u3001<a href=\"https:\/\/github.com\/0xd4d\/dnSpy\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">dnSpy<\/a>\u3092\u4f7f\u3063\u3066\u30b3\u30fc\u30c9\u3092Microsoft Visual Studio\u306e\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306b\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u30e9\u30f3\u30c0\u30e0\u306a\u30e1\u30bd\u30c3\u30c9\u540d\u3092\u30ea\u30cd\u30fc\u30e0\u3057\u3066\u3001\u30b3\u30fc\u30c9\u306e\u6d41\u308c\u3092\u7406\u89e3\u3057\u3084\u3059\u304f\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002Kazuar\u304c\u3069\u306e\u3088\u3046\u306b\u52d5\u4f5c\u3057\u3001\u8105\u5a01\u306e\u653b\u6483\u8005\u306b\u3069\u306e\u3088\u3046\u306a\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308b\u306e\u304b\u3001\u4ee5\u4e0b\u306b\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<h3>\u521d\u671f\u5316<\/h3>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u304a\u3088\u3073\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30a4\u30eb\u540d\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u3053\u3068\u3067\u521d\u671f\u5316\u3092\u884c\u3044\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f5c\u6210\u3057\u3066\u3001\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u304c\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u5fc5\u305a\u4e00\u5ea6\u306b1\u500b\u3057\u304b\u5b9f\u884c\u3055\u308c\u306a\u3044\u3088\u3046\u306b\u3057\u307e\u3059\u3002Kazuar\u304c\u81ea\u8eab\u306e\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u751f\u6210\u3059\u308b\u969b\u3001\u6587\u5b57\u5217\u300c<i>[username]<\/i>=&gt;singleton-instance-mutex\u300d\u306eMD5\u30cf\u30c3\u30b7\u30e5\u306e\u53d6\u5f97\u3092\u6700\u521d\u306b\u884c\u3046\u30d7\u30ed\u30bb\u30b9\u3092\u4f7f\u3044\u307e\u3059\u3002\u6b21\u306b\u3001XOR\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u304a\u3088\u3073\u30b9\u30c8\u30ec\u30fc\u30b8 \u30dc\u30ea\u30e5\u30fc\u30e0\u306e\u30b7\u30ea\u30a2\u30eb\u756a\u53f7\u3092\u4f7f\u3063\u3066\u3001\u3053\u306eMD5\u30cf\u30c3\u30b7\u30e5\u3092\u6697\u53f7\u5316\u3057\u307e\u3059\u3002\u7d50\u679c\u3068\u3057\u3066\u5f97\u3089\u308c\u305f\u6697\u53f7\u5316\u30c6\u30ad\u30b9\u30c8\u3092\u4f7f\u3063\u3066GUID\u3092\u751f\u6210\u3057\u3001\u3053\u306eGUID\u3092\u6587\u5b57\u5217\u300cGlobal\\\\\u300d\u306e\u672b\u5c3e\u306b\u8ffd\u52a0\u3057\u3066\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u4f5c\u6210\u904e\u7a0b\u3067\u5f0a\u793e\u304c\u767a\u898b\u3057\u305f\u8208\u5473\u6df1\u3044\u75d5\u8de1\u306f\u3001\u30b3\u30fc\u30c9\u304c\u30b7\u30b9\u30c6\u30e0\u306e\u30b9\u30c8\u30ec\u30fc\u30b8\u306e\u30b7\u30ea\u30a2\u30eb\u756a\u53f7\u3092\u53d6\u5f97\u3067\u304d\u306a\u3044\u5834\u5408\u3001MD5\u30cf\u30c3\u30b7\u30e5\u3092\u6697\u53f7\u5316\u3059\u308b\u305f\u3081\u306e\u30ad\u30fc\u3068\u3057\u3066\u3001Kazuar\u304c\u9759\u7684\u306a\u6574\u657016456730\u3092\u4f7f\u3046\u3053\u3068\u3067\u3059\u300216456730\u306e16\u9032\u6570\u8868\u8a18\u306f0xFB1C1A\u3067\u3042\u308a\u3001\u3053\u308c\u306f\u3001\u7c73\u56fd\u306e\u7d44\u7e54FBI\u304a\u3088\u3073CIA\u3092\u6307\u3057\u3066\u3044\u308b\u3068\u601d\u308f\u305b\u308b\u3082\u306e\u3092\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4f5c\u6210\u8005\u304c\u542b\u3081\u3066\u304a\u3044\u305f\u3088\u3046\u306b\u898b\u53d7\u3051\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u5f15\u304d\u7d9a\u304d\u3001\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u30b7\u30b9\u30c6\u30e0\u4e0a\u306b\u30d5\u30a9\u30eb\u30c0\u3092\u4e00\u5f0f\u4f5c\u6210\u3057\u3001\u5b9f\u884c\u4e2d\u306b\u4f5c\u6210\u3055\u308c\u308b\u3055\u307e\u3056\u307e\u306a\u30d5\u30a1\u30a4\u30eb\u3092\u305d\u3053\u306b\u4fdd\u5b58\u3057\u307e\u3059\u3002Kazuar\u306f\u30b0\u30eb\u30fc\u30d7\u540d\u3092\u4f7f\u3063\u3066\u30d5\u30a9\u30eb\u30c0\u3092\u4f5c\u6210\u3057\u3001\u3053\u308c\u306b\u3088\u308a\u30d5\u30a1\u30a4\u30eb\u3092\u7cfb\u7d71\u7684\u306b\u6574\u7406\u3057\u3066\u30d5\u30a9\u30eb\u30c0\u5185\u306b\u7f6e\u304d\u307e\u3059\u3002\u88681\u306f\u30d5\u30a9\u30eb\u30c0\u306e\u30ec\u30a4\u30a2\u30a6\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table class=\"table table-bordered\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"100\"><b>\u30d5\u30a9\u30eb\u30c0 \u30b0\u30eb\u30fc\u30d7<\/b><\/td>\n<td valign=\"top\" width=\"531\"><b>\u30d5\u30a1\u30a4\u30eb\u306e\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"100\">base<\/td>\n<td valign=\"top\" width=\"531\">\u4e0b\u8a18\u306e\u30d5\u30a9\u30eb\u30c0 \u30b0\u30eb\u30fc\u30d7\u3092\u542b\u3080\u89aa\u30d5\u30a9\u30eb\u30c0<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"100\">sys<\/td>\n<td valign=\"top\" width=\"531\">Kazuar\u304c\u8a2d\u5b9a\u306b\u4f7f\u7528\u3059\u308b\u30d5\u30a1\u30a4\u30eb(\u4f8b\u3048\u3070\u300cserv\u300d\u9805\u76ee\u306fC2\u30b5\u30fc\u30d0\u306e\u4f4d\u7f6e\u3092\u4fdd\u5b58\u3059\u308b)<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"100\">log<\/td>\n<td valign=\"top\" width=\"531\">\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u542b\u3080\u30d5\u30a1\u30a4\u30eb<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"100\">plg<\/td>\n<td valign=\"top\" width=\"531\">\u30d5\u30a1\u30a4\u30eb\u306fKazuar\u306e\u6a5f\u80fd\u3092\u62e1\u5f35\u3059\u308b\u305f\u3081\u306b\u4f7f\u308f\u308c\u308b\u30d7\u30e9\u30b0\u30a4\u30f3<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"100\">tsk<\/td>\n<td valign=\"top\" width=\"531\">Kazuar\u306b\u3088\u3063\u3066\u30b3\u30de\u30f3\u30c9\u304a\u3088\u3073\u305d\u306e\u5f15\u6570\u3068\u3057\u3066\u51e6\u7406\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"100\">res<\/td>\n<td valign=\"top\" width=\"531\">\u9996\u5c3e\u3088\u304f\u51e6\u7406\u3067\u304d\u305f\u30bf\u30b9\u30af\u306e\u7d50\u679c\u3092\u542b\u3080\u30d5\u30a1\u30a4\u30eb<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><i>\u88681 Kazuar\u306e\u30d5\u30a9\u30eb\u30c0 \u30b0\u30eb\u30fc\u30d7\u540d\u304a\u3088\u3073\u5185\u90e8\u306b\u4fdd\u5b58\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb<\/i><\/span><\/p>\n<p>\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u81ea\u8eab\u306e\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u751f\u6210\u3059\u308b\u306e\u306b\u4f7f\u3063\u305f\u30d7\u30ed\u30bb\u30b9\u306b\u985e\u4f3c\u3059\u308b\u3082\u306e\u3092\u4f7f\u3063\u3066\u3001\u30d5\u30a9\u30eb\u30c0\u540d\u3068\u30d5\u30a1\u30a4\u30eb\u540d\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u305d\u306e\u969b\u3001\u540d\u524d\u306eMD5\u30cf\u30c3\u30b7\u30e5\u3092\u751f\u6210\u3057\u3001\u30ad\u30fc\u3068\u3057\u3066\u30dc\u30ea\u30e5\u30fc\u30e0 \u30b7\u30ea\u30a2\u30eb\u756a\u53f7\u3092\u4f7f\u3063\u3066\u5404\u30d0\u30a4\u30c8\u306bXOR\u6f14\u7b97\u3092\u884c\u3044\u3001\u3053\u306e\u6697\u53f7\u5316\u30c6\u30ad\u30b9\u30c8\u306b\u57fa\u3065\u3044\u3066GUID\u3092\u751f\u6210\u3057\u307e\u3059\u3002\u7d50\u679c\u3068\u3057\u3066\u5f97\u3089\u308c\u305fGUID\u304c\u30d5\u30a1\u30a4\u30eb\u540d\u304a\u3088\u3073\u30d5\u30a9\u30eb\u30c0\u540d\u3068\u3057\u3066\u4f7f\u308f\u308c\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u540d\u524d\u304c%LOCALAPPDATA%\u30d5\u30a9\u30eb\u30c0\u306b\u5bfe\u3059\u308b\u30ed\u30fc\u30ab\u30eb \u30b7\u30b9\u30c6\u30e0\u306e\u30d1\u30b9\u3068\u9023\u7d50\u3055\u308c\u3066Kazuar\u306e\u30d5\u30a9\u30eb\u30c0\u304c\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u30b3\u30fc\u30c9\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u3001Kazuar\u306f\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u300clog\u300d\u30d5\u30a9\u30eb\u30c0\u5185\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u30ed\u30b0 \u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u3080\u3053\u3068\u3067\u3001\u81ea\u8eab\u306e\u6d3b\u52d5\u306e\u8a73\u7d30\u306a\u8a18\u9332\u3092\u6b8b\u3057\u307e\u3059\u3002Kazuar\u306f\u3053\u308c\u3089\u306e\u30ed\u30b0 \u30d5\u30a1\u30a4\u30eb\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u3001<a href=\"https:\/\/en.wikipedia.org\/wiki\/Advanced_Encryption_Standard\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">Rijndael cipher<\/a>\u3092\u4f7f\u3063\u3066\u6697\u53f7\u5316\u3057\u307e\u3059\u3002\u5f0a\u793e\u306f\u3001\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306e\u5b9f\u884c\u4e2d\u306b\u30ed\u30b0 \u30d5\u30a1\u30a4\u30eb\u306b\u8ffd\u52a0\u3055\u308c\u305f\u521d\u671f\u30a8\u30f3\u30c8\u30ea\u3092\u5fa9\u53f7\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u30a8\u30f3\u30c8\u30ea\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u60c5\u5831\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<pre class=\"\u201cwrap:true \" lang:default=\"\" decode:true=\"\"> malware_file_name[2720]: Kazuar's entry point started in process malware_file_name [2720] as user USERNAME<\/pre>\n<p>\u4e0a\u8a18\u30ed\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8\u304b\u3089\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4f5c\u6210\u8005\u304c\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u300cKazuar\u300d\u3068\u547c\u3093\u3067\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u300cKazuar\u300d\u3068\u3044\u3046\u8a00\u8449\u306f\u3001\u30dd\u30fc\u30e9\u30f3\u30c9\u8a9e\u3001\u30cf\u30f3\u30ac\u30ea\u30fc\u8a9e\u3001\u30b9\u30ed\u30d9\u30cb\u30a2\u8a9e\u306a\u3069\u306e\u3044\u304f\u3064\u304b\u306e\u8a00\u8a9e\u306b\u898b\u3089\u308c\u307e\u3059\u304c\u3001\u3053\u308c\u306f\u30ed\u30b7\u30a2\u8a9e\u306e\u5358\u8a9e\u300c\u043a\u0430\u0437\u0443\u0430\u0440\u300d\u3092ASCII\u5f62\u5f0f\u3067\u8868\u3057\u305f\u3082\u306e\u3067\u3059\u3002\u300cKazuar\u300d\u304a\u3088\u3073\u043a\u0430\u0437\u0443\u0430\u0440\u306f<a