{"id":106698,"date":"2020-04-23T21:00:09","date_gmt":"2020-04-24T04:00:09","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=106698"},"modified":"2020-05-18T21:06:15","modified_gmt":"2020-05-19T04:06:15","slug":"how-cybercriminals-prey-on-the-covid-19-pandemic","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/","title":{"rendered":"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306e\u4e16\u754c\u7684\u5e83\u307e\u308a\u3092\u53d7\u3051\u3001\u305d\u306e\u95a2\u9023\u30c8\u30d4\u30c3\u30af\u3078\u306e\u95a2\u5fc3\u304c\u9ad8\u307e\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u3068\u3082\u306a\u30442\u6708\u521d\u3081\u4ee5\u964d\u3001\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u540c\u611f\u67d3\u75c7\u95a2\u9023\u306eGoogle\u691c\u7d22\u3084\u95b2\u89a7URL\u304c\u5927\u5e45\u306b\u4f38\u3073\u3066\u3044\u308b\u69d8\u5b50\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u305f\u3061\u306f\u306a\u3093\u3089\u502b\u7406\u4e0a\u306e\u61f8\u5ff5\u306b\u3068\u3089\u308f\u308c\u308b\u3053\u3068\u306a\u304f\u3001\u3053\u306e\u6a5f\u306b\u4e57\u3058\u3066\u6570\u5341\u5104\u306e\u7121\u8f9c\u306e\u6c11\u3092\u98df\u3044\u7269\u306b\u3057\u3001\u8a71\u984c\u306e\u30c8\u30d4\u30c3\u30af\u3067\u306e\u8352\u7a3c\u304e\u3092\u76ee\u8ad6\u3093\u3067\u3044\u307e\u3059\u3002<\/p>\n<p>Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u5bfe\u8c61\u3068\u306a\u3063\u3066\u3044\u308b\u8a71\u984c\u306e\u30c8\u30d4\u30c3\u30af\u3084\u3001\u305d\u308c\u3089\u306b\u95a2\u9023\u3057\u3066\u65b0\u898f\u306b\u767b\u9332\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u3092\u76e3\u8996\u3059\u308b\u3053\u3068\u3067\u3001\u5f0a\u793e\u306e\u304a\u5ba2\u69d8\u3092\u4fdd\u8b77\u3057\u3066\u3044\u307e\u3059\u3002\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u306f\u3053\u3046\u3057\u305f\u65b0\u898f\u30c9\u30e1\u30a4\u30f3\u3092\u60aa\u610f\u306e\u3042\u308b\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u5229\u7528\u3059\u308b\u3053\u3068\u304c\u3088\u304f\u3042\u308b\u304b\u3089\u3067\u3059\u3002\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306e\u9ad8\u307e\u308a\u306b\u3068\u3082\u306a\u3044\u30012\u6708\u304b\u30893\u6708\u306b\u304b\u3051\u3066\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u540d\u306e\u767b\u9332\u304c1\u65e5\u3042\u305f\u308a\u5e73\u5747\u3067656\uff05\u5897\u52a0\u3057\u3066\u3044\u307e\u3059\u3002\u540c\u3058\u671f\u9593\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u3084\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306a\u3069\u3092\u542b\u3080\u60aa\u610f\u306e\u3042\u308b\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u306f569\uff05\u5897\u52a0\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u307b\u304b\u3001\u8a50\u6b3a\u306b\u95a2\u9023\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u3001\u4e0d\u6b63\u306a\u4eee\u60f3\u901a\u8ca8\u306e\u30de\u30a4\u30cb\u30f3\u30b0\u3092\u884c\u3046\u30c9\u30e1\u30a4\u30f3\u3001\u60aa\u610f\u306e\u3042\u308bURL\u3068\u306e\u95a2\u9023\u306a\u3044\u3057\u9632\u5f3e\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u306e\u5229\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u542b\u3080\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u306a\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u3082788\uff05\u5897\u52a0\u3057\u3066\u3044\u307e\u3059\u30023\u6708\u672b\u306e\u6642\u70b9\u3067\u79c1\u305f\u3061\u306f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u65b0\u898f\u767b\u9332\u30c9\u30e1\u30a4\u30f3\u540d\u309211\u4e076,357\u4ef6\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002\u3046\u30612,022\u4ef6\u306f\u300c\u60aa\u610f\u304c\u3042\u308b\u300d\u30c9\u30e1\u30a4\u30f3\u30014\u4e07261\u4ef6\u306f\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u306e\u30c9\u30e1\u30a4\u30f3\u3067\u3059\u3002<\/p>\n<p>\u79c1\u305f\u3061\u306f\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u3092WHOIS\u60c5\u5831\u3001DNS\u30ec\u30b3\u30fc\u30c9\u3001\u81ea\u52d5\u30af\u30ed\u30fc\u30e9\u30fc\u3067\u53ce\u96c6\u3057\u305f\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3092\u4f7f\u3063\u3066\u30af\u30e9\u30b9\u30bf\u5316\u3057\u3066\u5206\u6790\u3057\u3001\u30c9\u30e1\u30a4\u30f3\u767b\u9332\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306e\u691c\u51fa\u3092\u884c\u3044\u307e\u3057\u305f\u3002\u591a\u304f\u306e\u30c9\u30e1\u30a4\u30f3\u304c\u55b6\u5229\u76ee\u7684\u306e\u8ee2\u58f2\u3092\u3042\u3066\u3053\u3093\u3060\u767b\u9332\u3067\u3057\u305f\u304c\u3001\u305d\u306e\u304b\u306a\u308a\u306e\u90e8\u5206\u304c\u3088\u304f\u77e5\u3089\u308c\u3066\u3044\u308b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3084\u3001\u4e0d\u8db3\u7269\u8cc7\u306b\u4e57\u3058\u3066\u8a50\u6b3a\u7684\u5546\u58f2\u3092\u884c\u3046EC\u30b5\u30a4\u30c8\u306e\u4e21\u65b9\u306b\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306e\u8a71\u984c\u3092\u60aa\u7528\u3057\u305f\u3001\u5f93\u6765\u304b\u3089\u3042\u308b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u3057\u3066\u306f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30b5\u30a4\u30c8\u3001\u8a50\u6b3a\u30b5\u30a4\u30c8\u3001\u30de\u30eb\u30d0\u30bf\u30a4\u30b8\u30f3\u30b0\u3001\u4eee\u60f3\u901a\u8ca8\uff08\u6697\u53f7\u901a\u8ca8\uff09\u306e\u30de\u30a4\u30cb\u30f3\u30b0\u3001\u502b\u7406\u306b\u3082\u3068\u308bweb\u30b5\u30a4\u30c8\u306e\u691c\u7d22\u30e9\u30f3\u30ad\u30f3\u30b0\u5411\u4e0a\u3092\u72d9\u3063\u305f\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO\uff08\u4e0d\u6b63\u306b\u691c\u7d22\u30a8\u30f3\u30b8\u30f3\u6700\u9069\u5316\u3092\u884c\u3046\u884c\u70ba\uff09\u306a\u3069\u304c\u3042\u3052\u3089\u308c\u307e\u3059\u3002\u65b0\u898f\u767b\u9332\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u3092\u4f7f\u7528\u3059\u308bEC\u30b5\u30a4\u30c8\u306e\u591a\u304f\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u3092\u9a19\u305d\u3046\u3068\u3059\u308b\u3082\u306e\u3067\u3057\u305f\u304c\u3001\u3068\u308a\u308f\u3051\u502b\u7406\u610f\u8b58\u6b20\u5982\u306e\u306f\u306a\u306f\u3060\u3057\u3044\u30c9\u30e1\u30a4\u30f3\u306e\u30b0\u30eb\u30fc\u30d7\u3067\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u5bfe\u3059\u308b\u6050\u6016\u3092\u3055\u3089\u306b\u717d\u308b\u3053\u3068\u3067\u3001\u81ea\u5206\u305f\u3061\u306e\u88fd\u54c1\u3092\u8cb7\u308f\u305b\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u70b9\u304c\u8208\u5473\u3092\u5f15\u304d\u307e\u3059\u3002\u3055\u3089\u306b\u79c1\u305f\u3061\u306f\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3092\u30c6\u30fc\u30de\u3068\u3057\u3001\u30c9\u30e1\u30a4\u30f3\u30d1\u30fc\u30ad\u30f3\u30b0\u304c\u884c\u308f\u308c\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u30b0\u30eb\u30fc\u30d7\u3082\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u306b\u306f\u3001\u3044\u3064\u3067\u3082\u3059\u3050\u30e6\u30fc\u30b6\u30fc\u3092\u60aa\u610f\u306e\u3042\u308b\u30b3\u30f3\u30c6\u30f3\u30c4\u3078\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3057\u59cb\u3081\u3089\u308c\u308b\u3088\u3046\u3001\u30cf\u30a4\u30ea\u30b9\u30af\u306aJavaScript\u3092\u542b\u3080\u30da\u30fc\u30b8\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u672c\u7a3f\u3067\u306f\u3001Google\u30c8\u30ec\u30f3\u30c9\u3068\u30b5\u30fc\u30d3\u30b9\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u30ed\u30b0\u306e\u4e21\u30c7\u30fc\u30bf\u3092\u4f7f\u3044\u3001\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u4e0a\u3067\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c8\u30d4\u30c3\u30af\u3078\u306e\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306e\u9ad8\u307e\u308a\u306b\u3064\u3044\u3066\u307e\u305a\u8aac\u660e\u3057\u307e\u3059\u3002\u6b21\u306b\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u542b\u3080\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u304c\u6700\u8fd1\u6d3b\u767a\u306b\u306a\u3063\u3066\u304a\u308a\u3001\u305d\u306e\u6570\u304c\u5927\u5e45\u306b\u5897\u52a0\u3057\u3066\u3044\u308b\u69d8\u5b50\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u304c\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u4e0a\u3067\u306e\u305d\u3046\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306b\u3069\u306e\u3088\u3046\u306b\u3064\u3051\u3053\u307f\u3001\u53ce\u76ca\u5316\u3092\u56f3\u3063\u3066\u3044\u308b\u304b\u306b\u3064\u3044\u3066\u3001\u8a73\u7d30\u306a\u30b1\u30fc\u30b9\u30b9\u30bf\u30c7\u30a3\u3092\u793a\u3057\u307e\u3059\u3002\u6700\u5f8c\u306b\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u306a\u304a\u3001\u672c\u7a3f\u3067\u8a00\u53ca\u3059\u308b\u60aa\u610f\u306e\u3042\u308bweb\u30b5\u30a4\u30c8\u3084\u30de\u30eb\u30a6\u30a7\u30a2\u653b\u6483\u306f\u3059\u3079\u3066\u3001PAN-DB URL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3001DNS\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3001WildFire\u3001\u8105\u5a01\u9632\u5fa1\u306a\u3069\u306e\u5f0a\u793e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3067\u306b\u5bfe\u5fdc\u6e08\u307f\u3067\u3059\u3002<\/p>\n<h3>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u8a71\u984c\u306b\u5bfe\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306e\u9ad8\u307e\u308a<\/h3>\n<figure id=\"attachment_106735\" aria-describedby=\"caption-attachment-106735\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure01-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106735 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure01-1.png\" alt=\"\u56f31 \u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u95a2\u9023\u3057\u305f\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u691c\u7d22\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u50be\u5411\uff08\u7e26\u8ef8\u306f\u95a2\u5fc3\u5ea6\uff09\" width=\"600\" height=\"338\" \/><\/a><figcaption id=\"caption-attachment-106735\" class=\"wp-caption-text\">\u56f31 \u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u95a2\u9023\u3057\u305f\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u691c\u7d22\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u50be\u5411\uff08\u7e26\u8ef8\u306f\u95a2\u5fc3\u5ea6\uff09<\/figcaption><\/figure>\n<p>\u79c1\u305f\u3061\u306f\u3001Google\u30c8\u30ec\u30f3\u30c9\u3068\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u30ed\u30b0\u3092\u4f7f\u3063\u3066\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c8\u30d4\u30c3\u30af\u306b\u5bfe\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u304c\u6025\u6fc0\u306b\u9ad8\u307e\u3063\u3066\u3044\u308b\u69d8\u5b50\u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002Google\u30c8\u30ec\u30f3\u30c9\u304b\u3089\u306f\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u30ad\u30fc\u30ef\u30fc\u30c9\u306b\u30e6\u30fc\u30b6\u30fc\u304c\u3069\u306e\u7a0b\u5ea6\u95a2\u5fc3\u3092\u6301\u3063\u3066\u3044\u308b\u304b\u304c\u308f\u304b\u308a\u307e\u3059\uff08\u56f31\u53c2\u7167\uff09\u3002\u3068\u304f\u306b2020\u5e741\u6708\u672b\u30012\u6708\u672b\u30013\u6708\u4e2d\u65ec\u306b3\u3064\u306e\u9855\u8457\u306a\u30d4\u30fc\u30af\u304c\u898b\u3089\u308c\u307e\u3059\u3002\u6700\u521d\u306e\u30d4\u30fc\u30af\u306f\u4e2d\u56fd\u3067\u306e\u30a6\u30a4\u30eb\u30b9\u306e\u30a2\u30a6\u30c8\u30d6\u30ec\u30a4\u30af\u3068\u4e00\u81f4\u3057\u30012\u756a\u76ee\u306e\u30d4\u30fc\u30af\u306f\u611f\u67d3\u6e90\u3092\u78ba\u8a8d\u3067\u304d\u3066\u3044\u306a\u3044\u7c73\u56fd\u3067\u306e\u6700\u521d\u306e\u75c7\u4f8b\u3068\u4e00\u81f4\u3057\u30013\u756a\u76ee\u306e\u30d4\u30fc\u30af\u306f\u7c73\u56fd\u3067\u306e\u30a6\u30a4\u30eb\u30b9\u30a2\u30a6\u30c8\u30d6\u30ec\u30a4\u30af\u3068\u4e00\u81f4\u3057\u3066\u3044\u307e\u3059\u3002\u56f31\u3067\u3072\u3068\u3064\u8208\u5473\u6df1\u3044\u4f8b\u5916\u304c\u300cAlcohol\uff08\u30a2\u30eb\u30b3\u30fc\u30eb\uff09\u300d\u3068\u3044\u3046\u30ad\u30fc\u30ef\u30fc\u30c9\u3067\u3057\u3087\u3046\u3002\u30e6\u30fc\u30b6\u30fc\u306f\u4e00\u5e74\u4e2d\u30a2\u30eb\u30b3\u30fc\u30eb\u306b\u95a2\u5fc3\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3057\u3001\u30d4\u30fc\u30af\u306f\u30af\u30ea\u30b9\u30de\u30b9\u306b\u3042\u308a\u307e\u3059\u3002\u305f\u3060\u7d20\u76f4\u306b\u8003\u3048\u308c\u3070\u3001\u30a2\u30eb\u30b3\u30fc\u30eb\u306b\u5bfe\u3059\u308b\u5e74\u9593\u3092\u901a\u3058\u305f\u95a2\u5fc3\u306f\u98f2\u9152\u7528\u30a2\u30eb\u30b3\u30fc\u30eb\u306b\u3064\u3044\u3066\u3067\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3068\u4e00\u81f4\u3059\u308b\u30d4\u30fc\u30af\u306f\u533b\u7642\u7528\u30a2\u30eb\u30b3\u30fc\u30eb\u306b\u3064\u3044\u3066\u3067\u3057\u3087\u3046\u3002<\/p>\n<figure id=\"attachment_106737\" aria-describedby=\"caption-attachment-106737\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure02-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106737 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure02-1.png\" alt=\"\u56f32 \u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306eURL\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u50be\u5411\uff08\u7e26\u8ef8\u306f\u30e6\u30fc\u30b6\u30fc\u304c\u30a2\u30af\u30bb\u30b9\u3057\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023URL\u6570\uff09\" width=\"600\" height=\"337\" \/><\/a><figcaption id=\"caption-attachment-106737\" class=\"wp-caption-text\">\u56f32 \u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306eURL\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u50be\u5411\uff08\u7e26\u8ef8\u306f\u30e6\u30fc\u30b6\u30fc\u304c\u30a2\u30af\u30bb\u30b9\u3057\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023URL\u6570\uff09<\/figcaption><\/figure>\n<p>Google\u30c8\u30ec\u30f3\u30c9\u3067\u898b\u3089\u308c\u305f\u30e6\u30fc\u30b6\u30fc\u95a2\u5fc3\u5ea6\u306e\u89b3\u6e2c\u7d50\u679c\u3068\u6bd4\u4f8b\u3057\u30012\u6708\u4e0a\u65ec\u304b\u30893\u6708\u4e0b\u65ec\u306b\u304b\u3051\u3066\u3001\u5f0a\u793e\u9867\u5ba2\u304c\u30a2\u30af\u30bb\u30b9\u3057\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023URL\u6570\uff08\u91cd\u8907\u306a\u3057\u306e\u5b9f\u6570\uff09\u304c\u304a\u3088\u305d10\u500d\u306b\u5897\u52a0\u3057\u3066\u3044\u307e\u3059\uff08\u56f32\u53c2\u7167\uff09\u3002<\/p>\n<p>\u307e\u305f\u3053\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u5bfe\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306e\u9ad8\u307e\u308a\u306f\u3001\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u304c\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u3067\u8352\u7a3c\u304e\u3059\u308b\u7d76\u597d\u306e\u6a5f\u4f1a\u3067\u3082\u3042\u308a\u307e\u3059\u3002\u8a50\u6b3a\u5e2b\u304c\u6d41\u884c\u306e\u30c8\u30d4\u30c3\u30af\u304b\u3089\u5229\u76ca\u3092\u4e0a\u3052\u308b\u306e\u306b\u3088\u304f\u4f7f\u3046\u65b9\u6cd5\u304c\u300ccoronavirus\uff08\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\uff09\u300d\u3084\u300cCOVID\u300d\u306a\u3069\u306e\u95a2\u9023\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u542b\u3080\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u767b\u9332\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u3053\u3046\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u540d\u306f\u4e00\u898b\u307e\u3068\u3082\u306a\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u308b\u30b1\u30fc\u30b9\u304c\u591a\u304f\u3001\u30e6\u30fc\u30b6\u30fc\u3092\u3060\u307e\u3057\u3066\u60aa\u610f\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u305b\u305f\u308a\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u3001\u8a50\u6b3a\u3001\u4e0d\u6b63\u884c\u70ba\u3001\u6697\u53f7\u901a\u8ca8\u306e\u30de\u30a4\u30cb\u30f3\u30b0\u306a\u3069\u3001\u3055\u307e\u3056\u307e\u306a\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u4f7f\u7528\u3059\u308b\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u305f\u3061\u3068\u6226\u3046\u305f\u3081\u3001\u79c1\u305f\u3061\u306f\u6d41\u884c\u306e\u30c8\u30d4\u30c3\u30af\u304b\u3089\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u53d6\u5f97\u3057\u307e\u3057\u305f\u3002\u307e\u305a\u3001Google Trends API\u3092\u4f7f\u7528\u3057\u3001\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u81ea\u52d5\u62bd\u51fa\u3057\u307e\u3059\u3002\u6b21\u306b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3068\u6700\u3082\u95a2\u9023\u5ea6\u306e\u9ad8\u3044\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u624b\u52d5\u3067\u9078\u629e\u3057\u307e\u3059\u3002\u6700\u5f8c\u306b\u305d\u308c\u3089\u4e00\u9023\u306e\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u4f7f\u3044\u3001\u65b0\u898f\u306b\u767b\u9332\u3055\u308c\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u540d\u524d\u3092\u542b\u3080\u30c9\u30e1\u30a4\u30f3\u3092\u6ce8\u610f\u6df1\u304f\u76e3\u8996\u3057\u307e\u3059\u3002<\/p>\n<h3>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u540d\u306e\u5897\u52a0<\/h3>\n<p>Unit 42\u306f\u30019\u5e74\u4ee5\u4e0a\u524d\u304b\u3089\u65b0\u898f\u767b\u9332\u30c9\u30e1\u30a4\u30f3\uff08Newly Registered Domains: \u4ee5\u964dNRD\uff09\u3092\u8ffd\u8de1\u3057\u3066\u304a\u308a\u3001\u4ee5\u524d\u305d\u308c\u3089\u306e<a href=\"https:\/\/unit42.paloaltonetworks.jp\/newly-registered-domains-malicious-abuse-by-bad-actors\/\">\u5206\u6790\u7d50\u679c\u3092\u307e\u3068\u3081\u305f<\/a>\u30ec\u30dd\u30fc\u30c8\u3092\u516c\u958b\u3057\u3066\u3044\u307e\u3059\u3002COVID-19\u3092\u60aa\u7528\u3059\u308b\u65b0\u305f\u306a\u8105\u5a01\u3092\u8abf\u67fb\u3059\u308b\u305f\u3081\u3001\u79c1\u305f\u3061\u306f2020\u5e741\u67081\u65e5\u304b\u30892020\u5e743\u670831\u65e5\u307e\u3067\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u542b\u3080NRD\u3092\u53d6\u5f97\u3057\u307e\u3057\u305f\u3002\u79c1\u305f\u3061\u306e\u30b7\u30b9\u30c6\u30e0\u3067\u306f\u3001\u3053\u306e\u671f\u9593\u306b11\u4e076,357\u4ef6\u306e\u95a2\u9023NRD\u3092\u691c\u51fa\u3057\u3066\u3044\u307e\u3059\u306e\u3067\u30011\u65e5\u3042\u305f\u308a\u3067\u304a\u3088\u305d1,300\u4ef6\u306e\u30c9\u30e1\u30a4\u30f3\u304c\u691c\u51fa\u3055\u308c\u305f\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002\u56f33\u306f\u3001\u8abf\u67fb\u671f\u9593\u4e2d\u306b\u691c\u51fa\u3055\u308c\u305f\u65b0\u898f\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u306e\u65e5\u3054\u3068\u306e\u50be\u5411\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u6642\u9593\u306e\u7d4c\u904e\u3068\u3068\u3082\u306b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u6570\u306f\u5897\u52a0\u3057\u30013\u670812\u65e5\u4ee5\u964d\u306f\u6bce\u65e53,000\u4ef6\u3092\u8d85\u3048\u308b\u65b0\u898f\u30c9\u30e1\u30a4\u30f3\u304c\u691c\u51fa\u3055\u308c\u307e\u3057\u305f\u3002\u306a\u304a\u901a\u5e38\u306e\u5897\u52a0\u30c8\u30ec\u30f3\u30c9\u3068\u306f\u5225\u306b\u3001\u767b\u9332\u30c9\u30e1\u30a4\u30f3\u6570\u306e\u6025\u5897\u3082\u89b3\u5bdf\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u767b\u9332\u5897\u52a0\u306f\u3001Google\u30c8\u30ec\u30f3\u30c9\u3067\u898b\u3089\u308c\u305f\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306e\u30d4\u30fc\u30af\u306b\u6570\u65e5\u9045\u308c\u3066\u767a\u751f\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<figure id=\"attachment_106578\" aria-describedby=\"caption-attachment-106578\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-3.Daily-coronavirus-related-domain-registration-trends-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106579 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-3.Daily-coronavirus-related-domain-registration-trends-1.png\" alt=\"\u56f33 \u2f47\u3054\u3068\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u50be\u5411\uff08\u6a2a\u8ef8\u306f\u65e5\u6642\u3001\u7e26\u8ef8\u306f\u8a72\u5f53\u65e5\u306b\u691c\u51fa\u3055\u308c\u305f\u5168NRD\u30921(=100%)\u3068\u3057\u305f\u5834\u5408\u306b\u5404\u30ab\u30c6\u30b4\u30ea\u306eNRD\u304c\u5360\u3081\u308b\u5272\u5408(0.01=1%))\" width=\"600\" height=\"368\" \/><\/a><figcaption id=\"caption-attachment-106578\" class=\"wp-caption-text\">\u56f33 \u2f47\u3054\u3068\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u50be\u5411\uff08\u6a2a\u8ef8\u306f\u65e5\u6642\u3001\u7e26\u8ef8\u306f\u8a72\u5f53\u65e5\u306b\u691c\u51fa\u3055\u308c\u305f\u5168NRD\u30921(=100%)\u3068\u3057\u305f\u5834\u5408\u306b\u5404\u30ab\u30c6\u30b4\u30ea\u306eNRD\u304c\u5360\u3081\u308b\u5272\u5408(0.01=1%))<\/figcaption><\/figure>\n<p>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306eNRD\u8a55\u4fa1\u306b\u3042\u305f\u3063\u3066\u306f\u3001DNS\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9\u3001URL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u30b5\u30fc\u30d3\u30b9\u306a\u3069\u3001\u5f0a\u793e\u304c\u4fdd\u6709\u3059\u308b\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u7528\u3057\u307e\u3057\u305f\u3002NRD\u306f\u30012\u3064\u306e\u30ab\u30c6\u30b4\u30ea\u306b\u5206\u985e\u3055\u308c\u307e\u3059\u3002\u307e\u305a\u3001 \u300c<strong>\u60aa\u610f\u306e\u3042\u308b\u300d<\/strong>NRD\u306e\u30ab\u30c6\u30b4\u30ea\u306b\u306f\u3001\u30b3\u30de\u30f3\u30c9&amp;\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\uff08C2\uff09\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u914d\u5e03\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306b\u5229\u7528\u3055\u308c\u308b\u30c9\u30e1\u30a4\u30f3\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u6b21\u306b\u300c<strong>\u30cf\u30a4\u30ea\u30b9\u30af\u300d<\/strong>NRD\u306b\u306f\u3001\u8a50\u6b3a\u30da\u30fc\u30b8\u3001\u30b3\u30f3\u30c6\u30f3\u30c4\u4e0d\u8db3\u306e\u30da\u30fc\u30b8\u3001\u4eee\u60f3\u901a\u8ca8\u306e\u30de\u30a4\u30cb\u30f3\u30b0\u3092\u884c\u3046\u30d7\u30ed\u30b0\u30e9\u30e0\uff08\u30b3\u30a4\u30f3\u30de\u30a4\u30ca\u30fc\uff09\u3001\u65e2\u77e5\u306e\u60aa\u610f\u306e\u3042\u308b\u30c9\u30e1\u30a4\u30f3\u306a\u3044\u3057\u9632\u5f3e\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u306a\u304a\u672c\u7a3f\u3067\u306f\u300c\u60aa\u610f\u306e\u3042\u308b\u300d\u3068\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u306e2\u5206\u985e\u3092\u7528\u3044\u307e\u3057\u305f\u304c\u3001<a href=\"https:\/\/knowledgebase.paloaltonetworks.com\/KCSArticleDetail?id=kA10g000000Cm5hCAC\">\u3053\u3061\u3089\u306e\u6587\u66f8<\/a>\u3067\u3082\u8aac\u660e\u3057\u3066\u3044\u308b\u3088\u3046\u306b\u3001\u5f0a\u793e\u306eURL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u30b5\u30fc\u30d3\u30b9\u3092\u5229\u7528\u3059\u308b\u3068\u3055\u3089\u306b\u304d\u3081\u7d30\u304b\u304f\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u5206\u985e\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u3055\u3066\u3001\u79c1\u305f\u3061\u306e\u5206\u6790\u3067\u306f2,022\u4ef6\u306e\u300c\u60aa\u610f\u306e\u3042\u308b\u300dNDR\u30684\u4e07261\u4ef6\u306e\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300dNRD\u304c\u7279\u5b9a\u3055\u308c\u307e\u3057\u305f\u3002\u300c\u60aa\u610f\u306e\u3042\u308b\u300dNRD\u306b\u5206\u985e\u3055\u308c\u305f\u5272\u5408\u306f1.74\uff05\u3001\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300dNRD\u306b\u5206\u985e\u3055\u308c\u305f\u5272\u5408\u306f34.60\uff05\u3067\u3059\u3002\u300c\u60aa\u610f\u306e\u3042\u308b\u300d\u30c9\u30e1\u30a4\u30f3\u3067\u306f\u3001\u305d\u306e15.84\uff05\u304c\u30e6\u30fc\u30b6\u30fc\u306e\u8cc7\u683c\u60c5\u5831\u3092\u7a83\u53d6\u3059\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u306b\u95a2\u4e0e\u3057\u3066\u304a\u308a\u300184.09\uff05\u306f\u3053\u308c\u4ee5\u5916\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3084\u60c5\u5831\u7a83\u53d6\u7528\u30de\u30eb\u30a6\u30a7\u30a2\uff08\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fc\uff09\u3092\u542b\u3080\u3055\u307e\u3056\u307e\u306a\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u3084\u30de\u30eb\u30a6\u30a7\u30a2\u3068\u306f\u7570\u306a\u308a\u3001C2\u901a\u4fe1\u7528\u30c9\u30e1\u30a4\u30f3\u306f\u6570\u4ef6\u3057\u304b\u898b\u3064\u304b\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002<\/p>\n<p>\u4ee5\u524d\u306e\u89b3\u6e2c\u7d50\u679c\u3092\u88cf\u4ed8\u3051\u308b\u3088\u3046\u306b\u30012\u6708\u304b\u30893\u6708\u306b\u304b\u3051\u30011\u65e5\u3042\u305f\u308a\u306e\u5e73\u5747\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u767b\u9332\u6570\u306b\u306f656\uff05\u306e\u5897\u52a0\u304c\u898b\u3089\u308c\u307e\u3057\u305f\u3002\u300c\u60aa\u610f\u306e\u3042\u308b\u300d\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30b9\u30c9\u30e1\u30a4\u30f3\u3001\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3067\u3082\u540c\u69d8\u306e\u50be\u5411\u304c\u898b\u3089\u308c\u3001\u305d\u308c\u305e\u308c569\uff05\u3068788\uff05\u5897\u52a0\u3057\u3066\u3044\u308b\u306e\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u56f33\u3067\u306f\u3001\u300c\u60aa\u610f\u306e\u3042\u308b\u300d\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u6570\u304c\u3053\u308c\u3089NRD\u3068\u540c\u3058\u50be\u5411\u3092\u898b\u305b\u3066\u304a\u308a\u3001\u306a\u304b\u306b\u306fNRD\u3067\u898b\u3089\u308c\u305f\u50be\u5411\u3092\u4e0a\u56de\u308b\u30b1\u30fc\u30b9\u3082\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106580\" aria-describedby=\"caption-attachment-106580\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-4.-Daily-customer-DNS-query-trends-related-to-coronavirus.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106581 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-4.-Daily-customer-DNS-query-trends-related-to-coronavirus.png\" alt=\"\u56f34 \u5f0a\u793e\u9867\u5ba2\u30d9\u30fc\u30b9\u3067\u898b\u305f\u2f47\u3054\u3068\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023DNS\u30af\u30a8\u30ea\u50be\u5411\uff08\u7e26\u8ef8\u306f\u5f0a\u793e\u9867\u5ba2\u30d9\u30fc\u30b9\u3067\u89b3\u6e2c\u3055\u308c\u305f\u5168DNS\u30af\u30a8\u30ea\u30921(=100%)\u3068\u3057\u305f\u5834\u5408\u306b\u5404\u30ab\u30c6\u30b4\u30ea\u306eNRD\u3078\u306eDNS\u30af\u30a8\u30ea\u304c\u5360\u3081\u308b\u5272\u5408(0.01=1%))\" width=\"600\" height=\"371\" \/><\/a><figcaption id=\"caption-attachment-106580\" class=\"wp-caption-text\">\u56f34 \u5f0a\u793e\u9867\u5ba2\u30d9\u30fc\u30b9\u3067\u898b\u305f\u2f47\u3054\u3068\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023DNS\u30af\u30a8\u30ea\u50be\u5411\uff08\u7e26\u8ef8\u306f\u5f0a\u793e\u9867\u5ba2\u30d9\u30fc\u30b9\u3067\u89b3\u6e2c\u3055\u308c\u305f\u5168DNS\u30af\u30a8\u30ea\u30921(=100%)\u3068\u3057\u305f\u5834\u5408\u306b\u5404\u30ab\u30c6\u30b4\u30ea\u306eNRD\u3078\u306eDNS\u30af\u30a8\u30ea\u304c\u5360\u3081\u308b\u5272\u5408(0.01=1%))<\/figcaption><\/figure>\n<p>\u3055\u3089\u306b\u79c1\u305f\u3061\u306e\u53ce\u96c6\u3057\u305f\u30d1\u30c3\u30b7\u30d6DNS\u30c7\u30fc\u30bf\u304b\u3089\u306f\u3001\u6700\u8fd1\u767b\u9332\u3055\u308c\u305f\u3082\u306e\u3067\u3042\u308b\u306b\u3082\u304b\u304b\u308f\u3089\u305a\u3001\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u306b\u5bfe\u3057\u3066\u5408\u8a08\u3067283\u4e075,197\u4ef6\u306eDNS\u30af\u30a8\u30ea\uff08\u30ad\u30e3\u30c3\u30b7\u30e5\u3055\u308c\u305f\u3082\u306e\u306f\u9664\u304f\uff09\u304c\u3042\u3063\u305f\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u304f\u308f\u3048\u3066\u3001\u5e73\u5747\u7684\u306a\u300c\u60aa\u610f\u306e\u3042\u308b\u300dNRD\u306f\u3001\u5e73\u5747\u7684\u306a\u300c\u60aa\u610f\u306e\u306a\u3044\u300dNRD\u3088\u308a\u308288\uff05\u30af\u30a8\u30ea\u6570\u304c\u591a\u304f\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u3053\u3068\u304c\u3055\u3089\u306b\u653b\u6483\u8005\u305f\u3061\u306b\u3088\u308b\u30d6\u30e9\u30c3\u30af\u30ea\u30b9\u30c8\u767b\u9332\u524d\u306e\u30c9\u30e1\u30a4\u30f3\u5229\u7528\u3092\u5f8c\u62bc\u3057\u3057\u3066\u3044\u307e\u3059\u3002\u56f34\u306f\u30017\u65e5\u9593\u306e\u79fb\u52d5\u5e73\u5747\u3092\u4f7f\u7528\u3057\u3001\u30d1\u30c3\u30b7\u30d6DNS\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3067\u89b3\u6e2c\u3055\u308c\u305fDNS\u30af\u30a8\u30ea\u306e\u65e5\u3054\u3068\u306e\u50be\u5411\u3092\u793a\u3057\u305f\u3082\u306e\u3067\u3059\u304c\u30013\u670816\u65e5\u306b\u691c\u7d22\u3055\u308c\u305f\u300c\u826f\u6027\u300dNRD\u6570\u3001\u300c\u60aa\u610f\u306e\u3042\u308b\u300dNRD\u6570\u304c\u6025\u5897\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u3053\u306e\u5897\u52a0\u306f\u3001\u7c73\u56fd\u3067\u306e\u30a6\u30a4\u30eb\u30b9\u306e\u30a2\u30a6\u30c8\u30d6\u30ec\u30a4\u30af\u306b\u3088\u3063\u3066\u6570\u65e5\u524d\u306b\u30d4\u30fc\u30af\u306b\u9054\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u3068\u30c9\u30e1\u30a4\u30f3\u767b\u9332\u6570\u89b3\u6e2c\u5185\u5bb9\u3068\u306b\u76f8\u95a2\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106739\" aria-describedby=\"caption-attachment-106739\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure05-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106739 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure05-1.png\" alt=\"\u56f35 NRD\u306b\u6700\u3082\u4e71\u7528\u3055\u308c\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30ad\u30fc\u30ef\u30fc\u30c9\" width=\"600\" height=\"337\" \/><\/a><figcaption id=\"caption-attachment-106739\" class=\"wp-caption-text\">\u56f35 NRD\u306b\u6700\u3082\u4e71\u7528\u3055\u308c\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30ad\u30fc\u30ef\u30fc\u30c9<\/figcaption><\/figure>\n<p>\u79c1\u305f\u3061\u304c\u5206\u6790\u306b\u4f7f\u7528\u3057\u305f\u30ad\u30fc\u30ef\u30fc\u30c9\u96c6\u306b\u306f\u300ccoronavirus\uff08\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\uff09\u300d\u3084\u300cCOVID-19\u300d\u306a\u3069\u3001\u4eca\u56de\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u306b\u7279\u6709\u306e\u7528\u8a9e\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3053\u308c\u3089\u30a6\u30a4\u30eb\u30b9\u306b\u76f4\u63a5\u95a2\u9023\u3059\u308b\u5358\u8a9e\u306b\u52a0\u3048\u3001\u300cpandemic\uff08\u30d1\u30f3\u30c7\u30df\u30c3\u30af\uff09\u300d\u306a\u3069\u306e\u3088\u308a\u4e00\u822c\u7684\u306a\u7528\u8a9e\u3082\u6d3b\u7528\u3057\u3001\u300cfacemask\uff08\u30d5\u30a7\u30a4\u30b9\u30de\u30b9\u30af\uff09\u300d\u3084\u300csanitizer\uff08\u624b\u6307\u6d88\u6bd2\u6db2\uff09\u300d\u306a\u3069\u3001\u4e0d\u8db3\u3057\u3066\u3044\u308b\u7269\u8cc7\u306b\u95a2\u9023\u3057\u305f\u30ad\u30fc\u30ef\u30fc\u30c9\u3082\u542b\u3081\u307e\u3057\u305f\u3002<\/p>\n<p>\u56f35\u306b\u6700\u3082\u591a\u304f\u306eNRD\u306b\u4e00\u81f4\u3057\u305f\u4e0a\u4f4d15\u500b\u306e\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u307e\u3068\u3081\u307e\u3057\u305f\u3002\u307b\u3068\u3093\u3069\u306e\u5834\u5408\u3001\u4eca\u56de\u306e\u30a6\u30a4\u30eb\u30b9\u306b\u7279\u6709\u306e\u7528\u8a9e\u307b\u3069\u30c9\u30e1\u30a4\u30f3\u767b\u9332\u8005\u306b\u597d\u307e\u308c\u3066\u3044\u308b\u3088\u3046\u3067\u3001\u95a2\u9023\u5546\u54c1\u306b\u3064\u3044\u3066\u306e\u30c9\u30e1\u30a4\u30f3\u767b\u9332\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u8907\u6570\u898b\u3089\u308c\u307e\u3057\u305f\u3002\u691c\u51fa\u6570\u3068\u306f\u5225\u306b\u3001\u3053\u308c\u3089\u4eba\u6c17\u30ad\u30fc\u30ef\u30fc\u30c9\u306e\u30ea\u30b9\u30af\u30ec\u30d9\u30eb\u306f\u5e73\u5747\u3088\u308a\u3082\u9ad8\u304f\uff0840\uff05\u4ee5\u4e0a\u304c\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u306b\u5206\u985e\u3055\u308c\u308b\uff09\u3001\u60aa\u7528\u306e\u53ef\u80fd\u6027\u3082\u305d\u308c\u3060\u3051\u9ad8\u304f\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u4e00\u65b9\u3067\u300c\u60aa\u610f\u306e\u3042\u308b\u300d\u306b\u5206\u985e\u3055\u308c\u305f\u5272\u5408\u306f\u5e73\u5747\u7684\u306a\u30ad\u30fc\u30ef\u30fc\u30c9\u3068\u540c\u7a0b\u5ea6\u3067\u3059\u3002\u7279\u6b8a\u306a\u30b1\u30fc\u30b9\u306f344\u4ef6\u306eNRD\u3068\u5408\u81f4\u3059\u308b\u300cvirusnews\u300d\u3068\u3044\u3046\u30ad\u30fc\u30ef\u30fc\u30c9\u3067\u3001\u305d\u306e33\uff05\u304c\u60aa\u610f\u306e\u3042\u308b\u3082\u306e\u3067\u3057\u305f\u3002<\/p>\n<h3>\u653b\u6483\u8005\u306f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u3092\u3069\u3046\u60aa\u7528\u3057\u3066\u3044\u308b\u304b<\/h3>\n<p>\u79c1\u305f\u3061\u306f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u95a2\u9023\u3057\u305f\u300c\u60aa\u610f\u306e\u3042\u308b\u300dNRD\u3068\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300dNRD\u306e\u5897\u52a0\u3092\u89b3\u6e2c\u3057\u3001\u305d\u3053\u304b\u3089\u3055\u3089\u306b\u5206\u6790\u3092\u9032\u3081\u3066\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u305f\u3061\u304c\u3053\u308c\u3089\u306eNRD\u3092\u3069\u306e\u3088\u3046\u306b\u5229\u7528\u3057\u3066\u3044\u308b\u304b\u306b\u3064\u3044\u3066\u8abf\u67fb\u3057\u307e\u3057\u305f\u3002\u307e\u305a\u3001WHOIS\u60c5\u5831\u3068DNS\u30ec\u30b3\u30fc\u30c9\u306b\u57fa\u3065\u3044\u3066\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u30af\u30e9\u30b9\u30bf\u30ea\u30f3\u30b0\uff08\u30b0\u30eb\u30fc\u30d7\u5316\uff09\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u60c5\u5831\u306b\u306f\u3001\u767b\u9332\u65e5\u3001\u30ec\u30b8\u30b9\u30c8\u30e9\u3001\u767b\u9332\u8005\u306e\u7d44\u7e54\u3001\u81ea\u5f8b\u30b7\u30b9\u30c6\u30e0\u756a\u53f7\uff08ASN\uff09\u3001\u30cd\u30fc\u30e0\u30b5\u30fc\u30d3\u30b9\u30d7\u30ed\u30d0\u30a4\u30c0\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u3053\u306e\u307b\u304b\u4e3b\u3068\u306a\u308bweb\u30da\u30fc\u30b8\u306e\u8996\u899a\u7684\u306a\u985e\u4f3c\u6027\u304b\u3089\u3082\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u30af\u30e9\u30b9\u30bf\u30ea\u30f3\u30b0\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u8996\u899a\u7684\u985e\u4f3c\u6027\u306e\u5206\u6790\u306b\u306f<a