¡¾ÍøÂçÕ½¡¿ÎÚ¿ËÀ¼Õ½ÕùϵÄ×îÐÂÍøÂç¹¥»÷»î¶¯×ۺϳÂËß
Ðû²¼Ê±¼ä 2022-04-29Ò»¡¢Åä¾°
×Ô2022Äê2ÔÂ24ÈÕ¶íÎÚ³åÍ»Éý¼¶ÎªÈ«ÃæÕ½Õùºó£¬¶íÂÞ˹ÊÔͼͨ¹ý¡°ÉÁµçÕ½¡±µÄÕ½Êõ¿ìËÙ½áÊøÕ½ÕùµÄÄ¿µÄÂä¿Õ£¬Ö±µ½2¸ö¶àÔµĽñÌ죬´Ë´ÎÕ½ÕùÈÔ´¦ÓÚ½º×Å״̬£¬¶íÎÚË«·½¾ùÔâÊܵ½Á˷dz£ÑÏÖصÄËðʧºÍÉËÍö¡£ÔڲпáµÄÕ½Õù֮ϣ¬Ë«·½ÈÔÈ»²»Í£µØÔÚÍøÂçÕ½³¡ÉϽøÐÐ׿¤ÁҵĽÏÁ¿¡£ÔÚÕ½Õù·¢×÷µ±ÈÕ£¬¶«Éƽ̨ADLab¾Í¶ÔË«·½ÍøÂçÕ½Ïà¹ØµÄÍþвÇ鱨½øÐÐÁËÕûÀí£¬¶øÇÒ¶ÔÎÚ¿ËÀ¼±³ºóµÄÍøÂç¹¥»÷ºÍÏà¹ØÇ鱨»î¶¯½øÐÐÉîÈë·ÖÎö£¬Ðû²¼ÁËÏà¹Ø·ÖÎöÎÄÕ¡¶ÎÚ¿ËÀ¼Õ½Õù±³ºóµÄÍøÂç¹¥»÷ºÍÇ鱨»î¶¯¡·£»ÔÚ3Ô·ÝÎÒÃÇÓ¦Ñû׫дÁË¡¶¡¾ÍøÂçÕ½¡¿´ÓÎÚ¿ËÀ¼Õ½Õù̸ÏÖ´úÕ½ÕùµÄµÚ¶þÕ½³¡¡·µÄ³¤Æª³ÂËߣ¬½áºÏÀúÊ·ÉϵĶÔÕ½ÕùÆð×ÅÒªº¦×÷ÓõÄÍøÂçÕ½°¸ÀýÒÔ¼°ÎÚ¿ËÀ¼ºÍ¶íÂÞ˹֮¼ä³¤´ï30ÄêµÄÍøÂç·´¿¹°¸Àý£¬È«Ãæ·ÖÎöÁËÏÖ´úÕ½ÕùϵÄÍøÂçÕ½¼¼Êõ¡¢Ë¼Ïë¡¢×÷Óü°Ó°Ï죻½üÆÚ£¬ÎÒÃÇÓÖ½ÓÁ¬²¶×½µ½¶àÆðÕë¶ÔÎÚ¿ËÀ¼Õþ¸®ºÍµ¥ÔªµÄÍøÂç¹¥»÷»î¶¯£¬¹¥»÷Õß½èÒÔ¡°ÎÚ¿ËÀ¼·ÀÓù·½Ê½¡±¡¢¡°ÎÚ¿ËÀ¼³ÂËß_×îÖÕ¡±¡¢¡°ÈÕÒæÅÓ´óµÄ¶íÎÚΣ»ú½âÊÍ¡±ºÍ¡°Ð¹Â¶µÄ¿ËÀïÄ·ÁÖ¹¬µç×ÓÓʼþÏÔʾÃ÷˹¿ËÐÒ顱µÈ¾ßÓи߶ÈÃÔ»óÐÔµÄÈȵãÓÕ¶üÎĵµ½øÐй¥»÷£¬ÊÔͼÇÔÈ¡Ïà¹ØÕþ¸®µ¥ÔªµÄ»úÃÜÐÅÏ¢¡£
±¾ÎĽ«¶Ô×ÔÕ½ÕùÒÔÀ´ÎÒÃÇËù¼à¿Øµ½µÄÍøÂç¹¥»÷ʼþ½øÐÐÊáÀíºÍ»ã×Ü£¬Í¬Ê±´Ó¶à¸ö½Ç¶È³ö·¢£¬¶Ô²¿ÃŵäÐ͵ÄÍøÂç¹¥»÷ʼþ½øÐÐÉîÈëÆÊÎö¡£
¶þ¡¢½üÆÚ¹¥»÷ʼþ»Ø¹Ë
×ÔÕ½Õù·¢×÷ÒÔÀ´£¬ÍøÂç¿Õ¼ä¾Í³ÉÁ˶íÎÚË«·½²©Þĺͽ»·æµÄµÚ¶þÕ½³¡£¬Æ¾¾ÝÎÚ¿ËÀ¼CERT½üÆÚÐû²¼µÄÏûÏ¢£¬ÎÚ¿ËÀ¼ÒѾÊܵ½ÁËÖÁÉÙ12¸öºÚ¿Í×éÖ¯µÄ¹¥»÷¡£ÔÚÕâЩ¹¥»÷ÖУ¬ºÚ¿Í×éÖ¯²»½öÕë¶ÔÎÚ¿ËÀ¼Õþ¸®¡¢µçÐÅ¡¢¹ú·À¡¢¾ü¶ÓµÈÒªÖØÒª²¿ÃÅÕ¹¿ªÍøÂç¹¥»÷£¬ÉõÖÁ»¹Ö±½Ó¶ÔÎÚ¿ËÀ¼ÄÜÔ´µÈ»ù½¨ÉèÊ©½øÐÐÁËÆÆ»µÐÔÍøÂç¹¥»÷¡£Æ¾¾Ý¶«Éƽ̨ADLabµÄÍþвÇ鱨Êý¾Ý¼°ÎÚ¿ËÀ¼CERT-UAµÄ¹ûÈ»³ÂËߣ¬ÎÒÃǶÔ×Ô2022Äê3ÔÂÒÔÀ´ÎÚ¿ËÀ¼ËùÔâÊܵIJ¿ÃÅÍøÂç¹¥»÷Äþ¾²Ê¼þ½øÐÐÁËÊáÀíºÍ»ã×Ü£¬Ïà¹ØÍøÂç¹¥»÷ʼþµÄʱ¼äÏßÈçÏÂͼËùʾ¡£Êµ¼ÊÉÏ£¬ÕâЩͳ¼ÆµÄÍøÂç¹¥»÷ʼþ½ö½öÊÇʵ¼Ê¹¥»÷Çé¿öµÄ±ùɽһ½Ç£»µ«ÈÔ²»ÄÑ¿´³ö£¬Õ½ÕùÆÚ¼äÕë¶ÔÎÚ¿ËÀ¼µÄÍøÂç¹¥»÷ÕßÖڶ࣬ÆäÖв»·¦¡°InvisiMole¡±¡¢¡°Vermin¡±¡¢¡°APT-28¡±µÈÖøÃûºÚ¿Í×éÖ¯£¬Ïà¹ØÍøÂç¹¥»÷»î¶¯Òà¸ñÍâƵ·±¡£
¡¤ 3ÔÂ6ÈÕ£¬¶«Éƽ̨ADLab¼à²âµ½ÁËÒ»ÅúÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÍøÂç¹¥»÷»î¶¯¡£Ôڴ˴ι¥»÷»î¶¯ÖУ¬¹¥»÷ÕßÀûÓÃЯ´ø¶ñÒâºê»ò©¶´¶ñÒâÎļþ×÷Ϊ³õʼ¹¥»÷Ôغɣ¬ÓÕʹÊܺ¦ÕßÐÅÈβ¢Ö´ÐкóÐøµÄQuasarRAT¶ñÒâľÂí£¬ÊÔͼ´ÓÊܺ¦Ö÷»úÖÐÇÔÈ¡Ãô¸ÐÎļþ¡£ÎÚ¿ËÀ¼CERTÒ²½«´Ë´ÎʼþµÄ¹¥»÷ÕßÃüÃûΪ¡°UAC-0086¡±£¬¹¥»÷ÕßʹÓõIJ¿ÃÅÓÕ¶üÎĵµÈçÏÂËùʾ¡£
£¨1£©ÓÕ¶üÎĵµÊ¾ÀýÒ»£ºÎ±×°³ÉISW£¨Õ½ÕùÑо¿Ñо¿Ëù£©»ú¹¹Îļþ
