½©Ê¬ÃÛÍø£ºÊ׿î¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦µÄÎïÁªÍø½©Ê¬ÍøÂç

Ðû²¼Ê±¼ä 2020-07-24

Ò»¡¢¸ÅÊö


½üÆÚ£¬£¬£¬ £¬£¬£¬ÎÒÃǸú×Ùµ½Ò»ÆðÌØ±ðµÄÎïÁªÍø½©Ê¬ÍøÂç¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ½ü3¸öÔÂÀ´¶ÔÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹¡¢µÂ¹úµÈ¶à¸ö¹ú¼Ò·¢¶¯Á˽ÏΪƵÈԵĹ¥»÷¡£¡£¡£¡£¡£ÕâÅú¹¥»÷ËäÈ»Á÷Á¿²¢²»´ó£¬£¬£¬ £¬£¬£¬µ«ÔÚ×·×ÙµÄÀú³ÌÖз¢Ã÷£¬£¬£¬ £¬£¬£¬ÕâÅú¹¥»÷Öб£´æÒ»Ð©VT²éɱÂÊΪ0µÄ¶ñÒâÑù±¾£¬£¬£¬ £¬£¬£¬Èçͼ1Ëùʾ£»£»£»£»²¢ÇÒ»¹·¢Ã÷¸Ã½©Ê¬ÍøÂçµÄÐí¶à½ÚµãÐÂÓ±µØ¼ÓÈëÁËÓÕ²¶¼°·´Ì½²âÄÜÁ¦¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ1£ºVT¼ì²âÇéÐÎ


ÕâЩ½©Ê¬Ñù±¾¿ÉÒÔ½«ÊÜ¿Ø×°±¸µÄÖ¸ÎÆÐÅϢαװ³ÉÆäËû×°±¸µÄÖ¸ÎÆ£¨ÏÖÔÚ½ö·¢Ã÷DVRµÄαÔìÖ¸ÎÆ£¬£¬£¬ £¬£¬£¬ÍƲâºÚ¿Í¿ÉÒÔͨ¹ý¸üÐÂÄ£¿£¿£¿£¿£¿£¿£¿éÀ´Î±ÔìÆäËû×°±¸Ö¸ÎÆ£©¡£¡£¡£¡£¡£Ò»·½ÃæÒÔαÔì×°±¸Ö¸ÎƵķ½·¨À´ÓÕÆ­ÈçShodanµÈÖÖÖÖÎó²îɨÃè²úÆ·£¬£¬£¬ £¬£¬£¬ÒԵִﷴ̽²âµÄÄ¿µÄ£»£»£»£»ÁíÍâÒ»·½ÃæÕâÖÖαÔìµÄ×°±¸Ö¸ÎÆÒ²±»Ê¹ÓÃÀ´×öÓÕ²¶£¬£¬£¬ £¬£¬£¬Èçαװ³ÉΪһ¸ö±£´æÎó²îµÄ×°±¸£¬£¬£¬ £¬£¬£¬ÒÔÃÛ¹ÞÓÕ²¶µÄ·½·¨ÓÕʹÆäËûºÚ¿Í·¢ËÍʹÓôúÂë¾ÙÐй¥»÷£¬£¬£¬ £¬£¬£¬´Ó¶ø»ñµÃÎó²îʹÓÃϸ½Ú¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬ £¬£¬£¬ÎÒÃǽ«´ËÀཀྵʬËù¹¹½¨µÄ¿ÉÒÔ¶ÔÎó²îºÍ¹¥»÷Ñù±¾¾ÙÐÐÓÕ²¶µÄ½©Ê¬ÍøÂçÃüÃûΪ¡°½©Ê¬ÃÛÍø¡±¡£¡£¡£¡£¡£


ͨ¹ýÎÒÃÇ×Ô¼ºµÄÎïÁªÍøÍþвÊý¾Ýƽ̨¼°Ïà¹ØÇ鱨µÄ½»Ö¯Ó¡Ö¤£¬£¬£¬ £¬£¬£¬·¢Ã÷¡°½©Ê¬ÃÛÍø¡±°üÀ¨Á½ÀàÑù±¾¡£¡£¡£¡£¡£µÚÒ»ÀàÊÇÓÕ²¶Ó뷴̽²â½Úµã£¬£¬£¬ £¬£¬£¬¶Ô¸ÃÑù±¾¾ÙÐжþ½øÖÆÎļþÏàËÆ¶È±È¶Ô·¢Ã÷Æä¹¥»÷Ä£¿£¿£¿£¿£¿£¿£¿éºÍͨѶЭÒéÓëMoobot¼Ò×å¸ß¶ÈÏàËÆ£¬£¬£¬ £¬£¬£¬ÍƲâÓëMoobot¼Ò×åͬԴ£¬£¬£¬ £¬£¬£¬Òò´Ë½«ÕâÀàÐÂÐ͵ĶñÒâ³ÌÐòÃüÃûΪMoobot_Trap£¬£¬£¬ £¬£¬£¬Æä½è¼øÁËÃÛ¹ÞµÄÉè¼ÆÍ·ÄÔ£¬£¬£¬ £¬£¬£¬³ýÁËαװ×ÔÉíΪÆäËû×°±¸Í⣬£¬£¬ £¬£¬£¬»¹ÄÜͨ¹ýÓÕ²¶ÆäËü¹¥»÷ÕßµÄÎó²îʹÓÃÇ鱨Óë¹¥»÷Ñù±¾£¬£¬£¬ £¬£¬£¬À´ÎÞа¿ìËÙµÄÉý¼¶ÆäÎäÆ÷¿â£¬£¬£¬ £¬£¬£¬ÔöÇ¿×ÔÉíµÄ¹¥»÷Óë·ÀÓùÄÜÁ¦¡£¡£¡£¡£¡£µÚ¶þÀàÊǹ¹½¨ÊðÀíÍøÂçµÄ¶ñÒâÊðÀí½Úµã£¬£¬£¬ £¬£¬£¬ÎÒÃǽ«ÆäÃüÃûΪMal_Proxy£¬£¬£¬ £¬£¬£¬Í¨¹ýÏ·¢¶ñÒâÊðÀíÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»½«ÊÜѬȾ»ò¹ºÖõÄ×°±¸×÷ΪнڵãÀ´ÊðÀíí§ÒâÁ÷Á¿£¬£¬£¬ £¬£¬£¬½ø¶øÒ»Ö±Éú³¤×³´óÆäÊðÀíÍøÂç¡£¡£¡£¡£¡£¶ñÒâÁ÷Á¿¾­ÊðÀíÍøÂçÖÐתÖÁTorÍøÂç»òÕæÊµC&C£¬£¬£¬ £¬£¬£¬Ò»·½Ãæ¿ÉÒÔ×èÖ¹Ö±½Ó̻¶Éí·Ý£¬£¬£¬ £¬£¬£¬ÁíÒ»·½ÃæÒ²ÄܸüºÃµÄ´©Í¸Ä³Ð©ÍøÂç·À»ðǽµÄÏÞÖÆ¡£¡£¡£¡£¡£Í¨¹ýÏÖÔÚÕÆÎÕµÄÊý¾ÝÁ¬ÏµÎïÁªÍø½©Ê¬Ñù±¾µÄÆÊÎö£¬£¬£¬ £¬£¬£¬ÎÒÃÇ»¹Ô­³öÁ˸ý©Ê¬ÍøÂçµÄ¹¥»÷Ä£×ÓÈçͼ2Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ2£º¡±½©Ê¬ÃÛÍø¡°¹¥»÷Ä£×Ó


½øÒ»²½ËÝÔ´ºó£¬£¬£¬ £¬£¬£¬ÎÒÃÇ·¢Ã÷Õâ´Î¹¥»÷±³ºóµÄ×éÖ¯¿ÉÄÜÍ¬Ê±ÕÆ¿Ø×ŰüÀ¨Moobot¡¢LeeHozer¡¢Gafgyt±äÖÖÔÚÄڵĶà¸ö½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¸Ã×éÖ¯²»µ«¾ßÓжàÖÖ0DayºÍNdayÎó²î¹¥»÷µÄÄÜÁ¦£¬£¬£¬ £¬£¬£¬»¹ÉÆÓÚͨ¹ýÊðÀíÍøÂç¡¢TorÍøÂçµÈÊðÀíÊÖÒÕÀ´ÔöǿͨѶµÄÄäÃû»¯£¬£¬£¬ £¬£¬£¬´Ó¶øÌá¸ßÆäC&CЧÀÍÆ÷µÄÒþ²ØÐÔ¡£¡£¡£¡£¡£±¾ÎĽ«¶Ô²¶»ñµ½µÄ½©Ê¬Ñù±¾¡¢¶ñÒâÊðÀí³ÌÐò¼°Æä¹¥»÷Á´¾ÙÐÐÆÊÎö£¬£¬£¬ £¬£¬£¬²¢½øÒ»²½¶Ô±³ºóµÄºÚ¿Í×éÖ¯ÒÔ¼°ÕâЩ½©Ê¬ÍøÂç¼äµÄ¹ØÁªÐÔÕö¿ªÆÊÎöºÍ×·×Ù¡£¡£¡£¡£¡£


