
, , , . , Solar JSOC .
. -, user-agent . Solar JSOC , , , . , .
, user-agent , . ngfw , , , , , , , .
: , , , , . .
17 2017 3 , . , user-agent`, TightVNC. Solar JSOC, , .
:
03:08:02. .
03:26:00. .
03:29:00. .
03:32:48. 1- .
03:48:00. SIEM-.
( ) , , tnvserver.exe. , . -, .
:
, , , . , , .
. , , , , . , , , .
not-a-virus, , , . .
, , . , , , , remote administration. .
, / .
:
- , -. , .
- , not-a-virus.
- security awareness .
- . , .
- , ( ).
- SIEM- , TOR, .
.
Solar JSOC , . , .
, . Windows ( 2 System Event Log, Security )
, . (techuser). IT- .
:
, server - , wtmp ( ) root .
SRV , , nmap ( ) medusa ( ).
SRV root smb. , .
HPE ArcSight:
( 10 ) smb SRV . , . , techuser smb . Windows lsass.exe.
techuser , remoteshell.
:
- powershell, .
- svchost.exe , , .
- 9887 ( ).
- , /
, .
, , :
, , .
- :
- -:
- , (Mimikatz, procdump).
APT. ?
, Solar JSOC, , APT spoiler alert! . , :
, - . , , , Solar JSOC.
: ip-, 2-4 , . , . , activelist target address request url host (target host name), request url.
(IP- C&C-), .
. , .
. , Mipko Personal Monitor (MPK).
MPK - \Serv. .
Mipko Personal Monitor , , , .
: \serv .
8 :
- ***nks.biz FTP
- ******@gmail.com
.
\serv RDP ( 10 000 ).
, MPK, - \Serv:
MPK , 500 IP , RDP, (-).
, -, / , . , , .
.
( ).
MPK :
- MPK, : C:\ProgramData. PE-, MPK, -.
JFIF (JPEG File Interchange Format), .
- , MPK:
mpk.exe (NT AUTHORITY)
mpkl64.exe (NT AUTHORITY)
lsynchost.exe (NT AUTHORITY)
- PE- (MPK64.dll MPK.dll), MPK, .
, . PE-: MPK64.dll MPK.dll.
MPK , , :
- : %SYSTEMROOT%\ProgramData\MPK\*
%SYSTEMROOT%\SysWoW64\Mpk\*
%SYSTEMROOT%\Prefetch\*
%SYSTEMROOT%\inf\*
%SYSTEMROOT%\System32\Logs\*
%USERPROFILE%\AppData\Local\ Temporary Internet Files\*
%USERPROFILE%\Temp\*
- : HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
- .
C:\Windows\MPK -, : mpk_em_log.txt *.dat. MPK:
- PE- mpk_emni_mpk.exe. , , C:\Users\Serv\Desktop\1\6\*.
- Windows :

- \Serv 1 2. , C:\ProgramData, .
:
- .
- , .
- , Service-Desk , .
- IP- . IP- , :
- , , .
- :
, . , . , .
, JSOC. , , . , , Solar JSOC.
https://habrahabr.ru/post/333816/