ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab | SWEEDºÚ¿Í×éÖ¯¹¥»÷Ô˶¯ÆÊÎö±¨¸æ
Ðû²¼Ê±¼ä 2020-07-03Ò»¡¢¸ÅÊö
½üÆÚ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab½ÓÁ¬²¶»ñµ½´ó×ÚÕë¶ÔÈ«ÇòÖÆÔì¡¢ÔËÊä¡¢ÄÜÔ´µÈÐÐÒµ¼°²¿·ÖÒ½ÁÆ»ú¹¹ÌᳫµÄÓã²æʽ´¹ÂÚÓʼþ¶¨Ïò¹¥»÷¡£´ÓÓʼþµÄÆÊÎöЧ¹ûÀ´¿´£¬Êܺ¦Õß´ó¶à±é²¼ÓÚÃÀ¹ú¡¢¼ÓÄô󡢵¹ú¡¢Öйú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Î÷°àÑÀµÈ¹ú¼ÒºÍµØÇø¡£¹¥»÷ÕßÒÔ¡°×°´¬Í¨Öªµ¥¡±¡¢¡°×°Ïä½»»õ¼Ûµ¥¡±¡¢¡°½ôÆÈÔËÊäÎļþ¡±µÈÖ÷ÌâÓʼþ×÷ΪÓÕ¶üÏò¹¥»÷Ä¿µÄÖ²ÈëÐÅÏ¢ÇÔÃÜľÂí£¨Agent Tesla¡¢Formbook¡¢Lokibot£©ºÍÔ¶³Ì¿ØÖƳÌÐò£¨NanoCore¡¢Remcos£©¡£ÎÒÃÇͨ¹ý¶ÔÍøÂçµ½µÄ¹¥»÷¹¤¾ß¾ÙÐÐÈ¥Öز¢×öÆÊÎö£¬×îÖÕ·¢Ã÷´Ë´Î¹¥»÷Ô˶¯¹ØÁª×Å1362¸ö¹¥»÷Ñù±¾¡£Í¨¹ýͬԴÆÊÎö£¬ÎÒÃÇ·¢Ã÷ÕâÅúÑù±¾ÖÐÓнü80%ÊÇͳһ¿î¶ñÒâÈí¼þ£¬¶ÔÆäÆÊÎöÅжϺóÈ·¶¨ÕâÕýÊǽüÆÚ±»´ó¹æÄ£Èö²¥ÇÒ¼«Îª»îÔ¾µÄÐÂÐÍÏÂÔØÕß²¡¶¾Guloader¡£GuloaderÊÇÒ»¿îÃâɱÄÜÁ¦ºÜÇ¿µÄ²¡¶¾£¬½üÆÚÈ«Çò¸÷´ó³§É̾ù¶ÔÆä¾ÙÐÐÁËÔ¤¾¯£¬Æä¾ß±¸É³ºÐÌÓÒÝ¡¢´úÂë»ìÏý¡¢·´µ÷ÊÔ¡¢C&C/URL¼ÓÃܺÍÓÐÓÃÔغɼÓÃܵȶàÖÖÄÜÁ¦¡£ÓÉÓÚGuloader¾ßÓнÏÇ¿µÄÃâɱÄÜÁ¦ºÍ¶Ô¿¹»úÖÆ£¬Òò¶øÊܵ½´ó×ںڿ͵ÄÇàíù¡£±¾Åú¹¥»÷ÖУ¬¹¥»÷Õß¾ÍÆÕ±éµØʹÓÃGuloaderÏÂÔØÕß²¡¶¾ÍŽáÔÆ·þÎñÀ´·Ö·¢ÇÔÃܹ¤¾ß»òÔ¶³Ì¿ØÖƳÌÐò£¨RAT£©¡£
ÎÒÃÇͨ¹ýËÝÔ´ÆÊÎöÈ·¶¨´Ë´Î¹¥»÷Ô˶¯À´×ÔÄáÈÕÀûÑÇ£¬²¢ÇÒ¹ØÁª³öÁË´óÅúÁ¿µÄºÚ¶ñÒâÓòÃû£¨¹¥»÷ÕßʹÓþ³ÍâµÄDuck DNS×¢²á¶¯Ì¬ÓòÃû£©ºÍIPµØµã¡£Í¨¹ý¶Ô¹¥»÷ÕßʹÓõÄÍøÂç»ù´¡ÉèÊ©£¬×·×ÙÆÊÎö·¢Ã÷´Ë´Î¹¥»÷Ô˶¯×îÔç¿É×·Ëݵ½2020Äê1Ô¡£½øÒ»²½ÆÊÎöÎÒÃÇ·¢Ã÷£¬ÕâÅú¹¥»÷ÕߵĹ¥»÷ÄîÍ·¡¢¹¥»÷Ä¿µÄ¡¢×÷ÒµÆø¸ÅÓëSWEEDºÚ¿Í×éÖ¯¼«ÎªÏàËÆ£¬ËûÃÇÉÐÓÐ×ÅÏàËƵĹ¥»÷Ï°¹ß£¬²¢Ê¹ÓÃÏàͬÇÔÃÜľÂí³ÌÐò£¬ÒÔ¼°Í¬ÑùÆø¸ÅµÄC&CµØµã¡£Òò´Ë£¬ÎÒÃÇÍƶÏÕâÅú¹¥»÷±³ºóÓ¦¸Ã¾ÍÊÇSWEEDºÚ¿Í×éÖ¯¡£SWEEDÊÇÒ»¸öÀ´×ÔÄáÈÕÀûÑǵÄÒÔ»ñÈ¡¾¼ÃÀûÒæΪÖ÷ҪĿµÄµÄºÚ¿Í×éÖ¯£¬Æä×îÔç·ºÆðÓÚ2017Ä꣬³£Ê¹ÓùûÕæÅû¶µÄÎó²î£¬½èÖúÓã²æʽ´¹ÂÚÓʼþÀ´Èö²¥Ä¾Âí³ÌÐò£¬ÈçAgent Tesla¡¢FormbookºÍLokibotµÈ¡£¸Ã×éÖ¯ÔøÔÚÔçÆÚ±»Åû¶µÄ¹¥»÷Ô˶¯ÖУ¬Í¨¹ýÇÔÈ¡±»¹¥»÷Ä¿µÄÓû§ºÍÆóÒµÃô¸ÐÐÅϢʵÑéÖÐÐÄÈ˹¥»÷£¬ÓÕʹ²ÆÎñÖ°Ô±½«¿î×ÓתÖÁÖ¸¶¨ÕË»§£¬ÊÇÒ»¸öµä·¶µÄÍøÂçÕ©ÆÍŻ
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¶Ô±¾´Î¹¥»÷Ô˶¯µÄ¹¥»÷Àú³ÌºÍ¹¥»÷ÊÖ·¨¾ÙÐÐÁËÏêϸµØÆÊÎöºÍËÝÔ´£¬²¢¶ÔÆäËùʹÓõÄÐÂÐͶñÒâÈí¼þºÍC&C»ù´¡ÉèÊ©¾ÙÐÐÁËÉîÈëÑо¿¡£ÌáÐѸ÷´óÆóÒµµ¥Î»×öºÃÇå¾²Ìá·ÀÊÂÇ飬½÷·ÀºóÐø¿ÉÄÜ·ºÆðµÄ¹¥»÷¡£
¶þ¡¢¹¥»÷Ä¿µÄºÍÊܺ¦ÕßÂþÑÜ
×èÖ¹µ½2020Äê6Ô£¬ÎÒÃÇ·¢Ã÷¹¥»÷ÕßµÄÖصãÄ¿µÄΪ´ÓʶÔÍâÉÌÒµµÄÖÐСÐÍÆóÒµ£¬ÆäÄ¿µÄÊÇͨ¹ýÖ²ÈëÌض¨µÄºóÃÅÒÔʵÏÖ¶ÔÄ¿µÄÅÌËã»ú¾ÙÐÐÐÅÏ¢ÍøÂçºÍºã¾Ã¼à¿Ø£¬²¢Îª½ÓÏÂÀ´µÄºáÏòÒƶ¯¹¥»÷Ìṩ»ù´¡¡£
2.1 µØÇøÂþÑÜ
ͨ¹ý¶ÔÒÑÖªµÄSWEED×éÖ¯¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĹú¼ÒºÍµØÇøÂþÑÜÇéÐξÙÐÐͳ¼Æ£¨Èçͼ2-1£©£¬ÎÒÃÇ¿ÉÒÔ¿´µ½¸Ã×éÖ¯ÌᳫµÄ¹¥»÷Ô˶¯ÁýÕÖÁËÐí¶à¹ú¼ÒºÍµØÇø£¬ÓÉ´ËÍƲ⣬¹¥»÷ÕßÔÚ¹¥»÷Ä¿µÄµØÀíλÖõÄÑ¡ÔñÉϲ¢Ã»ÓÐÌض¨µÄÖ¸ÏòÐÔ¡£
ͼ2-1 Êܺ¦Õß¹ú¼ÒµØÇøÂþÑÜͼ
2.2 ÐÐÒµÂþÑÜ
ͳ¼ÆЧ¹ûÏÔʾ£¨Èçͼ2-2£©£¬´Ë´ÎSWEED×éÖ¯ÔÚÃæÏòÈ«ÇòµÄ¹¥»÷ÖУ¬ÔËÊä¡¢ÖÆÔìÒµºÍÄÜÔ´ÐÐÒµÒÀÈ»ÊÇÆäÖصãÕë¶ÔµÄÄ¿µÄ¹¤¾ß¡£
ͼ2-2 Êܺ¦ÕßÐÐÒµÂþÑÜͼ
Èý¡¢¹¥»÷ÊÂÎñÆÊÎö
±¾Ð¡½Ú×ܽáÁ˸Ã×éÖ¯ÔÚ½üЩÄêµÄ¹¥»÷Ô˶¯Ê±¼äµã¡¢´Ë´ÎÐж¯ÖÐʹÓõĹ¥»÷ÊÖ·¨ÒÔ¼°¹¥»÷Á÷³Ì¡£
3.1 ¹¥»÷Ô˶¯Ê±¼äÏß
ΪÁ˶ԺڿÍ×éÖ¯Ôڴ˴ι¥»÷Ô˶¯Ê¹ÓõÄÕ½ÂÔºÍÊÖÒÕ¾ÙÐÐÖÜÈ«µÄÏàʶ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÑо¿Ö°Ô±½«ÏÖÔÚ¹ØÁªµ½µÄ¸Ã×éÖ¯½ü¼¸ÄêµÄÖ÷ÒªÔ˶¯×öÁËÊáÀíºÍ×ܽᣬ²¢»æÖÆÁË¡°SWEED×éÖ¯¡±Ô˶¯Ê±¼äÖᣨÈçͼ3-1£©¡£´Óʱ¼äÖá¿ÉÒÔ¿´³ö£¬¸Ã×éÖ¯µÄ´ó²¿·ÖÔ˶¯¶¼¾ßÓÐÒ»ÖÂÐÔ¡ª¡ª½èÖú´øÓжñÒ⸽¼þµÄÓã²æʽ´¹ÂÚÓʼþ·Ö·¢Ô¶¿ØľÂí³ÌÐò£¨RAT£©£¬²¢ÇÒÐж¯ÖÐʹÓõÄľÂí³ÌÐòÖ÷ÒªÊÇÒÔAgent TeslaΪÖ÷¡£
ͼ3-1 SWEED×éÖ¯Ïà¹ØÔ˶¯Ê±¼äÖá
3.2 ¹¥»÷ÊÖ·¨ºÍÌصã
