ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ืื—ื“ ืžืกื•ื’ื™ ื”ื”ืชืงืคื•ืช ื”ื ืคื•ืฆื™ื ื‘ื™ื•ืชืจ ื”ื•ื ื”ืฉืจืฆืช ืชื”ืœื™ืš ื–ื“ื•ื ื™ ื‘ืขืฅ ื‘ืชื”ืœื™ื›ื™ื ืžื›ื•ื‘ื“ื™ื ืœื—ืœื•ื˜ื™ืŸ. ื”ื ืชื™ื‘ ืœืงื•ื‘ืฅ ื”ื”ืคืขืœื” ืขืฉื•ื™ ืœื”ื™ื•ืช ื—ืฉื•ื“: ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืžืฉืชืžืฉื•ืช ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื‘ืชื™ืงื™ื•ืช AppData ืื• Temp, ื•ื–ื” ืœื ืื•ืคื™ื™ื ื™ ืœืชื•ื›ื ื™ื•ืช ืœื’ื™ื˜ื™ืžื™ื•ืช. ืœืžืขืŸ ื”ื”ื’ื™ื ื•ืช, ื›ื“ืื™ ืœื•ืžืจ ืฉื›ืžื” ื›ืœื™ ืขื–ืจ ืœืขื“ื›ื•ืŸ ืื•ื˜ื•ืžื˜ื™ ืžื•ืคืขืœื™ื ื‘-AppData, ื›ืš ืฉืจืง ื‘ื“ื™ืงืช ืžื™ืงื•ื ื”ื”ืฉืงื” ืื™ื ื” ืžืกืคื™ืงื” ื›ื“ื™ ืœืืฉืจ ืฉื”ืชื•ื›ื ื™ืช ื–ื“ื•ื ื™ืช.

ื’ื•ืจื ื ื•ืกืฃ ืฉืœ ืœื’ื™ื˜ื™ืžื™ื•ืช ื”ื•ื ื—ืชื™ืžื” ืงืจื™ืคื˜ื•ื’ืจืคื™ืช: ืชื•ื›ื ื™ื•ืช ืžืงื•ืจื™ื•ืช ืจื‘ื•ืช ื—ืชื•ืžื•ืช ืขืœ ื™ื“ื™ ื”ืกืคืง. ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืขื•ื‘ื“ื” ืฉืื™ืŸ ื—ืชื™ืžื” ื›ืฉื™ื˜ื” ืœื–ื™ื”ื•ื™ ืคืจื™ื˜ื™ ื”ืคืขืœื” ื—ืฉื•ื“ื™ื. ืื‘ืœ ืฉื•ื‘ ื™ืฉ ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ืฉืžืฉืชืžืฉืช ื‘ืชืขื•ื“ื” ื’ื ื•ื‘ื” ื›ื“ื™ ืœื—ืชื•ื ืืช ืขืฆืžื”.

ืืชื” ื™ื›ื•ืœ ื’ื ืœื‘ื“ื•ืง ืืช ื”ืขืจืš ืฉืœ ื’ื™ื‘ื•ื‘ ืงืจื™ืคื˜ื•ื’ืจืคื™ MD5 ืื• SHA256, ืฉืขืฉื•ื™ ืœื”ืชืื™ื ืœื›ืžื” ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืฉื–ื•ื”ื• ื‘ืขื‘ืจ. ื ื™ืชืŸ ืœื‘ืฆืข ื ื™ืชื•ื— ืกื˜ื˜ื™ ืขืœ ื™ื“ื™ ื”ืชื‘ื•ื ื ื•ืช ื‘ื—ืชื™ืžื•ืช ื‘ืชื•ื›ื ื™ืช (ื‘ืืžืฆืขื•ืช ื—ื•ืงื™ ื™ืืจื” ืื• ืžื•ืฆืจื™ ืื ื˜ื™ ื•ื™ืจื•ืก). ื™ืฉ ื’ื ื ื™ืชื•ื— ื“ื™ื ืžื™ (ื”ืคืขืœืช ืชื•ื›ื ื™ืช ื‘ืกื‘ื™ื‘ื” ื‘ื˜ื•ื—ื” ื›ืœืฉื”ื™ ื•ืžืขืงื‘ ืื—ืจ ืคืขื•ืœื•ืชื™ื”) ื•ื”ื ื“ืกื” ืœืื—ื•ืจ.

ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ืกื™ืžื ื™ื ืจื‘ื™ื ืœืชื”ืœื™ืš ื–ื“ื•ื ื™. ื‘ืžืืžืจ ื–ื” ื ืกืคืจ ืœื›ื ื›ื™ืฆื“ ืœืืคืฉืจ ื‘ื™ืงื•ืจืช ืฉืœ ืื™ืจื•ืขื™ื ืจืœื•ื•ื ื˜ื™ื™ื ื‘-Windows, ื ื ืชื— ืืช ื”ืกื™ืžื ื™ื ืขืœื™ื”ื ืžืกืชืžืš ื”ื›ืœืœ ื”ืžื•ื‘ื ื” InTrust ืœื–ื”ื•ืช ืชื”ืœื™ืš ื—ืฉื•ื“. InTrust ื”ื•ื ืคืœื˜ืคื•ืจืžืช CLM ืœืื™ืกื•ืฃ, ื ื™ืชื•ื— ื•ืื—ืกื•ืŸ ื ืชื•ื ื™ื ืœื ืžื•ื‘ื ื™ื, ืฉื›ื‘ืจ ื™ืฉ ืœื• ืžืื•ืช ืชื’ื•ื‘ื•ืช ืžื•ื’ื“ืจื•ืช ืžืจืืฉ ืœืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ื”ืชืงืคื•ืช.

ื›ืืฉืจ ื”ืชื•ื›ื ื™ืช ืžื•ืคืขืœืช, ื”ื™ื ื ื˜ืขื ืช ืœื–ื™ื›ืจื•ืŸ ื”ืžื—ืฉื‘. ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ืžื›ื™ืœ ื”ื•ืจืื•ืช ืžื—ืฉื‘ ื•ืกืคืจื™ื•ืช ืชื•ืžื›ื•ืช (ืœื“ื•ื’ืžื”, *.dll). ื›ืืฉืจ ืชื”ืœื™ืš ื›ื‘ืจ ืคื•ืขืœ, ื”ื•ื ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืฉืจืฉื•ืจื™ื ื ื•ืกืคื™ื. ืฉืจืฉื•ืจื™ื ืžืืคืฉืจื™ื ืœืชื”ืœื™ืš ืœื‘ืฆืข ืงื‘ื•ืฆื•ืช ืฉื•ื ื•ืช ืฉืœ ื”ื•ืจืื•ืช ื‘ื• ื–ืžื ื™ืช. ื™ืฉื ืŸ ื“ืจื›ื™ื ืจื‘ื•ืช ืœืงื•ื“ ื–ื“ื•ื ื™ ืœื—ื“ื•ืจ ืœื–ื™ื›ืจื•ืŸ ื•ืœืจื•ืฅ, ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื›ืžื” ืžื”ืŸ.

ื”ื“ืจืš ื”ืงืœื” ื‘ื™ื•ืชืจ ืœื”ืคืขื™ืœ ืชื”ืœื™ืš ื–ื“ื•ื ื™ ื”ื™ื ืœืืœืฅ ืืช ื”ืžืฉืชืžืฉ ืœื”ืคืขื™ืœ ืื•ืชื• ื™ืฉื™ืจื•ืช (ืœื“ื•ื’ืžื”, ืžืงื•ื‘ืฅ ืžืฆื•ืจืฃ ืœื“ื•ื"ืœ), ื•ืœืื—ืจ ืžื›ืŸ ืœื”ืฉืชืžืฉ ื‘ืžืงืฉ RunOnce ื›ื“ื™ ืœื”ืคืขื™ืœ ืื•ืชื• ื‘ื›ืœ ืคืขื ืฉื”ืžื—ืฉื‘ ืžื•ืคืขืœ. ื–ื” ื›ื•ืœืœ ื’ื ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช "ื ื˜ื•ืœืช ืงื‘ืฆื™ื" ื”ืžืื—ืกื ืช ืกืงืจื™ืคื˜ื™ื ืฉืœ PowerShell ื‘ืžืคืชื—ื•ืช ืจื™ืฉื•ื ื”ืžื•ืคืขืœื™ื ืขืœ ืกืžืš ื˜ืจื™ื’ืจ. ื‘ืžืงืจื” ื–ื”, ื”ืกืงืจื™ืคื˜ ืฉืœ PowerShell ื”ื•ื ืงื•ื“ ื–ื“ื•ื ื™.

