Õë¶ÔÖÆÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷Ô˶¯Éî¶ÈÆÊÎö
Ðû²¼Ê±¼ä 2019-11-07½üÆÚ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷´ó×ÚʹÓøßΣÎó²îCVE-2017-11882¾ÙÐÐÍøÂç¹¥»÷µÄÊÂÎñ£¬ÆäÖÐÒ»Åú¹¥»÷ÔغÉÒýÆðÁËÎÒÃǵÄ×¢ÖØ£¬ËûÃǾùÒÔÀàËÆ¡°¸¶¿îÊÕÌõ¡±¡¢¡°ÒøÐÐÈ·ÈÏ¡±µÈ×ÖÑù×÷Ϊ¹¥»÷ÔغÉÃû³Æ¡£¸ÃÅú¹¥»÷Ôغɴ󲿷Öͨ¹ýÓʼþ¸½¼þµÄ·½·¨¾ÙÐд¹ÂÚ¹¥»÷£¬ÔÚÆÊÎöÀú³ÌÖУ¬ÎÒÃÇ·¢Ã÷Á˺ڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÏà¹ØÐÅÏ¢£¬´ËÅúºÚ¿ÍÒѾÀÖ³ÉÉø͸½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÖÆÒ©ÆóÒµ£¬ÒÔ¼°Î÷°àÑÀµÄÕþ¸®¡¢ÆóÊÂÒµµ¥Î»µÈ»ú¹¹£¬²¢ÇÒ͵ȡÁË´ó×ÚµÄÃôÇéÐ÷±¨¡£ÎÒÃÇͨ¹ýËÝÔ´ÆÊÎöÈ·¶¨´Ë´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ£¬²¢ÇÒÓÉÄ¿½ñ¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£Í¨¹ý¶Ô¸ÃÅúÑù±¾µÄÆÊÎö·¢Ã÷´Ë´Î¹¥»÷Ô˶¯×îÔç¿É×·Ëݵ½2019Äê7Ô£¬×èÖ¹ÏÖÔÚ£¬Ïà¹ØµÄÉèÊ©ÒÀÈ»ÔÚʹÓÃÖв¢Ò»Á¬ÔÚÍøÂçÇ鱨ÐÅÏ¢¡£¸ÃºÚ¿Í×éÖ¯»¹¹¥ÏÝÁËÎ÷°àÑÀÒ»¼Ò´óÐÍ´¬²°ÖÎÀí¹«Ë¾µÄ¹Ù·½ÍøÕ¾×÷ΪÇ鱨ÇÔÈ¡µÄÉñÃػش«µã£¬ÊÔͼÒþ²Ø×ÔÉíÉí·Ý¡£
ÔÚ±¾´Î¹¥»÷ÖУ¬ºÚ¿Í×é֯ͨ¹ýÓʼþ½«È«ÐĽṹµÄOfficeÎļþ£¨Õë¶ÔCVE-2017-11882Îó²îÖÆ×÷µÄ£©×÷Ϊ¸½¼þ·¢Ë͸øÄ¿µÄÓÊÏ䣬²¢ÓÕʹÊܺ¦Õßµã»÷ÒÔÇÖÈëÄ¿µÄϵͳ£¨ËäÈ»ÕâÖÖÒÔÉ繤ÐÎʽÕÒµ½Ä¿µÄÓÊÏ䲢ͨ¹ýÓʼþµÄ·½·¨¾ÙÐй¥»÷µÄÊÖ·¨ÀÏÌ×£¬µ«È´ÊǺڿÍ×î³£ÓõĹ¥»÷ÊÖ·¨Ö®Ò»£¬²¢ÇÒÍŽáÉ繤ÐÅϢαÔìµÄÓʼþÒ²¾ßÓкܸߵÄÀÖ³ÉÂÊ, ²¿·ÖÐÐÒµºÍÆóÊÂÒµµ¥Î»ÓÉÓÚδ¾ÙÐÐÏà¹ØÎó²î²¹¶¡¸üжøÒ×Êܵ½¹¥»÷£©¡£¹¥»÷Ôغɻáƾ֤µØÀíλÖõIJî±ð¶øÔÚÊܺ¦ÕßµçÄÔÉÏÏÂÔز¢×°ÖÃAgent Tesla¡¢HawEye Keylogger¡¢NanoCore RAT»òNetWire RATµÈ¶à¿îÌع¤Ä¾Âí£¬ÒÔ¶Ô¹¥»÷Ä¿µÄʵÑéºã¾ÃµÄ¼à¿Ø¿ØÖÆ¡¢Ãô¸ÐÐÅÏ¢ÇÔÈ¡µÈ¶ñÒâÐÐΪ¡£
±¾ÎĽ«¶ÔºÚ¿Í×éÖ¯ËùʵÑéµÄ¹¥»÷Àú³Ì¾ÙÐÐÏêϸµØÆÊÎöºÍËÝÔ´£¬²¢¶ÔÆäËùʹÓõÄÌع¤Èí¼þºÍ»ù´¡ÉèÊ©¾ÙÐÐ͸³¹µØÆÊÎö¡£
1¡¢¹¥»÷Àú³ÌÆÊÎö
´Ë´Î¹¥»÷ʼÓÚÒ»¸öЯ´øCVE-2017-11882Îó²îµÄEXCELÎĵµ£¬ºÚ¿ÍʹÓÃαװ³É¡°ÒøÐÐÈ·ÈÏ¡±µÄ´¹ÂÚÓʼþ·¢Ë͸ø¹¥»÷Ä¿µÄ£¬µ±Óû§·¿ªÎĵµºó±ã»áÖ´ÐÐshellcode´úÂ룬²¢´ÓÖ¸¶¨µÄ·þÎñÆ÷ÉÏÏÂÔØPayload²¢Ö´ÐС£¸ÃPayload»áÔÚÄÚ´æÖнâÃܳöеÄPE²¢×¢È뵽ϵͳÀú³ÌRegAsm.exeÖУ¬ÀÖ³É×¢Èëºó±ã×îÏȾÙÐÐʵʱ¼à¿Ø¡¢ÇÔÃܵÈÐÐΪ£¬×îÖÕ½«ÇÔÈ¡µ½µÄÓû§ÐÅÏ¢»Ø´«µ½ÍйܷþÎñÆ÷¡£
