¡¾Éî¶È·ÖÎö¡¿VPNFilter£ºÎ£¼°È«Çò¹¤¿ØÉ豸ºÍ°ì¹«ÍøÂçµÄÎïÁªÍø¸ß¼¶Íþв

Ðû²¼Ê±¼ä 2018-06-17

Ò»¡¢Íþв¸ÅÊö

        ½üÆÚ£¬Ë¼¿ÆTalosÍŶÓÒòÇé¿ö½ô¼±ÌáÇ°¹ûÈ»ÁËÒ»ÏîδÍê³ÉµÄÑо¿£¬¸ÃÑо¿Ìá¼°ÁËÒ»¸ö¿ÉÄܶÔÈ«ÇòÍøÂç·¢ÉúÖØ´óΣº¦µÄ¸ß¼¶Íþв¹¥»÷(ԼĪÓÐ50Íǫ̀É豸Êܵ½Ñ¬È¾)£¬ÓÉÓÚÆäºËÐÄÄ£¿éÎļþΪVPNFilter£¬¹Ê¸Ã¶ñÒâ´úÂëÒ²±»ÃüÃûΪ¡±VPNFilter¡±¡£¸Ã¹¥»÷ÊÇÒ»ÆðÒÔÈëÇÖÎïÁªÍøΪÔØÌå´ÓÊ¿ÉÄÜÓɹú¼ÒÌᳫµÄÈ«ÇòÐԵĸ߼¶¶ñÒâÈí¼þ¹¥»÷£¬¶ñÒâÈí¼þͨ¹ýÈý¸ö½×¶ÎÀ´²¿ÊðÆä¹¥»÷ÎäÆ÷£¬Ä¿Ç°ÒѾ­ÓÐÖÁÉÙ50Íǫ̀É豸Êܵ½Ñ¬È¾¡£¹¥»÷ÕßÀûÓøöñÒâÈí¼þÀ´¿ØÖƲ¢¼àÊÓ´¦ÓÚ¹¤¿ØÍøÂç¡¢°ì¹«»·¾³ÖеÄÍøÂçÉ豸(°üÂÞ·ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽÒÔ¼°ÆäËûµÄÎïÁªÍøÉ豸)£¬ÆäÖ§³Ö¹¤¿ØÍøÂçÇ鱨ÊÕ¼¯¡¢ÖØÒªÃô¸ÐµÄÁ÷Á¿(µÇ¼ƾ֤)½ØÈ¡¡¢Á÷Á¿¸Ä¶¯¡¢¶¨ÏòJS×¢Èë¡¢É豸ÆÆ»µÐÔ¹¥»÷µÈ¹¦Ð§¡£

        ¶ñÒâÈí¼þÔÚ5ÔÂ8ÈÕ·ºÆð´ó¹æÄ£µÄÒÔÎÚ¿ËÀ¼ÎªÖ÷ҪĿ±êµÄ¹¥»÷»î¶¯£¬¶øÇÒÔÚ5ÔÂ17ÈÕÎÚ¿ËÀ¼µÄÊÜѬȾÉ豸·ºÆð´ó·ù¶ÈÔö¼Ó£¬ÕâЩÊÜѬȾÉ豸¾ùÊÜ¿ØÓÚC&C 46.151.209.33, ¿´ÆðÀ´´Ë´Î¹¥»÷Ä¿±êËƺõÃé×¼ÎÚ¿ËÀ¼¡£ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³Ôø¾­Êܵ½¹ýÁ½´ÎºÚ¿Í¹¥»÷£¬¶øÇÒµ¼ÖÂÁËÍ£µçʹÊ£¬Á½´Î¹¥»÷¾ùÒԳ־öøÒþÃصÄÉø͸ÊÖ¶ÎÈëÇÖµ½Ä¿±ê¡£¶øÕâ´ÎµÄ¹¥»÷»î¶¯ÒÔÎïÁªÍøÈë¿Ú£¬ÀûÓôóÁ¿´æÔÚ©¶´µÄÎïÁªÍøÉ豸×÷ΪÔØÌå½øÐÐÈöÍøʽ¹¥»÷£¬¶øÇÒÒÔ¾ªÈ˵ÄËÙ¶ÈѬȾÁËÖÁÉÙ50Íǫ̀É豸£¬ÆäÖаüÂÞÓлªÎª¡¢ÖÐÐË¡¢»ªË¶¡¢Dlink¡¢Ubiquiti¡¢UPVEL¡¢Linksys¡¢MikroTik¡¢NETGEAR ºÍ TP-LinkµÈÉ豸¡£Í¬Ñù£¬´Ë´Î¶ñÒâ´úÂëÓë2015Äê¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄBlackEnergyʹÓÃÏàͬµÄ±äÐÎRC4Ëã·¨¶ÔÒªº¦ÐÅÏ¢½øÐмÓÃÜ£»¶øÇÒÓëÖ®ÀàËƵÄÊÇͬÑùÒ²ÓжÔÖ÷»úÉ豸½øÐÐÖØÒªÊý¾Ý²Á³ýÓëÖØÆôµÄÁ¬»·Ðж¯ÒÔµ½´ïÈÃÉ豸ÎÞ·¨Æô¶¯µÄÄ¿µÄ(ͬʱҲÌá¸ßÁËÈ¡Ö¤µÄÄѶÈ)¡£

        ¶«É­Æ½Ì¨ADLab·¢ÏÖ¸ÃÔ¤¾¯ºó¶Ô¸Ã¶ñÒâÈí¼þ½øÐÐÁËÉîÈëµÄ·ÖÎö£¬ÒÔÆÊÎöÆäʵÏÖ»úÖÆ¡£ÎÒÃÇ·¢ÏָöñÒâÈí¼þÖгýÁ˽ÓÄÉͼƬÎļþµÄEXIFÊý¾Ý´«ÊäÓÃÓÚÏÂÔضñÒâ´úÂëºËÐÄ×é¼þµÄC&CÍ⣬»¹½ÓÄÉHTTPÍ·ÖеÄlocationºÍdirect×ֶδ«Êä¸ÃC&C£¬ÉõÖÁ½ÓÄÉÁËÒ»ÖÖÎÒÃdzÆ֮Ϊ¡±SYNËíµÀ¼¼Êõ¡±µÄ¸ß¼¶Òþ²Ø¼¼ÊõÀ´ÊµÏÖ¶ñÒâÈí¼þC&CµÄ±»¶¯¸üУ¬¼´Ê¹Èç֮ǰËù±¨µÀÄÇÑù£¬FBI×è¶ÏÁ˸öñÒâÈí¼þµÄC&C£¬¸Ã¼¼ÊõÒ²¿ÉÒÔÈøöñÒâÈí¼þ¿ìËÙ¸´Éú¡£ÆäÖеÚÈý½×¶Î¶ñÒâ×é¼þרÃÅÕë¶ÔTCPЭÒé½øÐÐÐá̽´¦Ö㬲»½ö¶Ô¹¤¿Ømodbus SCADAЭÒé½øÐÐÇ鱨ÊÕ¼¯£¬Í¬Ê±»¹»áÐá̽»ùÓÚhttpЭÒéµÄµÇ¼ƾ֤ÐÅÏ¢ºÍAuthorizationÐÅÏ¢¡£¸ÃÐá̽Ä£¿éÐèÒªºÚ¿ÍÔ¶³ÌÖ¸¶¨modbus·þÎñÆ÷½øÐо«È·µÄ¼à¿Ø£¬ÒÔ·¢ÏÖËùÓÐÁ¬½ÓµÄ´Ó»úÉ豸¡£´ËÍ⣬ÔÚ×î½ü¹ûÈ»µÄ¹¥»÷²å¼þÄ£¿éÖл¹¿ÉÒÔ¿´³ö£¬¸Ã´Î¹¥»÷¿ÉÓÃÓڹ㷺µÄÇ鱨ÊÕ¼¯ÒÔ¼°¶ÔÌض¨Ä¿±ê½øÐÐÉø͸¹¥»÷£¬ÆäÖаüÂÞ¶Ô80¶Ë¿ÚµÄÁ÷Á¿Öض¨Ïò¡¢Ç¿ÖÆת»»HTTPSΪHTTPÒÔ·½±ãÁ÷Á¿¼à¿Ø¡¢ÇÔÈ¡HTTPÇëÇó°üÖеĵǼƾ֤ÐÅÏ¢¡¢ÏòÖ¸¶¨ÍøÕ¾µÄÏìÓ¦Êý¾ÝÖÐ×¢Èë¶ñÒâjavascript½Å±¾µÈµÈ¡£

