ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö

°ä²¼¹¦·ò 2019-05-18

½üÆÚ£¬GA»Æ½ð¼×ADLab¼à²âµ½Ò»ÅúÒÉËÆÕë¶ÔÎ÷°àÑÀÓïµØÓòÈ·µ±¾Ö»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿Ãŵ͍Ïò¹¥»÷»î¶¯£¬ºÚ¿Í×é֯ͨ¹ý»ú¹Ø¶ñÒâOffice WordÎĵµ²¢¹²Í¬Óã²æÓʼþÌáÒ鶨Ïò¹¥»÷£¬ÒÔ¡°¼òÀú¸üС±×÷Ϊµö¶üÎĵµÏò¹¥»÷Ö¸±êÖ²Èë¼äµýľÂí£¬´Óʵý±¨ÍøÂç¡¢Ô¶¿Ø¼à¶½¼°ÏµÍ³·ÛËéµÈ¶ñÒâÐж¯¡£ÎÒÃǽ«ÍÁ¶úÆäºÚ¿ÍµÄÕâ´Î¹¥»÷Ðж¯³ÆÎª¡°ºÚʨÐж¯¡±¡£


ͨ¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷ÓйØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷ÆðÔ´ÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¸Ã×éÖ¯ÊÇÒ»¸öÃñ×åÖ÷ÒåÉ«²Ê¼«¶ÈŨÃܵĺڿÍ×éÖ¯£¬Ôø¹¥ÏÂÆäËû¹ú¶ÈµÄ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂÆä×éÖ¯µÄÃû³Æ£¬ËæºóÒþûÁ˶àÄê¡£ Èç½ñͨ¹ýÎÒÃǶԡ±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯¼£Ïó¡£±¾´Î¹¥»÷¹ý³ÌÖУ¬¸ÃºÚ¿Í×éÖ¯Ñ¡È¡ÉøÈ뼿Á©¹¥Ï¶ą̀·þÎñÆ÷²¢½«Æä×÷Ϊ´æ·Å¹¥»÷´úÂëµÄÌø°å¡£


2019Äê2Ô£¬ÎÒÃÇ·¢ÏÖÁ˵ÚÒ»¸ö¹¥»÷Ñù±¾²¢½«Æä²ÎÓëµ½×·×ÙÇåµ¥ÖУ¬Ö±µ½½üÆÚÒѾ­·¢ÏÖÁ˶àÆð¹¥»÷£¬Ã¿´Î¹¥»÷¶¼Ê¹ÓÃÁË·ÖÆçµÄ¹¥»÷״̬ºÍÃâɱ·½Ê½¡£´ÓĿǰÒÑÓеĹ¥»÷´úÂëÖÐÎÒÃÇ·¢ÏÖÁËÁ½¿îÉÌÓÃÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©£ºWARZONEºÍRemcos£¬ÆäÖÐWARZONE±»É±¶¾³§ÉÌ¿í·ºµÄ¼ø±ðΪAVE_MARIA£¨ÓÉÓÚRAT´úÂëÖдæÔÚ¸Ã×Ö·û´®Òò¶ø±»¶¨ÃûΪ¡± AVE_MARIA¡±£©£¬ µ«ÊÇͨ¹ýÎÒÃÇÉî¿ÌµÄ·ÖÎöÈ·¶¨AVE_MARIAΪԶ³ÌÖÎÀí¹¤¾ßWARZONE¡£±¾ÎÄÖУ¬ÎÒÃǽ«¶ÔºÚ¿Í×éÖ¯¡¢¹¥»÷Ö¸±êÒÔ¼°ÆäËùʹÓõĹ¥»÷±øÆ÷½øÐÐÉî¿Ì·ÖÎö¡£



1Íþв·ÖÎö




1.1 ¹¥»÷Ö¸±ê·ÖÎö


´ÓĿǰËù»ñÈ¡µÄ¹¥»÷Ñù±¾ºÍÍþвµý±¨£¬Äܹ»¿´³ö±¾´Î¹¥»÷»î¶¯²¢Ã»Óдó¹æÄ£µÄ½øÐУ¬Ä¿Ç°»¹´¦ÓÚ¹¥»÷ÊÔ̽½×¶Î£¬µ«ÊÇ´ÓÆäͶ·ÅµÄµö¶üÎĵµÄܹ»µ¥Ò»¼òÖ±¶¨Æä¹¥»÷Ö¸±êËø¶¨ÔÚÎ÷°àÑÀÓïϵµÄ¹ú¶È¡£ÕâЩµö¶üÎĵµÐÎÈ磺¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±£¨¼òÀú¸üРº£Ã·°¢ÀïÑÇ˹£©¡¢¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±(¼òÀú¸üРµ¤Äá¶û°ÂµÙ×È)¡¢¡°Michelle Flores - Curriculum Actualizado.doc¡±(Ã×Ъ¶û¸¥ÂåÀ×˹-¼òÀú¸üÐÂ)¡¢¡°Jose Trujillo.doc¡±(ºÎÈûÌØÂ³Ï£ÂÔ)µÈµÈ£¬ËüÃǾùѡȡÎ÷°àÑÀÓïÀ´»ú¹ØÒ»¸ö´ø¶ñÒâºê´úÂëµÄ¼òÀúÎļþ¡£ÒÔ´ËÀ´¶ÔÖ¸±êÈËÁ¦²¿ÃŽøÐй¥»÷£¬ÒÔÓÕʹÓйØÈËÔ±Ö´ÐжñÒâ´úÂë½ø¶ø´Óʼäµý»î¶¯¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÎÒÃÇ·ÖÎöÕâÅúµö¶üÎĵµÊ±£¬»¹·¢ÏÖÒ»¸öÓÐȤµÄ¾°Ïó£¬ÄǾÍÊǺܶàµö¶üÎĵµÖÐÔ̺¬ÁËÎĵµ×÷ÕßÐÅÏ¢ºÍ×îºóÒ»´Î±£ÁôÕßÐÅÏ¢£¬²¢ÇÒÕâЩÐÅÏ¢¾ùΪÀàËÆ²ÆÕþ²¿¡¢Ðŷþ֡¢SCG£¨Southern Connecticut Gas£©µÈµÅ×ëµ±²¿ÃÅÃÅÓйصÄÐÅÏ¢¡£Í¨¹ýÎÒÃÇÏÖʵ²âÊÔ·¢ÏÖ£¬ÕâЩÐÅÏ¢¾ù»áÔÚÎĵµÅú¸ÄºóÔì³Éµ±Ç°½Ó¼ûÕßofficeµÇ½ÕË»§Ãû»òÕßÖ÷»úÃû£¬²¢ÇÒÓÐÐĵÄÈË»¹Äܹ»¶ÔÆä½øÐÐËÁÒⶨÔì¡£ÎÒÃǰÎÈ¡¼¸¸öµäÐ͵ÄÑù±¾²¢Õë¶ÔÓйØÐÅÏ¢ºÍÂß¼­¹ØÏµ×öÁËÈçÏÂÊáÀíºÍÍÆÂÛ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÎÒÃÇͨ¹ý´´½¨ÄÚÈݹ¦·ò¡¢×îºóÅú¸Ä¹¦·ò¼°¹¥»÷ÎĵµÄÚ²¿µÄÂß¼­¹ØÏµÍÆÂÛ³öÓйؼͼӦΪ¹¥»÷Õß±£Áô¡£»ùÓÚ×îºÏÀíÒÔ¼°×îÓпÉÄܵĴ§Ä¦£¬ÎÒÃÇÒÔΪ¹¥»÷Õß¿ÉÄÜÊÇ»ùÓÚºÚ¿Í×éÖ¯ÄÚ²¿¹æ·¶£¬½«ÎĵµµÄÓйØÃû³ÆÉèÖÃΪ¹¥»÷Ö¸±ê»òÓйØÐÐÒµÐÅÏ¢£¬´Ó¶øÎ±Ôì³ÉÄÚ²¿ÈËÊ¿£¬Ôڿ϶¨Ë®Æ½ÉÏÆðµ½»ìºÏÊÓÌý¡¢Òñ±Î×ÔÉíµÄÖ÷ÕÅ¡£


ÓÉ´ËÎÒÃÇÄܹ»¿´³öÕâ´ÎÐж¯µÄ¹¥»÷Ö¸±êΪÎ÷°àÑÀÓïϵµØÓòÈ·µ±¾Ö»òÕß¹«¹²·þÎñ²¿ÃÅ£¬µ±È»²¢²»ÅųýÆäÓиü¶àµÄÖ¸±ê£¬ÖÁÉÙÄܹ»×¢¶¨µÄÊÇÕâ´ÎÐж¯ÊÇÒ»´Î´øÓÐÕþÖÎÖ÷ÕŵĹ¥»÷»î¶¯¡£



1.2 ºÚ¿Í×éÖ¯·ÖÎö


ÔÚÎÒÃÇÉî¿Ì·ÖÎö¶ñÒâ´úÂëʱ£¬·¢Ïָôι¥»÷µÄ½ÚÔìºÅÁî·þÎñÆ÷ÊÇÓÉÉÏÓκڿÍÒ²¼´ÊǶñÒâÈí¼þÌṩÉÌËùÌṩµÄ£¬´ÓÕâЩ½ÚÔìºÅÁî·þÎñÆ÷ÉÏÊÇÎÞ·¨×·×Ùµ½¸Ã´ÎÐж¯µÄ±³ºó×éÖ¯£¬Òò¶øÎÒÃǰÑÖØÒª¾«Á¦¾Û½¹ÓÚ¹¥»÷µÄǰ¼¸¸ö½×¶ÎÓйصÄÓòÃû¡£¹ÌÈ»´ó²¿ÃÅÓòÃû¾ùѡȡÁËÒþÖÔ±£»¤£¬ÎÞ·¨ÕÒµ½ÓÐЧµÄÐÅÏ¢£¬µ«ÊÇÎÒÃÇÈ´ÔÚÆäÖÐÒ»¸öÇ¿¹ØÁªµÄÑù±¾Öз¢ÏÖÒ»¸ö¿ÉÍ»ÆÆµÄµã¡£ÎÒÃÇÔÚÆäÖÐÒ»¸öRTFÎĵµÖÐÄÚ²¿·¢ÏÖÁËÒ»¸öExcelÎļþ£¬¸ÃExcelÎļþ»áͨ¹ýÖ´ÐкêÀ´ÏÂÔØ¶ñÒâ´úÂ롣ͨ¹ý¶Ô¸Ã·þÎñÆ÷µÄ·ÖÎöÎÒÃdzɹ¦µØÕÒµ½ÁËÓëºÚ¿Í×éÖ¯ÓйصÄÏßË÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ¶ñÒâ´úÂë´æ´¢õè¾¶µÄͬĿ¼£¬ÎÒÃÇ·¢ÏÖºÚ¿Í×éÖ¯ËùÁôϵÄһЩÐÅÏ¢£¬ÏÂͼΪÆäÖÐÒ»¸öÎļþ¼Í¼µÄÐÅÏ¢£º 


