LinuxÁÀ¤¦¥Þ¥¤¥Ë¥ó¥°¥Þ¥ë¥¦¥§¥¢¡¢¿·¤·¤¤PyPI¥Ñ¥Ã¥±¡¼¥¸¤«¤éȯ¸«
Fortinet¤Ï1·î3Æü(Êƹñ»þ´Ö)¡¢¡ÖThree New Malicious PyPI Packages Deploy CoinMiner on Linux Devices¡ÃFortiGuard Labs¡×¤Ë¤ª¤¤¤Æ¡¢Linux¤òɸŪ¤È¤·¤¿¥Þ¥¤¥Ë¥ó¥°¥Þ¥ë¥¦¥§¥¢¡ÖCoinMiner¡×¤ò´Þ¤à°°Õ¤Î¤¢¤ëPyPI¡ÊPython Package Index¡Ë¥Ñ¥Ã¥±¡¼¥¸¤òȯ¸«¤·¤¿¤ÈÊ󤸤¿¡£È¯¸«¤µ¤ì¤¿¥Ñ¥Ã¥±¡¼¥¸¤Ï¡Ömodularseven-1.0¡×¡¢¡Ödriftme-1.0¡×¡¢¡Öcatme-1.0¡×¤Î3¼ïÎà¤Ç¡¢¤¹¤Ù¤ÆƱ¤¸PyPI¥¢¥«¥¦¥ó¥È¡Ösastra¡×¤Ë¤è¤Ã¤ÆÇÛÉÛ¤µ¤ì¤¿¤È¤¤¤¦¡£
Three New Malicious PyPI Packages Deploy CoinMiner on Linux Devices¡ÃFortiGuard Labs
¡û¥Þ¥ë¥¦¥§¥¢¤¬È¯¸«¤µ¤ì¤¿PyPI¥Ñ¥Ã¥±¡¼¥¸¤Î³µÍ×
¤³¤ì¤é¥Ñ¥Ã¥±¡¼¥¸¤Ï¶¦Ä̤ι¶·â¼êË¡¤òºÎÍѤ·¤Æ¤ª¤ê¡¢²áµî¤Ëȯ¸«¤µ¤ì¤¿¡Öculturestreak¡×¥Ñ¥Ã¥±¡¼¥¸¤Î¹¶·â¼êË¡¤òƧ½±¤·¤Æ¤¤¤ë¤È¤µ¤ì¤ë¡£¹¶·â¤Ï¥Ñ¥Ã¥±¡¼¥¸¤Ë´Þ¤Þ¤ì¤ë¡Ö__init__.py¡×¥Õ¥¡¥¤¥ë¤òµ¯ÅÀ¤È¤·¡¢¹¶·â¼Ô¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤«¤é°°Õ¤Î¤¢¤ë¥¹¥¯¥ê¥×¥È¤ò¼èÆÀ¤·¤Æ¼Â¹Ô¤¹¤ë¡£
¤³¤Î¥¹¥¯¥ê¥×¥È¤Ï±Ê³À¤ò³ÎÊݤ¹¤ë¤¿¤á¤Ë¡¢¥æ¡¼¥¶¡¼¤Î¥·¥§¥ëÀßÄê¥Õ¥¡¥¤¥ë¡Ö~/.bashrc¡×¤ò½¤Àµ¤¹¤ë¡£¤³¤Î¤¿¤á¡¢°°Õ¤Î¤¢¤ë¥×¥í¥»¥¹¤ª¤è¤Ó¥Õ¥¡¥¤¥ë¤òºï½ü¤·¤Æ¤â¡¢¥í¥°¥¤¥ó»þ¤Ê¤É¤Ë¥Þ¥ë¥¦¥§¥¢¤¬·«¤êÊÖ¤·¼Â¹Ô¤µ¤ì¤ë¤³¤È¤Ë¤Ê¤ë¡£
ȯ¸«¤µ¤ì¤¿CoinMiner¤Ï2021ǯ¤ËVirusTotal¤ËÅÐÏ¿¤µ¤ì¤Æ¤ª¤ê¡¢Â¿¤¯¤Î¼çÍפʥ»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤«¤é¸¡½Ð¤¬²Äǽ¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤³¤Î¤¿¤á¡¢¥¢¥ó¥Á¥¦¥¤¥ë¥¹¥½¥Õ¥È¥¦¥§¥¢¤òƳÆþ¤¹¤ë¤³¤È¤Ç¡¢¤³¤Î¹¶·â¤ò¸¡½Ð¤Þ¤¿¤Ï²óÈò¤Ç¤¤ë²ÄǽÀ¤¬¤¢¤ë¡£
¥Þ¥ë¥¦¥§¥¢¤Î¥Ï¥Ã¥·¥åÃͤò¤â¤È¤ËVirusTotal¤ò¸¡º÷¤·¤¿·ë²Ì
¡û°ÂÁ´¤ËPyPI¥Ñ¥Ã¥±¡¼¥¸¤òÍøÍѤ¹¤ëÊýË¡
Fortinet¤Ïº£²ó¤ÎÄ´ºº·ë²Ì¤«¤é¡¢¤³¤Î¹¶·â¼êË¡¤¬·Ñ³Ū¤Ë²þÎɤµ¤ì¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ë¤È»ØŦ¡¢º£¸å¤âƱÍͤι¶·â¤¬È¯À¸¤¹¤ë²ÄǽÀ¤¬¤¢¤ë¤ÈÃí°Õ¤òÂ¥¤·¤Æ¤¤¤ë¡£PyPI¥Ñ¥Ã¥±¡¼¥¸¤ò³èÍѤ¹¤ë³«È¯¼Ô¤Ï¿®Íê¤Ç¤¤ë³«È¯¼Ô¤Î¥Ñ¥Ã¥±¡¼¥¸¤Î¤ß¤ò»ÈÍѤ·¡¢¤½¤ì°Ê³°¤Î¥Ñ¥Ã¥±¡¼¥¸¤ò»ÈÍѤ¹¤ë¤È¤¤Ï¥¤¥ó¥¹¥È¡¼¥ëÁ°¤ËÉÔ¿³¤Ê½èÍý¤¬´Þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¤«³Îǧ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£
