WinSCP¤äPuTTY¤Îµ¶¹¹ð¤«¤é¥é¥ó¥µ¥à¥¦¥§¥¢ÇÛÉÛ¡¢Windows´ÉÍý¼Ô¤¬É¸Åª
Bleeping Computer¤Ï5·î18Æü(Êƹñ»þ´Ö)¡¢¡ÖRansomware gang targets Windows admins via PuTTy, WinSCP malvertising¡×¤Ë¤ª¤¤¤Æ¡¢¡ÖWinSCP¡×¤ª¤è¤Ó¡ÖPuTTY¡×¤Îµ¶¹¹ð¤«¤é¥é¥ó¥µ¥à¥¦¥§¥¢¤òŸ³«¤¹¤ë¥Þ¥ë¥Ð¥¿¥¤¥¸¥ó¥°¹¶·â¥¥ã¥ó¥Ú¡¼¥ó¤ËÃí°Õ¤ò¸Æ¤Ó¤«¤±¤¿¡£¤³¤Î¹¶·â¤Ç¤Ï¡¢»ÈÍѤµ¤ì¤ëµ¶¹¹ð¤ÎÆÃħ¤«¤é¡¢Windows¤Î¥·¥¹¥Æ¥à´ÉÍý¼Ô¤òɸŪ¤Ë¤·¤Æ¤¤¤ë²ÄǽÀ¤¬¹â¤¤¤È¤ß¤é¤ì¤ë¡£
Ransomware gang targets Windows admins via PuTTy, WinSCP malvertising
¡û¥Þ¥ë¥Ð¥¿¥¤¥¸¥ó¥°¹¶·â¥¥ã¥ó¥Ú¡¼¥ó¤Î³µÍ×
Bleeping Computer¤Ë¤è¤ë¤È¡¢¸¡º÷¥µ¥¤¥È¤Ç¡Ödownload winscp¡×¤Þ¤¿¤Ï¡Ödownload putty¡×¤ò¸¡º÷¤¹¤ë¤È¡¢WinSCP¤ª¤è¤ÓPuTTY¤Îµ¶¹¹ð¤¬É½¼¨¤µ¤ì¤ë¤È¤¤¤¦¡£¤³¤ì¤é¹¹ð¤Ë¤Ï¡¢¼¡¤Î¤è¤¦¤Ê¥¿¥¤¥Ý¥¹¥¯¥ï¥Ã¥Æ¥£¥ó¥°¥É¥á¥¤¥ó̾¤¬»ÈÍѤµ¤ì¤¿¤³¤È¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£
puttty[.]org
puutty[.]org
wnscp[.]net
vvinscp[.]net
¤Ê¤ª¡¢putty¤Î¸¡º÷»þ¤Ë¾å°Ì¤Ëɽ¼¨¤µ¤ì¤ë¡Öhttps://www.putty.org/¡×¤Ï¸ø¼°¥µ¥¤¥È¤Ç¤Ï¤Ê¤¤¡£¡Öhttps://www.chiark.greenend.org.uk/~sgtatham/putty/index.html¡×¤¬¸ø¼°¥µ¥¤¥È¤È¤µ¤ì¤ë¡£º£²ó¤Î¹¶·â¼Ô¤â¤³¤Î´ª°ã¤¤¤ò¤·¤Æ¤¤¤¿¤È¤ß¤é¤ì¡¢¾åµ¤Îµ¶¥µ¥¤¥È¤Ïputty.org¤òÌÏÊ路¤Æ¤¤¤¿¤³¤È¤¬¤ï¤«¤Ã¤Æ¤¤¤ë¡£
¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ëPuTTY¤Îµ¶¥µ¥¤¥È¡¡°úÍÑ¡§Rapid7
¡û¥é¥ó¥µ¥à¥¦¥§¥¢ÇÛÉÛ¤Îή¤ì
¤³¤ì¤éµ¶¥µ¥¤¥È¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥Õ¥¡¥¤¥ë¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È¡¢DLL(Dynamic Link Library)¤Î¥µ¥¤¥É¥í¡¼¥Ç¥£¥ó¥°µ»½Ñ¤ò»ÈÍѤ·¤Æ°°Õ¤Î¤¢¤ë¡Öpython311.dll¡×¤¬¼Â¹Ô¤µ¤ì¤ë¡£python311.dll¤Ï°Å¹æ²½¤µ¤ì¤¿Python¥¹¥¯¥ê¥×¥È¤òÃê½Ð¤·¡¢¼Â¹Ô¤¹¤ë¡£
Python¥¹¥¯¥ê¥×¥È¤Ï¡¢¹¶·â¼Ô¤¬ÍøÍѤǤ¤ë¤è¤¦¤ËÀßÄꤵ¤ì¤¿¥»¥¥å¥ê¥Æ¥£¥Æ¥¹¥È¥Ä¡¼¥ë¡ÖSilver C2¡×¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¡£¤½¤Î¸å¡¢¹¶·â¼Ô¤ÏSilver C2¤ò»ÈÍѤ·¤Æ¡ÖCobalt Strike¡×¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ä¡¢¡ÖBlackCat/ALPHV¡×¤ËÎà»÷¤·¤¿¥é¥ó¥µ¥à¥¦¥§¥¢¤ÎŸ³«¤ò»î¤ß¤ë¡£
º£²ó¤Î¥¥ã¥ó¥Ú¡¼¥ó¤Ë¤ª¤±¤ë¿¯³²·ÐÏ© ¡¡°úÍÑ¡§Rapid7
¡ûÂкö
¶áǯ¡¢µ¶¹¹ð¤ò»ÈÍѤ¹¤ë¥Þ¥ë¥Ð¥¿¥¤¥¸¥ó¥°¹¶·â¤¬Áý²Ã·¹¸þ¤Ë¤¢¤ë¡£¤³¤ì¤ÏÈæ³ÓŪÍưפ˷ë²Ì¤¬ÆÀ¤é¤ì¤ë¤¿¤á¤È¤ß¤é¤ì¤Æ¤ª¤ê¡¢Â¿¤¯¤Î¿Íµ¤¤Î¥½¥Õ¥È¥¦¥§¥¢¤¬°ÍѤµ¤ì¤Æ¤¤¤ë¡£
¤½¤Î¤¿¤á¡¢¸¡º÷¥µ¥¤¥È¤ò»ÈÍѤ·¤Æ¥½¥Õ¥È¥¦¥§¥¢¤ò¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¾ì¹ç¤Ï¡¢¥À¥¦¥ó¥í¡¼¥ÉÁ°¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤¤¤ë¥É¥á¥¤¥ó̾¤Ë´Ö°ã¤¤¤¬¤Ê¤¤¤«³Îǧ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢´ûÃΤΰ°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¤Ø¤Î¥¢¥¯¥»¥¹¤òËɻߤ¹¤ë¤¿¤á¡¢¥Ö¥é¥¦¥¶¡¼¤ÎÊݸǽ¤ò»ý¤Ä¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎƳÆþ¤â˾¤Þ¤ì¤Æ¤¤¤ë¡£
¡û¥Þ¥ë¥Ð¥¿¥¤¥¸¥ó¥°¹¶·â¥¥ã¥ó¥Ú¡¼¥ó¤Î³µÍ×
Bleeping Computer¤Ë¤è¤ë¤È¡¢¸¡º÷¥µ¥¤¥È¤Ç¡Ödownload winscp¡×¤Þ¤¿¤Ï¡Ödownload putty¡×¤ò¸¡º÷¤¹¤ë¤È¡¢WinSCP¤ª¤è¤ÓPuTTY¤Îµ¶¹¹ð¤¬É½¼¨¤µ¤ì¤ë¤È¤¤¤¦¡£¤³¤ì¤é¹¹ð¤Ë¤Ï¡¢¼¡¤Î¤è¤¦¤Ê¥¿¥¤¥Ý¥¹¥¯¥ï¥Ã¥Æ¥£¥ó¥°¥É¥á¥¤¥ó̾¤¬»ÈÍѤµ¤ì¤¿¤³¤È¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£
puttty[.]org
puutty[.]org
wnscp[.]net
vvinscp[.]net
¤Ê¤ª¡¢putty¤Î¸¡º÷»þ¤Ë¾å°Ì¤Ëɽ¼¨¤µ¤ì¤ë¡Öhttps://www.putty.org/¡×¤Ï¸ø¼°¥µ¥¤¥È¤Ç¤Ï¤Ê¤¤¡£¡Öhttps://www.chiark.greenend.org.uk/~sgtatham/putty/index.html¡×¤¬¸ø¼°¥µ¥¤¥È¤È¤µ¤ì¤ë¡£º£²ó¤Î¹¶·â¼Ô¤â¤³¤Î´ª°ã¤¤¤ò¤·¤Æ¤¤¤¿¤È¤ß¤é¤ì¡¢¾åµ¤Îµ¶¥µ¥¤¥È¤Ïputty.org¤òÌÏÊ路¤Æ¤¤¤¿¤³¤È¤¬¤ï¤«¤Ã¤Æ¤¤¤ë¡£
¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ëPuTTY¤Îµ¶¥µ¥¤¥È¡¡°úÍÑ¡§Rapid7
¡û¥é¥ó¥µ¥à¥¦¥§¥¢ÇÛÉÛ¤Îή¤ì
¤³¤ì¤éµ¶¥µ¥¤¥È¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥Õ¥¡¥¤¥ë¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È¡¢DLL(Dynamic Link Library)¤Î¥µ¥¤¥É¥í¡¼¥Ç¥£¥ó¥°µ»½Ñ¤ò»ÈÍѤ·¤Æ°°Õ¤Î¤¢¤ë¡Öpython311.dll¡×¤¬¼Â¹Ô¤µ¤ì¤ë¡£python311.dll¤Ï°Å¹æ²½¤µ¤ì¤¿Python¥¹¥¯¥ê¥×¥È¤òÃê½Ð¤·¡¢¼Â¹Ô¤¹¤ë¡£
Python¥¹¥¯¥ê¥×¥È¤Ï¡¢¹¶·â¼Ô¤¬ÍøÍѤǤ¤ë¤è¤¦¤ËÀßÄꤵ¤ì¤¿¥»¥¥å¥ê¥Æ¥£¥Æ¥¹¥È¥Ä¡¼¥ë¡ÖSilver C2¡×¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¡£¤½¤Î¸å¡¢¹¶·â¼Ô¤ÏSilver C2¤ò»ÈÍѤ·¤Æ¡ÖCobalt Strike¡×¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ä¡¢¡ÖBlackCat/ALPHV¡×¤ËÎà»÷¤·¤¿¥é¥ó¥µ¥à¥¦¥§¥¢¤ÎŸ³«¤ò»î¤ß¤ë¡£
º£²ó¤Î¥¥ã¥ó¥Ú¡¼¥ó¤Ë¤ª¤±¤ë¿¯³²·ÐÏ© ¡¡°úÍÑ¡§Rapid7
¡ûÂкö
¶áǯ¡¢µ¶¹¹ð¤ò»ÈÍѤ¹¤ë¥Þ¥ë¥Ð¥¿¥¤¥¸¥ó¥°¹¶·â¤¬Áý²Ã·¹¸þ¤Ë¤¢¤ë¡£¤³¤ì¤ÏÈæ³ÓŪÍưפ˷ë²Ì¤¬ÆÀ¤é¤ì¤ë¤¿¤á¤È¤ß¤é¤ì¤Æ¤ª¤ê¡¢Â¿¤¯¤Î¿Íµ¤¤Î¥½¥Õ¥È¥¦¥§¥¢¤¬°ÍѤµ¤ì¤Æ¤¤¤ë¡£
¤½¤Î¤¿¤á¡¢¸¡º÷¥µ¥¤¥È¤ò»ÈÍѤ·¤Æ¥½¥Õ¥È¥¦¥§¥¢¤ò¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¾ì¹ç¤Ï¡¢¥À¥¦¥ó¥í¡¼¥ÉÁ°¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤¤¤ë¥É¥á¥¤¥ó̾¤Ë´Ö°ã¤¤¤¬¤Ê¤¤¤«³Îǧ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢´ûÃΤΰ°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¤Ø¤Î¥¢¥¯¥»¥¹¤òËɻߤ¹¤ë¤¿¤á¡¢¥Ö¥é¥¦¥¶¡¼¤ÎÊݸǽ¤ò»ý¤Ä¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎƳÆþ¤â˾¤Þ¤ì¤Æ¤¤¤ë¡£