HP¤Ï4·î10Æü(Êƹñ»þ´Ö)¡¢¡ÖRaspberry Robin Now Spreading Through Windows Script Files¡ÃHP Wolf Security¡×¤Ë¤ª¤¤¤Æ¡¢Windows¤òɸŪ¤È¤¹¤ë¥ï¡¼¥à¡ÖRaspberry Robin¡×¤¬Windows¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë(WSF)¤òÄ̤¸¤ÆÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë¤³¤È¤òȯ¸«¤·¤¿¤È¤·¤Æ¡¢Ãí°Õ¤ò¸Æ¤Ó³Ý¤±¤¿¡£¤³¤Î¥ï¡¼¥à¤Ë´¶À÷¤¹¤ë¤È¡¢¥é¥ó¥µ¥à¥¦¥§¥¢¤Ê¤ÉÊ̤ʥޥ륦¥§¥¢¤Ë´¶À÷¤¹¤ë²ÄǽÀ­¤¬¤¢¤ë¡£

Raspberry Robin Now Spreading Through Windows Script Files¡ÃHP Wolf Security

¡ûRaspberry Robin¤Î´¶À÷·ÐÏ©

Raspberry Robin¤Ï2021ǯ¸åȾ¤Ëȯ¸«¤µ¤ì¤¿Windows¸þ¤±¤Î¥ï¡¼¥à¤È¤µ¤ì¤ë¡£È¯¸«Åö½é¤ÏUSB¥á¥â¥ê¤Ê¤É¤Î¥ê¥à¡¼¥Ð¥Ö¥ë¥á¥Ç¥£¥¢¤ò²ð¤·¤Æ´¶À÷¤·¡¢¿¯³²¤·¤¿QNAP¤ÎNAS¤«¤é¥Ú¥¤¥í¡¼¥É¤ò¥À¥¦¥ó¥í¡¼¥É¡¢¼Â¹Ô¤¹¤ë¼êË¡¤¬¤È¤é¤ì¤Æ¤¤¤¿¡£¤½¤Î¸å¡¢¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¹¶·â¤ä¥Þ¥ë¥Ð¥¿¥¤¥¸¥ó¥°¹¶·â¤ò²ð¤·¤Æ¥¢¡¼¥«¥¤¥Ö¥Õ¥¡¥¤¥ë¤ä¥¤¥ó¥¹¥È¡¼¥é¤òÇÛÉÛ¤¹¤ë¼êË¡¤¬¤È¤é¤ì¤Æ¤¤¤¿¤¬¡¢º£²ó¤Ï¤¸¤á¤ÆWindows¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤òÇÛÉÛ¤¹¤ë¼êË¡¤¬³Îǧ¤µ¤ì¤¿¡£

HP¤Î¸¦µæ¼Ô¤Ë¤è¤ë¤È¡¢Windows¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤Ï°­°Õ¤Î¤¢¤ë¥É¥á¥¤¥ó¤ä¥µ¥Ö¥É¥á¥¤¥ó·Ðͳ¤ÇÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë¤È¤¤¤¦¡£¹¶·â¼Ô¤¬¤³¤ì¤éURL¤ËÈï³²¼Ô¤ò¤É¤Î¤è¤¦¤Ë¤·¤ÆͶƳ¤·¤Æ¤¤¤ë¤Î¤«¤Ï¤ï¤«¤Ã¤Æ¤¤¤Ê¤¤¡£

¡û°­°Õ¤Î¤¢¤ëWindows¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë

ȯ¸«¤µ¤ì¤¿°­°Õ¤Î¤¢¤ëWindows¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤Ï¹âÅÙ¤ËÆñÆɲ½¤µ¤ì¤Æ¤ª¤ê¡¢¤µ¤Þ¤¶¤Þ¤ÊʬÀÏ˸³²µ»½Ñ¤ä²¾ÁÛ¥Þ¥·¥ó¸¡½Ðµ»½Ñ¤¬»ÈÍѤµ¤ì¤Æ¤¤¤ë¤È¤¤¤¦¡£¤³¤ì¤é¤¹¤Ù¤Æ¤Î¸¡ºº¤Ë¥Ñ¥¹¤·¤¿¾ì¹ç¤Ë¤Î¤ßºÇ½ª¥Ú¥¤¥í¡¼¥É¤¬¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¡¢¼Â¹Ô¤µ¤ì¤ë¡£

¥¹¥¯¥ê¥×¥ÈËÜÂΤΥ³¡¼¥É¤Ï¥Õ¥¡¥¤¥ë¤ÎÃæ±û¤Ëµ­½Ò¤µ¤ì¤Æ¤ª¤ê¡¢¤½¤ÎÁ°¸å¤Ë¤Ï°ÕÌ£¤Î¤Ê¤¤¥Ç¡¼¥¿¤¬ÇÛÃÖ¤µ¤ì¤Æ¤¤¤ë¡£¤³¤ì¤é¥Ç¡¼¥¿¤ÏWindows Script Host¥³¥ó¥Ý¡¼¥Í¥ó¥È¤«¤é¤Ï̵»ë¤µ¤ì¤ë¤¿¤á¡¢Ã±½ã¤ËʬÀϤò˸³²¤¹¤ë¤¿¤á¤ËÇÛÃÖ¤µ¤ì¤¿¤â¤Î¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£