SWEED×éÖ¯ÔÚ³õʼ»·½ÚÖ÷ÒªÒÔͶµÝ´¹ÂÚÓʼþ×îÏÈÕö¿ª¹¥»÷£¬¹¥»÷ÕßÔÚÇ°ÆÚ¶ÔÄ¿µÄÓû§¾ÙÐÐÉîÈëµ÷ÑУ¬Ñ¡È¡ÓëÄ¿µÄÓû§ËùÊôÐÐÒµ»òÁìÓòÏà¹ØµÄÄÚÈÝÀ´½á¹¹ÓʼþºÍ¶ñÒâÎĵµ¡£Ëæºó½«È«ÐÄÖÆ×÷µÄÖ÷ÌâÈ硱²É¹º¶©µ¥¡±¡¢¡°½ôÆÈÔËÊäÎļþ¡±¡¢¡±×°´¬Í¨Öªµ¥¡°µÈÎĵµÌí¼ÓÔÚÓʼþ¸½¼þÖз¢Ë͸øÄ¿µÄÓû§£¬ÓÕʹÆäÏÂÔظ½¼þ£¬Ä¿µÄÓû§Ò»µ©·¿ª´øÓÐÎó²îµÄ¶ñÒâÎĵµ£¬´¥·¢Îó²îµÄ¶ñÒâ´úÂë¾Í½«»áÔÚºǫ́¾²Ä¬ÏÂÔغÍÖ´ÐжñÒâÈí¼þ£¬´Ó¶øÇÔÈ¡Ä¿µÄÓû§µÄÃô¸ÐÐÅÏ¢²¢¶ÔÆäÖ÷»ú¾ÙÐпØÖÆ¡£
3.2.1 Óã²æÓʼþ
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabͨ¹ý¶ÔSWEED×éÖ¯ÄêÍ·ÖÁ½ñµÄ¹¥»÷Ðж¯¾ÙÐмà²âºÍ¹ØÁªÆÊÎöºó£¬ÊáÀí³ö¼¸Ê®Æð¶¨ÏòÄ¿µÄµÄ¹¥»÷´¹ÂÚÓʼþ¡£²¿·ÖÏà¹ØÓʼþÐÅÏ¢¼û±í3-1¡£
±í3-1 ²¿·Ö´¹ÂÚÓʼþ°¸ÀýÐÅÏ¢
ʱ¼ä |
ÓʼþÖ÷Ìâ |
·¢¼þÈË |
ÊÕ¼þÈË |
2020Äê6ÔÂ10ÈÕ |
RE : URGENT!!! 2 x 20ft - SHIPPING DOC BL,SI,INV#462345 //\r\n MAERSK KLEVEN V.949E // CLGQOE191781 // |
"A.P. Moller ¨C Maersk" nooreply@maersk.com |
undisclosed-recipients |
2020Äê6ÔÂ9ÈÕ |
M/V BCC - Port Agency Appointment |
InterTrans OPS¡± operation@inter-trans.co |
jameshall@compasspub.com |
2020Äê6ÔÂ8ÈÕ |
AGENCY APPOINTMENT/ MV SHOTAN /DISCHARGING/PDA |
df15ae634578@6b74fbd36.cn |
9ed08@dcc762b7ba3.uk |
2020Äê5ÔÂ17ÈÕ |
PAYMENT ADVICE-TELEGRAPHIC TRANSFER NO. M88SI1808BU00250 |
11@c7c7bacd336b.com |
undisclosed-recipients |
2020Äê4ÔÂ29ÈÕ |
Purchase Order /APO-074787648
|
jane.hsieh@sealking.com.tw |
gjchristopher@safeguard-technology.com |
2020Äê4ÔÂ24ÈÕ |
[ D.H.L ] Document Arrival Notice |
royalcrown_travel@hotmail.com |
Anna.Chitan@linde.com |
2020Äê4ÔÂ23ÈÕ |
Shipment Arrival Notice |
noreply@dhl.com |
andrea.schilling@silloptics.de |
2020Äê4ÔÂ21ÈÕ |
SF Express£ºÄúµÄ°ü¹ü¸üР|
no-reply@sendover.net |
info@kraeber.de |
2020Äê4ÔÂ7ÈÕ |
Returned Payment MT103 Swift |
shipping@angloeastern.com |
undisclosed-recipients |
2020Äê3ÔÂ24ÈÕ |
RE: New Order (PO Ref: 01002020) |
account@dongbuhitek.co.kr |
undisclosed-recipients |
2020Äê3ÔÂ23ÈÕ |
RE: M/V BLUE LOTUS/NOON RPT /VOY BL 03.20/ DD 24th March 2020- APPOINTMENT REQUEST |
shahid@erawanaircargo.com |
undisclosed-recipients |
2020Äê3ÔÂ17ÈÕ |
RE : RE : URGENT SHIPPING DOC BL,SI,INV 462345//MAERSK KLEVEN V.949E//CLGQOE191781// |
nooreply@maersk.com |
unrecognized@sys.redcondor.com |
2020Äê3ÔÂ17ÈÕ |
VSL: MV FORTUNE TRADER |
Oriental Logistics Group Limited cindy@persadanusantara.co.id |
undisclosed-recipients |
2020Äê3ÔÂ16ÈÕ |
New order by sea FO1909009 |
acct@gandptech.com |
undisclosed-recipients |
2020Äê3ÔÂ16ÈÕ |
P.I, P.O/MT SR YUJIN (SYNTEK) |
bright@kj-global.co.kr |
undisclosed-recipients |
2020Äê3ÔÂ9ÈÕ |
RE: Refund of deposit |
pffb@comsats.net.pk |
undisclosed-recipients |
2020Äê2ÔÂ21ÈÕ |
WG: New Order |
Anja.Sieveritz@hsm.eu |
holthausen@einstein.br |
2020Äê2ÔÂ19ÈÕ |
RE 2 second lot FCL shipment #48897 Ex works price |
Zhejiang Meto Electrical Co. |
operations@labcosulich.com |
2020Äê2ÔÂ19ÈÕ |
Request For Quotation (RFQ-008342) |
purchase@auronapharma.com |
kbrooks@alpinecom.net |
2020Äê2ÔÂ19ÈÕ |
?? ?? (?? ??) ???? ?? |
usef3@hotmail.com |
monstar1234@knps.or.kr |
2020Äê2ÔÂ18ÈÕ |
RE: Revised Cargo Receipts/Documents. |
ojs@ojshipping.co.kr |
undisclosed-recipients |
̫ͨ¹ýÎöÕâЩÓÊÏä·¢¼þÈËËùÊô¹«Ë¾µÄ×¢²áÐÅÏ¢ÒÔ¼°Æä¹ÙÍøÐÅÏ¢£¬ÎÒÃÇ·¢Ã÷´ó¶¼¹«Ë¾ÍøÕ¾¾ùΪÕýµ±ÍøÕ¾£¬ÓÉ´ËÍƲ⹥»÷ÕßʹÓõÄÕâЩÓÊÏ䣬ÓпÉÄÜÀ´×Ô±»ÈëÇֺ͵ÁÓõÄÕýµ±ÊµÌå»òСÎÒ˽¼Ò¡£ËäÈ»ÊÕ¼þÈ˵ÄÐÅÏ¢Ðí¶àÎÞ·¨¿´µ½£¬¿ÉÊÇ´ÓÓʼþµÄÖ÷ÌâÒÔ¼°ÕýÎÄÄÚÈݲ»ÄÑ¿´³ö£¬¹¥»÷ÕßÍýÏëʹÓÃÔËÊä»õÎïÇåµ¥¡¢×°Ïä½»»õ¼Ûµ¥¡¢ÎïÆ·µ½»õ֪ͨµ¥¡¢º£ÉÏж©µ¥µÈÓʼþÏòÔËÊäÉÌ¡¢ÖÆÔìÉ̼°ÆäÏàÖúÉ̾ÙÐÐÓÐÕë¶ÔÐԵĹ¥»÷Ô˶¯¡£ÏÂÃæÎÒÃÇ´ÓÒÔÉÏÓʼþÖÐö¾ÙÒ»¸ö×ö¼òÆÓÆÊÎö¡£
ÔÚ´Ë°¸ÀýÖУ¬¹¥»÷ÕßÊÔͼʹÓá°VSL: MV FORTUNE TRADER¡±Ö÷Ìâð³ä¡°MV Fortune Trader¡±¡£´¬²°FORTUNE TRADERÊÇÒ»ËÒ½¨ÓÚ1994ÄêµÄ¼¯×°Ïä´¬£¬¸Ã´¬²°µÄ×¢²á¹ú¼ÒΪº«¹ú¡£
ͼ3-2 ´¬²°FORTUNE TRADERÏà¹ØÐÅÏ¢
ÓʼþÕýÎÄÓëÖ÷Ìâ¼á³ÖÒ»Ö£¬ÏÔʾ¸ÃÓʼþÊÇÀ´×Ô³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾¡£¸Ã¹«Ë¾×ܲ¿Î»ÓŲ́Íą̊±±£¬Ö÷ÒªÌṩº£ÔË¡¢¿ÕÔ˺ÍÖиÛÔËÊäµÈÓªÒµ¡£
ͼ3-3 ³¬½Ý¹ú¼ÊÎïÁ÷¹«Ë¾Ö÷Ò³
ÓʼþÕýÎÄÈçͼ3-4£º
ͼ3-4 ÓʼþÕýÎÄÐÅÏ¢
¶ÔÓʼþÐÅÏ¢¾ÙÐÐÆÊÎöºóÈçͼ 3-5Ëùʾ£¬·¢¼þÈ˵ÄÓʼþµØµãÊÇÓ¡¶ÈÄáÎ÷ÑÇÒ»¼ÒÃûΪ¡°PT.INTI PERSADA NUSANTARA¡±µç»ú×°±¸¹«Ë¾µÄÕýµ±Óò£¬¶ø¸ÃÓʼþÏÖʵÉÏÊÇÓÉÍйÜÔÚus10.rumahweb.comÉϵÄRoundcube WebÓʼþ·þÎñÆ÷·¢ËÍ¡£ÕâÀïÊÕ¼þÈ˵صãÖ®ÒÔÊÇÏÔʾΪ¡°Undisclosed-Recipient¡±£¨µ¼ÖÂÎÞ·¨¿´µ½ÊÕ¼þÈËÐÅÏ¢£©£¬ÍƲ⹥»÷ÕßÊÇÔÚʹÓÃRoundcube Webmail/1.3.8Èí¼þȺ·¢Óʼþʱ£¬ÎªÁ˲»ÈÃÊÕ¼þÈË¿´µ½ÆäËûÎüÊÕÓʼþÈ˵ĵص㣬¹Ê½«´Ë´¦ÉèÖÃΪUndisclosed-Recipient¡£
ͼ3-5 ²¿·ÖÓʼþÍ·²¿ÐÅÏ¢
3.2.2 ÓÕ¶üÎļþ
ͨ¹ý¶Ô¸ÃÅú½Ø»ñµÄÓʼþ¾ÙÐÐÆÊÎöËùµÃ£¬¹¥»÷ÕßʹÓõĹ¥»÷ÔغÉÀàÐÍ×ܹ²ÓÐËÄÖÖ¡£ÏÂÃ潫ö¾Ùµä·¶µÄ¹¥»÷Ôغɼ°ÆäËù¶ÔÓ¦µÄ´¹ÂÚÓʼþ¡£
(1) Я´øÎó²îÎĵµ
ͼ3-6ÊÇÒ»·â¹¥»÷ÕßðÃûº½¿Õ»õÔ˹«Ë¾·¢Ë͸ø¿Í»§µÄÔ¤Ô¼ÇëÇó»Ø¸´Óʼþ£¬¸½¼þαװ³É´¬²°ÏêϸÐÅÏ¢±íµ¥¡£¸ÃÎĵµÊ¹ÓÃ΢ÈíOffice¾µäÎó²îCVE-2017-11882£¬µ±Óû§·¿ª¶ñÒâÎĵµÊ±£¬Ç¶Èëµ½ÎĵµÖеĶñÒâ³ÌÐòÔò»á×Ô¶¯¼ÓÔØ¡£¸ÃÎó²îµÄÌصãÊÇÔÚÕû¸öÀú³ÌÖÐÓû§ÍêÈ«ÎÞ¸ÐÖª£¬ÇÒÔÚ¶ÏÍøµÄÇéÐÎÏÂÈÔÈ»¿ÉµÖ´ïÓÐÓù¥»÷£¬ÒÔÊdzÉΪ¸÷´óAPT×éÖ¯±ØÓÃÎó²îʹÓÿâÖ®Ò»¡£
ͼ3-6 Я´øÎó²îÎĵµ°¸Àý1¡ªÓʼþ½Øͼ
£¨2£©Ð¯´øGZÃûÌõÄѹËõÎĵµ
ͼ3-7Êǹ¥»÷Õß·¢Ë͸ø×ܲ¿Î»ÓÚ±ÈÀûʱµÄÒ»¼Ò¶àÔª»¯µÄ¹¤ÒµÖÆÔìÉ̵ÄÓʼþ£¬¸ÃÓʼþʹÓÃÈÈÃŵÄCOVID-19ΪÖ÷Ì⣬²¢Í¨¹ýÕýÎÄÐÎò»Ñ³Æ¶ñÒ⸽¼þGZѹËõÎĵµÖаüÀ¨²É¹ºµ¥£¬ÓÕʹÊܺ¦ÕßÏÂÔØ¡£
ͼ3-7 Я´øGZÎĵµ°¸Àý2¡ªÓʼþ½Øͼ
¸½¼þÄÚÀïÊÇαװ³ÉbatÎļþµÄGuloaderÏÂÔØÆ÷¡£
ͼ3-8 GZѹËõ°üÀïµÄÎļþ
£¨3£©Ð¯´øISOÃûÌõÄÎĵµ
ÓÉͼ 3-9¿É¼û£¬¹¥»÷Õß½«Óʼþ¸½¼þαװ³Éϵͳ¾µÏñISOÎļþ£¨Ê¹ÓÃISOÎļþ¿ÉÓÃÓÚÈƹýÀ¬»øÓʼþ¹ýÂËÆ÷£©£¬½«ÆäÃüÃûΪ¡°COVID-19½â¾ö¼Æ»®Ðû²¼¡±ÓÕÆÓû§µã»÷¡£Ç¶ÈëÔÚISO¶ñÒ⸽¼þÖеĿÉÖ´ÐÐÎļþΪGuloaderÏÂÔØÆ÷¡£
ͼ3-9 ISOѹËõ°üÀïµÄÎļþ
£¨4£©Ð¯´øhtmlÃûÌõÄÎļþ
ͼ3-10Êǹ¥»÷Õßð³äDHL Express¹ú¼Ê¿ìµÝ¹«Ë¾·¢Ë͸øµÂ¹úÒ»¼Ò¹âѧ×é¼þÖÆÔìÉ̵Ĵ¹ÂÚÓʼþ£¬Óʼþ¸½¼þ±»ÃüÃûΪװ´¬Í¨Öªµ¥²¢ÒÔhtmlÐÎʽÓÕÆÊܺ¦Õßµã»÷¡£
ͼ3-10 Я´øhtmlÎļþ°¸Àý3¡ªÓʼþ½Øͼ
3.2.3 ¶ñÒâÈí¼þÍйÜλÖÃ
ÔÚ¹¥»÷Ô˶¯ÖУ¬¹¥»÷Õß¾³£Ê¹ÓÃÔ¶³ÌÉèÖÃÀ´¿ØÖƶñÒâÈí¼þ£¬¶øÇ徲ְԱͨ¹ýÑо¿ÆÊÎö²î±ðµÄ¶ñÒâÈí¼þÉèÖã¨ÀýÈçÖ÷»úµØÀíλÖúÍDNSÐÅÏ¢£©£¬¿ÉÒÔÉîÈëµÄÏàʶºÍ×·×Ù¹¥»÷ÕßʹÓõĻù´¡ÉèÊ©¡£ÎÒÃÇÔÚÑо¿Àú³ÌÖн«ÍøÂçµ½µÄ´ó×ÚÑù±¾Êý¾Ý¾ÙÐÐÌáÈ¡ºÍÕûºÏ£¬·¢Ã÷SWEED×éÖ¯´Ë´ÎʵÑé¹¥»÷Ðж¯ËùʹÓõĶñÒâÈí¼þÉèÖã¬Ö÷ÒªÓ¦ÓÃÁËGuloaderÏÂÔØÆ÷ÉèÖÃÑ¡ÏîÖеÄʹÓÃÔÆ·þÎñ·Ö·¢¶ñÒâÈí¼þµÄ¹¦Ð§¡£¹¥»÷ÕßÖ®ÒÔÊÇʹÓÃÕý¹æµÄÔƴ洢ƽ̨À´ÍйܶñÒâÈí¼þ£¬ÊÇÓÉÓÚÕâЩÔÆƽ̨´ó¶¼ÊÇÊÜÐÅÍеÄÇÒÓÐÖúÓÚÈƹýÉÌÒµÍþв¼ì²â²úÆ·¡£ËäÈ»Google DriveµÈÔÆƽ̨ͨ³£Ò²»áÖ´ÐзÀ²¡¶¾¼ì²â£¬µ«ÈôÊÇÓÐÓÃÔغÉÊDZ»¼ÓÃܺóÔÙ´æ´¢£¬¾Í¿ÉÒÔ¶ã¹ý´ËÀàÏÞÖÆ£¬²¢ÄÜÓÐÓõÄ×èÖ¹Çå¾²Ö°Ô±¶ÔºÚ¿Í×éÖ¯µÄ»ù´¡ÉèÊ©¾ÙÐÐ×·×Ù¡£Í¼3-11Ϊ¶ñÒâÔغÉÑù±¾ÍйÜƽ̨µÄʹÓÃÕ¼±ÈÂÊ¡£Æ¾Ö¤Í¼ÖÐÏÔʾµÄÊýÖµ¿ÉµÃ£¬Google DriveΪ¶ñÒâÈí¼þÖ÷ҪʹÓõÄÍйÜƽ̨¡£³ý´ËÖ®Í⣬ÉÐÓв¿·Ö¶ñÒâÈí¼þ»áÍйÜÔÚÒѱ»¹¥ÏݵÄÕýµ±ÍøÕ¾ÉÏ¡£
ͼ3-11ÓÐÓÃÔغÉÍйÜƽ̨µÄʹÓÃÂÊ
³ýÁËGoogle DriveºÍOneDrive£¬ÏÂÃæÎÒÃÇö¾Ù³ö¼¸¸ö¹¥»÷ÕßʹÓõÄÆäËûÔÆÍйÜƽ̨¡£
files.fmÊÇÍâÑóÒ»¼ÒÌṩÎļþÔƴ洢ƽ̨µÄÐÅÏ¢ÊÖÒÕ¹«Ë¾¡£Í¼3-12ÊÇÉúÑÄÔÚ¸Ãƽ̨µÄ¼ÓÃܵĶñÒâÎļþ¡£
ͼ3-12 ÔÆÍйÜƽ̨Àý1
sendspaceÊÇÒ»¼ÒÃâ·ÑÎļþÍйÜƽ̨¡£Í¼3-13Êǹ¥»÷ÕßÉÏ´«µ½¸Ãƽ̨¾ÙÐÐÍйܵĶñÒâÈí¼þ¡£
