½©Ê¬ÃÛÍø£ºÊ׿î¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦µÄÎïÁªÍø½©Ê¬ÍøÂç
Ðû²¼Ê±¼ä 2020-07-24Ò»¡¢¸ÅÊö
½üÆÚ£¬ÎÒÃǸú×Ùµ½Ò»ÆðÌرðµÄÎïÁªÍø½©Ê¬ÍøÂç¹¥»÷ÊÂÎñ¡£¸Ã¹¥»÷ÊÂÎñ½ü3¸öÔÂÀ´¶ÔÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹¡¢µÂ¹úµÈ¶à¸ö¹ú¼Ò·¢¶¯Á˽ÏΪƵÈԵĹ¥»÷¡£ÕâÅú¹¥»÷ËäÈ»Á÷Á¿²¢²»´ó£¬µ«ÔÚ×·×ÙµÄÀú³ÌÖз¢Ã÷£¬ÕâÅú¹¥»÷Öб£´æһЩVT²éɱÂÊΪ0µÄ¶ñÒâÑù±¾£¬Èçͼ1Ëùʾ£»²¢ÇÒ»¹·¢Ã÷¸Ã½©Ê¬ÍøÂçµÄÐí¶à½ÚµãÐÂÓ±µØ¼ÓÈëÁËÓÕ²¶¼°·´Ì½²âÄÜÁ¦¡£
ͼ1£ºVT¼ì²âÇéÐÎ
ÕâЩ½©Ê¬Ñù±¾¿ÉÒÔ½«ÊÜ¿Ø×°±¸µÄÖ¸ÎÆÐÅϢαװ³ÉÆäËû×°±¸µÄÖ¸ÎÆ£¨ÏÖÔÚ½ö·¢Ã÷DVRµÄαÔìÖ¸ÎÆ£¬ÍƲâºÚ¿Í¿ÉÒÔͨ¹ý¸üÐÂÄ£¿éÀ´Î±ÔìÆäËû×°±¸Ö¸ÎÆ£©¡£Ò»·½ÃæÒÔαÔì×°±¸Ö¸ÎƵķ½·¨À´ÓÕÆÈçShodanµÈÖÖÖÖÎó²îɨÃè²úÆ·£¬ÒԵִﷴ̽²âµÄÄ¿µÄ£»ÁíÍâÒ»·½ÃæÕâÖÖαÔìµÄ×°±¸Ö¸ÎÆÒ²±»Ê¹ÓÃÀ´×öÓÕ²¶£¬Èçαװ³ÉΪһ¸ö±£´æÎó²îµÄ×°±¸£¬ÒÔÃÛ¹ÞÓÕ²¶µÄ·½·¨ÓÕʹÆäËûºÚ¿Í·¢ËÍʹÓôúÂë¾ÙÐй¥»÷£¬´Ó¶ø»ñµÃÎó²îʹÓÃϸ½Ú¡£Òò´Ë£¬ÎÒÃǽ«´ËÀཀྵʬËù¹¹½¨µÄ¿ÉÒÔ¶ÔÎó²îºÍ¹¥»÷Ñù±¾¾ÙÐÐÓÕ²¶µÄ½©Ê¬ÍøÂçÃüÃûΪ¡°½©Ê¬ÃÛÍø¡±¡£
ͨ¹ýÎÒÃÇ×Ô¼ºµÄÎïÁªÍøÍþвÊý¾Ýƽ̨¼°Ïà¹ØÇ鱨µÄ½»Ö¯Ó¡Ö¤£¬·¢Ã÷¡°½©Ê¬ÃÛÍø¡±°üÀ¨Á½ÀàÑù±¾¡£µÚÒ»ÀàÊÇÓÕ²¶Ó뷴̽²â½Úµã£¬¶Ô¸ÃÑù±¾¾ÙÐжþ½øÖÆÎļþÏàËƶȱȶԷ¢Ã÷Æä¹¥»÷Ä£¿éºÍͨѶÐÒéÓëMoobot¼Ò×å¸ß¶ÈÏàËÆ£¬ÍƲâÓëMoobot¼Ò×åͬԴ£¬Òò´Ë½«ÕâÀàÐÂÐ͵ĶñÒâ³ÌÐòÃüÃûΪMoobot_Trap£¬Æä½è¼øÁËÃÛ¹ÞµÄÉè¼ÆÍ·ÄÔ£¬³ýÁËαװ×ÔÉíΪÆäËû×°±¸Í⣬»¹ÄÜͨ¹ýÓÕ²¶ÆäËü¹¥»÷ÕßµÄÎó²îʹÓÃÇ鱨Óë¹¥»÷Ñù±¾£¬À´ÎÞа¿ìËÙµÄÉý¼¶ÆäÎäÆ÷¿â£¬ÔöÇ¿×ÔÉíµÄ¹¥»÷Óë·ÀÓùÄÜÁ¦¡£µÚ¶þÀàÊǹ¹½¨ÊðÀíÍøÂçµÄ¶ñÒâÊðÀí½Úµã£¬ÎÒÃǽ«ÆäÃüÃûΪMal_Proxy£¬Í¨¹ýÏ·¢¶ñÒâÊðÀíÄ£¿é£¬¹¥»÷ÕßÄܹ»½«ÊÜѬȾ»ò¹ºÖõÄ×°±¸×÷ΪнڵãÀ´ÊðÀíí§ÒâÁ÷Á¿£¬½ø¶øÒ»Ö±Éú³¤×³´óÆäÊðÀíÍøÂç¡£¶ñÒâÁ÷Á¿¾ÊðÀíÍøÂçÖÐתÖÁTorÍøÂç»òÕæʵC&C£¬Ò»·½Ãæ¿ÉÒÔ×èÖ¹Ö±½Ó̻¶Éí·Ý£¬ÁíÒ»·½ÃæÒ²ÄܸüºÃµÄ´©Í¸Ä³Ð©ÍøÂç·À»ðǽµÄÏÞÖÆ¡£Í¨¹ýÏÖÔÚÕÆÎÕµÄÊý¾ÝÍŽáÎïÁªÍø½©Ê¬Ñù±¾µÄÆÊÎö£¬ÎÒÃÇ»¹Ô³öÁ˸ý©Ê¬ÍøÂçµÄ¹¥»÷Ä£×ÓÈçͼ2Ëùʾ£º
ͼ2£º¡±½©Ê¬ÃÛÍø¡°¹¥»÷Ä£×Ó
½øÒ»²½ËÝÔ´ºó£¬ÎÒÃÇ·¢Ã÷Õâ´Î¹¥»÷±³ºóµÄ×éÖ¯¿ÉÄÜͬʱÕÆ¿Ø×Å°üÀ¨Moobot¡¢LeeHozer¡¢Gafgyt±äÖÖÔÚÄڵĶà¸ö½©Ê¬ÍøÂç¡£¸Ã×éÖ¯²»µ«¾ßÓжàÖÖ0DayºÍNdayÎó²î¹¥»÷µÄÄÜÁ¦£¬»¹ÉÆÓÚͨ¹ýÊðÀíÍøÂç¡¢TorÍøÂçµÈÊðÀíÊÖÒÕÀ´ÔöǿͨѶµÄÄäÃû»¯£¬´Ó¶øÌá¸ßÆäC&C·þÎñÆ÷µÄÒþ²ØÐÔ¡£±¾ÎĽ«¶Ô²¶»ñµ½µÄ½©Ê¬Ñù±¾¡¢¶ñÒâÊðÀí³ÌÐò¼°Æä¹¥»÷Á´¾ÙÐÐÆÊÎö£¬²¢½øÒ»²½¶Ô±³ºóµÄºÚ¿Í×éÖ¯ÒÔ¼°ÕâЩ½©Ê¬ÍøÂç¼äµÄ¹ØÁªÐÔÕö¿ªÆÊÎöºÍ×·×Ù¡£
¶þ¡¢¹¥»÷×ÊÔ´ÆÊÎö
ÔÚ×·×ÙÀú³ÌÖУ¬ÎÒÃÇ·¢Ã÷¡°½©Ê¬ÃÛÍø¡±Óë¶à¸ö½©Ê¬ÍøÂç¼ä±£´æ½ÏÇ¿µÄ¹ØÁªÐÔ£¬°üÀ¨Moobot¡¢LeetHozerÒÔ¼°Gafgyt±äÖֵȵȡ£ÒÔMoobotºÍLeetHozerÁ½ÀཀྵʬÍøÂçΪÀý£¬proxy.2u0apcm6ylhdy7s.comÓòÃûÔø×÷ΪMal_ProxyµÄDownloader URLÒÔ¼°MoobotµÄC2£»elrooted.comÏà¹Ø×ÓÓòÃûÔøÓÃÓÚMal_ProxyµÄC2ÒÔ¼°Moobot¡¢LeetHozerµÄDownloader URL£¬ÀàËÆÓòÃû×ʲúÖØÓõÄÕ÷Ïó£¬Åú×¢Á½ÀཀྵʬºÜÓпÉÄÜÔ´×Ôͳһ×éÖ¯¡£ÎÒÃÇÕûÀíÁ˹ØÁªÑù±¾µÄÈö²¥ºÍÖ´ÐÐÁ÷³ÌÈçͼ3Ëùʾ£º
