<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>JPCERT/CCブログ 英語版</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/" />
  <link rel="self" type="application/atom+xml" href="https://blogs.jpcert.or.jp/en/atom.xml" />
  <id>tag:blogs.jpcert.or.jp,:/en/57374</id>
  <updated>2026-07-30T04:00:13Z</updated>
  <subtitle>JPCERT Coordination Center official Blog</subtitle><entry>
  <title>TSUBAME Report Overflow (Jan-Mar 2026)</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/07/tsubame_overflow_2026-01-03.html" />
  <id>tag:movabletype.net,2003:post-3294605</id>
  <published>2026-07-23T02:00:00Z</published>
  <updated>2026-07-23T02:32:28Z</updated>
  <summary>This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the Internet Threat Monitoring Quarterly Report. This article covers monitoring results from January to March 2026....</summary>
  <author>
    <name>鹿野 恵祐 (Keisuke Shikano)</name>
    <uri>https://www.jpcert.or.jp/</uri>  </author>
  <category term="Cyber Metrics" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="TSUBAME" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the Internet Threat Monitoring Quarterly Report. This article covers monitoring results from January to March 2026.&lt;/p&gt;

&lt;h3&gt;Observation Trends Related to Japan in FY2025 (April 2025–March 2026)&lt;/h3&gt;

&lt;p&gt;JPCERT/CC analyzes data collected daily through TSUBAME. In this article, we review incidents and observation trends related to Japan based on data observed during FY2025. As noted in the Internet Threat Monitoring Report, the packets most frequently observed by TSUBAME are scans targeting 23/TCP. Some of the packets observed on 23/TCP exhibit characteristics associated with Mirai. Figure 1 shows the proportion of traffic with Mirai-like characteristics. At the beginning of FY2025, traffic associated with Mirai accounted for approximately 70% of the observed packets. However, changes began to emerge around June 2025, and by the end of the fiscal year, the proportion had declined to around 30%. Although the packets observed from around June 2025 onward did not exhibit Mirai-like characteristics, they were also generated by compromised devices. In addition to differences in packet characteristics, the targeted IoT devices also differed from those targeted by Mirai.&lt;/p&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q4_of_section1-1en.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q4_of_section1-1en.png&quot; width=&quot;934&quot; height=&quot;497&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4244497&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 1: Trend in the number of source hosts in Japan sending packets to 23/TCP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Figure 1: Trend in the number of Mirai-like sources observed on 23/TCP from Japan&lt;/p&gt;

&lt;p&gt;The following device types were notably observed among devices originating from Japan between June 2025 and the end of March 2026:
    From June to July 2025: An increase in sources without Mirai-like characteristics was observed from devices such as surveillance cameras, DVRs, and NAS devices manufactured by overseas vendors.
    From mid to late July 2025: In addition to the DVRs and NAS devices mentioned above, increases were also observed from devices such as broadband routers manufactured by Japanese vendors.
    From September to mid-October 2025: Sources without Mirai-like characteristics increased primarily from Korean-made DVR products and Chinese-made routers.
    From October 2025 to the end of March 2026: Such sources increased almost exclusively from overseas DVR products.&lt;/p&gt;

&lt;p&gt;IP addresses associated with Mirai-like scanning activity were also observed communicating over ports other than 23/TCP. This suggests that the scans were targeting Internet-accessible services and known vulnerabilities associated with specific products.&lt;/p&gt;

&lt;p&gt;Based on insights gained from these observations, JPCERT/CC shared information on Mirai-related attack trends with domestic product developers and telecommunications operators, while also discussing possible countermeasures with them. When connecting devices such as routers to the Internet, it is essential to take appropriate precautions to prevent them from becoming infected with Mirai and contributing to the growth of botnets. Users should be aware that Internet-connected devices may be accessible to attackers and ensure that they are running the latest firmware and configured securely. After deployment, we also recommend performing port scans or using services such as SHODAN to verify that unnecessary services are not exposed to the Internet.&lt;/p&gt;

&lt;p&gt;JPCERT/CC expects continued attacks targeting specific products, as well as the emergence of suspicious packet sources. We will therefore continue to investigate IP addresses originating from Japan and share observation data and analysis results with product developers and telecommunications operators to support mitigation efforts.&lt;/p&gt;

&lt;h3&gt;Comparison of the observation trends in Japan and overseas&lt;/h3&gt;

&lt;p&gt;Figure 2 shows a monthly comparison of the average number of packets received in Japan and overseas. Overseas sensors received more packets than domestic sensors. A temporary decrease was observed in February across both domestic and overseas sensors, but observation counts in March returned to levels comparable to those seen in January.&lt;/p&gt;

&lt;table style=&quot;border-collapse: collapse; width: 110.24%; height: 36px;&quot; border=&quot;1&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q4_of_section2-1.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q4_of_section2-1.png&quot; width=&quot;1114&quot; height=&quot;726&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4176880&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 2: Monthly comparison of the average number of packets received in Japan and overseas&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt; Comparison of monitoring trends by sensor &lt;/h3&gt;

&lt;p&gt;Each sensor is assigned a unique global IP address. To examine differences in observation trends among sensors in Japan, North America, Europe, and other regions, Table 1 summarizes the top 10 destination ports observed by each sensor. 23/TCP was the most frequently observed port on the majority of sensors, although some sensors observed higher traffic on 443/TCP. This suggests that scanning activity targeting these ports is being conducted across a wide range of networks.&lt;/p&gt;

&lt;p style=&quot;text-align: center;&quot;&gt;Table 1: Comparison of top 10 packets by domestic and overseas sensors&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;&lt;/th&gt;
      &lt;th&gt;Japan #1&lt;/th&gt;
      &lt;th&gt;Japan #2&lt;/th&gt;
      &lt;th&gt;North America #1&lt;/th&gt;
      &lt;th&gt;North America #2&lt;/th&gt;
      &lt;th&gt;Europe #1&lt;/th&gt;
      &lt;th&gt;Europe #2&lt;/th&gt;
      &lt;th&gt;Other regions #1&lt;/th&gt;
      &lt;th&gt;Other regions #2&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;#1&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#2&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#3&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#4&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#5&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#6&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;25/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#7&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#8&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#9&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#10&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;&lt;td&gt;3000/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3000/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;3000/TCP&lt;/td&gt;&lt;td&gt;3000/TCP&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt;In closing&lt;/h3&gt;

&lt;p&gt;Monitoring at multiple locations enables us to identify whether certain changes are occurring only within specific networks. Although no unusual activity requiring an extra issue or special alert was observed this quarter, it remains important to continue monitoring scanning activity closely. We will continue to publish quarterly blog articles on Internet threat monitoring trends and provide additional reports when significant changes are observed. We welcome your feedback on this series. Please use the comment form below to let us know which topics you would like us to cover in future articles. Thank you for reading.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Keisuke Shikano&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;(Translated by Takumi Nakano)&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>Update on Attacks by Threat Group APT-C-60 in 2026</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/07/apt-c-60_2026.html" />
  <id>tag:movabletype.net,2003:post-3286361</id>
  <published>2026-07-13T04:15:00Z</published>
  <updated>2026-07-13T04:23:44Z</updated>
  <summary>In our previous two blog posts (Dec 2024...</summary>
  <author>
    <name>増渕 維摩(Yuma Masubuchi)</name>
      </author>
  <category term="Malware" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;In our previous two blog posts (&lt;a href=&quot;https://blogs.jpcert.or.jp/en/2024/12/APT-C-60.html&quot; target=&quot;_blank&quot;&gt;Dec 2024&lt;/a&gt;, &lt;a href=&quot;https://blogs.jpcert.or.jp/en/2025/11/APT-C-60_update.html&quot; target=&quot;_blank&quot;&gt;Nov 2025&lt;/a&gt;), we discussed attacks carried out by APT-C-60 against organizations in Japan. JPCERT/CC has continued to observe similar attack activity. In the attacks covered in this article, we observed several changes in the initial access techniques and attack infrastructure used by the threat actor. This article focuses on the attack flow of APT-C-60 activity observed in 2026.&lt;/p&gt;

&lt;h2&gt;Initial Access Method&lt;/h2&gt;

&lt;p&gt;Figure 1 shows the overall attack flow. In the case we observed, the spear-phishing email contained a Proton Drive link, which was used to lure the victim into downloading a RAR file from Proton Drive. When the RAR file is extracted, it contains files including an LNK file. Once the victim opens the LNK file, the subsequent infection process is executed.
We have also confirmed a similar case in which the malicious file was attached directly to the email, without using Proton Drive as an intermediary.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/image01-800wri.png&quot; width=&quot;800&quot; height=&quot;344&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4228724 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 1: Initial access flow
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;h2&gt;Behavior of the LNK File&lt;/h2&gt;

&lt;p&gt;When executed, the LNK file used during the infection copies itself and then uses mshta.exe to execute JavaScript embedded within the LNK file. As shown in Figure 2, the LNK file contains JavaScript code, which is called after the LNK file is executed. This allows the threat actor to use a legitimate Windows program while carrying out processes that lead to the retrieval and execution of subsequent payloads.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/image02-640wri.png&quot; width=&quot;640&quot; height=&quot;545&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4226056 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 2: JavaScript code embedded in the LNK file
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;Figure 3 shows the infection flow after the LNK file is executed. Although the JavaScript code embedded in the LNK file is obfuscated, it performs the following main functions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Downloads the file contributing[1].txt from jsDelivr&lt;/li&gt;
&lt;li&gt;Searches for, decodes, and extracts the downloaded contributing[1].txt file&lt;/li&gt;
&lt;li&gt;Uses the legitimate git.exe located in the extracted folder to execute a script in the same folder&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/image03-800wri.png&quot; width=&quot;800&quot; height=&quot;385&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4226062 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 3: Infection flow after execution of the LNK file
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;Figure 4 shows the executed script. The script creates and executes a downloader by combining .db files located in the extracted folder. The downloader accesses legitimate sites such as GitHub, downloads additional downloaders and loaders, and executes them.
The technique of executing scripts using git.exe, as well as the persistence method, was also observed in attacks in 2024 and 2025, and the same techniques were used in this attack. For details, please refer to our previous two articles (&lt;a href=&quot;https://blogs.jpcert.or.jp/en/2024/12/APT-C-60.html&quot; target=&quot;_blank&quot;&gt;Dec 2024&lt;/a&gt;, &lt;a href=&quot;https://blogs.jpcert.or.jp/en/2025/11/APT-C-60_update.html&quot; target=&quot;_blank&quot;&gt;Nov 2025&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/image04-800wri.png&quot; width=&quot;800&quot; height=&quot;144&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4226070 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 4: Contents of the script
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;h2&gt;Legitimate Services Used as Attack Infrastructure&lt;/h2&gt;

&lt;p&gt;As in previous cases, multiple legitimate services were used as access destinations for the executed downloader. In the 2025 attacks, GitHub and Bitbucket were used. However, in the 2026 attacks, we confirmed that GitLab, jsDelivr, and Codeberg, in addition to GitHub, were abused as attack infrastructure.
By using legitimate services, the threat actor may be attempting to make communications and downloads appear to be normal access. In particular, developer-oriented services and CDNs are often allowed in corporate environments, which makes it difficult to detect or block the activity based solely on the communication destination.
The downloader ultimately downloads and executes malware called SpyGlace from these legitimate services. In this attack, we observed SpyGlace versions v3.1.15, v3.1.17, and v3.1.18, but did not identify any major functional differences compared with earlier versions.&lt;/p&gt;

&lt;h2&gt;In Conclusion&lt;/h2&gt;

&lt;p&gt;In the SpyGlace attack observed in this case, we confirmed the use of Proton Drive for file distribution, an LNK file contained in a RAR archive, JavaScript execution via mshta.exe, and the abuse of legitimate services such as GitHub, GitLab, jsDelivr, and Codeberg. These attacks may be difficult to detect because they abuse legitimate services and standard Windows functionality.
Users should remain vigilant and avoid opening cloud storage links in suspicious emails or LNK files contained in archives such as RAR files. The IoCs, including the C2 servers and file hashes we confirmed, are listed in the Appendix.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Yuma Masubuch&lt;br&gt;(This article was machine-translated and manually reviewed.)&lt;/p&gt;

&lt;h4&gt;Appendix A: Network IoCs (SpyGlace C2 Infrastructure)&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;31.58.136[.]207&lt;/li&gt;
&lt;li&gt;154.18.239[.]209&lt;/li&gt;
&lt;li&gt;173.234.11[.]141&lt;/li&gt;
&lt;li&gt;185.18.222[.]241&lt;/li&gt;
&lt;li&gt;213.111.158[.]200 &lt;/li&gt;
&lt;li&gt;213.111.158[.]201&lt;/li&gt;
&lt;li&gt;213.111.158[.]216&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Appendix B: URLs of Legitimate Services Used by the Attacker&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;https[:]//c.statcounter[.]com/13178005/0/7f3c2735/1/ &lt;/li&gt;
&lt;li&gt;https[:]//cdn.jsdelivr[.]net/gh/mei1990789/class125/&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Appendix C: IoC Files&lt;/h4&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Table 1: List of IoC Files
&lt;/div&gt;

&lt;table&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Content&lt;/th&gt;&lt;th&gt;Filename&lt;/th&gt;&lt;th&gt;Hash（SHA256）&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;48bb091e0cab562fe094e0ef6a77b434dba97380c09a707220cbd9ca37999484&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;5e97848bebf521766910d9c8378e98bf7aa1ce4b06aeb6c3f86c31ababbe9663&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5ca&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;71819a1b856b49e7f194ce60468ed8e5ea925c75d01484f4d28ffcf69d480b36&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;83a22d4f61b054bda53a2ea4f506e97d818c7c961d8cd3975c1f2a51443cf95c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;866564bb455bb3c9f3e15cbbc1dcaf75c533a224eb96c4b6d6739e114ee1d065&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;cc2a6a3b4b771aba341293d2321e5f7b70cf517403fe44a58635b043e8868bdb&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader1&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;fa53663bfb80e197483e1a1bf123b94fa869e2d7f42b5fdfbff2869589b65a05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;Cached2014.tmp&lt;/td&gt;&lt;td&gt;6b84eab2aac7754b99d04365a83ec374e3cea99cc3223118a5f8fd545a8483e5&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;Encoded_File.tmp&lt;/td&gt;&lt;td&gt;0bda4beded9c2923fe16f20b7cbd7baf1a5b7078be5cde715592529a974f9bd9&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;Encoded_File.tmp, inst.tmp&lt;/td&gt;&lt;td&gt;a7981dfccd8e4bdc00133dc15b22472c1677d6270826863caa36e7d58ef50de0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;a101.dat&lt;/td&gt;&lt;td&gt;1b25c3d56fdb195b427a9c3bfc1f0e98e77a15322e8d3fc53a18edcc4891847f&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;iconcache.dat&lt;/td&gt;&lt;td&gt;119ad3dce05b5ef3db5a76655ac050eac51e318f1f31351ac103693a0a849158&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;item.tmp&lt;/td&gt;&lt;td&gt;0420fd9e5f9961458604909391fb0f1a353c17c986b55fc5722c1b68e41865df&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;item.tmp&lt;/td&gt;&lt;td&gt;2952d72ad1d44f3d424600b8fa4076794e2e072ab46936012a5fb872c67ce189&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;job.tmp, akdjfiwnkd.tmp&lt;/td&gt;&lt;td&gt;3f2f69a8403e6b4e02ebe65448caf6abb8e2fbd1f7636ec71599f2d2d5fac8fb&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;newjob.tmp&lt;/td&gt;&lt;td&gt;a9fd615fce38756ba6de8994f200e4b846397648138a9a0e6ef3b5952ef5e68c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;reaconinst.tmp&lt;/td&gt;&lt;td&gt;a4c8a56070fe6f613e79a14554d0a1dba2f70ce2b93319e72972943cc66edf4a&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Downloader2&lt;/td&gt;&lt;td&gt;wincfg.db, Cached.tmp&lt;/td&gt;&lt;td&gt;c4768d99445128c670a6f848bc69371872e4d6a2160dbe0073e62ffd786c94ee&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Install Script&lt;/td&gt;&lt;td&gt;msdic.log&lt;/td&gt;&lt;td&gt;7aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Install Script&lt;/td&gt;&lt;td&gt;msdic.log&lt;/td&gt;&lt;td&gt;d567af55c97b7a595fcde5082e37a752718044230c16704e24efb43025bed0c2&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;basecode.dat&lt;/td&gt;&lt;td&gt;14d799f7897d25f7cfb4d1c86f43c791b6d778d2efd92b5fac4f65fc472bf501&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;basecode.dat&lt;/td&gt;&lt;td&gt;16bdde15cbf9190883c146bab495c8be73daff4fff5ffbf86b4ee46847103fba&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;call1.js&lt;/td&gt;&lt;td&gt;8114e3f213713dbbbacafcd0f62884a7826139b434bb3c77eae8dce656477621&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;call2.js&lt;/td&gt;&lt;td&gt;ab5aba292c983db324987e9fde2e01fe24a979d1587888fcc7460c9489c54ee0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;call3.js&lt;/td&gt;&lt;td&gt;b5458541732f91793ef89cc58ec5e46d04bf43985ab4e6dc5ad10b6da21581ec&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;call4.js&lt;/td&gt;&lt;td&gt;e6a414a53206e25d061a11e63c7d381ab0eb80cd3d174bd13551e2c36f8b5c04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;call41.js&lt;/td&gt;&lt;td&gt;1ae423e91f6cd679f9ea5be879b07379633b05cd850c37a8a65cdeaf508d097e&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;close.js&lt;/td&gt;&lt;td&gt;7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;close.js&lt;/td&gt;&lt;td&gt;94072d60170fc72a528f68b2b3826638dbb7283c8906e8051f53fe16eaf054f8&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;close.js&lt;/td&gt;&lt;td&gt;ad1c890f458b94683464c4d6d6d41fe63551c2c06ba2a1b8f71d8acb6ab16de3&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;close.js&lt;/td&gt;&lt;td&gt;ffe5853d19be1acfe12bd681c7390d8fa88534a471020e6866a9e7c37d01fea2&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.dat&lt;/td&gt;&lt;td&gt;62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;0bf85d9065feb20ee946acf77c985cc7ec78de048ee41d8c5931e0e88873efaa&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;21ddfbf726caa6d0f32a6bbce8e619f75c81f884bca48564c7a0e5a84bf4bd39&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;2c98781e39a091b370ebd748b495c45752b2c54cdf2c36814358c8c6bd3ae912&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;78c108be692f1c45ed1da1988e3c5ac792c832a78d0b6e8e6550763156fe8f97&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;9706ee93f9b4b8214293e2ca4a68525eccaacfea58b135dcb2ea661a099ee9e6&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help.js&lt;/td&gt;&lt;td&gt;a1f0e6a30dc9753c5cbc80fd9df50eb44aee5a2349223b915b758af746275320&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help_v3.js&lt;/td&gt;&lt;td&gt;3b7a80fc62eb8b248fd0be0d94c78f1efe2f510499c68865a6d0c4ead6bc4055&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help_v4.js&lt;/td&gt;&lt;td&gt;a9287e3452ab09144120ecdd20ed7365de589d5dcad28dcd8e191742d1ce5744&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;help_v5.js&lt;/td&gt;&lt;td&gt;5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;index.js&lt;/td&gt;&lt;td&gt;131d8f72fde45c5ca1f662c510c3da16fbcd8ff6ef9b9fd893c25a9c8e8ec205&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;JS File&lt;/td&gt;&lt;td&gt;test.dat&lt;/td&gt;&lt;td&gt;7d09891e26d56a8bec44c3fe9a5791f3a93e8fa31539951ae6e2c40af83ba42d&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;desk.lnk&lt;/td&gt;&lt;td&gt;2d8def39b76ca17b419e5084832105c0167a171fdcc14eebd0c872ccb7bf9b0c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;desk.lnk&lt;/td&gt;&lt;td&gt;fd0c7713520bd19c3e2566e93696532aa7da39a0c5ce1a797b67ce777b56d395&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;idx2.lnk&lt;/td&gt;&lt;td&gt;899ce01e7313f4c1cfcf07cb2456282ded1d6b6c57286762f2914a9d60de0146&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;information.lnk&lt;/td&gt;&lt;td&gt;fa98deb16bd72f2f77349c8c24de674a007a3d1ec8e88dd590791a57c08ab8f6&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;ipo6.lnk&lt;/td&gt;&lt;td&gt;44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695f&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;利権癒着の具体的内容.lnk&lt;/td&gt;&lt;td&gt;5c3d820e032592f47ffb4850ae0183749199b3e0dca3413cd0c3cb631e322f1b&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;desk.lnk&lt;/td&gt;&lt;td&gt;2d8def39b76ca17b419e5084832105c0167a171fdcc14eebd0c872ccb7bf9b0c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;desk.lnk&lt;/td&gt;&lt;td&gt;fd0c7713520bd19c3e2566e93696532aa7da39a0c5ce1a797b67ce777b56d395&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;idx2.lnk&lt;/td&gt;&lt;td&gt;899ce01e7313f4c1cfcf07cb2456282ded1d6b6c57286762f2914a9d60de0146&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;information.lnk&lt;/td&gt;&lt;td&gt;fa98deb16bd72f2f77349c8c24de674a007a3d1ec8e88dd590791a57c08ab8f6&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;LNK File&lt;/td&gt;&lt;td&gt;ipo6.lnk&lt;/td&gt;&lt;td&gt;44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695f&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;0311_2nd_sdll.dat&lt;/td&gt;&lt;td&gt;5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35d&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;Encoded_File.tmp&lt;/td&gt;&lt;td&gt;2b650e2e2c46a52378aee70fbaff1ce5e832c759c5f937532047f52500428c4d&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;Encoded_File.tmp&lt;/td&gt;&lt;td&gt;8a8cabe5f94e7f4c0ccca97f0c361618ec944df03d8b3bfcfdd76a25dd8f7a5a&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;Encoded_File.tmp, sta.tmp&lt;/td&gt;&lt;td&gt;f0af281623b422c1d45e7006d78678762341288c05abcb62648ce55c6b63acb6&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;Encoded_File2.tmp&lt;/td&gt;&lt;td&gt;8ba3997afa07ac60312edf5f2d16357d1532a140081d638a9e4653768026ac56&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sDll_jj.dll&lt;/td&gt;&lt;td&gt;86ab5161f761822d16637d4d34b84ca6e1f66cea905aa27510620c9cf5f170d8&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll.tmp&lt;/td&gt;&lt;td&gt;843c4dc402e96ed72d7716d980c99e5dfa222a2a322250b7c3755a00d142bc1f&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll.tmp&lt;/td&gt;&lt;td&gt;9a19598ea286d5f6fa0b7ff981ba21aff503fb217757f4dfbd496ead01805543&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll.tmp&lt;/td&gt;&lt;td&gt;e8514a2372172b4975f77bf69d5e8b7708cfa60157b064fcab13d7a62a99cc55&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll2.tmp&lt;/td&gt;&lt;td&gt;248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51db&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll3.tmp&lt;/td&gt;&lt;td&gt;3c509ec732979d8c91009d2c9f898bea81f3fc4064c3c56576257f61f9bfaaee&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll3.tmp&lt;/td&gt;&lt;td&gt;55640ad319208915593db8ad43724dddf6e6e17fc6b0014affa69c90f5cd1eb4&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll3.tmp&lt;/td&gt;&lt;td&gt;c1faaff24d58af798c77d34405379df0a9e883e5bd1100a86d4c3e001414acd8&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;sdll3.tmp&lt;/td&gt;&lt;td&gt;f50a01ae446adfcaaddffe215abd94b5643211e83d52acf5de540abf9fb26045&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Loader&lt;/td&gt;&lt;td&gt;test1.txt&lt;/td&gt;&lt;td&gt;6cdc895eda4847f700d6f82fa2e3a8c72c10da1e16455985df855372142ebbd8&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI003.db&lt;/td&gt;&lt;td&gt;d14214e95c9d1ea850e508dfe27928494f2155a7597e4ea0bad9f70690abb397&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;131c27c3dce040979044ac1d363050c5d226af76aef1454bbf87c7193f8fc747&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;1aaf59f05bb724d501cc9bcd6642ab8fd7347cf274d46c24719c9dced9b22bea&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3b&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;3e2bc0bd2eb84282086cc5946673b22414a16e982402f1f05ea57059d2962588&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;afca3bb9fb8d7a4ab4ceb9707f6d9a17352ccfb8ece83c68b01fbb419818e2fc&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI100.db&lt;/td&gt;&lt;td&gt;deba513e2dc52a2931e61f5ac6d550a7938c1f7f63f661867c09d6141ee98560&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI210.db&lt;/td&gt;&lt;td&gt;18683bba19695d325372d195634afd2f76b14896ba68225ba51ea5a039f2f76d&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI210.db&lt;/td&gt;&lt;td&gt;45b2ba7c7a39817e1421f2abe2f869fa16af9651a6c863ac59683268fb391fe6&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI320.db&lt;/td&gt;&lt;td&gt;555360fb918b959176d669ef0ed40ec0b5ee57005fc625109891a16d02952462&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI320.db&lt;/td&gt;&lt;td&gt;771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97a&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;002e1207b96361fc4d53b10621225d61700003241fa38caacb411384b3d51135&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;0120a6396952aec3f05ec0b0efe25e2a1b73545d55d74a3ac0bcd359d29f52bb&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2ab&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;8f08ead23767e1e4389927c40af167122b477ad17a98d388c863342dc9259c5e&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;9789d80077998010c47a6a02ef1241eab11b69d667de8751b1e93fed6df913eb&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;a18b5a78143f004f33aafad998b518ad9ee4dbdec44817a6e9b570e727d3e22c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Part of Downloader&lt;/td&gt;&lt;td&gt;TMI400.db&lt;/td&gt;&lt;td&gt;a8bee6c4a5860b0ae08a984d2a6d62c13d3e91d9514262998924d2e0cef88f7c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;RAR File&lt;/td&gt;&lt;td&gt;具体的内容.rar&lt;/td&gt;&lt;td&gt;151b2dc70d141c12a33d8e45a80659fc53a71734e27233326bff150ac87744ea&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.15&lt;/td&gt;&lt;td&gt;Encoded_File.tmp&lt;/td&gt;&lt;td&gt;e5f2c7068ade7b87d24c3b94bc749c351d53609f5fcaa48dce06234beaa2444f&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.15&lt;/td&gt;&lt;td&gt;sdll.tmp&lt;/td&gt;&lt;td&gt;9394627e9c44cf2226ddf50012e5cf47ccf7d3bd8afa2395c635a93637e23502&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.15&lt;/td&gt;&lt;td&gt;sdll.tmp&lt;/td&gt;&lt;td&gt;add013bf7ffc8a89789a7fd0ae0ff799c620af9b2755b214880b6a56768fd48c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.15&lt;/td&gt;&lt;td&gt;sdll.tmp&lt;/td&gt;&lt;td&gt;c86f319f64d25f23ac29d9b53c9764f06a150634ee8e2d836424d460e5a99b52&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.17&lt;/td&gt;&lt;td&gt;test2.txt&lt;/td&gt;&lt;td&gt;669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304c&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.18&lt;/td&gt;&lt;td&gt;test2.txt&lt;/td&gt;&lt;td&gt;3f67b777660241a1afc39f2ec388cac933a9eb31b3a34bddd12e39e663f1b566&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.18&lt;/td&gt;&lt;td&gt;test2.txt&lt;/td&gt;&lt;td&gt;7c3d0bebd263d3529132f2299de55a7801bf3ff40c833b13838be7a98ea3475e&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.18&lt;/td&gt;&lt;td&gt;test2.txt&lt;/td&gt;&lt;td&gt;86c49174a032ebbba6aeb1541e2aa84da0933b2eac3976f8705451c13bc7f325&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.18&lt;/td&gt;&lt;td&gt;test2.txt&lt;/td&gt;&lt;td&gt;b3f0d48506ff868ba145c9dcad7622bc37b723155648053ce2e2e73d8ea30e93&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SpyGlace v3.1.18&lt;/td&gt;&lt;td&gt;test2.txt&lt;/td&gt;&lt;td&gt;c9295c923da64738b93ff1827a39a5cb8f6c71eab060de416c8175a4a67da524&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;

