ESET/ãã«ã¦ã§ã¢æ å ±å±
PCã使ããªãä¸ä»£ã«ã©ããªã»ãã¥ãªãã£ã¼å¯¾çæè²ãããã¹ããï¼
ãæ¬è¨äºã¯ãã¤ãã³ãã¼ã±ãã£ã³ã°ã¸ã£ãã³ãæä¾ããããã«ã¦ã§ã¢æ å ±å±ãã«æ²è¼ãããããã½ã³ã³ã使ããªãï¼ï¼ã¹ããä¸ä»£ã¸ã®ã»ãã¥ãªãã£å¯¾çã®æè²ã¯ã©ãããã¹ãï¼ããåç·¨éãããã®ã§ãã
æè¿ã®æ°å ¥ç¤¾å¡ã®å¾å
ãæ¥æ¬ã«ãããã¹ããæ®åã®ãã£ããã¨ãªã£ããiPhone 3Gãçºå£²ãããã®ã2008å¹´7æããããã11å¹´è¿ããçµéããä»20代ã®è¥è ãã¡ã«ã¨ã£ã¦ãå¹¼å°ã®é ããã¹ãããã¿ãã¬ããã¯èº«è¿ãªåå¨ã§ããã¸ã¿ã«ãã¤ãã£ãä¸ä»£ã¨å¼ã°ãã¦ããã»ã©ããã®ä¸ä»£ã®è¥è ãã¡ã¯ãæ¥å¸¸çæ´»ã¯ãã¡ããã®ãã¨ã大å¦ã§èª²ãããã¬ãã¼ããåè«ã¾ã§ããã¹ããã²ã¨ã¤ã§æ¸ã¾ãã¦ãã¾ããã¨ãå°ãªããªãã¨ããã以åã¯ãå°±è·æ´»åã§ã¯ãã½ã³ã³ãå¿ é ã¨è¨ããã¦ããããæè¿ã®å°±æ´»ãµã¤ãã¯ãã¹ã¦ã¹ããã«å¯¾å¿ãã¦ãããã¨ã³ããªã¼ã·ã¼ãã®æåºãã¹ããçµç±ã§ãããªãå¦çãããã»ã©ããã®ãããä»ã®æ°å ¥ç¤¾å¡ã®ä¸ã«ã¯ããã½ã³ã³ã使ã£ãçµé¨ãã»ã¨ãã©ãªãã¨ãã人ãåºã¦ãã¦ããã®ã ã
ãããããã»ã¨ãã©ã®ä¼æ¥ã§ã¯ãã¹ããã§ã¯ãªãããã½ã³ã³ã§æ¥åããããªããã¨ã«ãªããã¹ãããã¿ãã¬ããã ãã§æ¥åãéè¡å¯è½ãªè·ç¨®ãä¸é¨ããã ããããä¼ç»æ¸ãä½æãããã¬ã¼ã³ãã¼ã·ã§ã³ããããªããããªè·ç¨®ãã¨ã¯ã»ã«ã§çµè²»ããã¼ã¿ãªã©ã®ç®¡çãããæ¥åãªã©ããã½ã³ã³å¿ é ã®æ¥åã¯æ°å¤ããããæ°å ¥ç¤¾å¡ã®æè²ã«é¢ããæ å½è ã«ã¯ãããããå¦æ ¡ãåæ¥ããã¦ã®æ°ç¤¾ä¼äººã«å¯¾ããã¹ããã¨ãã½ã³ã³ã®éããããã¦ãã®ä½¿ãæ¹ã¾ã§ç¯å²ãåºãã¦æãã¦ãããã¨ãæ±ãããã¦ããã
ã¹ããã¨ãã½ã³ã³ã®éã
ãããããã¹ããã¨ãã½ã³ã³ã®éãã¨ã¯ãªãã ãããï¼ä¿¯ç°ãã¦èããã¨ã両è ã«å¤§ããªéãã¯ãªããã¹ããããã½ã³ã³ããCPUãã¡ã¢ãªãã¹ãã¬ã¼ã¸ãªã©ããæ§æãããã³ã³ãã¥ã¼ã¿ã¼ã®ä¸ç¨®ã§ãããéãã®ã¯å½¢ç¶ããµã¤ãºãã¹ããã¯ãã¢ã¼ããã¯ãã£ãããã§ãããæè¿ã¯ãã¹ããã大ååããå¾åã«ãããã³ã³ãã¯ããª2in1 PCã¨ã®å¤è¦çãªå·®ãã縮ã¾ã£ã¦ãã¦ããã
