ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö
°ä²¼¹¦·ò 2019-05-18½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab¼à²âµ½Ò»ÅúÒÉËÆÕë¶ÔÎ÷°àÑÀÓïµØÓòÈ·µ±¾Ö»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿Ãŵ͍Ïò¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í×é֯ͨ¹ý»ú¹Ø¶ñÒâOffice WordÎĵµ²¢¹²Í¬Óã²æÓʼþÌáÒ鶨Ïò¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¡°¼òÀú¸üС±×÷Ϊµö¶üÎĵµÏò¹¥»÷Ö¸±êÖ²Èë¼äµýľÂí£¬£¬£¬£¬£¬£¬£¬£¬´Óʵý±¨ÍøÂç¡¢Ô¶¿Ø¼à¶½¼°ÏµÍ³·ÛËéµÈ¶ñÒâÐж¯¡£¡£¡£¡£¡£ÎÒÃǽ«ÍÁ¶úÆäºÚ¿ÍµÄÕâ´Î¹¥»÷Ðж¯³ÆÎª¡°ºÚʨÐж¯¡±¡£¡£¡£¡£¡£
ͨ¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷ÓйØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬£¬£¬£¬£¬£¬£¬£¬È·¶¨¸Ã´Î¹¥»÷ÆðÔ´ÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¸Ã×éÖ¯ÊÇÒ»¸öÃñ×åÖ÷ÒåÉ«²Ê¼«¶ÈŨÃܵĺڿÍ×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬Ôø¹¥ÏÂÆäËû¹ú¶ÈµÄ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂÆä×éÖ¯µÄÃû³Æ£¬£¬£¬£¬£¬£¬£¬£¬ËæºóÒþûÁ˶àÄê¡£¡£¡£¡£¡£ Èç½ñͨ¹ýÎÒÃǶԡ±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯¼£Ï󡣡£¡£¡£¡£±¾´Î¹¥»÷¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯Ñ¡È¡ÉøÈ뼿Á©¹¥Ï¶ą̀·þÎñÆ÷²¢½«Æä×÷Ϊ´æ·Å¹¥»÷´úÂëµÄÌø°å¡£¡£¡£¡£¡£
1Íþв·ÖÎö
1.1 ¹¥»÷Ö¸±ê·ÖÎö
´ÓĿǰËù»ñÈ¡µÄ¹¥»÷Ñù±¾ºÍÍþвµý±¨£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»¿´³ö±¾´Î¹¥»÷»î¶¯²¢Ã»Óдó¹æÄ£µÄ½øÐУ¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹´¦ÓÚ¹¥»÷ÊÔ̽½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇ´ÓÆäͶ·ÅµÄµö¶üÎĵµÄܹ»µ¥Ò»¼òÖ±¶¨Æä¹¥»÷Ö¸±êËø¶¨ÔÚÎ÷°àÑÀÓïϵµÄ¹ú¶È¡£¡£¡£¡£¡£ÕâЩµö¶üÎĵµÐÎÈ磺¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±£¨¼òÀú¸üРº£Ã·°¢ÀïÑÇ˹£©¡¢¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±(¼òÀú¸üРµ¤Äá¶û°ÂµÙ×È)¡¢¡°Michelle Flores - Curriculum Actualizado.doc¡±(Ã×Ъ¶û¸¥ÂåÀ×˹-¼òÀú¸üÐÂ)¡¢¡°Jose Trujillo.doc¡±(ºÎÈûÌØÂ³Ï£ÂÔ)µÈµÈ£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǾùѡȡÎ÷°àÑÀÓïÀ´»ú¹ØÒ»¸ö´ø¶ñÒâºê´úÂëµÄ¼òÀúÎļþ¡£¡£¡£¡£¡£ÒÔ´ËÀ´¶ÔÖ¸±êÈËÁ¦²¿ÃŽøÐй¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÓÕʹÓйØÈËÔ±Ö´ÐжñÒâ´úÂë½ø¶ø´Óʼäµý»î¶¯¡£¡£¡£¡£¡£
ÔÚÎÒÃÇ·ÖÎöÕâÅúµö¶üÎĵµÊ±£¬£¬£¬£¬£¬£¬£¬£¬»¹·¢ÏÖÒ»¸öÓÐȤµÄ¾°Ï󣬣¬£¬£¬£¬£¬£¬£¬ÄǾÍÊǺܶàµö¶üÎĵµÖÐÔ̺¬ÁËÎĵµ×÷ÕßÐÅÏ¢ºÍ×îºóÒ»´Î±£ÁôÕßÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÕâЩÐÅÏ¢¾ùΪÀàËÆ²ÆÕþ²¿¡¢Ðŷþ֡¢SCG£¨Southern Connecticut Gas£©µÈµÅ×ëµ±²¿ÃÅÃÅÓйصÄÐÅÏ¢¡£¡£¡£¡£¡£Í¨¹ýÎÒÃÇÏÖʵ²âÊÔ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢¾ù»áÔÚÎĵµÅú¸ÄºóÔì³Éµ±Ç°½Ó¼ûÕßofficeµÇ½ÕË»§Ãû»òÕßÖ÷»úÃû£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÐÐĵÄÈË»¹Äܹ»¶ÔÆä½øÐÐËÁÒⶨÔì¡£¡£¡£¡£¡£ÎÒÃǰÎÈ¡¼¸¸öµäÐ͵ÄÑù±¾²¢Õë¶ÔÓйØÐÅÏ¢ºÍÂß¼¹ØÏµ×öÁËÈçÏÂÊáÀíºÍÍÆÂÛ£º
ÎÒÃÇͨ¹ý´´½¨ÄÚÈݹ¦·ò¡¢×îºóÅú¸Ä¹¦·ò¼°¹¥»÷ÎĵµÄÚ²¿µÄÂß¼¹ØÏµÍÆÂÛ³öÓйؼͼӦΪ¹¥»÷Õß±£Áô¡£¡£¡£¡£¡£»£»£»£»£»ùÓÚ×îºÏÀíÒÔ¼°×îÓпÉÄܵĴ§Ä¦£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÒÔΪ¹¥»÷Õß¿ÉÄÜÊÇ»ùÓÚºÚ¿Í×éÖ¯ÄÚ²¿¹æ·¶£¬£¬£¬£¬£¬£¬£¬£¬½«ÎĵµµÄÓйØÃû³ÆÉèÖÃΪ¹¥»÷Ö¸±ê»òÓйØÐÐÒµÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÎ±Ôì³ÉÄÚ²¿ÈËÊ¿£¬£¬£¬£¬£¬£¬£¬£¬Ôڿ϶¨Ë®Æ½ÉÏÆðµ½»ìºÏÊÓÌý¡¢Òñ±Î×ÔÉíµÄÖ÷ÕÅ¡£¡£¡£¡£¡£
ÓÉ´ËÎÒÃÇÄܹ»¿´³öÕâ´ÎÐж¯µÄ¹¥»÷Ö¸±êΪÎ÷°àÑÀÓïϵµØÓòÈ·µ±¾Ö»òÕß¹«¹²·þÎñ²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬µ±È»²¢²»ÅųýÆäÓиü¶àµÄÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙÄܹ»×¢¶¨µÄÊÇÕâ´ÎÐж¯ÊÇÒ»´Î´øÓÐÕþÖÎÖ÷ÕŵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£
1.2 ºÚ¿Í×éÖ¯·ÖÎö
ÔÚ¶ñÒâ´úÂë´æ´¢õè¾¶µÄͬĿ¼£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖºÚ¿Í×éÖ¯ËùÁôϵÄһЩÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÏÂͼΪÆäÖÐÒ»¸öÎļþ¼Í¼µÄÐÅÏ¢£º
¸ÃÎļþÖÐÔ̺¬ÁËһЩÉêÃ÷ÐÅÏ¢¡¢ºÚ¿Í×éÖ¯¼°ÆäÓйسÉÔ±£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒËùѡȡµÄ˵»°ÎªÍÁ¶úÆäÓ£¬£¬£¬£¬£¬£¬£¬Òò¶øÎÒÃÇÅж¨¸Ã×éÖ¯ÕýÊÇÒѾ»îԾһʱµÄKingSqlZºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¸Ã·þÎñÆ÷ºÜÓпÉÄÜÔÚ±»ºÚ¿Í×éÖ¯½ÚÔìºó×÷ÎªÌø°å»ú»ò×ÊÔ´·þÎñÆ÷³ÖÐøÊ¹Óᣡ£¡£¡£¡£´Ë±íͨ¹ý¶ñÒâ´úÂëʱ·Ö±æÎö·¨£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽøÒ»²½È·¶¨¸Ã´Î¹¥»÷À´×ÔÓÚÍÁ¶úÆäºÚ¿Í¡£¡£¡£¡£¡£ÎÒÃǶÔRATÑù±¾Ö®Ç°µÄPEÎļþ¼°ÆäËûǰÆÚ¹¥»÷»·½ÚÓйصÄÑù±¾µÄ±àÒ빦·ò×öÁËʱ·Ö±æÎö£¨ÓÉÓÚRATÑùÕý±¾×ÔÓÚÉÏÓκڿͣ¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÎÒÃǺöÂÔÁ˸ÃÀàÑù±¾µÄʱ·Ö±æÎö£©¡£¡£¡£¡£¡£×îºó·¢ÏÖÕâЩ¹¥»÷Ñù±¾µÄ±àÒ빦·òÔÚUTC¹¦·ò21:00ÖÁ06:00Çø¼äÄÚ³öÏֵįµ´Î¼«µÍ¡£¡£¡£¡£¡£¶ø¼Ù¶¨ÒÔ24:00ÖÁ08:00×÷Ϊ˯Ãß¹¦·ò£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßËù´¦µÄÊ±Çø¿ÉÄÜ»áÔÚ¶«3Çø£¨UTC+3£©Õý¸º 1 Ó×Ê±Çø¼äÄÚ£¬£¬£¬£¬£¬£¬£¬£¬¶øÍÁ¶úÆäÊ±ÇøÎª¶«ÈýÇøÕýºÃÇкϡ£¡£¡£¡£¡£
±¾´Î¹¥»÷»î¶¯ÆðÍ·ÓÚ2019Ä꣬£¬£¬£¬£¬£¬£¬£¬Ñ¡È¡´óÁ¿¹«¹²DDNS·þÎñ×ÓÓòÃû×÷ΪC2À´Ö´Ðй¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÕâÆäÖеÄһЩÓòÃûΪ2019ÄêÐÂ×¢²áµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓõIJ¿ÃÅÓòÃûÈçÏ£º
casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
2¹¥»÷¸ÅÊö
Õâ´ÎÊÂÎñµÄÖØÒª¹¥»÷»î¶¯¹¦·òÏßÈçÏÂËùʾ:
ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǶÔ2019Äê2ÔÂ7ÈÕ·¢Ïֵġ°Curriculum Vitae Actualizado Jaime Arias.doc¡±Îĵµ½øÐÐÁ˾ßÌåµÄ·ÖÎö£¬£¬£¬£¬£¬£¬£¬£¬²¢Ïà¼Ì²¶»ñµ½¹ØÁªÎĵµ¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc/ Jose Trujillo.doc¡±¡£¡£¡£¡£¡£
¹¥»÷ÕßʹÓÃÁËAPI¹þÏ£¡¢ÎÞÎļþ¹¥»÷¡¢WinrarSFX¡¢AutoIt¡¢C#»ìºÏºÍ¿þÀܹý³ÌµÈ¼¼ÊõÀ´¶ã±Ü¼ì²â²¢×ÌÈÅ·ÖÎöÈËÔ±¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ÎĵµÖ²ÈëµÄľÂíÆðÔ´×î³õÎÞ·¨È·ÈÏ£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÔÚÆäÖз¢ÏÖÁËÌØµã×Ö·û´®¡°AVE_MARIA¡±,ÆäÓëCybaze-Yoroi ZLab×êÑÐÈËÔ±ÔÚ2018Äê12Ôµ×Åû¶µÄÕë¶ÔÒâ´óÀûijÄÜÔ´ÆóÒµ½øÐй¥»÷µÄ¶ñÒâÈí¼þÀàËÆ¶ÈºÜ¸ß£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃŰ²È«×êÑÐÔ±ºÍ³§ÉÌÓÉÓÚûÓгɹ¦µÄ½øÐÐËÝÔ´±ãÒÔ´Ë×Ö·û´®×öΪ¸ÃľÂí¼Ò×åµÄÃû³Æ¡£¡£¡£¡£¡£¶øÎÒÃǾ¹ý¹ØÁªËÝÔ´ºÍͬԴÐÔ·ÖÎöºó·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾Í¬RAT¹¤¾ß¡°WARZONE¡±RATÓµÓи߶ÈÒ»ÖÂÐÔ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø½«´ËÀà¶ñÒâ¼Ò×嶨Ãû¸üÐÂΪ¡°WARZONE¡±¡£¡£¡£¡£¡£
