ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö

Ðû²¼Ê±¼ä 2019-05-18

½üÆÚ£¬¶«É­Æ½Ì¨ADLab¼à²âµ½Ò»ÅúÒÉËÆÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄÕþ¸®»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿ÃŵĶ¨Ïò¹¥»÷»î¶¯£¬ºÚ¿Í×é֯ͨ¹ý½á¹¹¶ñÒâOffice WordÎĵµ²¢ÅäºÏÓã²æÓʼþÌᳫ¶¨Ïò¹¥»÷£¬ÒÔ¡°¼òÀú¸üС±×÷ΪÓÕ¶üÎĵµÏò¹¥»÷Ä¿±êÖ²Èë¼äµýľÂí£¬´ÓÊÂÇ鱨ÊÕ¼¯¡¢Ô¶¿Ø¼àÊÓ¼°ÏµÍ³ÆÆ»µµÈ¶ñÒâÐж¯¡£ÎÒÃǽ«ÍÁ¶úÆäºÚ¿ÍµÄ´Ë´Î¹¥»÷Ðж¯³ÆΪ¡°ºÚʨÐж¯¡±¡£


ͨ¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷Ïà¹ØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷À´Ô´ÓÚÒ»ÅúÒþÃضàÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¸Ã×éÖ¯ÊÇÒ»¸öÃñ×åÖ÷ÒåÉ«²Ê·Ç³£Å¨ºñµÄºÚ¿Í×éÖ¯£¬Ôø¹¥ÏÝÆäËû¹ú¼ÒµÄ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂÆä×éÖ¯µÄÃû³Æ£¬ËæºóÏûʧÁ˶àÄê¡£ Èç½ñͨ¹ýÎÒÃǶԡ±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯¼£Ïó¡£±¾´Î¹¥»÷¹ý³ÌÖУ¬¸ÃºÚ¿Í×éÖ¯½ÓÄÉÉø͸Êֶι¥Ïݶą̀·þÎñÆ÷²¢½«Æä×÷Ϊ´æ·Å¹¥»÷´úÂëµÄÌø°å¡£


2019Äê2Ô£¬ÎÒÃÇ·¢ÏÖÁ˵ÚÒ»¸ö¹¥»÷Ñù±¾²¢½«Æä¼ÓÈëµ½×·×ÙÇåµ¥ÖУ¬Ö±µ½½üÆÚÒѾ­·¢ÏÖÁ˶àÆð¹¥»÷£¬Ã¿´Î¹¥»÷¶¼Ê¹ÓÃÁ˲îÒìµÄ¹¥»÷ÐÎ̬ºÍÃâɱ·½Ê½¡£´ÓÄ¿Ç°ÒÑÓеĹ¥»÷´úÂëÖÐÎÒÃÇ·¢ÏÖÁËÁ½¿îÉÌÓÃÔ¶³Ì¹ÜÀí¹¤¾ß£¨RAT£©£ºWARZONEºÍRemcos£¬ÆäÖÐWARZONE±»É±¶¾³§É̹㷺µÄʶ±ðΪAVE_MARIA£¨ÒòΪRAT´úÂëÖдæÔÚ¸Ã×Ö·û´®Òò¶ø±»ÃüÃûΪ¡± AVE_MARIA¡±£©£¬ µ«ÊÇͨ¹ýÎÒÃÇÉîÈëµÄ·ÖÎöÈ·¶¨AVE_MARIAΪԶ³Ì¹ÜÀí¹¤¾ßWARZONE¡£±¾ÎÄÖУ¬ÎÒÃǽ«¶ÔºÚ¿Í×éÖ¯¡¢¹¥»÷Ä¿±êÒÔ¼°ÆäËùʹÓõĹ¥»÷ÎäÆ÷½øÐÐÉîÈë·ÖÎö¡£



1Íþв·ÖÎö




1.1 ¹¥»÷Ä¿±ê·ÖÎö


´ÓÄ¿Ç°Ëù»ñÈ¡µÄ¹¥»÷Ñù±¾ºÍÍþвÇ鱨£¬¿ÉÒÔ¿´³ö±¾´Î¹¥»÷»î¶¯²¢Ã»Óдó¹æÄ£µÄ½øÐУ¬Ä¿Ç°»¹´¦ÓÚ¹¥»÷ÊÔ̽½×¶Î£¬µ«ÊÇ´ÓÆäͶ·ÅµÄÓÕ¶üÎĵµ¿ÉÒÔ¼òµ¥¼òÖ±¶¨Æä¹¥»÷Ä¿±êËø¶¨ÔÚÎ÷°àÑÀÓïϵµÄ¹ú¼Ò¡£ÕâЩÓÕ¶üÎĵµÐÎÈ磺¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±£¨¼òÀú¸üРº£Ã·°¢ÀïÑÇ˹£©¡¢¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±(¼òÀú¸üРµ¤Äá¶û°ÂµÙ×È)¡¢¡°Michelle Flores - Curriculum Actualizado.doc¡±(Ã×Ъ¶û¸¥ÂåÀ×˹-¼òÀú¸üÐÂ)¡¢¡°Jose Trujillo.doc¡±(ºÎÈûÌسϣÂÔ)µÈµÈ£¬ËüÃǾù½ÓÄÉÎ÷°àÑÀÓïÀ´½á¹¹Ò»¸ö´ø¶ñÒâºê´úÂëµÄ¼òÀúÎļþ¡£ÒÔ´ËÀ´¶ÔÄ¿±êÈËÁ¦²¿ÃŽøÐй¥»÷£¬ÒÔÓÕʹÏà¹ØÈËÔ±Ö´ÐжñÒâ´úÂë½ø¶ø´Óʼäµý»î¶¯¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÎÒÃÇ·ÖÎöÕâÅúÓÕ¶üÎĵµÊ±£¬»¹·¢ÏÖÒ»¸öÓÐȤµÄÏÖÏó£¬ÄǾÍÊÇÐí¶àÓÕ¶üÎĵµÖаüÂÞÁËÎĵµ×÷ÕßÐÅÏ¢ºÍ×îºóÒ»´ÎÉú´æÕßÐÅÏ¢£¬¶øÇÒÕâЩÐÅÏ¢¾ùΪÀàËƲÆÕþ²¿¡¢Ðŷþ֡¢SCG£¨Southern Connecticut Gas£©µÈµÈÓëÕþ¸®²¿ÃÅÏà¹ØµÄÐÅÏ¢¡£Í¨¹ýÎÒÃÇʵ¼Ê²âÊÔ·¢ÏÖ£¬ÕâЩÐÅÏ¢¾ù»áÔÚÎĵµÐ޸ĺóÄð³Éµ±Ç°·ÃÎÊÕßofficeµÇ½ÕË»§Ãû»òÕßÖ÷»úÃû£¬¶øÇÒÓÐÐĵÄÈË»¹¿ÉÒÔ¶ÔÆä½øÐÐÈÎÒⶨÖÆ¡£ÎÒÃÇÑ¡È¡¼¸¸öµäÐ͵ÄÑù±¾²¢Õë¶ÔÏà¹ØÐÅÏ¢ºÍÂß¼­¹Øϵ×öÁËÈçÏÂÊáÀíºÍÍÆÂÛ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÎÒÃÇͨ¹ý´´½¨ÄÚÈÝʱ¼ä¡¢×îºóÐÞ¸Äʱ¼ä¼°¹¥»÷ÎĵµÄÚ²¿µÄÂß¼­¹ØϵÍÆÂÛ³öÏà¹Ø¼Ç¼ӦΪ¹¥»÷ÕßÉú´æ¡£»ùÓÚ×îºÏÀíÒÔ¼°×îÓпÉÄܵÄÍƲ⣬ÎÒÃÇÈÏΪ¹¥»÷Õß¿ÉÄÜÊÇ»ùÓÚºÚ¿Í×éÖ¯ÄÚ²¿¹æ·¶£¬½«ÎĵµµÄÏà¹ØÃû³ÆÉèÖÃΪ¹¥»÷Ä¿±ê»òÏà¹ØÐÐÒµÐÅÏ¢£¬´Ó¶øαÔì³ÉÄÚ²¿ÈËÊ¿£¬ÔÚÒ»¶¨Ë®Æ½ÉÏÆðµ½»ìÏýÊÓÌý¡¢Òþ±Î×ÔÉíµÄÄ¿µÄ¡£


ÓÉ´ËÎÒÃÇ¿ÉÒÔ¿´³ö´Ë´ÎÐж¯µÄ¹¥»÷Ä¿±êΪÎ÷°àÑÀÓïϵµØÓòµÄÕþ¸®»òÕß¹«¹²·þÎñ²¿ÃÅ£¬ËäÈ»²¢²»ÅųýÆäÓиü¶àµÄÄ¿±ê£¬ÖÁÉÙ¿ÉÒԿ϶¨µÄÊÇ´Ë´ÎÐж¯ÊÇÒ»´Î´øÓÐÕþÖÎÄ¿µÄµÄ¹¥»÷»î¶¯¡£



1.2 ºÚ¿Í×éÖ¯·ÖÎö


ÔÚÎÒÃÇÉîÈë·ÖÎö¶ñÒâ´úÂëʱ£¬·¢Ïָôι¥»÷µÄ¿ØÖÆÃüÁî·þÎñÆ÷ÊÇÓÉÉÏÓκڿÍÒ²¼´ÊǶñÒâÈí¼þÌṩÉÌËùÌṩµÄ£¬´ÓÕâЩ¿ØÖÆÃüÁî·þÎñÆ÷ÉÏÊÇÎÞ·¨×·×Ùµ½¸Ã´ÎÐж¯µÄ±³ºó×éÖ¯£¬Òò´ËÎÒÃÇ°ÑÖ÷Òª¾«Á¦¾Û½¹ÓÚ¹¥»÷µÄÇ°¼¸¸ö½×¶ÎÏà¹ØµÄÓòÃû¡£ËäÈ»´ó²¿ÃÅÓòÃû¾ù½ÓÄÉÁËÒþ˽±£»¤£¬ÎÞ·¨ÕÒµ½ÓÐÓõÄÐÅÏ¢£¬µ«ÊÇÎÒÃÇÈ´ÔÚÆäÖÐÒ»¸öÇ¿¹ØÁªµÄÑù±¾Öз¢ÏÖÒ»¸ö¿ÉÍ»ÆƵĵã¡£ÎÒÃÇÔÚÆäÖÐÒ»¸öRTFÎĵµÖÐÄÚ²¿·¢ÏÖÁËÒ»¸öExcelÎļþ£¬¸ÃExcelÎļþ»áͨ¹ýÖ´ÐкêÀ´ÏÂÔضñÒâ´úÂ롣ͨ¹ý¶Ô¸Ã·þÎñÆ÷µÄ·ÖÎöÎÒÃÇÀֳɵØÕÒµ½ÁËÓëºÚ¿Í×éÖ¯Ïà¹ØµÄÏßË÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ¶ñÒâ´úÂë´æ´¢Â·¾¶µÄͬĿ¼£¬ÎÒÃÇ·¢ÏÖºÚ¿Í×éÖ¯ËùÁôϵÄһЩÐÅÏ¢£¬ÏÂͼΪÆäÖÐÒ»¸öÎļþ¼Ç¼µÄÐÅÏ¢£º 


