{"id":116757,"date":"2021-01-19T06:00:17","date_gmt":"2021-01-19T14:00:17","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=116757"},"modified":"2025-08-25T04:28:14","modified_gmt":"2025-08-25T11:28:14","slug":"wireshark-tutorial-emotet-infection","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/","title":{"rendered":"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb"},"content":{"rendered":"<h2>\u6982\u8981<\/h2>\n<p>\u672c\u30b7\u30ea\u30fc\u30ba\u306f\u3001\u7591\u308f\u3057\u3044\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u8abf\u67fb\u3084\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30d1\u30b1\u30c3\u30c8\u30ad\u30e3\u30d7\u30c1\u30e3\uff08pcap\uff09\u306e\u78ba\u8a8d\u3092\u696d\u52d9\u3067\u884c\u3063\u3066\u304a\u3089\u308c\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c02\u9580\u5bb6\u3092\u8aad\u8005\u3068\u3057\u3066\u60f3\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u305f\u3081\u672c\u7a3f\u3067\u306e\u624b\u9806\u8aac\u660e\u306f\u8aad\u8005\u306e\u7686\u3055\u3093\u304c<a href=\"https:\/\/www.wireshark.org\/\">Wireshark<\/a>\u306e\u4f7f\u3044\u304b\u305f\u3092\u3054\u5b58\u77e5\u3067\u3042\u308b\u3053\u3068\u3092\u524d\u63d0\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001\u672c\u7a3f\u306b\u3066\u5229\u7528\u3059\u308bWireshark\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u4e3b\u306b3.x\u3068\u306a\u308a\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.emotet\">Emotet<\/a>\u306f\u60c5\u5831\u7a83\u53d6\u578b\u306e\u30de\u30eb\u30a6\u30a7\u30a2 (\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9) \u3067\u3001\u30d0\u30f3\u30ad\u30f3\u30b0\u30de\u30eb\u30a6\u30a7\u30a2\u3068\u3057\u3066<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-banking-malware-uses-network-sniffing-for-data-theft\/\">2014\u5e74\u306b\u6700\u521d\u306b\u5831\u544a\u3055\u308c\u307e\u3057\u305f<\/a>\u3002\u305d\u308c\u4ee5\u6765\u3001\u30c9\u30ed\u30c3\u30d1\u306a\u3069\u306e\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u3066\u9032\u5316\u3092\u304b\u3055\u306d\u3001<a href=\"https:\/\/isc.sans.edu\/forums\/diary\/Emotet+infections+and+followup+malware\/24532\/\">Gootkit<\/a>\u3001<a href=\"https:\/\/www.malware-traffic-analysis.net\/2019\/01\/18\/index.html\">IcedID<\/a>\u3001<a href=\"https:\/\/www.malware-traffic-analysis.net\/2020\/08\/10\/index.html\">Qakbot<\/a>\u3001<a href=\"https:\/\/twitter.com\/Unit42_Intel\/status\/1320847745155059712\">Trickbot<\/a>\u306a\u3069\u3001\u307b\u304b\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u3092\u914d\u5e03\u3059\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u304d\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u4eca\u56de\u306e\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u3067\u306f\u3001Emotet\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u78ba\u8a8d\u3057\u3001\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u5206\u6790\u304b\u3089\u672c\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u7279\u5b9a\u3059\u308b\u306e\u306b\u5f79\u7acb\u3064\u30d2\u30f3\u30c8\u3092\u63d0\u4f9b\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<p><strong>\u6ce8\u610f:<\/strong> \u672c\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u306f\u3001\u4ee5\u524d\u306e\u300e<a href=\"https:\/\/unit42.paloaltonetworks.jp\/unit42-customizing-wireshark-changing-column-display\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea71: Wireshark\u306e\u8868\u793a\u5217\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3059\u308b<\/a>\u300f\u3067\u8a2d\u5b9a\u3057\u305f\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u6e08\u307f\u306e\u5217\u8868\u793a\u3092\u4f7f\u3044\u307e\u3059\u3002\u307e\u305f\u3001<a href=\"https:\/\/github.com\/pan-unit42\/wireshark-tutorial-Emotet-traffic\">\u672c\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u4f7f\u3046pcap\u30d5\u30a1\u30a4\u30eb\u306e\u5165\u3063\u305fZIP\u30a2\u30fc\u30ab\u30a4\u30d6<\/a>\u3092\u683c\u7d0d\u3057\u3066\u3044\u308bGithub\u30ea\u30dd\u30b8\u30c8\u30ea\u304b\u3089\u30b5\u30f3\u30d7\u30eb\u30d5\u30a1\u30a4\u30eb\u3092\u3042\u3089\u304b\u3058\u3081\u53d6\u5f97\u3057\u3066\u304a\u3044\u3066\u304f\u3060\u3055\u3044\u3002\u89e3\u51cd\u7528\u30d1\u30b9\u30ef\u30fc\u30c9\u306f\u300cinfected\u300d\u3067\u3059\u3002<\/p>\n<p><strong>\u6ce8\u610f: <\/strong>\u672c\u7a3f\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u306b\u5229\u7528\u3059\u308bpcap\u30d5\u30a1\u30a4\u30eb\u306fWindows\u3067\u52d5\u4f5c\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u542b\u3093\u3067\u3044\u307e\u3059\u3002\u3057\u305f\u304c\u3063\u3066\u3001Windows\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u3092\u4f7f\u3063\u3066\u3044\u308b\u5834\u5408\u611f\u67d3\u30ea\u30b9\u30af\u304c\u3042\u308a\u307e\u3059\u3002\u3067\u304d\u308b\u304b\u304e\u308a BSD\u7cfb\u3001Linux\u7cfb\u3001macOS\u306a\u3069\u3001Windows\u74b0\u5883\u4ee5\u5916\u306e\u74b0\u5883\u3067pcap\u30d5\u30a1\u30a4\u30eb\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/p>\n<h2>Emotet\u306b\u3088\u308b\u611f\u67d3\u30a4\u30d9\u30f3\u30c8 \u30c1\u30a7\u30fc\u30f3<\/h2>\n<p>Emotet\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u7406\u89e3\u3059\u308b\u306b\u306f\u3001\u611f\u67d3\u306b\u3064\u306a\u304c\u308b\u4e00\u9023\u306e\u30a4\u30d9\u30f3\u30c8\u3092\u7406\u89e3\u3057\u3066\u304a\u304f\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002Emotet\u306f\u305f\u3044\u3066\u3044\u60aa\u610f\u306e\u3042\u308b\u30b9\u30d1\u30e0\uff08\u30de\u30eb\u30b9\u30d1\u30e0\uff09\u3092\u4ecb\u3057\u3066\u914d\u5e03\u3055\u308c\u3066\u304a\u308a\u3001\u8106\u5f31\u306aWindows\u30db\u30b9\u30c8\u306b\u611f\u67d3\u3059\u308b\u3088\u3046\u306b\u8a2d\u8a08\u3055\u308c\u305f\u30de\u30af\u30ed\u3092\u542b\u3080Microsoft Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u304c\u305d\u306e\u611f\u67d3\u30c1\u30a7\u30fc\u30f3\u306e\u91cd\u8981\u30b9\u30c6\u30c3\u30d7\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116676\" class=\"wp-caption aligncenter\" style=\"width: 900px;\" aria-describedby=\"caption-attachment-116676\"><figure id=\"attachment_116677\" aria-describedby=\"caption-attachment-116677\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116677 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-30.jpeg\" alt=\"\u3053\u3053\u306b\u793a\u3057\u305fWord\u6587\u66f8\u306f\u30012021\u5e741\u6708\u306bEmotet\u611f\u67d3\u3092\u5f15\u304d\u8d77\u3053\u3059\u306e\u306b\u4f7f\u7528\u3055\u308c\u305f\u3082\u306e\u3067\u3059\u3002\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306b\u6ce8\u610f\u3057\u3066\u304f\u3060\u3055\u3044\u300cThis document is protected. (\u3053\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306f\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002)Previewing is not available for protected documents. (\u4fdd\u8b77\u3055\u308c\u305f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3067\u306f\u30d7\u30ec\u30d3\u30e5\u30fc\u3092\u5229\u7528\u3067\u304d\u307e\u305b\u3093\u3002)You have to press &quot;ENABLE EDITING&quot; and &quot;ENABLE CONTENT&quot; buttons to preview this document. (\u3053\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u30d7\u30ec\u30d3\u30e5\u30fc\u3059\u308b\u306b\u306f\u3001[ENABLE EDITING (\u7de8\u96c6\u3092\u6709\u52b9\u306b\u3059\u308b)]\u30dc\u30bf\u30f3\u3068[ENABLE CONTENT (\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u6709\u52b9\u306b\u3059\u308b)]\u30dc\u30bf\u30f3\u3092\u62bc\u3059\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002) \" width=\"900\" height=\"734\" \/><figcaption id=\"caption-attachment-116677\" class=\"wp-caption-text\">\u56f31 2021\u5e741\u6708\u306bEmotet\u611f\u67d3\u3092\u5f15\u304d\u8d77\u3053\u3059\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u305fWord\u6587\u66f8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3002<\/figcaption><\/figure><figcaption id=\"caption-attachment-116676\" class=\"wp-caption-text\"><\/figcaption><\/figure>\n<p>Emotet\u3092\u62e1\u6563\u3055\u305b\u308b\u30de\u30eb\u30b9\u30d1\u30e0\u306f\u3055\u307e\u3056\u307e\u306a\u624b\u6cd5\u3067\u3053\u308c\u3089Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u914d\u5e03\u3057\u307e\u3059\u3002<\/p>\n<p>\u30de\u30eb\u30b9\u30d1\u30e0\u306b\u306f\u3001\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u3068\u3057\u3066Microsoft Word\u6587\u66f8\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u5834\u5408\u3082\u3042\u308c\u3070\u3001Word\u6587\u66f8\u3092\u542b\u3080\u6dfb\u4ed8ZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u5834\u5408\u3082\u3042\u308a\u307e\u3059\u3002\u3053\u3053\u6570\u30f6\u6708\u3067\u306f\u3001\u3053\u308c\u3089ZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u304c\u30d1\u30b9\u30ef\u30fc\u30c9\u3067\u4fdd\u8b77\u3055\u308c\u3066\u3044\u308b\u4f8b\u304c\u8907\u6570\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002Emotet\u3092\u914d\u5e03\u3059\u308b\u96fb\u5b50\u30e1\u30fc\u30eb\u306e\u306a\u304b\u306b\u306f\u3001\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u304c\u306a\u3044\u3082\u306e\u3082\u3042\u308a\u3001\u305d\u306e\u5834\u5408\u304b\u308f\u308a\u306bWord\u6587\u66f8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u30ea\u30f3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u904e\u53bb\u6570\u5e74\u9593\u3001Emotet\u3092\u30d7\u30c3\u30b7\u30e5\u3059\u308b\u30de\u30eb\u30b9\u30d1\u30e0\u306f\u3001\u3053\u308c\u3089\u306eEmotet Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u914d\u4fe1\u3059\u308b\u76ee\u7684\u3067\u3001\u30ea\u30f3\u30af\u3092\u57cb\u3081\u8fbc\u3093\u3060PDF\u6dfb\u4ed8\u30d5\u30a1\u30a4\u30eb\u3082\u4f7f\u7528\u3057\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u56f32\u306b\u3053\u308c\u30894\u3064\u306e\u914d\u5e03\u624b\u6cd5\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116678\" aria-describedby=\"caption-attachment-116678\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116679 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-31.jpeg\" alt=\"Emotet \u306b\u3088\u308b Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u914d\u5e03\u7d4c\u8def\u30021\uff09Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u304c\u6dfb\u4ed8\u3055\u308c\u305f\u30de\u30eb\u30b9\u30d1\u30e0\u3002 2\uff09Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306eZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u304c\u6dfb\u4ed8\u3055\u308c\u305f\u30de\u30eb\u30b9\u30d1\u30e0\u3002 3\uff09Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308bWeb\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3078\u306e\u30ea\u30f3\u30af\u3092\u542b\u3080\u30de\u30eb\u30b9\u30d1\u30e0\u3002 4\uff09Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308bWeb\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u542b\u3081\u305fPDF\u30d5\u30a1\u30a4\u30eb\u6dfb\u4ed8\u3057\u305f\u30de\u30eb\u30b9\u30d1\u30e0\u3002\" width=\"900\" height=\"870\" \/><figcaption id=\"caption-attachment-116678\" class=\"wp-caption-text\">\u56f32 