GA»Æ½ð¼×ADLab£º¹ØÓÚ½üÈÕÃÅÂÞ±Ò¹©¸øÁ´¹¥»÷ÊÂÎñ·ÖÎö

°ä²¼¹¦·ò 2019-11-21

1.¹¥»÷²¼¾°


2019Äê11ÔÂ19ÈÕ£¬ÃÅÂÞ±Ò¹Ù·½githubÉϳöÏÖ¶ÔÃÅÂÞ±Òrelease°æÓë¹ÙÍøÉϳöÏÖ²»Ò»ÖÂÎÊÌâµÄissues£¬ÆäÖÐÌá¼°³öÏÖÎÊÌâµÄÃÅÂޱҰ汾Ϊ×îаæ0.15.0.0¡£ÇÒÃÅÂÞ±Ò¹Ù·½ÈÏ¿ÉÆä¹ÙÍøÊܵ½ºÚ¿ÍÈëÇÖ£¬Ê¹µÃÆäÌṩµÄÃÅÂÞ±Ò¿Í»§¶Ë´æÔÚÇÔÈ¡Óû§¹Ø¼üÐÅÏ¢µÄÊÂʵ£¬ÕâÒ²Êdzõ´Î±»·¢ÏÖµÄÖ±½ÓÕë¶Ô¼ÓÃÜÇ®±Ò¿Í»§¶ËµÄ¹©¸øÁ´¹¥»÷¡£

ÃÅÂÞ±Ò¹Ù·½ÉêÃ÷£¬¶ñÒâ¹¥»÷²úÉúÔÚ11ÔÂ18ÈÕ£¬11ÔÂ19ÈÕ¹¥»÷±»·¢ÏÖ²¢½øÐÐÁ˽¨¸´¡£Í¨¹ý¶ÔÒѾ­È·ÈϵÄϰȾ°æ±¾µÄhash ½øÐбȶÔ£¬·¢ÏÖ¿Í»§¶Ë×é¼þmonero-wallet-cli±»ºÚ¿Í´Û¸Ä£¬ÆäÖÐhashΪ£º5decc690a63aab004bae261630980e631b9d37a0271bbe0c5b477feffcd3f8c2µÄÎļþ±»´úÌæÎª£º7ab9afbc5f9a1df687558d570192fbfe9e085712657d2cfa5524f2c8caccca31¡£µ±Ì죬redditÉÏÒ²³öÏÖÁËʹÓÃÕßÓÉÓÚ×°ÖÃÁ˹ٷ½ÍøÕ¾µÄ×îÐÂrelease°æ±¾¶øÃÔʧÁ˼ÛÖµ7000ÃÀÔªÃÅÂÞ±ÒµÄÏÖʵ°¸Àý¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÊÂÎñÅû¶µÄͬʱ£¬ÎÒÃÇÒ²ÆðÍ·¶ÔÆä½øÐп϶¨µÄ¹Ø×¢£¬²¢¶ÔÉæ¼°¸Ã´Î¹¥»÷µÄ¶ñÒâ´úÂë½øÐÐÁË·ÖÎöºÍ×·×Ù¡£´Ó·ÖÎöµÄÁ˾ÖÀ´¿´£¬±¾´Î¹¥»÷µÄºÚ¿Í½«ÃÅÂÞ±ÒÔ´ÂëÖÐcryptonote::simple_wallet()Àà½øÐд۸Ä£¬Éæ¼°µÄÎļþÓУº