ͼ3£º¹ØÁªÑù±¾µÄÈö²¥ºÍÖ´ÐÐÁ÷³Ìͼ
ÆäÖУ¬MoobotÊÇÑù±¾ÊýÄ¿×î¶àÇÒÒ»Á¬»îÔ¾µÄÒ»Àཀྵʬ£¬ÎÒÃÇ·¢Ã÷µÄ¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦µÄMoobot_Trap¼´ÊÇÆäͬԴ¼Ò×塣ͬʱ£¬ÓÉÓÚMoobotÇ°ÆÚÈö²¥µÄÑù±¾Éæ¼°SocksºÍTor°æ±¾£¬Ò²¿ÉÄÜÓë´Ë´Î·¢Ã÷µÄ¶ñÒâÊðÀí³ÌÐòÓйء£LeetHozer½©Ê¬ÔòÊÇͨ¹ýSocks5ÐæźÍTor C&C½¨ÉèÅþÁ¬£¬ÇÒÓëMal_ProxyµÄ»îԾʱ¼äÏà½ü£¬ÍƲâLeetHozerÄÚÖõÄÊðÀí½ÚµãÁбíºÜ´ó¿ÉÄܾÍÊǺڿͿØÖƵĶñÒâÊðÀíÍøÂç¡£
ƾ֤ÏÖÔڵļà²âÇéÐΣ¬¸Ã×éÖ¯µ¥ÈÕÌᳫµÄ¹¥»÷´ÎÊýÔ¼ÔÚ100´Î×óÓÒ£¬±»¹¥»÷Ä¿µÄÔòÖ÷ÒªÂþÑÜÔÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹¡¢µÂ¹úµÈ¹ú¼Ò£¬ÆäÖÐÕë¶ÔÎÒ¹úµÄ¹¥»÷´ó¶à¼¯ÖÐÔÚн®¡¢ºÓÄÏ¡¢½ËÕ¡¢Ì¨ÍåµÈµØÇø£¬¹¥»÷¼Í¼ʾÀýÈçͼ4£º
ͼ4£º¹¥»÷¼Í¼
ͼ5£º¾³ÄÚÊܹ¥»÷IPλÖÃÂþÑÜͼ
±ðµÄ£¬¸Ã×éÖ¯»¹¾ß±¸ºÜÇ¿µÄÎó²îʹÓÃÄÜÁ¦£¬ÒÑÖªµÄÎäÆ÷¿â°üÀ¨½ñÄêÍ·Åû¶µÄLILIN DVR 0DayÎó²î¡¢HiSilicon DVR backdoor 0DayÎó²î£¬ÒÔ¼°Öî¶àÓ°Ïì¹æÄ£Æձ顢Σº¦ÑÏÖصÄNdayÎó²î£¬Ò»Ð©±»¹ûÕæµÄÎó²îPOCÒ²ÍùÍù»á±»Ñ¸ËÙ¼¯³É²¢Ó¦ÓÃÓÚÆäÎó²îɨÃèÄ£¿é£¬Ë¼Á¿µ½ºÚ¿Í»¹¿ÉÒÔͨ¹ýαװµÄÓÕ²¶½ÚµãÍøÂçÆäËü¹¥»÷ÕßµÄÇ鱨¼°Ñù±¾ÇéÐΣ¬ÎÒÃÇÔ¤¼ÆÆä¿ÉÓõÄÎó²î×ÊÔ´ºÜÊÇÖØ´ó¡£Í¨¹ýÏÖÔÚ¼à²â·¢Ã÷¼°Ïà¹Ø±¨¸æÖÐÅû¶µÄÎó²îʹÓÃÇéÐΣ¬¸Ã×é֯ʹÓõÄÎó²îÈç±í1Ëùʾ£º
±í1£ºÎó²îʹÓÃÁбí
ÔÚÓòÃû×ʲú·½Ã棬¸Ã×é֯ʹÓÃʱ¼ä½Ï³¤¡¢Æµ´Î½Ï¸ßµÄÓòÃûΪelrooted.com¡¢2u0apcm6ylhdy7s.comÒÔ¼°¶¥¼¶ÓòÃû.xyzϵIJ¿·ÖÓòÃû¡£ÕâÈýÀàÓòÃûϵÄ×ÓÓòÃûºã¾Ã±»ÆÊÎö²¢ÓÃÓÚÆäÑù±¾µÄDownloaderURL»òC&C¡£ÆäÖУ¬185.172.110.0/23Íø¶Î¹ØÁª×Å´ó×Ú½©Ê¬£¬ÀýÈç185.172.110.240¡¢185.172.110.224¡¢185.172.110.235µÈµÈ¡£
»ùÓÚÏÖÔÚÕÆÎÕµÄÇéÐΣ¬ÎÒÃÇ×ܽá¸Ã×éÖ¯µÄÌصãÈçÏ£º
¡ñ ¸Ã×éÖ¯¿ÉÄÜÕÆ¿Ø×Å°üÀ¨Moobot¡¢LeeHozer¡¢Gafgyt_variantÔÚÄڵĶà¸ö½©Ê¬ÍøÂ磬¹¥»÷Ä¿µÄ±é²¼È«Çò£¬ÇÒ½üÆÚÈÔÔÚ¼á³Ö¸ßƵÂʵĹ¥»÷Ô˶¯
¡ñ ÕÆÎÕ×ÅÊðÀíÍøÂç×ÊÔ´£¬ÓëÆäËüʹÓÃÊðÀíÍøÂçµÄ½©Ê¬±£´æÒ»¶¨¹ØÁª£¬ÇÒ¿ÉÄÜÔÚµØÏÂÂÛ̳³öÊÛÊðÆÊÎö¼ûȨÏÞ
¡ñ ÉÆÓÚ0DAY¡¢NDAYÎó²îʹÓÃ
¡ñ ÉÆÓÚʹÓÃSocks5ÊðÀí¡¢TorÍøÂçµÈC&CÒþ²ØÊÖÒÕ
¡ñ Ñù±¾É¨ÃèÄ£¿éÂþÑÜÔÚ¶àÖÖÑù±¾ÖÐÐ×÷ɨÃ裬ɨÃèЧÂʸß
¡ñ Ñù±¾¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦£¬Äܹ»²¶»ñÆäËüºÚ¿ÍµÄ¹¥»÷Ç鱨
¡ñ ¾ß±¸Ò»¶¨µÄÇå¾²¶Ô¿¹ÄÜÁ¦£¬Ñù±¾µü´ú¸üп졢ÃâɱÐԺã¬ÆµÈÔÌæ»»UPX»ÃÊý¿Ç¡¢¸üÐÂÃô¸ÐÐÅÏ¢¼ÓÃÜËã·¨¼°Í¨Ñ¶ÐÒéµÈ
Èý¡¢¹¥»÷ÑùÌìÖ°Îö
ÓÉÓÚ¸Ã×éÖ¯ÓµÓÐ×ÅÁ½Àཀྵʬ½Úµã£¨ÓÕ²¶Ó뷴̽²â½Úµã¡¢ÊðÀí½Úµã£©£¬ÎÒÃÇÒ²½«Öصã¶ÔÕâÁ½Àà½ÚµãÏà¹ØµÄÑù±¾¾ÙÐÐÆÊÎö¡£µÚÒ»ÀàÑù±¾ÎªMoobot_Trap£¬Æäαװ³ÉΪDVRʵÏÖÓÕ²¶Óë·´Õì²âµÄ¹¦Ð§£»µÚ¶þÀàÑù±¾ÎªÊµÏÖ·´×·×Ù²¢ÓëTorÍøÂç¶Ô½ÓµÄSocket5ÊðÀí½Úµã£¬°üÀ¨¶ñÒâÑù±¾Mal_ProxyºÍLeeHozer¡£