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¸ÃÎļþÖÐÔ̺¬ÁËһЩÉêÃ÷ÐÅÏ¢¡¢ºÚ¿Í×éÖ¯¼°ÆäÓйسÉÔ±£¬²¢ÇÒËùѡȡµÄ˵»°ÎªÍÁ¶úÆäÓÒò¶øÎÒÃÇÅж¨¸Ã×éÖ¯ÕýÊÇÒѾ­»îԾһʱµÄKingSqlZºÚ¿Í×éÖ¯¡£¸Ã·þÎñÆ÷ºÜÓпÉÄÜÔÚ±»ºÚ¿Í×éÖ¯½ÚÔìºó×÷ÎªÌø°å»ú»ò×ÊÔ´·þÎñÆ÷³ÖÐøÊ¹Óᣴ˱íͨ¹ý¶ñÒâ´úÂëʱ·Ö±æÎö·¨£¬ÎÒÃǽøÒ»²½È·¶¨¸Ã´Î¹¥»÷À´×ÔÓÚÍÁ¶úÆäºÚ¿Í¡£ÎÒÃǶÔRATÑù±¾Ö®Ç°µÄPEÎļþ¼°ÆäËûǰÆÚ¹¥»÷»·½ÚÓйصÄÑù±¾µÄ±àÒ빦·ò×öÁËʱ·Ö±æÎö£¨ÓÉÓÚRATÑùÕý±¾×ÔÓÚÉÏÓκڿÍ£¬Òò¶øÎÒÃǺöÂÔÁ˸ÃÀàÑù±¾µÄʱ·Ö±æÎö£©¡£×îºó·¢ÏÖÕâЩ¹¥»÷Ñù±¾µÄ±àÒ빦·òÔÚUTC¹¦·ò21:00ÖÁ06:00Çø¼äÄÚ³öÏֵįµ´Î¼«µÍ¡£¶ø¼Ù¶¨ÒÔ24:00ÖÁ08:00×÷Ϊ˯Ãß¹¦·ò£¬¹¥»÷ÕßËù´¦µÄÊ±Çø¿ÉÄÜ»áÔÚ¶«3Çø£¨UTC+3£©Õý¸º 1 Ó×Ê±Çø¼äÄÚ£¬¶øÍÁ¶úÆäÊ±ÇøÎª¶«ÈýÇøÕýºÃÇкÏ¡£


ÔÚÎļþµÄ¼Í¼ÐÅÏ¢ÀﻹÄܹ»µÃÖªµ½¸Ã×éÖ¯³ÉÔ±ÈçF0RTYSEVEN , BlackApple , Pyske , HeroTurk , SadrazaM , MrDemonLordµÈ£¬ËûÃÇÔçÆÚ½øÐйý·è¿ñµÄÍøÂç¹¥»÷»î¶¯£¬¹¥ÏµķþÎñÆ÷¸ß´ï3287¸ö£¬¶øÖ®ºó±ãÉñÃØµÄÙÈÆìÏ¢¹Ä£¬ÆätwitterÕ˺ÅÒ²ÖÕ³¡Á˻¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾´Î¹¥»÷»î¶¯ÆðÍ·ÓÚ2019Ä꣬ѡȡ´óÁ¿¹«¹²DDNS·þÎñ×ÓÓòÃû×÷ΪC2À´Ö´Ðй¥»÷£¬ÕâÆäÖеÄһЩÓòÃûΪ2019ÄêÐÂ×¢²áµÄ£¬Ê¹ÓõIJ¿ÃÅÓòÃûÈçÏ£º


asdfwrkhl.warzonedns.com
casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com

activate.office-on-the.net


µ½»ã±¨×«Ð´Ê±£¬²¿ÃÅÖÐÑë¹¥»÷½×¶ÎµÄÓòÃûÒѾ­Ê§Ð§£¬µ«RAT»ØÁ¬µÄC2ÒÀÈ»ÔÚ»îÔ¾¡£Æ¾¾ÝÎÒÃÇĿǰ¶ÔÒÉËÆ¹¥»÷×éÖ¯µÄ°ÑÎÕºÍËÝÔ´·ÖÎö£¬»æÔìºÚ¿Í×éÖ¯»­ÏñÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2¹¥»÷¸ÅÊö



Õâ´ÎÊÂÎñµÄÖØÒª¹¥»÷»î¶¯¹¦·òÏßÈçÏÂËùʾ:


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÖУ¬ÎÒÃǶÔ2019Äê2ÔÂ7ÈÕ·¢Ïֵġ°Curriculum Vitae Actualizado Jaime Arias.doc¡±Îĵµ½øÐÐÁ˾ßÌåµÄ·ÖÎö£¬²¢Ïà¼Ì²¶»ñµ½¹ØÁªÎĵµ¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc/ Jose Trujillo.doc¡±¡£


¹¥»÷ÕßʹÓÃÁËAPI¹þÏ£¡¢ÎÞÎļþ¹¥»÷¡¢WinrarSFX¡¢AutoIt¡¢C#»ìºÏºÍ¿þÀܹý³ÌµÈ¼¼ÊõÀ´¶ã±Ü¼ì²â²¢×ÌÈÅ·ÖÎöÈËÔ±¡£ÆäÖУ¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ÎĵµÖ²ÈëµÄľÂíÆðÔ´×î³õÎÞ·¨È·ÈÏ£¬ÎÒÃÇÔÚÆäÖз¢ÏÖÁËÌØµã×Ö·û´®¡°AVE_MARIA¡±,ÆäÓëCybaze-Yoroi ZLab×êÑÐÈËÔ±ÔÚ2018Äê12Ôµ×Åû¶µÄÕë¶ÔÒâ´óÀûijÄÜÔ´ÆóÒµ½øÐй¥»÷µÄ¶ñÒâÈí¼þÀàËÆ¶ÈºÜ¸ß£¬²¿ÃŰ²È«×êÑÐÔ±ºÍ³§ÉÌÓÉÓÚûÓгɹ¦µÄ½øÐÐËÝÔ´±ãÒÔ´Ë×Ö·û´®×öΪ¸ÃľÂí¼Ò×åµÄÃû³Æ¡£¶øÎÒÃǾ­¹ý¹ØÁªËÝÔ´ºÍͬԴÐÔ·ÖÎöºó·¢ÏÖ£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾Í¬RAT¹¤¾ß¡°WARZONE¡±RATÓµÓи߶ÈÒ»ÖÂÐÔ£¬Òò¶ø½«´ËÀà¶ñÒâ¼Ò×嶨Ãû¸üÐÂΪ¡°WARZONE¡±¡£


ºóÎĽ«³Áµã¾ÍÖ²Èë¼äµýľÂíµÄ2¸öOffice WordÎĵµ£¨¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc¡±£©¼°Æä¿ªÊ͵ÄÎļþ½øÐоßÌå·ÖÎö¡£



3¼¼Êõ·ÖÎö



3.1 ÔçÆÚ¹¥»÷Ñù±¾



Õâ´Î¹¥»÷¹ý³ÌÆðÍ·ÓÚÒ»¸öЯ´ø¶ñÒâºêµÄDOCÎĵµ£¬ºÚ¿Íͨ¹ýαÔì³É¼òÀúµÄͶµÝÓʼþ¼¿Á©½«´Ë¶ñÒâÎļþ·¢Ë͸ø¹¥»÷Ö¸±ê£¬µ±Ö¸±êÓû§Ê§É÷´ò¿ªÎĵµ±ã³ÉΪÁËÊܺ¦Õß¡£DOCÎĵµÔËÐкó»áÆô¶¯¶ñÒâºê´úÂë²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÏÂÔØEtr739.exe£¬³É¹¦ÏÂÔØºóµ±¼´Ö´ÐС£Ð¹ý³Ìͨ¹ýBase64½âÂë³öÁíÒ»¸ö·þÎñÆ÷µØÖ·£¬³ÖÐøÏÂÔØ¶ñÒâ´úÂëhqpi64.exeÖÁһʱĿ¼Ï¡£¶ñÒⷨʽhqpi64.exe¾ÍÊÇWarzone RATµÄ¿ªÊÍÆ÷£¬Æäͨ¹ý¿ªÊÍWarzone RATÀ´Ö´ÐкóÐø²Ù×÷£¬È罫explorer.exe×÷Ϊ¿þÀܹý³ÌÊØ»¤¡¢Óë½ÚÔì¶Ë½øÐÐͨѶµÈ¡£


