º£Á«»¨×éÖ¯×îй¥»÷ÊÂÎñ·ÖÎö
°ä²¼¹¦·ò 2018-06-09º£Á«»¨(OceanLotus¡¢APT32)ÊÇÒ»¸öÓµÓÐÔ½Äϲ¼¾°µÄºÚ¿Í×éÖ¯¡£¸Ã×éÖ¯×îÔç±»·¢ÏÖÓÚ 2012 Äê 4Ô¹¥»÷Öйúº£Ê»ú¹¹¡¢º£Óò½¨É貿ÃÅ¡¢¿ÆÑÐÔºËùºÍº½ÔËÆóÒµ¡£ÖØÒªÊ¹ÓÃÓã²æºÍË®¿Ó¹¥»÷·½Ê½£¬¹²Í¬É繤¼¿Á©£¬ÀûÓÃÌØÖÖľÂí½øÐÐÇкÏÔ½ÄϹú¶ÈÀûÒæµÄÕë¶ÔÐÔÇÔÃܻ¡£
½üÈÕ£¬GA»Æ½ð¼×½ð¾¦°²È«×êÑÐÍŶӷ¢ÏÖÁËһ·¸Ã×éÖ¯µÄ×îй¥»÷ÊÂÎñ£¬»¹ÔÁË´ÓÔØºÉͶµÝµ½×îºó¿ªÊÍÔ¶¿ØºóÃŵÄÕû¸ö¹¥»÷¹ý³Ì¡£
¡ôÔØºÉ·ÖÎö¡ô
±¾´ÎͶ·ÅµÄ¶ñÒâÎĵµÃûΪ??n khi?u n?i£¬ÎļþÃûΪԽÄÏÓ·ÒëºóÖÐÎÄÒâ˼Ϊ¡°Í¶Ëß¡±¡£
¸ÃÎĵµÏÖʵΪһ¸ö¶ñÒâºêÎĵµ£¬´ò¿ªºó»áÏÔʾÒýÓÕÓû§Æô¶¯ºê¿ª¹ØµÄͼƬ
ͨ¹ý½øÈëºê´úÂë´°¿Ú£¬·¢ÏÖÉèÖÃÁËÃÜÂë±£»¤¡£
¾¹ý´¦Öã¬ÎÒÃÇ»ñÈ¡µ½ÁËÒ»¶Î»ìºÏ½ÏΪÑϳÁµÄVBS´úÂë¡£
¾¹ý»ìºÏ½âÃܺó£¬Äܹ»µÃµ½ÒÔÏÂVBS´úÂë¡£
½âÃܺ󣬸þ籾»áÈ¥¼ÓÔØÒ»¶ÎеÄvbscript¾ç±¾¡£ÖµµÃÒ»ÌáµÄÊÇ£¬ÔÚ»ñÈ¡¸Ã¶Î¾ç±¾¹ý³ÌÖУ¬ÎÒÃÇ·¢ÏÖ´æÔÚÇøÓòÏÞ¶ÈÎÊÌ⣬¼´ÔÚijЩ¹ú¶ÈºÍµØÓòÎÞ·¨¶ÔÆä½øÐÐÏÂÔØ£¬×îºóÎÒÃÇͨ¹ýijЩõè¾¶½«Æä»ñÈ¡µ½¡£
¡ôVBS Loader·ÖÎö¡ô
µÃµ½¸Ã¾ç±¾ºó£¬ÎÒÃÇ·¢ÏָöδúÂëÒ²ÓµÓÐÇ¿»ìºÏÊÖ·¨¡£
¾¹ý¶ÈÎö·¢ÏÖ£¬ÔʼÎļþ´æÔÚ3¶Î´úÂ룬±ðÀëʹÓÃÁË0x35, 0x39, 0x35×÷ΪÒì»ò½âÃܵÄÃÜÔ¿¡£
µÚÒ»¶Î´úÂëÈçÏÂËùʾ¡£Õâ¶Î´úÂëн¨ÁËÒ»¸öExcel¶ÔÏ󣬲¢Åú¸ÄÁË×¢²á±íÖÐAccessVBOMµÄÖµ£¬Ê¹¾ç±¾Äܹ»¶Ôºê½øÐÐŲÓÃÖ´ÐС£
µÚ¶þ¶Î´úÂëΪ¸ÃExcel¶ÔÏóµÄºê´úÂ룬¸Ã¶Îºê´úÂë¾¹ýÁ˿϶¨µÄ»ìºÏ£¬²¢Ê¹ÓÃÁË0x78À´Òì»ò¼ÓÃÜÆäÖеÄ×Ö·û´®¡£²¢Ê¹ÓÃCreateProcessÀ´Å²ÓÃrundll32£¬¶øºó½«Ò»¶Îshellcode×¢Èëµ½¸Ã¹ý³ÌÖУ¬²¢×îÖÕͨ¹ýCreateRemoteThread¼ÓÔØ¸Ã¶Îshellcode¡£
shellcodeµÄǰ°ë²¿ÃÅÊÇbase64½âÂ뷨ʽ£¬ºó°ë²¿ÃÅÊÇbase64Êý¾Ý¡£
ºê´úÂëÖеÄshellcodeÄÚÈÝÈçÏÂËùʾ¡£
shellcodeµÄǰ0x76¸ö×Ö½ÚÊÇÒ»¸öloader£¬×÷ÓÃÊǶԺóÃæµÄÊý¾Ý½øÐнâÂë²¢¼ÓÔØ¡£¸ÃÊý¾ÝµÄ±àÂëΪbase64£¬¾¹ý½âÂëºóÄܹ»µÃµ½ÁíÒ»¶Îshellcode£¬ÈçÏÂËùʾ¡£
Õâ¶Îshellcode»áÏνÓC&C·þÎñÆ÷£¬ÏÂÔØÁíÒ»¶ÎshellcodeÄÚÈݲ¢Ö±½Ó¼ÓÔØ¡£
µÚÈý¶Î´úÂëÈçÏÂËùʾ¡£Õâ¶Î´úÂëŲÓÃÁ˸ÃExcelµÄAuto_Openº¯Êý£¬²¢¹Ø¹ØExcel¶ÔÏ󣬸´Ô×¢²á±íÖеÄAccessVBOM×ֶΡ£
¡ôÔ¶¿Ø·ÖÎö¡ô
×îÖÕµÄshellcode±ÉÈËÔØÊµÏÖ²¢ÔËÐкó£¬Ê×ÏÈshellcodeÍ·²¿Í¨¹ý½«Æ«ÒÆ0x34ºÍ0x38´¦µÄÊý¾Ý½øÐÐÒì»òÇóµÃÊý¾ÝµÄ×ܳ¤¶È£¬¶øºó¶ÔËæºóµÄÊý¾Ý½øÐÐÒì»ò½âÃÜ£¬ÔÚÈ«Êý½âÃÜʵÏÖºóÆðÍ·Ö´ÐдúÂë¡£
½âÃܺóµÃµ½Ò»¸öDLLÎļþ£¬¸ÃÎļþµÄµ¼³öÄ£¿éÃûΪ17f2d8.dll£¬µ¼³öº¯ÊýÃûΪ_ReflectiveLoader@4¡£
ÔÚDllMainº¯ÊýµÄ¿ªÍ·£¬»á¶Ô0x10030028´¦´óÓ×Ϊ0x1000µÄÊý¾Ý½øÐÐÒì»ò0x69½âÃÜ¡£
ÔÚ½âÃܺóµÄÊý¾ÝÖУ¬Äܹ»·¢ÏָúóÃÅ»ØÁ¬µÄC&C·þÎñÆ÷Ϊ£º
https://***.***.net,/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
Áí±í£¬¸ÃÑù±¾Ò²ÔÚÒªÇóÖн«×Ô¼ºÎ±ÔìΪamazon.com£¬½«´«ÊäµÄÊý¾Ý±àÂëºó°µ²ØÔÚCookies×Ö¶ÎÖС£
µ±µÃµ½C&C·þÎñÆ÷·¢¹ýÀ´µÄÖ¸Áîºó£¬¸ÃÔ¶¿Ø±ã»áÖ´ÐÐÏàÓ¦µÄ²Ù×÷£¬Í¨¹ýͳ¼Æ·¢ÏÖÓг¤´ï72ÖÖÖ¸Áî¡£
ÒÔÏÂΪÆäÖм¸ÖÖÖ¸ÁîµÄÖ°ÄÜ¡£
¡ôËÝÔ´Óë¹ØÁª·ÖÎö¡ô
