×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

ContiÔ´ÂëÆÊÎö£¬×ðÁú¿­Ê±ÀÕË÷½âÃܹ¤¾ßÒѾÍλ£¡

Ô´ÂëÆÊÎö+½âÃܹ¤¾ß£¡×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽ¡¢EDR¡¢×Ô˳Ӧ¡¢¹ýÂËÍø¹ØµÈ¶à²úÆ·Áª¶¯·ÀÓùContiÀÕË÷²¡¶¾

ContiÔ´ÂëÆÊÎö£¬×ðÁú¿­Ê±ÀÕË÷½âÃܹ¤¾ßÒѾÍλ£¡

Ðû²¼Ê±¼ä£º2022-04-28
ä¯ÀÀ´ÎÊý£º2866
·ÖÏí£º

¿ËÈÕ£¬×ðÁú¿­Ê±ÚÐÌýʵÑéÊÒ²¶»ñµ½ContiÀÕË÷²¡¶¾¡£ContiÊǹ¤ÒµÁìÓò×î»îÔ¾µÄÀÕË÷²¡¶¾Ö®Ò»£¬¾Ýͳ¼ÆContiÒÑÀֳɹ¥»÷ÖÁÉÙ475¸ö×éÖ¯²¢ÇÔÈ¡ÆäÊý¾Ý£¬°üÀ¨¹«¹²Æû³µ¼¯ÍÅ¡¢¹¤ÒµÎïÁªÍø³§ÉÌAdvantech¡¢Ì¨´ïµç×ӵȻú¹¹£¬ÆäÖоø´ó²¿·ÖµÄÊý¾ÝÒѲî±ðˮƽ±»¹ûÕæ¡£¿ËÈÕ£¬Ò»Î»ÎÚ¿ËÀ¼Ñо¿Ö°Ô±ÔÚTwitterÉÏÅû¶ContiÀÕË÷Èí¼þÔ´´úÂ룬 ContiÔâÓöɱ¾øÐÔ¹¥»÷¡£±¾ÎÄרÃÅÕë¶ÔContiÊÖÒÕϸ½ÚʹÓþÙÐÐÆÊÎö£¬²¢Ìṩ·À»¤½¨Òé¡£

ÏÖÔÚ£¬×ðÁú¿­Ê±ÚÐÌýʵÑéÊÒÒÑ»ñÈ¡¸ÃÀÕË÷²¡¶¾ÃÜÔ¿£¬¿ÉΪѬȾ¸ÃÀÕË÷²¡¶¾µÄ¿Í»§Ìṩ½âÃܹ¤¾ß¡£×ðÁú¿­Ê±EDR¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØµÈ²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸ÃÀÕË÷²¡¶¾£¬×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽ¿É¶Ô¸ÃÀÕË÷²¡¶¾Èö²¥Í¾¾¶¾ÙÐÐ×è¶Ï£¬ÓÐÓñÜÃâÀÕË÷ÊÂÎñ±¬·¢¡£

²¡¶¾ÆÊÎö
ContiÀÕË÷²¡¶¾v3°æ±¾µÄ²ÎÊýŲÓÃÈçÏ£º

³ÌÐòʹÓÃÀ©Õ¹Ãû.EXTEN£¬¼ÓÃÜˮƽg_EncryptSizeÊÇÖ¸¼ÓÃÜÎļþ¾ÞϸµÄ°Ù·Ö±È£¬Ä¬ÒÔΪ50%¡£

¾²Ì¬Ãâɱ

ÔÚ32λϵͳÖÐʹÓÃFS¼Ä´æÆ÷»ñÈ¡µ½PEBµØÖ·ºó£¬Í¨¹ý±éÀúÄں˽ṹÌåµÄÁ´±í²¢½ÏÁ¿¹þÏ£Öµ»ñÈ¡kernel32.dllµÄ»ùµØÖ·¡£

±éÀúkernel32.dllµÈϵͳÄ£¿éµÄµ¼³ö±íÃû×Ö²¢ÅÌËãMurmurHash2A ¹þÏ££¬Í¨¹ýÅÌÎÊǶÈëÔÚ¶þ½øÖÆPEÖеÄMurmurHash2A¹þϣֵѰÕÒLoadLibraryAµÈ±ØÐèµÄ¿âº¯ÊýµØÖ·¡£MurmurHash2AËã·¨£¬ÕâÊÇÒ»ÖÖÖÚËùÖÜÖªµÄ¼«¿ìµÄ·Ç¼ÓÃÜÉ¢ÁУ¬ÊÊÓÃÓÚ»ùÓÚÉ¢ÁеIJéÕÒ£¬ÆäÏîÄ¿¿ªÔ´µØÖ·Îª

https://github.com/abrandoned/murmur2/blob/master/MurmurHash2.c

ͨ¹ý__forceinlineÄÚÁªº¯ÊýGetProcAddressEx2¶¯Ì¬»ñÈ¡ËùÐèÒªµÄAPIº¯ÊýµØÖ·£¬Ö÷Òª×÷ÓÃÊÇÔÚµ¼Èë±íÖÐÒþ²ØËùÐèÒªµÄAPIº¯Êý£¬±ÜÃâ±»yaraµÈ¹æÔò¾²Ì¬Æ¥ÅäÆÊÎö¡£C++ÖÐinlineºÍ__inline֪ͨ±àÒëÆ÷½«¸Ãº¯ÊýµÄÄÚÈÝ¿½±´Ò»·Ý·ÅÔÚŲÓú¯ÊýµÄµØ·½£¬Õâ³ÆÖ®ÎªÄÚÁª¡£ÄÚÁªïÔÌ­Á˺¯ÊýŲÓõĿªÏú£¬µ«È´ÔöÌíÁË´úÂëÁ¿¡£__forceinlineÒªº¦×Ö²»»ùÓÚ±àÒëÆ÷µÄÐÔÄܺÍÓÅ»¯ÆÊÎö¶øÒÀÀµÓÚ³ÌÐòÔ±µÄÅжϾÙÐÐÄÚÁª¡£

·´µ÷ÊÔ·´HOOK

·´HOOKµÄº¯ÊýÊÂÇéÔ­Àí£ºÍ¨¹ýGetModuleFileNameW º¯Êý»ñȡģ¿éµÄ·¾¶£¬¸Ã·¾¶½«ÓÃÓÚCreateFileº¯Êý½¨Éè¾ä±ú£¬È»ºóʹÓÃCreateFileMappingºÍMapViewOfFileº¯Êý½«ÏµÍ³¿âÔÙ´ÎÓ³Éäµ½ÁíÒ»¸öÄڴ沿·Ö£¬ÕâÑù¶Ïµã¾Í²»»áÆð×÷Óá£

ͨ¹ý±éÀúµ¼³ö±íÀ´»ñÈ¡º¯ÊýµÄµØÖ·£¬ÅжϻñÈ¡µ½µÄµØÖ·µÄOPCODE·´»ã±àÊÇ·ñΪjmp»ã±àÖ¸ÁÈôÊDZ»HOOK×îÖÕͨ¹ýCopyMemoryº¯ÊýÐÞ¸´±»HOOKµÄº¯ÊýµØÖ·¡£

»ìÏý

×Ö·û´®»ìÏý

ʹÓÃOBFA()ºÍOBFW()º¯Êý¾ÙÐкêÌæ»»×Ö·û´®»ìÏý¡£¡°OBFA¡±ÓÃÓÚ ASCII ×Ö·û´®£¬¡°OBFW¡±ÓÃÓÚ UNICODE ×Ö·û´®¡£º¯ÊýÖÐʹÓÃÀ©Õ¹Å·¼¸ÀïµÃËã·¨Extended Euclidean£¬Ã¿´Î¶¼Ê¹ÓÃת±äµÄÊýÖµÌìÉú»ìÏýºóµÄ×Ö·û´®¡£

Ëã·¨ÖÐA¡¢BÊÇÁ½¸ö»áËæ»úת±äµÄÊý×Ö¡£(A*Òª¼ÓÃÜ×Ö·ûbyte+B)%127¾ÍÊǼÓÃܺóµÄ×Ö·û¡£

½âÃܾ籾Á´½Ó£º

https://github.com/Finch4/Malware-Analysis-

Reports/blob/master/conti_string_decrypt.py

Ö¸Áî»ìÏý

MorphcodeÊǺêÌæ»»»ìÏýÖ¸ÁÊý£¬»ìÏýÔ­ÀíÊÇʹÓÃMetaRandom2<0,0x7FFFFF - 1>::valueËæ»ú³öÒ»¸öÊýÖµ£¬È»ºóÌí¼Ó»®·ÖÅжÏËüÄÜ·ñ±»2¡¢3¡¢4¡¢5Ä£Õû³ýµÄÔËË㣬ÒÀ´ËÌí¼Ó´ó×ÚÎÞÓûã±àÖ¸Áî¡£

¹¦Ð§º¯Êý
TAILQÐÐÁд¦Öóͷ£

TAILQÐÐÁÐÊÇFreeBSDÄÚºËÖеÄÒ»ÖÖÐÐÁÐÊý¾Ý½á¹¹£¬Ö÷ÒªÓÃÓÚ´¦Öóͷ£ÐÐÁУ¬ÔÚÒ»Ð©ÖøÃûµÄ¿ªÔ´¿âÖÐ(ÈçDPDK,libevent)ÓÐÆÕ±éµÄÓ¦Óá£

Ï̳߳Ø

ÔÚthreadpoolÃüÃû¿Õ¼äÖнç˵ÁËCteate¡¢Start¡¢PutTask¡¢PutFinalTask¡¢IsActiveÏ̲߳Ù×÷º¯Êý¡£ÔÚÏ̳߳صÄStartº¯ÊýÖн¨ÉèÃûΪThreadPoolHandlerµÄÏ̺߳¯Êý£¬ThreadPoolHandlerÏ̺߳¯ÊýÖ÷Òª¾ÙÐÐÍøÂçºÍÎļþµÄ¼ÓÃÜ¡£Ïß³ÌÊýÄ¿ÔÚÍêÈ«¼ÓÃÜģʽϺʹ¦Öóͷ£Æ÷ÊýÄ¿Ïàͬ£¬ÆäËûģʽÏÂÊÇ´¦Öóͷ£Æ÷ÊýÄ¿µÄÁ½±¶¡£

Ö÷Òª¹¦Ð§º¯ÊýÁÐ±í£º

ɾ³ý¾íÓ°¸±±¾

DeleteShadowCopiesº¯ÊýŲÓÃwbemµÄÁ÷³Ì£º

Ò»¡¢³õʼ»¯COM

¶þ¡¢ÉèÖÃÒ»Ñùƽ³£µÄCOMÇ徲Ʒ¼¶

Èý¡¢»ñÈ¡×î³õµÄWMIµÄlocator

ËÄ¡¢Í¨¹ýIWbemLocator::ConnectServerÒªÁìÅþÁ¬WMI

Îå¡¢ÉèÖôúÀíÉϵÄÇ徲Ʒ¼¶

Áù¡¢Ê¹ÓÃIWbemServicesÖ¸Õë·¢³öWMIÇëÇó

Æß¡¢»ñÈ¡ÇëÇóµÄ·µ»ØÊý¾Ý

½¹µã¼ÓÃÜËã·¨

ÔÚ±éÀúÎļþµÄº¯ÊýÖÐʹÓý¹µã¼ÓÃܺ¯Êýcryptor::Encryptº¯Êý×îÏȼÓÃÜÎļþ¡£

ÔÚlocker::GenKeyÒªÁìÖÐʹÓÃRSA¹«Ô¿¼ÓÃÜËæ»ú±¬·¢µÄChaCha20Ëã·¨£¨Salsa20¼ÓÃÜËã·¨µÄÒ»ÖÖ±äÌ壩µÄ32×Ö½ÚkeyºÍ8×Ö½Úiv¡£

Îļþ·ÖÀà¼ÓÃÜ£¬ÏêϸÕë¶Ô²î±ðµÄÎļþ¼ÓÃÜÒªÁìÈçϱí¡£ÆäÖÐ1M=1048576×Ö½Ú¡£

¼ÓÃÜÐÔÄÜ

ÔÚ²âÊÔϵͳÖУ¬³ÌÐòÔËÐÐ3·ÖÖÓÍêÓñ³ÉÅ̼ÓÃÜ¡£¼ÓÃÜÀú³ÌÖÐÓÐÔ¼5Íò¸öÎļþÓÉÓÚȨÏÞÎÊÌâÎÞ·¨·­¿ª¡£

ÍøÂç¹²ÏíÎļþ¼ÓÃÜ

ÈôÊÇÔËÐÐģʽΪ-net»ò-all¶¼»á¾ÙÐÐÍøÂç¹²ÏíÎļþ¼ÓÃÜ¡£ÔÚÏ̺߳¯ÊýÖлáŲÓÃHostHandlerº¯ÊýÀ´»ñÈ¡ÍøÂç¹²ÏíÏÂÆäËûÖ÷»úµÄÐÅÏ¢£¬ÈçÏÂΪͨ¹ýNetShareEnumº¯Êýö¾Ùµ½ÍøÂç¹²ÏíÎļþ¼Ðºó¾ÙÐд¦Öóͷ£¼ÓÃÜ·¾¶µÄ´úÂë¡£

¼ÓÃܹ²ÏíÎļþĿ¼ÏµĴó¶¼ÎļþʱͬÑù»áÒòȨÏÞÎÊÌâ²»¿É¾ÙÐмÓÃÜ£¬¿ÉÊÇ/User/Public/Ŀ¼ÏµĹ«¹²ÒôÊÓÆµÎļþ»ù±¾¶¼¿ÉÒÔ±»¼ÓÃÜ¡£

ÖØÆôϵͳÇ徲ģʽ¼ÓÃÜ

ÔÚzscaler¹«Ë¾µÄ±¨¸æÅû¶ÖУ¬Conti»¹»áÒÔÇå¾²Ä£Ê½ÖØÆôϵͳ²¢¼ÓÃÜÎļþ£¬Æä»ù±¾°ì·¨ÈçÏ£º

Ò»¡¢Ö´ÐÐÏÂÁîcmd.exe /c net user <admin> /active:yesÒÔÈ·±£¸ÃÕÊ»§ÒÑÆôÓá£È»ºó£¬Conti ½«ÊµÑéͨ¹ýÖ´ÐÐÏÂÁîcmd.exe /c net user<admin> ¡°¡±½«´ËÕÊ»§µÄÃÜÂë¸ü¸ÄΪ¿Õ×Ö·û´®¡£½«ÏìÓ¦µÄ×¢²á±íÖµÉèÖÃΪÔÚÏµÍ³ÖØÐÂÆô¶¯Ê±ÒÔÇ徲ģʽ×Ô¶¯ÒÔ¹ÜÀíÔ±Éí·ÝµÇ¼£º

HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\WinlogonϵÄ×¢²á±íÖµÉèÖÃΪÒÔÏÂÖµ£º

AutoAdminLogon= 1

DefaultUserName= <username>

DefaultDomainName= <computer_name or domain_name>

DefaultPassword= <password>

¶þ¡¢ContiÈ»ºóÖ´ÐÐÏÂÁî bcedit.exe /set {current}safeboot network²¢Í¨¹ýŲÓà Windows API º¯ÊýExitWindowsEx()Ç¿ÖÆÏµÍ³ÖØÐÂÆô¶¯¡£Õ⽫ÔÚÆôÓÃÍøÂçµÄÇ徲ģʽÏÂÆô¶¯Windows£¬Òò´ËContiÈԿɼÓÃÜÍøÂç¹²ÏíÉϵÄÎļþ¡£

Èý¡¢Conti ÔÚÇ徲ģʽÏÂÍê³ÉÎļþ¼ÓÃܺó£¬Ö´ÐÐÏÂÁîbcedit.exe/deletevalue {current} safeboot²¢ÖØÐÂÆô¶¯ÏµÍ³¡£

×ðÁú¿­Ê±½âÃܹ¤¾ß

ÒÑѬȾ¿Í»§¿ÉÔÚ×ðÁú¿­Ê±¹ÙÍø»ñÈ¡½âÃܹ¤¾ß£¬»¹Ô­±»¼ÓÃܵÄÎļþ£¬ÎÞÐè×°Öã¬ÂÌÉ«ÔËÐУ¡

ÏÂÔØµØÖ·£º

http://edr.topsec.com.cn/antiConti.exe

ʹÓÃÒªÁ죺ѡÔñÐèҪɨÃèµÄÎļþ¼Ð£¬µã»÷¡°É¨Ã衱¼´¿É¶Ô¸ÃÎļþ¼ÐÏÂËùÓб»ContiÀÕË÷²¡¶¾¼ÓÃܵÄÎļþ¾ÙÐнâÃÜ£¬Ò²¿É½«±»¼ÓÃÜÎļþÖ±½ÓÍÏÈ빤¾ß¿ò¾ÙÐнâÃÜ¡£

·À»¤½¨Ò飺

1¡¢ÊµÊ±ÐÞ¸´ÏµÍ³¼°Ó¦ÓÃÎó²î£¬½µµÍ±»ContiÀÕË÷²¡¶¾Í¨¹ýÎó²îÈëÇÖµÄΣº¦¡£

2¡¢ÔöÇ¿»á¼û¿ØÖÆ£¬¹Ø±Õ²»ÐëÒªµÄ¶Ë¿Ú£¬½ûÓò»ÐëÒªµÄÅþÁ¬£¬½µµÍ×ʲúΣº¦Ì»Â¶Ãæ¡£

3¡¢¸ü¸Äϵͳ¼°Ó¦ÓÃʹÓõÄĬÈÏÃÜÂ룬ÉèÖøßÇ¿¶ÈÃÜÂëÈÏÖ¤£¬²¢°´ÆÚ¸üÐÂÃÜÂ룬±ÜÃâÈõ¿ÚÁî¹¥»÷¡£

4¡¢¿É×°ÖÃ×ðÁú¿­Ê±Çå¾²²úÆ·ÔöÇ¿·À»¤£¬×ðÁú¿­Ê±EDR¡¢×Ô˳Ӧ¡¢¹ýÂËÍø¹Ø²úÆ·¿ÉÓÐÓ÷ÀÓù¸ÃÀÕË÷²¡¶¾¡£

×ðÁú¿­Ê±²úÆ··ÀÓùÉèÖÃ
×ðÁú¿­Ê±EDRϵͳ

1¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ£¬½µµÍºáÏòѬȾΣº¦£»

2¡¢½¨ÉèÖÜÆÚɨÃèʹÃü£¬×¼Ê±¶ÔÖ÷»ú¾ÙÐÐÖÜÈ«ÕûÀí£¬Ïû³ýÇå¾²Òþ»¼£»

3¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾;

4¡¢¿ªÆôϵͳ¼Ó¹Ì¹¦Ð§£¬¿ÉÓÐÓÃ×èµ²¸ÃÀÕË÷²¡¶¾¶Ôϵͳ¾ÙÐÐÆÆËðºÍ¸Ä¶¯¡£

×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ

1¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ£¬½µµÍºáÏòѬȾΣº¦£»

2¡¢Í¨¹ýΣº¦·¢Ã÷¹¦Ð§É¨ÃèϵͳÊÇ·ñ±£´æÏà¹ØÎó²îºÍÈõ¿ÚÁ½µµÍΣº¦¡¢ïÔÌ­×ʲú̻¶£»

3¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾¡£

×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽϵͳ

1¡¢Í¨¹ý»á¼û¿ØÖÆÕ½ÂԹرղ»ÐëÒªµÄ¶Ë¿ÚºÍ·þÎñ£¬½µµÍÄÚÍø×ʲú̻¶Σº¦£»

2¡¢¿ªÆôÈëÇÖ¼ì²â·ÀÓù¹¦Ð§£¬·ÀÓù¿ÚÁîÀ๥»÷ÊֶΣ¬½µµÍ±»ÈëÇÖΣº¦£»

3¡¢Í¨¹ý»á¼û¿ØÖÆÕ½ÂÔÏÞÖÆÄÚÍøÖÐ̽²âÀàÊý¾Ý°ü£¬½µµÍÄÚÍø×ʲú̻¶ºÍºáÏòѬȾΣº¦¡£

×ðÁú¿­Ê±¹ýÂËÍø¹Ø

1¡¢Éý¼¶µ½×îв¡¶¾ÌØÕ÷¿â£»

2¡¢¿ªÆôHTTP¡¢POP3¡¢SMTP¡¢FTP¡¢IMAPµÈЭÒéµÄ²¡¶¾É¨Ãè¼ì²â£»

3¡¢ÉèÖò¡¶¾¼ì²â´¦Öóͷ£Õ½ÂÔ;

4¡¢¿ªÆôÈÕÖ¾¼Í¼ºÍ±¨¾¯¹¦Ð§¡£

²úÆ·»ñÈ¡·½·¨£º

1¡¢×ðÁú¿­Ê±ÏÂÒ»´ú·À»ðǽ¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢EDRÆóÒµ°æ£º¿Éͨ¹ý×ðÁú¿­Ê±¸÷µØ·Ö¹«Ë¾»ñÈ¡£¨ÅÌÎÊÍøÖ·£º

http://www.topsec.com.cn/contact/£©

2¡¢×ðÁú¿­Ê±EDRµ¥»ú°æÏÂÔØµØÖ·£º

http://edr.topsec.com.cn

3¡¢×ðÁú¿­Ê±¹ýÂËÍø¹ØÏµÍ³²¡¶¾¿âÏÂÔØµØÖ·£º

ftp://ftp.topsec.com.cn/·À²¡¶¾Íø¹Ø(Top-Filter)/²¡¶¾¿âÍÑ»úÉý¼¶°ü/¡£

¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