monero/src/simplewallet/simplewallet.h

monero/src/simplewallet/simplewallet.cpp

ºÚ¿ÍÀûÓÃÒÔÉÏÎļþʵÏÖÁËÇÔÈ¡ÃÅÂÞ±ÒseedµÄÖ°ÄÜ¡£ºÚ¿Í²»»áÖ±½ÓÇÔÈ¡ÃÅÂÞ±ÒµÄÇ®°üÎļþ£¬¶øÊÇÇÔÈ¡ÃÅÂÞ±ÒseedÒÔ¼°µÁÈ¡ÃÅÂÞ±ÒÇ®±ÒµÄËùÓÐȨ£¬Òò¶øµÁȡ֮ºó±ØÒªÊ¹ÓÃseedÀ´¸´Ô­Ç®°ü£¬ÒÔÌáÈ¡ÆäÖеÄÃÅÂÞ±Ò¡£´Ë±í£¬¶ñÒâ´úÂëÄÚÖÃÓÐÈý¸öC&C£¬±ðÀëΪnode.hashmonero.com¡¢node.xmrsupport.coºÍ45.9.148.65¡£ÆäÖУ¬node.hashmonero.comΪĬÈϵÄCC·þÎñÆ÷£¬¶ønode.xmrsupport.coºÍ45.9.148.65×÷Ϊºó±¸CCʹÓᣴӵ±Ç°µÄÓòÃû½âÎöÇé¿öÀ´¿´£¬node.xmrsupport.coºÍ45.9.148.65Ö¸Ïòͳһ̨·þÎñÆ÷£¬Ö÷CC node.hashmonero.comËùÖ¸ÏòµÄIPΪ91.210.104.245¡£ËùÓÐCC¶¼Ñ¡È¡¶Ë¿Ú18081×÷Ϊseed»Ø´«µÄ·þÎñ¶Ë¿Ú¡£

±¾ÎÄÊ×ÏȶԱ»´Û¸Ä¶ñÒâmonero-wallet-cliÎļþ×öÏêϸµÄ·ÖÎö£¬½Ó×ÅÊÔͼ¶ÔºÚ¿ÍµÄ»ù´¡ÉèÖýøÐÐ×·×Ù·ÖÎö£¬·¢ÏÖÁ˺ڿÍËùʹÓùýµÄÆäËû»ù´¡ÉèÊ©¡£ÓÉÓÚÃÅÂÞ±Ò¹Ù·½¶ÔÓÚ¸ÃÊÂÎñÈÔÔÚµ÷²éÖ®ÖУ¬ËùÒÔ¶ÔÓÚºÚ¿ÍÊÇÈôºÎ¹¥»÷½øÈëÃÅÂÞ±Ò¹Ù·½ÍøÕ¾µÄ¾ßÌåϸ½Ú±í½ç²¢²»Í¨´ï£¬ÎÒÃǽ«³ÖÐø¹Ø×¢¸ÃÊÂÎñµÄ½øÕ¹¡£


2.Ñù±¾·ÖÎö


¸ÃÑù±¾ÖØÒªÇÔÈ¡ÃÅÂÞ±ÒµÄseedÊý¾Ý£¬ÃÅÂÞ±ÒseedÓÉ25¸öµ¥´Ê×é³É£¬ÓÃÀ´Ö¤Ã÷Õ¼ÓÐÕß¶ÔÒ»¸öÃÅÂÞ±ÒµØÖ·ÀïÃæµÄÇ®±ÒËùÓÐȨ£¬Ò²¿ÉÓÃÓÚ¸´Ô­Ç®°ü¡£seedÀàËÆÓÚÈçÏÂ×Ö·û´®£º

juicy sorry lukewarm lively fitting pulp irony nobody ought pelican sanity fudge vibrate ozone nearby upright addicted foxes arises alerts sorry lobster inmate karate ozone