£¨2£©ÓÕ¶üÎĵµÊ¾Àý¶þ£ºÎ±×°³É¡°Hunter Biden,Burisma, and Corruption: The Impact on U.S.Government Policy and RelatedConcerns¡±£¨¡±ºàÌØ¡¤°ÝµÇ¡¶ÃÓÀÃ:¶ÔÃÀ¹úÕþ¸®Õþ²ßµÄÓ°Ïì¼°Ïà¹Ø¹ØÇС·¡±£©³ÂËßÎļþ
£¨3£©ÓÕ¶üÎĵµÊ¾ÀýÈý£º¡°The increasinglycomplicated Russia-Ukraine crisis explained¡±£¨¡°ÈÕÒæÅÓ´óµÄ¶íÂÞ˹-ÎÚ¿ËÀ¼Î£»ú½âÊÍ¡±£©³ÂËßÎļþ
¡¤ 3ÔÂ7ÈÕ£¬±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0051¡±µÄºÚ¿Í×é֯ʹÓöñÒâÈí¼þMicroBackdoor¶ÔÎÚ¿ËÀ¼¶à¸ö¹ú¼Ò²¿Ãź͵¥Ôª¿ªÕ¹Á˶à´ÎÍøÂç¹¥»÷»î¶¯¡£ÆäÖУ¬Ïà¹ØµÄÓÕ¶üÎļþºÍ²¿ÃŶñÒâÎļþ´úÂëÈçÏÂͼËùʾ¡£
¡¤ 3ÔÂ9ÈÕ£¬±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0041¡±µÄºÚ¿Í×éÖ¯½«¡°§§Ú§ã§ä §á§â§à §Ù§Ñ§ä§Ó§Ö§â§Õ§Ø§Ö§ß§ß§ñ §Ô§Ñ§â§Ñ§ß§ä??§Ô§â§à§ê§à§Ó§Ú§ç §Ü§à§ê§ä?§Ó¡±£¨¡°Ïֽ𵣱£Åú×¼º¯¡±£©×÷ΪÓʼþ±êÌ⣬²¢ÒÔ¡°Õ½ÕùºÍÌṩ²ÆÕþÔ®ÖúÒéÌ⡱ΪÓʼþÄÚÈÝ£¬ÏòÎÚ¿ËÀ¼Õþ¸®»ú¹¹ºÍµ¥Ôª½øÐдóÁ¿µÄͶµÝ¡£ÆäÖУ¬¡°support letter.xlsx¡±Óʼþ¸½¼þÊÇЯ´øºê´úÂëµÄ¶ñÒâÎĵµ£¬Êܺ¦ÕßÒ»µ©ÆôÓú꣬¸ÃºêÔò»á´Ó¹¥»÷ÕߵķþÎñÆ÷ÉÏÏÂÔØFormbook/XLoader¶ñÒⷨʽ£¬¹¥»÷Õß¼´¿É¿ªÕ¹½øÒ»²½µÄÍøÂç¹¥»÷»î¶¯¡£´Ë´Î¹¥»÷»î¶¯µÄÏà¹ØÎļþµÄ¾ßÌåÐÅÏ¢ÈçÏÂͼËùʾ¡£
¡¤ 3ÔÂ11ÈÕ£¬±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0056¡±µÄºÚ¿Í×é֯αװ³É¡°sed-rada.gov.ua¡±£¨±±¶ÙÄù´Ä¿Ë¾üÃñ×ÜÊð£©ÏòÎÚ¿ËÀ¼¹ú¼Ò»ú¹¹´ó¹æÄ£·Ö·¢µöÓãÓʼþ¡£¸ÃÓʼþÖаüÂÞÁ½¸öÓÕ¶üÎĵµ£¬ÇÒÓʼþÕýÎÄÖÐÐû³ÆÒªÇó¸÷»ú¹¹´Ó¡°https://forkscenter.fr¡±ÍøÕ¾ÏÂÔز¢°²×°·À²¡¶¾Èí¼þµÄ¸üÐÂÎļþ¡°BitdefenderWindowsUpdatePackage.exe¡±¡£µ±¸ÃEXEÎļþÀÖ³ÉÖ´Ðкó£¬×îÖÕ»á´ÓÖ¸¶¨·þÎñÆ÷ÉÏÏÂÔز¢Ö´ÐÐGraphSteelºÍGrimPlantºóÃÅ£¬ÒԱ㹥»÷ÕßÍê³É½øÒ»²½µÄÍøÂçÇÔÃÜÄ¿±ê¡£´Ë´Î¹¥»÷ʼþµÄÏà¹ØÎļþÈçÏÂͼËùʾ£º
ÓÕ¶üÎĵµ£º¡°?§ß§ã§ä§â§å§Ü§è?§ñ §Ù §Ñ§ß§ä§Ú§Ó?§â§å§ã§ß§à§Ô§à§Ù§Ñ§ç§Ú§ã§ä§å.doc¡±£¨·À²¡¶¾ËµÃ÷.doc£©
¡¤ 3ÔÂ15ÈÕ£¬ESETÔÚÎÚ¿ËÀ¼·¢ÏÖµÚÈý¸öÆÆ»µÐÔ²Á³ýÆ÷CaddyWiper£¬ÆäÖÐÇ°Á½¸öÆÆ»µÐͲÁ³ýÆ÷·Ö±ðÊÇÓÚ2ÔÂ23ÈÕÊ״η¢ÏÖµÄHermeticWiperºÍÔÚ2ÔÂ24ÈÕµÚ¶þ´Î·¢ÏÖµÄIsaacWiper¡£´ËÍ⣬Óë´Ë²Á³ýÆ÷Ïà¹ØµÄºÚ¿Í×éÖ¯Ò²±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0082¡±¡£ÆÆ»µÐÔ²Á³ýÆ÷CaddyWiperÖеġ°±éÀú´ÅÅÌÎļþ²¢Ïú»Ù¡±¹¦Ð§µÄ´úÂëÈçÏÂͼËùʾ£º
¡¤ 3ÔÂ16ÈÕ£¬ÒÉËÆAPT28£¨UAC-0028£©ºÚ¿Í×é֯ģ·ÂÀ´Ô´ÓÚUKR.NETÏûÏ¢µÄµöÓãÓʼþ£¬ÓʼþÕýÎÄÖÐʹÓÃURL¶ÌÁ´½Ó·þÎñ´´½¨µÄ¶þάÂ룬Òýµ¼Ä¿±êÓû§½øÐзÃÎÊ¡£Ò»µ©Óû§·ÃÎʺó£¬Ôò»á±»Öض¨Ïòµ½Î±×°µÄUKR.NETÃÜÂëÖØÖÃÒ³ÃæµÄµöÓãÍøÕ¾£¬¼Ì¶øͨ¹ýHTTP POSTÇëÇó½«Óû§ÊäÈëµÄÊý¾Ý·¢Ë͵½¹¥»÷ÕßÔÚPipedreamƽ̨ÕË»§ÖС£
Ä£·ÂÀ´×ÔUKR.NETµÄµç×ÓÓʼþÄÚÈÝ
UKR.NETÃÜÂëÖØÖÃαÔìÒ³Ãæ