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¸ÃÎļþÖаüÂÞÁËһЩÉùÃ÷ÐÅÏ¢¡¢ºÚ¿Í×éÖ¯¼°ÆäÏà¹Ø³ÉÔ±£¬¶øÇÒËù½ÓÄɵÄÓïÑÔΪÍÁ¶úÆäÓÒò´ËÎÒÃÇÅж¨¸Ã×éÖ¯ÕýÊÇÔø¾­»îԾһʱµÄKingSqlZºÚ¿Í×éÖ¯¡£¸Ã·þÎñÆ÷ºÜÓпÉÄÜÔÚ±»ºÚ¿Í×éÖ¯¿ØÖƺó×÷ΪÌø°å»ú»ò×ÊÔ´·þÎñÆ÷¼ÌÐøʹÓᣴËÍâͨ¹ý¶ñÒâ´úÂëʱÇø·ÖÎö·¨£¬ÎÒÃǽøÒ»²½È·¶¨¸Ã´Î¹¥»÷À´×ÔÓÚÍÁ¶úÆäºÚ¿Í¡£ÎÒÃǶÔRATÑù±¾Ö®Ç°µÄPEÎļþ¼°ÆäËûÇ°ÆÚ¹¥»÷»·½ÚÏà¹ØµÄÑù±¾µÄ±àÒëʱ¼ä×öÁËʱÇø·ÖÎö£¨ÒòΪRATÑùÔ­À´×ÔÓÚÉÏÓκڿÍ£¬Òò´ËÎÒÃǺöÂÔÁ˸ÃÀàÑù±¾µÄʱÇø·ÖÎö£©¡£×îºó·¢ÏÖÕâЩ¹¥»÷Ñù±¾µÄ±àÒëʱ¼äÔÚUTCʱ¼ä21:00ÖÁ06:00Çø¼äÄÚ·ºÆðµÄƵ´Î¼«µÍ¡£¶ø¼Ù¶¨ÒÔ24:00ÖÁ08:00×÷Ϊ˯Ãßʱ¼ä£¬¹¥»÷ÕßËù´¦µÄʱÇø¿ÉÄÜ»áÔÚ¶«3Çø£¨UTC+3£©Õý¸º 1 СʱÇø¼äÄÚ£¬¶øÍÁ¶úÆäʱÇøΪ¶«ÈýÇøÕýºÃÇкÏ¡£


ÔÚÎļþµÄ¼Ç¼ÐÅÏ¢Àﻹ¿ÉÒÔµÃÖªµ½¸Ã×éÖ¯³ÉÔ±ÈçF0RTYSEVEN , BlackApple , Pyske , HeroTurk , SadrazaM , MrDemonLordµÈ£¬ËûÃÇÔçÆÚ½øÐйý·è¿ñµÄÍøÂç¹¥»÷»î¶¯£¬¹¥ÏݵķþÎñÆ÷¸ß´ï3287¸ö£¬¶øÖ®ºó±ãÉñÃصÄÏúÉùÄä¼££¬ÆätwitterÕ˺ÅҲֹͣÁ˻¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾´Î¹¥»÷»î¶¯¿ªÊ¼ÓÚ2019Ä꣬½ÓÄÉ´óÁ¿¹«¹²DDNS·þÎñ×ÓÓòÃû×÷ΪC2À´ÊµÊ©¹¥»÷£¬ÕâÆäÖеÄһЩÓòÃûΪ2019ÄêÐÂ×¢²áµÄ£¬Ê¹ÓõIJ¿ÃÅÓòÃûÈçÏ£º


asdfwrkhl.warzonedns.com
casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com

activate.office-on-the.net


µ½³ÂËß׫дʱ£¬²¿ÃÅÖм乥»÷½×¶ÎµÄÓòÃûÒѾ­Ê§Ð§£¬µ«RAT»ØÁ¬µÄC2ÒÀÈ»ÔÚ»îÔ¾¡£ÒÀ¾ÝÎÒÃÇÄ¿Ç°¶ÔÒÉËƹ¥»÷×éÖ¯µÄÕÆÎÕºÍËÝÔ´·ÖÎö£¬»æÖƺڿÍ×éÖ¯»­ÏñÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2¹¥»÷¸ÅÊö



´Ë´ÎʼþµÄÖ÷Òª¹¥»÷»î¶¯Ê±¼äÏßÈçÏÂËùʾ:


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÖУ¬ÎÒÃǶÔ2019Äê2ÔÂ7ÈÕ·¢Ïֵġ°Curriculum Vitae Actualizado Jaime Arias.doc¡±Îĵµ½øÐÐÁËÏêϸµÄ·ÖÎö£¬²¢Ïà¼Ì²¶×½µ½¹ØÁªÎĵµ¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc/ Jose Trujillo.doc¡±¡£


¹¥»÷ÕßʹÓÃÁËAPI¹þÏ£¡¢ÎÞÎļþ¹¥»÷¡¢WinrarSFX¡¢AutoIt¡¢C#»ìÏýºÍ¿þÀܽø³ÌµÈ¼¼ÊõÀ´¹æ±Ü¼ì²â²¢×ÌÈÅ·ÖÎöÈËÔ±¡£ÆäÖУ¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ÎĵµÖ²ÈëµÄľÂíÀ´Ô´×î³õÎÞ·¨È·ÈÏ£¬ÎÒÃÇÔÚÆäÖз¢ÏÖÁËÌØÕ÷×Ö·û´®¡°AVE_MARIA¡±,ÆäÓëCybaze-Yoroi ZLabÑо¿ÈËÔ±ÔÚ2018Äê12Ôµ×Åû¶µÄÕë¶ÔÒâ´óÀûijÄÜÔ´ÆóÒµ½øÐй¥»÷µÄ¶ñÒâÈí¼þÏàËƶȺܸߣ¬²¿ÃÅÄþ¾²Ñо¿Ô±ºÍ³§ÉÌÒòΪûÓÐÀֳɵĽøÐÐËÝÔ´±ãÒÔ´Ë×Ö·û´®×öΪ¸ÃľÂí¼Ò×åµÄÃû³Æ¡£¶øÎÒÃǾ­¹ý¹ØÁªËÝÔ´ºÍͬԴÐÔ·ÖÎöºó·¢ÏÖ£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾Í¬RAT¹¤¾ß¡°WARZONE¡±RAT¾ßÓи߶ÈÒ»ÖÂÐÔ£¬Òò´Ë½«´ËÀà¶ñÒâ¼Ò×åÃüÃû¸üÐÂΪ¡°WARZONE¡±¡£


ºóÎĽ«Öصã¾ÍÖ²Èë¼äµýľÂíµÄ2¸öOffice WordÎĵµ£¨¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc¡±£©¼°ÆäÊͷŵÄÎļþ½øÐÐÏêϸ·ÖÎö¡£



3¼¼Êõ·ÖÎö



3.1 ÔçÆÚ¹¥»÷Ñù±¾



´Ë´Î¹¥»÷¹ý³Ì¿ªÊ¼ÓÚÒ»¸öЯ´ø¶ñÒâºêµÄDOCÎĵµ£¬ºÚ¿Íͨ¹ýαÔì³É¼òÀúµÄͶµÝÓʼþÊֶν«´Ë¶ñÒâÎļþ·¢Ë͸ø¹¥»÷Ä¿±ê£¬µ±Ä¿±êÓû§²»É÷´ò¿ªÎĵµ±ã³ÉΪÁËÊܺ¦Õß¡£DOCÎĵµÔËÐкó»áÆô¶¯¶ñÒâºê´úÂë²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÏÂÔØEtr739.exe£¬ÀÖ³ÉÏÂÔغóÁ¢¼´Ö´ÐС£Ð½ø³Ìͨ¹ýBase64½âÂë³öÁíÒ»¸ö·þÎñÆ÷µØÖ·£¬¼ÌÐøÏÂÔضñÒâ´úÂëhqpi64.exeÖÁÁÙʱĿ¼Ï¡£¶ñÒⷨʽhqpi64.exe±ãÊÇWarzone RATµÄÊÍ·ÅÆ÷£¬Æäͨ¹ýÊÍ·ÅWarzone RATÀ´Ö´ÐкóÐø²Ù×÷£¬È罫explorer.exe×÷Ϊ¿þÀܽø³ÌÊØ»¤¡¢Óë¿ØÖƶ˽øÐÐͨÐŵÈ¡£


