¡°º£»Æ·ä¡±£ºÕë¶ÔÎÒ¹úÐÂÐ˿Ƽ¼ÆóÒµµÄÇÔÃܻÉî¶È·ÖÎö
°ä²¼¹¦·ò 2022-04-28Ò»¡¢¸ÅÊö
GA»Æ½ð¼×ADLabÔÚ½ü¼¸¸öÔÂÄÚ£¬°ÑÎȵ½¶àÆð½«·¢¼þÈ˼ÙװΪÎïÁ÷»õÔ˹«Ë¾µÄ¶¨ÏòÓʼþ´¹µö»î¶¯£¬¼Ù×°µÄ¶ÔÏóÔ̺¬¡°ÉîÛÚÊÐÔË**¼ÊÎïÁ÷ÓÐÏÞ¹«Ë¾¡±¡¢¡°ÉϺ£Ó¡**¼Ê»õÔË´úÀíÓÐÏÞ¹«Ë¾ÉîÛÚ·Ö¹«Ë¾¡±ºÍ¡°ÖÐ**ÔËÉ¢»õÔËÊäÓÐÏÞ¹«Ë¾¡±¡£Ä¿Ç°ÎÒÃǼà²âµ½µÄÊܹ¥»÷Ö¸±êÓÓ×±ÐìÖÝ**¹âµç¿Æ¼¼ÓÐÏÞ¹«Ë¾¡±£¨ÖØÒª´ÓʹâµçÆ÷¼þÑз¢£©ºÍ¡°»ª**ͨ¹É·ÝÓÐÏÞ¹«Ë¾¡±£¨ÖØÒª´ÓÊÂÖÇÄÜÆû³µÔì×÷£©£¬¿ÉÄÜ»¹Óиü¶àµÄDZÔÚ¹¥»÷Ö¸±êδ±»·¢ÏÖ£¬¹¥»÷ÕßËÆºõÆ«²îÓÚ¶ÔһЩÐÂÐ˿Ƽ¼ÐÐÒµÌáÒé¹¥»÷£¬ÖµµÃÓÐ¹ØÆóÒµÌá¸ß¾¯Ì裬¼ÓÇ¿·À±¸´ëÊ©¡£Í¨¹ýËÝÔ´ÎÒÃDz¢Ã»Óз¢ÏÖÈκÎÓë±¾´Î¹¥»÷ÓйصÄÏÖÓй¥»÷×éÖ¯£¬¸Ã×éÖ¯ÔÚÇÔÃÜľÂíÖÐÄÚǶµÄÓÃÓÚÇÔÃÜÐÅÏ¢»Ø´«µÄ·¢ËÍÕßÓÊÏäºÍ½Ó¹ÜÕßÓÊÏä¾ùÀ´×ÔÒÁÀÊ£¬ÕâÔڿ϶¨Ë®Æ½ÈÃÎÒÃÇÎóÒÔΪ¹¥»÷ÕßÀ´×ÔÒÁÀÊ£¬µ«ÊÇͨ¹ý¸ü½øÒ»²½·ÖÎö·¢ÏÖ£¬ÕâЩÓÊÏä¾ùÊǺڿÍ×éÖ¯ÇÔÈ¡µÄÓÊÏ䣬ÆäÖл¹Ô̺¬´óÁ¿µÄƾ֤¡£
ÓÉÓÚ¸Ã×éÖ¯³ö¸ñÉÆÓÚ¼Ù×°£¬ÓÈÆäϲ»¶Ê¹ÓÃÒÑÇÔÈ¡µÄÓʼþƾ֤À´¹¥»÷Ö¸±ê£¬ÎÞÂÛÊǶñÒâÓʼþ¹¥»÷£¬»¹ÊÇÓÃÓڻش«Êý¾ÝµÄSMTPÐÅ·£¬¶¼¼«ÄÑËÝÔ´ºÍ×·×ÙºÚ¿Í£¬Òò¶øÎÒÃǽ«¸Ã×éÖ¯¶¨ÃûΪ¡°º£»Æ·ä¡±£¬¸Ã×éÖ¯¾ÍÏñ¡°º£»Æ·ä¡±Ò»ÑùÒþÃØ¶ø²»Ò×±»·¢ÏÖÈ´ÄܸøÈËÖÂÃüÒ»»÷¡£¡°º£»Æ·ä¡±×éÖ¯±ÈÁ¦Æ«²îÓÚÏȹ¥ÏÂһЩº£ÔËÀ๫˾²¢ÇÔÈ¡ÕâЩ¹«Ë¾ÓÊÏ䯾֤£¬¶øºóÒÔÕâЩ¹«Ë¾µÄÃûÒå¶ÔÆäÕæÊµµÄÖ¸±êÌáÒé¹¥»÷£¬¹¥»÷µÄ¶ÔÏóÒÔÐÂÐ˵ĿƼ¼ÆóҵΪÖ÷£¬µ±Ç°Äܹ»È·¶¨µÄÊܺ¦¹ú¶ÈÓÐÖйú¡¢ÒÁÀÊ¡¢º«¹úºÍ°¢ÁªÇõ¡£
¹ÌȻĿǰËù·¢ÏֵĹ¥»÷²¢²»ÆµÈÔ£¬µ«ÊÇ´Ó¡°º£»Æ·ä¡±µÄ¹¥»÷Ö÷ÕÅÀ´¿´£¬³ýÁËÎÒÃÇËù·¢ÏÖÓʼþ¹¥»÷±í£¬»¹¿ÉÄܰµº¬Óиü¶àÖ±½Ó¹¥»÷ºÃ±Èͨ¹ýVPNƾ֤¡¢Ô¶³ÌÖÎÀíÈí¼þƾ֤½øÈëÆóÒµÄÚ²¿Ëù²úÉúµÄδ֪DZÔڵĹ¥»÷Íþв£¬ÕâЩƾ֤×îΣÏյĴ¦µØµãÓÚºÚ¿Í¿ÉÄܵÈÏеØÖ´Ðй©¸øÁ´¹¥»÷£¬ÕýÈç2020Äê²úÉúµÄ¡°Ì«Ñô·ç¹©¸øÁ´¹¥»÷ÊÂÎñ¡±ÄÇÑù£¬ºÚ¿Íͨ¹ýƾ֤½øÈëÁËÌ«Ñô·ç¹«Ë¾ÄÚ²¿´Û¸ÄÔ¶³ÌÖÎÀíÈí¼þµÄÔ´´úÂ룬´Ó¶øµ¼ÖÂÏÂÓÎʹÓøÃÈí¼þµÄ´óÁ¿ÆóÒµÊܺ¦¡£
¶þ¡¢¹¥»÷µÄÖ¸±êÆóÒµ
±¾´Î·¢Ïֵġ°º£»Æ·ä¡±¹¥»÷ÖУ¬¹¥»÷Õß¼Ù×°³É ¡°ÉîÛÚÊÐÔË**¼ÊÎïÁ÷ÓÐÏÞ¹«Ë¾¡±Ä³Ô±¹¤µÄÓÊÏä¡°f***@wi***logistics.com¡±Ïò¡°ÐìÖÝ**¹âµç¿Æ¼¼ÓÐÏÞ¹«Ë¾¡±µÄ4ÃûÔ±¹¤·¢ËÍÁËÄÚÈÝÒ»ÑùµÄ´¹µöÓʼþ£¨Í¼1½öÁгöÊÕ¼þ±¨´ð¡°ja***@l**t.com¡±µÄ´¹µöÓʼþ£©¡£´¹µöÓʼþÈçͼ1Ëùʾ£¬ÓʼþÖ÷ÌâΪ¡°(SOA) OVERDUE FOR DEC. 2021¡±£¨SOAÓÚ2021Äê12Ôµ½ÆÚ£©£¬ÓʼþÕýÎÄΪ¡°Please check theattached statement for DEC. 2021¡±£¨Çë²é¿´2021Äê12Ôµĸ½¼þ£©¡£¸½¼þÊÇÃû³ÆÎª¡°updatedsoa.rar¡±µÄѹËõÎļþ£¬Æä½âѹºóÊÇÃû³ÆÎª¡°updated soa.exe¡±µÄ¶ñÒâ¿ÉÖ´Ðз¨Ê½¡£