Shellcode¹ØÁª
½áºÏ¸ÃVBS¾ç±¾ÏÂÔØµÄshellcodeµÄ±àд¼¼ÇÉ£¬ÎÒÃÇͨ¹ýÒÔÍù×·×Ùº£Á«»¨×éÖ¯µÄ¾Ñ飬·¢ÏָöÎshellcodeÓëÒÔÍùº£Á«»¨×éÖ¯ËùʹÓõÄshellcodeÊÖ·¨ÏÕЩһÖ¡£
£¨ÉÏͼΪ±¾´Î¹¥»÷ÖÐʹÓõÄshellcode£¬ÏÂͼΪÒÔÍùº£Á«»¨ËùʹÓõÄshellcode£©
ͬԴÐÔ¹ØÁª·ÖÎö
³ýÁËshellcode±í£¬´Ó±¾´Î¹¥»÷ÖÐ×îºó¿ªÊ͵ÄÔ¶¿Ø£¬ÓëÔÚÎÒÃÇÒÔÍùÅû¶µÄº£Á«»¨×éÖ¯»ã±¨ÖУ¨Ïê¼û¡¶2017ÍøÂç°²È«Ì¬ÊÆ¹Û²ì»ã±¨¡·£©£¬ÎÞÂÛÊǻش«Ìص㣬»¹ÊÇ´úÂë½á¹¹ÉõÖÁ¼Ù×°³ÉamazonµÄhostÖ÷»ú»Ø´«ÐÅÏ¢µÄÐÐΪ¶¼ÏÕЩһÖ¡£
Òò¶øÄܹ»È·ÈÏ£¬±¾´Î¹¥»÷ȷΪº£Á«»¨×éÖ¯ÌáÒ飬²¢ÇÒ¸Ã×éÖ¯ÒÀÈ»ÔÚÑØÓÃÒÔÍùµÄ±øÆ÷¡£
±¾´Î¹¥»÷ÖÐËùʹÓõÄÑù±¾ÎļþÃûΪԽÄÏÓïÊéд£¬ÇÒ±êÌâÓëóÒ×Óйأ¬Òò¶øºÜÓпÉÄÜÖ¸±êÕë¶ÔÔ½ÄÏÓйصÄ˽ӪÆóÒµ¡£
¡ô½â¾ö¹æ»®¡ô
1¡¢Ä¿Ç°£¬GA»Æ½ð¼×VenusEyeÍþвµý±¨ÖÐÐÄÒѾ֧³ÖÕë¶ÔÕâ´Î¹¥»÷ËùÉæ¼°µý±¨µÄ²éÎÊ¡£
2¡¢Ììãٸ߼¶³ÖÐøÐÔÍþв¼ì²âϵͳÎÞÐèÉý¼¶¼´¿É¼ì²âÓйع¥»÷Ñù±¾¡£
3¡¢ÌìãÙÈëÇÖ¼ì²âϵͳ¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳµÈÒѾ֧³Ö¶Ô´Ëº£Á«»¨×éÖ¯¹¥»÷»î¶¯µÄ¼ì²â£¬ÓйØÊÂÎñÃû£ºHTTP_ľÂí_º£Á«»¨_Ïνӡ£
½ð¾¦°²È«×êÑÐÍŶÓÊÇGA»Æ½ð¼×¼¯Íżì²â²úÆ·±¾²¿×¨Òµ´ÓÊÂÍþв·ÖÎöµÄÍŶӡ£ÖØÒªÖ°ÔðÊǶÔÏÖÓвúÆ·ÍøÂçÉϱ¨µÄ°²È«ÊÂÎñ¡¢Ñù±¾Êý¾Ý½øÐÐÍÚ¾ò¡¢·ÖÎö£¬²¢ÏòÓû§Ìṩרҵ·ÖÎö»ã±¨¡£¸Ã×éÖ¯»áƾ¾ÝÊý¾Ý²úÉúµÄÍþвµý±¨£¬¶ÔÆäµ±Ñ¡È¡µÄ¸÷À๥·À¼¼Êõ×öÉî¿ÌµÄ¸ú×ٺͷÖÎö£¬²¢ÇÒ¸ø³öרҵµÄ·ÖÎöÁ˾֡¢Ìá³öרҵ½¨Ò飬ΪÓû§¾ö²ßÌṩԮÊÖ¡£


¾©¹«Íø°²±¸11010802024551ºÅ