¶«É­Æ½Ì¨ADLab | SWEEDºÚ¿Í×éÖ¯¹¥»÷»î¶¯·ÖÎö³ÂËß

Ðû²¼Ê±¼ä 2020-07-03

Ò»¡¢¸ÅÊö


½üÆÚ£¬¶«É­Æ½Ì¨ADLab½ÓÁ¬²¶×½µ½´óÁ¿Õë¶ÔÈ«ÇòÖÆÔì¡¢ÔËÊä¡¢ÄÜÔ´µÈÐÐÒµ¼°²¿ÃÅÒ½ÁÆ»ú¹¹ÌᳫµÄÓã²æʽµöÓãÓʼþ¶¨Ïò¹¥»÷¡£´ÓÓʼþµÄ·ÖÎö½á¹ûÀ´¿´£¬Êܺ¦Õß´ó¶à±é²¼ÓÚÃÀ¹ú¡¢¼ÓÄô󡢵¹ú¡¢Öйú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Î÷°àÑÀµÈ¹ú¼ÒºÍµØÓò¡£¹¥»÷ÕßÒÔ¡°×°´¬Í¨Öªµ¥¡±¡¢¡°×°Ïä½»»õ¼Ûµ¥¡±¡¢¡°½ô¼±ÔËÊäÎļþ¡±µÈÖ÷ÌâÓʼþ×÷ΪÓÕ¶üÏò¹¥»÷Ä¿±êÖ²ÈëÐÅÏ¢ÇÔÃÜľÂí£¨Agent Tesla¡¢Formbook¡¢Lokibot£©ºÍÔ¶³Ì¿ØÖÆ·¨Ê½£¨NanoCore¡¢Remcos£©¡£ÎÒÃÇͨ¹ý¶ÔÊÕ¼¯µ½µÄ¹¥»÷¹¤¾ß½øÐÐÈ¥Öز¢×ö·ÖÎö£¬×îÖÕ·¢Ïִ˴ι¥»÷»î¶¯¹ØÁª×Å1362¸ö¹¥»÷Ñù±¾¡£Í¨¹ýͬԴ·ÖÎö£¬ÎÒÃÇ·¢ÏÖÕâÅúÑù±¾ÖÐÓнü80%ÊÇͬһ¿î¶ñÒâÈí¼þ£¬¶ÔÆä·ÖÎöÅж¨ºóÈ·¶¨ÕâÕýÊǽüÆÚ±»´ó·¶Î§Á÷´«ÇÒ¼«Îª»îÔ¾µÄÐÂÐÍÏÂÔØÕß²¡¶¾Guloader¡£GuloaderÊÇÒ»¿îÃâɱÄÜÁ¦ºÜÇ¿µÄ²¡¶¾£¬½üÆÚÈ«Çò¸÷´ó³§É̾ù¶ÔÆä½øÐÐÁËÔ¤¾¯£¬Æä¾ß±¸É³ºÐÌÓÒÝ¡¢´úÂë»ìÏý¡¢·´µ÷ÊÔ¡¢C&C/URL¼ÓÃܺÍÓÐЧÔغɼÓÃܵȶàÖÖÄÜÁ¦¡£ÓÉÓÚGuloader¾ßÓнÏÇ¿µÄÃâɱÄÜÁ¦ºÍ·´¿¹»úÖÆ£¬Òò¶øÊܵ½´óÁ¿ºÚ¿ÍµÄÇàíù¡£±¾Åú¹¥»÷ÖУ¬¹¥»÷Õ߾͹㷺µØÀûÓÃGuloaderÏÂÔØÕß²¡¶¾½áºÏÔÆ·þÎñÀ´·Ö·¢ÇÔÃܹ¤¾ß»òÔ¶³Ì¿ØÖÆ·¨Ê½£¨RAT£©¡£


ÎÒÃÇͨ¹ýËÝÔ´·ÖÎöÈ·¶¨´Ë´Î¹¥»÷»î¶¯À´×ÔÄáÈÕÀûÑÇ£¬¶øÇÒ¹ØÁª³öÁË´óÅúÁ¿µÄºÚ¶ñÒâÓòÃû£¨¹¥»÷ÕßʹÓþ³ÍâµÄDuck DNS×¢²á¶¯Ì¬ÓòÃû£©ºÍIPµØÖ·¡£Í¨¹ý¶Ô¹¥»÷ÕßʹÓõÄÍøÂç»ù´¡ÉèÊ©£¬×·×Ù·ÖÎö·¢Ïִ˴ι¥»÷»î¶¯×îÔç¿É×·Ëݵ½2020Äê1Ô¡£½øÒ»²½·ÖÎöÎÒÃÇ·¢ÏÖ£¬ÕâÅú¹¥»÷ÕߵĹ¥»÷¶¯»ú¡¢¹¥»÷Ä¿±ê¡¢×÷Òµ·ç¸ñÓëSWEEDºÚ¿Í×éÖ¯¼«ÎªÏàËÆ£¬ËûÃÇ»¹ÓÐ×ÅÏàËƵĹ¥»÷Ï°¹ß£¬²¢Ê¹ÓÃÏàͬÇÔÃÜľÂí·¨Ê½£¬ÒÔ¼°Í¬Ñù·ç¸ñµÄC&CµØÖ·¡£Òò´Ë£¬ÎÒÃÇÍƶÏÕâÅú¹¥»÷±³ºóÓ¦¸Ã¾ÍÊÇSWEEDºÚ¿Í×éÖ¯¡£SWEEDÊÇÒ»¸öÀ´×ÔÄáÈÕÀûÑǵÄÒÔ»ñÈ¡¾­¼ÃÀûÒæΪÖ÷ҪĿµÄµÄºÚ¿Í×éÖ¯£¬Æä×îÔç·ºÆðÓÚ2017Ä꣬³£ÀûÓùûÈ»Åû¶µÄ©¶´£¬½èÖúÓã²æʽµöÓãÓʼþÀ´Á÷´«Ä¾Âí·¨Ê½£¬ÈçAgent Tesla¡¢FormbookºÍLokibotµÈ¡£¸Ã×éÖ¯ÔøÔÚÔçÆÚ±»Åû¶µÄ¹¥»÷»î¶¯ÖУ¬Í¨¹ýÇÔÈ¡±»¹¥»÷Ä¿±êÓû§ºÍÆóÒµÃô¸ÐÐÅϢʵʩÖмäÈ˹¥»÷£¬ÓÕʹ²ÆÕþÈËÔ±½«¿îÏîתÖÁÖ¸¶¨ÕË»§£¬ÊÇÒ»¸öµäÐ͵ÄÍøÂçÕ©Æ­ÍŻ


¶«É­Æ½Ì¨ADLab¶Ô±¾´Î¹¥»÷»î¶¯µÄ¹¥»÷¹ý³ÌºÍ¹¥»÷ÊÖ·¨½øÐÐÁËÏêϸµØ·ÖÎöºÍËÝÔ´£¬²¢¶ÔÆäËùʹÓõÄÐÂÐͶñÒâÈí¼þºÍC&C»ù´¡ÉèÊ©½øÐÐÁËÉîÈëÑо¿¡£ÌáÐѸ÷´óÆóÒµµ¥Ôª×öºÃÄþ¾²·À·¶ÊÂÇ飬½÷·ÀºóÐø¿ÉÄÜ·ºÆðµÄ¹¥»÷¡£



¶þ¡¢¹¥»÷Ä¿±êºÍÊܺ¦ÕßÂþÑÜ


½ØÖ¹µ½2020Äê6Ô£¬ÎÒÃÇ·¢ÏÖ¹¥»÷ÕßµÄÖصãÄ¿±êΪ´ÓʶÔÍâóÒ×µÄÖÐСÐÍÆóÒµ£¬ÆäÄ¿µÄÊÇͨ¹ýÖ²ÈëÌض¨µÄºóÃÅÒÔʵÏÖ¶ÔÄ¿±ê¼ÆËã»ú½øÐÐÐÅÏ¢ÊÕ¼¯ºÍºã¾Ã¼à¿Ø£¬²¢Îª½ÓÏÂÀ´µÄºáÏòÒƶ¯¹¥»÷Ìṩ»ù´¡¡£


2.1 µØÓòÂþÑÜ


ͨ¹ý¶ÔÒÑÖªµÄSWEED×éÖ¯¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĹú¼ÒºÍµØÓòÂþÑÜÇé¿ö½øÐÐͳ¼Æ£¨Èçͼ2-1£©£¬ÎÒÃÇ¿ÉÒÔ¿´µ½¸Ã×éÖ¯ÌᳫµÄ¹¥»÷»î¶¯ÁýÕÖÁ˺ܶà¹ú¼ÒºÍµØÓò£¬ÓÉ´ËÍƲ⣬¹¥»÷ÕßÔÚ¹¥»÷Ä¿±êµØÀíλÖõÄÑ¡ÔñÉϲ¢Ã»ÓÐÌض¨µÄÖ¸ÏòÐÔ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ2-1 Êܺ¦Õß¹ú¼ÒµØÓòÂþÑÜͼ


2.2 ÐÐÒµÂþÑÜ


ͳ¼Æ½á¹ûÏÔʾ£¨Èçͼ2-2£©£¬´Ë´ÎSWEED×éÖ¯ÔÚÃæÏòÈ«ÇòµÄ¹¥»÷ÖУ¬ÔËÊä¡¢ÖÆÔìÒµºÍÄÜÔ´ÐÐÒµÒÀÈ»ÊÇÆäÖصãÕë¶ÔµÄÄ¿±ê¹¤¾ß¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ2-2 Êܺ¦ÕßÐÐÒµÂþÑÜͼ


