ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö
°ä²¼¹¦·ò 2019-05-18½üÆÚ£¬GA»Æ½ð¼×ADLab¼à²âµ½Ò»ÅúÒÉËÆÕë¶ÔÎ÷°àÑÀÓïµØÓòÈ·µ±¾Ö»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿Ãŵ͍Ïò¹¥»÷»î¶¯£¬ºÚ¿Í×é֯ͨ¹ý»ú¹Ø¶ñÒâOffice WordÎĵµ²¢¹²Í¬Óã²æÓʼþÌáÒ鶨Ïò¹¥»÷£¬ÒÔ¡°¼òÀú¸üС±×÷Ϊµö¶üÎĵµÏò¹¥»÷Ö¸±êÖ²Èë¼äµýľÂí£¬´Óʵý±¨ÍøÂç¡¢Ô¶¿Ø¼à¶½¼°ÏµÍ³·ÛËéµÈ¶ñÒâÐж¯¡£ÎÒÃǽ«ÍÁ¶úÆäºÚ¿ÍµÄÕâ´Î¹¥»÷Ðж¯³ÆÎª¡°ºÚʨÐж¯¡±¡£
ͨ¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷ÓйØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷ÆðÔ´ÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¸Ã×éÖ¯ÊÇÒ»¸öÃñ×åÖ÷ÒåÉ«²Ê¼«¶ÈŨÃܵĺڿÍ×éÖ¯£¬Ôø¹¥ÏÂÆäËû¹ú¶ÈµÄ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂÆä×éÖ¯µÄÃû³Æ£¬ËæºóÒþûÁ˶àÄê¡£ Èç½ñͨ¹ýÎÒÃǶԡ±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯¼£Ïó¡£±¾´Î¹¥»÷¹ý³ÌÖУ¬¸ÃºÚ¿Í×éÖ¯Ñ¡È¡ÉøÈ뼿Á©¹¥Ï¶ą̀·þÎñÆ÷²¢½«Æä×÷Ϊ´æ·Å¹¥»÷´úÂëµÄÌø°å¡£
1Íþв·ÖÎö
1.1 ¹¥»÷Ö¸±ê·ÖÎö
´ÓĿǰËù»ñÈ¡µÄ¹¥»÷Ñù±¾ºÍÍþвµý±¨£¬Äܹ»¿´³ö±¾´Î¹¥»÷»î¶¯²¢Ã»Óдó¹æÄ£µÄ½øÐУ¬Ä¿Ç°»¹´¦ÓÚ¹¥»÷ÊÔ̽½×¶Î£¬µ«ÊÇ´ÓÆäͶ·ÅµÄµö¶üÎĵµÄܹ»µ¥Ò»¼òÖ±¶¨Æä¹¥»÷Ö¸±êËø¶¨ÔÚÎ÷°àÑÀÓïϵµÄ¹ú¶È¡£ÕâЩµö¶üÎĵµÐÎÈ磺¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±£¨¼òÀú¸üРº£Ã·°¢ÀïÑÇ˹£©¡¢¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±(¼òÀú¸üРµ¤Äá¶û°ÂµÙ×È)¡¢¡°Michelle Flores - Curriculum Actualizado.doc¡±(Ã×Ъ¶û¸¥ÂåÀ×˹-¼òÀú¸üÐÂ)¡¢¡°Jose Trujillo.doc¡±(ºÎÈûÌØÂ³Ï£ÂÔ)µÈµÈ£¬ËüÃǾùѡȡÎ÷°àÑÀÓïÀ´»ú¹ØÒ»¸ö´ø¶ñÒâºê´úÂëµÄ¼òÀúÎļþ¡£ÒÔ´ËÀ´¶ÔÖ¸±êÈËÁ¦²¿ÃŽøÐй¥»÷£¬ÒÔÓÕʹÓйØÈËÔ±Ö´ÐжñÒâ´úÂë½ø¶ø´Óʼäµý»î¶¯¡£
ÔÚÎÒÃÇ·ÖÎöÕâÅúµö¶üÎĵµÊ±£¬»¹·¢ÏÖÒ»¸öÓÐȤµÄ¾°Ïó£¬ÄǾÍÊǺܶàµö¶üÎĵµÖÐÔ̺¬ÁËÎĵµ×÷ÕßÐÅÏ¢ºÍ×îºóÒ»´Î±£ÁôÕßÐÅÏ¢£¬²¢ÇÒÕâЩÐÅÏ¢¾ùΪÀàËÆ²ÆÕþ²¿¡¢Ðŷþ֡¢SCG£¨Southern Connecticut Gas£©µÈµÅ×ëµ±²¿ÃÅÃÅÓйصÄÐÅÏ¢¡£Í¨¹ýÎÒÃÇÏÖʵ²âÊÔ·¢ÏÖ£¬ÕâЩÐÅÏ¢¾ù»áÔÚÎĵµÅú¸ÄºóÔì³Éµ±Ç°½Ó¼ûÕßofficeµÇ½ÕË»§Ãû»òÕßÖ÷»úÃû£¬²¢ÇÒÓÐÐĵÄÈË»¹Äܹ»¶ÔÆä½øÐÐËÁÒⶨÔì¡£ÎÒÃǰÎÈ¡¼¸¸öµäÐ͵ÄÑù±¾²¢Õë¶ÔÓйØÐÅÏ¢ºÍÂß¼¹ØÏµ×öÁËÈçÏÂÊáÀíºÍÍÆÂÛ£º