¶þ¡¢¹¥»÷×ÊÔ´ÆÊÎö


ÔÚ×·×ÙÀú³ÌÖУ¬£¬£¬ £¬£¬£¬ÎÒÃÇ·¢Ã÷¡°½©Ê¬ÃÛÍø¡±Óë¶à¸ö½©Ê¬ÍøÂç¼ä±£´æ½ÏÇ¿µÄ¹ØÁªÐÔ£¬£¬£¬ £¬£¬£¬°üÀ¨Moobot¡¢LeetHozerÒÔ¼°Gafgyt±äÖֵȵÈ¡£¡£¡£¡£¡£ÒÔMoobotºÍLeetHozerÁ½Àà½©Ê¬ÍøÂçΪÀý£¬£¬£¬ £¬£¬£¬proxy.2u0apcm6ylhdy7s.comÓòÃûÔø×÷ΪMal_ProxyµÄDownloader URLÒÔ¼°MoobotµÄC2£»£»£»£»elrooted.comÏà¹Ø×ÓÓòÃûÔøÓÃÓÚMal_ProxyµÄC2ÒÔ¼°Moobot¡¢LeetHozerµÄDownloader URL£¬£¬£¬ £¬£¬£¬ÀàËÆÓòÃû×ʲúÖØÓõÄÕ÷Ï󣬣¬£¬ £¬£¬£¬Åú×¢Á½ÀཀྵʬºÜÓпÉÄÜÔ´×Ôͳһ×éÖ¯¡£¡£¡£¡£¡£ÎÒÃÇÕûÀíÁ˹ØÁªÑù±¾µÄÈö²¥ºÍÖ´ÐÐÁ÷³ÌÈçͼ3Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ3£º¹ØÁªÑù±¾µÄÈö²¥ºÍÖ´ÐÐÁ÷³Ìͼ


ÆäÖУ¬£¬£¬ £¬£¬£¬MoobotÊÇÑù±¾ÊýÄ¿×î¶àÇÒÒ»Á¬»îÔ¾µÄÒ»Àཀྵʬ£¬£¬£¬ £¬£¬£¬ÎÒÃÇ·¢Ã÷µÄ¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦µÄMoobot_Trap¼´ÊÇÆäͬԴ¼Ò×å¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬ £¬£¬£¬ÓÉÓÚMoobotǰÆÚÈö²¥µÄÑù±¾Éæ¼°SocksºÍTor°æ±¾£¬£¬£¬ £¬£¬£¬Ò²¿ÉÄÜÓë´Ë´Î·¢Ã÷µÄ¶ñÒâÊðÀí³ÌÐòÓйØ¡£¡£¡£¡£¡£LeetHozer½©Ê¬ÔòÊÇͨ¹ýSocks5ЭæÅºÍTor C&C½¨ÉèÅþÁ¬£¬£¬£¬ £¬£¬£¬ÇÒÓëMal_ProxyµÄ»îԾʱ¼äÏà½ü£¬£¬£¬ £¬£¬£¬ÍƲâLeetHozerÄÚÖõÄÊðÀí½ÚµãÁбíºÜ´ó¿ÉÄܾÍÊǺڿͿØÖƵĶñÒâÊðÀíÍøÂç¡£¡£¡£¡£¡£


ƾ֤ÏÖÔڵļà²âÇéÐΣ¬£¬£¬ £¬£¬£¬¸Ã×éÖ¯µ¥ÈÕÌᳫµÄ¹¥»÷´ÎÊýÔ¼ÔÚ100´Î×óÓÒ£¬£¬£¬ £¬£¬£¬±»¹¥»÷Ä¿µÄÔòÖ÷ÒªÂþÑÜÔÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹¡¢µÂ¹úµÈ¹ú¼Ò£¬£¬£¬ £¬£¬£¬ÆäÖÐÕë¶ÔÎÒ¹úµÄ¹¥»÷´ó¶à¼¯ÖÐÔÚн®¡¢ºÓÄÏ¡¢½­ËÕ¡¢Ì¨ÍåµÈµØÇø£¬£¬£¬ £¬£¬£¬¹¥»÷¼Í¼ʾÀýÈçͼ4£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ4£º¹¥»÷¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ5£º¾³ÄÚÊܹ¥»÷IPλÖÃÂþÑÜͼ


±ðµÄ£¬£¬£¬ £¬£¬£¬¸Ã×éÖ¯»¹¾ß±¸ºÜÇ¿µÄÎó²îʹÓÃÄÜÁ¦£¬£¬£¬ £¬£¬£¬ÒÑÖªµÄÎäÆ÷¿â°üÀ¨½ñÄêÍ·Åû¶µÄLILIN DVR 0DayÎó²î¡¢HiSilicon DVR backdoor 0DayÎó²î£¬£¬£¬ £¬£¬£¬ÒÔ¼°Öî¶àÓ°Ïì¹æÄ£ÆÕ±é¡¢Î£º¦ÑÏÖØµÄNdayÎó²î£¬£¬£¬ £¬£¬£¬Ò»Ð©±»¹ûÕæµÄÎó²îPOCÒ²ÍùÍù»á±»Ñ¸ËÙ¼¯³É²¢Ó¦ÓÃÓÚÆäÎó²îɨÃèÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬Ë¼Á¿µ½ºÚ¿Í»¹¿ÉÒÔͨ¹ýαװµÄÓÕ²¶½ÚµãÍøÂçÆäËü¹¥»÷ÕßµÄÇ鱨¼°Ñù±¾ÇéÐΣ¬£¬£¬ £¬£¬£¬ÎÒÃÇÔ¤¼ÆÆä¿ÉÓõÄÎó²î×ÊÔ´ºÜÊÇÖØ´ó¡£¡£¡£¡£¡£Í¨¹ýÏÖÔÚ¼à²â·¢Ã÷¼°Ïà¹Ø±¨¸æÖÐÅû¶µÄÎó²îʹÓÃÇéÐΣ¬£¬£¬ £¬£¬£¬¸Ã×é֯ʹÓõÄÎó²îÈç±í1Ëùʾ£º


±í1£ºÎó²îʹÓÃÁбí

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚÓòÃû×ʲú·½Ã棬£¬£¬ £¬£¬£¬¸Ã×é֯ʹÓÃʱ¼ä½Ï³¤¡¢Æµ´Î½Ï¸ßµÄÓòÃûΪelrooted.com¡¢2u0apcm6ylhdy7s.comÒÔ¼°¶¥¼¶ÓòÃû.xyzϵIJ¿·ÖÓòÃû¡£¡£¡£¡£¡£ÕâÈýÀàÓòÃûϵÄ×ÓÓòÃûºã¾Ã±»ÆÊÎö²¢ÓÃÓÚÆäÑù±¾µÄDownloaderURL»òC&C¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬ £¬£¬£¬185.172.110.0/23Íø¶Î¹ØÁª×Å´ó×Ú½©Ê¬£¬£¬£¬ £¬£¬£¬ÀýÈç185.172.110.240¡¢185.172.110.224¡¢185.172.110.235µÈµÈ¡£¡£¡£¡£¡£


»ùÓÚÏÖÔÚÕÆÎÕµÄÇéÐΣ¬£¬£¬ £¬£¬£¬ÎÒÃÇ×ܽá¸Ã×éÖ¯µÄÌØµãÈçÏ£º


¡ñ ¸Ã×éÖ¯¿ÉÄÜÕÆ¿Ø×ŰüÀ¨Moobot¡¢LeeHozer¡¢Gafgyt_variantÔÚÄڵĶà¸ö½©Ê¬ÍøÂ磬£¬£¬ £¬£¬£¬¹¥»÷Ä¿µÄ±é²¼È«Çò£¬£¬£¬ £¬£¬£¬ÇÒ½üÆÚÈÔÔÚ¼á³Ö¸ßƵÂʵĹ¥»÷»î¶¯

¡ñ ÕÆÎÕ×ÅÊðÀíÍøÂç×ÊÔ´£¬£¬£¬ £¬£¬£¬ÓëÆäËüʹÓÃÊðÀíÍøÂçµÄ½©Ê¬±£´æÒ»¶¨¹ØÁª£¬£¬£¬ £¬£¬£¬ÇÒ¿ÉÄÜÔÚµØÏÂÂÛ̳³öÊÛÊðÆÊÎö¼ûȨÏÞ

¡ñ ÉÆÓÚ0DAY¡¢NDAYÎó²îʹÓÃ

¡ñ ÉÆÓÚʹÓÃSocks5ÊðÀí¡¢TorÍøÂçµÈC&CÒþ²ØÊÖÒÕ

¡ñ Ñù±¾É¨ÃèÄ£¿£¿£¿£¿£¿£¿£¿éÂþÑÜÔÚ¶àÖÖÑù±¾ÖÐЭ×÷ɨÃ裬£¬£¬ £¬£¬£¬É¨ÃèЧÂʸß

¡ñ Ñù±¾¾ß±¸ÓÕ²¶¼°·´Ì½²âÄÜÁ¦£¬£¬£¬ £¬£¬£¬Äܹ»²¶»ñÆäËüºÚ¿ÍµÄ¹¥»÷Ç鱨

¡ñ ¾ß±¸Ò»¶¨µÄÇå¾²¶Ô¿¹ÄÜÁ¦£¬£¬£¬ £¬£¬£¬Ñù±¾µü´ú¸üп졢ÃâɱÐԺ㬣¬£¬ £¬£¬£¬ÆµÈÔÌæ»»UPX»ÃÊý¿Ç¡¢¸üÐÂÃô¸ÐÐÅÏ¢¼ÓÃÜËã·¨¼°Í¨Ñ¶Ð­ÒéµÈ


Èý¡¢¹¥»÷ÑùÌìÖ°Îö


ÓÉÓÚ¸Ã×éÖ¯ÓµÓÐ×ÅÁ½Àཀྵʬ½Úµã£¨ÓÕ²¶Ó뷴̽²â½Úµã¡¢ÊðÀí½Úµã£©£¬£¬£¬ £¬£¬£¬ÎÒÃÇÒ²½«Öصã¶ÔÕâÁ½Àà½ÚµãÏà¹ØµÄÑù±¾¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£µÚÒ»ÀàÑù±¾ÎªMoobot_Trap£¬£¬£¬ £¬£¬£¬Æäαװ³ÉΪDVRʵÏÖÓÕ²¶Óë·´Õì²âµÄ¹¦Ð§£»£»£»£»µÚ¶þÀàÑù±¾ÎªÊµÏÖ·´×·×Ù²¢ÓëTorÍøÂç¶Ô½ÓµÄSocket5ÊðÀí½Úµã£¬£¬£¬ £¬£¬£¬°üÀ¨¶ñÒâÑù±¾Mal_ProxyºÍLeeHozer¡£¡£¡£¡£¡£


