ÆÆ¿Ç¶ø³ö£ºÈ«ÐÂÎïÁªÍø½©Ê¬ÍøÂçAuthBot¸¡³öË®Ãæ
Ðû²¼Ê±¼ä 2023-08-07¼øºÚµ£±£ÍøÓë¹ãÖÝ´óÑ§Íø°²Ñ§Ôº·¢Ã÷ÁËÒ»¸öеÄÎïÁªÍø½©Ê¬ÍøÂ磬£¬£¬£¬²¢½«ÆäÃüÃûΪAuthBot¡£¡£¡£¡£¡£¡£¡£±¾ÎÄͨ¹ý¶Ô¸Ã½©Ê¬ÍøÂç¾ÙÐÐÑù±¾ÊÖÒÕÆÊÎö£¬£¬£¬£¬ÖÜÈ«ÏÈÈÝÁËÆäÖ´ÐÐÁ÷³Ì¡¢Í¨Ñ¶ÐÒé¡¢¿ØÖÆÏÂÁîµÈϸ½Ú£¬£¬£¬£¬ÒÔ×÷Ϊ¸÷ÐÐÒµ¼°Ïà¹ØÆóÒµÖÆ¶©ÍøÂçÇå¾²Õ½ÂԵIJο¼¡£¡£¡£¡£¡£¡£¡£
2023Äê7ÔÂ⣬£¬£¬£¬¼øºÚµ£±£ÍøÔÚ¼ÓÈë¹ú¼ÒÖØµãÑз¢ÍýÏëÏîÄ¿¡°´ó¹æÄ£Òì¹¹ÎïÁªÍøÍþв¿É¿Ø²¶»ñÓëÆÊÎöÊÖÒÕ£¨2022YFB3104100£©¡±µÄÑо¿Àú³ÌÖУ¬£¬£¬£¬·¢Ã÷ÁËÒ»¸öеÄÎïÁªÍø½©Ê¬ÍøÂç¼Ò×å¡£¡£¡£¡£¡£¡£¡£ÔÚVirusTotalÉÏ£¬£¬£¬£¬´ó²¿·Öɱ¶¾ÒýÇæ½«Æäʶ±ðΪMirai»òÕßGafgyt¡£¡£¡£¡£¡£¡£¡£¾ÓÉÏêϸÆÊÎö£¬£¬£¬£¬È·ÈÏÍêȫûÓи´ÓÃMirai¡¢GafgytµÄÈκÎÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£
¼øÓÚÑù±¾°üÀ¨×Ö·û´®AuthBot£¬£¬£¬£¬ÇÒ»á¼ÓÃÜ×÷ΪÉÏÏßÊý¾Ý·¢Ë͸øC2£¬£¬£¬£¬ÎÒÃǽ«ÆäÃüÃûΪAuthBot¡£¡£¡£¡£¡£¡£¡£AuthBotÉè¼ÆÁË×Ô½ç˵¼ÓÃÜËã·¨ÓÃÓÚ¼ÓÃܺÍC2µÄͨѶ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬Æä¹¦Ð§²¢²»ÍêÉÆ£¬£¬£¬£¬Ö»ÊµÏÖÁËÐÄÌøµÈÓÐÏÞ¹¦Ð§£¬£¬£¬£¬²¢²»°üÀ¨DDoS¹¥»÷µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ÓÐÀíÓÉÏàÐÅ£¬£¬£¬£¬ÎÒÃÇÕýÔÚ¼ûÖ¤Ò»¸öÈ«ÐÂÎïÁªÍø½©Ê¬ÍøÂçµÄ¡°ÆÆ¿Ç¶ø³ö¡±¡£¡£¡£¡£¡£¡£¡£
Ñù±¾ÊÖÒÕÆÊÎö
ÏÖÔÚAuthBotÖ»Ö§³Öamd64£¬£¬£¬£¬ÔÝʱû·¢Ã÷ÆäËüCPU¼Ü¹¹µÄÑù±¾¡£¡£¡£¡£¡£¡£¡£AuthBot½ÓÄÉUPX¼Ó¿Ç£¬£¬£¬£¬²¢¸Ä¶¯UPX»ÃÊýÀ´¶Ô¿¹Íѿǡ£¡£¡£¡£¡£¡£¡£½«UPX»ÃÊý¡°YTS\x99¡±ÖØÐ¸ÄΪ¡°UPX!¡±£¬£¬£¬£¬¼´¿ÉÀÖ³ÉÍѿǡ£¡£¡£¡£¡£¡£¡£
1¡¢Ö´ÐÐÁ÷³Ì
