¡¾Éî¶È·ÖÎö¡¿VPNFilter£ºÎ£¼°È«Çò¹¤¿ØÉ豸ºÍ°ì¹«ÍøÂçµÄÎïÁªÍø¸ß¼¶Íþв

°ä²¼¹¦·ò 2018-06-17

Ò»¡¢Íþв¸ÅÊö

        ½üÆÚ£¬Ë¼¿ÆTalosÍŶÓÒòÇé¿ö´¹Î£Ìáǰ¹«¿ªÁËÒ»ÏîδʵÏÖµÄ×êÑУ¬¸Ã×êÑÐÌá¼°ÁËÒ»¸ö¿ÉÄܶÔÈ«ÇòÍøÂç²úÉú³Á´ó·çÏյĸ߼¶Íþв¹¥»÷(ԼĪÓÐ50Íǫ̀É豸Êܵ½Ï°È¾)£¬ÓÉÓÚÆäÖ÷ÌâÄ£¿éÎļþΪVPNFilter£¬¹Ê¸Ã¶ñÒâ´úÂëÒ²±»¶¨ÃûΪ¡±VPNFilter¡±¡£¸Ã¹¥»÷ÊÇһ·ÒÔÈëÇÖÎïÁªÍøÎªÔØÌå´ÓÊ¿ÉÄÜÓɹú¶ÈÌáÒéµÄÈ«ÇòÐԵĸ߼¶¶ñÒâÈí¼þ¹¥»÷£¬¶ñÒâÈí¼þͨ¹ýÈý¸ö½×¶ÎÀ´²¿ÊðÆä¹¥»÷±øÆ÷£¬Ä¿Ç°ÒѾ­ÓÐÖÁÉÙ50Íǫ̀É豸Êܵ½Ï°È¾¡£¹¥»÷ÕßÀûÓøöñÒâÈí¼þÀ´½ÚÔì²¢¼à¶½´¦ÓÚ¹¤¿ØÍøÂç¡¢°ì¹«»·¾³ÖеÄÍøÂçÉ豸(Ô̺¬Â·ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽÒÔ¼°ÆäËûµÄÎïÁªÍøÉ豸)£¬ÆäÖ§³Ö¹¤¿ØÍøÂçµý±¨ÍøÂç¡¢³ÁÒªÃô¸ÐµÄÁ÷Á¿(µÇ¼ƾ֤)½ØÈ¡¡¢Á÷Á¿´Û¸Ä¡¢¶¨ÏòJS×¢Èë¡¢É豸·ÛËéÐÔ¹¥»÷µÈÖ°ÄÜ¡£

        ¶ñÒâÈí¼þÔÚ5ÔÂ8ÈÕ³öÏÖ´ó¹æÄ£µÄÒÔÎÚ¿ËÀ¼ÎªÖØÒªÖ¸±êµÄ¹¥»÷»î¶¯£¬²¢ÇÒÔÚ5ÔÂ17ÈÕÎÚ¿ËÀ¼µÄÊÜϰȾÉ豸³öÏÖ´ó·ù¶ÈÔö³¤£¬ÕâЩÊÜϰȾÉ豸¾ùÊÜ¿ØÓÚC&C 46.151.209.33, ¿´ÆðÀ´Õâ´Î¹¥»÷Ö¸±êËÆºõ¶Ô×¼ÎÚ¿ËÀ¼¡£ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³ÒѾ­Êܵ½¹ýÁ½´ÎºÚ¿Í¹¥»÷£¬²¢ÇÒµ¼ÖÂÁËÍ£µç±äÂÒ£¬Á½´Î¹¥»÷¾ùÒÔÓÆ¾Ã¶øÒþÃØµÄÉøÈ뼿Á©ÈëÇÖµ½Ö¸±ê¡£¶øÕâ´ÎµÄ¹¥»÷»î¶¯ÒÔÎïÁªÍøÈë¿Ú£¬ÀûÓôóÁ¿´æÔÚ·ì϶µÄÎïÁªÍøÉ豸×÷ÎªÔØÌå½øÐÐÈöÍøÊ½¹¥»÷£¬²¢ÇÒÒÔ¾ªÈ˵ĿìÂÊϰȾÁËÖÁÉÙ50Íǫ̀É豸£¬ÆäÖÐÔ̺¬ÓлªÎª¡¢ÖÐÐË¡¢»ªË¶¡¢Dlink¡¢Ubiquiti¡¢UPVEL¡¢Linksys¡¢MikroTik¡¢NETGEAR ºÍ TP-LinkµÈÉ豸¡£Í¬Ñù£¬Õâ´Î¶ñÒâ´úÂëÓë2015Äê¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄBlackEnergyʹÓÃÒ»ÑùµÄ±äÐÎRC4Ëã·¨¶Ô¹Ø¼üÐÅÏ¢½øÐмÓÃÜ£»²¢ÇÒÓëÖ®ÀàËÆµÄÊÇͬÑùÒ²ÓжÔÖ÷»úÉ豸½øÐгÁÒªÊý¾Ý²Á³ýÓë³ÁÆôµÄÁ¬»·×÷ΪÒÔ´ïµ½ÈÃÉ豸ÎÞ·¨Æô¶¯µÄÖ÷ÕÅ(ͬʱҲÌá¸ßÁËȡ֤µÄÄѶÈ)¡£

        GA»Æ½ð¼×ADLab·¢ÏÖ¸ÃÔ¤¾¯ºó¶Ô¸Ã¶ñÒâÈí¼þ½øÐÐÁËÉî¿ÌµÄ·ÖÎö£¬ÒÔ·Ö½âÆäʵÏÖ»úÔì¡£ÎÒÃÇ·¢ÏָöñÒâÈí¼þÖгýÁËѡȡͼƬÎļþµÄEXIFÊý¾Ý´«ÊäÓÃÓÚÏÂÔØ¶ñÒâ´úÂëÖ÷Ìâ×é¼þµÄC&C±í£¬»¹Ñ¡È¡HTTPÍ·ÖеÄlocationºÍdirect×ֶδ«Êä¸ÃC&C£¬ÉõÖÁѡȡÁËÒ»ÖÖÎÒÃdzÆÖ®Îª¡±SYNËí·¼¼Êõ¡±µÄ¸ß¼¶°µ²Ø¼¼ÊõÀ´ÊµÏÖ¶ñÒâÈí¼þC&CµÄ±»¶¯¸üУ¬¼´±ãÈç֮ǰËù±¨Â·ÄÇÑù£¬FBI×è¶ÏÁ˸öñÒâÈí¼þµÄC&C£¬¸Ã¼¼ÊõÒ²Äܹ»ÈøöñÒâÈí¼þ¼±¾çÐÂÉú¡£ÆäÖеÚÈý½×¶Î¶ñÒâ×é¼þרÃÅÕë¶ÔTCPºÍ̸½øÐÐÐá̽´¦Ö㬲»½ö¶Ô¹¤¿Ømodbus SCADAºÍ̸½øÐеý±¨ÍøÂ磬ͬʱ»¹»áÐá̽»ùÓÚhttpºÍ̸µÄµÇ¼ƾ֤ÐÅÏ¢ºÍAuthorizationÐÅÏ¢¡£¸ÃÐá̽Ä£¿é±ØÒªºÚ¿ÍÔ¶³ÌÖ¸¶¨modbus·þÎñÆ÷½øÐо«È·µÄ¼à¿Ø£¬ÒÔ·¢ÏÖËùÓÐÏνӵĴӻúÉ豸¡£´Ë±í£¬ÔÚ×î½ü¹«¿ªµÄ¹¥»÷²å¼þÄ£¿éÖл¹Äܹ»¿´³ö£¬¸Ã´Î¹¥»÷¿ÉÓÃÓÚ¿í·ºµÄµý±¨ÍøÂçÒÔ¼°¶ÔÌØ¶¨Ö¸±ê½øÐÐÉøÈë¹¥»÷£¬ÆäÖÐÔ̺¬¶Ô80¶Ë¿ÚµÄÁ÷Á¿³Á¶¨Ïò¡¢Ç¿Ôìת»»HTTPSΪHTTPÒÔ·½±ãÁ÷Á¿¼à¿Ø¡¢ÇÔÈ¡HTTPÒªÇó°üÖеĵǼƾ֤ÐÅÏ¢¡¢ÏòÖ¸¶¨ÍøÕ¾µÄÏìÓ¦Êý¾ÝÖÐ×¢Èë¶ñÒâjavascript¾ç±¾µÈµÈ¡£