ͼ1 ´¹µöÓʼþ
½öÒ»Öܺ󣬸ù¥»÷ÕßÓÖ¼Ù×°³É¡°ÉϺ£Ó¡**¼Ê»õÔË´úÀíÓÐÏÞ¹«Ë¾ÉîÛÚ·Ö¹«Ë¾¡±Ä³Ô±¹¤µÄÓÊÏä¡°***.wu@j***peed.com¡±Ïò¸Ã¹«Ë¾µÄͬÑù4ÃûÔ±¹¤·¢ËÍÁËÁíÒ»·âÄÚÈÝÒ»ÑùµÄ´¹µöÓʼþ£¨Í¼2½öÁгöÊÕ¼þ±¨´ð¡°ja***@l**t.com¡±µÄ´¹µöÓʼþ£©¡£´¹µöÓʼþÈçͼ2Ëùʾ£¬ÓʼþÖ÷ÌâΪ¡°URGENT REQUEST¡±£¨´¹Î£ÒªÇ󣩣¬ÓʼþÕýÎÄ´óÒâΪ¡°ÇëÆ¾¾ÝÓʼþ¸½¼þ¸üУ¬Ê£ÏµÄÎĵµÎһᾡ¿ì·¢ËÍ¡±£¬¸½¼þÊÇÃû³ÆÎª¡°Invoice.exe.xz¡±µÄѹËõÎļþ£¬Æä½âѹºóÊÇÃû³ÆÎª¡°Invoice.exe¡±¡¢Í¼±ê¼Ù×°³ÉXMLÎĵµµÄ¶ñÒâ¿ÉÖ´Ðз¨Ê½¡£

ͼ2 ´¹µöÓʼþ
ÎÒÃDz¶»ñµ½µÄÁí±íÒ»´Î¹¥»÷ÖУ¬¹¥»÷Õß¼Ù×°³É¡°ÖÐ**ÔËÉ¢»õÔËÊäÓÐÏÞ¹«Ë¾¡±Ä³Ô±¹¤µÄÓÊÏä¡°yuan-***@chi***ulker.com¡±Ïò¡°»ª**ͨ¡±¹«Ë¾µÄÔ±¹¤¡°***_gao@hum****orizons.com¡±·¢ËÍ´¹µöÓʼþ£¬¼ûͼ3¡£ÓʼþÖ÷ÌâΪ¡°TT Transmitted Copy¡±£¬ÓʼþÕýÎÄ´óÒâΪ¡°Çë²é¿´¸½¼þÖÐ120,000.00ÃÀÔªµÄ¸¶¿îƾ֤²¢È·ÈÏÎÞÎ󡱡£¸½¼þÊÇÃû³ÆÎª¡°SWIFT COPY.rar¡±µÄѹËõÎļþ£¬Æä½âѹºóÊÇÃû³ÆÎª¡°SWIFT COPY.exe¡±¡¢Í¼±ê¼Ù×°³ÉWordÎĵµµÄ¶ñÒâ¿ÉÖ´Ðз¨Ê½£¬¹¥»÷Õß̰ͼ¼Ù×°³É¡°SWIFT¡±£¨È«ÇòÒøÐнðÈÚµçÐÅлᣩµÄ¸¶¿îÍ´´¦ÓÕʹÊܺ¦Õßµã»÷¡£

