Microsoft Defender¤ò¥Ð¥¤¥Ñ¥¹¤¹¤ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤ËÃí°Õ
Trend Micro¤Ï¤³¤Î¤Û¤É¡¢¡ÖCVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day¡×¤Ë¤ª¤¤¤Æ¡¢¹âÅ٤ʻý³ŪɸŪ·¿¹¶·â(APT: Advanced Persistent Threat)¥°¥ë¡¼¥×¤Î¡ÖWater Hydra(ÊÌ̾:DarkCasino)¡×¤¬Microsoft Defender SmartScreen¤Î¥¼¥í¥Ç¥¤¤ÎÀȼåÀ¡ÖCVE-2024-21412¡×¤ò°ÍѤ·¤Æ¤¤¤ë¤ÈÅÁ¤¨¤¿¡£
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
¡ûAPT¥°¥ë¡¼¥×¡ÖWater Hydra¡×¤È¤Ï
Trend Micro¤Ë¤è¤ë¤È¡¢¡ÖWater Hydra¡×¤Ï¡¢2021ǯ¤Ëȯ¸«¤µ¤ì¤¿¶âÍ»¶È³¦¤òɸŪ¤È¤¹¤ë»ý³ŪɸŪ·¿¹¶·â(APT)¥°¥ë¡¼¥×¤È¤µ¤ì¤ë¡£À¤³¦Ãæ¤Î¶ä¹Ô¡¢°Å¹æ»ñ»º¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡¢³°¹ñ°ÙÂؤª¤è¤Ó³ô¼è°ú¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡¢¥®¥ã¥ó¥Ö¥ë¤ª¤è¤Ó¥«¥¸¥Î¥µ¥¤¥È¤òɸŪ¤Ë¤¹¤ë¡£2022ǯ9·î¤ÎÅê»ñ²È¤È¥®¥ã¥ó¥Ö¥ë¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤òɸŪ¤È¤·¤¿¡ÖDarkCasino¡×¥¥ã¥ó¥Ú¡¼¥ó¤Ë¤ª¤¤¤Æ¤Ï¡¢VisualBasic¤ÇºîÀ®¤µ¤ì¤¿±ó³ÖÁàºî·¿¥È¥í¥¤¤ÎÌÚÇÏ(RAT: Remote Administration Trojan)¡ÖDarkMe¡×¤¬»ÈÍѤµ¤ì¤Æ¤¤¤ë¡£
º£²ó³Îǧ¤µ¤ì¤¿Water Hydra¤Î¿·¤·¤¤¥¥ã¥ó¥Ú¡¼¥ó¤Ï2023ǯ12·î²¼½Ü¤´¤í¤«¤éTrend Micro¤¬ÄÉÀפò³«»Ï¡£¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È(.url)¥Õ¥¡¥¤¥ë¤ª¤è¤ÓWeb¥Ù¡¼¥¹¤Îʬ»¶¥ª¡¼¥µ¥ê¥ó¥°¤ª¤è¤Ó¥Ð¡¼¥¸¥ç¥Ë¥ó¥°(WebDAV)¥³¥ó¥Ý¡¼¥Í¥ó¥È¤ò°ÍѤ¹¤ë¤È¤¤¤¦¡£
2024ǯ1·î°Ê¹ß¤Ë³Îǧ¤µ¤ì¤¿Water Hydra¤Î¹¶·â¼ê½ç¡¡°úÍÑ¡§Trend Micro
¡ûÀȼåÀ¡ÖCVE-2024-21412¡×¤Î³µÍ×
CVE-2024-21412¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È(.url)¥Õ¥¡¥¤¥ë¤ò°ÍѤ¹¤ë¤³¤È¤Ç¡¢Microsoft Defender SmartScreen¤ò¥Ð¥¤¥Ñ¥¹¤Ç¤¤ëÀȼåÀ¡£¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤«¤é¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤ò¸Æ¤Ó½Ð¤¹¤À¤±¤Ç¥Ð¥¤¥Ñ¥¹¤Ç¤¤ë¤È¤µ¤ì¤ë¡£Water Hydra¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Î¥¢¥¤¥³¥ó(IconFile¥Ñ¥é¥á¡¼¥¿¡¼)¤ò²èÁü¥Õ¥¡¥¤¥ë¤Î¥¢¥¤¥³¥ó¤ËÊѹ¹¤·¡¢¥æ¡¼¥¶¡¼¤Ë²èÁü¥Õ¥¡¥¤¥ë¤È¤·¤Æ¸íǧ¤µ¤»¤ë¼êË¡¤òÊ»ÍѤ¹¤ë¡£