3¼¼Êõ·ÖÎö
3.1 ÔçÆÚ¹¥»÷Ñù±¾
Õâ´Î¹¥»÷¹ý³ÌÆðÍ·ÓÚÒ»¸öЯ´ø¶ñÒâºêµÄDOCÎĵµ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ýαÔì³É¼òÀúµÄͶµÝÓʼþ¼¿Á©½«´Ë¶ñÒâÎļþ·¢Ë͸ø¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬£¬µ±Ö¸±êÓû§Ê§É÷´ò¿ªÎĵµ±ã³ÉΪÁËÊܺ¦Õß¡£¡£¡£¡£¡£DOCÎĵµÔËÐкó»áÆô¶¯¶ñÒâºê´úÂë²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÏÂÔØEtr739.exe£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÏÂÔØºóÁ¢¼´Ö´ÐÓ×£¡£¡£¡£¡£Ð¹ý³Ìͨ¹ýBase64½âÂë³öÁíÒ»¸ö·þÎñÆ÷µØÖ·£¬£¬£¬£¬£¬£¬£¬£¬³ÖÐøÏÂÔØ¶ñÒâ´úÂëhqpi64.exeÖÁһʱĿ¼Ï¡£¡£¡£¡£¡£¶ñÒⷨʽhqpi64.exe¾ÍÊÇWarzone RATµÄ¿ªÊÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Æäͨ¹ý¿ªÊÍWarzone RATÀ´Ö´ÐкóÐø²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬È罫explorer.exe×÷Ϊ¿þÀܹý³ÌÊØ»¤¡¢Óë½ÚÔì¶Ë½øÐÐͨѶµÈ¡£¡£¡£¡£¡£
Ñù±¾ÖеĶñÒâ´úÂë´ó²¿ÃÅѡȡCRC32À´¼ÓÃÜÃô¸Ð×Ö´®£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÔÚAPIŲÓÃÊÖ·¨ÉÏѡȡÁËAPI HashÖµ¶¯Ì¬»ñÈ¡º¯ÊýµØÖ·ºÍÄ£Äâϵͳ¼±¾çŲÓÃÁ½ÖÖ·½Ê½¡£¡£¡£¡£¡£Ê¹ÓôËÀàÊÖ·¨²»Ö»ÄÜÔڿ϶¨Ë®Æ½ÉÏÏ÷¼õɱÈí¾²Ì¬É¨ÃèµÄ¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹²»Ò×±»¼à²âµ½APIµÄŲÓÃ×ÙÓ°¡£¡£¡£¡£¡£Í¬Ê±ÆäʹÓô¿¼ÓÃÜShellcode´úÂëÄÚ´æÖ´Ðеķ½Ê½¼ÓÔØÆäÖ÷ÌâÖ°ÄÜÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¡°ÎÞÎļþ¼¼Êõ¡±Ìá¸ß×ÔÉíÒñ±ÎÐÔ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ´ËÀ´¶ã±Ü°²È«³§É̲éɱ¡£¡£¡£¡£¡£ÆäÓëC2·þÎñÆ÷¼äµÄͨѶÊý¾ÝÒ²ÒÔCR4Ëã·¨½øÐмÓÃܽø¶ø¶ã±ÜIDSϵͳµÄ¼ì²â¡£¡£¡£¡£¡£
(1)DOCÎĵµ
ÔÚAutoOpenº¯ÊýÖÐÔ̺¬ÁËÒ»´®»ìºÏ¹ýµÄcmdºÅÁ£¬£¬£¬£¬£¬£¬£¬¾¹ý½âÃܺóµÄ´úÂëÈçͼËùʾ£º
Õâ¶Î´úÂë»ñµÃÖ´Ðк󣬣¬£¬£¬£¬£¬£¬£¬»áÖ±½Ó´Ó´ËÁ´½ÓµØÖ·(http[:]//linksysdatakeys.se)ÏÂÔØ¶ñÒⷨʽµ½¡°%Temp%\SAfdASF.exe¡±²¢Ö´ÐÓ×£¡£¡£¡£¡£
(2)Payload
¸ÃPayloadÏȽ«ÉÏͼÖмÓÃܵÄÊý¾Ýͨ¹ýBase64½âÂë³öÏÂÔØÁ´½ÓµØÖ·¡°http[:]//www.gestomarket[.]co/hqpi64.exe¡±£¬£¬£¬£¬£¬£¬£¬£¬¶øºó°Ñhqpi64.exe¸ÄÃûΪ2XC2DF0S.exe²¢±£ÁôÔÚһʱĿ¼Ï¡£¡£¡£¡£¡£
(3)Dropper
ÔÚºóÐøµÄ½âÃÜÒÔ¼°Ö´ÐеĹý³ÌÖУ¬£¬£¬£¬£¬£¬£¬£¬´ËDropper»á°ÑÒ»¶ÎShellcode×¢Èëµ½explorer¹ý³Ì²¢ÔÚÄÚ´æÖнâÃܳöRATʵÌåʹÆä²»Â䵨£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕͨ¹ýÎÞÎļþ¼¼Êõ½«RAT¼ÓÔØµ½ÄÚ´æÖÐÀ´Ö´ÐÓ×£¡£¡£¡£¡£
Ìӱܼì²â
½âÃÜshellcode
×Ô½ç˵µÄ½âÃܺ¯Êý
¾¹ý³Á³ÁÏÂÔØ²¢½âÃÜÖ®ºó£¬£¬£¬£¬£¬£¬£¬£¬ÄÇôÕâ¶Î½âÃܺóµÄShellcode(PE Loader)´úÂë¾ßÌåζ×öЩʲô£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÃæÎÒÃÇÀ´Ò»¿úµ½µ×¡£¡£¡£¡£¡£
PE Loader
|
ÐòºÅ |
ÄÚÈÝ |
Ö°ÄÜ |
|
²ÎÊý1 |
¡°FYBLV¡± |
¿½±´×ÔÉíµÄĿ¼ÃûºÍÎļþÃû(Ðè½âÃܵÄ×ÊÔ´Ãû) |
|
²ÎÊý2 |
¡°BJU¡± |
RATÔ¶¿ØÎļþ(Ðè½âÃܵÄPEÎļþ×ÊÔ´Ãû) |
|
²ÎÊý3 |
¡°OPTYUPPABIVSUWNRXSNCTDW¡± |
Key |
|
²ÎÊý4 |
0x01£¨¹Ì¶¨ÊýÖµ£© |
δʹÓà |
