Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºOilRig £¨APT-Q-53£©

ʱ¼ä£º2021-10-21 ×÷Õߣº»¢·ûÖÇ¿â

·ÖÏíµ½£º

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºOilRig £¨APT-Q-53£©

    ±¾ÎÄ3049×ÖÔĶÁÔ¼Ðè8ÖÓ

    ¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬ £¬£¬£¬ £¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬ £¬£¬£¬ £¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬ £¬£¬£¬ £¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽá¡£¡£¡£¡£¡£¡£

    »¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬ £¬£¬£¬ £¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬ £¬£¬£¬ £¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£±¾´ÎËø¶¨Ö÷Òª¹¥»÷Öж«µØÇøÕþ¸®¡¢ÄÜÔ´¡¢»¯¹¤¼°µçÐŵÈÐÐÒµµÄ¹ú¼Ò¼¶ºÚ¿ÍÍŻOilRig¡£¡£¡£¡£¡£¡£

    04

    Oilrig

    OilRigÊÇÖж«Ä³¹úÕþ¸®Ö§³ÖµÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£Ö÷ÒªÕë¶ÔÖж«¹ú¼ÒʵÑé¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬½ü¼¸ÄêÀ´ÎÒ¹úÒ²³ÉΪÁËÆä¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£

    ¸ÃAPT×éÖ¯×ÅÃû¶È½Ï¸ß£¬£¬ £¬£¬£¬ £¬£¬´ú±íÁ˸ùúÍø¾üµÄ×î¸ßÍøÂç¹¥»÷ˮƽ¡£¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÄÚ²¿¸ú×Ù±àºÅΪAPT-Q-53¡£¡£¡£¡£¡£¡£

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºOilRig £¨APT-Q-53£©

    Åä¾°

    OilRigÓÖÃûHelixKitten¡¢APT34¡¢GreenBug¡¢ITG13µÈ³Æºô£¬£¬ £¬£¬£¬ £¬£¬ÊÇÖж«Ä³¹úÕþ¸®Ö§³ÖÏÂ×ÅÃû¶È×î¸ßµÄAPT×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£

    ×Ô2014Äê±»·¢Ã÷ÒÔÀ´£¬£¬ £¬£¬£¬ £¬£¬OilRigÒ»Ö±·Ç³£»£»£»£»£»£» £»£»îÔ¾£¬£¬ £¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔÖж«¹ú¼ÒʵÑé¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬Æä´ÎÊÇÃÀ¹ú¡¢ÍÁ¶úÆä¡¢Ó¢¹úµÈÎ÷·½¹ú¼Ò£¬£¬ £¬£¬£¬ £¬£¬Ò²°üÀ¨ÖйúºÍÓ¡¶È¡£¡£¡£¡£¡£¡£

    OilRig¹¥»÷Ä¿µÄÏêϸ°üÀ¨°üÀ¨Õþ¸®¡¢Ã½Ìå¡¢¼°ÊÖÒÕЧÀÍÌṩÉ̵È×éÖ¯£¬£¬ £¬£¬£¬ £¬£¬ÐÐÒµ°üÀ¨½ðÈÚ¡¢Õþ¸®¡¢ÄÜÔ´¡¢»¯¹¤ºÍµçÐŵÈÁìÓò¡£¡£¡£¡£¡£¡£