ÎÒÃÇͨ¹ý´´½¨ÄÚÈݹ¦·ò¡¢×îºóÅú¸Ä¹¦·ò¼°¹¥»÷ÎĵµÄÚ²¿µÄÂß¼¹ØÏµÍÆÂÛ³öÓйؼͼӦΪ¹¥»÷Õß±£Áô¡£»ùÓÚ×îºÏÀíÒÔ¼°×îÓпÉÄܵĴ§Ä¦£¬ÎÒÃÇÒÔΪ¹¥»÷Õß¿ÉÄÜÊÇ»ùÓÚºÚ¿Í×éÖ¯ÄÚ²¿¹æ·¶£¬½«ÎĵµµÄÓйØÃû³ÆÉèÖÃΪ¹¥»÷Ö¸±ê»òÓйØÐÐÒµÐÅÏ¢£¬´Ó¶øÎ±Ôì³ÉÄÚ²¿ÈËÊ¿£¬Ôڿ϶¨Ë®Æ½ÉÏÆðµ½»ìºÏÊÓÌý¡¢Òñ±Î×ÔÉíµÄÖ÷ÕÅ¡£
ÓÉ´ËÎÒÃÇÄܹ»¿´³öÕâ´ÎÐж¯µÄ¹¥»÷Ö¸±êΪÎ÷°àÑÀÓïϵµØÓòÈ·µ±¾Ö»òÕß¹«¹²·þÎñ²¿ÃÅ£¬µ±È»²¢²»ÅųýÆäÓиü¶àµÄÖ¸±ê£¬ÖÁÉÙÄܹ»×¢¶¨µÄÊÇÕâ´ÎÐж¯ÊÇÒ»´Î´øÓÐÕþÖÎÖ÷ÕŵĹ¥»÷»î¶¯¡£
1.2 ºÚ¿Í×éÖ¯·ÖÎö
ÔÚ¶ñÒâ´úÂë´æ´¢õè¾¶µÄͬĿ¼£¬ÎÒÃÇ·¢ÏÖºÚ¿Í×éÖ¯ËùÁôϵÄһЩÐÅÏ¢£¬ÏÂͼΪÆäÖÐÒ»¸öÎļþ¼Í¼µÄÐÅÏ¢£º
¸ÃÎļþÖÐÔ̺¬ÁËһЩÉêÃ÷ÐÅÏ¢¡¢ºÚ¿Í×éÖ¯¼°ÆäÓйسÉÔ±£¬²¢ÇÒËùѡȡµÄ˵»°ÎªÍÁ¶úÆäÓÒò¶øÎÒÃÇÅж¨¸Ã×éÖ¯ÕýÊÇÒѾ»îԾһʱµÄKingSqlZºÚ¿Í×éÖ¯¡£¸Ã·þÎñÆ÷ºÜÓпÉÄÜÔÚ±»ºÚ¿Í×éÖ¯½ÚÔìºó×÷ÎªÌø°å»ú»ò×ÊÔ´·þÎñÆ÷³ÖÐøÊ¹Óᣴ˱íͨ¹ý¶ñÒâ´úÂëʱ·Ö±æÎö·¨£¬ÎÒÃǽøÒ»²½È·¶¨¸Ã´Î¹¥»÷À´×ÔÓÚÍÁ¶úÆäºÚ¿Í¡£ÎÒÃǶÔRATÑù±¾Ö®Ç°µÄPEÎļþ¼°ÆäËûǰÆÚ¹¥»÷»·½ÚÓйصÄÑù±¾µÄ±àÒ빦·ò×öÁËʱ·Ö±æÎö£¨ÓÉÓÚRATÑùÕý±¾×ÔÓÚÉÏÓκڿͣ¬Òò¶øÎÒÃǺöÂÔÁ˸ÃÀàÑù±¾µÄʱ·Ö±æÎö£©¡£×îºó·¢ÏÖÕâЩ¹¥»÷Ñù±¾µÄ±àÒ빦·òÔÚUTC¹¦·ò21:00ÖÁ06:00Çø¼äÄÚ³öÏֵįµ´Î¼«µÍ¡£¶ø¼Ù¶¨ÒÔ24:00ÖÁ08:00×÷Ϊ˯Ãß¹¦·ò£¬¹¥»÷ÕßËù´¦µÄÊ±Çø¿ÉÄÜ»áÔÚ¶«3Çø£¨UTC+3£©Õý¸º 1 Ó×Ê±Çø¼äÄÚ£¬¶øÍÁ¶úÆäÊ±ÇøÎª¶«ÈýÇøÕýºÃÇкϡ£
±¾´Î¹¥»÷»î¶¯ÆðÍ·ÓÚ2019Ä꣬ѡȡ´óÁ¿¹«¹²DDNS·þÎñ×ÓÓòÃû×÷ΪC2À´Ö´Ðй¥»÷£¬ÕâÆäÖеÄһЩÓòÃûΪ2019ÄêÐÂ×¢²áµÄ£¬Ê¹ÓõIJ¿ÃÅÓòÃûÈçÏ£º
casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
2¹¥»÷¸ÅÊö
Õâ´ÎÊÂÎñµÄÖØÒª¹¥»÷»î¶¯¹¦·òÏßÈçÏÂËùʾ:
ÆäÖУ¬ÎÒÃǶÔ2019Äê2ÔÂ7ÈÕ·¢Ïֵġ°Curriculum Vitae Actualizado Jaime Arias.doc¡±Îĵµ½øÐÐÁ˾ßÌåµÄ·ÖÎö£¬²¢Ïà¼Ì²¶»ñµ½¹ØÁªÎĵµ¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc/ Jose Trujillo.doc¡±¡£
¹¥»÷ÕßʹÓÃÁËAPI¹þÏ£¡¢ÎÞÎļþ¹¥»÷¡¢WinrarSFX¡¢AutoIt¡¢C#»ìºÏºÍ¿þÀܹý³ÌµÈ¼¼ÊõÀ´¶ã±Ü¼ì²â²¢×ÌÈÅ·ÖÎöÈËÔ±¡£ÆäÖУ¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ÎĵµÖ²ÈëµÄľÂíÆðÔ´×î³õÎÞ·¨È·ÈÏ£¬ÎÒÃÇÔÚÆäÖз¢ÏÖÁËÌØµã×Ö·û´®¡°AVE_MARIA¡±,ÆäÓëCybaze-Yoroi ZLab×êÑÐÈËÔ±ÔÚ2018Äê12Ôµ×Åû¶µÄÕë¶ÔÒâ´óÀûijÄÜÔ´ÆóÒµ½øÐй¥»÷µÄ¶ñÒâÈí¼þÀàËÆ¶ÈºÜ¸ß£¬²¿ÃŰ²È«×êÑÐÔ±ºÍ³§ÉÌÓÉÓÚûÓгɹ¦µÄ½øÐÐËÝÔ´±ãÒÔ´Ë×Ö·û´®×öΪ¸ÃľÂí¼Ò×åµÄÃû³Æ¡£¶øÎÒÃǾ¹ý¹ØÁªËÝÔ´ºÍͬԴÐÔ·ÖÎöºó·¢ÏÖ£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾Í¬RAT¹¤¾ß¡°WARZONE¡±RATÓµÓи߶ÈÒ»ÖÂÐÔ£¬Òò¶ø½«´ËÀà¶ñÒâ¼Ò×嶨Ãû¸üÐÂΪ¡°WARZONE¡±¡£