¶þ¡¢¶ñÒâÈí¼þÊÂÇéÔ­Àí

        ¸Ã¶ñÒâÈí¼þͨ¹ýÀûÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍøÉ豸©¶´½øÐй㷺µÄѬȾºÍÁ÷´«¡£ÔÚѬȾÉ豸ÖУ¬ÆäÊ×ÏÈÆô¶¯Ò»¸öLoaderÄ£¿éÖ´ÐУ¬¸ÃÄ£¿éÖ÷ҪʵÏÖÁËVPNFilter×é¼þµÄÏÂÔØÓëÖ´ÐС£LoaderÄ£¿é²¢²»ÊÇÖ±½Óͨ¹ýÖ¸¶¨µÄÏÂÔصØÖ·À´ÏÂÔØVPNFilter×é¼þ£¬¶øÊÇͨ¹ý¶àÖÖ¼¼ÊõÊÖ¶ÎÀ´»ñÈ¡VPNFilterµÄÏÂÔصØÖ·(´æ´¢µã)¡£ÆäÊ×ÏÈ»áÏò·þÎñÆ÷photobucket.com·¢ËÍÇëÇó²¢ÊµÑé½âÎöÏìÓ¦Êý¾ÝÖеÄLocaion¡¢direct¡¢Í¼Æ¬EXIFÐÅÏ¢À´»ñÈ¡£»Èç¹ûʧ°ÜÔòÏò·þÎñÆ÷taknowall.com·¢ËÍÇëÇó²¢½âÎöͼƬµÄEXIFÀ´»ñÈ¡£»Èç¹ûÈÔÈ»ÎÞ·¨»ñÈ¡µ½C&C£¬Ôò»á½ÓÄÉ¡±SYNËíµÀ¼¼Êõ¡±À´»ñÈ¡C&CʵÏÖÏÂÒ»¸ö½×¶Î×é¼þµÄÏÂÔصØÖ·¡£´ËÍ⣬VPN´æ´¢µã»ñÈ¡Àֳɺó£¬Loaderͨ¹ýÄÚÖÃSSLÖ¤ÊéÎļþÀ´ÑéÖ¤ÏÂÔØVPNFilter×é¼þ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        VPNFilter×é¼þ×îºó»á±»ÏÂÔص½¡±/var/run/¡±Ä¿Â¼Ï£¬ÊǸÃÀà¶ñÒâ¹¥»÷µÄºËÐÄ×é¼þ£¬Í¨¹ý¸Ã×é¼þ£¬¶ñÒâÈí¼þµÃÒÔפÁôÔÚ±»Ñ¬È¾ÏµÍ³ÖС£VPNFilter×é¼þΪ¹¥»÷ÕßÌṩÁËÒ»¸öÓÃÓÚά»¤½©Ê¬ÍøÂçµÄ¿ò¼Ü£¬¹¥»÷Õß¿ÉÒÔ»ùÓÚ²îÒìµÄ¹¥»÷Ä¿µÄ¼ÓÔزîÒìµÄ²å¼þºÍÖ´ÐвîÒìÔ¶¿Ø¿ØÖÆÃüÁĿǰËù·¢ÏֵIJå¼þÄ£¿éÓУºÒ»¸öÓÃÓÚÖ§³ÖÁ¬½Óµ½TorÍøÂçµÄTor ¿Í»§¶Ë£¨Tor Client,Îļþtor£©£»Ò»¸öΪÐá̽µÇ¼ƾ֤ºÍModbus¹¤¿ØЭÒéÐÅÏ¢µÄTCPÁ÷Á¿Ðá̽Ä£¿é£¨TCP Traffic Sniffer£¬Îļþps£©;Ò»¸öרÃÅΪHTTP 80¶Ë¿Ú½øÐÐÁ÷Á¿¼à¿Ø¡¢½ØÈ¡¡¢¸Ä¶¯¡¢×¢ÈëµÄHTTP Á÷Á¿¼à¿ØÄ£¿é£¨HTTP Traffic Controllor£¬Îļþssler£©£»ÒÔ¼°¿ÉÓÃÓÚÆÆ»µÉ豸ʹÆäÎÞ·¨ÖØÆô¡¢ÎÞ·¨È¡Ö¤µÄÉ豸ÆÆ»µÄ£¿é£¨Destroy Module£¬Îļþdstr£©£¬´ËÍâÆ仹´æÔÚÆäËûµÄÄ£¿éÈ磺mikrotik.o¡¢torrc¡¢ip_tables.ko¡¢iptable_filter.ko¡¢iptable_nat.ko¡£

Èý¡¢¶ñÒâÈí¼þÆÊÎö

        ƾ¾Ý¸Ã¶ñÒâÈí¼þÖ´Ðй¥»÷µÄ²½Ö裬¿ÉÒÔ½«Æä»®·ÖΪÈý¸ö½×¶Î£¬ÆäÖÐLoaderÎļþΪµÚÒ»¸ö½×¶ÎµÄ¶ñÒâÄ£¿é£¬VPNFilterÎļþΪµÚ¶þ½×¶ÎµÄ¶ñÒâÄ£¿é£¬Tor¿Í»§¶ËºÍÁ÷Á¿Ðá̽Æ÷ΪµÚÈý½×¶ÎµÄ¶ñÒâÄ£¿é¡£ÒÔÏ·ֱð¶ÔÕâÈý¸ö½×¶ÎµÄ¶ñÒâ´úÂë½øÐÐÉîÈëµÄÆÊÎö¡£

µÚÒ»½×¶Î£ºÑ¬È¾É豸²¢ÏÂÔضñÒâ´úÂëÖ÷ÌåÖ´ÐÐ

        µÚÒ»¸ö½×¶ÎµÄÑù±¾¿ÉÒÔ¿´×÷ÊÇÒ»¸öLoader£¨ÎļþÃûΪmsvf£©£¬¹¥»÷ÕßÀûÓÃÉ豸©¶´½«ÆäÂäµØµ½É豸ÄÚ´æÖÐÔËÐС£¸ÃLoaderÖ÷ҪĿµÄÊÇ´ÓC&C·þÎñÆ÷ÉÏÏÂÔصڶþ½×¶ÎµÄ¶ñÒâ×é¼þÖ´ÐС£¸ÃLoader²îÒìÓÚÒÔÍùµÄÎïÁªÍø¶ñÒâ´úÂëÄÇÑù½«C&CÄÚÖÃÓÚ´úÂëÄÚ£¬¶øÊÇͨ¹ýÔںϷ¨Í¼Æ¬ÍøÕ¾ÉÏÏÂÔØÒ»ÕÅÒþ²ØÓÐC&CµØÖ·µÄͼƬ½øÐнâÎö£¬´Ó¶øµÃµ½ÕæʵµÄC&C¡£¶ø¶ñÒâ´úÂëΪÁË·ÀÖ¹Á÷Á¿×·×Ù£¬½ÓÄÉsocks5ÊðÀí¡¢Tor¡¢ÒÔ¼°sslµÄ·½Ê½½øÐиÃͼƬµÄÏÂÔØ¡£Èç¹ûͼƬÏÂÔØʧ°Ü£¬Ò²»á½ÓÄɼ«ÆäÒþ±ÎµÄԭʼÁ÷Á¿Êý¾ÝÐá̽µÄ·½Ê½À´»ñÈ¡C&C¡£