    ´Ó¹¥»÷Ä¿µÄ¿ÉÒÔ¿´³ö£¬£¬ £¬£¬£¬ £¬£¬OilRigÓë¸Ã¹ú¹ú¼ÒÀûÒæºÍ×÷սʱ¼ä¼á³Ö»ù±¾Ò»Ö£¬£¬ £¬£¬£¬ £¬£¬Ô½·¢¹Ø×¢Éæ¼°Æä¹ú¼ÒÀûÒæµÄϸ½ÚÇ鱨¡£¡£¡£¡£¡£¡£2019ÄêOilRigÔâÊÜÖØ´ó¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬´ó×ÚÓë¸Ã¼¯ÍÅÏà¹ØµÄÐÅϢͨ¹ýTelegram±»¹ûÕæ¡£¡£¡£¡£¡£¡£Ð¹Â¶ÄÚÈݰüÀ¨Ê®ÓàÃû³ÉÔ±µÄÏêϸСÎÒ˽¼ÒÐÅÏ¢¼°Èô¸ÉÍøÂçÎäÆ÷¡£¡£¡£¡£¡£¡£Æä¹ûÕæÄÚÈÝʹµÃÇå¾²³§ÉÌÃÇÔÚºóÐøÒ»ÏµÁÐËÝÔ´¶¼ÓÐÁËÆ«Ïò¡£¡£¡£¡£¡£¡£

    ¹¥»÷ÌØµãÊֶΡ¢¹¤¾ß

    ºã¾ÃÒÔÀ´£¬£¬ £¬£¬£¬ £¬£¬OilRigͨ¹ý´ó×ÚÍøÂç²¢ÕûºÏÖÖÖֵǼƾ֤¡¢ÄäÃû×ÊÔ´¡¢Òþ²ØÍ¨µÀµÈÍøÂç¹¥»÷×ÊÔ´£¬£¬ £¬£¬£¬ £¬£¬¶ÔÄ³Ð©ÌØ¶¨Ä¿µÄÌᳫÊýÆð¶¨Ïò¹¥»÷¡£¡£¡£¡£¡£¡£OilrigÍÅ»ïÎäÆ÷¿â°üÀ¨´ó×Ú¶¨Öƹ¤¾ß£¬£¬ £¬£¬£¬ £¬£¬Ëæ×ÅÇå¾²ÐÐÒµ¶ÔÆäµÄÒ»Ö±ÆØ¹â£¬£¬ £¬£¬£¬ £¬£¬OilrigʹÓõĹ¥»÷ÎäÆ÷ºÍÊÖ·¨Ò»Á¬Éý¼¶¡£¡£¡£¡£¡£¡£

    ´Ó¹¥»÷Èë¿ÚÀ´¿´£¬£¬ £¬£¬£¬ £¬£¬OilrigÖ÷Òª½ÓÄÉÓã²æ¹¥»÷¡¢É繤´¹ÂÚ¡¢Ë®¿Ó¹¥»÷µÈ·½·¨ÊµÑé×éºÏ¹¥»÷¡£¡£¡£¡£¡£¡£

    ±ðµÄ£¬£¬ £¬£¬£¬ £¬£¬Oilrig»¹ÉÆÓÚʹÓÃͨѶÒþÄäÊÖÒÕÀ´¹æ±Ü¼ì²âºÍ×·×Ù£¬£¬ £¬£¬£¬ £¬£¬ºÃ±È£ºÍ¨¹ýExchangeWebServices£¨EWS£©)APIʵÏָ߿ÉÐŶȡ¢¸ßÒþÄäÐԵēEWSËíµÀÊÖÒÕ”¡£¡£¡£¡£¡£¡£Í¨¹ý´ó×Ú°¸ÀýÆÊÎö£¬£¬ £¬£¬£¬ £¬£¬×ܽá³öOilrigÒÔÏÂÌØµã£º

    ¸Ã×éÖ¯Ö÷ÒªÒÀÀµÉç»á¹¤³ÌѧʵÑé¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬Ê¹Óô¹ÂÚÍøÕ¾ÇÔÈ¡Óû§Æ¾Ö¤£¬£¬ £¬£¬£¬ £¬£¬ÀýÈçOWA£»£»£»£»£»£» £»£»

    µ±¸Ã×éÖ¯»ñȡϵͳ»á¼ûȨÏ޺󣬣¬ £¬£¬£¬ £¬£¬Ê¹ÓÃÃÜÂëץȡÆ÷Mimikatz¹¤¾ßdumpÕË»§Æ¾Ö¤ÐÅÏ¢£¬£¬ £¬£¬£¬ £¬£¬ÇÔÈ¡µÇ¼µÄÕË»§Æ¾Ö¤£»£»£»£»£»£» £»£»