²¿ÃŵöÓãÒ³Ãæ´úÂë
¡¤ 3ÔÂ17ÈÕ£¬ÓÉVermin (UAC-0020) ×é֯αװΪ¡°ÎÚ¿ËÀ¼¹ú·À²¿¡±ÏòÎÚ¿ËÀ¼¹ú¼ÒÕþ¸®»ú¹¹Í¶µÝÖ÷ÌâΪ¡°¹©Ó¦¡±µÄµöÓãÓʼþ¡£ÓʼþÖÐЯ´øÒ»¸ö¼ÓÃܵÄRARÎļþ£¬Ñ¹Ëõ°üÖаüÂÞÒ»¸öÎļþ¿ì½Ý·½Ê½ºÍÒ»¸öEXEÎļþ£¬µ±´ò¿ª¿ì½Ý·½Ê½Ê±£¬½«Ö´ÐÐEXEÎļþ¡£Ëæºó£¬Êܺ¦ÕßµÄÖ÷»ú»á±»¶ñÒâÈí¼þSPECTR¹¥»÷£¬¸Ã¶ñÒâÈí¼þ°üÂÞ£ºSPECTR.Usb¡¢SPECTR.Shell¡¢SPECTR.Fs¡¢SPECTR.Info¡¢SPECTR.ArchiverµÈÄ£¿é¡£²¿ÃÅÎļþÄÚÈÝÈçÏÂͼËùʾ¡£
¡¤ 3ÔÂ17ÈÕ£¬UAC-0088×é֯ʹÓà DoubleZero¶ÔÎÚ¿ËÀ¼µÄ²¿ÃÅÆóÒµ½øÐÐÍøÂç¹¥»÷¡£Ôڴ˴ι¥»÷ʼþÖУ¬±»·¢ÏÖµÄѹËõ°üÃûΪ¡°§£§Ú§â§å§ã... §Ü§â§Ñ§Û§ß§Ö §à§á§Ñ§ã§ß§à!!!.zip¡±£¨¡°²¡¶¾...·Ç³£Î£ÏÕ! ! !¡±£©£¬¸ÃѹËõ°ü°üÂÞÁ½¸öÎļþ£ºcpcrs.exeºÍcsrss.exe¡£Í¨¹ý·ÖÎö·¢ÏÖ£¬ËüÃÇʹÓÃC#±àд²¢±»¹éÀàΪDoubleZero²¡¶¾¡£¸Ã²¡¶¾»áÁýÕÖ´ÅÅÌÉÏËùÓеķÇϵͳÎļþ£¬²¢Æ¾¾ÝÒ»¶¨µÄ˳Ðò½øÐÐÖØд¡£
¡¤ 3ÔÂ18ÈÕ£¬InvisiMole£¨UAC-0035£©×éÖ¯Õë¶ÔÎÚ¿ËÀ¼¹ú¼ÒÕþ¸®»ú¹¹ºÍ¹ú·Àµ¥ÔªÌᳫÁËÓã²æʽÍøÂçµöÓãÓʼþ¹¥»÷¡£Óʼþ¸½¼þÊÇÃûΪ¡°501_25_103.zip¡±µÄѹËõ°üÎļþ£¬ÆäÖаüÂÞ501_25_103.lnk¿ì½Ý·½Ê½¡£µ±ÔËÐжñÒâ¿ì½Ý·½Ê½Ê±£¬¸Ã¿ì½Ý·½Ê½»á·ÃÎʹ¥»÷Õß·þÎñÆ÷²¢ÏÂÔغÍÖ´ÐÐHTAÎļþ¡£Ö®ºó£¬HTAÎļþÔÙ´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔز¢ÔËÐÐÓÕ¶üÎĵµ501_25_103.docºÍºóÃÅ·¨Ê½LoadEdge¡£
ÓÕ¶üÎĵµÄÚÈÝ
¡¤ 3ÔÂ22ÈÕ£¬Scarab APT×éÖ¯£¨UAC-0026£©Ê¹Óà HeaderTip ¶ñÒâÈí¼þÌᳫÕë¶ÔÎÚ¿ËÀ¼Õþ¸®²¿Ãź͵¥ÔªµÄÍøÂç¹¥»÷¡£¶«Éƽ̨ADLab×î³õ²¶×½µ½ÁËÃûΪ¡°§±§â§à§Ù§Ò§Ö§â§Ö§Ø§Ö§ß§ß§ñ §Ó?§Õ§Ö§à§Þ§Ñ§ä§Ö§â?§Ñ§Ý?§Ó §Ù §æ?§Ü§ã§Ñ§è??§ð §Ù§Ý§à§é§Ú§ß§ß§Ú§ç §Õ?§Û §Ñ§â§Þ??§â§à§ã?§Û§ã§î§Ü§à?§æ§Ö§Õ§Ö§â§Ñ§è??.rar¡±µÄѹËõ°üÎļþ£¬ÀïÃæ°üÂÞͬÃûµÄEXEÎļþ¡£¸Ã¶ñÒâÎļþÖ´Ðкó»áÊͷŲ¢´ò¿ªÎÞº¦µÄÓÕ¶üÎĵµ£¨¡°#2163_02_33-2022.pdf¡±£©£¬Í¬Ê±ÊͷźÍÖ´ÐÐÅú´¦ÖÃÎļþ£¨¡°officecleaner.bat¡±£©£¬Ö®ºó£¬batÎļþÊÍ·Å¡°httpshelper.dll¡±¶ñÒâÎļþ£¬²¢µ÷ÓÃrundll32.exeÖ´ÐиöñÒâľÂí¡£
ѹËõ°üÎļþÄÚÈÝ
ÓÕ¶üÎĵµÏà¹ØÄÚÈÝ
¡¤ 3ÔÂ23ÈÕ£¬ÒÉËÆUNC1151ºÚ¿Í×éÖ¯£¨UAC-0051£©Ê¹ÓöñÒâÈí¼þCobalt Strike Beacon¶ÔÎÚ¿ËÀ¼¹ú¼Ò²¿Ãź͵¥Ôª½øÐÐÍøÂç¹¥»÷¡£±»·¢ÏֵĶñÒâѹËõ°üÃûΪ¡°§¥§Ú§Ó§Ö§â§ã§Ñ§ß§ä§Ú.rar¡±£¬Æä°üÂÞÃûΪ¡°§¥§Ú§Ó§Ö§â§ã§Ñ§ß§ä§Ú 21.03.rar¡±µÄѹËõ°ü£¬¶ø¸ÃѹËõ°üÓÖ°üÂÞ¡°§¥§Ú§Ó§Ö§â§ã§Ñ§ß§ä§Ú filerar.scr¡± µÄSFXÎļþ£¬Ëƺõ½èÒÔÒþ²ØÎļþµÄ.scrÀ©Õ¹Ãû¡£´Ë´Î¹¥»÷ʼþÖеÄsfxÎļþ°üÂÞÓÕ¶üÎĵµºÍͼƬ£¬ÒÔ¼°¶ñÒâVBS´úÂë¡£¸Ã¶ñÒâvbs´úÂë»á´´½¨ºÍÔËÐÐÃûΪ¡°dhdhk0k34.com¡±µÄ .NET·¨Ê½£¬×îÖÕÖ´ÐÐCobalt Strike BeaconľÂí£¬Ïà¹ØµÄ¶ñÒâÎļþÄÚÈÝÈçÏÂͼËùʾ:
SFXÎļþÄÚÈÝ