        ͬʱ¸ÃÄ£¿é»¹ÊÔͼÐÞ¸ÄNVRAM²¢½«×ÔÉí¼ÓÈ붨ʱÈÎÎñÎļþ¡±crontab¡±ÖУ¬ÒÔµ½´ï³£×¤µÄÄ¿µÄ¡£Ò»°ãÎïÁªÍø¶ñÒâ´úÂëÈçmiraiµÈûÓÐÉæ¼°³£×¤»úÖÆ£¬Ê¹µÃÆäÔÚÉ豸ÖØÆôºó»áÏûʧ¡£

        1¡¢Á½´Î´´½¨×Ó½ø³Ì¶øÇÒÆôÓöñÒâ´úÂë¶Ôµ±Ç°Óû§×éµÄ¶ÁдִÐÐȨÏÞ

        µÚÒ»½×¶ÎÑù±¾Ö´Ðк󣬻áforkÁ½´Î£¬µÚÒ»´ÎÓÃÓÚÇåÀí½ø³Ì×ÊÔ´ÆôÓöÁдִÐÐȨÏÞ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        µÚ¶þ´Îfork»áÔÚ×Ó½ø³ÌÖÐÈ·ÈϽø³ÌÎļþÊÇ·ñ´æÔÚ£¬Èç¹û²»´æÔÚ»á½øÐÐÎļþµÄ»Øд£¬·ÀÖ¹½øÐÐÎļþ¶ªÊ§¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´ËÍâÔÚµÚ¶þ´ÎforkµÄ×Ó½ø³ÌÖУ¬¶ñÒâ´úÂëΪÁË·ÀÖ¹×ÔÉíÎļþÔÚÉ豸ÖØÆôºóÏûʧ£¬»¹»á½«×ÔÉíÎļþ¼ÓÈëµ½crontabÎļþĩ⣬ÒÔʵÏÖ¿ªÆôÆô¶¯¡¢³£×¤É豸µÄÄ¿µÄ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        2¡¢ ½âÃÜÖ¤ÊéÎļþÃû¡¢Í¼Æ¬Á´½ÓÊý¾ÝµÈÄÚÈÝ

        ½ÓÏÂÀ´¶ñÒâ´úÂë»áͨ¹ý±äÐεÄRC4Ëã·¨À´½âÃܺóÐøÒªÓõ½µÄ×Ö·û´®ºÍÊý¾Ý£¬±äÐÎRC4ÃØԿΪ¡±%^:d¡±£¬×îа汾ÒѾ­¸üÐÂΪ¡°g&*kdj$dg0_@@7¡¯x¡±¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

±äÐÎRC4µÄstableÊý¾ÝÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ×îºó½âÃܵõ½ÈçÏÂÐÅÏ¢£¬ÆäÖаüÂÞÖ¤ÊéÎļþÃû¡¢°æ±¾ºÅ¡¢buildÐÅÏ¢¡¢Í¼Æ¬urlµÈ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½âÃÜurl£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        3¡¢´´½¨sslÖ¤ÊéÎļþÒÔ¼°¶ñÒâ´úÂë°æ±¾Îļþ

        ½âÃÜÍê³Éºó£¬¶ñÒâ´úÂë»á½«´úÂëÖÐÄÚǶµÄ¹«Ô¿¡¢Ë½Ô¿Êý¾Ý´æ´¢ÔÚÖ¤ÊéÎļþÖС£¸Ã¶ñÒâ´úÂëÖдæ·ÅÓÐÈý¸öÖ¤ÊéÊý¾Ý£¬ÆäÖÐÁ½¸ö¹«Ô¿ºÍÒ»¸ö˽Կ£¬¹«Ô¿´æ´¢ÔÚÎļþ¡±/var/run/client_ca.crt¡±ºÍ¡±/var/run/client.crt¡±ÖУ¬Ë½Ô¿´æ´¢ÔÚÎļþ¡±/var/run/client.key¡±ÖС£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´ËÍ⣬°æ±¾ÐÅÏ¢0.3.9qa»á±»Ð´Èëµ½Îļþ/var/run/msvf.pidÖС£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        4¡¢ÏÂÔصڶþ½×¶Î×é¼þ

        µÚ¶þ½×¶ÎµÄ¶ñÒâ´úÂëÏÂÔصØÖ·½ÓÄÉÈýÖÖ·½Ê½»ñÈ¡¡£Ê×ÏÈʵÑé´ÓphotobucketÍøÕ¾ÇëÇóC&C£¬¾ßÌåƾ¾ÝÈçÏÂÁ´½Ó˳ÐòÈ¥ÏÂÔز¢ÌáÈ¡µÚ¶þ½×¶Î¶ñÒâ´úÂëµÄ·þÎñÆ÷µØÖ·¡£

http://photobucket.com/user/nikkireed11/library

http://photobucket.com/user/kmila302/library

http://photobucket.com/user/lisabraun87/library http://photobucket.com/user/katyperry45/library

        ËäÈ»µ±Ç°ÕâЩÁ´½ÓÒѾ­Ê§Ð§£¬µ«ÊÇͨ¹ýÄæÏò¿ÉÒÔ¿´³ö£¬Èç¹ûÇëÇóÏìÓ¦ÂëΪ302£¬¶ñÒâ´úÂëÔò»á´ÓÏìÓ¦Êý¾ÝÖеġ±Location¡±/¡±location¡±²ÎÊýÖÐÌáÈ¡³öµÚ¶þ½×¶Î¶ñÒâ´úÂëµÄÏÂÔصØÖ·¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Èç¹û¶ñÒâ´úÂëÇëÇóµÄÏìÓ¦ÂëΪ200£¬Ôò»á´ÓÇëÇóµÄÏìÓ¦Êý¾Ý°üµÄHTTPÍ·²¿ÖÐÌáÈ¡¡±direct¡±²ÎÊýµÄÖµ£¬×÷ΪµÚ¶þ½×¶Î¶ñÒâ´úÂëÏÂÔصØÖ·¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Èç¹û²»´æÔÚ¸ÃÖµ£¬Ôò»á´ÓͼƬÎļþÖеÄEXIFÓòÌáÈ¡¾­Î³¶ÈÊý¾Ý²¢½«Æäת»»ÎªµÚ¶þ½×¶Î¶ñÒâ´úÂëÏÂÔصÄIPµØÖ·¡£ÏÂÔصÄͼƬÎļþEXIF²¿ÃÅÊý¾ÝÀàËÆÏÂͼ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´¦ÖôúÂëÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Èç¹ûÒÔÉÏÇé¿ö¾ùʧ°Ü£¬¶ñÒâ´úÂ뻹»áʵÑéÇëÇóÈçÏÂÁ´½Ó£¬¸ÃÁ´½ÓÒ²ÊÇÒ»ÕÅͼƬ£¬ºÍÉÏÃæÒªÁìÒ»Ñù´ÓEXIFÖÐÌáÈ¡¾­Î³¶È²¢´¦Öõõ½ÏÂÔصØÖ·£ºhttp://taknowall.com/manage/content/update.php ¡£

