ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö
Ðû²¼Ê±¼ä 2019-05-18½üÆÚ£¬¶«Éƽ̨ADLab¼à²âµ½Ò»ÅúÒÉËÆÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄÕþ¸®»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿ÃŵĶ¨Ïò¹¥»÷»î¶¯£¬ºÚ¿Í×é֯ͨ¹ý½á¹¹¶ñÒâOffice WordÎĵµ²¢ÅäºÏÓã²æÓʼþÌᳫ¶¨Ïò¹¥»÷£¬ÒÔ¡°¼òÀú¸üС±×÷ΪÓÕ¶üÎĵµÏò¹¥»÷Ä¿±êÖ²Èë¼äµýľÂí£¬´ÓÊÂÇ鱨ÊÕ¼¯¡¢Ô¶¿Ø¼àÊÓ¼°ÏµÍ³ÆÆ»µµÈ¶ñÒâÐж¯¡£ÎÒÃǽ«ÍÁ¶úÆäºÚ¿ÍµÄ´Ë´Î¹¥»÷Ðж¯³ÆΪ¡°ºÚʨÐж¯¡±¡£
ͨ¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷Ïà¹ØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷À´Ô´ÓÚÒ»ÅúÒþÃضàÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¸Ã×éÖ¯ÊÇÒ»¸öÃñ×åÖ÷ÒåÉ«²Ê·Ç³£Å¨ºñµÄºÚ¿Í×éÖ¯£¬Ôø¹¥ÏÝÆäËû¹ú¼ÒµÄ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂÆä×éÖ¯µÄÃû³Æ£¬ËæºóÏûʧÁ˶àÄê¡£ Èç½ñͨ¹ýÎÒÃǶԡ±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯¼£Ïó¡£±¾´Î¹¥»÷¹ý³ÌÖУ¬¸ÃºÚ¿Í×éÖ¯½ÓÄÉÉø͸Êֶι¥Ïݶą̀·þÎñÆ÷²¢½«Æä×÷Ϊ´æ·Å¹¥»÷´úÂëµÄÌø°å¡£
1Íþв·ÖÎö
1.1 ¹¥»÷Ä¿±ê·ÖÎö
´ÓÄ¿Ç°Ëù»ñÈ¡µÄ¹¥»÷Ñù±¾ºÍÍþвÇ鱨£¬¿ÉÒÔ¿´³ö±¾´Î¹¥»÷»î¶¯²¢Ã»Óдó¹æÄ£µÄ½øÐУ¬Ä¿Ç°»¹´¦ÓÚ¹¥»÷ÊÔ̽½×¶Î£¬µ«ÊÇ´ÓÆäͶ·ÅµÄÓÕ¶üÎĵµ¿ÉÒÔ¼òµ¥¼òÖ±¶¨Æä¹¥»÷Ä¿±êËø¶¨ÔÚÎ÷°àÑÀÓïϵµÄ¹ú¼Ò¡£ÕâЩÓÕ¶üÎĵµÐÎÈ磺¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±£¨¼òÀú¸üРº£Ã·°¢ÀïÑÇ˹£©¡¢¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±(¼òÀú¸üРµ¤Äá¶û°ÂµÙ×È)¡¢¡°Michelle Flores - Curriculum Actualizado.doc¡±(Ã×Ъ¶û¸¥ÂåÀ×˹-¼òÀú¸üÐÂ)¡¢¡°Jose Trujillo.doc¡±(ºÎÈûÌسϣÂÔ)µÈµÈ£¬ËüÃǾù½ÓÄÉÎ÷°àÑÀÓïÀ´½á¹¹Ò»¸ö´ø¶ñÒâºê´úÂëµÄ¼òÀúÎļþ¡£ÒÔ´ËÀ´¶ÔÄ¿±êÈËÁ¦²¿ÃŽøÐй¥»÷£¬ÒÔÓÕʹÏà¹ØÈËÔ±Ö´ÐжñÒâ´úÂë½ø¶ø´Óʼäµý»î¶¯¡£
ÔÚÎÒÃÇ·ÖÎöÕâÅúÓÕ¶üÎĵµÊ±£¬»¹·¢ÏÖÒ»¸öÓÐȤµÄÏÖÏó£¬ÄǾÍÊÇÐí¶àÓÕ¶üÎĵµÖаüÂÞÁËÎĵµ×÷ÕßÐÅÏ¢ºÍ×îºóÒ»´ÎÉú´æÕßÐÅÏ¢£¬¶øÇÒÕâЩÐÅÏ¢¾ùΪÀàËƲÆÕþ²¿¡¢Ðŷþ֡¢SCG£¨Southern Connecticut Gas£©µÈµÈÓëÕþ¸®²¿ÃÅÏà¹ØµÄÐÅÏ¢¡£Í¨¹ýÎÒÃÇʵ¼Ê²âÊÔ·¢ÏÖ£¬ÕâЩÐÅÏ¢¾ù»áÔÚÎĵµÐ޸ĺóÄð³Éµ±Ç°·ÃÎÊÕßofficeµÇ½ÕË»§Ãû»òÕßÖ÷»úÃû£¬¶øÇÒÓÐÐĵÄÈË»¹¿ÉÒÔ¶ÔÆä½øÐÐÈÎÒⶨÖÆ¡£ÎÒÃÇÑ¡È¡¼¸¸öµäÐ͵ÄÑù±¾²¢Õë¶ÔÏà¹ØÐÅÏ¢ºÍÂß¼¹Øϵ×öÁËÈçÏÂÊáÀíºÍÍÆÂÛ£º