ͼ3 ´¹µöÓʼþ
ÒÔÉϹ¥»÷ÖУ¬¹¥»÷ÕßͶµÝµÄ¶ñÒâ¿ÉÖ´Ðз¨Ê½Ö´Ðкó¾ù»áÏòϰȾÉ豸¿ªÊÍ¡°Agent Tesla¡±Ä¾Âí£¬ÒÔÇÔÈ¡¹¥»÷Ö¸±êÖ÷»úµÄ¡°FTPÕË»§Æ¾Ö¤¡±¡¢¡°ÓÊÏäÕË»§Æ¾Ö¤¡±¡¢VPNÕË»§Æ¾Ö¤¡±¡¢¡°Ô¶³ÌÖÎÀíÈí¼þƾ֤¡±ÒÔ¼°¡°ä¯ÀÀÆ÷Öд洢µÄÕË»§Æ¾Ö¤¡±µÈ¸÷ÀàÕË»§Æ¾Ö¤ÐÅÏ¢¡£
Èý¡¢ËÝÔ´Óë¹ØÁª·ÖÎö
ÎÒÃǼà²âµ½µÄÒÔ¹¥»÷¡°ÐìÖÝ**¹âµç¿Æ¼¼ÓÐÏÞ¹«Ë¾¡±ÎªÖ¸±êµÄ¹¥»÷ÓʼþÓÐ8·â£¨¼û±í1£©¡£ºÚ¿Íǰºó¶Ô¸Ã¹«Ë¾ÌáÒéÁËÁ½ÂÖ¹¥»÷£¬²¢ÇÒÕâÁ½ÂÖ¹¥»÷ËùÑ¡¶¨µÄÖ¸±êºÍʹÓõÄÇÔÃÜľÂí¶¼ÊÇÒ»ÑùµÄ¡£µÚÒ»ÂÖ¹¥»÷²úÉúÓÚ1ÔÂ6ÈÕ£¬¹¥»÷Õß¼Ù×°³É¡°ÉîÛÚÊÐÔË**¼ÊÎïÁ÷ÓÐÏÞ¹«Ë¾¡±µÄÔ±¹¤ÏòÖ¸±ê·¢ËÍ´¹µöÓʼþ£»µÚ¶þÂÖ¹¥»÷²úÉúÓÚ1ÔÂ13ÈÕ£¬¹¥»÷ÕßÕâ´Î¼Ù×°³É¡°ÉϺ£Ó¡**¼Ê»õÔË´úÀíÓÐÏÞ¹«Ë¾ÉîÛÚ·Ö¹«Ë¾¡±Ô±¹¤ÔÙ´ÎÏòÖ¸±êͶµÝ´¹µöÓʼþ¡£Á½´Î¹¥»÷»î¶¯µÄTTPs¸ß¶ÈÀàËÆ£¬¹¥»÷Ö¸±ê¾ùΪ¸Ã¹«Ë¾µÄ4ÃûÄÚ²¿ÈËÔ±£¬²¢Ê¹ÓÃÁËͬÑùµÄÇÔÃÜľÂíAgent TeslaÒÔ¼°Í¬Ñù»Ø´«ÓÊÏä¡°donya@fortunaship.com¡±¡£

±í1 ¹ØÁªµÄ´¹µöÓʼþÐÅÏ¢
ͨ¹ý¶ÔÓʼþЯ´øµÄ¶ñÒâÔØºÉ¡°Agent Tesla¡±Ä¾ÂíµÄ·ÖÎö·¢ÏÖ£¬ºÚ¿Íͨ¹ýľÂí»á½«ÇÔÈ¡µ½µÄƾ֤ÐÅÏ¢»Ø´«¸øºÚ¿Í½ÚÔìµÄÓÊÏä¡£ºÚ¿ÍÔÚľÂíÖÐÄÚÖÃÁËÓÃÓڻش«ÇÔÃÜÊý¾ÝµÄ·¢ËÍÕßÓÊÏä¡°info@jindalpackaging.in¡±¡¢¡°nowzathali@ratllc.ae¡±ºÍ½Ó¹ÜÇÔÃÜÊý¾ÝµÄ½Ó¹ÜÕßÓÊÏä¡°donya@fortunaship.com¡±¡£ÎÒÃÇͨ¹ýÓÃÓڻش«ÇÔÃÜÊý¾ÝµÄ·¢ËÍÕßÓÊÏä¡°info@jindalpackaging.in¡±¹ØÁª³öÁíÒ»¸öÊôÓÚ¸Ã×éÖ¯µÄTeslaľÂí£¬²¢½øÒ»²½¶Ô¸ÃľÂí½øÐлØËÝ·ÖÎö£¬¹ØÁª³öÁí±íÒ»·âÕë¶ÔÎÒ¹úÖÇÄÜÆû³µÔì×÷Óйع«Ë¾¡°»ª**ͨ¡±ÄÚ²¿ÈËÔ±µÄ´¹µöÓʼþ£¨¼û±í2£©¡£

±í2 ¹ØÁªµÄ´¹µöÓʼþÐÅÏ¢
¡°info@jindalpackaging.in¡±Í¬Ñù¹ØÁªµ½ÁË2020Äê7Ô¹¥»÷Ö¸±êΪº«¹ú¹«Ë¾µÄ¶àÆð¹¥»÷£¨https://asec.ahnlab.com/en/17550£¬How AgentTesla Malware is Being Distributed in Korea£©¡£ÓÉ´ËÄܹ»¿´³ö¸Ã×éÖ¯ÖÁÉÙ´Ó2020Äê¾ÍÆðÍ·ÀûÓô¹µöÓʼþºÍ¡°AgentTesla¡±Ä¾Âí½øÐÐÍøÂç¹¥»÷¡£Áí±í£¬ÎÒÃÇ·¢ÏÖ ¡°info@jindalpackaging.in¡±ÒÉËÆºÍÓÊÏä¡°jindal23396@yahoo.com¡±ÎªÍ³Ò»Ó×ÎÒ³ÖÓеÄÁ½¸ö·ÖÆçÓÊÏ䣬¶ø´Ó¡°jindal23396@yahoo.com¡±¹ØÁª³öµÄÐÅÏ¢£¨¼ûͼ4£©À´¿´£¬Äܹ»È·ÈϸÃÓÊÏäµÄ³ÖÓÐÕß¹©Ö°ÓÚ¡°Jindal Packaging¡±¹«Ë¾£¬²¢ÇÒλÓÚÒÁÀÊ£¨98ÆðÍ·µÄµç»°£©¡£

ͼ4 ÓÊÏäºÍÒÁÀÊÓйØ
ͬʱ£¬ÎÒÃÇ·¢ÏÖÓÃÓÚ½Ó¹ÜÇÔÃÜÊý¾ÝµÄ½Ó¹ÜÕßÓÊÏä ¡°donya@fortunaship.com¡±ÒÉËÆÊÇÒÁÀʺ£ÔË´úÀí¹«Ë¾¡°Voice of Port's Mariner ShippingAgency¡±£¨http://vopmco.com/Aboutper.html£©Ò»Ö°Î»Îª²ÆÕþµÄÔ±¹¤ÓÊÏ䣨¼ûÏÂͼ5£©¡£½áºÏǰÎÄľÂíÓÃÓڻش«ÇÔÃÜÊý¾ÝµÄ·¢ËÍÕßÓÊÏä¡°info@jindalpackaging.in¡±µÄÕý³£³ÖÓÐÕßҲͬÑùΪÒÁÀʹ«Ë¾µÄÔ±¹¤£¬Äܹ»¿´³ö¹¥»÷ÕßËÆºõÇÔÈ¡ÁË´óÁ¿ÒÁÀÊÈËÔ±µÄÕý³£ÓÊÏ䣬ÓÉ´ËÄܹ»¿´³ö£¬¹¥»÷ÕßÔÚÔçǰ¹¥»÷¹ýÒÁÀÊÓйع«Ë¾¡£

ͼ5 ¹ØÁªµ½µÄÒÁÀÊijº£Ô˹«Ë¾Ô±¹¤
ÎÒÃÇÆ¾¾ÝÕâ´Î¹¥»÷ÖиúڿÍ×éÖ¯ÔÚľÂíÖÐÄÚÖõÄÓÃÓڻش«ÇÔÃÜÊý¾ÝµÄ·¢ËÍÕßÓÊÏä¡°info@jindalpackaging.in¡±¹ØÁªµ½¸Ã×éÖ¯2020Äê7Ô¹¥»÷Ö¸±êΪº«¹ú»¥ÁªÍø¹«Ë¾¡°NAVER¡±µÄ¶àÆð¹¥»÷£¬ÕâÆð¹¥»÷ÖУ¬ÓÃÓÚ·¢ËͺͽӹÜÇÔÃÜÊý¾ÝµÄÓÊÏäͬÑùÊôÓÚÒÁÀʵÄÁ½¼Òº£Ô˹«Ë¾£¬ÕâÁ½·âÓÊÏä±ðÀëΪ¡°info@jindalpackaging.in¡±ºÍ¡°donya@fortunaship.com¡±£¬ÓÐ¹ØµÄÆóÒµ±ðÀëΪ±ðÀëΪ¡°Jindal Packaging¡±¡¢¡°Voice of Port's MarinerShipping Agency¡±¡£¶øÍ¨¹ý½øÒ»²½·ÖÎö·¢ÏÖ£¬¡°º£»Æ·ä¡±×éÖ¯ÔçÔÚ2020ËêÊ×¶ÔÒÁÀʵÄÕâÁ½¼Ò¹«Ë¾½øÐÐÁ˹¥»÷²¢³É¹¦»ñµÃÓйØÈËÔ±µÄµÇ¼ƾ֤¡£´ÓºÚ¿Í×éÖ¯µÄÖ¸±êÎÒÃÇÄܹ»¿´³ö£¬¹¥»÷ÀàËÆº£Ô˹«Ë¾²¢»ñµÃƾ֤²¢²»ÊǸÃ×éÖ¯µÄÕæÊµÖ÷ÕÅ£¬ÆäÕæÊµÖ÷ÕÅÖ»ÊÇÏëÀûÓÃÕâЩº£Ô˹«Ë¾À´´òÑÚ»¤£¬ÒÔ¸ü¸ßµÄ³É¹¦ÂʸüÒþÃØµÄ·½Ê½À´¹¥»÷һЩ¸ß¿Æ¼¼ÆóÒµ¡£
ËÄ¡¢¹¥»÷Ñù±¾·ÖÎö
Èçͼ6Ëùʾ£¬¶ñÒâÓʼþ¸½¼þÊÇÃû³ÆÎª¡°updated soa.rar¡±µÄѹËõ°ü£¬Æä½âѹºóÊÇÃû³ÆÎª¡°updated soa.exe¡±¡¢Í¼±ê¼Ù×°³É¡°soa¡±¸üз¨Ê½Í¼±êµÄ¶ñÒâ¿ÉÖ´Ðз¨Ê½¡£¡°updated soa.exe¡±ÏÖʵÉÏÊÇ×Ô¶¯»¯¹¤¾ß¡°Agent Tesla¡±´ò°üµÄľÂí£¬ÆäÔËÐкó·ÖËĸö½×¶ÎÖ´ÐУº¡°updated soa.exe¡±ÊǾ¹ý´óÁ¿»ìºÏµÄĸÌå±í¿Ç·¨Ê½£¬ÆäÖ´Ðкó»áÔÚÄÚ´æÖнâÃܲ¢²»Â䵨ִÐеڶþ½×¶ÎÄ£¿é¡°Bunifu.UI.dll¡±£»¡°Bunifu.UI.dll¡±Ö´Ðкó»á´ÓĸÌå¡°updated soa.exe¡±µÄ×ÊÔ´¶Î¶ÁÈ¡Ãû³ÆÎª¡°qdjSmj¡±µÄ×ÊÔ´Îļþ½øÐнâÃÜ£¬²¢ÔÚÄÚ´æÖв»Â䵨ִÐеÚÈý½×¶ÎÄ£¿é¡°js¹ËRFH¹Ë diQC¡±£¨exe¿ÉÖ´Ðз¨Ê½£©£»¡°js¹ËRFH¹Ë diQC¡±Ä£¿éÒ»·½ÃæÕƹÜĸÌ巨ʽ¡°updated soa.exe¡±µÄÓÆ¾Ã»¯£¬ÁíÒ»·½Ãæ½âÃÜ¡¢×¢Èë²¢Ö´ÐÐ×îºó½×¶ÎÄ£¿é¡°AgentTesla¡±Ö÷ÌâľÂí¡£¡°Agent Tesla¡±Ö÷ÌâľÂíÖ´Ðкó»áÇÔȡϰȾÉ豸¡°FTPÕË»§Æ¾Ö¤¡±¡¢¡°ÓÊÏäÕË»§Æ¾Ö¤¡±¡¢¡°VPNÕË»§Æ¾Ö¤¡±¡¢¡°Ô¶³ÌÖÎÀíÈí¼þƾ֤¡±ÒÔ¼°¡°ä¯ÀÀÆ÷Öд洢µÄÕË»§Æ¾Ö¤¡±µÈ¸÷ÀàÕË»§Æ¾Ö¤ÐÅÏ¢ºó£¬ÒÔÓʼþµÄ´ó¾Ö½«ÕâЩÐÅÏ¢»Ø´«µ½¹¥»÷Õß½ÚÔìµÄÓÊÏä¡£