¸ÃPE LoaderÊ×ÏÈÔÚÔËÐйý³ÌÖнøÐÐÁËɳÏäºÍÖ¸¶¨¹ý³ÌµÄ¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·À±»×Ô¶¯»¯ÏµÍ³·ÖÎö¡£¡£¡£¡£¡£²¢ÇÒÆ¾¾Ý×Ô´øµÄ×ÊÔ´Êý¾ÝÀ´Åж¨ÊÇ·ñÖ´ÐÐפÁô±¾»úµÄ²Ù×÷ºÍ×¢ÈëÌåµÄÑ¡Ôñ¡£¡£¡£¡£¡£×îºó´ËPE Loader½«×îÖÕÑ¡ÔñµÄ¿þÀܹý³ÌµÄ¿Õ¼ä¼Ü¿Õ£¬£¬£¬£¬£¬£¬£¬£¬²¢°Ñ½âÃܳöµÄRATÄ£¿£¿£¿£¿£¿£¿£¿£¿éÓ³Éäµ½´Ë¹ý³ÌÖÐÖ´ÐÐ(Õý±¾PEÎļþ´úÂë±»Öû»)¡£¡£¡£¡£¡£
ÔËÐл·¾³¼ì²â
ÔËÐл·¾³¼ì²â
²Ù×÷×ÊÔ´Êý¾Ý
¾¹ý¶ÈÎö£¬£¬£¬£¬£¬£¬£¬£¬½á¹¹ÌåÖÐÿ¸ö³ÉÔ±µÄ¾ßÌåÖ°Äܿɲο¼ÏÂͼ£º
¿ªÊÍÓëפÁô
´´½¨µÄ¿ì½Ý¼üÊôÐÔ
×îºó£¬£¬£¬£¬£¬£¬£¬£¬¸ÃPE Loaderƾ¾Ý½á¹¹ÌåÖеÄdwFlagÖ·´Ñ¡ÔñºóÐøµÄRATÔØÌ壬£¬£¬£¬£¬£¬£¬£¬Ëù¶ÔÓ¦µÄRATÔØÌåÏê¼ûÏÂ±í£º
|
Êý¾Ý |
¹ý³ÌÃû |
|
0x01 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe |
|
0x02 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe |
|
0x03 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe |
|
0x04 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
0x05 |
C:\Windows\System32\svchost.exe |
|
0x06 |
C:\Windows\System32\dllhost.exe |
|
0x07 |
µ±Ç°ÔËÐеÄ×ÔÉí¹ý³Ì |
¶øÔÚ±¾Ñù±¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬´Ë³ÉÔ±µÄÖµËù¶ÔÓ¦µÄÔØÌåΪµ±Ç°ÔËÐеÄ×ÔÉí¹ý³Ì¡£¡£¡£¡£¡£
»ñÈ¡RAT²¢Ö´ÐÐ
½Ó×Å£¬£¬£¬£¬£¬£¬£¬£¬¸ÃPE Loader³Áд´½¨Ð¹ý³Ì²¢½«ÆäÉèÖÃΪ¹ÒÆð״̬¡£¡£¡£¡£¡£¶øºóÐ¶ÔØ´Ë¹ý³ÌÓ³Ïñ£¬£¬£¬£¬£¬£¬£¬£¬²¢°ÑÔÚÄÚ´æÖнâÃܳöµÄеÄPEÍ·²¿£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°½ÚÊý¾Ý˳´ÎдÈëµ½¹ÒÆðµÄ¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬£¬×îºóÅú¸ÄOEP²¢Æô¶¯ÔËÐÓ×£¡£¡£¡£¡£
(4) WARZONE RATÄ£¿£¿£¿£¿£¿£¿£¿£¿é
Ô¶¿Ø·¨Ê½Warzoneºó¶Ü½çÃæ
»ñÈ¡C&CµØÖ·
ΪÁËÔ¤·ÀC&C±»µÈÏз¢ÏÖ»òÕßÅúÁ¿ÌáÈ¡£¬£¬£¬£¬£¬£¬£¬£¬¸ÃľÂí½«Æä¼ÓÃÜºó´æ·ÅÔÚ¡°.bss¡±µÄ×ÊÔ´½ÚÊý¾ÝÖÓ×£¡£¡£¡£¡£Í¨¹ý¶Ô½âÃܺ¯ÊýµÄ·ÖÎöÎÒÃÇ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÀïѡȡÁËCR4Ëã·¨¡£¡£¡£¡£¡£CR4ÌìÉúÒ»ÖÖ³ÆÎªÃÜÔ¿Á÷µÄÎ±Ëæ»úÁ÷£¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇͬÃ÷ÎÄͨ¹ýÒì»ò²Ù×÷Ïà»ìºÏÀ´´ïµ½¼ÓÃܵÄÖ÷ÕÅ¡£¡£¡£¡£¡£½âÃÜʱÔòʹÓÃÃÜÔ¿µ÷¶ÈËã·¨(KSA)À´ÊµÏÖ¶Ô´óÓ×Ϊ256¸ö×Ö½ÚÊý×ésboxµÄ³õʼ»¯¼°´úÌæ¡£¡£¡£¡£¡£¾ßÌåÁ÷³ÌÈçÏ£º
(ÔÚ×ÊÔ´Êý¾ÝÖÐǰ0x32¸ö×Ö½ÚÊÇÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓà0x68¸ö×Ö½ÚÔòÊÇ´ý½âÃܵÄÊý¾Ý)
ÃÜÔ¿ºÍ´ý½âÃÜÊý¾Ý
4£©´úÌæºóµÄsboxÊý×éÖеÄÊýÖµÈçÏÂͼ£º
5£©Í¨¹ý´úÌæºóµÄsboxºÍ´ý½âÃܵÄÊý¾Ý½øÐÐXORÔËËãºó£¬£¬£¬£¬£¬£¬£¬£¬×îÖյõ½·þÎñÆ÷µÄhostµØÖ·"asdfwrkhl.warzonedns[.]com"¡£¡£¡£¡£¡£
Ö´ÐÐ×¢ÈëÖ°ÄÜ
½Ó×Å£¬£¬£¬£¬£¬£¬£¬£¬¸ÃľÂíʹÓÃÔ¶³ÌÏ̵߳ķ½Ê½À´×¢ÈëÖ÷ÌâÖ°ÄÜShellcode´úÂ룬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÆô¶¯Ô¶Ïß³ÌÖ´ÐÐʱ£¬£¬£¬£¬£¬£¬£¬£¬Åú¸ÄдÈëÖ¸±ê¹ý³ÌÄÚ´æÆ«ÒÆµÄ0x10E´¦ÎªÆðÍ·Ö´ÐдúÂë¡£¡£¡£¡£¡£
ͨ¹ý¶ÈÎöÎÒÃÇ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Õâ¶Î×¢Èë´úÂëµÄÖØÒªÖ°ÄÜÊÇÀûÓÿþÀܹý³ÌÀ´±£»£»£»£»£»¤Dropper(hqpi64.exe)¡£¡£¡£¡£¡£Æä»á°´Ê±²é³DropperÊÇ·ñ´¦ÓÚÔËÐÐ״̬£¬£¬£¬£¬£¬£¬£¬£¬Èç±»¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬Ôò³ÁÐÂÆô¶¯¡£¡£¡£¡£¡£ÒÔ´Ë´ïµ½¹ý³ÌÊØ»¤µÄÖ÷ÕÅ¡£¡£¡£¡£¡£
¹ý³ÌÊØ»¤Ö°ÄÜ
ͨѶºÍ̸½âÎö
