æã®ãã£ãã·ã³ã°ãããããè¦ãã調æ»ã®ã¨ãã«çæãããã¯ãã¼ãã³ã°ã®ãã¨
ã¯ããã«
ãã£ãã·ã³ã°è©æ¬ºã¯ä¼æ¥ã«ãå人ã«ãè¿«ã身è¿ãªãµã¤ãã¼è
å¨ã®1ã¤ã§ããããããå ãã被害件æ°ã®å²åã¯ãµã¤ãã¼æ»æå
¨ä½ã§è¦ã¦ãããããæå¤§ã¯ã©ã¹ã§ãã
å¤§è¦æ¨¡ãª SOC ã CSIRT ã«æå±ãã¦ããæ¹ã«ã¨ã£ã¦ã¯ã対å¿ãããã¨ãå¤ãã¢ã©ã¼ãã»ã¤ã³ã·ãã³ãã®ä¸ã¤ã«ãªã£ã¦ããã®ã§ã¯ãªããã¨æãã¾ãã
ãã¡ããã¢ã©ã¼ãã»ã¤ã³ã·ãã³ããããã°å¯¾å¿è
ããã£ãã·ã³ã°ãµã¤ãã®èª¿æ»ãããå¿
è¦ãåºã¦ãã¾ãããããã§ä¸ã¤èª²é¡ã«ãªãã®ã¯ ã¯ãã¼ãã³ã° ã®åå¨ã§ãã
ã¯ãã¼ãã³ã°ã¯ä¸è¬çãªITç¨èªãªã®ã§ãã§ã«ç¥ã£ã¦ããæ¹ãå¤ãã¨æãã¾ãããããããã¢ã¯ã»ã¹å
ã®æ
å ±ãé ¼ãã«è¡¨ç¤ºããã³ã³ãã³ããå¤ããæè¡ã®ãã¨ã§ããã
wacul-ai.com
ãã£ãã·ã³ã°ãµã¤ããã¯ãã¼ãã³ã°ã«ãã£ã¦ãã£ãã·ã³ã°ç¨ã³ã³ãã³ãã¨è¯æ§ã³ã³ãã³ãã®è¡¨ç¤ºãåãæ¿ãã¦ããã®ã§ãããåé¡ã¯ãã®ã¯ãã¼ãã³ã°æè¡ã¯å¯¾å¿è
ã»ãªãµã¼ãã£ã¼å´ããã¯è¦ããªããã©ãã¯ããã¯ã¹ã®åå¨ã§ããã¨ããç¹ã§ãã
ãUser Agent ã«ãã£ã¦åä½ãå¤ããã, ãIPã¢ãã¬ã¹ã«ãã£ã¦ãåä½ãå¤ããããªãã¦è©±ã人ããèãããã¨ã¯ããã¾ãããå®éã«ã³ã¼ããè¦ããã¨ããªãã®ã§èª¿æ»ãä¼èã®ç¥è¦ããã¨ã«ããããããã¾ããã
çè
ãããã¾ã§ã¯ãµã¼ãå´ã®ã³ã¼ããè¦ããã¨ããªãã£ãã®ã§åã§èª¿æ»ãè¡ã£ã¦ããã®ã§ãããä»åã²ãããªæ©ä¼ã§ãã£ãã·ã³ã°ããããè¦ãæ©ä¼ããã£ãã®ã§ããã£ãã·ã³ã°ãµã¤ãã使ãã¯ãã¼ãã³ã°æè¡ãã³ã¼ãã¬ãã«ã§ç¢ºèªãã¦ã¿ããã¨ã«ãã¾ããã
ãã£ããã®é·æä¼æä¸ãªã®ã§ãã¤ãã¨éãåæããã¦ã¿ããã¨ããã¢ãããããã調ã¹ãçµæãç°¡åã§ã¯ããã¾ããã¡ã¢æ¸ãç¨åº¦ã«æ®ãã¾ããçè
ã¨åããããªå¢éã«ãã¦ãã£ãã·ã³ã°ãµã¤ãã®èª¿æ»ãããæ©ä¼ããã£ãå ´ååèã«ãã¦ããã ããã°å¹¸ãã§ãã
å 責äºé
æ¬æç¨¿ã¯ãã£ãã·ã³ã°ãããã®ä½¿ç¨ãä¿ãå