ÎÒÃÇͨ¹ý´´½¨ÄÚÈÝʱ¼ä¡¢×îºóÐÞ¸Äʱ¼ä¼°¹¥»÷ÎĵµÄÚ²¿µÄÂß¼¹ØϵÍÆÂÛ³öÏà¹Ø¼Ç¼ӦΪ¹¥»÷ÕßÉú´æ¡£»ùÓÚ×îºÏÀíÒÔ¼°×îÓпÉÄܵÄÍƲ⣬ÎÒÃÇÈÏΪ¹¥»÷Õß¿ÉÄÜÊÇ»ùÓÚºÚ¿Í×éÖ¯ÄÚ²¿¹æ·¶£¬½«ÎĵµµÄÏà¹ØÃû³ÆÉèÖÃΪ¹¥»÷Ä¿±ê»òÏà¹ØÐÐÒµÐÅÏ¢£¬´Ó¶øαÔì³ÉÄÚ²¿ÈËÊ¿£¬ÔÚÒ»¶¨Ë®Æ½ÉÏÆðµ½»ìÏýÊÓÌý¡¢Òþ±Î×ÔÉíµÄÄ¿µÄ¡£
ÓÉ´ËÎÒÃÇ¿ÉÒÔ¿´³ö´Ë´ÎÐж¯µÄ¹¥»÷Ä¿±êΪÎ÷°àÑÀÓïϵµØÓòµÄÕþ¸®»òÕß¹«¹²·þÎñ²¿ÃÅ£¬ËäÈ»²¢²»ÅųýÆäÓиü¶àµÄÄ¿±ê£¬ÖÁÉÙ¿ÉÒԿ϶¨µÄÊÇ´Ë´ÎÐж¯ÊÇÒ»´Î´øÓÐÕþÖÎÄ¿µÄµÄ¹¥»÷»î¶¯¡£
1.2 ºÚ¿Í×éÖ¯·ÖÎö
ÔÚ¶ñÒâ´úÂë´æ´¢Â·¾¶µÄͬĿ¼£¬ÎÒÃÇ·¢ÏÖºÚ¿Í×éÖ¯ËùÁôϵÄһЩÐÅÏ¢£¬ÏÂͼΪÆäÖÐÒ»¸öÎļþ¼Ç¼µÄÐÅÏ¢£º

¸ÃÎļþÖаüÂÞÁËһЩÉùÃ÷ÐÅÏ¢¡¢ºÚ¿Í×éÖ¯¼°ÆäÏà¹Ø³ÉÔ±£¬¶øÇÒËù½ÓÄɵÄÓïÑÔΪÍÁ¶úÆäÓÒò´ËÎÒÃÇÅж¨¸Ã×éÖ¯ÕýÊÇÔø¾»îԾһʱµÄKingSqlZºÚ¿Í×éÖ¯¡£¸Ã·þÎñÆ÷ºÜÓпÉÄÜÔÚ±»ºÚ¿Í×éÖ¯¿ØÖƺó×÷ΪÌø°å»ú»ò×ÊÔ´·þÎñÆ÷¼ÌÐøʹÓᣴËÍâͨ¹ý¶ñÒâ´úÂëʱÇø·ÖÎö·¨£¬ÎÒÃǽøÒ»²½È·¶¨¸Ã´Î¹¥»÷À´×ÔÓÚÍÁ¶úÆäºÚ¿Í¡£ÎÒÃǶÔRATÑù±¾Ö®Ç°µÄPEÎļþ¼°ÆäËûÇ°ÆÚ¹¥»÷»·½ÚÏà¹ØµÄÑù±¾µÄ±àÒëʱ¼ä×öÁËʱÇø·ÖÎö£¨ÒòΪRATÑùÔÀ´×ÔÓÚÉÏÓκڿͣ¬Òò´ËÎÒÃǺöÂÔÁ˸ÃÀàÑù±¾µÄʱÇø·ÖÎö£©¡£×îºó·¢ÏÖÕâЩ¹¥»÷Ñù±¾µÄ±àÒëʱ¼äÔÚUTCʱ¼ä21:00ÖÁ06:00Çø¼äÄÚ·ºÆðµÄƵ´Î¼«µÍ¡£¶ø¼Ù¶¨ÒÔ24:00ÖÁ08:00×÷Ϊ˯Ãßʱ¼ä£¬¹¥»÷ÕßËù´¦µÄʱÇø¿ÉÄÜ»áÔÚ¶«3Çø£¨UTC+3£©Õý¸º 1 СʱÇø¼äÄÚ£¬¶øÍÁ¶úÆäʱÇøΪ¶«ÈýÇøÕýºÃÇкϡ£
±¾´Î¹¥»÷»î¶¯¿ªÊ¼ÓÚ2019Ä꣬½ÓÄÉ´óÁ¿¹«¹²DDNS·þÎñ×ÓÓòÃû×÷ΪC2À´ÊµÊ©¹¥»÷£¬ÕâÆäÖеÄһЩÓòÃûΪ2019ÄêÐÂ×¢²áµÄ£¬Ê¹ÓõIJ¿ÃÅÓòÃûÈçÏ£º
casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net

2¹¥»÷¸ÅÊö
´Ë´ÎʼþµÄÖ÷Òª¹¥»÷»î¶¯Ê±¼äÏßÈçÏÂËùʾ:
ÆäÖУ¬ÎÒÃǶÔ2019Äê2ÔÂ7ÈÕ·¢Ïֵġ°Curriculum Vitae Actualizado Jaime Arias.doc¡±Îĵµ½øÐÐÁËÏêϸµÄ·ÖÎö£¬²¢Ïà¼Ì²¶×½µ½¹ØÁªÎĵµ¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc/ Jose Trujillo.doc¡±¡£
¹¥»÷ÕßʹÓÃÁËAPI¹þÏ£¡¢ÎÞÎļþ¹¥»÷¡¢WinrarSFX¡¢AutoIt¡¢C#»ìÏýºÍ¿þÀܽø³ÌµÈ¼¼ÊõÀ´¹æ±Ü¼ì²â²¢×ÌÈÅ·ÖÎöÈËÔ±¡£ÆäÖУ¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ÎĵµÖ²ÈëµÄľÂíÀ´Ô´×î³õÎÞ·¨È·ÈÏ£¬ÎÒÃÇÔÚÆäÖз¢ÏÖÁËÌØÕ÷×Ö·û´®¡°AVE_MARIA¡±,ÆäÓëCybaze-Yoroi ZLabÑо¿ÈËÔ±ÔÚ2018Äê12Ôµ×Åû¶µÄÕë¶ÔÒâ´óÀûijÄÜÔ´ÆóÒµ½øÐй¥»÷µÄ¶ñÒâÈí¼þÏàËƶȺܸߣ¬²¿ÃÅÄþ¾²Ñо¿Ô±ºÍ³§ÉÌÒòΪûÓÐÀֳɵĽøÐÐËÝÔ´±ãÒÔ´Ë×Ö·û´®×öΪ¸ÃľÂí¼Ò×åµÄÃû³Æ¡£¶øÎÒÃǾ¹ý¹ØÁªËÝÔ´ºÍͬԴÐÔ·ÖÎöºó·¢ÏÖ£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾Í¬RAT¹¤¾ß¡°WARZONE¡±RAT¾ßÓи߶ÈÒ»ÖÂÐÔ£¬Òò´Ë½«´ËÀà¶ñÒâ¼Ò×åÃüÃû¸üÐÂΪ¡°WARZONE¡±¡£
3¼¼Êõ·ÖÎö
3.1 ÔçÆÚ¹¥»÷Ñù±¾
´Ë´Î¹¥»÷¹ý³Ì¿ªÊ¼ÓÚÒ»¸öЯ´ø¶ñÒâºêµÄDOCÎĵµ£¬ºÚ¿Íͨ¹ýαÔì³É¼òÀúµÄͶµÝÓʼþÊֶν«´Ë¶ñÒâÎļþ·¢Ë͸ø¹¥»÷Ä¿±ê£¬µ±Ä¿±êÓû§²»É÷´ò¿ªÎĵµ±ã³ÉΪÁËÊܺ¦Õß¡£DOCÎĵµÔËÐкó»áÆô¶¯¶ñÒâºê´úÂë²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÏÂÔØEtr739.exe£¬ÀÖ³ÉÏÂÔغóÁ¢¼´Ö´ÐС£Ð½ø³Ìͨ¹ýBase64½âÂë³öÁíÒ»¸ö·þÎñÆ÷µØÖ·£¬¼ÌÐøÏÂÔضñÒâ´úÂëhqpi64.exeÖÁÁÙʱĿ¼Ï¡£¶ñÒⷨʽhqpi64.exe±ãÊÇWarzone RATµÄÊÍ·ÅÆ÷£¬Æäͨ¹ýÊÍ·ÅWarzone RATÀ´Ö´ÐкóÐø²Ù×÷£¬È罫explorer.exe×÷Ϊ¿þÀܽø³ÌÊØ»¤¡¢Óë¿ØÖƶ˽øÐÐͨÐŵȡ£
Ñù±¾ÖеĶñÒâ´úÂë´ó²¿ÃŽÓÄÉCRC32À´¼ÓÃÜÃô¸Ð×Ö´®£¬Í¬Ê±ÔÚAPIµ÷ÓÃÊÖ·¨ÉϽÓÄÉÁËAPI HashÖµ¶¯Ì¬»ñÈ¡º¯ÊýµØÖ·ºÍÄ£Äâϵͳ¿ìËÙµ÷ÓÃÁ½ÖÖ·½Ê½¡£Ê¹ÓôËÀàÊÖ·¨²»¹âÄÜÔÚÒ»¶¨Ë®Æ½ÉϼõÉÙɱÈí¾²Ì¬É¨ÃèµÄ¼ì²â£¬¶øÇÒ»¹²»Ò×±»¼à²âµ½APIµÄµ÷ÓÃ×Ù¼£¡£Í¬Ê±ÆäʹÓô¿¼ÓÃÜShellcode´úÂëÄÚ´æÖ´Ðеķ½Ê½¼ÓÔØÆäºËÐĹ¦Ð§Ä£¿é£¬Í¨¹ý¡°ÎÞÎļþ¼¼Êõ¡±Ìá¸ß×ÔÉíÒþ±ÎÐÔ£¬ÒÔ´ËÀ´¶ã±ÜÄþ¾²³§É̲éɱ¡£ÆäÓëC2·þÎñÆ÷¼äµÄͨÐÅÊý¾ÝÒ²ÒÔCR4Ëã·¨½øÐмÓÃܽø¶ø¹æ±ÜIDSϵͳµÄ¼ì²â¡£
(1)DOCÎĵµ
ÔÚAutoOpenº¯ÊýÖаüÂÞÁËÒ»´®»ìÏý¹ýµÄcmdÃüÁ¾¹ý½âÃܺóµÄ´úÂëÈçͼËùʾ£º
Õâ¶Î´úÂë»ñµÃÖ´Ðк󣬻áÖ±½Ó½ñºóÁ´½ÓµØÖ·(http[:]//linksysdatakeys.se)ÏÂÔضñÒⷨʽµ½¡°%Temp%\SAfdASF.exe¡±²¢Ö´ÐС£
(2)Payload
¸ÃPayloadÏȽ«ÉÏͼÖмÓÃܵÄÊý¾Ýͨ¹ýBase64½âÂë³öÏÂÔØÁ´½ÓµØÖ·¡°http[:]//www.gestomarket[.]co/hqpi64.exe¡±£¬È»ºó°Ñhqpi64.exe¸üÃûΪ2XC2DF0S.exe²¢Éú´æÔÚÁÙʱĿ¼Ï¡£
(3)Dropper
ÔÚºóÐøµÄ½âÃÜÒÔ¼°Ö´ÐеĹý³ÌÖУ¬´ËDropper»á°ÑÒ»¶ÎShellcode×¢Èëµ½explorer½ø³Ì²¢ÔÚÄÚ´æÖнâÃܳöRATʵÌåʹÆä²»ÂäµØ£¬×îÖÕͨ¹ýÎÞÎļþ¼¼Êõ½«RAT¼ÓÔص½ÄÚ´æÖÐÀ´Ö´ÐС£
Ìӱܼì²â
½âÃÜshellcode
×Ô½ç˵µÄ½âÃܺ¯Êý
¾¹ýÖØÖØÏÂÔز¢½âÃÜÖ®ºó£¬ÄÇôÕâ¶Î½âÃܺóµÄShellcode(PE Loader)´úÂë¾ßÌå»á×öЩʲô£¬ÏÂÃæÎÒÃÇÀ´Ò»¿ú¾¿¾¹¡£
PE Loader
ÐòºÅ |
ÄÚÈÝ |
¹¦Ð§ |
²ÎÊý1 |
¡°FYBLV¡± |
¿½±´×ÔÉíµÄĿ¼ÃûºÍÎļþÃû(Ðè½âÃܵÄ×ÊÔ´Ãû) |
²ÎÊý2 |
¡°BJU¡± |
RATÔ¶¿ØÎļþ(Ðè½âÃܵÄPEÎļþ×ÊÔ´Ãû) |
²ÎÊý3 |