ããããããã¸ãã¹ã«ãããçç£æ§ãæ±ç¨æ§ã¨ããè¦ç¹ã«ãªãã¨è©±ã¯å¥ã ãã¹ããã¯ã常ã«è身é¢ããæã¡æ©ããã¨ãåæã§ããããµã¤ãºãééã¨ãã£ãæºå¸¯æ§ãéè¦ãããããã®ããã液æ¶ãµã¤ãºãå ¥åããã¤ã¹ã¨ãã£ãæä½æ§ãå·¦å³ããã¹ããã¯ãç ç²ã«ãªããããããªããããã«å¯¾ãããã½ã³ã³ãç¹ã«ãã¹ã¯ããããã½ã³ã³ã¯ããã¾ãã¾ãªæ¥åå¦çã®å¹çãåä¸ããããã¨ãåæã§ãããæä½æ§ãæ å ±ã®è¦èªæ§ãä¸è¦§æ§ã«åªãã¦ãããã¾ãããã¥ã¢ã«ãã£ã¹ãã¬ã¤ãªã©ãå¹çåãä¿é²ããæ´»ç¨æ¹æ³ã«ã¤ãã¦ãããã½ã³ã³ã®ã»ããå å®ãã¦ããã
ãä¸è¬çã«ãã¹ãããã¿ãã¬ããã¯ãåç»ãè¦è´ããããé»åæ¸ç±ãèªãã ãããããã£ãã³ã³ãã³ããæ¶è²»ããããã¤ã¹ã¨ãã¦ã¯åªãã¦ããããã³ã³ãã³ããã¼ãããä½ãåºãï¼åµé ããï¼ããã¤ã¹ã¨ãã¦ã¯ãå§åçã«ãã½ã³ã³ã«è»é ãä¸ãããã¹ãããã¿ãã¬ããã¯ãã³ã³ãã³ãã»ã³ã³ãµã³ãã·ã§ã³ã»ããã¤ã¹ãã§ããã®ã«å¯¾ãããã½ã³ã³ã¯ãã³ã³ãã³ãã»ã¯ãªã¨ã¤ã·ã§ã³ã»ããã¤ã¹ããªã®ã ã
ãªããã¹ããã§æ¥åãã§ã¯ãã¡ãªã®ãï¼
ããã¡ãããã¹ããã§æ¥åãéè¡ã§ããªãã¨ããããã§ã¯ãªããåè¿°ããããã«ãã¹ããã«ã¯æºå¸¯æ§ãåªãã¦ããã¨ããå©ç¹ããããããå® é ãã©ã¤ãã¼ã®ä¼ç¥¨ç®¡çãªã©ããã½ã³ã³ãããã¹ãããå°ç¨ç«¯æ«ã®ã»ããåãã¦ããæ¥åããããããããä¸è¬çãªãªãã£ã¹ã¯ã¼ã¯ã«ããã¦ã¯ããã¯ããã½ã³ã³ãæå©ã ã¨ãããããã®çç±ãããã¤ãæãã¦ãããã
ã»ç»é¢ãå°ãããã確èªä½æ¥ããã¥ãã