    Ê¹ÓÃÇÔÈ¡µÄÕË»§Æ¾Ö¤¾ÙÐкáÏòÒÆ¶¯£»£»£»£»£»£» £»£»

    ÒÑÍù¹¥»÷ÖдÓδʹÓÃ0dayÎó²î£¬£¬ £¬£¬£¬ £¬£¬µ«»áÔÚ¹¥»÷ÖÐʹÓÃÒÑÐÞ²¹µÄÎó²îµÄÏà¹ØÊ¹ÓôúÂ룻£»£»£»£»£» £»£»

    µ±»ñȡϵͳƾ֤ºó£¬£¬ £¬£¬£¬ £¬£¬Æ«ºÃÓÚʹÓù¤¾ß¶ø²»ÊǺóÃųÌÐòÀ´»á¼ûϵͳ£¬£¬ £¬£¬£¬ £¬£¬ÈçÔ¶³Ì×ÀÃæ»òputty¡£¡£¡£¡£¡£¡£

    £¨Ò»£©¹¥»÷ÊÖ¶Î

    1.Óã²æ¹¥»÷

    Óã²æ¹¥»÷ÊÇOilRig×ʹÓò¢ÇÒ×îÉÆÓÚµÄÒªÁ죬£¬ £¬£¬£¬ £¬£¬Í¨³£ÒÔÏÂÃæÈýÖÖ·½·¨×÷Ϊ³õʼ¹¥»÷£ºÍ¨¹ýµç×ÓÓʼþÖмдøº¬ÓжñÒâºêµÄOfficeÎļþ£¨DOX»òEXCELµÈ£©£»£»£»£»£»£» £»£»µç×ÓÓʼþÖÐÖ±½Ó·¢ËͶñÒâÁ´½Ó£»£»£»£»£»£» £»£»LinkedInÒÔÕÐÆ¸µÄ·½·¨·¢ËÍÁ´½ÓÈö²¥¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬ £¬£¬ÎªÁËÌá¸ß¹¥»÷ЧÂÊ£¬£¬ £¬£¬£¬ £¬£¬OilRig»áÔÚ·¢ËÍÓã²æÎļþǰ¶Ô¶ñÒâ´úÂëÌÓ±ÜÇå¾²¼ì²âµÄÄÜÁ¦Ìáǰ²âÊÔ¡£¡£¡£¡£¡£¡£

    2.Ë®¿Ó¹¥»÷

    OilRigÖ÷Ҫͨ¹ý´¹Âڵķ½·¨ÊµÑéË®¿Ó¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬²¢ÇÒÆäÖÐÓÃÓÚÖÆÔìË®¿ÓµÄÍøÕ¾¶¼ÊÇαÔìµÄ¡£¡£¡£¡£¡£¡£2017Ä꣬£¬ £¬£¬£¬ £¬£¬OilRigαÔìÁËJuniperNetworksVPNµÄÍøÕ¾£¬£¬ £¬£¬£¬ £¬£¬²¢Ê¹ÓÃJuniperµÄµç×ÓÓʼþÕÊ»§·¢ËÍÓʼþÓÕÆ­Ä¿µÄ¡£¡£¡£¡£¡£¡£¶ñÒâµç×ÓÓʼþÖеÄÁ´½ÓÖ¸Ïò¸ÃÐéÎ±ÍøÕ¾£¬£¬ £¬£¬£¬ £¬£¬²¢ÒªÇóÓû§ÊäÈëÓû§ÃûºÍÃÜÂ룬£¬ £¬£¬£¬ £¬£¬ËæºóÒªÇóÊܺ¦Õß×°ÖÓVPN¿Í»§¶Ë”£¬£¬ £¬£¬£¬ £¬£¬¶øÈí¼þÖÐÀ¦°óÁËOilRigµÄ¶ñÒâÈí¼þHelminth¡£¡£¡£¡£¡£¡£

