¡°°×Ïó¡±APT×éÖ¯½üÆÚ¶¯Ì¬·ÖÎö»ã±¨

°ä²¼¹¦·ò 2018-03-31

¡°°×Ïó¡±±ðÃû¡°Patchwork¡±£¬¡°Ä¦Ú­²Ý¡±£¬ÒÉËÆÀ´×ÔÄÏÑÇij¹ú£¬×Ô2012ÄêÒÔÀ´³ÖÐøÕë¶ÔÖйú¡¢°Í»ù˹̹µÈ¹ú½øÐÐÍøÂç¹¥»÷£¬³Ö¾ÃÇÔȡָ±ê¹ú¶ÈµÄ¿ÆÑÓ×¢¾üÊÂ×ÊÁÏ¡£ÓëÆäËû×éÖ¯·ÖÆçµÄÊÇ£¬¸Ã×éÖ¯¼«¶ÈÉÆÓÚÆ¾¾Ý·ÖÆçµÄ¹¥»÷Ö¸±êαÔì·ÖÆç°æ±¾µÄÓйؾüÊ¡¢ÕþÖÎÐÅÏ¢£¬ÒÔ½øÐÐÏÂÒ»²½µÄ¹¥»÷ÉøÈë¡£

 

2017ÄêϰëÄêÒÔÀ´£¬ÎÒÃÇ·¢ÏÖÁ˶àÆðÓë°×Ïó×éÖ¯ÓйصÄ×îй¥»÷ÊÂÎñ¡£¸Ã×é֯ͨ¹ýÓã²æÊ½´¹µöÓʼþ£¬²¢¹²Í¬Éç»á¹¤³Ìѧ¼¿Á©ÔÚÓʼþÖз¢ËÍ´øÓÐÌåʽ·ì϶ÎĵµµÄÁ´½Ó£¬ÓÕµ¼Êܺ¦È˵ã»÷ÏÂÔØ²¢µã»÷£¬·ì϶´¥·¢³É¹¦ºó£¬»áÏÂÔØQuasar£¬BADNEWSµÈ±äÖÖÔ¶¿ØÄ¾Âí¡£


 ¹¥»÷ÊÂÎñ·ÖÎö

 

 ¹¥»÷ÊÂÎñA

 

µÚÒ»´Î¼¯Öй¥»÷ÊÂÎñ²úÉúÔÚ2017Äê11Ô·Ý×óÓÒ£¬ÎÒÃÇ¼à¿Øµ½¸Ã×éÖ¯ÌáÒéÁËÂÅ´ÎÓã²æÓʼþ¹¥»÷¡£Óйذ¸ÀýÈçÏ£º

 

1.ʹÓÃÓʼþͶ·ÅÃûΪChina_Strategic_ChainµÄdocxÎĵµ£¬²¢ÔÚÓʼþÖÐÎĵµÄÚÈݽøÐÐÂÛÊö£¬ÒýÓÕÓû§µã»÷´ò¿ª¡£

 

2.µ±Óû§´ò¿ª¸ÃÎĵµºó£¬ÏÔʾÌáÐÑÔÚÊäÈëÀ¸ÊäÈëÃÜÂëKEY£¬ÔÙµã»÷×óÉÏ·½µÄͼ±ê¼´¿ÉʵÏÖ½âËø¡£ÏÖʵÉϸÃÊäÈëÀ¸ÎªÎı¾¿ò£¬ÇÒͼ±êΪÄÚǶµÄOLE¶ÔÏ󣬸öÔÏóÔÚµã»÷ºó±ã»á´¥·¢¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

3. ͨ¹ýÌáÈ¡ÄÚǶµÄOLE¶ÔÏóÄÚÈÝ£¬·¢ÏÔìäÊÇÒ»¸öÃûΪStart_chain_1µÄppsxÌåʽµÄpptÎĵµ£¬µã»÷¼´¿É×Ô¶¯²¥·Åppt¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

4.¸ÃppsxÎĵ·ûÓÃÁËCVE-2017-0199µÄ·ì϶£¬×Ô¶¯²¥·Åpptºó¼´¿É´¥·¢£¬²¢ÏÂÔØÔËÐÐÒ»¸ösct¾ç±¾¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

5.sct¾ç±¾½âÃܺó»áŲÓÃPowershellÏÂÔØ²¢ÔËÐÐputty.exeºÍ×Ô¶¯¼ÓÔØStrategic_Chain.pdf£¬ÈÃÓû§ÎóÒÔΪÒѾ­´ò¿ªÓйØÎĵµ³É¹¦¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