容ã§ã¯ããã¾ããããã£ã¦ããã£ãã·ã³ã°ãµã¤ãã®æ§ç¯ã¨ãã£ãé¨åã«ã¯è§¦ãããã¨ãããã¾ããã
ããã¾ã§è¡ããã¨ã¯ã½ã¼ã¹ã³ã¼ãããã¼ã¹ã«æ»æè
ãè¡ã£ã¦ããã¯ãã¼ãã³ã°ææ³ãåæãããã¨ã§ããããªãµã¼ãã£ã¼ã广çã«ãã£ãã·ã³ã°ãµã¤ãã調æ»ããããã®è¦ç¹ãå¦ã¶ãã¨ãç®çã¨ãã¦ãã¾ãã
æ¬æç¨¿å
å®¹ãæªç¨ç®çã§ã¯ä½¿ç¨ããªãã§ãã ããã
ãã¨ã®ããã¾ã
2023å¹´9æã®é ã16shop ã¨ãããã£ãã·ã³ã°ãããã使ç¨ãã¦ãããµã¤ãã¼ç¯ç½ªè
ãæµ·å¤ã§é®æãããäºä»¶ã¯çããã®è¨æ¶ã«ãæ°ããã¨æãã¾ãã
çè
ãä¸è¨ã®TrendMicroããã®è¨äºãè¦ãªãããã®å績ã®è©³ç´°ã追ãã¨ã¨ãã«ãç°¡åã«ãã£ãã·ã³ã°ãµã¤ãã使ã§ããã16shopãã¨ãããã¼ã«ãããã«ã¤ãã¦ãæ¦è¦ãç¥ããã¨ãã§ãã¾ããã
www.trendmicro.com
......ããè¨äºã®ä¸ã§ä¸æã®ç»åãç®ã«çã¾ãã¾ãããã㯠Maltego ã§ã®åæç»åã§ããããVirusTotal ã«16shopã®ãã£ãã·ã³ã°ããããã¢ãããã¼ãããã¦ããããã§ãã

ãªãããããã¢ãããã¼ãããã¦ãããçç±ã¯ãããã¾ãããããã¼ã«ã¯æµ·è³çãåå¨ãã¦ãããããªã®ã§ãã©ããã§æµ·è³çãå ¥æããæ»æè ãã¦ã¤ã«ã¹ã®ãã§ãã¯ãããããã« VirusTotal ã«ã¢ãããã¼ããããããã®ããããã¾ãããä½ã¯ã¨ãããã`16shop` ã¨ãããã¼ã¯ã¼ãã®ãã zip ã ãã§ VirusTotal ããè¦ã¤ãããã¨ãã§ãããã§ãã
試ãã«ã以ä¸ã®ã¯ã¨ãªã試ãã¦ã¿ã㨠47 ä»¶ã»ã©åå¨ãã¾ããã TrendMicro ããã®è¨äºã«ããå½åã¨åããªã®ã§ãããããæµ·è³ç(?)ã®16shopãã£ãã·ã³ã°ãããã®ããã§ãã
entity:file tag:zip name:16Shop

ãã£ããè¦ã¤ãã£ãã®ã§ããã¼ã«ããããåæãã¦çè
ã®ä¸ã§ãã©ãã¯ããã¯ã¹åãã¦ããã¯ãã¼ãã³ã°æè¡ãã¯ãªã¢ã«ãã¦ã¿ããã¨ã«ãã¾ããã
ããã§ãåã§ãã£ã¦ããã¯ãã¼ãã³ã°å¯¾çãããè«ççã«è¡ä½¿ãããããã«ãªãã§ãããã
16shop ãã£ãã·ã³ã°ãããã®èª¿æ»
åºæ¬æ å ±
ä»åã®åæãã対象ã¯ä»¥ä¸ã®ãããã§ããããã対象ã¨ããçç±ã¯ãæç¨¿æ¥æãæãæ°ããã£ãããã§ãã
www.virustotal.com
ãã¡ã¤ã«åãã16Shop-Amazon.zipããªã®ã§ããããã Amazon ã®ãã£ãã·ã³ã°ãµã¤ãæ§ç¯ç¨ã ã¨æããã¾ããzip ã® Bundle info ã«ãã Latest Content Modification ã 2023-05-31 ãªã®ã§ããããã4ãæã»ã©åã«ä½ããããã®ãªã®ã§ã¯ãªããã¨æ¨æ¸¬ã§ãã¾ãã
æ¦è¦
ä»åå ¥æãããã¼ã«ã®ä¸èº«ãè¦ãã¦ã¿ãã¨ãã©ããã php ã§æ¸ããã¦ãããã¼ã«ã®ããã§ãindex.php ã¸ã®ã¢ã¯ã»ã¹ãããã§ã«å¤§éã®ã¯ãã¼ãã³ã°å¦çãè¡ããã¦ãã¾ããç»åã«è¦ãã blocker.php, blocklist.php ãªã©ãããã«è©²å½ããå¦çã§ãããèªã¿è¾¼ãã§ãã php ãã¡ã¤ã«ã®éãå¤ããã¹ã¦ã®å¦çãåæãã¦ããã¨è¨äºã®å 容ãé常ã«é·ããªã£ã¦ãã¾ããããããã¤ãã«ã°ã«ã¼ãã³ã°ãã¦è¦ç¹ã ãã¾ã¨ãã¦ããããã¨æãã¾ãã

ä½è«ã§ããTrendMicro ããã®è¨äºãè¦ãéã¯ãã¼ã«ããã㯠python ã§å®è£
ããã¦ããããã«è¦ããã®ã§ãæä»£ã種é¡ã«ãã£ã¦ãããã®æ§æã¯ä¸æ°ããã¦ããã®ããããã¾ããã*1
ã¯ãã¼ãã³ã°å¦çé¨åã®è©³ç´°åæ
16shop ã®å ´åããã£ãã·ã³ã°ã³ã³ãã³ãã表示ããããã©ããã«ä½¿ã£ã¦ããæ å ±ã¯ä»¥ä¸ã®ããã§ãã
- CLIENT-IP, X-FORWARDED-FOR ããã
- ã¢ã¯ã»ã¹å ã®IPã¢ãã¬ã¹
- ã¢ã¯ã»ã¹å ã®ãã¹ãå
- ã¢ã¯ã»ã¹å ã®ISP
- User-Agent ããã
- Referer ããã
ããããããããã«æ¸ãã¾ãããã宿 ã¨ãã¦ã¯ ã¢ã¯ã»ã¹å ã®IPã¢ãã¬ã¹ 㨠HTTP header ã«ãã User-Agent ã®2ã¤ã§ããã¾ãç¨åº¦ã« Referer ãããç¨åº¦ã§ããããããIPã¢ãã¬ã¹é¨åã«ã¤ãã¦ã¯ããããæ£è¦å©ç¨è ãã©ããã®å¤å®ãã¸ãã¯ãå¤ãã®ã¨ãããããIPã¢ãã¬ã¹ãã©ã®ããã«ãã¦å¤å®ãããã¨ãããã¸ãã¯ãããããå°ãå°åãã«ãã¦è¨è¿°ãã¦ã¾ããããããã¯ãåé ç®ãç´°ããè¦ã¦ããã¾ãã
CLIENT-IP, X-FORWARDED-FOR ããã
大åæã¨ãã¦ããã®ãã£ãã·ã³ã°ãããã¯ã¢ã¯ã»ã¹å ã®IPã¢ãã¬ã¹ãåå¾ãããããbotã®ã¢ã¯ã»ã¹ãblacklistã«ç»é²ãããIPã¢ãã¬ã¹ã§ãã£ãå ´åã¯ãã£ãã·ã³ã°ã³ã³ãã³ããè¿ãããããã¯ããã¨ãã仿§ãæã£ã¦ãã¾ããã§ã¯ãããããã¢ã¯ã»ã¹å ã®IPã¢ãã¬ã¹ãã©ã®ããã«åå¾ãã¦ãããã¨ããã¨ä»¥ä¸ã®é¨åã®ã³ã¼ãã§ãã

çè ãè¦ã¦é©ãã¾ãããããã¸ãã¯ãããªãã¶ã«ã§ãããã®ã³ã¼ãã§ã¯ HTTP header ã« CLIENT-IP ã¾ã㯠X-Forwarded-For ãããå ´åãããããçã£å ã«åªå ãã¦IPã¢ãã¬ã¹ã¨ãã¦èªèãã¾ãããã®å ã«æ§ã ãªã¯ãã¼ãã³ã°å¦çãããã¾ãããã¾ãã¯çæ³ã«è¦ããIPã¢ãã¬ã¹ããããã®ãããã¼ã«å ¥ãããã¨ãã試ãã¦ã¿ã¦ãããããã§ãã
ã¢ã¯ã»ã¹å ã®IPã¢ãã¬ã¹
ã§ã¯çæ³çã«è¦ããIPã¢ãã¬ã¹ã¯ä½ãã¨ããã¨ãblacklist ã«è¼ã£ã¦ããªãIPã¢ãã¬ã¹ã鏿ãããã¨ã«ãªãã¾ããblacklist ã«è¼ã£ã¦ããIPã¢ãã¬ã¹ã¯åçºã®ãã®ãããã°ä¸å®ã®ã¬ã³ã¸ã®ãã®ãããã®ã§æ³¨æãå¿
è¦ã§ãããä¾ãã°ãã¬ã³ã¸ã§ã®blacklistãè¦ãã¨TOR ã AMAZON ã®IPã¢ãã¬ã¹å¸¯ãªã©ã¯åºæ¬çã«blockããã¦ãã¾ããã¨ãããã TOR ããã¢ã¯ã»ã¹ãã¦ãã¯ãã¼ãã³ã°ã«é»ã¾ãã¦ãã¾ãå¯è½æ§ã¯åäºåã«ããã¾ããã
ã¢ã¯ã»ã¹å ã®ãã¹ãå
ããã§ã¯IPã¢ãã¬ã¹ããgethostbyaddrã§ãã¹ãåãåãåãããblacklist ã«ãªããããã§ãã¯ãã¾ãããããããªããå
è¿°ã¹ãIPã¢ãã¬ã¹ãã§ãã¯ã®ãã¸ãã¯ã§ã¯ãªã $_SERVER['REMOTE_ADDR'] ã§åå¾ããIPã¢ãã¬ã¹ãããã¹ãåãåå¾ãã¦ããã®ã§ãçµå±ã®ã¨ããã¢ã¯ã»ã¹å
ã®IPã¢ãã¬ã¹ã¯Header以å¤ã§ããã¡ãã¨å½è£
ããå¿
è¦ãããããã§ãã
ä¸ããã£ã¨è¦ã¦ã¿ã㨠VPN ã®ãã¹ãåãªã©ããã§ãã¯ãã¦ããã®ã§ãVPN ã¢ã¯ã»ã¹ãã©ãããã¯ãã¼ãã³ã°ã®å¯¾è±¡ã«ãã¦ããããã§ããçè
㯠NordVPN ã ExpressVPN ã使ãã¾ããã©ã¡ããblacklistã«å
¥ã£ã¦ããã®ã§VPNã®å¥ç´ããªã¨ã¼ã·ã§ã³ãå¢ããå¿
è¦ããããªã¨åèªèãã¾ããã
ã¢ã¯ã»ã¹å ã®ISP
ãã¡ãã¯IPã¢ãã¬ã¹ã®åå¾ãã¸ãã¯ã§åå¾ããIPv4ã«å¯¾ãã¦ãInternet Service Provider ãåãåããã¦blacklistã«å½ã¦ã¯ã¾ã£ãå ´åå¼¾ããã¸ãã¯ã§ãã
ä¸ãè¦ãã¨ãDigital Ocean ãã Choopa ãããªãµã¼ãã£ã¼å´ãããæ»æã¤ã³ãã©ã¨ãã¦ä½¿ããã¦ããã®ãè¦ãæååã¯è¦ãã¾ããããOCN ãªã©ã®æ¥æ¬ã®å©ç¨è
åãã®ãã®ã¯è¦ãã¾ããã§ããããããã® Provider 㯠bot ã°ããã§ä¸è¬çãªå©ç¨è
ãããªãã¨ãã夿ãªã®ã§ãããããã
User-Agent ããã
ãã®ãããããåºæ¬çã«ã¯ blacklist ã«ããããããã®ãå¼¾ãä»çµã¿ãªã®ã§ãWebã§æ¤ç´¢ãã¦ä¸è¬äººã使ç¨ãã OS, Browser ã®ãã®ãå¼ã£å¼µã£ã¦ããã°å¼¾ããããã¨ã¯ãªãããã§ããããã¡ããéã« curl ããããpython ã® requests ã§è¨ªãããããå ´åã¯å¼¾ãããã®ã§ CLI ããæ¤è¨¼ãããå ´åã¯å¿
ã User-Agent ã夿´ãã¾ãããã
Referer ããã
Referer ã® blacklist 㯠.htaccess å´ã«ãã®è¨è¼ãããã¾ãããã©ããã phishtank ããã®ã¢ã¯ã»ã¹ãªã©ã¯ããã§å¼¾ããããã«ãã¦ããå®è£
ã®ããã§ããReferer ã¯ãããã«å
¥ã£ã¦ããå ´åã«å¼¾ãææã¨ãã¦ä½¿ããã¦ãããããªã®ã§åºæ¬ã¯è¨å®ããã¨ãåé¡ãªãã¨ã¯æãã¾ãããWebãµã¼ãã¹çµç±ã§èª¿æ»ãè¡ãå ´åãªã©ã¯èæ
®ããå¿
è¦ãããããã§ãã
ãã®ä»ãæ°ã«ãªã£ããã¨
ããã¯ã¯ãã¼ãã³ã°ã®ä»çµã¿ã¨ã¯ããã話ã¨ãªãã¾ãããblacklist ãªã©ã«ãã£ã¦botå¤å®ãããå ´åã®IPã¢ãã¬ã¹ãçç±ã¯ãã®é½åº¦è¨é²ããã¦ãã¦ãããã¯ãããã§ãã¦ãããªã¼ãã¨ããææ³ãæ¼ãã¾ãããä¾ãã°ã以ä¸ã®ã³ã¼ã㯠antibot[.]pw ã«IPã¢ãã¬ã¹ãåãåãã㦠bot ãã©ãããå¤å®ããå¦çãªã®ã§ãããbot å¤å®ãããå ´åã¯ãã®IPã¢ãã¬ã¹ããã¡ã¤ã«ã«æ¸ãåºãã¦ãã¾ãã

æ¸ãã ãããIPã¢ãã¬ã¹ãå³åº§ã«ä½¿ãããæ§åã¯ä»åã®ã³ã¼ããã確èªã§ãã¾ããã§ããããããããããã§æã«å ¥ããIPã¢ãã¬ã¹ãå©ç¨ãã¦ãæ»æè ãä»å¾ã®blacklistæ¡å¼µãªã©ã«æ´»ç¨ãããã®ã¨æããã¾ãããã®ãããªå¦çã¯ä»ã® blacklist å¦çã®ã³ã¼ãã§ãæ£è¦ãããããã調æ»ã®ä¸çªæåã§ãã¡ãã¨ã¯ãã¼ãã³ã°ãæèããã¢ã¯ã»ã¹ããããã©ãããé常ã«å¤§åãªãã¨ããããã¾ãããããå¼¾ãããå ´åãå³åº§ã«VPNã®åãæ¿ããªã©ãè¡ã£ãæ¹ãè³¢æããããã¾ããã
ä½è«ã§ãããã³ã¼ããæåã«è¦ãã¨ãã¯ããä¸åº¦ã¢ã¯ã»ã¹ããIPã¢ãã¬ã¹ã§botå¤å®ãããã blacklist å
¥ããããã¨ãã£ãè¨å®ãå
¥ã£ã¦ããå ´åãã¨ããããã¡ã¼ã«ã«æ¸ããã¦ããURLãå
¨é¨éã«curlãããã¨ã§ä¼æ¥ãããã¯ã¼ã¯ã®åãåºå£ã«ãã徿¥å¡ã®è¢«å®³ãæå°éã«ã§ããããªã¼ãã¨ã妿³ãã¦ããã®ã§ããã16shop ã®å ´åãããã§ããªãããªã®ã§æ®å¿µã§ããã
ã¾ã¨ã
ç°¡åã§ããããã£ãã·ã³ã°ãããã®èª¿æ»ããã¦ãã©ãã¯ããã¯ã¹ã ã£ãã¯ãã¼ãã³ã°æè¡ãã¯ãªã¢ã«ãã¾ãããåºæ¬çã«ã¯ã¯ãã¼ãã³ã°ã¯blacklistæ¹å¼ã§è¡ããã¦ããããã§ããã£ãã·ã³ã°ãµã¤ãã«ã¢ã¯ã»ã¹ããéã«ã¯
ãæä½é工夫ãã¦ããååã®èª¿æ»ãè¡ãããªããã°ãããªããã¨ããããã¾ããããªãµã¼ãã£ã¼ã®å ´åãæ»æè ã®ç°å¢ã«ã¯åæç¨ã®ä»®æ³ç°å¢ãã TOR, VPN ãªã©ãçµç±ãã¦ã¢ã¯ã»ã¹ãããã¨ã«ãªãã¨æãã¾ããããã£ãã·ã³ã°é¢é£ã®ã¤ã³ã·ãã³ãå ±åãåãã¦ã¢ã¯ã»ã¹ããçµæããããããã®ã表示ãããªãå ´åãVPN ãå¥ã®ãã®ã«åãæ¿ããã調æ»ç¨ã®å°ç¨ç·ããã¢ã¯ã»ã¹ãããããªã¢ã¯ã·ã§ã³ãå¿ è¦ã¨ãªãããã§ãã
æå¾ã«ãªãã¾ãããæ¬æç¨¿ã¯ããã¾ã§ç¹å®ã®1ã¤ã®ãã£ãã·ã³ã°ããããåæãããµããªã«ãªãã¾ããä»ã®ãã£ãã·ã³ã°ãããã¯åããããªåä½ãããã¨ã¯éãã¾ããããããå ¥å¿µãªæºåããã¦ããæ»æè ãªãblacklist以å¤ã®ã¯ãã¼ãã³ã°æè¡ãæ½ãã¦ããããããã¾ããããããã¤ã³ãã³ã対å¿è ã¯ãã®ä»®èª¬ãå¤ããå ´åããã©ãã¯ããã¯ã¹ãªç¶æ ãã夿°ãèå¯ãã¦æ¬¡ã®æãæã¤ãã¨ã¯å¿ é ã§ãããã®æç¨¿ããã£ãã·ã³ã°ã¤ã³ãã³ãã®å¯¾å¿è ã«ã¨ã£ã¦ã®ãåå対å¿ãèããããã®ä¸å©ã«ãªãã°ã¨æãã¾ãã