ÀÕË÷²¡¶¾¹¥»÷Ò½ÁÆ»ú¹¹Íø¹ØºÍVPNÊÂÎñͨ¸æ

Ðû²¼Ê±¼ä 2020-04-03

0x00 ÊÂÎñÅä¾°


REvil£¨ÓÖÃûΪSodinokibi£©ÀÕË÷²¡¶¾¿ËÈջƵÈÔ£¬£¬ £¬ £¬ËüÆð¾¢Ê¹ÓÃÍø¹ØºÍVPNµÄÎó²îÔÚÄ¿µÄ×éÖ¯ÖÐÕ¾ÎȽŸú¡£ ¡£¡£ÀÖ³ÉʹÓÃÎó²îºó£¬£¬ £¬ £¬¹¥»÷ÕßÔÚ×°ÖÃÀÕË÷Èí¼þ»òÆäËû¶ñÒâÈí¼þÓÐÓøºÔØÖ®Ç°£¬£¬ £¬ £¬»áÇÔȡƾ֤¡¢ÌáÉýȨÏÞ£¬£¬ £¬ £¬²¢ÔÚÄÚÍøºáÏòÒÆ¶¯ÒÔÈ·¼á³¤ÆÚÐÔ¡£ ¡£¡£Õâ¸öÅÅÃûÈ«ÇòµÚ5´óÀÕË÷²¡¶¾µ¥µ¥ÔÚÈ¥Äê¾ÍÏà¼ÌÈëÇÖÌṩ400¼ÒÒ½ÁÆÕïËùÔÚÏß±¸·ÝЧÀ͹«Ë¾ Digital Dental Record¡¢Â×¶ØÍâ»ãÉúÒ⹫˾ Travelex£¬£¬ £¬ £¬ÒÔ¼°ÃÀ¹úÊý¾ÝÖÐÐũӦÉÌ CyrusOne µÄÍøÂç²¢ÀÕË÷Êê½ð£¬£¬ £¬ £¬µ¼ÖÂЧÀÍÖÐÖ¹ºÍ¿Í»§Êý¾Ý±»¼ÓÃÜ¡£ ¡£¡£


Ä¿½ñÈ«ÇòÁýÕÖÔÚCOVID-19ÒßÇéµÄÒõÓ°Ï£¬£¬ £¬ £¬Ò½ÁÆ»ú¹¹±ÈÒÔÍùÈκÎʱ¼ä¶¼¸üÐèÒªÔöÇ¿¶ÔÄÚÍøµÄ·À»¤²½·¥£¬£¬ £¬ £¬ÒÔ¼°¸ü¶àµÄ¹Ø×¢Õë¶ÔÒªº¦ÏµÍ³¡¢¿Éµ¼ÖÂÃô¸ÐÐÅϢй¶µÄ¹¥»÷»î¶¯¡£ ¡£¡£Î¢ÈíÒ²Ê×´ÎÕë¶ÔÒ½ÁÆ»ú¹¹·¢³öÇ徲֪ͨ£¬£¬ £¬ £¬¹ØÓÚÀÕË÷²¡¶¾ REvil ¹¥»÷Ò½ÁÆ»ú¹¹µÄ¹¥»÷»î¶¯¡£ ¡£¡£


΢ÈíÖ¸³öREvil/SodinokibiÈ¥ÄêÒÔÀ´¹¥»÷ÊÖ·¨¶àÓÐÖØµþ£¬£¬ £¬ £¬¹¥»÷ÕßʹÓÃÄ¿½ñCOVID-19ÒßÇéÖØ¸´Ê¹ÓÃͬÑùµÄÃûÄ¿¡¢ÊÖÒÕºÍÊÖ·¨£¨tactics¡¢techniques£¬£¬ £¬ £¬procedure£¬£¬ £¬ £¬TTP£©·¢¶¯Ð¹¥»÷£¬£¬ £¬ £¬»ù±¾ÉÏûÓп´µ½Ê²Ã´ÊÖÒÕÁ¢Ò죬£¬ £¬ £¬×î¶àÖ»ÊÇʹÓÃÈËÃǿ־åÐÄÀíºÍ¶ÔÐÅÏ¢µÄÐèÇó¡£ ¡£¡£Õâ¸öÀÕË÷²¡¶¾±³ºóµÄºÚ¿Í×éÖ¯£¬£¬ £¬ £¬Ö÷ÒªËø¶¨ÏÖÔÚûÓÐʱ¼ä»ò×ÊÔ´À´ÉóÔÄÇå¾²·À»¤µÄ»ú¹¹£¬£¬ £¬ £¬Õë¶ÔÆäÇå¾²Èõµã·¢¶¯¹¥»÷À´»ñÈ¡ÀûÒæ¡£ ¡£¡£