Ïà¹ØÓÕ¶üÎĵµÄÚÈÝ
Ïà¹ØÓÕ¶üͼƬ
»ìÏýºóµÄ¶ñÒâvbs´úÂë
¡¤ 3ÔÂ28ÈÕ£¬UAC-0056×éÖ¯Õë¶ÔÎÚ¿ËÀ¼Õþ¸®£¨°üÂÞ˽È˵çÊÓƵµÀICTV£©Í¶µÝÖ÷ÌâΪ¡°§©§Ñ§Ò§à§â§Ô§à§Ó§Ñ§ß?§ã§ä§î §á§à §Ù§Ñ§â§á§Ý§Ñ§ä?¡±£¨¡°ÍÏÇ·ÈËΪ¡±£©µÄµöÓãÓʼþ£¬¸ÃµöÓãÓʼþÖаüÂÞExcelÎĵµµÄ¸½¼þÎļþÓëÓʼþÖ÷ÌâÃû³ÆÏàͬ£¬Ê¹Êܺ¦È˼õÉÙÔ¤·ÀÈ»ºó´ò¿ª¶ñÒâÎļþ¡£¸Ã¶ñÒâÎĵµÖаüÂÞÒ»¸öǶÈëµÄºê£¬ÒÔ¼°²¿ÃÅÒþ²ØÔÚ±í¸ñÖеÄÓÐЧÔغɡ£
¸Ã¶ñÒâºê´úÂë»áÊͷŲ¢Ö´Ðгõʼ¿ÉÖ´ÐÐÎļþ¡°Base-Update.exe¡±£¬¸Ã·¨Ê½±»Ö´Ðкó»á´ÓºÚ¿Í·þÎñÆ÷194[.]31.98.124ÉÏÏÂÔز¢Ö´ÐÐÏÂÒ»½×¶ÎºÚ¿Í½«Ê¹ÓõÄľÂí¡°java-sdk.exe¡±¡£ÆäÖУ¬java-sdk.exeµÄÖ÷Òª¹¦Ð§ÊÇʵÏÖÁ¬Ðø»¯£¬²¢´ÓºÚ¿Í·þÎñÆ÷194[.]31.98.124ÏÂÔز¿Êð½ÓÏÂÀ´½«Ê¹ÓõĶñÒⷨʽ¡°oracle-java.exe¡±Óë¡°microsoft-cortana.exe¡±¡£
ÆäÖУ¬¡°oracle-java.exe¡±£¨Elephant Implant/±»³ÆΪGrimPlantºóÃÅ£©ÊǴ˴ι¥»÷ÖÐ×îÖØÒªµÄ¶ñÒⷨʽ£¬Implant¿ÉÒÔͨ¹ý4ÖÖRPCÇëÇóÓëC2½øÐÐͨÐÅ£¬ÏòC2·¢ËÍÐÅÏ¢¶øÇÒ½ÓÊÕÏà¹ØÖ¸ÁÏà¹ØRPCÇëÇóÈçÏÂËùʾ£º
¶ø¡°microsoft-cortana.exe¡±ÔòÊÇÒ»¸öÊý¾ÝÇÔÈ¡Èí¼þ£¬ÆäÖ÷Òª¹¦Ð§°üÂÞÊÕ¼¯Êܺ¦ÕßÖ÷»úÃû¡¢²Ù×÷ϵͳÃû³Æ£¨windows£©¡¢CPUÊýÁ¿¡¢IPµØÖ·¡¢Ãû³Æ¡¢Óû§ÃûºÍÖ÷Ŀ¼¡¢ä¯ÀÀÆ÷ƾ¾Ý¡¢ÎÞÏßÍøÂçÐÅÏ¢¡¢Æ¾Ö¤¹ÜÀíÆ÷Êý¾Ý¡¢ÓʼþÕÊ»§¡¢PuttyÁ¬½ÓÊý¾Ý¡¢Filezilla ƾ¾ÝÒÔ¼°Êܺ¦ÕßÓû§Ä¿Â¼ÖÐËùÓÐÎļþ£¬²¢½øÐйþÏ£´¦Ö㬷¢Ë͵½Ö¸¶¨µÄC2·þÎñÆ÷ÉÏ¡£
¡¤ 3ÔÂ30ÈÕ£¬±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0041¡±µÄºÚ¿Í×éÖ¯ÒÔ¡°§¯§à§Ó§Ñ §á§â§à§Ô§â§Ñ§Þ§Ñ §Õ§Ý§ñ §Ù§Ñ§á§Ú§ã§å §Ó §Ø§å§â§ß§Ñ§Ýi.¡±£¨¡°ÐÂÆÚ¿¯Â¼Èë¼Æ»®¡±£©ÎªÖ÷Ìâ¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹ºÍµ¥Ôª½øÐдóÁ¿µÄµöÓãÓʼþ¹¥»÷¡£ÓʼþÕýÎÄÖаüÂÞ¹ØÓÚ¡°§Ö§Ý§Ö§Ü§ä§â§à§ß§ß§Ú§ç §ß§Ñ§Ó§é§Ñ§Ý§î§ß§Ú§ç §Ø§å§â§ß§Ñ§Ý?§Ó¡±£¨¡°µç×ÓѧϰÆÚ¿¯¡±£©µÄÏà¹ØÐÅÏ¢£¬ÒÔ¼°MarsStealerľÂíµÄÏÂÔØÁ´½ÓºÍÎĵµÃÜÂë¡£ÆäÖУ¬MarsStealerľÂíÊÇÒ»ÖÖ³£¼ûµÄÉÌҵľÂí£¬ÆäÖ÷Òª¹¦Ð§°üÂÞÊÕ¼¯±»Ñ¬È¾Ö÷»úµÄÃô¸ÐÐÅÏ¢£¬´Óä¯ÀÀÆ÷ÖÐÇÔÈ¡Óû§µÄÉí·ÝÑéÖ¤Êý¾Ý£¬´Ó¼ÓÃÜÇ®°ü²å¼þ»ò¶àÒòËØÉí·ÝÑéÖ¤·¨Ê½ÖÐÇÔÈ¡Îļþ£¬ÏÂÔغÍÔËÐпÉÖ´ÐÐÎļþ²¢½ØÈ¡ÆÁÄ»½Øͼ¡£
¡¤ 4ÔÂ4ÈÕ£¬±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0010¡±£¨ÒÉËÆArmageddon£©µÄºÚ¿Í×éÖ¯Õë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹·¢ËÍÖ÷ÌâΪ¡°?§ß§æ§à§â§Þ§Ñ§è?§ñ §ë§à§Õ§à §Ó?§Û§ã§î§Ü§à§Ó§Ú§ç §Ù§Ý§à§é§Ú§ß§è?§Ó §²§¶¡±£¨Ò룺¶íÂÞ˹Áª°îÕ½·¸¼Ç¼£©µÄµöÓãÓʼþ£¬Óʼþ¸½¼þΪ¡°§£?§Û§ã§î§Ü§à§Ó?§Ù§Ý§à§é§Ú§ß§è?§²§¶.htm¡±£¨Ò룺¶íÂÞ˹Áª°îµÄÕ½·¸.htm£©¡£
Èç¹ûÊܺ¦Õß´ò¿ª¸ÃhtmÎļþ£¬Æää¯ÀÀÆ÷Ôò»á×Ô¶¯ÏÂÔØ¡°Viyskovi_zlochinci_RU.rar¡±¡£
