¡¾Éî¶ÈÆÊÎö¡¿VPNFilter£ºÎ£¼°È«Çò¹¤¿Ø×°±¸ºÍ°ì¹«ÍøÂçµÄÎïÁªÍø¸ß¼¶Íþв
Ðû²¼Ê±¼ä 2018-06-17Ò»¡¢Íþв¸ÅÊö
½üÆÚ£¬Ë¼¿ÆTalosÍŶÓÒòÇéÐνôÆÈÌáÇ°¹ûÕæÁËÒ»ÏîδÍê³ÉµÄÑо¿£¬¸ÃÑо¿Ìá¼°ÁËÒ»¸ö¿ÉÄܶÔÈ«ÇòÍøÂ籬·¢ÖØ´óΣº¦µÄ¸ß¼¶Íþв¹¥»÷(ԼĪÓÐ50Íǫ̀װ±¸Êܵ½Ñ¬È¾)£¬ÓÉÓÚÆä½¹µãÄ£¿éÎļþΪVPNFilter£¬¹Ê¸Ã¶ñÒâ´úÂëÒ²±»ÃüÃûΪ¡±VPNFilter¡±¡£¸Ã¹¥»÷ÊÇÒ»ÆðÒÔÈëÇÖÎïÁªÍøΪÔØÌå´ÓÊ¿ÉÄÜÓɹú¼ÒÌᳫµÄÈ«ÇòÐԵĸ߼¶¶ñÒâÈí¼þ¹¥»÷£¬¶ñÒâÈí¼þͨ¹ýÈý¸ö½×¶ÎÀ´°²ÅÅÆä¹¥»÷ÎäÆ÷£¬ÏÖÔÚÒѾÓÐÖÁÉÙ50Íǫ̀װ±¸Êܵ½Ñ¬È¾¡£¹¥»÷ÕßʹÓøöñÒâÈí¼þÀ´¿ØÖƲ¢¼àÊÓ´¦ÓÚ¹¤¿ØÍøÂç¡¢°ì¹«ÇéÐÎÖеÄÍøÂç×°±¸(°üÀ¨Â·ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽÒÔ¼°ÆäËûµÄÎïÁªÍø×°±¸)£¬ÆäÖ§³Ö¹¤¿ØÍøÂçÇ鱨ÍøÂç¡¢Ö÷ÒªÃô¸ÐµÄÁ÷Á¿(µÇ¼ƾ֤)½ØÈ¡¡¢Á÷Á¿¸Ä¶¯¡¢¶¨ÏòJS×¢Èë¡¢×°±¸ÆÆËðÐÔ¹¥»÷µÈ¹¦Ð§¡£
¶ñÒâÈí¼þÔÚ5ÔÂ8ÈÕ·ºÆð´ó¹æÄ£µÄÒÔÎÚ¿ËÀ¼ÎªÖ÷ҪĿµÄµÄ¹¥»÷Ô˶¯£¬²¢ÇÒÔÚ5ÔÂ17ÈÕÎÚ¿ËÀ¼µÄÊÜѬȾװ±¸·ºÆð´ó·ù¶ÈÔöÌí£¬ÕâЩÊÜѬȾװ±¸¾ùÊÜ¿ØÓÚC&C 46.151.209.33, ¿´ÆðÀ´´Ë´Î¹¥»÷Ä¿µÄËƺõÃé×¼ÎÚ¿ËÀ¼¡£ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³Ò»¾Êܵ½¹ýÁ½´ÎºÚ¿Í¹¥»÷£¬²¢ÇÒµ¼ÖÂÁËÍ£µçʹʣ¬Á½´Î¹¥»÷¾ùÒÔ³¤ÆÚ¶øÒþÃصÄÉø͸ÊÖ¶ÎÈëÇÖµ½Ä¿µÄ¡£¶øÕâ´ÎµÄ¹¥»÷Ô˶¯ÒÔÎïÁªÍøÈë¿Ú£¬Ê¹Óôó×Ú±£´æÎó²îµÄÎïÁªÍø×°±¸×÷ΪÔØÌå¾ÙÐÐÈöÍøʽ¹¥»÷£¬²¢ÇÒÒÔ¾ªÈ˵ÄËÙÂÊѬȾÁËÖÁÉÙ50Íǫ̀װ±¸£¬ÆäÖаüÀ¨ÓлªÎª¡¢ÖÐÐË¡¢»ªË¶¡¢Dlink¡¢Ubiquiti¡¢UPVEL¡¢Linksys¡¢MikroTik¡¢NETGEAR ºÍ TP-LinkµÈ×°±¸¡£Í¬Ñù£¬´Ë´Î¶ñÒâ´úÂëÓë2015Äê¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄBlackEnergyʹÓÃÏàͬµÄ±äÐÎRC4Ëã·¨¶ÔÒªº¦ÐÅÏ¢¾ÙÐмÓÃÜ£»²¢ÇÒÓëÖ®ÀàËƵÄÊÇͬÑùÒ²ÓжÔÖ÷»ú×°±¸¾ÙÐÐÖ÷ÒªÊý¾Ý²Á³ýÓëÖØÆôµÄÁ¬»·Ðж¯ÒÔµÖ´ïÈÃ×°±¸ÎÞ·¨Æô¶¯µÄÄ¿µÄ(ͬʱҲÌá¸ßÁËÈ¡Ö¤µÄÄѶÈ)¡£
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷¸ÃÔ¤¾¯ºó¶Ô¸Ã¶ñÒâÈí¼þ¾ÙÐÐÁËÉîÈëµÄÆÊÎö£¬ÒÔÆÊÎö×ÅʵÏÖ»úÖÆ¡£ÎÒÃÇ·¢Ã÷¸Ã¶ñÒâÈí¼þÖгýÁ˽ÓÄÉͼƬÎļþµÄEXIFÊý¾Ý´«ÊäÓÃÓÚÏÂÔضñÒâ´úÂë½¹µã×é¼þµÄC&CÍ⣬»¹½ÓÄÉHTTPÍ·ÖеÄlocationºÍdirect×ֶδ«Êä¸ÃC&C£¬ÉõÖÁ½ÓÄÉÁËÒ»ÖÖÎÒÃdzÆ֮Ϊ¡±SYNËíµÀÊÖÒÕ¡±µÄ¸ß¼¶Òþ²ØÊÖÒÕÀ´ÊµÏÖ¶ñÒâÈí¼þC&CµÄ±»¶¯¸üУ¬×ÝÈ»Èç֮ǰËù±¨µÀÄÇÑù£¬FBI×è¶ÏÁ˸öñÒâÈí¼þµÄC&C£¬¸ÃÊÖÒÕÒ²¿ÉÒÔÈøöñÒâÈí¼þ¿ìËÙ¸´Éú¡£ÆäÖеÚÈý½×¶Î¶ñÒâ×é¼þרÃÅÕë¶ÔTCPÐÒé¾ÙÐÐÐá̽´¦Öóͷ££¬²»µ«¶Ô¹¤¿Ømodbus SCADAÐÒé¾ÙÐÐÇ鱨ÍøÂ磬ͬʱ»¹»áÐá̽»ùÓÚhttpÐÒéµÄµÇ¼ƾ֤ÐÅÏ¢ºÍAuthorizationÐÅÏ¢¡£¸ÃÐá̽ģ¿éÐèÒªºÚ¿ÍÔ¶³ÌÖ¸¶¨modbus·þÎñÆ÷¾ÙÐÐ׼ȷµÄ¼à¿Ø£¬ÒÔ·¢Ã÷ËùÓÐÅþÁ¬µÄ´Ó»ú×°±¸¡£±ðµÄ£¬ÔÚ×î½ü¹ûÕæµÄ¹¥»÷²å¼þÄ£¿éÖл¹¿ÉÒÔ¿´³ö£¬¸Ã´Î¹¥»÷¿ÉÓÃÓÚÆÕ±éµÄÇ鱨ÍøÂçÒÔ¼°¶ÔÌض¨Ä¿µÄ¾ÙÐÐÉø͸¹¥»÷£¬ÆäÖаüÀ¨¶Ô80¶Ë¿ÚµÄÁ÷Á¿Öض¨Ïò¡¢Ç¿ÖÆת»»HTTPSΪHTTPÒÔÀû±ãÁ÷Á¿¼à¿Ø¡¢ÇÔÈ¡HTTPÇëÇó°üÖеĵǼƾ֤ÐÅÏ¢¡¢ÏòÖ¸¶¨ÍøÕ¾µÄÏìÓ¦Êý¾ÝÖÐ×¢Èë¶ñÒâjavascript¾ç±¾µÈµÈ¡£
¶þ¡¢¶ñÒâÈí¼þÊÂÇéÔÀí
¸Ã¶ñÒâÈí¼þͨ¹ýʹÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍø×°±¸Îó²î¾ÙÐÐÆÕ±éµÄѬȾºÍÈö²¥¡£ÔÚѬȾװ±¸ÖУ¬ÆäÊ×ÏÈÆô¶¯Ò»¸öLoaderÄ£¿éÖ´ÐУ¬¸ÃÄ£¿éÖ÷ҪʵÏÖÁËVPNFilter×é¼þµÄÏÂÔØÓëÖ´ÐС£LoaderÄ£¿é²¢²»ÊÇÖ±½Óͨ¹ýÖ¸¶¨µÄÏÂÔصصãÀ´ÏÂÔØVPNFilter×é¼þ£¬¶øÊÇͨ¹ý¶àÖÖÊÖÒÕÊÖ¶ÎÀ´»ñÈ¡VPNFilterµÄÏÂÔصصã(´æ´¢µã)¡£ÆäÊ×ÏÈ»áÏò·þÎñÆ÷photobucket.com·¢ËÍÇëÇó²¢ÊµÑéÆÊÎöÏìÓ¦Êý¾ÝÖеÄLocaion¡¢direct¡¢Í¼Æ¬EXIFÐÅÏ¢À´»ñÈ¡£»ÈôÊÇʧ°ÜÔòÏò·þÎñÆ÷taknowall.com·¢ËÍÇëÇó²¢ÆÊÎöͼƬµÄEXIFÀ´»ñÈ¡£»ÈôÊÇÈÔÈ»ÎÞ·¨»ñÈ¡µ½C&C£¬Ôò»á½ÓÄÉ¡±SYNËíµÀÊÖÒÕ¡±À´»ñÈ¡C&CʵÏÖÏÂÒ»¸ö½×¶Î×é¼þµÄÏÂÔصص㡣±ðµÄ£¬VPN´æ´¢µã»ñÈ¡Àֳɺó£¬Loaderͨ¹ýÄÚÖÃSSLÖ¤ÊéÎļþÀ´ÑéÖ¤ÏÂÔØVPNFilter×é¼þ¡£

