ÀÕË÷²¡¶¾¹¥»÷Ò½ÁÆ»ú¹¹Íø¹ØºÍVPNÊÂÎñͨ¸æ
Ðû²¼Ê±¼ä 2020-04-030x00 ÊÂÎñÅä¾°
REvil£¨ÓÖÃûΪSodinokibi£©ÀÕË÷²¡¶¾¿ËÈÕÔ˶¯ÆµÈÔ£¬ËüÆð¾¢Ê¹ÓÃÍø¹ØºÍVPNµÄÎó²îÔÚÄ¿µÄ×éÖ¯ÖÐÕ¾ÎȽŸú¡£ÀÖ³ÉʹÓÃÎó²îºó£¬¹¥»÷ÕßÔÚ×°ÖÃÀÕË÷Èí¼þ»òÆäËû¶ñÒâÈí¼þÓÐÓøºÔØÖ®Ç°£¬»áÇÔȡƾ֤¡¢ÌáÉýȨÏÞ£¬²¢ÔÚÄÚÍøºáÏòÒÆ¶¯ÒÔÈ·¼á³¤ÆÚÐÔ¡£Õâ¸öÅÅÃûÈ«ÇòµÚ5´óÀÕË÷²¡¶¾µ¥µ¥ÔÚÈ¥Äê¾ÍÏà¼ÌÈëÇÖÌṩ400¼ÒÒ½ÁÆÕïËùÔÚÏß±¸·Ý·þÎñ¹«Ë¾ Digital Dental Record¡¢Â×¶ØÍâ»ãÉúÒ⹫˾ Travelex£¬ÒÔ¼°ÃÀ¹úÊý¾ÝÖÐÐũӦÉÌ CyrusOne µÄÍøÂç²¢ÀÕË÷Êê½ð£¬µ¼Ö·þÎñÖÐÖ¹ºÍ¿Í»§Êý¾Ý±»¼ÓÃÜ¡£
Ä¿½ñÈ«ÇòÁýÕÖÔÚCOVID-19ÒßÇéµÄÒõÓ°Ï£¬Ò½ÁÆ»ú¹¹±ÈÒÔÍùÈκÎʱ¼ä¶¼¸üÐèÒªÔöÇ¿¶ÔÄÚÍøµÄ·À»¤²½·¥£¬ÒÔ¼°¸ü¶àµÄ¹Ø×¢Õë¶ÔÒªº¦ÏµÍ³¡¢¿Éµ¼ÖÂÃô¸ÐÐÅϢй¶µÄ¹¥»÷Ô˶¯¡£Î¢ÈíÒ²Ê×´ÎÕë¶ÔÒ½ÁÆ»ú¹¹·¢³öÇ徲֪ͨ£¬¹ØÓÚÀÕË÷²¡¶¾ REvil ¹¥»÷Ò½ÁÆ»ú¹¹µÄ¹¥»÷Ô˶¯¡£
΢ÈíÖ¸³öREvil/SodinokibiÈ¥ÄêÒÔÀ´¹¥»÷ÊÖ·¨¶àÓÐÖØµþ£¬¹¥»÷ÕßʹÓÃÄ¿½ñCOVID-19ÒßÇéÖØ¸´Ê¹ÓÃͬÑùµÄÃûÄ¿¡¢ÊÖÒÕºÍÊÖ·¨£¨tactics¡¢techniques£¬procedure£¬TTP£©·¢¶¯Ð¹¥»÷£¬»ù±¾ÉÏûÓп´µ½Ê²Ã´ÊÖÒÕÁ¢Ò죬×î¶àÖ»ÊÇʹÓÃÈËÃǿ־åÐÄÀíºÍ¶ÔÐÅÏ¢µÄÐèÇó¡£Õâ¸öÀÕË÷²¡¶¾±³ºóµÄºÚ¿Í×éÖ¯£¬Ö÷ÒªËø¶¨ÏÖÔÚûÓÐʱ¼ä»ò×ÊÔ´À´ÉóÔÄÇå¾²·À»¤µÄ»ú¹¹£¬Õë¶ÔÆäÇå¾²Èõµã·¢¶¯¹¥»÷À´»ñÈ¡ÀûÒæ¡£
΢ÈíûÓÐ˵Ã÷ÓÐÎó²îµÄVPN×°±¸³§ÉÌ£¬µ«×î³£¼ûµÄÊÇPulse VPN¡£Ö®Ç°ÔâºÚ¿Í¹¥»÷µÄÂ×¶ØÍâ»ãÉúÒ⹫˾ Travelex£¬¾ÍÒÉËÆÊÇÆäPulse VPNÎó²îδÐÞ²¹£¬¶øÔâµ½SodinokibiÈëÇÖ¡£
0x01 ´¦Öóͷ£½¨Òé
½¨ Ò飺
¡ñ ½«ËùÓпÉÓõÄÇå¾²¸üÐÂÓ¦Óõ½VPNºÍ·À»ðǽ£»
¡ñ ¼à¿Ø²¢ÌØÊâ×¢ÖØ¿ÉÔ¶³Ì»á¼ûµÄϵͳºÍ·þÎñ£»
¡ñ ·¿ªïÔ̹¥»÷ÃæµÄ¹æÔò£¬°üÀ¨×èֹƾ֤͵ÇÔºÍÀÕË÷²¡¶¾Ô˶¯µÄ¹æÔò£»
¡ñ ÈôÊÇÄúÓÐOffice 365£¬¿ÉÔÚOffice VBAÖз¿ªAMSI¡£
ÔÝʱ²½·¥£º
¡ñ È·ÈÏ»¥ÁªÍø¿É»á¼ûµÄϵͳºÍÓ¦Óøüе½×îеIJ¹¶¡£¬Ê¹ÓÃÍþвºÍÎó²îÖÎÀíϵͳ°´ÆÚÉóºËÕâЩ×ʲúµÄÎó²î¡¢¹ýʧÉèÖúͿÉÒÉÊÂÎñ£»
¡ñ ʹÓÃAzure¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©µÈ½â¾ö¼Æ»®±£»¤Ô¶³Ì×ÀÃæÍø¹Ø¡£ÈôÊÇûÓÐMFAÍø¹Ø£¬ÇëÆôÓÃÍøÂç¼¶Éí·ÝÑéÖ¤£¨NLA£©£»
¡ñ ʵÑé×îÐ¡ÌØÈ¨ÔÔò£¬×èֹʹÓÃÓò¹æÄ£µÄÖÎÀí¼¶·þÎñÕÊ»§£¬Ç¿ÖÆÊ¹ÓÃËæ»úÖØ´óµÄÍâµØÖÎÀíÔ±ÃÜÂ룻
¡ñ ¼à¿Ø±©Á¦ÆÆ½â£¬¼ì²é¹ý¶àʧ°ÜµÄÉí·ÝÑé֤ʵÑ飨WindowsÇå¾²ÊÂÎñID 4625£©
¡ñ ¼à¿ØÉ¨³ýÊÂÎñÈÕÖ¾£¬ÌØÊâÊÇÇå¾²ÊÂÎñÈÕÖ¾ºÍPowerShell²Ù×÷ÈÕÖ¾£¬Microsoft Defender ATP·¢³ö¾¯±¨¡°ÊÂÎñÈÕÖ¾ÒÑɨ³ý¡±£¬±¬·¢´ËÇéÐÎʱ£¬Windows½«ÌìÉúÊÂÎñID 1102£»
¡ñ È·¶¨ÌØÈ¨ÕÊ»§µÇ¼ºÍ¹ûÕæÆ¾Ö¤µÄλÖã¬¼à¿ØºÍÊÓ²ìµÇ¼ÀàÐÍÊôÐԵĵǼÊÂÎñ£¨ÊÂÎñID 4624£©£¬ÓòÖÎÀíÕÊ»§ºÍÆäËû¾ßÓи߼¶È¨ÏÞµÄÕÊ»§²»Ó¦·ºÆðÔÚÊÂÇéÕ¾ÉÏ£»
¡ñ ¾¡¿ÉÄÜʹÓÃWindows Defender·À»ðǽºÍÍøÂç·À»ðǽÀ´±ÜÃâ¶ËµãÖ®¼äµÄRPCºÍSMBͨѶ£¬¿ÉÏÞÖÆÄÚÍøºáÏòÒÆ¶¯ºÍÆäËüµÄ¹¥»÷Ô˶¯¡£
0x02 ²Î¿¼Á´½Ó
https://www.microsoft.com/security/blog/2020/04/01/microsoft-works-with-healthcare-organizations-to-protect-from-popular-ransomware-during-covid-19-crisis-heres-what-to-do/


¾©¹«Íø°²±¸11010802024551ºÅ