×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

ContiÔ´ÂëÆÊÎö £¬×ðÁú¿­Ê±ÀÕË÷½âÃܹ¤¾ßÒѾÍλ£¡

Ô´ÂëÆÊÎö+½âÃܹ¤¾ß£¡×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽ¡¢EDR¡¢×Ô˳Ӧ¡¢¹ýÂËÍø¹ØµÈ¶à²úÆ·Áª¶¯·ÀÓùContiÀÕË÷²¡¶¾

ContiÔ´ÂëÆÊÎö £¬×ðÁú¿­Ê±ÀÕË÷½âÃܹ¤¾ßÒѾÍλ£¡

Ðû²¼Ê±¼ä£º2022-04-28
ä¯ÀÀ´ÎÊý£º2835
·ÖÏí£º

¿ËÈÕ £¬×ðÁú¿­Ê±ÚÐÌýʵÑéÊÒ²¶»ñµ½ContiÀÕË÷²¡¶¾¡£ContiÊǹ¤ÒµÁìÓò×î»îÔ¾µÄÀÕË÷²¡¶¾Ö®Ò» £¬¾Ýͳ¼ÆContiÒÑÀֳɹ¥»÷ÖÁÉÙ475¸ö×éÖ¯²¢ÇÔÈ¡ÆäÊý¾Ý £¬°üÀ¨¹«¹²Æû³µ¼¯ÍÅ¡¢¹¤ÒµÎïÁªÍø³§ÉÌAdvantech¡¢Ì¨´ïµç×ӵȻú¹¹ £¬ÆäÖоø´ó²¿·ÖµÄÊý¾ÝÒѲî±ðˮƽ±»¹ûÕæ¡£¿ËÈÕ £¬Ò»Î»ÎÚ¿ËÀ¼Ñо¿Ö°Ô±ÔÚTwitterÉÏÅû¶ContiÀÕË÷Èí¼þÔ´´úÂë £¬ ContiÔâÓöɱ¾øÐÔ¹¥»÷¡£±¾ÎÄרÃÅÕë¶ÔContiÊÖÒÕϸ½ÚʹÓþÙÐÐÆÊÎö £¬²¢Ìṩ·À»¤½¨Òé¡£

ÏÖÔÚ £¬×ðÁú¿­Ê±ÚÐÌýʵÑéÊÒÒÑ»ñÈ¡¸ÃÀÕË÷²¡¶¾ÃÜÔ¿ £¬¿ÉΪѬȾ¸ÃÀÕË÷²¡¶¾µÄ¿Í»§Ìṩ½âÃܹ¤¾ß¡£×ðÁú¿­Ê±EDR¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØµÈ²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸ÃÀÕË÷²¡¶¾ £¬×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽ¿É¶Ô¸ÃÀÕË÷²¡¶¾Èö²¥Í¾¾¶¾ÙÐÐ×è¶Ï £¬ÓÐÓñÜÃâÀÕË÷ÊÂÎñ±¬·¢¡£

²¡¶¾ÆÊÎö
ContiÀÕË÷²¡¶¾v3°æ±¾µÄ²ÎÊýŲÓÃÈçÏ£º

³ÌÐòʹÓÃÀ©Õ¹Ãû.EXTEN £¬¼ÓÃÜˮƽg_EncryptSizeÊÇÖ¸¼ÓÃÜÎļþ¾ÞϸµÄ°Ù·Ö±È £¬Ä¬ÒÔΪ50%¡£

¾²Ì¬Ãâɱ

ÔÚ32λϵͳÖÐʹÓÃFS¼Ä´æÆ÷»ñÈ¡µ½PEBµØµãºó £¬Í¨¹ý±éÀúÄں˽ṹÌåµÄÁ´±í²¢½ÏÁ¿¹þÏ£Öµ»ñÈ¡kernel32.dllµÄ»ùµØµã¡£

±éÀúkernel32.dllµÈϵͳÄ£¿éµÄµ¼³ö±íÃû×Ö²¢ÅÌËãMurmurHash2A ¹þÏ£ £¬Í¨¹ýÅÌÎÊǶÈëÔÚ¶þ½øÖÆPEÖеÄMurmurHash2A¹þϣֵѰÕÒLoadLibraryAµÈ±ØÐèµÄ¿âº¯ÊýµØµã¡£MurmurHash2AËã·¨ £¬ÕâÊÇÒ»ÖÖÖÚËùÖÜÖªµÄ¼«¿ìµÄ·Ç¼ÓÃÜÉ¢ÁÐ £¬ÊÊÓÃÓÚ»ùÓÚÉ¢ÁеIJéÕÒ £¬ÆäÏîÄ¿¿ªÔ´µØµãΪ

https://github.com/abrandoned/murmur2/blob/master/MurmurHash2.c

ͨ¹ý__forceinlineÄÚÁªº¯ÊýGetProcAddressEx2¶¯Ì¬»ñÈ¡ËùÐèÒªµÄAPIº¯ÊýµØµã £¬Ö÷Òª×÷ÓÃÊÇÔÚµ¼Èë±íÖÐÒþ²ØËùÐèÒªµÄAPIº¯Êý £¬±ÜÃâ±»yaraµÈ¹æÔò¾²Ì¬Æ¥ÅäÆÊÎö¡£C++ÖÐinlineºÍ__inline֪ͨ±àÒëÆ÷½«¸Ãº¯ÊýµÄÄÚÈÝ¿½±´Ò»·Ý·ÅÔÚŲÓú¯ÊýµÄµØ·½ £¬Õâ³ÆÖ®ÎªÄÚÁª¡£ÄÚÁªïÔÌ­Á˺¯ÊýŲÓõĿªÏú £¬µ«È´ÔöÌíÁË´úÂëÁ¿¡£__forceinlineÒªº¦×Ö²»»ùÓÚ±àÒëÆ÷µÄÐÔÄܺÍÓÅ»¯ÆÊÎö¶øÒÀÀµÓÚ³ÌÐòÔ±µÄÅжϾÙÐÐÄÚÁª¡£

·´µ÷ÊÔ·´HOOK

·´HOOKµÄº¯ÊýÊÂÇéÔ­Àí£ºÍ¨¹ýGetModuleFileNameW º¯Êý»ñȡģ¿éµÄ·¾¶ £¬¸Ã·¾¶½«ÓÃÓÚCreateFileº¯Êý½¨Éè¾ä±ú £¬È»ºóʹÓÃCreateFileMappingºÍMapViewOfFileº¯Êý½«ÏµÍ³¿âÔÙ´ÎÓ³Éäµ½ÁíÒ»¸öÄڴ沿·Ö £¬ÕâÑù¶Ïµã¾Í²»»áÆð×÷Óá£

ͨ¹ý±éÀúµ¼³ö±íÀ´»ñÈ¡º¯ÊýµÄµØµã £¬ÅжϻñÈ¡µ½µÄµØµãµÄOPCODE·´»ã±àÊÇ·ñΪjmp»ã±àÖ¸Áî £¬ÈôÊDZ»HOOK×îÖÕͨ¹ýCopyMemoryº¯ÊýÐÞ¸´±»HOOKµÄº¯ÊýµØµã¡£

»ìÏý

×Ö·û´®»ìÏý

ʹÓÃOBFA()ºÍOBFW()º¯Êý¾ÙÐкêÌæ»»×Ö·û´®»ìÏý¡£¡°OBFA¡±ÓÃÓÚ ASCII ×Ö·û´® £¬¡°OBFW¡±ÓÃÓÚ UNICODE ×Ö·û´®¡£º¯ÊýÖÐʹÓÃÀ©Õ¹Å·¼¸ÀïµÃËã·¨Extended Euclidean £¬Ã¿´Î¶¼Ê¹ÓÃת±äµÄÊýÖµÌìÉú»ìÏýºóµÄ×Ö·û´®¡£

Ëã·¨ÖÐA¡¢BÊÇÁ½¸ö»áËæ»úת±äµÄÊý×Ö¡£(A*Òª¼ÓÃÜ×Ö·ûbyte+B)%127¾ÍÊǼÓÃܺóµÄ×Ö·û¡£

½âÃܾ籾Á´½Ó£º

https://github.com/Finch4/Malware-Analysis-

Reports/blob/master/conti_string_decrypt.py

Ö¸Áî»ìÏý

MorphcodeÊǺêÌæ»»»ìÏýÖ¸ÁÊý £¬»ìÏýÔ­ÀíÊÇʹÓÃMetaRandom2<0,0x7FFFFF - 1>::valueËæ»ú³öÒ»¸öÊýÖµ £¬È»ºóÌí¼Ó»®·ÖÅжÏËüÄÜ·ñ±»2¡¢3¡¢4¡¢5Ä£Õû³ýµÄÔËËã £¬ÒÀ´ËÌí¼Ó´ó×ÚÎÞÓûã±àÖ¸Áî¡£

¹¦Ð§º¯Êý
TAILQÐÐÁд¦Öóͷ£

TAILQÐÐÁÐÊÇFreeBSDÄÚºËÖеÄÒ»ÖÖÐÐÁÐÊý¾Ý½á¹¹ £¬Ö÷ÒªÓÃÓÚ´¦Öóͷ£ÐÐÁÐ £¬ÔÚÒ»Ð©ÖøÃûµÄ¿ªÔ´¿âÖÐ(ÈçDPDK,libevent)ÓÐÆÕ±éµÄÓ¦Óá£

Ï̳߳Ø

ÔÚthreadpoolÃüÃû¿Õ¼äÖнç˵ÁËCteate¡¢Start¡¢PutTask¡¢PutFinalTask¡¢IsActiveÏ̲߳Ù×÷º¯Êý¡£ÔÚÏ̳߳صÄStartº¯ÊýÖн¨ÉèÃûΪThreadPoolHandlerµÄÏ̺߳¯Êý £¬ThreadPoolHandlerÏ̺߳¯ÊýÖ÷Òª¾ÙÐÐÍøÂçºÍÎļþµÄ¼ÓÃÜ¡£Ïß³ÌÊýÄ¿ÔÚÍêÈ«¼ÓÃÜģʽϺʹ¦Öóͷ£Æ÷ÊýÄ¿Ïàͬ £¬ÆäËûģʽÏÂÊÇ´¦Öóͷ£Æ÷ÊýÄ¿µÄÁ½±¶¡£

Ö÷Òª¹¦Ð§º¯ÊýÁÐ±í£º

ɾ³ý¾íÓ°¸±±¾

DeleteShadowCopiesº¯ÊýŲÓÃwbemµÄÁ÷³Ì£º

Ò»¡¢³õʼ»¯COM

¶þ¡¢ÉèÖÃÒ»Ñùƽ³£µÄCOMÇ徲Ʒ¼¶

Èý¡¢»ñÈ¡×î³õµÄWMIµÄlocator

ËÄ¡¢Í¨¹ýIWbemLocator::ConnectServerÒªÁìÅþÁ¬WMI

Îå¡¢ÉèÖÃÊðÀíÉϵÄÇ徲Ʒ¼¶

Áù¡¢Ê¹ÓÃIWbemServicesÖ¸Õë·¢³öWMIÇëÇó

Æß¡¢»ñÈ¡ÇëÇóµÄ·µ»ØÊý¾Ý

½¹µã¼ÓÃÜËã·¨

ÔÚ±éÀúÎļþµÄº¯ÊýÖÐʹÓý¹µã¼ÓÃܺ¯Êýcryptor::Encryptº¯Êý×îÏȼÓÃÜÎļþ¡£

ÔÚlocker::GenKeyÒªÁìÖÐʹÓÃRSA¹«Ô¿¼ÓÃÜËæ»ú±¬·¢µÄChaCha20Ëã·¨£¨Salsa20¼ÓÃÜËã·¨µÄÒ»ÖÖ±äÌ壩µÄ32×Ö½ÚkeyºÍ8×Ö½Úiv¡£

Îļþ·ÖÀà¼ÓÃÜ £¬ÏêϸÕë¶Ô²î±ðµÄÎļþ¼ÓÃÜÒªÁìÈçϱí¡£ÆäÖÐ1M=1048576×Ö½Ú¡£

¼ÓÃÜÐÔÄÜ

ÔÚ²âÊÔϵͳÖÐ £¬³ÌÐòÔËÐÐ3·ÖÖÓÍêÓñ³ÉÅ̼ÓÃÜ¡£¼ÓÃÜÀú³ÌÖÐÓÐÔ¼5Íò¸öÎļþÓÉÓÚȨÏÞÎÊÌâÎÞ·¨·­¿ª¡£

ÍøÂç¹²ÏíÎļþ¼ÓÃÜ

ÈôÊÇÔËÐÐģʽΪ-net»ò-all¶¼»á¾ÙÐÐÍøÂç¹²ÏíÎļþ¼ÓÃÜ¡£ÔÚÏ̺߳¯ÊýÖлáŲÓÃHostHandlerº¯ÊýÀ´»ñÈ¡ÍøÂç¹²ÏíÏÂÆäËûÖ÷»úµÄÐÅÏ¢ £¬ÈçÏÂΪͨ¹ýNetShareEnumº¯Êýö¾Ùµ½ÍøÂç¹²ÏíÎļþ¼Ðºó¾ÙÐд¦Öóͷ£¼ÓÃÜ·¾¶µÄ´úÂë¡£

¼ÓÃܹ²ÏíÎļþĿ¼ÏµĴó¶¼ÎļþʱͬÑù»áÒòȨÏÞÎÊÌâ²»¿É¾ÙÐмÓÃÜ £¬¿ÉÊÇ/User/Public/Ŀ¼ÏµĹ«¹²ÒôÊÓÆµÎļþ»ù±¾¶¼¿ÉÒÔ±»¼ÓÃÜ¡£

ÖØÆôϵͳÇ徲ģʽ¼ÓÃÜ

ÔÚzscaler¹«Ë¾µÄ±¨¸æÅû¶ÖÐ £¬Conti»¹»áÒÔÇå¾²Ä£Ê½ÖØÆôϵͳ²¢¼ÓÃÜÎļþ £¬Æä»ù±¾°ì·¨ÈçÏ£º

Ò»¡¢Ö´ÐÐÏÂÁîcmd.exe /c net user <admin> /active:yesÒÔÈ·±£¸ÃÕÊ»§ÒÑÆôÓá£È»ºó £¬Conti ½«ÊµÑéͨ¹ýÖ´ÐÐÏÂÁîcmd.exe /c net user<admin> ¡°¡±½«´ËÕÊ»§µÄÃÜÂë¸ü¸ÄΪ¿Õ×Ö·û´®¡£½«ÏìÓ¦µÄ×¢²á±íÖµÉèÖÃΪÔÚÏµÍ³ÖØÐÂÆô¶¯Ê±ÒÔÇ徲ģʽ×Ô¶¯ÒÔÖÎÀíÔ±Éí·ÝµÇ¼£º

HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\WinlogonϵÄ×¢²á±íÖµÉèÖÃΪÒÔÏÂÖµ£º

AutoAdminLogon= 1

DefaultUserName= <username>

DefaultDomainName= <computer_name or domain_name>

DefaultPassword= <password>

¶þ¡¢ContiÈ»ºóÖ´ÐÐÏÂÁî bcedit.exe /set {current}safeboot network²¢Í¨¹ýŲÓà Windows API º¯ÊýExitWindowsEx()Ç¿ÖÆÏµÍ³ÖØÐÂÆô¶¯¡£Õ⽫ÔÚÆôÓÃÍøÂçµÄÇ徲ģʽÏÂÆô¶¯Windows £¬Òò´ËContiÈԿɼÓÃÜÍøÂç¹²ÏíÉϵÄÎļþ¡£

Èý¡¢Conti ÔÚÇ徲ģʽÏÂÍê³ÉÎļþ¼ÓÃܺó £¬Ö´ÐÐÏÂÁîbcedit.exe/deletevalue {current} safeboot²¢ÖØÐÂÆô¶¯ÏµÍ³¡£

×ðÁú¿­Ê±½âÃܹ¤¾ß

ÒÑѬȾ¿Í»§¿ÉÔÚ×ðÁú¿­Ê±¹ÙÍø»ñÈ¡½âÃܹ¤¾ß £¬»¹Ô­±»¼ÓÃܵÄÎļþ £¬ÎÞÐè×°Öà £¬ÂÌÉ«ÔËÐУ¡

ÏÂÔØµØµã£º

http://edr.topsec.com.cn/antiConti.exe

ʹÓÃÒªÁ죺ѡÔñÐèҪɨÃèµÄÎļþ¼Ð £¬µã»÷¡°É¨Ã衱¼´¿É¶Ô¸ÃÎļþ¼ÐÏÂËùÓб»ContiÀÕË÷²¡¶¾¼ÓÃܵÄÎļþ¾ÙÐнâÃÜ £¬Ò²¿É½«±»¼ÓÃÜÎļþÖ±½ÓÍÏÈ빤¾ß¿ò¾ÙÐнâÃÜ¡£

·À»¤½¨Ò飺

1¡¢ÊµÊ±ÐÞ¸´ÏµÍ³¼°Ó¦ÓÃÎó²î £¬½µµÍ±»ContiÀÕË÷²¡¶¾Í¨¹ýÎó²îÈëÇÖµÄΣº¦¡£

2¡¢ÔöÇ¿»á¼û¿ØÖÆ £¬¹Ø±Õ²»ÐëÒªµÄ¶Ë¿Ú £¬½ûÓò»ÐëÒªµÄÅþÁ¬ £¬½µµÍ×ʲúΣº¦Ì»Â¶Ãæ¡£

3¡¢¸ü¸Äϵͳ¼°Ó¦ÓÃʹÓõÄĬÈÏÃÜÂë £¬ÉèÖøßÇ¿¶ÈÃÜÂëÈÏÖ¤ £¬²¢°´ÆÚ¸üÐÂÃÜÂë £¬±ÜÃâÈõ¿ÚÁî¹¥»÷¡£

4¡¢¿É×°ÖÃ×ðÁú¿­Ê±Çå¾²²úÆ·ÔöÇ¿·À»¤ £¬×ðÁú¿­Ê±EDR¡¢×Ô˳Ӧ¡¢¹ýÂËÍø¹Ø²úÆ·¿ÉÓÐÓ÷ÀÓù¸ÃÀÕË÷²¡¶¾¡£

×ðÁú¿­Ê±²úÆ··ÀÓùÉèÖÃ
×ðÁú¿­Ê±EDRϵͳ

1¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ £¬½µµÍºáÏòѬȾΣº¦ £»

2¡¢½¨ÉèÖÜÆÚɨÃèʹÃü £¬×¼Ê±¶ÔÖ÷»ú¾ÙÐÐÖÜÈ«ÕûÀí £¬Ïû³ýÇå¾²Òþ»¼ £»

3¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§ £¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾;

4¡¢¿ªÆôϵͳ¼Ó¹Ì¹¦Ð§ £¬¿ÉÓÐÓÃ×èµ²¸ÃÀÕË÷²¡¶¾¶Ôϵͳ¾ÙÐÐÆÆËðºÍ¸Ä¶¯¡£

×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ

1¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ £¬½µµÍºáÏòѬȾΣº¦ £»

2¡¢Í¨¹ýΣº¦·¢Ã÷¹¦Ð§É¨ÃèϵͳÊÇ·ñ±£´æÏà¹ØÎó²îºÍÈõ¿ÚÁî £¬½µµÍΣº¦¡¢ïÔÌ­×ʲú̻¶ £»

3¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§ £¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾¡£

×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽϵͳ

1¡¢Í¨¹ý»á¼û¿ØÖÆÕ½ÂԹرղ»ÐëÒªµÄ¶Ë¿ÚºÍ·þÎñ £¬½µµÍÄÚÍø×ʲú̻¶Σº¦ £»

2¡¢¿ªÆôÈëÇÖ¼ì²â·ÀÓù¹¦Ð§ £¬·ÀÓù¿ÚÁîÀ๥»÷ÊÖ¶Î £¬½µµÍ±»ÈëÇÖΣº¦ £»

3¡¢Í¨¹ý»á¼û¿ØÖÆÕ½ÂÔÏÞÖÆÄÚÍøÖÐ̽²âÀàÊý¾Ý°ü £¬½µµÍÄÚÍø×ʲú̻¶ºÍºáÏòѬȾΣº¦¡£

×ðÁú¿­Ê±¹ýÂËÍø¹Ø

1¡¢Éý¼¶µ½×îв¡¶¾ÌØÕ÷¿â £»

2¡¢¿ªÆôHTTP¡¢POP3¡¢SMTP¡¢FTP¡¢IMAPµÈЭÒéµÄ²¡¶¾É¨Ãè¼ì²â £»

3¡¢ÉèÖò¡¶¾¼ì²â´¦Öóͷ£Õ½ÂÔ;

4¡¢¿ªÆôÈÕÖ¾¼Í¼ºÍ±¨¾¯¹¦Ð§¡£

²úÆ·»ñÈ¡·½·¨£º

1¡¢×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽ¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢EDRÆóÒµ°æ£º¿Éͨ¹ý×ðÁú¿­Ê±¸÷µØ·Ö¹«Ë¾»ñÈ¡£¨ÅÌÎÊÍøÖ·£º

http://www.topsec.com.cn/contact/£©

2¡¢×ðÁú¿­Ê±EDRµ¥»ú°æÏÂÔØµØµã£º

http://edr.topsec.com.cn

3¡¢×ðÁú¿­Ê±¹ýÂËÍø¹ØÏµÍ³²¡¶¾¿âÏÂÔØµØµã£º

ftp://ftp.topsec.com.cn/·À²¡¶¾Íø¹Ø(Top-Filter)/²¡¶¾¿âÍÑ»úÉý¼¶°ü/¡£

¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