c7c7ÓéÀÖÆ½Ì¨ADLab | SWEEDºÚ¿Í×éÖ¯¹¥»÷»î¶¯ÆÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2020-07-03

Ò»¡¢¸ÅÊö


½üÆÚ£¬ £¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ADLab½ÓÁ¬²¶»ñµ½´ó×ÚÕë¶ÔÈ«ÇòÖÆÔì¡¢ÔËÊä¡¢ÄÜÔ´µÈÐÐÒµ¼°²¿·ÖÒ½ÁÆ»ú¹¹ÌᳫµÄÓã²æÊ½´¹ÂÚÓʼþ¶¨Ïò¹¥»÷¡£¡£¡£¡£´ÓÓʼþµÄÆÊÎöЧ¹ûÀ´¿´£¬ £¬£¬£¬£¬£¬Êܺ¦Õß´ó¶à±é²¼ÓÚÃÀ¹ú¡¢¼ÓÄô󡢵¹ú¡¢Öйú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Î÷°àÑÀµÈ¹ú¼ÒºÍµØÇø¡£¡£¡£¡£¹¥»÷ÕßÒÔ¡°×°´¬Í¨Öªµ¥¡±¡¢¡°×°Ïä½»»õ¼Ûµ¥¡±¡¢¡°½ôÆÈÔËÊäÎļþ¡±µÈÖ÷ÌâÓʼþ×÷ΪÓÕ¶üÏò¹¥»÷Ä¿µÄÖ²ÈëÐÅÏ¢ÇÔÃÜľÂí£¨Agent Tesla¡¢Formbook¡¢Lokibot£©ºÍÔ¶³Ì¿ØÖƳÌÐò£¨NanoCore¡¢Remcos£©¡£¡£¡£¡£ÎÒÃÇͨ¹ý¶ÔÍøÂçµ½µÄ¹¥»÷¹¤¾ß¾ÙÐÐÈ¥ÖØ²¢×öÆÊÎö£¬ £¬£¬£¬£¬£¬×îÖÕ·¢Ã÷´Ë´Î¹¥»÷»î¶¯¹ØÁª×Å1362¸ö¹¥»÷Ñù±¾¡£¡£¡£¡£Í¨¹ýͬԴÆÊÎö£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÕâÅúÑù±¾ÖÐÓнü80%ÊÇͳһ¿î¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬¶ÔÆäÆÊÎöÅжϺóÈ·¶¨ÕâÕýÊǽüÆÚ±»´ó¹æÄ£Èö²¥ÇÒ¼«Îª»îÔ¾µÄÐÂÐÍÏÂÔØÕß²¡¶¾Guloader¡£¡£¡£¡£GuloaderÊÇÒ»¿îÃâɱÄÜÁ¦ºÜÇ¿µÄ²¡¶¾£¬ £¬£¬£¬£¬£¬½üÆÚÈ«Çò¸÷´ó³§É̾ù¶ÔÆä¾ÙÐÐÁËÔ¤¾¯£¬ £¬£¬£¬£¬£¬Æä¾ß±¸É³ºÐÌÓÒÝ¡¢´úÂë»ìÏý¡¢·´µ÷ÊÔ¡¢C&C/URL¼ÓÃܺÍÓÐÓÃÔØºÉ¼ÓÃܵȶàÖÖÄÜÁ¦¡£¡£¡£¡£ÓÉÓÚGuloader¾ßÓнÏÇ¿µÄÃâɱÄÜÁ¦ºÍ¶Ô¿¹»úÖÆ£¬ £¬£¬£¬£¬£¬Òò¶øÊܵ½´ó×ںڿ͵ÄÇàíù¡£¡£¡£¡£±¾Åú¹¥»÷ÖУ¬ £¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÆÕ±éµØÊ¹ÓÃGuloaderÏÂÔØÕß²¡¶¾Á¬ÏµÔÆÐ§ÀÍÀ´·Ö·¢ÇÔÃܹ¤¾ß»òÔ¶³Ì¿ØÖƳÌÐò£¨RAT£©¡£¡£¡£¡£


ÎÒÃÇͨ¹ýËÝÔ´ÆÊÎöÈ·¶¨´Ë´Î¹¥»÷»î¶¯À´×ÔÄáÈÕÀûÑÇ£¬ £¬£¬£¬£¬£¬²¢ÇÒ¹ØÁª³öÁË´óÅúÁ¿µÄºÚ¶ñÒâÓòÃû£¨¹¥»÷ÕßʹÓþ³ÍâµÄDuck DNS×¢²á¶¯Ì¬ÓòÃû£©ºÍIPµØµã¡£¡£¡£¡£Í¨¹ý¶Ô¹¥»÷ÕßʹÓõÄÍøÂç»ù´¡ÉèÊ©£¬ £¬£¬£¬£¬£¬×·×ÙÆÊÎö·¢Ã÷´Ë´Î¹¥»÷»î¶¯×îÔç¿É×·Ëݵ½2020Äê1Ô¡£¡£¡£¡£½øÒ»²½ÆÊÎöÎÒÃÇ·¢Ã÷£¬ £¬£¬£¬£¬£¬ÕâÅú¹¥»÷ÕߵĹ¥»÷ÄîÍ·¡¢¹¥»÷Ä¿µÄ¡¢×÷񵮿¸ÅÓëSWEEDºÚ¿Í×éÖ¯¼«ÎªÏàËÆ£¬ £¬£¬£¬£¬£¬ËûÃÇÉÐÓÐ×ÅÏàËÆµÄ¹¥»÷ϰ¹ß£¬ £¬£¬£¬£¬£¬²¢Ê¹ÓÃÏàͬÇÔÃÜľÂí³ÌÐò£¬ £¬£¬£¬£¬£¬ÒÔ¼°Í¬ÑùÆø¸ÅµÄC&CµØµã¡£¡£¡£¡£Òò´Ë£¬ £¬£¬£¬£¬£¬ÎÒÃÇÍÆ¶ÏÕâÅú¹¥»÷±³ºóÓ¦¸Ã¾ÍÊÇSWEEDºÚ¿Í×éÖ¯¡£¡£¡£¡£SWEEDÊÇÒ»¸öÀ´×ÔÄáÈÕÀûÑǵÄÒÔ»ñÈ¡¾­¼ÃÀûÒæÎªÖ÷ҪĿµÄµÄºÚ¿Í×éÖ¯£¬ £¬£¬£¬£¬£¬Æä×îÔç·ºÆðÓÚ2017Ä꣬ £¬£¬£¬£¬£¬³£Ê¹ÓùûÕæÅû¶µÄÎó²î£¬ £¬£¬£¬£¬£¬½èÖúÓã²æÊ½´¹ÂÚÓʼþÀ´Èö²¥Ä¾Âí³ÌÐò£¬ £¬£¬£¬£¬£¬ÈçAgent Tesla¡¢FormbookºÍLokibotµÈ¡£¡£¡£¡£¸Ã×éÖ¯ÔøÔÚÔçÆÚ±»Åû¶µÄ¹¥»÷»î¶¯ÖУ¬ £¬£¬£¬£¬£¬Í¨¹ýÇÔÈ¡±»¹¥»÷Ä¿µÄÓû§ºÍÆóÒµÃô¸ÐÐÅϢʵÑéÖÐÐÄÈ˹¥»÷£¬ £¬£¬£¬£¬£¬ÓÕʹ²ÆÎñÖ°Ô±½«¿î×ÓתÖÁÖ¸¶¨ÕË»§£¬ £¬£¬£¬£¬£¬ÊÇÒ»¸öµä·¶µÄÍøÂçÕ©Æ­ÍŻ¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨ADLab¶Ô±¾´Î¹¥»÷»î¶¯µÄ¹¥»÷Àú³ÌºÍ¹¥»÷ÊÖ·¨¾ÙÐÐÁËÏêϸµØÆÊÎöºÍËÝÔ´£¬ £¬£¬£¬£¬£¬²¢¶ÔÆäËùʹÓõÄÐÂÐͶñÒâÈí¼þºÍC&C»ù´¡ÉèÊ©¾ÙÐÐÁËÉîÈëÑо¿¡£¡£¡£¡£ÌáÐѸ÷´óÆóÒµµ¥Î»×öºÃÇå¾²Ìá·ÀÊÂÇ飬 £¬£¬£¬£¬£¬½÷·ÀºóÐø¿ÉÄÜ·ºÆðµÄ¹¥»÷¡£¡£¡£¡£



¶þ¡¢¹¥»÷Ä¿µÄºÍÊܺ¦ÕßÂþÑÜ


×èÖ¹µ½2020Äê6Ô£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷¹¥»÷ÕßµÄÖØµãÄ¿µÄΪ´ÓʶÔÍâÉÌÒµµÄÖÐСÐÍÆóÒµ£¬ £¬£¬£¬£¬£¬ÆäÄ¿µÄÊÇͨ¹ýÖ²ÈëÌØ¶¨µÄºóÃÅÒÔʵÏÖ¶ÔÄ¿µÄÅÌËã»ú¾ÙÐÐÐÅÏ¢ÍøÂçºÍºã¾Ã¼à¿Ø£¬ £¬£¬£¬£¬£¬²¢Îª½ÓÏÂÀ´µÄºáÏòÒÆ¶¯¹¥»÷Ìṩ»ù´¡¡£¡£¡£¡£


2.1 µØÇøÂþÑÜ


ͨ¹ý¶ÔÒÑÖªµÄSWEED×éÖ¯¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĹú¼ÒºÍµØÇøÂþÑÜÇéÐξÙÐÐͳ¼Æ£¨Èçͼ2-1£©£¬ £¬£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔ¿´µ½¸Ã×éÖ¯ÌᳫµÄ¹¥»÷»î¶¯ÁýÕÖÁËÐí¶à¹ú¼ÒºÍµØÇø£¬ £¬£¬£¬£¬£¬ÓÉ´ËÍÆ²â£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ¹¥»÷Ä¿µÄµØÀíλÖõÄÑ¡ÔñÉϲ¢Ã»ÓÐÌØ¶¨µÄÖ¸ÏòÐÔ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ2-1 Êܺ¦Õß¹ú¼ÒµØÇøÂþÑÜͼ


2.2 ÐÐÒµÂþÑÜ


ͳ¼ÆÐ§¹ûÏÔʾ£¨Èçͼ2-2£©£¬ £¬£¬£¬£¬£¬´Ë´ÎSWEED×éÖ¯ÔÚÃæÏòÈ«ÇòµÄ¹¥»÷ÖУ¬ £¬£¬£¬£¬£¬ÔËÊä¡¢ÖÆÔìÒµºÍÄÜÔ´ÐÐÒµÒÀÈ»ÊÇÆäÖØµãÕë¶ÔµÄÄ¿µÄ¹¤¾ß¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ2-2 Êܺ¦ÕßÐÐÒµÂþÑÜͼ


Èý¡¢¹¥»÷ÊÂÎñÆÊÎö


±¾Ð¡½Ú×ܽáÁ˸Ã×éÖ¯ÔÚ½üЩÄêµÄ¹¥»÷»î¶¯Ê±¼äµã¡¢´Ë´ÎÐж¯ÖÐʹÓõĹ¥»÷ÊÖ·¨ÒÔ¼°¹¥»÷Á÷³Ì¡£¡£¡£¡£