3.1Moobot_TrapÆÊÎö
Moobot_Trap½©Ê¬ÊÇÒ»¸ö¹¦Ð§ÍêÕûµÄ½©Ê¬³ÌÐò£¬Æ书Ч°üÀ¨ÓÕ²¶¼à²âÒÔ¼°·´Ì½²â¡¢Îó²îɨÃè¡¢DDos¹¥»÷¡£Í¨¹ýÑù±¾µÄÏàËƶȱȶԣ¬ÎÒÃÇ×îÖÕÈ·¶¨Moobot_TrapÓëMoobot¼Ò×åͬԴ£¬Æä¹¥»÷´úÂëºÍͨѶÐÒé¾ßÓи߶ȵÄÏàËÆÐÔ¡£Moobot½©Ê¬×Ô2019ÄêÏ°ëÄê×îÏÈ»îÔ¾£¬Æäºã¾ÃʹÓÃÎó²î¾ÙÐÐÀ©É¢ÓëѬȾ£¬¸Ã½©Ê¬½ÓÄÉÒ»ÖÖÊèɢɨÃèµÄ·½·¨¾ÙÐй¥»÷£¬¼´²»½«ËùÓÐÎó²îɨÃè·½·¨¼¯³ÉÔÚµ¥¸öÑù±¾ÄÚ£¬¶øÊǽ«ÖÖÖÖÎó²îÂþÑÜÔÚ¶àÀàBotÑù±¾ÖУ¬ÒÔÌá¸ßɨÃèЧÂʽµµÍ±»·¢Ã÷µÄ¼¸ÂÊ¡£Moobot_TrapÒ²ÑÓÐø´ËÖÖÌØÕ÷£¬µ«Æä×îÖ÷Òª¸Ä±äÊǼÓÈëÓÕ²¶ºÍ·´Ì½²âÄÜÁ¦£¬ÆäÔÚÊÜѬȾװ±¸ÉÏ¿ªÆôÒ»¸ömini_httpd·þÎñ£¬²¢Î±×°³ÉDVR×°±¸£¬Ò»·½ÃæÓÃÓÚÓÕ²¶Îó²îºÍ¹¥»÷Ñù±¾£¬Ò»·½Ãæ¿ÉÒÔÓÕÆÖÖÖÖ×°±¸Ì½²âƽ̨¡£
ÏêϸÆÊÎöÑù±¾Èç±í2Ëùʾ£º
±í2£ºÑù±¾ÐÅÏ¢
3.1.1 ÓÕ²¶Ó뷴̽²âÄ£¿éÆÊÎö
¸ÃÄ£¿éΪÁËʵÏÖÓÕ²¶¹¦Ð§£¬½«×Ô¶¯¿ªÆôWEB·þÎñ¶Ë¿Ú(80¡¢8080¡¢8000)ÓëÊý¾Ý¿âHSQLµÄ·þÎñ¶Ë¿Ú(9002)£¬Ò»µ©ÊÕµ½Íâ½çµÄhttpÐÒéµÄɨÃè̽²â£¬±ã»á·µ»ØαװµÄ×°±¸Ö¸ÎÆ¡£ÏÖÔÚ·¢Ã÷µÄMoobot_Trap½«ÊÜ¿Ø×°±¸Î±×°³ÉDVR×°±¸£¬²»¹ýºÚ¿Í¿ÉÒÔͨ¹ý¸üÐÂÄ£¿éÀ´±ä»»Ö¸ÎÆÐÅÏ¢¡£±ðµÄ¸ÃÄ£¿é»¹Äܹ»¼à¿ØÍâ½ç¶Ô¸Ã×°±¸·¢¶¯µÄ¹¥»÷²¢½«¹¥»÷ÐÅÏ¢Éϱ¨¸øºÚ¿ÍÔ¤ÏÈ°²ÅŵÄC&C·þÎñÆ÷ÉÏ£¬ÒԴ˺ڿͿÉÒÔ»ñÈ¡µ½Îó²îɨÃèÌØÕ÷ºÍ¹¥»÷Ñù±¾¡£
( 1 ) ·´Ì½²â£ºÏÖÔÚ×îΪÖ÷Á÷µÄ×°±¸Ì½²âÊÖÒÕÒÀÈ»ÊÇ»ùÓÚÖ¸ÎÆʵÏֵģ¬ÈçShodan¡¢ZoomEye¡¢CensysÒÔ¼°ÖÖÖÖÎó²îɨÃè²úÆ·£¬Òò¶øMoobot_Trap»¹ÌṩһÀàÄÜÁ¦¾ÍÊǸøɨÃèÔ´ÌṩαÔìµÄÐÅÏ¢£¬ÒÔÓÕÆɨÃèÒýÇæ×öÍÉ»¯ÎóµÄ¾öÒé¡£Ò»ÔòMoobot_Trap¿ÉÒÔ½«×ÔÉíαװ³ÉΪһ¸ö¼áÈçÅÌʯµÄ×°±¸£¬ÈÃɨÃèÒýÇæÒÔΪÕâÊÇһ̨Çå¾²µÄ×°±¸¶ø½µµÍ±»·¢Ã÷µÄ¼¸ÂÊ£»Ò»ÔòMoobot_TrapÒ²¿ÉÒÔ½«ÈëÇÖµÄ×°±¸Î±×°³ÉΪһ¸ö±£´æйûÕæÎó²îµÄ×°±¸£¬Æä¿ÉÒÔÆðµ½ÓÕ²¶Ò»Ð©Î´¹ûÕæµÄÎó²îʹÓôúÂë¡£ÔÚÎÒÃÇÄ¿½ñËù·¢Ã÷µÄ½©Ê¬ÍøÂçÖУ¬ÆäÖб»ÈëÇÖµÄÈκÎһ̨װ±¸¶¼½«±»Ê¶±ð³ÉΪһ¸öÌṩmini_httpd·þÎñµÄDVR×°±¸(ÓÃÓÚÓÕ²¶Mini_httpd1.19Ïà¹ØµÄÎó²îʹÓôúÂë)¡£
ͼ6£ºÉ¨ÃèÖ¸ÎÆʾÀý
Mini_httpdÊÇÒ»¿î΢Ð͵ÄHttp·þÎñÆ÷£¬ÔÚÕ¼ÓÃϵͳ×ÊÔ´½ÏСµÄÇéÐÎÏ¿ÉÒÔ¼á³ÖÒ»¶¨Ë®Æ½µÄÐÔÄÜ£¬Òò´ËÆձ鱻ÖÖÖÖÎïÁªÍø×°±¸£¨Â·ÓÉÆ÷£¬½»Á÷Æ÷£¬ÉãÏñÍ·µÈ£©×÷ΪǶÈëʽ·þÎñÆ÷ʹÓ᣶ø°üÀ¨»ªÎª¡¢º£¿µÍþÊÓ¡¢zyxel¡¢Ê÷Ý®Åɵȳ§É̵ÄÆìÏÂ×°±¸¶¼Ôø½ÓÄÉMini_httpd×é¼þ£¬Ó°Ïì¹æÄ£ºÜ¹ã£¬Ïà¹ØÎó²î¿ÉÄÜÓ°ÏìÈ«ÇòÊý°ÙÍò×°±¸¡£ÒÔÊǺڿʹËÀàÐÂÓ±µÄÊÖÒÕ˼Ð÷ÔËÓÃÒ²ÐèÒªÒýÆðÎÒÃÇ×ã¹»µÄÖØÊÓ¡£
( 2 ) ÓÕ²¶£ºÎÒÃÇÖªµÀ£¬ÏÖʵÍøÂçÖб£´æ´ó×ÚÈä³æºÍ½©Ê¬ÍøÂ磬ËûÃÇÓÀ²»ÖÐÖ¹µØɨÃè̽²âÍøÂç×ÊÔ´£¬Í¬Ê±ËûÃÇÒ²ÔÚʵʱ¸üÐÂÆä̽²âÌØÕ÷£¬ÈçºÚ¿ÍÃǵÄ0day/NdayÎó²îɨÃèÌØÕ÷¡£¶ø´ó²¿·Ö¿ÉÓÃÓÚÈä³æºÍ½©Ê¬Èö²¥µÄÎïÁªÍøÎó²î¶¼¼¯ÖÐÔÚHTTP·þÎñµÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î(Õ¼±È¸ü¶àµÄTelnetÀ๥»÷ÒÔÈõ¿ÚÁîΪÖ÷£¬´Ë´¦²»±í)¡£¸Ã¶ñÒâÄ£¿éÕýÊÇÒÔ»ñÈ¡´ËÀàÎó²î¹¥»÷ÐÐΪΪĿµÄ£¬ÔÚÆô¶¯¶Ë¿ÚÉϼàÊÓwget¡¢tftp¡¢/bin/shÏÂÁÍøÂçÎó²îÐÅÏ¢ºÍÈö²¥Ñù±¾¡£ÏÂͼÊÇÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄPayload£º
