GA»Æ½ð¼×XDR£ºÕë¶ÔÃâɱC2¹¤¾ßµÄ³¡¾°»¯¼ì²âÀûÆ÷

°ä²¼¹¦·ò 2022-05-09

½üÄêÀ´ £¬´óÁ¿µÄºóÉøÈëÀûÓã¨Post-Exploitation£©¹¤¾ß°ü¡¢×Ô½ç˵¶ñÒâÈí¼þºÍ¿ªÔ´Ô¶³Ì½ÚÔìľÂí£¨RAT£©µÈ¾ß±¸·á˶µÄ¼ì²â¶ã±Ü¼¼ÊõºÍ·´ËÝÔ´ÄÜÁ¦µÄ¹¤¾ß £¬»îÔ¾ÓÚ¸÷ÀàʵսƥµÐÑÝÁ·¡¢ÀÕË÷¹¥»÷ÉõÖÁÊÇÓµÓйú¶È²¼¾°µÄAPT¹¥»÷Ö®ÖС£ÈëÇÖÕßÄܹ»Ê¹ÓÃÕâÀ๤¾ß½øÐÐÖÕ¶ËÐÐΪÒÔ¼°ÍøÂçͨѶÁ÷Á¿µÄÃâɱ¡£


ÔÚÕâÀྭ¹ýÉî¶ÈˢеÄÃâɱC2¹¤¾ß¿ÌÏ £¬»ð¼±±ØÒªÔ½·¢×³´óµÄЭͬ×÷Õ½ÌåÏ·´Ó³¶Ô¡£GA»Æ½ð¼×XDR¹æ»®ÊÇÒÔ½ôñîºÏ·½Ê½ÊµÏÖ¼±¾çÍþв¼ì²âºÍÏìÓ¦µÄ¹¤¾ß¼¯ £¬Í¨¹ýÆëÈ«¸²¸ÇÖÕ¶ËÍþв¼ì²âÓëÏìÓ¦£¨EDR£©¡¢¼ÓÃÜËí·¼ì²â¡¢È«Á÷Á¿È¡Ö¤·ÖÎö¡¢É³ÏäÑù±¾·ÖÎö¡¢¹¥»÷Á´»¹Ô­µÈÖ÷ÌâÄÜÁ¦ £¬ÓÐЧ¼ì²âºÍÀ¹½ØÖ÷Á÷ÃâɱC2¹¤¾ß¡£


±¾ÎÄÒÔCobalt StrikeΪÀý £¬¿´GA»Æ½ð¼×XDR¹æ»®ÈôºÎ¾«×¼ÄÃÄóËü¡££¨Cobalt Strike×÷Ϊһ¿îÉøÈë²âÊÔ¹¤¾ß £¬¼¯³ÉÁ˶àÖÖÖ°ÄÜ £¬ÓÖ³¤ÓÚ¡°ÍÅÕ½¡± £¬±»Òµ½çÈ˳ÆÎªCSÉñÆ÷¡££©


¡°Öն˲à+ÍøÂç²à¡±×óÓÒ¿ª¹­ ¾«×¼À¹½Ø¸÷ÀàÏÂÔØÐÐΪ


Cobalt Strike½«ÈëÇÖÖ´ÐеÄÄÚÈÝpayload²ð·ÖΪÁ½²¿ÃÅ £¬¼´stagerºÍstage£¨Ò²¾ÍÊÇbeacon£©¡£stagerͨ³£ÊǾ­¹ýÊÖ¹¤ÓÅ»¯µÄ»ã±àÖ¸Áî £¬ÓÃÓÚÏÂÔØshellcode £¬½âÃܳöbeacon²¢×¢ÈëÄÚ´æ £¬ÓÉbeaconÕÆ¹ÜºóÐøµÄC&CÓйع¤×÷ £¬Õû¸ö¹ý³Ì±»³ÆÎª¡°staging¡±¡£