ºÍ´ó´ó¶¼½©Ê¬ÍøÂç²î±ð£¬£¬£¬£¬AuthBot»áÊ×ÏÈÅþÁ¬C2£¬£¬£¬£¬ÅþÁ¬Ê§°ÜÍ˳öÀú³Ì¡£¡£¡£¡£¡£¡£¡£ÔÚºÍC2½¨ÉèͨѶ֮ºó£¬£¬£¬£¬²ÅÖ´ÐÐÆäËü²Ù×÷£¬£¬£¬£¬ÈçÐÞ¸Ä×ÔÉíÀú³ÌÃûµÈ¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÓÉÓÚËüÓ²±àÂëµÄ¼ÓÃÜ×Ö·û´®ÐèÒªÓõ½C2·µ»ØµÄÃÜÔ¿À´½âÃÜ¡£¡£¡£¡£¡£¡£¡£AuthBotµÄC2µØµãÖ±½ÓʹÓöþ½øÖƾÙÐи³Öµ£¬£¬£¬£¬¶ø·Ç×Ö·û´®¡£¡£¡£¡£¡£¡£¡£
ÔÚºÍC2ЧÀÍÆ÷½¨ÉèͨѶ֮ºó£¬£¬£¬£¬Ö´ÐÐÆô¶¯Á÷³Ì£º½âÃÜ×Ö·û´®×ÊÔ´¡¢·¢ËÍCPU¼Ü¹¹Ãû³Æµ½C2ЧÀÍÆ÷¡¢Àú³ÌÃûαװ¡¢×Ô¿½±´ÖÁ/usr/bin/BoxBusy¡£¡£¡£¡£¡£¡£¡£
Ëæºó½øÈëÑ»·£¬£¬£¬£¬Ö´ÐÐselectº¯Êý£¬£¬£¬£¬ÎüÊÕÖ´ÐÐC2Ï·¢µÄÖ¸Áî¡£¡£¡£¡£¡£¡£¡£ÐèÒªÖ¸³öµÄÊÇ£¬£¬£¬£¬ÔÚÑ»·º¯ÊýÀ£¬£¬£¬AuthBot»á»ñÈ¡¸¸Àú³ÌËù·¿ªµÄÎļþÃû³Æ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇËù·¿ªµÄÎļþÃû³Æ°üÀ¨¡°/proc/¡±»òÕß¡°socket:[¡±£¬£¬£¬£¬Ôò°Ñ¸¸Àú³ÌÃû³Æ¼ÓÃÜ·¢Ë͸øC2£¬£¬£¬£¬Í¬Ê±ÊµÑékill¸¸Àú³Ì¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÔÚʵÑé¼ì²âµ÷ÊÔÆ÷»òÕßɳÏäɳÏäÇéÐÎÌØÕ÷¡£¡£¡£¡£¡£¡£¡£
2¡¢Í¨Ñ¶ÐÒé
AuthBotºÍC2µÄͨѶÐÒé²¢²»Öش󣬣¬£¬£¬Ö»ÐèÒª4ÂÖ¼´¿ÉÓëC2½¨ÉèͨѶ¡£¡£¡£¡£¡£¡£¡£AuthBotºÍC2µÄͨѶÊý¾Ý¾ÓÉÁ½²ã¼ÓÃÜ£¬£¬£¬£¬Íâ²ãÊÇÒì»ò£¬£¬£¬£¬ÄÚ²ã½ÓÄÉÆä×Ô¼ºÊµÏÖµÄÊýѧÔËËã·½·¨¼ÓÃÜ£¬£¬£¬£¬Ïêϸ¼Ó¡¢½âÃÜËã·¨µÄα´úÂë»®·ÖÈçÏ£º
ÒÔÏÂÊÇÔËÐÐÑù±¾ÏÖʵÁ÷Á¿£º
Step1£ºBot¡úC2
AuthBotÌìÉú8µ½15×Ö½ÚµÄËæ»ú×Ö·û´®×÷ΪXORÃÜÔ¿£¬£¬£¬£¬ÓÃÓÚºóÐøÍ¨Ñ¶¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£½Ó×ÅÒì»ò¼ÓÃÜ×Ö·û´®"AuthBot "£¬£¬£¬£¬°ÑXORÃÜÔ¿×Ö·û´®ºÍÃÜÎÄÆ´½ÓÆðÀ´£¬£¬£¬£¬²¢Ê¹ÓÃ×Ô½ç˵Ëã·¨¼ÓÃÜËüÃÇ£¬£¬£¬£¬·¢ËÍÖÁC2¡£¡£¡£¡£¡£¡£¡£
