Avast¤¬ÌµÎÁ¤Ç¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖDoNex¡×¤È¤½¤Î°¡¼ï¤ÎÉü¹æ¥Ä¡¼¥ë¤òÇÛÉÛ
°ÊÁ°¤Ë¤â¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖBianLian¡×¤Î̵ÎÁÉü¹æ¥Ä¡¼¥ë¤ò¥ê¥ê¡¼¥¹¤·¤¿¤³¤È¤¬¤¢¤ë¥»¥¥å¥ê¥Æ¥£´ë¶È¤ÎAvast¤¬¡¢¿·¤·¤¯¡ÖDoNex¡×¤È¤¤¤¦¥é¥ó¥µ¥à¥¦¥§¥¢¤È¤½¤Î°¡¼ï¤Ë¤è¤ê°Å¹æ²½¤µ¤ì¤¿¥Õ¥¡¥¤¥ë¤ÎÉü¹æ¥Ä¡¼¥ë¤ò¸ø³«¤·¤Þ¤·¤¿¡£
Decrypted: DoNex Ransomware and its Predecessors - Avast Threat Labs
https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/
https://www.bleepingcomputer.com/news/security/avast-releases-free-decryptor-for-donex-ransomware-and-past-variants/
Avast releases DoNex ransomware decryptor • The Register
https://www.theregister.com/2024/07/08/avast_secretly_gave_donex_ransomware/
º£²óAvast¤Ë¤è¤Ã¤ÆÉü¹æ¥Ä¡¼¥ë¤¬¸ø³«¤µ¤ì¤¿¡ÖDoNext¡×¤Ï¡¢2022ǯ4·î¤«¤é»È¤ï¤ì¤ë¤è¤¦¤Ë¤Ê¤Ã¤¿¥é¥ó¥µ¥à¥¦¥§¥¢¡ÖMuse¡×¤¬Á°¿È¤Ç¤¹¡£¤½¤Î¸å¡¢Muse¤Ï2022ǯ11·î¤Ë¡ÖLockBit 3.0¡×¤È¤¤¤¦Ê̤Υé¥ó¥µ¥à¥¦¥§¥¢¤Ë¤Ê¤ê¤¹¤Þ¤·¤¿¸å¡¢2023ǯ¤Ë¡ÖDarkRace¡×¤Ø¤È²þ¾Î¤·¡¢2024ǯ¤ËDoNext¤È̾¾è¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿¡£
DoNex¤ÏɸŪ·¿¹¶·â¤ò¼ê¸ý¤È¤·¤Æ¤ª¤ê¡¢¥¢¥á¥ê¥«¤ä¥¤¥¿¥ê¥¢¡¢¥Ù¥ë¥®¡¼¤òÃæ¿´¤È¤·¤¿¹ñ¡¹¤ËÈï³²¤ò¤â¤¿¤é¤·¤Æ¤¤¿¤È¤Î¤³¤È¡£¤Þ¤¿¡¢¥µ¥¤¥Ð¡¼ÈȺá¤Î¿¤¯¤Ï¥í¥·¥¢¤ò¥¿¡¼¥²¥Ã¥È¤Ë¤¹¤ë¤³¤È¤òÈò¤±¤ë·¹¸þ¤¬¤¢¤ê¤Þ¤¹¤¬¡¢¥é¥ó¥µ¥à¥¦¥§¥¢¤È¤·¤Æ¤ÏÄÁ¤·¤¯DoNex¤Ï¥í¥·¥¢¤äÃæ¹ñ¤Ê¤É¤Ç¤âÈï³²¤¬³Îǧ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
DoNex¤Ë´¶À÷¤¹¤ë¤È¡¢°Ê²¼¤Î¤è¤¦¤Ê¿ÈÂå¶âÍ×µá¥á¥Ã¥»¡¼¥¸¤¬É½¼¨¤µ¤ì¤Þ¤¹¡£
¤³¤Î¥é¥ó¥µ¥à¥¦¥§¥¢Âкö¤Ë¼è¤êÁȤó¤Ç¤¤¤¿Avast¤Ï¡¢2024ǯ3·î¤«¤éË¡¼¹¹Ôµ¡´Ø¤òÄ̤¸¤ÆÈë̩΢¤ËÈï³²¼Ô¤ËÉü¹æ¥Ä¡¼¥ë¤òÄ󶡤·¤Æ¤¤Þ¤·¤¿¡£¥»¥¥å¥ê¥Æ¥£´ë¶È¤¬¤Ò¤½¤«¤ËÉü¹æ¥Ä¡¼¥ë¤òÇÛÉÛ¤¹¤ë¤Î¤Ï°ìÈÌŪ¤Ê¤³¤È¤Ç¡¢¤³¤ì¤Ë¤Ï¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤¬¼«Ê¬¤Î¥é¥ó¥µ¥à¥¦¥§¥¢¤Ë¤É¤ó¤Ê·ç´Ù¤¬¤¢¤ë¤Î¤«³Ø½¬¤·²þÎɤ¹¤ë¤Î¤òËɤ°ÁÀ¤¤¤¬¤¢¤ê¤Þ¤¹¡£
