¡¾Íþвͨ¸æ¡¿REvil·çÔÆÔÙÆð£¬APTʽÀÕË÷±¬·¢
2021-05-25
Ò». ÊÂÎñÅä¾°
2021Äê5Ô£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½REvil/SodinokibiÀÕË÷¼Ò×åµÄ¶àÆðÔ˶¯£¬REvilΪRansomware Evil£¨ÓÖ³ÆSodinokibi£©µÄËõд£¬ÊÇÒ»¸ö˽ÈËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯¡£ÓÚ2019Äê4ÔÂÊ״α»·¢Ã÷£¬ÔÚÒ»ÄêÄÚ¾ÍÒѱ»ÓÃÓÚһЩ×ÅÃûÍøÂç¹¥»÷£¬2019Äê8ÔµÄPerCSoft¹¥»÷£¬2020Äê1ÔµÄTravelexÀÕË÷Èí¼þ¹¥»÷£¬¼°2020Äê1ÔµÄGedia Automotive¹¥»÷µÈÊÂÎñ¡£½üÆÚ£¬¸Ã×éÖ¯ÈëÇÖÁËÆ»¹û¹«Ë¾µÄ¹©Ó¦ÉÌ£¬²¢ÇÔÈ¡ÁËÆ»¹û¹«Ë¾¼´½«ÍƳöµÄ²úÆ·ÉñÃØÔÀíͼ¡£
´ó¶¼ÍøÂçÇ徲ר¼ÒÒÔΪ£¬REvilÊÇÒÔǰһ¸öÎÛÃûÕÑÖøµ«ÒÑÇýÖðµÄºÚ¿ÍÍÅ»ïGandCrabµÄ·ÖÖ§¡£¸ÃÍÆ²âÔ´ÓÚREvilÔÚGandCrab×èÖ¹ÔËÓªºóÁ¬Ã¦×îÏÈÔ˶¯£¬ÇÒ¶þÕßʹÓõÄÀÕË÷Èí¼þ±£´æ´ó×Ú¹²Ïí´úÂë¡£

¶þ. ×éÖ¯ÆÊÎö
SodinokibiÔËÓªÉÌͨ³£ÕÐÆ¸ºÚ¿Í¹¥»÷Õß¾ÙÐгõʼÈëÇÖ¡£ËûÃǵĹ¥»÷ÍùÍù´ÓÊìϤµÄÊÖÒÕ×îÏÈ£¬Èç´øÓÐÓã²æÊ½´¹ÂÚÁ´½Ó»ò¸½¼þµÄ¶ñÒâÓʼþ¡¢Ê¹ÓÃÓÐÓÃÕË»§µÄRDP»á¼û¡¢Òѱ»ÈëÇÖµÄwebÍøÕ¾ºÍÎó²îʹÓõȡ£²¢ÇÒ»¹»áʹÓÃһЩ¶ÔÄ¿µÄ¾ßÓÐÕë¶ÔÐÔµÄÊÖÒÕ¡£
Sodinokibi¼Ò×å½ÓÄÉÀÕË÷Èí¼þ¼´·þÎñµÄģʽ£¬Òâζ×Å·Ö·¢µÄ¹¥»÷Õß½«ÏòÔËÓªÉÌÖ§¸¶×îа汾µÄʹÓ÷ѣ¬²¢ÓÉÀÕË÷×é֯ΪËûÃÇÔËÓª»ù´¡ÉèÊ©¡£ÔÚSodinokibiµÄÉèÖÃÖÐÓÐÁ½¸ö×ֶΣ¬½«¸ú×Ù¿Í»§¶ËºÍ°²ÅÅÀÕË÷Èí¼þʱ´úµÄÌØ¶¨¿Í»§¶ËÔ˶¯¡£
Èý. ¹¥»÷ÊÖ·¨ÆÊÎö
Sodinokibi²¡¶¾×Ô¼º²¢²»¾ß±¸×Ô¶¯Èö²¥¹¦Ð§£¬Ö÷ÒªÒÀÀµ¹¥»÷ÕßÊÖ¶¯Èö²¥£¬µ«»áͨ¹ýɨÃè¾ÖÓòÍø¹²Ïí×ÊÔ´£¬ÊµÑé¼ÓÃܹ²ÏíÎļþ¡£ÀÕË÷²¡¶¾ÍÅ»ï¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃÉøÍ¸£¬»ñÈ¡ÄÚÍøÈ¨ÏÞ²¢¿ØÖÆÒªº¦Éú²úÉèÊ©£¨ÀýÈçÓò¿ØÖ÷»ú£©£¬È»ºóͨ¹ýÌØ¶¨·½·¨£¨ÀýÈçÓòÕ½ÂÔ¡¢PsExecÔ¶³ÌÅþÁ¬Ö´Ðеȣ©ÔÚÄÚÍøÖÐÈö²¥¼ÓÃܲ¡¶¾Ö÷Ìå³ÌÐò¡£ÔÚÈëÇÖÀú³ÌÖУ¬¹¥»÷ÕßʹÓÃÁËÐí¶àÀàËÆAPT×éÖ¯µÄÊֶΣ¬ÈçʹÓÃCobaltStrikeµÈÔ¶¿ØÄ¾Âíºã¾ÃפÁô¡¢ÍøÂçÃô¸ÐÎļþ¡¢°×¼ÓºÚʵÏÖÀÕË÷²¡¶¾ÃâɱµÈ¡£
ij°¸ÀýÖУ¬¹¥»÷Õßͨ¹ýpowershellÏÂÁî½ûÓÃWindows DefenderµÄʵʱ±£»¤£º