ã¹ããã¯ããã¾ã§æã¡éã¶ãã¨ãåæã¨ããããã¼ã½ãã«ãªããã¤ã¹ã§ãããã©ããã¦ãç»é¢ãµã¤ãºã¯å°ãããªããæè¿ã¯ãçé¡ç¸åãé²ã¿ã以åããç»é¢ãµã¤ãºã¯å¤§ãããªã£ã¦ã¯ãããã®ã®ã6ã¤ã³ãåå¾ã主æµã15ã¤ã³ãåå¾ã主æµã®ãã¼ããã½ã³ã³ãã21ï½23ã¤ã³ãã主æµã®ãã¹ã¯ããããã½ã³ã³ã¨æ¯ã¹ã¦ãéãã«ç»é¢ãå°ãããä¸è¦§æ§ã«å£ããä¾ãã°ã大ããªã¨ã¯ã»ã«ã·ã¼ãã®è¦è½ã¨ãã®ãã§ãã¯ããã¶ã¤ã³ã®ç´°é¨ããã¾ãªããã§ãã¯ãã¨ãã£ãä½æ¥ããããªãå ´åãã¹ããã§ã¯å¹çãæªãããã¼ã¿å
¨ä½ã俯ç°ãã¦ãã§ãã¯ã§ããªãããã確èªæ¼ããªã©ãçããã¡ã ã
ã»ãã«ãã¿ã¹ã¯ã«åããªã
ãã½ã³ã³ã¨ã¹ããã®ä½¿ãæ¹ã®éãã¨ãã¦å¤§ããã®ããè¤æ°ã®ã¢ããªã±ã¼ã·ã§ã³ãåæã«ç«ã¡ä¸ãããã¼ã¿ãã¢ããªã±ã¼ã·ã§ã³éã§åãè²¼ãããªããæ¥åããããªãããã«ãã¿ã¹ã¯ãå¯è½ãã©ããã¨ããç¹ã ãå
è¿°ã®éãæè¿ã®ã¹ããã¯ãã¹ããã¯çã«ã¯ãã½ã³ã³ã¨æ¯ã¹ã¦ãããã»ã©è¦å£ãããªãããããããã¯ãç©ççãªç»é¢ãµã¤ãºã®å°ãããOSã«ããå¶ç´ãããããã½ã³ã³ã®ããã«è¤æ°ã®ã¦ã£ã³ãã¦ãåæã«éãã¦ä½æ¥ããããªããã¨ã¯ã§ããªããã²ã¨ã¤ã®ã¢ããªã±ã¼ã·ã§ã³ã ãã§å®çµããä½æ¥ãªãã¨ããããè¤æ°ã®ã¢ããªã±ã¼ã·ã§ã³ãä½µç¨ããæ¥åãã¹ããã§ãããªããã¨æ¥µãã¦ã¯éå¹çã§ãçç£æ§ãä½ä¸ããããããªãã£ã¹æ¥åã¨ãã¦ã®å©ç¨ã¯æ¨å¥¨ãããªãã
ã»æ¥åã¢ããªã±ã¼ã·ã§ã³ã対å¿ãã¦ããªã
ãªãã£ã¹ã§ã®ãã¹ã¯ã¯ã¼ã¯æ¥åã§ã¯ããã¾ãã¾ãªã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ããããããããæ¥åã¢ããªã±ã¼ã·ã§ã³ã¯ããã½ã³ã³ã§ã®å©ç¨ãåæã¨ãªã£ã¦ãããããããã¹ããã§ã¯å
¨ãåä½ããªããã®ãå¤ããåä½ããå ´åã§ããã¦ã¼ã¶ã¼ã¤ã³ã¿ã¼ãã§ã¼ã¹ããã½ã³ã³ãåæã¨ããè¨è¨ã¨ãªã£ã¦ãããããæä½æ§ã大ããä½ä¸ãããã¨ãããããã©ãã¬ã¿ããã½ãããªã©ãä¸é¨ã®æ¥åã¢ããªã±ã¼ã·ã§ã³ã§ã¯ãã¹ãããã¿ãã¬ããã§ã®åä½ã«æé©åããããã®ãç»å ´ãã¦ãããã¢ãã¤ã«å¯¾å¿ã®æ¥åã¢ããªã±ã¼ã·ã§ã³ãå¢å ãããã®ã¨æããããããããä½æ¥å¹çã¨ãã観ç¹ããã¯ãä»å¾ããã½ã³ã³åªä½ã®ç¶æ³ã¯å¤ãããªãã ããã
ã¹ããä¸ä»£ã«ä¼ããã¹ããã»ãã¥ãªãã£ã®åºæ¬ã