¶ÔÓÚÏÂÔØÆ÷stager £¬GA»Æ½ð¼×XDR¹æ»®ÖеÄÁ÷Á¿¼ì²â¼°É³Ïä¼ì²âÖ°ÄÜÄܹ»ÕýÈ·¼ø±ð´ó²¿ÃÅstager¼°shellcodeµÄÏÂÔØÐÐΪ¡£


È»¶ø £¬¾­ÑéÀÏ·µÄÈëÇÖÕßͨ³£²»»áʹÓøù¥»÷¿ò¼ÜÔ­ÉúµÄstager £¬¶øÊÇʹÓÃ×Ô¼º¿ª·¢µÄ¹¤¾ß´úÌæstagerÏÂÔØÖ´ÐÐbeacon¡£


Ãæ¶ÔÕâÖÖÇé¾° £¬GA»Æ½ð¼×XDR¹æ»®Äܹ»´ÓÖÕ¶Ë²à½øÐмì²âÀ¹½Ø¡£stagerÔÚÂ䵨¹ý³ÌÖÐͨ³£³ÇÊÐÓÐshellcodeÏÂÔØ¡¢ÎļþÂ䵨¡¢ÄÚ´æ×¢ÈëÐÐΪ¡£GA»Æ½ð¼×EDRͨ¹ý¹¹½¨ÖÕ¶ËÐÐΪ»ùÏß £¬¶ÔÕâÀàʱÐòÃýÎóÐÐΪ¡¢»ùÏ߯«ÀëÐÐΪ½øÐмì²â·À»¤ £¬²¢Æ¾½è×ÔÉíÓÐЧ¹ý³Ì¼¶¼à¿Ø²É¼¯ÓëÍþвÑÐÅÄîÜÁ¦ £¬¹¹½¨Öն˵ǽÁ÷Ë®¡¢¹ý³Ì¿ìÕÕ¡¢ÕʺſìÕÕµÈ £¬ÊµÊ±·¢ÏÖÕÊ»§ÌáȨ¼°¹ý³ÌÌáȨÐÐΪ¡¢Ô¤¾¯·çÏյ㡢ÃÀÂú²É¼¯ÐÅÏ¢ £¬ÎªºóÐøÍþвËÝÔ´ÌṩÓÐÁ¦Ö§³Ö¡£


»úе½ø½¨ÖúÁ¦ ¾«×¼¼ø±ð¼ÓÃÜËí·


Cobalt Strike BeaconÂ䵨ºó £¬»á³ÉÁ¢C2Ëí· £¬¶¨ÆÚ·¢ËÍÐÄÌø°üÓë·þÎñÆ÷ͨѶ £¬ÆÚ´ý»ñÈ¡ºóÐøÈëÇÖÖ¸Áî¡£ÔÚÖն˲à £¬GA»Æ½ð¼×EDRͨ¹ýºÅÁîÖ´ÐÐÄÚÈÝÑÐÅм°·´µ¯ÏνÓÐÐΪÑÐÅÐ £¬¶ÔC2Ëí·³ÖÐø¼à¿ØºÍʵʱԤ¾¯£»ÔÚÍøÂç²à £¬GA»Æ½ð¼×XDR¹æ»®ÖеÄÁ÷Á¿¼ì²âÒýÇæ¿É¶Ô¸ß¶È¶¨Ô컯µÄHTTP Beacon¡¢HTTPS Beacon¼°DNS Beacon½øÐÐÓÐЧ¼ì²â¡£