ื”ื‘ืขื™ื” ื‘ื”ืคืขืœืช ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ื‘ืžืคื•ืจืฉ ื”ื™ื ืฉื–ื•ื”ื™ ื’ื™ืฉื” ื™ื“ื•ืขื” ืฉืžืชื’ืœื” ื‘ืงืœื•ืช. ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืžืกื•ื™ืžื•ืช ืขื•ืฉื•ืช ื“ื‘ืจื™ื ื—ื›ืžื™ื ื™ื•ืชืจ, ื›ืžื• ืฉื™ืžื•ืฉ ื‘ืชื”ืœื™ืš ืื—ืจ ื›ื“ื™ ืœื”ืชื—ื™ืœ ืœื‘ืฆืข ื‘ื–ื™ื›ืจื•ืŸ. ืœื›ืŸ, ืชื”ืœื™ืš ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืชื”ืœื™ืš ืื—ืจ ืขืœ ื™ื“ื™ ื”ืคืขืœืช ื”ื•ืจืืช ืžื—ืฉื‘ ืกืคืฆื™ืคื™ืช ื•ืฆื™ื•ืŸ ืงื•ื‘ืฅ ื”ืคืขืœื” (.exe) ืœื”ืคืขืœื”.

ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืืช ื”ืงื•ื‘ืฅ ื‘ืืžืฆืขื•ืช ื ืชื™ื‘ ืžืœื (ืœื“ื•ื’ืžื”, C:Windowssystem32cmd.exe) ืื• ื ืชื™ื‘ ื—ืœืงื™ (ืœื“ื•ื’ืžื”, cmd.exe). ืื ื”ืชื”ืœื™ืš ื”ืžืงื•ืจื™ ืื™ื ื• ืžืื•ื‘ื˜ื—, ื”ื•ื ื™ืืคืฉืจ ืœืชื•ื›ื ื™ื•ืช ืœื ืœื’ื™ื˜ื™ืžื™ื•ืช ืœืคืขื•ืœ. ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ื™ืจืื•ืช ื›ืš: ืชื”ืœื™ืš ืžืคืขื™ืœ ืืช cmd.exe ืžื‘ืœื™ ืœืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ื”ืžืœื, ื”ืชื•ืงืฃ ืžืฆื™ื‘ ืืช cmd.exe ืฉืœื• ื‘ืžืงื•ื ื›ืš ืฉื”ืชื”ืœื™ืš ืžืคืขื™ืœ ืื•ืชื• ืœืคื ื™ ื”ื ืชื™ื‘ ื”ืœื’ื™ื˜ื™ืžื™. ื‘ืจื’ืข ืฉื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืคื•ืขืœืช, ื”ื™ื ื™ื›ื•ืœื” ื‘ืชื•ืจื” ืœื”ืคืขื™ืœ ืชื•ื›ื ื™ืช ืœื’ื™ื˜ื™ืžื™ืช (ื›ื’ื•ืŸ C:Windowssystem32cmd.exe) ื›ืš ืฉื”ืชื•ื›ื ื™ืช ื”ืžืงื•ืจื™ืช ืชืžืฉื™ืš ืœืขื‘ื•ื“ ื›ืจืื•ื™.

ื•ืจื™ืืฆื™ื” ืฉืœ ื”ืžืชืงืคื” ื”ืงื•ื“ืžืช ื”ื™ื ื”ื–ืจืงืช DLL ืœืชื”ืœื™ืš ืœื’ื™ื˜ื™ืžื™. ื›ืืฉืจ ืชื”ืœื™ืš ืžืชื—ื™ืœ, ื”ื•ื ืžื•ืฆื ื•ื˜ื•ืขืŸ ืกืคืจื™ื•ืช ืฉืžืจื—ื™ื‘ื•ืช ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœื•. ื‘ืืžืฆืขื•ืช ื”ื–ืจืงืช DLL, ืชื•ืงืฃ ื™ื•ืฆืจ ืกืคืจื™ื™ื” ื–ื“ื•ื ื™ืช ืขื ืื•ืชื• ืฉื ื•-API ื›ืžื• ืกืคืจื™ื™ื” ืœื’ื™ื˜ื™ืžื™ืช. ื”ืชื•ื›ื ื™ืช ื˜ื•ืขื ืช ืกืคืจื™ื™ื” ื–ื“ื•ื ื™ืช, ื•ื”ื™ื, ื‘ืชื•ืจื”, ื˜ื•ืขื ืช ืกืคืจื™ื™ื” ืœื’ื™ื˜ื™ืžื™ืช, ื•ื‘ืžื™ื“ืช ื”ืฆื•ืจืš ืงื•ืจืืช ืœื” ืœื‘ืฆืข ืคืขื•ืœื•ืช. ื”ืกืคืจื™ื™ื” ื”ื–ื“ื•ื ื™ืช ืžืชื—ื™ืœื” ืœืคืขื•ืœ ื›ืคืจื•ืงืกื™ ืœืกืคืจื™ื™ื” ื”ื˜ื•ื‘ื”.