1.1 ¹¥»÷Á÷³Ì
ÏÂͼչʾÁ˴˴ι¥»÷Ô˶¯ÍêÕûµÄÁ÷³Ì£º
ͼ1 ¹¥»÷Á÷³Ìͼ
1.2 ¹¥»÷Ä¿µÄ
±»¹¥»÷¹«Ë¾ÐÅÏ¢¼°Ïà¹ØÓʼþ1£º
´¹ÂÚÓʼþÊÇ·Ö·¢µ½µÂ¹úµÄÒ»¼Ò¼Ò×åÆóÒµ¹«Ë¾¡£¸Ã¹«Ë¾ÊÇרÃÅÑо¿¶¯Ö²ÎïÖÊÁϵÄÌáÈ¡£¬ÆäÖ÷ÒªÓªÒµÊÇÑо¿ÖÆÒ©¡¢»¯×±Æ·ºÍÉúÎïµÈÊÖÒÕ¡£
ͼ2 Ä¿µÄ¹«Ë¾1
ͨ¹ýͼ2¿ÉÒÔ¿´µ½£¬¹¥»÷Õß¿ÉÒԴӸù«Ë¾µÄÖ÷Ò³ÉÏ»ñÈ¡ÓÊÏäµØµã£¬²¢½«×ÔÉíαװ³É¡°¸¶¿îÈ·ÈÏ¡±µÈ֪ͨÓʼþ£¬ÓÕʹÊܺ¦Õß·¿ª¸½¼þÎĵµ¡£
ͼ3 ´¹ÂÚÓʼþ1
±»¹¥»÷¹«Ë¾ÐÅÏ¢¼°Ïà¹ØÓʼþ2£º
ÁíÒ»ÃûÊܺ¦ÕßÊǵ¹úµÄÒ»¼ÒÒ½ÁÆÒ©Æ·Æ÷е¹«Ë¾¡£¸ÃÊÕ¼þÓÊÏäµØµãͬÑù¿ÉÔÚÆä¹ÙÍøÉÏ»ñÈ¡¡£
ͼ4 Ä¿µÄ¹«Ë¾2
·¢Ë͸øÄ¿µÄ¹«Ë¾µÄ´¹ÂÚÓʼþʾÀýÈçÏÂͼ£º

ͼ5 ´¹ÂÚÓʼþ2
Á½Æð´¹ÂÚÓʼþµÄ¸½¼þ¾ùÊÇÃûΪ¡°bank cconfirmation¡±µÄXLSXÎĵµ£¬¶ø¸Ã¸½¼þÎļþÊÇÎÒÃDz¶»ñµÄÖÚ¶àʹÓÃCVE-2017-11882Îó²îµÄ¶ñÒâÎĵµÖ®Ò»¡£
1.3 ÓÕ¶üÓʼþ
Á½·âÓʼþµÄÄÚÈÝ¡¢·¢¼þÈËÒÔ¼°¶ñÒâÎĵµµÄÃû³Æ£¬¾ù¼á³Öן߶ȵÄÒ»ÖÂÐÔ¡£Ëæºó£¬ÎÒÃǽ«¶ÔÓʼþÐÅÏ¢×ö½øÒ»²½µÄÆÊÎö£¬ÒÔ±ãÍÚ¾ò³ö¸ü¶àµÄ¹ØÁªÏßË÷¡£
ͨ¹ý¶ÔÓʼþÐÅÏ¢¾ÙÐÐÆÊÎö¿ÉÒÔ¿´µ½Èçͼ6Ëùʾ£¬·¢¼þµØµãÀïÁгöµÄÏÖʵµç×ÓÓʼþµØµãΪ¡±mana00.balaempre.com¡±¡£Æ¾Ö¤ÓÊÏäºó׺Ãû¾ÙÐÐÅÌÎÊ£¬·¢Ã÷ÆäËù¶ÔÓ¦µÄÊÇÒ»¿îÃûΪ¡°AutoPMTA¡±µÄ×Ô¶¯»¯µç×ÓÓʼþ·Ö·¢·þÎñÆ÷£¬²¢ÔÚÍâÑóµÄÍøÕ¾ÖÐƾ֤Ïêϸ¹¦Ð§ÊÕÈ¡²î±ðµÄÓöȡ£ÓÉ´ËÎÒÃÇÍƲâºÚ¿Í×éÖ¯¾ÍÊÇʹÓô˿îÈí¼þÀ´¾ÙÐÐÓÊÏäµØµãµÄÍøÂçºÍÓʼþµÄÅúÁ¿·Ö·¢¡£
ͼ7 AutoPMTAÓʼþ·Ö·¢Æ÷
¶øÔÚÁíÒ»·âÓʼþÖУ¬ÎÒÃÇÊ״η¢Ã÷ÁËÒ»¸öÊôÓÚÄáÈÕÀûÑǵÄÔ¶³ÌIPµØµã£¬¸ÃÏßË÷µÄ·ºÆðÔÚºóÐøµÄ¹ØÁªËÝÔ´ÖÐÆð×ÅÖ÷ÒªµÄ×÷Óã¬ÔÚÕâÀïÏȽ«Æä¼Í¼ÏÂÀ´¡£
ͼ8 IPµØµãÅÌÎÊÐÅÏ¢
2¡¢ÑùÌìÖ°Îö
2.1 ¶ñÒâÎĵµ
ÔÚδÐÞ¸´CVE-2017-11882Îó²îµÄÅÌËã»úÉÏ£¬µ±Óû§·¿ª¶ñÒâEXCELÎļþʱ£¬OfficeÎĵµÖеĹ«Ê½±à¼Æ÷»áÆô¶¯EQNDT32.EXEÀú³Ì¡£µ±Equation¹¤¾ßÖб£´æ±ê¼ÇΪ×ÖÌåÃû³ÆµÄ³¬³¤×Ö½ÚÔ¼£¬Ôò³ÌÐòÔÚ´¦Öóͷ£¸Ã×Ö·û´®µÄÀú³ÌÖУ¬»á´¥·¢Õ»Òç³öÎó²î¡£¶ø´Ë¶ñÒâÎĵµ¼´ÊÇʹÓøÃÎó²î½«Ö¸ÏòshellcodeµÄÕ»µØµãÁýÕÖÁËÔʼ·µ»ØµØµã£¬´Ó¶øÖ´ÐÐÔ¶³ÌpayloadµÄÏÂÔØ¡£
Éó²éole¹¤¾ßµÄĿ¼½á¹¹£¬¿ÉÒÔ¿´µ½ole¹¤¾ßÒѱ»Ê¶±ðΪCVE-2017-11882£º
