ãããã¯ãŒã¯å ã®RDPãã«ãŒããã©ãŒã¹ã«é¢ããçµ±èšãåéããããã«ã5ã€ã®ãããŒãããïŒä»¥äžãåã«ããµãŒããŒãïŒãé 眮ããŸããã
1ã€ã®ãµãŒããŒã¯ãã³ãã³ã«ããããã1ã€ã¯ãã¥ãŒãªããã«ããã1ã€ã¯M9ã®å®å šãªãããã¯ãŒã¯ã«ãããä»ã®2ã€ã¯å®å šãªãããã¯ãŒã¯ãšå®å šã§ãªããããã¯ãŒã¯ã®RucloudããŒã¿ã»ã³ã¿ãŒã«ãããŸãããåãµãŒããŒã®IPã¢ãã¬ã¹ã¯ç°ãªããµããããã«ãããåIPã¢ãã¬ã¹ã¯æåã®ãªã¯ãããã«ãã£ãŠåºå¥ãããŸãã次ã®åŒã䜿çšããŠIPã¢ãã¬ã¹éã®ã¹ãã£ã³ãè·é¢ãã枬å®ããããšãããšïŒ
ïŒïŒãµããããïŒ1ã®æåã®ãªã¯ãããïŒ-ïŒãµããããïŒ2ã®æåã®ãªã¯ãããïŒïŒ*ïŒ2 ^ 24ïŒã
0.0.0.0/0ãã¹ãã£ã³ããå Žåãæ»æè ã¯å°ãªããšã771751936ã®IPã¢ãã¬ã¹ã調ã¹ãŠãäºãã«æãè¿ã2ã€ã®ãµãŒããŒãèŠã€ããå¿ èŠããããŸããããã«ãã©ã®ãµãŒããŒãICMPã«å¿çãããåIPã¢ãã¬ã¹ã¯3ãæé誰ã«ã䜿çšãããã5ã€ã®ãµãŒããŒãã¹ãŠãåæã«ããŒããéããŸããããã¹ãŠã®ãµãŒããŒãADã«æ¥ç¶ãããŸããã
ãã«ãã«ã©ãŒã°ã©ãã£ãã¯
èå³æ·±ããã®ããå§ããŠãéèŠãªãã®ã§çµãããŸãã
ã¹ã¿ãŒãã¯è¯ãã£ããæåã®ãã«ãŒããã©ãŒãµãŒã¯ãããŒããéãããæåã®1æéã«Rucloudã®ãµãŒããŒã«ã¢ã¯ã»ã¹ããŸãããä»ã®ãã¹ãŠã®ããŒã¿ã»ã³ã¿ãŒã§ã¯ããµãŒããŒã¯2æé以å ã«ã®ã¿æ€åºãããŸããã
ãã£ãŒããããããããã«ããã«ãŒããã©ãŒã¹ã¯æ¥ã ããŸãå€åããŠããŸããããããŠãããªããäžæ¥ã®æéãèŠããªãã°ïŒãããã°ã©ãã§ããç°ãªãè²ã¯ç°ãªãæ¥ã§ãã
æå»ã¹ã±ãžã¥ãŒã«dcZUR1ã
ä¿è·ããããµããããM9ã®æå»ã°ã©ãã
DCLD8ã®æå»ã°ã©ãã
ä¿è·ãããRucloudãµããããã®æå»ã°ã©ãã
Rucloudã®æå»ã°ã©ãã
éå±ãªçµµã§ãããæé垯ã«ãã£ãŠçµµã¯å€ãããªããšèšããŸãã
æå»ããšã«åããã£ãŒããèŠãŠã¿ãŸãããããã ãããã¹ãŠã®ããŒã¿ã»ã³ã¿ãŒã®åèšã§ãã
ç©ã¿äžãæå»ã°ã©ãã
æå»ã°ã©ãã
ãã«ãŒããã©ãŒã¹ã®ãã¿ãŒã³ã¯ãæé垯ã«ãã£ãŠå€åããŸãããã€ãŸãããã«ãŒããã©ãŒã¹æ»æã«åå ããããã€ã¹ã¯åžžã«ãªã³ã«ãªã£ãŠããå¯èœæ§ããããŸãã
1ã€ã®ä¿è·ãããŠããªãRucloudãµããããäžã®åã¢ãã¬ã¹ã®å€±æãããã°ã€ã³è©Šè¡ã®çµ±èšã
åèš89ã®IPã¢ãã¬ã¹ããä¿è·ãããŠããªãRucloudãµããããã®1ã€ã§äžž1é±éã®æ€çŽ¢ã«åå ããŸããã 10åã®IPã¢ãã¬ã¹ã114809åã®è©Šè¡ã®50ïŒ ãå ããŸããã
ãã¹ãŠã®ããŒã¿ã»ã³ã¿ãŒã®åã¢ãã¬ã¹ã®å€±æãããã°ã€ã³è©Šè¡ã®çµ±èšã
åãããšã§ããããã¹ãŠã®ããŒã¿ã»ã³ã¿ãŒã®çµ±èšã®ã¿ãå«ãŸããŸãããã¹ãŠã®çµ±èšã®50ïŒ ã15ã®IPã¢ãã¬ã¹ãæºãããŸããã5ã€ã®ãµãŒããŒãã¹ãŠã§50äžå以äžã®è©Šè¡ããããŸãããæ»æè ã¯ã©ã®ããã«ç°ãªã£ãŠããŸãããïŒ
ãã¹ãŠã®ãããã¯ãŒã¯ã§143åã®IPã¢ãã¬ã¹ã衚瀺ããã5å°ã®ãµãŒããŒãã¹ãŠã§29åã®IPã¢ãã¬ã¹ã®ã¿ã衚瀺ãããŸããããã¹ãŠã®æ»æè ã®ååæªæºã2ã€ä»¥äžã®ãµãŒããŒãæ»æããŠããŸãããããã¯ãIPã¢ãã¬ã¹éã®ã¹ãã£ã³è·é¢ãéèŠã§ããããšãæå³ããŸããããã¯ãæ»æè ãnmapã䜿çšããŠãéããŠããããŒãã«é¢ããæ å ±ãååŸããIPã¢ãã¬ã¹ã1ã€ãã€ã¹ãã£ã³ããããšãæå³ããŸãã
ãããããããæ°ãã
æ€çŽ¢ã«äœ¿çšãããã¬ããŒããšãŠãŒã¶ãŒåãèŠããšãç°ãªãIPã¢ãã¬ã¹ã䜿çšããŠããèŸæžãèŸæžãžã®ãã°ã€ã³æ°ã«é©ããããŸããã
ãããããã¹ãŠç°ãªãèŸæžãæã€ç°ãªãããããããã§ãããšä»®å®ããŠãNåã®ãããããããæ°ããŸãããããããã®èŸæžã¯æ¬¡ã®ãšããã§ã
ãadminãadministratorãadministradorãadministrateurãadminãadministratorãadministradorãadministrateurãADMINãUSERãUSER1ãTESTãTEST1ãADMINISTRATORãUSER1ãUSER2ãUSER3ãUSER4ãUSER5ãUSER6ãUSER7ãUSER8ã USER9ãHPãADMINãUSERãPCãDENTAL
ãã®ããããããã¯æ倧ã§ãæ倧ã®èŸæžã䜿çšããŠããŸããããå«ããããŸããŸãªèšèªã§ã®å€ãã®ãã°ã€ã³ããããŸããããã·ã¢èªããã©ã³ã¹èªãè±èªïŒ
1ã12ã123ã1234ã12345ã13ã14ã15ã19ã1CãCAMERAãCAMERAãADMINãUSERL8ãGVCãADMINISTRATEURãIPAD3ãUSR_TERMINALãJEREMYãADMINISTRATORãADMãALYSSAãADMINISTRATORãCAMERAãATAMER CAMERAãADMINãUSERL8ãGVCãADMINISTRATEURãUSR_TERMINALãJEREMYãIPAD3ãUSR_TERMINALãJEREMYãADMINISTRATORãADMINãADMãSERGEYãOLEGãIRINAãNATASHAãSYSTEMãSERVICEãGVCãUSTRATER ADMINãADMãSERGEYãOLEGãIRINAãNATASHAãªã©ãäžåœèªã®ãã°ã€ã³ãå«ãŸããŸãã
äžåœèªãšè±èªã®åèªã®ã¿ã䜿çšããèŸæžããããŸããã Powershellã䜿çšããŠããŒã¿ããŒã¹ããäžåœèªã®æåãæœåºã§ããŸããã§ãããããã«äžåœã®åå¿ã®èªåœã®ã»ãã®äžéšããããŸãïŒ
SHENZHENãTIANJINãMANDARINãCHONGQINGãSHENYANGãXIANãCONSãCHINAãTECHNOLOGYãISPADMINãBEIJINGãSHANGHAI
ãããã®ãã°ã€ã³ãå埩ããããšããŠããåäžã®IPã¢ãã¬ã¹ããããŸããããããããåäŸãã¡ã ããéãã§ããŸãïŒ