VPNFilter×é¼þ×îºó»á±»ÏÂÔص½¡±/var/run/¡±Ä¿Â¼Ï£¬ÊǸÃÀà¶ñÒâ¹¥»÷µÄ½¹µã×é¼þ£¬Í¨¹ý¸Ã×é¼þ£¬¶ñÒâÈí¼þµÃÒÔפÁôÔÚ±»Ñ¬È¾ÏµÍ³ÖС£VPNFilter×é¼þΪ¹¥»÷ÕßÌṩÁËÒ»¸öÓÃÓÚά»¤½©Ê¬ÍøÂçµÄ¿ò¼Ü£¬¹¥»÷Õß¿ÉÒÔ»ùÓÚ²î±ðµÄ¹¥»÷Ä¿µÄ¼ÓÔزî±ðµÄ²å¼þºÍÖ´Ðвî±ðÔ¶¿Ø¿ØÖÆÏÂÁî¡£ÏÖÔÚËù·¢Ã÷µÄ²å¼þÄ£¿éÓУºÒ»¸öÓÃÓÚÖ§³ÖÅþÁ¬µ½TorÍøÂçµÄTor ¿Í»§¶Ë£¨Tor Client,Îļþtor£©£»Ò»¸öΪÐá̽µÇ¼ƾ֤ºÍModbus¹¤¿ØÐÒéÐÅÏ¢µÄTCPÁ÷Á¿Ðá̽ģ¿é£¨TCP Traffic Sniffer£¬Îļþps£©;Ò»¸öרÃÅΪHTTP 80¶Ë¿Ú¾ÙÐÐÁ÷Á¿¼à¿Ø¡¢½ØÈ¡¡¢¸Ä¶¯¡¢×¢ÈëµÄHTTP Á÷Á¿¼à¿ØÄ£¿é£¨HTTP Traffic Controllor£¬Îļþssler£©£»ÒÔ¼°¿ÉÓÃÓÚÆÆËð×°±¸Ê¹ÆäÎÞ·¨ÖØÆô¡¢ÎÞ·¨È¡Ö¤µÄ×°±¸ÆÆËðÄ£¿é£¨Destroy Module£¬Îļþdstr£©£¬±ðµÄÆ仹±£´æÆäËûµÄÄ£¿éÈ磺mikrotik.o¡¢torrc¡¢ip_tables.ko¡¢iptable_filter.ko¡¢iptable_nat.ko¡£
Èý¡¢¶ñÒâÈí¼þÆÊÎö
ƾ֤¸Ã¶ñÒâÈí¼þÖ´Ðй¥»÷µÄ°ì·¨£¬¿ÉÒÔ½«Æä»®·ÖΪÈý¸ö½×¶Î£¬ÆäÖÐLoaderÎļþΪµÚÒ»¸ö½×¶ÎµÄ¶ñÒâÄ£¿é£¬VPNFilterÎļþΪµÚ¶þ½×¶ÎµÄ¶ñÒâÄ£¿é£¬Tor¿Í»§¶ËºÍÁ÷Á¿Ðá̽Æ÷ΪµÚÈý½×¶ÎµÄ¶ñÒâÄ£¿é¡£ÒÔÏ»®·Ö¶ÔÕâÈý¸ö½×¶ÎµÄ¶ñÒâ´úÂë¾ÙÐÐÉîÈëµÄÆÊÎö¡£
µÚÒ»½×¶Î£ºÑ¬È¾×°±¸²¢ÏÂÔضñÒâ´úÂëÖ÷ÌåÖ´ÐÐ
µÚÒ»¸ö½×¶ÎµÄÑù±¾¿ÉÒÔ¿´×÷ÊÇÒ»¸öLoader£¨ÎļþÃûΪmsvf£©£¬¹¥»÷ÕßʹÓÃ×°±¸Îó²î½«ÆäÂäµØµ½×°±¸ÄÚ´æÖÐÔËÐС£¸ÃLoaderÖ÷ҪĿµÄÊÇ´ÓC&C·þÎñÆ÷ÉÏÏÂÔصڶþ½×¶ÎµÄ¶ñÒâ×é¼þÖ´ÐС£¸ÃLoader²î±ðÓÚÒÔÍùµÄÎïÁªÍø¶ñÒâ´úÂëÄÇÑù½«C&CÄÚÖÃÓÚ´úÂëÄÚ£¬¶øÊÇͨ¹ýÔÚÕýµ±Í¼Æ¬ÍøÕ¾ÉÏÏÂÔØÒ»ÕÅÒþ²ØÓÐC&CµØµãµÄͼƬ¾ÙÐÐÆÊÎö£¬´Ó¶ø»ñµÃÕæʵµÄC&C¡£¶ø¶ñÒâ´úÂëΪÁ˱ÜÃâÁ÷Á¿×·×Ù£¬½ÓÄÉsocks5ÊðÀí¡¢Tor¡¢ÒÔ¼°sslµÄ·½·¨¾ÙÐиÃͼƬµÄÏÂÔØ¡£ÈôÊÇͼƬÏÂÔØʧ°Ü£¬Ò²»á½ÓÄɼ«ÆäÒþ²ØµÄÔʼÁ÷Á¿Êý¾ÝÐá̽µÄ·½·¨À´»ñÈ¡C&C¡£
ͬʱ¸ÃÄ£¿é»¹ÊÔͼÐÞ¸ÄNVRAM²¢½«×ÔÉí¼ÓÈë׼ʱʹÃüÎļþ¡±crontab¡±ÖУ¬ÒԵִﳣפµÄÄ¿µÄ¡£Ò»Ñùƽ³£ÎïÁªÍø¶ñÒâ´úÂëÈçmiraiµÈûÓÐÉæ¼°³£×¤»úÖÆ£¬Ê¹µÃÆäÔÚ×°±¸ÖØÆôºó»áÏûÊÅ¡£
1¡¢Á½´Î½¨Éè×ÓÀú³Ì²¢ÇÒÆôÓöñÒâ´úÂë¶ÔÄ¿½ñÓû§×éµÄ¶ÁдִÐÐȨÏÞ
µÚÒ»½×¶ÎÑù±¾Ö´Ðк󣬻áforkÁ½´Î£¬µÚÒ»´ÎÓÃÓÚÕûÀíÀú³Ì×ÊÔ´ÆôÓöÁдִÐÐȨÏÞ¡£

