Bleeping Computer¤Ï5·î27Æü(Êƹñ»þ´Ö)¡¢¡ÖQBot malware abuses Windows WordPad EXE to infect devices¡×¤Ë¤ª¤¤¤Æ¡¢QBot¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ë¿·¤¿¤Ê¥Õ¥£¥Ã¥·¥ó¥°¥­¥ã¥ó¥Ú¡¼¥ó¤¬Å¸³«¤µ¤ì¤Æ¤¤¤ë¤È¤·¤Æ¡¢Ãí°Õ¤ò¸Æ¤Ó³Ý¤±¤¿¡£DLL¥Ï¥¤¥¸¥ã¥Ã¥¯¤È¸Æ¤Ð¤ì¤ë¹¶·â¼êË¡¤òÍѤ¤¤Æ¥³¥ó¥Ô¥å¡¼¥¿¤Ë¥Þ¥ë¥¦¥§¥¢¤ò´¶À÷¤µ¤»¤ë¶¼°Ò¤¬Êó¹ð¤µ¤ì¤Æ¤¤¤ë¡£

QBot malware abuses Windows WordPad EXE to infect devices

QBot¡Ê¤Þ¤¿¤ÏQakbot¡Ë¤ÏWindows¥Þ¥ë¥¦¥§¥¢¤Î°ì¼ï¤Ç¥Ð¥ó¥­¥ó¥°·¿¥È¥í¥¤¤ÎÌÚÇϤȤ·¤ÆÅо줷¡¢¸å¤Ë¥Þ¥ë¥¦¥§¥¢¥É¥í¥Ã¥Ñ¡¼¤ÎÌò³ä¤âô¤¦¤è¤¦¿Ê²½¤·¤¿°­°Õ¤Î¤¢¤ë¥×¥í¥°¥é¥à¡£Black Basta¡¢Egregor¡¢Prolock¤È¤¤¤Ã¤¿¥é¥ó¥µ¥à¥¦¥§¥¢¥°¥ë¡¼¥×¤Ê¤É¤¬¤³¤Î¥Þ¥ë¥¦¥§¥¢¤òÍøÍѤ·¡¢´ë¶È¥Í¥Ã¥È¥ï¡¼¥¯¤Ø¤Î½é´ü¥¢¥¯¥»¥¹¤òÀ®¸ù¤µ¤»¡¢¶²³å¤ò¹Ô¤¦¤È¤µ¤ì¤Æ¤¤¤ë¡£

DLL¥Ï¥¤¥¸¥ã¥Ã¥¯¤Ï¹¶·â¼Ô¤¬Àµµ¬¤ÎDLL¤ÈƱ̾¤Î°­°Õ¤Î¤¢¤ëDLL¤òºîÀ®¤·¡¢¤½¤Î¥Õ¥¡¥¤¥ë¤òWindows¤Î½é´ü¸¡º÷¥Ñ¥¹(Ä̾ï¤Ï¼Â¹Ô¥Õ¥¡¥¤¥ë¤ÈƱ¤¸¥Õ¥©¥ë¥À)¤ËÇÛÃÖ¤¹¤ë¥µ¥¤¥Ð¡¼¹¶·â¡£¥æ¡¼¥¶¡¼¤¬¼Â¹Ô¥Õ¥¡¥¤¥ë¤òµ¯Æ°¤¹¤ë¤È¡¢Àµµ¬¤ÎDLL¤ÎÂå¤ï¤ê¤Ë¶¼°Ò¼Ô¤¬ºîÀ®¤·¤¿DLL¤¬Æɤ߹þ¤Þ¤ì¡¢¤½¤ÎÃæ¤Ë´Þ¤Þ¤ì¤ë°­°Õ¤Î¤¢¤ë¥³¥Þ¥ó¥É¤¬¼Â¹Ô¤µ¤ì¤ë»ÅÁȤߤȤʤäƤ¤¤ë¡£

¥»¥­¥å¥ê¥Æ¥£ÀìÌç²È¤Ë¤è¤êWindows 10¤Î¥ï¡¼¥É¥Ñ¥Ã¥É¤ò°­ÍѤ·¡¢DLL¥Ï¥¤¥¸¥ã¥Ã¥¯¤ò¹Ô¤¦¿·¤¿¤ÊQBot¥Õ¥£¥Ã¥·¥ó¥°¥­¥ã¥ó¥Ú¡¼¥ó¤¬Å¸³«¤µ¤ì¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤Ã¤¿¡£¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤Ë¤Ï¥Õ¥¡¥¤¥ë¤ò¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¤¿¤á¤Î¥ê¥ó¥¯¤¬´Þ¤Þ¤ì¤Æ¤ª¤ê¡¢¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¥é¥ó¥À¥à¤Ê̾Á°¤ÎZIP¥¢¡¼¥«¥¤¥Ö¤¬¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤ë¤È¤¤¤¦¡£

ZIP¥Õ¥¡¥¤¥ë¤Ë¤Ïdocument.exe¤Èedputil.dll¤È¤¤¤¦2¤Ä¤Î¥Õ¥¡¥¤¥ë¤¬¥¢¡¼¥«¥¤¥Ö¤µ¤ì¤Æ¤ª¤ê¡¢document.exe¤ÏWindows 10¤Î¥ï¡¼¥É¥Ñ¥Ã¥É¤òµ¯Æ°¤¹¤ë¤¿¤á¤Î¥Õ¥¡¥¤¥ë¤È¤µ¤ì¡¢edputil.dll¤ÏDLL¥Ï¥¤¥¸¥ã¥Ã¥¯¤Ë»ÈÍѤµ¤ì¤ëDLL¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë¤³¤È¤¬È½ÌÀ¤·¤Æ¤¤¤ë¡£document.exe¤ò¼Â¹Ô¤¹¤ë¤È¥ï¡¼¥É¥Ñ¥Ã¥É¤ÎÀµµ¬¤ÎDLL¥Õ¥¡¥¤¥ë¤Ç¤Ï¤Ê¤¯¡¢Âå¤ï¤ê¤Ëedputil.dll¤¬¼Â¹Ô¤µ¤ì¡¢¥Ð¥Ã¥¯¥°¥é¥¦¥ó¥É¤ÇQBot¤¬¼Â¹Ô¤µ¤ì¤Æ¤·¤Þ¤¦¤È¤Î¤³¤È¤À¡£

DLL¥Ï¥¤¥¸¥ã¥Ã¥¯¤¬ÍѤ¤¤é¤ì¤¿ÇطʤȤ·¤Æ¡¢¶¼°Ò¼Ô¤¬Windows 10¤Î¿®ÍêÀ­¤Î¹â¤¤¥×¥í¥°¥é¥à¤Ç¤¢¤ë¥ï¡¼¥É¥Ñ¥Ã¥É¤ò°­ÍѤ¹¤ë¤³¤È¤Ç¥»¥­¥å¥ê¥Æ¥£¥½¥Õ¥È¥¦¥§¥¢¤Ë¤è¤ë¸¡½Ð¤ò²óÈò¤Ç¤­¤ë¤È¸«¹þ¤ó¤À¤È¹Í¤¨¤é¤ì¤Æ¤¤¤ë¡£

´ë¶È¤äÁÈ¿¥¤ÏÉÔ¿³¤Ê¥á¡¼¥ë¤äÀµµ¬¤ÎURL¤Ç¤Ï¤Ê¤¤¥é¥ó¥Ç¥£¥ó¥°¥Ú¡¼¥¸¤äWeb¥µ¥¤¥È¤ËͶƳ¤·¤Æ¤¯¤ë¥á¡¼¥ë¤Ê¤É¤ËÃí°Õ¤·¡¢¥á¡¼¥ëÆâ¤Î¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤·¤¿¤ê¡¢ÅºÉÕ¥Õ¥¡¥¤¥ë¤ò³«¤¤¤¿¤ê¤·¤Ê¤¤¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£