ͼ7£ºÉ¨ÃèPayloadʾÀý
µ±Ä³Ð©¹¥»÷Õß¡¢Èä³æ»òÕß½©Ê¬³ÌÐòÕë¶ÔÊÜѬȾװ±¸¾ÙÐÐÎó²îɨÃè»ò´úÂëÖ²Èëʱ£¬Ò»µ©¹¥»÷PayloadÖÐЯ´øÓÐÖ¸¶¨ÃüÁÈçͼÖеÄwget£©Ê±£¬¸ÃÊý¾Ý¼´±»ÊÓΪÓÐÓÃÇ鱨±»×ª·¢ÖÁMoobot_TrapºÚ¿ÍµÄC&C¡£Í¨¹ýÕâÖÖÀàËÆÃ۹޵ļà²âÊÖÒÕ£¬ºÚ¿Í¿ÉÒÔ²¶»ñµ½´ó×ÚÎó²îʹÓôúÂ룬ÉõÖÁÊÇ0dayÎó²î£¬¸ü½øÒ»²½£¬»¹Äܹ»Í¨¹ýÈö²¥µÄ½©Ê¬ÑùÔÀ´ÌáÈ¡ºÍÑо¿¸ü¶àÓмÛÖµµÄÎó²î»òÊÖÒÕ¡£
´ÓÉÏÃæµÄÆÊÎöÎÒÃÇ»¹¿ÉÒÔ¿´³ö£¬ÈôÊǺڿÍ×éÖ¯¾ß±¸×ã¹»µÄÊÖÒÕʵÁ¦£¬»¹ÄÜͨ¹ý²¶»ñµÄɨÃèÐÅÏ¢»ñÈ¡µ½ÆäËü½©Ê¬ÍøÂçµÄDownload IP»òC&C²¢½øÒ»²½ÊµÑéÈëÇÖ¡£Í¨³£ÇéÐÎϹ¥»÷ÕßµÄÐí¶à·þÎñÆ÷¶¼À´×ÔÎó²îÈëÇÖ¡¢Telnet±¬ÆƵȵȣ¬ÄÇôÕâЩ·þÎñÆ÷×ʲú¾ÍºÜÓпÉÄܱ»ºÚ¿Í×éÖ¯¶þ´ÎÈëÇÖ£¬Ô¿ØÖÆÕßÓµÓеÄÈ⼦×ÊÔ´Ò²¿ÉÄܱ»¹²Ïí»ò½ÓÊÜ¡£ÏÂÎÄÎÒÃǽ«¶ÔMoobot_Trap¾ÙÐÐÆÊÎöÓëÐðÊö¡£
Moobot_TrapÊ×ÏÈ»áÔÚ80¡¢8080¡¢8000¡¢9002ËÄÖֶ˿ÚÖÐËæ»úÑ¡ÔñÆäÒ»½¨Éè·þÎñ¶Ë¼àÌý£¬¿ÉÒÔÒÔΪºÚ¿ÍµÄÄ¿µÄ¾ÍÊÇÍøÂçÕâËÄÀà¶Ë¿ÚµÄɨÃèÊý¾Ý¡£
ͼ8£ºÑ¡Ôñ¶Ë¿Ú½¨Éè¼àÌý
µ±¹¥»÷ÕßɨÃèÏìÓ¦¶Ë¿ÚÇÒ·¢Ë͵ÄÇëÇóÊý¾Ý°üÀ¨wget¡¢tftp¡¢/bin/shÏÂÁîʱ£¬Moobot_Trap»á·µ»ØαÔìµÄmini_httpd·þÎñÆ÷ÐÅÏ¢²¢½«ÇëÇóÊý¾Ýת·¢¸øC&C£¬Ö®ºó¹Ø±ÕÓë¿Í»§¶ËµÄÅþÁ¬£¨Ä£ÄâHTTPÎÞÅþÁ¬ÇëÇ󣩡£
ͼ9£º·µ»Ømini_httpd·þÎñÆ÷ÐÅÏ¢
ÅþÁ¬C&CÔòÊǼÓÃÜ´æ´¢ÔÚÄÚ´æÖУ¨Ãô¸ÐÐÅÏ¢¼ÓÃܽ«ÔÚºóÐøÕ½ÚÆÊÎö£©¡£
ͼ10£º×ª·¢Êý¾Ý
Ä£ÄâÒ»´ÎɨÃèµÄÏÖÕæÏàÐΣ¬µ±¹¥»÷ÕßÕë¶ÔÓÕ²¶½Úµã¾ÙÐÐÎó²îɨÃèʱ£¬½»»¥Á÷Á¿Êý¾Ý°üÈçͼ11Ëùʾ£º
ͼ11£º½»»¥Êý¾Ý°ü
Moobot_Trap¼ì²âµ½wgetÏÂÁîʱ£¬»áʶ±ðΪÓÐÓÃÇ鱨£¬²¢½«É¨ÃèÐÅÏ¢ÒÔÈçϵÄÐÎʽÉϱ¨ÖÁC&C¡£
ͼ12£ºÉϱ¨É¨ÃèÊý¾Ý
Éϱ¨Êý¾ÝÃûÌÃÈç±í3Ëùʾ£º
±í3£ºÉϱ¨Êý¾ÝÃûÌÃ
3.1.2 Ãô¸ÐÐÅÏ¢¼ÓÃÜ
¼ÓÃÜÊý¾Ý²¢·ÇÕû¶Î´æ´¢ÔÚ´úÂëÖУ¬¶øÊǽ«×Ö·û´®³£Á¿Ö§½â³É¶à¸ö²¿·Ö´æ·ÅÔÚrodataºÍtext¶Î£¬ÕâÒ²»á¸øÆÊÎöÊÂÇéÔì³ÉÒ»¶¨µÄ×ÌÈÅ¡£
ͼ13£º¼ÓÃÜ×Ö·û´®
Ïêϸ¼Ó½âÃÜËã·¨ÓëMiraiÏàͬ£¬ÃÜԿΪ0x0deadbeef£¬ËùÓÐ×Ö·û´®µÄʹÓö¼ÊÇÓÃʱ½âÃÜ£¬ÓÃÍê¼´»Ö¸´¼ÓÃÜ£¬¼Ó½âÃÜËã·¨Èçͼ14Ëùʾ£º
ͼ14£º¼Ó½âÃÜËã·¨
3.1.3 ¶Ë¿ÚɨÃèºÍÐÅÏ¢Éϱ¨
MoobotɨÃèÄ£¿é½ÓÄÉÈ«ÍøɨÃ裬²¢½«É¨ÃèЧ¹ûÉϱ¨Reporter£¬×îºóÓÉLoaderÕë¶ÔÎó²î×°±¸Ö²ÈëÑù±¾£¬ÀúÊ·ÉÏÆä±£´æ¶àÖÖɨÃè°æ±¾£º
( 1 ) TCP:23,26 (Telnet)
( 2 ) TCP:34567 (DVRIP)
( 3 ) TCP:4567(TVT)
( 4 ) TCP:5555 (ADB)
( 5 ) TCP:80,81,82,83,85,88,8000,8080,8081,9090,60001 (HTTP)
¹ØÓÚɨÃèhttp·þÎñµÄÑù±¾£¬ÈôÊǼì²âµ½ÈçÏÂHttp ServerÔò»áÉϱ¨Reporter¡£Ñù±¾½âÃܺóÓÃÓÚ¼ì²âµÄ·þÎñÆ÷×Ö·û´®Ê¾ÀýÈçÏ£º
"Server: JAWS/1.0."
"Server: DWS."
"URL=/view/viewer_index.shtml?id=."
"Server: thttpd/2.25b PHP/20030920."
"Server: Boa/0.93.15."
