ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÇøµÄ¹¥»÷»î¶¯ÆÊÎö
Ðû²¼Ê±¼ä 2019-05-18½üÆÚ£¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ADLab¼à²âµ½Ò»ÅúÒÉËÆÕë¶ÔÎ÷°àÑÀÓïµØÇøµÄÕþ¸®»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿·ÖµÄ¶¨Ïò¹¥»÷»î¶¯£¬£¬£¬£¬£¬ºÚ¿Í×é֯ͨ¹ý½á¹¹¶ñÒâOffice WordÎĵµ²¢ÅäºÏÓã²æÓʼþÌᳫ¶¨Ïò¹¥»÷£¬£¬£¬£¬£¬ÒÔ¡°¼òÀú¸üС±×÷ΪÓÕ¶üÎĵµÏò¹¥»÷Ä¿µÄÖ²ÈëÌØ¹¤Ä¾Âí£¬£¬£¬£¬£¬´ÓÊÂÇé±¨ÍøÂç¡¢Ô¶¿Ø¼àÊÓ¼°ÏµÍ³ÆÆËðµÈ¶ñÒâÐж¯¡£¡£¡£¡£ÎÒÃǽ«ÍÁ¶úÆäºÚ¿ÍµÄ´Ë´Î¹¥»÷Ðж¯³ÆÎª¡°ºÚʨÐж¯¡±¡£¡£¡£¡£
ͨ¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓÃЧÀÍÆ÷Ïà¹ØÐÅÏ¢µÄÆÊÎöºÍ×·×Ù£¬£¬£¬£¬£¬È·¶¨¸Ã´Î¹¥»÷ȪԴÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¡£¡£¡£¸Ã×éÖ¯ÊÇÒ»¸öÃñ×åÖ÷ÒåÉ«²ÊºÜÊÇō֨µÄºÚ¿Í×éÖ¯£¬£¬£¬£¬£¬Ôø¹¥ÏÝÆäËû¹ú¼ÒµÄ3ǧ¶à¸öÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂÆä×éÖ¯µÄÃû³Æ£¬£¬£¬£¬£¬ËæºóÏûÊÅÁ˶àÄê¡£¡£¡£¡£ ÏÖÔÚͨ¹ýÎÒÃǶԡ±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯¼£Ï󡣡£¡£¡£±¾´Î¹¥»÷Àú³ÌÖУ¬£¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯½ÓÄÉÉøÍ¸Êֶι¥Ïݶą̀ЧÀÍÆ÷²¢½«Æä×÷Ϊ´æ·Å¹¥»÷´úÂëµÄÌø°å¡£¡£¡£¡£
1ÍþвÆÊÎö
1.1 ¹¥»÷Ä¿µÄÆÊÎö
´ÓÏÖÔÚËù»ñÈ¡µÄ¹¥»÷Ñù±¾ºÍÍþвÇ鱨£¬£¬£¬£¬£¬¿ÉÒÔ¿´³ö±¾´Î¹¥»÷»î¶¯²¢Ã»Óдó¹æÄ£µÄ¾ÙÐУ¬£¬£¬£¬£¬ÏÖÔÚ»¹´¦ÓÚ¹¥»÷ÊÔ̽½×¶Î£¬£¬£¬£¬£¬¿ÉÊÇ´ÓÆäͶ·ÅµÄÓÕ¶üÎĵµ¿ÉÒÔ¼òÆÓ¼òÖ±¶¨Æä¹¥»÷Ä¿µÄËø¶¨ÔÚÎ÷°àÑÀÓïϵµÄ¹ú¼Ò¡£¡£¡£¡£ÕâЩÓÕ¶üÎĵµÐÎÈ磺¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±£¨¼òÀú¸üРº£Ã·°¢ÀïÑÇ˹£©¡¢¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±(¼òÀú¸üРµ¤Äá¶û°ÂµÙ×È)¡¢¡°Michelle Flores - Curriculum Actualizado.doc¡±(Ã×Ъ¶û¸¥ÂåÀ×˹-¼òÀú¸üÐÂ)¡¢¡°Jose Trujillo.doc¡±(ºÎÈûÌØÂ³Ï£ÂÔ)µÈµÈ£¬£¬£¬£¬£¬ËüÃǾù½ÓÄÉÎ÷°àÑÀÓïÀ´½á¹¹Ò»¸ö´ø¶ñÒâºê´úÂëµÄ¼òÀúÎļþ¡£¡£¡£¡£ÒÔ´ËÀ´¶ÔÄ¿µÄÈËÁ¦²¿·Ö¾ÙÐй¥»÷£¬£¬£¬£¬£¬ÒÔÓÕʹÏà¹ØÖ°Ô±Ö´ÐжñÒâ´úÂë½ø¶ø´ÓÊÂÌØ¹¤»î¶¯¡£¡£¡£¡£
ÔÚÎÒÃÇÆÊÎöÕâÅúÓÕ¶üÎĵµÊ±£¬£¬£¬£¬£¬»¹·¢Ã÷Ò»¸öÓÐȤµÄÕ÷Ï󣬣¬£¬£¬£¬ÄǾÍÊÇÐí¶àÓÕ¶üÎĵµÖаüÀ¨ÁËÎĵµ×÷ÕßÐÅÏ¢ºÍ×îºóÒ»´ÎÉúÑÄÕßÐÅÏ¢£¬£¬£¬£¬£¬²¢ÇÒÕâЩÐÅÏ¢¾ùΪÀàËÆ²ÆÎñ²¿¡¢Ðŷþ֡¢SCG£¨Southern Connecticut Gas£©µÈµÈÓëÕþ¸®²¿·ÖÏà¹ØµÄÐÅÏ¢¡£¡£¡£¡£Í¨¹ýÎÒÃÇÏÖʵ²âÊÔ·¢Ã÷£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢¾ù»áÔÚÎĵµÐ޸ĺóÄð³ÉÄ¿½ñ»á¼ûÕßofficeÉϰ¶ÕË»§Ãû»òÕßÖ÷»úÃû£¬£¬£¬£¬£¬²¢ÇÒÓÐÐĵÄÈË»¹¿ÉÒÔ¶ÔÆä¾ÙÐÐí§Òâ¶¨ÖÆ¡£¡£¡£¡£ÎÒÃÇѡȡ¼¸¸öµä·¶µÄÑù±¾²¢Õë¶ÔÏà¹ØÐÅÏ¢ºÍÂß¼¹ØÏµ×öÁËÈçÏÂÊáÀíºÍÍÆÂÛ£º
ÎÒÃÇͨ¹ý½¨ÉèÄÚÈÝʱ¼ä¡¢×îºóÐÞ¸Äʱ¼ä¼°¹¥»÷ÎĵµÄÚ²¿µÄÂß¼¹ØÏµÍÆÂÛ³öÏà¹Ø¼Í¼ӦΪ¹¥»÷ÕßÉúÑÄ¡£¡£¡£¡£»£»£»£»ùÓÚ×îºÏÀíÒÔ¼°×îÓпÉÄܵÄÍÆ²â£¬£¬£¬£¬£¬ÎÒÃÇÒÔΪ¹¥»÷Õß¿ÉÄÜÊÇ»ùÓÚºÚ¿Í×éÖ¯ÄÚ²¿¹æ·¶£¬£¬£¬£¬£¬½«ÎĵµµÄÏà¹ØÃû³ÆÉèÖÃΪ¹¥»÷Ä¿µÄ»òÏà¹ØÐÐÒµÐÅÏ¢£¬£¬£¬£¬£¬´Ó¶øÎ±Ôì³ÉÄÚ²¿ÈËÊ¿£¬£¬£¬£¬£¬ÔÚÒ»¶¨Ë®Æ½ÉÏÆðµ½»ìÏýÊÓÌý¡¢Òþ²Ø×ÔÉíµÄÄ¿µÄ¡£¡£¡£¡£
ÓÉ´ËÎÒÃÇ¿ÉÒÔ¿´³ö´Ë´ÎÐж¯µÄ¹¥»÷Ä¿µÄΪÎ÷°àÑÀÓïϵµØÇøµÄÕþ¸®»òÕß¹«¹²Ð§ÀͲ¿·Ö£¬£¬£¬£¬£¬ËäÈ»²¢²»É¨³ýÆäÓиü¶àµÄÄ¿µÄ£¬£¬£¬£¬£¬ÖÁÉÙ¿ÉÒԿ϶¨µÄÊÇ´Ë´ÎÐж¯ÊÇÒ»´Î´øÓÐÕþÖÎÄ¿µÄµÄ¹¥»÷»î¶¯¡£¡£¡£¡£
1.2 ºÚ¿Í×éÖ¯ÆÊÎö
ÔÚ¶ñÒâ´úÂë´æ´¢Â·¾¶µÄͬĿ¼£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ºÚ¿Í×éÖ¯ËùÁôϵÄһЩÐÅÏ¢£¬£¬£¬£¬£¬ÏÂͼΪÆäÖÐÒ»¸öÎļþ¼Í¼µÄÐÅÏ¢£º
¸ÃÎļþÖаüÀ¨ÁËһЩÉùÃ÷ÐÅÏ¢¡¢ºÚ¿Í×éÖ¯¼°ÆäÏà¹Ø³ÉÔ±£¬£¬£¬£¬£¬²¢ÇÒËù½ÓÄɵÄÓïÑÔΪÍÁ¶úÆäÓ£¬£¬£¬£¬Òò´ËÎÒÃÇÅжϸÃ×éÖ¯ÕýÊÇÒ»¾»îԾһʱµÄKingSqlZºÚ¿Í×éÖ¯¡£¡£¡£¡£¸ÃЧÀÍÆ÷ºÜÓпÉÄÜÔÚ±»ºÚ¿Í×éÖ¯¿ØÖƺó×÷ÎªÌø°å»ú»ò×ÊԴЧÀÍÆ÷¼ÌÐøÊ¹Óᣡ£¡£¡£±ðµÄͨ¹ý¶ñÒâ´úÂëÊ±ÇøÆÊÎö·¨£¬£¬£¬£¬£¬ÎÒÃǽøÒ»²½È·¶¨¸Ã´Î¹¥»÷À´×ÔÓÚÍÁ¶úÆäºÚ¿Í¡£¡£¡£¡£ÎÒÃǶÔRATÑù±¾Ö®Ç°µÄPEÎļþ¼°ÆäËûǰÆÚ¹¥»÷»·½ÚÏà¹ØµÄÑù±¾µÄ±àÒëʱ¼ä×öÁËÊ±ÇøÆÊÎö£¨ÓÉÓÚRATÑùÔÀ´×ÔÓÚÉÏÓκڿͣ¬£¬£¬£¬£¬Òò´ËÎÒÃǺöÂÔÁ˸ÃÀàÑù±¾µÄÊ±ÇøÆÊÎö£©¡£¡£¡£¡£×îºó·¢Ã÷ÕâЩ¹¥»÷Ñù±¾µÄ±àÒëʱ¼äÔÚUTCʱ¼ä21:00ÖÁ06:00Çø¼äÄÚ·ºÆðµÄƵ´Î¼«µÍ¡£¡£¡£¡£¶ø¼Ù¶¨ÒÔ24:00ÖÁ08:00×÷Ϊ˯Ãßʱ¼ä£¬£¬£¬£¬£¬¹¥»÷ÕßËù´¦µÄÊ±Çø¿ÉÄÜ»áÔÚ¶«3Çø£¨UTC+3£©Õý¸º 1 Ð¡Ê±Çø¼äÄÚ£¬£¬£¬£¬£¬¶øÍÁ¶úÆäÊ±ÇøÎª¶«ÈýÇøÕýºÃÇкϡ£¡£¡£¡£
±¾´Î¹¥»÷»î¶¯×îÏÈÓÚ2019Ä꣬£¬£¬£¬£¬½ÓÄÉ´ó×Ú¹«¹²DDNSЧÀÍ×ÓÓòÃû×÷ΪC2À´ÊµÑé¹¥»÷£¬£¬£¬£¬£¬ÕâÆäÖеÄһЩÓòÃûΪ2019ÄêÐÂ×¢²áµÄ£¬£¬£¬£¬£¬Ê¹ÓõIJ¿·ÖÓòÃûÈçÏ£º
casillas.hicam.net
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
2¹¥»÷¸ÅÊö
´Ë´ÎÊÂÎñµÄÖ÷Òª¹¥»÷»î¶¯Ê±¼äÏßÈçÏÂËùʾ:
ÆäÖУ¬£¬£¬£¬£¬ÎÒÃǶÔ2019Äê2ÔÂ7ÈÕ·¢Ã÷µÄ¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Îĵµ¾ÙÐÐÁËÏêϸµÄÆÊÎö£¬£¬£¬£¬£¬²¢Ïà¼Ì²¶»ñµ½¹ØÁªÎĵµ¡°Curriculum Vitae Actualizado Daniel Ortiz.doc¡±ºÍ¡°Michelle Flores - Curriculum Actualizado.doc/ Jose Trujillo.doc¡±¡£¡£¡£¡£
¹¥»÷ÕßʹÓÃÁËAPI¹þÏ£¡¢ÎÞÎļþ¹¥»÷¡¢WinrarSFX¡¢AutoIt¡¢C#»ìÏýºÍ¿þÀÜÀú³ÌµÈÊÖÒÕÀ´¹æ±Ü¼ì²â²¢×ÌÈÅÆÊÎöÖ°Ô±¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±ÎĵµÖ²ÈëµÄľÂíȪԴ×î³õÎÞ·¨È·ÈÏ£¬£¬£¬£¬£¬ÎÒÃÇÔÚÆäÖз¢Ã÷ÁËÌØÕ÷×Ö·û´®¡°AVE_MARIA¡±,ÆäÓëCybaze-Yoroi ZLabÑо¿Ö°Ô±ÔÚ2018Äê12ÔÂβÅû¶µÄÕë¶ÔÒâ´óÀûijÄÜÔ´ÆóÒµ¾ÙÐй¥»÷µÄ¶ñÒâÈí¼þÏàËÆ¶ÈºÜ¸ß£¬£¬£¬£¬£¬²¿·ÖÇå¾²Ñо¿Ô±ºÍ³§ÉÌÓÉÓÚûÓÐÀֳɵľÙÐÐËÝÔ´±ãÒÔ´Ë×Ö·û´®×öΪ¸ÃľÂí¼Ò×åµÄÃû³Æ¡£¡£¡£¡£¶øÎÒÃǾÓɹØÁªËÝÔ´ºÍͬԴÐÔÆÊÎöºó·¢Ã÷£¬£¬£¬£¬£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾Í¬RAT¹¤¾ß¡°WARZONE¡±RAT¾ßÓи߶ÈÒ»ÖÂÐÔ£¬£¬£¬£¬£¬Òò´Ë½«´ËÀà¶ñÒâ¼Ò×åÃüÃû¸üÐÂΪ¡°WARZONE¡±¡£¡£¡£¡£
