Õý¶ù°Ë¾Ëµ¼¼Êõ¡ª¡ªÒÔEmotetΪÀýÉî¿Ì·ÖÎöCMDºÅÁî»ìºÏ¼¼Êõ
°ä²¼¹¦·ò 2018-12-13CMDºÍPowershellºÅÁîʱʱ±»ÓÃÔÚ¶ñÒâÈí¼þÖÐÖ´ÐжñÒâ¾ç±¾Îļþ£¬£¬£¬£¬£¬²¢Í¨¹ý¾ç±¾»ìºÏ¡¢¼ÓÃÜ»ò±àÂ뷽ʽÀ´ÈƹýAV¼ì²â¡£¡£¡£¡£¡£¡£¡£±¾ÎÄÁоÙÁ½¸öµäÐ͵ÄEmotet´«²¼ÖÐʹÓõĻìºÏCMDºÅÁ£¬£¬£¬£¬À´Éî¿Ì·ÖÎöCMD.ºÅÁî»ìºÏ¼¼Êõ¡£¡£¡£¡£¡£¡£¡£
ÏÈ¿´Ò»¸ö´ÓDOCÎĵµÇ¶ÈëµÄVBAºê´úÂëÖÐÌáÈ¡µÄCMDºÅÁ£¬£¬£¬£¬Õ§Ò»¿´ÉÏÈ¥£¬£¬£¬£¬£¬ÏñÊÇÎÞÒâ˼µÄÒ»´®×Ö·û£¬£¬£¬£¬£¬×Ðϸ·ÖÎöÆðÀ´±ØÒªÏÈÏàʶһÏÂCMDºÅÁîµÄ»ìºÏ·½Ê½¡£¡£¡£¡£¡£¡£¡£
CMDºÅÁîµÄ»ìºÏ·½Ê½
²åÈëÌØÊâ×Ö·û»ìºÏºÅÁî
×Ö·û¡°^¡±ÊÇCMDºÅÁîÖÐ×î³£¼ûµÄתÒå×Ö·û£¬£¬£¬£¬£¬¸Ã×Ö·û²»Ó°ÏìºÅÁîµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£ÓÉÓÚÔÚcmd»·¾³ÖУ¬£¬£¬£¬£¬ÓÐЩ×Ö·û¾ß±¸ÌØÊâÖ°ÄÜ£¬£¬£¬£¬£¬Èç >¡¢>>°µÊ¾³Á¶¨Ïò£¬£¬£¬£¬£¬| °µÊ¾¹Ü·£¬£¬£¬£¬£¬&¡¢&&¡¢|| °µÊ¾Óï¾äÏνӡ£¡£¡£¡£¡£¡£¡£ËüÃǶ¼ÓÐÌØ¶¨µÄÖ°ÄÜ£¬£¬£¬£¬£¬ÈôÊDZØÒª°ÑËüÃÇ×÷Ϊ×Ö·ûÊä³öµÄ»°£¬£¬£¬£¬£¬echo >¡¢echo |Ö®ÀàµÄд·¨¾Í»á·¸´í¡ª¡ªcmdÚ¹ÊÍÆ÷»á°ÑËüÃÇ×÷ΪӵÓÐÌØÊâÖ°ÄܵÄ×Ö·û¶Ô´ý£¬£¬£¬£¬£¬¶ø²»»á×÷Ϊͨ³£×Ö·û´¦Ö㬣¬£¬£¬£¬Õâ¸öʱ³½£¬£¬£¬£¬£¬¾Í±ØÒª¶ÔÕâÐ©ÌØÊâ×Ö·û×öתÒå´¦ÖãºÔÚÿ¸öÌØÊâ×Ö·ûǰ¼ÓÉÏתÒå×Ö·û^¡£¡£¡£¡£¡£¡£¡£
Òò¶ø£¬£¬£¬£¬£¬ÒªÊä³öÕâÐ©ÌØÊâ×Ö·û£¬£¬£¬£¬£¬¾Í±ØÒªÓà echo ^>¡¢echo ^|¡¢echo ^|^|¡¢echo ^^Ö®ÀàµÄÌåʽÀ´´¦Öᣡ£¡£¡£¡£¡£¡£Áí±í£¬£¬£¬£¬£¬´ËתÒå×Ö·û»¹Äܹ»ÓÃ×÷ÐøÐзûºÅ¡£¡£¡£¡£¡£¡£¡£
¶ººÅ¡°,¡±ºÍ·ÖºÅ ¡°;¡±Äܹ»»¥»»£¬£¬£¬£¬£¬Äܹ»È¡´úºÅÁîÖеĺϷ¨¿Õ¸ñ¡£¡£¡£¡£¡£¡£¡£¶à¸ö¿Õ¸ñÒ²²»Ó°ÏìºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£
³É¶ÔµÄÔ²À¨ºÅ£¨£©Ò²»á³Ê´Ë¿ÌºÅÁî²ÎÊýÖУ¬£¬£¬£¬£¬Ò²²»Ó°ÏìºÅÁîµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£Ô²À¨ºÅ°µÊ¾Ç¶Èë×ÓºÅÁî×飬£¬£¬£¬£¬Í¬Ñù±»cmd.exe²ÎÊý´¦ÖÃÆ÷½øÐÐÚ¹ÊÍ¡£¡£¡£¡£¡£¡£¡£È磺cmd.exe /c ( ( ((echo Command 1) ) )) &&( ( (((((echo Command 2))))) ) )
ÀûÓÃCMD»·¾³±äÁ¿Æ´½ÓºÅÁî
Cmd.exeÄÚ²¿ºÅÁîÓУº set¡¢assoc £¬£¬£¬£¬£¬ftypeµÈ¡£¡£¡£¡£¡£¡£¡£
SetºÅÁîÓÃÀ´ÏÔʾ¡¢ÉèÖûòɾ³ýcmd.exe»·¾³±äÁ¿¡£¡£¡£¡£¡£¡£¡£ºÅÁîÌåʽ£º
SET [variable=[string]]
variable Ö¸¶¨»·¾³±äÁ¿Ãû¡£¡£¡£¡£¡£¡£¡£
string Ö¸¶¨ÒªÖ¸Åɸø±äÁ¿µÄһϵÁÐ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£
ÔÚºÅÁîÐÐÖÐÊäÈë set£¬£¬£¬£¬£¬»áÁоٳöcmd.exeÖÐËùÓеĻ·¾³±äÁ¿¡£¡£¡£¡£¡£¡£¡£
assoc£ºÎļþÃûÀ©´ó¹ØÁªºÅÁ£¬£¬£¬£¬ÓÃÓÚÏÔʾºÍÉèÖÃÎļþÃûÀ©´ó¹ØÁª£¬£¬£¬£¬£¬Äܹ»Ö¸¶¨Ä³ÖÖºó׺ÃûµÄÎļþÒÀÕÕÌØ¶¨µÄÀàÐÍÎļþ´ò¿ª»òÖ´ÐС£¡£¡£¡£¡£¡£¡£ºÅÁîÌåʽΪ£ºassoc [.ext[=[fileType]]]
.extÊÇÖ¸£ºÖ¸¶¨Òª¹ØÁªµÄÎļþºó׺Ãû¡£¡£¡£¡£¡£¡£¡£µãºÅ£¨.)ÊDz»ÄÜÊ¡ÂԵ쬣¬£¬£¬£¬ÈôÊÇÊ¡ÂÔÁËϵͳ½«ÏÔʾ¸Ãºó׺ÃûÎļþµÄ¹ØÁªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£fileTypeÊÇÖ¸£ºÖ¸¶¨ÓйØÁªµÄÎļþÀàÐÍ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇֻʹÓøòÎÊý£¬£¬£¬£¬£¬½«ÏÔʾ¸ÃÎļþÀàÐ͵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£·´Ö®£¬£¬£¬£¬£¬¸ÃºÅÁÁгöϵͳע²áµÄËØÓкó׺ÃûÎļþºÍÓйصÄÀàÐÍ¡£¡£¡£¡£¡£¡£¡£
ftype£ºÏÔʾ»òÅú¸ÄÓÃÔÚÎļþÀ©´óÃû¹ØÁªÖеÄÎļþÀàÐÍ£¬£¬£¬£¬£¬Ö¸¶¨Ò»ÖÖÀàÐ͵ÄÎļþĬÈÏÓÃÄĸö·¨Ê½ÔËÐлò´ò¿ª¡£¡£¡£¡£¡£¡£¡£ºÅÁîÌåʽΪ£ºftype [fileType[=[openCommandString]]
cmd.exeµÄ»·¾³±äÁ¿·ÖΪϵͳÒÑÓеĻ·¾³±äÁ¿ºÍ×Ô½ç˵±äÁ¿¡£¡£¡£¡£¡£¡£¡£ÀûÓû·¾³±äÁ¿µÄÖµÖеÄ×Ö·û»ò×Ö·û´®£¬£¬£¬£¬£¬Äܹ»Æ´½Ó³ÉºÚ¿Í±ØÒªµÄcmdºÅÁ£¬£¬£¬£¬Í¬Ê±Äܹ»Ìӱܾ²Ì¬¼ì²â¡£¡£¡£¡£¡£¡£¡£ÈçϵͳÒÑÓеĻ·¾³±äÁ¿%comspec%±äÁ¿µÄֵĬÒÔΪ£º¡°C:\WINDOWS\system32\cmd.exe¡±£¬£¬£¬£¬£¬setºÅÁîÄܹ»±»±àÂëΪ£º %comspec:~11,1%%comspec:~-1%%comspec:~-13,1%¡£¡£¡£¡£¡£¡£¡£
%VarName:~offset[,length]% ÖØÒªÓÃÓÚ»ñÈ¡»·¾³±äÁ¿VarNameµÄ±äÁ¿Öµ£¬£¬£¬£¬£¬Æ«ÒÆoffset×Ö½ÚÖ®ºó³¤¶ÈΪlength¸ö×Ö½Ú¡£¡£¡£¡£¡£¡£¡£[,length]¿ÉÊ¡ÂÔ¡£¡£¡£¡£¡£¡£¡£
%comspec:~11,1%°µÊ¾È¡comspec±äÁ¿ÖµÖеÄ×Ö·û£¬£¬£¬£¬£¬Ä¬ÈÏϱê´Ó0ÆðÍ·£¬£¬£¬£¬£¬´Óϱê11ÆðÍ·£¬£¬£¬£¬£¬È¡Ò»¸ö×Ö·û£¬£¬£¬£¬£¬¼´Îª¡±s¡±¡£¡£¡£¡£¡£¡£¡£offsetÒ²Ö§³Ö¸ºÊý£¬£¬£¬£¬£¬°µÊ¾·´Ïò±éÀú×Ö·û´®µÄϱꡣ¡£¡£¡£¡£¡£¡£%comspec:~-1%¼´Îª¡°e¡°£¬£¬£¬£¬£¬%comspec:~-13,1%¼´Îª¡±t¡°¡£¡£¡£¡£¡£¡£¡£Èç´Ë±àÂësetºÅÁ£¬£¬£¬£¬Äܹ»ÌÓÍѾ²Ì¬¼ì²â¡±set¡°ºÅÁî×Ö·û´®µÄ¼ì²â»úÔì¡£¡£¡£¡£¡£¡£¡£
ͨ³£ÎÒÃÇÒ²Äܹ»×Ô½ç˵һ¸ö»òÕß¶à¸ö»·¾³±äÁ¿£¬£¬£¬£¬£¬ÀûÓû·¾³±äÁ¿ÖµÖеÄ×Ö·û£¬£¬£¬£¬£¬ÌáÈ¡²¢Æ´½Ó³ö×îÖÕÏëÒªµÄcmdºÅÁî¡£¡£¡£¡£¡£¡£¡£Èç:
Cmd /C ¡°set envar=net user && call echo %envar%¡° Äܹ»Æ´½Ó³öcmdºÅÁnet user
Ò²Äܹ»½ç˵¶à¸ö»·¾³±äÁ¿½øÐÐÆ´½ÓºÅÁî´®£¬£¬£¬£¬£¬Ìá¸ß¾²Ì¬·ÖÎöµÄ¸´ÔÓ¶È£º
cmd /c ¡° set envar1=ser&& set envar2=ne&& set envar3=t u&&call echo %envar2%%envar3%%envar1%¡±
cmdºÅÁîµÄ¡°/C¡±²ÎÊý£¬£¬£¬£¬£¬Cmd /C ¡°string¡±°µÊ¾£ºÖ´ÐÐ×Ö·û´®stringÖ¸¶¨µÄºÅÁ£¬£¬£¬£¬¶øºóÖÕÖ¹¡£¡£¡£¡£¡£¡£¡£
¶øÆôÓÃÑÓ³¤µÄ»·¾³±äÁ¿À©´ó£¬£¬£¬£¬£¬Ê±Ê±Ê¹Óà cmd.exeµÄ /V:ON²ÎÊý£¬£¬£¬£¬£¬
/V:ON²ÎÊýÆôÓÃʱ£¬£¬£¬£¬£¬Äܹ»²»Ê¹ÓÃcallºÅÁîÀ´À©´ó±äÁ¿£¬£¬£¬£¬£¬Ê¹Óà %var% »ò !var! À´À©´ó±äÁ¿£¬£¬£¬£¬£¬!var!Äܹ»ÓÃÀ´°ü°ì%var%£¬£¬£¬£¬£¬Ò²¾ÍÊÇÄܹ»Ê¹ÓøÐ̾ºÅ×Ö·ûÀ´´úÌæÔËÐÐʱµÄ»·¾³±äÁ¿Öµ¡£¡£¡£¡£¡£¡£¡£ºóÃæ½éÉÜForÑ»·Ê±»á±ØÒª¿ªÆô/V:²ÎÊýÑÓ³¤±äÁ¿À©´ó·½Ê½¡£¡£¡£¡£¡£¡£¡£
ÀûÓÃForÑ»·Æ´½ÓºÅÁî
ForÑ»·Ê±Ê±±»ÓÃÀ´»ìºÏ´¦ÖÃcmdºÅÁ£¬£¬£¬£¬Ê¹µÃcmdºÅÁî¿´ÆðÀ´¸´ÔÓÇÒÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¡£¡£×î³£ÓõÄForÑ»·²ÎÊýÓÐ /L,/F²ÎÊý¡£¡£¡£¡£¡£¡£¡£
FOR ²ÎÊý %±äÁ¿Ãû IN (ÓйØÎļþ»òºÅÁî) DO Ö´ÐеĺÅÁî
FOR %variable IN (set) DO command [command-parameters]
%variable Ö¸¶¨Ò»¸öµ¥Ò»×Öĸ¿É´úÌæµÄ²ÎÊý¡£¡£¡£¡£¡£¡£¡£ Õâ¸ö±äÁ¿Ãû¿ÉËùÒÔÓ×дa-z»òÕß´óдA-Z,·Ö±æ´óÓ×д,FOR»á°Ñÿ¸ö¶ÁÈ¡µ½µÄÖµ¸³¸ø¸Ã±äÁ¿¡£¡£¡£¡£¡£¡£¡£ÔÚÅú´¦ÖÃÎļþÖУ¬£¬£¬£¬£¬ÒýÓñäÁ¿ÒªÓÃ%%variable£¬£¬£¬£¬£¬ÎÒÃÇÕâÀïÖØÒª½éÉÜÔÚcmd´°¿ÚÖУ¬£¬£¬£¬£¬ÒýÓñäÁ¿ÓÃ%variable¼´¿É¡£¡£¡£¡£¡£¡£¡£(set) Ö¸¶¨Ò»¸ö»òÒ»×éÎļþ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£Äܹ»Ê¹ÓÃͨÅä·û¡£¡£¡£¡£¡£¡£¡£ ÓйصÄÎļþ»òºÅÁî¡£¡£¡£¡£¡£¡£¡£
command Ö¸¶¨¶Ôÿ¸öÎļþÖ´ÐеĺÅÁî¡£¡£¡£¡£¡£¡£¡£
command-parameters
ÎªÌØ¶¨ÊýÁîÖ¸¶¨²ÎÊý»òºÅÁîÐпª¹Ø¡£¡£¡£¡£¡£¡£¡£
/L ²ÎÊý£º µü´úÊýÖµÁìÓò
for /L %variable in (start,step,end) do command [command-parameters]
¸ÃºÅÁʾÒÔÔöÁ¿´ó¾Ö´ÓÆðÍ·µ½ÊµÏÖµÄÒ»¸öÊý×ÖÐòÁС£¡£¡£¡£¡£¡£¡£Ê¹Óõü´ú±äÁ¿ÉèÖÃÕØÊ¼Öµ(start)£¬£¬£¬£¬£¬¶øºóÖð²½Ö´ÐÐÒ»×éÁìÓòµÄÖµ£¬£¬£¬£¬£¬Ö±µ½¸ÃÖµ³¬¹ýËùÉèÖõÄÖÕÖ¹Öµ (end)¡£¡£¡£¡£¡£¡£¡£/L ½«Í¨¹ý¶ÔstartÓëend½øÐбÈÁ¦À´Ö´Ðеü´ú±äÁ¿¡£¡£¡£¡£¡£¡£¡£ÈôÊÇstartÓ×ÓÚend£¬£¬£¬£¬£¬¾Í»áÖ´ÐиúÅÁ£¬£¬£¬£¬²»È»ºÅÁîÚ¹ÊÍ·¨Ê½Í˳ö´ËÑ»·¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»¹Äܹ»Ê¹ÓøºµÄ stepÒԵݼõÊýÖµµÄ·½Ê½Öð²½Ö´ÐдËÁìÓòÄÚµÄÖµ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬(1,1,5) ÌìÉúÐòÁÐ 1 2 3 4 5£¬£¬£¬£¬£¬¶ø (5,-1,1) ÔòÌìÉúÐòÁÐ (5 4 3 2 1)¡£¡£¡£¡£¡£¡£¡£ºÅÁîcmd /C ¡°for /L %i in (1,1,5) do start cmd¡±,»áÖ´Ðдò¿ª5¸öcmd´°¿Ú¡£¡£¡£¡£¡£¡£¡£
/F²ÎÊý£º ÊÇ×î׳´óµÄºÅÁ£¬£¬£¬£¬ÓÃÀ´´¦ÖÃÎļþºÍһЩºÅÁîµÄÊä³öÁ˾֡£¡£¡£¡£¡£¡£¡£
FOR /F ["options"] %variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %variable IN ('command') DO command [command-parameters]
(file-set) ΪÎļþÃû£¬£¬£¬£¬£¬for»á˳´Î½«file-setÖеÄÎļþ´ò¿ª£¬£¬£¬£¬£¬²¢ÇÒÔÚ½øÐе½ÏÂÒ»¸öÎļþ֮ǰ½«Ã¿¸öÎļþ¶ÁÈ¡µ½Äڴ棬£¬£¬£¬£¬ÒÀÕÕÿһÐзֳÉÒ»¸öÒ»¸öµÄÔªËØ£¬£¬£¬£¬£¬ºöÂÔ¿ÕȱÐС£¡£¡£¡£¡£¡£¡£
("string")´ú±í×Ö·û´®£¬£¬£¬£¬£¬('command')´ú±íºÅÁî¡£¡£¡£¡£¡£¡£¡£
Èç¹ûÎļþaa.txtÖÐÓÐÈçÏÂÄÚÈÝ£º
µÚ1ÐеÚ1ÁÐ µÚ1ÐеÚ2ÁÐ
µÚ2ÐеÚ1ÁÐ µÚ2ÐеÚ2ÁÐ
ÒªÏë¶Á³öaa.txtÖеÄÄÚÈÝ£¬£¬£¬£¬£¬Äܹ»ÓÃfor /F %i in (aa.txt) do echo %i £¬£¬£¬£¬£¬ÈôÊÇÈ¥µô/F²ÎÊýÔòÖ»»áÊä³öaa.txt£¬£¬£¬£¬£¬²¢²»»á¶ÁÈ¡ÆäÖеÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£
ÎÒÃǰÎȡнüµÄEmotetÑù±¾ÏÂÔØÀûÓõÄCMDºÅÁî»ìºÏ£¬£¬£¬£¬£¬À´ÀûÓÃÇ°ÃæµÄ֪ʶÀ´½â»ìºÏ¡£¡£¡£¡£¡£¡£¡£
ÀûÓÃ×Ô½ç˵»·¾³±äÁ¿ºÍForÑ»·»ìºÏ
¸ÃÑù±¾ÖÐÀûÓÃÁËcmd.exe µÄÆôÓÃÑÓ³¤»·¾³±äÁ¿/V:ON²ÎÊý£¬£¬£¬£¬£¬/C²ÎÊý£¬£¬£¬£¬£¬ÀûÓÃsetºÅÁî×Ô½ç˵һ¸ö»·¾³±äÁ¿kpx=lHUwrRfzapaiNzCqHfu:Doc(4YQ0S.1,xk}$) s6dK=mn5/+ygbW-TeP\v2tj{78Mh@;BO'FZ£¬£¬£¬£¬£¬Í¨¹ý&&Æ´½ÓºÅÁ£¬£¬£¬£¬¶øºóÊǸöforÑ»·£º for %G in £¨ÊýÁУ©do set 1q=!1q!!kpx:~ %G, 1!&& if %G== 81 call %1q:~ -377%¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇ×ųÁ·ÖÎöÏÂforºÅÁî¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÇ°ÃæÊ¹ÓÃÁËÑÓ³¤»·¾³±äÁ¿£¬£¬£¬£¬£¬ËùÒÔÄܹ»Ê¹ÓÃ!1q!!kpx:~ %G, 1!µÄ·½Ê½À´À©´ó±äÁ¿£¬£¬£¬£¬£¬ÔÚÔËÐÐʱ°ü°ì»·¾³±äÁ¿Öµ¡£¡£¡£¡£¡£¡£¡£forµÄÑ»·±äÁ¿ÊÇ%G£¬£¬£¬£¬£¬%G in (ÊýÁÐÖµ)£¬£¬£¬£¬£¬!kpx:~ %G, 1!°µÊ¾È¡»·¾³±äÁ¿kpxÖÐϱêΪ%GµÄÒ»¸ö×Ö·û£¬£¬£¬£¬£¬ÎÒÃÇÄܹ»ÓÃÈçÏÂpython±àÂëʵÏÖ¸ÃÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£ÊýÁÐÖеĿոñÄܹ»ºöÂÔ£¬£¬£¬£¬£¬ÊýÁÐÖеÄÊýÖµÕýºÃÊÇ377¸ö£¬£¬£¬£¬£¬kpx×Ö·û´®µÄ³¤¶ÈÊÇ72¸ö×Ö·û£¬£¬£¬£¬£¬Ï±êΪ81ÒѾ²»´æÔÚ£¬£¬£¬£¬£¬ËùÒÔµ±Ï±ê%G==81ʱ£¬£¬£¬£¬£¬ÔËÐÐʱ»·¾³±äÁ¿1q=!1q!powershell ¡¡, call %1q:~-377%£¬£¬£¬£¬£¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÊÇforÑ»·±éÀú³öµÄpowershell¡¡ºÅÁ£¬£¬£¬£¬Ç°ÃæµÄ1q=!1q!Êdzõʼ»¯±äÁ¿1q£¬£¬£¬£¬£¬±ØÒª±»È¥µôÒÔÃâÓ°ÏìÕý³£ºÅÁîµÄÖ´ÐУ¬£¬£¬£¬£¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÈÆ¹ýÇ°ÃæµÄ!1q!¡£¡£¡£¡£¡£¡£¡£
Êä³ö£º
ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://catbayouthaction.com/jKS86a
http://spsystems24.ru/O
http://xn--80abdh8aeoadtg.xn--p1ai/multimedia/hD4lyk7
http://borsehung.pro/pfWq
http://inpart-auto.ru/x2bu
ÀûÓÃcmdϵͳ»·¾³±äÁ¿ºÍForÑ»·»ìºÏ
ÏȽ«»ìºÏcmdºÅÁîÖеÄתÒå×Ö·û¡°^¡±È«ÊýÈ¥µô£¬£¬£¬£¬£¬ÔÙ½«³ýÁ˱äÁ¿@Ö®±íµÄ¶ººÅ¡°,¡±¡¢·ÖºÅ¡°;¡±¡¢ÓÐÓà¿Õ¸ñɾ³ý¡£¡£¡£¡£¡£¡£¡£°ÑÎȱ£Áô±äÁ¿@ÖеĶººÅºÍ·ÖºÅ£¬£¬£¬£¬£¬²»È»Ó°ÏìÊä³öÁ˾֡£¡£¡£¡£¡£¡£¡£
¿É¼ûÀûÓÃÁËcmdµÄϵͳ»·¾³±äÁ¿%comspec%£¬£¬£¬£¬£¬¼´ÊÇcmd.exeµÄÖ´ÐÐõè¾¶¡£¡£¡£¡£¡£¡£¡£ÀûÓÃForÑ»·µÄF²ÎÊý£¬£¬£¬£¬£¬ÔÚºÅÁî'aSsoC .cmd'ÖÐÒÔ×Ö·ûv¡¢f¡¢=Ϊ·Ö¸ô·û£¬£¬£¬£¬£¬È¡µÚ¶þÁм´ÊÇ¡°cmd¡±¡£¡£¡£¡£¡£¡£¡£
fOr /f " delims=vf= tokens=2" %f IN ( 'aSsoC .cmd' ) dO %f ¡£¡£¡£¡£¡£¡£¡£ÆäËûÎÞÒâ˼µÄ×Ö·û´®»á±»cmdºöÂÔ¡£¡£¡£¡£¡£¡£¡£
½Ó×Å×Ô½ç˵ÁËÒ»¸ö»·¾³±äÁ¿@£¬£¬£¬£¬£¬µÅ×ÚÒ»¸ö1460³¤¶ÈµÄ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£¶øºóÀûÓÃForÑ»·µÄ/L²ÎÊý£¬£¬£¬£¬£¬±éÀú±äÁ¿@£ºFOr /L %s In (1459,-4,+3 ) do (( ( (( seT \=!\!!@ :~ %s, 1!))))& iF %s eQU 3 (((CaLl %\ :~ -365% )£¬£¬£¬£¬£¬×Ô½ç˵ÁË»·¾³±äÁ¿¡°\¡±£¬£¬£¬£¬£¬ÀûÓû·¾³±äÁ¿À©´ó·ûºÅ£¡£¬£¬£¬£¬£¬!@ :~ %s, 1!°µÊ¾Ñ»·±äÁ¿%s´Ó1459ÆðÍ·£¬£¬£¬£¬£¬²½³¤Îª-4£¬£¬£¬£¬£¬µ½3ʵÏÖ£¬£¬£¬£¬£¬Ñ»·ÌáÈ¡±äÁ¿@ÖеÄÒ»¸ö×Ö·û£¬£¬£¬£¬£¬³¤¶ÈΪ365¸ö×Ö·û£¬£¬£¬£¬£¬¼´´ÓForÑ»·³Á×é³öµÄºÅÁîÆðÍ·Ö´ÐС£¡£¡£¡£¡£¡£¡£
ÎÒÃDZàдpython¾ç±¾ÊµÏÖForÑ»·Ö°ÄÜ£º
×îÖÕ½âÃܳö¿É¶ÁµÄÄÚǶpowershellºÅÁ
ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://reitmaier.de/01cedmfXohttp://phoxart.com/sWP0E9
http://panbras.com.br/FHhUYIQ
http://osmanager.com.br/t3HnvWx9x
http://oldwillysforum.com/ChleCkW
²Î¿¼£º
https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf


¾©¹«Íø°²±¸11010802024551ºÅ