ÕâЩ²î±ðɨÃèÖÖÀàµÄÑù±¾µÄDownloaderURLͨ³£Ò²ÊÇÒÔ¶ÔÓ¦Îó²î×°±¸µÄÃû³ÆÀ´ÃüÃûºÍ·ÖÀ࣬ÀýÈ磺
±í4£ºDownloadURLÌصã
¹ØÓÚɨÃèʹÓõı¬ÆÆƾ֤£¬³ýÁ˲¿·ÖÄÚÖÃÁÐ±í£¬»¹¿ÉÒÔÏòC&C·¢ËÍÇëÇóÖ¸ÁîÒÔ»ñÈ¡±¬ÆÆÃû³ÆÃÜÂëÁÐ±í£¬ÇëÇóÖµ²î±ð¶ÔÓ¦²î±ðµÄ±¬ÆÆ×éºÏÖµ¡£
ͼ15£º·µ»Ø±¬ÆÆ×éºÏ
µ±É¨Ãè·¢Ã÷¿ÉÓÃÎó²î×°±¸Ôò»áÏòReporterÉϱ¨×°±¸ÐÅÏ¢¡£
ͼ16£ºÉϱ¨×°±¸ÐÅÏ¢
±í5£ºÉϱ¨×°±¸ÐÅÏ¢ÆÊÎö
3.1.4 ͨѶÐÒé¼°¹¥»÷Ä£¿é
Moobot_TrapÔÚͨѶÐÒé·½ÃæÓë֮ǰµÄ°æ±¾ÓÐËùת±ä£¬Àֳɽ¨ÉèÅþÁ¬ºó£¬Ê×ÏÈ»áÏò¿ØÖƶ˷¢ËÍÉÏÏß°ü¡£
ͼ17£ºÉÏÏßÊý¾Ý°ü
±í6£ºÉÏÏßÊý¾Ý°üÆÊÎö
Ö®ºó¾àÀë60ÃëÑ»·Ïò¿ØÖƶ˷¢ËÍÐÄÌø°ü[0x00 0x00]£¨Àο¿Öµ£©£¬¿ØÖƶËÔò¾àÀë20ÃëÏò½©Ê¬³ÌÐò»Ø°ü[0x33 0x66 0x99]£¨Àο¿Öµ£©¡£
ͼ18£ºÐÄÌøÊý¾Ý°ü
µ±¿ØÖƶ˷¢Ë͵ÄÖ¸ÁîÇ°Èý×Ö½Ú·Ç[0x33 0x66 0x99]ʱ£¬Ôò½øÈë¹¥»÷ģʽÆÊÎöÖ¸Áî¡£
ͼ19£ºÆÊÎö¹¥»÷
¹¥»÷Ä£¿é·½Ã棬Moobot_TrapÑÓÓÃÁËMiraiµÄ¹¥»÷ÐÎʽ£¬Ñù±¾°üÀ¨7ÖÖ¹¥»÷ģʽ¡£
ͼ20£º¹¥»÷ģʽ
¹¥»÷Ö¸ÁîÊý¾Ý°üÈçͼ21Ëùʾ£º
¶ÔÓ¦½á¹¹ÌåʾÒâÈçÏ£º
type Attack struct {
Duration uint32
Type uint8
Targets counts uint8
Targets map[uint32]uint8
Flags counts uint8
Flags map[uint8]string
}
±í7£º¹¥»÷Ö¸ÁîÆÊÎö
3.2Mal_ProxyÆÊÎö
Mal_ProxyÊǺڿÍ×éÖ¯ÓÃÓÚ¹¹½¨ÊðÀíÍøÂçµÄ½¹µãÄ£¿é£¬Æä¿ÉÒÔÌṩÊðÀí·þÎñÒÔ¼°ÐÅÏ¢Éϱ¨¹¦Ð§¡£¸ÃÄ£¿éÇáÓ¯ÎÞа£¬¹¥»÷Õß¿ÉÒÔͨ¹ý²ÎÊýÉèÖÃÊðÀí·þÎñ£¬³ÌÐòÆô¶¯ºóÊÜ¿Ø×°±¸¼´×÷ΪÊðÀí½Úµã¼ÓÈëµ½ÊðÀíÍøÂçÖУ¬ÎªºÚ¿ÍµÄ¶ñÒâÔ˶¯ÌṩÒþÄä±£»¤¡£
Mal_Proxy±£´æÁ½¸ö°æ±¾£¬V1°æ±¾C2Ϊcest4.elrooted.com£¬V2°æ±¾C2Ôò°üÀ¨hxarasxg.hxarasxg.xyzºÍda.elrooted.com¡£ÆäÖÐV2°æ±¾ÔöÌíÁ˲ÎÊýÆô¶¯¡¢Socks5ÐÒéÈÏ֤ģʽ¼°UPX¿Ç£¬²¢ÐÞ¸ÄÁ˿ǵĻÃÊý£¨ÏÖʵ»ÃÊý0xBC7A3331£©ÒÔ¶Ô¿¹¾ç±¾ÍÑ¿Ç¡£Mal_ProxyÑù±¾¾ù±»°þÀë·ûºÅÇÒδÁôÏÂÈκÎÓëÊðÀíÏà¹ØµÄ×Ö·û´®¡¢ÌØÕ÷µÈÐÅÏ¢£¬ËµÃ÷¸Ã×éÖ¯¾ß±¸Ò»¶¨µÄÇå¾²¶Ô¿¹ÂÄÀú£¬ÓÐÒâ¸øÆÊÎöÖ°Ô±ÖÆÔì¸ü¶àµÄÄÑÌ⣬ҲʹµÃMal_Proxy¼á³ÖÁ˺ÜÊǺõÄÃâɱÐÔ¡£
ºóÎÄÒÔV2°æ±¾ÎªÀý¾ÙÐÐÏêϸÆÊÎö£¬²¢»á´©²åһЩV1°æ±¾µÄ±ÈÕÕ£¬Ñù±¾ÐÅÏ¢Èç±í8Ëùʾ£º
±í8£ºÑù±¾ÐÅÏ¢
3.2.1 ²ÎÊýÆô¶¯Ä£Ê½
Mal_Proxy V1°æ±¾²¢²»¾ß±¸²ÎÊýÆô¶¯Ä£Ê½£¬ÆäÊðÀí¶Ë¿ÚºÅÊÇͨ¹ýʱ¼ä´ÁÅÌËã³öµÄËæ»úÖµ»ñµÃ£¨¶Ë¿Ú¹æÄ££º0ÖÁ65535£©¡£
ͼ22£ºV1°æ±¾»ñÈ¡Ëæ»ú¶Ë¿Ú
Mal_Proxy V2°æ±¾ÔòÌí¼ÓÁ˲ÎÊýÆô¶¯Ä£Ê½£¬´Ó¶ø¿ÉÒÔÔ½·¢ÎÞаµÄÉèÖÃÊðÀí¶Ë¿ÚÒÔ¼°Socks5ÐÒéµÄÓû§Ãû/ÃÜÂëÈÏ֤ģʽ¡£²ÎÊýÆô¶¯¹²°üÀ¨ÈýÖÖÏÂÁî²ÎÊý£¬ÏÂÁîÐÎʽΪ£º
Mal_Proxy -pport -u user -P password
ÆäÖÐ-pΪָ¶¨µÄÊðÀí°ó¶¨¶Ë¿Ú£¬-u¡¢-PΪÉèÖÃÓû§Ãû/ÃÜÂëÈÏ֤ģʽ£¬Èç²»ÉèÖÃĬÒÔΪÎÞÐèÈÏÖ¤·½·¨¡£
V2°æ±¾ÎÞ²ÎÆô¶¯»áĬÈÏ°ó¶¨ÍâµØ28105¶Ë¿Ú£¬²¢ÒÔÎÞÐèÈÏÖ¤µÄ·½·¨Ö´ÐгÌÐò¡£
ͼ23£º²ÎÊýÆô¶¯
³ÌÐòÖ´Ðкó»áÔÚ²î±ð½×¶ÎFork¶àỊ̈߳¬²¢Í¨¹ý²î±ðÏß³ÌÖ´ÐÐÏìÓ¦µÄ¹¦Ð§Ä£¿é£¬°üÀ¨ÐÅÏ¢Éϱ¨Ä£¿éºÍÊðÀí·þÎñÄ£¿é¡£
3.2.2 ÐÅÏ¢Éϱ¨Ä£¿é
V2°æ±¾µÄÐÅÏ¢Éϱ¨Ä£¿éͬÑùÇø·ÖÓвκÍÎÞ²ÎÁ½ÖÖģʽ£¬ÏêϸÉϱ¨ÐÅϢͬ²ÎÊýÄÚÈÝÓйء£¶øV1°æ±¾½öÓÐÒ»ÖÖÉϱ¨·½·¨£¬¼´V2°æ±¾µÄÎÞ²Îģʽ¡£
ͼ24£ºV1°æ±¾ÐÅÏ¢Éϱ¨
ͼ25£ºV2°æ±¾Á½ÀàÐÅÏ¢Éϱ¨·½·¨
ÎÞ²ÎÉϱ¨Êý¾Ý°ü£º
ͼ26£ºV2°æ±¾ÎÞ²ÎÉϱ¨Êý¾Ý°ü
ÓвÎÉϱ¨Êý¾Ý°ü£º
ͼ27£ºV2°æ±¾ÓвÎÉϱ¨Êý¾Ý°ü
±í9£ºV2°æ±¾Éϱ¨Êý¾Ý°üÆÊÎö
³ÌÐòÿ¾àÀë300ÃëÑ»·Ïòhxarasxg.hxarasxg.xyz:38129·¢ËÍÐÄÌø°üÉϱ¨²ÎÊýÐÅÏ¢¡£Í¬Ê±³ÌÐòÄ£ÄâÁËÓòÃûÅÌÎÊÇëÇó£¬Í¨¹ý¹«¹²·þÎñDNS£¨8.8.8.8£©À´×ÔÐÐÆÊÎöIP£¬´Ó¶ø±ÜÃâhosts»òresolv.conf±»¸Ä¶¯»òЮÖÆÔì³ÉµÄDNSÅÌÎÊÒì³£¡£
ͼ28£ºV2°æ±¾ÐÅÏ¢Éϱ¨
3.2.3 ÊðÀí·þÎñÄ£¿é
ÊðÀíÄ£¿éÏß³ÌÊ×ÏÈ»á°ó¶¨¼àÌýÍâµØÖ¸¶¨¶Ë¿Ú£¨ÊðÀí¶Ë¿Ú£©£¬²¢Í¨¹ýlisten¡¢acceptµÈ²Ù×÷º¯ÊýÀ´½¨Éè¼àÌý²¢ÎüÊÕ¿Í»§¶ËÇëÇó¡£
ͼ29£º°ó¶¨¼àÌýÊðÀí¶Ë¿Ú
Ö®ºóÊðÀíÄ£¿é»á½øÒ»²½Õë¶Ô¿Í»§¶ËµÄÇëÇó¾ÙÐÐÅжϺÍУÑ飬ÀýÈçÕë¶Ô0x05 0x01 0x00 0x03ÄÚÈݵÄУÑ飬ʵÔòΪSocks5ÐÒéÈÏÖ¤½×¶ÎµÄÎÕÊÖÀú³Ì£¬½øÒ»²½ÆÊÎöºó¿ÉÒÔÈ·ÈϸÃÄ£¿éÊÇ»ùÓÚSocks5ÐÒéµÄ¶ñÒâÊðÀí³ÌÐò·þÎñ¶Ë¡£
ͼ30£ºSocks5ÐÒéУÑé
3.2.4 Socks5ÐÒéÏÈÈÝ
Socks5ÊÇÒ»ÖÖÍøÂç´«ÊäÐÒ飬Ö÷ÒªÓÃÓÚ¿Í»§¶ËÓëÍâÍø·þÎñÆ÷Ö®¼äͨѶµÄÖÐÐÄת´ï¡£´ËÐÒé²¢²»ÈÏÕæÊðÀí·þÎñÆ÷µÄÊý¾Ý´«Êä»·½Ú£¬¶øÊÇÔÚ C/S Á½Í·Õæʵ½»»¥Ö®¼ä£¬½¨ÉèÆðÒ»Ìõ´Ó¿Í»§¶Ëµ½ÊðÀí·þÎñÆ÷µÄÊÚÐÅÅþÁ¬¡£¿Í»§¶ËÊ×ÏÈÐèÒªºÍ·þÎñ¶Ë¾ÙÐÐÎÕÊÖÈÏÖ¤£¬¿ÉÒÔ½ÓÄÉÓû§Ãû/ÃÜÂëÈÏÖ¤»òÕßÎÞÐèÈÏÖ¤·½·¨£¬ÎÕÊÖÀֳɺ󼴿ɽøÈëÊý¾Ý´«Êä½×¶Î£¬ÐÒéÔÀíÈçͼ31Ëùʾ£º
ͼ31£ºSocks5ÐÒéÔÀí
ÒÔij´Îͨ¹ýSocks5ÊðÀí´«ÊäµÄ¹¥»÷Ö¸ÁîΪÀý£¬ÔÚÒѾ½èÖúÊðÀíÐÒ齨ÉèÅþÁ¬µÄÇéÐÎÏ£¬C&CÏ·¢µÄ¹¥»÷Ö¸Áî¾ÊðÀíÍøÂ磨54.188.198.118:9090£©ÖÐתºó´«Êäµ½Bot£¬´Ëʱ²¶»ñµÄÁ÷Á¿ÊÇÎÞ·¨»ñÈ¡µ½ÕæʵC&CµØµãµÄ£¬ÔÚÒ»¶¨Ë®Æ½ÉÏ¿ÉÒÔµÖ´ïÒþ²ØC&CµÄÄ¿µÄ¡£
ͼ32£ºÊðÀí´«Êä¹¥»÷Ö¸ÁîÁ÷Á¿
´ÓÁíÒ»¸ö½Ç¶È˼Á¿£¬Socks5ÐÒéËäÈ»ÔÚ´«Êä½×¶Î¾ßÓÐÒþ²ØC&CµÄЧ¹û£¬µ«Æä×÷Ϊ͸Ã÷ÊðÀí²¢²»¾ß±¸¼ÓÃܹ¦Ð§£¬ÈÏÖ¤ºÍÅþÁ¬½×¶ÎÒ²²¢²»Çå¾²¡£ÈôÊÇÄܹ»Ðá̽ÐÉÌÎÕÊֽ׶εÄÊý¾ÝÁ÷Á¿£¬ÒÀÈ»Äܹ»ÆÊÎö²¢»ñÈ¡µ½Ñù±¾ÅþÁ¬µÄÕæʵC&C¡£»ùÓÚÕâЩԵ¹ÊÔÓÉ£¬Ò»Ð©ºÚ¿Í»¹»á½øÒ»²½Ê¹ÓÃTor ÍøÂçÀ´ÔöÇ¿ÒþÄäÐÔ£¬ÓÉÓÚTorÍøÂçÿһÌõͨѶÁ´Â·¶¼ÓÉÈô¸ÉËæ»úÑ¡È¡µÄTor½Úµã×é³É£¬ÇÒͨѶÊý¾Ý¾ÙÐÐÁ˶à²ã¼ÓÃÜ£¬×ÝÈ»»ñÈ¡µ½Tor C&CÒ²ÄÑÒÔËÝÔ´µ½Òþ²ØµÄÕæʵ·þÎñÆ÷£¬ÒÔÊÇÔÚÒþÄäÐÔ·½ÃæTorÍøÂçÊǸüºÃµÄÑ¡Ôñ¡£ËäÈ»TorÍøÂçÒ²ÓÐÆäÎó²î£¬ÓÉÓÚÅþÁ¬µÄÖØ´óÐÔ£¬TorÍøÂçµÄ´«ÊäËÙÂʺÍÀÖ³ÉÂÊÍùÍùÄÑÒÔ°ü¹Ü¡£×ۺ϶øÑÔ£¬Ë¼Á¿µ½ÏÖÕæÏàÐÎÖмàÌýÊÜ¿Ø·þÎñÆ÷ÊðÀí¿Í»§¶Ëµ½ÊðÀí·þÎñÆ÷µÄËùÓÐÁ÷Á¿ÊǺÜÊÇÄÑÌâµÄ£¬ÒÔÊÇÎÞÂÛÊÇͨË×ÊðÀíÍøÂ磬ÕվɽøÒ»²½Ê¹ÓÃTorÍøÂ綼Äܹ»ÔÚÒ»¶¨Ë®Æ½ÉÏΪ½©Ê¬ÍøÂçÌṩ¸»×ãµÄÒþÄä±£»¤¡£
3.3LeeHozerÆÊÎö
LeeHozerÊÇÒ»Àà½èÖúSocks5ÐÒéÓëTor C&CͨѶµÄÐÂÐͽ©Ê¬¼Ò×壬ÆäÉè¼ÆÁËÏà¶ÔÑϽ÷¶øÖØ´óµÄͨѶÐÒé¡£ÓÉÓÚÑù±¾ÏÂÔصصã(http://exec.elrooted.com/uc/i686)ÓëMal_ProxyC&C(cest4.elrooted.com)ʹÓÃÁËÏàͬµÄ¶þ¼¶ÓòÃû£¬ÇÒͬÆÚÁ½ÀàÑù±¾¾ù¸üеü´úÁ˲ÎÊýÆô¶¯µÄа汾£¬ÎÒÃÇÒÔΪ¶þÕßÓÐ׎ÏÇ¿µÄ¹ØÁªÐÔ¡£ÏÂÎÄÒÔV3°æ±¾ÎªÀý¾ÙÐÐÆÊÎö£¬²¢¶ÔÆä²ÎÊýÆô¶¯¡¢É¨ÃèÄ£¿é¡¢¿ØÖÆÖ¸ÁîµÈ¹¦Ð§µÄ¸üÐÂÉý¼¶ÇéÐξÙÐÐ˵Ã÷¡£
±í10£ºÑù±¾ÐÅÏ¢
LeetHozerµÄ¹¥»÷Ä¿µÄÖ÷ÒªÊÇÕë¶ÔIOT×°±¸£¬Ò»µ©×°±¸ÖØÆô£¬ÆäÄÚ´æÖеÄBot³ÌÐòÒ²»áËæÖ®ÏûÊÅ¡£ÒÔÊÇLeetHozer»áͨ¹ýÏòwatchdog£¨¿´ÃŹ·£©·¢ËÍ0x80045704À´½ûÓÃwatchdog¹¦Ð§£¬´Ó¶ø±ÜÃâ×°±¸ÖØÆô¡£
ͼ33£º½ûÓÃwatchdog
ͬʱ³ÌÐò»áÔÚconsoleÖÐÊä³ö/bin/sh: ./filename: not foundÒÉ»óÓû§£¬Ö®ºóÖ´Ðж˿ÚɨÃèÉϱ¨£¬ÐÒéУÑéÉÏÏߺ͹¥»÷Ä£¿éµÈ¹¦Ð§¡£
ͼ34£ºconsoleÊä³ö
3.3.1 Ãô¸ÐÐÅÏ¢¼ÓÃÜ
LeetHozer½ÓÄÉÁË×Ô½ç˵µÄËã·¨¼ÓÃÜ×ÊÔ´ÐÅÏ¢£¬¼ÓÃÜÃÜԿΪqE6MGAbI¡£Ïà¹ØËã·¨Èçͼ35Ëùʾ£º
ͼ35£º¼ÓÃÜËã·¨
½âÃܺóµÄ×ÊÔ´ÐÅÏ¢Èç±í11Ëùʾ£º
±í11£º½âÃÜ×ÊÔ´ÐÅÏ¢
3.3.2 ¶Ë¿ÚɨÃèºÍÐÅÏ¢Éϱ¨
LeeHozer¸´ÓÃÁËMiraiµÄɨÃèÐÎʽ£¬ÈçɨÃè²¢ÉÏ°¶ÀֳɺóÔòÉϱ¨×°±¸ÐÅÏ¢£¬ÇÒ²î±ð°æ±¾¾ßÓвî±ðµÄɨÃèģʽ¡£
