ÀȼåÀ½¤Àµ¤ò¥¨¥µ¤ËÉÔÀµ¤ÊWordPress¤Î¥×¥é¥°¥¤¥óÇÛÉÛ¤¹¤ë¥Õ¥£¥Ã¥·¥ó¥°¤ËÃí°Õ
Patchstack¤Ï12·î3Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖFake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware¡×¤Ë¤ª¤¤¤Æ¡¢µ¶¤ÎÀȼåÀ¡ÖCVE-2023-45124¡×¤ò½¤Àµ¤¹¤ë¤È¤·¤Æ°°Õ¤Î¤¢¤ëWordPress¥×¥é¥°¥¤¥ó¤òÇÛÉÛ¤¹¤ëÂ絬ÌϤʥե£¥Ã¥·¥ó¥°¥¥ã¥ó¥Ú¡¼¥ó¤ò³Îǧ¤·¤¿¤È¤·¤ÆÃí°Õ´µ¯¤·¤¿¡£¤³¤Î¥¥ã¥ó¥Ú¡¼¥ó¤ÇÁ÷¿®¤µ¤ì¤ë¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤Ç¤Ï¡¢¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô(RCE: Remote Code Execution)¤ÎÀȼåÀ¤ò½¤Àµ¤¹¤ë¤È¼çÄ¥¤·¤Æ¤¤¤ë¡£
Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
Patchstack¤Ë¤è¤ë¤È¡¢¤³¤Î¥¥ã¥ó¥Ú¡¼¥ó¤ÇÁ÷ÉÕ¤µ¤ì¤ë¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤Ï¸ø¼°¤ÎWordPress¤«¤éÁ÷¤Ã¤¿¤è¤¦¤Ë¸«¤»¤«¤±¤Æ¤¤¤ë¤È¤¤¤¦¡£ÆâÍƤϡ¢WordPress¥µ¥¤¥È¤Ë¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô¤ÎÀȼåÀ¤¬³Îǧ¤µ¤ì¤¿¤¿¤á¡¢¼¡¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤Þ¤Ç¤Î´Ö¡¢»ØÄê¤Î¥×¥é¥°¥¤¥ó¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤è¤¦¤Ëµá¤á¤ë¤â¤Î¤È¤Ê¤Ã¤Æ¤¤¤ë¡£
¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤ÎÎã ¡¡°úÍÑ¡§Patchstack
¤³¤Î¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤ËµºÜ¤µ¤ì¤¿¥×¥é¥°¥¤¥ó¤Î¥À¥¦¥ó¥í¡¼¥É¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¡¢¸ø¼°¤ÎWordPress¥µ¥¤¥È¤Ë»÷¤»¤¿¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Ë¥ê¥À¥¤¥ì¥¯¥È¤µ¤ì¤ë¡£¤³¤Î¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Î¥É¥á¥¤¥ó̾¤Ï¡Öwordpress[.]secureplatform[.]org¡×¤ä¡Öen-gb-wordpress[.]org¡×¤È¤Ê¤Ã¤Æ¤ª¤ê¡¢¸ø¼°¥µ¥¤¥È¤È´Ö°ã¤¨¤ë¤è¤¦¤Ê¥É¥á¥¤¥ó̾¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤ÎÎã ¡¡°úÍÑ¡§Patchstack
¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Ç¤Ï¥×¥é¥°¥¤¥ó¤Î¥¢¥¯¥Æ¥£¥Ö¤Ê¥¤¥ó¥¹¥È¡¼¥ë¥æ¡¼¥¶¡¼¿ô¤ò50Ëü°Ê¾å¤Èɽ¼¨¤·¤Æ¤¤¤ë¤¬¡¢¤³¤ì¤Ï°Â¿´´¶¤òÍ¿¤¨¤ë¤¿¤á¤Ëµ¶¤Î¿ôÃͤòɽ¼¨¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢µ¶¤Î¥æ¡¼¥¶¡¼¥ì¥Ó¥å¤âɽ¼¨¤¹¤ëÅ°Äì¤Ö¤ê¤Ç¡¢Â¿¤¯¤Î¥æ¡¼¥¶¡¼¤¬¤³¤Î¥×¥é¥°¥¤¥ó¤Ë´¶¼Õ¤·¤Æ¤¤¤ë¤«¤Î¤è¤¦¤Ê°õ¾ÝÁàºî¤ò¹Ô¤Ã¤Æ¤¤¤ë¡£
