{"id":1557,"date":"2021-12-10T11:25:19","date_gmt":"2021-12-10T03:25:19","guid":{"rendered":"https:\/\/blog.billows.com.tw\/?p=1557"},"modified":"2021-12-10T11:37:25","modified_gmt":"2021-12-10T03:37:25","slug":"emotet-%e6%94%b9%e8%ae%8a%e7%ad%96%e7%95%a5%ef%bc%8c%e8%b7%b3%e9%81%8e%e4%b8%ad%e9%96%93%e7%9a%84%e6%9c%a8%e9%a6%ac%e7%a8%8b%e5%bc%8f%ef%bc%8c%e7%9b%b4%e6%8e%a5%e6%8a%95%e6%94%becobalt-strike%e7%9a%84","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=1557","title":{"rendered":"Emotet \u6539\u8b8a\u7b56\u7565\uff0c\u8df3\u904e\u4e2d\u9593\u7684\u6728\u99ac\u7a0b\u5f0f\uff0c\u76f4\u63a5\u6295\u653eCobalt Strike\u7684Beacon"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"599\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/12\/image-7.png\" alt=\"\" class=\"wp-image-1558\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/12\/image-7.png 865w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/12\/image-7-300x208.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/12\/image-7-768x532.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><\/figure>\n\n\n\n<p>Emotet\u7684<a href=\"https:\/\/blog.billows.com.tw\/?p=1505\">\u56de\u6b78<\/a>\u662f\u4e00\u500b\u5de8\u5927\u7684\u5a01\u8105\uff0c\u540c\u6642\u5b83\u7684\u767c\u5c55\u4e5f\u4ee4\u4eba\u64d4\u6182\uff0c\u5728\u904e\u53bbEmotet\u6703\u5728\u53d7\u611f\u67d3\u7684\u8a2d\u5099\u4e0a\u5b89\u88ddTrickBot\u6216Qbot\u6728\u99ac\uff0c\u9032\u800c\u5728\u53d7\u611f\u67d3\u7684\u7cfb\u7d71\u4e0a\u90e8\u7f72 Cobalt Strike\u3002\u5728\u5178\u578b\u7684\u653b\u64ca\u4e2d\uff0c\u53d7\u5bb3\u8005\u5728\u6700\u521d\u611f\u67d3\u548c\u88ab\u90e8\u7f72\u52d2\u7d22\u8edf\u9ad4\u4e4b\u9593\u6703\u6709\u5927\u7d04\u4e00\u500b\u6708\u7684\u6642\u9593\u3002\u4f46\u73fe\u5728\u7814\u7a76\u4eba\u54e1\u767c\u73fe\u7531\u65bcEmotet\u8df3\u904e\u4e86\u4e2d\u9593\u6728\u99acTrickBot \u548c Qbot \u7684\u521d\u59cb\u6709\u6548\u8ca0\u8f09\uff0c\u99ed\u5ba2\u5c07\u53ef\u7acb\u5373\u5b58\u53d6\u7db2\u8def\u3001\u6a6b\u5411\u50b3\u64ad\u3001\u5feb\u901f\u90e8\u7f72\u52d2\u7d22\u8edf\u9ad4\u4e26\u7aca\u53d6\u6578\u64da\uff0c\u9019\u81ea\u7136\u610f\u5473\u8457\u5f9e Emotet \u611f\u67d3\u5230\u52d2\u7d22\u8edf\u9ad4\u653b\u64ca\u7684\u6642\u9593\u5927\u5927\u7e2e\u77ed\u3002\u64da\u6089\uff0cEmotet\u7684\u6372\u571f\u91cd\u4f86\uff0c\u662f\u7531\u64cd\u4f5cConti\u52d2\u7d22\u8edf\u9ad4\u7684\u99ed\u5ba2\u63a8\u6ce2\u52a9\u703e\u7684\uff0c\u800cCobalt Strike\u7684Beacon\u5feb\u901f\u5b89\u88dd\u6709\u671b\u52a0\u901f\u52d2\u7d22\u8edf\u9ad4\u7684\u90e8\u7f72\u3002<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8\ud83d\udea8WARNING \ud83d\udea8\ud83d\udea8 We have confirmed that <a href=\"https:\/\/twitter.com\/hashtag\/Emotet?src=hash&amp;ref_src=twsrc%5Etfw\">#Emotet<\/a> is dropping CS Beacons on E5 Bots and we have observed the following as of 10:00EST\/15:00UTC.  The following beacon was dropped: <a href=\"https:\/\/t.co\/imJDQTGqxV\">https:\/\/t.co\/imJDQTGqxV<\/a> Note the traffic to lartmana[.]com. This is an active CS Teams Server. 1\/x<\/p>&mdash; Cryptolaemus (@Cryptolaemus1) <a href=\"https:\/\/twitter.com\/Cryptolaemus1\/status\/1468266929014157316?ref_src=twsrc%5Etfw\">December 7, 2021<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>\u6e1b\u5c11\u653b\u64ca\u93c8\u5c07\u4f7f\u99ed\u5ba2\u80fd\u5920\u901f\u9032\u5165\u653b\u64ca\u7684\u7b2c\u4e8c\u968e\u6bb5\uff0c\u4f8b\u5982\u5728\u53d7\u611f\u67d3\u7684\u7db2\u8def\u4e0a\u5b89\u88dd\u52d2\u7d22\u8edf\u9ad4\u3002<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8\ud83d\udea8WARNING \ud83d\udea8\ud83d\udea8 We have confirmed that <a href=\"https:\/\/twitter.com\/hashtag\/Emotet?src=hash&amp;ref_src=twsrc%5Etfw\">#Emotet<\/a> is dropping CS Beacons on E5 Bots and we have observed the following as of 10:00EST\/15:00UTC.  The following beacon was dropped: <a href=\"https:\/\/t.co\/imJDQTGqxV\">https:\/\/t.co\/imJDQTGqxV<\/a> Note the traffic to lartmana[.]com. This is an active CS Teams Server. 1\/x<\/p>&mdash; Cryptolaemus (@Cryptolaemus1) <a href=\"https:\/\/twitter.com\/Cryptolaemus1\/status\/1468266929014157316?ref_src=twsrc%5Etfw\">December 7, 2021<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>\u8cc7\u5b89\u516c\u53f8 Cofense \u8207<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-now-drops-cobalt-strike-fast-forwards-ransomware-attacks\/\">Bleeping Computer<\/a>\u5171\u4eab\u7684 Flash Alert\u4e2d\u8b49\u5be6\u4e86\u653b\u64ca\u4e2d\u4f7f\u7528\u7684\u65b0\u624b\u6cd5\u3002\u7576 Cobalt Strike \u6a23\u672c\u904b\u884c\u6642\uff0c\u5b83\u8a66\u5716\u806f\u7e6blartmana[.]com\u7684\u7db2\u57df\u3002\u4e0d\u4e45\u4e4b\u5f8c\uff0cEmotet\u6295\u653e\u4e86Cobalt Strike\u7684\u57f7\u884c\u6a94\u6848<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">This is a big deal. Typically Emotet dropped TrickBot or QakBot, which in turn dropped CobaltStrike. You&#39;d usually have about a month between first infection and ransomware. With Emotet dropping CS directly, there&#39;s likely to be a much much shorter delay. <a href=\"https:\/\/t.co\/QHGU4oq9Zi\">https:\/\/t.co\/QHGU4oq9Zi<\/a><\/p>&mdash; Marcus Hutchins (@MalwareTechBlog) <a href=\"https:\/\/twitter.com\/MalwareTechBlog\/status\/1468305592296951808?ref_src=twsrc%5Etfw\">December 7, 2021<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>Cofense \u7814\u7a76\u4eba\u54e1\u63a8\u6e2c\uff0c\u65b0\u7684\u653b\u64ca\u93c8\u53ef\u80fd\u662f\u4e00\u6b21\u6e2c\u8a66\uff0c\u751a\u81f3\u662f\u7121\u610f\u7684\uff0c\u7136\u800cEmotet \u7684\u91cd\u65b0\u51fa\u73fe\u548c\u96a8\u5f8c\u7684\u7b56\u7565\u8b8a\u5316\u9810\u793a\u8457\u66f4\u591a\u7684\u52d2\u7d22\u8edf\u9ad4\u653b\u64ca\u3002\u96a8\u8457\u653b\u64ca\u624b\u6cd5\u4e0a\u7684\u65b0\u8b8a\u5316\uff0cEmotet \u7e2e\u77ed\u4e86\u611f\u67d3\u548c\u6700\u7d42\u52d2\u7d22\u8edf\u9ad4\u90e8\u7f72\u4e4b\u9593\u7684\u6642\u9593\uff0c\u76ee\u524d\u5c08\u5bb6\u5011\u5c07\u7e7c\u7e8c\u76e3\u6e2c\u4e8b\u614b\u7684\u767c\u5c55\u3002<\/p>\n\n\n\n<p>Emotet\u76f8\u95dc\u7684Indicators of Compromise (IOCs):<\/p>\n\n\n\n<p>SHA256 hash: 7c5690577a49105db766faa999354e0e4128e902dd4b5337741e00e1305ced24<\/p>\n\n\n\n<p>SHA256 hash: bd9b8fe173935ad51f14abc16ed6a5bf6ee92ec4f45fd2ae1154dd2f727fb245<\/p>\n\n\n\n<p>SHA256 hash: f7a4da96129e9c9708a005ee28e4a46af092275af36e3afd63ff201633c70285<\/p>\n\n\n\n<p>SHA256 hash: d95125b9b82df0734b6bc27c426d42dea895c642f2f6516132c80f896be6cf32<\/p>\n\n\n\n<p>SHA256 hash: 88b225f9e803e2509cc2b83c57ccd6ca8b6660448a75b125e02f0ac32f6aadb9<\/p>\n\n\n\n<p>SHA256 hash: 1abd14d498605654e20feb59b5927aa835e5c021cada80e8614e9438ac323601<\/p>\n\n\n\n<p>URLs:<\/p>\n\n\n\n<p>hxxp:\/\/av-quiz[.]tk\/wp-content\/k6K\/<br>hxxp:\/\/devanture[.]com[.]sg\/wp-includes\/XBByNUNWvIEvawb68\/<br>hxxp:\/\/ranvipclub[.]net\/pvhko\/a\/<br>hxxp:\/\/visteme[.]mx\/shop\/wp-admin\/PP\/<br>hxxps:\/\/goodtech.cetxlabs[.]com\/content\/5MfZPgP06\/<br>hxxps:\/\/newsmag.danielolayinkas[.]com\/content\/nVgyRFrTE68Yd9s6\/<br>hxxps:\/\/team.stagingapps[.]xyz\/wp-content\/aPIm2GsjA\/<\/p>\n\n\n\n<p>IP:<\/p>\n\n\n\n<p>177.72.80.14<\/p>\n\n\n\n<p>51.210.242.234<\/p>\n\n\n\n<p>51.178.61.60<\/p>\n\n\n\n<p>196.44.98.190<\/p>\n\n\n\n<p>185.148.169.10<\/p>\n\n\n\n<p>142.4.219.173<\/p>\n\n\n\n<p>168.197.250.14<\/p>\n\n\n\n<p>94.177.248.64<\/p>\n\n\n\n<p>81.0.236.93<\/p>\n\n\n\n<p>66.42.55.5<\/p>\n\n\n\n<p>45.76.176.10<\/p>\n\n\n\n<p>188.93.125.116<\/p>\n\n\n\n<p>103.8.26.103<\/p>\n\n\n\n<p>103.8.26.102<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Emotet\u7684\u56de\u6b78\u662f\u4e00\u500b\u5de8\u5927\u7684\u5a01\u8105\uff0c\u540c\u6642\u5b83\u7684\u767c\u5c55\u4e5f\u4ee4\u4eba\u64d4\u6182\uff0c\u5728\u904e\u53bbEmotet\u6703\u5728\u53d7\u611f\u67d3\u7684\u8a2d\u5099\u4e0a\u5b89\u88ddTrick <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=1557\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[190],"class_list":["post-1557","post","type-post","status-publish","format-standard","hentry","category-6","tag-emotet"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1557"}],"version-history":[{"count":2,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1557\/revisions"}],"predecessor-version":[{"id":1561,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1557\/revisions\/1561"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}