¥¦¥¯¥é¥¤¥ÊÀ¯ÉܤΥ³¥ó¥Ô¥å¡¼¥¿¶ÛµÞÂбþ¥Á¡¼¥à¤Ç¤¢¤ëCERT-UA (Computer Emergency Response Team of Ukraine)¤Ï5·î9Æü(Êƹñ»þ´Ö)¡¢ÅŻҥ᡼¥ë¤ò²ð¤·¤Æ¡ÖJester Stealer¡×¤È¸Æ¤Ð¤ì¤ë¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ë¿·¤·¤¤¥µ¥¤¥Ð¡¼¹¶·â¥­¥ã¥ó¥Ú¡¼¥ó¤ò³Îǧ¤·¤Æ¤¤¤ë¤È¤·¤Æ·Ù¹ð¤òÂ¥¤·¤¿¡£

§®§Ñ§ã§à§Ó§Ö §â§à§Ù§á§à§Ó§ã§ð§Õ§Ø§Ö§ß§ß§ñ §ê§Üі§Õ§Ý§Ú§Ó§àї §á§â§à§Ô§â§Ñ§Þ§Ú JesterStealer §Ù §Ó§Ú§Ü§à§â§Ú§ã§ä§Ñ§ß§ß§ñ§Þ §ä§Ö§Þ§Ñ§ä§Ú§Ü§Ú §çі§Þі§é§ß§àї §Ñ§ä§Ñ§Ü§Ú (CERT-UA#4625)

Ʊ¥­¥ã¥ó¥Ú¡¼¥ó¤ÇÁ÷¿®¤µ¤ì¤ëÅŻҥ᡼¥ë¤Ï¡Ö²½³Ø¹¶·â¡×¤Ë´ØÏ¢¤¹¤ë¥È¥Ô¥Ã¥¯¤òÁõ¤Ã¤Æ¤ª¤ê¡¢¥Þ¥¯¥í¤ò´Þ¤àMicrosoft Excel¥Õ¥¡¥¤¥ë¤Ø¤Î¥ê¥ó¥¯¤¬´Þ¤Þ¤ì¤Æ¤¤¤ë¤È¤¤¤¦¡£¤³¤Î¥ê¥ó¥¯¤Ë¥¢¥¯¥»¥¹¤·¤Æ¥É¥­¥å¥á¥ó¥È¤ò³«¤¯¤È¡¢¥Þ¥¯¥í¤òÍ­¸ú¤Ë¤¹¤ë¤³¤È¤¬µá¤á¤é¤ì¡¢Æ±°Õ¤¹¤ë¤È°­°Õ¤ò»ý¤Ã¤¿exe¥Õ¥¡¥¤¥ë¤¬¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤Æ¡ÖJester Stealer¡×¤È¸Æ¤Ð¤ì¤ë¥Þ¥ë¥¦¥§¥¢¤Ë´¶À÷¤¹¤ë¡£exe¥Õ¥¡¥¤¥ë¤ÎÇÛÉۤϿ¯³²¤µ¤ì¤¿Web¥µ¥¤¥È¤Ë¤è¤Ã¤Æ¹Ô¤ï¤ì¤Æ¤¤¤ëÌÏÍͤÀ¡£

Jester Stealer¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ë¹¶·â¥­¥ã¥ó¥Ú¡¼¥ó¡¡°úÍÑ¡§CERT-UA

Jester Stealer¤Ï¡¢¿¯³²¤·¤¿PC¤ÎWeb¥Ö¥é¥¦¥¶¤«¤é¥Ñ¥¹¥ï¡¼¥É¤ä¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊó¡¢Cookie¤ÎÃÍ¡¢¼«Æ°ÆþÎÏÍѤËÅÐÏ¿¤µ¤ì¤¿¾ðÊó¤Ê¤É¤òÅð¤ß½Ð¤¹¾ðÊóÀà¼è·¿¤Î¥Þ¥ë¥¦¥§¥¢¤Ç¤¢¤ë¡£Web¥Ö¥é¥¦¥¶°Ê³°¤Ë¤â¡¢°ìÉô¤ÎÅŻҥ᡼¥ë¥¯¥é¥¤¥¢¥ó¥È¤ä¥á¥Ã¥»¥ó¥¸¥ã¡¼¥¢¥×¥ê¡¢¥Ñ¥¹¥ï¡¼¥É¥Þ¥Í¡¼¥¸¥ã¡¼¡¢°Å¹æ»ñ»º¥¦¥©¥ì¥Ã¥È¡¢¥²¡¼¥à¥¢¥×¥ê¤Ê¤É¤âɸŪ¤Ë¤¹¤ë¡£

¼ý½¸¤µ¤ì¤¿¥Ç¡¼¥¿¤Ï¥·¥¹¥Æ¥à¥á¥â¥ê¤Ë¥³¥Ô¡¼¤µ¤ì¡¢³°Éô¤Î¥µ¡¼¥Ð¤ËÁ÷¿®¤µ¤ì¤ë¡£Jester Stealer¤Ë¤Ï±Ê³²½¤Î»ÅÁȤߤϤʤ¯¡¢Áàºî¤¬´°Î»¤¹¤ë¤È¼«Æ°Åª¤Ëºï½ü¤µ¤ì¤ë¤¿¤á¡¢Àµµ¬¤Î¥æ¡¼¥¶¡¼¤¬¿¯³²¤µ¤ì¤¿¤³¤È¤Ëµ¤¤Å¤­¤Ë¤¯¤¤¤È¤¤¤¦ÆÃħ¤¬¤¢¤ë¡£

CERT-UA¤Ï5·î6Æü¤Ë¤â¡¢¡ÖCredoMap_v2¡×¤È¸Æ¤Ð¤ì¤ë¾ðÊóÀà¼è·¿¤Î¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ëÊ̤Υµ¥¤¥Ð¡¼¹¶·â¥­¥ã¥ó¥Ú¡¼¥ó¤Ë¤Ä¤¤¤Æ·Ù¹ð¤òȯ¤·¤Æ¤¤¤ë¡£CredoMap_v2¤ò»È¤Ã¤¿¹¶·â¤Ë¤Ä¤¤¤Æ¤Ï¡¢¥í¥·¥¢¤¬»Ù±ç¤¹¤ëAPT28¡ÊFancy Bear¡¢STRONTIUM¡¢Pawn Storm¤Ê¤É¤ÎÊÌ̾¤â¤¢¤ë¡Ë¤È¸Æ¤Ð¤ì¤ë¥µ¥¤¥Ð¡¼¹¶·â¥°¥ë¡¼¥×¤Ë¤è¤ë¤â¤Î¤È¸«¤é¤ì¤Æ¤ª¤ê¡¢Jester Stealer¹¶·â¤Ë¤Ä¤¤¤Æ¤âCredoMap_v2¤Î¥±¡¼¥¹¤È¤ÎÎà»÷À­¤¬»ØŦ¤µ¤ì¤Æ¤¤¤ë¡£