Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºOilRig £¨APT-Q-53£©

ʱ¼ä£º2021-10-21 ×÷Õߣº»¢·ûÖÇ¿â

·ÖÏíµ½£º

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºOilRig £¨APT-Q-53£©

    ±¾ÎÄ3049×ÖÔĶÁÔ¼Ðè8ÖÓ

    ¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽá¡£¡£¡£¡£¡£

    »¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶÓ£¬£¬£¬£¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£±¾´ÎËø¶¨Ö÷Òª¹¥»÷Öж«µØÇøÕþ¸®¡¢ÄÜÔ´¡¢»¯¹¤¼°µçÐŵÈÐÐÒµµÄ¹ú¼Ò¼¶ºÚ¿ÍÍŻOilRig¡£¡£¡£¡£¡£

    04

    Oilrig

    OilRigÊÇÖж«Ä³¹úÕþ¸®Ö§³ÖµÄAPT×éÖ¯¡£¡£¡£¡£¡£Ö÷ÒªÕë¶ÔÖж«¹ú¼ÒʵÑé¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½ü¼¸ÄêÀ´ÎÒ¹úÒ²³ÉΪÁËÆä¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£

    ¸ÃAPT×éÖ¯×ÅÃû¶È½Ï¸ß£¬£¬£¬£¬£¬£¬£¬£¬´ú±íÁ˸ùúÍø¾üµÄ×î¸ßÍøÂç¹¥»÷ˮƽ¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÄÚ²¿¸ú×Ù±àºÅΪAPT-Q-53¡£¡£¡£¡£¡£

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºOilRig £¨APT-Q-53£©

    Åä¾°

    OilRigÓÖÃûHelixKitten¡¢APT34¡¢GreenBug¡¢ITG13µÈ³Æºô£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÖж«Ä³¹úÕþ¸®Ö§³ÖÏÂ×ÅÃû¶È×î¸ßµÄAPT×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£

    ×Ô2014Äê±»·¢Ã÷ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬OilRigÒ»Ö±·Ç³ £»£»£»£»£» £»£»£»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖж«¹ú¼ÒʵÑé¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÃÀ¹ú¡¢ÍÁ¶úÆä¡¢Ó¢¹úµÈÎ÷·½¹ú¼Ò£¬£¬£¬£¬£¬£¬£¬£¬Ò²°üÀ¨ÖйúºÍÓ¡¶È¡£¡£¡£¡£¡£

    OilRig¹¥»÷Ä¿µÄÏêϸ°üÀ¨°üÀ¨Õþ¸®¡¢Ã½Ìå¡¢¼°ÊÖÒÕЧÀÍÌṩÉ̵È×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬ÐÐÒµ°üÀ¨½ðÈÚ¡¢Õþ¸®¡¢ÄÜÔ´¡¢»¯¹¤ºÍµçÐŵÈÁìÓò¡£¡£¡£¡£¡£

    ´Ó¹¥»÷Ä¿µÄ¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬£¬£¬£¬OilRigÓë¸Ã¹ú¹ú¼ÒÀûÒæºÍ×÷սʱ¼ä¼á³Ö»ù±¾Ò»Ö£¬£¬£¬£¬£¬£¬£¬£¬Ô½·¢¹Ø×¢Éæ¼°Æä¹ú¼ÒÀûÒæµÄϸ½ÚÇ鱨¡£¡£¡£¡£¡£2019ÄêOilRigÔâÊÜÖØ´ó¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬´ó×ÚÓë¸Ã¼¯ÍÅÏà¹ØµÄÐÅϢͨ¹ýTelegram±»¹ûÕæ¡£¡£¡£¡£¡£Ð¹Â¶ÄÚÈݰüÀ¨Ê®ÓàÃû³ÉÔ±µÄÏêϸСÎÒ˽¼ÒÐÅÏ¢¼°Èô¸ÉÍøÂçÎäÆ÷¡£¡£¡£¡£¡£Æä¹ûÕæÄÚÈÝʹµÃÇå¾²³§ÉÌÃÇÔÚºóÐøÒ»ÏµÁÐËÝÔ´¶¼ÓÐÁËÆ«Ïò¡£¡£¡£¡£¡£