¡°OPTYUPPABIVSUWNRXSNCTDW¡± |
Key |
²ÎÊý4 |
0x01£¨ÀιÌÊýÖµ£© |
δʹÓà |
¸ÃPE LoaderÊ×ÏÈÔÚÔËÐйý³ÌÖнøÐÐÁËɳÏäºÍÖ¸¶¨½ø³ÌµÄ¼ì²â£¬ÒÔ·ÀÖ¹±»×Ô¶¯»¯ÏµÍ³·ÖÎö¡£¶øÇÒƾ¾Ý×Ô´øµÄ×ÊÔ´Êý¾ÝÀ´Åж¨ÊÇ·ñʵʩפÁô±¾»úµÄ²Ù×÷ºÍ×¢ÈëÌåµÄÑ¡Ôñ¡£×îºó´ËPE Loader½«×îÖÕÑ¡ÔñµÄ¿þÀܽø³ÌµÄ¿Õ¼ä¼Ü¿Õ£¬²¢°Ñ½âÃܳöµÄRATÄ£¿éÓ³Éäµ½´Ë½ø³ÌÖÐÖ´ÐÐ(Ô±¾PEÎļþ´úÂë±»Öû»)¡£
ÔËÐл·¾³¼ì²â
ÔËÐл·¾³¼ì²â
²Ù×÷×ÊÔ´Êý¾Ý
¾¹ý·ÖÎö£¬½á¹¹ÌåÖÐÿ¸ö³ÉÔ±µÄ¾ßÌ幦Ч¿É²Î¿¼ÏÂͼ£º
ÊÍ·ÅÓëפÁô
´´½¨µÄ¿ì½Ý¼üÊôÐÔ
×îºó£¬¸ÃPE Loaderƾ¾Ý½á¹¹ÌåÖеÄdwFlagÖµÀ´Ñ¡ÔñºóÐøµÄRATÔØÌ壬Ëù¶ÔÓ¦µÄRATÔØÌåÏê¼ûÏÂ±í£º
Êý¾Ý |
½ø³ÌÃû |
0x01 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe |
0x02 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe |
0x03 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe |
0x04 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
0x05 |
C:\Windows\System32\svchost.exe |
0x06 |
C:\Windows\System32\dllhost.exe |
0x07 |
µ±Ç°ÔËÐеÄ×ÔÉí½ø³Ì |
¶øÔÚ±¾Ñù±¾ÖУ¬´Ë³ÉÔ±µÄÖµËù¶ÔÓ¦µÄÔØÌåΪµ±Ç°ÔËÐеÄ×ÔÉí½ø³Ì¡£
»ñÈ¡RAT²¢Ö´ÐÐ
½Ó×Å£¬¸ÃPE LoaderÖØд´½¨Ð½ø³Ì²¢½«ÆäÉèÖÃΪ¹ÒÆð״̬¡£È»ºóжÔش˽ø³ÌÓ³Ïñ£¬²¢°ÑÔÚÄÚ´æÖнâÃܳöµÄеÄPEÍ·²¿£¬ÒÔ¼°½ÚÊý¾ÝÒÀ´ÎдÈëµ½¹ÒÆðµÄ½ø³ÌÖУ¬×îºóÐÞ¸ÄOEP²¢Æô¶¯ÔËÐС£
(4) WARZONE RATÄ£¿é
Ô¶¿Ø·¨Ê½Warzoneºǫ́½çÃæ
»ñÈ¡C&CµØÖ·
ΪÁË·ÀÖ¹C&C±»ÇáÒ×·¢ÏÖ»òÕßÅúÁ¿ÌáÈ¡£¬¸ÃľÂí½«Æä¼ÓÃܺó´æ·ÅÔÚ¡°.bss¡±µÄ×ÊÔ´½ÚÊý¾ÝÖС£Í¨¹ý¶Ô½âÃܺ¯ÊýµÄ·ÖÎöÎÒÃÇ·¢ÏÖ£¬ÕâÀï½ÓÄÉÁËCR4Ëã·¨¡£CR4Éú³ÉÒ»ÖÖ³ÆΪÃÜÔ¿Á÷µÄαËæ»úÁ÷£¬ËüÊÇͬÃ÷ÎÄͨ¹ýÒì»ò²Ù×÷Ïà»ìºÏÀ´µ½´ï¼ÓÃܵÄÄ¿µÄ¡£½âÃÜʱÔòʹÓÃÃÜÔ¿µ÷ÖÎËã·¨(KSA)À´Íê³É¶Ô¾ÞϸΪ256¸ö×Ö½ÚÊý×ésboxµÄ³õʼ»¯¼°Ìæ»»¡£¾ßÌåÁ÷³ÌÈçÏ£º
(ÔÚ×ÊÔ´Êý¾ÝÖÐÇ°0x32¸ö×Ö½ÚÊÇÃÜÔ¿£¬ÆäÓà0x68¸ö×Ö½ÚÔòÊÇ´ý½âÃܵÄÊý¾Ý)

ÃÜÔ¿ºÍ´ý½âÃÜÊý¾Ý
4£©Ìæ»»ºóµÄsboxÊý×éÖеÄÊýÖµÈçÏÂͼ£º
5£©Í¨¹ýÌæ»»ºóµÄsboxºÍ´ý½âÃܵÄÊý¾Ý½øÐÐXORÔËËãºó£¬×îÖյõ½·þÎñÆ÷µÄhostµØÖ·"asdfwrkhl.warzonedns[.]com"¡£
Ö´ÐÐ×¢È빦Ч
½Ó×Å£¬¸ÃľÂíʹÓÃÔ¶³ÌÏ̵߳ķ½Ê½À´×¢ÈëºËÐĹ¦Ð§Shellcode´úÂ룬²¢ÔÚÆô¶¯Ô¶Ïß³ÌÖ´ÐÐʱ£¬ÐÞ¸ÄдÈëÄ¿±ê½ø³ÌÄÚ´æÆ«ÒƵÄ0x10E´¦Îª¿ªÊ¼Ö´ÐдúÂë¡£
ͨ¹ý·ÖÎöÎÒÃÇ·¢ÏÖ£¬Õâ¶Î×¢Èë´úÂëµÄÖ÷Òª¹¦Ð§ÊÇÀûÓÿþÀܽø³ÌÀ´±£»¤Dropper(hqpi64.exe)¡£Æä»á¶¨Ê±¼ì²éDropperÊÇ·ñ´¦ÓÚÔËÐÐ״̬£¬Èç±»¹Ø±Õ£¬ÔòÖØÐÂÆô¶¯¡£ÒԴ˵½´ï½ø³ÌÊØ»¤µÄÄ¿µÄ¡£
½ø³ÌÊØ»¤¹¦Ð§
ͨÐÅÐÒé½âÎö
1£©Á¬½Ó·þÎñÆ÷
2£©½âÃÜ¿ØÖÆ°ü
3£©Ö´ÐпØÖÆÖ¸Áî
ͨ¹ýÎÒÃÇÇ°ÃæµÄ·ÖÎö¿ÉÒÔ¿´µ½£¬¸ÃľÂí¿ØÖÆÖ¸ÁîÖаüÂÞÁË´óÁ¿Óû§Òþ˽ÐÅÏ¢µÄÇÔÈ¡¹¦Ð§¡£×îÖÕÊܺ¦ÕßµÄÃô¸ÐÊý¾ÝÐÅÏ¢£¬¶¼ÊÐƾ¾ÝÔ¶³Ì·þÎñÆ÷µÄÖ¸Áî»Ø´«¸øÔ¶³Ì·þÎñÆ÷¡£
¿ØÖÆÖ¸ÁЧ
¿ØÖÆÃüÁî |
Ö¸ÁЧ |
0x01~0x04 |
µ÷ÓÃ×Ô½ç˵º¯Êý£¬²¢½«Ö´Ðнá¹û»Ø´«·þÎñÆ÷ |
0x02 |
ÉÏ´«½ø³ÌÁбí |
0x04 |
»ñÈ¡¼ÆËã»úÂß¼´ÅÅÌÐÅÏ¢ |
0x06 |
ÉÏ´«ÎļþÁбíÐÅÏ¢ |
0x08 |
ÏÂÔØ¿ØÖÆÃüÁîÖÐÖ¸¶¨µÄÎļþ |
0x10 |
½áÊø¿ØÖÆÃüÁîÖÐÖ¸¶¨µÄ½ø³Ì |
0x0E |
Remote Shell |
0x10 |
È¡ÏûÏÂÔØ |
0x12 |
»ñÈ¡Webcam DevicesÁбí |
0x14 |
Start Webcam |
0x16 |
Stop Webcam |
0x18 |
·¢ËÍÐÄÌø°ü |
0x1A |
жÔØ¿Í»§¶Ë |
0x1C |
Ð޸ĿØÖÆÃüÁîÖÐÖ¸¶¨µÄÎļþ |
0x1E |
ÏÂÔØVNCÄ£¿é |
0x20 |
ÇÔÈ¡Google Chrome¡¢Mozilla FireFoxµÈä¯ÀÀÆ÷ºÍOutLook¡¢Thunderbird¡¢FoxmailÓÊÏäÖÐÉú´æµÄƾ֤ÐÅÏ¢ |
0x22 |
ÏÂÔØ¿ØÖÆÃüÁîÖÐÖ¸¶¨µÄÎļþÁ´½Ó²¢Ö´ÐÐ |
0x24 |
ƾ¾Ý¿ØÖÆÖ¸ÁÇл»Á½ÖÖ·½Ê½À´¼Ç¼¼üÅÌʹÓÃÐÅÏ¢ |
0x26 |
ʹÓÃÈ«¾ÖÏûÏ¢¹³×Ó£¬¼Ç¼¼üÅÌʹÓÃÐÅÏ¢ |
0x28 |
Remote VNC°²×° |
0x2A |
²âÊÔ±¾»úµÄÍøÂçÁ¬½Ó¹¦Ð§ |
0x2C |
¶Ï¿ªÔ¶³Ì·þÎñÆ÷ |
0x38 |
δ֪²âÊÔ |
other |
»ñÈ¡Óû§Ãû£¬ÏµÍ³°æ±¾£¬GUIDµÈÐÅÏ¢ |
1£©ÇÔȡƾ֤ÐÅÏ¢
ÇÔÈ¡µÄÐÅÏ¢°üÂÞGoogle Chrome¡¢Mozilla FirefoxµÈä¯ÀÀÆ÷ºÍOutlook¡¢Thunderbird¡¢FoxmailÓÊÏä¿Í»§¶ËÉú´æµÄƾ֤ÐÅÏ¢µÈ¡£
¸ÃľÂí»ñÈ¡Ïà¹Øƾ֤ÐÅÏ¢ÒÔ¼°ÊµÏÖÒªÁìÈçϱíËùʾ£º
ÇÔÈ¡µÄƾ֤ÐÅÏ¢ |
ʵÏÖÒªÁì |
Google Chrome |
¶ÁÈ¡\AppData\Local\Google\Chrome\User Data\Default\ Login DataÊý¾Ý¿âÎļþ½øÐвéѯ |
Mozilla Firefox |
¶ÁÈ¡ÅäÖ÷¾¶ÏµÄsignons.sqliteÊý¾Ý¿â£¬²¢Í¨¹ýnss3.dll½âÃÜ |
Outlook |
±éÀú×¢²á±íSoftware\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesÏÂ×Ó¼ü½øÐÐʶ±ð²¢½âÃÜ |
Thunderbird |
¶ÁÈ¡\AppData\Roaming\Thunderbird\ProfilesĿ¼ÏµÄÊý¾Ý¿âÎļþ£¬²¢Í¨¹ýÓ¦Ó÷¨Ê½Ä¿Â¼ÏµÄnss3..dll¶Ô´æ´¢µÄÃÜÂë½øÐнâÃÜ |
Foxmail |
¶ÁÈ¡ÓÊÏäĿ¼ÏµÄ\\Account\\Account.rec0Îļþ²¢½øÐнâÃÜ |
a£©ÌáÈ¡Chromeƾ֤
´Ó¸Ã±íÖжÁÈ¡µÄÄÚÈÝÊǼÓÃܵģ¬Í¨¹ýCryptUnProtectDataº¯Êý¶ÔÆä½øÐнâÃܱã¿ÉÒÔ»ñÈ¡µ½Ã÷ÎÄÊý¾Ý¡£×îºó¸ÃľÂí½«½âÃܺóµÄÊý¾ÝÉú´æÔÚÃûΪ¡±xxx.tmp¡±£¨¡±xxx¡°ÎªBase64½âÂë³öµÄ×Ö´®£©µÄÁÙʱÎļþÖС£
b£©ÌáÈ¡Mozillaƾ֤ÐÅÏ¢
Óû§ÃûºÍÃÜÂë
c£©OutLookƾ֤»ñÈ¡
»ñÈ¡OutlookÓÊÏäµÄÓû§ÐÅÏ¢
d£©Thunderbirdƾ֤»ñÈ¡
e£©FoxMailƾ֤»ñÈ¡
f£©ÉÏ´«»ñÈ¡µ½µÄƾ֤ÐÅÏ¢
2£©¼üÅ̼Ǽ
b£©ÁÙʱ¼üÅ̼Ǽ
°´¼üºÍ´°¿ÚÃûÐÅÏ¢µÄ»ñÈ¡
3£©RemoteVNC°²×°
a£©½«ÐÂÓû§Ìí¼Óµ½¡±Ô¶³Ì×ÀÃæÓû§¡±×é
Ìí¼Ó²¢Òþ²Ø´´½¨µÄÐÂÕË»§
b£©¸ü¸ÄÔ¶³Ì×ÀÃæÉèÖÃ
ͨ¹ý·ÖÎöÎÒÃÇ·¢ÏÖ£¬´ËRATµÄÔ¶³Ì×ÀÃ湦ЧÊÇͨ¹ýÌØÖƵÄVNCÄ£¿éÀ´ÊµÏֵġ£¶øÇÒÔÚºóÐøµÄ¸üа汾ÖУ¬»¹Ôö¼ÓÁËHRDPÄ£¿éÀ´ÊµÏÖÒþ²ØÔ¶¿Ø×ÀÃæ¡£¸ÃHRDPÄ£¿éʹÓÃÁËGithubÉϵÄrdpwrapÏîÄ¿£¬²»½ö¿ÉÒÔÔÚºǫ́µÇ¼Զ³Ì¼ÆËã»ú£¬¶øÇÒ´´½¨µÄWindowsÕË»§»¹»á×Ô¶¯Òþ²Ø¡£
4£©È¨ÏÞÉý¼¶£¨UACÈƹý£©
¸ÃľÂíµÄȨÏÞÌáÉýÊÇÀûÓÃÁË×Ô¶¯ÌáÉýȨÏ޵ĺϷ¨Ó¦Ó÷¨Ê½¡±pkgmgr.exe¡±À´Ö´ÐÐDISPÄ£¿é¡£Æ书Ч´úÂëʵÏÖÊǽÓÄÉÁËBypass-UAC¿ò¼Ü£¬¸Ã¿ò¼Ü¿ÉÒÔͨ¹ýµ÷ÓÃIFileOpertion COM¹¤¾ßËùÌṩµÄÒªÁìÀ´ÊµÏÖ×Ô¶¯ÌáȨ¡£
¸ÃľÂíÏȽ«Ç¶ÈëÔÚ×ÊÔ´Êý¾ÝÖеÄPEÎļþÔÚÄÚ´æÖмÓÔز¢ÔËÐС£¶ø´ËPEÎļþʵ¼ÊÉÏÊÇÒ»¸ö¼ÓÔØÆ÷£¬ÆäËù×öµÄÊÂÇéÔòÊǽ«×ÊÔ´ÖеÄÁíÒ»¸öPEαÔìΪ¡°dismcore.dll¡±£¬È»ºó½«´Ëdll¸´ÖƵ½System32Ŀ¼Ï£¬×îºóʹÓÃpkgmgr.exeÖ´ÐÐαÔìµÄ¶ñÒâDLL¡£ÓÉÓÚpkgmgr.exeÊÇÒ»¸öUAC°×Ãûµ¥·¨Ê½£¬ËùÒÔËüĬÈϾßÓйÜÀíԱȨÏÞ£¬ÇÒ²»»áµ¯³öUACÌáʾ¿ò¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ£º

´Ë¶ñÒâDLLµÄÖ÷Òª¹¦Ð§ÊÇ»ñȡע²á±íÖеġ±Install¡±°²×°ÐÅÏ¢(DropperµÄ·¾¶)²¢ÖØÐÂÆô¶¯¾ßÓйÜÀíԱȨÏÞµÄDropperнø³Ì¡£
5£©Î´Öª²âÊÔ
ÔÚÐÂÏß³ÌÖУ¬Æ¾¾ÝÔ¶³Ì·þÎñÆ÷·¢Ë͵ÄÖ¸ÁÓëÐÂÖ¸¶¨µÄC&C½øÐÐÁ¬½Ó¡£
ÓÉÓÚ½ÓÊÕÊý¾ÝÎÞ·¨»ñÈ¡£¬ËùÒÔÄ¿Ç°ÎÒÃÇÎÞ·¨È·¶¨Æä׼ȷÓÃ;£¬Ôݽ«ÆäÃüÃûΪδ֪²âÊÔ¡£
3.2 ×îй¥»÷Ñù±¾
½×¶ÎÒ»£º
½âÃܺ¯Êýmethod_0ÈçÏÂͼËùʾ£º
ÔÚ¾¹ýÄæÐòÅÅÁкÍBase64½âÂëºóµÄ×Ö·û´®£¨byte_0£©ÖУ¬Ç°16λΪ½âÃÜÃÜÔ¿¡°0x28 0x49 0xf7 0x30 0xec 0x8d 0x500x80 0x94 0xaf 0x85 0xaa 0xa8 0xe7 0xc0 0x41¡±,Ö®ºóΪ´ý½âÃÜÃÜÎÄ¡£º¯ÊýÒÔ16λΪѻ·,½«ÃÜԿͬÃÜÎÄÒÀ´Î½øÐа´Î»Òì»ò£¬×îÖÕ½âÃܵõ½¡°DUMP1¡±Îļþ²¢Í¨¹ýCallByNameº¯Êý¼ÓÔØÖ´ÐС£
½×¶Î¶þ£º
¡°DUMP1¡±ÎļþͬÑù½ÓÄÉC#±àд£¬·¨Ê½Ê×ÏÈ»á˯Ãß50ÃëÒÔ¶ã±ÜɳÏä¼ì²é£¬Ö®ºó»á¼ì²âµ÷ÊÔÆ÷²¢½«×ÔÉíÊÍ·ÅÖÁ¡°%ApplicationData%\riNpmWOoxxCY.exe¡±£¬½Ó×Å´´½¨schtasks.exe½ø³Ì²¢Ìí¼Ó¼Æ»®ÈÎÎñ¡°Updates\riNpmWOoxxCY¡±£¬´Ó¶øʵÏÖÔڵǼÕË»§Ê±×ÔÆô¶¯£¬Ïà¹ØÃüÁîÈçÏ£º
"C:\Windows\System32\schtasks.exe/Create/TN Updates\riNpmWOoxxCY/XMLC:\Users\super\AppData\Local\Temp\tmp925C.tmp"

Ö®ºó£¬·¨Ê½»á´Ó×ÔÉí×ÊÔ´ÄÚ½âÃܳöPEÎļþ¡°DUMP2¡±£¬Í¨¹ýCreateProcess¡¢WriteProcessMemoryºÍSetThreadContextµÈº¯Êý£¬ÒÔ¹ÒÆðµÄ·½Ê½¼ÓÔØÒ»¸öеĽø³Ì£¬²¢×îÖÕÒÔ¿þÀܽø³ÌµÄ·½Ê½Ð´Èë²¢¼ÓÔØ¡°DUMP2¡±¡£
¾¹ý·ÖÎö£¬ÎÒÃÇÔÚ¡°DUMP2¡±Öз¢ÏÖÁËһЩ¿ÉÒÉ×Ö·û´®È磺¡°Remcos¡±¡¢¡°Remcos_Mutex_Inj¡±¡¢¡°2.3.0 Pro¡±¡£
ÆäÃâ·Ñ°æ½ö¿ÉÌí¼ÓÒ»¸öC2Á¬½Ó·þÎñÆ÷£¬×¨Òµ°æÔòûÓÐÊýÁ¿ÏÞÖÆ¡£´Ë´Î¹¥»÷ÖÐÖ²ÈëµÄľÂíÊÇͨ¹ýרҵ°æÉú³ÉÇÒÁ¬½ÓÖÁ¶à¸ö¶ñÒâC2£¬°üÂÞµÄC2µØÖ·ÌáÈ¡ÈçÏ£º
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
4¶ñÒâ´úÂëËÝÔ´Óë¹ØÁª
4.1 ¶ñÒâ´úÂëËÝÔ´×·×Ù
Ç°ÎÄÔøÌáµ½£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÖаüÂÞÁË¡°AVE_MARIA¡±ÌØÕ÷×Ö·û´®£¬ÇÒ×Ô2018Äê12Ô¿ªÊ¼£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾ÔÚtwitter¡¢virustotalµÈƽ̨ԽÀ´Ô½¶àµÄ±»·¢ÏÖ¡£µ«¶àƪÏà¹ØÑо¿ÎÄÕ¾ùδָ³öÆäÕæʵÀ´Ô´£¬É±¶¾³§ÉÌÒ²¹ã·ºµÄ½«ÆäÃüÃûΪAVE_MARIA£¬ÕâÒýÆðÁËÎÒÃÇŨºñµÄÐËȤ¡£
ÎÒÃÇʵÑé´Ó¶àÖֽǶÈÈ¥ËÝԴľÂíÒÔÑ°ÕÒÏßË÷£¬°üÂÞÓòÃû¡¢IP¡¢¹ØÁªÑù±¾µÈµÈ¡£ÆäÖÐÔÚ¶Ô¹ØÁªÑù±¾¡°Michelle Flores - Curriculum Actualizado.doc¡±µÄ·ÖÎöÖÐÀÖ³ÉËÝÔ´µ½ÁËÉÌÓÃÈí¼þRemcos RAT¡£ÎÒÃÇ·ÖÎöÁ˸ÃÈí¼þµÄÐû²¼ÇþµÀ£¬·¢ÏÖÆä²»½öÔÚ¹ÙÍø½øÐÐÏúÊÛ£¬»¹ÔÚÖî¶àºÚ¿ÍÂÛ̳ÈçHackforumsÉÏ´óÁ¿ÊÛÂô¡£ÓÉ´Ë£¬ÎÒÃÇÍƲ⹥»÷ÈËÔ±ºÜ¿ÉÄÜ»îÔ¾ÔÚÏà¹ØÂÛ̳²¢¹ºÖùý¶à¿îÉÌÓÃÈí¼þ£¬Í¬Ê±Ò²½«ËÝÔ´ÖصãתÏòºÚ¿ÍÂÛ̳ºÍ°µÍøÊг¡¡£
SolmyrÔÚÂÛ̳ÖÐÌṩÁËwarzonedns.comÓòÃûµÄÃâ·ÑDDNS·þÎñ£¨IP¶¯Ì¬°ó¶¨ÖÁ×ÓÓòÃû£©£¬Ê¹µÃÓû§¿ÉÒÔÇáÒ׵Ľ«·þÎñÆ÷IP°ó¶¨½âÎöÖÁwarzonedns.comϵÄÈÎÒâ×ÓÓòÃû£¬Ê¹ÓÃʾÀýÈçÏ£º
ÕâÎÞÒɸøºÚ¿ÍÌṩÁ˺ܺõIJØÉíÖ®Ëù£¬Óë´ËͬʱÎÒÃÇ·¢ÏÖSolmyrµÄÁíÒ»¸öÉí·ÝÊÇWARZONE RATµÄÐû²¼Õߣ¬¸ÃÈí¼þÓÉÓÚ¿ØÖÆÊֶθ»ºñ¡¢¼¼Êõ¹¦Ð§Ç¿´ó¡¢µü´ú¸üÐÂѸËÙ£¬Ä¿Ç°ÔÚHackforumsÂÛ̳Öзdz£ÊÜ»¶Ó¡£
ÖÁ´Ë£¬ÎÒÃÇÓÐÀíÓÉ»³Òɹ¥»÷ÕßʹÓùý¸Ã¿îÉÌÓÃÔ¶³Ì¹ÜÀí¹¤¾ß¡£ÓÉÓÚ¸ÃÈí¼þ±ÕÔ´ÇÒ²»ÌṩÃâ·Ñ°æ±¾£¬ÎÒÃÇ×·Ëݵ½ÁËWARZONE RATÁ÷³öµÄÆƽâ°æ±¾£¨V1.31£©£¬²¢½«ÆäÓë¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÑù±¾½øÐÐͬԴÐÔ·ÖÎö,ÒÔÈ·¶¨¶þÕß¼äµÄ¹ØÁª¡£