Ñù±¾ÖеĶñÒâ´úÂë´ó²¿ÃÅѡȡCRC32À´¼ÓÃÜÃô¸Ð×Ö´®£¬Í¬Ê±ÔÚAPIŲÓÃÊÖ·¨ÉÏѡȡÁËAPI HashÖµ¶¯Ì¬»ñÈ¡º¯ÊýµØÖ·ºÍ·ÂÕÕϵͳ¼±¾çŲÓÃÁ½ÖÖ·½Ê½¡£Ê¹ÓôËÀàÊÖ·¨²»Ö»ÄÜÔڿ϶¨Ë®Æ½ÉÏÏ÷¼õɱÈí¾²Ì¬É¨ÃèµÄ¼ì²â£¬²¢ÇÒ»¹²»Ò×±»¼à²âµ½APIµÄŲÓÃ×ÙÓ°¡£Í¬Ê±ÆäʹÓô¿¼ÓÃÜShellcode´úÂëÄÚ´æÖ´Ðеķ½Ê½¼ÓÔØÆäÖ÷ÌâÖ°ÄÜÄ £¿é£¬Í¨¹ý¡°ÎÞÎļþ¼¼Êõ¡±Ìá¸ß×ÔÉíÒñ±ÎÐÔ£¬ÒÔ´ËÀ´¶ã±Ü°²È«³§É̲éɱ¡£ÆäÓëC2·þÎñÆ÷¼äµÄͨѶÊý¾ÝÒ²ÒÔCR4Ëã·¨½øÐмÓÃܽø¶ø¶ã±ÜIDSϵͳµÄ¼ì²â¡£


Ñù±¾ÕûÌåÖ´ÐÐÁ÷³ÌÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


(1)DOCÎĵµ


DocÎĵµÎªwordÎļþ£¬Ò²ÊÇÕë¶Ô¹¥»÷Ö¸±êÖ´ÐеĵÚÒ»²½¹¥»÷£¬ºÚ¿Íͨ¹ý´¹µö¹¥»÷¡¢É繤µÈ¼¿Á©ºýŪ¹¥»÷Ö¸±ê´ò¿ª´ËÎĵµÈÃÆäÖÐǶÈëµÄ¶ñÒâºê´úÂëµÃÒÔÖ´ÐС£ÎÒÃÇʹÓÃÌáÈ¡¹¤¾ß»ñÈ¡µ½µÄºê´úÂëÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚAutoOpenº¯ÊýÖÐÔ̺¬ÁËÒ»´®»ìºÏ¹ýµÄcmdºÅÁ¾­¹ý½âÃܺóµÄ´úÂëÈçͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Õâ¶Î´úÂë»ñµÃÖ´Ðк󣬻áÖ±½Ó´Ó´ËÁ´½ÓµØÖ·(http[:]//linksysdatakeys.se)ÏÂÔØ¶ñÒⷨʽµ½¡°%Temp%\SAfdASF.exe¡±²¢Ö´ÐС£


(2)Payload


ÏÂÒ»¸öDropperµÄÏÂÔØµØÖ·ÊDZ»¼ÓÃܺó±£ÁôÔÚ¶ñÒⷨʽSAfdASF.exeµÄ×ÊÔ´ÖУ¬¼ÓÃܵÄ×ÊÔ´Êý¾ÝÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸ÃPayloadÏȽ«ÉÏͼÖмÓÃܵÄÊý¾Ýͨ¹ýBase64½âÂë³öÏÂÔØÁ´½ÓµØÖ·¡°http[:]//www.gestomarket[.]co/hqpi64.exe¡±£¬¶øºó°Ñhqpi64.exe¸ÄÃûΪ2XC2DF0S.exe²¢±£ÁôÔÚһʱĿ¼Ï¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


(3)Dropper


ÔÚºóÐøµÄ½âÃÜÒÔ¼°Ö´ÐеĹý³ÌÖУ¬´ËDropper»á°ÑÒ»¶ÎShellcode×¢Èëµ½explorer¹ý³Ì²¢ÔÚÄÚ´æÖнâÃܳöRATʵÌåʹÆä²»Â䵨£¬×îÖÕͨ¹ýÎÞÎļþ¼¼Êõ½«RAT¼ÓÔØµ½ÄÚ´æÖÐÀ´Ö´ÐС£


Ìӱܼì²â


´Ë¶ñÒⷨʽÔÚÆðÍ·Ö´ÐÐʱ£¬»áͨ¹ý´óÁ¿µÄŲÓÃprintfº¯Êý´òÓ¡À¬»ø´úÂëºÍsleepº¯ÊýÀ´´ïµ½ÑÓʱ³ÉЧ£¬ÕâÔڿ϶¨Ë®Æ½ÉÏ¿ÉÄܶã±Ü°²È«Èí¼þµÄ¼à¿Ø¡£¶øÆäÖ÷ÌâÖ°ÄÜÊǽ«×ÔÉíЯ´øµÄshellcode½âÃܲ¢Ö´ÐУº


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½âÃÜshellcode


ÈçÉÏͼËùʾ£¬¶ñÒⷨʽ»áÔÚ¼ÓÔØÖ´ÐÐshellcodeǰ½øÐнâÃÜ¡£½âÃÜËã·¨¼«¶Èµ¥Ò»£¬½«Ã¿¸ö×Ö½ÚµÄÖµÔö³¤0x0c¼´¿É¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×Ô½ç˵µÄ½âÃܺ¯Êý


¾­¹ý³Á³ÁÏÂÔØ²¢½âÃÜÖ®ºó£¬ÄÇôÕâ¶Î½âÃܺóµÄShellcode(PE Loader)´úÂë¾ßÌåζ×öЩʲô£¬ÏÂÃæÎÒÃÇÀ´Ò»¿úµ½µ×¡£


PE Loader


´ËPE LoaderÔÚÖ´ÐÐShellcodeµÄʱ³½Ê¹ÓÃÁËËĸö²ÎÊý£¬¾­·ÖÎöºóÎÒÃǽ«Õâ4¸ö²ÎÊýÄÚÈÝËù¶ÔÓ¦µÄ¾ßÌåÖ°ÄÜÕû¶ÙÈçϱíËùʾ£º


ÐòºÅ

ÄÚÈÝ

Ö°ÄÜ

²ÎÊý1

¡°FYBLV¡±

¿½±´×ÔÉíµÄĿ¼ÃûºÍÎļþÃû(Ðè½âÃܵÄ×ÊÔ´Ãû)

²ÎÊý2

¡°BJU¡±

RATÔ¶¿ØÎļþ(Ðè½âÃܵÄPEÎļþ×ÊÔ´Ãû)

²ÎÊý3

¡°OPTYUPPABIVSUWNRXSNCTDW¡±

Key

²ÎÊý4

0x01£¨¹Ì¶¨ÊýÖµ£©

δʹÓÃ


¸ÃPE LoaderÊ×ÏÈÔÚÔËÐйý³ÌÖнøÐÐÁËɳÏäºÍÖ¸¶¨¹ý³ÌµÄ¼ì²â£¬ÒÔÔ¤·À±»×Ô¶¯»¯ÏµÍ³·ÖÎö¡£²¢ÇÒÆ¾¾Ý×Ô´øµÄ×ÊÔ´Êý¾ÝÀ´Åж¨ÊÇ·ñÖ´ÐÐפÁô±¾»úµÄ²Ù×÷ºÍ×¢ÈëÌåµÄÑ¡Ôñ¡£×îºó´ËPE Loader½«×îÖÕÑ¡ÔñµÄ¿þÀܹý³ÌµÄ¿Õ¼ä¼Ü¿Õ£¬²¢°Ñ½âÃܳöµÄRATÄ £¿éÓ³Éäµ½´Ë¹ý³ÌÖÐÖ´ÐÐ(Õý±¾PEÎļþ´úÂë±»Öû»)¡£


ÔËÐл·¾³¼ì²â


¸ÃPE LoaderÔÚÆðÍ·ÔËÐÐʱ£¬ÒÀÈ»»á½øÐÐɳÏäºÍµ÷ÊÔ»·¾³µÄ¼ì²â£¬Í¬Ê±Í¨¹ýÔ¤ÏÈÍÆËãºÃµÄ¹ý³ÌÃû¹þÏ£Ö·´²éÕÒÖ¸¶¨µÄ¹ý³Ì¡£µ¹ØâЩ¼ì²âǰÌáÖеÄËÁÒâÒ»ÌõÂú×ãʱ£¬¸Ã¶ñÒⷨʽ¾Í²»ÔÙ³ÖÐøÖ´ÐУ¬Ö±½Ó·µ»ØÍ˳ö¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔËÐл·¾³¼ì²â


²Ù×÷×ÊÔ´Êý¾Ý


ÈôÊÇÔËÐл·¾³µÄ¼ì²âÈ«Êýͨ¹ý£¬¸ÃPE LoaderÔò¼ÓÔØÃûΪ¡°FYBLV¡±µÄ×ÊÔ´Êý¾Ý£¬²¢´Ó×ÊÔ´ÖÐÈ¡³öºóÐøÒª¿½±´×ÔÉíµÄÎļþ¼ÐÃû³ÆºÍÎļþÃûµÄ×Ö´®¡£¶øºóÒÔ²ÎÊý3×÷Ϊ·Ö¸ô·û£¬Ë³´ÎÈ¡³öÆäËüµÄÊý¾Ý²¢±£ÁôÔÚ×Ô½ç˵µÄ½á¹¹ÌåÖС£×ÊÔ´ÖÐÌáÈ¡³öµÄ½á¹¹Êý¾ÝÄÚÈÝÈçÏÂͼ£º£¨Í¼ÖбêºìµÄÊýֵΪ±£ÁôÔڽṹÌåÖеÄ8¸ö³ÉÔ±Êý¾Ý£©£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾­¹ý¶ÈÎö£¬½á¹¹ÌåÖÐÿ¸ö³ÉÔ±µÄ¾ßÌåÖ°Äܿɲο¼ÏÂͼ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿ªÊÍÓëפÁô


