Guardio¤Ï2·î26Æü(¸½ÃÏ»þ´Ö)¡¢¡Ö¡ÈSubdoMailing¡É - Thousands of Hijacked Major-Brand Subdomains Found Bombarding Users With Millions of Malicious Emails¡Ãby Guardio¡ÃFeb, 2024¡ÃMedium¡×¤Ë¤ª¤¤¤Æ¡¢Í­Ì¾¥Ö¥é¥ó¥É¤Î8,000¤òĶ¤¨¤ë¥µ¥Ö¥É¥á¥¤¥ó¤¬¥Ï¥¤¥¸¥ã¥Ã¥¯¤µ¤ì¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤Ë°­ÍѤµ¤ì¤Æ¤¤¤ë¤ÈÊ󤸤¿¡£¤³¤Î¥­¥ã¥ó¥Ú¡¼¥ó¡ÖSubdoMailing¡×¤Ë´ØÍ¿¤·¤¿¶¼°Ò¥¢¥¯¥¿¡¼¤Ï¡¢¤³¤ì¤é¥É¥á¥¤¥ó¤Î¿®Íê¤ò°­ÍѤ·¤ÆËèÆü¿ôÉ´Ëü¤â¤Î¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤òÁ÷¿®¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£

¡ÈSubdoMailing¡É - Thousands of Hijacked Major-Brand Subdomains Found Bombarding Users With Millions of Malicious Emails¡Ãby Guardio¡ÃFeb, 2024¡ÃMedium

¡û¥µ¥Ö¥É¥á¥¤¥ó¥Ï¥¤¥¸¥ã¥Ã¥¯¤Î¼ÂÂÖ

Guardio¤ÎÄ´ºº¤Ë¤è¤ë¤È¡¢¥¹¥Ñ¥à¥Õ¥£¥ë¥¿¡¼¤ò²óÈò¤·¤ÆÇÛÁ÷¤µ¤ì¤ë¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤Î°ìÉô¤Ï¥á¡¼¥ë¤ÎÀµÅöÀ­¤ò¸¡¾Ú¤¹¤ëSPF (Sender Policy Framework)¡¢DKIM (DomainKeys Identified Mail)¡¢DMARC (Domain-based Message Authentication, Reporting, and Conformance)¤ò¥Ñ¥¹¤¹¤ë¤È¤¤¤¦¡£¤³¤ì¤é¤Î¤³¤È¤«¤é¶¼°Ò¥¢¥¯¥¿¡¼¤¬Á÷¿®¤ËÍøÍѤ·¤Æ¤¤¤ë¥á¡¼¥ë¥µ¡¼¥Ð¤Ï¡¢²¿¤é¤«¤ÎÍýͳ¤ÇÀµµ¬¤Î¥µ¡¼¥Ð¤Ë¾µÇ§¤µ¤ì¤Æ¤¤¤ë¤³¤È¤Ë¤Ê¤ë¡£¤³¤ÎÆ°ºî¤ò³Îǧ¤¹¤ë¤¿¤á¤ËGuardio¤Ï¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤ÎÁ÷¿®¼Ô¥¢¥É¥ì¥¹¤Ëµ­ºÜ¤µ¤ì¤Æ¤¤¤¿¥µ¥Ö¥É¥á¥¤¥ó¤Î1¤Ä¡Ö@marthastewart.msn.com¡×¤Ë¤Ä¤¤¤ÆÄ´ºº¤·¤Æ¤¤¤ë¡£

¸½ºß¡¢¤³¤Î¥µ¥Ö¥É¥á¥¤¥ó¤ÎDNS¥ì¥³¡¼¥É¤ÏCNAME (Canonical Name record)¤ò»ÈÍѤ·¤Æ¡Ömsnmarthastewartsweeps.com¡×¤Ë¥¨¥¤¥ê¥¢¥¹¤µ¤ì¤Æ¤¤¤ë¡£¤³¤Î¥É¥á¥¤¥ó¤Ï22ǯÁ°¤Ëû´ü´Ö³èÆ°¤·¤Æ¤¤¤¿¤¬¡¢2022ǯ9·î¤Ë¶¼°Ò¥¢¥¯¥¿¡¼¤Ë¼èÆÀ¤µ¤ì¤ë¤Þ¤Ç21ǯ´ÖÊü´þ¤µ¤ì¤Æ¤¤¤¿¤È¤¤¤¦¡£¤³¤ÎCNAME¥ì¥³¡¼¥É¤ÏMicrosoft¤¬°Ý»ý¤·¤Æ¤¤¤ë¤â¤Î¤È¤ß¤é¤ì¡¢ËܹƼ¹É®»þÅÀ¤Ç¤Ï¤Þ¤À̾Á°²ò·è²Äǽ¤Ç½¤Àµ¤µ¤ì¤Æ¤¤¤Ê¤¤(»²¹Í¡§¡ÖCNAME Lookup - Check CNAME DNS records for any domain¡×)¡£