ͼ 3-13 ÔÆÍйÜƽ̨Àý2
dmca.gripeÊÇÒ»¸öÃâ·ÑµÄÎļþÍйÜƽ̨£¬ÆäÖ÷Ò³Èçͼ3-14Ëùʾ¡£
ͼ3-14 ÔÆÍйÜƽ̨Àý3
3.3 ¹¥»÷Á÷³Ì
ÎÒÃǶÔÕâÅú¹¥»÷Ô˶¯¾ÙÐйéÄÉÆÊÎöºó·¢Ã÷¾ø´ó²¿·Ö¹¥»÷¾ßÓÐÏàͬµÄ¹¥»÷Á÷³Ì£¬Æä¹¥»÷µÄÁ÷³ÌÈçͼ3-15¡£
3-15 ¹¥»÷Á÷³Ìͼ
¹¥»÷Õßαװ³ÉÎïÁ÷»ò´¬²°µÈ¹«Ë¾Ö°Ô±£¬ÏòÄ¿µÄÆóҵͶµÝЯ´ø¸½¼þµÄ´¹ÂÚÓʼþ£¬¸½¼þÀàÐÍ°üÀ¨£º°üÀ¨Îó²îµÄ¶ñÒâÎĵµ¡¢GZÃûÌõÄѹËõ°ü¡¢ISOÎļþºÍHTMLÎļþ¡£ÔÚ´ó¶¼ÇéÐÎÏ£¬ÕâЩ¸½¼þÔçÏȶ¼»á°üÀ¨»òÏÂÔØGuloaderÏÂÔØÆ÷£¨ÆäËûÇéÐÎÏÂΪԶ¿ØľÂí£©¡£Guloader×îÏÈÖ´ÐÐʱ£¬ÏȶÔÖü±£´æ´úÂ벿·ÖµÄshellcode¾ÙÐнâÃÜ£¬ÔÙ½«½âÃܺóµÄshellcode×¢Èëµ½RegAsm.exeϵͳÎļþÖУ»½Ó×ÅRegAsm.exeÖеÄshellcodeÔÙ´ÓÖ¸¶¨µÄÔÆƽ̨µØµãÏÂÔؼÓÃܵÄpayload£¬²¢ÔÚÄÚ´æÖнâÃÜÖ´ÐÐpayload£¨Ô¶¿ØľÂí£©£¬×îºóͨ¹ýC2¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì¿ØÖÆ¡£
´Ë´Î¹¥»÷Ô˶¯ÖÐʹÓõ½µÄÇÔÃܺÍÔ¶¿ØľÂí°üÀ¨£ºAgent Tesla£¨ÊÇÒ»¿î×ÅÃûµÄÉÌÒµÇÔȡľÂí£¬Ö÷ÒªÓÃÓÚä¯ÀÀÆ÷¡¢Óʼþ¿Í»§¶Ë¡¢FTP¹¤¾ß¡¢ÏÂÔØÆ÷µÈÓû§Õ˺ÅÃÜÂëºÍWiFiƾ֤µÄÇÔÈ¡¡££©£»Formbook£¨ÊÇÒ»¿îÐÅÏ¢ÇÔȡľÂí£¬ÆäÖ÷ÒªÒÔÇÔÈ¡Óû§µçÄÔÉñÃØÐÅϢΪÖ÷£¬°üÀ¨¼üÅ̼ͼ¡¢¼ôÌù°å¼Í¼¡¢cookie»á»°ÓëÍâµØÃÜÂëµÈµÈ¡££©£»Lokibot£¨Ò»¿îÇÔÃÜľÂí£¬Æäͨ¹ý´Ó¶àÖÖÊ¢ÐеÄÍøÂçä¯ÀÀÆ÷¡¢FTP¡¢µç×ÓÓÊÏä¿Í»§¶Ë¡¢ÒÔ¼°PuTTYµÈITÖÎÀí¹¤¾ßÖлñȡƾ֤£¬À´ÇÔÈ¡Óû§µÄÃÜÂëºÍ¼ÓÃÜÇ®±ÒÇ®°ü£©£»NanoCore£¨ÊÇÒ»¿î.net±àдµÄÔ¶¿ØÈí¼þ£¬Æä¾ßÓмüÅ̼à¿Ø¡¢ÊµÊ±ÊÓƵ²Ù×÷¡¢ÓïÒô¡¢ÏÂÁîÐпØÖƵÈÍêÈ«¿ØÖÆÔ¶³ÌÖ÷»úµÄ¹¦Ð§¡££©£»Remcos£¨Ò»¿îÔ¶¿ØÈí¼þ£¬°üÀ¨ÏÂÔز¢Ö´ÐÐÏÂÁî¡¢¼üÅ̼ͼ¡¢ÆÁÄ»¼Í¼ÒÔ¼°Ê¹ÓÃÉãÏñÍ·ºÍÂó¿Ë·ç¾ÙÐмÒô¼ÏñµÈ¹¦Ð§¡££©¡£
¼øÓÚÎÒÃÇÆÊÎöµÄÕâЩľÂíÔÚ¹¦Ð§ºÍÊÖÒÕÉÏÓë¾É°æÀàËÆ£¬²¢Ã»Óз¢Ã÷Ì«¶àµÄת±äµã£¬ÒÔÊÇÔÚ´ËÎÒÃǽö¶ÔÆäÖ÷Òª¹¦Ð§×öÁ˼òÆÓµÄÐÎò£¬±¾ÎĺóÐø±ã²»ÔÙ¹ý¶àµÄÏêϸÐÎòÆäÏêϸµÄÊÖÒÕϸ½Ú£¬ÈôÓÐÐèÒª¸÷ÈË¿ÉÉó²éÎÄÄ©µÄ²Î¿¼ÎÄÏס£ÔÚϸöÕ½ڣ¬ÎÒÃÇÖ÷Òª¶ÔSWEED×éÖ¯ÐÂÒýÈëµÄGuloader¶ñÒâ´úÂë¾ÙÐÐÍêÕûÏêϸµØÆÊÎö¡£
ËÄ¡¢ÊÖÒÕÆÊÎö
ÕýÈçÇ°ÎÄËùÊö£¬ÎÒÃÇÏÖÔÚÍøÂçµ½µÄµç×ÓÓʼþµÄ¸½¼þÖ÷Òª·ÖΪËÄÀà¡£ËäÈ»ÆäÊͷŶñÒâÈí¼þµÄÐÎʽ²î±ð£¬µ«ËüÃǵÄÖ÷Òª¹¦Ð§ÐÐΪ¶¼»ù±¾Ò»Ö¡£ÔÚÕâÀÎÒÃÇÑ¡È¡Ò»¸öµä·¶°¸Àý¾ÙÐÐÏêϸÆÊÎö¡£
4.1 ´¹ÂÚÓʼþ
ͼ4-1Ϊ¹¥»÷ÕßÕë¶ÔÃÀ¹úÒ»¼Ò·À»¬²úÆ·ÖÆÔìÉ̾ÙÐй¥»÷µÄ´¹ÂÚÓʼþ£¬´ËÓʼþÓÚÃÀ¹úɽµØʱÇøʱ¼ä2020Äê4ÔÂ29ÈÕ£¨ÖÜÈý£©02:31±»·¢Ë͵½¸Ã¹«Ë¾¡£ÓʼþÎÊÌâΪ¡°Purchase Order /APO-074787648¡±£¬ÕýÎÄÐÎòΪ¡°ÇëÉó²éÇåµ¥ºÍÈ·ÈÏÉÌÆ·¿â´æ¡±£¬²¢¸½ÓÐͬÃû¶ñÒâÎĵµ¡°Purchase Order /APO-074787648¡±¡£
ͼ4-1 ´¹ÂÚÓʼþÄÚÈÝ
4.2 ¶ñÒâÎĵµ
Ñù±¾¡°Purchase Order /APO-074787648.ppsx¡±Ê¹ÓÃÁËɳ³æÎó²îCVE-2014-4114µÄ²¹¶¡£¨MS14-060£©ÈƹýÎó²îCVE-2014-6352¡£É³³æÎó²îÊÇWindows OLEí§Òâ´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²î·ºÆðÔÚMicrosoft Windows·þÎñÆ÷ÉϵÄOLE°ü¹ÜÀíÆ÷ÉÏ¡£¹¥»÷Õßͨ¹ýʹÓøÃÎó²îÔÚOLE´ò°üÎļþ£¨packer.dll£©ÖÐÏÂÔز¢Ö´ÐÐÀàËƵÄINFÎļþ£¬À´µÖ´ïÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ¡£ËäȻ΢ÈíΪɳ³æÎó²îÐû²¼²¹¶¡£¨MS14-60£©£¬µ«¹¥»÷Õß»¹¿Éͨ¹ý½á¹¹Ìض¨µÄCLSIDºÍOLE VerbÀ´ÈƹýMS14-160²¹¶¡µÄÏÞÖÆ£¨CVE-2014-6352£©¡£ÏÂÃæÎÒÃÇÒÔ±¾´ÎÐж¯ÖÐʹÓõĶñÒâÎĵµÎªÀý£¬¶Ô¸ÃÎó²îµÄʵÏÖÔÀí×ö¼òÆÓµÄÆÊÎö¡£
ͼ4-2Ϊ´Ë°¸ÀýÖÐʹÓõÄppsxÎó²î¹¥»÷ÎĵµÄÚÈÝ¡£
ͼ4-2 ppsxÎó²îÎĵµÄÚÈÝ
ÎÒÃǽâѹPPXSÎĵµ¿ÉÒÔ¿´µ½£¬ÔÚ¡°Purchase Order APO-074787648.ppsx\ppt\slides \slides.xml¡±ÖУ¬Ö¸¶¨ÁËǶÈëµÄ¹¤¾ßid=rld3¡£
ͼ4-3 ¡°slides.xml¡±ÎļþÄÚÈÝ
ÔÚ¡°Purchase Order APO-074787648\ppt\slides\_rels\slide1.xml.rels¡±ÖÐÖ¸¶¨ÁËrld3¶ÔÓ¦¡°ppt\embeddings\¡±Ä¿Â¼ÏµÄoleObject1.binÎļþ¡£
ͼ4-4 ¡°slide1.xml.rels¡±ÎļþÄÚÈÝ
¡°Purchase Order APO-074787648.ppsx\ppt\embeddings\¡±Ä¿Â¼Ïµġ°oleObject1.bin¡±ÎļþÄÚǶһ¸öOLE Package¹¤¾ß£¬Ç¶ÈëÎļþΪPE¿ÉÖ´ÐгÌÐò¡£
ͼ4-5 ¡°oleObject1.bin¡±ÎļþÄÚÈÝ