¸ÃÑù±¾ÒÔÔ´ÂëΪ»ù´¡£¬ÔÚº¯Êýcryptonote::simple_wallet::print_seedº¯ÊýÖвÎÓëÁ˶ñÒ⺯Êýcryptonote::simple_wallet::send_seed¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸Ãº¯Êý½«»ñÈ¡µÄseedÐÅÏ¢·¢Ë͸ønode.hashmonero.com£¬¶Ë¿ÚΪ18081£¬ÆäÖÐseedÐÅÏ¢´æ´¢ÔÚ¡±memo=¡±²ÎÊýÖС£¸Ãº¯ÊýÖØÒªÍ¨¹ýŲÓÃcryptonote::simple_wallet::send_to_ccº¯ÊýÀ´ÊµÏÖseedµÄ·¢ËÍ¡£·¢Ë͵ķ½Ê½ÊÇͨ¹ýhttps POST·½Ê½ÊµÏÖ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚsend_to_ccº¯ÊýÖУ¬Æä½«CC·þÎñÆ÷µÄ¶Ë¿ÚÓ²±àÂëÔÚ´úÂëÖУ¬Í¨¹ýSSLºÍ̸½«ÇÔÈ¡µÄÃÅÂÞ±Òseed·¢Ë͸øÖ¸¶¨µÄCC·þÎñÆ÷(node.hashmonero.com)¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈôÊǸÃCCÎÞ·¨Ê¹Ó㬶ñÒâ´úÂëÔò»áÊ×ÏÈѡȡºó±¸C&C node.xmrsupport.co½øÐÐÏνӲ¢½«ÇÔÈ¡µÄseed»Ø´«ÖÁCC·þÎñÆ÷ÉÏ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÈôÊǺó±¸C&C»¹ÊÇÎÞ·¨Ê¹Óã¬Ôòѡȡºó±¸·þÎñÆ÷"45.9.148.65"×÷ΪÇÔÈ¡seedµÄ»Ø´«CC¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͬʱ£¬±»´Û¸ÄµÄº¯Êýsend_seed»¹±»¶î±íÔö³¤µ½ÁËmonero-wallet-cliÎļþµÄÆäËûÈý¸ö´¦ËùÒÔÈ·±£ÔÚ¸÷ÀàʹÓòÙ×÷ÖпÉÄܸüÓÐЧµØ»ñÈ¡seed¡£ÕâÈý¸ö´¦Ëù±ðÀëΪǮ°ü´´½¨º¯Êýcryptonote::simple_wallet::new_wallet()£¬Ç®°ü´ò¿ªº¯Êýcryptonote::simple_wallet::open_wallet£¬ÒÔ¼°Í¬Ãû³ÁÔØº¯Êý¡£

£¨1£©ÔÚnew_wallet()º¯ÊýÖУ¬²¹¶¡º¯ÊýÖØÒªÓÃÓڽػñÇ®°ü´´½¨¹ý³Ì£¬Ò»µ©Ç®°ü´´½¨³É¹¦£¬ÆäÇ®°üÓйصÄseed¾Í»áµ±¼´·¢Ë͸øC&C¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨2£©open_walletº¯ÊýÖØÒªÓÃÓÚ´ò¿ªÒ»¸öÃÅÂÞ±ÒÇ®°üÎļþ(Ô̺¬ÓÉÓ²¼þÇ®°üÌṩµÄÉ豸´ò¿ª)£¬¸Ã¶ñÒâ´úÂëͬÑù¶Ô¸Ãº¯Êý½øÐд۸Ä£¬ÒÔ±ãÇ®°ü±»¼ÓÔØÖ®ºó£¬½«Æä·¢Ë͵½C&C·þÎñÆ÷ÉÏ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨3£©µÚÈý´¦ÊDzÎÓëµ½ÁËͬÃûµÄ³ÁÔØº¯Êýcryptonote::simple_wallet::print_seed(bool  encrypted)ÖÐ £¬Ôڸú¯ÊýÖУ¬ÆäÇÔÈ¡Óɺ¯Êýtools::wallet2::get_multisig_seedºÍtools::wallet2::get_seedËùµÃµ½µÄseed¡£¸ÃͬÃû³ÁÔØº¯ÊýÖØÒªÓÉcryptonote::simple_wallet::encrypted_seedºÍcryptonote::simple_wallet::seedÁ½¸öº¯ÊýŲÓá£encrypted_seedÓÃÓÚÏÔʾ¼ÓÃܺóµÄÃÅÂÞ±Òseed£¬¶øseedº¯ÊýÓÃÓڲ鿴δ¼ÓÃܵÄÃÅÂÞ±Òseed¡£ÕâÒâζ×Å£¬ÈÎºÎ±í²¿Ç®°üÎļþµÄ²é¿´ÐÐΪ³ÇÊб»½Ù³Ö£¬´Ó¶øµ¼ÖÂÓëÇ®°üÓйصÄseedÔâµ½ºÚ¿ÍÇÔÈ¡¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.ºÚ¿Í×·×ÙÓëËÝÔ´


