Kaspersky Lab¤Ï1·î16Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖDetecting iOS malware via Shutdown.log file¡ÃSecurelist¡×¤Ë¤ª¤¤¤Æ¡¢iOS¤Ë´¶À÷¤·¤¿¥Þ¥ë¥¦¥§¥¢¤òÆÃÄꤹ¤ë¤¿¤á¤ÎʬÀϥġ¼¥ë¤ò¸ø³«¤·¤¿¡£iOS¤Ï¥»¥­¥å¥¢¤Êºî¤ê¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤¿¤á¡¢Ê¬ÀϤˤϰŹ沽¤µ¤ì¤¿¥Õ¥ë¥Ð¥Ã¥¯¥¢¥Ã¥×¥¤¥á¡¼¥¸¤«¡¢¥Í¥Ã¥È¥ï¡¼¥¯¥È¥é¥Õ¥£¥Ã¥¯¤ò´Ñ»¡¤¹¤ëɬÍפ¬¤¢¤Ã¤¿¡£¤·¤¿¤¬¤Ã¤Æ¡¢ÀìÌçÃμ±¡¢ÈñÍÑ¡¢»þ´Ö¤¬µá¤á¤é¤ì¡¢°ìÈ̥桼¥¶¡¼¤Ë¤è¤ëʬÀϤÏÆñ¤·¤¤¤È¤µ¤ì¤Æ¤­¤¿¡£º£²ó¡¢Kaspersky Lab¤ÏiOS¤Î¥·¥¹¥Æ¥à¥í¥°¡ÖShutdown.log¡×¤Ë´¶À÷¤Îº¯Àפ¬»Ä¤ë¤³¤È¤òÆÃÄꤷ¡¢¤³¤ì¤òʬÀϤ¹¤ë¥Ä¡¼¥ë¤ò³«È¯¤·¤Æ¸ø³«¤·¤¿¡£

Detecting iOS malware via Shutdown.log file¡ÃSecurelist

¡ûiOS¤Î¥·¥¹¥Æ¥à¥í¥°¡ÖShutdown.log¡×¤òʬÀÏ

Kaspersky Lab¤¬³«È¯¤·¤¿Ê¬Àϥġ¼¥ë¤Ï3ÅÀ¤Ç¡¢¡ÖGitHub - KasperskyLab/iShutdown¡×¤«¤éÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë¡£Ê¬ÀϤÎÂоݤȤʤëShutdown.log¤ÏiOS¤ÎºÆµ¯Æ°»þ¤ËºîÀ®¤µ¤ì¤ë¥¤¥Ù¥ó¥È¥í¥°¤Ç¡¢¡ÖSysdiagnose¡×¤Î¥¢¡¼¥«¥¤¥Ö¤È¤·¤Æ¼èÆÀ¤¹¤ë¤³¤È¤¬¤Ç¤­¤ë¡£Sysdiagnose¤Î¼èÆÀÊýË¡¤Ï¡¢¡ÖProfiles and Logs - Bug Reporting - Apple Developer¡×¤Î¡ÖSysdiagnose for iOS¡×¤Ë¤Æ¸ø³«¤µ¤ì¤Æ¤¤¤ë¡£¼èÆÀ¤·¤¿Sysdiagnose¤Ï¡¢ÀßÄê¤Î¡Ö¥×¥é¥¤¥Ð¥·¡¼¤È¥»¥­¥å¥ê¥Æ¥£¡×¢ª¡Ö²òÀϤȲþÁ±¡×¢ª¡Ö²òÀϥǡ¼¥¿¡×¤ËÊݸ¤µ¤ì¤ë¤¿¤á¡¢¤³¤³¤«¤é¼è¤ê½Ð¤¹(žÁ÷¤¹¤ë)¤³¤È¤Ë¤Ê¤ë¡£

ʬÀϥġ¼¥ë¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£

iShutdown_detect - Shutdown.logÆâ¤Î°Û¾ï¤ò¸¡½Ð¤¹¤ë¡£¥Þ¥ë¥¦¥§¥¢¤ÏºÆµ¯Æ°¤òÃ٤餻¤ë¤³¤È¤¬¤¢¤ê¡¢ºÆµ¯Æ°¤ÎÃٱ䤬3²ó¤òĶ¤¨¤ë¾ì¹ç¤ÏÄ̾ï¤È°Û¤Ê¤ëÆ°ºî¤ò¤·¤Æ¤¤¤ë²ÄǽÀ­¤¬¤¢¤ë¡£Â¾¤Ë¤â°Û¾ï¤Ê¥×¥í¥»¥¹¤Î¸ºß¤ò¸¡½Ð¤Ç¤­¤ë

