Õý¶ù°Ë¾­Ëµ¼¼Êõ¡ª¡ªÒÔEmotetΪÀýÉîÈë·ÖÎöCMDÃüÁî»ìÏý¼¼Êõ

Ðû²¼Ê±¼ä 2018-12-13
EmotetÒ»¿îÖøÃûµÄÒøÐÐľÂí £¬Ê״ηºÆðÓÚ2014ÄêÄêÖС£¸ÃľÂíÖ÷Ҫͨ¹ýÀ¬»øÓʼþµÄ·½Ê½Á÷´«Ñ¬È¾Ä¿±êÓû§ £¬½ñÄêÈÔÈ»·Ç³£»îÔ¾ £¬¶øÇÒ²»Í£±ä»¯Á÷´«»¨Ñù £¬½ÓÄÉÔ½À´Ô½ÅÓ´óµÄ»ìÏý±àÂëÀ´¶ã±Ü¼ì²â¡£
    
CMDºÍPowershellÃüÁî¾­³£±»ÓÃÔÚ¶ñÒâÈí¼þÖÐÖ´ÐжñÒâ½Å±¾Îļþ £¬²¢Í¨¹ý½Å±¾»ìÏý¡¢¼ÓÃÜ»ò±àÂ뷽ʽÀ´ÈƹýAV¼ì²â¡£±¾ÎÄÁоÙÁ½¸öµäÐ͵ÄEmotetÁ÷´«ÖÐʹÓõĻìÏýCMDÃüÁî £¬À´ÉîÈë·ÖÎöCMD.ÃüÁî»ìÏý¼¼Êõ¡£

ÏÈ¿´Ò»¸ö´ÓDOCÎĵµÇ¶ÈëµÄVBAºê´úÂëÖÐÌáÈ¡µÄCMDÃüÁî £¬Õ§Ò»¿´ÉÏÈ¥ £¬ÏñÊÇÎÞÒâÒåµÄÒ»´®×Ö·û £¬×Ðϸ·ÖÎöÆðÀ´ÐèÒªÏÈÁ˽âÒ»ÏÂCMDÃüÁîµÄ»ìÏý·½Ê½¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 


 Ò¼

CMDÃüÁîµÄ»ìÏý·½Ê½


 
 ²åÈëÌØÊâ×Ö·û»ìÏýÃüÁî 
 
×Ö·û¡°^¡±ÊÇCMDÃüÁîÖÐ×î³£¼ûµÄתÒå×Ö·û £¬¸Ã×Ö·û²»Ó°ÏìÃüÁîµÄÖ´ÐС£ÒòΪÔÚcmd»·¾³ÖÐ £¬ÓÐЩ×Ö·û¾ß±¸ÌØÊ⹦Ч £¬Èç >¡¢>>ÌåÏÖÖØ¶¨Ïò £¬| ÌåÏֹܵÀ £¬&¡¢&&¡¢|| ÌåÏÖÓï¾äÁ¬½Ó¡£ËüÃǶ¼ÓÐÌØ¶¨µÄ¹¦Ð§ £¬Èç¹ûÐèÒª°ÑËüÃÇ×÷Ϊ×Ö·ûÊä³öµÄ»° £¬echo >¡¢echo |Ö®ÀàµÄд·¨¾Í»á¶éÂ䡪¡ªcmd½âÊÍÆ÷»á°ÑËüÃÇ×÷Ϊ¾ßÓÐÌØÊ⹦ЧµÄ×Ö·û¿´´ý £¬¶ø²»»á×÷ΪÆÕͨ×Ö·û´¦Öà £¬Õâ¸öʱºò £¬¾ÍÐèÒª¶ÔÕâÐ©ÌØÊâ×Ö·û×öתÒå´¦ÖãºÔÚÿ¸öÌØÊâ×Ö·ûǰ¼ÓÉÏתÒå×Ö·û^¡£

Òò´Ë £¬ÒªÊä³öÕâÐ©ÌØÊâ×Ö·û £¬¾ÍÐèÒªÓà echo ^>¡¢echo ^|¡¢echo ^|^|¡¢echo ^^Ö®ÀàµÄ¸ñʽÀ´´¦Öá£ÁíÍâ £¬´ËתÒå×Ö·û»¹¿ÉÒÔÓÃ×÷ÐøÐзûºÅ¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶ººÅ¡°,¡±ºÍ·ÖºÅ ¡°;¡±¿ÉÒÔ»¥»» £¬¿ÉÒÔÈ¡´úÃüÁîÖеĺϷ¨¿Õ¸ñ¡£¶à¸ö¿Õ¸ñÒ²²»Ó°ÏìÃüÁîÖ´ÐС£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


³É¶ÔµÄÔ²À¨ºÅ£¨£©Ò²»á·ºÆðÔÚÃüÁî²ÎÊýÖÐ £¬Ò²²»Ó°ÏìÃüÁîµÄÖ´ÐС£Ô²À¨ºÅÌåÏÖǶÈë×ÓÃüÁî×é £¬Í¬Ñù±»cmd.exe²ÎÊý´¦ÖÃÆ÷½øÐнâÊÍ¡£È磺cmd.exe /c ( ( ((echo Command 1) ) )) &&( ( (((((echo Command 2))))) ) )
 
 ÀûÓÃCMD»·¾³±äÁ¿Æ´½ÓÃüÁî 
 
Cmd.exeÄÚ²¿ÃüÁîÓУº set¡¢assoc  £¬ftypeµÈ¡£

SetÃüÁîÓÃÀ´ÏÔʾ¡¢ÉèÖûòɾ³ýcmd.exe»·¾³±äÁ¿¡£ÃüÁî¸ñʽ£º
SET [variable=[string]]
  variable  Ö¸¶¨»·¾³±äÁ¿Ãû¡£
  string    Ö¸¶¨ÒªÖ¸Åɸø±äÁ¿µÄһϵÁÐ×Ö·û´®¡£

ÔÚÃüÁîÐÐÖÐÊäÈë set £¬»áÁоٳöcmd.exeÖÐËùÓеĻ·¾³±äÁ¿¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


assoc£ºÎļþÃûÀ©Õ¹¹ØÁªÃüÁî £¬ÓÃÓÚÏÔʾºÍÉèÖÃÎļþÃûÀ©Õ¹¹ØÁª £¬¿ÉÒÔÖ¸¶¨Ä³ÖÖºó׺ÃûµÄÎļþƾ¾ÝÌØ¶¨µÄÀàÐÍÎļþ´ò¿ª»òÖ´ÐС£ÃüÁî¸ñʽΪ£ºassoc [.ext[=[fileType]]] 

.extÊÇÖ¸£ºÖ¸¶¨Òª¹ØÁªµÄÎļþºó׺Ãû¡£µãºÅ£¨.)ÊDz»ÄÜÊ¡Â﵀ £¬Èç¹ûÊ¡ÂÔÁËϵͳ½«ÏÔʾ¸Ãºó׺ÃûÎļþµÄ¹ØÁªÐÅÏ¢¡£fileTypeÊÇÖ¸£ºÖ¸¶¨Ïà¹ØÁªµÄÎļþÀàÐÍ¡£Èç¹ûֻʹÓøòÎÊý £¬½«ÏÔʾ¸ÃÎļþÀàÐ͵ÄÐÅÏ¢¡£·´Ö® £¬¸ÃÃüÁÁгöϵͳע²áµÄËØÓкó׺ÃûÎļþºÍÏà¹ØµÄÀàÐÍ¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ftype£ºÏÔʾ»òÐÞ¸ÄÓÃÔÚÎļþÀ©Õ¹Ãû¹ØÁªÖеÄÎļþÀàÐÍ £¬Ö¸¶¨Ò»ÖÖÀàÐ͵ÄÎļþĬÈÏÓÃÄĸö·¨Ê½ÔËÐлò´ò¿ª¡£ÃüÁî¸ñʽΪ£ºftype [fileType[=[openCommandString]]