µÚ¶þ´Îfork»áÔÚ×ÓÀú³ÌÖÐÈ·ÈÏÀú³ÌÎļþÊÇ·ñ±£´æ£¬ÈôÊDz»±£´æ»á¾ÙÐÐÎļþµÄ»Øд£¬±ÜÃâ¾ÙÐÐÎļþɥʧ¡£

±ðµÄÔÚµÚ¶þ´ÎforkµÄ×ÓÀú³ÌÖУ¬¶ñÒâ´úÂëΪÁ˱ÜÃâ×ÔÉíÎļþÔÚ×°±¸ÖØÆôºóÏûÊÅ£¬»¹»á½«×ÔÉíÎļþ¼ÓÈëµ½crontabÎļþĩ⣬ÒÔʵÏÖ¿ªÆôÆô¶¯¡¢³£×¤×°±¸µÄÄ¿µÄ¡£

2¡¢ ½âÃÜÖ¤ÊéÎļþÃû¡¢Í¼Æ¬Á´½ÓÊý¾ÝµÈÄÚÈÝ
½ÓÏÂÀ´¶ñÒâ´úÂë»áͨ¹ý±äÐεÄRC4Ëã·¨À´½âÃܺóÐøÒªÓõ½µÄ×Ö·û´®ºÍÊý¾Ý£¬±äÐÎRC4ÃØԿΪ¡±%^:d¡±£¬×îа汾ÒѾ¸üÐÂΪ¡°g&*kdj$dg0_@@7¡¯x¡±¡£

±äÐÎRC4µÄstableÊý¾ÝÈçÏ£º

×îºó½âÃÜ»ñµÃÈçÏÂÐÅÏ¢£¬ÆäÖаüÀ¨Ö¤ÊéÎļþÃû¡¢°æ±¾ºÅ¡¢buildÐÅÏ¢¡¢Í¼Æ¬urlµÈ¡£

½âÃÜurl£º

3¡¢½¨ÉèsslÖ¤ÊéÎļþÒÔ¼°¶ñÒâ´úÂë°æ±¾Îļþ
½âÃÜÍê³Éºó£¬¶ñÒâ´úÂë»á½«´úÂëÖÐÄÚǶµÄ¹«Ô¿¡¢Ë½Ô¿Êý¾Ý´æ´¢ÔÚÖ¤ÊéÎļþÖС£¸Ã¶ñÒâ´úÂëÖдæ·ÅÓÐÈý¸öÖ¤ÊéÊý¾Ý£¬ÆäÖÐÁ½¸ö¹«Ô¿ºÍÒ»¸ö˽Կ£¬¹«Ô¿´æ´¢ÔÚÎļþ¡±/var/run/client_ca.crt¡±ºÍ¡±/var/run/client.crt¡±ÖУ¬Ë½Ô¿´æ´¢ÔÚÎļþ¡±/var/run/client.key¡±ÖС£

±ðµÄ£¬°æ±¾ÐÅÏ¢0.3.9qa»á±»Ð´Èëµ½Îļþ/var/run/msvf.pidÖС£

4¡¢ÏÂÔصڶþ½×¶Î×é¼þ
µÚ¶þ½×¶ÎµÄ¶ñÒâ´úÂëÏÂÔصصã½ÓÄÉÈýÖÖ·½·¨»ñÈ¡¡£Ê×ÏÈʵÑé´ÓphotobucketÍøÕ¾ÇëÇóC&C£¬Ïêϸƾ֤ÈçÏÂÁ´½Ó˳ÐòÈ¥ÏÂÔز¢ÌáÈ¡µÚ¶þ½×¶Î¶ñÒâ´úÂëµÄ·þÎñÆ÷µØµã¡£
http://photobucket.com/user/nikkireed11/library
http://photobucket.com/user/kmila302/library
http://photobucket.com/user/lisabraun87/library http://photobucket.com/user/katyperry45/library
ËäȻĿ½ñÕâЩÁ´½ÓÒѾʧЧ£¬¿ÉÊÇͨ¹ýÄæÏò¿ÉÒÔ¿´³ö£¬ÈôÊÇÇëÇóÏìÓ¦ÂëΪ302£¬¶ñÒâ´úÂëÔò»á´ÓÏìÓ¦Êý¾ÝÖеġ±Location¡±/¡±location¡±²ÎÊýÖÐÌáÈ¡³öµÚ¶þ½×¶Î¶ñÒâ´úÂëµÄÏÂÔصص㡣

ÈôÊǶñÒâ´úÂëÇëÇóµÄÏìÓ¦ÂëΪ200£¬Ôò»á´ÓÇëÇóµÄÏìÓ¦Êý¾Ý°üµÄHTTPÍ·²¿ÖÐÌáÈ¡¡±direct¡±²ÎÊýµÄÖµ£¬×÷ΪµÚ¶þ½×¶Î¶ñÒâ´úÂëÏÂÔصص㡣

ÈôÊDz»±£´æ¸ÃÖµ£¬Ôò»á´ÓͼƬÎļþÖеÄEXIFÓòÌáÈ¡¾Î³¶ÈÊý¾Ý²¢½«Æäת»»ÎªµÚ¶þ½×¶Î¶ñÒâ´úÂëÏÂÔصÄIPµØµã¡£ÏÂÔصÄͼƬÎļþEXIF²¿·ÖÊý¾ÝÀàËÆÏÂͼ¡£