Patchstack¤ÎʬÀϤˤè¤ë¤È¡¢¤³¤Î¥×¥é¥°¥¤¥ó¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ͸ú²½¤¹¤ë¤È¼¡¤Î½èÍý¤¬¼Â¹Ô¤µ¤ì¤ë¤È¤¤¤¦¡£
¿·¤·¤¯´ÉÍý¼Ô¸¢¸Â¤ò»ý¤Ä¥æ¡¼¥¶¡¼¡Öwpsecuritypatch¡×¤ò¥é¥ó¥À¥à¤Ê¥Ñ¥¹¥ï¡¼¥É¤È¶¦¤ËºîÀ®¤¹¤ë
´¶À÷¤·¤¿¥µ¥¤¥È¤ÎURL¤ÈÀèÄøºîÀ®¤·¤¿´ÉÍý¼Ô¤Î¥Ñ¥¹¥ï¡¼¥É¤òBase64¥¨¥ó¥³¡¼¥É¤·¤Æ¡¢¹¶·â¼Ô¤Î¥µ¡¼¥Ð¡Öwpgate[.]zip/wpapi¡×¤ØÁ÷¿®¤¹¤ë
¹¶·â¼Ô¤Î¥µ¡¼¥Ð¡Öwpgate[.]zip/runscan¡×¤«¤é¥Ð¥Ã¥¯¥É¥¢¤ò¥À¥¦¥ó¥í¡¼¥É¤·¡¢¥µ¥¤¥È¤Î¥ë¡¼¥È¤Ë¡Öwp-autoload.php¡×¤È¤·¤ÆÊݸ¤¹¤ë
¥×¥é¥°¥¤¥ó¤ò¥×¥é¥°¥¤¥ó¤Î°ìÍ÷¤«¤éÈóɽ¼¨¤Ë¤·¡¢ºîÀ®¤·¤¿´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤âÈóɽ¼¨¤Ë¤¹¤ë
¸½ºß¤Î¤È¤³¤í¡¢ÀßÃÖ¤µ¤ì¤¿¥Ð¥Ã¥¯¥É¥¢¤Î»ÈÍÑÌÜŪ¤Ï¤ï¤«¤Ã¤Æ¤¤¤Ê¤¤¡£¤·¤«¤·¤Ê¤¬¤é¡¢¾ÍèŪ¤Ë¤Ï¤µ¤é¤Ë°ÍѤµ¤ì¤ë²ÄǽÀ¤¬¹â¤¤¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤Ê¤ª¡¢¤³¤Î¥Ð¥Ã¥¯¥É¥¢¤Ï¡ÖGitHub - cr1f/P.A.S.-Fork: A modified version of the well-known webshell - P.A.S. by Profexer. Tries to solve the problem of detecting some requests and responses by various WAF/IDS.¡×¤È¤Û¤ÜƱÅù¤Î¤â¤Î¤È¤µ¤ì¤ë¡£
Patchstack¤Ï¡¢¥¥ã¥ó¥Ú¡¼¥ó¤È¥×¥é¥°¥¤¥ó¤ÎʬÀϤÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤¤¤ë¡£¤À¤¿¤·¡¢¤³¤ì¤é¾ðÊó¤Ï¹¶·â¼Ô¤Ë¤è¤Ã¤ÆÍưפËÊѹ¹¤Ç¤¤ë¤È¤·¤Æ»²¹ÍÄøÅ٤˳èÍѤ¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£
Patchstack¤Ë¤è¤ë¤È¡¢¤³¤Î¥¥ã¥ó¥Ú¡¼¥ó¤ÇÁ÷ÉÕ¤µ¤ì¤ë¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤Ï¸ø¼°¤ÎWordPress¤«¤éÁ÷¤Ã¤¿¤è¤¦¤Ë¸«¤»¤«¤±¤Æ¤¤¤ë¤È¤¤¤¦¡£ÆâÍƤϡ¢WordPress¥µ¥¤¥È¤Ë¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô¤ÎÀȼåÀ¤¬³Îǧ¤µ¤ì¤¿¤¿¤á¡¢¼¡¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤Þ¤Ç¤Î´Ö¡¢»ØÄê¤Î¥×¥é¥°¥¤¥ó¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤è¤¦¤Ëµá¤á¤ë¤â¤Î¤È¤Ê¤Ã¤Æ¤¤¤ë¡£
¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤ÎÎã ¡¡°úÍÑ¡§Patchstack