3¼¼Êõ·ÖÎö
3.1 ÔçÆÚ¹¥»÷Ñù±¾
Õâ´Î¹¥»÷¹ý³ÌÆðÍ·ÓÚÒ»¸öЯ´ø¶ñÒâºêµÄDOCÎĵµ£¬ºÚ¿Íͨ¹ýαÔì³É¼òÀúµÄͶµÝÓʼþ¼¿Á©½«´Ë¶ñÒâÎļþ·¢Ë͸ø¹¥»÷Ö¸±ê£¬µ±Ö¸±êÓû§Ê§É÷´ò¿ªÎĵµ±ã³ÉΪÁËÊܺ¦Õß¡£DOCÎĵµÔËÐкó»áÆô¶¯¶ñÒâºê´úÂë²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÏÂÔØEtr739.exe£¬³É¹¦ÏÂÔØºóµ±¼´Ö´ÐС£Ð¹ý³Ìͨ¹ýBase64½âÂë³öÁíÒ»¸ö·þÎñÆ÷µØÖ·£¬³ÖÐøÏÂÔØ¶ñÒâ´úÂëhqpi64.exeÖÁһʱĿ¼Ï¡£¶ñÒⷨʽhqpi64.exe¾ÍÊÇWarzone RATµÄ¿ªÊÍÆ÷£¬Æäͨ¹ý¿ªÊÍWarzone RATÀ´Ö´ÐкóÐø²Ù×÷£¬È罫explorer.exe×÷Ϊ¿þÀܹý³ÌÊØ»¤¡¢Óë½ÚÔì¶Ë½øÐÐͨѶµÈ¡£
Ñù±¾ÖеĶñÒâ´úÂë´ó²¿ÃÅѡȡCRC32À´¼ÓÃÜÃô¸Ð×Ö´®£¬Í¬Ê±ÔÚAPIŲÓÃÊÖ·¨ÉÏѡȡÁËAPI HashÖµ¶¯Ì¬»ñÈ¡º¯ÊýµØÖ·ºÍ·ÂÕÕϵͳ¼±¾çŲÓÃÁ½ÖÖ·½Ê½¡£Ê¹ÓôËÀàÊÖ·¨²»Ö»ÄÜÔڿ϶¨Ë®Æ½ÉÏÏ÷¼õɱÈí¾²Ì¬É¨ÃèµÄ¼ì²â£¬²¢ÇÒ»¹²»Ò×±»¼à²âµ½APIµÄŲÓÃ×ÙÓ°¡£Í¬Ê±ÆäʹÓô¿¼ÓÃÜShellcode´úÂëÄÚ´æÖ´Ðеķ½Ê½¼ÓÔØÆäÖ÷ÌâÖ°ÄÜÄ£¿é£¬Í¨¹ý¡°ÎÞÎļþ¼¼Êõ¡±Ìá¸ß×ÔÉíÒñ±ÎÐÔ£¬ÒÔ´ËÀ´¶ã±Ü°²È«³§É̲éɱ¡£ÆäÓëC2·þÎñÆ÷¼äµÄͨѶÊý¾ÝÒ²ÒÔCR4Ëã·¨½øÐмÓÃܽø¶ø¶ã±ÜIDSϵͳµÄ¼ì²â¡£
(1)DOCÎĵµ
ÔÚAutoOpenº¯ÊýÖÐÔ̺¬ÁËÒ»´®»ìºÏ¹ýµÄcmdºÅÁ¾¹ý½âÃܺóµÄ´úÂëÈçͼËùʾ£º
Õâ¶Î´úÂë»ñµÃÖ´Ðк󣬻áÖ±½Ó´Ó´ËÁ´½ÓµØÖ·(http[:]//linksysdatakeys.se)ÏÂÔØ¶ñÒⷨʽµ½¡°%Temp%\SAfdASF.exe¡±²¢Ö´ÐС£
(2)Payload
¸ÃPayloadÏȽ«ÉÏͼÖмÓÃܵÄÊý¾Ýͨ¹ýBase64½âÂë³öÏÂÔØÁ´½ÓµØÖ·¡°http[:]//www.gestomarket[.]co/hqpi64.exe¡±£¬¶øºó°Ñhqpi64.exe¸ÄÃûΪ2XC2DF0S.exe²¢±£ÁôÔÚһʱĿ¼Ï¡£
(3)Dropper
ÔÚºóÐøµÄ½âÃÜÒÔ¼°Ö´ÐеĹý³ÌÖУ¬´ËDropper»á°ÑÒ»¶ÎShellcode×¢Èëµ½explorer¹ý³Ì²¢ÔÚÄÚ´æÖнâÃܳöRATʵÌåʹÆä²»Â䵨£¬×îÖÕͨ¹ýÎÞÎļþ¼¼Êõ½«RAT¼ÓÔØµ½ÄÚ´æÖÐÀ´Ö´ÐС£
Ìӱܼì²â
½âÃÜshellcode
×Ô½ç˵µÄ½âÃܺ¯Êý
¾¹ý³Á³ÁÏÂÔØ²¢½âÃÜÖ®ºó£¬ÄÇôÕâ¶Î½âÃܺóµÄShellcode(PE Loader)´úÂë¾ßÌåζ×öЩʲô£¬ÏÂÃæÎÒÃÇÀ´Ò»¿úµ½µ×¡£
PE Loader
|
ÐòºÅ |
ÄÚÈÝ |
Ö°ÄÜ |
|
²ÎÊý1 |
¡°FYBLV¡± |
¿½±´×ÔÉíµÄĿ¼ÃûºÍÎļþÃû(Ðè½âÃܵÄ×ÊÔ´Ãû) |
|
²ÎÊý2 |
¡°BJU¡± |
RATÔ¶¿ØÎļþ(Ðè½âÃܵÄPEÎļþ×ÊÔ´Ãû) |
|
²ÎÊý3 |
¡°OPTYUPPABIVSUWNRXSNCTDW¡± |
Key |
|
²ÎÊý4 |
0x01£¨¹Ì¶¨ÊýÖµ£© |
δʹÓà |
