½©Ê¬ÃÛÍø£ºÊ׿î¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦µÄÎïÁªÍø½©Ê¬ÍøÂç

Ðû²¼Ê±¼ä 2020-07-24

Ò»¡¢¸ÅÊö


½üÆÚ£¬ÎÒÃǸú×Ùµ½Ò»ÆðÌØ´ËÍâÎïÁªÍø½©Ê¬ÍøÂç¹¥»÷ʼþ¡£¸Ã¹¥»÷ʼþ½ü3¸öÔÂÀ´¶ÔÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹¡¢µÂ¹úµÈ¶à¸ö¹ú¼Ò·¢¶¯Á˽ÏΪƵ·±µÄ¹¥»÷¡£ÕâÅú¹¥»÷ËäÈ»Á÷Á¿²¢²»´ó£¬µ«ÔÚ×·×ٵĹý³ÌÖз¢ÏÖ£¬ÕâÅú¹¥»÷ÖдæÔÚһЩVT²éɱÂÊΪ0µÄ¶ñÒâÑù±¾£¬Èçͼ1Ëùʾ£»¶øÇÒ»¹·¢Ïָý©Ê¬ÍøÂçµÄÐí¶à½ÚµãÐÂÆæµØ¼ÓÈëÁËÓÕ²¶¼°·´Ì½²âÄÜÁ¦¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ1£ºVT¼ì²âÇé¿ö


ÕâЩ½©Ê¬Ñù±¾¿ÉÒÔ½«ÊÜ¿ØÉ豸µÄÖ¸ÎÆÐÅϢαװ³ÉÆäËûÉ豸µÄÖ¸ÎÆ£¨Ä¿Ç°½ö·¢ÏÖDVRµÄαÔìÖ¸ÎÆ£¬ÍƲâºÚ¿Í¿ÉÒÔͨ¹ý¸üÐÂÄ £¿éÀ´Î±ÔìÆäËûÉ豸ָÎÆ£©¡£Ò»·½ÃæÒÔαÔìÉ豸ָÎƵķ½Ê½À´ÆÛÆ­ÈçShodanµÈÖÖÖÖ©¶´É¨Ãè²úÎÒÔµ½´ï·´Ì½²âµÄÄ¿µÄ£»ÁíÍâÒ»·½ÃæÕâÖÖαÔìµÄÉ豸ָÎÆÒ²±»ÀûÓÃÀ´×öÓÕ²¶£¬Èçαװ³ÉΪһ¸ö´æÔÚ©¶´µÄÉ豸£¬ÒÔÃÛ¹ÞÓÕ²¶µÄ·½Ê½ÓÕʹÆäËûºÚ¿Í·¢ËÍÀûÓôúÂë½øÐй¥»÷£¬´Ó¶øµÃµ½Â©¶´ÀûÓÃϸ½Ú¡£Òò´Ë£¬ÎÒÃǽ«´ËÀཀྵʬËù¹¹½¨µÄ¿ÉÒÔ¶Ô©¶´ºÍ¹¥»÷Ñù±¾½øÐÐÓÕ²¶µÄ½©Ê¬ÍøÂçÃüÃûΪ¡°½©Ê¬ÃÛÍø¡±¡£


ͨ¹ýÎÒÃÇ×Ô¼ºµÄÎïÁªÍøÍþвÊý¾Ýƽ̨¼°Ïà¹ØÇ鱨µÄ½»²æÓ¡Ö¤£¬·¢ÏÖ¡°½©Ê¬ÃÛÍø¡±°üÂÞÁ½ÀàÑù±¾¡£µÚÒ»ÀàÊÇÓÕ²¶Ó뷴̽²â½Úµã£¬¶Ô¸ÃÑù±¾½øÐжþ½øÖÆÎļþÏàËƶȱȶԷ¢ÏÖÆä¹¥»÷Ä £¿éºÍͨÐÅЭÒéÓëMoobot¼Ò×å¸ß¶ÈÏàËÆ£¬ÍƲâÓëMoobot¼Ò×åͬԴ£¬Òò´Ë½«ÕâÀàÐÂÐ͵ĶñÒⷨʽÃüÃûΪMoobot_Trap£¬Æä½è¼øÁËÃÛ¹ÞµÄÉè¼Æ˼Ï룬³ýÁËαװ×ÔÉíΪÆäËûÉ豸Í⣬»¹ÄÜͨ¹ýÓÕ²¶ÆäËü¹¥»÷Õߵĩ¶´ÀûÓÃÇ鱨Óë¹¥»÷Ñù±¾£¬À´Áé»î¿ìËÙµÄÉý¼¶ÆäÎäÆ÷¿â£¬¼ÓÇ¿×ÔÉíµÄ¹¥»÷Óë·ÀÓùÄÜÁ¦¡£µÚ¶þÀàÊǹ¹½¨ÊðÀíÍøÂçµÄ¶ñÒâÊðÀí½Úµã£¬ÎÒÃǽ«ÆäÃüÃûΪMal_Proxy£¬Í¨¹ýÏ·¢¶ñÒâÊðÀíÄ £¿é£¬¹¥»÷ÕßÄܹ»½«ÊÜѬȾ»ò¹ºÖõÄÉ豸×÷ΪнڵãÀ´ÊðÀíÈÎÒâÁ÷Á¿£¬½ø¶ø²»Í£Éú³¤×³´óÆäÊðÀíÍøÂç¡£¶ñÒâÁ÷Á¿¾­ÊðÀíÍøÂçÖÐתÖÁTorÍøÂç»òÕæʵC&C£¬Ò»·½Ãæ¿ÉÒÔÖÆÖ¹Ö±½Ó̻¶Éí·Ý£¬ÁíÒ»·½ÃæÒ²ÄܸüºÃµÄ´©Í¸Ä³Ð©ÍøÂç·À»ðǽµÄÏÞÖÆ¡£Í¨¹ýÄ¿Ç°ÕÆÎÕµÄÊý¾Ý½áºÏÎïÁªÍø½©Ê¬Ñù±¾µÄ·ÖÎö£¬ÎÒÃÇ»¹Ô­³öÁ˸ý©Ê¬ÍøÂçµÄ¹¥»÷Ä£ÐÍÈçͼ2Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ2£º¡±½©Ê¬ÃÛÍø¡°¹¥»÷Ä£ÐÍ


½øÒ»²½ËÝÔ´ºó£¬ÎÒÃÇ·¢ÏÖÕâ´Î¹¥»÷±³ºóµÄ×éÖ¯¿ÉÄÜͬʱÕÆ¿Ø×Å°üÂÞMoobot¡¢LeeHozer¡¢Gafgyt±äÖÖÔÚÄڵĶà¸ö½©Ê¬ÍøÂç¡£¸Ã×éÖ¯²»½ö¾ßÓжàÖÖ0DayºÍNday©¶´¹¥»÷µÄÄÜÁ¦£¬»¹Éó¤Í¨¹ýÊðÀíÍøÂç¡¢TorÍøÂçµÈÊðÀí¼¼ÊõÀ´¼ÓǿͨÐŵÄÄäÃû»¯£¬´Ó¶øÌá¸ßÆäC&C·þÎñÆ÷µÄÒþ±ÎÐÔ¡£±¾ÎĽ«¶Ô²¶×½µ½µÄ½©Ê¬Ñù±¾¡¢¶ñÒâÊðÀí·¨Ê½¼°Æä¹¥»÷Á´½øÐÐÆÊÎö£¬²¢½øÒ»²½¶Ô±³ºóµÄºÚ¿Í×éÖ¯ÒÔ¼°ÕâЩ½©Ê¬ÍøÂç¼äµÄ¹ØÁªÐÔÕ¹¿ª·ÖÎöºÍ×·×Ù¡£


