Õë¶ÔÖÆÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷»î¶¯Éî¶È·ÖÎö

Ðû²¼Ê±¼ä 2019-11-07

½üÆÚ £¬¶«É­Æ½Ì¨ADLab·¢ÏÖ´óÁ¿Ê¹ÓøßΣ©¶´CVE-2017-11882½øÐÐÍøÂç¹¥»÷µÄʼþ £¬ÆäÖÐÒ»Åú¹¥»÷ÔغÉÒýÆðÁËÎÒÃǵÄ×¢Òâ £¬ËûÃǾùÒÔÀàËÆ¡°¸¶¿îÊվݡ±¡¢¡°ÒøÐÐÈ·ÈÏ¡±µÈ×ÖÑù×÷Ϊ¹¥»÷ÔغÉÃû³Æ¡£¸ÃÅú¹¥»÷Ôغɴó²¿ÃÅͨ¹ýÓʼþ¸½¼þµÄ·½Ê½½øÐеöÓã¹¥»÷ £¬ÔÚ·ÖÎö¹ý³ÌÖÐ £¬ÎÒÃÇ·¢ÏÖÁ˺ڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÏà¹ØÐÅÏ¢ £¬´ËÅúºÚ¿ÍÒѾ­ÀÖ³ÉÉø͸½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÖÆÒ©ÆóÒµ £¬ÒÔ¼°Î÷°àÑÀµÄÕþ¸®¡¢ÆóÊÂÒµµ¥ÔªµÈ»ú¹¹ £¬¶øÇÒ͵ȡÁË´óÁ¿µÄÃôÇé¸Ð±¨¡£ÎÒÃÇͨ¹ýËÝÔ´·ÖÎöÈ·¶¨´Ë´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ £¬¶øÇÒÓɵ±Ç°¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£Í¨¹ý¶Ô¸ÃÅúÑù±¾µÄ·ÖÎö·¢Ïִ˴ι¥»÷»î¶¯×îÔç¿É×·Ëݵ½2019Äê7Ô £¬½ØÖÁÄ¿Ç° £¬Ïà¹ØµÄÉèÊ©ÒÀÈ»ÔÚʹÓÃÖв¢Á¬ÐøÔÚÊÕ¼¯Ç鱨ÐÅÏ¢¡£¸ÃºÚ¿Í×éÖ¯»¹¹¥ÏÝÁËÎ÷°àÑÀÒ»¼Ò´óÐÍ´¬²°¹ÜÀí¹«Ë¾µÄ¹Ù·½ÍøÕ¾×÷ΪÇ鱨ÇÔÈ¡µÄÃØÃܻش«µã £¬ÊÔͼÒþ²Ø×ÔÉíÉí·Ý¡£


ÔÚ±¾´Î¹¥»÷ÖÐ £¬ºÚ¿Í×é֯ͨ¹ýÓʼþ½«¾«ÐĽṹµÄOfficeÎļþ£¨Õë¶ÔCVE-2017-11882©¶´ÖÆ×÷µÄ£©×÷Ϊ¸½¼þ·¢Ë͸øÄ¿±êÓÊÏä £¬²¢ÓÕʹÊܺ¦Õßµã»÷ÒÔÇÖÈëÄ¿±êϵͳ£¨ËäÈ»ÕâÖÖÒÔÉ繤ÐÎʽÕÒµ½Ä¿±êÓÊÏ䲢ͨ¹ýÓʼþµÄ·½Ê½½øÐй¥»÷µÄÊÖ·¨ÀÏÌ× £¬µ«È´ÊǺڿÍ×î³£ÓõĹ¥»÷ÊÖ·¨Ö®Ò» £¬¶øÇÒ½áºÏÉ繤ÐÅϢαÔìµÄÓʼþÒ²¾ßÓкܸߵÄÀÖ³ÉÂÊ, ²¿ÃÅÐÐÒµºÍÆóÊÂÒµµ¥ÔªÓÉÓÚδ½øÐÐÏà¹Ø©¶´²¹¶¡¸üжøÒ×Êܵ½¹¥»÷£©¡£¹¥»÷Ôغɻáƾ¾ÝµØÀíλÖõIJîÒì¶øÔÚÊܺ¦ÕßµçÄÔÉÏÏÂÔز¢°²×°Agent Tesla¡¢HawEye Keylogger¡¢NanoCore RAT»òNetWire RATµÈ¶à¿î¼äµýľÂí £¬ÒÔ¶Ô¹¥»÷Ä¿±êʵʩºã¾ÃµÄ¼à¿Ø¿ØÖÆ¡¢Ãô¸ÐÐÅÏ¢ÇÔÈ¡µÈ¶ñÒâÐÐΪ¡£


±¾ÎĽ«¶ÔºÚ¿Í×éÖ¯ËùʵʩµÄ¹¥»÷¹ý³Ì½øÐÐÏêϸµØ·ÖÎöºÍËÝÔ´ £¬²¢¶ÔÆäËùʹÓõļäµýÈí¼þºÍ»ù´¡ÉèÊ©½øÐÐ͸³¹µØ·ÖÎö¡£



1¡¢¹¥»÷¹ý³Ì·ÖÎö


´Ë´Î¹¥»÷ʼÓÚÒ»¸öЯ´øCVE-2017-11882©¶´µÄEXCELÎĵµ £¬ºÚ¿ÍʹÓÃαװ³É¡°ÒøÐÐÈ·ÈÏ¡±µÄµöÓãÓʼþ·¢Ë͸ø¹¥»÷Ä¿±ê £¬µ±Óû§´ò¿ªÎĵµºó±ã»áÖ´ÐÐshellcode´úÂë £¬²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÉÏÏÂÔØPayload²¢Ö´ÐС£¸ÃPayload»áÔÚÄÚ´æÖнâÃܳöеÄPE²¢×¢È뵽ϵͳ½ø³ÌRegAsm.exeÖÐ £¬ÀÖ³É×¢Èëºó±ã¿ªÊ¼½øÐÐʵʱ¼à¿Ø¡¢ÇÔÃܵÈÐÐΪ £¬×îÖÕ½«ÇÔÈ¡µ½µÄÓû§ÐÅÏ¢»Ø´«µ½ÍйܷþÎñÆ÷¡£


