{"id":3596,"date":"2025-02-21T16:26:54","date_gmt":"2025-02-21T08:26:54","guid":{"rendered":"https:\/\/blog.billows.com.tw\/?p=3596"},"modified":"2025-02-21T16:37:33","modified_gmt":"2025-02-21T08:37:33","slug":"ransomhub-%e5%86%8d%e9%80%b2%e5%8c%96%ef%bc%9a%e5%85%a8%e9%9d%a2%e6%94%bb%e6%93%8a-windows%e3%80%81esxi%e3%80%81linux-%e8%88%87-freebsd%e4%bd%9c%e6%a5%ad%e7%b3%bb%e7%b5%b1","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=3596","title":{"rendered":"RansomHub \u518d\u9032\u5316\uff1a\u5168\u9762\u653b\u64ca Windows\u3001ESXi\u3001Linux \u8207 FreeBSD\u4f5c\u696d\u7cfb\u7d71"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"665\" height=\"375\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-10.png\" alt=\"\" class=\"wp-image-3597\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-10.png 665w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-10-300x169.png 300w\" sizes=\"auto, (max-width: 665px) 100vw, 665px\" \/><\/figure>\n\n\n\n<p>RansomHub \u52d2\u7d22\u8edf\u9ad4\u96c6\u5718\u8fc5\u901f\u5d1b\u8d77\uff0c\u6210\u70ba 2024\u20132025 \u5e74\u5ea6\u6700\u7316\u7357\u7684\u7db2\u8def\u72af\u7f6a\u7d44\u7e54\u4e4b\u4e00\u3002\u8a72\u7d44\u7e54\u900f\u904e\u64f4\u5c55\u653b\u64ca\u7bc4\u570d\uff0c\u9396\u5b9a Windows\u3001VMware ESXi\u3001Linux \u53ca FreeBSD \u4f5c\u696d\u7cfb\u7d71\uff0c\u767c\u52d5\u5168\u7403\u6027\u653b\u64ca\u3002<\/p>\n\n\n\n<p><strong>\u9ad8\u5ea6\u9032\u5316\u7684\u653b\u64ca\u624b\u6cd5<\/strong><\/p>\n\n\n\n<p>RansomHub \u52d2\u7d22\u8edf\u9ad4\u96c6\u5718\u904b\u7528\u5148\u9032\u7684\u898f\u907f\u6280\u8853\u3001\u8de8\u5e73\u53f0\u52a0\u5bc6\u6a5f\u5236\uff0c\u4e26\u91dd\u5c0d\u4f01\u696d\u57fa\u790e\u67b6\u69cb\u6f0f\u6d1e\u9032\u884c\u653b\u64ca\u3002\u6839\u64da Group-IB \u7684<a href=\"https:\/\/www.group-ib.com\/blog\/ransomhub-never-sleeps-episode-1\/\" title=\"\">\u8abf\u67e5<\/a>\uff0c\u8a72\u96c6\u5718\u5df2\u6210\u529f\u5165\u4fb5\u8d85\u904e 600 \u5bb6\u7d44\u7e54\uff0c\u6db5\u84cb\u91ab\u7642\u3001\u91d1\u878d\u53ca\u95dc\u9375\u57fa\u790e\u8a2d\u65bd\u7b49\u7522\u696d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"887\" height=\"643\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-13.png\" alt=\"\" class=\"wp-image-3601\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-13.png 887w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-13-300x217.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-13-768x557.png 768w\" sizes=\"auto, (max-width: 887px) 100vw, 887px\" \/><\/figure>\n\n\n\n<p>2\u670816\u65e5\uff0c<a href=\"http:\/\/www.billows.tech\/\">\u7ae3\u76df\u79d1\u6280<\/a>\u767c\u73feRansomHub\u52d2\u7d22\u8edf\u9ad4\u7d44\u7e54\u8072\u7a31\u5c0d\u4f4d\u65bc\u53f0\u5317\u5e02\u7684\u4e0a\u5e02\u8a18\u61b6\u9ad4\u5927\u5ee0\u767c\u52d5\u4e86\u7db2\u8def\u653b\u64ca\u3002\u8a72\u7d44\u7e54\u8072\u7a31\u5df2\u7aca\u53d6 74GB \u7684\u6a5f\u5bc6\u6578\u64da\uff0c\u4e26\u5a01\u8105\u5982\u679c\u672a\u80fd\u6eff\u8db3\u5176\u8981\u6c42\uff0c\u5c07\u65bc 2025 \u5e74 2 \u6708 28 \u65e5\u516c\u958b\u9019\u4e9b\u6578\u64da\u3002RansomHub \u4ee5\u96d9\u91cd\u52d2\u7d22\u6a21\u5f0f\u8457\u7a31\uff0c\u9664\u4e86\u52a0\u5bc6\u53d7\u5bb3\u8005\u6578\u64da\uff0c\u9084\u5a01\u8105\u516c\u958b\u6d29\u9732\uff0c\u4ee5\u65bd\u58d3\u4f01\u696d\u652f\u4ed8\u8d16\u91d1\u3002\u8a72\u7d44\u7e54\u81ea 2024 \u5e74 2 \u6708\u6d3b\u8e8d\u4ee5\u4f86\uff0c\u8fc5\u901f\u5d1b\u8d77\uff0c\u4e26\u8207 ALPHV \u548c LockBit \u7b49\u77e5\u540d\u52d2\u7d22\u8edf\u9ad4\u7d44\u7e54<a>\u7684<\/a>\u524d\u9644\u5c6c\u6210\u54e1\u5408\u4f5c\uff0c\u91dd\u5c0d\u91ab\u7642\u3001\u653f\u5e9c\u6a5f\u69cb\u53ca\u88fd\u9020\u696d\u7b49\u5927\u578b\u4f01\u696d\u767c\u52d5\u653b\u64ca\uff0c\u6210\u70ba\u7576\u524d\u7db2\u8def\u72af\u7f6a\u9818\u57df\u7684\u6d3b\u8e8d\u5a01\u8105\u3002<\/p>\n\n\n\n<p><strong>\u591a\u4f5c\u696d\u7cfb\u7d71\u52a0\u5bc6\u80fd\u529b<\/strong><\/p>\n\n\n\n<p>RansomHub \u91dd\u5c0d\u4e0d\u540c\u74b0\u5883\u958b\u767c\u5c08\u5c6c\u52d2\u7d22\u8edf\u9ad4\u8b8a\u7a2e\uff0c\u4e26\u4f9d\u5e73\u53f0\u8abf\u6574\u6307\u4ee4\u53c3\u6578\u8207\u52a0\u5bc6\u6a5f\u5236\u3002<\/p>\n\n\n\n<p>powershell RansomHub.exe -pass &lt;SHA256&gt; -fast -disable-net -skip-vm &#8220;VM1&#8221;<\/p>\n\n\n\n<p>\u5728\u57f7\u884c\u671f\u9593\uff0c\u52d2\u7d22\u8edf\u9ad4\u6703\u89e3\u5bc6 JSON \u8a2d\u5b9a\u6a94\uff0c\u5176\u4e2d\u5305\u542b\u767d\u540d\u55ae\u76ee\u9304\u3001\u9032\u7a0b\u8207\u670d\u52d9\u7d42\u6b62\u5217\u8868\uff0c\u4ee5\u53ca\u6a6b\u5411\u79fb\u52d5\u6240\u9700\u7684\u6191\u8b49\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>ESXi <\/strong><strong>\u52a0\u5bc6\u5668 (C++ <\/strong><strong>\u958b\u767c)<\/strong>\uff1a\u900f\u904e vim-cmd \u6307\u4ee4\u5f37\u5236\u95dc\u9589\u865b\u64ec\u6a5f\uff0c\u4e26\u4f7f\u7528 ChaCha20 \u8207 Curve25519 \u6f14\u7b97\u6cd5\u52a0\u5bc6 .vmdk\u3001.vmx \u6a94\u6848\u3002<\/li>\n\n\n\n<li><strong>\u6f0f\u6d1e (<\/strong><strong>\u9632\u79a6\u6280\u5de7)<\/strong>\uff1a\u5728 \/tmp\/app.pid \u4e2d\u5beb\u5165 -1 \u53ef\u89f8\u767c\u7121\u9650\u8ff4\u5708\uff0c\u963b\u6b62\u52a0\u5bc6\u3002<\/li>\n<\/ul>\n\n\n\n<p>\/\/ ESXi \u52a0\u5bc6\u5668\u7a0b\u5f0f\u7684\u7247\u6bb5:<\/p>\n\n\n\n<p>if (access(&#8220;\/tmp\/app.pid&#8221;, F_OK) == 0) {<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; pid_t pid = read_pid();<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; if (kill(pid, 0) == 0) {<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; kill(pid, SIGKILL);<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; exit(0);<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; }<\/p>\n\n\n\n<p>}<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Linux <\/strong><strong>\u8b8a\u7a2e<\/strong>\uff1a\u4f7f\u7528\u9593\u6b47\u6027\u52a0\u5bc6\u6280\u8853 (1 MB \u5340\u584a)\uff0c\u4e26\u7d42\u6b62 syslog \u670d\u52d9\u4ee5\u964d\u4f4e\u5075\u6e2c\u6a5f\u7387\u3002<\/li>\n\n\n\n<li><strong>FreeBSD <\/strong><strong>\u8b8a\u7a2e<\/strong>\uff1a\u8b58\u5225\u70ba Ransom.FreeBSD.INTERLOCK.THJBBBD\uff0c\u907f\u958b \/boot\u3001\/etc \u7b49\u95dc\u9375\u76ee\u9304\uff0c\u4e26\u5c07 .interlock \u9644\u52a0\u65bc\u52a0\u5bc6\u6a94\u6848\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u521d\u59cb\u653b\u64ca\u8207\u6f0f\u6d1e\u5229\u7528<\/strong><\/p>\n\n\n\n<p>RansomHub \u5925\u4f34\u653b\u64ca\u8005\u900f\u904e\u5df2\u77e5\u6f0f\u6d1e\u5165\u4fb5\u4f01\u696d\u7db2\u8def\uff0c\u4f8b\u5982\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE-2024-3400<\/strong> (Palo Alto Networks \u9632\u706b\u7246)<\/li>\n\n\n\n<li><strong>CVE-2021-42278 \/ CVE-2020-1472<\/strong> (Active Directory \u6b0a\u9650\u63d0\u5347\u653b\u64ca)<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"276\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-12.png\" alt=\"\" class=\"wp-image-3599\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-12.png 865w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-12-300x96.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2025\/02\/image-12-768x245.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><figcaption class=\"wp-element-caption\">Palo Alto \u767c\u5e03\u7684\u5b89\u5168\u516c\u544a\u6458\u9304\uff08\u4f86\u6e90 \u2013 Group-IB\uff09<\/figcaption><\/figure>\n\n\n\n<p><strong>\u4f01\u696d\u53d7\u5bb3\u5f8c\u7684\u653b\u64ca\u884c\u70ba<\/strong><\/p>\n\n\n\n<p>\u653b\u64ca\u8005\u5165\u4fb5\u5f8c\u901a\u5e38\u90e8\u7f72\u4ee5\u4e0b\u5de5\u5177\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>PCHunter<\/strong>\uff1a\u7d42\u6b62 EDR \u9032\u7a0b\u4e26\u522a\u9664\u7cfb\u7d71\u65e5\u8a8c\u3002<\/li>\n\n\n\n<li><strong>FileZilla<\/strong>\uff1a\u5c07\u7aca\u53d6\u7684\u6578\u64da\u4e0a\u50b3\u81f3 C2 \u4f3a\u670d\u5668\u3002<\/li>\n\n\n\n<li><strong>BYOVD <\/strong><strong>\u653b\u64ca<\/strong>\uff1a\u5229\u7528\u6f0f\u6d1e\u9a45\u52d5\u7a0b\u5f0f (POORTRY.sys) \u7981\u7528\u5b89\u5168\u5de5\u5177\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6b64\u5916\uff0cRansomHub \u900f\u904e\u5f9e\u5df2\u95dc\u9589\u7684 Knight \u52d2\u7d22\u8edf\u9ad4\u96c6\u5718\u53d6\u5f97\u7684<strong>\u52d2\u7d22\u8edf\u9ad4\u7ba1\u7406\u9762\u677f<\/strong>\uff0c\u5141\u8a31\u5925\u4f34\u653b\u64ca\u8005\u81ea\u8a02\u52d2\u7d22\u8a0a\u606f\u8207\u8cc7\u6599\u5916\u6d29\u7db2\u7ad9\u6574\u5408\u3002<\/p>\n\n\n\n<p>\/\/ \u5df2\u89e3\u5bc6\u7684 RansomHub \u8a2d\u5b9a\u6a94\u7247\u6bb5<\/p>\n\n\n\n<p>{<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8220;master_public_key&#8221;: &#8220;a1b2c3&#8230;&#8221;,<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8220;extension&#8221;: &#8220;.6706c3&#8221;,<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8220;note_file_name&#8221;: &#8220;README.txt&#8221;,<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8220;kill_processes&#8221;: [&#8220;MsMpEng.exe&#8221;, &#8220;TaniumCX.exe&#8221;]<\/p>\n\n\n\n<p>}<\/p>\n\n\n\n<p><strong>\u7dca\u6025\u9632\u79a6\u5efa\u8b70<\/strong><\/p>\n\n\n\n<p>\u7f8e\u570b CISA (Cybersecurity and Infrastructure Security Agency) \u547c\u7c72\u7d44\u7e54\u7acb\u5373\uff1a<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>\u4fee\u88dc <strong>CVE-2024-3400<\/strong> \u53ca\u5176\u4ed6\u76f8\u95dc\u6f0f\u6d1e\u3002<\/li>\n\n\n\n<li>\u5f37\u5316\u9060\u7aef\u670d\u52d9\u5b58\u53d6\u7ba1\u63a7\uff0c\u9632\u7bc4\u672a\u6388\u6b0a\u5165\u4fb5\u3002<\/li>\n\n\n\n<li>\u90e8\u7f72 YARA \u898f\u5247\u5075\u6e2c RansomHub \u4e8c\u9032\u4f4d\u6587\u4ef6\u3002<\/li>\n\n\n\n<li>\u76e3\u63a7\u53ef\u7591\u7684 PowerShell \u547d\u4ee4\uff0c\u4f8b\u5982\uff1a<\/li>\n<\/ol>\n\n\n\n<p>Get-CimInstance Win32_ShadowCopy | Remove-CimInstance<\/p>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li>\u5c01\u9396\u5df2\u77e5\u653b\u64ca\u6307\u6a19 (IoC)\uff0c\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li>IP \u4f4d\u5740 10.10.10.10:22<\/li>\n\n\n\n<li>TOR \u7db2\u5740 <strong>(<\/strong><strong>\u8acb\u53c3\u95b1\u6700\u65b0 IoC <\/strong><strong>\u8cc7\u8a0a)<\/strong><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p>\u96a8\u8457 RansomHub \u7a4d\u6975\u62db\u52df\u5df2\u89e3\u6563\u7684 ALPHV \/ LockBit \u653b\u64ca\u8005\uff0c\u4f01\u696d\u5fc5\u9808\u52a0\u5f37\u7aef\u9ede\u5b89\u5168\u6027\uff0c\u4e26\u78ba\u4fdd\u5099\u4efd\u8cc7\u6599<strong>\u96e2\u7dda\u9694\u96e2<\/strong>\uff0c\u4ee5\u964d\u4f4e\u906d\u53d7\u653b\u64ca\u7684\u98a8\u96aa\u3002<\/p>\n\n\n\n<p>Ransom Hub \u52d2\u7d22\u8edf\u9ad4\u76f8\u95dc\u7684\u90e8\u5206\u5165\u4fb5\u6307\u6a19(Indicator of compromise -IOCs):<\/p>\n\n\n\n<p>09e382be8dc54551cbfc60557d5a70b0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>0cd4b7a48220b565eb7bd59f172ea278&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>19209b41db4a3d67e2c2c1962d91bd25&nbsp;&nbsp;<\/p>\n\n\n\n<p>19ebefbb1e4cb0fc5ce21b954f52e1bc&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>3034b61a52ddc30eabdb96f49334453b&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>392880023da7df0f504056be9e58d141&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>477293f80461713d51a98a24023d45e8&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>8c8916d8ea8c44e383d55e919a9f989f&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>a1dd2dff2859b22bcf6a3a4d868a2dbc<\/p>\n","protected":false},"excerpt":{"rendered":"<p>RansomHub \u52d2\u7d22\u8edf\u9ad4\u96c6\u5718\u8fc5\u901f\u5d1b\u8d77\uff0c\u6210\u70ba 2024\u20132025 \u5e74\u5ea6\u6700\u7316\u7357\u7684\u7db2\u8def\u72af\u7f6a\u7d44\u7e54\u4e4b\u4e00\u3002\u8a72\u7d44\u7e54\u900f\u904e\u64f4 <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=3596\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[183,174,254],"class_list":["post-3596","post","type-post","status-publish","format-standard","hentry","category-6","tag-iocs","tag-news","tag-ransom-hub"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/3596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3596"}],"version-history":[{"count":3,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/3596\/revisions"}],"predecessor-version":[{"id":3604,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/3596\/revisions\/3604"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}