3.1Moobot_TrapÆÊÎö


Moobot_Trap½©Ê¬ÊÇÒ»¸ö¹¦Ð§ÍêÕûµÄ½©Ê¬³ÌÐò£¬£¬£¬ £¬£¬£¬Æä¹¦Ð§°üÀ¨ÓÕ²¶¼à²âÒÔ¼°·´Ì½²â¡¢Îó²îɨÃè¡¢DDos¹¥»÷¡£¡£¡£¡£¡£Í¨¹ýÑù±¾µÄÏàËÆ¶È±È¶Ô£¬£¬£¬ £¬£¬£¬ÎÒÃÇ×îÖÕÈ·¶¨Moobot_TrapÓëMoobot¼Ò×åͬԴ£¬£¬£¬ £¬£¬£¬Æä¹¥»÷´úÂëºÍͨѶЭÒé¾ßÓи߶ȵÄÏàËÆÐÔ¡£¡£¡£¡£¡£Moobot½©Ê¬×Ô2019ÄêϰëÄê×îÏÈ»îÔ¾£¬£¬£¬ £¬£¬£¬Æäºã¾ÃʹÓÃÎó²î¾ÙÐÐÀ©É¢ÓëѬȾ£¬£¬£¬ £¬£¬£¬¸Ã½©Ê¬½ÓÄÉÒ»ÖÖÊèɢɨÃèµÄ·½·¨¾ÙÐй¥»÷£¬£¬£¬ £¬£¬£¬¼´²»½«ËùÓÐÎó²îɨÃè·½·¨¼¯³ÉÔÚµ¥¸öÑù±¾ÄÚ£¬£¬£¬ £¬£¬£¬¶øÊǽ«ÖÖÖÖÎó²îÂþÑÜÔÚ¶àÀàBotÑù±¾ÖУ¬£¬£¬ £¬£¬£¬ÒÔÌá¸ßɨÃèЧÂʽµµÍ±»·¢Ã÷µÄ¼¸ÂÊ¡£¡£¡£¡£¡£Moobot_TrapÒ²ÑÓÐø´ËÖÖÌØÕ÷£¬£¬£¬ £¬£¬£¬µ«Æä×îÖ÷Òª¸Ä±äÊǼÓÈëÓÕ²¶ºÍ·´Ì½²âÄÜÁ¦£¬£¬£¬ £¬£¬£¬ÆäÔÚÊÜѬȾװ±¸ÉÏ¿ªÆôÒ»¸ömini_httpdЧÀÍ£¬£¬£¬ £¬£¬£¬²¢Î±×°³ÉDVR×°±¸£¬£¬£¬ £¬£¬£¬Ò»·½ÃæÓÃÓÚÓÕ²¶Îó²îºÍ¹¥»÷Ñù±¾£¬£¬£¬ £¬£¬£¬Ò»·½Ãæ¿ÉÒÔÓÕÆ­ÖÖÖÖ×°±¸Ì½²âƽ̨¡£¡£¡£¡£¡£

ÏêϸÆÊÎöÑù±¾Èç±í2Ëùʾ£º


±í2£ºÑù±¾ÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3.1.1 ÓÕ²¶Ó뷴̽²âÄ£¿£¿£¿£¿£¿£¿£¿éÆÊÎö


¸ÃÄ£¿£¿£¿£¿£¿£¿£¿éΪÁËʵÏÖÓÕ²¶¹¦Ð§£¬£¬£¬ £¬£¬£¬½«×Ô¶¯¿ªÆôWEBЧÀͶ˿Ú(80¡¢8080¡¢8000)ÓëÊý¾Ý¿âHSQLµÄЧÀͶ˿Ú(9002)£¬£¬£¬ £¬£¬£¬Ò»µ©ÊÕµ½Íâ½çµÄhttpЭÒéµÄɨÃè̽²â£¬£¬£¬ £¬£¬£¬±ã»á·µ»ØÎ±×°µÄ×°±¸Ö¸ÎÆ¡£¡£¡£¡£¡£ÏÖÔÚ·¢Ã÷µÄMoobot_Trap½«ÊÜ¿Ø×°±¸Î±×°³ÉDVR×°±¸£¬£¬£¬ £¬£¬£¬²»¹ýºÚ¿Í¿ÉÒÔͨ¹ý¸üÐÂÄ£¿£¿£¿£¿£¿£¿£¿éÀ´±ä»»Ö¸ÎÆÐÅÏ¢¡£¡£¡£¡£¡£±ðµÄ¸ÃÄ£¿£¿£¿£¿£¿£¿£¿é»¹Äܹ»¼à¿ØÍâ½ç¶Ô¸Ã×°±¸·¢¶¯µÄ¹¥»÷²¢½«¹¥»÷ÐÅÏ¢Éϱ¨¸øºÚ¿ÍÔ¤ÏȰ²ÅŵÄC&CЧÀÍÆ÷ÉÏ£¬£¬£¬ £¬£¬£¬ÒԴ˺ڿͿÉÒÔ»ñÈ¡µ½Îó²îɨÃèÌØÕ÷ºÍ¹¥»÷Ñù±¾¡£¡£¡£¡£¡£


( 1 ) ·´Ì½²â£ºÏÖÔÚ×îΪÖ÷Á÷µÄ×°±¸Ì½²âÊÖÒÕÒÀÈ»ÊÇ»ùÓÚÖ¸ÎÆÊµÏֵ쬣¬£¬ £¬£¬£¬ÈçShodan¡¢ZoomEye¡¢CensysÒÔ¼°ÖÖÖÖÎó²îɨÃè²úÆ·£¬£¬£¬ £¬£¬£¬Òò¶øMoobot_Trap»¹ÌṩһÀàÄÜÁ¦¾ÍÊǸøÉ¨ÃèÔ´ÌṩαÔìµÄÐÅÏ¢£¬£¬£¬ £¬£¬£¬ÒÔÓÕÆ­É¨ÃèÒýÇæ×öÍÉ»¯ÎóµÄ¾öÒé¡£¡£¡£¡£¡£Ò»ÔòMoobot_Trap¿ÉÒÔ½«×ÔÉíαװ³ÉΪһ¸ö¼áÈçÅÌʯµÄ×°±¸£¬£¬£¬ £¬£¬£¬ÈÃɨÃèÒýÇæÒÔΪÕâÊÇһ̨Çå¾²µÄ×°±¸¶ø½µµÍ±»·¢Ã÷µÄ¼¸ÂÊ£»£»£»£»Ò»ÔòMoobot_TrapÒ²¿ÉÒÔ½«ÈëÇÖµÄ×°±¸Î±×°³ÉΪһ¸ö±£´æÐ¹ûÕæÎó²îµÄ×°±¸£¬£¬£¬ £¬£¬£¬Æä¿ÉÒÔÆðµ½ÓÕ²¶Ò»Ð©Î´¹ûÕæµÄÎó²îʹÓôúÂë¡£¡£¡£¡£¡£ÔÚÎÒÃÇÄ¿½ñËù·¢Ã÷µÄ½©Ê¬ÍøÂçÖУ¬£¬£¬ £¬£¬£¬ÆäÖб»ÈëÇÖµÄÈκÎһ̨װ±¸¶¼½«±»Ê¶±ð³ÉΪһ¸öÌṩmini_httpdЧÀ͵ÄDVR×°±¸(ÓÃÓÚÓÕ²¶Mini_httpd1.19Ïà¹ØµÄÎó²îʹÓôúÂë)¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ6£ºÉ¨ÃèÖ¸ÎÆÊ¾Àý


Mini_httpdÊÇÒ»¿î΢Ð͵ÄHttpЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬ÔÚÕ¼ÓÃϵͳ×ÊÔ´½ÏСµÄÇéÐÎÏ¿ÉÒÔ¼á³ÖÒ»¶¨Ë®Æ½µÄÐÔÄÜ£¬£¬£¬ £¬£¬£¬Òò´ËÆÕ±é±»ÖÖÖÖÎïÁªÍø×°±¸£¨Â·ÓÉÆ÷£¬£¬£¬ £¬£¬£¬½»Á÷Æ÷£¬£¬£¬ £¬£¬£¬ÉãÏñÍ·µÈ£©×÷ΪǶÈëʽЧÀÍÆ÷ʹÓᣡ£¡£¡£¡£¶ø°üÀ¨»ªÎª¡¢º£¿£¿£¿£¿£¿£¿£¿µÍþÊÓ¡¢zyxel¡¢Ê÷Ý®Åɵȳ§ÉÌµÄÆìÏÂ×°±¸¶¼Ôø½ÓÄÉMini_httpd×é¼þ£¬£¬£¬ £¬£¬£¬Ó°Ïì¹æÄ£ºÜ¹ã£¬£¬£¬ £¬£¬£¬Ïà¹ØÎó²î¿ÉÄÜÓ°ÏìÈ«ÇòÊý°ÙÍò×°±¸¡£¡£¡£¡£¡£ÒÔÊǺڿʹËÀàÐÂÓ±µÄÊÖÒÕ˼Ð÷ÔËÓÃÒ²ÐèÒªÒýÆðÎÒÃÇ×ã¹»µÄÖØÊÓ¡£¡£¡£¡£¡£