ÈôÊÇbIsCpySelfֵΪTRUE£¬ÄÇô¸ÃPELoader»á½«×Ô¼º¸´Ôìµ½C:\Users\SuperVirus\AppData\Roaming\ptdkuybasm\"Ŀ¼Ï²¢°ÑÐÂÎļþ¶¨ÃûΪszPathNameÀï±£ÁôµÄÄÚÈÝ¡£½Ó×ÅÔÚWindowsµÄÆô¶¯Îļþ¼ÐÀï´´½¨Ò»¸ö.urlµÄÍøÒ³Îļþ¿ì½Ý·½Ê½£¬ÎÒÃDz鿴¸ÃPE Loader´´½¨µÄ¿ì½Ý¼üÊôÐÔ£¬·¢ÏÖ´Ë¿ì½Ý¼üµÄ½Ó¼ûºÍ̸ÌåʽΪfile:///£¬¼´Ö¸ÏòµÄ×ÊÔ´ÊDZ¾µØÍÆËã»úÉϵÄÎļþ£¬¶øºóÃæ½ô¸úµÄõè¾¶¾ÍÊǸ´Ôì´ÓǰÐÂÎļþµÄÈ«õè¾¶¡£Í¨¹ý´Ë²½ÖèÁî¿ÉʵÏÖ¿ª»ú×ÔÆô¶¯ÒÔ´ïµ½³Ö¾Ã½ÚÔìÖ÷»úµÄÖ÷ÕÅ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´´½¨µÄ¿ì½Ý¼üÊôÐÔ


×îºó£¬¸ÃPE Loaderƾ¾Ý½á¹¹ÌåÖеÄdwFlagÖ·´Ñ¡ÔñºóÐøµÄRATÔØÌ壬Ëù¶ÔÓ¦µÄRATÔØÌåÏê¼ûÏÂ±í£º


Êý¾Ý

¹ý³ÌÃû

0x01

C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe

0x02

C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe

0x03

C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe

0x04

C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe

0x05

C:\Windows\System32\svchost.exe

0x06

C:\Windows\System32\dllhost.exe

0x07

µ±Ç°ÔËÐеÄ×ÔÉí¹ý³Ì


¶øÔÚ±¾Ñù±¾ÖУ¬´Ë³ÉÔ±µÄÖµËù¶ÔÓ¦µÄÔØÌåΪµ±Ç°ÔËÐеÄ×ÔÉí¹ý³Ì¡£


»ñÈ¡RAT²¢Ö´ÐÐ


ÔڳﱸºÃRATµÄ¿þÀܹý³Ìºó£¬¸ÃPE Loader½«½á¹¹ÌåÖеÄszKeyÖµ×÷Ϊkey£¬ºÍÃûΪ¡±BJU¡±µÄ×ÊÔ´´«Èë½âÃܺ¯Êý¡£½âÃܵÄËã·¨½öΪXORÔËË㣬¾ßÌåËã·¨´úÂëÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½Ó×Å£¬¸ÃPE Loader³Áд´½¨Ð¹ý³Ì²¢½«ÆäÉèÖÃΪ¹ÒÆð״̬¡£¶øºóÐ¶ÔØ´Ë¹ý³ÌÓ³Ïñ£¬²¢°ÑÔÚÄÚ´æÖнâÃܳöµÄеÄPEÍ·²¿£¬ÒÔ¼°½ÚÊý¾Ý˳´ÎдÈëµ½¹ÒÆðµÄ¹ý³ÌÖУ¬×îºóÅú¸ÄOEP²¢Æô¶¯ÔËÐС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


(4) WARZONE RATÄ £¿é


ÎÒÃǽ«´ËPEÎļþ´ÓÄÚ´æÖÐdump³öÀ´£¬Í¨¹ý¶ÈÎöºÍËÝÔ´ºó·¢ÏÖ£¬¸ÃPEÓë¹ú±íijºÚ¿ÍÂÛ̳ÖÐÊÛÂôµÄWARZONE RATͬ³öÒ»ÕÞ¡£ÓÉ´ËÎÒÃÇ´§Ä¦£¬´Ë´¦Ê¹ÓõÄRATÄ £¿é¿ÉÄÜΪWAREZONE RAT1.6°æ±¾£¬´Ë°æ±¾ÎªC++˵»°±àд£¬ÖØÒªÖ°ÄÜÔ̺¬Ô¶³Ì×ÀÃæ½ÚÔì¡¢¼üÅ̼ͼ¡¢ÌØÈ¨Éý¼¶£¨UACÈÆ¹ý£©¡¢Ô¶³ÌWebCam¡¢ÇÔȡƾ֤ÐÅÏ¢¡¢Remote Shell¡¢Offine KeyloggerµÈµÈ¡£ÏÂÃæÎÒÃÇ»á¶ÔRATÖеÄÖ÷ÌⲿÃÅ×ö¼òÒª½éÉÜ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô¶¿Ø·¨Ê½Warzoneºó¶Ü½çÃæ


»ñÈ¡C&CµØÖ·


ΪÁËÔ¤·ÀC&C±»µÈÏз¢ÏÖ»òÕßÅúÁ¿ÌáÈ¡£¬¸ÃľÂí½«Æä¼ÓÃÜºó´æ·ÅÔÚ¡°.bss¡±µÄ×ÊÔ´½ÚÊý¾ÝÖС£Í¨¹ý¶Ô½âÃܺ¯ÊýµÄ·ÖÎöÎÒÃÇ·¢ÏÖ£¬ÕâÀïѡȡÁËCR4Ëã·¨¡£CR4ÌìÉúÒ»ÖÖ³ÆÎªÃÜÔ¿Á÷µÄÎ±Ëæ»úÁ÷£¬ËüÊÇͬÃ÷ÎÄͨ¹ýÒì»ò²Ù×÷Ïà»ìºÏÀ´´ïµ½¼ÓÃܵÄÖ÷ÕÅ¡£½âÃÜʱÔòʹÓÃÃÜÔ¿µ÷¶ÈËã·¨(KSA)À´ÊµÏÖ¶Ô´óÓ×Ϊ256¸ö×Ö½ÚÊý×ésboxµÄ³õʼ»¯¼°´úÌæ¡£¾ßÌåÁ÷³ÌÈçÏ£º


1£©ÓÃÊýÖµ0~255À´³õʼ»¯Êý×ésbox¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2)µ±ÆðÍ·´úÌæµÄʱ³½£¬»ñȡӲ±àÂëÔÚ×ÊÔ´ÀïµÄÃÜÔ¿£¬³¤¶ÈΪ0x32¸ö×Ö½Ú¡£

(ÔÚ×ÊÔ´Êý¾ÝÖÐǰ0x32¸ö×Ö½ÚÊÇÃÜÔ¿£¬ÆäÓà0x68¸ö×Ö½ÚÔòÊÇ´ý½âÃܵÄÊý¾Ý)


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÜÔ¿ºÍ´ý½âÃÜÊý¾Ý


3£©ÃÜÔ¿Á÷µÄÌìÉúÊÇ´Ósbox[0]µ½sbox[255]£¬¶Ôÿ¸ösbox[i]£¬Æ¾¾Ýµ±Ç°sboxÖµ£¬½«sbox[i]ÓësboxÖеÄÁíÒ»¸ö×Ö½ÚÖû»£¬¶øºóʹÓÃÃÜÔ¿½øÐдúÌæ¡£µ±Êý×ésboxʵÏÖ³õʼ»¯Ö®ºó£¬ÊäÈëÃÜÂë±ã²»ÔÙ±»Ê¹Óá£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4£©´úÌæºóµÄsboxÊý×éÖеÄÊýÖµÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5£©Í¨¹ý´úÌæºóµÄsboxºÍ´ý½âÃܵÄÊý¾Ý½øÐÐXORÔËËãºó£¬×îÖյõ½·þÎñÆ÷µÄhostµØÖ·"asdfwrkhl.warzonedns[.]com"¡£


Ö´ÐÐ×¢ÈëÖ°ÄÜ


µ±³É¹¦½âÃܳöC&CµØÖ·ºó£¬¸ÃľÂíÔòÆðÍ·½«Ò»¶ÎShellcode´úÂë×¢Èëµ½¿þÀܹý³ÌÖС£ÔÚ×¢ÈëÖ°ÄÜ¿ªÆôʱ£¬Ä¾Âí·¨Ê½Ê×ÏÈ»áÆ¾¾Ý²Ù×÷ϵͳ¼Ü¹¹(64/32)À´Ñ¡Ôñ×¢Èëµ½cmd.exe»òexplorer.exeÖС£ÓйشúÂëÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½Ó×Å£¬¸ÃľÂíʹÓÃÔ¶³ÌÏ̵߳ķ½Ê½À´×¢ÈëÖ÷ÌâÖ°ÄÜShellcode´úÂ룬²¢ÔÚÆô¶¯Ô¶Ïß³ÌÖ´ÐÐʱ£¬Åú¸ÄдÈëÖ¸±ê¹ý³ÌÄÚ´æÆ«ÒÆµÄ0x10E´¦ÎªÆðÍ·Ö´ÐдúÂë¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý¶ÈÎöÎÒÃÇ·¢ÏÖ£¬Õâ¶Î×¢Èë´úÂëµÄÖØÒªÖ°ÄÜÊÇÀûÓÿþÀܹý³ÌÀ´±£»¤Dropper(hqpi64.exe)¡£Æä»á°´Ê±²é³­DropperÊÇ·ñ´¦ÓÚÔËÐÐ״̬£¬Èç±»¹Ø¹Ø£¬Ôò³ÁÐÂÆô¶¯¡£ÒÔ´Ë´ïµ½¹ý³ÌÊØ»¤µÄÖ÷ÕÅ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹ý³ÌÊØ»¤Ö°ÄÜ


ͨѶºÍ̸½âÎö


1£©ÏνӷþÎñÆ÷


µ±³É¹¦×¢Èëµ½Ö¸±ê¹ý³Ìºó£¬¸ÃľÂíÔòÆðÍ·³¢ÊÔÓëǰÎĽâÃܳöµÄC2·þÎñÆ÷½øÐÐÏνÓ£¬²¢»áƾ¾Ý·þÎñÆ÷·µ»ØµÄÄÚÈÝÖ´ÐÐÖ¸¶¨²Ù×÷¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½Ó¹ÜÊý¾Ý°üµÄ½á¹¹´óÌåÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2£©½âÃܽÚÔì°ü


¸ÃľÂíÊ×ÏȽ«½Ó¹Üµ½µÄǰ0x0C¸ö×Ö½Ú×÷Ϊͷ²¿Êý¾ÝŲÓÃ×Ô½ç˵fn_Decrypt_CR4º¯Êý½øÐнâÃÜ£¨ÃÜÔ¿ÒÔÃ÷ÎÄ·½Ê½Ó²±àÂëÔÚ´úÂëÖУ©¡£³É¹¦½âÃܺó£¬È¡³öÆ«ÒÆ0x04´¦µÄDWORDÊýÖµ×÷ΪÊÇ·ñ³ÖÐøÖ´ÐÐÒÔϼú³ÌµÄÅжÏǰÌᣨ´ËDWORDÊýÖ·ﱣÁô×ųýÈ¥0x0Cºó£¬Ôü×ÒµÄÊý¾Ý³¤¶È£©¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈôǰÌáÇкÏ£¬Ôò¸ÃľÂí»áÔÙ´ÎŲÓÃfn_Decrypt_CR4º¯Êý¶ÔÕû¸öÊý¾Ý£¨Í·²¿Êý¾Ý+×·ËæÊý¾Ý£©³ÁнøÐÐÒ»´Î½âÃÜ¡£½Ó×ÅŲÓÃ×Ô½ç˵fn_Distributeº¯Êý£¬²¢È¡³öÊý¾ÝÖеÄOpCodeÀ´Ö´ÐÐswitchÖÐ·ÖÆçµÄ²Ù×÷¡£ÓйشúÂëÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3£©Ö´ÐнÚÔìÖ¸Áî


ͨ¹ýÎÒÃÇÇ°ÃæµÄ·ÖÎöÄܹ»¿´µ½£¬¸ÃľÂí½ÚÔìÖ¸ÁîÖÐÔ̺¬ÁË´óÁ¿Óû§ÒþÖÔÐÅÏ¢µÄÇÔȡְÄÜ¡£×îÖÕÊܺ¦ÕßµÄÃô¸ÐÊý¾ÝÐÅÏ¢£¬³ÇÊÐÆ¾¾ÝÔ¶³Ì·þÎñÆ÷µÄÖ¸Áî»Ø´«¸øÔ¶³Ì·þÎñÆ÷¡£


½ÚÔìÖ¸ÁîÖ°ÄÜ


µ±Ô¶³Ì·þÎñÆ÷³É¹¦ÏìÓ¦Êý¾Ýºó£¬¸ÃľÂí¾Í»áƾ¾Ý·þÎñÆ÷·µ»ØµÄÄÚÈÝÖ´ÐÐÖ¸¶¨²Ù×÷¡£²¿ÃŽÚÔìÖ¸ÁîÖ°ÄÜÈçϱíËùʾ£º


½ÚÔìºÅÁî

Ö¸ÁîÖ°ÄÜ

0x01~0x04

ŲÓÃ×Ô½ç˵º¯Êý£¬²¢½«Ö´ÐÐÁ˾ֻش«·þÎñÆ÷

0x02

ÉÏ´«¹ý³ÌÁбí

0x04

»ñÈ¡ÍÆËã»úÂß¼­´ÅÅÌÐÅÏ¢

0x06

ÉÏ´«ÎļþÁбíÐÅÏ¢

0x08

ÏÂÔØ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþ

0x10

ʵÏÖ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄ¹ý³Ì

0x0E

Remote Shell

0x10

È¡µÞÏÂÔØ

0x12

»ñÈ¡Webcam DevicesÁбí

0x14

Start Webcam

0x16

Stop Webcam

0x18

·¢ËÍÐÄÌø°ü

0x1A

Ð¶ÔØ¿Í»§¶Ë

0x1C

Åú¸Ä½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþ

0x1E

ÏÂÔØVNCÄ £¿é

0x20

ÇÔÈ¡Google Chrome¡¢Mozilla FireFoxµÈä¯ÀÀÆ÷ºÍOutLook¡¢Thunderbird¡¢FoxmailÓÊÏäÖб£ÁôµÄƾ֤ÐÅÏ¢

0x22

ÏÂÔØ½ÚÔìºÅÁîÖÐÖ¸¶¨µÄÎļþÁ´½Ó²¢Ö´ÐÐ

0x24

ƾ¾Ý½ÚÔìÖ¸ÁÇл»Á½ÖÖ·½Ê½À´¼Í¼¼üÅÌʹÓÃÐÅÏ¢

0x26

ʹÓÃÈ«¾ÖÐÂÎŹ³×Ó£¬¼Í¼¼üÅÌʹÓÃÐÅÏ¢

0x28

Remote VNC×°ÖÃ

0x2A

²âÊÔ±¾»úµÄÍøÂçÏνÓÖ°ÄÜ

0x2C

¶Ï¿ªÔ¶³Ì·þÎñÆ÷

0x38

δ֪²âÊÔ

other

»ñÈ¡Óû§Ãû£¬ÏµÍ³°æ±¾£¬GUIDµÈÐÅÏ¢


1£©ÇÔȡƾ֤ÐÅÏ¢


ÇÔÈ¡µÄÐÅÏ¢Ô̺¬Google Chrome¡¢Mozilla FirefoxµÈä¯ÀÀÆ÷ºÍOutlook¡¢Thunderbird¡¢FoxmailÓÊÏä¿Í»§¶Ë±£ÁôµÄƾ֤ÐÅÏ¢µÈ¡£


¸ÃľÂí»ñÈ¡ÓÐ¹ØÆ¾Ö¤ÐÅÏ¢ÒÔ¼°ÊµÏÖ²½ÖèÈçϱíËùʾ£º


ÇÔÈ¡µÄƾ֤ÐÅÏ¢

ʵÏÖ²½Öè

Google Chrome

¶ÁÈ¡\AppData\Local\Google\Chrome\User  Data\Default\ Login DataÊý¾Ý¿âÎļþ½øÐвéÎÊ

Mozilla Firefox

¶ÁÈ¡ÅäÖÃõ辶ϵÄsignons.sqliteÊý¾Ý¿â£¬²¢Í¨¹ýnss3.dll½âÃÜ

Outlook

±éÀú×¢²á±íSoftware\\Microsoft\\Windows  NT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesÏÂ×Ó¼ü½øÐмø±ð²¢½âÃÜ

Thunderbird

¶ÁÈ¡\AppData\Roaming\Thunderbird\ProfilesĿ¼ÏµÄÊý¾Ý¿âÎļþ£¬²¢Í¨¹ýÀûÓ÷¨Ê½Ä¿Â¼ÏµÄnss3..dll¶Ô´æ´¢µÄÃÜÂë½øÐнâÃÜ

Foxmail

¶ÁÈ¡ÓÊÏäĿ¼ÏµÄ\\Account\\Account.rec0Îļþ²¢½øÐнâÃÜ



a£©ÌáÈ¡Chromeƾ֤


Chromeä¯ÀÀÆ÷±£ÁôÓû§µÇ¼ÐÅÏ¢µÄÊý¾Ý¿âÎļþΪ%AppData%\Local\Google\Chrome\UserData\Default\Login Data£¬¸ÃÊý¾Ý¿âÊÇsqlite3µÄÊý¾Ý¿â£¬Êý¾Ý¿âÖÐÓÃÓÚ´æ´¢Óû§ÃûÃÜÂëµÄ±íΪlogins¡£logins±í½á¹¹½ç˵ÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ó¸Ã±íÖжÁÈ¡µÄÄÚÈÝÊǼÓÃܵÄ£¬Í¨¹ýCryptUnProtectDataº¯Êý¶ÔÆä½øÐнâÃܱãÄܹ»»ñÈ¡µ½Ã÷ÎÄÊý¾Ý¡£×îºó¸ÃľÂí½«½âÃܺóµÄÊý¾Ý±£ÁôÔÚÃûΪ¡±xxx.tmp¡±£¨¡±xxx¡°ÎªBase64½âÂë³öµÄ×Ö´®£©µÄһʱÎļþÖС£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


b£©ÌáÈ¡Mozillaƾ֤ÐÅÏ¢


¸ÃľÂíÊ×ÏȼìË÷ºÍ¶ÁÈ¡profile.iniÅäÖÃÎļþ£¬²¢ÌáÈ¡¹ØÁªµÄÎļþ¼Ðõè¾¶¡£½Ó×ÅÀûÓÃnss3.dllÀ´½âÃÜÊý¾Ý¿âsignons.sqliteÖб»¼ÓÃܵÄÄÚÈÝ£¬²¢Í¨¹ýSQLÓï¾ä»ñÈ¡µ½Ö÷»úÃû¡¢±»¼ÓÃܵÄÓû§Ãû¼°ÃÜÂ룬¶øºóŲÓÃnss3.dllÖеĵ¼³öº¯Êý¶Ôsqlite²éÎʳöµÄÓû§ÃûºÍÃÜÂë½øÐнâÃÜ¡£×îºóͬÑùµÄ£¬½«½âÃܺóµÄÄÚÈݱ£ÁôÔÚÃûΪ¡±xxx.tmp¡±µÄһʱÎļþÖС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Óû§ÃûºÍÃÜÂë


c£©OutLookƾ֤»ñÈ¡


µç×ÓÓÊÏäOutLookµÄÓû§µÇ¼ƾ֤ͨ³£»á±£ÁôÔÚ×¢²á±íÖУ¬¸ÃľÂíͨ¹ýö¾Ù×¢²á±íSoftware\\Microsoft\\WindowsNT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesϵÄËùÓÐ×Ó½¡£¬¶ÁÈ¡¼üÃûΪϱíÖеÄÊý¾ÝºÃ±Èpassword½øÐнâÃÜ»¹Ô­³öÃ÷ÎĵÄÃÜÂë¡£×îºó½«»ñÈ¡µ½µÄÓû§µÄOutlookµÇ¼ƾ֤дÈëÃûΪ¡±xxx.tmp¡±µÄһʱÎļþÖС£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