3.1 ¹¥»÷»î¶¯Ê±¼äÏß


ΪÁ˶ԺڿÍ×éÖ¯Ôڴ˴ι¥»÷»î¶¯Ê¹ÓõÄÕ½ÂÔºÍÊÖÒÕ¾ÙÐÐÖÜÈ«µÄÏàʶ£¬ £¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ADLabÑо¿Ö°Ô±½«ÏÖÔÚ¹ØÁªµ½µÄ¸Ã×éÖ¯½ü¼¸ÄêµÄÖ÷Òª»î¶¯×öÁËÊáÀíºÍ×ܽᣬ £¬£¬£¬£¬£¬²¢»æÖÆÁË¡°SWEED×éÖ¯¡±»î¶¯Ê±¼äÖᣨÈçͼ3-1£©¡£¡£¡£¡£´Óʱ¼äÖá¿ÉÒÔ¿´³ö£¬ £¬£¬£¬£¬£¬¸Ã×éÖ¯µÄ´ó²¿·Ö»î¶¯¶¼¾ßÓÐÒ»ÖÂÐÔ¡ª¡ª½èÖú´øÓжñÒ⸽¼þµÄÓã²æÊ½´¹ÂÚÓʼþ·Ö·¢Ô¶¿ØÄ¾Âí³ÌÐò£¨RAT£©£¬ £¬£¬£¬£¬£¬²¢ÇÒÐж¯ÖÐʹÓõÄľÂí³ÌÐòÖ÷ÒªÊÇÒÔAgent TeslaΪÖ÷¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ3-1 SWEED×éÖ¯Ïà¹Ø»î¶¯Ê±¼äÖá


3.2 ¹¥»÷ÊÖ·¨ºÍÌØµã


SWEED×éÖ¯ÔÚ³õʼ»·½ÚÖ÷ÒªÒÔͶµÝ´¹ÂÚÓʼþ×îÏÈÕö¿ª¹¥»÷£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚǰÆÚ¶ÔÄ¿µÄÓû§¾ÙÐÐÉîÈëµ÷ÑУ¬ £¬£¬£¬£¬£¬Ñ¡È¡ÓëÄ¿µÄÓû§ËùÊôÐÐÒµ»òÁìÓòÏà¹ØµÄÄÚÈÝÀ´½á¹¹ÓʼþºÍ¶ñÒâÎĵµ¡£¡£¡£¡£Ëæºó½«È«ÐÄÖÆ×÷µÄÖ÷ÌâÈ硱²É¹º¶©µ¥¡±¡¢¡°½ôÆÈÔËÊäÎļþ¡±¡¢¡±×°´¬Í¨Öªµ¥¡°µÈÎĵµÌí¼ÓÔÚÓʼþ¸½¼þÖз¢Ë͸øÄ¿µÄÓû§£¬ £¬£¬£¬£¬£¬ÓÕʹÆäÏÂÔØ¸½¼þ£¬ £¬£¬£¬£¬£¬Ä¿µÄÓû§Ò»µ©·­¿ª´øÓÐÎó²îµÄ¶ñÒâÎĵµ£¬ £¬£¬£¬£¬£¬´¥·¢Îó²îµÄ¶ñÒâ´úÂë¾Í½«»áÔÚºǫ́¾²Ä¬ÏÂÔØºÍÖ´ÐжñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬´Ó¶øÇÔȡĿµÄÓû§µÄÃô¸ÐÐÅÏ¢²¢¶ÔÆäÖ÷»ú¾ÙÐпØÖÆ¡£¡£¡£¡£


3.2.1 Óã²æÓʼþ


c7c7ÓéÀÖÆ½Ì¨ADLabͨ¹ý¶ÔSWEED×éÖ¯ÄêÍ·ÖÁ½ñµÄ¹¥»÷Ðж¯¾ÙÐмà²âºÍ¹ØÁªÆÊÎöºó£¬ £¬£¬£¬£¬£¬ÊáÀí³ö¼¸Ê®Æð¶¨ÏòÄ¿µÄµÄ¹¥»÷´¹ÂÚÓʼþ¡£¡£¡£¡£²¿·ÖÏà¹ØÓʼþÐÅÏ¢¼û±í3-1¡£¡£¡£¡£


±í3-1 ²¿·Ö´¹ÂÚÓʼþ°¸ÀýÐÅÏ¢


ʱ¼ä

ÓʼþÖ÷Ìâ

·¢¼þÈË

ÊÕ¼þÈË

2020Äê6ÔÂ10ÈÕ

RE : URGENT!!! 2 x 20ft - SHIPPING DOC BL,SI,INV#462345 //\r\n MAERSK KLEVEN V.949E // CLGQOE191781 //

"A.P. Moller ¨C Maersk"

nooreply@maersk.com

undisclosed-recipients

2020Äê6ÔÂ9ÈÕ

M/V BCC - Port Agency Appointment

InterTrans OPS¡± operation@inter-trans.co

jameshall@compasspub.com

2020Äê6ÔÂ8ÈÕ

AGENCY APPOINTMENT/ MV SHOTAN /DISCHARGING/PDA

df15ae634578@6b74fbd36.cn

9ed08@dcc762b7ba3.uk

2020Äê5ÔÂ17ÈÕ

PAYMENT ADVICE-TELEGRAPHIC

TRANSFER NO. M88SI1808BU00250

11@c7c7bacd336b.com

undisclosed-recipients

2020Äê4ÔÂ29ÈÕ

Purchase Order /APO-074787648

jane.hsieh@sealking.com.tw

gjchristopher@safeguard-technology.com

2020Äê4ÔÂ24ÈÕ

[ D.H.L ] Document Arrival  Notice

royalcrown_travel@hotmail.com

Anna.Chitan@linde.com

2020Äê4ÔÂ23ÈÕ

Shipment Arrival Notice

noreply@dhl.com

andrea.schilling@silloptics.de

2020Äê4ÔÂ21ÈÕ

SF Express£ºÄúµÄ°ü¹ü¸üÐÂ

no-reply@sendover.net

info@kraeber.de

2020Äê4ÔÂ7ÈÕ

Returned Payment MT103 Swift

shipping@angloeastern.com

undisclosed-recipients

2020Äê3ÔÂ24ÈÕ

RE: New Order (PO Ref: 01002020)

account@dongbuhitek.co.kr

undisclosed-recipients

2020Äê3ÔÂ23ÈÕ

RE: M/V BLUE LOTUS/NOON RPT

/VOY BL 03.20/ DD 24th

March 2020- APPOINTMENT REQUEST

shahid@erawanaircargo.com

undisclosed-recipients

2020Äê3ÔÂ17ÈÕ

RE : RE : URGENT SHIPPING DOC BL,SI,INV

462345//MAERSK KLEVEN

V.949E//CLGQOE191781//

nooreply@maersk.com

unrecognized@sys.redcondor.com

2020Äê3ÔÂ17ÈÕ

VSL: MV FORTUNE TRADER

Oriental Logistics Group Limited cindy@persadanusantara.co.id

undisclosed-recipients

2020Äê3ÔÂ16ÈÕ

New order by sea FO1909009

acct@gandptech.com

undisclosed-recipients

2020Äê3ÔÂ16ÈÕ

P.I, P.O/MT SR YUJIN (SYNTEK)

bright@kj-global.co.kr

undisclosed-recipients

2020Äê3ÔÂ9ÈÕ

RE: Refund of deposit

pffb@comsats.net.pk

undisclosed-recipients

2020Äê2ÔÂ21ÈÕ

WG: New Order

Anja.Sieveritz@hsm.eu

holthausen@einstein.br

2020Äê2ÔÂ19ÈÕ

RE 2 second lot FCL shipment #48897 Ex works price

Zhejiang Meto Electrical Co.

operations@labcosulich.com

2020Äê2ÔÂ19ÈÕ

Request For Quotation (RFQ-008342)

purchase@auronapharma.com

kbrooks@alpinecom.net

2020Äê2ÔÂ19ÈÕ

?? ?? (?? ??) ???? ??

usef3@hotmail.com

monstar1234@knps.or.kr

2020Äê2ÔÂ18ÈÕ

RE: Revised Cargo Receipts/Documents.

ojs@ojshipping.co.kr

undisclosed-recipients




̫ͨ¹ýÎöÕâЩÓÊÏä·¢¼þÈËËùÊô¹«Ë¾µÄ×¢²áÐÅÏ¢ÒÔ¼°Æä¹ÙÍøÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷´ó¶¼¹«Ë¾ÍøÕ¾¾ùΪÕýµ±ÍøÕ¾£¬ £¬£¬£¬£¬£¬ÓÉ´ËÍÆ²â¹¥»÷ÕßʹÓõÄÕâЩÓÊÏ䣬 £¬£¬£¬£¬£¬ÓпÉÄÜÀ´×Ô±»ÈëÇֺ͵ÁÓõÄÕýµ±ÊµÌå»òСÎÒ˽¼Ò¡£¡£¡£¡£ËäÈ»ÊÕ¼þÈ˵ÄÐÅÏ¢Ðí¶àÎÞ·¨¿´µ½£¬ £¬£¬£¬£¬£¬¿ÉÊÇ´ÓÓʼþµÄÖ÷ÌâÒÔ¼°ÕýÎÄÄÚÈݲ»ÄÑ¿´³ö£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÍýÏëʹÓÃÔËÊä»õÎïÇåµ¥¡¢×°Ïä½»»õ¼Ûµ¥¡¢ÎïÆ·µ½»õ֪ͨµ¥¡¢º£ÉÏж©µ¥µÈÓʼþÏòÔËÊäÉÌ¡¢ÖÆÔìÉ̼°ÆäÏàÖúÉ̾ÙÐÐÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯¡£¡£¡£¡£ÏÂÃæÎÒÃÇ´ÓÒÔÉÏÓʼþÖÐö¾ÙÒ»¸ö×ö¼òÆÓÆÊÎö¡£¡£¡£¡£


Ôڴ˰¸ÀýÖУ¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼʹÓá°VSL: MV FORTUNE TRADER¡±Ö÷Ìâð³ä¡°MV Fortune Trader¡±¡£¡£¡£¡£´¬²°FORTUNE TRADERÊÇÒ»ËÒ½¨ÓÚ1994ÄêµÄ¼¯×°Ïä´¬£¬ £¬£¬£¬£¬£¬¸Ã´¬²°µÄ×¢²á¹ú¼ÒΪº«¹ú¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-2 ´¬²°FORTUNE TRADERÏà¹ØÐÅÏ¢


ÓʼþÕýÎÄÓëÖ÷Ìâ¼á³ÖÒ»Ö£¬ £¬£¬£¬£¬£¬ÏÔʾ¸ÃÓʼþÊÇÀ´×Ô³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾¡£¡£¡£¡£¸Ã¹«Ë¾×ܲ¿Î»ÓŲ́Íą̊±±£¬ £¬£¬£¬£¬£¬Ö÷ÒªÌṩº£ÔË¡¢¿ÕÔ˺ÍÖиÛÔËÊäµÈÓªÒµ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-3 ³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾Ö÷Ò³


ÓʼþÕýÎÄÈçͼ3-4£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-4 ÓʼþÕýÎÄÐÅÏ¢


¶ÔÓʼþÐÅÏ¢¾ÙÐÐÆÊÎöºóÈçͼ 3-5Ëùʾ£¬ £¬£¬£¬£¬£¬·¢¼þÈ˵ÄÓʼþµØµãÊÇÓ¡¶ÈÄáÎ÷ÑÇÒ»¼ÒÃûΪ¡°PT.INTI PERSADA NUSANTARA¡±µç»ú×°±¸¹«Ë¾µÄÕýµ±Óò£¬ £¬£¬£¬£¬£¬¶ø¸ÃÓʼþÏÖʵÉÏÊÇÓÉÍйÜÔÚus10.rumahweb.comÉϵÄRoundcube WebÓʼþЧÀÍÆ÷·¢ËÍ¡£¡£¡£¡£ÕâÀïÊÕ¼þÈ˵صãÖ®ÒÔÊÇÏÔʾΪ¡°Undisclosed-Recipient¡±£¨µ¼ÖÂÎÞ·¨¿´µ½ÊÕ¼þÈËÐÅÏ¢£©£¬ £¬£¬£¬£¬£¬ÍƲ⹥»÷ÕßÊÇÔÚʹÓÃRoundcube Webmail/1.3.8Èí¼þȺ·¢Óʼþʱ£¬ £¬£¬£¬£¬£¬ÎªÁ˲»ÈÃÊÕ¼þÈË¿´µ½ÆäËûÎüÊÕÓʼþÈ˵ĵص㣬 £¬£¬£¬£¬£¬¹Ê½«´Ë´¦ÉèÖÃΪUndisclosed-Recipient¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-5 ²¿·ÖÓʼþÍ·²¿ÐÅÏ¢


3.2.2 ÓÕ¶üÎļþ


ͨ¹ý¶Ô¸ÃÅú½Ø»ñµÄÓʼþ¾ÙÐÐÆÊÎöËùµÃ£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓõĹ¥»÷ÔØºÉÀàÐÍ×ܹ²ÓÐËÄÖÖ¡£¡£¡£¡£ÏÂÃæ½«Ã¶¾Ùµä·¶µÄ¹¥»÷ÔØºÉ¼°ÆäËù¶ÔÓ¦µÄ´¹ÂÚÓʼþ¡£¡£¡£¡£


(1) Я´øÎó²îÎĵµ


ͼ3-6ÊÇÒ»·â¹¥»÷ÕßðÃûº½¿Õ»õÔ˹«Ë¾·¢Ë͸ø¿Í»§µÄÔ¤Ô¼ÇëÇ󻨏´Óʼþ£¬ £¬£¬£¬£¬£¬¸½¼þαװ³É´¬²°ÏêϸÐÅÏ¢±íµ¥¡£¡£¡£¡£¸ÃÎĵµÊ¹ÓÃ΢ÈíOffice¾­µäÎó²îCVE-2017-11882£¬ £¬£¬£¬£¬£¬µ±Óû§·­¿ª¶ñÒâÎĵµÊ±£¬ £¬£¬£¬£¬£¬Ç¶Èëµ½ÎĵµÖеĶñÒâ³ÌÐòÔò»á×Ô¶¯¼ÓÔØ¡£¡£¡£¡£¸ÃÎó²îµÄÌØµãÊÇÔÚÕû¸öÀú³ÌÖÐÓû§ÍêÈ«ÎÞ¸ÐÖª£¬ £¬£¬£¬£¬£¬ÇÒÔÚ¶ÏÍøµÄÇéÐÎÏÂÈÔÈ»¿ÉµÖ´ïÓÐÓù¥»÷£¬ £¬£¬£¬£¬£¬ÒÔÊdzÉΪ¸÷´óAPT×éÖ¯±ØÓÃÎó²îʹÓÿâÖ®Ò»¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-6 Я´øÎó²îÎĵµ°¸Àý1¡ªÓʼþ½ØÍ¼


£¨2£©Ð¯´øGZÃûÌõÄѹËõÎĵµ


ͼ3-7Êǹ¥»÷Õß·¢Ë͸ø×ܲ¿Î»ÓÚ±ÈÀûʱµÄÒ»¼Ò¶àÔª»¯µÄ¹¤ÒµÖÆÔìÉ̵ÄÓʼþ£¬ £¬£¬£¬£¬£¬¸ÃÓʼþʹÓÃÈÈÃŵÄCOVID-19ΪÖ÷Ì⣬ £¬£¬£¬£¬£¬²¢Í¨¹ýÕýÎÄÐÎò»Ñ³Æ¶ñÒ⸽¼þGZѹËõÎĵµÖаüÀ¨²É¹ºµ¥£¬ £¬£¬£¬£¬£¬ÓÕʹÊܺ¦ÕßÏÂÔØ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-7 Я´øGZÎĵµ°¸Àý2¡ªÓʼþ½ØÍ¼


¸½¼þÄÚÀïÊÇαװ³ÉbatÎļþµÄGuloaderÏÂÔØÆ÷¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-8 GZѹËõ°üÀïµÄÎļþ


£¨3£©Ð¯´øISOÃûÌõÄÎĵµ


ÓÉͼ 3-9¿É¼û£¬ £¬£¬£¬£¬£¬¹¥»÷Õß½«Óʼþ¸½¼þαװ³Éϵͳ¾µÏñISOÎļþ£¨Ê¹ÓÃISOÎļþ¿ÉÓÃÓÚÈÆ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£©£¬ £¬£¬£¬£¬£¬½«ÆäÃüÃûΪ¡°COVID-19½â¾ö¼Æ»®Ðû²¼¡±ÓÕÆ­Óû§µã»÷¡£¡£¡£¡£Ç¶ÈëÔÚISO¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþΪGuloaderÏÂÔØÆ÷¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-9 ISOѹËõ°üÀïµÄÎļþ


£¨4£©Ð¯´øhtmlÃûÌõÄÎļþ


ͼ3-10Êǹ¥»÷Õßð³äDHL Express¹ú¼Ê¿ìµÝ¹«Ë¾·¢Ë͸øµÂ¹úÒ»¼Ò¹âѧ×é¼þÖÆÔìÉ̵Ĵ¹ÂÚÓʼþ£¬ £¬£¬£¬£¬£¬Óʼþ¸½¼þ±»ÃüÃûΪװ´¬Í¨Öªµ¥²¢ÒÔhtmlÐÎʽÓÕÆ­Êܺ¦Õßµã»÷¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-10 Я´øhtmlÎļþ°¸Àý3¡ªÓʼþ½ØÍ¼



3.2.3 ¶ñÒâÈí¼þÍйÜλÖÃ


ÔÚ¹¥»÷»î¶¯ÖУ¬ £¬£¬£¬£¬£¬¹¥»÷Õß¾­³£Ê¹ÓÃÔ¶³ÌÉèÖÃÀ´¿ØÖƶñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬¶øÇ徲ְԱͨ¹ýÑо¿ÆÊÎö²î±ðµÄ¶ñÒâÈí¼þÉèÖã¨ÀýÈçÖ÷»úµØÀíλÖúÍDNSÐÅÏ¢£©£¬ £¬£¬£¬£¬£¬¿ÉÒÔÉîÈëµÄÏàʶºÍ×·×Ù¹¥»÷ÕßʹÓõĻù´¡ÉèÊ©¡£¡£¡£¡£ÎÒÃÇÔÚÑо¿Àú³ÌÖн«ÍøÂçµ½µÄ´ó×ÚÑù±¾Êý¾Ý¾ÙÐÐÌáÈ¡ºÍÕûºÏ£¬ £¬£¬£¬£¬£¬·¢Ã÷SWEED×éÖ¯´Ë´ÎʵÑé¹¥»÷Ðж¯ËùʹÓõĶñÒâÈí¼þÉèÖ㬠£¬£¬£¬£¬£¬Ö÷ÒªÓ¦ÓÃÁËGuloaderÏÂÔØÆ÷ÉèÖÃÑ¡ÏîÖеÄʹÓÃÔÆÐ§ÀÍ·Ö·¢¶ñÒâÈí¼þµÄ¹¦Ð§¡£¡£¡£¡£¹¥»÷ÕßÖ®ÒÔÊÇʹÓÃÕý¹æµÄÔÆ´æ´¢Æ½Ì¨À´ÍйܶñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬ÊÇÓÉÓÚÕâÐ©ÔÆÆ½Ì¨´ó¶¼ÊÇÊÜÐÅÈεÄÇÒÓÐÖúÓÚÈÆ¹ýÉÌÒµÍþв¼ì²â²úÆ·¡£¡£¡£¡£ËäÈ»Google DriveµÈÔÆÆ½Ì¨Í¨³£Ò²»áÖ´ÐзÀ²¡¶¾¼ì²â£¬ £¬£¬£¬£¬£¬µ«ÈôÊÇÓÐÓÃÔØºÉÊDZ»¼ÓÃܺóÔÙ´æ´¢£¬ £¬£¬£¬£¬£¬¾Í¿ÉÒÔ¶ã¹ý´ËÀàÏÞÖÆ£¬ £¬£¬£¬£¬£¬²¢ÄÜÓÐÓõÄ×èÖ¹Çå¾²Ö°Ô±¶ÔºÚ¿Í×éÖ¯µÄ»ù´¡ÉèÊ©¾ÙÐÐ×·×Ù¡£¡£¡£¡£Í¼3-11Ϊ¶ñÒâÔØºÉÑù±¾ÍÐ¹ÜÆ½Ì¨µÄʹÓÃÕ¼±ÈÂÊ¡£¡£¡£¡£Æ¾Ö¤Í¼ÖÐÏÔʾµÄÊýÖµ¿ÉµÃ£¬ £¬£¬£¬£¬£¬Google DriveΪ¶ñÒâÈí¼þÖ÷ҪʹÓõÄÍÐ¹ÜÆ½Ì¨¡£¡£¡£¡£³ý´ËÖ®Í⣬ £¬£¬£¬£¬£¬ÉÐÓв¿·Ö¶ñÒâÈí¼þ»áÍйÜÔÚÒѱ»¹¥ÏݵÄÕýµ±ÍøÕ¾ÉÏ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-11ÓÐÓÃÔØºÉÍÐ¹ÜÆ½Ì¨µÄʹÓÃÂÊ


³ýÁËGoogle DriveºÍOneDrive£¬ £¬£¬£¬£¬£¬ÏÂÃæÎÒÃÇö¾Ù³ö¼¸¸ö¹¥»÷ÕßʹÓÃµÄÆäËûÔÆÍÐ¹ÜÆ½Ì¨¡£¡£¡£¡£

files.fmÊÇÍâÑóÒ»¼ÒÌṩÎļþÔÆ´æ´¢Æ½Ì¨µÄÐÅÏ¢ÊÖÒÕ¹«Ë¾¡£¡£¡£¡£Í¼3-12ÊÇÉúÑÄÔÚ¸ÃÆ½Ì¨µÄ¼ÓÃܵĶñÒâÎļþ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-12 ÔÆÍÐ¹ÜÆ½Ì¨Àý1


sendspaceÊÇÒ»¼ÒÃâ·ÑÎļþÍÐ¹ÜÆ½Ì¨¡£¡£¡£¡£Í¼3-13Êǹ¥»÷ÕßÉÏ´«µ½¸Ãƽ̨¾ÙÐÐÍйܵĶñÒâÈí¼þ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ 3-13 ÔÆÍÐ¹ÜÆ½Ì¨Àý2


dmca.gripeÊÇÒ»¸öÃâ·ÑµÄÎļþÍÐ¹ÜÆ½Ì¨£¬ £¬£¬£¬£¬£¬ÆäÖ÷Ò³Èçͼ3-14Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ3-14 ÔÆÍÐ¹ÜÆ½Ì¨Àý3


3.3 ¹¥»÷Á÷³Ì


ÎÒÃǶÔÕâÅú¹¥»÷»î¶¯¾ÙÐйéÄÉÆÊÎöºó·¢Ã÷¾ø´ó²¿·Ö¹¥»÷¾ßÓÐÏàͬµÄ¹¥»÷Á÷³Ì£¬ £¬£¬£¬£¬£¬Æä¹¥»÷µÄÁ÷³ÌÈçͼ3-15¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