¸ÃѹËõ°ü°üÂÞÒ»¸öÃûΪ¡°§£?§Û§ã§î§Ü§à§Ó?-§Ù§Ý§à§é§Ú§ß§è? §ë§à §Ù§ß§Ú§ë§å§ð§ä§î §µ§Ü§â§Ñ?§ß§å (§Õ§à§Þ§Ñ§ê§ß?§Ñ§Õ§â§Ö§ã§Ú, §æ§à§ä§à, §ß§à§Þ§Ö§â§Ñ §ä§Ö§Ý§Ö§æ§à§ß?§Ó, §ã§ä§à§â?§ß§Ü§Ú §å §ã§à§è?§Ñ§Ý§î§ß§Ú§ç §ã§Ö§ä§ñ§ç)¡±£¨Ò룺¡°´Ý»ÙÎÚ¿ËÀ¼µÄÕ½·¸£¨¼Òͥסַ£¬ÕÕƬ£¬µç»°ºÅÂ룬Éç½»ÍøÕ¾ÖеÄÒ³Ã棩¡±£©µÄlnkÎļþ¡£
¸ÃlnkÎļþ½«»á´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔØÏÂÒ»½×¶ÎµÄ¹¥»÷ÎäÆ÷£¬¼´Ò»¸ö°üÂÞVB´úÂëµÄHTAÎļþ¡£´ËHTAÎļþ»á´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔØget.php£¬¶ø¸ÃÎļþʵ¼ÊÉÏÈ´ÊÇÒ»¸öpowershell½Å±¾£¬ÆäÖ÷ÒªÓÃÓÚÈ·¶¨¼ÆËã»úµÄΨһ±êʶ·û¡£
¡¤ 4ÔÂ12ÈÕ£¬±»Åû¶ÓɶíÂÞ˹¹ú¼Ò×ÊÖúµÄAPT×éÖ¯Sandworm£¨ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0082¡±£©Ê¹ÓöñÒⷨʽ INDUSTROYER2 ºÍ CADDYWIPER£¬ÔÚ4ÔÂ8ÈÕÊÔͼ¶ÔÒ»¼Ò´óÐÍÎÚ¿ËÀ¼ÄÜÔ´¹©Ó¦É̽øÐй¥»÷¡£´Ë´Î¹¥»÷ʼþµÄ¾ßÌåʱ¼ä½ÚµãÈçͼËùʾ£º
´ÓÏà¹ØʼþµÄ·ÖÎö±¨µÀÖпÉÒÔÍƲâ³ö¹¥»÷ÕߵIJ¿ÃÅÄ¿µÄ£º
£¨3£©Ê¹ÓöñÒâÆÆ»µÐͽű¾ORCSHRED¡¢SOLOSHRED¡¢AWFULSHRED¶ÔÆóÒµÄÚ²¿µÄLinuxϵͳµÄ·þÎñÆ÷½øÐÐÆÆ»µ¹¥»÷¡£
¡¤ 4ÔÂ14ÈÕ£¬±»ÎÚ¿ËÀ¼CERTÃüÃûΪ¡°UAC-0098¡±µÄºÚ¿Í×éÖ¯ÀûÓÃÃûΪ¡°§®§à§Ò?§Ý?§Ù§Ñ§è?§Û§ß§Ú§Û §â§Ö?§ã§ä§â.xls¡±£¨¡°·¢¶¯¹ÒºÅ²á.xls¡±£©µÄ¶ñÒâÎļþ¶ÔÎÚ¿ËÀ¼×éÖ¯½øÐдó¹æÄ£ÍøÂçµöÓã¹¥»÷»î¶¯¡£Ò»µ©Êܺ¦Õß´ò¿ªÎĵµ²¢ÆôÓú꣬¶ñÒâºê´úÂë»áÏÂÔز¢Ö´ÐÐÃûΪ¡°spisok.exe¡±µÄ¶ñÒâ´úÂë¡£ÆäÖУ¬¸Ã¡°spisok.exe¡±¶ñÒⷨʽ»áÊÍ·ÅÔËÐÐGzipLoader¶ñÒâÈí¼þ£¬¶øÇÒ´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔز¢ÔËÐÐIcedID¶ñÒⷨʽ£¬½øÐнøÒ»²½µÄÐÅÏ¢ÇÔÃܻ¡£
Èý¡¢µäÐ͹¥»÷ʼþ·ÖÎö
Åãͬ¶íÎÚ³åÍ»¾ÖÊƵIJ»Í£¶ñ»¯£¬½üÆÚÃé×¼ÎÚ¿ËÀ¼µÄÍøÂç¹¥»÷»î¶¯Ã÷ÏÔÔö¶à¡£±¾½Ú´ÓÉÏÊöÖÚ¶àÕë¶ÔÎÚ¿ËÀ¼½øÐеÄÍøÂç¹¥»÷ʼþÖУ¬·Ö±ðÑ¡È¡¶«Éƽ̨ADLabÔÚ2022Äê3ÔÂ6ÈÕºÍ3ÔÂ22ÈÕ¼à²âµ½µÄÁ½Æð¹¥»÷ʼþΪÀý£¬½øÐÐÏêϸµÄ¼¼Êõ·ÖÎö¡£
3.1 ¹¥»÷ʼþÒ»
2022Äê3ÔÂ6ÈÕ£¬¶«Éƽ̨ADLab¼ì²âµ½Ò»ÅúÕë¶ÔÓÚÎÚ¿ËÀ¼µÄÍøÂç¹¥»÷Ñù±¾£¬¹¥»÷Õß½èÒÔ¡°ÎÚ¿ËÀ¼·ÀÓù·½Ê½¡±¡¢¡°ÎÚ¿ËÀ¼³ÂËß_×îÖÕ¡±¡¢¡°ÈÕÒæÅÓ´óµÄ¶íÎÚΣ»ú½âÊÍ¡±ºÍ¡°Ð¹Â¶µÄ¿ËÀïÄ·ÁÖ¹¬µç×ÓÓʼþÏÔʾÃ÷˹¿ËÐÒ顱µÈ¾ßÓи߶ÈÃÔ»óÐÔµÄÈȵãÓÕ¶üÎĵµ½øÐй¥»÷£¬ÒÔ´ËÓÕʹÊܺ¦ÕßÐÅÈβ¢Ö´ÐкóÐøµÄ¶ñÒâľÂí¡£
ͨ¹ý¶Ô¹¥»÷ÕßµÄËÝÔ´ºÍ¹ØÁª·ÖÎö£¬ÎÒÃÇÕûÀíÁËÆäÔڴ˴ι¥»÷»î¶¯ÖÐʹÓõĶñÒâÎļþ¡£¾ßÌåÐÅÏ¢ÈçϱíËùʾ¡£
3.1.1 ¹¥»÷ÔغÉ
Ôڴ˴λµÄ³õʼ¹¥»÷»·½ÚÖУ¬¹¥»÷ÕßÖ÷ҪʹÓÃÁËÈýÖÖ¸ñʽµÄ¹¥»÷Ôغɣ¬ÆäÖаüÂÞЯ´ø¶ñÒâºêµÄ¶ñÒâÎĵµ¡¢Ð¯´ø©¶´µÄ¶ñÒâÎĵµºÍ¶ñÒâѹËõ°üÎļþ¡£
£¨1£©Ð¯´ø¶ñÒâºêµÄ¶ñÒâÎĵµ