6.³ýÉÏÊöÊÂÎñÖ®±í£¬¸Ã×é֯ͨ¹ýÓʼþ»¹·¢ËÍÒ»·âÃûΪEntanglementµÄppsxµÄÎĵµ£¬ÎĵµÍ¬ÑùʹÓÃÁËCVE-2017-0199·ì϶£¬ÀûÓÃÊÖ·¨ÓëµÚһ·¹¥»÷ÊÂÎñÀàËÆ¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

7.ÓëÆäËû¹¥»÷ÊÂÎñ·ÖÆçµÄÊÇ£¬Óû§´ò¿ª¸ÃppsxÎĵµ²¢´¥·¢·ì϶ºó£¬»áͨ¹ýPowershellÏÂÔØÒ»·ÝÃûΪdecoyµÄppt²¢±»Powerpoint¼ÓÔØÆðÀ´¡£

 

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 

¹¥»÷ÊÂÎñB

 

µÚ¶þ´Î¼¯Öй¥»÷ÊÂÎñ²úÉúÔÚ2018Äê3Ô£¬Í¶·ÅµÄÎĵµÖØÒªÀûÓÃCVE-2017-8570·ì϶½øÐй¥»÷£¬ÎĵµÄÚÈÝÒ²´ó¶àºÍÉç»áÕþÖÎÉúÑÄÓйØ¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾ 


 

201340118359

 

ÉÏÊö¹¥»÷ÎĵµËùʹÓõĹ¥»÷ÊÖ·¨ÆëȫһÑù£¬¶¼Ô̺¬2¸öPackageÀàÐ͵ÄOLE¶ÔÏóºÍ1¸ö½á¹¹»¯´æ´¢ÀàÐ͵ÄOLE¶ÔÏó¡£

ǰÁ½¸öPackageÀàÐ͵ÄOLE¶ÔÏóÀûÓÃPackager.dllµÄ»úÔ죬ÕƹܰÑÄÚ²¿Ç¶ÈëµÄÎļþ¿ªÊ͵½%TMP%Ŀ¼Ï¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

×îºóÒ»¸öOLE¶ÔÏóÀûÓÃCVE-2017-8570·ì϶£¬Í¨¹ýScriptlet Moniker´Ó¶ø¼ÓÔØsctÎļþÖеÄÄÚÈÝ¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

·ì϶´¥·¢³É¹¦ºó£¬×îÖÕ³ÇÊпªÊͲ¢Æô¶¯Ò»¸öÃûΪqratµÄ·¨Ê½¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 

¹¥»÷ÊÂÎñC

 

ÔÚÏÕЩͬÆÚ£¬°×Ïó×éÖ¯»¹ÌáÒéÁËÁí±í¼¸Æð¹¥»÷ÊÂÎñ£¬ÕâЩ¹¥»÷ÊÂÎñÖØÒªÀûÓÃÁËCVE-2015-2545ºÍCVE-2017-0261·ì϶Îĵµ½øÐд¹µöÓʼþ¹¥»÷¡£Í¶·ÅµÄ·ì϶ÎļþÖÖÉæ¼°Èô¸ÉÖ÷Ì⣬ÆäÖÐÔ̺¬°Í»ù˹̹½¾ü×î½üµÄ¾üÊÂÍÆ½ø»î¶¯£¬Óë°Í»ù˹̹ԭ×ÓÄÜίԱ»áÓйصÄÐÅÏ¢µÈ¡£Óйطì϶Îĵµ´¥·¢ºó»á¿ªÊÍа汾µÄBADNEWSϵÁÐľÂí¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 
ľÂí·ÖÎö

 

ÔÚÉÏÊö¼¸Æð¹¥»÷ÊÂÎñÖУ¬ÏÂÔØ£¨¿ªÊÍ£©µÄľÂíÖØÒªÓÐQuasarRATºÍBADNEWSÁ½ÖÖ¡£

 

QuasarRATľÂí

 

ÔÚ¹¥»÷ÊÂÎñAºÍ¹¥»÷ÊÂÎñBÖУ¬ÏÂÔØ£¨¿ªÊÍ£©µÄľÂíΪQuasarRAT¡£

 

1.¿ªÊ͵ÄľÂí°æ±¾ÐÅϢαÔì³É΢Èí»òQiho 360µÈ¡£

 

201345014623

 

201344448133

 