ͼ9 OLE¹¤¾ßµÄĿ¼½á¹¹
ÓÉÓڸûº³åÇøÒç³öº¯Êý´¦ÓÚEQNDT32Àú³ÌÖУ¬ÒÔÊÇÎÒÃÇÌáÇ°½«EQNDT32.EXE¼ÓÔØÆðÀ´²¢ÕÒµ½Îó²îÒçÀ´ÓÉ϶ϵ㣬ÖØз¿ªÓÕ¶üÎĵµºó£¬·¢Ã÷Õ»Öзµ»ØµØµã0x004115D8±»ÁýÕÖ£¬´Ó¶øתÏòshellcodeÖ´ÐС£
ͼ10 Õ»ÖÐÉúÑĵÄÔʼº¯Êý·µ»ØµØµã
ͼ11 ±»ÁýÕÖºóµÄº¯Êý·µ»ØµØµã
2.2 shellcode
RetnÖ´Ðкó³ÌÐò»áתµ½0x0012F350´¦£¬ÕâÀï´æ·ÅµÄ¾ÍÊÇFONT[name]Êý¾Ý£¬Ò²¾ÍÊÇshellcode´úÂëλÖá£
ͼ12 shellcode´úÂëÖ´Ðд¦
¸Ã¶ÎshellcodeµÄ¹¦Ð§ÊÇ£¬½«Ô¶³Ì·þÎñÆ÷¡°http[:]//34.87.19.73/pqis/11a.exe¡±ÉϵÄPayloadÏÂÔص½ÍâµØ£¬²¢ÉúÑÄΪ¡°%AppData%Roaming\powerpoint.exe¡±£¬×îºóÔËÐиóÌÐò¡£
ͼ13 ÁªÍøÏÂÔØPayload
2.3 Payload
ÃûΪ11a.exeµÄPayloadÊÇʹÓÃMS Visual BasicÓïÑÔ±àдµÄ¡£µ±¶ñÒâ³ÌÐòÔËÐÐʱ£¬»áÔÚϽµµÍÙʱĿ¼ÏÂÏȽ¨Éè¡°subfolder¡±×ÓĿ¼²¢ÌìÉúÁ½¸öÎļþ£¨explorer.exeºÍexplorer.vbs£©£¬½Ó×ÅÔËÐÐexplorer.vbs¾ç±¾²¢¿¢ÊÂ×ÔÉíÀú³Ì¡£explorer.vbs¾ç±¾µÄÏêϸÄÚÈÝÈçÏÂͼ£º
ͼ14 explorer.vbs¾ç±¾ÄÚÈÝ
´Óͼ14µÄVBSÎļþÄÚÈÝ¿ÉÒÔ¿´³ö£¬¾ç±¾ÖÐʹÓÃÁËwscript shellÏÂÁî×öÁËÁ½¼þÊ¡£Ê×ÏȽ«×ÔÉíÌí¼Óµ½×¢²á±í¿ª»ú×ÔÆô¶¯ÏîÖУ¬ÒÔ±ãÿ´ÎÔÚϵͳÆô¶¯Ê±¶¼ÄÜ×Ô¶¯ÔËÐÐexplorer.vbsÎļþ£¬ÓÃÒÔʵÏÖÆ䳤ÆÚÐÔ£»Æä´Î£¬ÔËÐпÉÖ´ÐÐÎļþexplorer.exe¡£
ͼ15 Ìí¼Ó×¢²á±íÏî
2.4 Agent Tesla
̫ͨ¹ýÎö£¬¿ÉÒÔÈ·¶¨explorer.exe³ÌÐòÊÇÎÛÃûÕÑÖøµÄÌع¤Èí¼þ¡°Agent Tesla¡±¡£¸ÃľÂíÔËÐкó»áÁ¬Ã¦ÖØн¨ÉèÒ»¸ö¹ÒÆðµÄ×ÔÉí×ÓÀú³Ì¡£×ÓÀú³ÌµÄÏà¹ØÊôÐÔÈçÏÂͼ£º
ͼ16 ×ÓÀú³ÌÊôÐÔÐÅÏ¢
È»ºó×ÓÀú³Ì»á´Ó×ÊÔ´Êý¾ÝÖнâÃܳöÁíÒ»¸öÓÉ.NET±àдµÄPEÎļþ£¬Æ佫»áÔÚÄÚ´æÖÐÖ±½ÓÔËÐС£ÏÂͼÊÇÔÚÆÊÎö¹¤¾ßÖÐÏÔʾµÄ¸Ã.NET³ÌÐòµÄÖ÷Òª¹¦Ð§£º
ͼ17 Ö÷Òª¹¦Ð§´úÂ벿·Ö½Øͼ
¸Ã³ÌÐò»áʵÑé»á¼û¡°checkup[.]amazonaws.com¡±£¬ÒÔ´ËÀ´»ñÈ¡ÍâµØ»úеµÄÍâÍøIPµØµã¡£
ͼ18 »ñÈ¡ÍâµØIPµØµã
´Óͼ17µÄÄÚÈÝ¿ÉÒÔ¿´µ½£¬³ÌÐò´úÂëʹÓÃÁË»ìÏýÊÖÒÕÀ´ÔöÌíÆÊÎöÄѶȡ£±ðµÄ£¬Æ仹»á¶ÔVM¡¢É³Ïä¡¢µ÷ÊÔÆ÷ºÍÆäËû¼à¿Ø¹¤¾ßµÈ×öһϵÁеļì²â¡£ÈçÔËÐÐÇéÐÎÇå¾²£¬.NET³ÌÐòÔò×îÏȼàÊÓ²¢ÍøÂçÊܺ¦ÕßµÄÐÅÏ¢£¬²¢Ê¹ÓÃSMTPÐÒ齫¼à¿ØÈÕÖ¾·¢Ë͸øÔ¶³Ì·þÎñÆ÷¡°smtp[.]diagnosticsystem.in¡±¡£
Agent Tesla¼Ò×å