¸Ã¶ñÒâÎĵµÒÔ¡°Leaked Kremlin emails show Minsk protocol designed as path toUkraine's capitulation¡±£¨Ò룺¡°Ð¹Â¶µÄ¿ËÀïÄ·ÁÖ¹¬µç×ÓÓʼþÏÔʾ£¬Ã÷˹¿ËÐÒé±»Éè¼Æ³ÉÎÚ¿ËÀ¼Í¶½µµÄ;¾¶¡±£©×÷ΪÓÕ¶üÄÚÈÝ£¬²¢ÌáʾÊܺ¦Õß¡°ÆôÓúꡱ¡£¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£
µ±Êܺ¦Õß´ò¿ª¸ÃÎĵµ²¢ÆôÓúê´úÂ빦Чºó£¬½«×Ô¶¯µ÷ÓÃDocument_Openº¯Êý£¬ÆäÖ÷Òª¹¦Ð§ÎªÌáÈ¡²¢Ö´ÐÐÉú´æÔÚUserForm1ÖеÄpowershellÖ¸Áî¡£
¶ÔpowershellºóÃæµÄ´úÂë½øÐÐBase64½âÂëºó£¬µÃµ½ÁË»ìÏýºóµÄps½Å±¾¡£¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£
ÔڶԸýű¾½øÐÐÈ¥»ìÏý´¦Öú󣬿ÉÒÔ¿´µ½¸ÃpowershellÖ¸ÁîµÄÖ÷Òª¹¦Ð§Îª´ÓÖ¸¶¨µÄurlÁбíÖÐÏÂÔØ¡°SoftwareUpdate.exe¡±£¬ÔÙ½«ÆäÉú´æµ½%TEMP%Ŀ¼²¢ÃüÃûΪ¡°update.exe¡±¡£
£¨2£©¶ñÒâѹËõ°üÎļþ
ÁíÒ»ÖÖÀàÐÍÊÇRARѹËõ°üÎļþ£¬¹¥»÷Õß½«ÆäÃüÃûΪ¡°The increasinglycomplicated Russia-Ukraine crisis explained¡±£¬¸ÃѹËõÎļþ°üÂÞÓÃÓÚÃÔ»óÊܺ¦ÕßµÄÕý³£pdfÓÕ¶üÎĵµÒÔ¼°Î±×°³ÉpdfÎļþͼ±êµÄ¶þ½øÖÆ¿ÉÖ´ÐжñÒⷨʽ£¨Í¨¹ýÐÞ¸Äexeͼ±êΪÎĵµÀ´ÓÕµ¼Êܺ¦Õßµã»÷£©¡£
Õý³£pdfÓÕ¶üÎĵµµÄ²¿ÃÅÄÚÈÝÈçÏÂͼËùʾ¡£
£¨3£©Ð¯´ø©¶´µÄ¶ñÒâÎĵµ
¹¥»÷ÕßÔڴ˴ι¥»÷Ðж¯ÖÐʹÓõÄÊÇoffice©¶´cve-2021-40444£¬¸Ã©¶´ÊÇ΢ÈíÓÚ2021Äê9ÔÂÐû²¼µÄÒ»¸öMicrosoftMSHTMLÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õß¿ÉÖÆ×÷Ò»¸öÓÉÍйÜä¯ÀÀÆ÷·ºÆðÒýÇæµÄ Microsoft Office ÎĵµÊ¹ÓõĶñÒâ ActiveX ¿Ø¼þ£¬Ö®ºóÓÕµ¼Óû§´ò¿ª¶ñÒâÎĵµ£¬Ôò¿ÉÔÚÄ¿±êϵͳÉÏÒÔ¸ÃÓû§È¨ÏÞÖ´ÐÐÈÎÒâ´úÂë¡£
ÎÒÃǽ«Ð¯´ø©¶´µÄ¶ñÒâÎĵµ½âѹºó£¬ÔÚrelsµÄdocument.xmlÎļþÖз¢ÏÖÁË¿ÉÒɵÄÏÂÔØÁ´½Ó£ºTarget="mhtml:https://web.sunvn.net/QYWI6LH4M71O.html!x-usc:https://web.sunvn.net/QYWI6LH4M71O.html"¡£
ʵÑéÏÂÔظÃQYWI6LH4M71O.htmlÎļþ£¬·¢ÏÖ·þÎñÆ÷ÒÑÎÞ·¨·ÃÎÊÁË£¬¾ÑéÖ¤¸ÃÓòÃûÒѾʧЧ¡£
ÔÚ½øÒ»²½µÄ·ÖÎöºó£¬ÎÒÃÇ·¢ÏÖ¹¥»÷ÕßʹÓÃÁ˶¨ÖƵÄPOCÄ£°å½øÐÐÅúÁ¿×Ô¶¯»¯Éú³É¶ñÒâÎĵµ£¬ÇÒ¶Ô¸÷©¶´ÎĵµÖаüÂÞµÄÏÂÔØÁ´½ÓËùÖ¸ÏòµÄhtml¾ù½øÐÐÁËËæ»ú»¯´¦Öá£
3.1.2 ºóÃÅ·ÖÎö
¾ßÌ幦ЧÈçϱíËùʾ¡£
3.2 ¹¥»÷ʼþ¶þ
2022Äê3ÔÂ22ÈÕ£¬¶«Éƽ̨ADLab²¶×½µ½Ò»¸öÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷Ñù±¾¡£¹¥»÷Õßͨ¹ýÀàËÆ¡°¹ØÓÚÉú´æ¶íÂÞ˹Áª°î¾ü¶Ó·¸×ïÐÐΪµÄÊÓƵ¼Ç¼¡±µÈ¾ßÓÐÃÔ»óÐÔµÄÎļþÃûÀ´ÓÕʹÊܺ¦ÕßÖ´ÐжñÒâľÂí£¬ÒԴ˵½´ï¶ÔÌض¨¹¥»÷Ä¿±êʵʩÈëÇÖµÄÄ¿µÄ¡£ÎÒÃǶԴ˴ι¥»÷»î¶¯µÄÏßË÷½øÐÐÁËÉîÈëµÄ×·×ÙºÍËÝÔ´·ÖÎö£¬·¢ÏÖÆäÓëÀúÊ·ÓƾõÄScarabºÚ¿Í×éÖ¯¾ßÓÐÒ»¶¨µÄÏàËÆÐÔ¡£
3.2.1 ËÝÔ´·ÖÎö
ÎÒÃǽñºó´ÎºÚ¿Í×éÖ¯ËùʹÓõĻù´¡ÉèÊ©¼°¹¥»÷ÊÖ·¨µÈ²ãÃæ½øÐйØÁª·ÖÎö£¬²¢½áºÏ¸Ã×éÖ¯ÔçÆÚ¹¥»÷»î¶¯ÖеÄÏà¹ØÌØÕ÷£¬µÃ³öÁËÏÂÃ漸´¦ÖØÒªµÄ¹ØÁªµã¡£