        Èç¹ûÉÏÃæµÄËùÓз½Ê½¶¼ÊµÑéºóÒÀÈ»ÎÞ·¨ÀֳɻñÈ¡C&CµØÖ·£¬¶ñÒâ´úÂë»áͨ¹ýÁ´½Óhttp://api.ipify.org?format=json»ñÈ¡µ½µ±Ç°É豸µÄÍâÍøIPµØÖ·£¬È»ºóÐá̽µ±Ç°É豸µÄԭʼÍøÂçÁ÷Á¿Êý¾Ý£¬²¢ÊÔͼ´ÓÕâЩÁ÷Á¿Êý¾ÝÖйýÂ˳öÇкÏÌض¨¸ñʽµÄÍøÂçÊý¾Ý°ü£¬Èç¹ûÂú×ã¸ñʽҪÇ󣬱ã»á´Ó¸ÃÊý¾ÝÖÐÌáÈ¡³öµÚ¶þ½×¶Î¶ñÒâ´úÂëµÄÏÂÔصØÖ·¡£ÆäÖйýÂË°üʱÐèÂú×ãÈçÏÂÌõ¼þ£º

        (1)  ԭʼÊý¾ÝÁ÷³¤¶È±ØÐë´óÓÚ0x3D

        (2)  Êý¾Ý°ü±ØÐëΪTCP°ü

        (3)  Êý¾Ý°üµÄSYN±ØÐë±»ÉèÖÃ

        (4)  Ä¿µÄIP±ØÐëΪµ±Ç°É豸µÄ¹«ÍøIP

         (5)  Tcp OptionµÄMSS(Maximum Segment Size) ±ØÐëΪ0c 15 22 2B£¨Êµ¼ÊÉÏΪ·Ç·¨MSS£©

        Èç¹ûÂú×ãÒÔÉÏÌõ¼þ£¬Ôò´ÓMSSÖ®ºóµÄ4¸ö×Ö½ÚÌáÈ¡³öC&CµÄIPµØÖ·¡£ÎÒÃǽ«ÕâÖÖÒÔSYN TCPÊý¾ÝÁ÷×÷ΪÊý¾Ý´«ÊäµÄ¼¼Êõ³ÆΪ¡±SYNËíµÀ¼¼Êõ¡±¡£ÀûÓøÃÖÖ¼¼ÊõÀ´´«ÊäC&CµØÖ·²»½öÄܹ»ºÜºÃÒþÃغڿ͵Ä×Ù¼£(ÎÞÐèÔÚ¶ñÒâ´úÂëÄæÏò»òÕßÍøÂç´æ´¢µãÉÏ̻¶ºÚ¿ÍC&CµØÖ·)£¬¶øÇÒÄܹ»Áé»îµÄ±ä»»C&C£¬·Ç³£ÄÑÒÔ±»¾õ²ì¡£Òò´Ë£¬¿ÉÒÔ˵Ñù±¾ÖÐÈκÎÄÚÖÃC&C»òÕß´æ´¢C&CµÄ´æ´¢µã±»´¦Öú󣬸öñÒâ´úÂëÈÔÈ»¿ÉÒÔÊÜ¿ØÓÚºÚ¿Í¡£Õâ¸øÖ´·¨²¿ÃÅ´¦ÖøöñÒâ´úÂë´øÀ´Á˾޴óÌôÕ½¡£Ô­Ê¼Á÷µÄ²¿ÃÅÅж¨´úÂëÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Èç¹ûÒÔÉÏÈκÎÒ»ÖÖ·½Ê½Äܹ»ÀֳɻñÈ¡µ½ÏÂÔصØÖ·¶øÇÒÏÂÔØ×é¼þÀֳɣ¬¶ñÒâ´úÂë±ã»áÖ±½ÓÖ´ÐÐËùÏÂÔضñÒâ´úÂ룬ȻºóÍ˳ö¡£ÏÂÔصĵڶþ½×¶ÎµÄ¶ñÒâ´úÂë±»Éú´æΪÎļþ¡±/var/vpnfilter¡±¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

µÚ¶þ½×¶Î£º¿ØÖÆÃüÁî½ÓÊÕ¡¢·Ö·¢¡¢Ö´ÐÐ

        ¸ÃÑù±¾ÒÔʵÏÖºóÃÅ¿ØÖÆΪĿµÄ£¬ÆäÖ÷ÒªÓÃÓÚÁ¬½Ó¿ØÖƶ˷þÎñÆ÷£¬½ÓÊÕ¿ØÖÆÃüÁîÖ´ÐÐÏàÓ¦µÄ¹¦Ð§¿ØÖÆ¡£Ñù±¾Ê×ÏÈΪÁËÈ·±£ÔËÐÐʵÌåµÄΨһÐÔ£¬»á°ó¶¨1386¶Ë¿Ú¡£Èç¹û¸Ã¶Ë¿Ú±»Õ¼Óñã»áÖÕÖ¹ÔËÐС£´ËÍâÔÚа汾Öв»ÔÙͨ¹ýÕâÖÖÈÝÒ××ÔÎÒ̻¶µÄ·½Ê½À´×öΨһÐÔÅж¨£¬¶øÇÒÌí¼ÓÁË×ÔÎÒɾ³ýµÄ¹¦Ð§¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Èç¹û°ó¶¨Àֳɣ¬±ã»á½øÈëºËÐÄÊÂÇé´úÂëÖÐÖ´ÐС£Ê×ÏÈΪÁË·ÀÖ¹ÒòCPU×ÊÔ´²»×㡢ƽ̨¼æÈÝÐÔµÈÎÊÌâµ¼ÖÂÎÞ·¨ÊÂÇé»òÕßÍ˳ö£¬Æ仹ע²áÁË´óÁ¿Òì³£ÐźÅÓÃÓÚ×ÔÎÒ¸´Éú¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        È»ºó½ÓÄÉͬÑùµÄ±äÐÎRC4Ëã·¨ºÍÃØÔ¿À´½âÃÜÒªº¦×Ö·û´®ÒÔ¹©ºóÐøʹÓ᣽ÓÏÂÀ´»áÍê³ÉºóÐø°²×°ÅäÖÃÁ÷³Ì¡£

        Ê×Ïȼì²âsslÖ¤ÊéÎļþÊÇ·ñ´æÔÚ£¬Èç¹û²»´æÔÚ£¬Æä»á´¦ÓÚÆÚ´ý״̬£¬Ö±µ½Ö¤ÊéÎļþ°²×°Íê³É¡£·ñÔò¿ªÊ¼ÅäÖÃÊÂÇéĿ¼¡¢ÉèÖÃÊðÀíµØÖ·¡¢ÉèÖÃTorÍøÂçµØÖ·¡¢»ñÈ¡ÍâÍøIPµØÖ·¡¢MACµØÖ·¡¢ÍøÂçÃû³ÆµÈÐÅÏ¢¡£ÏÂͼΪ²¿ÃÅ°²×°ÐÅÏ¢¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´´´½¨ÊÂÇéĿ¼/var/run/xxm/¼°/var/run/xxw²¢¿ªÆôÖ÷Ñ­»·£¬Ïò¿ØÖƶËÇëÇó¿ØÖÆÃüÁî¶øÇÒÖ´ÐÐÏàÓ¦µÄ¿ØÖƹ¦Ð§¡£

        ¿ØÖÆÃüÁîµÄÇëÇóÓÐÁ½ÖÖ·½Ê½£¬Ò»ÖÖÊÇͨ¹ýsocks5ÊðÀí·½Ê½£¬Ò»ÖÖÊÇͨ¹ýTorÍøÂçÇëÇó¡£Í¨¹ýsocks5ÊðÀíÇëÇóµÄC&CµØÖ·ÈçÏÂ(ÔÚа汾ÖÐ91.121.109.209±»ÒƳý)£º

        91.121.109.209

        217.12.202.40

        94.242.222.68

        ͨ¹ýTorÍøÂçÇëÇóµÄµØÖ·ÈçÏ£¨ÔÚа汾ÖС±zuh3vcyskd4gipkm.onion/bin32/update.php¡±±»ÒƳý£©£º

6b57dcnonk2edf5a.onion/bin32/update.php

zuh3vcyskd4gipkm.onion/bin32/update.php

tljmmy4vmkqbdof4.onion/bin32/update.php

        ÕâÁ½ÖÖ·½Ê½µÄÇëÇó¶¼ÊÇͨ¹ýsslЭÒé½øÐеġ£ÇëÇóÍê³Éºó£¬¶ñÒâ´úÂë½âÎöÏàÓ¦Êý¾Ý¶øÇÒÌáÈ¡³ö¿ØÖÆÃüÁîºÍ¿ØÖƲÎÊýÐÅÏ¢¡£ÆäʵÏÖµÄÔ¶³Ì¿ØÖÆÃüÁîºÍ¿ØÖƲÎÊýÐÅÏ¢ÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ´Ó¸ÃºóÃÅʵÏÖµÄÔ¶³Ì¿ØÖƹ¦Ð§ÎÒÃÇ¿ÉÒÔÍƲâ¸ÃºÚ¿ÍµÄ¶¯»ú£º

        (1)  ºÍÆäËûºóÃÅÒ»Ñù£¬ºÚ¿ÍÏ£ÍûÄܹ»Í¨¹ýÔ¶³ÌshellÃüÁî¶ÔÉ豸½øÐÐÍêÈ«µÄ¿ØÖÆ¡£

        (2)  ºÚ¿Í¿ÉÒÔÔÚÒ»¶¨Ê±»ú¶ÔÕâЩÉ豸½øÐÐÆÆ»µÐÔ²Ù×÷£¬Ê¹ÆäÎÞ·¨ÔÙ´ÎʹÓá£

        (3)  ÎªÁËÒþ²ØÆä¿ÉÒɵĿØÖÆÁ÷Á¿£¬½ÓÄÉsocks5ºÍTorÌÓ±ÜIDS¼à²â¡£

        (4)  ¿ÉÒÔÁé»îµÄÅäÖÃÆäÔÚTorÍøÂçÖеÄC&C·þÎñÆ÷ÒÔ¼°ÊðÀí·þÎñÆ÷

        (5)  ÄÜÌṩÀ©Õ¹Ä£¿éµÄÏÂÔØÓëÖ´ÐеIJÙ×÷¡£

        (6)  ¿ÉÁé»îÅäÖÃÁ¬½ÓC&CµÄƵÂÊ£¬Ìá¸ßÆä»î¶¯µÄÒþ±ÎÐÔ¡£

        ´ËÍ⣬¸Ã½×¶ÎµÄ×îжñÒâ´úÂëÓнϴóµÄ±ä»¯£¬²»½ö¶Ô´úÂë×öÁËÓÅ»¯¡¢È¥³ýÁËÈÕÖ¾ÐÅÏ¢£¬»¹¸Ä±äÁ˲¿ÃÅ¿ØÖÆÃüÁîµÄ¹¦Ð§£¬ºÃ±ÈkillÃüÁîÓÃÓÚ½áÊø½ø³Ì¼°ÇåÀíÆäÏÂÔصIJå¼þ£¬ÐÂÔö¼ÓÁËupdateÃüÁîºÍrestartÃüÁî¡£²»ÑÔ¶øÓ÷£¬updateÃüÁîÓÃÓÚ¸üÐÂÑù±¾£¬restartÃüÁîÓÃÓÚÖØÆôÑù±¾Ö´ÐС£Í¬Ê±ÒƳýÁËseturl¡¢proxyÃüÁî¡£

µÚÈý½×¶Î£ºÀ©Õ¹×é¼þ

        µÚÈý½×¶ÎÄ¿Ç°ÒѾ­·¢ÏÖ´óÁ¿µÄ×é¼þ£¬ÆäÖаüÂÞÒ»¸öΪMIPSƽ̨µÄÁ÷Á¿Ðá̽Æ÷¡¢Ò»¸öÓÃÓÚÆÆ»µÉ豸µÄdstrÄ£¿é¡¢Ò»¸öÓÃÓÚ½øÐй㷺HTTPÁ÷Á¿Ðá̽ºÍ¼à¿ØµÄsslerÄ£¿é£¬»¹ÓÐһЩ¸¨ÖúÐÔÄ£¿éÈ磺Tor client¡¢mikrotik.o¡¢torrc¡¢ip_tables.ko¡¢iptable_filter.ko¡¢iptable_nat.koµÈ¡£¸¨ÖúÐÔÄ£¿éÈçTor¿Í»§¶ËÓÃÓÚÖ§³ÖµÚ¶þ½×¶ÎµÄTorÍøÂçͨÐÅ¡£Tor¹¤³ÌÌáʾ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÓÉÓÚÆäΪ³ß¶ÈµÄTor¿Í»§¶Ë£¬²»¾ß±¸¶ñÒ⹦Ч£¬Òò´ËÎÒÃǽö½ö·ÖÎöºËÐĵÄÈý¸öÄ£¿é¡£

        1¡¢MIPSƽ̨µÄTCPÁ÷Á¿Ðá̽Ä£¿é

        ¸ÃÄ£¿éΪMIPSƽ̨£¬ÆäÖ÷Ҫͨ¹ý´ÓԭʼÊý¾Ý°üÖйýÂ˳öTCP/IPÊý¾Ý°ü£¬¶øÇÒͨ¹ý¶ÔTCPµÄpayloadÊý¾Ý½øÐйýÂË£¬¼ìË÷ÆäÖеÄÃô¸ÐÐÅÏ¢´æ´¢ÆðÀ´¡£

        ¸ÃÁ÷Á¿Ðá̽Ä£¿éͨ¹ýµÚ¶þ½×¶Î¶ñÒâ´úÂëÔ¶³ÌÏÂÔز¢Æô¶¯Ö´ÐУ¬ÆäÆô¶¯ÔËÐвÎÊýÈçÏ£º

        {Ä£¿éÃû} DstDir Unkownagr ModbusServer

        ÆäÖеÚÒ»¸ö²ÎÊýΪÐá̽Êý¾ÝµÄ´æ·Å·¾¶£¬µÚ¶þ¸ö²ÎÊýδʹÓ㬵ÚÈý¸ö²ÎÊýΪmodbus serverµÄIPµØÖ·¡£

        ¸ÃÄ£¿éÆô¶¯ºó²¢Ã»ÓÐ×ö¹ý¶àÌرðµÄÊÂÇ飬³õʼ»¯»·¾³ºóÖ±½Óµ÷ÓÃÁ÷Á¿½ØÈ¡º¯Êý½øÐÐÁ÷Á¿Ðá̽¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ͬÑù¶þ½øÖÆ·¨Ê½Öв»´øÈκηûºÅÎļþ£¬º¯ÊýÓÉÎÒÃÇ·ÖÎöÍêºó½øÐÐÁËÖØÃüÃû¡£¸Ãº¯ÊýÖ÷Òª´´½¨Ò»¸öԭʼsocket¶øÇÒ½ÓÊÕµ±Ç°É豸Ëùͨ¹ýµÄԭʼÊý¾ÝÁ÷¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´¶ñÒâ´úÂë»áƾ¾ÝTCP/IPÍ·²¿¸ñʽʶ±ð³öTCPÊý¾Ý°üÒÔ½øÐнøÒ»²½µÄ´¦Öá£

        Ê×ÏȸÃÄ£¿éÖ»ÌåÌùÊý¾Ý°ü³¤¶È´óÓÚ0x96¸ö×Ö½ÚµÄԭʼÁ÷Êý¾Ý£¬Ò²¾ÍÊÇ˵³ýÈ¥TCP/IPЭÒéÍ·²¿µÄ³¤¶ÈµÄ0x36¸ö×Ö½Ú£¬¸ÃÄ£¿é½ö½ö¼àÊÓ´óÓÚ0x60¸ö×Ö½ÚµÄTCP payloadÊý¾Ý¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¶ÔÓÚTCP payloadÊý¾Ý´óÓÚ0x60¸ö×Ö½ÚµÄÊý¾Ý°ü£¬¸ÃÄ£¿é»á½âÎöIP¡¢TCPЭÒ飬¶øÇÒͨ¹ýÄ¿µÄ¶Ë¿Ú502Åж¨µ±Ç°Á÷Á¿Êý¾ÝÊÇ·ñÊǹ¤¿ØµÄmodbus TCPЭÒé°ü£¬Èç¹ûÊÇ£¬ÇÒµ±Ç°Êý¾Ý°üµÄÄ¿µÄIPΪÔËÐвÎÊýÖÐÖ¸¶¨µÄIPµØÖ·£¬¸ÃÄ£¿é±ã»á½«¸ÃÊý¾Ý°üÖеÄÔ´IP¡¢Ä¿µÄIP¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú¼Ç¼ÏÂÀ´¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÆäÖмǼµÄÐÅÏ¢¸ñʽÈçÏ£º

        *modbus*

        Ô´IP:Ô´¶Ë¿Ú->Ä¿µÄIP:Ä¿µÄ¶Ë¿Ú(È磺192.168.1.5:2243->192.168.1.3:503)

        ¸ÃÐÅÏ¢¼Ç¼ÔÚÎļþ%workdir%/rep_[time].bin¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Èç¹ûµ±Ç°Ð­Òé²»ÊÇmodbusЭÒ飬¸ÃÄ£¿é»áƾ¾ÝÒÑÓеĹæÔò½øÐйýÂË£¬ÕÒ³öÆäÌåÌùµÄÁ½ÀàÊý¾Ý£ºÒ»ÖÖΪЯ´øÓÐÑéÖ¤ÐÅÏ¢HTTPÊý¾Ý°ü£¬Ò»ÖÖÊÇЯ´øÓеǼÐÅÏ¢µÄHTTPÇëÇóÊý¾Ý¡£ÆäÖÐÌáÈ¡ÑéÖ¤Êý¾ÝµÄÒªº¦×ÖΪ"Authorization: Basic¡±£¬Ò»µ©ÕÒµ½¸ÃÐÅÏ¢£¬¸ÃÄ£¿é»á½«µ±Ç°Ðá̽µ½µÄÊý¾Ý°üÖ±½Ó¼Ç¼µ½Îļþ%workdir%/rep_[%time%].binÖС£

        ÌáÈ¡µÇ¼ÐÅÏ¢µÄÒªº¦×ÖÈçÏ£º

        Óû§ÃûÒªº¦×Ö£º"User="¡¢"user="¡¢"Name="¡¢"name="¡¢"Usr="¡¢"usr="¡¢"Login="¡¢"login="

        µÇ¼ÃÜÂëÒªº¦×Ö£º"Pass="¡¢"pass="¡¢"Password="¡¢"password="¡¢"Passwd="¡¢"passwd="

        ´ËÍâҪ˵Ã÷µÄÊÇ£¬Êý¾Ý°üÖÐÖ»ÒªÂú×ãÈçÏÂÌõ¼þ£¬¸ÃÄ£¿é±ã»áÅ×Æú£º

        (1)  Êý¾Ý°üµÄÄ¿µÄIPΪÄ£¿éÔËÐвÎÊýËùÖ¸¶¨µÄIP¡£

        (2)  Êý¾Ý°üµÄÔ´¶Ë¿ÚСÓÚ1024¡£

        (3)  Êý¾Ý°üµÄÔ´¶Ë¿ÚΪ8080/8088¡£

        (4)  TCP payloadÊý¾Ý³¤¶ÈСÓÚ0x14¡£

        (5)  TCP PayloadÊý¾Ý°üÖаüÂÞÓÐ"<?xml"¡¢">"¡¢"Basic Og=="¡¢"/tmUnblock.cgi"¡¢"Password required"¡¢"<div¡±¡¢"<form"¡¢"<input"¡¢"{"¡¢"}"¡¢"200 OK"¡¢".get"¡¢"<span "¡¢"<SPAN "¡¢"<DIV "µÈ¡£

        2¡¢ssler HTTPÐá̽Óë¼à¿ØÄ£¿é

        ¸ÃÄ£¿éÖ÷ÒªÕë¶ÔHTTP²ãʵʩԽ·¢¸»ºñºÍÇ¿´óµÄ´¦Öã¬ÆäÌṩÓÐHTTPÁ÷Á¿Öض¨Ïò¡¢HTTPÁ÷Á¿¼à¿ØÓë½ØÈ¡¡¢Á÷Á¿½Ù³ÖÓë¸Ä¶¯¡¢¶¨Ïò×¢ÈëJSÒÔ½øÐо«×¼¹¥»÷µÈ¹¦Ð§¡£ÆäÓɵڶþ½×¶ÎµÄ¶ñÒâÄ£¿éÆô¶¯ÔËÐУ¬ÔËÐвÎÊý˵Ã÷ÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Ê×ÏȸÃÄ£¿é»áʹÓÃinsmodÃüÁî°²×°Èý¸öiptableÏà¹ØµÄÄÚºËÄ£¿é (ip_tables.ko¡¢iptable_filter.ko¡¢ iptable_nat.ko)£¬Í¨¹ýÕâÈý¸öÄ£¿é£¬¶ñÒâ´úÂë¿ÉÒÔ½«×Ô¼ºµÄ¹æÔòÅäÖõ½iptableÖÐÈ¥ ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´Ö´ÐÐÈçÏÂÃüÁËùÓÐ80¶Ë¿ÚµÄÁ÷Á¿Öض¨Ïòµ½ÆäËù¼àÌýµÄ8888¶Ë¿ÚÉÏ£º

        iptables -I INPUT -p tcp --dport 8888 -j ACCEPT

        iptables -t nat -I PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8888

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ΪÁ˱£Ö¤¸Ã¹æÔò²»»á±»É¾³ý£¬¸ÃÄ£¿é»áÿ¸ô5·ÖÖÓ¸üÐÂÒ»´Î¸Ã¹æÔò¡£

        ¸ÃÄ£¿é»á¹Ø×¢ËùÓÐ80¶Ë¿ÚÉϵÄÊý¾Ý£¬°üÂÞÁ÷Ïò·þÎñÆ÷¶ËºÍÁ÷Ïò¿Í»§¶ËµÄÊý¾Ý¡£ÔÚ´¦ÖÃÁ÷Ïò·þÎñÆ÷¶ËµÄÊý¾Ýʱ£¬ÎªÁË×î´ó»¯µÄ¼à¿Øµ½Ãô¸ÐÊý¾Ý£¬Æä»á¶ÔHTTPÇëÇóµÄÊý¾Ý½øÐÐÒ»¶¨¸Ä¶¯¡£ÔÚ´¦ÖÃÁ÷Ïò¿Í»§¶ËµÄÏìÓ¦Êý¾Ýʱ£¬Í¬Ñù»á¶ÔÊý¾Ý½øÐиĶ¯¶øÇÒƾ¾ÝÆô¶¯²ÎÊýµÄÖ¸¶¨À´¶ÔÌض¨Ä¿±êʵʩ¾«×¼µÄJS×¢È룬ÈëÇÖµ½¾ßÌå¿Í»§¶ËÖ÷»úÉÏ£¬Ò²¿ÉÒÔÊÇÄÚÍøµÄ°ì¹«Ö÷»úÉÏ¡£

        £¨1£©¶ÔÇëÇóÊý¾ÝµÄ´¦ÖÃ

        Ê×ÏÈ£¬¸ÃÄ£¿éΪÁËÄܹ»×î´óÏ޶ȵļà¿Øµ½Á÷Á¿£¬Æä»á½«ËùÓÐÇëÇóÊý¾ÝµÄ"https://"¸Ä¶¯Îª"http://"¡£ÎªÁËÈ·±£HTTP´«ÊäµÄÊý¾Ý¶¼Îª¿É´¦ÖÃÊý¾Ý£¬»áÐ޸ġ±Accept-Encoding¡±µÄÖµ£¬ÒÔ¼°ÐÞ¸ÄConnectionµÄ·½Ê½£¬¾ßÌå´¦Ö÷½Ê½ÈçÏ£º

        i. ½«ÇëÇóÊý¾ÝÖеÄËùÓÐhttps¸Ä¶¯Îªhttp£¬ÒÔ·½±ã¼à¿Ø²¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÈçµÇ¼ƾ֤µÈ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ii. Èç¹ûHTTPÇëÇóÖаüÂÞÓС±Connection: keep-alive¡±£¬½«»á±»Ì滻Ϊ¡±Connection: close¡±¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        iii. Èç¹ûHTTPÇëÇóÖÐ,HTTPÍ·ÖаüÂÞÓÐgzipÖµµÄ¡±Accept-Encoding¡±Í·²¿Óò(ÅųýurlΪjpg¡¢jpeg¡¢png¡¢gif¡¢css¡¢js¡¢ttf¡¢woffÎļþ)£¬Æ佫»áת»¯Îª¡±Accept-Encoding: plaintext/none¡±£¬ÕâÑùÇëÇóµÃµ½µÄÊý¾Ý±ã²»»á±»·þÎñÆ÷¶ËѹËõ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Ëæºó£¬¸Ã×é¼þ¿É¶Ô½ØÈ¡µÄÁ÷Á¿½øÐйýÂ˲¢½«Ïà¹ØÊý¾ÝÉú´æµ½É豸ÖС£Ê×ÏÈÈç¹û¡±dump:domain¡±²ÎÊý±»Ö¸¶¨£¬httpÇëÇóµÄurl¡¢port¡¢http header¶¼ÊÐÉú´æÔÚÖ¸¶¨µÄÎļþÖС£Èç¹ûÔÚdump²ÎÊýÖÐûÓÐÖ¸¶¨¾ßÌåÖµ(domain×Ö·û´®Îª¿Õ)»òÕßdump²ÎÊýûÓÐÖ¸¶¨Ê±£¬Æä»ádump°üÂÞÓÐÌض¨ÐÅÏ¢httpÇëÇóÐÅÏ¢¡£Æäͨ¹ýURLÀ´Åж¨µ±Ç°ÇëÇóÊÇ·ñÊÇÆäÌåÌùµÄÇëÇó£¬Èç¹ûURLÖаüÂÞÓÐÒªº¦×Ö£º

¡±sername=¡±¡¢¡±ser=¡±¡¢¡±ame=¡±¡¢¡±ogin=¡±¡¢¡±ail=¡±¡¢¡±hone=¡±¡¢¡±session%5Busername¡±¡¢¡±session%5Bpassword¡±¡¢¡±session[password¡±±ã»ádumpÇëÇóµÄÍ·²¿ÐÅÏ¢µ½Ö¸¶¨µÄÎļþÖС£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÁíÍ⣬¶Ôaccounts.google.com·¢Ë͵ÄPOSTÇëÇó£¬Ö»ÒªÆäÖаüÂÞÓÐ×Ö·û´®¡±signin¡±,¶¼Êб»dumpÏÂÀ´¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        £¨2£©¶ÔÏìÓ¦ÐÅÏ¢µÄ´¦ÖÃ

        ËùÓÐHTTPÇëÇóµÃµ½µÄÏìÓ¦Êý¾Ý¶¼Êб»´¦Öã¬Æä´¦Ö÷½Ê½ÈçÏ£º

        i.  ÏìÓ¦ÐÅÏ¢ÖÐLocationµÄÖµÈç¹ûÊÇ¡±https://¡±£¬Ôò±»Ì滻Ϊhttp://¡£

        ii. Èç¹ûÏìӦͷ²¿ÖаüÂÞÓÐAlt-Scv¡¢Vary¡¢Content-MD5¡¢content-security-policy¡¢X-FB-Debug¡¢public-key-pins-report-only¡¢Access-Control-Allow-Origin£¬±ã»á±»×è¶Ï£¬Ò²¾ÍÊÇ˵£¬ÇëÇó·½ÎÞ·¨µÃµ½ÏìÓ¦¡£

        iii. DumpËùÓÐÇëÇó°üµÄÊý¾Ýµ½µ±µØ£¬ÆäÖаüÂÞhttps://ºÍhttp://¡£

        iv. Èç¹û²ÎÊý¡±site:domain¡±Ö¸¶¨ÁËÓòÃûÒªº¦×Ö»òÕßÓòÃûµÄÒ»²¿ÃÅ£¬Æä»á½«Ò»¶Îjavascript½Å±¾×¢Èëµ½ËùÓаüÂÞÓеġ±Content-Type: text/html¡± »òÕß¡±Content-Type: text/javascript¡±ÏìÓ¦Êý¾ÝµÄmsgbodyÖС£Æä×¢ÈëÒªÁ죺Ê×ÏÈÏìÓ¦µÄmsgbodyÊý¾ÝÖбØÐë°üÂÞ×Ö·û´®¡±<meta name= ¡­ >¡±¶øÇÒ³¤¶È±ØÐë´óÓÚ²ÎÊý¡±hook:¡±ËùÖ¸¶¨µÄ×Ö·û´®³¤¶È¡£Èç¹ûÂú×ãÌõ¼þ£¬×Ö·û´®¡±<meta name= ¡­ >¡±½«»á±»Ìæ»»³ÉΪ¡±<script type="text/javascript" src="[hook value]">¡±£¬µ±Ç°Êܺ¦ÕßIP¼°Æä·ÃÎʵÄÍøÕ¾ÓòÃû½«»á¼ÓÈëµ½ÄÚ²¿µÄÒ»¸ö°×Ãûµ¥ÖУ¬ÒÔ·ÀÖ¹Öظ´×¢È룬°×Ãûµ¥Ã¿4Ìì»á±»Çå¿ÕÒ»´Î¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÔÚÏìÓ¦Êý¾ÝÖУ¬¶ñÒâÄ£¿é»áÌáȡÿ¸öÁ´½ÓÖеÄÓòÃû£¬¶øÇÒ½«Æä¼ÓÈëµ½½ØÈ¡ÁбíÖУ¬Õâ¸ö½ØÈ¡ÁбíÖÐËùÓеÄhttpsºÍhttpÇëÇó¶¼ÊÐƾ¾Ý¡°£¨1£©¶ÔÇëÇóÊý¾ÝµÄ´¦Öᱵķ½Ê½½øÐд¦Öá£Ä¬ÈÏÇé¿öÏ°üÂÞÓÐ www.google.com¡¢ twitter.com¡¢ www.facebook.com¡¢www.youtube.com¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        3¡¢ É豸ÆÆ»µÄ£¿é£¨Destroy module£©

        ÓÉÓÚÀÏ°æ±¾µÄµÚ¶þ½×¶ÎÄ£¿éµ¥´¿µÄÖ»ÊǼòµ¥²Á³ýÉ豸mtdblock0µÄÇ°5000¸ö×Ö½ÚÒÔÆÆ»µÉ豸£¬Óкܴó¼¸ÂÊ»áʧ°Ü£¬Òò´Ëа汾µÄµÚ¶þ½×¶ÎÄ£¿é½«killÖ¸ÁîµÄÆÆ»µÐÔ¹¦Ð§È¡Ïû£¬²¢½ÓÄɲå¼þÄ£¿éµÄ·½Ê½À´ÊµÏÖ¡£¸Ã²å¼þÄ£¿é²»½ö¸ïÐÂÁËÆÆ»µÉ豸¹¦Ð§£¬¶øÇÒ»¹ÌṩÁ˺ۼ£ÇåÀíµÄ¹¦Ð§¡£ÆäÄ¿µÄ²»½öÈÃÉ豸ÎÞ·¨»Ö¸´£¬¶øÇÒ¼´±ã»Ö¸´ÁËÒ²ÎÞ·¨È¡Ö¤»ñÈ¡¶ñÒâ´úÂëÏà¹ØºÛ¼£¡£

