IcedIDÒøÐÐľÂíÑù±¾ÊÖÒÕÆÊÎöÓë·À»¤¼Æ»®
2017-11-17
ÄÚÈݼò½é
×ÛÊö
¿ËÈÕ£¬IBM X-ForceÑо¿Ð¡×é·¢Ã÷ÁËÒ»ÖÖȫеÄÒøÐÐľÂíIcedID¡£¸ÃľÂí×îÔçÓÚ2017Äê9ÔÂÔÚ»¥ÁªÍøÉÏÈö²¥£¬Ä¿µÄÖ÷ҪΪÃÀ¹ú½ðÈÚÐÐÒµµÄÏà¹ØÏµÍ³¡£¾ÝX-ForceÑо¿£¬¸ÃľÂí°üÀ¨Ò»¸ö¶ñÒâ´úÂëµÄÄ£¿é£¬ÓµÓÐÈçÖæË¹Ä¾Âí£¨Zeus Trojan£©µÈÏÖ½ñÒøÐÐľÂíµÄ´ó²¿·Ö¹¦Ð§¡£
ÏÖÔÚ¿´À´£¬¸ÃľÂíÖ÷ÒªµÄÄ¿µÄΪÃÀ¹úµÄÒøÐУ¬Ö§¸¶¿¨ÌṩÉÌ£¬ÊÖ»ú·þÎñÌṩÉÌ£¬ÓʼþºÍµçÉÌÍøÕ¾µÈϵͳ£¬»¹°üÀ¨2ËùÓ¢¹úµÄÖ÷Á÷ÒøÐС£
Ïà¹ØÁ´½Ó£º
https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/
ÊÂÎñÅä¾°
2017Äê11ÔÂ14ÈÕ£¬Ò»¸öÃûΪIcedIDµÄÒøÐÐľÂí±»Ñо¿Ö°Ô±·¢Ã÷£¬¸ÃľÂíÖ÷Òª¹¥»÷ÃÀ¹ú¾³ÄÚµÄÒøÐÐºÍÆäËû½ðÈÚ»ú¹¹£¬Í¨¹ýEmotetľÂíÀ´¾ÙÐÐÈö²¥¡£ÊÜѬȾÕßÔÚ»á¼ûÌØ¶¨µÄÏßÉϽðÈÚ»ú¹¹ÍøÕ¾Ê±£¬¸ÃľÂí»á½«Óû§ÖØÐ¶¨Ïòµ½¼ÙµÄ´¹ÂÚÍøÒ³£¬À´»ñÈ¡Óû§µÄÒøÐÐÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£
Èö²¥ÓëѬȾ
¾ÝX-ForceµÄÑо¿Ö°Ô±ÌåÏÖ£¬IcedIDûÓÐʹÓÃÎó²î¶øÊÇʹÓÃEmotetľÂí¾ÙÐÐÈö²¥¡£Emotet½«IcedID×÷ΪеÄPayloadÏÂÔØµ½ÊÜѬȾµÄÓû§Ö÷»úÉÏ£¬´Ó¶ø¾ÙÐÐѬȾ¡£EmotetÖ÷Ҫͨ¹ý´¹ÂÚÓʼþ¾ÙÐÐÈö²¥£¬Ò»µ©Ñ¬È¾Óû§¾Í»áÔÚÖ÷»úÉϾ²Ä¬×°Öã¬Ëæºó»áÓÃÀ´ÏÂÔØ¸ü¶àµÄ¶ñÒâÈí¼þ¡£
³ýÁ˳£¼ûµÄľÂí¹¦Ð§Í⣬IcedID»¹¿ÉÒÔͨ¹ýÍøÂçÈö²¥¡£ Ëüͨ¹ýÉèÖÃÒ»¸öÍâµØÊðÀíÀ´¼à¿ØÊܺ¦ÕßµÄÔÚÏßÔ˶¯£¬ ËüµÄ¹¥»÷ÊֶΰüÀ¨ÍøÕ¾×¢Èë¹¥»÷ºÍÀàËÆÓÚDridexºÍTrickBotµÄÖØ´óµÄÖØ¶¨Ïò¹¥»÷¡£
¹¥»÷Á÷³Ì

´¦Öóͷ£½¨Òé
Çå¾²²Ù×÷½¨Òé
1. ²»ÒªËæÒâÏÂÔØºÍ×°ÖÃÈí¼þ£¬ÒÔ·À±»Ä¾ÂíѬȾ£»
2. ×°Ö÷À²¡¶¾Èí¼þ²¢¼á³Ö¸üÐÂÖÁ×îа汾¡£
¼ì²éÓëɨ³ý
1. ¼ì²é×¢²á±í²¢É¾³ýHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRuncantimeam¼üÖµ¡£
2. ɾ³ýC:Users{UserName}AppDataLocalcantimeamĿ¼¼°¸ÃĿ¼ÏµĿÉÖ´ÐÐÎļþ¡£
Ò»Á¬Çå¾²¼à²âÓë·À»¤
ÔÚÒ»Á¬Çå¾²¼à²âºÍ·À»¤¼Æ»®ÖУ¬ÒÔAG¹«Ë¾ÍþвÆÊÎöϵͳ£¨TAC£©¼ì²âδ֪ºÍÒÑÖªÍþв£¬ÒÔÍþвÇ鱨Çå¾²ÐÅÓþΪŦ´ø£¬ÍŽáÍâµØÍøÂç°²ÅŵÄNIPS£¨AG¹«Ë¾ÈëÇÖ·À»¤ÏµÍ³£©£¬ÐγɶÔÒÑÖªÍþвÓëδ֪ÍþвµÄ¶¯Ì¬Çå¾²·À»¤ÏµÍ³£¬ÔÙÍŽáAG¹«Ë¾¿Æ¼¼×¨ÒµÓ¦¼±ÏìÓ¦ÍŶÓÒÔ¼°ÇøÓò·þÎñÍŶӵÄÏÖ³¡ÏìÓ¦¼°´¦Öóͷ£ÄÜÁ¦£¬¿É¶ÔÌìϹæÄ£ÄڵĿͻ§ÌṩÏÖ³¡¿ìËÙÆÊÎöÅŲ顢´¦Öóͷ£¼°¼Ó¹Ì·À»¤¡£

×¢£ºTACµÄÍþвÆÊÎöÄÜÁ¦Çë²Î¿¼¶ñÒâÈí¼þÐÐΪÕ½ÚÄÚÈÝ
¼Ò×幨Áª±ÈÕÕ

AG¹«Ë¾¿Æ¼¼¼ì²âÓë·À»¤¼Æ»®
AG¹«Ë¾¿Æ¼¼¼ì²â·þÎñ
· AG¹«Ë¾¿Æ¼¼¹¤³ÌʦǰÍù¿Í»§ÏÖ³¡¼ì²â¡£
· AG¹«Ë¾¿Æ¼¼ÔÚÏßÔÆ¼ì²â£¬Éϰ¶AG¹«Ë¾¿Æ¼¼ÔÆ£¬ÉêÇ뼫¹âÔ¶³ÌɨÃèÊÔÓá£
https://poma.nsfocus.com/
AG¹«Ë¾¿Æ¼¼Ä¾Âíרɱ½â¾ö¼Æ»®
· ¶ÌÆÚ·þÎñ£ºAG¹«Ë¾¿Æ¼¼¹¤³ÌʦÏÖ³¡Ä¾ÂíºóÃÅÕûÀí·þÎñ£¨È˹¤·þÎñ+IPS+TAC£©¡£È·±£µÚһʱ¼äÏû³ýÍøÂçÄÚÏà¹ØÎ£º¦µã£¬¿ØÖÆÊÂÎñÓ°Ïì¹æÄ££¬ÌṩÊÂÎñÆÊÎö±¨¸æ¡£
· ÖÐÆÚ·þÎñ£ºÌṩ3-6¸öÔµÄΣº¦¼à¿ØÓëѲ¼ì·þÎñ£¨IPS+TAC+È˹¤·þÎñ£©¡£¸ù³ýΣº¦£¬È·±£ÊÂÎñ²»¸´·¢¡£
· ºã¾Ã·þÎñ£º»ù½ðÐÐҵӪҵΣº¦½â¾ö¼Æ»®£¨ÍþвÇ鱨+¹¥»÷ËÝÔ´+רҵÇå¾²·þÎñ£©
×ܽá
IcedIDÊǽðÈÚÍøÂç·¸·¨ÁìÓòнü·¢Ã÷µÄÒ»¸öÍþв¡£ ËäÈ»ÏÖÔÚ»¹²»ÖªµÀËü½«»áÔõÑùÉú³¤£¬µ«ÆäÏÖÔÚµÄÄÜÁ¦£¬Èö²¥·½·¨Ñ¡ÔñºÍ¹¥»÷Ä¿µÄ¶¼Åú×¢ÎúÆä±³ºóÊÇÒ»¸ö¶ÔÕâ¸öÁìÓò²¢²»ÉúÊèµÄÕûÌå¡£
¸½Â¼£º
IOC
|
KEY |
VALUE |
|
DOMAIN |
nejokexulag.example.com nobleduty.com tradequel.net youaboard.com ztekbowrev.com
|
|
PORT |
443 |
|
PROTOCOL |
SSL/TLS |
|
IP |
185.127.26.227 |
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ