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


cmd.exeµÄ»·¾³±äÁ¿·ÖΪϵͳÒÑÓеĻ·¾³±äÁ¿ºÍ×Ô½ç˵±äÁ¿¡£ÀûÓû·¾³±äÁ¿µÄÖµÖеÄ×Ö·û»ò×Ö·û´® £¬¿ÉÒÔÆ´½Ó³ÉºÚ¿ÍÐèÒªµÄcmdÃüÁî £¬Í¬Ê±¿ÉÒÔÌӱܾ²Ì¬¼ì²â¡£ÈçϵͳÒÑÓеĻ·¾³±äÁ¿%comspec%±äÁ¿µÄֵĬÈÏΪ£º¡°C:\WINDOWS\system32\cmd.exe¡± £¬setÃüÁî¿ÉÒÔ±»±àÂëΪ£º %comspec:~11,1%%comspec:~-1%%comspec:~-13,1%¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


%VarName:~offset[,length]% Ö÷ÒªÓÃÓÚ»ñÈ¡»·¾³±äÁ¿VarNameµÄ±äÁ¿Öµ £¬Æ«ÒÆoffset×Ö½ÚÖ®ºó³¤¶ÈΪlength¸ö×Ö½Ú¡£[,length]¿ÉÊ¡ÂÔ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


%comspec:~11,1%ÌåÏÖÈ¡comspec±äÁ¿ÖµÖеÄ×Ö·û £¬Ä¬ÈÏϱê´Ó0¿ªÊ¼ £¬´Óϱê11¿ªÊ¼ £¬È¡Ò»¸ö×Ö·û £¬¼´Îª¡±s¡±¡£offsetÒ²Ö§³Ö¸ºÊý £¬ÌåÏÖ·´Ïò±éÀú×Ö·û´®µÄϱê¡£%comspec:~-1%¼´Îª¡°e¡° £¬%comspec:~-13,1%¼´Îª¡±t¡°¡£Èç´Ë±àÂësetÃüÁî £¬¿ÉÒÔÌÓÍѾ²Ì¬¼ì²â¡±set¡°ÃüÁî×Ö·û´®µÄ¼ì²â»úÖÆ¡£

ͨ³£ÎÒÃÇÒ²¿ÉÒÔ×Ô½ç˵һ¸ö»òÕß¶à¸ö»·¾³±äÁ¿ £¬ÀûÓû·¾³±äÁ¿ÖµÖеÄ×Ö·û £¬ÌáÈ¡²¢Æ´½Ó³ö×îÖÕÏëÒªµÄcmdÃüÁî¡£Èç:
Cmd /C ¡°set envar=net user && call echo %envar%¡° ¿ÉÒÔÆ´½Ó³öcmdÃüÁnet user
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò²¿ÉÒÔ½ç˵¶à¸ö»·¾³±äÁ¿½øÐÐÆ´½ÓÃüÁî´® £¬Ìá¸ß¾²Ì¬·ÖÎöµÄÅÓ´ó¶È£º
cmd /c ¡° set envar1=ser&& set envar2=ne&& set envar3=t u&&call echo %envar2%%envar3%%envar1%¡±
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


cmdÃüÁîµÄ¡°/C¡±²ÎÊý £¬Cmd /C ¡°string¡±ÌåÏÖ£ºÖ´ÐÐ×Ö·û´®stringÖ¸¶¨µÄÃüÁî £¬È»ºóÖÕÖ¹¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶øÆôÓÃÑӳٵĻ·¾³±äÁ¿À©Õ¹ £¬¾­³£Ê¹Óà cmd.exeµÄ /V:ON²ÎÊý £¬
/V:ON²ÎÊýÆôÓÃʱ £¬¿ÉÒÔ²»Ê¹ÓÃcallÃüÁîÀ´À©Õ¹±äÁ¿ £¬Ê¹Óà %var% »ò !var! À´À©Õ¹±äÁ¿ £¬!var!¿ÉÒÔÓÃÀ´È¡´ú%var% £¬Ò²¾ÍÊÇ¿ÉÒÔʹÓÃ̾ϢºÅ×Ö·ûÀ´Ìæ´úÔËÐÐʱµÄ»·¾³±äÁ¿Öµ¡£ºóÃæ½éÉÜForÑ­»·Ê±»áÐèÒª¿ªÆô/V:²ÎÊýÑÓ³Ù±äÁ¿À©Õ¹·½Ê½¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 
 ÀûÓÃForÑ­»·Æ´½ÓÃüÁî 
 
ForÑ­»·¾­³£±»ÓÃÀ´»ìÏý´¦ÖÃcmdÃüÁî £¬Ê¹µÃcmdÃüÁî¿´ÆðÀ´ÅÓ´óÇÒÄÑÒÔ¼ì²â¡£×î³£ÓõÄForÑ­»·²ÎÊýÓÐ /L,/F²ÎÊý¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FOR ²ÎÊý %±äÁ¿Ãû IN (Ïà¹ØÎļþ»òÃüÁî) DO Ö´ÐеÄÃüÁî

FOR %variable IN (set) DO command [command-parameters]

%variable Ö¸¶¨Ò»¸öµ¥Ò»×Öĸ¿ÉÌæ»»µÄ²ÎÊý¡£ Õâ¸ö±äÁ¿Ãû¿ÉÒÔÊÇСдa-z»òÕß´óдA-Z,Çø·Ö¾Þϸд,FOR»á°Ñÿ¸ö¶ÁÈ¡µ½µÄÖµ¸³¸ø¸Ã±äÁ¿¡£ÔÚÅú´¦ÖÃÎļþÖÐ £¬ÒýÓñäÁ¿ÒªÓÃ%%variable £¬ÎÒÃÇÕâÀïÖ÷Òª½éÉÜÔÚcmd´°¿ÚÖÐ £¬ÒýÓñäÁ¿ÓÃ%variable¼´¿É¡£
(set)      Ö¸¶¨Ò»¸ö»òÒ»×éÎļþ¡£¿ÉÒÔʹÓÃͨÅä·û¡£ Ïà¹ØµÄÎļþ»òÃüÁî¡£
command    Ö¸¶¨¶Ôÿ¸öÎļþÖ´ÐеÄÃüÁî¡£ 
command-parameters 
             ÎªÌض¨ÊýÁîÖ¸¶¨²ÎÊý»òÃüÁîÐпª¹Ø¡£
/L ²ÎÊý£º µü´úÊýÖµ·¶Î§
for /L %variable in (start,step,end) do command [command-parameters]

¸ÃÃüÁîÌåÏÖÒÔÔöÁ¿ÐÎʽ´Ó¿ªÊ¼µ½½áÊøµÄÒ»¸öÊý×ÖÐòÁС£Ê¹Óõü´ú±äÁ¿ÉèÖÃÆðʼֵ(start) £¬È»ºóÖð²½Ö´ÐÐÒ»×鷶ΧµÄÖµ £¬Ö±µ½¸ÃÖµÁè¼ÝËùÉèÖõÄÖÕÖ¹Öµ (end)¡£/L ½«Í¨¹ý¶ÔstartÓëend½øÐбÈÁ¦À´Ö´Ðеü´ú±äÁ¿¡£Èç¹ûstartСÓÚend £¬¾Í»áÖ´ÐиÃÃüÁî £¬·ñÔòÃüÁî½âÊÍ·¨Ê½Í˳ö´ËÑ­»·¡£»¹¿ÉÒÔʹÓøºµÄ stepÒԵݼõÊýÖµµÄ·½Ê½Öð²½Ö´Ðд˷¶Î§ÄÚµÄÖµ¡£ÀýÈç £¬(1,1,5) Éú³ÉÐòÁÐ 1 2 3 4 5 £¬¶ø (5,-1,1) ÔòÉú³ÉÐòÁÐ (5 4 3 2 1)¡£ÃüÁîcmd /C ¡°for /L %i in (1,1,5) do start cmd¡±,»áÖ´Ðдò¿ª5¸öcmd´°¿Ú¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


/F²ÎÊý£º ÊÇ×îÇ¿´óµÄÃüÁî £¬ÓÃÀ´´¦ÖÃÎļþºÍһЩÃüÁîµÄÊä³ö½á¹û¡£
FOR /F ["options"] %variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %variable IN ('command') DO command [command-parameters]
(file-set) ΪÎļþÃû £¬for»áÒÀ´Î½«file-setÖеÄÎļþ´ò¿ª £¬¶øÇÒÔÚ½øÐе½ÏÂÒ»¸öÎļþ֮ǰ½«Ã¿¸öÎļþ¶ÁÈ¡µ½ÄÚ´æ £¬Æ¾¾ÝÿһÐзֳÉÒ»¸öÒ»¸öµÄÔªËØ £¬ºöÂÔ¿Õ°×ÐС£
("string")´ú±í×Ö·û´® £¬('command')´ú±íÃüÁî¡£
¼ÙÈçÎļþaa.txtÖÐÓÐÈçÏÂÄÚÈÝ£º
µÚ1ÐеÚ1ÁÐ µÚ1ÐеÚ2ÁР
µÚ2ÐеÚ1ÁÐ µÚ2ÐеÚ2ÁÐ
ÒªÏë¶Á³öaa.txtÖеÄÄÚÈÝ £¬¿ÉÒÔÓÃfor /F %i in (aa.txt) do echo %i  £¬Èç¹ûÈ¥µô/F²ÎÊýÔòÖ»»áÊä³öaa.txt £¬²¢²»»á¶ÁÈ¡ÆäÖеÄÄÚÈÝ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÏÈ´ÓÀ¨ºÅÖ´ÐÐ £¬ÒòΪº¬ÓвÎÊý/F,ËùÒÔfor»áÏÈ´ò¿ªaa.txt £¬È»ºó¶Á³öaa.txtÀïÃæµÄËùÓÐÄÚÈÝ £¬°ÑËü×÷Ϊһ¸ö¼¯ºÏ £¬¶øÇÒÒÔÿһÐÐ×÷Ϊһ¸öÔªËØ¡£ÓÉÉÏͼ¿É¼û £¬²¢Ã»ÓÐÊä³öµÚ¶þÁеÄÄÚÈÝ £¬Ô­ÒòÊÇÈç¹ûûÓÐÖ¸¶¨¡°delims=·ûºÅÁÐ±í¡±Õâ¸ö¿ª¹Ø £¬ÄÇôfor /FÓï¾ä»áĬÈÏÒÔ¿Õ¸ñ¼ü»òTab¼ü×÷ΪÀ뿪·û¡£For /FÊÇÒÔÐÐΪµ¥ÔªÀ´´¦ÖÃÎı¾ÎļþµÄ £¬Èç¹ûÎÒÃÇÏë°ÑÿһÐÐÔÙÆÊÎö³É¸üСµÄÄÚÈÝ £¬¾ÍʹÓÃdelimsºÍtokensÑ¡Ïî¡£delimsÓÃÀ´¸æËßforÿһÐÐÓÃʲô×÷ΪÀ뿪·û £¬Ä¬ÈÏÀ뿪·ûÊǿոñºÍTab¼ü¡£for /F ¡°delims= ¡° %i in (aa.txt) do echo %i ,½«delimsÉèÖÃΪ¿Õ¸ñ £¬Êǽ«Ã¿¸öÔªËØÒÔ¿Õ¸ñÖ§½â £¬Ä¬ÈÏֻȡ֧½âÖ®ºóµÄµÚÒ»¸öÔªËØ¡£Èç¹ûÎÒÃÇÏëµÃµ½µÚ¶þÁÐÊý¾Ý £¬¾ÍÒªÓõ½tokens=2 £¬À´Ö¸¶¨Í¨¹ýdelims½«Ã¿Ò»ÐзֳɸüСµÄÔªËØÊ± £¬ÒªÈ¡³öÄÄÒ»¸ö»òÄöÔªËØ:for /F ¡°tokens=2 delims= ¡° %i in (aa.txt) do echo %i¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 ·¡
ʵ¼ÊÑùÌìÖ°Îö
 