ื“ืจืš ื ื•ืกืคืช ืœื”ื›ื ื™ืก ืงื•ื“ ื–ื“ื•ื ื™ ืœื–ื™ื›ืจื•ืŸ ื”ื™ื ืœื”ื›ื ื™ืก ืื•ืชื• ืœืชื”ืœื™ืš ืœื ื‘ื˜ื•ื— ืฉื›ื‘ืจ ืคื•ืขืœ. ืชื”ืœื™ื›ื™ื ืžืงื‘ืœื™ื ืงืœื˜ ืžืžืงื•ืจื•ืช ืฉื•ื ื™ื - ืงืจื™ืื” ืžื”ืจืฉืช ืื• ืžืงื‘ืฆื™ื. ื‘ื“ืจืš ื›ืœืœ ื”ื ืžื‘ืฆืขื™ื ื‘ื“ื™ืงื” ื›ื“ื™ ืœื•ื•ื“ื ืฉื”ืงืœื˜ ื”ื•ื ืœื’ื™ื˜ื™ืžื™. ืื‘ืœ ืœื—ืœืง ืžื”ืชื”ืœื™ื›ื™ื ืื™ืŸ ื”ื’ื ื” ืžืชืื™ืžื” ื‘ืขืช ื‘ื™ืฆื•ืข ื”ื•ืจืื•ืช. ื‘ื”ืชืงืคื” ื–ื•, ืื™ืŸ ืกืคืจื™ื” ื‘ื“ื™ืกืง ืื• ืงื•ื‘ืฅ ื”ืคืขืœื” ื”ืžื›ื™ืœื™ื ืงื•ื“ ื–ื“ื•ื ื™. ื”ื›ืœ ืžืื•ื—ืกืŸ ื‘ื–ื™ื›ืจื•ืŸ ื™ื—ื“ ืขื ื”ืชื”ืœื™ืš ื”ืžื ื•ืฆืœ.

ื›ืขืช ื ืกืชื›ืœ ืขืœ ื”ืžืชื•ื“ื•ืœื•ื’ื™ื” ืœืืคืฉืจ ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ื›ืืœื” ื‘-Windows ื•ืืช ื”ื›ืœืœ ื‘-InTrust ืฉืžื™ื™ืฉื ื”ื’ื ื” ืžืคื ื™ ืื™ื•ืžื™ื ื›ืืœื”. ืจืืฉื™ืช, ื‘ื•ืื• ื ืคืขื™ืœ ืื•ืชื• ื“ืจืš ืžืกื•ืฃ ื”ื ื™ื”ื•ืœ ืฉืœ InTrust.

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ื”ื›ืœืœ ืžืฉืชืžืฉ ื‘ื™ื›ื•ืœื•ืช ืžืขืงื‘ ื”ืชื”ืœื™ืš ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows. ืœืžืจื‘ื” ื”ืฆืขืจ, ื”ืคืขืœืช ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ื›ืืœื” ืจื—ื•ืงื” ืžืœื”ื™ื•ืช ื‘ืจื•ืจื” ืžืืœื™ื”. ื™ืฉื ืŸ 3 ื”ื’ื“ืจื•ืช ืฉื•ื ื•ืช ืฉืœ ืžื“ื™ื ื™ื•ืช ืงื‘ื•ืฆืชื™ืช ืฉืขืœื™ืš ืœืฉื ื•ืช:

ืชืฆื•ืจืช ืžื—ืฉื‘ > ืžื“ื™ื ื™ื•ืช > ื”ื’ื“ืจื•ืช Windows > ื”ื’ื“ืจื•ืช ืื‘ื˜ื—ื” > ืžื“ื™ื ื™ื•ืช ืžืงื•ืžื™ืช > ืžื“ื™ื ื™ื•ืช ื‘ื™ืงื•ืจืช > ืžืขืงื‘ ืื—ืจ ืชื”ืœื™ืš ื‘ื™ืงื•ืจืช