Emotet\u7528Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u3055\u307e\u3056\u307e\u306a\u914d\u5e03\u7d4c\u8def<\/figcaption><\/figure>\n<p>Word\u6587\u66f8\u306e\u914d\u4fe1\u5f8c\u3001\u88ab\u5bb3\u8005\u304c\u6587\u66f8\u3092\u958b\u304d\u3001\u8106\u5f31\u306aWindows\u30db\u30b9\u30c8\u4e0a\u3067\u30de\u30af\u30ed\u3092\u6709\u52b9\u306b\u3057\u305f\u5834\u5408\u3001\u305d\u306e\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u306fEmotet\u306b\u611f\u67d3\u3057\u307e\u3059\u3002<\/p>\n<p>\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u89b3\u70b9\u3067\u307f\u308b\u3068\u3001Emotet\u7528Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u304b\u3089Emotet\u611f\u67d3\u3078\u3044\u305f\u308b\u30b9\u30c6\u30c3\u30d7\u306f\u6b21\u306e\u3088\u3046\u306a\u3082\u306e\u3067\u3042\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u521d\u671f\u30d0\u30a4\u30ca\u30ea\u3092\u53d6\u5f97\u3059\u308bWeb\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<li>HTTP\u306b\u3088\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u306a\u3044\u3057\u6697\u53f7\u5316\u3055\u308c\u305f\u30b3\u30de\u30f3\u30c9&amp;\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\uff08C2\uff09\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<li>Emotet\u304c\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30c9\u30ed\u30c3\u30d7\u3057\u3066\u304f\u308b\u5834\u5408\u306f\u8ffd\u52a0\u306e\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<li>Emotet\u304c\u611f\u67d3\u30db\u30b9\u30c8\u3092\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u3068\u3057\u3066\u4f7f\u7528\u3059\u308b\u5834\u5408\u306fSMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<\/ul>\n<p>\u56f33\u306fEmotet\u3078\u306e\u611f\u67d3\u3067\u691c\u51fa\u3055\u308c\u308b\u3053\u3068\u306e\u3042\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u30d5\u30ed\u30fc\u30c1\u30e3\u30fc\u30c8\u306b\u3057\u305f\u3082\u306e\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_116680\" aria-describedby=\"caption-attachment-116680\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116681 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-32.jpeg\" alt=\"Emotet\u611f\u67d3\u30d5\u30ed\u30fc\u30c1\u30e3\u30fc\u30c8: Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8 \u2192 \u30de\u30af\u30ed\u306e\u6709\u52b9\u5316 \u2192 \u521d\u671f\u30d0\u30a4\u30ca\u30ea\u3092\u8981\u6c42\u3059\u308bWeb\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3002\u305d\u3053\u304b\u3089\u3001HTTP\u306b\u3088\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3002\u3053\u3053\u304c\u611f\u67d3\u30d5\u30ed\u30fc\u30c1\u30e3\u30fc\u30c8\u3067\u306e\u30cf\u30d6\u3068\u306a\u3063\u3066\u3001\u3053\u306e\u5f8c\u306e\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7\u30de\u30eb\u30a6\u30a7\u30a2\u3001\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3001\u30c7\u30fc\u30bf\u6f0f\u51fa\u3001\u30d0\u30a4\u30ca\u30ea\u306e\u66f4\u65b0\u306b\u3064\u306a\u304c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b \" width=\"900\" height=\"452\" \/><figcaption id=\"caption-attachment-116680\" class=\"wp-caption-text\">\u56f33 Emotet\u306e\u611f\u67d3\u30d5\u30ed\u30fc\u30c1\u30e3\u30fc\u30c8<\/figcaption><\/figure>\n<p>2020\u5e7412\u670821\u65e5\u4ee5\u964d\u3001Emotet\u306e\u521d\u671f\u30d0\u30a4\u30ca\u30ea\u306fWindowsDLL\u30d5\u30a1\u30a4\u30eb\u3067\u3057\u305f\u3002\u305d\u308c\u4ee5\u524d\u306e\u30d0\u30a4\u30ca\u30ea\u306fWindows \u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb (EXE) \u3067\u3057\u305f\u3002<\/p>\n<p>Emotet\u306eC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u3001HTTP\u3092\u4ecb\u3057\u3066\u9001\u4fe1\u3055\u308c\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u306a\u3044\u3057\u6697\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306eC2\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306fHTTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u6a19\u6e96\u30fb\u975e\u6a19\u6e96\u306eTCP\u30dd\u30fc\u30c8\u3092\u4f7f\u3046\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306eC2\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u3053\u306e\u307b\u304b\u3001\u30c7\u30fc\u30bf\u6f0f\u51fa\u3084\u3001\u521d\u671fEmotet\u30d0\u30a4\u30ca\u30ea\u66f4\u65b0\u306e\u305f\u3081\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3082\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>Emotet\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u30c9\u30ed\u30c3\u30d1\u3067\u3082\u3042\u308b\u306e\u3067\u3001\u88ab\u5bb3\u8005\u306f\u4ed6\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u3082\u611f\u67d3\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u30a2\u30ca\u30ea\u30b9\u30c8\u306f\u3001Emotet\u611f\u67d3\u30db\u30b9\u30c8\u304b\u3089\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u8abf\u67fb\u3059\u308b\u306b\u3042\u305f\u308a\u3001\u4ed6\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u304b\u3089\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u3064\u3044\u3066\u3082\u691c\u7d22\u3059\u3079\u304d\u3067\u3059\u3002<\/p>\n<p>\u6700\u5f8c\u306b\u3001Emotet\u611f\u67d3\u30db\u30b9\u30c8\u306f\u300125\/tcp\u3001465\/tcp\u3001587\/tcp\u306a\u3069\u306eSMTP\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305fTCP\u30dd\u30fc\u30c8\u3092\u4ecb\u3057\u3001\u5927\u91cf\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u751f\u6210\u3059\u308b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u306b\u306a\u308b\u53ef\u80fd\u6027\u3082\u3042\u308a\u307e\u3059\u3002<\/p>\n<h2>Emotet\u306e\u611f\u67d3\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u542b\u3080Pcap\u30d5\u30a1\u30a4\u30eb<\/h2>\n<p>\u6700\u8fd1\u306eEmotet\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306epcap\u3092\u542b\u30805\u3064\u306e\u30d1\u30b9\u30ef\u30fc\u30c9\u4ed8\u304dZIP\u30a2\u30fc\u30ab\u30a4\u30d6\uff08\u30d1\u30b9\u30ef\u30fc\u30c9\u306f\u300cinfected\u300d\uff09\u3092<a href=\"https:\/\/github.com\/pan-unit42\/wireshark-tutorial-Emotet-traffic\">\u3053\u3061\u3089\u306eGitHub\u30ea\u30dd\u30b8\u30c8\u30ea<\/a>\u304b\u3089\u53d6\u5f97\u3057\u3066\u304f\u3060\u3055\u3044\u3002Github\u30da\u30fc\u30b8\u306b\u79fb\u52d5\u3057\u3066\u3001ZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u306e\u30a8\u30f3\u30c8\u30ea\u3092\u30af\u30ea\u30c3\u30af\u3057\u3001\u56f34\u3068\u56f35\u306b\u793a\u3059\u624b\u9806\u3067\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116682\" aria-describedby=\"caption-attachment-116682\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116683 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-33.jpeg\" alt=\"The screenshot shows how to download ZIP archives used for this Wireshark tutorial from the GitHub repository. \" width=\"900\" height=\"598\" \/><figcaption id=\"caption-attachment-116682\" class=\"wp-caption-text\">\u56f34 \u3053\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u4f7f\u7528\u3059\u308bZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u3078\u306e\u30ea\u30f3\u30af\u3092\u542b\u3080GitHub\u30ea\u30dd\u30b8\u30c8\u30ea<\/figcaption><\/figure>\n<figure id=\"attachment_116684\" aria-describedby=\"caption-attachment-116684\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116685 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-34.jpeg\" alt=\"The screenshot shows where to click to download one of the ZIP archives used for this Wireshark Tutorial on analyzing Emotet infection traffic. \" width=\"900\" height=\"549\" \/><figcaption id=\"caption-attachment-116684\" class=\"wp-caption-text\">\u56f35 \u672c\u8b1b\u5ea7\u306eZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u30921\u3064\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u3044\u308b\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u672cZIP\u30a2\u30fc\u30ab\u30a4\u30d6\u30d5\u30a1\u30a4\u30eb\u3092\u89e3\u51cd\u3059\u308b\u30d1\u30b9\u30ef\u30fc\u30c9\u306f\u300c<strong><em>infected<\/em><\/strong>\u300d\u3067\u3059\u3002\u5c55\u958b\u3059\u308b\u3068\u6b21\u306e5\u3064\u306epcap\u30d5\u30a1\u30a4\u30eb\u304c\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li>Example-1-2021-01-06-Emotet-infection.pcap<\/li>\n<li>Example-2-2021-01-05-Emotet-with-spambot-traffic-part-1.pcap<\/li>\n<li>Example-3-2021-01-05-Emotet-with-spambot-traffic-part-2.pcap<\/li>\n<li>Example-4-2021-01-05-Emotet-infection-with-Trickbot.pcap<\/li>\n<li>Example-5-2020-08-18-Emotet-infection-with-Qakbot.pcap<\/li>\n<\/ul>\n<h2>\u4f8b1: Emotet\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/h2>\n<p><strong><em>Example-1-2021-01-06-Emotet-infection.pcap<\/em><\/strong>\u3092\u958b\u3044\u305f\u3089\u3001\u300e<a href=\"https:\/\/unit42.paloaltonetworks.jp\/using-wireshark-display-filter-expressions\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 2: \u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u8abf\u67fb\u306b\u5f79\u7acb\u3064\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u8a2d\u5b9a<\/a>\u300f\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u89e3\u8aac\u3057\u305f\u300cbasic\u300d\u306e web \u7528\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u307e\u3059\u3002Wireshark 3.x\u3067\u306ebasic\u30d5\u30a3\u30eb\u30bf\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">(http.request or tls.handshake.type eq 1) and !(ssdp)<\/span><\/p>\n<p>\u30b7\u30ea\u30fc\u30ba\u521d\u56de\u306e\u300e<a href=\"https:\/\/unit42.paloaltonetworks.jp\/unit42-customizing-wireshark-changing-column-display\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 1: Wireshark\u306e\u8868\u793a\u5217\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3059\u308b<\/a>\u300f\u306b\u5f93\u3063\u3066Wireshark\u3092\u8a2d\u5b9a\u3059\u308b\u3068\u3001\u56f36\u306e\u3088\u3046\u306a\u8868\u793a\u3068\u306a\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116686\" aria-describedby=\"caption-attachment-116686\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116687 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-35.jpeg\" alt=\"\u56f36 \u672c\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb1\u3064\u76ee\u306epcap\u3092Wireshark\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\u3002\" width=\"900\" height=\"582\" \/><figcaption id=\"caption-attachment-116686\" class=\"wp-caption-text\">\u56f36 \u672c\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb1\u3064\u76ee\u306epcap\u3092Wireshark\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u56f36\u306b\u793a\u3059\u3088\u3046\u306b\u3001\u6700\u521d\u306e5\u3064\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u521d\u671fEmotet DLL\u306e\u53d6\u5f97\u306b\u4f7f\u308f\u308c\u308b4\u3064\u306eURL\u3092\u8868\u3057\u3066\u3044\u307e\u3059\u3002\u305d\u308c\u3089\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">hangarlastik[.]com GET \/cgi-bin\/Ui4n\/<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">hangarlastik[.]com GET \/cgi-sys\/suspendedpage.cgi<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">padreescapes[.]com GET \/blog\/0I\/<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">sarture[.]com GET \/wp-includes\/JD8\/<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">seo.udaipurkart[.]com GET \/rx-5700-6hnr7\/Sgms\/<\/span><\/li>\n<\/ul>\n<p>\u6700\u521d\u306e2\u3064\u306eURL\u304b\u3089\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">hangarlastik[.]com<\/span>\u306b\u4ee5\u524d\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3055\u308c\u3066\u3044\u305fEmotet DLL\u30d5\u30a1\u30a4\u30eb\u304c\u3059\u3067\u306b\u5b58\u5728\u3057\u306a\u3044\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u305d\u306e\u78ba\u8a8d\u306b\u306f\u3001\u3053\u308c\u3089\u306e\u5404\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u3064\u3044\u3066TCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3001\u5404HTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u3078\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u78ba\u8a8d\u3057\u3066\u307f\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>HTTP \u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u78ba\u8a8d\u3059\u308b\u7c21\u5358\u306a\u65b9\u6cd5\u306f\u3001\u5148\u7a0b\u9069\u7528\u3057\u305fWireshark\u306e\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u306b\u3001HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u306e\u30d5\u30a3\u30eb\u30bf\u3092\u8ffd\u52a0\u3057\u3066\u3084\u308b\u3053\u3068\u3067\u3059 (\u4e0b\u8a18\u306e<strong>\u5f37\u8abf<\/strong>\u90e8\u5206)\u3002<\/p>\n<p style=\"text-align: center;\"><span style=\"font-family: 'courier new', courier, monospace;\">(http.request <strong>or http.response<\/strong> or tls.handshake.type eq 1) and !