Ñù±¾ÖеĶñÒâ´úÂë´ó²¿ÃŽÓÄÉCRC32À´¼ÓÃÜÃô¸Ð×Ö´®£¬Í¬Ê±ÔÚAPIµ÷ÓÃÊÖ·¨ÉϽÓÄÉÁËAPI HashÖµ¶¯Ì¬»ñÈ¡º¯ÊýµØÖ·ºÍÄ£Äâϵͳ¿ìËÙµ÷ÓÃÁ½ÖÖ·½Ê½¡£Ê¹ÓôËÀàÊÖ·¨²»¹âÄÜÔÚÒ»¶¨Ë®Æ½ÉϼõÉÙɱÈí¾²Ì¬É¨ÃèµÄ¼ì²â£¬¶øÇÒ»¹²»Ò×±»¼à²âµ½APIµÄµ÷ÓÃ×Ù¼£¡£Í¬Ê±ÆäʹÓô¿¼ÓÃÜShellcode´úÂëÄÚ´æÖ´Ðеķ½Ê½¼ÓÔØÆäºËÐĹ¦Ð§Ä£¿é£¬Í¨¹ý¡°ÎÞÎļþ¼¼Êõ¡±Ìá¸ß×ÔÉíÒþ±ÎÐÔ£¬ÒÔ´ËÀ´¶ã±ÜÄþ¾²³§É̲éɱ¡£ÆäÓëC2·þÎñÆ÷¼äµÄͨÐÅÊý¾ÝÒ²ÒÔCR4Ëã·¨½øÐмÓÃܽø¶ø¹æ±ÜIDSϵͳµÄ¼ì²â¡£


Ñù±¾ÕûÌåÖ´ÐÐÁ÷³ÌÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


(1)DOCÎĵµ


DocÎĵµÎªwordÎļþ£¬Ò²ÊÇÕë¶Ô¹¥»÷Ä¿±êʵʩµÄµÚÒ»²½¹¥»÷£¬ºÚ¿Íͨ¹ýµöÓã¹¥»÷¡¢É繤µÈÊÖ¶ÎÆÛÆ­¹¥»÷Ä¿±ê´ò¿ª´ËÎĵµÈÃÆäÖÐǶÈëµÄ¶ñÒâºê´úÂëµÃÒÔÖ´ÐС£ÎÒÃÇʹÓÃÌáÈ¡¹¤¾ß»ñÈ¡µ½µÄºê´úÂëÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚAutoOpenº¯ÊýÖаüÂÞÁËÒ»´®»ìÏý¹ýµÄcmdÃüÁ¾­¹ý½âÃܺóµÄ´úÂëÈçͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Õâ¶Î´úÂë»ñµÃÖ´Ðк󣬻áÖ±½Ó½ñºóÁ´½ÓµØÖ·(http[:]//linksysdatakeys.se)ÏÂÔضñÒⷨʽµ½¡°%Temp%\SAfdASF.exe¡±²¢Ö´ÐС£


(2)Payload


ÏÂÒ»¸öDropperµÄÏÂÔصØÖ·ÊDZ»¼ÓÃܺóÉú´æÔÚ¶ñÒⷨʽSAfdASF.exeµÄ×ÊÔ´ÖУ¬¼ÓÃܵÄ×ÊÔ´Êý¾ÝÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸ÃPayloadÏȽ«ÉÏͼÖмÓÃܵÄÊý¾Ýͨ¹ýBase64½âÂë³öÏÂÔØÁ´½ÓµØÖ·¡°http[:]//www.gestomarket[.]co/hqpi64.exe¡±£¬È»ºó°Ñhqpi64.exe¸üÃûΪ2XC2DF0S.exe²¢Éú´æÔÚÁÙʱĿ¼Ï¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


(3)Dropper


ÔÚºóÐøµÄ½âÃÜÒÔ¼°Ö´ÐеĹý³ÌÖУ¬´ËDropper»á°ÑÒ»¶ÎShellcode×¢Èëµ½explorer½ø³Ì²¢ÔÚÄÚ´æÖнâÃܳöRATʵÌåʹÆä²»ÂäµØ£¬×îÖÕͨ¹ýÎÞÎļþ¼¼Êõ½«RAT¼ÓÔص½ÄÚ´æÖÐÀ´Ö´ÐС£


Ìӱܼì²â


´Ë¶ñÒⷨʽÔÚ¿ªÊ¼Ö´ÐÐʱ£¬»áͨ¹ý´óÁ¿µÄµ÷ÓÃprintfº¯Êý´òÓ¡À¬»ø´úÂëºÍsleepº¯ÊýÀ´µ½´ïÑÓʱЧ¹û£¬ÕâÔÚÒ»¶¨Ë®Æ½ÉÏÄܹ»¶ã±ÜÄþ¾²Èí¼þµÄ¼à¿Ø¡£¶øÆäºËÐĹ¦Ð§Êǽ«×ÔÉíЯ´øµÄshellcode½âÃܲ¢Ö´ÐУº


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½âÃÜshellcode


ÈçÉÏͼËùʾ£¬¶ñÒⷨʽ»áÔÚ¼ÓÔØÖ´ÐÐshellcodeÇ°½øÐнâÃÜ¡£½âÃÜËã·¨·Ç³£¼òµ¥£¬½«Ã¿¸ö×Ö½ÚµÄÖµÔö¼Ó0x0c¼´¿É¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×Ô½ç˵µÄ½âÃܺ¯Êý


¾­¹ýÖØÖØÏÂÔز¢½âÃÜÖ®ºó£¬ÄÇôÕâ¶Î½âÃܺóµÄShellcode(PE Loader)´úÂë¾ßÌå»á×öЩʲô£¬ÏÂÃæÎÒÃÇÀ´Ò»¿ú¾¿¾¹¡£


PE Loader


´ËPE LoaderÔÚÖ´ÐÐShellcodeµÄʱºòʹÓÃÁËËĸö²ÎÊý£¬¾­·ÖÎöºóÎÒÃǽ«Õâ4¸ö²ÎÊýÄÚÈÝËù¶ÔÓ¦µÄ¾ßÌ幦ЧÕûÀíÈçϱíËùʾ£º


ÐòºÅ

ÄÚÈÝ

¹¦Ð§

²ÎÊý1

¡°FYBLV¡±

¿½±´×ÔÉíµÄĿ¼ÃûºÍÎļþÃû(Ðè½âÃܵÄ×ÊÔ´Ãû)

²ÎÊý2

¡°BJU¡±

RATÔ¶¿ØÎļþ(Ðè½âÃܵÄPEÎļþ×ÊÔ´Ãû)

²ÎÊý3

¡°OPTYUPPABIVSUWNRXSNCTDW¡±

Key

²ÎÊý4

0x01£¨ÀιÌÊýÖµ£©

δʹÓÃ


¸ÃPE LoaderÊ×ÏÈÔÚÔËÐйý³ÌÖнøÐÐÁËɳÏäºÍÖ¸¶¨½ø³ÌµÄ¼ì²â£¬ÒÔ·ÀÖ¹±»×Ô¶¯»¯ÏµÍ³·ÖÎö¡£¶øÇÒƾ¾Ý×Ô´øµÄ×ÊÔ´Êý¾ÝÀ´Åж¨ÊÇ·ñʵʩפÁô±¾»úµÄ²Ù×÷ºÍ×¢ÈëÌåµÄÑ¡Ôñ¡£×îºó´ËPE Loader½«×îÖÕÑ¡ÔñµÄ¿þÀܽø³ÌµÄ¿Õ¼ä¼Ü¿Õ£¬²¢°Ñ½âÃܳöµÄRATÄ£¿éÓ³Éäµ½´Ë½ø³ÌÖÐÖ´ÐÐ(Ô­±¾PEÎļþ´úÂë±»Öû»)¡£


ÔËÐл·¾³¼ì²â


¸ÃPE LoaderÔÚ¿ªÊ¼ÔËÐÐʱ£¬ÒÀÈ»»á½øÐÐɳÏäºÍµ÷ÊÔ»·¾³µÄ¼ì²â£¬Í¬Ê±Í¨¹ýÔ¤ÏȼÆËãºÃµÄ½ø³ÌÃû¹þÏ£ÖµÀ´²éÕÒÖ¸¶¨µÄ½ø³Ì¡£µ±ÕâЩ¼ì²âÌõ¼þÖеÄÈÎÒâÒ»ÌõÂú×ãʱ£¬¸Ã¶ñÒⷨʽ¾Í²»ÔÙ¼ÌÐøÖ´ÐУ¬Ö±½Ó·µ»ØÍ˳ö¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔËÐл·¾³¼ì²â


²Ù×÷×ÊÔ´Êý¾Ý


Èç¹ûÔËÐл·¾³µÄ¼ì²âÈ«²¿Í¨¹ý£¬¸ÃPE LoaderÔò¼ÓÔØÃûΪ¡°FYBLV¡±µÄ×ÊÔ´Êý¾Ý£¬²¢´Ó×ÊÔ´ÖÐÈ¡³öºóÐøÒª¿½±´×ÔÉíµÄÎļþ¼ÐÃû³ÆºÍÎļþÃûµÄ×Ö´®¡£È»ºóÒÔ²ÎÊý3×÷ΪÀ뿪·û£¬ÒÀ´ÎÈ¡³öÆäËüµÄÊý¾Ý²¢Éú´æÔÚ×Ô½ç˵µÄ½á¹¹ÌåÖС£×ÊÔ´ÖÐÌáÈ¡³öµÄ½á¹¹Êý¾ÝÄÚÈÝÈçÏÂͼ£º£¨Í¼ÖбêºìµÄÊýֵΪÉú´æÔڽṹÌåÖеÄ8¸ö³ÉÔ±Êý¾Ý£©£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾­¹ý·ÖÎö£¬½á¹¹ÌåÖÐÿ¸ö³ÉÔ±µÄ¾ßÌ幦Ч¿É²Î¿¼ÏÂͼ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÊÍ·ÅÓëפÁô


Èç¹ûbIsCpySelfֵΪTRUE£¬ÄÇô¸ÃPELoader»á½«×Ô¼º¸´ÖƵ½C:\Users\SuperVirus\AppData\Roaming\ptdkuybasm\"Ŀ¼Ï²¢°ÑÐÂÎļþÃüÃûΪszPathNameÀïÉú´æµÄÄÚÈÝ¡£½Ó×ÅÔÚWindowsµÄÆô¶¯Îļþ¼ÐÀï´´½¨Ò»¸ö.urlµÄÍøÒ³Îļþ¿ì½Ý·½Ê½£¬ÎÒÃǼì²ì¸ÃPE Loader´´½¨µÄ¿ì½Ý¼üÊôÐÔ£¬·¢ÏÖ´Ë¿ì½Ý¼üµÄ·ÃÎÊЭÒé¸ñʽΪfile:///£¬¼´Ö¸ÏòµÄ×ÊÔ´Êǵ±µØ¼ÆËã»úÉϵÄÎļþ£¬¶ûºóÃæ½ô¸úµÄ·¾¶±ãÊǸ´ÖƹýÈ¥ÐÂÎļþµÄȫ·¾¶¡£Í¨¹ý´Ë·½¹æÔò¿ÉʵÏÖ¿ª»ú×ÔÆô¶¯ÒÔµ½´ïºã¾Ã¿ØÖÆÖ÷»úµÄÄ¿µÄ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´´½¨µÄ¿ì½Ý¼üÊôÐÔ


