8827Ì«Ñô¼¯ÍÅADLab | SWEEDºÚ¿Í×éÖ¯¹¥»÷»î¶¯·ÖÎö»ã±¨

°ä²¼¹¦·ò 2020-07-03

Ò»¡¢¸ÅÊö


½üÆÚ£¬£¬£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab½ÓÁ¬²¶»ñµ½´óÁ¿Õë¶ÔÈ«ÇòÔì×÷¡¢ÔËÊä¡¢ÄÜÔ´µÈÐÐÒµ¼°²¿ÃÅÒ½ÁÆ»ú¹¹ÌáÒéµÄÓã²æÊ½´¹µöÓʼþ¶¨Ïò¹¥»÷¡£¡£¡£¡£¡£¡£¡£´ÓÓʼþµÄ·ÖÎöÁ˾ÖÀ´¿´£¬£¬£¬ £¬£¬£¬£¬£¬Êܺ¦Õß´ó¶à±é²¼ÓÚÃÀ¹ú¡¢¼ÓÄô󡢵¹ú¡¢Öйú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Î÷°àÑÀµÈ¹ú¶ÈºÍµØÓò¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ¡°×°´¬Í¨Öªµ¥¡±¡¢¡°×°Ïä½»»õ¼Ûµ¥¡±¡¢¡°´¹Î£ÔËÊäÎļþ¡±µÈÖ÷ÌâÓʼþ×÷Ϊµö¶üÏò¹¥»÷Ö¸±êÖ²ÈëÐÅÏ¢ÇÔÃÜľÂí£¨Agent Tesla¡¢Formbook¡¢Lokibot£©ºÍÔ¶³Ì½ÚÔ취ʽ£¨NanoCore¡¢Remcos£©¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇͨ¹ý¶ÔÍøÂçµ½µÄ¹¥»÷¹¤¾ß½øÐÐÈ¥³Á²¢×ö·ÖÎö£¬£¬£¬ £¬£¬£¬£¬£¬×îÖÕ·¢ÏÖÕâ´Î¹¥»÷»î¶¯¹ØÁª×Å1362¸ö¹¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£¡£Í¨¹ýͬԴ·ÖÎö£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÕâÅúÑù±¾ÖÐÓнü80%ÊÇͳһ¿î¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬¶ÔÆä·ÖÎöÅж¨ºóÈ·¶¨ÕâÕýÊǽüÆÚ±»´óÁìÓò´«²¼ÇÒ¼«Îª»îÔ¾µÄÐÂÐÍÏÂÔØÕß²¡¶¾Guloader¡£¡£¡£¡£¡£¡£¡£GuloaderÊÇÒ»¿îÃâɱÄÜÁ¦ºÜÇ¿µÄ²¡¶¾£¬£¬£¬ £¬£¬£¬£¬£¬½üÆÚÈ«Çò¸÷´ó³§É̾ù¶ÔÆä½øÐÐÁËÔ¤¾¯£¬£¬£¬ £¬£¬£¬£¬£¬Æä¾ß±¸É³ºÐÌÓÒÝ¡¢´úÂë»ìºÏ¡¢·´µ÷ÊÔ¡¢C&C/URL¼ÓÃܺÍÓÐÐ§ÔØºÉ¼ÓÃܵȶàÖÖÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚGuloaderÓµÓнÏÇ¿µÄÃâɱÄÜÁ¦ºÍÆ¥µÐ»úÔ죬£¬£¬ £¬£¬£¬£¬£¬Òò¶øÊܵ½´óÁ¿ºÚ¿ÍµÄÇàíù¡£¡£¡£¡£¡£¡£¡£±¾Åú¹¥»÷ÖУ¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¾Í¿í·ºµØÀûÓÃGuloaderÏÂÔØÕß²¡¶¾½áºÏÔÆ·þÎñÀ´·Ö·¢ÇÔÃܹ¤¾ß»òÔ¶³Ì½ÚÔ취ʽ£¨RAT£©¡£¡£¡£¡£¡£¡£¡£


ÎÒÃÇͨ¹ýËÝÔ´·ÖÎöÈ·¶¨Õâ´Î¹¥»÷»î¶¯À´×ÔÄáÈÕÀûÑÇ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ¹ØÁª³öÁË´óÅúÁ¿µÄºÚ¶ñÒâÓòÃû£¨¹¥»÷ÕßʹÓþ³±íµÄDuck DNS×¢²á¶¯Ì¬ÓòÃû£©ºÍIPµØÖ·¡£¡£¡£¡£¡£¡£¡£Í¨¹ý¶Ô¹¥»÷ÕßʹÓõÄÍøÂç»ù´¡ÉèÊ©£¬£¬£¬ £¬£¬£¬£¬£¬×·×Ù·ÖÎö·¢ÏÖÕâ´Î¹¥»÷»î¶¯×îÔç¿É×·Òäµ½2020Äê1Ô¡£¡£¡£¡£¡£¡£¡£½øÒ»²½·ÖÎöÎÒÃÇ·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬ÕâÅú¹¥»÷ÕߵĹ¥»÷¶¯»ú¡¢¹¥»÷Ö¸±ê¡¢×÷Òµ·ç¸ñÓëSWEEDºÚ¿Í×éÖ¯¼«ÎªÀàËÆ£¬£¬£¬ £¬£¬£¬£¬£¬ËûÃÇ»¹ÓÐ×ÅÀàËÆµÄ¹¥»÷ϰ¹ß£¬£¬£¬ £¬£¬£¬£¬£¬²¢Ê¹ÓÃÒ»ÑùÇÔÃÜľÂí·¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°Í¬Ñù·ç¸ñµÄC&CµØÖ·¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇ´§¶ÈÕâÅú¹¥»÷±³ºóÓ¦¸Ã¾ÍÊÇSWEEDºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¡£SWEEDÊÇÒ»¸öÀ´×ÔÄáÈÕÀûÑǵÄÒÔ»ñÈ¡¾­¼ÃÀûÒæÎªÖØÒªÖ÷ÕŵĺڿÍ×éÖ¯£¬£¬£¬ £¬£¬£¬£¬£¬Æä×îÔç³öÏÖÓÚ2017Ä꣬£¬£¬ £¬£¬£¬£¬£¬³£ÀûÓù«¿ªÅû¶µÄ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬½èÖúÓã²æÊ½´¹µöÓʼþÀ´´«²¼Ä¾Âí·¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬ÈçAgent Tesla¡¢FormbookºÍLokibotµÈ¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔøÔÚÔçÆÚ±»Åû¶µÄ¹¥»÷»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýÇÔÈ¡±»¹¥»÷Ö¸±êÓû§ºÍÆóÒµÃô¸ÐÐÅÏ¢Ö´ÐÐÖÐÑëÈ˹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬ÓÕʹ²ÆÕþÈËÔ±½«¿î×ÓתÖÁÖ¸¶¨ÕË»§£¬£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»¸öµäÐ͵ÄÍøÂçÚ¿Æ­ÍŻ¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅADLab¶Ô±¾´Î¹¥»÷»î¶¯µÄ¹¥»÷¹ý³ÌºÍ¹¥»÷ÊÖ·¨½øÐÐÁ˾ßÌ嵨·ÖÎöºÍËÝÔ´£¬£¬£¬ £¬£¬£¬£¬£¬²¢¶ÔÆäËùʹÓõÄÐÂÐͶñÒâÈí¼þºÍC&C»ù´¡ÉèÊ©½øÐÐÁËÉî¿Ì×êÑС£¡£¡£¡£¡£¡£¡£ÌáÐѸ÷´óÆóÒµµ¥Ôª×öºÃ°²È«·À±¸¹¤×÷£¬£¬£¬ £¬£¬£¬£¬£¬½÷·ÀºóÐø¿ÉÄܳöÏֵĹ¥»÷¡£¡£¡£¡£¡£¡£¡£



¶þ¡¢¹¥»÷Ö¸±êºÍÊܺ¦ÕßÉ¢²¼


½ØÖ¹µ½2020Äê6Ô£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖ¹¥»÷ÕߵijÁµãÖ¸±êΪ´ÓʶԱíÒµÎñµÄÖÐÓ×ÐÍÆóÒµ£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÖ÷ÕÅÊÇͨ¹ýÖ²ÈëÌØ¶¨µÄºóÃÅÒÔʵÏÖ¶ÔÖ¸±êÍÆËã»ú½øÐÐÐÅÏ¢ÍøÂçºÍ³Ö¾Ã¼à¿Ø£¬£¬£¬ £¬£¬£¬£¬£¬²¢Îª½ÓÏÂÀ´µÄºáÏòÒÆ¶¯¹¥»÷Ìṩ»ù´¡¡£¡£¡£¡£¡£¡£¡£


2.1 µØÓòÉ¢²¼


ͨ¹ý¶ÔÒÑÖªµÄSWEED×éÖ¯¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĹú¶ÈºÍµØÓòÉ¢²¼Çé¿ö½øÐÐͳ¼Æ£¨Èçͼ2-1£©£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇÄܹ»¿´µ½¸Ã×éÖ¯ÌáÒéµÄ¹¥»÷»î¶¯¸²¸ÇÁ˺öà¹ú¶ÈºÍµØÓò£¬£¬£¬ £¬£¬£¬£¬£¬Óɴ˲²â£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ¹¥»÷Ö¸±êµØÀíµØÎ»µÄÑ¡ÔñÉϲ¢Ã»ÓÐÌØ¶¨µÄÖ¸ÏòÐÔ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ2-1 Êܺ¦Õß¹ú¶ÈµØÓòÉ¢²¼Í¼


2.2 ÐÐҵɢ²¼


ͳ¼ÆÁ˾ÖÏÔʾ£¨Èçͼ2-2£©£¬£¬£¬ £¬£¬£¬£¬£¬Õâ´ÎSWEED×éÖ¯ÔÚÃæÏòÈ«ÇòµÄ¹¥»÷ÖУ¬£¬£¬ £¬£¬£¬£¬£¬ÔËÊä¡¢Ôì×÷ÒµºÍÄÜÔ´ÐÐÒµÒÀÈ»ÊÇÆä³ÁµãÕë¶ÔµÄÖ¸±ê¶ÔÏ󡣡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ2-2 Êܺ¦ÕßÐÐҵɢ²¼Í¼


Èý¡¢¹¥»÷ÊÂÎñ·ÖÎö


±¾Ó×½Ú×ܽáÁ˸Ã×éÖ¯ÔÚ½üЩÄêµÄ¹¥»÷»î¶¯¹¦·òµã¡¢Õâ´ÎÐж¯ÖÐʹÓõĹ¥»÷ÊÖ·¨ÒÔ¼°¹¥»÷Á÷³Ì¡£¡£¡£¡£¡£¡£¡£


3.1 ¹¥»÷»î¶¯¹¦·òÏß


ΪÁ˶ԺڿÍ×éÖ¯ÔÚÕâ´Î¹¥»÷»î¶¯Ê¹ÓõÄÕ½ÊõºÍ¼¼Êõ½øÐÐÈ«ÃæµÄÏàʶ£¬£¬£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab×êÑÐÈËÔ±½«Ä¿Ç°¹ØÁªµ½µÄ¸Ã×éÖ¯½ü¼¸ÄêµÄÖØÒª»î¶¯×öÁËÊáÀíºÍ×ܽᣬ£¬£¬ £¬£¬£¬£¬£¬²¢»æÔìÁË¡°SWEED×éÖ¯¡±»î¶¯¹¦·òÖᣨÈçͼ3-1£©¡£¡£¡£¡£¡£¡£¡£´Ó¹¦·òÖáÄܹ»¿´³ö£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã×éÖ¯µÄ´ó²¿ÃŻ¶¼ÓµÓÐÒ»ÖÂÐÔ¡ª¡ª½èÖú´øÓжñÒ⸽¼þµÄÓã²æÊ½´¹µöÓʼþ·Ö·¢Ô¶¿ØÄ¾Âí·¨Ê½£¨RAT£©£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÐж¯ÖÐʹÓõÄľÂí·¨Ê½ÖØÒªÊÇÒÔAgent TeslaΪÖ÷¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ3-1 SWEED×éÖ¯Óйػ¹¦·òÖá


3.2 ¹¥»÷ÊÖ·¨ºÍÌØµã


SWEED×éÖ¯ÔÚ³õʼ»·½ÚÖØÒªÒÔͶµÝ´¹µöÓʼþÆðÍ··¢Õ¹¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚǰÆÚ¶ÔÖ¸±êÓû§½øÐÐÉî¿Ìµ÷ÑУ¬£¬£¬ £¬£¬£¬£¬£¬°ÎÈ¡ÓëÖ¸±êÓû§ËùÊôÐÐÒµ»òÁìÓòÓйصÄÄÚÈÝÀ´»ú¹ØÓʼþºÍ¶ñÒâÎĵµ¡£¡£¡£¡£¡£¡£¡£Ëæºó½«¾«ÐÄÔì×÷µÄÖ÷ÌâÈ硱²É¹º¶©µ¥¡±¡¢¡°´¹Î£ÔËÊäÎļþ¡±¡¢¡±×°´¬Í¨Öªµ¥¡°µÈÎĵµÔö³¤ÔÚÓʼþ¸½¼þÖз¢Ë͸øÖ¸±êÓû§£¬£¬£¬ £¬£¬£¬£¬£¬ÓÕʹÆäÏÂÔØ¸½¼þ£¬£¬£¬ £¬£¬£¬£¬£¬Ö¸±êÓû§Ò»µ©´ò¿ª´øÓзì϶µÄ¶ñÒâÎĵµ£¬£¬£¬ £¬£¬£¬£¬£¬´¥·¢·ì϶µÄ¶ñÒâ´úÂë¾Í½«»áÔÚºó¶Ü¾²Ä¬ÏÂÔØºÍÖ´ÐжñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÇÔȡָ±êÓû§µÄÃô¸ÐÐÅÏ¢²¢¶ÔÆäÖ÷»ú½øÐнÚÔì¡£¡£¡£¡£¡£¡£¡£


3.2.1 Óã²æÓʼþ


8827Ì«Ñô¼¯ÍÅADLabͨ¹ý¶ÔSWEED×éÖ¯ËêÊ×ÖÁ½ñµÄ¹¥»÷Ðж¯½øÐмà²âºÍ¹ØÁª·ÖÎöºó£¬£¬£¬ £¬£¬£¬£¬£¬ÊáÀí³ö¼¸Ê®Æð¶¨ÏòÖ¸±êµÄ¹¥»÷´¹µöÓʼþ¡£¡£¡£¡£¡£¡£¡£²¿ÃÅÓйØÓʼþÐÅÏ¢¼û±í3-1¡£¡£¡£¡£¡£¡£¡£


±í3-1 ²¿ÃÅ´¹µöÓʼþ°¸ÀýÐÅÏ¢


¹¦·ò

ÓʼþÖ÷Ìâ

·¢¼þÈË

ÊÕ¼þÈË

2020Äê6ÔÂ10ÈÕ

RE : URGENT!!! 2 x 20ft - SHIPPING DOC BL,SI,INV#462345 //\r\n MAERSK KLEVEN V.949E // CLGQOE191781 //

"A.P. Moller ¨C Maersk"

nooreply@maersk.com

undisclosed-recipients

2020Äê6ÔÂ9ÈÕ

M/V BCC - Port Agency Appointment

InterTrans OPS¡± operation@inter-trans.co

jameshall@compasspub.com

2020Äê6ÔÂ8ÈÕ

AGENCY APPOINTMENT/ MV SHOTAN /DISCHARGING/PDA

df15ae634578@6b74fbd36.cn

9ed08@dcc762b7ba3.uk

2020Äê5ÔÂ17ÈÕ

PAYMENT ADVICE-TELEGRAPHIC

TRANSFER NO. M88SI1808BU00250

11@c7c7bacd336b.com

undisclosed-recipients

2020Äê4ÔÂ29ÈÕ

Purchase Order /APO-074787648

jane.hsieh@sealking.com.tw

gjchristopher@safeguard-technology.com

2020Äê4ÔÂ24ÈÕ

[ D.H.L ] Document Arrival  Notice

royalcrown_travel@hotmail.com

Anna.Chitan@linde.com

2020Äê4ÔÂ23ÈÕ

Shipment Arrival Notice

noreply@dhl.com

andrea.schilling@silloptics.de

2020Äê4ÔÂ21ÈÕ

SF Express£ºÄúµÄ°ü¹ü¸üÐÂ

no-reply@sendover.net

info@kraeber.de

2020Äê4ÔÂ7ÈÕ

Returned Payment MT103 Swift

shipping@angloeastern.com

undisclosed-recipients

2020Äê3ÔÂ24ÈÕ

RE: New Order (PO Ref: 01002020)

account@dongbuhitek.co.kr

undisclosed-recipients

2020Äê3ÔÂ23ÈÕ

RE: M/V BLUE LOTUS/NOON RPT

/VOY BL 03.20/ DD 24th

March 2020- APPOINTMENT REQUEST

shahid@erawanaircargo.com

undisclosed-recipients

2020Äê3ÔÂ17ÈÕ

RE : RE : URGENT SHIPPING DOC BL,SI,INV

462345//MAERSK KLEVEN

V.949E//CLGQOE191781//

nooreply@maersk.com

unrecognized@sys.redcondor.com

2020Äê3ÔÂ17ÈÕ

VSL: MV FORTUNE TRADER

Oriental Logistics Group Limited cindy@persadanusantara.co.id

undisclosed-recipients

2020Äê3ÔÂ16ÈÕ

New order by sea FO1909009

acct@gandptech.com

undisclosed-recipients

2020Äê3ÔÂ16ÈÕ

P.I, P.O/MT SR YUJIN (SYNTEK)

bright@kj-global.co.kr

undisclosed-recipients

2020Äê3ÔÂ9ÈÕ

RE: Refund of deposit

pffb@comsats.net.pk

undisclosed-recipients

2020Äê2ÔÂ21ÈÕ

WG: New Order

Anja.Sieveritz@hsm.eu

holthausen@einstein.br

2020Äê2ÔÂ19ÈÕ

RE 2 second lot FCL shipment #48897 Ex works price

Zhejiang Meto Electrical Co.

operations@labcosulich.com

2020Äê2ÔÂ19ÈÕ

Request For Quotation (RFQ-008342)

purchase@auronapharma.com

kbrooks@alpinecom.net

2020Äê2ÔÂ19ÈÕ

?? ?? (?? ??) ???? ??

usef3@hotmail.com

monstar1234@knps.or.kr

2020Äê2ÔÂ18ÈÕ

RE: Revised Cargo Receipts/Documents.

ojs@ojshipping.co.kr

undisclosed-recipients




ͨ¹ý¶ÈÎöÕâЩÓÊÏä·¢¼þÈËËùÊô¹«Ë¾µÄ×¢²áÐÅÏ¢ÒÔ¼°Æä¹ÙÍøÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÎÞÊý¹«Ë¾ÍøÕ¾¾ùΪºÏ·¨ÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬£¬Óɴ˲²⹥»÷ÕßʹÓõÄÕâЩÓÊÏ䣬£¬£¬ £¬£¬£¬£¬£¬ÓпÉÄÜÀ´×Ô±»ÈëÇֺ͵ÁÓõĺϷ¨ÊµÌå»òÓ×ÎÒ¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»ÊÕ¼þÈ˵ÄÐÅÏ¢ºÃ¶àÎÞ·¨¿´µ½£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÊÇ´ÓÓʼþµÄÖ÷ÌâÒÔ¼°ÕýÎÄÄÚÈݲ»ÄÑ¿´³ö£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õ߯óIJÀûÓÃÔËÊä»õÎïÇåµ¥¡¢×°Ïä½»»õ¼Ûµ¥¡¢ÎïÆ·µ½»õ֪ͨµ¥¡¢º£ÉÏж©µ¥µÅ×ʼþÏòÔËÊäÉÌ¡¢Ôì×÷É̼°ÆäºÏ×÷É̽øÐÐÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÎÒÃÇ´ÓÒÔÉÏÓʼþÖÐÁоÙÒ»¸ö×öµ¥Ò»·ÖÎö¡£¡£¡£¡£¡£¡£¡£


Ôڴ˰¸ÀýÖУ¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼʹÓá°VSL: MV FORTUNE TRADER¡±Ö÷Ìâ¼ÙÒâ¡°MV Fortune Trader¡±¡£¡£¡£¡£¡£¡£¡£´¬²°FORTUNE TRADERÊÇÒ»ËÒ½¨ÓÚ1994ÄêµÄ¼¯×°Ïä´¬£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã´¬²°µÄ×¢²á¹ú¶ÈΪº«¹ú¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-2 ´¬²°FORTUNE TRADERÓйØÐÅÏ¢


ÓʼþÕýÎÄÓëÖ÷Ìâά³ÖÒ»Ö£¬£¬£¬ £¬£¬£¬£¬£¬ÏÔʾ¸ÃÓʼþÊÇÀ´×Ô³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾×ܲ¿Î»ÓŲ́Íą̊±±£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÌṩº£ÔË¡¢¿ÕÔ˺ÍÖиÛÔËÊäµÈÒµÎñ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-3 ³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾Ö÷Ò³


ÓʼþÕýÎÄÈçͼ3-4£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-4 ÓʼþÕýÎÄÐÅÏ¢


¶ÔÓʼþÐÅÏ¢½øÐнâÎöºóÈçͼ 3-5Ëùʾ£¬£¬£¬ £¬£¬£¬£¬£¬·¢¼þÈ˵ÄÓʼþµØÖ·ÊÇÓ¡¶ÈÄáÎ÷ÑÇÒ»¼ÒÃûΪ¡°PT.INTI PERSADA NUSANTARA¡±µç»úÉ豸¹«Ë¾µÄºÏ·¨Óò£¬£¬£¬ £¬£¬£¬£¬£¬¶ø¸ÃÓʼþÏÖʵÉÏÊÇÓÉÍйÜÔÚus10.rumahweb.comÉϵÄRoundcube WebÓʼþ·þÎñÆ÷·¢ËÍ¡£¡£¡£¡£¡£¡£¡£ÕâÀïÊÕ¼þÈ˵ØÖ·Ö®ËùÒÔÏÔʾΪ¡°Undisclosed-Recipient¡±£¨µ¼ÖÂÎÞ·¨¿´µ½ÊÕ¼þÈËÐÅÏ¢£©£¬£¬£¬ £¬£¬£¬£¬£¬²Â²â¹¥»÷ÕßÊÇÔÚʹÓÃRoundcube Webmail/1.3.8Èí¼þȺ·¢Óʼþʱ£¬£¬£¬ £¬£¬£¬£¬£¬ÎªÁ˲»ÈÃÊÕ¼þÈË¿´µ½ÆäËû½Ó¹ÜÓʼþÈ˵ĵØÖ·£¬£¬£¬ £¬£¬£¬£¬£¬¹Ê½«´Ë´¦ÉèÖÃΪUndisclosed-Recipient¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-5 ²¿ÃÅÓʼþÍ·²¿ÐÅÏ¢


3.2.2 µö¶üÎļþ


ͨ¹ý¶Ô¸ÃÅú½Ø»ñµÄÓʼþ½øÐзÖÎöËùµÃ£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓõĹ¥»÷ÔØºÉÀàÐÍ×ܹ²ÓÐËÄÖÖ¡£¡£¡£¡£¡£¡£¡£ÏÂÃæ½«ÁоٵäÐ͵Ĺ¥»÷ÔØºÉ¼°ÆäËù¶ÔÓ¦µÄ´¹µöÓʼþ¡£¡£¡£¡£¡£¡£¡£


(1) Я´ø·ì϶Îĵµ


ͼ3-6ÊÇÒ»·â¹¥»÷ÕßðÃûº½¿Õ»õÔ˹«Ë¾·¢Ë͸ø¿Í»§µÄÔ¤Ô¼ÒªÇ󻨏´Óʼþ£¬£¬£¬ £¬£¬£¬£¬£¬¸½¼þ¼Ù×°³É´¬²°¾ßÌåÐÅÏ¢±íµ¥¡£¡£¡£¡£¡£¡£¡£¸ÃÎĵµÊ¹ÓÃ΢ÈíOffice¾­µä·ì϶CVE-2017-11882£¬£¬£¬ £¬£¬£¬£¬£¬µ±Óû§´ò¿ª¶ñÒâÎĵµÊ±£¬£¬£¬ £¬£¬£¬£¬£¬Ç¶Èëµ½ÎĵµÖеĶñÒⷨʽÔò»á×Ô¶¯¼ÓÔØ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄÌØµãÊÇÔÚÕû¸ö¹ý³ÌÖÐÓû§ÆëÈ«ÎÞ¸ÐÖª£¬£¬£¬ £¬£¬£¬£¬£¬ÇÒÔÚ¶ÏÍøµÄÇé¿öÏÂÒÀÈ»¿É´ïµ½ÓÐЧ¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬ËùÒÔ³ÉΪ¸÷´óAPT×éÖ¯±ØÓ÷ì϶ÀûÓÿâÖ®Ò»¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-6 Я´ø·ì϶Îĵµ°¸Àý1¡ªÓʼþ½ØÍ¼


£¨2£©Ð¯´øGZÌåʽµÄѹËõÎĵµ


ͼ3-7Êǹ¥»÷Õß·¢Ë͸ø×ܲ¿Î»ÓÚ±ÈÀûʱµÄÒ»¼Ò¶àÔª»¯µÄ¹¤ÒµÔì×÷É̵ÄÓʼþ£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÓʼþʹÓÃÈȵãµÄCOVID-19ΪÖ÷Ì⣬£¬£¬ £¬£¬£¬£¬£¬²¢Í¨¹ýÕýÎÄÃèÊö»Ñ³Æ¶ñÒ⸽¼þGZѹËõÎĵµÖÐÔ̺¬²É¹ºµ¥£¬£¬£¬ £¬£¬£¬£¬£¬ÓÕʹÊܺ¦ÕßÏÂÔØ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-7 Я´øGZÎĵµ°¸Àý2¡ªÓʼþ½ØÍ¼


¸½¼þÀïÃæÊǼÙ×°³ÉbatÎļþµÄGuloaderÏÂÔØÆ÷¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-8 GZѹËõ°üÀïµÄÎļþ


£¨3£©Ð¯´øISOÌåʽµÄÎĵµ


ÓÉͼ 3-9¿É¼û£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß½«Óʼþ¸½¼þ¼Ù×°³Éϵͳ¾µÏñISOÎļþ£¨Ê¹ÓÃISOÎļþ¿ÉÓÃÓÚÈÆ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£©£¬£¬£¬ £¬£¬£¬£¬£¬½«Æä¶¨ÃûΪ¡°COVID-19½â¾ö¹æ»®°ä·¢¡±ÓÕÆ­Óû§µã»÷¡£¡£¡£¡£¡£¡£¡£Ç¶ÈëÔÚISO¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþΪGuloaderÏÂÔØÆ÷¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-9 ISOѹËõ°üÀïµÄÎļþ


£¨4£©Ð¯´øhtmlÌåʽµÄÎļþ


ͼ3-10Êǹ¥»÷Õß¼ÙÒâDHL Express¹ú¼Ê¿ìµÝ¹«Ë¾·¢Ë͸øµÂ¹úÒ»¼Ò¹âѧ×é¼þÔì×÷É̵Ĵ¹µöÓʼþ£¬£¬£¬ £¬£¬£¬£¬£¬Óʼþ¸½¼þ±»¶¨ÃûΪװ´¬Í¨Öªµ¥²¢ÒÔhtml´ó¾ÖÓÕÆ­Êܺ¦Õßµã»÷¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-10 Я´øhtmlÎļþ°¸Àý3¡ªÓʼþ½ØÍ¼



3.2.3 ¶ñÒâÈí¼þÍйܵØÎ»


ÔÚ¹¥»÷»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʱʱÀûÓÃÔ¶³ÌÅäÖÃÀ´½ÚÔì¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬¶ø°²È«ÈËԱͨ¹ý×êÑзÖÎö·ÖÆçµÄ¶ñÒâÈí¼þÅäÖã¨ÀýÈçÖ÷»úµØÀíµØÎ»ºÍDNSÐÅÏ¢£©£¬£¬£¬ £¬£¬£¬£¬£¬Äܹ»Éî¿ÌµÄÏàʶºÍ×·×Ù¹¥»÷ÕßʹÓõĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇÔÚ×êÑйý³ÌÖн«ÍøÂçµ½µÄ´óÁ¿Ñù±¾Êý¾Ý½øÐÐÌáÈ¡ºÍÕûºÏ£¬£¬£¬ £¬£¬£¬£¬£¬·¢ÏÖSWEED×éÖ¯Õâ´ÎÖ´Ðй¥»÷Ðж¯ËùʹÓõĶñÒâÈí¼þÅäÖ㬣¬£¬ £¬£¬£¬£¬£¬ÖØÒªÀûÓÃÁËGuloaderÏÂÔØÆ÷ÅäÖÃÑ¡ÏîÖеÄÀûÓÃÔÆ·þÎñ·Ö·¢¶ñÒâÈí¼þµÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ®ËùÒÔʹÓÃÕý¹æµÄÔÆ´æ´¢Æ½Ì¨À´ÍйܶñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬ÊÇÓÉÓÚÕâÐ©ÔÆÆ½Ì¨ÎÞÊýÊÇÊÜÐÅÀµµÄÇÒÓÐÖúÓÚÈÆ¹ýóÒ×Íþв¼ì²â²úÆ·¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»Google DriveµÈÔÆÆ½Ì¨Í¨³£Ò²»áÖ´ÐзÀ²¡¶¾¼ì²â£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÈôÊÇÓÐÐ§ÔØºÉÊDZ»¼ÓÃܺóÔÙ´æ´¢£¬£¬£¬ £¬£¬£¬£¬£¬¾ÍÄܹ»¶ã¹ý´ËÀàÏÞ¶È£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÄÜÓÐЧµÄ×èÖ¹°²È«ÈËÔ±¶ÔºÚ¿Í×éÖ¯µÄ»ù´¡ÉèÊ©½øÐÐ×·×Ù¡£¡£¡£¡£¡£¡£¡£Í¼3-11Ϊ¶ñÒâÔØºÉÑù±¾ÍÐ¹ÜÆ½Ì¨µÄʹÓÃÕ¼±ÈÂÊ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝͼÖÐÏÔʾµÄÊýÖµ¿ÉµÃ£¬£¬£¬ £¬£¬£¬£¬£¬Google DriveΪ¶ñÒâÈí¼þÖØÒªÊ¹ÓõÄÍÐ¹ÜÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬ £¬£¬£¬£¬£¬»¹Óв¿ÃŶñÒâÈí¼þ»áÍйÜÔÚÒѱ»¹¥ÏµĺϷ¨ÍøÕ¾ÉÏ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-11ÓÐÐ§ÔØºÉÍÐ¹ÜÆ½Ì¨µÄʹÓÃÂÊ


³ýÁËGoogle DriveºÍOneDrive£¬£¬£¬ £¬£¬£¬£¬£¬ÏÂÃæÎÒÃÇÁоٳö¼¸¸ö¹¥»÷ÕßʹÓÃµÄÆäËûÔÆÍÐ¹ÜÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£

files.fmÊǹú±íÒ»¼ÒÌṩÎļþÔÆ´æ´¢Æ½Ì¨µÄÐÅÏ¢¼¼Êõ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£Í¼3-12ÊDZ£ÁôÔÚ¸ÃÆ½Ì¨µÄ¼ÓÃܵĶñÒâÎļþ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-12 ÔÆÍÐ¹ÜÆ½Ì¨Àý1


sendspaceÊÇÒ»¼ÒÃâ·ÑÎļþÍÐ¹ÜÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£Í¼3-13Êǹ¥»÷ÕßÉÏ´«µ½¸Ãƽ̨½øÐÐÍйܵĶñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ 3-13 ÔÆÍÐ¹ÜÆ½Ì¨Àý2


dmca.gripeÊÇÒ»¸öÃâ·ÑµÄÎļþÍÐ¹ÜÆ½Ì¨£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÖ÷Ò³Èçͼ3-14Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ3-14 ÔÆÍÐ¹ÜÆ½Ì¨Àý3


3.3 ¹¥»÷Á÷³Ì


ÎÒÃǶÔÕâÅú¹¥»÷»î¶¯½øÐÐ×ۺϷÖÎöºó·¢ÏÖ¾ø´ó²¿ÃŹ¥»÷ÓµÓÐÒ»ÑùµÄ¹¥»÷Á÷³Ì£¬£¬£¬ £¬£¬£¬£¬£¬Æä¹¥»÷µÄÁ÷³ÌÈçͼ3-15¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


3-15 ¹¥»÷Á÷³Ìͼ


¹¥»÷Õß¼Ù×°³ÉÎïÁ÷»ò´¬²°µÈ¹«Ë¾ÈËÔ±£¬£¬£¬ £¬£¬£¬£¬£¬ÏòÖ¸±êÆóҵͶµÝЯ´ø¸½¼þµÄ´¹µöÓʼþ£¬£¬£¬ £¬£¬£¬£¬£¬¸½¼þÀàÐÍÔ̺¬£ºÔ̺¬·ì϶µÄ¶ñÒâÎĵµ¡¢GZÌåʽµÄѹËõ°ü¡¢ISOÎļþºÍHTMLÎļþ¡£¡£¡£¡£¡£¡£¡£ÔÚÎÞÊýÇé¿öÏ£¬£¬£¬ £¬£¬£¬£¬£¬ÕâЩ¸½¼þÆð³õ³ÇÊÐÔ̺¬»òÏÂÔØGuloaderÏÂÔØÆ÷£¨ÆäËûÇé¿öÏÂΪԶ¿ØÄ¾Âí£©¡£¡£¡£¡£¡£¡£¡£GuloaderÆðÍ·Ö´ÐÐʱ£¬£¬£¬ £¬£¬£¬£¬£¬ÏȶÔÖü´æÔÚ´úÂ벿ÃŵÄshellcode½øÐнâÃÜ£¬£¬£¬ £¬£¬£¬£¬£¬ÔÙ½«½âÃܺóµÄshellcode×¢Èëµ½RegAsm.exeϵͳÎļþÖУ»£»£»£»£»£»£»½Ó×ÅRegAsm.exeÖеÄshellcodeÔÙ´ÓÖ¸¶¨µÄÔÆÆ½Ì¨µØÖ·ÏÂÔØ¼ÓÃܵÄpayload£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÔÚÄÚ´æÖнâÃÜÖ´ÐÐpayload£¨Ô¶¿ØÄ¾Âí£©£¬£¬£¬ £¬£¬£¬£¬£¬×îºóͨ¹ýC2¶ÔÖ¸±êÖ÷»ú½øÐÐÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì½ÚÔì¡£¡£¡£¡£¡£¡£¡£


Õâ´Î¹¥»÷»î¶¯ÖÐʹÓõ½µÄÇÔÃܺÍÔ¶¿ØÄ¾ÂíÔ̺¬£ºAgent Tesla£¨ÊÇÒ»¿î³ÛÃûµÄóÒ×ÇÔȡľÂí£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÓÃÓÚä¯ÀÀÆ÷¡¢Óʼþ¿Í»§¶Ë¡¢FTP¹¤¾ß¡¢ÏÂÔØÆ÷µÅ×û§Õ˺ÅÃÜÂëºÍWiFiƾ֤µÄÇÔÈ¡¡£¡£¡£¡£¡£¡£¡££©£»£»£»£»£»£»£»Formbook£¨ÊÇÒ»¿îÐÅÏ¢ÇÔȡľÂí£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÖØÒªÒÔÇÔÈ¡Óû§µçÄÔ»úÃÜÐÅϢΪÖ÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬¼üÅ̼ͼ¡¢¼ôÌù°å¼Í¼¡¢cookie»á»°Óë±¾µØÃÜÂëµÈµÈ¡£¡£¡£¡£¡£¡£¡££©£»£»£»£»£»£»£»Lokibot£¨Ò»¿îÇÔÃÜľÂí£¬£¬£¬ £¬£¬£¬£¬£¬Æäͨ¹ý´Ó¶àÖÖÊ¢ÐеÄÍøÂçä¯ÀÀÆ÷¡¢FTP¡¢µç×ÓÓÊÏä¿Í»§¶Ë¡¢ÒÔ¼°PuTTYµÈITÖÎÀí¹¤¾ßÖлñȡƾ֤£¬£¬£¬ £¬£¬£¬£¬£¬À´ÇÔÈ¡Óû§µÄÃÜÂëºÍ¼ÓÃÜÇ®±ÒÇ®°ü£©£»£»£»£»£»£»£»NanoCore£¨ÊÇÒ»¿î.net±àдµÄÔ¶¿ØÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÓµÓмüÅÌ¼à¿Ø¡¢ÊµÊ±ÊÓÆµ²Ù×÷¡¢ÓïÒô¡¢ºÅÁîÐнÚÔìµÈÆëÈ«½ÚÔìÔ¶³ÌÖ÷»úµÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡££©£»£»£»£»£»£»£»Remcos£¨Ò»¿îÔ¶¿ØÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬ÏÂÔØ²¢Ö´ÐкÅÁî¡¢¼üÅ̼ͼ¡¢ÆÁÄ»¼Í¼ÒÔ¼°Ê¹ÓÃÉãÏñÍ·ºÍÂó¿Ë·ç½øÐйàÒô¼ÏñµÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡££©¡£¡£¡£¡£¡£¡£¡£


¼øÓÚÎÒÃÇ·ÖÎöµÄÕâЩľÂíÔÚÖ°Äܺͼ¼ÊõÉÏÓë¾É°æÀàËÆ£¬£¬£¬ £¬£¬£¬£¬£¬²¢Ã»Óз¢ÏÖÌ«¶àµÄ±ä¶¯µã£¬£¬£¬ £¬£¬£¬£¬£¬ËùÒÔÔÚ´ËÎÒÃǽö¶ÔÆäÖØÒªÖ°ÄÜ×öÁ˵¥Ò»µÄÃèÊö£¬£¬£¬ £¬£¬£¬£¬£¬±¾ÎĺóÐø±ã²»ÔÙ¹ý¶àµÄ¾ßÌåÃèÊöÆä¾ßÌåµÄ¼¼Êõϸ½Ú£¬£¬£¬ £¬£¬£¬£¬£¬ÈçÓбØÒª¸÷È˿ɲ鿴ÎÄÄ©µÄ²Î¿¼Îļþ¡£¡£¡£¡£¡£¡£¡£±ÉÈ˸öÕ½Ú£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇÖØÒª¶ÔSWEED×éÖ¯ÐÂÒýÈëµÄGuloader¶ñÒâ´úÂë½øÐÐÆëÈ«¾ßÌ嵨·Ö½â¡£¡£¡£¡£¡£¡£¡£


ËÄ¡¢¼¼Êõ·ÖÎö


ÕýÈçǰÎÄËùÊö£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇÄ¿Ç°ÍøÂçµ½µÄµç×ÓÓʼþµÄ¸½¼þÖØÒª·ÖΪËÄÀà¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»Æä¿ªÊͶñÒâÈí¼þµÄ´ó¾Ö·ÖÆç£¬£¬£¬ £¬£¬£¬£¬£¬µ«ËüÃǵÄÖØÒªÖ°ÄÜÐÐΪ¶¼¸ù»ùÒ»Ö¡£¡£¡£¡£¡£¡£¡£ÔÚÕâÀ£¬£¬ £¬£¬£¬£¬£¬ÎÒÃǰÎȡһ¸öµäÐͰ¸Àý½øÐоßÌå·ÖÎö¡£¡£¡£¡£¡£¡£¡£


4.1 ´¹µöÓʼþ


ͼ4-1Ϊ¹¥»÷ÕßÕë¶ÔÃÀ¹úÒ»¼Ò·À»¬²úÆ·Ôì×÷É̽øÐй¥»÷µÄ´¹µöÓʼþ£¬£¬£¬ £¬£¬£¬£¬£¬´ËÓʼþÓÚÃÀ¹úɽµØÊ±Çø¹¦·ò2020Äê4ÔÂ29ÈÕ£¨ÖÜÈý£©02:31±»·¢Ë͵½¸Ã¹«Ë¾¡£¡£¡£¡£¡£¡£¡£Óʼþ±êÌâΪ¡°Purchase Order /APO-074787648¡±£¬£¬£¬ £¬£¬£¬£¬£¬ÕýÎÄÃèÊöΪ¡°Çë²é¿´Çåµ¥ºÍÈ·ÈÏÉÌÆ·¿â´æ¡±£¬£¬£¬ £¬£¬£¬£¬£¬²¢¸½ÓÐͬÃû¶ñÒâÎĵµ¡°Purchase Order /APO-074787648¡±¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-1 ´¹µöÓʼþÄÚÈÝ


4.2 ¶ñÒâÎĵµ


Ñù±¾¡°Purchase Order /APO-074787648.ppsx¡±ÀûÓÃÁËɳ³æ·ì϶CVE-2014-4114µÄ²¹¶¡£¡£¡£¡£¡£¡£¡£¨MS14-060£©Èƹý·ì϶CVE-2014-6352¡£¡£¡£¡£¡£¡£¡£É³³æ·ì϶ÊÇWindows OLEËÁÒâ´úÂëÖ´Ðзì϶£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶³Ê´Ë¿ÌMicrosoft Windows·þÎñÆ÷ÉϵÄOLE°üÖÎÀíÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÀûÓø÷ì϶ÔÚOLE´ò°üÎļþ£¨packer.dll£©ÖÐÏÂÔØ²¢Ö´ÐÐÀàËÆµÄINFÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬À´´ïµ½Ö´ÐÐËÁÒâºÅÁîµÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£¹ÌȻ΢ÈíΪɳ³æ·ì϶°ä²¼²¹¶¡£¡£¡£¡£¡£¡£¡£¨MS14-60£©£¬£¬£¬ £¬£¬£¬£¬£¬µ«¹¥»÷Õß»¹¿Éͨ¹ý»ú¹ØÌض¨µÄCLSIDºÍOLE VerbÀ´ÈƹýMS14-160²¹¶¡µÄÏÞ¶È£¨CVE-2014-6352£©¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÎÒÃÇÒÔ±¾´ÎÐж¯ÖÐʹÓõĶñÒâÎĵµÎªÀý£¬£¬£¬ £¬£¬£¬£¬£¬¶Ô¸Ã·ì϶µÄʵÏÖµÀÀí×öµ¥Ò»µÄ·ÖÎö¡£¡£¡£¡£¡£¡£¡£


ͼ4-2Ϊ´Ë°¸ÀýÖÐʹÓõÄppsx·ì϶¹¥»÷ÎĵµÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£




8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ4-2 ppsx·ì϶ÎĵµÄÚÈÝ


ÎÒÃǽâѹPPXSÎĵµÄܹ»¿´µ½£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚ¡°Purchase Order APO-074787648.ppsx\ppt\slides \slides.xml¡±ÖУ¬£¬£¬ £¬£¬£¬£¬£¬Ö¸¶¨ÁËǶÈëµÄ¶ÔÏóid=rld3¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-3 ¡°slides.xml¡±ÎļþÄÚÈÝ


ÔÚ¡°Purchase Order APO-074787648\ppt\slides\_rels\slide1.xml.rels¡±ÖÐÖ¸¶¨ÁËrld3¶ÔÓ¦¡°ppt\embeddings\¡±Ä¿Â¼ÏµÄoleObject1.binÎļþ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-4 ¡°slide1.xml.rels¡±ÎļþÄÚÈÝ


¡°Purchase Order APO-074787648.ppsx\ppt\embeddings\¡±Ä¿Â¼Ïµġ°oleObject1.bin¡±ÎļþÄÚǶһ¸öOLE Package¶ÔÏ󣬣¬£¬ £¬£¬£¬£¬£¬Ç¶ÈëÎļþΪPE¿ÉÖ´Ðз¨Ê½¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-5 ¡°oleObject1.bin¡±ÎļþÄÚÈÝ


CVE-2014-4114·ì϶µÄ³ÉÒòÊÇpackager.dllÖÐCPackage::Load²½Öè¼ÓÔØ¶ÔÓ¦µÄOLE¸´ºÏÎĵµ¶ÔÏóʱ£¬£¬£¬ £¬£¬£¬£¬£¬Õë¶Ô·ÖÆçÀàÐ͵ĸ´ºÏÎĵµ½øÐÐ·ÖÆçµÄ´¦ÖÃÁ÷³Ì£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÆäÖжÔijЩ¸´ºÏÎĵµÖÐǶÈëµÄ²»³ÉÐÅÆðÔ´ÎļþûÓÐ×ö´¦Öᣡ£¡£¡£¡£¡£¡£Óɴ˹¥»÷Õß¿ÉʹÓÃαÔìOLE¸´ºÏÎĵµµÄCLSIDÀ´´ïµ½Ö´ÐÐÌØ¶¨ÎļþµÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚMS14-060²¹¶¡ÖУ¬£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýÔö³¤MarkFileUnsafeº¯Êý¶ÔÎļþ½øÐÐMOTW´¦Ö㬣¬£¬ £¬£¬£¬£¬£¬½«ÆäSecurity ZoneÏóÕ÷Ϊ¡°´ËÎļþÀ´×ÔÆäËûÍÆËã»ú¡±£¬£¬£¬ £¬£¬£¬£¬£¬ÔËÐÐʱ»áµ¯³ö°²È«ÖҸ洰¿Ú¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ4-6 ¡°%TEMP%\NEW ORDER.exe¡±ÏóÕ÷Ϊ²»³ÉÐÅÎļþ


µ«¾ÍËãÊܺ¦ÕßÒÑ×°ÖÃMS14-060µÄ²¹¶¡£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß»¹ÊÇÄܹ»Í¨¹ý»ú¹ØÌض¨µÄCLSIDºÍOLE VerbÀ´Å¤×ªÖ´ÐÐÁ÷³Ì£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÈƹý¸Ã²¹¶¡£¡£¡£¡£¡£¡£¡£¨CVE-2014-6352·ì϶£©¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÒ»¸öexeÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬¼´±ã±»ÏóÕ÷ΪURLZONE_INTERNET£¬£¬£¬ £¬£¬£¬£¬£¬ÓÒ¼üµã»÷ÒÔÖÎÀíԱȨÏÞÖ´ÐиÃexeÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Äǵ±·¨Ê½ÔËÐÐʱ±ã²»»áÔÙµ¯³ö¡°°²È«ÖҸ桱£¨Èçͼ4-6£©µÄÌáÐÑ£¬£¬£¬ £¬£¬£¬£¬£¬¶øÊÇÒÔ£¨Èçͼ4-7£©UAC ÌáÐÑ´°µ¯³ö¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ4-7 µ¯³öµÄUACÌáÐÑ´°


  ÓÉ´Ë¿ÉÖª£¬£¬£¬ £¬£¬£¬£¬£¬µ±Êܺ¦Õß´ò¿ª´ËPPSX¶ñÒâÎĵµÊ±£¬£¬£¬ £¬£¬£¬£¬£¬×Ô¶¯²¥·Åģʽ±ã»á¿ªÆô£¬£¬£¬ £¬£¬£¬£¬£¬Í¬Ê±¡°%TEMP%\NEW ORDER.exe¡±½«±»¿ªÊÍÔÚһʱĿ¼ÖС£¡£¡£¡£¡£¡£¡£ÈôÊÇÊܺ¦ÕßÑ¡Ôñ¡°ÊÇ¡±£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂ뽫»á±»Ö´ÐС£¡£¡£¡£¡£¡£¡£¶øÈôÊÇÊܺ¦ÕßµÄϵͳ´¦ÓÚUAC¹Ø¹Ø×´Ì¬»òÔÚ»ñÈ¡ÁËÖÎÀíԱȨÏÞµÄÇé¿öÏ£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃUAC°²È«ÖҸ洰¿ÚÔò²»»áµ¯³ö£¬£¬£¬ £¬£¬£¬£¬£¬¡°NEW ORDER.exe¡±»á±»¾²Ä¬µØÖ´ÐС£¡£¡£¡£¡£¡£¡£



4.3 GuLoader


ÈçÉÏÎÄËùÊö£¬£¬£¬ £¬£¬£¬£¬£¬×îºó±»Ö´Ðеġ°NEW ORDER.exe¡±¿ÉÖ´ÐÐÎļþÏÖʵÉϾÍÊÇÎÄÕ¿ªÍ·Ìáµ½µÄGuloader¶ñÒâÈí¼þ£¨ÔÚºóÐø¶Ô¡°NEW ORDER.exe¡±µÄ¾ßÌå·ÖÎöÖУ¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃǾùʹÓá°Guloader¡±À´´úÌæ¸ÃÎļþÃû£©¡£¡£¡£¡£¡£¡£¡£GuloaderÊÇÒ»¿îÐÂÐ͵ĶñÒâÈí¼þÏÂÔØÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬Æä×ÔÉíÓµÓи´ÔÓµÄÖ´ÐÐÁ÷³Ì£¬£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýѡȡ¸÷Àà´úÂë»ìºÏºÍËæ»ú»¯¡¢·´É³Ïä¡¢·´µ÷ÊÔºÍÊý¾Ý¼ÓÃܵȻúÔìÀ´Æ¥µÐ°²È«²úÆ·µÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÎÒÃǽ«¶Ô¸ÃGuLoader½øÐÐÉî¿ÌµÄÍÚ¾ò·ÖÎö¡£¡£¡£¡£¡£¡£¡£


4.3.1 Ö´ÐÐÁ÷³Ì


Èçͼ4-8Ëùʾ£¬£¬£¬ £¬£¬£¬£¬£¬ GuLoaderÊ×ÏȽ«Öü´æÔÚ´úÂ벿ÃŵļÓÃÜShellcode½âÃܲ¢Ö´ÐС£¡£¡£¡£¡£¡£¡£Õâ¶ÎShellcodeµÄÖØÒªÖ°ÄÜΪ£ºÒÔ¹ÒÆð·½Ê½´´½¨Ò»¸öϵͳ×Ó¹ý³Ì£¬£¬£¬ £¬£¬£¬£¬£¬Ö®ºó½«±¾¶ÎShellcode×ÔÉí×¢Èëµ½×Ó¹ý³Ì²¢Åú¸Ä·¨Ê½Èë¿ÚµãΪShellcode´¦Ö´ÐС£¡£¡£¡£¡£¡£¡£×îºó´ÓÍйܷþÎñÆ÷¸ßµÍÔØ¼ÓÃܵÄBINÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÏÂÔØºó½«Æä½âÃܺÍÔËÐС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-8 GuloaderÖ´ÐÐÁ÷³Ìͼ


4.3.2 EXE¿ÉÖ´ÐÐÎļþ


£¨1£©´úÂë»ìºÏ

Guloader¿ÉÖ´ÐÐÎļþÊÇÓÉVisual Basic 6˵»°±àдµÄ¡£¡£¡£¡£¡£¡£¡£Ê¹Óù¤¾ß²é¿´ºó·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬Æä²¢Î´Ê¹ÓÃóÒ׿ǽøÐÐ×ÔÉí±£»£»£»£»£»£»£»¤£¬£¬£¬ £¬£¬£¬£¬£¬¶øÊÇʹÓûìºÏ¿Ç³¢ÊÔÆ¥µÐ°²È«²úÆ·µÄ²éɱ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚɱÈí¶ÔóÒ׿DZÈÁ¦Ãô¸Ð£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒóÒ׿Ǽì²âºÍÍѿǼ¼ÊõÒ²±ÈÁ¦³ÉÊ죬£¬£¬ £¬£¬£¬£¬£¬ËùÒÔ»ìºÏ¿Ç²»Ê§ÎªÒ»¸ö²»´íµÄÑ¡Ôñ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»ìºÏ¿Çͨ³£²»´æÔÚͨÓõļì²â²½Ö裬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ¾²Ì¬ÍÑ¿ÇÏà¶Ô½ÏÄÑ£¬£¬£¬ £¬£¬£¬£¬£¬ËùÒÔÆä¶ñÒâÐÐΪ²»Ò×±»·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø¿É³¤¹¦·òµÄ´æ»îÔÚÖ¸±ê»úеÉÏ¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÄæÏò·ÖÎöÈËÔ±À´½²£¬£¬£¬ £¬£¬£¬£¬£¬·ÖÎöÕâÖÖ´ø»ìºÏ¿ÇµÄÑù±¾ÍùÍù»áÆÆ·Ñ´óÁ¿µÄ¾«Á¦£¬£¬£¬ £¬£¬£¬£¬£¬ÎÞÐεÄÔö³¤ÁËÈËÁ¦ºÍ¹¦·ò³É±¾¡£¡£¡£¡£¡£¡£¡£


ͼ4-9ÊÇÒ»¶Î»ìºÏ´úÂëµÄ½ØÈ¡£¬£¬£¬ £¬£¬£¬£¬£¬ÕⲿÃÅ´úÂëʹÓÃÁËÊý¾Ý»ìºÏÖеij£Á¿²ð·Ö£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÖ÷ÕÅÊǰµ²ØÕæÊµµÄ´úÂëÂß¼­£¬£¬£¬ £¬£¬£¬£¬£¬È÷ÖÎöÕßÄÚÐı¼À£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ4-9 ²¿ÃÅ»ìºÏ´úÂë


£¨2£©´úÂë½âÃÜ


¶ñÒâÈí¼þÊ×ÏÈÍÆËã³öÓÃÓÚ½âÃÜshellcodeµÄÃÜÔ¿£¬£¬£¬ £¬£¬£¬£¬£¬ÆäֵΪ£º0x24EBE470¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-10 »ñÈ¡ÃÜÔ¿µÄ¶ñÒâ´úÂë


½Ó×Å£¬£¬£¬ £¬£¬£¬£¬£¬ÎªshellcodeÉêÇëÄÚ´æ¿Õ¼ä£¬£¬£¬ £¬£¬£¬£¬£¬ÔÙʹÓÃÃÜÔ¿½øÐÐXORÔËËã½âÃÜShellcode²¢Ö´ÐС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-11 ½âÃܺÍÖ´ÐÐshellcode


4.3.3 ShellCode


½âÃܺóµÄshellcodeǰÆÚÒ²²ÉÈ¡ÁË´óÁ¿µÄÆ¥µÐ¼¿Á©£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹Óø÷Àà´úÂë»ìºÏ¡¢É³Ïä¼ì²â¡¢·´µ÷ÊԵȼ¼Êõ¼¿Á©À´¶ã±Ü°²È«²úÆ·µÄÐÐΪ¼à²âºÍ²éɱ¡£¡£¡£¡£¡£¡£¡£½öµ±Í¨¹ý¸÷Àà²é³­ÅжÏǰÌáºó£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂë²ÅÆðÍ·Ö´ÐÐÖ÷Ö°ÄÜÐÐΪ¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÎÒÃǽ«¶Ô¶ñÒâ´úÂë×ö¾ßÌåµÄ·ÖÎö¡£¡£¡£¡£¡£¡£¡£


£¨1£©¼ì²âÖ°ÄÜ


¡ñ ´úÂë»ìºÏ

½«½âÃܺóµÄshellcode´ÓÄÚ´æÖÐdump³öÀ´²¢Ê¹ÓÃIDA·´±àÒ룬£¬£¬ £¬£¬£¬£¬£¬Äܹ»¿´µ½shellcodeÖÐʹÓõĻìºÏ¼¼Êõ¡£¡£¡£¡£¡£¡£¡£¶ñÒâ´úÂëÔÚÖ´Ðйý³ÌÖвåÈë»ìºÏº¯Êý£¬£¬£¬ £¬£¬£¬£¬£¬¸Ãº¯ÊýµÄ¹ý³Ì±»Ô׸î³É¶à¸öÌø×ªÁ÷³Ì£¬£¬£¬ £¬£¬£¬£¬£¬Ò»Ïòµ½×îºóÔÙ jmpµ½Ô­À´µÄÕý³£´úÂëÖгÖÐøÖ´ÐÐÏÂÃæµÄÁ÷³Ì¡£¡£¡£¡£¡£¡£¡£Í¼4-12ÊÇshellcodeÔÚÈë¿Ú´¦Å²ÓõĴËÀà»ìºÏº¯ÊýµÄ´úÂëÆ¬¶Î£¬£¬£¬ £¬£¬£¬£¬£¬ºÜÏÔȻͨ¹ý¸Ã²½Ö裬£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜÓÐЧµÄÇÖÈÅ·ÖÎöÕß¶ÔÑù±¾½øÐзÖÎö£¬£¬£¬ £¬£¬£¬£¬£¬ÑϳÁ½µµÍÁË·ÖÎöЧÄÜ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ͼ4-12 »ìºÏºóµÄ´úÂëÆ¬¶Î


¡ñ ¶¯Ì¬»ñÈ¡APIº¯Êý


½Ó×Å£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëͨ¹ý½Ó¼ûPEB->LDRÖеÄInMemoryOrderModuleList»ñÈ¡kernel32.dllµÄ»ùÖ·¡£¡£¡£¡£¡£¡£¡£±éÀúÌáÈ¡¸ÃÄ£¿£¿£¿£¿ £¿éµ¼³ö±í½á¹¹Öдæ·Åº¯ÊýÃûµÄÊý×飬£¬£¬ £¬£¬£¬£¬£¬²¢Ë³´Î½«Ãû³Æ×Ö·û´®×÷Ϊ²ÎÊý´«Èëµ½¹þÏ£Ëã·¨º¯ÊýÖÐ×öÔËË㣬£¬£¬ £¬£¬£¬£¬£¬ÔÙ½«Á˾ÖÓëÓ²±àÂëÊý¾Ý×ö±ÈÁ¦£¬£¬£¬ £¬£¬£¬£¬£¬ÒԴ˲½ÖèÀ´²éÕÒGetProcAddressº¯Êý¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-13 ²éÕÒGetProcAddressº¯Êý


´Ë´¦Ê¹ÓõÄÊÇdjb2µÄËã·¨£¬£¬£¬ £¬£¬£¬£¬£¬ djb2ÊÇÒ»¸ö²úÉúËæ»úÉ¢²¼µÄ¹þÏ£º¯Êý£¬£¬£¬ £¬£¬£¬£¬£¬ÓëLCGµÄËã·¨ÀàËÆ¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸú¯Êý»ú¹Øµ¥Ò»£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃÒÆÎ»ºÍÏà¼ÓµÄ²Ù×÷£¬£¬£¬ £¬£¬£¬£¬£¬ËùÒÔ³£±»ÓÃÀ´´¦ÖÃ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£¾ßÌåËã·¨¼ûͼ4-14¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-14 djb2Ëã·¨´úÂë½ØÍ¼


ÓÉ´ËÎÒÃÇÄܹ»¿´µ½£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔÚº¯ÊýµÄ»ñÈ¡·½ÃæÊÇÀûÓÃLoadLibraryºÍGetProcAddressÕâÁ½¸öº¯Êý½øÐж¯Ì¬µÄ»ñÈ¡¡£¡£¡£¡£¡£¡£¡£¾ßÌåÈçͼ4-15Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-15 ¶¯Ì¬»ñÈ¡APIº¯Êý


¡ñ É³Ïä¼ì²â


¶ñÒâ´úÂëö¾Ù´°¿ÚÊýÁ¿£¬£¬£¬ £¬£¬£¬£¬£¬ÈôÊÇÖµÓ×ÓÚ12ÔòÍ˳ö¹ý³Ì£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ´ËÀ´¼ì²â×ÔÉíÊÇ·ñÔËÐÐÔÚɳÏä»·¾³ÖС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-16 ɳÏä¼ì²â´úÂë


¡ñ ·´µ÷ÊÔ¼¼Êõ


²½Öè1£º

ŲÓÃZwProtectVirtualMemoryº¯ÊýÅú¸Äntdll.dllµÄ¡°.text¡±½ÚÊôÐÔΪ¿É¶Á¿Éд¿ÉÖ´ÐС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-17 Åú¸Äntdll.dll½ÚÊôÐÔ


¶ñÒâ´úÂëͨ¹ýÅú¸ÄDbgBreakPointºÍ DbgUiRemoteBreakinº¯Êý´úÂ룬£¬£¬ £¬£¬£¬£¬£¬Èõ÷ÊÔÆ÷ÎÞ·¨¸½¼Óµ÷ÊÔ·¨Ê½£¨Èçͼ4-18ºÍͼ4-19£©¡£¡£¡£¡£¡£¡£¡£¸øcallŲÓúóÃæÖ¸¶¨Ò»¸öδ֪µØÖ·£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ´ËÒý·¢µ÷ÊÔÆ÷±ÀÀ£Í˳ö¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-18 DbgBreakPointº¯Êý´úÂëÅú¸Äǰºó¶Ô±È


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-19 DbgUiRemoteBreakinº¯Êý´úÂëÅú¸Äǰºó¶Ô±È


²½Öè2£º

½«ZwSetInformationThreadº¯ÊýµÄµÚ¶þ¸ö²ÎÊýÉèÖÃΪThreadHideFromDebugger £¨ÖµÎª17£©£¬£¬£¬ £¬£¬£¬£¬£¬×÷ÓÃÊÇÔÚµ÷ÊÔ¹¤¾ßÖаµ²ØÏ̡߳£¡£¡£¡£¡£¡£¡£ÈôÊǶñÒâÈí¼þ´¦ÓÚ±»µ÷ÊÔ״̬£¬£¬£¬ £¬£¬£¬£¬£¬ÄÇô¸Ãº¯Êý¾Í»áʹµ±Ç°Áг̣¨Í¨³£ÊÇÖ÷Ị̈߳©ÍÑÀëµ÷ÊÔÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹µ÷ÊÔÆ÷ÎÞ·¨³ÖÐø½Ó¹Ü¸ÃÏ̵߳ĵ÷ÊÔÊÂÎñ¡£¡£¡£¡£¡£¡£¡£³ÉЧ¾ÍÏñÊǵ÷ÊÔÆ÷±ÀÀ£ÁËÒ»Ñù¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-20 °µ²ØÏ̴߳ﵽ·´µ÷ÊÔÖ÷ÕÅ


²½Öè3£º

ÔÚʹÓÃZwAllocateVirtualMemoryº¯ÊýÉêÇëÄÚ´æ¿Õ¼äʱ£¬£¬£¬ £¬£¬£¬£¬£¬ÎªÔ¤·À·ÖÎöÈËÔ±ÔÚµ÷ÊÔʱ¶Ô¹Ø¼üº¯Êý϶ϵ㣬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂë»áÌáǰ½«¸Ãº¯ÊýµÄÖ°ÄÜʵÏÖ´úÂ븴Ôìµ½±¾¹ý³Ì¿ÕÏпռäÖУ¬£¬£¬ £¬£¬£¬£¬£¬Ê¹µÃºóÐøÔÚʹÓô˺¯Êýʱֱ½ÓÌø×ªµ½×ÔÉí´úÂëÖÐÖ´ÐС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-21 ¸´Ô캯ÊýÖ°ÄÜʵÏÖ´úÂë


²½Öè4£º

ÔÚŲÓò¿ÃÅÃô¸ÐAPIº¯Êýʱ£¬£¬£¬ £¬£¬£¬£¬£¬»áÏÈŲÓÃ×Ô½ç˵µÄ²é³­º¯Êý×öÅжÏ£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔÏ÷¼õ±»°²È«²úÆ·¼ì²âµÄ¼¸ÂÊ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-22 ²é³­º¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³


¸Ã×Ô½ç˵µÄ²é³­º¯ÊýµÄÖØÒªÖ°ÄÜ£º

¢Ù ½«Å²Óøú¯ÊýǰµÄshellcode´úÂ루ÕýÐò£©°´×Ö½ÚÓë0x4×ֽڵķµ»ØµØÖ·×öÒì»òÔËËã ½øÐмÓÃÜ´¦Ö㻣»£»£»£»£»£»

¢Ú ŲÓÃZwGetContectThreadº¯Êý£¬£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý²é³­_CONTEX½á¹¹ÖеÄDr¼Ä·ÅÆ÷À´ÅжÏÊÇ·ñ   ÔÚµ÷ÊÔ»·¾³ÖУ»£»£»£»£»£»£»

¢Û ÅжÏÕâ´ÎÒª²é³­µÄ¹Ø¼üAPIº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÁ˾ÖΪ·ñ£¬£¬£¬ £¬£¬£¬£¬£¬ÔòŲÓøÃAPIº¯

Êý£¬£¬£¬ £¬£¬£¬£¬£¬²»È»·¨Ê½Ö±½Ó±ÀÀ£Í˳ö£»£»£»£»£»£»£»

¢Ü ͬ¡°²½Öè¢Ù¡±¶Ôshellcode´úÂ루µ¹Ðò£©½øÐнâÃܲ¢Ìø×ªµ½·µ»ØµØÖ·´¦Ö´ÐкóÐøÁ÷³Ì¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-23 ×Ô½ç˵²é³­º¯Êý´úÂë


£¨2£©¶ñÒâÐÐΪִÐÐÖ°ÄÜ

ÈôÊÇÒÔÉÏһϵÁеÄɳÏäÒÔ¼°·´µ÷ÊÔ¼ì²â¶¼Í¨¹ý£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔòÆðÍ·Ö´ÐÐÒÔϼú³Ì£º

¢Ù ¶¯Ì¬»ñȡͼ4-24ÖеÄAPIº¯Êý£¬£¬£¬ £¬£¬£¬£¬£¬²¢½«º¯ÊýŲÓõØÖ·±£ÁôÔÚ²Ö¿âÖС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-24 ¶¯Ì¬»ñÈ¡µÄAPIº¯ÊýÃû³Æ


¢Ú ƾ¾ÝÖ¸¶¨µØÖ·´¦±£ÁôµÄÊý¾ÝÄÚÈÝÌØµã£¨ÈôÊǶñÒâ´úÂëδִÐйý´´½¨×Ó¹ý³ÌÁ÷³Ì£¬£¬£¬ £¬£¬£¬£¬£¬ÄÇ Ã´¸ÃµØÖ·´¦Ô­Êý¾ÝΪÎÞЧÄÚÈÝ£»£»£»£»£»£»£»²»È»£¬£¬£¬ £¬£¬£¬£¬£¬´Ë´¦±£ÁôµÄÊǵ±Ç°¹ý³ÌµÄÈ«õè¾¶¡£¡£¡£¡£¡£¡£¡££©À´Åж¨ÊÇ ·ñ±ØÒª´´½¨×Ó¹ý³Ì¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-25 ÅжÏÊÇ·ñ±ØÒª´´½¨×Ó¹ý³Ì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-26 ¶ÔÖ¸¶¨µØÖ·´¦±£ÁôµÄÊý¾ÝÄÚÈÝ×öÅжÏ


¢Û ŲÓÃCreateProcessInternalº¯ÊýÒÔ¹ÒÆðģʽ´´½¨RegAsm.exe¹ý³Ì¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-27 ´´½¨ÏµÍ³×Ó¹ý³Ì


¢Ü ŲÓÃZwOpenFileº¯Êý£¬£¬£¬ £¬£¬£¬£¬£¬»ñµÃÓ³ÉäÎļþmstsc.exeµÄ¾ä±ú¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-28 »ñÈ¡mstsc.exeµÄ¾ä±ú


¢Ý ʹÓÃZwCreateSectionºÍNtMapViewOfSectionº¯Êý½«¡°mstsc.exe¡±ÎļþÓ³Éäµ½

RegAsm.exeÄÚ´æÖеÄ0x00400000µØÎ»ÉÏ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-29 Ó³ÉäÎļþ


¢Þ ÔÚ¿þÀܹý³ÌÖÐÉêÇëÄÚ´æ¿Õ¼ä£¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ÎÒÃÇÔÚµ÷ÊÔµÄÕû¸öshellcodeдÈëµ½Ö¸±êÄÚ´æÖС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-30 дÈëshellcodeµ½ÏµÍ³×Ó¹ý³ÌÖÐ


¢ß ʹÓÃZwGetContextThreadºÍZwSetContextThreadº¯Êý£¬£¬£¬ £¬£¬£¬£¬£¬»ñÈ¡ºÍÅú¸Ä¹ÒÆðµÄ×Ó Ï̸߳ߵÍÎÄÖÐ¼Ä·ÅÆ÷Öµ£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔʵÏÖ³Á¶¨Ïòµ½shellcodeÈë¿Ú´¦Ö´ÐеÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-31 Åú¸Äϵͳ×Ó¹ý³ÌµÄÖ´ÐÐÈë¿Úµã


¢à Èô¡°²½Öè¢Ý¡±²Ù×÷³É¹¦£¬£¬£¬ £¬£¬£¬£¬£¬Ôò¸´Ô­Ö´ÐÐ×Ó¹ý³Ì£»£»£»£»£»£»£»²»È»ÊµÏÖµ±Ç°·¨Ê½¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-32 Åжϲ½Öè¢ÝÊÇ·ñ²Ù×÷³É¹¦


£¨3£©³É¹¦×¢Èëºó¶ñÒâÐÐΪְÄÜ

ÎÒÃÇÔÚ¶ñÒâ´úÂëŲÓÃNtResumeThreadº¯Êýǰ£¬£¬£¬ £¬£¬£¬£¬£¬¸½¼ÓRegAsm.exe¹ý³Ì²¢ÔÚ×¢ÈëµÄshellcodeÖ´Ðд¦ÉèÖöϵ㣨Èçͼ4-33£©£¬£¬£¬ £¬£¬£¬£¬£¬¶øºóÔÙ³ÖÐøÖ´Ðиú¯ÊýÀ´¸´Ô­Ïß³ÌÔËÐС£¡£¡£¡£¡£¡£¡£¸Ãshellcodeǰ²¿ÃÅÓë֮ǰµÄ²Ù×÷Á÷³ÌÒ»Ñù£¬£¬£¬ £¬£¬£¬£¬£¬½«Ç°ÎÄÃèÊöµÄ¸÷Àà¼ì²â³ÁÐÂÖ´ÐÐÒ»±é£¬£¬£¬ £¬£¬£¬£¬£¬Ö±µ½ÔÚ¡°ÅжÏÊÇ·ñ´´½¨×Ó¹ý³Ì¡±´¦Ìø×ªµ½Áí±íµÄ·ÖÖ§Á÷³Ì¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÎÒÃdzÖÐø¶ÔºóÐøÖ°ÄܽøÐоßÌ嵨·ÖÎö¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-33 ShellcodeÖ´Ðд¦´úÂë


ÅжϿªÆôRegAsm.exe·¨Ê½µÄ¸¸¹ý³ÌÊÇ·ñΪ¡°C:\Users\***\directory\filename.exe¡±¡£¡£¡£¡£¡£¡£¡£

ÈôÊDz»ÊÇ£¬£¬£¬ £¬£¬£¬£¬£¬Ôò½«µ±Ç°¸¸¹ý³ÌÎļþ¸´Ôìµ½¸ÃĿ¼ÖУ¬£¬£¬ £¬£¬£¬£¬£¬½«Æä¶¨ÃûΪfilename.exe²¢³ÁÐÂÖ´ÐУ»£»£»£»£»£»£»

ÈôÊÇÊÇ£¬£¬£¬ £¬£¬£¬£¬£¬ÔòÔÚ×¢²á±íHLM\Software\Microsoft\Windows\CurrentVersion\RunOnceĿ¼Àォ¸Ãõè¾¶Ôö³¤ÔÚ¡°Startup key¡±ÖУ¬£¬£¬ £¬£¬£¬£¬£¬ÒÔʵÏÖ³Ö¾ÃפÁôµÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-34 Ôö³¤×¢²á±íÐÅÏ¢´úÂë


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-35 Ôö³¤×¢²á±í¿ª»úÆô¶¯Ïî


³É¹¦Ôö³¤×¢²á±íÏîºó£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔòÆðͷʹÓÃwinnet.dll¿âÖеÄInternet APIº¯Êý´ÓÔÆÍйܷþÎñÆ÷ÏÂÔØ¼ÓÃܵÄpayload¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-36 ´ÓÔÆÍйܷþÎñÏÂÔØpayload


ÏÂÔØÊµÏֺ󣬣¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔÙ½«Ó²±àÂëµÄÖµÓ뽫payloadµÄ´óÓ××ö±ÈÁ¦£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ´ËÀ´²é³­ÎļþµÄÆëÈ«ÐÔ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ´óÓײ»Æ¥Å䣬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔò»á³ÁÐÂÏÂÔØÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Ö±µ½ÆëȫƥÅäΪֹ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-37 ¼ì²âpayload´óÓ×


ÏÂÔØµ½µÄpayloadÎļþÊÇÓÉ0x40¸ö×Ö½ÚµÄHEXÓ×дÊý×ֺͼÓÃܵÄPEÎļþ×é³É£¬£¬£¬ £¬£¬£¬£¬£¬¾ßÌåÈçͼ4-38Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-38 payloadÄÚÈÝ


½Ó×Å£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔÙʹÓÃ×Ô½ç˵½âÃܺ¯Êý¶ÔÏÂÔØµÄpayload½øÐÐÒì»ò½âÃÜ¡£¡£¡£¡£¡£¡£¡£ÆäÃÜÔ¿Öü´æÔÚshellcode´úÂë0x2032Æ«ÒÆ´¦£¬£¬£¬ £¬£¬£¬£¬£¬ÃÜÔ¿³¤¶ÈΪ0x214¡£¡£¡£¡£¡£¡£¡£½âÃܺ¯ÊýÄÚÈÝÈçͼ4-39Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-39 payload½âÃܺ¯Êý


½âÃܺóµÄPEÎļþÈçͼ4-40Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-40 ½âÃܺóµÄÎļþÄÚÈÝ


×îºó£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂ뽫½âÃܺóµÄPEÎļþ¸²¸Ç0x00400000»ùÖ·µÄÄÚÈÝ£¬£¬£¬ £¬£¬£¬£¬£¬²¢Ìø×ªµ½Èë¿ÚµãÖ´ÐÐpayload¶ñÒⷨʽ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ4-41 Ö´ÐÐpayload


ÔÚÕâ´Î·ÖÎöµÄ°¸ÀýÖУ¬£¬£¬ £¬£¬£¬£¬£¬½âÃܳöµÄpayloadÊÇAgent Tesla¡£¡£¡£¡£¡£¡£¡£¶ÔÓڸöñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚ´ËÎÒÃǾͲ»ÔÙ×ö¹ý¶àµÄ½éÉܺͷÖÎöÁË¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÎÒÃÇ»á¶ÔºÚ¿Í×éÖ¯µÄC&C·þÎñÆ÷»ù´¡ÉèÊ©·¢Õ¹×·×ÙËÝÔ´¡£¡£¡£¡£¡£¡£¡£


Îå¡¢ËÝÔ´×·×Ù


5.1 C&C»ù´¡ÉèÊ©


½ØÖ¹µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇͨ¹ýÌáÈ¡ºÍÕû¶ÙËùÓйØÁªÑù±¾ÖеÄIPµØÖ·ºÍÓòÃûÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬Äܹ»¿´µ½Õâ´Î¹¥»÷Ðж¯ÖØÒªÒÔ¶¯Ì¬ÓòÃûΪÖ÷£¬£¬£¬ £¬£¬£¬£¬£¬´ó²¿ÃÅÓòÃû¶¼ÊÇͨ¹ý¾³±íµÄDuck DNS×¢²á¡£¡£¡£¡£¡£¡£¡£Í¼5-1ΪSWEEDºÚ¿Í×é֯ʹÓõIJ¿ÃÅÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹ØÏµ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-1 ²¿ÃÅÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹ØÏµÍ¼



ƾ¾ÝÑù±¾Í¬Ô´ÐÔ·ÖÎöµÄÁ˾Ö£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖ´óÁ¿µÄÓÐÐ§ÔØºÉ±»±ðÀë¹ÒÔØÔÚ·ÖÆçµÄ¶¯Ì¬ÓòÃûÖУ¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ±¸Ô̺¬·ì϶µÄOfficeÎĵµ»ò¶ñÒâÈí¼þGuloader½Ó¼ûºÍÏÂÔØ¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÓòÃûµÄ²éÎʼͼËùµÃ£¬£¬£¬ £¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯×îÔç¿É×·Òäµ½1ÔÂÖÐÏÂÑ®£¬£¬£¬ £¬£¬£¬£¬£¬Í¬Ê±Ò²Äܹ»¿´µ½£¬£¬£¬ £¬£¬£¬£¬£¬ËüÃÇ×î³õ¾ùʹÓÃÖ¸ÏòÄáÈÕÀûÑǵĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬ £¬£¬£¬£¬£¬ÕâЩÓòÃû½âÎöʹÓõÄIP×ܲ»¶¨ÆÚÔÚ³£ÓõÄIPµØÖ·¶ÎÀ´»ØÇл»¡£¡£¡£¡£¡£¡£¡£¾ßÌåÈçͼ5-2Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-2 ¶¯Ì¬ÓòÃû½âÎöµÄIPµØÖ·


ÎÒÃǽ«C&C¶ÔÓ¦µÄIPµØÖ·ËùÊô¹ú¶ÈºÍµØÓò½øÐÐͳ¼Æ£¬£¬£¬ £¬£¬£¬£¬£¬²¢»æÔìÆäµØÀíµØÎ»É¢²¼Í¼£¨Èçͼ5-3Ëùʾ£©¡£¡£¡£¡£¡£¡£¡£ÕûÌåÀ´¿´£¬£¬£¬ £¬£¬£¬£¬£¬ÃÀ¹úºÍ·¨¹úÕ¼±ÈÂÊ×î¸ß£¬£¬£¬ £¬£¬£¬£¬£¬Æä´ÎΪºÉÀ¼¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-3 C&C¶ÔÓ¦µÄIPµØÀíµØÎ»É¢²¼Í¼


5.2 ¹ØÁªÐÔ·ÖÎö


8827Ì«Ñô¼¯ÍÅADLab½«±¾´Î²¶»ñµ½µÄÑù±¾Í¬ÒÔÍùSWEED»î¶¯×öÁËÈ«ÃæµÄ¹ØÁª·ÖÎö£¬£¬£¬ £¬£¬£¬£¬£¬µÃ³öÒÔϼ¸´¦³ÁÒªµÄ¹ØÁªµã£º


£¨1£©·ì϶Îĵµ

ÔÚÕâ´ÎÐж¯Öй¥»÷×é֯ʹÓõķì϶ÎĵµÓÐÁ½ÀࣨCVE-2017-11882ºÍCVE-2014-6357£©£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÖÐÒÔCVE-2017-11882·ì϶ÀûÓÃÎĵµÎªÖØÒª¹¥»÷ÔØºÉ¡£¡£¡£¡£¡£¡£¡£¶øSWEED×éÖ¯Ò²ÔøÔÚÒÔÍùµÄ¹¥»÷Ðж¯ÖÐÆµÈÔµÄʹÓùý¸Ã·ì϶Îĵµ¡£¡£¡£¡£¡£¡£¡£¾ßÌåÈçͼ5-4Ëùʾ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-4 ·ì϶Îĵµ°¸Àý


£¨2£©¹¥»÷Ö¸±ê


ƾ¾Ý¹«¿ª»ã±¨Äܹ»µÃÖª£¬£¬£¬ £¬£¬£¬£¬£¬SWEEDºÚ¿Í×éÖ¯µÄ¹¥»÷Ö¸±êÖØÒªÕë¶ÔÈ«Çò´ÓʶԱíÒµÎñµÄÖÐÓ×ÐÍÆóÒµ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒËùÉæ¼°µÄÐÐÒµÖØÒªÒÔÔì×÷Òµ¡¢º½ÔË¡¢ÎïÁ÷ºÍÔËÊäΪÖ÷¡£¡£¡£¡£¡£¡£¡£ÕâÓëÎÒÃÇÕâ´Î¼à²âµ½µÄ¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĵØÀíµØÎ»ºÍÐÐҵɢ²¼ÓµÓнϸߵÄÀàËÆÐÔ¡£¡£¡£¡£¡£¡£¡£Í¼5-5ÁоÙÁ˼¸ÀýÔÚ±¾´Î¹¥»÷»î¶¯Öй¥»÷Õß·¢Ë͸øÖ¸±êÓû§µÄ´¹µöÓʼþ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-5 ´¹µöÓʼþ°¸Àý


£¨3£©¹¥»÷±øÆ÷


ÔÚĿǰ¹Û²âµ½µÄÐж¯ÖУ¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß×îÖÕͶ·ÅµÄ¶ñÒâÈí¼þÔ̺¬Agent Tesla¡¢Remcos¡¢NanoCore¡¢FormbookºÍLokibot¡£¡£¡£¡£¡£¡£¡£ÎÒÃǽ«²¶»ñµÄËùÓжñÒâÈí¼þ°´¼Ò×å·ÖÀàºÍͳ¼Æ£¬£¬£¬ £¬£¬£¬£¬£¬Æ¾¾ÝÁ˾ÖÏÔʾ£¬£¬£¬ £¬£¬£¬£¬£¬Agent TeslaµÄÕ¼±ÈÂÊ´¦ÓÚ×î¸ß£¬£¬£¬ £¬£¬£¬£¬£¬Êǹ¥»÷Õß³ÁµãʹÓõĹ¥»÷±øÆ÷¡£¡£¡£¡£¡£¡£¡£¶øÕâÖÖʹÓÃÌØµãÒ²Ôø·´¸´³Ê´Ë¿ÌSWEED×éÖ¯ÒÔǰµÄ¹¥»÷»î¶¯ÖС£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-6 ¶ñÒâÈí¼þ¼Ò×åÕ¼±ÈÂÊ


£¨4£©IPµØÖ·µØÎ»


ÎÒÃÇͨ¹ýWhoisÐÅÏ¢²éÎÊ£¬£¬£¬ £¬£¬£¬£¬£¬·¢´Ë¿ÌÕâ´ÎÐж¯ÖеÄÓòÃû¡°mogs20.xxx.org¡±ÔçÆÚ½âÎöµÄIP£¨105.112.XXX.XXX£©µØÀíµØÎ»Ö¸ÏòÄáÈÕÀûÑÇ£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÍø¶Î¹éÊôÄáÈÕÀûÑǵØÓòµçÐŵÄ105.112¶Î¡£¡£¡£¡£¡£¡£¡£ÕâÓëSWEED×éÖ¯ËùÊô¹ú¶ÈÓµÓи߶ȵÄÒ»ÖÂÐÔ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͼ5-7 Whois²éÎÊÐÅÏ¢ÄÚÈÝ


½áºÏSWEED×é֯һϵÁеĹ¥»÷»î¶¯ÌصãÒÔ¼°ÉÏÃæ×ܽáµÄËĵãÄܹ»¿´³ö£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ¹¥»÷¶¯»ú£¨ÇÔÈ¡Óû§ÐÅÏ¢ÒÔIJÀû£©¡¢¹¥»÷Ö¸±ê£¨Õë¶ÔÈ«Çò¶Ô±íÒµÎñµÄÖÐÓׯóÒµ£©¡¢×÷Òµ·ç¸ñ£¨Í¶µÝ¶¨ÔìÐÍ´¹µöÓʼþ·Ö·¢Ä¾Âí£©¡¢Õ½Êõ£¨¶ã±Ü¼ì²â¡¢³£×¤¡¢ºÅÁîÓë½ÚÔ죩¡¢¼¼Êõ£¨·ì϶ÀûÓã©¡¢¹ý³Ì£¨·¢ËÍЯ´ø¶ñÒ⸽¼þµÄÓʼþ->·ì϶Îĵµ->½âÃÜÔËÐÐAgent TeslaÔ¶¿ØÄ¾Âí£©ÒÔ¼°ÆäʹÓõÄÍøÂç»ù´¡ÉèÊ©µÈ·½Ãæ¶¼¼«¶ÈÇкÏSWEED×éÖ¯µÄÌØµã¡£¡£¡£¡£¡£¡£¡£ÓÉ´ËÎÒÃÇ´§¶È£¬£¬£¬ £¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯Ä»ºóÕߺܿÉÄÜÊÇÀ´×ÔÄáÈÕÀûÑǵÄSWEEDºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¡£


Áù¡¢×ܽá


Æù½ñΪֹSWEEDºÚ¿Í×éÖ¯ÖÁÉÙÒÑ»îÔ¾ÁË4ÄêµÄ¹¦·ò£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¸Ã×éÖ¯½üÆÚµÄ¹¥»÷Äܹ»·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬SWEEDÆðͷʹÓøüÓµÓÐÕë¶ÔÐÔµÄÓʼþÄÚÈݺ͸ü¾ß¹Æ»óÐÔµÄÎĵµ±êÌ⣬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÌá¸ßÊܺ¦ÕßÖÐÕеĸÅÂÊ¡£¡£¡£¡£¡£¡£¡£8827Ì«Ñô¼¯ÍÅADLab½«¸Ã×éÖ¯Õâ´ÎÐж¯TTPµÄ×êÑзÖÎöÁ˾ÖÓëÒÔÍù¸ú½ø»òÅû¶µÄÓйع¥»÷Ðж¯¸öÐÔ×ö±È¶Ôºó£¬£¬£¬ £¬£¬£¬£¬£¬µÃµ½µÄÓйØÖ¤¾Ý¶¼¿ÉÅú×¢ÕâЩÑùÕý±¾×ÔSWEEDºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¡£


SWEED×é֯ʹÓÃGuloaderÏÂÔØÆ÷´«²¼µÄÔ¶³ÌľÂíÖÖÀà¹ÌÈ»¶àÑù»¯£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÖØÒª»¹ÊÇÒÔÆäÆ«ºÃµÄAgent TeslaΪÖ÷¡£¡£¡£¡£¡£¡£¡£´ÓÆäËùʹÓõÄTTPÀ´¿´£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃºÚ¿Í×é֯Ŀǰ²¢Î´¾ß±¸ºÜºÃµÄ×ÔÑпª·¢ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£ÔÚÎÞÊýÇé¿öÏ£¬£¬£¬ £¬£¬£¬£¬£¬½ö»á´Ó¹ú±íһЩÖ÷Á÷ºÚ¿ÍÍøÕ¾ÉϲɰìľÂíÌìÉúÆ÷ºÍ¼ÓÃܹ¤¾ßÀ´×÷Ϊ¹¥»÷±øÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬ÀýÈçÔøÊ¹ÓõÄKazyCypterºÍÕâ´ÎʹÓõÄGuloader¡£¡£¡£¡£¡£¡£¡£²»Í⣬£¬£¬ £¬£¬£¬£¬£¬¼´±ã¹¥»÷ÕßÔÚ¼¼ÊõÄÜÁ¦ÉÏÏà¶Ô½ÏÈõ£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÆäÔÚÉ繤¼¼ÇɺͶàÑù»¯¹¥»÷·½Ê½µÄÀûÓÃÃæÉÏ»¹ÊǽÏΪ´¿ÊìµÄ¡£¡£¡£¡£¡£¡£¡£ÔÚ´Ë£¬£¬£¬ £¬£¬£¬£¬£¬½¨ÒéÓû§¾¡Á¿Ô¤·À´ò¿ª²»Ã÷À´ÀúµÄÓʼþÒÔ¼°¸½¼þÎļþ£¨À´×Ôδ֪·¢ËÍÕߵģ©£¬£¬£¬ £¬£¬£¬£¬£¬ÊµÊ±×°ÖÃϵͳ²¹¶¡£¬£¬£¬ £¬£¬£¬£¬£¬Ìá¸ß·çÏÕÒâʶ£¬£¬£¬ £¬£¬£¬£¬£¬·À±¸´ËÀà¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£




Æß¡¢IOC


MD5

F97CFA6C3F1338B597768808FC1B2F00

B1941921571C2B6ED0C3BDA77E402001    

DD82B2E488811E64BB9C039C441DB19C

EC4CF91427DAC3AD29CD2A52B0789DC6

166FD7B0C74C60DCBC80BF335D712EA2

BCBCC89F237B22F21BDAE9E6555404A

60147B91AB7B64B9BE27BD3422147E60

48408BBE8D9EE22D6BBB6820FCCC305F

7DDA46F2D9008FAE016AFFF39E9C5801

A22A37E699C20D42753D35A94A75B365

C36C41EB6A34880459154334681C203A

6BC92ACB050A2068EFF4842A1D360938

FB7ED44C2BAAA6F011F7BF51DE721BC4

58604AE63AEA84483C67980369958ACB

312BFAFE6746645E72FCB84ECBFB023C

779EB99965F1AAC12363632468DF7DCE

DD49030C00EF3C2341BCBE4489DCEF63

IP

167.114.85.125

URL

https://drive.google.com:80/uc?export=download&id=1lmmu6kv5ep_wkm7hfyhdshru-y1n2pqv

https://onedrive.live.com/download?cid=554BBD19BDD72613&resid=554BBD19BDD72613!156&authkey=AGIuaWEkkBxB_4o

https://drive.google.com/uc?export=download&id=1W3ddZnmArVGhsecoWW5KcQAKPZ9OacLU

https://share.dmca.gripe/iQakn267f3ZvpDN.bin

http://167.114.85.125/go/Origin%20server%20ilyas_tTzYDNEGay108.bin



°Ë¡¢²Î¿¼Á´½Ó


[1]https://www.fortinet.com/blog/threat-research/new-agent-tesla-variant-spreading-by-phishing

[2]https://www.fireeye.com/blog/threat-research/2017/10/formbook-malware-distribution-campaigns.html

[3]https://www.fortinet.com/blog/threat-research/new-infostealer-attack-uses-lokibot

[4]https://success.trendmicro.com/solution/1122912-nanocore-malware-information

[5]https://www.fortinet.com/blog/threat-research/remcos-a-new-rat-in-the-wild-2





8827Ì«Ñô¼¯ÍÅ»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬£¬ £¬£¬£¬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬£¬ £¬£¬£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬£¬ £¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£¡£¡£¡£¡£¡£¡£½ØÖ¹Ä¿Ç°£¬£¬£¬ £¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶1000Óà¸ö£¬£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶800Óà¸ö£¬£¬£¬ £¬£¬£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÒÆ¶¯ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£¡£¡£¡£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website