¥æ¡¼¥¶¡¼¤Ï¡¢²èÁü¥Õ¥¡¥¤¥ë¤Ë¸«¤¨¤ë¤³¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤ò³«¤¯¤³¤È¤Ç¡¢¥ê¥â¡¼¥È¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Ë¥¢¥¯¥»¥¹¤¹¤ë¡£¥ê¥â¡¼¥È¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Ï¥ê¥â¡¼¥È¤Î¥¢¡¼¥«¥¤¥Ö¤Ë´Þ¤Þ¤ì¤ë°°Õ¤Î¤¢¤ë¥³¥Þ¥ó¥É¤ò»Ø¤·¤Æ¤ª¤ê¡¢ÀȼåÀ¤Î±Æ¶Á¤«¤éSmartScreen¤Î·Ù¹ð¤ò¥Ð¥¤¥Ñ¥¹¤·¤Æ¼Â¹Ô¤µ¤ì¤ë¡£¤½¤Î·ë²Ì¥·¥¹¥Æ¥à¤ÏDarkMe¤Ë´¶À÷¤·¡¢¿¯³²¤µ¤ì¤ë¡£
¡ûÂкö
Microsoft¤Ï2·î13Æü(Êƹñ»þ´Ö)¡¢¡ÖCVE-2024-21412 - Security Update Guide - Microsoft - Internet Shortcut Files Security Feature Bypass Vulnerability¡×¤Ë¤ª¤¤¤Æ¡¢ÀȼåÀ¡ÖCVE-2024-21412¡×¤ËÂФ¹¤ë¥»¥¥å¥ê¥Æ¥£¥¢¥Ã¥×¥Ç¡¼¥È¤ò¸ø³«¤·¤¿¡£Microsoft Windows¤ÎÍøÍѼԤϡ¢±Æ¶Á¤ÎÍ̵¤ò³Îǧ¤·¤Æ¥¢¥Ã¥×¥Ç¡¼¥È¤ò¼Â»Ü¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£
Trend Micro¤Ï¤³¤Î¤è¤¦¤Ê¹¶·â¤ò¼õ¤±¤ÆÉÔ¿³¤ÊÆ°ºî¤ËľÌ̤·¤¿¾ì¹ç¤Ï¡¢¿¯³²¤òÁÛÄꤷ¤Æ®¤ä¤«¤Ë¥Ç¡¼¥¿¤ä¥Ä¡¼¥ë¥Á¥§¡¼¥ó¤ò³ÖÎ¥¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢¤³¤ÎÄ´ºº¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¡ÖCVE-2024-21412: Water Hydra Targets Traders with Windows Defender SmartScreen Zero-Day¡×¤Ë¤Æ¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡ûAPT¥°¥ë¡¼¥×¡ÖWater Hydra¡×¤È¤Ï
Trend Micro¤Ë¤è¤ë¤È¡¢¡ÖWater Hydra¡×¤Ï¡¢2021ǯ¤Ëȯ¸«¤µ¤ì¤¿¶âÍ»¶È³¦¤òɸŪ¤È¤¹¤ë»ý³ŪɸŪ·¿¹¶·â(APT)¥°¥ë¡¼¥×¤È¤µ¤ì¤ë¡£À¤³¦Ãæ¤Î¶ä¹Ô¡¢°Å¹æ»ñ»º¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡¢³°¹ñ°ÙÂؤª¤è¤Ó³ô¼è°ú¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡¢¥®¥ã¥ó¥Ö¥ë¤ª¤è¤Ó¥«¥¸¥Î¥µ¥¤¥È¤òɸŪ¤Ë¤¹¤ë¡£2022ǯ9·î¤ÎÅê»ñ²È¤È¥®¥ã¥ó¥Ö¥ë¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤òɸŪ¤È¤·¤¿¡ÖDarkCasino¡×¥¥ã¥ó¥Ú¡¼¥ó¤Ë¤ª¤¤¤Æ¤Ï¡¢VisualBasic¤ÇºîÀ®¤µ¤ì¤¿±ó³ÖÁàºî·¿¥È¥í¥¤¤ÎÌÚÇÏ(RAT: Remote Administration Trojan)¡ÖDarkMe¡×¤¬»ÈÍѤµ¤ì¤Æ¤¤¤ë¡£
º£²ó³Îǧ¤µ¤ì¤¿Water Hydra¤Î¿·¤·¤¤¥¥ã¥ó¥Ú¡¼¥ó¤Ï2023ǯ12·î²¼½Ü¤´¤í¤«¤éTrend Micro¤¬ÄÉÀפò³«»Ï¡£¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È(.url)¥Õ¥¡¥¤¥ë¤ª¤è¤ÓWeb¥Ù¡¼¥¹¤Îʬ»¶¥ª¡¼¥µ¥ê¥ó¥°¤ª¤è¤Ó¥Ð¡¼¥¸¥ç¥Ë¥ó¥°(WebDAV)¥³¥ó¥Ý¡¼¥Í¥ó¥È¤ò°ÍѤ¹¤ë¤È¤¤¤¦¡£