CVE-2014-4114Îó²îµÄ³ÉÒòÊÇpackager.dllÖÐCPackage::LoadÒªÁì¼ÓÔضÔÓ¦µÄOLE¸´ºÏÎĵµ¹¤¾ßʱ£¬Õë¶Ô²î±ðÀàÐ͵ĸ´ºÏÎĵµ¾ÙÐвî±ðµÄ´¦Öóͷ£Á÷³Ì£¬µ«ÆäÖжÔijЩ¸´ºÏÎĵµÖÐǶÈëµÄ²»¿ÉÐÅȪԴÎļþûÓÐ×ö´¦Öóͷ£¡£Óɴ˹¥»÷Õß¿ÉʹÓÃαÔìOLE¸´ºÏÎĵµµÄCLSIDÀ´µÖ´ïÖ´ÐÐÌض¨ÎļþµÄÄ¿µÄ¡£Î¢ÈíÔÚMS14-060²¹¶¡ÖУ¬Í¨¹ýÌí¼ÓMarkFileUnsafeº¯Êý¶ÔÎļþ¾ÙÐÐMOTW´¦Öóͷ££¬½«ÆäSecurity Zone±ê¼ÇΪ¡°´ËÎļþÀ´×ÔÆäËûÅÌËã»ú¡±£¬ÔËÐÐʱ»áµ¯³öÇå¾²ÖÒÑÔ´°¿Ú¡£
ͼ4-6 ¡°%TEMP%\NEW ORDER.exe¡±±ê¼ÇΪ²»¿ÉÐÅÎļþ
µ«¾ÍËãÊܺ¦ÕßÒÑ×°ÖÃMS14-060µÄ²¹¶¡£¬¹¥»÷ÕßÕվɿÉÒÔͨ¹ý½á¹¹Ìض¨µÄCLSIDºÍOLE VerbÀ´¸Ä±äÖ´ÐÐÁ÷³Ì£¬´Ó¶øÈƹý¸Ã²¹¶¡£¨CVE-2014-6352Îó²î£©¡£¹ØÓÚÒ»¸öexeÎļþ£¬×ÝÈ»±»±ê¼ÇΪURLZONE_INTERNET£¬ÓÒ¼üµã»÷ÒÔÖÎÀíԱȨÏÞÖ´ÐиÃexeÎļþ£¬Äǵ±³ÌÐòÔËÐÐʱ±ã²»»áÔÙµ¯³ö¡°Çå¾²ÖÒÑÔ¡±£¨Èçͼ4-6£©µÄÌáÐÑ£¬¶øÊÇÒÔ£¨Èçͼ4-7£©UAC ÌáÐÑ´°µ¯³ö¡£
ͼ4-7 µ¯³öµÄUACÌáÐÑ´°
ÓÉ´Ë¿ÉÖª£¬µ±Êܺ¦Õß·¿ª´ËPPSX¶ñÒâÎĵµÊ±£¬×Ô¶¯²¥·Åģʽ±ã»á¿ªÆô£¬Í¬Ê±¡°%TEMP%\NEW ORDER.exe¡±½«±»ÊÍ·ÅÔÚÔÝʱĿ¼ÖС£ÈôÊÇÊܺ¦ÕßÑ¡Ôñ¡°ÊÇ¡±£¬¶ñÒâ´úÂ뽫»á±»Ö´ÐС£¶øÈôÊÇÊܺ¦ÕßµÄϵͳ´¦ÓÚUAC¹Ø±Õ״̬»òÔÚ»ñÈ¡ÁËÖÎÀíԱȨÏÞµÄÇéÐÎÏ£¬¸ÃUACÇå¾²ÖÒÑÔ´°¿ÚÔò²»»áµ¯³ö£¬¡°NEW ORDER.exe¡±»á±»¾²Ä¬µØÖ´ÐС£
4.3 GuLoader
ÈçÉÏÎÄËùÊö£¬×îºó±»Ö´Ðеġ°NEW ORDER.exe¡±¿ÉÖ´ÐÐÎļþÏÖʵÉϼ´ÊÇÎÄÕ¿ªÍ·Ìáµ½µÄGuloader¶ñÒâÈí¼þ£¨ÔÚºóÐø¶Ô¡°NEW ORDER.exe¡±µÄÏêϸÆÊÎöÖУ¬ÎÒÃǾùʹÓá°Guloader¡±À´Ìæ»»¸ÃÎļþÃû£©¡£GuloaderÊÇÒ»¿îÐÂÐ͵ĶñÒâÈí¼þÏÂÔØÆ÷£¬Æä×Ô¼º¾ßÓÐÖØ´óµÄÖ´ÐÐÁ÷³Ì£¬Í¨¹ý½ÓÄÉÖÖÖÖ´úÂë»ìÏýºÍËæ»ú»¯¡¢·´É³Ïä¡¢·´µ÷ÊÔºÍÊý¾Ý¼ÓÃܵȻúÖÆÀ´¶Ô¿¹Çå¾²²úÆ·µÄ¼ì²â¡£ÏÂÃæÎÒÃǽ«¶Ô¸ÃGuLoader¾ÙÐÐÉîÈëµÄÍÚ¾òÆÊÎö¡£
4.3.1 Ö´ÐÐÁ÷³Ì
Èçͼ4-8Ëùʾ£¬ GuLoaderÊ×ÏȽ«Öü±£´æ´úÂ벿·ÖµÄ¼ÓÃÜShellcode½âÃܲ¢Ö´ÐС£Õâ¶ÎShellcodeµÄÖ÷Òª¹¦Ð§Îª£ºÒÔ¹ÒÆð·½·¨½¨ÉèÒ»¸öϵͳ×ÓÀú³Ì£¬Ö®ºó½«±¾¶ÎShellcode×ÔÉí×¢Èëµ½×ÓÀú³Ì²¢Ð޸ijÌÐòÈë¿ÚµãΪShellcode´¦Ö´ÐС£×îºó´ÓÍйܷþÎñÆ÷ÉÏÏÂÔؼÓÃܵÄBINÎļþ£¬ÀÖ³ÉÏÂÔغó½«Æä½âÃܺÍÔËÐС£
ͼ4-8 GuloaderÖ´ÐÐÁ÷³Ìͼ
4.3.2 EXE¿ÉÖ´ÐÐÎļþ
£¨1£©´úÂë»ìÏý
Guloader¿ÉÖ´ÐÐÎļþÊÇÓÉVisual Basic 6ÓïÑÔ±àдµÄ¡£Ê¹Óù¤¾ßÉó²éºó·¢Ã÷£¬Æ䲢δʹÓÃÉÌÒµ¿Ç¾ÙÐÐ×ÔÉí±£»¤£¬¶øÊÇʹÓûìÏý¿ÇʵÑé¶Ô¿¹Çå¾²²úÆ·µÄ²éɱ¡£ÓÉÓÚɱÈí¶ÔÉÌÒµ¿Ç½ÏÁ¿Ãô¸Ð£¬²¢ÇÒÉÌÒµ¿Ç¼ì²âºÍÍÑ¿ÇÊÖÒÕÒ²½ÏÁ¿³ÉÊ죬ÒÔÊÇ»ìÏý¿Ç²»Ê§ÎªÒ»¸ö²»´íµÄÑ¡Ôñ¡£»ìÏý¿ÇÒ»Ñùƽ³£²»±£´æͨÓõļì²âÒªÁ죬²¢ÇÒ¾²Ì¬ÍÑ¿ÇÏà¶Ô½ÏÄÑ£¬ÒÔÊÇÆä¶ñÒâÐÐΪ²»Ò×±»·¢Ã÷£¬´Ó¶ø¿É³¤Ê±¼äµÄ´æ»îÔÚÄ¿µÄ»úеÉÏ¡£¹ØÓÚÄæÏòÆÊÎöÖ°Ô±À´½²£¬ÆÊÎöÕâÖÖ´ø»ìÏý¿ÇµÄÑù±¾ÍùÍù»áÆÆ·Ñ´ó×ڵľ«Éñ£¬ÎÞÐεÄÔöÌíÁËÈËÁ¦ºÍʱ¼ä±¾Ç®¡£
ͼ4-9ÊÇÒ»¶Î»ìÏý´úÂëµÄ½ØÈ¡£¬Õⲿ·Ö´úÂëʹÓÃÁËÊý¾Ý»ìÏýÖеij£Á¿²ð·Ö£¬Ö÷ҪĿµÄÊÇÒþ²ØÕæʵµÄ´úÂëÂß¼£¬ÈÃÆÊÎöÕßÐÄÌï±¼À£¡£
ͼ4-9 ²¿·Ö»ìÏý´úÂë
£¨2£©´úÂë½âÃÜ
¶ñÒâÈí¼þÊ×ÏÈÅÌËã³öÓÃÓÚ½âÃÜshellcodeµÄÃÜÔ¿£¬ÆäֵΪ£º0x24EBE470¡£
ͼ4-10 »ñÈ¡ÃÜÔ¿µÄ¶ñÒâ´úÂë
½Ó×Å£¬ÎªshellcodeÉêÇëÄÚ´æ¿Õ¼ä£¬ÔÙʹÓÃÃÜÔ¿¾ÙÐÐXORÔËËã½âÃÜShellcode²¢Ö´ÐС£
ͼ4-11 ½âÃܺÍÖ´ÐÐshellcode
4.3.3 ShellCode
½âÃܺóµÄshellcodeÇ°ÆÚÒ²½ÓÄÉÁË´ó×ڵĶԿ¹ÊֶΣ¬Ê¹ÓÃÖÖÖÖ´úÂë»ìÏý¡¢É³Ïä¼ì²â¡¢·´µ÷ÊÔµÈÊÖÒÕÊÖ¶ÎÀ´¹æ±ÜÇå¾²²úÆ·µÄÐÐΪ¼à²âºÍ²éɱ¡£½öµ±Í¨¹ýÖÖÖÖ¼ì²éÅжÏÌõ¼þºó£¬¶ñÒâ´úÂë²Å×îÏÈÖ´ÐÐÖ÷¹¦Ð§ÐÐΪ¡£ÏÂÃæÎÒÃǽ«¶Ô¶ñÒâ´úÂë×öÏêϸµÄÆÊÎö¡£
£¨1£©¼ì²â¹¦Ð§
¡ñ ´úÂë»ìÏý
½«½âÃܺóµÄshellcode´ÓÄÚ´æÖÐdump³öÀ´²¢Ê¹ÓÃIDA·´±àÒ룬¿ÉÒÔ¿´µ½shellcodeÖÐʹÓõĻìÏýÊÖÒÕ¡£¶ñÒâ´úÂëÔÚÖ´ÐÐÀú³ÌÖвåÈë»ìÏýº¯Êý£¬¸Ãº¯ÊýµÄÀú³Ì±»Ö§½â³É¶à¸öÌøתÁ÷³Ì£¬Ò»Ö±µ½×îºóÔÙ jmpµ½ÔÀ´µÄÕý³£´úÂëÖмÌÐøÖ´ÐÐÏÂÃæµÄÁ÷³Ì¡£Í¼4-12ÊÇshellcodeÔÚÈë¿Ú´¦Å²ÓõĴËÀà»ìÏýº¯ÊýµÄ´úÂëƬ¶Ï£¬ºÜÏÔȻͨ¹ý¸ÃÒªÁ죬Äܹ»ÓÐÓõÄÈÅÂÒÆÊÎöÕ߶ÔÑù±¾¾ÙÐÐÆÊÎö£¬ÑÏÖؽµµÍÁËÆÊÎöЧÂÊ¡£
ͼ4-12 »ìÏýºóµÄ´úÂëƬ¶Ï
¡ñ ¶¯Ì¬»ñÈ¡APIº¯Êý
