HTTP¤Î¥ê¥¯¥¨¥¹¥È¤È¥ì¥¹¥Ý¥ó¥¹¤Ë¤Ä¤¤¤Æ²òÀ⤷¤Þ¤¹¡£
°Ê²¼¤Î¿Þ¤Ç¹Í¤¨¤Þ¤¹¡£
PC¤Î¥Ö¥é¥¦¥¶¤«¤é¡¢http://nw.seeeko.com¤È¤¤¤¦¥µ¥¤¥È¤ò±ÜÍ÷¤·¤¿¤È¤·¤Þ¤¹¡£¤³¤Î¤È¤­¡¢Web¥µ¡¼¥Ð¤ËÂФ·¤Æ¡¢¡Ö¥Ú¡¼¥¸¤òɽ¼¨¤·¤Æ¤¯¤À¤µ¤¤¡×¤È¤ª´ê¤¤¤¹¤ë¤Î¤¬HTTP¥ê¥¯¥¨¥¹¥È¤Ç¤¹¡£¤½¤ì¤ËÂФ·¤Æ¡¢Web¥µ¡¼¥Ð¤«¤éPC¤Î¥Ö¥é¥¦¥¶¤ËÂФ·¡¢¼ÂºÝ¤Î¥Ú¡¼¥¸¤Î¾ðÊó¡Êʸ»ú¤ä²èÁü¡¢Æ°²è¤Ê¤É¡Ë¤òÊÖ¤¹¤Î¤¬¡¢HTTP¥ì¥¹¥Ý¥ó¥¹¤Ç¤¹¡£
http
¡¡¡¡¡¡¡¡¡¡
²áµîÌä¡ÊH25SC½©¸á¸å­¶Ìä1¡Ë¤Ë¥ê¥¯¥¨¥¹¥È¤È¥ì¥¹¥Ý¥ó¥¹¤Î¶ñÂÎÎ㤬¤¢¤ë¤Î¤Ç·ÇºÜ¤¹¤ë¡£
¸«¤Æ¤â¤é¤¦¤Èʬ¤«¤ë¤¬¡¢¥ê¥¯¥¨¥¹¥È¤ÏGET¤Ê¤É¤Ç¾ðÊó¤ò¼èÆÀ¤Ë¹Ô¤¯¡£
¥ì¥¹¥Ý¥ó¥¹¤Ï¡¢¡Ö200¡¡OK¡×¤Ê¤É¤Î¡¢HTTP¤Î¥¹¥Æ¡¼¥¿¥¹¥³¡¼¥É¤«¤é¤Ï¤¸¤Þ¤ë¡£

¥ê¥¯¥¨¥¹¥È
GET /javarhino/ HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg,
image/pjpeg, application/¡ß-shockwave-flash., */*
Accept-Language: ja
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0;Windows NT 5.1; SVl)
Host: D.D.D.D
Connection: Keep-Alive
¢¨¸å½Ò¤·¤Þ¤¹¤¬¡¢1¹ÔÌܤÏHTTP¥ê¥¯¥¨¥¹¥È¹Ô¤Ç¤¹¡£HTTP¥ê¥¯¥¨¥¹¥È¹Ô¤Ë¤Ï¡¢GET¤äPOST¤Ê¤É¤Î¥á¥½¥Ã¥É¤¬µ­ºÜ¤µ¤ì¤Þ¤¹¡£¤Þ¤¿¡¢/javarhino/¤ÏURL¤Î¥Ñ¥¹¤Ë¤Ê¤ê¤Þ¤¹¡£HOST¤ÏÀܳÀè¡ÊWeb¥µ¡¼¥Ð¡Ë¤ÎIP¥¢¥É¥ì¥¹¤Ç¤¹¡£ËÜÍè¤Ï¡¢IP¥¢¥É¥ì¥¹¡§¥Ý¡¼¥ÈÈÖ¹æ¤Îɽµ­¤Ç¤¹¤¬¡¢80¤Î¾ì¹ç¤Ï¾Êά¤µ¤ì¤Þ¤¹¡£

