上文我们对第一台Target机器进行内存取证,今天我们继续往下学习,内存镜像请从上篇获取,这里不再进行赘述
Gideon
攻击者访问了"Gideon",他们向AllSafeCyberSec域控制器窃取文件,他们使用的密码是什么?
攻击者执行了net use z: \10.1.1.2\c$ 指令将 10.1.1.2域控制器的C盘映射到本地的Z盘,并且使用了rar压缩工具将文件存储在 crownjewlez.rar里,所以密码就在这里了
data:image/s3,"s3://crabby-images/da76f/da76f41affc9b348b5d46ef55352a417f83331c9" alt=""
攻击者创建的RAR文件的名称是什么?
data:image/s3,"s3://crabby-images/71f72/71f7248aad4d367333e0a4727598fcd65385e0d7" alt=""
攻击者向RAR压缩包添加了多少文件?
bash
./volatility_2.6_lin64_standalone -f target2-6186fe9f.vmss --profile=Win7SP1x86_23418 cmdline
./volatility_2.6_lin64_standalone -f target2-6186fe9f.vmss --profile=Win7SP1x86_23418 cmdscan
data:image/s3,"s3://crabby-images/fdfb6/fdfb60073be76d303b2a701ed00e3215a7ca3a5a" alt=""
将进程导出成dmp格式
bash
./volatility_2.6_lin64_standalone -f target2-6186fe9f.vmss --profile=Win7SP1x86_23418 memdump -p 3048 -D ./rar
data:image/s3,"s3://crabby-images/db27d/db27dd4e89f1867507e0a194d6a05be9c8cf141a" alt=""
直接搜索关键字,按照txt格式搜索就可以
bash
strings -e l 3048.dmp | grep -10 crownjewlez | grep txt
data:image/s3,"s3://crabby-images/cd07f/cd07fbc61c1343a0d041c862414041ed10fc5a81" alt=""
这里乱七八糟的,数来数去也就是3个,这里grep txt的原因是因为我们在上面的*txt就已经知道别人只是把txt文件压缩了,所以我们只要看txt文件就行
后来发现不用导出
bash
strings -e l target2-6186fe9f.vmss| grep -10 crownjewlez.rar | grep txt
data:image/s3,"s3://crabby-images/7c3df/7c3df48410865ed3151ce3520a7eceabf76de40d" alt=""
攻击者似乎在Gideon的机器上创建了一个计划任务。与计划任务关联的文件的名称是什么?
bash
./volatility_2.6_lin64_standalone -f target2-6186fe9f.vmss --profile=Win7SP1x86_23418 filescan | grep 'System32\\Tasks'
data:image/s3,"s3://crabby-images/fb6c6/fb6c6ef3ae449066775423de0f92a50528ebe218" alt=""
导出
bash
./volatility_2.6_lin64_standalone -f target2-6186fe9f.vmss --profile=Win7SP1x86_23418 dumpfiles -Q 0x000000003fc399b8 -D ./task
POS
恶意软件的CNC服务器是什么?
老规矩,先看第三个镜像的信息
bash
./volatility_2.6_lin64_standalone -f POS-01-c4e8f786.vmss imageinfo
data:image/s3,"s3://crabby-images/9e23b/9e23ba7940f52f95d9ccd63bed9f51c21aece4be" alt=""
网络扫描
bash
./volatility_2.6_lin64_standalone -f POS-01-c4e8f786.vmss --profile=Win7SP1x86_23418 netscan
data:image/s3,"s3://crabby-images/7b327/7b3273f116bd28e5849909df73a4707c536e8316" alt=""
暂时看到iexplore.exe ,该进程贯穿核心,而后我们继续往下看,尝试过滤一下恶意代码扫描结果
bash
./volatility_2.6_lin64_standalone -f POS-01-c4e8f786.vmss --profile=Win7SP1x86_23418 malfind | grep iexplore.exe
data:image/s3,"s3://crabby-images/a7fe0/a7fe0351c56bb2c199f875be0c738e9922f19c3d" alt=""
暂时对应了,所以此题答案就是54.84.237.92
用于感染POS系统的恶意软件的家族是什么?
笔者尝试了很多方法都没有找到正确的木马家族,然后就看了一下国外大佬的,才知道原来malfind也可以导出文件
bash
./volatility_2.6_lin64_standalone -f POS-01-c4e8f786.vmss --profile=Win7SP1x86_23418 malfind -p 3208 -D ./tmp
Allsafecybersec的具体应用程序是什么?
bash
strings process.0x83f324d8.0x50000.dmp| grep exe
data:image/s3,"s3://crabby-images/62b77/62b77bffe94d97eaada27462c29224053878f416" alt=""
恶意软件最初启动的文件名是什么?
bash
./volatility_2.6_lin64_standalone -f POS-01-c4e8f786.vmss --profile=Win7SP1x86_23418 iehistory
data:image/s3,"s3://crabby-images/3db8f/3db8f0aec81a48c2aea42307a5e33064f3833bd6" alt=""
或者将3208进程导出来
bash
./volatility_2.6_lin64_standalone -f POS-01-c4e8f786.vmss --profile=Win7SP1x86_23418 memdump -p 3208 -D ./tmp
data:image/s3,"s3://crabby-images/b0ac0/b0ac0c0cad9786c9e894807380b1e5f5e3b571f8" alt=""
bash
strings 3208.dmp| grep exe | grep all
data:image/s3,"s3://crabby-images/cedfb/cedfb3cf98c119c2ce3da8cc603bd93f6c57f6a0" alt=""
到此就告一段落了,下期将会出一个简单的流量溯源,关于tomcat 的网络取证场景,敬请期待吧