揭秘新型OT_IoT网络武器——IOCONTROL.pdf

编号:991842 PDF 73页 2.86MB 下载积分:VIP专享
下载报告请您先登录!

揭秘新型OT_IoT网络武器——IOCONTROL.pdf

1、Inside a New OT/IoT Cyberweapon:IOCONTROLNoam Moshe,Claroty Team82$whoamiNoam MosheVulnerability researcher and Claroty Team82 Team Lead-mostly breaking IoT clouds.Master of Pwn Pwn2Own ICSPreviously On“Irans OT Cyber Warfare”Nov 23:APT targets Unitronics PLCsCyberAv3ngers Used in water facilities w

2、orldwideFear and PanicSo We Bought a DeviceDB9RJ11Digital Forensics Key Indicators from PLCXXX.XXX.XXX.XXX1234561.PLC Name,Model&IO2.Date and time on PC during download3.PC username,file title&file download pathway4.Software version during file creation&modification5.Connection type to PLC,IP addres

3、s&port6.PC operating system&languageFindings:At least 3 separate naming conventionsIdentification of exact date and times of compromise to reference back to log dataAt least 3 separate usernames&file pathwaysAll compromised programs used old versions of VisilogicAll PCs running Windows 7 or later an

4、d in EnglishXXX.XXX.XXX.XXXNext On.“Irans OT Cyber Warfare”14 October 2023Infecting Gas Stations?SiteOmat360 Station Automation SoftwareHardcoded creds for both HTTP Server and SSH!Hardcoded creds for both HTTP Server and SSH!IOCONTROLOT/IoT MalwareBaicells,D-Link,Hikvision,Red Lion,Orpak,Phoenix Co

5、ntact,Teltonika,Unitronics.BaicellsPhoenix ContactHikvisionred lionD-LinkUnitronicsTeltonikaObtaining Sample Found sample on VT VT zero detections ARM 32-bit BE Packed IOCONTROL-Unpacking Emulation with UnicornHooked all syscallsSafe executionFound out to be modified UPX IOCONTROL-Unpacking Patched

6、UPXABC!UPX!CRC checksIOCONTROL Victim GUID identifier Encrypted modular configuration Persistency DNS over HTTPs MQTT C2 communication CommandsVictim GUID identifier Specific GUID identify each victim Used as seed for encryption Easy to binary patch instead of compileIOCONTROL Victim GUID identifier

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(揭秘新型OT_IoT网络武器——IOCONTROL.pdf)为本站 (可不可以) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