href=\"https:\/\/keras.io\/applications\/#densenet\">Keras\u30e9\u30a4\u30d6\u30e9\u30ea\u306e<\/a>DenseNet 201\u30e2\u30c7\u30eb\u306e\u6700\u7d42\u5c64\u3092\u7279\u5fb4\u8868\u73fe\u3068\u3057\u3066\u4f7f\u7528\u3059\u308bK\u8fd1\u508d\u6cd5\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3092\u63a1\u7528\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u7d50\u679c\u3001\u60aa\u610f\u306e\u3042\u308b\u30c9\u30e1\u30a4\u30f3\u3084\u60aa\u7528\u3092\u610f\u56f3\u3057\u305f\u767b\u9332\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u8907\u6570\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u3064\u3044\u3066\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30e6\u30fc\u30b9\u30b1\u30fc\u30b9\u306e\u5178\u578b\u7684\u306a\u30b7\u30ca\u30ea\u30aa\u3068\u5171\u306b\u8aac\u660e\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h4>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u4f7f\u3063\u3066\u30e6\u30fc\u30b6\u30fc\u8a8d\u8a3c\u60c5\u5831\u3092\u8a50\u53d6<\/h4>\n<p>\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u306e\u76ee\u7684\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u3092\u3060\u307e\u3057\u3066\u5f7c\u3089\u306e\u8cc7\u683c\u60c5\u5831\u3084\u500b\u4eba\u60c5\u5831\u3092\u5165\u624b\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3067\u306f\u3001\u653b\u6483\u8005\u304c\u6b63\u898f\u306e\u30d6\u30e9\u30f3\u30c9\u307e\u305f\u306f\u30b5\u30fc\u30d3\u30b9\u306eweb\u30b5\u30a4\u30c8\u3092\u9a19\u308b\u507dweb\u30b5\u30a4\u30c8\u3078\u306e\u30ea\u30f3\u30af\u3092\u5f0a\u793e\u9867\u5ba2\u306b\u30e1\u30fc\u30eb\u3067\u9001\u4fe1\u3057\u3001\u30ed\u30b0\u30a4\u30f3\u8a8d\u8a3c\u60c5\u5831\u3092\u3060\u307e\u3057\u53d6\u308d\u3046\u3068\u3059\u308b\u53e4\u5178\u7684\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30b9\u30ad\u30fc\u30e0\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><figure id=\"attachment_106584\" aria-describedby=\"caption-attachment-106584\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-6.-Domain-corona-masr21.com-hosting-a-Bank-of-America-phishing-page.jpeg\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106585 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-6.-Domain-corona-masr21.com-hosting-a-Bank-of-America-phishing-page.jpeg\" alt=\"\u56f36 Bank of America\u306e\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30da\u30fc\u30b8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\" width=\"600\" height=\"454\" \/><\/a><figcaption id=\"caption-attachment-106584\" class=\"wp-caption-text\">\u56f36 Bank of America\u306e\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30da\u30fc\u30b8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3<span style=\"font-family: 'courier new', courier, monospace;\">corona-masr21[.]com<\/span><\/figcaption><\/figure>\u79c1\u305f\u3061\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">corona-masr<strong>*<\/strong>[.]com<\/span>\u3068\u3044\u3046\u547d\u540d\u30d1\u30bf\u30fc\u30f3\u3067\u540c\u3058\u65e5\u306b\u767b\u9332\u3055\u308c\u305f<a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Phishing%20User%20Credentials%20with%20Coronavirus%20Domains\">20\u500b\u306e\u30c9\u30e1\u30a4\u30f3\u306e<\/a>\u30af\u30e9\u30b9\u30bf\u3092\u691c\u51fa\u3057\u307e\u3057\u305f\u3002\u3053\u3053\u3067\u300c<strong>*<\/strong>\u300d\u306b\u5165\u308b\u306e\u306f1\u301c101\u306e\u3044\u305a\u308c\u304b\u306e\u6570\u5b57\u3067\u3059\u3002\u3053\u306e\u7bc4\u56f2\u3060\u3068101\u4ef6\u5206\u30c9\u30e1\u30a4\u30f3\u540d\u306e\u30d0\u30ea\u30a8\u30fc\u30b7\u30e7\u30f3\u3092\u4f5c\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u304c\u3001\u767b\u9332\u3055\u308c\u3066\u3044\u305f\u306e\u306f20\u4ef6\u306e\u307f\u3067\u3057\u305f\u3002\u56f36\u306b\u3001Bank of America\u3092\u6a19\u7684\u3068\u3059\u308b\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u7528URL <span style=\"font-family: 'courier new', courier, monospace;\">hxxp[:]\/\/corona-masr21[.]com\/boa\/bankofamerica\/login.php <\/span>\u306e\u4f8b\u3092\u793a\u3057\u307e\u3059\u3002\u653b\u6483\u8005\u306e\u76ee\u6a19\u306f\u3001\u3053\u306e\u507dweb\u30da\u30fc\u30b8\u304c\u9280\u884c\u6240\u6709\u306e\u30b5\u30a4\u30c8\u3060\u3068\u601d\u308f\u305b\u3066\u30e6\u30fc\u30b6\u30fc\u306e\u30ed\u30b0\u30a4\u30f3\u3092\u4fc3\u3059\u3053\u3068\u3067\u3059\u3002\u3053\u306e\u30af\u30e9\u30b9\u30bf\u306b\u306f\u3001Apple\u306e\u30ed\u30b0\u30a4\u30f3\u30da\u30fc\u30b8\u3092\u6a19\u7684\u3068\u3059\u308b<span style=\"font-family: 'courier new', courier, monospace;\">http[:]\/\/corona-masr21[.]com\/apple-online<\/span>\u3084\u3001PayPal\u306e\u30ed\u30b0\u30a4\u30f3\u30da\u30fc\u30b8\u3092\u6a19\u7684\u3068\u3059\u308b<span style=\"font-family: 'courier new', courier, monospace;\">hxxps[:]\/\/corona-masr3[.]com\/CAZANOVA%20TRUE%20LOGIN%20SMART%202019\/<\/span>\u306a\u3069\u4ed6\u306e\u30b5\u30fc\u30d3\u30b9\u3092\u6a21\u5023\u3057\u305f\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0URL\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u307e\u305f\u3079\u3064\u306e\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306f<span style=\"font-family: 'courier new', courier, monospace;\">corona-virusus[.]com<\/span><span style=\"font-family: 'courier new', courier, monospace;\">\u3001<\/span><span style=\"font-family: 'courier new', courier, monospace;\">coronavirus-meds[.]com<\/span>\u306a\u3069\u306e\u30c9\u30e1\u30a4\u30f3\u304cOutlook\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u6a19\u7684\u306b\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u3055\u3089\u306b\u3053\u308c\u3089\u306e\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30da\u30fc\u30b8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30bd\u30fc\u30b9\u306e\u30a2\u30fc\u30c6\u30a3\u30d5\u30a1\u30af\u30c8\uff08\u75d5\u8de1\uff09\u3092\u542b\u3080zip\u30d5\u30a1\u30a4\u30eb\u3082\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306b\u306f\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306e\u300c\u30d5\u30ed\u30f3\u30c8\u30a8\u30f3\u30c9\u300d\u306b\u3042\u305f\u308bHTML\u3068PHP\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9(<span style=\"font-family: 'courier new', courier, monospace;\">corona-masr4[.]com\/test.zip)<\/span>\u3060\u3051\u3067\u306a\u304f\u3001\u30b9\u30d1\u30e0\u30e1\u30fc\u30eb\u3092\u9001\u4fe1\u3057\u305f\u308a\u3001\u7121\u5bb3\u306aweb\u30af\u30ed\u30fc\u30e9\u30fc\u304b\u3089\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u3066\u62d2\u5426\u3059\u308b\u30b3\u30fc\u30c9(<span style=\"font-family: 'courier new', courier, monospace;\">corona-virusus[.]com\/OwaOwaowa.zip<\/span>)\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u60aa\u610f\u306e\u3042\u308b\u653b\u6483\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u60aa\u610f\u306e\u3042\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30d1\u30c3\u30af\u6e08\u307f\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u306a\u3044\u3057\u914d\u5e03\u3059\u308b\u306e\u306f\u3053\u3046\u3057\u305f\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u306f\u3088\u304f\u898b\u3089\u308c\u308b\u3084\u308a\u53e3\u3067\u3001\u30c9\u30ed\u30c3\u30d1\u30fc\u304c\u3053\u3046\u3057\u305f\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5225\u306e\u4fb5\u5bb3\u6e08\u307fweb\u30b5\u30a4\u30c8\u304b\u3089\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106741\" aria-describedby=\"caption-attachment-106741\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure07-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106741 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/figure07-1.png\" alt=\"\u56f37 \u6b63\u898f\u306eBank of America\u306eweb\u30b5\u30a4\u30c8\" width=\"600\" height=\"337\" \/><\/a><figcaption id=\"caption-attachment-106741\" class=\"wp-caption-text\">\u56f37 \u6b63\u898f\u306eBank of America\u306eweb\u30b5\u30a4\u30c8<\/figcaption><\/figure>\n<p>\u30e6\u30fc\u30b6\u30fc\u306f\u56f37\u306b\u793a\u3057\u305f3\u3064\u306e\u4e3b\u8981\u306a\u6307\u6a19\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3067\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u306e\u88ab\u5bb3\u306b\u3042\u3063\u3066\u3044\u306a\u3044\u304b\u3069\u3046\u304b\u78ba\u8a8d\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u307e\u305a\u306fURL\u306e\u30c9\u30e1\u30a4\u30f3\u90e8\u5206\u304c\u3001\u30ed\u30b0\u30a4\u30f3\u5148\u30b5\u30fc\u30d3\u30b9\u306e\u6240\u6709\u304c\u60f3\u5b9a\u3055\u308c\u308b\u30c9\u30e1\u30a4\u30f3\u540d\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u6b21\u306b\u5de6\u4e0a\u306b\u30ed\u30c3\u30af\uff08\u9320\u524d\uff09\u30a2\u30a4\u30b3\u30f3\u304c\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u3053\u306e\u30ed\u30c3\u30af\u306f\u6709\u52b9\u306aHTTPS\u63a5\u7d9a\u7d4c\u7531\u3067\u63a5\u7d9a\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u304a\u308a\u3001\u4e2d\u9593\u8005\uff08MiTM\uff09\u653b\u6483\u3092\u9632\u6b62\u3057\u307e\u3059\u3002\u6700\u5f8c\u306b\u30c9\u30e1\u30a4\u30f3\u540d\u304c\u8a3c\u660e\u66f8\u306e\u6240\u6709\u8005\u3068\u4e00\u81f4\u3059\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/p>\n<h4>\u60aa\u610f\u306e\u3042\u308b\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u3092\u30db\u30b9\u30c8\u3059\u308b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3<\/h4>\n<p>\u65b0\u3057\u304f\u767b\u9332\u3055\u308c\u305fCOVID-19\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u306e\u591a\u304f\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u6d3b\u52d5\u306b\u95a2\u4e0e\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u7279\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305d\u3046\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u306e1\u3064\u3001<span style=\"font-family: 'courier new', courier, monospace;\">covid-19-gov[.]com<\/span>\u3068\u3044\u3046\u30c9\u30e1\u30a4\u30f3\u306b\u306f\u3068\u304f\u306b\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002\u3068\u3044\u3046\u306e\u3082\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f<a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/new-redline-stealer-distributed-using-coronavirus-themed-email-campaign\">\u4ee5\u524dProofpoint\u304c\u5831\u3058\u305f<\/a>\u5185\u5bb9\u306b\u4f3c\u305fRedLine Stealer\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u5408\u81f4\u3057\u3066\u3044\u308b\u304b\u3089\u3067\u3059\u3002<\/p>\n<p>\u6f5c\u5728\u7684\u88ab\u5bb3\u8005\u3092\u4e0a\u8a18\u306e\u30b5\u30a4\u30c8\u306b\u8a98\u5c0e\u3059\u308b\u305f\u3081\u306b\u5229\u7528\u3055\u308c\u305f\u521d\u671f\u611f\u67d3\u30d9\u30af\u30c8\u30eb\u304c\u4f55\u3067\u3042\u3063\u305f\u304b\u306f\u4e0d\u660e\u3067\u3059\u304c\u3001Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u3001ZIP\u30d5\u30a1\u30a4\u30eb\u5185\u306eURL <span style=\"font-family: 'courier new', courier, monospace;\">covid-19-gov[.]com<\/span>\u306bRedLine Stealer\u306e\u30b5\u30f3\u30d7\u30eb\u304c\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u7279\u5b9a\u6e08\u307f\u3067\u3059\u3002ZIP\u30d5\u30a1\u30a4\u30eb\u306e\u5185\u5bb9\u3092\u62bd\u51fa\u3059\u308b\u3068\u3001RedLine Stealer\u30d0\u30a4\u30ca\u30ea\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u306f<span style=\"font-family: 'courier new', courier, monospace;\">Covid-Locator.exe<\/span>\u3067\u3042\u308b\u3053\u3068\u304c\u5224\u660e\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u5b9f\u884c\u3055\u308c\u308b\u3068\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u307e\u305aInternet Explorer\u3092\u958b\u3044\u3066<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/localhost:14109<\/span>\u306b\u63a5\u7d9a\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001URL <span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/45.142.212[.]126:6677\/IRemotePanel<\/span>\u306b\u5bfe\u3059\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u9001\u4fe1\u3092\u958b\u59cb\u3057\u307e\u3059\u304c\u3001\u3053\u306e\u52d5\u4f5c\u306fRedLine Stealer\u306e\u30c1\u30a7\u30c3\u30af\u30a4\u30f3\u306e\u632f\u308b\u821e\u3044\u3068\u4e00\u81f4\u3057\u3066\u3044\u307e\u3059\u3002\u30c1\u30a7\u30c3\u30af\u30a4\u30f3\u304c\u884c\u308f\u308c\u3001\u30ea\u30e2\u30fc\u30c8\u306eC2\u30b5\u30fc\u30d0\u30fc\u304cHTTP 200 OK\u5fdc\u7b54\u3092\u8fd4\u3059\u3068\u30db\u30b9\u30c8\u304b\u3089\u30c7\u30fc\u30bf\u6f0f\u51fa\u304c\u59cb\u307e\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106588\" aria-describedby=\"caption-attachment-106588\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-8.-Network-traffic-from-RedLine-Stealer-data-exfiltration.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106589 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-8.