3ÊÖÒÕÆÊÎö
3.1 ÔçÆÚ¹¥»÷Ñù±¾
´Ë´Î¹¥»÷Àú³Ì×îÏÈÓÚÒ»¸öЯ´ø¶ñÒâºêµÄDOCÎĵµ£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ýαÔì³É¼òÀúµÄͶµÝÓʼþÊֶν«´Ë¶ñÒâÎļþ·¢Ë͸ø¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬µ±Ä¿µÄÓû§Ê§É÷·¿ªÎĵµ±ã³ÉΪÁËÊܺ¦Õß¡£¡£¡£¡£DOCÎĵµÔËÐкó»áÆô¶¯¶ñÒâºê´úÂë²¢´ÓÖ¸¶¨µÄЧÀÍÆ÷ÏÂÔØEtr739.exe£¬£¬£¬£¬£¬ÀÖ³ÉÏÂÔØºóÁ¬Ã¦Ö´ÐС£¡£¡£¡£ÐÂÀú³Ìͨ¹ýBase64½âÂë³öÁíÒ»¸öЧÀÍÆ÷µØµã£¬£¬£¬£¬£¬¼ÌÐøÏÂÔØ¶ñÒâ´úÂëhqpi64.exeÖÁÔÝʱĿ¼Ï¡£¡£¡£¡£¶ñÒâ³ÌÐòhqpi64.exe¼´ÊÇWarzone RATµÄÊÍ·ÅÆ÷£¬£¬£¬£¬£¬Æäͨ¹ýÊÍ·ÅWarzone RATÀ´Ö´ÐкóÐø²Ù×÷£¬£¬£¬£¬£¬È罫explorer.exe×÷Ϊ¿þÀÜÀú³ÌÊØ»¤¡¢Óë¿ØÖÆ¶Ë¾ÙÐÐͨѶµÈ¡£¡£¡£¡£
Ñù±¾ÖеĶñÒâ´úÂë´ó²¿·Ö½ÓÄÉCRC32À´¼ÓÃÜÃô¸Ð×Ö´®£¬£¬£¬£¬£¬Í¬Ê±ÔÚAPIŲÓÃÊÖ·¨ÉϽÓÄÉÁËAPI HashÖµ¶¯Ì¬»ñÈ¡º¯ÊýµØµãºÍÄ£Äâϵͳ¿ìËÙŲÓÃÁ½ÖÖ·½·¨¡£¡£¡£¡£Ê¹ÓôËÀàÊÖ·¨²»µ«ÄÜÔÚÒ»¶¨Ë®Æ½ÉÏïÔÌɱÈí¾²Ì¬É¨ÃèµÄ¼ì²â£¬£¬£¬£¬£¬²¢ÇÒ»¹²»Ò×±»¼à²âµ½APIµÄŲÓÃ×Ù¼£¡£¡£¡£¡£Í¬Ê±ÆäʹÓô¿¼ÓÃÜShellcode´úÂëÄÚ´æÖ´Ðеķ½·¨¼ÓÔØÆä½¹µã¹¦Ð§Ä£¿£¿£¿é£¬£¬£¬£¬£¬Í¨¹ý¡°ÎÞÎļþÊÖÒÕ¡±Ìá¸ß×ÔÉíÒþ²ØÐÔ£¬£¬£¬£¬£¬ÒÔ´ËÀ´ÌÓ±ÜÇå¾²³§É̲éɱ¡£¡£¡£¡£ÆäÓëC2ЧÀÍÆ÷¼äµÄͨѶÊý¾ÝÒ²ÒÔCR4Ëã·¨¾ÙÐмÓÃܽø¶ø¹æ±ÜIDSϵͳµÄ¼ì²â¡£¡£¡£¡£
(1)DOCÎĵµ
ÔÚAutoOpenº¯ÊýÖаüÀ¨ÁËÒ»´®»ìÏý¹ýµÄcmdÏÂÁ£¬£¬£¬£¬¾ÓɽâÃܺóµÄ´úÂëÈçͼËùʾ£º
Õâ¶Î´úÂë»ñµÃÖ´Ðк󣬣¬£¬£¬£¬»áÖ±½ÓÒÔºóÁ´½ÓµØµã(http[:]//linksysdatakeys.se)ÏÂÔØ¶ñÒâ³ÌÐòµ½¡°%Temp%\SAfdASF.exe¡±²¢Ö´ÐС£¡£¡£¡£
(2)Payload
¸ÃPayloadÏȽ«ÉÏͼÖмÓÃܵÄÊý¾Ýͨ¹ýBase64½âÂë³öÏÂÔØÁ´½ÓµØµã¡°http[:]//www.gestomarket[.]co/hqpi64.exe¡±£¬£¬£¬£¬£¬È»ºó°Ñhqpi64.exe¸üÃûΪ2XC2DF0S.exe²¢ÉúÑÄÔÚÔÝʱĿ¼Ï¡£¡£¡£¡£
(3)Dropper
ÔÚºóÐøµÄ½âÃÜÒÔ¼°Ö´ÐеÄÀú³ÌÖУ¬£¬£¬£¬£¬´ËDropper»á°ÑÒ»¶ÎShellcode×¢Èëµ½explorerÀú³Ì²¢ÔÚÄÚ´æÖнâÃܳöRATʵÌåʹÆä²»Â䵨£¬£¬£¬£¬£¬×îÖÕͨ¹ýÎÞÎļþÊÖÒÕ½«RAT¼ÓÔØµ½ÄÚ´æÖÐÀ´Ö´ÐС£¡£¡£¡£
Ìӱܼì²â
½âÃÜshellcode
×Ô½ç˵µÄ½âÃܺ¯Êý
¾ÓÉÖØÖØÏÂÔØ²¢½âÃÜÖ®ºó£¬£¬£¬£¬£¬ÄÇôÕâ¶Î½âÃܺóµÄShellcode(PE Loader)´úÂëÏêϸ»á×öЩʲô£¬£¬£¬£¬£¬ÏÂÃæÎÒÃÇÀ´Ò»¿úÊÂʵ¡£¡£¡£¡£
PE Loader
|
ÐòºÅ |
ÄÚÈÝ |
¹¦Ð§ |
|
²ÎÊý1 |
¡°FYBLV¡± |
¿½±´×ÔÉíµÄĿ¼ÃûºÍÎļþÃû(Ðè½âÃܵÄ×ÊÔ´Ãû) |
|
²ÎÊý2 |
¡°BJU¡± |
RATÔ¶¿ØÎļþ(Ðè½âÃܵÄPEÎļþ×ÊÔ´Ãû) |
|
²ÎÊý3 |
¡°OPTYUPPABIVSUWNRXSNCTDW¡± |
Key |
|
²ÎÊý4 |
0x01£¨Àο¿ÊýÖµ£© |
δʹÓà |
¸ÃPE LoaderÊ×ÏÈÔÚÔËÐÐÀú³ÌÖоÙÐÐÁËɳÏäºÍÖ¸¶¨Àú³ÌµÄ¼ì²â£¬£¬£¬£¬£¬ÒÔ±ÜÃâ±»×Ô¶¯»¯ÏµÍ³ÆÊÎö¡£¡£¡£¡£²¢ÇÒÆ¾Ö¤×Ô´øµÄ×ÊÔ´Êý¾ÝÀ´ÅжÏÊÇ·ñʵÑéפÁô±¾»úµÄ²Ù×÷ºÍ×¢ÈëÌåµÄÑ¡Ôñ¡£¡£¡£¡£×îºó´ËPE Loader½«×îÖÕÑ¡ÔñµÄ¿þÀÜÀú³ÌµÄ¿Õ¼äÇãÔþ£¬£¬£¬£¬£¬²¢°Ñ½âÃܳöµÄRATÄ£¿£¿£¿éÓ³Éäµ½´ËÀú³ÌÖÐÖ´ÐÐ(Ô±¾PEÎļþ´úÂë±»Öû»)¡£¡£¡£¡£
ÔËÐÐÇéÐμì²â
ÔËÐÐÇéÐμì²â
²Ù×÷×ÊÔ´Êý¾Ý
¾Ì«¹ýÎö£¬£¬£¬£¬£¬½á¹¹ÌåÖÐÿ¸ö³ÉÔ±µÄÏêϸ¹¦Ð§¿É²Î¿¼ÏÂͼ£º
ÊÍ·ÅÓëפÁô
½¨ÉèµÄ¿ì½Ý¼üÊôÐÔ
×îºó£¬£¬£¬£¬£¬¸ÃPE Loaderƾ֤½á¹¹ÌåÖеÄdwFlagÖµÀ´Ñ¡ÔñºóÐøµÄRATÔØÌ壬£¬£¬£¬£¬Ëù¶ÔÓ¦µÄRATÔØÌåÏê¼ûÏÂ±í£º
|
Êý¾Ý |
Àú³ÌÃû |
|
0x01 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe |
|
0x02 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe |
|
0x03 |
C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe |
|
0x04 |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
|
0x05 |
C:\Windows\System32\svchost.exe |
|
0x06 |
C:\Windows\System32\dllhost.exe |
|
0x07 |
Ä¿½ñÔËÐеÄ×ÔÉíÀú³Ì |
¶øÔÚ±¾Ñù±¾ÖУ¬£¬£¬£¬£¬´Ë³ÉÔ±µÄÖµËù¶ÔÓ¦µÄÔØÌåΪĿ½ñÔËÐеÄ×ÔÉíÀú³Ì¡£¡£¡£¡£
»ñÈ¡RAT²¢Ö´ÐÐ
½Ó×Å£¬£¬£¬£¬£¬¸ÃPE LoaderÖØÐ½¨ÉèÐÂÀú³Ì²¢½«ÆäÉèÖÃΪ¹ÒÆð״̬¡£¡£¡£¡£È»ºóÐ¶ÔØ´ËÀú³ÌÓ³Ïñ£¬£¬£¬£¬£¬²¢°ÑÔÚÄÚ´æÖнâÃܳöµÄеÄPEÍ·²¿£¬£¬£¬£¬£¬ÒÔ¼°½ÚÊý¾ÝÒÀ´ÎдÈëµ½¹ÒÆðµÄÀú³ÌÖУ¬£¬£¬£¬£¬×îºóÐÞ¸ÄOEP²¢Æô¶¯ÔËÐС£¡£¡£¡£
(4) WARZONE RATÄ£¿£¿£¿é
Ô¶¿Ø³ÌÐòWarzoneºǫ́½çÃæ
»ñÈ¡C&CµØµã
ΪÁ˱ÜÃâC&C±»ÈÝÒ×·¢Ã÷»òÕßÅúÁ¿ÌáÈ¡£¬£¬£¬£¬£¬¸ÃľÂí½«Æä¼ÓÃÜºó´æ·ÅÔÚ¡°.bss¡±µÄ×ÊÔ´½ÚÊý¾ÝÖС£¡£¡£¡£Í¨¹ý¶Ô½âÃܺ¯ÊýµÄÆÊÎöÎÒÃÇ·¢Ã÷£¬£¬£¬£¬£¬ÕâÀï½ÓÄÉÁËCR4Ëã·¨¡£¡£¡£¡£CR4ÌìÉúÒ»ÖÖ³ÆÎªÃÜÔ¿Á÷µÄÎ±Ëæ»úÁ÷£¬£¬£¬£¬£¬ËüÊÇͬÃ÷ÎÄͨ¹ýÒì»ò²Ù×÷Ïà»ìÏýÀ´µÖ´ï¼ÓÃܵÄÄ¿µÄ¡£¡£¡£¡£½âÃÜʱÔòʹÓÃÃÜÔ¿µ÷ÀíËã·¨(KSA)À´Íê³É¶Ô¾ÞϸΪ256¸ö×Ö½ÚÊý×ésboxµÄ³õʼ»¯¼°Ìæ»»¡£¡£¡£¡£ÏêϸÁ÷³ÌÈçÏ£º
(ÔÚ×ÊÔ´Êý¾ÝÖÐǰ0x32¸ö×Ö½ÚÊÇÃÜÔ¿£¬£¬£¬£¬£¬ÆäÓà0x68¸ö×Ö½ÚÔòÊÇ´ý½âÃܵÄÊý¾Ý)
ÃÜÔ¿ºÍ´ý½âÃÜÊý¾Ý
4£©Ìæ»»ºóµÄsboxÊý×éÖеÄÊýÖµÈçÏÂͼ£º
5£©Í¨¹ýÌæ»»ºóµÄsboxºÍ´ý½âÃܵÄÊý¾Ý¾ÙÐÐXORÔËËãºó£¬£¬£¬£¬£¬×îÖÕ»ñµÃЧÀÍÆ÷µÄhostµØµã"asdfwrkhl.warzonedns[.]com"¡£¡£¡£¡£
Ö´ÐÐ×¢È빦Ч
½Ó×Å£¬£¬£¬£¬£¬¸ÃľÂíʹÓÃÔ¶³ÌÏ̵߳ķ½·¨À´×¢Èë½¹µã¹¦Ð§Shellcode´úÂ룬£¬£¬£¬£¬²¢ÔÚÆô¶¯Ô¶Ïß³ÌÖ´ÐÐʱ£¬£¬£¬£¬£¬ÐÞ¸ÄдÈëÄ¿µÄÀú³ÌÄÚ´æÆ«ÒÆµÄ0x10E´¦Îª×îÏÈÖ´ÐдúÂë¡£¡£¡£¡£