USR1CV8ãADMINISTRATOR
ADMIãNIMDAãADMSãADMINS
ãã¹ã¯ãŒãã«å¯Ÿããæããªãã«ãŒããã©ãŒã¹æ»æããã¹ã¯ãŒãã®èŸæžæ€çŽ¢ããããŸãããå€ããå°ãªããèå³æ·±ãæ€çŽ¢ããããŸããæ»æè ã¯ããŠãŒã¶ãŒåãSMBå ±æãå Žåã«ãã£ãŠã¯ãã¹ã¯ãŒãããã·ã¥ãã³ã³ãã¥ãŒã¿ãŒåãADãã¡ã€ã³åããŸãã¯ã¯ãŒã¯ã°ã«ãŒããååŸããããšãã§ããŸãã
ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã¯BloodHoundã«ã€ããŠç¥ã£ãŠãããããã«ãŒã¯ããã«ã€ããŠç¥ã£ãŠããŸãã ADãããã©ã«ãã®ç¶æ ã®ãŸãŸã«ããŠãããšããã¡ã€ã³åãã³ã³ãã¥ãŒã¿ãŒåãããã«ã¯ãŠãŒã¶ãŒãã¹ã¯ãŒãã®ããã·ã¥ãçãããšãã§ããŸãã Habréã¯ãã§ã«ADãšãã®ããŒã«ã®æ»æãã¯ãã«ã«ã€ããŠæžããŠããŸãããã®çŽ æŽãããè³æãèªãããšããå§ãããŸãã
ã¡ãªã¿ã«ããµãŒããŒåãšãã¡ã€ã³ã䜿ã£ãæåã®æ»æã¯ãããŒããéãããŠãã13æéåŸã«å§ãŸããŸããããæ»æè ã¯ããã«é ããåãã138åããäŸµå ¥ããããšããŸããã§ãããåãèŸæžã䜿ã£ã2åç®ã®ãã®ãããªæ»æã¯ã3æ¥åŸã«ç¹°ãè¿ãããŸããããé·ãã¯ç¶ããŸããã§ããã
ç°ãªãèŸæžãæã€åèš5ã€ã®ãããããããã©ã®ãã°ã€ã³ãæãé »ç¹ã«äœ¿çšãããã©ã®å²åã§äœ¿çšãããŠããããç解ããããã«ã䜿çšããããã°ã€ã³ã«é¢ãããã詳现ãªçµ±èšãåéããå¿ èŠããããŸãããã¹ãŠã®çµ±èšæ å ±ãæ£ç¢ºã«åéãããŠããªããããäžèŠãããšããããŒãããŠããå¯èœæ§ãé«ããå®éã®ç¶æ³ã¯ããå°ãèå³æ·±ããã®ã§ãã
ããã¯åé¡ã§ããïŒ
èªå·±åé¢ã®åããããéåžžã«å¥åŠãªãµãŒããŒã䜿çšã§ããªãããšãèšé²ãå§ããŸãããæåã¯ãããŒã ã€ã³ã¿ãŒããããããã€ããŒãNetflixãããã³ãã¬ã³ãã®ãããã¯ãŒã¯ãéè² è·ã«ãªããŸã§ãã¹ãŠããã§ãŒã¯ããŸããããã€ã³ãã©ã¹ãã©ã¯ãã£ã®æºåãã§ããŠããªãå ŽåããããŸããã
Windows Server 2008ã®å°æ°ã®ã¯ã©ã€ã¢ã³ããååãšããŠRDPã«ã¢ã¯ã»ã¹ã§ããªãã£ããšããã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢ããçæã¯ããã«æ¶ããŸãããã»ãã¥ãªãã£ãã°ã確èªãããšããã24æéã§36,000å以äžã®æ»æãèšé²ãããŸããã
çµå±ã®ãšãããååãªåŒ·ãã®ãã«ãŒããã©ãŒã¹ã¯ãRDPãå®å šã«æ®ºãããæ°žç¶çãªäžæãåŒãèµ·ããå¯èœæ§ããããŸãã
åé¡ã®èµ·æºã¯å®å šã«ã¯ç解ãããŠããŸããã RDPã¯ãããã¯å šäœããŸãã¯1人ã®æ»æè ã«ãã£ãŠé 眮ãããŸããã¹ã¯ãªãããšmstsc.exeã¯ãåæãšç»åã®ããªãŒãºãåçŸã§ããŸããã§ããã
ãã«ãŒããã©ãŒã¹ãDDoSã«å€ããããæ»æè ã®äžã«ã¯ç¹å¥ãªæ¹æ³ã§ãã«ãŒããã©ãŒã¹ãå®è£ ããŠãããã®ãããããããåé¡ãåŒãèµ·ãããŸããæãããªå¯äžã®ããšã¯ãåæã®æå»ã倱æãããã°ã€ã³è©Šè¡ãšäžèŽããããšã§ãã
æãæ®é ·ãªæ»æã¯ãç§ãã¡ã®ãµããŒããRDPã®ã©ã°ãšãã¬ãŒã¯ã®æ倧æ°ãèšé²ãã6æã®ãã®å€ã«çºçããŸãããæ®å¿µãªããããŸã çµ±èšãåéããŠããŸããã
åºå žïŒKaspersky
決å®ïŒ
ã¯ãã
身ãå®ãããã«å¿ èŠãªã®ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§èº«ãé ãããšã ãã§ããããããç§ã¯ããªããšåãæ æ°ãæããã®ã§ãç§ã¯ãããã®ã¢ãžã¥ãŒã«ãäœããŸããã
ã¢ãžã¥ãŒã«ã¯WindowsPowershell5.1ããã³PowershellCore7ã§åäœããŸãããããžã§ã¯ãgithubãžã®ãªã³ã¯ã¯ããã«ãããŸããããã§ã¯ãé¢æ°ãèŠãŠã¿ãŸãããã
ä¿è·-ãã«ãŒããã©ãŒã¹
ãããŸã§ã®ãšãããã¢ãžã¥ãŒã«ã¯ãããšåŒã°ããŠããŸããæ£åžžã«ãã°ã€ã³ãããã¹ãŠã®IPã¢ãã¬ã¹ãã«ãŒã«ã«è¿œå ããŠããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãå€æŽããŸããéçIPã¢ãã¬ã¹ãšçµã¿åãããŠäœ¿çšââãããšäŸ¿å©ã§ãVPNã²ãŒããŠã§ã€ãšçµã¿åãããŠãªã¢ãŒããã¹ã¯ããããµãŒããŒã®å±éãç°¡çŽ åããŸãã
ä¿è·è§£é€-ãã«ãŒããã©ãŒã¹
ããã©ã«ãã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®RemoteAddressããªã»ããããŸãã
ã¹ããã-ãã«ãŒããã©ãŒã¹
倱æãããã°ã€ã³ã®ã€ãã³ããã°ãã¹ãã£ã³ããå¥ã®ãStop-Bruteforceãã«ãŒã«ã䜿çšããŠãªã¹ãããIPã¢ãã¬ã¹ããããã¯ããŸãã
Get-Bruteforce
åIPã¢ãã¬ã¹ã®çµ±èšãªããžã§ã¯ãã®é åãè¿ããŸãããã®é¢æ°ã¯ãäžèšã®ãã£ãŒãã®çµ±èšãåéããããã«äœ¿çšãããŸããã
ã€ã³ã¿ãã¥ãŒ
ç§ãã¡RUVDSã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããŸã£ããå€æŽãããŠããªãç¶æ ã§ãŠãŒã¶ãŒã«æäŸããå¿ èŠããããšèããŠããŸããçæ³çãªäžçã§ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãæåã«ãªãªãŒã¹ããããšãã®ã¹ããã¯ç¶æ ã®ãŸãŸã§è¡šç€ºããå¿ èŠããããšèããŠããŸããããããçµå±ã®ãšãããå人ã¢ã«ãŠã³ããããã¹ã¯ãŒããçæãããªã©ã®æ©èœã¯ãç掻ãç°¡çŽ åããã ãã§ãªããå€ãã®ã¯ã©ã€ã¢ã³ãã«ãšã£ãŠåã«å¿ èŠãªãã®ã§ãããã®ãããªç掻ã®è³ªã«ã€ããŠã®ãæèŠããèãããã ãããæ祚ããŠã³ã¡ã³ãããŠãã ããã