&lt;h4&gt;Appendix D: Spear-Phishing Email Senders&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
asako.t1011@protonmail.com
ayuko0328@protonmail.com
&lt;/pre&gt;

&lt;h4&gt;Appendix E: Attacker Management Repository&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
https[:]//github[.]com/mei1990789/class125
https[:]//github[.]com/sapphire679/tblsesarol/
https[:]//github[.]com/sapphire689/dnaluakxit
https[:]//github[.]com/wanib11399/zjeqopmfit
https[:]//github[.]com/cafes39636/ngwtaepesf
https[:]//github[.]com/rapefo2905/rncprjmauw
https[:]//github[.]com/hexif45133/yedkatinrc
https[:]//github[.]com/jewexo9791/archibkyof
https[:]//github[.]com/lowege1212/izrtysherg
https[:]//github[.]com/gixop88415/glfhvhtzih
https[:]//github[.]com/kapap40675/fpqtzyofdl
https[:]//github[.]com/cefobe3574/kojyyvtkqo
https[:]//github[.]com/vogenoc114/qlofnsayvl
https[:]//github[.]com/bohihef411/tuikfwoveb
https[:]//github[.]com/waxiyes819/dymcdbqqen
https[:]//github[.]com/fehijow850/uywcrcvlnb
https[:]//github[.]com/yefixi3890/krbgqbmlho
https[:]//github[.]com/williams250666/bluenote554
https[:]//gitlab[.]com/sapphire689/dnaluakxit
https[:]//gitlab[.]com/cafes39636/ngwtaepesf
https[:]//gitlab[.]com/rapefo2905/yedkatinrc
https[:]//gitlab[.]com/lowege1212/eboralfotj
https[:]//gitlab[.]com/kapap40675/fpqtzyofdl
https[:]//gitlab[.]com/vogenoc114/qlofnsayvl
https[:]//gitlab[.]com/waxiyes819/dymcdbqqen
https[:]//gitlab[.]com/yefixi3890/krbgqbmlho
https[:]//codeberg[.]org/ochi_ma992/3tv9239irfn83
https[:]//codeberg[.]org/meca922199/ertlokefgpokjper2359
https[:]//codeberg[.]org/Hamilton385673/eff88e889w33456
&lt;/pre&gt;

&lt;h4&gt;Appendix F: Email Addresses Used for Commits&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
sapphire679@proton.me
sapphire689@proton.me
meimei91@protonmail.com
rapefo2905@outlook.com
jewexo9791@outlook.com
legDevMachine@protonmail.com
&lt;/pre&gt;

&lt;h4&gt;Appendix G: Victimized Devices Identified from the GitHub Repository (Volume Serial Number and Computer Name)&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
1510781397@DESKTOP-CJU6TU7
1785033524@2024NOTEBOOK
2264373920@DESKTOP-S9E6ADG
2419945818@BD1
2428126365@SDI-WIN
242922728@DESKTOP-5K5ICQ5
2590771213@DESKTOP-LAVUNRP
317267226@DESKTOP-V1R49JC
3290476432@DESKTOP-J734R21
3362573326@DESKTOP-43R2GH0
3386414762@DESKTOP-MKV3QN0
3629482019@DESKTOP-8UM79S5
3704188960@DESKTOP-D1Q1I0J
3836479251@ADMIN-PC
409023259@JAY-PC
4127454498@DANY-LAPTOP
4166053503@LAPTOP-JHA4UD2S
582552893@LV
1409377236@DESKTOP-6OND78S
2283291050@DESKTOP-9CPEB4D
2590772946@DESKTOP-GL14J4L
3159231749@DESKTOP-SS0PND9
4166214414@DESKTOP-B9JE10V
840033591@DESKTOP-DBNHUR7
&lt;/pre&gt;

    

  </content>
</entry>
<entry>
  <title>TSUBAME Report Overflow (Oct-Dec 2025)</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/05/tsubame_overflow_2025-10-12.html" />
  <id>tag:movabletype.net,2003:post-3248898</id>
  <published>2026-05-14T04:30:00Z</published>
  <updated>2026-05-15T06:23:55Z</updated>
  <summary>This TSUBAME Report Overflow series discuss monitoring trends of overseas TSUBAME sensors and other activities which the Internet Threat Monitoring Quarterly Reports do not include. This article covers the monitoring results for the period October to December 2025. Suspicious Packets...</summary>
  <author>
    <name>鹿野 恵祐 (Keisuke Shikano)</name>
    <uri>https://www.jpcert.or.jp/</uri>  </author>
  <category term="Cyber Metrics" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="TSUBAME" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;This TSUBAME Report Overflow series discuss monitoring trends of overseas TSUBAME sensors and other activities which &lt;a href=&quot;https://www.jpcert.or.jp/tsubame/report/&quot;&gt;the Internet Threat Monitoring Quarterly Reports&lt;/a&gt; do not include. This article covers the monitoring results for the period October to December 2025.&lt;/p&gt;

&lt;h3&gt;Suspicious Packets Originating from DVR/NVR Devices&lt;/h3&gt;

&lt;p&gt;A review of the number of hosts in Japan sending traffic to Telnet (23/TCP) shows a temporary spike in October, followed by a downward trend beginning around November 7 (Figure 1).&lt;/p&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-1.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-1.png&quot; width=&quot;1280&quot; height=&quot;929&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4135347&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 1: Trend in the number of source hosts in Japan sending packets to 23/TCP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;However, a closer look at the sources indicates that many of these connections appear to originate from specific groups of DVR/NVR devices. On some days, these devices accounted for roughly 80% of the total, suggesting that a considerable number of such devices are still actively communicating with external networks. Below are examples of login screens observed from these device groups (Figures 2–5).&lt;/p&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-2.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-2.png&quot; width=&quot;1280&quot; height=&quot;720&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4135423&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 2: Example of a device likely to be a DVR/NVR product&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-3.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-3.png&quot; width=&quot;1280&quot; height=&quot;731&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4135426&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 3: Example of a device likely to be a DVR/NVR product (2)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-4.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-4.png&quot; width=&quot;1280&quot; height=&quot;720&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4135461&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 4: Example of a device likely to be a DVR/NVR product (3)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-5.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section1-5.png&quot; width=&quot;1280&quot; height=&quot;720&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4135463&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 5: Example of a device likely to be a DVR/NVR product (4)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Some of these interfaces display outdated copyright years (e.g., 2014), which suggests that firmware may not have been updated for a long time. Devices in this state may still contain known vulnerabilities, making them more susceptible to attacks from the Internet. If you are using similar devices, we recommend checking whether they fall into this category and taking this opportunity to ensure that firmware updates are properly applied.&lt;/p&gt;

&lt;h3&gt;Comparison of the observation trends in Japan and overseas&lt;/h3&gt;

&lt;p&gt;Figure 6 is a monthly comparison of the average number of packets received in Japan and overseas. Overseas sensors received more packets than those in Japan. Additionally, a gradual upward trend was observed from October onward across both domestic and overseas sensors.&lt;/p&gt;

&lt;table style=&quot;border-collapse: collapse; width: 110.24%; height: 36px;&quot; border=&quot;1&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section2-1.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/2025q3_of_section2-1.png&quot; width=&quot;1114&quot; height=&quot;726&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4135467&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 6: Monthly comparison of the average number of packets received in Japan and overseas&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt; Comparison of monitoring trends by sensor &lt;/h3&gt;

&lt;p&gt;Each sensor is assigned a single global IP address. To examine differences in monitoring trends among sensors in Japan, North America, Europe, and other regions, Table 1 summarizes the top 10 destination ports that received packets. Although the rankings vary by sensor, ports such as 22/TCP, 23/TCP, 80/TCP, 443/TCP, and 8080/TCP were observed by almost all sensors. This suggests that scanning activity targeting these protocols is being conducted across a wide range of networks.&lt;/p&gt;

&lt;p style=&quot;text-align: center;&quot;&gt;Table 1: Comparison of top 10 packets by domestic and overseas sensors&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;&lt;/th&gt;
      &lt;th&gt;Japan #1&lt;/th&gt;
      &lt;th&gt;Japan #2&lt;/th&gt;
      &lt;th&gt;North America #1&lt;/th&gt;
      &lt;th&gt;North America #2&lt;/th&gt;
      &lt;th&gt;Europe #1&lt;/th&gt;
      &lt;th&gt;Europe #2&lt;/th&gt;
      &lt;th&gt;Other regions #1&lt;/th&gt;
      &lt;th&gt;Other regions #2&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;#1&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#2&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#3&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#4&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#5&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#6&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#7&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#8&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#9&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;#10&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;&lt;td&gt;1433/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt;In closing&lt;/h3&gt;

&lt;p&gt;Monitoring at multiple locations enables us to determine if certain changes are occurring only in a particular network. Although we have not published any special alerts as an extra issue or other information this quarter, it is important to pay attention to scanners. We will continue to publish blog articles as the Internet Threat Monitoring Quarterly Report becomes available every quarter. We will also publish an extra issue when we observe any unusual change. Your feedback on this series is much appreciated. Please use the comment form below to let us know which topic you would like us to introduce or discuss further. Thank you for reading.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Keisuke Shikano&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;(Translated by Takumi Nakano)&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>ICS Security Conference 2026</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/04/ics-conference2026.html" />
  <id>tag:movabletype.net,2003:post-3207480</id>
  <published>2026-04-14T06:00:00Z</published>
  <updated>2026-08-07T06:36:01Z</updated>
  <summary>JPCERT/CC held the ICS Security Conference 2026 on February 10, 2026. This conference aims to share the current threat landscape surrounding Industrial Control System (ICS) in Japan and abroad, as well as initiatives undertaken by stakeholders in ICS security. It...</summary>
  <author>
    <name>織戸 由美（Yumi Orito）</name>
      </author>
  <category term="Event" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="ICS-OT" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="ICSSConf" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;JPCERT/CC held the ICS Security Conference 2026 on February 10, 2026. This conference aims to share the current threat landscape surrounding Industrial Control System (ICS) in Japan and abroad, as well as initiatives undertaken by stakeholders in ICS security. It also seeks to help participants strengthen their security measures and establish best practices. Since its launch in 2009, the conference has been held annually, and this year marked the 18th conference.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;This year’s conference was held as an in-person only event, with 137 attendees participating out of 216 registrants. In this article on JPCERT/CC Eyes, we introduce the opening and closing remarks along with six presentations delivered at the conference. Presentation videos, except for the panel session, are available on YouTube, and links are provided in this article.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-AU&quot;&gt;Opening remarks&lt;br&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;em&gt;&lt;strong&gt;Speaker: &lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span lang=&quot;EN-AU&quot;&gt;Katsukuni Hashimoto, Director, Cybersecurity Division, Ministry of Economy, Trade and Industry (METI)&lt;br&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&amp;lt;&lt;a href=&quot;https://www.jpcert.or.jp/present/2026/ICSSConf2026_00_MINISTRY_OF_ECONOMY_TRADE_AND_INDUSTRY.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Slides&lt;/span&gt;&lt;/a&gt;&amp;nbsp;&lt;span lang=&quot;EN-US&quot;&gt;(Japanese)&amp;gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;https://www.youtube.com/watch?v=7-SuRR2fqVo&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;YouTube&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;The conference opened with remarks from Mr. Hashimoto of METI’s Cybersecurity Division, Commerce and Information Policy Bureau.&lt;/p&gt;
&lt;p&gt;Referring to the IPA’s Top 10 Information Security Threats 2026 and related developments, Mr. Hashimoto noted that ransomware remains a major threat and that its impact continues to expand, particularly in the manufacturing sector.&lt;/p&gt;
&lt;p&gt;He also introduced recent policy developments in Japan, including the establishment of the SCS scheme to raise the baseline of security measures across the supply chain; the formulation of OT security guidelines for semiconductor device factories; the launch of JC-STAR (labeling scheme based on Japan Cyber-Security Technical Assessment Requirements) and moves to incorporate it into government procurement requirements; and Japan’s endorsement of international joint guidance on SBOM.&lt;/p&gt;
&lt;p&gt;In closing, he emphasized that, in light of the enactment of legislation to strengthen cyber response capabilities, it is essential to advance the development of an active cyber defense framework through public-private cooperation in order to protect the industrial base and people’s daily lives. He concluded by stressing the importance of steadily advancing effective initiatives across society as a whole.&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;img class=&quot;asset asset-image at-xid-4095543&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_opening-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-AU&quot;&gt;ICS Security Today and Tomorrow - A Review of the Past Year&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;span lang=&quot;EN-US&quot;&gt;Speaker: &lt;/span&gt;&lt;!-- [if !supportLists]--&gt;&lt;!--[endif]--&gt;&lt;/strong&gt;&lt;/em&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;em&gt;&lt;strong&gt;Toshio Miyachi, Expert Adviser, JPCERT/CC&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;lt;&lt;a href=&quot;https://www.jpcert.or.jp/present/2026/ICSSConf2026_01_JPCERTCC.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Slides&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;https://www.youtube.com/watch?v=0lWBEkx8xPY&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;YouTube&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;Mr. Miyachi reviewed the state of ICS security in 2025 and explained major trends and changes over the past year. At the outset, he noted that 2025 marked 15 years since the discovery of Stuxnet and 10 years since the Ukraine power outage incidents. Against this backdrop, he provided a broad overview of how growing geopolitical tensions are increasingly affecting cyber space as integration between ICS and IT continues to deepen.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Looking at incidents over the past year, ransomware remained a persistent threat, with especially serious impacts in manufacturing, including production shutdowns sand shipment delays. Using cases involving a UK automotive manufacturer and major Japanese companies, he highlighted the structural risk whereby compromises in IT environments can ultimately have major consequences for OT and production activities. He also discussed attacks by state-sponsored actors and hacktivists targeting critical infrastructure, as well as incidents involving renewable energy facilities, dams, and hydroelectric power plants, showing that cyber attacks with physical consequences are becoming increasingly realistic.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Regarding vulnerability trends, he pointed to the growing number of ICS-related advisories published by CISA and reports indicating an increase in Internet-exposed ICS/OT devices. He also touched on confusion surrounding the operation of the CVE Program and emerging efforts in Europe to establish a new vulnerability database, noting that global vulnerability information management is entering a period of transition.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He further reviewed developments in regulations and standards, including the EU’s NIS2 Directive, revisions to the IEC 62443 series, and progress related to CIRCIA in the United States. At the same time, he noted that policy developments in various countries and organizational instability affecting CISA in the United States are having an impact on ICS security. He also addressed challenges posed by rapidly advancing technologies such as AI and migration to post-quantum cryptography, underscoring the importance of preparing long-lived ICS environments for these changes.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Overall, while 2025 did not appear to be a year marked by frequent large-scale destructive attacks, he concluded that significant changes are steadily unfolding, suggesting the arrival of a new era: the broader spread of ransomware, the security implications of escalating interstate tensions, the reorganization of standards and institutional frameworks, and the need to respond to emerging technologies.&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;br&gt;&lt;img class=&quot;asset asset-image at-xid-4095544&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_01-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-US&quot;&gt;Learning Incident Response for ICS from the “Preparedness” Factories Have Practiced for Decades&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;em&gt;&lt;strong&gt;Speaker: Shunsuke Kato, Senior Solution Engineer, Claroty Ltd. APJ Sales.&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;lt;&lt;a href=&quot;https://www.jpcert.or.jp/present/2026/ICSSConf2026_02_CLAROTY.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Slides&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;https://www.youtube.com/watch?v=CaFfv8DgbTc&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;YouTube&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;Mr. Kato looked back on recent OT security incidents and explained how the concept of “preparedness,” long cultivated in factories, can be applied to cyber incident response.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He explained that roughly 80% of incidents are IT-originated “indirect OT outages”: even when control itself is not destroyed, operations can still be halted by disruptions to dependent IT systems.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He then explained that concepts long applied in factories at the design, implementation, and operations stages, such as inherently safe design, redundancy, and fail-safe mechanisms, can also function effectively against cyber attacks. He illustrated this point using examples such as the TRITON incident. He further shared concrete examples, including the Fukushima Daiichi nuclear power plant accident and cases from overseas manufacturers, illustrating how businesses were able to continue operations even when digital capabilities were lost by relying on non-digital means such as paper records, human senses, and manual operations.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Using the cases of Colonial Pipeline and Maersk, he showed that business operations can come to a standstill when IT functions such as billing and logistics fail, even if the ICS itself remains intact. This highlights the importance of designing operations with degraded functionality in mind. He also referred to recovery efforts enabled through mutual assistance and public support beyond the boundaries of individual companies, suggesting that collaboration beyond competition becomes critical in times of crisis.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Finally, he presented a framework for restart decisions from three perspectives: MVA (Minimum Viable Architecture), MVP (Minimum Viable Process), and MVC (Minimum Viable Control). He stressed the importance of organizing response options in advance, including analog continuity, backup digital recovery, and external support. He concluded that a deep understanding of OT ultimately strengthens effective incident response capabilities for ICS.&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;br&gt;&lt;img class=&quot;asset asset-image at-xid-4095545&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_02-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-US&quot;&gt;Security Challenges and Defense Methods for Digital Twins in the Automotive Industry&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;em&gt;&lt;strong&gt;Speaker: Chizuru Toyama, Threat Research / Senior Threat Researcher, TXOne Networks Inc.&lt;br&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;lt;&lt;a href=&quot;https://www.jpcert.or.jp/present/2026/ICSSConf2026_03_TXONE_NETWORKS.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Slides&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;https://www.youtube.com/watch?v=pY4ZGAXh9QQ&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;YouTube&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;Ms. Toyama provided a systematic overview of the security challenges associated with the growing use of digital twins in the automotive industry, as well as practical defense methods.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;She began by organizing definitions and standards related to digital twins, confirming that they are a concept for reproducing real-world products, facilities, and processes in virtual space for use in simulation, monitoring, and optimization. Against the backdrop of the automotive industry undergoing what is often described as a once-in-a-century transformation driven by CASE (Connected, Autonomous, Shared, and Electric), she showed that digital twins are playing an increasingly important role as a foundational technology supporting more advanced development, production, and operations.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Specific examples introduced included Toyota’s optimization of factory sensors, Honda’s energy management initiatives in anticipation of V2G/V1G strategies, and Hyundai’s smart factories. These examples illustrated benefits such as improved quality, lower costs, and more flexible production systems. At the same time, she pointed out that bidirectional connections between the physical and virtual worlds expand the attack surface. She outlined possible attack scenarios such as network reconnaissance, data injection, delay attacks, and model tampering, and showed how these could cascade into high-risk outcomes including incorrect control, production&lt;/span&gt;&lt;span style=&quot;font-family: &#39;游明朝&#39;,serif; mso-ascii-font-family: &#39;Segoe UI&#39;; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: &#39;Segoe UI&#39;;&quot;&gt;　&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;shutdowns, and intellectual property theft.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;She also emphasized the importance of role-specific defensive measures and their limitations, the development of incident response playbooks, and security design throughout the entire lifecycle from development to operations. She emphasized that rigorous Secure-by-Design practices, continuous monitoring, and multilayered defense including coordination with the SOC are key to achieving sustainable safety and security in the automotive industry in the era of digital twins.&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;br&gt;&lt;img class=&quot;asset asset-image at-xid-4095547&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_03-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-US&quot;&gt;Promoting Integrated Safety and Security Design for Cyber Attack Response&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;em&gt;&lt;strong&gt;Speaker: Taito Sasaki, Representative Member, Forehacks LLC /Visiting Researcher, Institute for Manufacturing and Innovation DX Laboratory, Nagoya Institute of Technology&lt;br&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;lt;&lt;a href=&quot;https://www.jpcert.or.jp/present/2026/ICSSConf2026_04_FOREHACKS.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Slides&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;https://www.youtube.com/watch?v=DEyxUna4q9c&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;YouTube&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;Mr. Sasaki proposed an approach that integrates safety and security in ICS across the entire lifecycle. This approach responds to increasingly sophisticated cyber attacks and stronger regulatory requirements.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He pointed out that, as the number of vulnerabilities continues to rise and organizations respond to frameworks such as the EU Cyber Resilience Act (CRA), consistent management is required from development through operations and maintenance. Under these conditions, conventional siloed organizational structures and fragmented document management approaches are reaching their limits.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;As a solution, he introduced a framework in which the Data Flow Diagram (DFD) serves as a common structural model, allowing safety requirements, security requirements, and SBOMs to be managed together in a single repository. By converting the DFD into JSON and using &lt;span style=&quot;mso-font-kerning: 0pt;&quot;&gt;node_id and dataflow_id as indexes, design intent, analysis results, test requirements, decision histories, and SBOM information can all be linked together to realize a Single Source of Truth (SSOT). He also introduced a mechanism for ensuring traceability through the use of MANIFEST files to manage the overall state and history of the project.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Using the development of an autonomous wheelchair as a case study, he showed how safety analysis (HARA) and security analysis (TARA) can be conducted on the same model to design countermeasures for sensor failures and spoofing attacks in a consistent manner. He also presented an audit process in which generative AI detects “ghost flows” not present in the original design during implementation and prompts corrective action by evaluating differences from the design JSON. In the operational phase, he emphasized the importance of linking SBOM and CVE information to enable tracing vulnerability impacts by ID and recording the rationale for risk acceptance and response decisions.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Throughout the presentation, he emphasized that ensuring safety and security in future ICS requires organizing system structures around the DFD and incorporating generative AI as an intelligence layer in an integrated design platform. This enables people to make decisions based on clear evidence.&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;br&gt;&lt;img class=&quot;asset asset-image at-xid-4095550&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_04-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-US&quot;&gt;International Trends in Vulnerability Information and CVD-Related Activities Amid Growing Interest Driven by European Regulations and Other Legal Requirements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Speaker: Tomotaka Ito, Global CVD Project Lead, Global Coordination Division, JPCERT/CC&lt;span lang=&quot;EN-US&quot;&gt;&lt;br&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;lt;&lt;a href=&quot;https://www.jpcert.or.jp/present/2026/ICSSConf2026_05_JPCERTCC.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Slides&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;https://www.youtube.com/watch?v=lq4Xdslmkcc&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;YouTube&lt;/a&gt; (Japanese)&amp;gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;Mr. Ito organized international trends, issues, and expected stakeholder responses related to vulnerability handling, an area of growing interest in light of evolving European regulations. The discussion focused on Coordinated Vulnerability Disclosure (CVD), CVE, and SBOM.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He explained that vulnerability information must be properly managed not only in terms of technical accuracy, but also in operational aspects such as &lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&lt;/span&gt;receiving, coordinating, and disclosing vulnerability information. Otherwise, new risks can emerge, including zero-day exploitation and response delays. For this reason, he emphasized the importance of CVD, in which reporters, vendors, users, coordinators, and others work together.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Regarding the CVE Program, he shared recent developments such as the growth in the number of &lt;/span&gt;&lt;span class=&quot;cf01&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 9.0pt; mso-bidi-font-family: Arial;&quot;&gt;CVE Numbering Authorities (&lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;CNA) and Roots and confusion surrounding the &lt;/span&gt;&lt;span class=&quot;cf01&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 9.0pt; mso-bidi-font-family: Arial;&quot;&gt;National Vulnerability Database (&lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;NVD), pointing out the need for data quality, enrichment, and proper handling. He also noted that JPCERT/CC supports organizations in Japan as both a CNA and a Root. On SBOM, he explained that it is a means of improving transparency and serves as a foundation for vulnerability management by identifying components and matching them against CVEs. He also noted that international discussions are underway on issues such as identifier harmonization, coverage, and differences among tools.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He further explained that the EU Cyber Resilience Act (CRA) and the NIS2 Directive require measures such as the establishment of vulnerability disclosure policies, reporting of exploited vulnerabilities within 24 hours, and preparation of SBOMs, suggesting that these requirements could also affect companies outside the EU. In light of these developments, he called on vendors to establish vulnerability handling processes and disclosure policies, improve supply chain visibility, and consider CVE assignment. He also encouraged users to improve asset visibility, make use of SBOMs, and adopt prioritization methods such as SSVC and EPSS. He concluded by stressing the importance of building a balanced ecosystem in which vulnerability information can be shared and used effectively across countries and stakeholder groups.&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;br&gt;&lt;/span&gt;&lt;img class=&quot;asset asset-image at-xid-4095553&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_05-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;Closing remarks&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Speaker: Takayoshi Shiigi, Board Member, JPCERT/CC&lt;br&gt;&lt;br&gt;&lt;/strong&gt;&lt;/em&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;The closing remarks were delivered by Mr. Shiigi, a board member of JPCERT/CC.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He noted that this conference marked the 18th event since the inaugural conference in 2009. He also reported that this year’s conference was held as an in-person event with archived distribution of selected presentations, and that much of the event’s operation was handled by JPCERT/CC.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He also noted that, as the term “cyber security” has become more widely used, its scope has expanded beyond IT and networks to include “the business itself,” including the ICS at the core of business operations.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;He concluded by encouraging practitioners facing challenges in a changing environment to make use of this conference and JPCERT/CC’s activities as a forum for experimentation. He also expressed his gratitude to the speakers and all participants.&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;br&gt;&lt;/span&gt;&lt;img class=&quot;asset asset-image at-xid-4095555&quot; style=&quot;display: block;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/ICSSConf2026_closing-640wri.png&quot; alt=&quot;&quot; width=&quot;640&quot; height=&quot;360&quot;&gt;&lt;/p&gt;
&lt;h3 class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;In Closing&lt;/span&gt;&lt;/h3&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;At this year’s ICS Security Conference, speakers from a variety of sectors, including ICS vendors, visiting researchers at university-affiliated institutes, and user companies, shared their perspectives on the evolving landscape surrounding ICS security. We hope that this conference will serve as a useful reference for all attendees involved in ICS in their future work. We will continue working to improve the conference while sharing information and knowledge that contribute to the advancement of ICS security in Japan.&lt;/span&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Thank you for reading this event report on the ICS Security Conference 2026. &lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&lt;/span&gt;We look forward to seeing you at the next conference.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: right;&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Yumi Orito&lt;br&gt;&lt;/span&gt;&lt;span lang=&quot;EN-AU&quot;&gt;(This article was machine-translated and manually reviewed.)&lt;/span&gt;&lt;/p&gt;
    