iShutdown_parse - Sysdiagnose¥¢¡¼¥«¥¤¥Ö¤«¤éShutdown.log¤òÃê½Ð¤·¡¢²òÀϤγµÍפòÀ¸À®¤¹¤ë¡£À¸À®¤µ¤ì¤¿¥Ç¡¼¥¿¤ÏÀìÌç²È¤È¤Î¾ðÊó¶¦Í­¤Ë³èÍѤ¹¤ë¤³¤È¤¬¤Ç¤­¤ë

iShutdown_stats - Shutdown.log¤«¤éºÆµ¯Æ°¤ÎÉÑÅ٤䥿¥¤¥ß¥ó¥°¤Ê¤É¤òʬÀϤ·¡¢Åý·×¥Ç¡¼¥¿¤ò½ÐÎϤ¹¤ë

3²ó¤òĶ¤¨¤ëºÆµ¯Æ°ÃÙ±ä¤Ë¤è¤ê¡¢¥Þ¥ë¥¦¥§¥¢¡ÖPegasus¡×¤Îº¯Àפò¸¡½Ð¡¡°úÍÑ¡§Securelist

¡û¥Þ¥ë¥¦¥§¥¢¸¡½Ð¥Ä¡¼¥ë¤Ë´Ø¤¹¤ëÃí°Õ»ö¹à

Kaspersky Lab¤Ë¤è¤ë¤È¡¢¤³¤Î¥Ä¡¼¥ë¤ò»ÈÍѤ·¤Æ¥Þ¥ë¥¦¥§¥¢¡ÖPegasus¡×¤Î´¶À÷¤ò¸¡½Ð¤Ç¤­¤ë¤È¤¤¤¦¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤³¤Î¥Ä¡¼¥ë¤ÏʬÀϤÎÊä½õ¤È¤·¤Æ»ÈÍѤ¹¤ë¤³¤È¤¬ÁÛÄꤵ¤ì¤Æ¤ª¤ê¡¢¤¹¤Ù¤Æ¤Î¥Þ¥ë¥¦¥§¥¢¤ò¸¡½Ð¤Ç¤­¤ë¤ï¤±¤Ç¤Ï¤Ê¤¤¤³¤È¤ËÃí°Õ¤¬É¬Íס£¤Þ¤¿¡¢¥Þ¥ë¥¦¥§¥¢¤ò²óÈò¤·¤¿¤ê¶î½ü¤¹¤ëµ¡Ç½¤Ï¤Ê¤¤¡£

¥Ä¡¼¥ë¤òÀµ¾ï¤Ëµ¡Ç½¤µ¤»¤ë¤Ë¤Ï¡¢¤¢¤ëÄøÅÙ¤ÎÉÑÅÙ¤ÇiOS¤òºÆµ¯Æ°¤·¤ÆShutdown.log¤ò¹¹¿·¤¹¤ëɬÍפ¬¤¢¤ë¡£ºÆµ¯Æ°¤ÎÉÑÅ٤ˤĤ¤¤Æ¤Ï¾õ¶·¼¡Âè¤È¤·¤ÆÌÀ¸À¤òÈò¤±¤Æ¤¤¤ë¤¬¡¢¿ô»þ´Ö¤´¤È¡¢ËèÆü¡¢½ÅÍפʥ¤¥Ù¥ó¥È¤ÎÁ°¸å¤Ê¤É¤¬Îã¤È¤·¤Æµó¤²¤é¤ì¤Æ¤¤¤ë¡£

Kaspersky Lab¤Ïº£¸å¤âSysdiagnoseʬÀϤò·Ñ³¤·¡¢Â¿¤¯¤Î·Ð¸³Â§¤òºîÀ®¤¹¤ëͽÄê¤È¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢¤³¤Î¸¦µæ¤Ë¹×¸¥¤Ç¤­¤ë¶½Ì£¿¼¤¤¥µ¥ó¥×¥ë¤Ë´Ø¤·¤Æ¾ðÊóÄ󶡤òµá¤á¤Æ¤ª¤ê¡¢¹×¸¥¤·¤¿¤¤¾ì¹ç¤Ï¥á¡¼¥ë¤ÇÏ¢Íí¤·¤Æ¤Û¤·¤¤¤È¸Æ¤Ó¤«¤±¤Æ¤¤¤ë¡£