¸ÃPE LoaderÊ×ÏÈÔÚÔËÐйý³ÌÖнøÐÐÁËɳÏäºÍÖ¸¶¨¹ý³ÌµÄ¼ì²â£¬ÒÔÔ¤·À±»×Ô¶¯»¯ÏµÍ³·ÖÎö¡£²¢ÇÒÆ¾¾Ý×Ô´øµÄ×ÊÔ´Êý¾ÝÀ´Åж¨ÊÇ·ñÖ´ÐÐפÁô±¾»úµÄ²Ù×÷ºÍ×¢ÈëÌåµÄÑ¡Ôñ¡£×îºó´ËPE Loader½«×îÖÕÑ¡ÔñµÄ¿þÀܹý³ÌµÄ¿Õ¼ä¼Ü¿Õ£¬²¢°Ñ½âÃܳöµÄRATÄ£¿éÓ³Éäµ½´Ë¹ý³ÌÖÐÖ´ÐÐ(Õý±¾PEÎļþ´úÂë±»Öû»)¡£
ÔËÐл·¾³¼ì²â
ÔËÐл·¾³¼ì²â
²Ù×÷×ÊÔ´Êý¾Ý
¾¹ý¶ÈÎö£¬½á¹¹ÌåÖÐÿ¸ö³ÉÔ±µÄ¾ßÌåÖ°Äܿɲο¼ÏÂͼ£º
¿ªÊÍÓëפÁô
´´½¨µÄ¿ì½Ý¼üÊôÐÔ
×îºó£¬¸ÃPE Loaderƾ¾Ý½á¹¹ÌåÖеÄdwFlagÖ·´Ñ¡ÔñºóÐøµÄRATÔØÌ壬Ëù¶ÔÓ¦µÄRATÔØÌåÏê¼ûÏÂ±í£º
|
Êý¾Ý |
¹ý³ÌÃû |
|
0x01 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe |
|
0x02 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe |
|
0x03 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe |
|
0x04 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
0x05 |
C:\Windows\System32\svchost.exe |
|
0x06 |
C:\Windows\System32\dllhost.exe |
|
0x07 |
µ±Ç°ÔËÐеÄ×ÔÉí¹ý³Ì |
¶øÔÚ±¾Ñù±¾ÖУ¬´Ë³ÉÔ±µÄÖµËù¶ÔÓ¦µÄÔØÌåΪµ±Ç°ÔËÐеÄ×ÔÉí¹ý³Ì¡£
»ñÈ¡RAT²¢Ö´ÐÐ
½Ó×Å£¬¸ÃPE Loader³Áд´½¨Ð¹ý³Ì²¢½«ÆäÉèÖÃΪ¹ÒÆð״̬¡£¶øºóÐ¶ÔØ´Ë¹ý³ÌÓ³Ïñ£¬²¢°ÑÔÚÄÚ´æÖнâÃܳöµÄеÄPEÍ·²¿£¬ÒÔ¼°½ÚÊý¾Ý˳´ÎдÈëµ½¹ÒÆðµÄ¹ý³ÌÖУ¬×îºóÅú¸ÄOEP²¢Æô¶¯ÔËÐС£
(4) WARZONE RATÄ£¿é
Ô¶¿Ø·¨Ê½Warzoneºó¶Ü½çÃæ
»ñÈ¡C&CµØÖ·
ΪÁËÔ¤·ÀC&C±»µÈÏз¢ÏÖ»òÕßÅúÁ¿ÌáÈ¡£¬¸ÃľÂí½«Æä¼ÓÃÜºó´æ·ÅÔÚ¡°.bss¡±µÄ×ÊÔ´½ÚÊý¾ÝÖС£Í¨¹ý¶Ô½âÃܺ¯ÊýµÄ·ÖÎöÎÒÃÇ·¢ÏÖ£¬ÕâÀïѡȡÁËCR4Ëã·¨¡£CR4ÌìÉúÒ»ÖÖ³ÆÎªÃÜÔ¿Á÷µÄÎ±Ëæ»úÁ÷£¬ËüÊÇͬÃ÷ÎÄͨ¹ýÒì»ò²Ù×÷Ïà»ìºÏÀ´´ïµ½¼ÓÃܵÄÖ÷ÕÅ¡£½âÃÜʱÔòʹÓÃÃÜÔ¿µ÷¶ÈËã·¨(KSA)À´ÊµÏÖ¶Ô´óÓ×Ϊ256¸ö×Ö½ÚÊý×ésboxµÄ³õʼ»¯¼°´úÌæ¡£¾ßÌåÁ÷³ÌÈçÏ£º
(ÔÚ×ÊÔ´Êý¾ÝÖÐǰ0x32¸ö×Ö½ÚÊÇÃÜÔ¿£¬ÆäÓà0x68¸ö×Ö½ÚÔòÊÇ´ý½âÃܵÄÊý¾Ý)
ÃÜÔ¿ºÍ´ý½âÃÜÊý¾Ý
4£©´úÌæºóµÄsboxÊý×éÖеÄÊýÖµÈçÏÂͼ£º
5£©Í¨¹ý´úÌæºóµÄsboxºÍ´ý½âÃܵÄÊý¾Ý½øÐÐXORÔËËãºó£¬×îÖյõ½·þÎñÆ÷µÄhostµØÖ·"asdfwrkhl.warzonedns[.]com"¡£
Ö´ÐÐ×¢ÈëÖ°ÄÜ
½Ó×Å£¬¸ÃľÂíʹÓÃÔ¶³ÌÏ̵߳ķ½Ê½À´×¢ÈëÖ÷ÌâÖ°ÄÜShellcode´úÂ룬²¢ÔÚÆô¶¯Ô¶Ïß³ÌÖ´ÐÐʱ£¬Åú¸ÄдÈëÖ¸±ê¹ý³ÌÄÚ´æÆ«ÒÆµÄ0x10E´¦ÎªÆðÍ·Ö´ÐдúÂë¡£
ͨ¹ý¶ÈÎöÎÒÃÇ·¢ÏÖ£¬Õâ¶Î×¢Èë´úÂëµÄÖØÒªÖ°ÄÜÊÇÀûÓÿþÀܹý³ÌÀ´±£»¤Dropper(hqpi64.exe)¡£Æä»á°´Ê±²é³DropperÊÇ·ñ´¦ÓÚÔËÐÐ״̬£¬Èç±»¹Ø¹Ø£¬Ôò³ÁÐÂÆô¶¯¡£ÒÔ´Ë´ïµ½¹ý³ÌÊØ»¤µÄÖ÷ÕÅ¡£
¹ý³ÌÊØ»¤Ö°ÄÜ
ͨѶºÍ̸½âÎö
1£©ÏνӷþÎñÆ÷
2£©½âÃܽÚÔì°ü