ÎÒÃÇÔÚÊÜϰȾµÄÃÅÂÞ±Ò¿Í»§¶ËÖз¢ÏÖÓ²±àÂëµÄCC·þÎñÆ÷µØÖ·£¬ÆäÖÐÓÐ2¸öÓòÃûºÍ¸ö1IPµØÖ·£¬Ó²±àÂëµÄCCÐÅÏ¢ÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÖУ¬ºóÁ½¸öÓ²±àÂëCCĿǰָÏòͳһ¸ö·þÎñÆ÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ΪÁ˶ԺڿÍʹÓõÄÉèÊ©ÓнøÒ»²½µÄ°ÑÎÕ£¬ÎÒÃÇËæºó¶ÔÕ⼸¸öÓ²±àÂëµÄCC½øÐÐÁ˾ßÌåµÄ·ÖÎö¡£

Ê×ÏÈ£¬ÎÒÃÇÀ´¿´C&C node.hashmonero.com£¬Õâ¸öC&CÊǶñÒâ´úÂëµÄĬÈÏC&CµØÖ·¡£¸ÃC&Cµ±Ç°±»½âÎöµ½IP£º91.210.104.245¡£´ÓwhoisÐÅÏ¢ÖÐÎÒÃÇ·¢ÏÖ¸ÃÓòÃûÊÇ2019Äê11ÔÂ14ÈÕ×¢²áµÄ£¬ÇÒÓòÃûÉêÇëµÄ¹«Ë¾×ֶα»±£»¤¡£ÓòÃû²éÎÊÁ˾ÖÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ë±í»¹Äܹ»¿´³ö¸ÃÓòÃû×öÁËÒþÖÔ±£»¤£¬ºÜÄѶԺڿ͵ÄÐÅÏ¢ÔÙ½øÇ°½øÒ»²½µÄ×·×Ù£¬µ«ÊÇÎÒÃÇ´Ó¸ÃÓòÃûµÄ×¢²á¹¦·òÄܹ»¿´³öºÚ¿Í´òËãÖ´Ðй¥»÷¹¦·òÒ²Ó¦¸Ã²»»áÌ«ÓÆ¾Ã¡£¶ø´ÓÓòÃûnode.xmrsupport.coµÄwhoisÐÅÏ¢ÖеÃÖªÆä´´½¨ÓÚ2019Äê11ÔÂ15ÈÕ¡£Òò¶øÄܹ»´§¶ÈºÚ¿ÍÌìÉú¹¥»÷Ñù±¾Ê±£¬Ó¦¸ÃÒѾ­°ÑÎÕÁËÃÅÂÞ±Ò¹Ù·½ÍøÕ¾µÄ·ì϶¼°¹¥»÷²½Öè¡£Òò¶øºÚ¿ÍµÄ¹¥»÷´òËãÒ²Ó¦¸ÃÔÚ2019Äê11ÔÂ14ÈÕ֮ǰµÄ¾ÍÒѾ­ÆðÍ·ÁË£¬ÕæÕýÖ´Ðй¥»÷¾ÍÔÚËæºó¼¸Ìì(11ÔÂ15ÈÕ-18ÈÕÖ®¼ä)¡£