ͼ6 ¹¥»÷Á÷³Ìͼ
4.1 µÚÒ»½×¶ÎÄ£¿é
ĸÌå¡°updated soa.exe¡±ÖØÒªÓÃÓÚ½âÃܲ¢ÔÚÄÚ´æÖмÓÔØÏÂÒ»½×¶ÎµÄÖ°ÄÜÄ£¿é¡°Bunifu.UI.dll¡±£¬¡°updated soa.exe¡±½«×ÔÉí¼Ù×°³É¡°soa¡±µÄ¸üз¨Ê½£¬ÒԹƻ󹥻÷Ö¸±êÖ´ÐС£¡°updated soa.exe¡±Ê¹ÓÃ×Ô½ç˵µÄº¯Êý½«ÃÜÎĽâÃܺÍ×Ö·û´®´úÌæºó£¬µÃµ½Ò»´®base64±àÂëµÄ×Ö·û´®£¬¶øºóŲÓÃFromBase64CharArrayº¯Êý½âÂë¸Ã×Ö·û´®£¨¼ûͼ7£©¡£½âÂëµÃµ½Ãû³ÆÎª¡°Bunifu.UI.dll¡±µÄDllÎļþ£¨¼ûͼ8£©²¢ÔÚÄÚ´æÖв»Â䵨ִÐС£

ͼ7 Base64½âÂë×Ö·û´®ºó£¬ÄÚ´æ¼ÓÔØÖ´ÐÐ

ͼ8 Base64½âÂëºóµÄ¡°Bunifu.UI.dll¡±Îļþ
4.2 µÚ¶þ½×¶ÎÄ£¿é
¸Ã½×¶ÎµÄÄ£¿éÃû³ÆÎª¡°Bunifu.UI.dll¡±£¬ÆäÖ´Ðкó»á´ÓĸÌå¡°updated soa.exe¡±µÄ×ÊÔ´¶Î¶ÁÈ¡Ãû³ÆÎª¡°qdjSmj¡±µÄ×ÊÔ´Îļþ£¨Èçͼ9Ëùʾ£©½øÐнâÃÜ£¬½âÃܺóÊÇÃû³ÆÎª¡°js¹ËRFH¹Ë diQC¡±µÄexe¿ÉÖ´Ðз¨Ê½¡£

ͼ9 ¡°updated soa.exe¡±ÖÐÃû³ÆÎª¡°qdjSmj¡±µÄ×ÊÔ´Îļþ
¡°Bunifu.UI.dll¡±µÄº¯Êý¡°Bunifu_TextBox¡±ÕƹܽâÃÜ¡°qdjSmj¡±×ÊÔ´Îļþ£¨Èçͼ10Ëùʾ£©£¬¸Ãº¯ÊýÊ×ÏȱéÀúͼ9×ÊÔ´ÎļþÖеÄÿ¸öÏñËØµã£¬¶Ôÿ¸öÏñËØµãµÄRGBÊý¾Ý˳´Î·ÖÁУ¬¶øºóʹÓÃ×Ô½ç˵µÄÒì»òËã·¨¶ÔÕâЩÏñËØÊý¾Ý½øÐнâÃÜ¡£

