Trend Micro¤Ï¤³¤Î¤Û¤É¡¢¡ÖCVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day¡×¤Ë¤ª¤¤¤Æ¡¢¹âÅ٤ʻý³ŪɸŪ·¿¹¶·â(APT: Advanced Persistent Threat)¥°¥ë¡¼¥×¤Î¡ÖWater Hydra(ÊÌ̾:DarkCasino)¡×¤¬Microsoft Defender SmartScreen¤Î¥¼¥í¥Ç¥¤¤ÎÀȼåÀ­¡ÖCVE-2024-21412¡×¤ò°­ÍѤ·¤Æ¤¤¤ë¤ÈÅÁ¤¨¤¿¡£

CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day

¡ûAPT¥°¥ë¡¼¥×¡ÖWater Hydra¡×¤È¤Ï

Trend Micro¤Ë¤è¤ë¤È¡¢¡ÖWater Hydra¡×¤Ï¡¢2021ǯ¤Ëȯ¸«¤µ¤ì¤¿¶âÍ»¶È³¦¤òɸŪ¤È¤¹¤ë»ý³ŪɸŪ·¿¹¶·â(APT)¥°¥ë¡¼¥×¤È¤µ¤ì¤ë¡£À¤³¦Ãæ¤Î¶ä¹Ô¡¢°Å¹æ»ñ»º¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡¢³°¹ñ°ÙÂؤª¤è¤Ó³ô¼è°ú¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡¢¥®¥ã¥ó¥Ö¥ë¤ª¤è¤Ó¥«¥¸¥Î¥µ¥¤¥È¤òɸŪ¤Ë¤¹¤ë¡£2022ǯ9·î¤ÎÅê»ñ²È¤È¥®¥ã¥ó¥Ö¥ë¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤òɸŪ¤È¤·¤¿¡ÖDarkCasino¡×¥­¥ã¥ó¥Ú¡¼¥ó¤Ë¤ª¤¤¤Æ¤Ï¡¢VisualBasic¤ÇºîÀ®¤µ¤ì¤¿±ó³ÖÁàºî·¿¥È¥í¥¤¤ÎÌÚÇÏ(RAT: Remote Administration Trojan)¡ÖDarkMe¡×¤¬»ÈÍѤµ¤ì¤Æ¤¤¤ë¡£

º£²ó³Îǧ¤µ¤ì¤¿Water Hydra¤Î¿·¤·¤¤¥­¥ã¥ó¥Ú¡¼¥ó¤Ï2023ǯ12·î²¼½Ü¤´¤í¤«¤éTrend Micro¤¬ÄÉÀפò³«»Ï¡£¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È(.url)¥Õ¥¡¥¤¥ë¤ª¤è¤ÓWeb¥Ù¡¼¥¹¤Îʬ»¶¥ª¡¼¥µ¥ê¥ó¥°¤ª¤è¤Ó¥Ð¡¼¥¸¥ç¥Ë¥ó¥°(WebDAV)¥³¥ó¥Ý¡¼¥Í¥ó¥È¤ò°­ÍѤ¹¤ë¤È¤¤¤¦¡£

2024ǯ1·î°Ê¹ß¤Ë³Îǧ¤µ¤ì¤¿Water Hydra¤Î¹¶·â¼ê½ç¡¡°úÍÑ¡§Trend Micro

¡ûÀȼåÀ­¡ÖCVE-2024-21412¡×¤Î³µÍ×

CVE-2024-21412¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È(.url)¥Õ¥¡¥¤¥ë¤ò°­ÍѤ¹¤ë¤³¤È¤Ç¡¢Microsoft Defender SmartScreen¤ò¥Ð¥¤¥Ñ¥¹¤Ç¤­¤ëÀȼåÀ­¡£¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤«¤é¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤ò¸Æ¤Ó½Ð¤¹¤À¤±¤Ç¥Ð¥¤¥Ñ¥¹¤Ç¤­¤ë¤È¤µ¤ì¤ë¡£Water Hydra¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Î¥¢¥¤¥³¥ó(IconFile¥Ñ¥é¥á¡¼¥¿¡¼)¤ò²èÁü¥Õ¥¡¥¤¥ë¤Î¥¢¥¤¥³¥ó¤ËÊѹ¹¤·¡¢¥æ¡¼¥¶¡¼¤Ë²èÁü¥Õ¥¡¥¤¥ë¤È¤·¤Æ¸íǧ¤µ¤»¤ë¼êË¡¤òÊ»ÍѤ¹¤ë¡£

¥æ¡¼¥¶¡¼¤Ï¡¢²èÁü¥Õ¥¡¥¤¥ë¤Ë¸«¤¨¤ë¤³¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤ò³«¤¯¤³¤È¤Ç¡¢¥ê¥â¡¼¥È¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Ë¥¢¥¯¥»¥¹¤¹¤ë¡£¥ê¥â¡¼¥È¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Ï¥ê¥â¡¼¥È¤Î¥¢¡¼¥«¥¤¥Ö¤Ë´Þ¤Þ¤ì¤ë°­°Õ¤Î¤¢¤ë¥³¥Þ¥ó¥É¤ò»Ø¤·¤Æ¤ª¤ê¡¢ÀȼåÀ­¤Î±Æ¶Á¤«¤éSmartScreen¤Î·Ù¹ð¤ò¥Ð¥¤¥Ñ¥¹¤·¤Æ¼Â¹Ô¤µ¤ì¤ë¡£¤½¤Î·ë²Ì¥·¥¹¥Æ¥à¤ÏDarkMe¤Ë´¶À÷¤·¡¢¿¯³²¤µ¤ì¤ë¡£

¡ûÂкö

Microsoft¤Ï2·î13Æü(Êƹñ»þ´Ö)¡¢¡ÖCVE-2024-21412 - Security Update Guide - Microsoft - Internet Shortcut Files Security Feature Bypass Vulnerability¡×¤Ë¤ª¤¤¤Æ¡¢ÀȼåÀ­¡ÖCVE-2024-21412¡×¤ËÂФ¹¤ë¥»¥­¥å¥ê¥Æ¥£¥¢¥Ã¥×¥Ç¡¼¥È¤ò¸ø³«¤·¤¿¡£Microsoft Windows¤ÎÍøÍѼԤϡ¢±Æ¶Á¤Î̵ͭ¤ò³Îǧ¤·¤Æ¥¢¥Ã¥×¥Ç¡¼¥È¤ò¼Â»Ü¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£

Trend Micro¤Ï¤³¤Î¤è¤¦¤Ê¹¶·â¤ò¼õ¤±¤ÆÉÔ¿³¤ÊÆ°ºî¤ËľÌ̤·¤¿¾ì¹ç¤Ï¡¢¿¯³²¤òÁÛÄꤷ¤Æ®¤ä¤«¤Ë¥Ç¡¼¥¿¤ä¥Ä¡¼¥ë¥Á¥§¡¼¥ó¤ò³ÖÎ¥¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢¤³¤ÎÄ´ºº¤ÇȽÌÀ¤·¤¿¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¡ÖCVE-2024-21412: Water Hydra Targets Traders with Windows Defender SmartScreen Zero-Day¡×¤Ë¤Æ¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£