( 2 ) ÓÕ²¶£ºÎÒÃÇÖªµÀ£¬£¬£¬ £¬£¬£¬ÏÖÊµÍøÂçÖб£´æ´ó×ÚÈ䳿ºÍ½©Ê¬ÍøÂ磬£¬£¬ £¬£¬£¬ËûÃÇÓÀ²»ÖÐÖ¹µØÉ¨Ãè̽²âÍøÂç×ÊÔ´£¬£¬£¬ £¬£¬£¬Í¬Ê±ËûÃÇÒ²ÔÚʵʱ¸üÐÂÆä̽²âÌØÕ÷£¬£¬£¬ £¬£¬£¬ÈçºÚ¿ÍÃǵÄ0day/NdayÎó²îɨÃèÌØÕ÷¡£¡£¡£¡£¡£¶ø´ó²¿·Ö¿ÉÓÃÓÚÈ䳿ºÍ½©Ê¬Èö²¥µÄÎïÁªÍøÎó²î¶¼¼¯ÖÐÔÚHTTPЧÀ͵ÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î(Õ¼±È¸ü¶àµÄTelnetÀ๥»÷ÒÔÈõ¿ÚÁîΪÖ÷£¬£¬£¬ £¬£¬£¬´Ë´¦²»±í)¡£¡£¡£¡£¡£¸Ã¶ñÒâÄ£¿£¿£¿£¿£¿£¿£¿éÕýÊÇÒÔ»ñÈ¡´ËÀàÎó²î¹¥»÷ÐÐΪΪĿµÄ£¬£¬£¬ £¬£¬£¬ÔÚÆô¶¯¶Ë¿ÚÉϼàÊÓwget¡¢tftp¡¢/bin/shÏÂÁ£¬£¬ £¬£¬£¬ÍøÂçÎó²îÐÅÏ¢ºÍÈö²¥Ñù±¾¡£¡£¡£¡£¡£ÏÂͼÊÇÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄPayload£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ7£ºÉ¨ÃèPayloadʾÀý


µ±Ä³Ð©¹¥»÷Õß¡¢È䳿»òÕß½©Ê¬³ÌÐòÕë¶ÔÊÜѬȾװ±¸¾ÙÐÐÎó²îɨÃè»ò´úÂëÖ²Èëʱ£¬£¬£¬ £¬£¬£¬Ò»µ©¹¥»÷PayloadÖÐЯ´øÓÐÖ¸¶¨ÃüÁÈçͼÖеÄwget£©Ê±£¬£¬£¬ £¬£¬£¬¸ÃÊý¾Ý¼´±»ÊÓΪÓÐÓÃÇ鱨±»×ª·¢ÖÁMoobot_TrapºÚ¿ÍµÄC&C¡£¡£¡£¡£¡£Í¨¹ýÕâÖÖÀàËÆÃ۹޵ļà²âÊÖÒÕ£¬£¬£¬ £¬£¬£¬ºÚ¿Í¿ÉÒÔ²¶»ñµ½´ó×ÚÎó²îʹÓôúÂ룬£¬£¬ £¬£¬£¬ÉõÖÁÊÇ0dayÎó²î£¬£¬£¬ £¬£¬£¬¸ü½øÒ»²½£¬£¬£¬ £¬£¬£¬»¹Äܹ»Í¨¹ýÈö²¥µÄ½©Ê¬ÑùÔ­À´ÌáÈ¡ºÍÑо¿¸ü¶àÓмÛÖµµÄÎó²î»òÊÖÒÕ¡£¡£¡£¡£¡£


´ÓÉÏÃæµÄÆÊÎöÎÒÃÇ»¹¿ÉÒÔ¿´³ö£¬£¬£¬ £¬£¬£¬ÈôÊǺڿÍ×éÖ¯¾ß±¸×ã¹»µÄÊÖÒÕʵÁ¦£¬£¬£¬ £¬£¬£¬»¹ÄÜͨ¹ý²¶»ñµÄɨÃèÐÅÏ¢»ñÈ¡µ½ÆäËü½©Ê¬ÍøÂçµÄDownload IP»òC&C²¢½øÒ»²½ÊµÑéÈëÇÖ¡£¡£¡£¡£¡£Í¨³£ÇéÐÎϹ¥»÷ÕßµÄÐí¶àЧÀÍÆ÷¶¼À´×ÔÎó²îÈëÇÖ¡¢Telnet±¬ÆÆµÈµÈ£¬£¬£¬ £¬£¬£¬ÄÇôÕâЩЧÀÍÆ÷×ʲú¾ÍºÜÓпÉÄܱ»ºÚ¿Í×éÖ¯¶þ´ÎÈëÇÖ£¬£¬£¬ £¬£¬£¬Ô­¿ØÖÆÕßÓµÓеÄÈ⼦×ÊÔ´Ò²¿ÉÄܱ»¹²Ïí»ò½ÓÊÜ¡£¡£¡£¡£¡£ÏÂÎÄÎÒÃǽ«¶ÔMoobot_Trap¾ÙÐÐÆÊÎöÓëÐðÊö¡£¡£¡£¡£¡£


Moobot_TrapÊ×ÏÈ»áÔÚ80¡¢8080¡¢8000¡¢9002ËÄÖÖ¶Ë¿ÚÖÐËæ»úÑ¡ÔñÆäÒ»½¨ÉèЧÀͶ˼àÌý£¬£¬£¬ £¬£¬£¬¿ÉÒÔÒÔΪºÚ¿ÍµÄÄ¿µÄ¾ÍÊÇÍøÂçÕâËÄÀà¶Ë¿ÚµÄɨÃèÊý¾Ý¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ8£ºÑ¡Ôñ¶Ë¿Ú½¨Éè¼àÌý


µ±¹¥»÷ÕßɨÃèÏìÓ¦¶Ë¿ÚÇÒ·¢Ë͵ÄÇëÇóÊý¾Ý°üÀ¨wget¡¢tftp¡¢/bin/shÏÂÁîʱ£¬£¬£¬ £¬£¬£¬Moobot_Trap»á·µ»ØÎ±ÔìµÄmini_httpdЧÀÍÆ÷ÐÅÏ¢²¢½«ÇëÇóÊý¾Ýת·¢¸øC&C£¬£¬£¬ £¬£¬£¬Ö®ºó¹Ø±ÕÓë¿Í»§¶ËµÄÅþÁ¬£¨Ä£ÄâHTTPÎÞÅþÁ¬ÇëÇ󣩡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ9£º·µ»Ømini_httpdЧÀÍÆ÷ÐÅÏ¢


ÅþÁ¬C&CÔòÊǼÓÃÜ´æ´¢ÔÚÄÚ´æÖУ¨Ãô¸ÐÐÅÏ¢¼ÓÃܽ«ÔÚºóÐøÕÂ½ÚÆÊÎö£©¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ10£º×ª·¢Êý¾Ý


Ä£ÄâÒ»´ÎɨÃèµÄÏÖÕæÏàÐΣ¬£¬£¬ £¬£¬£¬µ±¹¥»÷ÕßÕë¶ÔÓÕ²¶½Úµã¾ÙÐÐÎó²îɨÃèʱ£¬£¬£¬ £¬£¬£¬½»»¥Á÷Á¿Êý¾Ý°üÈçͼ11Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ11£º½»»¥Êý¾Ý°ü


Moobot_Trap¼ì²âµ½wgetÏÂÁîʱ£¬£¬£¬ £¬£¬£¬»áʶ±ðΪÓÐÓÃÇ鱨£¬£¬£¬ £¬£¬£¬²¢½«É¨ÃèÐÅÏ¢ÒÔÈçϵÄÐÎʽÉϱ¨ÖÁC&C¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ12£ºÉϱ¨É¨ÃèÊý¾Ý


Éϱ¨Êý¾ÝÃûÌÃÈç±í3Ëùʾ£º


±í3£ºÉϱ¨Êý¾ÝÃûÌÃ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3.1.2 Ãô¸ÐÐÅÏ¢¼ÓÃÜ


¼ÓÃÜÊý¾Ý²¢·ÇÕû¶Î´æ´¢ÔÚ´úÂëÖУ¬£¬£¬ £¬£¬£¬¶øÊǽ«×Ö·û´®³£Á¿Ö§½â³É¶à¸ö²¿·Ö´æ·ÅÔÚrodataºÍtext¶Î£¬£¬£¬ £¬£¬£¬ÕâÒ²»á¸øÆÊÎöÊÂÇéÔì³ÉÒ»¶¨µÄ×ÌÈÅ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ13£º¼ÓÃÜ×Ö·û´®


Ïêϸ¼Ó½âÃÜËã·¨ÓëMiraiÏàͬ£¬£¬£¬ £¬£¬£¬ÃÜԿΪ0x0deadbeef£¬£¬£¬ £¬£¬£¬ËùÓÐ×Ö·û´®µÄʹÓö¼ÊÇÓÃʱ½âÃÜ£¬£¬£¬ £¬£¬£¬ÓÃÍê¼´»Ö¸´¼ÓÃÜ£¬£¬£¬ £¬£¬£¬¼Ó½âÃÜËã·¨Èçͼ14Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ14£º¼Ó½âÃÜËã·¨


3.1.3 ¶Ë¿ÚɨÃèºÍÐÅÏ¢Éϱ¨


MoobotɨÃèÄ£¿£¿£¿£¿£¿£¿£¿é½ÓÄÉÈ«ÍøÉ¨Ã裬£¬£¬ £¬£¬£¬²¢½«É¨ÃèЧ¹ûÉϱ¨Reporter£¬£¬£¬ £¬£¬£¬×îºóÓÉLoaderÕë¶ÔÎó²î×°±¸Ö²ÈëÑù±¾£¬£¬£¬ £¬£¬£¬ÀúÊ·ÉÏÆä±£´æ¶àÖÖɨÃè°æ±¾£º


( 1 ) TCP:23,26 (Telnet)

( 2 ) TCP:34567 (DVRIP)

( 3 ) TCP:4567(TVT)

( 4 ) TCP:5555 (ADB)

( 5 ) TCP:80,81,82,83,85,88,8000,8080,8081,9090,60001 (HTTP)


¹ØÓÚɨÃèhttpЧÀ͵ÄÑù±¾£¬£¬£¬ £¬£¬£¬ÈôÊǼì²âµ½ÈçÏÂHttp ServerÔò»áÉϱ¨Reporter¡£¡£¡£¡£¡£Ñù±¾½âÃܺóÓÃÓÚ¼ì²âµÄЧÀÍÆ÷×Ö·û´®Ê¾ÀýÈçÏ£º

"Server: JAWS/1.0."

"Server: DWS."

"URL=/view/viewer_index.shtml?id=."

"Server: thttpd/2.25b PHP/20030920."

"Server: Boa/0.93.15."


ÕâЩ²î±ðɨÃèÖÖÀàµÄÑù±¾µÄDownloaderURLͨ³£Ò²ÊÇÒÔ¶ÔÓ¦Îó²î×°±¸µÄÃû³ÆÀ´ÃüÃûºÍ·ÖÀ࣬£¬£¬ £¬£¬£¬ÀýÈ磺


±í4£ºDownloadURLÌØµã

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹ØÓÚɨÃèʹÓõı¬ÆÆÆ¾Ö¤£¬£¬£¬ £¬£¬£¬³ýÁ˲¿·ÖÄÚÖÃÁбí£¬£¬£¬ £¬£¬£¬»¹¿ÉÒÔÏòC&C·¢ËÍÇëÇóÖ¸ÁîÒÔ»ñÈ¡±¬ÆÆÃû³ÆÃÜÂëÁбí£¬£¬£¬ £¬£¬£¬ÇëÇóÖµ²î±ð¶ÔÓ¦²î±ðµÄ±¬ÆÆ×éºÏÖµ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ15£º·µ»Ø±¬ÆÆ×éºÏ


µ±É¨Ãè·¢Ã÷¿ÉÓÃÎó²î×°±¸Ôò»áÏòReporterÉϱ¨×°±¸ÐÅÏ¢¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ16£ºÉϱ¨×°±¸ÐÅÏ¢


±í5£ºÉϱ¨×°±¸ÐÅÏ¢ÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3.1.4 ͨѶЭÒé¼°¹¥»÷Ä£¿£¿£¿£¿£¿£¿£¿é


Moobot_TrapÔÚͨѶЭÒé·½ÃæÓë֮ǰµÄ°æ±¾ÓÐËùת±ä£¬£¬£¬ £¬£¬£¬Àֳɽ¨ÉèÅþÁ¬ºó£¬£¬£¬ £¬£¬£¬Ê×ÏÈ»áÏò¿ØÖƶ˷¢ËÍÉÏÏß°ü¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ17£ºÉÏÏßÊý¾Ý°ü


±í6£ºÉÏÏßÊý¾Ý°üÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ö®ºó¾àÀë60ÃëÑ­»·Ïò¿ØÖƶ˷¢ËÍÐÄÌø°ü[0x00 0x00]£¨Àο¿Öµ£©£¬£¬£¬ £¬£¬£¬¿ØÖƶËÔò¾àÀë20ÃëÏò½©Ê¬³ÌÐò»Ø°ü[0x33 0x66 0x99]£¨Àο¿Öµ£©¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ18£ºÐÄÌøÊý¾Ý°ü


µ±¿ØÖƶ˷¢Ë͵ÄÖ¸ÁîǰÈý×Ö½Ú·Ç[0x33 0x66 0x99]ʱ£¬£¬£¬ £¬£¬£¬Ôò½øÈë¹¥»÷ģʽÆÊÎöÖ¸Áî¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ19£ºÆÊÎö¹¥»÷


¹¥»÷Ä£¿£¿£¿£¿£¿£¿£¿é·½Ã棬£¬£¬ £¬£¬£¬Moobot_TrapÑÓÓÃÁËMiraiµÄ¹¥»÷ÐÎʽ£¬£¬£¬ £¬£¬£¬Ñù±¾°üÀ¨7ÖÖ¹¥»÷ģʽ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ20£º¹¥»÷ģʽ


¹¥»÷Ö¸ÁîÊý¾Ý°üÈçͼ21Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¶ÔÓ¦½á¹¹ÌåʾÒâÈçÏ£º

type Attack struct {

  Duration          uint32

  Type              uint8

  Targets counts    uint8

  Targets           map[uint32]uint8  

  Flags counts      uint8

  Flags             map[uint8]string

}


±í7£º¹¥»÷Ö¸ÁîÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3.2Mal_ProxyÆÊÎö


Mal_ProxyÊǺڿÍ×éÖ¯ÓÃÓÚ¹¹½¨ÊðÀíÍøÂçµÄ½¹µãÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬Æä¿ÉÒÔÌṩÊðÀíЧÀÍÒÔ¼°ÐÅÏ¢Éϱ¨¹¦Ð§¡£¡£¡£¡£¡£¸ÃÄ£¿£¿£¿£¿£¿£¿£¿éÇáÓ¯ÎÞа£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý²ÎÊýÉèÖÃÊðÀíЧÀÍ£¬£¬£¬ £¬£¬£¬³ÌÐòÆô¶¯ºóÊÜ¿Ø×°±¸¼´×÷ΪÊðÀí½Úµã¼ÓÈëµ½ÊðÀíÍøÂçÖУ¬£¬£¬ £¬£¬£¬ÎªºÚ¿ÍµÄ¶ñÒâ»î¶¯ÌṩÒþÄä±£»£»£»£»¤¡£¡£¡£¡£¡£


Mal_Proxy±£´æÁ½¸ö°æ±¾£¬£¬£¬ £¬£¬£¬V1°æ±¾C2Ϊcest4.elrooted.com£¬£¬£¬ £¬£¬£¬V2°æ±¾C2Ôò°üÀ¨hxarasxg.hxarasxg.xyzºÍda.elrooted.com¡£¡£¡£¡£¡£ÆäÖÐV2°æ±¾ÔöÌíÁ˲ÎÊýÆô¶¯¡¢Socks5ЭÒéÈÏ֤ģʽ¼°UPX¿Ç£¬£¬£¬ £¬£¬£¬²¢ÐÞ¸ÄÁ˿ǵĻÃÊý£¨ÏÖʵ»ÃÊý0xBC7A3331£©ÒÔ¶Ô¿¹¾ç±¾Íѿǡ£¡£¡£¡£¡£Mal_ProxyÑù±¾¾ù±»°þÀë·ûºÅÇÒδÁôÏÂÈκÎÓëÊðÀíÏà¹ØµÄ×Ö·û´®¡¢ÌØÕ÷µÈÐÅÏ¢£¬£¬£¬ £¬£¬£¬ËµÃ÷¸Ã×éÖ¯¾ß±¸Ò»¶¨µÄÇå¾²¶Ô¿¹ÂÄÀú£¬£¬£¬ £¬£¬£¬ÓÐÒâ¸øÆÊÎöÖ°Ô±ÖÆÔì¸ü¶àµÄÄÑÌ⣬£¬£¬ £¬£¬£¬Ò²Ê¹µÃMal_Proxy¼á³ÖÁ˺ÜÊǺõÄÃâɱÐÔ¡£¡£¡£¡£¡£


ºóÎÄÒÔV2°æ±¾ÎªÀý¾ÙÐÐÏêϸÆÊÎö£¬£¬£¬ £¬£¬£¬²¢»á´©²åһЩV1°æ±¾µÄ±ÈÕÕ£¬£¬£¬ £¬£¬£¬Ñù±¾ÐÅÏ¢Èç±í8Ëùʾ£º


±í8£ºÑù±¾ÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3.2.1 ²ÎÊýÆô¶¯Ä£Ê½


Mal_Proxy V1°æ±¾²¢²»¾ß±¸²ÎÊýÆô¶¯Ä£Ê½£¬£¬£¬ £¬£¬£¬ÆäÊðÀí¶Ë¿ÚºÅÊÇͨ¹ýʱ¼ä´ÁÅÌËã³öµÄËæ»úÖµ»ñµÃ£¨¶Ë¿Ú¹æÄ££º0ÖÁ65535£©¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ22£ºV1°æ±¾»ñÈ¡Ëæ»ú¶Ë¿Ú


Mal_Proxy V2°æ±¾ÔòÌí¼ÓÁ˲ÎÊýÆô¶¯Ä£Ê½£¬£¬£¬ £¬£¬£¬´Ó¶ø¿ÉÒÔÔ½·¢ÎÞаµÄÉèÖÃÊðÀí¶Ë¿ÚÒÔ¼°Socks5ЭÒéµÄÓû§Ãû/ÃÜÂëÈÏ֤ģʽ¡£¡£¡£¡£¡£²ÎÊýÆô¶¯¹²°üÀ¨ÈýÖÖÏÂÁî²ÎÊý£¬£¬£¬ £¬£¬£¬ÏÂÁîÐÎʽΪ£º


Mal_Proxy -pport -u user -P password


ÆäÖÐ-pΪָ¶¨µÄÊðÀí°ó¶¨¶Ë¿Ú£¬£¬£¬ £¬£¬£¬-u¡¢-PΪÉèÖÃÓû§Ãû/ÃÜÂëÈÏ֤ģʽ£¬£¬£¬ £¬£¬£¬Èç²»ÉèÖÃĬÒÔΪÎÞÐèÈÏÖ¤·½·¨¡£¡£¡£¡£¡£

V2°æ±¾ÎÞ²ÎÆô¶¯»áĬÈϰó¶¨ÍâµØ28105¶Ë¿Ú£¬£¬£¬ £¬£¬£¬²¢ÒÔÎÞÐèÈÏÖ¤µÄ·½·¨Ö´ÐгÌÐò¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ23£º²ÎÊýÆô¶¯


³ÌÐòÖ´Ðкó»áÔÚ²î±ð½×¶ÎFork¶àỊ̈߳¬£¬£¬ £¬£¬£¬²¢Í¨¹ý²î±ðÏß³ÌÖ´ÐÐÏìÓ¦µÄ¹¦Ð§Ä£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬°üÀ¨ÐÅÏ¢Éϱ¨Ä£¿£¿£¿£¿£¿£¿£¿éºÍÊðÀíЧÀÍÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£


3.2.2 ÐÅÏ¢Éϱ¨Ä£¿£¿£¿£¿£¿£¿£¿é


V2°æ±¾µÄÐÅÏ¢Éϱ¨Ä£¿£¿£¿£¿£¿£¿£¿éͬÑùÇø·ÖÓвκÍÎÞ²ÎÁ½ÖÖģʽ£¬£¬£¬ £¬£¬£¬ÏêϸÉϱ¨ÐÅϢͬ²ÎÊýÄÚÈÝÓйØ¡£¡£¡£¡£¡£¶øV1°æ±¾½öÓÐÒ»ÖÖÉϱ¨·½·¨£¬£¬£¬ £¬£¬£¬¼´V2°æ±¾µÄÎÞ²Îģʽ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ24£ºV1°æ±¾ÐÅÏ¢Éϱ¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ25£ºV2°æ±¾Á½ÀàÐÅÏ¢Éϱ¨·½·¨


ÎÞ²ÎÉϱ¨Êý¾Ý°ü£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ26£ºV2°æ±¾ÎÞ²ÎÉϱ¨Êý¾Ý°ü


ÓвÎÉϱ¨Êý¾Ý°ü£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ27£ºV2°æ±¾ÓвÎÉϱ¨Êý¾Ý°ü


±í9£ºV2°æ±¾Éϱ¨Êý¾Ý°üÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


³ÌÐòÿ¾àÀë300ÃëÑ­»·Ïòhxarasxg.hxarasxg.xyz:38129·¢ËÍÐÄÌø°üÉϱ¨²ÎÊýÐÅÏ¢¡£¡£¡£¡£¡£Í¬Ê±³ÌÐòÄ£ÄâÁËÓòÃûÅÌÎÊÇëÇ󣬣¬£¬ £¬£¬£¬Í¨¹ý¹«¹²Ð§ÀÍDNS£¨8.8.8.8£©À´×ÔÐÐÆÊÎöIP£¬£¬£¬ £¬£¬£¬´Ó¶ø±ÜÃâhosts»òresolv.conf±»¸Ä¶¯»òÐ®ÖÆÔì³ÉµÄDNSÅÌÎÊÒì³£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ28£ºV2°æ±¾ÐÅÏ¢Éϱ¨


3.2.3 ÊðÀíЧÀÍÄ£¿£¿£¿£¿£¿£¿£¿é


ÊðÀíÄ£¿£¿£¿£¿£¿£¿£¿éÏß³ÌÊ×ÏÈ»á°ó¶¨¼àÌýÍâµØÖ¸¶¨¶Ë¿Ú£¨ÊðÀí¶Ë¿Ú£©£¬£¬£¬ £¬£¬£¬²¢Í¨¹ýlisten¡¢acceptµÈ²Ù×÷º¯ÊýÀ´½¨Éè¼àÌý²¢ÎüÊÕ¿Í»§¶ËÇëÇ󡣡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ29£º°ó¶¨¼àÌýÊðÀí¶Ë¿Ú


Ö®ºóÊðÀíÄ£¿£¿£¿£¿£¿£¿£¿é»á½øÒ»²½Õë¶Ô¿Í»§¶ËµÄÇëÇó¾ÙÐÐÅжϺÍУÑ飬£¬£¬ £¬£¬£¬ÀýÈçÕë¶Ô0x05 0x01 0x00 0x03ÄÚÈݵÄУÑ飬£¬£¬ £¬£¬£¬ÊµÔòΪSocks5ЭÒéÈÏÖ¤½×¶ÎµÄÎÕÊÖÀú³Ì£¬£¬£¬ £¬£¬£¬½øÒ»²½ÆÊÎöºó¿ÉÒÔÈ·ÈϸÃÄ£¿£¿£¿£¿£¿£¿£¿éÊÇ»ùÓÚSocks5ЭÒéµÄ¶ñÒâÊðÀí³ÌÐòЧÀͶË¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ30£ºSocks5ЭÒéУÑé


3.2.4 Socks5ЭÒéÏÈÈÝ


Socks5ÊÇÒ»ÖÖÍøÂç´«ÊäЭÒ飬£¬£¬ £¬£¬£¬Ö÷ÒªÓÃÓÚ¿Í»§¶ËÓëÍâÍøÐ§ÀÍÆ÷Ö®¼äͨѶµÄÖÐÐÄת´ï¡£¡£¡£¡£¡£´ËЭÒé²¢²»ÈÏÕæÊðÀíЧÀÍÆ÷µÄÊý¾Ý´«Êä»·½Ú£¬£¬£¬ £¬£¬£¬¶øÊÇÔÚ C/S Á½Í·ÕæÊµ½»»¥Ö®¼ä£¬£¬£¬ £¬£¬£¬½¨ÉèÆðÒ»Ìõ´Ó¿Í»§¶Ëµ½ÊðÀíЧÀÍÆ÷µÄÊÚÐÅÅþÁ¬¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿Í»§¶ËÊ×ÏÈÐèÒªºÍЧÀͶ˾ÙÐÐÎÕÊÖÈÏÖ¤£¬£¬£¬ £¬£¬£¬¿ÉÒÔ½ÓÄÉÓû§Ãû/ÃÜÂëÈÏÖ¤»òÕßÎÞÐèÈÏÖ¤·½·¨£¬£¬£¬ £¬£¬£¬ÎÕÊÖÀֳɺ󼴿ɽøÈëÊý¾Ý´«Êä½×¶Î£¬£¬£¬ £¬£¬£¬Ð­ÒéÔ­ÀíÈçͼ31Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ31£ºSocks5ЭÒéÔ­Àí


ÒÔij´Îͨ¹ýSocks5ÊðÀí´«ÊäµÄ¹¥»÷Ö¸ÁîΪÀý£¬£¬£¬ £¬£¬£¬ÔÚÒѾ­½èÖúÊðÀíЭÒ齨ÉèÅþÁ¬µÄÇéÐÎÏ£¬£¬£¬ £¬£¬£¬C&CÏ·¢µÄ¹¥»÷Ö¸Áî¾­ÊðÀíÍøÂ磨54.188.198.118:9090£©ÖÐתºó´«Êäµ½Bot£¬£¬£¬ £¬£¬£¬´Ëʱ²¶»ñµÄÁ÷Á¿ÊÇÎÞ·¨»ñÈ¡µ½ÕæÊµC&CµØµãµÄ£¬£¬£¬ £¬£¬£¬ÔÚÒ»¶¨Ë®Æ½ÉÏ¿ÉÒÔµÖ´ïÒþ²ØC&CµÄÄ¿µÄ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ32£ºÊðÀí´«Êä¹¥»÷Ö¸ÁîÁ÷Á¿


´ÓÁíÒ»¸ö½Ç¶È˼Á¿£¬£¬£¬ £¬£¬£¬Socks5ЭÒéËäÈ»ÔÚ´«Êä½×¶Î¾ßÓÐÒþ²ØC&CµÄЧ¹û£¬£¬£¬ £¬£¬£¬µ«Æä×÷Ϊ͸Ã÷ÊðÀí²¢²»¾ß±¸¼ÓÃܹ¦Ð§£¬£¬£¬ £¬£¬£¬ÈÏÖ¤ºÍÅþÁ¬½×¶ÎÒ²²¢²»Çå¾²¡£¡£¡£¡£¡£ÈôÊÇÄܹ»Ðá̽ЭÉÌÎÕÊֽ׶εÄÊý¾ÝÁ÷Á¿£¬£¬£¬ £¬£¬£¬ÒÀÈ»Äܹ»ÆÊÎö²¢»ñÈ¡µ½Ñù±¾ÅþÁ¬µÄÕæÊµC&C¡£¡£¡£¡£¡£»£»£»£»ùÓÚÕâЩԵ¹ÊÔ­ÓÉ£¬£¬£¬ £¬£¬£¬Ò»Ð©ºÚ¿Í»¹»á½øÒ»²½Ê¹ÓÃTor ÍøÂçÀ´ÔöÇ¿ÒþÄäÐÔ£¬£¬£¬ £¬£¬£¬ÓÉÓÚTorÍøÂçÿһÌõͨѶÁ´Â·¶¼ÓÉÈô¸ÉËæ»úѡȡµÄTor½Úµã×é³É£¬£¬£¬ £¬£¬£¬ÇÒͨѶÊý¾Ý¾ÙÐÐÁ˶à²ã¼ÓÃÜ£¬£¬£¬ £¬£¬£¬×ÝÈ»»ñÈ¡µ½Tor C&CÒ²ÄÑÒÔËÝÔ´µ½Òþ²ØµÄÕæÊµÐ§ÀÍÆ÷£¬£¬£¬ £¬£¬£¬ÒÔÊÇÔÚÒþÄäÐÔ·½ÃæTorÍøÂçÊǸüºÃµÄÑ¡Ôñ¡£¡£¡£¡£¡£ËäÈ»TorÍøÂçÒ²ÓÐÆäÎó²î£¬£¬£¬ £¬£¬£¬ÓÉÓÚÅþÁ¬µÄÖØ´óÐÔ£¬£¬£¬ £¬£¬£¬TorÍøÂçµÄ´«ÊäËÙÂʺÍÀÖ³ÉÂÊÍùÍùÄÑÒÔ°ü¹Ü¡£¡£¡£¡£¡£×ۺ϶øÑÔ£¬£¬£¬ £¬£¬£¬Ë¼Á¿µ½ÏÖÕæÏàÐÎÖмàÌýÊÜ¿ØÐ§ÀÍÆ÷ÊðÀí¿Í»§¶Ëµ½ÊðÀíЧÀÍÆ÷µÄËùÓÐÁ÷Á¿ÊǺÜÊÇÄÑÌâµÄ£¬£¬£¬ £¬£¬£¬ÒÔÊÇÎÞÂÛÊÇͨË×ÊðÀíÍøÂ磬£¬£¬ £¬£¬£¬ÕվɽøÒ»²½Ê¹ÓÃTorÍøÂç¶¼Äܹ»ÔÚÒ»¶¨Ë®Æ½ÉÏΪ½©Ê¬ÍøÂçÌṩ¸»×ãµÄÒþÄä±£»£»£»£»¤¡£¡£¡£¡£¡£