¶þ¡¢¹¥»÷×ÊÔ´·ÖÎö


ÔÚ×·×Ù¹ý³ÌÖУ¬ÎÒÃÇ·¢ÏÖ¡°½©Ê¬ÃÛÍø¡±Óë¶à¸ö½©Ê¬ÍøÂç¼ä´æÔÚ½ÏÇ¿µÄ¹ØÁªÐÔ£¬°üÂÞMoobot¡¢LeetHozerÒÔ¼°Gafgyt±äÖֵȵÈ¡£ÒÔMoobotºÍLeetHozerÁ½ÀཀྵʬÍøÂçΪÀý£¬proxy.2u0apcm6ylhdy7s.comÓòÃûÔø×÷ΪMal_ProxyµÄDownloader URLÒÔ¼°MoobotµÄC2£»elrooted.comÏà¹Ø×ÓÓòÃûÔøÓÃÓÚMal_ProxyµÄC2ÒÔ¼°Moobot¡¢LeetHozerµÄDownloader URL£¬ÀàËÆÓòÃû×ʲúÖØÓõÄÏÖÏ󣬱íÃ÷Á½ÀཀྵʬºÜÓпÉÄÜÔ´×Ôͬһ×éÖ¯¡£ÎÒÃÇÕûÀíÁ˹ØÁªÑù±¾µÄÁ÷´«ºÍÖ´ÐÐÁ÷³ÌÈçͼ3Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ3£º¹ØÁªÑù±¾µÄÁ÷´«ºÍÖ´ÐÐÁ÷³Ìͼ


ÆäÖУ¬MoobotÊÇÑù±¾ÊýÁ¿×î¶àÇÒÁ¬Ðø»îÔ¾µÄÒ»Àཀྵʬ£¬ÎÒÃÇ·¢Ïֵľ߱¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦µÄMoobot_Trap±ãÊÇÆäͬԴ¼Ò×塣ͬʱ£¬ÓÉÓÚMoobotÇ°ÆÚÁ÷´«µÄÑù±¾Éæ¼°SocksºÍTor°æ±¾£¬Ò²¿ÉÄÜÓë´Ë´Î·¢ÏֵĶñÒâÊðÀí·¨Ê½ÓйØ¡£LeetHozer½©Ê¬ÔòÊÇͨ¹ýSocks5ЭÒéºÍTor C&C½¨Á¢Á¬½Ó£¬ÇÒÓëMal_ProxyµÄ»îԾʱ¼äÏà½ü£¬ÍƲâLeetHozerÄÚÖõÄÊðÀí½ÚµãÁбíºÜ´ó¿ÉÄܾÍÊǺڿͿØÖƵĶñÒâÊðÀíÍøÂç¡£


ƾ¾ÝÄ¿Ç°µÄ¼à²âÇé¿ö£¬¸Ã×éÖ¯µ¥ÈÕÌᳫµÄ¹¥»÷´ÎÊýÔ¼ÔÚ100´Î×óÓÒ£¬±»¹¥»÷Ä¿±êÔòÖ÷ÒªÂþÑÜÔÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹¡¢µÂ¹úµÈ¹ú¼Ò£¬ÆäÖÐÕë¶ÔÎÒ¹úµÄ¹¥»÷´ó¶à¼¯ÖÐÔÚн®¡¢ºÓÄÏ¡¢½­ËÕ¡¢Ì¨ÍåµÈµØÓò£¬¹¥»÷¼Ç¼ʾÀýÈçͼ4£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4£º¹¥»÷¼Ç¼


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ5£º¾³ÄÚÊܹ¥»÷IPλÖÃÂþÑÜͼ


´ËÍ⣬¸Ã×éÖ¯»¹¾ß±¸ºÜÇ¿µÄ©¶´ÀûÓÃÄÜÁ¦£¬ÒÑÖªµÄÎäÆ÷¿â°üÂÞ½ñÄê³õÅû¶µÄLILIN DVR 0Day©¶´¡¢HiSilicon DVR backdoor 0Day©¶´£¬ÒÔ¼°Öî¶àÓ°Ï췶Χ¹ã·º¡¢Î£º¦ÑÏÖصÄNday©¶´£¬Ò»Ð©±»¹ûÈ»µÄ©¶´POCÒ²ÍùÍù»á±»Ñ¸ËÙ¼¯³É²¢Ó¦ÓÃÓÚÆ䩶´É¨ÃèÄ £¿é£¬¿¼Âǵ½ºÚ¿Í»¹¿ÉÒÔͨ¹ýαװµÄÓÕ²¶½ÚµãÊÕ¼¯ÆäËü¹¥»÷ÕßµÄÇ鱨¼°Ñù±¾Çé¿ö£¬ÎÒÃÇÔ¤¼ÆÆä¿ÉÓõÄ©¶´×ÊÔ´·Ç³£ÅÓ´ó¡£Í¨¹ýÄ¿Ç°¼à²â·¢ÏÖ¼°Ïà¹Ø³ÂËßÖÐÅû¶µÄ©¶´ÀûÓÃÇé¿ö£¬¸Ã×éÖ¯ÀûÓõÄ©¶´Èç±í1Ëùʾ£º


±í1£ºÂ©¶´ÀûÓÃÁбí

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÓòÃû×ʲú·½Ã棬¸Ã×é֯ʹÓÃʱ¼ä½Ï³¤¡¢Æµ´Î½Ï¸ßµÄÓòÃûΪelrooted.com¡¢2u0apcm6ylhdy7s.comÒÔ¼°¶¥¼¶ÓòÃû.xyzϵIJ¿ÃÅÓòÃû¡£ÕâÈýÀàÓòÃûϵÄ×ÓÓòÃûºã¾Ã±»½âÎö²¢ÓÃÓÚÆäÑù±¾µÄDownloaderURL»òC&C¡£ÆäÖУ¬185.172.110.0/23Íø¶Î¹ØÁª×Å´óÁ¿½©Ê¬£¬ÀýÈç185.172.110.240¡¢185.172.110.224¡¢185.172.110.235µÈµÈ¡£


»ùÓÚÄ¿Ç°ÕÆÎÕµÄÇé¿ö£¬ÎÒÃÇ×ܽá¸Ã×éÖ¯µÄÌصãÈçÏ£º


¡ñ ¸Ã×éÖ¯¿ÉÄÜÕÆ¿Ø×Å°üÂÞMoobot¡¢LeeHozer¡¢Gafgyt_variantÔÚÄڵĶà¸ö½©Ê¬ÍøÂ磬¹¥»÷Ä¿±ê±é²¼È«Çò£¬ÇÒ½üÆÚÈÔÔÚ±£³Ö¸ßƵÂʵĹ¥»÷»î¶¯

¡ñ ÕÆÎÕ×ÅÊðÀíÍøÂç×ÊÔ´£¬ÓëÆäËüʹÓÃÊðÀíÍøÂçµÄ½©Ê¬´æÔÚÒ»¶¨¹ØÁª£¬ÇÒ¿ÉÄÜÔÚµØÏÂÂÛ̳³öÊÛÊðÀí·ÃÎÊȨÏÞ

¡ñ Éó¤0DAY¡¢NDAY©¶´ÀûÓÃ

¡ñ Éó¤Ê¹ÓÃSocks5ÊðÀí¡¢TorÍøÂçµÈC&CÒþ²Ø¼¼Êõ

¡ñ Ñù±¾É¨ÃèÄ £¿éÂþÑÜÔÚ¶àÖÖÑù±¾ÖÐЭ×÷ɨÃ裬ɨÃèЧÂʸß

¡ñ Ñù±¾¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦£¬Äܹ»²¶×½ÆäËüºÚ¿ÍµÄ¹¥»÷Ç鱨

¡ñ ¾ß±¸Ò»¶¨µÄÄþ¾²·´¿¹ÄÜÁ¦£¬Ñù±¾µü´ú¸üп졢ÃâɱÐԺã¬Æµ·±¸ü»»UPX»ÃÊý¿Ç¡¢¸üÐÂÃô¸ÐÐÅÏ¢¼ÓÃÜËã·¨¼°Í¨ÐÅЭÒéµÈ


Èý¡¢¹¥»÷ÑùÌìÖ°Îö


ÓÉÓÚ¸Ã×éÖ¯ÓµÓÐ×ÅÁ½Àཀྵʬ½Úµã£¨ÓÕ²¶Ó뷴̽²â½Úµã¡¢ÊðÀí½Úµã£©£¬ÎÒÃÇÒ²½«Öصã¶ÔÕâÁ½Àà½ÚµãÏà¹ØµÄÑù±¾½øÐзÖÎö¡£µÚÒ»ÀàÑù±¾ÎªMoobot_Trap£¬Æäαװ³ÉΪDVRʵÏÖÓÕ²¶Óë·´Õì²âµÄ¹¦Ð§£»µÚ¶þÀàÑù±¾ÎªÊµÏÖ·´×·×Ù²¢ÓëTorÍøÂç¶Ô½ÓµÄSocket5ÊðÀí½Úµã£¬°üÂÞ¶ñÒâÑù±¾Mal_ProxyºÍLeeHozer¡£