ͨ¹ý¹²Ïí¿½±´ÓëwmicÏÂÁ½«ÀÕË÷²¡¶¾Ñù±¾¿½±´µ½Ä¿µÄÖ÷»ú²¢Ö´ÐУº

»òÕßͨ¹ýÓò¿ØÏ·¢×éÕ½ÂԵķ½·¨£¬½«ÀÕË÷²¡¶¾Ñù±¾¿½±´µ½Öն˲¢Ö´ÐС£ÀÕË÷²¡¶¾±¾Ìå¾ßÓÐÓÐÓÃÊý×ÖÊðÃû£¬²¢½ÓÄÉÁ˰׼Ӻڵķ½·¨£¬ÌÓ±Üɱ¶¾Èí¼þ²éɱ¡£

¹¥»÷Õß»¹»áʹÓÃpowershell»òMSBUILDÏÂÁîÖ´ÐÐÎļþ¼ÓÔØCobaltStrike Ô¶¿ØÄ¾ÂíÒÔʵÏÖºã¾ÃȨÏÞά³Ö¡£

²¡¶¾×Ô¼º²¢²»¾ß±¸ÏµÍ³×¤Áô¹¦Ð§£¬²»»á¶Áд±»¼ÓÃÜÖն˵ÄÈÎºÎÆô¶¯Ïî¡£µ«ÔÚһЩ°¸ÀýÖз¢Ã÷£¬²¿·Ö¹¥»÷Õßͨ¹ýÅú´¦Öóͷ£µÄ·½·¨Ð½¨×¼Ê±ÍýÏëʹÃüÀ´Ò»Ö±Æô¶¯¼ÓÃܳÌÐò£¬ÒÔ±ãµÖ´ïѬȾÐÂÎļþ¡¢Ð´洢½éÖʵÄÄ¿µÄ¡£

REvil¼Ò×åÔÚÉøÍ¸µÄÀú³ÌÖгýÁËͶ·ÅÀÕË÷²¡¶¾£¬»¹»áÍøÂçÉÏ´«±»¹¥»÷ϵͳµÄÎļþ¡£Ä³°¸ÀýÖУ¬ÀÕË÷ÐÅÌáµ½“ÎÒÃÇ»¹´ÓÄúµÄ·þÎñÆ÷ÏÂÔØÁË´ó×ÚÃô¸ÐÊý¾Ý£¬ÈôÊÇÄú²»¸¶¿î£¬ÎÒÃǽ«»á°ÑÄúµÄÎļþÉÏ´«µ½ÎÒÃǵĹ«¹²²©¿Í”¡£

ÔÚÍâµØ¿ªÆôÍøÂç¹²Ïí£¬²¢Í¨¹ýpsexec¹¤¾ß£¬Ê¹ÓÃͨÓÿÚÁÅúÁ¿½«users.ps1¿½±´µ½Ä¿µÄÖ÷»ú¡£

ʹÓÃpsexecÏÂÁÅúÁ¿Ö´Ðп½±´µ½Ä¿µÄÖ÷»úµÄusers.ps1Îļþ

¹¥»÷Õß»áͨ¹ýpowershell¾ç±¾ËѼ¯ÏµÍ³Ãô¸ÐÎļþ²¢ÉÏ´«¡£¾ç±¾×÷ÓãºÍøÂçÄ¿µÄÖ÷»ú120ÌìÄÚ½¨ÉèµÄÖ¸¶¨ºó׺Îļþ£¬²¢ÉÏ´«µ½Ä¿µÄÖ÷»ú¹²ÏíĿ¼¡£

ͨ¹ý×¢²á±íÐÅÏ¢£¬È·ÈϹ¥»÷Õß×°ÖÃÁËTntDrive¿Í»§¶Ë£¬²¢½«ÔÆ´æ´¢¹¤¾ß¹ÒÔØµ½ÍâµØ´ÅÅÌU(¹¥»÷ÕßÉÏ´«ÎļþµÄ¹²ÏíĿ¼)¡£


ËÄ. CobaltStrikeÆÊÎö
Ôʼpowershell´úÂëʹÓÃpowershell base64±àÂë

½âÂëºóÄÚÈÝÈçÏ£º

¾ÙÐжþ´Î½âÂ룬»ñÈ¡µ½powershellÕæÊµ´úÂ룬¹¦Ð§Îª½«¾ç±¾ÖеÄÊý¾Ý¾ÙÐÐÒì»ò£¬¼ÓÔØµ½ÄÚ´æÖÐÖ´ÐС£´Ë¾ç±¾ÎªCobaltstrike powershellÐÎʽµÄpayload¡£

½«¼ÓÔØµ½ÄÚ´æÖеÄÄÚÈݻָ´³É¶þ½øÖÆÎļþ£¬¿ÉÒÔ»ñÈ¡µ½CS beaconµÄ»ØÁ¬µØµã¡£Í¨¹ý»ØÁ¬µØµã·¢Ã÷£¬´ËshellcodeÊÇCSµÄSMB beacon£¬Ö÷ÒªÓÃÓÚÄÚÍøÉøÍ¸¡£

Îå. ÀÕË÷ÑùÌìÖ°Îö
5.1 Êͷű¾Ìå
Ñù±¾Èë¿ÚÈçÏ£º

»áÊͷųöÒ»¸öexeºÍÒ»¸ödll¹âÔÝʱĿ¼£¬²¢Æô¶¯Àú³ÌMsMpEng.exe
ÊͷŵÄMsMpEng.exeÎļþ×Ô¼ºÎÞ¶ñÒ⹦Ч£¬Ö÷ÒªÓÃÓÚ¸øMpsvc.dllÌṩÔËÐÐÇéÐΣ¬²¡¶¾µÄËùÓÐÐÐΪ¶¼ÔÚ¸ÃdllÎļþÖС£½Ó¿ÚΪMpsvc.dllµÄµ¼³öº¯ÊýServiceCrtMain£º


µ¼³öº¯ÊýServiceCrtMainʹÃüÊÇ

PEÈçÏ£º

»¹ÔPE±ê¼Ç£¬Ê¹ÓÃPEÎļþÆÊÎöÆ÷¿ÉÕý³£ÆÊÎö£¬µ«µ¼Èë±í±»¼ÓÃÜ£¬ØÊºó·¢Ã÷²¡À±ÊÖ¶¯Å²ÓÃҪʹÓõÄAPI£¨¶¯Ì¬½âÃÜ£©

¸ÃPEÎļþΪ²¡¶¾±¾Ì壬µ½´Ë²¡¶¾±¾ÌåÊÍ·ÅÍê³É¡£
²¡¶¾±¾Ìå¸ÅÀÀ

5.2 ²¡¶¾ÉèÖñí
¸ÃÀÕË÷²¡¶¾ÓÐÕÅÉèÖÃ±í£¬¸ÃÉèÖÃ±íµ¥Ö÷Òª¼Í¼Á˲¡¶¾¼ÓÃÜÐÐΪÒÔ¼°ÀÕË÷Îı¾ÈçÏ£º
ÎļþĿ¼ɨ³ý£º"fld":["$windows.~bt","intel","google","windows","torbrowser","$windows.~ws","applicationdata","mozilla","windows.old","perflogs","appdata","msocache","boot",
"systemvolumeinformation","programfiles","programfiles(x86)","$recycle.bin","programdata"],
Îļþɨ³ý£º
"fls":["thumbs.db","bootsect.bak","desktop.ini","ntldr","ntuser.dat","autorun.inf","iconcache.db","boot.ini","bootfont.bin","ntuser.ini","ntuser.dat.log"],
ÎļþÀ©Õ¹Ãûɨ³ý£º"ext":["exe","mod","shs","cpl","idx","diagcfg","ico","nomedia","sys","cmd","key","msp","msstyles","bin","rom","bat","cur","diagcab","ldf","dll","scr","hta","rtp","hlp","theme","msi","com","prf","spl","wpx","deskthemepack","diagpkg","mpa","icns","ps1","drv","ics","nls","adv","msu","cab","lnk","ocx","ani","themepack","icl","msc","386","lock"]},
ÎļþÄ¿Â¼ÒÆ³ý£º"wfld":["backup"],
Í£Ó÷þÎñÇåµ¥£º"prc":["mydesktopqos","thebat","synctime","onenote","mspub","dbsnmp","isqlplussvc","tbirdconfig","oracle","xfssvccon","wordpad","agntsvc","sqbcoreservice","ocautoupds","firefox","msaccess","thunderbird","excel","outlook","encsvc","visio","powerpnt","ocomm","steam","mydesktopservice","ocssd","sql","winword","dbeng50","infopath"]
ɱËÀ·þÎñÇåµ¥£º"svc":["veeam","sql","svc$","backup","sophos","vss","memtas","mepocs"]
ÀÕË÷Îı¾£º
[+] Whats Happen? [+]
Your files are encrypted, and currently unavailable. You can check it: all files on your system has extension u89416xh.
By the way, everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER).
[+] What guarantees? [+]
......................................
²¢ÇÒ²¡¶¾»áÅжÏËùѬȾÅÌËã»úʹÓõÄÓïÑÔ£¬ÈçÏ£º

ʹÓú¯ÊýGetUserDefaultUILanguage,GetSystemDefaultUILanguage·µ»ØµÄIDºÍÁбí¿òÖеÄID²î±ð£¬ÄÇôΪѬȾĿµÄ£¬Í¨¹ý´Ë´¦À´¿´Ð޸ķÇÄ¿µÄÅÌËã»úÓïÑÔ¿Éɨ³ýѬȾ¸Ã²¡¶¾¡£²¡¶¾»á½¨É軥³âÌåÈ·±£Î¨Ò»ÔËÐУ¬²¡¶¾»á¶à´Î¼ì²é×Ô¼ºµÄ¾ä±úȨÏÞÊÇ·ñΪÖÎÀíԱȨÏÞ£¬ÈôÊÇȨÏÞ²»·ó½«»áÖØÐÂÒÔÖÎÀíԱȨÏÞÖØÐÂÆô¶¯×Ô¼º£¬²¢ÇÒ¼¤»îÏà¹ØÈ¨ÏÞ¡£
5.3 Ö÷Ì幦Ч
5.3.1 ÍâµØ¼ÓÃÜ
²¡¶¾ÏÖʵµÄÐÐΪÊÇÔÚSub_F4476F_Startº¯ÊýÖУ¬ÈçÏ£º

²¡¶¾Ê×ÏÈÇå¿Õ½ÓÄÉÕ¾£¬¹Ø±ÕÇåµ¥ÖеÄÏà¹Ø·þÎñ£¬É±ËÀÇåµ¥ÖÐÀú³Ì£¬È»ºóÔÚ¼¤»îÏà¹ØÈ¨ÏÞµÄÇéÐÎÏ£¬×îÏȼÓÃܹ¦Ð§¡£Ö÷ҪʹÓÃFindFirstFile ºÍFindNextFileÀ´²éÕÒËùÓÐÎļþ£¬Ê¹ÓÃsalsa20+AESµÄËã·¨¾ÙÐÐÎļþ¼ÓÃÜ¡£

ÔÚ¼ÓÃܵÄÀú³ÌÈôÊÇ·¢Ã÷ÎļþΪĿµÄѬȾÎļþ£¬µ«±»Àú³ÌÕ¼Ó㬲¡¶¾»áŲÓÃterminateProcesss¿¢ÊÂÏà¹ØÀú³Ì£¬ÔÙ¾ÙÐмÓÃÜ¡£

¼ÓÃܺ¯ÊýÈçÏ£º

ÍøÂç´ÅÅ̼ÓÃÜ
²¡¶¾Ò²»áͬʱ¶ÔÍøÂç´ÅÅÌÖеÄÎļþ¾ÙÐмÓÃÜ£¬ÈçÏ£º

5.3.2 ʵÑé¼ÓÃܾÖÓòÍø¹²ÏíÎļþ
ÔÚ¼ÓÃܵÄÀú³ÌÖв¡¶¾ÓÐö¾Ù¾ÖÓòÍøÅÌËã»úµÄÐÐΪ£¬Ö÷ÒªÊDzéÕÒ¾ÖÓòÍø¹²Ïí£¬ÊµÑé¼ÓÃܹ²ÏíÎļþ¡£