    3.Êý¾ÝÐÅÏ¢ÆÆËð²Á³ý

    Óë¸Ã¹úÖ§³ÖµÄÆäËûºÚ¿ÍÒ»Ñù£¬£¬ £¬£¬£¬ £¬£¬OilRigͬÑùϲ»¶°²ÅÅ“´Ý»ÙÐÔ”¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£IBMÔøÅû¶OilRigʹÓÃÊý¾ÝÆÆËðÈí¼þZeroCleareÃé×¼Öж«ÄÜÔ´ºÍ¹¤Òµ²¿·Ö·¢¶¯¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬ÆðÔ´¹ÀËãÒÑÓÐ1400̨װ±¸ÔâѬȾ¡£¡£¡£¡£¡£¡£ZeroCleareºÍÁîÉ³ÌØÊ¯Ó;ÞÍ·Ðľªµ¨Õ½µÄÆÆËðÐÔ¶ñÒâÈí¼þShamoonÊôÓÚͬ×Ú£¬£¬ £¬£¬£¬ £¬£¬¾ùÓɳö×Ըùú¶¥¼¶ºÚ¿Í×éÖ¯Ò»ÊÖ¿ª·¢¡£¡£¡£¡£¡£¡£

    £¨¶þ£©Ê¹Óù¤¾ß¼°ÊÖÒÕÌØÕ÷

    OilRigʹÓõÄÍøÂçÎäÆ÷Ö÷Òª°üÀ¨£º¼üÅ̼ͼ¹¤¾ß£¨KEYPUNCH£©¡¢×ÀÃæÆÁÄ»½ØÍ¼²¶»ñ£¨CANDYKING£©¡¢ºóÃÅ£¨POWRUNER£©ºÍÓòÌìÉúËã·¨¹¦Ð§£¨BONDUPDATER£©µÈ¡£¡£¡£¡£¡£¡£

    ÔÚÆä¹¤¾ß¿âй¶ºó£¬£¬ £¬£¬£¬ £¬£¬¸Ã×é֯ΪÁË×èÖ¹¼ì²â£¬£¬ £¬£¬£¬ £¬£¬Ò»Ö±ÔÚÆð¾¢Ë¢Ðº͸üÐÂÆäÓÐÓÃÔØºÉ¿â£¬£¬ £¬£¬£¬ £¬£¬²¢½¨ÉèÁ˼¸ÖÖ²î±ðµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬ £¬£¬OilRigÒ²ÔÚÒ»Ö±¸üÐÂÎäÆ÷¿â£¬£¬ £¬£¬£¬ £¬£¬°üÀ¨DGAÌìÉúC2ÓòÃû£¬£¬ £¬£¬£¬ £¬£¬Ê¹ÓÃDNSExfiltratorµÈ¹¤¾ßÒþ²ØÆäÊý¾ÝÁ÷Á¿µÈ£¬£¬ £¬£¬£¬ £¬£¬Åú×¢¸Ã×éÖ¯Ò²ÔÚÒ»Ö±×·Çó·´Õì²âµÄÕ½ÂÔ¡£¡£¡£¡£¡£¡£

    ÒÔÏÂΪOilRigʹÓù¤¾ßµÄÌØµã£º

    Ê¹Óö¨ÖƺͿªÔ´Èí¼þ¹¤¾ß¾ÙÐÐDNSÉøÂ©£»£»£»£»£»£» £»£»

    Ê¹ÓÃ×Ô½ç˵µÄDNSTunnelingЭÒé¾ÙÐÐÏÂÁî¿ØÖÆºÍÊý¾Ý»Ø´«£»£»£»£»£»£» £»£»