»ùÓÚÒÑÖªµÄÏà¹Ø×ÊÁÏ£¬´Ó2014ÄêÆðÆù½ñΪֹ£¬Agent TeslaÒÑ´æ»î³¤´ï5ÄêÖ®¾Ã¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬¸ÃľÂíÔÚ½ÐøÒ»Ö±µÄµü´ú¸üУ¬×îа汾ÏÖÔÚ¿Éƾ֤ÐèÇóÔÚ»¥ÁªÍøÉÏËæÒ⹺Öá£
Agent Tesla¿Éʵʱ¼à¿ØºÍ¼ÍÈÎÃü»§µÄ¼üÅÌÊäÈë¡¢ÇÔÈ¡¼ôÇаåÊý¾Ý¡¢ÆÁÄ»½Øͼ¡¢»ñÈ¡Ö÷»úÐÅÏ¢£¬ÒÔ¼°ÍøÂç¸÷´óä¯ÀÀÆ÷ºÍÓÊÏäµÄÓû§Æ¾Ö¤²¢»Ø´«ÖÁºÚ¿Í·þÎñÆ÷¡£Ò²ÕýÓÉÓÚÆ书ЧºÜÊÇÇ¿Ê¢£¬ÒÔÊǽü¼¸ÄêÒÔÀ´¾³£±»ºÚ¿Í×éÖ¯ËùʹÓá£
ÏÂͼÊÇ´ÓÆäÍøÕ¾ÉÏժȡÏÂÀ´µÄ²¿·Ö¹¦Ð§ÏÈÈÝ£º
ͼ19 Agent TeslaXÏà¹Ø¹¦Ð§
×èÖ¹µ½ÏÖÔÚ£¬¼øÓÚÎÒÃÇÆÊÎöµÄÕâ¿îбäÖֺ;ɰæµÄľÂíÔÚ¹¦Ð§ºÍÊÖÒÕÉÏÀàËÆ£¬²¢Ã»Óз¢Ã÷Ì«¶àµÄת±äµã¡£ÒÔÊDZ¾ÎÄÔÚÕâÀï²»ÔÙ¹ý¶àµÄÏêϸÐÎòÆäÏêϸµÄÊÖÒÕϸ½Ú£¬ÈôÓÐÐèÒª¸÷ÈË¿ÉÉó²éÎÄÄ©µÄ²Î¿¼ÎÄÏס£
3¡¢ËÝÔ´Óë¹ØÁªÆÊÎö
3.1 ¶ñÒâÓòÃûÆÊÎö
ÎÒÃÇÊ×ÏÈ´Ó¶ñÒâÎĵµ´¥·¢Îó²îºóÖ´ÐеÄshellcodeÖÐÌáÈ¡³öÒ»¸öÓ²±àÂëµÄÁ´½ÓµØµã£º¡°http[:]//34.87.19.73/¡±¡£¾Êºǫ́´óÊý¾ÝµÄÑù±¾¹ØÁªÆÊÎöºó£¬´Ó¸ÃÍйܵÄÍⲿÖ÷»úÉÏÍÚ¾ò³ö¸ÃºÚ¿Í×éÖ¯×Ô2019Äê9ÔÂÆðʹÓõÄÖî¶àÀàÐ͵ÄÌع¤Ä¾Âí¡£
ͼ20 ÍйÜÖ÷»úÉϵÄľÂíÐÅϢͳ¼Æ
½Ó×Å£¬ÌáÈ¡¸ÃÅúľÂíÑù±¾Ê¹ÓõÄC2ÓòÃû½øÒ»²½µÄ¹ØÁª³ö²¿·Ö¿ÉÒɵÄCCµØµã¡£ÀýÈ磬²¿·ÖľÂí»á½«SMTPÁ÷Á¿·¢Ë͵½smtp[.]diagnosticsystem.in£¬¶ø¸ÃÓòÃûÆÊÎöµÄIPµØµãΪ208[.]91[.]199[.]143¡£
DNSÅÌÎÊ´ËÓòÃû£¬·¢Ã÷Æä×¢²áʱ¼äΪ2019Äê9ÔÂ19ÈÕ£¬ÕâÓë¸ÃÅúľÂíµÄÈö²¥Æðʼʱ¼äÕýºÃÎǺϡ£ÓòÃûÅÌÎÊÐÅÏ¢ÈçÏÂͼ£º
ͼ21 ÓòÃûµÄ×¢²áʱ¼ä
ÔٴζÔÏßË÷×öÀ©Õ¹ºÍ¶Ô¸ÃÓòÃû¾ÙÐÐÉîÈëµÄ×·×ÙÆÊÎöºó£¬ÎÒÃÇ»ñµÃÁ˸ü¶àµÄ¶ñÒâÑù±¾£¬ÒÔ¼°ÕâЩÓòÃûÔøÆÊÎöµ½µÄÖ÷»úIPµØµã¡£
ͼ22 ÓòÃûÆÊÎöµÄIPµØµã
ÎÒÃÇ´Ó»ñÈ¡µÄ´ó×Ú¶ñÒâÑù±¾ÖÐÕûÀí³ö½üÆÚ½ÏÁ¿»îÔ¾µÄ£¬Í¨¹ýÊÖ¶¯ÆÊÎöÈ·¶¨Á˴˴ι¥»÷Ô˶¯ÖÐʹÓõĴó×ÚC2ÓòÃû¡£¾ÓÉÅÌÎÊÆÊÎöºó·¢Ã÷£¬ÕâЩÓòÃû¾ùÊÇÒÔÉÏIPµØµã¡°208.91.199.**¡±ºÍ¡°208.91.198.143¡±µÄCNAME¡°us2.smtp.mailhostbox.com¡±µÄÓÖÃû¡£
ͼ23 ÓòÃûÅÌÎÊÐÅÏ¢
ͼÖÐö¾ÙÁ˲¿·Ö»îÔ¾Ñù±¾ºÍÆä»á¼ûµÄÓòÃû£¬Ïêϸ¶ÔÓ¦¹ØϵÈçÏÂËùʾ£º
ͼ24 ¶ñÒâÑù±¾ÓëC&C·þÎñÆ÷µÄ¹Øϵͼ
3.2 ¹ØÁªÓʼþ
ƾ֤ͬԴÆÊÎö£¬ÎÒÃÇ·¢Ã÷ÁËÁíÍâÒ»·âÕë¶ÔÎ÷°àÑÀµØÇøµÄ´¹ÂÚÓʼþ¡£¸ÃÓʼþµÄ·¢¼þµØµãÊÇÎ÷°àÑÀÒ»¼ÒÃûΪ¡°MAJ AGROQUIMICOS¡±µÄÅ©Ò©ÐÐÒµ¹«Ë¾¡£
