ÀÕË÷²¡¶¾¹¥»÷Ò½ÁÆ»ú¹¹Íø¹ØºÍVPNÊÂÎñ¹«¸æ
°ä²¼¹¦·ò 2020-04-030x00 ÊÂÎñ²¼¾°
REvil£¨±ðÃûΪSodinokibi£©ÀÕË÷²¡¶¾½üÈջƵÈÔ£¬Ëü»ý¼«ÀûÓÃÍø¹ØºÍVPNµÄ·ì϶ÔÚÖ¸±ê×éÖ¯ÖÐÕ¾ÎȽŸú¡£³É¹¦ÀûÓ÷ì϶ºó£¬¹¥»÷ÕßÔÚ×°ÖÃÀÕË÷Èí¼þ»òÆäËû¶ñÒâÈí¼þÓÐЧ¸ºÔØÖ®Ç°£¬»áÇÔȡʹ´¦¡¢ÌáÉýȨÏÞ£¬²¢ÔÚÄÚÍøºáÏòÒÆ¶¯ÒÔÈ·Î¬ÓÆ¾ÃÐÔ¡£Õâ¸öÅÅÃûÈ«ÇòµÚ5´óÀÕË÷²¡¶¾µ¥µ¥ÔÚÈ¥Äê¾ÍÏà¼ÌÈëÇÖÌṩ400¼ÒÒ½ÁÆÕïµØµãÏß±¸·Ý·þÎñ¹«Ë¾ Digital Dental Record¡¢Â׶رí»ãÂòÂô¹«Ë¾ Travelex£¬ÒÔ¼°ÃÀ¹úÊý¾ÝÖÐÐĹ©¸øÉÌ CyrusOne µÄÍøÂç²¢ÀÕË÷Êê½ð£¬µ¼Ö·þÎñÖжϺͿͻ§Êý¾Ý±»¼ÓÃÜ¡£
µ±Ç°È«ÇòÁýÕÖÔÚCOVID-19ÒßÇéµÄÒõÓ°Ï£¬Ò½ÁÆ»ú¹¹±ÈÒÔÍùÈκÎʱ³½¶¼¸ü±ØÒª¼ÓÇ¿¶ÔÄÚÍøµÄ·À»¤´ëÊ©£¬ÒÔ¼°¸ü¶àµÄ¹Ø×¢Õë¶Ô¹Ø¼üϵͳ¡¢¿Éµ¼ÖÂÃô¸ÐÐÅϢй¶µÄ¹¥»÷»î¶¯¡£Î¢ÈíÒ²³õ´ÎÕë¶ÔÒ½ÁÆ»ú¹¹·¢³ö°²È«Í¨Öª£¬¹ØÓÚÀÕË÷²¡¶¾ REvil ¹¥»÷Ò½ÁÆ»ú¹¹µÄ¹¥»÷»î¶¯¡£
΢ÈíÖ¸³öREvil/SodinokibiÈ¥ÄêÒÔÀ´¹¥»÷ÊÖ·¨¶àÓгÁµþ£¬¹¥»÷ÕßÀûÓõ±Ç°COVID-19ÒßÇé³Á¸´Ê¹ÓÃͬÑùµÄ¼¼Á©¡¢¼¼ÊõºÍÊÖ·¨£¨tactics¡¢techniques£¬procedure£¬TTP£©·¢Æðй¥»÷£¬¸ù»ùÉÏûÓп´µ½Ê²Ã´¼¼Êõ´´Ð£¬×î¶àÖ»ÊÇÀûÓÃÈËÃÇÕð¾ªÉúÀíºÍ¶ÔÐÅÏ¢µÄÐèÒª¡£Õâ¸öÀÕË÷²¡¶¾±³ºóµÄºÚ¿Í×éÖ¯£¬ÖØÒªËø¶¨Ä¿Ç°Ã»Óй¦·ò»ò×ÊÔ´À´ÉóÊÓ°²È«·À»¤µÄ»ú¹¹£¬Õë¶ÔÆä°²È«Èõµã·¢Æð¹¥»÷À´»ñÈ¡ÀûÒæ¡£
΢ÈíûÓÐ×¢Ã÷Óзì϶µÄVPNÉ豸³§ÉÌ£¬µ«×î³£¼ûµÄÊÇPulse VPN¡£Ö®Ç°ÔâºÚ¿Í¹¥»÷µÄÂ׶رí»ãÂòÂô¹«Ë¾ Travelex£¬¾ÍÒÉËÆÊÇÆäPulse VPN·ì϶佨²¹£¬¶øÔâµ½SodinokibiÈëÇÖ¡£
0x01 ´ëÖý¨Òé
½¨ Ò飺