½Ó×Å£¬¶ñÒâ´úÂëͨ¹ý»á¼ûPEB->LDRÖеÄInMemoryOrderModuleList»ñÈ¡kernel32.dllµÄ»ùÖ·¡£±éÀúÌáÈ¡¸ÃÄ£¿éµ¼³ö±í½á¹¹Öдæ·Åº¯ÊýÃûµÄÊý×飬²¢ÒÀ´Î½«Ãû³Æ×Ö·û´®×÷Ϊ²ÎÊý´«Èëµ½¹þÏ£Ëã·¨º¯ÊýÖÐ×öÔËË㣬ÔÙ½«Ð§¹ûÓëÓ²±àÂëÊý¾Ý×ö½ÏÁ¿£¬ÒÔ´ËÒªÁìÀ´²éÕÒGetProcAddressº¯Êý¡£
ͼ4-13 ²éÕÒGetProcAddressº¯Êý
´Ë´¦Ê¹ÓõÄÊÇdjb2µÄËã·¨£¬ djb2ÊÇÒ»¸ö±¬·¢Ëæ»úÂþÑܵĹþÏ£º¯Êý£¬ÓëLCGµÄËã·¨ÏàËÆ¡£ÓÉÓڸú¯Êý½á¹¹¼òÆÓ£¬Ê¹ÓÃÒÆλºÍÏà¼ÓµÄ²Ù×÷£¬ÒÔÊdz£±»ÓÃÀ´´¦Öóͷ£×Ö·û´®¡£ÏêϸËã·¨¼ûͼ4-14¡£
ͼ4-14 djb2Ëã·¨´úÂë½Øͼ
ÓÉ´ËÎÒÃÇ¿ÉÒÔ¿´µ½£¬¶ñÒâ´úÂëÔÚº¯ÊýµÄ»ñÈ¡·½ÃæÊÇʹÓÃLoadLibraryºÍGetProcAddressÕâÁ½¸öº¯Êý¾ÙÐж¯Ì¬µÄ»ñÈ¡¡£ÏêϸÈçͼ4-15Ëùʾ¡£
ͼ4-15 ¶¯Ì¬»ñÈ¡APIº¯Êý
¡ñ ɳÏä¼ì²â
¶ñÒâ´úÂëö¾Ù´°¿ÚÊýÄ¿£¬ÈôÊÇֵСÓÚ12ÔòÍ˳öÀú³Ì£¬ÒÔ´ËÀ´¼ì²â×ÔÉíÊÇ·ñÔËÐÐÔÚɳÏäÇéÐÎÖС£
ͼ4-16 ɳÏä¼ì²â´úÂë
¡ñ ·´µ÷ÊÔÊÖÒÕ
ÒªÁì1£º
ŲÓÃZwProtectVirtualMemoryº¯ÊýÐÞ¸Äntdll.dllµÄ¡°.text¡±½ÚÊôÐÔΪ¿É¶Á¿Éд¿ÉÖ´ÐС£
ͼ4-17 ÐÞ¸Äntdll.dll½ÚÊôÐÔ
¶ñÒâ´úÂëͨ¹ýÐÞ¸ÄDbgBreakPointºÍ DbgUiRemoteBreakinº¯Êý´úÂ룬Èõ÷ÊÔÆ÷ÎÞ·¨¸½¼Óµ÷ÊÔ³ÌÐò£¨Èçͼ4-18ºÍͼ4-19£©¡£¸øcallŲÓúóÃæÖ¸¶¨Ò»¸öδ֪µØµã£¬ÒÔ´ËÒý·¢µ÷ÊÔÆ÷Íß½âÍ˳ö¡£
ͼ4-18 DbgBreakPointº¯Êý´úÂëÐÞ¸ÄÇ°ºó±ÈÕÕ
ͼ4-19 DbgUiRemoteBreakinº¯Êý´úÂëÐÞ¸ÄÇ°ºó±ÈÕÕ
ÒªÁì2£º
½«ZwSetInformationThreadº¯ÊýµÄµÚ¶þ¸ö²ÎÊýÉèÖÃΪThreadHideFromDebugger £¨ÖµÎª17£©£¬×÷ÓÃÊÇÔÚµ÷ÊÔ¹¤¾ßÖÐÒþ²ØÏ̡߳£ÈôÊǶñÒâÈí¼þ´¦ÓÚ±»µ÷ÊÔ״̬£¬ÄÇô¸Ãº¯Êý¾Í»áʹĿ½ñỊ̈߳¨Ò»Ñùƽ³£ÊÇÖ÷Ị̈߳©ÍÑÀëµ÷ÊÔÆ÷£¬Ê¹µ÷ÊÔÆ÷ÎÞ·¨¼ÌÐøÎüÊÕ¸ÃÏ̵߳ĵ÷ÊÔÊÂÎñ¡£Ð§¹û¾ÍÏñÊǵ÷ÊÔÆ÷Íß½âÁËÒ»Ñù¡£
ͼ4-20 Òþ²ØÏ̵ִ߳ﷴµ÷ÊÔÄ¿µÄ
ÒªÁì3£º
ÔÚʹÓÃZwAllocateVirtualMemoryº¯ÊýÉêÇëÄÚ´æ¿Õ¼äʱ£¬Îª±ÜÃâÆÊÎöÖ°Ô±ÔÚµ÷ÊÔʱ¶ÔÒªº¦º¯Êý϶ϵ㣬¶ñÒâ´úÂë»áÌáÇ°½«¸Ãº¯ÊýµÄ¹¦Ð§ÊµÏÖ´úÂ븴ÖƵ½±¾Àú³Ì¿ÕÏпռäÖУ¬Ê¹µÃºóÐøÔÚʹÓô˺¯Êýʱֱ½ÓÌøתµ½×ÔÉí´úÂëÖÐÖ´ÐС£
ͼ4-21 ¸´Öƺ¯Êý¹¦Ð§ÊµÏÖ´úÂë
ÒªÁì4£º
ÔÚŲÓò¿·ÖÃô¸ÐAPIº¯Êýʱ£¬»áÏÈŲÓÃ×Ô½ç˵µÄ¼ì²éº¯Êý×öÅжϣ¬ÒÔïÔ̱»Çå¾²²úÆ·¼ì²âµÄ¼¸ÂÊ¡£
ͼ4-22 ¼ì²éº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³
¸Ã×Ô½ç˵µÄ¼ì²éº¯ÊýµÄÖ÷Òª¹¦Ð§£º
¢Ù ½«Å²Óøú¯ÊýÇ°µÄshellcode´úÂ루ÕýÐò£©°´×Ö½ÚÓë0x4×ֽڵķµ»ØµØµã×öÒì»òÔËËã ¾ÙÐмÓÃÜ´¦Öóͷ££»
¢Ú ŲÓÃZwGetContectThreadº¯Êý£¬Í¨¹ý¼ì²é_CONTEX½á¹¹ÖеÄDr¼Ä´æÆ÷À´ÅжÏÊÇ·ñ ÔÚµ÷ÊÔÇéÐÎÖУ»
¢Û Åжϴ˴ÎÒª¼ì²éµÄÒªº¦APIº¯ÊýÊÇ·ñ±»Ï¶ϵã»ò¹Ò¹³¡£ÈôÊÇЧ¹ûΪ·ñ£¬ÔòŲÓøÃAPIº¯
Êý£¬²»È»³ÌÐòÖ±½ÓÍß½âÍ˳ö£»
¢Ü ͬ¡°ÒªÁì¢Ù¡±¶Ôshellcode´úÂ루µ¹Ðò£©¾ÙÐнâÃܲ¢Ìøתµ½·µ»ØµØµã´¦Ö´ÐкóÐøÁ÷³Ì¡£
ͼ4-23 ×Ô½ç˵¼ì²éº¯Êý´úÂë
£¨2£©¶ñÒâÐÐΪִÐй¦Ð§
ÈôÊÇÒÔÉÏһϵÁеÄɳÏäÒÔ¼°·´µ÷ÊÔ¼ì²â¶¼Í¨¹ý£¬¶ñÒâ´úÂëÔò×îÏÈÖ´ÐÐÒÔÏÂÓγ̣º
¢Ù ¶¯Ì¬»ñȡͼ4-24ÖеÄAPIº¯Êý£¬²¢½«º¯ÊýŲÓõصãÉúÑÄÔÚ¿ÍÕ»ÖС£
ͼ4-24 ¶¯Ì¬»ñÈ¡µÄAPIº¯ÊýÃû³Æ
¢Ú ƾָ֤¶¨µØµã´¦ÉúÑĵÄÊý¾ÝÄÚÈÝÌØÕ÷£¨ÈôÊǶñÒâ´úÂëδִÐйý½¨Éè×ÓÀú³ÌÁ÷³Ì£¬ÄÇ Ã´¸ÃµØµã´¦ÔÊý¾ÝΪÎÞЧÄÚÈÝ£»²»È»£¬´Ë´¦ÉúÑĵÄÊÇÄ¿½ñÀú³ÌµÄȫ·¾¶¡££©À´ÅжÏÊÇ ·ñÐèÒª½¨Éè×ÓÀú³Ì¡£
ͼ4-25 ÅжÏÊÇ·ñÐèÒª½¨Éè×ÓÀú³Ì
ͼ4-26 ¶ÔÖ¸¶¨µØµã´¦ÉúÑĵÄÊý¾ÝÄÚÈÝ×öÅжÏ
¢Û ŲÓÃCreateProcessInternalº¯ÊýÒÔ¹ÒÆðģʽ½¨ÉèRegAsm.exeÀú³Ì¡£
ͼ4-27 ½¨Éèϵͳ×ÓÀú³Ì
¢Ü ŲÓÃZwOpenFileº¯Êý£¬»ñµÃÓ³ÉäÎļþmstsc.exeµÄ¾ä±ú¡£
ͼ4-28 »ñÈ¡mstsc.exeµÄ¾ä±ú
¢Ý ʹÓÃZwCreateSectionºÍNtMapViewOfSectionº¯Êý½«¡°mstsc.exe¡±ÎļþÓ³Éäµ½
RegAsm.exeÄÚ´æÖеÄ0x00400000λÖÃÉÏ¡£
ͼ4-29 Ó³ÉäÎļþ
¢Þ ÔÚ¿þÀÜÀú³ÌÖÐÉêÇëÄÚ´æ¿Õ¼ä£¬²¢½«ÎÒÃÇÕýÔÚµ÷ÊÔµÄÕû¸öshellcodeдÈ뵽ĿµÄÄÚ´æÖС£
ͼ4-30 дÈëshellcodeµ½ÏµÍ³×ÓÀú³ÌÖÐ
¢ß ʹÓÃZwGetContextThreadºÍZwSetContextThreadº¯Êý£¬»ñÈ¡ºÍÐ޸ĹÒÆðµÄ×Ó Ïß³ÌÉÏÏÂÎÄÖмĴæÆ÷Öµ£¬ÒÔʵÏÖÖض¨Ïòµ½shellcodeÈë¿Ú´¦Ö´ÐеÄÄ¿µÄ¡£
ͼ4-31 ÐÞ¸Äϵͳ×ÓÀú³ÌµÄÖ´ÐÐÈë¿Úµã
¢à Èô¡°°ì·¨¢Ý¡±²Ù×÷Àֳɣ¬Ôò»Ö¸´Ö´ÐÐ×ÓÀú³Ì£»²»È»¿¢ÊÂÄ¿½ñ³ÌÐò¡£
ͼ4-32 Åжϰ취¢ÝÊÇ·ñ²Ù×÷ÀÖ³É
£¨3£©ÀÖ³É×¢Èëºó¶ñÒâÐÐΪ¹¦Ð§
