2020-04-21

Ðû²¼Ê±¼ä 2020-04-21

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win.BACKSPACE/Lecna_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

BACKSPACEÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬ £¬£¬Ò²¾ÍÊÇ"Lecna"£¬£¬£¬£¬ £¬£¬¹¦Ð§ºÜÊÇǿʢ£¬£¬£¬£¬ £¬£¬¿ÉÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£¡£

BACKSPACE¿ÉÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬£¬ÈçÅÌËã»úÃû³Æ¡¢ÏµÍ³°æ±¾£¬£¬£¬£¬ £¬£¬IPµØµãµÈ£¬£¬£¬£¬ £¬£¬¾ßÓÐÀú³ÌÖÎÀí¡¢ÎļþÖÎÀí¡¢×¢²á±íÖÎÀí¡¢Ö´ÐÐÏÂÁîµÈ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200421











ÊÂÎñÃû³Æ£º

TCP_ľÂí_Sidewinder.PreBotModules_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ Sidewinder.PreBotModules ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅ Sidewinder.PreBotModules¡£¡£¡£¡£¡£¡£

PreBotModules ÊÇAPT×éÖ¯"ÏìβÉß"£¨SideWinder¡¢T-APT-04£©ÓÃc#дµÄÐÅÏ¢ÍøÂçÄ£¿£¿£¿£¿é£¬£¬£¬£¬ £¬£¬¸ÃºóÃÅÄ£¿£¿£¿£¿éͨ³£Ê¹ÓÃOfficeÓÕ¶üÎĵµÏ·¢£¬£¬£¬£¬ £¬£¬Ö²ÈëÖ÷»úºó»áÍøÂçÊܺ¦Ö÷»úµÄÅÌËã»úÃû¡¢Óû§Ãû¡¢MACµØµã¡¢ÆôÓõÄЧÀͺÍÀú³Ì¡¢¸üв¹¶¡µÈÖ¸ÎÆÐÅÏ¢·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200421











ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_FakeSanforUD_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFakeSanforUD¡£¡£¡£¡£¡£¡£

ÉîÐÅ·þVPN¿Í»§¶Ë±£´æÎó²î£¬£¬£¬£¬ £¬£¬ÔÚÉý¼¶Ê±»áÏÂÔØÖ´ÐÐÃûΪSangforUD.exeµÄ¸üгÌÐò¡£¡£¡£¡£¡£¡£µ«VPN¿Í»§¶Ë½ö¶ÔSangforUD.exe×öÁ˼òÆÓµÄ°æ±¾±ÈÕÕ£¬£¬£¬£¬ £¬£¬Ã»ÓÐ×öÈκεÄÇå¾²¼ì²é¡£¡£¡£¡£¡£¡£APT×éÖ¯Darkhotel¹¥ÆÆÁËVPNЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬¸Ä¶¯Éý¼¶ÉèÖÃÎļþ²¢°ÑSangforUD.exeÌæ»»Îª¶ñÒâµÄºóÃÅFakeSanforUD¡£¡£¡£¡£¡£¡£

FakeSanforUDÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬ £¬£¬Í¨¹ýÏÂÔØÖ´ÐÐshellcode£¬£¬£¬£¬ £¬£¬×îÖÕÏÂÔØ½¹µãµÄºóÃŶñÒâ×é¼þthinmon.dll¡£¡£¡£¡£¡£¡£½¹µãºóÃÅ×é¼þthinmon.dll»á½âÃÜÔÆ¶ËÏ·¢µÄÁíÍâÒ»¸ö¼ÓÃÜÎļþSangfor_tmp_1.dat£¬£¬£¬£¬ £¬£¬ÒÔ¼ÓÔØ¡¢Ïß³ÌÆô¶¯¡¢×¢ÈëÀú³Ì3ÖÖ·½·¨ÖеÄÒ»ÖÖÆô¶¯datÎļþ £¬£¬£¬£¬ £¬£¬×îÖÕÓÉdatÎļþʵÏÖÓëЧÀÍÆ÷½»»¥Ö´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200421















ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200421