ÎÒÃÇѡȡнüµÄEmotetÑù±¾ÏÂÔØÀûÓõÄCMDÃüÁî»ìÏý £¬À´ÀûÓÃÇ°ÃæµÄ֪ʶÀ´½â»ìÏý¡£
 
 ÀûÓÃ×Ô½ç˵»·¾³±äÁ¿ºÍForÑ­»·»ìÏý 
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸ÃÑù±¾ÖÐÀûÓÃÁËcmd.exe µÄÆôÓÃÑÓ³Ù»·¾³±äÁ¿/V:ON²ÎÊý £¬/C²ÎÊý £¬ÀûÓÃsetÃüÁî×Ô½ç˵һ¸ö»·¾³±äÁ¿kpx=lHUwrRfzapaiNzCqHfu:Doc(4YQ0S.1,xk}$) s6dK=mn5/+ygbW-TeP\v2tj{78Mh@;BO'FZ £¬Í¨¹ý&&Æ´½ÓÃüÁî £¬È»ºóÊǸöforÑ­»·£º for %G in £¨ÊýÁУ©do set     1q=!1q!!kpx:~  %G,    1!&& if %G==  81  call  %1q:~    -377%¡£ÎÒÃÇ×ÅÖØ·ÖÎöÏÂforÃüÁî¡£ÒòÎªÇ°ÃæÊ¹ÓÃÁËÑÓ³Ù»·¾³±äÁ¿ £¬ËùÒÔ¿ÉÒÔʹÓÃ!1q!!kpx:~  %G,    1!µÄ·½Ê½À´À©Õ¹±äÁ¿ £¬ÔÚÔËÐÐʱȡ´ú»·¾³±äÁ¿Öµ¡£forµÄÑ­»·±äÁ¿ÊÇ%G £¬%G in (ÊýÁÐÖµ) £¬!kpx:~ %G, 1!ÌåÏÖÈ¡»·¾³±äÁ¿kpxÖÐϱêΪ%GµÄÒ»¸ö×Ö·û £¬ÎÒÃÇ¿ÉÒÔÓÃÈçÏÂpython±àÂëʵÏָù¦Ð§¡£ÊýÁÐÖеĿոñ¿ÉÒÔºöÂÔ £¬ÊýÁÐÖеÄÊýÖµÕýºÃÊÇ377¸ö £¬kpx×Ö·û´®µÄ³¤¶ÈÊÇ72¸ö×Ö·û £¬Ï±êΪ81ÒѾ­²»´æÔÚ £¬ËùÒÔµ±Ï±ê%G==81ʱ £¬ÔËÐÐʱ»·¾³±äÁ¿1q=!1q!powershell ¡­¡­, call %1q:~-377% £¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÊÇforÑ­»·±éÀú³öµÄpowershell¡­¡­ÃüÁî £¬Ç°ÃæµÄ1q=!1q!Êdzõʼ»¯±äÁ¿1q £¬ÐèÒª±»È¥µôÒÔÃâÓ°ÏìÕý³£ÃüÁîµÄÖ´ÐÐ £¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÈÆ¹ýÇ°ÃæµÄ!1q!¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Êä³ö£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://catbayouthaction.com/jKS86a
http://spsystems24.ru/O
http://xn--80abdh8aeoadtg.xn--p1ai/multimedia/hD4lyk7
http://borsehung.pro/pfWq
http://inpart-auto.ru/x2bu