-Network-traffic-from-RedLine-Stealer-data-exfiltration.png\" alt=\"\u56f38 RedLine Stealer\u306b\u3088\u308b\u30c7\u30fc\u30bf\u6f0f\u51fa\u6642\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\" width=\"600\" height=\"351\" \/><\/a><figcaption id=\"caption-attachment-106588\" class=\"wp-caption-text\">\u56f38 RedLine Stealer\u306b\u3088\u308b\u30c7\u30fc\u30bf\u6f0f\u51fa\u6642\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/figcaption><\/figure>\n<p>\u3068\u304f\u306b\u6ce8\u76ee\u3059\u3079\u304d\u306f\u3001SOAPAction HTTP\u30d8\u30c3\u30c0\u30d5\u30a3\u30fc\u30eb\u30c9\u3067<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/tempuri[.]org\/IRemotePanel\/SendClientInfo<\/span>\u3068\u3044\u3046URL\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u70b9\u3067\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">tempuri[.]org<\/span>\u3068\u3044\u3046\u30c9\u30e1\u30a4\u30f3\u306f\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u76f4\u63a5\u306f\u95a2\u4e0e\u3057\u3066\u3044\u307e\u305b\u3093\u304c\u3001\u958b\u767a\u4e2d\u306eweb\u30b5\u30fc\u30d3\u30b9\u306b\u306f\u3088\u304f\u3042\u308b\u30d7\u30ec\u30fc\u30b9\u30db\u30eb\u30c0\u7684\u306a\u30c9\u30e1\u30a4\u30f3\u540d\u3067\u3059\u3002\u304d\u3061\u3093\u3068\u3057\u305fweb\u30b5\u30fc\u30d3\u30b9\u5b9f\u88c5\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u306b\u5f93\u3046\u306a\u3089\u3001\u3053\u306e\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u66f4\u65b0\u3057\u3066\u9069\u5207\u306a\u540d\u524d\u7a7a\u9593\u304c\u53cd\u6620\u3055\u308c\u308b\u3088\u3046\u306b\u3059\u3079\u304d\u3067\u3059\u3057\u3001\u7279\u5b9a\u306eweb\u30b5\u30fc\u30d3\u30b9\u3092\u4e00\u610f\u306b\u8b58\u5225\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u3066\u304a\u304f\u3079\u304d\u3067\u3057\u3087\u3046\u3002\u3068\u306f\u3044\u3048\u8a73\u7d30\u8aac\u660e\u306f\u6b63\u898f\u306eweb\u30b5\u30fc\u30d3\u30b9\u3067\u3082\u898b\u843d\u3068\u3057\u304c\u3061\u306a\u306e\u3067\u3001\u8105\u5a01\u3092\u8b58\u5225\u3059\u308b\u76ee\u7684\u3067\u306f\u3053\u306e<span style=\"font-family: 'courier new', courier, monospace;\">tempuri[.]org<\/span> \u3068\u3044\u3046URL\u3092IoC\u3068\u307f\u306a\u3059<strong>\u3079\u304d\u3067\u306f\u306a\u3044<\/strong>\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>\u3053\u306e\u307b\u304b\u3053\u306eRedLine Stealer\u4e9c\u7a2e\u306b\u3088\u308b\u30db\u30b9\u30c8\u4e0a\u3067\u306e\u632f\u308b\u821e\u3044\u3067\u8208\u5473\u3092\u5f15\u304f\u306e\u304c\u3001\u96a0\u3057\u30b3\u30de\u30f3\u30c9\u30d7\u30ed\u30f3\u30d7\u30c8\u30a6\u30a3\u30f3\u30c9\u30a6\u4e0a\u3067\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u70b9\u3067\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">cmd.exe\" \/C taskkill \/F \/PID &lt;RedLine Stealer PID&gt; &amp;&amp; choice \/C Y \/N \/D Y \/T 3 &amp; Del \u201c\u201d<\/span><\/p>\n<p>\u30b3\u30de\u30f3\u30c9\u306e\u5185\u5bb9\u304b\u3089\u3057\u3066\u3001\u3053\u3053\u3067\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u4f5c\u6210\u8005\u306e\u610f\u56f3\u306f\u3001 <span style=\"font-family: 'courier new', courier, monospace;\">cmd.exe<\/span>\u7d4c\u7531\u3067\u5b9f\u884c\u3055\u308c\u305f\u5834\u5408\u306b\u3001RedLine Stealer\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u4e2d\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u30d7\u30ed\u30bb\u30b9\u8b58\u5225\u5b50\uff08PID\uff09\u3067\u8b58\u5225\u3057\u3066\u3053\u306e\u30b3\u30de\u30f3\u30c9\u3067\u5f37\u5236\u7d42\u4e86\u3059\u308b\u3053\u3068\u306b\u3042\u3063\u305f\u3068\u63a8\u6e2c\u3067\u304d\u307e\u3059\u3002 \u3053\u308c\u306b\u3088\u308aRedLine Stealer\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u524a\u9664\u3092\u958b\u59cb\u3057\u3001\u524a\u9664\u30b3\u30de\u30f3\u30c9\u3067\u8fd4\u3055\u308c\u308b\u78ba\u8a8d\u30d7\u30ed\u30f3\u30d7\u30c8\u306b\u300c<span style=\"font-family: 'courier new', courier, monospace;\">Y<\/span>\uff08\u306f\u3044\uff09\u300d\u3068\u30d7\u30ed\u30b0\u30e9\u30e0\u7684\u306b\u5fdc\u7b54\u3057\u3088\u3046\u3068\u3057\u305f\u306e\u3067\u3057\u3087\u3046\u3002\u305f\u3060\u3057\u3001\u3053\u306e\u3084\u308a\u304b\u305f\u306b\u306f2\u3064\u306e\u554f\u984c\u304c\u3042\u308a\u307e\u3059\u30021\u3064\u76ee\u306e\u554f\u984c\u306f\u305d\u3082\u305d\u3082\u3053\u306e\u8003\u3048\u3067\u306f\u3046\u307e\u304f\u3044\u304b\u306a\u3044\u3088\u3046\u306b\u898b\u3048\u308b\u70b9\u3067\u3059\u3002\u3053\u306e\u4f8b\u3067\u306f<span style=\"font-family: 'courier new', courier, monospace;\">choice<\/span>\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3063\u3066\u3082\u671b\u3093\u3060\u7d50\u679c\u306f\u5f97\u3089\u308c\u306a\u3044\u3067\u3057\u3087\u3046\u3002\u6b21\u306b\u3001\u73fe\u72b6\u3067\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u4e2d\u306e\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u304d\u3061\u3093\u3068kill\u3057\u3066choice\u3067\u300c<span style=\"font-family: 'courier new', courier, monospace;\">Y<\/span>\u300d\u3092\u5b9f\u884c\u306f\u3059\u308b\u306e\u3067\u3059\u304c\uff08\u30b3\u30de\u30f3\u30c9\u306b<span style=\"font-family: 'courier new', courier, monospace;\">\/T<\/span>\u30b9\u30a4\u30c3\u30c1\u304c\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u306e\u30673\u79d2\u7d4c\u904e\u3059\u308c\u3070\u81ea\u52d5\u9078\u629e\u3055\u308c\u308b\uff09\u3001\u3053\u306e\u5834\u5408\u3001\u5148\u306bY\u304c\u9078\u629e\u3055\u308c\u3066\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u524a\u9664\u30d7\u30ed\u30f3\u30d7\u30c8\u304c\u8868\u793a\u3055\u308c\u3066\u3057\u307e\u3044\u307e\u3059\u3002\u3064\u307e\u308a\u3001\u4eee\u306b\u3053\u306e\u3084\u308a\u304b\u305f\u3067<span style=\"font-family: 'courier new', courier, monospace;\">choice<\/span>\u304c\u4f7f\u7528\u3067\u304d\u305f\u3068\u3057\u3066\u3082\u3084\u306f\u308a\u610f\u56f3\u3057\u305f\u52d5\u4f5c\u306b\u306f\u306a\u3089\u306a\u3044\u3068\u3044\u3046\u3053\u3068\u3067\u3059\u3002<\/p>\n<p>\u3055\u3089\u306b\u3053\u306eRedLine Stealer\u4e9c\u7a2e\u306f\u3001\u30c7\u30a3\u30b9\u30af\u4e0a\u306b\u8ffd\u52a0\u3067\u60aa\u610f\u306e\u3042\u308b\u30d5\u30a1\u30a4\u30eb\u3092\u751f\u6210\u3057\u305f\u308a\u3001\u30df\u30e5\u30fc\u30c6\u30c3\u30af\u30b9\u3092\u4f5c\u6210\u30fb\u5909\u66f4\u3057\u305f\u308a\u3001\u30db\u30b9\u30c8\u30d9\u30fc\u30b9\u306e\u6c38\u7d9a\u6027\u3092\u78ba\u7acb\u3057\u3088\u3046\u3068\u3057\u305f\u308a\u3059\u308b\u3088\u3046\u306b\u306f\u898b\u3048\u307e\u305b\u3093\u3002<\/p>\n<p>RedLine Stealer\u306b\u52a0\u3048\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u4f7f\u3063\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u914d\u4fe1\u4f8b\u3082\u691c\u51fa\u3055\u308c\u307e\u3057\u305f\u3002<span style=\"font-family: 'courier new', courier, monospace;\">corona-map-data[.]com\/bin\/regsrtjser346.exe<\/span>\u3067\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308b\u3082\u306e\u304c\u305d\u3046\u3057\u305f\u4f8b\u3067\u3001\u3053\u308c\u306fDanabot\u3068\u3044\u3046\u30d0\u30f3\u30ad\u30f3\u30b0\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3042\u308b\u3053\u3068\u304c\u7279\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u307b\u304b\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3092\u30c6\u30fc\u30de\u306b\u3057\u3066\u30e2\u30d0\u30a4\u30eb\u30e6\u30fc\u30b6\u30fc\u3092\u72d9\u3046\u30de\u30eb\u30a6\u30a7\u30a2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3082\u8907\u6570\u7279\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u30c9\u30e1\u30a4\u30f3<span style=\"font-family: 'courier new', courier, monospace;\">Corona-virusapps[.]com<\/span>\u4e0a\u3067\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308bURL\u304b\u30893\u3064\u306e\u60aa\u610f\u306e\u3042\u308bAndroid\u30a2\u30d7\u30ea\u304c\u898b\u3064\u304b\u3063\u3066\u3044\u307e\u3059\u3002\u305d\u306eURL\u30b9\u30ad\u30fc\u30de\u306f<span style=\"font-family: 'courier new', courier, monospace;\">Corona-virusapps[.]com\/s&lt;1-3&gt;\/CoronaVirus-apps.apk<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">coronaviruscovid19-information[.]com\/it\/corona.apk<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">coronaviruscovid19-information[.]com\/en\/corona.apk<\/span>\u3067\u3042\u308b\u3053\u3068\u304c\u305d\u308c\u305e\u308c\u7279\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u524d\u8ff0\u306eAPK\u306f\u3059\u3079\u3066\u4e00\u822c\u7684\u306a\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3042\u308b\u3053\u3068\u304c\u7279\u5b9a\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>Danabot\u30b5\u30f3\u30d7\u30eb\u3084\u3055\u307e\u3056\u307e\u306aAPK\u306e\u5b8c\u5168\u306a\u8a73\u7d30\u5206\u6790\u306f\u672c\u7a3f\u3067\u306e\u7bc4\u56f2\u5916\u306a\u306e\u3067\u5272\u611b\u3057\u307e\u3059\u304c\u3001\u95a2\u9023\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u5f8c\u8ff0\u306eIoC\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u8a18\u8f09\u3057\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<h4>C2\u901a\u4fe1\u7528\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3<\/h4>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u30b3\u30de\u30f3\u30c9\u53d7\u4fe1\u3084\u30c7\u30fc\u30bf\u6f0f\u51fa\u3092\u884c\u3046\u306b\u3042\u305f\u308a\u3001C2\u30c9\u30e1\u30a4\u30f3\u3092\u4f7f\u3063\u3066\u3044\u308f\u3086\u308bPhone Home\u901a\u4fe1\u3092\u884c\u3044\u307e\u3059\u3002\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u306e\u5927\u534a\u306f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3092\u4e3b\u306b\u30de\u30eb\u30a6\u30a7\u30a2\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u3001\u8a50\u6b3a\u306b\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u305d\u3046\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u304cC2\u901a\u4fe1\u306b\u95a2\u4e0e\u3057\u3066\u3044\u308b\u30b1\u30fc\u30b9\u3082\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106590\" aria-describedby=\"caption-attachment-106590\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-9.-NATsupport-network-communication.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106591 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-9.-NATsupport-network-communication.png\" alt=\"\u56f39 NATsupport\u306b\u3088\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u901a\u4fe1\" width=\"600\" height=\"96\" \/><\/a><figcaption id=\"caption-attachment-106590\" class=\"wp-caption-text\">\u56f39 NATsupport\u306b\u3088\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u901a\u4fe1<\/figcaption><\/figure>\n<p>\u60aa\u610f\u306e\u3042\u308bNATSupportManager\u3068\u3044\u3046\u9060\u9694\u30a2\u30af\u30bb\u30b9\u30c4\u30fc\u30eb\uff08RAT\uff09\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">covidpreventandcure[.]com<\/span>\u3068\u3044\u3046\u30c9\u30e1\u30a4\u30f3\u3092\u5229\u7528\u3057\u3066\u3044\u307e\u3059\u3002\u56f39\u306b\u793a\u3057\u305f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u3001\u5f53\u8a72\u30c9\u30e1\u30a4\u30f3\u304c<span style=\"font-family: 'courier new', courier, monospace;\">5.181.156[.]14<\/span>\u306b\u89e3\u6c7a\u3055\u308c\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u6b21\u306b\u3053\u306eRAT\u306f\u8907\u6570\u306ePOST\u30ea\u30af\u30a8\u30b9\u30c8\u3092<span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/5.181.156[.]14\/fakeurl.htm<\/span>\u306b\u9001\u4fe1\u3059\u308b\u307b\u304b\u3001443\/tcp\u7d4c\u7531\u3067TCP\u30d1\u30b1\u30c3\u30c8\u3092\u9001\u4fe1\u3057\u307e\u3059\u3002\u56f310\u306b\u793a\u3057\u305f\u3068\u304a\u308a\u3001\u3053\u306ePOST\u30ea\u30af\u30a8\u30b9\u30c8\u901a\u4fe1\u306fHTML\u30d5\u30a9\u30fc\u30e0\u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002C2\u30b5\u30fc\u30d0\u30fc\u5074\u306f\u3001HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u5185\u306b\u30b3\u30de\u30f3\u30c9\u3068\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30a8\u30f3\u30b3\u30fc\u30c9\u3057\u3066\u305d\u308c\u3092HTML\u30d5\u30a9\u30fc\u30e0\u306b\u6dfb\u4ed8\u3057\u3001\u305d\u308c\u306b\u5bfe\u3057\u3066\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u5074\u304c\u7a83\u53d6\u3057\u305f\u30c7\u30fc\u30bf\u3092\u30a8\u30f3\u30b3\u30fc\u30c9\u3057\u3066\u9001\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106592\" aria-describedby=\"caption-attachment-106592\" style=\"width: 459px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-10.-HTML-form-communication.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106593 size-full lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-10.-HTML-form-communication.png\" alt=\"\u56f310 HTML\u30d5\u30a9\u30fc\u30e0\u306b\u3088\u308b\u901a\u4fe1\" width=\"459\" height=\"76\" \/><\/a><figcaption id=\"caption-attachment-106592\" class=\"wp-caption-text\">\u56f310 HTML\u30d5\u30a9\u30fc\u30e0\u306b\u3088\u308b\u901a\u4fe1<\/figcaption><\/figure>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">covidpreventandcure[.]com<\/span>\u306f3\u670826\u65e5\u306b\u767b\u9332\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5f0a\u793e\u3067\u306f\u3053\u306e2\u65e5\u5f8c\u304b\u3089\u95a2\u9023DNS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u76e3\u8996\u3092\u958b\u59cb\u3057\u307e\u3057\u305f\u304c\u3001\u3053\u306e\u901a\u4fe1\u306f4\u670811\u65e5\u307e\u3067\u30a2\u30af\u30c6\u30a3\u30d6\u3067\u3057\u305f\u30024\u6708\u306b\u5165\u3063\u3066\u5f53\u8a72\u30c9\u30e1\u30a4\u30f3\u3092\u89e3\u6c7a\u3059\u308bDNS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u5927\u5e45\u306b\u5897\u52a0\u3057\u305f\u3053\u3068\u304b\u3089\u3001\u3053\u306e\u95a2\u9023\u3067\u306e\u4fb5\u5bb3\u304c\u6025\u5897\u3057\u305f\u53ef\u80fd\u6027\u304c\u793a\u5506\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u306f\u3001\u5225\u306e\u672a\u767b\u9332\u306eCOVID-19\u30c9\u30e1\u30a4\u30f3<span style=\"font-family: 'courier new', courier, monospace;\">covidwhereandhow[.]xyz<\/span>\u3092\u89e3\u6c7a\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306f\u5c06\u6765\u7684\u306a\u653b\u6483\u306b\u5099\u3048\u3066\u306e\u3082\u306e\u3067\u3042\u3063\u305f\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u307b\u304b\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u5229\u7528\u3055\u308c\u3066\u3044\u305fCOVID-19\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3068\u3057\u3066\u306f<span style=\"font-family: 'courier new', courier, monospace;\">coronavirusstatusp[.]space<\/span>\u304c\u3042\u3052\u3089\u308c\u307e\u3059\u3002\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f <a href=\"https:\/\/app.any.run\/tasks\/fb202ab9-de35-4ca0-a35f-eabdde068f03\/\">\u30b0\u30ed\u30fc\u30d0\u30eb\u306bCOVID-19\u3092\u8ffd\u8de1\u3059\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3<\/a>\u3067\u3042\u308b\u3053\u3068\u3092\u9a19\u308bAzoRult\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u306b\u95a2\u9023\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<h4>\u4e0d\u8db3\u7269\u8cc7\u306b\u4e57\u305a\u308b\u8a50\u6b3aEC\u30b5\u30a4\u30c8<\/h4>\n<p>\u60aa\u610f\u306e\u3042\u308b\u30e6\u30fc\u30b6\u30fc\u304c\u507d\u306eEC\u30b5\u30a4\u30c8\u3092\u4f5c\u308a\u3001\u30e6\u30fc\u30b6\u30fc\u3092\u3060\u307e\u3057\u3066\u4e0d\u8db3\u7269\u8cc7\u3092\u8cb7\u308f\u305b\u3088\u3046\u3068\u3059\u308b\u3001\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u306e\u30c9\u30e1\u30a4\u30f3\u304c\u767b\u9332\u3055\u308c\u3066\u3044\u308b\u69d8\u5b50\u3082\u8907\u6570\u7279\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u3046\u3057\u305f\u30b5\u30a4\u30c8\u306b\u3088\u308b\u88ab\u5bb3\u3092\u53d7\u3051\u305a\u306b\u6e08\u3080\u3088\u3046\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u8a50\u6b3aEC\u30b5\u30a4\u30c8\u306e\u6307\u6a19\u3068\u3057\u3066\u4f7f\u3048\u308b\u624b\u304c\u304b\u308a\u306f\u305f\u304f\u3055\u3093\u3042\u308a\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u3053\u3046\u3057\u305f\u507d\u306eEC\u30b5\u30a4\u30c8\u3067\u306f\u3001\u73fe\u5728\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306e\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u72b6\u6cc1\u304b\u3089\u306f\u8003\u3048\u3089\u308c\u306a\u3044\u307b\u3069\u597d\u6761\u4ef6\u306e\u5e83\u544a\u3092\u51fa\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u3088\u304f\u3042\u308a\u307e\u3059\u3002\u3064\u307e\u308a\u3001\u30d5\u30a7\u30a4\u30b9\u30de\u30b9\u30af\u3084\u624b\u6307\u6d88\u6bd2\u6db2\u306a\u3069\u9700\u8981\u306e\u9ad8\u3044\u5546\u54c1\u3092\u5272\u5f15\u4fa1\u683c\u3067\u63d0\u4f9b\u3059\u308b\u3068\u3044\u3046\u3082\u306e\u3067\u3059\u3002\u3053\u3046\u3057\u305f\u7279\u5fb4\u306b\u304f\u308f\u3048\u3001\u305d\u306eEC\u30b5\u30a4\u30c8\u304c\u65b0\u3057\u304f\u4f5c\u6210\u3055\u308c\u305f\u3082\u306e\u3067\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308c\u3070\u3001\u305d\u3053\u304b\u3089\u3055\u3089\u306b\u624b\u304c\u304b\u308a\u3092\u63a2\u3057\u307e\u3059\u3002\u3053\u306e\u307b\u304b\u306e\u6307\u6a19\u3068\u3057\u3066\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306b\u300c\u3059\u3050\u306b\u8cb7\u308f\u306a\u3044\u3068\u30bb\u30fc\u30eb\u3092\u9003\u3059\u300d\u3068\u305d\u305d\u306e\u304b\u3059\u3001\u507d\u306e\u30ec\u30d3\u30e5\u30fc\u304c\u3064\u3044\u3066\u3044\u308b\u3001\u9023\u7d61\u5148\u306e\u60c5\u5831\u304c\u507d\u7269\u3001EC\u30b5\u30a4\u30c8\u306e\u6587\u7ae0\u304c\u30b3\u30d4\u30da\u3001\u6587\u6cd5\u4e0a\u306e\u8aa4\u308a\u304c\u3042\u308b\u3001\u30da\u30fc\u30b8\u5185\u306b\u30ad\u30fc\u30ef\u30fc\u30c9\u304c\u8a70\u3081\u8fbc\u307e\u308c\u3066\u3044\u308b\u3001\u306a\u3069\u304c\u3042\u3052\u3089\u308c\u308b\u3067\u3057\u3087\u3046\u3002<\/p>\n<p><figure id=\"attachment_106594\" aria-describedby=\"caption-attachment-106594\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-11.