3£©Ö´ÐнÚÔìÖ¸Áî
ͨ¹ýÎÒÃÇÇ°ÃæµÄ·ÖÎöÄܹ»¿´µ½£¬¸ÃľÂí½ÚÔìÖ¸ÁîÖÐÔ̺¬ÁË´óÁ¿Óû§ÒþÖÔÐÅÏ¢µÄÇÔȡְÄÜ¡£×îÖÕÊܺ¦ÕßµÄÃô¸ÐÊý¾ÝÐÅÏ¢£¬³ÇÊÐÆ¾¾ÝÔ¶³Ì·þÎñÆ÷µÄÖ¸Áî»Ø´«¸øÔ¶³Ì·þÎñÆ÷¡£
½ÚÔìÖ¸ÁîÖ°ÄÜ
|
½ÚÔìºÅÁî |
Ö¸ÁîÖ°ÄÜ |
|
0x01~0x04 |
ŲÓÃ×Ô½ç˵º¯Êý£¬²¢½«Ö´ÐÐÁ˾ֻش«·þÎñÆ÷ |
|
0x02 |
ÉÏ´«¹ý³ÌÁбí |
|
0x04 |
»ñÈ¡ÍÆËã»úÂß¼´ÅÅÌÐÅÏ¢ |
|
0x06 |
ÉÏ´«ÎļþÁбíÐÅÏ¢ |
|
0x08 |
ÏÂÔØ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþ |
|
0x10 |
ʵÏÖ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄ¹ý³Ì |
|
0x0E |
Remote Shell |
|
0x10 |
È¡µÞÏÂÔØ |
|
0x12 |
»ñÈ¡Webcam DevicesÁбí |
|
0x14 |
Start Webcam |
|
0x16 |
Stop Webcam |
|
0x18 |
·¢ËÍÐÄÌø°ü |
|
0x1A |
Ð¶ÔØ¿Í»§¶Ë |
|
0x1C |
Åú¸Ä½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþ |
|
0x1E |
ÏÂÔØVNCÄ£¿é |
|
0x20 |
ÇÔÈ¡Google Chrome¡¢Mozilla FireFoxµÈä¯ÀÀÆ÷ºÍOutLook¡¢Thunderbird¡¢FoxmailÓÊÏäÖб£ÁôµÄƾ֤ÐÅÏ¢ |
|
0x22 |
ÏÂÔØ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþÁ´½Ó²¢Ö´ÐÐ |
|
0x24 |
ƾ¾Ý½ÚÔìÖ¸ÁÇл»Á½ÖÖ·½Ê½À´¼Í¼¼üÅÌʹÓÃÐÅÏ¢ |
|
0x26 |
ʹÓÃÈ«¾ÖÐÂÎŹ³×Ó£¬¼Í¼¼üÅÌʹÓÃÐÅÏ¢ |
|
0x28 |
Remote VNC×°ÖÃ |
|
0x2A |
²âÊÔ±¾»úµÄÍøÂçÏνÓÖ°ÄÜ |
|
0x2C |
¶Ï¿ªÔ¶³Ì·þÎñÆ÷ |
|
0x38 |
δ֪²âÊÔ |
|
other |
»ñÈ¡Óû§Ãû£¬ÏµÍ³°æ±¾£¬GUIDµÈÐÅÏ¢ |
1£©ÇÔȡƾ֤ÐÅÏ¢
ÇÔÈ¡µÄÐÅÏ¢Ô̺¬Google Chrome¡¢Mozilla FirefoxµÈä¯ÀÀÆ÷ºÍOutlook¡¢Thunderbird¡¢FoxmailÓÊÏä¿Í»§¶Ë±£ÁôµÄƾ֤ÐÅÏ¢µÈ¡£
¸ÃľÂí»ñÈ¡ÓÐ¹ØÆ¾Ö¤ÐÅÏ¢ÒÔ¼°ÊµÏÖ²½ÖèÈçϱíËùʾ£º
|
ÇÔÈ¡µÄƾ֤ÐÅÏ¢ |
ʵÏÖ²½Öè |
|
Google Chrome |
¶ÁÈ¡\AppData\Local\Google\Chrome\User Data\Default\ Login DataÊý¾Ý¿âÎļþ½øÐвéÎÊ |
|
Mozilla Firefox |
¶ÁÈ¡ÅäÖÃõ辶ϵÄsignons.sqliteÊý¾Ý¿â£¬²¢Í¨¹ýnss3.dll½âÃÜ |
|
Outlook |
±éÀú×¢²á±íSoftware\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesÏÂ×Ó¼ü½øÐмø±ð²¢½âÃÜ |
|
Thunderbird |
¶ÁÈ¡\AppData\Roaming\Thunderbird\ProfilesĿ¼ÏµÄÊý¾Ý¿âÎļþ£¬²¢Í¨¹ýÀûÓ÷¨Ê½Ä¿Â¼ÏµÄnss3..dll¶Ô´æ´¢µÄÃÜÂë½øÐнâÃÜ |
|
Foxmail |
¶ÁÈ¡ÓÊÏäĿ¼ÏµÄ\\Account\\Account.rec0Îļþ²¢½øÐнâÃÜ |
a£©ÌáÈ¡Chromeƾ֤
