Mbedbot£ºTLS¼ÓÃܵĺóÃÅ»¯½©Ê¬ÍøÂç
Ðû²¼Ê±¼ä 2023-09-27¶«Éƽ̨Óë¹ãÖÝ´óѧÍø°²Ñ§Ôº·¢ÏÖÁËÒ»¸öºóÃÅ»¯µÄÎïÁªÍøDDoS½©Ê¬ÍøÂ磬²¢½«ÆäÃüÃûΪMbedbot¡£±¾ÎĽ«´ÓÆäÖ´ÐÐÁ÷³Ì¡¢Í¨ÐÅÐÒé¡¢¿ØÖÆÃüÁî¼°ºóÃŵȼ¼Êõ·ÖÎö½Ç¶ÈÈëÊÖ£¬¶Ô¸Ã½©Ê¬ÍøÂç½øÐÐÈ«Ãæ½éÉÜ£¬ÒÔ×÷Ϊ¸÷ÐÐÒµ¼°Ïà¹ØÆóÒµÖƶ¨ÍøÂçÄþ¾²¼ÆıµÄ²Î¿¼¡£
2023Äê7Ô³õ£¬¶«Éƽ̨ÔÚ¼ÓÈë¹ú¼ÒÖصãÑз¢¼Æ»®ÏîÄ¿¡°´ó¹æÄ£Òì¹¹ÎïÁªÍøÍþв¿É¿Ø²¶×½Óë·ÖÎö¼¼Êõ£¨2022YFB3104100£©¡±µÄÑо¿¹ý³ÌÖУ¬·¢ÏÖÁËÒ»¸öºóÃÅ»¯µÄÎïÁªÍøDDoS½©Ê¬ÍøÂç¼Ò×å¡£
´úÂë½á¹¹ÉÏ£¬¸Ã½©Ê¬ÍøÂ縴ÓÃÁËMiraiµÄDDoS¹¥»÷Ïà¹Ø´úÂ룬²¢ÔÚÆä»ù´¡ÉÏÔö¼Óhttps ddosÒÔ¼°tcp syn¹¥»÷ÄÜÁ¦¡£ÓëÆäËü»ùÓÚMiraiÔ´ÂëµÄÖ÷Á÷½©Ê¬ÍøÂç²îÒìµÄÊÇ£¬³ýDDoS¹¦Ð§Ö®Í⣬¸Ã½©Ê¬ÍøÂ绹ʵÏÖÁËÔ¶³ÌÎļþ¹ÜÀí¡¢½ø³Ì²Ù×÷µÈÖî¶àºóÃŹ¦Ð§¡£
¶øÇÒ£¬ÆäʹÓÃtlsÐÒéÓëC2½øÐмÓÃÜͨÐÅ¡£ÒòÆäËùÓÃtlsÀà¿âΪmbedtls£¬ËùÒÔÎÒÃǰѴ˽©Ê¬ÍøÂç¼Ò×åÃüÃûΪMbedbot¡£
¼¼Êõ·ÖÎö
ĿǰΪֹ£¬ÎÒÃÇÔÝʱֻ²¶×½µ½arm4¼Ü¹¹µÄÑù±¾£¬Î´·¢ÏÖÆäËü¼Ü¹¹µÄÑù±¾¡£MbedbotÕûÌå´úÂëºÜ¼ò½à£¬Ã»ÓÐÌ«¶à»¨Éڵĵط½£¬Íê³É³£¼û²Ù×÷Á÷³Ìºó£¬¼´½øÈëºÍC2µÄ½»»¥Í¨ÐÅ¡£
1¡¢Ö´ÐÐÁ÷³Ì
ÔËÐк󣬴òÓ¡×Ö·û´®"listening tun0"£¬²¢Í¨¹ý¼àÌý31212¶Ë¿Ú£¬ÊµÏÖµ¥Ò»ÊµÀýÔËÐС£Ö®ºóͨ¹ýÒì»ò½âÃܳö×Ö·û´®×ÊÔ´£¬ÓëMiraiµÄ×Ö·û´®¸ß¶ÈÖغϣº
Ëæºó£¬³õʼ»¯DDoS¹¥»÷ÏòÁ¿£¬¹²Ö§³Ö11¸öDDoS¹¥»÷·½Ê½¡£³õʼ»¯´úÂëÒÔ¼°¸÷¸öDDoS´úÂëÍêÈ«¸´ÓÃ×ÔMirai£º
µ«Mbedbot±ÈMirai¶àÒ»¸öÕë¶ÔhttpsÐÒéµÄDDoS¹¥»÷ÀàÐÍattack_app_https£¬Í¬ÑùʹÓÃmbedtls¿â£¬ÕâÒ²ÊÇÊ״η¢ÏÖÖ§³ÖhttpsÐÒéµÄDDoS¹¥»÷¡£
Íê³ÉÉÏÊö²Ù×÷ºó£¬½øÈëºÍC2½»»¥Í¨ÐŵÄÑ»·º¯Êý¡£ÔÚ½»»¥º¯ÊýÀÊ×ÏÈͨ¹ýÒì»ò½âÃܳöC2µØÖ·£¬²¢Ê¹ÓÃtlsÐÒéºÍC2½¨Á¢Í¨ÐÅ¡£tlsÀà¿âΪmbedtls£¬ÆäÇ°ÉíÊÇPolarSLL£¬ÏÖÒѱ»ARM¹«Ë¾ÊÕ¹º£¬ÓÉARM¼¼ÊõÍŶÓά»¤¸üС£
ʹÓÃtls¼ÓÃÜ֮ǰÊÕ¼¯µÄϵͳÐÅÏ¢£¬·¢Ë͸øC2£¬ËæºóÆÚ´ýÖ´ÐÐC2Ï·¢µÄÖÖÖÖÃüÁî¡£