3-15 ¹¥»÷Á÷³Ìͼ


¹¥»÷Õßαװ³ÉÎïÁ÷»ò´¬²°µÈ¹«Ë¾Ö°Ô±£¬ £¬£¬£¬£¬£¬ÏòÄ¿µÄÆóҵͶµÝЯ´ø¸½¼þµÄ´¹ÂÚÓʼþ£¬ £¬£¬£¬£¬£¬¸½¼þÀàÐͰüÀ¨£º°üÀ¨Îó²îµÄ¶ñÒâÎĵµ¡¢GZÃûÌõÄѹËõ°ü¡¢ISOÎļþºÍHTMLÎļþ¡£¡£¡£¡£ÔÚ´ó¶¼ÇéÐÎÏ£¬ £¬£¬£¬£¬£¬ÕâЩ¸½¼þÔçÏȶ¼»á°üÀ¨»òÏÂÔØGuloaderÏÂÔØÆ÷£¨ÆäËûÇéÐÎÏÂΪԶ¿ØÄ¾Âí£©¡£¡£¡£¡£Guloader×îÏÈÖ´ÐÐʱ£¬ £¬£¬£¬£¬£¬ÏȶÔÖü±£´æ´úÂ벿·ÖµÄshellcode¾ÙÐнâÃÜ£¬ £¬£¬£¬£¬£¬ÔÙ½«½âÃܺóµÄshellcode×¢Èëµ½RegAsm.exeϵͳÎļþÖУ»£»£»£»½Ó×ÅRegAsm.exeÖеÄshellcodeÔÙ´ÓÖ¸¶¨µÄÔÆÆ½Ì¨µØµãÏÂÔØ¼ÓÃܵÄpayload£¬ £¬£¬£¬£¬£¬²¢ÔÚÄÚ´æÖнâÃÜÖ´ÐÐpayload£¨Ô¶¿ØÄ¾Âí£©£¬ £¬£¬£¬£¬£¬×îºóͨ¹ýC2¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì¿ØÖÆ¡£¡£¡£¡£


´Ë´Î¹¥»÷»î¶¯ÖÐʹÓõ½µÄÇÔÃܺÍÔ¶¿ØÄ¾Âí°üÀ¨£ºAgent Tesla£¨ÊÇÒ»¿î×ÅÃûµÄÉÌÒµÇÔȡľÂí£¬ £¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚä¯ÀÀÆ÷¡¢Óʼþ¿Í»§¶Ë¡¢FTP¹¤¾ß¡¢ÏÂÔØÆ÷µÈÓû§Õ˺ÅÃÜÂëºÍWiFiƾ֤µÄÇÔÈ¡¡£¡£¡£¡££©£»£»£»£»Formbook£¨ÊÇÒ»¿îÐÅÏ¢ÇÔȡľÂí£¬ £¬£¬£¬£¬£¬ÆäÖ÷ÒªÒÔÇÔÈ¡Óû§µçÄÔÉñÃØÐÅϢΪÖ÷£¬ £¬£¬£¬£¬£¬°üÀ¨¼üÅ̼ͼ¡¢¼ôÌù°å¼Í¼¡¢cookie»á»°ÓëÍâµØÃÜÂëµÈµÈ¡£¡£¡£¡££©£»£»£»£»Lokibot£¨Ò»¿îÇÔÃÜľÂí£¬ £¬£¬£¬£¬£¬Æäͨ¹ý´Ó¶àÖÖÊ¢ÐеÄÍøÂçä¯ÀÀÆ÷¡¢FTP¡¢µç×ÓÓÊÏä¿Í»§¶Ë¡¢ÒÔ¼°PuTTYµÈITÖÎÀí¹¤¾ßÖлñȡƾ֤£¬ £¬£¬£¬£¬£¬À´ÇÔÈ¡Óû§µÄÃÜÂëºÍ¼ÓÃÜÇ®±ÒÇ®°ü£©£»£»£»£»NanoCore£¨ÊÇÒ»¿î.net±àдµÄÔ¶¿ØÈí¼þ£¬ £¬£¬£¬£¬£¬Æä¾ßÓмüÅÌ¼à¿Ø¡¢ÊµÊ±ÊÓÆµ²Ù×÷¡¢ÓïÒô¡¢ÏÂÁîÐпØÖƵÈÍêÈ«¿ØÖÆÔ¶³ÌÖ÷»úµÄ¹¦Ð§¡£¡£¡£¡££©£»£»£»£»Remcos£¨Ò»¿îÔ¶¿ØÈí¼þ£¬ £¬£¬£¬£¬£¬°üÀ¨ÏÂÔØ²¢Ö´ÐÐÏÂÁî¡¢¼üÅ̼ͼ¡¢ÆÁÄ»¼Í¼ÒÔ¼°Ê¹ÓÃÉãÏñÍ·ºÍÂó¿Ë·ç¾ÙÐмÒô¼ÏñµÈ¹¦Ð§¡£¡£¡£¡££©¡£¡£¡£¡£


¼øÓÚÎÒÃÇÆÊÎöµÄÕâЩľÂíÔÚ¹¦Ð§ºÍÊÖÒÕÉÏÓë¾É°æÀàËÆ£¬ £¬£¬£¬£¬£¬²¢Ã»Óз¢Ã÷Ì«¶àµÄת±äµã£¬ £¬£¬£¬£¬£¬ÒÔÊÇÔÚ´ËÎÒÃǽö¶ÔÆäÖ÷Òª¹¦Ð§×öÁ˼òÆÓµÄÐÎò£¬ £¬£¬£¬£¬£¬±¾ÎĺóÐø±ã²»ÔÙ¹ý¶àµÄÏêϸÐÎòÆäÏêϸµÄÊÖÒÕϸ½Ú£¬ £¬£¬£¬£¬£¬ÈôÓÐÐèÒª¸÷ÈË¿ÉÉó²éÎÄÄ©µÄ²Î¿¼ÎÄÏס£¡£¡£¡£ÔÚϸöÕ½ڣ¬ £¬£¬£¬£¬£¬ÎÒÃÇÖ÷Òª¶ÔSWEED×éÖ¯ÐÂÒýÈëµÄGuloader¶ñÒâ´úÂë¾ÙÐÐÍêÕûÏêϸµØÆÊÎö¡£¡£¡£¡£


ËÄ¡¢ÊÖÒÕÆÊÎö


ÕýÈçǰÎÄËùÊö£¬ £¬£¬£¬£¬£¬ÎÒÃÇÏÖÔÚÍøÂçµ½µÄµç×ÓÓʼþµÄ¸½¼þÖ÷Òª·ÖΪËÄÀà¡£¡£¡£¡£ËäÈ»ÆäÊͷŶñÒâÈí¼þµÄÐÎʽ²î±ð£¬ £¬£¬£¬£¬£¬µ«ËüÃǵÄÖ÷Òª¹¦Ð§ÐÐΪ¶¼»ù±¾Ò»Ö¡£¡£¡£¡£ÔÚÕâÀ £¬£¬£¬£¬£¬ÎÒÃÇѡȡһ¸öµä·¶°¸Àý¾ÙÐÐÏêϸÆÊÎö¡£¡£¡£¡£


4.1 ´¹ÂÚÓʼþ


ͼ4-1Ϊ¹¥»÷ÕßÕë¶ÔÃÀ¹úÒ»¼Ò·À»¬²úÆ·ÖÆÔìÉ̾ÙÐй¥»÷µÄ´¹ÂÚÓʼþ£¬ £¬£¬£¬£¬£¬´ËÓʼþÓÚÃÀ¹úɽµØÊ±ÇøÊ±¼ä2020Äê4ÔÂ29ÈÕ£¨ÖÜÈý£©02:31±»·¢Ë͵½¸Ã¹«Ë¾¡£¡£¡£¡£ÓʼþÎÊÌâΪ¡°Purchase Order /APO-074787648¡±£¬ £¬£¬£¬£¬£¬ÕýÎÄÐÎòΪ¡°ÇëÉó²éÇåµ¥ºÍÈ·ÈÏÉÌÆ·¿â´æ¡±£¬ £¬£¬£¬£¬£¬²¢¸½ÓÐͬÃû¶ñÒâÎĵµ¡°Purchase Order /APO-074787648¡±¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-1 ´¹ÂÚÓʼþÄÚÈÝ


4.2 ¶ñÒâÎĵµ


Ñù±¾¡°Purchase Order /APO-074787648.ppsx¡±Ê¹ÓÃÁËɳ³æÎó²îCVE-2014-4114µÄ²¹¶¡£¡£¡£¡£¨MS14-060£©ÈƹýÎó²îCVE-2014-6352¡£¡£¡£¡£É³³æÎó²îÊÇWindows OLEí§Òâ´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬£¬£¬¸ÃÎó²î·ºÆðÔÚMicrosoft WindowsЧÀÍÆ÷ÉϵÄOLE°ü¹ÜÀíÆ÷ÉÏ¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓøÃÎó²îÔÚOLE´ò°üÎļþ£¨packer.dll£©ÖÐÏÂÔØ²¢Ö´ÐÐÀàËÆµÄINFÎļþ£¬ £¬£¬£¬£¬£¬À´µÖ´ïÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ¡£¡£¡£¡£ËäȻ΢ÈíΪɳ³æÎó²îÐû²¼²¹¶¡£¡£¡£¡£¨MS14-60£©£¬ £¬£¬£¬£¬£¬µ«¹¥»÷Õß»¹¿Éͨ¹ý½á¹¹Ìض¨µÄCLSIDºÍOLE VerbÀ´ÈƹýMS14-160²¹¶¡µÄÏÞÖÆ£¨CVE-2014-6352£©¡£¡£¡£¡£ÏÂÃæÎÒÃÇÒÔ±¾´ÎÐж¯ÖÐʹÓõĶñÒâÎĵµÎªÀý£¬ £¬£¬£¬£¬£¬¶Ô¸ÃÎó²îµÄʵÏÖÔ­Àí×ö¼òÆÓµÄÆÊÎö¡£¡£¡£¡£


ͼ4-2Ϊ´Ë°¸ÀýÖÐʹÓõÄppsxÎó²î¹¥»÷ÎĵµÄÚÈÝ¡£¡£¡£¡£




c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4-2 ppsxÎó²îÎĵµÄÚÈÝ


ÎÒÃǽâѹPPXSÎĵµ¿ÉÒÔ¿´µ½£¬ £¬£¬£¬£¬£¬ÔÚ¡°Purchase Order APO-074787648.ppsx\ppt\slides \slides.xml¡±ÖУ¬ £¬£¬£¬£¬£¬Ö¸¶¨ÁËǶÈëµÄ¹¤¾ßid=rld3¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-3 ¡°slides.xml¡±ÎļþÄÚÈÝ


ÔÚ¡°Purchase Order APO-074787648\ppt\slides\_rels\slide1.xml.rels¡±ÖÐÖ¸¶¨ÁËrld3¶ÔÓ¦¡°ppt\embeddings\¡±Ä¿Â¼ÏµÄoleObject1.binÎļþ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-4 ¡°slide1.xml.rels¡±ÎļþÄÚÈÝ


¡°Purchase Order APO-074787648.ppsx\ppt\embeddings\¡±Ä¿Â¼Ïµġ°oleObject1.bin¡±ÎļþÄÚǶһ¸öOLE Package¹¤¾ß£¬ £¬£¬£¬£¬£¬Ç¶ÈëÎļþΪPE¿ÉÖ´ÐгÌÐò¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-5 ¡°oleObject1.bin¡±ÎļþÄÚÈÝ


CVE-2014-4114Îó²îµÄ³ÉÒòÊÇpackager.dllÖÐCPackage::LoadÒªÁì¼ÓÔØ¶ÔÓ¦µÄOLE¸´ºÏÎĵµ¹¤¾ßʱ£¬ £¬£¬£¬£¬£¬Õë¶Ô²î±ðÀàÐ͵ĸ´ºÏÎĵµ¾ÙÐвî±ðµÄ´¦Öóͷ£Á÷³Ì£¬ £¬£¬£¬£¬£¬µ«ÆäÖжÔijЩ¸´ºÏÎĵµÖÐǶÈëµÄ²»¿ÉÐÅȪԴÎļþûÓÐ×ö´¦Öóͷ£¡£¡£¡£¡£Óɴ˹¥»÷Õß¿ÉʹÓÃαÔìOLE¸´ºÏÎĵµµÄCLSIDÀ´µÖ´ïÖ´ÐÐÌØ¶¨ÎļþµÄÄ¿µÄ¡£¡£¡£¡£Î¢ÈíÔÚMS14-060²¹¶¡ÖУ¬ £¬£¬£¬£¬£¬Í¨¹ýÌí¼ÓMarkFileUnsafeº¯Êý¶ÔÎļþ¾ÙÐÐMOTW´¦Öóͷ££¬ £¬£¬£¬£¬£¬½«ÆäSecurity Zone±ê¼ÇΪ¡°´ËÎļþÀ´×ÔÆäËûÅÌËã»ú¡±£¬ £¬£¬£¬£¬£¬ÔËÐÐʱ»áµ¯³öÇå¾²ÖÒÑÔ´°¿Ú¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4-6 ¡°%TEMP%\NEW ORDER.exe¡±±ê¼ÇΪ²»¿ÉÐÅÎļþ