  </content>
</entry>
<entry>
  <title>TSUBAME Report Overflow (Jul-Sep 2025)</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/03/tsubame_overflow_2025-07-09.html" />
  <id>tag:movabletype.net,2003:post-3213440</id>
  <published>2026-03-30T05:00:00Z</published>
  <updated>2026-03-30T05:00:13Z</updated>
  <summary>This TSUBAME Report Overflow series discusses monitoring trends observed by overseas TSUBAME sensors, as well as other activities that are not included in the Internet Threat Monitoring Quarterly Reports. This article covers the monitoring results from July to September 2025....</summary>
  <author>
    <name>鹿野 恵祐 (Keisuke Shikano)</name>
    <uri>https://www.jpcert.or.jp/</uri>  </author>
  <category term="Cyber Metrics" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="TSUBAME" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;This TSUBAME Report Overflow series discusses monitoring trends observed by overseas TSUBAME sensors, as well as other activities that are not included in the Internet Threat Monitoring Quarterly Reports. This article covers the monitoring results from July to September 2025.&lt;/p&gt;

&lt;h3&gt;Suspicious packets from domestic NVR products&lt;/h3&gt;

&lt;p&gt;In the main issue of the Internet Threat Monitoring Report, we presented observations of packets originating from TP-Link routers suspected to be infected with malware among nodes with source IP addresses in Japan. However, our honeypots have TSUBAME has also observed packets transmitted from devices manufactured by vendors other than TP-Link.
For some source IP addresses, multiple open ports were confirmed. In such cases, it is assumed that port forwarding is configured on the router deployed at the IP address, enabling multiple devices to provide services behind a single global IP address. While this type of configuration is not uncommon, it is difficult to identify which specific device has been compromised based solely on external observations.
In this article, we introduce a particularly noteworthy case observed among IP addresses where multiple devices are operating in combination. The characteristics observed for each IP address are summarized below:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A login page for an NVR product was accessible&lt;/li&gt;
&lt;li&gt;An administration interface for an enterprise router manufactured by a Japanese company was accessible.&lt;/li&gt;
&lt;li&gt;A login page for an SDN controller was accessible&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;One notable characteristic of this case is that the Web UIs of these devices were listening on the same port numbers, even though they were hosted on different IP addresses. In addition, the administration interface of the domestically manufactured routers contained a character string presumed to be an abbreviation of a prefecture name, suggesting that the systems may be deployed across multiple regions.
Based on these findings, it is possible that a system department or the SI/NIer responsible for deployment provisioned these systems using identical configurations. Given that suspicious packets have been observed, there is a high likelihood that one or more of the devices have been compromised. Although we are currently attempting to contact the users operating these systems, we have not yet been successful.&lt;/p&gt;

&lt;h3&gt;Comparison of the observation trends in Japan and overseas&lt;/h3&gt;

&lt;p&gt;Figure 1 is a monthly comparison of the average number of packets received in Japan and overseas. Overseas sensors received more packets than those in Japan. For domestic sensors, the number of packets peaked in July and then gradually decreased month by month. In contrast, packets from overseas sensors declined once through August, but increased again in September.&lt;/p&gt;

&lt;table style=&quot;border-collapse: collapse; width: 110.24%; height: 36px;&quot; border=&quot;1&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q2blogfig1e.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q2blogfig1e.png&quot; width=&quot;1155&quot; height=&quot;573&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4100610&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 1: Monthly comparison of the average number of packets received in Japan and overseas
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt; Comparison of monitoring trends by sensor &lt;/h3&gt;

&lt;p&gt;Each sensor is assigned a single global IP address. To examine differences in monitoring trends among sensors in Japan, North America, Europe, and other regions, Table 1 summarizes the top 10 destination ports that received packets. Although the rankings vary by sensor, ports such as 22/TCP, 23/TCP, 80/TCP, 443/TCP, and 8080/TCP were observed by almost all sensors. This suggests that scanning activity targeting these protocols is being conducted across a wide range of networks.&lt;/p&gt;

&lt;p style=&quot;text-align: center;&quot;&gt;Table 1: Comparison of top 10 packets by domestic and overseas sensors &lt;/p&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;th&gt;&lt;/th&gt;&lt;th&gt;Japan #1&lt;/th&gt;&lt;th&gt;Japan #2&lt;/th&gt;&lt;th&gt;North America #1&lt;/th&gt;&lt;th&gt;North America #2&lt;/th&gt;&lt;th&gt;Europe #1&lt;/th&gt;&lt;th&gt;Europe #2&lt;/th&gt;&lt;th&gt;Other regions #1&lt;/th&gt;&lt;th&gt;Other regions #2&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#1&lt;/td&gt;&lt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#2&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#3&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#4&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#5&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8888/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#6&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#7&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#8&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#9&lt;/td&gt;&lt;td&gt;34567/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#10&lt;/td&gt;&lt;td&gt;60000/TCP&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;8081/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;&lt;td&gt;2222/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt;In closing&lt;/h3&gt;

&lt;p&gt;Monitoring at multiple locations enables us to determine whether certain changes are occurring only within a specific network. Although we did not publish any special alerts or extra issues this quarter, it remains important to pay close attention to scanning activity. We will continue to publish blog articles as part of the Internet Threat Monitoring Quarterly Report each quarter, and we will also release an extra issue if we observe any unusual changes. We greatly appreciate your feedback on this series. Please use the comment form below to let us know which topics you would like us to introduce or discuss further. Thank you for reading.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Keisuke Shikano&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;(Translated by Takumi Nakano)&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>CSIRTs Around the World – Azerbaijan</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/03/csirts-around-the-world-azerbaijan.html" />
  <id>tag:movabletype.net,2003:post-3206154</id>
  <published>2026-03-25T06:00:00Z</published>
  <updated>2026-03-25T06:00:20Z</updated>
  <summary>Hello, this is Shihono from the Global Coordination Division. In early March, we traveled to Baku, the capital of Azerbaijan, and had the opportunity to visit five organizations, including CSIRTs and facilities involved in cyber security workforce development. In this...</summary>
  <author>
    <name>米澤 詩歩乃（Shihono Yonezawa）</name>
      </author>
  <category term="Other" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;Hello, this is Shihono from the Global Coordination Division. In early March, we traveled to Baku, the capital of Azerbaijan, and had the opportunity to visit five organizations, including CSIRTs and facilities involved in cyber security workforce development. In this article, I would like to introduce an overview of these visits.&lt;/p&gt;

&lt;h3&gt;Azerbaijan, the “Land of Fire,” and Its Capital Baku, the “City of Winds”&lt;/h3&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;
&lt;img class=&quot;asset asset-image at-xid-4094687 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/AZ01-640wri.jpg&quot; alt=&quot;&quot; width=&quot;450&quot; height=&quot;338&quot;&gt;&lt;figcaption&gt;Baku cityscape and the Caspian Sea&lt;/figcaption&gt;
&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;Azerbaijan is located in the Caucasus region, which stretches between the Caspian Sea and the Black Sea. The country possesses abundant natural resources such as natural gas and oil. It is sometimes referred to as the “Land of Fire” due to places like Yanar Dag, a mountain where natural gas continuously burns as it seeps from the ground.&lt;/p&gt;

&lt;p&gt;Its capital, Baku, lies along the Caspian Sea. The city left a strong impression with its coexistence of an old town that preserves the atmosphere of the medieval period and futuristic buildings that reflect its recent economic development. The name “Baku” is said to mean “City of Winds” in Persian, and the strong winds blowing in from the Caspian Sea seemed to embody its name.&lt;/p&gt;

&lt;h3&gt;CSIRTs in Azerbaijan&lt;/h3&gt;

&lt;p&gt;In Azerbaijan, CSIRTs have been established across various sectors, including government, the domestic Internet, and research and education networks, to address cyber security issues in line with their respective roles. Specifically, there are three CSIRTs: CERT.AZ&lt;a href=&quot;#01&quot;&gt;[1]&lt;/a&gt;, CERT.GOV.AZ&lt;a href=&quot;#02&quot;&gt;[2]&lt;/a&gt;, and AzScienceCERT&lt;a href=&quot;#03&quot;&gt;[3]&lt;/a&gt;. These organizations contribute to strengthening national cyber security through activities such as awareness-raising and incident response.&lt;/p&gt;

&lt;p&gt;JPCERT/CC has previously collaborated with CERT.AZ and CERT.GOV.AZ, both members of FIRST, through international conferences and workshops. This visit marked our first engagement with AzScienceCERT. In the following sections, we provide a brief overview of each CSIRT.&lt;/p&gt;

&lt;h4&gt;CERT.AZ&lt;/h4&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;
&lt;img class=&quot;asset asset-image at-xid-4094688 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/AZ02-640wri.jpg&quot; alt=&quot;&quot; width=&quot;450&quot; height=&quot;338&quot;&gt;&lt;figcaption&gt;Group photo with members of CERT.AZ&lt;/figcaption&gt;
&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;CERT.AZ is a CSIRT established in 2012 and is operated by the Electronic Security Service under the Ministry of Digital Development and Transport, which oversees ICT policy, digital government, telecommunications infrastructure, and transport infrastructure.&lt;/p&gt;

&lt;p&gt;Its primary activities include coordinating and collaborating with stakeholders involved in national information infrastructure, as well as providing incident response support for private organizations and general users. It is also engaged in collecting and analyzing threat intelligence and promoting cyber security awareness. In responding to cyber threats, CERT.AZ places strong emphasis on information sharing—not only domestically but also internationally—to address cross-border threats. During our discussions, they expressed their intention to further strengthen information sharing with international partners, including Japan.&lt;/p&gt;

&lt;p&gt;CERT.AZ is also actively involved in awareness-raising initiatives aimed at improving security literacy. In addition to disseminating information through TV commercials and podcasts, they also deliver security alerts via Azerbaijan’s digital ID application platform, “myGov.”&lt;/p&gt;

&lt;p&gt;JPCERT/CC previously held an online workshop with CERT.AZ in August 2025 to exchange information on activities and current situations. Meeting in person this time helped strengthen our relationship and will likely enable smoother coordination in emergency situations. CERT.AZ has also participated in JSAC, a conference hosted by JPCERT/CC, and we have continued to engage with them through various opportunities.&lt;/p&gt;

&lt;h4&gt;CERT.GOV.AZ&lt;/h4&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;
&lt;img class=&quot;asset asset-image at-xid-4094694&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/AZ03-640wri.jpg&quot; alt=&quot;&quot; width=&quot;450&quot; height=&quot;338&quot;&gt;&lt;figcaption&gt;Group photo with members of SCISSS and CERT.GOV.AZ &lt;/figcaption&gt;
&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;CERT.GOV.AZ is a government-focused CSIRT established in 2008 under the State Service for Special Communication and Information Security (SCISSS), one of Azerbaijan’s national security agencies.&lt;/p&gt;

&lt;p&gt;Its primary responsibilities include detecting cyber attacks targeting government networks, implementing preventive measures, monitoring the security of government systems, and providing incident response support. CERT.GOV.AZ operates a Security Operations Center (SOC) on a 24/7 basis and also maintains specialized teams dedicated to digital forensics and malware analysis. In addition, to promote cyber security awareness, the organization runs a dedicated website, focusing on the dissemination of threat intelligence. Through this platform, it publishes threat analysis reports and releases internally developed malware analysis tools.&lt;/p&gt;

&lt;p&gt;When incident investigations reveal cases that may affect entities outside the country, they notify their international counterparts. During our discussions, we confirmed that we will continue to cooperate through information sharing and other collaborative activities.&lt;/p&gt;

&lt;h4&gt;AzScienceCERT&lt;/h4&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;
&lt;img class=&quot;asset asset-image at-xid-4094697&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/AZ04-640wri.jpg&quot; alt=&quot;&quot; width=&quot;450&quot; height=&quot;338&quot;&gt;&lt;figcaption&gt;Group photo with members of the Institute of Information Technology and AzScienceCERT&lt;/figcaption&gt;
&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;AzScienceCERT is a CSIRT operating under the Institute of Information Technology of the Azerbaijan National Academy of Sciences (ANAS). It was established in 2011 and provides services to universities, research institutions, and educational organizations that utilize AzScienceNet, the national research and education network. Its activities include information security risk management and incident response support.&lt;/p&gt;

&lt;p&gt;The Institute of Information Technology houses various facilities, including a data center for AzScienceNet, research centers focused on information technology and cyber security, and an operations center responsible for network management and monitoring. As a research institution, it conducts studies and conferences on scientific and practical topics such as software engineering and digital forensics. During our visit, they expressed an interest in promoting international collaboration in these areas.&lt;/p&gt;

&lt;h3&gt;Organizations Supporting Human Resource Development and Capacity Building&lt;/h3&gt;

&lt;p&gt;In Azerbaijan, efforts to develop cyber security talent and enhance the capabilities of private-sector organizations are actively carried out alongside CSIRT activities. During this visit, we also had the opportunity to visit the following two organizations.&lt;/p&gt;

&lt;h4&gt;Azerbaijan Cybersecurity Center&lt;/h4&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;
&lt;img class=&quot;asset asset-image at-xid-4094700&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/AZ05-640wri.jpg&quot; alt=&quot;&quot; width=&quot;450&quot; height=&quot;338&quot;&gt;&lt;figcaption&gt;Facility tour&lt;/figcaption&gt;
&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;The Azerbaijan Cybersecurity Center &lt;a href=&quot;#04&quot;&gt;[4]&lt;/a&gt; is a national-level education and training hub established to develop cyber security talent within the country. It was founded in 2023 through the initiative of the Ministry of Digital Development and Transport and the Innovation and Digital Development Agency. The Technion – Israel Institute of Technology serves as an international education partner, supporting the center through curriculum development and the dispatch of instructors.&lt;/p&gt;

&lt;p&gt;One of the key features of the center’s training programs is their strong focus on practical skills, in contrast to traditional academic education at universities. Participants undergo intensive training over extended periods of six months to one year, including hands-on exercises based on realistic cyber attack and defense scenarios.&lt;/p&gt;

&lt;p&gt;Admission to the program is competitive and requires passing a selection process. Applicants must be at least 17 years old (with no upper age limit), and are expected to have advanced English proficiency and basic IT skills. The program receives around 2,000 applications for approximately 60 available positions, making it highly competitive. For students enrolled in partner universities, participation in the program can also count toward graduation credits, which adds to its appeal.&lt;/p&gt;

&lt;p&gt;To date, 480 participants have completed the program, and 86% of them have gone on to work in the cyber security field. The center also offers various career support opportunities, such as internships with companies and networking events with alumni, which contribute to this high employment rate. During our visit, we were given a tour of the facility and had the opportunity to interact with highly motivated trainees.&lt;/p&gt;

&lt;p&gt;In addition to these human resource development initiatives, Azerbaijan is also promoting activities that support the growth of the cyber security sector through the formation of networks among private companies and experts.&lt;/p&gt;

&lt;h4&gt;Association of Cybersecurity Organizations of Azerbaijan (AKTA)&lt;/h4&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;
&lt;img class=&quot;asset asset-image at-xid-4094702&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/AZ06-640wri.jpg&quot; alt=&quot;&quot; width=&quot;450&quot; height=&quot;338&quot;&gt;&lt;figcaption&gt;Meeting with AKTA members&lt;/figcaption&gt;
&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;The Association of Cybersecurity Organizations of Azerbaijan (AKTA)&lt;a href=&quot;#05&quot;&gt;[5]&lt;/a&gt; is a non-profit organization established in 2022 that brings together cyber security-related companies, organizations, and experts across the country. It serves as a platform to connect stakeholders in the cyber security field and works to strengthen Azerbaijan’s cyber security ecosystem. Its activities include enhancing the overall security environment, promoting education, training, and awareness, fostering public–private collaboration, and facilitating information sharing and joint initiatives.&lt;/p&gt;

&lt;p&gt;Currently, around 60 member organizations participate in AKTA, including cyber security firms, IT companies, telecommunications operators, and educational institutions. One of the challenges highlighted during our discussions was that while security measures in critical infrastructure sectors have progressed, small and medium-sized enterprises (SMEs) still lag behind in implementing adequate protections. In addressing such challenges, organizations like AKTA play an important role.&lt;/p&gt;

&lt;p&gt;AKTA is also actively engaged in building international networks through exchanges with companies and experts in countries such as Türkiye, Kazakhstan, and Uzbekistan, particularly in the areas of education and industry. The association organizes an international event called the “National Cybersecurity Forum”, where topics such as critical infrastructure protection, international cooperation, capacity building, and cyber diplomacy are discussed. They also expressed interest in having speakers from Japan participate in the future.&lt;/p&gt;

&lt;h3&gt;Conclusion&lt;/h3&gt;

&lt;p&gt;In Azerbaijan, efforts to strengthen cyber security at the national level are progressing alongside ongoing digital transformation. In 2023, the country formulated the “Information Security and Cybersecurity Strategy (2023–2027),” which identifies key priority areas such as the protection of critical information infrastructure, enhancement of cyber threat response capabilities, human resource development, and the promotion of international cooperation. Through this visit, we observed that government agencies, private-sector organizations, and research institutions are each fulfilling their respective roles while working collaboratively to improve the country’s overall cyber security capabilities. &lt;/p&gt;

&lt;p&gt;We were also impressed by the strong sense of motivation among the professionals we met, who are actively working to advance cyber security initiatives and international collaboration. This positive energy resonated with the dynamic atmosphere of Baku, a city that continues to grow and evolve, and was truly inspiring for us as well. Moving forward, we hope to further strengthen cooperation with CSIRTs around the world through continued exchanges, expanding information sharing and collaboration to address cross-border incidents and emerging threats.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Shihono Yonezawa &lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;(This document was machine-translated and manually reviewed.)&lt;/p&gt;

&lt;h2&gt;References&lt;/h2&gt;

&lt;p&gt;&lt;a name=&quot;01&quot;&gt;[1]&lt;/a&gt; CERT.AZ&lt;br&gt; 
&lt;a href=&quot;https://cert.az/&quot;&gt;https://cert.az/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;02&quot;&gt;[2]&lt;/a&gt; CERT.GOV.AZ&lt;br&gt; 
&lt;a href=&quot;https://cert.gov.az/&quot;&gt;https://cert.gov.az/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;03&quot;&gt;[3]&lt;/a&gt; AzScienceCERT&lt;br&gt; 
&lt;a href=&quot;https://azsciencenet.az/az/service/3&quot;&gt;https://azsciencenet.az/az/service/3&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;04&quot;&gt;[4]&lt;/a&gt; Azerbaijan Cybersecurity Center&lt;br&gt; 
&lt;a href=&quot;https://www.akm.az/&quot;&gt;https://www.akm.az/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;05&quot;&gt;[5]&lt;/a&gt; Association of Cybersecurity Organization of Azerbaijan&lt;br&gt; 
&lt;a href=&quot;https://akta.az/en&quot;&gt;https://akta.az/en&lt;/a&gt;&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>Study of Binaries Created with Rust through Reverse Engineering</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/03/rust_research_en.html" />
  <id>tag:movabletype.net,2003:post-3197115</id>
  <published>2026-03-12T05:00:00Z</published>
  <updated>2026-04-01T05:24:47Z</updated>
  <summary>Rust has been gaining attention in recent years as a language expected to replace C and C++, due to its memory safety and high performance. While Rust continues to be adopted as a programming language, malware developed using Rust (hereinafter...</summary>
  <author>
    <name>JPCERT/CC</name>
      </author>
  <category term="Other" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;Rust has been gaining attention in recent years as a language expected to replace C and C++, due to its memory safety and high performance. While Rust continues to be adopted as a programming language, malware developed using Rust (hereinafter referred to as &quot;Rust malware&quot;), such as Rust variants of SysJoker and the BlackCat ransomware, has also been increasing in recent years. However, knowledge of reverse engineering techniques for Rust malware is still insufficient compared to classical reverse engineering techniques for C/C++ malware. For this reason, JPCERT/CC has published the &quot;Study of Binaries Created with Rust through Reverse Engineering&quot;, which summarizes the results of verifications conducted on the reverse engineering of binaries created with Rust (hereinafter referred to as &quot;Rust binaries&quot;).&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://github.com/JPCERTCC/rust-binary-analysis-research-en&quot;&gt;Study of Binaries Created with Rust through Reverse Engineering&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This article provides an overview of the report.&lt;/p&gt;

&lt;h3&gt;Contents of the Report&lt;/h3&gt;

&lt;p&gt;This report summarizes the results of studies and verifications conducted by selecting study items related to reverse engineering of Rust binaries. For detailed study items, please refer to Appendix A. The versions of the tools used in this study are listed below. In addition, the binaries were compiled using a Windows MSVC environment during the study and verification.&lt;/p&gt;

&lt;pre style=&quot;background:#25292f;color: #fff;&quot;&gt;
  &lt;code&gt;
    cargo: 1.82.0
    rustc: 1.82.0
    IDA Pro v8.3.230608
  &lt;/code&gt;
&lt;/pre&gt;

&lt;h3&gt;Usage Scenarios&lt;/h3&gt;

&lt;p&gt;Since each study item in this report is independent, readers can refer only to items of interest rather than reading the entire report from start to finish. Some study items include sample programs. Therefore, it is recommended to first review the items of interest, then compile the sample programs and examine the Rust binaries alongside the report.&lt;/p&gt;

&lt;h3&gt;Conclusion&lt;/h3&gt;

&lt;p&gt;Rust is a language that is rapidly gaining adoption, and since it is considered relatively difficult to reverse engineer, its abuse by attackers is expected to increase. We hope that this report will be of some help in the reverse engineering of Rust malware. If you find any issues or have comments regarding the content, we welcome your feedback.&lt;/p&gt;

&lt;p style=&quot;text-align: right;&quot;&gt;Tomoya Kamei&lt;br/&gt;(This document was machine-translated and manually reviewed.)&lt;/p&gt;

&lt;h3&gt;Appendix A: Study Items&lt;/h3&gt;

&lt;table border=&quot;1&quot;&gt;
&lt;caption&gt;&lt;b&gt;Table 1: Study Items&lt;/b&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;No.&lt;/th&gt;
&lt;th&gt;Title&lt;/th&gt;
&lt;th&gt;Overview&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Differences between binaries, associated with setting modifications of Profiles in Cargo&lt;/td&gt;
&lt;td&gt;Study on what extent approaches that use cargo to reduce binary sizes can reduce the sizes and what information is left unremoved. The approaches should be those available from disclosed information.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Reducing binary sizes&lt;/td&gt;
&lt;td&gt;Study on to what extent approaches that use rustc to reduce binary sizes can reduce the sizes and what information is left unremoved. The approaches should be those available from disclosed information.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;Identifying Rust binaries&lt;/td&gt;
&lt;td&gt;Study on approaches that determine whether a binary is a Rust binary&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;Exception Directory&lt;/td&gt;
&lt;td&gt;Study on information available from an Exception Directory structure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;TLS Directory&lt;/td&gt;
&lt;td&gt;Study on information available from a TLS Directory structure and contents of a TLS Callback&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;Identifying the main function and initialization&lt;/td&gt;
&lt;td&gt;Approaches for identifying user-defined main functions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;Strings&lt;/td&gt;
&lt;td&gt;Approaches for handling strings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;Mangling function names&lt;/td&gt;
&lt;td&gt;Structure of mangled function names and how to demangle mangled function names&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;Closure&lt;/td&gt;
&lt;td&gt;Behavior of closures and memory layouts to be used&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Enum types&lt;/td&gt;
&lt;td&gt;Study on how behavior of enum types in Rust is implemented in assembly code&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;td&gt;Match statement&lt;/td&gt;
&lt;td&gt;Study on how behavior of match statements in Rust is implemented in assembly code&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;td&gt;Panic statement&lt;/td&gt;
&lt;td&gt;Differences in assembly code between behavior on a panic &quot;unwind&quot; and &quot;abort&quot;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;Iterator&lt;/td&gt;
&lt;td&gt;Study on how code using iterators or the &quot;next&quot; function is implemented in assembly code&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;Trait&lt;/td&gt;
&lt;td&gt;Differences between calls to a function using traits and to a common function&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;Identify typical traits&lt;/td&gt;
&lt;td&gt;Approaches for identifying traits the #[derive] attribute uses, in assembly code&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;td&gt;Dynamic dispatch reference&lt;/td&gt;
&lt;td&gt;Characteristics of assembly code and differences between calls using dynamic and static dispatches&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;17&lt;/td&gt;
&lt;td&gt;Collection&lt;/td&gt;
&lt;td&gt;Memory layout to be used&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;Identifying functions generated from the same generics&lt;/td&gt;
&lt;td&gt;Study on approaches for identifying a function generating another function&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;Smart pointer&lt;/td&gt;
&lt;td&gt;Characteristics and memory layouts of smart pointers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;td&gt;Inline assembly&lt;/td&gt;
&lt;td&gt;Characteristic code patterns&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;21&lt;/td&gt;
&lt;td&gt;Link attribute&lt;/td&gt;
&lt;td&gt;Differences in how to link libraries&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;Repr attribute&lt;/td&gt;
&lt;td&gt;Study on how memory layouts change according to specifiable options&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;td&gt;How to identify code in standard and third-party libraries&lt;/td&gt;
&lt;td&gt;Approaches for identifying statically linked standard and third-party library functions&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

    

  </content>
</entry>
<entry>
  <title>JSAC2026 -Workshop/Lightning Talk Session/Panel Discussion-</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/03/jsac2026-ws-lt-pd.html" />
  <id>tag:movabletype.net,2003:post-3188979</id>
  <published>2026-03-06T02:00:00Z</published>
  <updated>2026-03-06T02:00:14Z</updated>
  <summary>In this article, we continue our overvie...</summary>
  <author>
    <name>矢野 雄紀(Yuki Yano)</name>
      </author>
  <category term="Event" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="Tags" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="JSAC" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;In this article, we continue our overview of the sessions at JSAC2026.
We focus on the Workshop sessions, Lightning Talk sessions, and the Panel Discussion in this report.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Workshop 1］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Leveraging EML Analyzer to Triage Malicious Email Messages During Incident Response&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: Manabu Niseki; Michał Praszmo, CERT Polska&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_workshop1_en.pdf&quot;&gt;Slides (English)&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;Manabu Niseki and Michał Praszmo focused on the analysis and triage of malicious emails, first reviewing email architecture and attack techniques, and then introducing practical analytical methods using real email samples.  &lt;/p&gt;