̫ͨ¹ýÎöÎÒÃÇ·¢Ã÷£¬£¬£¬£¬£¬Õâ¶Î×¢Èë´úÂëµÄÖ÷Òª¹¦Ð§ÊÇʹÓÿþÀÜÀú³ÌÀ´±£»£»£»£»¤Dropper(hqpi64.exe)¡£¡£¡£¡£Æä»á׼ʱ¼ì²éDropperÊÇ·ñ´¦ÓÚÔËÐÐ״̬£¬£¬£¬£¬£¬Èç±»¹Ø±Õ£¬£¬£¬£¬£¬ÔòÖØÐÂÆô¶¯¡£¡£¡£¡£ÒԴ˵ִïÀú³ÌÊØ»¤µÄÄ¿µÄ¡£¡£¡£¡£
Àú³ÌÊØ»¤¹¦Ð§
ͨѶÐÒéÆÊÎö
1£©ÅþÁ¬Ð§ÀÍÆ÷
2£©½âÃÜ¿ØÖưü
3£©Ö´ÐпØÖÆÖ¸Áî
ͨ¹ýÎÒÃÇÇ°ÃæµÄÆÊÎö¿ÉÒÔ¿´µ½£¬£¬£¬£¬£¬¸ÃľÂí¿ØÖÆÖ¸ÁîÖаüÀ¨ÁË´ó×ÚÓû§Òþ˽ÐÅÏ¢µÄÇÔÈ¡¹¦Ð§¡£¡£¡£¡£×îÖÕÊܺ¦ÕßµÄÃô¸ÐÊý¾ÝÐÅÏ¢£¬£¬£¬£¬£¬¶¼»áƾ֤Զ³ÌЧÀÍÆ÷µÄÖ¸Áî»Ø´«¸øÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£
¿ØÖÆÖ¸ÁЧ
|
¿ØÖÆÏÂÁî |
Ö¸ÁЧ |
|
0x01~0x04 |
ŲÓÃ×Ô½ç˵º¯Êý£¬£¬£¬£¬£¬²¢½«Ö´ÐÐЧ¹û»Ø´«Ð§ÀÍÆ÷ |
|
0x02 |
ÉÏ´«Àú³ÌÁбí |
|
0x04 |
»ñÈ¡ÅÌËã»úÂß¼´ÅÅÌÐÅÏ¢ |
|
0x06 |
ÉÏ´«ÎļþÁбíÐÅÏ¢ |
|
0x08 |
ÏÂÔØ¿ØÖÆÏÂÁîÖÐÖ¸¶¨µÄÎļþ |
|
0x10 |
¿¢Ê¿ØÖÆÏÂÁîÖÐÖ¸¶¨µÄÀú³Ì |
|
0x0E |
Remote Shell |
|
0x10 |
×÷·ÏÏÂÔØ |
|
0x12 |
»ñÈ¡Webcam DevicesÁбí |
|
0x14 |
Start Webcam |
|
0x16 |
Stop Webcam |
|
0x18 |
·¢ËÍÐÄÌø°ü |
|
0x1A |
Ð¶ÔØ¿Í»§¶Ë |
|
0x1C |
Ð޸ĿØÖÆÏÂÁîÖÐÖ¸¶¨µÄÎļþ |
|
0x1E |
ÏÂÔØVNCÄ£¿£¿£¿é |
|
0x20 |
ÇÔÈ¡Google Chrome¡¢Mozilla FireFoxµÈä¯ÀÀÆ÷ºÍOutLook¡¢Thunderbird¡¢FoxmailÓÊÏäÖÐÉúÑĵį¾Ö¤ÐÅÏ¢ |
|
0x22 |
ÏÂÔØ¿ØÖÆÏÂÁîÖÐÖ¸¶¨µÄÎļþÁ´½Ó²¢Ö´ÐÐ |
|
0x24 |
ƾ֤¿ØÖÆÖ¸Á£¬£¬£¬£¬Çл»Á½ÖÖ·½·¨À´¼Í¼¼üÅÌʹÓÃÐÅÏ¢ |
|
0x26 |
ʹÓÃÈ«¾ÖÐÂÎŹ³×Ó£¬£¬£¬£¬£¬¼Í¼¼üÅÌʹÓÃÐÅÏ¢ |
|
0x28 |
Remote VNC×°ÖÃ |
|
0x2A |
²âÊÔ±¾»úµÄÍøÂçÅþÁ¬¹¦Ð§ |
|
0x2C |
¶Ï¿ªÔ¶³ÌЧÀÍÆ÷ |
|
0x38 |
δ֪²âÊÔ |
|
other |
»ñÈ¡Óû§Ãû£¬£¬£¬£¬£¬ÏµÍ³°æ±¾£¬£¬£¬£¬£¬GUIDµÈÐÅÏ¢ |
1£©ÇÔȡƾ֤ÐÅÏ¢
ÇÔÈ¡µÄÐÅÏ¢°üÀ¨Google Chrome¡¢Mozilla FirefoxµÈä¯ÀÀÆ÷ºÍOutlook¡¢Thunderbird¡¢FoxmailÓÊÏä¿Í»§¶ËÉúÑĵį¾Ö¤ÐÅÏ¢µÈ¡£¡£¡£¡£
¸ÃľÂí»ñÈ¡Ïà¹ØÆ¾Ö¤ÐÅÏ¢ÒÔ¼°ÊµÏÖÒªÁìÈçϱíËùʾ£º
|
ÇÔÈ¡µÄƾ֤ÐÅÏ¢ |
ʵÏÖÒªÁì |
|
Google Chrome |
¶ÁÈ¡\AppData\Local\Google\Chrome\User Data\Default\ Login DataÊý¾Ý¿âÎļþ¾ÙÐÐÅÌÎÊ |
|
Mozilla Firefox |
¶ÁÈ¡ÉèÖ÷¾¶ÏµÄsignons.sqliteÊý¾Ý¿â£¬£¬£¬£¬£¬²¢Í¨¹ýnss3.dll½âÃÜ |
|
Outlook |
±éÀú×¢²á±íSoftware\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\ProfilesÏÂ×Ó¼ü¾ÙÐÐʶ±ð²¢½âÃÜ |
|
Thunderbird |
¶ÁÈ¡\AppData\Roaming\Thunderbird\ProfilesĿ¼ÏµÄÊý¾Ý¿âÎļþ£¬£¬£¬£¬£¬²¢Í¨¹ýÓ¦ÓóÌÐòĿ¼ÏµÄnss3..dll¶Ô´æ´¢µÄÃÜÂë¾ÙÐнâÃÜ |
|
Foxmail |
¶ÁÈ¡ÓÊÏäĿ¼ÏµÄ\\Account\\Account.rec0Îļþ²¢¾ÙÐнâÃÜ |
a£©ÌáÈ¡Chromeƾ֤
´Ó¸Ã±íÖжÁÈ¡µÄÄÚÈÝÊǼÓÃܵ쬣¬£¬£¬£¬Í¨¹ýCryptUnProtectDataº¯Êý¶ÔÆä¾ÙÐнâÃܱã¿ÉÒÔ»ñÈ¡µ½Ã÷ÎÄÊý¾Ý¡£¡£¡£¡£×îºó¸ÃľÂí½«½âÃܺóµÄÊý¾ÝÉúÑÄÔÚÃûΪ¡±xxx.tmp¡±£¨¡±xxx¡°ÎªBase64½âÂë³öµÄ×Ö´®£©µÄÔÝʱÎļþÖС£¡£¡£¡£