µ«¾ÍËãÊܺ¦ÕßÒÑ×°ÖÃMS14-060µÄ²¹¶¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÕվɿÉÒÔͨ¹ý½á¹¹Ìض¨µÄCLSIDºÍOLE VerbÀ´¸Ä±äÖ´ÐÐÁ÷³Ì£¬ £¬£¬£¬£¬£¬´Ó¶øÈƹý¸Ã²¹¶¡£¡£¡£¡£¨CVE-2014-6352Îó²î£©¡£¡£¡£¡£¹ØÓÚÒ»¸öexeÎļþ£¬ £¬£¬£¬£¬£¬×ÝÈ»±»±ê¼ÇΪURLZONE_INTERNET£¬ £¬£¬£¬£¬£¬ÓÒ¼üµã»÷ÒÔÖÎÀíԱȨÏÞÖ´ÐиÃexeÎļþ£¬ £¬£¬£¬£¬£¬Äǵ±³ÌÐòÔËÐÐʱ±ã²»»áÔÙµ¯³ö¡°Çå¾²ÖÒÑÔ¡±£¨Èçͼ4-6£©µÄÌáÐÑ£¬ £¬£¬£¬£¬£¬¶øÊÇÒÔ£¨Èçͼ4-7£©UAC ÌáÐÑ´°µ¯³ö¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4-7 µ¯³öµÄUACÌáÐÑ´°


  ÓÉ´Ë¿ÉÖª£¬ £¬£¬£¬£¬£¬µ±Êܺ¦Õß·­¿ª´ËPPSX¶ñÒâÎĵµÊ±£¬ £¬£¬£¬£¬£¬×Ô¶¯²¥·Åģʽ±ã»á¿ªÆô£¬ £¬£¬£¬£¬£¬Í¬Ê±¡°%TEMP%\NEW ORDER.exe¡±½«±»ÊÍ·ÅÔÚÔÝʱĿ¼ÖС£¡£¡£¡£ÈôÊÇÊܺ¦ÕßÑ¡Ôñ¡°ÊÇ¡±£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂ뽫»á±»Ö´ÐС£¡£¡£¡£¶øÈôÊÇÊܺ¦ÕßµÄϵͳ´¦ÓÚUAC¹Ø±Õ״̬»òÔÚ»ñÈ¡ÁËÖÎÀíԱȨÏÞµÄÇéÐÎÏ£¬ £¬£¬£¬£¬£¬¸ÃUACÇå¾²ÖÒÑÔ´°¿ÚÔò²»»áµ¯³ö£¬ £¬£¬£¬£¬£¬¡°NEW ORDER.exe¡±»á±»¾²Ä¬µØÖ´ÐС£¡£¡£¡£



4.3 GuLoader


ÈçÉÏÎÄËùÊö£¬ £¬£¬£¬£¬£¬×îºó±»Ö´Ðеġ°NEW ORDER.exe¡±¿ÉÖ´ÐÐÎļþÏÖʵÉϼ´ÊÇÎÄÕ¿ªÍ·Ìáµ½µÄGuloader¶ñÒâÈí¼þ£¨ÔÚºóÐø¶Ô¡°NEW ORDER.exe¡±µÄÏêϸÆÊÎöÖУ¬ £¬£¬£¬£¬£¬ÎÒÃǾùʹÓá°Guloader¡±À´Ìæ»»¸ÃÎļþÃû£©¡£¡£¡£¡£GuloaderÊÇÒ»¿îÐÂÐ͵ĶñÒâÈí¼þÏÂÔØÆ÷£¬ £¬£¬£¬£¬£¬Æä×Ô¼º¾ßÓÐÖØ´óµÄÖ´ÐÐÁ÷³Ì£¬ £¬£¬£¬£¬£¬Í¨¹ý½ÓÄÉÖÖÖÖ´úÂë»ìÏýºÍËæ»ú»¯¡¢·´É³Ïä¡¢·´µ÷ÊÔºÍÊý¾Ý¼ÓÃܵȻúÖÆÀ´¶Ô¿¹Çå¾²²úÆ·µÄ¼ì²â¡£¡£¡£¡£ÏÂÃæÎÒÃǽ«¶Ô¸ÃGuLoader¾ÙÐÐÉîÈëµÄÍÚ¾òÆÊÎö¡£¡£¡£¡£


4.3.1 Ö´ÐÐÁ÷³Ì


Èçͼ4-8Ëùʾ£¬ £¬£¬£¬£¬£¬ GuLoaderÊ×ÏȽ«Öü±£´æ´úÂ벿·ÖµÄ¼ÓÃÜShellcode½âÃܲ¢Ö´ÐС£¡£¡£¡£Õâ¶ÎShellcodeµÄÖ÷Òª¹¦Ð§Îª£ºÒÔ¹ÒÆð·½·¨½¨ÉèÒ»¸öϵͳ×ÓÀú³Ì£¬ £¬£¬£¬£¬£¬Ö®ºó½«±¾¶ÎShellcode×ÔÉí×¢Èëµ½×ÓÀú³Ì²¢Ð޸ijÌÐòÈë¿ÚµãΪShellcode´¦Ö´ÐС£¡£¡£¡£×îºó´ÓÍйÜЧÀÍÆ÷ÉÏÏÂÔØ¼ÓÃܵÄBINÎļþ£¬ £¬£¬£¬£¬£¬ÀÖ³ÉÏÂÔØºó½«Æä½âÃܺÍÔËÐС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-8 GuloaderÖ´ÐÐÁ÷³Ìͼ


4.3.2 EXE¿ÉÖ´ÐÐÎļþ


£¨1£©´úÂë»ìÏý

Guloader¿ÉÖ´ÐÐÎļþÊÇÓÉVisual Basic 6ÓïÑÔ±àдµÄ¡£¡£¡£¡£Ê¹Óù¤¾ßÉó²éºó·¢Ã÷£¬ £¬£¬£¬£¬£¬Æä²¢Î´Ê¹ÓÃÉÌÒµ¿Ç¾ÙÐÐ×ÔÉí±£»£»£»£»¤£¬ £¬£¬£¬£¬£¬¶øÊÇʹÓûìÏý¿ÇʵÑé¶Ô¿¹Çå¾²²úÆ·µÄ²éɱ¡£¡£¡£¡£ÓÉÓÚɱÈí¶ÔÉÌÒµ¿Ç½ÏÁ¿Ãô¸Ð£¬ £¬£¬£¬£¬£¬²¢ÇÒÉÌÒµ¿Ç¼ì²âºÍÍÑ¿ÇÊÖÒÕÒ²½ÏÁ¿³ÉÊ죬 £¬£¬£¬£¬£¬ÒÔÊÇ»ìÏý¿Ç²»Ê§ÎªÒ»¸ö²»´íµÄÑ¡Ôñ¡£¡£¡£¡£»£»£»£»ìÏý¿ÇÒ»Ñùƽ³£²»±£´æÍ¨Óõļì²âÒªÁ죬 £¬£¬£¬£¬£¬²¢ÇÒ¾²Ì¬ÍÑ¿ÇÏà¶Ô½ÏÄÑ£¬ £¬£¬£¬£¬£¬ÒÔÊÇÆä¶ñÒâÐÐΪ²»Ò×±»·¢Ã÷£¬ £¬£¬£¬£¬£¬´Ó¶ø¿É³¤Ê±¼äµÄ´æ»îÔÚÄ¿µÄ»úеÉÏ¡£¡£¡£¡£¹ØÓÚÄæÏòÆÊÎöÖ°Ô±À´½²£¬ £¬£¬£¬£¬£¬ÆÊÎöÕâÖÖ´ø»ìÏý¿ÇµÄÑù±¾ÍùÍù»áÆÆ·Ñ´ó×ڵľ«Éñ£¬ £¬£¬£¬£¬£¬ÎÞÐεÄÔöÌíÁËÈËÁ¦ºÍʱ¼ä±¾Ç®¡£¡£¡£¡£


ͼ4-9ÊÇÒ»¶Î»ìÏý´úÂëµÄ½ØÈ¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬Õⲿ·Ö´úÂëʹÓÃÁËÊý¾Ý»ìÏýÖеij£Á¿²ð·Ö£¬ £¬£¬£¬£¬£¬Ö÷ҪĿµÄÊÇÒþ²ØÕæÊµµÄ´úÂëÂß¼­£¬ £¬£¬£¬£¬£¬ÈÃÆÊÎöÕßÐÄÌï±¼À£¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4-9 ²¿·Ö»ìÏý´úÂë


£¨2£©´úÂë½âÃÜ


¶ñÒâÈí¼þÊ×ÏÈÅÌËã³öÓÃÓÚ½âÃÜshellcodeµÄÃÜÔ¿£¬ £¬£¬£¬£¬£¬ÆäֵΪ£º0x24EBE470¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-10 »ñÈ¡ÃÜÔ¿µÄ¶ñÒâ´úÂë


½Ó×Å£¬ £¬£¬£¬£¬£¬ÎªshellcodeÉêÇëÄÚ´æ¿Õ¼ä£¬ £¬£¬£¬£¬£¬ÔÙʹÓÃÃÜÔ¿¾ÙÐÐXORÔËËã½âÃÜShellcode²¢Ö´ÐС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-11 ½âÃܺÍÖ´ÐÐshellcode


4.3.3 ShellCode


½âÃܺóµÄshellcodeǰÆÚÒ²½ÓÄÉÁË´ó×ڵĶԿ¹ÊֶΣ¬ £¬£¬£¬£¬£¬Ê¹ÓÃÖÖÖÖ´úÂë»ìÏý¡¢É³Ïä¼ì²â¡¢·´µ÷ÊÔµÈÊÖÒÕÊÖ¶ÎÀ´¹æ±ÜÇå¾²²úÆ·µÄÐÐΪ¼à²âºÍ²éɱ¡£¡£¡£¡£½öµ±Í¨¹ýÖÖÖÖ¼ì²éÅжÏÌõ¼þºó£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂë²Å×îÏÈÖ´ÐÐÖ÷¹¦Ð§ÐÐΪ¡£¡£¡£¡£ÏÂÃæÎÒÃǽ«¶Ô¶ñÒâ´úÂë×öÏêϸµÄÆÊÎö¡£¡£¡£¡£