´Ó¸Ã±íÖжÁÈ¡µÄÄÚÈÝÊǼÓÃܵģ¬Í¨¹ýCryptUnProtectDataº¯Êý¶ÔÆä½øÐнâÃܱãÄܹ»»ñÈ¡µ½Ã÷ÎÄÊý¾Ý¡£×îºó¸ÃľÂí½«½âÃܺóµÄÊý¾Ý±£ÁôÔÚÃûΪ¡±xxx.tmp¡±£¨¡±xxx¡°ÎªBase64½âÂë³öµÄ×Ö´®£©µÄһʱÎļþÖС£
b£©ÌáÈ¡Mozillaƾ֤ÐÅÏ¢
Óû§ÃûºÍÃÜÂë
c£©OutLookƾ֤»ñÈ¡
»ñÈ¡OutlookÓÊÏäµÄÓû§ÐÅÏ¢
d£©Thunderbirdƾ֤»ñÈ¡
e£©FoxMailƾ֤»ñÈ¡
f£©ÉÏ´«»ñÈ¡µ½µÄƾ֤ÐÅÏ¢
2£©¼üÅ̼ͼ
b£©Ò»Ê±¼üÅ̼ͼ
°´¼üºÍ´°¿ÚÃûÐÅÏ¢µÄ»ñÈ¡
3£©RemoteVNC×°ÖÃ
a£©½«ÐÂÓû§Ôö³¤µ½¡±Ô¶³Ì×ÀÃæÓû§¡±×é
Ôö³¤²¢°µ²Ø´´½¨µÄÐÂÕË»§
b£©¸ü¸ÄÔ¶³Ì×ÀÃæÉèÖÃ
ͨ¹ý¶ÈÎöÎÒÃÇ·¢ÏÖ£¬´ËRATµÄÔ¶³Ì×ÀÃæÖ°ÄÜÊÇͨ¹ýÌØÔìµÄVNCÄ£¿éÀ´ÊµÏֵġ£²¢ÇÒÔÚºóÐøµÄ¸üа汾ÖУ¬»¹Ôö³¤ÁËHRDPÄ£¿éÀ´ÊµÏÖ°µ²ØÔ¶¿Ø×ÀÃæ¡£¸ÃHRDPÄ£¿éʹÓÃÁËGithubÉϵÄrdpwrapÏîÄ¿£¬²»½öÄܹ»ÔÚºó¶ÜµÇ¼Զ³ÌÍÆËã»ú£¬²¢ÇÒ´´½¨µÄWindowsÕË»§»¹»á×Ô¶¯°µ²Ø¡£
4£©È¨ÏÞÉý¼¶£¨UACÈÆ¹ý£©
¸ÃľÂíµÄȨÏÞÌáÉýÊÇÀûÓÃÁË×Ô¶¯ÌáÉýȨÏ޵ĺϷ¨ÀûÓ÷¨Ê½¡±pkgmgr.exe¡±À´Ö´ÐÐDISPÄ£¿é¡£ÆäÖ°ÄÜ´úÂëʵÏÖÊÇѡȡÁËBypass-UAC¿ò¼Ü£¬¸Ã¿ò¼ÜÄܹ»Í¨¹ýŲÓÃIFileOpertion COM¶ÔÏóËùÌṩµÄ²½ÖèÀ´ÊµÏÖ×Ô¶¯ÌáȨ¡£
¸ÃľÂíÏȽ«Ç¶ÈëÔÚ×ÊÔ´Êý¾ÝÖеÄPEÎļþÔÚÄÚ´æÖмÓÔØ²¢ÔËÐС£¶ø´ËPEÎļþÏÖʵÉÏÊÇÒ»¸ö¼ÓÔØÆ÷£¬ÆäËù×öµÄʼþÔòÊǽ«×ÊÔ´ÖеÄÁíÒ»¸öPEαÔìΪ¡°dismcore.dll¡±£¬¶øºó½«´Ëdll¸´Ôìµ½System32Ŀ¼Ï£¬×îºóʹÓÃpkgmgr.exeÖ´ÐÐαÔìµÄ¶ñÒâDLL¡£ÓÉÓÚpkgmgr.exeÊÇÒ»¸öUAC°×Ãûµ¥·¨Ê½£¬ËùÒÔËüĬÈÏÓµÓÐÖÎÀíԱȨÏÞ£¬ÇÒ²»»áµ¯³öUACÌáÐÑ¿ò¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ£º
´Ë¶ñÒâDLLµÄÖØÒªÖ°ÄÜÊÇ»ñȡע²á±íÖеġ±Install¡±×°ÖÃÐÅÏ¢(DropperµÄõè¾¶)²¢³ÁÐÂÆô¶¯ÓµÓÐÖÎÀíԱȨÏÞµÄDropperйý³Ì¡£
5£©Î´Öª²âÊÔ
ÔÚÐÂÏß³ÌÖУ¬Æ¾¾ÝÔ¶³Ì·þÎñÆ÷·¢Ë͵ÄÖ¸ÁÓëÐÂÖ¸¶¨µÄC&C½øÐÐÏνӡ£
ÓÉÓÚ½Ó¹ÜÊý¾ÝÎÞ·¨»ñÈ¡£¬ËùÒÔĿǰÎÒÃÇÎÞ·¨È·¶¨ÆäÕýÈ·Óô¦£¬Ôݽ«Æä¶¨ÃûΪδ֪²âÊÔ¡£
3.2 ×îй¥»÷Ñù±¾
½×¶ÎÒ»£º
½âÃܺ¯Êýmethod_0ÈçÏÂͼËùʾ£º
ÔÚ¾¹ýÄæÐò·ÖÁкÍBase64½âÂëºóµÄ×Ö·û´®£¨byte_0£©ÖУ¬Ç°16λΪ½âÃÜÃÜÔ¿¡°0x28 0x49 0xf7 0x30 0xec 0x8d 0x500x80 0x94 0xaf 0x85 0xaa 0xa8 0xe7 0xc0 0x41¡±,Ö®ºóΪ´ý½âÃÜÃÜÎÄ¡£º¯ÊýÒÔ16λΪѻ·,½«ÃÜԿͬÃÜÎÄ˳´Î½øÐа´Î»Òì»ò£¬×îÖÕ½âÃܵõ½¡°DUMP1¡±Îļþ²¢Í¨¹ýCallByNameº¯Êý¼ÓÔØÖ´ÐС£
½×¶Î¶þ£º
¡°DUMP1¡±ÎļþͬÑùѡȡC#±àд£¬·¨Ê½Ê×ÏÈ»á˯Ãß50ÃëÒÔ¶ã±ÜɳÏä²é³£¬Ö®ºó»á¼ì²âµ÷ÊÔÆ÷²¢½«×ÔÉí¿ªÊÍÖÁ¡°%ApplicationData%\riNpmWOoxxCY.exe¡±£¬½Ó×Å´´½¨schtasks.exe¹ý³Ì²¢Ôö³¤´òË㹤×÷¡°Updates\riNpmWOoxxCY¡±£¬´Ó¶øÊµ´Ë¿ÌµÇ¼ÕË»§Ê±×ÔÆô¶¯£¬ÓйغÅÁîÈçÏ£º