»ñÈ¡OutlookÓÊÏäµÄÓû§ÐÅÏ¢


d£©Thunderbirdƾ֤»ñÈ¡


ͬÑù£¬ThunderbirdÓÊÏäµÄƾ֤Êý¾ÝÒ²ÊÇ´æ´¢ÔÚÊý¾Ý¿âÎļþ%AppData%\\Thunderbird\\ProfilesÖУ¬¸ÃľÂíͨ¹ýnss3.dll µÄµ¼³öº¯Êý¶ÔÖü´æÎļþµÄÃÜÂë½øÐнâÃÜ¡£×îºó½«½âÃܺóµÄÊý¾Ý±£ÁôÔÚÃûΪ¡±xxx.tmp¡±µÄһʱÎļþÖС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


e£©FoxMailƾ֤»ñÈ¡


¸ÃľÂíÔÚFoxMailµÄ×°ÖÃĿ¼Ï²éÕÒStorageÎļþ¼Ð£¬½Ó×űéÀúËùÓе±Ç°ÓÊÏäÕË»§Ä¿Â¼ÏµÄ\Account\Account.rec0Îļþ¡£´ËÎļþÏÖʵÉϾÍÊÇÓÃÀ´´æ·ÅÕË»§ÓйØÐÅÏ¢µÄ£¬¼ÓÃܺóµÄÃÜÂë¾ÍĬÈϱ£ÁôÔÚÕâÀľÂí»ñÈ¡²¢½âÃÜ´ËÎļþºó±ã¿ÉÇÔÈ¡µ½FoxmailµÄƾ֤ÐÅÏ¢¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


f£©ÉÏ´«»ñÈ¡µ½µÄƾ֤ÐÅÏ¢


ÇÔÈ¡ÍêËùÓÐÐÅÏ¢ºó£¬¸ÃľÂíÔòʹÓÃfn_Decrypt_CR4¼ÓÃܺ¯Êý½«ÎļþÄÚÈÝ×ö¼ÓÃÜ´¦Öò¢½«ËüÃÇ·¢Ë͸øÔ¶³Ì·þÎñÆ÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2£©¼üÅ̼ͼ


a£©ÀëÏß¼üÅ̼ͼ£¨³£×¤£©

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±½ÓÊܵ½µÄ½ÚÔìºÅÁîΪΪÆôÓÃÍÑ»ú¼üÅ̼ͼʱ£¬´ËľÂíÔòʹÓù³×ÓÀ´ÊµÏÖ¼üÅ̼ͼְÄÜ¡£¸Ã¹³×Ó½«²¶»ñ°´¼üºÍ´°¿ÚÃûÐÅÏ¢±£ÁôÔÚ¡±C:\user\sss\AppData\Local\MicrosoftVision\¡±Ä¿Â¼Ï£¬ÎļþÔòÒÔµ±Ç°ÈÕÆÚºÍ¹¦·òÀ´¶¨Ãû¡£ÓйشúÂëµÄʵÏÖÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


b£©Ò»Ê±¼üÅ̼ͼ


µ±Ô¶³Ì½ÚÔìÖ¸ÁîΪ¿ªÆô¼üÅ̼ͼʱ£¬¸ÃľÂíÔòͨ¹ýRaw Input²½ÖèÀ´ÊµÊ±¼à¿Øµ±Ç°¼üÅ̵ÄʹÓÃÇé¿ö¡£½Ó׎«²¶»ñµ½µÄ¼üÖµ½øÐÐÅжϲ¢×ª»¯Îª×Ö·ûÖµ¡£Í¬ÑùµÄ£¬ÕâЩ×Ö·ûÖµºÍ´°¿ÚÃûÐÅÏ¢±£ÁôÔÚ¡±C:\user\sss\AppData\Local\MicrosoftVision\¡±Ä¿Â¼Ï£¬ÎļþÔòÒÔµ±Ç°ÈÕÆÚºÍ¹¦·òÀ´¶¨Ãû¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°´¼üºÍ´°¿ÚÃûÐÅÏ¢µÄ»ñÈ¡


3£©RemoteVNC×°ÖÃ


a£©½«ÐÂÓû§Ôö³¤µ½¡±Ô¶³Ì×ÀÃæÓû§¡±×é


Ê×ÏÈ£¬¸ÃľÂí»áŲÓÃfn_Base64×Ô½ç˵º¯Êý£¬½âÂë³öºóÐø±ØÒªÔö³¤µÄÕË»§ÃûºÍÃÜÂë¡£²¢É趨Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\SpecialAccounts\Userlist×¢²á±íֵΪ0À´°µ²ØÐ´´½¨µÄÕË»§¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ôö³¤²¢°µ²Ø´´½¨µÄÐÂÕË»§


½Ó×Å£¬¸ÃľÂí½«ÉÏÎĽâÂë³öµÄÕË»§ÃûºÍÃÜÂë×÷ΪÐÂÓû§²ÎÓëµ½administorÓû§×éÖС£ÕâÑù±ã¿ÉʹÓ÷ÇÖÎÀíÔ±Óû§À´½øÐÐÔ¶³Ì×ÀÃæµÇ¼¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½«ÐÂÕË»§²ÎÓëÖÎÀíÔ±×éÖÐ

b£©¸ü¸ÄÔ¶³Ì×ÀÃæÉèÖÃ


¸ÃľÂí»áÅú¸Ä×¢²á±íÐÅÏ¢£¬ÊµÏÖ´ò¿ªÔ¶³Ì×ÀÃæ¡¢¶àÓû§Ö§³Ö¡¢¸ü¸ÄÓû§µÇ¼ºÍ×¢Ïú·½Ê½¡¢Ê¹Óü±¾çµÇ¼Çл»¡¢ÒÔ¼°ÉèÖÃÔ¶³Ì¡±ÖÕ¶Ë·þÎñ¡±µÄʹÓÃÃûΪ¡°RDPClip¡±µÈµÈ²Ù×÷¡£¾ßÌåϸ½ÚÈçÏÂͼËùʾ£¨½ö½ØÈ¡Á˲¿ÃŲ½Ö裩£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý¶ÈÎöÎÒÃÇ·¢ÏÖ£¬´ËRATµÄÔ¶³Ì×ÀÃæÖ°ÄÜÊÇͨ¹ýÌØÔìµÄVNCÄ £¿éÀ´ÊµÏֵġ£²¢ÇÒÔÚºóÐøµÄ¸üа汾ÖУ¬»¹Ôö³¤ÁËHRDPÄ £¿éÀ´ÊµÏÖ°µ²ØÔ¶¿Ø×ÀÃæ¡£¸ÃHRDPÄ £¿éʹÓÃÁËGithubÉϵÄrdpwrapÏîÄ¿£¬²»½öÄܹ»ÔÚºó¶ÜµÇ¼Զ³ÌÍÆËã»ú£¬²¢ÇÒ´´½¨µÄWindowsÕË»§»¹»á×Ô¶¯°µ²Ø¡£


4£©È¨ÏÞÉý¼¶£¨UACÈÆ¹ý£©


¸ÃľÂíµÄȨÏÞÌáÉýÊÇÀûÓÃÁË×Ô¶¯ÌáÉýȨÏ޵ĺϷ¨ÀûÓ÷¨Ê½¡±pkgmgr.exe¡±À´Ö´ÐÐDISPÄ £¿é¡£ÆäÖ°ÄÜ´úÂëʵÏÖÊÇѡȡÁËBypass-UAC¿ò¼Ü£¬¸Ã¿ò¼ÜÄܹ»Í¨¹ýŲÓÃIFileOpertion COM¶ÔÏóËùÌṩµÄ²½ÖèÀ´ÊµÏÖ×Ô¶¯ÌáȨ¡£


¸ÃľÂíÏȽ«Ç¶ÈëÔÚ×ÊÔ´Êý¾ÝÖеÄPEÎļþÔÚÄÚ´æÖмÓÔØ²¢ÔËÐС£¶ø´ËPEÎļþÏÖʵÉÏÊÇÒ»¸ö¼ÓÔØÆ÷£¬ÆäËù×öµÄʼþÔòÊǽ«×ÊÔ´ÖеÄÁíÒ»¸öPEαÔìΪ¡°dismcore.dll¡±£¬¶øºó½«´Ëdll¸´Ôìµ½System32Ŀ¼Ï£¬×îºóʹÓÃpkgmgr.exeÖ´ÐÐαÔìµÄ¶ñÒâDLL¡£ÓÉÓÚpkgmgr.exeÊÇÒ»¸öUAC°×Ãûµ¥·¨Ê½£¬ËùÒÔËüĬÈÏÓµÓÐÖÎÀíԱȨÏÞ£¬ÇÒ²»»áµ¯³öUACÌáÐÑ¿ò¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

´Ë¶ñÒâDLLµÄÖØÒªÖ°ÄÜÊÇ»ñȡע²á±íÖеġ±Install¡±×°ÖÃÐÅÏ¢(DropperµÄõè¾¶)²¢³ÁÐÂÆô¶¯ÓµÓÐÖÎÀíԱȨÏÞµÄDropperйý³Ì¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5£©Î´Öª²âÊÔ


¸ÃľÂí³¢ÊÔÓëÔ¶³Ì·þÎñÆ÷½øÐÐͨѶ£¬µ±Ïνӳɹ¦Ê±Ôò»áÏò·þÎñÆ÷·¢ËÍ¡±AVE_MARIA¡±×Ö´®×÷Ϊ¼ÇºÅ¡£¶øºóÆÚ´ý½Ó¹Ü·þÎñÆ÷·µ»ØÊý¾Ý£¬´óÓ×Ϊ4¸ö×Ö½Ú¡£ÈôÊǽӹܳɹ¦£¬Ôò¿ªÆôÐÂÏ̡߳£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÐÂÏß³ÌÖУ¬Æ¾¾ÝÔ¶³Ì·þÎñÆ÷·¢Ë͵ÄÖ¸ÁÓëÐÂÖ¸¶¨µÄC&C½øÐÐÏνÓ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚ½Ó¹ÜÊý¾ÝÎÞ·¨»ñÈ¡£¬ËùÒÔĿǰÎÒÃÇÎÞ·¨È·¶¨ÆäÕýÈ·Óô¦£¬Ôݽ«Æä¶¨ÃûΪδ֪²âÊÔ¡£