5.4 ÏÔʾ×ÀÃæÀÕË÷Åä¾°
ÔÚ¼ÓÃܹ¦Ð§Íê³ÉÒÔºó»áͨ¹ýÉèÖÃ×¢²á±íÉèÖÃ×ÀÃæÅ侰ΪÀÕË÷ͼƬ


Áù. ÀÕË÷Èí¼þÌá·À½¨Òé
l ÔöÇ¿ÆóÒµÔ±¹¤Çå¾²ÒâʶÅàѵ£¬½ûÖ¹Ò×·¿ªÉúÊèÓʼþ»òÔËÐÐȪԴ²»Ã÷µÄ³ÌÐò£»
l Ö»¹Üɨ³ýΣÏն˿ڶÔÍ⿪·Å£¬Ê¹ÓÃIPS¡¢·À»ðǽµÈ×°±¸¶ÔΣÏն˿ھÙÐзÀ»¤£¨445¡¢139¡¢3389µÈ£©£»
l ¿ªÆôWindowsϵͳ·À»ðǽ£¬Í¨¹ýACLµÈ·½·¨£¬¶ÔRDP¼°SMB·þÎñ»á¼û¾ÙÐмӹ̣»
l ͨ¹ýWindows×éÕ½ÂÔÉèÖÃÕË»§Ëø¶¨Õ½ÂÔ£¬¶Ô¶Ìʱ¼äÄÚÒ»Á¬Éϰ¶Ê§°ÜµÄÕË»§¾ÙÐÐËø¶¨£»
l ÔöÇ¿Ö÷»úÕË»§¿ÚÁîÖØÆ¯ºó¼°ÐÞ¸ÄÖÜÆÚÖÎÀí£¬²¢Ö»¹Üɨ³ý·ºÆðͨÓûò¼ÍÂÉ¿ÚÁîµÄÇéÐΣ»
l ÐÞ¸ÄϵͳÖÎÀíԱĬÈÏÓû§Ãû£¬É¨³ýʹÓÃadmin¡¢administrator¡¢testµÈ³£¼ûÓû§Ãû£»
l ×°Öþ߱¸×Ô±£»¤µÄ·À²¡¶¾Èí¼þ£¬±ÜÃâ±»ºÚ¿ÍÍ˳ö»ò¿¢ÊÂÀú³Ì£¬²¢ÊµÊ±¸üв¡¶¾¿â£»
l ʵʱ¸üвÙ×÷ϵͳ¼°ÆäËûÓ¦ÓõĸßΣÎó²îÇå¾²²¹¶¡£»
l ׼ʱ¶ÔÖ÷ÒªÓªÒµÊý¾Ý¾ÙÐб¸·Ý£¬±ÜÃâÊý¾ÝÆÆËð»òɥʧ¡£
Æß. ²úÆ··À»¤
Õë¶Ô´ËÀàÊÂÎñ£¬AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤/¼ì²âϵͳ(IPS/IDS)¡¢×ÛºÏÍþв̽Õ루UTS£©ÓëÏÂÒ»´ú·À»ðǽ £¨NF£©ÒÑÐû²¼¹æÔòÉý¼¶°ü¡£ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
²úÆ· |
Éý¼¶°ü°æ±¾ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
IPS/IDS¹æÔò°ü |
5.6.9.25418 5.6.10.25418 5.6.11.25418 |
http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.9 http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.10 http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.11 |
|
UTS¹æÔò°ü |
5.6.10.25418 |
http://update.nsfocus.com/update/listBsaUtsDetail/v/rule2.0.0 |
|
NF¹æÔò°ü |
6.0.1.850 6.0.2.850 |
http://update.nsfocus.com/update/listNewNfDetail/v/rule6.0.1 http://update.nsfocus.com/update/listNewNfDetail/v/rule6.0.2 |
°Ë. IOCs
835f242dde220cc76ee5544119562268
7d1807850275485397ce2bb218eff159
8cc83221870dd07144e63df594c391d9
Ö÷»úÌØÕ÷£º
%TEMP%\MsMpEng.exe
%TEMP%\Mpsvc.dl
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