4.2 ͬԴÐÔ·ÖÎö
Æä´Î£¬ÎÒÃÇͨ¹ýBindiff½øÐÐÁ˸üΪ¾«È·µÄ¶Ô±È£¬ÔÚÈ¥³ý²¿ÃÅAPI×ÌÈŲ¢±ÈÁ¦·ÖÎöÁË¿ÉÐŶȸߵĺ¯Êýºó£¬·¢ÏÖ´óÁ¿º¯ÊýÍêÈ«Ïàͬ£¬Õ¼±Èµ½´ï80.16%£¬ÆäÓຯÊýÔò¿ÉÄÜÒòΪ°æ±¾ÔÒòÂÔÓвîÒ죬ÕâÒ²Ó¡Ö¤Á˶þÕß¼äµÄÇ¿¹ØÁªÐÔ¡£
ÁíÍâ,´ÓÁ÷´«Ê±¼äµÄ½Ç¶È·ÖÎö,¡°AVE_MARIA¡±¹ØÁªÑù±¾×î³õ·ºÆðµÄʱ¼ä(2018Äê12ÔÂ2ÈÕ)ÂÔÍíÓÚWarzoneRATÔÚÂÛ̳µÄÐû²¼Ê±¼ä(2018Äê10ÔÂ22ÈÕ)£¬ÕâÒ²Çк϶ñÒâ´úÂëÁ÷´«µÄʱ¼äÂß¼¡£
ÒÀ¾ÝÒÔÉϼ¸µã·ÖÎö£¬ÎÒÃÇÈÏΪÁ½Õß¾ßÓи߶ȵÄÒ»ÖÂÐÔ¡£´ÓÄ¿Ç°ÒÑÖªµÄÇé¿ö¿´£¬WARZONE±»É±¶¾³§É̹㷺µÄʶ±ðΪAVE_MARIA£¬¶øÔÚÉîÈë±È¶Ô·ÖÎöºó£¬ÎÒÃÇÅж¨ºÚ¿Í×é֯ʹÓõÄÔ¶¿ØľÂíÕýÊÇWARZONE RAT¡£Òò´Ë¿ÉÒÔ½«´ËÀà°üÂÞ¡°AVE_MARIA¡±×Ö·û´®µÄ¶ñÒâÑù±¾¼Ò×åÃüÃû¸üÐÂΪ¡°WARZONE¡±¡£
4.3 ÓòÃû¹ØÁª
ÕâÅúÓòÃû¾ùΪwarzonedns.comÌṩµÄÃâ·Ñ×ÓÓòÃû£¬ÇÒ´ó²¿ÃŹØÁªÖÁ¶ñÒâÑù±¾£¬Õâ±íÃ÷´óÁ¿ºÚ¿ÍÕýÔÚÀÄÓôËÀà·þÎñ½øÐжñÒâ¹¥»÷¡£
5×Ü ½á
±¾ÎĶԱ¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Á÷³Ì¡¢Ïà¹ØµÄ¶ñÒâ´úÂë¡¢ºÚ¿ÍÅä¾°µÈ×öÁËÉîÈëµÄ·ÖÎöºÍÑо¿£¬´ÓÉÏÎĵķÖÎöÖÐÎÒÃÇ¿ÉÒÔ¿´³ö¸ÃºÚ¿Í×é֯ĿǰµÄ¹¥»÷»î¶¯Ê®·Ö½÷É÷£¬¼ÈûÓдó¹æÄ£µÄ¹¥»÷£¬Ò²Ã»ÓнÓÄɸ߳ɱ¾µÄ0day©¶´£¬Í¬Ê±£¬¹¥»÷»î¶¯Ê±¼äÒ²·Ç³£¶Ì¡£Õâ±íÃ÷¸Ã¹¥»÷»î¶¯»¹´¦ÓÚ³õÆÚ£¬²¢¶ÔÄ¿±ê½øÐÐÁËһЩÊÔ̽ÐÔ¡¢Õë¶ÔÐԵĹ¥»÷£¬Ò²ÎªºóÐøµÄ¹¥»÷×öºÃ×¼±¸¡£´ËÍâͨ¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´£¬ÎÒÃÇÈ·¶¨Á˸ôλ±³ºóµÄºÚ¿Í×éÖ¯£¬²¢Æ¾¾Ý¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯ÀúÊ·£¬·¢ÏÖÆäÃñ×åÖ÷ÒåÉ«²ÊÇ¿ÁÒ£¬Òò´ËÕþÖÎÄ¿µÄÒâͼҲ½ÏΪÃ÷ÏÔ¡£
IOC
MD5 |
99C82F8A07605DA4CCC8853C910F7CAF |
048DCA20685ECD6B7DBDBF04B9082A54 |
DEF105A9452DEF53D49631AF16F6018B |
1E19266FC9DFF1480F126BD211936AAC |
262D9C6C0DC9D54726738D264802CCAD |
B3C9F98DD07005FCCF57842451CE1B33 |
497566120F1020DBD6DF70DD128C0FFB |
ÓòÃû |
linksysdatakeys[.]se |
gestomarket[.]co |
asdfwrkhl.warzonedns[.]com |
casillas.hicam[.]net |
casillasmx.chickenkiller[.]com |
casillas.libfoobar[.]so |
du4alr0ute.sendsmtp[.]com |
settings.wifizone[.]org |
wifi.con-ip[.]com |
rsaupdatr.jumpingcrab[.]com |
activate.office-on-the[.]net |