ÒÔÉÏÊö½ØÍ¼ÀïµÄÊý¾ÝΪÀý£¬£¬£¬£¬¡°a78f928fa5a799979d9daa908e8f9b28421a160d431e256f¡±¾ÓÉÄÚ²ãËã·¨½âÃܺóÊÇ¡°7763666375776B696F6F786462636D203616120B37181F49¡±¡£¡£¡£¡£¡£¡£¡£
Step2£ºC2¡úBot
C2·µ»Ø17×Ö½Ú¼ÓÃÜÊý¾Ý£¬£¬£¬£¬¾ÓÉÒì»òºÍ×Ô½ç˵Ëã·¨½âÃܺóΪ¡°Accepted GoAwayMr¡±¡£¡£¡£¡£¡£¡£¡£Ç°8×Ö½Ú¡°Accepted¡±Åú×¢ÅþÁ¬C2Àֳɣ¬£¬£¬£¬ ¡°GoAwayMr¡±Í¬ÑùÊÇÃÜÔ¿£¬£¬£¬£¬ÓÃÓÚ½âÃÜ×ÔÉí¼ÓÃÜ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£
ÒÔÉÏÊö½ØÍ¼ÀïµÄÊý¾ÝΪÀý£¬£¬£¬£¬¡°12ece9f2d5d3faf94704e501c5eec604c1¡±¾ÓÉÒì»ò½âÃÜÖ®ºó£¬£¬£¬£¬ÊÇ¡°658f8f91a0a49190286b9d65a78dab73a2¡±¡£¡£¡£¡£¡£¡£¡£
¡°658f8f91a0a49190286b9d65a78dab73a2¡±¾ÓÉ×Ô½ç˵Ëã·¨½âÃܺóÕýÊÇ¡°Accepted GoAwayMr¡±¡£¡£¡£¡£¡£¡£¡£×Ô½ç˵Ëã·¨½âÃÜÈçÏ£º
Step3£ºBot¡úC2
AuthBotÆ´½ÓCPU¼Ü¹¹×Ö·û´®¡°x86_64¡±ºÍ¡°yarn¡±£¬£¬£¬£¬¾ÓÉÁ½²ã¼ÓÃÜ·¢Ë͸øC2¡£¡£¡£¡£¡£¡£¡£
Step4£ºBot¡úC2
AuthBotÏòC2·¢ËÍ×ÔÉíÀú³ÌµÄһЩȨÏÞÐÅÏ¢µÈ£¬£¬£¬£¬ÈçÊÇ·ñ¶Ô/usr/bin/Ŀ¼ÓÐдȨÏÞ£¬£¬£¬£¬ÊÇ·ñΪrootȨÏÞÔËÐеȡ£¡£¡£¡£¡£¡£¡£È¨ÏÞÊý¾ÝÖ»¾ÓÉÁËXOR¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£XOR½âÃÜÈçÏ£º
ÆäÖÐÊ××Ö½ÚΪÊÇÓ²±àÂëµÄ\x04£¬£¬£¬£¬µÚ¶þ×Ö½Ú\x00ÌåÏÖÊÇrootȨÏÞÔËÐУ¬£¬£¬£¬µÚÈý×Ö½ÚÊÇÓ²±àÂëµÄ\x01£¬£¬£¬£¬µÚ4×Ö½Ú\x00ÌåÏÖ¶Ô/usr/bin/Ŀ¼ÓÐдȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÆäÓà8×Ö½ÚÊÇ\x00¡£¡£¡£¡£¡£¡£¡£
ÖÁ´Ë£¬£¬£¬£¬AuthBotÉÏÏßÀֳɣ¬£¬£¬£¬×îÏÈÆÚ´ýÖ´ÐÐC2Ï·¢µÄÖ¸Áî¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚΪֹ£¬£¬£¬£¬Ö»ÊÕµ½¹ýC2·µ»ØµÄÁ½×Ö½ÚÐÄÌøÊý¾Ý\x76\x63£¬£¬£¬£¬Òì»ò½âÃܺóÊÇ\x01\x00¡£¡£¡£¡£¡£¡£¡£ÐÄÌøÊý¾ÝºÍ¿ØÖÆÏÂÁîÊý¾Ý¶¼ÊÇÖ»ÓÐÒ»²ãXORÒì»ò¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£