¶ÔÓÚHTTP Beacon £¬ÈëÇÖÕßÄܹ»×ÔÓɵØÅú¸ÄÅäÖÃÎļþÀ´½øÐи߶È×Ô½ç˵»¯µÄÅäÖà £¬ÉõÖÁÄܹ»½«Í¨Ñ¶Á÷Á¿¼Ù×°³ÉÆäËüÕý³£ÀûÓÃÍøÕ¾µÄ½Ó¼ûÁ÷Á¿ £¬ÒÔ¶ã±ÜÁ÷Á¿°²È«Éó²éºÍ¼ì²â¡£GA»Æ½ð¼×XDR¹æ»®Í¨¹ý·º»¯´¦ÖÃÒªÇóÍ·µÄ·ÖÆç²¿ÃÅ £¬ÈçÒªÇó²½Öèmethod¡¢url½á¹¹¡¢ÒªÇóÍ·¼¯ÖеÈ £¬¾ÛÀà³öHTTP BeaconµÄÒªÇóÄ£°å £¬²¢Æ¾¾Ýÿ¸öÄ£°å×é¼þµÄ³ÊÏÔìµÂÊ £¬·ÖÅä·ÖÆç·ÖÖµ¡£Í¬Ê±½áºÏÊ¢ÐÐÎªÌØµãÍÆËãÊ¢ÐÐΪ·ÖÖµ¡£×îºóƾ¾ÝÒªÇóÄ£°å¡¢Ê¢ÐÐΪµÄ¸÷×ÔȨ³Á×ö³ö×ÛºÏÅж¨ £¬µÃµ½·º»¯ÄÜÁ¦½ÏÇ¿µÄHTTP Beacon¼ì²âÄ£ÐÍ¡£


¶ÔÓÚHTTPS Beacon £¬ÈëÇÖÕß»á½èÖúCDN½ÓÈë·þÎñ»òÓòǰÖü¼Êõ½«Á÷Á¿×ªÖÁÕæÊµC2·þÎñÆ÷ £¬ÒÔ¶ã±ÜÁ÷Á¿Éó²é¡£GA»Æ½ð¼×XDR¹æ»®Í¨¹ýÖ¸ÎÆ¡¢SNI¡¢Ö¤Ê顢ʢÐÐΪµÈ¶à¸öά¶ÈÕë¶Ô´óÁ¿¶ñÒâÁ÷Á¿½øÇ°½ø½¨ £¬ÓÐЧ¼ø±ðʹÓÃCDN¡¢Ãâ·ÑÖ¤Êé¡¢APIµÈ·½Ê½µÄHTTPS Beacon £¬²¢¶ÔÓòǰÖü¼Êõ½øÐÐÉî¿Ì×êÑÐ £¬ÌáȡͨÓÃÓòǰÖüø±ð²½Öè £¬ÄÜ×î´óÏ޶ȼì²âÓòǰÖÃÈëÇÖ¡£


¶ÔÓÚDNS Beacon £¬ÈëÇÖÕßͨ¹ýÊÕÊÜij¸öÓòÃû½âÎö £¬Ê¹µÃ¶Ô¸ÃÓòÃûµÄËùÓÐ×ÓÓò½âÎöÒªÇó×îÖÕ´ïµ½C2·þÎñÆ÷ÉÏ £¬¶øºóÀûÓÃDNSÒªÇóºÍÏìÓ¦À´³ÐÔØ¾­¹ý±àÂë»ò¼ÓÃܵÄÊý¾ÝÄÚÈÝ¡£GA»Æ½ð¼×XDR¹æ»®Õë¶ÔDNSËí·ÓëÕý³£DNSÒªÇóµÄ²î¾àÐÔ £¬È磺ҪÇó´óÓס¢ÒªÇóÓòÃû¡¢ÒªÇó¾àÀ롢Ƶ´ÎµÈ¶à¸öά¶È³éÈ¡ÌØµãÏòÁ¿½øÐлúе½ø½¨¼ø±ð £¬µÃµ½·º»¯ÄÜÁ¦½ÏÇ¿µÄDNS Beacon¼ì²âÄ£ÐÍ¡£