&lt;p&gt;In the first half, they outlined fundamental email specifications such as the Internet Message Format and MIME, and explained how emails are delivered across systems and how to interpret the “Received” headers. They also covered authentication technologies including SPF, DKIM, and DMARC, clarifying their respective roles, limitations, and what analysts should verify within actual email headers.  &lt;/p&gt;

&lt;p&gt;In the second half, they conducted hands-on analysis using EML Analyzer, an open-source tool that parses EML and MSG files and visualizes structured data such as headers, message bodies, attachments, and URLs. &lt;br /&gt;
Participants used EML Analyzer to perform CTF-style exercises, submitting analysis results based on tasks such as: &lt;br /&gt;
　- Identifying the Message-ID &lt;br /&gt;
　- Determining the subject of the original message referenced in an NDR (Non-Delivery Report) &lt;br /&gt;
　- Calculating the SHA256 hash of a PDF attachment disguised as a quotation request &lt;br /&gt;
　- Identifying the source host IP that relayed the email to a Microsoft Outlook environment &lt;br /&gt;
　- Identifying the FQDN of the host that executed a ClamAV malware scan &lt;br /&gt;
　- Extracting the Envelope FROM (Return-Path) from debug headers &lt;br /&gt;
　- Identifying the sender’s client IP address from X-Headers &lt;br /&gt;
　- Identifying the attacker-controlled C2 server used in a Roundcube XSS attack &lt;br /&gt;
　- Determining the original sender’s full email address based on traces of conversation hijacking &lt;br /&gt;
　- Analyzing modifications that caused DKIM verification failure and identifying the original body hash &lt;br /&gt;
　- Identifying the mechanism by which the received email passed SPF validation &lt;br /&gt;
　- Determining the abuse report destination when an @gmail.com email fails DMARC validation  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/01_JSAC2026_Day1_WS1-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065718&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Workshop 2］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Advanced Malware Reverse Engineering: Dealing with Anti-Analysis Techniques from Scratch&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: Mark Lim, Palo Alto Networks, Inc.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_workshop2_en.pdf&quot;&gt;Slides (English)&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;Mark Lim guided participants through a hands-on reverse engineering workshop focused on bypassing anti-analysis techniques observed in real-world malware.  &lt;/p&gt;

&lt;p&gt;The workshop analyzed two malware families: &lt;br /&gt;
　- Guloader: a multi-stage dropper &lt;br /&gt;
　- Gremlin: an infostealer  &lt;/p&gt;

&lt;p&gt;Participants analyzed a multi-stage attack scenario in which Guloader acts as the initial access vector and ultimately deploys and executes Gremlin, conducting their analysis with the full attack chain in mind.  &lt;/p&gt;

&lt;p&gt;The session progressed step by step, beginning with analysis of VBS files and PowerShell scripts, moving to shellcode analysis, and ultimately addressing control flow obfuscation implemented through Vectored Exception Handlers (VEH). After each hands-on phase, Mark provided detailed explanations of the underlying mechanisms and analytical techniques, reinforcing both conceptual understanding and practical skills.  &lt;/p&gt;

&lt;p&gt;He also detailed the tools and scripts used throughout the analysis, allowing participants to systematically learn practical reverse engineering techniques.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/02_JSAC2026_Day1_WS2-640wri.jpg&quot; width=&quot;640&quot; height=&quot;361&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065720&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Workshop 3］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Re:birth the fidb: Reverse Engineering the .NET AOT Malware&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: Akihiro Yoshitake; Akihiro Kida; Akihiro Jin, NF Laboratories Co., Ltd.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_workshop3_jp.pdf&quot;&gt;Slides (Japanese)&lt;/a&gt;  &lt;/p&gt;

&lt;p&gt;This workshop was designed to enable beginners to systematically and practically learn analysis techniques for malware compiled with .NET Native AOT (Ahead-of-Time), which has recently begun to be observed in the wild.  &lt;/p&gt;

&lt;p&gt;Traditional .NET malware typically retains IL code and extensive metadata, making analysis with decompiles such as dnSpy relatively straightforward. In contrast, binaries compiled with Native AOT do not contain IL code and significantly reduce metadata, rendering conventional .NET malware analysis approaches insufficient. The workshop addressed practical strategies for overcoming these Native AOT-specific challenges.  &lt;/p&gt;

&lt;p&gt;In the first half, the speakers compared conventional .NET binaries (including IL) with Native AOT-compiled binaries, explaining their internal structures and characteristics. They demonstrated how Native AOT binaries can resemble C++ native binaries and how static linking of standard libraries greatly increases the volume of code subject to analysis.  &lt;/p&gt;

&lt;p&gt;They then introduced signature-based triage techniques to address this complexity. Through hands-on exercises using Ghidra and IDA Pro, participants learned how to identify functions derived from standard libraries and narrow down relevant code for analysis. By leveraging Ghidra’s Function ID and IDA Pro’s FLIRT signatures, participants confirmed substantial improvements in code readability.  &lt;/p&gt;

&lt;p&gt;In the latter half, they examined the Dehydrate / Rehydrate mechanisms used during Native AOT compilation and demonstrated techniques to restore string literals and object metadata that are often lost in static analysis. Using a Ghidra plugin, participants performed hands-on exercises to statically reconstruct compressed metadata and Frozen Objects without dynamic analysis, significantly improving code readability.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/03_JSAC2026_Day2_WS3-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065721&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Lightning Talk Sessions 1］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;HoldingHandsRAT Attacks Against Japanese Companies&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;講演者：Speaker: Toshiki Takeuchi, NEC&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_LT_1_toshiki_takeuchi_en.pdf&quot;&gt;Slides (English)&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;Toshiki Takeuchi analyzed HoldingHandsRAT attacks targeting Japanese companies, drawing on observed phishing emails and malware behavior.  &lt;/p&gt;

&lt;p&gt;HoldingHandsRAT has previously been used in campaigns targeting Taiwan, Japan, and Malaysia. He presented a case observed in May 2025, in which Japanese-language phishing emails targeted Japanese organizations. Based on PDB paths and runtime behavior identified during analysis, he demonstrated similarities with publicly available HoldingHands source code.  &lt;/p&gt;

&lt;p&gt;In one example, attackers disguised the phishing email as a business notification titled “Notice of Salary System Revision” and attached a ZIP archive. The archive contained a password-protected executable file along with a text file listing the password. Protecting the executable with a password likely aimed to evade detection by security products.  &lt;/p&gt;

&lt;p&gt;He further noted that some malware samples used in the campaign carried digital signatures suspected to have been stolen from legitimate companies. Additionally, multiple domains with similar naming patterns were registered around the same period, many resolving to IP addresses within Japan.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/04_JSAC2026_Day2_LT01-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065723&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Lightning Talk Sessions 2］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Dangerous Co-Tenants in Hosting Services&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;講演者：Speaker: Takayuki Tomatsuri, NTT Security Japan Co., Ltd.; Ryosuke Togashi, NTT DOCOMO BUSINESS, Inc.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_LT_2_takayuki_tomatsuri-ryosuke_togashi_jp.pdf&quot;&gt;Slides (Japanese)&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;Takayuki Tomatsuri and Ryosuke Togashi examined security risks arising from shared email infrastructures in rental servers and hosting services, illustrating their points with concrete examples.  &lt;/p&gt;

&lt;p&gt;Although rental servers offer ease of use, they frequently involve shared IP addresses and mail-sending infrastructure among multiple tenants. They highlighted how such shared environments do not always align well with sender authentication technologies such as SPF and DMARC. In particular, because SPF relies on source IP addresses, it may fail to distinguish spoofed emails sent by other tenants within the same IP range.  &lt;/p&gt;

&lt;p&gt;They also explained that when service providers and customers share the same mail infrastructure, attackers may be able to send emails impersonating the provider. Since the provider’s SPF record authorizes certain IP addresses, malicious tenants may effectively leverage those same IP addresses. In such environments, even properly configured SPF and DMARC settings may not fully prevent spoofing.  &lt;/p&gt;

&lt;p&gt;As one method to assess this risk, they introduced an approach that compares SPF records of providers and tenants. While external parties cannot easily determine the internal configuration of rental services, correlating publicly available DNS SPF records can help infer whether tenant-usable IP addresses are included in the provider’s SPF record, thereby indicating potential spoofing risk.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/05_JSAC2026_Day2_LT2-640wri.jpg&quot; width=&quot;640&quot; height=&quot;302&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065724&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Lightning Talk Sessions 3］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Efficient Phishing Site Hunting with TOAMI, IKESU, and CHOKA: Browser Extension Integration for Streamlined Operations&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: Yuichi Tsuboi, NTT DOCOMO BUSINESS, Inc.&lt;/h5&gt;

&lt;p&gt;&lt;br&gt;
Yuichi Tsuboi introduced the browser extension TOAMI and its companion tools IKESU and CHOKA, which were developed to support analysts engaged in phishing site investigations.  &lt;/p&gt;

&lt;p&gt;TOAMI assists analysts investigating suspicious URLs and outputs phishing detection results as structured logs.  &lt;/p&gt;

&lt;p&gt;IKESU visualizes logs generated by TOAMI through a GUI, enabling listing, searching, and sorting. Designed around the concept of managing logs as “fish in a holding tank,” the tool operates entirely within the browser.  &lt;/p&gt;

&lt;p&gt;CHOKA builds on detection results selected in IKESU and supports the creation and submission of abuse reports.  &lt;/p&gt;

&lt;p&gt;These tools address the substantial burden associated with manually conducting in-depth phishing site investigations. Because such investigations require significant resources and advanced expertise, operational efficiency and standardization are critical. By integrating TOAMI, IKESU, and CHOKA, Yuichi presented a vision of streamlining the workflow from detection and analysis to takedown, thereby accelerating phishing site mitigation.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/06_JSAC2026_Day2_LT03-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065725&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Lightning Talk Sessions 4］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Deceiving Developers: Abusing Legitimate GitHub Repositories to Deliver Malware&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: Theo Webb, GMO Cybersecurity by Ierae, Inc.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_LT_4_theo_webb_en.pdf&quot;&gt;Slides (English)&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;Theo Webb analyzed a campaign in which attackers abused legitimate GitHub repositories to distribute malware targeting developers, explaining the techniques, background, and impact.  &lt;/p&gt;

&lt;p&gt;The attack combined malvertising with GitHub’s repository structure. Attackers forked a legitimate repository and created a commit that modified the download links in the README. This commit could be displayed under a URL that appeared to belong to the official repository, allowing victims to view it in a format nearly identical to the legitimate page.  &lt;/p&gt;

&lt;p&gt;The attackers promoted a link to the malicious commit through advertisements using keywords such as “GitHub Desktop.” Victims who clicked the advertisement were taken to the modified README page and downloaded the installer from the altered link. On Windows systems, this resulted in the execution of malware including HijackLoader, while on macOS systems, it led to infection with AMOS Stealer.  &lt;/p&gt;

&lt;p&gt;Theo highlighted structural factors enabling the attack. GitHub allows fork-derived commits to appear under URLs resembling those of official repositories, and in some cases, commits remain accessible even after forks or accounts are deleted, complicating tracking and complete removal. He also demonstrated how anchor links within README files can bypass certain warning mechanisms on GitHub.  &lt;/p&gt;

&lt;p&gt;He concluded by emphasizing defensive measures, including verifying the default branch of official repositories and downloading installers from the Releases page or the vendor’s official website rather than directly from README links.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/07_JSAC2026_Day2_LT04-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065726&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Lightning Talk Sessions 5］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Unmasking Houken: Advanced TTPs and Detection&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: Ruth Ng, PricewaterhouseCoopers Hong Kong&lt;/h5&gt;

&lt;p&gt;&lt;br&gt;
Ruth Ng examined the division of labor in modern state-sponsored cyber attacks, focusing particularly on the role of Initial Access Brokers. 
As the presentation included a substantial amount of TLP:RED information, further details cannot be shared publicly.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/08_JSAC2026_Day2_LT05-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065727&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Lightning Talk Sessions 6］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Monitoring Domestic Mobile Line Contracts Used by Overseas Investment Scams and Similar Fraud Schemes&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: yumano&lt;/h5&gt;

&lt;p&gt;&lt;br&gt;
yumano presented research evaluating the effectiveness of SMS-based identity verification by analyzing mobile phone numbers abused in overseas investment scams and similar fraud schemes.  &lt;/p&gt;

&lt;p&gt;He described efforts to collect mobile numbers actually used in romance scams and to investigate their contract status and duration.  &lt;/p&gt;

&lt;p&gt;By analyzing contract status over approximately ten months before and after the fraudulent activities, he reported a pattern in which lines were contracted shortly before the scam operations and terminated soon after their completion.  &lt;/p&gt;

&lt;p&gt;These findings suggest that attackers may acquire large numbers of mobile phone numbers for authentication purposes within short periods. As a result, it was pointed out that SMS-based identity verification alone may not provide sufficient protection against fraud.  &lt;/p&gt;

&lt;p&gt;He also emphasized the importance of verifying contract status prior to account registration and rapidly sharing information about mobile numbers used in fraud cases to prevent further damage.  &lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;［Panel Discussion］&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;&lt;strong&gt;Security Incidents of 2025 Highlighted by the JSAC2026 Review Board&lt;/strong&gt;&lt;/h3&gt;

&lt;h5&gt;Speaker: CFP Review Board&lt;/h5&gt;

&lt;p&gt;&lt;strong&gt;(Rintaro Koike, NTT Security Japan Co., Ltd.; Minoru Kobayashi, Internet Initiative Japan Inc.; Shota Nakajima, Cyber Defense Institute, Inc.; Yu Nakatsuru, Fujitsu Limited; Yusuke Niwa, ITOCHU Corporation; Hiroaki Hara, Palo Alto Networks, Inc.; Steve Su, Google LLC; Shusei Tomonaga, JPCERT/CC)&lt;/strong&gt;    &lt;/p&gt;

&lt;p&gt;The CFP Review Board members reflected on major security incidents of 2025 and discussed the cases that drew their particular attention. &lt;br /&gt;
Although the discussion featured lively exchanges among the board members, many details fall under TLP:RED and therefore cannot be shared publicly.  &lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/10_JSAC2026_Day2_panel2-640wri.jpg&quot; width=&quot;640&quot; height=&quot;361&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4065728&quot; style=&quot;display: block;&quot;/&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;h3&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;At JSAC2026, selected sessions were recognized for their outstanding contributions. &lt;br /&gt;
The Excellent Presentation Award (formerly the Best Speaker Award) was determined based on participant survey results, recognizing the session that received the highest “Excellent” (very satisfied) rating. &lt;br /&gt;
The Special Recognition Award was decided through deliberation by the CFP Review Board. &lt;br /&gt;
The presentations that received the Excellent Presentation Award and Special Recognition Award are as follows: &lt;br /&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&amp;lt;&lt;strong&gt;Excellent Presentation Award&lt;/strong&gt;&gt; &lt;br /&gt;
Title: Re:birth the fidb: Reverse Engineering the .NET AOT Malware &lt;br /&gt;
Speaker: Akihiro Yoshitake; Akihiro Kida; Akihiro Jin, NF Laboratories Co., Ltd. &lt;br /&gt;
&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/thumbnail/award-c73ebb2f-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4071686&quot; style=&quot;display: block;&quot;/&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&amp;lt;&lt;strong&gt;Special Recognition Award&lt;/strong&gt;&gt; &lt;br /&gt;
Title: Unmasking the CoGUI Phishing Kit, the Major Chinese Phishing-as-a-Service Targeting Japan &lt;br /&gt;
Speaker: TeamDonut Shadow Liu, Lime Chen, Albert Song &lt;br /&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Finally, we would like to take this opportunity to express our sincere appreciation to everyone who participated in JSAC2026 and to all readers of this report.&lt;/p&gt;

&lt;p style=&quot;text-align: right;&quot;&gt;Yuki Yano &lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p style=&quot;text-align: right;&quot;&gt;(This article was machine-translated and manually reviewed.)&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>JSAC2026 -Day 2-</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/02/jsac2026day2.html" />
  <id>tag:movabletype.net,2003:post-3189137</id>
  <published>2026-02-27T02:00:00Z</published>
  <updated>2026-02-27T02:06:29Z</updated>
  <summary>Continuing from the previous report, thi...</summary>
  <author>
    <name>佐々木 奈々恵（Nanae Sasaki）</name>
      </author>
  <category term="Event" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="JSAC" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;Continuing from the &lt;a href=&quot;https://blogs.jpcert.or.jp/en/2026/02/jsac2026day1.html&quot;&gt;previous report&lt;/a&gt;, this second installment introduces the presentations delivered during the Day 2 Main Track.&lt;/p&gt;

&lt;h3&gt;Following the Trace: Reconstructing Attacks from Ext4 and XFS Journals&lt;/h3&gt;

&lt;h5&gt;Speaker: Minoru Kobayashi, Internet Initiative Japan Inc.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_1_minoru_kobayashi_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Minoru Kobayashi presented an approach for inferring file operations and reconstructing them as a timeline based on the journal structures and analysis methods of the ext4 and XFS file systems. Through a demonstration of the journal analysis tool “FJTA (Forensic Journal Timeline Analyzer),” developed for this purpose, the presentation highlighted the effectiveness of journal analysis in complementing conventional timeline analysis, even in situations where timestamps cannot be considered reliable.&lt;/p&gt;

&lt;p&gt;At the outset, the limitations of traditional timeline analysis in digital forensics were discussed. Specifically, MACB timestamps represent only a snapshot at the time of disk acquisition and, by design, cannot reflect multiple historical operations or manipulations such as timestomping. As a new approach to address this challenge, the motivation for focusing on the journal mechanisms of ext4 and XFS, which are widely used in Linux environments, was explained.&lt;/p&gt;

&lt;p&gt;The presentation then provided an overview of the structures and analysis methods of ext4 and XFS journals, demonstrating how metadata modification records stored on a per-transaction basis can be used to infer operations such as file creation and deletion, and to reconstruct them chronologically. Although the specifications of these file systems are publicly available, no open-source tools currently exist that can practically analyze both file systems and visualize the results in timeline form. It was also noted as a challenge that existing tools such as The Sleuth Kit only provide data enumeration.&lt;/p&gt;

&lt;p&gt;Through a demonstration of FJTA, it was shown that file activities can be detected from journal data, enabling the visualization of attack traces that would not be visible through conventional timeline analysis. The presentation also addressed practical application examples in real attack scenarios, as well as the limitations of anti-forensic techniques.&lt;/p&gt;

&lt;p&gt;In conclusion, it was emphasized that file system journals constitute highly reliable forensic artifacts that are difficult to tamper with. For incident response, it was recommended that journal data should be collected as a priority after acquiring a memory image. The speaker emphasized the importance of prioritizing journal acquisition over block device analysis and standard file collection.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_1.jpg&quot; alt=&quot;JSAC2026_Day2_1.JPG&quot; /&gt;&lt;/p&gt;

&lt;h3&gt;Unmasking the CoGUI Phishing Kit, the Major Chinese Phishing-as-a-Service Targeting Japan&lt;/h3&gt;

&lt;h5&gt;Speaker: TeamDonut Shadow Liu, Lime Chen, Albert Song&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_2_%20shadow_liu-lime_chen-albert_song_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Shadow Liu, Lime Chen, and Albert Song presented an analysis of the phishing campaign “CoGUI,” which targets numerous Japanese brands in the financial, transportation, and government service sectors, as well as of the China-based Phishing-as-a-Service (PhaaS) platform “FishingMaster (垂钓大师)” behind its operations.&lt;/p&gt;

&lt;p&gt;The session began with an overview of the current state of large-scale phishing attacks targeting Japan and demonstrated that CoGUI is operated through FishingMaster. Because the platform has promoted and distributed its services through closed channels, its operations had long remained largely unknown. By comparing its evolution from the first-generation platform to its successor systems, and through web scanner data analysis, monitoring of underground communities, and technical investigation, the speakers systematically uncovered the infrastructure configuration and operational ecosystem supporting CoGUI.&lt;/p&gt;

&lt;p&gt;It was further explained that, following media coverage in 2025, the operators temporarily suspended their activities but later resumed operations under rebranded names such as NX and FA. In doing so, they enhanced operational security by further concealing infrastructure, encrypting communications, and strengthening detection evasion capabilities.&lt;/p&gt;

&lt;p&gt;The presentation also shared findings related to attribution and behavioral patterns observed in underground markets, examining the group’s business model and risk management strategies.&lt;/p&gt;

&lt;p&gt;In conclusion, it was noted that the operators tend to scale down activities rapidly in response to legal pressure or law enforcement actions, suggesting that psychological pressure could be a point of weakness. For defenders, the importance of identifying characteristic URL and API patterns, tracking related infrastructure, and conducting proactive threat hunting was emphasized.&lt;/p&gt;

&lt;h3&gt;The Mechanism for Building a Phishing Admin Panel&lt;/h3&gt;

&lt;h5&gt;Speaker: Masaomi Masumoto, NTT DOCOMO BUSINESS, Inc.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_3_masaomi_masumoto_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Masaomi Masumoto presented the methods for building phishing admin panels and their functionalities, against the backdrop of the growing prevalence of Phishing-as-a-Service (PhaaS).&lt;/p&gt;

&lt;p&gt;The session began by explaining how the widespread adoption of PhaaS has lowered the technical barriers to conducting phishing attacks and improved the efficiency of phishing operations, leading to the emergence of phishing admin panels. In recent implementations, these panels allow operators to create and configure phishing sites, manage stolen information, configure cloaking settings, manage domains, and even bypass one-time passwords.&lt;/p&gt;

&lt;p&gt;The presentation then outlined the construction methods and technical mechanisms of phishing admin panels, highlighting that they are designed for rapid deployment and removal through the use of Docker and automated installation scripts. A notable characteristic of such attack infrastructure is that immediacy and efficiency are prioritized over persistence. It was also explained that analyzing the deployment tools can provide insight into the underlying infrastructure used by the operators.&lt;/p&gt;

&lt;p&gt;Furthermore, through case studies such as “CoGUI” and “Oriental Gudgeon,” the presentation analyzed the dependent domains and URL structures, demonstrating that PhaaS infrastructure relies heavily on a limited set of specific URLs or domains. Given this high level of dependency, it was pointed out that blocking those particular URLs or domains could potentially disrupt the operation of the service as a whole.&lt;/p&gt;

&lt;p&gt;In conclusion, it was emphasized that effective phishing countermeasures require addressing not only individual phishing sites but also identifying and taking down the admin panels themselves. As a first step toward this objective, the speaker emphasized the need to understand the mechanisms and construction methods of phishing admin panels.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_3.jpg&quot; alt=&quot;JSAC2026_Day2_3.JPG&quot; /&gt;&lt;/p&gt;

&lt;h3&gt;Combatting residential proxy services in Japan: Part II&lt;/h3&gt;

&lt;h5&gt;Speaker: Yuji Ino, Recruit Co., Ltd.; Paul Ziegler, Reflare, Ltd.&lt;/h5&gt;

&lt;p&gt;&lt;br&gt;
In his presentation at JSAC2022 &lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_3_ino_jp.pdf&quot;&gt;“The Struggle Against Domestic Malicious Proxy Services”&lt;/a&gt;, Yuji Ino collected and analyzed the exit IP addresses used by 911, which was the largest provider at the time, over a one-year period. The session explained the detection of residential IP proxies that leveraged consumer Internet connections, as well as the challenges of IP address–based reputation assessment.&lt;/p&gt;

&lt;p&gt;In this presentation, together with Paul Ziegler, the speakers provided an update on three years of research conducted since JSAC2022. Based on continuous monitoring of domestic IP addresses, they discussed the latest trends in residential proxy services, their patterns of abuse, and related detection techniques. As the presentation contained a significant amount of information classified as TLP:RED, specific details are not disclosed.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_4_01.jpg&quot; alt=&quot;JSAC2026_Day2_4_01.JPG&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_4_02.jpg&quot; alt=&quot;JSAC2026_Day2_4_02.JPG&quot; /&gt;&lt;/p&gt;

&lt;h3&gt;A deep-dive into RapperBot C2 operation and DDoS attacks&lt;/h3&gt;

&lt;h5&gt;Speaker: Hideyuki Furukawa, National Institute of Information and Communications Technology&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_5_hideyuki-furukawa_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Hideyuki Furukawa provided an in-depth analysis of the IoT-focused DDoS botnet “RapperBot,” presenting findings on its C2 operations and DDoS attack activities, which had not previously been reported in detail.&lt;/p&gt;

&lt;p&gt;The session began with an overview of RapperBot, explaining that it primarily targets DVRs and network cameras and propagates through multiple scanners. An ongoing investigation since 2022, including darknet monitoring and data collected through honeypots, confirmed a large number of infections in regions such as Taiwan, the United States, and Japan, and revealed the large-scale operation of its C2 servers.&lt;/p&gt;

&lt;p&gt;The presentation then examined specific cases, including the correlation between RapperBot’s DDoS attack timing and intermittent service disruptions affecting X (formerly Twitter) in March 2025, as well as concentrated attacks against online game–related servers in China. In addition, analysis of the malware architecture, C2 protocol specifications, server rotation practices, and operational aspects of the user interface suggested that the C2 control panel may have been operated through macro-based automation or via a console interface. It also revealed instances of operational mistakes and inefficient configurations.&lt;/p&gt;

&lt;p&gt;Furthermore, based on approximately five months of data collected prior to the operator’s arrest, the presentation organized details of the C2 operations, attack commands, and targeting trends. It was reported that the implementation of a blacklist function prevented repeat attacks, ultimately leading to the cessation of communications and the arrest of the operator.&lt;/p&gt;

&lt;p&gt;In conclusion, the speaker emphasized the importance of understanding the operational realities of large-scale IoT botnets in order to accurately assess the threat landscape, and highlighted the need to reduce the number of vulnerable IoT devices as a fundamental measure.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_5.jpg&quot; alt=&quot;JSAC2026_Day2_5.JPG&quot; /&gt;&lt;/p&gt;

&lt;h3&gt;Unraveling the WSUS Exploit Chain: Incident Analysis and Actor Insights&lt;/h3&gt;

