WannaCry勒索软件分析

2017-5-14 Nie.Meining Debug

大家都知道,昨天WannaCry勒索软件在一夜之间利用系统漏洞席卷全球,特别是在内网和专网中,通过攻击445端口(蠕虫性质)大肆传播,造成了巨大数据损失。我也凑个热闹,找到一批样本上传金刚分析系统(http://tcasoft.com/),看看效果。

其中比较典型的分为两类,一类就是昨天大家新闻中看到的,访问某个超长的域名,如果存在就放弃攻击。如图:

2.png

1.png

其实这个“域名开关”并不完全可以保平安。还有一类样本一上来就搞破坏,并不会探测域名。如某样本的分析报告:

http://tcasoft.com/tcaCloudPlatform/report/toViewReport.action?rid=22bfa9109ab9d405af4188867620c730&sk=60036875

下面对该报告简单解读。

首先观察运行过程截图可以看出,样本执行初期没有任何引人注意的表现,当桌面被替换、前台弹出提示信息时,一切都为时已晚,用户的文件就已经被加密,要想恢复文件内容只能向攻击者提供的地址汇入300美元比特币了。如下图所示。

3.png

4.jpg


观察行为列表可以看到,样本释放了大量可执行程序以及bat、vbs等恶意脚本,并借助这些程序、脚本和Windows自带的系统工具共同完成攻击目的。例如通过attrib系统工具实现自我隐藏、利用icacls工具获取文件操作权限、利用vssadmin工具破坏系统还原功能、利用reg程序导入注册表实现自启动等。如下图所示。

5.png

6.png

7.png


一切就绪后,样本开始重头戏——文件加密。在行为列表中可以看到大量与文件操作相关的行为,包括修改文件属性、读写文件、修改文件创建时间、文件重命名等。这些正是WannaCry对用户文件进行加密的详细过程。如下图所示。

8.png


进一步观察样本的详细行为数据可以发现,攻击者其实会针对每个文件生成一个扩展名为WNCRYT的临时文件,在加密完成并设置好文件创建时间后,会将该临时文件重命名为WNCRY文件。如下图所示。

9.png


具体这些被加密后的文件长什么样呢?只需查看分析报告里的“中间文件”就可以看到。如下图所示,攻击者感兴趣的文件主要包括doc、xls、jpg等各种文档和图片,被加密后文件头部均变成了“WANACRY!”标识。

a.png


除了以上主机破坏行为以外,样本运行过程中还能观测到大量的网络行为,连接地址包括美国、德国、奥地利等多个国家,同时会尝试连接一个很长的域名。如图所示。

b.png

c.png


由于金刚系统在分析过程中,引擎并未连接真实互联网,因此网络行为我就没有展开分析了。其实该样本还有不少技术细节上文并未展开介绍,大家若有兴趣欢迎查看分析报告自行研究。

评论:

Henrynib
2020-10-02 17:15
Wow! Questo è un modo più veloce per un'indipendenza finanziaria.
Link - - https://moneylinks.page.link/6SuK
Henrynib
2020-10-02 12:57
Robot finanziario garantisce a tutti stabilità e reddito.
Link - - http://www.google.com/url?q=%68%74%74%70%73%3A%2F%2F%68%64%72%65%64%74%75%62%65%33%2e%6d%6f%62%69%2F%62%74%73%6d%61%72%74%23%79%4a%5a%7a%5a%65%69%69%41%68%7a%76%7a%54%61%75%55&sa=D&sntz=1&usg=AFQjCNF2P4SPcX-xCsK7YYkJX3OmdlSaKw
Henrynib
2020-10-02 05:14
Automatic robot is the best start for financial independence.
Link - http://www.google.com/url?q=%68%74%74%70%73%3A%2F%2F%68%64%72%65%64%74%75%62%65%33%2e%6d%6f%62%69%2F%62%74%73%6d%61%72%74%23%48%49%61%69%59%54%46%59%6f%48%54%66%55%41%6e%68%6c&sa=D&sntz=1&usg=AFQjCNGdPVWXx53cSml1erGTu_y3ozA6uQ
Henrynib
2020-09-30 21:17
Controlla il Bot automatico, che funziona per voi 24/7.
Link - http://www.google.com/url?q=%68%74%74%70%73%3A%2F%2F%68%64%72%65%64%74%75%62%65%33%2e%6d%6f%62%69%2F%62%74%73%6d%61%72%74%23%63%79%62%49%53%54%6a%7a%52%47%53%69%77%41%51%47%6b&sa=D&sntz=1&usg=AFQjCNFrDoCXau5Tfkw4B2JtZTVEt-ecGQ
Henrynib
2020-09-24 11:54
Reddito supplementare è ora disponibile per chiunque in tutto il mondo.
Link - http://www.google.com/url?q=%68%74%74%70%73%3A%2F%2F%68%64%72%65%64%74%75%62%65%33%2e%6d%6f%62%69%2F%62%74%73%6d%61%72%74%23%54%63%64%75%64%45%50%49%72%41%70%6a%77%71%45%6c%42&sa=D&sntz=1&usg=AFQjCNEdVp4k_ZzGbgc81tO5TWrO-uIwPQ
Henrynib
2020-09-23 14:43
Questo robot può portare soldi 24/7.
Link - https://cloud.mail.ru/public/cvJx/3pa3NwGXk
TerryCem
2020-09-22 07:04
Very interesting to read you
Good luck to you
Henrynib
2020-09-16 19:21
Lascia che il Robot ti porti soldi mentre ti riposi.
Link - - https://moneylinks.page.link/6SuK
Williamdix
2020-09-14 03:59
The transformation she invoked this year has been something they only write about in books of fairytale and magic.Diga a ele que eu sou a pessoa que você ama Explique o que aconteceu Entre você e eu a chama acendeu Eu não sei como entrar.Pre-Ritornello 1 Charlie Puth Non voglio sapere Quale abito indossi stasera Se lui si sta stringendo così forte a te Come facevo io prima Sono esagerato Avrei dovuto sapere che il tuo amore fosse un gioco Ora non riesco a cancellarti dai miei pensieri Oh, è proprio un peccato.There is hint of Tasumi s crush on Jacobo in The Truth Hurts when she passes on a note in the classroom that asks Jacobo if she liked him and was crushed when he signed maybe.Jedná se o omezovaДЌ rychlosti s kladkou o prЕЇmД ru 120mm pro lanko 4mm vestavД ný pЕ ímo do ovládacího mechanizmu zachycovaДЌe ASG.

http://exuninivtweedanopdelcomppuncstanin.xyz/35/5th-ward-weebie-weebie-show-the-world-cassette.php
cheap essay writers
2020-09-01 23:32
cheap custom essay http://buyessayhelpvwe.com/ cheap custom essay
buy an essay
2020-09-01 18:04
buy essays online http://essaywritingservicefav.com/ buy an essay
help writing thesis
2020-09-01 15:50
help me write a thesis http://thesisbyl.com/ thesis writing service
ikiykinini
2020-09-01 15:06
fake essay writer http://customessaywritershb.com/ write my essay custom writing
online paper writer
2020-09-01 12:30
need help writing a paper http://writemypaperbuyxvv.com/ custom written papers
thesis editors
2020-09-01 08:05
thesis advice http://thesisbyl.com/ thesis for phd

发表评论:

Powered by emlog