´¦Öóͷ£´úÂëÈçÏ£º

ÈôÊÇÒÔÉÏÇéÐξùʧ°Ü£¬¶ñÒâ´úÂ뻹»áʵÑéÇëÇóÈçÏÂÁ´½Ó£¬¸ÃÁ´½ÓÒ²ÊÇÒ»ÕÅͼƬ£¬ºÍÉÏÃæÒªÁìÒ»Ñù´ÓEXIFÖÐÌáÈ¡¾Î³¶È²¢´¦Öóͷ£»ñµÃÏÂÔصص㣺http://taknowall.com/manage/content/update.php ¡£
ÈôÊÇÉÏÃæµÄËùÓз½·¨¶¼ÊµÑéºóÒÀÈ»ÎÞ·¨ÀֳɻñÈ¡C&CµØµã£¬¶ñÒâ´úÂë»áͨ¹ýÁ´½Óhttp://api.ipify.org?format=json»ñÈ¡µ½Ä¿½ñ×°±¸µÄÍâÍøIPµØµã£¬È»ºóÐá̽Ŀ½ñ×°±¸µÄÔʼÍøÂçÁ÷Á¿Êý¾Ý£¬²¢ÊÔͼ´ÓÕâЩÁ÷Á¿Êý¾ÝÖйýÂ˳öÇкÏÌØÃüÃûÌõÄÍøÂçÊý¾Ý°ü£¬ÈôÊÇÖª×ãÃûÌÃÒªÇ󣬱ã»á´Ó¸ÃÊý¾ÝÖÐÌáÈ¡³öµÚ¶þ½×¶Î¶ñÒâ´úÂëµÄÏÂÔصص㡣ÆäÖйýÂË°üʱÐèÖª×ãÈçÏÂÌõ¼þ£º
(1) ÔʼÊý¾ÝÁ÷³¤¶È±ØÐè´óÓÚ0x3D
(2) Êý¾Ý°ü±ØÐèΪTCP°ü
(3) Êý¾Ý°üµÄSYN±ØÐè±»ÉèÖÃ
(4) Ä¿µÄIP±ØÐèΪĿ½ñ×°±¸µÄ¹«ÍøIP
(5) Tcp OptionµÄMSS(Maximum Segment Size) ±ØÐèΪ0c 15 22 2B£¨ÏÖʵÉÏΪ²»·¨MSS£©
ÈôÊÇÖª×ãÒÔÉÏÌõ¼þ£¬Ôò´ÓMSSÖ®ºóµÄ4¸ö×Ö½ÚÌáÈ¡³öC&CµÄIPµØµã¡£ÎÒÃǽ«ÕâÖÖÒÔSYN TCPÊý¾ÝÁ÷×÷ΪÊý¾Ý´«ÊäµÄÊÖÒÕ³ÆΪ¡±SYNËíµÀÊÖÒÕ¡±¡£Ê¹ÓøÃÖÖÊÖÒÕÀ´´«ÊäC&CµØµã²»µ«Äܹ»ºÜºÃÒþÃغڿ͵Ä×Ù¼£(ÎÞÐèÔÚ¶ñÒâ´úÂëÄæÏò»òÕßÍøÂç´æ´¢µãÉÏ̻¶ºÚ¿ÍC&CµØµã)£¬²¢ÇÒÄܹ»ÎÞаµÄ±ä»»C&C£¬ºÜÊÇÄÑÒÔ±»¾õ²ì¡£Òò´Ë£¬¿ÉÒÔ˵Ñù±¾ÖÐÈκÎÄÚÖÃC&C»òÕß´æ´¢C&CµÄ´æ´¢µã±»´¦Öóͷ£ºó£¬¸Ã¶ñÒâ´úÂëÈÔÈ»¿ÉÒÔÊÜ¿ØÓÚºÚ¿Í¡£Õâ¸øÖ´·¨²¿·Ö´¦Öóͷ£¸Ã¶ñÒâ´úÂë´øÀ´ÁËÖØ´óÌôÕ½¡£ÔʼÁ÷µÄ²¿·ÖÅжϴúÂëÈçÏ£º

ÈôÊÇÒÔÉÏÈκÎÒ»ÖÖ·½·¨Äܹ»ÀֳɻñÈ¡µ½ÏÂÔصص㲢ÇÒÏÂÔØ×é¼þÀֳɣ¬¶ñÒâ´úÂë±ã»áÖ±½ÓÖ´ÐÐËùÏÂÔضñÒâ´úÂ룬ȻÍËÈ´³ö¡£ÏÂÔصĵڶþ½×¶ÎµÄ¶ñÒâ´úÂë±»ÉúÑÄΪÎļþ¡±/var/vpnfilter¡±¡£

µÚ¶þ½×¶Î£º¿ØÖÆÏÂÁîÎüÊÕ¡¢·Ö·¢¡¢Ö´ÐÐ
¸ÃÑù±¾ÒÔʵÏÖºóÃÅ¿ØÖÆΪĿµÄ£¬ÆäÖ÷ÒªÓÃÓÚÅþÁ¬¿ØÖƶ˷þÎñÆ÷£¬ÎüÊÕ¿ØÖÆÏÂÁîÖ´ÐÐÏìÓ¦µÄ¹¦Ð§¿ØÖÆ¡£Ñù±¾Ê×ÏÈΪÁËÈ·±£ÔËÐÐʵÌåµÄΨһÐÔ£¬»á°ó¶¨1386¶Ë¿Ú¡£ÈôÊǸö˿ڱ»Õ¼Óñã»áÖÕÖ¹ÔËÐС£±ðµÄÔÚа汾Öв»ÔÙͨ¹ýÕâÖÖÈÝÒ××ÔÎÒ̻¶µÄ·½·¨À´×öΨһÐÔÅжϣ¬²¢ÇÒÌí¼ÓÁË×ÔÎÒɾ³ýµÄ¹¦Ð§¡£

ÈôÊÇ°ó¶¨Àֳɣ¬±ã»á½øÈë½¹µãÊÂÇé´úÂëÖÐÖ´ÐС£Ê×ÏÈΪÁ˱ÜÃâÒòCPU×ÊԴȱ·¦¡¢Æ½Ì¨¼æÈÝÐÔµÈÎÊÌâµ¼ÖÂÎÞ·¨ÊÂÇé»òÕßÍ˳ö£¬Æ仹ע²áÁË´ó×ÚÒì³£ÐźÅÓÃÓÚ×ÔÎÒ¸´Éú¡£

È»ºó½ÓÄÉͬÑùµÄ±äÐÎRC4Ëã·¨ºÍÃØÔ¿À´½âÃÜÒªº¦×Ö·û´®ÒÔ¹©ºóÐøʹÓ᣽ÓÏÂÀ´»áÍê³ÉºóÐø×°ÖÃÉèÖÃÁ÷³Ì¡£
Ê×Ïȼì²âsslÖ¤ÊéÎļþÊÇ·ñ±£´æ£¬ÈôÊDz»±£´æ£¬Æä»á´¦ÓÚÆÚ´ý״̬£¬Ö±µ½Ö¤ÊéÎļþ×°ÖÃÍê³É¡£²»È»×îÏÈÉèÖÃÊÂÇéĿ¼¡¢ÉèÖÃÊðÀíµØµã¡¢ÉèÖÃTorÍøÂçµØµã¡¢»ñÈ¡ÍâÍøIPµØµã¡¢MACµØµã¡¢ÍøÂçÃû³ÆµÈÐÅÏ¢¡£ÏÂͼΪ²¿·Ö×°ÖÃÐÅÏ¢¡£

½ÓÏÂÀ´½¨ÉèÊÂÇéĿ¼/var/run/xxm/¼°/var/run/xxw²¢¿ªÆôÖ÷Ñ»·£¬Ïò¿ØÖƶËÇëÇó¿ØÖÆÏÂÁî²¢ÇÒÖ´ÐÐÏìÓ¦µÄ¿ØÖƹ¦Ð§¡£
¿ØÖÆÏÂÁîµÄÇëÇóÓÐÁ½ÖÖ·½·¨£¬Ò»ÖÖÊÇͨ¹ýsocks5ÊðÀí·½·¨£¬Ò»ÖÖÊÇͨ¹ýTorÍøÂçÇëÇó¡£Í¨¹ýsocks5ÊðÀíÇëÇóµÄC&CµØµãÈçÏÂ(ÔÚа汾ÖÐ91.121.109.209±»ÒƳý)£º
91.121.109.209
217.12.202.40
94.242.222.68
ͨ¹ýTorÍøÂçÇëÇóµÄµØµãÈçÏ£¨ÔÚа汾ÖС±zuh3vcyskd4gipkm.onion/bin32/update.php¡±±»ÒƳý£©£º
6b57dcnonk2edf5a.onion/bin32/update.php
zuh3vcyskd4gipkm.onion/bin32/update.php
tljmmy4vmkqbdof4.onion/bin32/update.php
ÕâÁ½ÖÖ·½·¨µÄÇëÇó¶¼ÊÇͨ¹ýsslÐÒé¾ÙÐеġ£ÇëÇóÍê³Éºó£¬¶ñÒâ´úÂëÆÊÎöÏìÓ¦Êý¾Ý²¢ÇÒÌáÈ¡³ö¿ØÖÆÏÂÁîºÍ¿ØÖƲÎÊýÐÅÏ¢¡£×ÅʵÏÖµÄÔ¶³Ì¿ØÖÆÏÂÁîºÍ¿ØÖƲÎÊýÐÅÏ¢ÈçÏ£º