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ืชืฆื•ืจืช ืžื—ืฉื‘ > ืžื“ื™ื ื™ื•ืช > ื”ื’ื“ืจื•ืช Windows > ื”ื’ื“ืจื•ืช ืื‘ื˜ื—ื” > ืชืฆื•ืจืช ืžื“ื™ื ื™ื•ืช ื‘ื™ืงื•ืจืช ืžืชืงื“ืžืช > ืžื“ื™ื ื™ื•ืช ื‘ื™ืงื•ืจืช > ืžืขืงื‘ ืžืคื•ืจื˜ > ื™ืฆื™ืจืช ืชื”ืœื™ืš ื‘ื™ืงื•ืจืช

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ืชืฆื•ืจืช ืžื—ืฉื‘ > ืžื“ื™ื ื™ื•ืช > ืชื‘ื ื™ื•ืช ื ื™ื”ื•ืœ > ืžืขืจื›ืช > ื™ืฆื™ืจืช ืชื”ืœื™ืš ื‘ื™ืงื•ืจืช > ื›ืœื•ืœ ืฉื•ืจืช ืคืงื•ื“ื” ื‘ืื™ืจื•ืขื™ ื™ืฆื™ืจืช ืชื”ืœื™ืš

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ืœืื—ืจ ื”ืคืขืœืชื, ื›ืœืœื™ InTrust ืžืืคืฉืจื™ื ืœืš ืœื–ื”ื•ืช ืื™ื•ืžื™ื ืฉืœื ื”ื™ื• ื™ื“ื•ืขื™ื ื‘ืขื‘ืจ ืฉืžืคื’ื™ื ื™ื ื”ืชื ื”ื’ื•ืช ื—ืฉื•ื“ื”. ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœื–ื”ื•ืช ื”ืžืชื•ืืจ ื›ืืŸ ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ืฉืœ Dridex. ื”ื•ื“ื•ืช ืœืคืจื•ื™ืงื˜ HP Bromium, ืื ื• ื™ื•ื“ืขื™ื ื›ื™ืฆื“ ื”ืื™ื•ื ื”ื–ื” ืขื•ื‘ื“.

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ื‘ืฉืจืฉืจืช ื”ืคืขื•ืœื•ืช ืฉืœื”, Dridex ืžืฉืชืžืฉืช ื‘-schtasks.exe ื›ื“ื™ ืœื™ืฆื•ืจ ืžืฉื™ืžื” ืžืชื•ื–ืžื ืช. ืฉื™ืžื•ืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช ื”ืžืกื•ื™ื ื”ื–ื” ืžืฉื•ืจืช ื”ืคืงื•ื“ื” ื ื—ืฉื‘ ืœื”ืชื ื”ื’ื•ืช ื—ืฉื•ื“ื” ืžืื•ื“; ื”ืคืขืœืช svchost.exe ืขื ืคืจืžื˜ืจื™ื ื”ืžืฆื‘ื™ืขื™ื ืขืœ ืชื™ืงื™ื•ืช ืžืฉืชืžืฉ ืื• ืขื ืคืจืžื˜ืจื™ื ื“ื•ืžื™ื ืœืคืงื•ื“ื•ืช "net view" ืื• "whoami" ื ืจืื™ืช ื“ื•ืžื”. ื”ื ื” ืงื˜ืข ืžื”ืžืชืื™ื ื—ื•ืงื™ SIGMA:

detection:
    selection1:
        CommandLine: '*svchost.exe C:Users\*Desktop\*'
    selection2:
        ParentImage: '*svchost.exe*'
        CommandLine:
            - '*whoami.exe /all'
            - '*net.exe view'
    condition: 1 of them

ื‘-InTrust, ื›ืœ ื”ืชื ื”ื’ื•ืช ื—ืฉื•ื“ื” ื ื›ืœืœืช ื‘ื›ืœืœ ืื—ื“, ืžื›ื™ื•ื•ืŸ ืฉืจื•ื‘ ื”ืคืขื•ืœื•ืช ื”ืœืœื• ืื™ื ืŸ ืกืคืฆื™ืคื™ื•ืช ืœืื™ื•ื ืžืกื•ื™ื, ืืœื ื”ืŸ ื—ืฉื•ื“ื•ืช ื‘ืžืชื—ื ื•ื‘-99% ืžื”ืžืงืจื™ื ืžืฉืžืฉื•ืช ืœืžื˜ืจื•ืช ืœื ืœื’ืžืจื™ ื ืขืœื•ืช. ืจืฉื™ืžืช ืคืขื•ืœื•ืช ื–ื• ื›ื•ืœืœืช ื‘ื™ืŸ ื”ื™ืชืจ:

  • ืชื”ืœื™ื›ื™ื ื”ืคื•ืขืœื™ื ืžืžื™ืงื•ืžื™ื ื—ืจื™ื’ื™ื, ื›ื’ื•ืŸ ืชื™ืงื™ื•ืช ื–ืžื ื™ื•ืช ืฉืœ ื”ืžืฉืชืžืฉ.
  • ืชื”ืœื™ืš ืžืขืจื›ืช ื™ื“ื•ืข ืขื ื™ืจื•ืฉื” ื—ืฉื•ื“ื” - ืื™ื•ืžื™ื ืžืกื•ื™ืžื™ื ืขืฉื•ื™ื™ื ืœื ืกื•ืช ืœื”ืฉืชืžืฉ ื‘ืฉื ืฉืœ ืชื”ืœื™ื›ื™ ืžืขืจื›ืช ื›ื“ื™ ืœื”ื™ืฉืืจ ื‘ืœืชื™ ืžื–ื•ื”ื™ื.
  • ื‘ื™ืฆื•ืขื™ื ื—ืฉื•ื“ื™ื ืฉืœ ื›ืœื™ ื ื™ื”ื•ืœ ื›ื’ื•ืŸ cmd ืื• PsExec ื›ืืฉืจ ื”ื ืžืฉืชืžืฉื™ื ื‘ืื™ืฉื•ืจื™ ืžืขืจื›ืช ืžืงื•ืžื™ื™ื ืื• ื‘ื™ืจื•ืฉื” ื—ืฉื•ื“ื”.
  • ืคืขื•ืœื•ืช ื—ืฉื•ื“ื•ืช ืœื”ืขืชืงืช ืฆืœ ื”ืŸ ื”ืชื ื”ื’ื•ืช ื ืคื•ืฆื” ืฉืœ ื•ื™ืจื•ืกื™ ื›ื•ืคืจ ืœืคื ื™ ื”ืฆืคื ืช ืžืขืจื›ืช; ื”ืŸ ื”ื•ืจื’ื•ืช ื’ื™ื‘ื•ื™ื™ื:

    - ื“ืจืš vssadmin.exe;
    - ื“ืจืš WMI.

  • ืจืฉื•ื ืžื–ื‘ืœื•ืช ืฉืœ ื›ื•ื•ืจื•ืช ืจื™ืฉื•ื ืฉืœืžื•ืช.
  • ืชื ื•ืขื” ืื•ืคืงื™ืช ืฉืœ ืงื•ื“ ื–ื“ื•ื ื™ ื›ืืฉืจ ืชื”ืœื™ืš ืžื•ืคืขืœ ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื•ืช ื›ื’ื•ืŸ at.exe.
  • ืคืขื•ืœื•ืช ื—ืฉื•ื“ื•ืช ืฉืœ ืงื‘ื•ืฆื•ืช ืžืงื•ืžื™ื•ืช ื•ืคืขื•ืœื•ืช ืชื—ื•ื ื‘ืืžืฆืขื•ืช net.exe.
  • ืคืขื™ืœื•ืช ื—ื•ืžืช ืืฉ ื—ืฉื•ื“ื” ื‘ืืžืฆืขื•ืช netsh.exe.
  • ืžื ื™ืคื•ืœืฆื™ื” ื—ืฉื•ื“ื” ืฉืœ ื”-ACL.
  • ืฉื™ืžื•ืฉ ื‘-BITS ืœื—ื™ืœื•ืฅ ื ืชื•ื ื™ื.
  • ืžื ื™ืคื•ืœืฆื™ื•ืช ื—ืฉื•ื“ื•ืช ืขื WMI.
  • ืคืงื•ื“ื•ืช ืชืกืจื™ื˜ ื—ืฉื•ื“ื•ืช.
  • ื ื™ืกื™ื•ื ื•ืช ืœื–ืจื•ืง ืงื‘ืฆื™ ืžืขืจื›ืช ืžืื•ื‘ื˜ื—ื™ื.