Èý¡¢¹¥»÷ʼþ·ÖÎö


±¾Ð¡½Ú×ܽáÁ˸Ã×éÖ¯ÔÚ½üЩÄêµÄ¹¥»÷»î¶¯Ê±¼äµã¡¢´Ë´ÎÐж¯ÖÐʹÓõĹ¥»÷ÊÖ·¨ÒÔ¼°¹¥»÷Á÷³Ì¡£


3.1 ¹¥»÷»î¶¯Ê±¼äÏß


ΪÁ˶ԺڿÍ×éÖ¯Ôڴ˴ι¥»÷»î¶¯Ê¹ÓõļÆıºÍ¼¼Êõ½øÐÐÈ«ÃæµÄÁ˽⣬¶«É­Æ½Ì¨ADLabÑо¿ÈËÔ±½«Ä¿Ç°¹ØÁªµ½µÄ¸Ã×éÖ¯½ü¼¸ÄêµÄÖ÷Òª»î¶¯×öÁËÊáÀíºÍ×ܽᣬ²¢»æÖÆÁË¡°SWEED×éÖ¯¡±»î¶¯Ê±¼äÖᣨÈçͼ3-1£©¡£´Óʱ¼äÖá¿ÉÒÔ¿´³ö£¬¸Ã×éÖ¯µÄ´ó²¿ÃŻ¶¼¾ßÓÐÒ»ÖÂÐÔ¡ª¡ª½èÖú´øÓжñÒ⸽¼þµÄÓã²æʽµöÓãÓʼþ·Ö·¢Ô¶¿ØľÂí·¨Ê½£¨RAT£©£¬¶øÇÒÐж¯ÖÐʹÓõÄľÂí·¨Ê½Ö÷ÒªÊÇÒÔAgent TeslaΪÖ÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ3-1 SWEED×éÖ¯Ïà¹Ø»î¶¯Ê±¼äÖá


3.2 ¹¥»÷ÊÖ·¨ºÍÌصã


SWEED×éÖ¯ÔÚ³õʼ»·½ÚÖ÷ÒªÒÔͶµÝµöÓãÓʼþ¿ªÊ¼Õ¹¿ª¹¥»÷£¬¹¥»÷ÕßÔÚÇ°ÆÚ¶ÔÄ¿±êÓû§½øÐÐÉîÈëµ÷ÑУ¬Ñ¡È¡ÓëÄ¿±êÓû§ËùÊôÐÐÒµ»òÁìÓòÏà¹ØµÄÄÚÈÝÀ´½á¹¹ÓʼþºÍ¶ñÒâÎĵµ¡£Ëæºó½«¾«ÐÄÖÆ×÷µÄÖ÷ÌâÈ硱²É¹º¶©µ¥¡±¡¢¡°½ô¼±ÔËÊäÎļþ¡±¡¢¡±×°´¬Í¨Öªµ¥¡°µÈÎĵµÌí¼ÓÔÚÓʼþ¸½¼þÖз¢Ë͸øÄ¿±êÓû§£¬ÓÕʹÆäÏÂÔظ½¼þ£¬Ä¿±êÓû§Ò»µ©´ò¿ª´øÓЩ¶´µÄ¶ñÒâÎĵµ£¬´¥·¢Â©¶´µÄ¶ñÒâ´úÂë¾Í½«»áÔÚºǫ́¾²Ä¬ÏÂÔغÍÖ´ÐжñÒâÈí¼þ£¬´Ó¶øÇÔÈ¡Ä¿±êÓû§µÄÃô¸ÐÐÅÏ¢²¢¶ÔÆäÖ÷»ú½øÐпØÖÆ¡£


3.2.1 Óã²æÓʼþ


¶«É­Æ½Ì¨ADLabͨ¹ý¶ÔSWEED×éÖ¯Äê³õÖÁ½ñµÄ¹¥»÷Ðж¯½øÐмà²âºÍ¹ØÁª·ÖÎöºó£¬ÊáÀí³ö¼¸Ê®Æð¶¨ÏòÄ¿±êµÄ¹¥»÷µöÓãÓʼþ¡£²¿ÃÅÏà¹ØÓʼþÐÅÏ¢¼û±í3-1¡£


±í3-1 ²¿ÃŵöÓãÓʼþ°¸ÀýÐÅÏ¢


ʱ¼ä

ÓʼþÖ÷Ìâ

·¢¼þÈË

ÊÕ¼þÈË

2020Äê6ÔÂ10ÈÕ

RE : URGENT!!! 2 x 20ft - SHIPPING DOC BL,SI,INV#462345 //\r\n MAERSK KLEVEN V.949E // CLGQOE191781 //

"A.P. Moller ¨C Maersk"

nooreply@maersk.com

undisclosed-recipients

2020Äê6ÔÂ9ÈÕ

M/V BCC - Port Agency Appointment

InterTrans OPS¡± operation@inter-trans.co

jameshall@compasspub.com

2020Äê6ÔÂ8ÈÕ

AGENCY APPOINTMENT/ MV SHOTAN /DISCHARGING/PDA

df15ae634578@6b74fbd36.cn

9ed08@dcc762b7ba3.uk

2020Äê5ÔÂ17ÈÕ

PAYMENT ADVICE-TELEGRAPHIC

TRANSFER NO. M88SI1808BU00250

11@c7c7bacd336b.com

undisclosed-recipients

2020Äê4ÔÂ29ÈÕ

Purchase Order /APO-074787648

jane.hsieh@sealking.com.tw

gjchristopher@safeguard-technology.com

2020Äê4ÔÂ24ÈÕ

[ D.H.L ] Document Arrival  Notice

royalcrown_travel@hotmail.com

Anna.Chitan@linde.com

2020Äê4ÔÂ23ÈÕ

Shipment Arrival Notice

noreply@dhl.com

andrea.schilling@silloptics.de

2020Äê4ÔÂ21ÈÕ

SF Express£ºÄúµÄ°ü¹ü¸üÐÂ

no-reply@sendover.net

info@kraeber.de

2020Äê4ÔÂ7ÈÕ

Returned Payment MT103 Swift

shipping@angloeastern.com

undisclosed-recipients

2020Äê3ÔÂ24ÈÕ

RE: New Order (PO Ref: 01002020)

account@dongbuhitek.co.kr

undisclosed-recipients

2020Äê3ÔÂ23ÈÕ

RE: M/V BLUE LOTUS/NOON RPT

/VOY BL 03.20/ DD 24th

March 2020- APPOINTMENT REQUEST

shahid@erawanaircargo.com

undisclosed-recipients

2020Äê3ÔÂ17ÈÕ

RE : RE : URGENT SHIPPING DOC BL,SI,INV

462345//MAERSK KLEVEN

V.949E//CLGQOE191781//

nooreply@maersk.com

unrecognized@sys.redcondor.com

2020Äê3ÔÂ17ÈÕ

VSL: MV FORTUNE TRADER

Oriental Logistics Group Limited cindy@persadanusantara.co.id

undisclosed-recipients

2020Äê3ÔÂ16ÈÕ

New order by sea FO1909009

acct@gandptech.com

undisclosed-recipients

2020Äê3ÔÂ16ÈÕ

P.I, P.O/MT SR YUJIN (SYNTEK)

bright@kj-global.co.kr

undisclosed-recipients

2020Äê3ÔÂ9ÈÕ

RE: Refund of deposit

pffb@comsats.net.pk

undisclosed-recipients

2020Äê2ÔÂ21ÈÕ

WG: New Order

Anja.Sieveritz@hsm.eu

holthausen@einstein.br

2020Äê2ÔÂ19ÈÕ

RE 2 second lot FCL shipment #48897 Ex works price

Zhejiang Meto Electrical Co.

operations@labcosulich.com

2020Äê2ÔÂ19ÈÕ

Request For Quotation (RFQ-008342)

purchase@auronapharma.com

kbrooks@alpinecom.net

2020Äê2ÔÂ19ÈÕ

?? ?? (?? ??) ???? ??

usef3@hotmail.com

monstar1234@knps.or.kr

2020Äê2ÔÂ18ÈÕ

RE: Revised Cargo Receipts/Documents.

ojs@ojshipping.co.kr

undisclosed-recipients




ͨ¹ý·ÖÎöÕâЩÓÊÏä·¢¼þÈËËùÊô¹«Ë¾µÄ×¢²áÐÅÏ¢ÒÔ¼°Æä¹ÙÍøÐÅÏ¢£¬ÎÒÃÇ·¢ÏÖ¶àÊý¹«Ë¾ÍøÕ¾¾ùΪºÏ·¨ÍøÕ¾£¬ÓÉ´ËÍƲ⹥»÷ÕßʹÓõÄÕâЩÓÊÏ䣬ÓпÉÄÜÀ´×Ô±»ÈëÇֺ͵ÁÓõĺϷ¨ÊµÌå»ò¸öÈË¡£ËäÈ»ÊÕ¼þÈ˵ÄÐÅÏ¢ºÜ¶àÎÞ·¨¿´µ½£¬µ«ÊÇ´ÓÓʼþµÄÖ÷ÌâÒÔ¼°ÕýÎÄÄÚÈݲ»ÄÑ¿´³ö£¬¹¥»÷ÕßÆóͼÀûÓÃÔËÊä»õÎïÇåµ¥¡¢×°Ïä½»»õ¼Ûµ¥¡¢ÎïÆ·µ½»õ֪ͨµ¥¡¢º£ÉÏж©µ¥µÈÓʼþÏòÔËÊäÉÌ¡¢ÖÆÔìÉ̼°ÆäºÏ×÷É̽øÐÐÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯¡£ÏÂÃæÎÒÃÇ´ÓÒÔÉÏÓʼþÖÐÁоÙÒ»¸ö×ö¼òµ¥·ÖÎö¡£


ÔÚ´Ë°¸ÀýÖУ¬¹¥»÷ÕßÊÔͼʹÓá°VSL: MV FORTUNE TRADER¡±Ö÷Ìâð³ä¡°MV Fortune Trader¡±¡£´¬²°FORTUNE TRADERÊÇÒ»ËÒ½¨ÓÚ1994ÄêµÄ¼¯×°Ïä´¬£¬¸Ã´¬²°µÄ×¢²á¹ú¼ÒΪº«¹ú¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-2 ´¬²°FORTUNE TRADERÏà¹ØÐÅÏ¢


ÓʼþÕýÎÄÓëÖ÷Ìâ±£³ÖÒ»Ö£¬ÏÔʾ¸ÃÓʼþÊÇÀ´×Ô³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾¡£¸Ã¹«Ë¾×ܲ¿Î»ÓŲ́Íą̊±±£¬Ö÷ÒªÌṩº£ÔË¡¢¿ÕÔ˺ÍÖиÛÔËÊäµÈÒµÎñ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-3 ³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾Ö÷Ò³


ÓʼþÕýÎÄÈçͼ3-4£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-4 ÓʼþÕýÎÄÐÅÏ¢