(ssdp)<\/span><\/p>\n<p>\u3053\u308c\u306b\u3088\u308a\u3001HTTP \u30ec\u30b9\u30dd\u30f3\u30b9\u304c[<strong><em>Info<\/em><\/strong>]\u5217\u306b\u8868\u793a\u3055\u308c\u307e\u3059 (\u56f37\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116688\" aria-describedby=\"caption-attachment-116688\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116689 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-36.jpeg\" alt=\"\u56f37 Wireshark\u306e\u8868\u793a\u30d5\u30a3\u30eb\u30bf\u306bHTTP \u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u8ffd\u52a0\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"382\" \/><figcaption id=\"caption-attachment-116688\" class=\"wp-caption-text\">\u56f37 Wireshark\u306e\u8868\u793a\u30d5\u30a3\u30eb\u30bf\u306bHTTP \u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u8ffd\u52a0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u3053\u308c\u3067\u3001Word\u30de\u30af\u30ed\u304cEmotet DLL\u3092\u53d6\u5f97\u3057\u3088\u3046\u3068\u3057\u305f\u3068\u304d\u306b\u4f55\u304c\u8d77\u3053\u3063\u305f\u306e\u304b\u304c\u3088\u308a\u660e\u78ba\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">hangarlastik[.]com GET \/cgi-bin\/Ui4n\/<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">HTTP\/1.1 302 Found<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">hangarlastik[.]com GET \/cgi-sys\/suspendedpage.cgi<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">HTTP\/1.1 200 OK<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">padreescapes[.]com GET \/blog\/0I\/<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">HTTP\/1.1 401 Unauthorized<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">sarture[.]com GET \/wp-includes\/JD8\/<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">HTTP\/1.1 403 Forbidden<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">seo.udaipurkart[.]com GET \/rx-5700-6hnr7\/Sgms\/<\/span><\/li>\n<\/ul>\n<p>\u552f\u4e00\u3001\u300c<span style=\"font-family: 'courier new', courier, monospace;\">200 OK<\/span>\u300d\u3068\u306a\u3063\u305f\u30ec\u30b9\u30dd\u30f3\u30b9\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">hangarlastik[.]com<\/span>\u304b\u3089\u306e\u3001\u30b5\u30b9\u30da\u30f3\u30c9\u3055\u308c\u305f\u30da\u30fc\u30b8\u306b\u95a2\u3059\u308b\u901a\u77e5\u3078\u306e\u30ea\u30d7\u30e9\u30a4\u3067\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">seo.udaipurkart[.]com<\/span>\u3078\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u30ec\u30b9\u30dd\u30f3\u30b9\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u306a\u3044\u306e\u3067\u3001\u3053\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3078\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3066\u307f\u307e\u3057\u3087\u3046\uff08\u56f38\u53c2\u7167\uff09\u3002<\/p>\n<p><figure id=\"attachment_116690\" aria-describedby=\"caption-attachment-116690\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116691 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-37.jpeg\" alt=\"\u56f38 seo.udaipurkart[.]com\u3078\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\" width=\"900\" height=\"657\" \/><figcaption id=\"caption-attachment-116690\" class=\"wp-caption-text\">\u56f38 seo.udaipurkart[.]com\u3078\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1<\/figcaption><\/figure>\u3053\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u304b\u3089\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">seo.udaipurkart[.]com<\/span>\u304cWindows DLL\u30d5\u30a1\u30a4\u30eb\u3092\u8fd4\u3066\u3044\u308b\u3068\u3044\u3046\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3059\uff08\u56f39\u53c2\u7167\uff09\u3002<\/p>\n<p><figure id=\"attachment_116692\" aria-describedby=\"caption-attachment-116692\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116693 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-38.jpeg\" alt=\"\u56f39 seo.udaipurkart[.]com\u304b\u3089DLL\u30d5\u30a1\u30a4\u30eb\u304c\u8fd4\u3055\u308c\u305f\u3053\u3068\u3092\u793a\u3059\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\" width=\"900\" height=\"630\" \/><figcaption id=\"caption-attachment-116692\" class=\"wp-caption-text\">\u56f39 seo.udaipurkart[.]com\u304b\u3089DLL\u30d5\u30a1\u30a4\u30eb\u304c\u8fd4\u3055\u308c\u305f\u3053\u3068\u3092\u793a\u3059\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3002\u30d5\u30a1\u30a4\u30eb\u540d\u304c\u300cdll\u300d\u3067\u3001\u5148\u982d2\u30d0\u30a4\u30c8\u304c\u300cMZ\u300d\u3001\u305d\u306e\u5f8c\u308d\u306b\u300cThis program cannot be run in DOS mode.\u300d\u3068\u3044\u3046Windows\u5b9f\u884c\u53ef\u80fd\u5f62\u5f0f\u30d5\u30a1\u30a4\u30eb\u3067\u3042\u308b\u3053\u3068\u3092\u793a\u3059\u30d5\u30a1\u30a4\u30eb\u30bf\u30a4\u30d7\u304c\u78ba\u8a8d\u3067\u304d\u308b<\/figcaption><\/figure>\u3053\u306eDLL\u30d5\u30a1\u30a4\u30eb\u3092pcap\u304b\u3089\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u307e\u3059\u3002\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b\u306b\u306f\u3001Wireshark \u306e\u30e1\u30cb\u30e5\u30fc\u3067<strong><em>[File (\u30d5\u30a1\u30a4\u30eb)\u300d\u3001\u300cExport Objects (\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8)\u300d\u3001\u300cHTTP\u300d<\/em><\/strong>\u306e\u9806\u306b\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059 (\u56f310\u53c2\u7167)\u3002\u7e70\u308a\u8fd4\u3057\u306b\u306a\u308a\u307e\u3059\u304c\u3001\u3053\u306eDLL\u306fWindows\u30d9\u30fc\u30b9\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306a\u306e\u3067\u3001Windows\u74b0\u5883\u3067\u306f\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u306a\u3044\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116694\" aria-describedby=\"caption-attachment-116694\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116695 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-39.jpeg\" alt=\"\u56f310 1\u3064\u76ee\u306epcap\u304b\u3089EmotetDLL\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b\" width=\"900\" height=\"447\" \/><figcaption id=\"caption-attachment-116694\" class=\"wp-caption-text\">\u56f310 1\u3064\u76ee\u306epcap\u304b\u3089EmotetDLL\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b<\/figcaption><\/figure>\n<p>\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3055\u308c\u305fDLL\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u5024\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">8e37a82ff94c03a5be3f9dd76b9dfc335a0f70efc0d8fd3dca9ca34dd287de1b<\/span><\/p>\n<p>Emotet\u306eC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u3001HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f7f\u7528\u3057\u3066\u9001\u4fe1\u3055\u308c\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u6b21\u306e\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u7528\u3059\u308b\u3068Wireshark\u3067\u7c21\u5358\u306b\u898b\u3064\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">http.request.method eq POST<\/span><\/p>\n<p>\u3053\u306e\u30d5\u30a3\u30eb\u30bf\u306e\u9069\u7528\u7d50\u679c\u3092\u56f311\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116696\" aria-describedby=\"caption-attachment-116696\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116697 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-40.jpeg\" alt=\"\u56f311 1\u3064\u76ee\u306epcap\u3067HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"536\" \/><figcaption id=\"caption-attachment-116696\" class=\"wp-caption-text\">\u56f311 1\u3064\u76ee\u306epcap\u3067HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>1\u3064\u76ee\u306epcap\u3067\u306f\u3001Emotet\u306eC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u6b21\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">5.2.136[.]90<\/span> (<span style=\"font-family: 'courier new', courier, monospace;\">80\/tcp)<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">167.71.4[.]0<\/span> (<span style=\"font-family: 'courier new', courier, monospace;\">8080\/tcp)<\/span><\/li>\n<\/ul>\n<p>Emotet\u306fC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b2\u7a2e\u985e\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u751f\u6210\u3057\u307e\u3059\u30021\u7a2e\u985e\u76ee\u306ePOST\u30ea\u30af\u30a8\u30b9\u30c8\u306f<span style=\"font-family: 'courier new', courier, monospace;\">HTTP \/1.1<\/span>\u3067\u7d42\u308f\u308b\u3082\u306e\u3067\u30012\u7a2e\u985e\u76ee\u306ePOST\u30ea\u30af\u30a8\u30b9\u30c8\u306f<span style=\"font-family: 'courier new', courier, monospace;\">HTTP\/1.1 (application\/x-www-form-urlencoded)<\/span>\u3067\u7d42\u308f\u308b\u3082\u306e\u3067\u3059\u3002<\/p>\n<p>16:42:34 UTC\u306e1\u3064\u76ee\u306e<span style=\"font-family: 'courier new', courier, monospace;\">5.2.136[.]90<\/span>\u3078\u306eHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3066\u30011\u7a2e\u985e\u76ee\u306eC2 POST\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u4f8b\u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046 (\u56f312\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116698\" aria-describedby=\"caption-attachment-116698\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116699 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-41.jpeg\" alt=\"\u56f312 EmotetC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e1\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\" width=\"900\" height=\"576\" \/><figcaption id=\"caption-attachment-116698\" class=\"wp-caption-text\">\u56f312 EmotetC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e1\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8<\/figcaption><\/figure>\n<p>\u56f312\u306f\u3053\u306ePOST\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u3001\u30a8\u30f3\u30b3\u30fc\u30c9\u306a\u3044\u3057\u6697\u53f7\u5316\u3055\u308c\u305f\u30d0\u30a4\u30ca\u30ea\u306e\u3088\u3046\u306b\u898b\u3048\u308b\u7d046KB\u306e\u30d5\u30a9\u30fc\u30e0\u30c7\u30fc\u30bf\u3092\u9001\u4fe1\u3059\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002HTTP\u30ec\u30b9\u30dd\u30f3\u30b9\u307e\u3067\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3001\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u8fd4\u3055\u308c\u305f\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046\u3002\u56f313\u306f\u3001\u3053\u306e\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u306e\u306f\u3058\u307e\u308a\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116700\" aria-describedby=\"caption-attachment-116700\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116701 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-42.jpeg\" alt=\"\u56f313 HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3078\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3068\u3057\u3066\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u8fd4\u3055\u308c\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\" width=\"900\" height=\"576\" \/><figcaption id=\"caption-attachment-116700\" class=\"wp-caption-text\">\u56f313 HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3078\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3068\u3057\u3066\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u8fd4\u3055\u308c\u308b\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf<\/figcaption><\/figure>\n<p>\u3053\u306e\u7a2e\u306e\u30a8\u30f3\u30b3\u30fc\u30c9\u306a\u3044\u3057\u6697\u53f7\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u304c\u3001Emotet\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u30b5\u30fc\u30d0\u30fc\u3068\u611f\u67d3Windows\u30db\u30b9\u30c8\u3068\u3067\u30c7\u30fc\u30bf\u3092\u4ea4\u63db\u3059\u308b\u65b9\u6cd5\u3067\u3059\u3002\u3053\u308c\u306f\u307e\u305f\u3001Emotet\u304cEmotet DLL\u3092\u66f4\u65b0\u3057\u3066\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30c9\u30ed\u30c3\u30d7\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3059\u308b\u30c1\u30e3\u30cd\u30eb\u3067\u3082\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e2\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u30011\u7a2e\u985e\u76ee\u3068\u306f\u304b\u306a\u308a\u7570\u306a\u3063\u3066\u898b\u3048\u307e\u3059\u3002Wireshark\u3067\u6b21\u306e\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u7528\u3059\u308b\u3068\u3001\u3053\u306e2\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5bb9\u6613\u306b\u898b\u3064\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">urlencoded-form<\/span><\/p>\n<p>\u3053\u306e\u30d5\u30a3\u30eb\u30bf\u306b\u3088\u308a\u3001<span style=\"font-family: 'courier new', courier, monospace;\">8080\/tcp<\/span>\u7d4c\u7531\u306e<span style=\"font-family: 'courier new', courier, monospace;\">167.71.4[.]0<\/span>\u3078\u306e2\u3064\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u8868\u793a\u3055\u308c\u307e\u3059 (\u56f314\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116702\" aria-describedby=\"caption-attachment-116702\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116703 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-43.jpeg\" alt=\"\u56f314 Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e2\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\" width=\"900\" height=\"199\" \/><figcaption id=\"caption-attachment-116702\" class=\"wp-caption-text\">\u56f314 Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e2\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/figcaption><\/figure>\n<p>16:58:43 UTC \u306b\u767a\u751f\u3057\u305f\u3053\u308c\u30892\u3064\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u3046\u3061\u30011\u3064\u76ee\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3066\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002\u305d\u306e\u7d50\u679c\u3092\u56f315\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116704\" aria-describedby=\"caption-attachment-116704\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116705 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-44.jpeg\" alt=\"\u56f315 Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e2\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\" width=\"900\" height=\"496\" \/><figcaption id=\"caption-attachment-116704\" class=\"wp-caption-text\">\u56f315 Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e2\u7a2e\u985e\u76ee\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0<\/figcaption><\/figure>\n<p>\u56f315\u306b\u793a\u3057\u305f\u3088\u3046\u306b\u3001POST\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30fc\u30bf\u306e\u4e00\u90e8\u306f\u3001URL\u30a8\u30f3\u30b3\u30fc\u30c9\u306b\u3088\u308abase64\u6587\u5b57\u5217\u3068\u3057\u3066\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u4f8b\u3048\u3070\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%2B<\/span>\u304c\u300c+\u300d\u8a18\u53f7\u3092\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%2F<\/span>\u304c\u300c\/\u300d\u3092\u3001<span style=\"font-family: 'courier new', courier, monospace;\">%3D<\/span>\u304c\u300c<span style=\"font-family: 'courier new', courier, monospace;\">=<\/span>\u300d\u3092\u8868\u3059\u306e\u306b\u4f7f\u7528\u3055\u308c\u308b\u3001\u3068\u3044\u3063\u305f\u3050\u3042\u3044\u3067\u3059\u3002<\/p>\n<p>\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3068\u3057\u3066\u9001\u4fe1\u3055\u308c\u308b\u30c7\u30fc\u30bf\u306f\u3001\u30a8\u30f3\u30b3\u30fc\u30c9\u307e\u305f\u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>1\u3064\u76ee\u306epcap\u306b\u306f\u3001\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7\u30de\u30eb\u30a6\u30a7\u30a2\u306a\u3069\u306e\u91cd\u8981\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u542b\u307e\u308c\u3066\u3044\u307e\u305b\u3093\u3002<\/p>\n<p>\u307b\u304b\u306e\u552f\u4e00\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">443\/tcp<\/span>\u7d4c\u7531\u3067<span style=\"font-family: 'courier new', courier, monospace;\">46.101.230[.]194<\/span>\u3078\u306e\u63a5\u7d9a\u8a66\u884c\u3092\u7e70\u308a\u8fd4\u3057\u3066\u3044\u308b\u3053\u3068\u3067\u3059\u3002\u3053\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u3001Retransmission (\u518d\u9001\u4fe1) \u306eTCP SYN\u30bb\u30b0\u30e1\u30f3\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3059\u308b\u3053\u3068\u3067\u7c21\u5358\u306b\u898b\u3064\u304b\u308a\u307e\u3059\u3002\u305d\u306e\u305f\u3081\u306b\u306f\u3001\u6b21\u306eWireshark\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">tcp.analysis.retransmission and tcp.flags eq 0x0002<\/span><\/p>\n<p>\u7d50\u679c\u3092\u56f316\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116706\" aria-describedby=\"caption-attachment-116706\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116707 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-45.jpeg\" alt=\"\u56f316 Retransmission (\u518d\u9001\u4fe1) \u306eTCP SYN\u30bb\u30b0\u30e1\u30f3\u30c8\u3092Wireshark\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\" width=\"900\" height=\"534\" \/><figcaption id=\"caption-attachment-116706\" class=\"wp-caption-text\">\u56f316 Retransmission (\u518d\u9001\u4fe1) \u306eTCP SYN\u30bb\u30b0\u30e1\u30f3\u30c8\u3092Wireshark\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/figcaption><\/figure>\n<p>\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u3067<span style=\"font-family: 'courier new', courier, monospace;\">46.101.230[.]194<\/span>\u3092\u691c\u7d22\u3059\u308c\u3070\u3001\u3053\u306eIP\u30a2\u30c9\u30ec\u30b9\u304cEmotet\u306eC2\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u4f7f\u7528\u3055\u308c\u3066\u304d\u305f\u3082\u306e\u3067\u3042\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u308b\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>\u3053\u306epcap\u5185\u306e\u6b8b\u308a\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306fMicrosoft Windows10\u30db\u30b9\u30c8\u304c\u751f\u6210\u3057\u305f\u30b7\u30b9\u30c6\u30e0 \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3067\u3059\u3002<\/p>\n<p>\u6b21\u306e2\u3064\u76ee\u306epcap\u3067\u306f\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u884c\u3046Emotet\u611f\u67d3\u306b\u3064\u3044\u3066\u8abf\u3079\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h2>\u4f8b2: \u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u542b\u3080 Emotet \u30d1\u30fc\u30c81<\/h2>\n<p><strong><em>Example-2-2021-01-05-Emotet-with-spambot-traffic-part-1.pcap<\/em><\/strong>\u3092Wireshark\u3067\u958b\u3044\u3066\u3001\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u307e\u3059\uff08\u56f317\u53c2\u7167\uff09\u3002<\/p>\n<figure id=\"attachment_116708\" aria-describedby=\"caption-attachment-116708\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116709 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-46.jpeg\" alt=\"\u56f317 Wireshark\u30672\u3064\u3081\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9\" width=\"900\" height=\"535\" \/><figcaption id=\"caption-attachment-116708\" class=\"wp-caption-text\">\u56f317 Wireshark\u30672\u3064\u3081\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9<\/figcaption><\/figure>\n<p>1\u3064\u76ee\u306e\u30b5\u30f3\u30d7\u30eb\u540c\u69d8\u3001Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u767a\u751f\u524d\u306b\u8907\u6570\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u53d7\u4fe1\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306eGET\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001Web\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u7d4c\u7531\u3067\u6700\u521d\u306eEmotet DLL\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u5217\u8868\u793a\u3057\u305f\u6700\u521d\u306e\u30d5\u30ec\u30fc\u30e0\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">obob[.]tv<\/span>\u3078\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u308c\u304c\u304a\u305d\u3089\u304f\u6700\u521d\u306eEmotet DLL\u3078\u306eWeb\u30ea\u30af\u30a8\u30b9\u30c8\u3060\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u3068\u3044\u3046\u306e\u3082\u3001<a href=\"https:\/\/urlhaus.abuse.ch\/url\/949290\/\">\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u30012021\u5e741\u67085\u65e5\u306bEmotet\u30d0\u30a4\u30ca\u30ea\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u305f\u3053\u3068\u304c\u5831\u544a<\/a>\u3055\u308c\u3066\u304a\u308a\u3001\u305d\u306e\u65e5\u4ed8\u306f\u3053\u306epcap\u306e\u65e5\u4ed8\u3068\u540c\u4e00\u3060\u304b\u3089\u3067\u3059\u3002<\/p>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">miprimercamino[.]com<\/span>\u3078\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3001\u3053\u308c\u304cEmotet DLL\u3092\u8fd4\u3057\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u30021\u3064\u76ee\u306epcap\u306e\u56f39\u3067\u793a\u3057\u305f\u3082\u306e\u3068\u4f3c\u305f\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u304c\u8868\u793a\u3055\u308c\u308b\u306f\u305a\u3067\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">miprimercamino[.]com<\/span>\u304b\u3089\u8fd4\u3055\u308c\u305fEmotet DLL\u306f\u3001\u56f318\u306b\u793a\u3057\u305f\u624b\u9806\u3067\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116710\" aria-describedby=\"caption-attachment-116710\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116711 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-47.jpeg\" alt=\"\u56f318 pcap\u304b\u3089Emotet DLL\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b\" width=\"900\" height=\"535\" \/><figcaption id=\"caption-attachment-116710\" class=\"wp-caption-text\">\u56f318 pcap\u304b\u3089Emotet DLL\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b<\/figcaption><\/figure>\n<p>2\u3064\u76ee\u306epcap\u304b\u3089\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u305fDLL\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u5024\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">963b00584d8d63ea84585f7457e6ddcac9eda54428a432f388a1ffee21137316<\/span><\/p>\n<p>\u3053\u3053\u3067\u3082Emotet\u306fC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b2\u7a2e\u985e\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u751f\u6210\u3057\u307e\u3059\u3002Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u305d\u308c\u305e\u308c\u306e\u7a2e\u985e\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3059\u308b\u306b\u306f\u3001\u6b21\u306eWireshark\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>1\u7a2e\u985e\u76ee: <span style=\"font-family: 'courier new', courier, monospace;\">http.request method eq POST and !(urlencoded-form)<\/span><\/li>\n<li>2\u7a2e\u985e\u76ee: <span style=\"font-family: 'courier new', courier, monospace;\">urlencoded-form<\/span><\/li>\n<\/ul>\n<p>\u3053\u308c\u3089\u306e\u30d5\u30a3\u30eb\u30bf\u3067\u8fd4\u3055\u308c\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u30012\u3064\u76ee\u306epcap\u3067\u30821\u3064\u76ee\u306epcap\u3067\u898b\u305f\u306e\u3068\u540c\u3058\u30c8\u30e9\u30d5\u30a3\u30c3\u30af \u30d1\u30bf\u30fc\u30f3\u304c\u898b\u3089\u308c\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>pcap\u5185\u3067Emotet\u306eC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u4f8b\u3092\u3044\u304f\u3064\u304b\u78ba\u8a8d\u3057\u305f\u3089\u3001\u6b21\u306f\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u78ba\u8a8d\u306b\u79fb\u308a\u307e\u3057\u3087\u3046\u3002<\/p>\n<p>\u3053\u306e\u4f8b\u3067\u306f\u3001\u611f\u67d3\u30db\u30b9\u30c8\u304c\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u306b\u5909\u3048\u3089\u308c\u305f\u305f\u3081\u3001SMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u306eSMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u300cbasic\u300d\u306eWeb\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u3063\u3066\u5217\u8868\u793a\u3092\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3059\u308b\u3053\u3068\u3067\u7c21\u5358\u306b\u898b\u3064\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u3053\u306epcap\u3067\u306f\u300120:06:20 UTC \u304b\u3089\u300125\/tcp\u3001465\/tcp\u3001587\/tcp\u306a\u3069\u306eSMTP\u96fb\u5b50\u30e1\u30fc\u30eb\u30d7\u30ed\u30c8\u30b3\u30eb\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305fTCP\u30dd\u30fc\u30c8\u3078\u306eSSL\/TLS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u8868\u793a\u3055\u308c\u59cb\u3081\u307e\u3059 (\u56f319\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116712\" aria-describedby=\"caption-attachment-116712\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116713 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-48.jpeg\" alt=\"\u56f319 \u300cbasic\u300d\u306eWeb\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u7528\u3057\u3001\u5217\u8868\u793a\u3092\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u63a2\u3057\u307e\u3059\u3002\" width=\"900\" height=\"617\" \/><figcaption id=\"caption-attachment-116712\" class=\"wp-caption-text\">\u56f319 \u300cbasic\u300d\u306eWeb\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u7528\u3057\u5217\u8868\u793a\u3092\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u63a2\u3059<\/figcaption><\/figure>\n<p>SMTP\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3059\u308c\u3070\u3001\u6697\u53f7\u5316\u3055\u308c\u305fSMTP\u30c8\u30f3\u30cd\u30eb\u306e\u78ba\u7acb\u524d\u306b<span style=\"font-family: 'courier new', courier, monospace;\">SMTP<\/span>\u30b3\u30de\u30f3\u30c9\u304c\u3044\u304f\u3064\u304b\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3059\u3002\u56f320\u306b\u7d50\u679c\u3092\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116714\" aria-describedby=\"caption-attachment-116714\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116715 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-49.jpeg\" alt=\"\u56f320 2\u756a\u76ee\u306epcap\u3067SMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3059\u308b\" width=\"900\" height=\"564\" \/><figcaption id=\"caption-attachment-116714\" class=\"wp-caption-text\">\u56f320 2\u756a\u76ee\u306epcap\u3067SMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3059\u308b<\/figcaption><\/figure>\n<p>Emotet\u306b\u611f\u67d3\u3057\u305fWindows\u30db\u30b9\u30c8\u306e\u751f\u6210\u3059\u308b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u306a\u304b\u306b\u306f\u3001\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u306a\u3044SMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3082\u898b\u3064\u304b\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u5e73\u6587\u306eSMTP\u304b\u3089\u306f\u30e1\u30c3\u30bb\u30fc\u30b8\u306e\u5185\u5bb9\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3059\u304c\u3001\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30db\u30b9\u30c8\u304b\u3089\u9001\u4fe1\u3055\u308c\u308b\u6697\u53f7\u5316SMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30dc\u30ea\u30e5\u30fc\u30e0\u306f\u5e73\u6587\u306e\u305d\u308c\u3068\u304f\u3089\u3079\u3066\u304d\u308f\u3060\u3063\u3066\u5927\u304d\u3044\u3053\u3068\u304b\u3089\u3001Emotet\u611f\u67d3\u30db\u30b9\u30c8\u306e\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u305d\u306e\u307b\u3068\u3093\u3069\u304c\u6697\u53f7\u5316\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u6f5c\u3093\u3067\u3044\u308b\u3068\u3044\u3046\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u4f8b\u3067\u306f\u6697\u53f7\u5316\u3055\u308c\u305fSMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u307f\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u306a\u304a\u3001\u6b21\u306b\u3042\u3052\u308b\u4f8b\u306f\u3053\u308c\u3068\u540c\u3058\u611f\u67d3\u306e\u5f8c\u534a\u306e\u3082\u306e\u3067\u3001\u3053\u3053\u3067\u3088\u3046\u3084\u304f\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u306a\u3044SMTP\u304c\u898b\u3064\u304b\u308a\u307e\u3059\u3002<\/p>\n<h2>\u4f8b2: \u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u542b\u3080 Emotet \u30d1\u30fc\u30c82<\/h2>\n<p><strong><em>Example-3-2021-01-05-Emotet-with-spambot-traffic-part-2.pcap<\/em><\/strong>\u3092Wireshark\u3067\u958b\u3044\u3066\u3001\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u307e\u3059\uff08\u56f321\u53c2\u7167\uff09\u3002<\/p>\n<figure id=\"attachment_116716\" aria-describedby=\"caption-attachment-116716\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116717 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-50.jpeg\" alt=\"\u56f321 Wireshark\u30673\u3064\u76ee\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9\" width=\"900\" height=\"564\" \/><figcaption id=\"caption-attachment-116716\" class=\"wp-caption-text\">\u56f321 Wireshark\u30673\u3064\u76ee\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9<\/figcaption><\/figure>\n<p>\u3053\u306epcap\u3067\u3082\u3001Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u5bfe\u3059\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u5c11\u306a\u304f\u3068\u30821\u5206\u306b2\u56de\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u4ee5\u524d\u306epcap\u3068\u540c\u69d8\u306e\u6697\u53f7\u5316\u3055\u308c\u305f\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3082\u898b\u3064\u304b\u308a\u307e\u3059\u3002<\/p>\n<p>\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3067\u306f\u983b\u7e41\u306b\u5927\u91cf\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u751f\u3058\u307e\u3059\u3002\u3053\u306epcap\u306b\u306f\u3001\u611f\u67d3Windows\u30db\u30b9\u30c8\u4e0a\u3067\u306e4\u520642\u79d2\u306b\u308f\u305f\u308b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u304c\u8a18\u9332\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u306e\u4e2d\u306b\u306f 21MB \u8d85\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u306a\u3044SMTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u3059\u3070\u3084\u304f\u8b58\u5225\u3059\u308b\u306b\u306f\u6b21\u306eWireshark\u30d5\u30a3\u30eb\u30bf\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-family: 'courier new', courier, monospace;\">smtp.data.fragment<\/span><\/p>\n<p>\u56f322\u306f\u30013\u3064\u76ee\u306epcap\u306b\u5bfe\u3059\u308b\u3053\u306e\u30d5\u30a3\u30eb\u30bf\u306e\u7d50\u679c\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30d5\u30a3\u30eb\u30bf\u306b\u3088\u308a\u3001\u611f\u67d3Windows\u30db\u30b9\u30c8\u304c\u751f\u6210\u3057\u305f5\u3064\u306eEmotet\u30de\u30eb\u30b9\u30d1\u30e0\u306e\u30b5\u30f3\u30d7\u30eb\u304c\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116718\" aria-describedby=\"caption-attachment-116718\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116719 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-51.jpeg\" alt=\"\u56f322 \u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u306a\u3044SMTP\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\u3002\" width=\"900\" height=\"255\" \/><figcaption id=\"caption-attachment-116718\" class=\"wp-caption-text\">\u56f322 \u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u306a\u3044SMTP\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>20:19:54 UTC\u306e<span style=\"font-family: 'courier new', courier, monospace;\">from: \u201cGladisbel Miranda<\/span>\u3068\u3044\u3046\u6700\u5f8c\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u3069\u306e\u3088\u3046\u306a\u5f62\u5f0f\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046 (\u56f323\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116720\" aria-describedby=\"caption-attachment-116720\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116721 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-52.jpeg\" alt=\"\u56f323 3\u3064\u76ee\u306epcap\u304b\u3089\u306eEmotet\u30de\u30eb\u30b9\u30d1\u30e0\u30b5\u30f3\u30d7\u30eb\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\" width=\"900\" height=\"1100\" \/><figcaption id=\"caption-attachment-116720\" class=\"wp-caption-text\">\u56f323 3\u3064\u76ee\u306epcap\u304b\u3089\u306eEmotet\u30de\u30eb\u30b9\u30d1\u30e0\u30b5\u30f3\u30d7\u30eb\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0<\/figcaption><\/figure>\n<p>Emotet\u30de\u30eb\u30b9\u30d1\u30e0\u306e\u3053\u308c\u30895\u3064\u306e\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306f\u3001Wireshark\u306e\u30e1\u30cb\u30e5\u30fc\u304b\u3089\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u56f324\u306b\u3057\u305f\u304c\u3063\u3066\u3001<strong><em>[File (\u30d5\u30a1\u30a4\u30eb)]\u3001[Export Objects (\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8)]\u3001[IMF]<\/em><\/strong>\u306e\u9806\u306b\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116722\" aria-describedby=\"caption-attachment-116722\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116723 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-53.jpeg\" alt=\"\u56f324 3\u3064\u76ee\u306epcap\u304b\u3089Emotet\u30de\u30eb\u30b9\u30d1\u30e0\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b\" width=\"900\" height=\"535\" \/><figcaption id=\"caption-attachment-116722\" class=\"wp-caption-text\">\u56f324 3\u3064\u76ee\u306epcap\u304b\u3089Emotet\u30de\u30eb\u30b9\u30d1\u30e0\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3059\u308b<\/figcaption><\/figure>\n<p>\u3053\u308c\u3089\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u3092\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u3066\u8abf\u3079\u307e\u3057\u3087\u3046\u3002\u3053\u308c\u3082\u3001\u3067\u304d\u308c\u3070Windows\u74b0\u5883\u4ee5\u5916\u3067\u3084\u308b\u306e\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002\u6f5c\u5728\u7684\u306a\u88ab\u5bb3\u8005\u304b\u3089\u3053\u3046\u3057\u305f\u96fb\u5b50\u30e1\u30fc\u30eb\u304c\u3069\u306e\u3088\u3046\u306b\u898b\u3048\u308b\u304b\u3092\u78ba\u8a8d\u3059\u308b\u3055\u3044\u306f\u3001<a href=\"https:\/\/www.thunderbird.net\/en-US\/\">Thunderbird<\/a>\u306a\u3069\u306e\u7121\u6599\u96fb\u5b50\u30e1\u30fc\u30eb\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3092\u4f7f\u3046\u3068\u3088\u3044\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>\u3055\u3066\u3001\u5148\u306b\u8ff0\u3079\u305f\u3068\u304a\u308a\u3001Emotet\u306f\u30de\u30eb\u30a6\u30a7\u30a2\u30c0\u30a6\u30f3\u30ed\u30fc\u30c0\u3067\u3082\u3042\u308a\u307e\u3059\u3002Emotet\u7d4c\u7531\u3067\u914d\u5e03\u3055\u308c\u308b\u6700\u3082\u4e00\u822c\u7684\u306a\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u304a\u305d\u3089\u304fTrickbot\u3067\u3057\u3087\u3046\u3002<\/p>\n<h2>\u4f8b4: Trickbot\u3092\u914d\u5e03\u3059\u308bEmotet\u611f\u67d3<\/h2>\n<p><strong><em>Example-4-2021-01-05-Emotet-infection-with-Trickbot.pcap<\/em><\/strong>\u3092Wireshark\u3067\u958b\u3044\u3066\u3001\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u307e\u3059\uff08\u56f325\u53c2\u7167\uff09\u3002<\/p>\n<figure id=\"attachment_116724\" aria-describedby=\"caption-attachment-116724\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116725 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-54.jpeg\" alt=\"\u56f325 Wireshark\u30674\u3064\u76ee\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9\" width=\"900\" height=\"535\" \/><figcaption id=\"caption-attachment-116724\" class=\"wp-caption-text\">\u56f325 Wireshark\u30674\u3064\u76ee\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9<\/figcaption><\/figure>\n<p>\u3053\u306epcap\u306b\u306f\u3001\u521d\u671fEmotet DLL\u306b\u5bfe\u3059\u308bHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u542b\u307e\u308c\u3066\u3044\u307e\u305b\u3093\u3002\u305f\u3060\u3057basic\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u3066\u8868\u793a\u3055\u305b\u305f\u6700\u521d\u306e\u30d5\u30ec\u30fc\u30e0\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">fathekarim[.]com<\/span>\u3078\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u304c\u304a\u305d\u3089\u304fEmotet DLL\u3078\u306eWeb\u30ea\u30af\u30a8\u30b9\u30c8\u3060\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u3068\u3044\u3046\u306e\u3082\u3001<a href=\"https:\/\/urlhaus.abuse.ch\/url\/949449\/\">\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u30012021\u5e741\u67085\u65e5\u306bEmotet\u30d0\u30a4\u30ca\u30ea\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u305f\u3053\u3068\u304c\u5831\u544a<\/a>\u3055\u308c\u3066\u304a\u308a\u3001\u305d\u306e\u65e5\u4ed8\u306f\u3053\u306epcap\u306e\u65e5\u4ed8\u3068\u540c\u4e00\u3060\u304b\u3089\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e pcap \u3067\u3082\u3001\u5148\u306e2\u3064\u306epcap\u3067\u8aac\u660e\u3057\u305f\u3088\u3046\u306b\u3001Emotet C2\u306b\u95a2\u9023\u4ed8\u3051\u3089\u3066\u3044\u308b\u3082\u306e\u3068\u540c\u30582\u7a2e\u985e\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u898b\u3064\u304b\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306epcap\u306b\u306f\u3001Trickbot\u611f\u67d3\u306e\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u3053\u3067\u3082\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u3001\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u3044\u3063\u3066Trickbot\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044 (\u56f326\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116726\" aria-describedby=\"caption-attachment-116726\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116727 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-55.jpeg\" alt=\"\u56f326 4\u756a\u76ee\u306epcap\u306b\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u5f8c\u3001\u5217\u8868\u793a\u3092\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u3044\u3063\u3066Trickbot\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u78ba\u8a8d\u3057\u3066\u3044\u308b\u3068\u3053\u308d\" width=\"900\" height=\"535\" \/><figcaption id=\"caption-attachment-116726\" class=\"wp-caption-text\">\u56f326 4\u756a\u76ee\u306epcap\u306b\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u5f8c\u3001\u5217\u8868\u793a\u3092\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u3044\u3063\u3066Trickbot\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u78ba\u8a8d\u3057\u3066\u3044\u308b\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u3059\u3067\u306bTrickbot\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u3064\u3044\u3066\u306f\u300e<a href=\"https:\/\/unit42.paloaltonetworks.jp\/wireshark-tutorial-examining-trickbot-infections\/\">Wireshark\u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 5: Trickbot\u611f\u67d3\u306e\u8abf\u67fb<\/a>\u300f\u3067\u30ec\u30d3\u30e5\u30fc\u6e08\u307f\u3067\u3059\u304c\u3001\u3053\u3053\u3067\u7c21\u5358\u306b\u304a\u3055\u3089\u3044\u3057\u3066\u304a\u304d\u307e\u3057\u3087\u3046\u3002Trickbot\u306e\u4e00\u822c\u7684\u306a\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u306b\u306f\u6b21\u306e\u3082\u306e\u304c\u3042\u3052\u3089\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u95a2\u9023\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3084\u30db\u30b9\u30c8\u540d\u306e\u306a\u3044447\/tcp\u306a\u3044\u3057449\/tcp\u7d4c\u7531\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">\/81\u3001\/83\u3001<\/span>\u307e\u305f\u306f<span style=\"font-family: 'courier new', courier, monospace;\">\/90<\/span>\u3067\u7d42\u308f\u308b\u3001\u6a19\u6e96\/\u975e\u6a19\u6e96TCP\u30dd\u30fc\u30c8\u3092\u7d4c\u7531\u3057\u305fHTTP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8(\u30c7\u30fc\u30bf\u6f0f\u51fa\u306b\u95a2\u9023)<\/li>\n<li>Emotet\u611f\u67d3\u306b\u3088\u308bTrickbot\u306e\u5834\u5408\u3001\u4e0a\u8a18\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306f<span style=\"font-family: 'courier new', courier, monospace;\">\/mor<\/span>\u3067\u59cb\u307e\u308a\u3001\u3053\u306e\u5f8c\u308d\u306b\u6570\u5b57 (\u3053\u308c\u307e\u3067\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308b\u306e\u306f1\u6841\u304b2\u6841\u306e\u307f) \u304c\u7d9a\u304f<\/li>\n<li>\u8ffd\u52a0\u306eTrickbot\u30d0\u30a4\u30ca\u30ea\u3092\u8fd4\u3059<span style=\"font-family: 'courier new', courier, monospace;\">.png<\/span>\u3067\u7d42\u308f\u308bURL\u306b\u5bfe\u3059\u308bHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8<\/li>\n<\/ul>\n<p>\u3053\u308c\u3089\u306e\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u306f\u6b21\u306eWireshark\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3059\u308b\u3068\u7c21\u5358\u306b\u898b\u3064\u304b\u308a\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">tls.handshake.type eq 1 and (tcp.port eq 447 or tcp.port eq 449)<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">(http.request.uri contains \/81 or http.request.uri contains \/83 or http.request.uri contains \/90) and http.request.uri contains mor<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">http.request.uri contains .png<\/span><\/li>\n<\/ul>\n<p>\u56f327\u304b\u3089\u56f329\u306f\u3001\u4e0a\u8a18\u306e\u5404\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u305f\u7d50\u679c\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116728\" aria-describedby=\"caption-attachment-116728\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116729 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-56.jpeg\" alt=\"\u56f327: 447\/tcp\u307e\u305f\u306f449\/tcp\u7d4c\u7531\u306eTrickbot\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"498\" \/><figcaption id=\"caption-attachment-116728\" class=\"wp-caption-text\">\u56f327: 447\/tcp\u307e\u305f\u306f449\/tcp\u7d4c\u7531\u306eTrickbot\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<figure id=\"attachment_116730\" aria-describedby=\"caption-attachment-116730\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116731 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-57.jpeg\" alt=\"\u56f328 Trickbot\u306e\u30c7\u30fc\u30bf\u306e\u6f0f\u51fa\u306b\u95a2\u9023\u3059\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"249\" \/><figcaption id=\"caption-attachment-116730\" class=\"wp-caption-text\">\u56f328 Trickbot\u306e\u30c7\u30fc\u30bf\u306e\u6f0f\u51fa\u306b\u95a2\u9023\u3059\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u56f328\u306b\u793a\u3057\u305f\u5404HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3001\u30d1\u30b9\u30ef\u30fc\u30c9\u30c7\u30fc\u30bf\u304c\u7a83\u53d6\u3055\u308c\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046\u3002<span style=\"font-family: 'courier new', courier, monospace;\">\/90<\/span>\u3067\u7d42\u308f\u308b\u6700\u5f8c\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u3001\u611f\u67d3Windows\u30db\u30b9\u30c8\u3068\u305d\u306e\u74b0\u5883\u306b\u95a2\u3059\u308b\u30c7\u30fc\u30bf\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116732\" aria-describedby=\"caption-attachment-116732\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116733 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-58.jpeg\" alt=\"\u56f329 \u8ffd\u52a0\u306eTrickbot\u30d0\u30a4\u30ca\u30ea\u3092\u8fd4\u3059.png\u3067\u7d42\u308f\u308bURL\u306b\u5bfe\u3059\u308bHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"254\" \/><figcaption id=\"caption-attachment-116732\" class=\"wp-caption-text\">\u56f329 \u8ffd\u52a0\u306eTrickbot\u30d0\u30a4\u30ca\u30ea\u3092\u8fd4\u3059.png\u3067\u7d42\u308f\u308bURL\u306b\u5bfe\u3059\u308bHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u56f329\u306b\u793a\u3057\u305f\u5404HTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u3092\u8ffd\u8de1\u3057\u3001Windows\u30d0\u30a4\u30ca\u30ea\u304c\u8fd4\u3055\u308c\u3066\u3044\u306a\u3044\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046\u3002\u305d\u3046\u3059\u308c\u3070\u3001Windows\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\u304c2\u3064\u8fd4\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308b\u306f\u305a\u3067\u3059\u3002\u78ba\u8a8d\u5f8c\u306f\u3001\u3053\u308c\u3089\u306e\u30d0\u30a4\u30ca\u30ea\u3092pcap\u304b\u3089\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u307e\u3057\u3087\u3046\u3002\u305d\u306e\u305f\u3081\u306b\u306f\u3053\u308c\u307e\u3067\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u540c\u69d8\u306b<strong><em>[File (\u30d5\u30a1\u30a4\u30eb)]\u30e1\u30cb\u30e5\u30fc\u3067<\/em><\/strong><strong><em>[Export Objects (\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8)]\u3001[HTTP]<\/em><\/strong>\u306e\u9806\u306b\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u30892\u3064\u306eWindows\u30d0\u30a4\u30ca\u30ea\uff08\u3044\u305a\u308c\u3082\u5b9f\u884c\u53ef\u80fd\u30d5\u30a1\u30a4\u30eb\uff09\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u5024\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">59e1711d6e4323da2dc22cdee30ba8876def991f6e476f29a0d3f983368ab461 (mingup.png)<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ed8dea5381a7f6c78108a04344dc73d5669690b7ecfe6e44b2c61687a2306785 (saved.png)<\/span><\/li>\n<\/ul>\n<p>Trickbot\u306fEmotet\u306e\u914d\u5e03\u3059\u308b\u6700\u3082\u4e00\u822c\u7684\u306a\u30de\u30eb\u30a6\u30a7\u30a2\u3067\u3059\u304c\u3001\u3053\u308c\u4ee5\u5916\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u304c\u914d\u5e03\u3055\u308c\u308b\u3053\u3068\u3082\u3042\u308a\u307e\u3059\u3002Qakbot\u304c\u305d\u3046\u3057\u305f\u30de\u30eb\u30a6\u30a7\u30a2\u306e1\u3064\u3067\u3001\u3053\u308c\u3082Emotet\u306b\u611f\u67d3\u3057\u305fWindows\u30db\u30b9\u30c8\u306b\u3088\u3063\u3066\u3088\u304f\u30c9\u30ed\u30c3\u30d7\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>\u4f8b5: Qakbot\u3092\u914d\u5e03\u3059\u308bEmotet\u611f\u67d3<\/h2>\n<p><strong><em>Example-5-2020-08-18-Emotet-infection-with-Qakbot.pcap<\/em><\/strong>\u3092Wireshark\u3067\u958b\u3044\u3066\u3001\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u307e\u3059\uff08\u56f330\u53c2\u7167\uff09\u3002<\/p>\n<figure id=\"attachment_116734\" aria-describedby=\"caption-attachment-116734\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116735 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-59.jpeg\" alt=\"\u56f330 