-allsurgicalfacemask.com-scam-website.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106595 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-11.-allsurgicalfacemask.com-scam-website.png\" alt=\"\u56f311 \u8a50\u6b3aEC\u30b5\u30a4\u30c8\" width=\"600\" height=\"413\" \/><\/a><figcaption id=\"caption-attachment-106594\" class=\"wp-caption-text\">\u56f311 \u8a50\u6b3aEC\u30b5\u30a4\u30c8<span style=\"font-family: 'courier new', courier, monospace;\">allsurgicalfacemask[.]com<\/span><\/figcaption><\/figure>\u3042\u308b\u7279\u5b9a\u30b0\u30eb\u30fc\u30d7\u304c\u3001<span style=\"font-family: 'courier new', courier, monospace;\">allsurgicalfacemask[.]com<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">surgicalfacemaskpharmacyonline[.]com<\/span>\u3068\u3044\u30462\u3064\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u767b\u9332\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30b5\u30a4\u30c8\u306f\u9700\u8981\u306e\u9ad8\u3044\u30d5\u30a7\u30a4\u30b9\u30de\u30b9\u30af\u306e\u5ba3\u4f1d\u3092\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u30892\u3064\u306e\u30b5\u30a4\u30c8\u9593\u306e\u9055\u3044\u306f\u3001\u4f7f\u308f\u308c\u3066\u3044\u308b\u9023\u7d61\u5148\u60c5\u5831\u3068\u507d\u306e\u30e6\u30fc\u30b6\u30fc\u30ec\u30d3\u30e5\u30fc\u3057\u304b\u3042\u308a\u307e\u305b\u3093\u3002<\/p>\n<p>\u3053\u308c\u3089\u8a50\u6b3a\u30b5\u30a4\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3068\u3001\u307e\u305a\u300c1996\u5e74\u304b\u3089\u55b6\u696d\u3057\u3066\u3044\u308b\u300d\u3068\u3044\u3046\u4e3b\u5f35\u306b\u7591\u554f\u304c\u308f\u304d\u307e\u3059\uff08\u56f311\u53c2\u7167\uff09\u3002\u4e21\u30c9\u30e1\u30a4\u30f3\u3068\u30821\u304b\u6708\u524d\u306b\u767b\u9332\u3055\u308c\u305f\u3070\u304b\u308a\u3067\u3001\u305d\u306e\u6642\u671f\u306f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u306e\u767a\u751f\u306e\u305d\u308c\u3068\u4e00\u81f4\u3057\u3066\u3044\u308b\u304b\u3089\u3067\u3059\u3002\u6b21\u306b\u3001\u56fd\u3068\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u60c5\u5831\u304c\u4e00\u81f4\u3057\u3066\u3044\u306a\u3044\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002\u30c9\u30e1\u30a4\u30f3\u540d\u306f\u30a4\u30f3\u30c9\u3067\u767b\u9332\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u30011\u3064\u306e\u30b5\u30a4\u30c8\u306e\u30a2\u30c9\u30ec\u30b9\u3068\u96fb\u8a71\u756a\u53f7\u306f\u30d5\u30e9\u30f3\u30b9\u306e\u3082\u306e\u3067\u3059\u3057\u3001\u3082\u30461\u3064\u306e\u30b5\u30a4\u30c8\u306f\u4f4f\u6240\u304c\u30c9\u30a4\u30c4\u306b\u306a\u3063\u3066\u3044\u308b\u306e\u306b\u96fb\u8a71\u756a\u53f7\u304c\u7c73\u56fd\u306e\u3082\u306e\u3067\u3059\u3002<\/p>\n<p>\u30c9\u30a4\u30c4\u306e\u4f4f\u6240\u300cMohrenstrasse 37 10117 Berlin\u300d\u3092\u691c\u7d22\u3059\u308b\u3068\u3001\u3053\u308c\u304c\u5b9f\u969b\u306b\u306f\u30d9\u30eb\u30ea\u30f3\u306b\u3042\u308b\u9023\u90a6\u53f8\u6cd5\u6d88\u8cbb\u8005\u4fdd\u8b77\u7701\u306e\u653f\u5e9c\u6a5f\u95a2\u306e\u5efa\u7269\u306e\u4f4f\u6240\u3067\u3042\u308b\u3053\u3068\u3082\u308f\u304b\u308a\u307e\u3059\u3002\u30d5\u30e9\u30f3\u30b9\u306e\u4f4f\u6240\u300c6 Rue Boreau, 49100 Angers, France\u300d\u306f\u304a\u305d\u3089\u304f\u306f\u500b\u4eba\u306e\u4f4f\u5b85\u3067\u3059\u3002<\/p>\n<p><figure id=\"attachment_106596\" aria-describedby=\"caption-attachment-106596\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-12.-allsurgicalfacemask.com-fake-testimonials.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106597 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-12.-allsurgicalfacemask.com-fake-testimonials.png\" alt=\"\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u8a50\u6b3a\u30b5\u30a4\u30c8\" width=\"600\" height=\"411\" \/><\/a><figcaption id=\"caption-attachment-106596\" class=\"wp-caption-text\">\u56f312 <span style=\"font-family: 'courier new', courier, monospace;\">allsurgicalfacemask[.]com<\/span>\u306e\u507d\u30e6\u30fc\u30b6\u30fc\u30ec\u30d3\u30e5\u30fc<\/figcaption><\/figure>\u3053\u308c\u3089\u306e\u6307\u6a19\u306b\u52a0\u3048\u3001\u304a\u7c97\u672b\u3067\u5358\u7d14\u3067\u6587\u4f53\u306b\u540c\u3058\u3088\u3046\u306a\u7656\u306e\u3042\u308b\u3001\u304a\u305d\u3089\u304f\u30b5\u30af\u30e9\u3068\u601d\u308f\u308c\u308b\u30e6\u30fc\u30b6\u30fc\u30ec\u30d3\u30e5\u30fc\u304c\u3069\u3061\u3089\u306e\u30da\u30fc\u30b8\u3067\u3082\u898b\u3064\u304b\u3063\u3066\u3044\u307e\u3059\uff08\u56f312\u53c2\u7167\uff09\u3002\u6700\u5f8c\u306e\u624b\u304c\u304b\u308a\u306fWhatsApp\u306e\u756a\u53f7\u300c+33 752 56 3071\u300d\u3092\u4f7f\u3063\u3066\u9023\u7d61\u3057\u3066\u307b\u3057\u3044\u3068\u3055\u308c\u3066\u3044\u308b\u70b9\u3067\u3059\u30021996\u5e74\u304b\u3089\u55b6\u696d\u3057\u3066\u3044\u308b\u3088\u3046\u306a\u307e\u3063\u3068\u3046\u306a\u4f01\u696d\u3067\u3042\u308c\u3070\u304a\u3088\u305d\u3042\u308a\u3048\u306a\u3044\u9023\u7d61\u624b\u6bb5\u3068\u3044\u3048\u307e\u3059\u3002<\/p>\n<p><figure id=\"attachment_106598\" aria-describedby=\"caption-attachment-106598\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-13.-selectsanitizer.com-user-reviews-from-before-the-domain-was-registered.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106599 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-13.-selectsanitizer.com-user-reviews-from-before-the-domain-was-registered.png\" alt=\"\u56f313\" width=\"600\" height=\"409\" \/><\/a><figcaption id=\"caption-attachment-106598\" class=\"wp-caption-text\">\u56f313 <span style=\"font-family: 'courier new', courier, monospace;\">selectsanitizer[.]com<\/span>\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u65e5\u4ee5\u524d\u304b\u3089\u5b58\u5728\u3059\u308b\u3053\u3068\u306b\u306a\u3063\u3066\u3044\u308b\u30e6\u30fc\u30b6\u30fc\u30ec\u30d3\u30e5\u30fc<\/figcaption><\/figure>\u6b21\u306b\u79c1\u305f\u3061\u306f<span style=\"font-family: 'courier new', courier, monospace;\">selectsanitizer[.]com<\/span>\u3067\u3001\u3082\u306f\u3084\u307b\u307c\u624b\u306b\u5165\u3089\u306a\u3044\u624b\u6307\u6d88\u6bd2\u6db2\u304c\u5272\u5f15\u4fa1\u683c\u3067\u5ba3\u4f1d\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u7a81\u304d\u6b62\u3081\u3001\u3055\u3089\u306b\u8abf\u67fb\u3092\u9032\u3081\u307e\u3057\u305f\u3002\u3053\u306e\u30b5\u30a4\u30c8\u3067\u8ca9\u58f2\u3055\u308c\u3066\u3044\u308b\u552f\u4e00\u306e\u5546\u54c1\u306b\u306f\u597d\u610f\u7684\u306a\u30e6\u30fc\u30b6\u30fc\u30ec\u30d3\u30e5\u30fc\u304c\u3064\u3044\u3066\u3044\u307e\u3059\u304c\u3001\u56f313\u306b\u793a\u3057\u305f\u3068\u304a\u308a\u3001\u672c\u30c9\u30e1\u30a4\u30f3\u306e\u767b\u9332\u306f2020\u5e743\u6708\u306b\u884c\u308f\u308c\u305f\u3070\u304b\u308a\u3067\u3059\u3002\u305d\u308c\u306b\u3082\u304b\u304b\u308f\u3089\u305a\u3001\u30e6\u30fc\u30b6\u30fc\u30ec\u30d3\u30e5\u30fc\u306e\u4e00\u90e8\u306f2019\u5e7411\u6708\u306b\u3055\u304b\u306e\u307c\u308b\u3082\u306e\u3067\u3057\u305f\u3002\u6700\u8fd1\u306e\u30ec\u30d3\u30e5\u30fc\u3067\u4f7f\u308f\u308c\u3066\u3044\u308b\u30c6\u30ad\u30b9\u30c8\u3092\u691c\u7d22\u3059\u308b\u3068\u3001\u3053\u308c\u3089\u306e\u30c6\u30ad\u30b9\u30c8\u304cAmazon\u306e\u30ec\u30d3\u30e5\u30fc\u306a\u3069\u3001\u624b\u6307\u6d88\u6bd2\u6db2\u3092\u8ca9\u58f2\u3057\u3066\u3044\u308b\u5225\u30b5\u30a4\u30c8\u304b\u3089\u30b3\u30d4\u30fc\u3055\u308c\u305f\u3082\u306e\u3067\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u6700\u5f8c\u306e\u624b\u304c\u304b\u308a\u306f\u3001EC\u30b5\u30a4\u30c8\u304c\u4f1a\u8a08\u6642\u306b\u5728\u5eab\u50c5\u5c11\u3067\u3042\u308b\u3068\u8b66\u544a\u3057\u3066\u30e6\u30fc\u30b6\u30fc\u3092\u7126\u3089\u305b\u3088\u3046\u3068\u3057\u305f\u70b9\u3067\u3059\u3002<\/p>\n<h4>\u30ab\u30fc\u30c9\u306e\u30b9\u30ad\u30df\u30f3\u30b0\u3092\u884c\u3046EC\u30b5\u30a4\u30c8<\/h4>\n<figure id=\"attachment_106603\" aria-describedby=\"caption-attachment-106603\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-14.-Example-of-a-pandemic-popular-store-with-an-embedded-card-skimmer-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106604 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-14.-Example-of-a-pandemic-popular-store-with-an-embedded-card-skimmer-1.png\" alt=\"\u56f314 \u30ab\u30fc\u30c9\u306e\u30b9\u30ad\u30df\u30f3\u30b0\u6a5f\u80fd\u3092\u57cb\u3081\u8fbc\u3093\u3060\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u3067\u95a2\u5fc3\u306e\u9ad8\u3044EC\u30b5\u30a4\u30c8\u306e\u4f8b\" width=\"600\" height=\"450\" \/><\/a><figcaption id=\"caption-attachment-106603\" class=\"wp-caption-text\">\u56f314 \u30d1\u30f3\u30c7\u30df\u30c3\u30af\u3067\u95a2\u5fc3\u306e\u9ad8\u307e\u3063\u3066\u3044\u308b\u507dEC\u30b5\u30a4\u30c8\u306e\u4f8b\u3002\u30ab\u30fc\u30c9\u306e\u30b9\u30ad\u30df\u30f3\u30b0\u6a5f\u80fd\u3092\u57cb\u3081\u8fbc\u3093\u3067\u3042\u308b<\/figcaption><\/figure>\n<p>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u4e0a\u3067\u306e\u602a\u3057\u3044\u8a50\u6b3aEC\u30b5\u30a4\u30c8\u306b\u52a0\u3048\u3001\u5225\u306eEC\u30b5\u30a4\u30c8\u3067\u306f\u3001\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u95a2\u9023\u5546\u54c1\u3092\u8ca9\u58f2\u3057\u3064\u3064\u3001web\u306b\u30b9\u30ad\u30df\u30f3\u30b0\u7528\u306e\u30b9\u30af\u30ea\u30d7\u30c8\uff08\u30b9\u30ad\u30de\u30fc\uff09\u3092\u57cb\u3081\u8fbc\u3093\u3067\u3044\u308b\u3053\u3068\u304c\u691c\u51fa\u3055\u308c\u307e\u3057\u305f\u3002\u305d\u3046\u3057\u305f\u30b9\u30c8\u30a2\u306e\u3072\u3068\u3064\u304c<span style=\"font-family: 'courier new', courier, monospace;\">www.sunrisepromos[.]com\/promotional-personal-care-accessories\/personalized-hand-sanitizer.html<\/span>\u3067\u3059\uff08\u56f314\u53c2\u7167\uff09\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u30b9\u30c8\u30a2\u306b\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u304c\u30af\u30ec\u30b8\u30c3\u30c8\u30ab\u30fc\u30c9\u691c\u8a3c\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u30a4\u30f3\u30b8\u30a7\u30af\u30c8\u3055\u308c\u3066\u304a\u308a\u3001\u30ad\u30fc\u30dc\u30fc\u30c9\u304b\u3089\u306e\u5165\u529b\u304c\u5b8c\u4e86\u3057\u305f\u3068\u305f\u3093\u30af\u30ec\u30b8\u30c3\u30c8\u30ab\u30fc\u30c9\u60c5\u5831\u304c\u9001\u4fe1\u3055\u308c\u3066\u3057\u307e\u3044\u307e\u3059\u3002\u633f\u5165\u3055\u308c\u3066\u3044\u308b\u30b9\u30cb\u30da\u30c3\u30c8\u3092\u56f315\u306b\u793a\u3057\u307e\u3059\u3002\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u30da\u30fc\u30b8\u304c\u8aad\u307f\u8fbc\u307e\u308c\u308b\u3068\u305d\u306eURL\u3092\u6b63\u898f\u8868\u73fe\u4e00\u89a7\u3068\u7167\u5408\u3059\u308b\u3053\u3068\u3067\u5bfe\u8c61\u30da\u30fc\u30b8\u304c\u6709\u52b9\u306a\u30c1\u30a7\u30c3\u30af\u30a2\u30a6\u30c8\u30da\u30fc\u30b8\u304b\u3069\u3046\u304b\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3001\u305d\u306e\u4e0a\u3067\u5165\u529b\u3055\u308c\u305f\u30af\u30ec\u30b8\u30c3\u30c8\u30ab\u30fc\u30c9\u756a\u53f7\u3092150\u30df\u30ea\u79d2\u3054\u3068\u306b\u5b9a\u671f\u7684\u306b\u53ce\u96c6\u30fb\u9001\u4fe1\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u95a2\u6570<span style=\"font-family: 'courier new', courier, monospace;\">send<\/span>\u304c\u547c\u3073\u51fa\u3055\u308c\u3001\u5165\u529b\u5185\u5bb9\u53ce\u96c6\u306e\u305f\u3081\u306b\u30d5\u30a9\u30fc\u30e0\u306e\u9001\u4fe1\u30a4\u30d9\u30f3\u30c8\u3068\u30dc\u30bf\u30f3\u30af\u30ea\u30c3\u30af\u30a4\u30d9\u30f3\u30c8\u306b\u30a4\u30d9\u30f3\u30c8\u30ea\u30b9\u30ca\u30fc\u304c\u8ffd\u52a0\u3055\u308c\u307e\u3059\u3002\u6b21\u306b\u3001\u53ce\u96c6\u3057\u305f\u60c5\u5831\u3092\u6b63\u898f\u8868\u73fe\u3068\u7167\u5408\u3057\u3066\u30af\u30ec\u30b8\u30c3\u30c8\u756a\u53f7\u3092\u78ba\u8a8d\u3057\u3066\u304b\u3089\u3001<span style=\"font-family: 'courier new', courier, monospace;\">\/js\/index.php<\/span>\u3068\u3044\u3046\u304a\u305d\u3089\u304f\u306f\u4fb5\u5bb3\u3055\u308c\u305f\u30d1\u30b9\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002\u3053\u3046\u3057\u305fweb\u30b5\u30a4\u30c8\u306fMagento\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3067\u958b\u767a\u3055\u308c\u3066\u3044\u308b\u306e\u3067\u3001\u3053\u308c\u3082Magecart\u30b9\u30ad\u30de\u30fc\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u306e\u4e00\u7a2e\u3067\u3042\u308b\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u30012016\u5e74\u306bMagento\u30e6\u30fc\u30b6\u30fc\u304c\u30ab\u30b9\u30bf\u30de\u30fc\u30d5\u30a9\u30fc\u30e9\u30e0\u3067<a href=\"https:\/\/community.magento.com\/t5\/Magento-1-x-Security-Patches\/Security-Issue-with-Magento-1-9-x-x-ccard-js\/td-p\/38562\">\u5831\u544a<\/a>\u3057\u305f\u305d\u308c\u3068\u3088\u304f\u4f3c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106605\" aria-describedby=\"caption-attachment-106605\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-15.-Credit-card-skimmer-code-found-on-several-websites-selling-pandemic-related-goods.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106606 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-15.-Credit-card-skimmer-code-found-on-several-websites-selling-pandemic-related-goods.png\" alt=\"\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u30af\u30ec\u30b8\u30c3\u30c8\u30ab\u30fc\u30c9\u30b9\u30ad\u30de\u30fc\u8a50\u6b3a\" width=\"600\" height=\"532\" \/><\/a><figcaption id=\"caption-attachment-106605\" class=\"wp-caption-text\">\u56f315 \u30d1\u30f3\u30c7\u30df\u30c3\u30af\u95a2\u9023\u5546\u54c1\u3092\u58f2\u308b\u8907\u6570\u306eEC\u30b5\u30a4\u30c8\u3067\u767a\u898b\u3055\u308c\u305f\u30af\u30ec\u30b8\u30c3\u30c8\u30ab\u30fc\u30c9\u7528\u30b9\u30ad\u30de\u30fc\u30b3\u30fc\u30c9<\/figcaption><\/figure>\n<h4>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3078\u306e\u6050\u6016\u5fc3\u3092\u98df\u3044\u7269\u306b\u3059\u308b\u60c5\u5831\u5546\u6750<\/h4>\n<p><figure id=\"attachment_106607\" aria-describedby=\"caption-attachment-106607\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-16.-survivecoronavirus.org-scaring-users-into-buying-their-survival-book.jpeg\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106608 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-16.-survivecoronavirus.org-scaring-users-into-buying-their-survival-book.jpeg\" alt=\"\u56f316 \u30e6\u30fc\u30b6\u30fc\u306e\u6050\u6016\u5fc3\u3092\u717d\u3063\u3066\u751f\u304d\u5ef6\u3073\u308b\u305f\u3081\u306e\u60c5\u5831\u5546\u6750\u3092\u8cb7\u308f\u305b\u3088\u3046\u3068\u3059\u308bsurvivecoronavirus[.]org\" width=\"600\" height=\"450\" \/><\/a><figcaption id=\"caption-attachment-106607\" class=\"wp-caption-text\">\u56f316 \u30e6\u30fc\u30b6\u30fc\u306e\u6050\u6016\u5fc3\u3092\u717d\u3063\u3066\u751f\u304d\u5ef6\u3073\u308b\u305f\u3081\u306e\u60c5\u5831\u5546\u6750\u3092\u8cb7\u308f\u305b\u3088\u3046\u3068\u3059\u308b<span style=\"font-family: 'courier new', courier, monospace;\">survivecoronavirus[.]org<\/span><\/figcaption><\/figure>\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u3082\u3064\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3078\u306e\u6050\u6016\u5fc3\u3092\u3055\u3089\u306b\u717d\u308b\u3053\u3068\u3067\u81ea\u5206\u305f\u3061\u306e\u96fb\u5b50\u66f8\u7c4d\u3092\u8cb7\u308f\u305b\u3088\u3046\u3068\u305f\u304f\u3089\u3080web\u30b5\u30a4\u30c8\u306e\u30b0\u30eb\u30fc\u30d7\u3082\u898b\u3064\u304b\u3063\u3066\u3044\u307e\u3059\uff08\u56f316\u53c2\u7167\uff09\u3002\u6700\u521d\u306b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u975e\u5e38\u306b\u6050\u308d\u3057\u3044\u72b6\u6cc1\u3084\u51fa\u6765\u4e8b\u306b\u3064\u3044\u3066\u306e\u4e0d\u7a4f\u306a\u30d3\u30c7\u30aa\u3092\u6d41\u3057\u3001\u6b21\u306b\u3053\u306e\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u3092\u751f\u304d\u6b8b\u308b\u305f\u3081\u306e\u9375\u3068\u3057\u3066\u96fb\u5b50\u66f8\u7c4d\u3092\u5ba3\u4f1d\u3057\u307e\u3059\u3002<\/p>\n<p>\u79c1\u305f\u3061\u306f\u3001\u3042\u308b<a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Feeding%20on%20Coronavirus%20Fears%20for%20Profit\">8\u3064\u306e\u30c9\u30e1\u30a4\u30f3<\/a>\u30b0\u30eb\u30fc\u30d7\u304c\u767b\u9332\u3055\u308c\u3066\u3053\u306e\u8a50\u6b3a\u306b\u95a2\u4e0e\u3057\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002\u5f53\u8a72\u30b0\u30eb\u30fc\u30d7\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">coronavirussecrets[.]com<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">pandemic-survival-coronavirus[.]com<\/span>\u306a\u3069\u304c\u542b\u307e\u308c\u307e\u3059\u304c\u3001\u96fb\u5b50\u66f8\u7c4d\u3092\u8cb7\u304a\u3046\u3068\u3059\u308b\u3068<span style=\"font-family: 'courier new', courier, monospace;\">buygoods[.]com<\/span>\u3068\u3044\u3046\u30b5\u30a4\u30c8\u306b\u98db\u3070\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30b5\u30a4\u30c8\u306b\u3064\u3044\u3066<a href=\"https:\/\/www.sandiegocan.org\/2018\/02\/01\/scam-alert-buygoods-sells-infoscam\/\">San Diego Consumers\u2019 Action Network\uff08\u30ab\u30ea\u30d5\u30a9\u30eb\u30cb\u30a2\u5dde\u30b5\u30f3\u30c7\u30a3\u30a8\u30b4\u306e\u6d88\u8cbb\u8005\u884c\u52d5\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\uff09<\/a>\u3084<a href=\"https:\/\/www.bbb.org\/us\/de\/wilmington\/profile\/online-retailer\/buygoods-inc-0251-92005844\/customer-reviews\">Better Business Bureau's\uff08\u7c73\u56fd\u304a\u3088\u3073\u30ab\u30ca\u30c0\u306e\u5546\u4e8b\u6539\u5584\u5354\u4f1a\uff09<\/a>\u3067\u30e6\u30fc\u30b6\u30fc\u304c\u8a55\u4fa1\u306e\u3044\u308a\u307e\u3058\u3063\u305f\u30ec\u30d3\u30e5\u30fc\u3092\u3064\u3051\u3066\u3044\u307e\u3059\u3002<a href=\"https:\/\/www.sandiegocan.org\/2018\/02\/01\/scam-alert-buygoods-sells-infoscam\/\">San Diego Consumers\u2019 Action Network<\/a>\u306f\u5f7c\u3089\u3092\u300c\u60c5\u5831\u5546\u6750\u8a50\u6b3a\u300d\u3068\u547c\u3073\u3001\u5f53\u8a72\u30b5\u30a4\u30c8\u3092\u300c\u8a50\u6b3a\u7684\u6226\u8853\u3092\u5229\u7528\u3057\u6d88\u8cbb\u8005\u306b\u8aa4\u89e3\u3092\u62db\u304f\u60c5\u5831\u3084\u865a\u507d\u306e\u60c5\u5831\u3092\u9ad8\u5024\u3067\u8ca9\u58f2\u3057\u3066\u3044\u308b\u30b5\u30a4\u30c8\u300d\u3068\u5b9a\u7fa9\u3057\u3066\u3044\u307e\u3059\u3002\u52a0\u3048\u3066\u3001\u591a\u304f\u306e\u30e6\u30fc\u30b6\u30fc\u304c\u652f\u6255\u3044\u3092\u3057\u305f\u5546\u54c1\u3092\u53d7\u3051\u53d6\u3063\u3066\u3044\u306a\u3044\u3068\u5831\u544a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h4>\u53e4\u5178\u7684\u8a50\u6b3a\u3092\u5e83\u3081\u308b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3<\/h4>\n<p><figure id=\"attachment_106609\" aria-describedby=\"caption-attachment-106609\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-17.-Example-of-a-technical-support-scam-page-on-covid19center.online.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106610 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-17.-Example-of-a-technical-support-scam-page-on-covid19center.online.png\" alt=\"\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u8a50\u6b3a\u306e\u30b5\u30f3\u30d7\u30eb\" width=\"600\" height=\"335\" \/><\/a><figcaption id=\"caption-attachment-106609\" class=\"wp-caption-text\">\u56f317 <span style=\"font-family: 'courier new', courier, monospace;\">covid19center[.]online<\/span>\u306e\u30c6\u30af\u30cb\u30ab\u30eb\u30b5\u30dd\u30fc\u30c8\u8a50\u6b3a\u30da\u30fc\u30b8\u306e\u4f8b<\/figcaption><\/figure>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u306e\u4eba\u6c17\u306f\u3001\u53e4\u5178\u7684\u306a\u8a50\u6b3a\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306b\u3082\u5229\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u79c1\u305f\u3061\u306f<span style=\"font-family: 'courier new', courier, monospace;\">coronavirusaware[.]xyz<\/span>\u3068<span style=\"font-family: 'courier new', courier, monospace;\">covid19center[.]online<\/span>\u3068\u304c\u3001\u3088\u304f\u77e5\u3089\u308c\u308b\u30c6\u30af\u30cb\u30ab\u30eb\u30b5\u30dd\u30fc\u30c8\u8a50\u6b3a\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u884c\u3063\u3066\u3044\u308b\u69d8\u5b50\u3092\u691c\u51fa\u3057\u307e\u3057\u305f\uff08\u56f317\u53c2\u7167\uff09\u3002\u904e\u53bb\u534a\u5e74\u3001\u3053\u306e\u8a50\u6b3a\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306f\u91cd\u8907\u306a\u3057\u306e\u5b9f\u6570\u30673,000\u4ef6\u3092\u8d85\u3048\u308b\u30c9\u30e1\u30a4\u30f3\u3084IP\u30a2\u30c9\u30ec\u30b9\u3067\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\uff08\u3053\u306e\u78ba\u8a8d\u306b\u306f<a href=\"https:\/\/github.com\/PaloAltoNetworks\/research-notes\/raw\/master\/papers\/Detecting%20malicious%20campaigns%20in%20obfuscated%20JavaScript%20with%20scalable%20behavior%20analytics.pdf\">\u3053\u3061\u3089\u306e\u30db\u30ef\u30a4\u30c8\u30da\u30fc\u30d1\u30fc\u3067<\/a>\u8aac\u660e\u3057\u305f\u632f\u308b\u821e\u3044\u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u4f7f\u3044\u307e\u3057\u305f\uff09\u3002\u653b\u6483\u8005\u306fweb\u3092\u95b2\u89a7\u3057\u3066\u3044\u308b\u30e6\u30fc\u30b6\u30fc\u3092\u6016\u304c\u3089\u305b\u3066\u81ea\u5206\u305f\u3061\u306b\u96fb\u8a71\u3092\u304b\u3051\u3055\u305b\u3001\u6700\u7d42\u7684\u306b\u306f\u8a50\u6b3a\u306e\u305f\u3081\u306e\u3084\u308a\u3068\u308a\u3092\u884c\u308f\u305b\u308b\u3053\u3068\u3092\u76ee\u7684\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u307b\u304b\u306e\u4f8b\u3068\u3057\u3066WhatsApp\u306e\u507d\u306e\u300c\u7121\u6599\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u300d\u8a50\u6b3a\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u3042\u3052\u3089\u308c\u307e\u3059\u3002\u3053\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u306f\u4ee5\u524d\u306f\u5225\u306eWhatsApp\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3092\u5229\u7528\u3057\u3066\u3044\u307e\u3057\u305f\uff08\u4f8b: <span style=\"font-family: 'courier new', courier, monospace;\">whatsapp[.]version[.]gratis<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">whatsapp[.]cc0[.]co<\/span>\uff09\u304c\u3001\u73fe\u5728\u306f<span style=\"font-family: 'courier new', courier, monospace;\">internet-covid19[.]xyz<\/span> \u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002\u8208\u5473\u6df1\u3044\u306e\u304c\u3001\u3053\u308c\u3089\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u304c\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u307e\u305f\u3044\u3067\u540c\u4e00\u306eGoogle Analytics ID <span style=\"font-family: 'courier new', courier, monospace;\">UA-108418953-1<\/span> \u3092\u5229\u7528\u3057\u3066\u3044\u308b\u70b9\u3067\u3059\uff08Google Analytics ID\u3092\u4f7f\u3063\u3066\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3092\u8ffd\u8de1\u3059\u308b\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306f<a href=\"https:\/\/github.com\/PaloAltoNetworks\/research-notes\/blob\/master\/papers\/Betrayed%20by%20Your%20Dashboard%20Discovering%20Malicious%20Campaigns%20via%20Web%20Analytics.pdf\">\u3053\u306e\u30da\u30fc\u30b8<\/a>\u3067\u78ba\u8a8d\u3067\u304d\u307e\u3059\uff09\u3002<\/p>\n<h4>\u9055\u6cd5\u85ac\u5c40<\/h4>\n<p><figure id=\"attachment_106611\" aria-describedby=\"caption-attachment-106611\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-18.-anticovid19-pharmacy.com-illicit-pharmacy.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106612 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-18.-anticovid19-pharmacy.com-illicit-pharmacy.png\" alt=\"\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306e\u9055\u6cd5\u306a\u85ac\u5c40\u8a50\u6b3a\" width=\"600\" height=\"399\" \/><\/a><figcaption id=\"caption-attachment-106611\" class=\"wp-caption-text\">\u56f318 <span style=\"font-family: 'courier new', courier, monospace;\">anticovid19-pharmacy[.]com<\/span>\u306e\u9055\u6cd5\u306a\u85ac\u5c40<\/figcaption><\/figure><a href=\"https:\/\/www.andrew.cmu.edu\/user\/nicolasc\/publications\/LMC-EC13.pdf\">\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u305f\u3061<\/a>\u306f\u9577\u5e74\u9055\u6cd5\u306a\u30aa\u30f3\u30e9\u30a4\u30f3\u85ac\u5c40\u306e\u8abf\u67fb\u3092\u884c\u3063\u3066\u304d\u307e\u3057\u305f\u304c\u3001\u79c1\u305f\u3061\u3082\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u30923\u3064\u542b\u3080\u3042\u308b\u30b0\u30eb\u30fc\u30d7\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u3067\u306f\u3001\u4f3c\u305f\u3088\u3046\u306a\u30aa\u30f3\u30e9\u30a4\u30f3\u85ac\u5c40\u30b5\u30a4\u30c8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u305d\u306e\u30c9\u30e1\u30a4\u30f3\u306f<span style=\"font-family: 'courier new', courier, monospace;\">covid19-remedy[.]com<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">rxcovid[.]com<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">anticovid19-pharmacy[.]com<\/span>\u306e3\u3064\u3067\u3059\u3002\u4f8b\u3092\u56f318\u306b\u793a\u3057\u307e\u3059\u3002<a href=\"https:\/\/www.usenix.org\/legacy\/event\/sec11\/tech\/full_papers\/Leontiadis.pdf\">\u540c\u3058\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u305f\u3061<\/a>\u304c\u300c\u3053\u308c\u3089\u306f\u7121\u8a8d\u53ef\u306e\u30aa\u30f3\u30e9\u30a4\u30f3\u85ac\u5c40\u3067\u3001\u4fb5\u5bb3\u3055\u308c\u305fweb\u30b5\u30a4\u30c8\u3092\u5229\u7528\u3057\u3066\u300echeap viagra\u300f\u306a\u3069\u306e\u30ad\u30fc\u30ef\u30fc\u30c9\u3092\u7d44\u307f\u5408\u308f\u305b\u3066\u691c\u7d22\u3057\u305f\u3055\u3044\u306e\u691c\u7d22\u30a8\u30f3\u30b8\u30f3\u3067\u306e\u8868\u793a\u7d50\u679c\u30e9\u30f3\u30ad\u30f3\u30b0\u3092\u3042\u3052\u3066\u3044\u308b\u300d\u3068\u8ad6\u3058\u3066\u3044\u307e\u3059\u3002\u3082\u3063\u3068\u60aa\u304f\u3059\u308c\u3070\u3053\u3046\u3057\u305f\u85ac\u5c40\u306f\u3001\u6f5c\u5728\u7684\u306b\u5371\u967a\u306a\u8aa4\u3063\u305f\u7528\u91cf\u306e\u85ac\u5264\u3092\u8ca9\u58f2\u3059\u308b\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002\u30c9\u30e1\u30a4\u30f3\u540d\u304b\u3089\u306f\u3053\u306e\u30aa\u30f3\u30e9\u30a4\u30f3\u85ac\u5c40\u304c\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u6cbb\u7642\u85ac\u3092\u8ca9\u58f2\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u3046\u304b\u304c\u308f\u308c\u308b\u3082\u306e\u306e\u3001\u305d\u3053\u3067\u306f\u4e3b\u306b\u30d0\u30a4\u30a2\u30b0\u30e9\u305d\u306e\u307b\u304b\u306e\u30a6\u30a4\u30eb\u30b9\u3068\u306f\u95a2\u4fc2\u306a\u3044\u85ac\u304c\u5ba3\u4f1d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306e\u30c8\u30ec\u30f3\u30c9\u3092\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO\u306b\u4e71\u7528<\/h3>\n<p>\u3042\u308b\u30c8\u30d4\u30c3\u30af\u306b\u95a2\u5fc3\u304c\u9ad8\u307e\u308c\u3070\u3001\u305d\u306e\u30c8\u30d4\u30c3\u30af\u3092\u5229\u7528\u3057\u3066web\u30b5\u30a4\u30c8\u306b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u96c6\u3081\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO\u3068\u306f\u3001\u7279\u5b9a\u30ad\u30fc\u30ef\u30fc\u30c9\u306b\u3088\u308b\u691c\u7d22\u30a8\u30f3\u30b8\u30f3\u306e\u691c\u7d22\u7d50\u679c\u4e0a\u4f4d\u306b\u7279\u5b9aweb\u30b5\u30a4\u30c8\u3092\u4eba\u70ba\u7684\u306b\u8868\u793a\u3055\u305b\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u4e00\u9023\u306e\u30c6\u30af\u30cb\u30c3\u30af\u306e\u3053\u3068\u3067\u3059\u3002<\/p>\n<p><figure id=\"attachment_106617\" aria-describedby=\"caption-attachment-106617\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-19.-coronavirus-latest-update.info-which-looks-like-a-coronavirus-informational-page-2.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106618 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-19.-coronavirus-latest-update.info-which-looks-like-a-coronavirus-informational-page-2.png\" alt=\"\u56f319\" width=\"600\" height=\"350\" \/><\/a><figcaption id=\"caption-attachment-106617\" class=\"wp-caption-text\">\u56f319 <span style=\"font-family: 'courier new', courier, monospace;\">coronavirus-latest-update[.]info<\/span>\u306e\u30da\u30fc\u30b8\u3002\u4e00\u898b\u3001\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u95a2\u9023\u3057\u305f\u60c5\u5831\u63d0\u4f9b\u30b5\u30a4\u30c8\u306b\u898b\u3048\u308b<\/figcaption><\/figure>\u79c1\u305f\u3061\u306f\u3001\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO\u306b\u5229\u7528\u3055\u308c\u308b9\u3064\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u3092\u542b\u3080\u30b0\u30eb\u30fc\u30d7\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u3059\u3079\u3066\u3001\u56f319\u306b\u793a\u3057\u305f<span style=\"font-family: 'courier new', courier, monospace;\">coronavirus-latest-update[.]info<\/span>\u306e\u3088\u3046\u306a\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306b\u95a2\u3059\u308b\u540c\u69d8\u306e\u60c5\u5831\u30da\u30fc\u30b8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3053\u308c\u3089\u306eweb\u30b5\u30a4\u30c8\u306f\u5b9f\u969b\u306b\u306f\u60c5\u5831\u63d0\u4f9b\u30da\u30fc\u30b8\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u307e\u305a\u3001\u30d3\u30c3\u30c8\u30b3\u30a4\u30f3\u30d9\u30fc\u30b9\u306e\u30aa\u30f3\u30e9\u30a4\u30f3\u30ab\u30b8\u30ce\u3067\u3042\u308b<span style=\"font-family: 'courier new', courier, monospace;\">sharkroulette[.]com<\/span>\u3078\u306e\u30ea\u30f3\u30af\u304c\u591a\u6570\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002\u3055\u3089\u306b\u3001coronavirus-com[.]info\u306b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3059\u308b\u3068\u3044\u3046\u30ea\u30f3\u30af\u3092\u30af\u30ea\u30c3\u30af\u3057\u3088\u3046\u3068\u3057\u3066\u3082\u3001\u30ea\u30f3\u30af\u4e0a\u306eJavaScript\u30aa\u30fc\u30d0\u30fc\u30ec\u30a4\u306b\u3088\u3063\u3066<span style=\"font-family: 'courier new', courier, monospace;\">sharkroulette[.]com<\/span>\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3055\u308c\u307e\u3059\u3002<\/p>\n<h3>\u7591\u308f\u3057\u3044\u30d1\u30fc\u30ad\u30f3\u30b0\u30da\u30fc\u30b8\u306e\u4e8b\u524d\u767b\u9332<\/h3>\n<p><figure id=\"attachment_106622\" aria-describedby=\"caption-attachment-106622\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-20.-Example-of-a-suspicious-parked-registration-on-coronavirus2day.com_-1.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106623 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-20.