href=\"https:\/\/en.wikipedia.org\/wiki\/Cassowary\" target=\"_blank\" rel=\"noopener noreferrer\" data-page-track=\"true\" data-page-track-value=\"company:unit42-kazuar-multiplatform-espionage-backdoor-api-access: section: \">Cassowary (\u30d2\u30af\u30a4\u30c9\u30ea)<\/a>\u3068\u8a33\u3055\u308c\u307e\u3059\u3002\u30d2\u30af\u30a4\u30c9\u30ea(\u706b\u98df\u9ce5)\u306f\u30cb\u30e5\u30fc\u30ae\u30cb\u30a2\u7523\u306e\u5927\u5f62\u306e\u98db\u3079\u306a\u3044\u9ce5\u3067\u3001\u56f31\u306b\u3042\u308b\u3088\u3046\u306a\u59ff\u3092\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/01.png\" alt=\"\u56f31 \u30d2\u30af\u30a4\u30c9\u30ea(\u60c5\u5831\u6e90\u306fWikicommons)\" width=\"975\" height=\"731\" \/><figcaption class=\"wp-caption-text\">\u56f31 \u30d2\u30af\u30a4\u30c9\u30ea(\u60c5\u5831\u6e90\u306fWikicommons)<\/figcaption><\/figure>\n<\/div>\n<p>\u521d\u671f\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306e\u5f8c\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30e1\u30a4\u30f3 \u30a8\u30f3\u30c8\u30ea \u30dd\u30a4\u30f3\u30c8\u306b\u3042\u308b\u30e1\u30bd\u30c3\u30c9\u306f\u3001\u56f32\u3067\u793a\u3059\u3088\u3046\u306b\u30014\u3064\u306e\u4e3b\u8981\u5b9f\u884c\u30d1\u30b9\u306e\u3046\u3061\u3069\u308c\u304b\u3092\u305f\u3069\u308b\u3053\u3068\u306b\u306a\u308b\u3067\u3057\u3087\u3046\u3002\u30e1\u30a4\u30f3 \u30a8\u30f3\u30c8\u30ea \u30dd\u30a4\u30f3\u30c8\u306b\u306f\u6bd4\u8f03\u7684\u5358\u7d14\u306aif\u6587\u306e\u30bb\u30c3\u30c8\u304c\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u3053\u306eif\u6587\u306e\u30bb\u30c3\u30c8\u306b\u3088\u308a\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u30d1\u30b9\u304c\u6c7a\u5b9a\u3055\u308c\u307e\u3059\u3002\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u3001\u30d1\u30b9\u306e1\u3064\u306fMac\u307e\u305f\u306fUnix\u306e\u30db\u30b9\u30c8\u4e0a\u3067\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u3088\u3046\u306b\u898b\u53d7\u3051\u3089\u308c\u307e\u3059\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/02.png\" alt=\"\u56f32\u30e1\u30a4\u30f3 \u30a8\u30f3\u30c8\u30ea \u30dd\u30a4\u30f3\u30c8\u306b\u306f\u5b9f\u884c\u30d5\u30ed\u30fc\u3092\u5236\u5fa1\u3059\u308bif\u6587\u304c\u3042\u308b\" width=\"975\" height=\"1206\" \/><figcaption class=\"wp-caption-text\">\u56f32 \u30e1\u30a4\u30f3 \u30a8\u30f3\u30c8\u30ea \u30dd\u30a4\u30f3\u30c8\u306b\u306f\u5b9f\u884c\u30d5\u30ed\u30fc\u3092\u5236\u5fa1\u3059\u308bif\u6587\u304c\u3042\u308b<\/figcaption><\/figure>\n<\/div>\n<p>Kazuar\u306e\u30e1\u30a4\u30f3 \u30a8\u30f3\u30c8\u30ea \u30dd\u30a4\u30f3\u30c8\u306b\u3088\u3063\u3066\u9078\u629e\u3055\u308c\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u5b9f\u884c\u30d1\u30b9\u306f4\u3064\u3067\u3001\u305d\u308c\u3089\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ol>\n<li>\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u5f15\u6570\u306b\u300cinstall\u300d\u3092\u6307\u5b9a\u3055\u308c\u3066\u5b9f\u884c\u3055\u308c\u305f\u5834\u5408\u3001.NET Framwork\u306eInstallHelper\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u3063\u3066\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30b5\u30fc\u30d3\u30b9\u3068\u3057\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3002<\/li>\n<li>\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u30e6\u30fc\u30b6\u30fc\u3068\u306e\u975e\u5bfe\u8a71\u74b0\u5883(\u975e\u30e6\u30fc\u30b6\u30fc \u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9)\u306b\u304a\u3044\u3066\u958b\u59cb\u3057\u305f\u5834\u5408\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u81ea\u8eab\u3092\u30b5\u30fc\u30d3\u30b9\u3068\u3057\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3002<\/li>\n<li>\u5f15\u6570\u304c\u4e0e\u3048\u3089\u308c\u3066\u3044\u306a\u3044\u3067\u30de\u30eb\u30a6\u30a7\u30a2\u304cWindows\u74b0\u5883\u3067\u5b9f\u884c\u4e2d\u3067\u3042\u308b\u3068\u5224\u65ad\u3057\u305f\u5834\u5408\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306fexplorer.exe\u30d7\u30ed\u30bb\u30b9\u306b\u57cb\u3081\u8fbc\u3080DLL\u3092\u30b7\u30b9\u30c6\u30e0\u306b\u4fdd\u5b58\u3059\u308b\u3002\u57cb\u3081\u8fbc\u307e\u308c\u305fDLL\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30ed\u30fc\u30c9\u3057\u3001\u30ed\u30fc\u30c9\u3057\u305f\u3082\u306e\u3092explorer.exe\u30d7\u30ed\u30bb\u30b9\u306e\u30e1\u30e2\u30ea\u5185\u3067\u3092\u5b9f\u884c\u3059\u308b\u3002<\/li>\n<li>\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u5f15\u6570\u306b\u300csingle\u300d\u3092\u6307\u5b9a\u3055\u308c\u3066\u5b9f\u884c\u3055\u308c\u305f\u5834\u5408\u3001\u307e\u305f\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u304cMac\u307e\u305f\u306fUnix\u74b0\u5883\u3067\u5b9f\u884c\u4e2d\u3067\u3042\u308b\u3068\u5224\u65ad\u3057\u305f\u5834\u5408\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u3001Kazuar\u306e\u95a2\u6570\u30b3\u30fc\u30c9\u3092\u542b\u3080\u30e1\u30bd\u30c3\u30c9\u3092\u5b9f\u884c\u3057\u3001Mac\u307e\u305f\u306fUnix\u74b0\u5883\u304c\u691c\u77e5\u3055\u308c\u305f\u5834\u5408\u306b\u306f\u7279\u5b9a\u306eWindows\u5c02\u7528\u6a5f\u80fd\u3092\u5236\u9650\u3059\u308b\u3002<\/li>\n<\/ol>\n<p>\u5b9f\u884c\u30d5\u30ed\u30fc\u306f\u52d5\u4f5c\u74b0\u5883\u306b\u3088\u3063\u3066\u614e\u91cd\u306b\u5c0e\u304b\u308c\u307e\u3059\u3002\u3053\u308c\u306f.NET Framework\u306eEnvironment.OSVersion.Platform.PlatformID\u306e\u5217\u6319\u3092\u4f7f\u3063\u3066\u6c7a\u5b9a\u3055\u308c\u307e\u3059\u304c\u3001\u305d\u306e\u69d8\u5b50\u306f\u56f33\u306e\u95a2\u6570\u306b\u793a\u3059\u3068\u304a\u308a\u3067\u3059\u3002\u3053\u306e\u95a2\u6570\u306f\u30b7\u30b9\u30c6\u30e0\u56fa\u6709\u60c5\u5831\u306e\u53ce\u96c6\u3092\u62c5\u5f53\u3057\u3066\u3044\u307e\u3059\u3002\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u3001Unix\u306b\u95a2\u3059\u308bPlatformID\u5024\u7528\u306e\u7279\u5b9a\u306e\u30d6\u30fc\u30ea\u30a2\u30f3\u5909\u6570\u304c\u76ee\u306b\u7559\u307e\u308a\u307e\u3059\u3002\u3053\u308c\u3092\u898b\u308b\u3068\u3001\u3053\u306eAPI\u306b\u5bfe\u3057\u3066True(\u771f)\u3092\u8fd4\u3059\u6a19\u7684\u306eMac\u307e\u305f\u306fUnix\u306b\u5bfe\u3057\u3066\u3001Kazuar\u304c\u4f7f\u308f\u308c\u3066\u3044\u305f\u53ef\u80fd\u6027\u304c\u3046\u304b\u304c\u3048\u307e\u3059\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/03.png\" alt=\"\u56f33getsysinfo()\u95a2\u6570\u304cKazuar\u7528\u306b\u3055\u307e\u3056\u307e\u306a\u74b0\u5883\u5217\u6319\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308b\" width=\"975\" height=\"553\" \/><figcaption class=\"wp-caption-text\">\u56f33 getsysinfo()\u95a2\u6570\u304cKazuar\u7528\u306b\u3055\u307e\u3056\u307e\u306a\u74b0\u5883\u5217\u6319\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308b<\/figcaption><\/figure>\n<\/div>\n<p>\u52d5\u4f5c\u74b0\u5883\u306e\u5217\u6319\u3092\u7d42\u3048\u308b\u3068\u3001Kazuar\u306f\u30b7\u30b9\u30c6\u30e0\u306b\u5bfe\u3057\u3066\u6301\u7d9a\u7684\u306a\u30a2\u30af\u30bb\u30b9\u3092\u78ba\u7acb\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u56f34\u306b\u793a\u3059Autorun\u30af\u30e9\u30b9\u5185\u306e\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u3063\u3066Windows\u30b7\u30b9\u30c6\u30e0\u306b\u6301\u7d9a\u6027\u3092\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3057\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u4e0b\u8a18\u306e\u8907\u6570\u306e\u9078\u629e\u80a2\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ol>\n<li>\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8(lnk\u30d5\u30a1\u30a4\u30eb)\u3092Windows\u306e\u30b9\u30bf\u30fc\u30c8\u30a2\u30c3\u30d7 \u30d5\u30a9\u30eb\u30c0\u306b\u8ffd\u52a0\u3059\u308b<\/li>\n<li>\u30ab\u30ec\u30f3\u30c8 \u30e6\u30fc\u30b6\u30fc(HKCU)\u30cf\u30a4\u30d6\u5185\u306b\u3001\u4e0b\u8a18\u30d1\u30b9\u3078\u306e\u30b5\u30d6 \u30ad\u30fc\u3092\u8ffd\u52a0\u3059\u308b\n<ul>\n<li>SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run<\/li>\n<li>SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce<\/li>\n<li>SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run<\/li>\n<li>SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell<\/li>\n<li>SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\load<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/04.png\" alt=\"\u56f34Kazuar\u306eAutorun\u30af\u30e9\u30b9\u306f\u6301\u7d9a\u6027\u3092\u76ee\u7684\u3068\u3059\u308b\u8907\u6570\u306e\u9078\u629e\u80a2\u3092\u542b\u3093\u3060Windows\u5c02\u7528\u30e1\u30bd\u30c3\u30c9\u3067\u3001\u30b9\u30bf\u30fc\u30c8\u30a2\u30c3\u30d7 \u30d5\u30a9\u30eb\u30c0\u304a\u3088\u3073\u30ec\u30b8\u30b9\u30c8\u30ea\u3092\u4f7f\u7528\u3059\u308b\" width=\"975\" height=\"1273\" \/><figcaption class=\"wp-caption-text\">\u56f34Kazuar\u306eAutorun\u30af\u30e9\u30b9\u306f\u6301\u7d9a\u6027\u3092\u76ee\u7684\u3068\u3059\u308b\u8907\u6570\u306e\u9078\u629e\u80a2\u3092\u542b\u3093\u3060Windows\u5c02\u7528\u30e1\u30bd\u30c3\u30c9\u3067\u3001\u30b9\u30bf\u30fc\u30c8\u30a2\u30c3\u30d7 \u30d5\u30a9\u30eb\u30c0\u304a\u3088\u3073\u30ec\u30b8\u30b9\u30c8\u30ea\u3092\u4f7f\u7528\u3059\u308b<\/figcaption><\/figure>\n<\/div>\n<h3>\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb(C2)<\/h3>\n<p>Kazuar\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u521d\u3081\u306b\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb \u30c1\u30e3\u30cd\u30eb\u3092\u4f7f\u3063\u3066\u3001\u653b\u6483\u8005\u304c\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u3068\u5bfe\u8a71\u3057\u3066\u30c7\u30fc\u30bf\u3092\u5bc6\u304b\u306b\u76d7\u307f\u51fa\u3059\u3053\u3068\u304c\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002Kazuar\u306fHTTP\u3001HTTPS\u3001FTP\u307e\u305f\u306fFTPS\u306a\u3069\u306e\u8907\u6570\u306e\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u3046\u6a5f\u80fd\u3092\u5099\u3048\u3066\u304a\u308a\u3001\u30d7\u30ed\u30c8\u30b3\u30eb\u306f\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u5316\u3055\u308c\u305fC2\u306eURL\u306e\u63a5\u982d\u8f9e\u306b\u3088\u3063\u3066\u6c7a\u5b9a\u3055\u308c\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u306e\u3068\u3053\u308d\u3001\u5f0a\u793e\u306b\u3042\u308b\u30b5\u30f3\u30d7\u30eb \u30bb\u30c3\u30c8\u3067\u306fC2\u30d7\u30ed\u30c8\u30b3\u30eb\u3068\u3057\u3066\u4f7f\u308f\u308c\u3066\u3044\u308b\u306e\u306fHTTP\u3057\u304b\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002Kazuar\u306e\u65e2\u77e5\u306eC2\u30b5\u30fc\u30d0\u306f\u3059\u3079\u3066\u3001\u4fb5\u5bb3\u3055\u308c\u305fWordPress\u30d6\u30ed\u30b0 \u30b5\u30a4\u30c8\u306e\u3082\u306e\u306e\u3088\u3046\u3067\u3059\u3002\u3053\u306e\u3053\u3068\u304b\u3089\u3001Kazuar\u3092\u653b\u6483\u306b\u4f7f\u3063\u3066\u3044\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306f\u8106\u5f31\u6027\u306e\u3042\u308bWordPress\u30b5\u30a4\u30c8\u3092\u81ea\u5206\u305f\u3061\u306e\u30d7\u30ec\u30a4\u30d6\u30c3\u30af\u306e\u4e00\u90e8\u3068\u3057\u3066\u898b\u3064\u3051\u51fa\u3057\u3001\u60aa\u7528\u3057\u3066\u3044\u308b\u3053\u3068\u3082\u3046\u304b\u304c\u3048\u307e\u3059\u3002<\/p>\n<p>\u81ea\u8eab\u306eC2\u30b5\u30fc\u30d0\u3068\u5bfe\u8a71\u3059\u308b\u305f\u3081\u3001Kazuar\u306f\u30d3\u30fc\u30b3\u30f3\u3068\u3057\u3066\u4f7f\u3046HTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u751f\u6210\u3059\u308b\u3053\u3068\u304b\u3089\u3084\u308a\u53d6\u308a\u3092\u59cb\u3081\u307e\u3059\u3002\u3053\u306e\u30d3\u30fc\u30b3\u30f3\u306f\u56f35\u306b\u3042\u308b\u30b3\u30fc\u30c9\u306b\u3088\u3063\u3066\u751f\u6210\u3055\u308c\u3001\u300cAuthToken\u300d\u5024\u3092\u6301\u3064\u30af\u30c3\u30ad\u30fc\u304c\u4e2d\u306b\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u300cAuthToken\u300d\u5024\u306f\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u3092\u4e00\u610f\u306b\u8b58\u5225\u3059\u308b\u306e\u306b\u4f7f\u3046GUID\u3092base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3057\u305f\u3082\u306e\u3067\u3059\u3002Kazuar\u306f\u3053\u306eGUID\u3092\u300cagent\u300d\u8b58\u5225\u5b50\u3068\u3057\u3066\u53c2\u7167\u3057\u307e\u3059\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/05.png\" alt=\"\u56f35createGET\u304a\u3088\u3073getWebRequest\u30af\u30e9\u30b9\u306f\u3001\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u901a\u4fe1\u306b\u4f7f\u308f\u308c\u308bHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u69cb\u7bc9\u3092\u5b9a\u7fa9\u3059\u308b\" width=\"975\" height=\"905\" \/><figcaption class=\"wp-caption-text\">\u56f35 createGET\u304a\u3088\u3073getWebRequest\u30af\u30e9\u30b9\u306f\u3001\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u901a\u4fe1\u306b\u4f7f\u308f\u308c\u308bHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u69cb\u7bc9\u3092\u5b9a\u7fa9\u3059\u308b<\/figcaption><\/figure>\n<\/div>\n<p>\u5206\u6790\u4e2d\u3001\u5f0a\u793e\u306f\u56f36\u306b\u3042\u308b\u30d3\u30fc\u30b3\u30f3\u304cHTTP\u306b\u3088\u308aKazuar\u30b5\u30f3\u30d7\u30eb\u304b\u3089\u305d\u306eC2\u30b5\u30fc\u30d0\u306b\u9001\u4fe1\u3055\u308c\u308b\u306e\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u6700\u521d\u306eHTTP\u30d3\u30fc\u30b3\u30f3\u3092\u898b\u308b\u3068\u3001Cookie\u30d5\u30a3\u30fc\u30eb\u30c9\u5185\u306bbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fAuthToken\u5024\u304c\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002C2\u30b5\u30fc\u30d0\u304c\u3053\u308c\u3092\u4f7f\u3063\u3066\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30db\u30b9\u30c8\u3092\u4e00\u610f\u306b\u8b58\u5225\u5b50\u3057\u3066\u500b\u3005\u306b\u8ffd\u8de1\u3057\u3066\u3044\u308b\u306e\u306b\u9055\u3044\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/06.png\" alt=\"\u56f36\u5b8c\u5168\u306b\u69cb\u6210\u3055\u308c\u305fHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306eWireshark\u30b9\u30cb\u30da\u30c3\u30c8(base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fGUID\u304cCookie\u30d8\u30c3\u30c0\u30fc\u5185\u306b\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308b)\" width=\"975\" height=\"206\" \/><figcaption class=\"wp-caption-text\">\u56f36 \u5b8c\u5168\u306b\u69cb\u6210\u3055\u308c\u305fHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306eWireshark\u30b9\u30cb\u30da\u30c3\u30c8(base64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fGUID\u304cCookie\u30d8\u30c3\u30c0\u30fc\u5185\u306b\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308b)<\/figcaption><\/figure>\n<\/div>\n<p>Kazuar\u306fC2\u30b5\u30fc\u30d0\u304b\u3089\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u8aad\u307f\u3001\u3053\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3092XML\u5f62\u5f0f\u306e\u30c7\u30fc\u30bf\u3068\u3057\u3066\u89e3\u6790\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002XML\u5f62\u5f0f\u306e\u30c7\u30fc\u30bf\u306b\u306fKazuar\u304c\u300ctask\u300d\u3068\u3057\u3066\u53c2\u7167\u3059\u308b\u5185\u5bb9\u304c\u542b\u307e\u308c\u3001\u305d\u306e\u5185\u5bb9\u306f\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50\u304a\u3088\u3073\u5404\u52d5\u4f5c\u306b\u95a2\u3059\u308b\u5c02\u7528\u306e\u5f15\u6570\u304b\u3089\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u4e0b\u306e\u56f37\u3067\u793a\u3057\u305f\u30b3\u30fc\u30c9\u306f\u3001HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3059\u308b\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u53d7\u4fe1\u3057\u3001\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50\u3068\u3057\u3066\u5909\u6570\u300cnum\u300d\u306b\u4fdd\u5b58\u3055\u308c\u305flong\u578b\u6574\u6570\u3092\u4f7f\u3046\u5f79\u5272\u3092\u62c5\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/07.png\" alt=\"\u56f37\u30ec\u30b9\u30dd\u30f3\u30b9\u89e3\u6790\u90e8\u306f\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb \u30b5\u30fc\u30d0\u304b\u3089\u65b0\u305f\u306a\u30bf\u30b9\u30af\u304c\u5c4a\u3044\u3066\u3044\u306a\u3044\u304b\u30ea\u30c3\u30b9\u30f3\u3059\u308b\" width=\"975\" height=\"826\" \/><figcaption class=\"wp-caption-text\">\u56f37 \u30ec\u30b9\u30dd\u30f3\u30b9\u89e3\u6790\u90e8\u306f\u30b3\u30de\u30f3\u30c9\u30a2\u30f3\u30c9\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb \u30b5\u30fc\u30d0\u304b\u3089\u65b0\u305f\u306a\u30bf\u30b9\u30af\u304c\u5c4a\u3044\u3066\u3044\u306a\u3044\u304b\u30ea\u30c3\u30b9\u30f3\u3059\u308b<\/figcaption><\/figure>\n<\/div>\n<p>\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50\u306f\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u653b\u6483\u8005\u304c\u5b9f\u884c\u3057\u305f\u3044\u30b3\u30de\u30f3\u30c9\u3068\u76f4\u63a5\u95a2\u9023\u3057\u3066\u3044\u307e\u3059\u3002\u9a5a\u3044\u305f\u3053\u3068\u306b\u3001Kazuar\u306b\u306f\u5404\u30b3\u30de\u30f3\u30c9\u7528\u306b\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50\u3068\u305d\u306e\u30b3\u30de\u30f3\u30c9\u3092\u8aac\u660e\u3057\u3066\u3044\u308b\u6587\u5b57\u5217\u3068\u3092\u540c\u3058\u3082\u306e\u3068\u307f\u306a\u3059\u30e1\u30bd\u30c3\u30c9\u3082\u542b\u307e\u308c\u3066\u304a\u308a\u3001\u3053\u306e\u3053\u3068\u304b\u3089\u5404\u30b3\u30de\u30f3\u30c9\u306e\u76ee\u7684\u3092\u5224\u65ad\u3059\u308b\u3053\u3068\u304c\u304b\u306a\u308a\u5bb9\u6613\u306b\u306a\u308a\u307e\u3059\u3002\u88682\u306fKazuar\u5185\u3067\u5229\u7528\u53ef\u80fd\u306a\u30b3\u30de\u30f3\u30c9\u306e\u30ea\u30b9\u30c8\u3067\u3042\u308a\u3001\u5404\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50\u3001\u30b3\u30de\u30f3\u30c9\u6587\u5b57\u5217\u304a\u3088\u3073\u8aac\u660e\u3092\u5177\u4f53\u7684\u306b\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table class=\"table table-bordered\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"77\"><b>\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50<\/b><\/td>\n<td valign=\"top\" width=\"91\"><b>\u30b3\u30de\u30f3\u30c9<\/b><\/td>\n<td valign=\"top\" width=\"463\"><b>\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>1<\/b><\/td>\n<td valign=\"top\" width=\"91\">log<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30c7\u30d0\u30c3\u30b0 \u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u8a18\u9332\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>2<\/b><\/td>\n<td valign=\"top\" width=\"91\">get<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u4fee\u6b63\u6642\u3001\u30a2\u30af\u30bb\u30b9\u6642\u304a\u3088\u3073\u4f5c\u6210\u6642\u306e\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u306b\u57fa\u3065\u3044\u3066\u3001\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u6307\u5b9a\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u308b\u3088\u3046\u3067\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>3<\/b><\/td>\n<td valign=\"top\" width=\"91\">put<\/td>\n<td