ãã»ãã¥ãªãã£å¯¾çãéè¦ã§ããã®ã¯ããã½ã³ã³ãã¹ãããå¤ãããªããããããæ¥åã®ç¾å ´ã§å©ç¨ããããã½ã³ã³ã®å ´åãæ¥åé¢ä¿ã®æ å ±ãèç©ããã¦ãããã»ãã¥ãªãã£ã¤ã³ã·ãã³ãçºçæã®ãªã¹ã¯ãæ±ãã¦ãããã¨ã«ãªããããã§ãã¹ããä¸ä»£ã«ãã½ã³ã³ã§ã®æ¥åããã¦ããã«ãããä¼ããã¹ãããã»ãã¥ãªãã£ã®åºæ¬ãã以ä¸ã«æãã¦ãããã
ã»é«ã¾ãç¶ããããã¼ã¿ãã®éè¦æ§
ã¾ãããã½ã³ã³ãã¹ããã¨ãã£ããã¼ãã¦ã§ã¢æ¬ä½ããããããã¼ã¿ããéè¦ã ã¨ãããã¨ããã£ããã¨èªèãããå¿
è¦ãããããã¼ã¿ã®ä¾¡å¤ã¯å¹´ã
ä¸ããç¶ãã¦ãããããã°ãã¼ã¿ã®æ代ã¨ãã°ããç¾ä»£ããã¼ã¿ãå¶ãããã®ããã¸ãã¹ãåã¡æãã¨ãã£ã¦ãéè¨ã§ã¯ãªããä¸æ¹ã§ãæ©å¯æ§ã®é«ãæ
å ±ã顧客ãã¼ã¿ãªã©ãæµåºãã¦ãã¾ãã¨ãä¼æ¥ã«ã¨ã£ã¦å¤§ããªãã¡ã¼ã¸ã¨ãªããæ¥åã§å©ç¨ããããã½ã³ã³ã¯å¤ãã®éè¦ãªãã¼ã¿ãä¿ç®¡ãã¦ãããã¨ãéè¦ãªãã¼ã¿ã®ä¿ç®¡å ´æã¸ã¢ã¯ã»ã¹ã§ãããã¨ãã¨ããç¹ãããã¿ã¼ã²ããã¨ãã¦çãããããã¨ãããã¨ã®ç解ãç´å¾ãä¿ãããã
ã»ãã½ã³ã³ãªãã§ã¯ã®ã»ãã¥ãªãã£å¯¾ç
ãã½ã³ã³ã¯ãæ¥åã«ä½¿ãããããã«ãªã£ã¦ãã20年以ä¸ãçµéããæ¥åå©ç¨ã«ãããå¤ãã®å
ä¾ãç©ã¿ä¸ãã£ã¦ãããããããå
人ã®æãã¯ãé常ã«åèã«ãªãã以ä¸ã®JPCERTã®æ
å ±ã»ãã¥ãªãã£ããã¥ã¢ã«ã¯ãä¼æ¥å
ã§èµ·ããã¡ãªã»ãã¥ãªãã£ã¤ã³ã·ãã³ãããããã«ã¤ãã¦ã®å¯¾å¦æ³ã解説ãããã®ã§ãæè²æ
å½è
ãã·ã¹ãã 管çè
ç®ç·ã§æ¸ããã¦ãããæ¯éãæ
å½è
ã¯ãã§ãã¯ãã¦ã»ããã
https://www.jpcert.or.jp/magazine/security/newcomer-rev3_20140326.pdf
ã»èªèº«ã®ã¹ãããå©ç¨ããéã«ããã»ãã¥ãªãã£ãã³ã³ãã©ã¤ã¢ã³ã¹ã®æèãæã¤ã¹ã
ãå人å©ç¨ã®ã¹ããããã©ã¤ãã¼ãã§ä½¿ç¨ããå ´åã§ããèªåãä¼æ¥ã¨ããçµç¹ã®ä¸å¡ã§ããããã®çµç¹ã¨ãã¦ã®ã«ã¼ã«ããããã¨ãæèãããå¿
è¦ããããèªãã®è¡åã«ãã£ã¦èªåãå±ãã¦ããä¼æ¥ã«æ害ãä¸ããå¯è½æ§ã¯ãªããã¨ãããã¨ã常ã«å¿µé ã«ããã¦ãçºè¨ããããªããã¨ãç解ãã¦ããããã°ãªããªãã
ãçºè¨å 容ããæ©å¯æ å ±ã®æ¼ããã«ã¤ãªãããªããã¨ãã観ç¹ã¯ãã¡ãããä¼æ¥ãå®ããã½ã¼ã·ã£ã«ã¡ãã£ã¢ããªã·ã¼ãã³ã³ãã©ã¤ã¢ã³ã¹ãéµå®ãããã¨ã大åã ã社ä¼äººã¨ãªã£ãããã«ã¯ã常ã«èªåã®è¡åã«è²¬ä»»ãæã¤å¿ è¦ãããã®ã ãæ°å ¥ç¤¾å¡ã«å¯¾ããæ å ±ã»ãã¥ãªãã£ãã³ã³ãã©ã¤ã¢ã³ã¹ã«é¢ããç ä¿®ã«ã¤ãã¦ã¯ã以ä¸ã®è¨äºãåèã«ãã¦ã»ããã
ç ä¿®ã³ã³ãµã«ã¿ã³ãã«èãæ°å
¥ç¤¾å¡åãæ
å ±ã»ãã¥ãªãã£ç ä¿®ã®ãã¤ã³ãã¨ã¯ï¼
https://eset-info.canon-its.jp/malware_info/trend/detail/190423.html
ã»ä¸çªæ³¨æãã¹ãã¯èªåèªèº«ã§ããã社ä¼äººã¨ãã¦ã®èªè¦ãéè¦
ãå¤é¨ããã®æªæãæã£ãæ»æã«å¯¾å¦ãããã¨ã¯ãã¡ããéè¦ã ããèªåèªèº«ã®ããã£ããããã¹ã§ãä¼ç¤¾ã«æ害ãä¸ãã¦ãã¾ãã»ãããå¯è½æ§ã¨ãã¦ã¯é«ããã¨ã«çæããããèªãã®ãã¹ã§ä½ãããããã¦ãã¾ã£ãå ´åãèªèº«ã¸ã®ããã«ãã£ã¯æ±ºãã¦å°ãããªããã¨ãèªèãã¹ãã ãå¦çæ代ã¯ã大ç®ã«ã¿ã¦ãããããã¹ã§ãã社ä¼äººã§ã¯ãã®è²¬ä»»ãã¨ããããããªãå ´é¢ãåºã¦ããã
ãç¹ã«ããã¹ã®ããã¾ãããã¯å¤§ããªè´å½å·ã«ãªããããªããå¾ãããã¹ãçºè¦ããå ´åããããããªãããã§ã¯æ¸ã¾ããæ²æãå è·ãææªã®å ´åã¯å¤é¡ã®æå®³è³ åãè«æ±ãããå¯è½æ§ãããããããä½ããå¼ãèµ·ããã¦ãã¾ã£ãå ´åãããã®çããããã¨ããå ´åã¯ãä½ãããå ã«ãå ±åã»é£çµ¡ã»ç¸è«ãããããªããã¨ãæ±ãããããæ©ãã«å ±åããããã¨ã§ã¤ã³ã·ãã³ãã¸ã®å¯¾å¦ãæ©ã¾ãã被害ãæå°éã«é²ãå¯è½æ§ãããããã®å¾¹åºãæ°å ¥ç¤¾å¡ã«ã¯ä¿ãã¦ã»ããã
åèè³æ
ã以ä¸ãæ°å
¥ç¤¾å¡ç ä¿®ã«å½¹ç«ã¤ã»ãã¥ãªãã£å¯¾çè³æãäºã¤æããããããããã®ã¾ã¾å©ç¨ãã¦ãããããåèã«ãã¦æ°ãã«è³æãä½ãã®ãããã ããã大ãã«æ´»ç¨ãã¦ã»ããã
åãã¦ã®æ
å ±ã»ãã¥ãªãã£å¯¾çã®ãããï¼IPAï¼
https://www.ipa.go.jp/security/antivirus/documents/09_hazimete.pdf
çºè¡ï¼2012å¹´1æ
æ
å ±ã»ãã¥ãªãã£èªæ¬ãæè²ç¨ãã¬ã¼ã³è³æï¼IPAï¼
https://www.ipa.go.jp/security/publications/dokuhon/ppt.html
çºè¡ï¼2014å¹´11æ
ãã®è¨äºã®ç·¨éè ã¯ä»¥ä¸ã®è¨äºããªã¹ã¹ã¡ãã¦ãã¾ã
-
ãã¸ã¿ã«
è延ãããã¸ãã¹ã¡ã¼ã«ã¸ã®è©æ¬ºã«é¨ããããªï¼ -
ãã¸ã¿ã«
ãããã¹ãã¼ã«ã¼ã¯ããªããã¤ã³ã¿ã¼ãããã«ã¢ããããæ å ±ãçã£ã¦ãã -
ãã¸ã¿ã«
ã»ãã¥ãªãã£ã¼ã¢ããªãé¨ã£ãå½ã¢ããªã®è å¨ -
ãã¸ã¿ã«
SMSãã¼ã¹ã®2段éèªè¨¼ãè¿åãããã«ã¦ã§ã¢ã¢ããªãçºè¦ -
ãã¸ã¿ã«
æ°ããªãWannaCryptorãã«ãªããããããªãèå¼±æ§ãBlueKeepãã¨ã¯ï¼ -
ãã¸ã¿ã«
macOSãçã£ããã«ã¦ã§ã¢ãã¢ãããã¼ãã§æ©è½è¿½å -
ãã¸ã¿ã«
å¤ããããã»ãã¥ãªãã£æ¨æºãæ¥æ¬HPã追ãæ±ãããã¼ãã¦ã§ã¢ã¬ã¤ã¤ã¼ã«ãããã»ãã¥ãªãã£å¯¾çã¨ã¯ï¼ãåç·¨ã -
ãã¸ã¿ã«
Windowsã®ã¼ããã¤èå¼±æ§ãä¿®æ£ããããããªãªã¼ã¹ -
ãã¸ã¿ã«
å·§å¦åããæ¨çåã¡ã¼ã«ã®è¦åãæ¹ã¨å¯¾å¿æ¹æ³ -
ãã¸ã¿ã«
ã¹ãã¤ã°ã«ã¼ããTurlaãã®PowerShell使ç¨æ¹æ³ãåæ -
ãã¸ã¿ã«
é«ãã»ãã¥ãªãã£ãèªãã¦ã©ã¬ããã¢ããªãKyashã -
ãã¸ã¿ã«
æ¥æ¬èªç°å¢ãçã£ãã°ãã¾ãåã¡ã¼ã«ã観測 6æã®ã»ãã¥ãªãã£ã¼æ å ±ã¾ã¨ã -
ãã¸ã¿ã«
社å ãã¼ã¿ã®æã¡åºãã§é®æãããªãããã«ããã¬ã¯ã¼ã¯æ代ã®æ å ±æ¼ãããªã¹ã¯é²æ¢ã¨ã¯ -
ãã¸ã¿ã«
ã¹ããã®PINããã¯ã³ã¼ããèªçæ¥ã«ããå±éºæ§ -
ãã¸ã¿ã«
æ°ãããã½ã³ã³ãè²·ã£ãããã¾ããã£ã¦ããããã㨠-
ãã¸ã¿ã«
ãããã®æ¸©åºã«ãªãããããå¦æ ¡è£ãµã¤ããã®å¤é·ã¨ãã®å¯¾å¦ã¨ã¯