´Ó¸ÃºóÃÅʵÏÖµÄÔ¶³Ì¿ØÖƹ¦Ð§ÎÒÃÇ¿ÉÒÔÍƲâ¸ÃºÚ¿ÍµÄÄîÍ·£º
(1) ºÍÆäËûºóÃÅÒ»Ñù£¬ºÚ¿ÍÏ£ÍûÄܹ»Í¨¹ýÔ¶³ÌshellÏÂÁî¶Ô×°±¸¾ÙÐÐÍêÈ«µÄ¿ØÖÆ¡£
(2) ºÚ¿Í¿ÉÒÔÔÚһ׼ʱ»ú¶ÔÕâЩװ±¸¾ÙÐÐÆÆËðÐÔ²Ù×÷£¬Ê¹ÆäÎÞ·¨ÔÙ´ÎʹÓá£
(3) ΪÁËÒþ²ØÆä¿ÉÒɵĿØÖÆÁ÷Á¿£¬½ÓÄÉsocks5ºÍTorÌÓ±ÜIDS¼à²â¡£
(4) ¿ÉÒÔÎÞаµÄÉèÖÃÆäÔÚTorÍøÂçÖеÄC&C·þÎñÆ÷ÒÔ¼°ÊðÀí·þÎñÆ÷
(5) ÄÜÌṩÀ©Õ¹Ä£¿éµÄÏÂÔØÓëÖ´ÐеIJÙ×÷¡£
(6) ¿ÉÎÞаÉèÖÃÅþÁ¬C&CµÄƵÂÊ£¬Ìá¸ßÆäÔ˶¯µÄÒþ²ØÐÔ¡£
±ðµÄ£¬¸Ã½×¶ÎµÄ×îжñÒâ´úÂëÓнϴóµÄת±ä£¬²»µ«¶Ô´úÂë×öÁËÓÅ»¯¡¢È¥³ýÁËÈÕÖ¾ÐÅÏ¢£¬»¹¸Ä±äÁ˲¿·Ö¿ØÖÆÏÂÁîµÄ¹¦Ð§£¬ºÃ±ÈkillÏÂÁîÓÃÓÚ¿¢ÊÂÀú³Ì¼°ÕûÀíÆäÏÂÔصIJå¼þ£¬ÐÂÔöÌíÁËupdateÏÂÁîºÍrestartÏÂÁî¡£²»ÑÔ¶øÓ÷£¬updateÏÂÁîÓÃÓÚ¸üÐÂÑù±¾£¬restartÏÂÁîÓÃÓÚÖØÆôÑù±¾Ö´ÐС£Í¬Ê±ÒƳýÁËseturl¡¢proxyÏÂÁî¡£
µÚÈý½×¶Î£ºÀ©Õ¹×é¼þ
µÚÈý½×¶ÎÏÖÔÚÒѾ·¢Ã÷´ó×ÚµÄ×é¼þ£¬ÆäÖаüÀ¨Ò»¸öΪMIPSƽ̨µÄÁ÷Á¿Ðá̽Æ÷¡¢Ò»¸öÓÃÓÚÆÆËð×°±¸µÄdstrÄ£¿é¡¢Ò»¸öÓÃÓÚ¾ÙÐÐÆÕ±éHTTPÁ÷Á¿Ðá̽ºÍ¼à¿ØµÄsslerÄ£¿é£¬ÉÐÓÐһЩ¸¨ÖúÐÔÄ£¿éÈ磺Tor client¡¢mikrotik.o¡¢torrc¡¢ip_tables.ko¡¢iptable_filter.ko¡¢iptable_nat.koµÈ¡£¸¨ÖúÐÔÄ£¿éÈçTor¿Í»§¶ËÓÃÓÚÖ§³ÖµÚ¶þ½×¶ÎµÄTorÍøÂçͨѶ¡£Tor¹¤³ÌÌáÐÑ£º

ÓÉÓÚÆäΪ±ê×¼µÄTor¿Í»§¶Ë£¬²»¾ß±¸¶ñÒ⹦Ч£¬Òò´ËÎÒÃǽö½öÆÊÎö½¹µãµÄÈý¸öÄ£¿é¡£
1¡¢MIPSƽ̨µÄTCPÁ÷Á¿Ðá̽ģ¿é
¸ÃÄ£¿éΪMIPSƽ̨£¬ÆäÖ÷Ҫͨ¹ý´ÓÔʼÊý¾Ý°üÖйýÂ˳öTCP/IPÊý¾Ý°ü£¬²¢ÇÒͨ¹ý¶ÔTCPµÄpayloadÊý¾Ý¾ÙÐйýÂË£¬¼ìË÷ÆäÖеÄÃô¸ÐÐÅÏ¢´æ´¢ÆðÀ´¡£
¸ÃÁ÷Á¿Ðá̽ģ¿éͨ¹ýµÚ¶þ½×¶Î¶ñÒâ´úÂëÔ¶³ÌÏÂÔز¢Æô¶¯Ö´ÐУ¬ÆäÆô¶¯ÔËÐвÎÊýÈçÏ£º
{Ä£¿éÃû} DstDir Unkownagr ModbusServer
ÆäÖеÚÒ»¸ö²ÎÊýΪÐá̽Êý¾ÝµÄ´æ·Å·¾¶£¬µÚ¶þ¸ö²ÎÊýδʹÓ㬵ÚÈý¸ö²ÎÊýΪmodbus serverµÄIPµØµã¡£
¸ÃÄ£¿éÆô¶¯ºó²¢Ã»ÓÐ×ö¹ý¶àÌØÁíÍâÊÂÇ飬³õʼ»¯ÇéÐκóÖ±½ÓŲÓÃÁ÷Á¿½ØÈ¡º¯Êý¾ÙÐÐÁ÷Á¿Ðá̽¡£

ͬÑù¶þ½øÖƳÌÐòÖв»´øÈκηûºÅÎļþ£¬º¯ÊýÓÉÎÒÃÇÆÊÎöÍêºó¾ÙÐÐÁËÖØÃüÃû¡£¸Ãº¯ÊýÖ÷Òª½¨ÉèÒ»¸öÔʼsocket²¢ÇÒÎüÊÕÄ¿½ñ×°±¸Ëùͨ¹ýµÄÔʼÊý¾ÝÁ÷¡£

½ÓÏÂÀ´¶ñÒâ´úÂë»áƾ֤TCP/IPÍ·²¿ÃûÌÃʶ±ð³öTCPÊý¾Ý°üÒÔ¾ÙÐнøÒ»²½µÄ´¦Öóͷ£¡£
Ê×ÏȸÃÄ£¿éÖ»ÌåÌùÊý¾Ý°ü³¤¶È´óÓÚ0x96¸ö×Ö½ÚµÄÔʼÁ÷Êý¾Ý£¬Ò²¾ÍÊÇ˵³ýÈ¥TCP/IPÐÒéÍ·²¿µÄ³¤¶ÈµÄ0x36¸ö×Ö½Ú£¬¸ÃÄ£¿é½ö½ö¼àÊÓ´óÓÚ0x60¸ö×Ö½ÚµÄTCP payloadÊý¾Ý¡£