¥¹¥¯¥ê¥×¥È¤ÎÁ°¸å¤ËÇÛÃÖ¤µ¤ì¤¿Ê¬ÀϤò˸³²¤¹¤ë°ÕÌ£¤Î¤Ê¤¤¥Ç¡¼¥¿¡¡°úÍÑ¡§HP

¥¹¥¯¥ê¥×¥ÈËÜÂΤϹâÅÙ¤ËÆñÆɲ½¤µ¤ì¤Æ¤ª¤ê¡¢¤½¤ÎÆ°ºî¤òÍý²ò¤¹¤ë¤Î¤ÏÍưפǤϤʤ¤¤È¤µ¤ì¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢HP¤Î¸¦µæ¼Ô¤Ï¥³¡¼¥É¤òʬÀϤ·¡¢¤½¤ÎÆ°ºî¤ò¾ÜºÙ¤Ë²òÀ⤷¤Æ¤¤¤ë¡£

ÆñÆɲ½¤µ¤ì¤¿À©¸æ¥Õ¥í¡¼¤ÎÎã¡¡°úÍÑ¡§HP

ʬÀϤˤè¤ë¤È¡¢¥¹¥¯¥ê¥×¥È¤ÏºÇ½é¤Ë¤¤¤¯¤Ä¤«¤Î³Îǧ¤ò¼Â¹Ô¤·¡¢¾ò·ï¤Ë°ìÃפ¹¤ë¾ì¹ç¤ÏʬÀϤµ¤ì¤Æ¤¤¤ë¡¢¤Þ¤¿¤ÏºÇ½ª¥Ú¥¤¥í¡¼¥É¤Î¼Â¹Ô¤Ë¾ã³²¤¬¤¢¤ë¤Èɾ²Á¤·¤Æ¥¹¥¯¥ê¥×¥È¤ò½ªÎ»¤¹¤ë¤È¤¤¤¦¡£¤Þ¤¿¡¢Æ°ÅªÊ¬ÀϤò˸³²¤¹¤ë¤¿¤á¤Ë¥¹¥¯¥ê¥×¥È¤òºÆ¼Â¹Ô¤·¤Æ¤«¤é¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤òºï½ü¤·¡¢½èÍý¤ò·Ñ³¤¹¤ëµ¡Ç½¤ò»ý¤Ä¤È¤µ¤ì¤ë¡£¤³¤ì¤é¤¹¤Ù¤Æ¤Î¸¡ºº¤ò¥Ñ¥¹¤¹¤ë¤ÈMicrosoft Defender¤ËÎã³°¤òÄɲä·¡¢¥Þ¥ë¥¦¥§¥¢¤Î¸¡½Ð¤òÁ˻ߤ·¤Æ¤«¤éRaspberry Robin¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¼Â¹Ô¤¹¤ë¡£

¡û±Æ¶Á¤ÈÂкö

Raspberry Robin¤òÇÛÉÛ¤¹¤ë¹¶·â¼Ô¤Ï¥»¥­¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Î²óÈòÊýË¡¤äʬÀÏ˸³²µ»½Ñ¤Ê¤É¤ËÀºÄ̤·¡¢¹âÅ٤ʵ»½ÑÎϤò»ý¤Ã¤Æ¤¤¤ë¤È¿ä¬¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢ÌÜŪ¤òãÀ®¤¹¤ë¤¿¤á¤Ë¤µ¤Þ¤¶¤Þ¤Ê´¶À÷·ÐÏ©¤ò¸¦µæ¤¹¤ë¤Ê¤É·Ñ³¤·¤¿³«È¯Ç½ÎϤâÈ÷¤¨¤Æ¤¤¤ë¤È¤ß¤é¤ì¤Æ¤ª¤ê¡¢º£¸å¤â¹¶·â¤¬Â³¤¯¤ÈͽÁÛ¤µ¤ì¤Æ¤¤¤ë¡£

HP¤Î¸¦µæ¼Ô¤Ï¤³¤Î¥ï¡¼¥à¤Î³È»¶¤Ïͫθ¤¹¤Ù¤­¤³¤È¤È¤·¤Æ¡¢´ë¶È¤Î¥»¥­¥å¥ê¥Æ¥£Ã´Åö¼Ô¤ËÁᤤÃʳ¬¤Ç¤ÎÂнè¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£HP¤Ïº£²ó¤ÎʬÀϤÇȽÌÀ¤·¤¿¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¡Öiocs/raspberryrobin at main · hpthreatresearch/iocs · GitHub¡×¤Ë¤Æ¸ø³«¤·¤Æ¤¤¤ë¡£

¤µ¤é¤Ë¡¢°­°Õ¤Î¤¢¤ëWindows¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤ò¸¡½Ð¤¹¤ëYara¥ë¡¼¥ë¡Ötools/raspberryrobin/wsf_loader_raspberryrobin.yar at main · hpthreatresearch/tools · GitHub¡×¤È¡¢¥¹¥¯¥ê¥×¥È¤ÎʬÀϼ«Æ°²½¥Ä¡¼¥ë¡Ötools/raspberryrobin at main · hpthreatresearch/tools · GitHub¡×¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢¤³¤ì¤é¤òɬÍפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£