1£©ÏνӷþÎñÆ÷
2£©½âÃܽÚÔì°ü
3£©Ö´ÐнÚÔìÖ¸Áî
ͨ¹ýÎÒÃÇÇ°ÃæµÄ·ÖÎöÄܹ»¿´µ½£¬£¬£¬£¬£¬£¬£¬£¬¸ÃľÂí½ÚÔìÖ¸ÁîÖÐÔ̺¬ÁË´óÁ¿Óû§ÒþÖÔÐÅÏ¢µÄÇÔȡְÄÜ¡£¡£¡£¡£¡£×îÖÕÊܺ¦ÕßµÄÃô¸ÐÊý¾ÝÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬³ÇÊÐÆ¾¾ÝÔ¶³Ì·þÎñÆ÷µÄÖ¸Áî»Ø´«¸øÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£
½ÚÔìÖ¸ÁîÖ°ÄÜ
|
½ÚÔìºÅÁî |
Ö¸ÁîÖ°ÄÜ |
|
0x01~0x04 |
ŲÓÃ×Ô½ç˵º¯Êý£¬£¬£¬£¬£¬£¬£¬£¬²¢½«Ö´ÐÐÁ˾ֻش«·þÎñÆ÷ |
|
0x02 |
ÉÏ´«¹ý³ÌÁбí |
|
0x04 |
»ñÈ¡ÍÆËã»úÂß¼´ÅÅÌÐÅÏ¢ |
|
0x06 |
ÉÏ´«ÎļþÁбíÐÅÏ¢ |
|
0x08 |
ÏÂÔØ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþ |
|
0x10 |
ʵÏÖ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄ¹ý³Ì |
|
0x0E |
Remote Shell |
|
0x10 |
È¡µÞÏÂÔØ |
|
0x12 |
»ñÈ¡Webcam DevicesÁбí |
|
0x14 |
Start Webcam |
|
0x16 |
Stop Webcam |
|
0x18 |
·¢ËÍÐÄÌø°ü |
|
0x1A |
Ð¶ÔØ¿Í»§¶Ë |
|
0x1C |
Åú¸Ä½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþ |
|
0x1E |
ÏÂÔØVNCÄ£¿£¿£¿£¿£¿£¿£¿£¿é |
|
0x20 |
ÇÔÈ¡Google Chrome¡¢Mozilla FireFoxµÈä¯ÀÀÆ÷ºÍOutLook¡¢Thunderbird¡¢FoxmailÓÊÏäÖб£ÁôµÄƾ֤ÐÅÏ¢ |
|
0x22 |
ÏÂÔØ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþÁ´½Ó²¢Ö´ÐÐ |
|
0x24 |
ƾ¾Ý½ÚÔìÖ¸Á£¬£¬£¬£¬£¬£¬£¬Çл»Á½ÖÖ·½Ê½À´¼Í¼¼üÅÌʹÓÃÐÅÏ¢ |
|
0x26 |
ʹÓÃÈ«¾ÖÐÂÎŹ³×Ó£¬£¬£¬£¬£¬£¬£¬£¬¼Í¼¼üÅÌʹÓÃÐÅÏ¢ |
|
0x28 |
Remote VNC×°ÖÃ |
|
0x2A |
²âÊÔ±¾»úµÄÍøÂçÏνÓÖ°ÄÜ |
|
0x2C |
¶Ï¿ªÔ¶³Ì·þÎñÆ÷ |
|
0x38 |
δ֪²âÊÔ |
|
other |
»ñÈ¡Óû§Ãû£¬£¬£¬£¬£¬£¬£¬£¬ÏµÍ³°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬GUIDµÈÐÅÏ¢ |
1£©ÇÔȡƾ֤ÐÅÏ¢
ÇÔÈ¡µÄÐÅÏ¢Ô̺¬Google Chrome¡¢Mozilla FirefoxµÈä¯ÀÀÆ÷ºÍOutlook¡¢Thunderbird¡¢FoxmailÓÊÏä¿Í»§¶Ë±£ÁôµÄƾ֤ÐÅÏ¢µÈ¡£¡£¡£¡£¡£
¸ÃľÂí»ñÈ¡ÓÐ¹ØÆ¾Ö¤ÐÅÏ¢ÒÔ¼°ÊµÏÖ²½ÖèÈçϱíËùʾ£º
|
ÇÔÈ¡µÄƾ֤ÐÅÏ¢ |
ʵÏÖ²½Öè |
|
Google Chrome |
¶ÁÈ¡\AppData\Local\Google\Chrome\User Data\Default\ Login DataÊý¾Ý¿âÎļþ½øÐвéÎÊ |
|
Mozilla Firefox |
¶ÁÈ¡ÅäÖÃõ辶ϵÄsignons.sqliteÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýnss3.dll½âÃÜ |
|
Outlook |
±éÀú×¢²á±íSoftware\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesÏÂ×Ó¼ü½øÐмø±ð²¢½âÃÜ |
|
Thunderbird |
¶ÁÈ¡\AppData\Roaming\Thunderbird\ProfilesĿ¼ÏµÄÊý¾Ý¿âÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÀûÓ÷¨Ê½Ä¿Â¼ÏµÄnss3..dll¶Ô´æ´¢µÄÃÜÂë½øÐнâÃÜ |
|
Foxmail |
¶ÁÈ¡ÓÊÏäĿ¼ÏµÄ\\Account\\Account.rec0Îļþ²¢½øÐнâÃÜ |
a£©ÌáÈ¡Chromeƾ֤
´Ó¸Ã±íÖжÁÈ¡µÄÄÚÈÝÊǼÓÃܵ쬣¬£¬£¬£¬£¬£¬£¬Í¨¹ýCryptUnProtectDataº¯Êý¶ÔÆä½øÐнâÃܱãÄܹ»»ñÈ¡µ½Ã÷ÎÄÊý¾Ý¡£¡£¡£¡£¡£×îºó¸ÃľÂí½«½âÃܺóµÄÊý¾Ý±£ÁôÔÚÃûΪ¡±xxx.tmp¡±£¨¡±xxx¡°ÎªBase64½âÂë³öµÄ×Ö´®£©µÄһʱÎļþÖÓ×£¡£¡£¡£¡£
b£©ÌáÈ¡Mozillaƾ֤ÐÅÏ¢
Óû§ÃûºÍÃÜÂë
c£©OutLookƾ֤»ñÈ¡
»ñÈ¡OutlookÓÊÏäµÄÓû§ÐÅÏ¢
d£©Thunderbirdƾ֤»ñÈ¡
e£©FoxMailƾ֤»ñÈ¡
f£©ÉÏ´«»ñÈ¡µ½µÄƾ֤ÐÅÏ¢
2£©¼üÅ̼ͼ
b£©Ò»Ê±¼üÅ̼ͼ
°´¼üºÍ´°¿ÚÃûÐÅÏ¢µÄ»ñÈ¡
3£©RemoteVNC×°ÖÃ
a£©½«ÐÂÓû§Ôö³¤µ½¡±Ô¶³Ì×ÀÃæÓû§¡±×é
Ôö³¤²¢°µ²Ø´´½¨µÄÐÂÕË»§
b£©¸ü¸ÄÔ¶³Ì×ÀÃæÉèÖÃ
ͨ¹ý¶ÈÎöÎÒÃÇ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬´ËRATµÄÔ¶³Ì×ÀÃæÖ°ÄÜÊÇͨ¹ýÌØÔìµÄVNCÄ£¿£¿£¿£¿£¿£¿£¿£¿éÀ´ÊµÏֵġ£¡£¡£¡£¡£²¢ÇÒÔÚºóÐøµÄ¸üа汾ÖУ¬£¬£¬£¬£¬£¬£¬£¬»¹Ôö³¤ÁËHRDPÄ£¿£¿£¿£¿£¿£¿£¿£¿éÀ´ÊµÏÖ°µ²ØÔ¶¿Ø×ÀÃæ¡£¡£¡£¡£¡£¸ÃHRDPÄ£¿£¿£¿£¿£¿£¿£¿£¿éʹÓÃÁËGithubÉϵÄrdpwrapÏîÄ¿£¬£¬£¬£¬£¬£¬£¬£¬²»½öÄܹ»ÔÚºó¶ÜµÇ¼Զ³ÌÍÆËã»ú£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ´´½¨µÄWindowsÕË»§»¹»á×Ô¶¯°µ²Ø¡£¡£¡£¡£¡£
4£©È¨ÏÞÉý¼¶£¨UACÈÆ¹ý£©
¸ÃľÂíµÄȨÏÞÌáÉýÊÇÀûÓÃÁË×Ô¶¯ÌáÉýȨÏ޵ĺϷ¨ÀûÓ÷¨Ê½¡±pkgmgr.exe¡±À´Ö´ÐÐDISPÄ£¿£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£ÆäÖ°ÄÜ´úÂëʵÏÖÊÇѡȡÁËBypass-UAC¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¿ò¼ÜÄܹ»Í¨¹ýŲÓÃIFileOpertion COM¶ÔÏóËùÌṩµÄ²½ÖèÀ´ÊµÏÖ×Ô¶¯ÌáȨ¡£¡£¡£¡£¡£
¸ÃľÂíÏȽ«Ç¶ÈëÔÚ×ÊÔ´Êý¾ÝÖеÄPEÎļþÔÚÄÚ´æÖмÓÔØ²¢ÔËÐÓ×£¡£¡£¡£¡£¶ø´ËPEÎļþÏÖʵÉÏÊÇÒ»¸ö¼ÓÔØÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäËù×öµÄʼþÔòÊǽ«×ÊÔ´ÖеÄÁíÒ»¸öPEαÔìΪ¡°dismcore.dll¡±£¬£¬£¬£¬£¬£¬£¬£¬¶øºó½«´Ëdll¸´Ôìµ½System32Ŀ¼Ï£¬£¬£¬£¬£¬£¬£¬£¬×îºóʹÓÃpkgmgr.exeÖ´ÐÐαÔìµÄ¶ñÒâDLL¡£¡£¡£¡£¡£ÓÉÓÚpkgmgr.exeÊÇÒ»¸öUAC°×Ãûµ¥·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ËùÒÔËüĬÈÏÓµÓÐÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒ²»»áµ¯³öUACÌáÐÑ¿ò¡£¡£¡£¡£¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ£º
´Ë¶ñÒâDLLµÄÖØÒªÖ°ÄÜÊÇ»ñȡע²á±íÖеġ±Install¡±×°ÖÃÐÅÏ¢(DropperµÄõè¾¶)²¢³ÁÐÂÆô¶¯ÓµÓÐÖÎÀíԱȨÏÞµÄDropperйý³Ì¡£¡£¡£¡£¡£
5£©Î´Öª²âÊÔ
ÔÚÐÂÏß³ÌÖУ¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝÔ¶³Ì·þÎñÆ÷·¢Ë͵ÄÖ¸Á£¬£¬£¬£¬£¬£¬£¬ÓëÐÂÖ¸¶¨µÄC&C½øÐÐÏνӡ£¡£¡£¡£¡£
ÓÉÓÚ½Ó¹ÜÊý¾ÝÎÞ·¨»ñÈ¡£¬£¬£¬£¬£¬£¬£¬£¬ËùÒÔĿǰÎÒÃÇÎÞ·¨È·¶¨ÆäÕýÈ·Óô¦£¬£¬£¬£¬£¬£¬£¬£¬Ôݽ«Æä¶¨ÃûΪδ֪²âÊÔ¡£¡£¡£¡£¡£
3.2 ×îй¥»÷Ñù±¾
½×¶ÎÒ»£º
½âÃܺ¯Êýmethod_0ÈçÏÂͼËùʾ£º
ÔÚ¾¹ýÄæÐò·ÖÁкÍBase64½âÂëºóµÄ×Ö·û´®£¨byte_0£©ÖУ¬£¬£¬£¬£¬£¬£¬£¬Ç°16λΪ½âÃÜÃÜÔ¿¡°0x28 0x49 0xf7 0x30 0xec 0x8d 0x500x80 0x94 0xaf 0x85 0xaa 0xa8 0xe7 0xc0 0x41¡±,Ö®ºóΪ´ý½âÃÜÃÜÎÄ¡£¡£¡£¡£¡£º¯ÊýÒÔ16λΪѻ·,½«ÃÜԿͬÃÜÎÄ˳´Î½øÐа´Î»Òì»ò£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ½âÃܵõ½¡°DUMP1¡±Îļþ²¢Í¨¹ýCallByNameº¯Êý¼ÓÔØÖ´ÐÓ×£¡£¡£¡£¡£
½×¶Î¶þ£º
¡°DUMP1¡±ÎļþͬÑùѡȡC#±àд£¬£¬£¬£¬£¬£¬£¬£¬·¨Ê½Ê×ÏÈ»á˯Ãß50ÃëÒÔ¶ã±ÜɳÏä²é³£¬£¬£¬£¬£¬£¬£¬£¬Ö®ºó»á¼ì²âµ÷ÊÔÆ÷²¢½«×ÔÉí¿ªÊÍÖÁ¡°%ApplicationData%\riNpmWOoxxCY.exe¡±£¬£¬£¬£¬£¬£¬£¬£¬½Ó×Å´´½¨schtasks.exe¹ý³Ì²¢Ôö³¤´òË㹤×÷¡°Updates\riNpmWOoxxCY¡±£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµ´Ë¿ÌµÇ¼ÕË»§Ê±×ÔÆô¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÓйغÅÁîÈçÏ£º
"C:\Windows\System32\schtasks.exe/Create/TN Updates\riNpmWOoxxCY/XMLC:\Users\super\AppData\Local\Temp\tmp925C.tmp"
Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬·¨Ê½»á´Ó×ÔÉí×ÊÔ´ÄÚ½âÃܳöPEÎļþ¡°DUMP2¡±£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýCreateProcess¡¢WriteProcessMemoryºÍSetThreadContextµÈº¯Êý£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¹ÒÆðµÄ·½Ê½¼ÓÔØÒ»¸öеĹý³Ì£¬£¬£¬£¬£¬£¬£¬£¬²¢×îÖÕÒÔ¿þÀܹý³ÌµÄ·½Ê½Ð´Èë²¢¼ÓÔØ¡°DUMP2¡±¡£¡£¡£¡£¡£
¾¹ý¶ÈÎö£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÔÚ¡°DUMP2¡±Öз¢ÏÖÁËһЩ¿ÉÒÉ×Ö·û´®È磺¡°Remcos¡±¡¢¡°Remcos_Mutex_Inj¡±¡¢¡°2.3.0 Pro¡±¡£¡£¡£¡£¡£
ÆäÃâ·Ñ°æ½ö¿ÉÔö³¤Ò»¸öC2ÏνӷþÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬×¨Òµ°æÔòûº±¼ûÁ¿ÏÞ¶È¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÖÐÖ²ÈëµÄľÂíÊÇͨ¹ýרҵ°æÌìÉúÇÒÏνÓÖÁ¶à¸ö¶ñÒâC2£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬µÄC2µØÖ·ÌáÈ¡ÈçÏ£º
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
4¶ñÒâ´úÂëËÝÔ´Óë¹ØÁª
4.1 ¶ñÒâ´úÂëËÝÔ´×·×Ù
ǰÎÄÔøÌáµ½£¬£¬£¬£¬£¬£¬£¬£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÖÐÔ̺¬ÁË¡°AVE_MARIA¡±Ìصã×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬ÇÒ×Ô2018Äê12ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾ÔÚtwitter¡¢virustotalµÈƽ̨ԽÀ´Ô½¶àµÄ±»·¢ÏÖ¡£¡£¡£¡£¡£µ«¶àƪÓйØ×êÑÐÎÄÕ¾ùδָ³öÆäÕæÊ·´Ô´£¬£¬£¬£¬£¬£¬£¬£¬É±¶¾³§ÉÌÒ²¿í·ºµÄ½«Æä¶¨ÃûΪAVE_MARIA£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒýÆðÁËÎÒÃÇŨÃܵÄÐËÖ¡£¡£¡£¡£¡£
ÎÒÃdz¢ÊÔ´Ó¶àÖֽǶÈÈ¥ËÝԴľÂíÒÔѰÕÒÏßË÷£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓòÃû¡¢IP¡¢¹ØÁªÑù±¾µÈµÈ¡£¡£¡£¡£¡£ÆäÖÐÔÚ¶Ô¹ØÁªÑù±¾¡°Michelle Flores - Curriculum Actualizado.doc¡±µÄ·ÖÎöÖгɹ¦ËÝÔ´µ½ÁËÉÌÓÃÈí¼þRemcos RAT¡£¡£¡£¡£¡£ÎÒÃÇ·ÖÎöÁ˸ÃÈí¼þµÄ°ä²¼Çþ·£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìä²»½öÔÚ¹ÙÍø½øÐÐÏúÊÛ£¬£¬£¬£¬£¬£¬£¬£¬»¹ÔÚÖî¶àºÚ¿ÍÂÛ̳ÈçHackforumsÉÏ´óÁ¿ÊÛÂô¡£¡£¡£¡£¡£ÓÉ´Ë£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃDz²⹥»÷ÈËÔ±ºÜ¿ÉÄÜ»îÔ¾ÔÚÓйØÂÛ̳²¢²É°ì¹ý¶à¿îÉÌÓÃÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ò²½«ËÝÔ´³ÁµãתÏòºÚ¿ÍÂÛ̳ºÍ°µÍøÊг¡¡£¡£¡£¡£¡£
SolmyrÔÚÂÛ̳ÖÐÌṩÁËwarzonedns.comÓòÃûµÄÃâ·ÑDDNS·þÎñ£¨IP¶¯Ì¬°ó¶¨ÖÁ×ÓÓòÃû£©£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÓû§Äܹ»µÈÏеĽ«·þÎñÆ÷IP°ó¶¨½âÎöÖÁwarzonedns.comϵÄËÁÒâ×ÓÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃʾÀýÈçÏ£º
ÕâÎÞÒɸøºÚ¿ÍÌṩÁ˺ܺõIJØÉíÖ®Ëù£¬£¬£¬£¬£¬£¬£¬£¬Óë´ËͬʱÎÒÃÇ·¢ÏÖSolmyrµÄÁíÒ»¸öÉí·ÝÊÇWARZONE RATµÄ°ä²¼Õߣ¬£¬£¬£¬£¬£¬£¬£¬¸ÃÈí¼þÓÉÓÚ½ÚÔ켿Á©·á˶¡¢¼¼ÊõÖ°ÄÜ׳´ó¡¢µü´ú¸üÐÂѸËÙ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÔÚHackforumsÂÛ̳Öм«¶ÈÊÜ»¶Ó¡£¡£¡£¡£¡£
ÖÁ´Ë£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÓÐÀíÓÉÒɻ󹥻÷ÕßʹÓùý¸Ã¿îÉÌÓÃÔ¶³ÌÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÈí¼þ¹ØÔ´ÇÒ²»ÌṩÃâ·Ñ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ×·Òäµ½ÁËWARZONE RATÁ÷³öµÄÆÆ½â°æ±¾£¨V1.31£©£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓë¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÑù±¾½øÐÐͬԴÐÔ·ÖÎö,ÒÔÈ·¶¨¶þÕß¼äµÄ¹ØÁª¡£¡£¡£¡£¡£
4.2 ͬԴÐÔ·ÖÎö