¥ì¥¹¥Ý¥ó¥¹
HTTP/1.1 200 OK
Content-Type: text/html
Connection: Keep-Alive
Server: Apache
Content-Length: 12e
<html><head></head><body><appletarchiveR"exploit.jar"
code="exploit.class" width="1" height="1"></applet></body></html>
kome
¢£¼ÂºÝ¤Î¥Ñ¥±¥Ã¥È¤ò¸«¤Æ¤ß¤Þ¤·¤ç¤¦¡£
¿Þ¤Ç½ñ¤¤¤¿¤è¤¦¤Êhttp://nw.seeeko.com¤Î¥µ¥¤¥È¤Ë¥¢¥¯¥»¥¹¤·¤¿¾ì¹ç¤Î¥ê¥¯¥¨¥¹¥È¤È¥ì¥¹¥Ý¥ó¥¹¤Ç¤¹¡£
­¡HTTP¥ê¥¯¥¨¥¹¥È
GET¤Îµ­ºÜ¤¬³Îǧ¤Ç¤­¤ë¤³¤È¤Ç¤·¤ç¤¦¡£
HTTP¥ê¥¯¥¨¥¹¥È
­¢HTTP¥ì¥¹¥Ý¥ó¥¹
200 OK¤¬¸«¤¨¤ë¤³¤È¤Ç¤·¤ç¤¦¡£
HTTP¥ì¥¹¥Ý¥ó¥¹
¢£Apache¤Î¥í¥°
»²¹Í¤È¤·¤Æ¡¢Apache¤Î¥í¥°¤ò¸«¤Æ¤ß¤Þ¤·¤ç¤¦¡£H30½©SC¸á¸å­¶Ìä2¤Îµ­½Ò¤Ç¤¹¡£
4:[04/Sep/2018:14:31:15+0900] "GET http://yyyy/dl/samplebun.zip HTTP/1.1" 200 89331
  "http://zzzz/2018/ne/bunrei.html" "¢¥¢¥"
Ãíµ­2¡¡¥×¥í¥­¥·¥µ¡¼¥Ð¤¬¼èÆÀ¤·¤¿¥í¥°¤Î¤¦¤Á¡¤Æü»þ¡¤¥ê¥¯¥¨¥¹¥È¤Î¥á¥½¥Ã¥É¡¤¥ê¥¯¥¨¥¹¥È¤ÎURL¡¤¥ê¥¯¥¨¥¹¥È¤Î¥×¥í¥È¥³¥ë¤È¥Ð¡¼¥¸¥ç¥ó¡¤Í׵ḵPC¤ËÁ÷¿®¤·¤¿¥ì¥¹¥Ý¥ó¥¹¤ÎHTTP¥¹¥Æ¡¼¥¿¥¹¥³¡¼¥É¡¤Í׵ḵPC¤ËÁ÷¿®¤·¤¿¥ì¥¹¥Ý¥ó¥¹¥á¥Ã¥»¡¼¥¸¤Î¥µ¥¤¥º¡¤¥ê¥¯¥¨¥¹¥È¤ÎReferer¥Ø¥Ã¥À¤ÎÃÍ¡¤µÚ¤Ó¥ê¥¯¥¨¥¹¥È¤ÎUser