        Ä£¿éÆô¶¯ºóÊ×ÏÈɾ³ý×ÔÉíÎļþ£¬È»ºóÇ¿ÖƹرÕËùÓаüÂÞ"vpnfilter"¡¢"security"¡¢"tor"Òªº¦×ֵĽø³Ì¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½ÓÏÂÀ´ÇåÀíµôËùÓкۼ£Îļþ£¬ÆäÖаüÂÞÓÐÖ¤ÊéÎļþ¡¢Tor¿Í»§¶ËÏà¹ØÎļþ¡¢°æ±¾ÐÅÏ¢ÎļþµÈ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¸ÃÄ£¿é»¹»á±éÀúmtd·ÖÇø£¬²¢Ç¿ÖƲÁ³ýÕû¸öFLASH¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ×îºó£¬Æä½ÓÄÉ¡±"rm -rf /*"¡±Ç¿ÖƵݹéɾ³ýÎļþϵͳÉϵÄËùÓÐÎļþ£¬²¢ÖØÆôÉ豸¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ËÄ¡¢×ܽá

        ͨ¹ý·ÖÎöÎÒÃÇ¿ÉÒÔ¿´³ö£¬¸Ã¶ñÒâ´úÂë¹¥»÷ÊÖ·¨ÒþÃظßÃ÷£¬Æä²»½ö½ÓÄÉÊðÀí+Tor+SSLµÄ·½Ê½ÒÔÌÓ±ÜÍøÂçÁ÷Á¿µÄ¼à²â£¬¶øÇÒ»¹ÓжàÖؼÆıÓÃÓÚÈ·±£ºËÐÄ×é¼þ(µÚ¶þ½×¶Î¶ñÒâ´úÂë)µÄÀÖ³ÉÏ·¢¡£Ê×ÏȽÓÄÉÁËHTTPµÄ·½Ê½½«C&C´æ·ÅÓÚ¡±direct¡±»òÕß¡±location¡±×Ö¶ÎÖУ¬Èç¹ûÕâÖÖ·½Ê½±»×è¶ÏÔò½ÓÄÉͼƬÒþд¼¼Êõ½«C&C´æ´¢ÓÚEXIFÖУ¬Èç¹û´æ´¢C&CµÄͼƬÁ´½ÓʧЧ£¬Æ仹ÔÚ´úÂëÖÐÁôÁËÒ»¸ö¡±SYN¡±ºóÃÅ£¬Í¨¹ý¡±SYNËíµÀ¼¼Êõ¡±À´´«ÊäC&C¡£ÕâÖÖ¿ÉÒÔ˵ÊǺڿͽÓÄɵÄÒ»ÖÖ½ÏΪ¸ßÃ÷Çҷdz£±£ÏյļÆı£¬ÎªÆäÐж¯ÔÚ±»·¢ÏÖÉõÖÁÊDZ»×è¶ÏºóÉèÖÃÁ˶àÖر£ÏÕ£¬Ò²±ãÓÚÔÚºÚ¿Í·¢ÏÖ±»×è¶Ïºó½øÐпìËÙÇл»£¬¼«´óµØÌá¸ßÁËÆä¿ØÖƵij־ÃÐÔºÍÁé»îÐÔ¡£

        ÎÒÃÇ»¹¿ÉÒÔ¿´µ½£¬Ñ¸ÃÍÉú³¤µÄÎïÁªÍøÉ豸Ҳ¿ªÊ¼Äð³É¸ß¼¶Íþв×éÖ¯µÄÒ»À๥»÷ÏòÁ¿£¬ÆäÊÔͼͨ¹ýÕâЩÉ豸À´ÊÕ¼¯Ç鱨£¬°üÂ޵Ǽƾ֤ÒÔ¼°¹¤¿ØÉèÊ©Ïà¹ØµÄÖØÒªÐÅÏ¢£¬Í¨¹ýÁé»îµÄÄ£¿é»¯¼Ü¹¹£¬¿Éƾ¾ÝÏà¹ØÇ鱨¶ÔÌض¨Ö÷»úʵʩ¾«×¼¹¥»÷»òÕ߶ԴóÁ¿É豸ʵʩ¼«¾ßÆÆ»µÐԵĹ¥»÷£¬ÆäΣº¦ÐԷdz£Ö®´ó¡£

        ½¨Ò鳧É̽«¼ì²â¹æÔò£¨TalosÒѾ­¹ûÈ»ÁË100¶àÌõsnort¹æÔò£©¼ÓÈëµ½Á÷Á¿¼ì²âÉ豸ÖУ¬Èç¹ûÖ§³ÖԭʼÁ÷Á¿¼ì²â£¬Ò²¿ÉÀûÓá°SYNËíµÀ¼¼Êõ¡±ÖеÄÌØÕ÷½øÐÐÔ½·¢Éî¶ÈºÍ¾«È·µÄ¼ì²â¡£Ò»µ©·¢ÏÖÊÜѬȾÉ豸£¬½¨Òé½ÓÄÉÓ¦¼±¼Æı¶ÔÉ豸½øÐд¦Ö㨺ñȶÔÉ豸½øÐжÏÍø¶øÇÒ¸´Î»»Ö¸´µ½³ö³§Ä£Ê½¡¢¸üÐÂ×îй̼þ£©£¬Í¬Ê±½øÒ»²½¼ì²éÄÚÍøÖ÷»úÊÇ·ñÓб»¹¥»÷²¢ÇëרҵÈËÊ¿½øÐд¦Öá£

 

 

IOC:

µÚÒ»½×¶ÎÉæ¼°µÄÏà¹ØURL:

photobucket[.]com/user/nikkireed11/library

photobucket[.]com/user/kmila302/library

photobucket[.]com/user/lisabraun87/library

photobucket[.]com/user/eva_green1/library

photobucket[.]com/user/monicabelci4/library

photobucket[.]com/user/katyperry45/library

photobucket[.]com/user/saragray1/library

photobucket[.]com/user/millerfred/library

photobucket[.]com/user/jeniferaniston1/library

photobucket[.]com/user/amandaseyfried1/library

photobucket[.]com/user/suwe8/library

photobucket[.]com/user/bob7301/library

toknowall[.]com

µÚ¶þ½×¶ÎÉæ¼°µÄÏà¹ØIP¼°Á´½Ó£º

91.121.109[.]209

217.12.202[.]40

94.242.222[.]68

82.118.242[.]124

46.151.209[.]33

217.79.179[.]14

91.214.203[.]144

95.211.198[.]231

195.154.180[.]60

5.149.250[.]54

91.200.13[.]76

94.185.80[.]82

62.210.180[.]229

62.210.180[.]229

91.200.13[.]76

23.111.177[.]114

6b57dcnonk2edf5a[.]onion/bin32/update.php

tljmmy4vmkqbdof4[.]onion/bin32/update.php

zuh3vcyskd4gipkm[.]onion/bin32/update.php

4seiwn2ur4f65zo4.onion/bin256/update.php

zm3lznxn27wtzkwa.onion/bin16/update.php

×îÐÂÊÜѬȾµÄÉ豸ÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

²Î¿¼Á´½Ó£º

https://blog[.]talosintelligence.com/2018/05/VPNFilter.html

https://blog.talosintelligence.com/2018/06/vpnfilter-update.html