    ¹¥»÷ÌØµãÊֶΡ¢¹¤¾ß

    ºã¾ÃÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬OilRigͨ¹ý´ó×ÚÍøÂç²¢ÕûºÏÖÖÖֵǼƾ֤¡¢ÄäÃû×ÊÔ´¡¢Òþ²ØÍ¨µÀµÈÍøÂç¹¥»÷×ÊÔ´£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÄ³Ð©ÌØ¶¨Ä¿µÄÌᳫÊýÆð¶¨Ïò¹¥»÷¡£¡£¡£¡£¡£OilrigÍÅ»ïÎäÆ÷¿â°üÀ¨´ó×Ú¶¨Öƹ¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬Ëæ×ÅÇå¾²ÐÐÒµ¶ÔÆäµÄÒ»Ö±ÆØ¹â£¬£¬£¬£¬£¬£¬£¬£¬OilrigʹÓõĹ¥»÷ÎäÆ÷ºÍÊÖ·¨Ò»Á¬Éý¼¶¡£¡£¡£¡£¡£

    ´Ó¹¥»÷Èë¿ÚÀ´¿´£¬£¬£¬£¬£¬£¬£¬£¬OilrigÖ÷Òª½ÓÄÉÓã²æ¹¥»÷¡¢É繤´¹ÂÚ¡¢Ë®¿Ó¹¥»÷µÈ·½·¨ÊµÑé×éºÏ¹¥»÷¡£¡£¡£¡£¡£

    ±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Oilrig»¹ÉÆÓÚʹÓÃͨѶÒþÄäÊÖÒÕÀ´¹æ±Ü¼ì²âºÍ×·×Ù£¬£¬£¬£¬£¬£¬£¬£¬ºÃ±È£ºÍ¨¹ýExchangeWebServices£¨EWS£©)APIʵÏָ߿ÉÐŶȡ¢¸ßÒþÄäÐԵēEWSËíµÀÊÖÒÕ”¡£¡£¡£¡£¡£Í¨¹ý´ó×Ú°¸ÀýÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬×ܽá³öOilrigÒÔÏÂÌØµã£º

    ¸Ã×éÖ¯Ö÷ÒªÒÀÀµÉç»á¹¤³ÌѧʵÑé¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ê¹Óô¹ÂÚÍøÕ¾ÇÔÈ¡Óû§Æ¾Ö¤£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçOWA £»£»£»£»£» £»£»£»

    µ±¸Ã×éÖ¯»ñȡϵͳ»á¼ûȨÏ޺󣬣¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÃÜÂëץȡÆ÷Mimikatz¹¤¾ßdumpÕË»§Æ¾Ö¤ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡µÇ¼µÄÕË»§Æ¾Ö¤ £»£»£»£»£» £»£»£»

    Ê¹ÓÃÇÔÈ¡µÄÕË»§Æ¾Ö¤¾ÙÐкáÏòÒÆ¶¯ £»£»£»£»£» £»£»£»

    ÒÑÍù¹¥»÷ÖдÓδʹÓÃ0dayÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ«»áÔÚ¹¥»÷ÖÐʹÓÃÒÑÐÞ²¹µÄÎó²îµÄÏà¹ØÊ¹ÓôúÂë £»£»£»£»£» £»£»£»

    µ±»ñȡϵͳƾ֤ºó£¬£¬£¬£¬£¬£¬£¬£¬Æ«ºÃÓÚʹÓù¤¾ß¶ø²»ÊǺóÃųÌÐòÀ´»á¼ûϵͳ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÔ¶³Ì×ÀÃæ»òputty¡£¡£¡£¡£¡£