3.2 ×îй¥»÷Ñù±¾



ÎÒÃÇÔÚ2019Äê3ÔÂ26ÈÕ²¶»ñµ½ÁË×îÐµĹØÁªÎĵµ¡°Michelle Flores - Curriculum Actualizado.doc¡±£¬ÆäͬÑùͨ¹ý¶ñÒâºêÆô¶¯¹¥»÷¡£ÎĵµÊ×ÏÈͨ¹ýPowershell¾ç±¾ÏÂÔØ²¢Ö´ÐÐPEÎļþ¡°massive.exe¡±(C#±àд²¢²ÎÓëÁË´óÁ¿»ìºÏ)¡£Ö®ºóÔ̺¬ÁËÁ½¸ö½×¶Î£¬µÚÒ»½×¶Î¡°massive.exe¡±»á´Ó×ÊÔ´ÖнâÃܳöPEÎļþ¡°DUMP1.exe¡±(C#±àд)²¢¼ÓÔØ¡£µÚ¶þ½×¶ÎÔòÊÇ¡°DUMP1.exe¡±¿ªÊÍ×ÔÉí²¢Í¨¹ý´òË㹤×÷ÉèÖÃ×ÔÆô¶¯£¬×îºó´Ó×ÊÔ´ÖÐÌáÈ¡³öRemcos RAT²¢ÒÔ¿þÀܹý³ÌµÄ·½Ê½¼ÓÔØÔËÐУ¬Ö÷Ìâ¹ý³ÌÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½×¶ÎÒ»£º


¡°massive.exe¡±´Ó×ÊÔ´ÖÐÌáÈ¡²¢½âÂë³ö¼ÓÃÜ×Ö·ûÁ÷£¬Ö®ºóͨ¹ýStrReverseº¯Êý½«¸Ã×Ö·ûÁ÷ÄæÐò·ÖÁУ¬ÔÙ¾­FromBase64Stringº¯Êý½âÂ룬×îºóͨ¹ý×Ô½ç˵µÄ½âÃܺ¯Êýmethod_0½âÃܵõ½PEÎļþ¡°DUMP1.exe¡±¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½âÃܺ¯Êýmethod_0ÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ¾­¹ýÄæÐò·ÖÁкÍBase64½âÂëºóµÄ×Ö·û´®£¨byte_0£©ÖУ¬Ç°16λΪ½âÃÜÃÜÔ¿¡°0x28 0x49 0xf7 0x30 0xec 0x8d 0x500x80 0x94 0xaf 0x85 0xaa 0xa8 0xe7 0xc0 0x41¡±,Ö®ºóΪ´ý½âÃÜÃÜÎÄ¡£º¯ÊýÒÔ16λΪѭ»·,½«ÃÜԿͬÃÜÎÄ˳´Î½øÐа´Î»Òì»ò£¬×îÖÕ½âÃܵõ½¡°DUMP1¡±Îļþ²¢Í¨¹ýCallByNameº¯Êý¼ÓÔØÖ´ÐС£


½×¶Î¶þ£º


¡°DUMP1¡±ÎļþͬÑùѡȡC#±àд£¬·¨Ê½Ê×ÏÈ»á˯Ãß50ÃëÒÔ¶ã±ÜɳÏä²é³­£¬Ö®ºó»á¼ì²âµ÷ÊÔÆ÷²¢½«×ÔÉí¿ªÊÍÖÁ¡°%ApplicationData%\riNpmWOoxxCY.exe¡±£¬½Ó×Å´´½¨schtasks.exe¹ý³Ì²¢Ôö³¤´òË㹤×÷¡°Updates\riNpmWOoxxCY¡±£¬´Ó¶øÊµ´Ë¿ÌµÇ¼ÕË»§Ê±×ÔÆô¶¯£¬ÓйغÅÁîÈçÏ£º


"C:\Windows\System32\schtasks.exe/Create/TN Updates\riNpmWOoxxCY/XMLC:\Users\super\AppData\Local\Temp\tmp925C.tmp"


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ö®ºó£¬·¨Ê½»á´Ó×ÔÉí×ÊÔ´ÄÚ½âÃܳöPEÎļþ¡°DUMP2¡±£¬Í¨¹ýCreateProcess¡¢WriteProcessMemoryºÍSetThreadContextµÈº¯Êý£¬ÒÔ¹ÒÆðµÄ·½Ê½¼ÓÔØÒ»¸öеĹý³Ì£¬²¢×îÖÕÒÔ¿þÀܹý³ÌµÄ·½Ê½Ð´Èë²¢¼ÓÔØ¡°DUMP2¡±¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾­¹ý¶ÈÎö£¬ÎÒÃÇÔÚ¡°DUMP2¡±Öз¢ÏÖÁËһЩ¿ÉÒÉ×Ö·û´®È磺¡°Remcos¡±¡¢¡°Remcos_Mutex_Inj¡±¡¢¡°2.3.0 Pro¡±¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý´óÁ¿¿ÉÒÉÐÅÏ¢ÎÒÃÇÈ·ÈÏ´ËľÂíΪRemcos RATµÄ¿Í»§¶Ë£¬ÇÒÆäʹÓõİ汾Ϊ2.3.0 Pro¡£ÒÔRemcos RATÃâ·Ñ°æV2.4.3ΪÀý£¬·þÎñ¶ËÈçͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÃâ·Ñ°æ½ö¿ÉÔö³¤Ò»¸öC2ÏνӷþÎñÆ÷£¬×¨Òµ°æÔòûº±¼ûÁ¿ÏÞ¶È¡£Õâ´Î¹¥»÷ÖÐÖ²ÈëµÄľÂíÊÇͨ¹ýרҵ°æÌìÉúÇÒÏνÓÖÁ¶à¸ö¶ñÒâC2£¬Ô̺¬µÄC2µØÖ·ÌáÈ¡ÈçÏ£º


casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com

activate.office-on-the.net


Remcos RAT×Ô2016ÄêϰëÄêÆðÍ·ÔÚÆä¹ÙÍøºÍºÚ¿ÍÂÛ̳ÊÛÂô£¬²¿Ãų§ÉÌÔø¶ÔÆä½øÐйý¾ßÌåµÄ¼¼Êõ·ÖÎö£¬Ôڴ˲»×ö׸Êö£¬µ«Õâ¿îľÂíµÄ·¢ÏÖΪÎÒÃÇѰÕÒ¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄδ֪ľÂíÆðÔ´ÌṩÁ˺ܺõÄËÝÔ´ÏßË÷¡£



4¶ñÒâ´úÂëËÝÔ´Óë¹ØÁª



4.1 ¶ñÒâ´úÂëËÝÔ´×·×Ù



ǰÎÄÔøÌáµ½£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÖÐÔ̺¬ÁË¡°AVE_MARIA¡±Ìصã×Ö·û´®£¬ÇÒ×Ô2018Äê12ÔÂÆðÍ·£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾ÔÚtwitter¡¢virustotalµÈƽ̨ԽÀ´Ô½¶àµÄ±»·¢ÏÖ¡£µ«¶àƪÓйØ×êÑÐÎÄÕ¾ùδָ³öÆäÕæÊ·´Ô´£¬É±¶¾³§ÉÌÒ²¿í·ºµÄ½«Æä¶¨ÃûΪAVE_MARIA£¬ÕâÒýÆðÁËÎÒÃÇŨÃܵÄÐËÖ¡£


ÎÒÃdz¢ÊÔ´Ó¶àÖֽǶÈÈ¥ËÝԴľÂíÒÔѰÕÒÏßË÷£¬Ô̺¬ÓòÃû¡¢IP¡¢¹ØÁªÑù±¾µÈµÈ¡£ÆäÖÐÔÚ¶Ô¹ØÁªÑù±¾¡°Michelle Flores - Curriculum Actualizado.doc¡±µÄ·ÖÎöÖгɹ¦ËÝÔ´µ½ÁËÉÌÓÃÈí¼þRemcos RAT¡£ÎÒÃÇ·ÖÎöÁ˸ÃÈí¼þµÄ°ä²¼Çþ·£¬·¢ÏÔìä²»½öÔÚ¹ÙÍø½øÐÐÏúÊÛ£¬»¹ÔÚÖî¶àºÚ¿ÍÂÛ̳ÈçHackforumsÉÏ´óÁ¿ÊÛÂô¡£ÓÉ´Ë£¬ÎÒÃDz²⹥»÷ÈËÔ±ºÜ¿ÉÄÜ»îÔ¾ÔÚÓйØÂÛ̳²¢²É°ì¹ý¶à¿îÉÌÓÃÈí¼þ£¬Í¬Ê±Ò²½«ËÝÔ´³ÁµãתÏòºÚ¿ÍÂÛ̳ºÍ°µÍøÊг¡¡£


ÎÒÃÇÍøÂç²¢·ÖÎöÁË´óÁ¿AVE_MARIAÀà¶ñÒâÑù±¾£¬·¢ÏÖ´ó²¿ÃÅÑù±¾¾ùͨ¹ýwarzonedns.com×ÓÓòÃû½øÐжñÒâÏνӺÍÏÂÔØ£¬×·Òä·¢ÏÔìäÄÚÈÝΪºÚ¿ÍÌṩµÄDDNS·þÎñ¡£½áºÏ¹¥»÷ÈËÔ±µÄ»î¶¯ÏßË÷£¬ÎÒÃdzɹ¦×·×Ùµ½HackforumsÂÛ̳ÉϵĿÉÒÉÓû§Solmyr¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SolmyrÔÚÂÛ̳ÖÐÌṩÁËwarzonedns.comÓòÃûµÄÃâ·ÑDDNS·þÎñ£¨IP¶¯Ì¬°ó¶¨ÖÁ×ÓÓòÃû£©£¬Ê¹µÃÓû§Äܹ»µÈÏеĽ«·þÎñÆ÷IP°ó¶¨½âÎöÖÁwarzonedns.comϵÄËÁÒâ×ÓÓòÃû£¬Ê¹ÓÃʾÀýÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÕâÎÞÒɸøºÚ¿ÍÌṩÁ˺ܺõIJØÉíÖ®Ëù£¬Óë´ËͬʱÎÒÃÇ·¢ÏÖSolmyrµÄÁíÒ»¸öÉí·ÝÊÇWARZONE RATµÄ°ä²¼Õߣ¬¸ÃÈí¼þÓÉÓÚ½ÚÔ켿Á©·á˶¡¢¼¼ÊõÖ°ÄÜ׳´ó¡¢µü´ú¸üÐÂѸ¿ì£¬Ä¿Ç°ÔÚHackforumsÂÛ̳Öм«¶ÈÊÜÓ­½Ó¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖÁ´Ë£¬ÎÒÃÇÓÐÀíÓÉÒɻ󹥻÷ÕßʹÓùý¸Ã¿îÉÌÓÃÔ¶³ÌÖÎÀí¹¤¾ß¡£ÓÉÓÚ¸ÃÈí¼þ¹ØÔ´ÇÒ²»ÌṩÃâ·Ñ°æ±¾£¬ÎÒÃÇ×·Òäµ½ÁËWARZONE RATÁ÷³öµÄÆÆ½â°æ±¾£¨V1.31£©£¬²¢½«ÆäÓë¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÑù±¾½øÐÐͬԴÐÔ·ÖÎö,ÒÔÈ·¶¨¶þÕß¼äµÄ¹ØÁª¡£



4.2 ͬԴÐÔ·ÖÎö



Ê×ÏÈ£¬ÎÒÃÇÔÚÁ½ÖÖÑù±¾Öоù·¢ÏÖÁËÌØµã×Ö·û´®¡°AVE_MARIA¡±£¬²¢ÇÒÕë¶ÔÁ½ÀàÑù±¾µÄ´úÂë½á¹¹½øÐÐÁ˱ȶÔ£¬·¢ÏÖÀàËÆ¶È¼«¸ß¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Æä´Î£¬ÎÒÃÇͨ¹ýBindiff½øÐÐÁ˸üΪ¾«È·µÄ¶Ô±È£¬ÔÚÈ¥³ý²¿ÃÅAPI×ÌÈŲ¢±ÈÁ¦·ÖÎöÁË¿ÉÐŶȸߵĺ¯Êýºó£¬·¢ÏÖ´óÁ¿º¯ÊýÆëȫһÑù£¬Õ¼±È´ïµ½80.16%£¬ÆäÓຯÊýÔò¿ÉÄÜÓÉÓÚ°æ±¾Ô­ÒòÂÔÓвî¾à£¬ÕâÒ²Ó¡Ö¤Á˶þÕß¼äµÄÇ¿¹ØÁªÐÔ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Áí±í,´Ó´«²¼¹¦·òµÄ½Ç¶È·ÖÎö,¡°AVE_MARIA¡±¹ØÁªÑù±¾×î³õ³öÏֵŦ·ò(2018Äê12ÔÂ2ÈÕ)ÂÔÍíÓÚWarzoneRATÔÚÂÛ̳µÄ°ä²¼¹¦·ò(2018Äê10ÔÂ22ÈÕ)£¬ÕâÒ²Çк϶ñÒâ´úÂë´«²¼µÄ¹¦·òÂß¼­¡£


ƾ¾ÝÒÔÉϼ¸µã·ÖÎö£¬ÎÒÃÇÒÔΪÁ½ÕßÓµÓи߶ȵÄÒ»ÖÂÐÔ¡£´ÓĿǰÒÑÖªµÄÇé¿ö¿´£¬WARZONE±»É±¶¾³§ÉÌ¿í·ºµÄ¼ø±ðΪAVE_MARIA£¬¶øÔÚÉî¿Ì±È¶Ô·ÖÎöºó£¬ÎÒÃÇÅж¨ºÚ¿Í×é֯ʹÓõÄÔ¶¿ØÄ¾ÂíÕýÊÇWARZONE RAT¡£Òò¶øÄܹ»½«´ËÀàÔ̺¬¡°AVE_MARIA¡±×Ö·û´®µÄ¶ñÒâÑùͬ×Ú×嶨Ãû¸üÐÂΪ¡°WARZONE¡±¡£



4.3 ÓòÃû¹ØÁª



ÎÒÃǹ۲쵽ĿǰÓëDDNS·þÎñwarzonedns.comÓйØÁªµÄ×ÓÓòÃû×ÜÊý¹²101¸ö£¬²¿ÃŽØÍ¼ÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÕâÅúÓòÃû¾ùΪwarzonedns.comÌṩµÄÃâ·Ñ×ÓÓòÃû£¬ÇÒ´ó²¿ÃŹØÁªÖÁ¶ñÒâÑù±¾£¬ÕâÅú×¢´óÁ¿ºÚ¿ÍÔÚÀÄÓôËÀà·þÎñ½øÐжñÒâ¹¥»÷¡£


Äܹ»ÅжÏ£¬SolmyrÍÅ»ï×÷ΪWARZONEÀà¶ñÒâÈí¼þ²úÒµÁ´µÄÉÏÓι©¸øÉÌ£¬ÌṩÁËÔ̺¬Ãâ·ÑÓòÃû·þÎñ¡¢ÊշѶñÒâÈí¼þ¼°ÆäËü¶ñÒâÀûÓü¼ÊõµÈһϵÁзþÎñ£¬´ò°üÊÛÂô¸øÏÂÓκڿÍʹÓá£Õâ´ÎÊÂÎñµÄ¹¥»÷×é֯ҲΪÆäÏÂÓοͻ§£¬Í¨¹ý²É°ìÆä²¿ÃÅ·þÎñ£¬Óë×ÔÉíµÄ¶ñÒâ´úÂë×éºÏÀûÓÃÀ´´ïµ½¸ü¼ÑµÄ¹¥»÷³ÉЧ£¬Í¬Ê±Ò²ÄܸüºÃµÄ°µ²Ø×Ô¼ºµÄÉí·Ý¡£



5×Ü ½á



±¾ÎĶԱ¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Á÷³Ì¡¢ÓйصĶñÒâ´úÂë¡¢ºÚ¿Í²¼¾°µÈ×öÁËÉî¿ÌµÄ·ÖÎöºÍ×êÑУ¬´ÓÉÏÎĵķÖÎöÖÐÎÒÃÇÄܹ»¿´³ö¸ÃºÚ¿Í×é֯ĿǰµÄ¹¥»÷»î¶¯¼«¶ÈÉóÉ÷£¬¼ÈûÓдó¹æÄ£µÄ¹¥»÷£¬Ò²Ã»ÓÐѡȡ¸ß³É±¾µÄ0day·ì϶£¬Í¬Ê±£¬¹¥»÷»î¶¯¹¦·òÒ²¼«¶È¶Ì¡£ÕâÅú×¢¸Ã¹¥»÷»î¶¯»¹´¦ÓÚ³õÆÚ£¬²¢¶ÔÖ¸±ê½øÐÐÁËһЩÊÔ̽ÐÔ¡¢Õë¶ÔÐԵĹ¥»÷£¬Ò²ÎªºóÐøµÄ¹¥»÷×öºÃ³ï±¸¡£´Ë±íͨ¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´£¬ÎÒÃÇÈ·¶¨Á˸ôλ±³ºóµÄºÚ¿Í×éÖ¯£¬²¢Æ¾¾Ý¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯º¹Ç࣬·¢ÏÔìäÃñ×åÖ÷ÒåÉ«²ÊÇ¿ÁÒ£¬Òò¶øÕþÖÎÖ÷ÕÅÒâͼҲ½ÏΪÏÔÖø¡£


µ±Ç°ÀûÓÃºê½øÐÐÍøÂç¹¥»÷ÒѾ­³ÉΪһÖֳɱ¾½ÏµÍµÄ¹¥»÷·½Ê½£¬Òò¶øÒ²±»´óÁ¿µÄºÚ¿Í×éÖ¯ËùʹÓ᣺ڿÍʱʱÀûÓÃÖ¸±êµÄһЩÓÄ΢»·½ÚÀ´½øÐдËÀ๥»÷£¬ÓµÓп϶¨µÄ³É¹¦ÂÊ£¬Í¨¹ýµö¶üÎĵµÄܹ»¿´³ö£¬±¾´Î»î¶¯Õë¶ÔµÄÊǵ±¾Ö»ú¹¹µÄÕÐÆ¸²¿ÃÅ£¬´ËÀàÈËȺӵÓÐÏà¶Ô½ÏÈõµÄ°²È«Òâʶ£¬ÇÒÓÉÓÚ¹¤×÷ÖбØÒª·­ÔĵļòÀúÁ¿½Ï¶à(Èç²ÆÕþ²¿ÃŵļòÀúÁ¿Í¨³£½Ï´ó)£¬Ê¹µÃÓйØÈËÔ±ÎÞ·¨·Ö±æ¼Ù×°µÃ½ÏºÃµÄ¶ñÒâ¼òÀúÎļþ¡£ÔÙ¼ÓÉ϶à½×¶ÎÔÚÏßÏÂÔØ¶ñÒâ´úÂëµÄÕ½Êõ¡¢ÎÞÎļþ¼¼ÊõºÍ´ò°ü¼ÓÃܼ¼ÊõµÄʹÓ㬴Ӷø´ó´óÌá¸ßÁ˹¥»÷µÄ³É¹¦ÂÊ¡£Òò¶ø´ËÀ๥»÷±ØÒªÓйز¿ÃÅÌá¸ß¾¯Ì裬¼Óǿϵͳ¼Ü¹¹ÖеĶ̰å·À±¸¡£

IOC

MD5

99C82F8A07605DA4CCC8853C910F7CAF

048DCA20685ECD6B7DBDBF04B9082A54

DEF105A9452DEF53D49631AF16F6018B

1E19266FC9DFF1480F126BD211936AAC

262D9C6C0DC9D54726738D264802CCAD

B3C9F98DD07005FCCF57842451CE1B33

497566120F1020DBD6DF70DD128C0FFB

ÓòÃû

linksysdatakeys[.]se

gestomarket[.]co

asdfwrkhl.warzonedns[.]com

casillas.hicam[.]net

casillasmx.chickenkiller[.]com

casillas.libfoobar[.]so

du4alr0ute.sendsmtp[.]com

settings.wifizone[.]org

wifi.con-ip[.]com

rsaupdatr.jumpingcrab[.]com

activate.office-on-the[.]net