b£©ÌáÈ¡Mozillaƾ֤ÐÅÏ¢
Óû§ÃûºÍÃÜÂë
c£©OutLookƾ֤»ñÈ¡
»ñÈ¡OutlookÓÊÏäµÄÓû§ÐÅÏ¢
d£©Thunderbirdƾ֤»ñÈ¡
e£©FoxMailƾ֤»ñÈ¡
f£©ÉÏ´«»ñÈ¡µ½µÄƾ֤ÐÅÏ¢
2£©¼üÅ̼ͼ
b£©ÔÝʱ¼üÅ̼ͼ
°´¼üºÍ´°¿ÚÃûÐÅÏ¢µÄ»ñÈ¡
3£©RemoteVNC×°ÖÃ
a£©½«ÐÂÓû§Ìí¼Óµ½¡±Ô¶³Ì×ÀÃæÓû§¡±×é
Ìí¼Ó²¢Òþ²Ø½¨ÉèµÄÐÂÕË»§
b£©¸ü¸ÄÔ¶³Ì×ÀÃæÉèÖÃ
̫ͨ¹ýÎöÎÒÃÇ·¢Ã÷£¬£¬£¬£¬£¬´ËRATµÄÔ¶³Ì×ÀÃæ¹¦Ð§ÊÇͨ¹ýÌØÖÆµÄVNCÄ£¿£¿£¿éÀ´ÊµÏֵġ£¡£¡£¡£²¢ÇÒÔÚºóÐøµÄ¸üа汾ÖУ¬£¬£¬£¬£¬»¹ÔöÌíÁËHRDPÄ£¿£¿£¿éÀ´ÊµÏÖÒþ²ØÔ¶¿Ø×ÀÃæ¡£¡£¡£¡£¸ÃHRDPÄ£¿£¿£¿éʹÓÃÁËGithubÉϵÄrdpwrapÏîÄ¿£¬£¬£¬£¬£¬²»µ«¿ÉÒÔÔÚºǫ́µÇ¼Զ³ÌÅÌËã»ú£¬£¬£¬£¬£¬²¢ÇÒ½¨ÉèµÄWindowsÕË»§»¹»á×Ô¶¯Òþ²Ø¡£¡£¡£¡£
4£©È¨ÏÞÉý¼¶£¨UACÈÆ¹ý£©
¸ÃľÂíµÄȨÏÞÌáÉýÊÇʹÓÃÁË×Ô¶¯ÌáÉýȨÏÞµÄÕýµ±Ó¦ÓóÌÐò¡±pkgmgr.exe¡±À´Ö´ÐÐDISPÄ£¿£¿£¿é¡£¡£¡£¡£Æä¹¦Ð§´úÂëʵÏÖÊǽÓÄÉÁËBypass-UAC¿ò¼Ü£¬£¬£¬£¬£¬¸Ã¿ò¼Ü¿ÉÒÔͨ¹ýŲÓÃIFileOpertion COM¹¤¾ßËùÌṩµÄÒªÁìÀ´ÊµÏÖ×Ô¶¯ÌáȨ¡£¡£¡£¡£
¸ÃľÂíÏȽ«Ç¶ÈëÔÚ×ÊÔ´Êý¾ÝÖеÄPEÎļþÔÚÄÚ´æÖмÓÔØ²¢ÔËÐС£¡£¡£¡£¶ø´ËPEÎļþÏÖʵÉÏÊÇÒ»¸ö¼ÓÔØÆ÷£¬£¬£¬£¬£¬ÆäËù×öµÄÊÂÇéÔòÊǽ«×ÊÔ´ÖеÄÁíÒ»¸öPEαÔìΪ¡°dismcore.dll¡±£¬£¬£¬£¬£¬È»ºó½«´Ëdll¸´ÖƵ½System32Ŀ¼Ï£¬£¬£¬£¬£¬×îºóʹÓÃpkgmgr.exeÖ´ÐÐαÔìµÄ¶ñÒâDLL¡£¡£¡£¡£ÓÉÓÚpkgmgr.exeÊÇÒ»¸öUAC°×Ãûµ¥³ÌÐò£¬£¬£¬£¬£¬ÒÔÊÇËüĬÈϾßÓÐÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬ÇÒ²»»áµ¯³öUACÌáÐÑ¿ò¡£¡£¡£¡£²¿·Ö´úÂëÈçÏÂͼËùʾ£º
´Ë¶ñÒâDLLµÄÖ÷Òª¹¦Ð§ÊÇ»ñȡע²á±íÖеġ±Install¡±×°ÖÃÐÅÏ¢(DropperµÄ·¾¶)²¢ÖØÐÂÆô¶¯¾ßÓÐÖÎÀíԱȨÏÞµÄDropperÐÂÀú³Ì¡£¡£¡£¡£
5£©Î´Öª²âÊÔ
ÔÚÐÂÏß³ÌÖУ¬£¬£¬£¬£¬Æ¾Ö¤Ô¶³ÌЧÀÍÆ÷·¢Ë͵ÄÖ¸Á£¬£¬£¬£¬ÓëÐÂÖ¸¶¨µÄC&C¾ÙÐÐÅþÁ¬¡£¡£¡£¡£
ÓÉÓÚÎüÊÕÊý¾ÝÎÞ·¨»ñÈ¡£¬£¬£¬£¬£¬ÒÔÊÇÏÖÔÚÎÒÃÇÎÞ·¨È·¶¨Æä׼ȷÓÃ;£¬£¬£¬£¬£¬Ôݽ«ÆäÃüÃûΪδ֪²âÊÔ¡£¡£¡£¡£
3.2 ×îй¥»÷Ñù±¾
½×¶ÎÒ»£º
½âÃܺ¯Êýmethod_0ÈçÏÂͼËùʾ£º
ÔÚ¾ÓÉÄæÐòÅÅÁкÍBase64½âÂëºóµÄ×Ö·û´®£¨byte_0£©ÖУ¬£¬£¬£¬£¬Ç°16λΪ½âÃÜÃÜÔ¿¡°0x28 0x49 0xf7 0x30 0xec 0x8d 0x500x80 0x94 0xaf 0x85 0xaa 0xa8 0xe7 0xc0 0x41¡±,Ö®ºóΪ´ý½âÃÜÃÜÎÄ¡£¡£¡£¡£º¯ÊýÒÔ16λΪѻ·,½«ÃÜԿͬÃÜÎÄÒÀ´Î¾ÙÐа´Î»Òì»ò£¬£¬£¬£¬£¬×îÖÕ½âÃÜ»ñµÃ¡°DUMP1¡±Îļþ²¢Í¨¹ýCallByNameº¯Êý¼ÓÔØÖ´ÐС£¡£¡£¡£
½×¶Î¶þ£º
¡°DUMP1¡±ÎļþͬÑù½ÓÄÉC#±àд£¬£¬£¬£¬£¬³ÌÐòÊ×ÏÈ»á˯Ãß50ÃëÒÔÌÓ±ÜɳÏä¼ì²é£¬£¬£¬£¬£¬Ö®ºó»á¼ì²âµ÷ÊÔÆ÷²¢½«×ÔÉíÊÍ·ÅÖÁ¡°%ApplicationData%\riNpmWOoxxCY.exe¡±£¬£¬£¬£¬£¬½Ó׎¨Éèschtasks.exeÀú³Ì²¢Ìí¼ÓÍýÏëʹÃü¡°Updates\riNpmWOoxxCY¡±£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÔڵǼÕË»§Ê±×ÔÆô¶¯£¬£¬£¬£¬£¬Ïà¹ØÏÂÁîÈçÏ£º