    £¨Ò»£©¹¥»÷ÊÖ¶Î

    1.Óã²æ¹¥»÷

    Óã²æ¹¥»÷ÊÇOilRig×ʹÓò¢ÇÒ×îÉÆÓÚµÄÒªÁ죬£¬£¬£¬£¬£¬£¬£¬Í¨³£ÒÔÏÂÃæÈýÖÖ·½·¨×÷Ϊ³õʼ¹¥»÷£ºÍ¨¹ýµç×ÓÓʼþÖмдøº¬ÓжñÒâºêµÄOfficeÎļþ£¨DOX»òEXCELµÈ£© £»£»£»£»£» £»£»£»µç×ÓÓʼþÖÐÖ±½Ó·¢ËͶñÒâÁ´½Ó £»£»£»£»£» £»£»£»LinkedInÒÔÕÐÆ¸µÄ·½·¨·¢ËÍÁ´½ÓÈö²¥¶ñÒâÎļþ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÎªÁËÌá¸ß¹¥»÷ЧÂÊ£¬£¬£¬£¬£¬£¬£¬£¬OilRig»áÔÚ·¢ËÍÓã²æÎļþǰ¶Ô¶ñÒâ´úÂëÌÓ±ÜÇå¾²¼ì²âµÄÄÜÁ¦Ìáǰ²âÊÔ¡£¡£¡£¡£¡£

    2.Ë®¿Ó¹¥»÷

    OilRigÖ÷Ҫͨ¹ý´¹Âڵķ½·¨ÊµÑéË®¿Ó¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÆäÖÐÓÃÓÚÖÆÔìË®¿ÓµÄÍøÕ¾¶¼ÊÇαÔìµÄ¡£¡£¡£¡£¡£2017Ä꣬£¬£¬£¬£¬£¬£¬£¬OilRigαÔìÁËJuniperNetworksVPNµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃJuniperµÄµç×ÓÓʼþÕÊ»§·¢ËÍÓʼþÓÕÆ­Ä¿µÄ¡£¡£¡£¡£¡£¶ñÒâµç×ÓÓʼþÖеÄÁ´½ÓÖ¸Ïò¸ÃÐéÎ±ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒªÇóÓû§ÊäÈëÓû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ËæºóÒªÇóÊܺ¦Õß×°ÖÓVPN¿Í»§¶Ë”£¬£¬£¬£¬£¬£¬£¬£¬¶øÈí¼þÖÐÀ¦°óÁËOilRigµÄ¶ñÒâÈí¼þHelminth¡£¡£¡£¡£¡£

    3.Êý¾ÝÐÅÏ¢ÆÆËð²Á³ý

    Óë¸Ã¹úÖ§³ÖµÄÆäËûºÚ¿ÍÒ»Ñù£¬£¬£¬£¬£¬£¬£¬£¬OilRigͬÑùϲ»¶°²ÅÅ“´Ý»ÙÐÔ”¶ñÒâÈí¼þ¡£¡£¡£¡£¡£IBMÔøÅû¶OilRigʹÓÃÊý¾ÝÆÆËðÈí¼þZeroCleareÃé×¼Öж«ÄÜÔ´ºÍ¹¤Òµ²¿·Ö·¢¶¯¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÆðÔ´¹ÀËãÒÑÓÐ1400̨װ±¸ÔâѬȾ¡£¡£¡£¡£¡£ZeroCleareºÍÁîÉ³ÌØÊ¯Ó;ÞÍ·Ðľªµ¨Õ½µÄÆÆËðÐÔ¶ñÒâÈí¼þShamoonÊôÓÚͬ×Ú£¬£¬£¬£¬£¬£¬£¬£¬¾ùÓɳö×Ըùú¶¥¼¶ºÚ¿Í×éÖ¯Ò»ÊÖ¿ª·¢¡£¡£¡£¡£¡£