¶ÔÓʼþÐÅÏ¢½øÐнâÎöºóÈçͼ 3-5Ëùʾ£¬·¢¼þÈ˵ÄÓʼþµØÖ·ÊÇÓ¡¶ÈÄáÎ÷ÑÇÒ»¼ÒÃûΪ¡°PT.INTI PERSADA NUSANTARA¡±µç»úÉ豸¹«Ë¾µÄºÏ·¨Óò£¬¶ø¸ÃÓʼþʵ¼ÊÉÏÊÇÓÉÍйÜÔÚus10.rumahweb.comÉϵÄRoundcube WebÓʼþ·þÎñÆ÷·¢ËÍ¡£ÕâÀïÊÕ¼þÈ˵ØÖ·Ö®ËùÒÔÏÔʾΪ¡°Undisclosed-Recipient¡±£¨µ¼ÖÂÎÞ·¨¿´µ½ÊÕ¼þÈËÐÅÏ¢£©£¬ÍƲ⹥»÷ÕßÊÇÔÚʹÓÃRoundcube Webmail/1.3.8Èí¼þȺ·¢Óʼþʱ£¬ÎªÁ˲»ÈÃÊÕ¼þÈË¿´µ½ÆäËû½ÓÊÕÓʼþÈ˵ĵØÖ·£¬¹Ê½«´Ë´¦ÉèÖÃΪUndisclosed-Recipient¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-5 ²¿ÃÅÓʼþÍ·²¿ÐÅÏ¢


3.2.2 ÓÕ¶üÎļþ


ͨ¹ý¶Ô¸ÃÅú½Ø»ñµÄÓʼþ½øÐзÖÎöËùµÃ£¬¹¥»÷ÕßʹÓõĹ¥»÷ÔغÉÀàÐÍ×ܹ²ÓÐËÄÖÖ¡£ÏÂÃ潫ÁоٵäÐ͵Ĺ¥»÷Ôغɼ°ÆäËù¶ÔÓ¦µÄµöÓãÓʼþ¡£


(1) Я´ø©¶´Îĵµ


ͼ3-6ÊÇÒ»·â¹¥»÷ÕßðÃûº½¿Õ»õÔ˹«Ë¾·¢Ë͸ø¿Í»§µÄÔ¤Ô¼ÇëÇó»Ø¸´Óʼþ£¬¸½¼þαװ³É´¬²°ÏêϸÐÅÏ¢±íµ¥¡£¸ÃÎĵµÊ¹ÓÃ΢ÈíOffice¾­µä©¶´CVE-2017-11882£¬µ±Óû§´ò¿ª¶ñÒâÎĵµÊ±£¬Ç¶Èëµ½ÎĵµÖеĶñÒⷨʽÔò»á×Ô¶¯¼ÓÔØ¡£¸Ã©¶´µÄÌصãÊÇÔÚÕû¸ö¹ý³ÌÖÐÓû§ÍêÈ«ÎÞ¸ÐÖª£¬ÇÒÔÚ¶ÏÍøµÄÇé¿öÏÂÈÔÈ»¿Éµ½´ïÓÐЧ¹¥»÷£¬ËùÒÔ³ÉΪ¸÷´óAPT×éÖ¯±ØÓ鶴ÀûÓÿâÖ®Ò»¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-6 Я´ø©¶´Îĵµ°¸Àý1¡ªÓʼþ½Øͼ


£¨2£©Ð¯´øGZ¸ñʽµÄѹËõÎĵµ


ͼ3-7Êǹ¥»÷Õß·¢Ë͸ø×ܲ¿Î»ÓÚ±ÈÀûʱµÄÒ»¼Ò¶àÔª»¯µÄ¹¤ÒµÖÆÔìÉ̵ÄÓʼþ£¬¸ÃÓʼþʹÓÃÈÈÃŵÄCOVID-19ΪÖ÷Ì⣬²¢Í¨¹ýÕýÎÄÃèÊö»Ñ³Æ¶ñÒ⸽¼þGZѹËõÎĵµÖаüÂ޲ɹºµ¥£¬ÓÕʹÊܺ¦ÕßÏÂÔØ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-7 Я´øGZÎĵµ°¸Àý2¡ªÓʼþ½Øͼ


¸½¼þÀïÃæÊÇαװ³ÉbatÎļþµÄGuloaderÏÂÔØÆ÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-8 GZѹËõ°üÀïµÄÎļþ


£¨3£©Ð¯´øISO¸ñʽµÄÎĵµ


ÓÉͼ 3-9¿É¼û£¬¹¥»÷Õß½«Óʼþ¸½¼þαװ³Éϵͳ¾µÏñISOÎļþ£¨Ê¹ÓÃISOÎļþ¿ÉÓÃÓÚÈƹýÀ¬»øÓʼþ¹ýÂËÆ÷£©£¬½«ÆäÃüÃûΪ¡°COVID-19½â¾ö·½°¸Ðû²¼¡±ÓÕÆ­Óû§µã»÷¡£Ç¶ÈëÔÚISO¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþΪGuloaderÏÂÔØÆ÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-9 ISOѹËõ°üÀïµÄÎļþ


£¨4£©Ð¯´øhtml¸ñʽµÄÎļþ


ͼ3-10Êǹ¥»÷Õßð³äDHL Express¹ú¼Ê¿ìµÝ¹«Ë¾·¢Ë͸øµÂ¹úÒ»¼Ò¹âѧ×é¼þÖÆÔìÉ̵ĵöÓãÓʼþ£¬Óʼþ¸½¼þ±»ÃüÃûΪװ´¬Í¨Öªµ¥²¢ÒÔhtmlÐÎʽÓÕÆ­Êܺ¦Õßµã»÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-10 Я´øhtmlÎļþ°¸Àý3¡ªÓʼþ½Øͼ



3.2.3 ¶ñÒâÈí¼þÍйÜλÖÃ


ÔÚ¹¥»÷»î¶¯ÖУ¬¹¥»÷Õß¾­³£ÀûÓÃÔ¶³ÌÅäÖÃÀ´¿ØÖƶñÒâÈí¼þ£¬¶øÄþ¾²ÈËԱͨ¹ýÑо¿·ÖÎö²îÒìµÄ¶ñÒâÈí¼þÅäÖã¨ÀýÈçÖ÷»úµØÀíλÖúÍDNSÐÅÏ¢£©£¬¿ÉÒÔÉîÈëµÄÁ˽âºÍ×·×Ù¹¥»÷ÕßʹÓõĻù´¡ÉèÊ©¡£ÎÒÃÇÔÚÑо¿¹ý³ÌÖн«ÊÕ¼¯µ½µÄ´óÁ¿Ñù±¾Êý¾Ý½øÐÐÌáÈ¡ºÍÕûºÏ£¬·¢ÏÖSWEED×éÖ¯´Ë´Îʵʩ¹¥»÷Ðж¯ËùʹÓõĶñÒâÈí¼þÅäÖã¬Ö÷ÒªÓ¦ÓÃÁËGuloaderÏÂÔØÆ÷ÅäÖÃÑ¡ÏîÖеÄÀûÓÃÔÆ·þÎñ·Ö·¢¶ñÒâÈí¼þµÄ¹¦Ð§¡£¹¥»÷ÕßÖ®ËùÒÔʹÓÃÕý¹æµÄÔƴ洢ƽ̨À´ÍйܶñÒâÈí¼þ£¬ÊÇÒòΪÕâЩÔÆƽ̨¶àÊýÊÇÊÜÐÅÈεÄÇÒÓÐÖúÓÚÈƹýÉÌÒµÍþв¼ì²â²úÎï¡£ËäÈ»Google DriveµÈÔÆƽ̨ͨ³£Ò²»áÖ´ÐзÀ²¡¶¾¼ì²â£¬µ«Èç¹ûÓÐЧÔغÉÊDZ»¼ÓÃܺóÔÙ´æ´¢£¬¾Í¿ÉÒÔ¶ã¹ý´ËÀàÏÞÖÆ£¬²¢ÄÜÓÐЧµÄ×èÖ¹Äþ¾²ÈËÔ±¶ÔºÚ¿Í×éÖ¯µÄ»ù´¡ÉèÊ©½øÐÐ×·×Ù¡£Í¼3-11Ϊ¶ñÒâÔغÉÑù±¾ÍйÜƽ̨µÄʹÓÃÕ¼±ÈÂÊ¡£Æ¾¾ÝͼÖÐÏÔʾµÄÊýÖµ¿ÉµÃ£¬Google DriveΪ¶ñÒâÈí¼þÖ÷ҪʹÓõÄÍйÜƽ̨¡£³ý´ËÖ®Í⣬»¹Óв¿ÃŶñÒâÈí¼þ»áÍйÜÔÚÒѱ»¹¥ÏݵĺϷ¨ÍøÕ¾ÉÏ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-11ÓÐЧÔغÉÍйÜƽ̨µÄʹÓÃÂÊ


³ýÁËGoogle DriveºÍOneDrive£¬ÏÂÃæÎÒÃÇÁоٳö¼¸¸ö¹¥»÷ÕßʹÓõÄÆäËûÔÆÍйÜƽ̨¡£

files.fmÊǹúÍâÒ»¼ÒÌṩÎļþÔƴ洢ƽ̨µÄÐÅÏ¢¼¼Êõ¹«Ë¾¡£Í¼3-12ÊÇÉú´æÔÚ¸Ãƽ̨µÄ¼ÓÃܵĶñÒâÎļþ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-12 ÔÆÍйÜƽ̨Àý1


sendspaceÊÇÒ»¼ÒÃâ·ÑÎļþÍйÜƽ̨¡£Í¼3-13Êǹ¥»÷ÕßÉÏ´«µ½¸Ãƽ̨½øÐÐÍйܵĶñÒâÈí¼þ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ 3-13 ÔÆÍйÜƽ̨Àý2


dmca.gripeÊÇÒ»¸öÃâ·ÑµÄÎļþÍйÜƽ̨£¬ÆäÖ÷Ò³Èçͼ3-14Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3-14 ÔÆÍйÜƽ̨Àý3


3.3 ¹¥»÷Á÷³Ì


ÎÒÃǶÔÕâÅú¹¥»÷»î¶¯½øÐйéÄÉ·ÖÎöºó·¢ÏÖ¾ø´ó²¿ÃŹ¥»÷¾ßÓÐÏàͬµÄ¹¥»÷Á÷³Ì£¬Æä¹¥»÷µÄÁ÷³ÌÈçͼ3-15¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3-15 ¹¥»÷Á÷³Ìͼ


¹¥»÷Õßαװ³ÉÎïÁ÷»ò´¬²°µÈ¹«Ë¾ÈËÔ±£¬ÏòÄ¿±êÆóҵͶµÝЯ´ø¸½¼þµÄµöÓãÓʼþ£¬¸½¼þÀàÐÍ°üÂÞ£º°üÂÞ©¶´µÄ¶ñÒâÎĵµ¡¢GZ¸ñʽµÄѹËõ°ü¡¢ISOÎļþºÍHTMLÎļþ¡£ÔÚ¶àÊýÇé¿öÏ£¬ÕâЩ¸½¼þÆð³õ¶¼ÊаüÂÞ»òÏÂÔØGuloaderÏÂÔØÆ÷£¨ÆäËûÇé¿öÏÂΪԶ¿ØľÂí£©¡£Guloader¿ªÊ¼Ö´ÐÐʱ£¬ÏȶԴ¢´æÔÚ´úÂ벿ÃŵÄshellcode½øÐнâÃÜ£¬ÔÙ½«½âÃܺóµÄshellcode×¢Èëµ½RegAsm.exeϵͳÎļþÖУ»½Ó×ÅRegAsm.exeÖеÄshellcodeÔÙ´ÓÖ¸¶¨µÄÔÆƽ̨µØÖ·ÏÂÔؼÓÃܵÄpayload£¬²¢ÔÚÄÚ´æÖнâÃÜÖ´ÐÐpayload£¨Ô¶¿ØľÂí£©£¬×îºóͨ¹ýC2¶ÔÄ¿±êÖ÷»ú½øÐÐÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì¿ØÖÆ¡£


´Ë´Î¹¥»÷»î¶¯ÖÐʹÓõ½µÄÇÔÃܺÍÔ¶¿ØľÂí°üÂÞ£ºAgent Tesla£¨ÊÇÒ»¿îÖªÃûµÄÉÌÒµÇÔȡľÂí£¬Ö÷ÒªÓÃÓÚä¯ÀÀÆ÷¡¢Óʼþ¿Í»§¶Ë¡¢FTP¹¤¾ß¡¢ÏÂÔØÆ÷µÈÓû§Õ˺ÅÃÜÂëºÍWiFiƾ֤µÄÇÔÈ¡¡££©£»Formbook£¨ÊÇÒ»¿îÐÅÏ¢ÇÔȡľÂí£¬ÆäÖ÷ÒªÒÔÇÔÈ¡Óû§µçÄÔ»úÃÜÐÅϢΪÖ÷£¬°üÂÞ¼üÅ̼Ǽ¡¢¼ôÌù°å¼Ç¼¡¢cookie»á»°Óëµ±µØÃÜÂëµÈµÈ¡££©£»Lokibot£¨Ò»¿îÇÔÃÜľÂí£¬Æäͨ¹ý´Ó¶àÖÖÁ÷ÐеÄÍøÂçä¯ÀÀÆ÷¡¢FTP¡¢µç×ÓÓÊÏä¿Í»§¶Ë¡¢ÒÔ¼°PuTTYµÈIT¹ÜÀí¹¤¾ßÖлñȡƾ֤£¬À´ÇÔÈ¡Óû§µÄÃÜÂëºÍ¼ÓÃÜ»õ±ÒÇ®°ü£©£»NanoCore£¨ÊÇÒ»¿î.net±àдµÄÔ¶¿ØÈí¼þ£¬Æä¾ßÓмüÅ̼à¿Ø¡¢ÊµÊ±ÊÓƵ²Ù×÷¡¢ÓïÒô¡¢ÃüÁîÐпØÖƵÈÍêÈ«¿ØÖÆÔ¶³ÌÖ÷»úµÄ¹¦Ð§¡££©£»Remcos£¨Ò»¿îÔ¶¿ØÈí¼þ£¬°üÂÞÏÂÔز¢Ö´ÐÐÃüÁî¡¢¼üÅ̼Ǽ¡¢ÆÁÄ»¼Ç¼ÒÔ¼°Ê¹ÓÃÉãÏñÍ·ºÍÂó¿Ë·ç½øÐмÒô¼ÏñµÈ¹¦Ð§¡££©¡£


¼øÓÚÎÒÃÇ·ÖÎöµÄÕâЩľÂíÔÚ¹¦Ð§ºÍ¼¼ÊõÉÏÓë¾É°æÀàËÆ£¬²¢Ã»Óз¢ÏÖÌ«¶àµÄ±ä»¯µã£¬ËùÒÔÔÚ´ËÎÒÃǽö¶ÔÆäÖ÷Òª¹¦Ð§×öÁ˼òµ¥µÄÃèÊö£¬±¾ÎĺóÐø±ã²»ÔÙ¹ý¶àµÄÏêϸÃèÊöÆä¾ßÌåµÄ¼¼Êõϸ½Ú£¬ÈçÓÐÐèÒª¸÷È˿ɼì²ìÎÄÄ©µÄ²Î¿¼ÎÄÏס£ÔÚϸöÕ½Ú£¬ÎÒÃÇÖ÷Òª¶ÔSWEED×éÖ¯ÐÂÒýÈëµÄGuloader¶ñÒâ´úÂë½øÐÐÍêÕûÏêϸµØÆÊÎö¡£


ËÄ¡¢¼¼Êõ·ÖÎö


ÕýÈçÇ°ÎÄËùÊö£¬ÎÒÃÇÄ¿Ç°ÊÕ¼¯µ½µÄµç×ÓÓʼþµÄ¸½¼þÖ÷Òª·ÖΪËÄÀà¡£ËäÈ»ÆäÊͷŶñÒâÈí¼þµÄÐÎʽ²îÒ죬µ«ËüÃǵÄÖ÷Òª¹¦Ð§ÐÐΪ¶¼»ù±¾Ò»Ö¡£ÔÚÕâÀÎÒÃÇÑ¡È¡Ò»¸öµäÐÍ°¸Àý½øÐÐÏêϸ·ÖÎö¡£


4.1 µöÓãÓʼþ


ͼ4-1Ϊ¹¥»÷ÕßÕë¶ÔÃÀ¹úÒ»¼Ò·À»¬²úÎïÖÆÔìÉ̽øÐй¥»÷µÄµöÓãÓʼþ£¬´ËÓʼþÓÚÃÀ¹úɽµØʱÇøʱ¼ä2020Äê4ÔÂ29ÈÕ£¨ÖÜÈý£©02:31±»·¢Ë͵½¸Ã¹«Ë¾¡£Óʼþ±êÌâΪ¡°Purchase Order /APO-074787648¡±£¬ÕýÎÄÃèÊöΪ¡°Çë¼ì²ìÇåµ¥ºÍÈ·ÈÏÉÌÆ·¿â´æ¡±£¬²¢¸½ÓÐͬÃû¶ñÒâÎĵµ¡°Purchase Order /APO-074787648¡±¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-1 µöÓãÓʼþÄÚÈÝ


4.2 ¶ñÒâÎĵµ


Ñù±¾¡°Purchase Order /APO-074787648.ppsx¡±ÀûÓÃÁËɳ³æ©¶´CVE-2014-4114µÄ²¹¶¡£¨MS14-060£©Èƹý©¶´CVE-2014-6352¡£É³³æ©¶´ÊÇWindows OLEÈÎÒâ´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´·ºÆðÔÚMicrosoft Windows·þÎñÆ÷ÉϵÄOLE±£Ö¤ÀíÆ÷ÉÏ¡£¹¥»÷Õßͨ¹ýÀûÓø鶴ÔÚOLE´ò°üÎļþ£¨packer.dll£©ÖÐÏÂÔز¢Ö´ÐÐÀàËƵÄINFÎļþ£¬À´µ½´ïÖ´ÐÐÈÎÒâÃüÁîµÄÄ¿µÄ¡£ËäȻ΢ÈíΪɳ³æ©¶´Ðû²¼²¹¶¡£¨MS14-60£©£¬µ«¹¥»÷Õß»¹¿Éͨ¹ý½á¹¹Ìض¨µÄCLSIDºÍOLE VerbÀ´ÈƹýMS14-160²¹¶¡µÄÏÞÖÆ£¨CVE-2014-6352£©¡£ÏÂÃæÎÒÃÇÒÔ±¾´ÎÐж¯ÖÐʹÓõĶñÒâÎĵµÎªÀý£¬¶Ô¸Ã©¶´µÄʵÏÖÔ­Àí×ö¼òµ¥µÄ·ÖÎö¡£


ͼ4-2Ϊ´Ë°¸ÀýÖÐʹÓõÄppsx©¶´¹¥»÷ÎĵµÄÚÈÝ¡£




¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4-2 ppsx©¶´ÎĵµÄÚÈÝ


ÎÒÃǽâѹPPXSÎĵµ¿ÉÒÔ¿´µ½£¬ÔÚ¡°Purchase Order APO-074787648.ppsx\ppt\slides \slides.xml¡±ÖУ¬Ö¸¶¨ÁËǶÈëµÄ¹¤¾ßid=rld3¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-3 ¡°slides.xml¡±ÎļþÄÚÈÝ


ÔÚ¡°Purchase Order APO-074787648\ppt\slides\_rels\slide1.xml.rels¡±ÖÐÖ¸¶¨ÁËrld3¶ÔÓ¦¡°ppt\embeddings\¡±Ä¿Â¼ÏµÄoleObject1.binÎļþ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-4 ¡°slide1.xml.rels¡±ÎļþÄÚÈÝ


¡°Purchase Order APO-074787648.ppsx\ppt\embeddings\¡±Ä¿Â¼Ïµġ°oleObject1.bin¡±ÎļþÄÚǶһ¸öOLE Package¹¤¾ß£¬Ç¶ÈëÎļþΪPE¿ÉÖ´Ðз¨Ê½¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-5 ¡°oleObject1.bin¡±ÎļþÄÚÈÝ