¶¼°Ò¥¢¥¯¥¿¡¼¤ËºÆ¼èÆÀ¤µ¤ì¤¿msnmarthastewartsweeps.com¤ÎSFP¥ì¥³¡¼¥É(DNS TXT¥ì¥³¡¼¥É)¤Ë¤Ï¡¢ºÆµ¢¥É¥á¥¤¥ó²ò·è¤Ë¤è¤ê17,826¸Ä¤ÎIP¥¢¥É¥ì¥¹¤¬ÅÐÏ¿¤µ¤ì¤Æ¤ª¤ê¡¢¤½¤Î1¤Ä¤Ëº£²óÄ´ºº¤ÎÂоݤȤʤä¿¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤ÎÁ÷¿®¥µ¡¼¥Ð¤¬´Þ¤Þ¤ì¤Æ¤¤¤¿¤³¤È¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£¤Ä¤Þ¤ê¡¢¶¼°Ò¥¢¥¯¥¿¡¼¤ÏMicrosoft¤¬ÊüÃÖ¤·¤Æ¤¤¤ëCNAME¥ì¥³¡¼¥É¤Î¥¨¥¤¥ê¥¢¥¹Àè¥É¥á¥¤¥ó¤ò¥Ï¥¤¥¸¥ã¥Ã¥¯¤·¡¢Microsoft¤Î¥µ¥Ö¥É¥á¥¤¥ó¤È¤·¤Æ¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤òÇÛÁ÷¤·¤Æ¤¤¤¿¤³¤È¤Ë¤Ê¤ë¡£¤³¤Î¤è¤¦¤Ë¡¢CNAME¥ì¥³¡¼¥É¤Î´ÉÍý¤òÂÕ¤ë¤È¶¼°Ò¥¢¥¯¥¿¡¼¤Ë¥µ¥Ö¥É¥á¥¤¥ó¤ò°­ÍѤµ¤ì¤ë²ÄǽÀ­¤¬¤¢¤ë¡£

¥Ï¥¤¥¸¥ã¥Ã¥¯¤µ¤ì¤¿¥µ¥Ö¥É¥á¥¤¥ó¤«¤é²ò·è¤µ¤ì¤ëSPF¥ì¥³¡¼¥É¤ÎÎã¡¡Ä󶡡§Guardio

¡û¿·¤¿¤Ê¥µ¥Ö¥É¥á¥¤¥ó¥Ï¥¤¥¸¥ã¥Ã¥¯

Guardio¤Ï¡¢SPF¥ì¥³¡¼¥É¤ò°­ÍѤ·¤¿¹¶·â¡ÖSPF-Takeover¡×¤Ë¤Ä¤¤¤Æ¤âÊó¹ð¤·¤Æ¤¤¤ë¡£¤³¤ÎÊýË¡¤ÏSPF¥ì¥³¡¼¥É¤ËÅÐÏ¿¤µ¤ì¤¿»ÈÍѤµ¤ì¤Æ¤¤¤Ê¤¤¥É¥á¥¤¥ó¤ò¥Ï¥¤¥¸¥ã¥Ã¥¯¤¹¤ë¼êË¡¡£SPF¤Ë¤ÏÊ̤Υµ¡¼¥Ð¤ò»²¾È¤¹¤ë»ÅÁȤߤ¬¤¢¤ê¡¢¤³¤Î»²¾ÈÀè¥É¥á¥¤¥ó¤¬Êü´þ¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ë¤½¤ì¤òºÆ¼èÆÀ¤¹¤ë¤³¤È¤Ç°­ÍѤ¹¤ë¡£