¤Þ¤¿¡¢Fortinet¤ÏÄ´ºº¤Î²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡û¥Þ¥ë¥¦¥§¥¢¤¬È¯¸«¤µ¤ì¤¿PyPI¥Ñ¥Ã¥±¡¼¥¸¤Î³µÍ×
¤³¤ì¤é¥Ñ¥Ã¥±¡¼¥¸¤Ï¶¦Ä̤ι¶·â¼êË¡¤òºÎÍѤ·¤Æ¤ª¤ê¡¢²áµî¤Ëȯ¸«¤µ¤ì¤¿¡Öculturestreak¡×¥Ñ¥Ã¥±¡¼¥¸¤Î¹¶·â¼êË¡¤òƧ½±¤·¤Æ¤¤¤ë¤È¤µ¤ì¤ë¡£¹¶·â¤Ï¥Ñ¥Ã¥±¡¼¥¸¤Ë´Þ¤Þ¤ì¤ë¡Ö__init__.py¡×¥Õ¥¡¥¤¥ë¤òµ¯ÅÀ¤È¤·¡¢¹¶·â¼Ô¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤«¤é°°Õ¤Î¤¢¤ë¥¹¥¯¥ê¥×¥È¤ò¼èÆÀ¤·¤Æ¼Â¹Ô¤¹¤ë¡£
¤³¤Î¥¹¥¯¥ê¥×¥È¤Ï±Ê³À¤ò³ÎÊݤ¹¤ë¤¿¤á¤Ë¡¢¥æ¡¼¥¶¡¼¤Î¥·¥§¥ëÀßÄê¥Õ¥¡¥¤¥ë¡Ö~/.bashrc¡×¤ò½¤Àµ¤¹¤ë¡£¤³¤Î¤¿¤á¡¢°°Õ¤Î¤¢¤ë¥×¥í¥»¥¹¤ª¤è¤Ó¥Õ¥¡¥¤¥ë¤òºï½ü¤·¤Æ¤â¡¢¥í¥°¥¤¥ó»þ¤Ê¤É¤Ë¥Þ¥ë¥¦¥§¥¢¤¬·«¤êÊÖ¤·¼Â¹Ô¤µ¤ì¤ë¤³¤È¤Ë¤Ê¤ë¡£
ȯ¸«¤µ¤ì¤¿CoinMiner¤Ï2021ǯ¤ËVirusTotal¤ËÅÐÏ¿¤µ¤ì¤Æ¤ª¤ê¡¢Â¿¤¯¤Î¼çÍפʥ»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤«¤é¸¡½Ð¤¬²Äǽ¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤³¤Î¤¿¤á¡¢¥¢¥ó¥Á¥¦¥¤¥ë¥¹¥½¥Õ¥È¥¦¥§¥¢¤òƳÆþ¤¹¤ë¤³¤È¤Ç¡¢¤³¤Î¹¶·â¤ò¸¡½Ð¤Þ¤¿¤Ï²óÈò¤Ç¤¤ë²ÄǽÀ¤¬¤¢¤ë¡£
¥Þ¥ë¥¦¥§¥¢¤Î¥Ï¥Ã¥·¥åÃͤò¤â¤È¤ËVirusTotal¤ò¸¡º÷¤·¤¿·ë²Ì
¡û°ÂÁ´¤ËPyPI¥Ñ¥Ã¥±¡¼¥¸¤òÍøÍѤ¹¤ëÊýË¡
Fortinet¤Ïº£²ó¤ÎÄ´ºº·ë²Ì¤«¤é¡¢¤³¤Î¹¶·â¼êË¡¤¬·Ñ³Ū¤Ë²þÎɤµ¤ì¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ë¤È»ØŦ¡¢º£¸å¤âƱÍͤι¶·â¤¬È¯À¸¤¹¤ë²ÄǽÀ¤¬¤¢¤ë¤ÈÃí°Õ¤òÂ¥¤·¤Æ¤¤¤ë¡£PyPI¥Ñ¥Ã¥±¡¼¥¸¤ò³èÍѤ¹¤ë³«È¯¼Ô¤Ï¿®Íê¤Ç¤¤ë³«È¯¼Ô¤Î¥Ñ¥Ã¥±¡¼¥¸¤Î¤ß¤ò»ÈÍѤ·¡¢¤½¤ì°Ê³°¤Î¥Ñ¥Ã¥±¡¼¥¸¤ò»ÈÍѤ¹¤ë¤È¤¤Ï¥¤¥ó¥¹¥È¡¼¥ëÁ°¤ËÉÔ¿³¤Ê½èÍý¤¬´Þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¤«³Îǧ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£
¤Þ¤¿¡¢Fortinet¤ÏÄ´ºº¤Î²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£