ͼ25 MAJ AGROQUIMICOS¹«Ë¾Ê×Ò³
ÓʼþÄÚÈÝʹÓõÄÊÇÎ÷°àÑÀÓ´óÖÂÒâ˼ÊǸ¶¿îÈ·ÈÏÊ飬´¹ÂÚÓʼþµÄ¸½¼þÊÇÒ»¸öαװ³É.imgÃûÌõÄISOÎļþ¡£ËäÈ»ÎļþÃû³ÆÓëÓʼþµÄÄÚÈÝÓÐËù²î±ð£¬¿ÉÊÇ´Ó·¢¼þµØµãÀ´¿´£¬ÆäȪԴҲÓпÉÄÜ»áÊǹ¥»÷Ä¿µÄµÄÏàÖúÉÌ»ò¹©Ó¦ÉÌÖ®À࣬ÕâÑù±ã¿ÉÔöÌíÓʼþµÄÕæʵÐÔ£¬Í¬ÑùÓÐʱ»úÓÕʹÊܺ¦ÕßÏÂÔظ½¼þ¡£ÓʼþÏêϸÄÚÈÝÈçÏÂͼËùʾ£º
ͼ26 Î÷°àÑÀÓïµÄ´¹ÂÚÓʼþ
ͼ27 Óʼþ·ÒëºóµÄÄÚÈÝ
3.3 ISOÎļþ
ISOÓ³ÏñÊÇÒ»ÖÖ¹âÅ̵Ĵ浵Îļþ£¬ÆäÖаüÀ¨½«ÒªÐ´Èë¹âÅ̵ÄËùÓÐÐÅÏ¢¡£Í¨³£ÓÃÓÚ½¨ÉèCD»òDVDµÄ±¸·Ý¡£ÓÉÓÚISOÎļþµÄ³ß´çÏà¶Ô½ÏÁ¿´ó£¬ÒÔÊÇÓпÉÄܵ¼ÖÂÐí¶àµç×ÓÓʼþÍø¹ØɨÃè³ÌÐòÎÞ·¨×¼È·Ê¶±ð´ËÀàÐ͵ĸ½¼þ¡£²¢ÇÒ×ÔWin 8¼°ÒÔÉϵĸü¸ß°æ±¾ºó£¬Windows¶¼×Ô´øISOÔËÐй¤¾ß£¬Óû§¾ÍÏñ·¿ªEXEÎļþÒ»Ñù£¬Ö±½ÓË«»÷ISOÎļþ¼´¿ÉÔËÐС£Òò´ËÕâ´Î¹¥»÷ÖкڿÍʹÓÃÁËISOÎļþ×÷Ϊ¶ñÒ⸽¼þ¡£
3.4 ¶ñÒ⸽¼þ
ǶÈëÔÚIOS¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþÈçÏÂͼËùʾ£º
ͼ28 ǶÈëµÄ¿ÉÖ´ÐÐÎļþ
ǶÈëµÄ¿ÉÖ´ÐÐÎļþ
ʹÓÃÆÊÎö¹¤¾ß¿ÉÒÔ¿´µ½£¬Õâ¸öÃûΪ¡°SOA300329042943243_pdf.exe¡±µÄ¿ÉÖ´ÐÐÎļþÏÖʵÉÏÊÇÒ»¸öAutoItÚ¹ÊÍÆ÷£¬²¢Ç¶ÈëÁËAutoIt±àÒë¾ç±¾×÷Ϊ×ÊÔ´¡£
ͼ29 ¿ÉÖ´ÐÐÎļþµÄ×ÊÔ´ÐÅÏ¢
¸Ã¿ÉÖ´ÐÐÎļþÔËÐк󣬻áÔÚ%User\Public%Ŀ¼ÏÂÊͷŶñÒâµÄVBS¾ç±¾Îļþ²¢½«¸ÃĿ¼Ìí¼Óµ½×¢²á±íµÄRunÆô¶¯ÏîÖУ¬ÒÔʵÏÖÆ䳤ÆÚÐÔ¡£½Ó×ÅÔÙ½«ÄÚ´æÖнâÃܳöµÄµÄPEÎļþ×¢È뵽ϵͳÎļþ¡°Regasm.exe¡±ÖС£
ͼ30 ÔÚ×¢²á±íÖÐÌí¼Ó×ÔÆô¶¯Ïî
ÐÂPEÎļþ
̫ͨ¹ýÎöÄÚ´æÖнâÃܳöµÄÐÂPEÎļþ£¬ÎÒÃÇÈ·¶¨¸ÃEXEÊÇÁíÒ»°æʹÓÃ.NET¿ò¼Ü±àдµÄAgent TeslaľÂí¡£ÔÚľÂí³ÌÐòÀÖ³É×¢Èëµ½Regasm.exeÀú³Ì²¢ÔËÐк󣬱ã×îÏÈʵÑéÓëÔ¶³Ì·þÎñÆ÷¾ÙÐÐÅþÁ¬¡£
ÎÒÃÇÔÚ¶ñÒâ´úÂëÆÊÎöÀú³ÌÖз¢Ã÷Á˺ڿÍC&C·þÎñÆ÷ÉϵÄÏà¹ØÐÅÏ¢£¬C&CÎļþĿ¼ÈçÏÂͼ£º
ͼ31 ·þÎñÆ÷ÉϵÄÎļþĿ¼
ͨ¹ý½øÒ»²½µÄÆÊÎö£¬ÎÒÃÇ·¢Ã÷C&C·þÎñÆ÷ÉÏÉúÑÄ×Å´ó×ڵĴÓÊܺ¦Õß»úе»Ø´«µÄ¼à¿ØÈÕÖ¾£¬Æ¾Ö¤ÆäÖü´æµÄÎļþÃû³ÆÃûÌúÍÄÚÈݵÈÌØÕ÷£¬ÔÙ´ÎÈ·¶¨¸ÃľÂíÊÇ¡°Agent Tesla¡±¼Ò×å¡£
ÒÔºó£¬ÎÒÃÇ»¹×·×Ùµ½Á˸úڿÍ×éÖ¯ËùÍøÂçµÄÊܺ¦ÕßÐÅÏ¢£¬ÕâЩÐÅÏ¢ÒÔhtmlºÍjpegÎļþµÄÐÎʽ´æ´¢ÔÚC&C·þÎñÆ÷ÉÏ£¬ÆäÖÐhtml´æ´¢µÄÊDZ¾»úÐÅÏ¢¡¢¼üÅ̼ͼ¡¢Õ˺ÅÃÜÂëµÈÐÅÏ¢£¬jpeg´æ´¢µÄÊǽØÆÁÐÅÏ¢¡£ÏÂͼÊǽØÈ¡Á˲¿·Ö¼à¿ØÈÕÖ¾£º