Guardio¤Ï¤½¤Î°ìÎã¤È¤·¤Æ¥¹¥¤¥¹¤Î¿Íµ¤»þ·×¥Ö¥é¥ó¥É¡Öswatch.com¡×¤òµó¤²¤Æ¤¤¤ë¡£swatch.com¤ÎTXT¥ì¥³¡¼¥É¤ò¼èÆÀ¤¹¤ë¤È¡¢¡Ö"v=spf1 mx a a:directtoaccess.com ¡Ä"¡×¤Èµ­ºÜ¤¬¤¢¤ê¡Ödirecttoaccess.com¡×¤ÎA¥ì¥³¡¼¥É¤ò»²¾È¤·¤Æ¤¤¤ë¡£directtoaccess.com¤ÎA¥ì¥³¡¼¥É¤Ë¤Ï¼¹É®»þÅÀ¤Ç86¤ÎIP¥¢¥É¥ì¥¹¤¬ÅÐÏ¿¤µ¤ì¤Æ¤ª¤ê¡¢¤³¤ì¤éIP¥¢¥É¥ì¥¹¤Ï¤¹¤Ù¤Æswatch.com¤ÎÀµµ¬¤Î¥á¡¼¥ë¥µ¡¼¥Ð¡¼¤È¤·¤Æ°·¤ï¤ì¤ë¤³¤È¤Ë¤Ê¤ë¡£

¡û¥Ï¥¤¥¸¥ã¥Ã¥¯¤Î±Æ¶Á¤ÈÂкö

Guardio¤ÎÄ´ºº¤Ë¤è¤ë¤È¡¢¤³¤ì¤Þ¤Ç¤Ë8,000¤òĶ¤¨¤ë¥µ¥Ö¥É¥á¥¤¥ó¤Î¥Ï¥¤¥¸¥ã¥Ã¥¯¤¬³Îǧ¤µ¤ì¤¿¤È¤¤¤¦¡£¶¼°Ò¥¢¥¯¥¿¡¼¤Ï¤³¤ì¤é¥µ¥Ö¥É¥á¥¤¥ó¤ò°­ÍѤ·¡¢Í­Ì¾¥Ö¥é¥ó¥É¤Ë¤Ê¤ê¤¹¤Þ¤·¤Æ¥Õ¥£¥Ã¥·¥ó¥°¥á¡¼¥ë¤òËèÆüÂçÎ̤ËÁ÷¿®¤·¤ÆÍø±×¤òÆÀ¤Æ¤¤¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤Ê¤ª¡¢¤³¤Î¥­¥ã¥ó¥Ú¡¼¥ó¤Ï¹­ÈϰϤÎÄ´ºº¤Ë´ð¤Å¤­¡ÖResurrecAds¡×¤È¸Æ¤Ð¤ì¤ë¶¼°Ò¥¢¥¯¥¿¡¼¤Ë¤è¤ë¤â¤Î¤È¿ä¬¤µ¤ì¤Æ¤¤¤ë¡£

¿¯³²¤µ¤ì¤¿¥µ¥Ö¥É¥á¥¤¥ó¤ÎÎã¡¡Ä󶡡§Guardio

Guardio¤Ï¤³¤Î¶¼°Ò¤Îº¬Àä¤òÌܻؤ¹¤¿¤á¡¢Web¥µ¥¤¥È¡ÖSubdoMailing Checker Tool | Guardio¡×¤òºîÀ®¤·¤¿¡£¤³¤Î¥Ä¡¼¥ë¤ò»ÈÍѤ¹¤ë¤È¡¢¥É¥á¥¤¥ó´ÉÍý¼Ô¤È¥µ¥¤¥È½êÍ­¼Ô¤ÏÉÔÀµ¹Ô°Ù¤Îº¯Àפθ¡½Ð¤È¡¢ÌäÂêÅÀ¤Î½¤Àµ¤ª¤è¤ÓËɻߤËɬÍפʾðÊó¤ò¼èÆÀ¤Ç¤­¤ë¤È¤¤¤¦¡£¤¹¤Ù¤Æ¤ÎDNS¥ì¥³¡¼¥É¤Î´ÉÍý¼Ô¤Ë¤Ï¡¢CNAME¤ª¤è¤ÓTXT¥ì¥³¡¼¥É¤ÎÆâÍƤ˥ϥ¤¥¸¥ã¥Ã¥¯²Äǽ¤Ê¥É¥á¥¤¥ó¤Î¾ðÊ󤬴ޤޤì¤Æ¤¤¤Ê¤¤¤«³Îǧ¤·¡¢Å¬Àڤ˽¤Àµ¤¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£