¶þ¡¢¶ñÒâÈí¼þ¹¤×÷µÀÀí

        ¸Ã¶ñÒâÈí¼þͨ¹ýÀûÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍøÉ豸·ì϶½øÐÐ¿í·ºµÄϰȾºÍ´«²¼¡£ÔÚϰȾÉ豸ÖУ¬ÆäÊ×ÏÈÆô¶¯Ò»¸öLoaderÄ£¿éÖ´ÐУ¬¸ÃÄ£¿éÖØÒªÊµÏÖÁËVPNFilter×é¼þµÄÏÂÔØÓëÖ´ÐС£LoaderÄ£¿é²¢²»ÊÇÖ±½Óͨ¹ýÖ¸¶¨µÄÏÂÔØµØÖ·À´ÏÂÔØVPNFilter×é¼þ£¬¶øÊÇͨ¹ý¶àÖÖ¼¼Êõ¼¿Á©À´»ñÈ¡VPNFilterµÄÏÂÔØµØÖ·(´æ´¢µã)¡£ÆäÊ×ÏÈ»áÏò·þÎñÆ÷photobucket.com·¢ËÍÒªÇó²¢³¢ÊÔ½âÎöÏìÓ¦Êý¾ÝÖеÄLocaion¡¢direct¡¢Í¼Æ¬EXIFÐÅÏ¢À´»ñÈ¡£»ÈôÊÇʧ°ÜÔòÏò·þÎñÆ÷taknowall.com·¢ËÍÒªÇó²¢½âÎöͼƬµÄEXIFÀ´»ñÈ¡£»ÈôÊÇÒÀÈ»ÎÞ·¨»ñÈ¡µ½C&C£¬Ôò»áѡȡ¡±SYNËí·¼¼Êõ¡±À´»ñÈ¡C&CʵÏÖÏÂÒ»¸ö½×¶Î×é¼þµÄÏÂÔØµØÖ·¡£´Ë±í£¬VPN´æ´¢µã»ñÈ¡³É¹¦ºó£¬Loaderͨ¹ýÄÚÖÃSSLÖ¤ÊéÎļþÀ´ÑéÖ¤ÏÂÔØVPNFilter×é¼þ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        VPNFilter×é¼þ×îºó»á±»ÏÂÔØµ½¡±/var/run/¡±Ä¿Â¼Ï£¬ÊǸÃÀà¶ñÒâ¹¥»÷µÄÖ÷Ìâ×é¼þ£¬Í¨¹ý¸Ã×é¼þ£¬¶ñÒâÈí¼þµÃÒÔפÁôÔÚ±»Ï°È¾ÏµÍ³ÖС£VPNFilter×é¼þΪ¹¥»÷ÕßÌṩÁËÒ»¸öÓÃÓÚÊØ»¤½©Ê¬ÍøÂçµÄ¿ò¼Ü£¬¹¥»÷ÕßÄܹ»»ùÓÚ·ÖÆçµÄ¹¥»÷Ö÷ÕżÓÔØ·ÖÆçµÄ²å¼þºÍÖ´ÐÐ·ÖÆçÔ¶¿Ø½ÚÔìºÅÁĿǰËù·¢ÏֵIJå¼þÄ£¿éÓУºÒ»¸öÓÃÓÚÖ§³ÖÏνӵ½TorÍøÂçµÄTor ¿Í»§¶Ë£¨Tor Client,Îļþtor£©£»Ò»¸öΪÐá̽µÇ¼ƾ֤ºÍModbus¹¤¿ØºÍ̸ÐÅÏ¢µÄTCPÁ÷Á¿Ðá̽Ä£¿é£¨TCP Traffic Sniffer£¬Îļþps£©;Ò»¸öרÃÅΪHTTP 80¶Ë¿Ú½øÐÐÁ÷Á¿¼à¿Ø¡¢½ØÈ¡¡¢´Û¸Ä¡¢×¢ÈëµÄHTTP Á÷Á¿¼à¿ØÄ£¿é£¨HTTP Traffic Controllor£¬Îļþssler£©£»ÒÔ¼°¿ÉÓÃÓÚ·ÛËéÉ豸ʹÆäÎÞ·¨³ÁÆô¡¢ÎÞ·¨È¡Ö¤µÄÉ豸·ÛËéÄ£¿é£¨Destroy Module£¬Îļþdstr£©£¬´Ë±íÆä»¹´æÔÚÆäËûµÄÄ£¿éÈ磺mikrotik.o¡¢torrc¡¢ip_tables.ko¡¢iptable_filter.ko¡¢iptable_nat.ko¡£

Èý¡¢¶ñÒâÈí¼þ·Ö½â

        ƾ¾Ý¸Ã¶ñÒâÈí¼þÖ´Ðй¥»÷µÄ²½Ö裬Äܹ»½«Æä»®·ÖΪÈý¸ö½×¶Î£¬ÆäÖÐLoaderÎļþΪµÚÒ»¸ö½×¶ÎµÄ¶ñÒâÄ£¿é£¬VPNFilterÎļþΪµÚ¶þ½×¶ÎµÄ¶ñÒâÄ£¿é£¬Tor¿Í»§¶ËºÍÁ÷Á¿Ðá̽Æ÷ΪµÚÈý½×¶ÎµÄ¶ñÒâÄ£¿é¡£ÒÔϱðÀë¶ÔÕâÈý¸ö½×¶ÎµÄ¶ñÒâ´úÂë½øÐÐÉî¿ÌµÄ·Ö½â¡£

µÚÒ»½×¶Î£ºÏ°È¾É豸²¢ÏÂÔØ¶ñÒâ´úÂëÖ÷ÌåÖ´ÐÐ

        µÚÒ»¸ö½×¶ÎµÄÑù±¾Äܹ»¿´×÷ÊÇÒ»¸öLoader£¨ÎļþÃûΪmsvf£©£¬¹¥»÷ÕßÀûÓÃÉ豸·ì϶½«ÆäÂ䵨µ½É豸ÄÚ´æÖÐÔËÐС£¸ÃLoaderÖØÒªÖ÷ÕÅÊÇ´ÓC&C·þÎñÆ÷¸ßµÍÔØµÚ¶þ½×¶ÎµÄ¶ñÒâ×é¼þÖ´ÐС£¸ÃLoader·ÖÆçÓÚÒÔÍùµÄÎïÁªÍø¶ñÒâ´úÂëÄÇÑù½«C&CÄÚÖÃÓÚ´úÂëÄÚ£¬¶øÊÇͨ¹ýÔںϷ¨Í¼Æ¬ÍøÕ¾¸ßµÍÔØÒ»Õ۵²ØÓÐC&CµØÖ·µÄͼƬ½øÐнâÎö£¬´Ó¶øµÃµ½ÕæÊµµÄC&C¡£¶ø¶ñÒâ´úÂëΪÁËÔ¤·ÀÁ÷Á¿×·×Ù£¬Ñ¡È¡socks5´úÀí¡¢Tor¡¢ÒÔ¼°sslµÄ·½Ê½½øÐиÃͼƬµÄÏÂÔØ¡£ÈôÊÇͼƬÏÂÔØÊ§°Ü£¬Ò²»áѡȡ¼«ÆäÒñ±ÎµÄԭʼÁ÷Á¿Êý¾ÝÐá̽µÄ·½Ê½À´»ñÈ¡C&C¡£