valign=\"top\" width=\"463\">\u63d0\u4f9b\u3055\u308c\u305f\u30c7\u30fc\u30bf(\u300c\u30da\u30a4\u30ed\u30fc\u30c9\u300d\u3068\u547c\u3070\u308c\u308b)\u3092\u3001\u30b7\u30b9\u30c6\u30e0\u4e0a\u306e\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u307f\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>4<\/b><\/td>\n<td valign=\"top\" width=\"91\">cmd<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001\u305d\u306e\u51fa\u529b\u3092\u4e00\u6642\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u307f\u307e\u3059\u3002\u4e00\u6642\u30d5\u30a1\u30a4\u30eb\u306fC2\u30b5\u30fc\u30d0\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>5<\/b><\/td>\n<td valign=\"top\" width=\"91\">sleep<\/td>\n<td valign=\"top\" width=\"463\">\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u6307\u5b9a\u3055\u308c\u305f\u6642\u9593\u9577\u306b\u308f\u305f\u308a\u30b9\u30ea\u30fc\u30d7\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>6<\/b><\/td>\n<td valign=\"top\" width=\"91\">upgrade<\/td>\n<td valign=\"top\" width=\"463\">\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u66f4\u65b0\u3057\u307e\u3059\u3002\u305d\u306e\u969b\u3001\u73fe\u5728\u306e\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306e\u62e1\u5f35\u5b50\u3092\u300c.old\u300d\u306b\u5909\u66f4\u3057\u3001\u65b0\u305f\u306b\u63d0\u4f9b\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u3057\u304b\u308b\u3079\u304d\u5834\u6240\u306b\u66f8\u304d\u8fbc\u307f\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>7<\/b><\/td>\n<td valign=\"top\" width=\"91\">scrshot<\/td>\n<td valign=\"top\" width=\"463\">\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u753b\u9762\u5168\u4f53\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3092\u64ae\u308a\u307e\u3059\u3002\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306f\u3001\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u540d\u3067\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002\u307e\u305f\u306f\u3001[\u5e74]-[\u6708]-[\u65e5]-[\u6642]-[\u5206]-[\u79d2]-[\u30df\u30ea\u79d2].jpg\u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u540d\u3067\u4fdd\u5b58\u3055\u308c\u307e\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u306fC2\u30b5\u30fc\u30d0\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>8<\/b><\/td>\n<td valign=\"top\" width=\"91\">camshot<\/td>\n<td valign=\"top\" width=\"463\">\u300cWebCapt\u300d\u3068\u3044\u3046\u30a6\u30a3\u30f3\u30c9\u30a6\u3092\u4f5c\u6210\u3057\u3001\u4ed8\u5c5e\u306eWeb\u30ab\u30e1\u30e9\u304b\u3089\u753b\u50cf\u3092\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u307e\u3059\u3002\u30ad\u30e3\u30d7\u30c1\u30e3\u753b\u50cf\u306f\u30af\u30ea\u30c3\u30d7\u30dc\u30fc\u30c9\u306b\u30b3\u30d4\u30fc\u3055\u308c\u3001\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u307e\u305f\u306f\u300cscrshot\u300d\u30b3\u30de\u30f3\u30c9\u306e\u3068\u304d\u3068\u540c\u3058\u5f62\u5f0f\u306e\u540d\u524d\u306e\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u307e\u308c\u307e\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u306fC2\u30b5\u30fc\u30d0\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>9<\/b><\/td>\n<td valign=\"top\" width=\"91\">uuid<\/td>\n<td valign=\"top\" width=\"463\">\u7279\u5b9a\u306eGUID\u3092\u63d0\u4f9b\u3059\u308b\u3053\u3068\u3067\u3001\u4e00\u610f\u306e\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u8b58\u5225\u5b50\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>10<\/b><\/td>\n<td valign=\"top\" width=\"91\">interval<\/td>\n<td valign=\"top\" width=\"463\">\u8ee2\u9001\u9593\u9694\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001C2\u901a\u4fe1\u3069\u3046\u3057\u306e\u6700\u5c0f\u304a\u3088\u3073\u6700\u5927\u306e\u6642\u9593\u9593\u9694\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>11<\/b><\/td>\n<td valign=\"top\" width=\"91\">server<\/td>\n<td valign=\"top\" width=\"463\">URL\u306e\u30ea\u30b9\u30c8\u3092\u63d0\u4f9b\u3059\u308b\u3053\u3068\u3067\u3001C2\u30b5\u30fc\u30d0\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>12<\/b><\/td>\n<td valign=\"top\" width=\"91\">transport<\/td>\n<td valign=\"top\" width=\"463\">\u30d7\u30ed\u30bb\u30b9\u306e\u30ea\u30b9\u30c8\u3092\u63d0\u4f9b\u3059\u308b\u3053\u3068\u3067\u3001\u8ee2\u9001\u30d7\u30ed\u30bb\u30b9\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30d7\u30ed\u30bb\u30b9\u306b\u306fKazuar\u306e\u30b3\u30fc\u30c9\u304c\u633f\u5165\u3055\u308c\u3001\u633f\u5165\u3055\u308c\u305f\u30b3\u30fc\u30c9\u304c\u30d7\u30ed\u30bb\u30b9\u5185\u90e8\u3067\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>13<\/b><\/td>\n<td valign=\"top\" width=\"91\">autorun<\/td>\n<td valign=\"top\" width=\"463\">Autorun\u30bf\u30a4\u30d7\u3092\u3001\u3053\u306e\u30d6\u30ed\u30b0\u3067\u524d\u8ff0\u3057\u305f\u3068\u304a\u308a\u306b\u8a2d\u5b9a\u3057\u307e\u3059\u3002Kazuar\u306f\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306b\u5bfe\u3057\u3066\u3001\u4ee5\u4e0b\u306e\u6587\u5b57\u5217\u3092\u53d7\u3051\u4ed8\u3051\u307e\u3059\u3002DISABLED\u3001WINLOGON\u3001POLICIES\u3001HKCURUN\u3001RUNONCE\u3001LOADKEY\u3001STARTUP<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>14<\/b><\/td>\n<td valign=\"top\" width=\"91\">remote<\/td>\n<td valign=\"top\" width=\"463\">\u30ea\u30e2\u30fc\u30c8 \u30bf\u30a4\u30d7\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002\u5f0a\u793e\u3067\u8a8d\u8b58\u3057\u3066\u3044\u308b\u30ea\u30e2\u30fc\u30c8 \u30bf\u30a4\u30d7\u306f1\u3064\u3060\u3051\u3067\u3059\u3002\u305d\u306e\u30bf\u30a4\u30d7\u306e\u6307\u793a\u306b\u3088\u308a\u3001Kazuar\u306fHTTP\u30b5\u30fc\u30d0\u3068\u3057\u3066\u632f\u308b\u821e\u3044\u3001\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3057\u3066\u653b\u6483\u8005\u304c\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u3068\u5bfe\u8a71\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>15<\/b><\/td>\n<td valign=\"top\" width=\"91\">info<\/td>\n<td valign=\"top\" width=\"463\">\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3092\u53ce\u96c6\u3057\u307e\u3059\u3002\u5177\u4f53\u7684\u306a\u60c5\u5831\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u60c5\u5831\u3001\u30b7\u30b9\u30c6\u30e0\u60c5\u5831\u3001\u30e6\u30fc\u30b6\u30fc\u60c5\u5831\u3001\u30ed\u30fc\u30ab\u30eb \u30b0\u30eb\u30fc\u30d7\u304a\u3088\u3073\u30e1\u30f3\u30d0\u30fc\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6e08\u307f\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3001\u7279\u6b8a\u30d5\u30a9\u30eb\u30c0\u3001\u74b0\u5883\u5909\u6570\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30a2\u30c0\u30d7\u30bf\u3001\u30a2\u30af\u30c6\u30a3\u30d6\u306a\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u63a5\u7d9a\u3001\u8ad6\u7406\u30c9\u30e9\u30a4\u30d6\u3001\u5b9f\u884c\u4e2d\u306e\u30d7\u30ed\u30bb\u30b9\u304a\u3088\u3073\u958b\u3044\u3066\u3044\u308b\u30a6\u30a3\u30f3\u30c9\u30a6<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>16<\/b><\/td>\n<td valign=\"top\" width=\"91\">copy<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u6307\u5b9a\u3055\u308c\u305f\u5834\u6240\u306b\u30b3\u30d4\u30fc\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u30b3\u30d4\u30fc\u5148\u30d5\u30a1\u30a4\u30eb\u304c\u3059\u3067\u306b\u5b58\u5728\u3057\u3066\u3044\u308b\u5834\u5408\u3001\u305d\u306e\u30d5\u30a1\u30a4\u30eb\u306b\u5bfe\u3057\u3066\u4e0a\u66f8\u304d\u3059\u308b\u305f\u3081\u306e\u30d5\u30e9\u30b0\u3092C2\u304c\u4ed8\u3051\u308b\u306e\u3092\u8a31\u53ef\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>17<\/b><\/td>\n<td valign=\"top\" width=\"91\">move<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u6307\u5b9a\u3055\u308c\u305f\u5834\u6240\u306b\u79fb\u52d5\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u30b3\u30d4\u30fc\u5148\u30d5\u30a1\u30a4\u30eb\u304c\u3059\u3067\u306b\u5b58\u5728\u3057\u3066\u3044\u308b\u5834\u5408\u3001\u305d\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3059\u308b\u305f\u3081\u306e\u30d5\u30e9\u30b0\u3092C2\u304c\u4ed8\u3051\u308b\u306e\u3092\u8a31\u53ef\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>18<\/b><\/td>\n<td valign=\"top\" width=\"91\">remove<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3057\u307e\u3059\u3002\u5b89\u5168\u306b\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3059\u308b\u305f\u3081\u306e\u30d5\u30e9\u30b0\u3092C2\u304c\u4ed8\u3051\u308b\u3053\u3068\u3092\u8a31\u53ef\u3057\u307e\u3059\u304c\u3001\u305d\u306e\u5834\u5408\u3001\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3059\u308b\u524d\u306b\u30e9\u30f3\u30c0\u30e0 \u30c7\u30fc\u30bf\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u4e0a\u66f8\u304d\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>19<\/b><\/td>\n<td valign=\"top\" width=\"91\">finddir<\/td>\n<td valign=\"top\" width=\"463\">\u6307\u5b9a\u3055\u308c\u305f\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u898b\u3064\u3051\u3001\u305d\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u30ea\u30b9\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u30ea\u30b9\u30c8\u306e\u5185\u5bb9\u306f\u3001\u4f5c\u6210\u6642\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u3001\u4fee\u6b63\u6642\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u3001\u30b5\u30a4\u30ba\u3001\u304a\u3088\u3073\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u5185\u306e\u5404\u30d5\u30a1\u30a4\u30eb\u306e\u30d5\u30a1\u30a4\u30eb \u30d1\u30b9\u3067\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>20<\/b><\/td>\n<td valign=\"top\" width=\"91\">kill<\/td>\n<td