-Example-of-a-suspicious-parked-registration-on-coronavirus2day.com_-1.png\" alt=\"\u56f320\" width=\"600\" height=\"379\" \/><\/a><figcaption id=\"caption-attachment-106622\" class=\"wp-caption-text\">\u56f320 <span style=\"font-family: 'courier new', courier, monospace;\">coronavirus2day[.]com<\/span> \u306e\u4e0d\u5be9\u306a\u30d1\u30fc\u30ad\u30f3\u30b0\u767b\u9332\u4f8b<\/figcaption><\/figure>\u56f320\u306b\u793a\u3057\u305f\u3088\u3046\u306b\u3001\u65b0\u3057\u304f\u767b\u9332\u3055\u308c\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u3067\u306f\u3001\u4e0d\u5be9\u306a\u30d1\u30fc\u30ad\u30f3\u30b0\u30da\u30fc\u30b8\u304c\u591a\u6570\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u308b\u69d8\u5b50\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u540c\u3058\u7a2e\u985e\u306e\u30d1\u30fc\u30ad\u30f3\u30b0\u30da\u30fc\u30b8\u304c\u3001\u91cd\u8907\u306a\u3057\u306e\u5b9f\u6570\u3067200\u4ef6\u3092\u8d85\u3048\u308b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3092\u30c6\u30fc\u30de\u3068\u3057\u305f<a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Proactive%20Registrations%20of%20Suspicious%20Parked%20Pages\">\u30c9\u30e1\u30a4\u30f3<\/a>\u4e0a\u3067\u898b\u3064\u304b\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u3088\u3046\u306a\u30da\u30fc\u30b8\u306f\u3059\u3079\u3066\u3001\u89aa\u306b\u3042\u305f\u308bURL <span style=\"font-family: 'courier new', courier, monospace;\">http[:]\/\/cdn[.]dsultra[.]com\/js\/registrar.js<\/span>\u304b\u3089\u6f5c\u5728\u7684\u306b\u60aa\u610f\u306e\u3042\u308b\u53ef\u80fd\u6027\u306e\u9ad8\u3044JavaScript\u3092\u30ed\u30fc\u30c9\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u4e00\u90e8\u3092\u4ee5\u4e0b\u306b\u793a\u3057\u307e\u3059\u3002\u30da\u30fc\u30b8\u304c\u30ed\u30fc\u30c9\u3055\u308c\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">dL<\/span>\u95a2\u6570\u304c\u5b9f\u884c\u3055\u308c\u3001URL\u3001\u30ea\u30d5\u30a1\u30e9\u3001\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7\u3001cookie\u60c5\u5831\u306a\u3069\u3092<span style=\"font-family: 'courier new', courier, monospace;\">hashtag.sslproviders[.]net<\/span>\u306b\u9001\u4fe1\u3057\u307e\u3059\uff08\u306a\u304a\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30ea\u30ed\u30fc\u30c9\u3059\u308b\u3068\u7279\u5b9a\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u540d\u306b\u5909\u5316\u3059\u308b\u69d8\u5b50\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\uff09\u3002\u6b21\u306b<span style=\"font-family: 'courier new', courier, monospace;\">bL<\/span>\u95a2\u6570\u3067\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u30ea\u30c3\u30b9\u30f3\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">parent.top.window.location.href<\/span>\u306e\u5024\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u3067\u53d7\u4fe1\u3057\u305f\u4efb\u610f\u306e\u5b9b\u5148\u306b\u30e6\u30fc\u30b6\u30fc\u306e\u30d6\u30e9\u30a6\u30b6\u3092\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3057\u307e\u3059\u3002\u79c1\u305f\u3061\u304c\u89b3\u6e2c\u3057\u305f\u30b1\u30fc\u30b9\u306e\u591a\u304f\u306f\u3001\u30ec\u30b9\u30dd\u30f3\u30b9\u3067\u65b0\u3057\u3044\u5b9b\u5148URL\u3092\u53d7\u4fe1\u3057\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u81ea\u4f53\u306f\u6f5c\u5728\u7684\u306b\u60aa\u610f\u306e\u3042\u308b\u4efb\u610f\u306eURL\u30ea\u30c0\u30a4\u30ec\u30af\u30bf\u3068\u3057\u3066\u6a5f\u80fd\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_106625\" aria-describedby=\"caption-attachment-106625\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-21.-Partial-snippet-of-a-malicious-redirector-found-over-many-coronavirus-themed-parking-domains.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106626 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-21.-Partial-snippet-of-a-malicious-redirector-found-over-many-coronavirus-themed-parking-domains.png\" alt=\"\u56f321\" width=\"600\" height=\"334\" \/><\/a><figcaption id=\"caption-attachment-106625\" class=\"wp-caption-text\">\u56f321 \u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u591a\u304f\u306e\u30d1\u30fc\u30ad\u30f3\u30b0\u30c9\u30e1\u30a4\u30f3\u3067\u898b\u3064\u304b\u3063\u305f\u60aa\u610f\u306e\u3042\u308b\u30ea\u30c0\u30a4\u30ec\u30af\u30bf\u306e\u30b9\u30cb\u30da\u30c3\u30c8\uff08\u4e00\u90e8\uff09<\/figcaption><\/figure>\n<h3>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u306eIP\u30ed\u30ac\u30fc<\/h3>\n<p><figure id=\"attachment_106627\" aria-describedby=\"caption-attachment-106627\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-22.-coronavirus-game.ru-serving-IP-loggers.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106628 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-22.-coronavirus-game.ru-serving-IP-loggers.png\" alt=\"\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u8a50\u6b3a\u306e\u30b2\u30fc\u30e0\" width=\"600\" height=\"454\" \/><\/a><figcaption id=\"caption-attachment-106627\" class=\"wp-caption-text\">\u56f322 IP\u30ed\u30ac\u30fc\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3059\u308b<span style=\"font-family: 'courier new', courier, monospace;\">coronavirus-game[.]ru<\/span><\/figcaption><\/figure>\u5185\u5bb9\u306e\u5145\u5b9f\u3057\u305f\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u306eweb\u30b5\u30a4\u30c8\u306e\u306a\u304b\u306b\u306f\u3001\u4e0d\u5be9\u306a\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u308b\u3082\u306e\u3082\u3042\u308a\u307e\u3059\u3002\u305d\u3046\u3057\u305f\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u597d\u4f8b\u304cIP\u30ed\u30ac\u30fc\u3067\uff08\u4f8b: \u56f322\u306e<span style=\"font-family: 'courier new', courier, monospace;\">coronavirus-game[.]ru<\/span>\uff09\u3001\u540c\u30b5\u30a4\u30c8\u306b\u306f\u96e3\u8aad\u5316\u3055\u308c\u305f\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3001\u30e6\u30fc\u30b6\u30fc\u306eIP\u30a2\u30c9\u30ec\u30b9\u3092\u6b63\u5f53\u306aIP\u30ed\u30ae\u30f3\u30b0\u30b5\u30fc\u30d3\u30b9\u306e<span style=\"font-family: 'courier new', courier, monospace;\">iplogger[.]org<\/span>\u306b\u9001\u4fe1\u3059\u308b\u975e\u8868\u793a\u306eiframe\u3092\u30c9\u30ed\u30c3\u30d7\u3057\u307e\u3059\u3002<\/p>\n<h3>\uff08\u52d5\u4f5c\u3057\u3066\u3044\u306a\u3044\uff09\u30af\u30ea\u30d7\u30c8\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f7f\u7528\u3059\u308b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023web\u30b5\u30a4\u30c8<\/h3>\n<p><figure id=\"attachment_106629\" aria-describedby=\"caption-attachment-106629\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-23.-Unsuccessful-in-browser-cryptojacking-on-coronavirusinrealtime.com_.png\" rel=\"wpdevart_lightbox\"><img  class=\"wp-image-106630 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/04\/Figure-23.-Unsuccessful-in-browser-cryptojacking-on-coronavirusinrealtime.com_.png\" alt=\"\u56f323\" width=\"600\" height=\"306\" \/><\/a><figcaption id=\"caption-attachment-106629\" class=\"wp-caption-text\">\u56f323 <span style=\"font-family: 'courier new', courier, monospace;\">coronavirusinrealtime[.]com<\/span>\u306e\u30d6\u30e9\u30a6\u30b6\u5185\u30af\u30ea\u30d7\u30c8\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\uff08\u305f\u3060\u3057\u52d5\u4f5c\u306f\u3057\u3066\u3044\u306a\u3044\uff09<\/figcaption><\/figure>\u8208\u5473\u6df1\u3044\u3053\u3068\u306b\u3001<span style=\"font-family: 'courier new', courier, monospace;\">coronamasksupply[.]com<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">coronavirusinrealtime[.]com<\/span>\u306a\u3069\u306e\u65b0\u3057\u3044\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9web\u30b5\u30a4\u30c8\u306e\u591a\u304f\u306b\u306f\u3001\u300c\u52d5\u4f5c\u3057\u3066\u3044\u306a\u3044\u300d\u30d6\u30e9\u30a6\u30b6\u5185\u3067\u4eee\u60f3\u901a\u8ca8\uff08\u6697\u53f7\u901a\u8ca8\uff09\u306e\u30de\u30a4\u30cb\u30f3\u30b0\u3092\u884c\u3046\u30b3\u30fc\u30c9\u304c\u57cb\u3081\u8fbc\u307e\u308c\u3066\u3044\u307e\u3059\uff08\u56f323\u53c2\u7167\uff09\u3002\u307b\u3068\u3093\u3069\u306f\u53e4\u3044Coinhive\u30b5\u30fc\u30d3\u30b9\u3084\u5ec3\u6b62\u3055\u308c\u305fWebminerpool\u306a\u3044\u3057Crypto-Loot\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u305f\u3081\u3001\u5bfe\u5fdc\u3059\u308b\u30de\u30a4\u30cb\u30f3\u30b0\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u30ed\u30fc\u30c9\u306b\u5931\u6557\u3057\u305f\u308a\u3001\u3059\u3067\u306b\u30a2\u30af\u30c6\u30a3\u30d6\u3067\u306a\u304f\u306a\u3063\u305fweb\u30bd\u30b1\u30c3\u30c8\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3068\u306e\u63a5\u7d9a\u306e\u78ba\u7acb\u306b\u5931\u6557\u3057\u305f\u308a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\u3067\u306f\u30b3\u30fc\u30c9\u304c\u307e\u3060\u6a5f\u80fd\u3057\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3082\u305b\u305a\u3001\u53e4\u3044web\u30b5\u30a4\u30c8\u304b\u3089\u4ee5\u524d\u4f7f\u3063\u3066\u3044\u305f\u4fb5\u8972\u7684\u306a\u4eee\u60f3\u8ca8\u30de\u30a4\u30cb\u30f3\u30b0\u30b3\u30fc\u30c9\u3092\u30b3\u30d4\u30fc\u3057\u3066\u8cbc\u308a\u4ed8\u3051\u3066\u3044\u308b\u3060\u3051\u3067\u306f\u306a\u3044\u304b\u3068\u601d\u308f\u308c\u307e\u3059\u3002\u540c\u69d8\u306b\u3001\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u95a2\u9023\u60c5\u5831\u4eba\u6c17\u3092\u5229\u7528\u3057\u305f\u5185\u5bb9\u306e\u5145\u5b9f\u3057\u305fweb\u30da\u30fc\u30b8\u3067\u3082\u30af\u30ea\u30d7\u30c8\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u5b9f\u884c\u306b\u5931\u6557\u3057\u3001\u5ec3\u6b62\u3055\u308c\u305f\u30de\u30a4\u30cb\u30f3\u30b0\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306bWebSocket\u63a5\u7d9a\u3092\u3057\u3088\u3046\u3068\u3057\u3066\u30a8\u30e9\u30fc\u3092\u53d7\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3055\u3089\u306b\u79c1\u305f\u3061\u306f\u30d6\u30e9\u30a6\u30b6\u5185\u30af\u30ea\u30d7\u30c8\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u7528\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u30b5\u30f3\u30d7\u30eb\u3082\u898b\u3064\u3051\u307e\u3057\u305f\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u306f<span style=\"font-family: 'courier new', courier, monospace;\">coronashirts[.]store<\/span>\u4e0a\u306eJSE-coin\u306a\u3069\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u4fb5\u8972\u7684\u306a\u4eee\u60f3\u901a\u8ca8\u30de\u30a4\u30cb\u30f3\u30b0\u30d7\u30ed\u30b0\u30e9\u30e0\u306b\u3064\u3044\u3066\u8a73\u3057\u304f\u306f\u30011\u5e74\u524d\u306b\u516c\u958b\u3055\u308c\u305f<a href=\"https:\/\/unit42.paloaltonetworks.jp\/caught-in-the-act-from-intrusive-coin-miners-to-scam-websites\/\">\u3053\u3061\u3089\u306e\u30d6\u30ed\u30b0<\/a>\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u6b8b\u5ff5\u306a\u304c\u3089\u3001\u5730\u57df\u3084\u56fd\u3001\u4e16\u754c\u3067\u767a\u751f\u3059\u308b\u3055\u307e\u3056\u307e\u306a\u51fa\u6765\u4e8b\u3067\u9ad8\u307e\u3063\u305f\u4eba\u3005\u306e\u6050\u6016\u5fc3\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u306f\u5f8c\u3092\u305f\u3061\u307e\u305b\u3093\u3002\u79c1\u305f\u3061\u306f\u3053\u306e\u624b\u306e\u632f\u308b\u821e\u3044\u3092\u3053\u308c\u307e\u3067\u5e7e\u5ea6\u3082\u89b3\u6e2c\u3057\u3066\u304d\u3066\u3044\u307e\u3059\u3057\u3001\u4f55\u304b\u3057\u3089\u6050\u308d\u3057\u3044\u4e8b\u4ef6\u304c\u8d77\u304d\u308c\u3070\u3001\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u305f\u3061\u306f\u88ab\u5bb3\u8005\u306e\u5468\u56f2\u3092\u3046\u308d\u3064\u304d\u59cb\u3081\u307e\u3059\u3002\u60b2\u3057\u3044\u304b\u306a\u3001\u79c1\u305f\u3061\u306f\u3053\u3046\u3057\u305f\u3072\u3068\u306e\u5f31\u307f\u306b\u3064\u3051\u3053\u3080\u884c\u70ba\u304c\u305d\u306e\u3046\u3061\u3069\u3046\u306b\u304b\u306a\u308b\u3068\u306f\u8003\u3048\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<p>\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u306e\u30b1\u30fc\u30b9\u3067\u306f\u3001\u3053\u306e\u30d1\u30f3\u30c7\u30df\u30c3\u30af\u306b\u5bfe\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u95a2\u5fc3\u306e\u9ad8\u307e\u308a\u306b\u6bd4\u4f8b\u3057\u3001\u65e5\u3005\u767b\u9332\u3055\u308c\u308b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u30c9\u30e1\u30a4\u30f3\u6570\u304c\u6025\u5897\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u30022\u6708\u30683\u6708\u3092\u6bd4\u3079\u3001\u300c\u60aa\u610f\u306e\u3042\u308b\u300d\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u95a2\u9023\u65b0\u898f\u767b\u9332\u30c9\u30e1\u30a4\u30f3\uff08NRD\uff09\u306e1\u65e5\u3042\u305f\u308a\u306e\u5e73\u5747\u6570\u306f569\uff05\u5897\u52a0\u3057\u3001\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300d\u30c9\u30e1\u30a4\u30f3\u306f788\uff05\u5897\u52a0\u3057\u3066\u3044\u308b\u70b9\u304c\u6182\u616e\u3055\u308c\u307e\u3059\u30021\u67081\u65e5\u4ee5\u964d\u30012,022\u4ef6\u306e\u300c\u60aa\u610f\u306e\u3042\u308b\u300dNDR\u30684\u4e07261\u4ef6\u306e\u300c\u30cf\u30a4\u30ea\u30b9\u30af\u300dNRD\u304c\u7279\u5b9a\u3055\u308c\u307e\u3057\u305f\u304c\u3001\u3053\u308c\u3089\u306e\u30c9\u30e1\u30a4\u30f3\u540d\u306f\u307e\u305f\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03\u3001\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u653b\u6483\u3001\u8a50\u6b3a\u3001\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO\u306a\u3069\u3001\u3055\u307e\u3056\u307e\u306a\u60aa\u610f\u306e\u3042\u308b\u76ee\u7684\u306b\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>\u60c5\u5831\u3067\u3042\u308c\u3001\u691c\u67fb\u30ad\u30c3\u30c8\u3067\u3042\u308c\u3001\u6cbb\u7642\u6cd5\u3067\u3042\u308c\u3001\u305d\u306e\u4e3b\u5f35\u5185\u5bb9\u306e\u3044\u304b\u3093\u3092\u3068\u308f\u305a\u3001COVID-19\u3092\u30c6\u30fc\u30de\u3068\u3059\u308b\u96fb\u5b50\u30e1\u30fc\u30eb\u3084\u65b0\u3057\u304f\u767b\u9332\u3055\u308c\u305fweb\u30b5\u30a4\u30c8\u306b\u63a5\u3059\u308b\u3055\u3044\u306f\u3001\u8ab0\u3082\u304c\u3054\u304f\u614e\u91cd\u306b\u306a\u308b\u5fc5\u8981\u304c\u3042\u308b\u3067\u3057\u3087\u3046\u3002\u6b63\u5f53\u306a\u30c9\u30e1\u30a4\u30f3\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u306a\u3069\u3001\u30c9\u30e1\u30a4\u30f3\u540d\u306e\u6b63\u5f53\u6027\u3068\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u30c1\u30a7\u30c3\u30af\u306b\u306f\u3068\u304f\u306b\u6ce8\u610f\u3092\u6255\u3046\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\uff08\u305f\u3068\u3048\u3070google[.]com\u3067\u3042\u308b\u3079\u304d\u3068\u3053\u308d\u304cg00gle[.]com\u306b\u306a\u3063\u3066\u3044\u306a\u3044\u304b\u306a\u3069\uff09\u3002\u307e\u305f\u3001\u30d6\u30e9\u30a6\u30b6\u306eURL\u30d0\u30fc\u306e\u5de6\u306b\u30ed\u30c3\u30af\uff08\u9320\u524d\uff09\u306e\u30a2\u30a4\u30b3\u30f3\u304c\u3042\u308b\u304b\u3069\u3046\u304b\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3001HTTPS\u63a5\u7d9a\u304c\u6709\u52b9\u304b\u3069\u3046\u304b\u3082\u78ba\u8a8d\u3059\u3079\u304d\u3067\u3057\u3087\u3046\u3002COVID-19\u3092\u30c6\u30fc\u30de\u306b\u3057\u305f\u30e1\u30fc\u30eb\u306b\u3064\u3044\u3066\u3082\u540c\u69d8\u306e\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002\u9001\u4fe1\u8005\u306e\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u4e00\u77a5\u3057\u305f\u3060\u3051\u3067\u30b3\u30f3\u30c6\u30f3\u30c4\u304c\u6b63\u5f53\u3067\u306a\u3044\u53ef\u80fd\u6027\u304c\u9ad8\u3044\u3053\u3068\u304c\u308f\u304b\u308b\u30b1\u30fc\u30b9\u3082\u3042\u308a\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u53d7\u4fe1\u8005\u306e\u77e5\u3089\u306a\u3044\u5dee\u51fa\u4eba\u3060\u3068\u304b\u3001\u5dee\u51fa\u4eba\u306e\u30a2\u30c9\u30ec\u30b9\u306b\u30b9\u30da\u30eb\u30df\u30b9\u304c\u3042\u308b\u3068\u304b\u3001\u3080\u3084\u307f\u306b\u9577\u3044\u30e9\u30f3\u30c0\u30e0\u306a\u6587\u5b57\u5217\u306e\u5dee\u51fa\u4eba\u3067\u3042\u308b\u3001\u3068\u3044\u3063\u305f\u3053\u3068\u306f\u3088\u304f\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u30e6\u30fc\u30b6\u30fc\u3092\u30b5\u30a4\u30d0\u30fc\u72af\u7f6a\u8005\u304b\u3089\u4fdd\u8b77\u3059\u308b<a href=\"https:\/\/www.paloaltonetworks.com\/products\/threat-detection-and-prevention\/web-security\">URL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/a>\u306b\u95a2\u3059\u308b\u5f0a\u793e\u306e\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9\uff08\u63a8\u5968\u4e8b\u9805\uff09\u306f\u3001\u300cNewly Registered Domain\uff08\u65b0\u898f\u767b\u9332\u30c9\u30e1\u30a4\u30f3\uff09\u300d\u306e\u30ab\u30c6\u30b4\u30ea\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u30d6\u30ed\u30c3\u30af\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u306a\u304a\u3001\u3053\u306e\u30ab\u30c6\u30b4\u30ea\u306b\u5bfe\u3059\u308b\u30a2\u30af\u30bb\u30b9\u3092\u30d6\u30ed\u30c3\u30af\u3067\u304d\u306a\u3044\u5834\u5408\u306f\u3001\u3053\u306e\u30ab\u30c6\u30b4\u30ea\u306eURL\u306bSSL\u5fa9\u53f7\u5316\u3092\u9069\u7528\u3057\u3066\u53ef\u8996\u6027\u3092\u9ad8\u3081\u3001\u30e6\u30fc\u30b6\u30fc\u304cPowerShell\u3084\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u306a\u3069\u306e\u5371\u967a\u306a\u7a2e\u985e\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u306a\u3044\u3088\u3046\u306b\u3057\u3001\u3088\u308a\u53b3\u5bc6\u306a\u8105\u5a01\u9632\u6b62\u30dd\u30ea\u30b7\u30fc\u3092\u9069\u7528\u3057\u3066\u3001Newly Registered Domain\uff08\u65b0\u898f\u767b\u9332\u30c9\u30e1\u30a4\u30f3\uff09\u30ab\u30c6\u30b4\u30ea\u306e\u30c9\u30e1\u30a4\u30f3\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3055\u3044\u306e\u30ed\u30b0\u30ec\u30d9\u30eb\u3092\u3042\u3052\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002\u30de\u30eb\u30a6\u30a7\u30a2\u306e80\uff05\u4ee5\u4e0a\u304cDNS\u3092\u4f7f\u7528\u3057\u3066C2\u3092\u78ba\u7acb\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u3066\u3044\u307e\u3059\u306e\u3067\u3001<a