2.QuasarRATľÂíѡȡC#±àд£¬µ«×îз¢ÏֵľÂí±í²ãÔö³¤ÁËÒ»¶ÎLoader´úÂë¡£Loader´úÂëµÄÖØÒªÖ°ÄÜÊÇ·´¼ì²â·´É³ÏäÖ°ÄÜ£¬²¢ÔÚ×îºó¼ÓÔØÔ­Ê¼QuasarRATľÂí¡£QuasarRATľÂíѡȡ¸ßÇ¿¶È»ìºÏ´¦Öá£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

3.ÆäÖØÒªÖ°ÄÜÓÐÒÔϼ¸¸ö²¿ÃÅ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

4.ÍøÂçϵͳÐÅÏ¢¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

5.Ñù±¾ÔÚÍøÂçÍêÐÅÏ¢ºó£¬ »á³¢ÊÔÏνÓC&C·þÎñÆ÷¡£
 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


6.×îºó½«ÍøÂçµ½µÄÐé¹¹»·¾³£¬·´²¡¶¾Èí¼þ£¬Ö÷»ú£¬Óû§ÃûµÈÐÅÏ¢·¢Ë͵½C&C·þÎñÆ÷¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

201349019771

201349041142


 


BADNEWSľÂí

ÔÚ¹¥»÷ÊÂÎñCÖУ¬¿ªÊ͵ÄľÂíΪBADNEWSľÂí¡£

1.ÓйØÎĵµ´¥·¢·ì϶ºó»á¿ªÊÍÈý¸öÎļþ£º

%PROGRAMDATA%\Microsoft\DeviceSync\VMwareCplLauncher.exe
%PROGRAMDATA%\Microsoft\DeviceSync\vmtools.dll
%PROGRAMDATA%\Microsoft\DeviceSync\MSBuild.exe

ÆäÖÐVMwareCplLauncher.exeΪӵÓкϷ¨Êý×ÖÊðÃûµÄÎļþ£¬vmtools.dllΪ¾­¹ý´Û¸ÄµÄdll£¬ÓÃÓÚ×îÖÕ¼ÓÔØBADNEWSµÄ×îбäÖÖMSBuild.exe¡£

2.VMwareCplLauncher.exeÔËÐк󣬻á×Ô¶¯¼ÓÔØvmtools.dll£¬vmtools.dllÖ´Ðкó»á´´½¨Ò»¸öÃûΪBaiduUpdateTask1µÄ¹¤×÷´òË㣬¸Ã¹¤×÷´òËãÿ¸ôÒ»·ÖÖÓ»áÖ´ÐÐÒ»´ÎMSBuild.exe¡£

3. MSBuild.exeÖ´Ðк󣬻áÏÂÔØ
hxxps://raw.githubusercontent.com/husngilgit/husnahazrt/master/xml.xml

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

È¡³ö¡°[[¡±ºÍ¡°]]¡±ÖÐÑëµÄBase64×Ö·û´®£¬¾­¹ýÁ½´Îbase64½âÂëºÍÊý´Î½âÃܺóµÃµ½Ñù±¾±ØÒªÏνӵÄC&CµØÖ·¡£

 

4. Æ´´ÕÖ÷»úÉÏÏßÐÅÏ¢·¢Ë͵½C&C·þÎñÆ÷Ó²±àÂëµØÖ·¡£Ö÷»úÉÏÏßÐÅÏ¢ÌåʽÈçÏ£ºuuid=[UUID] #un=[µÇ¼Ãû]#cn=[ÍÆËã»úÃû]#on=[²Ù×÷ϵͳ°æ±¾] #lan=[IPµØÖ·]#nop=#ver=1.0¡£²¢Ê¹ÓÃAES¼ÓÃÜËã·¨£¨ÃÜÔ¿£ºDD1876848203D9E10ABCEEC07282FF37£©+base64±àÂë·¢Ë͵½//e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php

 

5.ÔÚʹÓÃbase64±àÂëºó»¹¶Ô±àÂëºóµÄÊý¾ÝµÄ¹Ì¶¨Æ«ÒƵØÎ»µÄ²åÈ롱=¡±ºÍ¡±&¡±×Ö·û¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

6.ÍøÂç¿Í»§¶Ë·ÇÒÆ¶¯´ÅÅ̵ÄÃô¸ÐÎļþÁбí
£¨.xls£¬.xlsx£¬.doc£¬.docx£¬.ppt£¬.pptx£¬.pdfµÈ£©£¬²¢±£ÁôΪһʱĿ¼ÏµÄedg499.dat¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

7.´´½¨Ị̈߳¬½«¼üÅ̼ͼÐÅÏ¢£¬´°¿ÚÐÅÏ¢µÈ±£ÁôΪһʱĿ¼ÏµÄTPX498.dat¡£

 

8.ÉÏÊö±£ÁôΪdatÎļþµÄÊý¾Ý£¬Í¬ÑùʹÓÃÉÏÊöAES¼ÓÃÜËã·¨+base64±àÂë·¢ËÍ¡£µ«·¢Ë͵ÄÓ²±àÂëµØÖ·±äΪ\e3e7e71a0b28b5e96cc492e636722f73\4sVKAOvu3D\UYEfgEpXAOE.php
 

×ܽá

°×Ïó×éÖ¯Ä¿Ç°ÖØÒªÍþвָ±êΪ°Í»ù˹̹ºÍÖйúµÄ´óÃæ»ýÖ¸±ê£¬Ô̺¬½ÌÓý¡¢¾üÊ¡¢¿ÆÑÓעýÌåµÈ¸÷ÀàÖ¸±ê¡£ÆäÏȵ¼¹¥»÷¼¿Á©¶àΪÓã²æÊ½´¹µöÓʼþ£¬·¢ËÍ´øÓÐÌåʽ·ì϶ÎĵµµÄÁ´½Ó£¬²¢ÇÒÉÆÓÚαÔìÓйؾüÊ¡¢ÕþÖÎÐÅÏ¢£¬½ÏΪ¾«ÃÜ¡£

Ŀǰ¸Ã×éÖ¯ÒѾ­³É³¤ÎªÓнϸ߹¥»÷ÄÜÁ¦µÄÓ×·Ö¶Ó£¬ÇÒʹÓõķì϶µÄÊÖ·¨Ò²±ÈÁ¦ÐÂÏÊ£¬¶ÔÉç»á¹¤³ÌѧµÄ°ÑÄóÏ൱µÄ¾«ÃÕâ´Ó½üÆÚ¶àÆð¹¥»÷ÊÂÎñÖоÍÄܹ»¿´³ö¡£ ¶ÔÓÚÀàËÆ°×ÏóµÄ¹¥»÷×éÖ¯£¬ÓÉÓÚ´ÓÀ´¸ü¶àÒÀÀ·àËÆµç×ÓÓʼþÕâÑùµÄ»¥ÁªÍøÈë¿Ú£¬Æäʵ±¾Äܹ»ºÜºÃµÄ×öµ½·ÀÓù£¬µ«Í¨¹ýÓÕµ¼ÐÔµÄ˵»°È´Äܹ»°ÑÕâЩ·ÀÓù´ëÊ©ÎÞЧ»¯¡£Òò¶ø£¬¼ÓÇ¿¶ÔÈËÔ±µÄ°²È«Ë¼Ïë½ÌÓý£¬Äܹ»ºÜºÃµÄÔ¤·ÀÀàËÆ°²È«ÊÂÎñµÄ²úÉú¡£


ÓйØIOC

rannd.org
brokings.org
crazywomen-dating.com
ifenngnews.com
209.58.185.37
mail.ifenngnews.com
chinapolicyanalysis.org
94.242.249.203
209.58.183.33

 
¹ØÓڽ𾦰²È«×êÑÐÍŶÓ

 

½ð¾¦°²È«×êÑÐÍŶÓÊÇGA»Æ½ð¼×¼¯Íżì²â²úÆ·±¾²¿´ÓÊÂרҵ°²È«·ÖÎöµÄ¼¼ÊõÐÍÍŶÓ£¬ÖØÒªÖ°ÔðÊǶÔÏÖÓвúÆ·Éϱ¨µÄ°²È«ÊÂÎñ¡¢Ñù±¾Êý¾Ý½øÐÐÍÚ¾ò¡¢·ÖÎö£¬²¢ÏòÓû§ÌṩרҵµÄ·ÖÎö»ã±¨¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 


¹ØÓÚVenusEyeÍþвµý±¨ÖÐÐÄ

 

VenusEyeÍþвµý±¨ÖÐÐÄ£¨www.venuseye.vip£©ÊÇGA»Æ½ð¼×ÇãÁ¦´òÔìµÄ¼¯Íþвµý±¨ÍøÂç¡¢·ÖÎö¡¢´¦Öᢰ䲼ºÍÀûÓÃΪһÌåµÄÍþвµý±¨ÔÆ·þÎñƽ̨£¬ÌṩÍþвµý±¨Êý¾Ý¡¢ÏµÍ³¡¢¼¼ÊõºÍרҵÄÜÁ¦µÄÊä³ö¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