£¨1£©¼ì²â¹¦Ð§


¡ñ ´úÂë»ìÏý

½«½âÃܺóµÄshellcode´ÓÄÚ´æÖÐdump³öÀ´²¢Ê¹ÓÃIDA·´±àÒ룬 £¬£¬£¬£¬£¬¿ÉÒÔ¿´µ½shellcodeÖÐʹÓõĻìÏýÊÖÒÕ¡£¡£¡£¡£¶ñÒâ´úÂëÔÚÖ´ÐÐÀú³ÌÖвåÈë»ìÏýº¯Êý£¬ £¬£¬£¬£¬£¬¸Ãº¯ÊýµÄÀú³Ì±»Ö§½â³É¶à¸öÌø×ªÁ÷³Ì£¬ £¬£¬£¬£¬£¬Ò»Ö±µ½×îºóÔÙ jmpµ½Ô­À´µÄÕý³£´úÂëÖмÌÐøÖ´ÐÐÏÂÃæµÄÁ÷³Ì¡£¡£¡£¡£Í¼4-12ÊÇshellcodeÔÚÈë¿Ú´¦Å²ÓõĴËÀà»ìÏýº¯ÊýµÄ´úÂëÆ¬¶Ï£¬ £¬£¬£¬£¬£¬ºÜÏÔȻͨ¹ý¸ÃÒªÁ죬 £¬£¬£¬£¬£¬Äܹ»ÓÐÓõÄÈÅÂÒÆÊÎöÕß¶ÔÑù±¾¾ÙÐÐÆÊÎö£¬ £¬£¬£¬£¬£¬ÑÏÖØ½µµÍÁËÆÊÎöЧÂÊ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4-12 »ìÏýºóµÄ´úÂëÆ¬¶Ï


¡ñ ¶¯Ì¬»ñÈ¡APIº¯Êý


½Ó×Å£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëͨ¹ý»á¼ûPEB->LDRÖеÄInMemoryOrderModuleList»ñÈ¡kernel32.dllµÄ»ùÖ·¡£¡£¡£¡£±éÀúÌáÈ¡¸ÃÄ£¿£¿£¿éµ¼³ö±í½á¹¹Öдæ·Åº¯ÊýÃûµÄÊý×飬 £¬£¬£¬£¬£¬²¢ÒÀ´Î½«Ãû³Æ×Ö·û´®×÷Ϊ²ÎÊý´«Èëµ½¹þÏ£Ëã·¨º¯ÊýÖÐ×öÔËË㣬 £¬£¬£¬£¬£¬ÔÙ½«Ð§¹ûÓëÓ²±àÂëÊý¾Ý×ö½ÏÁ¿£¬ £¬£¬£¬£¬£¬ÒÔ´ËÒªÁìÀ´²éÕÒGetProcAddressº¯Êý¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-13 ²éÕÒGetProcAddressº¯Êý


´Ë´¦Ê¹ÓõÄÊÇdjb2µÄËã·¨£¬ £¬£¬£¬£¬£¬ djb2ÊÇÒ»¸ö±¬·¢Ëæ»úÂþÑܵĹþÏ£º¯Êý£¬ £¬£¬£¬£¬£¬ÓëLCGµÄËã·¨ÏàËÆ¡£¡£¡£¡£ÓÉÓڸú¯Êý½á¹¹¼òÆÓ£¬ £¬£¬£¬£¬£¬Ê¹ÓÃÒÆÎ»ºÍÏà¼ÓµÄ²Ù×÷£¬ £¬£¬£¬£¬£¬ÒÔÊdz£±»ÓÃÀ´´¦Öóͷ£×Ö·û´®¡£¡£¡£¡£ÏêϸËã·¨¼ûͼ4-14¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-14 djb2Ëã·¨´úÂë½ØÍ¼


ÓÉ´ËÎÒÃÇ¿ÉÒÔ¿´µ½£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔÚº¯ÊýµÄ»ñÈ¡·½ÃæÊÇʹÓÃLoadLibraryºÍGetProcAddressÕâÁ½¸öº¯Êý¾ÙÐж¯Ì¬µÄ»ñÈ¡¡£¡£¡£¡£ÏêϸÈçͼ4-15Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-15 ¶¯Ì¬»ñÈ¡APIº¯Êý


¡ñ É³Ïä¼ì²â


¶ñÒâ´úÂëö¾Ù´°¿ÚÊýÄ¿£¬ £¬£¬£¬£¬£¬ÈôÊÇֵСÓÚ12ÔòÍ˳öÀú³Ì£¬ £¬£¬£¬£¬£¬ÒÔ´ËÀ´¼ì²â×ÔÉíÊÇ·ñÔËÐÐÔÚɳÏäÇéÐÎÖС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-16 ɳÏä¼ì²â´úÂë


¡ñ ·´µ÷ÊÔÊÖÒÕ


ÒªÁì1£º

ŲÓÃZwProtectVirtualMemoryº¯ÊýÐÞ¸Äntdll.dllµÄ¡°.text¡±½ÚÊôÐÔΪ¿É¶Á¿Éд¿ÉÖ´ÐС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-17 ÐÞ¸Äntdll.dll½ÚÊôÐÔ


¶ñÒâ´úÂëͨ¹ýÐÞ¸ÄDbgBreakPointºÍ DbgUiRemoteBreakinº¯Êý´úÂ룬 £¬£¬£¬£¬£¬Èõ÷ÊÔÆ÷ÎÞ·¨¸½¼Óµ÷ÊÔ³ÌÐò£¨Èçͼ4-18ºÍͼ4-19£©¡£¡£¡£¡£¸øcallŲÓúóÃæÖ¸¶¨Ò»¸öδ֪µØµã£¬ £¬£¬£¬£¬£¬ÒÔ´ËÒý·¢µ÷ÊÔÆ÷Íß½âÍ˳ö¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-18 DbgBreakPointº¯Êý´úÂëÐÞ¸Äǰºó±ÈÕÕ


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-19 DbgUiRemoteBreakinº¯Êý´úÂëÐÞ¸Äǰºó±ÈÕÕ


ÒªÁì2£º

½«ZwSetInformationThreadº¯ÊýµÄµÚ¶þ¸ö²ÎÊýÉèÖÃΪThreadHideFromDebugger £¨ÖµÎª17£©£¬ £¬£¬£¬£¬£¬×÷ÓÃÊÇÔÚµ÷ÊÔ¹¤¾ßÖÐÒþ²ØÏ̡߳£¡£¡£¡£ÈôÊǶñÒâÈí¼þ´¦ÓÚ±»µ÷ÊÔ״̬£¬ £¬£¬£¬£¬£¬ÄÇô¸Ãº¯Êý¾Í»áʹĿ½ñỊ̈߳¨Ò»Ñùƽ³£ÊÇÖ÷Ị̈߳©ÍÑÀëµ÷ÊÔÆ÷£¬ £¬£¬£¬£¬£¬Ê¹µ÷ÊÔÆ÷ÎÞ·¨¼ÌÐøÎüÊÕ¸ÃÏ̵߳ĵ÷ÊÔÊÂÎñ¡£¡£¡£¡£Ð§¹û¾ÍÏñÊǵ÷ÊÔÆ÷Íß½âÁËÒ»Ñù¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-20 Òþ²ØÏ̵ִ߳ﷴµ÷ÊÔÄ¿µÄ


ÒªÁì3£º

ÔÚʹÓÃZwAllocateVirtualMemoryº¯ÊýÉêÇëÄÚ´æ¿Õ¼äʱ£¬ £¬£¬£¬£¬£¬Îª±ÜÃâÆÊÎöÖ°Ô±ÔÚµ÷ÊÔʱ¶ÔÒªº¦º¯Êý϶ϵ㣬 £¬£¬£¬£¬£¬¶ñÒâ´úÂë»áÌáǰ½«¸Ãº¯ÊýµÄ¹¦Ð§ÊµÏÖ´úÂë¸´ÖÆµ½±¾Àú³Ì¿ÕÏпռäÖУ¬ £¬£¬£¬£¬£¬Ê¹µÃºóÐøÔÚʹÓô˺¯Êýʱֱ½ÓÌø×ªµ½×ÔÉí´úÂëÖÐÖ´ÐС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-21 ¸´Öƺ¯Êý¹¦Ð§ÊµÏÖ´úÂë


ÒªÁì4£º

ÔÚŲÓò¿·ÖÃô¸ÐAPIº¯Êýʱ£¬ £¬£¬£¬£¬£¬»áÏÈŲÓÃ×Ô½ç˵µÄ¼ì²éº¯Êý×öÅжϣ¬ £¬£¬£¬£¬£¬ÒÔïÔÌ­±»Çå¾²²úÆ·¼ì²âµÄ¼¸ÂÊ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-22 ¼ì²éº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³


¸Ã×Ô½ç˵µÄ¼ì²éº¯ÊýµÄÖ÷Òª¹¦Ð§£º

¢Ù ½«Å²Óøú¯ÊýǰµÄshellcode´úÂ루ÕýÐò£©°´×Ö½ÚÓë0x4×ֽڵķµ»ØµØµã×öÒì»òÔËËã ¾ÙÐмÓÃÜ´¦Öóͷ££»£»£»£»

¢Ú ŲÓÃZwGetContectThreadº¯Êý£¬ £¬£¬£¬£¬£¬Í¨¹ý¼ì²é_CONTEX½á¹¹ÖеÄDr¼Ä´æÆ÷À´ÅжÏÊÇ·ñ   ÔÚµ÷ÊÔÇéÐÎÖУ»£»£»£»

¢Û Åжϴ˴ÎÒª¼ì²éµÄÒªº¦APIº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³¡£¡£¡£¡£ÈôÊÇЧ¹ûΪ·ñ£¬ £¬£¬£¬£¬£¬ÔòŲÓøÃAPIº¯

Êý£¬ £¬£¬£¬£¬£¬²»È»³ÌÐòÖ±½ÓÍß½âÍ˳ö£»£»£»£»

¢Ü ͬ¡°ÒªÁì¢Ù¡±¶Ôshellcode´úÂ루µ¹Ðò£©¾ÙÐнâÃܲ¢Ìø×ªµ½·µ»ØµØµã´¦Ö´ÐкóÐøÁ÷³Ì¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-23 ×Ô½ç˵¼ì²éº¯Êý´úÂë


£¨2£©¶ñÒâÐÐΪִÐй¦Ð§

ÈôÊÇÒÔÉÏһϵÁеÄɳÏäÒÔ¼°·´µ÷ÊÔ¼ì²â¶¼Í¨¹ý£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔò×îÏÈÖ´ÐÐÒÔÏÂÓγ̣º

¢Ù ¶¯Ì¬»ñȡͼ4-24ÖеÄAPIº¯Êý£¬ £¬£¬£¬£¬£¬²¢½«º¯ÊýŲÓõصãÉúÑÄÔÚ¿ÍÕ»ÖС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-24 ¶¯Ì¬»ñÈ¡µÄAPIº¯ÊýÃû³Æ


¢Ú ƾָ֤¶¨µØµã´¦ÉúÑĵÄÊý¾ÝÄÚÈÝÌØÕ÷£¨ÈôÊǶñÒâ´úÂëδִÐйý½¨Éè×ÓÀú³ÌÁ÷³Ì£¬ £¬£¬£¬£¬£¬ÄÇ Ã´¸ÃµØµã´¦Ô­Êý¾ÝΪÎÞЧÄÚÈÝ£»£»£»£»²»È»£¬ £¬£¬£¬£¬£¬´Ë´¦ÉúÑĵÄÊÇÄ¿½ñÀú³ÌµÄȫ·¾¶¡£¡£¡£¡££©À´ÅжÏÊÇ ·ñÐèÒª½¨Éè×ÓÀú³Ì¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-25 ÅжÏÊÇ·ñÐèÒª½¨Éè×ÓÀú³Ì


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-26 ¶ÔÖ¸¶¨µØµã´¦ÉúÑĵÄÊý¾ÝÄÚÈÝ×öÅжÏ


¢Û ŲÓÃCreateProcessInternalº¯ÊýÒÔ¹ÒÆðģʽ½¨ÉèRegAsm.exeÀú³Ì¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-27 ½¨Éèϵͳ×ÓÀú³Ì


¢Ü ŲÓÃZwOpenFileº¯Êý£¬ £¬£¬£¬£¬£¬»ñµÃÓ³ÉäÎļþmstsc.exeµÄ¾ä±ú¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-28 »ñÈ¡mstsc.exeµÄ¾ä±ú