 ÀûÓÃcmdϵͳ»·¾³±äÁ¿ºÍForÑ­»·»ìÏý 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÏȽ«»ìÏýcmdÃüÁîÖеÄתÒå×Ö·û¡°^¡±È«²¿È¥µô £¬ÔÙ½«³ýÁ˱äÁ¿@Ö®ÍâµÄ¶ººÅ¡°,¡±¡¢·ÖºÅ¡°;¡±¡¢¶àÓà¿Õ¸ñɾ³ý¡£×¢Òâ±£Áô±äÁ¿@ÖеĶººÅºÍ·ÖºÅ £¬·ñÔòÓ°ÏìÊä³ö½á¹û¡£

 ¿É¼ûÀûÓÃÁËcmdµÄϵͳ»·¾³±äÁ¿%comspec% £¬¼´ÊÇcmd.exeµÄÖ´Ðз¾¶¡£ÀûÓÃForÑ­»·µÄF²ÎÊý £¬ÔÚÃüÁî'aSsoC .cmd'ÖÐÒÔ×Ö·ûv¡¢f¡¢=ΪÀ뿪·û £¬È¡µÚ¶þÁм´ÊÇ¡°cmd¡±¡£
fOr  /f  " delims=vf=  tokens=2"  %f  IN  ( 'aSsoC  .cmd' ) dO  %f  ¡£ÆäËûÎÞÒâÒåµÄ×Ö·û´®»á±»cmdºöÂÔ¡£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½Ó×Å×Ô½ç˵ÁËÒ»¸ö»·¾³±äÁ¿@ £¬¼´ÊÇÒ»¸ö1460³¤¶ÈµÄ×Ö·û´®¡£È»ºóÀûÓÃForÑ­»·µÄ/L²ÎÊý £¬±éÀú±äÁ¿@£ºFOr /L %s In (1459,-4,+3 ) do (( ( (( seT \=!\!!@ :~ %s, 1!))))& iF %s eQU 3 (((CaLl %\ :~ -365% ) £¬×Ô½ç˵ÁË»·¾³±äÁ¿¡°\¡± £¬ÀûÓû·¾³±äÁ¿À©Õ¹·ûºÅ£¡ £¬!@ :~ %s, 1!ÌåÏÖÑ­»·±äÁ¿%s´Ó1459¿ªÊ¼ £¬²½³¤Îª-4 £¬µ½3½áÊø £¬Ñ­»·ÌáÈ¡±äÁ¿@ÖеÄÒ»¸ö×Ö·û £¬³¤¶ÈΪ365¸ö×Ö·û £¬¼´´ÓForÑ­»·ÖØ×é³öµÄÃüÁʼִÐС£
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÒÃDZàдpython½Å±¾ÊµÏÖForÑ­»·¹¦Ð§£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×îÖÕ½âÃܳö¿É¶ÁµÄÄÚǶpowershellÃüÁ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÏÂÔØEmotetµÄÁ´½ÓΪ£º

http://reitmaier.de/01cedmfXo
http://phoxart.com/sWP0E9
http://panbras.com.br/FHhUYIQ
http://osmanager.com.br/t3HnvWx9x
http://oldwillysforum.com/ChleCkW

 Èþ
×ܽá
 
CMDµÄÃüÁî»ìÏýǧ±äÍò»¯ £¬Î¨Ò»µÄÄ¿µÄ¾ÍÊÇÌÓ±ÜɳÏäµÄ¾²Ì¬»ò¶¯Ì¬¼ì²â £¬Ôö¼Ó·ÖÎöÄѶÈ¡£Íò±ä²»ÀëÆä×Ú £¬Ö»ÒªÕÆÎÕÁËcmdÃüÁîµÄ»ù±¾Óï¹æÔòÔò²¢ÊìÁ·Ê¹Óà £¬Ä¿Ç°¶ñÒâÑù±¾µÄÖÖÖÖcmd»ìÏýÃüÁî¶¼¿ÉÒÔÓ­Èжø½â £¬½ø¶øÊµÏÖ¶Ô¸ÃÀàÑù±¾µÄʶ±ð¼ì²âºÍ·À·¶¡£
 
²Î¿¼£º 
https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf