ÐÂÐÍÀÕË÷²¡¶¾VIBOROTÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-28

ÊÖÒÕϸ½Ú


VIBOROTÀÕË÷²¡¶¾ÓÚ2018Äê9ÔÂÖÐÑ®Ê״η¢Ã÷£¬£¬£¬£¬£¬£¬£¬±»¸Ã²¡¶¾¼ÓÃܺóµÄÎļþÀ©Õ¹ÃûΪ.enc¡£¡£¡£¡£¡£¡£Í¨Ì«¹ýÎö¸Ã²¡¶¾£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÆäÊ×ÏÈͨ¹ý¼ì²é×¢²á±í¼üÖµ(ÅÌËã»úGUIDºÍ²úÆ·ÃÜÔ¿)À´È·ÈÏÊÇ·ñÐèÒª¼ÓÃܱ»Ñ¬È¾ÏµÍ³ÖеÄÎļþ¡£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¡¾VIBOROTͨ¹ýÅÌÎÊ×¢²á±íÀ´ÅжÏÊÇ·ñ±£´æÌض¨×¢²á±í¼üÖµ¡¿


ÈôÊDZ»Ñ¬È¾ÏµÍ³Öб£´æÌض¨µÄ×¢²á±í¼üÖµ£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷²¡¶¾²»µ«Í¨¹ýËæ»úÊý¼ÓÃÜÌìÉúÆ÷ÌìÉú¼ÓÃÜÏ¢ÕùÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬ÓÃÀ´¼ÓÃÜϵͳÖеÄÎļþ¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»¹»á½«ÍøÂçµÄÊܺ¦ÕßÐÅϢͨ¹ýPOST·¢Ë͵½C&CЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÆäÍøÂçÈçÏÂÐÅÏ¢:
ÅÌËã»úGUID
ÅÌËã»úÃû
Óû§Ãû
VIBOROTÀÕË÷²¡¶¾¼ÓÃÜÈçÏÂÀ©Õ¹ÃûÎļþ:

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¡¾VIBOROT¼ÓÃÜÄ £¿£¿£¿é´úÂë½ØÍ¼¡¿


VIBOROTÀÕË÷²¡¶¾»¹¾ßÓмüÅ̼ͼ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Æä»á½«¼Í¼µÄÐÅÏ¢·¢Ë͸øC&CЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ò»µ©ÅþÁ¬Àֳɣ¬£¬£¬£¬£¬£¬£¬Æä»¹»áÏÂÔØ¶ñÒâµÄ¶þ½øÖÆÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýPowerShellÖ´ÐÐËü¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¡¾VIBOROT¼üÅ̼ͼ¹¦Ð§´úÂë½ØÍ¼¡¿


VIBOROTÀÕË÷²¡¶¾Ê¹Óñ»Ñ¬È¾»úеµÄMicrosoft Outlook×Ô¶¯Ïò±»º¦ÕßµÄͨѶ¼·¢ËÍÀ¬»øÓʼþ£¬£¬£¬£¬£¬£¬£¬Æä¸½¼þΪVIBOROTÀÕË÷²¡¶¾»òÕßÊÇ´ÓC&CЧÀÍÆ÷ÏÂÔØµÄ¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¡¾VIBOROTʹÓÃMicrosoft Outlook·¢ËÍÀ¬»øÓʼþ´úÂë½ØÍ¼¡¿


ѬȾ¸ÃÀÕË÷²¡¶¾ºó£¬£¬£¬£¬£¬£¬£¬Æä×ÀÃæÍ¼Ö½Äð³ÉÈçÏÂÀÕË÷ÐÅÏ¢£º

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¡¾VIBOROTÀÕË÷ÐÅÏ¢½ØÍ¼¡¿


Ìá·ÀÒªÁì


1.²»Òªµã»÷ȪԴ²»Ã÷µÄÓʼþÒÔ¼°¸½¼þ£»£»£»£»£»£»£»
2.²»Òªµã»÷ÓʼþÖеĿÉÒÉÁ´½Ó£»£»£»£»£»£»£»
3.ʵʱÉý¼¶ÏµÍ³£¬£¬£¬£¬£¬£¬£¬´òȫϵͳ²¹¶¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»
4.Ö»¹Ü¹Ø±Õ²»ÐëÒªµÄÎļþ¹²ÏíȨÏ޺Ͳ»ÐëÒªµÄ¶Ë¿Ú£»£»£»£»£»£»£»

5.Çë×¢ÖØ±¸·ÝÖ÷ÒªÎĵµ¡£¡£¡£¡£¡£¡£±¸·ÝµÄ×î¼Ñ×ö·¨ÊǽÓÄÉ3-2-1¹æÔò£¬£¬£¬£¬£¬£¬£¬¼´ÖÁÉÙ×öÈý¸ö¸±±¾£¬£¬£¬£¬£¬£¬£¬ÓÃÁ½ÖÖ²î±ðÃûÌÃÉúÑÄ£¬£¬£¬£¬£¬£¬£¬²¢½«¸±±¾·ÅÔÚÒìµØ´æ´¢¡£¡£¡£¡£¡£¡£


IOCs


Hash detected as RANSOM_VIBOROT.THIAHAH (SHA256):    
911b25a4d99e65ff920ba0e2ef387653b45789ef4693ef36d95f14c9777a568b
Related malicious URLs:
hxxps://viro(.)mleydier(.)fr
hxxps://viro(.)mleydier(.)fr/noauth/order/
hxxps://viro(.)mleydier(.)fr/noauth/keys/
hxxps://viro(.)mleydier(.)fr/noauth/attachment/

hxxps://viro(.)mleydier(.)fr/noauth/attachment/


²Î¿¼Á´½Ó


https://blog.trendmicro.com/trendlabs-security-intelligence/virobot-ransomware-with-botnet-capability-breaks-through/