        ͬʱ¸ÃÄ£¿é»¹ÊÔͼÅú¸ÄNVRAM²¢½«×ÔÉí²ÎÓ밴ʱ¹¤×÷Îļþ¡±crontab¡±ÖУ¬ÒÔ´ïµ½³£×¤µÄÖ÷ÕÅ¡£Í¨³£ÎïÁªÍø¶ñÒâ´úÂëÈçmiraiµÈûÓÐÉæ¼°³£×¤»úÔ죬ʹµÃÆäÔÚÉ豸³ÁÆôºó»áÒþû¡£

        1¡¢Á½´Î´´½¨×Ó¹ý³Ì²¢ÇÒÆôÓöñÒâ´úÂë¶Ôµ±Ç°Óû§×éµÄ¶ÁдִÐÐȨÏÞ

        µÚÒ»½×¶ÎÑù±¾Ö´Ðк󣬻áforkÁ½´Î£¬µÚÒ»´ÎÓÃÓÚËãÕʹý³Ì×ÊÔ´ÆôÓöÁдִÐÐȨÏÞ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        µÚ¶þ´Îfork»áÔÚ×Ó¹ý³ÌÖÐÈ·ÈϹý³ÌÎļþÊÇ·ñ´æÔÚ£¬ÈôÊDz»´æÔÚ»á½øÐÐÎļþµÄ»ØÐ´£¬Ô¤·À½øÐÐÎļþÃÔʧ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´Ë±íÔÚµÚ¶þ´ÎforkµÄ×Ó¹ý³ÌÖУ¬¶ñÒâ´úÂëΪÁËÔ¤·À×ÔÉíÎļþÔÚÉ豸³ÁÆôºóÒþû£¬»¹»á½«×ÔÉíÎļþ²ÎÓëµ½crontabÎļþĩ⣬ÒÔʵÏÖ¿ªÆôÆô¶¯¡¢³£×¤É豸µÄÖ÷ÕÅ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        2¡¢ ½âÃÜÖ¤ÊéÎļþÃû¡¢Í¼Æ¬Á´½ÓÊý¾ÝµÈÄÚÈÝ

        ½ÓÏÂÀ´¶ñÒâ´úÂë»áͨ¹ý±äÐεÄRC4Ëã·¨À´½âÃܺóÐøÒªÓõ½µÄ×Ö·û´®ºÍÊý¾Ý£¬±äÐÎRC4ÃØÔ¿Îª¡±%^:d¡±£¬×îа汾ÒѾ­¸üÐÂΪ¡°g&*kdj$dg0_@@7¡¯x¡±¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

±äÐÎRC4µÄstableÊý¾ÝÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ×îºó½âÃܵõ½ÈçÏÂÐÅÏ¢£¬ÆäÖÐÔ̺¬Ö¤ÊéÎļþÃû¡¢°æ±¾ºÅ¡¢buildÐÅÏ¢¡¢Í¼Æ¬urlµÈ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½âÃÜurl£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        3¡¢´´½¨sslÖ¤ÊéÎļþÒÔ¼°¶ñÒâ´úÂë°æ±¾Îļþ

        ½âÃÜʵÏֺ󣬶ñÒâ´úÂë»á½«´úÂëÖÐÄÚǶµÄ¹«Ô¿¡¢Ë½Ô¿Êý¾Ý´æ´¢ÔÚÖ¤ÊéÎļþÖС£¸Ã¶ñÒâ´úÂëÖдæ·ÅÓÐÈý¸öÖ¤ÊéÊý¾Ý£¬ÆäÖÐÁ½¸ö¹«Ô¿ºÍÒ»¸ö˽Կ£¬¹«Ô¿´æ´¢ÔÚÎļþ¡±/var/run/client_ca.crt¡±ºÍ¡±/var/run/client.crt¡±ÖУ¬Ë½Ô¿´æ´¢ÔÚÎļþ¡±/var/run/client.key¡±ÖС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´Ë±í£¬°æ±¾ÐÅÏ¢0.3.9qa»á±»Ð´Èëµ½Îļþ/var/run/msvf.pidÖС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        4¡¢ÏÂÔØµÚ¶þ½×¶Î×é¼þ

        µÚ¶þ½×¶ÎµÄ¶ñÒâ´úÂëÏÂÔØµØÖ·Ñ¡È¡ÈýÖÖ·½Ê½»ñÈ¡¡£Ê×Ïȳ¢ÊÔ´ÓphotobucketÍøÕ¾ÒªÇóC&C£¬¾ßÌåÒÀÕÕÈçÏÂÁ´½Ó°¤´ÎÈ¥ÏÂÔØ²¢ÌáÈ¡µÚ¶þ½×¶Î¶ñÒâ´úÂëµÄ·þÎñÆ÷µØÖ·¡£

http://photobucket.com/user/nikkireed11/library

http://photobucket.com/user/kmila302/library

http://photobucket.com/user/lisabraun87/library http://photobucket.com/user/katyperry45/library

        ¹ÌÈ»µ±Ç°ÕâЩÁ´½ÓÒѾ­Ê§Ð§£¬µ«ÊÇͨ¹ýÄæÏòÄܹ»¿´³ö£¬ÈôÊÇÒªÇóÏìÓ¦ÂëΪ302£¬¶ñÒâ´úÂëÔò»á´ÓÏìÓ¦Êý¾ÝÖеġ±Location¡±/¡±location¡±²ÎÊýÖÐÌáÈ¡³öµÚ¶þ½×¶Î¶ñÒâ´úÂëµÄÏÂÔØµØÖ·¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÈôÊǶñÒâ´úÂëÒªÇóµÄÏìÓ¦ÂëΪ200£¬Ôò»á´ÓÒªÇóµÄÏìÓ¦Êý¾Ý°üµÄHTTPÍ·²¿ÖÐÌáÈ¡¡±direct¡±²ÎÊýµÄÖµ£¬×÷ΪµÚ¶þ½×¶Î¶ñÒâ´úÂëÏÂÔØµØÖ·¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÈôÊDz»´æÔÚ¸ÃÖµ£¬Ôò»á´ÓͼƬÎļþÖеÄEXIFÓòÌáÈ¡¾­Î³¶ÈÊý¾Ý²¢½«Æäת»»ÎªµÚ¶þ½×¶Î¶ñÒâ´úÂëÏÂÔØµÄIPµØÖ·¡£ÏÂÔØµÄͼƬÎļþEXIF²¿ÃÅÊý¾ÝÀàËÆÏÂͼ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´¦ÖôúÂëÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÈôÊÇÒÔÉÏÇé¿ö¾ùʧ°Ü£¬¶ñÒâ´úÂ뻹»á³¢ÊÔÒªÇóÈçÏÂÁ´½Ó£¬¸ÃÁ´½ÓÒ²ÊÇÒ»ÕÅͼƬ£¬ºÍÉÏÃæ²½ÖèÒ»Ñù´ÓEXIFÖÐÌáÈ¡¾­Î³¶È²¢´¦Öõõ½ÏÂÔØµØÖ·£ºhttp://taknowall.com/manage/content/update.php ¡£

        ÈôÊÇÉÏÃæµÄËùÓз½Ê½¶¼³¢ÊÔºóÒÀÈ»ÎÞ·¨³É¹¦»ñÈ¡C&CµØÖ·£¬¶ñÒâ´úÂë»áͨ¹ýÁ´½Óhttp://api.ipify.org?format=json»ñÈ¡µ½µ±Ç°É豸µÄ±íÍøIPµØÖ·£¬¶øºóÐá̽µ±Ç°É豸µÄÔ­Ê¼ÍøÂçÁ÷Á¿Êý¾Ý£¬²¢ÊÔͼ´ÓÕâЩÁ÷Á¿Êý¾ÝÖйýÂ˳öÇкÏÌØ¶¨ÌåʽµÄÍøÂçÊý¾Ý°ü£¬ÈôÊÇÂú×ãÌåʽҪÇ󣬱ã»á´Ó¸ÃÊý¾ÝÖÐÌáÈ¡³öµÚ¶þ½×¶Î¶ñÒâ´úÂëµÄÏÂÔØµØÖ·¡£ÆäÖйýÂ˰üʱÐèÂú×ãÈçÏÂǰÌ᣺

        (1)  ԭʼÊý¾ÝÁ÷³¤¶È±ØÐë´óÓÚ0x3D

        (2)  Êý¾Ý°ü±ØÐëΪTCP°ü

        (3)  Êý¾Ý°üµÄSYN±ØÐë±»ÉèÖÃ

        (4)  Ö÷ÕÅIP±ØÐëΪµ±Ç°É豸µÄ¹«ÍøIP

         (5)  Tcp OptionµÄMSS(Maximum Segment Size) ±ØÐëΪ0c 15 22 2B£¨ÏÖʵÉÏΪ·¸·¨MSS£©

        ÈôÊÇÂú×ãÒÔÉÏǰÌᣬÔò´ÓMSSÖ®ºóµÄ4¸ö×Ö½ÚÌáÈ¡³öC&CµÄIPµØÖ·¡£ÎÒÃǽ«ÕâÖÖÒÔSYN TCPÊý¾ÝÁ÷×÷ΪÊý¾Ý´«ÊäµÄ¼¼Êõ³ÆÎª¡±SYNËí·¼¼Êõ¡±¡£ÀûÓøÃÖÖ¼¼ÊõÀ´´«ÊäC&CµØÖ·²»½ö¿ÉÄܺܺÃÒþÃØºÚ¿ÍµÄ×ÙÓ°(ÎÞÐèÔÚ¶ñÒâ´úÂëÄæÏò»òÕßÍøÂç´æ´¢µãÉ϶³öºÚ¿ÍC&CµØÖ·)£¬²¢ÇÒ¿ÉÄܽýݵı任C&C£¬¼«¶ÈÄÑÒÔ±»·¢¾õ¡£Òò¶ø£¬Äܹ»ËµÑù±¾ÖÐÈκÎÄÚÖÃC&C»òÕß´æ´¢C&CµÄ´æ´¢µã±»´ëÖú󣬸öñÒâ´úÂëÒÀÈ»Äܹ»ÊÜ¿ØÓÚºÚ¿Í¡£Õâ¸ø·¨Âɲ¿ÃÅ´ëÖøöñÒâ´úÂë´øÀ´Á˾޴óÌôÕ½¡£Ô­Ê¼Á÷µÄ²¿ÃÅÅж¨´úÂëÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÈôÊÇÒÔÉÏÈκÎÒ»ÖÖ·½Ê½¿ÉÄܳɹ¦»ñÈ¡µ½ÏÂÔØµØÖ·²¢ÇÒÏÂÔØ×é¼þ³É¹¦£¬¶ñÒâ´úÂë±ã»áÖ±½ÓÖ´ÐÐËùÏÂÔØ¶ñÒâ´úÂ룬¶øºóÍ˳ö¡£ÏÂÔØµÄµÚ¶þ½×¶ÎµÄ¶ñÒâ´úÂë±»±£ÁôΪÎļþ¡±/var/vpnfilter¡±¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

µÚ¶þ½×¶Î£º½ÚÔìºÅÁî½Ó¹Ü¡¢·Ö·¢¡¢Ö´ÐÐ

        ¸ÃÑù±¾ÒÔʵÏÖºóÃŽÚÔìΪÖ÷ÕÅ£¬ÆäÖØÒªÓÃÓÚÏνӽÚÔì¶Ë·þÎñÆ÷£¬½Ó¹Ü½ÚÔìºÅÁîÖ´ÐÐÏàÓ¦µÄÖ°ÄܽÚÔì¡£Ñù±¾Ê×ÏÈΪÁËÈ·±£ÔËÐÐʵÌåµÄΨһÐÔ£¬»á°ó¶¨1386¶Ë¿Ú¡£ÈôÊǸö˿ڱ»Õ¼Óñã»áÖÕÖ¹ÔËÐС£´Ë±íÔÚа汾Öв»ÔÙͨ¹ýÕâÖÖÈÝÒ××ÔÎÒ¶³öµÄ·½Ê½À´×öΨһÐÔÅж¨£¬²¢ÇÒÔö³¤ÁË×ÔÎÒɾ³ýµÄÖ°ÄÜ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÈôÊǰ󶨳ɹ¦£¬±ã»á½øÈëÖ÷Ì⹤×÷´úÂëÖÐÖ´ÐС£Ê×ÏÈΪÁËÔ¤·ÀÒòCPU×ÊÔ´²»¼°¡¢Æ½Ì¨¼æÈÝÐÔµÈÎÊÌâµ¼ÖÂÎÞ·¨¹¤×÷»òÕßÍ˳ö£¬Æä»¹×¢²áÁË´óÁ¿Òì³£ÐźÅÓÃÓÚ×ÔÎÒÐÂÉú¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¶øºóѡȡͬÑùµÄ±äÐÎRC4Ëã·¨ºÍÃØÔ¿À´½âÃܹؼü×Ö·û´®ÒÔ¹©ºóÐøÊ¹Ó᣽ÓÏÂÀ´»áʵÏÖºóÐø×°ÖÃÅäÖÃÁ÷³Ì¡£

        Ê×Ïȼì²âsslÖ¤ÊéÎļþÊÇ·ñ´æÔÚ£¬ÈôÊDz»´æÔÚ£¬Æä»á´¦Óڵȴý״̬£¬Ö±µ½Ö¤ÊéÎļþ×°ÖÃʵÏÖ¡£²»È»ÆðÍ·ÅäÖù¤×÷Ŀ¼¡¢ÉèÖôúÀíµØÖ·¡¢ÉèÖÃTorÍøÂçµØÖ·¡¢»ñÈ¡±íÍøIPµØÖ·¡¢MACµØÖ·¡¢ÍøÂçÃû³ÆµÈÐÅÏ¢¡£ÏÂͼΪ²¿ÃÅ×°ÖÃÐÅÏ¢¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´´´½¨¹¤×÷Ŀ¼/var/run/xxm/¼°/var/run/xxw²¢¿ªÆôÖ÷Ñ­»·£¬Ïò½ÚÔì¶ËÒªÇó½ÚÔìºÅÁî²¢ÇÒÖ´ÐÐÏàÓ¦µÄ½ÚÔìÖ°ÄÜ¡£

        ½ÚÔìºÅÁîµÄÒªÇóÓÐÁ½ÖÖ·½Ê½£¬Ò»ÖÖÊÇͨ¹ýsocks5´úÀí·½Ê½£¬Ò»ÖÖÊÇͨ¹ýTorÍøÂçÒªÇó¡£Í¨¹ýsocks5´úÀíÒªÇóµÄC&CµØÖ·ÈçÏÂ(ÔÚа汾ÖÐ91.121.109.209±»ÒƳý)£º

        91.121.109.209

        217.12.202.40

        94.242.222.68

        ͨ¹ýTorÍøÂçÒªÇóµÄµØÖ·ÈçÏ£¨ÔÚа汾ÖÓ×±zuh3vcyskd4gipkm.onion/bin32/update.php¡±±»ÒƳý£©£º

6b57dcnonk2edf5a.onion/bin32/update.php

zuh3vcyskd4gipkm.onion/bin32/update.php

tljmmy4vmkqbdof4.onion/bin32/update.php

        ÕâÁ½ÖÖ·½Ê½µÄÒªÇó¶¼ÊÇͨ¹ýsslºÍ̸½øÐеÄ¡£ÒªÇóʵÏֺ󣬶ñÒâ´úÂë½âÎöÏàÓ¦Êý¾Ý²¢ÇÒÌáÈ¡³ö½ÚÔìºÅÁîºÍ½ÚÔì²ÎÊýÐÅÏ¢¡£ÆäʵÏÖµÄÔ¶³Ì½ÚÔìºÅÁîºÍ½ÚÔì²ÎÊýÐÅÏ¢ÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´Ó¸ÃºóÃÅʵÏÖµÄÔ¶³Ì½ÚÔìÖ°ÄÜÎÒÃÇÄܹ»´§Ä¦¸ÃºÚ¿ÍµÄ¶¯»ú£º

        (1)  ºÍÆäËûºóÃÅÒ»Ñù£¬ºÚ¿Íµ«Ô¸¿ÉÄÜͨ¹ýÔ¶³ÌshellºÅÁî¶ÔÉ豸½øÐÐÆëÈ«µÄ½ÚÔì¡£

        (2)  ºÚ¿ÍÄܹ»ÔÚÒ»°´»úÓö¶ÔÕâЩÉ豸½øÐзÛËéÐÔ²Ù×÷£¬Ê¹ÆäÎÞ·¨ÔÙ´ÎʹÓá£

        (3)  ÎªÁ˰µ²ØÆä¿ÉÒɵĽÚÔìÁ÷Á¿£¬Ñ¡È¡socks5ºÍTorÌÓ±ÜIDS¼à²â¡£

        (4)  Äܹ»½Ã½ÝµÄÅäÖÃÆäÔÚTorÍøÂçÖеÄC&C·þÎñÆ÷ÒÔ¼°´úÀí·þÎñÆ÷

        (5)  ÄÜÌṩÀ©´óÄ£¿éµÄÏÂÔØÓëÖ´ÐеIJÙ×÷¡£

        (6)  ¿É½Ã½ÝÅäÖÃÏνÓC&CµÄƵÂÊ£¬Ìá¸ßÆä»î¶¯µÄÒñ±ÎÐÔ¡£

        ´Ë±í£¬¸Ã½×¶ÎµÄ×îжñÒâ´úÂëÓнϴóµÄ±ä¶¯£¬²»½ö¶Ô´úÂë×öÁËÓÅ»¯¡¢È¥³ýÁËÈÕÖ¾ÐÅÏ¢£¬»¹Å¤×ªÁ˲¿ÃŽÚÔìºÅÁîµÄÖ°ÄÜ£¬ºÃ±ÈkillºÅÁîÓÃÓÚʵÏÖ¹ý³Ì¼°ËãÕÊÆäÏÂÔØµÄ²å¼þ£¬ÐÂÔö³¤ÁËupdateºÅÁîºÍrestartºÅÁî¡£²»ÑÔ¶øÓ÷£¬updateºÅÁîÓÃÓÚ¸üÐÂÑù±¾£¬restartºÅÁîÓÃÓÚ³ÁÆôÑù±¾Ö´ÐС£Í¬Ê±ÒƳýÁËseturl¡¢proxyºÅÁî¡£

µÚÈý½×¶Î£ºÀ©´ó×é¼þ

        µÚÈý½×¶ÎĿǰÒѾ­·¢ÏÖ´óÁ¿µÄ×é¼þ£¬ÆäÖÐÔ̺¬Ò»¸öΪMIPSƽ̨µÄÁ÷Á¿Ðá̽Æ÷¡¢Ò»¸öÓÃÓÚ·ÛËéÉ豸µÄdstrÄ£¿é¡¢Ò»¸öÓÃÓÚ½øÐÐ¿í·ºHTTPÁ÷Á¿Ðá̽ºÍ¼à¿ØµÄsslerÄ£¿é£¬»¹ÓÐһЩ¸¨ÖúÐÔÄ£¿éÈ磺Tor client¡¢mikrotik.o¡¢torrc¡¢ip_tables.ko¡¢iptable_filter.ko¡¢iptable_nat.koµÈ¡£¸¨ÖúÐÔÄ£¿éÈçTor¿Í»§¶ËÓÃÓÚÖ§³ÖµÚ¶þ½×¶ÎµÄTorÍøÂçͨѶ¡£Tor¹¤³ÌÌáÐÑ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÓÉÓÚÆäΪ³ß¶ÈµÄTor¿Í»§¶Ë£¬²»¾ß±¸¶ñÒâÖ°ÄÜ£¬Òò¶øÎÒÃǽö½ö·ÖÎöÖ÷ÌâµÄÈý¸öÄ£¿é¡£

        1¡¢MIPSƽ̨µÄTCPÁ÷Á¿Ðá̽Ä£¿é

        ¸ÃÄ£¿éΪMIPSƽ̨£¬ÆäÖØÒªÍ¨¹ý´ÓԭʼÊý¾Ý°üÖйýÂ˳öTCP/IPÊý¾Ý°ü£¬²¢ÇÒͨ¹ý¶ÔTCPµÄpayloadÊý¾Ý½øÐйýÂË£¬¼ìË÷ÆäÖеÄÃô¸ÐÐÅÏ¢´æ´¢ÆðÀ´¡£

        ¸ÃÁ÷Á¿Ðá̽Ä£¿éͨ¹ýµÚ¶þ½×¶Î¶ñÒâ´úÂëÔ¶³ÌÏÂÔØ²¢Æô¶¯Ö´ÐУ¬ÆäÆô¶¯ÔËÐвÎÊýÈçÏ£º

        {Ä£¿éÃû} DstDir Unkownagr ModbusServer

        ÆäÖеÚÒ»¸ö²ÎÊýΪÐá̽Êý¾ÝµÄ´æ·Åõè¾¶£¬µÚ¶þ¸ö²ÎÊýδʹÓ㬵ÚÈý¸ö²ÎÊýΪmodbus serverµÄIPµØÖ·¡£

        ¸ÃÄ£¿éÆô¶¯ºó²¢Ã»ÓÐ×ö¹ý¶à¶î±íµÄ¹¤×÷£¬³õʼ»¯»·¾³ºóÖ±½ÓŲÓÃÁ÷Á¿½ØÈ¡º¯Êý½øÐÐÁ÷Á¿Ðá̽¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ͬÑù¶þ½øÔ취ʽÖв»´øÈκηûºÅÎļþ£¬º¯ÊýÓÉÎÒÃÇ·ÖÎöÍêºó½øÐÐÁ˳Á¶¨Ãû¡£¸Ãº¯ÊýÖØÒª´´½¨Ò»¸öԭʼsocket²¢Çҽӹܵ±Ç°É豸Ëùͨ¹ýµÄԭʼÊý¾ÝÁ÷¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´¶ñÒâ´úÂë»áƾ¾ÝTCP/IPÍ·²¿Ìåʽ¼ø±ð³öTCPÊý¾Ý°üÒÔ½øÇ°½øÒ»²½µÄ´¦Öá£

        Ê×ÏȸÃÄ£¿éÖ»¹ØÇÐÊý¾Ý°ü³¤¶È´óÓÚ0x96¸ö×Ö½ÚµÄԭʼÁ÷Êý¾Ý£¬Ò²¾ÍÊÇ˵³ýÈ¥TCP/IPºÍ̸ͷ²¿µÄ³¤¶ÈµÄ0x36¸ö×Ö½Ú£¬¸ÃÄ£¿é½ö½ö¼à¶½´óÓÚ0x60¸ö×Ö½ÚµÄTCP payloadÊý¾Ý¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¶ÔÓÚTCP payloadÊý¾Ý´óÓÚ0x60¸ö×Ö½ÚµÄÊý¾Ý°ü£¬¸ÃÄ£¿é»á½âÎöIP¡¢TCPºÍ̸£¬²¢ÇÒͨ¹ýÖ÷ÕŶ˿Ú502Åж¨µ±Ç°Á÷Á¿Êý¾ÝÊÇ·ñÊǹ¤¿ØµÄmodbus TCPºÍ̸°ü£¬ÈôÊÇÊÇ£¬ÇÒµ±Ç°Êý¾Ý°üµÄÖ÷ÕÅIPΪÔËÐвÎÊýÖÐÖ¸¶¨µÄIPµØÖ·£¬¸ÃÄ£¿é±ã»á½«¸ÃÊý¾Ý°üÖеÄÔ´IP¡¢Ö÷ÕÅIP¡¢Ô´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڼͼÏÂÀ´¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÆäÖмͼµÄÐÅÏ¢ÌåʽÈçÏ£º

        *modbus*

        Ô´IP:Ô´¶Ë¿Ú->Ö÷ÕÅIP:Ö÷ÕŶ˿Ú(È磺192.168.1.5:2243->192.168.1.3:503)

        ¸ÃÐÅÏ¢¼Í¼ÔÚÎļþ%workdir%/rep_[time].bin¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÈôÊǵ±Ç°ºÍ̸²»ÊÇmodbusºÍ̸£¬¸ÃÄ£¿é»áƾ¾ÝÒÑÓеĹ涨½øÐйýÂË£¬ÕÒ³öÆä¹ØÇеÄÁ½ÀàÊý¾Ý£ºÒ»ÖÖΪЯ´øÓÐÑéÖ¤ÐÅÏ¢HTTPÊý¾Ý°ü£¬Ò»ÖÖÊÇЯ´øÓеǼÐÅÏ¢µÄHTTPÒªÇóÊý¾Ý¡£ÆäÖÐÌáÈ¡ÑéÖ¤Êý¾ÝµÄ¹Ø¼ü×ÖΪ"Authorization: Basic¡±£¬Ò»µ©ÕÒµ½¸ÃÐÅÏ¢£¬¸ÃÄ£¿é»á½«µ±Ç°Ðá̽µ½µÄÊý¾Ý°üÖ±½Ó¼Í¼µ½Îļþ%workdir%/rep_[%time%].binÖС£

        ÌáÈ¡µÇ¼ÐÅÏ¢µÄ¹Ø¼ü×ÖÈçÏ£º

        Óû§Ãû¹Ø¼ü×Ö£º"User="¡¢"user="¡¢"Name="¡¢"name="¡¢"Usr="¡¢"usr="¡¢"Login="¡¢"login="

        µÇ¼ÃÜÂë¹Ø¼ü×Ö£º"Pass="¡¢"pass="¡¢"Password="¡¢"password="¡¢"Passwd="¡¢"passwd="

        ´Ë±íҪעÃ÷µÄÊÇ£¬Êý¾Ý°üÖÐÖ»ÓÐÂú×ãÈçÏÂǰÌᣬ¸ÃÄ£¿é±ã»áÅׯú£º

        (1)  Êý¾Ý°üµÄÖ÷ÕÅIPΪÄ£¿éÔËÐвÎÊýËùÖ¸¶¨µÄIP¡£

        (2)  Êý¾Ý°üµÄÔ´¶Ë¿ÚÓ×ÓÚ1024¡£

        (3)  Êý¾Ý°üµÄÔ´¶Ë¿ÚΪ8080/8088¡£

        (4)  TCP payloadÊý¾Ý³¤¶ÈÓ×ÓÚ0x14¡£

        (5)  TCP PayloadÊý¾Ý°üÖÐÔ̺¬ÓÐ"<?xml"¡¢">"¡¢"Basic Og=="¡¢"/tmUnblock.cgi"¡¢"Password required"¡¢"<div¡±¡¢"<form"¡¢"<input"¡¢"{"¡¢"}"¡¢"200 OK"¡¢".get"¡¢"<span "¡¢"<SPAN "¡¢"<DIV "µÈ¡£

        2¡¢ssler HTTPÐá̽Óë¼à¿ØÄ£¿é

        ¸ÃÄ£¿éÖØÒªÕë¶ÔHTTP²ãÖ´ÐÐÔ½·¢·á˶ºÍ׳´óµÄ´¦Öã¬ÆäÌṩÓÐHTTPÁ÷Á¿³Á¶¨Ïò¡¢HTTPÁ÷Á¿¼à¿ØÓë½ØÈ¡¡¢Á÷Á¿½Ù³ÖÓë´Û¸Ä¡¢¶¨Ïò×¢ÈëJSÒÔ½øÐо«×¼¹¥»÷µÈÖ°ÄÜ¡£ÆäÓɵڶþ½×¶ÎµÄ¶ñÒâÄ£¿éÆô¶¯ÔËÐУ¬ÔËÐвÎÊý×¢Ã÷ÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Ê×ÏȸÃÄ£¿é»áʹÓÃinsmodºÅÁî×°ÖÃÈý¸öiptableÓйصÄÄÚºËÄ£¿é (ip_tables.ko¡¢iptable_filter.ko¡¢ iptable_nat.ko)£¬Í¨¹ýÕâÈý¸öÄ£¿é£¬¶ñÒâ´úÂëÄܹ»½«×Ô¼ºµÄ¹æ¶¨ÅäÖõ½iptableÖÐÈ¥ ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´Ö´ÐÐÈçϺÅÁËùÓÐ80¶Ë¿ÚµÄÁ÷Á¿³Á¶¨Ïòµ½ÆäËù¼àÌýµÄ8888¶Ë¿ÚÉÏ£º

        iptables -I INPUT -p tcp --dport 8888 -j ACCEPT

        iptables -t nat -I PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8888

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ΪÁ˱£Õϸù涨²»»á±»É¾³ý£¬¸ÃÄ£¿é»áÿ¸ô5·ÖÖÓ¸üÐÂÒ»´Î¸Ã¹æ¶¨¡£

        ¸ÃÄ£¿é»á¹Ø×¢ËùÓÐ80¶Ë¿ÚÉϵÄÊý¾Ý£¬Ô̺¬Á÷Ïò·þÎñÆ÷¶ËºÍÁ÷Ïò¿Í»§¶ËµÄÊý¾Ý¡£ÔÚ´¦ÖÃÁ÷Ïò·þÎñÆ÷¶ËµÄÊý¾Ýʱ£¬ÎªÁË×î´ó»¯µÄ¼à¿Øµ½Ãô¸ÐÊý¾Ý£¬Æä»á¶ÔHTTPÒªÇóµÄÊý¾Ý½øÐп϶¨´Û¸Ä¡£ÔÚ´¦ÖÃÁ÷Ïò¿Í»§¶ËµÄÏìÓ¦Êý¾Ýʱ£¬Í¬Ñù»á¶ÔÊý¾Ý½øÐд۸IJ¢ÇÒÆ¾¾ÝÆô¶¯²ÎÊýµÄÖ¸¶¨À´¶ÔÌØ¶¨Ö¸±êÖ´Ðо«×¼µÄJS×¢È룬ÈëÇÖµ½¾ßÌå¿Í»§¶ËÖ÷»úÉÏ£¬Ò²¿ÉËùÒÔÄÚÍøµÄ°ì¹«Ö÷»úÉÏ¡£

        £¨1£©¶ÔÒªÇóÊý¾ÝµÄ´¦ÖÃ

        Ê×ÏÈ£¬¸ÃÄ£¿éΪÁË¿ÉÄÜ×î´óÏÞ¶ÈµÄ¼à¿Øµ½Á÷Á¿£¬Æä»á½«ËùÓÐÒªÇóÊý¾ÝµÄ"https://"´Û¸ÄΪ"http://"¡£ÎªÁËÈ·±£HTTP´«ÊäµÄÊý¾Ý¶¼Îª¿É´¦ÖÃÊý¾Ý£¬»áÅú¸Ä¡±Accept-Encoding¡±µÄÖµ£¬ÒÔ¼°Åú¸ÄConnectionµÄ·½Ê½£¬¾ßÌå´¦Ö÷½Ê½ÈçÏ£º

        i. ½«ÒªÇóÊý¾ÝÖеÄËùÓÐhttps´Û¸ÄΪhttp£¬ÒÔ·½±ã¼à¿Ø²¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÈçµÇ¼ƾ֤µÈ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ii. ÈôÊÇHTTPÒªÇóÖÐÔ̺¬ÓÓ×±Connection: keep-alive¡±£¬½«»á±»´úÌæÎª¡±Connection: close¡±¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        iii. ÈôÊÇHTTPÒªÇóÖÐ,HTTPÍ·ÖÐÔ̺¬ÓÐgzipÖµµÄ¡±Accept-Encoding¡±Í·²¿Óò(ÅųýurlΪjpg¡¢jpeg¡¢png¡¢gif¡¢css¡¢js¡¢ttf¡¢woffÎļþ)£¬Æä½«»áת»¯Îª¡±Accept-Encoding: plaintext/none¡±£¬ÕâÑùÒªÇóµÃµ½µÄÊý¾Ý±ã²»»á±»·þÎñÆ÷¶ËѹËõ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Ëæºó£¬¸Ã×é¼þ¿É¶Ô½ØÈ¡µÄÁ÷Á¿½øÐйýÂ˲¢½«ÓйØÊý¾Ý±£Áôµ½É豸ÖС£Ê×ÏÈÈôÊÇ¡±dump:domain¡±²ÎÊý±»Ö¸¶¨£¬httpÒªÇóµÄurl¡¢port¡¢http header³ÇÊб£ÁôÔÚÖ¸¶¨µÄÎļþÖС£ÈôÊÇÔÚdump²ÎÊýÖÐûÓÐÖ¸¶¨¾ßÌåÖµ(domain×Ö·û´®Îª¿Õ)»òÕßdump²ÎÊýûÓÐÖ¸°´Ê±£¬Æä»ádumpÔ̺¬ÓÐÌØ¶¨ÐÅÏ¢httpÒªÇóÐÅÏ¢¡£Æäͨ¹ýURLÀ´Åж¨µ±Ç°ÒªÇóÊÇ·ñÊÇÆä¹ØÇеÄÒªÇó£¬ÈôÊÇURLÖÐÔ̺¬Óйؼü×Ö£º

¡±sername=¡±¡¢¡±ser=¡±¡¢¡±ame=¡±¡¢¡±ogin=¡±¡¢¡±ail=¡±¡¢¡±hone=¡±¡¢¡±session%5Busername¡±¡¢¡±session%5Bpassword¡±¡¢¡±session[password¡±±ã»ádumpÒªÇóµÄÍ·²¿ÐÅÏ¢µ½Ö¸¶¨µÄÎļþÖС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Áí±í£¬¶Ôaccounts.google.com·¢Ë͵ÄPOSTÒªÇó£¬Ö»ÓÐÆäÖÐÔ̺¬ÓÐ×Ö·û´®¡±signin¡±,³ÇÊб»dumpÏÂÀ´¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        £¨2£©¶ÔÏìÓ¦ÐÅÏ¢µÄ´¦ÖÃ

        ËùÓÐHTTPÒªÇóµÃµ½µÄÏìÓ¦Êý¾Ý³ÇÊб»´¦Öã¬Æä´¦Ö÷½Ê½ÈçÏ£º

        i.  ÏìÓ¦ÐÅÏ¢ÖÐLocationµÄÖµÈôÊÇÊÇ¡±https://¡±£¬Ôò±»´úÌæÎªhttp://¡£

        ii. ÈôÊÇÏìӦͷ²¿ÖÐÔ̺¬ÓÐAlt-Scv¡¢Vary¡¢Content-MD5¡¢content-security-policy¡¢X-FB-Debug¡¢public-key-pins-report-only¡¢Access-Control-Allow-Origin£¬±ã»á±»×è¶Ï£¬Ò²¾ÍÊÇ˵£¬ÒªÇó·½ÎÞ·¨µÃµ½ÏìÓ¦¡£

        iii. DumpËùÓÐÒªÇó°üµÄÊý¾Ýµ½±¾µØ£¬ÆäÖÐÔ̺¬https://ºÍhttp://¡£

        iv. ÈôÊDzÎÊý¡±site:domain¡±Ö¸¶¨ÁËÓòÃû¹Ø¼ü×Ö»òÕßÓòÃûµÄÒ»²¿ÃÅ£¬Æä»á½«Ò»¶Îjavascript¾ç±¾×¢Èëµ½ËùÓÐÔ̺¬Óеġ±Content-Type: text/html¡± »òÕß¡±Content-Type: text/javascript¡±ÏìÓ¦Êý¾ÝµÄmsgbodyÖС£Æä×¢Èë²½Ö裺Ê×ÏÈÏìÓ¦µÄmsgbodyÊý¾ÝÖбØÐëÔ̺¬×Ö·û´®¡±<meta name= ¡­ >¡±²¢ÇÒ³¤¶È±ØÐë´óÓÚ²ÎÊý¡±hook:¡±ËùÖ¸¶¨µÄ×Ö·û´®³¤¶È¡£ÈôÊÇÂú×ãǰÌᣬ×Ö·û´®¡±<meta name= ¡­ >¡±½«»á±»´úÌæ³ÉΪ¡±<script type="text/javascript" src="[hook value]">¡±£¬µ±Ç°Êܺ¦ÕßIP¼°Æä½Ó¼ûµÄÍøÕ¾ÓòÃû½«»á²ÎÓëµ½ÄÚ²¿µÄÒ»¸ö°×Ãûµ¥ÖУ¬ÒÔÔ¤·À³Á¸´×¢È룬°×Ãûµ¥Ã¿4Ìì»á±»Çå¿ÕÒ»´Î¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÔÚÏìÓ¦Êý¾ÝÖУ¬¶ñÒâÄ£¿é»áÌáȡÿ¸öÁ´½ÓÖеÄÓòÃû£¬²¢ÇÒ½«Æä²ÎÓëµ½½ØÈ¡ÁбíÖУ¬Õâ¸ö½ØÈ¡ÁбíÖÐËùÓеÄhttpsºÍhttpÒªÇó³ÇÊÐÒÀÕÕ¡°£¨1£©¶ÔÒªÇóÊý¾ÝµÄ´¦Öᱵķ½Ê½½øÐд¦Öá£Ä¬ÈÏÇé¿öÏÂÔ̺¬ÓÐ www.google.com¡¢ twitter.com¡¢ www.facebook.com¡¢www.youtube.com¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        3¡¢ É豸·ÛËéÄ£¿é£¨Destroy module£©

        ÓÉÓÚÀϰ汾µÄµÚ¶þ½×¶ÎÄ£¿éµ¥´¿µÄÖ»Êǵ¥Ò»²Á³ýÉ豸mtdblock0µÄǰ5000¸ö×Ö½ÚÒÔ·ÛËéÉ豸£¬Óкܴó¼¸ÂÊ»áʧ°Ü£¬Òò¶øÐ°汾µÄµÚ¶þ½×¶ÎÄ£¿é½«killÖ¸ÁîµÄ·ÛËéÐÔÖ°ÄÜÈ¡µÞ£¬²¢Ñ¡È¡²å¼þÄ£¿éµÄ·½Ê½À´ÊµÏÖ¡£¸Ã²å¼þÄ£¿é²»½ö¸Ä½øÁË·ÛËéÉ豸ְÄÜ£¬²¢ÇÒ»¹ÌṩÁ˺ۼ£ËãÕʵÄÖ°ÄÜ¡£ÆäÖ÷ÕŲ»½öÈÃÉ豸ÎÞ·¨¸´Ô­£¬²¢ÇÒ¼´±ã¸´Ô­ÁËÒ²ÎÞ·¨È¡Ö¤»ñÈ¡¶ñÒâ´úÂëÓйغۼ£¡£

        Ä£¿éÆô¶¯ºóÊ×ÏÈɾ³ý×ÔÉíÎļþ£¬¶øºóÇ¿Ôì¹Ø¹ØËùÓÐÔ̺¬"vpnfilter"¡¢"security"¡¢"tor"¹Ø¼ü×ֵĹý³Ì¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´ËãÕʵôËùÓкۼ£Îļþ£¬ÆäÖÐÔ̺¬ÓÐÖ¤ÊéÎļþ¡¢Tor¿Í»§¶ËÓйØÎļþ¡¢°æ±¾ÐÅÏ¢ÎļþµÈ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¸ÃÄ£¿é»¹»á±éÀúmtd·ÖÇø£¬²¢Ç¿Ôì²Á³ýÕû¸öFLASH¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ×îºó£¬Æäѡȡ¡±"rm -rf /*"¡±Ç¿ÔìµÝ¹éɾ³ýÎļþϵͳÉϵÄËùÓÐÎļþ£¬²¢³ÁÆôÉ豸¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ËÄ¡¢×ܽá

        ͨ¹ý¶ÈÎöÎÒÃÇÄܹ»¿´³ö£¬¸Ã¶ñÒâ´úÂë¹¥»÷ÊÖ·¨ÒþÃØ¸ßÃÆä²»½öѡȡ´úÀí+Tor+SSLµÄ·½Ê½ÒÔÌÓ±ÜÍøÂçÁ÷Á¿µÄ¼à²â£¬²¢ÇÒ»¹Óжà³ÁÕ½ÊõÓÃÓÚÈ·±£Ö÷Ìâ×é¼þ(µÚ¶þ½×¶Î¶ñÒâ´úÂë)µÄ³É¹¦Ï·¢¡£Ê×ÏÈѡȡÁËHTTPµÄ·½Ê½½«C&C´æ·ÅÓÚ¡±direct¡±»òÕß¡±location¡±×Ö¶ÎÖУ¬ÈôÊÇÕâÖÖ·½Ê½±»×è¶ÏÔòѡȡͼƬÒþд¼¼Êõ½«C&C´æ´¢ÓÚEXIFÖУ¬ÈôÊÇ´æ´¢C&CµÄͼƬÁ´½ÓʧЧ£¬Æä»¹ÔÚ´úÂëÖÐÁôÁËÒ»¸ö¡±SYN¡±ºóÃÅ£¬Í¨¹ý¡±SYNËí·¼¼Êõ¡±À´´«ÊäC&C¡£ÕâÖÖÄܹ»ËµÊǺڿͲÉÈ¡µÄÒ»ÖÖ½ÏΪ¸ßÃîÇÒ¼«¶È±£ÏÕµÄÕ½Êõ£¬ÎªÆäÐж¯ÔÚ±»·¢ÏÖÉõÖÁÊDZ»×è¶ÏºóÉèÖÃÁ˶à³Á±£ÏÕ£¬Ò²±ãÓÚÔÚºÚ¿Í·¢ÏÖ±»×è¶Ïºó½øÐм±¾çÇл»£¬¼«´óµØÌá¸ßÁËÆä½ÚÔìµÄÓÆ¾ÃÐԺͽýÝÐÔ¡£

        ÎÒÃÇ»¹Äܹ»¿´µ½£¬Ñ¸ÃÍ·¢Õ¹µÄÎïÁªÍøÉ豸ҲÆðÍ·Ôì³É¸ß¼¶Íþв×éÖ¯µÄÒ»À๥»÷ÏòÁ¿£¬ÆäÊÔͼͨ¹ýÕâЩÉ豸À´ÍøÂçµý±¨£¬Ô̺¬µÇ¼ƾ֤ÒÔ¼°¹¤¿ØÉèÊ©ÓйصijÁÒªÐÅÏ¢£¬Í¨¹ý½Ã½ÝµÄÄ£¿é»¯¼Ü¹¹£¬¿Éƾ¾ÝÓйصý±¨¶ÔÌØ¶¨Ö÷»úÖ´Ðо«×¼¹¥»÷»òÕß¶Ô´óÁ¿É豸ִÐм«¾ß·ÛËéÐԵĹ¥»÷£¬Æä·çÏÕÐÔ¼«¶ÈÖ®´ó¡£

        ½¨Òé³§É̽«¼ì²â¹æ¶¨£¨TalosÒѾ­¹«¿ªÁË100¶àÌõsnort¹æ¶¨£©²ÎÓëµ½Á÷Á¿¼ì²âÉ豸ÖУ¬ÈôÊÇÖ§³ÖԭʼÁ÷Á¿¼ì²â£¬Ò²¿ÉÀûÓá°SYNËí·¼¼Êõ¡±ÖеÄÌØµã½øÐÐÔ½·¢Éî¶ÈºÍ¾«È·µÄ¼ì²â¡£Ò»µ©·¢ÏÖÊÜϰȾÉ豸£¬½¨ÒéѡȡӦ¼±Õ½Êõ¶ÔÉ豸½øÐдëÖ㨺ñȶÔÉ豸½øÐжÏÍø²¢ÇÒ¸´Î»¸´Ô­µ½³ö³§Ä£Ê½¡¢¸üÐÂ×îй̼þ£©£¬Í¬Ê±½øÒ»²½²é³­ÄÚÍøÖ÷»úÊÇ·ñÓб»¹¥»÷²¢ÇëרҵÈËÊ¿½øÐд¦Öá£

 

 

IOC:

µÚÒ»½×¶ÎÉæ¼°µÄÓйØURL:

photobucket[.]com/user/nikkireed11/library

photobucket[.]com/user/kmila302/library

photobucket[.]com/user/lisabraun87/library

photobucket[.]com/user/eva_green1/library

photobucket[.]com/user/monicabelci4/library

photobucket[.]com/user/katyperry45/library

photobucket[.]com/user/saragray1/library

photobucket[.]com/user/millerfred/library

photobucket[.]com/user/jeniferaniston1/library

photobucket[.]com/user/amandaseyfried1/library

photobucket[.]com/user/suwe8/library

photobucket[.]com/user/bob7301/library

toknowall[.]com

µÚ¶þ½×¶ÎÉæ¼°µÄÓйØIP¼°Á´½Ó£º

91.121.109[.]209

217.12.202[.]40

94.242.222[.]68

82.118.242[.]124

46.151.209[.]33

217.79.179[.]14

91.214.203[.]144

95.211.198[.]231

195.154.180[.]60

5.149.250[.]54

91.200.13[.]76

94.185.80[.]82

62.210.180[.]229

62.210.180[.]229

91.200.13[.]76

23.111.177[.]114

6b57dcnonk2edf5a[.]onion/bin32/update.php

tljmmy4vmkqbdof4[.]onion/bin32/update.php

zuh3vcyskd4gipkm[.]onion/bin32/update.php

4seiwn2ur4f65zo4.onion/bin256/update.php

zm3lznxn27wtzkwa.onion/bin16/update.php

×îÐÂÊÜϰȾµÄÉ豸ÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

²Î¿¼Á´½Ó£º

https://blog[.]talosintelligence.com/2018/05/VPNFilter.html

https://blog.talosintelligence.com/2018/06/vpnfilter-update.html