ื”ื›ืœืœ ื”ืžืฉื•ืœื‘ ืขื•ื‘ื“ ื˜ื•ื‘ ืžืื•ื“ ื›ื“ื™ ืœื–ื”ื•ืช ืื™ื•ืžื™ื ื›ื’ื•ืŸ RUYK, LockerGoga ื•ืขืจื›ื•ืช ื›ืœื™ื ืื—ืจื•ืช ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ, ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื•ืคืฉืขื™ ืกื™ื™ื‘ืจ. ื”ื›ืœืœ ื ื‘ื“ืง ืขืœ ื™ื“ื™ ื”ืกืคืง ื‘ืกื‘ื™ื‘ื•ืช ื™ื™ืฆื•ืจ ื›ื“ื™ ืœืžื–ืขืจ ืชื•ืฆืื•ืช ื—ื™ื•ื‘ื™ื•ืช ืฉื’ื•ื™ื•ืช. ื•ื‘ื–ื›ื•ืช ืคืจื•ื™ืงื˜ SIGMA, ืจื•ื‘ ื”ืื™ื ื“ื™ืงื˜ื•ืจื™ื ื”ืœืœื• ืžื™ื™ืฆืจื™ื ืžืกืคืจ ืžื™ื ื™ืžืœื™ ืฉืœ ืื™ืจื•ืขื™ ืจืขืฉ.

ื›ื™ ื‘-InTrust ื–ื”ื• ื›ืœืœ ื ื™ื˜ื•ืจ, ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืกืงืจื™ืคื˜ ืชื’ื•ื‘ื” ื›ืชื’ื•ื‘ื” ืœืื™ื•ื. ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืื—ื“ ืžื”ืกืงืจื™ืคื˜ื™ื ื”ืžื•ื‘ื ื™ื ืื• ืœื™ืฆื•ืจ ืžืฉืœืš ื•-InTrust ื™ืคื™ืฅ ืื•ืชื• ืื•ื˜ื•ืžื˜ื™ืช.

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ื‘ื ื•ืกืฃ, ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ืืช ื›ืœ ื”ื˜ืœืžื˜ืจื™ื” ื”ืงืฉื•ืจื” ืœืื™ืจื•ืขื™ื: ืกืงืจื™ืคื˜ื™ื ืฉืœ PowerShell, ื‘ื™ืฆื•ืข ืชื”ืœื™ื›ื™ื, ืžื ื™ืคื•ืœืฆื™ื•ืช ืžืชื•ื–ืžื ื•ืช ืฉืœ ืžืฉื™ืžื•ืช, ืคืขื™ืœื•ืช ืื“ืžื™ื ื™ืกื˜ืจื˜ื™ื‘ื™ืช ืฉืœ WMI, ื•ืœื”ืฉืชืžืฉ ื‘ื”ื ืœื ืชื™ื—ื” ืฉืœืื—ืจ ื”ืžื•ื•ืช ื‘ืžื”ืœืš ืื™ืจื•ืขื™ ืื‘ื˜ื—ื”.

ืื ื• ืžืืคืฉืจื™ื ืื™ืกื•ืฃ ืื™ืจื•ืขื™ื ืขืœ ื”ืฉืงืช ืชื”ืœื™ื›ื™ื ื—ืฉื•ื“ื™ื ื‘-Windows ื•ืžื–ื”ื™ื ืื™ื•ืžื™ื ื‘ืืžืฆืขื•ืช Quest InTrust

ืœ-InTrust ื™ืฉ ืžืื•ืช ื›ืœืœื™ื ืื—ืจื™ื, ื—ืœืงื:

  • ื–ื™ื”ื•ื™ ืžืชืงืคืช ืฉื“ืจื•ื’ ืœืื—ื•ืจ ืฉืœ PowerShell ื”ื•ื ื›ืืฉืจ ืžื™ืฉื”ื• ืžืฉืชืžืฉ ื‘ื›ื•ื•ื ื” ื‘ื’ืจืกื” ื™ืฉื ื” ื™ื•ืชืจ ืฉืœ PowerShell ืžื›ื™ื•ื•ืŸ ืฉ... ื‘ื’ืจืกื” ื”ื™ืฉื ื” ื™ื•ืชืจ ืœื ื”ื™ื™ืชื” ื“ืจืš ืœื‘ื“ื•ืง ืžื” ืงื•ืจื”.
  • ื–ื™ื”ื•ื™ ื›ื ื™ืกื” ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช ื”ื•ื ื›ืืฉืจ ื—ืฉื‘ื•ื ื•ืช ืฉื”ื ื—ื‘ืจื™ื ื‘ืงื‘ื•ืฆื” ืžื•ืกืžื›ืช ืžืกื•ื™ืžืช (ื›ื’ื•ืŸ ืžื ื”ืœื™ ืชื—ื•ื) ื ื›ื ืกื™ื ืœืชื—ื ื•ืช ืขื‘ื•ื“ื” ื‘ื˜ืขื•ืช ืื• ืขืงื‘ ืชืงืจื™ื•ืช ืื‘ื˜ื—ื”.