    ¸Ã×é֯ʹÓÃ×Ô¶¨ÖƵÄwebshellºóÃųÌÐòά³Ö¶ÔЧÀÍÆ÷µÄ³¤ÆÚ»á¼û£»£»£»£»£»£» £»£»

    »ùÓÚµç×ÓÓʼþµÄC2ʹÓÃExchangeWebЧÀͺÍÒþдÊõ£¬£¬ £¬£¬£¬ £¬£¬ÀýÈ罫Êý¾ÝºÍÏÂÁî²åÈëµ½µç×ÓÓʼþµÄͼÏñÎļþÖС£¡£¡£¡£¡£¡£

    ×ÅÃû¹¥»÷ÊÂÎñ

    £¨Ò»£©OilRigÊ״α»½Ò¿ªÃæÉ´

    2016Äê5Ô£¬£¬ £¬£¬£¬ £¬£¬OilRig¹¥»÷É³ÌØ°¢À­²®¹ú·À¹¤Òµ²¿·Ö±»Çå¾²³§ÉÌPaloAltoNetwork¡¾2¡¿·¢Ã÷£¬£¬ £¬£¬£¬ £¬£¬²¢½«´ËÊÂÓëÁ½ÄêǰµÄÏàËÆ¹¥»÷ÊÂÎñ¹ØÁª£¬£¬ £¬£¬£¬ £¬£¬½Ò¿ªOilRigµÄ“ÉñÃØÃæÉ´”¡£¡£¡£¡£¡£¡£

    ´Ë´ÎÊÂÎñOilRigʹÓÃÁ½ÖÖ¹¥»÷·½·¨£ºµÚÒ»ÖÖÊÇExcel¼Ð´ø¶ñÒâºêÈö²¥VBºÍPowerShell¾ç±¾£¬£¬ £¬£¬£¬ £¬£¬ÏÂÔØHelminthľÂíÈëÇÖµçÄÔ£¬£¬ £¬£¬£¬ £¬£¬Í¨¹ýDNSÇëÇóÇÔÈ¡Êý¾Ý£»£»£»£»£»£» £»£»µÚ¶þÖÖÊÇͨ¹ýÓʼþZIP¸½¼þÀ´Èö²¥Windows¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£

    £¨¶þ£©Õë¶ÔÖж«Õþ¸®Ê¹ÓÃOfficeÎó²îÈö²¥ºóÃÅ

    2017Äê11Ô£¬£¬ £¬£¬£¬ £¬£¬OilRigÕë¶ÔÖж«Õþ¸®¾ÙÐÐÓã²æ¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬²¢Ê¹ÓÃOfficeÎó²îÈö²¥.rtf¶ñÒâÎļþ¡¾3¡¿¡£¡£¡£¡£¡£¡£¶ñÒâÎļþʹÓÃCVE-2017-11882Îó²îÆÆËð¿ÍÕ»Äڴ棬£¬ £¬£¬£¬ £¬£¬È»ºó½«¶ñÒâÊý¾Ýѹջ£¬£¬ £¬£¬£¬ £¬£¬¾­ÓÉһϵÁа취ִÐУ¬£¬ £¬£¬£¬ £¬£¬½¨ÉèÓëÏÂÁîºÍ¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷µÄÅþÁ¬¡£¡£¡£¡£¡£¡£

    ´Ë´Î¹¥»÷ÖУ¬£¬ £¬£¬£¬ £¬£¬OilRigʹÓÃÁË»ùÓÚPoweShellµÄºóÃÅPOWRUNER£¬£¬ £¬£¬£¬ £¬£¬ÒÔ¼°Ò»¸ö¾ßÓÐÓòÃûÌìÉúËã·¨¹¦Ð§µÄÏÂÔØÆ÷BONDUPDATER¡£¡£¡£¡£¡£¡£