ͨ¹ýIPµØÖ·45.9.148.65½âÎöµÄº¹Ç࣬»¹·¢ÏÖ2019Äê11ÔÂ16ÈÕÓòÃûhashmonero.com±»½âÎöµ½´ËIPµØÖ·ÉÏ,ÔÚ¹¥»÷±»·¢ÏÖµ±Ìì2019Äê11ÔÂ19ÈÕÓòÃûnode.xmrsupport.co²Å±»½âÎöµ½¸ÃIP¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ËǰÔÚgithubÉÏÓÐÈËÀûÓÃä¯ÀÀÆ÷½Ó¼ûhttps://91.210.104.245:18081Ò³Ãæ»á±»³Á¶¨Ïòµ½https://monerohash.com/?r=from_node£¬²»ÍâÔÚ11ÔÂ20ÈÕ21ʱ×óÓÒ£¬ÓÉÓÚ±»´óÁ¿Óû§¾Ù±¨£¬CC·þÎñÆ÷91.210.104.245ÒѾ­±»Ö÷»úÌṩÉÌÖÕ³¡·þÎñ¡£¾­²éÎÊ£¬ÎÒÃÇ·¢ÏÖ91.210.104.245Ϊ¶íÂÞ˹Ö÷»ú·þÎñÉÌwww.hostkey.ruËùÓУ¬IPµØÖ·µÄwhoisÐÅÏ¢ÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ýVT¶ÔIP £º91.210.104.245µÄº¹Çà¼Í¼½øÐзÖÎö£¬·¢Ïָ÷þÎñÆ÷ÔøÓÚ2017Äê7ÔÂ24ÈÕÖ¸ÏòÒ»¸öÓòÃûbitcoinbotreview.com£¬ÔÚÁ½ÄêÒÔÀ´²Å±»½âÎöµ½µ±Ç°µÄIP £º91.210.104.245¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸ÃÓòÃû¹ÌȻֻÓп¨°Í˹»ùÒ»¿îɱ¶¾Èí¼þ±¨¶¾£¬µ«´ÓÓòÃû¹ØÁª³öµÄÑù±¾Äܹ»¿´³ö¸Ã·þÎñÆ÷Ôø±»×÷ΪÁí±íÒ»¿î¶ñÒâ´úÂëµÄCC·þÎñÆ÷¡£´ÓÓòÃû×ÔÉíµÄÔ¢ÒâÉÏ¿´£¬ËƺõÓ¦¸ÃÓë±ÈÌØ±ÒÓйضñÒâ¹¥»÷ÓйØ¡£´Ë´¦ÎÒÃÇÒ²¶ÔÕâ¸ö¹ØÁªµÄÑù±¾½øÐÐÁ˼òÒª·ÖÎö¡£

VTÉϵĹØÁªÑù±¾Ô­Ê¼Ãû³ÆÎª¡°documentation.doc.exe¡± ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ¶ÔÑù±¾¡°documentation.doc.exe¡±½øÐзÖÎöºó£¬ÎÒÃÇ·¢ÏÔìäÊÇÒ»¸öʹÓÃAutoit3±àдµÄ¶ñÒâ´úÂë¼ÓÔØÆ÷£¨¼ÓÔØÆ÷ÄÚÖÃÓÐÁ½¸öC&C£ºbitcoinbotreview.comºÍbitcoinautobot.com£©£¬Æä´ÓÁ´½Óhttp://bitcoinbotreview.com/mailpv.exeÏÂÔØºóÐøÎļþ²¢¼ÓÔØÖ´ÐС£µ«ÊÇÔÚÎÒÃÇ·ÖÎöʱ£¬¸ÃÁ´½ÓÒѾ­Ê§Ð§£¬µ«Í¨Ò»Ð©ÌصãÎÒÃÇÕÒµ½Õâ¸öÁ´½ÓµÄԭʼÎļþ¡£¸ÃÎļþÊÇÒ»¿îÇÔÃÜÐ͵ÄľÂí£¬Æä¼Ù×°³ÉNirSoft¹«Ë¾¿ª·¢µÄÓÊÏäÃÜÂ븴ԭÈí¼þmailpv.exe£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚĿǰÃÅÂÞ±Ò¹Ù·½ÉÐδÓе÷²éÐÅÏ¢Åû¶£¬ËùÒÔÎÒÃÇÕâÀï½ö½ö×öÁËһЩ³õ²½×·×Ù£¬µ«ÈÔÄܹ»¿´³öÕâÊÇһ·ͨ¹ý¾«ÐÄ³ï±¸ÍøÂç¹¥»÷£¬´ÓºÚ¿Í¼±ÓÚ×¢²áÐÂÓòÃû²¢ÔÚ×¢²áºóµÄ2-3ÌìÄÚ¾ÍÆðÍ·½øÐй¥»÷µÄÇé¿öÀ´¿´£¬ºÚ¿ÍÓ¦¸ÃÊDz»¾Ãǰ·¢ÏÖÁËÃÅÂÞ±ÒÍøÕ¾µÄ·ì϶£¬´Ó¶ø×¨ÃŶ¨Ôì¶ñÒⷨʽÒÔÆÚ¿ÉÄÜʵʱ¶ÒÏÖ¡£


4.×ܽá


ͨ¹ý¸ÃÊÂÎñµÄ·ÖÎöÎÒÃÇÄܹ»¿´³ö£¬ºÚ¿Í²¢Ã»ÓÐÖ±½ÓÇÔÈ¡Êý¾ÝÁ¿½Ï´óµÄÃÅÂÞ±ÒÇ®°üÎļþ£¬È¡¶ø´úÖ®µÄÊÇÇÔÈ¡Óû§ÃÅÂÞ±ÒµÄseed£¬²¢Ê¹ÓÃSSLºÍ̸½øÐÐͨѶ£¬Ê¹µÃ¹¥»÷Ô½·¢ÒþÃØ¡£ÓÉÓÚÇÔÈ¡seed¶ÔÓû§ÕË»§µÄÓ°ÏìÓµÓÐÖͺóÐÔ£¬Òò¶ø£¬¹ÌȻĿǰ½öÓÐÉÙÊýÈ˻㱨Á˽ðÇ®ËðʧµÄ°¸Àý£¬µ«ÊDz»ÅųýºÚ¿ÍÒѾ­ÇÔÈ¡ÁËÏ൱ÊýÁ¿µÄÃÅÂÞ±Òseed£¬Ö»²»ÍâºÚ¿ÍĿǰ»¹Î´½øÐжÒÏÖ¡£

±¾´Î¹¥»÷ÊÂÎñÔٴδÍÓëÎÒÃǰ²È«¾¯Ê¾£¬Ä¿Ç°Ô½À´Ô½¶àµÄºÚ¿Íͨ¹ý¹©¸øÁ´¹¥»÷£¬ÀûÓÃÓû§¶Ô¹Ù·½µÄÐÅÀµ£¬ÉøÈë½øÌṩ¿ÉÐŹ¤¾ßµÄÍøÕ¾²¢´úÌæµôԭʼÎļþ£¬ÒÔ¿ÉÐŹÙÍø×÷Ϊ¶ñÒâ´úÂëµÄ´«²¼õè¾¶£¬Ìá¸ß¹¥»÷µÄ³É¹¦ÂÊ¡£Òò¶øÎÒÃÇÌáÐÑÓÐ¹ØÆóÒµÓû§£¬¼ÓÇ¿×ÔÉíµÄÍøÂ簲ȫ£¬¶¨ÆÚ½øÐÐÍøÕ¾µÄƽ²¿Êð²éºÍ¼Ó¹Ì£¬ÊµÊ±¸üÐÂϵͳµÄ°²È«²¹¶¡¡£


²Î¿¼Á´½Ó£º


1.https://github.com/monero-project/monero/issues/6151

2.https://www.reddit.com/user/moneromanz/

3.https://bartblaze.blogspot.com/2019/11/monero-project-compromised.html