valign=\"top\" width=\"463\">\u540d\u524d\u307e\u305f\u306f\u30d7\u30ed\u30bb\u30b9\u8b58\u5225\u5b50(PID)\u306b\u3088\u308a\u30d7\u30ed\u30bb\u30b9\u3092kill\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>21<\/b><\/td>\n<td valign=\"top\" width=\"91\">tasklisk<\/td>\n<td valign=\"top\" width=\"463\">\u5b9f\u884c\u4e2d\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u30ea\u30b9\u30c8\u3092\u8868\u793a\u3057\u307e\u3059\u3002WMI\u30af\u30a8\u30ea\u300cselect * from Win32_Process\u300d\u3092Windows\u30b7\u30b9\u30c6\u30e0\u306b\u5bfe\u3057\u3066\u4f7f\u3044\u307e\u3059\u304c\u3001\u300cps -eo comm,pid,ppid,user,start,tty,args\u300d\u3092\u5b9f\u884c\u3057\u3066\u3001\u5b9f\u884c\u4e2d\u30d7\u30ed\u30bb\u30b9\u306e\u60c5\u5831\u3092Unix\u30b7\u30b9\u30c6\u30e0\u304b\u3089\u53d6\u5f97\u3059\u308b\u3053\u3068\u3082\u53ef\u80fd\u3067\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>22<\/b><\/td>\n<td valign=\"top\" width=\"91\">suicide<\/td>\n<td valign=\"top\" width=\"463\">\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306f\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u30a2\u30f3\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u305f\u3081\u306e\u3082\u306e\u3068\u5f0a\u793e\u3067\u306f\u898b\u3066\u304a\u308a\u307e\u3059\u304c\u3001\u65e2\u77e5\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u4eca\u306e\u3068\u3053\u308d\u5b9f\u88c5\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>23<\/b><\/td>\n<td valign=\"top\" width=\"91\">plugin<\/td>\n<td valign=\"top\" width=\"463\">\u4e0e\u3048\u3089\u308c\u305f\u30a2\u30bb\u30f3\u30d6\u30ea\u3092\u30ed\u30fc\u30c9\u3059\u308b\u3053\u3068\u3067\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u30a2\u30bb\u30f3\u30d6\u30ea\u306e\u540d\u524d\u306eMD5\u30cf\u30c3\u30b7\u30e5\u3092\u540d\u524d\u3068\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u306b\u3001\u3053\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u4fdd\u5b58\u3057\u3001\u300cStart\u300d\u3068\u3044\u3046\u30e1\u30bd\u30c3\u30c9\u3092\u547c\u3073\u51fa\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>24<\/b><\/td>\n<td valign=\"top\" width=\"91\">plugout<\/td>\n<td valign=\"top\" width=\"463\">\u30a2\u30bb\u30f3\u30d6\u30ea\u306e\u540d\u524d\u306b\u57fa\u3065\u3044\u3066\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u524a\u9664\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>25<\/b><\/td>\n<td valign=\"top\" width=\"91\">pluglist<\/td>\n<td valign=\"top\" width=\"463\">\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u30ea\u30b9\u30c8\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002\u30d7\u30e9\u30b0\u30a4\u30f3\u304c\u300c\u7a3c\u50cd\u4e2d\u300d\u3067\u3042\u308b\u304b\u300c\u505c\u6b62\u4e2d\u300d\u3067\u3042\u308b\u304b\u306b\u3064\u3044\u3066\u3082\u3001\u30ea\u30b9\u30c8\u306b\u4f75\u8a18\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"77\"><b>26<\/b><\/td>\n<td valign=\"top\" width=\"91\">run<\/td>\n<td valign=\"top\" width=\"463\">\u4e0e\u3048\u3089\u308c\u305f\u5f15\u6570\u3092\u4f7f\u3063\u3066\u3001\u6307\u5b9a\u3055\u308c\u305f\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u5b9f\u884c\u3057\u3001\u305d\u306e\u51fa\u529b\u3092\u4e00\u6642\u30d5\u30a1\u30a4\u30eb\u306b\u4fdd\u5b58\u3057\u307e\u3059\u3002\u4e00\u6642\u30d5\u30a1\u30a4\u30eb\u306fC2\u30b5\u30fc\u30d0\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><i>\u88682 Kazuar\u306e\u30b3\u30de\u30f3\u30c9 \u30cf\u30f3\u30c9\u30e9(\u30a2\u30af\u30b7\u30e7\u30f3\u8b58\u5225\u5b50\u3001\u30b3\u30de\u30f3\u30c9\u6587\u5b57\u5217\u304a\u3088\u3073\u8aac\u660e)<\/i><\/span><\/p>\n<h3>\u6a5f\u80fd<\/h3>\n<p>\u4e0a\u306e\u88682\u304b\u3089\u308f\u304b\u308b\u3088\u3046\u306b\u3001Kazuar\u306b\u306f\u591a\u5f69\u306a\u30b3\u30de\u30f3\u30c9 \u30bb\u30c3\u30c8\u304c\u5099\u308f\u3063\u3066\u304a\u308a\u3001\u305d\u306e\u591a\u304f\u304c\u6a5f\u80fd\u306b\u304a\u3044\u3066\u4ed6\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3068\u985e\u4f3c\u3057\u3066\u3044\u307e\u3059\u3002\u3057\u304b\u3057\u3001\u3044\u304f\u3064\u304b\u306eKazuar\u5c02\u7528\u30b3\u30de\u30f3\u30c9\u306f\u72ec\u7279\u3067\u3001\u3055\u3089\u306b\u8003\u5bdf\u3092\u9032\u3081\u308b\u4fa1\u5024\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u307e\u305a\u3001\u3053\u308c\u3089\u306e\u30b3\u30de\u30f3\u30c9\u306e\u3044\u304f\u3064\u304b\u306b\u306f\u3001\u9069\u5207\u306a\u30d1\u30b9\u307e\u305f\u306f\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u7528\u3059\u308b\u305f\u3081\u306b\u74b0\u5883\u5224\u5b9a\u3092\u884c\u3046\u30c1\u30a7\u30c3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u300ctasklist\u300d\u30b3\u30de\u30f3\u30c9\u306fWMI\u30af\u30a8\u30ea\u307e\u305f\u306f\u300cps\u300d\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3044\u3001\u3053\u308c\u306b\u3088\u308a\u3001Kazuar\u306f\u5b9f\u884c\u4e2d\u30d7\u30ed\u30bb\u30b9\u306e\u60c5\u5831\u3092Windows\u30b7\u30b9\u30c6\u30e0\u304a\u3088\u3073Unix\u30b7\u30b9\u30c6\u30e0\u306e\u3044\u305a\u308c\u304b\u3089\u3082\u53d6\u5f97\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u307e\u305f\u3001Kazuar\u306e\u300ccmd\u300d\u30b3\u30de\u30f3\u30c9\u306f\u3001Windows\u30b7\u30b9\u30c6\u30e0\u306b\u5bfe\u3057\u3066\u306f\u300ccmd.exe\u300d\u3092\u4f7f\u3063\u3066\u3001Unix\u30b7\u30b9\u30c6\u30e0\u306b\u5bfe\u3057\u3066\u306f\u300c\/bin\/bash\u300d\u3092\u4f7f\u3063\u3066\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u3053\u306e2\u3064\u306e\u30b3\u30de\u30f3\u30c9\u306f\u3001Kazuar\u306e\u4f5c\u6210\u8005\u304c\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30af\u30ed\u30b9 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u578b\u30c4\u30fc\u30eb\u3068\u3057\u3066\u4f7f\u3063\u3066Windows\u304a\u3088\u3073Unix\u306e\u4e21\u30b7\u30b9\u30c6\u30e0\u3092\u6a19\u7684\u306b\u3059\u308b\u3064\u3082\u308a\u3067\u3044\u305f\u3053\u3068\u3092\u793a\u3059\u8a3c\u62e0\u3067\u3059\u3002<\/p>\n<p>Kazuar\u306b\u306f\u30d7\u30e9\u30b0\u30a4\u30f3\u95a2\u9023\u306e\u30b3\u30de\u30f3\u30c9\u3068\u3057\u3066\u6b21\u306e3\u3064\u304c\u3042\u308a\u307e\u3059\u3002<i>plugin\u3001plugout<\/i>\u304a\u3088\u3073<i>pluglist<\/i>\u3002\u3053\u306e3\u3064\u306e\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3046\u3053\u3068\u3067\u3001\u653b\u6483\u8005\u306fKazuar\u304c\u8ffd\u52a0\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u5229\u7528\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3092\u7ba1\u7406\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u30d7\u30e9\u30b0\u30a4\u30f3 \u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u306b\u3088\u308a\u3001Kazuar\u306f\u6f5c\u5728\u7684\u306b\u969b\u9650\u306e\u306a\u3044\u6a5f\u80fd\u3092\u624b\u306b\u5165\u308c\u308b\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002\u305d\u308c\u306f\u3001Kazuar\u304c\u30ed\u30fc\u30c9\u3057\u3001\u5b9f\u884c\u3059\u308b\u65b0\u305f\u306a.NET\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u3001Kazuar\u306e\u30aa\u30da\u30ec\u30fc\u30bf\u30fc\u304c\u63d0\u4f9b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u304b\u3089\u3067\u3059\u3002<\/p>\n<h3>Kazuar\u306e\u30ea\u30e2\u30fc\u30c8API<\/h3>\n<p>\u591a\u304f\u306e\u30d0\u30c3\u30af\u30c9\u30a2\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306b\u591a\u5f69\u306a\u30b3\u30de\u30f3\u30c9 \u30cf\u30f3\u30c9\u30e9\u3068\u30d7\u30e9\u30b0\u30a4\u30f3 \u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u304c\u5099\u308f\u3063\u3066\u3044\u308b\u306e\u306b\u5bfe\u3057\u3001Kazuar\u306e\u300cremote\u300d\u30b3\u30de\u30f3\u30c9\u306b\u306f\u30b9\u30d1\u30a4\u653b\u6483\u6d3b\u52d5\u3067\u4f7f\u308f\u308c\u305f\u30d0\u30c3\u30af\u30c9\u30a2\u306b\u306f\u3081\u3063\u305f\u306b\u898b\u3089\u308c\u306a\u3044\u6a5f\u80fd\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306f\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306b\u5bfe\u3057\u3066\u3001\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30ea\u30c3\u30b9\u30f3\u3059\u308b\u30b9\u30ec\u30c3\u30c9\u3092\u958b\u59cb\u3059\u308b\u3088\u3046\u6307\u793a\u3057\u307e\u3059\u3002\u3053\u306e\u7d50\u679c\u3001\u5b9f\u8cea\u4e0a\u3001Kazuar\u306fWeb\u30b5\u30fc\u30d0\u306b\u5909\u8eab\u3057\u307e\u3059\u3002\u3053\u306e\u6a5f\u80fd\u306f\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u4e0a\u3067\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304c\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306eAPI\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u56f38\u306f\u3001\u3053\u306e\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308bKazuar\u5185\u306e\u30b3\u30fc\u30c9\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<div align=\"center\">\n<figure style=\"width: 975px\" class=\"wp-caption aligncenter\"><img  data-src=\"https:\/\/www.paloaltonetworks.jp\/content\/dam\/pan\/ja_JP\/Images\/blog\/2017\/87644\/08.png\" alt=\"\u56f38 \u8105\u5a01\u306e\u653b\u6483\u8005\u306bAPI\u30a2\u30af\u30bb\u30b9\u3092\u63d0\u4f9b\u3059\u308b\u305f\u3081\u306bKazuar\u304c\u4f7f\u7528\u3059\u308bHTTP\u30e1\u30bd\u30c3\u30c9 \u30cf\u30f3\u30c9\u30e9\" width=\"975\" height=\"709\" \/><figcaption class=\"wp-caption-text\">\u56f38 \u8105\u5a01\u306e\u653b\u6483\u8005\u306bAPI\u30a2\u30af\u30bb\u30b9\u3092\u63d0\u4f9b\u3059\u308b\u305f\u3081\u306bKazuar\u304c\u4f7f\u7528\u3059\u308bHTTP\u30e1\u30bd\u30c3\u30c9 \u30cf\u30f3\u30c9\u30e9<\/figcaption><\/figure>\n<\/div>\n<p>\u3053\u306e\u6a5f\u80fd\u3092\u958b\u59cb\u3059\u308b\u305f\u3081\u3001\u653b\u6483\u8005\u306f\u300cremote\u300d\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3057\u3001URI\u63a5\u982d\u8f9e\u306e\u30ea\u30b9\u30c8\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u3053\u306e\u63a5\u982d\u8f9e\u3092Kazuar\u306eHTTP\u30ea\u30b9\u30ca\u30fc\u304c\u51e6\u7406\u3057\u3001\u5fdc\u7b54\u3057\u307e\u3059\u3002\u653b\u6483\u8005\u304c\u63d0\u4f9b\u3059\u308bURI\u63a5\u982d\u8f9e\u306f\u3001HttpListener\u30af\u30e9\u30b9\u306e\u300cPrefixes\u300d\u30d7\u30ed\u30d1\u30c6\u30a3\u306b\u8ffd\u52a0\u3055\u308c\u308b\u3067\u3057\u3087\u3046\u304c\u3001\u3053\u306e\u30d7\u30ed\u30d1\u30c6\u30a3\u306b\u306f\u30b9\u30ad\u30fc\u30de\u3001\u30db\u30b9\u30c8\u3001\u30aa\u30d7\u30b7\u30e7\u30f3\u306e\u30dd\u30fc\u30c8\u304a\u3088\u3073\u30aa\u30d7\u30b7\u30e7\u30f3\u306e\u30d1\u30b9\u304c\u5fc5\u8981\u3068\u306a\u308a\u307e\u3059\u3002\u7d9a\u3044\u3066\u653b\u6483\u8005\u306f\u3001\u3053\u308c\u3089\u306eURI\u63a5\u982d\u8f9e\u306b\u5408\u81f4\u3059\u308bURI\u306b\u5bfe\u3057\u3066\u3001\u7279\u5b9a\u306e\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u3063\u3066HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u884c\u3057\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001OPTIONS\u3001POST\u3001GET\u304a\u3088\u3073PUT\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u3063\u3066\u3001\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u3068\u5bfe\u8a71\u3092\u3057\u307e\u3059\u304c\u3001\u305d\u306e\u969b\u306b\u4f7f\u3046Kazuar\u306e\u30b3\u30de\u30f3\u30c9 \u30bb\u30c3\u30c8\u306f\u88683\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e\u6a5f\u80fd\u306f\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3068C2\u30b5\u30fc\u30d0\u3068\u306e\u9593\u306e\u901a\u4fe1\u30d5\u30ed\u30fc\u3092\u53cd\u8ee2\u3055\u305b\u307e\u3059\u3002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304cC2\u30b5\u30fc\u30d0\u3068\u306e\u901a\u4fe1\u3092\u958b\u59cb\u3059\u308b\u306e\u3067\u306f\u306a\u304f\u3001C2\u30b5\u30fc\u30d0\u304c\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306b\u5bfe\u3057\u3066\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u76f4\u63a5\u9001\u4fe1\u3057\u307e\u3059\u3002\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u304c\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30b5\u30fc\u30d0\u3067\u3042\u308b\u5834\u5408\u3001\u30b5\u30fc\u30d0\u304c\u30a2\u30a6\u30c8\u30d0\u30a6\u30f3\u30c9\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u958b\u59cb\u3059\u308b\u969b\u306e\u30d5\u30e9\u30b0\u3092\u7acb\u3066\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u3001\u3053\u306e\u901a\u4fe1\u30d5\u30ed\u30fc\u306f\u91cd\u8981\u3067\u3059\u3002\u307e\u305f\u3001\u3053\u306e\u7a2e\u306eAPI\u30a2\u30af\u30bb\u30b9\u3092\u767a\u751f\u3055\u305b\u308b\u3053\u3068\u3067\u3001\u8105\u5a01\u306e\u653b\u6483\u8005\u306f\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30b5\u30fc\u30d0\u306e1\u3064\u3092\u5358\u4e00\u70b9\u3068\u3057\u3066\u5229\u7528\u3057\u3066\u3001\u30c7\u30fc\u30bf\u306e\u30c0\u30f3\u30d7\u5148\u3068\u3057\u3001\u307e\u305f\u3001\u3053\u306e\u5358\u4e00\u70b9\u304b\u3089\u30c7\u30fc\u30bf\u3092\u5bc6\u304b\u306b\u76d7\u307f\u51fa\u3057\u307e\u3059\u3002<\/p>\n<table class=\"table table-bordered\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"104\"><b>HTTP\u30e1\u30bd\u30c3\u30c9<\/b><\/td>\n<td valign=\"top\" width=\"527\"><b>\u6a5f\u80fd\u306e\u8aac\u660e<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"104\">OPTIONS<\/td>\n<td valign=\"top\" width=\"527\">\u6a5f\u80fd\u306a\u3057\u3002\u5358\u306bHTTP\u306e\u300cOK\u300d\u30b9\u30c6\u30fc\u30bf\u30b9\u3092\u8fd4\u3059\u3060\u3051\u3067\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"104\">POST<\/td>\n<td valign=\"top\" width=\"527\">\u653b\u6483\u8005\u306f\u3001\u65b0\u305f\u306a\u30bf\u30b9\u30af\u751f\u6210\u306bKazuar\u304c\u4f7f\u3046XML\u5f62\u5f0f\u306e\u30c7\u30fc\u30bf\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u307e\u3063\u305f\u304f\u540c\u3058\u30e1\u30bd\u30c3\u30c9(\u56f37\u306e\u300creadResponse0\u300d)\u3092\u4f7f\u3063\u3066\u3001\u524d\u8ff0\u306e\u6700\u521d\u306eC2\u901a\u4fe1\u30c1\u30e3\u30cd\u30eb\u306b\u304a\u3044\u3066\u53d6\u5f97\u3057\u305fXML\u30c7\u30fc\u30bf\u3092\u89e3\u6790\u3057\u307e\u3059\u3002Kazuar\u306f\u30bf\u30b9\u30af\u306e\u7d50\u679c\u3092\u30ed\u30b0\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u307f\u307e\u3059\u3002\u30ed\u30b0\u30d5\u30a1\u30a4\u30eb\u306f\u300cres\u300d\u3068\u547c\u3070\u308c\u3001\u300ctsk\u300d\u3068\u547c\u3070\u308c\u308b\u30d5\u30a9\u30eb\u30c0\u306e\u4e2d\u306b\u7f6e\u304b\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"104\">GET<\/td>\n<td valign=\"top\" width=\"527\">\u4ee5\u524d\u306e\u30bf\u30b9\u30af\u306b\u95a2\u3057\u3066\u7d50\u679c\u5185\u5bb9\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u3053\u306e\u7d50\u679c\u5185\u5bb9\u306f\u300cres\u300d\u30d5\u30a1\u30a4\u30eb\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3057\u3066\u751f\u6210\u3055\u308c\u305f\u3082\u306e\u3067\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"104\">PUT<\/td>\n<td valign=\"top\" width=\"527\">\u653b\u6483\u8005\u306f\u3001\u65b0\u305f\u306a\u30bf\u30b9\u30af\u751f\u6210\u306bKazuar\u304c\u4f7f\u3046XML\u5f62\u5f0f\u306e\u30c7\u30fc\u30bf\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002\u3053\u306e\u30e1\u30bd\u30c3\u30c9\u306fPOST\u30e1\u30bd\u30c3\u30c9\u306b\u4f3c\u3066\u3044\u307e\u3059\u304c\u3001\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u300cres\u300d\u30d5\u30a1\u30a4\u30eb\u306b\u4fdd\u5b58\u3059\u308b\u306e\u3067\u306f\u306a\u304f\u3001HTTP PUT\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3057\u3066\u3001\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u4ed8\u304d\u3067\u5fdc\u7b54\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 10pt;\"><i>\u88683 Kazuar\u306eAPI\u306e\u5f62\u3067\u63d0\u4f9b\u3055\u308c\u308bHTTP\u30e1\u30bd\u30c3\u30c9\u304a\u3088\u3073\u6a5f\u80fd<\/i><\/span><\/p>\n<p>\u3053\u306e\u6a5f\u80fd\u306f\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3068C2\u30b5\u30fc\u30d0\u3068\u306e\u9593\u306e\u901a\u4fe1\u30d5\u30ed\u30fc\u3092\u53cd\u8ee2\u3055\u305b\u307e\u3059\u3002\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304cC2\u30b5\u30fc\u30d0\u3068\u306e\u901a\u4fe1\u3092\u958b\u59cb\u3059\u308b\u306e\u3067\u306f\u306a\u304f\u3001C2\u30b5\u30fc\u30d0\u304c\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306b\u5bfe\u3057\u3066\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u76f4\u63a5\u9001\u4fe1\u3057\u307e\u3059\u3002\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u304c\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30b5\u30fc\u30d0\u3067\u3042\u308b\u5834\u5408\u3001\u30b5\u30fc\u30d0\u304c\u30a2\u30a6\u30c8\u30d0\u30a6\u30f3\u30c9\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u958b\u59cb\u3059\u308b\u969b\u306e\u30d5\u30e9\u30b0\u3092\u7acb\u3066\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u3001\u3053\u306e\u901a\u4fe1\u30d5\u30ed\u30fc\u306f\u91cd\u8981\u3067\u3059\u3002\u307e\u305f\u3001\u3053\u306e\u7a2e\u306eAPI\u30a2\u30af\u30bb\u30b9\u3092\u767a\u751f\u3055\u305b\u308b\u3053\u3068\u3067\u3001\u8105\u5a01\u306e\u653b\u6483\u8005\u306f\u30a2\u30af\u30bb\u30b9\u53ef\u80fd\u306a\u30b5\u30fc\u30d0\u306e1\u3064\u3092\u5358\u4e00\u70b9\u3068\u3057\u3066\u5229\u7528\u3057\u3066\u3001\u30c7\u30fc\u30bf\u306e\u30c0\u30f3\u30d7\u5148\u3068\u3057\u3001\u307e\u305f\u3001\u3053\u306e\u5358\u4e00\u70b9\u304b\u3089\u30c7\u30fc\u30bf\u3092\u5bc6\u304b\u306b\u76d7\u307f\u51fa\u3057\u307e\u3059\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u3082\u3046\u4e00\u6bb5\u30d5\u30eb\u6a5f\u80fd\u306b\u306a\u3063\u3066\u3044\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u3092\u5358\u72ec\u3067\u53d6\u308a\u4e0a\u3052\u3066\u3082\u7279\u306b\u76ee\u65b0\u3057\u3044\u3082\u306e\u306f\u3042\u308a\u307e\u305b\u3093\u304c\u3001Unix\u7528\u306e\u30b3\u30fc\u30c9 \u30d1\u30b9\u306e\u5b58\u5728\u306b\u3088\u308a\u3001.NET Framework\u30b3\u30fc\u30c9\u306e\u79fb\u690d\u6027\u3068\u76f8\u307e\u3063\u3066\u3001Kazuar\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304c\u76ee\u3092\u96e2\u3059\u3053\u3068\u306e\u3067\u304d\u306a\u3044\u8208\u5473\u6df1\u3044\u30c4\u30fc\u30eb\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u3082\u3046\u3072\u3068\u3064\u8208\u5473\u6df1\u3044\u90e8\u5206\u306f\u3001\u305d\u306e\u30ea\u30e2\u30fc\u30c8API\u3067\u3059\u3002\u3053\u306eAPI\u3092\u4f7f\u3048\u3070\u3001\u653b\u6483\u8005\u306f\u4fb5\u5bb3\u3055\u308c\u305f\u30b7\u30b9\u30c6\u30e0\u306b\u5bfe\u3057\u30a4\u30f3\u30d0\u30a6\u30f3\u30c9HTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092\u767a\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u5f0a\u793e\u306e\u5206\u6790\u304b\u3089\u3001\u8105\u5a01\u306e\u653b\u6483\u8005\u304cWindows\u304a\u3088\u3073Unix\u306e\u4e21\u30d7\u30e9\u30c3\u30c8\u306b\u5bfe\u3057\u3066Kazuar\u3092\u5c0e\u5165\u3059\u308b\u76ee\u7684\u3067\u3001\u540c\u4e00\u30b3\u30fc\u30c9\u3092\u4f7f\u3063\u3066Windows\u304a\u3088\u3073Unix\u30d9\u30fc\u30b9\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30b3\u30f3\u30d1\u30a4\u30eb\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3082\u306e\u3068\u601d\u308f\u308c\u307e\u3059\u3002Palo Alto Networks\u306eAutoFocus\u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001Kazuar AutoFocus\u30bf\u30b0\u3092\u4f7f\u3063\u3066\u3001\u65b0\u305f\u306a\u30b5\u30f3\u30d7\u30eb\u3092\u8abf\u67fb\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<h3>\u95a2\u9023\u3059\u308b\u5146\u5019\u304a\u3088\u3073\u8b58\u5225\u60c5\u5831<\/h3>\n<h4><b>\u30cf\u30c3\u30b7\u30e5<\/b><\/h4>\n<ul>\n<li>8490daab736aa638b500b27c962a8250bbb8615ae1c68ef77494875ac9d2ada2<\/li>\n<li>b51105c56d1bf8f98b7e924aa5caded8322d037745a128781fa0bc23841d1e70<\/li>\n<li>bf6f30673cf771d52d589865675a293dc5c3668a956d0c2fc0d9403424d429b2<\/li>\n<li>cd4c2e85213c96f79ddda564242efec3b970eded8c59f1f6f4d9a420eb8f1858<\/li>\n<\/ul>\n<h4><b>URL<\/b><\/h4>\n<ul>\n<li>http:\/\/gaismustudija[.]lv\/wp-includes\/pomo\/kontakti.php<\/li>\n<li>http:\/\/hcdh-tunisie[.]org\/wp-includes\/SimplePie\/gzencode.php<\/li>\n<li>http:\/\/www.gallen[.]fi\/wp-content\/gallery\/<\/li>\n<\/ul>\n<h4><b>\u30d5\u30a1\u30a4\u30eb\u6d3b\u52d5<\/b><\/h4>\n<ul>\n<li>%LOCALAPPDATA%\\\/[a-f0-9]{32}\\\/[a-f0-9]{32}\\.dll<\/li>\n<li>%LOCALAPPDATA%\\\/[a-f0-9]{32}\\\/[a-f0-9]{32}\/<\/li>\n<li>%USERPROFILE%\\Start Menu\\Programs\\Startup\\*.lnk<\/li>\n<\/ul>\n<h4><b>RSA\u30ad\u30fc<\/b><\/h4>\n<div class=\"pan-rsa-key-value\">\n<p style=\"padding-left: 40px;\">&lt;RSAKeyValue&gt;&lt;Modulus&gt;gSI+OxtBrfXVfSRRSlNIMVYr9HFy40jokIDkUqffhU7Y\/VcFB1nc8GwT4GOjK6lR\/mJi3XcGg+nxqR9iLoeoOLgBFFz9O1l++81tPtRaVZ8yg+IzmZlaMhdOg0apatxhjRA\/4pYOhZHwifQIjZzid6\/+BgYIPBXWcX8e58l1PH+chm3DJzJ2gdHOsx6Dz9HHPr+sGLshAFF35ICb\/11jq0vU9KU7CjYdf0Rvl16EDYyUQXbIG1ZMaTDzBrMcXZrBfXHEqn2Qwr4NiaDUwOwGCynBtSZXoNOfHArYxbRaBA269SPKhZgCBqdAhYfPFe2q8r8Y4fz21iZTqTngMsA2zw==&lt;\/Modulus&gt;&lt;Exponent&gt;EQ==&lt;\/Exponent&gt;&lt;P&gt;hGjs2pEZW4pN2b0Bm9xl84zxqQ2BMSflj2xpf5MH+XvCY5BBN3YROm24LYtGwy3xOdKeUJOENvYbkvirBcm2ecRxmLgE5AMMeWxZpOayUtOUd+Abx3+TT8giPG3sqEHtuaHVUjypBloE4EWnFWrmq0f3+Kpi8kHFxLul9jHubsc=&lt;\/P&gt;&lt;Q&gt;+ap\/8gRvidWrAhZcAiCAYdFZIt6hSwBz5ohU5ZSPomv9e\/Urtts8cin+QeBvDwF6UvyP1vz3wxUOXycaBI3StCMjCXHuBLN+wfpEhfdt6KKywsmW7I5OdogIbVRLTUJvBtiXBGG3c10ay3H8TYx00lt6GgcLAJZMZE4mHEjnj7k=&lt;\/Q&gt;&lt;DP&gt;D5PfoT4\/N\/InRsrxIWU5K7Y6jFvxFNeEaznuSz55aKUl7ZiAJKR6f1gzyR9xvJv+Qwm4RbcAfu\/HAjtfahe7HWJnt50twHjUSoU3uQwU+q964O0wcdLGCWLW2e7QjEP92ZqRkTRQHt1p\/ERuAoUMFCaVpMjAWLxxnqyqHPbQwb0=&lt;\/DP&gt;&lt;DQ&gt;vuvLQJn68O6v8omRp0YH0lTLsUDVsdMrdA3mkXGbA7v+E38\/i9TT3tTRfaugOKbG9CqMHN+QSeLs31oi9Gxz8yntnc+X5XozwYMlV2Lbk8e14D\/Nw\/RaHmgGcbjuSiO+UIeCiuFQDOzYQTkMO01KRoIwMgVixDay40rR2WTtT8k=&lt;\/DQ&gt;&lt;InverseQ&gt;cfVixwsMog8F8CDikcYKNmUGNJPeJ4grdJi4ZIMX5mSuhdvSccTnx7JoCMJ2LKwFLyMnmZIIeYF4EYBgwHz6rumL8Zam6Zr04uIpxWL3MZyR9BImREmH6e6aFzHq\/P02phU6tNbzkHMp6QGsfgtkLSmzOed0GsvfwAxCfD20PXU=&lt;\/InverseQ&gt;&lt;D&gt;PMTR\/bJ5Qs4KHMXL5r3Hnr8jvlOBW+YTFtM+RQO0evftpGUviv0crWAJWok9ujGP\/z1bs4NOXDHbImkfJPSLZfw8vknglGZZ3+gzaNxmvuGBLwEJOTkbYt3KmCFAqsIPyemHebAG1XHam0WprA2Xv9pZbD8S7xlV2w6lIcg3K4ak6tNG2yKepoQ2DvFdF\/ZTtOu0ybE+g8AA6UxWCy\/liTLN2fxgVwP45XAAFIue\/x6aF6m09gxi\/xJaxwafEeonVZU9aaqpbyb5eeMixRSbkVuK2DZrF\/lW9oedp0mYtI+E7nRyxykxFl3rrC9B8ETKBzNONPgB4PpuaSSdC0ELcQ==&lt;\/D&gt;&lt;\/RSAKeyValue&gt;<\/p>\n<p style=\"padding-left: 40px;\">&lt;RSAKeyValue&gt;&lt;Modulus&gt;m4SbvlZhH5UzcgDLIEIygjTCCQMxc\/TrwUYZ5JA5SU2jtSBt9aqwljKJ7h4Tv5eP2Efy4Z+2QajDNtOThift4nVTWsl+iOoMKKV6pvQOFj6k2P4kRTBGo\/t8J46j7DqnFeMHXUjhjv2RFnp1nms8thE6+MJsI0lnxYTLBip5mNbj+Jbr7vVzK8MKnjGxsr9FoRBVNyZM+ILFu3aO62z1a8PIrI4kqVVggD35oF4WdSrmVLFvec\/1ej3Cx12NjqCXo3lZhwxlIKjFNMNtslXnk0o9L\/ZlWlEjqXiez\/3ryzpVBrlrtb9D+x1ZRtv58jtdSTE61\/\/jtEb3mMUeTry+2w==&lt;\/Modulus&gt;&lt;Exponent&gt;EQ==&lt;\/Exponent&gt;&lt;\/RSAKeyValue&gt;<\/p>\n<\/div>\n<h4><b>\u5fa9\u53f7\u6e08\u307f\u30ed\u30b0\u304a\u3088\u3073\u30a8\u30e9\u30fc \u30e1\u30c3\u30bb\u30fc\u30b8<\/b><\/h4>\n<p style=\"padding-left: 40px;\">'{0}' autorun algorithm is not supported!<\/p>\n<p style=\"padding-left: 40px;\">'{0}' request method isn't supported.<\/p>\n<p style=\"padding-left: 40px;\">Accessed date mismatch in get command!<\/p>\n<p style=\"padding-left: 40px;\">Accessed date mismatch in list command!<\/p>\n<p style=\"padding-left: 40px;\">Action with identifier {0} is not implemented.<\/p>\n<p style=\"padding-left: 40px;\">Autorun command requeres autorun type to be set!<\/p>\n<p style=\"padding-left: 40px;\">Autorun failed due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Cmd command requires actual commands list!<\/p>\n<p style=\"padding-left: 40px;\">Commiting suicide\u2026<\/p>\n<p style=\"padding-left: 40px;\">Control server address '{0}' is invalid.<\/p>\n<p style=\"padding-left: 40px;\">Copy command requires destination path!<\/p>\n<p style=\"padding-left: 40px;\">Copy command requires source path!<\/p>\n<p style=\"padding-left: 40px;\">Copying file from {0} to {1}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Created date mismatch in get command!<\/p>\n<p style=\"padding-left: 40px;\">Created date mismatch in list command!<\/p>\n<p style=\"padding-left: 40px;\">Directory listing for {0}<\/p>\n<p style=\"padding-left: 40px;\">Executing command with {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Failed to create agent due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Failed to create channel due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Failed to create injector due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Fatal failure due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Getting file query {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Getting system information\u2026<\/p>\n<p style=\"padding-left: 40px;\">Going to sleep for {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Got '{0}' command from {1}.<\/p>\n<p style=\"padding-left: 40px;\">Got new '{0}' command.<\/p>\n<p style=\"padding-left: 40px;\">Got new task #{0} from {1}.<\/p>\n<p style=\"padding-left: 40px;\">HTTP listening isn't supported.<\/p>\n<p style=\"padding-left: 40px;\">IPC channel is not ready.<\/p>\n<p style=\"padding-left: 40px;\">Injected into explorer.<\/p>\n<p style=\"padding-left: 40px;\">Injected into {0} [{1}].<\/p>\n<p style=\"padding-left: 40px;\">Injecting into explorer\u2026<\/p>\n<p style=\"padding-left: 40px;\">Injecting into {0} [{1}]\u2026<\/p>\n<p style=\"padding-left: 40px;\">Injection failed due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Installing plugin\u2026<\/p>\n<p style=\"padding-left: 40px;\">Invalid FTP server status ({0}).<\/p>\n<p style=\"padding-left: 40px;\">Invalid last contact time.<\/p>\n<p style=\"padding-left: 40px;\">Invalid or unknown action format ({0})!<\/p>\n<p style=\"padding-left: 40px;\">Invalid sender interval.<\/p>\n<p style=\"padding-left: 40px;\">Kazuar's {0} started in process {1} [{2}] as user {3}\/{4}.<\/p>\n<p style=\"padding-left: 40px;\">Killing processes\u2026<\/p>\n<p style=\"padding-left: 40px;\">List command requires file query string!<\/p>\n<p style=\"padding-left: 40px;\">Listening<\/p>\n<p style=\"padding-left: 40px;\">Listing plugins\u2026<\/p>\n<p style=\"padding-left: 40px;\">Listing processes\u2026<\/p>\n<p style=\"padding-left: 40px;\">Max interval value is less than min value!<\/p>\n<p style=\"padding-left: 40px;\">Max interval value is more than supported!<\/p>\n<p style=\"padding-left: 40px;\">Min interval value is less than supported!<\/p>\n<p style=\"padding-left: 40px;\">Modified date mismatch in get command!<\/p>\n<p style=\"padding-left: 40px;\">Modified date mismatch in list command!<\/p>\n<p style=\"padding-left: 40px;\">Move command requires destination path!<\/p>\n<p style=\"padding-left: 40px;\">Move command requires source path!<\/p>\n<p style=\"padding-left: 40px;\">Moving file from {0} to {1}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Mozilla\/5.0 (Windows NT {0}.{1}; rv:22.0) Gecko\/20130405 Firefox\/23.0<\/p>\n<p style=\"padding-left: 40px;\">Mozilla\/5.0 (X11; {0} {1}; rv:24.0) Gecko\/20100101 Firefox\/24.0<\/p>\n<p style=\"padding-left: 40px;\">New plugin {0} was installed.<\/p>\n<p style=\"padding-left: 40px;\">No servers available now.<\/p>\n<p style=\"padding-left: 40px;\">Plugin command requires payload!<\/p>\n<p style=\"padding-left: 40px;\">Plugin installed.<\/p>\n<p style=\"padding-left: 40px;\">Plugin removed.<\/p>\n<p style=\"padding-left: 40px;\">Plugin {0} was removed.<\/p>\n<p style=\"padding-left: 40px;\">Plugin {0} was started.<\/p>\n<p style=\"padding-left: 40px;\">Plugout command requires plugin name string!<\/p>\n<p style=\"padding-left: 40px;\">Proc kill command requires name or pid to be set!<\/p>\n<p style=\"padding-left: 40px;\">Process {0} [{1}] exited with {2} code.<\/p>\n<p style=\"padding-left: 40px;\">Process {0} [{1}] impersonated.<\/p>\n<p style=\"padding-left: 40px;\">Put command requires correct file path!<\/p>\n<p style=\"padding-left: 40px;\">Put command requires payload!<\/p>\n<p style=\"padding-left: 40px;\">Putting file to {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Remote control failed due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Remote failed due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Remote iteration failed due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Remote request from {0} failed due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Remove command requires file path!<\/p>\n<p style=\"padding-left: 40px;\">Removing file {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Removing plugin\u2026<\/p>\n<p style=\"padding-left: 40px;\">Request was sent to {0}.<\/p>\n<p style=\"padding-left: 40px;\">Result #{0} was sent to {1}.<\/p>\n<p style=\"padding-left: 40px;\">Result #{0} was taken by {1}.<\/p>\n<p style=\"padding-left: 40px;\">Run command requires executable path!<\/p>\n<p style=\"padding-left: 40px;\">Run-time error {0}:{1:X8}.<\/p>\n<p style=\"padding-left: 40px;\">Run-time error {0}:{1}.<\/p>\n<p style=\"padding-left: 40px;\">Scheme '{0}' is not supported!<\/p>\n<p style=\"padding-left: 40px;\">Searching file query {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Send iteration failed due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Sending request to {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Sending result #{0} to {1}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Server command requires at least one server!<\/p>\n<p style=\"padding-left: 40px;\">Setting agent id to {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Setting autorun type to {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Setting remote type to {0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Setting transport interval to [{0} \u2013 {1}]\u2026<\/p>\n<p style=\"padding-left: 40px;\">Setting transport processes:<\/p>\n<p style=\"padding-left: 40px;\">Setting transport servers:<\/p>\n<p style=\"padding-left: 40px;\">Shellcode error {0:X16}.<\/p>\n<p style=\"padding-left: 40px;\">Sleep interval is longer than supported!<\/p>\n<p style=\"padding-left: 40px;\">Solving task #{0}\u2026<\/p>\n<p style=\"padding-left: 40px;\">Startup path is empty.<\/p>\n<p style=\"padding-left: 40px;\">Taking screen shot\u2026<\/p>\n<p style=\"padding-left: 40px;\">Taking webcam shot\u2026<\/p>\n<p style=\"padding-left: 40px;\">Task #{0} execution finished.<\/p>\n<p style=\"padding-left: 40px;\">Task #{0} execution started:<\/p>\n<p style=\"padding-left: 40px;\">Task #{0} failed due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Task #{0} solved.<\/p>\n<p style=\"padding-left: 40px;\">Transport command requires at least one process name!<\/p>\n<p style=\"padding-left: 40px;\">Transport process name '{0}' is invalid.<\/p>\n<p style=\"padding-left: 40px;\">Transport processes<\/p>\n<p style=\"padding-left: 40px;\">Unable to create capture window.<\/p>\n<p style=\"padding-left: 40px;\">Unable to delete task #{0} file due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Unable to execute command due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to execute task #{0} due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Unable to get last contact time due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to get task from {0} due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Unable to impersonate {0} [{1}] due to {2}<\/p>\n<p style=\"padding-left: 40px;\">Unable to return logs due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to send result #{0} to {1} due to {2}<\/p>\n<p style=\"padding-left: 40px;\">Unable to start plugin {0} due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Unable to stop plugin {0} due to {1}<\/p>\n<p style=\"padding-left: 40px;\">Unable to store agent id due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to store autorun type due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to store interval due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to store remote type due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to store servers due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unable to store transports due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Unhandled exception {0}<\/p>\n<p style=\"padding-left: 40px;\">Upgrade command requires payload!<\/p>\n<p style=\"padding-left: 40px;\">Upgrading agent\u2026<\/p>\n<p style=\"padding-left: 40px;\">Using default agent id due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Using default autorun type due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Using default interval due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Using default remote type due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Using default servers due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Using default transports due to {0}<\/p>\n<p style=\"padding-left: 40px;\">Uuid command requires identifier!<\/p>\n<p style=\"padding-left: 40px;\">Waiting for shellcode failed.<\/p>\n<p style=\"padding-left: 40px;\">Waiting for window '{0}' failed.<\/p>\n<p style=\"padding-left: 40px;\">explorer.exe, {0}<\/p>\n<p style=\"padding-left: 40px;\">ERROR: {0}<\/p>\n<p style=\"padding-left: 40px;\">Plugin {0}<\/p>\n<p style=\"padding-left: 40px;\">{0} doesn't exist!<\/p>\n<p style=\"padding-left: 40px;\">{0} was skipped.<\/p>\n<p style=\"padding-left: 40px;\">proc \u2013 {0} [{1}]<\/p>\n<p style=\"padding-left: 40px;\">time \u2013 {0}<\/p>\n<p style=\"padding-left: 40px;\">user \u2013 {0}\/{1} ({2})<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 Kazuar\u30c4\u30fc\u30eb\u306fTurla\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7(Uroburos\u304a\u3088\u3073Snake\u3068\u3057\u3066\u3082\u77e5\u3089\u308c\u3066\u3044\u308b)\u3068\u95a2\u9023\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u5f0a\u793e\u3067\u306f\u898b\u3066\u3044\u307e\u3059\u3002Turla\u653b\u6483\u8005\u30b0\u30eb\u30fc\u30d7\u306f\u4e16\u754c\u4e2d\u306e\u5927\u4f7f\u9928\u3001\u9632\u885b\u8acb\u8ca0\u696d\u8005\u3001\u6559\u80b2\u6a5f\u95a2\u304a<\/p>\n","protected":false},"author":22,"featured_media":103240,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[4819,4977,7107,4881,4883,4987,7366,7367,4885,4887],"product_categories":[],"coauthors":[935],"class_list":["post-106267","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-net-framework-ja","tag-carbon-ja","tag-confuserex-ja","tag-kazuar-ja","tag-pensive-ursa-ja","tag-snake-ja","tag-trojans","tag-trojans-ja","tag-turla-ja","tag-uroburos-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2<\/title>\n<meta name=\"description\" content=\"\u6982\u8981\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8981\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-03T21:08:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-10T01:54:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/09\/unit42-web-banner-650x300.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"650\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Robert Falcone\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2","description":"\u6982\u8981","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/","og_locale":"ja_JP","og_type":"article","og_title":"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2","og_description":"\u6982\u8981","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/","og_site_name":"Unit 42","article_published_time":"2017-05-03T21:08:28+00:00","article_modified_time":"2020-04-10T01:54:10+00:00","og_image":[{"width":650,"height":300,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/09\/unit42-web-banner-650x300.jpg","type":"image\/jpeg"}],"author":"Robert Falcone","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/"},"author":{"name":"Robert Falcone","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1"},"headline":"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2","datePublished":"2017-05-03T21:08:28+00:00","dateModified":"2020-04-10T01:54:10+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/"},"wordCount":9393,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/09\/unit42-web-banner-650x300.jpg","keywords":[".NET Framework","Carbon","ConfuserEx","Kazuar","Pensive Ursa","Snake","Trojans","Trojans","Turla","Uroburos"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/","name":"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/09\/unit42-web-banner-650x300.jpg","datePublished":"2017-05-03T21:08:28+00:00","dateModified":"2020-04-10T01:54:10+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1"},"description":"\u6982\u8981","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/09\/unit42-web-banner-650x300.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2016\/09\/unit42-web-banner-650x300.jpg","width":650,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/unit42-kazuar-multiplatform-espionage-backdoor-api-access\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"Kazuar\u3001API\u3092\u4f7f\u3046\u30de\u30eb\u30c1\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5bfe\u5fdc\u306e\u30b9\u30d1\u30a4\u6d3b\u52d5\u578b\u30d0\u30c3\u30af\u30c9\u30a2"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/99e613cb620722a191a363182abe6fb1","name":"Robert Falcone","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Robert Falcone"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/robertfalcone\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106267","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=106267"}],"version-history":[{"count":4,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106267\/revisions"}],"predecessor-version":[{"id":106273,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106267\/revisions\/106273"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/103240"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=106267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=106267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=106267"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=106267"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=106267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}