£¨1£©»ù´¡ÉèÊ©
ͨ¹ýÌáÈ¡ËùÓÐÑù±¾ÖеÄC2·þÎñÆ÷£¬ÎÒÃÇ·¢ÏÖ¹¥»÷ÕßÔڴ˴λÖÐËùʹÓõĻØÁªÓòÃû£¬ÊÇÔÚChangeIp.comƽ̨ÉÏÃâ·Ñ×¢²áµÄÈý¼¶×ÓÓò£¨¸Ãƽ̨ÌṩµÄÃâ·ÑÓòʵ¼ÊÉÏÊǶþ¼¶Óò£¬ÈçÏÂͼËùʾ£©¡£
ΪÁËÈ·¶¨¹¥»÷ÕßËùÊô×éÖ¯£¬ÎÒÃǶÔľÂí½øÐÐËÝÔ´·ÖÎö£¬ÕÒµ½ÁËÆäËûµÄͬԴľÂí¡£¼ì²ìÕâЩÓòÃûµÄ×¢²áÐÅÏ¢£¬ÎÒÃÇ·¢ÏÖÕâЩľÂíËùʹÓõÄC2Ò²¾ùÊÇÔÚChangeIp.comƽ̨½øÐÐ×¢²áµÄ¡£¶øÇÒÒѱ»±êעΪËùÊôScarabºÚ¿Í×éÖ¯¡£ÔÚÔçÆڵĹ¥»÷»î¶¯ÖУ¬¸ÃºÚ¿Í×éÖ¯¼¸ºõÍêÈ«ÊÇͨ¹ý¶¯Ì¬ÓòÃûϵͳ£¨DDNS£©ÓòÀ´Ö´ÐÐÃüÁîºÍ¿ØÖÆ£¨C&C£©²Ù×÷¡£¾ßÌåÈçÏÂͼËùʾ¡£
£¨2£©¹¥»÷ÊÖ·¨
¹¥»÷ÕßÔڴ˴ι¥»÷»î¶¯ÖУ¬ÊÇÒÔ¶ñÒâѹËõ°ü×÷Ϊ¹¥»÷Ôغɣ¬ËäÈ»ÎÒÃÇδÄÜÈ·¶¨¸ÃÎļþÊÇ·ñͨ¹ýµç×ÓÓʼþ½øÐÐͶµÝ¡£µ«Í¨¹ý¶ÔScarabºÚ¿Í×éÖ¯ÔçÆڵĹ¥»÷ÔغɽøÐÐÈ«ÃæµØÊÕ¼¯ºÍ·ÖÎöºó£¬ÎÒÃÇÊӲ쵽¸Ã×éÖ¯¹ßÓÚʹÓÃѹËõ°ü×÷ΪµÚÒ»½×¶ÎµÄÓÕ¶üÎĵµ¡£¾ßÌåÈçÏÂͼËùʾ¡£
´ËÍ⣬ºÚ¿Í×éÖ¯ÔÚÔçÆÚ¹¥»÷»î¶¯ÖУ¬ÊÇͨ¹ýѹËõ°üÖеĶñÒâÎĵµÀ´Õ¹¿ªÏÂÒ»½×¶ÎµÄ¹¥»÷Ðж¯£¬ÎĵµÖж¼°üÂÞÏàͬµÄÌáʾģ¿é¡£ÏêϸÄÚÈÝÈçÏÂͼËùʾ¡£
¶øÔڴ˴λÖУ¬¹¥»÷Õ߸ÄÓÃÁËÓëѹËõ°üͬÃûµÄEXE¿ÉÖ´ÐÐÎļþÀ´½øÐÐÈëÇÖÐÐΪ¡£µ«ÓëÔçÆÚÊÖ·¨ÏàËƵÄÊÇ£¬ÔÚÖ´ÐÐÍê´Ë½×¶ÎµÄ¹¥»÷Ôغɺó£¬Æ䶼ÊÐÔÚ%TMP%Ŀ¼ÏÂдÈë²¢´ò¿ªÒ»¸öÎÞº¦µÄÓëÖ÷ÌâÏà¹ØµÄÎĵµ£¬ÓÃÒÔÃÔ»óÊܺ¦Õß¡£¾ßÌåÈçÏÂͼËùʾ¡£
³ýÁËÒÔÉÏÂÞÁгöµÄ¹¥»÷ÊÖ·¨Í¬ScarabºÚ¿Í×éÖ¯¾ßÓÐÒ»¶¨µÄÖصþÐÔÒÔÍ⣬ÔÚºóÐø¹¥»÷Öй¥»÷ÕßʹÓõ½µÄ¶ñÒâ½Å±¾ºÍľÂí£¨°üÂÞÎļþÃû³ÆºÍÄÚÈÝ£©¾ùΪ¸Ã×éÖ¯ËùÓС£
»ùÓÚ¸Ã×éÖ¯µÄÓòÃûʹÓÃϲºÃ¡¢¹¥»÷ÊÖ·¨ºÍÈëÇÖ¼ÆıµÈ·½ÃæµÄ¶Ô±È·ÖÎö£¬ÎÒÃÇ¿ª¶ËÅжϱ¾´ÎµÄ¹¥»÷»î¶¯À´×ÔScarabºÚ¿Í×éÖ¯¡£ÖµµÃ×¢ÒâµÄÊÇ£¬ScarabºÚ¿Í×éÖ¯Ôø±»²¿ÃŹúÍ⹫˾±ê־ΪÀ´×ÔÖйúµÄºÚ¿Í×éÖ¯¡£È»¶ø£¬ÎÒÃǶÔÕâЩ¹«Ë¾ÌṩµÄÏêϸ³ÂËߺÍËùνµÄÖ¤¾Ý½øÐÐ×Ðϸ·ÖÎöºó·¢ÏÖ£¬ËùνµÄÖ¤¾Ý²»ÍâÊÇÎÞ·¨ÌṩµÄ¡°»ùÓÚÓïÑÔµÄ×ÊÔ´¡±ºÍÓÕ¶üÎĵµÖеÄÖÐÎÄ¡°Óû§¡±¶þ×Ö£¬ÕâÏÔȻ̫¹ýǣǿ£¬ÎÒÃDz¢²»ÖªµÀ¸Ã¹«Ë¾°Ñ¹¥»÷¹é¾ÌÓÚÖйúµÄÄ¿µÄÊÇʲô£¬µ«ÕâÖÖ¡°Æ¾¾ÝÎÞÁ¦µÄÖ¤¾Ý¾Í°ÑÍøÂç¹¥»÷¹é¾ÌÓÚÖйú¡±µÄǣǿÂß¼²¢²»ÉÙ¼û£¬Æä±³ºóµÄÍÆÊÖ¼°ÆäÄ¿µÄÔçÒÑÕÑÈ»Èô½Ò¡£
3.2.2 ¼¼Êõ·ÖÎö
´Ë´Î¹¥»÷»î¶¯ÖУ¬¶«Éƽ̨ADLab²¶×½µ½Á˸Ã×é֯ʹÓÃRARÎļþµÄ·½Ê½À´Õ¹¿ª¹¥»÷¡£ÎÒÃÇËäδÄÜÈ·¶¨¸Ã¶ñÒâÎļþµÄÀ´Ô´£¬µ«Æ¾¾ÝÒÔÍùµÄ¹¥»÷£¬¿ÉÒÔÍƶÏScarab×éÖ¯ÓпÉÄÜÊÇÀûÓõöÓãÓʼþ£¬½«Ñ¹Ëõ°ü×÷Ϊ¸½¼þ´Ó¶ø½øÐй¥»÷Ðж¯¡£µ±Ñ¹Ëõ°üÖеÄexeÎļþ±»Ö´Ðк󣬻áÊͷŲ¢´ò¿ªÎÞº¦µÄÓÕ¶üpdfÎĵµ£¬Í¬Ê±ÔÚ%TEMP%Ŀ¼ÏÂдÈë²¢Ö´ÐС°officecleaner.bat¡±Åú´¦ÖÃÎļþ¡£Ö®ºó£¬batÎļþÔòÔÚͬĿ¼ÏÂÊÍ·Å¡°httpshelper.dll¡±¶ñÒâÎļþ£¬²¢µ÷ÓÃrundll32.exeÖ´ÐжñÒâľÂí¡£µ¥´Ó¹¦Ð§À´¿´£¬´ËľÂí½ö°üÂÞ¼òµ¥µÄÉÏ´«ÏÂÔØÎļþ¡¢ÉèÖÃÐÝÃßʱ¼äµÈ£¬µ«ÊÇ£¬Æä¿ÉÖ±½Ó´ÓÃüÁîºÍ¿ØÖÆ£¨C2£©·þÎñÆ÷ÉÏ£¬ÏÂÔؼÓÔØÌض¨¹¦Ð§Ä£¿éÀ´½øÒ»²½µÄÖ´ÐжñÒâ²Ù×÷¡£
