¿ËÈÕ£¬×ðÁú¿Ê±ÚÐÌýʵÑéÊÒ²¶»ñµ½ContiÀÕË÷²¡¶¾¡£ContiÊǹ¤ÒµÁìÓò×î»îÔ¾µÄÀÕË÷²¡¶¾Ö®Ò»£¬¾Ýͳ¼ÆContiÒÑÀֳɹ¥»÷ÖÁÉÙ475¸ö×éÖ¯²¢ÇÔÈ¡ÆäÊý¾Ý£¬°üÀ¨¹«¹²Æû³µ¼¯ÍÅ¡¢¹¤ÒµÎïÁªÍø³§ÉÌAdvantech¡¢Ì¨´ïµç×ӵȻú¹¹£¬ÆäÖоø´ó²¿·ÖµÄÊý¾ÝÒѲî±ðˮƽ±»¹ûÕæ¡£¿ËÈÕ£¬Ò»Î»ÎÚ¿ËÀ¼Ñо¿Ö°Ô±ÔÚTwitterÉÏÅû¶ContiÀÕË÷Èí¼þÔ´´úÂ룬 ContiÔâÓöɱ¾øÐÔ¹¥»÷¡£±¾ÎÄרÃÅÕë¶ÔContiÊÖÒÕϸ½ÚʹÓþÙÐÐÆÊÎö£¬²¢Ìṩ·À»¤½¨Òé¡£
ÏÖÔÚ£¬×ðÁú¿Ê±ÚÐÌýʵÑéÊÒÒÑ»ñÈ¡¸ÃÀÕË÷²¡¶¾ÃÜÔ¿£¬¿ÉΪѬȾ¸ÃÀÕË÷²¡¶¾µÄ¿Í»§Ìṩ½âÃܹ¤¾ß¡£×ðÁú¿Ê±EDR¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØµÈ²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸ÃÀÕË÷²¡¶¾£¬×ðÁú¿Ê±ÏÂÒ»´ú·À»ðǽ¿É¶Ô¸ÃÀÕË÷²¡¶¾Èö²¥Í¾¾¶¾ÙÐÐ×è¶Ï£¬ÓÐÓñÜÃâÀÕË÷ÊÂÎñ±¬·¢¡£
²¡¶¾ÆÊÎö
ContiÀÕË÷²¡¶¾v3°æ±¾µÄ²ÎÊýŲÓÃÈçÏ£º

³ÌÐòʹÓÃÀ©Õ¹Ãû.EXTEN£¬¼ÓÃÜˮƽg_EncryptSizeÊÇÖ¸¼ÓÃÜÎļþ¾ÞϸµÄ°Ù·Ö±È£¬Ä¬ÒÔΪ50%¡£

¾²Ì¬Ãâɱ
ÔÚ32λϵͳÖÐʹÓÃFS¼Ä´æÆ÷»ñÈ¡µ½PEBµØµãºó£¬Í¨¹ý±éÀúÄں˽ṹÌåµÄÁ´±í²¢½ÏÁ¿¹þÏ£Öµ»ñÈ¡kernel32.dllµÄ»ùµØµã¡£

±éÀúkernel32.dllµÈϵͳģ¿éµÄµ¼³ö±íÃû×Ö²¢ÅÌËãMurmurHash2A ¹þÏ££¬Í¨¹ýÅÌÎÊǶÈëÔÚ¶þ½øÖÆPEÖеÄMurmurHash2A¹þϣֵѰÕÒLoadLibraryAµÈ±ØÐèµÄ¿âº¯ÊýµØµã¡£MurmurHash2AËã·¨£¬ÕâÊÇÒ»ÖÖÖÚËùÖÜÖªµÄ¼«¿ìµÄ·Ç¼ÓÃÜÉ¢ÁУ¬ÊÊÓÃÓÚ»ùÓÚÉ¢ÁеIJéÕÒ£¬ÆäÏîÄ¿¿ªÔ´µØµãΪ
https://github.com/abrandoned/murmur2/blob/master/MurmurHash2.c

ͨ¹ý__forceinlineÄÚÁªº¯ÊýGetProcAddressEx2¶¯Ì¬»ñÈ¡ËùÐèÒªµÄAPIº¯ÊýµØµã£¬Ö÷Òª×÷ÓÃÊÇÔÚµ¼Èë±íÖÐÒþ²ØËùÐèÒªµÄAPIº¯Êý£¬±ÜÃâ±»yaraµÈ¹æÔò¾²Ì¬Æ¥ÅäÆÊÎö¡£C++ÖÐinlineºÍ__inline֪ͨ±àÒëÆ÷½«¸Ãº¯ÊýµÄÄÚÈÝ¿½±´Ò»·Ý·ÅÔÚŲÓú¯ÊýµÄµØ·½£¬Õâ³ÆÖ®ÎªÄÚÁª¡£ÄÚÁªïÔÌÁ˺¯ÊýŲÓõĿªÏú£¬µ«È´ÔöÌíÁË´úÂëÁ¿¡£__forceinlineÒªº¦×Ö²»»ùÓÚ±àÒëÆ÷µÄÐÔÄܺÍÓÅ»¯ÆÊÎö¶øÒÀÀµÓÚ³ÌÐòÔ±µÄÅжϾÙÐÐÄÚÁª¡£

·´µ÷ÊÔ·´HOOK
·´HOOKµÄº¯ÊýÊÂÇéÔÀí£ºÍ¨¹ýGetModuleFileNameW º¯Êý»ñȡģ¿éµÄ·¾¶£¬¸Ã·¾¶½«ÓÃÓÚCreateFileº¯Êý½¨Éè¾ä±ú£¬È»ºóʹÓÃCreateFileMappingºÍMapViewOfFileº¯Êý½«ÏµÍ³¿âÔÙ´ÎÓ³Éäµ½ÁíÒ»¸öÄڴ沿·Ö£¬ÕâÑù¶Ïµã¾Í²»»áÆð×÷Óá£

ͨ¹ý±éÀúµ¼³ö±íÀ´»ñÈ¡º¯ÊýµÄµØµã£¬ÅжϻñÈ¡µ½µÄµØµãµÄOPCODE·´»ã±àÊÇ·ñΪjmp»ã±àÖ¸ÁÈôÊDZ»HOOK×îÖÕͨ¹ýCopyMemoryº¯ÊýÐÞ¸´±»HOOKµÄº¯ÊýµØµã¡£

»ìÏý
×Ö·û´®»ìÏý
ʹÓÃOBFA()ºÍOBFW()º¯Êý¾ÙÐкêÌæ»»×Ö·û´®»ìÏý¡£¡°OBFA¡±ÓÃÓÚ ASCII ×Ö·û´®£¬¡°OBFW¡±ÓÃÓÚ UNICODE ×Ö·û´®¡£º¯ÊýÖÐʹÓÃÀ©Õ¹Å·¼¸ÀïµÃËã·¨Extended Euclidean£¬Ã¿´Î¶¼Ê¹ÓÃת±äµÄÊýÖµÌìÉú»ìÏýºóµÄ×Ö·û´®¡£

Ëã·¨ÖÐA¡¢BÊÇÁ½¸ö»áËæ»úת±äµÄÊý×Ö¡£(A*Òª¼ÓÃÜ×Ö·ûbyte+B)%127¾ÍÊǼÓÃܺóµÄ×Ö·û¡£

½âÃܾ籾Á´½Ó£º
https://github.com/Finch4/Malware-Analysis-
Reports/blob/master/conti_string_decrypt.py
Ö¸Áî»ìÏý
MorphcodeÊǺêÌæ»»»ìÏýÖ¸ÁÊý£¬»ìÏýÔÀíÊÇʹÓÃMetaRandom2<0,0x7FFFFF - 1>::valueËæ»ú³öÒ»¸öÊýÖµ£¬È»ºóÌí¼Ó»®·ÖÅжÏËüÄÜ·ñ±»2¡¢3¡¢4¡¢5Ä£Õû³ýµÄÔËË㣬ÒÀ´ËÌí¼Ó´ó×ÚÎÞÓûã±àÖ¸Áî¡£

¹¦Ð§º¯Êý
TAILQÐÐÁд¦Öóͷ£
TAILQÐÐÁÐÊÇFreeBSDÄÚºËÖеÄÒ»ÖÖÐÐÁÐÊý¾Ý½á¹¹£¬Ö÷ÒªÓÃÓÚ´¦Öóͷ£ÐÐÁУ¬ÔÚÒ»Ð©ÖøÃûµÄ¿ªÔ´¿âÖÐ(ÈçDPDK,libevent)ÓÐÆÕ±éµÄÓ¦Óá£

Ï̳߳Ø
ÔÚthreadpoolÃüÃû¿Õ¼äÖнç˵ÁËCteate¡¢Start¡¢PutTask¡¢PutFinalTask¡¢IsActiveÏ̲߳Ù×÷º¯Êý¡£ÔÚÏ̳߳صÄStartº¯ÊýÖн¨ÉèÃûΪThreadPoolHandlerµÄÏ̺߳¯Êý£¬ThreadPoolHandlerÏ̺߳¯ÊýÖ÷Òª¾ÙÐÐÍøÂçºÍÎļþµÄ¼ÓÃÜ¡£Ïß³ÌÊýÄ¿ÔÚÍêÈ«¼ÓÃÜģʽϺʹ¦Öóͷ£Æ÷ÊýÄ¿Ïàͬ£¬ÆäËûģʽÏÂÊÇ´¦Öóͷ£Æ÷ÊýÄ¿µÄÁ½±¶¡£

Ö÷Òª¹¦Ð§º¯ÊýÁÐ±í£º

ɾ³ý¾íÓ°¸±±¾
DeleteShadowCopiesº¯ÊýŲÓÃwbemµÄÁ÷³Ì£º
Ò»¡¢³õʼ»¯COM
¶þ¡¢ÉèÖÃÒ»Ñùƽ³£µÄCOMÇ徲Ʒ¼¶
Èý¡¢»ñÈ¡×î³õµÄWMIµÄlocator
ËÄ¡¢Í¨¹ýIWbemLocator::ConnectServerÒªÁìÅþÁ¬WMI
Îå¡¢ÉèÖÃÊðÀíÉϵÄÇ徲Ʒ¼¶
Áù¡¢Ê¹ÓÃIWbemServicesÖ¸Õë·¢³öWMIÇëÇó
Æß¡¢»ñÈ¡ÇëÇóµÄ·µ»ØÊý¾Ý

½¹µã¼ÓÃÜËã·¨
ÔÚ±éÀúÎļþµÄº¯ÊýÖÐʹÓý¹µã¼ÓÃܺ¯Êýcryptor::Encryptº¯Êý×îÏȼÓÃÜÎļþ¡£

ÔÚlocker::GenKeyÒªÁìÖÐʹÓÃRSA¹«Ô¿¼ÓÃÜËæ»ú±¬·¢µÄChaCha20Ëã·¨£¨Salsa20¼ÓÃÜËã·¨µÄÒ»ÖÖ±äÌ壩µÄ32×Ö½ÚkeyºÍ8×Ö½Úiv¡£

Îļþ·ÖÀà¼ÓÃÜ£¬ÏêϸÕë¶Ô²î±ðµÄÎļþ¼ÓÃÜÒªÁìÈçÏÂ±í¡£ÆäÖÐ1M=1048576×Ö½Ú¡£

¼ÓÃÜÐÔÄÜ
ÔÚ²âÊÔϵͳÖУ¬³ÌÐòÔËÐÐ3·ÖÖÓÍêÓñ³ÉÅ̼ÓÃÜ¡£¼ÓÃÜÀú³ÌÖÐÓÐÔ¼5Íò¸öÎļþÓÉÓÚȨÏÞÎÊÌâÎÞ·¨·¿ª¡£

ÍøÂç¹²ÏíÎļþ¼ÓÃÜ
ÈôÊÇÔËÐÐģʽΪ-net»ò-all¶¼»á¾ÙÐÐÍøÂç¹²ÏíÎļþ¼ÓÃÜ¡£ÔÚÏ̺߳¯ÊýÖлáŲÓÃHostHandlerº¯ÊýÀ´»ñÈ¡ÍøÂç¹²ÏíÏÂÆäËûÖ÷»úµÄÐÅÏ¢£¬ÈçÏÂΪͨ¹ýNetShareEnumº¯Êýö¾Ùµ½ÍøÂç¹²ÏíÎļþ¼Ðºó¾ÙÐд¦Öóͷ£¼ÓÃÜ·¾¶µÄ´úÂë¡£

¼ÓÃܹ²ÏíÎļþĿ¼ÏµĴó¶¼ÎļþʱͬÑù»áÒòȨÏÞÎÊÌâ²»¿É¾ÙÐмÓÃÜ£¬¿ÉÊÇ/User/Public/Ŀ¼ÏµĹ«¹²ÒôÊÓÆµÎļþ»ù±¾¶¼¿ÉÒÔ±»¼ÓÃÜ¡£

ÖØÆôϵͳÇ徲ģʽ¼ÓÃÜ
ÔÚzscaler¹«Ë¾µÄ±¨¸æÅû¶ÖУ¬Conti»¹»áÒÔÇå¾²Ä£Ê½ÖØÆôϵͳ²¢¼ÓÃÜÎļþ£¬Æä»ù±¾°ì·¨ÈçÏ£º
Ò»¡¢Ö´ÐÐÏÂÁîcmd.exe /c net user <admin> /active:yesÒÔÈ·±£¸ÃÕÊ»§ÒÑÆôÓá£È»ºó£¬Conti ½«ÊµÑéͨ¹ýÖ´ÐÐÏÂÁîcmd.exe /c net user<admin> ¡°¡±½«´ËÕÊ»§µÄÃÜÂë¸ü¸ÄΪ¿Õ×Ö·û´®¡£½«ÏìÓ¦µÄ×¢²á±íÖµÉèÖÃΪÔÚÏµÍ³ÖØÐÂÆô¶¯Ê±ÒÔÇ徲ģʽ×Ô¶¯ÒÔÖÎÀíÔ±Éí·ÝµÇ¼£º
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\WinlogonϵÄ×¢²á±íÖµÉèÖÃΪÒÔÏÂÖµ£º
AutoAdminLogon= 1
DefaultUserName= <username>
DefaultDomainName= <computer_name or domain_name>
DefaultPassword= <password>
¶þ¡¢ContiÈ»ºóÖ´ÐÐÏÂÁî bcedit.exe /set {current}safeboot network²¢Í¨¹ýŲÓà Windows API º¯ÊýExitWindowsEx()Ç¿ÖÆÏµÍ³ÖØÐÂÆô¶¯¡£Õ⽫ÔÚÆôÓÃÍøÂçµÄÇ徲ģʽÏÂÆô¶¯Windows£¬Òò´ËContiÈԿɼÓÃÜÍøÂç¹²ÏíÉϵÄÎļþ¡£
Èý¡¢Conti ÔÚÇ徲ģʽÏÂÍê³ÉÎļþ¼ÓÃܺó£¬Ö´ÐÐÏÂÁîbcedit.exe/deletevalue {current} safeboot²¢ÖØÐÂÆô¶¯ÏµÍ³¡£
×ðÁú¿Ê±½âÃܹ¤¾ß
ÒÑѬȾ¿Í»§¿ÉÔÚ×ðÁú¿Ê±¹ÙÍø»ñÈ¡½âÃܹ¤¾ß£¬»¹Ô±»¼ÓÃܵÄÎļþ£¬ÎÞÐè×°Öã¬ÂÌÉ«ÔËÐУ¡
ÏÂÔØµØµã£º
http://edr.topsec.com.cn/antiConti.exe
ʹÓÃÒªÁ죺ѡÔñÐèҪɨÃèµÄÎļþ¼Ð£¬µã»÷¡°É¨Ã衱¼´¿É¶Ô¸ÃÎļþ¼ÐÏÂËùÓб»ContiÀÕË÷²¡¶¾¼ÓÃܵÄÎļþ¾ÙÐнâÃÜ£¬Ò²¿É½«±»¼ÓÃÜÎļþÖ±½ÓÍÏÈ빤¾ß¿ò¾ÙÐнâÃÜ¡£

·À»¤½¨Ò飺
1¡¢ÊµÊ±ÐÞ¸´ÏµÍ³¼°Ó¦ÓÃÎó²î£¬½µµÍ±»ContiÀÕË÷²¡¶¾Í¨¹ýÎó²îÈëÇÖµÄΣº¦¡£
2¡¢ÔöÇ¿»á¼û¿ØÖÆ£¬¹Ø±Õ²»ÐëÒªµÄ¶Ë¿Ú£¬½ûÓò»ÐëÒªµÄÅþÁ¬£¬½µµÍ×ʲúΣº¦Ì»Â¶Ãæ¡£
3¡¢¸ü¸Äϵͳ¼°Ó¦ÓÃʹÓõÄĬÈÏÃÜÂ룬ÉèÖøßÇ¿¶ÈÃÜÂëÈÏÖ¤£¬²¢°´ÆÚ¸üÐÂÃÜÂ룬±ÜÃâÈõ¿ÚÁî¹¥»÷¡£
4¡¢¿É×°ÖÃ×ðÁú¿Ê±Çå¾²²úÆ·ÔöÇ¿·À»¤£¬×ðÁú¿Ê±EDR¡¢×Ô˳Ӧ¡¢¹ýÂËÍø¹Ø²úÆ·¿ÉÓÐÓ÷ÀÓù¸ÃÀÕË÷²¡¶¾¡£
×ðÁú¿Ê±²úÆ··ÀÓùÉèÖÃ
×ðÁú¿Ê±EDRϵͳ
1¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ£¬½µµÍºáÏòѬȾΣº¦£»
2¡¢½¨ÉèÖÜÆÚɨÃèʹÃü£¬×¼Ê±¶ÔÖ÷»ú¾ÙÐÐÖÜÈ«ÕûÀí£¬Ïû³ýÇå¾²Òþ»¼£»
3¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾;
4¡¢¿ªÆôϵͳ¼Ó¹Ì¹¦Ð§£¬¿ÉÓÐÓÃ×èµ²¸ÃÀÕË÷²¡¶¾¶Ôϵͳ¾ÙÐÐÆÆËðºÍ¸Ä¶¯¡£
×ðÁú¿Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ
1¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ£¬½µµÍºáÏòѬȾΣº¦£»
2¡¢Í¨¹ýΣº¦·¢Ã÷¹¦Ð§É¨ÃèϵͳÊÇ·ñ±£´æÏà¹ØÎó²îºÍÈõ¿ÚÁ½µµÍΣº¦¡¢ïÔÌ×ʲú̻¶£»
3¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾¡£
×ðÁú¿Ê±ÏÂÒ»´ú·À»ðǽϵͳ
1¡¢Í¨¹ý»á¼û¿ØÖÆÕ½ÂԹرղ»ÐëÒªµÄ¶Ë¿ÚºÍ·þÎñ£¬½µµÍÄÚÍø×ʲú̻¶Σº¦£»
2¡¢¿ªÆôÈëÇÖ¼ì²â·ÀÓù¹¦Ð§£¬·ÀÓù¿ÚÁîÀ๥»÷ÊֶΣ¬½µµÍ±»ÈëÇÖΣº¦£»
3¡¢Í¨¹ý»á¼û¿ØÖÆÕ½ÂÔÏÞÖÆÄÚÍøÖÐ̽²âÀàÊý¾Ý°ü£¬½µµÍÄÚÍø×ʲú̻¶ºÍºáÏòѬȾΣº¦¡£
×ðÁú¿Ê±¹ýÂËÍø¹Ø
1¡¢Éý¼¶µ½×îв¡¶¾ÌØÕ÷¿â£»
2¡¢¿ªÆôHTTP¡¢POP3¡¢SMTP¡¢FTP¡¢IMAPµÈÐÒéµÄ²¡¶¾É¨Ãè¼ì²â£»
3¡¢ÉèÖò¡¶¾¼ì²â´¦Öóͷ£Õ½ÂÔ;
4¡¢¿ªÆôÈÕÖ¾¼Í¼ºÍ±¨¾¯¹¦Ð§¡£
²úÆ·»ñÈ¡·½·¨£º
1¡¢×ðÁú¿Ê±ÏÂÒ»´ú·À»ðǽ¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢EDRÆóÒµ°æ£º¿Éͨ¹ý×ðÁú¿Ê±¸÷µØ·Ö¹«Ë¾»ñÈ¡£¨ÅÌÎÊÍøÖ·£º
http://www.topsec.com.cn/contact/£©
2¡¢×ðÁú¿Ê±EDRµ¥»ú°æÏÂÔØµØµã£º
http://edr.topsec.com.cn
3¡¢×ðÁú¿Ê±¹ýÂËÍø¹ØÏµÍ³²¡¶¾¿âÏÂÔØµØµã£º
ftp://ftp.topsec.com.cn/·À²¡¶¾Íø¹Ø(Top-Filter)/²¡¶¾¿âÍÑ»úÉý¼¶°ü/¡£