ͼ32 »Ø´«µ½·þÎñÆ÷µÄ¼à¿ØÈÕÖ¾
´ÓÕâЩÎļþÃûÖеģº¡°Keystrokes¡±£¨¼üÅ̼ͼ£©¡¢¡°Screen¡±£¨ÆÁÄ»½Ø£©¡¢¡°Recovered¡±£¨ÃÜÂë»Ö¸´£©µÈÒªº¦×Ö¿ÉÒÔ¿´³ö£¬Ä¾ÂíÊÇƾ֤ºÚ¿ÍµÄ¿ØÖÆÖ¸ÁîÀ´ÇÔÈ¡Êܺ¦ÕßµÄÏà¹ØÐÅÏ¢£¬ÇÒƾ֤¡°¹¦Ð§-Óû§Ãû-ÅÌËã»úÃû-ʱ¼ä£¨Äê-ÔÂ-ÈÕ-ʱ-·Ö-Ã룩¡±µÄ½á¹¹ÃüÃû²¢ÉúÑÄΪHTMLÃûÌõÄÎļþ¡£
ÎÒÃǽ«Ò»¸öÒÔ¡°Recovery¡±¿ªÍ·µÄhtmlÎļþʹÓÃIEä¯ÀÀÆ÷·¿ª£¬Äܹ»¿´µ½Ä¾ÂíÏêϸÍøÂçÁËÄÄЩÐÅÏ¢¡£ÆäÖаüÀ¨Êܺ¦ÕßµÄÅÌËã»úÓû§Ãû¡¢Ö÷»úÐÅÏ¢¡¢ÏµÍ³Ãû³Æ¡¢CPUÐÅÏ¢¡¢ÄÚ´æÐÅÏ¢¡¢IPµØµãÒÔ¼°Chromeä¯ÀÀÆ÷ƾ֤ÐÅÏ¢µÈ¡£
ͼ33 HTMLÎļþµÄÄÚÈÝÏêÇé
3.5 »ù´¡ÉèÊ©ÆÊÎö
ͨ¹ýÍøÂçÓë¸ÃC&C·þÎñÆ÷Ïà¹ØµÄ»Ø´«ÐÅÏ¢¾ÙÐÐÕûÀíÆÊÎöºó£¬ÎÒÃÇ·¢Ã÷Á˼¸¸öÒªº¦ÐÅÏ¢¡£ÍŽáÇ°ÎÄÖÐËѼ¯µ½µÄÏßË÷£¬ÎÒÃǽøÒ»²½¼òÖ±ÈÏÁ˸÷þÎñÆ÷ÊDZ»ºÚ¿Í×éÖ¯¹¥Ïݺó£¬×¨ÃÅÓÃ×÷ÎüÊÕľÂí»Ø´«Êܺ¦ÕßÐÅÏ¢µÄ·þÎñÆ÷¡£¶ø¸Ã×éÖ¯ÔçÔÚ7Ô·ݵÄʱ¼ä¾ÍÒÑ×îÏÈʵÑé¹¥»÷Ô˶¯£¬²¢ÇÒÊܺ¦Õß´ó¶¼ÊÇÀ´×ÔÓÚÎ÷°àÑÀµØÇøµÄÆóÊÂÒµµ¥Î»ÊÂÇéÖ°Ô±¡£ºÚ¿Í×éÖ¯¹ßÓÚʹÓÃAgent Tesla»òHawkeye Keylogger¡¢Nanocore RATºÍNetWire RATµÈÌع¤Ä¾ÂíÀ´ÇÔÈ¡Ä¿µÄÖ°Ô±µÄµÇ¼ƾ֤µÈÐÅÏ¢£¬ÇҴ˴ι¥»÷Ô˶¯ÊÇÓÉÀ´×ÔÓÚÄáÈÕÀûÑǵĺڿÍ×éÖ¯²ß»®ÓëʵÑé¡£
3.5.1 Êܹ¥»÷·þÎñÆ÷ÆÊÎö
ÎÒÃÇ×¢Öص½£¬W-EAGLEĿ¼ÏÂÉúÑÄ×ÅÒ»¸öÃûΪ¡°W-EAGLE PMS Deck.zip¡±µÄѹËõ°ü¡£½âѹ²¢·¿ªÄ³DOCÎĵµ£¬·¢Ã÷ÕâÊÇÒ»¸ö´ø׏«Ë¾logoµÄÎ÷°àÑÀÓïÎļþ£¬ÎÊÌâÔڹȸè·ÒëΪ¡°¼×°åÍýÏëµÄά»¤/¼ì²éÊֲᡱ¡£
ͼ34 W-EAGLEĿ¼ÏµÄÎļþÄÚÈÝ
ƾ֤¹«Ë¾Ãû³ÆËÑË÷ºó֤ʵ£¬ÕâÊÇÎ÷°àÑÀÒ»¼Ò´óÐÍ´¬²°ÖÎÀí¹«Ë¾£¬Ö÷Òª´ÓʸÉÉ¢»õ´¬µÄÔËÓª¡£
ͼ35 W MARINE INC¹«Ë¾Ö÷Ò³ÐÅÏ¢
Èçͼ35Ëùʾ£¬¸Ã¹«Ë¾µÄÍøַͬºÚ¿ÍËùʹÓõķþÎñÆ÷Ãû³ÆÏàͬ£¬ÓÉ´Ë֤ʵ´Ë·þÎñÆ÷ÏÖʵÊÇÊôÓڴ˹«Ë¾¡£²¢ÇÒƾ֤·þÎñÆ÷ÉÏÉúÑĵÄÓë¸Ã¹«Ë¾ÓйصÄÎĵµ½¨Éèʱ¼äÊÇ2016Äê10ÔÂÖÐÏÂÑ®×óÓÒ£¬ÎÒÃÇÍƲâ´Ë·þÎñÆ÷Òòºã¾Ã±»ÏÐÖöøÎÞÈËά»¤£¬ÖÂʹ±»ºÚ¿Í×éÖ¯¼ÓÒÔʹÓá£
3.5.2 ¼à¿ØÈÕÖ¾ÐÅÏ¢
ÎÒÃǽ«ÊýÄ¿½ü2ÍòµÄ¼à¿ØÈÕÖ¾¾ÙÐÐÕûÀíÆÊÎö£¬Êý¾ÝÏÔʾºÚ¿Í×éÖ¯ÏÖʵÉÏ´Ó2019Äê7Ô±ãÒÑ×îÏÈ´¦ÓÚ»îԾ״̬£¬Êܺ¦ÕßµÄÖ÷»úÐÅÏ¢ÒÔ¼°Ð¡ÎÒ˽¼ÒµÇ¼ƾ֤һÁ¬µÄ±»»Ø´«µ½´Ë·þÎñÆ÷ÉÏ¡£×èÖ¹ÏÖÔÚΪֹ£¬KeystrokesÎļþµÄÕ¼±ÈÂÊÏà¶Ô½ÏÁ¿´ó£¬Æä´ÎÊÇScreenÎļþ£¬RecovereyÎļþÏà¶Ô½ÏÉÙ¡£²»µ«ÔÆÔÆ£¬ÎÒÃǼà²âµ½´ËÀàÎļþÔÚ·þÎñÆ÷ÉÏÈÔÈ»²»ÖÐÖ¹µÄÐÂÔö¡£
ÎļþÀàÐÍ |
½¨Éèʱ¼ä |
ÎļþÊýÄ¿ |
Keystrokes |
2019Äê7ÔÂ16ÈÕ |
8383 |
Screen |
2019Äê8ÔÂ10ÈÕ |
5447 |
Recovery |
2019Äê7ÔÂ16ÈÕ |
3859 |
±í1 ·þÎñÆ÷ÉϵÄÈÕ־ͳ¼Æ
3.5.3 Êܺ¦ÕßµØÇøºÍÐÐÒµÂþÑÜ
Êܺ¦ÕßIPµØµãÖ÷ÒªÂþÑÜÔÚÎ÷°àÑÀ¡¢Ó¡¶È£¬ÒÔ¼°ÉÙÁ¿À´×Ô°¢ÁªÇõºÍÄ«Î÷¸çµØÇø£¬Æä»òÐíÕ¼±ÈÂÊÈçÏÂͼ£º
ͼ36 Êܺ¦ÕßµØÇøÂþÑÜͼ
»ùÓÚÎÒÃǶԺڿÍ×éÖ¯µÄ¹¥»÷ÐÅϢͳ¼ÆÏÔʾ£¬´Ë´Î¹¥»÷Ô˶¯Éæ¼°µ½Î÷°àÑÀµØÇøµÄÊÐÕþ¸®¡¢Å©Òµ»úеÐÐÒµ¡¢Ë®Àû¹¤³ÌÐÐÒµºÍ¶ÔÍâÉÌÒµÐÐÒµ£¬ÒÔ¼°Ó¡¶ÈºÍ°¢ÁªÇõµÈÆäËûÐÐÒµ¡£Ï±íչʾÁ˲¿·ÖµÄÏà¹Øͳ¼ÆÐÅÏ¢£º
¹«Ë¾Ãû³Æ |
¹«Ë¾ÐÅÏ¢ |
FEMAC |
λÓÚÎ÷°àÑÀµÄÒ»¼ÒÅ©Òµ»úе¹«Ë¾ |
XUNTA DE GALICIA |
Î÷°àÑÀ¼ÓÀûÎ÷ÑǵØÇøµÄ·Ñ˹ÌØÀÊÐÕþÌü |
ICINCO |
λÓÚÎ÷°àÑÀ¼ÓÄÉÀûȺµºµÄÐÞ½¨Ë®Àû¹¤³Ì¹«Ë¾ |
GALACANARIA |
λÓÚÎ÷°àÑÀ´ó¼ÓÄÉÀûȺµºµÄÒ»¼ÒʳÎÒûÁϺÍÑ̲ÝÅú·¢ÉÌÒµ¹«Ë¾ |
AIRSAT |
Î÷°àÑÀÒ»¼Ò»¥ÁªÍø¹©Ó¦ÉÌ |
Al Serh Al Kabeer |
λÓÚ°¢ÁªÇõµÄÒ»¼ÒÐÞ½¨¹«Ë¾ |
AFS Logistics International Pvt.Ltd |
λÓÚÓ¡¶ÈµÄÒ»¼Ò¹ú¼ÊÎïÁ÷»õÔËÊðÀí¹«Ë¾ |
Vanity Case |
λÓÚÓ¡¶ÈµÄÒ»¼Ò×ÔÈ»»¤·ô²úÆ··ÖÏúÉÌ |
sanbe-farma |
Ó¡¶ÈÄáÎ÷ÑÇÍâµØÁìÏȵÄÖÆÒ©¹«Ë¾ |
±í2 ±»¹¥»÷µÄ²¿·Ö¹«Ë¾ÐÅÏ¢
3.5.4 ºÚ¿ÍµÄ¹éÊôλÖÃ
±ðµÄ£¬ÎÒÃÇ»¹×¢Öص½Ò»Ð©HawkEye KeyloggerÈÕÖ¾ËƺõÊǴӺڿ͵ĵçÄÔÖÐÉÏ´«µÄ£¬ÎļþÃûÖеÄHawkEye KeyloggerºÍ±àºÅRebornv9£¨¸ÃľÂíµÄ×îа汾ºÅ£©£¬ÒÔ¼°Òªº¦×Ö¡°PasswordsLogs¡±ºÍ¡°TestLogs¡±µÈ£¬ÒÉËÆÊǺڿ͵IJâÊÔÈÕÖ¾¡£
ͼ37 ²âÊÔÈÕÖ¾½Øͼ
ÈÕÖ¾Îı¾ÀïÏêϸÁгöÁ˺ڿÍ×éÖ¯¼¸¸öÓÃÓÚ²âÊÔµÄÓÊÏäµÇ¼ƾ֤£¬²¿·ÖÐÅÏ¢ÈçÏ¡£
ʾÀý1£º
ͼ38 ÈÕÖ¾ÐÅÏ¢½Øͼ1
ͼ39 MovistarÓÊÏäµÇ¼½çÃæ
ʾÀý2£º
ͼ 40 ÈÕÖ¾ÐÅÏ¢½Øͼ2
ͼ41 Suite Correo Profesional ÓÊÏäµÇ¼½çÃæ
ÎÒÃÇÌáÈ¡³öÁ˸ÃÈÕÖ¾µÄIPµØµã¡°197.210.226.51¡±¡£ÅÌÎʺóµÃ³ö¸ÃµØµãλÓÚÄáÈÕÀûÑǵØÇø£º
ͼ42 IPµØµãÅÌÎʺóµÄÏà¹ØÐÅÏ¢
±ðµÄ£¬ÔÚÁíÍâµÄKeystrokesÈÕÖ¾ÖÐÔٴη¢Ã÷µÄIPµØµã¡°41.203.73.185¡±ÓëÇ°ÎÄÖÐÎÒÃǼͼµÄIPµØµãÏàͬ£¬ÆäÒ²ÊÇÖ¸ÏòÄáÈÕÀûÑǵØÇø¡£ÏêϸÐÅÏ¢ÈçÏÂͼ£º
ͼ43 KeystrokesÈÕÖ¾ÖеÄÐÅÏ¢
È»ºó£¬ÎÒÃÇ´ÓͬԴµÄRecoveryÈÕÖ¾ÖÐÕÒµ½Á˺ڿͲ»Ð¡ÐÄ鶵ÄÍâÑóANY.RUN£¨ÔÚÏ߶ñÒâÈí¼þɳÏ䣩ƽ̨µÄÕ˺źÍÃÜÂë¡£