±í12£ºÉ¨Ãèģʽ
V2°æ±¾É¨Ãè9530¶Ë¿Ú£º
ͼ36£º9530¶Ë¿ÚɨÃè
V3°æ±¾ÔòÓÐËù²î±ð£¬Ïà½ÏÓÚ֮ǰµÄ°æ±¾£¬V3°æ±¾ÔöÌíÁ˲ÎÊýÆô¶¯ÉèÖá£ÈôÊÇÎÞ²ÎÖ´ÐÐÑù±¾£¬Ä¬Èϲ»»áÖ´ÐÐɨÃ蹦Ч£»¶øÈôÊÇÆô¶¯³ÌÐòʱÌí¼Ótelnet²ÎÊýÔò»á¾ÙÐÐɨÃè²Ù×÷£¨Èç¡°./samples telnet¡±£©
ͼ37£º23/26¶Ë¿ÚɨÃè
ͼ38£ºÉϱ¨Reporter
3.3.3 ͨѶÐÒé¼°¹¥»÷Ä£¿é
LeeHozer½¨ÉèͨѶµÄÀú³Ì½ÏΪÖØ´ó£¬Ê×ÏÈÆä»áͨ¹ýSocks5ÐÒéÅþÁ¬ÊðÀíÍøÂ磬´Ó¶ø½øÒ»²½ÓëTor C&C½¨ÉèÅþÁ¬£º
ͼ39£ºSocks5ÐÒé½»»¥
ÈôÊÇÄ¿½ñSocksÊðÀíÅþÁ¬Ê§Ð§£¬³ÌÐò»áËæ»ú´ÓÄÚÖõÄ107¸öÊðÀíÖÐÑ¡ÔñÆäÒ»²¢ÖØн¨ÉèÊðÀíÅþÁ¬£¬ÄÚÖÃÊðÀíÁбíÈçÏ£º
±í13£ºÊðÀíÁбí
ÕâÅúÊðÀí×ÊÔ´ºÜÓпÉÄܾÍÊÇͨ¹ýMal_Proxy½¨É裬ËäÈ»£¬ÆäÖÐÒ²¿ÉÄÜ°üÀ¨Ò»Ð©¹²Ïí×ÊÔ´ºÍÃâ·Ñ½Úµã¡£
µ±LeeHozerÀֳɺÍC&C½¨ÉèÅþÁ¬ºó£¬»¹Ðè¾ÓÉÁ½ÂÖУÑé½»»¥²Å»ªÕæÕýʵÏÖÉÏÏß¡£
µÚÒ»ÂÖУÑ飺
Client->Server£º
УÑéÇëÇó°ü³¤¶ÈΪ255×Ö½Ú£¬µ«Ö»ÓÐÇ°32×Ö½ÚΪÓÐÓÃÄÚÈÝ¡£
ͼ40£ºµÚÒ»ÂÖУÑéÇëÇó°ü
±í14£ºµÚÒ»ÂÖУÑéÇëÇó°üÆÊÎö
ÅÌËãУÑéÖµµÄËã·¨Èçͼ41Ëùʾ£º
ͼ41£ºÅÌËãУÑéÖµ
Server->Client:
¿ØÖƶ˻ذüͬÑùΪ255×Ö½Ú£¬Ç°32×Ö½ÚÓÐÓá£
ͼ42£ºµÚÒ»ÂÖ¿ØÖƶ˻ذü
¿Í»§¶Ë»áÕë¶Ô»Ø°üµÄÁ½¸ö±ê¼Çλ¾ÙÐÐУÑ飬»®·ÖΪ0x70f1ºÍ0x4819£¬Ð£Ñéͨʺó¼ÌÐø¾ÙÐеڶþÂÖ½»»¥¡£
ͼ43£º±ê¼ÇλУÑé
µÚ¶þÂÖУÑ飺
Client->Server£º
¿Í»§¶ËУÑéÇëÇó°üÈÔΪ255×Ö½Ú£¬Ç°32×Ö½ÚÓÐÓ㬲¿·ÖÊý¾ÝÔ´×ÔµÚÒ»ÂÖ·þÎñ¶ËµÄ»Ø°ü¡£
ͼ44£ºµÚ¶þÂÖУÑéÇëÇó°ü
±í15£ºµÚ¶þÂÖУÑéÇëÇó°üÆÊÎö
Server->Client:
µÚ¶þÑ»·°üÓëµÚһѻ·°üÏàËÆ£¬×ܳ¤255×Ö½Ú£¬Ç°32×Ö½ÚÓÐÓá£
ͼ45£ºµÚ¶þÂÖ¿ØÖƶ˻ذü
¿Í»§¶Ë¶Ô0x70F2ºÍ0x2775Á½¸ö±ê¼ÇλУÑéÀֳɺ󣬽©Ê¬µÄÉÏÏßÀú³Ì²ÅËãÍê³É£¬Ö®ºó½©Ê¬ÆÚ´ý¿ØÖƶËÏ·¢Ö¸ÁÆäÖÐÖ¸ÁîµÄÊ××Ö½ÚÖ¸¶¨ÁË¿ØÖÆÖ¸ÁîÀàÐÍ¡£
¿ØÖÆÖ¸Áî¹²°üÀ¨ÈýÀࣺ
±í16£º¿ØÖÆÖ¸ÁîÀàÐÍ
0x00 ÐÄÌø°ü£º
ͼ46£ºÐÄÌø°ü
0x01 ·¢ËͱêʶÐÅÏ¢£º
ͼ47£º·¢ËͱêʶÐÅÏ¢
ÈçÊ××Ö½ÚΪÆäËüÖµ£¬Ôò»áÆÊÎöÏêϸµÄÖ¸ÁЧ£¬LeetHozer²î±ð°æ±¾µÄ¹¦Ð§Ö¸ÁîÈç±í18Ëùʾ£º
±í17£º¹¦Ð§Ö¸Áî±í
ͼ48£ºV3°æ±¾¹¥»÷Ö¸ÁîÅжÏ
ÎÒÃÇÊӲ쵽£¬½üÆÚLeeHozerÈÔÔÚÒ»Á¬Õö¿ª¹¥»÷Ô˶¯£¬¹¥»÷Ö¸ÁîÈçͼ48Ëùʾ£º
ͼ49£º¹¥»÷Ö¸ÁîÊý¾Ý°ü
±í18£º¹¥»÷Ö¸ÁîÊý¾ÝÆÊÎö
ËÝÔ´Óë¹ØÁª
ÖµµÃ×¢ÖصÄÊÇ£¬LeeHozerÔÚ´úÂëÖжദʹÓÃÁËÓëvbrxmrÏà¹ØµÄ×Ö·û´®£¬ÀýÈç¡®GET /vbrxmr/i586 HTTP/1.0¡¯¡¢¡®/bin/busybox VBRXMR¡¯£¬ÒÔ¼°C2£¨vbrxmrhrjnnouvjf.onion£©µÈ¡£ÓëÖ®Ïà¹ØµÄ£¬Hoaxcalls(XTC)½©Ê¬ÍøÂçÔøʹÓÃcbc.vbrxmr.pw×÷ΪC2£¬´úÂëÖÐÒ²·ºÆð¹ývbrxmr×Ö·û´®£¬ÇÒͬÑù¿ÉÒÔ½èÖúÊðÀíÍøÂçͨѶ£¨¾ß±¸Fastflux¹¦Ð§£©£¬VbrxmrµÄƵÈÔ·ºÆðÒ²²»µÃ²»ÈÃÈËÏÓÒÉÁ½ÕßÖ®¼ä±£´æÒ»¶¨µÄ¹ØÁª¡£
ͼ50£ºHoaxcalls×Ö·û´®
±ðµÄ£¬Í¨¹ýËÑË÷LeeHozerµÄ¼ÓÃÜÃÜÔ¿qE6MGAbI£¬»¹·¢Ã÷ÁËÁíÒ»ÖÖʹÓÃÊðÀíͨѶµÄÑù±¾£¬ÇÒÆäʹÓõÄÊðÀíÁбíÒ²ºÍLeeHozerÓв¿·ÖÖغϡ£
ͼ51£ºÄ³ÊðÀíÑù±¾×Ö·û´®
ÀàËƵĹØÁªÅú×¢ÕâЩʹÓÃÊðÀíµÄ½©Ê¬ÍøÂç¿ØÖÆÕß¼ä»ò¶à»òÉÙ±£´æ×ÅһЩÁªÏµ£¬ºÚ¿ÍÃǺܿÉÄÜÔÚµØÏÂÂÛ̳ÉúÒâÊðÀí×ÊÔ´¡¢¹²Ïí´úÂë»òÊÇͨ¹ý´úÂëÄ£ÄâÀ´ÒÉ»óÑо¿Ö°Ô±¡£
ËÄ¡¢×ܽá
Ëæ×ÅÎïÁªÍøʱ´úµÄ¿ìËÙÉú³¤£¬Çå¾²¶Ô¿¹Ò²ÔÚÒ»Ö±Éý¼¶ºÍ½ø»¯¡£¿ÉÒÔ¿´µ½£¬Ô½À´Ô½¶àµÄ¹¥»÷ÕßʵÑé´Ó¸ü¶àµÄά¶È¿ªÕ¹¹¥»÷Ô˶¯ºÍÇå¾²¶Ô¿¹¡£Ò»·½Ã棬ԽÀ´Ô½¶àµÄ¹¥»÷Õß×îÏȽèÖúÊðÀíÍøÂçÀ´ÔöÇ¿ÒþÄäÇå¾²£¬ÊðÀí×ÊÔ´×÷ΪÒþÄäC&CµÄÇ°ÖÃÍøÂçÎÞÒÉÊÇÒ»¸öÖØ´óµÄÍþвºÍÒþ»¼£»ÁíÒ»·½Ã棬Ҳ·ºÆðÁËʹÓöñÒâÑù±¾ÊµÏÖÓÕ²¶¼à²âºÍ·´Ì½²âÄÜÁ¦µÄÓ¦ÓÃÐÂ˼Ð÷£¬ÕâЩ¶¼»á¸øÎïÁªÍø×°±¸µÄÇå¾²·À»¤ºÍÑо¿ÊÂÇé´øÀ´¸ü¶àµÄת±ä£¬ºóÐøÎÒÃÇÒ²»á¾ÙÐÐÒ»Á¬µÄ¹Ø×¢ºÍ×·×Ù¡£