¹ØÓÚTCP payloadÊý¾Ý´óÓÚ0x60¸ö×Ö½ÚµÄÊý¾Ý°ü£¬¸ÃÄ£¿é»áÆÊÎöIP¡¢TCPÐÒ飬²¢ÇÒͨ¹ýÄ¿µÄ¶Ë¿Ú502ÅжÏÄ¿½ñÁ÷Á¿Êý¾ÝÊÇ·ñÊǹ¤¿ØµÄmodbus TCPÐÒé°ü£¬ÈôÊÇÊÇ£¬ÇÒÄ¿½ñÊý¾Ý°üµÄÄ¿µÄIPΪÔËÐвÎÊýÖÐÖ¸¶¨µÄIPµØµã£¬¸ÃÄ£¿é±ã»á½«¸ÃÊý¾Ý°üÖеÄÔ´IP¡¢Ä¿µÄIP¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú¼Í¼ÏÂÀ´¡£

ÆäÖмͼµÄÐÅÏ¢ÃûÌÃÈçÏ£º
*modbus*
Ô´IP:Ô´¶Ë¿Ú->Ä¿µÄIP:Ä¿µÄ¶Ë¿Ú(È磺192.168.1.5:2243->192.168.1.3:503)
¸ÃÐÅÏ¢¼Í¼ÔÚÎļþ%workdir%/rep_[time].bin¡£

ÈôÊÇÄ¿½ñÐÒé²»ÊÇmodbusÐÒ飬¸ÃÄ£¿é»áƾ֤ÒÑÓеĹæÔò¾ÙÐйýÂË£¬ÕÒ³öÆäÌåÌùµÄÁ½ÀàÊý¾Ý£ºÒ»ÖÖΪЯ´øÓÐÑéÖ¤ÐÅÏ¢HTTPÊý¾Ý°ü£¬Ò»ÖÖÊÇЯ´øÓеǼÐÅÏ¢µÄHTTPÇëÇóÊý¾Ý¡£ÆäÖÐÌáÈ¡ÑéÖ¤Êý¾ÝµÄÒªº¦×ÖΪ"Authorization: Basic¡±£¬Ò»µ©ÕÒµ½¸ÃÐÅÏ¢£¬¸ÃÄ£¿é»á½«Ä¿½ñÐá̽µ½µÄÊý¾Ý°üÖ±½Ó¼Í¼µ½Îļþ%workdir%/rep_[%time%].binÖС£
ÌáÈ¡µÇ¼ÐÅÏ¢µÄÒªº¦×ÖÈçÏ£º
Óû§ÃûÒªº¦×Ö£º"User="¡¢"user="¡¢"Name="¡¢"name="¡¢"Usr="¡¢"usr="¡¢"Login="¡¢"login="
µÇ¼ÃÜÂëÒªº¦×Ö£º"Pass="¡¢"pass="¡¢"Password="¡¢"password="¡¢"Passwd="¡¢"passwd="
±ðµÄҪ˵Ã÷µÄÊÇ£¬Êý¾Ý°üÖÐÖ»ÒªÖª×ãÈçÏÂÌõ¼þ£¬¸ÃÄ£¿é±ã»áÑïÆú£º
(1) Êý¾Ý°üµÄÄ¿µÄIPΪģ¿éÔËÐвÎÊýËùÖ¸¶¨µÄIP¡£
(2) Êý¾Ý°üµÄÔ´¶Ë¿ÚСÓÚ1024¡£
(3) Êý¾Ý°üµÄÔ´¶Ë¿ÚΪ8080/8088¡£
(4) TCP payloadÊý¾Ý³¤¶ÈСÓÚ0x14¡£
(5) TCP PayloadÊý¾Ý°üÖаüÀ¨ÓÐ"<?xml"¡¢">"¡¢"Basic Og=="¡¢"/tmUnblock.cgi"¡¢"Password required"¡¢"<div¡±¡¢"<form"¡¢"<input"¡¢"{"¡¢"}"¡¢"200 OK"¡¢".get"¡¢"<span "¡¢"<SPAN "¡¢"<DIV "µÈ¡£
2¡¢ssler HTTPÐá̽Óë¼à¿ØÄ£¿é
¸ÃÄ£¿éÖ÷ÒªÕë¶ÔHTTP²ãʵÑéÔ½·¢¸»ºñºÍÇ¿Ê¢µÄ´¦Öóͷ££¬ÆäÌṩÓÐHTTPÁ÷Á¿Öض¨Ïò¡¢HTTPÁ÷Á¿¼à¿ØÓë½ØÈ¡¡¢Á÷Á¿Ð®ÖÆÓë¸Ä¶¯¡¢¶¨Ïò×¢ÈëJSÒÔ¾ÙÐо«×¼¹¥»÷µÈ¹¦Ð§¡£ÆäÓɵڶþ½×¶ÎµÄ¶ñÒâÄ£¿éÆô¶¯ÔËÐУ¬ÔËÐвÎÊý˵Ã÷ÈçÏ£º

Ê×ÏȸÃÄ£¿é»áʹÓÃinsmodÏÂÁî×°ÖÃÈý¸öiptableÏà¹ØµÄÄÚºËÄ£¿é (ip_tables.ko¡¢iptable_filter.ko¡¢ iptable_nat.ko)£¬Í¨¹ýÕâÈý¸öÄ£¿é£¬¶ñÒâ´úÂë¿ÉÒÔ½«×Ô¼ºµÄ¹æÔòÉèÖõ½iptableÖÐÈ¥ ¡£

½ÓÏÂÀ´Ö´ÐÐÈçÏÂÏÂÁËùÓÐ80¶Ë¿ÚµÄÁ÷Á¿Öض¨Ïòµ½ÆäËù¼àÌýµÄ8888¶Ë¿ÚÉÏ£º
iptables -I INPUT -p tcp --dport 8888 -j ACCEPT
iptables -t nat -I PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8888

ΪÁË°ü¹Ü¸Ã¹æÔò²»»á±»É¾³ý£¬¸ÃÄ£¿é»áÿ¸ô5·ÖÖÓ¸üÐÂÒ»´Î¸Ã¹æÔò¡£
¸ÃÄ£¿é»á¹Ø×¢ËùÓÐ80¶Ë¿ÚÉϵÄÊý¾Ý£¬°üÀ¨Á÷Ïò·þÎñÆ÷¶ËºÍÁ÷Ïò¿Í»§¶ËµÄÊý¾Ý¡£ÔÚ´¦Öóͷ£Á÷Ïò·þÎñÆ÷¶ËµÄÊý¾Ýʱ£¬ÎªÁË×î´ó»¯µÄ¼à¿Øµ½Ãô¸ÐÊý¾Ý£¬Æä»á¶ÔHTTPÇëÇóµÄÊý¾Ý¾ÙÐÐÒ»¶¨¸Ä¶¯¡£ÔÚ´¦Öóͷ£Á÷Ïò¿Í»§¶ËµÄÏìÓ¦Êý¾Ýʱ£¬Í¬Ñù»á¶ÔÊý¾Ý¾ÙÐиĶ¯²¢ÇÒƾ֤Æô¶¯²ÎÊýµÄÖ¸¶¨À´¶ÔÌض¨Ä¿µÄʵÑ龫׼µÄJS×¢È룬ÈëÇÖµ½Ïêϸ¿Í»§¶ËÖ÷»úÉÏ£¬Ò²¿ÉÒÔÊÇÄÚÍøµÄ°ì¹«Ö÷»úÉÏ¡£
£¨1£©¶ÔÇëÇóÊý¾ÝµÄ´¦Öóͷ£
Ê×ÏÈ£¬¸ÃÄ£¿éΪÁËÄܹ»×î´óÏ޶ȵļà¿Øµ½Á÷Á¿£¬Æä»á½«ËùÓÐÇëÇóÊý¾ÝµÄ"https://"¸Ä¶¯Îª"http://"¡£ÎªÁËÈ·±£HTTP´«ÊäµÄÊý¾Ý¶¼Îª¿É´¦Öóͷ£Êý¾Ý£¬»áÐ޸ġ±Accept-Encoding¡±µÄÖµ£¬ÒÔ¼°ÐÞ¸ÄConnectionµÄ·½·¨£¬Ïêϸ´¦Öóͷ£·½·¨ÈçÏ£º
i. ½«ÇëÇóÊý¾ÝÖеÄËùÓÐhttps¸Ä¶¯Îªhttp£¬ÒÔÀû±ã¼à¿Ø²¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÈçµÇ¼ƾ֤µÈ¡£