CVE-2014-4114©¶´µÄ³ÉÒòÊÇpackager.dllÖÐCPackage::LoadÒªÁì¼ÓÔضÔÓ¦µÄOLE¸´ºÏÎĵµ¹¤¾ßʱ£¬Õë¶Ô²îÒìÀàÐ͵ĸ´ºÏÎĵµ½øÐвîÒìµÄ´¦ÖÃÁ÷³Ì£¬µ«ÆäÖжÔijЩ¸´ºÏÎĵµÖÐǶÈëµÄ²»ÐÐÐÅÀ´Ô´ÎļþûÓÐ×ö´¦Öá£Óɴ˹¥»÷Õß¿ÉʹÓÃαÔìOLE¸´ºÏÎĵµµÄCLSIDÀ´µ½´ïÖ´ÐÐÌض¨ÎļþµÄÄ¿µÄ¡£Î¢ÈíÔÚMS14-060²¹¶¡ÖУ¬Í¨¹ýÌí¼ÓMarkFileUnsafeº¯Êý¶ÔÎļþ½øÐÐMOTW´¦Ö㬽«ÆäSecurity Zone±ê־Ϊ¡°´ËÎļþÀ´×ÔÆäËû¼ÆËã»ú¡±£¬ÔËÐÐʱ»áµ¯³öÄþ¾²¾¯¸æ´°¿Ú¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4-6 ¡°%TEMP%\NEW ORDER.exe¡±±ê־Ϊ²»ÐÐÐÅÎļþ


µ«¾ÍËãÊܺ¦ÕßÒÑ°²×°MS14-060µÄ²¹¶¡£¬¹¥»÷Õß»¹ÊÇ¿ÉÒÔͨ¹ý½á¹¹Ìض¨µÄCLSIDºÍOLE VerbÀ´¸Ä±äÖ´ÐÐÁ÷³Ì£¬´Ó¶øÈƹý¸Ã²¹¶¡£¨CVE-2014-6352©¶´£©¡£¶ÔÓÚÒ»¸öexeÎļþ£¬¼´Ê¹±»±ê־ΪURLZONE_INTERNET£¬ÓÒ¼üµã»÷ÒÔ¹ÜÀíԱȨÏÞÖ´ÐиÃexeÎļþ£¬Äǵ±·¨Ê½ÔËÐÐʱ±ã²»»áÔÙµ¯³ö¡°Äþ¾²¾¯¸æ¡±£¨Èçͼ4-6£©µÄÌáʾ£¬¶øÊÇÒÔ£¨Èçͼ4-7£©UAC Ìáʾ´°µ¯³ö¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4-7 µ¯³öµÄUACÌáʾ´°


  ÓÉ´Ë¿ÉÖª£¬µ±Êܺ¦Õß´ò¿ª´ËPPSX¶ñÒâÎĵµÊ±£¬×Ô¶¯²¥·Åģʽ±ã»á¿ªÆô£¬Í¬Ê±¡°%TEMP%\NEW ORDER.exe¡±½«±»ÊÍ·ÅÔÚÁÙʱĿ¼ÖС£Èç¹ûÊܺ¦ÕßÑ¡Ôñ¡°ÊÇ¡±£¬¶ñÒâ´úÂ뽫»á±»Ö´ÐС£¶øÈç¹ûÊܺ¦ÕßµÄϵͳ´¦ÓÚUAC¹Ø±Õ״̬»òÔÚ»ñÈ¡Á˹ÜÀíԱȨÏÞµÄÇé¿öÏ£¬¸ÃUACÄþ¾²¾¯¸æ´°¿ÚÔò²»»áµ¯³ö£¬¡°NEW ORDER.exe¡±»á±»¾²Ä¬µØÖ´ÐС£



4.3 GuLoader


ÈçÉÏÎÄËùÊö£¬×îºó±»Ö´Ðеġ°NEW ORDER.exe¡±¿ÉÖ´ÐÐÎļþʵ¼ÊÉϱãÊÇÎÄÕ¿ªÍ·Ìáµ½µÄGuloader¶ñÒâÈí¼þ£¨ÔÚºóÐø¶Ô¡°NEW ORDER.exe¡±µÄÏêϸ·ÖÎöÖУ¬ÎÒÃǾùʹÓá°Guloader¡±À´Ìæ´ú¸ÃÎļþÃû£©¡£GuloaderÊÇÒ»¿îÐÂÐ͵ĶñÒâÈí¼þÏÂÔØÆ÷£¬Æä×Ô¼º¾ßÓÐÅÓ´óµÄÖ´ÐÐÁ÷³Ì£¬Í¨¹ý½ÓÄÉÖÖÖÖ´úÂë»ìÏýºÍËæ»ú»¯¡¢·´É³Ïä¡¢·´µ÷ÊÔºÍÊý¾Ý¼ÓÃܵȻúÖÆÀ´·´¿¹Äþ¾²²úÎïµÄ¼ì²â¡£ÏÂÃæÎÒÃǽ«¶Ô¸ÃGuLoader½øÐÐÉîÈëµÄÍÚ¾ò·ÖÎö¡£


4.3.1 Ö´ÐÐÁ÷³Ì


Èçͼ4-8Ëùʾ£¬ GuLoaderÊ×ÏȽ«´¢´æÔÚ´úÂ벿ÃŵļÓÃÜShellcode½âÃܲ¢Ö´ÐС£Õâ¶ÎShellcodeµÄÖ÷Òª¹¦Ð§Îª£ºÒÔ¹ÒÆð·½Ê½´´½¨Ò»¸öϵͳ×Ó½ø³Ì£¬Ö®ºó½«±¾¶ÎShellcode×ÔÉí×¢Èëµ½×Ó½ø³Ì²¢Ð޸ķ¨Ê½Èë¿ÚµãΪShellcode´¦Ö´ÐС£×îºó´ÓÍйܷþÎñÆ÷ÉÏÏÂÔؼÓÃܵÄBINÎļþ£¬ÀÖ³ÉÏÂÔغó½«Æä½âÃܺÍÔËÐС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-8 GuloaderÖ´ÐÐÁ÷³Ìͼ


4.3.2 EXE¿ÉÖ´ÐÐÎļþ


£¨1£©´úÂë»ìÏý

Guloader¿ÉÖ´ÐÐÎļþÊÇÓÉVisual Basic 6ÓïÑÔ±àдµÄ¡£Ê¹Óù¤¾ß¼ì²ìºó·¢ÏÖ£¬Æ䲢δʹÓÃÉÌÒµ¿Ç½øÐÐ×ÔÉí±£»¤£¬¶øÊÇʹÓûìÏý¿ÇʵÑé·´¿¹Äþ¾²²úÎïµÄ²éɱ¡£ÓÉÓÚɱÈí¶ÔÉÌÒµ¿Ç±ÈÁ¦Ãô¸Ð£¬¶øÇÒÉÌÒµ¿Ç¼ì²âºÍÍѿǼ¼ÊõÒ²±ÈÁ¦³ÉÊ죬ËùÒÔ»ìÏý¿Ç²»Ê§ÎªÒ»¸ö²»´íµÄÑ¡Ôñ¡£»ìÏý¿ÇÒ»°ã²»´æÔÚͨÓõļì²âÒªÁ죬¶øÇÒ¾²Ì¬ÍÑ¿ÇÏà¶Ô½ÏÄÑ£¬ËùÒÔÆä¶ñÒâÐÐΪ²»Ò×±»·¢ÏÖ£¬´Ó¶ø¿É³¤Ê±¼äµÄ´æ»îÔÚÄ¿±ê»úÆ÷ÉÏ¡£¶ÔÓÚÄæÏò·ÖÎöÈËÔ±À´½²£¬·ÖÎöÕâÖÖ´ø»ìÏý¿ÇµÄÑù±¾ÍùÍù»á»¨·Ñ´óÁ¿µÄ¾«Á¦£¬ÎÞÐεÄÔö¼ÓÁËÈËÁ¦ºÍʱ¼ä³É±¾¡£


ͼ4-9ÊÇÒ»¶Î»ìÏý´úÂëµÄ½ØÈ¡£¬ÕⲿÃÅ´úÂëʹÓÃÁËÊý¾Ý»ìÏýÖеij£Á¿²ð·Ö£¬Ö÷ҪĿµÄÊÇÒþ²ØÕæʵµÄ´úÂëÂß¼­£¬È÷ÖÎöÕßÄÚÐı¼À£¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4-9 ²¿ÃÅ»ìÏý´úÂë


£¨2£©´úÂë½âÃÜ


¶ñÒâÈí¼þÊ×ÏȼÆËã³öÓÃÓÚ½âÃÜshellcodeµÄÃÜÔ¿£¬ÆäֵΪ£º0x24EBE470¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-10 »ñÈ¡ÃÜÔ¿µÄ¶ñÒâ´úÂë


½Ó×Å£¬ÎªshellcodeÉêÇëÄÚ´æ¿Õ¼ä£¬ÔÙʹÓÃÃÜÔ¿½øÐÐXORÔËËã½âÃÜShellcode²¢Ö´ÐС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-11 ½âÃܺÍÖ´ÐÐshellcode


4.3.3 ShellCode


½âÃܺóµÄshellcodeÇ°ÆÚÒ²½ÓÄÉÁË´óÁ¿µÄ·´¿¹ÊֶΣ¬Ê¹ÓÃÖÖÖÖ´úÂë»ìÏý¡¢É³Ïä¼ì²â¡¢·´µ÷ÊԵȼ¼ÊõÊÖ¶ÎÀ´¹æ±ÜÄþ¾²²úÎïµÄÐÐΪ¼à²âºÍ²éɱ¡£½öµ±Í¨¹ýÖÖÖÖ¼ì²éÅжÏÌõ¼þºó£¬¶ñÒâ´úÂë²Å¿ªÊ¼Ö´ÐÐÖ÷¹¦Ð§ÐÐΪ¡£ÏÂÃæÎÒÃǽ«¶Ô¶ñÒâ´úÂë×öÏêϸµÄ·ÖÎö¡£


£¨1£©¼ì²â¹¦Ð§


¡ñ ´úÂë»ìÏý

½«½âÃܺóµÄshellcode´ÓÄÚ´æÖÐdump³öÀ´²¢Ê¹ÓÃIDA·´±àÒ룬¿ÉÒÔ¿´µ½shellcodeÖÐʹÓõĻìÏý¼¼Êõ¡£¶ñÒâ´úÂëÔÚÖ´Ðйý³ÌÖвåÈë»ìÏýº¯Êý£¬¸Ãº¯ÊýµÄ¹ý³Ì±»Ö§½â³É¶à¸öÌøתÁ÷³Ì£¬Ò»Ö±µ½×îºóÔÙ jmpµ½Ô­À´µÄÕý³£´úÂëÖмÌÐøÖ´ÐÐÏÂÃæµÄÁ÷³Ì¡£Í¼4-12ÊÇshellcodeÔÚÈë¿Ú´¦µ÷ÓõĴËÀà»ìÏýº¯ÊýµÄ´úÂëƬ¶Î£¬ºÜÏÔȻͨ¹ý¸ÃÒªÁ죬Äܹ»ÓÐЧµÄÈÅÂÒ·ÖÎöÕ߶ÔÑù±¾½øÐзÖÎö£¬ÑÏÖؽµµÍÁË·ÖÎöЧÂÊ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4-12 »ìÏýºóµÄ´úÂëƬ¶Î


¡ñ ¶¯Ì¬»ñÈ¡APIº¯Êý


½Ó×Å£¬¶ñÒâ´úÂëͨ¹ý·ÃÎÊPEB->LDRÖеÄInMemoryOrderModuleList»ñÈ¡kernel32.dllµÄ»ùÖ·¡£±éÀúÌáÈ¡¸ÃÄ£¿éµ¼³ö±í½á¹¹Öдæ·Åº¯ÊýÃûµÄÊý×飬²¢ÒÀ´Î½«Ãû³Æ×Ö·û´®×÷Ϊ²ÎÊý´«Èëµ½¹þÏ£Ëã·¨º¯ÊýÖÐ×öÔËË㣬ÔÙ½«½á¹ûÓëÓ²±àÂëÊý¾Ý×ö±ÈÁ¦£¬ÒÔ´ËÒªÁìÀ´²éÕÒGetProcAddressº¯Êý¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-13 ²éÕÒGetProcAddressº¯Êý


´Ë´¦Ê¹ÓõÄÊÇdjb2µÄËã·¨£¬ djb2ÊÇÒ»¸ö·¢ÉúËæ»úÂþÑܵĹþÏ£º¯Êý£¬ÓëLCGµÄËã·¨ÏàËÆ¡£ÓÉÓڸú¯Êý½á¹¹¼òµ¥£¬Ê¹ÓÃÒÆλºÍÏà¼ÓµÄ²Ù×÷£¬ËùÒÔ³£±»ÓÃÀ´´¦ÖÃ×Ö·û´®¡£¾ßÌåËã·¨¼ûͼ4-14¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-14 djb2Ëã·¨´úÂë½Øͼ


ÓÉ´ËÎÒÃÇ¿ÉÒÔ¿´µ½£¬¶ñÒâ´úÂëÔÚº¯ÊýµÄ»ñÈ¡·½ÃæÊÇÀûÓÃLoadLibraryºÍGetProcAddressÕâÁ½¸öº¯Êý½øÐж¯Ì¬µÄ»ñÈ¡¡£¾ßÌåÈçͼ4-15Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-15 ¶¯Ì¬»ñÈ¡APIº¯Êý


¡ñ É³Ïä¼ì²â


¶ñÒâ´úÂëö¾Ù´°¿ÚÊýÁ¿£¬Èç¹ûֵСÓÚ12ÔòÍ˳ö½ø³Ì£¬ÒÔ´ËÀ´¼ì²â×ÔÉíÊÇ·ñÔËÐÐÔÚɳÏä»·¾³ÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-16 ɳÏä¼ì²â´úÂë


¡ñ ·´µ÷ÊÔ¼¼Êõ


ÒªÁì1£º

µ÷ÓÃZwProtectVirtualMemoryº¯ÊýÐÞ¸Äntdll.dllµÄ¡°.text¡±½ÚÊôÐÔΪ¿É¶Á¿Éд¿ÉÖ´ÐС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-17 ÐÞ¸Äntdll.dll½ÚÊôÐÔ


¶ñÒâ´úÂëͨ¹ýÐÞ¸ÄDbgBreakPointºÍ DbgUiRemoteBreakinº¯Êý´úÂ룬Èõ÷ÊÔÆ÷ÎÞ·¨¸½¼Óµ÷ÊÔ·¨Ê½£¨Èçͼ4-18ºÍͼ4-19£©¡£¸øcallµ÷ÓúóÃæÖ¸¶¨Ò»¸öδ֪µØÖ·£¬ÒÔ´ËÒý·¢µ÷ÊÔÆ÷Íß½âÍ˳ö¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-18 DbgBreakPointº¯Êý´úÂëÐÞ¸ÄÇ°ºó¶Ô±È


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-19 DbgUiRemoteBreakinº¯Êý´úÂëÐÞ¸ÄÇ°ºó¶Ô±È


ÒªÁì2£º

½«ZwSetInformationThreadº¯ÊýµÄµÚ¶þ¸ö²ÎÊýÉèÖÃΪThreadHideFromDebugger £¨ÖµÎª17£©£¬×÷ÓÃÊÇÔÚµ÷ÊÔ¹¤¾ßÖÐÒþ²ØÏ̡߳£Èç¹û¶ñÒâÈí¼þ´¦ÓÚ±»µ÷ÊÔ״̬£¬ÄÇô¸Ãº¯Êý¾Í»áʹµ±Ç°Ị̈߳¨Ò»°ãÊÇÖ÷Ị̈߳©ÍÑÀëµ÷ÊÔÆ÷£¬Ê¹µ÷ÊÔÆ÷ÎÞ·¨¼ÌÐø½ÓÊÕ¸ÃÏ̵߳ĵ÷ÊÔʼþ¡£Ð§¹û¾ÍÏñÊǵ÷ÊÔÆ÷Íß½âÁËÒ»Ñù¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-20 Òþ²ØÏ̵߳½´ï·´µ÷ÊÔÄ¿µÄ


ÒªÁì3£º

ÔÚʹÓÃZwAllocateVirtualMemoryº¯ÊýÉêÇëÄÚ´æ¿Õ¼äʱ£¬Îª·ÀÖ¹·ÖÎöÈËÔ±ÔÚµ÷ÊÔʱ¶ÔÒªº¦º¯Êý϶ϵ㣬¶ñÒâ´úÂë»áÌáÇ°½«¸Ãº¯ÊýµÄ¹¦Ð§ÊµÏÖ´úÂ븴ÖƵ½±¾½ø³Ì¿ÕÏпռäÖУ¬Ê¹µÃºóÐøÔÚʹÓô˺¯Êýʱֱ½ÓÌøתµ½×ÔÉí´úÂëÖÐÖ´ÐС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-21 ¸´Öƺ¯Êý¹¦Ð§ÊµÏÖ´úÂë


ÒªÁì4£º

ÔÚµ÷Óò¿ÃÅÃô¸ÐAPIº¯Êýʱ£¬»áÏȵ÷ÓÃ×Ô½ç˵µÄ¼ì²éº¯Êý×öÅжÏ£¬ÒÔ¼õÉÙ±»Äþ¾²²úÎï¼ì²âµÄ¼¸ÂÊ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-22 ¼ì²éº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³


¸Ã×Ô½ç˵µÄ¼ì²éº¯ÊýµÄÖ÷Òª¹¦Ð§£º

¢Ù ½«µ÷Óøú¯ÊýÇ°µÄshellcode´úÂ루ÕýÐò£©°´×Ö½ÚÓë0x4×ֽڵķµ»ØµØÖ·×öÒì»òÔËËã ½øÐмÓÃÜ´¦Öã»

¢Ú µ÷ÓÃZwGetContectThreadº¯Êý£¬Í¨¹ý¼ì²é_CONTEX½á¹¹ÖеÄDr¼Ä´æÆ÷À´ÅжÏÊÇ·ñ   ÔÚµ÷ÊÔ»·¾³ÖУ»

¢Û Åжϴ˴ÎÒª¼ì²éµÄÒªº¦APIº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³¡£Èç¹û½á¹ûΪ·ñ£¬Ôòµ÷ÓøÃAPIº¯

Êý£¬·ñÔò·¨Ê½Ö±½ÓÍß½âÍ˳ö£»

¢Ü ͬ¡°ÒªÁì¢Ù¡±¶Ôshellcode´úÂ루µ¹Ðò£©½øÐнâÃܲ¢Ìøתµ½·µ»ØµØÖ·´¦Ö´ÐкóÐøÁ÷³Ì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-23 ×Ô½ç˵¼ì²éº¯Êý´úÂë


£¨2£©¶ñÒâÐÐΪִÐй¦Ð§

Èç¹ûÒÔÉÏһϵÁеÄɳÏäÒÔ¼°·´µ÷ÊÔ¼ì²â¶¼Í¨¹ý£¬¶ñÒâ´úÂëÔò¿ªÊ¼Ö´ÐÐÒÔÏÂÁ÷³Ì£º

¢Ù ¶¯Ì¬»ñȡͼ4-24ÖеÄAPIº¯Êý£¬²¢½«º¯Êýµ÷ÓõØÖ·Éú´æÔÚ¶ÑÕ»ÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-24 ¶¯Ì¬»ñÈ¡µÄAPIº¯ÊýÃû³Æ


¢Ú ƾ¾ÝÖ¸¶¨µØÖ·´¦Éú´æµÄÊý¾ÝÄÚÈÝÌØÕ÷£¨Èç¹û¶ñÒâ´úÂëδִÐйý´´½¨×Ó½ø³ÌÁ÷³Ì£¬ÄÇ Ã´¸ÃµØÖ·´¦Ô­Êý¾ÝΪÎÞЧÄÚÈÝ£»·ñÔò£¬´Ë´¦Éú´æµÄÊǵ±Ç°½ø³ÌµÄȫ·¾¶¡££©À´Åж¨ÊÇ ·ñÐèÒª´´½¨×Ó½ø³Ì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-25 ÅжÏÊÇ·ñÐèÒª´´½¨×Ó½ø³Ì


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-26 ¶ÔÖ¸¶¨µØÖ·´¦Éú´æµÄÊý¾ÝÄÚÈÝ×öÅжÏ


¢Û µ÷ÓÃCreateProcessInternalº¯ÊýÒÔ¹ÒÆðģʽ´´½¨RegAsm.exe½ø³Ì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-27 ´´½¨ÏµÍ³×Ó½ø³Ì


¢Ü µ÷ÓÃZwOpenFileº¯Êý£¬»ñµÃÓ³ÉäÎļþmstsc.exeµÄ¾ä±ú¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-28 »ñÈ¡mstsc.exeµÄ¾ä±ú


¢Ý ʹÓÃZwCreateSectionºÍNtMapViewOfSectionº¯Êý½«¡°mstsc.exe¡±ÎļþÓ³Éäµ½

RegAsm.exeÄÚ´æÖеÄ0x00400000λÖÃÉÏ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-29 Ó³ÉäÎļþ


¢Þ ÔÚ¿þÀܽø³ÌÖÐÉêÇëÄÚ´æ¿Õ¼ä£¬²¢½«ÎÒÃÇÕýÔÚµ÷ÊÔµÄÕû¸öshellcodeдÈ뵽Ŀ±êÄÚ´æÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-30 дÈëshellcodeµ½ÏµÍ³×Ó½ø³ÌÖÐ


¢ß ʹÓÃZwGetContextThreadºÍZwSetContextThreadº¯Êý£¬»ñÈ¡ºÍÐ޸ĹÒÆðµÄ×Ó Ïß³ÌÉÏÏÂÎÄÖмĴæÆ÷Öµ£¬ÒÔʵÏÖÖض¨Ïòµ½shellcodeÈë¿Ú´¦Ö´ÐеÄÄ¿µÄ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-31 ÐÞ¸Äϵͳ×Ó½ø³ÌµÄÖ´ÐÐÈë¿Úµã


¢à Èô¡°²½Öè¢Ý¡±²Ù×÷Àֳɣ¬Ôò»Ö¸´Ö´ÐÐ×Ó½ø³Ì£»·ñÔò½áÊøµ±Ç°·¨Ê½¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-32 Åжϲ½Öè¢ÝÊÇ·ñ²Ù×÷ÀÖ³É


£¨3£©ÀÖ³É×¢Èëºó¶ñÒâÐÐΪ¹¦Ð§

ÎÒÃÇÔÚ¶ñÒâ´úÂëµ÷ÓÃNtResumeThreadº¯ÊýÇ°£¬¸½¼ÓRegAsm.exe½ø³Ì²¢ÔÚ×¢ÈëµÄshellcodeÖ´Ðд¦ÉèÖöϵ㣨Èçͼ4-33£©£¬È»ºóÔÙ¼ÌÐøÖ´Ðиú¯ÊýÀ´»Ö¸´Ïß³ÌÔËÐС£¸ÃshellcodeÇ°²¿ÃÅÓë֮ǰµÄ²Ù×÷Á÷³ÌÏàͬ£¬½«Ç°ÎÄÃèÊöµÄÖÖÖÖ¼ì²âÖØÐÂÖ´ÐÐÒ»±é£¬Ö±µ½ÔÚ¡°ÅжÏÊÇ·ñ´´½¨×Ó½ø³Ì¡±´¦Ìøתµ½ÁíÍâµÄ·ÖÖ§Á÷³Ì¡£ÏÂÃæÎÒÃǼÌÐø¶ÔºóÐø¹¦Ð§½øÐÐÏêϸµØ·ÖÎö¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-33 ShellcodeÖ´Ðд¦´úÂë


ÅжϿªÆôRegAsm.exe·¨Ê½µÄ¸¸½ø³ÌÊÇ·ñΪ¡°C:\Users\***\directory\filename.exe¡±¡£

Èç¹û²»ÊÇ£¬Ôò½«µ±Ç°¸¸½ø³ÌÎļþ¸´ÖƵ½¸ÃĿ¼ÖУ¬½«ÆäÃüÃûΪfilename.exe²¢ÖØÐÂÖ´ÐУ»

Èç¹ûÊÇ£¬ÔòÔÚ×¢²á±íHLM\Software\Microsoft\Windows\CurrentVersion\RunOnceĿ¼Àォ¸Ã·¾¶Ìí¼ÓÔÚ¡°Startup key¡±ÖУ¬ÒÔʵÏÖºã¾ÃפÁôµÄÄ¿µÄ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-34 Ìí¼Ó×¢²á±íÐÅÏ¢´úÂë


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-35 Ìí¼Ó×¢²á±í¿ª»úÆô¶¯Ïî


ÀÖ³ÉÌí¼Ó×¢²á±íÏîºó£¬¶ñÒâ´úÂëÔò¿ªÊ¼Ê¹ÓÃwinnet.dll¿âÖеÄInternet APIº¯Êý´ÓÔÆÍйܷþÎñÆ÷ÏÂÔؼÓÃܵÄpayload¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-36 ´ÓÔÆÍйܷþÎñÏÂÔØpayload


ÏÂÔØÍê³Éºó£¬¶ñÒâ´úÂëÔÙ½«Ó²±àÂëµÄÖµÓ뽫payloadµÄ¾Þϸ×ö±ÈÁ¦£¬ÒÔ´ËÀ´¼ì²éÎļþµÄÍêÕûÐÔ¡£Èç¹û¾Þϸ²»Æ¥Å䣬¶ñÒâ´úÂëÔò»áÖØÐÂÏÂÔØÎļþ£¬Ö±µ½ÍêÈ«Æ¥ÅäΪֹ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-37 ¼ì²âpayload¾Þϸ


ÏÂÔص½µÄpayloadÎļþÊÇÓÉ0x40¸ö×Ö½ÚµÄHEXСдÊý×ֺͼÓÃܵÄPEÎļþ×é³É£¬¾ßÌåÈçͼ4-38Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-38 payloadÄÚÈÝ


½Ó×Å£¬¶ñÒâ´úÂëÔÙʹÓÃ×Ô½ç˵½âÃܺ¯Êý¶ÔÏÂÔصÄpayload½øÐÐÒì»ò½âÃÜ¡£ÆäÃÜÔ¿´¢´æÔÚshellcode´úÂë0x2032Æ«ÒÆ´¦£¬ÃÜÔ¿³¤¶ÈΪ0x214¡£½âÃܺ¯ÊýÄÚÈÝÈçͼ4-39Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-39 payload½âÃܺ¯Êý


½âÃܺóµÄPEÎļþÈçͼ4-40Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-40 ½âÃܺóµÄÎļþÄÚÈÝ


×îºó£¬¶ñÒâ´úÂ뽫½âÃܺóµÄPEÎļþÁýÕÖ0x00400000»ùÖ·µÄÄÚÈÝ£¬²¢Ìøתµ½Èë¿ÚµãÖ´ÐÐpayload¶ñÒⷨʽ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4-41 Ö´ÐÐpayload


Ôڴ˴ηÖÎöµÄ°¸ÀýÖУ¬½âÃܳöµÄpayloadÊÇAgent Tesla¡£¶ÔÓڸöñÒâÈí¼þ£¬ÔÚ´ËÎÒÃǾͲ»ÔÙ×ö¹ý¶àµÄ½éÉܺͷÖÎöÁË¡£ÏÂÃæÎÒÃÇ»á¶ÔºÚ¿Í×éÖ¯µÄC&C·þÎñÆ÷»ù´¡ÉèÊ©Õ¹¿ª×·×ÙËÝÔ´¡£


Îå¡¢ËÝÔ´×·×Ù


5.1 C&C»ù´¡ÉèÊ©


½ØÖ¹µ½Ä¿Ç°ÎªÖ¹£¬ÎÒÃÇͨ¹ýÌáÈ¡ºÍÕûÀíËùÓйØÁªÑù±¾ÖеÄIPµØÖ·ºÍÓòÃûÐÅÏ¢£¬¿ÉÒÔ¿´µ½´Ë´Î¹¥»÷Ðж¯Ö÷ÒªÒÔ¶¯Ì¬ÓòÃûΪÖ÷£¬´ó²¿ÃÅÓòÃû¶¼ÊÇͨ¹ý¾³ÍâµÄDuck DNS×¢²á¡£Í¼5-1ΪSWEEDºÚ¿Í×é֯ʹÓõIJ¿ÃÅÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹Øϵ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-1 ²¿ÃÅÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹Øϵͼ



ƾ¾ÝÑù±¾Í¬Ô´ÐÔ·ÖÎöµÄ½á¹û£¬ÎÒÃÇ·¢ÏÖ´óÁ¿µÄÓÐЧÔغɱ»·Ö±ð¹ÒÔØÔÚ²îÒìµÄ¶¯Ì¬ÓòÃûÖУ¬ÒÔ±¸°üÂÞ©¶´µÄOfficeÎĵµ»ò¶ñÒâÈí¼þGuloader·ÃÎʺÍÏÂÔØ¡£Í¨¹ýÓòÃûµÄ²éѯ¼Ç¼ËùµÃ£¬´Ë´Î¹¥»÷»î¶¯×îÔç¿É×·Ëݵ½1ÔÂÖÐÏÂÑ®£¬Í¬Ê±Ò²¿ÉÒÔ¿´µ½£¬ËüÃÇ×î³õ¾ùʹÓÃÖ¸ÏòÄáÈÕÀûÑǵĻù´¡ÉèÊ©¡£ÖµµÃ×¢ÒâµÄÊÇ£¬ÕâЩÓòÃû½âÎöʹÓõÄIP×ܲ»¶¨ÆÚÔÚ³£ÓõÄIPµØÖ·¶ÎÀ´»ØÇл»¡£¾ßÌåÈçͼ5-2Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-2 ¶¯Ì¬ÓòÃû½âÎöµÄIPµØÖ·


ÎÒÃǽ«C&C¶ÔÓ¦µÄIPµØÖ·ËùÊô¹ú¼ÒºÍµØÓò½øÐÐͳ¼Æ£¬²¢»æÖÆÆäµØÀíλÖÃÂþÑÜͼ£¨Èçͼ5-3Ëùʾ£©¡£ÕûÌåÀ´¿´£¬ÃÀ¹úºÍ·¨¹úÕ¼±ÈÂÊ×î¸ß£¬Æä´ÎΪºÉÀ¼¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-3 C&C¶ÔÓ¦µÄIPµØÀíλÖÃÂþÑÜͼ


5.2 ¹ØÁªÐÔ·ÖÎö


¶«É­Æ½Ì¨ADLab½«±¾´Î²¶×½µ½µÄÑù±¾Í¬ÒÔÍùSWEED»î¶¯×öÁËÈ«ÃæµÄ¹ØÁª·ÖÎö£¬µÃ³öÒÔϼ¸´¦ÖØÒªµÄ¹ØÁªµã£º


£¨1£©Â©¶´Îĵµ

ÔÚ´Ë´ÎÐж¯Öй¥»÷×é֯ʹÓõÄ©¶´ÎĵµÓÐÁ½ÀࣨCVE-2017-11882ºÍCVE-2014-6357£©£¬ÆäÖÐÒÔCVE-2017-11882©¶´ÀûÓÃÎĵµÎªÖ÷Òª¹¥»÷ÔغÉ¡£¶øSWEED×éÖ¯Ò²ÔøÔÚÒÔÍùµÄ¹¥»÷Ðж¯ÖÐƵ·±µÄʹÓùý¸Ã©¶´Îĵµ¡£¾ßÌåÈçͼ5-4Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-4 ©¶´Îĵµ°¸Àý


£¨2£©¹¥»÷Ä¿±ê


ƾ¾Ý¹ûÈ»³ÂËß¿ÉÒÔµÃÖª£¬SWEEDºÚ¿Í×éÖ¯µÄ¹¥»÷Ä¿±êÖ÷ÒªÕë¶ÔÈ«Çò´ÓʶÔÍâóÒ×µÄÖÐСÐÍÆóÒµ£¬¶øÇÒËùÉæ¼°µÄÐÐÒµÖ÷ÒªÒÔÖÆÔìÒµ¡¢º½ÔË¡¢ÎïÁ÷ºÍÔËÊäΪÖ÷¡£ÕâÓëÎÒÃǴ˴μà²âµ½µÄ¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĵØÀíλÖúÍÐÐÒµÂþÑܾßÓнϸߵÄÏàËÆÐÔ¡£Í¼5-5ÁоÙÁ˼¸ÀýÔÚ±¾´Î¹¥»÷»î¶¯Öй¥»÷Õß·¢Ë͸øÄ¿±êÓû§µÄµöÓãÓʼþ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-5 µöÓãÓʼþ°¸Àý


£¨3£©¹¥»÷ÎäÆ÷


ÔÚÄ¿Ç°ÊӲ쵽µÄÐж¯ÖУ¬¹¥»÷Õß×îÖÕͶ·ÅµÄ¶ñÒâÈí¼þ°üÂÞAgent Tesla¡¢Remcos¡¢NanoCore¡¢FormbookºÍLokibot¡£ÎÒÃǽ«²¶×½µÄËùÓжñÒâÈí¼þ°´¼Ò×å·ÖÀàºÍͳ¼Æ£¬Æ¾¾Ý½á¹ûÏÔʾ£¬Agent TeslaµÄÕ¼±ÈÂÊ´¦ÓÚ×î¸ß£¬Êǹ¥»÷ÕßÖصãʹÓõĹ¥»÷ÎäÆ÷¡£¶øÕâÖÖʹÓÃÌØÕ÷Ò²ÔøÖظ´·ºÆðÔÚSWEED×éÖ¯ÒÔÇ°µÄ¹¥»÷»î¶¯ÖС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-6 ¶ñÒâÈí¼þ¼Ò×åÕ¼±ÈÂÊ


£¨4£©IPµØַλÖÃ


ÎÒÃÇͨ¹ýWhoisÐÅÏ¢²éѯ£¬·¢ÏÖÔÚ´Ë´ÎÐж¯ÖеÄÓòÃû¡°mogs20.xxx.org¡±ÔçÆÚ½âÎöµÄIP£¨105.112.XXX.XXX£©µØÀíλÖÃÖ¸ÏòÄáÈÕÀûÑÇ£¬¸ÃÍø¶Î¹éÊôÄáÈÕÀûÑǵØÓòµçÐŵÄ105.112¶Î¡£ÕâÓëSWEED×éÖ¯ËùÊô¹ú¼Ò¾ßÓи߶ȵÄÒ»ÖÂÐÔ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5-7 Whois²éѯÐÅÏ¢ÄÚÈÝ


½áºÏSWEED×é֯һϵÁеĹ¥»÷»î¶¯ÌصãÒÔ¼°ÉÏÃæ×ܽáµÄËĵã¿ÉÒÔ¿´³ö£¬¹¥»÷ÕßÔÚ¹¥»÷¶¯»ú£¨ÇÔÈ¡Óû§ÐÅÏ¢ÒÔIJÀû£©¡¢¹¥»÷Ä¿±ê£¨Õë¶ÔÈ«Çò¶ÔÍâóÒ×µÄÖÐСÆóÒµ£©¡¢×÷Òµ·ç¸ñ£¨Í¶µÝ¶¨ÖÆÐ͵öÓãÓʼþ·Ö·¢Ä¾Âí£©¡¢Õ½Êõ£¨¹æ±Ü¼ì²â¡¢³£×¤¡¢ÃüÁîÓë¿ØÖÆ£©¡¢¼¼Êõ£¨Â©¶´ÀûÓã©¡¢¹ý³Ì£¨·¢ËÍЯ´ø¶ñÒ⸽¼þµÄÓʼþ->©¶´Îĵµ->½âÃÜÔËÐÐAgent TeslaÔ¶¿ØľÂí£©ÒÔ¼°ÆäʹÓõÄÍøÂç»ù´¡ÉèÊ©µÈ·½Ã涼ʮ·ÖÇкÏSWEED×éÖ¯µÄÌØÕ÷¡£ÓÉ´ËÎÒÃÇÍƶÏ£¬´Ë´Î¹¥»÷»î¶¯Ä»ºóÕߺܿÉÄÜÊÇÀ´×ÔÄáÈÕÀûÑǵÄSWEEDºÚ¿Í×éÖ¯¡£


Áù¡¢×ܽá


Æù½ñΪֹSWEEDºÚ¿Í×éÖ¯ÖÁÉÙÒÑ»îÔ¾ÁË4ÄêµÄʱ¼ä£¬´Ó¸Ã×éÖ¯½üÆڵĹ¥»÷¿ÉÒÔ·¢ÏÖ£¬SWEED¿ªÊ¼Ê¹Óøü¾ßÓÐÕë¶ÔÐÔµÄÓʼþÄÚÈݺ͸ü¾ßÃÔ»óÐÔµÄÎĵµ±êÌ⣬´Ó¶øÌá¸ßÊܺ¦ÕßÖÐÕеĸÅÂÊ¡£¶«É­Æ½Ì¨ADLab½«¸Ã×éÖ¯´Ë´ÎÐж¯TTPµÄÑо¿·ÖÎö½á¹ûÓëÒÔÍù¸ú½ø»òÅû¶µÄÏà¹Ø¹¥»÷Ðж¯ÌØÐÔ×ö±È¶Ôºó£¬µÃµ½µÄÏà¹ØÖ¤¾Ý¶¼¿É±íÃ÷ÕâЩÑùÔ­À´×ÔSWEEDºÚ¿Í×éÖ¯¡£


SWEED×é֯ʹÓÃGuloaderÏÂÔØÆ÷Á÷´«µÄÔ¶³ÌľÂíÖÖÀàËäÈ»¶àÑù»¯£¬µ«Ö÷Òª»¹ÊÇÒÔÆäÆ«ºÃµÄAgent TeslaΪÖ÷¡£´ÓÆäËùʹÓõÄTTPÀ´¿´£¬¸ÃºÚ¿Í×é֯Ŀǰ²¢Î´¾ß±¸ºÜºÃµÄ×ÔÑпª·¢ÄÜÁ¦¡£ÔÚ¶àÊýÇé¿öÏ£¬½ö»á´Ó¹úÍâһЩÖ÷Á÷ºÚ¿ÍÍøÕ¾ÉϹºÖÃľÂíÉú³ÉÆ÷ºÍ¼ÓÃܹ¤¾ßÀ´×÷Ϊ¹¥»÷ÎäÆ÷£¬ÀýÈçÔøʹÓõÄKazyCypterºÍ´Ë´ÎʹÓõÄGuloader¡£²»Í⣬¼´±ã¹¥»÷ÕßÔÚ¼¼ÊõÄÜÁ¦ÉÏÏà¶Ô½ÏÈõ£¬µ«ÆäÔÚÉ繤¼¼ÇɺͶàÑù»¯¹¥»÷·½Ê½µÄÓ¦ÓÃÃæÉÏ»¹ÊǽÏΪÊìÁ·µÄ¡£ÔÚ´Ë£¬½¨ÒéÓû§¾¡Á¿ÖÆÖ¹´ò¿ª²»Ã÷À´ÀúµÄÓʼþÒÔ¼°¸½¼þÎļþ£¨À´×Ôδ֪·¢ËÍÕߵģ©£¬¼°Ê±°²×°ÏµÍ³²¹¶¡£¬Ìá¸ß·çÏÕÒâʶ£¬·À·¶´ËÀà¶ñÒâÈí¼þ¹¥»÷¡£




Æß¡¢IOC


MD5

F97CFA6C3F1338B597768808FC1B2F00

B1941921571C2B6ED0C3BDA77E402001    

DD82B2E488811E64BB9C039C441DB19C

EC4CF91427DAC3AD29CD2A52B0789DC6

166FD7B0C74C60DCBC80BF335D712EA2

BCBCC89F237B22F21BDAE9E6555404A

60147B91AB7B64B9BE27BD3422147E60

48408BBE8D9EE22D6BBB6820FCCC305F

7DDA46F2D9008FAE016AFFF39E9C5801

A22A37E699C20D42753D35A94A75B365

C36C41EB6A34880459154334681C203A

6BC92ACB050A2068EFF4842A1D360938

FB7ED44C2BAAA6F011F7BF51DE721BC4

58604AE63AEA84483C67980369958ACB

312BFAFE6746645E72FCB84ECBFB023C

779EB99965F1AAC12363632468DF7DCE

DD49030C00EF3C2341BCBE4489DCEF63

IP

167.114.85.125

URL

https://drive.google.com:80/uc?export=download&id=1lmmu6kv5ep_wkm7hfyhdshru-y1n2pqv

https://onedrive.live.com/download?cid=554BBD19BDD72613&resid=554BBD19BDD72613!156&authkey=AGIuaWEkkBxB_4o

https://drive.google.com/uc?export=download&id=1W3ddZnmArVGhsecoWW5KcQAKPZ9OacLU

https://share.dmca.gripe/iQakn267f3ZvpDN.bin

http://167.114.85.125/go/Origin%20server%20ilyas_tTzYDNEGay108.bin



°Ë¡¢²Î¿¼Á´½Ó


[1]https://www.fortinet.com/blog/threat-research/new-agent-tesla-variant-spreading-by-phishing

[2]https://www.fireeye.com/blog/threat-research/2017/10/formbook-malware-distribution-campaigns.html

[3]https://www.fortinet.com/blog/threat-research/new-infostealer-attack-uses-lokibot

[4]https://success.trendmicro.com/solution/1122912-nanocore-malware-information

[5]https://www.fortinet.com/blog/threat-research/remcos-a-new-rat-in-the-wild-2





¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´800Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