3.3LeeHozerÆÊÎö


LeeHozerÊÇÒ»Àà½èÖúSocks5ЭÒéÓëTor C&CͨѶµÄÐÂÐͽ©Ê¬¼Ò×壬£¬£¬ £¬£¬£¬ÆäÉè¼ÆÁËÏà¶ÔÑϽ÷¶øÖØ´óµÄͨѶЭÒé¡£¡£¡£¡£¡£ÓÉÓÚÑù±¾ÏÂÔØµØµã(http://exec.elrooted.com/uc/i686)ÓëMal_ProxyC&C(cest4.elrooted.com)ʹÓÃÁËÏàͬµÄ¶þ¼¶ÓòÃû£¬£¬£¬ £¬£¬£¬ÇÒͬÆÚÁ½ÀàÑù±¾¾ù¸üеü´úÁ˲ÎÊýÆô¶¯µÄа汾£¬£¬£¬ £¬£¬£¬ÎÒÃÇÒÔΪ¶þÕßÓÐ׎ÏÇ¿µÄ¹ØÁªÐÔ¡£¡£¡£¡£¡£ÏÂÎÄÒÔV3°æ±¾ÎªÀý¾ÙÐÐÆÊÎö£¬£¬£¬ £¬£¬£¬²¢¶ÔÆä²ÎÊýÆô¶¯¡¢É¨ÃèÄ£¿£¿£¿£¿£¿£¿£¿é¡¢¿ØÖÆÖ¸ÁîµÈ¹¦Ð§µÄ¸üÐÂÉý¼¶ÇéÐξÙÐÐ˵Ã÷¡£¡£¡£¡£¡£


±í10£ºÑù±¾ÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


LeetHozerµÄ¹¥»÷Ä¿µÄÖ÷ÒªÊÇÕë¶ÔIOT×°±¸£¬£¬£¬ £¬£¬£¬Ò»µ©×°±¸ÖØÆô£¬£¬£¬ £¬£¬£¬ÆäÄÚ´æÖеÄBot³ÌÐòÒ²»áËæÖ®ÏûÊÅ¡£¡£¡£¡£¡£ÒÔÊÇLeetHozer»áͨ¹ýÏòwatchdog£¨¿´ÃŹ·£©·¢ËÍ0x80045704À´½ûÓÃwatchdog¹¦Ð§£¬£¬£¬ £¬£¬£¬´Ó¶ø±ÜÃâ×°±¸ÖØÆô¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ33£º½ûÓÃwatchdog


ͬʱ³ÌÐò»áÔÚconsoleÖÐÊä³ö/bin/sh: ./filename: not foundÒÉ»óÓû§£¬£¬£¬ £¬£¬£¬Ö®ºóÖ´Ðж˿ÚɨÃèÉϱ¨£¬£¬£¬ £¬£¬£¬Ð­ÒéУÑéÉÏÏߺ͹¥»÷Ä£¿£¿£¿£¿£¿£¿£¿éµÈ¹¦Ð§¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ34£ºconsoleÊä³ö


3.3.1 Ãô¸ÐÐÅÏ¢¼ÓÃÜ


LeetHozer½ÓÄÉÁË×Ô½ç˵µÄËã·¨¼ÓÃÜ×ÊÔ´ÐÅÏ¢£¬£¬£¬ £¬£¬£¬¼ÓÃÜÃÜԿΪqE6MGAbI¡£¡£¡£¡£¡£Ïà¹ØËã·¨Èçͼ35Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ35£º¼ÓÃÜËã·¨


½âÃܺóµÄ×ÊÔ´ÐÅÏ¢Èç±í11Ëùʾ£º


±í11£º½âÃÜ×ÊÔ´ÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3.3.2 ¶Ë¿ÚɨÃèºÍÐÅÏ¢Éϱ¨


LeeHozer¸´ÓÃÁËMiraiµÄɨÃèÐÎʽ£¬£¬£¬ £¬£¬£¬ÈçɨÃè²¢Éϰ¶ÀֳɺóÔòÉϱ¨×°±¸ÐÅÏ¢£¬£¬£¬ £¬£¬£¬ÇÒ²î±ð°æ±¾¾ßÓвî±ðµÄɨÃèģʽ¡£¡£¡£¡£¡£


±í12£ºÉ¨Ãèģʽ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


V2°æ±¾É¨Ãè9530¶Ë¿Ú£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ36£º9530¶Ë¿ÚɨÃè


V3°æ±¾ÔòÓÐËù²î±ð£¬£¬£¬ £¬£¬£¬Ïà½ÏÓÚ֮ǰµÄ°æ±¾£¬£¬£¬ £¬£¬£¬V3°æ±¾ÔöÌíÁ˲ÎÊýÆô¶¯ÉèÖᣡ£¡£¡£¡£ÈôÊÇÎÞ²ÎÖ´ÐÐÑù±¾£¬£¬£¬ £¬£¬£¬Ä¬Èϲ»»áÖ´ÐÐɨÃ蹦Ч£»£»£»£»¶øÈôÊÇÆô¶¯³ÌÐòʱÌí¼Ótelnet²ÎÊýÔò»á¾ÙÐÐɨÃè²Ù×÷£¨Èç¡°./samples telnet¡±£©


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ37£º23/26¶Ë¿ÚɨÃè


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ38£ºÉϱ¨Reporter


3.3.3 ͨѶЭÒé¼°¹¥»÷Ä£¿£¿£¿£¿£¿£¿£¿é


LeeHozer½¨ÉèͨѶµÄÀú³Ì½ÏÎªÖØ´ó£¬£¬£¬ £¬£¬£¬Ê×ÏÈÆä»áͨ¹ýSocks5ЭÒéÅþÁ¬ÊðÀíÍøÂ磬£¬£¬ £¬£¬£¬´Ó¶ø½øÒ»²½ÓëTor C&C½¨ÉèÅþÁ¬£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ39£ºSocks5ЭÒé½»»¥


ÈôÊÇÄ¿½ñSocksÊðÀíÅþÁ¬Ê§Ð§£¬£¬£¬ £¬£¬£¬³ÌÐò»áËæ»ú´ÓÄÚÖõÄ107¸öÊðÀíÖÐÑ¡ÔñÆäÒ»²¢ÖØÐ½¨ÉèÊðÀíÅþÁ¬£¬£¬£¬ £¬£¬£¬ÄÚÖÃÊðÀíÁбíÈçÏ£º


±í13£ºÊðÀíÁбí

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÕâÅúÊðÀí×ÊÔ´ºÜÓпÉÄܾÍÊÇͨ¹ýMal_Proxy½¨É裬£¬£¬ £¬£¬£¬ËäÈ»£¬£¬£¬ £¬£¬£¬ÆäÖÐÒ²¿ÉÄܰüÀ¨Ò»Ð©¹²Ïí×ÊÔ´ºÍÃâ·Ñ½Úµã¡£¡£¡£¡£¡£

µ±LeeHozerÀֳɺÍC&C½¨ÉèÅþÁ¬ºó£¬£¬£¬ £¬£¬£¬»¹Ðè¾­ÓÉÁ½ÂÖУÑé½»»¥²Å»ªÕæÕýʵÏÖÉÏÏß¡£¡£¡£¡£¡£


µÚÒ»ÂÖУÑ飺

Client->Server£º

УÑéÇëÇó°ü³¤¶ÈΪ255×Ö½Ú£¬£¬£¬ £¬£¬£¬µ«Ö»ÓÐǰ32×Ö½ÚΪÓÐÓÃÄÚÈÝ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ40£ºµÚÒ»ÂÖУÑéÇëÇó°ü


±í14£ºµÚÒ»ÂÖУÑéÇëÇó°üÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÅÌËãУÑéÖµµÄËã·¨Èçͼ41Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ41£ºÅÌËãУÑéÖµ


Server->Client:

¿ØÖƶ˻ذüͬÑùΪ255×Ö½Ú£¬£¬£¬ £¬£¬£¬Ç°32×Ö½ÚÓÐÓᣡ£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ42£ºµÚÒ»ÂÖ¿ØÖƶ˻ذü


¿Í»§¶Ë»áÕë¶Ô»Ø°üµÄÁ½¸ö±ê¼Çλ¾ÙÐÐУÑ飬£¬£¬ £¬£¬£¬»®·ÖΪ0x70f1ºÍ0x4819£¬£¬£¬ £¬£¬£¬Ð£Ñéͨʺó¼ÌÐø¾ÙÐеڶþÂÖ½»»¥¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ43£º±ê¼ÇλУÑé


µÚ¶þÂÖУÑ飺

Client->Server£º

¿Í»§¶ËУÑéÇëÇó°üÈÔΪ255×Ö½Ú£¬£¬£¬ £¬£¬£¬Ç°32×Ö½ÚÓÐÓ㬣¬£¬ £¬£¬£¬²¿·ÖÊý¾ÝÔ´×ÔµÚÒ»ÂÖЧÀͶ˵Ļذü¡£¡£¡£¡£¡£


ͼ44£ºµÚ¶þÂÖУÑéÇëÇó°ü


±í15£ºµÚ¶þÂÖУÑéÇëÇó°üÆÊÎö


Server->Client:

µÚ¶þÑ­»·°üÓëµÚһѭ»·°üÏàËÆ£¬£¬£¬ £¬£¬£¬×ܳ¤255×Ö½Ú£¬£¬£¬ £¬£¬£¬Ç°32×Ö½ÚÓÐÓᣡ£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ45£ºµÚ¶þÂÖ¿ØÖƶ˻ذü


¿Í»§¶Ë¶Ô0x70F2ºÍ0x2775Á½¸ö±ê¼ÇλУÑéÀֳɺ󣬣¬£¬ £¬£¬£¬½©Ê¬µÄÉÏÏßÀú³Ì²ÅËãÍê³É£¬£¬£¬ £¬£¬£¬Ö®ºó½©Ê¬ÆÚ´ý¿ØÖƶËÏ·¢Ö¸Á£¬£¬ £¬£¬£¬ÆäÖÐÖ¸ÁîµÄÊ××Ö½ÚÖ¸¶¨ÁË¿ØÖÆÖ¸ÁîÀàÐÍ¡£¡£¡£¡£¡£


¿ØÖÆÖ¸Áî¹²°üÀ¨ÈýÀࣺ


±í16£º¿ØÖÆÖ¸ÁîÀàÐÍ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x00 ÐÄÌø°ü£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ46£ºÐÄÌø°ü