1.1 ¹¥»÷Á÷³Ì


ÏÂͼչʾÁ˴˴ι¥»÷»î¶¯ÍêÕûµÄÁ÷³Ì£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 Í¼1 ¹¥»÷Á÷³Ìͼ



1.2 ¹¥»÷Ä¿±ê


±»¹¥»÷¹«Ë¾ÐÅÏ¢¼°Ïà¹ØÓʼþ1£º


µöÓãÓʼþÊÇ·Ö·¢µ½µÂ¹úµÄÒ»¼Ò¼Ò×åÆóÒµ¹«Ë¾¡£¸Ã¹«Ë¾ÊÇרÃÅÑо¿¶¯Ö²ÎïÔ­ÁϵÄÌáÈ¡ £¬ÆäÖ÷ÒªÒµÎñÊÇÑо¿ÖÆÒ©¡¢»¯×±Æ·ºÍÉúÎïµÈ¼¼Êõ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ2 Ä¿±ê¹«Ë¾1


ͨ¹ýͼ2¿ÉÒÔ¿´µ½ £¬¹¥»÷Õß¿ÉÒԴӸù«Ë¾µÄÖ÷Ò³ÉÏ»ñÈ¡ÓÊÏäµØÖ· £¬²¢½«×ÔÉíαװ³É¡°¸¶¿îÈ·ÈÏ¡±µÈ֪ͨÓʼþ £¬ÓÕʹÊܺ¦Õß´ò¿ª¸½¼þÎĵµ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ3 µöÓãÓʼþ1


±»¹¥»÷¹«Ë¾ÐÅÏ¢¼°Ïà¹ØÓʼþ2£º


ÁíÒ»ÃûÊܺ¦ÕßÊǵ¹úµÄÒ»¼ÒÒ½ÁÆÒ©Æ·Æ÷е¹«Ë¾¡£¸ÃÊÕ¼þÓÊÏäµØַͬÑù¿ÉÔÚÆä¹ÙÍøÉÏ»ñÈ¡¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4 Ä¿±ê¹«Ë¾2


·¢Ë͸øÄ¿±ê¹«Ë¾µÄµöÓãÓʼþʾÀýÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ5 µöÓãÓʼþ2


Á½ÆðµöÓãÓʼþµÄ¸½¼þ¾ùÊÇÃûΪ¡°bank cconfirmation¡±µÄXLSXÎĵµ £¬¶ø¸Ã¸½¼þÎļþÊÇÎÒÃDz¶×½µÄÖÚ¶àʹÓÃCVE-2017-11882©¶´µÄ¶ñÒâÎĵµÖ®Ò»¡£


1.3 ÓÕ¶üÓʼþ


Á½·âÓʼþµÄÄÚÈÝ¡¢·¢¼þÈËÒÔ¼°¶ñÒâÎĵµµÄÃû³Æ £¬¾ù±£³Öן߶ȵÄÒ»ÖÂÐÔ¡£Ëæºó £¬ÎÒÃǽ«¶ÔÓʼþÐÅÏ¢×ö½øÒ»²½µÄ·ÖÎö £¬ÒÔ±ãÍÚ¾ò³ö¸ü¶àµÄ¹ØÁªÏßË÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ6 ÓʼþÍ·²¿ÐÅÏ¢


ͨ¹ý¶ÔÓʼþÐÅÏ¢½øÐнâÎö¿ÉÒÔ¿´µ½Èçͼ6Ëùʾ £¬·¢¼þµØÖ·ÀïÁгöµÄʵ¼Êµç×ÓÓʼþµØַΪ¡±mana00.balaempre.com¡±¡£Æ¾¾ÝÓÊÏäºó׺Ãû½øÐвéѯ £¬·¢ÏÖÆäËù¶ÔÓ¦µÄÊÇÒ»¿îÃûΪ¡°AutoPMTA¡±µÄ×Ô¶¯»¯µç×ÓÓʼþ·Ö·¢·þÎñÆ÷ £¬²¢ÔÚ¹úÍâµÄÍøÕ¾ÖÐƾ¾Ý¾ßÌ幦ЧÊÕÈ¡²îÒìµÄÓöÈ¡£ÓÉ´ËÎÒÃÇÍƲâºÚ¿Í×éÖ¯¾ÍÊÇÀûÓô˿îÈí¼þÀ´½øÐÐÓÊÏäµØÖ·µÄÊÕ¼¯ºÍÓʼþµÄÅúÁ¿·Ö·¢¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ7 AutoPMTAÓʼþ·Ö·¢Æ÷


¶øÔÚÁíÒ»·âÓʼþÖÐ £¬ÎÒÃÇÊ״η¢ÏÖÁËÒ»¸öÊôÓÚÄáÈÕÀûÑǵÄÔ¶³ÌIPµØÖ· £¬¸ÃÏßË÷µÄ·ºÆðÔÚºóÐøµÄ¹ØÁªËÝÔ´ÖÐÆð×ÅÖØÒªµÄ×÷Óà £¬ÔÚÕâÀïÏȽ«Æä¼Ç¼ÏÂÀ´¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ8 IPµØÖ·²éѯÐÅÏ¢



2¡¢ÑùÌìÖ°Îö


2.1  ¶ñÒâÎĵµ


ÔÚδÐÞ¸´CVE-2017-11882©¶´µÄ¼ÆËã»úÉÏ £¬µ±Óû§´ò¿ª¶ñÒâEXCELÎļþʱ £¬OfficeÎĵµÖеĹ«Ê½±à¼­Æ÷»áÆô¶¯EQNDT32.EXE½ø³Ì¡£µ±Equation¹¤¾ßÖдæÔÚ±ê־Ϊ×ÖÌåÃû³ÆµÄ³¬³¤×Ö½ÚÁ÷ £¬Ôò·¨Ê½ÔÚ´¦ÖøÃ×Ö·û´®µÄ¹ý³ÌÖÐ £¬»á´¥·¢Õ»Òç³ö©¶´¡£¶ø´Ë¶ñÒâÎĵµ±ãÊÇÀûÓø鶴½«Ö¸ÏòshellcodeµÄÕ»µØÖ·ÁýÕÖÁËԭʼ·µ»ØµØÖ· £¬´Ó¶øÖ´ÐÐÔ¶³ÌpayloadµÄÏÂÔØ¡£


¼ì²ìole¹¤¾ßµÄĿ¼½á¹¹ £¬¿ÉÒÔ¿´µ½ole¹¤¾ßÒѱ»Ê¶±ðΪCVE-2017-11882£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ9 OLE¹¤¾ßµÄĿ¼½á¹¹


ÓÉÓڸûº³åÇøÒç³öº¯Êý´¦ÓÚEQNDT32½ø³ÌÖÐ £¬ËùÒÔÎÒÃÇÌáÇ°½«EQNDT32.EXE¼ÓÔØÆðÀ´²¢ÕÒµ½Â©¶´Òç³ö´¦Ï¶ϵã £¬ÖØдò¿ªÓÕ¶üÎĵµºó £¬·¢ÏÖÕ»Öзµ»ØµØÖ·0x004115D8±»ÁýÕÖ £¬´Ó¶øתÏòshellcodeÖ´ÐС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ10 Õ»ÖÐÉú´æµÄԭʼº¯Êý·µ»ØµØÖ·


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ11 ±»ÁýÕÖºóµÄº¯Êý·µ»ØµØÖ·


2.2 shellcode


RetnÖ´Ðкó·¨Ê½»áתµ½0x0012F350´¦ £¬ÕâÀï´æ·ÅµÄ¾ÍÊÇFONT[name]Êý¾Ý £¬Ò²¾ÍÊÇshellcode´úÂëλÖá£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ12 shellcode´úÂëÖ´Ðд¦


¸Ã¶ÎshellcodeµÄ¹¦Ð§ÊÇ £¬½«Ô¶³Ì·þÎñÆ÷¡°http[:]//34.87.19.73/pqis/11a.exe¡±ÉϵÄPayloadÏÂÔص½µ±µØ £¬²¢Éú´æΪ¡°%AppData%Roaming\powerpoint.exe¡± £¬×îºóÔËÐи÷¨Ê½¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ13 ÁªÍøÏÂÔØPayload


2.3 Payload


ÃûΪ11a.exeµÄPayloadÊÇʹÓÃMS Visual BasicÓïÑÔ±àдµÄ¡£µ±¶ñÒⷨʽÔËÐÐʱ £¬»áÔÚϵÍÂäÙʱĿ¼ÏÂÏÈ´´½¨¡°subfolder¡±×ÓĿ¼²¢Éú³ÉÁ½¸öÎļþ£¨explorer.exeºÍexplorer.vbs£© £¬½Ó×ÅÔËÐÐexplorer.vbs½Å±¾²¢½áÊø×ÔÉí½ø³Ì¡£explorer.vbs½Å±¾µÄ¾ßÌåÄÚÈÝÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ14 explorer.vbs½Å±¾ÄÚÈÝ


´Óͼ14µÄVBSÎļþÄÚÈÝ¿ÉÒÔ¿´³ö £¬½Å±¾ÖÐʹÓÃÁËwscript shellÃüÁî×öÁËÁ½¼þÊ¡£Ê×ÏȽ«×ÔÉíÌí¼Óµ½×¢²á±í¿ª»ú×ÔÆô¶¯ÏîÖÐ £¬ÒÔ±ãÿ´ÎÔÚϵͳÆô¶¯Ê±¶¼ÄÜ×Ô¶¯ÔËÐÐexplorer.vbsÎļþ £¬ÓÃÒÔʵÏÖÆä³Ö¾ÃÐÔ £»Æä´Î £¬ÔËÐпÉÖ´ÐÐÎļþexplorer.exe¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ15 Ìí¼Ó×¢²á±íÏî


2.4 Agent Tesla


ͨ¹ý·ÖÎö £¬¿ÉÒÔÈ·¶¨explorer.exe·¨Ê½ÊÇÎÛÃûÕÑÖøµÄ¼äµýÈí¼þ¡°Agent Tesla¡±¡£¸ÃľÂíÔËÐкó»áÁ¢¼´ÖØд´½¨Ò»¸ö¹ÒÆðµÄ×ÔÉí×Ó½ø³Ì¡£×Ó½ø³ÌµÄÏà¹ØÊôÐÔÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ16 ×Ó½ø³ÌÊôÐÔÐÅÏ¢


È»ºó×Ó½ø³Ì»á´Ó×ÊÔ´Êý¾ÝÖнâÃܳöÁíÒ»¸öÓÉ.NET±àдµÄPEÎļþ £¬Æ佫»áÔÚÄÚ´æÖÐÖ±½ÓÔËÐС£ÏÂͼÊÇÔÚ·ÖÎö¹¤¾ßÖÐÏÔʾµÄ¸Ã.NET·¨Ê½µÄÖ÷Òª¹¦Ð§£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ17 Ö÷Òª¹¦Ð§´úÂ벿ÃŽØͼ


¸Ã·¨Ê½»áʵÑé·ÃÎÊ¡°checkup[.]amazonaws.com¡± £¬ÒÔ´ËÀ´»ñÈ¡µ±µØ»úÆ÷µÄÍâÍøIPµØÖ·¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ18 »ñÈ¡µ±µØIPµØÖ·


´Óͼ17µÄÄÚÈÝ¿ÉÒÔ¿´µ½ £¬·¨Ê½´úÂëʹÓÃÁË»ìÏý¼¼ÊõÀ´Ôö¼Ó·ÖÎöÄѶÈ¡£´ËÍâ £¬Æ仹»á¶ÔVM¡¢É³Ïä¡¢µ÷ÊÔÆ÷ºÍÆäËû¼à¿Ø¹¤¾ßµÈ×öһϵÁеļì²â¡£ÈçÔËÐл·¾³Äþ¾² £¬.NET·¨Ê½Ôò¿ªÊ¼¼àÊÓ²¢ÊÕ¼¯Êܺ¦ÕßµÄÐÅÏ¢ £¬²¢Ê¹ÓÃSMTPЭÒ齫¼à¿ØÈÕÖ¾·¢Ë͸øÔ¶³Ì·þÎñÆ÷¡°smtp[.]diagnosticsystem.in¡±¡£


Agent Tesla¼Ò×å


»ùÓÚÒÑÖªµÄÏà¹Ø×ÊÁÏ £¬´Ó2014ÄêÆðÆù½ñΪֹ £¬Agent TeslaÒÑ´æ»î³¤´ï5ÄêÖ®¾Ã¡£Ëæ×Åʱ¼äµÄÍÆÒÆ £¬¸ÃľÂíÔÚ½Ðø²»Í£µÄµü´ú¸üР£¬×îа汾Ŀǰ¿Éƾ¾ÝÐèÇóÔÚ»¥ÁªÍøÉÏËæÒ⹺Öá£


Agent Tesla¿Éʵʱ¼à¿ØºÍ¼Ç¼Óû§µÄ¼üÅÌÊäÈë¡¢ÇÔÈ¡¼ôÇаåÊý¾Ý¡¢ÆÁÄ»½Øͼ¡¢»ñÈ¡Ö÷»úÐÅÏ¢ £¬ÒÔ¼°ÊÕ¼¯¸÷´óä¯ÀÀÆ÷ºÍÓÊÏäµÄÓû§Æ¾Ö¤²¢»Ø´«ÖÁºÚ¿Í·þÎñÆ÷¡£Ò²ÕýÒòΪÆ书Ч·Ç³£Ç¿´ó £¬ËùÒÔ½ü¼¸ÄêÒÔÀ´¾­³£±»ºÚ¿Í×éÖ¯ËùÀûÓá£

ÏÂͼÊÇ´ÓÆäÍøÕ¾ÉÏժȡÏÂÀ´µÄ²¿ÃŹ¦Ð§½éÉÜ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ19 Agent TeslaXÏà¹Ø¹¦Ð§


½ØÖ¹µ½Ä¿Ç° £¬¼øÓÚÎÒÃÇ·ÖÎöµÄÕâ¿îбäÖֺ;ɰæµÄľÂíÔÚ¹¦Ð§ºÍ¼¼ÊõÉÏÀàËÆ £¬²¢Ã»Óз¢ÏÖÌ«¶àµÄ±ä»¯µã¡£ËùÒÔ±¾ÎÄÔÚÕâÀï²»ÔÙ¹ý¶àµÄÏêϸÃèÊöÆä¾ßÌåµÄ¼¼Êõϸ½Ú £¬ÈçÓÐÐèÒª¸÷È˿ɼì²ìÎÄÄ©µÄ²Î¿¼ÎÄÏס£



3¡¢ËÝÔ´Óë¹ØÁª·ÖÎö


3.1  ¶ñÒâÓòÃû·ÖÎö


ÎÒÃÇÊ×ÏÈ´Ó¶ñÒâÎĵµ´¥·¢Â©¶´ºóÖ´ÐеÄshellcodeÖÐÌáÈ¡³öÒ»¸öÓ²±àÂëµÄÁ´½ÓµØÖ·£º¡°http[:]//34.87.19.73/¡±¡£¾­¹ýºǫ́´óÊý¾ÝµÄÑù±¾¹ØÁª·ÖÎöºó £¬´Ó¸ÃÍйܵÄÍⲿÖ÷»úÉÏÍÚ¾ò³ö¸ÃºÚ¿Í×éÖ¯×Ô2019Äê9ÔÂÆðʹÓõÄÖî¶àÀàÐ͵ļäµýľÂí¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ20  ÍйÜÖ÷»úÉϵÄľÂíÐÅϢͳ¼Æ


½Ó×Å £¬ÌáÈ¡¸ÃÅúľÂíÑù±¾Ê¹ÓõÄC2ÓòÃû½øÒ»²½µÄ¹ØÁª³ö²¿ÃÅ¿ÉÒɵÄCCµØÖ·¡£ÀýÈç £¬²¿ÃÅľÂí»á½«SMTPÁ÷Á¿·¢Ë͵½smtp[.]diagnosticsystem.in £¬¶ø¸ÃÓòÃû½âÎöµÄIPµØַΪ208[.]91[.]199[.]143¡£


DNS²éѯ´ËÓòÃû £¬·¢ÏÖÆä×¢²áʱ¼äΪ2019Äê9ÔÂ19ÈÕ £¬ÕâÓë¸ÃÅúľÂíµÄÁ÷´«Æðʼʱ¼äÕýºÃÎǺÏ¡£ÓòÃû²éѯÐÅÏ¢ÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ21 ÓòÃûµÄ×¢²áʱ¼ä


ÔٴζÔÏßË÷×öÀ©Õ¹ºÍ¶Ô¸ÃÓòÃû½øÐÐÉîÈëµÄ×·×Ù·ÖÎöºó £¬ÎÒÃÇ»ñµÃÁ˸ü¶àµÄ¶ñÒâÑù±¾ £¬ÒÔ¼°ÕâЩÓòÃûÔø½âÎöµ½µÄÖ÷»úIPµØÖ·¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ22 ÓòÃû½âÎöµÄIPµØÖ·


ÎÒÃÇ´Ó»ñÈ¡µÄ´óÁ¿¶ñÒâÑù±¾ÖÐÕûÀí³ö½üÆÚ±ÈÁ¦»îÔ¾µÄ £¬Í¨¹ýÊÖ¶¯·ÖÎöÈ·¶¨Á˴˴ι¥»÷»î¶¯ÖÐʹÓõĴóÁ¿C2ÓòÃû¡£¾­¹ý²éѯ½âÎöºó·¢ÏÖ £¬ÕâЩÓòÃû¾ùÊÇÒÔÉÏIPµØÖ·¡°208.91.199.**¡±ºÍ¡°208.91.198.143¡±µÄCNAME¡°us2.smtp.mailhostbox.com¡±µÄ±ðÃû¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ23 ÓòÃû²éѯÐÅÏ¢


ͼÖÐÁоÙÁ˲¿ÃÅ»îÔ¾Ñù±¾ºÍÆä·ÃÎʵÄÓòÃû £¬¾ßÌå¶ÔÓ¦¹ØϵÈçÏÂËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ24 ¶ñÒâÑù±¾ÓëC&C·þÎñÆ÷µÄ¹Øϵͼ


3.2 ¹ØÁªÓʼþ


ƾ¾ÝͬԴ·ÖÎö £¬ÎÒÃÇ·¢ÏÖÁËÁíÍâÒ»·âÕë¶ÔÎ÷°àÑÀµØÓòµÄµöÓãÓʼþ¡£¸ÃÓʼþµÄ·¢¼þµØÖ·ÊÇÎ÷°àÑÀÒ»¼ÒÃûΪ¡°MAJ AGROQUIMICOS¡±µÄÅ©Ò©ÐÐÒµ¹«Ë¾¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ25 MAJ AGROQUIMICOS¹«Ë¾Ê×Ò³


ÓʼþÄÚÈÝʹÓõÄÊÇÎ÷°àÑÀÓï £¬´óÖÂÒâ˼ÊǸ¶¿îÈ·ÈÏÊé £¬µöÓãÓʼþµÄ¸½¼þÊÇÒ»¸öαװ³É.img¸ñʽµÄISOÎļþ¡£ËäÈ»ÎļþÃû³ÆÓëÓʼþµÄÄÚÈÝÓÐËù²îÒì £¬µ«ÊÇ´Ó·¢¼þµØÖ·À´¿´ £¬ÆäÀ´Ô´Ò²ÓпÉÄÜ»áÊǹ¥»÷Ä¿±êµÄºÏ×÷ÉÌ»ò¹©Ó¦ÉÌÖ®Àà £¬ÕâÑù±ã¿ÉÔö¼ÓÓʼþµÄÕæʵÐÔ £¬Í¬ÑùÓлú»áÓÕʹÊܺ¦ÕßÏÂÔظ½¼þ¡£Óʼþ¾ßÌåÄÚÈÝÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ26 Î÷°àÑÀÓïµÄµöÓãÓʼþ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ27 Óʼþ·­ÒëºóµÄÄÚÈÝ


3.3 ISOÎļþ


ISOÓ³ÏñÊÇÒ»ÖÖ¹âÅ̵Ĵ浵Îļþ £¬ÆäÖаüÂÞ½«ÒªÐ´Èë¹âÅ̵ÄËùÓÐÐÅÏ¢¡£Í¨³£ÓÃÓÚ´´½¨CD»òDVDµÄ±¸·Ý¡£ÓÉÓÚISOÎļþµÄ³ß´çÏà¶Ô±ÈÁ¦´ó £¬ËùÒÔÓпÉÄܵ¼Öºܶàµç×ÓÓʼþÍø¹ØɨÃ跨ʽÎÞ·¨Õýȷʶ±ð´ËÀàÐ͵ĸ½¼þ¡£¶øÇÒ×ÔWin 8¼°ÒÔÉϵĸü¸ß°æ±¾ºó £¬Windows¶¼×Ô´øISOÔËÐй¤¾ß £¬Óû§¾ÍÏñ´ò¿ªEXEÎļþÒ»Ñù £¬Ö±½ÓË«»÷ISOÎļþ¼´¿ÉÔËÐС£Òò´ËÕâ´Î¹¥»÷ÖкڿÍʹÓÃÁËISOÎļþ×÷Ϊ¶ñÒ⸽¼þ¡£


3.4 ¶ñÒ⸽¼þ


ǶÈëÔÚIOS¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ28 ǶÈëµÄ¿ÉÖ´ÐÐÎļþ


ǶÈëµÄ¿ÉÖ´ÐÐÎļþ


ʹÓ÷ÖÎö¹¤¾ß¿ÉÒÔ¿´µ½ £¬Õâ¸öÃûΪ¡°SOA300329042943243_pdf.exe¡±µÄ¿ÉÖ´ÐÐÎļþʵ¼ÊÉÏÊÇÒ»¸öAutoIt½âÊÍÆ÷ £¬²¢Ç¶ÈëÁËAutoIt±àÒë½Å±¾×÷Ϊ×ÊÔ´¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ29 ¿ÉÖ´ÐÐÎļþµÄ×ÊÔ´ÐÅÏ¢


¸Ã¿ÉÖ´ÐÐÎļþÔËÐкó £¬»áÔÚ%User\Public%Ŀ¼ÏÂÊͷŶñÒâµÄVBS½Å±¾Îļþ²¢½«¸ÃĿ¼Ìí¼Óµ½×¢²á±íµÄRunÆô¶¯ÏîÖÐ £¬ÒÔʵÏÖÆä³Ö¾ÃÐÔ¡£½Ó×ÅÔÙ½«ÄÚ´æÖнâÃܳöµÄµÄPEÎļþ×¢È뵽ϵͳÎļþ¡°Regasm.exe¡±ÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ30 ÔÚ×¢²á±íÖÐÌí¼Ó×ÔÆô¶¯Ïî


ÐÂPEÎļþ


ͨ¹ý·ÖÎöÄÚ´æÖнâÃܳöµÄÐÂPEÎļþ £¬ÎÒÃÇÈ·¶¨¸ÃEXEÊÇÁíÒ»°æʹÓÃ.NET¿ò¼Ü±àдµÄAgent TeslaľÂí¡£ÔÚľÂí·¨Ê½ÀÖ³É×¢Èëµ½Regasm.exe½ø³Ì²¢ÔËÐкó £¬±ã¿ªÊ¼ÊµÑéÓëÔ¶³Ì·þÎñÆ÷½øÐÐÁ¬½Ó¡£


ÎÒÃÇÔÚ¶ñÒâ´úÂë·ÖÎö¹ý³ÌÖз¢ÏÖÁ˺ڿÍC&C·þÎñÆ÷ÉϵÄÏà¹ØÐÅÏ¢ £¬C&CÎļþĿ¼ÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ31 ·þÎñÆ÷ÉϵÄÎļþĿ¼


ͨ¹ý½øÒ»²½µÄ·ÖÎö £¬ÎÒÃÇ·¢ÏÖC&C·þÎñÆ÷ÉÏÉú´æ×Å´óÁ¿µÄ´ÓÊܺ¦Õß»úÆ÷»Ø´«µÄ¼à¿ØÈÕÖ¾ £¬Æ¾¾ÝÆä´¢´æµÄÎļþÃû³Æ¸ñʽºÍÄÚÈݵÈÌØÕ÷ £¬ÔÙ´ÎÈ·¶¨¸ÃľÂíÊÇ¡°Agent Tesla¡±¼Ò×å¡£


½ñºó £¬ÎÒÃÇ»¹×·×Ùµ½Á˸úڿÍ×éÖ¯ËùÊÕ¼¯µÄÊܺ¦ÕßÐÅÏ¢ £¬ÕâЩÐÅÏ¢ÒÔhtmlºÍjpegÎļþµÄÐÎʽ´æ´¢ÔÚC&C·þÎñÆ÷ÉÏ £¬ÆäÖÐhtml´æ´¢µÄÊDZ¾»úÐÅÏ¢¡¢¼üÅ̼Ǽ¡¢Õ˺ÅÃÜÂëµÈÐÅÏ¢ £¬jpeg´æ´¢µÄÊǽØÆÁÐÅÏ¢¡£ÏÂͼÊǽØÈ¡Á˲¿Ãżà¿ØÈÕÖ¾£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ32 »Ø´«µ½·þÎñÆ÷µÄ¼à¿ØÈÕÖ¾


´ÓÕâЩÎļþÃûÖеģº¡°Keystrokes¡±£¨¼üÅ̼Ǽ£©¡¢¡°Screen¡±£¨ÆÁÄ»½Ø£©¡¢¡°Recovered¡±£¨ÃÜÂë»Ö¸´£©µÈÒªº¦×Ö¿ÉÒÔ¿´³ö £¬Ä¾ÂíÊÇƾ¾ÝºÚ¿ÍµÄ¿ØÖÆÖ¸ÁîÀ´ÇÔÈ¡Êܺ¦ÕßµÄÏà¹ØÐÅÏ¢ £¬ÇÒƾ¾Ý¡°¹¦Ð§-Óû§Ãû-¼ÆËã»úÃû-ʱ¼ä£¨Äê-ÔÂ-ÈÕ-ʱ-·Ö-Ã룩¡±µÄ½á¹¹ÃüÃû²¢Éú´æΪHTML¸ñʽµÄÎļþ¡£


ÎÒÃǽ«Ò»¸öÒÔ¡°Recovery¡±¿ªÍ·µÄhtmlÎļþʹÓÃIEä¯ÀÀÆ÷´ò¿ª £¬Äܹ»¿´µ½Ä¾Âí¾ßÌåÊÕ¼¯ÁËÄÄЩÐÅÏ¢¡£ÆäÖаüÂÞÊܺ¦ÕߵļÆËã»úÓû§Ãû¡¢Ö÷»úÐÅÏ¢¡¢ÏµÍ³Ãû³Æ¡¢CPUÐÅÏ¢¡¢ÄÚ´æÐÅÏ¢¡¢IPµØÖ·ÒÔ¼°Chromeä¯ÀÀÆ÷ƾ¾ÝÐÅÏ¢µÈ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ33 HTMLÎļþµÄÄÚÈÝÏêÇé


3.5 »ù´¡ÉèÊ©·ÖÎö


ͨ¹ýÊÕ¼¯Óë¸ÃC&C·þÎñÆ÷Ïà¹ØµÄ»Ø´«ÐÅÏ¢½øÐÐÕûÀí·ÖÎöºó £¬ÎÒÃÇ·¢ÏÖÁ˼¸¸öÒªº¦ÐÅÏ¢¡£½áºÏÇ°ÎÄÖÐËѼ¯µ½µÄÏßË÷ £¬ÎÒÃǽøÒ»²½¼òÖ±ÈÏÁ˸÷þÎñÆ÷ÊDZ»ºÚ¿Í×éÖ¯¹¥Ïݺó £¬×¨ÃÅÓÃ×÷½ÓÊÕľÂí»Ø´«Êܺ¦ÕßÐÅÏ¢µÄ·þÎñÆ÷¡£¶ø¸Ã×éÖ¯ÔçÔÚ7Ô·ݵÄʱºò¾ÍÒÑ¿ªÊ¼ÊµÊ©¹¥»÷»î¶¯ £¬¶øÇÒÊܺ¦Õ߶àÊýÊÇÀ´×ÔÓÚÎ÷°àÑÀµØÓòµÄÆóÊÂÒµµ¥ÔªÊÂÇéÈËÔ±¡£ºÚ¿Í×éÖ¯¹ßÓÚÀûÓÃAgent Tesla»òHawkeye Keylogger¡¢Nanocore RATºÍNetWire RATµÈ¼äµýľÂíÀ´ÇÔÈ¡Ä¿±êÈËÔ±µÄµÇ¼ƾ֤µÈÐÅÏ¢ £¬ÇҴ˴ι¥»÷»î¶¯ÊÇÓÉÀ´×ÔÓÚÄáÈÕÀûÑǵĺڿÍ×éÖ¯³ïıÓëʵʩ¡£


3.5.1 Êܹ¥»÷·þÎñÆ÷·ÖÎö


ÎÒÃÇ×¢Òâµ½ £¬W-EAGLEĿ¼ÏÂÉú´æ×ÅÒ»¸öÃûΪ¡°W-EAGLE  PMS Deck.zip¡±µÄѹËõ°ü¡£½âѹ²¢´ò¿ªÄ³DOCÎĵµ £¬·¢ÏÖÕâÊÇÒ»¸ö´ø׏«Ë¾logoµÄÎ÷°àÑÀÓïÎļþ £¬±êÌâÔڹȸ跭ÒëΪ¡°¼×°å¼Æ»®µÄά»¤/¼ì²éÊֲᡱ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ34 W-EAGLEĿ¼ÏµÄÎļþÄÚÈÝ


ƾ¾Ý¹«Ë¾Ãû³ÆËÑË÷ºó֤ʵ £¬ÕâÊÇÎ÷°àÑÀÒ»¼Ò´óÐÍ´¬²°¹ÜÀí¹«Ë¾ £¬Ö÷Òª´ÓʸÉÉ¢»õ´¬µÄÔËÓª¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ35 W MARINE INC¹«Ë¾Ö÷Ò³ÐÅÏ¢


Èçͼ35Ëùʾ £¬¸Ã¹«Ë¾µÄÍøַͬºÚ¿ÍËùʹÓõķþÎñÆ÷Ãû³ÆÏàͬ £¬ÓÉ´ËÖ¤Ã÷´Ë·þÎñÆ÷ʵ¼ÊÊÇÊôÓڴ˹«Ë¾¡£¶øÇÒƾ¾Ý·þÎñÆ÷ÉÏÉú´æµÄÓë¸Ã¹«Ë¾ÓйصÄÎĵµ´´½¨Ê±¼äÊÇ2016Äê10ÔÂÖÐÏÂÑ®×óÓÒ £¬ÎÒÃÇÍƲâ´Ë·þÎñÆ÷Òòºã¾Ã±»ÏÐÖöøÎÞÈËά»¤ £¬ÖÂʹ±»ºÚ¿Í×éÖ¯¼ÓÒÔÀûÓá£


3.5.2 ¼à¿ØÈÕÖ¾ÐÅÏ¢


ÎÒÃǽ«ÊýÁ¿½ü2ÍòµÄ¼à¿ØÈÕÖ¾½øÐÐÕûÀí·ÖÎö £¬Êý¾ÝÏÔʾºÚ¿Í×é֯ʵ¼ÊÉÏ´Ó2019Äê7Ô±ãÒÑ¿ªÊ¼´¦ÓÚ»îԾ״̬ £¬Êܺ¦ÕßµÄÖ÷»úÐÅÏ¢ÒÔ¼°¸öÈ˵Ǽƾ֤Á¬ÐøµÄ±»»Ø´«µ½´Ë·þÎñÆ÷ÉÏ¡£½ØֹĿǰΪֹ £¬KeystrokesÎļþµÄÕ¼±ÈÂÊÏà¶Ô±ÈÁ¦´ó £¬Æä´ÎÊÇScreenÎļþ £¬RecovereyÎļþÏà¶Ô½ÏÉÙ¡£²»½öÈç´Ë £¬ÎÒÃǼà²âµ½´ËÀàÎļþÔÚ·þÎñÆ÷ÉÏÈÔÈ»²»¼ä¶ÏµÄÐÂÔö¡£


ÎļþÀàÐÍ

´´½¨Ê±¼ä

ÎļþÊýÁ¿

Keystrokes

2019Äê7ÔÂ16ÈÕ

8383

Screen

2019Äê8ÔÂ10ÈÕ

5447

Recovery

2019Äê7ÔÂ16ÈÕ

3859

±í1 ·þÎñÆ÷ÉϵÄÈÕ־ͳ¼Æ


3.5.3 Êܺ¦ÕßµØÓòºÍÐÐÒµÂþÑÜ


Êܺ¦ÕßIPµØÖ·Ö÷ÒªÂþÑÜÔÚÎ÷°àÑÀ¡¢Ó¡¶È £¬ÒÔ¼°ÉÙÁ¿À´×Ô°¢ÁªÇõºÍÄ«Î÷¸çµØÓò £¬Æä´ó¸ÅÕ¼±ÈÂÊÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ36 Êܺ¦ÕßµØÓòÂþÑÜͼ


»ùÓÚÎÒÃǶԺڿÍ×éÖ¯µÄ¹¥»÷ÐÅϢͳ¼ÆÏÔʾ £¬´Ë´Î¹¥»÷»î¶¯Éæ¼°µ½Î÷°àÑÀµØÓòµÄÊÐÕþ¸®¡¢Å©Òµ»úеÐÐÒµ¡¢Ë®Àû¹¤³ÌÐÐÒµºÍ¶ÔÍâóÒ×ÐÐÒµ £¬ÒÔ¼°Ó¡¶ÈºÍ°¢ÁªÇõµÈÆäËûÐÐÒµ¡£Ï±íչʾÁ˲¿ÃŵÄÏà¹Øͳ¼ÆÐÅÏ¢£º


¹«Ë¾Ãû³Æ

¹«Ë¾ÐÅÏ¢

FEMAC

λÓÚÎ÷°àÑÀµÄÒ»¼ÒÅ©Òµ»úе¹«Ë¾

XUNTA DE GALICIA

Î÷°àÑÀ¼ÓÀûÎ÷ÑǵØÓòµÄ·Ñ˹ÌØÀ­ÊÐÕþÌü

ICINCO

λÓÚÎ÷°àÑÀ¼ÓÄÉÀûȺµºµÄ½¨ÖþË®Àû¹¤³Ì¹«Ë¾

GALACANARIA

λÓÚÎ÷°àÑÀ´ó¼ÓÄÉÀûȺµºµÄÒ»¼ÒʳƷ £¬ÒûÁϺÍÑ̲ÝÅú·¢Ã³Ò×¹«Ë¾

AIRSAT

Î÷°àÑÀÒ»¼Ò»¥ÁªÍø¹©Ó¦ÉÌ

Al Serh Al Kabeer

λÓÚ°¢ÁªÇõµÄÒ»¼Ò½¨Öþ¹«Ë¾

AFS Logistics  International Pvt.Ltd

λÓÚÓ¡¶ÈµÄÒ»¼Ò¹ú¼ÊÎïÁ÷»õÔËÊðÀí¹«Ë¾

Vanity Case

λÓÚÓ¡¶ÈµÄÒ»¼ÒÌìÈ»»¤·ô²úÎï·ÖÏúÉÌ

sanbe-farma

Ó¡¶ÈÄáÎ÷Ñǵ±µØÁìÏȵÄÖÆÒ©¹«Ë¾

±í2 ±»¹¥»÷µÄ²¿ÃŹ«Ë¾ÐÅÏ¢


3.5.4 ºÚ¿ÍµÄ¹éÊôλÖÃ


´ËÍâ £¬ÎÒÃÇ»¹×¢Ò⵽һЩHawkEye KeyloggerÈÕÖ¾ËƺõÊǴӺڿ͵ĵçÄÔÖÐÉÏ´«µÄ £¬ÎļþÃûÖеÄHawkEye KeyloggerºÍ±àºÅRebornv9£¨¸ÃľÂíµÄ×îа汾ºÅ£© £¬ÒÔ¼°Òªº¦×Ö¡°PasswordsLogs¡±ºÍ¡°TestLogs¡±µÈ £¬ÒÉËÆÊǺڿ͵IJâÊÔÈÕÖ¾¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ37 ²âÊÔÈÕÖ¾½Øͼ


ÈÕÖ¾Îı¾ÀïÏêϸÁгöÁ˺ڿÍ×éÖ¯¼¸¸öÓÃÓÚ²âÊÔµÄÓÊÏäµÇ¼ƾ֤ £¬²¿ÃÅÐÅÏ¢ÈçÏ¡£

ʾÀý1£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ38 ÈÕÖ¾ÐÅÏ¢½Øͼ1


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ39 MovistarÓÊÏäµÇ¼½çÃæ


ʾÀý2£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ 40 ÈÕÖ¾ÐÅÏ¢½Øͼ2


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ41 Suite Correo Profesional ÓÊÏäµÇ¼½çÃæ


ÎÒÃÇÌáÈ¡³öÁ˸ÃÈÕÖ¾µÄIPµØÖ·¡°197.210.226.51¡±¡£²éѯºóµÃ³ö¸ÃµØַλÓÚÄáÈÕÀûÑǵØÓò£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ42 IPµØÖ·²éѯºóµÄÏà¹ØÐÅÏ¢


´ËÍâ £¬ÔÚÁíÍâµÄKeystrokesÈÕÖ¾ÖÐÔٴη¢ÏÖµÄIPµØÖ·¡°41.203.73.185¡±ÓëÇ°ÎÄÖÐÎÒÃǼǼµÄIPµØÖ·Ïàͬ £¬ÆäÒ²ÊÇÖ¸ÏòÄáÈÕÀûÑǵØÓò¡£¾ßÌåÐÅÏ¢ÈçÏÂͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ43 KeystrokesÈÕÖ¾ÖеÄÐÅÏ¢


È»ºó £¬ÎÒÃÇ´ÓͬԴµÄRecoveryÈÕÖ¾ÖÐÕÒµ½Á˺ڿͲ»Ð¡ÐÄй¶µÄ¹úÍâANY.RUN£¨ÔÚÏ߶ñÒâÈí¼þɳÏ䣩ƽ̨µÄÕ˺źÍÃÜÂë¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ44 RecoveryÈÕÖ¾ÖеÄÐÅÏ¢


ÀֳɵǼºó¼ì²ìɨÃèÀúÊ· £¬ÎÒÃÇ¿ÉÒÔ¿´µ½ºÚ¿Í×éÖ¯ÔÚ7Ô·ݵÄʱºò±ã¿ªÊ¼½«Ä¾ÂíÉÏ´«½øÐвéɱ¼ì²â¡£Í¬Ê±Æ¾¾ÝɳÏäɨÃè½á¹ûÏÔʾ £¬ÔÙ´ÎÈ·ÈϸÃÅúľÂíÊôÓÚAgent TeslaºÍHawkEye Keylogger¼Ò×å¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ45 ANY.RUNÉÏ´«ÀúÊ·¼Ç¼



4¡¢×Ü ½á


ºã¾ÃÒÔÀ´ £¬ ÓÃÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢µÄ¼äµýľÂíÒ»Ö±ÔÚ²»Í£µÄ¸üл»´ú¡£Ëæ×Å»ÒÉ«Êг¡µÄÐËÆ𠣬¼üÅ̼Ǽ·¨Ê½¡¢ÇÔÃÜ·¨Ê½ºÍÔ¶¿Ø·¨Ê½ÕýÔÚÖð½¥µØÇ÷ÏòÓÚÉÌÒµ»¯ £¬ÒÔÖÁÓÚ¹¥»÷ÕßÔÚ´Ë·½ÃæÎÞÐëͶÈëÌ«¶àµÄʱ¼äºÍ¾«Á¦ £¬¶ø½«¹Ø×¢µã·ÅÔÚÆä¹¥»÷ÊֶκÍÉç»á¹¤³ÌѧµÄÄÜÁ¦ÉÏ¡£


ͨ¹ý¶Ô·þÎñÆ÷ÉÏÁ¬Ðø¸üеĻش«Îļþ¼à²â £¬ÎÒÃÇ¿ÉÒÔ¿´³ö¸ÃºÚ¿Í×éÖ¯µÄ¹¥»÷»î¶¯ÕýÔÚÁ¬Ðø½øÐÐ £¬Êܺ¦ÕßµÄÈËÊýÈÔÈ»³ÊÉÏÉýÇ÷ÊÆ¡£´ËÍâ £¬Í¨¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´ºÍºǫ́Êý¾Ýͳ¼Æ £¬ÎÒÃÇÍƲâºóÐøµÄ¹¥»÷Ä¿±êÖصãÆ«ÏòÓÚÎ÷°àÑÀºÍÓ¡¶ÈµÈµØÓò¡£


Ôڴ˶«É­Æ½Ì¨ADLabÌáÐѸ÷ÆóÒµµ¥Ôª¼°¸öÈËÓû§Ìá¸ß¾¯Ìè £¬²»´ÓÀ´Àú²»Ã÷µÄÍøÕ¾ÏÂÔØÈí¼þ £¬²»ÒªÇáÒ×µã»÷À´Ô´²»Ã÷µÄÓʼþ¸½¼þ £¬²»ÒªËæÒâÆôÓúê £¬¼°Ê±ÏÂÔز¹¶¡ÐÞ¸´¡£



IOC£º


SHA-256

DE01B6A27D4EBA814FE3CE5084CFC23FDEEB47D50F8BEC5A973578E66B768A48

D5F2418628B818FCFFDD7F3A31F9A137761FA307D1C05C9B783E9040E008DE90

CA56DAD3CABD5AD85411B88C5E094055BEAA96DF6F9B37B9E9FD03AFF823CBAF

4DE32AD800A7847510925D34142B16AE6D7C3C0E44E33EC54466F527FCC93F41

F183992B4BC36F3B33F967EAB83B53A2448260ADA4A92A4B86F32284285EEFED

D6F5AAD82A21C384171BC8FE1BFBC47867151CCE9E8FA54FA21903191A63FD9E

BB3A12EDEFB5A96D6BDBFDC86ED125757ABC3C479EDAF485444A05F4A1D9F9B6

0514990857770F5AF20C96B97D7B63DC8248593D223A672D60C5C6479910C84B

1DD9B3CBB1AAC20E3A3954A1CFBE1BC8CB746C1BF446512A0AB6795546A9774F

C2ÓòÃû

smtp[.]diagnosticsystem[.]in

kartelicemoneyy[.]duckdns[.]org

virtualhost19791[.]duckdns[.]org


²Î¿¼Á´½Ó£º


https://www.fortinet.com/blog/threat-research/in-depth-analysis-of-net-malware-javaupdtr.html