¡ñ ½«ËùÓпÉÓõݲȫ¸üÐÂÀûÓõ½VPNºÍ·À»ðǽ£»
¡ñ ¼à¿Ø²¢³ö¸ñ°ÑÎÈ¿ÉÔ¶³Ì½Ó¼ûµÄϵͳºÍ·þÎñ£»
¡ñ ´ò¿ªÏ÷¼õ¹¥»÷ÃæµÄ¹æ¶¨£¬Ô̺¬×èֹƾ֤͵ÇÔºÍÀÕË÷²¡¶¾»î¶¯µÄ¹æ¶¨£»
¡ñ ÈôÊÇÄúÓÐOffice 365£¬¿ÉÔÚOffice VBAÖдò¿ªAMSI¡£
һʱ´ëÊ©£º
¡ñ È·ÈÏ»¥ÁªÍø¿É½Ó¼ûµÄϵͳºÍÀûÓøüе½×îеIJ¹¶¡£¬Ê¹ÓÃÍþвºÍ·ì϶ÖÎÀíϵͳ¶¨ÆÚÉóºËÕâЩ×ʲúµÄ·ì϶¡¢ÃýÎóÅäÖúͿÉÒÉÊÂÎñ£»
¡ñ ʹÓÃAzure¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©µÈ½â¾ö¹æ»®±£»¤Ô¶³Ì×ÀÃæÍø¹Ø¡£ÈôÊÇûÓÐMFAÍø¹Ø£¬ÇëÆôÓÃÍøÂç¼¶Éí·ÝÑéÖ¤£¨NLA£©£»
¡ñ ³¢ÊÔ×îÓ×ÌØÈ¨×¼Ôò£¬Ô¤·ÀʹÓÃÓòÁìÓòµÄÖÎÀí¼¶·þÎñÕÊ»§£¬Ç¿ÔìʹÓÃËæ»ú¸´Ôӵı¾µØÖÎÀíÔ±ÃÜÂ룻
¡ñ ¼à¿Ø±©Á¦ÆÆ½â£¬²é³¹ý¶àʧ°ÜµÄÉí·ÝÑéÖ¤³¢ÊÔ£¨Windows°²È«ÊÂÎñID 4625£©
¡ñ ¼à¿Ø¶Ï¸ùÊÂÎñÈÕÖ¾£¬³ö¸ñÊǰ²È«ÊÂÎñÈÕÖ¾ºÍPowerShell²Ù×÷ÈÕÖ¾£¬Microsoft Defender ATP·¢³ö¾¯±¨¡°ÊÂÎñÈÕÖ¾ÒѶϸù¡±£¬²úÉú´ËÇé¿öʱ£¬Windows½«ÌìÉúÊÂÎñID 1102£»
¡ñ È·¶¨ÌØÈ¨ÕÊ»§µÇ¼ºÍ¹«¿ªÍ´´¦µÄµØÎ»£¬¼à¿ØºÍµ÷²éµÇ¼ÀàÐÍÊôÐԵĵǼÊÂÎñ£¨ÊÂÎñID 4624£©£¬ÓòÖÎÀíÕÊ»§ºÍÆäËûÓµÓи߼¶È¨ÏÞµÄÕÊ»§²»Ó¦³Ê´Ë¿Ì¹¤×÷Õ¾ÉÏ£»
¡ñ ¾¡¿ÉÄÜÀûÓÃWindows Defender·À»ðǽºÍÍøÂç·À»ðǽÀ´Ô¤·À¶ËµãÖ®¼äµÄRPCºÍSMBͨѶ£¬¿ÉÏÞ¶ÈÄÚÍøºáÏòÒÆ¶¯ºÍÆäËüµÄ¹¥»÷»î¶¯¡£
0x02 ²Î¿¼Á´½Ó
https://www.microsoft.com/security/blog/2020/04/01/microsoft-works-with-healthcare-organizations-to-protect-from-popular-ransomware-during-covid-19-crisis-heres-what-to-do/


¾©¹«Íø°²±¸11010802024551ºÅ