¡°Bunifu.UI.dll¡±½âÃܵõ½ÃûΪ¡°js¹ËRFH¹Ë diQC¡±µÄ exe¿ÉÖ´Ðз¨Ê½ºó¼Ì¶øÔÚÄÚ´æÖв»Â䵨¼ÓÔØÖ´Ðи÷¨Ê½¡£Í¼11ΪBunifu.UI.dll½âÃÜĸÌå¡°updated soa.exe¡± ÖÐ×ÊÔ´Îļþ¡°qdjSmj¡±µÃµ½µÄ¡°js¹ËRFH¹Ë diQC¡±¿ÉÖ´Ðз¨Ê½¡£

ͼ11 ½âÃÜ×ÊÔ´ÎļþΪ¿ÉÖ´Ðз¨Ê½
4.3 µÚÈý½×¶ÎÄ£¿é
¡°js¹ËRFH¹Ë diQC¡±Ä£¿é¾¹ýÁË´óÁ¿»ìºÏ£¨Èçͼ12Ëùʾ£©¡£ÎÒÃÇ·ÖÎöºó·¢ÏÖ¸ÃÄ£¿éÖØÒªÓÐÁ½¸öÖ°ÄÜ£ºÒ»ÊÇ´´½¨´òË㹤×÷ʵÏÖĸÌå¡°updated soa.exe¡±µÄÓÆ¾Ã»¯£¬¶þÊǽâÃܲ¢Ö´ÐÐ×îºó½×¶ÎµÄ¡°AgentTesla¡±Ö÷ÌâľÂí¡£

ͼ12 ¾¹ý»ìºÏµÄ¡°js¹ËRFH¹Ë diQC¡±
4.3.1 ÓÆ¾Ã»¯
¸ÃÄ£¿éÊ×ÏÈ»áʹÓÃWriteAllBytesº¯Êý½«Ä¸Ìå¡°updated soa.exe¡±µÄ¸±±¾Ð´Èë¡°C:\Users\username\AppData\Roaming\¡±Ä¿Â¼£¬²¢³Á¶¨ÃûΪ¡°KcSOZJHG.exe¡±£¬¼ûͼ13ºÍͼ14¡£

ͼ13 дÈëµÚÒ»½×¶ÎÄ£¿é¸±±¾

ͼ14 дÈëµÄµÚÒ»½×¶ÎÄ£¿é¸±±¾
¶øºó¸ÃÄ£¿é»á¶ÁȡϰȾÉ豸Ö÷»úÃû¡¢Óû§ÃûµÈÐÅÏ¢£¬Ê¹Óá°WriteAllText¡±º¯ÊýÏòϰȾÉ豸µÄ¡°%tmp%¡±Ä¿Â¼Ð´Èë¡°.tmp¡±ºó׺µÄXMLÎļþ£¨¼ûͼ15£©¡£

XMLÎļþµÄÄÚÈݼûͼ16£º

ͼ16 XMLÎļþÄÚÈÝ
½ÓןÃÄ£¿éÖ´ÐÐ"schtasks.exe" /Create /TN \"Updates\\KcSOZJHG\"/XML \"C:\\Users\\ThinkPad\\AppData\\Local\\Temp\\tmp32C4.tmp\"ºÅÁî´´½¨´òË㹤×÷£¨¼ûͼ17£©£¬ÊµÏÖÓÆ¾Ã»¯£¬ÒÔ´ïµ½¶ñÒⷨʽ¿ª»úÆô¶¯µÄÖ÷ÕÅ¡£

ͼ17 ´´½¨´òË㹤×÷£¬ÊµÏÖ¿ª»úÆô¶¯
Ö®ºó¸ÃÄ£¿é»áɾ³ýxmlһʱÎļþ£¨¼ûͼ18£©¡£

ͼ18 ɾ³ýxmlһʱÎļþ
ÎÒÃÇʹÓúÅÁîÐв鿴¸ÃÄ£¿é´´½¨µÄ´òË㹤×÷£¨¼ûͼ19£©£¬Äܹ»¿´µ½¸ÃÄ£¿é´´½¨ÁËÃû³ÆÎª¡°\Updates\KcSOZJHG¡±µÄ´òË㹤×÷£¬ÔÚϵͳÿ´ÎÆô¶¯ºóÔËÐжñÒⷨʽ¡°C:\Users\username\AppData\Roaming\KcSOZJHG.exe¡±¡£

ͼ19 ¶ñÒâ´úÂë´´½¨µÄ´òË㹤×÷
4.3.2 ½âÃܲ¢×¢Èë¡°Agent Tesla¡±Ö÷ÌâľÂí
ʵÏÖÓÆ¾Ã»¯²Ù×÷ºó£¬¸ÃÄ£¿é»áÔÚÄÚ´æÖнâÃܳö×îºó½×¶ÎµÄÄ£¿é-¡°Agent Tesla¡±Ö÷ÌâľÂí£¬¶øºóÆô¶¯¡°RegSvcs.exe¡±¹ý³Ì£¬Ê¹Óùý³Ìïοյķ½Ê½½«¡°Agent Tesla¡±Ö÷ÌâľÂí×¢Èëµ½¡°RegSvcs.exe¡±¹ý³ÌÖÐÖ´ÐС£RegAsm.exe ÊÇ Microsoft .Net Framework µÄ¹Ù·½×é¼þ£¬¹¥»÷Õß½«AgentTesla¡±Ö÷ÌâľÂí×¢ÈëÆäÖÐÒÔ¶ã±Ü°²È«¼ì²â¡£Í¼20ΪÄÚ´æÖнâÃܵġ°Agent Tesla¡±Ö÷ÌâľÂíÊý¾Ý¡£

ͼ20 ÄÚ´æÖнâÃܵġ°Agent Tesla¡±Ä¾ÂíÊý¾Ý
ÔÚ¹ý³Ì×¢È뷽ʽÉÏ£¬¸ÃÄ£¿éŲÓÃÁ˳£¼ûµÄ¹ý³Ì×¢ÈëAPI½øÐÐ×¢Èë²Ù×÷£ºÊ¹Óà CreateProcess() ´´½¨¹ÒÆðµÄ¡°RegSvcs.exe¡±¹ý³Ì£¬Í¨¹ý VirtualAllocEx()¡¢NtUnmapViewOfSection()¡¢ReadProcessMemory()¡¢WriteProcessMemory() ½«¡°Agent Tesla¡±Ä¾Âí×¢Èë¹ÒÆðµÄ¡°RegSvcs.exe¡±¹ý³ÌзÖÅäµÄÄÚ´æÖУ¬½Ó×ÅʹÓÃSetThreadContext()/Wow64SetThreadContext()¡¢GetThreadContext()/Wow64GetThreadContext() Åú¸Äexe µÄ×¢²á±í²¢Åú¸Ä EIP Ö¸ÕëÖ¸ÏòAgent TeslaÖ÷ÌâľÂí£¬×îºóŲÓà ResumeThread() ¸´ÔÖ´ÐÓ×°RegSvcs.exe¡±¹ý³Ì¡£Í¼21ÊǸÃÄ£¿é²¿ÃÅAPIµÄ½ØÍ¼¡£

ͼ21 ¹ý³Ì×¢ÈëÓõ½µÄ²¿ÃÅAPI
4.4 ×îºó½×¶ÎÄ£¿é
¡°Agent Tesla¡±Ö÷ÌâľÂíÖ´Ðкó£¬ÏȽ«×ÔÉí¿½±´µ½¡°C:\Users\ThinkPad\AppData\Roaming\tKZVPq¡±Ä¿Â¼£¬²¢³Á¶¨ÃûΪtKZVPq.exe£¬¶øºóͨ¹ýÉèÖÃ×¢²á±í¡°HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run¡±ÊµÏÖ¿ª»ú×ÔÆô¶¯£¨¼ûͼ22£©£¬ÊµÏÖÓÆ¾Ã»¯¡£

ͼ22 ÉèÖÿª»ú×ÔÆô¶¯
4.4.1 ÇÔÊØÐÅÏ¢
ͼ23ÊÇ¡°Agent Tesla¡±Ö÷ÌâľÂíÇÔÈ¡ÕË»§Æ¾Ö¤Éæ¼°µ½µÄ²¿ÃÅä¯ÀÀÆ÷½ØÍ¼¡£

ͼ23ÇÔÈ¡ÕË»§Æ¾Ö¤µÄ²¿ÃÅä¯ÀÀÆ÷½ØÍ¼
ÎÒÃǽ«ÕâЩä¯ÀÀÆ÷Õû¶Ùµ½±í3ÖС£´Ó±í3ÖÐÎÒÃÇÄܹ»¿´µ½£¬¡°AgentTesla¡±Ö÷ÌâľÂí³¢ÊÔÇÔÈ¡Ô̺¬Chrome¡¢Edge¡¢Safari¡¢FirefoxµÈÖ÷Á÷ä¯ÀÀÆ÷¡¢ºÍ¹úÄÚQQä¯ÀÀÆ÷¡¢360ä¯ÀÀÆ÷¡¢UCä¯ÀÀÆ÷¡¢ÁÔ±ªä¯ÀÀÆ÷ÒÔ¼°ÆäËû¶à¸öä¯ÀÀÆ÷ÖÐËù±£ÁôµÄÕË»§Æ¾Ö¤ºÍCookie¡£

±í3 ÇÔÈ¡ÕË»§Æ¾Ö¤µÄËùÓÐä¯ÀÀÆ÷
ÎÒÃǽ«Ä¾ÂíÇÔÈ¡ÕË»§Æ¾Ö¤Éæ¼°µ½µÄFTPÀûÓá¢ÓÊÏäÀûÓá¢VPNÀûÓá¢Ô¶³ÌÖÎÀíµ±ÓÃÒÔ¼°Ò»Ð©ÆäËûÀûÓñðÀëÁе½ÒÔϼ¸¸ö±í¸ñÖС£

±í4 ľÂíÇÔÈ¡ÕË»§ÐÅÏ¢µÄFTPÀûÓÃ

±í5 ľÂíÇÔÈ¡ÕË»§ÐÅÏ¢µÄÓʼþÀûÓÃ

±í6 ľÂíÇÔÈ¡ÕË»§ÐÅÏ¢µÄVPNºÍÔ¶³ÌÖÎÀíµ±ÓÃ

±í7 ľÂíÇÔÈ¡ÕË»§ÐÅÏ¢µÄÆäËûÀûÓÃ
4.4.2 »Ø´«ÇÔÃÜÐÅÏ¢
ͼ24ÏÔʾµÄÊÇ¡°Agent Tesla¡±Ö÷ÌâľÂíÇÔÈ¡µ½µÄϰȾÖ÷»úOutlookÓÊÏäÀûÓñ£ÁôµÄÓÊÏäÕË»§ºÍÓÊÏäÃÜÂë¡£

ͼ24 ÇÔÈ¡µ½µÄOutlookÓÊÏäÕË»§ºÍÃÜÂë
ľÂíÇÔÈ¡µ½Ï°È¾Ö÷»úµÄÓйØÕË»§Æ¾Ö¤ÐÅÏ¢ºó£¬»áʹÓù¥»÷ÕßÊÂÏÈÇÔÈ¡µÄÓÊÏ佫ÕâЩÐÅÏ¢»Ø´«¸øÆä½ÚÔìµÄÁíÒ»ÓÊÏ䣨Èçͼ25Ëùʾ£©¡£

ͼ25 ÓÊÏä·¢ËÍÇÔÃÜÐÅÏ¢
´ÓÉÏͼÄܹ»¿´µ½£¬»Ø´«ÇÔÃÜÊý¾ÝµÄ·¢ËÍÕßÓÊÏäΪ¡°info@jindalpackaging.in¡±£¬½Ó¹ÜÇÔÃÜÊý¾ÝµÄ½Ó¹ÜÕßÓÊÏäΪ¡°donya@fortunaship.com¡±¡£ÓʼþÖ÷ÌâΪPW_Óû§Ãû/Ö÷»úÃû£¬ÓʼþÕýÎÄÔ̺¬¹¦·ò¡¢Ï°È¾É豸µÄÓû§Ãû¡¢Ö÷»úÃû¡¢²Ù×÷ϵͳÃû³Æ¡¢CPUÐÅÏ¢¡¢ÄÚ´æÐÅÏ¢¡¢ÒÔ¼°ÇÔÈ¡µ½µÄOutlookÓÊÏäÕË»§Ãû³ÆºÍÃÜÂ루Èçͼ26Ëùʾ£©¡£

ͼ26 ÓʼþÖ÷ÌâºÍÕýÎÄ
Îå¡¢×ܽá
ͨ¹ý¶ÈÎöÄܹ»¿´³ö£¬¡°º£»Æ·ä¡±×é֯Ŀǰ¿ÉÄܱ»·¢ÏֵĹ¥»÷¼¿Á©ÒÀÈ»ÒÔαÔìµÄÓÊÏäÕË»§¶ÔÖ¸±ê½øÐж¨Ïò¹¥»÷£¬ÒÔÏòÖ¸±êÉ豸Ͷ·Å¶ñÒâľÂí¡£ÔÚÇÖÈëÖ¸±êÉ豸ºó£¬¶ñÒâľÂíÔÙͨ¹ýÄÚ´æ½âÃܺͶà²ãǶÌ×¼ÓÔØ¡¢²»Â䵨ִÐÐÀ´¶ã±Ü°²È«²é³£¬×îÖÕÔÚÖ¸±êÉ豸Éϳ־ÃÂñ·ü¡£Õë¶Ô´ËÀ๥»÷£¬ÆóÒµ¸Ãµ±×öºÃÆóÒµÓÊÏäSPF·À»¤£¬ÒÔ×èÖ¹À´×ÔαÔìÓÊÏäµÄ¹¥»÷¡£Í¬Ê±ÎÒÃǽ¨ÒéÓû§²»ÒªÇáÒ×´ò¿ªºÍÏÂÔØÎ´ÖªÆðÔ´µÄÓʼþ¸½¼þ¡¢×öºÃÓʼþϵͳµÄ·À»¤±í£¬¼´¾ÍÊÇÊÕµ½µÄÓʼþÀ´×ÔÒÑÖªÆðÔ´»òÊìϤµÄºÏ×÷ͬ°é¹«Ë¾Ò²ÒªÉóÉ÷¶Ô´ý£¬É÷³Á´ò¿ªÆä¸½¼þÖеÄÎļþ£¬ÈçÓбØÒªÁªÏµ·¢ËÍÕß½øÐÐÈ·ÈÏ£¬Ìá¸ß°²È«·çÏÕÒâʶ£¬Ò»µ©·¢ÏÖϵͳ»ò·þÎñÆ÷³öÏÖÒì³£ÐÐΪ£¬Ó¦ÊµÊ±»ã±¨²¢ÇëרҵÈËÔ±½øÐÐÅŲ飬ÒÔ½â³ý°²È«Òþ»¼¡£´Ë±í£¬¡°º£»Æ·ä¡±×éÖ¯ÖØÒªÖ÷ÕÅÊÇÇÔÈ¡²¢ÍøÂç¹¥»÷Ö¸±êÉ豸Éϵġ°FTPÕË»§Æ¾Ö¤¡±¡¢¡°ÓÊÏäÕË»§Æ¾Ö¤¡±¡¢¡°VPNÕË»§Æ¾Ö¤¡±¡¢¡°Ô¶³ÌÖÎÀíÈí¼þƾ֤¡±ÒÔ¼°¡°ä¯ÀÀÆ÷Öд洢µÄÕË»§Æ¾Ö¤¡°µÈ¸÷ÀàÕË»§Æ¾Ö¤ÐÅÏ¢£¬¶øºóÀûÓÃÕâЩÐÅÏ¢×÷Ϊ¼Ù×°£¬½øÒ»²½¹¥»÷ÆäËûÖ¸±ê¡£¸üÈÃÈ˲»°²µÄÊÇ£¬ÕâЩÃô¸ÐÐÅÏ¢Äܹ»ÈÃºÚ¿ÍÆëÈ«½ÚÔìÆóÒµµÄÄÚ²¿ÏµÍ³£¬²¢ÇÒ¿ÉÄܵÈÏеØÖ´ÐÐÒñ±ÎÐÔ¸üÇ¿¡¢·çÏÕÐÔ¸ü¸ßµÄ¹©¸øÁ´¹¥»÷¡£Òò¶ø£¬ÎÒÃdzýÁ˶ÔÓʼþÌá¸ß¾¯ÌèºÍ·À»¤±í£¬»¹±ØÒª¼ÓÇ¿VPN¡¢Ô¶³ÌÖÎÀíÈí¼þµÈµÈÄÚ²¿Èí¼þµÄÒì³£ÐÐΪ¼à²â¡£


¾©¹«Íø°²±¸11010802024551ºÅ