&lt;h5&gt;Speaker: Shohei Iwata; Teruki Yoshikawa, NTT Security Japan KK&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_6_shohei_iwata-teruki_yoshikawa_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Shohei Iwata and Teruki Yoshikawa presented an in-depth analysis of an attack exploiting the WSUS RCE vulnerability (CVE-2025-59287). They shared how the investigation progressed toward identifying the initial point of compromise, describing a hypothesis-driven analysis informed by insights gained through daily intelligence collection, as well as attribution analysis based on TTP evidence, including the abuse of Velociraptor. The session provided a practical reference case for incident response and offered recommendations for reviewing defensive measures in light of evolving threat trends.&lt;/p&gt;

&lt;p&gt;The presentation began with an overview of an attack targeting a Japanese company that was observed by a SOC in October 2025. In this incident, the intrusion began with the exploitation of the WSUS RCE vulnerability, and Velociraptor, a legitimate forensic/DFIR tool, was abused as an RMM tool. At the outset, there was no clear information regarding the infection vector, and the true initial point of compromise could not be readily determined based solely on EDR telemetry. However, by correlating multiple detected alerts with process tree analysis and network IoCs, the analysis reconstructed the deployment flow of Velociraptor via an MSI installer and concluded that this vulnerability was very likely used for initial access.&lt;/p&gt;

&lt;p&gt;The presentation then detailed the attack flow and the tools employed. By identifying commonalities across Velociraptor configuration files, PKI structures, hosting server domains, MSI file names, and AWS account names, the speakers determined that the multiple incidents were linked to the same actor.&lt;/p&gt;

&lt;p&gt;In conclusion, the speakers emphasized the importance of strengthening detection capabilities and reviewing configurations based on the lessons learned from this case, and shared practical insights applicable to incident analysis.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_6_01.jpg&quot; alt=&quot;JSAC2026_Day2_6_01.JPG&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_6_02.jpg&quot; alt=&quot;JSAC2026_Day2_6_02.JPG&quot; /&gt;&lt;/p&gt;

&lt;h3&gt;Continuous Intrusion/Continuous Distribution: Tracking Fox’s Iterative Malspam Campaign&lt;/h3&gt;

&lt;h5&gt;Speaker: Satoshi Kamekawa, ITOCHU Cyber &amp;amp; Intelligence Inc.&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_7_satoshi_kamekawa_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Satoshi Kamekawa presented an analysis of a phishing campaign targeting Japanese organizations that was attributed to “Silver Fox” and observed between September and October 2025. Based on attack patterns classified into five distinct phases, the session examined the characteristics of the suspicious emails, findings from the analysis of the attack infrastructure, and technical findings from the observed malware samples.&lt;/p&gt;

&lt;p&gt;The presentation began with an overview of the investigation into a large volume of phishing emails impersonating specific organizations and containing embedded URLs within the message body. When recipients clicked the malicious URLs, they were redirected through intermediary sites, leading to the download of a loader, which subsequently retrieved additional payloads in a multi-stage infection chain.&lt;/p&gt;

&lt;p&gt;The session then detailed the infection flow and highlighted inconsistencies in the malware’s implementation, such as logic designed to detect Japanese language environments while failing to execute outside Chinese language environments, suggesting potential development or configuration contradictions.&lt;/p&gt;

&lt;p&gt;Furthermore, it was explained that the threat actors continuously updated their tactics, including compiling malware and deploying it to C2 servers shortly before distributing phishing emails. The malware used in the campaign included ValleyRAT and VShell. While ValleyRAT had previously been reported primarily in attacks targeting organizations in China and Taiwan, cases involving Japanese organizations had been limited. In this campaign, however, Japan was also included among the targets, suggesting that the threat actors may be expanding the scope of their operations.&lt;/p&gt;

&lt;p&gt;In conclusion, based on similarities in the malware used and overlaps with previously observed activities, the speaker stated that the campaign was likely linked to “Silver Fox.” The presentation emphasized the importance of strengthening monitoring of Japanese-language phishing emails, improving detection and blocking of anomalous communications, and conducting continuous threat analysis.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_7.jpg&quot; alt=&quot;JSAC2026_Day2_7.JPG&quot; /&gt;&lt;/p&gt;

&lt;h3&gt;From Access to Encryption: Uncovering Qilin’s Attack Lifecycle&lt;/h3&gt;

&lt;h5&gt;Speaker: Takahiro Takeda, Cisco Talos&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_8_takahiro_takeda_en.pdf&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Takahiro Takeda presented an overview of ransomware trends in Japan, with a particular focus on the Qilin group. The session outlined the full attack lifecycle and the current state of initial access based on analysis of multiple incidents.&lt;/p&gt;

&lt;p&gt;The presentation began by noting that the number of ransomware incidents in Japan increased in 2025, with small and medium-sized enterprises accounting for more than half of affected organizations. Among these cases, Qilin was associated with a notable share of domestic incidents, underscoring its significant presence among domestic cases.&lt;/p&gt;

&lt;p&gt;It was further explained that Qilin has expanded its activities globally, including in the United States, Canada, China, and South Korea, and remains highly active, continuously publishing victim organizations on its leak site.&lt;/p&gt;

&lt;p&gt;The session then examined the realities of Qilin’s initial access methods. Primary intrusion vectors included the abuse of leaked credentials obtained through encrypted messaging applications such as Telegram and Signal, marketplace forums, and initial access brokers. Once inside a network, the attack typically progressed through reconnaissance, lateral movement, credential theft, abuse of RMM tools, and ultimately data exfiltration and encryption.&lt;/p&gt;

&lt;p&gt;Characteristic TTPs were also highlighted, including selective data exfiltration using a combination of legitimate and custom tools, encryption of entire virtual environments through automated scripts, clearly defined role separation within the group, and EDR evasion techniques.&lt;/p&gt;

&lt;p&gt;In conclusion, given the short time between initial access and encryption, the importance of early detection before ransomware execution was emphasized. Recommended measures included comprehensive log collection, strict enforcement of MFA, implementation of offline backups, proactive configuration of security products, and strengthened detection through the use of Sigma and YARA rules. The speaker also cautioned that attacks are likely to continue and become increasingly automated.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/ja/.assets/JSAC2026_Day2_8.jpg&quot; alt=&quot;JSAC2026_Day2_8.JPG&quot; /&gt;&lt;/p&gt;

&lt;h2&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;This article introduced the presentations delivered on the second day of JSAC2026. In the next installment of JPCERT/CC Eyes, coverage will continue with highlights from the workshop, lightning talk session, and panel discussion.&lt;/p&gt;

&lt;p&gt;Nanae Sasaki
(This article was machine-translated and manually reviewed.)&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>JSAC2026 -Day 1-</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/02/jsac2026day1.html" />
  <id>tag:movabletype.net,2003:post-3185053</id>
  <published>2026-02-20T02:00:00Z</published>
  <updated>2026-04-01T05:25:32Z</updated>
  <summary>JPCERT/CC hosted JSAC2026 from January 21 to 23, 2026. JSAC is an annual conference dedicated to advancing the capabilities of security analysts by fostering the exchange of technical knowledge and operational insights related to incident analysis and response. Now in...</summary>
  <author>
    <name>JPCERT/CC</name>
      </author>
  <category term="Event" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="JSAC" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;JPCERT/CC hosted JSAC2026 from January 21 to 23, 2026. JSAC is an annual conference dedicated to advancing the capabilities of security analysts by fostering the exchange of technical knowledge and operational insights related to incident analysis and response. Now in its ninth year, the event incorporated a new training program, expanding the program to three days. Across two days, the conference featured 17 presentations, three workshops, and six lightning talks. Presentation materials are available on &lt;a href=&quot;https://jsac.jpcert.or.jp/timetable.html&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;the JSAC website&lt;/a&gt;(some materials are not publicly available). This series in JPCERT/CC Eyes presents highlights from the conference in three installments. This first installment covers the presentations from Day 1 of the Main Track.&lt;/p&gt;

&lt;h3&gt;The Betrayed Update: Beyond the Signpost&lt;/h3&gt;

&lt;h5&gt;Speaker: Takahiro Yamamoto (ITOCHU Cyber &amp;amp; Intelligence Inc.)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_1_yamamoto_jp.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (Japanese)&lt;/a&gt;&lt;br/&gt;
&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_1_yamamoto_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Takahiro Yamamoto discussed a case involving a compromised update process of a legitimate application attributed to the threat actor “Tropic Trooper.” The investigative process leading to identification of the root cause was outlined, along with key lessons learned.&lt;/p&gt;

&lt;p&gt;At the outset, the speaker suspected lateral movement or a supply chain attack. However, detailed log analysis revealed that configuration data pointing to the legitimate application’s update server had been tampered with, redirecting the application to a malicious update destination. Analysis of multiple cases uncovered a common pattern: the issue only reproduced when the affected systems were connected to a specific home network. This finding indicated that the root cause was not the endpoint itself, but the surrounding network environment. Further investigation—leveraging endpoint sensors and custom scripts—revealed that a suspicious IP address had been configured on the cache DNS server referenced by the home router. As a result, DNS responses were poisoned, causing specific domains to resolve to a fake update server. The application then downloaded malicious configuration data, leading to malware delivery and execution.&lt;/p&gt;

&lt;p&gt;As countermeasures, the use of trusted DNS servers via full-tunnel VPNs was emphasized, along with adoption of DNS-over-TLS (DoT) or DNS-over-HTTPS (DoH) to mitigate DNS hijacking, and strengthened endpoint detection and monitoring. The session concluded that incident analysis yields valuable intelligence when attention is paid not only to observable outcomes, but also to the structural characteristics of the attack and the adversary’s intent.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_1-640wri.jpg&quot; width=&quot;640&quot; height=&quot;359&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059330 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Knife Cutting the Edge: Dissecting a Gateway Surveillance &amp;amp; MitM Framework&lt;/h3&gt;

&lt;h5&gt;Speaker: Chi-en “Ashley” Shen (Cisco Talos)&lt;/h5&gt;

&lt;p&gt;Chi-en “Ashley” Shen examined how routers and other edge devices have become critical targets in surveillance and espionage campaigns. The session analyzed a framework capable of inspecting and manipulating traffic directly on gateway edge devices. As this session was classified as TLP:RED, further details are omitted here.&lt;/p&gt;

&lt;h3&gt;The Return of Old Forces: Revealing New Campaigns Connected to a Missing Cyber Mercenary Firm&lt;/h3&gt;

&lt;h5&gt;Speaker: Joseph Chen (Trend Micro)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_3_joseph_chen_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Joseph Chen examined activities attributed to “Earth Lusca” and “Earth Krahang,” both reportedly linked to the Chinese company i-Soon. The company drew significant attention in February 2024 after internal documents were leaked, suggesting involvement in espionage activities and possible ties to government entities. Although activity from the associated groups appeared to subside following the leak, operations may have resumed in 2025.&lt;/p&gt;

&lt;p&gt;The “PONDSNAKE” campaign, first detected around October 2024, targeted government organizations as well as financial institutions, including insurance and securities firms. Initial access was achieved through exploitation of vulnerabilities in public-facing servers or via spear-phishing emails. After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN. Based on shared characteristics—such as the use of SnakeC2 variants and the abuse of compromised government websites—the activity was assessed with medium-to-high confidence as attributable to Earth Krahang.&lt;/p&gt;

&lt;p&gt;The “WILYCODE” campaign, identified around May 2025, targeted government agencies, educational institutions, and hospitals. It primarily exploited vulnerabilities in public-facing servers, including React2Shell (CVE-2025-55182). The group also utilized open-source hacking tools and executed Cobalt Strike and VShell via HyperBro Launcher. While overlaps such as HyperBro Launcher usage and similarities in C2 profiles were identified, many of the observed TTPs were common. As a result, attribution to Earth Lusca was assessed with low confidence.&lt;/p&gt;

&lt;p&gt;Chen concluded that when legacy tools are reused alongside newly introduced elements, attribution should be based on multiple independent lines of evidence rather than single indicators.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_3-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059331 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Attribution in Action: A Case Study of an Incident Involving Multiple Activity Clusters&lt;/h3&gt;

&lt;h5&gt;Speakers: Hiroaki Hara and Doel Santos (Palo Alto Networks)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_4_hiroaki_hara-doel_santos_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Hiroaki Hara and Doel Santos presented a case study in which three distinct activity clusters were operating concurrently within a single organization. A step-by-step attribution methodology grounded in observed facts was described.&lt;/p&gt;

&lt;p&gt;One cluster, “CL-STA-1048,” employed tools such as RawCookie, EggStreme Loader, Gorem RAT, and Masol RAT. Although potential links to known groups such as Earth Estries were considered, attribution was assessed with low confidence.&lt;/p&gt;

&lt;p&gt;Another cluster, “CL-STA-1049,” initiated activity using Hypnosis Loader via DLL proxy sideloading and subsequently deployed tools such as FluffyGh0st. Tool overlap provided strong evidence linking this cluster to “Unfading Sea Haze.”&lt;/p&gt;

&lt;p&gt;The “Stately Taurus” cluster involved tools including HIUPAN, USBFect, PUBLOAD (spread via USB), and CoolClient variants. Although a direct execution chain between PUBLOAD and CoolClient was not confirmed, similarities in obfuscation techniques suggested codebase-level connections.&lt;/p&gt;

&lt;p&gt;A framework separating source reliability from information credibility in attribution assessments was introduced. The trend of “Premier Pass-as-a-Service,” in which multiple APT groups collaborate closely in coordinated operations, was also highlighted, underscoring the importance of regularly reviewing internal attribution processes.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_4-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059332 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Ghost in Your Network: How Earth Kurma Stays Hidden and Exfiltrates Your Data&lt;/h3&gt;

&lt;h5&gt;Speakers: Nick Dai and Sunny W. Lu (Trend Micro)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_5_nick_dai_sunny-w-lu_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Nick Dai and Sunny W. Lu shared findings on the APT group “Earth Kurma,” which targets government and telecommunications sectors in Southeast Asia. Initial compromise typically begins with vulnerable web servers, followed by reconnaissance and lateral movement. Multiple toolsets are selectively deployed depending on the environment to maintain persistence and evade detection.&lt;/p&gt;

&lt;p&gt;For persistence, combinations of rootkits, backdoors, and loaders are used. “MMLOAD” relies on reflective loading for staged deployment. “KRNRAT” injects a user-mode agent into svchost.exe to maintain memory-resident execution. “MORIYA” incorporates new injection methods and EDR evasion techniques. Additionally, a Cisco Webex variant of “DOWNBEGIN” abuses multiple meeting rooms as distinct C2 channels.&lt;/p&gt;

&lt;p&gt;For data exfiltration, PowerShell is used for collection and compression while legitimate cloud services such as OneDrive (ODRIZ), Dropbox (SIMPOBOXSPY), and Cisco Webex (SIMPOWEBEXSPY) are leveraged to reduce visibility. Distributed file systems are also used for both deployment and exfiltration.&lt;/p&gt;

&lt;p&gt;As countermeasures, they recommended monitoring cloud communications by unauthorized applications, analyzing large internal data transfers and anomalous network paths, and preventing the installation of untrusted drivers.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_5-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059334 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Continuous Evolution of Tianwu&#39;s Pangolin8RAT and Custom Cobalt Strike Beacon&lt;/h3&gt;

&lt;h5&gt;Speaker: Naoki Takayama (Internet Initiative Japan Inc.)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_6_naoki_takayama_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Naoki Takayama reported on the continued evolution of “Pangolin8RAT” and a custom Cobalt Strike Beacon associated with the Chinese-linked APT group “Tianwu.”&lt;/p&gt;

&lt;p&gt;Using a sample submitted to VirusTotal in September 2025 as a starting point, Takayama outlined an execution chain in which legitimate processes such as regsvr32.exe load “CoreX Loader.” The loader decrypts data embedded in its resources using XOR and AES before ultimately loading Pangolin8RAT into memory.&lt;/p&gt;

&lt;p&gt;Pangolin8RAT is designed with plugin-based extensibility in mind, allowing its functionality to be expanded through additional modules. Takayama explained that the malware minimizes forensic artifacts by deleting logs and certain data after a system reboot, making it more difficult to trace. He also highlighted several communication-related characteristics, including abuse of Nutstore’s WebDAV service, the use of uniquely structured cookies in HTTPS communications, and manipulation of Host headers to conceal the underlying C2 infrastructure. In addition, recent evolutions aimed at detection evasion were discussed. These include strengthened string obfuscation, suppression of RTTI, and a mechanism that XOR-encrypts configuration data when specific processes are detected.&lt;/p&gt;

&lt;p&gt;On the Beacon side, improvements such as integrating BOFs for sleep masking and changes to configuration encoding were observed. Remnants of legacy C2 information in headers provided operational clues regarding development and deployment practices.&lt;/p&gt;

&lt;p&gt;Takayama noted that activity has continued since 2022, with indications that operations may have intensified again around October 2024. He emphasized the importance of continuous monitoring through the sharing of YARA and Sigma rules as well as IoCs.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_6-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059335 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Incident Response at the Edge: Unmasking the Massive Exploitation of Ivanti&lt;/h3&gt;

&lt;h5&gt;Speakers: Greg Chen and Sharon Liu (TeamT5)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_7_Greg_chen_Sharon_liu_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Greg Chen and Sharon Liu examined widespread exploitation campaigns targeting VPN and gateway products such as Ivanti Connect Secure (ICS), with a focus on incident response methodologies for edge devices. They reported identifying at least 170 compromised devices across 25 regions, with significant concentrations in Japan, Taiwan, South Korea, and the United States. The operation involved intrusions associated with the SPAWN malware suite.&lt;/p&gt;

&lt;p&gt;They outlined investigative challenges specific to Ivanti Connect Secure, including encrypted system partitions, GUI-centric management that limits log visibility, and overreliance on vendor-provided integrity check tools. To address these limitations, they demonstrated vendor-assisted remote debugging, offline analysis via decrypted disk images, and SSH console validation in controlled lab environments. When identifying suspicious binaries, they recommended supplementing integrity hash comparisons with additional indicators such as anomalous timestamps, differences between static and dynamic linking, and ELF metadata analysis.&lt;/p&gt;

&lt;p&gt;They explained that the attack chain began with CVE exploitation, followed by deployment of the in-memory backdoor “TextDoor,” persistence via the SPAWN malware suite, and credential theft through “DebtTheft.” They emphasized the importance of protocol analysis and network signatures in identifying previously unknown compromises, particularly when integrity checks may have been bypassed.&lt;/p&gt;

&lt;h3&gt;Infrastructure-less Adversary: C2 Laundering via Dead-Drop Resolvers and the Microsoft Graph API&lt;/h3&gt;

&lt;h5&gt;Speakers: Wei-Chieh Chao and Shih-Min Chan (Cycraft)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_8_wei-chieh_chao_shih-min_chan_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Wei-Chieh Chao and Shih-Min Chan presented a case involving a Chinese state-sponsored actor targeting Taiwanese government agencies and the manufacturing sector. They described infrastructure-agnostic tradecraft, in which dedicated infrastructure is avoided by abusing legitimate communication platforms for C2 operations.&lt;/p&gt;

&lt;p&gt;In the incident they analyzed, the attackers gained initial access via phishing, escalated privileges by exploiting AD CS misconfigurations, conducted lateral movement, and deployed remote access infrastructure such as SoftEther VPN. For C2 communications, they leveraged the Microsoft Graph API, C2 servers hosted behind Cloudflare, and compromised public websites functioning as “dead-drop” resolvers. They also highlighted a technique in which AD logon scripts were temporarily modified to distribute malware across endpoints before being restored to their original state to evade detection. They analyzed three malware families: GRAPHBROTLI and GRAPHRELOOK, which repurpose Microsoft Graph and Outlook APIs for C2 communications, and RCREMARK, which communicates with C2 servers hosted behind Cloudflare and retrieves commands embedded in HTML comments for execution.&lt;/p&gt;

&lt;p&gt;They assessed that short-lived configuration changes and abuse of legitimate infrastructure reduce the effectiveness of blocklist-based defenses. They emphasized the importance of protecting and monitoring logon scripts, as well as closely inspecting cloud service API traffic and web access patterns.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_8-640wri.jpg&quot; width=&quot;640&quot; height=&quot;360&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059336 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Konni’s New Arsenal: Unmasking GSRAT in North Korea-linked APT Operation&lt;/h3&gt;

&lt;h5&gt;Speakers: Takuma Matsumoto and Yoshihiro Ishikawa (LAC Co., Ltd.)&lt;/h5&gt;

&lt;p&gt;&lt;a href=&quot;https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_9_takuma_matsumoto-yoshihiro_ishikawa_en.pdf&quot; title=&quot;&quot; target=&quot;_blank&quot;&gt;Presentation Materials (English)&lt;/a&gt;&lt;br/&gt;&lt;/p&gt;

&lt;p&gt;Takuma Matsumoto and Yoshihiro Ishikawa analyzed attacks leveraging “GSRAT,” an AutoIt-based RAT observed since February 2025 and attributed to activity associated with the North Korea-linked threat actor “Konni.” In May 2025, they reported that the attackers conducted a spear-phishing campaign targeting organizations related to domestic financial institutions. In this campaign, the attackers impersonated affiliated companies and distributed malicious links.&lt;/p&gt;

&lt;p&gt;In the observed infection chain, victims received spear-phishing emails that led them to download ZIP archives containing shortcut (LNK) files disguised as documents. When the LNK file was executed, an obfuscated script ran and displayed decoy content to the user while simultaneously downloading and extracting additional payloads. The infection then proceeded through VBS and BAT scripts, which ultimately launched AutoIt. Persistence was achieved by registering the malware in the Startup folder and creating scheduled tasks. The compiled AutoIt script containing GSRAT then communicated with its C2 server, enabling remote control of the compromised host.&lt;/p&gt;

&lt;p&gt;The speakers also outlined characteristics of AutoIt, noting its capabilities for Windows GUI automation and API invocation, as well as its ability to be compiled into standalone executables with minimal dependencies, making it relatively lightweight. They introduced encoding techniques observed in recent samples, including the widely seen EA06 format, and explained associated extraction methods. GSRAT transmits a victim-specific identifier generated from host information along with version data to its C2 server and provides core backdoor functionality such as remote shell access, file upload and download, enumeration, deletion, and execution. Variants were observed incorporating modifications such as JSON-formatted communications and the introduction of custom delimiters.&lt;/p&gt;

&lt;p&gt;Finally, the speakers outlined the indicators linking GSRAT to Konni. These included the transition from Custom Lilith RAT to GSRAT and distinctive infrastructure operation patterns observed across campaigns. They also summarized recommended defensive measures. These include using YARA and Sigma rules for detection, monitoring persistence mechanisms with Autoruns and EDR solutions, and restricting AutoIt execution through AppLocker or WDAC based on code-signing information.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/JSAC2026_Day1_9-640wri.jpg&quot; width=&quot;640&quot; height=&quot;413&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-4059337 mt-image-left&quot; style=&quot;display: inline-block; float: left&quot;/&gt;&lt;/p&gt;

&lt;h3&gt;Conclusion&lt;/h3&gt;

&lt;p&gt;This installment covered the presentations delivered on the first day of JSAC2026. The next issue of JPCERT/CC Eyes will continue with highlights from Day 2.&lt;/p&gt;

&lt;p style=&quot;text-align: right;&quot;&gt;
Tomoya Kamei&lt;br/&gt;
(This article was machine-translated and manually reviewed.)
&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>Multiple Threat Actors Rapidly Exploit React2Shell: A Case Study of Active Compromise</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2026/02/multiple-threat-actors-rapidly-exploit-react2shell-a-case-study-of-active-compromise.html" />
  <id>tag:movabletype.net,2003:post-3179989</id>
  <published>2026-02-13T02:00:00Z</published>
  <updated>2026-08-31T23:40:18Z</updated>
  <summary>On December 3, 2025 (local time), a vulnerability allowing unauthenticated remote code execution in React Server Components (RSC) (CVE-2025-55182) was disclosed. JPCERT/CC has received multiple incident reports related to this attack. Among them, there was a case in which this...</summary>
  <author>
    <name>JPCERT/CC</name>
      </author>
  <category term="Incident" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;On December 3, 2025 (local time), a vulnerability allowing unauthenticated remote code execution in React Server Components (RSC) (&lt;a href=&quot;https://www.jpcert.or.jp/newsflash/2025120501.html&quot; target=&quot;_blank&quot;&gt;CVE-2025-55182&lt;/a&gt;) was disclosed. JPCERT/CC has received multiple incident reports related to this attack. Among them, there was a case in which this vulnerability was exploited by multiple threat actors within a short period of time, resulting in multiple incidents occurring simultaneously, including website defacement. This article demonstrates how rapidly and indiscriminately attackers act when an easily exploitable vulnerability is disclosed, together with an attack timeline and an overview of the malware used. We hope this will serve as a reference for understanding how quickly countermeasures must be implemented when such critical vulnerabilities are made public.&lt;/p&gt;

&lt;h3&gt;Attack Timeline&lt;/h3&gt;

&lt;p&gt;Table 1 shows the attack timeline identified in the case. (To avoid revealing the identity of the affected organization, some URL paths and identifiers are masked.)&lt;/p&gt;

&lt;table border=&quot;1&quot; width=&quot;100%&quot;&gt;
&lt;caption&gt;Table 1: Attack Timeline&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;Date and Time (JST)&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;Description&lt;/div&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-05 15:52&lt;/td&gt;
&lt;td&gt;Installation of coin miners (sex.sh, xmrig)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-06 07:28&lt;/td&gt;
&lt;td&gt;Installation of coin miner (sex.sh.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-06 09:53, 10:09, 11:00&lt;/td&gt;
&lt;td&gt;Installation of HISONIC (javax) backdoor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-06 15:00&lt;/td&gt;
&lt;td&gt;Execution of Global Socket (npm-cli) hourly via cron&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-06 19:31&lt;/td&gt;
&lt;td&gt;Installation of SNOWLIGHT downloader (javas) and CrossC2 (rsyslo)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-07 12:24&lt;/td&gt;
&lt;td&gt;Installation of coin miner (xmrig)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-07 16:51&lt;/td&gt;
&lt;td&gt;Cron configuration modified to execute /tmp/kernal (disguised as kernel) every minute&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-07 19:46&lt;/td&gt;
&lt;td&gt;Website defacement (display of warning message)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;left&quot;&gt;2025-12-07 22:15&lt;/td&gt;
&lt;td&gt;Incident discovered following a report from a service user&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Only two days after the React2Shell vulnerability was disclosed on December 3, 2025, attacks aimed at installing coin miners were observed. Following this initial activity, various types of malware such as RATs and backdoors were installed and executed by multiple attackers, resulting in a situation where multiple threat actors had compromised a single server. &lt;br /&gt;
In addition to the timeline above, suspicious HTTP POST communications believed to target the React2Shell vulnerability were observed in the web server access logs from more than 100 IP addresses during the period from December 5 to 7, 2025. (Because request headers and POST data were not recorded in the access logs, this assessment was based on factors such as the User-Agent, request path, and response size.) This suggests that the server may actually have been targeted by even more attackers.&lt;/p&gt;

&lt;h3&gt;Initial Website Defacement&lt;/h3&gt;

&lt;p&gt;In this case, the compromise was discovered after a website user noticed that the website had been defaced by attackers and reported it. On the defaced website, a warning message was displayed in four languages stating that there was a vulnerability identified as CVE-2025-55182 and that patches needed to be applied immediately. Figure 1 shows an example of a defaced web page.&lt;/p&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/react2shell-fig1-800wri.png&quot; width=&quot;800&quot; height=&quot;347&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-1862911 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;figcaption&gt;Figure 1: Defaced web page&lt;/figcaption&gt;&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;Such defacements were confirmed on multiple websites both in Japan and overseas, all of which contained text urging immediate countermeasures to the vulnerability. Figure 2 shows an example of defaced sites displayed in search engine results.&lt;/p&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/react2shell-fig2-800wri.png&quot; width=&quot;800&quot; height=&quot;398&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-1862911 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;figcaption&gt;Figure 2: Google search results&lt;/figcaption&gt;&lt;/figure&gt;&lt;/p&gt;

&lt;h3&gt;Installed Malware&lt;/h3&gt;

&lt;p&gt;In this case, a variety of malware and open-source tools were abused. Table 2 lists the malware that was installed (excluding configuration files and similar artifacts).&lt;/p&gt;

&lt;table border=&quot;1&quot; width=&quot;100%&quot;&gt;
&lt;caption&gt;Table 2: Installed Malware&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;No.&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;File Name&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;Description&lt;/div&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;sex.sh&lt;/td&gt;
&lt;td&gt;Bash script for downloading xmrig&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;sex.sh.1&lt;/td&gt;
&lt;td&gt;Bash script for downloading xmrig&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;miner.sh&lt;/td&gt;
&lt;td&gt;Bash script for launching xmrig&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;xmrig&lt;/td&gt;
&lt;td&gt;xmrig coin miner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;javax&lt;/td&gt;
&lt;td&gt;HISONIC backdoor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;javas&lt;/td&gt;
&lt;td&gt;Bash script for downloading SNOWLIGHT&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;rsyslo&lt;/td&gt;
&lt;td&gt;CrossC2 RAT&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;npm-cli&lt;/td&gt;
&lt;td&gt;Global Socket tool&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;kernal&lt;/td&gt;
&lt;td&gt;Details unknown because it had been deleted&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Notably, in addition to typical financially motivated coin miners, the following were also observed: a SNOWLIGHT &lt;a href=&quot;#1&quot;&gt;[1]&lt;/a&gt; downloader reportedly used by UNC5174, a Golang-based HISONIC backdoor &lt;a href=&quot;#2&quot;&gt;[2]&lt;/a&gt; reportedly used by UNC6603, and CrossC2 RAT &lt;a href=&quot;#3&quot;&gt;[3]&lt;/a&gt;, the Linux version of the Cobalt Strike implementation, which was installed at the same time as SNOWLIGHT. Although the attackers’ actual objectives remain unclear, it is possible that these tools were intended to be exploited as part of a future attack infrastructure. &lt;br /&gt;
Additionally, unlike most cases reported by other security vendors, this incident involved the abuse of the open-source tool Global Socket (gsocket) &lt;a href=&quot;#4&quot;&gt;[4]&lt;/a&gt;. This tool enables two devices that cannot directly reach each other due to NAT or firewall restrictions to connect via a relay network called the Global Socket Relay Network (GSRN). A key feature is that only devices sharing the same pre-shared key can communicate with each other. Communications are end-to-end encrypted, and GSRN only relays encrypted traffic. &lt;br /&gt;
In this case, the attackers specified the following environment variables and options at execution time, using npm-cli.dat as a secret file and abusing the tool as a backdoor that allowed remote operation via bash over port 53, which is primarily used for DNS communication.  &lt;/p&gt;

&lt;pre&gt;
GS_PORT=&#39;53&#39; SHELL=/bin/bash TERM=xterm-256color GS_ARGS=&quot;-k /home/***/.config/dbus/npm-cli.dat -liqD&quot;
&lt;/pre&gt;

&lt;h3&gt;Conclusion&lt;/h3&gt;

&lt;p&gt;In this React2Shell case, the vulnerability was rapidly incorporated into attack tools after disclosure, and within just a few days it was observed being abused by many threat actors. Attackers exploit vulnerabilities at extremely high speed, and when critical vulnerabilities are disclosed, it is essential to promptly assess the scope of impact and apply patches and other countermeasures. &lt;br /&gt;
Furthermore, when addressing vulnerabilities that are known to be actively exploited, it is necessary to verify whether compromise has already occurred in addition to applying patches. As demonstrated in this case, there may be more serious compromises beyond visible website defacement, and so it is recommended to carefully investigate whether there are any other affected components. &lt;br /&gt;
Details such as the C2 of the malware covered in this article are provided in the Appendix for reference.&lt;/p&gt;

&lt;p style=&quot;text-align: right;&quot;&gt;Kota Kino, Yuki Yano (This article was machine-translated and manually reviewed.)&lt;/p&gt;

&lt;h3&gt;References&lt;/h3&gt;

&lt;p&gt;&lt;a name=&quot;1&quot;&gt;&lt;/a&gt;[1] SNOWLIGHT Windows malware used by UNC5174 &lt;br /&gt;
&lt;a href=&quot;https://sect.iij.ad.jp/blog/2025/11/unc5174-windows-snowlight-in-2025/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://sect.iij.ad.jp/blog/2025/11/unc5174-windows-snowlight-in-2025/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;2&quot;&gt;&lt;/a&gt;[2] Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) &lt;br /&gt;
&lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-exploit-react2shell-cve-2025-55182&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-exploit-react2shell-cve-2025-55182&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;3&quot;&gt;&lt;/a&gt;[3] CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks &lt;br /&gt;
&lt;a href=&quot;https://blogs.jpcert.or.jp/en/2025/08/crossc2.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://blogs.jpcert.or.jp/en/2025/08/crossc2.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;4&quot;&gt;&lt;/a&gt;[4] Global Socket &lt;br /&gt;
&lt;a href=&quot;https://github.com/hackerschoice/gsocket&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://github.com/hackerschoice/gsocket&lt;/a&gt;&lt;/p&gt;

&lt;h4&gt;Appendix A: C2&lt;/h4&gt;

&lt;table border=&quot;1&quot; width=&quot;100%&quot;&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;No.&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;Destination&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;Purpose&lt;/div&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;45.143.131[.]123:59999&lt;/td&gt;
&lt;td&gt;SNOWLIGHT download source / C2 server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;154.89.152[.]240:443&lt;/td&gt;
&lt;td&gt;CrossC2 C2 server&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h4&gt;Appendix B: Malware Hashes&lt;/h4&gt;

&lt;table border=&quot;1&quot; width=&quot;100%&quot;&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;No.&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;Hash (SHA-256)&lt;/div&gt;&lt;/th&gt;
&lt;th&gt;&lt;div style=&quot;text-align: center;&quot;&gt;File Name&lt;/div&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;5bae25736a09de5f4a0f9761d2b7bfa81ca8dba39de2a724473c9d021a65daa9&lt;/td&gt;
&lt;td&gt;sex.sh&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;ba43e447e63611d365300bf2e8e43ccb02ea112778d0d555ef9a9ccf6169808b&lt;/td&gt;
&lt;td&gt;sex.sh&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;ac3e12fa0aa4d6e4eed322e81ecf708a8c9bea29247ae6b26cc39d3b3a6c2fb8&lt;/td&gt;
&lt;td&gt;miner.sh&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;a536d755313ce550a510137211eca6171f636fb316026e9df8523c496c8fcd12&lt;/td&gt;
&lt;td&gt;xmrig&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;0c748b9e8bc6b5b4fe989df67655f3301d28ef81617b9cbe8e0f6a19d4f9b657&lt;/td&gt;
&lt;td&gt;xmrig&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;1a1edbea47162b1aa844252fcd4fb97f2a67faec1993e7819efc6a04b7c15552&lt;/td&gt;
&lt;td&gt;javax&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;0d07a974993221305ca7af139b73d9de1dcd992f553215e4f041e830a2d82729&lt;/td&gt;
&lt;td&gt;javas&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;5baa52387daedea5e3e00adf96ecacb4a2cdc98100664f29ac86e8e4a423baaf&lt;/td&gt;
&lt;td&gt;54ad0ee3tcp&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;c1a9cfc62626118bd9f54e401fd52ecd2d766a5e8a69dbc7db909ea5c987fcc0&lt;/td&gt;
&lt;td&gt;54ad0ee3tcp&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;4a74676bd00250d9b905b95c75c067369e3911cdf3141f947de517f58fc9f85c&lt;/td&gt;
&lt;td&gt;rsyslo&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;td&gt;cb5f62bf7b591e69bd38e6bf8e40e8d307d154b2935703422d44f02e403d2e78&lt;/td&gt;
&lt;td&gt;npm-cli&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

    

  </content>
</entry>
<entry>
  <title>YAMAGoya: A Real-time Client Monitoring Tool Using Sigma and YARA Rules</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2025/11/YAMAGoya.html" />
  <id>tag:movabletype.net,2003:post-3097269</id>
  <published>2025-11-18T02:00:00Z</published>
  <updated>2025-11-18T03:00:51Z</updated>
  <summary>In recent years, fileless malware and obfuscation techniques have made it increasingly difficult to detect suspicious activity by scanning files alone. To counter these threats, security researchers and malware analysts actively create and publish detection rules such as Sigma and...</summary>
  <author>
    <name>朝長 秀誠 (Shusei Tomonaga)</name>
      </author>
  <category term="Security Technology" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="Tool" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;In recent years, fileless malware and obfuscation techniques have made it increasingly difficult to detect suspicious activity by scanning files alone. To counter these threats, security researchers and malware analysts actively create and publish detection rules such as Sigma and YARA. &lt;br /&gt;
However, many existing endpoint security tools rely on unique detection engines, instead of directly using Sigma or YARA. To address this problem, JPCERT/CC released the open-source threat hunting tool &lt;strong&gt;YAMAGoya&lt;/strong&gt;. The tool is available at the following GitHub repository, and feel free to use it.&lt;/p&gt;

&lt;p&gt;GitHub JPCERTCC/YAMAGoya: &lt;a href=&quot;https://github.com/JPCERTCC/YAMAGoya&quot; title=&quot;YAMAGoya&quot; target=&quot;_blank&quot;&gt;https://github.com/JPCERTCC/YAMAGoya&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/yamagoya-fig1.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/yamagoya-fig1-640wri.png&quot; width=&quot;640&quot; height=&quot;424&quot; alt=&quot;YAMAGoya startup screen&quot; class=&quot;asset asset-image at-xid-3934546 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/a&gt;&lt;figcaption&gt;Figure 1: YAMAGoya startup screen&lt;/figcaption&gt;&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;This blog article introduces YAMAGoya&#39;s concept and how to use it.&lt;/p&gt;

&lt;h3&gt;Concept of YAMAGoya&lt;/h3&gt;

&lt;p&gt;YAMAGoya is designed to detect threats by combining &lt;strong&gt;ETW (Event Tracing for Windows) event monitoring with memory scanning&lt;/strong&gt;. The main features of this tool are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Userland-only operation&lt;/strong&gt;: No kernel driver required, making implementation easy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real-time monitoring&lt;/strong&gt;: Monitor files, processes, registry, DNS, network, PowerShell, WMI, etc. in real time via ETW.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Supports multiple rule formats&lt;/strong&gt;: Supports Sigma and original YAML rules that can be used for correlation analysis.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Memory scanning&lt;/strong&gt;: Detect fileless or packed malware using YARA rules.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;GUI / CLI support&lt;/strong&gt;: Can be used from the GUI or automated from the command line.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Installation&lt;/h3&gt;

&lt;h4&gt;Get binaries&lt;/h4&gt;

&lt;p&gt;If you want to evaluate the tool immediately, you can download binaries from the &lt;a href=&quot;https://github.com/JPCERTCC/YAMAGoya/releases&quot; title=&quot;Releases&quot; target=&quot;_blank&quot;&gt;GitHub repository&#39;s Releases page&lt;/a&gt;.&lt;/p&gt;

&lt;h4&gt;Build&lt;/h4&gt;

&lt;p&gt;If you want to build it from source, please refer to the &lt;a href=&quot;https://github.com/JPCERTCC/YAMAGoya/blob/main/README.md&quot; title=&quot;README&quot; target=&quot;_blank&quot;&gt;README&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;How to use&lt;/h3&gt;

&lt;p&gt;YAMAGoya can be used via GUI and CLI. Start from command-line without options or double-click to launch the GUI.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
# Execute GUI
&gt; YAMAGoya.exe
&lt;/pre&gt;

&lt;p&gt;This tool must be executed with administrative privileges (to start an ETW session). When launching the tool, choose “Run as administrator” from the right-click menu or start a command prompt with administrative privileges.&lt;/p&gt;

&lt;p&gt;From the command line, you can run it as follows. See the &lt;strong&gt;help&lt;/strong&gt;option for additional options.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
# Monitor with Sigma rules
&gt; YAMAGoya.exe --session --sigma &quot;C:\Rules\Sigma&quot; --all
&lt;/pre&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
# Memory scan with YARA rules
&gt; YAMAGoya.exe --session --yara &quot;C:\Rules\YARA&quot; --all
&lt;/pre&gt;

&lt;h3&gt;Supported rules in YAMAGoya&lt;/h3&gt;

&lt;p&gt;Since YAMAGoya supports Sigma and YARA rules, please make use of publicly available rules. For Sigma rules, the supported categories are limited to those targeting Windows OS. For details, see &lt;a href=&quot;https://github.com/JPCERTCC/YAMAGoya/blob/main/README.md#sigma-support&quot; title=&quot;SIGMA Support&quot; target=&quot;_blank&quot;&gt;README&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;In addition to Sigma and YARA rules, the tool supports original YAML rules. The following section explains how to write custom YAML rules.&lt;/p&gt;

&lt;h4&gt;How to write custom YAML rules&lt;/h4&gt;

&lt;p&gt;To create a custom YAML rule, follow the schema below. Each rule file must include the following:&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#1a1a1a;background:#f5f0f0;overflow: auto;white-space: pre&#39;&gt;
- rulename: A unique name for the rule
- description: A description of what the rule detects
- rules: A list of rule items. Each item must include:
  - ruletype: The type of rule (e.g., regex, binary)
  - target: The event category to match
  - rule: The pattern or value to match (For regex rules, a valid regular expression)
&lt;/pre&gt;

&lt;p&gt;You can use the following event categories for &lt;strong&gt;target&lt;/strong&gt;(Table 1).&lt;/p&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;caption&gt;Table 1: List of “target”&lt;/caption&gt;
&lt;tr&gt;
&lt;td style=&quot;background-color: #bdbdbd; width: 150px; text-align: center;&quot;&gt;Target name&lt;/td&gt;
&lt;td style=&quot;background-color: #bdbdbd; width: 300px; text-align: center;&quot;&gt;Description&lt;/td&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;file&lt;/td&gt;
&lt;td&gt;File creation events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;delfile&lt;/td&gt;
&lt;td&gt;File deletion events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;process&lt;/td&gt;
&lt;td&gt;Process events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;open&lt;/td&gt;
&lt;td&gt;OpenProcess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;load&lt;/td&gt;
&lt;td&gt;DLL load events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;registry&lt;/td&gt;
&lt;td&gt;Registry events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;dns&lt;/td&gt;
&lt;td&gt;DNS events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ipv4&lt;/td&gt;
&lt;td&gt;IPv4 network events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ipv6&lt;/td&gt;
&lt;td&gt;IPv6 network events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;shell&lt;/td&gt;
&lt;td&gt;Shell-related events (RunKey, shortcuts)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;powershell&lt;/td&gt;
&lt;td&gt;PowerShell execution events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;wmi&lt;/td&gt;
&lt;td&gt;WMI command execution events&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;By default, an alert is raised if all rules listed in a single file are observed within 10 seconds. For example, you can create a rule that detects malware when a file is created, a process is executed, a DLL is loaded, and network communication occurs. In this way, custom YAML rules are effective for detection by correlating multiple activities.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
rulename: &quot;ANEL&quot;
description: &quot;Detects ANEL from maldoc type&quot;
rules:
  - ruletype: &quot;regex&quot;
    target: &quot;file&quot;
    rule: &quot;Tmp\\.docx$&quot;
  - ruletype: &quot;regex&quot;
    target: &quot;process&quot;
    rule: &quot;ScnCfg32\\.Exe$&quot;
  - ruletype: &quot;regex&quot;
    target: &quot;dll&quot;
    rule: &quot;vsodscpl\\.dll$&quot;
  - ruletype: &quot;regex&quot;
    target: &quot;file&quot;
    rule: &quot;TCDolW0p\\.log$&quot;
  - ruletype: &quot;ipv4&quot;
    target: &quot;ipv4&quot;
    rule: &quot;45.32.116.146&quot;
&lt;/pre&gt;

&lt;h3&gt;Checking logs&lt;/h3&gt;

&lt;p&gt;When using the GUI, you can view logs in the Alert tab. From &lt;strong&gt;Open Log File&lt;/strong&gt; in Alert tab, you can also check the text log (Figure 2).&lt;/p&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/yamagoya-fig2.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/yamagoya-fig2-640wri.png&quot; width=&quot;640&quot; height=&quot;423&quot; alt=&quot;YAMAGoya&#39;s Alert tab&quot; class=&quot;asset asset-image at-xid-3934547 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/a&gt;&lt;figcaption&gt;Figure 2: YAMAGoya&#39;s Alert tab&lt;/figcaption&gt;&lt;/figure&gt;&lt;/p&gt;

&lt;p&gt;Alerts are also stored in the Event Log (Application). Table 2 lists the event IDs that YAMAGoya records.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;caption&gt;Table 2: List of Event Log IDs recorded by YAMAGoya (Application)&lt;/caption&gt;
    &lt;tr&gt;
      &lt;td style=&quot;background-color:#bdbdbd; width:100px; text-align:center;&quot;&gt;Event ID&lt;/td&gt;
      &lt;td style=&quot;background-color:#bdbdbd; text-align:center;&quot;&gt;Main trigger condition&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8001&lt;/td&gt;
      &lt;td&gt;Detection by a custom YAML rule&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8002&lt;/td&gt;
      &lt;td&gt;Partial match with a custom YAML rule (debug message)&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8003&lt;/td&gt;
      &lt;td&gt;Termination of a process detected by a custom YAML rule (when Kill mode is active)&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8005&lt;/td&gt;
      &lt;td&gt;WinRM outbound communication&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8006&lt;/td&gt;
      &lt;td&gt;WinRM inbound communication&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8008&lt;/td&gt;
      &lt;td&gt;Security Mitigations event detection&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8009&lt;/td&gt;
      &lt;td&gt;Security Adminless event detection&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8011&lt;/td&gt;
      &lt;td&gt;Security CVE event detection&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8012&lt;/td&gt;
      &lt;td&gt;SMB server authentication detection&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8013&lt;/td&gt;
      &lt;td&gt;SMB server file share detection&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8014&lt;/td&gt;
      &lt;td&gt;SMB server file share addition detection&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8015&lt;/td&gt;
      &lt;td&gt;SMB client connection failure&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8016&lt;/td&gt;
      &lt;td&gt;SMB client file transfer&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8017&lt;/td&gt;
      &lt;td&gt;ETW session start&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;8018&lt;/td&gt;
      &lt;td&gt;ETW session stop&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;9001&lt;/td&gt;
      &lt;td&gt;Detection by a Sigma rule&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td style=&quot;text-align:center;&quot;&gt;9002&lt;/td&gt;
      &lt;td&gt;Termination of a process detected by a Sigma rule (when Kill mode is active)&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;figure class=&quot;mt-figure mt-figure-center&quot;&gt;&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/yamagoya-fig3.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/yamagoya-fig3-640wri.png&quot; width=&quot;640&quot; height=&quot;302&quot; alt=&quot;YAMAGoya alerts recorded in the event log&quot; class=&quot;asset asset-image at-xid-3934548 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/a&gt;&lt;figcaption&gt;Figure 3: YAMAGoya alerts recorded in the event log&lt;/figcaption&gt;&lt;/figure&gt;&lt;/p&gt;

&lt;h3&gt;In closing&lt;/h3&gt;

&lt;p&gt;Because YAMAGoya can use publicly available signatures such as Sigma and YARA, it enables security teams to use the community’s knowledge for security measures. Please use the tool for threat hunting and incident response. We welcome Pull Request and any other requests for features.&lt;/p&gt;

&lt;p&gt;Shusei Tomonaga &lt;br /&gt;
(Translated by Takumi Nakano)&lt;/p&gt;

&lt;h4&gt;FAQ&lt;/h4&gt;

&lt;h5&gt;Q1. Can YAMAGoya replace traditional antivirus software?&lt;/h5&gt;

&lt;p&gt;A. No. YAMAGoya is not a replacement for antivirus software but a complementary tool. Since the tool has no default detection rule, you first need to collect or create detection rules.&lt;/p&gt;

&lt;h5&gt;Q2. Can I run YAMAGoya in the background?&lt;/h5&gt;

&lt;p&gt;A. Yes. It can reside in the system tray and monitor in the background. When it detects something based on your configured rules, it will notify you and output logs.&lt;/p&gt;

&lt;h5&gt;Q3. Can I integrate YAMAGoya with existing SIEMs?&lt;/h5&gt;

&lt;p&gt;A. Yes. YAMAGoya outputs logs as text and to the Event Log (Application). You can import those outputs to SIEMs such as Splunk using log collection agents or forwarding functions.&lt;/p&gt;

&lt;h5&gt;Q4. Are there limitations for countermeasures against ETW bypass (evasion technique)?&lt;/h5&gt;

&lt;p&gt;A. Yes. At present, there is no dedicated measure for ETW bypass. Advanced attackers may disable or compromise ETW to evade detection. We recommend using YAMAGoya together with EDR and other monitoring tools to implement a layered defense.&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>Update on Attacks by Threat Group APT-C-60</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2025/11/APT-C-60_update.html" />
  <id>tag:movabletype.net,2003:post-3091615</id>
  <published>2025-11-05T04:30:00Z</published>
  <updated>2025-11-05T04:31:53Z</updated>
  <summary>In JPCERT/CC Eyes, we previously reporte...</summary>
  <author>
    <name>増渕 維摩(Yuma Masubuchi)</name>
      </author>
  <category term="Malware" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="Incident" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;In JPCERT/CC Eyes, we previously reported on attacks conducted by &lt;a href=&quot;https://blogs.jpcert.or.jp/en/2024/12/APT-C-60.html&quot; target=&quot;_blank&quot;&gt;Attack Exploiting Legitimate Service by APT-C-60&lt;/a&gt;. JPCERT/CC continues to observe similar attack activities in Japan. This report provides an update on the attacks confirmed between June and August 2025, focusing on developments since our last article. The following topics are covered:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Attack flow&lt;/li&gt;
&lt;li&gt;Updates to the downloader and SpyGlace&lt;/li&gt;
&lt;li&gt;SpyGlace encoding functions and communication methods&lt;/li&gt;
&lt;li&gt;Decoy documents used in the attacks&lt;/li&gt;
&lt;li&gt;Analysis of the GitHub repository&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Attack Flow&lt;/h3&gt;

&lt;p&gt;The attacks confirmed by JPCERT/CC were targeted spear-phishing emails sent to recruitment staff, in which the attackers impersonated job seekers. This pattern is closely similar to attacks that occurred around August 2024. Figure 1 shows the flow of the attack. In the previous attacks, victims were directed to download a VHDX file from Google Drive. However, in the latest attacks, the malicious VHDX file was directly attached to the email. When the recipient clicks the LNK file contained within the VHDX, a malicious script is executed via Git, which is a legitimate file.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/aptc60update01-800wri.png&quot; width=&quot;800&quot; height=&quot;449&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3924578 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 1: Flow of malware infection
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;The LNK file executes gcmd.exe (a legitimate Git file), and it runs the script glog.txt stored in the VHDX file. &lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
P:\LICENSES.LOG\mingw64\bin\gcmd.exe &quot;cd .\LICENSES.LOG\mingw64\bin &amp;&amp; type glog.txt | gcmd.exe&quot; &amp;&amp; exit
&lt;/pre&gt;

&lt;p&gt;The script executed by Git is responsible for displaying a decoy document, creating files, and executing those files. The created WebClassUser.dat (hereafter referred to as “Downloader1”) is registered in the registry as shown below, and then it gets persisted and executed through COM hijacking.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
HKCU\Software\Classes\CLSID\{566296fe-e0e8-475f-ba9c-a31ad31620b1}\InProcServer32
&lt;/pre&gt;

&lt;h3&gt;Updates to Downloader1 and Downloader2&lt;/h3&gt;

&lt;p&gt;For attackers to identify compromised devices, Downloader1 periodically communicates with a legitimate statistics service called statcounter. The request headers are created in the following format. Compared to earlier versions, the current one is different in that it identifies compromised machines by their &lt;strong&gt;volume serial number&lt;/strong&gt; and &lt;strong&gt;computer name&lt;/strong&gt;.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
Referer: ONLINE=&gt;[Number1],[Number2] &gt;&gt; [%userprofile%] / [VolumeSerialNumber + ComputerName]
&lt;/pre&gt;

&lt;p&gt;Downloader1 combines a filename derived from the &lt;strong&gt;volume serial number&lt;/strong&gt; and the &lt;strong&gt;computer name&lt;/strong&gt; with a URL embedded in the malware sample to generate a path in the following format, and it is used for communication.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
https://raw.githubusercontent.com/carolab989/class2025/refs/heads/main/[VolumeSerialNumber + ComputerName].txt
&lt;/pre&gt;