×îºó£¬¸ÃPE Loaderƾ¾Ý½á¹¹ÌåÖеÄdwFlagÖµÀ´Ñ¡ÔñºóÐøµÄRATÔØÌ壬Ëù¶ÔÓ¦µÄRATÔØÌåÏê¼ûÏÂ±í£º


Êý¾Ý

½ø³ÌÃû

0x01

C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe

0x02

C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe

0x03

C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe

0x04

C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe

0x05

C:\Windows\System32\svchost.exe

0x06

C:\Windows\System32\dllhost.exe

0x07

µ±Ç°ÔËÐеÄ×ÔÉí½ø³Ì


¶øÔÚ±¾Ñù±¾ÖУ¬´Ë³ÉÔ±µÄÖµËù¶ÔÓ¦µÄÔØÌåΪµ±Ç°ÔËÐеÄ×ÔÉí½ø³Ì¡£


»ñÈ¡RAT²¢Ö´ÐÐ


ÔÚ×¼±¸ºÃRATµÄ¿þÀܽø³Ìºó£¬¸ÃPE Loader½«½á¹¹ÌåÖеÄszKeyÖµ×÷Ϊkey£¬ºÍÃûΪ¡±BJU¡±µÄ×ÊÔ´´«Èë½âÃܺ¯Êý¡£½âÃܵÄËã·¨½öΪXORÔËË㣬¾ßÌåËã·¨´úÂëÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½Ó×Å£¬¸ÃPE LoaderÖØд´½¨Ð½ø³Ì²¢½«ÆäÉèÖÃΪ¹ÒÆð״̬¡£È»ºóжÔش˽ø³ÌÓ³Ïñ£¬²¢°ÑÔÚÄÚ´æÖнâÃܳöµÄеÄPEÍ·²¿£¬ÒÔ¼°½ÚÊý¾ÝÒÀ´ÎдÈëµ½¹ÒÆðµÄ½ø³ÌÖУ¬×îºóÐÞ¸ÄOEP²¢Æô¶¯ÔËÐС£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


(4) WARZONE RATÄ£¿é


ÎÒÃǽ«´ËPEÎļþ´ÓÄÚ´æÖÐdump³öÀ´£¬Í¨¹ý·ÖÎöºÍËÝÔ´ºó·¢ÏÖ£¬¸ÃPEÓë¹úÍâijºÚ¿ÍÂÛ̳ÖÐÊÛÂôµÄWARZONE RATͬ³öÒ»ÕÞ¡£ÓÉ´ËÎÒÃÇÍƲ⣬´Ë´¦Ê¹ÓõÄRATÄ£¿é¿ÉÄÜΪWAREZONE RAT1.6°æ±¾£¬´Ë°æ±¾ÎªC++ÓïÑÔ±àд£¬Ö÷Òª¹¦Ð§°üÂÞÔ¶³Ì×ÀÃæ¿ØÖÆ¡¢¼üÅ̼Ǽ¡¢ÌØȨÉý¼¶£¨UACÈƹý£©¡¢Ô¶³ÌWebCam¡¢ÇÔȡƾ֤ÐÅÏ¢¡¢Remote Shell¡¢Offine KeyloggerµÈµÈ¡£ÏÂÃæÎÒÃÇ»á¶ÔRATÖеĺËÐIJ¿ÃÅ×ö¼òÒª½éÉÜ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô¶¿Ø·¨Ê½Warzoneºǫ́½çÃæ


»ñÈ¡C&CµØÖ·


ΪÁË·ÀÖ¹C&C±»ÇáÒ×·¢ÏÖ»òÕßÅúÁ¿ÌáÈ¡£¬¸ÃľÂí½«Æä¼ÓÃܺó´æ·ÅÔÚ¡°.bss¡±µÄ×ÊÔ´½ÚÊý¾ÝÖС£Í¨¹ý¶Ô½âÃܺ¯ÊýµÄ·ÖÎöÎÒÃÇ·¢ÏÖ£¬ÕâÀï½ÓÄÉÁËCR4Ëã·¨¡£CR4Éú³ÉÒ»ÖÖ³ÆΪÃÜÔ¿Á÷µÄαËæ»úÁ÷£¬ËüÊÇͬÃ÷ÎÄͨ¹ýÒì»ò²Ù×÷Ïà»ìºÏÀ´µ½´ï¼ÓÃܵÄÄ¿µÄ¡£½âÃÜʱÔòʹÓÃÃÜÔ¿µ÷ÖÎËã·¨(KSA)À´Íê³É¶Ô¾ÞϸΪ256¸ö×Ö½ÚÊý×ésboxµÄ³õʼ»¯¼°Ìæ»»¡£¾ßÌåÁ÷³ÌÈçÏ£º


1£©ÓÃÊýÖµ0~255À´³õʼ»¯Êý×ésbox¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2)µ±¿ªÊ¼Ìæ»»µÄʱºò£¬»ñÈ¡Ó²±àÂëÔÚ×ÊÔ´ÀïµÄÃÜÔ¿£¬³¤¶ÈΪ0x32¸ö×Ö½Ú¡£

(ÔÚ×ÊÔ´Êý¾ÝÖÐÇ°0x32¸ö×Ö½ÚÊÇÃÜÔ¿£¬ÆäÓà0x68¸ö×Ö½ÚÔòÊÇ´ý½âÃܵÄÊý¾Ý)


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÜÔ¿ºÍ´ý½âÃÜÊý¾Ý


3£©ÃÜÔ¿Á÷µÄÉú³ÉÊÇ´Ósbox[0]µ½sbox[255]£¬¶Ôÿ¸ösbox[i]£¬Æ¾¾Ýµ±Ç°sboxÖµ£¬½«sbox[i]ÓësboxÖеÄÁíÒ»¸ö×Ö½ÚÖû»£¬È»ºóʹÓÃÃÜÔ¿½øÐÐÌæ»»¡£µ±Êý×ésboxÍê³É³õʼ»¯Ö®ºó£¬ÊäÈëÃÜÂë±ã²»ÔÙ±»Ê¹Óá£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4£©Ìæ»»ºóµÄsboxÊý×éÖеÄÊýÖµÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5£©Í¨¹ýÌæ»»ºóµÄsboxºÍ´ý½âÃܵÄÊý¾Ý½øÐÐXORÔËËãºó£¬×îÖյõ½·þÎñÆ÷µÄhostµØÖ·"asdfwrkhl.warzonedns[.]com"¡£


Ö´ÐÐ×¢È빦Ч


µ±ÀֳɽâÃܳöC&CµØÖ·ºó£¬¸ÃľÂíÔò¿ªÊ¼½«Ò»¶ÎShellcode´úÂë×¢Èëµ½¿þÀܽø³ÌÖС£ÔÚ×¢È빦Ч¿ªÆôʱ£¬Ä¾Âí·¨Ê½Ê×ÏÈ»áƾ¾Ý²Ù×÷ϵͳ¼Ü¹¹(64/32)À´Ñ¡Ôñ×¢Èëµ½cmd.exe»òexplorer.exeÖС£Ïà¹Ø´úÂëÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½Ó×Å£¬¸ÃľÂíʹÓÃÔ¶³ÌÏ̵߳ķ½Ê½À´×¢ÈëºËÐĹ¦Ð§Shellcode´úÂ룬²¢ÔÚÆô¶¯Ô¶Ïß³ÌÖ´ÐÐʱ£¬ÐÞ¸ÄдÈëÄ¿±ê½ø³ÌÄÚ´æÆ«ÒƵÄ0x10E´¦Îª¿ªÊ¼Ö´ÐдúÂë¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý·ÖÎöÎÒÃÇ·¢ÏÖ£¬Õâ¶Î×¢Èë´úÂëµÄÖ÷Òª¹¦Ð§ÊÇÀûÓÿþÀܽø³ÌÀ´±£»¤Dropper(hqpi64.exe)¡£Æä»á¶¨Ê±¼ì²éDropperÊÇ·ñ´¦ÓÚÔËÐÐ״̬£¬Èç±»¹Ø±Õ£¬ÔòÖØÐÂÆô¶¯¡£ÒԴ˵½´ï½ø³ÌÊØ»¤µÄÄ¿µÄ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½ø³ÌÊØ»¤¹¦Ð§


ͨÐÅЭÒé½âÎö


1£©Á¬½Ó·þÎñÆ÷


µ±ÀÖ³É×¢È뵽Ŀ±ê½ø³Ìºó£¬¸ÃľÂíÔò¿ªÊ¼ÊµÑéÓëÇ°ÎĽâÃܳöµÄC2·þÎñÆ÷½øÐÐÁ¬½Ó£¬²¢»áƾ¾Ý·þÎñÆ÷·µ»ØµÄÄÚÈÝÖ´ÐÐÖ¸¶¨²Ù×÷¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½ÓÊÕÊý¾Ý°üµÄ½á¹¹´óÖÂÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2£©½âÃÜ¿ØÖÆ°ü


¸ÃľÂíÊ×ÏȽ«½ÓÊÕµ½µÄÇ°0x0C¸ö×Ö½Ú×÷Ϊͷ²¿Êý¾Ýµ÷ÓÃ×Ô½ç˵fn_Decrypt_CR4º¯Êý½øÐнâÃÜ£¨ÃÜÔ¿ÒÔÃ÷ÎÄ·½Ê½Ó²±àÂëÔÚ´úÂëÖУ©¡£ÀֳɽâÃܺó£¬È¡³öÆ«ÒÆ0x04´¦µÄDWORDÊýÖµ×÷ΪÊÇ·ñ¼ÌÐøÖ´ÐÐÒÔÏÂÁ÷³ÌµÄÅжÏÌõ¼þ£¨´ËDWORDÊýÖµÀïÉú´æ×ųýÈ¥0x0Cºó£¬Ê£ÓàµÄÊý¾Ý³¤¶È£©¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈôÌõ¼þÇкÏ£¬Ôò¸ÃľÂí»áÔٴε÷ÓÃfn_Decrypt_CR4º¯Êý¶ÔÕû¸öÊý¾Ý£¨Í·²¿Êý¾Ý+×·ËæÊý¾Ý£©ÖØнøÐÐÒ»´Î½âÃÜ¡£½Ó×ŵ÷ÓÃ×Ô½ç˵fn_Distributeº¯Êý£¬²¢È¡³öÊý¾ÝÖеÄOpCodeÀ´Ö´ÐÐswitchÖвîÒìµÄ²Ù×÷¡£Ïà¹Ø´úÂëÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3£©Ö´ÐпØÖÆÖ¸Áî


ͨ¹ýÎÒÃÇÇ°ÃæµÄ·ÖÎö¿ÉÒÔ¿´µ½£¬¸ÃľÂí¿ØÖÆÖ¸ÁîÖаüÂÞÁË´óÁ¿Óû§Òþ˽ÐÅÏ¢µÄÇÔÈ¡¹¦Ð§¡£×îÖÕÊܺ¦ÕßµÄÃô¸ÐÊý¾ÝÐÅÏ¢£¬¶¼ÊÐƾ¾ÝÔ¶³Ì·þÎñÆ÷µÄÖ¸Áî»Ø´«¸øÔ¶³Ì·þÎñÆ÷¡£


¿ØÖÆÖ¸ÁЧ


µ±Ô¶³Ì·þÎñÆ÷ÀÖ³ÉÏìÓ¦Êý¾Ýºó£¬¸ÃľÂí¾Í»áƾ¾Ý·þÎñÆ÷·µ»ØµÄÄÚÈÝÖ´ÐÐÖ¸¶¨²Ù×÷¡£²¿ÃÅ¿ØÖÆÖ¸ÁЧÈçϱíËùʾ£º


¿ØÖÆÃüÁî

Ö¸ÁЧ

0x01~0x04

µ÷ÓÃ×Ô½ç˵º¯Êý£¬²¢½«Ö´Ðнá¹û»Ø´«·þÎñÆ÷

0x02

ÉÏ´«½ø³ÌÁбí

0x04

»ñÈ¡¼ÆËã»úÂß¼­´ÅÅÌÐÅÏ¢

0x06

ÉÏ´«ÎļþÁбíÐÅÏ¢

0x08

ÏÂÔØ¿ØÖÆÃüÁîÖÐÖ¸¶¨µÄÎļþ

0x10

½áÊø¿ØÖÆÃüÁîÖÐÖ¸¶¨µÄ½ø³Ì

0x0E

Remote Shell

0x10

È¡ÏûÏÂÔØ

0x12

»ñÈ¡Webcam DevicesÁбí

0x14

Start Webcam

0x16

Stop Webcam

0x18

·¢ËÍÐÄÌø°ü

0x1A

жÔØ¿Í»§¶Ë

0x1C

Ð޸ĿØÖÆÃüÁîÖÐÖ¸¶¨µÄÎļþ

0x1E

ÏÂÔØVNCÄ£¿é

0x20

ÇÔÈ¡Google Chrome¡¢Mozilla FireFoxµÈä¯ÀÀÆ÷ºÍOutLook¡¢Thunderbird¡¢FoxmailÓÊÏäÖÐÉú´æµÄƾ֤ÐÅÏ¢

0x22

ÏÂÔØ¿ØÖÆÃüÁîÖÐÖ¸¶¨µÄÎļþÁ´½Ó²¢Ö´ÐÐ

0x24

ƾ¾Ý¿ØÖÆÖ¸ÁÇл»Á½ÖÖ·½Ê½À´¼Ç¼¼üÅÌʹÓÃÐÅÏ¢

0x26

ʹÓÃÈ«¾ÖÏûÏ¢¹³×Ó£¬¼Ç¼¼üÅÌʹÓÃÐÅÏ¢

0x28

Remote VNC°²×°

0x2A

²âÊÔ±¾»úµÄÍøÂçÁ¬½Ó¹¦Ð§

0x2C

¶Ï¿ªÔ¶³Ì·þÎñÆ÷

0x38

δ֪²âÊÔ

other

»ñÈ¡Óû§Ãû£¬ÏµÍ³°æ±¾£¬GUIDµÈÐÅÏ¢


1£©ÇÔȡƾ֤ÐÅÏ¢


ÇÔÈ¡µÄÐÅÏ¢°üÂÞGoogle Chrome¡¢Mozilla FirefoxµÈä¯ÀÀÆ÷ºÍOutlook¡¢Thunderbird¡¢FoxmailÓÊÏä¿Í»§¶ËÉú´æµÄƾ֤ÐÅÏ¢µÈ¡£


¸ÃľÂí»ñÈ¡Ïà¹Øƾ֤ÐÅÏ¢ÒÔ¼°ÊµÏÖÒªÁìÈçϱíËùʾ£º


ÇÔÈ¡µÄƾ֤ÐÅÏ¢

ʵÏÖÒªÁì

Google Chrome

¶ÁÈ¡\AppData\Local\Google\Chrome\User  Data\Default\ Login DataÊý¾Ý¿âÎļþ½øÐвéѯ

Mozilla Firefox

¶ÁÈ¡ÅäÖ÷¾¶ÏµÄsignons.sqliteÊý¾Ý¿â£¬²¢Í¨¹ýnss3.dll½âÃÜ

Outlook

±éÀú×¢²á±íSoftware\\Microsoft\\Windows  NT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesÏÂ×Ó¼ü½øÐÐʶ±ð²¢½âÃÜ

Thunderbird

¶ÁÈ¡\AppData\Roaming\Thunderbird\ProfilesĿ¼ÏµÄÊý¾Ý¿âÎļþ£¬²¢Í¨¹ýÓ¦Ó÷¨Ê½Ä¿Â¼ÏµÄnss3..dll¶Ô´æ´¢µÄÃÜÂë½øÐнâÃÜ

Foxmail

¶ÁÈ¡ÓÊÏäĿ¼ÏµÄ\\Account\\Account.rec0Îļþ²¢½øÐнâÃÜ



a£©ÌáÈ¡Chromeƾ֤


Chromeä¯ÀÀÆ÷Éú´æÓû§µÇ¼ÐÅÏ¢µÄÊý¾Ý¿âÎļþΪ%AppData%\Local\Google\Chrome\UserData\Default\Login Data£¬¸ÃÊý¾Ý¿âÊÇsqlite3µÄÊý¾Ý¿â£¬Êý¾Ý¿âÖÐÓÃÓÚ´æ´¢Óû§ÃûÃÜÂëµÄ±íΪlogins¡£logins±í½á¹¹½ç˵ÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ó¸Ã±íÖжÁÈ¡µÄÄÚÈÝÊǼÓÃܵÄ£¬Í¨¹ýCryptUnProtectDataº¯Êý¶ÔÆä½øÐнâÃܱã¿ÉÒÔ»ñÈ¡µ½Ã÷ÎÄÊý¾Ý¡£×îºó¸ÃľÂí½«½âÃܺóµÄÊý¾ÝÉú´æÔÚÃûΪ¡±xxx.tmp¡±£¨¡±xxx¡°ÎªBase64½âÂë³öµÄ×Ö´®£©µÄÁÙʱÎļþÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


b£©ÌáÈ¡Mozillaƾ֤ÐÅÏ¢


¸ÃľÂíÊ×ÏȼìË÷ºÍ¶ÁÈ¡profile.iniÅäÖÃÎļþ£¬²¢ÌáÈ¡¹ØÁªµÄÎļþ¼Ð·¾¶¡£½Ó×ÅÀûÓÃnss3.dllÀ´½âÃÜÊý¾Ý¿âsignons.sqliteÖб»¼ÓÃܵÄÄÚÈÝ£¬²¢Í¨¹ýSQLÓï¾ä»ñÈ¡µ½Ö÷»úÃû¡¢±»¼ÓÃܵÄÓû§Ãû¼°ÃÜÂ룬Ȼºóµ÷ÓÃnss3.dllÖеĵ¼³öº¯Êý¶Ôsqlite²éѯ³öµÄÓû§ÃûºÍÃÜÂë½øÐнâÃÜ¡£×îºóͬÑùµÄ£¬½«½âÃܺóµÄÄÚÈÝÉú´æÔÚÃûΪ¡±xxx.tmp¡±µÄÁÙʱÎļþÖС£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Óû§ÃûºÍÃÜÂë


c£©OutLookƾ֤»ñÈ¡


µç×ÓÓÊÏäOutLookµÄÓû§µÇ¼ƾ֤һ°ã»áÉú´æÔÚ×¢²á±íÖУ¬¸ÃľÂíͨ¹ýö¾Ù×¢²á±íSoftware\\Microsoft\\WindowsNT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesϵÄËùÓÐ×Ó½¡£¬¶ÁÈ¡¼üÃûΪϱíÖеÄÊý¾ÝºÃ±Èpassword½øÐнâÃÜ»¹Ô­³öÃ÷ÎĵÄÃÜÂë¡£×îºó½«»ñÈ¡µ½µÄÓû§µÄOutlookµÇ¼ƾ֤дÈëÃûΪ¡±xxx.tmp¡±µÄÁÙʱÎļþÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


»ñÈ¡OutlookÓÊÏäµÄÓû§ÐÅÏ¢


d£©Thunderbirdƾ֤»ñÈ¡


ͬÑù£¬ThunderbirdÓÊÏäµÄƾ֤Êý¾ÝÒ²ÊÇ´æ´¢ÔÚÊý¾Ý¿âÎļþ%AppData%\\Thunderbird\\ProfilesÖУ¬¸ÃľÂíͨ¹ýnss3.dll µÄµ¼³öº¯Êý¶Ô´¢´æÎļþµÄÃÜÂë½øÐнâÃÜ¡£×îºó½«½âÃܺóµÄÊý¾ÝÉú´æÔÚÃûΪ¡±xxx.tmp¡±µÄÁÙʱÎļþÖС£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


e£©FoxMailƾ֤»ñÈ¡


¸ÃľÂíÔÚFoxMailµÄ°²×°Ä¿Â¼Ï²éÕÒStorageÎļþ¼Ð£¬½Ó×űéÀúËùÓе±Ç°ÓÊÏäÕË»§Ä¿Â¼ÏµÄ\Account\Account.rec0Îļþ¡£´ËÎļþʵ¼ÊÉϾÍÊÇÓÃÀ´´æ·ÅÕË»§Ïà¹ØÐÅÏ¢µÄ£¬¼ÓÃܺóµÄÃÜÂë¾ÍĬÈÏÉú´æÔÚÕâÀľÂí»ñÈ¡²¢½âÃÜ´ËÎļþºó±ã¿ÉÇÔÈ¡µ½FoxmailµÄƾ֤ÐÅÏ¢¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


f£©ÉÏ´«»ñÈ¡µ½µÄƾ֤ÐÅÏ¢


ÇÔÈ¡ÍêËùÓÐÐÅÏ¢ºó£¬¸ÃľÂíÔòʹÓÃfn_Decrypt_CR4¼ÓÃܺ¯Êý½«ÎļþÄÚÈÝ×ö¼ÓÃÜ´¦Öò¢½«ËüÃÇ·¢Ë͸øÔ¶³Ì·þÎñÆ÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2£©¼üÅ̼Ǽ


a£©ÀëÏß¼üÅ̼Ǽ£¨³£×¤£©

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±½ÓÊܵ½µÄ¿ØÖÆÃüÁîΪΪÆôÓÃÍÑ»ú¼üÅ̼Ǽʱ£¬´ËľÂíÔòʹÓù³×ÓÀ´ÊµÏÖ¼üÅ̼Ǽ¹¦Ð§¡£¸Ã¹³×Ó½«²¶×½°´¼üºÍ´°¿ÚÃûÐÅÏ¢Éú´æÔÚ¡±C:\user\sss\AppData\Local\MicrosoftVision\¡±Ä¿Â¼Ï£¬ÎļþÔòÒÔµ±Ç°ÈÕÆÚºÍʱ¼äÀ´ÃüÃû¡£Ïà¹Ø´úÂëµÄʵÏÖÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


b£©ÁÙʱ¼üÅ̼Ǽ


µ±Ô¶³Ì¿ØÖÆÖ¸ÁîΪ¿ªÆô¼üÅ̼Ǽʱ£¬¸ÃľÂíÔòͨ¹ýRaw InputÒªÁìÀ´ÊµÊ±¼à¿Øµ±Ç°¼üÅ̵ÄʹÓÃÇé¿ö¡£½Ó׎«²¶×½µ½µÄ¼üÖµ½øÐÐÅжϲ¢×ª»¯Îª×Ö·ûÖµ¡£Í¬ÑùµÄ£¬ÕâЩ×Ö·ûÖµºÍ´°¿ÚÃûÐÅÏ¢Éú´æÔÚ¡±C:\user\sss\AppData\Local\MicrosoftVision\¡±Ä¿Â¼Ï£¬ÎļþÔòÒÔµ±Ç°ÈÕÆÚºÍʱ¼äÀ´ÃüÃû¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°´¼üºÍ´°¿ÚÃûÐÅÏ¢µÄ»ñÈ¡


3£©RemoteVNC°²×°


a£©½«ÐÂÓû§Ìí¼Óµ½¡±Ô¶³Ì×ÀÃæÓû§¡±×é


Ê×ÏÈ£¬¸ÃľÂí»áµ÷ÓÃfn_Base64×Ô½ç˵º¯Êý£¬½âÂë³öºóÐøÐèÒªÌí¼ÓµÄÕË»§ÃûºÍÃÜÂë¡£²¢É趨Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\SpecialAccounts\Userlist×¢²á±íֵΪ0À´Òþ²Øд´½¨µÄÕË»§¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ìí¼Ó²¢Òþ²Ø´´½¨µÄÐÂÕË»§


½Ó×Å£¬¸ÃľÂí½«ÉÏÎĽâÂë³öµÄÕË»§ÃûºÍÃÜÂë×÷ΪÐÂÓû§¼ÓÈëµ½administorÓû§×éÖС£ÕâÑù±ã¿ÉʹÓ÷ǹÜÀíÔ±Óû§À´½øÐÐÔ¶³Ì×ÀÃæµÇ¼¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½«ÐÂÕË»§¼ÓÈë¹ÜÀíÔ±×éÖÐ

b£©¸ü¸ÄÔ¶³Ì×ÀÃæÉèÖÃ


¸ÃľÂí»áÐÞ¸Ä×¢²á±íÐÅÏ¢£¬ÊµÏÖ´ò¿ªÔ¶³Ì×ÀÃæ¡¢¶àÓû§Ö§³Ö¡¢¸ü¸ÄÓû§µÇ¼ºÍ×¢Ïú·½Ê½¡¢Ê¹ÓÿìËٵǼÇл»¡¢ÒÔ¼°ÉèÖÃÔ¶³Ì¡±Öն˷þÎñ¡±µÄʹÓÃÃûΪ¡°RDPClip¡±µÈµÈ²Ù×÷¡£¾ßÌåϸ½ÚÈçÏÂͼËùʾ£¨½ö½ØÈ¡Á˲¿ÃŲ½Ö裩£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý·ÖÎöÎÒÃÇ·¢ÏÖ£¬´ËRATµÄÔ¶³Ì×ÀÃ湦ЧÊÇͨ¹ýÌØÖƵÄVNCÄ£¿éÀ´ÊµÏֵġ£¶øÇÒÔÚºóÐøµÄ¸üа汾ÖУ¬»¹Ôö¼ÓÁËHRDPÄ£¿éÀ´ÊµÏÖÒþ²ØÔ¶¿Ø×ÀÃæ¡£¸ÃHRDPÄ£¿éʹÓÃÁËGithubÉϵÄrdpwrapÏîÄ¿£¬²»½ö¿ÉÒÔÔÚºǫ́µÇ¼Զ³Ì¼ÆËã»ú£¬¶øÇÒ´´½¨µÄWindowsÕË»§»¹»á×Ô¶¯Òþ²Ø¡£


4£©È¨ÏÞÉý¼¶£¨UACÈƹý£©


¸ÃľÂíµÄȨÏÞÌáÉýÊÇÀûÓÃÁË×Ô¶¯ÌáÉýȨÏ޵ĺϷ¨Ó¦Ó÷¨Ê½¡±pkgmgr.exe¡±À´Ö´ÐÐDISPÄ£¿é¡£Æ书Ч´úÂëʵÏÖÊǽÓÄÉÁËBypass-UAC¿ò¼Ü£¬¸Ã¿ò¼Ü¿ÉÒÔͨ¹ýµ÷ÓÃIFileOpertion COM¹¤¾ßËùÌṩµÄÒªÁìÀ´ÊµÏÖ×Ô¶¯ÌáȨ¡£


¸ÃľÂíÏȽ«Ç¶ÈëÔÚ×ÊÔ´Êý¾ÝÖеÄPEÎļþÔÚÄÚ´æÖмÓÔز¢ÔËÐС£¶ø´ËPEÎļþʵ¼ÊÉÏÊÇÒ»¸ö¼ÓÔØÆ÷£¬ÆäËù×öµÄÊÂÇéÔòÊǽ«×ÊÔ´ÖеÄÁíÒ»¸öPEαÔìΪ¡°dismcore.dll¡±£¬È»ºó½«´Ëdll¸´ÖƵ½System32Ŀ¼Ï£¬×îºóʹÓÃpkgmgr.exeÖ´ÐÐαÔìµÄ¶ñÒâDLL¡£ÓÉÓÚpkgmgr.exeÊÇÒ»¸öUAC°×Ãûµ¥·¨Ê½£¬ËùÒÔËüĬÈϾßÓйÜÀíԱȨÏÞ£¬ÇÒ²»»áµ¯³öUACÌáʾ¿ò¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

´Ë¶ñÒâDLLµÄÖ÷Òª¹¦Ð§ÊÇ»ñȡע²á±íÖеġ±Install¡±°²×°ÐÅÏ¢(DropperµÄ·¾¶)²¢ÖØÐÂÆô¶¯¾ßÓйÜÀíԱȨÏÞµÄDropperнø³Ì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5£©Î´Öª²âÊÔ


¸ÃľÂíʵÑéÓëÔ¶³Ì·þÎñÆ÷½øÐÐͨÐÅ£¬µ±Á¬½ÓÀÖ³ÉʱÔò»áÏò·þÎñÆ÷·¢ËÍ¡±AVE_MARIA¡±×Ö´®×÷ΪµÆºÅ¡£È»ºóÆÚ´ý½ÓÊÕ·þÎñÆ÷·µ»ØÊý¾Ý£¬¾ÞϸΪ4¸ö×Ö½Ú¡£Èç¹û½ÓÊÕÀֳɣ¬Ôò¿ªÆôÐÂÏ̡߳£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÐÂÏß³ÌÖУ¬Æ¾¾ÝÔ¶³Ì·þÎñÆ÷·¢Ë͵ÄÖ¸ÁÓëÐÂÖ¸¶¨µÄC&C½øÐÐÁ¬½Ó¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚ½ÓÊÕÊý¾ÝÎÞ·¨»ñÈ¡£¬ËùÒÔÄ¿Ç°ÎÒÃÇÎÞ·¨È·¶¨Æä׼ȷÓÃ;£¬Ôݽ«ÆäÃüÃûΪδ֪²âÊÔ¡£



3.2 ×îй¥»÷Ñù±¾



ÎÒÃÇÔÚ2019Äê3ÔÂ26ÈÕ²¶×½µ½ÁË×îеĹØÁªÎĵµ¡°Michelle Flores - Curriculum Actualizado.doc¡±£¬ÆäͬÑùͨ¹ý¶ñÒâºêÆô¶¯¹¥»÷¡£ÎĵµÊ×ÏÈͨ¹ýPowershell½Å±¾ÏÂÔز¢Ö´ÐÐPEÎļþ¡°massive.exe¡±(C#±àд²¢¼ÓÈëÁË´óÁ¿»ìÏý)¡£Ö®ºó°üÂÞÁËÁ½¸ö½×¶Î£¬µÚÒ»½×¶Î¡°massive.exe¡±»á´Ó×ÊÔ´ÖнâÃܳöPEÎļþ¡°DUMP1.exe¡±(C#±àд)²¢¼ÓÔØ¡£µÚ¶þ½×¶ÎÔòÊÇ¡°DUMP1.exe¡±ÊÍ·Å×ÔÉí²¢Í¨¹ý¼Æ»®ÈÎÎñÉèÖÃ×ÔÆô¶¯£¬×îºó´Ó×ÊÔ´ÖÐÌáÈ¡³öRemcos RAT²¢ÒÔ¿þÀܽø³ÌµÄ·½Ê½¼ÓÔØÔËÐУ¬ºËÐĹý³ÌÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½×¶ÎÒ»£º


¡°massive.exe¡±´Ó×ÊÔ´ÖÐÌáÈ¡²¢½âÂë³ö¼ÓÃÜ×Ö·ûÁ÷£¬Ö®ºóͨ¹ýStrReverseº¯Êý½«¸Ã×Ö·ûÁ÷ÄæÐòÅÅÁУ¬ÔÙ¾­FromBase64Stringº¯Êý½âÂ룬×îºóͨ¹ý×Ô½ç˵µÄ½âÃܺ¯Êýmethod_0½âÃܵõ½PEÎļþ¡°DUMP1.exe¡±¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½âÃܺ¯Êýmethod_0ÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ¾­¹ýÄæÐòÅÅÁкÍBase64½âÂëºóµÄ×Ö·û´®£¨byte_0£©ÖУ¬Ç°16λΪ½âÃÜÃÜÔ¿¡°0x28 0x49 0xf7 0x30 0xec 0x8d 0x500x80 0x94 0xaf 0x85 0xaa 0xa8 0xe7 0xc0 0x41¡±,Ö®ºóΪ´ý½âÃÜÃÜÎÄ¡£º¯ÊýÒÔ16λΪѭ»·,½«ÃÜԿͬÃÜÎÄÒÀ´Î½øÐа´Î»Òì»ò£¬×îÖÕ½âÃܵõ½¡°DUMP1¡±Îļþ²¢Í¨¹ýCallByNameº¯Êý¼ÓÔØÖ´ÐС£


½×¶Î¶þ£º


¡°DUMP1¡±ÎļþͬÑù½ÓÄÉC#±àд£¬·¨Ê½Ê×ÏÈ»á˯Ãß50ÃëÒÔ¶ã±ÜɳÏä¼ì²é£¬Ö®ºó»á¼ì²âµ÷ÊÔÆ÷²¢½«×ÔÉíÊÍ·ÅÖÁ¡°%ApplicationData%\riNpmWOoxxCY.exe¡±£¬½Ó×Å´´½¨schtasks.exe½ø³Ì²¢Ìí¼Ó¼Æ»®ÈÎÎñ¡°Updates\riNpmWOoxxCY¡±£¬´Ó¶øʵÏÖÔڵǼÕË»§Ê±×ÔÆô¶¯£¬Ïà¹ØÃüÁîÈçÏ£º


"C:\Windows\System32\schtasks.exe/Create/TN Updates\riNpmWOoxxCY/XMLC:\Users\super\AppData\Local\Temp\tmp925C.tmp"


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ö®ºó£¬·¨Ê½»á´Ó×ÔÉí×ÊÔ´ÄÚ½âÃܳöPEÎļþ¡°DUMP2¡±£¬Í¨¹ýCreateProcess¡¢WriteProcessMemoryºÍSetThreadContextµÈº¯Êý£¬ÒÔ¹ÒÆðµÄ·½Ê½¼ÓÔØÒ»¸öеĽø³Ì£¬²¢×îÖÕÒÔ¿þÀܽø³ÌµÄ·½Ê½Ð´Èë²¢¼ÓÔØ¡°DUMP2¡±¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾­¹ý·ÖÎö£¬ÎÒÃÇÔÚ¡°DUMP2¡±Öз¢ÏÖÁËһЩ¿ÉÒÉ×Ö·û´®È磺¡°Remcos¡±¡¢¡°Remcos_Mutex_Inj¡±¡¢¡°2.3.0 Pro¡±¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý´óÁ¿¿ÉÒÉÐÅÏ¢ÎÒÃÇÈ·ÈÏ´ËľÂíΪRemcos RATµÄ¿Í»§¶Ë£¬ÇÒÆäʹÓõİ汾Ϊ2.3.0 Pro¡£ÒÔRemcos RATÃâ·Ñ°æV2.4.3ΪÀý£¬·þÎñ¶ËÈçͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÃâ·Ñ°æ½ö¿ÉÌí¼ÓÒ»¸öC2Á¬½Ó·þÎñÆ÷£¬×¨Òµ°æÔòûÓÐÊýÁ¿ÏÞÖÆ¡£´Ë´Î¹¥»÷ÖÐÖ²ÈëµÄľÂíÊÇͨ¹ýרҵ°æÉú³ÉÇÒÁ¬½ÓÖÁ¶à¸ö¶ñÒâC2£¬°üÂÞµÄC2µØÖ·ÌáÈ¡ÈçÏ£º


casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com

activate.office-on-the.net


Remcos RAT×Ô2016ÄêÏ°ëÄ꿪ʼÔÚÆä¹ÙÍøºÍºÚ¿ÍÂÛ̳ÊÛÂô£¬²¿Ãų§ÉÌÔø¶ÔÆä½øÐйýÏêϸµÄ¼¼Êõ·ÖÎö£¬Ôڴ˲»×ö׸Êö£¬µ«Õâ¿îľÂíµÄ·¢ÏÖΪÎÒÃÇÑ°ÕÒ¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄδ֪ľÂíÀ´Ô´ÌṩÁ˺ܺõÄËÝÔ´ÏßË÷¡£



4¶ñÒâ´úÂëËÝÔ´Óë¹ØÁª



4.1 ¶ñÒâ´úÂëËÝÔ´×·×Ù



Ç°ÎÄÔøÌáµ½£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÖаüÂÞÁË¡°AVE_MARIA¡±ÌØÕ÷×Ö·û´®£¬ÇÒ×Ô2018Äê12Ô¿ªÊ¼£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾ÔÚtwitter¡¢virustotalµÈƽ̨ԽÀ´Ô½¶àµÄ±»·¢ÏÖ¡£µ«¶àƪÏà¹ØÑо¿ÎÄÕ¾ùδָ³öÆäÕæʵÀ´Ô´£¬É±¶¾³§ÉÌÒ²¹ã·ºµÄ½«ÆäÃüÃûΪAVE_MARIA£¬ÕâÒýÆðÁËÎÒÃÇŨºñµÄÐËȤ¡£


ÎÒÃÇʵÑé´Ó¶àÖֽǶÈÈ¥ËÝԴľÂíÒÔÑ°ÕÒÏßË÷£¬°üÂÞÓòÃû¡¢IP¡¢¹ØÁªÑù±¾µÈµÈ¡£ÆäÖÐÔÚ¶Ô¹ØÁªÑù±¾¡°Michelle Flores - Curriculum Actualizado.doc¡±µÄ·ÖÎöÖÐÀÖ³ÉËÝÔ´µ½ÁËÉÌÓÃÈí¼þRemcos RAT¡£ÎÒÃÇ·ÖÎöÁ˸ÃÈí¼þµÄÐû²¼ÇþµÀ£¬·¢ÏÖÆä²»½öÔÚ¹ÙÍø½øÐÐÏúÊÛ£¬»¹ÔÚÖî¶àºÚ¿ÍÂÛ̳ÈçHackforumsÉÏ´óÁ¿ÊÛÂô¡£ÓÉ´Ë£¬ÎÒÃÇÍƲ⹥»÷ÈËÔ±ºÜ¿ÉÄÜ»îÔ¾ÔÚÏà¹ØÂÛ̳²¢¹ºÖùý¶à¿îÉÌÓÃÈí¼þ£¬Í¬Ê±Ò²½«ËÝÔ´ÖصãתÏòºÚ¿ÍÂÛ̳ºÍ°µÍøÊг¡¡£


ÎÒÃÇÊÕ¼¯²¢·ÖÎöÁË´óÁ¿AVE_MARIAÀà¶ñÒâÑù±¾£¬·¢ÏÖ´ó²¿ÃÅÑù±¾¾ùͨ¹ýwarzonedns.com×ÓÓòÃû½øÐжñÒâÁ¬½ÓºÍÏÂÔØ£¬×·ËÝ·¢ÏÖÆäʵÖÊΪºÚ¿ÍÌṩµÄDDNS·þÎñ¡£½áºÏ¹¥»÷ÈËÔ±µÄ»î¶¯ÏßË÷£¬ÎÒÃÇÀÖ³É×·×Ùµ½HackforumsÂÛ̳ÉϵĿÉÒÉÓû§Solmyr¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SolmyrÔÚÂÛ̳ÖÐÌṩÁËwarzonedns.comÓòÃûµÄÃâ·ÑDDNS·þÎñ£¨IP¶¯Ì¬°ó¶¨ÖÁ×ÓÓòÃû£©£¬Ê¹µÃÓû§¿ÉÒÔÇáÒ׵Ľ«·þÎñÆ÷IP°ó¶¨½âÎöÖÁwarzonedns.comϵÄÈÎÒâ×ÓÓòÃû£¬Ê¹ÓÃʾÀýÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÕâÎÞÒɸøºÚ¿ÍÌṩÁ˺ܺõIJØÉíÖ®Ëù£¬Óë´ËͬʱÎÒÃÇ·¢ÏÖSolmyrµÄÁíÒ»¸öÉí·ÝÊÇWARZONE RATµÄÐû²¼Õߣ¬¸ÃÈí¼þÓÉÓÚ¿ØÖÆÊֶθ»ºñ¡¢¼¼Êõ¹¦Ð§Ç¿´ó¡¢µü´ú¸üÐÂѸËÙ£¬Ä¿Ç°ÔÚHackforumsÂÛ̳Öзdz£ÊÜ»¶Ó­¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖÁ´Ë£¬ÎÒÃÇÓÐÀíÓÉ»³Òɹ¥»÷ÕßʹÓùý¸Ã¿îÉÌÓÃÔ¶³Ì¹ÜÀí¹¤¾ß¡£ÓÉÓÚ¸ÃÈí¼þ±ÕÔ´ÇÒ²»ÌṩÃâ·Ñ°æ±¾£¬ÎÒÃÇ×·Ëݵ½ÁËWARZONE RATÁ÷³öµÄÆƽâ°æ±¾£¨V1.31£©£¬²¢½«ÆäÓë¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÑù±¾½øÐÐͬԴÐÔ·ÖÎö,ÒÔÈ·¶¨¶þÕß¼äµÄ¹ØÁª¡£