ͼ44 RecoveryÈÕÖ¾ÖеÄÐÅÏ¢
ÀֳɵǼºóÉó²éɨÃèÀúÊ·£¬ÎÒÃÇ¿ÉÒÔ¿´µ½ºÚ¿Í×éÖ¯ÔÚ7Ô·ݵÄʱ¼ä±ã×îÏȽ«Ä¾ÂíÉÏ´«¾ÙÐвéɱ¼ì²â¡£Í¬Ê±Æ¾Ö¤É³ÏäɨÃèЧ¹ûÏÔʾ£¬ÔÙ´ÎÈ·ÈϸÃÅúľÂíÊôÓÚAgent TeslaºÍHawkEye Keylogger¼Ò×å¡£
ͼ45 ANY.RUNÉÏ´«ÀúÊ·¼Í¼
4¡¢×Ü ½á
ºã¾ÃÒÔÀ´£¬ ÓÃÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢µÄÌع¤Ä¾ÂíÒ»Ö±ÔÚÒ»Ö±µÄ¸üл»´ú¡£Ëæ×Å»ÒÉ«Êг¡µÄÐËÆ𣬼üÅ̼ͼ³ÌÐò¡¢ÇÔÃܳÌÐòºÍÔ¶¿Ø³ÌÐòÕýÔÚÖð½¥µØÇ÷ÏòÓÚÉÌÒµ»¯£¬ÒÔÖÁÓÚ¹¥»÷ÕßÔÚ´Ë·½ÃæÎÞÐëͶÈëÌ«¶àµÄʱ¼äºÍ¾«Éñ£¬¶ø½«¹Ø×¢µã·ÅÔÚÆä¹¥»÷ÊֶκÍÉç»á¹¤³ÌѧµÄÄÜÁ¦ÉÏ¡£
ͨ¹ý¶Ô·þÎñÆ÷ÉÏÒ»Á¬¸üеĻش«Îļþ¼à²â£¬ÎÒÃÇ¿ÉÒÔ¿´³ö¸ÃºÚ¿Í×éÖ¯µÄ¹¥»÷Ô˶¯ÕýÔÚÒ»Á¬¾ÙÐУ¬Êܺ¦ÕßµÄÈËÊýÈÔÈ»³ÊÉÏÉýÇ÷ÊÆ¡£±ðµÄ£¬Í¨¹ý¶Ô¹¥»÷Ô˶¯µÄËÝÔ´ºÍºǫ́Êý¾Ýͳ¼Æ£¬ÎÒÃÇÍƲâºóÐøµÄ¹¥»÷Ä¿µÄÖصãÆ«ÏòÓÚÎ÷°àÑÀºÍÓ¡¶ÈµÈµØÇø¡£
ÔÚ´ËÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÌáÐѸ÷ÆóÒµµ¥Î»¼°Ð¡ÎÒ˽¼ÒÓû§Ìá¸ßСÐÄ£¬²»´ÓȪԴ²»Ã÷µÄÍøÕ¾ÏÂÔØÈí¼þ£¬²»ÒªÈÝÒ×µã»÷ȪԴ²»Ã÷µÄÓʼþ¸½¼þ£¬²»ÒªËæÒâÆôÓú꣬ʵʱÏÂÔز¹¶¡ÐÞ¸´¡£
IOC£º
SHA-256
DE01B6A27D4EBA814FE3CE5084CFC23FDEEB47D50F8BEC5A973578E66B768A48
D5F2418628B818FCFFDD7F3A31F9A137761FA307D1C05C9B783E9040E008DE90
CA56DAD3CABD5AD85411B88C5E094055BEAA96DF6F9B37B9E9FD03AFF823CBAF
4DE32AD800A7847510925D34142B16AE6D7C3C0E44E33EC54466F527FCC93F41
F183992B4BC36F3B33F967EAB83B53A2448260ADA4A92A4B86F32284285EEFED
D6F5AAD82A21C384171BC8FE1BFBC47867151CCE9E8FA54FA21903191A63FD9E
BB3A12EDEFB5A96D6BDBFDC86ED125757ABC3C479EDAF485444A05F4A1D9F9B6
0514990857770F5AF20C96B97D7B63DC8248593D223A672D60C5C6479910C84B
1DD9B3CBB1AAC20E3A3954A1CFBE1BC8CB746C1BF446512A0AB6795546A9774F
C2ÓòÃû
smtp[.]diagnosticsystem[.]in
kartelicemoneyy[.]duckdns[.]org
virtualhost19791[.]duckdns[.]org
²Î¿¼Á´½Ó£º
https://www.fortinet.com/blog/threat-research/in-depth-analysis-of-net-malware-javaupdtr.html