3.1Moobot_Trap·ÖÎö


Moobot_Trap½©Ê¬ÊÇÒ»¸ö¹¦Ð§ÍêÕûµÄ½©Ê¬·¨Ê½£¬Æ书Ч°üÂÞÓÕ²¶¼à²âÒÔ¼°·´Ì½²â¡¢Â©¶´É¨Ãè¡¢DDos¹¥»÷¡£Í¨¹ýÑù±¾µÄÏàËƶȱȶÔ£¬ÎÒÃÇ×îÖÕÈ·¶¨Moobot_TrapÓëMoobot¼Ò×åͬԴ£¬Æä¹¥»÷´úÂëºÍͨÐÅЭÒé¾ßÓи߶ȵÄÏàËÆÐÔ¡£Moobot½©Ê¬×Ô2019ÄêÏ°ëÄ꿪ʼ»îÔ¾£¬Æäºã¾ÃÀûÓ鶴½øÐÐÀ©É¢ÓëѬȾ£¬¸Ã½©Ê¬½ÓÄÉÒ»ÖÖÊèɢɨÃèµÄ·½Ê½½øÐй¥»÷£¬¼´²»½«ËùÓЩ¶´É¨Ã跽ʽ¼¯³ÉÔÚµ¥¸öÑù±¾ÄÚ£¬¶øÊǽ«ÖÖÖÖ©¶´ÂþÑÜÔÚ¶àÀàBotÑù±¾ÖУ¬ÒÔÌá¸ßɨÃèЧÂʽµµÍ±»·¢Ïֵļ¸ÂÊ¡£Moobot_TrapÒ²ÑÓÐø´ËÖÖÌØÕ÷£¬µ«Æä×îÖØÒª¸Ä±äÊǼÓÈëÓÕ²¶ºÍ·´Ì½²âÄÜÁ¦£¬ÆäÔÚÊÜѬȾÉ豸ÉÏ¿ªÆôÒ»¸ömini_httpd·þÎñ£¬²¢Î±×°³ÉDVRÉ豸£¬Ò»·½ÃæÓÃÓÚÓÕ²¶Â©¶´ºÍ¹¥»÷Ñù±¾£¬Ò»·½Ãæ¿ÉÒÔÆÛÆ­ÖÖÖÖÉ豸̽²âƽ̨¡£

¾ßÌå·ÖÎöÑù±¾Èç±í2Ëùʾ£º


±í2£ºÑù±¾ÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.1.1 ÓÕ²¶Ó뷴̽²âÄ £¿é·ÖÎö


¸ÃÄ £¿éΪÁËʵÏÖÓÕ²¶¹¦Ð§£¬½«Ö÷¶¯¿ªÆôWEB·þÎñ¶Ë¿Ú(80¡¢8080¡¢8000)ÓëÊý¾Ý¿âHSQLµÄ·þÎñ¶Ë¿Ú(9002)£¬Ò»µ©ÊÕµ½Íâ½çµÄhttpЭÒéµÄɨÃè̽²â£¬±ã»á·µ»ØαװµÄÉ豸ָÎÆ¡£Ä¿Ç°·¢ÏÖµÄMoobot_Trap½«ÊÜ¿ØÉ豸αװ³ÉDVRÉ豸£¬²»ÍâºÚ¿Í¿ÉÒÔͨ¹ý¸üÐÂÄ £¿éÀ´±ä»»Ö¸ÎÆÐÅÏ¢¡£´ËÍâ¸ÃÄ £¿é»¹Äܹ»¼à¿ØÍâ½ç¶Ô¸ÃÉ豸·¢¶¯µÄ¹¥»÷²¢½«¹¥»÷ÐÅÏ¢Éϱ¨¸øºÚ¿ÍÔ¤ÏȲ¿ÊðµÄC&C·þÎñÆ÷ÉÏ£¬ÒԴ˺ڿͿÉÒÔ»ñÈ¡µ½Â©¶´É¨ÃèÌØÕ÷ºÍ¹¥»÷Ñù±¾¡£


( 1 ) ·´Ì½²â£ºÄ¿Ç°×îΪÖ÷Á÷µÄÉ豸̽²â¼¼ÊõÒÀÈ»ÊÇ»ùÓÚÖ¸ÎÆʵÏֵģ¬ÈçShodan¡¢ZoomEye¡¢CensysÒÔ¼°ÖÖÖÖ©¶´É¨Ãè²úÎÒò¶øMoobot_Trap»¹ÌṩһÀàÄÜÁ¦¾ÍÊǸøɨÃèÔ´ÌṩαÔìµÄÐÅÏ¢£¬ÒÔÆÛƭɨÃèÒýÇæ×ö¶éÂäÎóµÄ¾ö²ß¡£Ò»ÔòMoobot_Trap¿ÉÒÔ½«×ÔÉíαװ³ÉΪһ¸ö¼á²»ÐдݵÄÉ豸£¬ÈÃɨÃèÒýÇæÈÏΪÕâÊÇһ̨Äþ¾²µÄÉ豸¶ø½µµÍ±»·¢Ïֵļ¸ÂÊ£»Ò»ÔòMoobot_TrapÒ²¿ÉÒÔ½«ÈëÇÖµÄÉ豸αװ³ÉΪһ¸ö´æÔÚйûȻ©¶´µÄÉ豸£¬Æä¿ÉÒÔÆðµ½ÓÕ²¶Ò»Ð©Î´¹ûÈ»µÄ©¶´ÀûÓôúÂë¡£ÔÚÎÒÃǵ±Ç°Ëù·¢ÏֵĽ©Ê¬ÍøÂçÖУ¬ÆäÖб»ÈëÇÖµÄÈκÎһ̨É豸¶¼½«±»Ê¶±ð³ÉΪһ¸öÌṩmini_httpd·þÎñµÄDVRÉ豸(ÓÃÓÚÓÕ²¶Mini_httpd1.19Ïà¹ØµÄ©¶´ÀûÓôúÂë)¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ6£ºÉ¨ÃèÖ¸ÎÆʾÀý


Mini_httpdÊÇÒ»¿î΢Ð͵ÄHttp·þÎñÆ÷£¬ÔÚÕ¼ÓÃϵͳ×ÊÔ´½ÏСµÄÇé¿öÏ¿ÉÒÔ±£³ÖÒ»¶¨Ë®Æ½µÄÐÔÄÜ£¬Òò´Ë¹ã·º±»ÖÖÖÖÎïÁªÍøÉ豸£¨Â·ÓÉÆ÷£¬½»»»Æ÷£¬ÉãÏñÍ·µÈ£©×÷ΪǶÈëʽ·þÎñÆ÷ʹÓ᣶ø°üÂÞ»ªÎª¡¢º £¿µÍþÊÓ¡¢zyxel¡¢Ê÷Ý®Åɵȳ§É̵ÄÆìÏÂÉ豸¶¼Ôø½ÓÄÉMini_httpd×é¼þ£¬Ó°Ï췶ΧºÜ¹ã£¬Ïà¹Ø©¶´¿ÉÄÜÓ°ÏìÈ«ÇòÊý°ÙÍòÉ豸¡£ËùÒÔºÚ¿Í´ËÀàÐÂÓ±µÄ¼¼Êõ˼·ÔËÓÃÒ²ÐèÒªÒýÆðÎÒÃÇ×ã¹»µÄÖØÊÓ¡£


( 2 ) ÓÕ²¶£ºÎÒÃÇÖªµÀ£¬ÏÖʵÍøÂçÖдæÔÚ´óÁ¿Èä³æºÍ½©Ê¬ÍøÂ磬ËûÃÇÓÀ²»¼ä¶ÏµØɨÃè̽²âÍøÂç×ÊÔ´£¬Í¬Ê±ËûÃÇÒ²ÔÚʵʱ¸üÐÂÆä̽²âÌØÕ÷£¬ÈçºÚ¿ÍÃǵÄ0day/Nday©¶´É¨ÃèÌØÕ÷¡£¶ø´ó²¿ÃÅ¿ÉÓÃÓÚÈä³æºÍ½©Ê¬Á÷´«µÄÎïÁªÍø©¶´¶¼¼¯ÖÐÔÚHTTP·þÎñµÄÔ¶³ÌÃüÁîÖ´ÐЩ¶´(Õ¼±È¸ü¶àµÄTelnetÀ๥»÷ÒÔÈõ¿ÚÁîΪÖ÷£¬´Ë´¦²»±í)¡£¸Ã¶ñÒâÄ £¿éÕýÊÇÒÔ»ñÈ¡´ËÀ੶´¹¥»÷ÐÐΪΪĿµÄ£¬ÔÚÆô¶¯¶Ë¿ÚÉϼàÊÓwget¡¢tftp¡¢/bin/shÃüÁÊÕ¼¯Â©¶´ÐÅÏ¢ºÍÁ÷´«Ñù±¾¡£ÏÂͼÊÇÒ»¸öÔ¶³ÌÃüÁîÖ´ÐЩ¶´µÄPayload£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ7£ºÉ¨ÃèPayloadʾÀý


µ±Ä³Ð©¹¥»÷Õß¡¢Èä³æ»òÕß½©Ê¬·¨Ê½Õë¶ÔÊÜѬȾÉ豸½øÐЩ¶´É¨Ãè»ò´úÂëÖ²Èëʱ£¬Ò»µ©¹¥»÷PayloadÖÐЯ´øÓÐÖ¸¶¨ÊýÁÈçͼÖеÄwget£©Ê±£¬¸ÃÊý¾Ý¼´±»ÊÓΪÓÐЧÇ鱨±»×ª·¢ÖÁMoobot_TrapºÚ¿ÍµÄC&C¡£Í¨¹ýÕâÖÖÀàËÆÃ۹޵ļà²â¼¼Êõ£¬ºÚ¿Í¿ÉÒÔ²¶×½µ½´óÁ¿Â©¶´ÀûÓôúÂ룬ÉõÖÁÊÇ0day©¶´£¬¸ü½øÒ»²½£¬»¹Äܹ»Í¨¹ýÁ÷´«µÄ½©Ê¬ÑùÔ­À´ÌáÈ¡ºÍÑо¿¸ü¶àÓмÛÖµµÄ©¶´»ò¼¼Êõ¡£


´ÓÉÏÃæµÄ·ÖÎöÎÒÃÇ»¹¿ÉÒÔ¿´³ö£¬Èç¹ûºÚ¿Í×éÖ¯¾ß±¸×ã¹»µÄ¼¼ÊõʵÁ¦£¬»¹ÄÜͨ¹ý²¶×½µÄɨÃèÐÅÏ¢»ñÈ¡µ½ÆäËü½©Ê¬ÍøÂçµÄDownload IP»òC&C²¢½øÒ»²½ÊµÊ©ÈëÇÖ¡£Í¨³£Çé¿öϹ¥»÷Õߵĺܶà·þÎñÆ÷¶¼À´×Ô©¶´ÈëÇÖ¡¢Telnet±¬ÆƵȵÈ£¬ÄÇôÕâЩ·þÎñÆ÷×ʲú¾ÍºÜÓпÉÄܱ»ºÚ¿Í×éÖ¯¶þ´ÎÈëÇÖ£¬Ô­¿ØÖÆÕßÓµÓеÄÈ⼦×ÊÔ´Ò²¿ÉÄܱ»¹²Ïí»ò½Ó¹Ü¡£ÏÂÎÄÎÒÃǽ«¶ÔMoobot_Trap½øÐзÖÎöÓëÂÛÊö¡£


Moobot_TrapÊ×ÏÈ»áÔÚ80¡¢8080¡¢8000¡¢9002ËÄÖֶ˿ÚÖÐËæ»úÑ¡ÔñÆäÒ»½¨Á¢·þÎñ¶Ë¼àÌý£¬¿ÉÒÔÈÏΪºÚ¿ÍµÄÄ¿±ê¾ÍÊÇÊÕ¼¯ÕâËÄÀà¶Ë¿ÚµÄɨÃèÊý¾Ý¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ8£ºÑ¡Ôñ¶Ë¿Ú½¨Á¢¼àÌý


µ±¹¥»÷ÕßɨÃèÏàÓ¦¶Ë¿ÚÇÒ·¢Ë͵ÄÇëÇóÊý¾Ý°üÂÞwget¡¢tftp¡¢/bin/shÃüÁîʱ£¬Moobot_Trap»á·µ»ØαÔìµÄmini_httpd·þÎñÆ÷ÐÅÏ¢²¢½«ÇëÇóÊý¾Ýת·¢¸øC&C£¬Ö®ºó¹Ø±ÕÓë¿Í»§¶ËµÄÁ¬½Ó£¨Ä£ÄâHTTPÎÞÁ¬½ÓÇëÇ󣩡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ9£º·µ»Ømini_httpd·þÎñÆ÷ÐÅÏ¢


Á¬½ÓC&CÔòÊǼÓÃÜ´æ´¢ÔÚÄÚ´æÖУ¨Ãô¸ÐÐÅÏ¢¼ÓÃܽ«ÔÚºóÐøÕ½ڷÖÎö£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ10£º×ª·¢Êý¾Ý


Ä£ÄâÒ»´ÎɨÃèµÄʵ¼ÊÇé¿ö£¬µ±¹¥»÷ÕßÕë¶ÔÓÕ²¶½Úµã½øÐЩ¶´É¨Ãèʱ£¬½»»¥Á÷Á¿Êý¾Ý°üÈçͼ11Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ11£º½»»¥Êý¾Ý°ü


Moobot_Trap¼ì²âµ½wgetÃüÁîʱ£¬»áʶ±ðΪÓÐЧÇ鱨£¬²¢½«É¨ÃèÐÅÏ¢ÒÔÈçϵÄÐÎʽÉϱ¨ÖÁC&C¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ12£ºÉϱ¨É¨ÃèÊý¾Ý


Éϱ¨Êý¾Ý¸ñʽÈç±í3Ëùʾ£º


±í3£ºÉϱ¨Êý¾Ý¸ñʽ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.1.2 Ãô¸ÐÐÅÏ¢¼ÓÃÜ


¼ÓÃÜÊý¾Ý²¢·ÇÕû¶Î´æ´¢ÔÚ´úÂëÖУ¬¶øÊǽ«×Ö·û´®³£Á¿Ö§½â³É¶à¸ö²¿ÃÅ´æ·ÅÔÚrodataºÍtext¶Î£¬ÕâÒ²»á¸ø·ÖÎöÊÂÇéÔì³ÉÒ»¶¨µÄ×ÌÈÅ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ13£º¼ÓÃÜ×Ö·û´®


¾ßÌå¼Ó½âÃÜËã·¨ÓëMiraiÏàͬ£¬ÃÜԿΪ0x0deadbeef£¬ËùÓÐ×Ö·û´®µÄʹÓö¼ÊÇÓÃʱ½âÃÜ£¬ÓÃÍê¼´»Ö¸´¼ÓÃÜ£¬¼Ó½âÃÜËã·¨Èçͼ14Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ14£º¼Ó½âÃÜËã·¨


3.1.3 ¶Ë¿ÚɨÃèºÍÐÅÏ¢Éϱ¨


MoobotɨÃèÄ £¿é½ÓÄÉÈ«ÍøɨÃ裬²¢½«É¨Ãè½á¹ûÉϱ¨Reporter£¬×îºóÓÉLoaderÕë¶Ô©¶´É豸ֲÈëÑù±¾£¬ÀúÊ·ÉÏÆä´æÔÚ¶àÖÖɨÃè°æ±¾£º


( 1 ) TCP:23,26 (Telnet)

( 2 ) TCP:34567 (DVRIP)

( 3 ) TCP:4567(TVT)

( 4 ) TCP:5555 (ADB)

( 5 ) TCP:80,81,82,83,85,88,8000,8080,8081,9090,60001 (HTTP)


¶ÔÓÚɨÃèhttp·þÎñµÄÑù±¾£¬Èç¹û¼ì²âµ½ÈçÏÂHttp ServerÔò»áÉϱ¨Reporter¡£Ñù±¾½âÃܺóÓÃÓÚ¼ì²âµÄ·þÎñÆ÷×Ö·û´®Ê¾ÀýÈçÏ£º

"Server: JAWS/1.0."

"Server: DWS."

"URL=/view/viewer_index.shtml?id=."

"Server: thttpd/2.25b PHP/20030920."

"Server: Boa/0.93.15."


ÕâЩ²îÒìɨÃèÖÖÀàµÄÑù±¾µÄDownloaderURLͨ³£Ò²ÊÇÒÔ¶ÔӦ©¶´É豸µÄÃû³ÆÀ´ÃüÃûºÍ·ÖÀ࣬ÀýÈ磺


±í4£ºDownloadURLÌصã

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶ÔÓÚɨÃèʹÓõı¬ÆÆƾ֤£¬³ýÁ˲¿ÃÅÄÚÖÃÁбí£¬»¹¿ÉÒÔÏòC&C·¢ËÍÇëÇóÖ¸ÁîÒÔ»ñÈ¡±¬ÆÆÃû³ÆÃÜÂëÁбí£¬ÇëÇóÖµ²îÒì¶ÔÓ¦²îÒìµÄ±¬ÆÆ×éºÏÖµ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ15£º·µ»Ø±¬ÆÆ×éºÏ


µ±É¨Ãè·¢ÏÖ¿ÉÓ鶴É豸Ôò»áÏòReporterÉϱ¨É豸ÐÅÏ¢¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ16£ºÉϱ¨É豸ÐÅÏ¢


±í5£ºÉϱ¨É豸ÐÅÏ¢½âÎö

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.1.4 ͨÐÅЭÒé¼°¹¥»÷Ä £¿é


Moobot_TrapÔÚͨÐÅЭÒé·½ÃæÓë֮ǰµÄ°æ±¾ÓÐËù±ä»¯£¬Àֳɽ¨Á¢Á¬½Óºó£¬Ê×ÏÈ»áÏò¿ØÖƶ˷¢ËÍÉÏÏß°ü¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ17£ºÉÏÏßÊý¾Ý°ü


±í6£ºÉÏÏßÊý¾Ý°ü½âÎö

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ö®ºó¼ä¸ô60ÃëÑ­»·Ïò¿ØÖƶ˷¢ËÍÐÄÌø°ü[0x00 0x00]£¨ÀιÌÖµ£©£¬¿ØÖƶËÔò¼ä¸ô20ÃëÏò½©Ê¬·¨Ê½»Ø°ü[0x33 0x66 0x99]£¨ÀιÌÖµ£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ18£ºÐÄÌøÊý¾Ý°ü


µ±¿ØÖƶ˷¢Ë͵ÄÖ¸ÁîÇ°Èý×Ö½Ú·Ç[0x33 0x66 0x99]ʱ£¬Ôò½øÈë¹¥»÷ģʽ½âÎöÖ¸Áî¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ19£º½âÎö¹¥»÷


¹¥»÷Ä £¿é·½Ã棬Moobot_TrapÑÓÓÃÁËMiraiµÄ¹¥»÷ÐÎʽ£¬Ñù±¾°üÂÞ7ÖÖ¹¥»÷ģʽ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ20£º¹¥»÷ģʽ


¹¥»÷Ö¸ÁîÊý¾Ý°üÈçͼ21Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶ÔÓ¦½á¹¹ÌåʾÒâÈçÏ£º

type Attack struct {

  Duration          uint32

  Type              uint8

  Targets counts    uint8

  Targets           map[uint32]uint8  

  Flags counts      uint8

  Flags             map[uint8]string

}


±í7£º¹¥»÷Ö¸Áî½âÎö

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.2Mal_Proxy·ÖÎö


Mal_ProxyÊǺڿÍ×éÖ¯ÓÃÓÚ¹¹½¨ÊðÀíÍøÂçµÄºËÐÄÄ £¿é£¬Æä¿ÉÒÔÌṩÊðÀí·þÎñÒÔ¼°ÐÅÏ¢Éϱ¨¹¦Ð§¡£¸ÃÄ £¿éÇá±ãÁé»î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý²ÎÊýÅäÖÃÊðÀí·þÎñ£¬·¨Ê½Æô¶¯ºóÊÜ¿ØÉ豸¼´×÷ΪÊðÀí½Úµã¼ÓÈëµ½ÊðÀíÍøÂçÖУ¬ÎªºÚ¿ÍµÄ¶ñÒâ»î¶¯ÌṩÒþÄä±£»¤¡£


Mal_Proxy´æÔÚÁ½¸ö°æ±¾£¬V1°æ±¾C2Ϊcest4.elrooted.com£¬V2°æ±¾C2Ôò°üÂÞhxarasxg.hxarasxg.xyzºÍda.elrooted.com¡£ÆäÖÐV2°æ±¾Ôö¼ÓÁ˲ÎÊýÆô¶¯¡¢Socks5ЭÒéÈÏ֤ģʽ¼°UPX¿Ç£¬²¢ÐÞ¸ÄÁ˿ǵĻÃÊý£¨Êµ¼Ê»ÃÊý0xBC7A3331£©ÒÔ·´¿¹½Å±¾ÍÑ¿Ç¡£Mal_ProxyÑù±¾¾ù±»°þÀë·ûºÅÇÒδÁôÏÂÈκÎÓëÊðÀíÏà¹ØµÄ×Ö·û´®¡¢ÌØÕ÷µÈÐÅÏ¢£¬ËµÃ÷¸Ã×éÖ¯¾ß±¸Ò»¶¨µÄÄþ¾²·´¿¹¾­Ñ飬ÓÐÒâ¸ø·ÖÎöÈËÔ±ÖÆÔì¸ü¶àµÄÀ§ÄÑ£¬Ò²Ê¹µÃMal_Proxy±£³ÖÁ˷dz£ºÃµÄÃâɱÐÔ¡£


ºóÎÄÒÔV2°æ±¾ÎªÀý½øÐоßÌå·ÖÎö£¬²¢»á´©²åһЩV1°æ±¾µÄ¶Ô±È£¬Ñù±¾ÐÅÏ¢Èç±í8Ëùʾ£º


±í8£ºÑù±¾ÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.2.1 ²ÎÊýÆô¶¯Ä£Ê½


Mal_Proxy V1°æ±¾²¢²»¾ß±¸²ÎÊýÆô¶¯Ä£Ê½£¬ÆäÊðÀí¶Ë¿ÚºÅÊÇͨ¹ýʱ¼ä´Á¼ÆËã³öµÄËæ»úÖµµÃµ½£¨¶Ë¿Ú·¶Î§£º0ÖÁ65535£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ22£ºV1°æ±¾»ñÈ¡Ëæ»ú¶Ë¿Ú


Mal_Proxy V2°æ±¾ÔòÌí¼ÓÁ˲ÎÊýÆô¶¯Ä£Ê½£¬´Ó¶ø¿ÉÒÔÔ½·¢Áé»îµÄÅäÖÃÊðÀí¶Ë¿ÚÒÔ¼°Socks5ЭÒéµÄÓû§Ãû/ÃÜÂëÈÏ֤ģʽ¡£²ÎÊýÆô¶¯¹²°üÂÞÈýÖÖÃüÁî²ÎÊý£¬ÃüÁîÐÎʽΪ£º


Mal_Proxy -pport -u user -P password


ÆäÖÐ-pΪָ¶¨µÄÊðÀí°ó¶¨¶Ë¿Ú£¬-u¡¢-PΪÅäÖÃÓû§Ãû/ÃÜÂëÈÏ֤ģʽ£¬Èç²»ÅäÖÃĬÈÏΪÎÞÐèÈÏÖ¤·½Ê½¡£

V2°æ±¾ÎÞ²ÎÆô¶¯»áĬÈϰ󶨵±µØ28105¶Ë¿Ú£¬²¢ÒÔÎÞÐèÈÏÖ¤µÄ·½Ê½Ö´Ðз¨Ê½¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ23£º²ÎÊýÆô¶¯


·¨Ê½Ö´Ðкó»áÔÚ²îÒì½×¶ÎFork¶àỊ̈߳¬²¢Í¨¹ý²îÒìÏß³ÌÖ´ÐÐÏàÓ¦µÄ¹¦Ð§Ä £¿é£¬°üÂÞÐÅÏ¢Éϱ¨Ä £¿éºÍÊðÀí·þÎñÄ £¿é¡£


3.2.2 ÐÅÏ¢Éϱ¨Ä £¿é


V2°æ±¾µÄÐÅÏ¢Éϱ¨Ä £¿éͬÑùÇø·ÖÓвκÍÎÞ²ÎÁ½ÖÖģʽ£¬¾ßÌåÉϱ¨ÐÅϢͬ²ÎÊýÄÚÈÝÓйØ¡£¶øV1°æ±¾½öÓÐÒ»ÖÖÉϱ¨·½Ê½£¬¼´V2°æ±¾µÄÎÞ²Îģʽ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ24£ºV1°æ±¾ÐÅÏ¢Éϱ¨


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ25£ºV2°æ±¾Á½ÀàÐÅÏ¢Éϱ¨·½Ê½


ÎÞ²ÎÉϱ¨Êý¾Ý°ü£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ26£ºV2°æ±¾ÎÞ²ÎÉϱ¨Êý¾Ý°ü


ÓвÎÉϱ¨Êý¾Ý°ü£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ27£ºV2°æ±¾ÓвÎÉϱ¨Êý¾Ý°ü


±í9£ºV2°æ±¾Éϱ¨Êý¾Ý°ü½âÎö

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·¨Ê½Ã¿¼ä¸ô300ÃëÑ­»·Ïòhxarasxg.hxarasxg.xyz:38129·¢ËÍÐÄÌø°üÉϱ¨²ÎÊýÐÅÏ¢¡£Í¬Ê±·¨Ê½Ä£ÄâÁËÓòÃû²éѯÇëÇó£¬Í¨¹ý¹«¹²·þÎñDNS£¨8.8.8.8£©À´×ÔÐнâÎöIP£¬´Ó¶ø·ÀÖ¹hosts»òresolv.conf±»¸Ä¶¯»ò½Ù³ÖÔì³ÉµÄDNS²éѯÒì³£¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ28£ºV2°æ±¾ÐÅÏ¢Éϱ¨


3.2.3 ÊðÀí·þÎñÄ £¿é


ÊðÀíÄ £¿éÏß³ÌÊ×ÏÈ»á°ó¶¨¼àÌýµ±µØÖ¸¶¨¶Ë¿Ú£¨ÊðÀí¶Ë¿Ú£©£¬²¢Í¨¹ýlisten¡¢acceptµÈ²Ù×÷º¯ÊýÀ´´´½¨¼àÌý²¢½ÓÊÕ¿Í»§¶ËÇëÇó¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ29£º°ó¶¨¼àÌýÊðÀí¶Ë¿Ú


Ö®ºóÊðÀíÄ £¿é»á½øÒ»²½Õë¶Ô¿Í»§¶ËµÄÇëÇó½øÐÐÅжϺÍУÑ飬ÀýÈçÕë¶Ô0x05 0x01 0x00 0x03ÄÚÈݵÄУÑ飬ʵÔòΪSocks5ЭÒéÈÏÖ¤½×¶ÎµÄÎÕÊÖ¹ý³Ì£¬½øÒ»²½·ÖÎöºó¿ÉÒÔÈ·ÈϸÃÄ £¿éÊÇ»ùÓÚSocks5ЭÒéµÄ¶ñÒâÊðÀí·¨Ê½·þÎñ¶Ë¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ30£ºSocks5ЭÒéУÑé


3.2.4 Socks5ЭÒé½éÉÜ


Socks5ÊÇÒ»ÖÖÍøÂç´«ÊäЭÒ飬Ö÷ÒªÓÃÓÚ¿Í»§¶ËÓëÍâÍø·þÎñÆ÷Ö®¼äͨѶµÄÖмäͨ±¨¡£´ËЭÒé²¢²»ÂôÁ¦ÊðÀí·þÎñÆ÷µÄÊý¾Ý´«Êä»·½Ú£¬¶øÊÇÔÚ C/S Á½¶ËÕæʵ½»»¥Ö®¼ä£¬½¨Á¢ÆðÒ»Ìõ´Ó¿Í»§¶Ëµ½ÊðÀí·þÎñÆ÷µÄÊÚÐÅÁ¬½Ó¡ £¿Í»§¶ËÊ×ÏÈÐèÒªºÍ·þÎñ¶Ë½øÐÐÎÕÊÖÈÏÖ¤£¬¿ÉÒÔ½ÓÄÉÓû§Ãû/ÃÜÂëÈÏÖ¤»òÕßÎÞÐèÈÏÖ¤·½Ê½£¬ÎÕÊÖÀֳɺ󼴿ɽøÈëÊý¾Ý´«Êä½×¶Î£¬Ð­ÒéÔ­ÀíÈçͼ31Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ31£ºSocks5ЭÒéÔ­Àí


ÒÔij´Îͨ¹ýSocks5ÊðÀí´«ÊäµÄ¹¥»÷Ö¸ÁîΪÀý£¬ÔÚÒѾ­½èÖúÊðÀíЭÒ齨Á¢Á¬½ÓµÄÇé¿öÏ£¬C&CÏ·¢µÄ¹¥»÷Ö¸Áî¾­ÊðÀíÍøÂ磨54.188.198.118:9090£©ÖÐתºó´«Êäµ½Bot£¬´Ëʱ²¶×½µÄÁ÷Á¿ÊÇÎÞ·¨»ñÈ¡µ½ÕæʵC&CµØÖ·µÄ£¬ÔÚÒ»¶¨Ë®Æ½ÉÏ¿ÉÒÔµ½´ïÒþ²ØC&CµÄÄ¿µÄ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ32£ºÊðÀí´«Êä¹¥»÷Ö¸ÁîÁ÷Á¿


´ÓÁíÒ»¸ö½Ç¶È¿¼ÂÇ£¬Socks5ЭÒéËäÈ»ÔÚ´«Êä½×¶Î¾ßÓÐÒþ²ØC&CµÄЧ¹û£¬µ«Æä×÷Ϊ͸Ã÷ÊðÀí²¢²»¾ß±¸¼ÓÃܹ¦Ð§£¬ÈÏÖ¤ºÍÁ¬½Ó½×¶ÎÒ²²¢²»Äþ¾²¡£Èç¹ûÄܹ»Ðá̽ЭÉÌÎÕÊֽ׶εÄÊý¾ÝÁ÷Á¿£¬ÒÀÈ»Äܹ»½âÎö²¢»ñÈ¡µ½Ñù±¾Á¬½ÓµÄÕæʵC&C¡£»ùÓÚÕâЩԭÒò£¬Ò»Ð©ºÚ¿Í»¹»á½øÒ»²½ÀûÓÃTor ÍøÂçÀ´¼ÓÇ¿ÒþÄäÐÔ£¬ÓÉÓÚTorÍøÂçÿһÌõͨÐÅÁ´Â·¶¼ÓÉÈô¸ÉËæ»úÑ¡È¡µÄTor½Úµã×é³É£¬ÇÒͨÐÅÊý¾Ý½øÐÐÁ˶à²ã¼ÓÃÜ£¬¼´Ê¹»ñÈ¡µ½Tor C&CÒ²ÄÑÒÔËÝÔ´µ½Òþ²ØµÄÕæʵ·þÎñÆ÷£¬ËùÒÔÔÚÒþÄäÐÔ·½ÃæTorÍøÂçÊǸüºÃµÄÑ¡Ôñ¡£ËäÈ»TorÍøÂçÒ²ÓÐÆä벡£¬ÓÉÓÚÁ¬½ÓµÄÅÓ´óÐÔ£¬TorÍøÂçµÄ´«ÊäËÙÂʺÍÀÖ³ÉÂÊÍùÍùÄÑÒÔ±£Ö¤¡£×ۺ϶øÑÔ£¬¿¼Âǵ½ÏÖʵÇé¿öÖмàÌýÊÜ¿Ø·þÎñÆ÷ÊðÀí¿Í»§¶Ëµ½ÊðÀí·þÎñÆ÷µÄÈ«²¿Á÷Á¿ÊǷdz£À§ÄѵÄ£¬ËùÒÔÎÞÂÛÊÇÆÕͨÊðÀíÍøÂ磬»¹ÊǽøÒ»²½Ê¹ÓÃTorÍøÂ綼Äܹ»ÔÚÒ»¶¨Ë®Æ½ÉÏΪ½©Ê¬ÍøÂçÌṩ¸»×ãµÄÒþÄä±£»¤¡£


3.3LeeHozer·ÖÎö


LeeHozerÊÇÒ»Àà½èÖúSocks5ЭÒéÓëTor C&CͨÐŵÄÐÂÐͽ©Ê¬¼Ò×壬ÆäÉè¼ÆÁËÏà¶ÔÑϽ÷¶øÅÓ´óµÄͨÐÅЭÒé¡£ÓÉÓÚÑù±¾ÏÂÔصØÖ·(http://exec.elrooted.com/uc/i686)ÓëMal_ProxyC&C(cest4.elrooted.com)ʹÓÃÁËÏàͬµÄ¶þ¼¶ÓòÃû£¬ÇÒͬÆÚÁ½ÀàÑù±¾¾ù¸üеü´úÁ˲ÎÊýÆô¶¯µÄа汾£¬ÎÒÃÇÈÏΪ¶þÕßÓÐ׎ÏÇ¿µÄ¹ØÁªÐÔ¡£ÏÂÎÄÒÔV3°æ±¾ÎªÀý½øÐзÖÎö£¬²¢¶ÔÆä²ÎÊýÆô¶¯¡¢É¨ÃèÄ £¿é¡¢¿ØÖÆÖ¸ÁîµÈ¹¦Ð§µÄ¸üÐÂÉý¼¶Çé¿ö½øÐÐ˵Ã÷¡£


±í10£ºÑù±¾ÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


LeetHozerµÄ¹¥»÷Ä¿±êÖ÷ÒªÊÇÕë¶ÔIOTÉ豸£¬Ò»µ©É豸ÖØÆô£¬ÆäÄÚ´æÖеÄBot·¨Ê½Ò²»áËæÖ®Ïûʧ¡£ËùÒÔLeetHozer»áͨ¹ýÏòwatchdog£¨¿´ÃŹ·£©·¢ËÍ0x80045704À´½ûÓÃwatchdog¹¦Ð§£¬´Ó¶ø·ÀÖ¹É豸ÖØÆô¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ33£º½ûÓÃwatchdog


ͬʱ·¨Ê½»áÔÚconsoleÖÐÊä³ö/bin/sh: ./filename: not foundÃÔ»óÓû§£¬Ö®ºóÖ´Ðж˿ÚɨÃèÉϱ¨£¬Ð­ÒéУÑéÉÏÏߺ͹¥»÷Ä £¿éµÈ¹¦Ð§¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ34£ºconsoleÊä³ö


3.3.1 Ãô¸ÐÐÅÏ¢¼ÓÃÜ


LeetHozer½ÓÄÉÁË×Ô½ç˵µÄËã·¨¼ÓÃÜ×ÊÔ´ÐÅÏ¢£¬¼ÓÃÜÃÜԿΪqE6MGAbI¡£Ïà¹ØËã·¨Èçͼ35Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ35£º¼ÓÃÜËã·¨


½âÃܺóµÄ×ÊÔ´ÐÅÏ¢Èç±í11Ëùʾ£º


±í11£º½âÃÜ×ÊÔ´ÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.3.2 ¶Ë¿ÚɨÃèºÍÐÅÏ¢Éϱ¨


LeeHozer¸´ÓÃÁËMiraiµÄɨÃèÐÎʽ£¬ÈçɨÃè²¢µÇ½ÀֳɺóÔòÉϱ¨É豸ÐÅÏ¢£¬ÇÒ²îÒì°æ±¾¾ßÓвîÒìµÄɨÃèģʽ¡£


±í12£ºÉ¨Ãèģʽ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


V2°æ±¾É¨Ãè9530¶Ë¿Ú£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ36£º9530¶Ë¿ÚɨÃè


V3°æ±¾ÔòÓÐËù²îÒ죬Ïà½ÏÓÚ֮ǰµÄ°æ±¾£¬V3°æ±¾Ôö¼ÓÁ˲ÎÊýÆô¶¯ÅäÖá£Èç¹ûÎÞ²ÎÖ´ÐÐÑù±¾£¬Ä¬Èϲ»»áÖ´ÐÐɨÃ蹦Ч£»¶øÈç¹ûÆô¶¯·¨Ê½Ê±Ìí¼Ótelnet²ÎÊýÔò»á½øÐÐɨÃè²Ù×÷£¨Èç¡°./samples telnet¡±£©


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ37£º23/26¶Ë¿ÚɨÃè


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ38£ºÉϱ¨Reporter


3.3.3 ͨÐÅЭÒé¼°¹¥»÷Ä £¿é


LeeHozer½¨Á¢Í¨ÐŵĹý³Ì½ÏΪÅÓ´ó£¬Ê×ÏÈÆä»áͨ¹ýSocks5ЭÒéÁ¬½ÓÊðÀíÍøÂ磬´Ó¶ø½øÒ»²½ÓëTor C&C½¨Á¢Á¬½Ó£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ39£ºSocks5ЭÒé½»»¥


Èç¹ûµ±Ç°SocksÊðÀíÁ¬½ÓʧЧ£¬·¨Ê½»áËæ»ú´ÓÄÚÖõÄ107¸öÊðÀíÖÐÑ¡ÔñÆäÒ»²¢ÖØн¨Á¢ÊðÀíÁ¬½Ó£¬ÄÚÖÃÊðÀíÁбíÈçÏ£º


±í13£ºÊðÀíÁбí

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÕâÅúÊðÀí×ÊÔ´ºÜÓпÉÄܾÍÊÇͨ¹ýMal_Proxy½¨Á¢£¬ËäÈ»£¬ÆäÖÐÒ²¿ÉÄÜ°üÂÞһЩ¹²Ïí×ÊÔ´ºÍÃâ·Ñ½Úµã¡£

µ±LeeHozerÀֳɺÍC&C½¨Á¢Á¬½Óºó£¬»¹Ðè¾­¹ýÁ½ÂÖУÑé½»»¥²ÅÆøÕæÕýʵÏÖÉÏÏß¡£


µÚÒ»ÂÖУÑ飺

Client->Server£º

УÑéÇëÇó°ü³¤¶ÈΪ255×Ö½Ú£¬µ«Ö»ÓÐÇ°32×Ö½ÚΪÓÐЧÄÚÈÝ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ40£ºµÚÒ»ÂÖУÑéÇëÇó°ü


±í14£ºµÚÒ»ÂÖУÑéÇëÇó°ü½âÎö

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÆËãУÑéÖµµÄËã·¨Èçͼ41Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ41£º¼ÆËãУÑéÖµ


Server->Client:

¿ØÖƶ˻ذüͬÑùΪ255×Ö½Ú£¬Ç°32×Ö½ÚÓÐЧ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ42£ºµÚÒ»ÂÖ¿ØÖƶ˻ذü


¿Í»§¶Ë»áÕë¶Ô»Ø°üµÄÁ½¸ö±ê־λ½øÐÐУÑ飬·Ö±ðΪ0x70f1ºÍ0x4819£¬Ð£Ñéͨ¹ýºó¼ÌÐø½øÐеڶþÂÖ½»»¥¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ43£º±ê־λУÑé


µÚ¶þÂÖУÑ飺

Client->Server£º

¿Í»§¶ËУÑéÇëÇó°üÈÔΪ255×Ö½Ú£¬Ç°32×Ö½ÚÓÐЧ£¬²¿ÃÅÊý¾ÝÔ´×ÔµÚÒ»ÂÖ·þÎñ¶ËµÄ»Ø°ü¡£


ͼ44£ºµÚ¶þÂÖУÑéÇëÇó°ü


±í15£ºµÚ¶þÂÖУÑéÇëÇó°ü½âÎö


Server->Client:

µÚ¶þÂֻذüÓëµÚÒ»ÂֻذüÏàËÆ£¬×ܳ¤255×Ö½Ú£¬Ç°32×Ö½ÚÓÐЧ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ45£ºµÚ¶þÂÖ¿ØÖƶ˻ذü


¿Í»§¶Ë¶Ô0x70F2ºÍ0x2775Á½¸ö±ê־λУÑéÀֳɺ󣬽©Ê¬µÄÉÏÏß¹ý³Ì²ÅËãÍê³É£¬Ö®ºó½©Ê¬ÆÚ´ý¿ØÖƶËÏ·¢Ö¸ÁÆäÖÐÖ¸ÁîµÄÊ××Ö½ÚÖ¸¶¨ÁË¿ØÖÆÖ¸ÁîÀàÐÍ¡£


¿ØÖÆÖ¸Áî¹²°üÂÞÈýÀࣺ


±í16£º¿ØÖÆÖ¸ÁîÀàÐÍ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


0x00 ÐÄÌø°ü£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ46£ºÐÄÌø°ü


0x01 ·¢ËͱêʶÐÅÏ¢£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ47£º·¢ËͱêʶÐÅÏ¢


ÈçÊ××Ö½ÚΪÆäËüÖµ£¬Ôò»á½âÎö¾ßÌåµÄÖ¸ÁЧ£¬LeetHozer²îÒì°æ±¾µÄ¹¦Ð§Ö¸ÁîÈç±í18Ëùʾ£º


±í17£º¹¦Ð§Ö¸Áî±í

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ48£ºV3°æ±¾¹¥»÷Ö¸ÁîÅжÏ


ÎÒÃÇÊӲ쵽£¬½üÆÚLeeHozerÈÔÔÚÁ¬ÐøÕ¹¿ª¹¥»÷»î¶¯£¬¹¥»÷Ö¸ÁîÈçͼ48Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ49£º¹¥»÷Ö¸ÁîÊý¾Ý°ü


±í18£º¹¥»÷Ö¸ÁîÊý¾Ý½âÎö

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ËÝÔ´Óë¹ØÁª


ÖµµÃ×¢ÒâµÄÊÇ£¬LeeHozerÔÚ´úÂëÖжദʹÓÃÁËÓëvbrxmrÏà¹ØµÄ×Ö·û´®£¬ÀýÈç¡®GET /vbrxmr/i586 HTTP/1.0¡¯¡¢¡®/bin/busybox VBRXMR¡¯£¬ÒÔ¼°C2£¨vbrxmrhrjnnouvjf.onion£©µÈ¡£ÓëÖ®Ïà¹ØµÄ£¬Hoaxcalls(XTC)½©Ê¬ÍøÂçÔøʹÓÃcbc.vbrxmr.pw×÷ΪC2£¬´úÂëÖÐÒ²·ºÆð¹ývbrxmr×Ö·û´®£¬ÇÒͬÑù¿ÉÒÔ½èÖúÊðÀíÍøÂçͨÐÅ£¨¾ß±¸Fastflux¹¦Ð§£©£¬VbrxmrµÄƵ·±·ºÆðÒ²²»µÃ²»ÈÃÈË»³ÒÉÁ½ÕßÖ®¼ä´æÔÚÒ»¶¨µÄ¹ØÁª¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ50£ºHoaxcalls×Ö·û´®


´ËÍ⣬ͨ¹ýËÑË÷LeeHozerµÄ¼ÓÃÜÃÜÔ¿qE6MGAbI£¬»¹·¢ÏÖÁËÁíÒ»ÖÖʹÓÃÊðÀíͨÐŵÄÑù±¾£¬ÇÒÆäʹÓõÄÊðÀíÁбíÒ²ºÍLeeHozerÓв¿ÃÅÖغÏ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ51£ºÄ³ÊðÀíÑù±¾×Ö·û´®


ÀàËƵĹØÁª±íÃ÷ÕâЩʹÓÃÊðÀíµÄ½©Ê¬ÍøÂç¿ØÖÆÕß¼ä»ò¶à»òÉÙ´æÔÚ×ÅһЩÁªÏµ£¬ºÚ¿ÍÃǺܿÉÄÜÔÚµØÏÂÂÛ̳½»Ò×ÊðÀí×ÊÔ´¡¢¹²Ïí´úÂë»òÊÇͨ¹ý´úÂëÄ£·ÂÀ´ÃÔ»óÑо¿ÈËÔ±¡£


ËÄ¡¢×ܽá


Ëæ×ÅÎïÁªÍøʱ´úµÄ¿ìËÙÉú³¤£¬Äþ¾²·´¿¹Ò²ÔÚ²»Í£Éý¼¶ºÍ½ø»¯¡ £¿ÉÒÔ¿´µ½£¬Ô½À´Ô½¶àµÄ¹¥»÷ÕßʵÑé´Ó¸ü¶àµÄά¶È¿ªÕ¹¹¥»÷»î¶¯ºÍÄþ¾²·´¿¹¡£Ò»·½Ã棬ԽÀ´Ô½¶àµÄ¹¥»÷Õß¿ªÊ¼½èÖúÊðÀíÍøÂçÀ´¼ÓÇ¿ÒþÄäÄþ¾²£¬ÊðÀí×ÊÔ´×÷ΪÒþÄäC&CµÄÇ°ÖÃÍøÂçÎÞÒÉÊÇÒ»¸ö¾Þ´óµÄÍþвºÍÒþ»¼£»ÁíÒ»·½Ã棬Ҳ·ºÆðÁËÀûÓöñÒâÑù±¾ÊµÏÖÓÕ²¶¼à²âºÍ·´Ì½²âÄÜÁ¦µÄÓ¦ÓÃÐÂ˼·£¬ÕâЩ¶¼ÊиøÎïÁªÍøÉ豸µÄÄþ¾²·À»¤ºÍÑо¿ÊÂÇé´øÀ´¸ü¶àµÄ±ä»¯£¬ºóÐøÎÒÃÇÒ²»á½øÐÐÁ¬ÐøµÄ¹Ø×¢ºÍ×·×Ù¡£


IOCÐÅÏ¢


Moobot£º


URL :

http://exec.elrooted.com/ab/i686

http://conn.elrooted.com/li/arm

http://91.92.66.87:80/420/adb/x86

http://185.163.46.6/a/x86_64

http://5.252.179.60/b/x86_64

http://185.172.110.224/ab/i586


C2£º

proxy.2u0apcm6ylhdy7s.com

abcdefg.elrooted.com

park.elrooted.com

frsaxhta.elrooted.com

cccc.elrooted.com

205.185.114.231

185.172.110.224


Reporter IP£º

gfedcba.elrooted.com

hello.elrooted.com


HASH£º

1a64cd13d9c71542ce60183356a615505f10ddc192eded5fce0f0075f3ad7648

ca3889994301f28baa791f4ef1aa473b0bc6e975cda703195787872795171869

e9a7aab3ab25c0a091d98d3ae4a313fba3b3bd0588bfe8e3624ec016bc11f02e

2516bdc3ae3818e30e1145f75811937e29ce10f94722c6da1ea7c28f4c0bc3dc

a6e18135a2afcd96957bff63388501465f5a1203b2d22ee0f1074661e286d9e3

59b1ca2d47af1d5b60b84c3a9d6a64a09b7340864b9e90247466d7f91ed53b84

d5d5488ae9c80558cc4634ce6d51837d82347fd48d1a665e606dcfbfdf638b7b


Mal_Proxy£º


URL £º

http://proxy.2u0apcm6ylhdy7s.com/b/x86_64

http://proxy.2u0apcm6ylhdy7s.com/b/armv7l


C2£º

hxarasxg.hxarasxg.xyz

cest4.elrooted.com

da.elrooted.com

185.172.110.240


HASH£º

a67f79c7ae6b1177309cb328d3ec93ec91960edf457a4f5a74120baaf80139ee       V2

04114bd136941811e355df28e9b2eeaa941a04b61b185fd214a4c54daa171e1c     V2

80f1973b82cbea485f27eb8c44983c565701fdc4e6d3e994ed57bf57a66b9c81     V2

f91427e74a84c34d329116443fa1c89c63dab57e01129345a9f9ed364533dd49     V1

4ed3c601022b4d8c1478521241b847dcacecd837bc75547f3a378ee9d5b9e15f    V1

b41de82ea89e2ceedda5b4a856c273c4ce06429d876ee4a05ee9a2423741461f      V1


LeeHozer£º


C2£º

vbrxmrhrjnnouvjf.onion:31337

37.49.226.171:31337

w6gr2jqz3eag4ksi.onion:31337


Reporter IP:

report.infidel.ml:9814


HASH£º

84efc5ce8a0729b1248b5f7a43ddf371f517ac0a0eea0a5b0674ce195be61b8e  v3

ca8095af62b836f3ddd12007bc8cb67cdd39266c3d40179691f9ee1ca94e9428 v2

1c5349696c04dfa8e0f458ad1d9aa360f4768b21d3dd83fb98d935691b1b2a88  v1


²Î¿¼ÎÄÏ×£º


1.https://blog.radware.com/security/botnets/2020/05/whos-viktor-tracking-down-the-xtc-polaris-botnets/

2.https://blog.netlab.360.com/the-leethozer-botnet-en/

3.https://www.exploit-db.com/exploits/48225

4.https://blog.netlab.360.com/multiple-botnets-are-spreading-using-lilin-dvr-0-day/

5.https://habr.com/en/post/486856/


Ô­ÎÄÀ´Ô´£ºÍøÂçÄþ¾²Ó¦¼±¼¼Êõ¹ú¼Ò¹¤³ÌʵÑéÊÒ


±¾³ÂËßÓÉCNCERTÎïÁªÍøÄþ¾²Ñо¿ÍŶÓÓ붫ɭƽ̨¼¯ÍÅADLab¹¥·ÀʵÑéÊÒÁªºÏÐû²¼


¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´800Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