0x01 ·¢ËͱêʶÐÅÏ¢£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ47£º·¢ËͱêʶÐÅÏ¢


ÈçÊ××Ö½ÚΪÆäËüÖµ£¬£¬£¬ £¬£¬£¬Ôò»áÆÊÎöÏêϸµÄÖ¸ÁЧ£¬£¬£¬ £¬£¬£¬LeetHozer²î±ð°æ±¾µÄ¹¦Ð§Ö¸ÁîÈç±í18Ëùʾ£º


±í17£º¹¦Ð§Ö¸Áî±í

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ48£ºV3°æ±¾¹¥»÷Ö¸ÁîÅжÏ


ÎÒÃÇÊӲ쵽£¬£¬£¬ £¬£¬£¬½üÆÚLeeHozerÈÔÔÚÒ»Á¬Õö¿ª¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬¹¥»÷Ö¸ÁîÈçͼ48Ëùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ49£º¹¥»÷Ö¸ÁîÊý¾Ý°ü


±í18£º¹¥»÷Ö¸ÁîÊý¾ÝÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ËÝÔ´Óë¹ØÁª


ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬ £¬£¬£¬LeeHozerÔÚ´úÂëÖжദʹÓÃÁËÓëvbrxmrÏà¹ØµÄ×Ö·û´®£¬£¬£¬ £¬£¬£¬ÀýÈç¡®GET /vbrxmr/i586 HTTP/1.0¡¯¡¢¡®/bin/busybox VBRXMR¡¯£¬£¬£¬ £¬£¬£¬ÒÔ¼°C2£¨vbrxmrhrjnnouvjf.onion£©µÈ¡£¡£¡£¡£¡£ÓëÖ®Ïà¹ØµÄ£¬£¬£¬ £¬£¬£¬Hoaxcalls(XTC)½©Ê¬ÍøÂçÔøÊ¹ÓÃcbc.vbrxmr.pw×÷ΪC2£¬£¬£¬ £¬£¬£¬´úÂëÖÐÒ²·ºÆð¹ývbrxmr×Ö·û´®£¬£¬£¬ £¬£¬£¬ÇÒͬÑù¿ÉÒÔ½èÖúÊðÀíÍøÂçͨѶ£¨¾ß±¸Fastflux¹¦Ð§£©£¬£¬£¬ £¬£¬£¬VbrxmrµÄƵÈÔ·ºÆðÒ²²»µÃ²»ÈÃÈËÏÓÒÉÁ½ÕßÖ®¼ä±£´æÒ»¶¨µÄ¹ØÁª¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ50£ºHoaxcalls×Ö·û´®


±ðµÄ£¬£¬£¬ £¬£¬£¬Í¨¹ýËÑË÷LeeHozerµÄ¼ÓÃÜÃÜÔ¿qE6MGAbI£¬£¬£¬ £¬£¬£¬»¹·¢Ã÷ÁËÁíÒ»ÖÖʹÓÃÊðÀíͨѶµÄÑù±¾£¬£¬£¬ £¬£¬£¬ÇÒÆäʹÓõÄÊðÀíÁбíÒ²ºÍLeeHozerÓв¿·ÖÖØºÏ¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ͼ51£ºÄ³ÊðÀíÑù±¾×Ö·û´®


ÀàËÆµÄ¹ØÁªÅú×¢ÕâЩʹÓÃÊðÀíµÄ½©Ê¬ÍøÂç¿ØÖÆÕß¼ä»ò¶à»òÉÙ±£´æ×ÅһЩÁªÏµ£¬£¬£¬ £¬£¬£¬ºÚ¿ÍÃǺܿÉÄÜÔÚµØÏÂÂÛ̳ÉúÒâÊðÀí×ÊÔ´¡¢¹²Ïí´úÂë»òÊÇͨ¹ý´úÂëÄ£ÄâÀ´ÒÉ»óÑо¿Ö°Ô±¡£¡£¡£¡£¡£


ËÄ¡¢×ܽá


Ëæ×ÅÎïÁªÍøÊ±´úµÄ¿ìËÙÉú³¤£¬£¬£¬ £¬£¬£¬Çå¾²¶Ô¿¹Ò²ÔÚÒ»Ö±Éý¼¶ºÍ½ø»¯¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉÒÔ¿´µ½£¬£¬£¬ £¬£¬£¬Ô½À´Ô½¶àµÄ¹¥»÷ÕßʵÑé´Ó¸ü¶àµÄά¶È¿ªÕ¹¹¥»÷»î¶¯ºÍÇå¾²¶Ô¿¹¡£¡£¡£¡£¡£Ò»·½Ã棬£¬£¬ £¬£¬£¬Ô½À´Ô½¶àµÄ¹¥»÷Õß×îÏȽèÖúÊðÀíÍøÂçÀ´ÔöÇ¿ÒþÄäÇå¾²£¬£¬£¬ £¬£¬£¬ÊðÀí×ÊÔ´×÷ΪÒþÄäC&CµÄǰÖÃÍøÂçÎÞÒÉÊÇÒ»¸öÖØ´óµÄÍþвºÍÒþ»¼£»£»£»£»ÁíÒ»·½Ã棬£¬£¬ £¬£¬£¬Ò²·ºÆðÁËʹÓöñÒâÑù±¾ÊµÏÖÓÕ²¶¼à²âºÍ·´Ì½²âÄÜÁ¦µÄÓ¦ÓÃÐÂ˼Ð÷£¬£¬£¬ £¬£¬£¬ÕâЩ¶¼»á¸øÎïÁªÍø×°±¸µÄÇå¾²·À»¤ºÍÑо¿ÊÂÇé´øÀ´¸ü¶àµÄת±ä£¬£¬£¬ £¬£¬£¬ºóÐøÎÒÃÇÒ²»á¾ÙÐÐÒ»Á¬µÄ¹Ø×¢ºÍ×·×Ù¡£¡£¡£¡£¡£


IOCÐÅÏ¢


Moobot£º


URL :

http://exec.elrooted.com/ab/i686

http://conn.elrooted.com/li/arm

http://91.92.66.87:80/420/adb/x86

http://185.163.46.6/a/x86_64

http://5.252.179.60/b/x86_64

http://185.172.110.224/ab/i586


C2£º

proxy.2u0apcm6ylhdy7s.com

abcdefg.elrooted.com

park.elrooted.com

frsaxhta.elrooted.com

cccc.elrooted.com

205.185.114.231

185.172.110.224


Reporter IP£º

gfedcba.elrooted.com

hello.elrooted.com


HASH£º

1a64cd13d9c71542ce60183356a615505f10ddc192eded5fce0f0075f3ad7648

ca3889994301f28baa791f4ef1aa473b0bc6e975cda703195787872795171869

e9a7aab3ab25c0a091d98d3ae4a313fba3b3bd0588bfe8e3624ec016bc11f02e

2516bdc3ae3818e30e1145f75811937e29ce10f94722c6da1ea7c28f4c0bc3dc

a6e18135a2afcd96957bff63388501465f5a1203b2d22ee0f1074661e286d9e3

59b1ca2d47af1d5b60b84c3a9d6a64a09b7340864b9e90247466d7f91ed53b84

d5d5488ae9c80558cc4634ce6d51837d82347fd48d1a665e606dcfbfdf638b7b


Mal_Proxy£º


URL £º

http://proxy.2u0apcm6ylhdy7s.com/b/x86_64

http://proxy.2u0apcm6ylhdy7s.com/b/armv7l


C2£º

hxarasxg.hxarasxg.xyz

cest4.elrooted.com

da.elrooted.com

185.172.110.240


HASH£º

a67f79c7ae6b1177309cb328d3ec93ec91960edf457a4f5a74120baaf80139ee       V2

04114bd136941811e355df28e9b2eeaa941a04b61b185fd214a4c54daa171e1c     V2

80f1973b82cbea485f27eb8c44983c565701fdc4e6d3e994ed57bf57a66b9c81     V2

f91427e74a84c34d329116443fa1c89c63dab57e01129345a9f9ed364533dd49     V1

4ed3c601022b4d8c1478521241b847dcacecd837bc75547f3a378ee9d5b9e15f    V1

b41de82ea89e2ceedda5b4a856c273c4ce06429d876ee4a05ee9a2423741461f      V1


LeeHozer£º


C2£º

vbrxmrhrjnnouvjf.onion:31337

37.49.226.171:31337

w6gr2jqz3eag4ksi.onion:31337


Reporter IP:

report.infidel.ml:9814


HASH£º

84efc5ce8a0729b1248b5f7a43ddf371f517ac0a0eea0a5b0674ce195be61b8e  v3

ca8095af62b836f3ddd12007bc8cb67cdd39266c3d40179691f9ee1ca94e9428 v2

1c5349696c04dfa8e0f458ad1d9aa360f4768b21d3dd83fb98d935691b1b2a88  v1


²Î¿¼ÎÄÏ×£º


1.https://blog.radware.com/security/botnets/2020/05/whos-viktor-tracking-down-the-xtc-polaris-botnets/

2.https://blog.netlab.360.com/the-leethozer-botnet-en/

3.https://www.exploit-db.com/exploits/48225

4.https://blog.netlab.360.com/multiple-botnets-are-spreading-using-lilin-dvr-0-day/

5.https://habr.com/en/post/486856/


Ô­ÎÄȪԴ£ºÍøÂçÇå¾²Ó¦¼±ÊÖÒÕ¹ú¼Ò¹¤³ÌʵÑéÊÒ


±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓë¼øºÚµ£±£Íø¼¯ÍÅADLab¹¥·ÀʵÑéÊÒÁªºÏÐû²¼


¼øºÚµ£±£ÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬ £¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬ £¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬ £¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬ £¬£¬£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬£¬£¬ £¬£¬£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î800Óà¸ö£¬£¬£¬ £¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØÏµÍ³Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£¡£¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵È¡£¡£¡£¡£¡£



¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