href=\"https:\/\/www.paloaltonetworks.com\/products\/threat-detection-and-prevention\/dns-security\">DNS\u30ec\u30a4\u30e4\u30fc<\/a>\u306b\u3088\u308b\u4fdd\u8b77\u3082\u63a8\u5968\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u672c\u7a3f\u3067\u5177\u4f53\u7684\u306b\u8aac\u660e\u3057\u305f\u8105\u5a01\u3068IoC\u306b\u3064\u3044\u3066\u3001\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u306e\u30c6\u30af\u30ce\u30ed\u30b8\u306b\u3088\u308a\u3001\u3067\u304d\u308b\u304b\u304e\u308a\u6700\u9069\u306a\u691c\u51fa\u30fb\u9632\u6b62\u30e1\u30ab\u30cb\u30ba\u30e0\u3092\u78ba\u4fdd\u3067\u304d\u308b\u3088\u3046\u3001\u5f0a\u793e\u306f\u6b21\u306e\u5bfe\u7b56\u3092\u53d6\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul style=\"list-style-type: disc;\">\n<li>\u8a18\u8f09\u3055\u308c\u3066\u3044\u308b\u30c9\u30e1\u30a4\u30f3\u3001IP\u30a2\u30c9\u30ec\u30b9\u3001URL\u306f\u305d\u308c\u305e\u308c\u9069\u5207\u306a\u30ab\u30c6\u30b4\u30ea\u306b\u5206\u985e\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li>\u3059\u3079\u3066\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u3064\u3044\u3066WildFire&#x2122;\u3067\u306e\u5224\u5b9a\u304c\u66f4\u65b0\u30fb\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li>\u5bfe\u5fdc\u3059\u308b\u4fb5\u5165\u9632\u5fa1\u30b7\u30b9\u30c6\u30e0\u306e\u30b7\u30b0\u30cd\u30c1\u30e3\u304c\u4f5c\u6210\u30fb\u66f4\u65b0\u30fb\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li>Cortex XDR\u306b\u3088\u308b\u691c\u51fa\u304c\u914d\u5099\u30fb\u66f4\u65b0\u30fb\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li>Autofocus\u30bf\u30b0\u304c\u4f5c\u6210\u30fb\u66f4\u65b0\u30fb\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u7a81\u7136\u306e\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u30a2\u30a6\u30c8\u30d6\u30ec\u30a4\u30af\u306b\u3088\u308a\u3001\u591a\u304f\u306e\u5f93\u696d\u54e1\u304c\u81ea\u8eab\u3092\u9694\u96e2\u3057\u3066\u5728\u5b85\u52e4\u52d9\u3092\u884c\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u306e\u7d44\u7e54\u306f\u5e38\u306bVPN\u63a5\u7d9a\u3092\u4ecb\u3057\u3066\u5f93\u696d\u54e1\u306b\u5b89\u5168\u306a\u30a2\u30af\u30bb\u30b9\u3092\u63d0\u4f9b\u3057\u3066\u304d\u307e\u3057\u305f\u304c\u3001\u305d\u3046\u3057\u305f\u5b89\u5168\u306a\u30a2\u30af\u30bb\u30b9\u3092\u5fc5\u8981\u3068\u3059\u308b\u793e\u54e1\u306e\u6570\u304c\u3053\u308c\u307b\u3069\u5897\u3048\u305f\u3053\u3068\u306f\u3044\u307e\u3060\u304b\u3064\u3066\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u3053\u306e\u305f\u3081\u3001\u8ffd\u52a0\u306e\u30ea\u30bd\u30fc\u30b9\u3084\u5e2f\u57df\u5e45\u304c\u5fc5\u8981\u3068\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u304d\u3066\u3044\u307e\u3059\u3002\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u3067\u306f\u3053\u306e\u5bfe\u7b56\u3068\u3057\u3066\u3001<a href=\"https:\/\/www.paloaltonetworks.com\/prisma\/access\">Prisma Access<\/a>\u3092\u3054\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002Prisma Access\u306f\u3001\u30ea\u30e2\u30fc\u30c8\u30aa\u30d5\u30a3\u30b9\u3084\u30e2\u30d0\u30a4\u30eb\u30e6\u30fc\u30b6\u30fc\u306b\u4e00\u8cab\u3057\u305f\u30dd\u30ea\u30b7\u30fc\u306e\u9069\u7528\u3068\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u63d0\u4f9b\u3059\u308b\u3001\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u306e\u30bb\u30ad\u30e5\u30a2\u30a2\u30af\u30bb\u30b9\u30b5\u30fc\u30d3\u30b9\u30a8\u30c3\u30b8\uff08SASE\uff09\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3067\u3001\u30d3\u30b8\u30cd\u30b9\u30cb\u30fc\u30ba\u306e\u5909\u5316\u306b\u5fdc\u3058\u3001\u30b9\u30b1\u30fc\u30eb\u30a2\u30c3\u30d7\u3001\u30b9\u30b1\u30fc\u30eb\u30c0\u30a6\u30f3\u3092\u884c\u3046\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u304c\u30ea\u30e2\u30fc\u30c8\u306e\u5f93\u696d\u54e1\u306e\u305f\u3081\u306b\u3054\u63d0\u4f9b\u3067\u304d\u308b\u30b5\u30fc\u30d3\u30b9\u306b\u3064\u3044\u3066\u8a73\u3057\u304f\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.com\/our-response-to-covid-19\">\u3053\u3061\u3089\u306e<\/a>\u30ea\u30bd\u30fc\u30b9\u3092\u53c2\u7167\u3057<a href=\"https:\/\/register.paloaltonetworks.com\/securemobileworkforce\">BCP\uff08\u30d3\u30b8\u30cd\u30b9\u7d99\u7d9a\u6027\uff09\u3092\u9ad8\u3081\u308b\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306eNir Zuk\u306b\u3088\u308bweb\u30ad\u30e3\u30b9\u30c8<\/a>\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002<\/p>\n<h4>\u8b1d\u8f9e<\/h4>\n<p>\u5206\u6790\u306b\u5fc5\u8981\u306a\u30c7\u30fc\u30bf\u30bd\u30fc\u30b9\u306e\u4e00\u90e8\u3092\u3054\u63d0\u4f9b\u304f\u3060\u3055\u3063\u305fShawn Huang\u6c0f\u3001Wei Wang\u6c0f\u3001Tao Yan\u6c0f\u3001Wanjin Li\u6c0f\u3001\u672c\u7a3f\u306b\u52a9\u8a00\u3092\u3044\u305f\u3060\u304d\u3001\u5185\u5bb9\u306e\u6539\u5584\u306b\u3054\u5354\u529b\u3044\u305f\u3060\u3044\u305fDaiping Liu\u6c0f\u3001Kelvin Kwan\u6c0f\u3001Eddy Rivera\u6c0f\u3001Mark Karayan\u6c0f\u3001Zoltan Deak\u6c0f\u3001Jen Miller Osborn\u6c0f\u306b\u539a\u304f\u304a\u793c\u7533\u3057\u4e0a\u3052\u307e\u3059\u3002\u3042\u308a\u304c\u3068\u3046\u3054\u3056\u3044\u307e\u3057\u305f\u3002<\/p>\n<h4>IOC<\/h4>\n<p>\u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6:<br \/>\ncorona-masr21[.]com\/boa\/bankofamerica\/login.php<br \/>\ncorona-masr21[.]com\/apple-online<br \/>\ncorona-masr3[.]com\/CAZANOVA%20TRUE%20LOGIN%20SMART%202019\/<br \/>\ncorona-virusus[.]com<\/p>\n<p>\u8a50\u6b3a:<br \/>\nallsurgicalfacemask[.]com<br \/>\nsurgicalfacemaskpharmacyonline[.]com<br \/>\nselectsanitizer[.]com<br \/>\nsurvivecoronavirus[.]org<br \/>\nfacemasksus[.]com<br \/>\ncoronavirussecrets[.]com<br \/>\npandemic-survival-coronavirus[.]com<br \/>\n<span style=\"font-family: 'courier new', courier, monospace;\">internet-covid19.xyz<br \/>\n<\/span>coronavirusaware[.]xyz<br \/>\ncovid19center[.]online<br \/>\nWhatsapp[.]version[.]gratis<br \/>\nwhatsapp[.]cc0[.]co<\/p>\n<p>\u6697\u53f7\u901a\u8ca8\u30de\u30a4\u30cb\u30f3\u30b0\u30d7\u30ed\u30b0\u30e9\u30e0\uff08\u30b3\u30a4\u30f3\u30de\u30a4\u30ca\u30fc\uff09:<br \/>\ncoronamasksupply[.]com<br \/>\ncoronavirusinrealtime[.]com<br \/>\ncoronashirts[.]store<\/p>\n<p>\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO:<br \/>\ncoronavirus-latest-update[.]info<br \/>\ncoronavirus-com[.]info<br \/>\nsharkroulette[.]com<br \/>\nIllicit pharmacy:<br \/>\ncovid19-remedy[.]com<br \/>\nrxcovid[.]com<br \/>\nanticovid19-pharmacy[.]com<\/p>\n<p>\u305d\u306e\u4ed6\u306e\u4e0d\u5be9\u30c9\u30e1\u30a4\u30f3:<br \/>\ncoronavirus2day[.]com<br \/>\nhashtag.sslproviders[.]net<br \/>\ncoronavirus-game[.]ru<br \/>\n<span style=\"font-weight: 400;\">buygoods[.]com<\/span><\/p>\n<p>\u6b63\u898f\u306eIP\u30ed\u30ae\u30f3\u30b0\u30b5\u30fc\u30d3\u30b9:<br \/>\nIplogger[.]org<\/p>\n<p>\u914d\u5099\u3055\u308c\u3066\u3044\u305f\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u30ad\u30c3\u30c8:<br \/>\ncorona-masr4[.]com\/test.zip<br \/>\n07bc3abcb6f3a7f7ec38f088068f5cefc953111e066b4dddc35cf43e836b215e<br \/>\ncorona-virusus[.]com\/OwaOwaowa.zip<br \/>\nc77c5df13430db98d0eaac6e593fc28e90df3f1ef6c48f81cc5681c67f91b4a8<\/p>\n<p>\u4e00\u822c\u7684\u306aAndroid\u7528\u30c8\u30ed\u30a4\u306e\u6728\u99ac:<br \/>\ncoronaviruscovid19-information[.]com\/it\/corona.apk<br \/>\n3d30b7df52672307b20beb1deb7b3b18e06edca63a6583d92125cba8329da107<br \/>\ncoronaviruscovid19-information[.]com\/en\/corona.apk<br \/>\n1de6e6c140ff1b301b7df12d4b6388a21a6fbf0f141347dd2f9289740438a6d8<br \/>\ncorona-virusapps[.]com\/s1\/CoronaVirus-apps.apk<br \/>\na754c35dd09677b0b96d8a0dad5c9c5fdd28abd8cf2d8d38a9bd945ca8362e02<br \/>\ncorona-virusapps[.]com\/s2\/CoronaVirus-apps.apk<br \/>\nbca52647ce9f4900b754fcc0d8ef6329fb0229401e833534905969d10a82d839<br \/>\ncorona-virusapps[.]com\/s3\/CoronaVirus-apps.apk<br \/>\nc3096b341d6807a5a7d353f97554017a6242349b081837de60908081bcada1d0<\/p>\n<p>RedLine Stealer:<br \/>\ncovid-19-gov[.]com<br \/>\n45.142.212[.]126<br \/>\nc50c4cff782e1bb7171ffb04cb7c1ff69af47371e059bf300fed68949c77514c (hosted zip file)<br \/>\nf3b0aa7d9664258c9e1783289c4fc56e05b23e3eb9a3557f55733806564deb73 (payload)<\/p>\n<p>DanaBot:<br \/>\n202.195.34[.]6<br \/>\ncorona-map-data[.]com\/bin\/regsrtjser346.exe<br \/>\n44c7ef261a066790a4ce332afc634fb5f89f3273c0c908ec02ab666088b27757<br \/>\nNetSupportManagerRAT<br \/>\n5.181.156[.]14<br \/>\ncovidpreventandcure[.]com<br \/>\ncovidwhereandhow[.]xyz<br \/>\n1a08a65d4199f08d60644f2aee1182d87f29b36d38257239e5c80965ed65e0d1<\/p>\n<p>AzoRult:<br \/>\ncoronavirusstatus.space<br \/>\n2b35aa9c70ef66197abfb9bc409952897f9f70818633ab43da85b3825b256307<\/p>\n<p>\u30ea\u30c0\u30a4\u30ec\u30af\u30bf (registrar.js):<br \/>\ncoronavirus123[.]org (parent URL)<br \/>\ncovide19cleanse[.]com (parent URL)<br \/>\ncdn.dsultra[.]com\/js\/registrar.js<br \/>\nf6a46b22d26523d4db3dd78fa77c56d4e755aed942321751eda0f48955861ab9<\/p>\n<p>\u30b9\u30ad\u30de\u30fc (ccard.js):<br \/>\nwww.sunrisepromos[.]com\/promotional-personal-care-accessories\/personalized-hand-sanitizer.html (parent URL)<br \/>\nwww.sunrisepromos[.]com\/js\/lib\/ccard.js<br \/>\ne43bdc87269d0b9da7742049dd533db93579cf3126df433f08e8265edd09243e<\/p>\n<p><span style=\"font-weight: 400;\">\u5916\u90e8\u30ea\u30f3\u30af:<br \/>\n<\/span><span style=\"font-weight: 400;\">\u8a8d\u8a3c\u60c5\u5831\u7a83\u53d6\u3092\u884c\u3046\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u306eIoC: <\/span><a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Phishing%20User%20Credentials%20with%20Coronavirus%20Domains\"><span style=\"font-weight: 400;\">https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Phishing%20User%20Credentials%20with%20Coronavirus%20Domains<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">\u8a50\u6b3a\u30b5\u30a4\u30c8\u306eIoC:<br \/>\n<\/span><a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Feeding%20on%20Coronavirus%20Fears%20for%20Profit\"><span style=\"font-weight: 400;\">https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Feeding%20on%20Coronavirus%20Fears%20for%20Profit<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">\u30d6\u30e9\u30c3\u30af\u30cf\u30c3\u30c8SEO\u306eIoC:<br \/>\n<\/span><a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Abuse%20of%20Coronavirus%20Trends%20for%20Black%20Hat%20SEO\"><span style=\"font-weight: 400;\">https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Abuse%20of%20Coronavirus%20Trends%20for%20Black%20Hat%20SEO<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">\u4e0d\u5be9\u306a\u30c9\u30e1\u30a4\u30f3\u767b\u9332:<br \/>\n<\/span><a href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Proactive%20Registrations%20of%20Suspicious%20Parked%20Pages\"><span style=\"font-weight: 400;\">https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/COVID-19%20IOCs\/Proactive%20Registrations%20of%20Suspicious%20Parked%20Pages<\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306e\u4e16\u754c\u7684\u5e83\u307e\u308a\u3092\u53d7\u3051\u3001\u305d\u306e\u95a2\u9023\u30c8\u30d4\u30c3\u30af\u3078\u306e\u95a2\u5fc3\u304c\u9ad8\u307e\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306b\u3068\u3082\u306a\u30442\u6708\u521d\u3081\u4ee5\u964d\u3001\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30c1\u30fc\u30e0Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u540c\u611f\u67d3\u75c7\u95a2\u9023\u306eG<\/p>\n","protected":false},"author":341,"featured_media":134312,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[4689,5888,4519,4799],"product_categories":[4444,4343,4448,4457],"coauthors":[2288,1434,1296,647,1318],"class_list":["post-106698","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-botnet-ja","tag-covid","tag-phishing-ja","tag-scams-ja","product_categories-advanced-wildfire-ja","product_categories-cortex-xdr","product_categories-cortex-xdr-ja","product_categories-prisma-access-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316<\/title>\n<meta name=\"description\" content=\"\u6982\u8981\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316\" \/>\n<meta property=\"og:description\" content=\"\u6982\u8981\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-24T04:00:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-05-19T04:06:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Hactivism_Overview_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janos Szurdi, Zhanhao Chen, Oleksii Starov, Netanel Rimer, Adrian McCabe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316","description":"\u6982\u8981","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/","og_locale":"ja_JP","og_type":"article","og_title":"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316","og_description":"\u6982\u8981","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/","og_site_name":"Unit 42","article_published_time":"2020-04-24T04:00:09+00:00","article_modified_time":"2020-05-19T04:06:15+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Hactivism_Overview_1920x900.jpg","type":"image\/jpeg"}],"author":"Janos Szurdi, Zhanhao Chen, Oleksii Starov, Netanel Rimer, Adrian McCabe","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/"},"author":{"name":"Janos Szurdi","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/11ddae04caa753b17880bdd58902d0e9"},"headline":"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316","datePublished":"2020-04-24T04:00:09+00:00","dateModified":"2020-05-19T04:06:15+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/"},"wordCount":1180,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Hactivism_Overview_1920x900.jpg","keywords":["botnet","COVID","phishing","Scams"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/","name":"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Hactivism_Overview_1920x900.jpg","datePublished":"2020-04-24T04:00:09+00:00","dateModified":"2020-05-19T04:06:15+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/11ddae04caa753b17880bdd58902d0e9"},"description":"\u6982\u8981","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Hactivism_Overview_1920x900.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Hactivism_Overview_1920x900.jpg","width":1920,"height":900,"caption":"A digital artwork depicting a futuristic city integrated with a circuit board, highlighting a blend of urban architecture and technology, illuminated by vibrant, warm lights against a backdrop of a blurred city skyline."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/how-cybercriminals-prey-on-the-covid-19-pandemic\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u65b0\u578b\u30b3\u30ed\u30ca\u30a6\u30a4\u30eb\u30b9\u611f\u67d3\u75c7\u306b\u3064\u3051\u3053\u3080\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u305f\u3061\uff1a\u95a2\u5fc3\u306e\u9ad8\u3044\u30c9\u30e1\u30a4\u30f3\u540d\u767b\u9332\u3067\u53ce\u76ca\u5316"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/11ddae04caa753b17880bdd58902d0e9","name":"Janos Szurdi","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Janos Szurdi"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/janos-szurdi\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/341"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=106698"}],"version-history":[{"count":27,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106698\/revisions"}],"predecessor-version":[{"id":107311,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/106698\/revisions\/107311"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134312"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=106698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=106698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=106698"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=106698"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=106698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}