¤³¤Î¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤ËµºÜ¤µ¤ì¤¿¥×¥é¥°¥¤¥ó¤Î¥À¥¦¥ó¥í¡¼¥É¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¡¢¸ø¼°¤ÎWordPress¥µ¥¤¥È¤Ë»÷¤»¤¿¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Ë¥ê¥À¥¤¥ì¥¯¥È¤µ¤ì¤ë¡£¤³¤Î¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Î¥É¥á¥¤¥ó̾¤Ï¡Öwordpress[.]secureplatform[.]org¡×¤ä¡Öen-gb-wordpress[.]org¡×¤È¤Ê¤Ã¤Æ¤ª¤ê¡¢¸ø¼°¥µ¥¤¥È¤È´Ö°ã¤¨¤ë¤è¤¦¤Ê¥É¥á¥¤¥ó̾¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤ÎÎã ¡¡°úÍÑ¡§Patchstack
¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Ç¤Ï¥×¥é¥°¥¤¥ó¤Î¥¢¥¯¥Æ¥£¥Ö¤Ê¥¤¥ó¥¹¥È¡¼¥ë¥æ¡¼¥¶¡¼¿ô¤ò50Ëü°Ê¾å¤Èɽ¼¨¤·¤Æ¤¤¤ë¤¬¡¢¤³¤ì¤Ï°Â¿´´¶¤òÍ¿¤¨¤ë¤¿¤á¤Ëµ¶¤Î¿ôÃͤòɽ¼¨¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢µ¶¤Î¥æ¡¼¥¶¡¼¥ì¥Ó¥å¤âɽ¼¨¤¹¤ëÅ°Äì¤Ö¤ê¤Ç¡¢Â¿¤¯¤Î¥æ¡¼¥¶¡¼¤¬¤³¤Î¥×¥é¥°¥¤¥ó¤Ë´¶¼Õ¤·¤Æ¤¤¤ë¤«¤Î¤è¤¦¤Ê°õ¾ÝÁàºî¤ò¹Ô¤Ã¤Æ¤¤¤ë¡£
Patchstack¤ÎʬÀϤˤè¤ë¤È¡¢¤³¤Î¥×¥é¥°¥¤¥ó¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ͸ú²½¤¹¤ë¤È¼¡¤Î½èÍý¤¬¼Â¹Ô¤µ¤ì¤ë¤È¤¤¤¦¡£
¿·¤·¤¯´ÉÍý¼Ô¸¢¸Â¤ò»ý¤Ä¥æ¡¼¥¶¡¼¡Öwpsecuritypatch¡×¤ò¥é¥ó¥À¥à¤Ê¥Ñ¥¹¥ï¡¼¥É¤È¶¦¤ËºîÀ®¤¹¤ë
´¶À÷¤·¤¿¥µ¥¤¥È¤ÎURL¤ÈÀèÄøºîÀ®¤·¤¿´ÉÍý¼Ô¤Î¥Ñ¥¹¥ï¡¼¥É¤òBase64¥¨¥ó¥³¡¼¥É¤·¤Æ¡¢¹¶·â¼Ô¤Î¥µ¡¼¥Ð¡Öwpgate[.]zip/wpapi¡×¤ØÁ÷¿®¤¹¤ë
¹¶·â¼Ô¤Î¥µ¡¼¥Ð¡Öwpgate[.]zip/runscan¡×¤«¤é¥Ð¥Ã¥¯¥É¥¢¤ò¥À¥¦¥ó¥í¡¼¥É¤·¡¢¥µ¥¤¥È¤Î¥ë¡¼¥È¤Ë¡Öwp-autoload.php¡×¤È¤·¤ÆÊݸ¤¹¤ë
¥×¥é¥°¥¤¥ó¤ò¥×¥é¥°¥¤¥ó¤Î°ìÍ÷¤«¤éÈóɽ¼¨¤Ë¤·¡¢ºîÀ®¤·¤¿´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤âÈóɽ¼¨¤Ë¤¹¤ë
¸½ºß¤Î¤È¤³¤í¡¢ÀßÃÖ¤µ¤ì¤¿¥Ð¥Ã¥¯¥É¥¢¤Î»ÈÍÑÌÜŪ¤Ï¤ï¤«¤Ã¤Æ¤¤¤Ê¤¤¡£¤·¤«¤·¤Ê¤¬¤é¡¢¾ÍèŪ¤Ë¤Ï¤µ¤é¤Ë°ÍѤµ¤ì¤ë²ÄǽÀ¤¬¹â¤¤¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤Ê¤ª¡¢¤³¤Î¥Ð¥Ã¥¯¥É¥¢¤Ï¡ÖGitHub - cr1f/P.A.S.-Fork: A modified version of the well-known webshell - P.A.S. by Profexer. Tries to solve the problem of detecting some requests and responses by various WAF/IDS.¡×¤È¤Û¤ÜƱÅù¤Î¤â¤Î¤È¤µ¤ì¤ë¡£
Patchstack¤Ï¡¢¥¥ã¥ó¥Ú¡¼¥ó¤È¥×¥é¥°¥¤¥ó¤ÎʬÀϤÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤¤¤ë¡£¤À¤¿¤·¡¢¤³¤ì¤é¾ðÊó¤Ï¹¶·â¼Ô¤Ë¤è¤Ã¤ÆÍưפËÊѹ¹¤Ç¤¤ë¤È¤·¤Æ»²¹ÍÄøÅ٤˳èÍѤ¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£