2¡¢Í¨ÐÅÐÒé
MbedbotµÄͨÐÅÐÒéÏà¶Ô¼òµ¥¡£ÔÚºÍC2½¨Á¢tlsͨÐÅÖ®ºó£¬ÏÈÏòC2·¢ËÍ4×Ö½ÚµÄÉÏÏßÊý¾Ý³¤¶È£¬2×Ö½ÚµÄÊý¾ÝÀàÐÍ"\xFF\xFF"£¬ÔÙ·¢ËÍÊܺ¦ÏµÍ³ÐÅÏ¢£¨ÉÏÏßÊý¾Ý£©¡£
¿É¼û£¬MbedbotÊÕ¼¯µÄϵͳÐÅÏ¢ºÜÈ«Ãæ¡£ÆäÖУº
huuidÊÇÓ²±àÂëµÄ×Ö·û´®£¬Ö¸Ê¾C2·þÎñÆ÷£¨host£©Éí·Ýid;
buuidÔòËæ»úÉú³É£¬ÌåÏÖÊܺ¦Ö÷»ú£¨bot£©Éí·Ýid£»
versionÓÃÓÚָʾ°æ±¾ÐÅÏ¢¡£
·¢ËÍÉÏÏßÊý¾ÝÖ®ºó£¬Ö´ÐÐselectº¯Êý£¬ÊµÑé½ÓÊÕC2Ï·¢µÄÖÖÖÖÃüÁî¡£ÆäÖУ¬Mbedbotÿ15·ÖÖÓ»áÏòC2·¢ËÍÒ»´ÎÓ²±àÂëµÄ¡°ÐÄÌø¡°°ü£¬ÓÃÒÔ¸üÐÂÖ÷»ú´æ»î״̬¡£·¢ËÍÐÄÌø°üÈçÏ£º
ͬʱC2·µ»ØµÄ17×Ö½ÚÐÄÌø°üÊý¾Ý£¬ÈçÏ£º
ÆäÖÐÇ°16×Ö½Ú"\xD9\x01....\x3B\x3F"ÊÇËæ»úÉú³ÉµÄSessionID£¬µÚ16×Ö½ÚÊÇÃüÁîÂ룬\xFFÌåÏÖÊÇÐÄÌø°üÊý¾Ý¡£
3¡¢¿ØÖÆÃüÁî&ºóÃÅ
MbedbotʵÏÖÁ˺ܶàºóÃŹ¦Ð§£¬°üÂÞÎļþÀà(´´½¨¶ÁÈ¡ÉÏ´«ÏÂÔØÖ´ÐÐ)£¬Ö´ÐÐshell½ø³Ì£¬DDoS¹¥»÷£¬½áÊøÖ¸¶¨½ø³Ì£¬ÖØÖÃC2·þÎñÆ÷£¬Í˳ö×ÔÉí½ø³ÌµÈ¡£
MbedbotµÄÃüÁî¸ñʽ±ÈÁ¦¼òµ¥£¬Ç°16×Ö½ÚÊÇC2Ëæ»úÉú³ÉSessionID£¬Í¬Ò»Í¨ÐŻỰÊÇΨһµÄ¡£µÚ16×Ö½ÚÊÇÃüÁîÂ룬ÆäºóÊÇÃüÁî²ÎÊý¡£
ÒÔÈçÏÂÃüÁîΪÀý£º
FC12¡57D2£¬16×Ö½ÚSessionID£»
0x0F£¬1×Ö½ÚÃüÁîÂ룬´ËÃüÁîÓÃÀ´ÉèÖò¢ÖØÐÂÁ¬½ÓеÄC2·þÎñÆ÷¡£
fakembedbotc2.com£¬ÃüÁî²ÎÊý£¬½«C2·þÎñÆ÷ÖØÉèΪ´Ë¡£
Ëæºó£¬Êܺ¦Ö÷»úʵÑé½âÎö²¢Á¬½Ófakembedbotc2.com£º
ÒÔÏÂÊǸ÷ÃüÁîÂë¼°Æä¶ÔÓ¦ºóÃŹ¦Ð§£º
½á Óï
MbedbotÍêÕû¸´ÓÃÁËMiraiµÄDDoS´úÂ룬²¢ÔÚÆä»ù´¡ÉÏÐÂÔöÁ½¸ö¡°×ÔÑС°µÄtcp syn¹¥»÷ÒÔ¼°https ddos¹¥»÷ÄÜÁ¦¡£¶øÇÒ£¬Õë¶Ô×ÔÉíµÄºóÃŹ¦Ð§½øÐÐÁ˸»ºñ£¬ÒÔʵÑé¼ÓÇ¿¶ÔbotÖ÷»úµÄ¿ØÖÆÄÜÁ¦¡£
´ËÍ⣬Ïà½ÏÓÚÆäËü½©Ê¬ÍøÂ磬MbedbotÖ±½ÓʹÓÃtls¼ÓÃܺÍC2µÄͨÐÅ£¬¾¡¹ÜͨÐÅÐÒé×Ô¼º²¢²»ÅӴ󣬵«ÔÚtls¼Ó³ÖÏ£¬Äܹ»ÓÐЧµÄ¹æ±ÜͨÀýÌØÕ÷Ö¸ÎƼì²â¡£
IOC
66.42.52.39:443
92.38.135.146:77
dftiscasdwe.w8510.com:443