3¡¢¿ØÖÆÏÂÁî
ÏÖÔÚ£¬£¬£¬£¬AuthBotÖ»Ö§³Ö°üÀ¨ÐÄÌøÔÚÄÚµÄ3Àà¿ØÖÆÏÂÁî¡£¡£¡£¡£¡£¡£¡£
1¡¢IPµØµãÏ·¢£ºµ±C2·µ»ØµÄÊý¾Ý³¤¶È´óÓÚ10×Ö½Ú£¬£¬£¬£¬½«Æ«ÒÆ1ÆðʼµÄÊý¾ÝÆÊÎöΪip:portÐÎʽµÄ×Ö·û´®²¢ÉúÑÄ£¬£¬£¬£¬ÖÁ¶àÉúÑÄ4¸ö¡£¡£¡£¡£¡£¡£¡£¸ÃÏÂÁîÏÖÔÚÖ»ÓÃÀ´²âÊÔÑù±¾¶ÔIPµÄÆÊÎöÊÇ·ñ׼ȷ£¬£¬£¬£¬ºóÐøºÜ¿ÉÄÜÓÃÓÚÆÊÎöDDoS¹¥»÷Ä¿µÄ»ò»ØÁ¬C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
2¡¢ÐÄÌø£ºµ±C2·µ»ØµÄÊý¾Ý³¤¶ÈСÓÚ¼´ÊÇ10×Ö½Ú²¢ÇÒÊ××Ö½ÚΪ\x01£¬£¬£¬£¬ÔòÈ϶¨ÊÇÐÄÌø°ü£¬£¬£¬£¬Ö±½Ó·µ»ØC2ÏàͬµÄÐÄÌø°üÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
3¡¢É¾³ýIPµØµã£ºµ±C2·µ»ØµÄÊý¾Ý³¤¶ÈСÓÚ¼´ÊÇ10×Ö½Ú²¢ÇÒÊ××Ö½ÚΪ\x00£¬£¬£¬£¬É¾³ý¶ÔÓ¦ÒÑÉúÑĵÄIPµØµã¡£¡£¡£¡£¡£¡£¡£
×ܽá
×ܵÄÀ´¿´£¬£¬£¬£¬AuthBotµÄ¹¦Ð§»¹ºÜ²»ÍêÉÆ£¬£¬£¬£¬²»°üÀ¨DDoS¹¥»÷¹¦Ð§£¬£¬£¬£¬Ò²Ã»ÓÐÏÂÔØ¡¢shellµÈÆäËü¹¦Ð§¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ¹ØÓÚ·ÇÐÄÌø°üµÄÁíÍâÁ½Àà¿ØÖÆÏÂÁ£¬£¬£¬ºÜÄÑÃ÷È·¹¥»÷ÕßµÄÕæÊµÒâͼ¡£¡£¡£¡£¡£¡£¡£
²»¹ýÕÕ¾ÉÓÐһЩÁÁµã£¬£¬£¬£¬ºÃ±ÈÐÂÓ±µÄÁ½´Î¼ÓÃÜ£¬£¬£¬£¬ÓÈÆäÊÇͨ¹ýC2·µ»ØµÄÃÜÔ¿À´½âÃÜ×ÔÉí¼ÓÃÜ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ËüµÄ´úÂëÀïÒ²¿´²»³ö³£¼û½©Ê¬ÍøÂç¶ÔMirai¡¢Gafgyt´úÂëµÄ¸´Óᣡ£¡£¡£¡£¡£¡£
Òò´Ë£¬£¬£¬£¬ÎÒÃÇÒÔΪAuthBotÊÇȫеÄÎïÁªÍø½©Ê¬ÍøÂ磬£¬£¬£¬µ«»¹Ö»ÊǸոսµÉúµÄ³õ¼¶½×¶Î¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇ»áÒ»Á¬¼à¿ØAuthBotеÄÑݱäÉú³¤¡£¡£¡£¡£¡£¡£¡£
IOC
C2£º
190[.]10[.]8[.]179:8008
MD5£º
7fd6f1ffceb010e4607198d1d4a527c3