InTrust ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ื•ืช ื”ืื‘ื˜ื—ื” ื”ื˜ื•ื‘ื•ืช ื‘ื™ื•ืชืจ ื‘ืฆื•ืจื” ืฉืœ ื›ืœืœื™ ื–ื™ื”ื•ื™ ื•ืชื’ื•ื‘ื” ืžื•ื’ื“ืจื™ื ืžืจืืฉ. ื•ืื ืืชื” ื—ื•ืฉื‘ ืฉืžืฉื”ื• ืฆืจื™ืš ืœืขื‘ื•ื“ ืื—ืจืช, ืืชื” ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืขื•ืชืง ืžืฉืœืš ืฉืœ ื”ื›ืœืœ ื•ืœื”ื’ื“ื™ืจ ืื•ืชื• ืœืคื™ ื”ืฆื•ืจืš. ื ื™ืชืŸ ืœื”ื’ื™ืฉ ื‘ืงืฉื” ืœื‘ื™ืฆื•ืข ืคื™ื™ืœื•ื˜ ืื• ืงื‘ืœืช ืขืจื›ื•ืช ื”ืคืฆื” ืขื ืจื™ืฉื™ื•ื ื•ืช ื–ืžื ื™ื™ื ื“ืจืš ื˜ื•ืคืก ืžืฉื•ื‘ ื‘ืืชืจ ืฉืœื ื•.

ื”ื™ืจืฉืžื• ืœื ื• ืขืžื•ื“ ื‘ืคื™ื™ืกื‘ื•ืง, ืื ื• ืžืคืจืกืžื™ื ืฉื ื”ืขืจื•ืช ืงืฆืจื•ืช ื•ืงื™ืฉื•ืจื™ื ืžืขื ื™ื™ื ื™ื.

ืงืจื ืืช ื”ืžืืžืจื™ื ื”ืื—ืจื™ื ืฉืœื ื• ื‘ื ื•ืฉื ืื‘ื˜ื—ืช ืžื™ื“ืข:

ื›ื™ืฆื“ InTrust ื™ื›ื•ืœ ืœืขื–ื•ืจ ืœื”ืคื—ื™ืช ืืช ืฉื™ืขื•ืจ ื ื™ืกื™ื•ื ื•ืช ื”ื”ืจืฉืื” ื”ื›ื•ืฉืœื™ื ื‘ืืžืฆืขื•ืช RDP

ืื ื• ืžื–ื”ื™ื ืžืชืงืคืช ื›ื•ืคืจ, ืžืงื‘ืœื™ื ื’ื™ืฉื” ืœื‘ืงืจ ื”ืชื—ื•ื ื•ืžื ืกื™ื ืœื”ืชื ื’ื“ ืœื”ืชืงืคื•ืช ืืœื•

ืื™ืœื• ื“ื‘ืจื™ื ืฉื™ืžื•ืฉื™ื™ื ื ื™ืชืŸ ืœื—ืœืฅ ืžื”ื™ื•ืžื ื™ื ืฉืœ ืชื—ื ืช ืขื‘ื•ื“ื” ืžื‘ื•ืกืกืช Windows? (ืžืืžืจ ืคื•ืคื•ืœืจื™)

ืžืขืงื‘ ืื—ืจ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ืฉืœ ืžืฉืชืžืฉื™ื ืœืœื ืคืœื™ื™ืจ ืื• ืกืจื˜ ื“ื‘ื™ืง

ืžื™ ืขืฉื” ืืช ื–ื”? ืื ื• ืขื•ืฉื™ื ืื•ื˜ื•ืžืฆื™ื” ืฉืœ ื‘ื™ืงื•ืจืช ืื‘ื˜ื—ืช ืžื™ื“ืข

ื›ื™ืฆื“ ืœื”ืคื—ื™ืช ืืช ืขืœื•ืช ื”ื‘ืขืœื•ืช ืขืœ ืžืขืจื›ืช SIEM ื•ืœืžื” ืืชื” ืฆืจื™ืš ื ื™ื”ื•ืœ ื™ื•ืžื ื™ื ืžืจื›ื–ื™ื™ื (CLM)

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”