ii. ÈôÊÇHTTPÇëÇóÖаüÀ¨ÓС±Connection: keep-alive¡±£¬½«»á±»Ì滻Ϊ¡±Connection: close¡±¡£

iii. ÈôÊÇHTTPÇëÇóÖÐ,HTTPÍ·ÖаüÀ¨ÓÐgzipÖµµÄ¡±Accept-Encoding¡±Í·²¿Óò(ɨ³ýurlΪjpg¡¢jpeg¡¢png¡¢gif¡¢css¡¢js¡¢ttf¡¢woffÎļþ)£¬Æ佫»áת»¯Îª¡±Accept-Encoding: plaintext/none¡±£¬ÕâÑùÇëÇó»ñµÃµÄÊý¾Ý±ã²»»á±»·þÎñÆ÷¶ËѹËõ¡£

Ëæºó£¬¸Ã×é¼þ¿É¶Ô½ØÈ¡µÄÁ÷Á¿¾ÙÐйýÂ˲¢½«Ïà¹ØÊý¾ÝÉúÑĵ½×°±¸ÖС£Ê×ÏÈÈôÊÇ¡±dump:domain¡±²ÎÊý±»Ö¸¶¨£¬httpÇëÇóµÄurl¡¢port¡¢http header¶¼»áÉúÑÄÔÚÖ¸¶¨µÄÎļþÖС£ÈôÊÇÔÚdump²ÎÊýÖÐûÓÐÖ¸¶¨Ïêϸֵ(domain×Ö·û´®Îª¿Õ)»òÕßdump²ÎÊýûÓÐָ׼ʱ£¬Æä»ádump°üÀ¨ÓÐÌض¨ÐÅÏ¢httpÇëÇóÐÅÏ¢¡£Æäͨ¹ýURLÀ´ÅжÏÄ¿½ñÇëÇóÊÇ·ñÊÇÆäÌåÌùµÄÇëÇó£¬ÈôÊÇURLÖаüÀ¨ÓÐÒªº¦×Ö£º
¡±sername=¡±¡¢¡±ser=¡±¡¢¡±ame=¡±¡¢¡±ogin=¡±¡¢¡±ail=¡±¡¢¡±hone=¡±¡¢¡±session%5Busername¡±¡¢¡±session%5Bpassword¡±¡¢¡±session[password¡±±ã»ádumpÇëÇóµÄÍ·²¿ÐÅÏ¢µ½Ö¸¶¨µÄÎļþÖС£

ÁíÍ⣬¶Ôaccounts.google.com·¢Ë͵ÄPOSTÇëÇó£¬Ö»ÒªÆäÖаüÀ¨ÓÐ×Ö·û´®¡±signin¡±,¶¼»á±»dumpÏÂÀ´¡£

£¨2£©¶ÔÏìÓ¦ÐÅÏ¢µÄ´¦Öóͷ£
ËùÓÐHTTPÇëÇó»ñµÃµÄÏìÓ¦Êý¾Ý¶¼»á±»´¦Öóͷ££¬Æä´¦Öóͷ£·½·¨ÈçÏ£º
i. ÏìÓ¦ÐÅÏ¢ÖÐLocationµÄÖµÈôÊÇÊÇ¡±https://¡±£¬Ôò±»Ì滻Ϊhttp://¡£
ii. ÈôÊÇÏìӦͷ²¿ÖаüÀ¨ÓÐAlt-Scv¡¢Vary¡¢Content-MD5¡¢content-security-policy¡¢X-FB-Debug¡¢public-key-pins-report-only¡¢Access-Control-Allow-Origin£¬±ã»á±»×è¶Ï£¬Ò²¾ÍÊÇ˵£¬ÇëÇó·½ÎÞ·¨»ñµÃÏìÓ¦¡£
iii. DumpËùÓÐÇëÇó°üµÄÊý¾Ýµ½ÍâµØ£¬ÆäÖаüÀ¨https://ºÍhttp://¡£
iv. ÈôÊDzÎÊý¡±site:domain¡±Ö¸¶¨ÁËÓòÃûÒªº¦×Ö»òÕßÓòÃûµÄÒ»²¿·Ö£¬Æä»á½«Ò»¶Îjavascript¾ç±¾×¢Èëµ½ËùÓаüÀ¨Óеġ±Content-Type: text/html¡± »òÕß¡±Content-Type: text/javascript¡±ÏìÓ¦Êý¾ÝµÄmsgbodyÖС£Æä×¢ÈëÒªÁ죺Ê×ÏÈÏìÓ¦µÄmsgbodyÊý¾ÝÖбØÐè°üÀ¨×Ö·û´®¡±<meta name= ¡ >¡±²¢ÇÒ³¤¶È±ØÐè´óÓÚ²ÎÊý¡±hook:¡±ËùÖ¸¶¨µÄ×Ö·û´®³¤¶È¡£ÈôÊÇÖª×ãÌõ¼þ£¬×Ö·û´®¡±<meta name= ¡ >¡±½«»á±»Ìæ»»³ÉΪ¡±<script type="text/javascript" src="[hook value]">¡±£¬Ä¿½ñÊܺ¦ÕßIP¼°Æä»á¼ûµÄÍøÕ¾ÓòÃû½«»á¼ÓÈëµ½ÄÚ²¿µÄÒ»¸ö°×Ãûµ¥ÖУ¬ÒÔ±ÜÃâÖظ´×¢È룬°×Ãûµ¥Ã¿4Ìì»á±»Çå¿ÕÒ»´Î¡£

ÔÚÏìÓ¦Êý¾ÝÖУ¬¶ñÒâÄ£¿é»áÌáȡÿ¸öÁ´½ÓÖеÄÓòÃû£¬²¢ÇÒ½«Æä¼ÓÈëµ½½ØÈ¡ÁбíÖУ¬Õâ¸ö½ØÈ¡ÁбíÖÐËùÓеÄhttpsºÍhttpÇëÇ󶼻áƾ֤¡°£¨1£©¶ÔÇëÇóÊý¾ÝµÄ´¦Öóͷ£¡±µÄ·½·¨¾ÙÐд¦Öóͷ£¡£Ä¬ÈÏÇéÐÎÏ°üÀ¨ÓÐ www.google.com¡¢ twitter.com¡¢ www.facebook.com¡¢www.youtube.com¡£

3¡¢ ×°±¸ÆÆËðÄ£¿é£¨Destroy module£©
ÓÉÓÚÀÏ°æ±¾µÄµÚ¶þ½×¶ÎÄ£¿é´¿´âµÄÖ»ÊǼòÆÓ²Á³ý×°±¸mtdblock0µÄÇ°5000¸ö×Ö½ÚÒÔÆÆËð×°±¸£¬Óкܴó¼¸ÂÊ»áʧ°Ü£¬Òò´Ëа汾µÄµÚ¶þ½×¶ÎÄ£¿é½«killÖ¸ÁîµÄÆÆËðÐÔ¹¦Ð§×÷·Ï£¬²¢½ÓÄɲå¼þÄ£¿éµÄ·½·¨À´ÊµÏÖ¡£¸Ã²å¼þÄ£¿é²»µ«Ë¢ÐÂÁËÆÆËð×°±¸¹¦Ð§£¬²¢ÇÒ»¹ÌṩÁ˺ۼ£ÕûÀíµÄ¹¦Ð§¡£ÆäÄ¿µÄ²»µ«ÈÃ×°±¸ÎÞ·¨»Ö¸´£¬²¢ÇÒ¼´±ã»Ö¸´ÁËÒ²ÎÞ·¨È¡Ö¤»ñÈ¡¶ñÒâ´úÂëÏà¹ØºÛ¼£¡£
Ä£¿éÆô¶¯ºóÊ×ÏÈɾ³ý×ÔÉíÎļþ£¬È»ºóÇ¿ÖƹرÕËùÓаüÀ¨"vpnfilter"¡¢"security"¡¢"tor"Òªº¦×ÖµÄÀú³Ì¡£

½ÓÏÂÀ´ÕûÀíµôËùÓкۼ£Îļþ£¬ÆäÖаüÀ¨ÓÐÖ¤ÊéÎļþ¡¢Tor¿Í»§¶ËÏà¹ØÎļþ¡¢°æ±¾ÐÅÏ¢ÎļþµÈ¡£

¸ÃÄ£¿é»¹»á±éÀúmtd·ÖÇø£¬²¢Ç¿ÖƲÁ³ýÕû¸öFLASH¡£

×îºó£¬Æä½ÓÄÉ¡±"rm -rf /*"¡±Ç¿ÖƵݹéɾ³ýÎļþϵͳÉϵÄËùÓÐÎļþ£¬²¢ÖØÆô×°±¸¡£

ËÄ¡¢×ܽá
̫ͨ¹ýÎöÎÒÃÇ¿ÉÒÔ¿´³ö£¬¸Ã¶ñÒâ´úÂë¹¥»÷ÊÖ·¨ÒþÃظßÃ÷£¬Æä²»µ«½ÓÄÉÊðÀí+Tor+SSLµÄ·½·¨ÒÔÌÓ±ÜÍøÂçÁ÷Á¿µÄ¼à²â£¬²¢ÇÒÉÐÓжàÖØÕ½ÂÔÓÃÓÚÈ·±£½¹µã×é¼þ(µÚ¶þ½×¶Î¶ñÒâ´úÂë)µÄÀÖ³ÉÏ·¢¡£Ê×ÏȽÓÄÉÁËHTTPµÄ·½·¨½«C&C´æ·ÅÓÚ¡±direct¡±»òÕß¡±location¡±×Ö¶ÎÖУ¬ÈôÊÇÕâÖÖ·½·¨±»×è¶ÏÔò½ÓÄÉͼƬÒþдÊÖÒÕ½«C&C´æ´¢ÓÚEXIFÖУ¬ÈôÊÇ´æ´¢C&CµÄͼƬÁ´½ÓʧЧ£¬Æ仹ÔÚ´úÂëÖÐÁôÁËÒ»¸ö¡±SYN¡±ºóÃÅ£¬Í¨¹ý¡±SYNËíµÀÊÖÒÕ¡±À´´«ÊäC&C¡£ÕâÖÖ¿ÉÒÔ˵ÊǺڿͽÓÄɵÄÒ»ÖÖ½ÏΪ¸ßÃ÷ÇÒºÜÊÇ°ü¹ÜµÄÕ½ÂÔ£¬ÎªÆäÐж¯ÔÚ±»·¢Ã÷ÉõÖÁÊDZ»×è¶ÏºóÉèÖÃÁ˶àÖØ°ü¹Ü£¬Ò²±ãÓÚÔÚºÚ¿Í·¢Ã÷±»×è¶Ïºó¾ÙÐпìËÙÇл»£¬¼«´óµØÌá¸ßÁËÆä¿ØÖƵij¤ÆÚÐÔºÍÎÞаÐÔ¡£
ÎÒÃÇ»¹¿ÉÒÔ¿´µ½£¬Ñ¸ÃÍÉú³¤µÄÎïÁªÍø×°±¸Ò²×îÏÈÄð³É¸ß¼¶Íþв×éÖ¯µÄÒ»À๥»÷ÏòÁ¿£¬ÆäÊÔͼͨ¹ýÕâЩװ±¸À´ÍøÂçÇ鱨£¬°üÀ¨µÇ¼ƾ֤ÒÔ¼°¹¤¿ØÉèÊ©Ïà¹ØµÄÖ÷ÒªÐÅÏ¢£¬Í¨¹ýÎÞаµÄÄ£¿é»¯¼Ü¹¹£¬¿Éƾ֤Ïà¹ØÇ鱨¶ÔÌض¨Ö÷»úʵÑ龫׼¹¥»÷»òÕ߶Դó×Ú×°±¸ÊµÑ鼫¾ßÆÆËðÐԵĹ¥»÷£¬ÆäΣº¦ÐÔºÜÊÇÖ®´ó¡£
½¨Ò鳧É̽«¼ì²â¹æÔò£¨TalosÒѾ¹ûÕæÁË100¶àÌõsnort¹æÔò£©¼ÓÈëµ½Á÷Á¿¼ì²â×°±¸ÖУ¬ÈôÊÇÖ§³ÖÔʼÁ÷Á¿¼ì²â£¬Ò²¿ÉʹÓá°SYNËíµÀÊÖÒÕ¡±ÖеÄÌØÕ÷¾ÙÐÐÔ½·¢Éî¶ÈºÍ׼ȷµÄ¼ì²â¡£Ò»µ©·¢Ã÷ÊÜѬȾװ±¸£¬½¨Òé½ÓÄÉÓ¦¼±Õ½ÂÔ¶Ô×°±¸¾ÙÐд¦Öóͷ££¨ºÃ±È¶Ô×°±¸¾ÙÐжÏÍø²¢ÇÒ¸´Î»»Ö¸´µ½³ö³§Ä£Ê½¡¢¸üÐÂ×îй̼þ£©£¬Í¬Ê±½øÒ»²½¼ì²éÄÚÍøÖ÷»úÊÇ·ñÓб»¹¥»÷²¢ÇëרҵÈËÊ¿¾ÙÐд¦Öóͷ£¡£
IOC:
µÚÒ»½×¶ÎÉæ¼°µÄÏà¹ØURL:
photobucket[.]com/user/nikkireed11/library
photobucket[.]com/user/kmila302/library
photobucket[.]com/user/lisabraun87/library
photobucket[.]com/user/eva_green1/library
photobucket[.]com/user/monicabelci4/library
photobucket[.]com/user/katyperry45/library
photobucket[.]com/user/saragray1/library
photobucket[.]com/user/millerfred/library
photobucket[.]com/user/jeniferaniston1/library
photobucket[.]com/user/amandaseyfried1/library
photobucket[.]com/user/suwe8/library
photobucket[.]com/user/bob7301/library
toknowall[.]com
µÚ¶þ½×¶ÎÉæ¼°µÄÏà¹ØIP¼°Á´½Ó£º
91.121.109[.]209
217.12.202[.]40
94.242.222[.]68
82.118.242[.]124
46.151.209[.]33
217.79.179[.]14
91.214.203[.]144
95.211.198[.]231
195.154.180[.]60
5.149.250[.]54
91.200.13[.]76
94.185.80[.]82
62.210.180[.]229
62.210.180[.]229
91.200.13[.]76
23.111.177[.]114
6b57dcnonk2edf5a[.]onion/bin32/update.php
tljmmy4vmkqbdof4[.]onion/bin32/update.php
zuh3vcyskd4gipkm[.]onion/bin32/update.php
4seiwn2ur4f65zo4.onion/bin256/update.php
zm3lznxn27wtzkwa.onion/bin16/update.php
×îÐÂÊÜѬȾµÄ×°±¸ÈçÏ£º

²Î¿¼Á´½Ó£º
https://blog[.]talosintelligence.com/2018/05/VPNFilter.html
https://blog.talosintelligence.com/2018/06/vpnfilter-update.html