¤·¤«¤·¡¢DoNext¤Î·ç´Ù¤Ï2024ǯ6·î¤Ë³«ºÅ¤µ¤ì¤¿¥»¥¥å¥ê¥Æ¥£¥«¥ó¥Õ¥¡¥ì¥ó¥¹¡ÖRecon 2024¡×¤Ç¹¤¯¸ø³«¤µ¤ì¡¢DoNext¤¬±¿±Ä¤·¤Æ¤¤¤¿¥À¡¼¥¯¥¦¥§¥Ö¤Î¥Ú¡¼¥¸¤âÊĺ¿¤µ¤ì¤Æ¤·¤Þ¤Ã¤¿¤¿¤á¤â¤Ï¤ä¶¼°Ò¤Ç¤Ï¤Ê¤¯¤Ê¤Ã¤¿¤È¤·¤Æ¡¢Avast¤Ïº£²óÉü¹æ¥Ä¡¼¥ë¤Î¸ø³«¤ËƧ¤ßÀÚ¤ê¤Þ¤·¤¿¡£
Éü¹æ¥Ä¡¼¥ë¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤Ë¤Ï¡¢¤Þ¤ºAvast¤Î¸ø³«¥Ú¡¼¥¸¤«¤é¥ê¥ó¥¯¤µ¤ì¤Æ¤¤¤ë¼Â¹Ô¥Õ¥¡¥¤¥ë¡Ö¡Öavast_decryptor_donex.exe¡×¤ò¥À¥¦¥ó¥í¡¼¥É¤·¡¢Ç¤°Õ¤Î¾ì½ê¤ËÊݸ¤·¤Þ¤¹¡£
Êݸ¤·¤¿¤é¡¢¼Â¹Ô¥Õ¥¡¥¤¥ë¤ò³«¤¤Þ¤¹¡£¤Ê¤ª¡¢Avast¤Ï´ÉÍý¼Ô¤È¤·¤Æ¼Â¹Ô¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Æ¤¤¤Þ¤¹¡£
¥Ä¡¼¥ë¤¬µ¯Æ°¤·¤¿¤é¡ÖNext¡×¤ò¥¯¥ê¥Ã¥¯¤·¤Þ¤¹¡£
³¤¤¤Æ¡¢Éü¹æ¤¹¤ë¥Õ¥©¥ë¥À¤ä¥Ç¥£¥ì¥¯¥È¥ê¤ò»ØÄꤷ¤Þ¤¹¤¬¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¤¹¤Ù¤Æ¤Î¥í¡¼¥«¥ë¥É¥é¥¤¥Ö¤¬»ØÄꤵ¤ì¤Æ¤¤¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£»ØÄꤷ¤¿¤é¡ÖNext¡×¤ò¥¯¥ê¥Ã¥¯¡£
¼¡¤Ë¡¢°Å¹æ²½¤µ¤ì¤¿¥Õ¥¡¥¤¥ë¤È¸µ¤Î·Á¼°¤Î¥Õ¥¡¥¤¥ë¤ò¥µ¥ó¥×¥ë¤È¤·¤Æ»ØÄꤷ¡ÖNext¡×¤ò¥¯¥ê¥Ã¥¯¤·¤Þ¤¹¡£¤Ç¤¤ë¤À¤±Â礤¤¥Õ¥¡¥¤¥ë¤ò»ØÄꤹ¤ë¤È¤¤¤¤¤È¤Î¤³¤È¡£
³¤¤¤Æ¡¢¥Ñ¥¹¥ï¡¼¥É¥¯¥é¥Ã¥¥ó¥°¥×¥í¥»¥¹¤¬¼Â¹Ô¤µ¤ì¤Þ¤¹¡£¤³¤Î¥×¥í¥»¥¹¤Ë¤ÏÂçÎ̤Υ·¥¹¥Æ¥à¥á¥â¥ê¤¬É¬ÍפǤ¹¤¬¡¢¥á¥â¥ê¤¬½½Ê¬¤Ê¤éÄ̾ï1Éäǽª¤ï¤ë¤È¤Î¤³¤È¡£
ºÇ¸å¤Ë¡¢°Å¹æ²½¤µ¤ì¤¿¥Õ¥¡¥¤¥ë¤ò¥Ð¥Ã¥¯¥¢¥Ã¥×¤¹¤ë¤«¤É¤¦¤«¤Ë¥Á¥§¥Ã¥¯¤òÆþ¤ì¤Æ¡¢¡ÖDecrypt¡×¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤ÈÉü¹æ¤µ¤ì¤Þ¤¹¡£¥Ð¥Ã¥¯¥¢¥Ã¥×¤Ï¡¢Éü¹æ¥×¥í¥»¥¹¤ËÌäÂ꤬¤¢¤Ã¤¿¾ì¹ç¤Ë¤ä¤êľ¤¹¤¿¤á¤Î¤â¤Î¤Ç¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¥Ð¥Ã¥¯¥¢¥Ã¥×¤¹¤ëÊý¤Ë¥Á¥§¥Ã¥¯¤¬Æþ¤Ã¤Æ¤¤¤Þ¤¹¡£