4.2 ͬԴÐÔ·ÖÎö



Ê×ÏÈ£¬ÎÒÃÇÔÚÁ½ÖÖÑù±¾Öоù·¢ÏÖÁËÌØÕ÷×Ö·û´®¡°AVE_MARIA¡±£¬¶øÇÒÕë¶ÔÁ½ÀàÑù±¾µÄ´úÂë½á¹¹½øÐÐÁ˱ȶÔ£¬·¢ÏÖÏàËƶȼ«¸ß¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Æä´Î£¬ÎÒÃÇͨ¹ýBindiff½øÐÐÁ˸üΪ¾«È·µÄ¶Ô±È£¬ÔÚÈ¥³ý²¿ÃÅAPI×ÌÈŲ¢±ÈÁ¦·ÖÎöÁË¿ÉÐŶȸߵĺ¯Êýºó£¬·¢ÏÖ´óÁ¿º¯ÊýÍêÈ«Ïàͬ£¬Õ¼±Èµ½´ï80.16%£¬ÆäÓຯÊýÔò¿ÉÄÜÒòΪ°æ±¾Ô­ÒòÂÔÓвîÒ죬ÕâÒ²Ó¡Ö¤Á˶þÕß¼äµÄÇ¿¹ØÁªÐÔ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÁíÍâ,´ÓÁ÷´«Ê±¼äµÄ½Ç¶È·ÖÎö,¡°AVE_MARIA¡±¹ØÁªÑù±¾×î³õ·ºÆðµÄʱ¼ä(2018Äê12ÔÂ2ÈÕ)ÂÔÍíÓÚWarzoneRATÔÚÂÛ̳µÄÐû²¼Ê±¼ä(2018Äê10ÔÂ22ÈÕ)£¬ÕâÒ²Çк϶ñÒâ´úÂëÁ÷´«µÄʱ¼äÂß¼­¡£


ÒÀ¾ÝÒÔÉϼ¸µã·ÖÎö£¬ÎÒÃÇÈÏΪÁ½Õß¾ßÓи߶ȵÄÒ»ÖÂÐÔ¡£´ÓÄ¿Ç°ÒÑÖªµÄÇé¿ö¿´£¬WARZONE±»É±¶¾³§É̹㷺µÄʶ±ðΪAVE_MARIA£¬¶øÔÚÉîÈë±È¶Ô·ÖÎöºó£¬ÎÒÃÇÅж¨ºÚ¿Í×é֯ʹÓõÄÔ¶¿ØľÂíÕýÊÇWARZONE RAT¡£Òò´Ë¿ÉÒÔ½«´ËÀà°üÂÞ¡°AVE_MARIA¡±×Ö·û´®µÄ¶ñÒâÑù±¾¼Ò×åÃüÃû¸üÐÂΪ¡°WARZONE¡±¡£



4.3 ÓòÃû¹ØÁª



ÎÒÃÇÊӲ쵽ĿǰÓëDDNS·þÎñwarzonedns.comÏà¹ØÁªµÄ×ÓÓòÃû×ÜÊý¹²101¸ö£¬²¿ÃŽØͼÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÕâÅúÓòÃû¾ùΪwarzonedns.comÌṩµÄÃâ·Ñ×ÓÓòÃû£¬ÇÒ´ó²¿ÃŹØÁªÖÁ¶ñÒâÑù±¾£¬Õâ±íÃ÷´óÁ¿ºÚ¿ÍÕýÔÚÀÄÓôËÀà·þÎñ½øÐжñÒâ¹¥»÷¡£


¿ÉÒÔÅжÏ£¬SolmyrÍÅ»ï×÷ΪWARZONEÀà¶ñÒâÈí¼þ¹¤ÒµÁ´µÄÉÏÓι©Ó¦ÉÌ£¬ÌṩÁË°üÂÞÃâ·ÑÓòÃû·þÎñ¡¢ÊշѶñÒâÈí¼þ¼°ÆäËü¶ñÒâÀûÓü¼ÊõµÈһϵÁзþÎñ£¬´ò°üÊÛÂô¸øÏÂÓκڿÍʹÓᣴ˴ÎʼþµÄ¹¥»÷×é֯ҲΪÆäÏÂÓοͻ§£¬Í¨¹ý¹ºÖÃÆ䲿ÃÅ·þÎñ£¬Óë×ÔÉíµÄ¶ñÒâ´úÂë×éºÏÀûÓÃÀ´µ½´ï¸ü¼ÑµÄ¹¥»÷Ч¹û£¬Í¬Ê±Ò²ÄܸüºÃµÄÒþ²Ø×Ô¼ºµÄÉí·Ý¡£



5×Ü ½á



±¾ÎĶԱ¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Á÷³Ì¡¢Ïà¹ØµÄ¶ñÒâ´úÂë¡¢ºÚ¿ÍÅä¾°µÈ×öÁËÉîÈëµÄ·ÖÎöºÍÑо¿£¬´ÓÉÏÎĵķÖÎöÖÐÎÒÃÇ¿ÉÒÔ¿´³ö¸ÃºÚ¿Í×é֯ĿǰµÄ¹¥»÷»î¶¯Ê®·Ö½÷É÷£¬¼ÈûÓдó¹æÄ£µÄ¹¥»÷£¬Ò²Ã»ÓнÓÄɸ߳ɱ¾µÄ0day©¶´£¬Í¬Ê±£¬¹¥»÷»î¶¯Ê±¼äÒ²·Ç³£¶Ì¡£Õâ±íÃ÷¸Ã¹¥»÷»î¶¯»¹´¦ÓÚ³õÆÚ£¬²¢¶ÔÄ¿±ê½øÐÐÁËһЩÊÔ̽ÐÔ¡¢Õë¶ÔÐԵĹ¥»÷£¬Ò²ÎªºóÐøµÄ¹¥»÷×öºÃ×¼±¸¡£´ËÍâͨ¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´£¬ÎÒÃÇÈ·¶¨Á˸ôλ±³ºóµÄºÚ¿Í×éÖ¯£¬²¢Æ¾¾Ý¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯ÀúÊ·£¬·¢ÏÖÆäÃñ×åÖ÷ÒåÉ«²ÊÇ¿ÁÒ£¬Òò´ËÕþÖÎÄ¿µÄÒâͼҲ½ÏΪÃ÷ÏÔ¡£


µ±Ç°ÀûÓúê½øÐÐÍøÂç¹¥»÷ÒѾ­³ÉΪһÖֳɱ¾½ÏµÍµÄ¹¥»÷·½Ê½£¬Òò´ËÒ²±»´óÁ¿µÄºÚ¿Í×éÖ¯ËùʹÓ᣺ڿ;­³£ÀûÓÃÄ¿±êµÄһЩµ¥±¡»·½ÚÀ´½øÐдËÀ๥»÷£¬¾ßÓÐÒ»¶¨µÄÀÖ³ÉÂÊ£¬Í¨¹ýÓÕ¶üÎĵµ¿ÉÒÔ¿´³ö£¬±¾´Î»î¶¯Õë¶ÔµÄÊÇÕþ¸®»ú¹¹µÄÕÐƸ²¿ÃÅ£¬´ËÀàÈËȺ¾ßÓÐÏà¶Ô½ÏÈõµÄÄþ¾²Òâʶ£¬ÇÒÓÉÓÚÊÂÇéÖÐÐèÒª·­ÔĵļòÀúÁ¿½Ï¶à(Èç²ÆÕþ²¿ÃŵļòÀúÁ¿Í¨³£½Ï´ó)£¬Ê¹µÃÏà¹ØÈËÔ±ÎÞ·¨·Ö±æαװµÃ½ÏºÃµÄ¶ñÒâ¼òÀúÎļþ¡£ÔÙ¼ÓÉ϶à½×¶ÎÔÚÏßÏÂÔضñÒâ´úÂëµÄ¼Æı¡¢ÎÞÎļþ¼¼ÊõºÍ´ò°ü¼ÓÃܼ¼ÊõµÄʹÓ㬴Ӷø´ó´óÌá¸ßÁ˹¥»÷µÄÀÖ³ÉÂÊ¡£Òò¶ø´ËÀ๥»÷ÐèÒªÏà¹Ø²¿ÃÅÌá¸ß¾¯Ì裬¼ÓÇ¿Ìåϵ¼Ü¹¹ÖеĶ̰å·À·¶¡£

IOC

MD5

99C82F8A07605DA4CCC8853C910F7CAF

048DCA20685ECD6B7DBDBF04B9082A54

DEF105A9452DEF53D49631AF16F6018B

1E19266FC9DFF1480F126BD211936AAC

262D9C6C0DC9D54726738D264802CCAD

B3C9F98DD07005FCCF57842451CE1B33

497566120F1020DBD6DF70DD128C0FFB

ÓòÃû

linksysdatakeys[.]se

gestomarket[.]co

asdfwrkhl.warzonedns[.]com

casillas.hicam[.]net

casillasmx.chickenkiller[.]com

casillas.libfoobar[.]so

du4alr0ute.sendsmtp[.]com

settings.wifizone[.]org

wifi.con-ip[.]com

rsaupdatr.jumpingcrab[.]com

activate.office-on-the[.]net