΢ÈíûÓÐ˵Ã÷ÓÐÎó²îµÄVPN×°±¸³§ÉÌ£¬£¬ £¬ £¬µ«×î³£¼ûµÄÊÇPulse VPN¡£ ¡£¡£Ö®Ç°ÔâºÚ¿Í¹¥»÷µÄÂ×¶ØÍâ»ãÉúÒ⹫˾ Travelex£¬£¬ £¬ £¬¾ÍÒÉËÆÊÇÆäPulse VPNÎó²îδÐÞ²¹£¬£¬ £¬ £¬¶øÔâµ½SodinokibiÈëÇÖ¡£ ¡£¡£


0x01 ´¦Öóͷ£½¨Òé


½¨  Ò飺

¡ñ ½«ËùÓпÉÓõÄÇå¾²¸üÐÂÓ¦Óõ½VPNºÍ·À»ðǽ£»£»£»£»

¡ñ ¼à¿Ø²¢ÌØÊâ×¢ÖØ¿ÉÔ¶³Ì»á¼ûµÄϵͳºÍЧÀÍ£»£»£»£»

¡ñ ·­¿ªïÔÌ­¹¥»÷ÃæµÄ¹æÔò£¬£¬ £¬ £¬°üÀ¨×èֹƾ֤͵ÇÔºÍÀÕË÷²¡¶¾»î¶¯µÄ¹æÔò£»£»£»£»

¡ñ ÈôÊÇÄúÓÐOffice 365£¬£¬ £¬ £¬¿ÉÔÚOffice VBAÖз­¿ªAMSI¡£ ¡£¡£


ÔÝʱ²½·¥£º

¡ñ È·ÈÏ»¥ÁªÍø¿É»á¼ûµÄϵͳºÍÓ¦Óøüе½×îеIJ¹¶¡£¬£¬ £¬ £¬Ê¹ÓÃÍþвºÍÎó²îÖÎÀíϵͳ°´ÆÚÉóºËÕâЩ×ʲúµÄÎó²î¡¢¹ýʧÉèÖúͿÉÒÉÊÂÎñ£»£»£»£»

¡ñ Ê¹ÓÃAzure¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©µÈ½â¾ö¼Æ»®±£»£»£»£»¤Ô¶³Ì×ÀÃæÍø¹Ø¡£ ¡£¡£ÈôÊÇûÓÐMFAÍø¹Ø£¬£¬ £¬ £¬ÇëÆôÓÃÍøÂç¼¶Éí·ÝÑéÖ¤£¨NLA£©£»£»£»£»

¡ñ ÊµÑé×îÐ¡ÌØÈ¨Ô­Ôò£¬£¬ £¬ £¬×èֹʹÓÃÓò¹æÄ£µÄÖÎÀí¼¶Ð§ÀÍÕÊ»§£¬£¬ £¬ £¬Ç¿ÖÆÊ¹ÓÃËæ»úÖØ´óµÄÍâµØÖÎÀíÔ±ÃÜÂ룻£»£»£»

¡ñ ¼à¿Ø±©Á¦ÆÆ½â£¬£¬ £¬ £¬¼ì²é¹ý¶àʧ°ÜµÄÉí·ÝÑé֤ʵÑ飨WindowsÇå¾²ÊÂÎñID 4625£©

¡ñ ¼à¿ØÉ¨³ýÊÂÎñÈÕÖ¾£¬£¬ £¬ £¬ÌØÊâÊÇÇå¾²ÊÂÎñÈÕÖ¾ºÍPowerShell²Ù×÷ÈÕÖ¾£¬£¬ £¬ £¬Microsoft Defender ATP·¢³ö¾¯±¨¡°ÊÂÎñÈÕÖ¾ÒÑɨ³ý¡±£¬£¬ £¬ £¬±¬·¢´ËÇéÐÎʱ£¬£¬ £¬ £¬Windows½«ÌìÉúÊÂÎñID 1102£»£»£»£»

¡ñ È·¶¨ÌØÈ¨ÕÊ»§µÇ¼ºÍ¹ûÕæÆ¾Ö¤µÄλÖ㬣¬ £¬ £¬¼à¿ØºÍÊÓ²ìµÇ¼ÀàÐÍÊôÐԵĵǼÊÂÎñ£¨ÊÂÎñID 4624£©£¬£¬ £¬ £¬ÓòÖÎÀíÕÊ»§ºÍÆäËû¾ßÓи߼¶È¨ÏÞµÄÕÊ»§²»Ó¦·ºÆðÔÚÊÂÇéÕ¾ÉÏ£»£»£»£»

¡ñ ¾¡¿ÉÄÜʹÓÃWindows Defender·À»ðǽºÍÍøÂç·À»ðǽÀ´±ÜÃâ¶ËµãÖ®¼äµÄRPCºÍSMBͨѶ£¬£¬ £¬ £¬¿ÉÏÞÖÆÄÚÍøºáÏòÒÆ¶¯ºÍÆäËüµÄ¹¥»÷»î¶¯¡£ ¡£¡£


0x02 ²Î¿¼Á´½Ó


https://www.microsoft.com/security/blog/2020/04/01/microsoft-works-with-healthcare-organizations-to-protect-from-popular-ransomware-during-covid-19-crisis-heres-what-to-do/