¢Ý ʹÓÃZwCreateSectionºÍNtMapViewOfSectionº¯Êý½«¡°mstsc.exe¡±ÎļþÓ³Éäµ½

RegAsm.exeÄÚ´æÖеÄ0x00400000λÖÃÉÏ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-29 Ó³ÉäÎļþ


¢Þ ÔÚ¿þÀÜÀú³ÌÖÐÉêÇëÄÚ´æ¿Õ¼ä£¬ £¬£¬£¬£¬£¬²¢½«ÎÒÃÇÕýÔÚµ÷ÊÔµÄÕû¸öshellcodeдÈ뵽ĿµÄÄÚ´æÖС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-30 дÈëshellcodeµ½ÏµÍ³×ÓÀú³ÌÖÐ


¢ß ʹÓÃZwGetContextThreadºÍZwSetContextThreadº¯Êý£¬ £¬£¬£¬£¬£¬»ñÈ¡ºÍÐÞ¸Ä¹ÒÆðµÄ×Ó Ïß³ÌÉÏÏÂÎÄÖмĴæÆ÷Öµ£¬ £¬£¬£¬£¬£¬ÒÔʵÏÖÖØ¶¨Ïòµ½shellcodeÈë¿Ú´¦Ö´ÐеÄÄ¿µÄ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-31 ÐÞ¸Äϵͳ×ÓÀú³ÌµÄÖ´ÐÐÈë¿Úµã


¢à Èô¡°°ì·¨¢Ý¡±²Ù×÷Àֳɣ¬ £¬£¬£¬£¬£¬Ôò»Ö¸´Ö´ÐÐ×ÓÀú³Ì£»£»£»£»²»È»¿¢ÊÂÄ¿½ñ³ÌÐò¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-32 Åжϰ취¢ÝÊÇ·ñ²Ù×÷ÀÖ³É


£¨3£©ÀÖ³É×¢Èëºó¶ñÒâÐÐΪ¹¦Ð§

ÎÒÃÇÔÚ¶ñÒâ´úÂëŲÓÃNtResumeThreadº¯Êýǰ£¬ £¬£¬£¬£¬£¬¸½¼ÓRegAsm.exeÀú³Ì²¢ÔÚ×¢ÈëµÄshellcodeÖ´Ðд¦ÉèÖöϵ㣨Èçͼ4-33£©£¬ £¬£¬£¬£¬£¬È»ºóÔÙ¼ÌÐøÖ´Ðиú¯ÊýÀ´»Ö¸´Ïß³ÌÔËÐС£¡£¡£¡£¸Ãshellcodeǰ²¿·ÖÓë֮ǰµÄ²Ù×÷Á÷³ÌÏàͬ£¬ £¬£¬£¬£¬£¬½«Ç°ÎÄÐÎòµÄÖÖÖÖ¼ì²âÖØÐÂÖ´ÐÐÒ»±é£¬ £¬£¬£¬£¬£¬Ö±µ½ÔÚ¡°ÅжÏÊÇ·ñ½¨Éè×ÓÀú³Ì¡±´¦Ìø×ªµ½ÁíÍâµÄ·ÖÖ§Á÷³Ì¡£¡£¡£¡£ÏÂÃæÎÒÃǼÌÐø¶ÔºóÐø¹¦Ð§¾ÙÐÐÏêϸµØÆÊÎö¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-33 ShellcodeÖ´Ðд¦´úÂë


ÅжϿªÆôRegAsm.exe³ÌÐòµÄ¸¸Àú³ÌÊÇ·ñΪ¡°C:\Users\***\directory\filename.exe¡±¡£¡£¡£¡£

ÈôÊDz»ÊÇ£¬ £¬£¬£¬£¬£¬Ôò½«Ä¿½ñ¸¸Àú³ÌÎļþ¸´ÖƵ½¸ÃĿ¼ÖУ¬ £¬£¬£¬£¬£¬½«ÆäÃüÃûΪfilename.exe²¢ÖØÐÂÖ´ÐУ»£»£»£»

ÈôÊÇÊÇ£¬ £¬£¬£¬£¬£¬ÔòÔÚ×¢²á±íHLM\Software\Microsoft\Windows\CurrentVersion\RunOnceĿ¼Àォ¸Ã·¾¶Ìí¼ÓÔÚ¡°Startup key¡±ÖУ¬ £¬£¬£¬£¬£¬ÒÔʵÏÖºã¾ÃפÁôµÄÄ¿µÄ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-34 Ìí¼Ó×¢²á±íÐÅÏ¢´úÂë


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-35 Ìí¼Ó×¢²á±í¿ª»úÆô¶¯Ïî


ÀÖ³ÉÌí¼Ó×¢²á±íÏîºó£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔò×îÏÈʹÓÃwinnet.dll¿âÖеÄInternet APIº¯Êý´ÓÔÆÍйÜЧÀÍÆ÷ÏÂÔØ¼ÓÃܵÄpayload¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-36 ´ÓÔÆÍйÜЧÀÍÏÂÔØpayload


ÏÂÔØÍê³Éºó£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔÙ½«Ó²±àÂëµÄÖµÓ뽫payloadµÄ¾Þϸ×ö½ÏÁ¿£¬ £¬£¬£¬£¬£¬ÒÔ´ËÀ´¼ì²éÎļþµÄÍêÕûÐÔ¡£¡£¡£¡£ÈôÊǾÞϸ²»Æ¥Å䣬 £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔò»áÖØÐÂÏÂÔØÎļþ£¬ £¬£¬£¬£¬£¬Ö±µ½ÍêȫƥÅäΪֹ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-37 ¼ì²âpayload¾Þϸ


ÏÂÔØµ½µÄpayloadÎļþÊÇÓÉ0x40¸ö×Ö½ÚµÄHEXСдÊý×ֺͼÓÃܵÄPEÎļþ×é³É£¬ £¬£¬£¬£¬£¬ÏêϸÈçͼ4-38Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-38 payloadÄÚÈÝ


½Ó×Å£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂëÔÙʹÓÃ×Ô½ç˵½âÃܺ¯Êý¶ÔÏÂÔØµÄpayload¾ÙÐÐÒì»ò½âÃÜ¡£¡£¡£¡£ÆäÃÜÔ¿Öü±£´æshellcode´úÂë0x2032Æ«ÒÆ´¦£¬ £¬£¬£¬£¬£¬ÃÜÔ¿³¤¶ÈΪ0x214¡£¡£¡£¡£½âÃܺ¯ÊýÄÚÈÝÈçͼ4-39Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-39 payload½âÃܺ¯Êý


½âÃܺóµÄPEÎļþÈçͼ4-40Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-40 ½âÃܺóµÄÎļþÄÚÈÝ


×îºó£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂ뽫½âÃܺóµÄPEÎļþÁýÕÖ0x00400000»ùÖ·µÄÄÚÈÝ£¬ £¬£¬£¬£¬£¬²¢Ìø×ªµ½Èë¿ÚµãÖ´ÐÐpayload¶ñÒâ³ÌÐò¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ4-41 Ö´ÐÐpayload


ÔÚ´Ë´ÎÆÊÎöµÄ°¸ÀýÖУ¬ £¬£¬£¬£¬£¬½âÃܳöµÄpayloadÊÇAgent Tesla¡£¡£¡£¡£¹ØÓڸöñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬ÔÚ´ËÎÒÃǾͲ»ÔÙ×ö¹ý¶àµÄÏÈÈÝºÍÆÊÎöÁË¡£¡£¡£¡£ÏÂÃæÎÒÃÇ»á¶ÔºÚ¿Í×éÖ¯µÄC&CЧÀÍÆ÷»ù´¡ÉèÊ©Õö¿ª×·×ÙËÝÔ´¡£¡£¡£¡£


Îå¡¢ËÝÔ´×·×Ù


5.1 C&C»ù´¡ÉèÊ©


×èÖ¹µ½ÏÖÔÚΪֹ£¬ £¬£¬£¬£¬£¬ÎÒÃÇͨ¹ýÌáÈ¡ºÍÕûÀíËùÓйØÁªÑù±¾ÖеÄIPµØµãºÍÓòÃûÐÅÏ¢£¬ £¬£¬£¬£¬£¬¿ÉÒÔ¿´µ½´Ë´Î¹¥»÷Ðж¯Ö÷ÒªÒÔ¶¯Ì¬ÓòÃûΪÖ÷£¬ £¬£¬£¬£¬£¬´ó²¿·ÖÓòÃû¶¼ÊÇͨ¹ý¾³ÍâµÄDuck DNS×¢²á¡£¡£¡£¡£Í¼5-1ΪSWEEDºÚ¿Í×é֯ʹÓõIJ¿·ÖÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹ØÏµ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-1 ²¿·ÖÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹ØÏµÍ¼



ƾ֤Ñù±¾Í¬Ô´ÐÔÆÊÎöµÄЧ¹û£¬ £¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷´ó×ÚµÄÓÐÓÃÔØºÉ±»»®·Ö¹ÒÔØÔÚ²î±ðµÄ¶¯Ì¬ÓòÃûÖУ¬ £¬£¬£¬£¬£¬ÒÔ±¸°üÀ¨Îó²îµÄOfficeÎĵµ»ò¶ñÒâÈí¼þGuloader»á¼ûºÍÏÂÔØ¡£¡£¡£¡£Í¨¹ýÓòÃûµÄÅÌÎʼͼËùµÃ£¬ £¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯×îÔç¿É×·Ëݵ½1ÔÂÖÐÏÂÑ®£¬ £¬£¬£¬£¬£¬Í¬Ê±Ò²¿ÉÒÔ¿´µ½£¬ £¬£¬£¬£¬£¬ËüÃÇ×î³õ¾ùʹÓÃÖ¸ÏòÄáÈÕÀûÑǵĻù´¡ÉèÊ©¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ £¬£¬£¬£¬£¬ÕâЩÓòÃûÆÊÎöʹÓõÄIP×Üδ±ØÆÚÔÚ³£ÓõÄIPµØµã¶ÎÍù·µÇл»¡£¡£¡£¡£ÏêϸÈçͼ5-2Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-2 ¶¯Ì¬ÓòÃûÆÊÎöµÄIPµØµã


ÎÒÃǽ«C&C¶ÔÓ¦µÄIPµØµãËùÊô¹ú¼ÒºÍµØÇø¾ÙÐÐͳ¼Æ£¬ £¬£¬£¬£¬£¬²¢»æÖÆÆäµØÀíλÖÃÂþÑÜͼ£¨Èçͼ5-3Ëùʾ£©¡£¡£¡£¡£ÕûÌåÀ´¿´£¬ £¬£¬£¬£¬£¬ÃÀ¹úºÍ·¨¹úÕ¼±ÈÂÊ×î¸ß£¬ £¬£¬£¬£¬£¬Æä´ÎΪºÉÀ¼¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-3 C&C¶ÔÓ¦µÄIPµØÀíλÖÃÂþÑÜͼ


5.2 ¹ØÁªÐÔÆÊÎö


c7c7ÓéÀÖÆ½Ì¨ADLab½«±¾´Î²¶»ñµ½µÄÑù±¾Í¬ÒÔÍùSWEED»î¶¯×öÁËÖÜÈ«µÄ¹ØÁªÆÊÎö£¬ £¬£¬£¬£¬£¬µÃ³öÒÔϼ¸´¦Ö÷ÒªµÄ¹ØÁªµã£º


£¨1£©Îó²îÎĵµ

ÔÚ´Ë´ÎÐж¯Öй¥»÷×é֯ʹÓõÄÎó²îÎĵµÓÐÁ½ÀࣨCVE-2017-11882ºÍCVE-2014-6357£©£¬ £¬£¬£¬£¬£¬ÆäÖÐÒÔCVE-2017-11882Îó²îʹÓÃÎĵµÎªÖ÷Òª¹¥»÷ÔØºÉ¡£¡£¡£¡£¶øSWEED×éÖ¯Ò²ÔøÔÚÒÔÍùµÄ¹¥»÷Ðж¯ÖÐÆµÈÔµÄʹÓùý¸ÃÎó²îÎĵµ¡£¡£¡£¡£ÏêϸÈçͼ5-4Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-4 Îó²îÎĵµ°¸Àý


£¨2£©¹¥»÷Ä¿µÄ


ƾ֤¹ûÕæ±¨¸æ¿ÉÒÔµÃÖª£¬ £¬£¬£¬£¬£¬SWEEDºÚ¿Í×éÖ¯µÄ¹¥»÷Ä¿µÄÖ÷ÒªÕë¶ÔÈ«Çò´ÓʶÔÍâÉÌÒµµÄÖÐСÐÍÆóÒµ£¬ £¬£¬£¬£¬£¬²¢ÇÒËùÉæ¼°µÄÐÐÒµÖ÷ÒªÒÔÖÆÔìÒµ¡¢º½ÔË¡¢ÎïÁ÷ºÍÔËÊäΪÖ÷¡£¡£¡£¡£ÕâÓëÎÒÃǴ˴μà²âµ½µÄ¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĵØÀíλÖúÍÐÐÒµÂþÑܾßÓнϸߵÄÏàËÆÐÔ¡£¡£¡£¡£Í¼5-5ö¾ÙÁ˼¸ÀýÔÚ±¾´Î¹¥»÷»î¶¯Öй¥»÷Õß·¢Ë͸øÄ¿µÄÓû§µÄ´¹ÂÚÓʼþ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-5 ´¹ÂÚÓʼþ°¸Àý


£¨3£©¹¥»÷ÎäÆ÷


ÔÚÏÖÔÚÊӲ쵽µÄÐж¯ÖУ¬ £¬£¬£¬£¬£¬¹¥»÷Õß×îÖÕͶ·ÅµÄ¶ñÒâÈí¼þ°üÀ¨Agent Tesla¡¢Remcos¡¢NanoCore¡¢FormbookºÍLokibot¡£¡£¡£¡£ÎÒÃǽ«²¶»ñµÄËùÓжñÒâÈí¼þ°´¼Ò×å·ÖÀàºÍͳ¼Æ£¬ £¬£¬£¬£¬£¬Æ¾Ö¤Ð§¹ûÏÔʾ£¬ £¬£¬£¬£¬£¬Agent TeslaµÄÕ¼±ÈÂÊ´¦ÓÚ×î¸ß£¬ £¬£¬£¬£¬£¬Êǹ¥»÷ÕßÖØµãʹÓõĹ¥»÷ÎäÆ÷¡£¡£¡£¡£¶øÕâÖÖʹÓÃÌØÕ÷Ò²ÔøÖØ¸´·ºÆðÔÚSWEED×éÖ¯ÒÔǰµÄ¹¥»÷»î¶¯ÖС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-6 ¶ñÒâÈí¼þ¼Ò×åÕ¼±ÈÂÊ


£¨4£©IPµØµãλÖÃ


ÎÒÃÇͨ¹ýWhoisÐÅÏ¢ÅÌÎÊ£¬ £¬£¬£¬£¬£¬·¢Ã÷ÔÚ´Ë´ÎÐж¯ÖеÄÓòÃû¡°mogs20.xxx.org¡±ÔçÆÚÆÊÎöµÄIP£¨105.112.XXX.XXX£©µØÀíλÖÃÖ¸ÏòÄáÈÕÀûÑÇ£¬ £¬£¬£¬£¬£¬¸ÃÍø¶Î¹éÊôÄáÈÕÀûÑǵØÇøµçÐŵÄ105.112¶Î¡£¡£¡£¡£ÕâÓëSWEED×éÖ¯ËùÊô¹ú¼Ò¾ßÓи߶ȵÄÒ»ÖÂÐÔ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ5-7 WhoisÅÌÎÊÐÅÏ¢ÄÚÈÝ


Á¬ÏµSWEED×é֯һϵÁеĹ¥»÷»î¶¯ÌصãÒÔ¼°ÉÏÃæ×ܽáµÄËĵã¿ÉÒÔ¿´³ö£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ¹¥»÷ÄîÍ·£¨ÇÔÈ¡Óû§ÐÅÏ¢ÒÔIJÀû£©¡¢¹¥»÷Ä¿µÄ£¨Õë¶ÔÈ«Çò¶ÔÍâÉÌÒµµÄÖÐСÆóÒµ£©¡¢×÷񵮿¸Å£¨Í¶µÝ¶¨ÖÆÐÍ´¹ÂÚÓʼþ·Ö·¢Ä¾Âí£©¡¢Õ½Êõ£¨¹æ±Ü¼ì²â¡¢³£×¤¡¢ÏÂÁîÓë¿ØÖÆ£©¡¢ÊÖÒÕ£¨Îó²îʹÓã©¡¢Àú³Ì£¨·¢ËÍЯ´ø¶ñÒ⸽¼þµÄÓʼþ->Îó²îÎĵµ->½âÃÜÔËÐÐAgent TeslaÔ¶¿ØÄ¾Âí£©ÒÔ¼°ÆäʹÓõÄÍøÂç»ù´¡ÉèÊ©µÈ·½Ã涼ʮ·ÖÇкÏSWEED×éÖ¯µÄÌØÕ÷¡£¡£¡£¡£ÓÉ´ËÎÒÃÇÍÆ¶Ï£¬ £¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯Ä»ºóÕߺܿÉÄÜÊÇÀ´×ÔÄáÈÕÀûÑǵÄSWEEDºÚ¿Í×éÖ¯¡£¡£¡£¡£


Áù¡¢×ܽá


Æù½ñΪֹSWEEDºÚ¿Í×éÖ¯ÖÁÉÙÒÑ»îÔ¾ÁË4ÄêµÄʱ¼ä£¬ £¬£¬£¬£¬£¬´Ó¸Ã×éÖ¯½üÆÚµÄ¹¥»÷¿ÉÒÔ·¢Ã÷£¬ £¬£¬£¬£¬£¬SWEED×îÏÈʹÓøü¾ßÓÐÕë¶ÔÐÔµÄÓʼþÄÚÈݺ͸ü¾ßÒÉ»óÐÔµÄÎĵµÎÊÌ⣬ £¬£¬£¬£¬£¬´Ó¶øÌá¸ßÊܺ¦ÕßÖÐÕеĸÅÂÊ¡£¡£¡£¡£c7c7ÓéÀÖÆ½Ì¨ADLab½«¸Ã×éÖ¯´Ë´ÎÐж¯TTPµÄÑо¿ÆÊÎöЧ¹ûÓëÒÔÍù¸ú½ø»òÅû¶µÄÏà¹Ø¹¥»÷Ðж¯ÌØÕ÷×ö±È¶Ôºó£¬ £¬£¬£¬£¬£¬»ñµÃµÄÏà¹ØÖ¤¾Ý¶¼¿ÉÅú×¢ÕâЩÑùÔ­À´×ÔSWEEDºÚ¿Í×éÖ¯¡£¡£¡£¡£


SWEED×é֯ʹÓÃGuloaderÏÂÔØÆ÷Èö²¥µÄÔ¶³ÌľÂíÖÖÀàËäÈ»¶àÑù»¯£¬ £¬£¬£¬£¬£¬µ«Ö÷ÒªÕÕ¾ÉÒÔÆäÆ«ºÃµÄAgent TeslaΪÖ÷¡£¡£¡£¡£´ÓÆäËùʹÓõÄTTPÀ´¿´£¬ £¬£¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯ÏÖÔÚ²¢Î´¾ß±¸ºÜºÃµÄ×ÔÑпª·¢ÄÜÁ¦¡£¡£¡£¡£ÔÚ´ó¶¼ÇéÐÎÏ£¬ £¬£¬£¬£¬£¬½ö»á´ÓÍâÑóһЩÖ÷Á÷ºÚ¿ÍÍøÕ¾ÉϹºÖÃľÂíÌìÉúÆ÷ºÍ¼ÓÃܹ¤¾ßÀ´×÷Ϊ¹¥»÷ÎäÆ÷£¬ £¬£¬£¬£¬£¬ÀýÈçÔøÊ¹ÓõÄKazyCypterºÍ´Ë´ÎʹÓõÄGuloader¡£¡£¡£¡£²»¹ý£¬ £¬£¬£¬£¬£¬¼´±ã¹¥»÷ÕßÔÚÊÖÒÕÄÜÁ¦ÉÏÏà¶Ô½ÏÈõ£¬ £¬£¬£¬£¬£¬µ«ÆäÔÚÉ繤¼¼ÇɺͶàÑù»¯¹¥»÷·½·¨µÄÓ¦ÓÃÃæÉÏÕվɽÏΪÊìÁ·µÄ¡£¡£¡£¡£ÔÚ´Ë£¬ £¬£¬£¬£¬£¬½¨ÒéÓû§Ö»¹Ü×èÖ¹·­¿ª²»Ã÷ȪԴµÄÓʼþÒÔ¼°¸½¼þÎļþ£¨À´×Ôδ֪·¢ËÍÕߵģ©£¬ £¬£¬£¬£¬£¬ÊµÊ±×°ÖÃϵͳ²¹¶¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬Ìá¸ßΣº¦Òâʶ£¬ £¬£¬£¬£¬£¬Ìá·À´ËÀà¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£




Æß¡¢IOC


MD5

F97CFA6C3F1338B597768808FC1B2F00

B1941921571C2B6ED0C3BDA77E402001    

DD82B2E488811E64BB9C039C441DB19C

EC4CF91427DAC3AD29CD2A52B0789DC6

166FD7B0C74C60DCBC80BF335D712EA2

BCBCC89F237B22F21BDAE9E6555404A

60147B91AB7B64B9BE27BD3422147E60

48408BBE8D9EE22D6BBB6820FCCC305F

7DDA46F2D9008FAE016AFFF39E9C5801

A22A37E699C20D42753D35A94A75B365

C36C41EB6A34880459154334681C203A

6BC92ACB050A2068EFF4842A1D360938

FB7ED44C2BAAA6F011F7BF51DE721BC4

58604AE63AEA84483C67980369958ACB

312BFAFE6746645E72FCB84ECBFB023C

779EB99965F1AAC12363632468DF7DCE

DD49030C00EF3C2341BCBE4489DCEF63

IP

167.114.85.125

URL

https://drive.google.com:80/uc?export=download&id=1lmmu6kv5ep_wkm7hfyhdshru-y1n2pqv

https://onedrive.live.com/download?cid=554BBD19BDD72613&resid=554BBD19BDD72613!156&authkey=AGIuaWEkkBxB_4o

https://drive.google.com/uc?export=download&id=1W3ddZnmArVGhsecoWW5KcQAKPZ9OacLU

https://share.dmca.gripe/iQakn267f3ZvpDN.bin

http://167.114.85.125/go/Origin%20server%20ilyas_tTzYDNEGay108.bin



°Ë¡¢²Î¿¼Á´½Ó


[1]https://www.fortinet.com/blog/threat-research/new-agent-tesla-variant-spreading-by-phishing

[2]https://www.fireeye.com/blog/threat-research/2017/10/formbook-malware-distribution-campaigns.html

[3]https://www.fortinet.com/blog/threat-research/new-infostealer-attack-uses-lokibot

[4]https://success.trendmicro.com/solution/1122912-nanocore-malware-information

[5]https://www.fortinet.com/blog/threat-research/remcos-a-new-rat-in-the-wild-2





c7c7ÓéÀÖÆ½Ì¨Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨ÉèÓÚ1999Ä꣬ £¬£¬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬ £¬£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬ £¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬ £¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬ £¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î800Óà¸ö£¬ £¬£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØÏµÍ³Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵È¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú