ESET/ãã«ã¦ã§ã¢æ å ±å±
æ¥æ¬èªç°å¢ãçã£ãã°ãã¾ãåã¡ã¼ã«ã観測 6æã®ã»ãã¥ãªãã£ã¼æ å ±ã¾ã¨ã
ãæ¬è¨äºã¯ãã¤ãã³ãã¼ã±ãã£ã³ã°ã¸ã£ãã³ãæä¾ããããã«ã¦ã§ã¢æ å ±å±ãã«æ²è¼ããã2019å¹´6æ ãã«ã¦ã§ã¢ã¬ãã¼ããåç·¨éãããã®ã§ãã
ã1.6æã®æ¦æ³ã«ã¤ãã¦
ã2.æ¥æ¬èªç°å¢ãçã£ãã°ãã¾ãåã¡ã¼ã«
1ï¼6æã®æ¦æ³ã«ã¤ãã¦
ã2019å¹´6æï¼6æ1æ¥ï½6æ30æ¥ï¼ã«ESET製åãå½å ã§æ¤åºãããã«ã¦ã§ã¢ã®æ¤åºæ°ã¯ã以ä¸ã®ã¨ããã§ãã
ã*1 æ¤åºæ°ã«ã¯PUA (Potentially Unwanted/Unsafe Application; å¿ ãããæªæãããã¨ã¯éããªãããã³ã³ãã¥ã¼ã¿ã¼ã®ããã©ã¼ãã³ã¹ã«æªå½±é¿ãåã¼ãå¯è½æ§ãããã¢ããªã±ã¼ã·ã§ã³)ãå«ãã¦ãã¾ãã
ãå½å ãã«ã¦ã§ã¢æ¤åºæ°ã¯ã2019å¹´1æãã4æã¯æ¸å°å¾åã§ãããã5æ以éã¯å¢å å¾åã§ãã
ãæ¤åºããããã«ã¦ã§ã¢ã®å 訳ã¯ä»¥ä¸ã®ã¨ããã§ãã
å½å ãã«ã¦ã§ã¢æ¤åºæ°*2ä¸ä½ï¼2019å¹´6æï¼ | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
é ä½ | ãã«ã¦ã§ã¢å | å²å | ç¨®å¥ | |||||||
1 | JS/Adware.Agent | 14.6% | ã¢ãã¦ã§ã¢ | |||||||
2 | JS/Adware.Subprop | 10.4% | ã¢ãã¦ã§ã¢ | |||||||
3 | JS/Danger.ScriptAttachment | 5.5% | ãã¦ã³ãã¼ãã¼ | |||||||
4 | HTML/ScrInject | 5.0% | HTMLã«åãè¾¼ã¾ããä¸æ£ã¹ã¯ãªãã | |||||||
5 | DOC/Agent.DZ | 4.8% | ãã¦ã³ãã¼ãã¼ | |||||||
6 | JS/Redirector | 3.7% | ãªãã¤ã¬ã¯ã¿ã¼ | |||||||
7 | VBA/TrojanDownloader.Agent | 2.8% | ãã¦ã³ãã¼ãã¼ | |||||||
8 | Suspicious | 2.3% | æªç¥ã®ä¸å¯©ãã¡ã¤ã«ã®ç·ç§° | |||||||
9 | VBA/Agent.EH | 1.2% | ãã¦ã³ãã¼ãã¼ | |||||||
10 | Win32/Injector.Autoit | 1.1% | ä»ã®ããã»ã¹ã«ã¤ã³ã¸ã§ã¯ã·ã§ã³ãããã«ã¦ã§ã¢ |
ã*2 æ¬è¡¨ã«ã¯PUAãå«ãã¦ãã¾ããã
ã6æã«å½å ã§æãå¤ãæ¤åºããããã«ã¦ã§ã¢ã¯ãJSï¼Adware.Agentã§ãããæ¬ãã«ã¦ã§ã¢ã¯ãæªæã®ããåºåã表示ãããã¢ãã¦ã§ã¢ã§ãWebé²è¦§ä¸ã«å®è¡ããã¾ãã2çªç®ã«å¤ãæ¤åºãããJS/Adware.Subpropãåæ§ã®æåãããã¢ãã¦ã§ã¢ã§ãã
ãããã2種é¡ã®ã¢ãã¦ã§ã¢ã¯ãæµ·å¤ã§ãé常ã«å¤ãæ¤åºããã¾ãããä¸çå ¨ä½ã§æ¤åºããããã«ã¦ã§ã¢ã®ãã¡ãPUAãé¤ãã¨ãä¸ä½1ä½ãJS/Adware.Subpropã2ä½ãJS/Adware.Agentã§ããã
ã6æã«å½å ã§æ¤åºããããã«ã¦ã§ã¢ã®ãã¡ãç¹å¾´çãªãã®ãDOCï¼Agent.DZã§ããæ¬ãã«ã¦ã§ã¢ã¯ã6æ17æ¥ã«ç»é²ãããæ°ãããã«ã¦ã§ã¢ã§ããã6æå ¨ä½ã®å½å æ¤åºæ°ä¸ä½5ä½ã«ä½ç½®ä»ãã¦ãã¾ãã6æ17æ¥ãã6æ30æ¥ã¾ã§ã®14æ¥éã§ãæ¬ãã«ã¦ã§ã¢ã極ãã¦å¤ãæ¤åºããããã¨ãåããã¾ãã
ãã¾ããDOCï¼Agent.DZã¯ãæ¥æ¬ä»¥å¤ã§ã¯ã»ã¨ãã©æ¤åºã確èªããã¦ãã¾ããã6æã«æ¤åºãããDOCï¼Agent.DZã®å½å¥å²åã¯ä»¥ä¸ã®ã¨ããã§ãã
ãæ¬¡ç« ã§ãæ¥æ¬ã§å¤æ°ç¢ºèªãããDOCï¼Agent.DZã®äºä¾ãç´¹ä»ãã¾ãã
2ï¼æ¥æ¬èªç°å¢ãçã£ãã°ãã¾ãåã¡ã¼ã«
ãåç« ã§ç´¹ä»ããããã«6æã¯ãDOC/Agent.DZãå½å ãã«ã¦ã§ã¢æ¤åºæ°ã®5ä½ã«ãªãã¾ãããDOC/Agent.DZã®æ¤åºã¯ã6ï¼17ã«ã°ãã¾ãããã¡ã¼ã«ã«æ·»ä»ãããExcelãã¡ã¤ã«ã大åãå ãã¦ãã¾ãã
ãã¡ã¼ã«ã¯ä¸è¨ã®ãããªå 容ã§ããRe: è«æ±æ¸ã®éä»ããªã©ã®ä»¶åã«ãªã£ã¦ãã¾ããå ¨é¨ã§7種é¡ã®ä»¶åã確èªããã¦ãã¾ãã
ãæ·»ä»ãããExcelãã¡ã¤ã«ãå®è¡ããã¨ä¸è¨ã®ç»åã表示ããã¾ãã
ããã¯ããæå¹åãããå ´åã¯ãç»åãã¡ã¤ã«ããã¦ã³ãã¼ãããã¾ããããã¯æ¨å¹´ã«ç´¹ä»ããã¹ãã¬ãã°ã©ãã£ã¼ãç¨ããææ³ã§ããç»åãã¡ã¤ã«å ã«ãã¼ã¿ãé è½ããã¦ãã¾ãã
ãVBAï¼Visual Basic for Applicationsï¼ã®ã³ã¼ãã確èªãããã¨ããã¨ããããã¸ã§ã¯ããããã¯ããã¦ãã¾ããããã¸ã§ã¯ãã表示ã§ãã¾ããããã¨ãããã¤ã¢ãã°(å·¦ã®ç»å)ãåºã¦ã³ã¼ãã確èªã§ãã¾ãããé常ã®ããã¸ã§ã¯ãã®ããã¯ã®å ´åã¯ãVBAProjectãã¹ã¯ã¼ãå ¥åç»é¢ï¼å³ã®ç»åï¼ã表示ããã¾ããããã®æ·»ä»ãã¡ã¤ã«ã§ã¯è¡¨ç¤ºããã¾ãããæ»æè ã¯ç°¡åã«ã¯è§£é¤ã§ããªãæ¹æ³ã§ããã¯ãæãã解æ妨害ãè¡ã£ããã®ã¨èãããã¾ãã
ãVBAã®ã³ã¼ããæ½åºã確èªããã¨ã主ã«æ¥æ¬èªç°å¢ãçã£ãã¨èããããå¦çãæ¸ããã¦ãã¾ãã
ãä¸è¨ã®ã¹ã¯ãªããã¯ãLong Dateå½¢å¼ã§æ¥ä»ãåå¾ããå¦çã§ãããæ¥æ¬èªãªã©ã®ä¸é¨ã®è¨èªã®å ´åã¯ãYYYYå¹´MMæDDæ¥ãã¨ãããã©ã¼ãããã§åå¾ããã¾ããLong Dateå½¢å¼ã§åå¾ããæ¥ä»ã®æååã«ããå¹´ããå«ã¾ãã¦ããå ´åã¯ä»¥éã®å¦çãè¡ããããã§ãªãå ´åã¯çµäºãã¾ãã
ãå®éã®ãã¦ã³ãã¼ãå¦çã¯ãExcelã®ã»ã«å ã®é£èªåãããæååã解èªãããã¦ã³ãã¼ãã³ãã³ããä½æããã¾ãã
ãPowerShellã®ã³ãã³ãã¯ãé£èªåãå¤éã«æ½ããã¦ãã¾ããä¸é¨ã®é£èªåã解èªããã¨ãExcelã®VBAã³ã¼ãã¨åæ§ã«æ¥æ¬èªç°å¢ãæ¤ç¥ããå¦çã«å ãã¦ãã¤ã³ã¹ãã¼ã«ããã¦ããã¢ã³ãã¦ã¤ã«ã¹ã½ããã®æ å ±ãCPUã®æ å ±ãæ»æè ã®ãµã¼ãã¼ã«éä¿¡ããå¦çãè¨è¼ããã¦ãã¾ãããæ å ±éä¿¡ã¯Invoke-WebRequestã³ãã³ãã¬ãããå©ç¨ããã¦ããããPowerShell v3.0以éãã¤ã³ã¹ãã¼ã«ããã¦ããç°å¢ã§ã®ã¿åä½ãã¾ããWindows 8以éã¯ãPowerShell v3.0以éãæ¨æºã§æè¼ããã¦ãã¾ãã
ããã¦ã³ãã¼ãã¼ã«ããä¸è¨ã®ãããªç»åããã¦ã³ãã¼ãããã¾ããç»åå ã®é è½ããã¦ãããã¼ã¿ã解æãå®è¡ããã¨ãããã«å¥ã®ç»åï¼ã¹ãã¬ãã°ã©ãã£ã¼ï¼ããã¦ã³ãã¼ããã¾ãã
ãã¾ãã6æå¾åã«ã¯DOCï¼Agent.EAãDOCï¼Agent.EBã®æ¤åºã確èªãã¦ãã¾ãããããã®ãã«ã¦ã§ã¢ã¯ã¤ã¿ãªã¢ã§å¤ãæ¤åºããã¾ãããä¸è¨ã§ãç´¹ä»ããDOCï¼Agent.DZåæ§ãLong Dateãã©ã¼ãããã®æ¥ä»æååãå©ç¨ãã¦ãææ対象ãçµã£ã¦ãã¾ãã
ãDOC/Agent.EAã§ã¯ãLong Dateãã©ã¼ãããã®æ¥ä»æååã«ânoâãå«ã¾ãã¦ããå ´åã«ãã¦ã³ãã¼ãå¦çãè¡ããã¾ããã¤ã¿ãªã¢èªã§6æã¯âgiugnoâã¨è¡¨è¨ãã¾ãã
ãDOC/Agent.EBã¯ãå°ãè¤éã«ãªããLong Dateãã©ã¼ãããã®æ¥ä»æååããæã®æååãæãåºããæã®æååã«å«ã¾ããâgâã®æåã2æåã§ããå ´åã«ãã¦ã³ãã¼ãå¦çãè¡ããã¾ãã
ããã®ããã«è¿å¹´ã§ã¯ããã¦ã³ãã¼ãã¼ã®æç¹ã§ãç¹å®ã®ç°å¢ã§ããåä½ããªããããªè§£æ妨害ãæ½ããããã¨ãå¤ããªãã¾ãããæ»æè ã¯ãèªå解æã§åä½ããªãããã«ãããã¨ã解æãé ããããã¨ã§ãæ¤ç¥ãé ããæææ¡å¤§ãçã£ã¦ããã®ããããã¾ããã
ããç´¹ä»ããããã«ã6æã¯DOCï¼Agent.DZã¨å¼ã°ãããã«ã¦ã§ã¢ãæ¥æ¬ã§å¤ã観測ããã¾ãããããã¯æ¥æ¬èªç°å¢ãçã£ããã¦ã³ãã¼ãã¼ãæ·»ä»ãããã°ãã¾ãåã¡ã¼ã«ããã£ããã¨ãåå ã¨ãã¦èãããã¾ãã常ã«ææ°ã®è å¨æ å ±ããã£ããã¢ãããã対çãå®æ½ãã¦ãããã¨ãéè¦ã§ãã
â 常æ¥é ãããªã¹ã¯è»½æ¸ããããã®å¯¾çã«ã¤ãã¦
ãåè¨äºã§ãæ¡å ãã¦ãããããªãªã¹ã¯è»½æ¸ã®å¯¾çããæ¡å ãããã¾ãã
ãä¸è¨ã®å¯¾çãå®æ½ãã¦ãã ããã
ã1. ESET製åããã°ã©ã ã®æ¤åºã¨ã³ã¸ã³ï¼ã¦ã¤ã«ã¹å®ç¾©ãã¼ã¿ãã¼ã¹ï¼ãææ°ã«ã¢ãããã¼ããã
ãESET製åã§ã¯ã次ã
ã¨çºçããæ°ããªãã«ã¦ã§ã¢ãªã©ã«å¯¾ãã¦é次対å¿ãã¦ããã¾ãã
ãææ°ã®è
å¨ã«å¯¾å¿ã§ãããããæ¤åºã¨ã³ã¸ã³ï¼ã¦ã¤ã«ã¹å®ç¾©ãã¼ã¿ãã¼ã¹ï¼ãææ°ã«ã¢ãããã¼ããã¦ãã ããã
ã2. OSã®ã¢ãããã¼ããè¡ããã»ãã¥ãªãã£ããããé©ç¨ãã
ãã¦ã¤ã«ã¹ã®å¤ãã¯ãOSã«å«ã¾ãããèå¼±æ§ããå©ç¨ãã¦ã³ã³ãã¥ã¼ã¿ã¼ã«ææãã¾ãã
ããWindows Updateããªã©ã®OSã®ã¢ãããã¼ããè¡ããèå¼±æ§ã解æ¶ãã¦ãã ããã
ã3. ã½ããã¦ã§ã¢ã®ã¢ãããã¼ããè¡ããã»ãã¥ãªãã£ããããé©ç¨ãã
ãã¦ã¤ã«ã¹ã®å¤ããçããèå¼±æ§ãã¯ãJavaãAdobe Flash PlayerãAdobe Readerãªã©ã®ã¢ããªã±ã¼ã·ã§ã³ã«ãå«ã¾ãã¦ãã¾ãã
ãå種ã¢ããªã®ã¢ãããã¼ããè¡ããèå¼±æ§ã解æ¶ãã¦ãã ããã
ã4. ãã¼ã¿ã®ããã¯ã¢ãããè¡ã£ã¦ãã
ãä¸ãä¸ã¦ã¤ã«ã¹ã«ææããå ´åãã³ã³ãã¥ã¼ã¿ã¼ã®åæåï¼ãªã«ããªã¼ï¼ãªã©ãå¿ è¦ã«ãªããã¨ãããã¾ãã 念ã®ããããã¼ã¿ã®ããã¯ã¢ãããè¡ã£ã¦ããã¦ãã ããã
ã5. è å¨ãåå¨ãããã¨ãç¥ã
ããç¥ããªã人ãããããç¥ã£ã¦ãã人ãã®æ¹ãã¦ã¤ã«ã¹ã«ææãããªã¹ã¯ã¯ä½ãã¨èãããã¾ããã¦ã¤ã«ã¹ã¨ããè å¨ã«è§¦ãã¦ãã¾ãåã«ãçãããã¨ãã§ããããã§ãã å¼ç¤¾ãå§ããåä¼æ¥ã»å£ä½ããã»ãã¥ãªãã£ã«é¢ããæ å ±ãçºä¿¡ããã¦ãã¾ãããã®ãããªæ å ±ã«ç®ãåããããããããè å¨ãç¥ã£ã¦ããããã¨ãéè¦ã§ãã
ãâ»ESETã¯ãESET, spol. s r.o.ã®åæ¨ã§ãã
ãã®è¨äºã®ç·¨éè ã¯ä»¥ä¸ã®è¨äºããªã¹ã¹ã¡ãã¦ãã¾ã
-
ãã¸ã¿ã«
PCã使ããªãä¸ä»£ã«ã©ããªã»ãã¥ãªãã£ã¼å¯¾çæè²ãããã¹ããï¼ -
ãã¸ã¿ã«
ãã£ã¼ãªã³ã¯ã®ã«ã¡ã©ã«èå¼±æ§ããããªçã¿è¦ã«ãã¡ã¼ã ã¦ã§ã¢æä½ã -
ãã¸ã¿ã«
ã¨ã¯ã¹ããã¤ãã使ã£ãæ»æãæ¯æ¥æ°10ä¸ä»¶ãèµ·ãã¦ãã -
ãã¸ã¿ã«
macOSãçã£ããã«ã¦ã§ã¢ãã¢ãããã¼ãã§æ©è½è¿½å -
ãã¸ã¿ã«
æ°ããªèå¼±æ§BlueKeepãçºè¦ããã 5æã®ã»ãã¥ãªãã£ã¼æ å ±ã¾ã¨ã -
ãã¸ã¿ã«
ããµã¤ãã¼ã»ãã¥ãªãã£åºæ¬æ³ãã¨ã¯ãªã«ã