"C:\Windows\System32\schtasks.exe/Create/TN Updates\riNpmWOoxxCY/XMLC:\Users\super\AppData\Local\Temp\tmp925C.tmp"
Ö®ºó£¬·¨Ê½»á´Ó×ÔÉí×ÊÔ´ÄÚ½âÃܳöPEÎļþ¡°DUMP2¡±£¬Í¨¹ýCreateProcess¡¢WriteProcessMemoryºÍSetThreadContextµÈº¯Êý£¬ÒÔ¹ÒÆðµÄ·½Ê½¼ÓÔØÒ»¸öеĹý³Ì£¬²¢×îÖÕÒÔ¿þÀܹý³ÌµÄ·½Ê½Ð´Èë²¢¼ÓÔØ¡°DUMP2¡±¡£
¾¹ý¶ÈÎö£¬ÎÒÃÇÔÚ¡°DUMP2¡±Öз¢ÏÖÁËһЩ¿ÉÒÉ×Ö·û´®È磺¡°Remcos¡±¡¢¡°Remcos_Mutex_Inj¡±¡¢¡°2.3.0 Pro¡±¡£
ÆäÃâ·Ñ°æ½ö¿ÉÔö³¤Ò»¸öC2ÏνӷþÎñÆ÷£¬×¨Òµ°æÔòûº±¼ûÁ¿ÏÞ¶È¡£Õâ´Î¹¥»÷ÖÐÖ²ÈëµÄľÂíÊÇͨ¹ýרҵ°æÌìÉúÇÒÏνÓÖÁ¶à¸ö¶ñÒâC2£¬Ô̺¬µÄC2µØÖ·ÌáÈ¡ÈçÏ£º
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
4¶ñÒâ´úÂëËÝÔ´Óë¹ØÁª
4.1 ¶ñÒâ´úÂëËÝÔ´×·×Ù
ǰÎÄÔøÌáµ½£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÖÐÔ̺¬ÁË¡°AVE_MARIA¡±Ìصã×Ö·û´®£¬ÇÒ×Ô2018Äê12ÔÂÆðÍ·£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾ÔÚtwitter¡¢virustotalµÈƽ̨ԽÀ´Ô½¶àµÄ±»·¢ÏÖ¡£µ«¶àƪÓйØ×êÑÐÎÄÕ¾ùδָ³öÆäÕæÊ·´Ô´£¬É±¶¾³§ÉÌÒ²¿í·ºµÄ½«Æä¶¨ÃûΪAVE_MARIA£¬ÕâÒýÆðÁËÎÒÃÇŨÃܵÄÐËÖ¡£
ÎÒÃdz¢ÊÔ´Ó¶àÖֽǶÈÈ¥ËÝԴľÂíÒÔѰÕÒÏßË÷£¬Ô̺¬ÓòÃû¡¢IP¡¢¹ØÁªÑù±¾µÈµÈ¡£ÆäÖÐÔÚ¶Ô¹ØÁªÑù±¾¡°Michelle Flores - Curriculum Actualizado.doc¡±µÄ·ÖÎöÖгɹ¦ËÝÔ´µ½ÁËÉÌÓÃÈí¼þRemcos RAT¡£ÎÒÃÇ·ÖÎöÁ˸ÃÈí¼þµÄ°ä²¼Çþ·£¬·¢ÏÔìä²»½öÔÚ¹ÙÍø½øÐÐÏúÊÛ£¬»¹ÔÚÖî¶àºÚ¿ÍÂÛ̳ÈçHackforumsÉÏ´óÁ¿ÊÛÂô¡£ÓÉ´Ë£¬ÎÒÃDz²⹥»÷ÈËÔ±ºÜ¿ÉÄÜ»îÔ¾ÔÚÓйØÂÛ̳²¢²É°ì¹ý¶à¿îÉÌÓÃÈí¼þ£¬Í¬Ê±Ò²½«ËÝÔ´³ÁµãתÏòºÚ¿ÍÂÛ̳ºÍ°µÍøÊг¡¡£
SolmyrÔÚÂÛ̳ÖÐÌṩÁËwarzonedns.comÓòÃûµÄÃâ·ÑDDNS·þÎñ£¨IP¶¯Ì¬°ó¶¨ÖÁ×ÓÓòÃû£©£¬Ê¹µÃÓû§Äܹ»µÈÏеĽ«·þÎñÆ÷IP°ó¶¨½âÎöÖÁwarzonedns.comϵÄËÁÒâ×ÓÓòÃû£¬Ê¹ÓÃʾÀýÈçÏ£º
ÕâÎÞÒɸøºÚ¿ÍÌṩÁ˺ܺõIJØÉíÖ®Ëù£¬Óë´ËͬʱÎÒÃÇ·¢ÏÖSolmyrµÄÁíÒ»¸öÉí·ÝÊÇWARZONE RATµÄ°ä²¼Õߣ¬¸ÃÈí¼þÓÉÓÚ½ÚÔ켿Á©·á˶¡¢¼¼ÊõÖ°ÄÜ׳´ó¡¢µü´ú¸üÐÂѸ¿ì£¬Ä¿Ç°ÔÚHackforumsÂÛ̳Öм«¶ÈÊÜÓ½Ó¡£
ÖÁ´Ë£¬ÎÒÃÇÓÐÀíÓÉÒɻ󹥻÷ÕßʹÓùý¸Ã¿îÉÌÓÃÔ¶³ÌÖÎÀí¹¤¾ß¡£ÓÉÓÚ¸ÃÈí¼þ¹ØÔ´ÇÒ²»ÌṩÃâ·Ñ°æ±¾£¬ÎÒÃÇ×·Òäµ½ÁËWARZONE RATÁ÷³öµÄÆÆ½â°æ±¾£¨V1.31£©£¬²¢½«ÆäÓë¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÑù±¾½øÐÐͬԴÐÔ·ÖÎö,ÒÔÈ·¶¨¶þÕß¼äµÄ¹ØÁª¡£
4.2 ͬԴÐÔ·ÖÎö
Æä´Î£¬ÎÒÃÇͨ¹ýBindiff½øÐÐÁ˸üΪ¾«È·µÄ¶Ô±È£¬ÔÚÈ¥³ý²¿ÃÅAPI×ÌÈŲ¢±ÈÁ¦·ÖÎöÁË¿ÉÐŶȸߵĺ¯Êýºó£¬·¢ÏÖ´óÁ¿º¯ÊýÆëȫһÑù£¬Õ¼±È´ïµ½80.16%£¬ÆäÓຯÊýÔò¿ÉÄÜÓÉÓÚ°æ±¾ÔÒòÂÔÓвî¾à£¬ÕâÒ²Ó¡Ö¤Á˶þÕß¼äµÄÇ¿¹ØÁªÐÔ¡£
Áí±í,´Ó´«²¼¹¦·òµÄ½Ç¶È·ÖÎö,¡°AVE_MARIA¡±¹ØÁªÑù±¾×î³õ³öÏֵŦ·ò(2018Äê12ÔÂ2ÈÕ)ÂÔÍíÓÚWarzoneRATÔÚÂÛ̳µÄ°ä²¼¹¦·ò(2018Äê10ÔÂ22ÈÕ)£¬ÕâÒ²Çк϶ñÒâ´úÂë´«²¼µÄ¹¦·òÂß¼¡£
ƾ¾ÝÒÔÉϼ¸µã·ÖÎö£¬ÎÒÃÇÒÔΪÁ½ÕßÓµÓи߶ȵÄÒ»ÖÂÐÔ¡£´ÓĿǰÒÑÖªµÄÇé¿ö¿´£¬WARZONE±»É±¶¾³§ÉÌ¿í·ºµÄ¼ø±ðΪAVE_MARIA£¬¶øÔÚÉî¿Ì±È¶Ô·ÖÎöºó£¬ÎÒÃÇÅж¨ºÚ¿Í×é֯ʹÓõÄÔ¶¿ØÄ¾ÂíÕýÊÇWARZONE RAT¡£Òò¶øÄܹ»½«´ËÀàÔ̺¬¡°AVE_MARIA¡±×Ö·û´®µÄ¶ñÒâÑùͬ×Ú×嶨Ãû¸üÐÂΪ¡°WARZONE¡±¡£
4.3 ÓòÃû¹ØÁª
ÕâÅúÓòÃû¾ùΪwarzonedns.comÌṩµÄÃâ·Ñ×ÓÓòÃû£¬ÇÒ´ó²¿ÃŹØÁªÖÁ¶ñÒâÑù±¾£¬ÕâÅú×¢´óÁ¿ºÚ¿ÍÔÚÀÄÓôËÀà·þÎñ½øÐжñÒâ¹¥»÷¡£
5×Ü ½á
±¾ÎĶԱ¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Á÷³Ì¡¢ÓйصĶñÒâ´úÂë¡¢ºÚ¿Í²¼¾°µÈ×öÁËÉî¿ÌµÄ·ÖÎöºÍ×êÑУ¬´ÓÉÏÎĵķÖÎöÖÐÎÒÃÇÄܹ»¿´³ö¸ÃºÚ¿Í×é֯ĿǰµÄ¹¥»÷»î¶¯¼«¶ÈÉóÉ÷£¬¼ÈûÓдó¹æÄ£µÄ¹¥»÷£¬Ò²Ã»ÓÐѡȡ¸ß³É±¾µÄ0day·ì϶£¬Í¬Ê±£¬¹¥»÷»î¶¯¹¦·òÒ²¼«¶È¶Ì¡£ÕâÅú×¢¸Ã¹¥»÷»î¶¯»¹´¦ÓÚ³õÆÚ£¬²¢¶ÔÖ¸±ê½øÐÐÁËһЩÊÔ̽ÐÔ¡¢Õë¶ÔÐԵĹ¥»÷£¬Ò²ÎªºóÐøµÄ¹¥»÷×öºÃ³ï±¸¡£´Ë±íͨ¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´£¬ÎÒÃÇÈ·¶¨Á˸ôλ±³ºóµÄºÚ¿Í×éÖ¯£¬²¢Æ¾¾Ý¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯º¹Ç࣬·¢ÏÔìäÃñ×åÖ÷ÒåÉ«²ÊÇ¿ÁÒ£¬Òò¶øÕþÖÎÖ÷ÕÅÒâͼҲ½ÏΪÏÔÖø¡£
IOC
|
MD5 |
|
99C82F8A07605DA4CCC8853C910F7CAF |
|
048DCA20685ECD6B7DBDBF04B9082A54 |
|
DEF105A9452DEF53D49631AF16F6018B |
|
1E19266FC9DFF1480F126BD211936AAC |
|
262D9C6C0DC9D54726738D264802CCAD |
|
B3C9F98DD07005FCCF57842451CE1B33 |
|
497566120F1020DBD6DF70DD128C0FFB |
|
ÓòÃû |
|
linksysdatakeys[.]se |
|
gestomarket[.]co |
|
asdfwrkhl.warzonedns[.]com |
|
casillas.hicam[.]net |
|
casillasmx.chickenkiller[.]com |
|
casillas.libfoobar[.]so |
|
du4alr0ute.sendsmtp[.]com |
|
settings.wifizone[.]org |
|
wifi.con-ip[.]com |
|
rsaupdatr.jumpingcrab[.]com |
|
activate.office-on-the[.]net |


¾©¹«Íø°²±¸11010802024551ºÅ