Õë¶ÔÔìÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷»î¶¯Éî¶È·ÖÎö
°ä²¼¹¦·ò 2019-11-07½üÆÚ£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab·¢ÏÖ´óÁ¿Ê¹ÓøßΣ·ì϶CVE-2017-11882½øÐÐÍøÂç¹¥»÷µÄÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»Åú¹¥»÷ÔØºÉÒýÆðÁË8827Ì«Ñô¼¯ÍŰÑÎÈ£¬£¬£¬£¬£¬£¬£¬ËûÃǾùÒÔÀàËÆ¡°¸¶¿îÊÕÌõ¡±¡¢¡°ÒøÐÐÈ·ÈÏ¡±µÈ×ÖÑù×÷Ϊ¹¥»÷ÔØºÉÃû³Æ¡£¡£¡£¡£¡£¸ÃÅú¹¥»÷ÔØºÉ´ó²¿ÃÅͨ¹ýÓʼþ¸½¼þµÄ·½Ê½½øÐд¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÔÚ·ÖÎö¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÁ˺ڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÓйØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬´ËÅúºÚ¿ÍÒѾ³É¹¦ÉøÈë½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÔìÒ©ÆóÒµ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Î÷°àÑÀÈ·µ±¾Ö¡¢ÆóÊÂÒµµ¥ÔªµÈ»ú¹¹£¬£¬£¬£¬£¬£¬£¬²¢ÇÒµÁÈ¡ÁË´óÁ¿µÄÃô¸Ðµý±¨¡£¡£¡£¡£¡£ÎÒÃÇͨ¹ýËÝÔ´·ÖÎöÈ·¶¨Õâ´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓɵ±Ç°¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£¡£¡£¡£¡£Í¨¹ý¶Ô¸ÃÅúÑù±¾µÄ·ÖÎö·¢ÏÖÕâ´Î¹¥»÷»î¶¯×îÔç¿É×·Òäµ½2019Äê7Ô£¬£¬£¬£¬£¬£¬£¬½ØÖÁĿǰ£¬£¬£¬£¬£¬£¬£¬ÓйصÄÉèÊ©ÒÀÈ»ÔÚʹÓÃÖв¢³ÖÐøÔÚÍøÂçµý±¨ÐÅÏ¢¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯»¹¹¥ÏÂÁËÎ÷°àÑÀÒ»¼Ò´óÐÍ´¬²°ÖÎÀí¹«Ë¾µÄ¹Ù·½ÍøÕ¾×÷Ϊµý±¨ÇÔÈ¡µÄ°ÂÃØ»Ø´«µã£¬£¬£¬£¬£¬£¬£¬ÊÔͼ°µ²Ø×ÔÉíÉí·Ý¡£¡£¡£¡£¡£
ÔÚ±¾´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬ºÚ¿Í×é֯ͨ¹ýÓʼþ½«¾«ÐÄ»ú¹ØµÄOfficeÎļþ£¨Õë¶ÔCVE-2017-11882·ì϶Ôì×÷µÄ£©×÷Ϊ¸½¼þ·¢Ë͸øÖ¸±êÓÊÏ䣬£¬£¬£¬£¬£¬£¬²¢ÓÕʹÊܺ¦Õßµã»÷ÒÔÇÖÈëÖ¸±êϵͳ£¨¹ÌÈ»ÕâÖÖÒÔÉ繤´ó¾ÖÕÒµ½Ö¸±êÓÊÏ䲢ͨ¹ýÓʼþµÄ·½Ê½½øÐй¥»÷µÄÊÖ·¨ÀÏÌ×£¬£¬£¬£¬£¬£¬£¬µ«È´ÊǺڿÍ×î³£ÓõĹ¥»÷ÊÖ·¨Ö®Ò»£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½áºÏÉ繤ÐÅϢαÔìµÄÓʼþÒ²ÓµÓкܸߵijɹ¦ÂÊ, ²¿ÃÅÐÐÒµºÍÆóÊÂÒµµ¥ÔªÓÉÓÚδ½øÐÐÓйطì϶²¹¶¡¸üжøÒ×Êܵ½¹¥»÷£©¡£¡£¡£¡£¡£¹¥»÷ÔØºÉ»áƾ¾ÝµØÀíµØÎ»µÄ·ÖÆç¶øÔÚÊܺ¦ÕßµçÄԸߵÍÔØ²¢×°ÖÃAgent Tesla¡¢HawEye Keylogger¡¢NanoCore RAT»òNetWire RATµÈ¶à¿î¼äµýľÂí£¬£¬£¬£¬£¬£¬£¬ÒÔ¶Ô¹¥»÷Ö¸±êÖ´ÐÐ³Ö¾ÃµÄ¼à¿Ø½ÚÔì¡¢Ãô¸ÐÐÅÏ¢ÇÔÈ¡µÈ¶ñÒâÐÐΪ¡£¡£¡£¡£¡£
±¾ÎĽ«¶ÔºÚ¿Í×éÖ¯ËùÖ´ÐеĹ¥»÷¹ý³Ì½øÐоßÌ嵨·ÖÎöºÍËÝÔ´£¬£¬£¬£¬£¬£¬£¬²¢¶ÔÆäËùʹÓõļäµýÈí¼þºÍ»ù´¡ÉèÊ©½øÐÐ͸±ÙµØ·ÖÎö¡£¡£¡£¡£¡£
1¡¢¹¥»÷¹ý³Ì·ÖÎö
Õâ´Î¹¥»÷ʼÓÚÒ»¸öЯ´øCVE-2017-11882·ì϶µÄEXCELÎĵµ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓüÙ×°³É¡°ÒøÐÐÈ·ÈÏ¡±µÄ´¹µöÓʼþ·¢Ë͸ø¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬µ±Óû§´ò¿ªÎĵµºó±ã»áÖ´ÐÐshellcode´úÂ룬£¬£¬£¬£¬£¬£¬²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷¸ßµÍÔØPayload²¢Ö´ÐС£¡£¡£¡£¡£¸ÃPayload»áÔÚÄÚ´æÖнâÃܳöеÄPE²¢×¢È뵽ϵͳ¹ý³ÌRegAsm.exeÖУ¬£¬£¬£¬£¬£¬£¬³É¹¦×¢Èëºó±ãÆðÍ·½øÐÐʵʱ¼à¿Ø¡¢ÇÔÃܵÈÐÐΪ£¬£¬£¬£¬£¬£¬£¬×îÖÕ½«ÇÔÈ¡µ½µÄÓû§ÐÅÏ¢»Ø´«µ½ÍйܷþÎñÆ÷¡£¡£¡£¡£¡£
1.1 ¹¥»÷Á÷³Ì
ÏÂͼչʾÁËÕâ´Î¹¥»÷»î¶¯ÆëÈ«µÄÁ÷³Ì£º
ͼ1 ¹¥»÷Á÷³Ìͼ
1.2 ¹¥»÷Ö¸±ê
±»¹¥»÷¹«Ë¾ÐÅÏ¢¼°ÓйØÓʼþ1£º
´¹µöÓʼþÊÇ·Ö·¢µ½µÂ¹úµÄÒ»¼Ò¼Ò×åÆóÒµ¹«Ë¾¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÊÇרÃÅ×êÑж¯Ö²ÎïÔÁϵÄÌáÈ¡£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÒµÎñÊÇ×êÑÐÔìÒ©¡¢»¯×±Æ·ºÍÉúÎïµÈ¼¼Êõ¡£¡£¡£¡£¡£
ͼ2 Ö¸±ê¹«Ë¾1
ͨ¹ýͼ2Äܹ»¿´µ½£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»´Ó¸Ã¹«Ë¾µÄÖ÷Ò³ÉÏ»ñÈ¡ÓÊÏ䵨ַ£¬£¬£¬£¬£¬£¬£¬²¢½«×ÔÉí¼Ù×°³É¡°¸¶¿îÈ·ÈÏ¡±µÈ֪ͨÓʼþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õß´ò¿ª¸½¼þÎĵµ¡£¡£¡£¡£¡£
ͼ3 ´¹µöÓʼþ1
±»¹¥»÷¹«Ë¾ÐÅÏ¢¼°ÓйØÓʼþ2£º
ÁíÒ»ÃûÊܺ¦ÕßÊǵ¹úµÄÒ»¼ÒÒ½ÁÆÒ©Æ·Æ÷е¹«Ë¾¡£¡£¡£¡£¡£¸ÃÊÕ¼þÓÊÏäµØÖ·Í¬Ñù¿ÉÔÚÆä¹ÙÍøÉÏ»ñÈ¡¡£¡£¡£¡£¡£
ͼ4 Ö¸±ê¹«Ë¾2
·¢Ë͸øÖ¸±ê¹«Ë¾µÄ´¹µöÓʼþʾÀýÈçÏÂͼ£º
ͼ5 ´¹µöÓʼþ2
Á½Æð´¹µöÓʼþµÄ¸½¼þ¾ùÊÇÃûΪ¡°bank cconfirmation¡±µÄXLSXÎĵµ£¬£¬£¬£¬£¬£¬£¬¶ø¸Ã¸½¼þÎļþÊÇÎÒÃDz¶»ñµÄ¶à¶àʹÓÃCVE-2017-11882·ì϶µÄ¶ñÒâÎĵµÖ®Ò»¡£¡£¡£¡£¡£
1.3 µö¶üÓʼþ
Á½·âÓʼþµÄÄÚÈÝ¡¢·¢¼þÈËÒÔ¼°¶ñÒâÎĵµµÄÃû³Æ£¬£¬£¬£¬£¬£¬£¬¾ùά³Öן߶ȵÄÒ»ÖÂÐÔ¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«¶ÔÓʼþÐÅÏ¢×ö½øÒ»²½µÄ·ÖÎö£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÍÚ¾ò³ö¸ü¶àµÄ¹ØÁªÏßË÷¡£¡£¡£¡£¡£
ͨ¹ý¶ÔÓʼþÐÅÏ¢½øÐнâÎöÄܹ»¿´µ½Èçͼ6Ëùʾ£¬£¬£¬£¬£¬£¬£¬·¢¼þµØÖ·ÀïÁгöµÄÏÖʵµç×ÓÓʼþµØÖ·Îª¡±mana00.balaempre.com¡±¡£¡£¡£¡£¡£Æ¾¾ÝÓÊÏäºó׺Ãû½øÐвéÎÊ£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäËù¶ÔÓ¦µÄÊÇÒ»¿îÃûΪ¡°AutoPMTA¡±µÄ×Ô¶¯»¯µç×ÓÓʼþ·Ö·¢·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¹ú±íµÄÍøÕ¾ÖÐÆ¾¾Ý¾ßÌåÖ°ÄÜÊÕÈ¡·ÖÆçµÄÓöȡ£¡£¡£¡£¡£ÓÉ´ËÎÒÃÇ´§Ä¦ºÚ¿Í×éÖ¯¾ÍÊÇÀûÓô˿îÈí¼þÀ´½øÐÐÓÊÏ䵨ַµÄÍøÂçºÍÓʼþµÄÅúÁ¿·Ö·¢¡£¡£¡£¡£¡£
ͼ7 AutoPMTAÓʼþ·Ö·¢Æ÷
¶øÔÚÁíÒ»·âÓʼþÖУ¬£¬£¬£¬£¬£¬£¬ÎÒÃdzõ´Î·¢ÏÖÁËÒ»¸öÊôÓÚÄáÈÕÀûÑǵÄÔ¶³ÌIPµØÖ·£¬£¬£¬£¬£¬£¬£¬¸ÃÏßË÷µÄ³Ê´Ë¿ÌºóÐøµÄ¹ØÁªËÝÔ´ÖÐÆð×ųÁÒªµÄ×÷Ó㬣¬£¬£¬£¬£¬£¬ÔÚÕâÀïÏȽ«Æä¼Í¼ÏÂÀ´¡£¡£¡£¡£¡£
ͼ8 IPµØÖ·²éÎÊÐÅÏ¢
2¡¢Ñù±¾·ÖÎö
2.1 ¶ñÒâÎĵµ
ÔÚ佨¸´CVE-2017-11882·ì϶µÄÍÆËã»úÉÏ£¬£¬£¬£¬£¬£¬£¬µ±Óû§´ò¿ª¶ñÒâEXCELÎļþʱ£¬£¬£¬£¬£¬£¬£¬OfficeÎĵµÖеĹ«Ê½±à×ëÆ÷»áÆô¶¯EQNDT32.EXE¹ý³Ì¡£¡£¡£¡£¡£µ±Equation¶ÔÏóÖдæÔÚÏóÕ÷Ϊ×ÖÌåÃû³ÆµÄ³¬³¤×Ö½ÚÁ÷£¬£¬£¬£¬£¬£¬£¬Ôò·¨Ê½ÔÚ´¦ÖøÃ×Ö·û´®µÄ¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬»á´¥·¢Õ»Òç¶Âí½Å¡£¡£¡£¡£¡£¶ø´Ë¶ñÒâÎĵµ¾ÍÊÇÀûÓø÷ì϶½«Ö¸ÏòshellcodeµÄÕ»µØÖ·¸²¸ÇÁËÔʼ·µ»ØµØÖ·£¬£¬£¬£¬£¬£¬£¬´Ó¶øÖ´ÐÐÔ¶³ÌpayloadµÄÏÂÔØ¡£¡£¡£¡£¡£
²é¿´ole¶ÔÏóµÄĿ¼½á¹¹£¬£¬£¬£¬£¬£¬£¬Äܹ»¿´µ½ole¶ÔÏóÒѱ»¼ø±ðΪCVE-2017-11882£º
ͼ9 OLE¶ÔÏóµÄĿ¼½á¹¹
ÓÉÓڸûº³åÇøÒç³öº¯Êý´¦ÓÚEQNDT32¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬ËùÒÔÎÒÃÇÌáǰ½«EQNDT32.EXE¼ÓÔØÆðÀ´²¢ÕÒµ½·ì϶Òç³ö´¦Ï¶ϵ㣬£¬£¬£¬£¬£¬£¬³Áдò¿ªµö¶üÎĵµºó£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÕ»Öзµ»ØµØÖ·0x004115D8±»¸²¸Ç£¬£¬£¬£¬£¬£¬£¬´Ó¶ø×ªÏòshellcodeÖ´ÐС£¡£¡£¡£¡£
ͼ10 Õ»Öб£ÁôµÄÔʼº¯Êý·µ»ØµØÖ·
ͼ11 ±»¸²¸ÇºóµÄº¯Êý·µ»ØµØÖ·
2.2 shellcode
RetnÖ´Ðкó·¨Ê½»áתµ½0x0012F350´¦£¬£¬£¬£¬£¬£¬£¬ÕâÀï´æ·ÅµÄ¾ÍÊÇFONT[name]Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇshellcode´úÂëµØÎ»¡£¡£¡£¡£¡£
ͼ12 shellcode´úÂëÖ´Ðд¦
¸Ã¶ÎshellcodeµÄÖ°ÄÜÊÇ£¬£¬£¬£¬£¬£¬£¬½«Ô¶³Ì·þÎñÆ÷¡°http[:]//34.87.19.73/pqis/11a.exe¡±ÉϵÄPayloadÏÂÔØµ½±¾µØ£¬£¬£¬£¬£¬£¬£¬²¢±£ÁôΪ¡°%AppData%Roaming\powerpoint.exe¡±£¬£¬£¬£¬£¬£¬£¬×îºóÔËÐи÷¨Ê½¡£¡£¡£¡£¡£
ͼ13 ÁªÍøÏÂÔØPayload
2.3 Payload
ÃûΪ11a.exeµÄPayloadÊÇʹÓÃMS Visual Basic˵»°±àдµÄ¡£¡£¡£¡£¡£µ±¶ñÒⷨʽÔËÐÐʱ£¬£¬£¬£¬£¬£¬£¬»áÔÚϵͳһʱĿ¼ÏÂÏÈ´´½¨¡°subfolder¡±×ÓĿ¼²¢ÌìÉúÁ½¸öÎļþ£¨explorer.exeºÍexplorer.vbs£©£¬£¬£¬£¬£¬£¬£¬½Ó×ÅÔËÐÐexplorer.vbs¾ç±¾²¢ÊµÏÖ×ÔÉí¹ý³Ì¡£¡£¡£¡£¡£explorer.vbs¾ç±¾µÄ¾ßÌåÄÚÈÝÈçÏÂͼ£º
ͼ14 explorer.vbs¾ç±¾ÄÚÈÝ
´Óͼ14µÄVBSÎļþÄÚÈÝÄܹ»¿´³ö£¬£¬£¬£¬£¬£¬£¬¾ç±¾ÖÐʹÓÃÁËwscript shellºÅÁî×öÁËÁ½¼þÊ¡£¡£¡£¡£¡£Ê×ÏȽ«×ÔÉíÔö³¤µ½×¢²á±í¿ª»ú×ÔÆô¶¯ÏîÖУ¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÿ´ÎÔÚϵͳÆô¶¯Ê±¶¼ÄÜ×Ô¶¯ÔËÐÐexplorer.vbsÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÃÒÔʵÏÔìäÓÆ¾ÃÐÔ£»£»£»£»£»£»Æä´Î£¬£¬£¬£¬£¬£¬£¬ÔËÐпÉÖ´ÐÐÎļþexplorer.exe¡£¡£¡£¡£¡£
ͼ15 Ôö³¤×¢²á±íÏî
2.4 Agent Tesla
ͨ¹ý¶ÈÎö£¬£¬£¬£¬£¬£¬£¬Äܹ»È·¶¨explorer.exe·¨Ê½ÊdzôÃûÔ¶ÑïµÄ¼äµýÈí¼þ¡°Agent Tesla¡±¡£¡£¡£¡£¡£¸ÃľÂíÔËÐкó»áÁ¢¼´³Áд´½¨Ò»¸ö¹ÒÆðµÄ×ÔÉí×Ó¹ý³Ì¡£¡£¡£¡£¡£×Ó¹ý³ÌµÄÓйØÊôÐÔÈçÏÂͼ£º
ͼ16 ×Ó¹ý³ÌÊôÐÔÐÅÏ¢
¶øºó×Ó¹ý³Ì»á´Ó×ÊÔ´Êý¾ÝÖнâÃܳöÁíÒ»¸öÓÉ.NET±àдµÄPEÎļþ£¬£¬£¬£¬£¬£¬£¬Æä½«»áÔÚÄÚ´æÖÐÖ±½ÓÔËÐС£¡£¡£¡£¡£ÏÂͼÊÇÔÚ·ÖÎö¹¤¾ßÖÐÏÔʾµÄ¸Ã.NET·¨Ê½µÄÖØÒªÖ°ÄÜ£º
ͼ17 ÖØÒªÖ°ÄÜ´úÂ벿ÃŽØÍ¼
¸Ã·¨Ê½»á³¢ÊÔ½Ó¼û¡°checkup[.]amazonaws.com¡±£¬£¬£¬£¬£¬£¬£¬ÒÔ´ËÀ´»ñÈ¡±¾µØ»úеµÄ±íÍøIPµØÖ·¡£¡£¡£¡£¡£
ͼ18 »ñÈ¡±¾µØIPµØÖ·
´Óͼ17µÄÄÚÈÝÄܹ»¿´µ½£¬£¬£¬£¬£¬£¬£¬·¨Ê½´úÂëʹÓÃÁË»ìºÏ¼¼ÊõÀ´Ôö³¤·ÖÎöÄѶȡ£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Æä»¹»á¶ÔVM¡¢É³Ïä¡¢µ÷ÊÔÆ÷ºÍÆäËû¼à¿Ø¹¤¾ßµÈ×öһϵÁеļì²â¡£¡£¡£¡£¡£ÈçÔËÐл·¾³°²È«£¬£¬£¬£¬£¬£¬£¬.NET·¨Ê½ÔòÆðÍ·¼à¶½²¢ÍøÂçÊܺ¦ÕßµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃSMTPºÍ̸½«¼à¿ØÈÕÖ¾·¢Ë͸øÔ¶³Ì·þÎñÆ÷¡°smtp[.]diagnosticsystem.in¡±¡£¡£¡£¡£¡£
Agent Tesla¼Ò×å
»ùÓÚÒÑÖªµÄÓйØ×ÊÁÏ£¬£¬£¬£¬£¬£¬£¬´Ó2014ÄêÆðÆù½ñΪֹ£¬£¬£¬£¬£¬£¬£¬Agent TeslaÒÑ´æ»î³¤´ï5ÄêÖ®¾Ã¡£¡£¡£¡£¡£Ëæ×ʦ·òµÄÍÆÒÆ£¬£¬£¬£¬£¬£¬£¬¸ÃľÂíÔÚÂ½Ðø²»Ðݵĵü´ú¸üУ¬£¬£¬£¬£¬£¬£¬×îа汾Ŀǰ¿Éƾ¾ÝÐèÒªÔÚ»¥ÁªÍøÉÏÇáÒײɰ졣¡£¡£¡£¡£
Agent Tesla¿Éʵʱ¼à¿ØºÍ¼Í¼Óû§µÄ¼üÅÌÊäÈë¡¢ÇÔÈ¡¼ôÇаåÊý¾Ý¡¢ÆÁÄ»½ØÍ¼¡¢»ñÈ¡Ö÷»úÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÍøÂç¸÷´óä¯ÀÀÆ÷ºÍÓÊÏäµÄÓû§Æ¾Ö¤²¢»Ø´«ÖÁºÚ¿Í·þÎñÆ÷¡£¡£¡£¡£¡£Ò²ÕýÓÉÓÚÆäÖ°Äܼ«¶È׳´ó£¬£¬£¬£¬£¬£¬£¬ËùÒÔ½ü¼¸ÄêÒÔÀ´Ê±Ê±±»ºÚ¿Í×éÖ¯ËùÀûÓᣡ£¡£¡£¡£
ÏÂͼÊÇ´ÓÆäÍøÕ¾ÉÏժȡÏÂÀ´µÄ²¿ÃÅÖ°ÄܽéÉÜ£º
ͼ19 Agent TeslaXÓйØÖ°ÄÜ
½ØÖ¹µ½Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬¼øÓÚÎÒÃÇ·ÖÎöµÄÕâ¿îбäÖֺ;ɰæµÄľÂíÔÚÖ°Äܺͼ¼ÊõÉÏÀàËÆ£¬£¬£¬£¬£¬£¬£¬²¢Ã»Óз¢ÏÖÌ«¶àµÄ±ä¶¯µã¡£¡£¡£¡£¡£ËùÒÔ±¾ÎÄÔÚÕâÀï²»ÔÙ¹ý¶àµÄ¾ßÌåÃèÊöÆä¾ßÌåµÄ¼¼Êõϸ½Ú£¬£¬£¬£¬£¬£¬£¬ÈçÓбØÒª¸÷È˿ɲ鿴ÎÄÄ©µÄ²Î¿¼Îļþ¡£¡£¡£¡£¡£
3¡¢ËÝÔ´Óë¹ØÁª·ÖÎö
3.1 ¶ñÒâÓòÃû·ÖÎö
ÎÒÃÇÊ×ÏÈ´Ó¶ñÒâÎĵµ´¥·¢·ì϶ºóÖ´ÐеÄshellcodeÖÐÌáÈ¡³öÒ»¸öÓ²±àÂëµÄÁ´½ÓµØÖ·£º¡°http[:]//34.87.19.73/¡±¡£¡£¡£¡£¡£¾¹ýºó¶Ü´óÊý¾ÝµÄÑù±¾¹ØÁª·ÖÎöºó£¬£¬£¬£¬£¬£¬£¬´Ó¸ÃÍÐ¹ÜµÄ±í²¿Ö÷»úÉÏÍÚ¾ò³ö¸ÃºÚ¿Í×éÖ¯×Ô2019Äê9ÔÂÆðʹÓõÄÖî¶àÀàÐ͵ļäµýľÂí¡£¡£¡£¡£¡£
ͼ20 ÍйÜÖ÷»úÉϵÄľÂíÐÅϢͳ¼Æ
½Ó×Å£¬£¬£¬£¬£¬£¬£¬ÌáÈ¡¸ÃÅúľÂíÑù±¾Ê¹ÓõÄC2ÓòÃû½øÒ»²½µÄ¹ØÁª³ö²¿ÃÅ¿ÉÒɵÄCCµØÖ·¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬²¿ÃÅľÂí»á½«SMTPÁ÷Á¿·¢Ë͵½smtp[.]diagnosticsystem.in£¬£¬£¬£¬£¬£¬£¬¶ø¸ÃÓòÃû½âÎöµÄIPµØÖ·Îª208[.]91[.]199[.]143¡£¡£¡£¡£¡£
DNS²éÎÊ´ËÓòÃû£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìä×¢²á¹¦·òΪ2019Äê9ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬ÕâÓë¸ÃÅúľÂíµÄ´«²¼ÕØÊ¼¹¦·òÕýºÃÎǺϡ£¡£¡£¡£¡£ÓòÃû²éÎÊÐÅÏ¢ÈçÏÂͼ£º
ͼ21 ÓòÃûµÄ×¢²á¹¦·ò
ÔٴζÔÏßË÷×öÀ©´óºÍ¶Ô¸ÃÓòÃû½øÐÐÉî¿ÌµÄ×·×Ù·ÖÎöºó£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ»ñµÃÁ˸ü¶àµÄ¶ñÒâÑù±¾£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÕâЩÓòÃûÔø½âÎöµ½µÄÖ÷»úIPµØÖ·¡£¡£¡£¡£¡£
ͼ22 ÓòÃû½âÎöµÄIPµØÖ·
ÎÒÃÇ´Ó»ñÈ¡µÄ´óÁ¿¶ñÒâÑù±¾ÖÐÕû¶Ù³ö½üÆÚ±ÈÁ¦»îÔ¾µÄ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÊÖ¶¯·ÖÎöÈ·¶¨ÁËÕâ´Î¹¥»÷»î¶¯ÖÐʹÓõĴóÁ¿C2ÓòÃû¡£¡£¡£¡£¡£¾¹ý²éÎʽâÎöºó·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÕâЩÓòÃû¾ùÊÇÒÔÉÏIPµØÖ·¡°208.91.199.**¡±ºÍ¡°208.91.198.143¡±µÄCNAME¡°us2.smtp.mailhostbox.com¡±µÄ±ðºÅ¡£¡£¡£¡£¡£
ͼ23 ÓòÃû²éÎÊÐÅÏ¢
ͼÖÐÁоÙÁ˲¿ÃÅ»îÔ¾Ñù±¾ºÍÆä½Ó¼ûµÄÓòÃû£¬£¬£¬£¬£¬£¬£¬¾ßÌå¶ÔÓ¦¹ØÏµÈçÏÂËùʾ£º
ͼ24 ¶ñÒâÑù±¾ÓëC&C·þÎñÆ÷µÄ¹ØÏµÍ¼
3.2 ¹ØÁªÓʼþ
ƾ¾ÝͬԴ·ÖÎö£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÁËÁí±íÒ»·âÕë¶ÔÎ÷°àÑÀµØÓòµÄ´¹µöÓʼþ¡£¡£¡£¡£¡£¸ÃÓʼþµÄ·¢¼þµØÖ·ÊÇÎ÷°àÑÀÒ»¼ÒÃûΪ¡°MAJ AGROQUIMICOS¡±µÄũҩÐÐÒµ¹«Ë¾¡£¡£¡£¡£¡£
ͼ25 MAJ AGROQUIMICOS¹«Ë¾Ê×Ò³
ÓʼþÄÚÈÝʹÓõÄÊÇÎ÷°àÑÀÓ£¬£¬£¬£¬£¬£¬´óÌåÒâ˼ÊǸ¶¿îÈ·ÈÏÊ飬£¬£¬£¬£¬£¬£¬´¹µöÓʼþµÄ¸½¼þÊÇÒ»¸ö¼Ù×°³É.imgÌåʽµÄISOÎļþ¡£¡£¡£¡£¡£¹ÌÈ»ÎļþÃû³ÆÓëÓʼþµÄÄÚÈÝÓÐËù·ÖÆç£¬£¬£¬£¬£¬£¬£¬µ«ÊÇ´Ó·¢¼þµØÖ·À´¿´£¬£¬£¬£¬£¬£¬£¬ÆäÆðÔ´Ò²ÓпÉÄÜ»áÊǹ¥»÷Ö¸±êµÄºÏ×÷ÉÌ»ò¹©¸øÉÌÖ®À࣬£¬£¬£¬£¬£¬£¬ÕâÑù±ã¿ÉÔö³¤ÓʼþµÄÕæÊµÐÔ£¬£¬£¬£¬£¬£¬£¬Í¬ÑùÓлúÓöÓÕʹÊܺ¦ÕßÏÂÔØ¸½¼þ¡£¡£¡£¡£¡£Óʼþ¾ßÌåÄÚÈÝÈçÏÂͼËùʾ£º
ͼ26 Î÷°àÑÀÓïµÄ´¹µöÓʼþ
ͼ27 Óʼþ·ÒëºóµÄÄÚÈÝ
3.3 ISOÎļþ
ISOÓ³ÏñÊÇÒ»ÖÖ¹âÅ̵Ĵ浵Îļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬½«ÒªÐ´Èë¹âÅ̵ÄËùÓÐÐÅÏ¢¡£¡£¡£¡£¡£Í¨³£ÓÃÓÚ´´½¨CD»òDVDµÄ±¸·Ý¡£¡£¡£¡£¡£ÓÉÓÚISOÎļþµÄ³ß´çÏà¶Ô±ÈÁ¦´ó£¬£¬£¬£¬£¬£¬£¬ËùÒÔÓпÉÄܵ¼Öºöàµç×ÓÓʼþÍø¹ØÉ¨Ã跨ʽÎÞ·¨ÕýÈ·¼ø±ð´ËÀàÐ͵ĸ½¼þ¡£¡£¡£¡£¡£²¢ÇÒ×ÔWin 8¼°ÒÔÉϵĸü¸ß°æ±¾ºó£¬£¬£¬£¬£¬£¬£¬Windows¶¼×Ô´øISOÔËÐй¤¾ß£¬£¬£¬£¬£¬£¬£¬Óû§¾ÍÏñ´ò¿ªEXEÎļþÒ»Ñù£¬£¬£¬£¬£¬£¬£¬Ö±½ÓË«»÷ISOÎļþ¼´¿ÉÔËÐС£¡£¡£¡£¡£Òò¶øÕâ´Î¹¥»÷ÖкڿÍʹÓÃÁËISOÎļþ×÷Ϊ¶ñÒ⸽¼þ¡£¡£¡£¡£¡£
3.4 ¶ñÒ⸽¼þ
ǶÈëÔÚIOS¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþÈçÏÂͼËùʾ£º
ͼ28 ǶÈëµÄ¿ÉÖ´ÐÐÎļþ
ǶÈëµÄ¿ÉÖ´ÐÐÎļþ
ʹÓ÷ÖÎö¹¤¾ßÄܹ»¿´µ½£¬£¬£¬£¬£¬£¬£¬Õâ¸öÃûΪ¡°SOA300329042943243_pdf.exe¡±µÄ¿ÉÖ´ÐÐÎļþÏÖʵÉÏÊÇÒ»¸öAutoItÚ¹ÊÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢Ç¶ÈëÁËAutoIt±àÒë¾ç±¾×÷Ϊ×ÊÔ´¡£¡£¡£¡£¡£
ͼ29 ¿ÉÖ´ÐÐÎļþµÄ×ÊÔ´ÐÅÏ¢
¸Ã¿ÉÖ´ÐÐÎļþÔËÐк󣬣¬£¬£¬£¬£¬£¬»áÔÚ%User\Public%Ŀ¼Ï¿ªÊͶñÒâµÄVBS¾ç±¾Îļþ²¢½«¸ÃĿ¼Ôö³¤µ½×¢²á±íµÄRunÆô¶¯ÏîÖУ¬£¬£¬£¬£¬£¬£¬ÒÔʵÏÔìäÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£½Ó×ÅÔÙ½«ÄÚ´æÖнâÃܳöµÄµÄPEÎļþ×¢È뵽ϵͳÎļþ¡°Regasm.exe¡±ÖС£¡£¡£¡£¡£
ͼ30 ÔÚ×¢²á±íÖÐÔö³¤×ÔÆô¶¯Ïî
ÐÂPEÎļþ
ͨ¹ý¶ÈÎöÄÚ´æÖнâÃܳöµÄÐÂPEÎļþ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÈ·¶¨¸ÃEXEÊÇÁíÒ»°æÊ¹ÓÃ.NET¿ò¼Ü±àдµÄAgent TeslaľÂí¡£¡£¡£¡£¡£ÔÚľÂí·¨Ê½³É¹¦×¢Èëµ½Regasm.exe¹ý³Ì²¢ÔËÐк󣬣¬£¬£¬£¬£¬£¬±ãÆðÍ·³¢ÊÔÓëÔ¶³Ì·þÎñÆ÷½øÐÐÏνӡ£¡£¡£¡£¡£
ÎÒÃÇÔÚ¶ñÒâ´úÂë·ÖÎö¹ý³ÌÖз¢ÏÖÁ˺ڿÍC&C·þÎñÆ÷ÉϵÄÓйØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬C&CÎļþĿ¼ÈçÏÂͼ£º
ͼ31 ·þÎñÆ÷ÉϵÄÎļþĿ¼
ͨ¹ý½øÒ»²½µÄ·ÖÎö£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖC&C·þÎñÆ÷Éϱ£Áô×Å´óÁ¿µÄ´ÓÊܺ¦Õß»úе»Ø´«µÄ¼à¿ØÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝÆäÖü´æµÄÎļþÃû³ÆÌåʽºÍÄÚÈݵÈÌØµã£¬£¬£¬£¬£¬£¬£¬ÔÙ´ÎÈ·¶¨¸ÃľÂíÊÇ¡°Agent Tesla¡±¼Ò×å¡£¡£¡£¡£¡£
¶ûºó£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ»¹×·×Ùµ½Á˸úڿÍ×éÖ¯ËùÍøÂçµÄÊܺ¦ÕßÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢ÒÔhtmlºÍjpegÎļþµÄ´ó¾Ö´æ´¢ÔÚC&C·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐhtml´æ´¢µÄÊDZ¾»úÐÅÏ¢¡¢¼üÅ̼ͼ¡¢Õ˺ÅÃÜÂëµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬jpeg´æ´¢µÄÊÇ½ØÆÁÐÅÏ¢¡£¡£¡£¡£¡£ÏÂͼÊǽØÈ¡Á˲¿ÃÅ¼à¿ØÈÕÖ¾£º
ͼ32 »Ø´«µ½·þÎñÆ÷µÄ¼à¿ØÈÕÖ¾
´ÓÕâЩÎļþÃûÖеģº¡°Keystrokes¡±£¨¼üÅ̼ͼ£©¡¢¡°Screen¡±£¨ÆÁÄ»½Ø£©¡¢¡°Recovered¡±£¨ÃÜÂ븴ԣ©µÈ¹Ø¼ü×ÖÄܹ»¿´³ö£¬£¬£¬£¬£¬£¬£¬Ä¾ÂíÊÇÆ¾¾ÝºÚ¿ÍµÄ½ÚÔìÖ¸ÁîÀ´ÇÔÈ¡Êܺ¦ÕßµÄÓйØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÇÒÒÀÕÕ¡°Ö°ÄÜ-Óû§Ãû-ÍÆËã»úÃû-¹¦·ò£¨Äê-ÔÂ-ÈÕ-ʱ-·Ö-Ã룩¡±µÄ½á¹¹¶¨Ãû²¢±£ÁôΪHTMLÌåʽµÄÎļþ¡£¡£¡£¡£¡£
ÎÒÃǽ«Ò»¸öÒÔ¡°Recovery¡±¿ªÍ·µÄhtmlÎļþʹÓÃIEä¯ÀÀÆ÷´ò¿ª£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ¿´µ½Ä¾Âí¾ßÌåÍøÂçÁËÄÄЩÐÅÏ¢¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Êܺ¦ÕßµÄÍÆËã»úÓû§Ãû¡¢Ö÷»úÐÅÏ¢¡¢ÏµÍ³Ãû³Æ¡¢CPUÐÅÏ¢¡¢ÄÚ´æÐÅÏ¢¡¢IPµØÖ·ÒÔ¼°Chromeä¯ÀÀÆ÷Í´´¦ÐÅÏ¢µÈ¡£¡£¡£¡£¡£
ͼ33 HTMLÎļþµÄÄÚÈÝÏêÇé
3.5 »ù´¡ÉèÊ©·ÖÎö
ͨ¹ýÍøÂçÓë¸ÃC&C·þÎñÆ÷ÓйصĻش«ÐÅÏ¢½øÐÐÕû¶Ù·ÖÎöºó£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÁ˼¸¸ö¹Ø¼üÐÅÏ¢¡£¡£¡£¡£¡£½áºÏǰÎÄÖÐÍøÂçµ½µÄÏßË÷£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽøÒ»²½¼òÖ±ÈÏÁ˸÷þÎñÆ÷ÊDZ»ºÚ¿Í×éÖ¯¹¥Ïº󣬣¬£¬£¬£¬£¬£¬×¨ÃÅÓÃ×÷½Ó¹ÜľÂí»Ø´«Êܺ¦ÕßÐÅÏ¢µÄ·þÎñÆ÷¡£¡£¡£¡£¡£¶ø¸Ã×éÖ¯ÔçÔÚ7Ô·ݵÄʱ³½¾ÍÒÑÆðÍ·Ö´Ðй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÊܺ¦ÕßÎÞÊýÊÇÀ´×ÔÓÚÎ÷°àÑÀµØÓòµÄÆóÊÂÒµµ¥Ôª¹¤×÷ÈËÔ±¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯¹ßÓÚÀûÓÃAgent Tesla»òHawkeye Keylogger¡¢Nanocore RATºÍNetWire RATµÈ¼äµýľÂíÀ´ÇÔȡָ±êÈËÔ±µÄµÇ¼ƾ֤µÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÇÒÕâ´Î¹¥»÷»î¶¯ÊÇÓÉÀ´×ÔÓÚÄáÈÕÀûÑǵĺڿÍ×éÖ¯²ß¶¯ÓëÖ´ÐС£¡£¡£¡£¡£
3.5.1 Êܹ¥»÷·þÎñÆ÷·ÖÎö
ÎÒÃǰÑÎȵ½£¬£¬£¬£¬£¬£¬£¬W-EAGLEĿ¼Ï±£Áô×ÅÒ»¸öÃûΪ¡°W-EAGLE PMS Deck.zip¡±µÄѹËõ°ü¡£¡£¡£¡£¡£½âѹ²¢´ò¿ªÄ³DOCÎĵµ£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÕâÊÇÒ»¸ö´ø×Ź«Ë¾logoµÄÎ÷°àÑÀÓïÎļþ£¬£¬£¬£¬£¬£¬£¬±êÌâÔڹȸè·ÒëΪ¡°´¬Ãæ´òËãµÄÊØ»¤/²é³Êֲᡱ¡£¡£¡£¡£¡£
ͼ34 W-EAGLEĿ¼ÏµÄÎļþÄÚÈÝ
ƾ¾Ý¹«Ë¾Ãû³ÆËÑË÷ºó֤ʵ£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÎ÷°àÑÀÒ»¼Ò´óÐÍ´¬²°ÖÎÀí¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÖØÒª´ÓʸÉÉ¢»õ´¬µÄÔËÓª¡£¡£¡£¡£¡£
ͼ35 W MARINE INC¹«Ë¾Ö÷Ò³ÐÅÏ¢
Èçͼ35Ëùʾ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÍøÖ·Í¬ºÚ¿ÍËùʹÓõķþÎñÆ÷Ãû³ÆÒ»Ñù£¬£¬£¬£¬£¬£¬£¬ÓÉ´ËÖ¤Ã÷´Ë·þÎñÆ÷ÏÖʵÊÇÊôÓڴ˹«Ë¾¡£¡£¡£¡£¡£²¢ÇÒÆ¾¾Ý·þÎñÆ÷Éϱ£ÁôµÄÓë¸Ã¹«Ë¾ÓйصÄÎĵµ´´½¨¹¦·òÊÇ2016Äê10ÔÂÖÐÏÂÑ®×óÓÒ£¬£¬£¬£¬£¬£¬£¬ÎÒÃDz²â´Ë·þÎñÆ÷Òò³Ö¾Ã±»ÏÐÖöøÎÞÈËÊØ»¤£¬£¬£¬£¬£¬£¬£¬ÒÔÖÁ±»ºÚ¿Í×éÖ¯¼ÓÒÔÀûÓᣡ£¡£¡£¡£
3.5.2 ¼à¿ØÈÕÖ¾ÐÅÏ¢
ÎÒÃǽ«ÊýÁ¿½ü2ÍòµÄ¼à¿ØÈÕÖ¾½øÐÐÕû¶Ù·ÖÎö£¬£¬£¬£¬£¬£¬£¬Êý¾ÝÏÔʾºÚ¿Í×éÖ¯ÏÖʵÉÏ´Ó2019Äê7Ô±ãÒÑÆðÍ·´¦ÓÚ»îԾ״̬£¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßµÄÖ÷»úÐÅÏ¢ÒÔ¼°Ó×ÎҵǼƾ֤³ÖÐøµÄ±»»Ø´«µ½´Ë·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡£½ØÖ¹Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬£¬£¬KeystrokesÎļþµÄÕ¼±ÈÂÊÏà¶Ô±ÈÁ¦´ó£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇScreenÎļþ£¬£¬£¬£¬£¬£¬£¬RecovereyÎļþÏà¶Ô½ÏÉÙ¡£¡£¡£¡£¡£²»½öÈç´Ë£¬£¬£¬£¬£¬£¬£¬ÎÒÃǼà²âµ½´ËÀàÎļþÔÚ·þÎñÆ÷ÉÏÒÀÈ»²»¼ä¶ÏµÄÐÂÔö¡£¡£¡£¡£¡£
|
ÎļþÀàÐÍ |
´´½¨¹¦·ò |
ÎļþÊýÁ¿ |
|
Keystrokes |
2019Äê7ÔÂ16ÈÕ |
8383 |
|
Screen |
2019Äê8ÔÂ10ÈÕ |
5447 |
|
Recovery |
2019Äê7ÔÂ16ÈÕ |
3859 |
±í1 ·þÎñÆ÷ÉϵÄÈÕ־ͳ¼Æ
3.5.3 Êܺ¦ÕßµØÓòºÍÐÐҵɢ²¼
Êܺ¦ÕßIPµØÖ·ÖØÒªÉ¢²¼ÔÚÎ÷°àÑÀ¡¢Ó¡¶È£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÉÙÁ¿À´×Ô°¢ÁªÇõºÍÄ«Î÷¸çµØÓò£¬£¬£¬£¬£¬£¬£¬Æä»òÐíÕ¼±ÈÂÊÈçÏÂͼ£º
ͼ36 Êܺ¦ÕßµØÓòÉ¢²¼Í¼
»ùÓÚÎÒÃǶԺڿÍ×éÖ¯µÄ¹¥»÷ÐÅϢͳ¼ÆÏÔʾ£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯Éæ¼°µ½Î÷°àÑÀµØÓòµÄÊе±¾Ö¡¢Å©Òµ»úеÐÐÒµ¡¢Ë®Àû¹¤³ÌÐÐÒµºÍ¶Ô±íÒµÎñÐÐÒµ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ó¡¶ÈºÍ°¢ÁªÇõµÈÆäËûÐÐÒµ¡£¡£¡£¡£¡£Ï±íչʾÁ˲¿ÃŵÄÓйØÍ³¼ÆÐÅÏ¢£º
|
¹«Ë¾Ãû³Æ |
¹«Ë¾ÐÅÏ¢ |
|
FEMAC |
λÓÚÎ÷°àÑÀµÄÒ»¼Òũҵ»úе¹«Ë¾ |
|
XUNTA DE GALICIA |
Î÷°àÑÀ¼ÓÀûÎ÷ÑǵØÓòµÄ·ÑË¹ÌØÀÊÐÕþÌü |
|
ICINCO |
λÓÚÎ÷°àÑÀ¼ÓÄÉÀûȺµºµÄ¹¹ÖþË®Àû¹¤³Ì¹«Ë¾ |
|
GALACANARIA |
λÓÚÎ÷°àÑÀ´ó¼ÓÄÉÀûȺµºµÄÒ»¼ÒʳƷ£¬£¬£¬£¬£¬£¬£¬ÒûÁϺÍÑ̲ÝÅú·¢ÒµÎñ¹«Ë¾ |
|
AIRSAT |
Î÷°àÑÀÒ»¼Ò»¥ÁªÍø¹©¸øÉÌ |
|
Al Serh Al Kabeer |
λÓÚ°¢ÁªÇõµÄÒ»¼Ò¹¹Öþ¹«Ë¾ |
|
AFS Logistics International Pvt.Ltd |
λÓÚÓ¡¶ÈµÄÒ»¼Ò¹ú¼ÊÎïÁ÷»õÔË´úÀí¹«Ë¾ |
|
Vanity Case |
λÓÚÓ¡¶ÈµÄÒ»¼ÒÌìÈ»»¤·ô²úÆ··ÖÏúÉÌ |
|
sanbe-farma |
Ó¡¶ÈÄáÎ÷ÑDZ¾µØµ±ÏȵÄÔìÒ©¹«Ë¾ |
±í2 ±»¹¥»÷µÄ²¿ÃŹ«Ë¾ÐÅÏ¢
3.5.4 ºÚ¿ÍµÄ¹éÊôµØÎ»
´Ë±í£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ»¹°ÑÎȵ½Ò»Ð©HawkEye KeyloggerÈÕÖ¾ËÆºõÊǴӺڿ͵ĵçÄÔÖÐÉÏ´«µÄ£¬£¬£¬£¬£¬£¬£¬ÎļþÃûÖеÄHawkEye KeyloggerºÍ±àºÅRebornv9£¨¸ÃľÂíµÄ×îа汾ºÅ£©£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¹Ø¼ü×Ö¡°PasswordsLogs¡±ºÍ¡°TestLogs¡±µÈ£¬£¬£¬£¬£¬£¬£¬ÒÉËÆÊǺڿ͵IJâÊÔÈÕÖ¾¡£¡£¡£¡£¡£
ͼ37 ²âÊÔÈÕÖ¾½ØÍ¼
ÈÕÖ¾Îı¾Àï¾ßÌåÁгöÁ˺ڿÍ×éÖ¯¼¸¸öÓÃÓÚ²âÊÔµÄÓÊÏäµÇ¼ƾ֤£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÐÅÏ¢ÈçÏ¡£¡£¡£¡£¡£
ʾÀý1£º
ͼ38 ÈÕÖ¾ÐÅÏ¢½ØÍ¼1
ͼ39 MovistarÓÊÏäµÇ¼½çÃæ
ʾÀý2£º
ͼ 40 ÈÕÖ¾ÐÅÏ¢½ØÍ¼2
ͼ41 Suite Correo Profesional ÓÊÏäµÇ¼½çÃæ
ÎÒÃÇÌáÈ¡³öÁ˸ÃÈÕÖ¾µÄIPµØÖ·¡°197.210.226.51¡±¡£¡£¡£¡£¡£²éÎʺóµÃ³ö¸ÃµØÖ·Î»ÓÚÄáÈÕÀûÑǵØÓò£º
ͼ42 IPµØÖ·²éÎʺóµÄÓйØÐÅÏ¢
´Ë±í£¬£¬£¬£¬£¬£¬£¬ÔÚÁí±íµÄKeystrokesÈÕÖ¾ÖÐÔٴη¢ÏÖµÄIPµØÖ·¡°41.203.73.185¡±ÓëǰÎÄÖÐÎÒÃǼͼµÄIPµØÖ·Ò»Ñù£¬£¬£¬£¬£¬£¬£¬ÆäÒ²ÊÇÖ¸ÏòÄáÈÕÀûÑǵØÓò¡£¡£¡£¡£¡£¾ßÌåÐÅÏ¢ÈçÏÂͼ£º
ͼ43 KeystrokesÈÕÖ¾ÖеÄÐÅÏ¢
¶øºó£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ´ÓͬԴµÄRecoveryÈÕÖ¾ÖÐÕÒµ½Á˺ڿͲ»Ó×ÐÄй¶µÄ¹ú±íANY.RUN£¨ÔÚÏß¶ñÒâÈí¼þɳÏ䣩ƽ̨µÄÕ˺źÍÃÜÂë¡£¡£¡£¡£¡£
ͼ44 RecoveryÈÕÖ¾ÖеÄÐÅÏ¢
³É¹¦µÇ¼ºó²é¿´É¨Ã躹Ç࣬£¬£¬£¬£¬£¬£¬ÎÒÃÇÄܹ»¿´µ½ºÚ¿Í×éÖ¯ÔÚ7Ô·ݵÄʱ³½±ãÆðÍ·½«Ä¾¶Ùʱ´«½øÐвéɱ¼ì²â¡£¡£¡£¡£¡£Í¬Ê±Æ¾¾ÝɳÏäɨÃèÁ˾ÖÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÔÙ´ÎÈ·ÈϸÃÅúľÂíÊôÓÚAgent TeslaºÍHawkEye Keylogger¼Ò×å¡£¡£¡£¡£¡£
ͼ45 ANY.RUNÉÏ´«º¹Çà¼Í¼
4¡¢×Ü ½á
³Ö¾ÃÒÔÀ´£¬£¬£¬£¬£¬£¬£¬ ÓÃÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢µÄ¼äµýľÂíÒ»ÏòÔÚ²»Ðݵĸüл»´ú¡£¡£¡£¡£¡£Ëæ×Å»ÒÉ«Êг¡µÄ¹ÄÆð£¬£¬£¬£¬£¬£¬£¬¼üÅ̼ͼ·¨Ê½¡¢ÇÔÃÜ·¨Ê½ºÍÔ¶¿Ø·¨Ê½ÔÚÖð²½µØÇ÷ÏòÓÚóÒ×»¯£¬£¬£¬£¬£¬£¬£¬ÒÔÖÁÓÚ¹¥»÷ÕßÔÚ´Ë·½ÃæÎãӹͶÈëÌ«¶àµÄ¹¦·òºÍ¾«Á¦£¬£¬£¬£¬£¬£¬£¬¶ø½«¹Ø×¢µã·ÅÔÚÆä¹¥»÷¼¿Á©ºÍÉç»á¹¤³ÌѧµÄÄÜÁ¦ÉÏ¡£¡£¡£¡£¡£
ͨ¹ý¶Ô·þÎñÆ÷ÉϳÖÐø¸üеĻش«Îļþ¼à²â£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÄܹ»¿´³ö¸ÃºÚ¿Í×éÖ¯µÄ¹¥»÷»î¶¯ÔÚ³ÖÐø½øÐУ¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßµÄÈËÊýÒÀÈ»³ÊÉÏÉýÇ÷Ïò¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´ºÍºó¶ÜÊý¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬ÎÒÃDz²âºóÐøµÄ¹¥»÷Ö¸±ê³Áµã×óÌ»ÓÚÎ÷°àÑÀºÍÓ¡¶ÈµÈµØÓò¡£¡£¡£¡£¡£
ÔÚ´Ë8827Ì«Ñô¼¯ÍÅADLabÌáÐѸ÷ÆóÒµµ¥Ôª¼°Ó×ÎÒÓû§Ìá¸ß¾¯Ì裬£¬£¬£¬£¬£¬£¬²»´ÓÀ´Àú²»Ã÷µÄÍøÕ¾ÏÂÔØÈí¼þ£¬£¬£¬£¬£¬£¬£¬²»ÒªµÈÏеã»÷ÆðÔ´²»Ã÷µÄÓʼþ¸½¼þ£¬£¬£¬£¬£¬£¬£¬²»ÒªÇáÒׯôÓú꣬£¬£¬£¬£¬£¬£¬ÊµÊ±ÏÂÔØ²¹¶¡½¨¸´¡£¡£¡£¡£¡£
IOC£º
SHA-256
DE01B6A27D4EBA814FE3CE5084CFC23FDEEB47D50F8BEC5A973578E66B768A48
D5F2418628B818FCFFDD7F3A31F9A137761FA307D1C05C9B783E9040E008DE90
CA56DAD3CABD5AD85411B88C5E094055BEAA96DF6F9B37B9E9FD03AFF823CBAF
4DE32AD800A7847510925D34142B16AE6D7C3C0E44E33EC54466F527FCC93F41
F183992B4BC36F3B33F967EAB83B53A2448260ADA4A92A4B86F32284285EEFED
D6F5AAD82A21C384171BC8FE1BFBC47867151CCE9E8FA54FA21903191A63FD9E
BB3A12EDEFB5A96D6BDBFDC86ED125757ABC3C479EDAF485444A05F4A1D9F9B6
0514990857770F5AF20C96B97D7B63DC8248593D223A672D60C5C6479910C84B
1DD9B3CBB1AAC20E3A3954A1CFBE1BC8CB746C1BF446512A0AB6795546A9774F
C2ÓòÃû
smtp[.]diagnosticsystem[.]in
kartelicemoneyy[.]duckdns[.]org
virtualhost19791[.]duckdns[.]org
²Î¿¼Á´½Ó£º
https://www.fortinet.com/blog/threat-research/in-depth-analysis-of-net-malware-javaupdtr.html


¾©¹«Íø°²±¸11010802024551ºÅ