ÀÕË÷²¡¶¾¹¥»÷Ò½ÁÆ»ú¹¹Íø¹ØºÍVPNÊÂÎñ¹«¸æ

°ä²¼¹¦·ò 2020-04-03

0x00 ÊÂÎñ²¼¾°


REvil£¨±ðÃûΪSodinokibi£©ÀÕË÷²¡¶¾½üÈջƵÈÔ£¬ £¬ £¬£¬£¬£¬£¬£¬Ëü»ý¼«ÀûÓÃÍø¹ØºÍVPNµÄ·ì϶ÔÚÖ¸±ê×éÖ¯ÖÐÕ¾ÎȽŸú¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓ÷ì϶ºó£¬ £¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ×°ÖÃÀÕË÷Èí¼þ»òÆäËû¶ñÒâÈí¼þÓÐЧ¸ºÔØÖ®Ç°£¬ £¬ £¬£¬£¬£¬£¬£¬»áÇÔȡʹ´¦¡¢ÌáÉýȨÏÞ£¬ £¬ £¬£¬£¬£¬£¬£¬²¢ÔÚÄÚÍøºáÏòÒÆ¶¯ÒÔÈ·Î¬ÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öÅÅÃûÈ«ÇòµÚ5´óÀÕË÷²¡¶¾µ¥µ¥ÔÚÈ¥Äê¾ÍÏà¼ÌÈëÇÖÌṩ400¼ÒÒ½ÁÆÕïµØµãÏß±¸·Ý·þÎñ¹«Ë¾ Digital Dental Record¡¢Â׶رí»ãÂòÂô¹«Ë¾ Travelex£¬ £¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°ÃÀ¹úÊý¾ÝÖÐÐĹ©¸øÉÌ CyrusOne µÄÍøÂç²¢ÀÕË÷Êê½ð£¬ £¬ £¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÖжϺͿͻ§Êý¾Ý±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£


µ±Ç°È«ÇòÁýÕÖÔÚCOVID-19ÒßÇéµÄÒõÓ°Ï£¬ £¬ £¬£¬£¬£¬£¬£¬Ò½ÁÆ»ú¹¹±ÈÒÔÍùÈκÎʱ³½¶¼¸ü±ØÒª¼ÓÇ¿¶ÔÄÚÍøµÄ·À»¤´ëÊ©£¬ £¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°¸ü¶àµÄ¹Ø×¢Õë¶Ô¹Ø¼üϵͳ¡¢¿Éµ¼ÖÂÃô¸ÐÐÅϢй¶µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÒ²³õ´ÎÕë¶ÔÒ½ÁÆ»ú¹¹·¢³ö°²È«Í¨Öª£¬ £¬ £¬£¬£¬£¬£¬£¬¹ØÓÚÀÕË÷²¡¶¾ REvil ¹¥»÷Ò½ÁÆ»ú¹¹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£


΢ÈíÖ¸³öREvil/SodinokibiÈ¥ÄêÒÔÀ´¹¥»÷ÊÖ·¨¶àÓгÁµþ£¬ £¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓõ±Ç°COVID-19ÒßÇé³Á¸´Ê¹ÓÃͬÑùµÄ¼¼Á©¡¢¼¼ÊõºÍÊÖ·¨£¨tactics¡¢techniques£¬ £¬ £¬£¬£¬£¬£¬£¬procedure£¬ £¬ £¬£¬£¬£¬£¬£¬TTP£©·¢Æðй¥»÷£¬ £¬ £¬£¬£¬£¬£¬£¬¸ù»ùÉÏûÓп´µ½Ê²Ã´¼¼Êõ´´Ð£¬ £¬ £¬£¬£¬£¬£¬£¬×î¶àÖ»ÊÇÀûÓÃÈËÃÇÕð¾ªÉúÀíºÍ¶ÔÐÅÏ¢µÄÐèÒª¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öÀÕË÷²¡¶¾±³ºóµÄºÚ¿Í×éÖ¯£¬ £¬ £¬£¬£¬£¬£¬£¬ÖØÒªËø¶¨Ä¿Ç°Ã»Óй¦·ò»ò×ÊÔ´À´ÉóÊÓ°²È«·À»¤µÄ»ú¹¹£¬ £¬ £¬£¬£¬£¬£¬£¬Õë¶ÔÆä°²È«Èõµã·¢Æð¹¥»÷À´»ñÈ¡ÀûÒæ¡£¡£¡£¡£¡£¡£¡£¡£


΢ÈíûÓÐ×¢Ã÷Óзì϶µÄVPNÉ豸³§ÉÌ£¬ £¬ £¬£¬£¬£¬£¬£¬µ«×î³£¼ûµÄÊÇPulse VPN¡£¡£¡£¡£¡£¡£¡£¡£Ö®Ç°ÔâºÚ¿Í¹¥»÷µÄÂ׶رí»ãÂòÂô¹«Ë¾ Travelex£¬ £¬ £¬£¬£¬£¬£¬£¬¾ÍÒÉËÆÊÇÆäPulse VPN·ì϶佨²¹£¬ £¬ £¬£¬£¬£¬£¬£¬¶øÔâµ½SodinokibiÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¡£


0x01 ´ëÖý¨Òé


½¨  Ò飺

¡ñ ½«ËùÓпÉÓõݲȫ¸üÐÂÀûÓõ½VPNºÍ·À»ðǽ£»£»£»£»£»£»

¡ñ ¼à¿Ø²¢³ö¸ñ°ÑÎÈ¿ÉÔ¶³Ì½Ó¼ûµÄϵͳºÍ·þÎñ£»£»£»£»£»£»

¡ñ ´ò¿ªÏ÷¼õ¹¥»÷ÃæµÄ¹æ¶¨£¬ £¬ £¬£¬£¬£¬£¬£¬Ô̺¬×èֹƾ֤͵ÇÔºÍÀÕË÷²¡¶¾»î¶¯µÄ¹æ¶¨£»£»£»£»£»£»

¡ñ ÈôÊÇÄúÓÐOffice 365£¬ £¬ £¬£¬£¬£¬£¬£¬¿ÉÔÚOffice VBAÖдò¿ªAMSI¡£¡£¡£¡£¡£¡£¡£¡£


һʱ´ëÊ©£º

¡ñ È·ÈÏ»¥ÁªÍø¿É½Ó¼ûµÄϵͳºÍÀûÓøüе½×îеIJ¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬ £¬ £¬£¬£¬£¬£¬£¬Ê¹ÓÃÍþвºÍ·ì϶ÖÎÀíϵͳ¶¨ÆÚÉóºËÕâЩ×ʲúµÄ·ì϶¡¢ÃýÎóÅäÖúͿÉÒÉÊÂÎñ£»£»£»£»£»£»

¡ñ Ê¹ÓÃAzure¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©µÈ½â¾ö¹æ»®±£»£»£»£»£»£»¤Ô¶³Ì×ÀÃæÍø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇûÓÐMFAÍø¹Ø£¬ £¬ £¬£¬£¬£¬£¬£¬ÇëÆôÓÃÍøÂç¼¶Éí·ÝÑéÖ¤£¨NLA£©£»£»£»£»£»£»

¡ñ ³¢ÊÔ×îÓ×ÌØÈ¨×¼Ôò£¬ £¬ £¬£¬£¬£¬£¬£¬Ô¤·ÀʹÓÃÓòÁìÓòµÄÖÎÀí¼¶·þÎñÕÊ»§£¬ £¬ £¬£¬£¬£¬£¬£¬Ç¿ÔìʹÓÃËæ»ú¸´Ôӵı¾µØÖÎÀíÔ±ÃÜÂ룻£»£»£»£»£»

¡ñ ¼à¿Ø±©Á¦ÆÆ½â£¬ £¬ £¬£¬£¬£¬£¬£¬²é³­¹ý¶àʧ°ÜµÄÉí·ÝÑéÖ¤³¢ÊÔ£¨Windows°²È«ÊÂÎñID 4625£©

¡ñ ¼à¿Ø¶Ï¸ùÊÂÎñÈÕÖ¾£¬ £¬ £¬£¬£¬£¬£¬£¬³ö¸ñÊǰ²È«ÊÂÎñÈÕÖ¾ºÍPowerShell²Ù×÷ÈÕÖ¾£¬ £¬ £¬£¬£¬£¬£¬£¬Microsoft Defender ATP·¢³ö¾¯±¨¡°ÊÂÎñÈÕÖ¾ÒѶϸù¡±£¬ £¬ £¬£¬£¬£¬£¬£¬²úÉú´ËÇé¿öʱ£¬ £¬ £¬£¬£¬£¬£¬£¬Windows½«ÌìÉúÊÂÎñID 1102£»£»£»£»£»£»

¡ñ È·¶¨ÌØÈ¨ÕÊ»§µÇ¼ºÍ¹«¿ªÍ´´¦µÄµØÎ»£¬ £¬ £¬£¬£¬£¬£¬£¬¼à¿ØºÍµ÷²éµÇ¼ÀàÐÍÊôÐԵĵǼÊÂÎñ£¨ÊÂÎñID 4624£©£¬ £¬ £¬£¬£¬£¬£¬£¬ÓòÖÎÀíÕÊ»§ºÍÆäËûÓµÓи߼¶È¨ÏÞµÄÕÊ»§²»Ó¦³Ê´Ë¿Ì¹¤×÷Õ¾ÉÏ£»£»£»£»£»£»

¡ñ ¾¡¿ÉÄÜÀûÓÃWindows Defender·À»ðǽºÍÍøÂç·À»ðǽÀ´Ô¤·À¶ËµãÖ®¼äµÄRPCºÍSMBͨѶ£¬ £¬ £¬£¬£¬£¬£¬£¬¿ÉÏÞ¶ÈÄÚÍøºáÏòÒÆ¶¯ºÍÆäËüµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£


0x02 ²Î¿¼Á´½Ó


https://www.microsoft.com/security/blog/2020/04/01/microsoft-works-with-healthcare-organizations-to-protect-from-popular-ransomware-during-covid-19-crisis-heres-what-to-do/