Wireshark\u30675\u3064\u76ee\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9\" width=\"900\" height=\"588\" \/><figcaption id=\"caption-attachment-116734\" class=\"wp-caption-text\">\u56f330 Wireshark\u30675\u3064\u76ee\u306epcap\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u3044\u3066\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3067\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u5185\u5bb9<\/figcaption><\/figure>\n<p>5\u3064\u76ee\u306epcap\u3067\u306f\u3001Emotet Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u304c21:23:50 UTC\u306b<span style=\"font-family: 'courier new', courier, monospace;\">sawtpranamam.mysquare[.]in<\/span>\u304b\u3089\u53d6\u5f97\u3055\u308c\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u308c\u306f<a href=\"https:\/\/urlhaus.abuse.ch\/url\/435882\/\">\u540c\u3058\u65e5\u306bEmotet Word\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u305f\u3053\u3068\u304c\u5831\u544a\u3055\u308c\u3066\u3044\u308bURL<\/a>\u3068\u5408\u81f4\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306eWord\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092pcap\u304b\u3089\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u307e\u3057\u3087\u3046\u3002\u305d\u306e\u305f\u3081\u306b\u306f\u3001\u3053\u308c\u307e\u3067\u306e\u30b5\u30f3\u30d7\u30eb\u3068\u540c\u69d8\u306b<strong><em>[File (\u30d5\u30a1\u30a4\u30eb)]\u30e1\u30cb\u30e5\u30fc\u3067[Export Objects (\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8)]\u3001[HTTP]<\/em><\/strong>\u306e\u9806\u306b\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<p>\u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u3057\u305fWord\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306eSHA256\u30cf\u30c3\u30b7\u30e5\u5024\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c7f429dde8986a1b2fc51a9b3f4a78a92311677a01790682120ab603fd3c2fcb<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">samaritantec[.]com<\/span>\u3078\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c21:24:40 UTC\u306b\u767a\u751f\u3057\u3066\u3044\u308b\u3053\u3068\u3082\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<a href=\"https:\/\/urlhaus.abuse.ch\/url\/436011\/\">\u3053\u306e\u30c9\u30e1\u30a4\u30f3\u306f\u3001\u540c\u3058\u65e5\u306bEmotet\u30d0\u30a4\u30ca\u30ea\u3092\u30db\u30b9\u30c6\u30a3\u30f3\u30b0\u3057\u3066\u3044\u305f\u3053\u3068\u304c\u5831\u544a\u3055\u308c\u3066\u3044\u307e\u3059<\/a>\u3002<\/p>\n<p>\u3053\u308c\u307e\u3067\u306e\u4f8b\u3068\u540c\u69d8\u306b\u3001Emotet C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u3082\u306e\u3068\u540c\u30582\u7a2e\u985e\u306eHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u898b\u3064\u304b\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306epcap\u306b\u306f\u3053\u306e\u307b\u304b\u306bQakbot\u611f\u67d3\u306e\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u3053\u3067\u3082\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u3001\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u3044\u3063\u3066Qakbot\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044 (\u56f331\u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_116736\" aria-describedby=\"caption-attachment-116736\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116737 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-60.jpeg\" alt=\"\u56f331 4\u3064\u76ee\u306epcap\u306b\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u5f8c\u3001\u5217\u8868\u793a\u3092\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u3044\u3063\u3066Qakbot\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u78ba\u8a8d\u3057\u3066\u3044\u308b\u3068\u3053\u308d\" width=\"900\" height=\"588\" \/><figcaption id=\"caption-attachment-116736\" class=\"wp-caption-text\">\u56f331 4\u3064\u76ee\u306epcap\u306b\u300cbasic\u300dWeb\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u5f8c\u3001\u5217\u8868\u793a\u3092\u4e0b\u306b\u30b9\u30af\u30ed\u30fc\u30eb\u3057\u3066\u3044\u3063\u3066Qakbot\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u78ba\u8a8d\u3057\u3066\u3044\u308b\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u3059\u3067\u306bQakbot\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u3064\u3044\u3066\u306f\u300e<a href=\"https:\/\/unit42.paloaltonetworks.jp\/tutorial-qakbot-infection\/\">Wireshark\u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 7: Qakbot\u611f\u67d3\u306e\u8abf\u67fb<\/a>\u300f\u3067\u30ec\u30d3\u30e5\u30fc\u6e08\u307f\u3067\u3059\u304c\u3001\u3053\u3053\u3067\u7c21\u5358\u306b\u304a\u3055\u3089\u3044\u3057\u3066\u304a\u304d\u307e\u3057\u3087\u3046\u3002Qakbot\u306e\u4e00\u822c\u7684\u306a\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u306b\u306f\u6b21\u306e\u3082\u306e\u304c\u3042\u3052\u3089\u308c\u307e\u3059\u3002<\/p>\n<ul>\n<li>HTTPS\u306e\u6a19\u6e96\/\u975e\u6a19\u6e96TCP\u30dd\u30fc\u30c8\u3092\u4ecb\u3057\u305fHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<li>Qakbot HTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8a3c\u660e\u66f8\u30c7\u30fc\u30bf\u306eIssuer\u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u5024\u304c\u6b63\u5e38\u306a\u5185\u5bb9\u3068\u306f\u7570\u306a\u3063\u3066\u304a\u308a\u3001\u8a3c\u660e\u66f8\u3082\u7c73\u56fd\u306b\u62e0\u70b9\u3092\u7f6e\u304f\u8a8d\u8a3c\u5c40\u304c\u767a\u884c\u3057\u305f\u3082\u306e\u3067\u306f\u306a\u3044<\/li>\n<li>65400\/tcp\u7d4c\u7531\u306eTCP\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/li>\n<li>2020\u5e7411\u6708\u4e0b\u65ec\u4ee5\u524d\u306fQakbot\u306f\u3088\u304f<span style=\"font-family: 'courier new', courier, monospace;\">cdn.speedof[.]me<\/span>\u3078\u306eHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u751f\u6210\u3057\u3066\u3044\u305f<\/li>\n<li>2020\u5e7411\u6708\u4e0b\u65ec\u4ee5\u524d\u306fQakbot\u306f\u3088\u304f<span style=\"font-family: 'courier new', courier, monospace;\">a.strandsglobal[.]com<\/span>\u3078\u306eHTTP GET\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u751f\u6210\u3057\u3066\u3044\u305f<\/li>\n<\/ul>\n<p>\u3053\u308c\u3089\u306e\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u306f\u6b21\u306eWireshark\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3059\u308b\u3068\u7c21\u5358\u306b\u898b\u3064\u304b\u308a\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">tls.handshake.type eq 11 and !(x509sat.CountryName == US)<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">tcp.port eq 65400<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">tls.handshake.extensions_server_name contains speedof<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">http.host contains strandsglobal<\/span><\/li>\n<\/ul>\n<p>\u56f332\u304b\u3089\u56f335\u306f\u3001\u4e0a\u8a18\u306e\u5404\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u305f\u7d50\u679c\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_116738\" aria-describedby=\"caption-attachment-116738\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116739 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-61.jpeg\" alt=\"\u56f332 Qakbot\u304c\u751f\u6210\u3057\u305fHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u5185\u306e\u6b63\u5e38\u3067\u306a\u3044\u8a3c\u660e\u66f8\u306eIssuer\u30c7\u30fc\u30bf\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u3066\u691c\u7d22\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"764\" \/><figcaption id=\"caption-attachment-116738\" class=\"wp-caption-text\">\u56f332 Qakbot\u304c\u751f\u6210\u3057\u305fHTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u5185\u306e\u6b63\u5e38\u3067\u306a\u3044\u8a3c\u660e\u66f8\u306eIssuer\u30c7\u30fc\u30bf\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u3066\u691c\u7d22\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>1\u3064\u76ee\u306e\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u305f\u7d50\u679c\u304c\u56f332\u3067\u3059\u304c\u3001\u3053\u3053\u3067\u306f<span style=\"font-family: 'courier new', courier, monospace;\">71.80.66[.]107<\/span>\u304b\u3089\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304c\u5217\u8868\u793a\u3055\u308c\u3066\u3044\u3066\u3001\u30d5\u30ec\u30fc\u30e0\u304c\u8907\u6570\u3042\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002\u5404\u30d5\u30ec\u30fc\u30e0\u3067\u30d1\u30b1\u30c3\u30c8\u306e\u8a73\u7d30\u30da\u30a4\u30f3 (Packet Details \u30da\u30a4\u30f3) \u3092\u63a2\u7d22\u3057\u3001\u8a3c\u660e\u66f8\u306eIssuer\u30c7\u30fc\u30bf\u306b\u7570\u5e38\u304c\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<figure id=\"attachment_116740\" aria-describedby=\"caption-attachment-116740\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116741 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-62.jpeg\" alt=\"\u56f333 65400\/tcp\u7d4c\u7531\u306eQakbot\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\" width=\"900\" height=\"560\" \/><figcaption id=\"caption-attachment-116740\" class=\"wp-caption-text\">\u56f333 65400\/tcp\u7d4c\u7531\u306eQakbot\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d<\/figcaption><\/figure>\n<p>\u56f333\u306f\u300165400\/tcp\u7d4c\u7531\u306eQakbot\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306eTCP\u30b9\u30c8\u30ea\u30fc\u30e0\u30921\u3064\u8868\u793a\u3055\u305b\u305f\u3068\u3053\u308d\u3067\u3059\u304c\u3001\u3053\u306e\u30b9\u30c8\u30ea\u30fc\u30e0\u306b\u306f\u3001Qakbot\u611f\u67d3Windows\u30db\u30b9\u30c8\u306e\u30d1\u30d6\u30ea\u30c3\u30afIP\u30a2\u30c9\u30ec\u30b9\u3068\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u8b58\u5225\u6587\u5b57\u5217\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><figure id=\"attachment_116744\" aria-describedby=\"caption-attachment-116744\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-116745 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2021\/01\/word-image-64.jpeg\" alt=\"\u56f335 a.stransglobal[.]com\u3078\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\u30022020\u5e7411\u6708\u4e0b\u65ec\u4ee5\u524d\u306eQakbot\u306b\u3088\u304f\u751f\u6210\u3055\u308c\u3066\u3044\u305f\u3082\u306e\u3002\" width=\"900\" height=\"265\" \/><figcaption id=\"caption-attachment-116744\" class=\"wp-caption-text\">\u56f335 a.stransglobal[.]com\u3078\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u305f\u3068\u3053\u308d\u30022020\u5e7411\u6708\u4e0b\u65ec\u4ee5\u524d\u306eQakbot\u306b\u3088\u304f\u751f\u6210\u3055\u308c\u3066\u3044\u305f\u3082\u306e\u3002<\/figcaption><\/figure>Emotet\u306fTrickbot\u3084Qakbot\u3092\u30c9\u30ed\u30c3\u30d7\u3059\u308b\u3053\u3068\u304c\u591a\u3044\u3067\u3059\u304c\u3001Gootkit\u3084IcedID\u306a\u3069\u3001\u5225\u306e\u7a2e\u985e\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u3092\u30c9\u30ed\u30c3\u30d7\u3059\u308b\u3053\u3068\u3082\u3042\u308b\u306e\u3067\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u4eca\u56de\u306fEmotet\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u542b\u3080pcap\u3092\u4f7f\u3063\u3066\u540c\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8b58\u5225\u3059\u308b\u65b9\u6cd5\u3092\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002\u6700\u8fd1\u306e5\u3064\u306epcap\u3092\u78ba\u8a8d\u3057\u3001Emotet\u611f\u67d3\u5f8c\u306eC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306b\u3088\u3063\u3066\u5f15\u304d\u8d77\u3053\u3055\u308c\u308bHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u985e\u4f3c\u70b9\u304c\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30d1\u30bf\u30fc\u30f3\u306f\u540c\u30de\u30eb\u30a6\u30a7\u30a2\u306b\u3064\u3044\u3066\u304b\u306a\u308a\u7279\u5fb4\u7684\u306a\u3082\u306e\u306a\u306e\u3067\u3001\u3053\u308c\u3089\u3092\u4f7f\u3048\u3070\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306eEmotet\u611f\u67d3\u3092\u8b58\u5225\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u3053\u3067\u306f\u307e\u305f\u3001\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8 \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3084\u3001\u611f\u67d3\u30db\u30b9\u30c8\u306b\u30c9\u30ed\u30c3\u30d7\u3055\u308c\u305f\u8907\u6570\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30d5\u30a1\u30df\u30ea\u306a\u3069\u306e\u3001Emotet\u95a2\u9023\u306e\u611f\u67d3\u5f8c\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u3064\u3044\u3066\u3082\u78ba\u8a8d\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u7591\u308f\u3057\u3044\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c02\u9580\u5bb6\u304c\u78ba\u8a8d\u3059\u308b\u3055\u3044\u306b\u3053\u3046\u3057\u305f\u77e5\u8b58\u304c\u3042\u308c\u3070\u3001Emotet\u611f\u67d3\u3092\u3088\u308a\u3046\u307e\u304f\u691c\u51fa\u30fb\u6355\u6349\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u300eWireshark\u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u300f\u30b7\u30ea\u30fc\u30ba\u306e\u4ee5\u524d\u306e\u8b1b\u5ea7\u306f\u4ee5\u4e0b\u304b\u3089\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/unit42-customizing-wireshark-changing-column-display\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 1: Wireshark\u306e\u8868\u793a\u5217\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3059\u308b<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/using-wireshark-display-filter-expressions\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 2: \u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u8abf\u67fb\u306b\u5f79\u7acb\u3064\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u8a2d\u5b9a<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/using-wireshark-identifying-hosts-and-users\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 3: \u30db\u30b9\u30c8\u3068\u30e6\u30fc\u30b6\u30fc\u3092\u7279\u5b9a\u3059\u308b<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/using-wireshark-exporting-objects-from-a-pcap\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 4: Pcap\u304b\u3089\u306e\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u306e\u30a8\u30af\u30b9\u30dd\u30fc\u30c8<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/wireshark-tutorial-examining-trickbot-infections\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 5: Trickbot\u611f\u67d3\u306e\u8abf\u67fb<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/wireshark-tutorial-examining-ursnif-infections\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 6: Ursnif\u611f\u67d3\u306e\u8abf\u67fb<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/tutorial-qakbot-infection\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 7: Qakbot\u611f\u67d3\u306e\u8abf\u67fb<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/wireshark-tutorial-decrypting-https-traffic\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 8: HTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u5fa9\u53f7<\/a><\/li>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/wireshark-tutorial-dridex-infection-traffic\/\">Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7 9: Dridex\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u672c\u30b7\u30ea\u30fc\u30ba\u306f\u3001\u7591\u308f\u3057\u3044\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u8abf\u67fb\u3084\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30d1\u30b1\u30c3\u30c8\u30ad\u30e3\u30d7\u30c1\u30e3\uff08pcap\uff09\u306e\u78ba\u8a8d\u3092\u696d\u52d9\u3067\u884c\u3063\u3066\u304a\u3089\u308c\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c02\u9580\u5bb6\u3092\u8aad\u8005\u3068\u3057\u3066\u60f3\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u305f\u3081\u672c\u7a3f\u3067\u306e\u624b\u9806\u8aac\u660e\u306f\u8aad<\/p>\n","protected":false},"author":35,"featured_media":134398,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4438,4435],"tags":[5397,4617],"product_categories":[],"coauthors":[485],"class_list":["post-116757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-tutorials-ja","category-learning-hub-ja","tag-emotet-ja","tag-wireshark-tutorial-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb<\/title>\n<meta name=\"description\" content=\"\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fcEmotet\u306f\u69d8\u3005\u306a\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u3066\u9032\u5316\u3057\u30c9\u30ed\u30c3\u30d1\u3084\u307b\u304b\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03\u6a5f\u80fd\u306a\u3069\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u4eca\u56de\u306eWireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u3067\u306f\u3001Emotet\u3092\u30d9\u30fc\u30b9\u306b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u3001Trickbot\u3001Qabot\u306a\u3069\u306e\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u89e3\u6790\u3059\u308b\u65b9\u6cd5\u3092\u5b66\u3073\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb\" \/>\n<meta property=\"og:description\" content=\"\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fcEmotet\u306f\u69d8\u3005\u306a\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u3066\u9032\u5316\u3057\u30c9\u30ed\u30c3\u30d1\u3084\u307b\u304b\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03\u6a5f\u80fd\u306a\u3069\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u4eca\u56de\u306eWireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u3067\u306f\u3001Emotet\u3092\u30d9\u30fc\u30b9\u306b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u3001Trickbot\u3001Qabot\u306a\u3069\u306e\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u89e3\u6790\u3059\u308b\u65b9\u6cd5\u3092\u5b66\u3073\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-19T14:00:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-25T11:28:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/02_Tutorial_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Brad Duncan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb","description":"\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fcEmotet\u306f\u69d8\u3005\u306a\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u3066\u9032\u5316\u3057\u30c9\u30ed\u30c3\u30d1\u3084\u307b\u304b\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03\u6a5f\u80fd\u306a\u3069\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u4eca\u56de\u306eWireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u3067\u306f\u3001Emotet\u3092\u30d9\u30fc\u30b9\u306b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u3001Trickbot\u3001Qabot\u306a\u3069\u306e\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u89e3\u6790\u3059\u308b\u65b9\u6cd5\u3092\u5b66\u3073\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/","og_locale":"ja_JP","og_type":"article","og_title":"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb","og_description":"\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fcEmotet\u306f\u69d8\u3005\u306a\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u3066\u9032\u5316\u3057\u30c9\u30ed\u30c3\u30d1\u3084\u307b\u304b\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03\u6a5f\u80fd\u306a\u3069\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u4eca\u56de\u306eWireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u3067\u306f\u3001Emotet\u3092\u30d9\u30fc\u30b9\u306b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u3001Trickbot\u3001Qabot\u306a\u3069\u306e\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u89e3\u6790\u3059\u308b\u65b9\u6cd5\u3092\u5b66\u3073\u307e\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/","og_site_name":"Unit 42","article_published_time":"2021-01-19T14:00:17+00:00","article_modified_time":"2025-08-25T11:28:14+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/02_Tutorial_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Brad Duncan","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/"},"author":{"name":"Brad Duncan","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/66a2d5ad3475220e098802b8b82a6b5b"},"headline":"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb","datePublished":"2021-01-19T14:00:17+00:00","dateModified":"2025-08-25T11:28:14+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/"},"wordCount":1173,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/02_Tutorial_Category_1920x900.jpg","keywords":["Emotet","Wireshark Tutorial"],"articleSection":["\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb","\u30e9\u30fc\u30cb\u30f3\u30b0 \u30cf\u30d6"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/","name":"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/02_Tutorial_Category_1920x900.jpg","datePublished":"2021-01-19T14:00:17+00:00","dateModified":"2025-08-25T11:28:14+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/66a2d5ad3475220e098802b8b82a6b5b"},"description":"\u30a4\u30f3\u30d5\u30a9\u30b9\u30c6\u30a3\u30fc\u30e9\u30fcEmotet\u306f\u69d8\u3005\u306a\u6a5f\u80fd\u3092\u8ffd\u52a0\u3057\u3066\u9032\u5316\u3057\u30c9\u30ed\u30c3\u30d1\u3084\u307b\u304b\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u914d\u5e03\u6a5f\u80fd\u306a\u3069\u3092\u6301\u3063\u3066\u3044\u307e\u3059\u3002\u4eca\u56de\u306eWireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea7\u3067\u306f\u3001Emotet\u3092\u30d9\u30fc\u30b9\u306b\u30b9\u30d1\u30e0\u30dc\u30c3\u30c8\u3001Trickbot\u3001Qabot\u306a\u3069\u306e\u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u89e3\u6790\u3059\u308b\u65b9\u6cd5\u3092\u5b66\u3073\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/02_Tutorial_Category_1920x900.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/02_Tutorial_Category_1920x900.jpg","width":1920,"height":900,"caption":"A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/wireshark-tutorial-emotet-infection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"Wireshark \u306b\u3088\u308b\u30d1\u30b1\u30c3\u30c8\u89e3\u6790\u8b1b\u5ea710: Emotet \u611f\u67d3\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u8abf\u67fb"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/66a2d5ad3475220e098802b8b82a6b5b","name":"Brad Duncan","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/a6a5d4eca3047f1862b91c34bc0e8f57","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2017\/09\/Duncan-bio-picture-1-copy-150x150.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2017\/09\/Duncan-bio-picture-1-copy-150x150.jpg","caption":"Brad Duncan"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/bduncan\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/116757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/35"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=116757"}],"version-history":[{"count":8,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/116757\/revisions"}],"predecessor-version":[{"id":153792,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/116757\/revisions\/153792"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134398"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=116757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=116757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=116757"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=116757"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=116757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}