2024ǯ1·î°Ê¹ß¤Ë³Îǧ¤µ¤ì¤¿Water Hydra¤Î¹¶·â¼ê½ç¡¡°úÍÑ¡§Trend Micro
¡ûÀȼåÀ¡ÖCVE-2024-21412¡×¤Î³µÍ×
CVE-2024-21412¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È(.url)¥Õ¥¡¥¤¥ë¤ò°ÍѤ¹¤ë¤³¤È¤Ç¡¢Microsoft Defender SmartScreen¤ò¥Ð¥¤¥Ñ¥¹¤Ç¤¤ëÀȼåÀ¡£¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤«¤é¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¤ò¸Æ¤Ó½Ð¤¹¤À¤±¤Ç¥Ð¥¤¥Ñ¥¹¤Ç¤¤ë¤È¤µ¤ì¤ë¡£Water Hydra¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Î¥¢¥¤¥³¥ó(IconFile¥Ñ¥é¥á¡¼¥¿¡¼)¤ò²èÁü¥Õ¥¡¥¤¥ë¤Î¥¢¥¤¥³¥ó¤ËÊѹ¹¤·¡¢¥æ¡¼¥¶¡¼¤Ë²èÁü¥Õ¥¡¥¤¥ë¤È¤·¤Æ¸íǧ¤µ¤»¤ë¼êË¡¤òÊ»ÍѤ¹¤ë¡£
¥æ¡¼¥¶¡¼¤Ï¡¢²èÁü¥Õ¥¡¥¤¥ë¤Ë¸«¤¨¤ë¤³¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤ò³«¤¯¤³¤È¤Ç¡¢¥ê¥â¡¼¥È¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Ë¥¢¥¯¥»¥¹¤¹¤ë¡£¥ê¥â¡¼¥È¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥·¥ç¡¼¥È¥«¥Ã¥È¥Õ¥¡¥¤¥ë¤Ï¥ê¥â¡¼¥È¤Î¥¢¡¼¥«¥¤¥Ö¤Ë´Þ¤Þ¤ì¤ë°°Õ¤Î¤¢¤ë¥³¥Þ¥ó¥É¤ò»Ø¤·¤Æ¤ª¤ê¡¢ÀȼåÀ¤Î±Æ¶Á¤«¤éSmartScreen¤Î·Ù¹ð¤ò¥Ð¥¤¥Ñ¥¹¤·¤Æ¼Â¹Ô¤µ¤ì¤ë¡£¤½¤Î·ë²Ì¥·¥¹¥Æ¥à¤ÏDarkMe¤Ë´¶À÷¤·¡¢¿¯³²¤µ¤ì¤ë¡£
¡ûÂкö
Microsoft¤Ï2·î13Æü(Êƹñ»þ´Ö)¡¢¡ÖCVE-2024-21412 - Security Update Guide - Microsoft - Internet Shortcut Files Security Feature Bypass Vulnerability¡×¤Ë¤ª¤¤¤Æ¡¢ÀȼåÀ¡ÖCVE-2024-21412¡×¤ËÂФ¹¤ë¥»¥¥å¥ê¥Æ¥£¥¢¥Ã¥×¥Ç¡¼¥È¤ò¸ø³«¤·¤¿¡£Microsoft Windows¤ÎÍøÍѼԤϡ¢±Æ¶Á¤ÎÍ̵¤ò³Îǧ¤·¤Æ¥¢¥Ã¥×¥Ç¡¼¥È¤ò¼Â»Ü¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£
Trend Micro¤Ï¤³¤Î¤è¤¦¤Ê¹¶·â¤ò¼õ¤±¤ÆÉÔ¿³¤ÊÆ°ºî¤ËľÌ̤·¤¿¾ì¹ç¤Ï¡¢¿¯³²¤òÁÛÄꤷ¤Æ®¤ä¤«¤Ë¥Ç¡¼¥¿¤ä¥Ä¡¼¥ë¥Á¥§¡¼¥ó¤ò³ÖÎ¥¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢¤³¤ÎÄ´ºº¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¡ÖCVE-2024-21412: Water Hydra Targets Traders with Windows Defender SmartScreen Zero-Day¡×¤Ë¤Æ¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£