ÎÒÃÇÔÚ¶ñÒâ´úÂëŲÓÃNtResumeThreadº¯ÊýÇ°£¬¸½¼ÓRegAsm.exeÀú³Ì²¢ÔÚ×¢ÈëµÄshellcodeÖ´Ðд¦ÉèÖöϵ㣨Èçͼ4-33£©£¬È»ºóÔÙ¼ÌÐøÖ´Ðиú¯ÊýÀ´»Ö¸´Ïß³ÌÔËÐС£¸ÃshellcodeÇ°²¿·ÖÓë֮ǰµÄ²Ù×÷Á÷³ÌÏàͬ£¬½«Ç°ÎÄÐÎòµÄÖÖÖÖ¼ì²âÖØÐÂÖ´ÐÐÒ»±é£¬Ö±µ½ÔÚ¡°ÅжÏÊÇ·ñ½¨Éè×ÓÀú³Ì¡±´¦Ìøתµ½ÁíÍâµÄ·ÖÖ§Á÷³Ì¡£ÏÂÃæÎÒÃǼÌÐø¶ÔºóÐø¹¦Ð§¾ÙÐÐÏêϸµØÆÊÎö¡£
ͼ4-33 ShellcodeÖ´Ðд¦´úÂë
ÅжϿªÆôRegAsm.exe³ÌÐòµÄ¸¸Àú³ÌÊÇ·ñΪ¡°C:\Users\***\directory\filename.exe¡±¡£
ÈôÊDz»ÊÇ£¬Ôò½«Ä¿½ñ¸¸Àú³ÌÎļþ¸´ÖƵ½¸ÃĿ¼ÖУ¬½«ÆäÃüÃûΪfilename.exe²¢ÖØÐÂÖ´ÐУ»
ÈôÊÇÊÇ£¬ÔòÔÚ×¢²á±íHLM\Software\Microsoft\Windows\CurrentVersion\RunOnceĿ¼Àォ¸Ã·¾¶Ìí¼ÓÔÚ¡°Startup key¡±ÖУ¬ÒÔʵÏÖºã¾ÃפÁôµÄÄ¿µÄ¡£
ͼ4-34 Ìí¼Ó×¢²á±íÐÅÏ¢´úÂë
ͼ4-35 Ìí¼Ó×¢²á±í¿ª»úÆô¶¯Ïî
ÀÖ³ÉÌí¼Ó×¢²á±íÏîºó£¬¶ñÒâ´úÂëÔò×îÏÈʹÓÃwinnet.dll¿âÖеÄInternet APIº¯Êý´ÓÔÆÍйܷþÎñÆ÷ÏÂÔؼÓÃܵÄpayload¡£
ͼ4-36 ´ÓÔÆÍйܷþÎñÏÂÔØpayload
ÏÂÔØÍê³Éºó£¬¶ñÒâ´úÂëÔÙ½«Ó²±àÂëµÄÖµÓ뽫payloadµÄ¾Þϸ×ö½ÏÁ¿£¬ÒÔ´ËÀ´¼ì²éÎļþµÄÍêÕûÐÔ¡£ÈôÊǾÞϸ²»Æ¥Å䣬¶ñÒâ´úÂëÔò»áÖØÐÂÏÂÔØÎļþ£¬Ö±µ½ÍêÈ«Æ¥ÅäΪֹ¡£
ͼ4-37 ¼ì²âpayload¾Þϸ
ÏÂÔص½µÄpayloadÎļþÊÇÓÉ0x40¸ö×Ö½ÚµÄHEXСдÊý×ֺͼÓÃܵÄPEÎļþ×é³É£¬ÏêϸÈçͼ4-38Ëùʾ¡£
ͼ4-38 payloadÄÚÈÝ
½Ó×Å£¬¶ñÒâ´úÂëÔÙʹÓÃ×Ô½ç˵½âÃܺ¯Êý¶ÔÏÂÔصÄpayload¾ÙÐÐÒì»ò½âÃÜ¡£ÆäÃÜÔ¿Öü±£´æshellcode´úÂë0x2032Æ«ÒÆ´¦£¬ÃÜÔ¿³¤¶ÈΪ0x214¡£½âÃܺ¯ÊýÄÚÈÝÈçͼ4-39Ëùʾ¡£
ͼ4-39 payload½âÃܺ¯Êý
½âÃܺóµÄPEÎļþÈçͼ4-40Ëùʾ¡£
ͼ4-40 ½âÃܺóµÄÎļþÄÚÈÝ
×îºó£¬¶ñÒâ´úÂ뽫½âÃܺóµÄPEÎļþÁýÕÖ0x00400000»ùÖ·µÄÄÚÈÝ£¬²¢Ìøתµ½Èë¿ÚµãÖ´ÐÐpayload¶ñÒâ³ÌÐò¡£
ͼ4-41 Ö´ÐÐpayload
ÔÚ´Ë´ÎÆÊÎöµÄ°¸ÀýÖУ¬½âÃܳöµÄpayloadÊÇAgent Tesla¡£¹ØÓڸöñÒâÈí¼þ£¬ÔÚ´ËÎÒÃǾͲ»ÔÙ×ö¹ý¶àµÄÏÈÈݺÍÆÊÎöÁË¡£ÏÂÃæÎÒÃÇ»á¶ÔºÚ¿Í×éÖ¯µÄC&C·þÎñÆ÷»ù´¡ÉèÊ©Õö¿ª×·×ÙËÝÔ´¡£
Îå¡¢ËÝÔ´×·×Ù
5.1 C&C»ù´¡ÉèÊ©
×èÖ¹µ½ÏÖÔÚΪֹ£¬ÎÒÃÇͨ¹ýÌáÈ¡ºÍÕûÀíËùÓйØÁªÑù±¾ÖеÄIPµØµãºÍÓòÃûÐÅÏ¢£¬¿ÉÒÔ¿´µ½´Ë´Î¹¥»÷Ðж¯Ö÷ÒªÒÔ¶¯Ì¬ÓòÃûΪÖ÷£¬´ó²¿·ÖÓòÃû¶¼ÊÇͨ¹ý¾³ÍâµÄDuck DNS×¢²á¡£Í¼5-1ΪSWEEDºÚ¿Í×é֯ʹÓõIJ¿·ÖÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹Øϵ¡£
ͼ5-1 ²¿·ÖÓòÃû¡¢IP¡¢Ñù±¾µÄ¶ÔÓ¦¹Øϵͼ
ƾ֤Ñù±¾Í¬Ô´ÐÔÆÊÎöµÄЧ¹û£¬ÎÒÃÇ·¢Ã÷´ó×ÚµÄÓÐÓÃÔغɱ»»®·Ö¹ÒÔØÔÚ²î±ðµÄ¶¯Ì¬ÓòÃûÖУ¬ÒÔ±¸°üÀ¨Îó²îµÄOfficeÎĵµ»ò¶ñÒâÈí¼þGuloader»á¼ûºÍÏÂÔØ¡£Í¨¹ýÓòÃûµÄÅÌÎʼͼËùµÃ£¬´Ë´Î¹¥»÷Ô˶¯×îÔç¿É×·Ëݵ½1ÔÂÖÐÏÂÑ®£¬Í¬Ê±Ò²¿ÉÒÔ¿´µ½£¬ËüÃÇ×î³õ¾ùʹÓÃÖ¸ÏòÄáÈÕÀûÑǵĻù´¡ÉèÊ©¡£ÖµµÃ×¢ÖصÄÊÇ£¬ÕâЩÓòÃûÆÊÎöʹÓõÄIP×Üδ±ØÆÚÔÚ³£ÓõÄIPµØµã¶ÎÍù·µÇл»¡£ÏêϸÈçͼ5-2Ëùʾ¡£
ͼ5-2 ¶¯Ì¬ÓòÃûÆÊÎöµÄIPµØµã
ÎÒÃǽ«C&C¶ÔÓ¦µÄIPµØµãËùÊô¹ú¼ÒºÍµØÇø¾ÙÐÐͳ¼Æ£¬²¢»æÖÆÆäµØÀíλÖÃÂþÑÜͼ£¨Èçͼ5-3Ëùʾ£©¡£ÕûÌåÀ´¿´£¬ÃÀ¹úºÍ·¨¹úÕ¼±ÈÂÊ×î¸ß£¬Æä´ÎΪºÉÀ¼¡£
ͼ5-3 C&C¶ÔÓ¦µÄIPµØÀíλÖÃÂþÑÜͼ
5.2 ¹ØÁªÐÔÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab½«±¾´Î²¶»ñµ½µÄÑù±¾Í¬ÒÔÍùSWEEDÔ˶¯×öÁËÖÜÈ«µÄ¹ØÁªÆÊÎö£¬µÃ³öÒÔϼ¸´¦Ö÷ÒªµÄ¹ØÁªµã£º
£¨1£©Îó²îÎĵµ
ÔÚ´Ë´ÎÐж¯Öй¥»÷×é֯ʹÓõÄÎó²îÎĵµÓÐÁ½ÀࣨCVE-2017-11882ºÍCVE-2014-6357£©£¬ÆäÖÐÒÔCVE-2017-11882Îó²îʹÓÃÎĵµÎªÖ÷Òª¹¥»÷Ôغɡ£¶øSWEED×éÖ¯Ò²ÔøÔÚÒÔÍùµÄ¹¥»÷Ðж¯ÖÐƵÈÔµÄʹÓùý¸ÃÎó²îÎĵµ¡£ÏêϸÈçͼ5-4Ëùʾ¡£
ͼ5-4 Îó²îÎĵµ°¸Àý
£¨2£©¹¥»÷Ä¿µÄ
ƾ֤¹ûÕ汨¸æ¿ÉÒÔµÃÖª£¬SWEEDºÚ¿Í×éÖ¯µÄ¹¥»÷Ä¿µÄÖ÷ÒªÕë¶ÔÈ«Çò´ÓʶÔÍâÉÌÒµµÄÖÐСÐÍÆóÒµ£¬²¢ÇÒËùÉæ¼°µÄÐÐÒµÖ÷ÒªÒÔÖÆÔìÒµ¡¢º½ÔË¡¢ÎïÁ÷ºÍÔËÊäΪÖ÷¡£ÕâÓëÎÒÃǴ˴μà²âµ½µÄ¹¥»÷Ðж¯ÖÐÊܺ¦ÕߵĵØÀíλÖúÍÐÐÒµÂþÑܾßÓнϸߵÄÏàËÆÐÔ¡£Í¼5-5ö¾ÙÁ˼¸ÀýÔÚ±¾´Î¹¥»÷Ô˶¯Öй¥»÷Õß·¢Ë͸øÄ¿µÄÓû§µÄ´¹ÂÚÓʼþ¡£
ͼ5-5 ´¹ÂÚÓʼþ°¸Àý
£¨3£©¹¥»÷ÎäÆ÷
ÔÚÏÖÔÚÊӲ쵽µÄÐж¯ÖУ¬¹¥»÷Õß×îÖÕͶ·ÅµÄ¶ñÒâÈí¼þ°üÀ¨Agent Tesla¡¢Remcos¡¢NanoCore¡¢FormbookºÍLokibot¡£ÎÒÃǽ«²¶»ñµÄËùÓжñÒâÈí¼þ°´¼Ò×å·ÖÀàºÍͳ¼Æ£¬Æ¾Ö¤Ð§¹ûÏÔʾ£¬Agent TeslaµÄÕ¼±ÈÂÊ´¦ÓÚ×î¸ß£¬Êǹ¥»÷ÕßÖصãʹÓõĹ¥»÷ÎäÆ÷¡£¶øÕâÖÖʹÓÃÌØÕ÷Ò²ÔøÖظ´·ºÆðÔÚSWEED×éÖ¯ÒÔÇ°µÄ¹¥»÷Ô˶¯ÖС£
ͼ5-6 ¶ñÒâÈí¼þ¼Ò×åÕ¼±ÈÂÊ
£¨4£©IPµØµãλÖÃ
ÎÒÃÇͨ¹ýWhoisÐÅÏ¢ÅÌÎÊ£¬·¢Ã÷ÔÚ´Ë´ÎÐж¯ÖеÄÓòÃû¡°mogs20.xxx.org¡±ÔçÆÚÆÊÎöµÄIP£¨105.112.XXX.XXX£©µØÀíλÖÃÖ¸ÏòÄáÈÕÀûÑÇ£¬¸ÃÍø¶Î¹éÊôÄáÈÕÀûÑǵØÇøµçÐŵÄ105.112¶Î¡£ÕâÓëSWEED×éÖ¯ËùÊô¹ú¼Ò¾ßÓи߶ȵÄÒ»ÖÂÐÔ¡£
ͼ5-7 WhoisÅÌÎÊÐÅÏ¢ÄÚÈÝ
ÍŽáSWEED×é֯һϵÁеĹ¥»÷Ô˶¯ÌصãÒÔ¼°ÉÏÃæ×ܽáµÄËĵã¿ÉÒÔ¿´³ö£¬¹¥»÷ÕßÔÚ¹¥»÷ÄîÍ·£¨ÇÔÈ¡Óû§ÐÅÏ¢ÒÔIJÀû£©¡¢¹¥»÷Ä¿µÄ£¨Õë¶ÔÈ«Çò¶ÔÍâÉÌÒµµÄÖÐСÆóÒµ£©¡¢×÷ÒµÆø¸Å£¨Í¶µÝ¶¨ÖÆÐÍ´¹ÂÚÓʼþ·Ö·¢Ä¾Âí£©¡¢Õ½Êõ£¨¹æ±Ü¼ì²â¡¢³£×¤¡¢ÏÂÁîÓë¿ØÖÆ£©¡¢ÊÖÒÕ£¨Îó²îʹÓã©¡¢Àú³Ì£¨·¢ËÍЯ´ø¶ñÒ⸽¼þµÄÓʼþ->Îó²îÎĵµ->½âÃÜÔËÐÐAgent TeslaÔ¶¿ØľÂí£©ÒÔ¼°ÆäʹÓõÄÍøÂç»ù´¡ÉèÊ©µÈ·½Ã涼ʮ·ÖÇкÏSWEED×éÖ¯µÄÌØÕ÷¡£ÓÉ´ËÎÒÃÇÍƶϣ¬´Ë´Î¹¥»÷Ô˶¯Ä»ºóÕߺܿÉÄÜÊÇÀ´×ÔÄáÈÕÀûÑǵÄSWEEDºÚ¿Í×éÖ¯¡£
Áù¡¢×ܽá
Æù½ñΪֹSWEEDºÚ¿Í×éÖ¯ÖÁÉÙÒÑ»îÔ¾ÁË4ÄêµÄʱ¼ä£¬´Ó¸Ã×éÖ¯½üÆڵĹ¥»÷¿ÉÒÔ·¢Ã÷£¬SWEED×îÏÈʹÓøü¾ßÓÐÕë¶ÔÐÔµÄÓʼþÄÚÈݺ͸ü¾ßÒÉ»óÐÔµÄÎĵµÎÊÌ⣬´Ó¶øÌá¸ßÊܺ¦ÕßÖÐÕеĸÅÂÊ¡£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab½«¸Ã×éÖ¯´Ë´ÎÐж¯TTPµÄÑо¿ÆÊÎöЧ¹ûÓëÒÔÍù¸ú½ø»òÅû¶µÄÏà¹Ø¹¥»÷Ðж¯ÌØÕ÷×ö±È¶Ôºó£¬»ñµÃµÄÏà¹ØÖ¤¾Ý¶¼¿ÉÅú×¢ÕâЩÑùÔÀ´×ÔSWEEDºÚ¿Í×éÖ¯¡£
SWEED×é֯ʹÓÃGuloaderÏÂÔØÆ÷Èö²¥µÄÔ¶³ÌľÂíÖÖÀàËäÈ»¶àÑù»¯£¬µ«Ö÷ÒªÕÕ¾ÉÒÔÆäÆ«ºÃµÄAgent TeslaΪÖ÷¡£´ÓÆäËùʹÓõÄTTPÀ´¿´£¬¸ÃºÚ¿Í×éÖ¯ÏÖÔÚ²¢Î´¾ß±¸ºÜºÃµÄ×ÔÑпª·¢ÄÜÁ¦¡£ÔÚ´ó¶¼ÇéÐÎÏ£¬½ö»á´ÓÍâÑóһЩÖ÷Á÷ºÚ¿ÍÍøÕ¾ÉϹºÖÃľÂíÌìÉúÆ÷ºÍ¼ÓÃܹ¤¾ßÀ´×÷Ϊ¹¥»÷ÎäÆ÷£¬ÀýÈçÔøʹÓõÄKazyCypterºÍ´Ë´ÎʹÓõÄGuloader¡£²»¹ý£¬¼´±ã¹¥»÷ÕßÔÚÊÖÒÕÄÜÁ¦ÉÏÏà¶Ô½ÏÈõ£¬µ«ÆäÔÚÉ繤¼¼ÇɺͶàÑù»¯¹¥»÷·½·¨µÄÓ¦ÓÃÃæÉÏÕվɽÏΪÊìÁ·µÄ¡£ÔÚ´Ë£¬½¨ÒéÓû§Ö»¹Ü×èÖ¹·¿ª²»Ã÷ȪԴµÄÓʼþÒÔ¼°¸½¼þÎļþ£¨À´×Ôδ֪·¢ËÍÕߵģ©£¬ÊµÊ±×°ÖÃϵͳ²¹¶¡£¬Ìá¸ßΣº¦Òâʶ£¬Ìá·À´ËÀà¶ñÒâÈí¼þ¹¥»÷¡£
Æß¡¢IOC
MD5 |
F97CFA6C3F1338B597768808FC1B2F00 |
B1941921571C2B6ED0C3BDA77E402001 |
DD82B2E488811E64BB9C039C441DB19C |
EC4CF91427DAC3AD29CD2A52B0789DC6 |
166FD7B0C74C60DCBC80BF335D712EA2 |
BCBCC89F237B22F21BDAE9E6555404A |
60147B91AB7B64B9BE27BD3422147E60 |
48408BBE8D9EE22D6BBB6820FCCC305F |
7DDA46F2D9008FAE016AFFF39E9C5801 |
A22A37E699C20D42753D35A94A75B365 |
C36C41EB6A34880459154334681C203A |
6BC92ACB050A2068EFF4842A1D360938 |
FB7ED44C2BAAA6F011F7BF51DE721BC4 |
58604AE63AEA84483C67980369958ACB |
312BFAFE6746645E72FCB84ECBFB023C |
779EB99965F1AAC12363632468DF7DCE |
DD49030C00EF3C2341BCBE4489DCEF63 |
IP |
167.114.85.125 |
URL |
https://drive.google.com:80/uc?export=download&id=1lmmu6kv5ep_wkm7hfyhdshru-y1n2pqv |
https://onedrive.live.com/download?cid=554BBD19BDD72613&resid=554BBD19BDD72613!156&authkey=AGIuaWEkkBxB_4o |
https://drive.google.com/uc?export=download&id=1W3ddZnmArVGhsecoWW5KcQAKPZ9OacLU |
https://share.dmca.gripe/iQakn267f3ZvpDN.bin |
http://167.114.85.125/go/Origin%20server%20ilyas_tTzYDNEGay108.bin |
°Ë¡¢²Î¿¼Á´½Ó
[1]https://www.fortinet.com/blog/threat-research/new-agent-tesla-variant-spreading-by-phishing
[2]https://www.fireeye.com/blog/threat-research/2017/10/formbook-malware-distribution-campaigns.html
[3]https://www.fortinet.com/blog/threat-research/new-infostealer-attack-uses-lokibot
[4]https://success.trendmicro.com/solution/1122912-nanocore-malware-information
[5]https://www.fortinet.com/blog/threat-research/remcos-a-new-rat-in-the-wild-2
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î800Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØϵͳÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£