    £¨Èý£©Ê¹ÓÃÉ繤ÊÖÒÕαװʵÑé¹¥»÷

    2019Äê6Ô£¬£¬ £¬£¬£¬ £¬£¬Oilrigαװ³É½£ÇÅ´óѧ³ÉÔ±µÄÉí·ÝÒÔ»ñµÃÊܺ¦ÕßÐÅÍУ¬£¬ £¬£¬£¬ £¬£¬²¢Ê¹ÓÃLinkedin˽ÐÅת´ï¶ñÒâÈí¼þ¡¾4¡¿£¬£¬ £¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔÄÜÔ´¡¢¹«ÓÃÊÂÒµ¡¢Õþ¸®ÓÍÆøµÈ¶àÐÐÒµÖ°Ô±¡£¡£¡£¡£¡£¡£

    OilrigʹÓÃÁËÆäÌØ¶¨±äÖÖÈí¼þPICKPOCKET±»Fireeyeʶ±ð²¢×èµ²£¬£¬ £¬£¬£¬ £¬£¬ºóÅû¶Õâ´Î¹¥»÷ÖÐʹÓÃÁËÈý¿î×îжñÒâÈí¼þ£ºTonedeaf£¨ºóÃÅ£©¡¢ValueVault£¨ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡£¡£¡£¡£¡£¡£©ºÍLongwatch£¨¼üÅ̼ͼÆ÷£©¡£¡£¡£¡£¡£¡£

    £¨ËÄ£©Ê¹ÓÃÊý¾Ý²Á³ýÆÆËðÖж«ÄÜÔ´»ú¹¹Êý¾Ý

    2019Äê12Ô£¬£¬ £¬£¬£¬ £¬£¬IBMÅû¶WiperÀà¶ñÒâÈí¼þ“Zeroclear”£¬£¬ £¬£¬£¬ £¬£¬¿ÉÒÔɾ³ýѬȾװ±¸Êý¾Ý£¬£¬ £¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔÖж«ÄÜÔ´ºÍ¹¤Òµ²¿·Ö¾ÙÐÐÆÆËðÐÔ¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬ÆðÔ´¹ÀËãÓÐ1400̨װ±¸Êܵ½Ñ¬È¾¡¾5¡¿¡£¡£¡£¡£¡£¡£

    ±¨¸æÒÔΪ£¬£¬ £¬£¬£¬ £¬£¬ZeroCleare¼«ÆäΣÏÕ£¬£¬ £¬£¬£¬ £¬£¬Ê¹ÓÃÓò¿ØÖÆÆ÷(DomainControllers)¿ÉÒÔÔÚ×éÖ¯ÖÐѸËÙÈö²¥¡£¡£¡£¡£¡£¡£±¨¸æÌåÏÖ´ÓÊܺ¦Ä¿µÄ¡¢IP¹ØÁªÒÔ¼°Ê¹ÓÃÈí¼þµÄÏà¹ØÁªÏµ¿ÉÒÔÍÆ²â´Ë´Î¹¥»÷¿ÉÄÜÔ´×ÔOilRig¡£¡£¡£¡£¡£¡£

    £¨Î壩2021Äê¶ÔÖж«µÄ×îй¥»÷Ô˶¯

    2021Äê1ÔÂÖÁ4ÔÂʱ´ú£¬£¬ £¬£¬£¬ £¬£¬OilRigÕë¶ÔÖж«µØÇøÔÙ´ÎʵÑé¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬½ÓÄÉWordÓÕ¶üÎĵµ×÷Ϊ³õʼ¹¥»÷¡¾6¡¿¡£¡£¡£¡£¡£¡£ÎĵµÎ±×°³É“Àè°ÍÄÛˮʦս½¢Í£µ±Çåµ¥”¡¢“Ntiva¹«Ë¾µÄÕÐÆ¸ÐÅÏ¢”£¨ÃÀ¹úITЧÀÍÉÌ£©µÈÓÕ¶üÎļþ×÷Ϊ¹¥»÷Èë¿Ú£¬£¬ £¬£¬£¬ £¬£¬ÍŽáÇÔÈ¡µÄExchangeÕ˺ÅÍê³É×éºÏÈëÇÖ¡£¡£¡£¡£¡£¡£OilRigÔÚÎĵµÕýÎÄÖÐÌí¼ÓÓÕµ¼ÐÔÐÎòÒÔÓÕʹĿµÄÆôÓöñÒâºê´úÂ룬£¬ £¬£¬£¬ £¬£¬´Ó¶øÖ²ÈëºóÃųÌÐò¡£¡£¡£¡£¡£¡£

    ÖµµÃÒ»ÌáµÄÊÇ£¬£¬ £¬£¬£¬ £¬£¬´Ë´Î¹¥»÷ÄÚÖÃÁËÀè°ÍÄÛÕþ¸®µÈÓëÓÕ¶üÎļþÏà·ûµÄExchangeÓÊÏäÕË»§Éϰ¶Æ¾Ö¤£¬£¬ £¬£¬£¬ £¬£¬ÍƲ⹥»÷ÕßÔÚÏÈÆÚ×¼±¸½×¶ÎÒÑÀÖ³ÉÈëÇÖÁËÓйØ×éÖ¯»òÓëÆä¾ßÓÐÐÅÍйØÏµµÄÓʼþÕË»§£¬£¬ £¬£¬£¬ £¬£¬²¢½è¸ß¿ÉÐÅExchangeЧÀÍÆ÷ΪÐÅÍнڵãÖÐתͨѶ£¬£¬ £¬£¬£¬ £¬£¬Òþ²Ø¶ñÒâÐÐΪ¡£¡£¡£¡£¡£¡£

    ×ܽá

    ×ÜÌå¶øÑÔ£¬£¬ £¬£¬£¬ £¬£¬OilRig´ú±íÁ˸ÃÖж«¹ú¼ÒÍø¾üµÄ×î¸ßÍøÂç¹¥»÷ˮƽ£¬£¬ £¬£¬£¬ £¬£¬ÊÇÒÔʵÆäÕþÖÎÄ¿µÄΪÖ÷ҪĿµÄµÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£

    Æä¹¥»÷¹æÄ£Ö÷ÒªÕë¶ÔÖж«¹ú¼Ò£¨ÒÔÉ«ÁÐΪÖ÷£©¼°µÐ¹úÃÀ¹ú£¬£¬ £¬£¬£¬ £¬£¬½ü¼¸ÄêÀ´ÎÒ¹úÒ²³ÉΪÁËÆä¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£

    OilRigµÄ³õʼ¹¥»÷ËäÈ»¼òÆÓÖ±½Ó£¬£¬ £¬£¬£¬ £¬£¬¿ÉÊÇÍŽáÆäÍøÂçµÄµÇ¼ƾ֤µÈÊý¾ÝʹµÃÊܺ¦ÕßÎÞ·¨Õç±ð¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬ £¬£¬OilRigÉÆÓÚʹÓÃÁ÷Á¿Òþ²ØÊÖÒÕʹµ½ÊÖÒÕÖ°Ô±Ô½·¢ÄÑÒÔ·¢Ã÷¼°×·×Ù¡£¡£¡£¡£¡£¡£

    ×¢½â

    https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf

    https://unit42.paloaltonetworks.com/unit42-oilrig-actors-provide-glimpse-development-testing-efforts/

    https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html

    https://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-their-professional-network.html

    https://www.ibm.com/downloads/cas/OAJ4VZNJ

    https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/

    ¹ØÓÚ×÷Õß

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬ £¬£¬£¬ £¬£¬@RedDrip7£©£¬£¬ £¬£¬£¬ £¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬ £¬£¬£¬ £¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬ £¬£¬£¬ £¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬ £¬£¬£¬ £¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺÓ¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬ £¬£¬£¬ £¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý46¸ö£¬£¬ £¬£¬£¬ £¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯13¸ö£¬£¬ £¬£¬£¬ £¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬ £¬£¬£¬ £¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