IOCÐÅÏ¢
Moobot£º
URL :
http://exec.elrooted.com/ab/i686
http://conn.elrooted.com/li/arm
http://91.92.66.87:80/420/adb/x86
http://185.163.46.6/a/x86_64
http://5.252.179.60/b/x86_64
http://185.172.110.224/ab/i586
C2£º
proxy.2u0apcm6ylhdy7s.com
abcdefg.elrooted.com
park.elrooted.com
frsaxhta.elrooted.com
cccc.elrooted.com
205.185.114.231
185.172.110.224
Reporter IP£º
gfedcba.elrooted.com
hello.elrooted.com
HASH£º
1a64cd13d9c71542ce60183356a615505f10ddc192eded5fce0f0075f3ad7648
ca3889994301f28baa791f4ef1aa473b0bc6e975cda703195787872795171869
e9a7aab3ab25c0a091d98d3ae4a313fba3b3bd0588bfe8e3624ec016bc11f02e
2516bdc3ae3818e30e1145f75811937e29ce10f94722c6da1ea7c28f4c0bc3dc
a6e18135a2afcd96957bff63388501465f5a1203b2d22ee0f1074661e286d9e3
59b1ca2d47af1d5b60b84c3a9d6a64a09b7340864b9e90247466d7f91ed53b84
d5d5488ae9c80558cc4634ce6d51837d82347fd48d1a665e606dcfbfdf638b7b
Mal_Proxy£º
URL £º
http://proxy.2u0apcm6ylhdy7s.com/b/x86_64
http://proxy.2u0apcm6ylhdy7s.com/b/armv7l
C2£º
hxarasxg.hxarasxg.xyz
cest4.elrooted.com
da.elrooted.com
185.172.110.240
HASH£º
a67f79c7ae6b1177309cb328d3ec93ec91960edf457a4f5a74120baaf80139ee V2
04114bd136941811e355df28e9b2eeaa941a04b61b185fd214a4c54daa171e1c V2
80f1973b82cbea485f27eb8c44983c565701fdc4e6d3e994ed57bf57a66b9c81 V2
f91427e74a84c34d329116443fa1c89c63dab57e01129345a9f9ed364533dd49 V1
4ed3c601022b4d8c1478521241b847dcacecd837bc75547f3a378ee9d5b9e15f V1
b41de82ea89e2ceedda5b4a856c273c4ce06429d876ee4a05ee9a2423741461f V1
LeeHozer£º
C2£º
vbrxmrhrjnnouvjf.onion:31337
37.49.226.171:31337
w6gr2jqz3eag4ksi.onion:31337
Reporter IP:
report.infidel.ml:9814
HASH£º
84efc5ce8a0729b1248b5f7a43ddf371f517ac0a0eea0a5b0674ce195be61b8e v3
ca8095af62b836f3ddd12007bc8cb67cdd39266c3d40179691f9ee1ca94e9428 v2
1c5349696c04dfa8e0f458ad1d9aa360f4768b21d3dd83fb98d935691b1b2a88 v1
²Î¿¼ÎÄÏ×£º
1.https://blog.radware.com/security/botnets/2020/05/whos-viktor-tracking-down-the-xtc-polaris-botnets/
2.https://blog.netlab.360.com/the-leethozer-botnet-en/
3.https://www.exploit-db.com/exploits/48225
4.https://blog.netlab.360.com/multiple-botnets-are-spreading-using-lilin-dvr-0-day/
5.https://habr.com/en/post/486856/
ÔÎÄȪԴ£ºÍøÂçÇå¾²Ó¦¼±ÊÖÒÕ¹ú¼Ò¹¤³ÌʵÑéÊÒ
±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓëÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅADLab¹¥·ÀʵÑéÊÒÍŽáÐû²¼
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î800Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØϵͳÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£