¡¸Íþвͨ¸æ¡¹Vollgar½©Ê¬ÍøÂç
2020-04-01
Ò»¡¢Íþв¸ÅÊö
4ÔÂ1ÈÕ£¬Guardicore LabsÍŶÓÐû²¼ÁËÒ»·Ýºã¾Ã¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ£¬´Ë¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÔËÐÐMS-SQL·þÎñµÄWindowsϵͳ¡£ÆÊÎö±¨¸æ³Æ£¬´Ë¹¥»÷Ô˶¯ÖÁÉÙ´Ó2018Äê5ÔÂ×îÏÈ£¬¹¥»÷Õß»áÕë¶ÔÄ¿µÄµÄMS-SQL¾ÙÐб©Á¦²Â½â£¬ÀֳɵǼĿµÄϵͳºó£¬ÔÙÔÚϵͳÖа²ÅźóÃŲ¢ÔËÐÐÔ¶¿Ø¹¤¾ßµÈ¶ñÒâ³ÌÐò¡£ÕâһϵÁеĹ¥»÷Ô˶¯±»ÃüÃûΪ“Vollgar”¡£

ͨ¹ý±©Á¦ÆÆ½âÕË»§Éϰ¶ÏµÍ³ÔÙÖ²Èë¶ñÒâ³ÌÐòÊÇÒ»ÖÖÊ®·ÖÆÕ±éµÄ¹¥»÷ÊÖ·¨£¬µ«±¨¸æÖгƣ¬ÌìÌìÈÔÓÐ2-3ǧ¸öÊý¾Ý¿âÔÚVollgar¹¥»÷Ô˶¯Öб»¹¥ÏÝ£¬ÆäÖаüÀ¨Öйú¡¢Ó¡¶È¡¢º«¹ú¡¢ÍÁ¶úÆäºÍÃÀ¹úµÈ¹ú¼Ò£¬ÊÜÓ°ÏìµÄÐÐÒµº¸ÇÒ½ÁÆ¡¢º½¿Õ¡¢IT¡¢µçÐÅ¡¢½ÌÓýµÈ¶à¸öÁìÓò¡£
²Î¿¼Á´½Ó£º
https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack/
¶þ¡¢Ó°Ïì¹æÄ£
±£´æMS-SQLÈõ¿ÚÁîµÄWindowsϵͳ
Èý¡¢Î£º¦ÅŲé
3.1 detect_vollgar.ps1¾ç±¾×Ô²é
Guardicore LabsÌṩÁËPowerShell×Ô²é¾ç±¾Script – detect_vollgar.ps1£¬×Ô²é¾ç±¾detect_vollgar.ps1¿ÉʵÏÖÍâµØ¹¥»÷ºÛ¼£¼ì²â£¬¼ì²âÄÚÈÝÈçÏ£º
- ÎļþϵͳÖеĶñÒâpayload£»
- ¶ñÒâ·þÎñÀú³ÌʹÃüÃû£»
- ºóÃÅÓû§Ãû¡£
¾ç±¾ÏÂÔØÁ´½Ó£º
https://github.com/guardicore/labs_campaigns/tree/master/Vollgar
¼ì²â°ì·¨£º
1¡¢ÏÂÔØ×Ô²é¾ç±¾detect_vollgar.ps1ÖÁÍâµØ£¬¾ç±¾ÄÚÈÝÏê¿´·¨Ö·https://github.com/guardicore/labs_campaigns/blob/master/Vollgar/detect_vollgar.ps1
2¡¢“Windows”+“R”£¬ÔÚµ¯³öµÄÔËÐнçÃæËÑË÷PowerShell¡£
3¡¢ÔËÐо籾¡£ÈôÊÇ»ØÏÔÖаüÀ¨“Evidence for Vollgar campaign has been found on this host.”×ÖÑù£¬Ôò˵Ã÷Ä¿½ñϵͳ¿ÉÄÜÒѱ»Ñ¬È¾¡£

Èô±£´æÑ¬È¾ÇéÐΣ¬Çë²Î¿¼ÏÂÁÐÒªÁì¾ÙÐд¦Öóͷ££º
- ÒÆ³ý̽²â×Ô²éЧ¹ûÖеĹ¥»÷ºÛ¼£¡£
- ÖÕÖ¹¶ñÒâ³ÌÐò
×¢£ºÈô·ºÆðÖ±½ÓÔËÐÐPowerShellʱÌáÐÑ“ÎÞ·¨¼ÓÔØÎļþps1£¬ÓÉÓÚÔÚ´ËϵͳÖÐեȡִÐо籾¡£ÓйØÏêϸÐÅÏ¢£¬Çë²ÎÔÄ “get-help about_signing”¡£´ËÌáÐÑÊÇÓÉÓÚûÓÐȨÏÞÖ´Ðиþ籾¡£¿ÉÔËÐÐÈçÏÂÏÂÁîÉó²éÄ¿½ñÖ´ÐÐÕ½ÂÔ£º
|
1
|
get-executionpolicy
|
ÈôÊÇÏÔʾ“Restricted”ÔòΪ²»ÔÊÐíÖ´ÐÐÈκξ籾¡£
ͨ¹ýÔËÐÐÒÔÏÂÏÂÁî¿ÉÐÞ¸ÄÆäÕ½ÂÔ£º
|
1
|
set-executionpolicy remotesigned
|
ÐÞ¸ÄÀֳɺ󼴿ÉʹÓÃPowerShellÖ´Ðо籾
ÈçÐè×÷·Ï¶ÔÆäÕ½ÂÔµÄÐ޸ģ¬¿Éͨ¹ýÔËÐÐÒÔÏÂÏÂÁî¾ÙÐлָ´¡£
|
1
|
set-executionpolicy Restricted
|
3.2 ͨÀý·À»¤½¨Òé
- ¹Ø±ÕÊý¾Ý¿âÕ˺ŵǼ·½·¨ ÒÔwindowsÉí·ÝÑéÖ¤·½·¨µÇ¼Êý¾Ý¿â ²¢ÔÚwindowsÕ½ÂÔÀïÉèÖÃÃÜÂëÇ¿¶È¡£
- ÔöÇ¿ÍøÂç½çÏßÈëÇÖÌá·ÀºÍÖÎÀí£¬ÔÚÍøÂçÊÕÖ§¿ÚÉèÖ÷À»ðǽµÈÍøÂçÇå¾²×°±¸£¬¶Ô²»ÐëÒªµÄͨѶÓèÒÔ×è¶Ï¡£
- ¶Ô̻¶ÔÚ»¥ÁªÍøÉϵÄÍøÂç×°±¸¡¢·þÎñÆ÷¡¢²Ù×÷ϵͳºÍÓ¦ÓÃϵͳ¾ÙÐÐÇå¾²ÅŲ飬°üÀ¨µ«²»ÏÞÎó²îɨÃ衢ľÂí¼à²â¡¢ÉèÖú˲顢WEBÎó²î¼ì²â¡¢ÍøÕ¾ÉøÍ¸²âÊԵȡ£
- ÔöÇ¿Çå¾²ÖÎÀí£¬½¨ÉèÍøÂçÇå¾²Ó¦¼±´¦Öóͷ£»úÖÆ£¬ÆôÓÃÍøÂçºÍÔËÐÐÈÕÖ¾É󼯣¬°²ÅÅÍøÂçÖµÊØ£¬×öºÃ¼à²â²½·¥£¬ÊµÊ±·¢Ã÷¹¥»÷Σº¦£¬ÊµÊ±´¦Öóͷ£¡£

AG¹«Ë¾ÔÆ