Æä´Î£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇͨ¹ýBindiff½øÐÐÁ˸üΪ¾«È·µÄ¶Ô±È£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÈ¥³ý²¿ÃÅAPI×ÌÈŲ¢±ÈÁ¦·ÖÎöÁË¿ÉÐŶȸߵĺ¯Êýºó£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖ´óÁ¿º¯ÊýÆëȫһÑù£¬£¬£¬£¬£¬£¬£¬£¬Õ¼±È´ïµ½80.16%£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓຯÊýÔò¿ÉÄÜÓÉÓÚ°æ±¾ÔÒòÂÔÓвî¾à£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ²Ó¡Ö¤Á˶þÕß¼äµÄÇ¿¹ØÁªÐÔ¡£¡£¡£¡£¡£
Áí±í,´Ó´«²¼¹¦·òµÄ½Ç¶È·ÖÎö,¡°AVE_MARIA¡±¹ØÁªÑù±¾×î³õ³öÏֵŦ·ò(2018Äê12ÔÂ2ÈÕ)ÂÔÍíÓÚWarzoneRATÔÚÂÛ̳µÄ°ä²¼¹¦·ò(2018Äê10ÔÂ22ÈÕ)£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ²Çк϶ñÒâ´úÂë´«²¼µÄ¹¦·òÂß¼¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉϼ¸µã·ÖÎö£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÒÔΪÁ½ÕßÓµÓи߶ȵÄÒ»ÖÂÐÔ¡£¡£¡£¡£¡£´ÓĿǰÒÑÖªµÄÇé¿ö¿´£¬£¬£¬£¬£¬£¬£¬£¬WARZONE±»É±¶¾³§ÉÌ¿í·ºµÄ¼ø±ðΪAVE_MARIA£¬£¬£¬£¬£¬£¬£¬£¬¶øÔÚÉî¿Ì±È¶Ô·ÖÎöºó£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÅж¨ºÚ¿Í×é֯ʹÓõÄÔ¶¿ØÄ¾ÂíÕýÊÇWARZONE RAT¡£¡£¡£¡£¡£Òò¶øÄܹ»½«´ËÀàÔ̺¬¡°AVE_MARIA¡±×Ö·û´®µÄ¶ñÒâÑùͬ×Ú×嶨Ãû¸üÐÂΪ¡°WARZONE¡±¡£¡£¡£¡£¡£
4.3 ÓòÃû¹ØÁª
ÕâÅúÓòÃû¾ùΪwarzonedns.comÌṩµÄÃâ·Ñ×ÓÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬ÇÒ´ó²¿ÃŹØÁªÖÁ¶ñÒâÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢´óÁ¿ºÚ¿ÍÔÚÀÄÓôËÀà·þÎñ½øÐжñÒâ¹¥»÷¡£¡£¡£¡£¡£
5×Ü ½á
±¾ÎĶԱ¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Á÷³Ì¡¢ÓйصĶñÒâ´úÂë¡¢ºÚ¿Í²¼¾°µÈ×öÁËÉî¿ÌµÄ·ÖÎöºÍ×êÑУ¬£¬£¬£¬£¬£¬£¬£¬´ÓÉÏÎĵķÖÎöÖÐÎÒÃÇÄܹ»¿´³ö¸ÃºÚ¿Í×é֯ĿǰµÄ¹¥»÷»î¶¯¼«¶ÈÉóÉ÷£¬£¬£¬£¬£¬£¬£¬£¬¼ÈûÓдó¹æÄ£µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐѡȡ¸ß³É±¾µÄ0day·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷»î¶¯¹¦·òÒ²¼«¶È¶Ì¡£¡£¡£¡£¡£ÕâÅú×¢¸Ã¹¥»÷»î¶¯»¹´¦ÓÚ³õÆÚ£¬£¬£¬£¬£¬£¬£¬£¬²¢¶ÔÖ¸±ê½øÐÐÁËһЩÊÔ̽ÐÔ¡¢Õë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ò²ÎªºóÐøµÄ¹¥»÷×öºÃ³ï±¸¡£¡£¡£¡£¡£´Ë±íͨ¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÈ·¶¨Á˸ôλ±³ºóµÄºÚ¿Í×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬²¢Æ¾¾Ý¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯º¹Ç࣬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäÃñ×åÖ÷ÒåÉ«²ÊÇ¿ÁÒ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÕþÖÎÖ÷ÕÅÒâͼҲ½ÏΪÏÔÖø¡£¡£¡£¡£¡£
IOC
|
MD5 |
|
99C82F8A07605DA4CCC8853C910F7CAF |
|
048DCA20685ECD6B7DBDBF04B9082A54 |
|
DEF105A9452DEF53D49631AF16F6018B |
|
1E19266FC9DFF1480F126BD211936AAC |
|
262D9C6C0DC9D54726738D264802CCAD |
|
B3C9F98DD07005FCCF57842451CE1B33 |
|
497566120F1020DBD6DF70DD128C0FFB |
|
ÓòÃû |
|
linksysdatakeys[.]se |
|
gestomarket[.]co |
|
asdfwrkhl.warzonedns[.]com |
|
casillas.hicam[.]net |
|
casillasmx.chickenkiller[.]com |
|
casillas.libfoobar[.]so |
|
du4alr0ute.sendsmtp[.]com |
|
settings.wifizone[.]org |
|
wifi.con-ip[.]com |
|
rsaupdatr.jumpingcrab[.]com |
|
activate.office-on-the[.]net |


¾©¹«Íø°²±¸11010802024551ºÅ