Agent¥Ø¥Ã¥À¤ÎÃͤò¼¨¤¹¡£

¡¡Ãíµ­2¤Ëµ­ºÜ¤¬¤¢¤ê¤Þ¤¹¤¬¡¢Êä­¤·¤Þ¤¹¡£
­¡Æü»þ¡§¡Ü0900¤Ï¡¢À¤³¦¤Îɸ½à»þ¹ïGMT¡Ê¼ÂºÝ¤Ë¤ÏUTC¡Ë¤È9»þ´Ö¤Î¥º¥ì¤¬¤¢¤ë¤³¤È¤ò°ÕÌ£¤·¤Þ¤¹¡£
­¢¥ê¥¯¥¨¥¹¥È¤Î¥á¥½¥Ã¥É¡§Àµ³Î¤ËÀâÌÀ¤¹¤ë¤ÈŤ¯¤Ê¤ê¤Þ¤¹¤¬¡¢GET¥á¥½¥Ã¥É¤Ï¥Ç¡¼¥¿¤ò¼èÆÀ¡¢POST¤Ï¥Ç¡¼¥¿¤òÁ÷¿®¤È¹Í¤¨¤Æ¤¯¤À¤µ¤¤¡£
­£¥ê¥¯¥¨¥¹¥È¤ÎURL:Àܳ¤¹¤ëURL¤Ç¤¹¡£
­¤¥ê¥¯¥¨¥¹¥È¤Î¥×¥í¥È¥³¥ë¤È¥Ð¡¼¥¸¥ç¥ó¡§HTTP/1.1¤ÏHTTP¤Î¥Ð¡¼¥¸¥ç¥ó¤Ç¤¹¡£HTTP2.0¤â¤¢¤ê¤Þ¤¹¤¬¡¢ºÇ¤âÉáµÚ¤·¤Æ¤¤¤ë¤Î¤¬1.1¤Î¥Ð¡¼¥¸¥ç¥ó¤Ç¤¹¡£
­¥Í׵ḵPC¤ËÁ÷¿®¤·¤¿¥ì¥¹¥Ý¥ó¥¹¤ÎHTTP¥¹¥Æ¡¼¥Æ¥¹¥³¡¼¥É¡§HTTP¤Î¥¹¥Æ¡¼¥¿¥¹¥³¡¼¥É¤Ç¡¢200¤ÏÄÌ¿®¤¬À®¸ù¤·¤¿¤³¤È¤ò°ÕÌ£¤·¤Þ¤¹¡£
­¦Í׵ḵPC¤ËÁ÷¿®¤·¤¿¥ì¥¹¥Ý¥ó¥¹¥á¥Ã¥»¡¼¥¸¤Î¥µ¥¤¥º¡§¥Ç¡¼¥¿¤Î¥Ð¥¤¥È¿ô¤Ç¤¹¡£º£²ó¤ÎÄÌ¿®¤Ï89331¥Ð¥¤¥È¤Ç¤¢¤ë¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£
­§¥ê¥¯¥¨¥¹¥È¤ÎReferer¥Ø¥Ã¥À¤ÎÃÍ¡§""¤ÎÃæ¤ÎURL¤Ï¥ê¥Õ¥¡¥é¤Ê¤Î¤Ç¡¢¥¢¥¯¥»¥¹¸µ¤ÎURL¤¬µ­ºÜ¤µ¤ì¤Þ¤¹¡£Ä¾ÀÜ¥¢¥¯¥»¥¹¤·¤¿¾ì¹ç¤Ï¡¢-¤Îɽµ­¤¬¤µ¤ì¤Þ¤¹¡£
­¨¥ê¥¯¥¨¥¹¥È¤ÎUser-Agent¥Ø¥Ã¥À¤ÎÃÍ¡§Ãíµ­5¤Ë¤âµ­ºÜ¤¬¤¢¤ë¥æ¡¼¥¶¥¨¡¼¥¸¥§¥ó¥È¤Ç¡¢PC¤ÎOS¤ä¥Ö¥é¥¦¥¶¤Î¾ðÊ󤬵­ºÜ¤µ¤ì¤Þ¤¹¡£PC¤´¤È¤Ë°Û¤Ê¤ë¾ðÊ󤬵­ºÜ¤µ¤ì¤Þ¤¹¡£

¢£HTTP¥ê¥¯¥¨¥¹¥È¤ä¥ì¥¹¥Ý¥ó¥¹¤Î¹½À®
¤Ç¤Ï¡¢¤³¤ÎHTTP¥ê¥¯¥¨¥¹¥È¤ä¥ì¥¹¥Ý¥ó¥¹¤Î¹½À®¤Ï¤É¤¦¤Ê¤Ã¤Æ¤¤¤ë¤Ç¤·¤ç¤¦¤«¡£Ê¬¤«¤ê¤ä¤¹¤¤HTTP¥ì¥¹¥Ý¥ó¥¹¤òÎã¤Ëµ­ºÜ¤·¤Þ¤¹¡£
HTTP
¤³¤Î¤è¤¦¤Ë¡¢HTTP¥ì¥¹¥Ý¥ó¥¹¹Ô¡Ê¤Þ¤¿¤ÏHTTP¥ê¥¯¥¨¥¹¥È¹Ô¡Ë¡¢HTTP¥Ø¥Ã¥À¡¢1¹Ô¤Î¶õÇò¤ò¶õ¤±¤ÆHTTP¥á¥Ã¥»¡¼¥¸¥Ü¥Ç¥£¤Î3¤Ä¤ÎÉôʬ¤Ç¹½À®¤µ¤ì¤Þ¤¹¡£HTTP¥á¥Ã¥»¡¼¥¸¥Ü¥Ç¥£¤Ï¡¢¼ÂºÝ¤ÎHTML¥Õ¥¡¥¤¥ë¤¬Æþ¤Ã¤Æ¤¤¤Þ¤¹¡£
HTTP¥ê¥¯¥¨¥¹¥È¹Ô¤Ë¤Ï¡¢GET¤äPOST¤Ê¤É¤Î¥á¥½¥Ã¥É¤¬µ­ºÜ¤µ¤ì¤Þ¤¹¡£HTTP¥ì¥¹¥Ý¥ó¥¹¹Ô¤Ë¤Ï¡¢200OK¤Ê¤É¤Î¥¹¥Æ¡¼¥¿¥¹¥³¡¼¥É¤¬µ­ºÜ¤µ¤ì¤Þ¤¹¡£
¼ÂºÝ¤Î¥Ñ¥±¥Ã¥È¤ÎÎã¤Ï°Ê²¼¤Ç¤¹¡£
pcap

¢£User-Agent¤Ë´Ø¤·¤Æ
¥Ö¥é¥¦¥¶¤ËUser-Agent¤òÁ÷¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢PC¤«¤éÀܳ¤·¤¿¾ì¹ç¤È¥¹¥Þ¥Û¡Ê¤¿¤È¤¨¤ÐiPhone¡Ë¤Ê¤Î¤«¤¬¤ï¤«¤ê¡¢Web¥µ¡¼¥Ð¦¤Ç¡¢¤½¤ì¤Ë´ð¤Å¤¤¤ÆºÇŬ¤Ê¥Ú¡¼¥¸¤òɽ¼¨²Äǽ¤Ë¤Ê¤ë¡£¡Ê¼ÂºÝ¡¢¤½¤¦¤Ê¤Ã¤Æ¤Þ¤¹¤è¤Í¡©¡Ë
Burp Suite¤Ç¡¢User-Agent¤òÊѤ¨¤Æ¤ß¤ë¤È¤¤¤¤¤À¤í¤¦¡£¢ª¤ä¤Ã¤Æ¤ß¤ë¤È¡¢°Õ³°¤Ë³Ú¤·¤¤¡£
C&C¥µ¡¼¥Ð¤Ê¤É¤Ç¤Ï¡¢¥Þ¥ë¥¦¥§¥¢¤Ë»Å¹þ¤ó¤ÀUser-Agent¤Ç¤·¤«±þÅú¤·¤Ê¤¤¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£¤³¤ì¤Ë¤è¤ê¡¢Ä´ººÌÜŪ¤Ç¥¢¥¯¥»¥¹¤¬¤¢¤Ã¤Æ¤â¡¢°­°Õ¤¬¤¢¤ë¹Ôư¤¬¤Ð¤ì¤Ê¤¤¡£

¥¹¥Ý¥ó¥µ¡¼¥É¥ê¥ó¥¯