{"id":2083,"date":"2022-08-02T09:58:03","date_gmt":"2022-08-02T01:58:03","guid":{"rendered":"https:\/\/blog.billows.com.tw\/?p=2083"},"modified":"2022-08-03T09:28:29","modified_gmt":"2022-08-03T01:28:29","slug":"%e6%b3%a8%e6%84%8f%e4%ba%86-lockbit3-0%e6%bf%ab%e7%94%a8%e5%be%ae%e8%bb%9fdefender-%e8%bc%89%e5%85%a5-cobalt-strike-%e7%9a%84beacon%e4%be%86%e6%84%9f%e6%9f%93%e8%a8%ad%e5%82%99","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=2083","title":{"rendered":"\u6ce8\u610f\u4e86! LockBit3.0\u6feb\u7528\u5fae\u8edfDefender \u8f09\u5165 Cobalt Strike \u7684Beacon\u4f86\u611f\u67d3\u8a2d\u5099"},"content":{"rendered":"\n<p>\u7814\u7a76\u6307\u51fa\u5fae\u8edfDefender \u6210\u70ba LockBit 3.0 \u52d2\u7d22\u8edf\u9ad4\u7684\u76ee\u6a19\uff0c\u8a72\u52d2\u7d22\u8edf\u9ad4\u901a\u904e\u90e8\u7f72 Cobalt Strike \u7684Beacon\u4f86\u5229\u7528\u7cfb\u7d71\u4e26\u6210\u529f\u907f\u514d\u6aa2\u6e2c\u3002\u6839\u64da<a href=\"https:\/\/www.sentinelone.com\/labs\/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility\/\">Sentinel Labs<\/a>\u7684\u7814\u7a76\u4eba\u54e1\u8868\u793a\uff0c LockBit 3.0 \u52d2\u7d22\u8edf\u9ad4\u6feb\u7528 Defender\u4e2d\u7279\u6b8a\u7684 Command Line\u5de5\u5177 MpCmdRun.exe \u4f86\u5074\u8f09\u60e1\u610f\u7a0b<a>\u5f0f<\/a>DLL (DLL Sideloading)\u3002MpCmdRun \u8ca0\u8cac\u4fdd\u8b77 Windows \u514d\u53d7\u7dda\u4e0a\u5a01\u8105\u548c\u60e1\u610f\u8edf\u9ad4\u7684\u5165\u4fb5\uff0c\u4e00\u65e6\u904b\u884c\u60e1\u610f DLL \u4ee5\u89e3\u5bc6\u7cfb\u7d71\uff0c\u5c31\u6703\u5c07 Cobalt Strike \u4fe1\u6a19\u5b89\u88dd\u5230\u8a2d\u5099\u4e2d\u3002<\/p>\n\n\n\n<p>\u5728\u9019\u7a2e\u60c5\u6cc1\u4e0b\uff0c\u6700\u521d\u7684\u7db2\u8def\u5165\u4fb5\u662f\u901a\u904e\u672a\u4fee\u88dc\u7684 VMWare Horizo\u200b\u200bn \u4f3a\u670d\u5668\u4e0a\u7684 Log4j \u6f0f\u6d1e\u57f7\u884c PowerShell \u6307\u4ee4\u78bc\u4f86\u9032\u884c\u7684\u3002\u653b\u64ca\u904e\u7a0b\u7684\u65b9\u5f0f\u8207\u548c\u6b64\u524d\u66dd\u5149\u7684 <a href=\"https:\/\/www.sentinelone.com\/labs\/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility\/\">VMWare CLI \u6848\u4f8b<\/a>\u5e7e\u4e4e\u76f8\u540c\uff0c\u653b\u64ca\u8005\u5be6\u8cea\u4e0a\u662f\u5229\u7528Log4j \u6f0f\u6d1e\u5f9e\u5176\u547d\u4ee4\u8207\u63a7\u5236 (C2) \u4f3a\u670d\u5668\u4e0b\u8f09 MpCmdRun.exe\u3001\u60e1\u610f\u201cmpclient\u201dDLL \u548c\u52a0\u5bc6\u7684 Cobalt Strike \u6709\u6548\u916c\u8f09\u6a94\u6848\uff0c\u4ee5\u611f\u67d3\u6f5b\u5728\u53d7\u5bb3\u8005\u7684\u7cfb\u7d71\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-2.png\" alt=\"\" class=\"wp-image-2089\" width=\"728\" height=\"582\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-2.png 728w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-2-300x240.png 300w\" sizes=\"auto, (max-width: 728px) 100vw, 728px\" \/><figcaption>LockBit 3.0 \u653b\u64ca\u93c8 Photo Credit: Sentinel Labs<\/figcaption><\/figure>\n\n\n\n<p>MpCmdRun.exe \u662f\u4e00\u500b\u7528\u65bc\u57f7\u884c Microsoft Defender \u4efb\u52d9\u7684\u547d\u4ee4\u884c\u5be6\u7528\u7a0b\u5f0f\uff0c\u5b83\u652f\u6301\u6383\u63cf\u60e1\u610f\u8edf\u9ad4\u3001\u6536\u96c6\u8cc7\u6599\u3001\u9084\u539f\u9805\u76ee\u3001\u57f7\u884c\u8a3a\u65b7\u8ffd\u8e2a\u7b49\u547d\u4ee4\u3002\u57f7\u884c\u6642\uff0cMpCmdRun.exe \u5c07\u4e0b\u8f09\u4e00\u500b\u540d\u70ba\u201cmpclient.dll\u201d\u7684\u5408\u6cd5 DLL\uff0c\u8a72 DLL \u5c0d\u65bc\u7a0b\u5e8f\u6b63\u5e38\u904b\u884c\u81f3\u95dc\u91cd\u8981\u3002<\/p>\n\n\n\n<p>\u5728 SentinelLabs \u5206\u6790\u7684\u6848\u4f8b\u4e2d\uff0c\u653b\u64ca\u8005\u5efa\u7acb\u4e86\u81ea\u5df1\u7684mpclient.dll\u6b66\u5668\u5316\u7248\u672c\uff0c\u4e26\u5c07\u5176\u653e\u7f6e\u5728\u512a\u5148\u8f09\u5165\u60e1\u610f\u7248\u672c DLL \u6a94\u6848\u7684\u4f4d\u7f6e\uff0c\u518d\u5c07\u5f9e c0000015.log \u6a94\u6848\uff08\u52a0\u5bc6\u7684Beacon\uff09\u8f09\u5165\u52a0\u5bc6\u7684 Cobalt Strike \u6709\u6548\u916c\u8f09\u3002<\/p>\n\n\n\n<p>\u5728\u653b\u64ca\u4e2d\u4f7f\u7528\u7684\u5143\u4ef6\u8207Windows Defender\u547d\u4ee4\u884c\u5de5\u5177\u7684\u76f8\u95dc:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"217\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-1.png\" alt=\"\" class=\"wp-image-2085\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-1.png 865w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-1-300x75.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/08\/image-1-768x193.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><figcaption>Photo credit: Sentinel Labs<\/figcaption><\/figure>\n\n\n\n<p>\u96d6\u7136\u76ee\u524d\u5c1a\u4e0d\u6e05\u695a LockBit \u6210\u54e1\u5982\u4f55\u5f9e VMware \u5207\u63db\u5230 Windows Defender \u547d\u4ee4\u884c\u5de5\u5177\u4ee5\u5074\u8f09 Cobalt Strike \u7684Beacon\uff0c\u4f46\u73fe\u4eca\u4f7f\u7528\u5c31\u5730\u53d6\u6750 (Living Off-the-Land-LoL)\u7684\u5de5\u5177\u4f86\u9003\u907f EDR \u548c AV \u6aa2\u6e2c\u975e\u5e38\u666e\u904d\uff1b\u56e0\u6b64\uff0c\u4f01\u696d\u9700\u6aa2\u67e5\u4ed6\u5011\u7684\u5b89\u5168\u63a7\u5236\uff0c\u4e26\u8ffd\u8e2a\u53ef\u80fd\u88ab\u653b\u64ca\u8005\u4f7f\u7528\u7684\u5408\u6cd5\u53ef\u57f7\u884c\u6a94\u6848\u7684\u4f7f\u7528\u4fdd\u6301\u8b66\u60d5\u3002<\/p>\n\n\n\n<p>LockBit 3.0 \u7684\u90e8\u5206\u5165\u4fb5\u6307\u6a19(Indicator of compromise -IOCs):<\/p>\n\n\n\n<p>SHA1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>729eb505c36c08860c4408db7be85d707bdcbf1b<\/p>\n\n\n\n<p>091b490500b5f827cc8cde41c9a7f68174d11302&nbsp;<\/p>\n\n\n\n<p>e35a702db47cb11337f523933acd3bce2f60346d&nbsp;<\/p>\n\n\n\n<p>25fbfa37d5a01a97c4ad3f0ee0396f953ca51223<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7814\u7a76\u6307\u51fa\u5fae\u8edfDefender \u6210\u70ba LockBit 3.0 \u52d2\u7d22\u8edf\u9ad4\u7684\u76ee\u6a19\uff0c\u8a72\u52d2\u7d22\u8edf\u9ad4\u901a\u904e\u90e8\u7f72 Cobalt  <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=2083\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[204,220],"class_list":["post-2083","post","type-post","status-publish","format-standard","hentry","category-6","tag-lockbit","tag-lockbit3-0"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/2083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2083"}],"version-history":[{"count":3,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/2083\/revisions"}],"predecessor-version":[{"id":2091,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/2083\/revisions\/2091"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}