&lt;p&gt;The attackers check the referrer value sent to statcounter and then upload a file named &lt;strong&gt;&quot;[VolumeSerialNumber + ComputerName].txt&quot;&lt;/strong&gt; corresponding to the infected device to GitHub. DownLoader1 then retrieves that file from GitHub. Based on the URL in the retrieved file, DownLoader2 is downloaded and executed. In addition to specifying the download URL, the &lt;strong&gt;&quot;[VolumeSerialNumber + ComputerName].txt&quot;&lt;/strong&gt; can execute the following commands in Table 1. For example, the command &lt;strong&gt;&quot;1*&quot;&lt;/strong&gt; can change the interval at which a GET request is sent to statcounter.com from the default of one hour to six hours. Such capability indicates the attackers’ intent to monitor the victim environment more cautiously.&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Table 1: Commands of the downloader
&lt;/div&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Command&lt;/th&gt;
&lt;th&gt;Contents&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&quot;1*&quot;&lt;/td&gt;
&lt;td&gt;Change the interval settings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&quot;0&lt;em&gt;&quot; or &quot;40&lt;/em&gt;&quot;&lt;/td&gt;
&lt;td&gt;Reset the interval settings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&quot;http*&quot;&lt;/td&gt;
&lt;td&gt;Download DLL&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Like earlier versions, the retrieved files are XOR-decoded and then executed using &lt;strong&gt;&quot;sgznqhtgnghvmzxponum&quot;&lt;/strong&gt; as the key. Downloader2 can download and execute SpyGlace and its loader. The malware’s dynamic API resolution uses an encoding scheme based on ADD and XOR. The value has changed from earlier versions, and now &lt;strong&gt;XOR 0x05&lt;/strong&gt; is performed after &lt;strong&gt;add 0x04&lt;/strong&gt;. The SpyGlace loader uses the same encoding scheme. As in earlier versions, files retrieved by Downloader2 are XOR-decoded with the key &lt;strong&gt;&quot;AadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE&quot;&lt;/strong&gt; and then executed by COM hijacking.&lt;/p&gt;

&lt;h3&gt;Updates to SpyGlace&lt;/h3&gt;

&lt;p&gt;JPCERT/CC has observed three versions of SpyGlace: &lt;strong&gt;3.1.12, 3.1.13, and 3.1.14&lt;/strong&gt;. Compared with Version 3.1.6, which was observed by JPCERT/CC in 2024, the previously implemented commands &lt;strong&gt;prockill&lt;/strong&gt; and &lt;strong&gt;proclist&lt;/strong&gt; have been modified to perform no action. JPCERT/CC also confirmed a new command, &lt;strong&gt;uld&lt;/strong&gt;, has been added. The command calls a specific function of a loaded module and then unloads the module two seconds after that. This is possibly intended for modules that must execute a specific function before being unloaded. Additionally, in the screenupload command, the file path and the export function name for what appears to be a screenshot-related module have been changed to those shown below. Since the &lt;strong&gt;Clouds.db&lt;/strong&gt; module itself has not been observed, its functionality is unknown, but it is believed to be related to the screenshot command. For a full list of implemented commands, see Appendix D.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
File path: %LocalAppData%\Microsoft\Windows\Clouds\Clouds.db
Export Function: mssc1
&lt;/pre&gt;

&lt;p&gt;There are slight differences among the observed versions, 3.1.12, 3.1.13, and 3.1.14. However, JPCERT/CC confirmed that the Mutex value is different between them. From version 3.1.14, the automatic execution path has also changed from &lt;strong&gt;%public%\AccountPictures\Default\&lt;/strong&gt; to &lt;strong&gt;%appdata%\Microsoft\SystemCertificates\My\CPLs&lt;/strong&gt;. An article published in September 2025 &lt;a href=&quot;#1&quot;&gt;[1]&lt;/a&gt; describes a campaign in which version 3.1.14 was used, but this is likely a separate campaign observed overseas because the GitHub repositories and other resources used in the campaign do not overlap with those observed by JPCERT/CC.&lt;/p&gt;

&lt;h3&gt;Details of SpyGlace’s Encoding Functions and Communication Methods&lt;/h3&gt;

&lt;p&gt;SpyGlace’s characteristic encoding scheme combines a single-byte XOR with a SUB instruction. This is heavily used for strings the malware employs and for resolving dynamic APIs. The &lt;strong&gt;&quot;Download&quot;&lt;/strong&gt; command, one of SpyGlace’s commands, downloads an encrypted file. The file is decrypted using &lt;strong&gt;AES-128-CBC&lt;/strong&gt; with the KEY and IV shown below and is created to the path &lt;strong&gt;%temp%\wcts66889.tmp&lt;/strong&gt;. Figure 2 shows a part of the Download command code.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
KEY: B0747C82C23359D1342B47A669796989
IV: 21A44712685A8BA42985783B67883999
&lt;/pre&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/aptc60update02-800wri.png&quot; width=&quot;800&quot; height=&quot;598&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3924594 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 2: Part of Download command code
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;SpyGlace communicates with its C2 servers using BASE64 and RC4. The format of the request headers used in the initial communication is shown below. The a001 value contains the userid value &lt;strong&gt;&quot;GOLDBAR&quot;&lt;/strong&gt;, and it is the same string reported by Positive Technologies &lt;a href=&quot;#2&quot;&gt;[2]&lt;/a&gt; and was also used in attacks observed in Japan last year, suggesting that it may indicate the targeted region or a specific campaign. Regarding encoding scheme, SpyGlace has employed a modified &lt;strong&gt;RC4&lt;/strong&gt; since at least version 3.1.6.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
a001=[md5(&quot;GOLDBAR&quot;)]&amp;a002=[md5(systeminfo)]&amp;a003=[&quot;uid&quot; or &quot;info&quot;]&amp;a004=[BASE64(CustomRC4([ComputerName;UserName;CpuInfo;OS Version;SpyGlace Version]))]
&lt;/pre&gt;

&lt;p&gt;The modified RC4 increases the number of KSA cycles and performs additions to the value that is to be XORed. The variant can be decoded with the following Python script.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
import base64

def CustomRC4(key: bytes, data: bytes) -&gt; bytes:
    # --- KSA ---
    S = list(range(256))
    n = 3
    for round in range(n):
        j = 0
        keylen = len(key)
        if keylen == 0:
            raise ValueError(&quot;key must be non-empty&quot;)
        for i in range(256):
            j = (j + S[i] + key[i % keylen]) &amp; 0xFF
            S[i], S[j] = S[j], S[i]

    # --- PRGA ---
    i = j = 0
    out = []
    for b in data:
        i = (i + 1) &amp; 0xFF
        j = (j + S[i]) &amp; 0xFF
        k = S[(S[i] + j) &amp; 0xFF]
        S[i], S[j] = S[j], S[i]
        k2 = S[((S[((i &gt;&gt; 3) ^ (0x20 * j)) &amp; 0xFF] + S[((0x20 * i) ^ (j &gt;&gt; 3)) &amp; 0xFF]) ^ 0xAA) &amp; 0xFF] + S[(S[j] + S[i]) &amp; 0xFF]
        out.append( (b ^ k ^ k2) &amp; 0xFF )
    return bytes(out)


def decode(base64in):
    key = b&quot;90b149c69b149c4b99c04d1dc9b940b9&quot;
    decoded = CustomRC4(key, base64.b64decode(base64in))
    print(&quot;Result: &quot;, decoded)
&lt;/pre&gt;

&lt;h3&gt;Decoy Document Used&lt;/h3&gt;

&lt;p&gt;Figure 3 shows a part of the decoy document used in this campaign. Because the attackers targeted recruitment officers, the fabricated resume disguise the writer as a researcher and list multiple academic papers in the CV. However, the authors of those papers do not include the name of the email sender. The name on the resume partially matches the Gmail account name used by the sender, suggesting that the attackers may have created the account specifically for this attack.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/aptc60update03-800wri.png&quot; width=&quot;800&quot; height=&quot;1034&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3924604 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 3: Part of the used decoy document
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;h3&gt;Analysis of GitHub Repositories&lt;/h3&gt;

&lt;p&gt;Because the attackers use GitHub to distribute their payloads, all payloads distributed in the past can be retrieved unless the repository is deleted. Table 2 shows the uploaded SpyGlace versions and the periods during which they were available on GitHub.&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Table 2: Upload dates of each SpyGlace version on GitHub
&lt;/div&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;SpyGlace Version&lt;/th&gt;
&lt;th&gt;Upload Date &amp;amp; Time&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Version 3.1.12&lt;/td&gt;
&lt;td&gt;Fri Jun 27 14:33:28 2025 +0900&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Version 3.1.13&lt;/td&gt;
&lt;td&gt;Thu Jul 3 18:25:18 2025 +0900&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Version 3.1.14&lt;/td&gt;
&lt;td&gt;Wed Jul 16 15:03:52 2025 +0900&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;table&gt;&lt;/p&gt;

&lt;p&gt;JPCERT/CC has identified email addresses recorded in the commit logs of the GitHub repository managed by the attackers, as well as information on compromised devices composed of their &lt;strong&gt;volume serial numbers&lt;/strong&gt; and &lt;strong&gt;computer names&lt;/strong&gt;. The details are provided for reference in Appendices E and F.&lt;/p&gt;

&lt;h2&gt;In Closing&lt;/h2&gt;

&lt;p&gt;As with previous cases, attacks by APT-C-60 continue to primarily target Japan and other East Asian regions. While several changes have been identified, such as a shift in infrastructure from Bitbucket to GitHub and updates to the malware itself, many characteristics remain consistent, including the abuse of legitimate services and the behavior of the malware. JPCERT/CC recommends remaining alerted to this threat. C2 and hash values of the confirmed malware are listed in the Appendix. Please note that the C2 information includes legitimate services.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Yuma Masubuchi (Translated by Takumi Nakano)&lt;/p&gt;

&lt;h4&gt;References&lt;/h4&gt;

&lt;p&gt;&lt;a name=&quot;1&quot;&gt;&lt;/a&gt;[1] Sangfor
【高级威胁追踪(APT)】深入分析“伪猎者”组织Github仓库加密载荷
    &lt;a href=&quot;https://mp.weixin.qq.com/s/A1UhFfqnGRLsEZywvaQA4A&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://mp.weixin.qq.com/s/A1UhFfqnGRLsEZywvaQA4A&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;2&quot;&gt;&lt;/a&gt;[2] Positive Technologies
DarkHotel. A cluster of groups united by common techniques
    &lt;a href=&quot;https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/darkhotel-a-cluster-of-groups-united-by-common-techniques/&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/darkhotel-a-cluster-of-groups-united-by-common-techniques/&lt;/a&gt;&lt;/p&gt;

&lt;h4&gt;Appendix A: IoC Network&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;https[:]//c.statcounter[.]com/13139439/0/1ba1a548/1/&lt;/li&gt;
&lt;li&gt;https[:]//raw.githubusercontent[.]com/carolab989/class2025//refs/heads/main/&lt;/li&gt;
&lt;li&gt;https[:]//raw.githubusercontent[.]com/football2025/class2025//refs/heads/main/&lt;/li&gt;
&lt;li&gt;https[:]//raw.githubusercontent[.]com/fenchiuwu/class2025/refs/heads/main/&lt;/li&gt;
&lt;li&gt;http[:]//raw.githubusercontent[.]com/Ridgley22387/r834829jf/refs/heads/main/datapages.txt&lt;/li&gt;
&lt;li&gt;http[:]//raw.githubusercontent[.]com/Ridgley22387/r834829jf/refs/heads/main/datautils.txt&lt;/li&gt;
&lt;li&gt;https[:]//bitbucket[.]org/clouds999/glo29839/downloads/&lt;/li&gt;
&lt;li&gt;https[:]//raw.githubusercontent[.]com/goldbars33/ozbdkak33/refs/heads/main/&lt;/li&gt;
&lt;li&gt;https[:]//185.181.230[.]71/wkdo9/4b3ru.asp&lt;/li&gt;
&lt;li&gt;https[:]//185.181.230[.]71/wkdo9/t1802.asp&lt;/li&gt;
&lt;li&gt;https[:]//185.181.230[.]71/wkdo9/n3tb4.asp&lt;/li&gt;
&lt;li&gt;https[:]//185.181.230[.]71/wkdo9/2qpmk.asp&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Appendix B: IoC File&lt;/h4&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Table 3: List of IoC Files
&lt;/div&gt;

&lt;table style=&quot;table-layout: fixed; width: 100%;&quot;&gt;
&lt;colgroup&gt;
  &lt;col style=&quot;width: 20%;&quot;&gt;
  &lt;col style=&quot;width: 20%;&quot;&gt;
  &lt;col style=&quot;width: 60%;&quot;&gt;
&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Content&lt;/th&gt;
&lt;th&gt;Filename&lt;/th&gt;
&lt;th&gt;Hash(SHA256)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Malicious VHDX&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CV &amp;amp; Professional Experience.vhdx&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;f42d0fa77e5101f0f793e055cb963b45b36536b1835b9ea8864b4283b21bb68f&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Malicious LNK&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Resume.rtf.lnk&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;25f81709d914a0981716e1afba6b8b5b3163602037d466a02bc1ec97cdc2063b&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Part of Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;wic60.ds&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ea37dfa94a63689c1195566aab3d626794adaab4d040d473d4dfbd36f1e5f237&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Part of Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;wic400.ds&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;a80848cf7d42e444b7ec1161c479b1d51167893f47d202b05f590ad24bf47942&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Part of Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;wic900.ds&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;1e931c8aa00b7f2b3adedc5260a3b69d1ac914fe1c022db072ed45d7b2dddf6c&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Dropper Script&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;glog.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;c9c6960a5e6f44afda4cc01ff192d84d59c4b31f304d2aeba0ef01ae04ca7df3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;WebClassUser.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;f102d490ad02b1588b9b76664cd715c315eaab33ac22b5d0812c092676242b15&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;DownLoader2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;WebCacheR.tmp.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;57a77d8d21ef6a3458763293dbe3130dae2615a5de75cbbdf17bc61785ee79da&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;DownLoader2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;WebCacheR.tmp.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;9e30df1844300032931e569b256f1a8a906a46c6a7efa960d95142d6bea05941&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;git.exe(Legitimate)&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;gcmd.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;96312254d33241ce276afc7d7e0c7da648ffe33f3b91b6e4a1810f0086df3dba&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;SpyGlace version 1.3.12&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;datautils.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;669c268e4e1ced22113e5561a7d414a76fcd247189ed87a8f89fbbd61520966a&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;SpyGlace version 1.3.13&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;datautils.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;f96557e8d714aa9bac8c3f112294bac28ebc81ea52775c4b8604352bbb8986b8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;SpyGlace version 1.3.14&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;datautils.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;8b51939700c65f3cb7ccdc5ef63dba6ca5953ab5d3c255ce3ceb657e7f5bfae8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;SpyGlace Loader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;datapages.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;d535837fe4e5302f73b781173346fc9031d60019ea65a0e1e92e20e399a2f387&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;SpyGlace Loader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;datapages.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;6d8a935f11665850c45f53dc1a3fc0b4ac9629211bd4281a4ec4343f8fa02004&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Downloader2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;coninst3110.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;d287dc5264fd504b016ec7e424650e2b353946cbf14d3b285ca37d78a6fda6f4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Loader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;constart3110.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;10278a46b13797269fd79a5f8f0bc14ff1cc5bc0ea87cdd1bbc8670c464a3cf1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ingredient.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;156df8c8bea005bd7dc49eb7aca230ef85ada1c092e45bb3d69913d78c4fa1f9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Loader Scrpt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;UsrClass.sct&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;7ae86f2cb0bbe344b3102d22ecfcdda889608e103e69ec92932b437674ad5d2f&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Loader Scrpt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;UsrClass.sct&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;e8b3b14a998ce3640a985b4559c90c31a5d7465bc5be5c6962e487172d3c9094&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Loader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;intersection.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;09fcc1dfe973a4dc91582d7a23265c0fd8fc2a011adb2528887c1e1d3a89075a&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Downloader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;opinsfile.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;048b69386410b8b7ddb7835721de0cba5945ee026a9134d425e0ba0662d9aee4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Loader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;constafile.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;f495171e7a10fb0b45d28a5260782a8c1f7080bd1173af405476e8d3b11b21b6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Downloader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;coninsfile.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;8ea32792c1624a928e60334b715d11262ed2975fe921c5de7f4fac89f8bb2de5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Malicious VHDX&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CV &amp;amp; Professional Experience.vhdx&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;94ccdaf238a42fcc3af9ed1cae1358c05c04a8fa77011331d75825c8ac16ffd8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Dropper Script&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;volumelog.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;299d792c8d0d38d13af68a2467186b2f47a1834c6f2041666adafc626149edaf&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Part of Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;vol60.dot&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ea37dfa94a63689c1195566aab3d626794adaab4d040d473d4dfbd36f1e5f237&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Part of Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;vol400.dot&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;94f6406a0f40fb8d84ceafaf831f20482700ee1a92f6bca1f769dff98896245c&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Part of Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;vol900.dot&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;45c1c79064cef01b85f0a62dac368e870e8ac3023bfbb772ec6d226993dc0f87&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Downloader1&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;UsrClassCache.dat&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;50b40556aa7461566661d6a8b9486e5829680951b5df5b7584e0ab58f8a7e92f&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Malicious LNK&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Resume.rtf.lnk&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;5da82fa87b0073de56f2b20169fa4d6ea610ed9c079def6990f4878d020c9d95&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h4&gt;Appendix C: Other IoC&lt;/h4&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Table 4: Other IoC
&lt;/div&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Content&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Mutex&lt;/td&gt;
&lt;td&gt;K31610KIO9834PG79A90B&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mutex&lt;/td&gt;
&lt;td&gt;K31610KIO9834PG79AD7B&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mutex&lt;/td&gt;
&lt;td&gt;K31610KIO9834PG79A44A&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CLASSID&lt;/td&gt;
&lt;td&gt;{566296fe-e0e8-475f-ba9c-a31ad31620b1}&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CLASSID&lt;/td&gt;
&lt;td&gt;{64B8F404-A4AE-11D1-B7B6-00C04FB926AF}&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%userprofile%\AppData\Local\Microsoft\Windows\WebClassUser.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%localappdata%\Microsoft\Windows\WebCache\WebCacheR.tmp.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%userprofile%ppdata\local\Microsoft\GameDVR\data\GameList.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%userprofile%ppdata\local\Microsoft\GameDVR\data\DataCache.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%temp%\wcts66889.tmp&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%localappdata%\Microsoft\Windows\UsrClassCache.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%localappdata%\Microsoft\Windows\UsrClassLib.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%userprofile%ppdata\local\Microsoft\Edge\cache\Config.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%userprofile%ppdata\Local\Microsoft\Windows\UsrClassCache.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File path&lt;/td&gt;
&lt;td&gt;%userprofile%ppdata\local\Microsoft\Edge\cache\Cache.dat&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h4&gt;Appendix D: Commands&lt;/h4&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Table 5: List of SpyGlace commands
&lt;/div&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Command&lt;/th&gt;
&lt;th&gt;Contents&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;turn on&lt;/td&gt;
&lt;td&gt;Change the interval settings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;turn off&lt;/td&gt;
&lt;td&gt;Reset the interval settings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;cd&lt;/td&gt;
&lt;td&gt;Change directory&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ddir&lt;/td&gt;
&lt;td&gt;List of the files in the directory&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ddel&lt;/td&gt;
&lt;td&gt;Delete file and directory&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ld&lt;/td&gt;
&lt;td&gt;Load module&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;uld&lt;/td&gt;
&lt;td&gt;unload module&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;attach&lt;/td&gt;
&lt;td&gt;Start module&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;detach&lt;/td&gt;
&lt;td&gt;Stop module&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;procspawn&lt;/td&gt;
&lt;td&gt;Start process&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;prockill&lt;/td&gt;
&lt;td&gt;None&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;proclist&lt;/td&gt;
&lt;td&gt;None&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diskinfo&lt;/td&gt;
&lt;td&gt;Get disk information&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;download&lt;/td&gt;
&lt;td&gt;Download encrypted file&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;downfree&lt;/td&gt;
&lt;td&gt;Download file&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;cancel&lt;/td&gt;
&lt;td&gt;Remote shell&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;screenupload&lt;/td&gt;
&lt;td&gt;Upload screenshot&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;screenauto&lt;/td&gt;
&lt;td&gt;Upload screenshot automatically&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;upload&lt;/td&gt;
&lt;td&gt;Upload file&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h4&gt;Appendix E: Email address used for the commit&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
kithatart@outlook.com
magnolia099@163.com
carolab989@proton.me
fenchiuwu@proton.me
Ridgley223870@proton.me
&lt;/pre&gt;

&lt;h4&gt;Appendix F: Victimized devices identified from the GitHub repository&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
1014988494f04da28046ba
1020301627MBE4OSU
2096821130DESKTOP-BN9A2SA
2958455713DESKTOP-NKVAKV1
4205732935******(Names have been masked as they may contain personal information)
3761538073DESKTOP-PVKDUAM
3537034124JKS
3472318429******(Names have been masked as they may contain personal information)
1620260207DESKTOP-6LO36DE
1347261043DESKTOP-0V7K7HA
2352730816DESKTOP-4QC5J5Q
3362573326DESKTOP-43R2GH0
&lt;/pre&gt;

    

  </content>
</entry>
<entry>
  <title>TSUBAME Report Overflow (Apr-Jun 2025)</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2025/10/tsubame_overflow_2025-04-06.html" />
  <id>tag:movabletype.net,2003:post-3088004</id>
  <published>2025-10-28T05:00:00Z</published>
  <updated>2025-10-28T05:00:23Z</updated>
  <summary>This TSUBAME Report Overflow series discuss monitoring trends of overseas TSUBAME sensors and other activities which the Internet Threat Monitoring Quarterly Reports do not include. This article covers the monitoring results for the period April to June 2025. Fluctuations in...</summary>
  <author>
    <name>鹿野 恵祐 (Keisuke Shikano)</name>
    <uri>https://www.jpcert.or.jp/</uri>  </author>
  <category term="Cyber Metrics" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="TSUBAME" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;This TSUBAME Report Overflow series discuss monitoring trends of overseas TSUBAME sensors and other activities which the Internet Threat Monitoring Quarterly Reports do not include. This article covers the monitoring results for the period April to June 2025.&lt;/p&gt;

&lt;h3&gt;Fluctuations in packets from Iran, potentially linked to Israel-Iran military conflict&lt;/h3&gt;

&lt;p&gt;Between June 13 and around June 25, 2025, military conflict occurred between Israel and Iran. During this period, fluctuations were observed in packets originating from Iran. This section focuses on these changes.
Figure 1 shows the number of unique IP addresses per day originating from Iran and Israel during June.&lt;/p&gt;

&lt;table style=&quot;border-collapse: collapse; width: 110.24%; height: 36px;&quot; border=&quot;1&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q1blogfig1e.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q1blogfig1e.png&quot; width=&quot;1179&quot; height=&quot;577&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3918449&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 1: Trends in the number of IP addresses from Israel and Iran &lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;The number of IP addresses associated with packets originating from Iran typically ranged between 170 and 200 every day. However, from around June 13 to June 18, this number dropped to approximately 100 to 130. A more significant decrease was observed from June 19 to June 27, when the number temporarily dropped to between 20 and 100. In contrast, the number of IP addresses originating from Israel showed no notable changes during the same period. Some media sources reported that, around June 18, cyber attacks targeted Iran’s state broadcaster, banks, and cryptocurrency exchanges. It was also reported that the Iranian government temporarily restricted Internet connectivity to mitigate the impact of these attacks, and the decline in the number of source IP addresses was likely due to this disruption.&lt;/p&gt;

&lt;h3&gt;Comparison of the observation trends in Japan and overseas&lt;/h3&gt;

&lt;p&gt;Figure 2 is a monthly comparison of the average number of packets received in Japan and overseas. While overseas sensors received more packets than those in Japan, both of them recorded the highest number in April, with a gradual decrease in the following months.&lt;/p&gt;

&lt;table style=&quot;border-collapse: collapse; width: 110.24%; height: 36px;&quot; border=&quot;1&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 50%; height: 18px;&quot;&gt;
&lt;a class=&quot;mt-asset-link&quot; href=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q1blogfig2e.png&quot;&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/2025q1blogfig2e.png&quot; width=&quot;1153&quot; height=&quot;573&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3918475&quot; style=&quot;display: block;&quot;/&gt;&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 18px;&quot;&gt;
&lt;td style=&quot;width: 48.0795%; height: 18px; text-align: center;&quot;&gt;Figure 2: Monthly comparison of the average number of packets received in Japan and overseas&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt; Comparison of monitoring trends by sensor &lt;/h3&gt;

&lt;p&gt;A global IP address is assigned to each TSUBAME sensor. Table 1 shows the top 10 ports of each sensor which received packets the most. Although the order is different in each sensor, almost all the sensors observed the packets for 22/TCP, 23/TCP, 80/TCP, 443/TCP, and 8080/TCP. This suggests that these protocols are being scanned in a wide range of networks.&lt;/p&gt;

&lt;p style=&quot;text-align: center;&quot;&gt;Table 1: Comparison of top 10 packets by domestic and overseas sensors &lt;/p&gt;

&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;th&gt;&lt;/th&gt;&lt;th&gt;Japan #1&lt;/th&gt;&lt;th&gt;Japan #2&lt;/th&gt;&lt;th&gt;North America #1&lt;/th&gt;&lt;th&gt;North America #2&lt;/th&gt;&lt;th&gt;Europe #1&lt;/th&gt;&lt;th&gt;Europe #2&lt;/th&gt;&lt;th&gt;Other regions #1&lt;/th&gt;&lt;th&gt;Other regions #2&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#1&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#2&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#3&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#4&lt;/td&gt;&lt;td&gt;8443/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;23/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;80/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#5&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;8728/TCP&lt;/td&gt;&lt;td&gt;34567/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#6&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;22/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#7&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;ICMP&lt;/td&gt;&lt;td&gt;443/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#8&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#9&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;1433/TCP&lt;/td&gt;&lt;td&gt;8080/TCP&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;td&gt;5555/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td align=&quot;right&quot;&gt;#10&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;3389/TCP&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;81/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;445/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;td&gt;6379/TCP&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h3&gt;In closing&lt;/h3&gt;

&lt;p&gt;Monitoring at multiple locations enables us to determine if certain changes are occurring only in a particular network. Although we have not published any special alerts as an extra issue or other information this quarter, it is important to pay attention to scanners. We will continue to publish blog articles as the Internet Threat Monitoring Quarterly Report becomes available every quarter. We will also publish an extra issue when we observe any unusual change. Your feedback on this series is much appreciated. Please use the comment form below to let us know which topic you would like us to introduce or discuss further. Thank you for reading.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Keisuke Shikano&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;(Translated by Takumi Nakano)&lt;/p&gt;

    