    £¨¶þ£©Ê¹Óù¤¾ß¼°ÊÖÒÕÌØÕ÷

    OilRigʹÓõÄÍøÂçÎäÆ÷Ö÷Òª°üÀ¨£º¼üÅ̼ͼ¹¤¾ß£¨KEYPUNCH£©¡¢×ÀÃæÆÁÄ»½ØÍ¼²¶»ñ£¨CANDYKING£©¡¢ºóÃÅ£¨POWRUNER£©ºÍÓòÌìÉúËã·¨¹¦Ð§£¨BONDUPDATER£©µÈ¡£¡£¡£¡£¡£

    ÔÚÆä¹¤¾ß¿âй¶ºó£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×é֯ΪÁË×èÖ¹¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬Ò»Ö±ÔÚÆð¾¢Ë¢Ðº͸üÐÂÆäÓÐÓÃÔØºÉ¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨ÉèÁ˼¸ÖÖ²î±ðµÄ¶ñÒâÈí¼þ±äÌå¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬OilRigÒ²ÔÚÒ»Ö±¸üÐÂÎäÆ÷¿â£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨DGAÌìÉúC2ÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃDNSExfiltratorµÈ¹¤¾ßÒþ²ØÆäÊý¾ÝÁ÷Á¿µÈ£¬£¬£¬£¬£¬£¬£¬£¬Åú×¢¸Ã×éÖ¯Ò²ÔÚÒ»Ö±×·Çó·´Õì²âµÄÕ½ÂÔ¡£¡£¡£¡£¡£

    ÒÔÏÂΪOilRigʹÓù¤¾ßµÄÌØµã£º

    Ê¹Óö¨ÖƺͿªÔ´Èí¼þ¹¤¾ß¾ÙÐÐDNSÉøÂ© £»£»£»£»£» £»£»£»

    Ê¹ÓÃ×Ô½ç˵µÄDNSTunnelingЭÒé¾ÙÐÐÏÂÁî¿ØÖÆºÍÊý¾Ý»Ø´« £»£»£»£»£» £»£»£»

    ¸Ã×é֯ʹÓÃ×Ô¶¨ÖƵÄwebshellºóÃųÌÐòά³Ö¶ÔЧÀÍÆ÷µÄ³¤ÆÚ»á¼û £»£»£»£»£» £»£»£»

    »ùÓÚµç×ÓÓʼþµÄC2ʹÓÃExchangeWebЧÀͺÍÒþдÊõ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈ罫Êý¾ÝºÍÏÂÁî²åÈëµ½µç×ÓÓʼþµÄͼÏñÎļþÖС£¡£¡£¡£¡£

    ×ÅÃû¹¥»÷ÊÂÎñ

    £¨Ò»£©OilRigÊ״α»½Ò¿ªÃæÉ´

    2016Äê5Ô£¬£¬£¬£¬£¬£¬£¬£¬OilRig¹¥»÷É³ÌØ°¢À­²®¹ú·À¹¤Òµ²¿·Ö±»Çå¾²³§ÉÌPaloAltoNetwork¡¾2¡¿·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬²¢½«´ËÊÂÓëÁ½ÄêǰµÄÏàËÆ¹¥»÷ÊÂÎñ¹ØÁª£¬£¬£¬£¬£¬£¬£¬£¬½Ò¿ªOilRigµÄ“ÉñÃØÃæÉ´”¡£¡£¡£¡£¡£

    ´Ë´ÎÊÂÎñOilRigʹÓÃÁ½ÖÖ¹¥»÷·½·¨£ºµÚÒ»ÖÖÊÇExcel¼Ð´ø¶ñÒâºêÈö²¥VBºÍPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØHelminthľÂíÈëÇÖµçÄÔ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýDNSÇëÇóÇÔÈ¡Êý¾Ý £»£»£»£»£» £»£»£»µÚ¶þÖÖÊÇͨ¹ýÓʼþZIP¸½¼þÀ´Èö²¥Windows¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£

    £¨¶þ£©Õë¶ÔÖж«Õþ¸®Ê¹ÓÃOfficeÎó²îÈö²¥ºóÃÅ

    2017Äê11Ô£¬£¬£¬£¬£¬£¬£¬£¬OilRigÕë¶ÔÖж«Õþ¸®¾ÙÐÐÓã²æ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃOfficeÎó²îÈö²¥.rtf¶ñÒâÎļþ¡¾3¡¿¡£¡£¡£¡£¡£¶ñÒâÎļþʹÓÃCVE-2017-11882Îó²îÆÆËð¿ÍÕ»Äڴ棬£¬£¬£¬£¬£¬£¬£¬È»ºó½«¶ñÒâÊý¾Ýѹջ£¬£¬£¬£¬£¬£¬£¬£¬¾­ÓÉһϵÁа취ִÐУ¬£¬£¬£¬£¬£¬£¬£¬½¨ÉèÓëÏÂÁîºÍ¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷µÄÅþÁ¬¡£¡£¡£¡£¡£

    ´Ë´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬OilRigʹÓÃÁË»ùÓÚPoweShellµÄºóÃÅPOWRUNER£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ò»¸ö¾ßÓÐÓòÃûÌìÉúËã·¨¹¦Ð§µÄÏÂÔØÆ÷BONDUPDATER¡£¡£¡£¡£¡£

    £¨Èý£©Ê¹ÓÃÉ繤ÊÖÒÕαװʵÑé¹¥»÷

    2019Äê6Ô£¬£¬£¬£¬£¬£¬£¬£¬Oilrigαװ³É½£ÇÅ´óѧ³ÉÔ±µÄÉí·ÝÒÔ»ñµÃÊܺ¦ÕßÐÅÍУ¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃLinkedin˽ÐÅת´ï¶ñÒâÈí¼þ¡¾4¡¿£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÜÔ´¡¢¹«ÓÃÊÂÒµ¡¢Õþ¸®ÓÍÆøµÈ¶àÐÐÒµÖ°Ô±¡£¡£¡£¡£¡£

    OilrigʹÓÃÁËÆäÌØ¶¨±äÖÖÈí¼þPICKPOCKET±»Fireeyeʶ±ð²¢×èµ²£¬£¬£¬£¬£¬£¬£¬£¬ºóÅû¶Õâ´Î¹¥»÷ÖÐʹÓÃÁËÈý¿î×îжñÒâÈí¼þ£ºTonedeaf£¨ºóÃÅ£©¡¢ValueVault£¨ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡£¡£¡£¡£¡£©ºÍLongwatch£¨¼üÅ̼ͼÆ÷£©¡£¡£¡£¡£¡£

    £¨ËÄ£©Ê¹ÓÃÊý¾Ý²Á³ýÆÆËðÖж«ÄÜÔ´»ú¹¹Êý¾Ý

    2019Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬IBMÅû¶WiperÀà¶ñÒâÈí¼þ“Zeroclear”£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔɾ³ýѬȾװ±¸Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖж«ÄÜÔ´ºÍ¹¤Òµ²¿·Ö¾ÙÐÐÆÆËðÐÔ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÆðÔ´¹ÀËãÓÐ1400̨װ±¸Êܵ½Ñ¬È¾¡¾5¡¿¡£¡£¡£¡£¡£

    ±¨¸æÒÔΪ£¬£¬£¬£¬£¬£¬£¬£¬ZeroCleare¼«ÆäΣÏÕ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÓò¿ØÖÆÆ÷(DomainControllers)¿ÉÒÔÔÚ×éÖ¯ÖÐѸËÙÈö²¥¡£¡£¡£¡£¡£±¨¸æÌåÏÖ´ÓÊܺ¦Ä¿µÄ¡¢IP¹ØÁªÒÔ¼°Ê¹ÓÃÈí¼þµÄÏà¹ØÁªÏµ¿ÉÒÔÍÆ²â´Ë´Î¹¥»÷¿ÉÄÜÔ´×ÔOilRig¡£¡£¡£¡£¡£

    £¨Î壩2021Äê¶ÔÖж«µÄ×îй¥»÷Ô˶¯

    2021Äê1ÔÂÖÁ4ÔÂʱ´ú£¬£¬£¬£¬£¬£¬£¬£¬OilRigÕë¶ÔÖж«µØÇøÔÙ´ÎʵÑé¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½ÓÄÉWordÓÕ¶üÎĵµ×÷Ϊ³õʼ¹¥»÷¡¾6¡¿¡£¡£¡£¡£¡£ÎĵµÎ±×°³É“Àè°ÍÄÛˮʦս½¢Í£µ±Çåµ¥”¡¢“Ntiva¹«Ë¾µÄÕÐÆ¸ÐÅÏ¢”£¨ÃÀ¹úITЧÀÍÉÌ£©µÈÓÕ¶üÎļþ×÷Ϊ¹¥»÷Èë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬ÍŽáÇÔÈ¡µÄExchangeÕ˺ÅÍê³É×éºÏÈëÇÖ¡£¡£¡£¡£¡£OilRigÔÚÎĵµÕýÎÄÖÐÌí¼ÓÓÕµ¼ÐÔÐÎòÒÔÓÕʹĿµÄÆôÓöñÒâºê´úÂ룬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÖ²ÈëºóÃųÌÐò¡£¡£¡£¡£¡£

    ÖµµÃÒ»ÌáµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÄÚÖÃÁËÀè°ÍÄÛÕþ¸®µÈÓëÓÕ¶üÎļþÏà·ûµÄExchangeÓÊÏäÕË»§Éϰ¶Æ¾Ö¤£¬£¬£¬£¬£¬£¬£¬£¬ÍƲ⹥»÷ÕßÔÚÏÈÆÚ×¼±¸½×¶ÎÒÑÀÖ³ÉÈëÇÖÁËÓйØ×éÖ¯»òÓëÆä¾ßÓÐÐÅÍйØÏµµÄÓʼþÕË»§£¬£¬£¬£¬£¬£¬£¬£¬²¢½è¸ß¿ÉÐÅExchangeЧÀÍÆ÷ΪÐÅÍнڵãÖÐתͨѶ£¬£¬£¬£¬£¬£¬£¬£¬Òþ²Ø¶ñÒâÐÐΪ¡£¡£¡£¡£¡£

    ×ܽá

    ×ÜÌå¶øÑÔ£¬£¬£¬£¬£¬£¬£¬£¬OilRig´ú±íÁ˸ÃÖж«¹ú¼ÒÍø¾üµÄ×î¸ßÍøÂç¹¥»÷ˮƽ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒÔʵÆäÕþÖÎÄ¿µÄΪÖ÷ҪĿµÄµÄAPT×éÖ¯¡£¡£¡£¡£¡£

    Æä¹¥»÷¹æÄ£Ö÷ÒªÕë¶ÔÖж«¹ú¼Ò£¨ÒÔÉ«ÁÐΪÖ÷£©¼°µÐ¹úÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬½ü¼¸ÄêÀ´ÎÒ¹úÒ²³ÉΪÁËÆä¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£

    OilRigµÄ³õʼ¹¥»÷ËäÈ»¼òÆÓÖ±½Ó£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÍŽáÆäÍøÂçµÄµÇ¼ƾ֤µÈÊý¾ÝʹµÃÊܺ¦ÕßÎÞ·¨Õç±ð¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬OilRigÉÆÓÚʹÓÃÁ÷Á¿Òþ²ØÊÖÒÕʹµ½ÊÖÒÕÖ°Ô±Ô½·¢ÄÑÒÔ·¢Ã÷¼°×·×Ù¡£¡£¡£¡£¡£

    ×¢½â

    https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf

    https://unit42.paloaltonetworks.com/unit42-oilrig-actors-provide-glimpse-development-testing-efforts/

    https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html

    https://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-their-professional-network.html

    https://www.ibm.com/downloads/cas/OAJ4VZNJ

    https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/

    ¹ØÓÚ×÷Õß

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺÓ¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý46¸ö£¬£¬£¬£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯13¸ö£¬£¬£¬£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