"C:\Windows\System32\schtasks.exe/Create/TN Updates\riNpmWOoxxCY/XMLC:\Users\super\AppData\Local\Temp\tmp925C.tmp"
Ö®ºó£¬£¬£¬£¬£¬³ÌÐò»á´Ó×ÔÉí×ÊÔ´ÄÚ½âÃܳöPEÎļþ¡°DUMP2¡±£¬£¬£¬£¬£¬Í¨¹ýCreateProcess¡¢WriteProcessMemoryºÍSetThreadContextµÈº¯Êý£¬£¬£¬£¬£¬ÒÔ¹ÒÆðµÄ·½·¨¼ÓÔØÒ»¸öеÄÀú³Ì£¬£¬£¬£¬£¬²¢×îÖÕÒÔ¿þÀÜÀú³ÌµÄ·½·¨Ð´Èë²¢¼ÓÔØ¡°DUMP2¡±¡£¡£¡£¡£
¾Ì«¹ýÎö£¬£¬£¬£¬£¬ÎÒÃÇÔÚ¡°DUMP2¡±Öз¢Ã÷ÁËһЩ¿ÉÒÉ×Ö·û´®È磺¡°Remcos¡±¡¢¡°Remcos_Mutex_Inj¡±¡¢¡°2.3.0 Pro¡±¡£¡£¡£¡£
ÆäÃâ·Ñ°æ½ö¿ÉÌí¼ÓÒ»¸öC2ÅþÁ¬Ð§ÀÍÆ÷£¬£¬£¬£¬£¬×¨Òµ°æÔòûÓÐÊýÄ¿ÏÞÖÆ¡£¡£¡£¡£´Ë´Î¹¥»÷ÖÐÖ²ÈëµÄľÂíÊÇͨ¹ýרҵ°æÌìÉúÇÒÅþÁ¬ÖÁ¶à¸ö¶ñÒâC2£¬£¬£¬£¬£¬°üÀ¨µÄC2µØµãÌáÈ¡ÈçÏ£º
casillasmx.chickenkiller.com
casillas.libfoobar.so
du4alr0ute.sendsmtp.com
settings.wifizone.org
wifi.con-ip.com
rsaupdatr.jumpingcrab.com
activate.office-on-the.net
4¶ñÒâ´úÂëËÝÔ´Óë¹ØÁª
4.1 ¶ñÒâ´úÂëËÝÔ´×·×Ù
ǰÎÄÔøÌáµ½£¬£¬£¬£¬£¬¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÖаüÀ¨ÁË¡°AVE_MARIA¡±ÌØÕ÷×Ö·û´®£¬£¬£¬£¬£¬ÇÒ×Ô2018Äê12ÔÂ×îÏÈ£¬£¬£¬£¬£¬¡°AVE_MARIA¡±Àà¶ñÒâÑù±¾ÔÚtwitter¡¢virustotalµÈƽ̨ԽÀ´Ô½¶àµÄ±»·¢Ã÷¡£¡£¡£¡£µ«¶àƪÏà¹ØÑо¿ÎÄÕ¾ùδָ³öÆäÕæÊµÈªÔ´£¬£¬£¬£¬£¬É±¶¾³§ÉÌÒ²ÆÕ±éµÄ½«ÆäÃüÃûΪAVE_MARIA£¬£¬£¬£¬£¬ÕâÒýÆðÁËÎÒÃÇō֨µÄÐËȤ¡£¡£¡£¡£
ÎÒÃÇʵÑé´Ó¶àÖֽǶÈÈ¥ËÝԴľÂíÒÔѰÕÒÏßË÷£¬£¬£¬£¬£¬°üÀ¨ÓòÃû¡¢IP¡¢¹ØÁªÑù±¾µÈµÈ¡£¡£¡£¡£ÆäÖÐÔÚ¶Ô¹ØÁªÑù±¾¡°Michelle Flores - Curriculum Actualizado.doc¡±µÄÆÊÎöÖÐÀÖ³ÉËÝÔ´µ½ÁËÉÌÓÃÈí¼þRemcos RAT¡£¡£¡£¡£ÎÒÃÇÆÊÎöÁ˸ÃÈí¼þµÄÐû²¼ÇþµÀ£¬£¬£¬£¬£¬·¢Ã÷Æä²»µ«ÔÚ¹ÙÍø¾ÙÐÐÏúÊÛ£¬£¬£¬£¬£¬»¹ÔÚÖî¶àºÚ¿ÍÂÛ̳ÈçHackforumsÉÏ´ó×ÚÊÛÂô¡£¡£¡£¡£ÓÉ´Ë£¬£¬£¬£¬£¬ÎÒÃÇÍÆ²â¹¥»÷Ö°Ô±ºÜ¿ÉÄÜ»îÔ¾ÔÚÏà¹ØÂÛ̳²¢¹ºÖùý¶à¿îÉÌÓÃÈí¼þ£¬£¬£¬£¬£¬Í¬Ê±Ò²½«ËÝÔ´ÖØµãתÏòºÚ¿ÍÂÛ̳ºÍ°µÍøÊг¡¡£¡£¡£¡£
SolmyrÔÚÂÛ̳ÖÐÌṩÁËwarzonedns.comÓòÃûµÄÃâ·ÑDDNSЧÀÍ£¨IP¶¯Ì¬°ó¶¨ÖÁ×ÓÓòÃû£©£¬£¬£¬£¬£¬Ê¹µÃÓû§¿ÉÒÔÈÝÒ׵Ľ«Ð§ÀÍÆ÷IP°ó¶¨ÆÊÎöÖÁwarzonedns.comϵÄí§Òâ×ÓÓòÃû£¬£¬£¬£¬£¬Ê¹ÓÃʾÀýÈçÏ£º
ÕâÎÞÒɸøºÚ¿ÍÌṩÁ˺ܺõIJØÉíÖ®Ëù£¬£¬£¬£¬£¬Óë´ËͬʱÎÒÃÇ·¢Ã÷SolmyrµÄÁíÒ»¸öÉí·ÝÊÇWARZONE RATµÄÐû²¼Õߣ¬£¬£¬£¬£¬¸ÃÈí¼þÓÉÓÚ¿ØÖÆÊֶθ»ºñ¡¢ÊÖÒÕ¹¦Ð§Ç¿Ê¢¡¢µü´ú¸üÐÂѸËÙ£¬£¬£¬£¬£¬ÏÖÔÚÔÚHackforumsÂÛ̳ÖкÜÊÇÊܽӴý¡£¡£¡£¡£
ÖÁ´Ë£¬£¬£¬£¬£¬ÎÒÃÇÓÐÀíÓÉÏÓÒɹ¥»÷ÕßʹÓùý¸Ã¿îÉÌÓÃÔ¶³ÌÖÎÀí¹¤¾ß¡£¡£¡£¡£ÓÉÓÚ¸ÃÈí¼þ±ÕÔ´ÇÒ²»ÌṩÃâ·Ñ°æ±¾£¬£¬£¬£¬£¬ÎÒÃÇ×·Ëݵ½ÁËWARZONE RATÁ÷³öµÄÆÆ½â°æ±¾£¨V1.31£©£¬£¬£¬£¬£¬²¢½«ÆäÓë¡°Curriculum Vitae Actualizado Jaime Arias.doc¡±Ö²ÈëµÄľÂíÑù±¾¾ÙÐÐͬԴÐÔÆÊÎö,ÒÔÈ·¶¨¶þÕß¼äµÄ¹ØÁª¡£¡£¡£¡£
4.2 ͬԴÐÔÆÊÎö
Æä´Î£¬£¬£¬£¬£¬ÎÒÃÇͨ¹ýBindiff¾ÙÐÐÁ˸üΪ׼ȷµÄ±ÈÕÕ£¬£¬£¬£¬£¬ÔÚÈ¥³ý²¿·ÖAPI×ÌÈŲ¢½ÏÁ¿ÆÊÎöÁË¿ÉÐŶȸߵĺ¯Êýºó£¬£¬£¬£¬£¬·¢Ã÷´ó×Úº¯ÊýÍêÈ«Ïàͬ£¬£¬£¬£¬£¬Õ¼±ÈµÖ´ï80.16%£¬£¬£¬£¬£¬ÆäÓຯÊýÔò¿ÉÄÜÓÉÓÚ°æÀ´Ô´ÒòÂÔÓвî±ð£¬£¬£¬£¬£¬ÕâÒ²Ó¡Ö¤Á˶þÕß¼äµÄÇ¿¹ØÁªÐÔ¡£¡£¡£¡£
ÁíÍâ,´ÓÈö²¥Ê±¼äµÄ½Ç¶ÈÆÊÎö,¡°AVE_MARIA¡±¹ØÁªÑù±¾×î³õ·ºÆðµÄʱ¼ä(2018Äê12ÔÂ2ÈÕ)ÂÔÍíÓÚWarzoneRATÔÚÂÛ̳µÄÐû²¼Ê±¼ä(2018Äê10ÔÂ22ÈÕ)£¬£¬£¬£¬£¬ÕâÒ²Çк϶ñÒâ´úÂëÈö²¥µÄʱ¼äÂß¼¡£¡£¡£¡£
ÒÀ¾ÝÒÔÉϼ¸µãÆÊÎö£¬£¬£¬£¬£¬ÎÒÃÇÒÔΪÁ½Õß¾ßÓи߶ȵÄÒ»ÖÂÐÔ¡£¡£¡£¡£´ÓÏÖÔÚÒÑÖªµÄÇéÐο´£¬£¬£¬£¬£¬WARZONE±»É±¶¾³§ÉÌÆÕ±éµÄʶ±ðΪAVE_MARIA£¬£¬£¬£¬£¬¶øÔÚÉîÈë±È¶ÔÆÊÎöºó£¬£¬£¬£¬£¬ÎÒÃÇÅжϺڿÍ×é֯ʹÓõÄÔ¶¿ØÄ¾ÂíÕýÊÇWARZONE RAT¡£¡£¡£¡£Òò´Ë¿ÉÒÔ½«´ËÀà°üÀ¨¡°AVE_MARIA¡±×Ö·û´®µÄ¶ñÒâÑùͬ×å×åÃüÃû¸üÐÂΪ¡°WARZONE¡±¡£¡£¡£¡£
4.3 ÓòÃû¹ØÁª
ÕâÅúÓòÃû¾ùΪwarzonedns.comÌṩµÄÃâ·Ñ×ÓÓòÃû£¬£¬£¬£¬£¬ÇҴ󲿷ֹØÁªÖÁ¶ñÒâÑù±¾£¬£¬£¬£¬£¬ÕâÅú×¢´ó×ÚºÚ¿ÍÕýÔÚÀÄÓôËÀàЧÀ;ÙÐжñÒâ¹¥»÷¡£¡£¡£¡£
5×Ü ½á
±¾ÎĶԱ¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Á÷³Ì¡¢Ïà¹ØµÄ¶ñÒâ´úÂë¡¢ºÚ¿ÍÅä¾°µÈ×öÁËÉîÈëµÄÆÊÎöºÍÑо¿£¬£¬£¬£¬£¬´ÓÉÏÎĵįÊÎöÖÐÎÒÃÇ¿ÉÒÔ¿´³ö¸ÃºÚ¿Í×éÖ¯ÏÖÔڵĹ¥»÷»î¶¯Ê®·ÖÉóÉ÷£¬£¬£¬£¬£¬¼ÈûÓдó¹æÄ£µÄ¹¥»÷£¬£¬£¬£¬£¬Ò²Ã»ÓнÓÄɸ߱¾Ç®µÄ0dayÎó²î£¬£¬£¬£¬£¬Í¬Ê±£¬£¬£¬£¬£¬¹¥»÷»î¶¯Ê±¼äÒ²ºÜÊǶ̡£¡£¡£¡£ÕâÅú×¢¸Ã¹¥»÷»î¶¯»¹´¦ÓÚ³õÆÚ£¬£¬£¬£¬£¬²¢¶ÔÄ¿µÄ¾ÙÐÐÁËһЩÊÔ̽ÐÔ¡¢Õë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬Ò²ÎªºóÐøµÄ¹¥»÷×öºÃ×¼±¸¡£¡£¡£¡£±ðµÄͨ¹ý¶Ô¹¥»÷»î¶¯µÄËÝÔ´£¬£¬£¬£¬£¬ÎÒÃÇÈ·¶¨Á˸ôλ±³ºóµÄºÚ¿Í×éÖ¯£¬£¬£¬£¬£¬²¢Æ¾Ö¤¸ÃºÚ¿Í×éÖ¯µÄ»î¶¯ÀúÊ·£¬£¬£¬£¬£¬·¢Ã÷ÆäÃñ×åÖ÷ÒåÉ«²ÊÇ¿ÁÒ£¬£¬£¬£¬£¬Òò´ËÕþÖÎÄ¿µÄÒâͼҲ½ÏΪÏÔ×Å¡£¡£¡£¡£
IOC
|
MD5 |
|
99C82F8A07605DA4CCC8853C910F7CAF |
|
048DCA20685ECD6B7DBDBF04B9082A54 |
|
DEF105A9452DEF53D49631AF16F6018B |
|
1E19266FC9DFF1480F126BD211936AAC |
|
262D9C6C0DC9D54726738D264802CCAD |
|
B3C9F98DD07005FCCF57842451CE1B33 |
|
497566120F1020DBD6DF70DD128C0FFB |
|
ÓòÃû |
|
linksysdatakeys[.]se |
|
gestomarket[.]co |
|
asdfwrkhl.warzonedns[.]com |
|
casillas.hicam[.]net |
|
casillasmx.chickenkiller[.]com |
|
casillas.libfoobar[.]so |
|
du4alr0ute.sendsmtp[.]com |
|
settings.wifizone[.]org |
|
wifi.con-ip[.]com |
|
rsaupdatr.jumpingcrab[.]com |
|
activate.office-on-the[.]net |


¾©¹«Íø°²±¸11010802024551ºÅ