£¨1£©³õʼÔغÉ
¶«Éƽ̨ADLab×î³õ·¢ÏÖµÄRARÎļþ£¬Ãû³ÆΪ¡°§á§â§à§Ù§Ò§Ö§â§Ö§Ø§Ö§ß§ß§ñ§Ó§Ù§Ö§à§Þ§Ñ§ä§Ö§â?§Ñ§Ý?§Ó§Ù§æ?§Ü§ã§Ñ§è?§ê§Û§Ñ§â§Þ?§ê?§²§à§ã?§Û§ã§î§Ü§à§ð§æ§Ö§Õ§Ö§â§Ñ§è?????.rar¡±£¨Ò룺¡°¹ØÓÚÉú´æ¶íÂÞ˹Áª°î¾ü¶Ó·¸×ïÐÐΪµÄÊÓƵ¼Ç¼.rar¡±£©£¬Ñ¹Ëõ°üÖаüÂÞÒ»¸öͬÃûµÄEXE¿ÉÖ´ÐÐÎļþ¡£
µ±¶ñÒâEXEÎļþÖ´Ðк󣬻á´ÓÆä×ÊÔ´½ÚÖжÁÈ¡Ö¸¶¨µÄÊý¾Ý²¢Ð´Èëµ½Óû§µçÄÔ%TEMP%Ŀ¼Ï£¬¸ÃÎļþÊÇÃûΪ¡°#2163_02_33-2022.pdf¡±£¨À´×ÔÓÚÎÚ¿ËÀ¼¹ú¼Ò¾¯²ì¾ÖµÄÀ´ÐÅ£©µÄÓÕ¶üÎļþ£¬ËæºóÔÙÖ´ÐÐCMDÃüÁî´ò¿ª´ËÎļþ¡£Îļþ¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£
½Ó×Å£¬ÔٴζÁÈ¡Ö¸¶¨µÄ×ÊÔ´Êý¾Ý£¬²¢½«ÆäдÈëµ½%TEMP%Ŀ¼Ï£¬ÃüÃûΪ¡°officecleaner.bat¡±¡£ÄÚÈÝÈçÏÂͼËùʾ¡£
×îºó£¬Ê¹ÓÃCMDÃüÁBATÎļþÌí¼Óµ½×¢²á±íÆô¶¯ÏÒÔÈ·±£¸ÃÅú´¦ÖÃÎļþµÄ³Ö¾ÃÐÔ¡£
£¨2£©batÅú´¦ÖÃÎļþ
¡°officecleaner.bat¡±µÄÖ÷Òª¹¦Ð§Îª£¬Ìæ»»%TMP%Ŀ¼Ï¡°officecleaner.bat¡±µÄMZÍ·²¿²¢ÔÚͬĿ¼ÏÂдÈë¡°httpshelper.dll¡±Îļþ£¬Ö®ºóɾ³ýbatÅú´¦ÖÃÎļþ£¬ÒÔ¼°Ìí¼Ó¿ª»úÆô¶¯ÏîÈ·±£´ËDLLÎļþµÄ³Ö¾Ã»¯¡£
£¨3£©¶ñÒâľÂí
¸ÃÖ÷¹¦Ð§º¯ÊýÊ×ÏÈͨ¹ýPEB¶¯Ì¬»ñÈ¡ºóÆÚËùʹÓõÄAPIº¯Êý¡£
Ö®ºó»ñȡϵͳĿ¼µÄ¾íÐòÁкŲ¢½øÐÐÉú´æ¡£
½Ó×Å£¬½«»ñÈ¡µ½µÄÐòÁкŽøÐиñʽ»¯ºó·¢Ë͸øºÚ¿Í×éÖ¯µÄ·þÎñÆ÷¡£
µ±Óë·þÎñÆ÷ÀÖ³ÉÁ¬½Óºó£¬Ôòƾ¾Ý·þÎñÆ÷µÄ¿ØÖÆÖ¸ÁîÀ´½øÐÐÏàÓ¦µÄ²Ù×÷¡£¿ØÖÆÖ¸Áî½Ï¼òµ¥£¬°üÂÞÉÏ´«Îļþ¡¢ÏÂÔØÎļþ¡¢½ÓÊÕ·¢ËÍÖ¸¶¨Êý¾ÝºÍÖ¸¶¨ÐÝÃßʱ¼äµÈ¡£
ËÄ¡¢×ܽá
¶íÎÚÕ½Õù·¢×÷ÒÔÀ´£¬Ë«·½³ýÁËÔÚʵµØÕ½³¡½øÐн»·æÍ⣬ÔÚÍøÂç¿Õ¼äÕ½³¡ÖнøÐеIJ©ÞÄÒ²Óú¼Ó¼¤ÁÒ£»²»ÄÑ·¢ÏÖ£¬ÍøÂç¿Õ¼äÕ½ÒѳÉΪÏÖ´úÕ½ÕùµÄÖØÒª×é³É²¿ÃÅ£¬ÍøÂçÕ½¶ÔÏÖ´úÕ½Õù¾ÖÊƵÄÓ°ÏìͬÑùÖØÒª¡£ÔÚ¶íÎÚÕ½ÕùÈ«Ãæ·¢×÷֮ǰ£¬Ë«·½ÔÚÍøÂç¿Õ¼äÕ½³¡¾ÍÔçÒѽ»·æ£¬Ö»²»ÍâÍøÂçÕ½·¢ÉúÓÚÒ»¸ö¡°ÎÞÉùµÄ¶øÇÒûÓÐÏõÑ̵ÄÕ½³¡¡±£¬²¢²»Îª¹«ÖÚËù¹Ø×¢£¬µ«Æä¶ÔʵµØÕ½ÕùµÄÓ°ÏìÈ´¾Ù×ãÇáÖØ£»ºÃ±È£¬ÔÚÎÚ¶íÕ½Õù·¢×÷µ±Ì죬¶íÂÞ˹¶ÔÎÚ¿ËÀ¼µÄ²¿ÃžüÊ»ùµØ½øÐС°¶¨µãÇå³ý¹¥»÷¡±£¬Ö±½Óµ¼ÖÂÎÚ¿ËÀ¼Ê§È¥ÔÚµÚһʱ¼äÄÚ»¹»÷µÄÄÜÁ¦£¬´Ë¡°¶¨µãÇå³ý¹¥»÷¡±±³ºóËùÉæ¼°µÄÇ鱨ºÜ¿ÉÄܾÍÊÇ´ÓÍøÂçÕ½ÖлñÈ¡£»Õ½ÕùÈ«Ãæ·¢×÷ºó£¬Ë«·½ÔÚÍøÂçÕ½³¡µÄ½»·æÔ½·¢¼¤ÁÒ£¬ÖÖÖÖÍøÂç¹¥»÷ʼþƵ·¢£¬ÍøÂç¹¥»÷Ò»·½ÃæÄܹ»ÇÔÈ¡¶ÔÊÖÊÖÖÐÓëÕ½Õù½ôÃÜÏà¹ØµÄ»úÃÜÐÅÏ¢£¬ÁíÒ»·½ÃæÆÆ»µÍøÂçºÍÆäËû»ù´¡ÉèÊ©Ò²ÄÜÕðÉå¶ÔÊÖ£¬ÈÅÂÒ¶ÔÊÖ¶ÔʵµØÕ½¾ÖµÄ¾ÖÊÆÅжϣ¬´Ó¶øÓ°ÏìÕ½¾Ö×ßÊÆ¡£½áºÏ±¾´Î¹¥»÷»î¶¯·ÖÎö¼°ÒÔÍùÎÒÃǶÔÎÚ¿ËÀ¼ÔâÊܵĺڿ͹¥»÷µÄ·ÖÎö¡ª¡ª¡¶ÎÚ¿ËÀ¼Õ½Õù±³ºóµÄÍøÂç¹¥»÷ºÍÇ鱨»î¶¯¡·ºÍ¡¶Õë¶ÔÎÚ¿ËÀ¼±ß·À¾ÖºÍ¹ú·À²¿¹¥»÷»î¶¯Éî¶È·ÖÎö¡·£¬¿ÉÒÔ¿´³ö£¬ÍøÂç¿Õ¼äÕ½Æäʵ±ÈʵµØÕ½Õù·¢×÷µÄʱ¼ä¸üÔ磬սÏ߸ü³¤¶øÇÒÒþ±Î£¬ÍøÂç¿Õ¼äÄþ¾²¶Ô¹ú¼ÒÄþ¾²µÄÖØÒªÐÔ²»ÑÔ¶øÓ÷¡£