ÆëÈ«»¹Ô­¹¥»÷Á´ ÈëÇÖ×ã¼£ÎÞ´¦ÌÓÐÎ


1.png


GA»Æ½ð¼×XDR¹æ»®Æ¾½è¶ÀÓеĹ¥»÷Á´»¹Ô­Ö°ÄÜ £¬Í¨¹ýÏßË÷·¢ÏÖ¡¢À©Ïß¹ØÁª¡¢¹¥»÷Ä£ÐÍÓ³ÉäÈý¸öÖØÒª²½Öè £¬Ô®ÊÖÓû§¿ÉÊÓ»¯»¹Ô­³öÆëÈ«µÄ¹¥»÷Á´Â·Í¼ £¬ÕÒµ½ÈëÇÖõè¾¶¼°ÏµÍ³´àÈõÐÔ»·½Ú £¬¼±¾çÏàʶÔì³ÉÈëÇÖÊÂÎñµÄÔ­Òò¡¢¹¥»÷Ô´¡¢ºóÐø²Ù×÷¡¢ËðʧÁìÓò £¬¾«×¼·Ö½âÈëÇÖÊÂÎñ £¬¾ßÌåÃèÊöÈëÇÖÊÖ·¨ £¬Ô¤²âÈëÇÖÕßÖ÷ÕÅÓë´òËã¡£


ÏßË÷·¢ÏÖ¼´È·¶¨ÐÔÏßË÷ºÍ·ÇÈ·¶¨ÐÔÏßË÷µÄ¹ØÁª¹ý³Ì¡£È·¶¨ÐÔÏßË÷¼´ÍøÂç²à¡¢Öն˲àÈ·¶¨ÈëÇֳɹ¦²¢ÇÒÄÜÏ໥ӡ֤µÄÕýÈ·ÏßË÷¡£·ÇÈ·¶¨ÐÔÏßË÷¼´ÔÚÍøÂç²à¡¢Öն˲෢ÏֵIJ»ÄÜÈ·¶¨ÊÇ·ñÈëÇֳɹ¦µÄ¸¨ÖúÏßË÷¡£È·¶¨ÐÔÏßË÷Óë·ÇÈ·¶¨ÐÔÏßË÷½øÐÐÀ©Ïß¹ØÁªºó £¬GA»Æ½ð¼×XDR¹æ»®»áÒÀÕÕ¹¦·ò¡¢ÈëÇÖÕßÊܺ¦Õß¹ØÏµ¡¢ATT&CKÄ£ÐÍÓ³ÉäÄâºÏµÈ½«¸÷¸öÀ©ÏßʵÏֵĹ¥»÷ÏßË÷´®Áª³ÉÆëÈ«µÄ¹¥»÷Á´ £¬ÔÙ½áºÏÈËΪȷÈÏ¡¢¼ôÖ¦µÈ´¦Öùý³Ì×îÖÕÐγɶÔÕû¸öÈëÇÖÊÂÎñµÄÃèÊö¡£


GA»Æ½ð¼×XDR¹æ»®¼áÊØ´´Ð £¬Õë¶Ô¼à¹Ü²à¡¢¹Ø»ù¡¢¹¤Òµ»¥ÁªÍø¡¢µ±¾Ö¡¢¼¯ÍÅÐÍÆóÒµµÈ³ÁµãÀûÓó¡¾°µÄ¸ß¼¶Íþв¼ì²âÓë·À»¤ÐèÒª £¬Í¨¹ýÕûºÏÍøÂç²à¼°Öն˲àÊÂÎñºÍµý±¨ÐÅÏ¢ £¬×ÛºÏÀûÓÃ×Ô¶¯È¡Ö¤ºÍÍØÏß¼¼Êõ £¬ÒÔϵͳ»¯·½Ê½ÊµÏֶԸ߼¶Íþв»òÈëÇֵļ±¾ç¾«×¼¼ì²âºÍÏìÓ¦ £¬½øÒ»²½Ìá¸ßÓû§µÄ×ÝÉî·ÀÓù³ÉЧ¡£