  </content>
</entry>
<entry>
  <title>CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks</title>
  <link rel="alternate" type="text/html" href="https://blogs.jpcert.or.jp/en/2025/08/crossc2.html" />
  <id>tag:movabletype.net,2003:post-3039885</id>
  <published>2025-08-14T05:00:00Z</published>
  <updated>2025-08-14T05:00:00Z</updated>
  <summary>From September to December 2024, JPCERT/CC has confirmed incidents involving CrossC2, the extension tool to create Cobalt Strike Beacon for Linux OS. The attacker employed CrossC2 as well as other tools such as PsExec, Plink, and Cobalt Strike in attempts...</summary>
  <author>
    <name>増渕 維摩(Yuma Masubuchi)</name>
      </author>
  <category term="Malware" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="Incident" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="Tags" scheme="http://www.sixapart.com/ns/types#category" />
  <category term="Tool" scheme="http://www.sixapart.com/ns/types#category" />
    <content type="html" xml:lang="en-US" xml:base="https://blogs.jpcert.or.jp/en/">
    &lt;p&gt;From September to December 2024, JPCERT/CC has confirmed incidents involving CrossC2, the extension tool to create Cobalt Strike Beacon for Linux OS. The attacker employed CrossC2 as well as other tools such as PsExec, Plink, and Cobalt Strike in attempts to penetrate AD. Further investigation revealed that the attacker used custom malware (hereafter referred to as &lt;strong&gt;&quot;ReadNimeLoader&quot;&lt;/strong&gt;) as a loader for Cobalt Strike. Information submitted to VirusTotal suggests that this attack campaign may have been observed across multiple countries, not only in Japan. 
This article explains CrossC2 and Cobalt Strike, the malware used in the campaign, as well as other tools employed by the attacker. A tool released by JPCERT/CC to support the analysis of CrossC2 is also introduced at the end.&lt;/p&gt;

&lt;h3&gt;CrossC2&lt;/h3&gt;

&lt;p&gt;CrossC2 is an unofficial Beacon and builder compatible with Cobalt Strike version 4.1 and above, developed in C language. It is designed to operate on Linux (x86, x64) and macOS (x86, x64, M1) architectures. While the builder is publicly available on GitHub&lt;a href=&quot;#1&quot;&gt;[1]&lt;/a&gt;, allowing users to create Beacons, the source code for both the builder and the Beacon are not released.&lt;/p&gt;

&lt;p&gt;Upon execution, CrossC2 immediately forks itself, and the main processing is carried out in the child process. The C2 information is retrieved from the configuration, while the C2 server host and port number can also be obtained from the environment variables &lt;strong&gt;&quot;CCHOST&quot;&lt;/strong&gt; and &lt;strong&gt;&quot;CCPORT&quot;&lt;/strong&gt;. Once executed, CrossC2 is capable of executing various Cobalt Strike commands after establishing communication with the Cobalt Strike TeamServer. However, the range of executable commands is limited compared to the full functionality of standard Cobalt Strike. The Beacon contains the following multiple anti-analysis features:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;String encoding using single-byte XOR&lt;/li&gt;
&lt;li&gt;Insertion of a large amount of junk code&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Figure 1 shows a part of the inserted junk code. A significant amount of such code is embedded in key functions. However, the obfuscation can be easily removed by replacing the following byte sequence with NOP instruction.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
8B 85 ?? ?? ?? ?? 2D ?? ?? ?? ?? 89 85 ?? ?? ?? ?? 0F 84 ?? ?? ?? ?? E9 00 00 00 00
&lt;/pre&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/LinuxCS01-800wri.png&quot; width=&quot;800&quot; height=&quot;912&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3835191 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 1: A part of obfuscated code in CrossC2
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;The configuration data is stored at the end of the file. CrossC2 first retrieves its own file path using the readlink function and then fread its own code. It keeps searching for the string &lt;strong&gt;&quot;HOOK&quot;&lt;/strong&gt; to locate the address of the configuration data. The structure of the configuration is as shown below. The encrypted configuration data can be decrypted using &lt;strong&gt;AES128-CBC(no padding)&lt;/strong&gt;. CrossC2 uses OpenSSL library functions to perform the decryption.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
0x0: &quot;HOOK&quot; search tag
0x4: Size of the configuration data
0x8: Encrypted configuration data
&lt;/pre&gt;

&lt;p&gt;CrossC2 can create Beacon using legitimate TeamServer extensions. By default, the generated Beacon is packed with UPX, but attempting to unpack it with UPX fails due to the configuration information at the end of the file. To unpack the Beacon successfully, the configuration block must first be removed. After unpacking using UPX, the configuration block needs to be reinserted at the end.&lt;/p&gt;

&lt;h3&gt;Cobalt Strike&lt;/h3&gt;

&lt;p&gt;Figure 2 illustrates the flow of Cobalt Strike execution. The process is initiated by a legitimate java.exe file, which is executed from a Task Scheduler job registered by the attacker. This java.exe loads jli.dll through DLL sideloading. The DLL file is ReadNimeLoader, which is written in Nim language. ReadNimeLoader reads a data file named readme.txt from the same directory, decrypts it, and executes its content in memory. This file contains OdinLdr&lt;a href=&quot;#2&quot;&gt;[2]&lt;/a&gt;, an open-source Shellcode-format loader, which decodes the embedded Cobalt Strike Beacon and executes it in memory. All related files, including ReadNimeLoader, were located under &lt;strong&gt;&quot;C:\$recycle.bin\&quot;&lt;/strong&gt; on the affected system. In addition, some ReadNimeLoader samples were found to contain the following PDB path.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
D:\BuildServer\bna-4\work-git\phoenix-repository\phoenix\Release\Battle.net Launcher.exe.pdb
&lt;/pre&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/LinuxCS02-800wri.png&quot; width=&quot;800&quot; height=&quot;337&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3835192 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 2: Flow of Cobalt Strike execution
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;h4&gt;ReadNimeLoader&lt;/h4&gt;

&lt;p&gt;ReadNimeLoader incorporates the following four anti-analysis techniques:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Detect debugging by checking BeingDebugged value in PEB&lt;/li&gt;
&lt;li&gt;Detect debugging by checking CONTEXT_DEBUG_REGISTER value&lt;/li&gt;
&lt;li&gt;Measure the difference of elapsed time and proceed to debag checking when the value exceeds 0x512&lt;/li&gt;
&lt;li&gt;Detect debugging by causing an exception and checking whether an exception handler is obtained&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A part of the decryption key required to decode OdinLdr is embedded within the functions for the abovementioned anti-analysis techniques. As a result, unless these functions are executed, the correct decryption key is not generated, and OdinLdr cannot be decrypted. In addition to these anti-analysis mechanisms, a large amount of junk code is also inserted. Figure 3 shows a part of the code.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/LinuxCS03-640wri.png&quot; width=&quot;640&quot; height=&quot;629&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3835193 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 3: A part of junk code
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;Strings used by ReadNimeLoader are encoded, and they are decoded using two distinct XOR-based decoding functions. Figure 4 shows a portion of each code.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/LinuxCS04-800wri.png&quot; width=&quot;800&quot; height=&quot;370&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3835194 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 4: Each decoding function
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;The encoded strings can be decoded using the Python script shown below. In earlier versions of ReadNimeLoader do not contain the decode02 function, indicating that it was added in a later version.&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
def BYTE1(in_data):
    return (in_data &gt;&gt; 8) &amp; 0xff


def BYTE2(in_data):
    return (in_data &gt;&gt; 16) &amp; 0xff


def BYTE3(in_data):
    return (in_data &gt;&gt; 24) &amp; 0xff


def decode02(enc_bytes, xor_key):
    result = []
    for enc_byte in enc_bytes:
        enc_byte ^= BYTE3(xor_key) &amp; 0xEE ^ BYTE2(xor_key) &amp; 0xEE ^ (xor_key ^ BYTE1(xor_key)) &amp; 0xEE
        result.append(i)
        enc_byte += 1
    return result


def decode01(enc_bytes, xor_key):
    xor_table = [ 0, 8, 0x10, 0x18]
    result = []
    for enc_byte in enc_bytes:
        for j in range(4):
            enc_byte ^= ((xor_key &gt;&gt; xor_table[j]) &amp; 0xEE)
        result.append(i)
    return result
&lt;/pre&gt;

&lt;p&gt;ReadNimeLoader uses &lt;strong&gt;AES256-ECB&lt;/strong&gt; mode to decrypt the malware payload. The key is created by combining specific strings decoded by the aforementioned decoding functions, which is then converted into hexadecimal format, transformed to uppercase, and zero-padded. This decryption can be performed using the following Python script:&lt;/p&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
from Crypto.Cipher import AES
import binascii

def ZeroPadding(hexstr, num):
    padding_num = num - len(hexstr)
    if padding_num &lt; 0:
        return hexstr
    return  hexstr + b&quot;\x00&quot; * padding_num


def decrypt(readme_data, key_string):
    capitalized_key = binascii.hexlify(ascii_to_bytes(key_string)).upper()
    key = ZeroPadding(capitalized_key, 32)
    Cipher = AES.new(key, AES.MODE_ECB)
    return Cipher.decrypt(readme_data)
&lt;/pre&gt;

&lt;h4&gt;OdinLdr&lt;/h4&gt;

&lt;p&gt;After execution, OdinLdr decrypts the internally encoded Cobalt Strike Beacon and runs it in memory. To avoid detection, the Beacon is periodically re-encrypted using a randomly generated XOR key and stored in newly allocated heap memory. It is a distinctive characteristic that there is the string &lt;strong&gt;&quot;OdinLdr1337&quot;&lt;/strong&gt; at the beginning of the heap memory. Additionally, it has been confirmed that there are two types of Shellcode deployed by ReadNimeLoader: some samples execute the Cobalt Strike Beacon through OdinLdr, while others run the Beacon directly. 
Appendix B outlines the relations between ReadNimeLoader versions and their corresponding decryption keys, the specific readme.txt files loaded, and the encoded malware payloads. A part of the Cobalt Strike configuration used is included in the appendix.&lt;/p&gt;

&lt;h3&gt;Tools used by the attacker&lt;/h3&gt;

&lt;p&gt;Among the tools used by the attacker, multiple ELF versions of SystemBC were identified. For more information on the differences from the Windows version of SystemBC, please refer to the report by ANY.RUN &lt;a href=&quot;#3&quot;&gt;[3]&lt;/a&gt;. Other confirmed tools include PsExec, commonly used for lateral movement; GetNPUsers &lt;a href=&quot;#4&quot;&gt;[4]&lt;/a&gt;, often leveraged in AS-REP Roasting attacks; Plink, an SSH client tool; and privilege escalation tools for Windows systems.&lt;/p&gt;

&lt;h3&gt;Attribution&lt;/h3&gt;

&lt;p&gt;Despite architectural differences, confirmed identical characteristics suggest that this attacker and the attack campaign have a potential connection to BlackBasta.  More specifically, the domain confirmed to be used for the C2 in this campaign matches the one listed in Rapid7’s report on BlackBasta &lt;a href=&quot;#5&quot;&gt;[5]&lt;/a&gt;. Further similarities include the use of the files named jli.dll and readme.txt. Additionally, SystemBC was leveraged, and when attacking AD, AS-REP was also used.&lt;/p&gt;

&lt;h3&gt;Tools for analyzing CrossC2&lt;/h3&gt;

&lt;p&gt;As an analysis tools for CrossC2, a configuration parser is publicly available on JPCERT/CC’s GitHub.&lt;/p&gt;

&lt;p&gt;GitHub: JPCERTCC/aa-tools/parse_crossc2beacon_config.py &lt;br /&gt;
&lt;a href=&quot;https://github.com/JPCERTCC/aa-tools/blob/master/parse_crossc2beacon_config.py&quot; target=&quot;_blank&quot;&gt;https://github.com/JPCERTCC/aa-tools/blob/master/parse_crossc2beacon_config.py&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;CrossC2 can generate binaries for macOS, not only for Linux, and this parser is designed to support macOS binaries as well. Figure 5 shows a sample output from running the configuration parser.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://blogs.jpcert.or.jp/en/.assets/thumbnail/LinuxCS05-800wri.png&quot; width=&quot;800&quot; height=&quot;689&quot; alt=&quot;&quot; class=&quot;asset asset-image at-xid-3835195 mt-image-center&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot;/&gt;&lt;/p&gt;

&lt;div style=&quot;text-align: center;&quot;&gt;
Figure 5: Sample output of the configuration parser
&lt;/div&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;

&lt;h3&gt;In Closing&lt;/h3&gt;

&lt;p&gt;While there are numerous incidents involving Cobalt Strike, this article focused on the particular case in which CrossC2, a tool that extends Cobalt Strike Beacon functionality to multiple platforms, was used in attacks, compromising Linux servers within an internal network. Many Linux servers do not have EDR or similar systems installed, making them potential entry points for further compromise, and thus more attention is required. We hope the information provided in this article will be useful to you in incident response and malware analysis. For details on confirmed C2 servers and malware hash values, please refer to the Appendix.&lt;/p&gt;

&lt;p style=&quot;text-align: right&quot;&gt;Yuma Masubuchi (Translated by Takumi Nakano)
&lt;/p&gt;

&lt;h4&gt;References&lt;/h4&gt;

&lt;p&gt;&lt;a name=&quot;1&quot;&gt;&lt;/a&gt;[1] CrossC2
    &lt;a href=&quot;https://github.com/gloxec/CrossC2&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://github.com/gloxec/CrossC2&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;2&quot;&gt;&lt;/a&gt;[2] OdinLdr
    &lt;a href=&quot;https://github.com/emdnaia/OdinLdr&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://github.com/emdnaia/OdinLdr&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;3&quot;&gt;&lt;/a&gt;[3] ANY.RUN&lt;br&gt;
A new SystemBC RAT is targeting Linux-based platforms
    &lt;a href=&quot;https://x.com/anyrun_app/status/1884207667058463188&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://x.com/anyrun_app/status/1884207667058463188&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;4&quot;&gt;&lt;/a&gt;[4] GetNPUsers.py
    &lt;a href=&quot;https://github.com/fortra/impacket/blob/master/examples/GetNPUsers.py&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://github.com/fortra/impacket/blob/master/examples/GetNPUsers.py&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a name=&quot;5&quot;&gt;&lt;/a&gt;[5] Rapid7&lt;br&gt;
    BlackSuit Continues Social Engineering Attacks in Wake of Black Basta’s Internal Conflict
    &lt;a href=&quot;https://www.rapid7.com/blog/post/2025/06/10/blacksuit-continues-social-engineering-attacks-in-wake-of-black-bastas-internal-conflict/&quot; target=&quot;_blank&quot;&gt;&lt;br&gt;https://www.rapid7.com/blog/post/2025/06/10/blacksuit-continues-social-engineering-attacks-in-wake-of-black-bastas-internal-conflict/&lt;/a&gt;&lt;/p&gt;

&lt;h4&gt;Appendix A: Example of CrossC2 configuration&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
C2: 162.33.179[.]247:8443
PUBLICKEY: 
-----BEGIN PUBLIC KEY-----
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCaW
34Iv7znqVuomjiJn4Yr1ck9YSWylfAoiy20DnR0ab
CoHtdPK3L05CgOjnLGSfM5Vji0IRd8xtCGpU699Jt
FCa/Jg7zmuejilkKTFpMB36+49UQtaYp4KjFuImRC
z72NdzszsLzHDlVWAPmn5CSTfsTIzceomQfmCDY//
IygzQIDAQAB
-----END PUBLIC KEY-----
&lt;/pre&gt;

&lt;h4&gt;Appendix B: The relations between ReadNimeLoader and malware payloads&lt;/h4&gt;

&lt;p&gt;Table 1: The relations between ReadNimeLoader and malware payloads &lt;/p&gt;

&lt;table style=&quot;table-layout: fixed; width: 100%;&quot;&gt;
&lt;colgroup&gt;
  &lt;col style=&quot;width: 24%;&quot;&gt;
  &lt;col style=&quot;width: 9%;&quot;&gt;
  &lt;col style=&quot;width: 30%;&quot;&gt;
  &lt;col style=&quot;width: 24%;&quot;&gt;
  &lt;col style=&quot;width: 13%;&quot;&gt;
&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;ReadNimeLoader Hash(SHA256)&lt;/th&gt;
&lt;th&gt;Version&lt;/th&gt;
&lt;th&gt;Key&lt;/th&gt;
&lt;th&gt;readme.txt Hash(SHA256)&lt;/th&gt;
&lt;th&gt;Encoded Malware&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;56b941f6dcb769ae6d6995412559012abab830f05d5d8acf2648f7fa48c20833&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;New&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;mfzuyqroasv&quot;)) + zero padding&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;6246fb5c8b714707ac49ade53e6fe5017d96442db393b1c0ba964698ae24245d&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;OdinLdr + CobaltStrike&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;dfe79b9c57cfb9fc10597b43af1c0a798991b6ceeec2af9b1e0ed46e6a8661c8&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;New&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;vbewtdsmmswfweoz&quot;))&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;acdf2a87ed03f2c6fe1d9899e8a74e8b56f7b77bb8aed5adf2cc374ee5465168&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;OdinLdr + CobaltStrike&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;3f96b6589996e57abc1c4d9b732528d2d11dea5c814f8241170c14ca2cd0281d&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;New&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;lgehaoevolq&quot;)) + zero padding&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;6b80d602472c76b1d0f05bcce62e0a34de758232d9d570ba61b540784c663c01&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CobaltStrike&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;0ab709728666f8759ad8db574d4009cf74ebce36ef2572ef52b058997a9b2a25&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;New&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;ffjazoinsmsiywwt&quot;))&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;3079a29575a0adff91f04c5493a7f3e1c89795e3a90cf842650cd8bd45c4e1bc&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CobaltStrike&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ecca3194613b0bab02059c3544fdc90f6d4af5a4c06518c853517eb1d81b9735&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Old&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;bcstctskmngpjjax&quot;))&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Unknown&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Unknown&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ad90a4490d82c7bd300fdbbdca0336e5ad2219d63ea0f08cebc33050d65b7ef2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Old&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;lklzndaawijhd&quot;)) + zero padding&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;70b3b8e07752c1f3d4a462b2ab47ca3d9fb5094131971067230031b8b2cd84f2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CobaltStrike&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;99d6b73b1a9e66d7f6dcb3244ea0783b60776efd223d95c4f95e31fde434e258&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Old&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;toupper(to_hex(&quot;ifovxtgokm|yzjwz&quot;))&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Unknown&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Unknown&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h4&gt;Appendix C: Example of Cobalt Strike configuration&lt;/h4&gt;

&lt;pre style=&#39;padding: 10px 10px;color:#d1d1d1;background:#1f1f1f;overflow: auto;white-space: pre&#39;&gt;
BeaconType                       - HTTPS
Port                             - 443
SleepTime                        - 30000
MaxGetSize                       - 2097328
Jitter                           - 40
MaxDNS                           - Not Found
PublicKey_MD5                    - d67a7903c6777d64b69845b6fcd5db65
C2Server                         - 64.95.10[.]209,/Collector/2.0/settings/,179.60.149[.]209,/Collector/2.0/settings/,64.52.80[.]62,/Collector/2.0/settings/
UserAgent                        - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Teams/1.4.00.2879 Chrome/80.0.3987.165 Electron/8.5.1 Safari/537.36
HttpPostUri                      - /MkuiIJzM2IZs
Malleable_C2_Instructions        - Remove 46 bytes from the end
                                   Remove 130 bytes from the beginning
                                   NetBIOS decode &#39;a&#39;
HttpGet_Metadata                 - ConstHeaders
                                        Accept: json
                                        Host: westeurope-teams.azureedge.net
                                        Referer: https://teams.microsoft.com/_
                                        x-ms-session-id: f73c3186-057a-d996-3b63-b6e5de6ef20c
                                        x-ms-client-type: desktop
                                        x-mx-client-version: 27/1.0.0.2021020410
                                        Accept-Encoding: gzip, deflate, br
                                        Origin: https://teams.microsoft.com
                                   ConstParams
                                        qsp=true
                                        client-id=NO_AUTH
                                        sdk-version=ACT-Web-JS-2.5.0&amp;
                                   Metadata
                                        base64url
                                        parameter &quot;events&quot;
HttpPost_Metadata                - ConstHeaders
                                        Connection: Keep-Alive
                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
                                   SessionId
                                        base64url
                                        parameter &quot;id&quot;
                                   Output
                                        base64url
                                        print
PipeName                         - Not Found
DNS_Idle                         - Not Found
DNS_Sleep                        - Not Found
SSH_Host                         - Not Found
SSH_Port                         - Not Found
SSH_Username                     - Not Found
SSH_Password_Plaintext           - Not Found
SSH_Password_Pubkey              - Not Found
SSH_Banner                       -
HttpGet_Verb                     - GET
HttpPost_Verb                    - POST
HttpPostChunk                    - 0
Spawnto_x86                      - %windir%\syswow64\powercfg.exe
Spawnto_x64                      - %windir%\sysnative\powercfg.exe
CryptoScheme                     - 0
Proxy_Config                     - Not Found
Proxy_User                       - Not Found
Proxy_Password                   - Not Found
Proxy_Behavior                   - Use IE settings
Watermark_Hash                   - NtZOV6JzDr9QkEnX6bobPg==
Watermark                        - 987654321
bStageCleanup                    - True
bCFGCaution                      - True
KillDate                         - 0
bProcInject_StartRWX             - True
bProcInject_UseRWX               - False
bProcInject_MinAllocSize         - 8096
ProcInject_PrependAppend_x86     - Empty
ProcInject_PrependAppend_x64     - Empty
ProcInject_Execute               - ntdll.dll:RtlUserThreadStart
                                   NtQueueApcThread-s
                                   SetThreadContext
                                   CreateRemoteThread
                                   kernel32.dll:LoadLibraryA
                                   RtlCreateUserThread
ProcInject_AllocationMethod      - VirtualAllocEx
bUsesCookies                     - False
HostHeader                       -
headersToRemove                  - Not Found
DNS_Beaconing                    - Not Found
DNS_get_TypeA                    - Not Found
DNS_get_TypeAAAA                 - Not Found
DNS_get_TypeTXT                  - Not Found
DNS_put_metadata                 - Not Found
DNS_put_output                   - Not Found
DNS_resolver                     - Not Found
DNS_strategy                     - round-robin
DNS_strategy_rotate_seconds      - -1
DNS_strategy_fail_x              - -1
DNS_strategy_fail_seconds        - -1
Retry_Max_Attempts               - 0
Retry_Increase_Attempts          - 0
Retry_Duration                   - 0
&lt;/pre&gt;

&lt;h4&gt;Appendix D: Network&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;64.52.80[.]62:443&lt;/li&gt;
&lt;li&gt;64.95.10[.]209:443&lt;/li&gt;
&lt;li&gt;67.217.228[.]55:443&lt;/li&gt;
&lt;li&gt;137.184.155[.]92:443&lt;/li&gt;
&lt;li&gt;159.65.241[.]37:443&lt;/li&gt;
&lt;li&gt;162.33.179[.]247:8443&lt;/li&gt;
&lt;li&gt;165.227.113[.]183:443&lt;/li&gt;
&lt;li&gt;179.60.149[.]209:443&lt;/li&gt;
&lt;li&gt;192.241.190[.]181:443&lt;/li&gt;
&lt;li&gt;api.glazeceramics[.]com:443&lt;/li&gt;
&lt;li&gt;doc.docu-duplicator[.]com:53&lt;/li&gt;
&lt;li&gt;doc2.docu-duplicator[.]com:53&lt;/li&gt;
&lt;li&gt;comdoc1.docu-duplicator[.]com:53&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Appendix E: Malware&lt;/h4&gt;

&lt;p&gt;Table 2: List of malware and tools&lt;/p&gt;

&lt;table style=&quot;table-layout: fixed; width: 100%;&quot;&gt;
&lt;colgroup&gt;
  &lt;col style=&quot;width: 15%;&quot;&gt;
  &lt;col style=&quot;width: 15%;&quot;&gt;
  &lt;col style=&quot;width: 70%;&quot;&gt;
&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Malware&lt;/th&gt;
&lt;th&gt;Filename&lt;/th&gt;
&lt;th&gt;Hash(SHA256)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;java(Legitimate)&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;java.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;16b1819186f0803b9408d9a448a176142f8271a4bc0b42cdb78eb4489bce16fe&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;56b941f6dcb769ae6d6995412559012abab830f05d5d8acf2648f7fa48c20833&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;dfe79b9c57cfb9fc10597b43af1c0a798991b6ceeec2af9b1e0ed46e6a8661c8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;3f96b6589996e57abc1c4d9b732528d2d11dea5c814f8241170c14ca2cd0281d&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;0ab709728666f8759ad8db574d4009cf74ebce36ef2572ef52b058997a9b2a25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ecca3194613b0bab02059c3544fdc90f6d4af5a4c06518c853517eb1d81b9735&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ad90a4490d82c7bd300fdbbdca0336e5ad2219d63ea0f08cebc33050d65b7ef2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ReadNimeLoader&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;jli.dll&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;99d6b73b1a9e66d7f6dcb3244ea0783b60776efd223d95c4f95e31fde434e258&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Cobalt Strike&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;readme.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;6246fb5c8b714707ac49ade53e6fe5017d96442db393b1c0ba964698ae24245d&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Cobalt Strike&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;readme.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;acdf2a87ed03f2c6fe1d9899e8a74e8b56f7b77bb8aed5adf2cc374ee5465168&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Cobalt Strike&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;readme.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;6b80d602472c76b1d0f05bcce62e0a34de758232d9d570ba61b540784c663c01&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Cobalt Strike&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;readme.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;3079a29575a0adff91f04c5493a7f3e1c89795e3a90cf842650cd8bd45c4e1bc&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Cobalt Strike&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;readme.txt&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;70b3b8e07752c1f3d4a462b2ab47ca3d9fb5094131971067230031b8b2cd84f2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CrossC2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;gds&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;28d668f3e1026a56d55bc5d6e36fad71622c1ab20ace52d3ab12738f9f8c6589&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;CrossC2&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;gss&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;9e8c550545aea5212c687e15399344df8a2c89f8359b90d8054f233a757346e7&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ELF-SystemBC&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;monitor&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;74a33138ce1e57564baa4ea4db4a882d6bf51081b79a167a6cb2bf9130ddad7f&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ELF-SystemBC&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;monitor&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;7ccff87db7b4e6bc8c5a7e570f83e26ccb6f3a8f72388210af466048d3793b00&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;GetNPUsers&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;GetNPUsers_windows.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;e0e827198a70eef6c697559660106cfab7229483b0cd7f0c7abd384a3d2ee504&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Tools related to privilege escalation&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;wermgr.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;f79e047ae4834e6a9234ca1635f18b074a870b366fe4368c10c2ddc56dfbb1bc&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Tools related to privilege escalation&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;wermgr.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;ac02aee660d44a8bfbc69e9c46cf402fd41e99915e13d0de3977e662ef13b2ca&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;Plink v0.81&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;conhost.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;2e338a447b4ceaa00b99d742194d174243ca82830a03149028f9713d71fe9aab&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;PsExec v2.43&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;PsExec.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;cab-related tool&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;hhupd.exe&lt;/td&gt;
&lt;td style=&quot;word-wrap: break-word; white-space: normal;&quot;&gt;d74eac55eeaa3138bc1e723c56013bb1af7709f0a77308bfbf268d4e32b37243&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

    

  </content>
</entry>
</feed>
